ClamAV issue

smileluo

Member
Jan 16, 2021
41
4
13
45
The clamav can never start,the error is as low. Version 7.0-8

Oct 22 20:51:48 postfix pmgdaemon[1133]: starting task UPID:postfix:00003619:000470B1:6172B3E4:srvstart:clamav-daemon:root@pam:
Oct 22 20:51:48 postfix pmgdaemon[13849]: starting service clamav-daemon: UPID:postfix:00003619:000470B1:6172B3E4:srvstart:clamav-daemon:root@pam:
Oct 22 20:51:48 postfix systemd[1]: Starting Clam AntiVirus userspace daemon...
Oct 22 20:51:48 postfix systemd[1]: Started Clam AntiVirus userspace daemon.
Oct 22 20:51:48 postfix pmgdaemon[1133]: end task UPID:postfix:00003619:000470B1:6172B3E4:srvstart:clamav-daemon:root@pam: OK
Oct 22 20:51:48 postfix audit[13853]: AVC apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="stream" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:51:48 postfix audit[13853]: AVC apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="stream" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:51:48 postfix audit[13853]: AVC apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="stream" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:51:48 postfix audit[13853]: AVC apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="stream" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:51:48 postfix kernel: kauditd_printk_skb: 2 callbacks suppressed
Oct 22 20:51:48 postfix kernel: audit: type=1400 audit(1634907108.620:428): apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="stream" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:51:48 postfix kernel: audit: type=1400 audit(1634907108.620:429): apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="stream" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:51:48 postfix kernel: audit: type=1400 audit(1634907108.620:430): apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="stream" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:51:48 postfix kernel: audit: type=1400 audit(1634907108.620:431): apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="stream" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:51:48 postfix audit[13853]: AVC apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="dgram" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:51:48 postfix kernel: audit: type=1400 audit(1634907108.624:432): apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="dgram" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:51:48 postfix audit[13853]: AVC apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="dgram" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:51:48 postfix audit[13853]: AVC apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="dgram" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:51:48 postfix audit[13853]: AVC apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="dgram" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:51:48 postfix audit[13853]: AVC apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="dgram" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:51:48 postfix audit[13853]: AVC apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="dgram" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:51:48 postfix kernel: audit: type=1400 audit(1634907108.628:433): apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="dgram" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:51:48 postfix kernel: audit: type=1400 audit(1634907108.628:434): apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="dgram" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:51:48 postfix kernel: audit: type=1400 audit(1634907108.628:435): apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="dgram" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:51:48 postfix kernel: audit: type=1400 audit(1634907108.628:436): apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="dgram" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:51:48 postfix kernel: audit: type=1400 audit(1634907108.628:437): apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="dgram" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:52:01 postfix CRON[13910]: pam_unix(cron:session): session opened for user ccagent(uid=998) by (uid=0)
Oct 22 20:52:01 postfix CRON[13911]: (ccagent) CMD (bash /opt/cloudcone/agent.sh > /opt/cloudcone/cron.log 2>&1)
Oct 22 20:52:05 postfix CRON[13910]: pam_unix(cron:session): session closed for user ccagent
Oct 22 20:52:38 postfix audit[13853]: AVC apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="dgram" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:52:38 postfix kernel: audit: type=1400 audit(1634907158.805:438): apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="dgram" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:52:47 postfix audit[13853]: AVC apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="stream" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:52:47 postfix kernel: audit: type=1400 audit(1634907167.109:439): apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="stream" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:52:47 postfix kernel: audit: type=1400 audit(1634907167.109:440): apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="dgram" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:52:47 postfix audit[13853]: AVC apparmor="DENIED" operation="create" profile="/usr/sbin/clamd" pid=13853 comm="clamd" family="unix" sock_type="dgram" protocol=0 requested_mask="create" denied_mask="create" addr=none
Oct 22 20:52:47 postfix clamd[13853]: ERROR: LOCAL: Socket allocation error: Permission denied
Oct 22 20:52:47 postfix systemd[1]: clamav-daemon.service: Main process exited, code=exited, status=1/FAILURE
Oct 22 20:52:47 postfix systemd[1]: clamav-daemon.service: Failed with result 'exit-code'.
Oct 22 20:52:47 postfix systemd[1]: clamav-daemon.service: Consumed 48.904s CPU time.
 
This seems like a mismatch of the apparmor profiles and the kernel - usually you can safely remove apparmor

I hope this helps!
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!