File: SignFile.cmake

package info (click to toggle)
libvbz-hdf-plugin 1.0.2-3.1
  • links: PTS, VCS
  • area: main
  • in suites: forky, sid, trixie
  • size: 8,384 kB
  • sloc: cpp: 28,289; python: 392; ansic: 40; sh: 21; makefile: 19; xml: 16
file content (61 lines) | stat: -rw-r--r-- 1,862 bytes parent folder | download | duplicates (2)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
set(file_to_sign ${CMAKE_ARGV3})

# Pull from command line by default - otherwise require an environment variable.
if (NOT MINKNOW_CODE_SIGN_IDENTITY)
    if ("$ENV{MINKNOW_CODE_SIGN_IDENTITY}" STREQUAL "")
        message(FATAL_ERROR "Caller must specify code sign identiyy in environment variable 'MINKNOW_CODE_SIGN_IDENTITY'")
    endif()

    set(MINKNOW_CODE_SIGN_IDENTITY "$ENV{MINKNOW_CODE_SIGN_IDENTITY}")
endif()

if (APPLE)
    message("Signing file... ${file_to_sign}${keychain_comment}")
    set(SIGN_COMMAND 
        codesign -s ${MINKNOW_CODE_SIGN_IDENTITY} ${keychain_arg} --force --deep -vvvv ${file_to_sign})
elseif(WIN32)
    find_program(
        SIGNTOOL_EXE "Signtool.exe"
        PATHS "C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit")

    if (NOT SIGNTOOL_EXE)
        message(FATAL_ERROR "Failed to find signtool executable")
    endif()

    message("Signing file... ${file_to_sign}${comment}")
    set(SIGN_COMMAND ${SIGNTOOL_EXE} sign "/v" "/sha1" "${MINKNOW_CODE_SIGN_IDENTITY}"
        "/tr" "http://rfc3161timestamp.globalsign.com/advanced"
        "/td" "SHA256"
        ${file_to_sign}
    )

else()
    message(FATAL_ERROR "Cannot sign code on this platform.")
endif()

set(retry_count 10)
foreach(retry_index RANGE ${retry_count})
    message("Running sign command: ${SIGN_COMMAND}")
    execute_process(
        COMMAND ${SIGN_COMMAND}
        RESULT_VARIABLE result
        OUTPUT_VARIABLE output
        ERROR_VARIABLE output
    )

    if (result EQUAL 0)
        break()
    endif()

    message(WARN "Signing failed, waiting and retrying (${retry_index}/${retry_count})")
    execute_process(
        COMMAND ${CMAKE_COMMAND} -E sleep 5
    )

endforeach()

if (NOT result EQUAL 0)
    message(FATAL_ERROR "Could not sign file: ${result}: ${output}")
else()
    message("Signed file: ${output}")
endif()