osquery / osquery/osquery-go

Constraints that are not `==` don't appear to be passed along

Open
#88 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Go
Stars
433
Forks
89
PR merge metrics
No merged PRs in 30d

Description

As pointed out on slack, it's not clear how to get a constraint that isn't ==

I added a spew to table.Call and I don't see the constraints coming in.

If I look at a trace in panic, I don't see much in between that, and the thrift layer.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start in plugin/table/table.go at table.Call and trace the request through the thrift layer, comparing how == and other constraints are represented. Confirm why non-== constraints are absent at table.Call and verify that the intended constraints reach it.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
backend
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.