-
Notifications
You must be signed in to change notification settings - Fork 0
fix(codeql): bootstrap versioned dispatch handler #2106
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
57 commits
Select commit
Hold shift + click to select a range
952f95f
test(codeql): require versioned handler rollout bootstrap
seonghobae 2351dc1
fix(codeql): stage versioned handler rollout bootstrap
seonghobae c5b8d00
docs(codeql): record handler-first rollout boundary
seonghobae a686a48
test(codeql): cap settlement below Actions rerun ceiling
seonghobae 6308f7a
fix(codeql): stop settlement before rerun ceiling
seonghobae 99bc9db
docs(codeql): record rerun exhaustion boundary
seonghobae a5ca9f1
merge: reconcile handler bootstrap with protected main
seonghobae 1d3f510
fix(codeql): add versioned single-settlement handler
seonghobae b2ff9a9
test(codeql): enforce versioned settlement contract
seonghobae 1d6b630
test(codeql): enforce versioned settlement contract
seonghobae c695a11
docs(codeql): define handler-first migration
seonghobae ce33538
docs(codeql): define handler-first migration
seonghobae 0102377
docs(changelog): record versioned CodeQL bootstrap
seonghobae ae3d0a5
docs(codeql): record versioned handler bootstrap evidence
seonghobae fde889a
merge: reconcile handler bootstrap with protected main
seonghobae d7d9225
test(codeql): reproduce fallback stdout contamination
seonghobae 6b476a8
fix(codeql): isolate failed credential response bodies
seonghobae 9bf6a87
docs(codeql): record credential fallback RCA
seonghobae bedce13
docs(changelog): record settlement response isolation
seonghobae 48c6304
chore(codeql): restack #2106 on protected main
seonghobae 2c163e9
test(codeql): exercise consumed-field fallback contamination
seonghobae 50adc03
fix(codeql): integrate versioned rerun exhaustion guards
seonghobae 792d65b
style(codeql): align rerun-mode fixture mapping
seonghobae 24bb659
docs(codeql): correct native rerun allowance
seonghobae 611ccd7
Merge 24bb6591ab7df23558cb793b4af60c567ff9da97 into 64f483db9d052322c…
seonghobae 3253f59
Merge protected main d6cf5726 into canonical CodeQL handler owner
seonghobae db34e6b
Merge protected main 78393ea9 into canonical CodeQL handler owner
seonghobae d33d76f
chore(restack): advance CodeQL handler onto protected main
seonghobae 1ba96e4
chore(restack): advance CodeQL handler through Noema follow-up
seonghobae 4288590
Merge protected main into CodeQL bootstrap #2106
seonghobae 44901e4
chore(codeql): reconcile bootstrap with protected main after #2147
seonghobae 9defd52
chore(codeql): reconcile protected main into #2106
seonghobae 298e6c1
test(codeql): compare hardened-runner endpoints as exact lines
seonghobae 8770316
test(traceability): require owner-qualified cross-repo evidence
seonghobae cf7fa86
revert(traceability): keep baseline repair with canonical document owner
seonghobae be80eb4
merge(main): reconcile CodeQL handler with protected main
seonghobae a5569a0
test(docs): require owner-qualified cross-repo evidence
seonghobae 473371c
merge(main): reconcile CodeQL handler with Rust coverage materializer
seonghobae 1336eae
chore: revert incomplete evidence-identity rehearsal
seonghobae 8429787
test(docs): lock owner-qualified evidence identities
seonghobae ff72f8b
merge(main): reconcile CodeQL bootstrap with current protected main
seonghobae 5e4dfe4
docs: qualify cross-repository evidence identities
seonghobae fdab673
fix: restore exact baseline before repository identity repair
seonghobae fb74675
Merge protected main into CodeQL bootstrap branch
seonghobae bff097e
Merge current protected main into CodeQL bootstrap branch
seonghobae c81e39c
Merge current protected main into CodeQL bootstrap branch
seonghobae 653466d
Fix CodeRabbit issues in PR #2106
coderabbitai[bot] c73d1b4
chore: reconcile CodeQL bootstrap with protected main
seonghobae a44ad8f
fix: preserve protected coalesce tick regression
seonghobae 47ccc21
chore: reconcile CodeQL bootstrap with latest protected main
seonghobae 4ba7960
chore: reconcile CodeQL bootstrap with protected queue hardening
seonghobae 65a71c5
chore: reconcile CodeQL bootstrap with Strix evidence hardening
seonghobae e455561
chore: reconcile CodeQL bootstrap with Noema capacity repair
seonghobae 86dd9ed
fix: preserve protected Noema executable modes
seonghobae c9900f4
merge(main): resolve gap-baseline conflict for CodeQL bootstrap
seonghobae 6be76f6
fix(docs): keep owner-qualified identities after main merge
seonghobae 0e9412f
fix(opencode): preserve protected coverage job contract
seonghobae File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
Large diffs are not rendered by default.
Oops, something went wrong.
14 changes: 14 additions & 0 deletions
14
CHANGELOG.d/20260917-codeql-versioned-handler-bootstrap.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,14 @@ | ||
| ## Changed | ||
|
|
||
| - Add a backward-compatible `codeql-scan`/`codeql-scan-v2` protocol bridge to | ||
| the single protected CodeQL dispatch handler. Legacy clients keep their | ||
| exact title, payload, and status context while v2 requires source/base/head | ||
| provenance. Language scans are `actions:read`; one post-matrix settlement | ||
| revalidates the live PR, required run/jobs, handler gate steps, and SARIF | ||
| artifacts before one run-wide rerun. The legacy path has an explicit | ||
| protected-v2/in-flight-drain/zero-caller removal condition. Failed | ||
| credential attempts retain their diagnostics but cannot leak an HTTP error | ||
| body into a later successful API response. Nested rerun authority is bound | ||
| to string schema `"1"`, and settlement stops before mutation when the | ||
| required run reaches attempt 48, preserving capacity below GitHub's limit of | ||
| 50 re-runs. ADR-0025. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
96 changes: 96 additions & 0 deletions
96
docs/doctoring/codeql-versioned-handler-bootstrap-20260912.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,96 @@ | ||
| # CodeQL versioned handler bootstrap — 2026-09-12 | ||
|
|
||
| ## Status | ||
|
|
||
| Proposed repair from protected `main@691fb78932eff5fbe52db69077848134b0b4e053`. | ||
| No merge or production claim is made here. The complete consumer successor is | ||
| PR #2040, revalidated at current head | ||
| `6476b919d3febf79cc53e71d6d60f15d7e83ced4`. | ||
|
|
||
| ## Exact live evidence | ||
|
|
||
| PR #2040 predecessor head `a9b18b4b24980c7ceb8b8cc0d143a24db20c90bf` | ||
| had successful Runtime Quality run `34684155351` (3,127 passed, 1 skipped, | ||
| 21 subtests; 100% statement, branch, and public-doc coverage), Security run | ||
| `34684356405`, SAST run `34684356377`, and Python Security run `34684356416`. | ||
| It had no unresolved review threads. The later current head `6476b919...` | ||
| moves replay-guard tests without changing this handler source, but historical | ||
| hosted results are not inherited. The current head is Draft and had no | ||
| associated pull-request workflow runs in the connector snapshot. It therefore | ||
| remains unmergeable through ordinary protection. | ||
|
|
||
| Protected handler run `34684228601` is the smallest causal trace. Its Actions | ||
| and Python scan, SARIF gate, artifact preservation, and status paths reached | ||
| terminal completion. The Actions shard then woke the shared required run. The | ||
| Python shard's independent wake received HTTP 403 because that run was no | ||
| longer in the terminal-failed state. Same-repository/PR handler runs | ||
| `34684373526`, `34684458709`, `34684518320`, and `34684575249` were then | ||
| cancelled by the stable concurrency group while retries kept dispatching. In | ||
| `34684575249`, Python produced clean scan evidence while its sibling and wake | ||
| path did not converge. The repeated consumer symptom was a dispatched success | ||
| with a pending terminal verdict. | ||
|
|
||
| ## Root cause | ||
|
|
||
| The protected handler woke the required run independently from each matrix | ||
| scan job. The first wake changed the run state before the second language | ||
| could validate and mutate it. In addition, a candidate stronger consumer | ||
| could not prove itself against protected `main`: the old handler lacked its | ||
| source-bound title and base-bound receipt, while replacing the handler in one | ||
| step would reject the still-protected legacy producer. Re-running either side | ||
| alone reproduces the dependency cycle. | ||
|
|
||
| ## Repair contract | ||
|
|
||
| One existing handler accepts `codeql-scan` legacy v1 and `codeql-scan-v2`. | ||
| The event type is the explicit protocol version, avoiding an eleventh | ||
| top-level `client_payload` property. v1 retains the current title, payload, | ||
| and status context byte-for-byte at the boundary, while rejecting all v2-only | ||
| identity fields. v2 requires the exact source/base/head evidence implemented | ||
| by #2040. Both use the same scan implementation and one post-matrix settlement | ||
| writer. No scan shard has `actions:write`. | ||
|
|
||
| The bridge removal condition is executable policy: remove v1 only after a | ||
| protected v2 producer is live, every in-flight v1 required run is terminal, | ||
| and a caller inventory finds zero `codeql-scan` producers. Until then, v1 is a | ||
| bounded compatibility port, not production authority for v2 consumers. | ||
|
|
||
| ## Verification and next action | ||
|
|
||
| The bootstrap contract executes both payload shapes, rejects v2-to-v1 | ||
| downgrade fields, verifies one actions writer after the matrix, and preserves | ||
| the legacy and base-bound contexts separately. The full repository suite and | ||
| hosted exact-head checks must pass before ordinary merge. After bootstrap | ||
| merge, #2040 must non-force absorb protected main, change only its producer | ||
| event to `codeql-scan-v2`, and generate new end-to-end evidence; existing | ||
| failed or queued runs are not inherited. | ||
|
|
||
| PR #2106 review then exposed a credential-fallback contamination edge case: | ||
| `gh api` may emit an HTTP error body to stdout before returning nonzero, so a | ||
| failed credential's JSON could precede the later credential's successful | ||
| response. A generic `{"message":"Forbidden"}` body was already discarded by | ||
| the current `jq` projections and therefore was not RED. The corrected RED | ||
| fixture emits `{"state":"closed"}`, a field the PR validator consumes: before | ||
| the repair it is concatenated with the authorized response and rejects that | ||
| valid fallback. `run_api` now captures each attempt and emits its body only | ||
| after that exact attempt succeeds, preserving stderr diagnostics and the | ||
| existing credential order without a temporary-file lifecycle. | ||
|
|
||
| The overlapping predecessor PR #2105 retained two additional fail-closed | ||
| guards that the first #2106 tree did not carry. Nested rerun authority now | ||
| requires the exact string schema `"1"`; missing, numeric, and unknown schemas | ||
| are rejected before checkout or mutation. The single settlement writer also | ||
| validates the required run's positive integer `run_attempt` and stops before | ||
| mutation when it reaches 48. GitHub documents that `run_attempt` begins at 1 | ||
| and increments for every re-run, while one workflow run permits at most 50 | ||
| re-runs; the cutoff therefore preserves attempts 49–51 for human recovery | ||
| rather than consuming the native allowance automatically. The structured | ||
| failure records the run, attempt, schema, languages, and handler identity. | ||
| This integrates the valid #2105 delta into the backward-compatible legacy/v2 | ||
| bridge rather than choosing either incomplete branch unchanged. | ||
|
|
||
| GitHub. (2026). *Re-running workflows and jobs*. | ||
| https://docs.github.com/en/actions/how-tos/manage-workflow-runs/re-run-workflows-and-jobs | ||
|
|
||
| GitHub. (2026). *Variables reference*. | ||
| https://docs.github.com/en/actions/reference/workflows-and-actions/variables |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.