Skip to content

Commit b9c56d6

Browse files
committed
Fix static analysis scanner build
1 parent aafade1 commit b9c56d6

2 files changed

Lines changed: 10 additions & 5 deletions

File tree

‎.agents/sow/done/SOW-0009-20260602-github-security-scanning.md‎

Lines changed: 9 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44

55
Status: completed
66

7-
Sub-state: GitHub scanner automation is complete; Supply Chain Security and CodeQL first-run regressions were repaired and validated locally.
7+
Sub-state: GitHub scanner automation is complete; Supply Chain Security, CodeQL, and Static Analysis first-run regressions were repaired and validated locally.
88

99
## Requirements
1010

@@ -333,6 +333,7 @@ What broke:
333333
- First pushed GitHub run `26812274378` failed in `.github/workflows/codeql.yml`.
334334
- Rust CodeQL failed because Rust does not support manual build mode.
335335
- C/C++ CodeQL failed because the workflow built every CMake target and hit an existing GCC preprocessor issue in `tests/fixtures/c/test_stress.c:840`.
336+
- First pushed final Static Analysis run `26812569114` failed in the C Static Analysis job because it also built every CMake target before running library-scoped analyzers.
336337

337338
Evidence:
338339

@@ -342,22 +343,25 @@ Evidence:
342343
- `gh run view 26812274378 --repo netdata/plugin-ipc --json jobs` showed `Analyze Rust` and `Analyze C/C++` failed while `Analyze Go` succeeded.
343344
- The CodeQL Rust log showed `Rust does not support the manual build mode. Please try using one of the following build modes instead: none`.
344345
- The CodeQL C/C++ log showed `tests/fixtures/c/test_stress.c:840:46: error: missing binary operator before token "("`.
346+
- `gh run view 26812569114 --repo netdata/plugin-ipc --json jobs` showed `C Static Analysis` failed at `Build C targets`, while Go and workflow/shell jobs completed successfully.
345347

346348
Why previous validation missed it:
347349

348350
- Local OSV ran under the workstation Go toolchain, which is newer than the SDK module `go.mod` version used by `actions/setup-go`.
349351
- Local `actionlint` verifies workflow syntax but cannot validate Scorecard's runtime publishing restrictions.
350352
- Local CodeQL was not run; `actionlint` cannot validate per-language CodeQL build-mode restrictions.
351353
- Local full CMake used the workstation compiler environment, while the GitHub C/C++ CodeQL job used the hosted runner compiler path and built all tests.
354+
- The Static Analysis C job had the same over-broad build step as the original CodeQL C/C++ job.
352355

353356
Repair plan:
354357

355358
1. Use Go `1.26.x` only for the OSV-Scanner tool job.
356359
2. Keep top-level workflow permissions read-only and move `security-events: write` to SARIF-uploading jobs.
357360
3. Use CodeQL `build-mode: none` for Rust.
358361
4. Limit C/C++ CodeQL manual build to the C library targets.
359-
5. Re-run YAML parse, `actionlint`, SARIF command probes, SOW audit, and `git diff --check`.
360-
6. Commit and push the repair, then inspect the new GitHub run.
362+
5. Limit Static Analysis C build to the C library targets before running library-scoped analyzers.
363+
6. Re-run YAML parse, `actionlint`, C library target build, SOW audit, and `git diff --check`.
364+
7. Commit and push the repair, then inspect the new GitHub run.
361365

362366
Validation:
363367

@@ -367,8 +371,9 @@ Validation:
367371
- `bash .agents/sow/audit.sh` passed with this SOW reopened in `current/`.
368372
- `git diff --check` passed.
369373
- CodeQL repair validation passed: YAML parsing, `actionlint`, local CMake build of `netipc_protocol`, `netipc_uds`, `netipc_shm`, and `netipc_service`, SOW audit, and `git diff --check`.
374+
- Static Analysis C repair validation passed: YAML parsing, `actionlint`, local CMake build of `netipc_protocol`, `netipc_uds`, `netipc_shm`, and `netipc_service`, scoped `clang-tidy`, `cppcheck`, `flawfinder`, SOW audit, and `git diff --check`.
370375

371376
Artifact updates:
372377

373-
- Updated `.github/workflows/supply-chain-security.yml` and `.github/workflows/codeql.yml`.
378+
- Updated `.github/workflows/supply-chain-security.yml`, `.github/workflows/codeql.yml`, and `.github/workflows/static-analysis.yml`.
374379
- No specs, public docs, or project skills changed because the repair is CI configuration only.

‎.github/workflows/static-analysis.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,7 @@ jobs:
4040
run: cmake -S . -B build-static -DCMAKE_BUILD_TYPE=Debug -DCMAKE_EXPORT_COMPILE_COMMANDS=ON
4141

4242
- name: Build C targets
43-
run: cmake --build build-static --parallel
43+
run: cmake --build build-static --parallel --target netipc_protocol netipc_uds netipc_shm netipc_service
4444

4545
- name: Run clang-tidy on C library sources
4646
run: |

0 commit comments

Comments
 (0)