[Pkg-clamav-devel] Bug#543309: Bug#543309: local socket clamav-milter.ctl unsafe - milter set to error state

Stephen Gran sgran at debian.org
Tue Aug 25 14:39:32 UTC 2009


This one time, at band camp, Mark Rushing said:
> On Tue, 2009-08-25 at 08:37 +0100, Stephen Gran wrote:
> > > Ah, ok. I'd suggest correcting the installation instructions, too. They
> > > also say to use clamav-milter.ctl, even when configuring manually,
> > > without using the convenience script. It's the README-Debian.gz
> > 
> > Good catch.  On review, it looks like more places reference
> > clamav-milter.ctl than reference milter.ctl, so I have changed the
> > latter to be in harmony with the former.
> 
> Does that mean you're changing where the milter socket is created, to
> match the documentation? How radical if so! ;)
> 
> If you're doing that, could you write something into the update scripts
> that will change the .m4 file back to clamav-milter, for people who
> have, over the years, corrected that mistake? I know I'll have a lot of
> machines to update with broken configurations if that socket gets
> renamed without making sure the .m4 file points to the right place.

Nothing should change from your point of view.  The m4 file has
clamav-milter.ctl in it as it always did, and since it won't change on
upgrade, you won't be reprompted for it.

The clamav-milter.conf will also not change on upgrade, since I've only
changed the defaults for new installs, not programmatically altered
what's in the file after upgrade.

This means, unless I'm missing something, that they should match after
just as before - if not, please let us know, as that would be a fairly
serious bug in conffile handling.

> I'm a little amazed nobody has reported this before. Maybe I'm the only
> one using it... ?

I know there are lots of other people using the milter, but you may be
the only one using the m4 :)

Cheers,
-- 
 -----------------------------------------------------------------
|   ,''`.                                            Stephen Gran |
|  : :' :                                        sgran at debian.org |
|  `. `'                        Debian user, admin, and developer |
|    `-                                     http://www.debian.org |
 -----------------------------------------------------------------
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature
URL: <http://lists.alioth.debian.org/pipermail/pkg-clamav-devel/attachments/20090825/703a2d37/attachment.pgp>


More information about the Pkg-clamav-devel mailing list