samba-vscan/icap vscan-icap.c,1.14.2.3,1.14.2.4 vscan-icap.h,1.4.2.1,1.4.2.2

Rainer Link <[email protected]> Tue, 28 Sep 2004 15:54:37 +0000
Newsgroups gmane.comp.security.virus.openantivirus.cvs
Message-ID <[email protected]>
Update of /cvsroot/openantivirus/samba-vscan/icap
In directory sc8-pr-cvs1.sourceforge.net:/tmp/cvs-serv5612/icap

Modified Files:
      Tag: VSCAN_0_3
	vscan-icap.c vscan-icap.h 
Log Message:
updated to use the new global configuration parsing module	


Index: vscan-icap.c
===================================================================
RCS file: /cvsroot/openantivirus/samba-vscan/icap/vscan-icap.c,v
retrieving revision 1.14.2.3
retrieving revision 1.14.2.4
diff -u -d -r1.14.2.3 -r1.14.2.4
--- vscan-icap.c	25 Sep 2004 12:27:05 -0000	1.14.2.3
+++ vscan-icap.c	28 Sep 2004 15:54:35 -0000	1.14.2.4
@@ -43,33 +43,10 @@
 
 #define VSCAN_MODULE_STR "vscan-icap"
 
-fstring config_file;            /* location of config file, either
-                                   PARAMCONF or as set via vfs options
-                                */
+vscan_config_struct vscan_config; /* contains the vscan module configuration */
 
-ssize_t max_size;          	/* do not scan files greater than max_size
-                                   if max_size = 0, scan any file
-                                */
 
 BOOL verbose_file_logging;  	/* log ever file access */
-
-BOOL scan_on_open;         	/* scan a file before it is opened
-                                   Defaults to True
-                                */
-
-BOOL scan_on_close;        	/* scan a new file put on share or
-                                   if file was modified
-                                   Defaults to False
-                                */
-
-BOOL deny_access_on_error;      /* if connection to daemon fails,  should access to any
-                                   file be denied? Defaults to True 
-				*/
-
-
-BOOL deny_access_on_minor_error; /* if daemon returns non-critical error,
-                                    should access to the file be denied? */
-
 BOOL send_warning_message;	/* send a warning message using the windows
 				   messenger service? */
 
@@ -77,86 +54,26 @@
 unsigned short int icap_port;    /* port number ICAP server listens on */
 
 
-fstring quarantine_dir;	/* directory for infected files */
-fstring quarantine_prefix;	/* prefix    for infected files */
-
-enum infected_file_action_enum infected_file_action; /* what to do with infected files;
-                                                        defaults to quarantine */
-
-int max_lrufiles;               /* specified the maximum entries in lrufiles list */
-time_t lrufiles_invalidate_time; /* specified the time in seconds after the lifetime
-                                    of an entry is expired and entry will be invalidated */
-pstring exclude_file_types;	/* list of file types which should be excluded from scanning */
-
-
-
 /* module version */
 static const char module_id[]=VSCAN_MODULE_STR" "SAMBA_VSCAN_VERSION_STR;
 
 
 static BOOL do_parameter(const char *param, const char *value)
 {
-        if ( StrCaseCmp("max file size", param) == 0 ) {
-		/* FIXME: sanity check missing! what, if value is out of range?
-		   atoi returns int - what about LFS? atoi should be avoided!
-		*/
-                max_size = atoi(value);
-                DEBUG(3, ("max file size is: %d\n", max_size));
-        } else if ( StrCaseCmp("verbose file logging", param) == 0 ) {
-                set_boolean(&verbose_file_logging, value);
-                DEBUG(3, ("verbose file logging is: %d\n", verbose_file_logging));
-        } else if ( StrCaseCmp("scan on open", param) == 0 ) {
-                set_boolean(&scan_on_open, value);
-                DEBUG(3, ("scan on open: %d\n", scan_on_open));
-        } else if ( StrCaseCmp("scan on close", param) == 0 ) {
-                set_boolean(&scan_on_close, value);
-                DEBUG(3, ("scan on close is: %d\n", scan_on_close));
-        } else if ( StrCaseCmp("deny access on error", param) == 0 ) {
-                set_boolean(&deny_access_on_error, value);
-                DEBUG(3, ("deny access on error is: %d\n", deny_access_on_error));
-        } else if ( StrCaseCmp("deny access on minor error", param) == 0 ) {
-                set_boolean(&deny_access_on_minor_error, value);
-                DEBUG(3, ("deny access on minor error is: %d\n", deny_access_on_minor_error));
-        } else if ( StrCaseCmp("send warning message", param) == 0 ) {
-                set_boolean(&send_warning_message, value);
-                DEBUG(3, ("send warning message is: %d\n", send_warning_message));
-        } else if ( StrCaseCmp("infected file action", param) == 0 ) {
-		if (StrCaseCmp("quarantine", value) == 0) {
-			infected_file_action = INFECTED_QUARANTINE;
-		} else if (StrCaseCmp("delete", value) == 0) {
-			infected_file_action = INFECTED_DELETE;
-		} else if (StrCaseCmp("nothing", value) == 0) {
-			infected_file_action = INFECTED_DO_NOTHING;
-		} else {
-			DEBUG(2, ("samba-vscan: badly formed infected file action in configuration file, parameter %s\n", value));
-		}
-                DEBUG(3, ("infected file action is: %d\n", infected_file_action));
-        } else if ( StrCaseCmp("quarantine directory", param) == 0 ) {
-                fstrcpy(quarantine_dir, value);
-                DEBUG(3, ("quarantine directory is: %s\n", quarantine_dir));
-        } else if ( StrCaseCmp("quarantine prefix", param) == 0 ) {
-                fstrcpy(quarantine_prefix, value);
-                DEBUG(3, ("quarantine prefix is: %s\n", quarantine_prefix));
-        } else if ( StrCaseCmp("max lru files entries", param) == 0 ) {
-                max_lrufiles = atoi(value);
-                DEBUG(3, ("max lru files entries is: %d\n", max_lrufiles));
-        } else if ( StrCaseCmp("lru file entry lifetime", param) == 0 ) {
-                lrufiles_invalidate_time = atol(value);
-                DEBUG(3, ("lru file entry lifetime is: %li\n", (long)lrufiles_invalidate_time));
-        } else if ( StrCaseCmp("icap ip", param) == 0 ) {
-                fstrcpy(icap_ip, value);
-                DEBUG(3, ("ICAP server IP is: %s\n", icap_ip));
-	} else if ( StrCaseCmp("exclude file types", param) == 0 ) {
-		pstrcpy(exclude_file_types, value);
-		DEBUG(3, ("Exclude list is: %s\n", exclude_file_types));
-        } else if ( StrCaseCmp("icap port", param) == 0 ) {
-                /* FIXME: icap_ip is short int ! atoi converts string to int
-                   overflow is possible. Should a check be added, if port number
-                   is too high? */
-                icap_port = atoi(value);
-                DEBUG(3, ("ICAP server port is: %d\n", icap_port));
-        } else
-                DEBUG(3, ("unknown parameter: %s\n", param));
+        if ( do_common_parameter(&vscan_config, param, value) == False ) {
+                /* parse VFS module specific configuration values */
+        	if ( StrCaseCmp("icap ip", param) == 0 ) {
+                	fstrcpy(icap_ip, value);
+	                DEBUG(3, ("ICAP server IP is: %s\n", icap_ip));
+        	} else if ( StrCaseCmp("icap port", param) == 0 ) {
+                	/* FIXME: icap_ip is short int ! atoi converts string to int
+                   	overflow is possible. Should a check be added, if port number
+                   	is too high? */
+                	icap_port = atoi(value);
+                	DEBUG(3, ("ICAP server port is: %d\n", icap_port));
+        	} else
+                	DEBUG(3, ("unknown parameter: %s\n", param));
+	}
 
         return True;
 }
@@ -178,6 +95,11 @@
 static int vscan_connect(struct connection_struct *conn, PROTOTYPE_CONST char *svc, PROTOTYPE_CONST char *user)
 #endif
 {
+        fstring config_file;            /* location of config file, either
+                                           PARAMCONF or as set via vfs options
+                                        */
+
+
 	#if (SAMBA_VERSION_MAJOR==2 && SAMBA_VERSION_RELEASE>=4) || SAMBA_VERSION_MAJOR==3
 	 #if !(SMB_VFS_INTERFACE_VERSION >= 6)
           pstring opts_str;
@@ -193,95 +115,37 @@
         /* set default value for configuration files */
         fstrcpy(config_file, PARAMCONF);
 
-        /* set default value for max file size */
-        max_size = VSCAN_MAX_SIZE;
-
-        /* set default value for file logging */
-        verbose_file_logging = VSCAN_VERBOSE_FILE_LOGGING;
-
-        /* set default value for scan on open() */
-        scan_on_open = VSCAN_SCAN_ON_OPEN;
-
-        /* set default value for scan on close() */
-        scan_on_close = VSCAN_SCAN_ON_CLOSE;
-
-        /* set default value for deny access on error */
-        deny_access_on_error = VSCAN_DENY_ACCESS_ON_ERROR;
-
-	/* set default value for deny access on minor error */
-	deny_access_on_minor_error = VSCAN_DENY_ACCESS_ON_MINOR_ERROR;
- 
-	/* set default value for send warning message */
-	send_warning_message = VSCAN_SEND_WARNING_MESSAGE;
-
-        /* set default value for infected file action */
-        infected_file_action = VSCAN_INFECTED_FILE_ACTION;
-
-        /* set default value for quarantine directory */
-        fstrcpy(quarantine_dir, VSCAN_QUARANTINE_DIRECTORY);
-
-        /* set default value for quarantine prefix */
-        fstrcpy(quarantine_prefix, VSCAN_QUARANTINE_PREFIX);
+        /* set default values */
+        set_common_default_settings(&vscan_config);
 
-        /* set default value for OAV ScannerDaemon IP */
-        fstrcpy(icap_ip, VSCAN_ICAP_IP);
 
         /* set default value for OAV ScannerDaemon port */
         icap_port = VSCAN_ICAP_PORT;
 
-        /* set default value for maximum lrufile entries */
-        max_lrufiles = VSCAN_MAX_LRUFILES;
-
-        /* time after an entry is considered as expired */
-        lrufiles_invalidate_time = VSCAN_LRUFILES_INVALIDATE_TIME;
-
-	/* file type exclude ist */
-	pstrcpy(exclude_file_types, VSCAN_FT_EXCLUDE_LIST);
-
 	vscan_syslog("INFO: connect to service %s by user %s", 
 	       svc, user);
 
 	#if (SAMBA_VERSION_MAJOR==2 && SAMBA_VERSION_RELEASE>=4) || SAMBA_VERSION_MAJOR==3
-	 #if (SMB_VFS_INTERFACE_VERSION >= 6)
-	  fstrcpy(config_file, lp_parm_const_string(SNUM(conn),VSCAN_MODULE_STR,"config-file",PARAMCONF));
-	 #else
-          pstrcpy(opts_str, (const char*) lp_vfs_options(SNUM(conn)));
-          if( !*opts_str ) {
-                DEBUG(3, ("samba-vscan: no configuration file set - using default value (%s).\n", lp_vfs_options(SNUM(conn))));
-          } else {
-                p = opts_str;
-                if ( next_token(&p, config_file, "=", sizeof(config_file)) ) {
-                        trim_string(config_file, " ", " ");
-                        if ( !strequal("config-file", config_file) ) {
-                                DEBUG(3, ("samba-vscan - connect: options %s is not config-file\n", config_file));
-                                /* setting default value */
-                                fstrcpy(config_file, PARAMCONF);
 
-                        } else {
-                                if ( !next_token(&p, config_file," \n",sizeof(config_file)) ) {
-                                        DEBUG(3, ("samba-vscan - connect: no option after config-file=\n"));
-                                        /* setting default value */
-                                        fstrcpy(config_file, PARAMCONF);
-                                } else {
-                                        trim_string(config_file, " ", " ");
-                                        DEBUG(3, ("samba-vscan - connect: config file name is %s\n", config_file));
-                                }
-                        }
-                }
-          }
-	  #endif /*  #if (SMB_VFS_INTERFACE_VERSION >= 6)*/
+          fstrcpy(config_file, get_configuration_file(conn, VSCAN_MODULE_STR, PARAMCONF));
+          DEBUG(0, ("configuration file is: %s\n", config_file));
           retval = pm_process(config_file, do_section, do_parameter);
           DEBUG(10, ("pm_process returned %d\n", retval));
+
+         /* FIXME: this is lame! */
+          verbose_file_logging = vscan_config.common.verbose_file_logging;
+          send_warning_message = vscan_config.common.send_warning_message;	
+
 	  if (!retval) vscan_syslog("ERROR: could not parse configuration file '%s'. File not found or not read-able. Using compiled-in defaults", config_file);
 	#endif
 
         /* initialise lrufiles list */
         DEBUG(5, ("init lrufiles list\n"));
-        lrufiles_init(max_lrufiles, lrufiles_invalidate_time);
+        lrufiles_init(vscan_config.common.max_lrufiles, vscan_config.common.lrufiles_invalidate_time);
 
 	/* initialise filetype */
 	DEBUG(5, ("init file type\n"));
-	filetype_init(0, exclude_file_types);
+	filetype_init(0, vscan_config.common.exclude_file_types);
 
 
 	#if (SMB_VFS_INTERFACE_VERSION >= 6)
@@ -328,13 +192,12 @@
 	int rc;
 
 	/* Assemble complete file path */
-	pstrcpy(filepath, conn->connectpath);
 	pstrcat(filepath, "/");
 	pstrcat(filepath, fname);
 
 
         /* scan files while opening? */
-        if ( !scan_on_open ) {
+        if ( !vscan_config.common.scan_on_open ) {
                 DEBUG(3, ("samba-vscan - open: File '%s' not scanned as scan_on_open is not set\n", fname));
 #if (SMB_VFS_INTERFACE_VERSION >= 6)
 		return SMB_VFS_NEXT_OPEN(handle, conn, fname, flags, mode);
@@ -356,7 +219,7 @@
 #else
 		return default_vfs_ops.open(conn, fname, flags, mode);
 #endif
-	else if ( ( stat_buf.st_size > max_size ) && ( max_size > 0 ) ) /* file is too large */
+	else if ( ( stat_buf.st_size > vscan_config.common.max_size ) && ( vscan_config.common.max_size > 0 ) ) /* file is too large */
 		vscan_syslog("INFO: File %s is larger than specified maximum file size! Not scanned!", fname);
 	else if ( stat_buf.st_size == 0 ) /* do not scan empty files */
 #if (SMB_VFS_INTERFACE_VERSION >= 6)
@@ -377,7 +240,7 @@
 		/* open socket */
 		sockfd = vscan_icap_init();
 
-                if ( sockfd == -1 && deny_access_on_error ) {
+                if ( sockfd == -1 && vscan_config.common.deny_access_on_error ) {
                         /* an error occured - can not communicate to daemon - deny access */
                         vscan_syslog("ERROR: can not communicate to daemon - access denied");
                         errno = EACCES;
@@ -420,7 +283,7 @@
 
 			/* scan file */
 			retval = vscan_icap_scanfile(sockfd, filepath, client_ip);
-			if ( retval == VSCAN_SCAN_MINOR_ERROR && deny_access_on_minor_error ) {
+			if ( retval == VSCAN_SCAN_MINOR_ERROR && vscan_config.common.deny_access_on_minor_error ) {
 				/* a minor error occured - deny access */
 				vscan_syslog("ERROR: daemon failed with a minor error - access to file %s denied", fname);
 				vscan_icap_end(sockfd);
@@ -431,7 +294,7 @@
                                 /* deny access */
 				errno = EACCES;
 				return -1;
-                        } else if ( retval == VSCAN_SCAN_ERROR && deny_access_on_error ) {
+                        } else if ( retval == VSCAN_SCAN_ERROR && vscan_config.common.deny_access_on_error ) {
                                 /* an error occured - can not communicate to daemon - deny access */
                                 vscan_syslog("ERROR: can not communicate to daemon - access to file %s denied", fname);
                                 vscan_icap_end(sockfd);
@@ -449,9 +312,9 @@
 				/* do action ... */
 				
 #if (SMB_VFS_INTERFACE_VERSION >= 6)
-				rc = vscan_do_infected_file_action(handle, conn, filepath, quarantine_dir, quarantine_prefix, infected_file_action);
+				rc = vscan_do_infected_file_action(handle, conn, filepath, vscan_config.common.quarantine_dir, vscan_config.common.quarantine_prefix, vscan_config.common.infected_file_action);
 #else
-				rc = vscan_do_infected_file_action(&default_vfs_ops, conn, filepath, quarantine_dir, quarantine_prefix, infected_file_action);
+				rc = vscan_do_infected_file_action(&default_vfs_ops, conn, filepath, vscan_config.common.quarantine_dir, vscan_config.common.quarantine_prefix, vscan_config.common.infected_file_action);
 #endif
 
                                 /* add/update file. mark file as infected! */
@@ -495,7 +358,7 @@
         retval = default_vfs_ops.close(fsp, fd);
 #endif
 
-        if ( !scan_on_close ) {
+        if ( !vscan_config.common.scan_on_close ) {
                 DEBUG(3, ("samba-vscan - close: File '%s' not scanned as scan_on_close is not set\n", fsp->fsp_name));
                 return retval;
         }
@@ -536,9 +399,9 @@
 		if ( rv == VSCAN_SCAN_VIRUS_FOUND ) {
 			/* virus was found */
 #if (SMB_VFS_INTERFACE_VERSION >= 6)
-			rc = vscan_do_infected_file_action(handle, fsp->conn, filepath, quarantine_dir, quarantine_prefix, infected_file_action);
+			rc = vscan_do_infected_file_action(handle, fsp->conn, filepath, vscan_config.common.quarantine_dir, vscan_config.common.quarantine_prefix, vscan_config.common.infected_file_action);
 #else
-			rc = vscan_do_infected_file_action(&default_vfs_ops, fsp->conn, filepath, quarantine_dir, quarantine_prefix, infected_file_action);
+			rc = vscan_do_infected_file_action(&default_vfs_ops, fsp->conn, filepath, vscan_config.common.quarantine_dir, vscan_config.common.quarantine_prefix, vscan_config.common.infected_file_action);
 #endif
 		}
 

Index: vscan-icap.h
===================================================================
RCS file: /cvsroot/openantivirus/samba-vscan/icap/vscan-icap.h,v
retrieving revision 1.4.2.1
retrieving revision 1.4.2.2
diff -u -d -r1.4.2.1 -r1.4.2.2
--- vscan-icap.h	12 Sep 2003 07:12:15 -0000	1.4.2.1
+++ vscan-icap.h	28 Sep 2004 15:54:35 -0000	1.4.2.2
@@ -10,71 +10,6 @@
 
 #define PARAMCONF "/etc/samba/vscan-icap.conf"
 
-
-/* False = log only infected file, True = log every file access */
- 
-#ifndef VSCAN_VERBOSE_FILE_LOGGING
-# define VSCAN_VERBOSE_FILE_LOGGING False
-#endif
- 
-/* if a file is bigger than VSCAN_MAX_SIZE it won't be scanned. Has to be
-   specified in bytes! If it set to 0, the file size check is disabled */
- 
-#ifndef VSCAN_MAX_SIZE
-# define VSCAN_MAX_SIZE 0
-#endif
-  
-
-/* True = scan files on open */
- 
-#ifndef VSCAN_SCAN_ON_OPEN
-# define VSCAN_SCAN_ON_OPEN True
-#endif
-
-/* True = scan files on close */
-
-#ifndef VSCAN_SCAN_ON_CLOSE
-# define VSCAN_SCAN_ON_CLOSE False
-#endif
-
-
-/* True = deny access in case of virus scanning failure */
-
-#ifndef VSCAN_DENY_ACCESS_ON_ERROR
-# define VSCAN_DENY_ACCESS_ON_ERROR True
-#endif
-
-/* True = deny access in case of minor virus scanning failure */
-
-#ifndef VSCAN_DENY_ACCESS_ON_MINOR_ERROR
-# define VSCAN_DENY_ACCESS_ON_MINOR_ERROR True
-#endif
-
-/* True = send a warning message via window messenger service for viruses found */
-
-#ifndef VSCAN_SEND_WARNING_MESSAGE
-# define VSCAN_SEND_WARNING_MESSAGE True
-#endif
-
-/* default infected file action */
-#define VSCAN_INFECTED_FILE_ACTION INFECTED_QUARANTINE
-
-/* default quarantine settings; hopefully the user changes this */
-#define VSCAN_QUARANTINE_DIRECTORY "/tmp"
-#define VSCAN_QUARANTINE_PREFIX    "vir-"
-
-
-/* set default value for maximum lrufile entries */
-#define VSCAN_MAX_LRUFILES 100
-
-/* time after an entry is considered as expired */
-#define VSCAN_LRUFILES_INVALIDATE_TIME 5
-
-/* MIME-types of files to be exluded from scanning; that's an
-   semi-colon seperated list */
-#define VSCAN_FT_EXCLUDE_LIST ""
-
-
 /* IP:PORT ICAP server listens on */
 #define VSCAN_ICAP_IP    "127.0.0.1"
 #define VSCAN_ICAP_PORT  1344



-------------------------------------------------------
This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170
Project Admins to receive an Apple iPod Mini FREE for your judgement on
who ports your project to Linux PPC the best. Sponsored by IBM.
Deadline: Sept. 24. Go here: http://sf.net/ppc_contest.php