[Amavisd-new-debian-devel] Fwd: Bug in amavisd-new.

Alexander Wirt formorer at formorer.de
Sun May 23 06:51:56 UTC 2010


Henrique de Moraes Holschuh schrieb am Sunday, den 23. May 2010:

> > Postfix (25) is accepting the mail. �It then tries to deliver it to amavis,
> > and it 'thinks' it is successful, so postfix removes it from the queue.
> > Amavis actually had a problem, but instead of returning an error code to
> > postfix, it inadvertantly returned a success code. �Here are the applicable
> 
> ...
> 
> > log entries:
> > May �7 14:54:18 av1 amavis[24167]: (24167-11-2) Negative SMTP resp to
> > DATA: 250 Ok
> > May �7 14:54:18 av1 amavis[24167]: (24167-11-2) Message-ID:
> > <4BE40D65.3050609 at ac-lille.fr>, mail_id: w6Qb5UwLrm7G, Hits: -2.599,
> > size: 2671, queued_as: 250 2.1.0 Ok/250 2.1.5 Ok, 5811 ms
> > 
> > I don't know why my bug report doesn't appear in your bug reporting interface.
> > 
> > And when i apply the patch found on this link :
> > http://marc.info/?l=amavis-user&m=122055191316224
> > 
> > All works fine.
> 
> Ok, so it is a silent dataloss bug, but quite rare (because it happens only
> on sites with an extremely broken and stupid backscatter-generating
> configuration that goes against every postfix and amavisd-new out there).
> 
> Also, the data lost is actually the information that the email was NOT going
> to be delivered (i.e. the bounce), since it is the rejection in the
> after-filter injection path that triggers the bug.
> 
> And it is supposed to be fixed in testing and sid, but stable is probably
> vulnerable.
> 
> Should we bother with an upload to proposed-updates?
I'm not sure as this bug isn't triggered very often, otherwise it loses data
and it does it silently. 

So I think I'll prepare a fixed package for stable which also includes the
patch for the data-pipelining problem and ask debian-release for permission
to upload. 

Alex




More information about the Amavisd-new-debian-devel mailing list