| 1 | #!/usr/bin/env bash |
| 2 | set -euo pipefail |
| 3 | |
| 4 | arch="${1:?usage: finalize-windows-signed-candidate.sh ARCH SIGNING_WORK PAYLOAD DIST BUNDLE VERSION}" |
| 5 | signing_work="${2:?missing signing work directory}" |
| 6 | signed_payload="${3:?missing signed payload directory}" |
| 7 | dist="${4:?missing output dist directory}" |
| 8 | bundle="${5:?missing output bundle directory}" |
| 9 | version="${6:?missing release version}" |
| 10 | |
| 11 | case "$arch" in |
| 12 | amd64 | arm64) ;; |
| 13 | *) echo "unsupported Windows architecture: $arch" >&2; exit 1 ;; |
| 14 | esac |
| 15 | |
| 16 | product_root="$(pwd)" |
| 17 | control_root="$(cd "$(dirname "$0")/.." && pwd)" |
| 18 | case "$signing_work" in /*) ;; *) signing_work="$product_root/$signing_work" ;; esac |
| 19 | case "$signed_payload" in /*) ;; *) signed_payload="$product_root/$signed_payload" ;; esac |
| 20 | case "$dist" in /*) ;; *) dist="$product_root/$dist" ;; esac |
| 21 | case "$bundle" in /*) ;; *) bundle="$product_root/$bundle" ;; esac |
| 22 | for variable in CERTUM_KEY_ID MINISIGN_PRIVATE_KEY MINISIGN_PASSWORD RELEASE_SOURCE_SHA RELEASE_CONTROL_SHA RELEASE_TAG RELEASE_VERSION RELEASE_CHANNEL RELEASE_SIGNING_FINGERPRINT RELEASE_ARTIFACT_PREFIX; do |
| 23 | [ -n "${!variable:-}" ] || { echo "missing $variable" >&2; exit 1; } |
| 24 | done |
| 25 | |
| 26 | # FINALIZE_PHASE splits the run so the Certum steps stay in one session while |
| 27 | # the two architectures compress their installers at the same time: |
| 28 | # sign (Certum), package (no credentials), seal (Certum). Unset runs all three. |
| 29 | phase="${FINALIZE_PHASE:-all}" |
| 30 | case "$phase" in |
| 31 | all | sign | package | seal) ;; |
| 32 | *) echo "unsupported FINALIZE_PHASE: $phase" >&2; exit 1 ;; |
| 33 | esac |
| 34 | run_phase() { [ "$phase" = all ] || [ "$phase" = "$1" ]; } |
| 35 | |
| 36 | if run_phase sign; then |
| 37 | pwsh -NoProfile -File "$control_root/scripts/sign-certum.ps1" -PayloadDirectory "$signed_payload" |
| 38 | fi |
| 39 | if ! run_phase package && ! run_phase seal; then |
| 40 | exit 0 |
| 41 | fi |
| 42 | |
| 43 | installer="$dist/Reasonix-windows-$arch-installer.exe" |
| 44 | portable="$dist/Reasonix-windows-$arch.zip" |
| 45 | if run_phase package; then |
| 46 | # Keep the immutable checkout's NSIS template and icon. The signing handoff |
| 47 | # carries generated identity and payload files, not these committed inputs. |
| 48 | rm -rf "$dist" "$bundle" |
| 49 | mkdir -p "$product_root/desktop/build/windows/installer" |
| 50 | cp "$signing_work/desktop/build/windows/installer/reasonix_project.nsh" \ |
| 51 | "$product_root/desktop/build/windows/installer/" |
| 52 | ( |
| 53 | cd "$product_root/desktop" |
| 54 | go run ./cmd/sign windows-payload "$signed_payload" "$version" |
| 55 | go run ./cmd/sign sign "$signed_payload/reasonix-payload.json" |
| 56 | go run ./cmd/sign verify "$signed_payload/reasonix-payload.json" |
| 57 | ) |
| 58 | |
| 59 | REASONIX_REQUIRE_PAYLOAD_MANIFEST=1 \ |
| 60 | "$product_root/scripts/package-windows-desktop.sh" "$arch" "$signed_payload" |
| 61 | mv "$product_root/dist" "$dist" |
| 62 | fi |
| 63 | run_phase seal || exit 0 |
| 64 | |
| 65 | pwsh -NoProfile -File "$control_root/scripts/sign-certum.ps1" -FilePath "$installer" |
| 66 | |
| 67 | portable_layout="legacy-dual" |
| 68 | if [ -f "$product_root/desktop/packaging/windows-portable-layout.txt" ]; then |
| 69 | portable_layout="$(tr -d '\r\n' < "$product_root/desktop/packaging/windows-portable-layout.txt")" |
| 70 | fi |
| 71 | pwsh -NoProfile -File "$control_root/scripts/verify-windows-authenticode.ps1" \ |
| 72 | -PayloadDirectory "$signed_payload" -InstallerPath "$installer" \ |
| 73 | -PortableArchivePath "$portable" -ExpectedThumbprint "$CERTUM_KEY_ID" \ |
| 74 | -RequireTrusted -PortableLayout "$portable_layout" |
| 75 | |
| 76 | node "$product_root/desktop/packaging/size-report.mjs" \ |
| 77 | --platform "windows/$arch" --version "$version" \ |
| 78 | --bundle "$signed_payload" --dist "$dist" \ |
| 79 | --output "$product_root/desktop/build/reports/windows-$arch" |
| 80 | ( |
| 81 | cd "$product_root/desktop" |
| 82 | go run ./cmd/sign sign "$dist"/* |
| 83 | ) |
| 84 | node "$control_root/scripts/desktop-release-artifacts.mjs" pack "$dist" "$bundle" "windows-$arch" |
| 85 |