diff --git a/.vscode/settings.json b/.vscode/settings.json deleted file mode 100644 index 6c447a2..0000000 --- a/.vscode/settings.json +++ /dev/null @@ -1,61 +0,0 @@ -{ - "cSpell.words": [ - "ALLMATCHSCAN", - "authenticode", - "behaviour", - "bofh", - "clamav", - "clamd", - "clamdscan", - "clamonacc", - "clamscan", - "Clamuko", - "clamupdate", - "concurrentdatabasereload", - "Dazuko", - "dbname", - "epel", - "excludepaths", - "fanotify", - "fdpass", - "filesize", - "freshclam", - "getsebool", - "INADDR", - "kubelet", - "libclamav", - "logclean", - "logfacility", - "logfile", - "logfilemaxsize", - "logfileunlock", - "logrotation", - "logsyslog", - "logtime", - "logverbose", - "multiscan", - "mypass", - "myproxy", - "myusername", - "NOFILE", - "normalisation", - "PCRE", - "pipefail", - "preludeanalyzername", - "preludeenable", - "recieve", - "RLIMIT", - "safebrowsing", - "setsebool", - "subsig", - "subsigs", - "tcpaddre", - "tcpaddress", - "tcpsocket", - "VIRUSEVENT", - "virusgroup", - "VIRUSNAME", - "XMLDOCS", - "xxxyyzzzz" - ] -} \ No newline at end of file diff --git a/Jenkinsfile b/Jenkinsfile deleted file mode 100644 index 3de3324..0000000 --- a/Jenkinsfile +++ /dev/null @@ -1,128 +0,0 @@ -pipeline { - agent { - label 'puppet' - } - - post { - always { - deleteDir() /* clean up our workspace */ - } - success { - updateGitlabCommitStatus state: 'success' - } - failure { - updateGitlabCommitStatus state: 'failed' - step([$class: 'Mailer', notifyEveryUnstableBuild: true, recipients: 'support@confdroid.com', sendToIndividuals: true]) - } - } - - options { - gitLabConnection('gitlab.confdroid.com') - } - - stages { - - stage('pull master') { - steps { - sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) { - sh ''' - git config user.name "Jenkins Server" - git config user.email jenkins@confdroid.com - # Ensure we're on the development branch (triggered by push) - git checkout development - # Create jenkins branch from development - git checkout -b jenkins-build-$BUILD_NUMBER - # Optionally merge master into jenkins to ensure compatibility - git merge origin/master --no-ff || { echo "Merge conflict detected"; exit 1; } - ''' - } - } - } - - stage('puppet parser') { - steps { - sh '''for file in $(find . -iname \'*.pp\'); do - /opt/puppetlabs/bin/puppet parser validate --color false --render-as s --modulepath=modules $file || exit 1; - done;''' - } - } - - stage('check templates') { - steps{ - sh '''for file in $(find . -iname \'*.erb\'); - do erb -P -x -T "-" $file | ruby -c || exit 1; - done;''' - } - } - - stage('puppet-lint') { - steps { - sh '''/usr/local/bin/puppet-lint . \\ - --no-variable_scope-check \\ - || { echo "Puppet lint failed"; exit 1; } - ''' - } - } - - stage('SonarScan') { - steps { - withCredentials([string(credentialsId: 'sonar-token', variable: 'SONAR_TOKEN')]) { - sh ''' - /opt/sonar-scanner/bin/sonar-scanner \ - -Dsonar.projectKey=confdroid_clamav \ - -Dsonar.sources=. \ - -Dsonar.host.url=https://sonarqube.confdroid.com \ - -Dsonar.token=$SONAR_TOKEN - ''' - } - } - } - - stage('create Puppet documentation') { - steps { - sh '/opt/puppetlabs/bin/puppet strings' - } - } - - stage('update repo') { - steps { - sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) { - sh ''' - git config user.name "Jenkins Server" - git config user.email jenkins@confdroid.com - git rm -r --cached .vscode || echo "No .vscode to remove from git" - git add -A && git commit -am "Recommit for updates in build $BUILD_NUMBER" || echo "No changes to commit" - git push origin HEAD:master - ''' - } - } - } - - stage('Mirror to Gitea') { - steps { - sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) { - withCredentials([usernamePassword( - credentialsId: 'Jenkins-gitea', - usernameVariable: 'GITEA_USER', - passwordVariable: 'GITEA_TOKEN')]) { - script { - // Checkout from GitLab (already done implicitly) - sh ''' - git checkout master - git pull origin master - git branch -D development - git branch -D jenkins-build-$BUILD_NUMBER - git rm -f Jenkinsfile - git rm -r --cached .vscode || echo "No .vscode to remove from git" - git commit --amend --no-edit --allow-empty - git remote add master https://sourcecode.confdroid.com/confdroid/confdroid_clamav.git - git -c credential.helper="!f() { echo username=${GITEA_USER}; echo password=${GITEA_TOKEN}; }; f" \ - push master --mirror - ''' - } - } - } - } - } - } -} \ No newline at end of file diff --git a/doc/file.README.html b/doc/file.README.html index 532dad2..0e25580 100644 --- a/doc/file.README.html +++ b/doc/file.README.html @@ -107,7 +107,7 @@
  • run cron job to scan the file system (by default starting at root, configurable) via clamdscan

  • -

    set ConcurrentDatabaseReload option yes/no to optimize RAM consumption

    +

    set ConcurrentDatabaseReload option yes/no to optimize RAM consumption. defaults to no

  • manage services

  • diff --git a/doc/index.html b/doc/index.html index 414d029..4879aff 100644 --- a/doc/index.html +++ b/doc/index.html @@ -107,7 +107,7 @@
  • run cron job to scan the file system (by default starting at root, configurable) via clamdscan

  • -

    set ConcurrentDatabaseReload option yes/no to optimize RAM consumption

    +

    set ConcurrentDatabaseReload option yes/no to optimize RAM consumption. defaults to no

  • manage services

  • diff --git a/doc/puppet_classes/confdroid_clamav_3A_3Amain_3A_3Afiles.html b/doc/puppet_classes/confdroid_clamav_3A_3Amain_3A_3Afiles.html index 33b9294..4be93f9 100644 --- a/doc/puppet_classes/confdroid_clamav_3A_3Amain_3A_3Afiles.html +++ b/doc/puppet_classes/confdroid_clamav_3A_3Amain_3A_3Afiles.html @@ -158,7 +158,23 @@ 60 61 62 -63 +63 +64 +65 +66 +67 +68 +69 +70 +71 +72 +73 +74 +75 +76 +77 +78 +79
    # File 'manifests/main/files.pp', line 6
    @@ -193,6 +209,7 @@ class confdroid_clamav::main::files (
         seltype  => etc_t,
         seluser  => system_u,
         content  => template($cv_freshclam_erb),
    +    notify   => Service[$cv_freshclam],
       }
     
       # freshclam service config file
    @@ -206,6 +223,21 @@ class confdroid_clamav::main::files (
         seltype  => etc_t,
         seluser  => system_u,
         content  => template($cv_freshclam_svc_erb),
    +    notify   => Service[$cv_freshclam],
    +  }
    +
    +  # clamd service config file
    +  file { $cv_clamd_svc  :
    +    ensure   => file,
    +    owner    => 'root',
    +    group    => 'root',
    +    mode     => '0600',
    +    selrange => s0,
    +    selrole  => object_r,
    +    seltype  => etc_t,
    +    seluser  => system_u,
    +    content  => template($cv_clamd_svc_erb),
    +    notify   => Service[$cv_service],
       }
     
       # shell script for scanning and alerting
    diff --git a/doc/puppet_classes/confdroid_clamav_3A_3Aparams.html b/doc/puppet_classes/confdroid_clamav_3A_3Aparams.html
    index d06b5b8..62df361 100644
    --- a/doc/puppet_classes/confdroid_clamav_3A_3Aparams.html
    +++ b/doc/puppet_classes/confdroid_clamav_3A_3Aparams.html
    @@ -550,6 +550,11 @@ inherited by all classes except defines.
             (defaults to: 'no')
           
           
    +        —
    +        
    +

    whether to enable concurrent database reloads. This is useful when you have multiple clamd instances running on the same machine. If you have only one clamd instance, this should be set to ‘no’.

    +
    + @@ -563,10 +568,6 @@ inherited by all classes except defines.
     
     
    -40
    -41
    -42
    -43
     44
     45
     46
    @@ -615,10 +616,16 @@ inherited by all classes except defines.
     89
     90
     91
    -92
    +92 +93 +94 +95 +96 +97 +98
    -
    # File 'manifests/params.pp', line 40
    +        
    # File 'manifests/params.pp', line 44
     
     class confdroid_clamav::params (
     
    @@ -666,6 +673,8 @@ class confdroid_clamav::params (
       $cv_freshclam_erb       = 'confdroid_clamav/freshclam_conf.erb'
       $cv_freshclam_svc       = '/usr/lib/systemd/system/freshclam.service'
       $cv_freshclam_svc_erb   = 'confdroid_clamav/freshclam_svc.erb'
    +  $cv_clamd_svc           = '/usr/lib/systemd/system/clamd@.service'
    +  $cv_clamd_svc_erb       = 'confdroid_clamav/clamd_svc.erb'
       $cv_shell_script        = "${cv_config_d_dir}/scan.sh"
       $cv_shell_script_erb    = 'confdroid_clamav/scan.sh.erb'