Repository navigation
fix(OSQUERY-004): CU-86akhf8u2 2 review findings across 2 files - #78
flamingo[bot] wants to merge 2 commits into
Conversation
| @@ -47,7 +47,7 @@ Status OpenBSMEventPublisher::configureAuditPipe() { | |||
| } | |||
|
|
|||
| if (ioctl(au_fd, AUDITPIPE_SET_QLIMIT, &kQLimit) == -1) { | |||
There was a problem hiding this comment.
🦩 🟠 openbsm.cpp uses LOG(INFO) for a failure condition that should be a warning
In OpenBSMEventPublisher::configureAuditPipe, changed the LOG(INFO) call logging the AUDITPIPE_SET_QLIMIT ioctl failure to LOG(WARNING), matching the severity used for the adjacent AUDITPIPE_SET_PRESELECT_MODE, AUDITPIPE_SET_PRESELECT_FLAGS, and AUDITPIPE_SET_PRESELECT_NAFLAGS ioctl failure logs.
🤖 Prompt for AI agents
In osquery/events/darwin/openbsm.cpp around line 49, review and complete this code-review fix: openbsm.cpp uses LOG(INFO) for a failure condition that should be a warning.
What the draft fix changed: In `OpenBSMEventPublisher::configureAuditPipe`, changed the `LOG(INFO)` call logging the `AUDITPIPE_SET_QLIMIT` ioctl failure to `LOG(WARNING)`, matching the severity used for the adjacent `AUDITPIPE_SET_PRESELECT_MODE`, `AUDITPIPE_SET_PRESELECT_FLAGS`, and `AUDITPIPE_SET_PRESELECT_NAFLAGS` ioctl failure logs.
Verify the change is correct and complete; do not refactor unrelated code.
fix confidence: 🟢 95 high — react 👍/👎 to teach the reviewer
| @@ -176,6 +176,8 @@ void UserEtwSessionRunnable::initUserTraceSession( | |||
| void UserEtwSessionRunnable::stopUserTraceSession( | |||
There was a problem hiding this comment.
🦩 🟠 stopUserTraceSession silently returns on empty session name without logging
Added LOG(ERROR) << "Failed to stop user trace session - session does not have a name."; inside the empty-sessionName early return in UserEtwSessionRunnable::stopUserTraceSession, matching the suggested fix and the kernel-session counterpart's logging behavior.
🤖 Prompt for AI agents
In osquery/events/windows/etw/etw_user_session.cpp around line 176, review and complete this code-review fix: stopUserTraceSession silently returns on empty session name without logging.
What the draft fix changed: Added `LOG(ERROR) << "Failed to stop user trace session - session does not have a name.";` inside the empty-sessionName early return in `UserEtwSessionRunnable::stopUserTraceSession`, matching the suggested fix and the kernel-session counterpart's logging behavior.
Verify the change is correct and complete; do not refactor unrelated code.
fix confidence: 🟢 95 high — react 👍/👎 to teach the reviewer
Closes 2 review findings across 2 files.
Draft — this is a starting point, not a finished change. The fix required judgment, so read it before trusting it.
osquery/events/darwin/openbsm.cpp:49osquery/events/windows/etw/etw_user_session.cpp:176What changed — and what was deliberately left — is explained per finding as inline review comments on the lines each finding touched.
Run: https://product-hub.flamingo.so/admin/code-review
Run id:
39233833-f1d6-416e-93a7-71af15e3e968Merging this PR is recorded as acceptance of the rule that produced it;
closing it unmerged is recorded as rejection. Both feed rule health, so
closing a wrong suggestion is useful rather than merely tidy.
ClickUp task: CU-86akhf8u2 Osquery review findings sweep (15 PRs)