1 Commits

Author SHA1 Message Date
4c441cde92 Added process manager 2025-05-27 20:43:42 +02:00
17 changed files with 229 additions and 398 deletions

View File

@@ -1,79 +0,0 @@
name: CI
on:
push:
tags:
- '*' # Triggers on all tags
branches:
- '**' # Triggers on all branches
defaults:
run:
shell: bash
working-directory: .
jobs:
build:
runs-on: ubuntu
container:
image: node:20
steps:
- name: Checkout code
uses: actions/checkout@v3
- name: Install tools
run: apt update && apt install -y build-essential
- name: Compile project
run: make
- name: Save build output
uses: actions/upload-artifact@v3
with:
name: ncsambawatcher
path: ./ncsambawatcher
release:
if: startsWith(github.ref, 'refs/tags/')
needs: build
runs-on: ubuntu
container:
image: node:20
steps:
- name: Checkout code
uses: actions/checkout@v3
- name: Install build tools
run: apt update && apt install -y zip
- name: Download compiled binary
uses: actions/download-artifact@v3
with:
name: ncsambawatcher
- name: Copy files
run: |
mkdir build
cp ncsambawatcher build/ncsambawatcher
cp configs/ncsambawatcher.config.default build/ncsambawatcher.config
cp configs/ncsambawatcher.service.default build/ncsambawatcher.service
cp init.sh build/init.sh
- name: Create release zip
run: |
cd build
ls -al
zip -rv ../ncsambawatcher.zip ./*
cd ../
ls -al
- name: Publish release
uses: akkuman/gitea-release-action@v1
env:
GITHUB_TOKEN: ${{ secrets.RELEASE_SECRET }}
with:
tag_name: ${{ github.ref_name }}
name: Release ${{ github.ref_name }}
files: ./ncsambawatcher.zip
token: ${{ secrets.RELEASE_SECRET }}
draft: true

3
.gitignore vendored
View File

@@ -90,6 +90,3 @@ settings.json
watch.c
ncwatchfile
ncsambawatcher
obj/
build/

View File

@@ -1,31 +1,2 @@
# Compiler and flags
CXX := g++
CXXFLAGS := -std=c++17 -Wall -Wextra -O2
# Directories
SRC_DIR := src
OBJ_DIR := obj
BUILD_DIR := .
TARGET := $(BUILD_DIR)/ncsambawatcher
# Create list of source and object files
SRCS := $(wildcard $(SRC_DIR)/*.cpp)
OBJS := $(SRCS:$(SRC_DIR)/%.cpp=$(OBJ_DIR)/%.o)
# Default target
all: $(TARGET)
# Link object files into final binary
$(TARGET): $(OBJS)
$(CXX) $(CXXFLAGS) -o $@ $^
# Compile .cpp to .o into obj/
$(OBJ_DIR)/%.o: $(SRC_DIR)/%.cpp
@mkdir -p $(OBJ_DIR)
$(CXX) $(CXXFLAGS) -c $< -o $@
# Clean build artifacts
clean:
rm -f $(OBJ_DIR)/*.o $(TARGET)
.PHONY: all clean
all:
g++ -lrt -std=c++17 src/main.cpp src/usermanager.cpp src/guarder.cpp -o ncsambawatcher

View File

@@ -1 +0,0 @@
NEXTCLOUD_CONTAINER_NAME=nextcloud

View File

@@ -1,14 +1,14 @@
[Unit]
Description=A service which scan Nextcloud folders
After=network.target docker.service
Requires=docker.service
After=network.target
[Service]
ExecStart=/path/to/folder/ncsambawatcher
WorkingDirectory=/path/to/folder/
ExecStart=/usr/bin/ncsambawatcher
Restart=always
User=root
Group=root
WorkingDirectory=/usr/bin/
Environment=PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
StandardOutput=journal
StandardError=journal
SyslogIdentifier=ncsambawatcher

View File

@@ -1,48 +0,0 @@
[global]
vfs objects = full_audit
full_audit:prefix = %u|%I|%m|%S
full_audit:success = mkdirat unlinkat renameat write
full_audit:failure = none
full_audit:facility = local5
full_audit:priority = NOTICE
# Example usershare
[<username>] #CHANGEME
path = /path/to/nextcloud/data/<username>/files/ #CHANGEME
valid users = <username> #CHANGEME
force user = www-data
force group = www-data
create mask = 0755
force create mode = 0755
directory mask = 0755
force directory mode = 0755
guest ok = no
public = no
writable = yes
browsable = yes
hide dot files = no
inherit owner = yes
hide unreadable = no
# Example groupfolder share
[Sharename]
path = /path/to/nextcloud/data/__groupfolders/<groupfolder-id> #CHANGEME
valid users = usernames #CHANGEME
force user = www-data
force group = www-data
create mask = 0755
force create mode = 0755
directory mask = 0755
force directory mode = 0755
guest ok = no
public = no
writable = yes
browsable = yes
hide dot files = no
inherit owner = yes
hide unreadable = no
full_audit:prefix = %u|%I|%m|__groupfolders/<groupfolder-id> #CHANGEME
# To disable logs for a specific share, add this line to that share
[Sharename]
vfs objects =

View File

@@ -1,9 +1,11 @@
#!/bin/bash
current_dir=$(pwd)
sed -i "s|/path/to/folder/|$current_dir/|g" ncsambawatcher.service
make
sudo cp ./ncsambawatcher.service /etc/systemd/system
sudo cp ncsambawatcher /usr/bin/
sudo chmod +x /usr/bin/ncsambawatcher
sudo cp configs/ncsambawatcher.service /etc/systemd/system
sudo systemctl daemon-reload
sudo systemctl enable ncsambawatcher.service

View File

@@ -1 +0,0 @@
#include "configfilemanager.h"

View File

@@ -1,62 +0,0 @@
#ifndef _CONFIGFILEMANAGER_H
#define _CONFIGFILEMANAGER_H
#include <map>
#include <string>
#include <vector>
#include <fstream>
#include <iostream>
#include <mutex>
#include "definitions.h"
class configfilemanager{
private:
std::map<std::string, std::string> configs;
std::mutex mtx;
public:
configfilemanager(std::string filepath = "./ncsambawatcher.config")
{
std::ifstream is(filepath);
if(!is.good())
{
std::cerr << "File not exits: " << filepath << std::endl;
exit(EXIT_FAILURE);
}
std::string tmp;
while(!is.eof())
{
std::getline(is, tmp);
std::cout << tmp << std::endl;
if (tmp.at(0) == '#') // ignore comments
continue;
std::vector<std::string> splited = splitString(tmp, '=');
if (splited.size() != 2)
{
std::cerr << "Invalid line: " << tmp << std::endl;
continue;
}
configs.insert(std::make_pair(splited.at(0), splited.at(1)));
}
std::cout << "Config file loaded successfuly" << std::endl;
}
std::string at(const std::string &config)
{
std::lock_guard<std::mutex> lock(mtx);
return configs.at(config);
}
std::string at(const char* config)
{
return at(std::string(config));
}
};
#endif // _CONFIGFILEMANAGER_H

View File

@@ -1,13 +0,0 @@
#ifndef _LOCATIONS_H
#define _LOCATIONS_H
#define LOGFILE "journalctl -u smbd --since now -f"
#define USER_LOG_LOCATION 3
#define SCAN_CMD_USR "docker exec --user www-data %1% /var/www/html/occ files:scan --path="
#define SCAN_CMD_GRP "docker exec --user www-data %1% /var/www/html/occ groupfolder:scan "
std::vector<std::string> splitString(const std::string& input, char delimiter);
#endif // _LOCATIONS_H

1
src/guarder.cpp Normal file
View File

@@ -0,0 +1 @@
#include "guarder.h"

52
src/guarder.h Normal file
View File

@@ -0,0 +1,52 @@
#ifndef _GUARDER_H
#define _GUARDER_H
#include <sys/types.h>
#include <sys/shm.h>
#include <sys/ipc.h>
class guarder{
private:
const int shmid;
void setFlag(bool value)
{
bool *flag = static_cast<bool *>(shmat(shmid, nullptr, 0));
*flag = value;
shmdt(flag);
}
public:
guarder() : shmid(shmget(IPC_PRIVATE, sizeof(bool), 0666 | IPC_CREAT))
{
setFlagOff();
}
guarder(guarder &g) : shmid(g.shmid) {}
void setFlagOff()
{
setFlag(false);
}
void setFlagOn()
{
setFlag(true);
}
bool isFlagOn()
{
bool *flag = static_cast<bool *>(shmat(shmid, nullptr, 0));
bool ret = *flag;
shmdt(flag);
return ret;
}
~guarder()
{
shmctl(shmid, IPC_RMID, nullptr);
}
};
#endif // _GUARDER_H

8
src/locations.h Normal file
View File

@@ -0,0 +1,8 @@
#ifndef _LOCATIONS_H
#define _LOCATIONS_H
#define LOGFILE "journalctl -u smbd --since now -f"
#define USER_LOG_LOCATION 3
#endif // _LOCATIONS_H

View File

@@ -1,116 +1,120 @@
#include <stdio.h>
#include <unistd.h>
#include <sys/wait.h>
#include <iostream>
#include <thread>
#include <vector>
#include <set>
#include <array>
#include <string>
#include <mutex>
#include <condition_variable>
#include <cstdio>
#include "definitions.h"
#include <vector>
#include <unistd.h>
#include <sys/types.h>
#include <syslog.h>
#include <fcntl.h>
#include <signal.h>
#include "locations.h"
#include "usermanager.h"
#include "configfilemanager.h"
#include "guarder.h"
#include "processManager.h"
configfilemanager cfm;
#define MAXNAMESIZE 255
#define SCAN_DONE_SIG SIGRTMIN
#define SCAN_CMD_USR "docker exec --user www-data nextcloud /var/www/html/occ files:scan --path="
int p1[2];
guarder guard;
userManager manager;
std::condition_variable cv;
std::mutex mtx;
std::vector<std::string> splitString(const std::string& str, char delimiter = '|')
void flushManagerToPipe()
{
std::vector<std::string> ret;
std::stringstream ss(str);
std::string token;
while (std::getline(ss, token, delimiter)) {
ret.push_back(token);
}
return ret;
}
void readingThreadFunc()
{
FILE *logpipe = popen(LOGFILE, "r");
std::array<char, 256> buffer;
while (fgets(buffer.data(), buffer.size(), logpipe) != nullptr)
if (!guard.isFlagOn())
{
std::string line(buffer.data());
if (line.find('|') == std::string::npos)
continue;
std::vector<std::string> x = splitString(line, '|');
std::string user(x.at(USER_LOG_LOCATION));
std::vector<std::string> users = manager.getFlaggedUsers();
for (std::vector<std::string>::iterator it = users.begin(); it != users.end(); ++it)
{
std::lock_guard<std::mutex> lock(mtx);
manager.addUser(user);
manager.setUserFlagged(user);
int size = it->size();
write(p1[1], &size, sizeof(int));
write(p1[1], it->data(), size * sizeof(char));
}
cv.notify_one();
std::cout << "User find: " << user << std::endl;
}
}
void scannerThreadFunc()
{
std::unique_lock<std::mutex> lock(mtx);
std::vector<pid_t> childrens;
while (true)
{
cv.wait(lock, []
{ return manager.isAnybodyFlagged(); });
std::set<std::string> scanUsers = manager.getFlaggedUsers();
manager.unflagAllUsers();
}
}
lock.unlock();
childrens.clear();
for (const std::string& user : scanUsers)
{
pid_t child = fork();
if (child < 0)
{
std::cerr << "Fork failed for: " << user << std::endl;
}
else if (child == 0) // child
{
std::string cmd = userManager::getScanCommandFromUser(user, cfm);
execl("/bin/sh", "sh", "-c", cmd.c_str(), static_cast<char *>(nullptr));
std::cerr << "Scan failed" << std::endl;
_exit(EXIT_FAILURE);
}
else // parent
{
childrens.push_back(child);
}
}
for (const pid_t& pid : childrens)
{
waitpid(pid, nullptr, 0);
}
lock.lock();
void handler(int sig)
{
if (sig == SCAN_DONE_SIG)
{
flushManagerToPipe();
}
}
int main()
{
std::thread readingThread(readingThreadFunc);
std::thread scannerThread(scannerThreadFunc);
openlog("ncsambawatcher", LOG_PID | LOG_CONS, LOG_USER);
pipe(p1);
readingThread.join();
scannerThread.join();
pid_t parent = getpid();
pid_t child = fork();
return 0;
if (child > 0) // parent
{
signal(SCAN_DONE_SIG, handler);
close(p1[0]); // read
FILE *logpipe = popen(LOGFILE, "r");
std::array<char, 256> buffer;
while (fgets(buffer.data(), buffer.size(), logpipe) != nullptr)
{
std::string line(buffer.data());
if (line.find('|') == std::string::npos)
continue;
std::vector<std::string> x = splitLogFile(line, '|');
std::string user(x.at(USER_LOG_LOCATION));
manager.addUser(user);
manager.setUserFlagged(user);
std::cout << "User find: " << user << std::endl;
flushManagerToPipe();
}
fclose(logpipe);
close(p1[1]); // write
}
else // child
{
close(p1[1]); // write
int size;
char *buffer = nullptr;
processManager pm;
while (read(p1[0], &size, sizeof(int)))
{
if (buffer == nullptr)
buffer = new char[size];
read(p1[0], buffer, size * sizeof(char));
std::string name(buffer);
std::string cmd = std::string(SCAN_CMD_USR) + name;
std::cout << "Scan received for: " << name << std::endl;
pm.runTask(name, cmd);
kill(parent, SCAN_DONE_SIG);
if (buffer != nullptr)
{
delete[] buffer;
buffer = nullptr;
}
}
close(p1[0]); // read
}
closelog();
return EXIT_SUCCESS;
}

41
src/processManager.h Normal file
View File

@@ -0,0 +1,41 @@
#ifndef _PROCCESSMANAGER_H
#define _PROCCESSMANAGER_H
#include <map>
#include <string>
#include <unistd.h>
#include <sys/types.h>
#include "guarder.h"
#include "usermanager.h"
class processManager
{
private:
std::map<std::string, guarder> running;
bool getIdTag(std::string &id)
{
return running[id].isFlagOn();
}
public:
void runTask(std::string &id, std::string &cmdCommand)
{
if (!getIdTag(id))
{
running[id].setFlagOn();
pid_t child = fork();
if (child == 0) // child
{
system(cmdCommand.c_str());
running[id].setFlagOff();
exit(EXIT_SUCCESS);
}
}
}
};
#endif // _PROCCESSMANAGER_H

View File

@@ -1,28 +1,14 @@
#include "usermanager.h"
std::string userManager::getScanCommandFromUser(const std::string &user, configfilemanager &cfm)
std::vector<std::string> splitLogFile(const std::string& input, char delimiter = '|')
{
std::string contname = cfm.at("NEXTCLOUD_CONTAINER_NAME");
std::string baseCommand;
std::string userCommand;
std::string placeholder("%1%");
std::vector<std::string> ret;
std::stringstream ss(input);
std::string token;
if (user.find("__groupfolder") != std::string::npos)
{
baseCommand = SCAN_CMD_GRP;
userCommand = splitString(user, '/').back();
}
else
{
baseCommand = SCAN_CMD_USR;
userCommand = user;
while (std::getline(ss, token, delimiter)) {
ret.push_back(token);
}
size_t pos = 0;
while ((pos = baseCommand.find(placeholder, pos)) != std::string::npos) {
baseCommand.replace(pos, placeholder.length(), contname);
pos += contname.length(); // Move past the replacement
}
return baseCommand + userCommand;
return ret;
}

View File

@@ -4,30 +4,25 @@
#include <string>
#include <map>
#include <vector>
#include <set>
#include <sstream>
#include <mutex>
#include "definitions.h"
#include "configfilemanager.h"
#include "locations.h"
std::vector<std::string> splitLogFile(const std::string& input, char delimiter);
class userManager
{
private:
std::map<std::string, bool> users;
std::mutex mtx;
public:
static std::string getScanCommandFromUser(const std::string&, configfilemanager& cfm);
void addUserFromLogLine(std::string &line)
{
addUser(splitString(line, '|').at(USER_LOG_LOCATION));
addUser(splitLogFile(line, '|').at(USER_LOG_LOCATION));
}
void addUser(std::string &user)
{
std::lock_guard<std::mutex> lock(mtx);
if (users.count(user) == 0)
{
users[user] = false;
@@ -36,19 +31,16 @@ public:
void removeUser(std::string &user)
{
std::lock_guard<std::mutex> lock(mtx);
users.erase(user);
}
bool isContains(std::string &user)
{
std::lock_guard<std::mutex> lock(mtx);
return users.count(user) == 1;
}
void setUserFlagged(std::string &user)
{
std::lock_guard<std::mutex> lock(mtx);
if (users.count(user) == 1)
{
users[user] = true;
@@ -57,7 +49,6 @@ public:
void setUserUnflagged(std::string &user)
{
std::lock_guard<std::mutex> lock(mtx);
if (users.count(user) == 1)
{
users[user] = false;
@@ -66,56 +57,38 @@ public:
void unflagAllUsers()
{
std::lock_guard<std::mutex> lock(mtx);
for (std::map<std::string, bool>::iterator it = users.begin(); it != users.end(); ++it)
{
it->second = false;
}
}
std::set<std::string> getUsers()
std::vector<std::string> getUsers()
{
std::set<std::string> ret;
std::lock_guard<std::mutex> lock(mtx);
std::vector<std::string> ret;
for (std::map<std::string, bool>::iterator it = users.begin(); it != users.end(); ++it)
{
ret.insert(it->first);
ret.push_back(it->first);
}
return ret;
}
std::set<std::string> getFlaggedUsers()
std::vector<std::string> getFlaggedUsers()
{
std::set<std::string> ret;
std::lock_guard<std::mutex> lock(mtx);
std::vector<std::string> ret;
for (std::map<std::string, bool>::iterator it = users.begin(); it != users.end(); ++it)
{
if (it->second)
{
ret.insert(it->first);
ret.push_back(it->first);
}
}
return ret;
}
bool isAnybodyFlagged()
{
std::lock_guard<std::mutex> lock(mtx);
for (std::map<std::string, bool>::iterator it = users.begin(); it != users.end(); ++it)
{
if (it->second)
return true;
}
return false;
}
};
#endif // _USERMAN_H