返回 DeepSeek-Reasonix
finalize-windows-signed-candidate.sh
根目录 / scripts / finalize-windows-signed-candidate.sh
1 #!/usr/bin/env bash
2 set -euo pipefail
3
4 arch="${1:?usage: finalize-windows-signed-candidate.sh ARCH SIGNING_WORK PAYLOAD DIST BUNDLE VERSION}"
5 signing_work="${2:?missing signing work directory}"
6 signed_payload="${3:?missing signed payload directory}"
7 dist="${4:?missing output dist directory}"
8 bundle="${5:?missing output bundle directory}"
9 version="${6:?missing release version}"
10
11 case "$arch" in
12 amd64 | arm64) ;;
13 *) echo "unsupported Windows architecture: $arch" >&2; exit 1 ;;
14 esac
15
16 product_root="$(pwd)"
17 control_root="$(cd "$(dirname "$0")/.." && pwd)"
18 case "$signing_work" in /*) ;; *) signing_work="$product_root/$signing_work" ;; esac
19 case "$signed_payload" in /*) ;; *) signed_payload="$product_root/$signed_payload" ;; esac
20 case "$dist" in /*) ;; *) dist="$product_root/$dist" ;; esac
21 case "$bundle" in /*) ;; *) bundle="$product_root/$bundle" ;; esac
22 for variable in CERTUM_KEY_ID MINISIGN_PRIVATE_KEY MINISIGN_PASSWORD RELEASE_SOURCE_SHA RELEASE_CONTROL_SHA RELEASE_TAG RELEASE_VERSION RELEASE_CHANNEL RELEASE_SIGNING_FINGERPRINT RELEASE_ARTIFACT_PREFIX; do
23 [ -n "${!variable:-}" ] || { echo "missing $variable" >&2; exit 1; }
24 done
25
26 # FINALIZE_PHASE splits the run so the Certum steps stay in one session while
27 # the two architectures compress their installers at the same time:
28 # sign (Certum), package (no credentials), seal (Certum). Unset runs all three.
29 phase="${FINALIZE_PHASE:-all}"
30 case "$phase" in
31 all | sign | package | seal) ;;
32 *) echo "unsupported FINALIZE_PHASE: $phase" >&2; exit 1 ;;
33 esac
34 run_phase() { [ "$phase" = all ] || [ "$phase" = "$1" ]; }
35
36 if run_phase sign; then
37 pwsh -NoProfile -File "$control_root/scripts/sign-certum.ps1" -PayloadDirectory "$signed_payload"
38 fi
39 if ! run_phase package && ! run_phase seal; then
40 exit 0
41 fi
42
43 installer="$dist/Reasonix-windows-$arch-installer.exe"
44 portable="$dist/Reasonix-windows-$arch.zip"
45 if run_phase package; then
46 # Keep the immutable checkout's NSIS template and icon. The signing handoff
47 # carries generated identity and payload files, not these committed inputs.
48 rm -rf "$dist" "$bundle"
49 mkdir -p "$product_root/desktop/build/windows/installer"
50 cp "$signing_work/desktop/build/windows/installer/reasonix_project.nsh" \
51 "$product_root/desktop/build/windows/installer/"
52 (
53 cd "$product_root/desktop"
54 go run ./cmd/sign windows-payload "$signed_payload" "$version"
55 go run ./cmd/sign sign "$signed_payload/reasonix-payload.json"
56 go run ./cmd/sign verify "$signed_payload/reasonix-payload.json"
57 )
58
59 REASONIX_REQUIRE_PAYLOAD_MANIFEST=1 \
60 "$product_root/scripts/package-windows-desktop.sh" "$arch" "$signed_payload"
61 mv "$product_root/dist" "$dist"
62 fi
63 run_phase seal || exit 0
64
65 pwsh -NoProfile -File "$control_root/scripts/sign-certum.ps1" -FilePath "$installer"
66
67 portable_layout="legacy-dual"
68 if [ -f "$product_root/desktop/packaging/windows-portable-layout.txt" ]; then
69 portable_layout="$(tr -d '\r\n' < "$product_root/desktop/packaging/windows-portable-layout.txt")"
70 fi
71 pwsh -NoProfile -File "$control_root/scripts/verify-windows-authenticode.ps1" \
72 -PayloadDirectory "$signed_payload" -InstallerPath "$installer" \
73 -PortableArchivePath "$portable" -ExpectedThumbprint "$CERTUM_KEY_ID" \
74 -RequireTrusted -PortableLayout "$portable_layout"
75
76 node "$product_root/desktop/packaging/size-report.mjs" \
77 --platform "windows/$arch" --version "$version" \
78 --bundle "$signed_payload" --dist "$dist" \
79 --output "$product_root/desktop/build/reports/windows-$arch"
80 (
81 cd "$product_root/desktop"
82 go run ./cmd/sign sign "$dist"/*
83 )
84 node "$control_root/scripts/desktop-release-artifacts.mjs" pack "$dist" "$bundle" "windows-$arch"
85
85 lines BASH