Skip to content

ci: reject incomplete Swift module extraction - #3

Merged
hideouts-io merged 5 commits into
mainfrom
codex/github-codeql-modules-20261008
Oct 9, 2026
Merged

hideouts-io merged 5 commits into
mainfrom
codex/github-codeql-modules-20261008

Conversation

@hideouts-io

@hideouts-io hideouts-io commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

Problem

The first native Swift scan extracted all six application source files but emitted 96 imported Clang-module diagnostics: 48 precompiled-module compiler branch mismatches and 48 failed module emissions. A successful scan status did not establish complete imported-module semantics.

Changes

  • Use Apple's explicit-module opt-out only in the CodeQL xcodebuild invocation, with a single x86_64 scanner build and an explicit matching macOS destination, as advertised by the CodeQL-traced Xcode process. Normal arm64 native CI is unchanged.
  • Apply GitHub's documented Xcode analysis settings: disable the integrated Swift driver and both compile caches, and disable signing requirements in the scanner build.
  • Reject Swift extraction-error notifications regardless of severity before publishing SARIF. Missing, empty, or invalid consumed SARIF structures fail explicitly.
  • Retain failed analysis SARIF for one day for bounded diagnostic review; publishing still requires every source job to pass.
  • Preserve the normal native CI gates, product settings, Go coverage, Actions coverage, read-only build permissions, and isolated SARIF publishers.

Validation

  • The gate rejects the actual prior MacScope SARIF with 96 diagnostics and DriveTrace SARIF with 2 diagnostics.
  • It accepts the actual Interface-Sentinel SARIF with zero extraction errors.
  • Missing SARIF and invalid SARIF schema fail; workflow YAML parsing and diff checks pass.
  • Fresh hosted native checks, all language analyses, zero Swift extraction errors, intended production source inventories, and processed uploads are required before merge.

Sources and limits

Apple documents the explicit-module opt-out in Xcode 26 release notes. The CodeQL extractor compatibility change describes explicit-module limitations and compiler-flag handling.

The official CodeQL preparation guide documents the driver, cache and signing requirements.

No live system scan, scanner execution, privileged collection, native UI interaction, release, or deployment is included.

@hideouts-io
hideouts-io merged commit 5ae6205 into main Oct 9, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant