<#22 Native install and uninstall of osquery via o...
# osctrl
g
#22 Native install and uninstall of osquery via osctrld Pull request opened by javuto Native install and uninstall Ports the osctrl quick-add and quick-remove scripts into Go.
osctrld install
does natively what the shell/PowerShell scripts do — installs osquery when missing or outdated, writes the secret, flags and certificate, then starts and enables the service.
osctrld uninstall
reverses the configuration and deliberately leaves osquery installed, matching the remove script.
enroll
and
remove
are unchanged — they still print scripts to stdout. Design decisions • One server round-trip.
retrieveVerify
already returns flags, certificate and required version together, so
install
needs no extra calls. • Verified downloads. The osquery package is refused unless a SHA-256 is available. The digest is resolved server-field-first, then from `--osquery-sha256`; without either,
--allow-unverified
is required.
VerifyResponse
carries an
osquery_sha256
field that today's osctrl doesn't send yet — once it does, every node starts verifying with no client change. • No privilege escalation. osctrld never calls
sudo
. It requires existing root (or Administrator) and fails fast before any network or filesystem work. • Never downgrade. A node running newer osquery than required is left alone, matching the script's deliberate behavior. • Platform commands run through a single
execCommand
seam, so tests never invoke
dpkg
,
systemctl
or
msiexec
. Windows Gains real service control via
<http://golang.org/x/sys/windows/svc/mgr|golang.org/x/sys/windows/svc/mgr>
, replacing the previous "unsupported on windows" error for `install`/`uninstall`. Two limitations are documented rather than hidden: osctrld does not create the
osqueryd
service (it relies on the MSI having registered it), and the
service
daemon's restart path still has no Windows case —
osqueryRestartCommand
is unchanged, so daemon mode syncs files but leaves osquery on the old configuration. Wiring that up is a small follow-up now that the service-manager pieces exist. Not ported deliberately: FreeBSD, the PowerShell ACL hardening (the MSI already sets those permissions and osctrld writes only config files), machine
PATH
modification, and the service delete-and-recreate dance. Notable fix along the way
writeContentExists
only applied its file mode at creation — `os.WriteFile`'s perm is ignored for an existing file. A node enrolled by the quick-add script has its secret at
0644
, so
install
would have reported success while leaving the enrollment credential world-readable. The mode is now enforced on every path, including the unchanged-content early return, so a re-run repairs a stale mode. jmpsec/osctrld