From 7f20c0e45e0066bf129d8c00dac640175c095524 Mon Sep 17 00:00:00 2001 From: 12ww1160 <12ww1160@confdroid.com> Date: Tue, 22 Sep 2026 12:45:06 +0200 Subject: [PATCH] OP#785 add excludepaths and option to use it --- .vscode/settings.json | 2 ++ manifests/main/install.pp | 4 ++-- manifests/params.pp | 10 ++++++---- templates/scan_conf.erb | 24 +++++++++++++++++++++++- 4 files changed, 33 insertions(+), 7 deletions(-) diff --git a/.vscode/settings.json b/.vscode/settings.json index 551a816..43d2b81 100644 --- a/.vscode/settings.json +++ b/.vscode/settings.json @@ -14,11 +14,13 @@ "Dazuko", "dbname", "epel", + "excludepaths", "fanotify", "filesize", "freshclam", "getsebool", "INADDR", + "kubelet", "libclamav", "logclean", "logfacility", diff --git a/manifests/main/install.pp b/manifests/main/install.pp index edc3408..c897277 100644 --- a/manifests/main/install.pp +++ b/manifests/main/install.pp @@ -9,7 +9,7 @@ class confdroid_clamav::main::install ( ) inherits confdroid_clamav::params { require confdroid_resources::main::epel - package { $reqpackages: - ensure => $pkg_ensure, + package { $cv_reqpackages: + ensure => $cv_pkg_ensure, } } diff --git a/manifests/params.pp b/manifests/params.pp index b931da5..f4288bd 100644 --- a/manifests/params.pp +++ b/manifests/params.pp @@ -3,8 +3,8 @@ # Author: 12ww1160 (12ww1160@confdroid.com) # @summary Class holds all parameters for the confdroid_clamav module and is # inherited by all classes except defines. -# @param [Array] reqpackages List of packages to install. -# @param [String] pkg_ensure +# @param [Array] cv_reqpackages List of packages to install. +# @param [String] cv_pkg_ensure # which [package type](https://confdroid.com/2017/05/puppet-type-package/) # to choose, i.e. `latest` or `present`. # @param [String] cv_logfile where to log messages for the clamd service. @@ -35,12 +35,13 @@ # @param [String] cv_alert_file location and name of the alert file # @param [Boolean] cv_enable_freshclam whether to enable the freshclam service # @param [Boolean] cv_enable_clamd whether to enable the clamd service +# @param [Boolean] cv_use_excludepaths whether to use advanced exclude paths ############################################################################## class confdroid_clamav::params ( # installation - Array $reqpackages = ['clamav','clamd','s-nail'], - String $pkg_ensure = 'present', + Array $cv_reqpackages = ['clamav','clamd','s-nail'], + String $cv_pkg_ensure = 'present', # clamd String $cv_logfile = '/var/log/clamd.scan', @@ -64,6 +65,7 @@ class confdroid_clamav::params ( String $cv_alert_file = 'tmp/clamav-alert.txt', Boolean $cv_enable_freshclam = true, Boolean $cv_enable_clamd = true, + Boolean $cv_use_excludepaths = true ) { # service diff --git a/templates/scan_conf.erb b/templates/scan_conf.erb index ad77152..6b3c880 100644 --- a/templates/scan_conf.erb +++ b/templates/scan_conf.erb @@ -21,7 +21,7 @@ PreludeAnalyzerName ClamAV # Log additional information about the infected file, such as its # size and hash, together with the virus name. -#ExtendedDetectionInfo yes +ExtendedDetectionInfo yes # This option allows you to save a process identifier of the listening # daemon (main thread). @@ -132,6 +132,28 @@ PreludeAnalyzerName ClamAV #ExcludePath ^/proc/ #ExcludePath ^/sys/ +<% if @cv_use_excludepaths %> +ExcludePath ^/proc +ExcludePath ^/sys +ExcludePath ^/dev +ExcludePath ^/run +ExcludePath ^/var/run +ExcludePath ^/var/tmp +ExcludePath ^/tmp +ExcludePath ^/var/lib/clamav +ExcludePath ^/var/log/clamav +ExcludePath ^/var/lib/docker +ExcludePath ^/var/lib/containerd +ExcludePath ^/var/lib/kubelet/pods +ExcludePath ^/var/lib/kubelet/plugins +ExcludePath ^/var/lib/kubelet/plugins_registry +ExcludePath ^/var/log/pods +ExcludePath ^/var/log/containers +ExcludePath ^/var/cache +ExcludePath ^/run/containerd +ExcludePath ^/run/docker +<% end %> + # Maximum depth directories are scanned at. # Default: 15 #MaxDirectoryRecursion 20