Skip to content

Native install and uninstall of osquery via osctrld - #22

Merged
javuto merged 1 commit into
developfrom
native-install
Sep 12, 2026
Merged

javuto merged 1 commit into
developfrom
native-install

Conversation

@javuto

@javuto javuto commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

Native install and uninstall

Ports the osctrl quick-add and quick-remove scripts into Go. osctrld install does natively what the shell/PowerShell scripts do — installs osquery when missing or outdated, writes the secret, flags and certificate, then starts and enables the service. osctrld uninstall reverses the configuration and deliberately leaves osquery installed, matching the remove script.

enroll and remove are unchanged — they still print scripts to stdout.

Design decisions

  • One server round-trip. retrieveVerify already returns flags, certificate and required version together, so install needs no extra calls.
  • Verified downloads. The osquery package is refused unless a SHA-256 is available. The digest is resolved server-field-first, then from --osquery-sha256; without either, --allow-unverified is required. VerifyResponse carries an osquery_sha256 field that today's osctrl doesn't send yet — once it does, every node starts verifying with no client change.
  • No privilege escalation. osctrld never calls sudo. It requires existing root (or Administrator) and fails fast before any network or filesystem work.
  • Never downgrade. A node running newer osquery than required is left alone, matching the script's deliberate behavior.
  • Platform commands run through a single execCommand seam, so tests never invoke dpkg, systemctl or msiexec.

Windows

Gains real service control via golang.org/x/sys/windows/svc/mgr, replacing the previous "unsupported on windows" error for install/uninstall. Two limitations are documented rather than hidden: osctrld does not create the osqueryd service (it relies on the MSI having registered it), and the service daemon's restart path still has no Windows case — osqueryRestartCommand is unchanged, so daemon mode syncs files but leaves osquery on the old configuration. Wiring that up is a small follow-up now that the service-manager pieces exist.

Not ported deliberately: FreeBSD, the PowerShell ACL hardening (the MSI already sets those permissions and osctrld writes only config files), machine PATH modification, and the service delete-and-recreate dance.

Notable fix along the way

writeContentExists only applied its file mode at creation — os.WriteFile's perm is ignored for an existing file. A node enrolled by the quick-add script has its secret at 0644, so install would have reported success while leaving the enrollment credential world-readable. The mode is now enforced on every path, including the unchanged-content early return, so a re-run repairs a stale mode.

@javuto javuto added the ✨ enhancement New feature or request label Sep 12, 2026
@javuto
javuto merged commit af3ca1b into develop Sep 12, 2026
2 checks passed
@javuto
javuto deleted the native-install branch September 12, 2026 19:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

✨ enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant