Skip to content

fix(windows): report the WMI error code and warn on an empty os_version - #111

Merged
mikhailm-coder merged 1 commit into
masterfrom
hotfix/wmi-startup-diagnostics
Oct 5, 2026
Merged

mikhailm-coder merged 1 commit into
masterfrom
hotfix/wmi-startup-diagnostics

Conversation

@mikhailm-coder

@mikhailm-coder mikhailm-coder commented Oct 5, 2026 •

Copy link
Copy Markdown

CU-86akqy70q

Change-Set: wmi-startup-diagnostics

Problem

On a Windows host where WMI is broken, orbit's startup host-info query (system_info, os_version, osquery_info) comes back empty and orbit exits with get UUID: invalid number of rows from system info query: 0. os_version is the table that returns no row, and osquery gives no usable reason for it:

  • A failed WMI request is logged without the Windows error code (WmiRequest creation failed to connect to server).
  • If the request is accepted but reading the results fails, CreateWmiRequest drops the Next() HRESULT and returns a successful request with zero results. os_version then returns empty without logging anything.

So the cause could only be found with a live look at the machine.

Change

Where Change
wmi.cpp CreateWmiRequest The six failure messages that have an HRESULT now end with it, e.g. WmiRequest creation failed to connect to server: 0x800706ba. The three allocation failures have no code and are unchanged.
wmi.cpp, wmi.h The HRESULT that ends the Next() loop is kept and exposed as getEnumerationResult().
os_version.cpp An empty result now warns: WMI query on Win32_OperatingSystem failed while reading results: 0x... when the enumeration failed, ... returned no results otherwise.

Logging only: no table output and no control flow changes. The other WMI helpers (property getters, ExecMethod) are deliberately left alone. They are not on this failure path, and every touched line is merge surface against upstream.

The orbit side, which puts osqueryd's stderr into the startup error, is the sibling PR flamingo-stack/fleetmdm#232. Neither PR needs the other merged first.

Testing

  • Not built with MSVC locally. Both changed translation units pass a syntax and type check with MinGW-w64 g++ against the vendored headers; the Windows CI build is the real compile.
  • No unit test added: this fork's CI builds osquery without its test targets, so a test here would not be compiled or run.
  • Not yet exercised on a host with broken WMI.

🤖 Generated with Claude Code

Change set flamingo-stack/wmi-startup-diagnostics: these pull requests are one change, reviewed together.

Linked work

Linked by the Depends-On / Change-Set lines in these descriptions; this block is maintained by the hub.

CreateWmiRequest failures now end with the HRESULT, and the code that ends
the result enumeration is kept instead of being dropped. os_version warns
when its Win32_OperatingSystem query returns nothing, with that code when
reading the results failed.

Logging only, no table output or control flow changes.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@mikhailm-coder

Copy link
Copy Markdown
Author

@flamingo-review

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

🦩 Flamingo Code Review

✅ No findings on the current head.

Advisory: findings do not block the merge.


Review again. New commits are not reviewed until you ask:

  • Review the new commits: only what was pushed since this review
  • Review the whole diff again: everything, including what was already reviewed

Or comment @flamingo-review (new commits) or @flamingo-review full (everything). Add the flamingo-review-always label to review every push.

Started 2026-10-05 17:41 UTC · updated 2026-10-05 17:43 UTC · workflow run

@mikhailm-coder
mikhailm-coder merged commit 4d991ff into master Oct 5, 2026
18 checks passed
@mikhailm-coder
mikhailm-coder deleted the hotfix/wmi-startup-diagnostics branch October 5, 2026 21:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants