From 2431162ee9194b2051bdeb7fc6ce19af2bf76f0c Mon Sep 17 00:00:00 2001 From: Aditya Sharad <6874315+adityasharad@users.noreply.github.com> Date: Tue, 7 Dec 2021 18:42:59 -0800 Subject: [PATCH] Autobuild: Prefix invocations with CODEQL_RUNNER --- src/codeql.ts | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/src/codeql.ts b/src/codeql.ts index c7f64e60d..fde9eb47e 100644 --- a/src/codeql.ts +++ b/src/codeql.ts @@ -732,7 +732,17 @@ async function getCodeQLForCmd( "-Dmaven.wagon.http.pool=false", ].join(" "); - await runTool(autobuildCmd); + const runnerExecutable = process.env["CODEQL_RUNNER"] || ""; + // On Mac, prefixing with the runner executable is required to handle System Integrity Protection. + if (runnerExecutable) { + // Earlier steps (init) are expected to have written the runner executable path + // to the tracing environment, and the current step is expected to have + // correctly loaded that environment. + await runTool(runnerExecutable, [autobuildCmd]); + } else { + // Fallback in case CODEQL_RUNNER wasn't correctly set or loaded. + await runTool(autobuildCmd); + } }, async extractScannedLanguage(databasePath: string, language: Language) { // Get extractor location