Rust: extraction succeeds with missing proc-macro output when the project's `rust-version` exceeds the forced toolchain
Les mainteneurs répondent en général sous 1 jour
@paldepind y travaille déjà.
Depuis le 9/10/2026.
Évaluation
Cette issue n'a pas encore été évaluée.
Description
Description of the issue
Since the Rust extractor began forcing FIXED_RUST_TOOLCHAIN (d9417a34, first shipped in CodeQL 2.27.1), a project whose Cargo.toml declares a rust-version newer than that toolchain loses its build-script outputs and procedural-macro expansions during extraction.
get_extra_env() in rust/extractor/src/config.rs sets RUSTUP_TOOLCHAIN to the fixed toolchain after merging cargo_extra_env, so the build-script cargo check that rust-analyzer runs uses that toolchain. Cargo refuses the package because its declared rust-version is newer than the active compiler. load_workspace_at in ra_ap_load_cargo logs the error at debug level and continues loading the workspace.
The analysis reports success. Macro-expansion warnings appear in the extraction output, but the underlying Cargo refusal is hidden by the default logging filter, which does not include rust-analyzer's targets.
Because the fixed toolchain trails the latest stable release, a project can be affected whenever its declared minimum exceeds the extractor's selected compiler. Cargo's documentation describes tracking the latest Rust version as one valid rust-version policy, and projects following it will be affected after a stable release until the extractor's toolchain catches up. The open rust-analyzer updates (#22741, #22776) move the fixed toolchain to 1.99.0, which would cover this project's current declaration but not the next stable release.
Evidence
Environment: CodeQL CLI 2.27.1 (FIXED_RUST_TOOLCHAIN = "1.97.0"), github/codeql-action v4.38.2, build-mode: none, ubuntu-latest. The project pins 1.99.0 in rust-toolchain.toml and declares rust-version = "1.99.0".
With RUST_LOG enabling ra_ap_load_cargo=debug, rust-analyzer logs the refusal:
Errors occurred while running build scripts for .../backend/Cargo.toml: error: rustc 1.97.0 is not supported by the following packages:
[email protected] requires rustc 1.99.0
To confirm the cause, two runs were made on the same revision, differing only in whether CODEQL_EXTRACTOR_RUST_OPTION_CARGO_EXTRA_ARGS=--ignore-rust-version was set. Each queried the finished database for first-party macro expansions:
| Measure | Without the flag | With the flag |
|---|---|---|
Build-script/proc-macro outputs loaded (BuildScriptOutput entries) |
0 | 83 |
| "proc-macro not yet built" diagnostics | 317 | 0 |
| "macro expansion failed" diagnostics (capped per file) | 128 | 0 |
sqlx expand_query calls expanding to more than five AST nodes |
0 of 308 | 308 of 308 |
| Derive expansions containing items | 587 of 904 | 1,059 of 1,059 |
| Attribute-macro expansions containing items | 0 | 96 |
Job logs, including the database query output:
- Without the flag: https://github.com/unkos-dev/reverie/actions/runs/37893162409/job/113698447396
- With the flag: https://github.com/unkos-dev/reverie/actions/runs/37894117181/job/113701453702
The flag only skips Cargo's version check. It would not help if a build script or procedural-macro dependency genuinely required a newer compiler than the forced toolchain, and cargo_extra_args is not part of the published option schema in rust/codeql-extractor.yml.
Related: #19982 (macro expansion warnings), #22493 (pinning the toolchain).
- Langage dominant
- CodeQL
- Étoiles
- 10.2k
- Forks
- 2.1k
- Merge moyen
- 2 j 11 h
- PR mergées (30 j)
- 155
Préparer son environnement
Lance le conteneur de développement du projet dans votre navigateur, avec votre propre compte GitHub.
- Aucun Dockerfile ni fichier Docker Compose
- Aucun modèle de pull request
- Lire le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de github/codeql
-
false-positive javascript
Difficulté 2/5 1-3 heures Accessibilité débutants 84/100
github/codeql#22632 · 1 commentaire ·
Les mainteneurs répondent en général sous 1 jour
-
Add AlertSuppression.ql for Rust (inline // codeql[...] suppression)Peut-être pris @cnuss l’a pris il y a 191 jours. Ouverte
Difficulté 2/5 1-3 heures Accessibilité débutants 78/100
github/codeql#21637 · 2 commentaires ·
Les mainteneurs répondent en général sous 1 jour
-
false-positive
Difficulté 2/5 1-3 heures Accessibilité débutants 70/100
github/codeql#21076 · 3 commentaires · 3 réactions ·
Les mainteneurs répondent en général sous 1 jour
-
Difficulté 4/5 3-5 jours Accessibilité débutants 15/100
Les mainteneurs répondent en général sous 1 jour
-
Actions: `uses: $/…` self-repository references are not resolved to local reusable workflows or composite actions (false positives and downgraded severity)Peut-être pris @WilliamBerryiii l’a pris il y a 1 jour. Ouverte
Difficulté 3/5 1-2 jours Accessibilité débutants 62/100
github/codeql#22755 · 1 commentaire · 1 réaction ·
Les mainteneurs répondent en général sous 1 jour