GitHub
09/12/2026, 6:57 PMosctrld install does natively what the shell/PowerShell scripts do — installs osquery when missing or outdated, writes the secret, flags and certificate, then starts and enables the service. osctrld uninstall reverses the configuration and deliberately leaves osquery installed, matching the remove script.
enroll and remove are unchanged — they still print scripts to stdout.
Design decisions
• One server round-trip. retrieveVerify already returns flags, certificate and required version together, so install needs no extra calls.
• Verified downloads. The osquery package is refused unless a SHA-256 is available. The digest is resolved server-field-first, then from `--osquery-sha256`; without either, --allow-unverified is required. VerifyResponse carries an osquery_sha256 field that today's osctrl doesn't send yet — once it does, every node starts verifying with no client change.
• No privilege escalation. osctrld never calls sudo. It requires existing root (or Administrator) and fails fast before any network or filesystem work.
• Never downgrade. A node running newer osquery than required is left alone, matching the script's deliberate behavior.
• Platform commands run through a single execCommand seam, so tests never invoke dpkg, systemctl or msiexec.
Windows
Gains real service control via <http://golang.org/x/sys/windows/svc/mgr|golang.org/x/sys/windows/svc/mgr>, replacing the previous "unsupported on windows" error for `install`/`uninstall`. Two limitations are documented rather than hidden: osctrld does not create the osqueryd service (it relies on the MSI having registered it), and the service daemon's restart path still has no Windows case — osqueryRestartCommand is unchanged, so daemon mode syncs files but leaves osquery on the old configuration. Wiring that up is a small follow-up now that the service-manager pieces exist.
Not ported deliberately: FreeBSD, the PowerShell ACL hardening (the MSI already sets those permissions and osctrld writes only config files), machine PATH modification, and the service delete-and-recreate dance.
Notable fix along the way
writeContentExists only applied its file mode at creation — `os.WriteFile`'s perm is ignored for an existing file. A node enrolled by the quick-add script has its secret at 0644, so install would have reported success while leaving the enrollment credential world-readable. The mode is now enforced on every path, including the unchanged-content early return, so a re-run repairs a stale mode.
jmpsec/osctrldGitHub
09/12/2026, 7:29 PM