A bundle that contains a single language can also be requested directly
via the `tools` input, in which case we did not choose it but must still
keep it out of the toolcache, since a later job analyzing a different
language could otherwise pick up an installation that is missing the
extractor it needs.
Recognise such bundles by their name. When one was requested explicitly,
a missing bundle is an error rather than a reason to fall back, since
substituting a different bundle would ignore what was asked for.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d4c7b873-8278-4a36-b67c-6cc5ea3b2316
Per-language bundles are not yet published as part of a release, so this
check points at a pre-release and needs exercising before it can run on
`main`. Allow a check to opt in to running on additional branches so that
it can be, without opening a pull request.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d4c7b873-8278-4a36-b67c-6cc5ea3b2316
Checks that a bundle containing only a single language is both trimmed
and able to analyze that language. Uses the Actions bundle, since the
Actions QL pack is the only one that depends on the library pack of
another language, and so is the case most likely to be missing something
it needs.
The bundle is pinned to a specific pre-release, so this check will need
updating once per-language bundles are published as part of a release.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d4c7b873-8278-4a36-b67c-6cc5ea3b2316
Download a bundle containing only the single language being analyzed,
rather than the combined bundle that contains every language, when that
is both safe and beneficial. Per-language bundles are substantially
smaller, so this saves download time and disk space on the runner.
Eligibility is decided in one place, since it is easy for these
conditions to drift apart. Per-language bundles are never added to the
toolcache, because a bundle for one language must not be reused for a
job that analyzes another.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d4c7b873-8278-4a36-b67c-6cc5ea3b2316
Delete each version directory individually so that a symlinked one is skipped rather than removed, take an `ActionState` so the environment is read through `ReadOnlyEnv` rather than the deprecated `getOptionalEnvVar`, let `deleteToolcacheBundles` report its own failure to locate the toolcache instead of having the caller catch it, quote paths in log messages, and rename `HAS_OBTAINED_CODEQL_TOOLS` to `HAS_SET_UP_CODEQL`, which is also set when we find the tools in the toolcache rather than downloading them.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Some runner images keep the toolcache on a different volume to the workspace, so deleting the tools there frees up disk space that the analysis cannot use, and costs a later step that wanted them in the toolcache a download. Windows runners are laid out this way, with the toolcache on `C:` and the workspace on `D:`.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Run the cleanup even when the download will not be cached in the toolcache, since the toolcache shares a filesystem with the directory we extract to, so freeing it helps either way, and report an error other than the toolcache being absent as a failure rather than as an empty toolcache.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
The check installs the tools from a URL, so most versions in its matrix are downloaded rather than found in the toolcache, which is when the cleanup runs, and it then builds and analyses seven languages, so a bundle we damaged on the way in would show up.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
When we download a bundle the toolcache often already holds a different one that the job will not use, and on GitHub-hosted runners it shares a filesystem with the workspace, so it takes space away from the analysis. Empty the toolcache before downloading, which also frees space for the archive during extraction, and which is safe because getting as far as a download means the tools were not resolved from the toolcache. Skip this once a step has obtained the tools, since a later step may run a path it was given, and gate it on the runner being GitHub-hosted and on a feature flag that is off by default.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
`deleteToolcacheBundles` removes `$RUNNER_TOOL_CACHE/CodeQL` and reports which versions were there. It refuses to follow a symlinked CodeQL directory so that it can only ever delete paths that are really inside the toolcache, and reports failures rather than throwing. Not called yet.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
`isHostedRunner` infers hostedness from the runner name and the toolcache path, so it also matches self-hosted runners that are configured to resemble hosted ones. Rename it to `looksLikeHostedRunner` so callers can see they are getting a heuristic, and add `isGitHubHostedRunner`, which reads the `RUNNER_ENVIRONMENT` value the Actions service reports. The existing callers keep the heuristic, so there is no behaviour change.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
- Analyze all languages CodeQL supports on Linux Arm64 (except Swift,
which is macOS only) in the Linux Arm64 check, building the compiled
ones via the shared multi-language-repo build.sh
- De-duplicate the check's language list via a shared LANGUAGES env var
used by both the init input and the assert loop
- Fix CHANGELOG tense: "download" -> "downloads"
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
- Stub process.platform/arch in the supported-platform test and loop
over all supported pairs (including linux/arm64) so it no longer
depends on the host
- Run the default queries in the Linux Arm64 PR check so the databases
are finalized end-to-end
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: fb7e2d12-6620-4a67-9c1c-4e82f4a5e8d9
`ApiClient` was hand-composed from `Octokit`, `Api` and `PaginateInterface`, imported directly from separately versioned Octokit packages. That asserted a shape matching what `@actions/github` actually returns, which held only while the versions happened to agree.
`@octokit/plugin-rest-endpoint-methods` v18 adds twelve Actions cache-limit methods. `@actions/github` still depends on `^17.0.0`, so the client it constructs no longer satisfies the v18-derived alias and the build fails.
Deriving the type from the constructor removes the assumption, so the alias tracks whatever `@actions/github` returns.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>