OP#785 add excludepaths and option to use it

This commit is contained in:
2026-09-22 12:45:06 +02:00
parent 2d3304abac
commit 7f20c0e45e
4 changed files with 33 additions and 7 deletions

View File

@@ -14,11 +14,13 @@
"Dazuko",
"dbname",
"epel",
"excludepaths",
"fanotify",
"filesize",
"freshclam",
"getsebool",
"INADDR",
"kubelet",
"libclamav",
"logclean",
"logfacility",

View File

@@ -9,7 +9,7 @@ class confdroid_clamav::main::install (
) inherits confdroid_clamav::params {
require confdroid_resources::main::epel
package { $reqpackages:
ensure => $pkg_ensure,
package { $cv_reqpackages:
ensure => $cv_pkg_ensure,
}
}

View File

@@ -3,8 +3,8 @@
# Author: 12ww1160 (12ww1160@confdroid.com)
# @summary Class holds all parameters for the confdroid_clamav module and is
# inherited by all classes except defines.
# @param [Array] reqpackages List of packages to install.
# @param [String] pkg_ensure
# @param [Array] cv_reqpackages List of packages to install.
# @param [String] cv_pkg_ensure
# which [package type](https://confdroid.com/2017/05/puppet-type-package/)
# to choose, i.e. `latest` or `present`.
# @param [String] cv_logfile where to log messages for the clamd service.
@@ -35,12 +35,13 @@
# @param [String] cv_alert_file location and name of the alert file
# @param [Boolean] cv_enable_freshclam whether to enable the freshclam service
# @param [Boolean] cv_enable_clamd whether to enable the clamd service
# @param [Boolean] cv_use_excludepaths whether to use advanced exclude paths
##############################################################################
class confdroid_clamav::params (
# installation
Array $reqpackages = ['clamav','clamd','s-nail'],
String $pkg_ensure = 'present',
Array $cv_reqpackages = ['clamav','clamd','s-nail'],
String $cv_pkg_ensure = 'present',
# clamd
String $cv_logfile = '/var/log/clamd.scan',
@@ -64,6 +65,7 @@ class confdroid_clamav::params (
String $cv_alert_file = 'tmp/clamav-alert.txt',
Boolean $cv_enable_freshclam = true,
Boolean $cv_enable_clamd = true,
Boolean $cv_use_excludepaths = true
) {
# service

View File

@@ -21,7 +21,7 @@ PreludeAnalyzerName ClamAV
# Log additional information about the infected file, such as its
# size and hash, together with the virus name.
#ExtendedDetectionInfo yes
ExtendedDetectionInfo yes
# This option allows you to save a process identifier of the listening
# daemon (main thread).
@@ -132,6 +132,28 @@ PreludeAnalyzerName ClamAV
#ExcludePath ^/proc/
#ExcludePath ^/sys/
<% if @cv_use_excludepaths %>
ExcludePath ^/proc
ExcludePath ^/sys
ExcludePath ^/dev
ExcludePath ^/run
ExcludePath ^/var/run
ExcludePath ^/var/tmp
ExcludePath ^/tmp
ExcludePath ^/var/lib/clamav
ExcludePath ^/var/log/clamav
ExcludePath ^/var/lib/docker
ExcludePath ^/var/lib/containerd
ExcludePath ^/var/lib/kubelet/pods
ExcludePath ^/var/lib/kubelet/plugins
ExcludePath ^/var/lib/kubelet/plugins_registry
ExcludePath ^/var/log/pods
ExcludePath ^/var/log/containers
ExcludePath ^/var/cache
ExcludePath ^/run/containerd
ExcludePath ^/run/docker
<% end %>
# Maximum depth directories are scanned at.
# Default: 15
#MaxDirectoryRecursion 20