Skip to content

Commit 3f03fc9

Browse files
committed
Split signing process from building
1 parent 45c4774 commit 3f03fc9

3 files changed

Lines changed: 197 additions & 46 deletions

File tree

‎.github/workflows/build.yml‎

Lines changed: 66 additions & 30 deletions
Original file line numberDiff line numberDiff line change
@@ -168,7 +168,7 @@ jobs:
168168
if: runner.os == 'Windows'
169169
shell: pwsh
170170
run: |
171-
Copy-Item "build/Release/sine-win-$env:ARCH.exe" -Destination "unsigned/sine-installer.exe"
171+
Copy-Item "build/Release/sine-win-$env:ARCH.exe" -Destination "unsigned/sine-win-$env:ARCH-unsigned.exe"
172172
env:
173173
ARCH: ${{ matrix.arch }}
174174

@@ -178,49 +178,85 @@ jobs:
178178
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
179179
with:
180180
name: sine-win-${{ matrix.arch }}-unsigned
181-
path: unsigned/sine-installer.exe
181+
path: unsigned/sine-win-${{ matrix.arch }}-unsigned.exe
182182

183-
- name: Submit signing request
184-
if: matrix.os == 'windows'
185-
uses: signpath/github-action-submit-signing-request@b9d91eadd323de506c0c81cf0c7fe7438f3360fd # v2.2
183+
- name: Upload Linux executable
184+
if: matrix.os == 'linux'
185+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
186186
with:
187-
api-token: "${{ secrets.SIGNPATH_API_TOKEN }}"
188-
organization-id: "1324b51a-cb3d-4d1e-aab7-27b1169bd402"
189-
project-slug: "Sine"
190-
signing-policy-slug: "release-signing"
191-
github-artifact-id: "${{ steps.upload-unsigned-artifact.outputs.artifact-id }}"
192-
wait-for-completion: true
193-
output-artifact-directory: "artifacts"
187+
name: sine-linux-${{ matrix.arch }}
188+
path: artifacts/sine-linux-${{ matrix.arch }}
194189

195-
- name: Rename Windows signed artifact
196-
if: matrix.os == 'windows'
197-
shell: bash
198-
run: mv "artifacts/sine-installer.exe" "artifacts/sine-win-${ARCH}.exe"
190+
- name: Upload macOS executable
191+
if: matrix.os == 'macos'
192+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
193+
with:
194+
name: sine-osx-${{ matrix.arch }}
195+
path: artifacts/sine-osx-${{ matrix.arch }}
196+
197+
post-build:
198+
runs-on: ubuntu-latest
199+
name: Handle post-build steps
200+
steps:
201+
- name: Check signing requirements
202+
id: status
199203
env:
200-
ARCH: ${{ matrix.arch }}
204+
REF_NAME: ${{ github.ref_name }}
205+
run: |
206+
if [[ "$REF_NAME" == "main" ]]; then
207+
echo "should-sign=yes" >> $GITHUB_OUTPUT
208+
else
209+
echo "should-sign=no" >> $GITHUB_OUTPUT
210+
fi
211+
212+
- name: Download all artifacts
213+
if: steps.status.outputs.should-sign == 'yes'
214+
uses: actions/download-artifact@v8
201215

202216
- name: Attest artifacts
203217
uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0
204218
with:
205219
subject-path: artifacts/*
206220

207-
- name: Upload Windows executable
208-
if: matrix.os == 'windows'
209-
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
221+
- name: Attest unsigned executables
222+
uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0
210223
with:
211-
name: sine-win-${{ matrix.arch }}
212-
path: artifacts/sine-win-${{ matrix.arch }}.exe
224+
subject-path: unsigned/*
213225

214-
- name: Upload Linux executable
215-
if: matrix.os == 'linux'
226+
- name: Upload Windows artifacts (for code signing)
227+
if: steps.status.outputs.should-sign == 'yes'
228+
id: upload-unsigned-zip
216229
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
217230
with:
218-
name: sine-linux-${{ matrix.arch }}
219-
path: artifacts/sine-linux-${{ matrix.arch }}
231+
name: sine-package-for-signing
232+
path: ./unsigned
220233

221-
- name: Upload macOS executable
222-
if: matrix.os == 'macos'
234+
- name: Submit signing request
235+
if: steps.status.outputs.should-sign == 'yes'
236+
id: signpath-code-signing
237+
uses: signpath/github-action-submit-signing-request@b9d91eadd323de506c0c81cf0c7fe7438f3360fd # v2.2
238+
with:
239+
api-token: "${{ secrets.SIGNPATH_API_TOKEN }}"
240+
organization-id: "1324b51a-cb3d-4d1e-aab7-27b1169bd402"
241+
project-slug: "Sine"
242+
signing-policy-slug: "release-signing"
243+
github-artifact-id: "${{ steps.upload-unsigned-zip.outputs.artifact-id }}"
244+
wait-for-completion: false
245+
246+
- name: Save code signing info
247+
if: steps.status.outputs.should-sign == 'yes'
248+
run: |
249+
mkdir -p artifacts/info
250+
cp repo-info/* artifacts/info
251+
252+
echo "${{ steps.signpath-code-signing.outputs.signing-request-id }}" \
253+
| tee artifacts/info/signing-request-id.txt
254+
echo "${{ steps.signpath-code-signing.outputs.signing-request-web-url }}" \
255+
| tee artifacts/info/signing-request-web-url.txt
256+
257+
- name: Upload Artifact (signing info)
258+
if: steps.status.outputs.should-sign == 'yes'
223259
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
224260
with:
225-
name: sine-osx-${{ matrix.arch }}
226-
path: artifacts/sine-osx-${{ matrix.arch }}
261+
name: info
262+
path: ./artifacts/info

‎.github/workflows/release.yml‎

Lines changed: 42 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,10 @@ on:
1111
type: number
1212
description: "Version type (0: normal, 1: abnormal, 2: bootloader, see docs/updates.md)"
1313
required: true
14+
run_id:
15+
description: "GitHub Actions run_id when created the corresponding release"
16+
required: false
17+
type: string
1418

1519
permissions:
1620
id-token: write
@@ -114,43 +118,65 @@ jobs:
114118
subject-path: artifacts/*
115119

116120
- name: Trigger build workflow
121+
if: steps.extract_branch.outputs.suffix == 'c'
117122
id: build_job
118123
uses: benc-uk/workflow-dispatch@31e2b3319479a63f0ab15bf800eff9e913504e26 # v1.3.2
119124
with:
120125
workflow: build.yml
121126
inputs: '{ "sine_version": "${{ steps.format_inputs.outputs.sine_version }}", "boot_version": "${{ steps.format_inputs.outputs.boot_version }}" }'
122127
wait-for-completion: true
123128

129+
- name: Trigger upload workflow
130+
if: steps.extract_branch.outputs.suffix != 'c'
131+
id: build_job
132+
uses: benc-uk/workflow-dispatch@31e2b3319479a63f0ab15bf800eff9e913504e26 # v1.3.2
133+
with:
134+
workflow: upload-signed-files.yml
135+
inputs: '{ "run_id": "${{ inputs.run_id }}" }'
136+
wait-for-completion: true
137+
124138
- name: Download artifacts
125139
env:
126140
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
127141
RUN_ID: ${{ steps.build_job.outputs.runId }}
142+
INPUT_RUN_ID: ${{ inputs.run_id }}
128143
run: |
129144
gh run download $RUN_ID -D build/
130145
146+
if [[ "$INPUT_RUN_ID" != "" ]]; then
147+
gh run download $INPUT_RUN_ID -D build/
148+
fi
149+
131150
- name: Organize and verify artifacts
132151
env:
133152
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
134153
run: |
135-
for folder in build/*/; do
136-
[ -d "$folder" ] || continue
137-
file=$(find "$folder" -maxdepth 1 -type f)
154+
if [ -d "build/signed-package" ]; then
155+
echo "Signed package detected. Cleaning out old unsigned binaries..."
156+
rm -rf build/sine-win-*-unsigned/
157+
fi
158+
159+
find build/ -type f ! -path "*/info/*" -exec mv {} artifacts/ \;
160+
find build/ -type d -empty -delete
161+
162+
for file in artifacts/*; do
163+
[ -f "$file" ] || continue
138164
filename=$(basename "$file")
139-
foldername=$(basename "$folder")
140-
141-
if [ "$filename" = "$foldername" ]; then
142-
extension="${filename##*.}"
143-
tempname="${foldername}_file.$extension"
144-
mv "$file" "artifacts/$tempname"
145-
rmdir "$folder"
146-
mv "artifacts/$tempname" "artifacts/$filename"
147-
else
148-
mv "$file" artifacts/
149-
rmdir "$folder"
165+
166+
if [[ "$filename" == *"-unsigned.exe" ]]; then
167+
new_name="${file/-unsigned/}"
168+
mv "$file" "$new_name"
169+
file="$new_name"
170+
filename=$(basename "$file")
150171
fi
151172
152-
gh attestation verify "artifacts/$filename" --repo CosmoCreeper/Sine
153-
echo "Processed 'artifacts/$filename' properly"
173+
if [[ "$filename" =~ ^sine-(linux|osx|win)- ]]; then
174+
gh attestation verify "$file" --repo CosmoCreeper/Sine
175+
echo "Processed and verified 'artifacts/$filename' properly"
176+
else
177+
echo "Removing unwanted artifact asset: $filename"
178+
rm -f "$file"
179+
fi
154180
done
155181
156182
- name: Upload artifacts to draft release
Lines changed: 89 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,89 @@
1+
name: Upload signed executables
2+
3+
on:
4+
workflow_dispatch:
5+
inputs:
6+
run_id:
7+
description: "GitHub Actions run_id when created the corresponding release"
8+
required: true
9+
type: string
10+
11+
permissions:
12+
id-token: write
13+
attestations: write
14+
15+
jobs:
16+
download:
17+
runs-on: ubuntu-latest
18+
steps:
19+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
20+
21+
- name: Download build info
22+
shell: bash
23+
env:
24+
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
25+
RUN_ID: ${{ inputs.run_id }}
26+
run: gh run download "${RUN_ID}" --name "info" --dir info
27+
28+
- name: Download signed files
29+
shell: bash
30+
timeout-minutes: 10
31+
env:
32+
SIGNPATH_API_TOKEN: ${{ secrets.SIGNPATH_API_TOKEN }}
33+
ORGANIZATION_ID: 1324b51a-cb3d-4d1e-aab7-27b1169bd402
34+
run: |
35+
SIGNING_REQUEST_ID=$(cat info/signing-request-id.txt)
36+
REQUEST_URL=https://app.signpath.io/API/v1/${ORGANIZATION_ID}/SigningRequests/${SIGNING_REQUEST_ID}
37+
38+
# Check SignPath status
39+
status=InProgress
40+
while [ "$status" = "InProgress" ]; do
41+
status=$(curl -f --silent -H "Authorization: Bearer ${SIGNPATH_API_TOKEN}" ${REQUEST_URL} \
42+
| jq -r .status)
43+
44+
echo "SignPath status: $status"
45+
case "$status" in
46+
WaitingForApproval)
47+
echo "Not approved yet. Approve it first:"
48+
cat info/signing-request-web-url.txt
49+
exit 1
50+
;;
51+
InProgress)
52+
;;
53+
Completed)
54+
break
55+
;;
56+
*)
57+
exit 1
58+
;;
59+
esac
60+
61+
sleep 10
62+
done
63+
64+
# Download the signed files
65+
curl -f -H "Authorization: Bearer ${SIGNPATH_API_TOKEN}" \
66+
-o package.zip \
67+
${REQUEST_URL}/SignedArtifact
68+
unzip package.zip -d package
69+
70+
rm -f package/*_pdb.*
71+
72+
for i in package/sine-win-*-unsigned.exe; do
73+
[ -f "$i" ] || continue
74+
mv "$i" "${i/-unsigned/}"
75+
done
76+
77+
ls -l package
78+
79+
- name: Upload signed executables
80+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
81+
with:
82+
name: signed-package
83+
path: |
84+
./package/*
85+
86+
- name: Attest
87+
uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0
88+
with:
89+
subject-path: ./package/*

0 commit comments

Comments
 (0)