github / github/codeql

Build tracing filtering: path-based inclusion & content-based exclusion

Đang mở
#21,572 4 bình luận 1 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
CodeQL
Star
10.1k
Fork
2.1k
Merge trung bình
2 ngày 15 giờ
Pull request đã merge (30 ngày)
141

Mô tả

I'm using the CodeQL CLI with a large Java/Kotlin project that makes heavy use of autogenerated source during the build process. Because of this, I am using build tracing (`codeql database trace-command`) to extract CodeQL databases.

Is there any way to filter the files processed by the extractor in the following ways? If not, please consider this a feature request :)

---

### Include-filtering by path

I'd like to be able to extract databases for certain components of the project. Due to the complexity of the project's build system, it's not easy to just build/trace only those components of the project; instead it would be much easier if I could just restrict extraction to those components' files by providing path globs during build tracing.

I'm aware that files can be excluded using the `exclude` extractor option, but this only allows certain path globs to be *excluded*, not *included*.

### Exclude-filtering by file contents

As mentioned earlier, the project has a lot of autogenerated code, some (but only some) of which needs to be ignored. This code is often generated with paths that are not easily excludable using the existing path-glob-based exclusions. It would be great if I can specify regexes to search for in the content of files that indicate that the file should not be extracted (e.g. to look for things like "// Autogenerated file, do not edit", etc.)

---

If there isn't a way to do these, I'm happy to hear about hacky workarounds. For example, the commands I trace are already wrapped in shell scripts that wrap the underlying compilers (`javac` etc.) in order to provide for more filtering criteria than mentioned here. However, it's hard to do the above properly using such a wrapper because of i.e. the need to properly parse the original compiler command line arguments, handle things like files in JAR files, [indirect command line options](https://docs.oracle.com/en/java/javase/17/docs/specs/man/javac.html#option-at), etc. The extractor is much better placed to handle such filtering.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Start with the CodeQL CLI `database trace-command` flow and the existing extractor `exclude` option, then trace how Java and Kotlin compiler inputs are passed to extraction. The request has two separate goals: path-based inclusion and content-based exclusion. Done means defining and implementing both filtering behaviors, with their command-line configuration and supported matching semantics documented.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
java, kotlin
Lĩnh vực
build-system, tooling
Loại issue
Tính năng
Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức độ hoạt động
Ít trao đổi
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
38/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.