Skip to content

fix(OSQUERY-004): CU-86akhf8u2 2 review findings across 2 files - #78

Draft
flamingo[bot] wants to merge 2 commits into
masterfrom
ai-fix/osquery-004-cf7bf070-39233833
Draft

flamingo[bot] wants to merge 2 commits into
masterfrom
ai-fix/osquery-004-cf7bf070-39233833

Conversation

@flamingo

@flamingo flamingo Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Closes 2 review findings across 2 files.

Draft — this is a starting point, not a finished change. The fix required judgment, so read it before trusting it.

# Fix confidence Finding Location
1 🟢 95 high openbsm.cpp uses LOG(INFO) for a failure condition that should be a warning osquery/events/darwin/openbsm.cpp:49
2 🟢 95 high stopUserTraceSession silently returns on empty session name without logging osquery/events/windows/etw/etw_user_session.cpp:176

What changed — and what was deliberately left — is explained per finding as inline review comments on the lines each finding touched.


Run: https://product-hub.flamingo.so/admin/code-review
Run id: 39233833-f1d6-416e-93a7-71af15e3e968

Merging this PR is recorded as acceptance of the rule that produced it;
closing it unmerged is recorded as rejection. Both feed rule health, so
closing a wrong suggestion is useful rather than merely tidy.

ClickUp task: CU-86akhf8u2 Osquery review findings sweep (15 PRs)

@flamingo flamingo Bot left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🦩 What this fix changed, finding by finding

2 finding(s) fixed in this draft — 2 explained inline on the diff.

@@ -47,7 +47,7 @@ Status OpenBSMEventPublisher::configureAuditPipe() {
}

if (ioctl(au_fd, AUDITPIPE_SET_QLIMIT, &kQLimit) == -1) {

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🦩 🟠 openbsm.cpp uses LOG(INFO) for a failure condition that should be a warning

In OpenBSMEventPublisher::configureAuditPipe, changed the LOG(INFO) call logging the AUDITPIPE_SET_QLIMIT ioctl failure to LOG(WARNING), matching the severity used for the adjacent AUDITPIPE_SET_PRESELECT_MODE, AUDITPIPE_SET_PRESELECT_FLAGS, and AUDITPIPE_SET_PRESELECT_NAFLAGS ioctl failure logs.

🤖 Prompt for AI agents
In osquery/events/darwin/openbsm.cpp around line 49, review and complete this code-review fix: openbsm.cpp uses LOG(INFO) for a failure condition that should be a warning.
What the draft fix changed: In `OpenBSMEventPublisher::configureAuditPipe`, changed the `LOG(INFO)` call logging the `AUDITPIPE_SET_QLIMIT` ioctl failure to `LOG(WARNING)`, matching the severity used for the adjacent `AUDITPIPE_SET_PRESELECT_MODE`, `AUDITPIPE_SET_PRESELECT_FLAGS`, and `AUDITPIPE_SET_PRESELECT_NAFLAGS` ioctl failure logs.
Verify the change is correct and complete; do not refactor unrelated code.

fix confidence: 🟢 95 high — react 👍/👎 to teach the reviewer

@@ -176,6 +176,8 @@ void UserEtwSessionRunnable::initUserTraceSession(
void UserEtwSessionRunnable::stopUserTraceSession(

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🦩 🟠 stopUserTraceSession silently returns on empty session name without logging

Added LOG(ERROR) << "Failed to stop user trace session - session does not have a name."; inside the empty-sessionName early return in UserEtwSessionRunnable::stopUserTraceSession, matching the suggested fix and the kernel-session counterpart's logging behavior.

🤖 Prompt for AI agents
In osquery/events/windows/etw/etw_user_session.cpp around line 176, review and complete this code-review fix: stopUserTraceSession silently returns on empty session name without logging.
What the draft fix changed: Added `LOG(ERROR) << "Failed to stop user trace session - session does not have a name.";` inside the empty-sessionName early return in `UserEtwSessionRunnable::stopUserTraceSession`, matching the suggested fix and the kernel-session counterpart's logging behavior.
Verify the change is correct and complete; do not refactor unrelated code.

fix confidence: 🟢 95 high — react 👍/👎 to teach the reviewer

@flamingo flamingo Bot changed the title fix(OSQUERY-004): 2 review findings across 2 files fix(OSQUERY-004): CU-86akhf8u2 2 review findings across 2 files Sep 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants