Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 11 additions & 4 deletions Packaging/DeveloperID/tests/notarize_release_contract_test.sh
Original file line number Diff line number Diff line change
Expand Up @@ -114,10 +114,17 @@ printf 'codesign %s\n' "$*" >> "$CALL_LOG"
if [[ "$*" == *"--verify"* && "${FAIL_GATE:-}" == codesign-verify ]]; then exit 74; fi
if [[ "$*" == *"--extract-certificates"* ]]; then
while [[ $# -gt 0 ]]; do
if [[ "$1" == --extract-certificates ]]; then
printf 'public certificate fixture\n' > "$2"0
exit 0
fi
case "$1" in
--extract-certificates=*)
certificate_prefix="${1#*=}"
printf 'public certificate fixture\n' > "${certificate_prefix}0"
exit 0
;;
--extract-certificates)
echo "Certificate prefix must use --extract-certificates=<prefix>." >&2
exit 75
;;
esac
shift
done
elif [[ "$*" == *"-dvvv"* ]]; then
Expand Down
5 changes: 3 additions & 2 deletions Packaging/DeveloperID/verify_release_artifact.sh
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ set -euo pipefail

ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
source "$ROOT_DIR/script/disk_image_tools.sh"
source "$ROOT_DIR/Packaging/DeveloperID/codesign_details.sh"
DMG_PATH=""
MANIFEST_PATH=""
PHASE=""
Expand Down Expand Up @@ -120,7 +121,7 @@ signature_fingerprint() {
local fingerprint
certificate_dir="$(mktemp -d "${TMPDIR:-/tmp}/codebase-combiner-signature-certificates.XXXXXX")"
certificate_prefix="$certificate_dir/certificate-"
if ! codesign -d --extract-certificates "$certificate_prefix" "$artifact" >/dev/null 2>&1; then
if ! codesign -d --extract-certificates="$certificate_prefix" "$artifact" >/dev/null 2>&1; then
rm -rf "$certificate_dir"
echo "Unable to extract the public signing certificate from $artifact." >&2
return 1
Expand Down Expand Up @@ -203,7 +204,7 @@ if [[ "$SIGNING_MODE" == developer-id ]]; then
codesign -dvvv "$MOUNTED_APP" >/dev/null 2> "$app_details"
grep -F 'Authority=Developer ID Application:' "$app_details" >/dev/null
grep -F "TeamIdentifier=$TEAM_ID" "$app_details" >/dev/null
grep -E '^flags=.*runtime' "$app_details" >/dev/null
codesign_details_has_hardened_runtime "$app_details"
grep -F 'Timestamp=' "$app_details" >/dev/null
rm -f "$app_details"
fi
Expand Down