  • clamav fails to build if clamav user doesn't exist
    (not everyone wants to use clamav-server port)
  • create dir with virus database automatically : /share/clamav
  • configure clamav to run out of the box
  • set suid bit of freshclam to work with clamxav

comment:1 Changed 7 years ago by mf2k (Frank Schima)

Trac requires valid email addresses.

comment:2 Changed 7 years ago by mf2k (Frank Schima)

comment:3 Changed 7 years ago by danielluke (Daniel J. Luke)

I'll try to take a look at this this weekend (and try to incorporate as much as is reasonable) - a couple of thoughts though.

clamav should build without the clamav user (I haven't tested that specifically in a while, so upstream may have broken it) - I'm not sure if the buildbot has a clamav user or not, the existing (lack of) setup was done on purpose since there are a wide variety of ways one might want to use clamav, I don't think setting the suid bit is something we want to do at all.

comment:4 Changed 7 years ago by danielluke (Daniel J. Luke)

comment:5 Changed 7 years ago by mroman@…

The freshclam.conf says it runs by default as clamav user. So I was curious and deleted the clamav user and group using dscl. Rebuilding port gave me configure error.
The problem with no having clamav user is that enduser has to manually edit .conf files and create ${prefix}/share/clamav with appropriate owner/group to enable freshclam to fetch virus definitions. But most users just use default settings. Besides, separate clamav user account rather doesn't create any security risk.
If you look at clamav-server there is big list of things for user to do. Pretty nasty for me.
I am not sure about this suid bit, but I suppose it would not pose any additional security problem: it's just for freshclam and the clamav user doesn't have admin privileges afterall.
Thank you for your response. I have just thought to make the configuration of this port a little easier.

comment:6 Changed 7 years ago by mroman@…

The documentation says, that the check for existence of clamav account may be disabled when installing on unprivileged user account:
Right now I don't have access to mac to check this.

comment:7 Changed 7 years ago by mroman@…

On second thoughts, probably using suid on freshclam isn't the best solution indeed, however we could consider setting to "clamav" the owner and group of freshclam in post-destroot.

comment:8 Changed 7 years ago by petrrr

comment:9 Changed 6 years ago by cooljeanius (Eric Gallager)

comment:10 Changed 6 years ago by jul_bsd@…

