Skip to content

Commit de77116

Browse files
Merge branch 'main' into actions-unpinned-tag-floating-immutable
2 parents 2b1cbcc + e387ca4 commit de77116

499 files changed

Lines changed: 19270 additions & 3860 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.gitattributes‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -75,6 +75,9 @@
7575
/ruby/extractor/cargo-bazel-lock.json linguist-generated=true
7676
/ruby/extractor/cargo-bazel-lock.json -merge
7777

78+
# GitHub Agentic Workflows compiled output
79+
.github/workflows/*.lock.yml linguist-generated=true
80+
7881
# auto-generated files for the C# build
7982
/csharp/paket.lock linguist-generated=true
8083
# needs eol=crlf, as `paket` touches this file and saves it as crlf

‎.github/workflows/label-external-contributions.yml‎

Lines changed: 42 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,9 +20,21 @@ jobs:
2020
pull-requests: write
2121

2222
steps:
23+
- name: Create organization membership token
24+
id: membership-token
25+
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
26+
with:
27+
client-id: ${{ vars.CODEQL_ORG_MEMBERS_APP_CLIENT_ID }}
28+
private-key: ${{ secrets.CODEQL_ORG_MEMBERS_APP_PRIVATE_KEY }}
29+
owner: ${{ github.repository_owner }}
30+
permission-members: read
31+
2332
- name: Label external contributions
2433
env:
34+
API_URL: ${{ github.api_url }}
2535
GH_TOKEN: ${{ github.token }}
36+
MEMBERS_TOKEN: ${{ steps.membership-token.outputs.token }}
37+
ORG: ${{ github.repository_owner }}
2638
REPO: ${{ github.repository }}
2739
run: |
2840
set -euo pipefail
@@ -46,13 +58,13 @@ jobs:
4658
(.head.repo.full_name | type == "string") and
4759
.head.repo.full_name != $repo and
4860
.user.type == "User" and
49-
.author_association != "MEMBER" and
50-
.author_association != "OWNER" and
61+
(.user.login | type == "string" and length > 0) and
5162
(any(.labels[]?; .name == $label) | not)' \
5263
>/dev/null <<<"$pr_json"; then
5364
continue
5465
fi
5566
67+
author=$(jq -r '.user.login' <<<"$pr_json")
5668
events=$(gh api --paginate \
5769
"repos/$REPO/issues/$pr_number/events?per_page=100" |
5870
jq -cs 'add')
@@ -63,6 +75,34 @@ jobs:
6375
continue
6476
fi
6577
78+
if ! membership_status=$(curl \
79+
--silent \
80+
--show-error \
81+
--output /dev/null \
82+
--write-out '%{http_code}' \
83+
--connect-timeout 10 \
84+
--max-time 30 \
85+
--header "Accept: application/vnd.github+json" \
86+
--header "Authorization: Bearer $MEMBERS_TOKEN" \
87+
--header "X-GitHub-Api-Version: 2022-11-28" \
88+
"$API_URL/orgs/$ORG/members/$author"); then
89+
echo "::error::Membership check failed for pull request #$pr_number."
90+
exit 1
91+
fi
92+
93+
case "$membership_status" in
94+
204)
95+
echo "Pull request #$pr_number was opened by an organization member; skipping."
96+
continue
97+
;;
98+
404)
99+
;;
100+
*)
101+
echo "::error::Membership check for pull request #$pr_number returned HTTP $membership_status."
102+
exit 1
103+
;;
104+
esac
105+
66106
jq -n --arg label "$label" '{labels: [$label]}' |
67107
gh api --method POST \
68108
"repos/$REPO/issues/$pr_number/labels" \

‎.github/workflows/update-rust-analyzer.lock.yml‎

Lines changed: 1822 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
Lines changed: 131 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,131 @@
1+
---
2+
name: Update rust-analyzer
3+
emoji: 🦀
4+
description: Update the rust-analyzer version used by the Rust extractor and prepare a pull request.
5+
intent: Keep the Rust extractor on the latest compatible rust-analyzer version with a reviewable, validated pull request.
6+
on:
7+
workflow_dispatch:
8+
roles: [admin, maintainer, write]
9+
permissions:
10+
contents: read
11+
actions: read
12+
pull-requests: read
13+
copilot-requests: write
14+
strict: true
15+
checkout:
16+
fetch-depth: 0
17+
concurrency:
18+
group: update-rust-analyzer
19+
cancel-in-progress: false
20+
timeout-minutes: 180
21+
tools:
22+
github:
23+
mode: gh-proxy
24+
toolsets: [repos, pull_requests, actions]
25+
bash: ["*"]
26+
edit: true
27+
network:
28+
allowed:
29+
- defaults
30+
- github
31+
- github-actions
32+
- rust
33+
- bazel
34+
- python
35+
steps:
36+
- name: Configure Git
37+
run: |
38+
git config user.name "github-actions[bot]"
39+
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
40+
41+
- name: Install cargo-edit
42+
continue-on-error: true
43+
run: cargo install cargo-edit@0.13.0 --locked
44+
45+
- name: Run rust-analyzer updater script
46+
run: |
47+
mkdir -p /tmp/gh-aw/agent
48+
set +e
49+
python3 rust/scripts/update_rust_analyzer.py \
50+
2>&1 | tee /tmp/gh-aw/agent/rust-analyzer-update.log
51+
status=${PIPESTATUS[0]}
52+
set -e
53+
54+
printf '%s\n' "$status" > /tmp/gh-aw/agent/rust-analyzer-update-status.txt
55+
if grep -Fxq "No new rust-analyzer version available." \
56+
/tmp/gh-aw/agent/rust-analyzer-update.log; then
57+
printf '%s\n' "no-update" > /tmp/gh-aw/agent/rust-analyzer-update-result.txt
58+
else
59+
printf '%s\n' "update" > /tmp/gh-aw/agent/rust-analyzer-update-result.txt
60+
fi
61+
safe-outputs:
62+
report-incomplete: {}
63+
create-pull-request:
64+
title-prefix: "Rust: "
65+
branch-prefix: "automation/update-rust-analyzer/"
66+
draft: true
67+
max-patch-size: 10240
68+
max-patch-files: 1000
69+
allowed-files:
70+
- "Cargo.lock"
71+
- "shared/tree-sitter-extractor/Cargo.toml"
72+
- "shared/yeast/Cargo.toml"
73+
- "shared/yeast-macros/Cargo.toml"
74+
- "shared/yeast-schema/Cargo.toml"
75+
- "ruby/extractor/Cargo.toml"
76+
- "unified/extractor/Cargo.toml"
77+
- "unified/swift-syntax-rs/Cargo.toml"
78+
- "MODULE.bazel"
79+
- "MODULE.bazel.lock"
80+
- "rust-toolchain.toml"
81+
- "rust/**"
82+
- "misc/bazel/3rdparty/**"
83+
---
84+
85+
# Update rust-analyzer
86+
87+
## Task
88+
89+
The workflow has already run `rust/scripts/update_rust_analyzer.py`. Read:
90+
91+
- `/tmp/gh-aw/agent/rust-analyzer-update.log` for its complete output.
92+
- `/tmp/gh-aw/agent/rust-analyzer-update-status.txt` for its exit status.
93+
- `/tmp/gh-aw/agent/rust-analyzer-update-result.txt` for the deterministic result classification.
94+
95+
If the result is `no-update`, call `noop` with the reason
96+
`No new rust-analyzer version available.` and stop immediately. Do not inspect
97+
CI, modify files, or create a pull request.
98+
99+
Otherwise, continue the update from the existing working tree and commits:
100+
101+
1. Read `rust/updating-rust-analyzer.md` and all applicable repository
102+
instructions.
103+
2. Review the updater log, exit status, commits, and working tree. Do not rerun
104+
the updater script.
105+
3. Complete as much of the documented update as possible. Fix extractor or
106+
code-generation breakage, keep all `ra_ap_` dependency versions aligned,
107+
regenerate required files, and add schema upgrade/downgrade scripts, tests,
108+
and a change note when the schema changed.
109+
4. Run the relevant formatting, linting, code generation, build, and tests,
110+
including `bazel run //rust:install`. Use `gh` to inspect relevant existing
111+
CI configuration and prior failures while diagnosing problems.
112+
5. Review the complete diff and commits. Do not include secrets. Do not refer
113+
to private repositories, internal issues, or internal pull requests in the
114+
public pull request.
115+
6. Use `create_pull_request` exactly once to create a focused draft pull
116+
request. Summarize the updater output, changes, and validation. If the
117+
update cannot be finished, still create a partial draft pull request when
118+
there are useful changes, and clearly list failures, missing work, and the
119+
next commands for a maintainer.
120+
121+
The pull request is created after this agent execution, so its newly triggered
122+
CI cannot be awaited in this run. Compensate with the strongest practical
123+
local validation and state this limitation accurately in the pull request.
124+
If the updater did not report `no-update` but no useful patch can be produced,
125+
call `report_incomplete` with the updater failure and exact blocker.
126+
127+
## Safe Outputs
128+
129+
- Use `create_pull_request` for the update or partial update.
130+
- Use `noop` only for the exact no-update result.
131+
- Use `report_incomplete` only when no useful pull request can be created.

‎CONTRIBUTING.md‎

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -16,15 +16,17 @@ If you have an idea for a query that you would like to share with other CodeQL u
1616

1717
1. **Directory structure**
1818

19-
There are eight language-specific query directories in this repository:
19+
There are ten language-specific query directories in this repository:
2020

21+
* Actions: `actions/ql/src`
2122
* C/C++: `cpp/ql/src`
2223
* C#: `csharp/ql/src`
2324
* Go: `go/ql/src`
2425
* Java/Kotlin: `java/ql/src`
2526
* JavaScript: `javascript/ql/src`
2627
* Python: `python/ql/src`
2728
* Ruby: `ruby/ql/src`
29+
* Rust: `rust/ql/src`
2830
* Swift: `swift/ql/src`
2931

3032
Each language-specific directory contains further subdirectories that group queries based on their `@tags` or purpose.
@@ -75,7 +77,3 @@ After the experimental query is merged, we welcome pull requests to improve it.
7577
If you contribute to this project, we will record your name and email address (as provided by you with your contributions) as part of the code repositories, which are public. We might also use this information to contact you in relation to your contributions, as well as in the normal course of software development. We also store records of CLA agreements signed in the past, but no longer require contributors to sign a CLA. Under GDPR legislation, we do this on the basis of our legitimate interest in creating the CodeQL product.
7678

7779
Please do get in touch (privacy@github.com) if you have any questions about this or our data protection policies.
78-
79-
## Bazel
80-
Please notice that any bazel targets and definitions in this repository are currently experimental
81-
and for internal use only.

‎MODULE.bazel‎

Lines changed: 22 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ bazel_dep(name = "rules_kotlin", version = "2.2.2-codeql.1")
3030
bazel_dep(name = "gazelle", version = "0.50.0")
3131
bazel_dep(name = "rules_dotnet", version = "0.21.5-codeql.1")
3232
bazel_dep(name = "googletest", version = "1.17.0.bcr.2")
33-
bazel_dep(name = "rules_rust", version = "0.73.0")
33+
bazel_dep(name = "rules_rust", version = "0.74.0")
3434
bazel_dep(name = "rules_swift", version = "4.0.0-rc5-codeql.2")
3535
bazel_dep(name = "swift-syntax", version = "603.0.2")
3636
bazel_dep(name = "zstd", version = "1.5.7.bcr.1")
@@ -45,7 +45,7 @@ RUST_EDITION = "2024"
4545
# a nightly toolchain is required to enable experimental_use_cc_common_link, which we require internally
4646
# we prefer to run the same version as internally, even if experimental_use_cc_common_link is not really
4747
# required in this repo
48-
RUST_VERSION = "nightly/2026-07-15"
48+
RUST_VERSION = "nightly/2026-09-03"
4949

5050
rust = use_extension("@rules_rust//rust:extensions.bzl", "rust")
5151
rust.toolchain(
@@ -57,26 +57,26 @@ rust.toolchain(
5757
],
5858
# generated by buildutils-internal/scripts/fill-rust-sha256s.py (internal repo)
5959
sha256s = {
60-
"2026-07-15/rustc-nightly-x86_64-unknown-linux-gnu.tar.xz": "dad49ece98c6d0e5f3bfd7c532b5111f55319a0e2a880ef1a87379643348cf8e",
61-
"2026-07-15/rustc-nightly-x86_64-apple-darwin.tar.xz": "54fe056dd41fd0ae2e74e8a941ee207af21e9b86700636fa254f11f0f1fa0783",
62-
"2026-07-15/rustc-nightly-aarch64-apple-darwin.tar.xz": "0e8c44436fefd06850a343e244236bf8e2b7eadaee447c53a91bc4e17e6710d1",
63-
"2026-07-15/rustc-nightly-x86_64-pc-windows-msvc.tar.xz": "a55c3933faf617a47a10545a072bae1de03aa3fe7363d0779baad35bed2cf259",
64-
"2026-07-15/clippy-nightly-x86_64-unknown-linux-gnu.tar.xz": "49425e37f45e428b569098174a28985aae3102965dfa7434ca8472d1b3e58b5e",
65-
"2026-07-15/clippy-nightly-x86_64-apple-darwin.tar.xz": "2b1ca2938c8d3d35f9c26badd696d575db876260569900684c766cf8319960a7",
66-
"2026-07-15/clippy-nightly-aarch64-apple-darwin.tar.xz": "7c95556525376e0250dcdfb9c36725e8c0c131c1c6ac3b7e5872279e040852fb",
67-
"2026-07-15/clippy-nightly-x86_64-pc-windows-msvc.tar.xz": "e737590737fdf81e08af55c7cbc3e7f4883d5f68cbec4bd572ccb7af44fc15d8",
68-
"2026-07-15/cargo-nightly-x86_64-unknown-linux-gnu.tar.xz": "4df5b9f2ad9b597d272fa9500d650561f22c8543233485078a13a64693e567c3",
69-
"2026-07-15/cargo-nightly-x86_64-apple-darwin.tar.xz": "e45a0ab75df0e61a3429ab450e35551ca920b138be39dc5cf8af824dd36fcb15",
70-
"2026-07-15/cargo-nightly-aarch64-apple-darwin.tar.xz": "81e1469252cd4630fdf221f9390cdb4604472c0ef6774e6162370864e5adc3e0",
71-
"2026-07-15/cargo-nightly-x86_64-pc-windows-msvc.tar.xz": "077cf2ad9811cba2596faab7b5763f8430791263ab7f3961fa31f23aaa3d741d",
72-
"2026-07-15/llvm-tools-nightly-x86_64-unknown-linux-gnu.tar.xz": "25823477ba51d4aba12beb19cb7d2c46d453357a4b6d1c301102fc06d0c5db28",
73-
"2026-07-15/llvm-tools-nightly-x86_64-apple-darwin.tar.xz": "168f79a128b34c88a8cef03af0ced8986a99c52df4016e5d111cba3c4638e4e3",
74-
"2026-07-15/llvm-tools-nightly-aarch64-apple-darwin.tar.xz": "f95a27de3a30e6ba3d36548663b434e625cd1bbbfb015eadd90f67d80f657c5a",
75-
"2026-07-15/llvm-tools-nightly-x86_64-pc-windows-msvc.tar.xz": "1d48b7b8f511a23f270e9380f729ee414db918abbc88535fe419dd53aa0d5429",
76-
"2026-07-15/rust-std-nightly-x86_64-unknown-linux-gnu.tar.xz": "4c1a2f508b6791a1059924e6369d813b46888215add0a5906af95266b33219b2",
77-
"2026-07-15/rust-std-nightly-x86_64-apple-darwin.tar.xz": "a2438da77f7eb292f80a5cab3de1aa2e8deb718b89c0ba6e26ef5c76299cc048",
78-
"2026-07-15/rust-std-nightly-aarch64-apple-darwin.tar.xz": "02c36fc7728dc17376062e7a0f3bf26439e1317317971ba9339b3a3a34dee2fa",
79-
"2026-07-15/rust-std-nightly-x86_64-pc-windows-msvc.tar.xz": "5e724d34d34ec4ed34161bb890452640ddda11fd9ef64f6a74e47541d5b02583",
60+
"2026-09-03/rustc-nightly-x86_64-unknown-linux-gnu.tar.xz": "bd1f0986150596835e808635d81786c60ab9da3981687dfb00918329925e837a",
61+
"2026-09-03/rustc-nightly-x86_64-apple-darwin.tar.xz": "8f3da4fcdaf5c8574f723ee0dab80c0e47e59e97fb55c1b84a1dc96dc2b90f6b",
62+
"2026-09-03/rustc-nightly-aarch64-apple-darwin.tar.xz": "ef4e9dda67ee052fb60b506f76a5dbd2f1c45822aec878b31b98c2fe75ab6f84",
63+
"2026-09-03/rustc-nightly-x86_64-pc-windows-msvc.tar.xz": "b2feb930850f69c40c4fc4658a054676de9a3c263b6e1afbdad86b61ab0940ef",
64+
"2026-09-03/clippy-nightly-x86_64-unknown-linux-gnu.tar.xz": "9715b53a8e80261f85eeddc6096e82e6038218ddd81e9fd8d7d5d558d076191b",
65+
"2026-09-03/clippy-nightly-x86_64-apple-darwin.tar.xz": "83b26f9becd27e65b822a70d2f0ca1b676e0bad3d7a99597adf65326692744bb",
66+
"2026-09-03/clippy-nightly-aarch64-apple-darwin.tar.xz": "51708a4c7399d2a71e5fcaa491a9e233e63c98f67dcad7bbe11fd164ba604690",
67+
"2026-09-03/clippy-nightly-x86_64-pc-windows-msvc.tar.xz": "2990517d181ffe467505070d8842ae63089b781addedffa296100d018b746979",
68+
"2026-09-03/cargo-nightly-x86_64-unknown-linux-gnu.tar.xz": "a60615509715996b8d4d54b30a7db8a1cd62400d06206dbeeb20b223ad1e6b34",
69+
"2026-09-03/cargo-nightly-x86_64-apple-darwin.tar.xz": "1650d406de2cef5d7b0d573fa131937a09559c33b03766380fb3b97eb30b2493",
70+
"2026-09-03/cargo-nightly-aarch64-apple-darwin.tar.xz": "058ced0d2b26cde728a0553a572c0895cbbc5bdaaf23dc995649737cb2dd043d",
71+
"2026-09-03/cargo-nightly-x86_64-pc-windows-msvc.tar.xz": "1ce268af2f3e143b4a4aa114cfcead7091659af7b36660b007652b1f34329dff",
72+
"2026-09-03/llvm-tools-nightly-x86_64-unknown-linux-gnu.tar.xz": "c4557aaddd0b4a65593bd1f8474322fe3d91e5cc41a0221f383a8780256ad102",
73+
"2026-09-03/llvm-tools-nightly-x86_64-apple-darwin.tar.xz": "47d0e8184d270c223c298a227b0485afcfa5dc70429f5454b472a8b69ca03e9c",
74+
"2026-09-03/llvm-tools-nightly-aarch64-apple-darwin.tar.xz": "141b1f097db3a292f8641fe6e4ec1e48edb758154a2defa2dbd4a088af72caf7",
75+
"2026-09-03/llvm-tools-nightly-x86_64-pc-windows-msvc.tar.xz": "f6bb9e1cabc5b790bd419b7fe18c7ff132a40d0ff2db794efd2d5f4c0b535ba0",
76+
"2026-09-03/rust-std-nightly-x86_64-unknown-linux-gnu.tar.xz": "7bfd37eda0920b04ef50b4785475c5fa2cea8df19c24f3879d0b5cac6e4dcdbc",
77+
"2026-09-03/rust-std-nightly-x86_64-apple-darwin.tar.xz": "462e83115594799aff5d77a221b29a59d5e166435773c8eae37d047a8a5f39e1",
78+
"2026-09-03/rust-std-nightly-aarch64-apple-darwin.tar.xz": "79f676f8265e332ece71eea226a3a9b124506c9460e758ca1f669f80e0336eb0",
79+
"2026-09-03/rust-std-nightly-x86_64-pc-windows-msvc.tar.xz": "075661d74da5a65b8d5c8adb9375a868fea80d5b0e5c131af6f4cd059d6b3113",
8080
},
8181
versions = [RUST_VERSION],
8282
)
Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,4 @@
1+
---
2+
category: minorAnalysis
3+
---
4+
* Added taint flow summaries for the BDE `bslx` byte-stream deserializers `BloombergLP::bslx::ByteInStream`, `BloombergLP::bslx::GenericInStream`, and `BloombergLP::bslx::InStreamFunctions::bdexStreamIn`.
Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,4 @@
1+
---
2+
category: minorAnalysis
3+
---
4+
* Added flow summaries for the BDE codecs `BloombergLP::balber::BerDecoder`/`BerEncoder`, `BloombergLP::baljsn::Decoder`/`Encoder` and `BloombergLP::balxml::Decoder`/`Encoder`.

‎cpp/ql/lib/ext/balber.model.yml‎

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
# Model of the BDE balber BER codec (BloombergLP::balber).
2+
# All overloads take the stream at argument 0 and the object at argument 1 and return int.
3+
extensions:
4+
- addsTo:
5+
pack: codeql/cpp-all
6+
extensible: summaryModel
7+
data: # namespace, type, subtypes, name, signature, ext, input, output, kind, provenance
8+
# Decoding: stream -> object
9+
- ["BloombergLP::balber", "BerDecoder", true, "decode", "", "", "Argument[*0]", "Argument[*1]", "taint", "manual"]
10+
- ["BloombergLP::balber", "BerDecoder", true, "decodeAny", "", "", "Argument[*0]", "Argument[*1]", "taint", "manual"]
11+
# Encoding: object -> stream
12+
- ["BloombergLP::balber", "BerEncoder", true, "encode", "", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]
13+
- ["BloombergLP::balber", "BerEncoder", true, "encodeAny", "", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]

‎cpp/ql/lib/ext/baljsn.model.yml‎

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
# Model of the BDE baljsn JSON codec (BloombergLP::baljsn).
2+
# All overloads, including those taking DecoderOptions/EncoderOptions, take the stream at
3+
# argument 0 and the object at argument 1 and return int.
4+
extensions:
5+
- addsTo:
6+
pack: codeql/cpp-all
7+
extensible: summaryModel
8+
data: # namespace, type, subtypes, name, signature, ext, input, output, kind, provenance
9+
# Decoding: stream -> object
10+
- ["BloombergLP::baljsn", "Decoder", true, "decode", "", "", "Argument[*0]", "Argument[*1]", "taint", "manual"]
11+
- ["BloombergLP::baljsn", "Decoder", true, "decodeAny", "", "", "Argument[*0]", "Argument[*1]", "taint", "manual"]
12+
# Encoding: object -> stream
13+
- ["BloombergLP::baljsn", "Encoder", true, "encode", "", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]
14+
- ["BloombergLP::baljsn", "Encoder", true, "encodeAny", "", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]

0 commit comments

Comments
 (0)