Rust: extraction succeeds with missing proc-macro output when the project's `rust-version` exceeds the forced toolchain
维护者通常 1 天内回复
@paldepind 已经在做这个了。
开始于 2026年10月9日。
评估
这个 Issue 还没有评估数据。
描述
Description of the issue
Since the Rust extractor began forcing FIXED_RUST_TOOLCHAIN (d9417a34, first shipped in CodeQL 2.27.1), a project whose Cargo.toml declares a rust-version newer than that toolchain loses its build-script outputs and procedural-macro expansions during extraction.
get_extra_env() in rust/extractor/src/config.rs sets RUSTUP_TOOLCHAIN to the fixed toolchain after merging cargo_extra_env, so the build-script cargo check that rust-analyzer runs uses that toolchain. Cargo refuses the package because its declared rust-version is newer than the active compiler. load_workspace_at in ra_ap_load_cargo logs the error at debug level and continues loading the workspace.
The analysis reports success. Macro-expansion warnings appear in the extraction output, but the underlying Cargo refusal is hidden by the default logging filter, which does not include rust-analyzer's targets.
Because the fixed toolchain trails the latest stable release, a project can be affected whenever its declared minimum exceeds the extractor's selected compiler. Cargo's documentation describes tracking the latest Rust version as one valid rust-version policy, and projects following it will be affected after a stable release until the extractor's toolchain catches up. The open rust-analyzer updates (#22741, #22776) move the fixed toolchain to 1.99.0, which would cover this project's current declaration but not the next stable release.
Evidence
Environment: CodeQL CLI 2.27.1 (FIXED_RUST_TOOLCHAIN = "1.97.0"), github/codeql-action v4.38.2, build-mode: none, ubuntu-latest. The project pins 1.99.0 in rust-toolchain.toml and declares rust-version = "1.99.0".
With RUST_LOG enabling ra_ap_load_cargo=debug, rust-analyzer logs the refusal:
Errors occurred while running build scripts for .../backend/Cargo.toml: error: rustc 1.97.0 is not supported by the following packages:
[email protected] requires rustc 1.99.0
To confirm the cause, two runs were made on the same revision, differing only in whether CODEQL_EXTRACTOR_RUST_OPTION_CARGO_EXTRA_ARGS=--ignore-rust-version was set. Each queried the finished database for first-party macro expansions:
| Measure | Without the flag | With the flag |
|---|---|---|
Build-script/proc-macro outputs loaded (BuildScriptOutput entries) |
0 | 83 |
| "proc-macro not yet built" diagnostics | 317 | 0 |
| "macro expansion failed" diagnostics (capped per file) | 128 | 0 |
sqlx expand_query calls expanding to more than five AST nodes |
0 of 308 | 308 of 308 |
| Derive expansions containing items | 587 of 904 | 1,059 of 1,059 |
| Attribute-macro expansions containing items | 0 | 96 |
Job logs, including the database query output:
- Without the flag: https://github.com/unkos-dev/reverie/actions/runs/37893162409/job/113698447396
- With the flag: https://github.com/unkos-dev/reverie/actions/runs/37894117181/job/113701453702
The flag only skips Cargo's version check. It would not help if a build script or procedural-macro dependency genuinely required a newer compiler than the forced toolchain, and cargo_extra_args is not part of the published option schema in rust/codeql-extractor.yml.
Related: #19982 (macro expansion warnings), #22493 (pinning the toolchain).
- 主要语言
- CodeQL
- 星标
- 10.2k
- 派生
- 2.1k
- 平均合并
- 2 天 11 小时
- 30 天内合并 PR
- 155
环境准备
在浏览器里用你自己的 GitHub 账号启动这个项目的开发容器。
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
github/codeql 的其他 Issue
-
false-positive javascript
难度 2/5 1-3 小时 新手友好度 84/100
维护者通常 1 天内回复
-
Add AlertSuppression.ql for Rust (inline // codeql[...] suppression)可能已有人在做 @cnuss 于 192 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复
-
false-positive
难度 2/5 1-3 小时 新手友好度 70/100
github/codeql#21076 · 3 条评论 · 3 个 reaction ·
维护者通常 1 天内回复
-
难度 4/5 3-5 天 新手友好度 15/100
维护者通常 1 天内回复
-
Actions: `uses: $/…` self-repository references are not resolved to local reusable workflows or composite actions (false positives and downgraded severity)可能已有人在做 @WilliamBerryiii 于 1 天前认领。 未关闭
难度 3/5 1-2 天 新手友好度 62/100
github/codeql#22755 · 1 条评论 · 1 个 reaction ·
维护者通常 1 天内回复