-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathMakefile
More file actions
84 lines (82 loc) · 4.74 KB
/
Copy pathMakefile
File metadata and controls
84 lines (82 loc) · 4.74 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
WINDOWS_CERT_DIR ?= certs/win
WINDOWS_CERT_NAME ?= ChatGPT Multitab Local Code Signing
WINDOWS_CERT_PFX ?= $(WINDOWS_CERT_DIR)/chatgpt-multitab-code-signing.pfx
WINDOWS_CERT_PASSWORD_FILE ?= $(WINDOWS_CERT_DIR)/chatgpt-multitab-code-signing.password.txt
WINDOWS_SIGN_EXE ?=
WINDOWS_SIGN_TIMESTAMP_URL ?= http://timestamp.digicert.com
.PHONY: windows-code-sign-cert
windows-code-sign-cert:
@mkdir -p "$(WINDOWS_CERT_DIR)"
@powershell.exe -NoProfile -ExecutionPolicy Bypass -Command "\
\$$ErrorActionPreference = 'Stop'; \
\$$certPath = '$(WINDOWS_CERT_PFX)'; \
\$$passwordPath = '$(WINDOWS_CERT_PASSWORD_FILE)'; \
if (Test-Path \$$certPath) { throw \"Certificate already exists: \$$certPath\" }; \
if (Test-Path \$$passwordPath) { throw \"Password file already exists: \$$passwordPath\" }; \
\$$passwordBytes = New-Object byte[] 32; \
[System.Security.Cryptography.RandomNumberGenerator]::Create().GetBytes(\$$passwordBytes); \
\$$password = [Convert]::ToBase64String(\$$passwordBytes); \
\$$securePassword = ConvertTo-SecureString -String \$$password -Force -AsPlainText; \
\$$cert = New-SelfSignedCertificate \
-Type CodeSigningCert \
-Subject 'CN=$(WINDOWS_CERT_NAME)' \
-CertStoreLocation 'Cert:\CurrentUser\My' \
-KeyExportPolicy Exportable \
-KeySpec Signature \
-KeyLength 2048 \
-KeyAlgorithm RSA \
-HashAlgorithm SHA256 \
-NotAfter (Get-Date).AddYears(3); \
Export-PfxCertificate -Cert \$$cert -FilePath \$$certPath -Password \$$securePassword | Out-Null; \
Set-Content -Path \$$passwordPath -Value \$$password -NoNewline; \
Write-Host \"Created \$$certPath\"; \
Write-Host \"Saved password in \$$passwordPath\"; \
Write-Host \"Use for Windows packaging:\"; \
Write-Host \" CSC_LINK=\$$certPath CSC_KEY_PASSWORD=\$$password npm run dist:win\"; \
"
.PHONY: windows-sign-exe
windows-sign-exe:
@powershell.exe -NoProfile -ExecutionPolicy Bypass -Command "\
\$$ErrorActionPreference = 'Stop'; \
\$$requestedExe = '$(WINDOWS_SIGN_EXE)'; \
\$$certPath = '$(WINDOWS_CERT_PFX)'; \
\$$passwordPath = '$(WINDOWS_CERT_PASSWORD_FILE)'; \
if (-not (Test-Path \$$certPath)) { throw \"Certificate not found: \$$certPath. Run make windows-code-sign-cert first.\" }; \
if (-not (Test-Path \$$passwordPath)) { throw \"Certificate password file not found: \$$passwordPath. Run make windows-code-sign-cert first.\" }; \
if (\$$requestedExe) { \
if (-not (Test-Path \$$requestedExe)) { throw \"Executable not found: \$$requestedExe\" }; \
\$$exePaths = @((Resolve-Path \$$requestedExe).Path); \
} else { \
\$$exePaths = @(Get-ChildItem 'dist' -Recurse -Filter '*.exe' | Select-Object -ExpandProperty FullName); \
if (\$$exePaths.Count -eq 0) { throw 'No .exe files found under dist. Run npm run dist:win first.' }; \
}; \
\$$password = Get-Content -Raw \$$passwordPath; \
\$$signtool = Get-Command signtool.exe -ErrorAction SilentlyContinue | Select-Object -ExpandProperty Source -First 1; \
\$$kitsRoot = Join-Path ([Environment]::GetEnvironmentVariable('ProgramFiles(x86)')) 'Windows Kits\10\bin'; \
if (-not \$$signtool -and (Test-Path \$$kitsRoot)) { \
\$$signtool = Get-ChildItem -Path \$$kitsRoot -Recurse -Filter signtool.exe | Sort-Object FullName -Descending | Select-Object -ExpandProperty FullName -First 1; \
}; \
\$$timestampUrl = '$(WINDOWS_SIGN_TIMESTAMP_URL)'; \
if (\$$signtool) { \
foreach (\$$exePath in \$$exePaths) { \
\$$args = @('sign', '/f', (Resolve-Path \$$certPath).Path, '/p', \$$password, '/fd', 'SHA256', '/v'); \
if (\$$timestampUrl) { \$$args += @('/tr', \$$timestampUrl, '/td', 'SHA256') }; \
\$$args += \$$exePath; \
& \$$signtool @args; \
if (\$$LASTEXITCODE -ne 0) { exit \$$LASTEXITCODE }; \
Write-Host \"Signed \$$exePath\"; \
}; \
} else { \
\$$subject = 'CN=$(WINDOWS_CERT_NAME)'; \
\$$cert = Get-ChildItem 'Cert:\CurrentUser\My' | Where-Object { \$$_.Subject -eq \$$subject -and \$$_.HasPrivateKey } | Sort-Object NotAfter -Descending | Select-Object -First 1; \
if (-not \$$cert) { throw \"Code signing certificate not found in Cert:\CurrentUser\My for \$$subject. Run make windows-code-sign-cert first.\" }; \
foreach (\$$exePath in \$$exePaths) { \
\$$signatureArgs = @{ FilePath = \$$exePath; Certificate = \$$cert; HashAlgorithm = 'SHA256' }; \
if (\$$timestampUrl) { \$$signatureArgs.TimestampServer = \$$timestampUrl }; \
\$$signature = Set-AuthenticodeSignature @signatureArgs; \
if (-not \$$signature.SignerCertificate) { throw \"Signing failed for \$${exePath}: \$$(\$$signature.Status) \$$(\$$signature.StatusMessage)\" }; \
if (\$$signature.Status -ne 'Valid') { Write-Warning \"Signed \$$exePath, but Windows reports: \$$(\$$signature.Status) \$$(\$$signature.StatusMessage)\" }; \
Write-Host \"Signed \$$exePath\"; \
}; \
}; \
"