You can not select more than 25 topics Topics must start with a chinese character,a letter or number, can include dashes ('-') and can be up to 35 characters long.

SignJar.java 12 kB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386
  1. /*
  2. * The Apache Software License, Version 1.1
  3. *
  4. * Copyright (c) 2000-2002 The Apache Software Foundation. All rights
  5. * reserved.
  6. *
  7. * Redistribution and use in source and binary forms, with or without
  8. * modification, are permitted provided that the following conditions
  9. * are met:
  10. *
  11. * 1. Redistributions of source code must retain the above copyright
  12. * notice, this list of conditions and the following disclaimer.
  13. *
  14. * 2. Redistributions in binary form must reproduce the above copyright
  15. * notice, this list of conditions and the following disclaimer in
  16. * the documentation and/or other materials provided with the
  17. * distribution.
  18. *
  19. * 3. The end-user documentation included with the redistribution, if
  20. * any, must include the following acknowlegement:
  21. * "This product includes software developed by the
  22. * Apache Software Foundation (http://www.apache.org/)."
  23. * Alternately, this acknowlegement may appear in the software itself,
  24. * if and wherever such third-party acknowlegements normally appear.
  25. *
  26. * 4. The names "The Jakarta Project", "Ant", and "Apache Software
  27. * Foundation" must not be used to endorse or promote products derived
  28. * from this software without prior written permission. For written
  29. * permission, please contact apache@apache.org.
  30. *
  31. * 5. Products derived from this software may not be called "Apache"
  32. * nor may "Apache" appear in their names without prior written
  33. * permission of the Apache Group.
  34. *
  35. * THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESSED OR IMPLIED
  36. * WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
  37. * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
  38. * DISCLAIMED. IN NO EVENT SHALL THE APACHE SOFTWARE FOUNDATION OR
  39. * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
  40. * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
  41. * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF
  42. * USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
  43. * ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
  44. * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
  45. * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
  46. * SUCH DAMAGE.
  47. * ====================================================================
  48. *
  49. * This software consists of voluntary contributions made by many
  50. * individuals on behalf of the Apache Software Foundation. For more
  51. * information on the Apache Software Foundation, please see
  52. * <http://www.apache.org/>.
  53. */
  54. package org.apache.tools.ant.taskdefs;
  55. import java.io.File;
  56. import java.io.IOException;
  57. import java.util.Enumeration;
  58. import java.util.Vector;
  59. import java.util.zip.ZipEntry;
  60. import java.util.zip.ZipFile;
  61. import org.apache.tools.ant.Task;
  62. import org.apache.tools.ant.BuildException;
  63. import org.apache.tools.ant.DirectoryScanner;
  64. import org.apache.tools.ant.types.FileSet;
  65. import org.apache.tools.ant.util.JavaEnvUtils;
  66. /**
  67. * Signs jar or zip files with the javasign command line tool. The
  68. * tool detailed dependency checking: files are only signed if they
  69. * are not signed. The <tt>signjar</tt> attribute can point to the file to
  70. * generate; if this file exists then
  71. * its modification date is used as a cue as to whether to resign any JAR file.
  72. * <br>
  73. * <strong>Note:</strong> Requires Java 1.2 or later. </p>
  74. *
  75. * @author Peter Donald
  76. * <a href="mailto:donaldp@apache.org">donaldp@apache.org</a>
  77. * @author Nick Fortescue
  78. * <a href="mailto:nick@ox.compsoc.net">nick@ox.compsoc.net</a>
  79. * @since Ant 1.1
  80. * @ant.task category="java"
  81. */
  82. public class SignJar extends Task {
  83. /**
  84. * The name of the jar file.
  85. */
  86. protected File jar;
  87. /**
  88. * The alias of signer.
  89. */
  90. protected String alias;
  91. /**
  92. * The name of keystore file.
  93. */
  94. protected File keystore;
  95. protected String storepass;
  96. protected String storetype;
  97. protected String keypass;
  98. protected File sigfile;
  99. protected File signedjar;
  100. protected boolean verbose;
  101. protected boolean internalsf;
  102. protected boolean sectionsonly;
  103. /**
  104. * the filesets of the jars to sign
  105. */
  106. protected Vector filesets = new Vector();
  107. /**
  108. * Whether to assume a jar which has an appropriate .SF file in is already
  109. * signed.
  110. */
  111. protected boolean lazy;
  112. /**
  113. * the jar file to sign; required
  114. */
  115. public void setJar(final File jar) {
  116. this.jar = jar;
  117. }
  118. /**
  119. * the alias to sign under; required
  120. */
  121. public void setAlias(final String alias) {
  122. this.alias = alias;
  123. }
  124. /**
  125. * keystore location; required
  126. */
  127. public void setKeystore(final File keystore) {
  128. this.keystore = keystore;
  129. }
  130. /**
  131. * password for keystore integrity; required
  132. */
  133. public void setStorepass(final String storepass) {
  134. this.storepass = storepass;
  135. }
  136. /**
  137. * keystore type; optional
  138. */
  139. public void setStoretype(final String storetype) {
  140. this.storetype = storetype;
  141. }
  142. /**
  143. * password for private key (if different); optional
  144. */
  145. public void setKeypass(final String keypass) {
  146. this.keypass = keypass;
  147. }
  148. /**
  149. * name of .SF/.DSA file; optional
  150. */
  151. public void setSigfile(final File sigfile) {
  152. this.sigfile = sigfile;
  153. }
  154. /**
  155. * name of signed JAR file; optional
  156. */
  157. public void setSignedjar(final File signedjar) {
  158. this.signedjar = signedjar;
  159. }
  160. /**
  161. * Enable verbose output when signing
  162. * ; optional: default false
  163. */
  164. public void setVerbose(final boolean verbose) {
  165. this.verbose = verbose;
  166. }
  167. /**
  168. * Flag to include the .SF file inside the signature;
  169. * optional; default false
  170. */
  171. public void setInternalsf(final boolean internalsf) {
  172. this.internalsf = internalsf;
  173. }
  174. /**
  175. * flag to compute hash of entire manifest;
  176. * optional, default false
  177. */
  178. public void setSectionsonly(final boolean sectionsonly) {
  179. this.sectionsonly = sectionsonly;
  180. }
  181. /**
  182. * flag to control whether the presence of a signature
  183. * file means a JAR is signed;
  184. * optional, default false
  185. */
  186. public void setLazy(final boolean lazy) {
  187. this.lazy = lazy;
  188. }
  189. /**
  190. * Adds a set of files to sign
  191. * @since Ant 1.4
  192. */
  193. public void addFileset(final FileSet set) {
  194. filesets.addElement(set);
  195. }
  196. /**
  197. * sign the jar(s)
  198. */
  199. public void execute() throws BuildException {
  200. if (null == jar && null == filesets) {
  201. throw new BuildException("jar must be set through jar attribute "
  202. + "or nested filesets");
  203. }
  204. if (null != jar) {
  205. doOneJar(jar, signedjar);
  206. return;
  207. } else {
  208. //Assume null != filesets
  209. // deal with the filesets
  210. for (int i = 0; i < filesets.size(); i++) {
  211. FileSet fs = (FileSet) filesets.elementAt(i);
  212. DirectoryScanner ds = fs.getDirectoryScanner(getProject());
  213. String[] jarFiles = ds.getIncludedFiles();
  214. for (int j = 0; j < jarFiles.length; j++) {
  215. doOneJar(new File(fs.getDir(getProject()), jarFiles[j]), null);
  216. }
  217. }
  218. }
  219. }
  220. /**
  221. * sign one jar
  222. */
  223. private void doOneJar(File jarSource, File jarTarget)
  224. throws BuildException {
  225. if (JavaEnvUtils.isJavaVersion(JavaEnvUtils.JAVA_1_1)) {
  226. throw new BuildException("The signjar task is only available on "
  227. + "JDK versions 1.2 or greater");
  228. }
  229. if (null == alias) {
  230. throw new BuildException("alias attribute must be set");
  231. }
  232. if (null == storepass) {
  233. throw new BuildException("storepass attribute must be set");
  234. }
  235. if (isUpToDate(jarSource, jarTarget)) {
  236. return;
  237. }
  238. final ExecTask cmd = (ExecTask) getProject().createTask("exec");
  239. cmd.setExecutable("jarsigner");
  240. if (null != keystore) {
  241. cmd.createArg().setValue("-keystore");
  242. cmd.createArg().setValue(keystore.toString());
  243. }
  244. if (null != storepass) {
  245. cmd.createArg().setValue("-storepass");
  246. cmd.createArg().setValue(storepass);
  247. }
  248. if (null != storetype) {
  249. cmd.createArg().setValue("-storetype");
  250. cmd.createArg().setValue(storetype);
  251. }
  252. if (null != keypass) {
  253. cmd.createArg().setValue("-keypass");
  254. cmd.createArg().setValue(keypass);
  255. }
  256. if (null != sigfile) {
  257. cmd.createArg().setValue("-sigfile");
  258. cmd.createArg().setValue(sigfile.toString());
  259. }
  260. if (null != jarTarget) {
  261. cmd.createArg().setValue("-signedjar");
  262. cmd.createArg().setValue(jarTarget.toString());
  263. }
  264. if (verbose) {
  265. cmd.createArg().setValue("-verbose");
  266. }
  267. if (internalsf) {
  268. cmd.createArg().setValue("-internalsf");
  269. }
  270. if (sectionsonly) {
  271. cmd.createArg().setValue("-sectionsonly");
  272. }
  273. cmd.createArg().setValue(jarSource.toString());
  274. cmd.createArg().setValue(alias);
  275. log("Signing Jar : " + jarSource.getAbsolutePath());
  276. cmd.setFailonerror(true);
  277. cmd.setTaskName(getTaskName());
  278. cmd.execute();
  279. }
  280. protected boolean isUpToDate(File jarFile, File signedjarFile) {
  281. if (null == jarFile) {
  282. return false;
  283. }
  284. if (null != signedjarFile) {
  285. if (!jarFile.exists()) {
  286. return false;
  287. }
  288. if (!signedjarFile.exists()) {
  289. return false;
  290. }
  291. if (jarFile.equals(signedjarFile)) {
  292. return false;
  293. }
  294. if (signedjarFile.lastModified() > jarFile.lastModified()) {
  295. return true;
  296. }
  297. } else {
  298. if (lazy) {
  299. return isSigned(jarFile);
  300. }
  301. }
  302. return false;
  303. }
  304. protected boolean isSigned(File file) {
  305. final String SIG_START = "META-INF/";
  306. final String SIG_END = ".SF";
  307. if (!file.exists()) {
  308. return false;
  309. }
  310. ZipFile jarFile = null;
  311. try {
  312. jarFile = new ZipFile(file);
  313. if (null == alias) {
  314. Enumeration entries = jarFile.entries();
  315. while (entries.hasMoreElements()) {
  316. String name = ((ZipEntry) entries.nextElement()).getName();
  317. if (name.startsWith(SIG_START) && name.endsWith(SIG_END)) {
  318. return true;
  319. }
  320. }
  321. return false;
  322. } else {
  323. return jarFile.getEntry(SIG_START + alias.toUpperCase() +
  324. SIG_END) != null;
  325. }
  326. } catch (IOException e) {
  327. return false;
  328. } finally {
  329. if (jarFile != null) {
  330. try {
  331. jarFile.close();
  332. } catch (IOException e) {
  333. }
  334. }
  335. }
  336. }
  337. }