[From nobody Sun Jun 28 16:54:07 2026
Received: (at submit) by bugs.debian.org; 10 Aug 2023 19:45:15 +0000
X-Spam-Checker-Version: SpamAssassin 3.4.6-bugs.debian.org_2005_01_02
 (2021-04-09) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-8.7 required=4.0 tests=ATTENDEES_DBSPAM_BODY4,
 BAYES_00,DIGITS_LETTERS,FOURLA,FVGT_m_MULTI_ODD,HAS_PACKAGE,
 MURPHY_DRUGS_REL8,RCVD_IN_PBL,RCVD_IN_SORBS_DUL,RDNS_NONE,SPF_FAIL,
 XMAILER_REPORTBUG,X_DEBBUGS_CC autolearn=ham autolearn_force=no
 version=3.4.6-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 72; hammy, 150; neutral, 632; spammy,
 0. spammytokens: hammytokens:0.000-+--sk:taint_o,
 0.000-+--sk:TAINT_O, 
 0.000-+--sk:taint_u, 0.000-+--sk:TAINT_U, 0.000-+--rw-r
Return-path: &lt;michal.maloszewski@canonical.com&gt;
Received: from [46.204.77.106] (port=49774 helo=[127.0.1.1])
 by buxtehude.debian.org with esmtp (Exim 4.94.2)
 (envelope-from &lt;michal.maloszewski@canonical.com&gt;)
 id 1qUBas-007zNM-HM
 for submit@bugs.debian.org; Thu, 10 Aug 2023 19:45:15 +0000
Content-Type: multipart/mixed; boundary=&quot;===============0158999082230727299==&quot;
MIME-Version: 1.0
From: Michal Maloszewski &lt;michal.maloszewski@canonical.com&gt;
To: Debian Bug Tracking System &lt;submit@bugs.debian.org&gt;
Subject: clamav: Mention in the README.Debian that clamAV AppArmor profiles do
 not allow OnAccess scanning
Message-ID: &lt;169169671017.180776.10151259401804273026.reportbug@michalmal99-ubuntu&gt;
X-Mailer: reportbug 7.6.0ubuntu1
Date: Thu, 10 Aug 2023 21:45:10 +0200
X-Debbugs-Cc: michal.maloszewski@canonical.com
Delivered-To: submit@bugs.debian.org

This is a multi-part MIME message sent by reportbug.


--===============0158999082230727299==
Content-Type: text/plain; charset=&quot;us-ascii&quot;
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

Package:=20clamav
Version:=200.103.8+dfsg-0ubuntu0.20.04.1
Severity:=20wishlist
Tags:=20a11y=20patch

Dear=20Maintainer,

Apparmor=20profiles=20included=20with=20the=20Ubuntu=20packages=20-=20&quot;clam=
av-daemon&quot;
and=20&quot;clamav-freshclam&quot;=20-=20do=20not=20allow=20the=20proper=20execution=
=20of=20clamd
(disallow=20OnAccess=20scanning).

The=20only=20missing=20capability=20that=20prevents=20clamd=20from=20starti=
ng=20in=20OnAccess=20mode=20seems=20to=20be=20the=20'sys_admin'=20capabilit=
y.
The=20best=20way=20would=20be=20to=20handle=20it=20by=20giving=20cap_sys_ad=
min=20to=20/usr/sbin/clamd=20or=20to=20the=20clamav=20user.

The=20apparmor=20rule=20that=20would=20need=20to=20be=20added=20by=20defaul=
t=20is=20considered=20not=20safe.

Therefore,=20the=20fix=20can=20only=20be=20to=20ensure=20users=20who=20want=
=20to=20use=20it=20this=20way=20are=20aware.

Proposed=20diff=20in=20the=20attachment.

--=20Package-specific=20info:
---=20configuration=20---
Checking=20configuration=20files=20in=20/etc/clamav

Config=20file:=20clamd.conf
-----------------------
AlertExceedsMax=20disabled
PreludeEnable=20disabled
PreludeAnalyzerName=20=3D=20&quot;ClamAV&quot;
LogFile=20=3D=20&quot;/var/log/clamav/clamav.log&quot;
LogFileUnlock=20disabled
LogFileMaxSize=20=3D=20&quot;4294967295&quot;
LogTime=20=3D=20&quot;yes&quot;
LogClean=20disabled
LogSyslog=20disabled
LogFacility=20=3D=20&quot;LOG_LOCAL6&quot;
LogVerbose=20disabled
LogRotate=20=3D=20&quot;yes&quot;
ExtendedDetectionInfo=20=3D=20&quot;yes&quot;
PidFile=20disabled
TemporaryDirectory=20disabled
DatabaseDirectory=20=3D=20&quot;/var/lib/clamav&quot;
OfficialDatabaseOnly=20disabled
LocalSocket=20=3D=20&quot;/var/run/clamav/clamd.ctl&quot;
LocalSocketGroup=20=3D=20&quot;clamav&quot;
LocalSocketMode=20=3D=20&quot;666&quot;
FixStaleSocket=20=3D=20&quot;yes&quot;
TCPSocket=20disabled
TCPAddr=20disabled
MaxConnectionQueueLength=20=3D=20&quot;15&quot;
StreamMaxLength=20=3D=20&quot;26214400&quot;
StreamMinPort=20=3D=20&quot;1024&quot;
StreamMaxPort=20=3D=20&quot;2048&quot;
MaxThreads=20=3D=20&quot;12&quot;
ReadTimeout=20=3D=20&quot;180&quot;
CommandReadTimeout=20=3D=20&quot;30&quot;
SendBufTimeout=20=3D=20&quot;200&quot;
MaxQueue=20=3D=20&quot;100&quot;
IdleTimeout=20=3D=20&quot;30&quot;
ExcludePath=20disabled
MaxDirectoryRecursion=20=3D=20&quot;15&quot;
FollowDirectorySymlinks=20disabled
FollowFileSymlinks=20disabled
CrossFilesystems=20=3D=20&quot;yes&quot;
SelfCheck=20=3D=20&quot;3600&quot;
ConcurrentDatabaseReload=20=3D=20&quot;yes&quot;
DisableCache=20disabled
VirusEvent=20disabled
ExitOnOOM=20disabled
AllowAllMatchScan=20=3D=20&quot;yes&quot;
Foreground=20disabled
Debug=20disabled
LeaveTemporaryFiles=20disabled
User=20=3D=20&quot;clamav&quot;
Bytecode=20=3D=20&quot;yes&quot;
BytecodeSecurity=20=3D=20&quot;TrustSigned&quot;
BytecodeTimeout=20=3D=20&quot;60000&quot;
BytecodeUnsigned=20disabled
BytecodeMode=20=3D=20&quot;Auto&quot;
DetectPUA=20disabled
ExcludePUA=20disabled
IncludePUA=20disabled
ScanPE=20=3D=20&quot;yes&quot;
ScanELF=20=3D=20&quot;yes&quot;
ScanMail=20=3D=20&quot;yes&quot;
ScanPartialMessages=20disabled
PhishingSignatures=20=3D=20&quot;yes&quot;
PhishingScanURLs=20=3D=20&quot;yes&quot;
HeuristicAlerts=20=3D=20&quot;yes&quot;
HeuristicScanPrecedence=20disabled
StructuredDataDetection=20disabled
StructuredMinCreditCardCount=20=3D=20&quot;3&quot;
StructuredMinSSNCount=20=3D=20&quot;3&quot;
StructuredSSNFormatNormal=20=3D=20&quot;yes&quot;
StructuredSSNFormatStripped=20disabled
ScanHTML=20=3D=20&quot;yes&quot;
ScanOLE2=20=3D=20&quot;yes&quot;
AlertBrokenExecutables=20disabled
AlertBrokenMedia=20disabled
AlertEncrypted=20disabled
StructuredCCOnly=20disabled
AlertEncryptedArchive=20disabled
AlertEncryptedDoc=20disabled
AlertOLE2Macros=20disabled
AlertPhishingSSLMismatch=20disabled
AlertPhishingCloak=20disabled
AlertPartitionIntersection=20disabled
ScanPDF=20=3D=20&quot;yes&quot;
ScanSWF=20=3D=20&quot;yes&quot;
ScanXMLDOCS=20=3D=20&quot;yes&quot;
ScanHWP3=20=3D=20&quot;yes&quot;
ScanArchive=20=3D=20&quot;yes&quot;
ForceToDisk=20disabled
MaxScanTime=20=3D=20&quot;120000&quot;
MaxScanSize=20=3D=20&quot;104857600&quot;
MaxFileSize=20=3D=20&quot;26214400&quot;
MaxRecursion=20=3D=20&quot;16&quot;
MaxFiles=20=3D=20&quot;10000&quot;
MaxEmbeddedPE=20=3D=20&quot;10485760&quot;
MaxHTMLNormalize=20=3D=20&quot;10485760&quot;
MaxHTMLNoTags=20=3D=20&quot;2097152&quot;
MaxScriptNormalize=20=3D=20&quot;5242880&quot;
MaxZipTypeRcg=20=3D=20&quot;1048576&quot;
MaxPartitions=20=3D=20&quot;50&quot;
MaxIconsPE=20=3D=20&quot;100&quot;
MaxRecHWP3=20=3D=20&quot;16&quot;
PCREMatchLimit=20=3D=20&quot;10000&quot;
PCRERecMatchLimit=20=3D=20&quot;5000&quot;
PCREMaxFileSize=20=3D=20&quot;26214400&quot;
OnAccessMountPath=20disabled
OnAccessIncludePath=20disabled
OnAccessExcludePath=20disabled
OnAccessExcludeRootUID=20disabled
OnAccessExcludeUID=20disabled
OnAccessExcludeUname=20disabled
OnAccessMaxFileSize=20=3D=20&quot;5242880&quot;
OnAccessDisableDDD=20disabled
OnAccessPrevention=20disabled
OnAccessExtraScanning=20disabled
OnAccessCurlTimeout=20=3D=20&quot;5000&quot;
OnAccessMaxThreads=20=3D=20&quot;5&quot;
OnAccessRetryAttempts=20disabled
OnAccessDenyOnError=20disabled
DevACOnly=20disabled
DevACDepth=20disabled
DevPerformance=20disabled
DevLiblog=20disabled
DisableCertCheck=20disabled
AlgorithmicDetection=20=3D=20&quot;yes&quot;
BlockMax=20disabled
PhishingAlwaysBlockSSLMismatch=20disabled
PhishingAlwaysBlockCloak=20disabled
PartitionIntersection=20disabled
OLE2BlockMacros=20disabled
ArchiveBlockEncrypted=20disabled

Config=20file:=20freshclam.conf
---------------------------
LogFileMaxSize=20=3D=20&quot;4294967295&quot;
LogTime=20=3D=20&quot;yes&quot;
LogSyslog=20disabled
LogFacility=20=3D=20&quot;LOG_LOCAL6&quot;
LogVerbose=20disabled
LogRotate=20=3D=20&quot;yes&quot;
PidFile=20disabled
DatabaseDirectory=20=3D=20&quot;/var/lib/clamav&quot;
Foreground=20disabled
Debug=20disabled
UpdateLogFile=20=3D=20&quot;/var/log/clamav/freshclam.log&quot;
DatabaseOwner=20=3D=20&quot;clamav&quot;
Checks=20=3D=20&quot;24&quot;
DNSDatabaseInfo=20=3D=20&quot;current.cvd.clamav.net&quot;
DatabaseMirror=20=3D=20&quot;db.local.clamav.net&quot;,=20&quot;database.clamav.net&quot;
PrivateMirror=20disabled
MaxAttempts=20=3D=20&quot;5&quot;
ScriptedUpdates=20=3D=20&quot;yes&quot;
TestDatabases=20=3D=20&quot;yes&quot;
CompressLocalDatabase=20disabled
ExtraDatabase=20disabled
ExcludeDatabase=20disabled
DatabaseCustomURL=20disabled
HTTPProxyServer=20disabled
HTTPProxyPort=20disabled
HTTPProxyUsername=20disabled
HTTPProxyPassword=20disabled
HTTPUserAgent=20disabled
NotifyClamd=20=3D=20&quot;/etc/clamav/clamd.conf&quot;
OnUpdateExecute=20disabled
OnErrorExecute=20disabled
OnOutdatedExecute=20disabled
LocalIPAddress=20disabled
ConnectTimeout=20=3D=20&quot;30&quot;
ReceiveTimeout=20disabled
Bytecode=20=3D=20&quot;yes&quot;

clamav-milter.conf=20not=20found

Software=20settings
-----------------
Version:=200.103.8
Optional=20features=20supported:=20MEMPOOL=20IPv6=20FRESHCLAM_DNS_FIX=20AUT=
OIT_EA06=20BZIP2=20LIBXML2=20PCRE2=20ICONV=20JSON=20

Database=20information
--------------------
Database=20directory:=20/var/lib/clamav
main.cvd:=20version=2062,=20sigs:=206647427,=20built=20on=20Thu=20Sep=2016=
=2014:32:42=202021
daily.cld:=20version=2026996,=20sigs:=202039824,=20built=20on=20Thu=20Aug=
=2010=2009:33:34=202023
bytecode.cld:=20version=20334,=20sigs:=2091,=20built=20on=20Wed=20Feb=2022=
=2022:33:21=202023
Total=20number=20of=20signatures:=208687342

Platform=20information
--------------------
uname:=20Linux=205.15.0-79-generic=20#86~20.04.2-Ubuntu=20SMP=20Mon=20Jul=
=2017=2023:27:17=20UTC=202023=20x86_64
OS:=20linux-gnu,=20ARCH:=20x86_64,=20CPU:=20x86_64
Full=20OS=20version:=20Ubuntu=2020.04.6=20LTS
zlib=20version:=201.2.11=20(1.2.11),=20compile=20flags:=20a9
platform=20id:=200x0a2181810800000000090400

Build=20information
-----------------
GNU=20C:=209.4.0=20(9.4.0)
CPPFLAGS:=20-Wdate-time=20-D_FORTIFY_SOURCE=3D2
CFLAGS:=20-g=20-O2=20-fdebug-prefix-map=3D/build/clamav-q8zvwf/clamav-0.103=
.8+dfsg=3D.=20-fstack-protector-strong=20-Wformat=20-Werror=3Dformat-securi=
ty=20-Wall=20-D_FILE_OFFSET_BITS=3D64=20=20-D_LARGEFILE_SOURCE=20-D_LARGEFI=
LE64_SOURCE=20-D_FILE_OFFSET_BITS=3D64
CXXFLAGS:=20-g=20-O2=20-fdebug-prefix-map=3D/build/clamav-q8zvwf/clamav-0.1=
03.8+dfsg=3D.=20-fstack-protector-strong=20-Wformat=20-Werror=3Dformat-secu=
rity=20-Wall=20-D_FILE_OFFSET_BITS=3D64
LDFLAGS:=20-Wl,-Bsymbolic-functions=20-Wl,-z,relro=20-Wl,-z,now=20-Wl,--as-=
needed
Configure:=20'--build=3Dx86_64-linux-gnu'=20'--prefix=3D/usr'=20'--included=
ir=3D/usr/include'=20'--mandir=3D/usr/share/man'=20'--infodir=3D/usr/share/=
info'=20'--sysconfdir=3D/etc'=20'--localstatedir=3D/var'=20'--disable-silen=
t-rules'=20'--libdir=3D/usr/lib/x86_64-linux-gnu'=20'--runstatedir=3D/run'=
=20'--disable-maintainer-mode'=20'--disable-dependency-tracking'=20'CFLAGS=
=3D-g=20-O2=20-fdebug-prefix-map=3D/build/clamav-q8zvwf/clamav-0.103.8+dfsg=
=3D.=20-fstack-protector-strong=20-Wformat=20-Werror=3Dformat-security=20-W=
all=20-D_FILE_OFFSET_BITS=3D64'=20'CPPFLAGS=3D-Wdate-time=20-D_FORTIFY_SOUR=
CE=3D2'=20'CXXFLAGS=3D-g=20-O2=20-fdebug-prefix-map=3D/build/clamav-q8zvwf/=
clamav-0.103.8+dfsg=3D.=20-fstack-protector-strong=20-Wformat=20-Werror=3Df=
ormat-security=20-Wall=20-D_FILE_OFFSET_BITS=3D64'=20'LDFLAGS=3D-Wl,-Bsymbo=
lic-functions=20-Wl,-z,relro=20-Wl,-z,now=20-Wl,--as-needed'=20'--with-dbdi=
r=3D/var/lib/clamav'=20'--sysconfdir=3D/etc/clamav'=20'--disable-clamav'=20=
'--disable-unrar'=20'--enable-milter'=20'--enable-dns-fix'=20'--with-libjso=
n'=20'--with-system-libmspack'=20'--with-libcurl=3D/usr'=20'--with-gnu-ld'=
=20'--with-systemdsystemunitdir=3D/lib/systemd/system'=20'build_alias=3Dx86=
_64-linux-gnu'=20'OBJCFLAGS=3D-g=20-O2=20-fdebug-prefix-map=3D/build/clamav=
-q8zvwf/clamav-0.103.8+dfsg=3D.=20-fstack-protector-strong=20-Wformat=20-We=
rror=3Dformat-security'
sizeof(void*)=20=3D=208
Engine=20flevel:=20129,=20dconf:=20129

---=20data=20dir=20---
total=20358548
-rw-r--r--=201=20clamav=20clamav=20=20=201430528=20Feb=2022=2023:02=20bytec=
ode.cld
-rw-r--r--=201=20clamav=20clamav=20195224576=20Aug=2010=2010:29=20daily.cld
-rw-r--r--=201=20clamav=20clamav=20=20=20=20=20=20=20=2069=20Aug=2031=20=20=
2022=20freshclam.dat
-rw-r--r--=201=20clamav=20clamav=20170479789=20Aug=2031=20=202022=20main.cvd

--=20System=20Information:
Debian=20Release:=20bullseye/sid
=20=20APT=20prefers=20focal-updates
=20=20APT=20policy:=20(500,=20'focal-updates'),=20(500,=20'focal-security')=
,=20(500,=20'focal-proposed'),=20(500,=20'focal'),=20(100,=20'focal-backpor=
ts')
Architecture:=20amd64=20(x86_64)
Foreign=20Architectures:=20i386

Kernel:=20Linux=205.15.0-79-generic=20(SMP=20w/8=20CPU=20cores)
Kernel=20taint=20flags:=20TAINT_PROPRIETARY_MODULE,=20TAINT_OOT_MODULE,=20T=
AINT_UNSIGNED_MODULE
Locale:=20LANG=3Den_US.UTF-8,=20LC_CTYPE=3Den_US.UTF-8=20(charmap=3DUTF-8),=
=20LANGUAGE=3Den_US.UTF-8=20(charmap=3DUTF-8)
Shell:=20/bin/sh=20linked=20to=20/usr/bin/dash
Init:=20systemd=20(via=20/run/systemd/system)
LSM:=20AppArmor:=20enabled

Versions=20of=20packages=20clamav=20depends=20on:
ii=20=20clamav-freshclam=20[clamav-data]=20=200.103.8+dfsg-0ubuntu0.20.04.1
ii=20=20libc6=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=
=20=20=20=20=20=20=202.31-0ubuntu9.12
ii=20=20libclamav9=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=
=20=20=200.103.8+dfsg-0ubuntu0.20.04.1
ii=20=20libcurl4=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=
=20=20=20=20=207.68.0-1ubuntu2.19
ii=20=20libjson-c4=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=
=20=20=200.13.1+dfsg-7ubuntu0.3
ii=20=20libssl1.1=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=
=20=20=20=201.1.1f-1ubuntu2.19
ii=20=20zlib1g=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=
=20=20=20=20=20=201:1.2.11.dfsg-2ubuntu1.5

Versions=20of=20packages=20clamav=20recommends:
ii=20=20clamav-base=20=200.103.8+dfsg-0ubuntu0.20.04.1

Versions=20of=20packages=20clamav=20suggests:
pn=20=20clamav-docs=20=20=20&lt;none&gt;
pn=20=20libclamunrar=20=20&lt;none&gt;

--=20no=20debconf=20information

--===============0158999082230727299==
Content-Type: text/plain; charset=&quot;us-ascii&quot;
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment; filename=&quot;my_patch.patch&quot;

diff --git a/debian/README.Debian b/debian/README.Debian
index 8c7180ce..d4e2a7b0 100644
--- a/debian/README.Debian
+++ b/debian/README.Debian
@@ -277,7 +277,11 @@ APPARMOR PROFILES
   /etc/clamav/onupdateexecute.d, or /etc/clamav/virusevent.d directories,
   appropriate rules need to be added to the apparmor profile.
 
-  If you prefer to fully disable AppArmor confinement for
+  A common case is ScanOnAccess which for example you'd best allow via
+  a local overrides (see /etc/apparmor.d/local/README)
+    echo &quot;capability sys_admin,&quot; &gt;&gt; /etc/apparmor.d/local/usr.sbin.clamd
+
+  If you instead prefer to fully disable AppArmor confinement for
   clamav-daemon or freshclam, run respectively:
 
     aa-disable /usr/sbin/clamd

--===============0158999082230727299==--
]