Overlay-base cache restore misses on cache backends that only prefix-match restoreKeys
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Newbie friendliness
- 90/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- typescript
- Domain
- ci-cd
Research direction
Start at src/overlay/caching.ts around lines 290-302, where downloadOverlayBaseDatabaseFromCache calls actionsCache.restoreCache with the key prefix as the only argument; compare with the upload path just above it that writes codeql-overlay-base-database-<hash>-<sha>-<run_id>. The fix is passing the same prefix as the third argument (restoreKeys), then run the existing overlay caching tests in the TypeScript suite to confirm no current GitHub-cache behavior regresses. Done means PR runs on prefix-only backends can restore while GitHub-hosted behavior matches today.
Written by the indexing model from the issue text.
Description
Summary
downloadOverlayBaseDatabaseFromCache restores the overlay-base database by passing the key prefix as the primary key, with no restoreKeys:
actionsCache.restoreCache(
[dbLocation],
cacheRestoreKeyPrefix,
undefined,
{ segmentTimeoutInMs: 3000 },
)
This depends on the primary key matching by prefix. GitHub's cache service does that, but some Actions-cache-compatible backends only prefix-match restoreKeys. One example is the transparent cache on Blacksmith runners. On those backends, PR runs can never restore the overlay-base database, even though default-branch runs upload it successfully. Every PR run then falls back to a full analysis.
What we see
Default-branch run, on the same runner type:
Setting overlay database mode to overlay-base with caching because we are analyzing the default branch.
Uploading overlay-base database to Actions cache with key codeql-overlay-base-database-1-<hash>-python-2.27.1-<sha>-<run_id>-1
Successfully uploaded overlay-base database from /home/runner/_work/_temp/codeql_databases
Pull request run:
Setting overlay database mode to overlay with caching because we are analyzing a pull request.
Looking in Actions cache for overlay-base database with restore key codeql-overlay-base-database-1-<hash>-python-2.27.1-
No overlay-base database found in Actions cache
No overlay-base database found in cache, reverting overlay database mode to none.
Minimal reproduction of the backend difference
A cache entry saved as probe-<run_id>-full, then restored in a later job on the same branch with actions/cache/restore@v4:
| Restore | GitHub-hosted runner | Blacksmith runner |
|---|---|---|
key: probe-<run_id>- (prefix as the primary key, like this action) |
hit | miss |
key: probe-<run_id>-nomatch, restore-keys: probe-<run_id>- |
hit | hit |
Suggested fix
Also pass the prefix as a restore key:
actionsCache.restoreCache(
[dbLocation],
cacheRestoreKeyPrefix,
[cacheRestoreKeyPrefix],
{ segmentTimeoutInMs: 3000 },
)
On GitHub's cache this matches exactly the same entries as today, since the prefix is tried first either way. On backends that only prefix-match restore keys, overlay analysis starts working.
Environment
github/codeql-action/initandanalyze@v4, CodeQL bundle 2.27.1build-mode: none, languagespythonandjavascript-typescript- Third-party hosted runners (Blacksmith) whose
actions/cachecalls go to their own cache backend
- Dominant language
- TypeScript
- Stars
- 1.7k
- Forks
- 494
- Avg merge
- 1d 10h
- Merged PRs (30d)
- 52
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from github/codeql-action
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
github/codeql-action#4052 · 4 comments ·
Maintainers usually reply within 1 day
-
Difficulty 5/5 Over a week Newbie friendliness 28/100
github/codeql-action#4199 ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 45/100
github/codeql-action#4185 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
github/codeql-action#4173 · 3 comments ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 45/100
github/codeql-action#4078 · 1 comment ·
Maintainers usually reply within 1 day
All issues in github/codeql-action
Similar issues
-
refactor
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
tomnewport/memprot-topo#55 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
WalletConnect/walletconnect-monorepo#7368 · 1 comment ·
Maintainers usually reply within 1 day
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
BU-Spark/se-chem-apll#47 ·
-
embed: handleTurboSignMessage header comment says the signing page posts to '*' (it never does)Opendocumentation
Difficulty 2/5 Under an hour Newbie friendliness 82/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 Half a day Newbie friendliness 70/100
udistrital/paginaweb_root#23 ·