Skip to content

feat(codegen): CU-17tkuw5tebe publish release-bound osquery schemas - #104

Open
yevhenii-flamingo wants to merge 4 commits into
masterfrom
feat/remove-osquery-schema-refresh
Open

yevhenii-flamingo wants to merge 4 commits into
masterfrom
feat/remove-osquery-schema-refresh

Conversation

@yevhenii-flamingo

@yevhenii-flamingo yevhenii-flamingo commented Oct 2, 2026 •

Copy link
Copy Markdown

Ticket: https://app.clickup.com/t/9013925967/17tkuw5tebe
Change-Set: feat-remove-osquery-schema-refresh

Summary

  • Publish osquery-schema.json, its SHA-256 sidecar and binary archive checksums with each osquery release.
  • Generate platform/architecture-specific schema metadata from the same checkout and CMake-selected table specs as the released binaries.
  • Validate engine version, table/column registration and SQL aliases against each built executable before publishing the combined Darwin amd64, Darwin arm64 and Windows amd64 catalog.
  • Related changes: tenant #3650, Fleet #221, shared #2393.

Compatibility

  • Existing binary asset names, agent SQL execution, APIs, persisted data/events and frontend contracts are unchanged; release assets gain an additive versioned schema contract (formatVersion: 1).
  • The tenant AI service consumes the new catalog in tenant undefined symbol '__secure_getenv' when building osquery osquery/osquery#3650. Older osquery releases without schema assets cannot satisfy its enabled deployment validation.
  • Catalog provenance identifies the built release, not a verified installed device version; device rollout remains a separate operational responsibility.

Release risks

  • Merge this PR first and publish an osquery release containing the schema assets, then select that release in the feature tenant and run E2E before merging tenant undefined symbol '__secure_getenv' when building osquery osquery/osquery#3650.
  • Retire the Fleet/shared schema endpoint only after every consuming tenant environment has migrated to the new tenant implementation; do not deploy Fleet LSPCI virtual table osquery/osquery#221 or shared Windows: script to produce an osquery choco package osquery/osquery#2393 prematurely.
  • Schema export, binary/schema mismatch, incomplete build variants or checksum generation failures block release publication. No database migration or library release is required.
  • This PR does not automatically open tenant tag-update PRs. The selected osquery tag must be updated explicitly; the mutable latest prerelease does not prove installed device compatibility.
  • Full platform build and binary verification remain pending in CI. The local native build is blocked by unchanged Boost MPL failing with Apple Clang 21; a Windows build toolchain is unavailable on this Mac. All three CI platform builds, their binary/schema verification and All Checks must pass before merge or release.

Change set flamingo-stack/osquery#104: these pull requests are one change, reviewed together.

Merge order: #104 → flamingo-stack/fleetmdm#221

Linked work

Linked by the Depends-On / Change-Set lines in these descriptions; this block is maintained by the hub.

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

🦩 Flamingo Code Review

No findings on the current head.

Mode: advisory


Need another pass? Commits pushed after this review are not reviewed automatically.

  • Review the new commits — the commits added since this review
  • Review the whole diff again — ignoring what was already reviewed

Prefer typing? Comment @flamingo-review, or @flamingo-review full. To review every push on this pull request, add the flamingo-review-always label.

React 👍/👎 on inline comments to teach the reviewer.

Started 2026-10-02 18:48 UTC · updated 2026-10-02 18:51 UTC · workflow run

ivan-flamingo
ivan-flamingo previously approved these changes Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants