Skip to content

Commit

Permalink
DO NOT MERGE - Test signingscript rcodesign
Browse files Browse the repository at this point in the history
  • Loading branch information
hneiva committed Dec 6, 2023
1 parent c94d9b5 commit fac73a7
Show file tree
Hide file tree
Showing 27 changed files with 54 additions and 292 deletions.
12 changes: 0 additions & 12 deletions signing-manifests/2023-new-gpg-subkey-test.yml

This file was deleted.

12 changes: 0 additions & 12 deletions signing-manifests/bug1751450-nsis-core-ansi.yml

This file was deleted.

12 changes: 0 additions & 12 deletions signing-manifests/bug1751450-nsis-core-unicode.yml

This file was deleted.

12 changes: 0 additions & 12 deletions signing-manifests/bug1751450.yml

This file was deleted.

12 changes: 0 additions & 12 deletions signing-manifests/bug1763427b.yml

This file was deleted.

11 changes: 0 additions & 11 deletions signing-manifests/bug1769081.yml

This file was deleted.

12 changes: 0 additions & 12 deletions signing-manifests/bug1774221-2.yml

This file was deleted.

12 changes: 0 additions & 12 deletions signing-manifests/bug1774221-3.yml

This file was deleted.

15 changes: 0 additions & 15 deletions signing-manifests/bug1774221.yml

This file was deleted.

13 changes: 0 additions & 13 deletions signing-manifests/bug1778996.yml

This file was deleted.

12 changes: 0 additions & 12 deletions signing-manifests/bug1799220.yml

This file was deleted.

13 changes: 0 additions & 13 deletions signing-manifests/bug1808742-rm-distribution-mar.yml

This file was deleted.

13 changes: 0 additions & 13 deletions signing-manifests/bug1835022-2.yml

This file was deleted.

13 changes: 0 additions & 13 deletions signing-manifests/bug1835022-3.yml

This file was deleted.

13 changes: 0 additions & 13 deletions signing-manifests/bug1835022.yml

This file was deleted.

13 changes: 0 additions & 13 deletions signing-manifests/bug1843034-2.yml

This file was deleted.

13 changes: 0 additions & 13 deletions signing-manifests/bug1843034.yml

This file was deleted.

14 changes: 0 additions & 14 deletions signing-manifests/mozregression-macOS.yml

This file was deleted.

12 changes: 0 additions & 12 deletions signing-manifests/mozregression-windows.yml

This file was deleted.

33 changes: 22 additions & 11 deletions signing-manifests/test-mac-hardened-sign.yml
Original file line number Diff line number Diff line change
@@ -1,53 +1,64 @@
---
bug: 0000000
sha256: 5b95d1a32ca449970e49d7a85a8a88294de31ec427e8b6616098b088aeea5ee7
filesize: 80945464
sha256: 68527bbca7bf226febbe0d308594740dc45175e37440566cff219b532af068db
filesize: 112748218
private-artifact: false
signing-formats: ["macapp", "autograph_widevine", "autograph_omnija"]
requestor: Haik Aftandilian <[email protected]>
signing-formats:
- apple_hardened_signing
- autograph_widevine
- autograph_omnija
requestor: Heitor Neiva <[email protected]>
reason: Firefox hardened signing per-process entitlements
product: firefox
artifact-name: target.dmg
mac-behavior: mac_sign_and_pkg_hardened
signingscript-notarization: true
sign-tool: rcodesign
provisioning-profile-config:
- profile_name: "orgmozillanightly.provisionprofile"
target_path: "/Contents/embedded.provisionprofile"
hardened-sign-config:
- deep: false
runtime: true
force: true
entitlements: https://hg.mozilla.org/try/raw-file/722d4a7887b701cdef7b8ff81d0273985adada6a/security/mac/hardenedruntime/v2/production/plugin-container.xml
entitlements: https://hg.mozilla.org/try/raw-file/tip/security/mac/hardenedruntime/v2/developer/plugin-container.xml
globs:
- "/Contents/MacOS/plugin-container.app"

- deep: false
runtime: true
force: true
entitlements: https://hg.mozilla.org/try/raw-file/722d4a7887b701cdef7b8ff81d0273985adada6a/security/mac/hardenedruntime/v2/production/media-plugin-helper.xml
entitlements: https://hg.mozilla.org/try/raw-file/tip/security/mac/hardenedruntime/v2/developer/media-plugin-helper.xml
globs:
- "/Contents/MacOS/media-plugin-helper.app"

- deep: false
runtime: true
force: true
entitlements: https://hg.mozilla.org/try/raw-file/722d4a7887b701cdef7b8ff81d0273985adada6a/security/mac/hardenedruntime/v2/production/default.xml
entitlements: https://hg.mozilla.org/try/raw-file/tip/security/mac/hardenedruntime/v2/developer/utility.xml
globs:
- "/Contents/MacOS/crashreporter.app"
- "/Contents/MacOS/updater.app"
- "/Contents/Library/LaunchServices/org.mozilla.updater"
- "/Contents/MacOS/XUL"
- "/Contents/MacOS/pingsender"
- "/Contents/MacOS/minidump-analyzer"

- deep: false
runtime: true
force: true
globs:
- "/Contents/MacOS/XUL"
- "/Contents/MacOS/*.dylib"
- "/Contents/Resources/gmp-clearkey/*/*.dylib"

- deep: false
runtime: true
force: true
entitlements: https://hg.mozilla.org/try/raw-file/722d4a7887b701cdef7b8ff81d0273985adada6a/security/mac/hardenedruntime/v2/production/browser.xml
entitlements: https://hg.mozilla.org/try/raw-file/tip/security/mac/hardenedruntime/v2/developer/browser.xml
globs:
- "/Contents/MacOS/firefox-bin"
- "/"

fetch:
type: static-url
# mozilla-release OS X AArch64 Cross Compiled Shippable
url: https://firefox-ci-tc.services.mozilla.com/api/queue/v1/task/LjKBrB4WTiOpm_2A0ljKDQ/runs/0/artifacts/public%2Fbuild%2Ftarget.dmg
url: https://firefox-ci-tc.services.mozilla.com/api/queue/v1/task/W72c65ebTiua43cljitiFw/runs/0/artifacts/public%2Fbuild%2Ftarget.dmg
14 changes: 0 additions & 14 deletions signing-manifests/test-mac.yml

This file was deleted.

16 changes: 0 additions & 16 deletions signing-manifests/test-notarization-signingscript.yml

This file was deleted.

12 changes: 10 additions & 2 deletions taskcluster/adhoc_taskgraph/signing_manifest.py
Original file line number Diff line number Diff line change
Expand Up @@ -27,8 +27,9 @@
"autograph_authenticode_sha2_rfc3161_stub",
"autograph_hash_only_mar384",
"macapp",
"apple_hardened_signing",
"mac_single_file",
"autograph_widevine",
"autograph_widevine",
"autograph_omnija",
)

Expand Down Expand Up @@ -61,9 +62,16 @@
},
),
Required("manifest_name"): str,
Optional("sign-tool"): str,
Optional("mac-behavior"): str,
Optional("signingscript-notarization"): bool,
Optional("hardened-sign-config"): [{str: object}],
Optional("hardened-sign-config"): [{str: str}],
Optional("provisioning-profile-config"): [
{
"profile_name": str,
"target_path": str,
}
],
Optional("product"): str,
Optional("single-file-globs"): [str],
}
Expand Down
Loading

0 comments on commit fac73a7

Please sign in to comment.