-
Notifications
You must be signed in to change notification settings - Fork 8.5k
[Tool] Script to build an installer locally #39017
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from 15 commits
Commits
Show all changes
20 commits
Select commit
Hold shift + click to select a range
d32fb44
add script to build a installer
vanzue 242ba82
minor fix
vanzue 3289f4c
fix search path for msix file
vanzue def90e6
fix sign
vanzue 302e139
fix sign
vanzue dc11217
fix spelling
vanzue 821698c
Fix powershell5 can't recognize emoji
vanzue 2e69c30
ensure-wix
vanzue aa77b32
bring cmdpal available during local build
vanzue bce1dff
remove early quit
vanzue 0f21476
fix marco
vanzue faa4c03
add logger
vanzue 691cc93
doc
vanzue b37f4eb
add a note
vanzue d404faf
self review
vanzue b15209f
Merge remote-tracking branch 'origin/main' into dev/vanzue/build-script
vanzue 2100f3d
Merge remote-tracking branch 'origin/main' into dev/vanzue/build-script
vanzue 7c1a3a4
fix macro def
vanzue de231d3
add functionality to export cert so that other machine can install it.
vanzue 736b14d
spelling
vanzue File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,122 @@ | ||
| <# | ||
| .SYNOPSIS | ||
| Build and package PowerToys (CmdPal and installer) for a specific platform and configuration LOCALLY. | ||
|
|
||
| .DESCRIPTION | ||
| This script automates the end-to-end build and packaging process for PowerToys, including: | ||
| - Restoring and building all necessary solutions (CmdPal, BugReportTool, StylesReportTool, etc.) | ||
| - Cleaning up old output | ||
| - Signing generated .msix packages | ||
| - Building the WiX-based MSI and bootstrapper installers | ||
|
|
||
| It is designed to work in local development. | ||
|
|
||
| .PARAMETER Platform | ||
| Specifies the target platform for the build (e.g., 'arm64', 'x64'). Default is 'arm64'. | ||
|
|
||
| .PARAMETER Configuration | ||
| Specifies the build configuration (e.g., 'Debug', 'Release'). Default is 'Release'. | ||
|
|
||
| .EXAMPLE | ||
| .\build-installer.ps1 | ||
| Runs the installer build pipeline for ARM64 Release (default). | ||
|
|
||
| .EXAMPLE | ||
| .\build-installer.ps1 -Platform x64 -Configuration Release | ||
| Runs the pipeline for x64 Debug. | ||
|
|
||
| .NOTES | ||
| - Requires MSBuild, WiX Toolset, and Git to be installed and accessible from your environment. | ||
| - Make sure to run this script from a Developer PowerShell (e.g., VS2022 Developer PowerShell). | ||
| - Generated MSIX files will be signed using cert-sign-package.ps1. | ||
| - This script will clean previous outputs under the build directories and installer directory (except *.exe files). | ||
| - First time run need admin permission to trust the certificate. | ||
| - The built installer will be placed under: installer/PowerToysSetup/[Platform]/[Configuration]/UserSetup | ||
| relative to the solution root directory. | ||
| - The installer can't be run right after the build, I need to copy it to another file before it can be run. | ||
| #> | ||
|
|
||
|
|
||
| param ( | ||
| [string]$Platform = 'arm64', | ||
| [string]$Configuration = 'Release' | ||
| ) | ||
|
|
||
| $repoRoot = Resolve-Path "$PSScriptRoot\..\.." | ||
| Set-Location $repoRoot | ||
|
|
||
| function RunMSBuild { | ||
| param ( | ||
| [string]$Solution, | ||
| [string]$ExtraArgs | ||
| ) | ||
|
|
||
| $base = @( | ||
| $Solution | ||
| "/p:Platform=`"$Platform`"" | ||
| "/p:Configuration=$Configuration" | ||
| '/verbosity:normal' | ||
| '/clp:Summary;PerformanceSummary;ErrorsOnly;WarningsOnly' | ||
|
|
||
| '/nologo' | ||
|
|
||
| ) | ||
|
|
||
| $cmd = $base + ($ExtraArgs -split ' ') | ||
| Write-Host ("[MSBUILD] {0} {1}" -f $Solution, ($cmd -join ' ')) | ||
| & msbuild.exe @cmd | ||
|
|
||
| if ($LASTEXITCODE -ne 0) { | ||
| Write-Error ("Build failed: {0} {1}" -f $Solution, $ExtraArgs) | ||
| exit $LASTEXITCODE | ||
| } | ||
|
|
||
| } | ||
|
|
||
| function RestoreThenBuild { | ||
| param ([string]$Solution) | ||
|
|
||
| # 1) restore | ||
| RunMSBuild $Solution '/t:restore /p:RestorePackagesConfig=true' | ||
| # 2) build ------------------------------------------------- | ||
| RunMSBuild $Solution '/m' | ||
| } | ||
|
|
||
| Write-Host ("Make sure wix is installed and available") | ||
| & "$PSScriptRoot\ensure-wix.ps1" | ||
|
|
||
| Write-Host ("[PIPELINE] Start | Platform={0} Configuration={1}" -f $Platform, $Configuration) | ||
| Write-Host '' | ||
|
|
||
| $cmdpalOutputPath = Join-Path $repoRoot "$Platform\$Configuration\WinUI3Apps\CmdPal" | ||
|
|
||
| if (Test-Path $cmdpalOutputPath) { | ||
| Write-Host "[CLEAN] Removing previous output: $cmdpalOutputPath" | ||
| Remove-Item $cmdpalOutputPath -Recurse -Force -ErrorAction Ignore | ||
| } | ||
|
|
||
| RestoreThenBuild '.\PowerToys.sln' | ||
|
|
||
| $msixSearchRoot = Join-Path $repoRoot "$Platform\$Configuration" | ||
| $msixFiles = Get-ChildItem -Path $msixSearchRoot -Recurse -Filter *.msix | | ||
| Select-Object -ExpandProperty FullName | ||
|
|
||
| if ($msixFiles.Count) { | ||
| Write-Host ("[SIGN] .msix file(s): {0}" -f ($msixFiles -join '; ')) | ||
| & "$PSScriptRoot\cert-sign-package.ps1" -TargetPaths $msixFiles | ||
| } | ||
| else { | ||
| Write-Warning "[SIGN] No .msix files found in $msixSearchRoot" | ||
| } | ||
|
|
||
| RestoreThenBuild '.\tools\BugReportTool\BugReportTool.sln' | ||
| RestoreThenBuild '.\tools\StylesReportTool\StylesReportTool.sln' | ||
|
|
||
| Write-Host '[CLEAN] installer (keep *.exe)' | ||
| git clean -xfd -e '*.exe' -- .\installer\ | Out-Null | ||
|
|
||
| RunMSBuild '.\installer\PowerToysSetup.sln' '/t:restore /p:RestorePackagesConfig=true' | ||
|
|
||
| RunMSBuild '.\installer\PowerToysSetup.sln' '/m /t:PowerToysInstaller /p:PerUser=true' | ||
|
|
||
| RunMSBuild '.\installer\PowerToysSetup.sln' '/m /t:PowerToysBootstrapper /p:PerUser=true' | ||
|
|
||
| Write-Host '[PIPELINE] Completed' | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,119 @@ | ||
| <# | ||
| .SYNOPSIS | ||
| Ensures a code signing certificate exists and is trusted in all necessary certificate stores. | ||
|
|
||
| .DESCRIPTION | ||
| This script provides two functions: | ||
|
|
||
| 1. EnsureCertificate: | ||
| - Searches for an existing code signing certificate by subject name. | ||
| - If not found, creates a new self-signed certificate. | ||
| - Exports the certificate and attempts to import it into: | ||
| - CurrentUser\TrustedPeople | ||
| - CurrentUser\Root | ||
| - LocalMachine\Root (admin privileges may be required) | ||
|
|
||
| 2. ImportAndVerifyCertificate: | ||
| - Imports a `.cer` file into the specified certificate store if not already present. | ||
| - Verifies the certificate is successfully imported by checking thumbprint. | ||
|
|
||
| This is useful in build or signing pipelines to ensure a valid and trusted certificate is available before signing MSIX or executable files. | ||
|
|
||
| .PARAMETER certSubject | ||
| The subject name of the certificate to search for or create. Default is: | ||
| "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US" | ||
|
|
||
| .PARAMETER cerPath | ||
| (ImportAndVerifyCertificate only) The file path to a `.cer` certificate file to import. | ||
|
|
||
| .PARAMETER storePath | ||
| (ImportAndVerifyCertificate only) The destination certificate store path (e.g. Cert:\CurrentUser\Root). | ||
|
|
||
| .EXAMPLE | ||
| $cert = EnsureCertificate | ||
|
|
||
| Ensures the default certificate exists and is trusted, and returns the certificate object. | ||
|
|
||
| .EXAMPLE | ||
| ImportAndVerifyCertificate -cerPath "$env:TEMP\temp_cert.cer" -storePath "Cert:\CurrentUser\Root" | ||
|
|
||
| Imports a certificate into the CurrentUser Root store and verifies its presence. | ||
|
|
||
| .NOTES | ||
| - For full trust, administrative privileges may be needed to import into LocalMachine\Root. | ||
| - Certificates are created using RSA and SHA256 and marked as CodeSigningCert. | ||
| #> | ||
|
|
||
| function ImportAndVerifyCertificate { | ||
| param ( | ||
| [string]$cerPath, | ||
| [string]$storePath | ||
| ) | ||
|
|
||
| $thumbprint = (Get-PfxCertificate -FilePath $cerPath).Thumbprint | ||
|
|
||
| $existingCert = Get-ChildItem -Path $storePath | Where-Object { $_.Thumbprint -eq $thumbprint } | ||
| if ($existingCert) { | ||
| Write-Host "Certificate already exists in $storePath" | ||
| return $true | ||
| } | ||
|
|
||
| try { | ||
| $null = Import-Certificate -FilePath $cerPath -CertStoreLocation $storePath -ErrorAction Stop | ||
| } catch { | ||
| Write-Warning "Failed to import certificate to $storePath : $_" | ||
| return $false | ||
| } | ||
|
|
||
| $imported = Get-ChildItem -Path $storePath | Where-Object { $_.Thumbprint -eq $thumbprint } | ||
| if ($imported) { | ||
| Write-Host "Certificate successfully imported to $storePath" | ||
| return $true | ||
| } else { | ||
| Write-Warning "Certificate not found in $storePath after import" | ||
| return $false | ||
| } | ||
| } | ||
|
|
||
| function EnsureCertificate { | ||
| param ( | ||
| [string]$certSubject = "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US" | ||
|
yeelam-gordon marked this conversation as resolved.
|
||
| ) | ||
|
|
||
| $cert = Get-ChildItem -Path Cert:\CurrentUser\My | | ||
| Where-Object { $_.Subject -eq $certSubject } | | ||
| Sort-Object NotAfter -Descending | | ||
| Select-Object -First 1 | ||
|
|
||
| if (-not $cert) { | ||
| Write-Host "Certificate not found. Creating a new one..." | ||
|
|
||
| $cert = New-SelfSignedCertificate -Subject $certSubject ` | ||
| -CertStoreLocation "Cert:\CurrentUser\My" ` | ||
| -KeyAlgorithm RSA ` | ||
| -Type CodeSigningCert ` | ||
| -HashAlgorithm SHA256 | ||
|
|
||
| if (-not $cert) { | ||
| Write-Error "Failed to create a new certificate." | ||
| return $null | ||
| } | ||
|
|
||
| Write-Host "New certificate created with thumbprint: $($cert.Thumbprint)" | ||
| } | ||
| else { | ||
| Write-Host "Using existing certificate with thumbprint: $($cert.Thumbprint)" | ||
| } | ||
|
|
||
| $cerPath = "$env:TEMP\temp_cert.cer" | ||
| [void](Export-Certificate -Cert $cert -FilePath $cerPath -Force) | ||
|
|
||
| if (-not (ImportAndVerifyCertificate -cerPath $cerPath -storePath "Cert:\CurrentUser\TrustedPeople")) { return $null } | ||
| if (-not (ImportAndVerifyCertificate -cerPath $cerPath -storePath "Cert:\CurrentUser\Root")) { return $null } | ||
| if (-not (ImportAndVerifyCertificate -cerPath $cerPath -storePath "Cert:\LocalMachine\Root")) { | ||
| Write-Warning "Failed to import to LocalMachine\Root (admin may be required)" | ||
| return $null | ||
| } | ||
|
|
||
| return $cert | ||
| } | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,29 @@ | ||
| param ( | ||
| [string]$certSubject = "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US", | ||
| [string[]]$TargetPaths = "C:\PowerToys\ARM64\Release\WinUI3Apps\CmdPal\AppPackages\Microsoft.CmdPal.UI_0.0.1.0_Test\Microsoft.CmdPal.UI_0.0.1.0_arm64.msix" | ||
| ) | ||
|
|
||
| . "$PSScriptRoot\cert-management.ps1" | ||
| $cert = EnsureCertificate -certSubject $certSubject | ||
|
|
||
| if (-not $cert) { | ||
| Write-Error "Failed to prepare certificate." | ||
| exit 1 | ||
| } | ||
|
|
||
| Write-Host "Certificate ready: $($cert.Thumbprint)" | ||
|
|
||
| if (-not $TargetPaths -or $TargetPaths.Count -eq 0) { | ||
| Write-Error "No target files provided to sign." | ||
| exit 1 | ||
| } | ||
|
|
||
| foreach ($filePath in $TargetPaths) { | ||
| if (-not (Test-Path $filePath)) { | ||
| Write-Warning "Skipping: File does not exist - $filePath" | ||
| continue | ||
| } | ||
|
|
||
| Write-Host "Signing: $filePath" | ||
| & signtool sign /sha1 $($cert.Thumbprint) /fd SHA256 /t http://timestamp.digicert.com "$filePath" | ||
| } |
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I see the caller, e.g.
PowerToys/src/modules/cmdpal/CmdPalModuleInterface/dllmain.cpp
Line 231 in d4e577b
If we return empty, no further logging will be happening.
In the past, interestingly it may throw "exception", given the later on code will return a "null" value.