From 08ac30206282800a3a0a551a75395cad382134fa Mon Sep 17 00:00:00 2001 From: Mauro Baluda Date: Tue, 29 Sep 2026 17:14:34 +0200 Subject: [PATCH] Use platform-specific CodeQL bundles Build only the current host bundle, preserve current-platform environment aliases, and package codeql-bundle 0.6.0 for releases. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- .../internal-build-release-linux64.yml | 2 +- .../internal-build-release-macos64.yml | 2 +- .../internal-build-release-win64.yml | 2 +- ...nternal-pr-bundle-integration-test-cpp.yml | 5 +-- .../run-bundle-integration-tests-cpp.yml | 5 +-- developer_guide.md | 2 +- .../CodeQL/Commands/Targets/InstallCommand.cs | 7 ++-- .../run-bundle-integration-tests.liquid | 5 +-- .../CodeQL/CodeQLInstallation.cs | 15 +++++---- src/CodeQLToolkit.Shared/CodeQL/RESOLUTION.md | 13 ++++---- .../CodeQL/CodeQLInstallationTests.cs | 32 +++++++++++++++++++ 11 files changed, 57 insertions(+), 33 deletions(-) create mode 100644 test/CodeQLToolkit.Shared.Tests/CodeQL/CodeQLInstallationTests.cs diff --git a/.github/workflows/internal-build-release-linux64.yml b/.github/workflows/internal-build-release-linux64.yml index 7434572..7bc3933 100644 --- a/.github/workflows/internal-build-release-linux64.yml +++ b/.github/workflows/internal-build-release-linux64.yml @@ -50,7 +50,7 @@ jobs: pip install -U pyinstaller # run the packaging - ./scripts/build_codeql_bundle_dist.ps1 -Version 0.5.0 -WorkDirectory dist -DestinationDirectory ./src/CodeQLToolkit.Core/bin/Release/net6.0/publish/linux-x64/tools/ + ./scripts/build_codeql_bundle_dist.ps1 -Version 0.6.0 -WorkDirectory dist -DestinationDirectory ./src/CodeQLToolkit.Core/bin/Release/net6.0/publish/linux-x64/tools/ env: GH_TOKEN: ${{ github.token }} diff --git a/.github/workflows/internal-build-release-macos64.yml b/.github/workflows/internal-build-release-macos64.yml index 4f98924..b9fa8f2 100644 --- a/.github/workflows/internal-build-release-macos64.yml +++ b/.github/workflows/internal-build-release-macos64.yml @@ -48,7 +48,7 @@ jobs: pip install -U pyinstaller # run the packaging - ./scripts/build_codeql_bundle_dist.ps1 -Version 0.5.0 -WorkDirectory dist -DestinationDirectory ./src/CodeQLToolkit.Core/bin/Release/net6.0/publish/macos-arm64/tools/ + ./scripts/build_codeql_bundle_dist.ps1 -Version 0.6.0 -WorkDirectory dist -DestinationDirectory ./src/CodeQLToolkit.Core/bin/Release/net6.0/publish/macos-arm64/tools/ env: GH_TOKEN: ${{ github.token }} diff --git a/.github/workflows/internal-build-release-win64.yml b/.github/workflows/internal-build-release-win64.yml index 4596f93..57ec4b2 100644 --- a/.github/workflows/internal-build-release-win64.yml +++ b/.github/workflows/internal-build-release-win64.yml @@ -45,7 +45,7 @@ jobs: pip install -U pyinstaller # run the packaging - .\scripts\build_codeql_bundle_dist.ps1 -Version 0.5.0 -WorkDirectory dist -DestinationDirectory .\src\CodeQLToolkit.Core\bin\Release\net6.0\publish\windows-x64\tools\ + .\scripts\build_codeql_bundle_dist.ps1 -Version 0.6.0 -WorkDirectory dist -DestinationDirectory .\src\CodeQLToolkit.Core\bin\Release\net6.0\publish\windows-x64\tools\ env: GH_TOKEN: ${{ github.token }} diff --git a/.github/workflows/internal-pr-bundle-integration-test-cpp.yml b/.github/workflows/internal-pr-bundle-integration-test-cpp.yml index f732af3..1563bde 100644 --- a/.github/workflows/internal-pr-bundle-integration-test-cpp.yml +++ b/.github/workflows/internal-pr-bundle-integration-test-cpp.yml @@ -96,10 +96,7 @@ jobs: uses: actions/upload-artifact@v4 with: name: codeql-bundles - path: | - ${{ env.QLT_CODEQL_BUNDLE_PATH_LINUX64 }} - ${{ env.QLT_CODEQL_BUNDLE_PATH_WIN64 }} - ${{ env.QLT_CODEQL_BUNDLE_PATH_OSX64 }} + path: ${{ env.QLT_CODEQL_BUNDLE_PATH }} if-no-files-found: error compression-level: 0 diff --git a/.github/workflows/run-bundle-integration-tests-cpp.yml b/.github/workflows/run-bundle-integration-tests-cpp.yml index 6e051a6..6ec8f72 100644 --- a/.github/workflows/run-bundle-integration-tests-cpp.yml +++ b/.github/workflows/run-bundle-integration-tests-cpp.yml @@ -68,10 +68,7 @@ jobs: uses: actions/upload-artifact@v4 with: name: codeql-bundles - path: | - ${{ env.QLT_CODEQL_BUNDLE_PATH_LINUX64 }} - ${{ env.QLT_CODEQL_BUNDLE_PATH_WIN64 }} - ${{ env.QLT_CODEQL_BUNDLE_PATH_OSX64 }} + path: ${{ env.QLT_CODEQL_BUNDLE_PATH }} if-no-files-found: error compression-level: 0 diff --git a/developer_guide.md b/developer_guide.md index 11fe0f7..7b5d0bc 100644 --- a/developer_guide.md +++ b/developer_guide.md @@ -15,7 +15,7 @@ Note that we keep recent copies of tools (for local debugging purposes) in the ` **CodeQL Bundle** ``` -./scripts/build_codeql_bundle_dist.ps1 -Version 0.5.0 -WorkDirectory dist -DestinationDirectory ./src/CodeQLToolkit.Core/bin/Debug/net6.0/tools +./scripts/build_codeql_bundle_dist.ps1 -Version 0.6.0 -WorkDirectory dist -DestinationDirectory ./src/CodeQLToolkit.Core/bin/Debug/net6.0/tools ``` diff --git a/src/CodeQLToolkit.Features/CodeQL/Commands/Targets/InstallCommand.cs b/src/CodeQLToolkit.Features/CodeQL/Commands/Targets/InstallCommand.cs index f076448..e8057ed 100644 --- a/src/CodeQLToolkit.Features/CodeQL/Commands/Targets/InstallCommand.cs +++ b/src/CodeQLToolkit.Features/CodeQL/Commands/Targets/InstallCommand.cs @@ -99,10 +99,9 @@ public override void Run() if (CustomBundles || QuickBundles) { - SetEnvironmentVariableMultiTarget("QLT_CODEQL_BUNDLE_PATH", installation.CustomBundleOutputBundleCurrentPlatform); - SetEnvironmentVariableMultiTarget("QLT_CODEQL_BUNDLE_PATH_WIN64", installation.CustomBundleOutputBundleWindows); - SetEnvironmentVariableMultiTarget("QLT_CODEQL_BUNDLE_PATH_OSX64", installation.CustomBundleOutputBundleOSX); - SetEnvironmentVariableMultiTarget("QLT_CODEQL_BUNDLE_PATH_LINUX64", installation.CustomBundleOutputBundleLinux); + var bundlePath = installation.CustomBundleOutputBundleCurrentPlatform; + SetEnvironmentVariableMultiTarget("QLT_CODEQL_BUNDLE_PATH", bundlePath); + SetEnvironmentVariableMultiTarget($"QLT_CODEQL_BUNDLE_PATH_{installation.PlatformID.Replace("-", "_").ToUpperInvariant()}", bundlePath); } } diff --git a/src/CodeQLToolkit.Features/Templates/Bundle/Actions/run-bundle-integration-tests.liquid b/src/CodeQLToolkit.Features/Templates/Bundle/Actions/run-bundle-integration-tests.liquid index fd2c109..d7e0215 100644 --- a/src/CodeQLToolkit.Features/Templates/Bundle/Actions/run-bundle-integration-tests.liquid +++ b/src/CodeQLToolkit.Features/Templates/Bundle/Actions/run-bundle-integration-tests.liquid @@ -89,10 +89,7 @@ jobs: uses: actions/upload-artifact@v4 with: name: codeql-bundles - path: | - ${{ env.QLT_CODEQL_BUNDLE_PATH_LINUX64 }} - ${{ env.QLT_CODEQL_BUNDLE_PATH_WIN64 }} - ${{ env.QLT_CODEQL_BUNDLE_PATH_OSX64 }} + path: ${{ env.QLT_CODEQL_BUNDLE_PATH }} if-no-files-found: error compression-level: 0 diff --git a/src/CodeQLToolkit.Shared/CodeQL/CodeQLInstallation.cs b/src/CodeQLToolkit.Shared/CodeQL/CodeQLInstallation.cs index d92346d..b3db24f 100644 --- a/src/CodeQLToolkit.Shared/CodeQL/CodeQLInstallation.cs +++ b/src/CodeQLToolkit.Shared/CodeQL/CodeQLInstallation.cs @@ -96,7 +96,12 @@ public string PlatformID if (RuntimeInformation.IsOSPlatform(OSPlatform.Linux)) { - return "linux64"; + return RuntimeInformation.OSArchitecture switch + { + Architecture.X64 => "linux64", + Architecture.Arm64 => "linux-arm64", + _ => throw new PlatformNotSupportedException($"Unsupported Linux architecture: {RuntimeInformation.OSArchitecture}.") + }; } if (RuntimeInformation.IsOSPlatform(OSPlatform.OSX)) @@ -205,10 +210,9 @@ private void CustomBundleInstall() Directory.CreateDirectory(InstallationDirectory); } - // Download the platform-independent bundle. Log.G().LogInformation($"Downloading CodeQL base bundle..."); - var downloadFile = $"codeql-bundle.tar.gz"; + var downloadFile = $"codeql-bundle-{PlatformID}.tar.gz"; var customBundlePath = Path.Combine(InstallationDirectory, downloadFile); Log.G().LogInformation($"Checking if existing source bundle {downloadFile} is present..."); @@ -221,7 +225,7 @@ private void CustomBundleInstall() { using var client = new WebClient(); string uri = $"https://github.com/github/codeql-action/releases/download/{CLIBundle}/{downloadFile}"; - Log.G().LogInformation($"Downloading platform-independent bundle from remote URL: {uri}..."); + Log.G().LogInformation($"Downloading platform-specific bundle from remote URL: {uri}..."); client.DownloadFile(uri, customBundlePath); } @@ -252,8 +256,7 @@ private void CustomBundleInstall() var packsToExport = CodeQLPackConfiguration.Where(p => p.Bundle == true).Select(p => p.Name).ToArray(); var packs = string.Join(" ", packsToExport); - // Run the bundling tool to create the platform-specific custom bundles from the platform-independent bundle - var bundleArgs = $"--log DEBUG -a qlt.conf.json -p win64 -p osx64 -p linux64 -b {customBundlePath} -o {CustomBundleOutputDirectory} -w {workingDirectory} {packs}"; + var bundleArgs = $"--log DEBUG -a qlt.conf.json -p {PlatformID} -b {customBundlePath} -o {CustomBundleOutputDirectory} -w {workingDirectory} {packs}"; if (QuickBundle) { diff --git a/src/CodeQLToolkit.Shared/CodeQL/RESOLUTION.md b/src/CodeQLToolkit.Shared/CodeQL/RESOLUTION.md index 0d1b4ca..9919415 100644 --- a/src/CodeQLToolkit.Shared/CodeQL/RESOLUTION.md +++ b/src/CodeQLToolkit.Shared/CodeQL/RESOLUTION.md @@ -45,19 +45,18 @@ For a normal installation, the mapping of these values is as follows: For a bundle installation the mapping is as follows: -- `CodeQLCLIBundle` - The bundle downloaded from `github/codeql-action/releases` to base the bundle on. +- `CodeQLCLIBundle` - The `github/codeql-action` bundle release tag to base the bundle on. QLT downloads the current platform's bundle. In all cases, two environment variables are set after a run: - `QLT_CODEQL_PATH` - The path to the CodeQL binary. (Always set) - `QLT_CODEQL_HOME` - The root installation of CodeQL. (Always set) -When using custom bundles, four additional environmental variables are set after a run: -- `QLT_CODEQL_BUNDLE_PATH` - The path to the current platform bundle created by QLT. (Set when using custom bundles) -- `QLT_CODEQL_BUNDLE_PATH_WIN64` - The path to the Windows bundle created by QLT. (Set when using custom bundles) -- `QLT_CODEQL_BUNDLE_PATH_LINUX64` - The path to the Linux bundle created by QLT. (Set when using custom bundles) -- `QLT_CODEQL_BUNDLE_PATH_OSX64` - The path to the MacOS bundle created by QLT. (Set when using custom bundles) +When using custom bundles, two additional environment variables are set after a run: +- `QLT_CODEQL_BUNDLE_PATH` - The path to the current platform bundle created by QLT. +- `QLT_CODEQL_BUNDLE_PATH_` - The same path under the existing platform-specific name for the current platform. -The environmental variable `QLT_CODE_BUNDLE_PATH` will map to one of the three other bundle variables. +Each invocation creates one bundle for its current platform. Run QLT on each target platform when multiple bundles are required. +Linux ARM64 bundle creation requires CodeQL CLI 2.27.0 or later and codeql-bundle 0.6.0 or later. ## Idents within the Installation Directory diff --git a/test/CodeQLToolkit.Shared.Tests/CodeQL/CodeQLInstallationTests.cs b/test/CodeQLToolkit.Shared.Tests/CodeQL/CodeQLInstallationTests.cs new file mode 100644 index 0000000..a5b0d0e --- /dev/null +++ b/test/CodeQLToolkit.Shared.Tests/CodeQL/CodeQLInstallationTests.cs @@ -0,0 +1,32 @@ +using System.Runtime.InteropServices; +using CodeQLToolkit.Shared.CodeQL; + +namespace CodeQLToolkit.Shared.Tests.CodeQL +{ + public class CodeQLInstallationTests + { + [Test] + public void UsesCurrentPlatformBundle() + { + var expectedPlatform = RuntimeInformation.IsOSPlatform(OSPlatform.Windows) + ? "win64" + : RuntimeInformation.IsOSPlatform(OSPlatform.Linux) + ? RuntimeInformation.OSArchitecture switch + { + Architecture.X64 => "linux64", + Architecture.Arm64 => "linux-arm64", + _ => throw new PlatformNotSupportedException($"Unsupported Linux architecture: {RuntimeInformation.OSArchitecture}.") + } + : "osx64"; + var installation = new CodeQLInstallation + { + CLIBundle = "test", + EnableCustomCodeQLBundles = true + }; + + Assert.That( + Path.GetFileName(installation.CustomBundleOutputBundleCurrentPlatform), + Is.EqualTo($"codeql-bundle-{expectedPlatform}.tar.gz")); + } + } +}