How to Configure CIFS/SMB NAS Recording with Username and Password Authentication on AtomCam
Enable CIFS/SMB NAS recording by entering the server address, username, and password in the web UI, which writes credentials to /tmp/hack.ini and triggers mount_cifs.sh to mount the share at /atom/mnt for automatic video storage.
The atomcam_tools open-source firmware extends Wyze and Atom cameras with enterprise-grade storage capabilities. Configuring CIFS/SMB NAS recording with username and password authentication allows you to centralize surveillance footage on network-attached storage while maintaining secure credential management.
Kernel and Prerequisites
The firmware includes native CIFS support through the kernel configuration. In configs/kernel.config at line 1836, the setting CONFIG_CIFS=m compiles the CIFS driver as a loadable module, ensuring the camera can mount Windows and Samba shares without additional kernel compilation.
Configuring NAS Credentials in the Web Interface
The settings interface collects your NAS connection parameters and persists them to the runtime configuration. In web/source/vue/Setting.vue (around lines 218-222), three input fields bind directly to the configuration variables:
STORAGE_CIFSSERVER– The UNC path or IP address of your NAS (e.g.,//192.168.1.100/atomcam)STORAGE_CIFSUSER– The username for SMB authenticationSTORAGE_CIFSPASSWD– The password for SMB authentication
When you save the settings, the UI writes these values to /tmp/hack.ini, which serves as the central configuration store for all shell scripts.
Understanding the Mount Process
The mount_cifs.sh Script
The actual mounting logic resides in overlay_rootfs/atom_patch/system_bin/mount_cifs.sh. This script reads the credentials from /tmp/hack.ini and attempts to mount the share with automatic protocol negotiation.
The script implements a fallback mechanism for protocol versions. It attempts to mount using version 3.0, then falls back to 2.1, and finally 2.0 if the previous attempts fail. This ensures compatibility with both modern Samba servers and legacy Windows shares.
The mount command constructed by the script (lines 24-33) follows this pattern:
mount -t cifs -o username=$STORAGE_CIFSUSER,password=$STORAGE_CIFSPASSWD,vers=$VER,iocharset=utf8 $STORAGE_CIFSSERVER /atom/mnt
The mount point /atom/mnt exists inside the overlay root filesystem. When running outside the chroot environment, the system uses /mnt instead.
Enabling Recording Modes for NAS Storage
Once the CIFS share is mounted, you must enable specific recording modes to utilize NAS storage. The configuration translation script overlay_rootfs/scripts/hack_ini_reconfig.sh (lines 44-66) converts the generic NAS settings into per-recording flags.
Periodic Recording
Set PERIODICREC_CIFS=on to enable continuous recording to the NAS. The system writes files to the subdirectory specified by PERIODICREC_CIFS_PATH, which supports strftime formatting (e.g., %Y%m%d/%H%M%S creates date-based folders).
Alarm Recording
For motion-triggered recordings, enable ALARMREC_CIFS=on. This directs alarm videos to ALARMREC_CIFS_PATH on the mounted share, ensuring critical events are preserved on network storage even if the local SD card fails.
Timelapse Recording
The timelapse script overlay_rootfs/scripts/timelapse.sh checks TIMELAPSE_CIFS=on and writes generated videos to TIMELAPSE_CIFS_PATH. This mode is particularly useful for long-term construction or weather monitoring projects requiring centralized archival.
Automatic Cleanup of Old Recordings
To prevent the NAS share from filling up, the system includes automatic rotation logic in overlay_rootfs/scripts/remove_old.sh. When you enable PERIODICREC_CIFS_REMOVE, ALARMREC_CIFS_REMOVE, or TIMELAPSE_CIFS_REMOVE, the script executes find commands with the -mtime parameter:
find $NAS_PATH -type f -mtime +$PERIODICREC_CIFS_REMOVE_DAYS -delete
This removes files older than the specified number of days, maintaining predictable storage usage on your network share.
Manual Verification and Troubleshooting
After configuring the settings, verify the mount status by checking active mounts:
mount | grep cifs
You should see output similar to:
//192.168.1.100/atomcam on /atom/mnt type cifs (rw,vers=3.0,username=camuser,iocharset=utf8)
List the recording directory to confirm write access:
ls -la /atom/mnt/record/
If the mount fails, check the system log for authentication errors or protocol mismatches. Ensure the NAS supports at least SMB 2.0, as the camera does not support the legacy SMB 1.0/CIFS protocol due to security constraints.
Summary
- Kernel support is enabled via
CONFIG_CIFS=min the firmware build configuration. - Credentials are stored in
/tmp/hack.inithrough the web UI fieldsSTORAGE_CIFSSERVER,STORAGE_CIFSUSER, andSTORAGE_CIFSPASSWD. - Mounting is handled by
overlay_rootfs/atom_patch/system_bin/mount_cifs.sh, which negotiates SMB protocol versions 3.0, 2.1, or 2.0. - Recording modes are activated via
PERIODICREC_CIFS,ALARMREC_CIFS, andTIMELAPSE_CIFSflags, with paths translated byhack_ini_reconfig.sh. - Cleanup is managed by
remove_old.shusingfindwith-mtimeparameters to rotate old files.
Frequently Asked Questions
What CIFS protocol versions does atomcam_tools support?
The firmware supports SMB 3.0, 2.1, and 2.0. The mount_cifs.sh script attempts to mount using version 3.0 first, then automatically falls back to 2.1 and 2.0 if the server rejects the connection. SMB 1.0 is not supported due to security vulnerabilities.
Where are NAS credentials stored on the camera?
Credentials are stored in the runtime configuration file /tmp/hack.ini. The web interface writes the server path to STORAGE_CIFSSERVER, username to STORAGE_CIFSUSER, and password to STORAGE_CIFSPASSWD. These values are read by the mount script to authenticate with the NAS.
Can I use a NAS without authentication?
While the code supports empty username and password fields, this is not recommended for security reasons. If you must use a guest-accessible share, leave the username and password fields blank in the web UI. The mount command will omit the credentials, relying on the server's guest access configuration.
How do I troubleshoot a failed CIFS mount?
First, verify the credentials in /tmp/hack.ini are correct. Run mount_cifs.sh manually and check for error messages. Use mount | grep cifs to confirm the share is listed. If the mount fails with "permission denied," verify the NAS supports SMB 2.0 or higher and that the user has write access to the share path. Check system logs with logread for kernel-level CIFS errors.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →