Repository navigation
fix(orbit): name the cause when the startup host-info query returns no rows - #232
Merged
Merged
Conversation
…o rows The row-count error from getHostInfo now carries osqueryd's stderr, and on Windows with zero rows from a query that ran cleanly it names WMI as the cause. Upstream reports only the count, so a host with broken WMI could not be diagnosed from logs. The stderr is flattened to one line and capped, since the supervisor restarts orbit on this failure and the line is logged each time. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Author
🦩 Flamingo Code Review✅ No findings on the current head. Advisory: findings do not block the merge. Review again. New commits are not reviewed until you ask:
Or comment Started 2026-10-05 17:42 UTC · updated 2026-10-05 17:43 UTC · workflow run |
denys-gif
approved these changes
Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CU-86akqy70q
Change-Set: wmi-startup-diagnostics
Problem
At startup orbit runs
osqueryd -Swith a query joiningsystem_info,os_versionandosquery_info, and needs exactly one row. On a Windows host where WMI is broken the join is empty and orbit exits with:osqueryd exits 0 in that case, and
getHostInfoonly logs its stderr on a non-zero exit, so whatever osquery said about the failure is dropped. The line says the result was empty but not why, and diagnosing it took a live look at the machine.Fix (
OPENFRAME(agent-host-info-diagnostics))The row-count check in
getHostInforeturnshostInfoRowsError(...)(new fileorbit/cmd/orbit/host_info_openframe.go) instead of the bare count:os_versionis the only table of the three that can be empty:system_infofalls back to-1values andosquery_infoalways has one row. A query that fails outright (SQL error, a table that throws) also prints an empty result but exits non-zero, so in that case the clause is left out and the stderr clause carries the cause.--openframe-mode: it only changes the text of an error that already ends the run.The Windows error code inside the stderr comes from the sibling PR flamingo-stack/osquery#111. Neither PR needs the other merged first: with an older osqueryd the stderr clause may be absent or carry no code, and the WMI clause is there regardless.
Docs:
openframe/docs/agent-host-info-diagnostics.md, plus rows in the docs README, fork-file manifest, sync runbook, and the slug inopenframe/scripts/verify.sh.Tests
orbit/cmd/orbit/host_info_openframe_test.go: the message per platform, row count and osqueryd exit status, the truncation (including a cut inside a multi-byte character), andgetHostInfoend to end against a fakeosquerydthat prints[]plus a warning and exits 0 or 1.go build ./orbit/cmd/orbitfor macOS and Windows,go vet, andgo test -race ./orbit/cmd/orbit/pass.go test -race ./orbit/...passes exceptorbit/pkg/profilesTestGetFleetdConfig, a package this PR does not touch.openframe/scripts/verify.shfast tier: build, vet, marker presence and key-prefix pass. Its marker-coverage step fails on unmarked lines underserver/, none underorbit/, the same as onmain.🤖 Generated with Claude Code
Change set
flamingo-stack/wmi-startup-diagnostics: these pull requests are one change, reviewed together.Linked work
Linked by the
Depends-On/Change-Setlines in these descriptions; this block is maintained by the hub.