Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Sign macOS build #323

Merged
merged 16 commits into from
Feb 18, 2025
Merged

Sign macOS build #323

merged 16 commits into from
Feb 18, 2025

Conversation

edvilme
Copy link
Member

@edvilme edvilme commented Jan 28, 2025

Fixes #300

Uses 1ESPipelineTemplates EsrpCodesigning task to sign macOS builds.
Successfully generates signed binary artifacts for both x64 and arm64 on Mac.
See below output of codesign -dv on a M1 Mac.

image

image

@edvilme edvilme force-pushed the edvilme-macos-signing branch 6 times, most recently from 14b77dc to 8cec3f7 Compare February 4, 2025 17:35
@edvilme edvilme changed the title (Draft) Sign macOS build Sign macOS build Feb 4, 2025
@edvilme edvilme marked this pull request as ready for review February 4, 2025 23:49
@edvilme edvilme requested a review from Copilot February 5, 2025 17:16

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot reviewed 1 out of 1 changed files in this pull request and generated no comments.

@edvilme edvilme requested a review from a team February 5, 2025 19:11
@edvilme edvilme requested a review from a team February 5, 2025 19:48
@edvilme edvilme force-pushed the edvilme-macos-signing branch 2 times, most recently from 8a3c16d to cd0cf3d Compare February 5, 2025 22:51
@mmitche
Copy link
Member

mmitche commented Feb 6, 2025

@edvilme FYI, newer versions of arcade do support mac signing and notarization via microbuild. No need need to use AzDO tasks. That said, performance is somewhat dependent on the number of files signed, at least for the next month or so. A low number (< 10) will be fine. Beyond that, the scaling of Microbuild is poor on Mac/Linux right now.

@Forgind
Copy link
Member

Forgind commented Feb 6, 2025

@edvilme FYI, newer versions of arcade do support mac signing and notarization via microbuild. No need need to use AzDO tasks. That said, performance is somewhat dependent on the number of files signed, at least for the next month or so. A low number (< 10) will be fine. Beyond that, the scaling of Microbuild is poor on Mac/Linux right now.

This repo is tiny, so number of files shouldn't be an issue. This might be a good direction if it isn't hard. (If this already works, I wouldn't put too much time into it, though.)

Copy link
Member

@MiYanni MiYanni left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes generally look good. Keep in mind, I don't know this repo or its CI. I'd just check with Chet about the zip vs tar.gz thing.

@edvilme
Copy link
Member Author

edvilme commented Feb 7, 2025

@Forgind @MiYanni the first commit contains changes made to make signing under 1ES and confirmed it worked. However that is no longer the case after updating arcade. The second commit is work in progress to testing signing with arcade instead.

I would like to investigate the arcade issue on main first before continuing testing :)

See #328

@edvilme edvilme marked this pull request as draft February 11, 2025 17:29
@edvilme edvilme force-pushed the edvilme-macos-signing branch from 6a8eb0f to defa237 Compare February 11, 2025 18:04
@edvilme edvilme force-pushed the edvilme-macos-signing branch from 3045564 to 359b843 Compare February 11, 2025 18:39
@edvilme edvilme marked this pull request as ready for review February 18, 2025 17:55
@edvilme
Copy link
Member Author

edvilme commented Feb 18, 2025

This PR was rewritten but is now generating valid signed binaries for macOS using microbuild

@edvilme edvilme requested review from MiYanni and Copilot February 18, 2025 17:59

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.

Files not reviewed (1)
  • eng/Signing.props: Language not supported
@edvilme edvilme force-pushed the edvilme-macos-signing branch from 480f19f to 7206567 Compare February 18, 2025 18:21
@edvilme edvilme merged commit 06d1e0e into main Feb 18, 2025
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Malicious software warning on MacOS when using the latest version
5 participants