[Pkg-clamav-devel] [Clamav-binary] New ClamAV Package

Heiko Richter lists-clamav at heikorichter.name
Wed Jan 24 01:53:29 UTC 2018

Am 24. Januar 2018 02:23:12 MEZ schrieb "Thomas McCourt (tmccourt)" <tmccourt at cisco.com>:
>Yeah, we understand that people might not read the email, blog posts
>etc.  I will discuss more with the Clam-AV dev team tomorrow to make
>sure these scenarios are well thought out (I am sure they have, but a
>double check never hurt).
>Since the mirrors have been a primary focus of myself, IF any mirrors
>are having issues with the switch- I will look into that mirror.

Checking mirrors after the update is to late.

As blacklists are suggested by the mirroring howto and bandwith is still expensive it is to be expected that they are widely used. Furthermore ClamAV mirrors have quite excessive loads during normal operations so admins will definitely optimize regex evaluations by shortning the regex and therby reducing the number of evaluations per client access.

Therefor someone should check *all* mirrors *before* moving to 0.100.x. Otherwise the traffic Spike could rise to ddos levels in busy regions.

Scripting that check in bash should be quite easy.....

>In the future, we want a 1.0.0 version to be, what do the kids call it
>these days? “The bee’s knees” of software releases for ClamAV. That
>isn’t to say, that it isn’t a possibility to move to that version
>instead. I will see what the ClamAV Dev team says first.
>Thank you,
>Tom McCourt
>From: clamav-binary
><clamav-binary-bounces at lists.clamav.net<mailto:clamav-binary-bounces at lists.clamav.net>>
>on behalf of Heiko Richter
><lists-clamav at heikorichter.name<mailto:lists-clamav at heikorichter.name>>
>Reply-To: ClamAV Binary package maintainers
><clamav-binary at lists.clamav.net<mailto:clamav-binary at lists.clamav.net>>
>Date: Tuesday, January 23, 2018 at 6:40 PM
>To: ClamAV Binary package maintainers
><clamav-binary at lists.clamav.net<mailto:clamav-binary at lists.clamav.net>>
>Subject: Re: [Clamav-binary] New ClamAV Package (fwd)
>when releasing 0.100.x please be aware that several mirror operators
>are blocking old outdated versions form their servers by regex's that
>might not accept a 0.100.x release.
>You should expect some mirrors to use blacklists formed like this to
>minimize the number oft regex checks per request:
>Going to 0.100.x will break those blacklists and - depending on how
>many (faulty) blacklists are out there - it could drasticly increase
>the traffic for those mirrors that are configured to accept Version
>I know many open source projects like to stay below 1.0 but being a
>mirror operator myself I expect my traffic to spike as soon as 0.100.x
>is released.
>It might be prudent to discuss a 1.0.0 version. Alternatively somebody
>could check every mirror with a "clamav/0.100.0" useragent and contact
>all the operators whose servers answer with 403 directly - not
>everybody will read the list.
>Am 23. Januar 2018 19:25:53 MEZ schrieb "Joel Esler (jesler)"
><jesler at cisco.com<mailto:jesler at cisco.com>>:
>Something we have "considered".
>I can't type today.
>Joel Esler | Talos: Manager | jesler at cisco.com<mailto:jesler at cisco.com>
>On Jan 23, 2018, at 1:23 PM, Joel Esler (jesler)
><jesler at cisco.com<mailto:jesler at cisco.com>> wrote:
>On Jan 23, 2018, at 10:05 AM, Reinhard Max
><max at suse.com<mailto:max at suse.com>> wrote:
>On Mon, 22 Jan 2018 at 23:49, Micah Snyder (micasnyd) wrote:
>0.99.3 suffered of scope creep and included more than just security
>patches and urgent bugfixes.  As such, I would like to re-target these
>features for an upcoming “0.100.0” version. We are presently
>investigating to validate that the “100” number will not break other
>things that we’re aware of.  If all is okay, we would immediately
>re-release 0.99.3-beta2 as 0.100.0-beta and continue to address the few
>remaining issues blocking us from the 0.100.0 release candidate and
>Given how long ClamAV already exists and still has a zero in front of
>its version number, I wonder if it woudn't make more sense to just call
>this new release 1.0.0 instead of investigating whether three digits in
>the 2nd component would break anything.
>That is also something we have considering.  We want 1.0 to include a
>big functional update or change to warrant that number.  When you move
>between major versions like that, there are entities which then have to
>go "recertify" the software.  So we don't want to make a big change
>like that without something major to add.
>Joel Esler
>Open Source, Design, Web, and Education
>Talos Group
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.alioth.debian.org/pipermail/pkg-clamav-devel/attachments/20180124/09ce766d/attachment.html>
-------------- next part --------------

More information about the Pkg-clamav-devel mailing list