Skip to content

[release/v7.4.21] Support macOS signatures in nonofficial pipelines - #28051

Merged
Aditya Patwardhan (adityapatwardhan) merged 1 commit into
PowerShell:release/v7.4.21from
adityapatwardhan:backport/release/v7.4.21/27976-b376b3f34
Sep 22, 2026
Merged

Aditya Patwardhan (adityapatwardhan) merged 1 commit into
PowerShell:release/v7.4.21from
adityapatwardhan:backport/release/v7.4.21/27976-b376b3f34

Conversation

@adityapatwardhan

Copy link
Copy Markdown
Member

Backport of #27976 to release/v7.4.21

Triggered by Aditya Patwardhan (@adityapatwardhan) on behalf of Justin Chung (@jshigetomi)

Original CL Label: CL-BuildPackaging

/cc @PowerShell/powershell-maintainers

Impact

REQUIRED: Choose either Tooling Impact or Customer Impact (or both). At least one checkbox must be selected.

Tooling Impact

  • Required tooling change
  • Optional tooling change (include reasoning)

Required packaging pipeline change that accepts or repairs ad-hoc Mach-O signatures in nonofficial builds while preserving production Developer ID requirements for official builds.

Customer Impact

  • Customer reported
  • Found internally

Regression

REQUIRED: Check exactly one box.

  • Yes
  • No

This is not a regression.

Testing

The original PR was validated by coordinated nonofficial build 715578 and packages run 715615 for x64 and arm64 macOS signature handling; its YAML and inline PowerShell parsed successfully and PSScriptAnalyzer passed. The release-branch backport cherry-picked without conflicts, git diff --check upstream/release/v7.4.21...HEAD passed, and the MCP PowerShell syntax validator reported the new helper valid with no conflict markers. Full platform validation is delegated to PR CI.

Risk

REQUIRED: Check exactly one box.

  • High
  • Medium
  • Low

High risk because the change affects macOS signing verification and package-pipeline behavior across official and nonofficial builds. Risk is mitigated by keeping official builds verification-only, limiting repair to failed nonofficial signatures, and requiring strict native codesign verification afterward.

Co-authored-by: Justin Chung <[email protected]>
Co-authored-by: Copilot App <[email protected]>
Copilot-Session: 282853d0-d027-4558-9425-624a244cb9a3
@adityapatwardhan Aditya Patwardhan (adityapatwardhan) added the CL-BuildPackaging Indicates that a PR should be marked as a build or packaging change in the Change Log label Sep 21, 2026
Copilot AI lite review requested due to automatic review settings September 21, 2026 22:47
@adityapatwardhan Aditya Patwardhan (adityapatwardhan) added the CL-BuildPackaging Indicates that a PR should be marked as a build or packaging change in the Change Log label Sep 21, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The review identified two moderate createdump coverage gaps and a native-command handling nit that should be addressed before approval.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 Low severity

Open (1)
What changed in this PR

This backport adds nonofficial macOS signature repair and validation while preserving strict official-build verification.

Changes:

  • Adds macOS signature verification and ad-hoc repair.
  • Propagates OfficialBuild through packaging stages.
  • Updates validation and invokes the helper during package builds.
File Summary Final review comments
tools/​packaging/​Update-MacOSCodeSignature.ps1 Verifies and repairs macOS signatures. Moderate (1 vote): include createdump in verification/repair. Nit (2 votes): use Start-NativeExecution for codesign calls on lines 28 and 46.
.pipelines/​templates/​stages/​PowerShell-Packages-Stages.yml Forwards official-build status. No final comments.
.pipelines/​templates/​mac.yml Validates Developer ID or ad-hoc signatures. Moderate (1 vote): include createdump in the signing-job enumeration.
.pipelines/​templates/​mac-package-build.yml Invokes signature processing during packaging. No final comments.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +16 to +29
)

$binaries = @(
Get-ChildItem -LiteralPath $Path -Recurse -File |
Where-Object { $_.Name -eq 'pwsh' -or $_.Extension -eq '.dylib' }
)

if ($binaries.Count -eq 0) {
throw "No Mach-O binaries were found in '$Path'."
}

foreach ($binary in $binaries) {
& codesign --verify --deep --strict --verbose=4 $binary.FullName
if ($LASTEXITCODE -eq 0) {
@adityapatwardhan
Aditya Patwardhan (adityapatwardhan) merged commit 8661c83 into PowerShell:release/v7.4.21 Sep 22, 2026
40 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CL-BuildPackaging Indicates that a PR should be marked as a build or packaging change in the Change Log

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants