Summary: | acct-user/clamav clobbers existing supplementary groups | ||
---|---|---|---|
Product: | Gentoo Linux | Reporter: | Daniel M. Weeks <dan> |
Component: | Current packages | Assignee: | Michael Orlitzky <mjo> |
Status: | RESOLVED DUPLICATE | ||
Severity: | normal | ||
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Package list: | Runtime testing required: | --- |
Description
Daniel M. Weeks
2020-02-08 16:11:31 UTC
*** This bug has been marked as a duplicate of bug 708560 *** I know that better than anyone... But in this case, the recommended way to integrate clamav and amavisd-new was overly-permissive, and there's just a much better way to do it. The CONTSCAN method asks clamd to perform the scan itself, which means that it has to be able to read ALL of your personal files, not just the one being scanned. Running clamdscan with --fdpass is better in every way. Now that amavis has an active upstream again, we can hopefully get the default entry replaced: https://gitlab.com/amavis/amavis/issues/59 |