Re: Scanning memory mapped files

neel roy via clamav-users <[email protected]>
Newsgroups gmane.comp.security.virus.clamav.user
Message-ID <1733391171.S.23990.16600.f4-234-163.1733392858.19088@webmail.rediffmail.com>
Hello,

I think I could not explain correctly.

I am not using clamonacc. I run my own program that uses fanotify, just like clamonacc does, and gets list of files that are modifed\added.

I send that list to clamscan or clamdscan.

The problem is limitation of fanotify which is that &quot; The fanotify API does not report file accesses and modifications that may occur because of mmap(2), msync(2), and munmap(2).&quot;.

Now my assumption is mmap, msync, munmap deals with memory mapped files. So questions I have are:
&nbsp;	does clamav scan memory mapped files?&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Further details: If run clamscan or clamdscan on &quot;/&quot; it would scan all files so it does not matter. But how does clamonacc overcomes this limitation since it uses fanotify?
	If it does, is there a way to ask clamav to scan just memory mapped files?&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Further details: This question is probably invalid. You can ignore this question.
Thanks in advance,
-Neel.
From: &lt;[email protected]&gt;
Sent: Thu, 05 Dec 2024 15:02:51
To: &lt;[email protected]&gt;
Cc: &lt;[email protected]&gt;
Subject: Re: [clamav-users] Scanning memory mapped files

Thank you for your email.
I saw the post you mentioned (https://superuser.com/questions/1863769/clamav-and-memory-mapped-files).
It seems to be the same issue!
I am considering commenting out the part of the startup shell script that starts and stops the clamonacc.service,&nbsp;
but I haven&#39;t been able to test it yet.
For now, I think we can only ignore the error messages.
Thank you for your understanding.
&nbsp;
&nbsp;
&nbsp;
$B:9=P?M(B: clamav-users &lt;[email protected]&gt; $B$,(B neel roy via clamav-users &lt;[email protected]&gt; $B$NBeM}$GAw?.(B
$BAw?.F|;~(B: 2024$BG/(B12$B7n(B5$BF|(B 16:48
$B08@h(B: [email protected] &lt;[email protected]&gt;
CC: neel roy &lt;[email protected]&gt;
$B7oL&gt;(B: Re: [clamav-users] Scanning memory mapped files
&nbsp;
Hello,

Sorry, I should have given complete information but my thought process was little slow :) Here is the question as I posted on stackoverflow (https://superuser.com/questions/1863769/clamav-and-memory-mapped-files):
&nbsp;I am using clamav on Enterprise Linux 9. In order to optimize it&#39;s scanning I am getting list of modified files using fanotify (https://man7.org/linux/man-pages/man7/fanotify.7.html).
But it states &quot; The fanotify API does not report file accesses and modifications that may occur because of mmap(2), msync(2), and munmap(2).&quot;.
Based on this I have two questions:
	does clamav scan memory mapped files?	If it does, is there a way to ask clamav to scan just memory mapped files?
Thanks in advance!


Thanks!

From: neel roy via clamav-users &lt;[email protected]&gt;
Sent: Thu, 05 Dec 2024 12:24:27
To: &lt;[email protected]&gt;
Cc: neel roy &lt;[email protected]&gt;
Subject: [clamav-users] Scanning memory mapped files

Hello,

Does clamav scan memory mapped files? If yes, does it option to scan _just_ memory mapped files?

Thanks in advance,
-Neel.
_______________________________________________

Manage your clamav-users mailing list subscription / unsubscribe:
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/Cisco-Talos/clamav-documentation

https://docs.clamav.net/#mailing-lists-and-chat

_______________________________________________

Manage your clamav-users mailing list subscription / unsubscribe:
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/Cisco-Talos/clamav-documentation

https://docs.clamav.net/#mailing-lists-and-chat
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.