From faf4230ffdbf15ed963b040bab3a036e0102054c Mon Sep 17 00:00:00 2001 From: Beq Date: Thu, 3 Oct 2024 21:14:49 +0100 Subject: [PATCH 1/7] make sure the output step is correctly named --- .github/workflows/sign.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/sign.yml b/.github/workflows/sign.yml index b3ea7d23d7..0679c4f4dd 100644 --- a/.github/workflows/sign.yml +++ b/.github/workflows/sign.yml @@ -62,7 +62,7 @@ jobs: runs-on: ubuntu-latest strategy: matrix: - file: ${{ fromJson( needs.find-find-setup-files.outputs.setup_files) }} + file: ${{ fromJson( needs.find-setup-files.outputs.setup_files) }} steps: - name: Upload unsigned artifact id: upload-unsigned-artifact From b1abf5b82eb6f0e066d72a9d2d5bcb9d4b9a7f53 Mon Sep 17 00:00:00 2001 From: Beq Date: Thu, 3 Oct 2024 21:24:30 +0100 Subject: [PATCH 2/7] Fix incorrect output reference --- .github/workflows/sign.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/sign.yml b/.github/workflows/sign.yml index 0679c4f4dd..c7abd29e76 100644 --- a/.github/workflows/sign.yml +++ b/.github/workflows/sign.yml @@ -38,7 +38,7 @@ jobs: actions: read contents: read outputs: - setup_files: ${{ steps.get-files.output.setup_files }} + setup_files: ${{ steps.get-files.outputs.setup_files }} steps: - name: Download Build Artifacts uses: dawidd6/action-download-artifact@v6 From 887a2b87e7196beeba7d9d87defa35551e03dac2 Mon Sep 17 00:00:00 2001 From: Beq Date: Thu, 3 Oct 2024 21:30:57 +0100 Subject: [PATCH 3/7] We need to upload the individual files --- .github/workflows/sign.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/sign.yml b/.github/workflows/sign.yml index c7abd29e76..ea1c76bf9a 100644 --- a/.github/workflows/sign.yml +++ b/.github/workflows/sign.yml @@ -69,7 +69,7 @@ jobs: uses: actions/upload-artifact@v4 with: name: unsigned-artifact - path: ./to_sign + path: ${{ matrix.file }} - name: sign uses: signpath/github-action-submit-signing-request@v1 env: From 03c946d80a947fa8ad909bfe71dfa115e54dd9c2 Mon Sep 17 00:00:00 2001 From: Beq Date: Thu, 3 Oct 2024 21:57:44 +0100 Subject: [PATCH 4/7] Can't pass folders between jobs, pass as artifacts instead --- .github/workflows/sign.yml | 32 ++++++++++++++++++++++++++------ 1 file changed, 26 insertions(+), 6 deletions(-) diff --git a/.github/workflows/sign.yml b/.github/workflows/sign.yml index ea1c76bf9a..60af7274bc 100644 --- a/.github/workflows/sign.yml +++ b/.github/workflows/sign.yml @@ -53,9 +53,19 @@ jobs: id: get-files shell: bash run: | + mkdir -p setup_exe_files files=$(find artifacts -type f -name '*Setup.exe') - files_json=$(printf '%s\n' "$files" | jq -R . | jq -s -c .) + for file in $files; do + basename=$(basename "$file") + cp "$file" "setup_exe_files/$basename" + done + files_json=$(ls setup_exe_files | jq -R . | jq -s -c .) echo "setup_files=$files_json" >> $GITHUB_OUTPUT + - name: Upload Setup.exe Files + uses: actions/upload-artifact@v4 + with: + name: setup-exe-files + path: setup_exe_files/ sign-and-upload: name: Sign and Upload each Setup.exe needs: find-setup-files @@ -64,13 +74,23 @@ jobs: matrix: file: ${{ fromJson( needs.find-setup-files.outputs.setup_files) }} steps: + - name: Download Setup.exe Files Artifact + uses: actions/download-artifact@v3 + with: + name: setup-exe-files + path: setup_exe_files + - name: Prepare File for Signing + run: | + mkdir -p to_sign + cp "setup_exe_files/${{ matrix.file }}" to_sign/ - name: Upload unsigned artifact id: upload-unsigned-artifact - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v3 with: - name: unsigned-artifact - path: ${{ matrix.file }} - - name: sign + name: unsigned-artifact-${{ matrix.file }} + path: to_sign/ + + - name: sign the file uses: signpath/github-action-submit-signing-request@v1 env: SIGNPATH_SIGNING_POLICY_SLUG: ${{ github.event.inputs.policy == 'Test' && vars.SIGNPATH_SIGNING_POLICY_SLUG_TEST || vars.SIGNPATH_SIGNING_POLICY_SLUG_RELEASE }} @@ -86,5 +106,5 @@ jobs: - name: Upload signed artifact uses: actions/upload-artifact@v4 with: - name: signed-artifact + name: signed-artifact-${{ matrix.file }} path: ./application-signed \ No newline at end of file From 08ba77873e5c2438ca28b316ed30b13526710647 Mon Sep 17 00:00:00 2001 From: Beq Date: Thu, 3 Oct 2024 22:28:14 +0100 Subject: [PATCH 5/7] tweak permissions to hopefully enable artifact access. --- .github/workflows/sign.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/sign.yml b/.github/workflows/sign.yml index 60af7274bc..151283c0d4 100644 --- a/.github/workflows/sign.yml +++ b/.github/workflows/sign.yml @@ -73,6 +73,9 @@ jobs: strategy: matrix: file: ${{ fromJson( needs.find-setup-files.outputs.setup_files) }} + permissions: + actions: read + contents: read steps: - name: Download Setup.exe Files Artifact uses: actions/download-artifact@v3 From ab31e68b6c1b3d36143b8675f058b3a0795b2da2 Mon Sep 17 00:00:00 2001 From: Beq Date: Thu, 3 Oct 2024 23:05:21 +0100 Subject: [PATCH 6/7] why can't the second job see the artifacts from the first? --- .github/workflows/sign.yml | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/.github/workflows/sign.yml b/.github/workflows/sign.yml index 151283c0d4..797425df15 100644 --- a/.github/workflows/sign.yml +++ b/.github/workflows/sign.yml @@ -77,8 +77,15 @@ jobs: actions: read contents: read steps: + - name: List Available Artifacts + run: | + echo "Available artifacts:" + curl -H "Authorization: token ${{ secrets.GITHUB_TOKEN }}" \ + -H "Accept: application/vnd.github.v3+json" \ + https://api.github.com/repos/${{ github.repository }}/actions/runs/${{ github.run_id }}/artifacts + - name: Download Setup.exe Files Artifact - uses: actions/download-artifact@v3 + uses: actions/download-artifact@v4 with: name: setup-exe-files path: setup_exe_files @@ -88,7 +95,7 @@ jobs: cp "setup_exe_files/${{ matrix.file }}" to_sign/ - name: Upload unsigned artifact id: upload-unsigned-artifact - uses: actions/upload-artifact@v3 + uses: actions/upload-artifact@v4 with: name: unsigned-artifact-${{ matrix.file }} path: to_sign/ From 57f8c6ad1808873e011c6f3fec457571a7b7f859 Mon Sep 17 00:00:00 2001 From: Beq Date: Thu, 3 Oct 2024 23:08:21 +0100 Subject: [PATCH 7/7] fix indentation --- .github/workflows/sign.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/sign.yml b/.github/workflows/sign.yml index 797425df15..9d300f8c13 100644 --- a/.github/workflows/sign.yml +++ b/.github/workflows/sign.yml @@ -77,7 +77,7 @@ jobs: actions: read contents: read steps: - - name: List Available Artifacts + - name: List Available Artifacts run: | echo "Available artifacts:" curl -H "Authorization: token ${{ secrets.GITHUB_TOKEN }}" \