diff --git a/.github/workflows/__per-language-bundle.yml b/.github/workflows/__per-language-bundle.yml deleted file mode 100644 index ea28390b7..000000000 --- a/.github/workflows/__per-language-bundle.yml +++ /dev/null @@ -1,105 +0,0 @@ -# Warning: This file is generated automatically, and should not be modified. -# Instead, please modify the template in the pr-checks directory and run: -# pr-checks/sync.sh -# to regenerate this file. - -name: PR Check - Per-language bundle -env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - GO111MODULE: auto -on: - push: - branches: - - main - - releases/v* - - henrymercer/per-language-bundles - pull_request: {} - merge_group: - types: - - checks_requested - schedule: - - cron: '0 5 * * *' - workflow_dispatch: - inputs: {} - workflow_call: - inputs: {} -defaults: - run: - shell: bash -concurrency: - cancel-in-progress: ${{ github.event_name == 'pull_request' || false }} - group: per-language-bundle-${{github.ref}} -jobs: - per-language-bundle: - strategy: - fail-fast: false - matrix: - include: - - os: ubuntu-latest - version: linked - name: Per-language bundle - if: github.triggering_actor != 'dependabot[bot]' - permissions: - contents: read - security-events: read - timeout-minutes: 45 - runs-on: ${{ matrix.os }} - steps: - - name: Check out repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - name: Prepare test - id: prepare-test - uses: ./.github/actions/prepare-test - with: - version: ${{ matrix.version }} - use-all-platform-bundle: 'false' - setup-kotlin: 'true' - - id: init - uses: ./../action/init - with: - languages: actions - tools: https://github.com/dsp-testing/henrymercer-codeql-cli-binaries/releases/download/codeql-bundle-20260825/codeql-bundle-actions-linux64.tar.zst - - name: Check that the bundle contains only the Actions extractor - env: - CODEQL_PATH: ${{ steps.init.outputs.codeql-path }} - run: | - languages="$("$CODEQL_PATH" resolve languages --format=json | jq -r 'keys[]')" - echo "Extractors in the bundle:" - echo "$languages" - - if ! echo "$languages" | grep -qx "actions"; then - echo "::error::The Actions bundle does not contain the Actions extractor." - exit 1 - fi - - # If the bundle still contained extractors for languages we did not ask for, then it would not - # have been trimmed, and this test would be silently exercising the combined bundle instead. - for language in cpp csharp go java python ruby rust swift; do - if echo "$languages" | grep -qx "$language"; then - echo "::error::The Actions bundle also contains the ${language} extractor, so it is not trimmed." - exit 1 - fi - done - - name: Check that the bundle was not added to the toolcache - env: - CODEQL_PATH: ${{ steps.init.outputs.codeql-path }} - run: | - # A bundle that is missing most of its extractors must never be left in the toolcache, where - # a later job analyzing a different language could pick it up. - echo "CodeQL is at $CODEQL_PATH" - if [[ "$CODEQL_PATH" == "$RUNNER_TOOL_CACHE"/* ]]; then - echo "::error::The per-language bundle was added to the toolcache at $CODEQL_PATH." - exit 1 - fi - # The runner image ships with its own CodeQL in the toolcache, so look for the version we - # downloaded rather than for CodeQL in general. - cached_version="$RUNNER_TOOL_CACHE/CodeQL/0.0.0-20260825" - if [ -d "$cached_version" ]; then - echo "::error::The per-language bundle was added to the toolcache at $cached_version." - exit 1 - fi - - uses: ./../action/analyze - with: - upload-database: false - env: - CODEQL_ACTION_TEST_MODE: true diff --git a/.github/workflows/per-language-bundle-validation.yml b/.github/workflows/per-language-bundle-validation.yml index e491e7303..4dae4359c 100644 --- a/.github/workflows/per-language-bundle-validation.yml +++ b/.github/workflows/per-language-bundle-validation.yml @@ -36,6 +36,9 @@ jobs: - language: actions platform: linux64 os: ubuntu-latest + # The Actions QL pack depends on the JavaScript one, which is the only dependency of its + # kind, so the Actions bundle has to carry the JavaScript extractor as well. + expected-extractors: actions javascript - language: cpp platform: linux64 os: ubuntu-latest @@ -93,24 +96,31 @@ jobs: languages: ${{ matrix.language }} build-mode: ${{ matrix['build-mode'] }} tools: https://github.com/dsp-testing/henrymercer-codeql-cli-binaries/releases/download/${{ env.BUNDLE_TAG }}/codeql-bundle-${{ matrix.language }}-${{ matrix.platform }}.tar.zst - - name: Check that the bundle contains only the expected extractor + - name: Check that the bundle contains only the expected extractors env: CODEQL_PATH: ${{ steps.init.outputs.codeql-path }} LANGUAGE: ${{ matrix.language }} + EXPECTED_EXTRACTORS: ${{ matrix['expected-extractors'] || matrix.language }} run: | extractors="$("$CODEQL_PATH" resolve languages --format=json | jq -r 'keys[]')" echo "Extractors in the bundle:" echo "$extractors" + echo "Expected: $EXPECTED_EXTRACTORS" - if ! echo "$extractors" | grep -qx "$LANGUAGE"; then - echo "::error::The ${LANGUAGE} bundle does not contain the ${LANGUAGE} extractor." - exit 1 - fi + for expected in $EXPECTED_EXTRACTORS; do + if ! echo "$extractors" | grep -qx "$expected"; then + echo "::error::The ${LANGUAGE} bundle does not contain the ${expected} extractor." + exit 1 + fi + done - # If the bundle still contained extractors for languages we did not ask for, then it would - # not have been trimmed, and this job would be silently validating the combined bundle. + # If the bundle contained extractors beyond those the language needs, then it would not + # have been trimmed, and this job would be silently validating the combined bundle. for other in actions cpp csharp go java javascript python ruby rust swift; do - if [ "$other" != "$LANGUAGE" ] && echo "$extractors" | grep -qx "$other"; then + if echo "$EXPECTED_EXTRACTORS" | grep -qw "$other"; then + continue + fi + if echo "$extractors" | grep -qx "$other"; then echo "::error::The ${LANGUAGE} bundle also contains the ${other} extractor, so it is not trimmed." exit 1 fi diff --git a/pr-checks/checks/per-language-bundle.yml b/pr-checks/checks/per-language-bundle.yml deleted file mode 100644 index 25303fdd3..000000000 --- a/pr-checks/checks/per-language-bundle.yml +++ /dev/null @@ -1,56 +0,0 @@ -name: "Per-language bundle" -description: "Tests that a CodeQL bundle containing only a single language can analyze that language" -versions: - - linked # Unused: this test pins `tools` to a specific per-language bundle. -# TODO: Remove once per-language bundles ship in a release, so that this check no longer needs to be -# exercised on a feature branch. -extraPushBranches: - - henrymercer/per-language-bundles -steps: - - id: init - uses: ./../action/init - with: - languages: actions - tools: https://github.com/dsp-testing/henrymercer-codeql-cli-binaries/releases/download/codeql-bundle-20260825/codeql-bundle-actions-linux64.tar.zst - - name: Check that the bundle contains only the Actions extractor - env: - CODEQL_PATH: ${{ steps.init.outputs.codeql-path }} - run: | - languages="$("$CODEQL_PATH" resolve languages --format=json | jq -r 'keys[]')" - echo "Extractors in the bundle:" - echo "$languages" - - if ! echo "$languages" | grep -qx "actions"; then - echo "::error::The Actions bundle does not contain the Actions extractor." - exit 1 - fi - - # If the bundle still contained extractors for languages we did not ask for, then it would not - # have been trimmed, and this test would be silently exercising the combined bundle instead. - for language in cpp csharp go java python ruby rust swift; do - if echo "$languages" | grep -qx "$language"; then - echo "::error::The Actions bundle also contains the ${language} extractor, so it is not trimmed." - exit 1 - fi - done - - name: Check that the bundle was not added to the toolcache - env: - CODEQL_PATH: ${{ steps.init.outputs.codeql-path }} - run: | - # A bundle that is missing most of its extractors must never be left in the toolcache, where - # a later job analyzing a different language could pick it up. - echo "CodeQL is at $CODEQL_PATH" - if [[ "$CODEQL_PATH" == "$RUNNER_TOOL_CACHE"/* ]]; then - echo "::error::The per-language bundle was added to the toolcache at $CODEQL_PATH." - exit 1 - fi - # The runner image ships with its own CodeQL in the toolcache, so look for the version we - # downloaded rather than for CodeQL in general. - cached_version="$RUNNER_TOOL_CACHE/CodeQL/0.0.0-20260825" - if [ -d "$cached_version" ]; then - echo "::error::The per-language bundle was added to the toolcache at $cached_version." - exit 1 - fi - - uses: ./../action/analyze - with: - upload-database: false diff --git a/pr-checks/sync.ts b/pr-checks/sync.ts index 7e0e61fc9..c307f6e48 100755 --- a/pr-checks/sync.ts +++ b/pr-checks/sync.ts @@ -90,13 +90,6 @@ interface Specification extends JobSpecification { /** If set, this check is part of a named collection that gets its own caller workflow. */ collection?: string; - - /** - * Additional branches on which a push should run this check. - * - * Useful for temporarily exercising a check on a feature branch without opening a pull request. - */ - extraPushBranches?: string[]; } /** Minimal type to represent steps in Actions workflows. */ @@ -770,11 +763,7 @@ function main(): void { }, on: { push: { - branches: [ - "main", - "releases/v*", - ...(checkSpecification.extraPushBranches ?? []), - ], + branches: ["main", "releases/v*"], }, pull_request: {}, merge_group: {