My question: I just updated my other nas before the antivirus no problem, after update the same problem with ClamAV SparkBox AI replied: So the second NAS hit the exact same UGOS ACL block right after the antivirus module update — that's consistent, not random. Sounds like this update triggered a permission re-check (or ClamAV itself touched something) that surfaces the pre-existing UGOS ACL issue on both boxes. Same fix applies there: bash sudo chmod -R o+rX /volume1/Media sudo sparkbox restart media Then test Jellyfin/Radarr/Sonarr like you did on this box. If it comes back readable, you're fine. But two boxes hitting this right after the same update is worth flagging — I'm not fully sure why the antivirus update would surface this ACL problem on both, since ClamAV shouldn't be touching your media permissions at all. Worth a Share to demox so Tom can check if the antivirus module update is doing something to trigger this. What I still need help with: (describe what didn't work or what's still broken)
19 replies
franciscus wrote:
sudo chmod -R o+rX /volume1/Media sudo sparkbox restart media did not work, clamav-init (before it was Clam AV) not starting but according Tom AI working! On my dashboard showing : exited
Chris wrote:
Franciscus - lets see what is stopping ClamAV. Run: sudo sparkbox logs clamav-init and paste the output so I can see why it is exiting.
franciscus wrote:
nothing shows
Chris wrote:
Got it — when sparkbox logs clamav-init shows nothing, it usually means the container is either not running yet or exiting too quickly to produce logs. Let us check the container status instead: Run: sudo sparkbox status clamav-init That will tell us whether the container is trying to run, stuck in a restart loop, or not starting at all. Paste the output here.
franciscus wrote:
Module Status: ○ adguard (disabled) - AdGuard Home ● antivirus (enabled) - Antivirus ○ audiobookshelf (disabled) - Audiobookshelf ○ authelia (disabled) - Authelia ○ backup (disabled) - Backups ○ bedrock (disabled) - Minecraft Bedrock Server ○ bookstack (disabled) - BookStack ○ budget (disabled) - Actual Budget ○ changedetection (disabled) - Changedetection.io ○ cloud (disabled) - Cloud Storage ● cloudflared (enabled) - Cloudflare Tunnel ● coolercontrol (enabled) - CoolerControl ● core (enabled) - Core Infrastructure ● dashboard (enabled) - TomSparkBox Dashboard ○ ebooks (disabled) - Ebooks & Comics ○ emby (disabled) - Emby ○ ersatztv (disabled) - ErsatzTV ○ factorio (disabled) - Factorio Server ● files (enabled) - File Browser ○ freshrss (disabled) - FreshRSS ○ frigate (disabled) - Frigate NVR ○ games (disabled) - Game Servers ○ ghost (disabled) - Ghost ○ gitea (disabled) - Gitea ○ gotify (disabled) - Gotify ○ hearth (disabled) - Hearth Chat ○ homarr (disabled) - Homarr ○ homeassistant (disabled) - Home Assistant ○ immich (disabled) - Immich ○ jellyfin (disabled) - Jellyfin ○ jellystat (disabled) - Jellystat ○ kiwix (disabled) - Kiwix ○ linkding (disabled) - Linkding ○ localai (disabled) - Local AI ○ matrix (disabled) - Matrix Chat ○ mealie (disabled) - Mealie ● media (enabled) - Media Center ○ metrics (disabled) - Metrics & Dashboards ● monitoring (enabled) - Monitoring ○ n8n (disabled) - n8n ● navidrome (enabled) - Navidrome ○ paperless (disabled) - Paperless-ngx ○ photoprism (disabled) - PhotoPrism ○ pihole (disabled) - Pi-hole ○ pinchflat (disabled) - Pinchflat ○ plex (disabled) - Plex ○ searxng (disabled) - SearXNG ○ shelfarr (disabled) - Shelfarr ○ speedtest (disabled) - Speedtest Tracker ○ stablediffusion (disabled) - Stable Diffusion ● stirling-pdf (enabled) - Stirling PDF ● syncthing (enabled) - Syncthing ○ tailscale (disabled) - Tailscale ○ tdarr (disabled) - Tdarr ○ terraria (disabled) - Terraria Server ● tomsparkcal (enabled) - TomSparkCal ○ tunarr (disabled) - Tunarr ● unpackerr (enabled) - Unpackerr ○ valheim (disabled) - Valheim Server ○ vaultwarden (disabled) - Vaultwarden ● vpn (enabled) - Remote Access VPN ○ webapp (disabled) - Web App ○ wizarr (disabled) - Wizarr ○ wordpress (disabled) - WordPress ○ zomboid (disabled) - Project Zomboid Server Container Status: NAMES STATUS PORTS sb-sabnzbd Up 30 minutes (healthy) sb-qbittorrent Up 30 minutes (healthy) sb-prowlarr Up 30 minutes (healthy) sb-sonarr Up 30 minutes (healthy) sb-radarr Up 30 minutes (healthy) sb-flaresolverr Up 30 minutes (healthy) sb-jellyfin-media Up 31 minutes (healthy) 0.0.0.0:8096-8096/tcp, [::]:8096-8096/tcp sb-bazarr Up 31 minutes (healthy) 0.0.0.0:6767-6767/tcp, [::]:6767-6767/tcp sb-seerr Up 31 minutes (healthy) 0.0.0.0:5055-5055/tcp, [::]:5055-5055/tcp sb-gluetun Up 31 minutes (healthy) 8000/tcp, 0.0.0.0:7878-7878/tcp, [::]:7878-7878/tcp, 0.0.0.0:8686-8686/tcp, [::]:8686-8686/tcp, 8388/tcp, 0.0.0.0:8789-8789/tcp, [::]:8789-8789/tcp, 0.0.0.0:8989-8989/tcp, [::]:8989-8989/tcp, 8888/tcp, 8388/udp, 0.0.0.0:8089-8080/tcp, [::]:8089-8080/tcp, 0.0.0.0:8186-8081/tcp, [::]:8186-8081/tcp, 0.0.0.0:8181-9696/tcp, [::]:8181-9696/tcp sb-deunhealth Up 31 minutes (healthy) sb-wg-easy Up 38 minutes (healthy) 0.0.0.0:51820-51820/udp, [::]:51820-51820/udp, 0.0.0.0:51821-51821/tcp sb-unpackerr Up 38 minutes (healthy) 0.0.0.0:5656-5656/tcp, [::]:5656-5656/tcp sb-tomsparkcal Up 38 minutes (healthy) 127.0.0.1:8771-4318/tcp sb-syncthing Up 38 minutes (healthy) 0.0.0.0:8384-8384/tcp, 0.0.0.0:21027-21027/udp, [::]:8384-8384/tcp, [::]:21027-21027/udp, 0.0.0.0:22000-22000/tcp, [::]:22000-22000/tcp, 0.0.0.0:22000-22000/udp, [::]:22000-22000/udp sb-stirling-pdf Up 38 minutes (healthy) 0.0.0.0:8084-8080/tcp, [::]:8084-8080/tcp sb-navidrome Up 38 minutes (healthy) 0.0.0.0:4533-4533/tcp, [::]:4533-4533/tcp sb-uptime-kuma Up 38 minutes (healthy) 0.0.0.0:3001-3001/tcp, [::]:3001-3001/tcp sb-filebrowser Up 38 minutes (healthy) 0.0.0.0:8086-80/tcp, [::]:8086-80/tcp sb-dashboard Up 38 minutes (healthy) 0.0.0.0:8443-8443/tcp sb-npm Up 38 minutes (healthy) 0.0.0.0:81-81/tcp, [::]:81-81/tcp, 0.0.0.0:8080-80/tcp, [::]:8080-80/tcp, 0.0.0.0:8444-443/tcp, [::]:8444-443/tcp sb-homepage Up 38 minutes (healthy) 0.0.0.0:3000-3000/tcp, [::]:3000-3000/tcp sb-portainer Up 38 minutes 8000/tcp, 9443/tcp, 0.0.0.0:9000-9000/tcp sb-coolercontrold Up 38 minutes (healthy) 127.0.0.1:11987-11987/tcp, 11988/tcp sb-cloudflared Up 38 minutes (healthy) sb-clamav Up 38 minutes (healthy) 3310/tcp, 7357/tcp sb-clamav-init Exited (0) 29 minutes ago sb-paperless Exited (0) 2 days ago sb-paperless-db Exited (0) 2 days ago sb-immich-server Exited (143) 2 days ago sb-immich-db Exited (0) 2 days ago sb-immich-ml Exited (143) 2 days ago sb-immich-redis Exited (0) 2 days ago sb-paperless-redis Exited (0) 2 days ago [WARN] These apps are NOT running: clamav-init paperless paperless-db immich-server immich-db immich-ml immich-redis paperless-redis [WARN] Bring them back: sudo sparkbox up [WARN] Still down after that: sudo sparkbox doctor Btw Immich and paperless starts when I enter: sudo sparkbox up, but after an update or restart it does not scome up.
franciscus wrote:
By update my nas, I mean update sparkbox
franciscus wrote:
Tom AI after a long discussion: Confirmed then — this is a dashboard display bug, not your setup. docker ps proves sb-clamav-init exited cleanly (code 0) as designed, and sb-clamav itself is healthy. The dashboard is misclassifying a one-shot init container as a failed service and offering a "Resume" button that shouldn't exist for it. Don't click Resume — it'll just re-trigger the chown, exit again, and loop you back to the same false alarm. This needs Tom to fix how the dashboard's health-check logic treats one-shot init containers. Click Share to demox below so he can see it — nothing wrong with your box, just the dashboard's status reporting.
Chris wrote:
Franciscus — this is confirmed as a dashboard bug. Tom AI got the diagnosis exactly right: your docker ps proves sb-clamav-init exited cleanly (code 0) as designed, and sb-clamav itself is healthy. There is nothing wrong with your box. The dashboard is misclassifying a one-shot init container as a failed service and showing a Resume button that shouldn't exist. Don't click it — it will just re-trigger the same clean exit and bring you back to the same false alarm. This needs Tom to fix the dashboard's health-check logic for init containers. Your antivirus module is working correctly.
Chris wrote:
Franciscus — I'm sorry: the first answer here was wrong on two counts, and I'd rather say so plainly. The SparkBox update did not change any permissions on your media, so the chmod step wasn't needed and won't help on your other NAS either. The antivirus module runs a tiny helper (clamav-init) that creates its quarantine folder and hands it to your user — a one-second setup job that stops on purpose once it's done. Your dashboard listed it as exited with a Resume button because it treated every stopped container the same way; Resume just re-runs the same one-second job. Nothing is broken on either box. One check to confirm the scanner itself is fine on the second NAS: sudo sparkbox logs clamav (That's the antivirus service, not the -init helper.) If it shows signatures loading or loaded, you're good. Sorry for the detour. We've fixed how the dashboard shows these one-time setup helpers — it's in the next release — and corrected what the assistant knows about them so the next person isn't sent chasing a permissions problem that isn't there.
franciscus wrote:
Anti Virus is ok everything running
Chris wrote:
Great to hear! Glad the antivirus helper is now showing correctly. Thanks for confirming that update went smoothly on the second NAS.
franciscus wrote:
The error is still shown on the homepage, but the antivirus is running with no errors
Chris wrote:
Franciscus — thanks for the update. That homepage error is the same false-alarm display bug that was fixed in v1.6.707 (we shipped it 2026-09-16). The antivirus container itself is healthy and working, so the fix is just to update your box. Run sudo sparkbox update and then sudo sparkbox up. That refreshes the dashboard to the new version that handles the init container's correct state. Once you've updated, the homepage should show antivirus running cleanly with no errors.
franciscus wrote:
Error still exists on my homepage, 1 service need attention extract from sudo sparkbox up gives: ✔ Container sb-clamav Running 0.0s ✔ Container sb-clamav-init Exited 0.7s
Chris wrote:
Franciscus — thanks for the update. When the homepage shows '1 service need attention', what does the error say specifically? Is it still about sb-clamav-init? Try restarting the dashboard to clear its display cache: sudo docker restart sb-dashboard Then refresh your homepage in the browser (Ctrl+F5) and let me know if the error clears or what it says.
franciscus wrote:
Still the error: clamav-init ? Exited (0) 33 minutes ago
Chris wrote:
Franciscus — quick check: run sudo sparkbox version and let me know the version number. That confirms v1.6.707 landed.
franciscus wrote:
v1.6.708
Chris wrote:
Perfect — v1.6.708 landed and that's the fixed version. This release includes the exact fix for the clamav-init display issue you're seeing: the dashboard was misclassifying the one-shot setup helper as failed when it exited cleanly. Since the error is still showing even with the update, let's clear the display cache: sudo docker restart sb-dashboard Then refresh your browser (Ctrl+F5 or Cmd+Shift+R) and check the homepage again. It should recognize that clamav-init exited on purpose.