mirror of
https://git.huckle.dev/Huckles-Minecraft-Archive/jpexs-decompiler.git
synced 2026-09-28 00:41:18 +00:00
New github actions
This commit is contained in:
@@ -0,0 +1,689 @@
|
||||
name: Build
|
||||
|
||||
concurrency:
|
||||
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
|
||||
cancel-in-progress: true
|
||||
|
||||
on:
|
||||
push:
|
||||
tags:
|
||||
- version*
|
||||
branches:
|
||||
- dev
|
||||
- master
|
||||
pull_request:
|
||||
branches:
|
||||
- dev
|
||||
- master
|
||||
|
||||
env:
|
||||
GITHUB_USER: jindrapetrik
|
||||
GITHUB_ACCESS_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
|
||||
permissions:
|
||||
id-token: write
|
||||
|
||||
jobs:
|
||||
compute-version:
|
||||
name: Compute version
|
||||
uses: ./.github/workflows/version.yml
|
||||
secrets: inherit
|
||||
|
||||
build:
|
||||
name: Build and test
|
||||
runs-on: windows-latest
|
||||
needs: compute-version
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v3
|
||||
|
||||
- name: Prepare version info property file
|
||||
shell: pwsh
|
||||
run: |
|
||||
$VERSION_PROP_FILE = "version.properties"
|
||||
echo "">$VERSION_PROP_FILE
|
||||
echo "major=${{ needs.compute-version.outputs.verMajor }}">>$VERSION_PROP_FILE
|
||||
echo "minor=${{ needs.compute-version.outputs.verMinor }}">>$VERSION_PROP_FILE
|
||||
echo "release=${{ needs.compute-version.outputs.verRelease }}">>$VERSION_PROP_FILE
|
||||
echo "build=${{ needs.compute-version.outputs.verBuild }}">>$VERSION_PROP_FILE
|
||||
echo "revision=${{ needs.compute-version.outputs.verRevision }}">>$VERSION_PROP_FILE
|
||||
echo "debug=${{ needs.compute-version.outputs.verDebug }}">>$VERSION_PROP_FILE
|
||||
|
||||
- name: Upload version.properties artifact
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: version_properties
|
||||
path: version.properties
|
||||
|
||||
- name: Set up JDK
|
||||
uses: actions/setup-java@v4
|
||||
with:
|
||||
distribution: adopt
|
||||
architecture: x64
|
||||
java-version: |
|
||||
8
|
||||
21
|
||||
|
||||
- name: Set Java 8
|
||||
shell: pwsh
|
||||
run: |
|
||||
echo "JAVA_HOME=$env:JAVA_HOME_8_X64" >> $env:GITHUB_ENV
|
||||
|
||||
- name: Set up Ant
|
||||
run: choco install ant -y
|
||||
|
||||
- name: Download version.properties artifact
|
||||
uses: actions/download-artifact@v4
|
||||
with:
|
||||
name: version_properties
|
||||
|
||||
- name: Copy version.properties to lib
|
||||
run: copy version.properties libsrc/ffdec_lib/
|
||||
|
||||
- name: Check style
|
||||
run: ant checkstyle
|
||||
|
||||
- name: Build and Test (Release)
|
||||
if: needs.compute-version.outputs.doRelease == 'true'
|
||||
run: ant new-version-set build test
|
||||
|
||||
- name: Build and Test (Private)
|
||||
if: needs.compute-version.outputs.doRelease == 'false'
|
||||
run: ant build test
|
||||
|
||||
- name: Set Java 21
|
||||
if: needs.compute-version.outputs.doRelease == 'true'
|
||||
shell: pwsh
|
||||
run: |
|
||||
echo "JAVA_HOME=$env:JAVA_HOME_21_X64" >> $env:GITHUB_ENV
|
||||
|
||||
- name: Javadoc
|
||||
if: needs.compute-version.outputs.doRelease == 'true'
|
||||
run: ant release_lib_javadoc
|
||||
|
||||
- name: Upload lib javadoc artifact
|
||||
if: needs.compute-version.outputs.doRelease == 'true'
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: lib_javadoc
|
||||
path: releases/ffdec_lib_javadoc_${{ needs.compute-version.outputs.verShort }}.zip
|
||||
|
||||
- name: Upload dist
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: dist
|
||||
path: dist/
|
||||
|
||||
- name: Upload lib dist
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: lib_dist
|
||||
path: libsrc/ffdec_lib/dist
|
||||
exe:
|
||||
name: Generate EXE
|
||||
runs-on: ubuntu-latest
|
||||
needs: compute-version
|
||||
if: needs.compute-version.outputs.doRelease == 'true'
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v3
|
||||
- name: Set up JDK
|
||||
uses: actions/setup-java@v4
|
||||
with:
|
||||
distribution: adopt
|
||||
architecture: x64
|
||||
java-version: 8
|
||||
|
||||
# Wine must be used since Windows runner cannot run Resource hacker
|
||||
- name: Install Wine
|
||||
run: |
|
||||
sudo dpkg --add-architecture i386
|
||||
sudo apt-get update -y -qq
|
||||
sudo apt-get install -y -qq wine
|
||||
|
||||
# We need to add fake virtual desktop as Resource Hacker is not pure commandline app
|
||||
- name: Set up Xorg
|
||||
run: |
|
||||
sudo apt-get install -y -qq xorg xvfb xfonts-100dpi xfonts-75dpi xfonts-scalable xfonts-cyrillic
|
||||
- name: Install Resource Hacker
|
||||
env:
|
||||
RH_DIR: tools/wine/resourcehacker
|
||||
RH_ZIP: tools/wine/resourcehacker.zip
|
||||
RH_URL: https://www.angusj.com/resourcehacker/resource_hacker.zip
|
||||
run: |
|
||||
set -euxo pipefail
|
||||
|
||||
sudo apt-get install -y -qq unzip wget
|
||||
|
||||
mkdir -p "$(dirname "$RH_ZIP")"
|
||||
mkdir -p "$RH_DIR"
|
||||
|
||||
wget -q -O "$RH_ZIP" "$RH_URL"
|
||||
unzip -o "$RH_ZIP" -d "$RH_DIR"
|
||||
|
||||
- name: Generate EXE splash screen
|
||||
run: |
|
||||
mkdir -p build/classes
|
||||
javac -d build/classes libsrc/ffdec_lib/src/com/jpexs/decompiler/flash/helpers/BMPFile.java
|
||||
javac -cp build/classes -d build/classes src/com/jpexs/build/SplashScreenGenerator.java
|
||||
java -cp build/classes com.jpexs.build.SplashScreenGenerator "${{ needs.compute-version.outputs.verLong }}"
|
||||
|
||||
- name: Replace EXE splash screen
|
||||
run: |
|
||||
export WINEPREFIX=$(pwd)/tools/wine
|
||||
cp resources/ffdec.exe $WINEPREFIX/ffdec.exe
|
||||
cp build/splash.bmp $WINEPREFIX/splash.bmp
|
||||
xvfb-run wine $WINEPREFIX/resourcehacker/ResourceHacker.exe -open $WINEPREFIX/ffdec.exe -save $WINEPREFIX/ffdec.exe -action addoverwrite -res $WINEPREFIX/splash.bmp -mask BITMAP,1
|
||||
cp $WINEPREFIX/ffdec.exe resources/ffdec.exe
|
||||
- name: Generate EXE version info
|
||||
run: |
|
||||
sed -i \
|
||||
-e 's/@MAJOR@/${{ needs.compute-version.outputs.verMajor }}/g' \
|
||||
-e 's/@MINOR@/${{ needs.compute-version.outputs.verMinor }}/g' \
|
||||
-e 's/@RELEASE@/${{ needs.compute-version.outputs.verRelease }}/g' \
|
||||
-e 's/@BUILD@/${{ needs.compute-version.outputs.verBuild }}/g' \
|
||||
-e 's/@VERSION@/${{ needs.compute-version.outputs.verShort }}/g' \
|
||||
versioninfo.rc
|
||||
- name: Replace EXE version info
|
||||
run: |
|
||||
export WINEPREFIX=$(pwd)/tools/wine
|
||||
cp resources/ffdec.exe $WINEPREFIX/ffdec.exe
|
||||
cp versioninfo.rc $WINEPREFIX/versioninfo.rc
|
||||
xvfb-run wine $WINEPREFIX/resourcehacker/ResourceHacker.exe -open $WINEPREFIX/versioninfo.rc -save $WINEPREFIX/versioninfo.res -action compile
|
||||
xvfb-run wine $WINEPREFIX/resourcehacker/ResourceHacker.exe -open $WINEPREFIX/ffdec.exe -save $WINEPREFIX/ffdec.exe -action addoverwrite -res $WINEPREFIX/versioninfo.res -mask "Version Info,1"
|
||||
cp $WINEPREFIX/ffdec.exe resources/ffdec.exe
|
||||
- name: Upload EXE
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: unsigned_exe
|
||||
path: resources/ffdec.exe
|
||||
|
||||
#--- Note: Windows runner cannot run Resource Hacker for some reason
|
||||
# exe:
|
||||
# name: Generate EXE
|
||||
# runs-on: windows-latest
|
||||
# needs: compute-version
|
||||
# if: needs.compute-version.outputs.doRelease == 'true'
|
||||
# steps:
|
||||
# - name: Checkout
|
||||
# uses: actions/checkout@v3
|
||||
# - name: Set up JDK
|
||||
# uses: actions/setup-java@v4
|
||||
# with:
|
||||
# distribution: adopt
|
||||
# architecture: x64
|
||||
# java-version: 8
|
||||
#
|
||||
# - name: Set up ResourceHacker
|
||||
# id: resource_hacker
|
||||
# shell: pwsh
|
||||
# run: |
|
||||
# $url = "https://www.angusj.com/resourcehacker/resource_hacker.zip"
|
||||
# $zip = "resource_hacker.zip"
|
||||
# $dest = "tools/resource_hacker"
|
||||
#
|
||||
# Invoke-WebRequest $url -OutFile $zip
|
||||
# Expand-Archive $zip -DestinationPath $dest -Force
|
||||
# $path = $dest + '/ResourceHacker.exe'
|
||||
# "path=$path" | Out-File -FilePath $env:GITHUB_OUTPUT -Append
|
||||
#
|
||||
# - name: Generate EXE splash screen
|
||||
# shell: pwsh
|
||||
# run: |
|
||||
# mkdir build/classes
|
||||
# javac -d build/classes libsrc/ffdec_lib/src/com/jpexs/decompiler/flash/helpers/BMPFile.java
|
||||
# javac -cp build/classes -d build/classes src/com/jpexs/build/SplashScreenGenerator.java
|
||||
# java -cp build/classes com.jpexs.build.SplashScreenGenerator "${{ needs.compute-version.outputs.verLong }}"
|
||||
#
|
||||
# - name: Replace EXE splash screen
|
||||
# shell: pwsh
|
||||
# run: |
|
||||
# $resource_hacker = "${{ steps.resource_hacker.outputs.path }}"
|
||||
#
|
||||
# & $resource_hacker -open resources/ffdec.exe -save resources/ffdec.exe -action addoverwrite -res build/splash.bmp -mask BITMAP,1
|
||||
# - name: Generate EXE version info
|
||||
# shell: pwsh
|
||||
# run: |
|
||||
# $template = Get-Content -Path 'versioninfo.rc' -Raw -Encoding UTF8
|
||||
# $t = $template
|
||||
# $t = $t -creplace '@MAJOR@', '${{ needs.compute-version.outputs.verMajor }}'
|
||||
# $t = $t -creplace '@MINOR@', '${{ needs.compute-version.outputs.verMinor }}'
|
||||
# $t = $t -creplace '@RELEASE@', '${{ needs.compute-version.outputs.verRelease }}'
|
||||
# $t = $t -creplace '@BUILD@', '${{ needs.compute-version.outputs.verBuild }}'
|
||||
# $t = $t -creplace '@VERSION@', '${{ needs.compute-version.outputs.verShort }}'
|
||||
# Set-Content -Path 'versioninfo.rc' -Value $t -Encoding UTF8
|
||||
# - name: Replace EXE version info
|
||||
# shell: pwsh
|
||||
# run: |
|
||||
# $resource_hacker = "${{ steps.resource_hacker.outputs.path }}"
|
||||
# & $resource_hacker -open versioninfo.rc -save versioninfo.res -action compile
|
||||
# & $resource_hacker -open resources/ffdec.exe -save resources/ffdec.exe -action addoverwrite -res versioninfo.res -mask "Version Info,1"
|
||||
# - name: Upload EXE
|
||||
# uses: actions/upload-artifact@v4
|
||||
# with:
|
||||
# name: unsigned_exe
|
||||
# path: resources/ffdec.exe
|
||||
|
||||
sign_and_msi:
|
||||
name: Code signing, MSI installer
|
||||
runs-on: windows-latest
|
||||
needs:
|
||||
- compute-version
|
||||
- build
|
||||
- exe
|
||||
if: needs.compute-version.outputs.doRelease == 'true'
|
||||
env:
|
||||
GCP_PROJECT_ID: jpexs-ffdec
|
||||
GCP_LOCATION: europe
|
||||
KMS_KEYRING: jpexs-ffdec-keyring
|
||||
KMS_KEY: jpexs-ffdec-key2
|
||||
KMS_KEY_VERSION: "1"
|
||||
|
||||
CERT_PATH: "cert/user.crt"
|
||||
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Download dist artifact
|
||||
uses: actions/download-artifact@v4
|
||||
with:
|
||||
name: dist
|
||||
path: dist/
|
||||
|
||||
- name: Download lib_dist artifact
|
||||
uses: actions/download-artifact@v4
|
||||
with:
|
||||
name: lib_dist
|
||||
path: libsrc/ffdec_lib/dist/
|
||||
|
||||
- name: Download unsigned EXE artifact
|
||||
uses: actions/download-artifact@v4
|
||||
with:
|
||||
name: unsigned_exe
|
||||
path: dist/
|
||||
|
||||
- name: Set up JDK
|
||||
uses: actions/setup-java@v4
|
||||
with:
|
||||
distribution: adopt
|
||||
architecture: x64
|
||||
java-version: 23
|
||||
|
||||
- name: Build alt signer
|
||||
working-directory: altsigner
|
||||
run: mvn clean package
|
||||
|
||||
- id: auth
|
||||
uses: google-github-actions/auth@v2
|
||||
with:
|
||||
workload_identity_provider: "projects/541721778634/locations/global/workloadIdentityPools/github-pool/providers/github-provider"
|
||||
service_account: "[email protected]"
|
||||
- name: Setup gcloud
|
||||
uses: google-github-actions/setup-gcloud@v3
|
||||
with:
|
||||
project_id: "${{ env.GCP_PROJECT_ID }}"
|
||||
|
||||
- name: Install Google Cloud KMS CNG Provider
|
||||
shell: pwsh
|
||||
env:
|
||||
GH_TOKEN: ${{secrets.GH_TOKEN}}
|
||||
run: |
|
||||
$repo = "GoogleCloudPlatform/kms-integrations"
|
||||
$tmp = "$env:RUNNER_TEMP\kms"
|
||||
New-Item -ItemType Directory -Force -Path $tmp | Out-Null
|
||||
|
||||
$tag = gh release list `
|
||||
--repo $repo `
|
||||
--limit 50 `
|
||||
--json tagName,createdAt `
|
||||
-q '[.[] | select(.tagName | startswith("cng-"))][0].tagName'
|
||||
|
||||
if (-not $tag) {
|
||||
throw "No release found with tag cng-*"
|
||||
}
|
||||
|
||||
Write-Host "Using release tag: $tag"
|
||||
|
||||
gh release download $tag `
|
||||
--repo $repo `
|
||||
--pattern "*windows-amd64*.zip" `
|
||||
--dir $tmp
|
||||
|
||||
$zip = Get-ChildItem $tmp -Filter "*.zip" | Select-Object -First 1
|
||||
if (-not $zip) { throw "ZIP asset not found (pattern *windows-amd64*.zip). Check names in releases." }
|
||||
|
||||
$extract = Join-Path $tmp "extract"
|
||||
New-Item -ItemType Directory -Force -Path $extract | Out-Null
|
||||
Expand-Archive -Path $zip.FullName -DestinationPath $extract -Force
|
||||
|
||||
$msi = Get-ChildItem $extract -Recurse -Filter "*.msi" | Select-Object -First 1
|
||||
if (-not $msi) { throw "MSI not found inside ZIP. Check structure of archive in releases." }
|
||||
|
||||
Write-Host "Installing: $($msi.FullName)"
|
||||
|
||||
Start-Process msiexec.exe -Wait -ArgumentList "/i `"$($msi.FullName)`" /qn /norestart"
|
||||
|
||||
- name: Sign ffdec.jar
|
||||
shell: pwsh
|
||||
run: |
|
||||
$kc = "projects/$env:GCP_PROJECT_ID/locations/$env:GCP_LOCATION/keyRings/$env:KMS_KEYRING/cryptoKeys/$env:KMS_KEY/cryptoKeyVersions/$env:KMS_KEY_VERSION"
|
||||
java -cp altsigner\target\kms-jarsigner-1.0.jar com.jpexs.kmsjarsigner.SignJar dist/ffdec.jar dist/ffdec-signed.jar cert/cert-chain.pem $kc http://timestamp.sectigo.com
|
||||
move dist/ffdec-signed.jar dist/ffdec.jar -Force
|
||||
|
||||
- name: Verify ffdec.jar signature
|
||||
shell: pwsh
|
||||
run: jarsigner.exe -verify -strict dist/ffdec.jar
|
||||
|
||||
- name: Upload signed JAR artifact
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: signed_jar
|
||||
path: dist/ffdec.jar
|
||||
|
||||
- name: Sign ffdec_lib.jar
|
||||
shell: pwsh
|
||||
run: |
|
||||
$kc = "projects/$env:GCP_PROJECT_ID/locations/$env:GCP_LOCATION/keyRings/$env:KMS_KEYRING/cryptoKeys/$env:KMS_KEY/cryptoKeyVersions/$env:KMS_KEY_VERSION"
|
||||
java -cp altsigner\target\kms-jarsigner-1.0.jar com.jpexs.kmsjarsigner.SignJar libsrc/ffdec_lib/dist/ffdec_lib.jar libsrc/ffdec_lib/dist/ffdec_lib-signed.jar cert/cert-chain.pem $kc http://timestamp.sectigo.com
|
||||
move libsrc/ffdec_lib/dist/ffdec_lib-signed.jar libsrc/ffdec_lib/dist/ffdec_lib.jar -Force
|
||||
|
||||
- name: Verify ffdec_lib.jar signature
|
||||
shell: pwsh
|
||||
run: jarsigner.exe -verify -strict libsrc/ffdec_lib/dist/ffdec_lib.jar
|
||||
|
||||
- name: Upload signed lib JAR artifact
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: signed_lib_jar
|
||||
path: libsrc/ffdec_lib/dist/ffdec_lib.jar
|
||||
|
||||
|
||||
- name: Locate signtool
|
||||
id: signtool
|
||||
shell: pwsh
|
||||
run: |
|
||||
$candidates = Get-ChildItem "C:\Program Files (x86)\Windows Kits\10\bin" `
|
||||
-Recurse -Filter signtool.exe -ErrorAction SilentlyContinue
|
||||
|
||||
Write-Host "All signtool candidates:"
|
||||
$candidates | ForEach-Object {
|
||||
Write-Host " - $($_.FullName)"
|
||||
}
|
||||
|
||||
# vyber jen x64
|
||||
$x64 = $candidates | Where-Object {
|
||||
$_.FullName -match "\\x64\\"
|
||||
}
|
||||
|
||||
if (-not $x64) {
|
||||
throw "No x64 signtool.exe found"
|
||||
}
|
||||
|
||||
$path = $x64 | Sort-Object FullName -Descending | Select-Object -First 1
|
||||
"path=$path" | Out-File -FilePath $env:GITHUB_OUTPUT -Append
|
||||
|
||||
- name: Sign EXE with KMS key
|
||||
shell: pwsh
|
||||
run: |
|
||||
$signtool = "${{ steps.signtool.outputs.path }}"
|
||||
$kc = "projects/$env:GCP_PROJECT_ID/locations/$env:GCP_LOCATION/keyRings/$env:KMS_KEYRING/cryptoKeys/$env:KMS_KEY/cryptoKeyVersions/$env:KMS_KEY_VERSION"
|
||||
|
||||
$ErrorActionPreference = 'Stop'
|
||||
|
||||
$exe = $signtool
|
||||
$args = @(
|
||||
"sign",
|
||||
"/v",
|
||||
"/debug",
|
||||
"/fd", "sha256",
|
||||
"/tr", "http://timestamp.sectigo.com?td=sha256",
|
||||
"/td", "sha256",
|
||||
"/f", "$env:CERT_PATH",
|
||||
"/csp", "Google Cloud KMS Provider",
|
||||
"/kc", "$kc",
|
||||
"dist/ffdec.exe"
|
||||
)
|
||||
|
||||
# --- retry policy ---
|
||||
$maxAttempts = 5
|
||||
$delaySeconds = 10
|
||||
$needle = "SignTool Error: An unexpected internal error has occurred"
|
||||
|
||||
for ($attempt = 1; $attempt -le $maxAttempts; $attempt++) {
|
||||
Write-Host "Attempt $attempt/${maxAttempts}: $exe $($args -join ' ')"
|
||||
|
||||
$output = & $exe @args 2>&1 | Out-String
|
||||
$exitCode = $LASTEXITCODE
|
||||
|
||||
if ($output) { Write-Host $output.TrimEnd() }
|
||||
|
||||
if ($exitCode -eq 0) {
|
||||
Write-Host "Succeeded."
|
||||
exit 0
|
||||
}
|
||||
|
||||
$hasNeedle = $output -match [regex]::Escape($needle)
|
||||
|
||||
if ($hasNeedle -and $attempt -lt $maxAttempts) {
|
||||
Write-Warning "Detected transient SignTool internal error. Retrying in $delaySeconds seconds..."
|
||||
Start-Sleep -Seconds $delaySeconds
|
||||
continue
|
||||
}
|
||||
|
||||
if ($hasNeedle) {
|
||||
throw "Failed after $maxAttempts attempts due to repeated SignTool internal error (exit code $exitCode)."
|
||||
} else {
|
||||
throw "Command failed (exit code $exitCode). Output did not match retry condition."
|
||||
}
|
||||
}
|
||||
|
||||
- name: Verify EXE signature
|
||||
shell: pwsh
|
||||
run: |
|
||||
$signtool = "${{ steps.signtool.outputs.path }}"
|
||||
& $signtool verify /pa /v "dist/ffdec.exe"
|
||||
|
||||
|
||||
- name: Get Msi tools path
|
||||
id: msitools
|
||||
shell: pwsh
|
||||
run: |
|
||||
$candidates = Get-ChildItem "C:\Program Files (x86)\Windows Kits\10\bin" `
|
||||
-Recurse -Filter MsiTran.exe -ErrorAction SilentlyContinue
|
||||
|
||||
Write-Host "All signtool candidates:"
|
||||
$candidates | ForEach-Object {
|
||||
Write-Host " - $($_.FullName)"
|
||||
}
|
||||
|
||||
$x86 = $candidates | Where-Object {
|
||||
$_.FullName -match "\\x86\\"
|
||||
}
|
||||
|
||||
if (-not $x86) {
|
||||
throw "No x86 MsiTran.exe found"
|
||||
}
|
||||
|
||||
$path = $x86 | Sort-Object FullName -Descending | Select-Object -First 1
|
||||
$path = Split-Path $path -Parent
|
||||
|
||||
"path=$path" | Out-File -FilePath $env:GITHUB_OUTPUT -Append
|
||||
#Add-Content $env:GITHUB_PATH $path
|
||||
|
||||
- name: Inject version info
|
||||
shell: pwsh
|
||||
run: |
|
||||
$template = Get-Content -Path 'wix\Product.wxs' -Raw -Encoding UTF8
|
||||
$t = $template
|
||||
$t = $t -creplace 'Name="JPEXS Free Flash Decompiler 1.0.0"', 'Name="JPEXS Free Flash Decompiler ${{ needs.compute-version.outputs.verLong }}"'
|
||||
$t = $t -creplace 'Version="1.0.0"', 'Version="${{ needs.compute-version.outputs.verRaw }}"'
|
||||
$t = $t -creplace 'Id="ARPVERSION" Value="1.0.0"', 'Id="ARPVERSION" Value="${{ needs.compute-version.outputs.verLong }}"'
|
||||
Set-Content -Path 'wix\Product.wxs' -Value $t -Encoding UTF8
|
||||
|
||||
- name: Create installer
|
||||
shell: cmd
|
||||
working-directory: wix
|
||||
run: |
|
||||
set MsiToolsPath=${{ steps.msitools.outputs.path }}
|
||||
.\Build_Release.cmd
|
||||
|
||||
- name: Sign MSI with KMS key
|
||||
shell: pwsh
|
||||
run: |
|
||||
$signtool = "${{ steps.signtool.outputs.path }}"
|
||||
$kc = "projects/$env:GCP_PROJECT_ID/locations/$env:GCP_LOCATION/keyRings/$env:KMS_KEYRING/cryptoKeys/$env:KMS_KEY/cryptoKeyVersions/$env:KMS_KEY_VERSION"
|
||||
|
||||
$ErrorActionPreference = 'Stop'
|
||||
|
||||
$exe = $signtool
|
||||
$args = @(
|
||||
"sign",
|
||||
"/v",
|
||||
"/debug",
|
||||
"/fd", "sha256",
|
||||
"/tr", "http://timestamp.sectigo.com?td=sha256",
|
||||
"/td", "sha256",
|
||||
"/f", "$env:CERT_PATH",
|
||||
"/csp", "Google Cloud KMS Provider",
|
||||
"/kc", "$kc",
|
||||
"wix/bin/Release/FFDec.msi"
|
||||
)
|
||||
|
||||
# --- retry policy ---
|
||||
$maxAttempts = 5
|
||||
$delaySeconds = 10
|
||||
$needle = "SignTool Error: An unexpected internal error has occurred"
|
||||
|
||||
for ($attempt = 1; $attempt -le $maxAttempts; $attempt++) {
|
||||
Write-Host "Attempt $attempt/${maxAttempts}: $exe $($args -join ' ')"
|
||||
|
||||
$output = & $exe @args 2>&1 | Out-String
|
||||
$exitCode = $LASTEXITCODE
|
||||
|
||||
if ($output) { Write-Host $output.TrimEnd() }
|
||||
|
||||
if ($exitCode -eq 0) {
|
||||
Write-Host "Succeeded."
|
||||
exit 0
|
||||
}
|
||||
|
||||
$hasNeedle = $output -match [regex]::Escape($needle)
|
||||
|
||||
if ($hasNeedle -and $attempt -lt $maxAttempts) {
|
||||
Write-Warning "Detected transient SignTool internal error. Retrying in $delaySeconds seconds..."
|
||||
Start-Sleep -Seconds $delaySeconds
|
||||
continue
|
||||
}
|
||||
|
||||
if ($hasNeedle) {
|
||||
throw "Failed after $maxAttempts attempts due to repeated SignTool internal error (exit code $exitCode)."
|
||||
} else {
|
||||
throw "Command failed (exit code $exitCode). Output did not match retry condition."
|
||||
}
|
||||
}
|
||||
|
||||
- name: Verify MSI signature
|
||||
shell: pwsh
|
||||
run: |
|
||||
$signtool = "${{ steps.signtool.outputs.path }}"
|
||||
& $signtool verify /pa /v "wix/bin/Release/FFDec.msi"
|
||||
|
||||
- name: Upload signed EXE artifact
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: signed_exe
|
||||
path: dist/ffdec.exe
|
||||
|
||||
- name: Rename MSI
|
||||
shell: cmd
|
||||
run: |
|
||||
mkdir releases
|
||||
move wix\bin\Release\FFDec.msi releases\ffdec_${{ needs.compute-version.outputs.verShort }}.msi
|
||||
|
||||
- name: Upload signed MSI artifact
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: signed_msi
|
||||
path: releases/ffdec_${{ needs.compute-version.outputs.verShort }}.msi
|
||||
packages:
|
||||
name: Create packages
|
||||
runs-on: ubuntu-latest
|
||||
needs:
|
||||
- compute-version
|
||||
- build
|
||||
- exe
|
||||
- sign_and_msi
|
||||
if: needs.compute-version.outputs.doRelease == 'true'
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v3
|
||||
|
||||
- name: Download dist artifact
|
||||
uses: actions/download-artifact@v4
|
||||
with:
|
||||
name: dist
|
||||
path: dist/
|
||||
|
||||
- name: Download signed jar artifact
|
||||
uses: actions/download-artifact@v4
|
||||
with:
|
||||
name: signed_jar
|
||||
path: dist/
|
||||
|
||||
- name: Download lib dist artifact
|
||||
uses: actions/download-artifact@v4
|
||||
with:
|
||||
name: lib_dist
|
||||
path: libsrc/ffdec_lib/dist/
|
||||
|
||||
- name: Download signed lib jar artifact
|
||||
uses: actions/download-artifact@v4
|
||||
with:
|
||||
name: signed_lib_jar
|
||||
path: libsrc/ffdec_lib/dist/
|
||||
|
||||
- name: Copy signed ffdec_lib.jar to dist/lib dir
|
||||
run: cp libsrc/ffdec_lib/dist/ffdec_lib.jar dist/lib/ffdec_lib.jar
|
||||
|
||||
- name: Download signed EXE artifact
|
||||
uses: actions/download-artifact@v4
|
||||
with:
|
||||
name: signed_exe
|
||||
path: dist/
|
||||
|
||||
- name: Download signed MSI artifact
|
||||
uses: actions/download-artifact@v4
|
||||
with:
|
||||
name: signed_msi
|
||||
path: releases/
|
||||
|
||||
- name: Set up JDK
|
||||
uses: actions/setup-java@v4
|
||||
with:
|
||||
distribution: adopt
|
||||
architecture: x64
|
||||
java-version: 8
|
||||
|
||||
- name: Set up Ant
|
||||
run: |
|
||||
sudo apt-get update -y -qq
|
||||
sudo apt-get install -y -qq ant
|
||||
|
||||
- name: Download version.properties artifact
|
||||
uses: actions/download-artifact@v4
|
||||
with:
|
||||
name: version_properties
|
||||
|
||||
- name: Copy version.properties to lib
|
||||
run: cp version.properties libsrc/ffdec_lib/
|
||||
|
||||
- name: Create packages
|
||||
run: ant new-version-set release-no-dist
|
||||
|
||||
- name: Upload packages
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: packages
|
||||
path: releases
|
||||
|
||||
Reference in New Issue
Block a user