Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 1 addition & 2 deletions contrib/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,9 +33,8 @@ source .venv/bin/activate
packages need to be additionally sourced.

* [cargo-deny](https://github.com/EmbarkStudios/cargo-deny)
* [CodeQL 2.27 or higher](https://github.com/github/codeql-cli-binaries/releases)
* [Git](https://git-scm.com/install/)
* [CodeQL 2.24 or higher](https://github.com/github/codeql-cli-binaries/releases) (Rust support was added in 2.23.3,
[source](https://github.blog/changelog/2025-10-23-codeql-2-23-3-adds-a-new-rust-query-rust-support-and-easier-c-c-scanning/))
* [Node.js 24 or higher](https://nodejs.org/en/download) (current LTS,
[source](https://nodejs.org/en/blog/release/v24.11.0))

Expand Down
17 changes: 17 additions & 0 deletions contrib/nix/flake.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

33 changes: 20 additions & 13 deletions contrib/nix/flake.nix
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,8 @@
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";

nixpkgs-unstable.url = "github:NixOS/nixpkgs/nixpkgs-unstable";

pyproject-build-systems = {
url = "github:pyproject-nix/build-system-pkgs";
inputs.nixpkgs.follows = "nixpkgs";
Expand Down Expand Up @@ -33,6 +35,7 @@
outputs =
{
nixpkgs,
nixpkgs-unstable,
rust-overlay,
...
}@inputs:
Expand All @@ -50,26 +53,30 @@
f:
lib.genAttrs systems (
system:
f (
import nixpkgs {
f {
pkgs = import nixpkgs {
inherit system;
config.allowUnfreePredicate =
pkg:
builtins.elem (lib.getName pkg) [
"codeql"
"xcode-sdk"
];
config.allowUnfree = true;
overlays = [ rust-overlay.overlays.default ];
}
)
};
unstable = import nixpkgs-unstable {
inherit system;
config.allowUnfree = true;
};
}
);
in
{
devShells = eachSystem (
pkgs:
{ pkgs, unstable }:
let
ctx = import ./shell/common.nix {
inherit pkgs lib inputs;
inherit
pkgs
lib
inputs
unstable
;
root = ../..;
};
ci = import ./shell/ci.nix ctx;
Expand All @@ -80,6 +87,6 @@
}
);

formatter = eachSystem (pkgs: pkgs.nixfmt);
formatter = eachSystem ({ pkgs, ... }: pkgs.nixfmt);
};
}
101 changes: 12 additions & 89 deletions contrib/nix/mods/codeql.nix
Original file line number Diff line number Diff line change
@@ -1,101 +1,24 @@
# CodeQL CLI

{ pkgs, lib }:
{ pkgs, unstable }:

let
version = "2.26.1";
linux64 = {
file = "codeql-linux64.zip";
hash = "sha256-FUgN2m4gM2qcfdy2Fx4OkVXx/nOh0xuurBU4IcuJrqs=";
};
osx64 = {
file = "codeql-osx64.zip";
hash = "sha256-YcXStT4c2O4r1XwxpVxXr1P/qv3xnEbSNBcExsrPNdM=";
};
version = "2.27.0";

# CodeQL does not offer ARM64 builds for Linux (github/codeql#20616), so we
# resort to x86_64 emulation instead. macOS releases include both AMD64 and
# ARM64 support, mitigating the need for emulation.
targets = {
x86_64-linux = {
asset = linux64;
dir = "linux64";
emulate = false;
};
aarch64-linux = {
asset = linux64;
dir = "linux64";
emulate = true;
};
x86_64-darwin = {
asset = osx64;
dir = "osx64";
emulate = false;
};
aarch64-darwin = {
asset = osx64;
dir = "osx64";
emulate = false;
};
};

target = targets.${pkgs.stdenv.hostPlatform.system};

# The Linux archive names its tracer lib64trace.so and bundles an x86_64 JDK
# that will not run from a Nix store.
linuxFixup = ''
ln -sf $out/codeql/tools/linux64/lib64trace.so $out/codeql/tools/linux64/libtrace.so
rm -rf $out/codeql/tools/linux64/java
ln -s ${pkgs.zulu17} $out/codeql/tools/linux64/java
'';

# Wrapping all executables around QEMU to achieve x86_64 emulation. Shared
# objects are unmodified to avoid caller dlopen() breakage.
emulateFixup = ''
find $out/codeql -type f -perm -u+x -print0 |
while IFS= read -r -d "" bin; do
case "$(file -b "$bin")" in
*ELF*executable*x86-64*)
mv "$bin" "$bin.x86_64"
cat > "$bin" <<WRAP
#!${pkgs.runtimeShell}
exec ${lib.getExe' pkgs.qemu-user "qemu-x86_64"} \
-L ${pkgs.pkgsCross.gnu64.glibc.out} "$bin.x86_64" "\$@"
WRAP
chmod +x "$bin"
;;
esac
done
'';

codeql = pkgs.codeql.overrideAttrs (old: {
# Fetching more recent CodeQL releases requires `unstable` and `x86_64-darwin`
# as a target is no longer supported since 26.11 (see nixos/nixpkgs#535508),
# though GitHub themselves still provide binaries that support Intel Macs so
# we rely on a pin for `x86_64-darwin` and consume from `unstable` otherwise.
pinned = pkgs.codeql.overrideAttrs (_: {
inherit version;

src = pkgs.fetchurl {
url = "https://github.com/github/codeql-cli-binaries/releases/download/v${version}/${target.asset.file}";
inherit (target.asset) hash;
src = pkgs.fetchzip {
url = "https://github.com/github/codeql-cli-binaries/releases/download/v${version}/codeql.zip";
hash = "sha256-8WhsburnhVWvVLTNOmAwmkjwN45exmKmw7Q5elTjYiI=";
};

nativeBuildInputs = (old.nativeBuildInputs or [ ]) ++ [
pkgs.unzip
pkgs.file
];

installPhase = ''
runHook preInstall

mkdir -p $out/codeql $out/bin
cp -R * $out/codeql/
${lib.optionalString (target.dir == "linux64") linuxFixup}
ln -s $out/codeql/codeql $out/bin/

runHook postInstall
'';

# Emulation is applied in postFixup instead of installPhase to avoid
# getting mangled by autopatchelf
postFixup = (old.postFixup or "") + lib.optionalString target.emulate emulateFixup;
});

codeql = if pkgs.stdenv.hostPlatform.system == "x86_64-darwin" then pinned else unstable.codeql;
in
{
packages = [ codeql ];
Expand Down
6 changes: 6 additions & 0 deletions contrib/nix/mods/rust.nix
Original file line number Diff line number Diff line change
Expand Up @@ -11,12 +11,18 @@ let
named = lib.mapAttrs' (name: t: lib.nameValuePair "TOOLCHAIN_${lib.toUpper name}" "${t}") (
lib.filterAttrs (name: _: name != default) toolchains
);

# rust-overlay symlinks a toolchain together, leaving the standard library
# source under a sysroot the CodeQL Rust extractor cannot resolve, costing
# us prelude resolution. Hand it the component those links land in.
rustSrc = toolchains.${default}.availableComponents.rust-src;
in
{
packages = [ toolchains.${default} ];

env = {
CARGO_TERM_COLOR = "always";
CODEQL_EXTRACTOR_RUST_OPTION_SYSROOT_SRC = "${rustSrc}/lib/rustlib/src/rust/library";
}
// named;
}
3 changes: 2 additions & 1 deletion contrib/nix/shell/common.nix
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@
lib,
inputs,
root,
unstable,
}:

let
Expand Down Expand Up @@ -86,7 +87,7 @@ in
;

mods = lib.mapAttrs (name: m: m // { _name = name; }) {
codeql = import ../mods/codeql.nix { inherit pkgs lib; };
codeql = import ../mods/codeql.nix { inherit pkgs unstable; };
cxx = cxx.compiler;
nixpkgs = import ../mods/nixpkgs.nix { inherit pkgs; };
python = import ../mods/python.nix {
Expand Down
30 changes: 15 additions & 15 deletions maint/codeql/rust/codeql-pack.lock.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,33 +2,33 @@
lockVersion: 1.0.0
dependencies:
codeql/concepts:
version: 0.0.27
version: 0.0.31
codeql/controlflow:
version: 2.0.37
version: 2.0.41
codeql/dataflow:
version: 2.1.9
version: 2.1.13
codeql/mad:
version: 1.0.53
version: 1.0.57
codeql/namebinding:
version: 0.0.2
version: 0.0.6
codeql/regex:
version: 1.0.53
version: 1.0.57
codeql/rust-all:
version: 0.2.17
version: 0.2.21
codeql/rust-queries:
version: 0.1.38
version: 0.1.42
codeql/ssa:
version: 2.0.29
version: 2.0.33
codeql/suite-helpers:
version: 1.0.53
version: 1.0.57
codeql/threat-models:
version: 1.0.53
version: 1.0.57
codeql/tutorial:
version: 1.0.53
version: 1.0.57
codeql/typeinference:
version: 0.0.34
version: 0.0.38
codeql/typetracking:
version: 2.0.37
version: 2.0.41
codeql/util:
version: 2.0.40
version: 2.0.44
compiled: false
2 changes: 1 addition & 1 deletion maint/codeql/rust/decl.ql
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,7 @@ where
not isSerdeInternalType(t) and
not isNotEncodable(t) and
isEnforcedCrate(fileOf(t)) and
name = t.getName().getText() and
name = nameOf(t) and
exists(DeclSlot badSlot, int badLine, DeclSlot priorSlot |
outOfOrder(t, badSlot, badLine, priorSlot, item) and
message =
Expand Down
1 change: 0 additions & 1 deletion maint/codeql/rust/import.ql
Original file line number Diff line number Diff line change
Expand Up @@ -71,7 +71,6 @@ where
item = u and
fileRelPath(fileOf(u), _) and
isForeignReexport(u) and
not isMacroReexport(u) and
message = "pub use " + usePrefix(u) + ":: re-exports from a foreign crate"
)
select item, message
Loading