How to Configure CIFS/SMB NAS Recording with Username and Password Authentication on AtomCam

Enable CIFS/SMB NAS recording by entering the server address, username, and password in the web UI, which writes credentials to /tmp/hack.ini and triggers mount_cifs.sh to mount the share at /atom/mnt for automatic video storage.

The atomcam_tools open-source firmware extends Wyze and Atom cameras with enterprise-grade storage capabilities. Configuring CIFS/SMB NAS recording with username and password authentication allows you to centralize surveillance footage on network-attached storage while maintaining secure credential management.

Kernel and Prerequisites

The firmware includes native CIFS support through the kernel configuration. In configs/kernel.config at line 1836, the setting CONFIG_CIFS=m compiles the CIFS driver as a loadable module, ensuring the camera can mount Windows and Samba shares without additional kernel compilation.

Configuring NAS Credentials in the Web Interface

The settings interface collects your NAS connection parameters and persists them to the runtime configuration. In web/source/vue/Setting.vue (around lines 218-222), three input fields bind directly to the configuration variables:

  • STORAGE_CIFSSERVER – The UNC path or IP address of your NAS (e.g., //192.168.1.100/atomcam)
  • STORAGE_CIFSUSER – The username for SMB authentication
  • STORAGE_CIFSPASSWD – The password for SMB authentication

When you save the settings, the UI writes these values to /tmp/hack.ini, which serves as the central configuration store for all shell scripts.

Understanding the Mount Process

The mount_cifs.sh Script

The actual mounting logic resides in overlay_rootfs/atom_patch/system_bin/mount_cifs.sh. This script reads the credentials from /tmp/hack.ini and attempts to mount the share with automatic protocol negotiation.

The script implements a fallback mechanism for protocol versions. It attempts to mount using version 3.0, then falls back to 2.1, and finally 2.0 if the previous attempts fail. This ensures compatibility with both modern Samba servers and legacy Windows shares.

The mount command constructed by the script (lines 24-33) follows this pattern:

mount -t cifs -o username=$STORAGE_CIFSUSER,password=$STORAGE_CIFSPASSWD,vers=$VER,iocharset=utf8 $STORAGE_CIFSSERVER /atom/mnt

The mount point /atom/mnt exists inside the overlay root filesystem. When running outside the chroot environment, the system uses /mnt instead.

Enabling Recording Modes for NAS Storage

Once the CIFS share is mounted, you must enable specific recording modes to utilize NAS storage. The configuration translation script overlay_rootfs/scripts/hack_ini_reconfig.sh (lines 44-66) converts the generic NAS settings into per-recording flags.

Periodic Recording

Set PERIODICREC_CIFS=on to enable continuous recording to the NAS. The system writes files to the subdirectory specified by PERIODICREC_CIFS_PATH, which supports strftime formatting (e.g., %Y%m%d/%H%M%S creates date-based folders).

Alarm Recording

For motion-triggered recordings, enable ALARMREC_CIFS=on. This directs alarm videos to ALARMREC_CIFS_PATH on the mounted share, ensuring critical events are preserved on network storage even if the local SD card fails.

Timelapse Recording

The timelapse script overlay_rootfs/scripts/timelapse.sh checks TIMELAPSE_CIFS=on and writes generated videos to TIMELAPSE_CIFS_PATH. This mode is particularly useful for long-term construction or weather monitoring projects requiring centralized archival.

Automatic Cleanup of Old Recordings

To prevent the NAS share from filling up, the system includes automatic rotation logic in overlay_rootfs/scripts/remove_old.sh. When you enable PERIODICREC_CIFS_REMOVE, ALARMREC_CIFS_REMOVE, or TIMELAPSE_CIFS_REMOVE, the script executes find commands with the -mtime parameter:

find $NAS_PATH -type f -mtime +$PERIODICREC_CIFS_REMOVE_DAYS -delete

This removes files older than the specified number of days, maintaining predictable storage usage on your network share.

Manual Verification and Troubleshooting

After configuring the settings, verify the mount status by checking active mounts:

mount | grep cifs

You should see output similar to:

//192.168.1.100/atomcam on /atom/mnt type cifs (rw,vers=3.0,username=camuser,iocharset=utf8)

List the recording directory to confirm write access:

ls -la /atom/mnt/record/

If the mount fails, check the system log for authentication errors or protocol mismatches. Ensure the NAS supports at least SMB 2.0, as the camera does not support the legacy SMB 1.0/CIFS protocol due to security constraints.

Summary

  • Kernel support is enabled via CONFIG_CIFS=m in the firmware build configuration.
  • Credentials are stored in /tmp/hack.ini through the web UI fields STORAGE_CIFSSERVER, STORAGE_CIFSUSER, and STORAGE_CIFSPASSWD.
  • Mounting is handled by overlay_rootfs/atom_patch/system_bin/mount_cifs.sh, which negotiates SMB protocol versions 3.0, 2.1, or 2.0.
  • Recording modes are activated via PERIODICREC_CIFS, ALARMREC_CIFS, and TIMELAPSE_CIFS flags, with paths translated by hack_ini_reconfig.sh.
  • Cleanup is managed by remove_old.sh using find with -mtime parameters to rotate old files.

Frequently Asked Questions

What CIFS protocol versions does atomcam_tools support?

The firmware supports SMB 3.0, 2.1, and 2.0. The mount_cifs.sh script attempts to mount using version 3.0 first, then automatically falls back to 2.1 and 2.0 if the server rejects the connection. SMB 1.0 is not supported due to security vulnerabilities.

Where are NAS credentials stored on the camera?

Credentials are stored in the runtime configuration file /tmp/hack.ini. The web interface writes the server path to STORAGE_CIFSSERVER, username to STORAGE_CIFSUSER, and password to STORAGE_CIFSPASSWD. These values are read by the mount script to authenticate with the NAS.

Can I use a NAS without authentication?

While the code supports empty username and password fields, this is not recommended for security reasons. If you must use a guest-accessible share, leave the username and password fields blank in the web UI. The mount command will omit the credentials, relying on the server's guest access configuration.

How do I troubleshoot a failed CIFS mount?

First, verify the credentials in /tmp/hack.ini are correct. Run mount_cifs.sh manually and check for error messages. Use mount | grep cifs to confirm the share is listed. If the mount fails with "permission denied," verify the NAS supports SMB 2.0 or higher and that the user has write access to the share path. Check system logs with logread for kernel-level CIFS errors.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →