-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathbuild.sh
More file actions
executable file
·76 lines (68 loc) · 3.14 KB
/
Copy pathbuild.sh
File metadata and controls
executable file
·76 lines (68 loc) · 3.14 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
#!/bin/bash
# Builds Input Control for x86 and x86-64. Signing is optional and skipped without a key.
set -e
cd "$(dirname "$0")"
SRC=src
OUT=bin
mkdir -p "$OUT"
SOURCES="main.c kbd.c mouse.c pad_draw.c xinput.c dinput.c wgi.c hidview.c analog.c capture.c guide.c"
LIBS="-lgdi32 -luser32 -lcomdlg32 -ldinput8 -ldxguid -lole32 -lm"
echo "== resources =="
i686-w64-mingw32-windres "$SRC/inputcontrol.rc" -O coff -o "$SRC/res32.o"
x86_64-w64-mingw32-windres "$SRC/inputcontrol.rc" -O coff -o "$SRC/res64.o"
echo "== compiling =="
( cd "$SRC" && i686-w64-mingw32-gcc -std=c99 -O2 -s -Wall -Wextra -mwindows \
-o "../$OUT/InputControl32.exe" $SOURCES res32.o $LIBS )
( cd "$SRC" && x86_64-w64-mingw32-gcc -std=c99 -O2 -s -Wall -Wextra -mwindows \
-o "../$OUT/InputControl64.exe" $SOURCES res64.o $LIBS )
rm -f "$SRC/res32.o" "$SRC/res64.o"
echo "built:"
ls -la "$OUT"/InputControl32.exe "$OUT"/InputControl64.exe
# dinput8 / xinput entry points are resolved with LoadLibrary at runtime, so the
# exe must NOT carry a hard import for them - a container missing one should show
# "not available" rather than failing to start. Guard that here.
echo "== import check =="
for f in "$OUT"/InputControl32.exe "$OUT"/InputControl64.exe; do
if command -v python3 >/dev/null 2>&1 && python3 -c "import pefile" 2>/dev/null; then
python3 - "$f" <<'EOF'
import sys, pefile
pe = pefile.PE(sys.argv[1], fast_load=True); pe.parse_data_directories()
dlls = sorted(e.dll.decode().lower() for e in pe.DIRECTORY_ENTRY_IMPORT)
bad = [d for d in dlls if 'dinput' in d or 'xinput' in d or 'ole32' in d]
print(f" {sys.argv[1].split('/')[-1]}: {', '.join(dlls)}")
if bad:
print(f" !! hard import on {bad} - runtime loading broken"); sys.exit(1)
EOF
fi
done
# --- optional signing ---------------------------------------------------------
# Private key is not in this repo. Generate your own once:
#
# openssl req -x509 -newkey rsa:3072 -keyout signing/inputcontrol-key.pem \
# -out signing/inputcontrol-cert.pem -days 3650 -nodes -sha256 \
# -subj "/CN=Input Control (self-signed)/O=Input Control" \
# -addext "basicConstraints=critical,CA:FALSE" \
# -addext "keyUsage=critical,digitalSignature" \
# -addext "extendedKeyUsage=critical,codeSigning"
#
KEY=signing/inputcontrol-key.pem
CERT=signing/inputcontrol-cert.pem
if [ -f "$KEY" ] && command -v osslsigncode >/dev/null 2>&1; then
echo "== signing =="
for a in 32 64; do
osslsigncode sign -certs "$CERT" -key "$KEY" \
-h sha256 -n "Input Control - input test suite" \
-ts http://timestamp.digicert.com \
-in "$OUT/InputControl$a.exe" -out "$OUT/InputControl$a-s.exe"
mv "$OUT/InputControl$a-s.exe" "$OUT/InputControl$a.exe"
done
echo "== verifying =="
# -TSA-CAfile is required or the timestamp check reports "failed" on a good signature
for a in 32 64; do
osslsigncode verify -CAfile "$CERT" \
-TSA-CAfile /etc/ssl/certs/ca-certificates.crt "$OUT/InputControl$a.exe" \
| grep -E "Signature verification|Timestamp Server Signature"
done
else
echo "== signing skipped (no $KEY, or osslsigncode not installed) =="
fi