forked from moodle/moodle
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
MDL-71627 check: Add AV status, notification levels and more logging
- `notifylevel` will change what gets sent as part of the antivirus notification emails based on the scan type. For example if set on SCAN_RESULT_FOUND, it will not notify for any detections, if set to SCAN_RESULT_ERROR, it will notify for both detections and errors. - `threshold` will determine how far the lookback is when displaying the status of the /reports/status (System Status) page. It will display as an ERROR state if there has been scanner issues within this certain threshold period - As part of the above, scanner errors will now trigger a new event which will be logged as antivirus_scan_data_error or antivirus_scan_file_error. Due to the nature of it reading from the logs table, it only works currently for the "Standard logging" logstore.
- Loading branch information
Showing
10 changed files
with
452 additions
and
17 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,123 @@ | ||
<?php | ||
// This file is part of Moodle - http://moodle.org/ | ||
// | ||
// Moodle is free software: you can redistribute it and/or modify | ||
// it under the terms of the GNU General Public License as published by | ||
// the Free Software Foundation, either version 3 of the License, or | ||
// (at your option) any later version. | ||
// | ||
// Moodle is distributed in the hope that it will be useful, | ||
// but WITHOUT ANY WARRANTY; without even the implied warranty of | ||
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | ||
// GNU General Public License for more details. | ||
// | ||
// You should have received a copy of the GNU General Public License | ||
// along with Moodle. If not, see <http://www.gnu.org/licenses/>. | ||
|
||
namespace core\check\environment; | ||
|
||
defined('MOODLE_INTERNAL') || die(); | ||
|
||
use core\check\check; | ||
use core\check\result; | ||
|
||
/** | ||
* Checks status of antivirus scanners by looking back at any recent scans. | ||
* | ||
* @package core | ||
* @category check | ||
* @author Kevin Pham <[email protected]> | ||
* @copyright Catalyst IT, 2021 | ||
* @license http://www.gnu.org/copyleft/gpl.html GNU GPL v3 or later | ||
*/ | ||
class antivirus extends check { | ||
|
||
/** | ||
* Get the short check name | ||
* | ||
* @return string | ||
*/ | ||
public function get_name(): string { | ||
return get_string('check_antivirus_name', 'report_security'); | ||
} | ||
|
||
/** | ||
* A link to a place to action this | ||
* | ||
* @return action_link|null | ||
*/ | ||
public function get_action_link(): ?\action_link { | ||
return new \action_link( | ||
new \moodle_url('/admin/settings.php', ['section' => 'manageantiviruses']), | ||
get_string('antivirussettings', 'antivirus')); | ||
} | ||
|
||
/** | ||
* Return result | ||
* @return result | ||
*/ | ||
public function get_result(): result { | ||
global $CFG, $DB; | ||
$details = \html_writer::tag('p', get_string('check_antivirus_details', 'report_security')); | ||
|
||
// If no scanners are enabled, then return an NA status since the results do not matter. | ||
if (empty($CFG->antiviruses)) { | ||
$status = result::NA; | ||
$summary = get_string('check_antivirus_info', 'report_security'); | ||
return new result($status, $summary, $details); | ||
} | ||
|
||
$logmanager = get_log_manager(); | ||
$readers = $logmanager->get_readers('\core\log\sql_internal_table_reader'); | ||
|
||
// If reader is not a sql_internal_table_reader return UNKNOWN since we | ||
// aren't able to fetch the required information. Legacy logs are not | ||
// supported here. They do not hold enough adequate information to be | ||
// used for these checks. | ||
if (empty($readers)) { | ||
$status = result::UNKNOWN; | ||
$summary = get_string('check_antivirus_logstore_not_supported', 'report_security'); | ||
return new result($status, $summary, $details); | ||
} | ||
|
||
$reader = reset($readers); | ||
|
||
// If there has been a recent timestamp within threshold period, then | ||
// set the status to ERROR and describe the problem, e.g. X issues in | ||
// the last N period. | ||
$threshold = get_config('antivirus', 'threshold'); | ||
$params = []; | ||
$params['lookback'] = time() - $threshold; | ||
|
||
// Type of "targets" to include. | ||
list($targetsqlin, $inparams) = $DB->get_in_or_equal([ | ||
'antivirus_scan_file', | ||
'antivirus_scan_data', | ||
], SQL_PARAMS_NAMED); | ||
$params = array_merge($inparams, $params); | ||
|
||
// Specify criteria for search. | ||
$selectwhere = "timecreated > :lookback | ||
AND target $targetsqlin | ||
AND action = 'error'"; | ||
|
||
$totalerrors = $reader->get_events_select_count($selectwhere, $params); | ||
if (!empty($totalerrors)) { | ||
$status = result::ERROR; | ||
$summary = get_string('check_antivirus_error', 'report_security', [ | ||
'errors' => $totalerrors, | ||
'lookback' => format_time($threshold) | ||
]); | ||
} else if (!empty($CFG->antiviruses)) { | ||
$status = result::OK; | ||
// Fetch count of enabled antiviruses (we don't care about which ones). | ||
$totalantiviruses = !empty($CFG->antiviruses) ? count(explode(',', $CFG->antiviruses)) : 0; | ||
$summary = get_string('check_antivirus_ok', 'report_security', [ | ||
'scanners' => $totalantiviruses, | ||
'lookback' => format_time($threshold) | ||
]); | ||
} | ||
return new result($status, $summary, $details); | ||
} | ||
} | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,69 @@ | ||
<?php | ||
// This file is part of moodle - http://moodle_org/ | ||
// | ||
// Moodle is free software: you can redistribute it and/or modify | ||
// it under the terms of the GNU General Public License as published by | ||
// the Free Software Foundation, either version 3 of the License, or | ||
// (at your option) any later version. | ||
// | ||
// Moodle is distributed in the hope that it will be useful, | ||
// but WITHOUT ANY WARRANTY; without even the implied warranty of | ||
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | ||
// GNU General Public License for more details. | ||
// | ||
// You should have received a copy of the GNU General Public License | ||
// along with Moodle. If not, see <http://www.gnu.org/licenses/>. | ||
|
||
namespace core\event; | ||
|
||
defined('MOODLE_INTERNAL') || die(); | ||
/** | ||
* Antivirus scan data error event | ||
* | ||
* @package core | ||
* @author Kevin Pham <[email protected]> | ||
* @copyright Catalyst IT, 2021 | ||
* @license http://www.gnu.org/copyleft/gpl.html GNU GPL v3 or later | ||
*/ | ||
class antivirus_scan_data_error extends \core\event\base { | ||
/** | ||
* Event data | ||
*/ | ||
protected function init() { | ||
$this->data['crud'] = 'c'; | ||
$this->data['edulevel'] = self::LEVEL_OTHER; | ||
} | ||
|
||
/** | ||
* Return event description | ||
* | ||
* @return string description | ||
* @throws \coding_exception | ||
*/ | ||
public function get_description() { | ||
if (isset($this->other['incidentdetails'])) { | ||
return format_text($this->other['incidentdetails'], FORMAT_MOODLE); | ||
} else { | ||
return get_string('dataerrordesc', 'antivirus'); | ||
} | ||
} | ||
|
||
/** | ||
* Return event name | ||
* | ||
* @return string name | ||
* @throws \coding_exception | ||
*/ | ||
public static function get_name() { | ||
return get_string('dataerrorname', 'antivirus'); | ||
} | ||
|
||
/** | ||
* Return event report link | ||
* @return \moodle_url | ||
* @throws \moodle_exception | ||
*/ | ||
public function get_url() { | ||
return new \moodle_url('/report/infectedfiles/index.php'); | ||
} | ||
} |
Oops, something went wrong.