Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion osquery/events/darwin/openbsm.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -47,7 +47,7 @@ Status OpenBSMEventPublisher::configureAuditPipe() {
}

if (ioctl(au_fd, AUDITPIPE_SET_QLIMIT, &kQLimit) == -1) {

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🦩 🟠 openbsm.cpp uses LOG(INFO) for a failure condition that should be a warning

In OpenBSMEventPublisher::configureAuditPipe, changed the LOG(INFO) call logging the AUDITPIPE_SET_QLIMIT ioctl failure to LOG(WARNING), matching the severity used for the adjacent AUDITPIPE_SET_PRESELECT_MODE, AUDITPIPE_SET_PRESELECT_FLAGS, and AUDITPIPE_SET_PRESELECT_NAFLAGS ioctl failure logs.

πŸ€– Prompt for AI agents
In osquery/events/darwin/openbsm.cpp around line 49, review and complete this code-review fix: openbsm.cpp uses LOG(INFO) for a failure condition that should be a warning.
What the draft fix changed: In `OpenBSMEventPublisher::configureAuditPipe`, changed the `LOG(INFO)` call logging the `AUDITPIPE_SET_QLIMIT` ioctl failure to `LOG(WARNING)`, matching the severity used for the adjacent `AUDITPIPE_SET_PRESELECT_MODE`, `AUDITPIPE_SET_PRESELECT_FLAGS`, and `AUDITPIPE_SET_PRESELECT_NAFLAGS` ioctl failure logs.
Verify the change is correct and complete; do not refactor unrelated code.

fix confidence: 🟒 95 high β€” react πŸ‘/πŸ‘Ž to teach the reviewer

LOG(INFO) << "The auditpipe:ioctl AUDITPIPE_SET_QLIMIT failed";
LOG(WARNING) << "The auditpipe:ioctl AUDITPIPE_SET_QLIMIT failed";
}

au_mask_t pr_flags = {0, 0};
Expand Down
4 changes: 3 additions & 1 deletion osquery/events/windows/etw/etw_user_session.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -176,6 +176,8 @@ void UserEtwSessionRunnable::initUserTraceSession(
void UserEtwSessionRunnable::stopUserTraceSession(

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🦩 🟠 stopUserTraceSession silently returns on empty session name without logging

Added LOG(ERROR) << "Failed to stop user trace session - session does not have a name."; inside the empty-sessionName early return in UserEtwSessionRunnable::stopUserTraceSession, matching the suggested fix and the kernel-session counterpart's logging behavior.

πŸ€– Prompt for AI agents
In osquery/events/windows/etw/etw_user_session.cpp around line 176, review and complete this code-review fix: stopUserTraceSession silently returns on empty session name without logging.
What the draft fix changed: Added `LOG(ERROR) << "Failed to stop user trace session - session does not have a name.";` inside the empty-sessionName early return in `UserEtwSessionRunnable::stopUserTraceSession`, matching the suggested fix and the kernel-session counterpart's logging behavior.
Verify the change is correct and complete; do not refactor unrelated code.

fix confidence: 🟒 95 high β€” react πŸ‘/πŸ‘Ž to teach the reviewer

const std::string& sessionName) {
if (sessionName.empty()) {
LOG(ERROR) << "Failed to stop user trace session - session does not have "
"a name.";
return;
}

Expand All @@ -201,4 +203,4 @@ void UserEtwSessionRunnable::stopUserTraceSession(
LOG(WARNING) << "ControlTrace() failed with error code " << retCtrl;
}
}
} // namespace osquery
} // namespace osquery
Loading