Delete each version directory individually so that a symlinked one is skipped rather than removed, take an `ActionState` so the environment is read through `ReadOnlyEnv` rather than the deprecated `getOptionalEnvVar`, let `deleteToolcacheBundles` report its own failure to locate the toolcache instead of having the caller catch it, quote paths in log messages, and rename `HAS_OBTAINED_CODEQL_TOOLS` to `HAS_SET_UP_CODEQL`, which is also set when we find the tools in the toolcache rather than downloading them.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Some runner images keep the toolcache on a different volume to the workspace, so deleting the tools there frees up disk space that the analysis cannot use, and costs a later step that wanted them in the toolcache a download. Windows runners are laid out this way, with the toolcache on `C:` and the workspace on `D:`.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Run the cleanup even when the download will not be cached in the toolcache, since the toolcache shares a filesystem with the directory we extract to, so freeing it helps either way, and report an error other than the toolcache being absent as a failure rather than as an empty toolcache.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
When we download a bundle the toolcache often already holds a different one that the job will not use, and on GitHub-hosted runners it shares a filesystem with the workspace, so it takes space away from the analysis. Empty the toolcache before downloading, which also frees space for the archive during extraction, and which is safe because getting as far as a download means the tools were not resolved from the toolcache. Skip this once a step has obtained the tools, since a later step may run a path it was given, and gate it on the runner being GitHub-hosted and on a feature flag that is off by default.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
`deleteToolcacheBundles` removes `$RUNNER_TOOL_CACHE/CodeQL` and reports which versions were there. It refuses to follow a symlinked CodeQL directory so that it can only ever delete paths that are really inside the toolcache, and reports failures rather than throwing. Not called yet.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
`isHostedRunner` infers hostedness from the runner name and the toolcache path, so it also matches self-hosted runners that are configured to resemble hosted ones. Rename it to `looksLikeHostedRunner` so callers can see they are getting a heuristic, and add `isGitHubHostedRunner`, which reads the `RUNNER_ENVIRONMENT` value the Actions service reports. The existing callers keep the heuristic, so there is no behaviour change.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
- Stub process.platform/arch in the supported-platform test and loop
over all supported pairs (including linux/arm64) so it no longer
depends on the host
- Run the default queries in the Linux Arm64 PR check so the databases
are finalized end-to-end
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: fb7e2d12-6620-4a67-9c1c-4e82f4a5e8d9
`ApiClient` was hand-composed from `Octokit`, `Api` and `PaginateInterface`, imported directly from separately versioned Octokit packages. That asserted a shape matching what `@actions/github` actually returns, which held only while the versions happened to agree.
`@octokit/plugin-rest-endpoint-methods` v18 adds twelve Actions cache-limit methods. `@actions/github` still depends on `^17.0.0`, so the client it constructs no longer satisfies the v18-derived alias and the build fails.
Deriving the type from the constructor removes the assumption, so the alias tracks whatever `@actions/github` returns.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Surface `tools_extraction_duration_ms` and `tools_total_duration_ms` from
both the `init` and `setup-codeql` actions.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 628ce334-991a-4578-9c1b-93d2e96bbddb
The streaming path reported no timings at all, so we have no data for the
path that most runs take. It now reports a total duration, which is also
populated on the download-then-extract path.
That path additionally reports the extraction duration, which was
previously computed but only logged.
`downloadDurationMs` keeps its existing meaning of time spent downloading
alone, so existing telemetry stays comparable.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 628ce334-991a-4578-9c1b-93d2e96bbddb