This is the libraries module for the Greenbone Community Edition.
It is used for the Greenbone Enterprise appliances and provides various functionalities to support the integrated service daemons.
All release files are signed with
the Greenbone Community Feed integrity key.
This gpg key can be downloaded at https://www.greenbone.net/GBCommunitySigningKey.asc
and the fingerprint is 8AE4 BE42 9B60 A59B 311C 2E73 9823 FAA6 0ED1 E580.
This module can be configured, built and installed with following commands:
cmake .
make install
For detailed installation requirements and instructions, please see the file INSTALL.md.
If you are not familiar or comfortable building from source code, we recommend that you use the Greenbone Security Manager TRIAL (GSM TRIAL), a prepared virtual machine with a readily available setup. Information regarding the virtual machine is available at https://www.greenbone.net/en/testnow.
The gvm-libs module consists of the following libraries:
-
base: All basic modules which require only thegliblibrary as a dependency. -
util: All modules that require more than thegliblibrary as dependency. -
gmp: API support for the Greenbone Management Protocol (GMP). -
osp: API support for the Open Scanner Protocol (OSP). -
agent_controller: Agent controller client for agent management. -
boreas: Host discovery functions. -
container_image_scanner: Container image scanner communication. -
cyberark: Cyberark credential store communication. -
http: Utility functions for http built on libcurl. -
http_scanner: Communication with an http scanner. -
openvasd: Openvas daemon communication. -
security_intelligence: Security intelligence client. -
web_application_scanner: Web application scanner communication. -
ad_connector: Active directory connector interface.
For more information on using the functionality provided by the gvm-libs
module please refer to the source code documentation.
The base module of gvm-libs contains routines for logging, they
can be configured with a file on the following format.
The log configuration is divided into domains like these:
# Comment
[log domain name]
level=debug
[*]
prepend=%t %p
prepend_time_format=%Y-%m-%d %Hh%M.%S %Z
file=/var/log/gvm/filename.log
level=infoEach heading (text in square brackets) controls log messages emitted
for that log domain name. The heading for log domain name * defines
defaults for most values.
Valid labels under each log domain name heading are:
- prepend
- separator
- prepend_time_format
- file
- level
- syslog_facility
- syslog_ident
Labels without definition in a log domain will default to the value
set in the default log domain named * with one exception:
syslog_ident defaults to the log domain name.
Labels without definition in either the log domain for a particular log message or the default log domain have these defaults:
- prepend: "%t %s %p - "
- separator: ":"
- prepend_time_format: "%Y-%m-%d %Hh%M.%S %Z"
- file: "-"
- level: "debug"
- syslog_facility: "local0"
- syslog_ident: log domain name
The value of prepend is formatted and prepended to each log message
sent to file or stderr, valid format sequences are:
- %p: pid
- %t: time (as formatted by prepend_time_format)
- %s: separator (as specified by separator)
Valid values for separator are most strings.
Valid values for prepend_time_format are format specifications for
strftime(3).
The value of file controls where the logs are sent:
- null (not specified for the log domain of a particular message or for the default log domain): log to stderr
- "" (the empty string): log to stderr
- "-": log to stderr
- "syslog": log to syslog
- all other values: treat the value as a path and try to append to the file specified
The level label controls what log levels are output, example values:
- "error", "4": errors
- "critical", "8": critical situation
- "warning", "16": warnings
- "message", "32": messages
- "info", "64": information
- "debug", "128": debug (lots of output)
Enabling any level includes all the levels above it. So enabling information will include warnings, critical situations and errors.
To get absolutely all logging, set the level to debug for all domains in the configuration file. Do note warnings though about sensitive information in log messages in comments at the start of some config files as shipped from dependent projects.
Valid values for syslog_facility are "auth", "authpriv", "cron",
"daemon", "ftp", "kern", "lpr", "mail", "mark", "news", "security",
"syslog", "user", "uucp" and "local0" through "local7".
Valid values for syslog_ident are most strings.
Empty lines and lines beginning with the hash symbol ("#") are treated as comments.
For any question on the usage of gvm-libs please use the Greenbone Community
Portal. If you found a problem with the
software, please create an issue
on GitHub. If you are a Greenbone customer you may alternatively or additionally
forward your issue to the Greenbone Support Portal.
This project is maintained by Greenbone AG.
Your contributions are highly appreciated. Please create a pull request on GitHub. Bigger changes need to be discussed with the development team via the issues section at github first.
Before creating a pull request, it is recommended to check the formatting for source code and cmake files.
All C source and header files are formatted using clang-format. To install clang-format on a Debian based system the following command can be used:
sudo apt install clang-format
To format all C source and header files run the command:
make format
This reformats the new code to ensure that it follows the code style and formatting guidelines.
All CMake files are formatted using gersemi. To install gersemi on a Debian based system the following commands can be used:
sudo apt install pipx
pipx install gersemi
To format all CMake files run the command:
gersemi -i cmake .
If you want to use the Clang Static Analyzer
to do a static code analysis, you can do so by prefixing the configuration and
build commands with scan-build:
scan-build cmake ..
scan-build make
The tool will provide a hint on how to launch a web browser with the results.
It is recommended to do this analysis in a separate, empty build directory and
to empty the build directory before scan-build call.
Copyright (C) 2009-2026 Greenbone AG
Licensed under the GNU General Public License v2.0 or later.
