OP#785 add control for clamd service config file

This commit is contained in:
2026-09-22 13:37:25 +02:00
parent 905676c71a
commit 66173a7573
4 changed files with 42 additions and 1 deletions

View File

@@ -33,7 +33,7 @@
- manage required config files - manage required config files
- manage cronjob settings via parameters - manage cronjob settings via parameters
- run cron job to scan the file system (by default starting at root, configurable) via clamdscan - run cron job to scan the file system (by default starting at root, configurable) via clamdscan
- set ConcurrentDatabaseReload option yes/no to optimize RAM consumption - set ConcurrentDatabaseReload option `yes`/`no` to optimize RAM consumption. defaults to `no`
- manage services - manage services
## Dependencies ## Dependencies

View File

@@ -33,6 +33,7 @@ class confdroid_clamav::main::files (
seltype => etc_t, seltype => etc_t,
seluser => system_u, seluser => system_u,
content => template($cv_freshclam_erb), content => template($cv_freshclam_erb),
notify => Service[$cv_freshclam],
} }
# freshclam service config file # freshclam service config file
@@ -46,6 +47,21 @@ class confdroid_clamav::main::files (
seltype => etc_t, seltype => etc_t,
seluser => system_u, seluser => system_u,
content => template($cv_freshclam_svc_erb), content => template($cv_freshclam_svc_erb),
notify => Service[$cv_freshclam],
}
# clamd service config file
file { $cv_clamd_svc :
ensure => file,
owner => 'root',
group => 'root',
mode => '0600',
selrange => s0,
selrole => object_r,
seltype => etc_t,
seluser => system_u,
content => template($cv_clamd_svc_erb),
notify => Service[$cv_service],
} }
# shell script for scanning and alerting # shell script for scanning and alerting

View File

@@ -36,6 +36,10 @@
# @param [Boolean] cv_enable_freshclam whether to enable the freshclam service # @param [Boolean] cv_enable_freshclam whether to enable the freshclam service
# @param [Boolean] cv_enable_clamd whether to enable the clamd service # @param [Boolean] cv_enable_clamd whether to enable the clamd service
# @param [Boolean] cv_use_excludepaths whether to use advanced exclude paths # @param [Boolean] cv_use_excludepaths whether to use advanced exclude paths
# @param [String] cv_concurrentdatabasereload whether to enable concurrent
# database reloads. This is useful when you have multiple clamd instances
# running on the same machine. If you have only one clamd instance, this
# should be set to 'no'.
############################################################################## ##############################################################################
class confdroid_clamav::params ( class confdroid_clamav::params (
@@ -83,6 +87,8 @@ class confdroid_clamav::params (
$cv_freshclam_erb = 'confdroid_clamav/freshclam_conf.erb' $cv_freshclam_erb = 'confdroid_clamav/freshclam_conf.erb'
$cv_freshclam_svc = '/usr/lib/systemd/system/freshclam.service' $cv_freshclam_svc = '/usr/lib/systemd/system/freshclam.service'
$cv_freshclam_svc_erb = 'confdroid_clamav/freshclam_svc.erb' $cv_freshclam_svc_erb = 'confdroid_clamav/freshclam_svc.erb'
$cv_clamd_svc = '/usr/lib/systemd/system/clamd@.service'
$cv_clamd_svc_erb = 'confdroid_clamav/clamd_svc.erb'
$cv_shell_script = "${cv_config_d_dir}/scan.sh" $cv_shell_script = "${cv_config_d_dir}/scan.sh"
$cv_shell_script_erb = 'confdroid_clamav/scan.sh.erb' $cv_shell_script_erb = 'confdroid_clamav/scan.sh.erb'

19
templates/clamd_svc.erb Normal file
View File

@@ -0,0 +1,19 @@
################################################################################
### clamd.svc created by Puppet, manual changes will be overwritten!!! ###
################################################################################
[Unit]
Description = clamd scanner (%i) daemon
Documentation=man:clamd(8) man:clamd.conf(5) https://www.clamav.net/documents/
After = syslog.target nss-lookup.target network.target
[Service]
Type = forking
ExecStart = /usr/sbin/clamd -c /etc/clamd.d/%i.conf
# Reload the database
ExecReload=/bin/kill -USR2 $MAINPID
Restart = on-failure
TimeoutStartSec=420
[Install]
WantedBy = multi-user.target