= Main Inclusion Report for clamav = The purpose of promoting clamav is to get a more complete server solution. == Requirements == 0. ''Availability:'' [[http://archive.ubuntu.com/ubuntu/pool/universe/c/clamav/]]; available for all supported architectures 0. ''Rationale:'' * Approved spec for Intrepid: https://wiki.ubuntu.com/ClamavSpamassassinInMain. Note: clamav-milter binary can stay in Universe. 0. ''Security:'' * [[http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=clamav|CVE entries]] Clamav has a long history of large numbers of CVEs. It seems to be trending better. * [[http://secunia.com/search/?search=clamav|Secunia History]]: * Any binaries running as root or suid/sgid ? NO Any daemons ? YES (clamav-freshclam, clamav-daemon, and clamav-milter) * Network activity: does it open any port ? Yes Does it handle incoming network data ? YES * Does it directly (not through a library) process binary (video, audio, etc) or structured (PDF, etc) data ? YES * Any source code review performed ? (The approver will do a quick and shallow check.) NO 0. ''Quality assurance:'' * In what situations does the package not work out of the box without configuration ? None * Does the package ask any debconf questions higher than priority 'medium' ? No * [[http://bugs.debian.org/src:clamav|Debian Bugs]]: None * [[http://packages.qa.debian.org/c/clamav.html|Maintenance in Debian]] is vigorous. The current maintainer is a bit burned out on the package and has recently started pkg-clamav on alioth. He's agreed to host Ubuntu branches in the same Git repository and we can work on it together there. * [[http://www.clamav.net|Upstream]] is frenetic and does not have a good track record for interface stability. * [[http://bugs.clamav.net|Upstream Bug tracker]] * Hardware: Does this package deal with hardware and if so how exotic is it ? NO * Is there a test suite in the upstream source or packaging ? YES Is it enabled to run in the build ? 0. ''Standards compliance:'' * [[http://www.pathname.com/fhs/|FHS]], [[http://www.de.debian.org/doc/debian-policy/|Debian Policy]] compliance ? YES * [[http://www.netfort.gr.jp/~dancer/column/libpkg-guide/libpkg-guide.html|Debian library packaging guide]] standards compliance ? YES * Packaging system (debhelper/cdbs/dbs) ? Debhelper Patch system ? dpatch historically, maintained in Git now. Any packaging oddities ? Package is complex and somewhat painful due to it's long and complex history. Debian maintainer plans to simplify post-Lenny. 0. ''Dependencies:'' Build-Depends: dpkg-dev (>= 1.13.19), debhelper (>=5.0), po-debconf, zlib1g-dev (>=1:1.1.4), libbz2-dev, libmilter-dev, libgmp3-dev, libwrap0-dev, perl, bc Depends : adduser, ucf (>= 0.28), logrotate, sharutils, arj, and unzoo * Are these all in main ? NO (MIR needed for arj and unzoo) 0. ''Background information:'' * What do upstream call this software ? CLAMAV Has it had different names in the past ? NO == Reviewers == MIR bug: [[https://launchpad.net/ubuntu/+source/clamav/+bug/261249]] Author: leonelnunez and ScottKitterman