Bug report
Moritz Both <[email protected]> Tue, 4 Nov 2003 13:38:36 +0100
| Newsgroups | gmane.comp.security.virus.openantivirus.general |
|---|---|
| Organization | Aldebaran Daten- und Kommunikationssysteme GmbH |
| Message-ID | <[email protected]> |
This list seems to be quite low-traffic and I am not certain where to put this. I'll post it here and see what happens! Bug Report Summary: When samba-vscan is activated for on-access scanning of files, the smbd sometimes crashes. Version: RedHat 7.3, Kernel 2.4.20 Samba 2.2.7 of RedHat 7.3 recompiled to include samba-vscan and ldap support in the rpm, but otherwise using original RedHat spec file and patches samba-vscan 0.3.4 F-PROT Antivirus for Linux, version 4.3.0 Description: smbd crashes sometimes, unfortunatelly we still cannot reproduce the event. It happens approx. once or twice a day per client, depending on smbd usage. The crash would not harm much if it would leave locked files, i.e. files that had been opened by the client are still marked as open in the open files / lock database of samba. The database can only be cleaned up by restarting samba (all smbd's) manually. Here is a log fragment with some lines before the crash, I think this will be enough but of course I can provide more if neccessary, generated by a setting of log level = 10: [2003/11/04 12:26:54, 3] smbd/process.c:switch_message(685) switch message SMBntcreateX (pid 3888) [2003/11/04 12:26:54, 3] smbd/sec_ctx.c:set_sec_ctx(328) setting sec ctx (500, 500) - sec_ctx_stack_ndx = 0 [2003/11/04 12:26:54, 3] smbd/sec_ctx.c:set_sec_ctx(334) 7 user groups: 500 501 502 5001 5002 5007 509 [2003/11/04 12:26:54, 5] smbd/uid.c:change_to_user(201) change_to_user uid=(0,500) gid=(0,500) [2003/11/04 12:26:54, 10] smbd/nttrans.c:reply_ntcreate_and_X(652) reply_ntcreateX: flags = 0x6, desired_access = 0x2019f file_attributes = 0x80, share_access = 0x0, create_dispo sition = 0x3 create_options = 0x0 root_dir_fid = 0x40 [2003/11/04 12:26:54, 10] smbd/nttrans.c:map_create_disposition(398) map_create_disposition: Mapped create_disposition 0x3 to 0x11 [2003/11/04 12:26:54, 10] smbd/nttrans.c:get_filename(259) get_filename: data_offset = 87, data_len = 33, fname_len = 32 [2003/11/04 12:26:54, 10] smbd/nttrans.c:map_share_mode(523) map_share_mode: Mapped desired access 0x2019f, share access 0x0, file attributes 0x80 to open_mode 0x12 [2003/11/04 12:26:54, 5] smbd/filename.c:unix_convert(119) unix_convert called on file "\TheBat\The Bat Mail\ACCOUNT.LOG" [2003/11/04 12:26:54, 3] lib/util.c:unix_clean_name(387) unix_clean_name [/TheBat/The Bat Mail/ACCOUNT.LOG] [2003/11/04 12:26:54, 5] smbd/mangle_hash.c:is_8_3(368) Checking ACCOUNT.LOG for 8.3 [2003/11/04 12:26:54, 3] smbd/dosmode.c:unix_mode(111) unix_mode(TheBat/The Bat Mail/ACCOUNT.LOG) returning 0744 [2003/11/04 12:26:54, 5] smbd/files.c:file_new(122) allocated file structure 9448, fnum = 13544 (11 used) [2003/11/04 12:26:54, 10] smbd/open.c:open_file_shared1(781) open_file_shared: fname = TheBat/The Bat Mail/ACCOUNT.LOG, share_mode = 12, ofun = 11, mode = 744, oplock reque st = 3 [2003/11/04 12:26:54, 8] lib/util.c:is_in_path(1145) is_in_path: TheBat/The Bat Mail/ACCOUNT.LOG [2003/11/04 12:26:54, 8] lib/util.c:is_in_path(1150) is_in_path: no name list. [2003/11/04 12:26:54, 3] lib/util.c:unix_clean_name(387) unix_clean_name [TheBat/The Bat Mail/ACCOUNT.LOG] [2003/11/04 12:26:54, 8] smbd/dosmode.c:dos_mode(123) dos_mode: TheBat/The Bat Mail/ACCOUNT.LOG [2003/11/04 12:26:54, 8] lib/util.c:is_in_path(1145) is_in_path: TheBat/The Bat Mail/ACCOUNT.LOG [2003/11/04 12:26:54, 8] lib/util.c:is_in_path(1150) is_in_path: no name list. [2003/11/04 12:26:54, 8] smbd/dosmode.c:dos_mode(167) dos_mode returning a [2003/11/04 12:26:54, 4] smbd/open.c:open_file_shared1(940) calling open_file with flags=0x2 flags2=0x40 mode=0744 [2003/11/04 12:26:54, 10] global/vscan-fileaccesslog.c:lrufiles_must_be_checked(247) lookup '/home/moritz/TheBat/The Bat Mail/ACCOUNT.LOG' [2003/11/04 12:26:54, 10] global/vscan-fileaccesslog.c:lrufiles_search(77) search for '/home/moritz/TheBat/The Bat Mail/ACCOUNT.LOG' in lrufiles [2003/11/04 12:26:54, 10] global/vscan-fileaccesslog.c:lrufiles_search(82) file '/home/moritz/TheBat/The Bat Mail/ACCOUNT.LOG' matched [2003/11/04 12:26:54, 10] global/vscan-fileaccesslog.c:lrufiles_must_be_checked(272) Lifetime expired. Invalidate '/home/moritz/TheBat/The Bat Mail/ACCOUNT.LOG' [2003/11/04 12:26:54, 10] global/vscan-fileaccesslog.c:lrufiles_add(120) file '/home/moritz/TheBat/The Bat Mail/ACCOUNT.LOG' should be added [2003/11/04 12:26:54, 10] global/vscan-fileaccesslog.c:lrufiles_search(77) search for '/home/moritz/TheBat/The Bat Mail/ACCOUNT.LOG' in lrufiles [2003/11/04 12:26:54, 10] global/vscan-fileaccesslog.c:lrufiles_search(95) file '/home/moritz/TheBat/The Bat Mail/ACCOUNT.LOG' not matched [2003/11/04 12:26:54, 10] global/vscan-fileaccesslog.c:lrufiles_add(132) alloc space for file entry '/home/moritz/TheBat/The Bat Mail/ACCOUNT.LOG' [2003/11/04 12:26:54, 10] global/vscan-fileaccesslog.c:lrufiles_add(145) lru maximum reached '100' [2003/11/04 12:26:54, 0] lib/fault.c:fault_report(38) =============================================================== [2003/11/04 12:26:54, 0] lib/fault.c:fault_report(39) INTERNAL ERROR: Signal 11 in pid 3888 (2.2.7-security-rollup-fix) Please read the file BUGS.txt in the distribution [2003/11/04 12:26:54, 0] lib/fault.c:fault_report(41) =============================================================== [2003/11/04 12:26:54, 0] lib/util.c:smb_panic(1094) PANIC: internal error There is no hint of a virus infection found at that time. Also, the file ACCOUNT.LOG certainly does not include a virus signature. samba-vscan is switched on on two shares ([homes] and [tmp]) (the above ACCOUNT.LOG is on one of them, homes). Here are the respective smb.conf snippets: [homes] comment = Your home directory browseable = no writable = yes map hidden = yes map system = yes vfs object = /usr/lib/samba/vfs/vscan-fprotd.so vfs options = config-file = /etc/samba/vscan-fprotd.conf [tmp] comment = zeitweiliger Platz (< 2 Tage), wird ruecksichtslos geloescht browseable = yes writable = yes path = /data/a/tmp force group = smbusers valid users = @smbusers force directory mode = 070 vfs object = /usr/lib/samba/vfs/vscan-fprotd.so vfs options = config-file = /etc/samba/vscan-fprotd.conf Note that when we comment the "vfs object =" lines and thus disable the scanning, the error never appears. This is why we believe that samba-vscan is probably the cause. Below is more configuration information. If more info is needed, I will be happy to provide it (higher log level on samba?). Thanks for any help or hints how to avoid this error. --- vscan-fprotd.conf --- ; run-time configure options for vscan-samba using ; F-Prot Daemon. All options set to default values ; do not scan files larger than X bytes. If set to 0 (default), ; this feature is disable (i.e. all files are scanned) max file size = 0 ; log all file access (yes/no). If set to yes, every access will ; be logged. If set to no (default), only access to infected files ; will be logged verbose file logging = no ; if set to yes (default), a file will be scanned while opening scan on open = yes ; if set to yes, a file will be scanned while closing (default is yes) scan on close = yes ; if communication to daemon fails, should access to file denied? ; (default: yes) deny access on error = no ; if daemon files with a minor error (corruption, etc.), ; should access to file denied? ; (default: yes) deny access on minor error = no ; send a warning message via Windows Messenger service ; when virus is found? ; (default: yes) send warning message = yes ; what to do with an infected file ; quarantine: try to move to quantine directory; delete it if moving fails ; delete: delete infected file ; nothing: do nothing infected file action = quarantine ;infected file action = nothing ; where to put infected files - you really want to change this! ; it has to be on the same physical device as the share! quarantine directory = /data/a/tmp/infected ; prefix for files in quarantine quarantine prefix = vir- ; as Windows tries to open a file multiple time in a (very) short time ; of period, samba-vscan use a last recently used file mechanism to avoid ; multiple scans of a file. This setting specified the maximum number of ; elements of the last recently used file list. If set to 0, this ; mechanism is disabled completely (default: 100) max lru files entries = 100 ; an entry is invalidad after lru file entry lifetime (in seconds). ; (Default: 5) lru file entry lifetime = 5 ; IP of F-Prot daemon fprotd ip = 127.0.0.1 ; port number(s), F-Prot daemon listens on ; default is 10200;10201;10202;10203;10204 fprotd port = 10200;10201;10202;10203;10204 ; arguments passed to F-Prot daemon, remember space has to be written ; as %20 fprotd args = -dumb%20-archive ------------------------------------------------------- This SF.net email is sponsored by: SF.net Giveback Program. Does SourceForge.net help you be more productive? Does it help you create better code? SHARE THE LOVE, and help us help YOU! Click Here: http://sourceforge.net/donate/