** Also affects: clamav (Ubuntu Resolute)
Importance: Undecided
Status: New
** Also affects: clamav (Ubuntu Stonking)
Importance: Undecided
Status: New
** Description changed:
This bug is related to LP: #2129160
(https://bugs.launchpad.net/ubuntu/+source/clamav/+bug/2129160)
Bug 2129160 aims to fix an issue with the packaging files that prevents
reconfiguration of the clamav sockets.
[Impact]
Bug 2129160 was fixed during the Resolute Feature Freeze (and,
therefore, Stonking also contains the fix). However, during SRU review
for the Jammy, Noble, and Questing uploads it was pointed out that the
modifications which added daemon-reload calls to the clamav-
daemon.postinst script weren't necessary as the script's expansion
already reloads the daemon.
- For a higher quality SRU, the daemon-reload call should be removed from
- the postinst script in the Jammy and Noble uploads (Questing is now
- EOL). However, that means the same modification first needs to be
- reflected in Stonking and then Resolute. Discussions in #devel lead me
- to opening this new bug report specifically for this issue since the
- original bug report is focused on a separate issue.
+ For a higher quality SRU, and as requested, the daemon-reload call
+ should be removed from the postinst script in the Jammy and Noble
+ uploads (but not Questing as it is now EOL). For Jammy and Noble the
+ removal of the unnecessary daemon-reload are bundled in with the rest of
+ the fix on the original bug (since that has not been merged yet for
+ those releases). However, that means the same modification first needs
+ to be reflected in Stonking and then Resolute. Discussions in #devel
+ lead me to opening this new bug report specifically for this issue since
+ the original bug report is focused on a separate issue.
The fix (with the daemon-reload call removed) was merged in the Debian VCS
PR to Debian unstable:
https://salsa.debian.org/clamav-team/clamav/-/merge_requests/12
Above PR was merged here:
https://salsa.debian.org/clamav-team/clamav/-/commit/f32a2a45f70d58150a0b55539da9c4a793d09cc8
[Test Plan]
Ensure that the reconfiguration of the package works even with the removal of
daemon-reload call from the postinst script. This should work against both the
current package, and the -proposed package.
Install the package
sudo apt install clamav-daemon
To test TCP configurability
---------------------------
sudo dpkg-reconfigure clamav-daemon
Select "Socket type" as "TCP"
Specify a custom address and port (eg. the ip on the machine's primary
interface, and a port other than 3310). For example 10.108.97.118 and 3330
Leave everything else as defaults and finish the config setup
sudo systemctl restart clamav-daemon
sudo ss -pln | grep 3330 # Check for the daemon running on a TCP socket (it
won't be):
printf "PING\n" | nc 10.108.97.118 3330 # Try to ping the socket (it won't
work)
systemctl cat clamav-daemon.socket # Doesn't show any configuration with
respect to TCP
To Test Local Socket Configurability
------------------------------------
sudo dpkg-reconfigure clamav-daemon
Select "Socket type" as "UNIX"
Set the socket path to something like /run/clamav/clamd-alt.ctl # Anything
other than the default /var/run/clamav/clamd.ctl so that it is obvious the
configuration was considered and has taken effect
Set custom group owner and permission mode for the socket (eg. a user other
than ubuntu and permissions other than 666)
sudo systemctl restart clamav-daemon
printf "PING\n" | socat - UNIX-CONNECT:/run/clamav/clamd-alt.ctl # Try to
ping the socket (it won't work)
systemctl cat clamav-daemon.socket # Shows that the specified group and
permissions
[Seeded in Ubuntu]
seeded-in-ubuntu clamav-daemon
The source package 'clamav-daemon' does not exist in the Ubuntu primary
archive in resolute for pockets Release, Security, Updates, Proposed with
status in Pending, Published
[Where problems could occur]
Removing the daemon-reload could break automatic configurability of the
package as it may not reload the daemon. However, I have prepared the
package without the daemon-reload and tested it and ensured it still
works as intended.
** Merge proposal linked:
https://code.launchpad.net/~bryanfraschetti/ubuntu/+source/clamav/+git/clamav/+merge/508528
** Merge proposal linked:
https://code.launchpad.net/~bryanfraschetti/ubuntu/+source/clamav/+git/clamav/+merge/508530
** Description changed:
This bug is related to LP: #2129160
(https://bugs.launchpad.net/ubuntu/+source/clamav/+bug/2129160)
Bug 2129160 aims to fix an issue with the packaging files that prevents
reconfiguration of the clamav sockets.
[Impact]
Bug 2129160 was fixed during the Resolute Feature Freeze (and,
therefore, Stonking also contains the fix). However, during SRU review
for the Jammy, Noble, and Questing uploads it was pointed out that the
modifications which added daemon-reload calls to the clamav-
daemon.postinst script weren't necessary as the script's expansion
already reloads the daemon.
For a higher quality SRU, and as requested, the daemon-reload call
should be removed from the postinst script in the Jammy and Noble
- uploads (but not Questing as it is now EOL). For Jammy and Noble the
- removal of the unnecessary daemon-reload are bundled in with the rest of
- the fix on the original bug (since that has not been merged yet for
- those releases). However, that means the same modification first needs
- to be reflected in Stonking and then Resolute. Discussions in #devel
- lead me to opening this new bug report specifically for this issue since
- the original bug report is focused on a separate issue.
+ uploads (but not Questing as it is now EOL). For simplicity the removal
+ of the unnecessary daemon-reload is bundled in with the rest of the fix
+ on the original bug for Jammy and Noble since that has not been merged
+ yet for those releases. However, that means the same modification first
+ needs to be reflected in Stonking and then Resolute. Discussions in
+ #devel lead me to opening this new bug report specifically for this
+ issue on R and S, since the original bug report is focused on a separate
+ issue.
The fix (with the daemon-reload call removed) was merged in the Debian VCS
PR to Debian unstable:
https://salsa.debian.org/clamav-team/clamav/-/merge_requests/12
Above PR was merged here:
https://salsa.debian.org/clamav-team/clamav/-/commit/f32a2a45f70d58150a0b55539da9c4a793d09cc8
[Test Plan]
Ensure that the reconfiguration of the package works even with the removal of
daemon-reload call from the postinst script. This should work against both the
current package, and the -proposed package.
Install the package
sudo apt install clamav-daemon
To test TCP configurability
---------------------------
sudo dpkg-reconfigure clamav-daemon
Select "Socket type" as "TCP"
Specify a custom address and port (eg. the ip on the machine's primary
interface, and a port other than 3310). For example 10.108.97.118 and 3330
Leave everything else as defaults and finish the config setup
sudo systemctl restart clamav-daemon
sudo ss -pln | grep 3330 # Check for the daemon running on a TCP socket (it
won't be):
printf "PING\n" | nc 10.108.97.118 3330 # Try to ping the socket (it won't
work)
systemctl cat clamav-daemon.socket # Doesn't show any configuration with
respect to TCP
To Test Local Socket Configurability
------------------------------------
sudo dpkg-reconfigure clamav-daemon
Select "Socket type" as "UNIX"
Set the socket path to something like /run/clamav/clamd-alt.ctl # Anything
other than the default /var/run/clamav/clamd.ctl so that it is obvious the
configuration was considered and has taken effect
Set custom group owner and permission mode for the socket (eg. a user other
than ubuntu and permissions other than 666)
sudo systemctl restart clamav-daemon
printf "PING\n" | socat - UNIX-CONNECT:/run/clamav/clamd-alt.ctl # Try to
ping the socket (it won't work)
systemctl cat clamav-daemon.socket # Shows that the specified group and
permissions
[Seeded in Ubuntu]
seeded-in-ubuntu clamav-daemon
The source package 'clamav-daemon' does not exist in the Ubuntu primary
archive in resolute for pockets Release, Security, Updates, Proposed with
status in Pending, Published
[Where problems could occur]
Removing the daemon-reload could break automatic configurability of the
package as it may not reload the daemon. However, I have prepared the
package without the daemon-reload and tested it and ensured it still
works as intended.
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2160988
Title:
[SRU] Duplicate daemon-reload call in clamav-daemon.postinst script
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/clamav/+bug/2160988/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs