Bug report

Moritz Both <[email protected]> Tue, 4 Nov 2003 13:38:36 +0100
Newsgroups gmane.comp.security.virus.openantivirus.general
Organization Aldebaran Daten- und Kommunikationssysteme GmbH
Message-ID <[email protected]>
This list seems to be quite low-traffic and I am not certain where to
put this. I'll post it here and see what happens!

Bug Report

Summary:
When samba-vscan is activated for on-access scanning of files, the
smbd sometimes crashes.

Version:
RedHat 7.3, Kernel 2.4.20
Samba 2.2.7 of RedHat 7.3
  recompiled to include samba-vscan and ldap support in the rpm, but
  otherwise using original RedHat spec file and patches
samba-vscan 0.3.4
F-PROT Antivirus for Linux, version 4.3.0

Description:
smbd crashes sometimes, unfortunatelly we still cannot reproduce the
event. It happens approx. once or twice a day per client, depending on
smbd usage. The crash would not harm much if it would leave locked
files, i.e. files that had been opened by the client are still marked
as open in the open files / lock database of samba. The database can
only be cleaned up by restarting samba (all smbd's) manually.

Here is a log fragment with some lines before the crash, I think this
will be enough but of course I can provide more if neccessary,
generated by a setting of log level = 10:

[2003/11/04 12:26:54, 3] smbd/process.c:switch_message(685)
  switch message SMBntcreateX (pid 3888)
[2003/11/04 12:26:54, 3] smbd/sec_ctx.c:set_sec_ctx(328)
  setting sec ctx (500, 500) - sec_ctx_stack_ndx = 0
[2003/11/04 12:26:54, 3] smbd/sec_ctx.c:set_sec_ctx(334)
  7 user groups:
  500 501 502 5001 5002 5007 509
[2003/11/04 12:26:54, 5] smbd/uid.c:change_to_user(201)
  change_to_user uid=(0,500) gid=(0,500)
[2003/11/04 12:26:54, 10] smbd/nttrans.c:reply_ntcreate_and_X(652)
  reply_ntcreateX: flags = 0x6, desired_access = 0x2019f file_attributes = 0x80, share_access = 0x0, create_dispo
sition = 0x3 create_options = 0x0 root_dir_fid = 0x40
[2003/11/04 12:26:54, 10] smbd/nttrans.c:map_create_disposition(398)
  map_create_disposition: Mapped create_disposition 0x3 to 0x11
[2003/11/04 12:26:54, 10] smbd/nttrans.c:get_filename(259)
  get_filename: data_offset = 87, data_len = 33, fname_len = 32
[2003/11/04 12:26:54, 10] smbd/nttrans.c:map_share_mode(523)
  map_share_mode: Mapped desired access 0x2019f, share access 0x0, file attributes 0x80 to open_mode 0x12
[2003/11/04 12:26:54, 5] smbd/filename.c:unix_convert(119)
  unix_convert called on file "\TheBat\The Bat Mail\ACCOUNT.LOG"
[2003/11/04 12:26:54, 3] lib/util.c:unix_clean_name(387)
  unix_clean_name [/TheBat/The Bat Mail/ACCOUNT.LOG]
[2003/11/04 12:26:54, 5] smbd/mangle_hash.c:is_8_3(368)
  Checking ACCOUNT.LOG for 8.3
[2003/11/04 12:26:54, 3] smbd/dosmode.c:unix_mode(111)
  unix_mode(TheBat/The Bat Mail/ACCOUNT.LOG) returning 0744
[2003/11/04 12:26:54, 5] smbd/files.c:file_new(122)
  allocated file structure 9448, fnum = 13544 (11 used)
[2003/11/04 12:26:54, 10] smbd/open.c:open_file_shared1(781)
  open_file_shared: fname = TheBat/The Bat Mail/ACCOUNT.LOG, share_mode = 12, ofun = 11, mode = 744, oplock reque
st = 3
[2003/11/04 12:26:54, 8] lib/util.c:is_in_path(1145)
  is_in_path: TheBat/The Bat Mail/ACCOUNT.LOG
[2003/11/04 12:26:54, 8] lib/util.c:is_in_path(1150)
  is_in_path: no name list.
[2003/11/04 12:26:54, 3] lib/util.c:unix_clean_name(387)
  unix_clean_name [TheBat/The Bat Mail/ACCOUNT.LOG]
[2003/11/04 12:26:54, 8] smbd/dosmode.c:dos_mode(123)
  dos_mode: TheBat/The Bat Mail/ACCOUNT.LOG
[2003/11/04 12:26:54, 8] lib/util.c:is_in_path(1145)
  is_in_path: TheBat/The Bat Mail/ACCOUNT.LOG
[2003/11/04 12:26:54, 8] lib/util.c:is_in_path(1150)
  is_in_path: no name list.
[2003/11/04 12:26:54, 8] smbd/dosmode.c:dos_mode(167)
  dos_mode returning a
[2003/11/04 12:26:54, 4] smbd/open.c:open_file_shared1(940)
  calling open_file with flags=0x2 flags2=0x40 mode=0744
[2003/11/04 12:26:54, 10] global/vscan-fileaccesslog.c:lrufiles_must_be_checked(247)
  lookup '/home/moritz/TheBat/The Bat Mail/ACCOUNT.LOG'
[2003/11/04 12:26:54, 10] global/vscan-fileaccesslog.c:lrufiles_search(77)
  search for '/home/moritz/TheBat/The Bat Mail/ACCOUNT.LOG' in lrufiles
[2003/11/04 12:26:54, 10] global/vscan-fileaccesslog.c:lrufiles_search(82)
  file '/home/moritz/TheBat/The Bat Mail/ACCOUNT.LOG' matched
[2003/11/04 12:26:54, 10] global/vscan-fileaccesslog.c:lrufiles_must_be_checked(272)
  Lifetime expired. Invalidate '/home/moritz/TheBat/The Bat Mail/ACCOUNT.LOG'
[2003/11/04 12:26:54, 10] global/vscan-fileaccesslog.c:lrufiles_add(120)
  file '/home/moritz/TheBat/The Bat Mail/ACCOUNT.LOG' should be added
[2003/11/04 12:26:54, 10] global/vscan-fileaccesslog.c:lrufiles_search(77)
  search for '/home/moritz/TheBat/The Bat Mail/ACCOUNT.LOG' in lrufiles
[2003/11/04 12:26:54, 10] global/vscan-fileaccesslog.c:lrufiles_search(95)
  file '/home/moritz/TheBat/The Bat Mail/ACCOUNT.LOG' not matched
[2003/11/04 12:26:54, 10] global/vscan-fileaccesslog.c:lrufiles_add(132)
  alloc space for file entry '/home/moritz/TheBat/The Bat Mail/ACCOUNT.LOG'
[2003/11/04 12:26:54, 10] global/vscan-fileaccesslog.c:lrufiles_add(145)
  lru maximum reached '100'
[2003/11/04 12:26:54, 0] lib/fault.c:fault_report(38)
  ===============================================================
[2003/11/04 12:26:54, 0] lib/fault.c:fault_report(39)
  INTERNAL ERROR: Signal 11 in pid 3888 (2.2.7-security-rollup-fix)
  Please read the file BUGS.txt in the distribution
[2003/11/04 12:26:54, 0] lib/fault.c:fault_report(41)
  ===============================================================
[2003/11/04 12:26:54, 0] lib/util.c:smb_panic(1094)
  PANIC: internal error

There is no hint of a virus infection found at that time. Also, the
file ACCOUNT.LOG certainly does not include a virus signature.

samba-vscan is switched on on two shares ([homes] and [tmp]) (the
above ACCOUNT.LOG is on one of them, homes). Here are the respective
smb.conf snippets:

[homes]
   comment = Your home directory
   browseable = no
   writable = yes
   map hidden = yes
   map system = yes
   vfs object = /usr/lib/samba/vfs/vscan-fprotd.so
   vfs options = config-file = /etc/samba/vscan-fprotd.conf

[tmp]
   comment = zeitweiliger Platz (< 2 Tage), wird ruecksichtslos geloescht
   browseable = yes
   writable = yes
   path = /data/a/tmp
   force group = smbusers
   valid users = @smbusers
   force directory mode = 070
   vfs object = /usr/lib/samba/vfs/vscan-fprotd.so
   vfs options = config-file = /etc/samba/vscan-fprotd.conf

Note that when we comment the "vfs object =" lines and thus disable
the scanning, the error never appears. This is why we believe that
samba-vscan is probably the cause.

Below is more configuration information. If more info is needed, I
will be happy to provide it (higher log level on samba?).

Thanks for any help or hints how to avoid this error.


--- vscan-fprotd.conf ---
; run-time configure options for vscan-samba using
; F-Prot Daemon. All options set to default values

; do not scan files larger than X bytes. If set to 0 (default),
; this feature is disable (i.e. all files are scanned)
max file size = 0

; log all file access (yes/no). If set to yes, every access will
; be logged. If set to no (default), only access to infected files
; will be logged
verbose file logging = no

; if set to yes (default), a file will be scanned while opening
scan on open = yes

; if set to yes, a file will be scanned while closing (default is yes)
scan on close = yes

; if communication to daemon fails, should access to file denied?
; (default: yes)
deny access on error = no

; if daemon files with a minor error (corruption, etc.),
; should access to file denied?
; (default: yes)
deny access on minor error = no

; send a warning message via Windows Messenger service
; when virus is found?
; (default: yes)
send warning message = yes

; what to do with an infected file
; quarantine: try to move to quantine directory; delete it if moving fails
; delete:     delete infected file
; nothing:    do nothing
infected file action = quarantine
;infected file action = nothing

; where to put infected files - you really want to change this!
; it has to be on the same physical device as the share!
quarantine directory  = /data/a/tmp/infected
; prefix for files in quarantine
quarantine prefix = vir-

; as Windows tries to open a file multiple time in a (very) short time
; of period, samba-vscan use a last recently used file mechanism to avoid
; multiple scans of a file. This setting specified the maximum number of
; elements of the last recently used file list. If set to 0, this
; mechanism is disabled completely (default: 100)
max lru files entries = 100

; an entry is invalidad after lru file entry lifetime (in seconds).
; (Default: 5)
lru file entry lifetime = 5

; IP of F-Prot daemon
fprotd ip = 127.0.0.1

; port number(s), F-Prot daemon listens on
; default is 10200;10201;10202;10203;10204
fprotd port = 10200;10201;10202;10203;10204

; arguments passed to F-Prot daemon, remember space has to be written
; as %20
fprotd args = -dumb%20-archive



-------------------------------------------------------
This SF.net email is sponsored by: SF.net Giveback Program.
Does SourceForge.net help you be more productive?  Does it
help you create better code?   SHARE THE LOVE, and help us help
YOU!  Click Here: http://sourceforge.net/donate/