13 Commits

8 changed files with 190 additions and 129 deletions

View File

@@ -0,0 +1,18 @@
[Unit]
Description=A service which scan Nextcloud folders
After=network.target docker.service
Requires=docker.service
[Service]
ExecStart=/usr/bin/ncsambawatcher
Restart=always
User=root
Group=root
WorkingDirectory=/usr/bin/
Environment=PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
StandardOutput=journal
StandardError=journal
SyslogIdentifier=ncsambawatcher
[Install]
WantedBy=multi-user.target

18
configs/smb.24.04.conf Normal file
View File

@@ -0,0 +1,18 @@
[global]
vfs objects = full_audit
full_audit:prefix = %u|%I|%m|%S
full_audit:success = mkdirat unlinkat renameat write
full_audit:failure = none
full_audit:facility = local5
full_audit:priority = NOTICE
# Put this line only for the groupfolder's share
[Some gorupfolder share]
full_audit:prefix = %u|%I|%m|__groupfolders/<group-folders-id>
# To disable logs for a specific share
[A share]
vfs objects =

12
init.sh Executable file
View File

@@ -0,0 +1,12 @@
#!/bin/bash
make
sudo cp ncsambawatcher /usr/bin/
sudo chmod +x /usr/bin/ncsambawatcher
sudo cp configs/ncsambawatcher.service /etc/systemd/system
sudo systemctl daemon-reload
sudo systemctl enable ncsambawatcher.service
sudo systemctl start ncsambawatcher.service

11
src/definitions.h Normal file
View File

@@ -0,0 +1,11 @@
#ifndef _LOCATIONS_H
#define _LOCATIONS_H
#define LOGFILE "journalctl -u smbd --since now -f"
#define USER_LOG_LOCATION 3
#define SCAN_CMD_USR "docker exec --user www-data nextcloud /var/www/html/occ files:scan --path="
#define SCAN_CMD_GRP "docker exec --user www-data nextcloud /var/www/html/occ groupfolder:scan "
#endif // _LOCATIONS_H

View File

@@ -1,8 +0,0 @@
#ifndef _LOCATIONS_H
#define _LOCATIONS_H
#define LOGFILE "journalctl -u smbd --since now -f"
#define USER_LOG_LOCATION 3
#endif // _LOCATIONS_H

View File

@@ -1,128 +1,100 @@
#include <stdio.h>
#include <unistd.h>
#include <sys/wait.h>
#include <iostream> #include <iostream>
#include <thread>
#include <vector>
#include <set>
#include <array> #include <array>
#include <string> #include <string>
#include <map> #include <mutex>
#include <vector> #include <condition_variable>
#include <unistd.h> #include <cstdio>
#include <sys/types.h>
#include <sys/shm.h>
#include <sys/ipc.h>
#include <syslog.h>
#include <sys/stat.h>
#include <fcntl.h>
#include <signal.h>
#include <stdbool.h>
#include "locations.h"
#include "usermanager.h" #include "usermanager.h"
#define MAXNAMESIZE 255 userManager manager;
#define SCAN_DONE_SIG SIGRTMIN std::condition_variable cv;
#define SCAN_CMD_USR "docker exec -ti --user www-data nextcloud /var/www/html/occ files:scan --path=" std::mutex mtx;
void initRunningFlag(int shmid) void readingThreadFunc()
{ {
bool *init = static_cast<bool *>(shmat(shmid, nullptr, 0)); FILE *logpipe = popen(LOGFILE, "r");
*init = false; std::array<char, 256> buffer;
shmdt(init);
while (fgets(buffer.data(), buffer.size(), logpipe) != nullptr)
{
std::string line(buffer.data());
if (line.find('|') == std::string::npos)
continue;
std::vector<std::string> x = splitString(line, '|');
std::string user(x.at(USER_LOG_LOCATION));
{
std::lock_guard<std::mutex> lock(mtx);
manager.addUser(user);
manager.setUserFlagged(user);
}
cv.notify_one();
std::cout << "User find: " << user << std::endl;
}
} }
bool readRunningFlag(int shmid) void scannerThreadFunc()
{ {
bool *init = static_cast<bool *>(shmat(shmid, nullptr, 0)); std::unique_lock<std::mutex> lock(mtx);
*init = false; std::vector<pid_t> childrens;
shmdt(init); while (true)
return *init; {
} cv.wait(lock, []
{ return manager.isAnybodyFlagged(); });
void setRunningFlag(int shmid, bool data) std::set<std::string> scanUsers = manager.getFlaggedUsers();
{ manager.unflagAllUsers();
bool *init = static_cast<bool *>(shmat(shmid, nullptr, 0));
*init = data;
shmdt(init);
}
void handler(int sig) {} lock.unlock();
childrens.clear();
for (const std::string& user : scanUsers)
{
pid_t child = fork();
if (child < 0)
{
std::cerr << "Fork failed for: " << user << std::endl;
}
else if (child == 0) // child
{
std::string cmd = userManager::getScanCommandFromUser(user);
execl("/bin/sh", "sh", "-c", cmd.c_str(), static_cast<char *>(nullptr));
std::cerr << "Scan failed" << std::endl;
_exit(EXIT_FAILURE);
}
else // parent
{
childrens.push_back(child);
}
}
for (const pid_t& pid : childrens)
{
waitpid(pid, nullptr, 0);
}
lock.lock();
}
}
int main() int main()
{ {
openlog("ncsambawatcher", LOG_PID | LOG_CONS, LOG_USER); std::thread readingThread(readingThreadFunc);
std::thread scannerThread(scannerThreadFunc);
int p1[2]; readingThread.join();
pipe(p1); scannerThread.join();
sigset_t ss;
sigfillset(&ss);
sigdelset(&ss, SCAN_DONE_SIG);
int shmid = shmget(IPC_PRIVATE, sizeof(bool), 0666 | IPC_CREAT); return 0;
initRunningFlag(shmid);
pid_t parent = getpid();
pid_t child = fork();
if (child > 0) // parent
{
close(p1[0]); // read
FILE *logpipe = popen(LOGFILE, "r");
std::array<char, 256> buffer;
userManager manager;
while (fgets(buffer.data(), buffer.size(), logpipe) != nullptr)
{
std::string line(buffer.data());
if (line.find('|') == std::string::npos)
continue;
std::vector<std::string> x = splitLogFile(line, '|');
std::string user(x.at(USER_LOG_LOCATION));
manager.addUser(user);
manager.setUserFlagged(user);
std::vector<std::string> users = manager.getFlaggedUsers();
for (std::vector<std::string>::iterator it = users.begin(); it != users.end(); ++it)
{
int size = it->size();
write(p1[1], &size, sizeof(int));
write(p1[1], it->data(), size * sizeof(char));
}
}
fclose(logpipe);
close(p1[1]); // write
}
else // child
{
close(p1[1]); // write
int size;
char *buffer = nullptr;
while (read(p1[0], &size, sizeof(int)))
{
if (buffer == nullptr)
buffer = new char[size];
read(p1[0], buffer, size * sizeof(char));
std::string name(buffer);
system((std::string(SCAN_CMD_USR) + name).data());
if (buffer != nullptr)
{
delete[] buffer;
buffer = nullptr;
}
}
close(p1[0]); // read
}
shmctl(shmid, IPC_RMID, nullptr);
closelog();
return EXIT_SUCCESS;
} }

View File

@@ -1,9 +1,9 @@
#include "usermanager.h" #include "usermanager.h"
std::vector<std::string> splitLogFile(const std::string& input, char delimiter = '|') std::vector<std::string> splitString(const std::string& str, char delimiter = '|')
{ {
std::vector<std::string> ret; std::vector<std::string> ret;
std::stringstream ss(input); std::stringstream ss(str);
std::string token; std::string token;
while (std::getline(ss, token, delimiter)) { while (std::getline(ss, token, delimiter)) {
@@ -12,3 +12,13 @@ std::vector<std::string> splitLogFile(const std::string& input, char delimiter =
return ret; return ret;
} }
std::string userManager::getScanCommandFromUser(const std::string &user)
{
if (user.find("__groupfolder") != std::string::npos)
{
return std::string(SCAN_CMD_GRP) + splitString(user, '/').back();
}
return std::string(SCAN_CMD_USR) + user;
}

View File

@@ -4,25 +4,31 @@
#include <string> #include <string>
#include <map> #include <map>
#include <vector> #include <vector>
#include <set>
#include <sstream> #include <sstream>
#include "locations.h" #include <mutex>
#include "definitions.h"
std::vector<std::string> splitLogFile(const std::string& input, char delimiter); std::vector<std::string> splitString(const std::string& input, char delimiter);
class userManager class userManager
{ {
private: private:
std::map<std::string, bool> users; std::map<std::string, bool> users;
std::mutex mtx;
public: public:
static std::string getScanCommandFromUser(const std::string&);
void addUserFromLogLine(std::string &line) void addUserFromLogLine(std::string &line)
{ {
addUser(splitLogFile(line, '|').at(USER_LOG_LOCATION)); addUser(splitString(line, '|').at(USER_LOG_LOCATION));
} }
void addUser(std::string &user) void addUser(std::string &user)
{ {
std::lock_guard<std::mutex> lock(mtx);
if (users.count(user) == 0) if (users.count(user) == 0)
{ {
users[user] = false; users[user] = false;
@@ -31,16 +37,19 @@ public:
void removeUser(std::string &user) void removeUser(std::string &user)
{ {
std::lock_guard<std::mutex> lock(mtx);
users.erase(user); users.erase(user);
} }
bool isContains(std::string &user) bool isContains(std::string &user)
{ {
std::lock_guard<std::mutex> lock(mtx);
return users.count(user) == 1; return users.count(user) == 1;
} }
void setUserFlagged(std::string &user) void setUserFlagged(std::string &user)
{ {
std::lock_guard<std::mutex> lock(mtx);
if (users.count(user) == 1) if (users.count(user) == 1)
{ {
users[user] = true; users[user] = true;
@@ -49,6 +58,7 @@ public:
void setUserUnflagged(std::string &user) void setUserUnflagged(std::string &user)
{ {
std::lock_guard<std::mutex> lock(mtx);
if (users.count(user) == 1) if (users.count(user) == 1)
{ {
users[user] = false; users[user] = false;
@@ -57,38 +67,56 @@ public:
void unflagAllUsers() void unflagAllUsers()
{ {
std::lock_guard<std::mutex> lock(mtx);
for (std::map<std::string, bool>::iterator it = users.begin(); it != users.end(); ++it) for (std::map<std::string, bool>::iterator it = users.begin(); it != users.end(); ++it)
{ {
it->second = false; it->second = false;
} }
} }
std::vector<std::string> getUsers() std::set<std::string> getUsers()
{ {
std::vector<std::string> ret; std::set<std::string> ret;
std::lock_guard<std::mutex> lock(mtx);
for (std::map<std::string, bool>::iterator it = users.begin(); it != users.end(); ++it) for (std::map<std::string, bool>::iterator it = users.begin(); it != users.end(); ++it)
{ {
ret.push_back(it->first); ret.insert(it->first);
} }
return ret; return ret;
} }
std::vector<std::string> getFlaggedUsers() std::set<std::string> getFlaggedUsers()
{ {
std::vector<std::string> ret; std::set<std::string> ret;
std::lock_guard<std::mutex> lock(mtx);
for (std::map<std::string, bool>::iterator it = users.begin(); it != users.end(); ++it) for (std::map<std::string, bool>::iterator it = users.begin(); it != users.end(); ++it)
{ {
if (it->second) if (it->second)
{ {
ret.push_back(it->first); ret.insert(it->first);
} }
} }
return ret; return ret;
} }
bool isAnybodyFlagged()
{
std::lock_guard<std::mutex> lock(mtx);
for (std::map<std::string, bool>::iterator it = users.begin(); it != users.end(); ++it)
{
if (it->second)
return true;
}
return false;
}
}; };
#endif // _USERMAN_H #endif // _USERMAN_H