Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
364 commits
Select commit Hold shift + click to select a range
75e48bf
trace2:gvfs:experiment: increase default event depth for unpack-tree …
jeffhostetler Jul 25, 2019
630809f
t5799: cleanup wc-l and grep-c lines
jeffhostetler Nov 13, 2019
6da2653
fetch: reprepare packs before checking connectivity
derrickstolee Mar 12, 2020
fd4d860
gvfs-helper: add --max-retries to prefetch verb
jeffhostetler Apr 12, 2023
e7b8d00
t5799: explicitly test gvfs-helper --fallback and --no-fallback
jeffhostetler Jun 28, 2024
ab3ce37
trace2:gvfs:experiment: add data for check_updates() in unpack_trees()
jeffhostetler Jul 25, 2019
e0359c5
gvfs-helper: verify loose objects after write
derrickstolee Sep 18, 2020
bec0553
gvfs-helper: retry when creating temp files
derrickstolee Dec 26, 2019
7fe5232
t5799: add tests to detect corrupt pack/idx files in prefetch
jeffhostetler Apr 13, 2023
5dd772c
gvfs-helper: don't fallback with new config
derrickstolee Jun 27, 2024
74946f0
Trace2:gvfs:experiment: capture more 'tracking' details
jeffhostetler Jul 26, 2019
7556764
t7599: create corrupt blob test
jeffhostetler Sep 18, 2020
acf2d9e
sparse: avoid warnings about known cURL issues in gvfs-helper.c
derrickstolee Aug 3, 2021
10db8bd
gvfs-helper: ignore .idx files in prefetch multi-part responses
jeffhostetler Apr 13, 2023
a5d20e9
scalar: set the config write-lock timeout to 150ms
dscho May 18, 2021
1f075cf
.github/actions/akv-secret: add action to get secrets
mjcheetham Apr 1, 2025
c5787fb
scalar: set the config write-lock timeout to 150ms
dscho May 18, 2021
6b1da47
release: create initial Windows installer build workflow
dscho Apr 29, 2026
3b168a0
scalar: upgrade the config lock timeout setting automagically
dscho Sep 16, 2026
d4bf00e
help: special-case HOST_CPU `universal`
jeffhostetler Oct 17, 2023
870a629
config: (handle and) warn about deprecated lock timeout setting
dscho Sep 16, 2026
497191f
release: add Mac OSX installer build
vdye Jul 16, 2021
5c9d88a
scalar: add docs from microsoft/scalar
derrickstolee Jun 16, 2021
7842b98
Merge branch 'scalar-gentler-config-locking'
dscho May 19, 2021
9b95aaf
release: build unsigned Ubuntu .deb package
vdye Jul 16, 2021
9de5df2
Merge branch 'scalar-extra-docs'
dscho Nov 16, 2021
d07d812
release: add signing step for .deb package
vdye Jul 16, 2021
5367252
scalar (Windows): use forward slashes as directory separators
dscho May 10, 2022
cbdcbc8
release: create draft GitHub release with packages & installers
vdye Jul 16, 2021
fb2e14d
dist: archive HEAD instead of HEAD^{tree}
vdye Dec 2, 2021
1fcec3b
update-microsoft-git: create barebones builtin
derrickstolee Apr 29, 2021
ae9b78c
.github: reinstate ISSUE_TEMPLATE.md for microsoft/git
derrickstolee Mar 16, 2022
22a7966
scalar: add retry logic to run_git()
derrickstolee Jun 17, 2021
5ecf3bb
test-gvfs-protocol: add cache_http_503 to mayhem
jeffhostetler Jun 28, 2024
f3f0e5b
Disable the `monitor-components` workflow in msft-git
dscho May 13, 2022
c0a3a17
build-git-installers: publish gpg public key
ldennington Oct 24, 2023
9791d9d
release: include GIT_BUILT_FROM_COMMIT in MacOS build
vdye Dec 2, 2021
36cf2f7
update-microsoft-git: Windows implementation
derrickstolee Apr 29, 2021
f9ce800
.github: update PULL_REQUEST_TEMPLATE.md
derrickstolee Mar 16, 2022
e4a5905
scalar: support the `config` command for backwards compatibility
dscho May 27, 2021
255fd47
Merge branch 'microsoft/vfs-2.35.0'
dscho Oct 7, 2021
6dbf7cf
t5799: add unit tests for new `gvfs.fallback` config setting
jeffhostetler Jun 28, 2024
c838597
maintenance: care about gvfs.sharedCache config
derrickstolee Dec 15, 2020
219ebba
unpack-trees:virtualfilesystem: Improve efficiency of clear_ce_flags
neerajsi-msft2 Feb 6, 2021
de6f508
.github: enable windows builds on microsoft fork
derrickstolee Mar 8, 2023
459064f
release: continue pestering until user upgrades
derrickstolee Oct 6, 2021
4260d8a
release: remove the obsolete GitHub installer workflow
ldennington Aug 17, 2022
57863d3
update-microsoft-git: use brew on macOS
derrickstolee Apr 29, 2021
a4164b8
Adjust README.md for microsoft/git
May 4, 2021
637a8d7
scalar: implement a minimal JSON parser
dscho Apr 26, 2021
5a7e556
scalar clone: support GVFS-enabled remote repositories
dscho Aug 24, 2021
e831f8d
test-gvfs-protocol: also serve smart protocol
dscho Apr 16, 2021
f71f87e
gvfs-helper: add the `endpoint` command
dscho Apr 26, 2021
7ac7981
dir_inside_of(): handle directory separators correctly
dscho May 14, 2021
4a3752c
scalar: disable authentication in unattended mode
dscho May 6, 2021
6123963
abspath: make strip_last_path_component() global
derrickstolee Oct 4, 2022
83e9639
scalar: do initialize `gvfs.sharedCache`
dscho May 3, 2021
fdcad07
scalar diagnose: include shared cache info
dscho Jun 1, 2021
01b3708
scalar: only try GVFS protocol on https:// URLs
dscho Apr 28, 2021
25b769d
scalar: verify that we can use a GVFS-enabled repository
dscho Apr 16, 2021
d79d71c
scalar: add the `cache-server` command
dscho Apr 23, 2021
f50912e
scalar: add a test toggle to skip accessing the vsts/info endpoint
dscho May 12, 2021
d7941ff
scalar: adjust documentation to the microsoft/git fork
dscho Jan 25, 2022
bfd6b9f
scalar: enable untracked cache unconditionally
derrickstolee Jun 21, 2021
cbb2ebb
scalar: parse `clone --no-fetch-commits-and-trees` for backwards comp…
dscho Aug 24, 2021
7e1217e
scalar: make GVFS Protocol a forced choice
derrickstolee May 1, 2024
538a7a8
scalar: work around GVFS Protocol HTTP/2 failures
Copilot May 22, 2025
8e728f4
scalar diagnose: accommodate Scalar's Functional Tests
dscho May 9, 2022
862ef02
gvfs-helper-client: clean up server process(es)
derrickstolee May 23, 2025
4670592
Merge branch 'scalar'
dscho Aug 24, 2021
04c574e
ci: run Scalar's Functional Tests
dscho Jun 8, 2021
75fdf5d
Merge branch 'scalar-with-gvfs'
dscho May 3, 2021
fd0b38a
sparse-checkout: add config to disable deleting dirs
derrickstolee Aug 22, 2021
be59a89
add/rm: allow adding sparse entries when virtual
derrickstolee Jun 29, 2021
5a76643
scalar: upgrade to newest FSMonitor config setting
vdye Apr 5, 2022
21e5611
Merge branch 'run-scalar-functional-tests'
dscho Nov 16, 2021
21beda0
diff: ignore sparse paths in diffstat
derrickstolee Jul 26, 2021
480b521
Merge pull request #392: add: allow adding sparse entries when virtual
derrickstolee Jul 1, 2021
1f236df
repo-settings: enable sparse index by default
derrickstolee Jun 15, 2021
7960031
TO-UPSTREAM: sequencer: avoid progress when stderr is redirected
derrickstolee Sep 23, 2021
c9342d0
Merge branch 'scalar-reconfigure'
dscho Jun 1, 2021
cf1c47d
sparse-index: add ensure_full_index_with_reason()
derrickstolee Sep 30, 2024
ff6b08e
treewide: add reasons for expanding index
derrickstolee Sep 30, 2024
404c0cf
Merge core VFS features
dscho Jun 11, 2018
0b9952a
treewide: custom reasons for expanding index
derrickstolee Sep 30, 2024
5a69532
Merge pull request #410: Sparse Index: latest integrations
derrickstolee Aug 24, 2021
a32d2a6
Merge advanced VFS-specific features
dscho Jun 11, 2018
2232ab1
sparse-index: add macro for unaudited expansions
derrickstolee Sep 30, 2024
909041c
TO-CHECK: t1092: use quiet mode for rebase tests
derrickstolee Oct 31, 2021
04fb33e
Merge pull request #414: Make sparse index the default
derrickstolee Aug 26, 2021
fdbb953
Permit `repack` command in Scalar clones (#732)
mjcheetham Mar 31, 2025
a3803a7
Docs: update sparse index plan with logging
derrickstolee Sep 30, 2024
41d9d91
reset: fix mixed reset when using virtual filesystem
Mar 15, 2017
d1a0c3d
Merge pull request #432: sequencer: avoid progress when stderr is red…
derrickstolee Sep 23, 2021
6f43764
Merge virtualfilesystem hook
dscho Jun 11, 2018
016b76e
sparse-index: log failure to clear skip-worktree
derrickstolee Sep 30, 2024
6c84673
diff(sparse-index): verify with partially-sparse
ldennington Sep 10, 2021
b2c484d
Merge pull request #494: reset: fix mixed reset when using virtual fi…
derrickstolee Apr 4, 2022
754bf69
Merge updates to serialized status
dscho Jun 11, 2018
87f33f9
stash: use -f in checkout-index child process
derrickstolee Sep 30, 2024
3195c9e
stash: expand testing for `git stash -u`
vdye Sep 22, 2021
f9bea6d
Merge pull request #419 from ldennington/sparse-index-diff
ldennington Sep 12, 2021
23bd2c9
Merge trace2 experimental regions
jeffhostetler Apr 23, 2019
6f7b471
sparse-index: do not copy hashtables during expansion
derrickstolee Sep 27, 2024
518a4b1
Merge pull request #430 from vdye/sparse-index/clean
vdye Sep 23, 2021
9917230
Merge first wave of gvfs-helper feature
jeffhostetler Nov 14, 2019
25f42a7
Fix rare segfault in sparse-index (#690)
dscho Oct 9, 2024
f9ca743
Merge gvfs-helper prefetch feature
derrickstolee Dec 17, 2019
13550d9
Harden gvfs-helper to validate the packfiles in a multipart prefetch …
jeffhostetler Apr 17, 2023
1781d62
gvfs-helper: add gvfs.fallback and unit tests (#665)
dscho Jul 1, 2024
25deb6c
Merge pull request #301: Update 'git maintenance' to match upstream
derrickstolee Dec 15, 2020
c113f2d
Merge pull request #315: unpack-trees:virtualfilesystem: Improve effi…
derrickstolee Feb 16, 2021
907ce68
Merge branch 'adjust-g4w-workflows'
dscho May 13, 2022
90f2bad
Merge pull request #399 from vdye/feature/build-installers
vdye Jul 29, 2021
8698124
Merge pull request #472 from vdye/ms/macos-build-options
vdye Dec 6, 2021
9faf45f
Merge pull request #329: Add `git update-microsoft-git`
derrickstolee Apr 30, 2021
eff3c45
TO-UPSTREAM: sub-process: avoid leaking `cmd`
dscho Dec 18, 2024
7b2ecae
Merge pull request #333: update microsoft/git README
derrickstolee May 17, 2021
9b04f1a
remote-curl: release filter options before re-setting them
dscho Dec 18, 2024
cff9e94
Merge pull request #371 from dscho/run-scalar-functional-tests-and-fi…
dscho Jun 9, 2021
b2707e1
transport: release object filter options
dscho Dec 18, 2024
7b6206f
Merge branch 'sparse-index-stuff'
dscho Jun 17, 2022
381f03f
maintenance: add cache-local-objects maintenance task
mjcheetham Jan 14, 2025
a5a64ee
push: don't reuse deltas with path walk
derrickstolee Nov 16, 2024
73346e0
Merge branch 'leak-fixes'
dscho Dec 18, 2024
c9b802b
scalar.c: add cache-local-objects task
mjcheetham Jan 23, 2025
1bf16c6
pack-objects: don't reuse deltas with path walk (#707)
dscho Dec 19, 2024
7d98df5
hooks: add custom post-command hook config
derrickstolee Mar 25, 2025
82e49c3
maintenance: add new `cache-local-objects` maintenance task (#720)
mjcheetham Jan 31, 2025
eadfb3d
revision: defensive programming
dscho Dec 16, 2022
1d11c5d
get_parent(): defensive programming
dscho Dec 16, 2022
de0db57
fetch-pack: defensive programming
dscho Dec 16, 2022
ecef271
unparse_commit(): defensive programming
dscho Dec 16, 2022
8182273
verify_commit_graph(): defensive programming
dscho Dec 16, 2022
e9a0fa5
stash: defensive programming
dscho Dec 16, 2022
ce409d6
codeql: run static analysis as part of CI builds
dscho Aug 9, 2022
4584b36
cat_one_file(): make it easy to see that the `size` variable is initi…
dscho Oct 27, 2022
e8dfe54
stash: defensive programming
dscho Dec 16, 2022
8b429e7
TO-UPSTREAM: Docs: fix asciidoc failures from short delimiters
derrickstolee Mar 25, 2025
10f28ea
codeql: publish the sarif file as build artifact
dscho Mar 22, 2023
b83b568
fsck: avoid using an uninitialized variable
dscho Dec 16, 2022
bd57977
push: defensive programming
dscho Dec 16, 2022
aa4c7bc
test-tool repository: check return value of `lookup_commit()`
dscho Dec 16, 2022
4c96fdd
hooks: make hook logic memory-leak free
derrickstolee Mar 25, 2025
cc2fb95
codeql: disable a couple of non-critical queries for now
dscho Mar 21, 2025
c023a8c
load_revindex_from_disk(): avoid accessing uninitialized data
dscho Dec 16, 2022
fe28fdb
fetch: defensive programming
dscho Dec 16, 2022
6c0fec2
shallow: handle missing shallow commits gracefully
dscho Dec 16, 2022
0f6ccae
t0401: test post-command for alias, version, typo
derrickstolee Nov 7, 2025
4b9108d
date: help CodeQL understand that there are no leap-year issues here
dscho Jul 23, 2025
24347f7
load_pack_mtimes_file(): avoid accessing uninitialized data
dscho Dec 16, 2022
0ab6b13
inherit_tracking(): defensive programming
dscho Dec 16, 2022
f910864
commit-graph: suppress warning about using a stale stack addresses
dscho Dec 17, 2022
c73f70e
hooks: better handle config without gitdir
derrickstolee Nov 7, 2025
b807b8b
help: help CodeQL understand that consuming envvars is okay here
dscho Jul 23, 2025
2d80402
ctype: help CodeQL understand that `sane_istest()` does not access ar…
dscho Jul 23, 2025
889b5bc
ctype: accommodate for CodeQL misinterpreting the `z` in `mallocz()`
dscho Jul 23, 2025
f22e7cb
Merge branch 'uninitialized-variables'
dscho Oct 27, 2022
9bd4d71
strbuf_read: help with CodeQL misunderstanding that `strbuf_read()` d…
dscho Jul 23, 2025
cb947d7
Merge branch 'defensive-programming'
dscho Mar 21, 2025
65e9edc
codeql: also check JavaScript code
dscho Jul 24, 2025
90075bf
Merge branch 'codeql-fixes'
dscho Mar 21, 2025
586f61a
scalar: add run_git_argv
mjcheetham Dec 17, 2025
2399762
Merge branch 'codeql'
dscho Mar 21, 2025
5ce8b19
hooks: add custom post-command hook config (#736)
dscho Apr 7, 2025
3872753
scalar: add --ref-format option to scalar clone
mjcheetham Dec 17, 2025
9cf8ec4
Merge branch 'codeql'
dscho Mar 21, 2025
86a5d01
gvfs-helper: skip collision check for loose objects
derrickstolee Jan 8, 2026
06ab468
Add `--ref-format` option to scalar clone (port to `vfs-2.52.0`) (#832)
dscho Jan 8, 2026
2ab4358
t5799: update cache-server methods for multiple instances
derrickstolee Jan 17, 2026
60cd821
gvfs-helper: override cache server for prefetch
derrickstolee Jan 5, 2026
96b644d
gvfs-helper: override cache server for get
derrickstolee Jan 5, 2026
48a86cb
gvfs-helper: override cache server for post
derrickstolee Jan 5, 2026
730a739
t5799: add test for all verb-specific cache-servers together
derrickstolee Jan 17, 2026
8f2d027
gvfs-helper: emit advice on transient errors
derrickstolee Jan 8, 2026
b573a64
lib-gvfs-helper: create helper script for protocol tests
derrickstolee Jan 18, 2026
41b6372
gvfs-helper: avoid collision check for packfiles
derrickstolee Jan 8, 2026
b4b2e41
t579*: split t5799 into several parts
derrickstolee Jan 18, 2026
6d6ff8d
gvfs-helper: prevent and/or give advice on repeated downloads to shar…
dscho Jan 9, 2026
65a1b01
scalar: add --<verb>-cache-server-url options
derrickstolee Jan 23, 2026
b9c5de0
Restore previous errno after post command hook
tyrielv Feb 10, 2026
250da7f
gvfs-helper: add config to incrementally replace cache servers (#836)
derrickstolee Jan 22, 2026
328b363
t9210: differentiate origin and cache servers
derrickstolee Jan 28, 2026
7b325ed
Restore previous errno after post command hook (#860)
dscho Feb 10, 2026
8b82747
unpack-trees: skip lstats for deleted VFS entries in checkout
Mar 6, 2026
69afe97
scalar: add --<verb>-cache-server-url options (#849)
dscho Feb 11, 2026
7f1e0fc
worktree: conditionally allow worktree on VFS-enabled repos
Mar 26, 2026
5749118
unpack-trees: skip lstats for deleted VFS entries in checkout (#865)
dscho Mar 26, 2026
e8189bc
gvfs-helper: send X-Session-Id headers
derrickstolee Mar 24, 2026
8368c93
gvfs-helper: create shared object cache if missing
derrickstolee Feb 12, 2026
f9f9d26
worktree: conditionally allow worktree on VFS-enabled repos (#868)
mjcheetham Mar 27, 2026
61c0d3f
gvfs: add gvfs.sessionKey config
derrickstolee Mar 24, 2026
15e74ed
gvfs-helper: create shared object cache if missing (#861)
mjcheetham Mar 27, 2026
c43dbab
gvfs: clear DIE_IF_CORRUPT in streaming incore fallback
tyrielv Mar 27, 2026
c912e39
gvfs-helper: emit X-Session-Id headers for requests (#862)
mjcheetham Mar 27, 2026
786638a
worktree remove: use GVFS_SUPPORTS_WORKTREES for skip-clean-check gate
tyrielv Mar 30, 2026
5027795
gvfs: clear DIE_IF_CORRUPT in streaming incore fallback (#873)
dscho Mar 28, 2026
7144c57
ci: add new VFS for Git functional tests workflow
mjcheetham Mar 30, 2026
63628f0
worktree remove: use gvfs_config_is_set for skip-clean-check gate (#875)
mjcheetham Apr 2, 2026
351b889
azure-pipelines: add stub release pipeline for Azure
mjcheetham Apr 17, 2026
4e8d9d2
Add VFS for Git functional tests workflow (#874)
mjcheetham Apr 2, 2026
20e9452
azure-pipelines: add ESRP code signing
mjcheetham Apr 30, 2026
5160950
azure-pipelines: allow overriding Git version
mjcheetham May 15, 2026
c95d2e5
azure-pipelines: build, sign and stage the Linux Debian package
dscho Apr 30, 2026
807d852
azure-pipelines: add signed macOS ARM64 releases
dscho Apr 30, 2026
6f802d1
azure-pipelines: build, sign and stage the Windows installer
mjcheetham May 1, 2026
cd44034
azure-pipelines: enable on tag push, default ESRP and GitHub release on
dscho May 8, 2026
7cfead7
gvfs-helper: separate packfile extraction from indexing
derrickstolee Apr 7, 2026
1b9fed5
blame: add blame.renames, blame.renameThreshold, blame.renameLimit
Apr 20, 2026
9334b6d
diff: add renameThreshold configuration option
tyrielv Apr 8, 2026
c78372c
azure-pipelines: add stub release pipeline for Azure (#886)
mjcheetham Apr 17, 2026
9aec7c7
release: binskim for Windows
mjcheetham May 21, 2026
9d90d6f
gvfs-helper: run prefetch index-pack in parallel
derrickstolee Apr 7, 2026
fe37339
blame: add blame.rename* configuration (#894)
dscho Apr 22, 2026
f3a5146
diff: add renameThreshold configuration option (#878)
dscho Apr 20, 2026
1453163
release: suppress unfixable binskim findings
mjcheetham May 28, 2026
333e8df
gvfs-helper: add gvfs.prefetchThreads config for parallel prefetch
derrickstolee Apr 21, 2026
8178cca
Synchronize `vfs-2.54.0` with `vfs-2.53.0` (`git blame` changes) (#896)
dscho Apr 27, 2026
b88a912
binskim: add baseline
microsoft-github-policy-service[bot] May 29, 2026
aea9d82
scalar: Install prefetch packfiles in parallel (#876)
dscho Apr 28, 2026
32a70e4
release-homebrew: add a hand-run script to replace the workflow
dscho Jul 7, 2026
e1e2078
checkout: preserve skip-worktree for virtual filesystem paths
tyrielv May 14, 2026
18d8be1
azure-pipelines: migrate installer release pipeline from GitHub Actio…
dscho May 19, 2026
f16752c
release-vfsforgit: add hand-run script to supersede the workflow
dscho Jul 7, 2026
2e8125b
checkout: preserve skip-worktree for virtual filesystem paths (forwar…
dscho May 27, 2026
ac2bd7e
.github: add release-winget.sh to open winget-pkgs PR
dscho Jul 7, 2026
463af91
ci(vfs): install the GCC-compatible Rust target before building
dscho Jun 11, 2026
6c8b20f
trace2: tolerate failed timestamp formatting
derrickstolee Jul 13, 2026
5475b94
Replace release workflows with scripts (v2.55 version) (#953)
dscho Jul 9, 2026
8ec064c
reset --mixed: clear skip-worktree for all changed entries in VFS mode
tyrielv Jun 11, 2026
874e447
[2.55.0] fixup! gvfs: add global command pre and post hook procs (#956)
dscho Jul 15, 2026
294138c
send-pack: add gvfs.negativeRefCheck to skip missing negatives
derrickstolee Jul 24, 2026
514395b
reset --mixed: clear skip-worktree for all changed entries in VFS mod…
dscho Jul 23, 2026
f5ca4ad
scalar: add --[no-]prefetch option
derrickstolee Aug 19, 2026
78c3276
odb: scan all sources' packfiles before loose objects
tyrielv Aug 7, 2026
cf14d10
send-pack: add gvfs.negativeRefCheck to skip missing negatives (#967)
dscho Jul 27, 2026
4356260
gvfs-helper: add gvfs.postThreads config option
derrickstolee Aug 24, 2026
49856fe
scalar: request for commit via POST
derrickstolee Aug 20, 2026
85d4a65
odb: scan all sources' packfiles before loose objects (#975)
dscho Aug 10, 2026
b9221b9
http: factor reusable curl handle preparation
derrickstolee Sep 4, 2026
88ad4f4
scalar: add --[no-]prefetch (#979)
derrickstolee Aug 26, 2026
8259bdb
gvfs-helper: parallelize POST object requests
derrickstolee Sep 4, 2026
b366cf7
odb: warn when ignoring unusable alternates
dscho Sep 17, 2026
d0c509c
gvfs-helper: preserve POST failure handling in parallel mode
derrickstolee Sep 4, 2026
6d5c156
ci: avoid vcpkg telemetry contention during MSBuild
dscho Sep 18, 2026
10ae4bb
t5798: test parallel POST object requests
derrickstolee Sep 4, 2026
497e82d
rust: honor the active MinGW prefix when invoking Cargo
dscho Sep 18, 2026
1348610
t5798: test parallel POST failure handling
derrickstolee Sep 4, 2026
af775f2
cmake: default the Windows runtime prefix to UCRT64
dscho Sep 18, 2026
0faae01
gvfs-helper: parallelize POST requests (#980)
dscho Sep 21, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
106 changes: 106 additions & 0 deletions .azure-pipelines/esrp/sign.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,106 @@
# Reusable step template for ESRP code signing via EsrpCodeSigning@6.
#
# For macOS, ESRP requires files to be submitted as a zip archive.
# Set 'useArchive: true' to automatically handle the
# copy → zip → sign → extract cycle. For Windows/Linux where ESRP
# can sign files directly in a folder, leave it as false (default).
#
parameters:
- name: displayName
type: string
- name: folderPath
type: string
- name: pattern
type: string
- name: inlineOperation
type: string
# When true, matching files are copied to a staging dir, zipped,
# signed, and extracted back to folderPath.
- name: useArchive
type: boolean
default: false
# ESRP connection parameters (defaults use pipeline variables)
- name: connectedServiceName
type: string
default: $(esrpAppConnectionName)
- name: appRegistrationClientId
type: string
default: $(esrpClientId)
- name: appRegistrationTenantId
type: string
default: $(esrpTenantId)
- name: authAkvName
type: string
default: $(esrpKeyVaultName)
- name: authSignCertName
type: string
default: $(esrpSignReqCertName)
- name: serviceEndpointUrl
type: string
default: $(esrpEndpointUrl)

steps:
- ${{ if eq(parameters.useArchive, true) }}:
- task: DeleteFiles@1
displayName: 'Clean staging dir for ${{ parameters.displayName }}'
inputs:
SourceFolder: '$(Agent.TempDirectory)/esrp-staging'
Contents: '*'
RemoveSourceFolder: true
- task: CopyFiles@2
displayName: 'Collect files for ${{ parameters.displayName }}'
inputs:
SourceFolder: '${{ parameters.folderPath }}'
Contents: '${{ parameters.pattern }}'
TargetFolder: '$(Agent.TempDirectory)/esrp-staging/contents'
- task: ArchiveFiles@2
displayName: 'Archive files for ${{ parameters.displayName }}'
inputs:
rootFolderOrFile: '$(Agent.TempDirectory)/esrp-staging/contents'
includeRootFolder: false
archiveType: zip
archiveFile: '$(Agent.TempDirectory)/esrp-staging/archive.zip'
- task: EsrpCodeSigning@6
displayName: '${{ parameters.displayName }}'
inputs:
connectedServiceName: '${{ parameters.connectedServiceName }}'
useMSIAuthentication: true
appRegistrationClientId: '${{ parameters.appRegistrationClientId }}'
appRegistrationTenantId: '${{ parameters.appRegistrationTenantId }}'
authAkvName: '${{ parameters.authAkvName }}'
authSignCertName: '${{ parameters.authSignCertName }}'
serviceEndpointUrl: '${{ parameters.serviceEndpointUrl }}'
folderPath: '$(Agent.TempDirectory)/esrp-staging'
pattern: 'archive.zip'
useMinimatch: true
signConfigType: inlineSignParams
inlineOperation: ${{ parameters.inlineOperation }}
- task: ExtractFiles@1
displayName: 'Extract signed files for ${{ parameters.displayName }}'
inputs:
archiveFilePatterns: '$(Agent.TempDirectory)/esrp-staging/archive.zip'
destinationFolder: '${{ parameters.folderPath }}'
overwriteExistingFiles: true
- task: DeleteFiles@1
displayName: 'Clean up staging dir for ${{ parameters.displayName }}'
condition: always()
inputs:
SourceFolder: '$(Agent.TempDirectory)/esrp-staging'
Contents: '*'
RemoveSourceFolder: true
- ${{ else }}:
- task: EsrpCodeSigning@6
displayName: '${{ parameters.displayName }}'
inputs:
connectedServiceName: '${{ parameters.connectedServiceName }}'
useMSIAuthentication: true
appRegistrationClientId: '${{ parameters.appRegistrationClientId }}'
appRegistrationTenantId: '${{ parameters.appRegistrationTenantId }}'
authAkvName: '${{ parameters.authAkvName }}'
authSignCertName: '${{ parameters.authSignCertName }}'
serviceEndpointUrl: '${{ parameters.serviceEndpointUrl }}'
folderPath: '${{ parameters.folderPath }}'
pattern: '${{ parameters.pattern }}'
useMinimatch: true
signConfigType: inlineSignParams
inlineOperation: ${{ parameters.inlineOperation }}
173 changes: 173 additions & 0 deletions .azure-pipelines/esrp/windows/esrpsign.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,173 @@
#!/bin/bash
#
# Sign Windows files using the ESRP client (Authenticode).
# Usage: esrpsign.sh <file1> [file2 ...]
#
# Required environment variables:
# ESRP_TOOL - Path to ESRPClient.exe
# ESRP_AUTH - Path to the ESRP auth JSON file
# SYSTEM_ACCESSTOKEN - ADO system access token (OAuth bearer)
#
# Optional environment variables:
# ESRP_KEYCODE - Signing key code (default: CP-231522)
#
# The script generates the auth and input JSON files and sets the
# following ESRP client environment variables automatically:
# ESRP_AUTH_CONFIG - Path to the auth JSON file
# ESRP_POLICY_CONFIG - Path to the policy JSON file
# ESRP_SESSION_CONFIG - Not set; ESRP client defaults are used
#
set -euo pipefail

if [ $# -lt 1 ]; then
echo "usage: esrpsign.sh <file> [file ...]" >&2
exit 1
fi

if [ -z "${ESRP_TOOL:-}" ]; then
echo "error: ESRP_TOOL environment variable must be set" >&2
exit 1
fi
if [ -z "${ESRP_AUTH:-}" ]; then
echo "error: ESRP_AUTH environment variable must be set" >&2
exit 1
fi
if [ -z "${SYSTEM_ACCESSTOKEN:-}" ]; then
echo "error: SYSTEM_ACCESSTOKEN environment variable must be set" >&2
exit 1
fi

SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
. "$SCRIPT_DIR/../../scripts/windows/utils.sh"

# Check for overriden key code, otherwise use default (Microsoft Third-Party/OSS)
ESRP_KEYCODE="${ESRP_KEYCODE:-CP-231522}"

# Create work dir and resolve its Windows path by cd-ing into it.
WORK_DIR="$(mktemp -d)"
WORK_DIR_WIN="$(cd "$WORK_DIR" && pwd -W | sed 's|/|\\|g')"

echo "==> ESRP signing tool: $ESRP_TOOL"
echo "==> Working directory: $WORK_DIR"

if [ ! -f "$ESRP_TOOL" ]; then
echo "error: ESRPClient.exe not found at $ESRP_TOOL" >&2
exit 1
fi

# Build the SignRequestFiles JSON array
echo "==> Preparing files for signing ($# file(s))..."
files_json=""
for file in "$@"; do
if [ ! -f "$file" ]; then
echo "error: file not found: $file" >&2
exit 1
fi

abs_path="$(cd "$(dirname "$file")" && pwd)/$(basename "$file")"
win_path="$(to_windows_path "$abs_path")"
# Escape backslashes for JSON
win_path_escaped="${win_path//\\/\\\\}"
echo " - $win_path"

if [ -n "$files_json" ]; then
files_json+=","
fi
files_json+="
{
\"SourceLocation\": \"$win_path_escaped\",
\"DestinationLocation\": \"$win_path_escaped\"
}"
done

# Generate the input JSON
input_json="$WORK_DIR/input.json"
output_json="$WORK_DIR/output.json"

echo "==> Generating input JSON: $input_json"
cat > "$input_json" <<-EOF
{
"Version": "1.0.0",
"SignBatches": [
{
"SourceLocationType": "UNC",
"DestinationLocationType": "UNC",
"SignRequestFiles": [$files_json
],
"SigningInfo": {
"Operations": [
{
"KeyCode": "$ESRP_KEYCODE",
"OperationCode": "SigntoolSign",
"ToolName": "sign",
"ToolVersion": "1.0",
"Parameters": {
"OpusName": "Microsoft",
"OpusInfo": "https://www.microsoft.com",
"FileDigest": "/fd SHA256",
"PageHash": "/NPH",
"TimeStamp": "/tr \"http://rfc3161.gtm.corp.microsoft.com/TSS/HttpTspServer\" /td sha256"
}
},
{
"KeyCode": "$ESRP_KEYCODE",
"OperationCode": "SigntoolVerify",
"ToolName": "sign",
"ToolVersion": "1.0",
"Parameters": {}
}
]
}
}
]
}
EOF

# Generate policy JSON
echo "==> Generating policy JSON..."
policy_json="$WORK_DIR/policy.json"
cat > "$policy_json" <<-EOF
{
"Version": "1.0.0",
"Intent": "ProductRelease",
"ContentType": "Binaries",
"ContentOrigin": "1stParty",
"ProductState": "Current",
"Audience": "ExternalBroad"
}
EOF

# Use auth JSON from ESRP_AUTH
export ESRP_AUTH_CONFIG="$(to_windows_path "$ESRP_AUTH")"
export ESRP_POLICY_CONFIG="$WORK_DIR_WIN\\policy.json"

# The ADO system access token is referenced in the auth JSON via the environment
# variable - export this so the ESRP client can pick it up when it runs.
export SYSTEM_ACCESSTOKEN

# Print generated JSON files for debugging
echo "==> Auth JSON:"
cat "$ESRP_AUTH"
echo ""
echo "==> Policy JSON:"
cat "$policy_json"
echo ""
echo "==> Input JSON:"
cat "$input_json"
echo ""

# Sign the files
esrp_tool_win="$(to_windows_path "$ESRP_TOOL")"
input_json_win="$WORK_DIR_WIN\\input.json"
output_json_win="$WORK_DIR_WIN\\output.json"

echo "==> ESRP_AUTH_CONFIG=$ESRP_AUTH_CONFIG"
echo "==> ESRP_POLICY_CONFIG=$ESRP_POLICY_CONFIG"
echo "==> Running: $esrp_tool_win sign -i $input_json_win -o $output_json_win"
"$esrp_tool_win" sign \
-i "$input_json_win" \
-o "$output_json_win"

echo "==> Signing complete."
echo "==> Output JSON:"
cat "$output_json"
69 changes: 69 additions & 0 deletions .azure-pipelines/esrp/windows/setup.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,69 @@
parameters:
- name: serviceConnectionName
type: string
- name: esrpClientId
type: string
- name: keyVaultName
type: string
- name: signCertName
type: string

steps:
- task: EsrpClientTool@5
name: esrpinstall
displayName: 'Install ESRP client'
- task: AzureCLI@2
displayName: 'Set up ESRP environment'
inputs:
azureSubscription: ${{ parameters.serviceConnectionName }}
addSpnToEnvironment: true
scriptType: ps
scriptLocation: inlineScript
inlineScript: |
# Resolve ESRP client tool path (passed via env to avoid PS subexpression issues)
$esrpTool = "$env:ESRPCLIENT_TOOLPATH\$env:ESRPCLIENT_TOOLNAME"
if (-not (Test-Path $esrpTool)) { Write-Error "ESRPClient.exe not found at $esrpTool"; exit 1 }
Write-Host "Found ESRP client: $esrpTool"
Write-Host "##vso[task.setvariable variable=ESRP_TOOL]$esrpTool"

# Derive the service connection GUID from the ENDPOINT_URL_* env vars
# that the agent emits for the bound connection. Filter out the
# built-in SystemVssConnection which is always present.
$scId = (Get-ChildItem env:ENDPOINT_URL_*).Name `
-replace '^ENDPOINT_URL_','' |
Where-Object { $_ -ne 'SYSTEMVSSCONNECTION' }
if (-not $scId) { Write-Error "Could not derive service connection GUID"; exit 1 }
Write-Host "Resolved service connection GUID: $scId"

# servicePrincipalId and tenantId are provided by addSpnToEnvironment
$authJson = @{
Version = "1.0.0"
AuthenticationType = "AAD_MSI_WIF"
EsrpClientId = "${{ parameters.esrpClientId }}"
ClientId = $env:servicePrincipalId
TenantId = $env:tenantId
AADAuthorityBaseUri = "https://login.microsoftonline.com/"
FederatedTokenData = @{
JobId = "$(System.JobId)"
PlanId = "$(System.PlanId)"
ProjectId = "$(System.TeamProjectId)"
Hub = "$(System.HostType)"
Uri = "$(System.CollectionUri)"
ServiceConnectionId = $scId
SystemAccessToken = "SYSTEM_ACCESSTOKEN"
}
RequestSigningCert = @{
GetCertFromKeyVault = $true
KeyVaultName = "${{ parameters.keyVaultName }}"
KeyVaultCertName = "${{ parameters.signCertName }}"
}
} | ConvertTo-Json -Depth 4

$authPath = "$(Agent.TempDirectory)\esrp-auth.json"
$authJson | Set-Content -Path $authPath -Encoding UTF8
Write-Host "Generated ESRP auth JSON: $authPath"
Write-Host "##vso[task.setvariable variable=ESRP_AUTH]$authPath"
env:
SYSTEM_ACCESSTOKEN: $(System.AccessToken)
ESRPCLIENT_TOOLPATH: $(esrpinstall.esrpclient.toolpath)
ESRPCLIENT_TOOLNAME: $(esrpinstall.esrpclient.toolname)
1 change: 1 addition & 0 deletions .azure-pipelines/patches/.gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
*.patch whitespace=-trailing-space,-blank-at-eof
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
diff --git a/installer/install.iss b/installer/install.iss
index 70787b7..137f660 100644
--- a/installer/install.iss
+++ b/installer/install.iss
@@ -65,7 +65,7 @@ SignTool=signtool
; Installer-related
AllowNoIcons=yes
AppName={#APP_NAME}
-AppPublisher=The Git Development Community
+AppPublisher=The Git Client Team at Microsoft
AppPublisherURL={#APP_URL}
AppSupportURL={#APP_CONTACT_URL}
AppVersion={#APP_VERSION}
Loading
Loading