Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 483390 - mail-filter/qmail-scanner - qmail-scanner-queue.pl needs to be patched for sudo
Summary: mail-filter/qmail-scanner - qmail-scanner-queue.pl needs to be patched for sudo
Status: RESOLVED WONTFIX
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Net-Mail Packages
URL: https://forums.gentoo.org/viewtopic-t...
Whiteboard: Pending removal: 2018-04-18
Keywords: PMASKED
Depends on:
Blocks:
 
Reported: 2013-09-02 13:32 UTC by Harold Anderson
Modified: 2018-04-29 17:29 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Harold Anderson 2013-09-02 13:32:47 UTC
mail-filter/qmailscanner-2.08 is an old piece of software that was designed to work with perl-5.8.8, which had a setuid option.  Current versions of perl do not support setuid.  qmail-scanner-queue.pl needs to be patched like this:

$ENV{'PATH'}='/bin:/usr/bin'; 
$whoami = getpwuid($<) || "unknown"; 
if($whoami ne "qscand") { 
    exec("/usr/bin/sudo -u qscand /var/qmail/bin/qmail-scanner-queue.pl") || die; 
}

In addition, various files need to be changed to be owned by qscand, and clamav needs to run as qscand.  It would be desirable if the Gentoo install could take care of as much of the necessary post-emerge hacking (changing permissions, run-as users, and patching perl-scripts) that is currently time-consuming for users.

Reproducible: Always

Steps to Reproduce:
1. emerge qmail-scanner
2. cd /usr/share/doc/qmail-scanner-2.08/contrib/
3.  ./test_installation.sh -doit --log-details syslog
Actual Results:  
X-Qmail-Scanner-1.23st:[some numbers] clamdscan: corrupt or unknown clamd scanner error or memory/resource/perms problem - exit status 512/2 
qmail-inject: fatal: qq temporary problem (#4.3.0)

Expected Results:  
cd /usr/share/doc/qmail-scanner-2.08/contrib/ 
./test_installation.sh -doit --log-details syslog 

Sending standard test message - no viruses... 1/4 
done! 

Sending eicar test virus - should be caught by perlscanner module... 2/4 
done! 

Sending eicar test virus with altered filename - should only be caught by commercial anti-virus modules (if you have any)... 3/4 
done! 

Sending bad spam message for anti-spam testing - In case you are using SpamAssassin... 4/4 


If you have enabled $sa_quarantine, $sa_delete or $sa_reject the 
spam-message wont't arrive to the recipients. But if you have enabled 
(good idea!) 'minidebug' or 'debug' you should check 
/var/spool/qscan/qmail-queue.log (or where ever you have the log). 


        Done! 

Finished test. Now go and check Email sent to postmaster@tough-widgets.com and/or the log.. 

emerge --info qmail-scanner
Portage 2.2.1 (default/linux/amd64/13.0/no-multilib, gcc-4.7.3, glibc-2.17, 3.9.5-gentooBlackSwan x86_64)
=================================================================
                        System Settings
=================================================================
System uname: Linux-3.9.5-gentooBlackSwan-x86_64-Intel-R-_Xeon-R-_CPU_E5-2650_0_@_2.00GHz-with-gentoo-2.2
KiB Mem:     3844100 total,   2065544 free
KiB Swap:          0 total,         0 free
Timestamp of tree: Wed, 28 Aug 2013 07:45:01 +0000
ld GNU ld (GNU Binutils) 2.23.2
app-shells/bash:          4.2_p45
dev-java/java-config:     2.2.0
dev-lang/python:          2.7.5-r2, 3.2.5-r2
dev-util/cmake:           2.8.11.1
dev-util/pkgconfig:       0.28
sys-apps/baselayout:      2.2
sys-apps/openrc:          0.12
sys-apps/sandbox:         2.6-r1
sys-devel/autoconf:       2.69
sys-devel/automake:       1.12.6
sys-devel/binutils:       2.23.2
sys-devel/gcc:            4.7.3
sys-devel/gcc-config:     1.8
sys-devel/libtool:        2.4.2
sys-devel/make:           3.82-r4
sys-kernel/linux-headers: 3.10 (virtual/os-headers)
sys-libs/glibc:           2.17
Repositories: gentoo
ACCEPT_KEYWORDS="amd64 ~amd64"
ACCEPT_LICENSE="*"
CBUILD="x86_64-pc-linux-gnu"
CFLAGS="-O2 -pipe"
CHOST="x86_64-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/share/gnupg/qualified.txt /var/lib/hsqldb /var/qmail/alias /var/qmail/control /var/vpopmail/etc"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/env.d /etc/fonts/fonts.conf /etc/gconf /etc/gentoo-release /etc/php/apache2-php5.4/ext-active/ /etc/php/apache2-php5.5/ext-active/ /etc/php/cgi-php5.4/ext-active/ /etc/php/cgi-php5.5/ext-active/ /etc/php/cli-php5.4/ext-active/ /etc/php/cli-php5.5/ext-active/ /etc/revdep-rebuild /etc/sandbox.d /etc/terminfo"
CXXFLAGS="-O2 -pipe"
DISTDIR="/usr/portage/distfiles"
FCFLAGS="-O2 -pipe"
FEATURES="assume-digests binpkg-logs config-protect-if-modified distlocks ebuild-locks fixlafiles merge-sync parallel-fetch preserve-libs protect-owned sandbox sfperms strict unknown-features-warn unmerge-logs unmerge-orphans userfetch userpriv usersandbox usersync"
FFLAGS="-O2 -pipe"
GENTOO_MIRRORS="http://mirror.bytemark.co.uk/gentoo/  http://www.mirrorservice.org/sites/www.ibiblio.org/gentoo/ http://de-mirror.org/gentoo/"
LDFLAGS="-Wl,-O1 -Wl,--as-needed"
MAKEOPTS="-j5"
PKGDIR="/usr/portage/packages"
PORTAGE_CONFIGROOT="/"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --omit-dir-times --compress --force --whole-file --delete --stats --human-readable --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
PORTDIR_OVERLAY=""
SYNC="rsync://rsync.uk.gentoo.org/gentoo-portage"
USE="acl amd64 apache2 authdaemond berkdb bzip2 clamav cli cracklib crypt cxx dri fortran gdbm gif hwdb iconv imap ipv6 jpeg maildir mariadb mmx modules mudflap mysql ncurses nls nptl openmp pam pcre persuid png python readline sasl session spamassassin spell sqlite3 sse sse2 ssl svg tcpd tiff unicode urandom vda vhosts vim-syntax zlib" ABI_X86="64" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci" APACHE2_MODULES="suexec dumpio negotiation vhost_alias log_config dbd authz-user authz_default authz_dbm authn_default authz_user authn_dbm authn_dbd authn_basic alias actions auth_basic authn_alias authn_anon authn_core authn_file authz_core authz_groupfile authz_host authz_owner autoindex cache cgi cgid dav dav_fs dav_lock deflate dir env ext_filter filter headers include logio mime mime_magic rewrite setenvif socache_shmcb speling status unique_id unixd userd" CALLIGRA_FEATURES="kexi words flow plan sheets stage tables krita karbon braindump author" CAMERAS="ptp2" COLLECTD_PLUGINS="df interface irq load memory rrdtool swap syslog" ELIBC="glibc" GPSD_PROTOCOLS="ashtech aivdm earthmate evermore fv18 garmin garmintxt gpsclock itrax mtk3301 nmea ntrip navcom oceanserver oldstyle oncore rtcm104v2 rtcm104v3 sirf superstar2 timing tsip tripmate tnt ubx" INPUT_DEVICES="evdev" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" LIBREOFFICE_EXTENSIONS="presenter-console presenter-minimizer" LINGUAS="en" NGINX_MODULES_HTTP="access auth_basic autoindex browser charset empty_gif fastcgi geo gzip limit_req limit_zone map memcached proxy referer rewrite scgi split_clients ssi upstream_ip_hash userid uwsgi realip gzip_static gunzip spdy cache_purge limit_conn slowfs_cache" NGINX_MODULES_MAIL="smtp pop3 imap" OFFICE_IMPLEMENTATION="libreoffice" PHP_TARGETS="php5-4" PYTHON_SINGLE_TARGET="python2_7" PYTHON_TARGETS="python2_7 python3_2" RUBY_TARGETS="ruby20 ruby19" USERLAND="GNU" VIDEO_CARDS="fbdev glint intel mach64 mga nouveau nv r128 radeon savage sis tdfx trident vesa via vmware dummy v4l" XTABLES_ADDONS="quota2 psd pknock lscan length2 ipv4options ipset ipp2p iface geoip fuzzy condition tee tarpit sysrq steal rawnat logmark ipmark dhcpmac delude chaos account"
Unset:  CPPFLAGS, CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LANG, LC_ALL, PORTAGE_BUNZIP2_COMMAND, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS, USE_PYTHON

=================================================================
                        Package Settings
=================================================================

mail-filter/qmail-scanner-2.08 was built with the following:
USE="clamav spamassassin"
Comment 1 Pacho Ramos gentoo-dev 2018-04-29 17:29:12 UTC
removed