Skip to content

codeql-action/init Makes Metal Toolchain Unavailable on macOS 26 Runners #3978

Description

@PSchmiedmayer

Description

Swift/iOS builds fail after github/codeql-action/init with Xcode 26 on macOS 26 GitHub-hosted runners when the build needs the Metal toolchain.

The failing build error is:

error: error: cannot execute tool 'metal' due to missing Metal Toolchain; use: xcodebuild -downloadComponent MetalToolchain
Command CompileMetalFile failed with a nonzero exit code

This was originally discussed in actions/runner-images:

Reproduction outline

jobs:
  codeql-metal-repro:
    runs-on: macos-26
    permissions:
      contents: read
      security-events: write
    steps:
      - uses: actions/checkout@v4
      - name: Select Xcode
        uses: maxim-lobanov/setup-xcode@v1
        with:
          xcode-version: latest-stable
      - name: Check Metal before CodeQL init
        run: |
          xcodebuild -version
          xcrun --find metal
          xcrun metal -v
      - name: Initialize CodeQL
        uses: github/codeql-action/init@v4
        with:
          languages: swift
          build-mode: manual
      - name: Check Metal after CodeQL init
        run: |
          xcrun --find metal
          xcrun metal -v
      - name: Build
        run: |
          # Run the normal xcodebuild command for an iOS app target that compiles Metal files.
          xcodebuild ...

Expected: xcrun metal -v and the xcodebuild invocation continue to find the selected Xcode’s Metal toolchain after CodeQL initialization.

Actual: after codeql-action/init, xcrun metal -v / CompileMetalFile can fail with “missing Metal Toolchain”, even though the runner image appears to have the toolchain available before CodeQL initialization.

Note: Xcode 26 changed Metal Toolchain distribution/visibility, and MacPorts documented extra steps sometimes needed to make the toolchain visible to all users:
https://trac.macports.org/wiki/TahoeProblems#MetaltoolchainisnolongerbundledinXcode

Activity

  1. mbg commented on Jun 26, 2026

    @mbg
    Member

    Hi @PSchmiedmayer 👋🏻

    Thanks for opening this issue. My first thought here is that this could be a Rosetta issue. One of the things that the codeql-action/init step does is to initialise the CodeQL tracer which injects itself into certain processes to observe how the project is built. This does not natively support ARM-based architectures, and so runs through Rosetta on macOS. Subsequently, all processes it intercepted then also run under Rosetta. My hypothesis would therefore be that in the example run, Metal is installed for the ARM-based host, but not for the Intel-based process tree that runs after the CodeQL tracer intercepted the command.

    I'll pass this on to the team that looks after Swift support in CodeQL who'll know best and whether there's anything we can do on our end to address this.

  2. PSchmiedmayer commented on Jun 26, 2026

    @PSchmiedmayer
    Author

    Thank you @mbg for the quick response; greatly appreciated and thank you for looking into this!

  3. jketema commented on Jun 29, 2026

    @jketema

    I investigated this in the context of actions/runner-images#13014, and this also failed on macOS Intel runners, so this is not Rosetta related.

    Currently this fails for me already in the "Check Metal before CodeQL init" step, so it looks like there a regression in the runner images which would need be be resolved first.

  4. PSchmiedmayer commented on Jul 1, 2026

    @PSchmiedmayer
    Author

    Thanks @jketema; that's unfortunate, I will report that back to the main issue over in actions/runner-images#13014.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions