files in /tmp

Alain Fauconnet <[email protected]> Mon, 8 Mar 2004 17:29:26 +0700
Newsgroups gmane.comp.security.virus.vtools
Message-ID <[email protected]>
Hello Beth & others,

In a posting to the 'vtools' mailing list of Thu  Sep  11,  2003,  you
mentioned suffering from leftover files in /tmp:

--- begin quote ---
> Hiya,
>
> We've got problems with Sophie leaving files lying around in /tmp:
>
> 111d0004.$$$    47b7000b.$$$    99f00002.$$$    c9f90004.$$$    f0fc0009.$$$
> 12cb0004.$$$    47da0002.$$$    99f00004.$$$    cc110005.$$$    f13f0018.$$$
(...)
I have not filed a bug report, because I wanted to upgrade both amavisd-new
and Sophie before doing so and verify whether the behavior continued.  In
addition, I wanted to determine whether the message had corrupt MIME
attachments.

Until that time (hopefully, in the next few weeks), I periodically have a
cron job which looks for "old" Sophie files and removes them.  This is not
a solution, but it buys me time until I can determine the true cause.

--- end quote ---

Have you eventually found something? We're having the same exact problem here
with:
- amavisd-new 20021227-p1
- Sophie v1.42
- Sophos v3.76 (newer versions give us trouble with stuck processes),
  libsavi.so.3.2.07.040

It has started last week with an incoming mail having >60 parts and a
very deep level of MIME structure (endless stack of forwards, typically
in the 'this is fun, I'll forward it to all my friends' style)
but being pure text.

I'm stuck as for the cause. Not even as for what exactly creates these files,
although I'm more and more convinced that libsavi does.

BTW any way to let Sophie/libsavi create temp files out of /tmp?
I'd rather have it use /var/tmp but I haven't found any option for
this. --with-net-tempdir=DIR seems to relate to the version
with network scans enabled only (which we don't use).

Greets,
_Alain_