Commit 93b47f32 authored by Adrien's avatar Adrien Committed by GitHub

Merge pull request #6 from bonitasoft/codesign_macos

macOs codesigning

closes [BS-18586](https://bonitasoft.atlassian.net/browse/BS-18586)
parents e56f9150 abb9f9e6
#Tue Jun 12 16:10:51 CEST 2018
distributionBase=GRADLE_USER_HOME
distributionPath=wrapper/dists
distributionUrl=https\://services.gradle.org/distributions/gradle-4.7-bin.zip
zipStoreBase=GRADLE_USER_HOME
zipStorePath=wrapper/dists
distributionUrl=https\://services.gradle.org/distributions/gradle-4.7-all.zip
/**
* Copyright (C) 2018 Bonitasoft S.A.
* Bonitasoft, 32 rue Gustave Eiffel - 38000 Grenoble
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 2.0 of the License, or
* (at your option) any later version.
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
package org.bonitasoft.exception
class BuildDmgException(message : String) : Throwable(message) {
}
\ No newline at end of file
/**
* Copyright (C) 2018 Bonitasoft S.A.
* Bonitasoft, 32 rue Gustave Eiffel - 38000 Grenoble
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 2.0 of the License, or
* (at your option) any later version.
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
package org.bonitasoft.exception
class SignException(message : String) : Throwable(message){
}
\ No newline at end of file
......@@ -21,5 +21,5 @@ import org.springframework.boot.autoconfigure.SpringBootApplication
class CodeSignApp
fun main(args: Array<String>) {
SpringApplication.run(CodeSignApp::class.java, *args)
SpringApplication.run(CodeSignApp::class.java, *args)
}
\ No newline at end of file
......@@ -16,69 +16,134 @@ package org.bonitasoft.releng
import org.apache.commons.logging.Log
import org.apache.commons.logging.LogFactory
import org.bonitasoft.exception.BuildDmgException
import org.bonitasoft.exception.SignException
import org.springframework.web.bind.annotation.PostMapping
import org.springframework.web.bind.annotation.RequestParam
import org.springframework.web.bind.annotation.RestController
import org.springframework.web.multipart.MultipartFile
import org.springframework.web.servlet.mvc.method.annotation.StreamingResponseBody
import java.io.File
import java.io.FileInputStream
import java.nio.file.Files
import javax.servlet.http.HttpServletResponse
import java.io.FileOutputStream
import java.io.File
@RestController
class CodeSigningRestController {
val logger: Log = LogFactory.getLog(javaClass)
@PostMapping("/sign")
fun singleFileUpload(@RequestParam("exeFile") file: MultipartFile,
response: HttpServletResponse): StreamingResponseBody {
if (file.isEmpty) {
logger.error("File '%s' is empty".format(file.originalFilename))
response.setStatus(400)
return StreamingResponseBody { outputStream ->
outputStream.write("File '%s' is empty".format(file.originalFilename).toByteArray())
outputStream.close()
}
}
try {
val exeCopy = Files.createTempFile(file.originalFilename,"").toFile()
logger.info("Copy of input file as $exeCopy....")
file.transferTo(exeCopy)
response.setContentType("application/octet-stream");
response.setHeader("Content-Disposition", "attachment; filename='${file.originalFilename}'");
val processBuilder = ProcessBuilder("signtool", "sign", "/tr", "http://timestamp.digicert.com",
"/td", "sha256", "/fd", "sha256", "/a", exeCopy.canonicalFile.absolutePath)
logger.info("Signing file...")
val signResult = processBuilder.inheritIO().start().waitFor()
if (signResult != 0) {
logger.error("An error occured while signing file.")
response.setStatus(500);
return StreamingResponseBody { outputStream ->
outputStream.write("An error occured while signing file.".toByteArray())
}
}
return StreamingResponseBody { outputStream ->
FileInputStream(exeCopy.canonicalFile).use { inputStream ->
inputStream.copyTo(outputStream)
outputStream.flush()
outputStream.close()
}
if (!exeCopy.delete()) {
logger.error("Failed to delete temp file $exeCopy")
}
}
} catch (e: Throwable) {
logger.error("An error occured", e)
}
return StreamingResponseBody { outputStream ->
outputStream.write("An error occured server side. Check logs.".toByteArray())
}
}
val logger: Log = LogFactory.getLog(javaClass)
val macOs: String = "Mac OS X"
var windowsCodeSign = WindowsCodeSign()
var macCodeSign = MacCodeSign()
@PostMapping("/sign")
fun signProduct(@RequestParam("exeFile") file: MultipartFile,
response: HttpServletResponse): StreamingResponseBody {
if (file.isEmpty) {
logger.error("File '%s' is empty".format(file.originalFilename))
response.setStatus(400)
return StreamingResponseBody { outputStream ->
outputStream.write("File '%s' is empty".format(file.originalFilename).toByteArray())
outputStream.close()
}
}
try {
val exeCopy: File = Files.createTempFile(file.originalFilename, "").toFile()
logger.info("Copy of input file as $exeCopy....")
file.transferTo(exeCopy)
val fileSigned: File
try {
if (System.getProperty("os.name") == macOs) {
fileSigned = macCodeSign.signMacProduct(exeCopy)
} else {
fileSigned = windowsCodeSign.signWindowsProduct(exeCopy)
}
} catch (e: SignException) {
logger.error(e)
response.setStatus(500)
return StreamingResponseBody { outputStream ->
outputStream.write("An error occured while signing file.".toByteArray())
}
}
response.setContentType("application/octet-stream")
response.setHeader("Content-Disposition", "attachment; filename='${fileSigned.name}'")
return StreamingResponseBody { outputStream ->
FileInputStream(fileSigned.canonicalFile).use { inputStream ->
inputStream.copyTo(outputStream)
outputStream.flush()
outputStream.close()
}
if (!fileSigned.delete()) {
logger.error("Failed to delete temp file $fileSigned")
}
}
} catch (e: Throwable) {
logger.error("An error occured", e)
}
return StreamingResponseBody { outputStream ->
outputStream.write("An error occured server side. Check logs.".toByteArray())
}
}
@PostMapping("/buildAndSignMacInstaller")
fun buildAndSignOsxInstaller(@RequestParam("exeFile") file: MultipartFile,
response: HttpServletResponse): StreamingResponseBody {
if (file.isEmpty) {
logger.error("File '%s' is empty".format(file.originalFilename))
response.setStatus(400)
return StreamingResponseBody { outputStream ->
outputStream.write("File '%s' is empty".format(file.originalFilename).toByteArray())
outputStream.close()
}
}
try {
val exeCopy: File = Files.createTempFile(file.originalFilename, "").toFile()
logger.info("Copy of input file as $exeCopy....")
file.transferTo(exeCopy)
try {
val fileSigned: File = macCodeSign.buildAndSignMacInstaller(exeCopy)
response.setContentType("application/octet-stream");
response.setHeader("Content-Disposition", "attachment; filename='${fileSigned.name}'");
return StreamingResponseBody { outputStream ->
FileInputStream(fileSigned).use { inputStream ->
inputStream.copyTo(outputStream)
outputStream.flush()
outputStream.close()
}
if (!fileSigned.delete()) {
logger.error("Failed to delete temp file $fileSigned")
}
}
} catch (e: SignException) {
logger.error(e)
response.setStatus(500);
return StreamingResponseBody { outputStream ->
outputStream.write("An error occured while signing file.".toByteArray())
}
} catch (e: BuildDmgException) {
logger.error(e)
response.setStatus(500);
return StreamingResponseBody { outputStream ->
outputStream.write("An error occured while building dmg.".toByteArray())
}
}
} catch (e: Throwable) {
logger.error("An error occured", e)
}
return StreamingResponseBody { outputStream ->
outputStream.write("An error occured server side. Check logs.".toByteArray())
}
}
}
\ No newline at end of file
/**
* Copyright (C) 2018 Bonitasoft S.A.
* Bonitasoft, 32 rue Gustave Eiffel - 38000 Grenoble
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 2.0 of the License, or
* (at your option) any later version.
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
package org.bonitasoft.releng
import org.apache.commons.logging.Log
import org.apache.commons.logging.LogFactory
import org.bonitasoft.exception.BuildDmgException
import org.bonitasoft.exception.SignException
import java.io.File
class MacCodeSign {
val logger: Log = LogFactory.getLog(javaClass)
val separator = System.getProperty("file.separator")
fun signMacProduct(zipFile: File): File {
val file: File = unzip(zipFile);
if (!zipFile.delete()) {
logger.error("Failed to delete temp file $zipFile")
throw Throwable()
}
logger.info("Signing osx application...")
val signResult = ProcessBuilder()
.inheritIO()
.command("codesign", "--deep", "-s", "Bonitasoft", file.canonicalPath)
.start()
.waitFor()
if (signResult != 0) {
throw SignException("An error occured while signing file.")
}
var newZipFile = zip(file);
deleteApplication(file)
logger.info("Osx application has been signed successfully")
return newZipFile
}
fun buildAndSignMacInstaller(zipFile: File): File {
val file: File = unzip(zipFile);
if (!zipFile.delete()) {
throw Throwable("Failed to delete temp file $zipFile")
}
logger.info("Signing macOS installer...")
var signResult = ProcessBuilder()
.inheritIO()
.command("codesign", "--deep", "-s", "Bonitasoft", file.canonicalPath)
.start()
.waitFor()
if (signResult != 0) {
throw SignException("An error occured while signing installer.")
}
logger.info("Building dmg...")
var dmgName = file.nameWithoutExtension
var dmgPath = file.parentFile.canonicalPath + separator + file.nameWithoutExtension + ".dmg"
val buildDmgResult = ProcessBuilder()
.inheritIO()
.command("hdiutil", "create", "-volname", dmgName, "-srcfolder", file.canonicalPath, "-ov", "-format", "UDZO", dmgPath)
.start()
.waitFor()
var dmg = File(dmgPath);
if (buildDmgResult != 0 || !dmg.exists()) {
throw BuildDmgException("An error occured while building dmg")
}
logger.info("Signing macOS dmg...")
signResult = ProcessBuilder()
.inheritIO()
.command("codesign", "-s", "Bonitasoft", dmgPath)
.start()
.waitFor()
if (signResult != 0) {
throw SignException("An error occured while signing dmg.")
}
deleteApplication(file)
logger.info("dmg has been created and signed successfully")
return dmg
}
fun unzip(zipFile: File): File {
ProcessBuilder()
.inheritIO()
.command("unzip", zipFile.canonicalPath, "-d", zipFile.parentFile.canonicalPath)
.start()
.waitFor()
var file: File = File(zipFile.parentFile.canonicalPath + separator + zipFile.nameWithoutExtension + ".app")
if (!file.exists()) {
logger.error("failed to unzip $zipFile")
throw Throwable()
}
return file
}
fun zip(file: File): File {
val zipPath: String = file.parentFile.canonicalPath + separator + file.nameWithoutExtension + ".zip"
ProcessBuilder()
.inheritIO()
.command("zip", zipPath, "-r", file.canonicalPath)
.start()
.waitFor()
var zipFile = File(zipPath)
if (!zipFile.exists()) {
logger.error("failed to unzip $file")
throw Throwable()
}
return zipFile
}
fun deleteApplication(application: File) {
ProcessBuilder()
.inheritIO()
.command("rm", "-r", application.canonicalPath)
.start()
.waitFor()
}
}
\ No newline at end of file
/**
* Copyright (C) 2018 Bonitasoft S.A.
* Bonitasoft, 32 rue Gustave Eiffel - 38000 Grenoble
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 2.0 of the License, or
* (at your option) any later version.
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
* You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
package org.bonitasoft.releng
import org.apache.commons.logging.Log
import org.apache.commons.logging.LogFactory
import org.bonitasoft.exception.SignException
import org.springframework.web.multipart.MultipartFile
import java.io.File
import javax.servlet.http.HttpServletResponse
class WindowsCodeSign {
val logger: Log = LogFactory.getLog(javaClass)
fun signWindowsProduct(file: File) : File {
val processBuilder = ProcessBuilder("signtool", "sign", "/tr", "http://timestamp.digicert.com",
"/td", "sha256", "/fd", "sha256", "/a", file.canonicalFile.absolutePath)
logger.info("Signing windows file...")
val signResult = processBuilder.inheritIO().start().waitFor()
if (signResult != 0) {
throw SignException("An error occured while signing file.")
}
return file;
}
}
\ No newline at end of file
......@@ -37,7 +37,7 @@ class CodeSigningRestControllerTest : Spek({
Mockito.`when`(file.originalFilename).thenReturn("fileName")
on("sending file to controller") {
controller.singleFileUpload(file, response)
controller.signProduct(file, response)
it("should set a code 400 on the response") {
assertEquals(response.status, 400)
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment