Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 122397 - mail-filter/qmail-scanner-1.25-r1 sandbox violation
Summary: mail-filter/qmail-scanner-1.25-r1 sandbox violation
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: High major (vote)
Assignee: Qmail Team (OBSOLETE)
URL:
Whiteboard:
Keywords:
: 177247 (view as bug list)
Depends on:
Blocks:
 
Reported: 2006-02-10 10:11 UTC by Jorge Cisneros
Modified: 2014-12-01 10:52 UTC (History)
5 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jorge Cisneros 2006-02-10 10:11:57 UTC
When i try to update  qmail-scanner, always crash with this error

emerge -va qmail-scanner

These are the packages that I would merge, in order:

Calculating dependencies ...done!
[ebuild  N    ] mail-filter/qmail-scanner-1.25-r1  +spamassassin 0 kB

Code
...

If you see the error "Can't do setuid", or "Permission denied", then
refer to the FAQ.

(e.g.  "setuidgid qmaild /var/qmail/bin/qmail-scanner-queue.pl -g")


That's it! To report success:

   % (echo 'First M. Last'; cat SYSDEF)|mail jhaar-s4vstats@crom.trimble.co.nz
Replace First M. Last with your name.
--------------------------- ACCESS VIOLATION SUMMARY ---------------------------
LOG FILE = "/var/log/sandbox/sandbox-mail-filter_-_qmail-scanner-1.25-r1-12346.log"

open_wr:   /proc/linuxshield/...
--------------------------------------------------------------------------------
Comment 1 Jorge Cisneros 2006-03-06 13:11:52 UTC
the problem is when uvscan is installed in the system.
Comment 2 Matei Daniel 2007-02-24 00:41:03 UTC
I have the same problem but its not from uvscan because I dont have it installed:

Finished. Please read README(.html) and then go over the script to
check paths/etc, and then install as you see fit.
 
Remember to copy quarantine-attachments.txt to /var/spool/qmailscan and then
run "qmail-scanner-queue.pl -g" to generate DB version.
 
 
              ****** FINAL TEST ******
 
Please log into an unpriviledged account and run 
/var/qmail/bin/qmail-scanner-queue.pl -g
 
If you see the error "Can't do setuid", or "Permission denied", then  
refer to the FAQ.
 
(e.g.  "setuidgid qmaild /var/qmail/bin/qmail-scanner-queue.pl -g")
 
 
That's it! To report success:
 
   % (echo 'First M. Last'; cat SYSDEF)|mail jhaar-s4vstats@crom.trimble.co.nz
Replace First M. Last with your name.
>>> Source compiled.
--------------------------- ACCESS VIOLATION SUMMARY ---------------------------
LOG FILE = "/var/log/sandbox/sandbox-mail-filter_-_qmail-scanner-1.25-r1-23937.log"
 
open_wr:   /var/lib/clamav/.dbLock
open_wr:   /var/lib/clamav/.dbLock
--------------------------------------------------------------------------------
Comment 3 Tomas Lavicky 2007-03-01 13:27:04 UTC
Same problem. Is it clamav-0.90 dependent?

# emerge qmail-scanner
.... truncated ....
>>> Source compiled.
--------------------------- ACCESS VIOLATION SUMMARY ---------------------------
LOG FILE = "/var/log/sandbox/sandbox-mail-filter_-_qmail-scanner-1.25-r1-13765.log"

open_wr:   /var/lib/clamav/.dbLock
open_wr:   /var/lib/clamav/.dbLock
open_wr:   /var/lib/clamav/daily.inc/.dbLock
open_wr:   /var/lib/clamav/daily.inc/.dbLock

# emerge -pv qmail-scanner
.... truncated ....
[ebuild  N    ] mail-filter/qmail-scanner-1.25-r1  USE="spamassassin" 0 kB

# emerge --info
Portage 2.1.2-r9 (default-linux/x86/2006.1/server, gcc-4.1.1, glibc-2.5-r0, 2.6.18-tproxy-rr3 i686)
=================================================================
System uname: 2.6.18-tproxy-rr3 i686 Intel(R) Pentium(R) D CPU 3.40GHz
Gentoo Base System release 1.12.9
Timestamp of tree: Thu, 01 Mar 2007 12:00:08 +0000
dev-lang/python:     2.3.5-r3, 2.4.3-r4
dev-python/pycrypto: 2.0.1-r5
sys-apps/sandbox:    1.2.17
sys-devel/autoconf:  2.13, 2.61
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r2, 1.10
sys-devel/binutils:  2.16.1-r3
sys-devel/gcc-config: 1.3.14
sys-devel/libtool:   1.5.22
virtual/os-headers:  2.6.17-r2
ACCEPT_KEYWORDS="x86"
AUTOCLEAN="yes"
CBUILD="i686-pc-linux-gnu"
CFLAGS="-O2 -mtune=i686"
CHOST="i686-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/lib/mozilla/defaults/pref /usr/share/X11/xkb /var/bind /var/qmail/alias /var/qmail/control"
CONFIG_PROTECT_MASK="/etc/env.d /etc/gconf /etc/revdep-rebuild /etc/terminfo"
CXXFLAGS="-O2 -mtune=i686"
DISTDIR="/usr/portage/distfiles"
FEATURES="autoconfig buildpkg distlocks metadata-transfer sandbox sfperms strict"
GENTOO_MIRRORS="ftp://localhost http://gentoo.supp.name/ ftp://ftp.sh.cvut.cz/MIRRORS/gentoo/gentoo ftp://ftp.stw-bonn.de/gentoo ftp://ftp.tu-clausthal.de/pub/linux/gentoo http://gentoo.oregonstate.edu http://distfiles.gentoo.org http://www.ibiblio.org/pub/Linux/distributions/gentoo"
LANG="en_GB.UTF-8"
MAKEOPTS="-j2"
PKGDIR="/usr/portage/packages"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --delete-after --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
SYNC="rsync://rsync.gentoo.org/gentoo-portage"
USE="apache2 berkdb bitmap-fonts cli cracklib crypt cups dri fortran gdbm gpm iconv ipv6 isdnlog ldap libg++ mailwrapper midi mysql ncurses nls nptl nptlonly pam pcre perl ppds pppd python readline reflection session snmp spl ssl tcpd truetype truetype-fonts type1-fonts unicode x86 xml xorg zlib" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1 emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci" ALSA_PCM_PLUGINS="adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mulaw multi null plug rate route share shm softvol" ELIBC="glibc" INPUT_DEVICES="keyboard mouse evdev" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" USERLAND="GNU" VIDEO_CARDS="apm ark ati chips cirrus cyrix dummy fbdev glint i128 i740 i810 imstt mga neomagic nsc nv rendition s3 s3virge savage siliconmotion sis sisusb tdfx tga trident tseng v4l vesa vga via vmware voodoo"
Unset:  CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LC_ALL, LDFLAGS, LINGUAS, PORTAGE_RSYNC_EXTRA_OPTS, PORTDIR_OVERLAY

--------------------------------------------------------------------------------
Comment 4 Tomas Lavicky 2007-03-01 13:33:45 UTC
Additional info - there are no .dbLock file in /var/lib/clamav/ tree after and before emerge.
Comment 5 Vieri 2007-04-11 18:56:36 UTC
(In reply to comment #2)
> >>> Source compiled.
> --------------------------- ACCESS VIOLATION SUMMARY
> ---------------------------
> LOG FILE =
> "/var/log/sandbox/sandbox-mail-filter_-_qmail-scanner-1.25-r1-23937.log"
> open_wr:   /var/lib/clamav/.dbLock
> open_wr:   /var/lib/clamav/.dbLock

I'm having the same problem too.
Emerging 2.01 (~ keyword) does not give this issue.
Comment 6 Jakub Moc (RETIRED) gentoo-dev 2007-05-05 21:56:22 UTC
*** Bug 177247 has been marked as a duplicate of this bug. ***
Comment 7 FieldySnuts 2007-05-18 18:24:37 UTC
Nudge. Any progress on this? Been quite a while.
Comment 8 Konstantin 2007-06-14 11:45:38 UTC
I remembered, that I've workarounded this problem downgrading clamav, installed qmail-scanner and after that upgrading clamav. But with latest clamav versions you cannot reemerge mail-filter/qmail-scanner.
Comment 9 Jurek Bartuszek (RETIRED) gentoo-dev 2007-08-03 17:49:24 UTC
How about adding:

addpredict /var/lib/clamav

to the ebuild? It wouldn't mess things up since it only tries to write to db locks.
Comment 10 Claudiu Radu 2007-09-14 11:31:01 UTC
I think is old news already (is al over the internet ) but u cand re-emerge qmail-scanner if you do like this:
FEATURES="-sandbox -usersandbox" emerge -av qmail-scanner 
this worked for me...


Cheers
Comment 11 Adrian Perez 2008-07-05 21:07:42 UTC
I see no violations when using app-antivirus/clamav-0.93.1, could this be related to a specific clamav version?
Comment 12 marbacz 2009-09-05 11:51:01 UTC
Shouldn't this bug be closed? Two years have gone since last comment notifying the issue.
Comment 13 Pacho Ramos gentoo-dev 2014-12-01 10:52:33 UTC
Also, 2.05 is the current stable