<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>73001</bug_id>
          
          <creation_ts>2004-12-01 00:37 0000</creation_ts>
          <short_desc>clamav 0.80 doesn&apos;t work with qmail-scanner.</short_desc>
          <delta_ts>2008-01-04 22:49:02 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Linux</product>
          <component>Applications</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          
          <priority>P2</priority>
          <bug_severity>critical</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>david@rohr.se</reporter>
          <assigned_to>qmail-bugs@gentoo.org</assigned_to>
          <cc>carter.smithhart@gmail.com</cc>
    
    <cc>gentoo@oliwel.de</cc>
    
    <cc>mmokrejs@ribosome.natur.cuni.cz</cc>

      

      
          <long_desc isprivate="0">
            <who>david@rohr.se</who>
            <bug_when>2004-12-01 00:37:27 0000</bug_when>
            <thetext>@4000000041ad8266106e8cf4 X-Qmail-Scanner-1.24st:[angelica110189014068027253] clamdscan: corrupt or unknown clamd scanner error or memory/resource/perms problem - exit status 512/2

I get this on every mail that comes in. Works great with 0.75.

Also tested with the FixStaleSocket option, didn&apos;t help at all..

Reproducible: Always
Steps to Reproduce:
1. Upgrade to clamav 0.80
2.
3.

Actual Results:  
qmail-scanner stoped working.

Expected Results:  
A working mailscanner.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>david@rohr.se</who>
            <bug_when>2004-12-01 00:37:48 0000</bug_when>
            <thetext>Portage 2.0.51-r3 (default-linux/x86/2004.3, gcc-3.3.4, glibc-2.3.4.20040808-r1, 2.4.27-grsec-2.0.1 i686)
=================================================================
System uname: 2.4.27-grsec-2.0.1 i686 AMD Duron(tm) processor
Gentoo Base System version 1.4.16
Autoconf: sys-devel/autoconf-2.59-r5
Automake: sys-devel/automake-1.8.5-r1
Binutils: sys-devel/binutils-2.15.90.0.1.1-r3
Headers:  sys-kernel/linux-headers-2.4.21-r1
Libtools: sys-devel/libtool-1.5.2-r7
ACCEPT_KEYWORDS=&quot;x86&quot;
AUTOCLEAN=&quot;yes&quot;
CFLAGS=&quot;-O3 -march=i686 -fomit-frame-pointer&quot;
CHOST=&quot;i686-pc-linux-gnu&quot;
COMPILER=&quot;&quot;
CONFIG_PROTECT=&quot;/etc /usr/kde/2/share/config /usr/kde/3/share/config /usr/share/config /var/bind /var/qmail/alias /var/qmail/control&quot;
CONFIG_PROTECT_MASK=&quot;/etc/gconf /etc/terminfo /etc/env.d&quot;
CXXFLAGS=&quot;-O3 -march=i686 -fomit-frame-pointer&quot;
DISTDIR=&quot;/usr/portage/distfiles&quot;
FEATURES=&quot;autoaddcvs autoconfig ccache distlocks sandbox sfperms&quot;
GENTOO_MIRRORS=&quot;http://ftp.du.se/pub/os/gentoo http://gentoo.oregonstate.edu http://www.ibiblio.org/pub/Linux/distributions/gentoo&quot;
MAKEOPTS=&quot;-j2&quot;
PKGDIR=&quot;/usr/portage/packages&quot;
PORTAGE_TMPDIR=&quot;/var/tmp&quot;
PORTDIR=&quot;/usr/portage&quot;
PORTDIR_OVERLAY=&quot;&quot;
SYNC=&quot;rsync://rsync.gentoo.org/gentoo-portage&quot;
USE=&quot;apache2 apm arts avi berkdb bitmap-fonts chroot crypt curl encode f77 foomaticdb fortran gd gdbm gif gmp gpm gtk2 imagemagick imap imlib ipv6 java jpeg libg++ libwww mad mailbox maildir mbox mcal mikmod motif mpeg mysql ncurses nls oggvorbis opengl oss pam pdflib perl perlsuid png python quicktime readline ruby sasl sdl session slang snmp spamassassin spell ssl svga tcpd tiff truetype x86 xml2 xmms xv zlib&quot;
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>david@rohr.se</who>
            <bug_when>2004-12-01 00:46:00 0000</bug_when>
            <thetext>I noticed that the old 0.75.1 uses root as user, and 0.80 uses clamav. So maybe the problem is there... But isn&apos;t right permissions set for the clamav user?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>glen@delfi.ee</who>
            <bug_when>2004-12-05 16:32:13 0000</bug_when>
            <thetext>get newer qmail-scanner. the problem is there (fixed in 1.24).
the real issue is that version string of clamdscan has changed and qmail scanner gets confused on that.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>glen@delfi.ee</who>
            <bug_when>2004-12-05 16:36:13 0000</bug_when>
            <thetext>ah. sorry. You have 1.24.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>st_lim@gentoo.org</who>
            <bug_when>2004-12-23 19:09:51 0000</bug_when>
            <thetext>Hi,
  I&apos;m not sure what you mean when you say that clamd uses root as user.  Can you clarify?  clamdscan is working fine over here. :)

/etc/clamav.conf
User qscand

Regards
Lim Swee Tat</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>david@rohr.se</who>
            <bug_when>2004-12-24 00:42:02 0000</bug_when>
            <thetext>On 0.75.1 clamav uses the root-user, and when I tested 0.80 i changed the options to use a diffrent user, clamd. Using this user causes the message i displayed. Maybe it works better with qscand, haven&apos;t tried that one...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>david@rohr.se</who>
            <bug_when>2004-12-28 13:27:54 0000</bug_when>
            <thetext>Now tested with &quot;User qscand&quot; and now everything works. Guess this should be noticed in the documents for either clamav or qmail-scanner.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carter.smithhart@gmail.com</who>
            <bug_when>2005-08-28 11:16:54 0000</bug_when>
            <thetext>Here&apos;s an interesting page on this issue:
http://qmail.jms1.net/clamav-qms.shtml

And this is the test program to see if you&apos;re configuration is working:
/usr/share/doc/qmail-scanner-1.25-r1/contrib/test_installation.sh.gz

I&apos;ve tried everything on google and everything on the first link and I continue
to get the problem mentioned in this bug.. I have these versions installed.
*  app-antivirus/clamav :
        [  I] 0.86.2 (0)
*  mail-filter/spamassassin :
        [  I] 3.0.4 (0)
*  mail-filter/qmail-scanner :
        [  I] 1.25-r1 (0)

advocate etc # /tmp/test_installation.sh -doit
QMAILQUEUE was not set, defaulting to /var/qmail/bin/qmail-scanner-queue.pl for
this test...
QMAILQUEUE was not set, defaulting to /var/qmail/bin/qmail-scanner-queue.pl for
this test...

Sending standard test message - no viruses...
done!

Sending eicar test virus - should be caught by perlscanner module...
X-Qmail-Scanner-1.25st:[advocate112525294571831715] clamdscan: corrupt or
unknown clamd scanner error or memory/resource/perms problem - exit status 512/2
qmail-inject: fatal: qq temporary problem (#4.3.0)
Bad error. qmail-inject died

When the test_installation program is run, do you see this problem?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carter.smithhart@gmail.com</who>
            <bug_when>2005-08-28 11:20:25 0000</bug_when>
            <thetext>NOTE: I just retested setting &quot;User root&quot; in etc/clamd.conf and I get

advocate etc # /tmp/test_installation.sh -doit
QMAILQUEUE was not set, defaulting to /var/qmail/bin/qmail-scanner-queue.pl for
this test...
QMAILQUEUE was not set, defaulting to /var/qmail/bin/qmail-scanner-queue.pl for
this test...

Sending standard test message - no viruses...
done!

Sending eicar test virus - should be caught by perlscanner module...
done!

Sending eicar test virus with altered filename - should only be caught by
commercial anti-virus modules (if you have any)...

Sending bad spam message for anti-spam testing - In case you are using
SpamAssassin...
Done!

Finished test. Now go and check Email for root@localhost

What on that previous link is still wrong where root is still needed?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ufs@sapo.pt</who>
            <bug_when>2005-09-07 19:57:26 0000</bug_when>
            <thetext>The solution for your problems might be here:
http://qmail.jms1.net/clamav-qms.shtml

Mine Was!!! ;)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>mmokrejs@ribosome.natur.cuni.cz</who>
            <bug_when>2006-02-06 11:42:21 0000</bug_when>
            <thetext>I have just hit the same problem with clamav-0.88 and qmail-scanner-1.25-r1.
The fix for me was:

# vim /etc/clamd.conf # set User to qscand
# chown qscand /var/run/clamav

This should be noted in qmail-scanner-1.25-r1.ebuild:pkg_postinst
right after the line with:
export QMAILQUEUE=/var/qmail/bin/qmail-scanner-queue</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>johan@bondeson.mine.nu</who>
            <bug_when>2006-02-08 15:19:54 0000</bug_when>
            <thetext>I can confirm that this problem is solved by:
instructions on http://qmail.jms1.net/clamav-qms.shtml
COMBINED with
export QMAILQUEUE=/var/qmail/bin/qmail-scanner-queue

note that you should not use the .pl file.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>mailbin@comcast.net</who>
            <bug_when>2006-04-05 12:29:25 0000</bug_when>
            <thetext>(In reply to comment #12)
&gt; I can confirm that this problem is solved by:
&gt; instructions on http://qmail.jms1.net/clamav-qms.shtml
&gt; COMBINED with
&gt; export QMAILQUEUE=/var/qmail/bin/qmail-scanner-queue
&gt; 
&gt; note that you should not use the .pl file.
&gt; 

Well I&apos;m not sure what I&apos;m doing wrong, but I followed the above instructions and still get the error.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rentorbuy@yahoo.com</who>
            <bug_when>2006-04-11 01:52:27 0000</bug_when>
            <thetext>(In reply to comment #13)
&gt; Well I&apos;m not sure what I&apos;m doing wrong, but I followed the above instructions
&gt; and still get the error.

Here&apos;s what I&apos;ve done.

Edit /etc/clamd.conf:
User qscand

Edit /etc/freshclam.conf:
DatabaseOwner qscand

# chown -R qscand:qscand /var/lib/clamav
# chown -R qscand:qscand /var/run/clamav
# chown -R qscand:qscand /var/log/clamav 

For the first bundle of processed emails, everythng works fine but then I get clamd segfaults.

/var/log:

Tue Apr 11 09:26:51 2006 -&gt; /var/spool/qmailscan/tmp/INF-BL07114474041172614965/
msg.pif: Worm.SomeFool.P FOUND
Tue Apr 11 09:26:52 2006 -&gt; /var/spool/qmailscan/tmp/INF-BL07114474041272614996/
message.scr: Worm.SomeFool.P FOUND
Tue Apr 11 09:26:52 2006 -&gt; /var/spool/qmailscan/tmp/INF-BL07114474041272614996/
textfile2: Exploit.HTML.IFrame FOUND
Tue Apr 11 09:29:44 2006 -&gt; /var/spool/qmailscan/tmp/INF-BL07114474058472618615/
message.scr: Worm.SomeFool.P FOUND
Tue Apr 11 09:29:44 2006 -&gt; /var/spool/qmailscan/tmp/INF-BL07114474058472618615/
textfile2: Exploit.HTML.IFrame FOUND
Tue Apr 11 09:29:54 2006 -&gt; Segmentation fault :-( Bye..
@40000000443b64bd275436e4 X-Qmail-Scanner-1.25st:[INF-BL07114474309172615709] cl
amdscan: corrupt or unknown clamd scanner error or memory/resource/perms problem
 - exit status 512/2

The same happens if I change to root:
Edit /etc/clamd.conf:
User root

I changed softlimit in /var/qmail/control/conf-common:
SOFTLIMIT_OPTS=&quot;-m 128000000&quot; # this server has 4GB RAM

but I still have the same problem (i.e. clamd works fine for a while then segfaults).

This has started happening after emerging clamav-0.88.1 (0.88 was doing fine).

I still have a second server with 0.88 and is working fine. (same config as the main server; just different clamav version)
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rentorbuy@yahoo.com</who>
            <bug_when>2006-04-11 02:26:36 0000</bug_when>
            <thetext>(In reply to comment #14)

Maybe qmail-scanner has to be re-emerged. Has anyone tried that?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>mmokrejs@ribosome.natur.cuni.cz</who>
            <bug_when>2006-04-11 02:31:01 0000</bug_when>
            <thetext>I saw some config file changes lifted up by my etc-update(1). If I remeber right it seems someone at Gentoo gave up and made the default user in clamav.conf User &quot;clamav&quot; instead of &quot;qscand&quot;. That means one won&apos;t have to chown() the spool directories anymore. Be prepared to revert back. I have myself reject the config file change.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rentorbuy@yahoo.com</who>
            <bug_when>2006-04-11 04:15:49 0000</bug_when>
            <thetext>I had to downgrade to 0.88 because 0.88.1 segfaults after correctly processing a certain number of messages. This behavior makes me think, although I may be wrong, that it&apos;s neither the ebuild&apos;s fault nor a file permission/ownership issue. I will check the clamav mailing list.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>mmokrejs@ribosome.natur.cuni.cz</who>
            <bug_when>2006-04-11 05:40:34 0000</bug_when>
            <thetext>Well, the segfaults have definitely another cause. Try:

USE=&quot;debug&quot; emerge qmail-scanner clamav # maybe others?

and try to get the segfaults happen when you run the clamdscan daemon in foreground mode (--stdout). Does clamscan(1) crash as well? Or does clamd(1) die?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rentorbuy@yahoo.com</who>
            <bug_when>2006-04-11 10:40:55 0000</bug_when>
            <thetext>(In reply to comment #18)

There **may** be an issue with zip scanning on 64-bit platforms as reported by Chris Wakelin on the clamav mailing list.

Will test and post back.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rentorbuy@yahoo.com</who>
            <bug_when>2006-04-11 13:41:18 0000</bug_when>
            <thetext>Created an attachment (id=84469)
possible clamav source patch for 64bit systems

Testing this patch on a 64bit system.
Procedure:

emerge gentoolkit
equery which clamav
ebuild /usr/portage/app-antivirus/clamav/clamav-0.88.1.ebuild clean
ebuild /usr/portage/app-antivirus/clamav/clamav-0.88.1.ebuild unpack
cd /var/tmp/portage/clamav-0.88.1/work/
patch -p0 &lt; /tmp/clamav-0.88.1-zziplib-64bit.patch
ebuild /usr/portage/app-antivirus/clamav/clamav-0.88.1.ebuild compile
ebuild /usr/portage/app-antivirus/clamav/clamav-0.88.1.ebuild install
ebuild /usr/portage/app-antivirus/clamav/clamav-0.88.1.ebuild qmerge

Patched clamd daemon running since Apr. 11th 2006 22:00 GMT+1 on a system scanning aprox. 400 mailboxes.

Will report segmentation faults, if any.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rentorbuy@yahoo.com</who>
            <bug_when>2006-04-12 08:14:47 0000</bug_when>
            <thetext>(In reply to comment #20)

Since this bug report is different I opened a new one, for amd64:

http://bugs.gentoo.org/show_bug.cgi?id=129702
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gentoo@oliwel.de</who>
            <bug_when>2006-07-18 00:31:14 0000</bug_when>
            <thetext>Hi

QMS2.0 is not in stable arch and so I dont want to use it. The approach of making clamav run as qscand user is imho the most common and the most secure one - so whats about adding a &quot;qmailscanner&quot; useflag to the ebuild, that correctly sets the config and the rights of the associated files/dirs ?

I think this can be done in a whimp and will not break or depend on anything else

Oliver</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tupone@gentoo.org</who>
            <bug_when>2008-01-04 22:49:02 0000</bug_when>
            <thetext>Should be fixed in 2.01-r1. Additional instruction for clamav configuration are in the package.
Thanks</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>84469</attachid>
            <date>2006-04-11 13:41 0000</date>
            <desc>possible clamav source patch for 64bit systems</desc>
            <filename>clamav-0.88.1-zziplib-64bit.patch</filename>
            <type>text/plain</type>
            <data encoding="base64">LS0tIGNsYW1hdi0wLjg4LjEvbGliY2xhbWF2L3p6aXBsaWIvenppcC16aXAuYy5vcmlnCTIwMDYt
MDMtMjggMDA6NDM6NTMuMDAwMDAwMDAwICswMTAwCisrKyBjbGFtYXYtMC44OC4xL2xpYmNsYW1h
di96emlwbGliL3p6aXAtemlwLmMJMjAwNi0wNC0xMSAxODowNTowNi4yNzU2NDQwODYgKzAxMDAK
QEAgLTMwLDYgKzMwLDggQEAKICNpbmNsdWRlIDxzeXMvc3RhdC5oPgogI2luY2x1ZGUgPHVuaXN0
ZC5oPgogCisjaW5jbHVkZSAib3RoZXJzLmgiCisKIC8qCiAjaW5jbHVkZSAiX19tbWFwLmgiCiAj
aW5jbHVkZSAiX19kZWJ1Zy5oIgo=
</data>        

          </attachment>
    </bug>

</bugzilla>