Skip to content

[release/v7.6.7] Support macOS signatures in nonofficial pipelines - #28076

Merged
Aditya Patwardhan (adityapatwardhan) merged 1 commit into
PowerShell:release/v7.6.7from
adityapatwardhan:backport/release/v7.6.7/27976-b376b3f34
Sep 24, 2026
Merged

Aditya Patwardhan (adityapatwardhan) merged 1 commit into
PowerShell:release/v7.6.7from
adityapatwardhan:backport/release/v7.6.7/27976-b376b3f34

Conversation

@adityapatwardhan

Copy link
Copy Markdown
Member

Backport of #27976 to release/v7.6.7

Triggered by Aditya Patwardhan (@adityapatwardhan) on behalf of Justin Chung (@jshigetomi)

Original CL Label: CL-BuildPackaging

/cc @PowerShell/powershell-maintainers

Impact

REQUIRED: Choose either Tooling Impact or Customer Impact (or both). At least one checkbox must be selected.

Tooling Impact

  • Required tooling change
  • Optional tooling change (include reasoning)

Required packaging pipeline change that accepts supported Microsoft Developer ID or ad-hoc signatures for nonofficial coordinated builds, repairs Mach-O binaries that fail native verification on macOS package agents, and retains production Developer ID verification for official builds.

Customer Impact

  • Customer reported
  • Found internally

Regression

REQUIRED: Check exactly one box.

  • Yes
  • No

This is not a regression.

Testing

The original change was validated in coordinated nonofficial build 715578 for x64 and arm64 signature validation and packages run 715615 for both macOS package architectures with strict native codesign verification. The changed YAML and inline PowerShell parsed successfully, PSScriptAnalyzer passed for the new helper, and local scenarios covered nonofficial repair and official verification-only behavior. For this conflict-free backport, the cherry-picked PowerShell helper passed parser validation, all changed files were checked for conflict markers, git diff --check passed, and CI will provide final release-branch validation.

Risk

REQUIRED: Check exactly one box.

  • High
  • Medium
  • Low

High risk because this changes macOS package signing and validation behavior in release pipelines. The change is narrowly scoped to Mach-O signature handling, preserves verification-only behavior for official builds, requires strict native codesign verification before packaging, and was validated in coordinated nonofficial x64 and arm64 builds.

Co-authored-by: Justin Chung <[email protected]>
Co-authored-by: Copilot App <[email protected]>
Copilot-Session: 282853d0-d027-4558-9425-624a244cb9a3
@adityapatwardhan Aditya Patwardhan (adityapatwardhan) added the CL-BuildPackaging Indicates that a PR should be marked as a build or packaging change in the Change Log label Sep 23, 2026
Copilot AI lite review requested due to automatic review settings September 23, 2026 23:30
@adityapatwardhan Aditya Patwardhan (adityapatwardhan) added the CL-BuildPackaging Indicates that a PR should be marked as a build or packaging change in the Change Log label Sep 23, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Fix the incorrect checkout paths and wrap all native codesign calls as requested.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 High severity · 1 Medium severity

Open (2)
What changed in this PR

Backports macOS signature validation and repair for nonofficial packaging pipelines while preserving official-build verification.

Changes:

  • Adds ad-hoc signature repair and verification.
  • Propagates OfficialBuild to macOS package jobs.
  • Accepts Developer ID or ad-hoc signatures for coordinated validation.
File Summary
tools/​packaging/​Update-MacOSCodeSignature.ps1 Adds signature validation and repair; native codesign calls require the repository’s execution wrapper.
.pipelines/​templates/​stages/​PowerShell-Packages-Stages.yml Passes official-build configuration to macOS jobs.
.pipelines/​templates/​mac.yml Validates supported macOS signatures.
.pipelines/​templates/​mac-package-build.yml Runs signature processing; entitlements and script paths must include the PowerShell checkout directory.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +85 to +87
EntitlementsPath = "$(Build.SourcesDirectory)/assets/macos-entitlements.plist"
}
displayName: 'Verify Apple codesign on signed binaries'
& "$(Build.SourcesDirectory)/tools/packaging/Update-MacOSCodeSignature.ps1" @signatureParameters
}

foreach ($binary in $binaries) {
& codesign --verify --deep --strict --verbose=4 $binary.FullName
@adityapatwardhan
Aditya Patwardhan (adityapatwardhan) merged commit c1b47f7 into PowerShell:release/v7.6.7 Sep 24, 2026
39 checks passed
@adityapatwardhan
Aditya Patwardhan (adityapatwardhan) deleted the backport/release/v7.6.7/27976-b376b3f34 branch September 24, 2026 17:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CL-BuildPackaging Indicates that a PR should be marked as a build or packaging change in the Change Log

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants