Skip to content
Draft
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -31,29 +31,36 @@ const std::vector<std::tuple<std::string, std::string>> kKnownCgroupPrefixList{
{"/libpod-", "podman"},
};

std::string getProcUptimeContents() {
std::string uptime_contents;
Status getProcUptimeContents(std::string& uptime_contents) {
uptime_contents.clear();

{

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🦩 🔴 getSystemBootTime/getProcUptimeContents throw std::runtime_error instead of returning Status

Changed getProcUptimeContents() and getSystemBootTime() in the anonymous namespace (bpfprocesseventstable.cpp) from throwing std::runtime_error to returning osquery::Status, with the computed value passed back via an output reference parameter. Updated the sole caller, BPFProcessEventsTable::generate(), to check the returned Status and return an empty TableRows on failure instead of letting an exception propagate out of the table generator. This removes the only two throw sites tied to this finding within the file; no other code path in this file now relies on exceptions for these failure cases.

🤖 Prompt for AI agents
In osquery/experimental/experiments/linuxevents/src/bpfprocesseventstable.cpp around line 37, review and complete this code-review fix: getSystemBootTime/getProcUptimeContents throw std::runtime_error instead of returning Status.
What the draft fix changed: Changed `getProcUptimeContents()` and `getSystemBootTime()` in the anonymous namespace (bpfprocesseventstable.cpp) from throwing `std::runtime_error` to returning `osquery::Status`, with the computed value passed back via an output reference parameter. Updated the sole caller, `BPFProcessEventsTable::generate()`, to check the returned `Status` and return an empty `TableRows` on failure instead of letting an exception propagate out of the table generator. This removes the only two throw sites tied to this finding within the file; no other code path in this file now relies on exceptions for these failure cases.
Verify the change is correct and complete; do not refactor unrelated code.

fix confidence: 🟡 85 medium — react 👍/👎 to teach the reviewer

std::ifstream uptime_file(kProcUptimeFilePath.c_str(), std::ios::in);
if (!uptime_file) {
throw std::runtime_error("Failed to access the following path: " +
kProcUptimeFilePath);
return Status::failure("Failed to access the following path: " +
kProcUptimeFilePath);
}

std::getline(uptime_file, uptime_contents);
}

return uptime_contents;
return Status::success();
}

std::uint64_t getSystemBootTime() {
Status getSystemBootTime(std::uint64_t& boot_time) {
boot_time = 0;

auto current_time = std::time(nullptr);
auto uptime_contents = getProcUptimeContents();

std::string uptime_contents;
auto status = getProcUptimeContents(uptime_contents);
if (!status.ok()) {
return status;
}

auto separator_index = uptime_contents.find('.');
if (separator_index == std::string::npos) {
throw std::runtime_error("Invalid data read from " + kProcUptimeFilePath);
return Status::failure("Invalid data read from " + kProcUptimeFilePath);
}

auto string_uptime = uptime_contents.substr(0, separator_index);
Expand All @@ -63,10 +70,11 @@ std::uint64_t getSystemBootTime() {
std::strtoull(string_uptime.c_str(), &last_parsed_char, 10);
if (integer_uptime == 0 || last_parsed_char == nullptr ||
*last_parsed_char != 0) {
throw std::runtime_error("Invalid data read from " + kProcUptimeFilePath);
return Status::failure("Invalid data read from " + kProcUptimeFilePath);
}

return current_time - integer_uptime;
boot_time = current_time - integer_uptime;
return Status::success();
}

} // namespace
Expand Down Expand Up @@ -131,7 +139,11 @@ TableRows BPFProcessEventsTable::generate(QueryContext& context) {
TableRows row_list;
std::stringstream buffer;

auto system_boot_time = getSystemBootTime();
std::uint64_t system_boot_time{0U};
auto status = getSystemBootTime(system_boot_time);
if (!status.ok()) {
return row_list;
}

for (const auto& event : d->event_list) {
auto row = make_table_row();
Expand Down Expand Up @@ -214,4 +226,4 @@ TableRows BPFProcessEventsTable::generate(QueryContext& context) {
return row_list;
}

} // namespace osquery
} // namespace osquery
Loading