Skip to content

fix(orbit): name the cause when the startup host-info query returns no rows - #232

Merged
mikhailm-coder merged 1 commit into
mainfrom
hotfix/wmi-startup-diagnostics
Oct 5, 2026
Merged

mikhailm-coder merged 1 commit into
mainfrom
hotfix/wmi-startup-diagnostics

Conversation

@mikhailm-coder

@mikhailm-coder mikhailm-coder commented Oct 5, 2026 •

Copy link
Copy Markdown

CU-86akqy70q

Change-Set: wmi-startup-diagnostics

Problem

At startup orbit runs osqueryd -S with a query joining system_info, os_version and osquery_info, and needs exactly one row. On a Windows host where WMI is broken the join is empty and orbit exits with:

run orbit failed error="get UUID: invalid number of rows from system info query: 0"

osqueryd exits 0 in that case, and getHostInfo only logs its stderr on a non-zero exit, so whatever osquery said about the failure is dropped. The line says the result was empty but not why, and diagnosing it took a live look at the machine.

Fix (OPENFRAME(agent-host-info-diagnostics))

The row-count check in getHostInfo returns hostInfoRowsError(...) (new file orbit/cmd/orbit/host_info_openframe.go) instead of the bare count:

get UUID: invalid number of rows from system info query: 0; on Windows this means osquery got no OS data from WMI (Win32_OperatingSystem); osqueryd stderr: W1005 12:00:00.000000 4321 os_version.cpp:33] enum osquery::WmiError[0] (WmiRequest creation failed to connect to server: 0x800706ba)
  • Upstream's text stays as the prefix, so existing log searches still match.
  • The WMI clause is added only for zero rows on Windows when osqueryd exited 0. There os_version is the only table of the three that can be empty: system_info falls back to -1 values and osquery_info always has one row. A query that fails outright (SQL error, a table that throws) also prints an empty result but exits non-zero, so in that case the clause is left out and the stderr clause carries the cause.
  • The stderr clause is added only when osqueryd printed something. It is flattened to one line and capped at 2048 bytes, because the supervisor restarts orbit every few seconds on this failure and the line is logged again each time.
  • Unconditional, not gated on --openframe-mode: it only changes the text of an error that already ends the run.

The Windows error code inside the stderr comes from the sibling PR flamingo-stack/osquery#111. Neither PR needs the other merged first: with an older osqueryd the stderr clause may be absent or carry no code, and the WMI clause is there regardless.

Docs: openframe/docs/agent-host-info-diagnostics.md, plus rows in the docs README, fork-file manifest, sync runbook, and the slug in openframe/scripts/verify.sh.

Tests

  • orbit/cmd/orbit/host_info_openframe_test.go: the message per platform, row count and osqueryd exit status, the truncation (including a cut inside a multi-byte character), and getHostInfo end to end against a fake osqueryd that prints [] plus a warning and exits 0 or 1.
  • Locally: go build ./orbit/cmd/orbit for macOS and Windows, go vet, and go test -race ./orbit/cmd/orbit/ pass. go test -race ./orbit/... passes except orbit/pkg/profiles TestGetFleetdConfig, a package this PR does not touch.
  • openframe/scripts/verify.sh fast tier: build, vet, marker presence and key-prefix pass. Its marker-coverage step fails on unmarked lines under server/, none under orbit/, the same as on main.
  • Not yet exercised on a host with broken WMI.

🤖 Generated with Claude Code

Change set flamingo-stack/wmi-startup-diagnostics: these pull requests are one change, reviewed together.

Linked work

Linked by the Depends-On / Change-Set lines in these descriptions; this block is maintained by the hub.

…o rows

The row-count error from getHostInfo now carries osqueryd's stderr, and on
Windows with zero rows from a query that ran cleanly it names WMI as the
cause. Upstream reports only the count, so a host with broken WMI could not
be diagnosed from logs.

The stderr is flattened to one line and capped, since the supervisor
restarts orbit on this failure and the line is logged each time.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@mikhailm-coder

Copy link
Copy Markdown
Author

@flamingo-review

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

🦩 Flamingo Code Review

✅ No findings on the current head.

Advisory: findings do not block the merge.


Review again. New commits are not reviewed until you ask:

  • Review the new commits: only what was pushed since this review
  • Review the whole diff again: everything, including what was already reviewed

Or comment @flamingo-review (new commits) or @flamingo-review full (everything). Add the flamingo-review-always label to review every push.

Started 2026-10-05 17:42 UTC · updated 2026-10-05 17:43 UTC · workflow run

@mikhailm-coder
mikhailm-coder merged commit 6f46a68 into main Oct 5, 2026
18 of 19 checks passed
@mikhailm-coder
mikhailm-coder deleted the hotfix/wmi-startup-diagnostics branch October 5, 2026 21:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants