I am running a server with Centos 4.4, using a combo of
sendmail-clamav-spamassassin for mail, which has been working quite well
up until last night. Around 3:00am, all mail going to all users was
being rejected by spamassassin. My ~/mail/.procmailrc is as follows:
#
:0 H
* ^X-Spam-Status:.*Yes
{
EXITCODE=67
:0:
/dev/null
}
=========================
Checking yum logs, nothing that would affect SA or sendmail was updated,
so I have no idea why everything would suddenly go bananas. Clamav was
updated, but that was at 5:00am, and the mails were getting bounced back
starting at 3:00. I am attaching 2 maillog snips showing mail from the
centos list, with one going thru as expected and the other getting
bounced back per my .procmailrc file. Any help appreciated.
--
TomE.
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_envfrom:
centos-bounces@centos.org
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_envrcpt:
tom@acalprecision.com
Oct 30 00:08:21 linux sendmail[19149]: k9U58LTp019149: from=
centos-bounces@centos.org, size=3765, class=-30, nrcpts=1, msgid=
1162184892.2646.85.camel@Dev.PoMec.Net, proto=ESMTP, daemon=MTA, relay=mail.centos.org [72.21.40.12]
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: Received: from lists.centos.org (localhost.localdomain [127.0.0.1]) by mail.centos.org (Postfix) with ESMTP id DCA59F3C2F0; Mon, 30 Oct 2006 05:08:19 +0000 (UTC)
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: X-Original-To: centos@centos.org
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: Delivered-To: centos@centos.org
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: Received: from Mail.PoMec.net (static-70-104-28-250.dllstx.fios.verizon.net [70.104.28.250]) by mail.centos.org (Postfix) with ESMTP id 9B9EEF3C2BC for
centos@centos.org; Mon, 30 Oct 2006 05:08:12 +0000 (UTC)
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: Received: from Dev.PoMec.Net (dev.pomec.net [10.0.0.121]) by Mail.PoMec.net (8.13.7/8.13.7) with ESMTP id k9U58CGK011364 for
centos@centos.org; Sun, 29 Oct 2006 23:08:12 -0600
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: Received: from Dev.PoMec.Net (localhost.localdomain [127.0.0.1]) by Dev.PoMec.Net (8.13.7/8.13.4) with ESMTP id k9U58Csr004236 for
centos@centos.org; Sun, 29 Oct 2006 23:08:12 -0600
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: Received: (from greg@localhost) by Dev.PoMec.Net (8.13.7/8.13.7/Submit) id k9U58C5o004235 for centos@centos.org; Sun, 29 Oct 2006 23:08:12 -0600
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: X-Authentication-Warning: Dev.PoMec.Net: greg set sender to PoMec@PoMec.Net using -f
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: Subject: Re: [CentOS] 4.4 versas AS and ES
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: From: "Gregory P. Ennis"
PoMec@PoMec.Net
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: To: CentOS mailing list
centos@centos.org
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: In-Reply-To:
Pine.LNX.4.61.0610292240230.15382@localhost.localdomain
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: References:
1162182974.2646.79.camel@Dev.PoMec.Net Pine.LNX.4.61.0610292240230.15382@localhost.localdomain
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: Content-Type: text/plain
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: Content-Transfer-Encoding: 7bit
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: Date: Sun, 29 Oct 2006 23:08:11 -0600
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: Message-Id:
1162184892.2646.85.camel@Dev.PoMec.Net
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: Mime-Version: 1.0
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: X-Mailer: Evolution 2.6.3 (2.6.3-1.fc5.5)
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: X-BeenThere: centos@centos.org
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: X-Mailman-Version: 2.1.5
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: Precedence: list
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: Reply-To: CentOS mailing list
centos@centos.org
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: List-Id: CentOS mailing list <centos.centos.org>
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: List-Unsubscribe:
http://lists.centos.org/mailman/listinfo/centos,
mailto:centos-request@centos.org?subject=unsubscribe
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: List-Archive:
http://lists.centos.org/pipermail/centos
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: List-Post:
mailto:centos@centos.org
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: List-Help:
mailto:centos-request@centos.org?subject=help
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: List-Subscribe:
http://lists.centos.org/mailman/listinfo/centos,
mailto:centos-request@centos.org?subject=subscribe
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: Sender: centos-bounces@centos.org
Oct 30 00:08:21 linux clamav-milter[3360]: clamfi_header: Errors-To: centos-bounces@centos.org
Oct 30 00:08:22 linux clamav-milter[3360]: clamfi_eoh
Oct 30 00:08:22 linux clamav-milter[3360]: clamfi_envbody: 1593 bytes
Oct 30 00:08:22 linux clamav-milter[3360]: clamfi_eom
Oct 30 00:08:22 linux sendmail[19149]: k9U58LTp019149: Milter add: header: X-Virus-Scanned: ClamAV 0.88.4/2129/Sun Oct 29 02:02:26 2006 on linux.acalprecision.com
Oct 30 00:08:22 linux sendmail[19149]: k9U58LTp019149: Milter add: header: X-Virus-Status: Clean
Oct 30 00:08:22 linux clamav-milter[3360]: clamfi_close
Oct 30 00:08:22 linux spamd[15524]: spamd: connection from localhost.localdomain [127.0.0.1] at port 57489
Oct 30 00:08:22 linux spamd[15524]: spamd: setuid to root succeeded
Oct 30 00:08:22 linux spamd[15524]: spamd: still running as root: user not specified with -u, not found, or set to root, falling back to nobody at /usr/bin/spamd line 1147, <GEN436> line 4.
Oct 30 00:08:22 linux spamd[15524]: spamd: processing message
1162184892.2646.85.camel@Dev.PoMec.Net for root:99
Oct 30 00:08:22 linux spamd[15524]: spamd: clean message (0.0/4.2) for root:99 in 0.6 seconds, 4166 bytes.
Oct 30 00:08:22 linux spamd[15524]: spamd: result: . 0 - scantime=0.6,size=4166,user=root,uid=99,required_score=4.2,rhost=localhost.localdomain,raddr=127.0.0.1,rport=57489,mid=
1162184892.2646.85.camel@Dev.PoMec.Net,autolearn=ham
Oct 30 00:08:22 linux sendmail[19151]: k9U58LTp019149: to=
tom@acalprecision.com, delay=00:00:01, xdelay=00:00:00, mailer=local, pri=88050, dsn=2.0.0, stat=Sent
Oct 30 07:08:59 linux clamav-milter[3360]: clamfi_envfrom:
centos-bounces@centos.org
Oct 30 07:08:59 linux clamav-milter[3360]: clamfi_envrcpt:
tom@acalprecision.com
Oct 30 07:09:00 linux sendmail[20669]: k9UC8xCK020669: from=
centos-bounces@centos.org, size=5460, class=-30, nrcpts=1, msgid=
1162210110.20470.107.camel@myth.home.local, proto=ESMTP, daemon=MTA, relay=mail.centos.org [72.21.40.12]
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: Received: from lists.centos.org (localhost.localdomain [127.0.0.1]) by mail.centos.org (Postfix) with ESMTP id 43BCEF3C328; Mon, 30 Oct 2006 12:08:41 +0000 (UTC)
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: X-Original-To: centos@centos.org
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: Delivered-To: centos@centos.org
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: Received: from mx2.lsn.net (mx2.lsn.net [66.90.130.74]) by mail.centos.org (Postfix) with ESMTP id 909D0F3C1D8 for
centos@centos.org; Mon, 30 Oct 2006 12:08:32 +0000 (UTC)
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: Received: from myth.home.local (24-155-196-96.dyn.grandenetworks.net [24.155.196.96]) by mx2.lsn.net (8.13.5.20060308/8.13.5) with ESMTP id k9UC8UQp015085 for
centos@centos.org; Mon, 30 Oct 2006 06:08:31 -0600
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: Subject: Re: [CentOS] 4.4 versas AS and ES
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: From: Johnny Hughes
mailing-lists@hughesjr.com
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: To: CentOS ML
centos@centos.org
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: In-Reply-To:
1162187207.6290.13.camel@lin-workstation.azapple.com
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: References:
1162182974.2646.79.camel@Dev.PoMec.Net Pine.LNX.4.61.0610292240230.15382@localhost.localdomain 1162184892.2646.85.camel@Dev.PoMec.Net 1162187207.6290.13.camel@lin-workstation.azapple.com
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: Date: Mon, 30 Oct 2006 06:08:30 -0600
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: Message-Id:
1162210110.20470.107.camel@myth.home.local
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: Mime-Version: 1.0
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: X-Mailer: Evolution 2.0.2 (2.0.2-27.rhel4.6)
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: X-Virus-Scanned: ClamAV 0.88.5/2131/Sun Oct 29 16:00:12 2006 on mx0.lsn.net
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: X-Virus-Status: Clean
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: X-BeenThere: centos@centos.org
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: X-Mailman-Version: 2.1.5
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: Precedence: list
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: Reply-To: CentOS mailing list
centos@centos.org
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: List-Id: CentOS mailing list <centos.centos.org>
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: List-Unsubscribe:
http://lists.centos.org/mailman/listinfo/centos,
mailto:centos-request@centos.org?subject=unsubscribe
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: List-Archive:
http://lists.centos.org/pipermail/centos
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: List-Post:
mailto:centos@centos.org
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: List-Help:
mailto:centos-request@centos.org?subject=help
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: List-Subscribe:
http://lists.centos.org/mailman/listinfo/centos,
mailto:centos-request@centos.org?subject=subscribe
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: Content-Type: multipart/mixed; boundary="===============1766466836=="
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: Sender: centos-bounces@centos.org
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_header: Errors-To: centos-bounces@centos.org
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_eoh
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_envbody: 3572 bytes
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_eom
Oct 30 07:09:00 linux sendmail[20669]: k9UC8xCK020669: Milter delete: header X-Virus-Status: Clean
Oct 30 07:09:00 linux sendmail[20669]: k9UC8xCK020669: Milter add: header: X-Virus-Scanned: ClamAV 0.88.4/2131/Sun Oct 29 17:00:12 2006 on linux.acalprecision.com
Oct 30 07:09:00 linux sendmail[20669]: k9UC8xCK020669: Milter add: header: X-Virus-Status: Clean
Oct 30 07:09:00 linux clamav-milter[3360]: clamfi_close
Oct 30 07:09:00 linux spamd[18043]: spamd: connection from localhost.localdomain [127.0.0.1] at port 58264
Oct 30 07:09:00 linux spamd[18043]: spamd: setuid to root succeeded
Oct 30 07:09:00 linux spamd[18043]: spamd: still running as root: user not specified with -u, not found, or set to root, falling back to nobody at /usr/bin/spamd line 1147, <GEN295> line 4.
Oct 30 07:09:00 linux spamd[18043]: spamd: processing message
1162210110.20470.107.camel@myth.home.local for root:99
Oct 30 07:09:00 linux pop3-login: Login: joe [10.1.1.15]
Oct 30 07:09:02 linux spamd[18043]: spamd: clean message (0.0/4.2) for root:99 in 2.2 seconds, 5838 bytes.
Oct 30 07:09:02 linux spamd[18043]: spamd: result: . 0 - AWL,BAYES_00,FORGED_RCVD_HELO,MANGLED_PENIS scantime=2.2,size=5838,user=root,uid=99,required_score=4.2,rhost=localhost.localdomain,raddr=127.0.0.1,rport=58264,mid=
1162210110.20470.107.camel@myth.home.local,bayes=0,autolearn=no
Oct 30 07:09:02 linux sendmail[20671]: k9UC8xCK020669: to=
tom@acalprecision.com, delay=00:00:03, xdelay=00:00:02, mailer=local, pri=89726, dsn=5.1.1, stat=User unknown
Oct 30 07:09:02 linux sendmail[20671]: k9UC8xCK020669: k9UC92CK020671: DSN: User unknown
Oct 30 07:09:02 linux spamd[348]: prefork: child states: II
Oct 30 07:09:03 linux sendmail[20671]: k9UC92CK020671: to=
centos-bounces@centos.org, delay=00:00:01, xdelay=00:00:01, mailer=relay, pri=30000, relay=smtp.sbc.mail.yahoo4.akadns.net. [68.142.229.41], dsn=2.0.0, stat=Sent (ok 1162210144 qp 91576)