CodeQL analyses the viewer as built, and the workflows run with least privilege - #402
Conversation
The configure step passed AL_GRID with quotes of its own, a leftover of when the grid was a C string define. Since the install rules became the package manifest, AL_GRID is a plain string checked against agni: the quoted name never matched, so every CI build shipped a settings_install.xml with CmdLineGridChoice set to "agni". The viewer took that for a grid given on the command line, could not find it, and in doing so skipped the user's last grid (CurrentGrid) and, at the login panel, their saved start location. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Same-repository pull requests were given the writer keys and readwrite mode as a temporary test to populate the cache. That let code still under review put packages in the cache that release builds then use. They are back on the read-only keys in read mode, as the cache was set up; the read-only keys pass the cache's preflight, as the pull request builds of 2026-09-20 showed. Only trusted builds of protected refs write. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… privilege CodeQL's default setup read the C/C++ without building it: no vcpkg header resolved, no platform #if decided, two and three quarter hours a run. The CodeQL workflow traces a real build instead, on Linux and on Windows, with the security-extended queries, plus Python and the workflows themselves without a build. The configure runs before tracing starts, so the vcpkg ports stay out of the database, and the build tree sits outside the checkout, so their headers stay out of the alerts. Linux keeps default setup's category, so its alerts and dismissals carry over. Default setup has to be switched off for it to upload. - A composite action, setup-build, holds the host packages, Python tools, vcpkg bootstrap and R2 cache setup the build and CodeQL share. Its Rust cache is keyed on the vcpkg manifest and registry baseline; the Cargo.lock it was keyed on never existed, so the key never moved. - Every workflow names its token's permissions, so the repository's default can be read only: the release job writes contents, CodeQL writes security events, the labeler writes pull requests, the rest read or nothing. The build job no longer asks for packages: write. - Inputs and ref names reach scripts through the environment, never pasted into them; checkouts keep no credentials. - Build: a pull request's new push cancels its old run; one platform failing no longer cancels the others; pull requests that change only documentation or GitHub files no build reads do not build; the release carries the tag's relnotes; the packaging job checks out only dotnet-tools.json; the .tar.xz and .dmg packages upload without being compressed a second time; dead matrix excludes and step outputs are gone. - Dependabot watches the composite action and no longer proposes vcpkg baselines: it moves builtin-baseline without the submodule, and every such pull request failed to configure. - Lint workflows runs actionlint on changes under .github. - The labeler drops libraries that are gone and labels alscript, llwebrtc, llphysicsextensionsos, media_plugins and .github. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (11)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 SummarySummary by CodeRabbit
WalkthroughThe pull request adds reusable GitHub Actions build setup, revises build and release workflows, introduces CodeQL analysis and workflow linting, and updates repository automation rules. ChangesBuild and Code Analysis
Repository Automation
Priority: ➖ Normal Estimated code review effort: 4 (Complex) | ~45 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant BuildWorkflow as build.yaml
participant SetupAction as setup-build action
participant Vcpkg as vcpkg bootstrap
participant R2Config as R2 cache configuration script
BuildWorkflow->>SetupAction: Pass R2 mode, endpoint, bucket, and credentials
SetupAction->>Vcpkg: Run the platform bootstrap script
opt R2 cache mode is nonempty
SetupAction->>R2Config: Configure cache with action inputs
end
Merge Risk: ⚪ Minimal · up to The workflow changes appear mergeable after normal checks; no actionable build or release failure was established. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to Normal pull-request builds lose shared-cache write access, while release authority remains separated from ordinary builds. No introduced security issue was established, but protection against malicious workflow edits and the actual cache credential permissions could not be verified. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the build with care Comment |
Without them the tree does not build: llstring.h calls std::strlen with no <cstring> of its own, which the precompiled header always supplied, and the Linux analysis stopped at httpstats.cpp. Turning them off was a precaution only; the extractor reads the forced-include header as text whether or not the compiler has a precompiled copy of it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Description
Proper CodeQL support, least-privilege workflow permissions, and the defects a review of
build.yamlturned up. Three commits:1. CI builds name their grid
agni, not"agni"with its quotes (fix, can be cherry-picked to release branches)The configure step passed
-DAL_GRID:STRING="\"$VIEWER_GRID\"". Every build log showsGrid "agni". Since the install rules became the package manifest (388db40), that quoted name fails theagnicheck innewview/CMakeLists.txt. As a result every CI build ships asettings_install.xmlwithCmdLineGridChoiceset to"agni". The viewer then reports an unknown grid at startup and skips the user's last grid (CurrentGrid) and their saved start location.2. Pull requests read the vcpkg cache in R2 and no longer write it (security)
Same-repository PRs were on the writer keys in readwrite mode, a temporary cache population test. That let unreviewed code put packages in the cache that release builds use. PRs are back on
VCPKG_R2_READ_*in read mode. Those keys passed the cache's preflight in the PR builds of 2026-09-20.3. CodeQL analyses the viewer as built, and the workflows run with least privilege
codeql.yaml,codeql/codeql-config.yaml):security-extendedqueries. Python and the workflows themselves are scanned without a build.llstring.husesstd::strlenwith no<cstring>).actions/setup-build): one place for the apt/brew packages, Python tools, vcpkg bootstrap, R2 cache setup and Rust cache, used by the build and CodeQL. The Rust cache was keyed on aCargo.lockthat doesn't exist, so its key never changed; it's now keyed on the vcpkg manifest and registry baseline.release:contents: write.security-events: write.pull-requests: write.pull-requests: read, forwhich-branch.contents: reador nothing.packages: write.inputs.project,inputs.channel,github.ref_name, the release URL, and thetag-releaseinputs)..git/config.fail-fast: false, so one platform failing doesn't cancel the others.relnotes. They were extracted but never used.dotnet-tools.jsoninstead of every submodule..tar.xz/.dmgartifacts upload without being compressed a second time.builtin-baselinewithout the submodule and every such PR failed to configure (Bump github.com/microsoft/vcpkg from master to 2026.07.29 in /indra #358)..githubchanges, with shellcheck at warning level.llcrashloggerandllmeshoptimizer, which no longer exist. Addedalscript,llwebrtc,llphysicsextensionsos,media_plugins, andgithub_actionsfor.github/**.Related Issues
Issue Link: none
Checklist
Additional Notes
Repository settings this needs:
alscript,llphysicsextensionsos,llwebrtcandmedia_plugins. The labeler can only create a label withissues: write, which it isn't given.Expect long CodeQL C/C++ runs. A full Linux viewer build takes about 95 minutes, and tracing slows it further, so expect about 3–4.5 hours per platform. The job timeout is the 6-hour maximum.
Still open:
🤖 Generated with Claude Code