-
Notifications
You must be signed in to change notification settings - Fork 541
[msbuild] Improve ComputeCodesignItems to take symlinked directories into account. Fixes #20193. #22907
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
…into account. Fixes #20193. 1. There's no need to codesign a symlink, because: a. A symlink can only point to another file or directory inside the app bundle (not outside of it). b. That other file or directory should already be in the list of files to sign. 2. We're already skipping files and directories that are symlinks, but we weren't skipping normal files or directories inside a symlinked directory. This is now fixed. Example 1: MyBundle.app/Contents/Frameworks/XTest.framework/XTest -> MyBundle.app/Contents/Frameworks/XTest.framework/Versions/A/Resources/XTest This file (MyBundle.app/Contents/Frameworks/XTest.framework/XTest) was already not signed. Example 2: MyBundle.app/Contents/Frameworks/XTest.framework/Libraries -> MyBundle.app/Contents/Frameworks/XTest.framework/Versions/A/Libraries MyBundle.app/Contents/Frameworks/XTest.framework/Versions/A/Libraries/libTest.dylib Here we'd find 'libTest.dylib' twice, once inside 'MyBundle.app/Contents/Frameworks/XTest.framework/Libraries', and once inside 'MyBundle.app/Contents/Frameworks/XTest.framework/Versions/A/Libraries'. The algorithm has been changed to not recurse into directories that are symlinks, so with this fix we'll no longer find 'MyBundle.app/Contents/Frameworks/XTest.framework/Libraries/libTest.dylib'. Fixes #20193.
✅ [PR Build #c95f56c] Build passed (Detect API changes) ✅Pipeline on Agent |
✅ API diff for current PR / commit.NET ( No breaking changes )✅ API diff vs stable.NET ( No breaking changes )ℹ️ Generator diffGenerator Diff: vsdrops (html) vsdrops (raw diff) gist (raw diff) - Please review changes) Pipeline on Agent |
✅ [CI Build #c95f56c] Build passed (Build packages) ✅Pipeline on Agent |
✅ [CI Build #c95f56c] Build passed (Build macOS tests) ✅Pipeline on Agent |
💻 [CI Build #c95f56c] Tests on macOS X64 - Mac Sonoma (14) passed 💻✅ All tests on macOS X64 - Mac Sonoma (14) passed. Pipeline on Agent |
💻 [CI Build #c95f56c] Tests on macOS M1 - Mac Monterey (12) passed 💻✅ All tests on macOS M1 - Mac Monterey (12) passed. Pipeline on Agent |
💻 [CI Build #c95f56c] Tests on macOS arm64 - Mac Sequoia (15) passed 💻✅ All tests on macOS arm64 - Mac Sequoia (15) passed. Pipeline on Agent |
💻 [CI Build #c95f56c] Tests on macOS M1 - Mac Ventura (13) passed 💻✅ All tests on macOS M1 - Mac Ventura (13) passed. Pipeline on Agent |
🚀 [CI Build #c95f56c] Test results 🚀Test results✅ All tests passed on VSTS: test results. 🎉 All 115 tests passed 🎉 Tests counts✅ cecil: All 1 tests passed. Html Report (VSDrops) Download Pipeline on Agent |
a. A symlink can only point to another file or directory inside the app
bundle (not outside of it).
b. That other file or directory should already be in the list of files to sign.
weren't skipping normal files or directories inside a symlinked directory.
This is now fixed.
Example 1:
This file (MyBundle.app/Contents/Frameworks/XTest.framework/XTest) was already not signed.
Example 2:
Here we'd find 'libTest.dylib' twice, once inside
'MyBundle.app/Contents/Frameworks/XTest.framework/Libraries', and once inside
'MyBundle.app/Contents/Frameworks/XTest.framework/Versions/A/Libraries'.
The algorithm has been changed to not recurse into directories that are
symlinks, so with this fix we'll no longer find
'MyBundle.app/Contents/Frameworks/XTest.framework/Libraries/libTest.dylib'.
Fixes #20193.