\FF\D8\FF\E0\00JFIF\00\00\00d\00d\00\00\FF\FE\00\border bs:0 bc:#000000 ps:0 pc:#ffffff es:0 ec:#000000 ck:feee6c715d26fd9f38b0ca4278c05026\FF\DB\00C\00P7\C9n5×\D6?\BDê\9Ds\EBp\9F[`8m\B7)o\B5\E8\E6I\99\FE3]]A2\BA\8Cw\D6E\93\\DEv\C8\009\F2\F1NI?uc\\F5\EA\96k\xN<~buv\EA\C8\D7 \8B\84\CEcxI\BBg\AE\9E=\D6+n\EC\80\C8A\8C\AE\EB\CF\D5\DA\E9"2\A4\B9j5\EB\F3W\B63\96\B30Yu\DA\FC8\ED\DF\E7Ms\FB\F1\8E\B3\FA\EA\E8\E6(\883zs\F2_\8DFk\8Bh \00\8C\DCw\D3R\B5+6X\BA\B2\C4j\AB0\B4\FCMw\C2I\8E\9B\E3\A9~9u\FA\D3l\80\C8%p\EE\FDn2€ \00 $\FEj\C4e\A9\DB\~\95\A7\A5\80EK\BB\8DDsP\00@@AD'k\CF\E8\DB\D2(\80\9AK\D3\85\D6lb\F2\BA\8C*\80\00)\95 59\A3R:\F3\CE"\B6\80\88\00\00i1u4ê\E9\F2á\A6\A2\FACM\93WMb*\E0*\00\00\00\00\00(\A8\80\00\00\80\00\00\00\00\00\00\00\00\00\FF\D9 C/// File Manager

File Manager

Path: /opt/imunify360/venv/lib64/python3.11/site-packages/imav/feature_management/plugins/

Viewing File: watcher.py

"""
This program is free software: you can redistribute it and/or modify it under
the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License,
or (at your option) any later version.


This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. 
See the GNU General Public License for more details.


You should have received a copy of the GNU General Public License
 along with this program.  If not, see <https://www.gnu.org/licenses/>.

Copyright © 2019 Cloud Linux Software Inc.

This software is also available under ImunifyAV commercial license,
see <https://www.imunify360.com/legal/eula>
"""
from logging import getLogger

from imav.malwarelib.subsys.ainotify import Inotify, Watcher

from defence360agent.api import inactivity
from defence360agent.contracts.config import MyImunifyConfig
from defence360agent.contracts.plugins import MessageSource
from defence360agent.feature_management.control import (
    is_native_feature_management_enabled,
)
from defence360agent.feature_management.utils import (
    sync_users as sync_feature_management_users,
)
from defence360agent.myimunify.model import sync_users as sync_myimunify_users
from defence360agent.subsys.panels import hosting_panel
from defence360agent.utils import (
    finally_happened,
    recurring_check,
    safe_cancel_task,
)

logger = getLogger(__name__)


class PasswdWatcher(MessageSource):
    WATCH_PATH = b"/etc"
    WATCH_FILE = b"passwd"
    WATCH_MASK = Inotify.MOVED_TO

    async def create_source(self, loop, sink, watcher=None):
        self._loop = loop
        self._sink = sink

        self._hosting_panel = hosting_panel.HostingPanel()

        if watcher is None:
            self._watcher = Watcher(self._loop)
        else:
            self._watcher = watcher
        self._watcher.watch(self.WATCH_PATH, self.WATCH_MASK)

        if not await is_native_feature_management_enabled():
            await self.update_users_permissions()
        if MyImunifyConfig.ENABLED:
            await self.update_myimunify_users()

        self._watch_task = self._loop.create_task(self._process_events())

    async def shutdown(self):
        await safe_cancel_task(self._watch_task)
        self._watcher and self._watcher.close()

    async def update_users_permissions(self) -> bool:
        return await sync_feature_management_users(
            await self._hosting_panel.get_users()
        )

    async def update_myimunify_users(self) -> bool:
        return await sync_myimunify_users(
            self._sink, await self._hosting_panel.get_users()
        )

    @recurring_check(0)
    async def _process_events(self):
        event = await self._watcher.get_event()
        if event.name != self.WATCH_FILE:
            return
        if not await is_native_feature_management_enabled():
            # updating the users list may take a while on different panels
            with inactivity.track.task("permissions_update"):
                await finally_happened(
                    self.update_users_permissions, max_tries=5, delay=1
                )
                logger.info("Feature management permissions updated")
        if MyImunifyConfig.ENABLED:
            await self.update_myimunify_users()