Skip to content
Draft
Show file tree
Hide file tree
Changes from 1 commit
Commits
Show all changes
26 commits
Select commit Hold shift + click to select a range
e68fb0e
Add minimal working Nix env
rvermeulen Jan 26, 2024
e0841eb
Remove dependency on CodeQL CLI
rvermeulen Jan 27, 2024
3efa7b5
Add derivative CodeQL QL for QL queries and libraries
rvermeulen Jan 27, 2024
c5be6b1
Add support for additional packs and extractors
rvermeulen Jan 27, 2024
3fbd6a6
Rename derivatives and include QL for QL pack.
rvermeulen Jan 27, 2024
39126fb
Move CodeQL tooling and shell derivative into tooling directory
rvermeulen Jan 27, 2024
cda3971
Remove output of environment when building CodeQL derivative
rvermeulen Jan 27, 2024
ab731b2
Copy the contents of the pack derivative instead of the derivative dir
rvermeulen Jan 27, 2024
749ea80
Add workflow to run CodeQL on QL queries
rvermeulen Jan 27, 2024
93b27e8
Run analyzes on PRs or pushes to main
rvermeulen Jan 27, 2024
e60bb08
Allow usage of non-free derivatives
rvermeulen Jan 27, 2024
b628c0c
Pin Nix packages
rvermeulen Jan 27, 2024
67baed8
Select the hash based on the platform
rvermeulen Jan 27, 2024
f80e31e
Address issue with JDK on Linux
rvermeulen Jan 29, 2024
6fe5e35
Prepare all tools for other derivatives
rvermeulen Jan 29, 2024
131f6ab
Add shell derivate to test CodeQL CLI
rvermeulen Jan 29, 2024
4e5d514
Cache the Nix store for improved runtime
rvermeulen Jan 29, 2024
4121f79
Fix incorrect option specification
rvermeulen Jan 29, 2024
cdf9295
Close Nix expression
rvermeulen Jan 29, 2024
250fe90
Preserve the GitHub token environment variable to upload results
rvermeulen Jan 29, 2024
6f4124e
Pass GitHub token through env
rvermeulen Jan 29, 2024
750e8be
Limit GH token to security event writes
rvermeulen Jan 29, 2024
1dda311
Key the Nix store on the workflow file
rvermeulen Jan 29, 2024
9537f6a
Attempt bind mount to address cache write issues
rvermeulen Jan 29, 2024
b824f61
Attempt use of Nix copy command for caching store
rvermeulen Jan 30, 2024
e7ea5b7
Unify cache key
rvermeulen Jan 30, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Next Next commit
Add minimal working Nix env
Create a shell environment with a CodeQL CLI that includes the Ql
extractor to create CodeQL databases of QL files.
  • Loading branch information
rvermeulen committed Jan 26, 2024
commit e68fb0e21c6998e2e9176b0b7a39895841c8d5ac
42 changes: 42 additions & 0 deletions scripts/codeql/codeql-cli/2.16.0.nix
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
{ lib, stdenv, fetchzip, withQlExtractor ? null}:

stdenv.mkDerivation rec {
pname = "codeql-cli";
version = "2.16.0";
platform = if stdenv.isDarwin then "osx64" else "linux64";

dontConfigure = true;
dontBuild = true;
dontStrip = true;

src = fetchzip {
url = "https://github.com/github/codeql-cli-binaries/releases/download/v${version}/codeql-${platform}.zip";
hash = "sha256-trWUSMOT7h7J5ejjp9PzhGgBS3DYsJxzcv6aYKuk8TI=";
};

buildInputs = if isNull withQlExtractor then [ ] else [ withQlExtractor ];
inherit withQlExtractor;

installPhase = ''
# codeql directory should not be top-level, otherwise,
# it'll include /nix/store to resolve extractors.
env
mkdir -p $out/{codeql,bin}
cp -R * $out/codeql/

ln -s $out/codeql/codeql $out/bin/

if [ -n "$withQlExtractor" ]; then
# Copy the extractor, because CodeQL doesn't follow symlinks.
cp -R $withQlExtractor $out/codeql/ql
fi
'';


meta = with lib; {
description = "Semantic code analysis engine";
homepage = "https://codeql.github.com";
platforms = lib.platforms.linux ++ lib.platforms.darwin;
license = licenses.unfree;
};
}
9 changes: 9 additions & 0 deletions scripts/codeql/default.nix
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
let
pkgs = import <nixpkgs> {};
in
rec {
ql-extractor_0_0_1 = pkgs.callPackage ./ql-extractor/0.0.1.nix {inherit codeql-cli_2_16_0;};
codeql-cli_2_16_0 = pkgs.callPackage ./codeql-cli/2.16.0.nix {};
codeql-cli_2_16_0_with_ql_extractor = pkgs.callPackage ./codeql-cli/2.16.0.nix { withQlExtractor = ql-extractor_0_0_1; };

}
43 changes: 43 additions & 0 deletions scripts/codeql/ql-extractor/0.0.1.nix
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
{ stdenv, lib, fetchFromGitHub, rustPlatform, gh, libiconv, which, jq, codeql-cli_2_16_0}:

rustPlatform.buildRustPackage rec {
pname = "codeql-ql-extractor";
version = "0.0.1";

dontConfigure = true;
dontStrip = true;

src = fetchFromGitHub {
owner = "github";
repo = "codeql";
rev = "codeql-cli/v2.16.0";
sha256 = "x2EFoOt1MZRXxIZt6hF86Z1Qu/hVUoOVla562TApVwo=";
};

sourceRoot = "${src.name}/ql";

cargoLock = {
lockFile = "${src.outPath}/ql/Cargo.lock";
outputHashes = {
"tree-sitter-json-0.20.0" = "sha256-fIh/bKxHMnok8D+xQlyyp5GaO2Ra/U2Y/5IjQ+t4+xY=";
"tree-sitter-ql-0.19.0" = "sha256-2QOtNguYAIhIhGuVqyx/33gFu3OqcxAPBZOk85Q226M=";
"tree-sitter-ql-dbscheme-0.0.1" = "sha256-wp0LtcbkP2lxbmE9rppO9cK+RATTjZxOb0EWfdKT884=";
};
};

nativeBuildInputs = [ gh libiconv which codeql-cli_2_16_0 jq];

platform = if stdenv.isLinux then "linux64" else "osx64";

installPhase = ''
runHook preInstall
mkdir -p $out/tools/$platform
cargo run --profile release --bin codeql-extractor-ql -- generate --dbscheme ql/src/ql.dbscheme --library ql/src/codeql_ql/ast/internal/TreeSitter.qll
codeql query format -i ql/src/codeql_ql/ast/internal/TreeSitter.qll
# For some reason the fixupPhase isn't working, so we do it manually
patchShebangs tools/
cp -r codeql-extractor.yml tools ql/src/ql.dbscheme ql/src/ql.dbscheme.stats $out/
cp $(cargo metadata --format-version 1 | jq -r '.target_directory')/release/codeql-extractor-ql $out/tools/$platform/extractor
runHook postInstall
'';
}
6 changes: 6 additions & 0 deletions scripts/codeql/ql-extractor/default.nix
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
let
pkgs = import <nixpkgs> {};
in
{
ql-extractor_0_0_1 = pkgs.callPackage ./0.0.1.nix {};
}
15 changes: 15 additions & 0 deletions shell.nix
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
let
nixpkgs = fetchTarball "https://github.com/NixOS/nixpkgs/archive/0e148322b344eab7c8d52f6e59b0d95ba73fb62e.tar.gz";
pkgs = (import nixpkgs { config = {}; overlays = []; }) // (import ./scripts/codeql/default.nix);
in

pkgs.mkShell {
packages = with pkgs; [
clang-tools_14
python39
git
gh
jq
codeql-cli_2_16_0_with_ql_extractor
];
}