From 88c5598c2a9fd031f738f54a54db4a9157f9fe8a Mon Sep 17 00:00:00 2001 From: Jian Chen Date: Mon, 24 Feb 2025 11:34:25 -0800 Subject: [PATCH 1/5] Make Nuget package pipeline 1ES compliant --- .../github/azure-pipelines/publish-nuget.yml | 59 +++++++++++-------- .../stages/java-cuda-publishing-stage.yml | 3 +- .../stages/py-cuda-publishing-stage.yml | 6 +- .../templates/publish-nuget-steps.yml | 43 +++++++------- 4 files changed, 64 insertions(+), 47 deletions(-) diff --git a/tools/ci_build/github/azure-pipelines/publish-nuget.yml b/tools/ci_build/github/azure-pipelines/publish-nuget.yml index b78d586288ba3..7ad0aa3b95d9d 100644 --- a/tools/ci_build/github/azure-pipelines/publish-nuget.yml +++ b/tools/ci_build/github/azure-pipelines/publish-nuget.yml @@ -8,35 +8,48 @@ resources: - main - rel-* branch: main - + repositories: + - repository: 1esPipelines + type: git + name: 1ESPipelineTemplates/1ESPipelineTemplates + ref: refs/tags/release parameters: - - name: isReleaseBuild - type: boolean - default: false +- name: isReleaseBuild + type: boolean + default: false variables: - - name: ArtifactFeed - ${{ if eq(parameters.isReleaseBuild, false) }}: - value: ort-cuda-11-nightly - ${{ else }}: - value: onnxruntime-cuda-11 - -stages: - - template: templates/publish-nuget-steps.yml - parameters: - stage_name: 'Publish_NuGet_Package_And_Report' - include_cpu_ep: true - download_artifacts_steps: +- name: ArtifactFeed + ${{ if eq(parameters.isReleaseBuild, false) }}: + value: ort-cuda-11-nightly + ${{ else }}: + value: onnxruntime-cuda-11 +extends: + # The pipeline extends the 1ES PT which will inject different SDL and compliance tasks. + # For non-production pipelines, use "Unofficial" as defined below. + # For productions pipelines, use "Official". + template: v1/1ES.Official.PipelineTemplate.yml@1esPipelines + parameters: + sdl: + sourceAnalysisPool: + name: onnxruntime-Win-CPU-2022 + os: windows + stages: + - template: templates/publish-nuget-steps.yml + parameters: + stage_name: 'Publish_NuGet_Package_And_Report' + include_cpu_ep: true + download_artifacts_steps: - download: build displayName: 'Download Pipeline Artifact - Signed NuGet Package' artifact: 'drop-signed-nuget-dml' - script: move "$(Pipeline.Workspace)\build\drop-signed-nuget-dml\*" $(Build.BinariesDirectory)\nuget-artifact\final-package - # Publish CUDA 11 Nuget/Java pkgs to ADO feed - - template: stages/nuget-cuda-publishing-stage.yml - parameters: - artifact_feed: $(ArtifactFeed) + # Publish CUDA 11 Nuget/Java pkgs to ADO feed + - template: stages/nuget-cuda-publishing-stage.yml + parameters: + artifact_feed: $(ArtifactFeed) - - template: stages/java-cuda-publishing-stage.yml - parameters: - artifact_feed: $(ArtifactFeed) + - template: stages/java-cuda-publishing-stage.yml + parameters: + artifact_feed: $(ArtifactFeed) diff --git a/tools/ci_build/github/azure-pipelines/stages/java-cuda-publishing-stage.yml b/tools/ci_build/github/azure-pipelines/stages/java-cuda-publishing-stage.yml index 946d651b795d4..8f14b315d899d 100644 --- a/tools/ci_build/github/azure-pipelines/stages/java-cuda-publishing-stage.yml +++ b/tools/ci_build/github/azure-pipelines/stages/java-cuda-publishing-stage.yml @@ -11,7 +11,8 @@ stages: condition: ${{ or(eq(parameters.artifact_feed, 'onnxruntime-cuda-11'), eq(parameters.artifact_feed, 'onnxruntime-cuda-12')) }} workspace: clean: all - pool: 'onnxruntime-Win-CPU-2022' + pool: + name: 'onnxruntime-Win-CPU-2022' variables: - name: SYSTEM_ACCESSTOKEN value: $(System.AccessToken) diff --git a/tools/ci_build/github/azure-pipelines/stages/py-cuda-publishing-stage.yml b/tools/ci_build/github/azure-pipelines/stages/py-cuda-publishing-stage.yml index 1ff43667f4788..fbfbc69bce0a8 100644 --- a/tools/ci_build/github/azure-pipelines/stages/py-cuda-publishing-stage.yml +++ b/tools/ci_build/github/azure-pipelines/stages/py-cuda-publishing-stage.yml @@ -7,13 +7,15 @@ stages: - stage: Python_Publishing_GPU jobs: - job: Python_Publishing_GPU - pool: 'onnxruntime-Ubuntu2204-AMD-CPU' + pool: + name: 'onnxruntime-Ubuntu2204-AMD-CPU' + os: linux steps: - checkout: none - download: build displayName: 'Download Pipeline Artifact' artifact: 'whl' - + - task: UsePythonVersion@0 inputs: versionSpec: '3.13' diff --git a/tools/ci_build/github/azure-pipelines/templates/publish-nuget-steps.yml b/tools/ci_build/github/azure-pipelines/templates/publish-nuget-steps.yml index 6671d3870dd67..897deb43e5d38 100644 --- a/tools/ci_build/github/azure-pipelines/templates/publish-nuget-steps.yml +++ b/tools/ci_build/github/azure-pipelines/templates/publish-nuget-steps.yml @@ -17,7 +17,8 @@ stages: variables: - name: GDN_CODESIGN_TARGETDIRECTORY value: '$(Agent.TempDirectory)\binfiles' - pool: 'onnxruntime-Win-CPU-2022' + pool: + name: 'onnxruntime-Win-CPU-2022' steps: # https://learn.microsoft.com/en-us/azure/devops/pipelines/yaml-schema/resources-pipelines-pipeline?view=azure-pipelines#pipeline-resource-metadata-as-predefined-variables @@ -53,25 +54,25 @@ stages: displayName: 'Post binary sizes to the dashboard database using command line' inputs: script: | - echo changing directory to artifact download path - cd $(Build.BinariesDirectory)/nuget-artifact/final-package - echo processing nupkg - SETLOCAL EnableDelayedExpansion - FOR /R %%i IN (*.nupkg) do ( - set filename=%%~ni - IF NOT "!filename:~25,7!"=="Managed" ( - echo processing %%~ni.nupkg - copy %%~ni.nupkg %%~ni.zip - echo copied to zip - echo listing lib files in the zip - REM use a single .csv file to put the data - echo os,arch,build_config,size > $(Build.BinariesDirectory)\binary_size_data.txt - 7z.exe l -slt %%~ni.zip runtimes\linux-arm64\native\libonnxruntime.so | findstr /R /C:"^Size = [0-9]*" | for /F "tokens=3" %%a in ('more') do if not "%%a" == "" echo linux,aarch64,default,%%a >> $(Build.BinariesDirectory)\binary_size_data.txt - 7z.exe l -slt %%~ni.zip runtimes\osx-x64\native\libonnxruntime.dylib | findstr /R /C:"^Size = [0-9]*" | for /F "tokens=3" %%a in ('more') do if not "%%a" == "" echo osx,x64,default,%%a >> $(Build.BinariesDirectory)\binary_size_data.txt - 7z.exe l -slt %%~ni.zip runtimes\win-x64\native\onnxruntime.dll | findstr /R /C:"^Size = [0-9]*" | for /F "tokens=3" %%a in ('more') do if not "%%a" == "" echo win,x64,default,%%a >> $(Build.BinariesDirectory)\binary_size_data.txt - 7z.exe l -slt %%~ni.zip runtimes\win-x86\native\onnxruntime.dll | findstr /R /C:"^Size = [0-9]*" | for /F "tokens=3" %%a in ('more') do if not "%%a" == "" echo win,x86,default,%%a >> $(Build.BinariesDirectory)\binary_size_data.txt - ) + echo changing directory to artifact download path + cd $(Build.BinariesDirectory)/nuget-artifact/final-package + echo processing nupkg + SETLOCAL EnableDelayedExpansion + FOR /R %%i IN (*.nupkg) do ( + set filename=%%~ni + IF NOT "!filename:~25,7!"=="Managed" ( + echo processing %%~ni.nupkg + copy %%~ni.nupkg %%~ni.zip + echo copied to zip + echo listing lib files in the zip + REM use a single .csv file to put the data + echo os,arch,build_config,size > $(Build.BinariesDirectory)\binary_size_data.txt + 7z.exe l -slt %%~ni.zip runtimes\linux-arm64\native\libonnxruntime.so | findstr /R /C:"^Size = [0-9]*" | for /F "tokens=3" %%a in ('more') do if not "%%a" == "" echo linux,aarch64,default,%%a >> $(Build.BinariesDirectory)\binary_size_data.txt + 7z.exe l -slt %%~ni.zip runtimes\osx-x64\native\libonnxruntime.dylib | findstr /R /C:"^Size = [0-9]*" | for /F "tokens=3" %%a in ('more') do if not "%%a" == "" echo osx,x64,default,%%a >> $(Build.BinariesDirectory)\binary_size_data.txt + 7z.exe l -slt %%~ni.zip runtimes\win-x64\native\onnxruntime.dll | findstr /R /C:"^Size = [0-9]*" | for /F "tokens=3" %%a in ('more') do if not "%%a" == "" echo win,x64,default,%%a >> $(Build.BinariesDirectory)\binary_size_data.txt + 7z.exe l -slt %%~ni.zip runtimes\win-x86\native\onnxruntime.dll | findstr /R /C:"^Size = [0-9]*" | for /F "tokens=3" %%a in ('more') do if not "%%a" == "" echo win,x86,default,%%a >> $(Build.BinariesDirectory)\binary_size_data.txt ) + ) - task: AzureCLI@2 displayName: 'Azure CLI' @@ -132,5 +133,5 @@ stages: allowPackageConflicts: true - template: component-governance-component-detection-steps.yml - parameters : - condition : 'succeeded' + parameters: + condition: 'succeeded' From 24252b5d09fc91df1ef12f080ead2526eb27ca40 Mon Sep 17 00:00:00 2001 From: Jian Chen Date: Mon, 24 Feb 2025 11:41:00 -0800 Subject: [PATCH 2/5] Make Nuget package pipeline 1ES compliant --- .../github/azure-pipelines/templates/publish-nuget-steps.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/tools/ci_build/github/azure-pipelines/templates/publish-nuget-steps.yml b/tools/ci_build/github/azure-pipelines/templates/publish-nuget-steps.yml index 897deb43e5d38..c7865436475ca 100644 --- a/tools/ci_build/github/azure-pipelines/templates/publish-nuget-steps.yml +++ b/tools/ci_build/github/azure-pipelines/templates/publish-nuget-steps.yml @@ -124,11 +124,11 @@ stages: GdnBreakPolicyMinSev: Error #TODO: allow choosing different feeds - - task: NuGetCommand@2 + - task:1ES.PublishNuget@1 displayName: 'Copy Signed Native NuGet Package to ORT-NIGHTLY' inputs: - command: 'push' packagesToPush: '$(Build.BinariesDirectory)/nuget-artifact/final-package/*.nupkg' + packageParentPath: '$(Build.BinariesDirectory)' publishVstsFeed: '2692857e-05ef-43b4-ba9c-ccf1c22c437c/7982ae20-ed19-4a35-a362-a96ac99897b7' allowPackageConflicts: true From 26609ab67193bbbf51219130172e0639c8811971 Mon Sep 17 00:00:00 2001 From: Jian Chen Date: Mon, 24 Feb 2025 11:43:20 -0800 Subject: [PATCH 3/5] Make Nuget package pipeline 1ES compliant --- .../github/azure-pipelines/templates/publish-nuget-steps.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tools/ci_build/github/azure-pipelines/templates/publish-nuget-steps.yml b/tools/ci_build/github/azure-pipelines/templates/publish-nuget-steps.yml index c7865436475ca..aa47294acac2b 100644 --- a/tools/ci_build/github/azure-pipelines/templates/publish-nuget-steps.yml +++ b/tools/ci_build/github/azure-pipelines/templates/publish-nuget-steps.yml @@ -124,7 +124,7 @@ stages: GdnBreakPolicyMinSev: Error #TODO: allow choosing different feeds - - task:1ES.PublishNuget@1 + - task: 1ES.PublishNuget@1 displayName: 'Copy Signed Native NuGet Package to ORT-NIGHTLY' inputs: packagesToPush: '$(Build.BinariesDirectory)/nuget-artifact/final-package/*.nupkg' From 366ff7440862c7ede327cecd5e9ddcfcd9312707 Mon Sep 17 00:00:00 2001 From: Jian Chen Date: Mon, 24 Feb 2025 11:45:02 -0800 Subject: [PATCH 4/5] Make Nuget package pipeline 1ES compliant --- .../stages/nuget-cuda-publishing-stage.yml | 118 +++++++++--------- 1 file changed, 59 insertions(+), 59 deletions(-) diff --git a/tools/ci_build/github/azure-pipelines/stages/nuget-cuda-publishing-stage.yml b/tools/ci_build/github/azure-pipelines/stages/nuget-cuda-publishing-stage.yml index b802dd43f9058..f6d78707d5b9c 100644 --- a/tools/ci_build/github/azure-pipelines/stages/nuget-cuda-publishing-stage.yml +++ b/tools/ci_build/github/azure-pipelines/stages/nuget-cuda-publishing-stage.yml @@ -1,71 +1,71 @@ parameters: - - name: artifact_feed - type: string - default: 'onnxruntime-cuda-12' +- name: artifact_feed + type: string + default: 'onnxruntime-cuda-12' stages: - - stage: NuGet_Publishing_GPU - jobs: - - job: NuGet_Publishing_GPU - workspace: - clean: all - variables: - - name: GDN_CODESIGN_TARGETDIRECTORY - value: '$(Build.BinariesDirectory)/nuget-artifact/final-package' - pool: 'onnxruntime-Win-CPU-2022' - steps: - - checkout: none +- stage: NuGet_Publishing_GPU + jobs: + - job: NuGet_Publishing_GPU + workspace: + clean: all + variables: + - name: GDN_CODESIGN_TARGETDIRECTORY + value: '$(Build.BinariesDirectory)/nuget-artifact/final-package' + pool: 'onnxruntime-Win-CPU-2022' + steps: + - checkout: none - - task: NuGetToolInstaller@1 - inputs: - versionSpec: 6.8.x + - task: NuGetToolInstaller@1 + inputs: + versionSpec: 6.8.x - - script: mkdir "$(Build.BinariesDirectory)\nuget-artifact\final-package" - - - download: build - displayName: 'Download Pipeline Artifact - Signed NuGet Package' - artifact: 'drop-signed-nuget-GPU' - - - script: move "$(Pipeline.Workspace)\build\drop-signed-nuget-GPU\*" "$(Build.BinariesDirectory)\nuget-artifact\final-package" - - - powershell: | - New-Item -Path $(Agent.TempDirectory) -Name "binfiles" -ItemType "directory" - $base_path_name = Join-Path -Path $(Agent.TempDirectory) -ChildPath "binfiles" - Get-ChildItem $Env:BUILD_BINARIESDIRECTORY\nuget-artifact\final-package -Filter *.nupkg | - Foreach-Object { - $dir_name = Join-Path -Path $base_path_name -ChildPath $_.Basename - $cmd = "7z.exe x $($_.FullName) -y -o$dir_name" - Write-Output $cmd - Invoke-Expression -Command $cmd - } - dir $(Agent.TempDirectory) - tree $(Agent.TempDirectory) - workingDirectory: '$(Agent.TempDirectory)' + - script: mkdir "$(Build.BinariesDirectory)\nuget-artifact\final-package" - - task: CodeSign@1 - displayName: 'Run Codesign Validation' + - download: build + displayName: 'Download Pipeline Artifact - Signed NuGet Package' + artifact: 'drop-signed-nuget-GPU' - - task: PublishSecurityAnalysisLogs@3 - displayName: 'Publish Security Analysis Logs' - continueOnError: true + - script: move "$(Pipeline.Workspace)\build\drop-signed-nuget-GPU\*" "$(Build.BinariesDirectory)\nuget-artifact\final-package" - - task: PostAnalysis@2 - inputs: - GdnBreakAllTools: true - GdnBreakPolicy: M365 - GdnBreakPolicyMinSev: Error + - powershell: | + New-Item -Path $(Agent.TempDirectory) -Name "binfiles" -ItemType "directory" + $base_path_name = Join-Path -Path $(Agent.TempDirectory) -ChildPath "binfiles" + Get-ChildItem $Env:BUILD_BINARIESDIRECTORY\nuget-artifact\final-package -Filter *.nupkg | + Foreach-Object { + $dir_name = Join-Path -Path $base_path_name -ChildPath $_.Basename + $cmd = "7z.exe x $($_.FullName) -y -o$dir_name" + Write-Output $cmd + Invoke-Expression -Command $cmd + } + dir $(Agent.TempDirectory) + tree $(Agent.TempDirectory) + workingDirectory: '$(Agent.TempDirectory)' - - template: ../nuget/templates/get-nuget-package-version-as-variable.yml - parameters: - packageFolder: '$(Build.BinariesDirectory)/nuget-artifact/final-package' - #This task must be run on a Windows machine - - task: NuGetCommand@2 - displayName: 'NuGet push ${{ parameters.artifact_feed }}' - inputs: - command: push - packagesToPush: '$(Build.BinariesDirectory)/nuget-artifact/final-package/*.nupkg' - publishVstsFeed: 'PublicPackages/${{ parameters.artifact_feed }}' - allowPackageConflicts: true + - task: CodeSign@1 + displayName: 'Run Codesign Validation' + + - task: PublishSecurityAnalysisLogs@3 + displayName: 'Publish Security Analysis Logs' + continueOnError: true + + - task: PostAnalysis@2 + inputs: + GdnBreakAllTools: true + GdnBreakPolicy: M365 + GdnBreakPolicyMinSev: Error + + - template: ../nuget/templates/get-nuget-package-version-as-variable.yml + parameters: + packageFolder: '$(Build.BinariesDirectory)/nuget-artifact/final-package' + #This task must be run on a Windows machine + - task: 1ES.PublishNuget@1 + displayName: 'NuGet push ${{ parameters.artifact_feed }}' + inputs: + packagesToPush: '$(Build.BinariesDirectory)/nuget-artifact/final-package/*.nupkg' + packageParentPath: '$(Build.BinariesDirectory)' + publishVstsFeed: 'PublicPackages/${{ parameters.artifact_feed }}' + allowPackageConflicts: true From 1c5a0adeb7f15e88996a43ad09067fe46530558a Mon Sep 17 00:00:00 2001 From: Jian Chen Date: Mon, 24 Feb 2025 11:47:38 -0800 Subject: [PATCH 5/5] Make Nuget CUDA package pipeline 1ES compliant --- .../nuget-cuda-publishing-pipeline.yml | 48 ++++++++++++------- 1 file changed, 31 insertions(+), 17 deletions(-) diff --git a/tools/ci_build/github/azure-pipelines/nuget-cuda-publishing-pipeline.yml b/tools/ci_build/github/azure-pipelines/nuget-cuda-publishing-pipeline.yml index aeb250e1e0cbc..df4e328f49eaf 100644 --- a/tools/ci_build/github/azure-pipelines/nuget-cuda-publishing-pipeline.yml +++ b/tools/ci_build/github/azure-pipelines/nuget-cuda-publishing-pipeline.yml @@ -2,30 +2,44 @@ resources: pipelines: - pipeline: build source: 'CUDA-Zip-Nuget-Java-Packaging-Pipeline' - trigger: + trigger: branches: include: - main - rel-* branch: main + repositories: + - repository: 1esPipelines + type: git + name: 1ESPipelineTemplates/1ESPipelineTemplates + ref: refs/tags/release parameters: - - name: isReleaseBuild - type: boolean - default: false +- name: isReleaseBuild + type: boolean + default: false variables: - - name: ArtifactFeed - ${{ if eq(parameters.isReleaseBuild, false) }}: - value: ORT-Nightly - ${{ else }}: - value: onnxruntime-cuda-12 +- name: ArtifactFeed + ${{ if eq(parameters.isReleaseBuild, false) }}: + value: ORT-Nightly + ${{ else }}: + value: onnxruntime-cuda-12 +extends: + # The pipeline extends the 1ES PT which will inject different SDL and compliance tasks. + # For non-production pipelines, use "Unofficial" as defined below. + # For productions pipelines, use "Official". + template: v1/1ES.Official.PipelineTemplate.yml@1esPipelines + parameters: + sdl: + sourceAnalysisPool: + name: onnxruntime-Win-CPU-2022 + os: windows + stages: + - template: stages/nuget-cuda-publishing-stage.yml + parameters: + artifact_feed: $(ArtifactFeed) -stages: - - template: stages/nuget-cuda-publishing-stage.yml - parameters: - artifact_feed: $(ArtifactFeed) - - - template: stages/java-cuda-publishing-stage.yml - parameters: - artifact_feed: $(ArtifactFeed) \ No newline at end of file + - template: stages/java-cuda-publishing-stage.yml + parameters: + artifact_feed: $(ArtifactFeed) \ No newline at end of file