From fa839bb21333f2815fe2e626b515aba28e9cfcf4 Mon Sep 17 00:00:00 2001 From: "flamingo[bot]" <277372822+flamingo[bot]@users.noreply.github.com> Date: Mon, 5 Oct 2026 05:15:11 +0000 Subject: [PATCH 01/11] fix(adhoc-sweep-fixes): 11 review findings across 11 files --- tests/integration/tables/azure_instance_metadata.cpp | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/tests/integration/tables/azure_instance_metadata.cpp b/tests/integration/tables/azure_instance_metadata.cpp index 016c2a5f527..3e35d56683b 100644 --- a/tests/integration/tables/azure_instance_metadata.cpp +++ b/tests/integration/tables/azure_instance_metadata.cpp @@ -28,7 +28,8 @@ TEST_F(azureInstanceMetadata, test_sanity) { {"architecture", NormalType}, {"offer", NormalType}, {"publisher", NormalType}, - {"sku", NormalType} {"version", NormalType}, + {"sku", NormalType}, + {"version", NormalType}, {"os_type", NormalType}, {"platform_update_domain", NormalType}, {"platform_fault_domain", NormalType}, @@ -42,6 +43,7 @@ TEST_F(azureInstanceMetadata, test_sanity) { }; validate_rows(data, row_map); } +} } // namespace table_tests -} // namespace table_tests +} // namespace osquery From ed1131fb7547826301ac5fc89032872da0ba8a20 Mon Sep 17 00:00:00 2001 From: "flamingo[bot]" <277372822+flamingo[bot]@users.noreply.github.com> Date: Mon, 5 Oct 2026 05:15:12 +0000 Subject: [PATCH 02/11] fix(adhoc-sweep-fixes): 11 review findings across 11 files --- tools/tests/test_windows_service.py | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/tools/tests/test_windows_service.py b/tools/tests/test_windows_service.py index ae0f6a48ebb..35b5638816b 100644 --- a/tools/tests/test_windows_service.py +++ b/tools/tests/test_windows_service.py @@ -103,11 +103,11 @@ def sc(*args): ['sc.exe'] + list(args), stderr=subprocess.PIPE, stdout=subprocess.PIPE) - except subprocess.CalledProcessError, err: + except subprocess.CalledProcessError as err: return (err.returncode, err.output) out, _ = p.communicate() - out = [x.strip() for x in out.split('\r\n') if x.strip() is not ''] + out = [x.strip() for x in out.split('\r\n') if x.strip() != ''] if len(out) >= 1: if 'SUCCESS' in out[0]: @@ -246,10 +246,10 @@ def setUp(self): self.flagfile = os.path.join(self.tmp_dir, 'osquery.flags') # Write out our mock configuration files - with open(self.config_path, 'wb') as fd: + with open(self.config_path, 'w') as fd: fd.write(CONFIG_FILE) - with open(self.flagfile, 'wb') as fd: + with open(self.flagfile, 'w') as fd: fd.write( FLAGS_FILE.format(self.log_path, self.pidfile, test_http_server.HTTP_SERVER_CA, From acc2bd31f2ed31cd7f9c7b49b24b7465ff0c1b66 Mon Sep 17 00:00:00 2001 From: "flamingo[bot]" <277372822+flamingo[bot]@users.noreply.github.com> Date: Mon, 5 Oct 2026 05:15:13 +0000 Subject: [PATCH 03/11] fix(adhoc-sweep-fixes): 11 review findings across 11 files --- plugins/database/rocksdb.cpp | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/plugins/database/rocksdb.cpp b/plugins/database/rocksdb.cpp index 1f5419cd69d..ce735f9e9a5 100644 --- a/plugins/database/rocksdb.cpp +++ b/plugins/database/rocksdb.cpp @@ -426,9 +426,6 @@ Status RocksDBDatabasePlugin::removeRange(const std::string& domain, options.sync = false; } auto s = getDB()->DeleteRange(options, cfh, low, high); - if (low <= high) { - s = getDB()->Delete(options, cfh, high); - } return Status(s.code(), s.ToString()); } @@ -466,3 +463,4 @@ Status RocksDBDatabasePlugin::scan(const std::string& domain, return Status::success(); } } // namespace osquery + From a03cb4583301d7e2fc89f0f09e718802423ca451 Mon Sep 17 00:00:00 2001 From: "flamingo[bot]" <277372822+flamingo[bot]@users.noreply.github.com> Date: Mon, 5 Oct 2026 05:15:14 +0000 Subject: [PATCH 04/11] fix(adhoc-sweep-fixes): 11 review findings across 11 files --- osquery/events/windows/windowseventlogpublisher.cpp | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/osquery/events/windows/windowseventlogpublisher.cpp b/osquery/events/windows/windowseventlogpublisher.cpp index b76b479446c..a1bcab2f35a 100644 --- a/osquery/events/windows/windowseventlogpublisher.cpp +++ b/osquery/events/windows/windowseventlogpublisher.cpp @@ -208,6 +208,10 @@ double WindowsEventLogPublisher::cosineSimilarity( std::vector buffer_freqs(kCharFreqVectorLen, 0.0); auto buffer_size = buffer.size(); + if (buffer_size == 0) { + return 0.0; + } + for (unsigned char chr : buffer) { if (chr < kCharFreqVectorLen) { buffer_freqs[chr] += 1.0 / buffer_size; @@ -227,6 +231,10 @@ double WindowsEventLogPublisher::cosineSimilarity( mag1 = std::sqrt(mag1); mag2 = std::sqrt(mag2); + if (mag1 * mag2 == 0.0) { + return 0.0; + } + return dot / (mag1 * mag2); } From 03230fc6c77e59be6e5ee37c3f16e58c475643b2 Mon Sep 17 00:00:00 2001 From: "flamingo[bot]" <277372822+flamingo[bot]@users.noreply.github.com> Date: Mon, 5 Oct 2026 05:15:16 +0000 Subject: [PATCH 05/11] fix(adhoc-sweep-fixes): 11 review findings across 11 files --- osquery/events/darwin/diskarbitration.cpp | 1 + 1 file changed, 1 insertion(+) diff --git a/osquery/events/darwin/diskarbitration.cpp b/osquery/events/darwin/diskarbitration.cpp index 5ffd9b60b33..c590278c14c 100644 --- a/osquery/events/darwin/diskarbitration.cpp +++ b/osquery/events/darwin/diskarbitration.cpp @@ -269,3 +269,4 @@ std::string DiskArbitrationEventPublisher::getProperty( return ""; } } // namespace osquery + From 4db13d466d3e2096f1afe7f4b278d26bfd1cb44f Mon Sep 17 00:00:00 2001 From: "flamingo[bot]" <277372822+flamingo[bot]@users.noreply.github.com> Date: Mon, 5 Oct 2026 05:15:17 +0000 Subject: [PATCH 06/11] fix(adhoc-sweep-fixes): 11 review findings across 11 files --- osquery/utils/pidfile/pidfile_windows.cpp | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/osquery/utils/pidfile/pidfile_windows.cpp b/osquery/utils/pidfile/pidfile_windows.cpp index 015d05c4def..7781940ef5b 100644 --- a/osquery/utils/pidfile/pidfile_windows.cpp +++ b/osquery/utils/pidfile/pidfile_windows.cpp @@ -146,7 +146,7 @@ Expected Pidfile::readFile( auto remaining_bytes = buffer.size(); - for (int retry = 0; retry < 5; ++retry) { + for (int retry = 0; retry < 5 && remaining_bytes > 0; ++retry) { auto buffer_ptr = buffer.data() + buffer.size() - remaining_bytes; DWORD bytes_read{}; @@ -161,6 +161,10 @@ Expected Pidfile::readFile( remaining_bytes -= static_cast(bytes_read); } + if (remaining_bytes != 0) { + return createError(Pidfile::Error::IOError); + } + return buffer; } @@ -173,3 +177,4 @@ void Pidfile::destroyFile(FileHandle file_handle, const std::string&) noexcept { } } // namespace osquery + From 0c04b2d76fa4d38c31607f929c218bb09fb55232 Mon Sep 17 00:00:00 2001 From: "flamingo[bot]" <277372822+flamingo[bot]@users.noreply.github.com> Date: Mon, 5 Oct 2026 05:15:18 +0000 Subject: [PATCH 07/11] fix(adhoc-sweep-fixes): 11 review findings across 11 files --- plugins/logger/windows_event_log.cpp | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/plugins/logger/windows_event_log.cpp b/plugins/logger/windows_event_log.cpp index 8897f3f53f0..b863a2c8d04 100644 --- a/plugins/logger/windows_event_log.cpp +++ b/plugins/logger/windows_event_log.cpp @@ -64,7 +64,10 @@ void WindowsEventLoggerPlugin::init(const std::string& name, return; } - logStatus(log); + auto log_status = logStatus(log); + if (!log_status.ok()) { + LOG(ERROR) << log_status.getMessage(); + } } Status WindowsEventLoggerPlugin::acquireHandle(REGHANDLE& registration_handle) { @@ -141,3 +144,4 @@ Status WindowsEventLoggerPlugin::emitLogRecord( return Status(); } } // namespace osquery + From a122a067f30ba4f2484842076646da5a48030327 Mon Sep 17 00:00:00 2001 From: "flamingo[bot]" <277372822+flamingo[bot]@users.noreply.github.com> Date: Mon, 5 Oct 2026 05:15:19 +0000 Subject: [PATCH 08/11] fix(adhoc-sweep-fixes): 11 review findings across 11 files --- osquery/tables/system/linux/md_tables.cpp | 28 +++++++++++++++++++---- 1 file changed, 23 insertions(+), 5 deletions(-) diff --git a/osquery/tables/system/linux/md_tables.cpp b/osquery/tables/system/linux/md_tables.cpp index 63faa5d2bde..e0bea408016 100644 --- a/osquery/tables/system/linux/md_tables.cpp +++ b/osquery/tables/system/linux/md_tables.cpp @@ -121,9 +121,11 @@ std::string MD::getPathByDevName(const std::string& name) { std::string devPath; walkUdevDevices("block", [&](udev_device* const& device) { - auto const devName = std::string( - udev_device_get_property_value(device, "DEVNAME") - ); + const char* devNamePtr = udev_device_get_property_value(device, "DEVNAME"); + if (devNamePtr == nullptr) { + return false; + } + auto const devName = std::string(devNamePtr); if (boost::ends_with(devName, name)) { if (!boost::starts_with(devPath, "/")) { devPath = "/dev/" + devPath; @@ -146,8 +148,15 @@ std::string MD::getDevName(int major, int minor) { const char* devMajor = udev_device_get_property_value(device, "MAJOR"); const char* devMinor = udev_device_get_property_value(device, "MINOR"); + if (devMajor == nullptr || devMinor == nullptr) { + return false; + } + if (std::stoi(devMajor) == major && std::stoi(devMinor) == minor) { - devName = udev_device_get_property_value(device, "DEVNAME"); + const char* name = udev_device_get_property_value(device, "DEVNAME"); + if (name != nullptr) { + devName = name; + } return true; } @@ -163,10 +172,18 @@ std::string MD::getSuperblkVersion(const std::string& arrayName) { walkUdevDevices("block", [&](udev_device* const& device) { const char* devName = udev_device_get_property_value(device, "DEVNAME"); + if (devName == nullptr) { + return false; + } + if (arrayName.compare(strlen(devName) - arrayName.length(), std::string::npos, devName) == 0) { - version = udev_device_get_property_value(device, "MD_METADATA"); + const char* metadata = + udev_device_get_property_value(device, "MD_METADATA"); + if (metadata != nullptr) { + version = metadata; + } return true; } @@ -785,3 +802,4 @@ QueryData genMDPersonalities(QueryContext& context) { } } // namespace tables } // namespace osquery + From b24915d5cdf7b8117c3e109b983b6c91c8eff7b0 Mon Sep 17 00:00:00 2001 From: "flamingo[bot]" <277372822+flamingo[bot]@users.noreply.github.com> Date: Mon, 5 Oct 2026 05:15:20 +0000 Subject: [PATCH 09/11] fix(adhoc-sweep-fixes): 11 review findings across 11 files --- osquery/tables/applications/posix/carbon_black.cpp | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/osquery/tables/applications/posix/carbon_black.cpp b/osquery/tables/applications/posix/carbon_black.cpp index 52586cf8005..db705732e83 100644 --- a/osquery/tables/applications/posix/carbon_black.cpp +++ b/osquery/tables/applications/posix/carbon_black.cpp @@ -92,7 +92,6 @@ void getSensorSettings(Row& r) { boost::replace_all(server, "%3A", ":"); r["sensor_backend_server"] = SQL_TEXT(server); r["collect_data_file_writes"] = INTEGER(0); - r["collect_processes"] = INTEGER(0); r["collect_sensor_operations"] = INTEGER(0); r["log_file_disk_quota_mb"] = INTEGER(0); r["log_file_disk_quota_percentage"] = INTEGER(0); @@ -135,3 +134,4 @@ QueryData genCarbonBlackInfo(QueryContext& context) { } } // namespace tables } // namespace osquery + From e229099f7480f19529203e3455fb1f293ab42aed Mon Sep 17 00:00:00 2001 From: "flamingo[bot]" <277372822+flamingo[bot]@users.noreply.github.com> Date: Mon, 5 Oct 2026 05:15:21 +0000 Subject: [PATCH 10/11] fix(adhoc-sweep-fixes): 11 review findings across 11 files --- osquery/events/eventsubscriberplugin.cpp | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/osquery/events/eventsubscriberplugin.cpp b/osquery/events/eventsubscriberplugin.cpp index 6e9e5d8f99b..54df62b010c 100644 --- a/osquery/events/eventsubscriberplugin.cpp +++ b/osquery/events/eventsubscriberplugin.cpp @@ -123,7 +123,6 @@ Status EventSubscriberPlugin::addBatch(std::vector& row_list, for (auto& row : row_list) { auto event_identifier = getEventID(); - event_id_list.push_back(event_identifier); auto string_event_identifier = toIndex(event_identifier); @@ -138,6 +137,11 @@ Status EventSubscriberPlugin::addBatch(std::vector& row_list, continue; } + // Only commit the event id to the index once its row data has been + // successfully serialized, so that the index never references a row + // that was never stored. + event_id_list.push_back(event_identifier); + // Then remove the newline. if (serialized_row.size() > 0 && serialized_row.back() == '\n') { serialized_row.pop_back(); From 6e5769154ec95abd6e449563bd2cd918bcbfff42 Mon Sep 17 00:00:00 2001 From: "flamingo[bot]" <277372822+flamingo[bot]@users.noreply.github.com> Date: Mon, 5 Oct 2026 05:15:22 +0000 Subject: [PATCH 11/11] fix(adhoc-sweep-fixes): 11 review findings across 11 files --- osquery/utils/system/uptime.cpp | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/osquery/utils/system/uptime.cpp b/osquery/utils/system/uptime.cpp index c29c6da9550..5a2317c0fb2 100644 --- a/osquery/utils/system/uptime.cpp +++ b/osquery/utils/system/uptime.cpp @@ -22,7 +22,7 @@ namespace osquery { long getUptime() { -#if defined(DARWIN) +#if defined(__APPLE__) struct timeval boot_time; size_t len = sizeof(boot_time); int mib[2] = {CTL_KERN, KERN_BOOTTIME}; @@ -51,3 +51,4 @@ long getUptime() { } } // namespace osquery +