@@ -1603,6 +1603,14 @@ function runCleanSignTempDirectory() {
16031603
16041604let signCount = 0 ;
16051605
1606+ /**
1607+ * @param {string } value
1608+ */
1609+ function assertMsbuildXmlValue ( value ) {
1610+ assert ( value . length > 0 && ! / [ ^ \w . / \\ : - ] / . test ( value ) , `Unsupported MSBuild XML value: ${ JSON . stringify ( value ) } ` ) ;
1611+ return value ;
1612+ }
1613+
16061614/**
16071615 * @typedef {{
16081616 * SignFileRecordList: {
@@ -1615,11 +1623,10 @@ let signCount = 0;
16151623 * @param {DDSignFileList } filelist
16161624 */
16171625async function sign ( filelist , unchangedOutputOkay = false ) {
1618- let data = JSON . stringify ( filelist , undefined , 4 ) ;
1619- console . log ( "filelist:" , data ) ;
1626+ console . log ( "filelist:" , JSON . stringify ( filelist , undefined , 4 ) ) ;
16201627
1621- if ( ! process . env . MBSIGN_APPFOLDER ) {
1622- console . log ( styleText ( "yellow" , "Faking signing because MBSIGN_APPFOLDER is not set." ) ) ;
1628+ if ( ! process . env . MICROBUILD_PLUGIN_DIRECTORY ) {
1629+ console . log ( styleText ( "yellow" , "Faking signing because MICROBUILD_PLUGIN_DIRECTORY is not set." ) ) ;
16231630
16241631 // Fake signing for testing.
16251632
@@ -1659,6 +1666,7 @@ async function sign(filelist, unchangedOutputOkay = false) {
16591666 }
16601667
16611668 const signingWorkaround = true ;
1669+ let signingFilelist = filelist ;
16621670
16631671 /** @type {{ source: string; target: string }[] } */
16641672 const signingWorkaroundFiles = [ ] ;
@@ -1699,8 +1707,8 @@ async function sign(filelist, unchangedOutputOkay = false) {
16991707 } ) ,
17001708 } ;
17011709
1702- data = JSON . stringify ( newFileList , undefined , 4 ) ;
1703- console . log ( "new filelist:" , data ) ;
1710+ signingFilelist = newFileList ;
1711+ console . log ( "new filelist:" , JSON . stringify ( signingFilelist , undefined , 4 ) ) ;
17041712 }
17051713
17061714 /** @type {Map<string, string> } */
@@ -1724,16 +1732,41 @@ async function sign(filelist, unchangedOutputOkay = false) {
17241732 }
17251733
17261734 const tmp = await getSignTempDir ( ) ;
1727- const filelistPath = path . resolve ( tmp , `signing-filelist-${ signCount ++ } .json` ) ;
1728- await fs . promises . writeFile ( filelistPath , data ) ;
1735+ const propsPath = path . resolve ( tmp , `signing-items-${ signCount ++ } .props` ) ;
1736+ const signingItems = signingFilelist . SignFileRecordList . flatMap ( record => record . SignFileList . map ( file => ( { path : file . SrcPath , cert : record . Certs , macAppName : record . MacAppName } ) ) ) ;
1737+ const items = signingItems . map ( ( { path : filePath , cert, macAppName } ) =>
1738+ ` <FilesToSign Include="${ assertMsbuildXmlValue ( filePath ) } ">
1739+ <Authenticode>${ assertMsbuildXmlValue ( cert ) } </Authenticode>
1740+ <StrongName>None</StrongName>${
1741+ macAppName ? `
1742+ <MacAppName>${ assertMsbuildXmlValue ( macAppName ) } </MacAppName>` : ""
1743+ }
1744+ </FilesToSign>`
1745+ ) . join ( "\n" ) ;
1746+ await fs . promises . writeFile (
1747+ propsPath ,
1748+ `<Project xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
1749+ <ItemGroup>
1750+ ${ items }
1751+ </ItemGroup>
1752+ </Project>
1753+ ` ,
1754+ ) ;
17291755
17301756 try {
1731- const dll = path . join ( process . env . MBSIGN_APPFOLDER , "DDSignFiles.dll" ) ;
1732- const filelistFlag = `/filelist:${ filelistPath } ` ;
1733- await run ( "dotnet" , [ dll , "--" , filelistFlag ] ) ;
1757+ await run ( "dotnet" , [
1758+ "build" ,
1759+ path . resolve ( "tools/signing/Sign.csproj" ) ,
1760+ "--target:AfterBuild" ,
1761+ "--verbosity:normal" ,
1762+ "-p:SignType=real" ,
1763+ `-p:SignFilesDir=${ path . resolve ( "built" ) } ` ,
1764+ `-p:FilesToSignPropsFile=${ propsPath } ` ,
1765+ `-p:MicroBuildOverridePluginDirectory=${ process . env . MICROBUILD_PLUGIN_DIRECTORY } ` ,
1766+ ] ) ;
17341767 }
17351768 finally {
1736- await fs . promises . unlink ( filelistPath ) ;
1769+ await fs . promises . unlink ( propsPath ) ;
17371770 }
17381771
17391772 if ( signingWorkaround ) {
@@ -2798,7 +2831,7 @@ async function runSignVsixExtensions() {
27982831 ] ,
27992832 } ) ;
28002833
2801- if ( ! process . env . MBSIGN_APPFOLDER ) {
2834+ if ( ! process . env . MICROBUILD_PLUGIN_DIRECTORY ) {
28022835 console . log ( "Skipping VSIX signature verification because signing was faked." ) ;
28032836 return ;
28042837 }
0 commit comments