Compare commits

...

5 Commits

Author SHA1 Message Date
Jenkins Server
820d65151b Recommit for updates in build 9 2026-09-22 13:39:18 +02:00
Jenkins Server
5a1c95427c Merge remote-tracking branch 'origin/master' into jenkins-build-9 2026-09-22 13:38:36 +02:00
8e32d2ad32 OP#785 add control for clamd service config file 2026-09-22 13:38:17 +02:00
66173a7573 OP#785 add control for clamd service config file 2026-09-22 13:37:25 +02:00
Jenkins Server
5d46317b6a Recommit for updates in build 8 2026-09-22 13:17:45 +02:00
16 changed files with 153 additions and 226 deletions

61
.vscode/settings.json vendored
View File

@@ -1,61 +0,0 @@
{
"cSpell.words": [
"ALLMATCHSCAN",
"authenticode",
"behaviour",
"bofh",
"clamav",
"clamd",
"clamdscan",
"clamonacc",
"clamscan",
"Clamuko",
"clamupdate",
"concurrentdatabasereload",
"Dazuko",
"dbname",
"epel",
"excludepaths",
"fanotify",
"fdpass",
"filesize",
"freshclam",
"getsebool",
"INADDR",
"kubelet",
"libclamav",
"logclean",
"logfacility",
"logfile",
"logfilemaxsize",
"logfileunlock",
"logrotation",
"logsyslog",
"logtime",
"logverbose",
"multiscan",
"mypass",
"myproxy",
"myusername",
"NOFILE",
"normalisation",
"PCRE",
"pipefail",
"preludeanalyzername",
"preludeenable",
"recieve",
"RLIMIT",
"safebrowsing",
"setsebool",
"subsig",
"subsigs",
"tcpaddre",
"tcpaddress",
"tcpsocket",
"VIRUSEVENT",
"virusgroup",
"VIRUSNAME",
"XMLDOCS",
"xxxyyzzzz"
]
}

128
Jenkinsfile vendored
View File

@@ -1,128 +0,0 @@
pipeline {
agent {
label 'puppet'
}
post {
always {
deleteDir() /* clean up our workspace */
}
success {
updateGitlabCommitStatus state: 'success'
}
failure {
updateGitlabCommitStatus state: 'failed'
step([$class: 'Mailer', notifyEveryUnstableBuild: true, recipients: 'support@confdroid.com', sendToIndividuals: true])
}
}
options {
gitLabConnection('gitlab.confdroid.com')
}
stages {
stage('pull master') {
steps {
sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) {
sh '''
git config user.name "Jenkins Server"
git config user.email jenkins@confdroid.com
# Ensure we're on the development branch (triggered by push)
git checkout development
# Create jenkins branch from development
git checkout -b jenkins-build-$BUILD_NUMBER
# Optionally merge master into jenkins to ensure compatibility
git merge origin/master --no-ff || { echo "Merge conflict detected"; exit 1; }
'''
}
}
}
stage('puppet parser') {
steps {
sh '''for file in $(find . -iname \'*.pp\'); do
/opt/puppetlabs/bin/puppet parser validate --color false --render-as s --modulepath=modules $file || exit 1;
done;'''
}
}
stage('check templates') {
steps{
sh '''for file in $(find . -iname \'*.erb\');
do erb -P -x -T "-" $file | ruby -c || exit 1;
done;'''
}
}
stage('puppet-lint') {
steps {
sh '''/usr/local/bin/puppet-lint . \\
--no-variable_scope-check \\
|| { echo "Puppet lint failed"; exit 1; }
'''
}
}
stage('SonarScan') {
steps {
withCredentials([string(credentialsId: 'sonar-token', variable: 'SONAR_TOKEN')]) {
sh '''
/opt/sonar-scanner/bin/sonar-scanner \
-Dsonar.projectKey=confdroid_clamav \
-Dsonar.sources=. \
-Dsonar.host.url=https://sonarqube.confdroid.com \
-Dsonar.token=$SONAR_TOKEN
'''
}
}
}
stage('create Puppet documentation') {
steps {
sh '/opt/puppetlabs/bin/puppet strings'
}
}
stage('update repo') {
steps {
sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) {
sh '''
git config user.name "Jenkins Server"
git config user.email jenkins@confdroid.com
git rm -r --cached .vscode || echo "No .vscode to remove from git"
git add -A && git commit -am "Recommit for updates in build $BUILD_NUMBER" || echo "No changes to commit"
git push origin HEAD:master
'''
}
}
}
stage('Mirror to Gitea') {
steps {
sshagent(['edd05eb6-26b5-4c7b-a5cc-ea2ab899f4fa']) {
withCredentials([usernamePassword(
credentialsId: 'Jenkins-gitea',
usernameVariable: 'GITEA_USER',
passwordVariable: 'GITEA_TOKEN')]) {
script {
// Checkout from GitLab (already done implicitly)
sh '''
git checkout master
git pull origin master
git branch -D development
git branch -D jenkins-build-$BUILD_NUMBER
git rm -f Jenkinsfile
git rm -r --cached .vscode || echo "No .vscode to remove from git"
git commit --amend --no-edit --allow-empty
git remote add master https://sourcecode.confdroid.com/confdroid/confdroid_clamav.git
git -c credential.helper="!f() { echo username=${GITEA_USER}; echo password=${GITEA_TOKEN}; }; f" \
push master --mirror
'''
}
}
}
}
}
}
}

View File

@@ -33,7 +33,7 @@
- manage required config files
- manage cronjob settings via parameters
- run cron job to scan the file system (by default starting at root, configurable) via clamdscan
- set ConcurrentDatabaseReload option yes/no to optimize RAM consumption
- set ConcurrentDatabaseReload option `yes`/`no` to optimize RAM consumption. defaults to `no`
- manage services
## Dependencies

View File

@@ -98,6 +98,11 @@
</li>
<li>
<span class='object_link'><a href="puppet_classes/confdroid_clamav_3A_3Aparams.html" title="puppet_classes::confdroid_clamav::params (puppet_class)">confdroid_clamav::params</a></span>
</li>
</ul>
</ul>

View File

@@ -107,6 +107,8 @@
</li><li>
<p>run cron job to scan the file system (by default starting at root, configurable) via clamdscan</p>
</li><li>
<p>set ConcurrentDatabaseReload option <code>yes</code>/<code>no</code> to optimize RAM consumption. defaults to <code>no</code></p>
</li><li>
<p>manage services</p>
</li></ul>

View File

@@ -107,6 +107,8 @@
</li><li>
<p>run cron job to scan the file system (by default starting at root, configurable) via clamdscan</p>
</li><li>
<p>set ConcurrentDatabaseReload option <code>yes</code>/<code>no</code> to optimize RAM consumption. defaults to <code>no</code></p>
</li><li>
<p>manage services</p>
</li></ul>

View File

@@ -78,6 +78,13 @@
</li>
<li id="object_puppet_classes::confdroid_clamav::params" class="odd">
<div class="item">
<span class='object_link'><a href="puppet_classes/confdroid_clamav_3A_3Aparams.html" title="puppet_classes::confdroid_clamav::params (puppet_class)">confdroid_clamav::params</a></span>
</div>
</li>
</ul>
</div>

View File

@@ -64,7 +64,7 @@
<dl>
<dt>Inherits:</dt>
<dd>confdroid_clamav::params</dd>
<dd><span class='object_link'><a href="confdroid_clamav_3A_3Aparams.html" title="puppet_classes::confdroid_clamav::params (puppet_class)">confdroid_clamav::params</a></span></dd>
</dl>

View File

@@ -64,7 +64,7 @@
<dl>
<dt>Inherits:</dt>
<dd>confdroid_clamav::params</dd>
<dd><span class='object_link'><a href="confdroid_clamav_3A_3Aparams.html" title="puppet_classes::confdroid_clamav::params (puppet_class)">confdroid_clamav::params</a></span></dd>
</dl>

View File

@@ -64,7 +64,7 @@
<dl>
<dt>Inherits:</dt>
<dd>confdroid_clamav::params</dd>
<dd><span class='object_link'><a href="confdroid_clamav_3A_3Aparams.html" title="puppet_classes::confdroid_clamav::params (puppet_class)">confdroid_clamav::params</a></span></dd>
</dl>
@@ -158,7 +158,23 @@
60
61
62
63</pre>
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79</pre>
</td>
<td>
<pre class="code"><span class="info file"># File 'manifests/main/files.pp', line 6</span>
@@ -193,6 +209,7 @@ class confdroid_clamav::main::files (
seltype =&gt; etc_t,
seluser =&gt; system_u,
content =&gt; template($cv_freshclam_erb),
notify =&gt; Service[$cv_freshclam],
}
# freshclam service config file
@@ -206,6 +223,21 @@ class confdroid_clamav::main::files (
seltype =&gt; etc_t,
seluser =&gt; system_u,
content =&gt; template($cv_freshclam_svc_erb),
notify =&gt; Service[$cv_freshclam],
}
# clamd service config file
file { $cv_clamd_svc :
ensure =&gt; file,
owner =&gt; &#39;root&#39;,
group =&gt; &#39;root&#39;,
mode =&gt; &#39;0600&#39;,
selrange =&gt; s0,
selrole =&gt; object_r,
seltype =&gt; etc_t,
seluser =&gt; system_u,
content =&gt; template($cv_clamd_svc_erb),
notify =&gt; Service[$cv_service],
}
# shell script for scanning and alerting

View File

@@ -64,7 +64,7 @@
<dl>
<dt>Inherits:</dt>
<dd>confdroid_clamav::params</dd>
<dd><span class='object_link'><a href="confdroid_clamav_3A_3Aparams.html" title="puppet_classes::confdroid_clamav::params (puppet_class)">confdroid_clamav::params</a></span></dd>
</dl>

View File

@@ -64,7 +64,7 @@
<dl>
<dt>Inherits:</dt>
<dd>confdroid_clamav::params</dd>
<dd><span class='object_link'><a href="confdroid_clamav_3A_3Aparams.html" title="puppet_classes::confdroid_clamav::params (puppet_class)">confdroid_clamav::params</a></span></dd>
</dl>

View File

@@ -535,6 +535,24 @@ inherited by all classes except defines.
&mdash;
<div class='inline'>
<p>whether to use advanced exclude paths</p>
</div>
</li>
<li>
<span class='name'>cv_concurrentdatabasereload</span>
<span class='type'>(<tt>String</tt>)</span>
<em class="default">(defaults to: <tt>&#39;no&#39;</tt>)</em>
&mdash;
<div class='inline'>
<p>whether to enable concurrent database reloads. This is useful when you have multiple clamd instances running on the same machine. If you have only one clamd instance, this should be set to ‘no’.</p>
</div>
</li>
@@ -550,10 +568,6 @@ inherited by all classes except defines.
<pre class="lines">
40
41
42
43
44
45
46
@@ -601,40 +615,48 @@ inherited by all classes except defines.
88
89
90
91</pre>
91
92
93
94
95
96
97
98</pre>
</td>
<td>
<pre class="code"><span class="info file"># File 'manifests/params.pp', line 40</span>
<pre class="code"><span class="info file"># File 'manifests/params.pp', line 44</span>
class confdroid_clamav::params (
# installation
Array $cv_reqpackages = [&#39;clamav&#39;,&#39;clamd&#39;,&#39;s-nail&#39;],
String $cv_pkg_ensure = &#39;present&#39;,
Array $cv_reqpackages = [&#39;clamav&#39;,&#39;clamd&#39;,&#39;s-nail&#39;],
String $cv_pkg_ensure = &#39;present&#39;,
# clamd
String $cv_logfile = &#39;/var/log/clamd.scan&#39;,
String $cv_logfileunlock = &#39;no&#39;,
String $cv_logfilemaxsize = &#39;2M&#39;,
String $cv_logtime = &#39;yes&#39;,
String $cv_logclean = &#39;no&#39;,
String $cv_logsyslog = &#39;yes&#39;,
String $cv_logfacility = &#39;LOG_MAIL&#39;,
String $cv_logverbose = &#39;no&#39;,
String $cv_logrotate = &#39;yes&#39;,
String $cv_preludeenable = &#39;no&#39;,
String $cv_preludeanalyzername = &#39;ClamAV&#39;,
String $cv_tcpsocket = &#39;3310&#39;,
String $cv_tcpaddress = &#39;localhost&#39;,
String $cv_alert_email = &#39;you@example.com&#39;,
String $cv_cron_hour = &#39;2&#39;,
String $cv_cron_minute = &#39;0&#39;,
String $cv_cron_user = &#39;root&#39;,
String $cv_scan_dir = &#39;/&#39;,
String $cv_alert_file = &#39;tmp/clamav-alert.txt&#39;,
Boolean $cv_enable_freshclam = true,
Boolean $cv_enable_clamd = true,
Boolean $cv_use_excludepaths = true
String $cv_logfile = &#39;/var/log/clamd.scan&#39;,
String $cv_logfileunlock = &#39;no&#39;,
String $cv_logfilemaxsize = &#39;2M&#39;,
String $cv_logtime = &#39;yes&#39;,
String $cv_logclean = &#39;no&#39;,
String $cv_logsyslog = &#39;yes&#39;,
String $cv_logfacility = &#39;LOG_MAIL&#39;,
String $cv_logverbose = &#39;no&#39;,
String $cv_logrotate = &#39;yes&#39;,
String $cv_preludeenable = &#39;no&#39;,
String $cv_preludeanalyzername = &#39;ClamAV&#39;,
String $cv_tcpsocket = &#39;3310&#39;,
String $cv_tcpaddress = &#39;localhost&#39;,
String $cv_alert_email = &#39;you@example.com&#39;,
String $cv_cron_hour = &#39;2&#39;,
String $cv_cron_minute = &#39;0&#39;,
String $cv_cron_user = &#39;root&#39;,
String $cv_scan_dir = &#39;/&#39;,
String $cv_alert_file = &#39;tmp/clamav-alert.txt&#39;,
Boolean $cv_enable_freshclam = true,
Boolean $cv_enable_clamd = true,
Boolean $cv_use_excludepaths = true,
String $cv_concurrentdatabasereload = &#39;no&#39;,
) {
# service
@@ -651,6 +673,8 @@ class confdroid_clamav::params (
$cv_freshclam_erb = &#39;confdroid_clamav/freshclam_conf.erb&#39;
$cv_freshclam_svc = &#39;/usr/lib/systemd/system/freshclam.service&#39;
$cv_freshclam_svc_erb = &#39;confdroid_clamav/freshclam_svc.erb&#39;
$cv_clamd_svc = &#39;/usr/lib/systemd/system/clamd@.service&#39;
$cv_clamd_svc_erb = &#39;confdroid_clamav/clamd_svc.erb&#39;
$cv_shell_script = &quot;${cv_config_d_dir}/scan.sh&quot;
$cv_shell_script_erb = &#39;confdroid_clamav/scan.sh.erb&#39;

View File

@@ -33,6 +33,7 @@ class confdroid_clamav::main::files (
seltype => etc_t,
seluser => system_u,
content => template($cv_freshclam_erb),
notify => Service[$cv_freshclam],
}
# freshclam service config file
@@ -46,6 +47,21 @@ class confdroid_clamav::main::files (
seltype => etc_t,
seluser => system_u,
content => template($cv_freshclam_svc_erb),
notify => Service[$cv_freshclam],
}
# clamd service config file
file { $cv_clamd_svc :
ensure => file,
owner => 'root',
group => 'root',
mode => '0600',
selrange => s0,
selrole => object_r,
seltype => etc_t,
seluser => system_u,
content => template($cv_clamd_svc_erb),
notify => Service[$cv_service],
}
# shell script for scanning and alerting

View File

@@ -36,6 +36,10 @@
# @param [Boolean] cv_enable_freshclam whether to enable the freshclam service
# @param [Boolean] cv_enable_clamd whether to enable the clamd service
# @param [Boolean] cv_use_excludepaths whether to use advanced exclude paths
# @param [String] cv_concurrentdatabasereload whether to enable concurrent
# database reloads. This is useful when you have multiple clamd instances
# running on the same machine. If you have only one clamd instance, this
# should be set to 'no'.
##############################################################################
class confdroid_clamav::params (
@@ -83,6 +87,8 @@ class confdroid_clamav::params (
$cv_freshclam_erb = 'confdroid_clamav/freshclam_conf.erb'
$cv_freshclam_svc = '/usr/lib/systemd/system/freshclam.service'
$cv_freshclam_svc_erb = 'confdroid_clamav/freshclam_svc.erb'
$cv_clamd_svc = '/usr/lib/systemd/system/clamd@.service'
$cv_clamd_svc_erb = 'confdroid_clamav/clamd_svc.erb'
$cv_shell_script = "${cv_config_d_dir}/scan.sh"
$cv_shell_script_erb = 'confdroid_clamav/scan.sh.erb'

22
templates/clamd_svc.erb Normal file
View File

@@ -0,0 +1,22 @@
################################################################################
### clamd.svc created by Puppet, manual changes will be overwritten!!! ###
################################################################################
[Unit]
Description = clamd scanner (%i) daemon
Documentation=man:clamd(8) man:clamd.conf(5) https://www.clamav.net/documents/
After = syslog.target nss-lookup.target network.target
[Service]
Type = forking
ExecStart = /usr/sbin/clamd -c /etc/clamd.d/%i.conf
# Reload the database
ExecReload=/bin/kill -USR2 $MAINPID
Restart = on-failure
TimeoutStartSec=420
MemoryLimit=1024M
CPUQuota=30%
Nice=19
[Install]
WantedBy = multi-user.target