diff --git a/.github/workflows/__bundle-toolcache.yml b/.github/workflows/__bundle-toolcache.yml index 9cc983a84..d12aeb6e7 100644 --- a/.github/workflows/__bundle-toolcache.yml +++ b/.github/workflows/__bundle-toolcache.yml @@ -80,7 +80,7 @@ jobs: - id: init uses: ./../action/init with: - languages: javascript + languages: javascript,python tools: ${{ steps.prepare-test.outputs.tools-url }} - uses: ./../action/analyze with: diff --git a/.github/workflows/__per-language-bundle-validation.yml b/.github/workflows/__per-language-bundle-validation.yml new file mode 100644 index 000000000..ea900a9e0 --- /dev/null +++ b/.github/workflows/__per-language-bundle-validation.yml @@ -0,0 +1,164 @@ +# Warning: This file is generated automatically, and should not be modified. +# Instead, please modify the template in the pr-checks directory and run: +# pr-checks/sync.sh +# to regenerate this file. + +name: PR Check - Per-language bundles +env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GO111MODULE: auto +on: + push: + branches: + - main + - releases/v* + pull_request: {} + merge_group: + types: + - checks_requested + schedule: + - cron: '0 5 * * *' + workflow_dispatch: + inputs: {} + workflow_call: + inputs: {} +defaults: + run: + shell: bash +concurrency: + cancel-in-progress: ${{ github.event_name == 'pull_request' || false }} + group: per-language-bundle-validation-${{github.ref}} +jobs: + per-language-bundle-validation: + strategy: + fail-fast: false + matrix: + include: + - language: actions + os: ubuntu-latest + version: nightly-latest + expected-extractors: actions javascript + - language: cpp + os: ubuntu-latest + version: nightly-latest + build-mode: manual + build-command: gcc -o main main.c + - language: csharp + os: ubuntu-latest + version: nightly-latest + build-mode: none + - language: go + os: ubuntu-latest + version: nightly-latest + build-mode: autobuild + - language: java + os: ubuntu-latest + version: nightly-latest + build-mode: none + - language: javascript + os: ubuntu-latest + version: nightly-latest + - language: python + os: ubuntu-latest + version: nightly-latest + - language: ruby + os: ubuntu-latest + version: nightly-latest + - language: rust + os: ubuntu-latest + version: nightly-latest + - language: swift + os: macos-latest-xlarge + version: nightly-latest + build-mode: autobuild + name: Per-language bundles + if: github.triggering_actor != 'dependabot[bot]' + permissions: + contents: read + security-events: read + timeout-minutes: 45 + runs-on: ${{ matrix.os }} + steps: + - name: Check out repository + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - name: Prepare test + id: prepare-test + uses: ./.github/actions/prepare-test + with: + version: ${{ matrix.version }} + use-all-platform-bundle: 'false' + setup-kotlin: 'true' + - uses: ./../action/init + id: init + with: + languages: ${{ matrix.language }} + build-mode: ${{ matrix['build-mode'] }} + tools: ${{ steps.prepare-test.outputs.tools-url }} + - name: Check that the bundle contains only the expected extractors + env: + CODEQL_PATH: ${{ steps.init.outputs.codeql-path }} + LANGUAGE: ${{ matrix.language }} + EXPECTED_EXTRACTORS: ${{ matrix['expected-extractors'] || matrix.language }} + run: | + extractors="$("$CODEQL_PATH" resolve languages --format=json | jq -r 'keys[]')" + echo "Extractors in the bundle:" + echo "$extractors" + echo "Expected: $EXPECTED_EXTRACTORS" + + for expected in $EXPECTED_EXTRACTORS; do + if ! echo "$extractors" | grep -qx "$expected"; then + echo "::error::The ${LANGUAGE} bundle does not contain the ${expected} extractor." + exit 1 + fi + done + + # If the bundle contained extractors beyond those the language needs, then it would not + # have been trimmed, and this job would be silently validating the combined bundle. + for other in actions cpp csharp go java javascript python ruby rust swift; do + if echo "$EXPECTED_EXTRACTORS" | grep -qw "$other"; then + continue + fi + if echo "$extractors" | grep -qx "$other"; then + echo "::error::The ${LANGUAGE} bundle also contains the ${other} extractor, so it is not trimmed." + exit 1 + fi + done + - name: Check that the bundle was not added to the toolcache + env: + CODEQL_PATH: ${{ steps.init.outputs.codeql-path }} + run: | + # A bundle that is missing most of its extractors must never be left in the toolcache, + # where a later job analyzing a different language could pick it up. The runner image + # ships with its own CodeQL in the toolcache, so check where this bundle was extracted to + # rather than whether the toolcache contains CodeQL at all. + echo "CodeQL is at $CODEQL_PATH" + if [[ "$CODEQL_PATH" == "$RUNNER_TOOL_CACHE"/* ]]; then + echo "::error::The per-language bundle was added to the toolcache at $CODEQL_PATH." + exit 1 + fi + if [[ "$CODEQL_PATH" != "$RUNNER_TEMP"/* ]]; then + echo "::error::Expected the per-language bundle to be extracted under $RUNNER_TEMP, but found it at $CODEQL_PATH." + exit 1 + fi + - name: Build code + if: matrix['build-command'] + run: ${{ matrix['build-command'] }} + - uses: ./../action/analyze + id: analysis + with: + upload-database: false + - name: Check that a database was created for the language + env: + DB_LOCATIONS: ${{ steps.analysis.outputs.db-locations }} + LANGUAGE: ${{ matrix.language }} + run: | + database="$(echo "$DB_LOCATIONS" | jq -r --arg lang "$LANGUAGE" '.[$lang] // empty')" + if [ -z "$database" ] || [ ! -d "$database" ]; then + echo "::error::No CodeQL database was created for ${LANGUAGE}." + echo "Databases: $DB_LOCATIONS" + exit 1 + fi + echo "Created a ${LANGUAGE} database at ${database}." + env: + CODEQL_ACTION_PER_LANGUAGE_BUNDLES: true + CODEQL_ACTION_TEST_MODE: true diff --git a/.github/workflows/codescanning-config-cli.yml b/.github/workflows/codescanning-config-cli.yml index 7bc6718e3..54474d58f 100644 --- a/.github/workflows/codescanning-config-cli.yml +++ b/.github/workflows/codescanning-config-cli.yml @@ -75,7 +75,8 @@ jobs: uses: ./../action/.github/actions/check-codescanning-config with: expected-config-file-contents: "{}" - languages: javascript + # Request multiple languages so later checks can reuse the combined bundle. + languages: javascript,python tools: ${{ steps.prepare-test.outputs.tools-url }} - name: Packs from input diff --git a/lib/entry-points.js b/lib/entry-points.js index 35c18d8af..88ad90dcf 100644 --- a/lib/entry-points.js +++ b/lib/entry-points.js @@ -27216,8 +27216,8 @@ var require_gte = __commonJS({ "node_modules/semver/functions/gte.js"(exports2, module2) { "use strict"; var compare3 = require_compare(); - var gte7 = (a, b, loose) => compare3(a, b, loose) >= 0; - module2.exports = gte7; + var gte8 = (a, b, loose) => compare3(a, b, loose) >= 0; + module2.exports = gte8; } }); @@ -27238,7 +27238,7 @@ var require_cmp = __commonJS({ var eq = require_eq(); var neq = require_neq(); var gt = require_gt(); - var gte7 = require_gte(); + var gte8 = require_gte(); var lt2 = require_lt(); var lte2 = require_lte(); var cmp = (a, op, b, loose) => { @@ -27268,7 +27268,7 @@ var require_cmp = __commonJS({ case ">": return gt(a, b, loose); case ">=": - return gte7(a, b, loose); + return gte8(a, b, loose); case "<": return lt2(a, b, loose); case "<=": @@ -28076,7 +28076,7 @@ var require_outside = __commonJS({ var gt = require_gt(); var lt2 = require_lt(); var lte2 = require_lte(); - var gte7 = require_gte(); + var gte8 = require_gte(); var outside = (version, range2, hilo, options) => { version = new SemVer(version, options); range2 = new Range2(range2, options); @@ -28091,7 +28091,7 @@ var require_outside = __commonJS({ break; case "<": gtfn = lt2; - ltefn = gte7; + ltefn = gte8; ltfn = gt; comp = "<"; ecomp = "<="; @@ -28406,7 +28406,7 @@ var require_semver2 = __commonJS({ var lt2 = require_lt(); var eq = require_eq(); var neq = require_neq(); - var gte7 = require_gte(); + var gte8 = require_gte(); var lte2 = require_lte(); var cmp = require_cmp(); var coerce3 = require_coerce(); @@ -28445,7 +28445,7 @@ var require_semver2 = __commonJS({ lt: lt2, eq, neq, - gte: gte7, + gte: gte8, lte: lte2, cmp, coerce: coerce3, @@ -31721,7 +31721,7 @@ var require_brace_expansion = __commonJS({ function lte2(i, y) { return i <= y; } - function gte7(i, y) { + function gte8(i, y) { return i >= y; } function combine2(acc, base, pre, values, max, maxLength, dropEmpties, outBase) { @@ -31754,7 +31754,7 @@ var require_brace_expansion = __commonJS({ var reverse = y < x; if (reverse) { incr *= -1; - test = gte7; + test = gte8; } var pad = n.some(isPadded2); var length = 0; @@ -33901,8 +33901,8 @@ var require_semver3 = __commonJS({ function neq(a, b, loose) { return compare3(a, b, loose) !== 0; } - exports2.gte = gte7; - function gte7(a, b, loose) { + exports2.gte = gte8; + function gte8(a, b, loose) { return compare3(a, b, loose) >= 0; } exports2.lte = lte2; @@ -33933,7 +33933,7 @@ var require_semver3 = __commonJS({ case ">": return gt(a, b, loose); case ">=": - return gte7(a, b, loose); + return gte8(a, b, loose); case "<": return lt2(a, b, loose); case "<=": @@ -34478,7 +34478,7 @@ var require_semver3 = __commonJS({ break; case "<": gtfn = lt2; - ltefn = gte7; + ltefn = gte8; ltfn = gt; comp = "<"; ecomp = "<="; @@ -34699,7 +34699,7 @@ var require_cacheUtils = __commonJS({ var crypto3 = __importStar2(require("crypto")); var fs32 = __importStar2(require("fs")); var path30 = __importStar2(require("path")); - var semver11 = __importStar2(require_semver3()); + var semver12 = __importStar2(require_semver3()); var util3 = __importStar2(require("util")); var constants_1 = require_constants7(); var versionSalt = "1.0"; @@ -34792,7 +34792,7 @@ var require_cacheUtils = __commonJS({ function getCompressionMethod() { return __awaiter2(this, void 0, void 0, function* () { const versionOutput = yield getVersion("zstd", ["--quiet"]); - const version = semver11.clean(versionOutput); + const version = semver12.clean(versionOutput); core32.debug(`zstd version: ${version}`); if (versionOutput === "") { return constants_1.CompressionMethod.Gzip; @@ -82401,7 +82401,7 @@ var require_manifest = __commonJS({ exports2._findMatch = _findMatch; exports2._getOsVersion = _getOsVersion; exports2._readLinuxVersionFile = _readLinuxVersionFile; - var semver11 = __importStar2(require_semver2()); + var semver12 = __importStar2(require_semver2()); var core_1 = require_core(); var os7 = require("os"); var cp = require("child_process"); @@ -82415,7 +82415,7 @@ var require_manifest = __commonJS({ for (const candidate of candidates) { const version = candidate.version; (0, core_1.debug)(`check ${version} satisfies ${versionSpec}`); - if (semver11.satisfies(version, versionSpec) && (!stable || candidate.stable === stable)) { + if (semver12.satisfies(version, versionSpec) && (!stable || candidate.stable === stable)) { file = candidate.files.find((item) => { (0, core_1.debug)(`${item.arch}===${archFilter} && ${item.platform}===${platFilter}`); let chk = item.arch === archFilter && item.platform === platFilter; @@ -82424,7 +82424,7 @@ var require_manifest = __commonJS({ if (osVersion === item.platform_version) { chk = true; } else { - chk = semver11.satisfies(osVersion, item.platform_version); + chk = semver12.satisfies(osVersion, item.platform_version); } } return chk; @@ -82684,7 +82684,7 @@ var require_tool_cache = __commonJS({ var os7 = __importStar2(require("os")); var path30 = __importStar2(require("path")); var httpm = __importStar2(require_lib()); - var semver11 = __importStar2(require_semver2()); + var semver12 = __importStar2(require_semver2()); var stream2 = __importStar2(require("stream")); var util3 = __importStar2(require("util")); var assert_1 = require("assert"); @@ -82957,7 +82957,7 @@ var require_tool_cache = __commonJS({ } function cacheDir2(sourceDir, tool, version, arch2) { return __awaiter2(this, void 0, void 0, function* () { - version = semver11.clean(version) || version; + version = semver12.clean(version) || version; arch2 = arch2 || os7.arch(); core32.debug(`Caching tool ${tool} ${version} ${arch2}`); core32.debug(`source dir: ${sourceDir}`); @@ -82975,7 +82975,7 @@ var require_tool_cache = __commonJS({ } function cacheFile(sourceFile, targetFile, tool, version, arch2) { return __awaiter2(this, void 0, void 0, function* () { - version = semver11.clean(version) || version; + version = semver12.clean(version) || version; arch2 = arch2 || os7.arch(); core32.debug(`Caching tool ${tool} ${version} ${arch2}`); core32.debug(`source file: ${sourceFile}`); @@ -83005,7 +83005,7 @@ var require_tool_cache = __commonJS({ } let toolPath = ""; if (versionSpec) { - versionSpec = semver11.clean(versionSpec) || ""; + versionSpec = semver12.clean(versionSpec) || ""; const cachePath = path30.join(_getCacheDirectory(), toolName, versionSpec, arch2); core32.debug(`checking cache: ${cachePath}`); if (fs32.existsSync(cachePath) && fs32.existsSync(`${cachePath}.complete`)) { @@ -83085,7 +83085,7 @@ var require_tool_cache = __commonJS({ } function _createToolPath(tool, version, arch2) { return __awaiter2(this, void 0, void 0, function* () { - const folderPath = path30.join(_getCacheDirectory(), tool, semver11.clean(version) || version, arch2 || ""); + const folderPath = path30.join(_getCacheDirectory(), tool, semver12.clean(version) || version, arch2 || ""); core32.debug(`destination ${folderPath}`); const markerPath = `${folderPath}.complete`; yield io9.rmRF(folderPath); @@ -83095,15 +83095,15 @@ var require_tool_cache = __commonJS({ }); } function _completeToolPath(tool, version, arch2) { - const folderPath = path30.join(_getCacheDirectory(), tool, semver11.clean(version) || version, arch2 || ""); + const folderPath = path30.join(_getCacheDirectory(), tool, semver12.clean(version) || version, arch2 || ""); const markerPath = `${folderPath}.complete`; fs32.writeFileSync(markerPath, ""); core32.debug("finished caching tool"); } function isExplicitVersion(versionSpec) { - const c = semver11.clean(versionSpec) || ""; + const c = semver12.clean(versionSpec) || ""; core32.debug(`isExplicit: ${c}`); - const valid4 = semver11.valid(c) != null; + const valid4 = semver12.valid(c) != null; core32.debug(`explicit? ${valid4}`); return valid4; } @@ -83111,14 +83111,14 @@ var require_tool_cache = __commonJS({ let version = ""; core32.debug(`evaluating ${versions.length} versions`); versions = versions.sort((a, b) => { - if (semver11.gt(a, b)) { + if (semver12.gt(a, b)) { return 1; } return -1; }); for (let i = versions.length - 1; i >= 0; i--) { const potential = versions[i]; - const satisfied = semver11.satisfies(potential, versionSpec); + const satisfied = semver12.satisfies(potential, versionSpec); if (satisfied) { version = potential; break; @@ -89595,7 +89595,7 @@ var require_brace_expansion2 = __commonJS({ function lte2(i, y) { return i <= y; } - function gte7(i, y) { + function gte8(i, y) { return i >= y; } function combine2(acc, pre, values, max, maxLength, dropEmpties) { @@ -89627,7 +89627,7 @@ var require_brace_expansion2 = __commonJS({ var reverse = y < x; if (reverse) { incr *= -1; - test = gte7; + test = gte8; } var pad = n.some(isPadded2); var length = 0; @@ -148091,6 +148091,11 @@ var featureConfig = { envVar: "CODEQL_ACTION_OVERLAY_ANALYSIS_SKIP_RESOURCE_CHECKS", minimumVersion: void 0 }, + ["per_language_bundles" /* PerLanguageBundles */]: { + defaultValue: false, + envVar: "CODEQL_ACTION_PER_LANGUAGE_BUNDLES", + minimumVersion: void 0 + }, ["qa_telemetry_enabled" /* QaTelemetryEnabled */]: { defaultValue: false, envVar: "CODEQL_ACTION_QA_TELEMETRY", @@ -151192,7 +151197,7 @@ var path13 = __toESM(require("path")); var core12 = __toESM(require_core()); var toolcache3 = __toESM(require_tool_cache()); var import_fast_deep_equal = __toESM(require_fast_deep_equal()); -var semver9 = __toESM(require_semver2()); +var semver10 = __toESM(require_semver2()); // src/overlay/caching.ts var fs11 = __toESM(require("fs")); @@ -151492,6 +151497,89 @@ async function getCodeQlVersionsForOverlayBaseDatabases(rawLanguages, logger) { return versions; } +// src/per-language-bundles.ts +var semver7 = __toESM(require_semver2()); +var MIN_PER_LANGUAGE_BUNDLE_CLI_VERSION = "2.27.1"; +var PER_LANGUAGE_BUNDLE_NAME = /^codeql-bundle-(.+)-(?:linux64|osx64|win64)\.tar\.(?:gz|zst)$/; +function tryGetBundleLanguageFromUrl(url2) { + let assetName; + try { + const pathname = new URL(url2).pathname; + assetName = decodeURIComponent(pathname.split("/").pop() ?? ""); + } catch { + return void 0; + } + const match2 = assetName.match(PER_LANGUAGE_BUNDLE_NAME); + return match2 ? parseBuiltInLanguage(match2[1]) : void 0; +} +var PER_LANGUAGE_BUNDLE_PLATFORMS = { + ["actions" /* actions */]: "linux64", + ["cpp" /* cpp */]: "linux64", + ["csharp" /* csharp */]: "linux64", + ["go" /* go */]: "linux64", + ["java" /* java */]: "linux64", + ["javascript" /* javascript */]: "linux64", + ["python" /* python */]: "linux64", + ["ruby" /* ruby */]: "linux64", + ["rust" /* rust */]: "linux64", + ["swift" /* swift */]: "osx64" +}; +async function getPerLanguageBundleLanguage(options, features, logger) { + const { + rawLanguages, + cliVersion: cliVersion2, + compressionMethod, + platform: platform2, + variant, + isNightly + } = options; + const explain = (reason) => { + logger.debug(`Not using a per-language CodeQL bundle since ${reason}.`); + return void 0; + }; + if (rawLanguages?.length !== 1) { + return explain( + `exactly one language must be requested via the 'languages' input, but ${rawLanguages?.length ?? 0} were` + ); + } + const language = parseBuiltInLanguage(rawLanguages[0]); + if (language === void 0) { + return explain(`'${rawLanguages[0]}' is not a known CodeQL language`); + } + if (compressionMethod !== "zstd") { + return explain(`the bundle would be downloaded as ${compressionMethod}`); + } + if (variant !== "GitHub.com" /* DOTCOM */) { + return explain(`we are running against ${variant}`); + } + if (!isGitHubHostedRunner()) { + return explain("the job is not running on a GitHub-hosted runner"); + } + if (!isNightly) { + if (cliVersion2 === void 0) { + return explain("the CLI version of the bundle is unknown"); + } + if (!semver7.gte(cliVersion2, MIN_PER_LANGUAGE_BUNDLE_CLI_VERSION)) { + return explain( + `CodeQL ${cliVersion2} is older than ${MIN_PER_LANGUAGE_BUNDLE_CLI_VERSION}, which is the first version that publishes per-language bundles` + ); + } + } + const supportedPlatform = PER_LANGUAGE_BUNDLE_PLATFORMS[language]; + if (supportedPlatform === void 0) { + return explain(`no per-language bundle is published for ${language}`); + } + if (supportedPlatform !== platform2) { + return explain( + `the ${language} bundle is only published for ${supportedPlatform}, but this job is running on ${platform2 ?? "an unknown platform"}` + ); + } + if (!await features.getValue("per_language_bundles" /* PerLanguageBundles */)) { + return explain(`the ${"per_language_bundles" /* PerLanguageBundles */} feature is disabled`); + } + return language; +} + // src/tar.ts var import_child_process = require("child_process"); var fs12 = __toESM(require("fs")); @@ -151499,7 +151587,7 @@ var stream = __toESM(require("stream")); var import_toolrunner = __toESM(require_toolrunner()); var io4 = __toESM(require_io()); var toolcache = __toESM(require_tool_cache()); -var semver7 = __toESM(require_semver2()); +var semver8 = __toESM(require_semver2()); var MIN_REQUIRED_BSD_TAR_VERSION = "3.4.3"; var MIN_REQUIRED_GNU_TAR_VERSION = "1.31"; async function getTarVersion() { @@ -151541,9 +151629,9 @@ async function isZstdAvailable(logger) { case "gnu": return { available: foundZstdBinary && // GNU tar only uses major and minor version numbers - semver7.gte( - semver7.coerce(version), - semver7.coerce(MIN_REQUIRED_GNU_TAR_VERSION) + semver8.gte( + semver8.coerce(version), + semver8.coerce(MIN_REQUIRED_GNU_TAR_VERSION) ), foundZstdBinary, version: tarVersion @@ -151552,7 +151640,7 @@ async function isZstdAvailable(logger) { return { available: foundZstdBinary && // Do a loose comparison since these version numbers don't contain // a patch version number. - semver7.gte(version, MIN_REQUIRED_BSD_TAR_VERSION), + semver8.gte(version, MIN_REQUIRED_BSD_TAR_VERSION), foundZstdBinary, version: tarVersion }; @@ -151661,7 +151749,7 @@ var core11 = __toESM(require_core()); var import_http_client = __toESM(require_lib()); var toolcache2 = __toESM(require_tool_cache()); var import_follow_redirects = __toESM(require_follow_redirects()); -var semver8 = __toESM(require_semver2()); +var semver9 = __toESM(require_semver2()); var STREAMING_HIGH_WATERMARK_BYTES = 4 * 1024 * 1024; var STREAMING_STALL_TIMEOUT_MS = 5 * 60 * 1e3; var TOOLCACHE_TOOL_NAME = "CodeQL"; @@ -151787,7 +151875,7 @@ function getToolcacheToolDirectory(env) { ); } function getToolcacheVersionDirectoryName(version) { - return semver8.clean(version) || version; + return semver9.clean(version) || version; } function getToolcacheDirectory(version) { return path12.join( @@ -151899,18 +151987,27 @@ function getCodeQLBundleExtension(compressionMethod) { assertNever(compressionMethod); } } -function getCodeQLBundleName(compressionMethod) { +function getBundlePlatform() { + switch (process.platform) { + case "win32": + return "win64"; + case "linux": + return process.arch === "arm64" ? "linux-arm64" : "linux64"; + case "darwin": + return "osx64"; + default: + return void 0; + } +} +function getCodeQLBundleName(compressionMethod, language) { const extension = getCodeQLBundleExtension(compressionMethod); - let platform2; - if (process.platform === "win32") { - platform2 = "win64"; - } else if (process.platform === "linux") { - platform2 = process.arch === "arm64" ? "linux-arm64" : "linux64"; - } else if (process.platform === "darwin") { - platform2 = "osx64"; - } else { + const platform2 = getBundlePlatform(); + if (platform2 === void 0) { return `codeql-bundle${extension}`; } + if (language !== void 0) { + return `codeql-bundle-${language}-${platform2}${extension}`; + } return `codeql-bundle-${platform2}${extension}`; } function getCodeQLActionRepository(logger) { @@ -151922,7 +152019,7 @@ function getCodeQLActionRepository(logger) { } return getRequiredEnvParam("GITHUB_ACTION_REPOSITORY"); } -async function getCodeQLBundleDownloadURL(tagName, apiDetails, compressionMethod, logger) { +async function getCodeQLBundleDownloadURL(tagName, apiDetails, codeQLBundleName, logger) { const codeQLActionRepository = getCodeQLActionRepository(logger); const potentialDownloadSources = [ // This GitHub instance, and this Action. @@ -151937,7 +152034,6 @@ async function getCodeQLBundleDownloadURL(tagName, apiDetails, compressionMethod return !self2.slice(0, index2).some((other) => (0, import_fast_deep_equal.default)(source, other)); } ); - const codeQLBundleName = getCodeQLBundleName(compressionMethod); for (const downloadSource of uniqueDownloadSources) { const [apiURL, repository] = downloadSource; if (apiURL === GITHUB_DOTCOM_URL && repository === CODEQL_DEFAULT_ACTION_REPOSITORY) { @@ -151992,13 +152088,13 @@ function tryGetTagNameFromUrl(url2, logger) { return match2[1]; } function convertToSemVer(version, logger) { - if (!semver9.valid(version)) { + if (!semver10.valid(version)) { logger.debug( `Bundle version ${version} is not in SemVer format. Will treat it as pre-release 0.0.0-${version}.` ); version = `0.0.0-${version}`; } - const s = semver9.clean(version); + const s = semver10.clean(version); if (!s) { throw new Error(`Bundle version ${version} is not in SemVer format.`); } @@ -152126,6 +152222,7 @@ async function getCodeQLSource(toolsInput, defaultCliVersion, rawLanguages, useO let cliVersion2; let tagName; let url2; + let bundle; const canForceNightlyWithFF = isDynamicWorkflow() || isInTestMode(); const forceNightlyValueFF = await features.getValue("force_nightly" /* ForceNightly */); const forceNightly = forceNightlyValueFF && canForceNightlyWithFF; @@ -152156,7 +152253,8 @@ async function getCodeQLSource(toolsInput, defaultCliVersion, rawLanguages, useO `Using the latest CodeQL CLI nightly, as requested by 'tools: ${toolsInput}'.` ); } - toolsInput = await getNightlyToolsUrl(logger); + bundle = await getNightlyBundle(rawLanguages, variant, features, logger); + toolsInput = bundle.url; } const forceShippedTools = toolsInput && CODEQL_BUNDLE_VERSION_ALIAS.includes(toolsInput); if (forceShippedTools) { @@ -152207,7 +152305,7 @@ async function getCodeQLSource(toolsInput, defaultCliVersion, rawLanguages, useO url2 = toolsInput; if (tagName) { const bundleVersion3 = tryGetBundleVersionFromTagName(tagName, logger); - if (bundleVersion3 !== void 0 && semver9.valid(bundleVersion3)) { + if (bundleVersion3 !== void 0 && semver10.valid(bundleVersion3)) { cliVersion2 = convertToSemVer(bundleVersion3, logger); } } @@ -152310,12 +152408,38 @@ async function getCodeQLSource(toolsInput, defaultCliVersion, rawLanguages, useO let compressionMethod; if (!url2) { compressionMethod = cliVersion2 !== void 0 && await useZstdBundle(cliVersion2, tarSupportsZstd) ? "zstd" : "gzip"; - url2 = await getCodeQLBundleDownloadURL( - tagName, - apiDetails, - compressionMethod, + const perLanguageBundleLanguage = await getPerLanguageBundleLanguage( + { + rawLanguages, + cliVersion: cliVersion2, + compressionMethod, + platform: getBundlePlatform(), + variant + }, + features, logger ); + const resolveBundleURL = (language) => getCodeQLBundleDownloadURL( + tagName, + apiDetails, + getCodeQLBundleName(compressionMethod, language), + logger + ); + if (perLanguageBundleLanguage !== void 0) { + logger.info( + `Downloading the ${perLanguageBundleLanguage} CodeQL bundle, since ${perLanguageBundleLanguage} is the only language being analyzed.` + ); + url2 = await resolveBundleURL(perLanguageBundleLanguage); + bundle = { + kind: "per-language", + url: url2, + language: perLanguageBundleLanguage, + combinedBundleURL: await resolveBundleURL() + }; + } else { + url2 = await resolveBundleURL(); + bundle = { kind: "combined", url: url2 }; + } } else { const method = inferCompressionMethod(url2); if (method === void 0) { @@ -152324,6 +152448,15 @@ async function getCodeQLSource(toolsInput, defaultCliVersion, rawLanguages, useO ); } compressionMethod = method; + if (bundle === void 0) { + const language = tryGetBundleLanguageFromUrl(url2); + bundle = language === void 0 ? { kind: "combined", url: url2 } : { kind: "per-language", url: url2, language }; + } + if (bundle.kind === "per-language") { + logger.info( + `${url2} appears to be a CodeQL bundle that contains only ${bundle.language}.` + ); + } } if (cliVersion2) { logger.info(`Using CodeQL CLI version ${cliVersion2} sourced from ${url2} .`); @@ -152331,7 +152464,7 @@ async function getCodeQLSource(toolsInput, defaultCliVersion, rawLanguages, useO logger.info(`Using CodeQL CLI sourced from ${url2} .`); } return { - bundle: { kind: "combined", url: url2 }, + bundle, bundleVersion: bundleVersion2, cliVersion: cliVersion2, compressionMethod, @@ -152383,7 +152516,7 @@ var downloadCodeQL = async function(source, apiDetails, tarVersion, tempDir, log writeToolcacheMarkerFile(toolcacheDestination, logger); } else { logger.debug( - `Could not cache CodeQL tools because we could not determine the bundle version from the URL ${codeqlURL}.` + bundle.kind === "per-language" ? "Not caching the CodeQL tools because they came from a bundle that contains only a single language." : `Could not cache CodeQL tools because we could not determine the bundle version from the URL ${codeqlURL}.` ); } return { @@ -152392,7 +152525,7 @@ var downloadCodeQL = async function(source, apiDetails, tarVersion, tempDir, log }; }; function getToolcacheDestination(source, logger) { - if (!source.bundleVersion) { + if (source.bundle.kind !== "combined" || !source.bundleVersion) { return void 0; } return getToolcacheDirectory( @@ -152496,30 +152629,77 @@ async function setupCodeQLBundle(toolsInput, apiDetails, tempDir, variant, defau }; } async function downloadCodeQLBundle(action, source, apiDetails, tarVersion, tempDir) { + const { bundle } = source; + const { logger } = action; await tryDeleteToolcacheBundles(action); - return await downloadCodeQL( - source, - apiDetails, - tarVersion, - tempDir, - action.logger - ); + try { + const result = await downloadCodeQL( + source, + apiDetails, + tarVersion, + tempDir, + logger + ); + return bundle.kind === "combined" ? result : { + ...result, + statusReport: { + ...result.statusReport, + bundleLanguage: bundle.language + } + }; + } catch (e) { + if (bundle.kind !== "per-language" || bundle.combinedBundleURL === void 0 || asHTTPError(e)?.status !== 404) { + throw e; + } + logger.warning( + `No ${bundle.language} CodeQL bundle was found at ${bundle.url}, so falling back to the bundle that contains all languages. This analysis will still produce correct results, but will take longer to set up.` + ); + const result = await downloadCodeQL( + { + ...source, + bundle: { kind: "combined", url: bundle.combinedBundleURL } + }, + apiDetails, + tarVersion, + tempDir, + logger + ); + return { + ...result, + statusReport: { + ...result.statusReport, + perLanguageBundleFallback: true + } + }; + } } async function useZstdBundle(cliVersion2, tarSupportsZstd) { return ( // In testing, gzip performs better than zstd on Windows. - process.platform !== "win32" && tarSupportsZstd && semver9.gte(cliVersion2, CODEQL_VERSION_ZSTD_BUNDLE) + process.platform !== "win32" && tarSupportsZstd && semver10.gte(cliVersion2, CODEQL_VERSION_ZSTD_BUNDLE) ); } function getTempExtractionDir(tempDir) { return path13.join(tempDir, v4_default()); } -async function getNightlyToolsUrl(logger) { +async function getNightlyBundle(rawLanguages, variant, features, logger) { const zstdAvailability = await isZstdAvailable(logger); const compressionMethod = await useZstdBundle( CODEQL_VERSION_ZSTD_BUNDLE, zstdAvailability.available ) ? "zstd" : "gzip"; + const language = await getPerLanguageBundleLanguage( + { + rawLanguages, + cliVersion: void 0, + compressionMethod, + platform: getBundlePlatform(), + variant, + isNightly: true + }, + features, + logger + ); try { const release2 = await getApiClient().rest.repos.listReleases({ owner: CODEQL_NIGHTLIES_REPOSITORY_OWNER, @@ -152532,7 +152712,14 @@ async function getNightlyToolsUrl(logger) { if (!latestRelease) { throw new Error("Could not find the latest nightly release."); } - return `https://github.com/${CODEQL_NIGHTLIES_REPOSITORY_OWNER}/${CODEQL_NIGHTLIES_REPOSITORY_NAME}/releases/download/${latestRelease.tag_name}/${getCodeQLBundleName(compressionMethod)}`; + const assetUrl = (name) => `https://github.com/${CODEQL_NIGHTLIES_REPOSITORY_OWNER}/${CODEQL_NIGHTLIES_REPOSITORY_NAME}/releases/download/${latestRelease.tag_name}/${name}`; + const url2 = assetUrl(getCodeQLBundleName(compressionMethod, language)); + return language === void 0 ? { kind: "combined", url: url2 } : { + kind: "per-language", + url: url2, + language, + combinedBundleURL: assetUrl(getCodeQLBundleName(compressionMethod)) + }; } catch (e) { throw new Error( `Failed to retrieve the latest nightly release: ${wrapError(e)}` @@ -152540,7 +152727,7 @@ async function getNightlyToolsUrl(logger) { } } function getLatestToolcacheVersion(logger) { - const allVersions = toolcache3.findAllVersions("CodeQL").sort((a, b) => semver9.compare(b, a)); + const allVersions = toolcache3.findAllVersions("CodeQL").sort((a, b) => semver10.compare(b, a)); logger.debug( `Found the following versions of the CodeQL tools in the toolcache: ${JSON.stringify( allVersions @@ -156724,7 +156911,7 @@ function isPadded(el) { function lte(i, y) { return i <= y; } -function gte6(i, y) { +function gte7(i, y) { return i >= y; } function combine(acc, pre, values, max, maxLength, dropEmpties) { @@ -156759,7 +156946,7 @@ function expandSequence(body, isAlphaSequence, max, maxLength) { const reverse = y < x; if (reverse) { incr *= -1; - test = gte6; + test = gte7; } const pad = n.some(isPadded); let length = 0; @@ -158656,7 +158843,7 @@ var import_async = __toESM(require_async(), 1); var import_path7 = require("path"); // node_modules/archiver/lib/error.js -var import_util34 = __toESM(require("util"), 1); +var import_util35 = __toESM(require("util"), 1); var ERROR_CODES = { ABORTED: "archive was aborted", DIRECTORYDIRPATHREQUIRED: "diretory dirpath argument must be a non-empty string value", @@ -158681,7 +158868,7 @@ function ArchiverError(code, data) { this.code = code; this.data = data; } -import_util34.default.inherits(ArchiverError, Error); +import_util35.default.inherits(ArchiverError, Error); // node_modules/archiver/lib/core.js var import_readable_stream2 = __toESM(require_ours(), 1); @@ -161613,7 +161800,7 @@ var fs29 = __toESM(require("fs")); var path25 = __toESM(require("path")); var core22 = __toESM(require_core()); var io7 = __toESM(require_io()); -var semver10 = __toESM(require_semver2()); +var semver11 = __toESM(require_semver2()); // src/config/inputs.ts async function getToolsInput(action, repositoryProperties) { @@ -161974,6 +162161,12 @@ async function sendCompletedStatusReport2(startedAt, config, configFile, toolsIn if (toolsDownloadStatusReport?.totalDurationMs !== void 0) { initToolsDownloadFields.tools_total_duration_ms = toolsDownloadStatusReport.totalDurationMs; } + if (toolsDownloadStatusReport?.bundleLanguage !== void 0) { + initToolsDownloadFields.tools_bundle_language = toolsDownloadStatusReport.bundleLanguage; + } + if (toolsDownloadStatusReport?.perLanguageBundleFallback !== void 0) { + initToolsDownloadFields.tools_per_language_bundle_fallback = toolsDownloadStatusReport.perLanguageBundleFallback; + } if (toolsFeatureFlagsValid !== void 0) { initToolsDownloadFields.tools_feature_flags_valid = toolsFeatureFlagsValid; } @@ -162093,12 +162286,12 @@ async function run3(actionState) { const experimental = "2.19.3"; const publicPreview = "2.22.1"; const actualVer = (await codeql.getVersion()).version; - if (semver10.lt(actualVer, experimental)) { + if (semver11.lt(actualVer, experimental)) { throw new ConfigurationError( `Rust analysis is supported by CodeQL CLI version ${experimental} or higher, but found version ${actualVer}` ); } - if (semver10.lt(actualVer, publicPreview)) { + if (semver11.lt(actualVer, publicPreview)) { core22.exportVariable("CODEQL_ENABLE_EXPERIMENTAL_FEATURES" /* EXPERIMENTAL_FEATURES */, "true"); logger.info("Experimental Rust analysis enabled"); } @@ -163022,6 +163215,12 @@ async function sendCompletedStatusReport3(startedAt, toolsInput, toolsDownloadSt if (toolsDownloadStatusReport?.totalDurationMs !== void 0) { initToolsDownloadFields.tools_total_duration_ms = toolsDownloadStatusReport.totalDurationMs; } + if (toolsDownloadStatusReport?.bundleLanguage !== void 0) { + initToolsDownloadFields.tools_bundle_language = toolsDownloadStatusReport.bundleLanguage; + } + if (toolsDownloadStatusReport?.perLanguageBundleFallback !== void 0) { + initToolsDownloadFields.tools_per_language_bundle_fallback = toolsDownloadStatusReport.perLanguageBundleFallback; + } if (toolsFeatureFlagsValid !== void 0) { initToolsDownloadFields.tools_feature_flags_valid = toolsFeatureFlagsValid; } diff --git a/pr-checks/checks/bundle-toolcache.yml b/pr-checks/checks/bundle-toolcache.yml index 83d1d7d0b..efa1a4d76 100644 --- a/pr-checks/checks/bundle-toolcache.yml +++ b/pr-checks/checks/bundle-toolcache.yml @@ -30,7 +30,7 @@ steps: - id: init uses: ./../action/init with: - languages: javascript + languages: javascript,python tools: ${{ steps.prepare-test.outputs.tools-url }} - uses: ./../action/analyze with: diff --git a/pr-checks/checks/per-language-bundle-validation.yml b/pr-checks/checks/per-language-bundle-validation.yml new file mode 100644 index 000000000..21fe33e75 --- /dev/null +++ b/pr-checks/checks/per-language-bundle-validation.yml @@ -0,0 +1,117 @@ +name: Per-language bundles +description: Validates extraction and analysis using each per-language CodeQL bundle. +# TODO: Use a released bundle once releases include per-language bundles. +matrix: + include: + - language: actions + os: ubuntu-latest + version: nightly-latest + # Actions also needs the JavaScript extractor. + expected-extractors: actions javascript + - language: cpp + os: ubuntu-latest + version: nightly-latest + build-mode: manual + build-command: gcc -o main main.c + - language: csharp + os: ubuntu-latest + version: nightly-latest + build-mode: none + - language: go + os: ubuntu-latest + version: nightly-latest + build-mode: autobuild + - language: java + os: ubuntu-latest + version: nightly-latest + build-mode: none + - language: javascript + os: ubuntu-latest + version: nightly-latest + - language: python + os: ubuntu-latest + version: nightly-latest + - language: ruby + os: ubuntu-latest + version: nightly-latest + - language: rust + os: ubuntu-latest + version: nightly-latest + - language: swift + os: macos-latest-xlarge + version: nightly-latest + build-mode: autobuild +env: + CODEQL_ACTION_PER_LANGUAGE_BUNDLES: true +steps: + - uses: ./../action/init + id: init + with: + languages: ${{ matrix.language }} + build-mode: ${{ matrix['build-mode'] }} + tools: ${{ steps.prepare-test.outputs.tools-url }} + - name: Check that the bundle contains only the expected extractors + env: + CODEQL_PATH: ${{ steps.init.outputs.codeql-path }} + LANGUAGE: ${{ matrix.language }} + EXPECTED_EXTRACTORS: ${{ matrix['expected-extractors'] || matrix.language }} + run: | + extractors="$("$CODEQL_PATH" resolve languages --format=json | jq -r 'keys[]')" + echo "Extractors in the bundle:" + echo "$extractors" + echo "Expected: $EXPECTED_EXTRACTORS" + + for expected in $EXPECTED_EXTRACTORS; do + if ! echo "$extractors" | grep -qx "$expected"; then + echo "::error::The ${LANGUAGE} bundle does not contain the ${expected} extractor." + exit 1 + fi + done + + # If the bundle contained extractors beyond those the language needs, then it would not + # have been trimmed, and this job would be silently validating the combined bundle. + for other in actions cpp csharp go java javascript python ruby rust swift; do + if echo "$EXPECTED_EXTRACTORS" | grep -qw "$other"; then + continue + fi + if echo "$extractors" | grep -qx "$other"; then + echo "::error::The ${LANGUAGE} bundle also contains the ${other} extractor, so it is not trimmed." + exit 1 + fi + done + - name: Check that the bundle was not added to the toolcache + env: + CODEQL_PATH: ${{ steps.init.outputs.codeql-path }} + run: | + # A bundle that is missing most of its extractors must never be left in the toolcache, + # where a later job analyzing a different language could pick it up. The runner image + # ships with its own CodeQL in the toolcache, so check where this bundle was extracted to + # rather than whether the toolcache contains CodeQL at all. + echo "CodeQL is at $CODEQL_PATH" + if [[ "$CODEQL_PATH" == "$RUNNER_TOOL_CACHE"/* ]]; then + echo "::error::The per-language bundle was added to the toolcache at $CODEQL_PATH." + exit 1 + fi + if [[ "$CODEQL_PATH" != "$RUNNER_TEMP"/* ]]; then + echo "::error::Expected the per-language bundle to be extracted under $RUNNER_TEMP, but found it at $CODEQL_PATH." + exit 1 + fi + - name: Build code + if: matrix['build-command'] + run: ${{ matrix['build-command'] }} + - uses: ./../action/analyze + id: analysis + with: + upload-database: false + - name: Check that a database was created for the language + env: + DB_LOCATIONS: ${{ steps.analysis.outputs.db-locations }} + LANGUAGE: ${{ matrix.language }} + run: | + database="$(echo "$DB_LOCATIONS" | jq -r --arg lang "$LANGUAGE" '.[$lang] // empty')" + if [ -z "$database" ] || [ ! -d "$database" ]; then + echo "::error::No CodeQL database was created for ${LANGUAGE}." + echo "Databases: $DB_LOCATIONS" + exit 1 + fi + echo "Created a ${LANGUAGE} database at ${database}." diff --git a/pr-checks/sync.ts b/pr-checks/sync.ts index 6dde1ee48..f0942ad2d 100755 --- a/pr-checks/sync.ts +++ b/pr-checks/sync.ts @@ -79,6 +79,8 @@ interface Specification extends JobSpecification { useAllPlatformBundle?: string; /** Values for the `analysis-kinds` matrix dimension. */ analysisKinds?: string[]; + /** Overrides the generated job matrix using GitHub Actions matrix syntax. */ + matrix?: Record; /** Container image configuration for the job. */ container?: any; @@ -512,9 +514,6 @@ function generateJob( specDocument: yaml.Document, checkSpecification: Specification, ) { - const matrix: Array> = - generateJobMatrix(checkSpecification); - const useAllPlatformBundle = checkSpecification.useAllPlatformBundle ? checkSpecification.useAllPlatformBundle : "false"; @@ -567,8 +566,8 @@ function generateJob( const checkJob: Record = { strategy: { "fail-fast": false, - matrix: { - include: matrix, + matrix: checkSpecification.matrix ?? { + include: generateJobMatrix(checkSpecification), }, }, name: checkSpecification.name, diff --git a/src/feature-flags.ts b/src/feature-flags.ts index da7bccead..afddaea2a 100644 --- a/src/feature-flags.ts +++ b/src/feature-flags.ts @@ -164,6 +164,11 @@ export enum Feature { OverlayAnalysisStatusCheck = "overlay_analysis_status_check", /** Controls whether overlay build failures on the default branch are stored in the Actions cache. */ OverlayAnalysisStatusSave = "overlay_analysis_status_save", + /** + * Controls whether we may download a bundle containing only the single language being analysed, + * rather than the combined bundle that contains every language. + */ + PerLanguageBundles = "per_language_bundles", QaTelemetryEnabled = "qa_telemetry_enabled", /** Routes (some) API requests through the registry proxy. */ ProxyApiRequests = "proxy_api_requests", @@ -434,6 +439,11 @@ export const featureConfig = { envVar: "CODEQL_ACTION_OVERLAY_ANALYSIS_SKIP_RESOURCE_CHECKS", minimumVersion: undefined, }, + [Feature.PerLanguageBundles]: { + defaultValue: false, + envVar: "CODEQL_ACTION_PER_LANGUAGE_BUNDLES", + minimumVersion: undefined, + }, [Feature.QaTelemetryEnabled]: { defaultValue: false, envVar: "CODEQL_ACTION_QA_TELEMETRY", diff --git a/src/init-action.ts b/src/init-action.ts index 8173d67aa..dd576548d 100644 --- a/src/init-action.ts +++ b/src/init-action.ts @@ -182,6 +182,14 @@ async function sendCompletedStatusReport( initToolsDownloadFields.tools_total_duration_ms = toolsDownloadStatusReport.totalDurationMs; } + if (toolsDownloadStatusReport?.bundleLanguage !== undefined) { + initToolsDownloadFields.tools_bundle_language = + toolsDownloadStatusReport.bundleLanguage; + } + if (toolsDownloadStatusReport?.perLanguageBundleFallback !== undefined) { + initToolsDownloadFields.tools_per_language_bundle_fallback = + toolsDownloadStatusReport.perLanguageBundleFallback; + } if (toolsFeatureFlagsValid !== undefined) { initToolsDownloadFields.tools_feature_flags_valid = toolsFeatureFlagsValid; } diff --git a/src/per-language-bundles.test.ts b/src/per-language-bundles.test.ts new file mode 100644 index 000000000..8242bd014 --- /dev/null +++ b/src/per-language-bundles.test.ts @@ -0,0 +1,189 @@ +import test from "ava"; + +import { ActionsEnvVars } from "./environment"; +import { Feature } from "./feature-flags"; +import { BuiltInLanguage } from "./languages"; +import { getRunnerLogger } from "./logging"; +import { + getPerLanguageBundleLanguage, + MIN_PER_LANGUAGE_BUNDLE_CLI_VERSION, + PerLanguageBundleOptions, + tryGetBundleLanguageFromUrl, +} from "./per-language-bundles"; +import { createFeatures, setupTests } from "./testing-utils"; +import { GitHubVariant } from "./util"; + +setupTests(test); + +/** Options for which we would use a per-language bundle. */ +const ELIGIBLE_OPTIONS: PerLanguageBundleOptions = { + rawLanguages: ["java"], + // Any version at least as new as the minimum will do. + cliVersion: MIN_PER_LANGUAGE_BUNDLE_CLI_VERSION, + compressionMethod: "zstd", + platform: "linux64", + variant: GitHubVariant.DOTCOM, +}; + +async function checkEligibility( + overrides: Partial, + enabledFeatures: Feature[] = [Feature.PerLanguageBundles], +) { + return getPerLanguageBundleLanguage( + { ...ELIGIBLE_OPTIONS, ...overrides }, + createFeatures(enabledFeatures), + getRunnerLogger(true), + ); +} + +test.beforeEach(() => { + process.env[ActionsEnvVars.RUNNER_ENVIRONMENT] = "github-hosted"; +}); + +test.serial("uses Linux bundles for non-Swift languages", async (t) => { + for (const language of Object.values(BuiltInLanguage)) { + if (language === BuiltInLanguage.swift) { + continue; + } + t.is(await checkEligibility({ rawLanguages: [language] }), language); + } +}); + +test.serial("normalizes an alias before selecting a bundle", async (t) => { + t.is( + await checkEligibility({ rawLanguages: ["java-kotlin"] }), + BuiltInLanguage.java, + ); +}); + +test.serial("uses the macOS bundle for Swift", async (t) => { + t.is( + await checkEligibility({ rawLanguages: ["swift"], platform: "osx64" }), + BuiltInLanguage.swift, + ); + // Swift is only published for macOS. + t.is( + await checkEligibility({ rawLanguages: ["swift"], platform: "linux64" }), + undefined, + ); +}); + +test.serial("only publishes non-Swift languages for Linux", async (t) => { + t.is(await checkEligibility({ platform: "osx64" }), undefined); + t.is(await checkEligibility({ platform: "win64" }), undefined); + // We do not publish per-language bundles for Linux Arm64 either. + t.is(await checkEligibility({ platform: "linux-arm64" }), undefined); + t.is(await checkEligibility({ platform: undefined }), undefined); +}); + +test.serial("requires exactly one language", async (t) => { + t.is(await checkEligibility({ rawLanguages: undefined }), undefined); + t.is(await checkEligibility({ rawLanguages: [] }), undefined); + t.is(await checkEligibility({ rawLanguages: ["java", "python"] }), undefined); +}); + +test.serial("requires a language that CodeQL knows about", async (t) => { + t.is(await checkEligibility({ rawLanguages: ["cobol"] }), undefined); +}); + +test.serial("requires a zstd bundle", async (t) => { + t.is(await checkEligibility({ compressionMethod: "gzip" }), undefined); +}); + +test.serial("requires GitHub.com", async (t) => { + // Other products resolve the combined bundle against their own instance, so asking for a + // per-language bundle they do not mirror would move the download off that instance. + for (const variant of [GitHubVariant.GHES, GitHubVariant.GHEC_DR]) { + t.is(await checkEligibility({ variant }), undefined); + } +}); + +test.serial("requires a GitHub-hosted runner", async (t) => { + // A self-hosted runner may have a toolcache that persists between jobs, which is worth more than + // a smaller download. + process.env[ActionsEnvVars.RUNNER_ENVIRONMENT] = "self-hosted"; + t.is(await checkEligibility({}), undefined); + + // Self-hosted runners are routinely configured to look like hosted ones, for example by mounting + // a persistent volume at `/opt/hostedtoolcache`, so we require the service to tell us explicitly. + delete process.env[ActionsEnvVars.RUNNER_ENVIRONMENT]; + process.env["RUNNER_TOOL_CACHE"] = "/opt/hostedtoolcache"; + t.is(await checkEligibility({}), undefined); +}); + +test.serial("requires a new enough CLI version", async (t) => { + t.is(await checkEligibility({ cliVersion: undefined }), undefined); + t.is(await checkEligibility({ cliVersion: "2.27.0" }), undefined); + t.is(await checkEligibility({ cliVersion: "2.27.1" }), BuiltInLanguage.java); +}); + +test.serial("requires the feature flag", async (t) => { + t.is(await checkEligibility({}, []), undefined); +}); + +test.serial("nightlies skip only the release version check", async (t) => { + const nightly = { isNightly: true, cliVersion: undefined }; + t.is(await checkEligibility(nightly), BuiltInLanguage.java); + + for (const overrides of [ + { rawLanguages: undefined }, + { rawLanguages: ["java", "python"] }, + { compressionMethod: "gzip" as const }, + { platform: "osx64" }, + { variant: GitHubVariant.GHES }, + { variant: GitHubVariant.GHEC_DR }, + ]) { + t.is(await checkEligibility({ ...nightly, ...overrides }), undefined); + } + t.is(await checkEligibility(nightly, []), undefined); + process.env[ActionsEnvVars.RUNNER_ENVIRONMENT] = "self-hosted"; + t.is(await checkEligibility(nightly), undefined); +}); + +test.serial("recognizes a per-language bundle from its URL", (t) => { + const url = (name: string) => + `https://github.com/github/codeql-action/releases/download/codeql-bundle-v1.2.3/${name}`; + + t.is( + tryGetBundleLanguageFromUrl(url("codeql-bundle-java-linux64.tar.zst")), + BuiltInLanguage.java, + ); + t.is( + tryGetBundleLanguageFromUrl(url("codeql-bundle-swift-osx64.tar.zst")), + BuiltInLanguage.swift, + ); + // We do not publish these, but should still recognize them if we ever do. + t.is( + tryGetBundleLanguageFromUrl(url("codeql-bundle-csharp-win64.tar.gz")), + BuiltInLanguage.csharp, + ); + // A percent-encoded name resolves to the same asset, so it must not let a bundle that contains a + // single language pass for one that contains them all and end up in the toolcache. + t.is( + tryGetBundleLanguageFromUrl(url("codeql-bundle-%70ython-linux64.tar.zst")), + BuiltInLanguage.python, + ); +}); + +test.serial("does not mistake other bundles for per-language ones", (t) => { + const url = (name: string) => + `https://github.com/github/codeql-action/releases/download/codeql-bundle-v1.2.3/${name}`; + + for (const name of [ + "codeql-bundle-linux64.tar.zst", + "codeql-bundle-osx64.tar.gz", + "codeql-bundle-win64.tar.zst", + // The all-platform bundle. + "codeql-bundle.tar.gz", + // A platform we do not publish per-language bundles for, whose name also contains a hyphen. + "codeql-bundle-linux-arm64.tar.zst", + // Not a language we know about. + "codeql-bundle-cobol-linux64.tar.zst", + // A name we cannot decode must not be mistaken for a language either. + "codeql-bundle-%zz-linux64.tar.zst", + ]) { + t.is(tryGetBundleLanguageFromUrl(url(name)), undefined, name); + } + + t.is(tryGetBundleLanguageFromUrl("not a url"), undefined); +}); diff --git a/src/per-language-bundles.ts b/src/per-language-bundles.ts new file mode 100644 index 000000000..1b63e4f10 --- /dev/null +++ b/src/per-language-bundles.ts @@ -0,0 +1,142 @@ +import * as semver from "semver"; + +import { isGitHubHostedRunner } from "./actions-util"; +import { Feature, FeatureEnablement } from "./feature-flags"; +import { BuiltInLanguage, parseBuiltInLanguage } from "./languages"; +import { Logger } from "./logging"; +import * as tar from "./tar"; +import { GitHubVariant } from "./util"; + +/** Minimum CLI version for selecting a per-language release bundle. */ +export const MIN_PER_LANGUAGE_BUNDLE_CLI_VERSION = "2.27.1"; + +const PER_LANGUAGE_BUNDLE_NAME = + /^codeql-bundle-(.+)-(?:linux64|osx64|win64)\.tar\.(?:gz|zst)$/; + +/** Identifies per-language tools URLs that must not populate the toolcache. */ +export function tryGetBundleLanguageFromUrl( + url: string, +): BuiltInLanguage | undefined { + let assetName: string; + try { + const pathname = new URL(url).pathname; + // URL-encoded names must not bypass the toolcache safeguard. + assetName = decodeURIComponent(pathname.split("/").pop() ?? ""); + } catch { + return undefined; + } + + const match = assetName.match(PER_LANGUAGE_BUNDLE_NAME); + return match ? parseBuiltInLanguage(match[1]) : undefined; +} + +/** Published platform for each language; absent entries are ineligible. */ +const PER_LANGUAGE_BUNDLE_PLATFORMS: Readonly< + Partial> +> = { + [BuiltInLanguage.actions]: "linux64", + [BuiltInLanguage.cpp]: "linux64", + [BuiltInLanguage.csharp]: "linux64", + [BuiltInLanguage.go]: "linux64", + [BuiltInLanguage.java]: "linux64", + [BuiltInLanguage.javascript]: "linux64", + [BuiltInLanguage.python]: "linux64", + [BuiltInLanguage.ruby]: "linux64", + [BuiltInLanguage.rust]: "linux64", + [BuiltInLanguage.swift]: "osx64", +}; + +/** Inputs that determine whether we may download a per-language bundle. */ +export interface PerLanguageBundleOptions { + /** Explicit input only: autodetection needs a CLI instance. */ + rawLanguages: string[] | undefined; + /** CLI version, if known. Ignored for nightly bundles. */ + cliVersion: string | undefined; + compressionMethod: tar.CompressionMethod; + /** Bundle platform identifier, such as linux64. */ + platform: string | undefined; + variant: GitHubVariant; + isNightly?: boolean; +} + +/** Returns the eligible bundle language, or undefined for the combined bundle. */ +export async function getPerLanguageBundleLanguage( + options: PerLanguageBundleOptions, + features: FeatureEnablement, + logger: Logger, +): Promise { + const { + rawLanguages, + cliVersion, + compressionMethod, + platform, + variant, + isNightly, + } = options; + + const explain = (reason: string) => { + logger.debug(`Not using a per-language CodeQL bundle since ${reason}.`); + return undefined; + }; + + if (rawLanguages?.length !== 1) { + return explain( + `exactly one language must be requested via the 'languages' input, but ${ + rawLanguages?.length ?? 0 + } were`, + ); + } + + const language = parseBuiltInLanguage(rawLanguages[0]); + if (language === undefined) { + return explain(`'${rawLanguages[0]}' is not a known CodeQL language`); + } + + if (compressionMethod !== "zstd") { + // Per-language bundles are only published as zstd archives. + return explain(`the bundle would be downloaded as ${compressionMethod}`); + } + + if (variant !== GitHubVariant.DOTCOM) { + // Tenant mirrors may lack these assets, and an unreachable github.com fails with a + // connection error rather than a recoverable 404. + return explain(`we are running against ${variant}`); + } + + if (!isGitHubHostedRunner()) { + // Per-language installs stay out of the toolcache; self-hosted runners should retain + // the reusable combined bundle instead. + return explain("the job is not running on a GitHub-hosted runner"); + } + + // Nightly tags contain dates rather than comparable CLI versions. + if (!isNightly) { + if (cliVersion === undefined) { + return explain("the CLI version of the bundle is unknown"); + } + + if (!semver.gte(cliVersion, MIN_PER_LANGUAGE_BUNDLE_CLI_VERSION)) { + return explain( + `CodeQL ${cliVersion} is older than ${MIN_PER_LANGUAGE_BUNDLE_CLI_VERSION}, which is the ` + + "first version that publishes per-language bundles", + ); + } + } + + const supportedPlatform = PER_LANGUAGE_BUNDLE_PLATFORMS[language]; + if (supportedPlatform === undefined) { + return explain(`no per-language bundle is published for ${language}`); + } + if (supportedPlatform !== platform) { + return explain( + `the ${language} bundle is only published for ${supportedPlatform}, but this job is ` + + `running on ${platform ?? "an unknown platform"}`, + ); + } + + if (!(await features.getValue(Feature.PerLanguageBundles))) { + return explain(`the ${Feature.PerLanguageBundles} feature is disabled`); + } + + return language; +} diff --git a/src/setup-codeql-action.ts b/src/setup-codeql-action.ts index bb6b73c9a..3c2a191e7 100644 --- a/src/setup-codeql-action.ts +++ b/src/setup-codeql-action.ts @@ -93,6 +93,14 @@ async function sendCompletedStatusReport( initToolsDownloadFields.tools_total_duration_ms = toolsDownloadStatusReport.totalDurationMs; } + if (toolsDownloadStatusReport?.bundleLanguage !== undefined) { + initToolsDownloadFields.tools_bundle_language = + toolsDownloadStatusReport.bundleLanguage; + } + if (toolsDownloadStatusReport?.perLanguageBundleFallback !== undefined) { + initToolsDownloadFields.tools_per_language_bundle_fallback = + toolsDownloadStatusReport.perLanguageBundleFallback; + } if (toolsFeatureFlagsValid !== undefined) { initToolsDownloadFields.tools_feature_flags_valid = toolsFeatureFlagsValid; } diff --git a/src/setup-codeql.test.ts b/src/setup-codeql.test.ts index 973beef5e..f7caf575f 100644 --- a/src/setup-codeql.test.ts +++ b/src/setup-codeql.test.ts @@ -12,8 +12,10 @@ import * as api from "./api-client"; import * as diagnostics from "./diagnostics"; import { ActionsEnvVars, EnvVar, getEnv, ReadOnlyEnv } from "./environment"; import { Feature } from "./feature-flags"; +import { BuiltInLanguage } from "./languages"; import { getRunnerLogger } from "./logging"; import { getCacheRestoreKeyPrefix } from "./overlay/caching"; +import { MIN_PER_LANGUAGE_BUNDLE_CLI_VERSION } from "./per-language-bundles"; import * as setupCodeql from "./setup-codeql"; import * as tar from "./tar"; import { @@ -55,6 +57,25 @@ function stubDownloadAndExtract() { }); } +function stubHostedNightly(tagName: string) { + sinon.stub(process, "platform").value("linux"); + sinon.stub(process, "arch").value("x64"); + process.env[ActionsEnvVars.RUNNER_ENVIRONMENT] = "github-hosted"; + sinon.stub(tar, "isZstdAvailable").resolves({ + available: true, + foundZstdBinary: true, + }); + const client = github.getOctokit("123", { + request: { + fetch: async () => + new Response(JSON.stringify([{ tag_name: tagName }]), { + headers: { "content-type": "application/json" }, + }), + }, + }); + sinon.stub(api, "getApiClient").value(() => client); +} + test.serial("parse codeql bundle url version", (t) => { t.deepEqual( setupCodeql.getCodeQLURLVersion( @@ -374,20 +395,7 @@ test.serial( const expectedDate = "30260213"; const expectedTag = `codeql-bundle-${expectedDate}`; - // Ensure that we consistently select "zstd" for the test. - sinon.stub(process, "platform").value("linux"); - sinon.stub(tar, "isZstdAvailable").resolves({ - available: true, - foundZstdBinary: true, - }); - - const client = github.getOctokit("123"); - const listReleases = sinon.stub(client.rest.repos, "listReleases"); - // eslint-disable-next-line @typescript-eslint/no-unsafe-argument - listReleases.resolves({ - data: [{ tag_name: expectedTag }], - } as any); - sinon.stub(api, "getApiClient").value(() => client); + stubHostedNightly(expectedTag); await withTmpDir(async (tmpDir) => { setupActionsVars(tmpDir, tmpDir); @@ -456,20 +464,7 @@ test.serial( const expectedDate = "30260213"; const expectedTag = `codeql-bundle-${expectedDate}`; - // Ensure that we consistently select "zstd" for the test. - sinon.stub(process, "platform").value("linux"); - sinon.stub(tar, "isZstdAvailable").resolves({ - available: true, - foundZstdBinary: true, - }); - - const client = github.getOctokit("123"); - const listReleases = sinon.stub(client.rest.repos, "listReleases"); - // eslint-disable-next-line @typescript-eslint/no-unsafe-argument - listReleases.resolves({ - data: [{ tag_name: expectedTag }], - } as any); - sinon.stub(api, "getApiClient").value(() => client); + stubHostedNightly(expectedTag); await withTmpDir(async (tmpDir) => { setupActionsVars(tmpDir, tmpDir, { GITHUB_EVENT_NAME: "dynamic" }); @@ -513,6 +508,8 @@ for (const bundlePath of [ "codeql-bundle.tar.gz", "codeql-bundle.tar.zst", "codeql-bundle-/codeql-bundle.tar.gz", + "codeql-bundle-linux64.tar.zst", + "codeql-bundle-ruby-linux64.tar.zst", ]) { test.serial( `setupCodeQLBundle reports an unknown version for ${bundlePath}`, @@ -542,6 +539,12 @@ for (const bundlePath of [ t.is(downloadSpy.firstCall.args[0].toolsVersion, "unknown"); t.is(result.toolsVersion, "unknown"); t.is(result.toolsSource, setupCodeql.ToolsSource.Download); + t.is( + result.toolsDownloadStatusReport?.bundleLanguage, + bundlePath === "codeql-bundle-ruby-linux64.tar.zst" + ? BuiltInLanguage.ruby + : undefined, + ); t.is(path.dirname(result.codeqlFolder), tmpDir); t.true(fs.existsSync(result.codeqlFolder)); t.false(fs.existsSync(`${result.codeqlFolder}.complete`)); @@ -594,6 +597,131 @@ test.serial( }, ); +for (const toolsInput of ["nightly", "nightly-latest"]) { + test.serial( + `getCodeQLSource selects a per-language bundle for tools == ${toolsInput}`, + async (t) => { + const expectedTag = "codeql-bundle-30260213"; + const baseURL = `https://github.com/dsp-testing/codeql-cli-nightlies/releases/download/${expectedTag}`; + stubHostedNightly(expectedTag); + + await withTmpDir(async (tmpDir) => { + setupActionsVars(tmpDir, tmpDir); + const source = await setupCodeql.getCodeQLSource( + toolsInput, + SAMPLE_DEFAULT_CLI_VERSION, + ["java"], + false, // useOverlayAwareDefaultCliVersion + SAMPLE_DOTCOM_API_DETAILS, + GitHubVariant.DOTCOM, + true, // tarSupportsZstd + createFeatures([Feature.PerLanguageBundles]), + getRunnerLogger(true), + ); + + t.deepEqual(source, { + sourceType: "download", + bundle: { + kind: "per-language", + language: BuiltInLanguage.java, + url: `${baseURL}/codeql-bundle-java-linux64.tar.zst`, + combinedBundleURL: `${baseURL}/codeql-bundle-linux64.tar.zst`, + }, + bundleVersion: "30260213", + cliVersion: undefined, + compressionMethod: "zstd", + toolsVersion: "0.0.0-30260213", + } satisfies setupCodeql.CodeQLDownloadSource); + }); + }, + ); +} + +test.serial( + "getCodeQLSource downloads the combined nightly bundle when not eligible", + async (t) => { + const expectedTag = "codeql-bundle-30260213"; + stubHostedNightly(expectedTag); + + await withTmpDir(async (tmpDir) => { + setupActionsVars(tmpDir, tmpDir); + for (const { languages, features } of [ + { languages: ["java"], features: createFeatures([]) }, + { + languages: ["java", "python"], + features: createFeatures([Feature.PerLanguageBundles]), + }, + ]) { + const source = await setupCodeql.getCodeQLSource( + "nightly", + SAMPLE_DEFAULT_CLI_VERSION, + languages, + false, // useOverlayAwareDefaultCliVersion + SAMPLE_DOTCOM_API_DETAILS, + GitHubVariant.DOTCOM, + true, // tarSupportsZstd + features, + getRunnerLogger(true), + ); + + t.is(source.sourceType, "download"); + if (source.sourceType === "download") { + t.deepEqual(source.bundle, { + kind: "combined", + url: `https://github.com/dsp-testing/codeql-cli-nightlies/releases/download/${expectedTag}/codeql-bundle-linux64.tar.zst`, + }); + } + } + }); + }, +); + +for (const perLanguageBundles of [false, true]) { + test.serial( + `getCodeQLSource uses a ${perLanguageBundles ? "per-language" : "combined"} bundle for a forced nightly`, + async (t) => { + const expectedTag = "codeql-bundle-30260213"; + const baseURL = `https://github.com/dsp-testing/codeql-cli-nightlies/releases/download/${expectedTag}`; + stubHostedNightly(expectedTag); + + await withTmpDir(async (tmpDir) => { + setupActionsVars(tmpDir, tmpDir, { GITHUB_EVENT_NAME: "dynamic" }); + const source = await setupCodeql.getCodeQLSource( + undefined, // toolsInput: the nightly is selected by ForceNightly + SAMPLE_DEFAULT_CLI_VERSION, + ["java"], + false, // useOverlayAwareDefaultCliVersion + SAMPLE_DOTCOM_API_DETAILS, + GitHubVariant.DOTCOM, + true, // tarSupportsZstd + createFeatures( + perLanguageBundles + ? [Feature.ForceNightly, Feature.PerLanguageBundles] + : [Feature.ForceNightly], + ), + getRunnerLogger(true), + ); + + t.is(source.sourceType, "download"); + if (source.sourceType === "download") { + const combinedURL = `${baseURL}/codeql-bundle-linux64.tar.zst`; + t.deepEqual( + source.bundle, + perLanguageBundles + ? { + kind: "per-language", + language: BuiltInLanguage.java, + url: `${baseURL}/codeql-bundle-java-linux64.tar.zst`, + combinedBundleURL: combinedURL, + } + : { kind: "combined", url: combinedURL }, + ); + } + }); + }, + ); +} + test.serial( "getCodeQLSource correctly returns latest version from toolcache when tools == toolcache", async (t) => { @@ -878,6 +1006,439 @@ test.serial( }, ); +const PER_LANGUAGE_CLI_VERSION = { + enabledVersions: [ + { + cliVersion: MIN_PER_LANGUAGE_BUNDLE_CLI_VERSION, + tagName: `codeql-bundle-v${MIN_PER_LANGUAGE_BUNDLE_CLI_VERSION}`, + }, + ], +}; + +test.serial("getCodeQLBundleName names the per-language bundle", (t) => { + sinon.stub(process, "platform").value("linux"); + sinon.stub(process, "arch").value("x64"); + t.is( + setupCodeql.getCodeQLBundleName("zstd", BuiltInLanguage.java), + "codeql-bundle-java-linux64.tar.zst", + ); + t.is( + setupCodeql.getCodeQLBundleName("zstd"), + "codeql-bundle-linux64.tar.zst", + ); +}); + +test.serial("getCodeQLBundleName names the Swift bundle for macOS", (t) => { + sinon.stub(process, "platform").value("darwin"); + t.is( + setupCodeql.getCodeQLBundleName("zstd", BuiltInLanguage.swift), + "codeql-bundle-swift-osx64.tar.zst", + ); +}); + +test.serial( + "getCodeQLSource downloads the per-language bundle for a single explicit language", + async (t) => { + sinon.stub(process, "platform").value("linux"); + sinon.stub(process, "arch").value("x64"); + process.env[ActionsEnvVars.RUNNER_ENVIRONMENT] = "github-hosted"; + + await withTmpDir(async (tmpDir) => { + setupActionsVars(tmpDir, tmpDir); + const source = await setupCodeql.getCodeQLSource( + undefined, + PER_LANGUAGE_CLI_VERSION, + ["java-kotlin"], + false, // useOverlayAwareDefaultCliVersion + SAMPLE_DOTCOM_API_DETAILS, + GitHubVariant.DOTCOM, + true, // tarSupportsZstd + createFeatures([Feature.PerLanguageBundles]), + getRunnerLogger(true), + ); + + t.is(source.sourceType, "download"); + if (source.sourceType === "download") { + t.true( + source.bundle.url.endsWith("/codeql-bundle-java-linux64.tar.zst"), + `Unexpected URL ${source.bundle.url}`, + ); + t.is(source.bundle.kind, "per-language"); + if (source.bundle.kind === "per-language") { + t.is(source.bundle.language, BuiltInLanguage.java); + t.true( + source.bundle.combinedBundleURL?.endsWith( + "/codeql-bundle-linux64.tar.zst", + ), + ); + } + } + }); + }, +); + +test.serial( + "getCodeQLSource downloads the combined bundle when the feature is disabled", + async (t) => { + sinon.stub(process, "platform").value("linux"); + sinon.stub(process, "arch").value("x64"); + process.env[ActionsEnvVars.RUNNER_ENVIRONMENT] = "github-hosted"; + + await withTmpDir(async (tmpDir) => { + setupActionsVars(tmpDir, tmpDir); + const source = await setupCodeql.getCodeQLSource( + undefined, + PER_LANGUAGE_CLI_VERSION, + ["java"], + false, // useOverlayAwareDefaultCliVersion + SAMPLE_DOTCOM_API_DETAILS, + GitHubVariant.DOTCOM, + true, // tarSupportsZstd + createFeatures([]), + getRunnerLogger(true), + ); + + t.is(source.sourceType, "download"); + if (source.sourceType === "download") { + t.true(source.bundle.url.endsWith("/codeql-bundle-linux64.tar.zst")); + t.is(source.bundle.kind, "combined"); + } + }); + }, +); + +for (const fallback of [false, true]) { + test.serial( + `setupCodeQLBundle retains the selected release identity for an opaque asset URL${fallback ? " with fallback" : ""}`, + async (t) => { + sinon.stub(process, "platform").value("linux"); + sinon.stub(process, "arch").value("x64"); + sinon.stub(actionsUtil, "isRunningLocalAction").returns(false); + process.env[ActionsEnvVars.RUNNER_ENVIRONMENT] = "github-hosted"; + sinon.stub(tar, "isZstdAvailable").resolves({ + available: true, + foundZstdBinary: true, + }); + const tag = PER_LANGUAGE_CLI_VERSION.enabledVersions[0].tagName; + const assetURL = + "https://api.github.com/repos/codeql-testing/action-fork/releases/assets/123"; + const combinedURL = `${assetURL}4`; + const fetchRelease = sinon + .stub, ReturnType>() + .callsFake( + async () => + new Response( + JSON.stringify({ + assets: [ + { name: "codeql-bundle-java-linux64.tar.zst", url: assetURL }, + { + name: "codeql-bundle-linux64.tar.zst", + url: combinedURL, + }, + ], + }), + { headers: { "content-type": "application/json" } }, + ), + ); + const client = github.getOctokit("123", { + request: { fetch: fetchRelease }, + }); + sinon.stub(api, "getApiClient").value(() => client); + const authorizationSpy = sinon.spy(api, "getAuthorizationHeaderFor"); + const extractStub = stubDownloadAndExtract(); + if (fallback) { + extractStub.onFirstCall().rejects(new HTTPError("Not Found", 404)); + } + + await withTmpDir(async (tmpDir) => { + setupActionsVars(tmpDir, tmpDir, { + GITHUB_ACTION_REPOSITORY: "codeql-testing/action-fork", + }); + const result = await setupCodeql.setupCodeQLBundle( + undefined, + SAMPLE_DOTCOM_API_DETAILS, + tmpDir, + GitHubVariant.DOTCOM, + PER_LANGUAGE_CLI_VERSION, + ["java"], + false, // useOverlayAwareDefaultCliVersion + createFeatures([Feature.PerLanguageBundles]), + getRunnerLogger(true), + ); + + t.true(fetchRelease.calledTwice); + t.is( + fetchRelease.firstCall.args[0], + `https://api.github.com/repos/codeql-testing/action-fork/releases/tags/${tag}`, + ); + t.is(extractStub.callCount, fallback ? 2 : 1); + t.is(extractStub.firstCall.args[0], assetURL); + t.is(extractStub.lastCall.args[0], fallback ? combinedURL : assetURL); + t.is(authorizationSpy.callCount, extractStub.callCount); + t.is(authorizationSpy.firstCall.args[2], assetURL); + t.is( + authorizationSpy.lastCall.args[2], + fallback ? combinedURL : assetURL, + ); + t.is(extractStub.lastCall.args[3], "token token"); + t.is(result.toolsVersion, MIN_PER_LANGUAGE_BUNDLE_CLI_VERSION); + t.is( + result.toolsDownloadStatusReport?.bundleLanguage, + fallback ? undefined : BuiltInLanguage.java, + ); + t.is( + result.toolsDownloadStatusReport?.perLanguageBundleFallback, + fallback ? true : undefined, + ); + if (fallback) { + t.is( + result.codeqlFolder, + toolcache.find("CodeQL", MIN_PER_LANGUAGE_BUNDLE_CLI_VERSION), + ); + t.true(fs.existsSync(`${result.codeqlFolder}.complete`)); + } else { + t.is(path.dirname(result.codeqlFolder), tmpDir); + t.deepEqual(toolcache.findAllVersions("CodeQL"), []); + t.false(fs.existsSync(`${result.codeqlFolder}.complete`)); + } + }); + }, + ); +} + +for (const bundle of ["per-language", "combined", "fallback"] as const) { + test.serial( + `setupCodeQLBundle preserves the nightly version for a ${bundle} download`, + async (t) => { + const expectedDate = "30260213"; + const expectedTag = `codeql-bundle-${expectedDate}`; + const expectedVersion = `0.0.0-${expectedDate}`; + const baseURL = `https://github.com/dsp-testing/codeql-cli-nightlies/releases/download/${expectedTag}`; + const combinedURL = `${baseURL}/codeql-bundle-linux64.tar.zst`; + const perLanguageURL = `${baseURL}/codeql-bundle-javascript-linux64.tar.zst`; + const loggedMessages: LoggedMessage[] = []; + const logger = getRecordingLogger(loggedMessages); + + stubHostedNightly(expectedTag); + delete process.env[EnvVar.HAS_SET_UP_CODEQL]; + + const downloadSpy = sinon.spy(setupCodeql, "downloadCodeQL"); + const extractStub = stubDownloadAndExtract(); + if (bundle === "fallback") { + extractStub.onFirstCall().rejects(new HTTPError("Not Found", 404)); + } + const addDiagnostic = sinon.stub(diagnostics, "addNoLanguageDiagnostic"); + const features = createFeatures([ + Feature.PerLanguageBundles, + Feature.CleanupToolcacheBundles, + ]); + + await withTmpDir(async (tmpDir) => { + setupActionsVars(tmpDir, tmpDir); + const result = await setupCodeql.setupCodeQLBundle( + "nightly", + SAMPLE_DOTCOM_API_DETAILS, + tmpDir, + GitHubVariant.DOTCOM, + SAMPLE_DEFAULT_CLI_VERSION, + bundle === "combined" ? ["javascript", "python"] : ["javascript"], + false, // useOverlayAwareDefaultCliVersion + features, + logger, + ); + + const source = downloadSpy.firstCall.args[0]; + t.is(result.toolsVersion, expectedVersion); + t.is(result.toolsVersion, source.toolsVersion); + t.is( + source.bundle.kind, + bundle === "combined" ? "combined" : "per-language", + ); + t.is(result.codeqlFolder, extractStub.lastCall.args[2]); + t.is(extractStub.callCount, bundle === "fallback" ? 2 : 1); + t.is(downloadSpy.callCount, extractStub.callCount); + t.is( + extractStub.firstCall.args[0], + bundle === "combined" ? combinedURL : perLanguageURL, + ); + t.is( + extractStub.lastCall.args[0], + bundle === "per-language" ? perLanguageURL : combinedURL, + ); + t.is( + result.toolsDownloadStatusReport?.bundleLanguage, + bundle === "per-language" ? BuiltInLanguage.javascript : undefined, + ); + t.is( + result.toolsDownloadStatusReport?.perLanguageBundleFallback, + bundle === "fallback" ? true : undefined, + ); + t.is( + addDiagnostic + .getCalls() + .filter( + (call) => + call.args[1].source?.id === + "codeql-action/toolcache-bundle-cleanup", + ).length, + 1, + ); + if (bundle === "fallback") { + t.deepEqual(downloadSpy.secondCall.args[0], { + ...source, + bundle: { kind: "combined", url: combinedURL }, + }); + checkExpectedLogMessages(t, loggedMessages, [ + `No javascript CodeQL bundle was found at ${perLanguageURL}`, + ]); + } + if (bundle === "per-language") { + t.is(path.dirname(result.codeqlFolder), tmpDir); + t.deepEqual(toolcache.findAllVersions("CodeQL"), []); + t.false(fs.existsSync(`${result.codeqlFolder}.complete`)); + } else { + t.is( + result.codeqlFolder, + toolsDownload.getToolcacheDirectory(expectedVersion), + ); + t.true(fs.existsSync(`${result.codeqlFolder}.complete`)); + + const cachedResult = await setupCodeql.setupCodeQLBundle( + "nightly", + SAMPLE_DOTCOM_API_DETAILS, + tmpDir, + GitHubVariant.DOTCOM, + SAMPLE_DEFAULT_CLI_VERSION, + ["javascript"], + false, // useOverlayAwareDefaultCliVersion + features, + logger, + ); + t.is(cachedResult.toolsSource, setupCodeql.ToolsSource.Toolcache); + t.is(cachedResult.toolsVersion, expectedVersion); + t.is(cachedResult.codeqlFolder, result.codeqlFolder); + t.is(extractStub.callCount, bundle === "fallback" ? 2 : 1); + } + }); + }, + ); +} + +for (const asset of [ + "codeql-bundle-ruby-linux64.tar.zst", + "codeql-bundle-%72uby-linux64.tar.zst", +]) { + test.serial( + `setupCodeQLBundle keeps explicitly requested ${asset} out of the toolcache`, + async (t) => { + const extractStub = stubDownloadAndExtract(); + const url = `https://github.com/github/codeql-action/releases/download/codeql-bundle-v9.9.9/${asset}`; + process.env[ActionsEnvVars.RUNNER_ENVIRONMENT] = "self-hosted"; + + await withTmpDir(async (tmpDir) => { + setupActionsVars(tmpDir, tmpDir); + const result = await setupCodeql.setupCodeQLBundle( + url, + SAMPLE_DOTCOM_API_DETAILS, + tmpDir, + GitHubVariant.DOTCOM, + SAMPLE_DEFAULT_CLI_VERSION, + undefined, // rawLanguages + false, // useOverlayAwareDefaultCliVersion + createFeatures([]), + getRunnerLogger(true), + ); + + t.true(extractStub.calledOnce); + t.is(extractStub.firstCall.args[0], url); + t.is(result.toolsVersion, "9.9.9"); + t.is( + result.toolsDownloadStatusReport?.bundleLanguage, + BuiltInLanguage.ruby, + ); + t.is(path.dirname(result.codeqlFolder), tmpDir); + t.deepEqual(toolcache.findAllVersions("CodeQL"), []); + t.false(fs.existsSync(`${result.codeqlFolder}.complete`)); + }); + }, + ); +} + +for (const error of [ + new HTTPError("Internal Server Error", 500), + new Error("Connection reset"), +]) { + test.serial( + `setupCodeQLBundle does not fall back after ${error.message}`, + async (t) => { + sinon.stub(process, "platform").value("linux"); + sinon.stub(process, "arch").value("x64"); + process.env[ActionsEnvVars.RUNNER_ENVIRONMENT] = "github-hosted"; + sinon.stub(tar, "isZstdAvailable").resolves({ + available: true, + foundZstdBinary: true, + }); + const extractStub = sinon + .stub(toolsDownload, "downloadAndExtract") + .rejects(error); + + await withTmpDir(async (tmpDir) => { + setupActionsVars(tmpDir, tmpDir); + await t.throwsAsync( + setupCodeql.setupCodeQLBundle( + undefined, + SAMPLE_DOTCOM_API_DETAILS, + tmpDir, + GitHubVariant.DOTCOM, + PER_LANGUAGE_CLI_VERSION, + ["java"], + false, // useOverlayAwareDefaultCliVersion + createFeatures([Feature.PerLanguageBundles]), + getRunnerLogger(true), + ), + { is: error }, + ); + t.true(extractStub.calledOnce); + t.true( + extractStub.firstCall.args[0].endsWith( + "/codeql-bundle-java-linux64.tar.zst", + ), + ); + }); + }, + ); +} + +test.serial( + "setupCodeQLBundle does not substitute a bundle for an explicitly requested one that is missing", + async (t) => { + const error = new HTTPError("Not Found", 404); + const extractStub = sinon + .stub(toolsDownload, "downloadAndExtract") + .rejects(error); + + await withTmpDir(async (tmpDir) => { + setupActionsVars(tmpDir, tmpDir); + await t.throwsAsync( + setupCodeql.setupCodeQLBundle( + "https://github.com/github/codeql-action/releases/download/codeql-bundle-v9.9.9/codeql-bundle-ruby-linux64.tar.zst", + SAMPLE_DOTCOM_API_DETAILS, + tmpDir, + GitHubVariant.DOTCOM, + SAMPLE_DEFAULT_CLI_VERSION, + undefined, // rawLanguages + false, // useOverlayAwareDefaultCliVersion + createFeatures([]), + getRunnerLogger(true), + ), + { is: error }, + ); + + t.true(extractStub.calledOnce); + }); + }, +); + test.serial( "getEnabledVersionsWithOverlayBaseDatabases returns flag-enabled versions present in cache, sorted desc", async (t) => { diff --git a/src/setup-codeql.ts b/src/setup-codeql.ts index e5d6a77a9..85639ff93 100644 --- a/src/setup-codeql.ts +++ b/src/setup-codeql.ts @@ -30,8 +30,13 @@ import { Feature, FeatureEnablement, } from "./feature-flags"; +import { BuiltInLanguage } from "./languages"; import { Logger } from "./logging"; import { getCodeQlVersionsForOverlayBaseDatabases } from "./overlay/caching"; +import { + getPerLanguageBundleLanguage, + tryGetBundleLanguageFromUrl, +} from "./per-language-bundles"; import * as tar from "./tar"; import { deleteToolcacheBundles, @@ -72,21 +77,40 @@ function getCodeQLBundleExtension( } } +/** Returns the platform component of the CodeQL bundle name for the current platform. */ +export function getBundlePlatform(): string | undefined { + switch (process.platform) { + case "win32": + return "win64"; + case "linux": + return process.arch === "arm64" ? "linux-arm64" : "linux64"; + case "darwin": + return "osx64"; + default: + return undefined; + } +} + +/** + * Returns the name of the CodeQL bundle asset to download. + * + * @param compressionMethod The compression method of the bundle. + * @param language If provided, the name of the bundle that contains only this language, rather than + * the name of the combined bundle that contains every language. + */ export function getCodeQLBundleName( compressionMethod: tar.CompressionMethod, + language?: BuiltInLanguage, ): string { const extension = getCodeQLBundleExtension(compressionMethod); + const platform = getBundlePlatform(); - let platform: string; - if (process.platform === "win32") { - platform = "win64"; - } else if (process.platform === "linux") { - platform = process.arch === "arm64" ? "linux-arm64" : "linux64"; - } else if (process.platform === "darwin") { - platform = "osx64"; - } else { + if (platform === undefined) { return `codeql-bundle${extension}`; } + if (language !== undefined) { + return `codeql-bundle-${language}-${platform}${extension}`; + } return `codeql-bundle-${platform}${extension}`; } @@ -107,7 +131,7 @@ export function getCodeQLActionRepository(logger: Logger): string { async function getCodeQLBundleDownloadURL( tagName: string, apiDetails: api.GitHubApiDetails, - compressionMethod: tar.CompressionMethod, + codeQLBundleName: string, logger: Logger, ): Promise { const codeQLActionRepository = getCodeQLActionRepository(logger); @@ -126,7 +150,6 @@ async function getCodeQLBundleDownloadURL( return !self.slice(0, index).some((other) => deepEqual(source, other)); }, ); - const codeQLBundleName = getCodeQLBundleName(compressionMethod); for (const downloadSource of uniqueDownloadSources) { const [apiURL, repository] = downloadSource; // If we've reached the final case, short-circuit the API check since we know the bundle exists and is public. @@ -216,7 +239,15 @@ export function convertToSemVer(version: string, logger: Logger): string { } /** Describes the contents and location of a downloadable CodeQL bundle. */ -type CodeQLBundle = { kind: "combined"; url: string }; +type CodeQLBundle = + | { kind: "combined"; url: string } + | { + kind: "per-language"; + url: string; + language: BuiltInLanguage; + /** Only set when the Action selected the bundle, allowing a same-version fallback. */ + combinedBundleURL?: string; + }; /** A resolved download, including its bundle identity and version. */ export interface CodeQLDownloadSource { @@ -467,6 +498,7 @@ export async function getCodeQLSource( * This does not always include a tag name. */ let url: string | undefined; + let bundle: CodeQLBundle | undefined; // We allow forcing the nightly CLI via the FF for `dynamic` events (or in test mode) where the // `tools` input cannot be adjusted to explicitly request it. @@ -475,7 +507,8 @@ export async function getCodeQLSource( const forceNightly = forceNightlyValueFF && canForceNightlyWithFF; // For advanced workflows, a value from `CODEQL_NIGHTLY_TOOLS_INPUTS` can be specified explicitly - // for the `tools` input in the workflow file. + // for the `tools` input. This is the computed input, so it may come from the repository property + // rather than the workflow file. const nightlyRequestedByToolsInput = toolsInput !== undefined && CODEQL_NIGHTLY_TOOLS_INPUTS.includes(toolsInput); @@ -509,7 +542,8 @@ export async function getCodeQLSource( `Using the latest CodeQL CLI nightly, as requested by 'tools: ${toolsInput}'.`, ); } - toolsInput = await getNightlyToolsUrl(logger); + bundle = await getNightlyBundle(rawLanguages, variant, features, logger); + toolsInput = bundle.url; } /** @@ -738,12 +772,42 @@ export async function getCodeQLSource( ? "zstd" : "gzip"; - url = await getCodeQLBundleDownloadURL( - tagName!, - apiDetails, - compressionMethod, + const perLanguageBundleLanguage = await getPerLanguageBundleLanguage( + { + rawLanguages, + cliVersion, + compressionMethod, + platform: getBundlePlatform(), + variant, + }, + features, logger, ); + + const resolveBundleURL = (language?: BuiltInLanguage) => + getCodeQLBundleDownloadURL( + tagName!, + apiDetails, + getCodeQLBundleName(compressionMethod, language), + logger, + ); + + if (perLanguageBundleLanguage !== undefined) { + logger.info( + `Downloading the ${perLanguageBundleLanguage} CodeQL bundle, since ${perLanguageBundleLanguage} ` + + "is the only language being analyzed.", + ); + url = await resolveBundleURL(perLanguageBundleLanguage); + bundle = { + kind: "per-language", + url, + language: perLanguageBundleLanguage, + combinedBundleURL: await resolveBundleURL(), + }; + } else { + url = await resolveBundleURL(); + bundle = { kind: "combined", url }; + } } else { const method = tar.inferCompressionMethod(url); if (method === undefined) { @@ -753,6 +817,20 @@ export async function getCodeQLSource( ); } compressionMethod = method; + + if (bundle === undefined) { + // Explicit per-language URLs must also stay out of the toolcache, but have no fallback. + const language = tryGetBundleLanguageFromUrl(url); + bundle = + language === undefined + ? { kind: "combined", url } + : { kind: "per-language", url, language }; + } + if (bundle.kind === "per-language") { + logger.info( + `${url} appears to be a CodeQL bundle that contains only ${bundle.language}.`, + ); + } } if (cliVersion) { @@ -761,7 +839,7 @@ export async function getCodeQLSource( logger.info(`Using CodeQL CLI sourced from ${url} .`); } return { - bundle: { kind: "combined", url }, + bundle, bundleVersion, cliVersion, compressionMethod, @@ -841,8 +919,11 @@ export const downloadCodeQL = async function ( writeToolcacheMarkerFile(toolcacheDestination, logger); } else { logger.debug( - "Could not cache CodeQL tools because we could not determine the bundle version from the " + - `URL ${codeqlURL}.`, + bundle.kind === "per-language" + ? "Not caching the CodeQL tools because they came from a bundle that contains only a " + + "single language." + : "Could not cache CodeQL tools because we could not determine the bundle version from the " + + `URL ${codeqlURL}.`, ); } @@ -860,7 +941,8 @@ function getToolcacheDestination( source: CodeQLDownloadSource, logger: Logger, ): string | undefined { - if (!source.bundleVersion) { + // Per-language bundles must not be stored in the toolcache. + if (source.bundle.kind !== "combined" || !source.bundleVersion) { return undefined; } @@ -1046,6 +1128,9 @@ export async function setupCodeQLBundle( /** * Performs eligible toolcache cleanup once, then downloads and extracts the resolved bundle. * + * If `source` refers to a bundle for a single language and that bundle turns out not to exist, this + * falls back to downloading the combined bundle. + * * @returns The extraction directory and download timings. */ export async function downloadCodeQLBundle( @@ -1058,14 +1143,60 @@ export async function downloadCodeQLBundle( codeqlFolder: string; statusReport: ToolsDownloadStatusReport; }> { + const { bundle } = source; + const { logger } = action; + await tryDeleteToolcacheBundles(action); - return await downloadCodeQL( - source, - apiDetails, - tarVersion, - tempDir, - action.logger, - ); + + try { + const result = await downloadCodeQL( + source, + apiDetails, + tarVersion, + tempDir, + logger, + ); + return bundle.kind === "combined" + ? result + : { + ...result, + statusReport: { + ...result.statusReport, + bundleLanguage: bundle.language, + }, + }; + } catch (e) { + if ( + bundle.kind !== "per-language" || + bundle.combinedBundleURL === undefined || + util.asHTTPError(e)?.status !== 404 + ) { + throw e; + } + logger.warning( + `No ${bundle.language} CodeQL bundle was found at ${bundle.url}, so ` + + "falling back to the bundle that contains all languages. This analysis will still " + + "produce correct results, but will take longer to set up.", + ); + + const result = await downloadCodeQL( + { + ...source, + bundle: { kind: "combined", url: bundle.combinedBundleURL }, + }, + apiDetails, + tarVersion, + tempDir, + logger, + ); + return { + ...result, + statusReport: { + ...result.statusReport, + perLanguageBundleFallback: true, + }, + }; + } } async function useZstdBundle( @@ -1084,10 +1215,13 @@ function getTempExtractionDir(tempDir: string) { return path.join(tempDir, uuidV4()); } -/** - * Get the URL of the latest nightly CodeQL bundle. - */ -async function getNightlyToolsUrl(logger: Logger) { +/** Selects a bundle from the latest nightly, with a same-release fallback when applicable. */ +async function getNightlyBundle( + rawLanguages: string[] | undefined, + variant: util.GitHubVariant, + features: FeatureEnablement, + logger: Logger, +): Promise { const zstdAvailability = await tar.isZstdAvailable(logger); // The nightly is guaranteed to have a zstd bundle const compressionMethod = (await useZstdBundle( @@ -1097,6 +1231,19 @@ async function getNightlyToolsUrl(logger: Logger) { ? "zstd" : "gzip"; + const language = await getPerLanguageBundleLanguage( + { + rawLanguages, + cliVersion: undefined, + compressionMethod, + platform: getBundlePlatform(), + variant, + isNightly: true, + }, + features, + logger, + ); + try { // Since nightlies are prereleases, we can't just download the latest release // on the repository. So instead we need to find the latest pre-release @@ -1112,7 +1259,17 @@ async function getNightlyToolsUrl(logger: Logger) { if (!latestRelease) { throw new Error("Could not find the latest nightly release."); } - return `https://github.com/${CODEQL_NIGHTLIES_REPOSITORY_OWNER}/${CODEQL_NIGHTLIES_REPOSITORY_NAME}/releases/download/${latestRelease.tag_name}/${getCodeQLBundleName(compressionMethod)}`; + const assetUrl = (name: string) => + `https://github.com/${CODEQL_NIGHTLIES_REPOSITORY_OWNER}/${CODEQL_NIGHTLIES_REPOSITORY_NAME}/releases/download/${latestRelease.tag_name}/${name}`; + const url = assetUrl(getCodeQLBundleName(compressionMethod, language)); + return language === undefined + ? { kind: "combined", url } + : { + kind: "per-language", + url, + language, + combinedBundleURL: assetUrl(getCodeQLBundleName(compressionMethod)), + }; } catch (e) { throw new Error( `Failed to retrieve the latest nightly release: ${util.wrapError(e)}`, diff --git a/src/status-report.ts b/src/status-report.ts index a2acd631d..820b1c210 100644 --- a/src/status-report.ts +++ b/src/status-report.ts @@ -645,6 +645,13 @@ export interface InitToolsDownloadFields { * Whether the relevant tools dotcom feature flags have been misconfigured. * Only populated if we attempt to determine the default version based on the dotcom feature flags. */ tools_feature_flags_valid?: boolean; + /** The language of the single-language bundle that was downloaded, if any. */ + tools_bundle_language?: string; + /** + * Whether we tried to download a single-language bundle, but it did not exist and we fell back to + * the combined bundle. + */ + tools_per_language_bundle_fallback?: boolean; } /** diff --git a/src/tools-download.ts b/src/tools-download.ts index 222a18cd9..f7b0a708c 100644 --- a/src/tools-download.ts +++ b/src/tools-download.ts @@ -54,6 +54,13 @@ export type ToolsDownloadStatusReport = { * spent on a streaming attempt that failed and fell back to downloading before extracting. */ totalDurationMs: number; + /** The language of the single-language bundle that was downloaded, if any. */ + bundleLanguage?: string; + /** + * Whether we tried to download a single-language bundle, but it did not exist and we fell back to + * the combined bundle. + */ + perLanguageBundleFallback?: boolean; }; export async function downloadAndExtract(