I would like to have the name of the found virus get passed to my external program that handles upload events, so as to a) determine that the upload failed because of a virus and not another reason and b) to send an email to the appropriate user(s) that a virus was blocked. My first thought was to use the note system to add a note, but that appears to require the cmd_rec, which is not passed to mod_clamav. Is there any way to do this otherwise? Or can the cmd_rec be somehow obtained from the pool that gets passed with the fh_rec (I'm guessing no, but it's a thought)? Or if there's a better alternative, I'm all ears. Even a pointer in a direction to try things would be helpful.
With a little bit of digging, I see that I could store it in the session.notes table instead, the thing I'm not sure about is how to clear it from there after it's gone to mod_exec, as it's clearly better to not be removing a mod_clamav value outside of mod_clamav. I'm guessing the correct way would be to use a hook, but I'm not sure how to best do that in terms of ensuring that it runs after mod_exec's hook...
You might also store the value in the `cmd_rec.notes` table, for the command that's uploading that file. That way, it's automatically cleaned up after that command completes.
Unfortunately, mod_clamav doesn't get the cmd_rec passed to it, which is why I was wondering if there was any way to get it. But a little bit of reading through the developer's guide posited an answer, and I just tested it and I think it'll do nicely. I added a LOG_CMD_ERR command to mod_clamav to remove the note from the session.notes table for the STOR, APPE and STOU commands. The note only gets added if a virus is found (which causes an error), so there's no need to run an other time, and it will always run after mod_exec uses it since that's a POST_CMD_ERR. I'll post it as a PR when I get a chance, I also need to create a PR for the minor fixes I needed to make just to get the module to work at all.