[opensuse] clamd curiosity
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi, I just noticed that "clamdscan" can not scan almost anything: cer@Telcontar:~> clamdscan /tmp/* /tmp/320d47c9-cfa9-433a-ad1d-2b24b11df4ee: OK /tmp/BootInfo-CZkghR2J: lstat() failed: Permission denied. ERROR /tmp/BootInfo-r7ePTyOE: lstat() failed: Permission denied. ERROR /tmp/VMwareDnD: OK /tmp/YaST2-01430-lMTcNo: lstat() failed: Permission denied. ERROR /tmp/c7f75ac9-b4e3-4f32-9277-4a3425dcc928: OK /tmp/calibre-installer-cache: OK /tmp/check_no_plus.1Acv: OK ... /tmp/check_sysctl.zpHH: OK /tmp/conflicts.txt: OK /tmp/dar_la_hora_en_cron.log: OK /tmp/dialgo.wav.03DckDFBAoOhq: Access denied. ERROR /tmp/dialgo.wav.1YmOqdIaczlIz: Access denied. ERROR /tmp/dialgo.wav.2RBwjb4jWWdTM: Access denied. ERROR /tmp/dialgo.wav.2gHJ2SsXSI7Oo: Access denied. ERROR ... /tmp/dialgo.wav.zs3pmaMYt8mye: Access denied. ERROR /tmp/e6fa4579-b26d-442a-9342-857f994b3f07: OK /tmp/firefox_cer: lstat() failed: Permission denied. ERROR /tmp/generar.log: OK /tmp/gpg-xcr0WB: lstat() failed: Permission denied. ERROR /tmp/hsperfdata_root: OK /tmp/kde-root: lstat() failed: Permission denied. ERROR /tmp/libstorage-Y2DQAK: lstat() failed: Permission denied. ERROR /tmp/mc-root: lstat() failed: Permission denied. ERROR /tmp/procmail_cer: OK /tmp/rpm-md5.0FTZ: Access denied. ERROR /tmp/rpm-md5.2KYB: Access denied. ERROR ... /tmp/specia_files_owner.x0Vr: Access denied. ERROR /tmp/specia_files_owner.x8CC: Access denied. ERROR /tmp/ssh-oRhjHZ8E73LJ: lstat() failed: Permission denied. ERROR /tmp/systemd-private-0u2UcV: lstat() failed: Permission denied. ERROR /tmp/systemd-private-1dtMRP: lstat() failed: Permission denied. ERROR /tmp/systemd-private-1e192c2431f146d9afc71f88a0b8b32d-apache2.service-mlxebp: lstat() failed: Permission denied. ERROR /tmp/systemd-private-1e192c2431f146d9afc71f88a0b8b32d-ntpd.service-qKBKXN: lstat() failed: Permission denied. ERROR /tmp/systemd-private-1e192c2431f146d9afc71f88a0b8b32d-rtkit-daemon.service-d3hE5L: lstat() failed: Permission denied. ERROR ... /tmp/systemd-private-yf0F0p: lstat() failed: Permission denied. ERROR /tmp/thunderbird_cer: lstat() failed: Permission denied. ERROR /tmp/tracker-extract-files.0: lstat() failed: Permission denied. ERROR /tmp/vmware-root: lstat() failed: Permission denied. ERROR /tmp/vmwareNetworking.oZD9uQ: Access denied. ERROR /tmp/y2log-jxeqWb.tar.xz: Access denied. ERROR - ----------- SCAN SUMMARY ----------- Infected files: 0 Total errors: 277 Time: 0.076 sec (0 m 0 s) cer@Telcontar:~> My reading is that the files are opened directly by the daemon, not by clamdscan, with the clamd permissions, not those of the user calling the scan. It means that with clamdscan, which is faster than clamscan (15 seconds to load), I can not scan my own user directory. Only those files that are readable by all. But worse is that this is logged to the warn syslog! Ie, it spams the warning log: <2.4> 2018-03-28 14:58:58 Telcontar clamd 4317 - - lstat() failed on: /tmp/systemd-private-veb9BL <2.4> 2018-03-28 14:58:58 Telcontar clamd 4317 - - lstat() failed on: /tmp/systemd-private-yf0F0p <2.4> 2018-03-28 14:58:58 Telcontar clamd 4317 - - lstat() failed on: /tmp/thunderbird_cer <2.4> 2018-03-28 14:58:58 Telcontar clamd 4317 - - lstat() failed on: /tmp/tracker-extract-files.0 <2.4> 2018-03-28 14:58:58 Telcontar clamd 4317 - - lstat() failed on: /tmp/vmware-root - -- Cheers Carlos E. R. (from 42.2 x86_64 "Malachite" at Telcontar) -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iEYEARECAAYFAlq7lJUACgkQtTMYHG2NR9X5qQCeOEtgapBG2o13RyXwfWto2EhV YPEAnjCOQqJsVW+uHEoi2RvZfxpY9YHF =f/TQ -----END PGP SIGNATURE----- -- To unsubscribe, e-mail: opensuse+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse+owner@opensuse.org
participants (1)
-
Carlos E. R.