Project

General

Profile

Actions

action #156733

closed

[security][15-SP6] test fails in clamav

Added by emiler 10 months ago. Updated 13 days ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
Bugs in existing tests
Target version:
-
Start date:
Due date:
% Done:

100%

Estimated time:
1.00 h
Difficulty:
Tags:

Description

All platforms:

ERROR: Verification: Can't allocate memory
Giving up on http://openqa.oqa.prg2.suse.org/assets/repo/cvd...
ERROR: Update failed for database: daily
ERROR: Database update process failed: Invalid or corrupted CVD/CLD database
ERROR: Update failed.
Actions #1

Updated by emiler 10 months ago

  • Description updated (diff)
Actions #2

Updated by emiler 10 months ago

Perhaps running out of disk space?

Actions #3

Updated by tjyrinki_suse 10 months ago

  • Estimated time set to 8.00 h
Actions #4

Updated by tjyrinki_suse 10 months ago

  • Status changed from New to Workable
  • Start date deleted (2024-03-06)
Actions #5

Updated by tjyrinki_suse 10 months ago

  • Subject changed from [security][SP6] test fails in clamav to [security][15-SP6] test fails in clamav
Actions #6

Updated by emiler 9 months ago

  • Assignee set to emiler
Actions #7

Updated by emiler 9 months ago

MD5 is disabled in FIPS, hence the error, which is caused during file verification.

In this case, the Can't allocate memory error is somewhat of a red herring. The true issue is that when FIPS mode is active, non–FIPS-approved hashing algorithms are disabled, and that includes MD5, which ClamAV uses extensively internally.

Actions #8

Updated by emiler 9 months ago

This started happening in build 59.2. Is it possible we were patching clamav ourselves and stopped patching it for some reason?

Actions #9

Updated by emiler 9 months ago · Edited

Possible cause: https://build.suse.de/package/rdiff/SUSE:Factory:Head/clamav?linkrev=base&rev=105
Timestamps are on point. Change happened on 26th, first fail on 28th (first build since).

Actions #10

Updated by emiler 9 months ago · Edited

  • Status changed from Workable to Feedback
Actions #11

Updated by openqa_review 7 months ago

This is an autogenerated message for openQA integration by the openqa_review script:

This bug is still referenced in a failing openQA test: fips_env_mode_tests_crypt_tool
https://openqa.suse.de/tests/14459784#step/git/1

To prevent further reminder comments one of the following options should be followed:

  1. The test scenario is fixed by applying the bug fix to the tested product or the test is adjusted
  2. The openQA job group is moved to "Released" or "EOL" (End-of-Life)
  3. The bugref in the openQA scenario is removed or replaced, e.g. label:wontfix:boo1234

Expect the next reminder at the earliest in 28 days if nothing changes in this ticket.

Actions #12

Updated by emiler 5 months ago

  • Status changed from Feedback to Resolved

ClamAV is not FIPS compliant at the moment. See the bug report for more details.
Closing.

Actions #13

Updated by amanzini 4 months ago

  • Status changed from Resolved to Blocked

issue is still present; in my opinion we need to either

  • exclude clamav from FIPS testing (until clamav will be FIPS compliant again)

or

Actions #14

Updated by pstivanin 4 months ago

  • Status changed from Blocked to In Progress
  • Assignee changed from emiler to pstivanin
Actions #16

Updated by pstivanin 4 months ago

  • % Done changed from 0 to 100
  • Estimated time changed from 8.00 h to 1.00 h

since the proposed upstream PR has not been merged and/or backported, I'd prefer we disable clamav for now on 15.6+: https://gitlab.suse.de/qe-security/osd-sle15-security/-/merge_requests/281

Actions #17

Updated by pstivanin 4 months ago

  • Status changed from In Progress to Resolved
Actions #18

Updated by amanzini 13 days ago · Edited

test fails on 15-SP7 as well; https://openqa.suse.de/tests/16175469

In the meantime some progress has been done on upstream https://github.com/Cisco-Talos/clamav/issues/564#issuecomment-2318234501 , new CLAMAV version with FIPS support should be released by the end of the year

Actions

Also available in: Atom PDF