Skip to content

fix(OSQUERY-002-2): CU-86aknprfh getSystemBootTime/getProcUptimeContents throw std::runtime_error instead of returning Status - #109

Draft
flamingo[bot] wants to merge 1 commit into
masterfrom
ai-fix/osquery-002-2-d3495ba3-116a6ce1
Draft

flamingo[bot] wants to merge 1 commit into
masterfrom
ai-fix/osquery-002-2-d3495ba3-116a6ce1

Conversation

@flamingo

@flamingo flamingo Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Closes findings from rule OSQUERY-002-2 — getSystemBootTime/getProcUptimeContents throw std::runtime_error instead of returning Status.

Draft — this is a starting point, not a finished change. The fix required judgment, so read it before trusting it.

# Fix confidence Finding Location
1 🟡 85 medium getSystemBootTime/getProcUptimeContents throw std::runtime_error instead of returning Status osquery/experimental/experiments/linuxevents/src/bpfprocesseventstable.cpp:37

What changed — and what was deliberately left — is explained per finding as inline review comments on the lines each finding touched.


Run: https://product-hub.flamingo.so/admin/code-review
Run id: 116a6ce1-ae2a-4217-a4a6-046396b5281c

Merging this PR is recorded as acceptance of the rule that produced it;
closing it unmerged is recorded as rejection. Both feed rule health, so
closing a wrong suggestion is useful rather than merely tidy.

ClickUp task: CU-86aknprfh Osquery review findings sweep (14 PRs)

@flamingo flamingo Bot left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🦩 What this fix changed, finding by finding

1 finding(s) fixed in this draft — 1 explained inline on the diff.

Status getProcUptimeContents(std::string& uptime_contents) {
uptime_contents.clear();

{

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🦩 🔴 getSystemBootTime/getProcUptimeContents throw std::runtime_error instead of returning Status

Changed getProcUptimeContents() and getSystemBootTime() in the anonymous namespace (bpfprocesseventstable.cpp) from throwing std::runtime_error to returning osquery::Status, with the computed value passed back via an output reference parameter. Updated the sole caller, BPFProcessEventsTable::generate(), to check the returned Status and return an empty TableRows on failure instead of letting an exception propagate out of the table generator. This removes the only two throw sites tied to this finding within the file; no other code path in this file now relies on exceptions for these failure cases.

🤖 Prompt for AI agents
In osquery/experimental/experiments/linuxevents/src/bpfprocesseventstable.cpp around line 37, review and complete this code-review fix: getSystemBootTime/getProcUptimeContents throw std::runtime_error instead of returning Status.
What the draft fix changed: Changed `getProcUptimeContents()` and `getSystemBootTime()` in the anonymous namespace (bpfprocesseventstable.cpp) from throwing `std::runtime_error` to returning `osquery::Status`, with the computed value passed back via an output reference parameter. Updated the sole caller, `BPFProcessEventsTable::generate()`, to check the returned `Status` and return an empty `TableRows` on failure instead of letting an exception propagate out of the table generator. This removes the only two throw sites tied to this finding within the file; no other code path in this file now relies on exceptions for these failure cases.
Verify the change is correct and complete; do not refactor unrelated code.

fix confidence: 🟡 85 medium — react 👍/👎 to teach the reviewer

@flamingo flamingo Bot changed the title fix(OSQUERY-002-2): getSystemBootTime/getProcUptimeContents throw std::runtime_error instead of returning Status fix(OSQUERY-002-2): CU-86aknprfh getSystemBootTime/getProcUptimeContents throw std::runtime_error instead of returning Status Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants