Skip to content

sdk%lint(codeql): use unstable channel for CodeQL 2.27, pin for Intel Macs, bump packs and update queries, move crate policy to datasource - #50

Merged
kwvg merged 14 commits into
dashpay:developfrom
kwvg:cql_bump
Sep 22, 2026
Merged

kwvg merged 14 commits into
dashpay:developfrom
kwvg:cql_bump

Conversation

@kwvg

@kwvg kwvg commented Sep 20, 2026

Copy link
Copy Markdown
Collaborator

Additional Information

Breaking Changes

The minimum CodeQL version is now 2.27, our queries may not work with earlier versions.

How Has This Been Tested?

./maint/lint/lint_codeql.py run --lang=rust --with-suite=rust-security-and-quality
nix develop ./contrib/nix#dev --command python3 maint/lint_all.py

Checklist

  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have added or updated relevant unit/integration/functional tests
  • I have made corresponding changes to the documentation
  • I have assigned this pull request to a milestone (for repository code-owners and collaborators only)

@kwvg kwvg added this to the 0.1 milestone Sep 20, 2026
@kwvg kwvg self-assigned this Sep 20, 2026
@kwvg kwvg moved this to Build/CI in base-sdk v0.1 Sep 20, 2026
@coderabbitai

coderabbitai Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

Understand this PR’s impact

Explore downstream dependencies and potential security impact with Blast Radius.

View blast radius →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: c75de7c3-cf08-482b-8ef7-9b3e95dc6b68

📥 Commits

Reviewing files that changed from the base of the PR and between 5d8abbf and 2982659.

⛔ Files ignored due to path filters (1)
  • contrib/nix/flake.lock is excluded by !**/*.lock, !**/*.lock
📒 Files selected for processing (15)
  • contrib/nix/mods/rust.nix
  • maint/codeql/rust/decl.ql
  • maint/codeql/rust/import.ql
  • maint/codeql/rust/lib/ast.qll
  • maint/codeql/rust/lib/crates.qll
  • maint/codeql/rust/lib/files.qll
  • maint/codeql/rust/lib/filters.qll
  • maint/codeql/rust/lib/imports.qll
  • maint/codeql/rust/lib/policy.qll
  • maint/codeql/rust/lib/traits.qll
  • maint/codeql/rust/lib/types.qll
  • maint/codeql/rust/pkc.ql
  • maint/codeql/rust/policy.model.yml
  • maint/codeql/rust/trait.ql
  • maint/codeql/rust/zeroize.ql
💤 Files with no reviewable changes (2)
  • maint/codeql/rust/import.ql
  • maint/codeql/rust/lib/types.qll

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The pull request upgrades CodeQL to 2.27.0, changes Nix package selection, adds shared Rust CodeQL libraries and crate policies, updates Rust queries and dependencies, and removes a Rust diagnostic suppression.

Changes

CodeQL upgrade

Layer / File(s) Summary
Nix CodeQL packaging
contrib/README.md, contrib/nix/...
The Nix flake adds nixpkgs-unstable and passes it to the shell. CodeQL uses the pinned unified archive on x86_64-darwin and unstable.codeql elsewhere. Linux fixups and QEMU emulation are removed.
Rust analysis library foundations
maint/codeql/rust/lib/ast.qll, maint/codeql/rust/lib/crates.qll, maint/codeql/rust/lib/files.qll, maint/codeql/rust/lib/types.qll, maint/codeql/rust/policy.model.yml
Shared AST, path, type, location, and crate-policy helpers are added. Type helpers move to ast.qll, and types.qll is deleted.
Rust policy and import migration
maint/codeql/rust/lib/filters.qll, maint/codeql/rust/lib/imports.qll, maint/codeql/rust/lib/policy.qll, maint/codeql/rust/lib/traits.qll
Rust analysis libraries use the shared helpers. Re-export allowlisting uses crate policy data, and several internal predicates become private or are removed.
Rust query integration and toolchain updates
maint/codeql/rust/*.ql, maint/codeql/rust/qlpack.yml, maint/codeql/rust/codeql-pack.lock.yml, contrib/nix/mods/rust.nix, maint/lint/lint_codeql.py
Rust queries use shared naming, path, macro, and associated-item helpers. CodeQL dependencies and Rust source configuration are updated. The Rust-specific diagnostic suppression is removed.

Sequence Diagram(s)

sequenceDiagram
  participant NixFlake as contrib/nix/flake.nix
  participant Shell as common.nix
  participant CodeQLModule as codeql.nix
  participant CodeQL as CodeQL Rust pack
  participant RustQueries as Rust queries
  NixFlake->>Shell: pass pkgs and unstable
  Shell->>CodeQLModule: configure CodeQL package
  CodeQLModule->>CodeQL: select pinned archive or unstable.codeql
  CodeQL->>RustQueries: load updated libraries and dependencies
  RustQueries->>RustQueries: apply shared AST and crate-policy helpers
Loading

Priority: ➖ Normal

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Linked Issues check ✅ Passed The pull request satisfies the coding requirements in issue #37. maint/lint/lint_codeql.py removes the Rust suppression. contrib/nix/mods/codeql.nix removes aarch64-linux QEMU emulation and uses `…
Out of Scope Changes check ✅ Passed The changes remain within issue #37. The flake and Rust source configuration support the new CodeQL package. The README records the new minimum version. The query, library, policy-model, and lockfile …
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Title check ✅ Passed The title clearly summarizes the main changes: CodeQL 2.27 support, unstable-channel usage, Intel Mac pinning, pack updates, query updates, and crate-policy migration. It is long but remains specific …
Description check ✅ Passed The description is directly related to the changeset. It documents the CodeQL version requirement, Nix and query updates, linked issue, testing, breaking change, and checklist.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown

Note

This pull request has no conflicts! 🎊 🎉 🎊

@kwvg
kwvg marked this pull request as draft September 21, 2026 21:20
@kwvg kwvg changed the title sdk%ci(nix): use unstable channel for CodeQL 2.27, pin for Intel Macs, update queries, bump packs sdk%lint(codeql): use unstable channel for CodeQL 2.27, pin for Intel Macs, bump packs and update queries, move crate policy to datasource Sep 22, 2026
@kwvg
kwvg marked this pull request as ready for review September 22, 2026 06:44
@kwvg kwvg changed the title sdk%lint(codeql): use unstable channel for CodeQL 2.27, pin for Intel Macs, bump packs and update queries, move crate policy to datasource sdk%lint(codeql): use unstable channel for CodeQL 2.27, pin for Intel Macs, bump packs and update queries, move crate policy to datasource Sep 22, 2026
@kwvg
kwvg merged commit 4754149 into dashpay:develop Sep 22, 2026
59 checks passed
@github-actions github-actions Bot added the Build/CI Pull requests associated with work on the build system and maintenance label Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Build/CI Pull requests associated with work on the build system and maintenance

Projects

Status: Build/CI

Development

Successfully merging this pull request may close these issues.

Drop x86_64 emulation for CodeQL on arm64 Linux in favour of upcoming native support

1 participant