Your message dated Sat, 11 Jul 2009 16:20:25 +0000 (UTC)
with message-id <20090711162025.e1437b...@verdi.debian.org>
and subject line Bug#522106: fixed in clamav 0.95.2+dfsg-0volatile1
has caused the Debian Bug report #522106,
regarding clamav-daemon: Doesn't start with anal permissions on /root
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
522106: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=522106
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: clamav-daemon
Version: 0.95+dfsg-1
Severity: normal

I'm getting the followin on most of my centrally managed machines,
where policy has been that no one can peruse /root and cfengine
enforces that policy (so the bypass below is only temporary).

It seems odd to su <user> (shouldn't that really be su - <user>) and
then invoke start-stop-daemon - which has its own chuid argument.

Or, I guess the cheap solutino would be to:
        cd "$DataBaseDirectory" -- or $(dirname "$SUPERVISORPIDFILE")
before the startup

---------------------------------------------------------------------------

# ls -ld /root
drwx--S---. 29 root root 3072 Mar 31 19:50 /root/

# /etc/init.d/clamav-daemon restart
Stopping ClamAV daemon: clamd Waiting .  .  .  .  .  .  .  .  .  . .
Starting ClamAV daemon: clamd /sbin/start-stop-daemon: Unable to chdir() to 
/root (Permission denied)
 failed!

# chmod go+x /root
/etc/init.d/clamav-daemon restart
Stopping ClamAV daemon: clamd.
Starting ClamAV daemon: clamd .

---------------------------------------------------------------------------
-- Package-specific info:
--- configuration ---
ClamAV engine version: 0.95
Checking configuration files in /etc/clamav

Config file: clamd.conf
-----------------------
LogFile = "/var/log/clamav/clamav.log"
LogFileUnlock disabled
LogFileMaxSize disabled
LogTime = "yes"
LogClean disabled
LogVerbose disabled
LogSyslog = "yes"
LogFacility = "LOG_LOCAL6"
PidFile = "/var/run/clamav/clamd.pid"
TemporaryDirectory = "/tmp"
DatabaseDirectory = "/var/lib/clamav"
LocalSocket = "/var/run/clamav/clamd.ctl"
FixStaleSocket = "yes"
TCPSocket disabled
TCPAddr disabled
MaxConnectionQueueLength = "15"
StreamMaxLength = "10485760"
StreamMinPort = "1024"
StreamMaxPort = "2048"
MaxThreads = "12"
ReadTimeout = "180"
CommandReadTimeout = "5"
SendBufTimeout = "500"
MaxQueue = "100"
IdleTimeout = "30"
ExcludePath disabled
MaxDirectoryRecursion = "15"
FollowDirectorySymlinks disabled
FollowFileSymlinks disabled
SelfCheck = "3600"
VirusEvent disabled
ExitOnOOM disabled
Foreground disabled
Debug disabled
LeaveTemporaryFiles disabled
User = "clamav"
AllowSupplementaryGroups = "yes"
DetectPUA disabled
ExcludePUA disabled
IncludePUA disabled
AlgorithmicDetection = "yes"
ScanPE = "yes"
ScanELF = "yes"
DetectBrokenExecutables disabled
ScanMail = "yes"
MailFollowURLs disabled
ScanPartialMessages disabled
PhishingSignatures = "yes"
PhishingScanURLs = "yes"
PhishingAlwaysBlockCloak disabled
PhishingAlwaysBlockSSLMismatch disabled
HeuristicScanPrecedence disabled
StructuredDataDetection disabled
StructuredMinCreditCardCount = "3"
StructuredMinSSNCount = "3"
StructuredSSNFormatNormal = "yes"
StructuredSSNFormatStripped disabled
ScanHTML = "yes"
ScanOLE2 = "yes"
ScanPDF = "yes"
ScanArchive = "yes"
ArchiveBlockEncrypted disabled
MaxScanSize = "104857600"
MaxFileSize = "26214400"
MaxRecursion = "16"
MaxFiles = "10000"
ClamukoScanOnAccess disabled
ClamukoScanOnOpen disabled
ClamukoScanOnClose disabled
ClamukoScanOnExec disabled
ClamukoIncludePath disabled
ClamukoExcludePath disabled
ClamukoMaxFileSize = "5242880"
DevACOnly disabled
DevACDepth disabled

Config file: freshclam.conf
---------------------------
LogFileMaxSize disabled
LogTime disabled
LogVerbose disabled
LogSyslog disabled
LogFacility = "LOG_LOCAL6"
PidFile = "/var/run/clamav/freshclam.pid"
DatabaseDirectory = "/var/lib/clamav/"
Foreground disabled
Debug disabled
AllowSupplementaryGroups disabled
UpdateLogFile = "/var/log/clamav/freshclam.log"
DatabaseOwner = "clamav"
Checks = "24"
DNSDatabaseInfo = "current.cvd.clamav.net"
DatabaseMirror = "db.local.clamav.net", "database.clamav.net"
MaxAttempts = "5"
ScriptedUpdates = "yes"
CompressLocalDatabase disabled
HTTPProxyServer disabled
HTTPProxyPort disabled
HTTPProxyUsername disabled
HTTPProxyPassword disabled
HTTPUserAgent disabled
NotifyClamd = "/etc/clamav/clamd.conf"
OnUpdateExecute disabled
OnErrorExecute disabled
OnOutdatedExecute disabled
LocalIPAddress disabled
ConnectTimeout = "30"
ReceiveTimeout = "30"
SubmitDetectionStats disabled
DetectionStatsCountry disabled
SafeBrowsing disabled

clamav-milter.conf not found

--- data dir ---
total 62128
-rw-r--r--  1 clamav clamav     3973 Mar 30 18:50 MSRBL-Images.hdb
-rw-r--r--. 1 clamav clamav   243578 Mar 18 11:03 MSRBL-SPAM.ndb
-rw-r--r--  1 clamav clamav  2378240 Mar 31 15:39 daily.cld
-rw-r--r--. 1 clamav clamav    31906 Jan 22 06:27 honeynet.hdb
-rw-r--r--. 1 clamav clamav     9484 Jan 21 11:10 honeynet.hdb.gz
-rw-r--r--. 1 clamav clamav   747581 Nov  6 06:30 junk.ndb
-rw-r--r--. 1 clamav clamav   130167 Nov  5 18:56 junk.ndb.gz
-rw-r--r--. 1 clamav clamav 44391424 Feb 15 22:52 main.cld
-rw-r--r--  1 clamav clamav    99405 Mar 31 06:26 mbl.db
-rw-------. 1 clamav clamav      780 Mar 31 19:39 mirrors.dat
-rw-r--r--. 1 clamav clamav  1676397 Nov  6 06:30 phish.ndb
-rw-r--r--. 1 clamav clamav   270749 Nov  5 18:56 phish.ndb.gz
-rw-r--r--. 1 clamav clamav    22183 Nov  6 06:30 rogue.hdb
-rw-r--r--. 1 clamav clamav     9017 Nov  5 18:56 rogue.hdb.gz
-rw-r--r--. 1 clamav clamav  1373515 Nov  6 06:31 scam.ndb
-rw-r--r--. 1 clamav clamav   271560 Nov  5 18:56 scam.ndb.gz
-rw-r--r--. 1 clamav clamav  7451460 Mar 14 06:26 securiteinfo.hdb
-rw-r--r--. 1 clamav clamav  3012029 Mar 13 10:53 securiteinfo.hdb.gz
-rw-r--r--. 1 clamav clamav   109076 Oct  7 06:25 submit_action_list_clamav
-rw-r--r--  1 clamav clamav    24365 Mar 31 06:26 submit_action_list_clamav.gz
-rw-r--r--. 1 clamav clamav   805365 Jun 11  2008 vx.hdb
-rw-r--r--. 1 clamav clamav   321464 Jun 10  2008 vx.hdb.gz

-- System Information:
Debian Release: squeeze-sid
  APT prefers testing-proposed-updates
  APT policy: (500, 'testing-proposed-updates'), (500, 'proposed-updates'), 
(500, 'unstable'), (500, 'testing'), (500, 'stable'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.29 (SMP w/2 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages clamav-daemon depends on:
ii  clamav-base            0.95+dfsg-1       anti-virus utility for Unix - base
ii  clamav-freshclam [clam 0.95+dfsg-1       anti-virus utility for Unix - viru
ii  libbz2-1.0             1.0.5-1           high-quality block-sorting file co
ii  libc6                  2.9-6             GNU C Library: Shared libraries
ii  libclamav6             0.95+dfsg-1       anti-virus utility for Unix - libr
ii  libltdl3               1.5.26-4          A system independent dlopen wrappe
ii  libtommath0            0.39-3            multiple-precision integer library
ii  lsb-base               3.2-22            Linux Standard Base 3.2 init scrip
ii  ucf                    3.0018            Update Configuration File: preserv
ii  zlib1g                 1:1.2.3.3.dfsg-13 compression library - runtime

clamav-daemon recommends no packages.

Versions of packages clamav-daemon suggests:
ii  clamav-docs                  0.95+dfsg-1 anti-virus utility for Unix - docu
pn  daemon                       <none>      (no description available)

-- no debconf information



--- End Message ---
--- Begin Message ---
Source: clamav
Source-Version: 0.95.2+dfsg-0volatile1

We believe that the bug you reported is fixed in the latest version of
clamav, which is due to be installed in the volatile.debian.org FTP archive:

clamav-base_0.95.2+dfsg-0volatile1_all.deb
  to pool/volatile/main/c/clamav/clamav-base_0.95.2+dfsg-0volatile1_all.deb
clamav-daemon_0.95.2+dfsg-0volatile1_i386.deb
  to pool/volatile/main/c/clamav/clamav-daemon_0.95.2+dfsg-0volatile1_i386.deb
clamav-dbg_0.95.2+dfsg-0volatile1_i386.deb
  to pool/volatile/main/c/clamav/clamav-dbg_0.95.2+dfsg-0volatile1_i386.deb
clamav-docs_0.95.2+dfsg-0volatile1_all.deb
  to pool/volatile/main/c/clamav/clamav-docs_0.95.2+dfsg-0volatile1_all.deb
clamav-freshclam_0.95.2+dfsg-0volatile1_i386.deb
  to 
pool/volatile/main/c/clamav/clamav-freshclam_0.95.2+dfsg-0volatile1_i386.deb
clamav-milter_0.95.2+dfsg-0volatile1_i386.deb
  to pool/volatile/main/c/clamav/clamav-milter_0.95.2+dfsg-0volatile1_i386.deb
clamav-testfiles_0.95.2+dfsg-0volatile1_all.deb
  to pool/volatile/main/c/clamav/clamav-testfiles_0.95.2+dfsg-0volatile1_all.deb
clamav_0.95.2+dfsg-0volatile1.diff.gz
  to pool/volatile/main/c/clamav/clamav_0.95.2+dfsg-0volatile1.diff.gz
clamav_0.95.2+dfsg-0volatile1.dsc
  to pool/volatile/main/c/clamav/clamav_0.95.2+dfsg-0volatile1.dsc
clamav_0.95.2+dfsg-0volatile1_i386.deb
  to pool/volatile/main/c/clamav/clamav_0.95.2+dfsg-0volatile1_i386.deb
clamav_0.95.2+dfsg.orig.tar.gz
  to pool/volatile/main/c/clamav/clamav_0.95.2+dfsg.orig.tar.gz
libclamav-dev_0.95.2+dfsg-0volatile1_i386.deb
  to pool/volatile/main/c/clamav/libclamav-dev_0.95.2+dfsg-0volatile1_i386.deb
libclamav6_0.95.2+dfsg-0volatile1_i386.deb
  to pool/volatile/main/c/clamav/libclamav6_0.95.2+dfsg-0volatile1_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 522...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

volatile.debian.org distribution maintenance software
pp.
Stephen Gran <sg...@debian.org> (supplier of updated clamav package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@volatile.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Sat, 20 Jun 2009 14:53:09 +0100
Source: clamav
Binary: clamav libclamav-dev clamav-dbg clamav-milter clamav-base 
clamav-freshclam clamav-testfiles clamav-daemon clamav-docs libclamav6
Architecture: source i386 all
Version: 0.95.2+dfsg-0volatile1
Distribution: etch-volatile
Urgency: low
Maintainer: ClamAV Team <pkg-clamav-de...@lists.alioth.debian.org>
Changed-By: Stephen Gran <sg...@debian.org>
Description: 
 clamav     - anti-virus utility for Unix - command-line interface
 clamav-base - anti-virus utility for Unix - base package
 clamav-daemon - anti-virus utility for Unix - scanner daemon
 clamav-dbg - debug symbols for ClamAV
 clamav-docs - anti-virus utility for Unix - documentation
 clamav-freshclam - anti-virus utility for Unix - virus database update utility
 clamav-milter - anti-virus utility for Unix - sendmail integration
 clamav-testfiles - anti-virus utility for Unix - test files
 libclamav-dev - anti-virus utility for Unix - development files
 libclamav6 - anti-virus utility for Unix - library
Closes: 522106 523573 524356 525044 525084 525483 526024 526123 526644 526727 
526730 526745 527320 527903 533397 533548 533568 533638 533667 533779 534339
Changes: 
 clamav (0.95.2+dfsg-0volatile1) etch-volatile; urgency=low
 .
   * New upstream version
   * Should fix crash on unofficial sigs (closes: #525483)
   * Get rid of ridiculous home rolled suid (closes: #522106)
   * Freshclam gets 0400 or 0444 config file (closes: #524356)
   * Debconf templates and debian/control reviewed by the debian-l10n-
     english team as part of the Smith review project. Closes: #523573
   * [Debconf translation updates]
     - Swedish. Closes: #525044
     - Japanese. Closes: #525084
     - French. Closes: #526024
     - Portuguese. Closes: #526644
     - Russian. Closes: #526727
     - German. Closes: #526730
     - Dutch. Closes: #526745
     - Galician. Closes: #527320
     - French (closes: #533667)
     - Russian (closes: #533548)
     - Swedish (closes: #533568)
     - Portuguese (closes: #533779)
     - Finnish (closes: #534339)
   * Define status_of_proc in the event that it's not in lsb/init-functions
     (closes: #527903)
   * Stop referencing /etc/default/clamav-milter and drop command line
     arguments in milter init script (closes: #526123)
   * Don't abort dpkg on failed start (closes: #533397)
   * Get rid of spurious patch downgrading version (closes: #533638)
Files: 
 4c58bfaef0ccf246d21c74e40543b791 998 utils optional 
clamav_0.95.2+dfsg-0volatile1.dsc
 86328e1b3bb03dbdc4580bb5e72a7593 25146569 utils optional 
clamav_0.95.2+dfsg.orig.tar.gz
 ee07bd2d857b10fe90f70908dd69c7c2 254964 utils optional 
clamav_0.95.2+dfsg-0volatile1.diff.gz
 56704145a55b313650eda50190ca606d 22261760 utils optional 
clamav-base_0.95.2+dfsg-0volatile1_all.deb
 270c0152d4782d80d884db5781721ade 225350 utils optional 
clamav-testfiles_0.95.2+dfsg-0volatile1_all.deb
 5bcacb4b36a0fdd87f61ac11c9bed3d7 1116690 doc optional 
clamav-docs_0.95.2+dfsg-0volatile1_all.deb
 6145d6aa329c67a593e1c8a9ec5a7fd5 579268 libs optional 
libclamav6_0.95.2+dfsg-0volatile1_i386.deb
 4c6fec3263d39c0773cf1ba73be25d31 268084 utils optional 
clamav_0.95.2+dfsg-0volatile1_i386.deb
 e3d1a08dd3d5f9cc12635cd8346c97b4 361478 utils optional 
clamav-daemon_0.95.2+dfsg-0volatile1_i386.deb
 0db8b1a213e1f7c83eaa114d23c2d890 277802 utils optional 
clamav-freshclam_0.95.2+dfsg-0volatile1_i386.deb
 12dfe5e6ea68976196510595db06cafd 290272 utils extra 
clamav-milter_0.95.2+dfsg-0volatile1_i386.deb
 296937369d944b2516bfd996d36c24c7 607636 libdevel optional 
libclamav-dev_0.95.2+dfsg-0volatile1_i386.deb
 700a450cc30ad41681991eada8ebea73 1049056 debug extra 
clamav-dbg_0.95.2+dfsg-0volatile1_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAkpYshMACgkQSYIMHOpZA44gsACeIhlGozZmxBkjXgskNDAIBez4
+9YAn2GCJPJ5fxVSGaEm6mlNClYEk+t0
=ZDr5
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to