Repository navigation
fix(OSQUERY-003): CU-86akhf8u2 genSudoersFile ignores unchecked substr/at() calls on possibly malformed sudoers lines - #76
Conversation
…on possibly malformed sudoers lines
| @@ -117,11 +117,16 @@ void genSudoersFile(const std::string& filename, | |||
|
|
|||
| if (is_includedir) { | |||
There was a problem hiding this comment.
🦩 🔴 genSudoersFile ignores unchecked substr/at() calls on possibly malformed sudoers lines
In genSudoersFile (osquery/tables/system/posix/sudoers.cpp), the two rule_details.at(0) calls under the is_includedir and is_include branches are now guarded with !rule_details.empty() before indexing, and an explicit empty-string check (with a TLOG message and continue) was added right after each path-normalization block to avoid passing an empty string into listFilesInDirectory/recursive genSudoersFile calls. This removes the possibility of an uncaught std::out_of_range from .at(0) on a malformed/empty rule_details value while preserving existing control flow and style.
🤖 Prompt for AI agents
In osquery/tables/system/posix/sudoers.cpp around line 118, review and complete this code-review fix: genSudoersFile ignores unchecked substr/at() calls on possibly malformed sudoers lines.
What the draft fix changed: In genSudoersFile (osquery/tables/system/posix/sudoers.cpp), the two `rule_details.at(0)` calls under the `is_includedir` and `is_include` branches are now guarded with `!rule_details.empty()` before indexing, and an explicit empty-string check (with a TLOG message and `continue`) was added right after each path-normalization block to avoid passing an empty string into `listFilesInDirectory`/recursive `genSudoersFile` calls. This removes the possibility of an uncaught `std::out_of_range` from `.at(0)` on a malformed/empty rule_details value while preserving existing control flow and style.
Verify the change is correct and complete; do not refactor unrelated code.
fix confidence: 🟡 85 medium — react 👍/👎 to teach the reviewer
Closes findings from rule OSQUERY-003 — genSudoersFile ignores unchecked substr/at() calls on possibly malformed sudoers lines.
Draft — this is a starting point, not a finished change. The fix required judgment, so read it before trusting it.
osquery/tables/system/posix/sudoers.cpp:118What changed — and what was deliberately left — is explained per finding as inline review comments on the lines each finding touched.
Run: https://product-hub.flamingo.so/admin/code-review
Run id:
39233833-f1d6-416e-93a7-71af15e3e968Merging this PR is recorded as acceptance of the rule that produced it;
closing it unmerged is recorded as rejection. Both feed rule health, so
closing a wrong suggestion is useful rather than merely tidy.
ClickUp task: CU-86akhf8u2 Osquery review findings sweep (15 PRs)