Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion Packaging/DeveloperID/build_release.sh
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@ set -euo pipefail
ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
source "$ROOT_DIR/script/release_path_guard.sh"
source "$ROOT_DIR/script/disk_image_tools.sh"
source "$ROOT_DIR/Packaging/DeveloperID/codesign_details.sh"
PACKAGE_DIR="$ROOT_DIR/SwiftExplorerApp"
PACKAGING_DIR="$ROOT_DIR/Packaging/DeveloperID"
OUTPUT_NAME="${DEVELOPER_ID_OUTPUT_NAME:-developer-id}"
Expand Down Expand Up @@ -215,7 +216,7 @@ validate_app() {
if [[ "$SKIP_SIGNING" -eq 0 ]]; then
grep -F 'Authority=Developer ID Application:' "$signature_output" >/dev/null
grep -F "TeamIdentifier=$EXPECTED_TEAM_ID" "$signature_output" >/dev/null
grep -E '^flags=.*runtime' "$signature_output" >/dev/null
codesign_details_has_hardened_runtime "$signature_output"
grep -F 'Timestamp=' "$signature_output" >/dev/null
fi
}
Expand Down
9 changes: 9 additions & 0 deletions Packaging/DeveloperID/codesign_details.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
#!/usr/bin/env bash

codesign_details_has_hardened_runtime() {
if [[ $# -ne 1 || ! -f "$1" ]]; then
return 2
fi

grep -Eq '(^|[[:space:]])flags=[^[:space:]]*[(,]runtime[),]' "$1"
}
49 changes: 49 additions & 0 deletions Packaging/DeveloperID/tests/codesign_details_contract_test.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
#!/usr/bin/env bash
set -euo pipefail

ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/../../.." && pwd)"
CHECKS="$ROOT_DIR/Packaging/DeveloperID/codesign_details.sh"
TMP_DIR="$(mktemp -d "${TMPDIR:-/tmp}/codebase-combiner-codesign-details.XXXXXX")"
trap 'rm -rf "$TMP_DIR"' EXIT

if [[ ! -f "$CHECKS" ]]; then
echo "Code-signing detail checks are missing: $CHECKS" >&2
exit 1
fi
source "$CHECKS"

cat > "$TMP_DIR/current.txt" <<'DETAILS'
Executable=/Applications/Codebase Combiner.app/Contents/MacOS/CodebaseExplorerApp
CodeDirectory v=20500 size=4521 flags=0x10000(runtime) hashes=130+7 location=embedded
Runtime Version=26.5.0
DETAILS

cat > "$TMP_DIR/legacy.txt" <<'DETAILS'
Executable=/Applications/Codebase Combiner.app/Contents/MacOS/CodebaseExplorerApp
flags=0x10000(runtime)
DETAILS

cat > "$TMP_DIR/no-runtime-flag.txt" <<'DETAILS'
CodeDirectory v=20500 size=4521 flags=0x0(none) hashes=130+7 location=embedded
Runtime Version=26.5.0
DETAILS

cat > "$TMP_DIR/misleading-runtime.txt" <<'DETAILS'
CodeDirectory v=20500 size=4521 flags=0x0(none) hashes=130+7 location=embedded
Path=/tmp/runtime/Codebase Combiner.app
DETAILS

codesign_details_has_hardened_runtime "$TMP_DIR/current.txt"
codesign_details_has_hardened_runtime "$TMP_DIR/legacy.txt"

if codesign_details_has_hardened_runtime "$TMP_DIR/no-runtime-flag.txt"; then
echo "Runtime version metadata was mistaken for the hardened-runtime signing flag." >&2
exit 1
fi

if codesign_details_has_hardened_runtime "$TMP_DIR/misleading-runtime.txt"; then
echo "An unrelated runtime path was mistaken for the hardened-runtime signing flag." >&2
exit 1
fi

echo "Code-signing details contract passed"
1 change: 1 addition & 0 deletions Packaging/DeveloperID/tests/run_tests.sh
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ set -euo pipefail

TEST_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"

bash "$TEST_DIR/codesign_details_contract_test.sh"
bash "$TEST_DIR/build_release_contract_test.sh"
bash "$TEST_DIR/notarize_release_contract_test.sh"

Expand Down