mirror of
https://github.com/3proxy/3proxy.git
synced 2026-09-17 19:45:49 +08:00
Signing the release binaries with a self-signed certificate gives no trust benefit: Windows does not recognize the issuer, so SmartScreen warns anyway, and the signature is a frequent trigger for antivirus false positives. Drop the Decode Certificate / Extract public certificate / Sign steps from the MSVC and Watcom workflows, stop shipping the extracted 3proxy.crt in the distribution, and remove the certificate URL from the build version string. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
115 lines
4.1 KiB
YAML
115 lines
4.1 KiB
YAML
name: Build Win32 3proxy with MSVC
|
|
|
|
on:
|
|
release:
|
|
types: [published]
|
|
workflow_dispatch:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
ci:
|
|
permissions:
|
|
contents: write
|
|
id-token: write
|
|
attestations: write
|
|
name: "${{ matrix.target }}"
|
|
strategy:
|
|
matrix:
|
|
target:
|
|
- windows-2022
|
|
runs-on: ${{ matrix.target }}
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
# - name: configure
|
|
# run: ./configure
|
|
- name: set date
|
|
run: |
|
|
$NOW = Get-Date -Format "yyMMddHHmmss"
|
|
$RELEASE = Get-Content -Path "RELEASE" -Raw
|
|
echo "RELEASE=$RELEASE" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append
|
|
echo "VERSION=/D `"VERSION=\`"3proxy-$RELEASE\`"`"" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append
|
|
echo "BUILDDATE=/D `"BUILDDATE=\`"$NOW\`"`"" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append
|
|
- name: install packages
|
|
run: vcpkg install pcre2:x86-windows-static wolfssl:x86-windows-static
|
|
- name: Add msbuild to PATH
|
|
uses: microsoft/setup-msbuild@v3
|
|
- name: make Windows MSVC
|
|
if: ${{ startsWith(matrix.target, 'windows') }}
|
|
shell: cmd
|
|
run: |
|
|
call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars32.bat"
|
|
D:
|
|
cd "D:/a/3proxy/3proxy"
|
|
set "LIB=%LIB%;c:/vcpkg/installed/x86-windows-static/lib"
|
|
set "INCLUDE=%INCLUDE%;c:/vcpkg/installed/x86-windows-static/include"
|
|
echo "volatile char VerSion[]=^"3APA3A-3proxy-Internal-Build: 3proxy-%RELEASE%-%NOW%\r\n^";" >>src/3proxy.c
|
|
nmake /F Makefile.msvc WOLFSSL=1
|
|
- name: make dist dir
|
|
shell: cmd
|
|
run: |
|
|
mkdir dist
|
|
mkdir dist\3proxy
|
|
mkdir dist\3proxy\bin
|
|
mkdir dist\3proxy\cfg
|
|
mkdir dist\3proxy\cfg\sql
|
|
mkdir dist\3proxy\doc
|
|
mkdir dist\3proxy\doc\ru
|
|
mkdir dist\3proxy\doc\html
|
|
mkdir dist\3proxy\doc\html\plugins
|
|
mkdir dist\3proxy\doc\html\man5
|
|
mkdir dist\3proxy\doc\html\man8
|
|
mkdir dist\3proxy\doc\html\devel
|
|
copy bin\3proxy.exe dist\3proxy\bin\
|
|
copy bin\*.dll dist\3proxy\bin\
|
|
copy bin\3proxy_crypt.exe dist\3proxy\bin\
|
|
copy cfg\*.* dist\3proxy\cfg\
|
|
copy cfg\sql\*.* dist\3proxy\cfg\sql\
|
|
copy doc\ru\*.* dist\3proxy\doc\ru\
|
|
copy doc\html\*.* dist\3proxy\doc\html\
|
|
copy doc\html\plugins\*.* dist\3proxy\doc\html\plugins\
|
|
copy doc\html\man8\*.* dist\3proxy\doc\html\man8\
|
|
copy doc\html\man5\*.* dist\3proxy\doc\html\man5\
|
|
copy doc\html\devel\*.* dist\3proxy\doc\html\devel\
|
|
copy copying dist\3proxy\
|
|
copy authors dist\3proxy\
|
|
copy README.md dist\3proxy\
|
|
copy rus.3ps dist\3proxy\
|
|
- name: Get artifact
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
name: "3proxy-${{ env.RELEASE }}-x86"
|
|
path: dist/
|
|
- name: Create zip
|
|
if: github.event_name == 'release'
|
|
shell: pwsh
|
|
run: Compress-Archive -Path dist/* -DestinationPath 3proxy-${{ env.RELEASE }}-x86.zip
|
|
- name: Checksums and detached signature
|
|
if: github.event_name == 'release'
|
|
shell: bash
|
|
env:
|
|
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }}
|
|
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
|
|
run: |
|
|
if [ -z "$GPG_PRIVATE_KEY" ]; then echo "GPG_PRIVATE_KEY is not set"; exit 1; fi
|
|
printf '%s' "$GPG_PRIVATE_KEY" | gpg --batch --import
|
|
KEYID=$(gpg --list-secret-keys --with-colons | awk -F: '/^sec:/{print $5; exit}')
|
|
sha256sum *.zip > SHA256SUMS-win-x86
|
|
gpg --batch --yes --pinentry-mode loopback --passphrase "$GPG_PASSPHRASE" \
|
|
-u "$KEYID" --armor --detach-sign SHA256SUMS-win-x86
|
|
sha256sum -c SHA256SUMS-win-x86
|
|
- name: Attest build provenance
|
|
if: github.event_name == 'release'
|
|
uses: actions/attest-build-provenance@v4
|
|
with:
|
|
subject-path: |
|
|
*.zip
|
|
- name: Upload to release
|
|
if: github.event_name == 'release'
|
|
shell: bash
|
|
env:
|
|
GH_TOKEN: ${{ github.token }}
|
|
TAG: ${{ github.event.release.tag_name }}
|
|
run: gh release upload "$TAG" *.zip SHA256SUMS-win-x86 SHA256SUMS-win-x86.asc
|