[clamav-users] clamav-milter: ClamAV, mi_rd_cmd: read returned -1: Connection reset by peer

Marco falon at ruparpiemonte.it
Mon Mar 17 10:43:30 EDT 2014


Hello

> How many Postfix servers?  Do you know that your clamd server is
> capable of sustaining the load from the many Postfix servers?

now I have four postfix servers. The load on clamav servers is low...  
this is an instance:

top - 15:24:36 up 31 days, 19:17,  1 user,  load average: 0.14, 0.08, 0.02
Tasks: 116 total,   1 running, 115 sleeping,   0 stopped,   0 zombie
Cpu0  :  1.7%us,  1.0%sy,  0.0%ni, 97.0%id,  0.0%wa,  0.0%hi,  0.3%si,  0.0%st
Cpu1  : 15.0%us,  0.7%sy,  0.0%ni, 84.3%id,  0.0%wa,  0.0%hi,  0.0%si,  0.0%st
Mem:   3925152k total,  2742588k used,  1182564k free,   203704k buffers
Swap:  2097144k total,    17964k used,  2079180k free,   713052k cached

   PID USER      PR  NI  VIRT  RES  SHR S %CPU %MEM    TIME+  COMMAND
10142 clamav    20   0 1453m 421m 2132 S 17.3 11.0 139:56.99 clamd
30560 clamav    20   0 1918m 889m  940 S  0.7 23.2  10:56.87 clamav-milter

procs -----------memory---------- ---swap-- -----io---- --system--  
-----cpu-----
  r  b   swpd   free   buff  cache   si   so    bi    bo   in   cs us  
sy id wa st
  0  0  17964 1183096 203704 713056    0    0     4    12    6    1  2  
  0 98  0  0

   ClamdTOP version 0.98.1   Mon Mar 17 15:40:19 2014
NO CONNTIME LIV IDL QUEUE  MAXQ   MEM HOST           ENGINE DBVER DBTIME
  1 00:00:04  18  17     0     0  356M local          0.98.1 18614  
2014-03-17 14h
Details for Clamd version:  ClamAV 0.98.1/18614/Mon Mar 17 14:43:12 2014
Primary threads: live  18 idle  17 max 50                               
                        ?????????????????????????????????????????
  [|||||||||||||                       ]                                
                          ?Mem:  heap   10M mmap    0M unused   8M?
Queue:     0 items      0 max                                           
                         ?Libc: used    0M free    9M total   10M?
  [                                    ]                                
                          ?Pool: count    1 used  346M total  346M?
                                                                        
                          ?[||||||||||||||||||||||||||||||||||| ] ?
                                                                        
                          ?????????????????????????????????????????
  COMMAND        QUEUEDSINCE   FILE
  IDLE               3.800s
[...]

> You could use syslog-ng, and tell it to send them to /dev/null. :)

I'll try with rsyslog ;)

> You could try increasing the Postfix timeout (if that is in fact the
> cause of the issue) but I wonder if you might need a more powerful
> clamd server.  Scanning for viruses can be processor intensive.

I don't see log on Postfix correlated to these warning.
Just two or three error a day like this, really:

2014-03-17T12:47:34.538025+01:00 postfix2 postfix/smtpd[17215]:  
warning: milter inet:example.com:7357: can't read SMFIC_MAIL reply  
packet header: Connection reset by peer

Postfix milter timeout are:

milter_command_timeout = 30s
milter_connect_timeout = 30s
milter_content_timeout = 300s

that are greater than clamav timeout (I have a doubt on command_timeout...).

Thank you for all hints
Marco




More information about the clamav-users mailing list