|
| 1 | +<?php |
| 2 | + |
| 3 | +declare(strict_types=1); |
| 4 | + |
| 5 | +/** |
| 6 | + * SPDX-FileCopyrightText: 2026 Nextcloud GmbH and Nextcloud contributors |
| 7 | + * SPDX-License-Identifier: AGPL-3.0-or-later |
| 8 | + */ |
| 9 | + |
| 10 | +namespace OC\Core\BackgroundJobs; |
| 11 | + |
| 12 | +use OC\Core\AppInfo\ConfigLexicon; |
| 13 | +use OC\IntegrityCheck\Checker; |
| 14 | +use OCP\AppFramework\Utility\ITimeFactory; |
| 15 | +use OCP\BackgroundJob\IJob; |
| 16 | +use OCP\BackgroundJob\TimedJob; |
| 17 | +use OCP\IAppConfig; |
| 18 | +use OCP\IConfig; |
| 19 | +use OCP\IGroupManager; |
| 20 | +use OCP\IL10N; |
| 21 | +use OCP\IURLGenerator; |
| 22 | +use OCP\IUser; |
| 23 | +use OCP\L10N\IFactory; |
| 24 | +use OCP\Mail\IMailer; |
| 25 | +use OCP\Notification\IManager as INotificationManager; |
| 26 | +use Psr\Log\LoggerInterface; |
| 27 | + |
| 28 | +/** |
| 29 | + * Re-runs the code integrity check daily and notifies and emails admins whenever |
| 30 | + * its result differs from the one they were last notified about. |
| 31 | + * Disabled by setting `integrity.check.scheduled` to false. |
| 32 | + */ |
| 33 | +class CheckCodeIntegrityJob extends TimedJob { |
| 34 | + public const NOTIFICATION_OBJECT_TYPE = 'code_integrity'; |
| 35 | + |
| 36 | + public function __construct( |
| 37 | + ITimeFactory $time, |
| 38 | + private readonly Checker $checker, |
| 39 | + private readonly IConfig $config, |
| 40 | + private readonly IAppConfig $appConfig, |
| 41 | + private readonly IGroupManager $groupManager, |
| 42 | + private readonly INotificationManager $notificationManager, |
| 43 | + private readonly IMailer $mailer, |
| 44 | + private readonly IFactory $l10nFactory, |
| 45 | + private readonly IURLGenerator $urlGenerator, |
| 46 | + private readonly LoggerInterface $logger, |
| 47 | + ) { |
| 48 | + parent::__construct($time); |
| 49 | + |
| 50 | + $this->setInterval(24 * 60 * 60); |
| 51 | + $this->setTimeSensitivity(IJob::TIME_INSENSITIVE); |
| 52 | + $this->setAllowParallelRuns(false); |
| 53 | + } |
| 54 | + |
| 55 | + #[\Override] |
| 56 | + protected function run($argument): void { |
| 57 | + if (!$this->config->getSystemValueBool('integrity.check.scheduled', true) |
| 58 | + || !$this->checker->isCodeCheckEnforced()) { |
| 59 | + return; |
| 60 | + } |
| 61 | + |
| 62 | + $this->checker->runInstanceVerification(); |
| 63 | + $results = $this->checker->getResults() ?? []; |
| 64 | + |
| 65 | + $fingerprint = $this->fingerprint($results); |
| 66 | + $notifiedFingerprint = $this->appConfig->getValueString('core', ConfigLexicon::INTEGRITY_CHECK_NOTIFIED_RESULT, lazy: true); |
| 67 | + if ($fingerprint === $notifiedFingerprint) { |
| 68 | + return; |
| 69 | + } |
| 70 | + |
| 71 | + if ($notifiedFingerprint !== '') { |
| 72 | + $notification = $this->notificationManager->createNotification(); |
| 73 | + $notification->setApp('core') |
| 74 | + ->setObject(self::NOTIFICATION_OBJECT_TYPE, $notifiedFingerprint); |
| 75 | + $this->notificationManager->markProcessed($notification); |
| 76 | + } |
| 77 | + |
| 78 | + if ($fingerprint !== '') { |
| 79 | + $this->notifyAdmins($fingerprint, $this->summarize($results)); |
| 80 | + } |
| 81 | + |
| 82 | + $this->appConfig->setValueString('core', ConfigLexicon::INTEGRITY_CHECK_NOTIFIED_RESULT, $fingerprint, lazy: true); |
| 83 | + } |
| 84 | + |
| 85 | + /** |
| 86 | + * Stable hash of the check result, or an empty string when the check passed |
| 87 | + */ |
| 88 | + private function fingerprint(array $results): string { |
| 89 | + $entries = []; |
| 90 | + foreach ($results as $scope => $scopeResult) { |
| 91 | + foreach ($scopeResult as $type => $details) { |
| 92 | + if ($type === 'EXCEPTION') { |
| 93 | + $entries[] = json_encode([$scope, $type, $details['message'] ?? ''], JSON_THROW_ON_ERROR); |
| 94 | + continue; |
| 95 | + } |
| 96 | + foreach ($details as $file => $hashes) { |
| 97 | + $entries[] = json_encode([$scope, $type, $file, $hashes['current'] ?? ''], JSON_THROW_ON_ERROR); |
| 98 | + } |
| 99 | + } |
| 100 | + } |
| 101 | + |
| 102 | + if ($entries === []) { |
| 103 | + return ''; |
| 104 | + } |
| 105 | + |
| 106 | + // Scope and file order depend on filesystem iteration order |
| 107 | + sort($entries); |
| 108 | + return hash('sha256', implode("\n", $entries)); |
| 109 | + } |
| 110 | + |
| 111 | + /** |
| 112 | + * Number of files that failed, and the scopes (core or app ids) whose |
| 113 | + * signature could not be verified at all |
| 114 | + * |
| 115 | + * @return array{files: int, unverified: list<string>} |
| 116 | + */ |
| 117 | + private function summarize(array $results): array { |
| 118 | + $files = 0; |
| 119 | + $unverified = []; |
| 120 | + foreach ($results as $scope => $scopeResult) { |
| 121 | + foreach ($scopeResult as $type => $entries) { |
| 122 | + if ($type === 'EXCEPTION') { |
| 123 | + $unverified[] = (string)$scope; |
| 124 | + } elseif (is_array($entries)) { |
| 125 | + $files += count($entries); |
| 126 | + } |
| 127 | + } |
| 128 | + } |
| 129 | + sort($unverified); |
| 130 | + return ['files' => $files, 'unverified' => $unverified]; |
| 131 | + } |
| 132 | + |
| 133 | + /** |
| 134 | + * Human readable sentences for a summary, shared by the notification and the email |
| 135 | + * |
| 136 | + * @param array{files?: int, unverified?: list<string>} $summary |
| 137 | + * @return list<string> |
| 138 | + */ |
| 139 | + public static function formatSummary(IL10N $l, array $summary): array { |
| 140 | + $files = (int)($summary['files'] ?? 0); |
| 141 | + $unverified = $summary['unverified'] ?? []; |
| 142 | + |
| 143 | + $sentences = []; |
| 144 | + if ($files > 0) { |
| 145 | + $sentences[] = $l->n( |
| 146 | + '%n file does not match the signed release. It may have been modified or added without authorization.', |
| 147 | + '%n files do not match the signed release. They may have been modified or added without authorization.', |
| 148 | + $files, |
| 149 | + ); |
| 150 | + } |
| 151 | + if ($unverified !== []) { |
| 152 | + $sentences[] = $l->n( |
| 153 | + 'The signature of %s is missing or invalid, so it could not be verified.', |
| 154 | + 'The signatures of %s are missing or invalid, so they could not be verified.', |
| 155 | + count($unverified), |
| 156 | + [implode(', ', $unverified)], |
| 157 | + ); |
| 158 | + } |
| 159 | + return $sentences; |
| 160 | + } |
| 161 | + |
| 162 | + /** |
| 163 | + * @param array{files: int, unverified: list<string>} $summary |
| 164 | + */ |
| 165 | + private function notifyAdmins(string $fingerprint, array $summary): void { |
| 166 | + $admins = $this->groupManager->get('admin')?->getUsers() ?? []; |
| 167 | + if ($admins === []) { |
| 168 | + return; |
| 169 | + } |
| 170 | + |
| 171 | + $notification = $this->notificationManager->createNotification(); |
| 172 | + $notification->setApp('core') |
| 173 | + ->setDateTime($this->time->getDateTime()) |
| 174 | + ->setObject(self::NOTIFICATION_OBJECT_TYPE, $fingerprint) |
| 175 | + ->setSubject('code_integrity_changed', $summary); |
| 176 | + |
| 177 | + foreach ($admins as $admin) { |
| 178 | + $notification->setUser($admin->getUID()); |
| 179 | + $this->notificationManager->notify($notification); |
| 180 | + $this->sendMail($admin, $summary); |
| 181 | + } |
| 182 | + } |
| 183 | + |
| 184 | + /** |
| 185 | + * @param array{files: int, unverified: list<string>} $summary |
| 186 | + */ |
| 187 | + private function sendMail(IUser $admin, array $summary): void { |
| 188 | + $email = $admin->getEMailAddress(); |
| 189 | + if ($email === null || $email === '') { |
| 190 | + return; |
| 191 | + } |
| 192 | + |
| 193 | + $l = $this->l10nFactory->get('core', $this->l10nFactory->getUserLanguage($admin)); |
| 194 | + |
| 195 | + $template = $this->mailer->createEMailTemplate('core.CodeIntegrityChanged', $summary); |
| 196 | + $template->setSubject($l->t('The code integrity check result has changed')); |
| 197 | + $template->addHeader(); |
| 198 | + $template->addHeading($l->t('The code integrity check result has changed')); |
| 199 | + foreach (self::formatSummary($l, $summary) as $sentence) { |
| 200 | + $template->addBodyText($sentence); |
| 201 | + } |
| 202 | + $template->addBodyButton( |
| 203 | + $l->t('Review integrity check results'), |
| 204 | + $this->urlGenerator->linkToRouteAbsolute('settings.AdminSettings.index', ['section' => 'overview']), |
| 205 | + ); |
| 206 | + $template->addFooter(); |
| 207 | + |
| 208 | + $message = $this->mailer->createMessage(); |
| 209 | + $message->setTo([$email => $admin->getDisplayName()]); |
| 210 | + $message->useTemplate($template); |
| 211 | + |
| 212 | + try { |
| 213 | + $this->mailer->send($message); |
| 214 | + } catch (\Exception $e) { |
| 215 | + $this->logger->error('Could not send code integrity email to ' . $admin->getUID(), ['exception' => $e]); |
| 216 | + } |
| 217 | + } |
| 218 | +} |
0 commit comments