pkgsrc-Changes archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
CVS commit: pkgsrc/mail/rspamd
Module Name: pkgsrc
Committed By: wiz
Date: Sat Sep 26 10:50:07 UTC 2026
Modified Files:
pkgsrc/mail/rspamd: Makefile PLIST cfgfiles.mk distinfo
Log Message:
rspamd: update to 4.2.0.
4.2.0: 18 Sep 2026
** Incompatible changes **
* [Rework] symcache: One scheduler over the dependency graph: every item gets a stage and a level at init, and a dependency edge moves its target instead of being executed from the wrong stage
* [Rework] url: Resolve host TLDs through the new public suffix lookup ('!' exception rules are honoured, and a host that is itself a public suffix resolves to the whole host)
* [Rework] url: Discover URLs in free text with two passes (static matcher plus dot-anchored suffix labels) and drop the 10.5k-pattern TLD hyperscan database from the scanner
* [Rework] multimap: Return the full public suffix from the 'top' filter, so maps must list full suffixes ('com.au' instead of 'au')
* [Rework] rbl: Match URL composition maps with the suffix lookup instead of per-TLD regexes
* [Rework] fuzzy: Count redis hashes with a periodic SCAN instead of a counter maintained by the update script (negative counters left by older versions are reported as 0)
** Major features **
* [Feature] mime: Extract content and smuggling indicators from SVG attachments (SVG_CONTENT, SVG_SCRIPT, SVG_FOREIGN_OBJECT, SVG_DATA_URI, SVG_FORM and friends)
* [Feature] mime: Extract content from XLSX and PPTX attachments with relationship-level facts (OOXML_MACROS, OOXML_OLE_OBJECT, OOXML_REMOTE_TEMPLATE, OOXML_EXTERNAL_DATA)
* [Feature] mime: Add bounded DOCX content extraction
* [Feature] mime: Flag unprocessable DOCX attachments
* [Feature] lua_task: Inject HTML parts from Lua, so decoded payloads go through the regular HTML parser
* [Feature] url: Add a public suffix lookup component with full public suffix list semantics (wildcards, exceptions, ICANN/private split)
* [Feature] lua: Expose the suffix lookup and custom suffix-like rule sets as rspamd_tld_lookup
* [Feature] lua_url: Add url:get_public_suffix() with the suffix match flags
* [Feature] lua_selectors: Add the get_public_suffix transform
* [Feature] lua_selectors: Extractors declare the symbols they need, and ratelimit, multimap, rbl and reputation register them as dependencies
* [Feature] symcache: Let prefilters depend on filters, hoisting the filter and its own dependencies to the prefilter stage
* [Feature] css: Evaluate compound selectors and combinators ('div.mainbox', 'div p', 'div > p', 'h1 + p', 'h1 ~ p')
* [Feature] dkim: Decide From alignment in the module that knows and report it as R_DKIM_ALIGNED (R_DKIM_ALLOW goes from -0.2 to -0.1, the rest to R_DKIM_ALIGNED)
* [Feature] lua_aliases: Mailbox identity and equivalent domain classes for comparing addresses
* [Feature] fuzzy: Sampled storage statistics from the count scan (count_scan.stats_sample), published in /fuzzystat and printed by rspamadm fuzzystat
* [Feature] fuzzy: Lazy per-source stats for keys with a configurable cap (max_ips_per_key, per-key max_ips) and an overflow guard
* [Feature] libucl: Add ucl.untrusted_parser() to the Lua API, plus parser:set_limits() and parser:get_limits()
* [Feature] protocol: Bound UCL parsing of untrusted network input (controller and proxy bodies, checkv3 metadata in JSON and msgpack)
* [Feature] clickhouse: Data-skipping indexes for point lookups (schema 12)
* [Feature] metadata_exporter: Add the redis_list pusher
* [Feature] lua_redis: Pin a request to a specific upstream
* [Feature] WebUI: Ping fuzzy storages (fuzzy_check.ping_storage_all, /plugins/fuzzy/status), per-server liveness marks, down badges and an on-demand Check button
* [Feature] WebUI: Enrich the fuzzy storage table and show unavailable storages
* [Feature] WebUI: Bayes learns balance bar and min_learns status badge
* [Feature] WebUI: Richer Status servers table (three-state health, per-server details row, load and latency, version and config drift, Writable badge)
* [Feature] WebUI: Informative All SERVERS cluster row derived from cluster data
* [Feature] WebUI: Show the git build id in the cluster table
** Bug fixes **
* [CritFix] libucl: Bound container nesting for every parse type and free trees iteratively (a deeply nested document crashed while being freed)
* [CritFix] rdns: Harden the DNS reply parser against malformed packets (out of bounds name and RDATA reads, a wrapping TXT counter, recursion on TCP reads)
* [Fix] pdf: Bound resource amplification in parsing and text extraction (CMap bytes, object totals, deadlines, memoised streams)
* [Fix] lua_compress: Bound decompression output and memory (zstd passed the attacker-controlled frame size straight to g_malloc)
* [Fix] maps: Drop destroyed regexp helpers from the hyperscan compilation queue (worker crash on a freed helper)
* [Fix] maps: Defer the reread of a map file that has just been truncated
* [Fix] maps: Converge cold passive workers on HTTP maps quickly instead of sleeping a full poll interval with no data
* [Fix] symcache: Break dependency cycles at init (stack overflow in rspamd_symcache_get_max_timeout)
* [Fix] symcache: Forbid connfilter and prefilter dependencies on filter symbols, and actually drop every rejected edge
* [Fix] symcache: Plan symbols registered after the cache init and never spin on leaked async counters
* [Fix] symcache: Run ignore_passthrough symbols after a pre-result from a prefilter
* [Fix] settings: Keep custom apply keys when merging layers, and apply actions the same way as on the single-layer path
* [Fix] settings: Re-enable actions from higher layers
* [Fix] settings: Make ip_map and client_ip_map actually match
* [Fix] css: Bound selector matching with a document-wide budget and stop the combinatorial backtracking on deep nesting
* [Fix] css: Keep a repeated selector as its own cascade entry and allocate only the winning rule
* [Fix] css: Drop a grouped selector that cannot be evaluated instead of registering its first part
* [Fix] css: Fix relative and shorthand font sizes hiding visible text (line-height taken as the size, misspelled vw/vh units, unresolved percent sizes)
* [Fix] css: Accept a unitless zero as the font shorthand size
* [Fix] html: Read a transparent tag's content from the buffer it was written to (R_WHITE_ON_WHITE on messages that also carry hidden text)
* [Fix] html: Ignore layout padding in hidden text checks and penalise substantial hidden content
* [Fix] chartable: Handle language diacritics correctly, including non-Latin ones, and harden the Unicode spoof detection
* [Fix] mime: Charge nested SVG payloads to the shared payload budget
* [Fix] mime: Give injected HTML parts the regular URL pipeline
* [Fix] mime: Keep OOXML relationship-only parts ahead of story truncation and parse xlIntlMacrosheet
* [Fix] mime: Bound OOXML processing resources
* [Fix] mime: Register the DOCX content symbol scores
* [Fix] fuzzy: Give customer keys precedence over IP bans by applying the source policy after decryption
* [Fix] fuzzy: Initialize the key expiry time fields before mktime and reject failed date parses
* [Fix] fuzzy: Keep the unkeyed aggregate stats when per-IP tracking is disabled
* [Fix] fuzzy: Ping write servers with the write keypair, and only override the keypair when the server lists are actually shared
* [Fix] fuzzy: Report empty storages in /stat
* [Fix] dkim: Require a single author before reporting alignment
* [Fix] spf: Return permerror when a domain publishes multiple SPF records
* [Fix] spf: Match the version section as RFC 7208 4.5 defines it, without reading past a short TXT string
* [Fix] forged_recipients: Compare addresses by mailbox identity instead of as raw strings
* [Fix] greylist: Use the lowest passthrough priority for its pre-result
* [Fix] milter: Do not insert a bogus space after the header colon (negotiate SMFIP_HDR_LEADSPC)
* [Fix] url_redirector: Honour redirectors_only, which followed every redirect target
* [Fix] url_suspect: Restrict the html_entities obfuscation pattern to ASCII
* [Fix] url_suspect: Derive the public suffix through the suffix lookup instead of stripping a label from the eSLD
* [Fix] lua_maps: Key url-list maps by their effective type, so a glob map is no longer served as a hash map
* [Fix] WebUI: Order stat refresh cycles by start rather than completion
* [Fix] WebUI: Raise the stale-rate threshold above the largest auto-refresh preset
* [Fix] rspamadm: Fix the -n description in the fuzzy_ping help
To generate a diff of this commit:
cvs rdiff -u -r1.140 -r1.141 pkgsrc/mail/rspamd/Makefile
cvs rdiff -u -r1.43 -r1.44 pkgsrc/mail/rspamd/PLIST
cvs rdiff -u -r1.24 -r1.25 pkgsrc/mail/rspamd/cfgfiles.mk
cvs rdiff -u -r1.79 -r1.80 pkgsrc/mail/rspamd/distinfo
Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.
Modified files:
Index: pkgsrc/mail/rspamd/Makefile
diff -u pkgsrc/mail/rspamd/Makefile:1.140 pkgsrc/mail/rspamd/Makefile:1.141
--- pkgsrc/mail/rspamd/Makefile:1.140 Wed Sep 2 19:03:20 2026
+++ pkgsrc/mail/rspamd/Makefile Sat Sep 26 10:50:07 2026
@@ -1,9 +1,8 @@
-# $NetBSD: Makefile,v 1.140 2026/09/02 19:03:20 wiz Exp $
+# $NetBSD: Makefile,v 1.141 2026/09/26 10:50:07 wiz Exp $
#
# When updating this, run 'make cfgfiles'.
-DISTNAME= rspamd-4.1.5
-PKGREVISION= 1
+DISTNAME= rspamd-4.2.0
CATEGORIES= mail
MASTER_SITES= ${MASTER_SITE_GITHUB:=rspamd/}
Index: pkgsrc/mail/rspamd/PLIST
diff -u pkgsrc/mail/rspamd/PLIST:1.43 pkgsrc/mail/rspamd/PLIST:1.44
--- pkgsrc/mail/rspamd/PLIST:1.43 Mon Jul 27 15:26:07 2026
+++ pkgsrc/mail/rspamd/PLIST Sat Sep 26 10:50:07 2026
@@ -1,4 +1,4 @@
-@comment $NetBSD: PLIST,v 1.43 2026/07/27 15:26:07 wiz Exp $
+@comment $NetBSD: PLIST,v 1.44 2026/09/26 10:50:07 wiz Exp $
bin/mapstats
bin/rspamadm
bin/rspamadm-${PKGVERSION}
@@ -28,6 +28,7 @@ share/examples/rspamd/lua.local.d/module
share/examples/rspamd/lua.local.d/regexps/example.lua.example
share/examples/rspamd/lua.local.d/selectors/example.lua.example
share/examples/rspamd/maps.d/dmarc_whitelist.inc
+share/examples/rspamd/maps.d/equivalent_domains.inc
share/examples/rspamd/maps.d/exe_clickbait.inc
share/examples/rspamd/maps.d/maillist.inc
share/examples/rspamd/maps.d/mid.inc
@@ -154,6 +155,7 @@ share/rspamd/languages/pl.json
share/rspamd/languages/pt.json
share/rspamd/languages/ro.json
share/rspamd/languages/ru.json
+share/rspamd/languages/sk.json
share/rspamd/languages/sl.json
share/rspamd/languages/so.json
share/rspamd/languages/sq.json
@@ -182,10 +184,15 @@ share/rspamd/lualib/lua_cache.lua
share/rspamd/lualib/lua_cfg_transform.lua
share/rspamd/lualib/lua_cfg_utils.lua
share/rspamd/lualib/lua_clickhouse.lua
+share/rspamd/lualib/lua_content/docx.lua
share/rspamd/lualib/lua_content/ical.lua
share/rspamd/lualib/lua_content/init.lua
+share/rspamd/lualib/lua_content/ooxml.lua
share/rspamd/lualib/lua_content/pdf.lua
+share/rspamd/lualib/lua_content/pptx.lua
+share/rspamd/lualib/lua_content/svg.lua
share/rspamd/lualib/lua_content/vcard.lua
+share/rspamd/lualib/lua_content/xlsx.lua
share/rspamd/lualib/lua_cta.lua
share/rspamd/lualib/lua_dkim_tools.lua
share/rspamd/lualib/lua_extras.lua
@@ -268,6 +275,8 @@ share/rspamd/lualib/redis_scripts/bayes_
share/rspamd/lualib/redis_scripts/bayes_classify.lua
share/rspamd/lualib/redis_scripts/bayes_learn.lua
share/rspamd/lualib/redis_scripts/bayes_stat.lua
+share/rspamd/lualib/redis_scripts/fuzzy_count_scan.lua
+share/rspamd/lualib/redis_scripts/fuzzy_stats_scan.lua
share/rspamd/lualib/redis_scripts/fuzzy_update.lua
share/rspamd/lualib/redis_scripts/neural_maybe_invalidate.lua
share/rspamd/lualib/redis_scripts/neural_maybe_lock.lua
Index: pkgsrc/mail/rspamd/cfgfiles.mk
diff -u pkgsrc/mail/rspamd/cfgfiles.mk:1.24 pkgsrc/mail/rspamd/cfgfiles.mk:1.25
--- pkgsrc/mail/rspamd/cfgfiles.mk:1.24 Sun Aug 16 13:17:03 2026
+++ pkgsrc/mail/rspamd/cfgfiles.mk Sat Sep 26 10:50:07 2026
@@ -1,3 +1,3 @@
-# $NetBSD: cfgfiles.mk,v 1.24 2026/08/16 13:17:03 wiz Exp $
+# $NetBSD: cfgfiles.mk,v 1.25 2026/09/26 10:50:07 wiz Exp $
# Do not edit, regenerate using 'make cfgfiles'
-CFGFILES= actions.conf common.conf composites.conf groups.conf lang_detection.inc local.d/antivirus.conf.example local.d/module.conf.example logging.inc lua.local.d/maps/example.lua.example
lua.local.d/module.lua.example lua.local.d/regexps/example.lua.example lua.local.d/selectors/example.lua.example maps.d/dmarc_whitelist.inc maps.d/exe_clickbait.inc maps.d/maillist.inc maps.d/mid.inc
maps.d/mime_types.inc maps.d/redirectors.inc maps.d/spf_dkim_whitelist.inc maps.d/surbl-whitelist.inc maps.d/suspicious_tlds.inc metrics.conf modules.conf modules.d/aliases.conf
modules.d/antivirus.conf modules.d/arc.conf modules.d/asn.conf modules.d/aws_s3.conf modules.d/bayes_expiry.conf modules.d/bimi.conf modules.d/chartable.conf modules.d/clickhouse.conf
modules.d/contextal.conf modules.d/dcc.conf modules.d/dkim.conf modules.d/dkim_signing.conf modules.d/dmarc.conf modules.d/elastic.conf modules.d/emails.conf modules.d/external_relay.conf
modules.d/external_services.conf modules.d/force_actions.
conf modules.d/forged_recipients.conf modules.d/fuzzy_check.conf modules.d/gpt.conf modules.d/greylist.conf modules.d/hfilter.conf modules.d/history_redis.conf modules.d/http_headers.conf
modules.d/known_senders.conf modules.d/maillist.conf modules.d/metadata_exporter.conf modules.d/metric_exporter.conf modules.d/mid.conf modules.d/milter_headers.conf modules.d/mime_types.conf
modules.d/multimap.conf modules.d/mx_check.conf modules.d/neural.conf modules.d/neural_autolearn.conf modules.d/once_received.conf modules.d/p0f.conf modules.d/phishing.conf modules.d/ratelimit.conf
modules.d/rbl.conf modules.d/redis.conf modules.d/regexp.conf modules.d/replies.conf modules.d/reputation.conf modules.d/rspamd_update.conf modules.d/spamassassin.conf modules.d/spamtrap.conf
modules.d/spf.conf modules.d/surbl.conf modules.d/trie.conf modules.d/url_redirector.conf modules.d/url_suspect.conf modules.d/whitelist.conf modules.local.d/module.conf.example options.inc
override.d/module.conf.example rspam
d.conf scores.d/content_group.conf scores.d/fuzzy_group.conf scores.d/headers_group.conf scores.d/hfilter_group.conf scores.d/mime_types_group.conf scores.d/mua_group.conf
scores.d/phishing_group.conf scores.d/policies_group.conf scores.d/rbl_group.conf scores.d/statistics_group.conf scores.d/subject_group.conf scores.d/surbl_group.conf scores.d/url_suspect_group.conf
scores.d/whitelist_group.conf settings.conf statistic.conf worker-controller.inc worker-fuzzy.inc worker-normal.inc worker-proxy.inc
+CFGFILES= actions.conf common.conf composites.conf groups.conf lang_detection.inc local.d/antivirus.conf.example local.d/module.conf.example logging.inc lua.local.d/maps/example.lua.example
lua.local.d/module.lua.example lua.local.d/regexps/example.lua.example lua.local.d/selectors/example.lua.example maps.d/dmarc_whitelist.inc maps.d/equivalent_domains.inc maps.d/exe_clickbait.inc
maps.d/maillist.inc maps.d/mid.inc maps.d/mime_types.inc maps.d/redirectors.inc maps.d/spf_dkim_whitelist.inc maps.d/surbl-whitelist.inc maps.d/suspicious_tlds.inc metrics.conf modules.conf
modules.d/aliases.conf modules.d/antivirus.conf modules.d/arc.conf modules.d/asn.conf modules.d/aws_s3.conf modules.d/bayes_expiry.conf modules.d/bimi.conf modules.d/chartable.conf
modules.d/clickhouse.conf modules.d/contextal.conf modules.d/dcc.conf modules.d/dkim.conf modules.d/dkim_signing.conf modules.d/dmarc.conf modules.d/elastic.conf modules.d/emails.conf
modules.d/external_relay.conf modules.d/external_services
.conf modules.d/force_actions.conf modules.d/forged_recipients.conf modules.d/fuzzy_check.conf modules.d/gpt.conf modules.d/greylist.conf modules.d/hfilter.conf modules.d/history_redis.conf
modules.d/http_headers.conf modules.d/known_senders.conf modules.d/maillist.conf modules.d/metadata_exporter.conf modules.d/metric_exporter.conf modules.d/mid.conf modules.d/milter_headers.conf
modules.d/mime_types.conf modules.d/multimap.conf modules.d/mx_check.conf modules.d/neural.conf modules.d/neural_autolearn.conf modules.d/once_received.conf modules.d/p0f.conf modules.d/phishing.conf
modules.d/ratelimit.conf modules.d/rbl.conf modules.d/redis.conf modules.d/regexp.conf modules.d/replies.conf modules.d/reputation.conf modules.d/rspamd_update.conf modules.d/spamassassin.conf
modules.d/spamtrap.conf modules.d/spf.conf modules.d/surbl.conf modules.d/trie.conf modules.d/url_redirector.conf modules.d/url_suspect.conf modules.d/whitelist.conf
modules.local.d/module.conf.example options.inc overri
de.d/module.conf.example rspamd.conf scores.d/content_group.conf scores.d/fuzzy_group.conf scores.d/headers_group.conf scores.d/hfilter_group.conf scores.d/mime_types_group.conf
scores.d/mua_group.conf scores.d/phishing_group.conf scores.d/policies_group.conf scores.d/rbl_group.conf scores.d/statistics_group.conf scores.d/subject_group.conf scores.d/surbl_group.conf
scores.d/url_suspect_group.conf scores.d/whitelist_group.conf settings.conf statistic.conf worker-controller.inc worker-fuzzy.inc worker-normal.inc worker-proxy.inc
Index: pkgsrc/mail/rspamd/distinfo
diff -u pkgsrc/mail/rspamd/distinfo:1.79 pkgsrc/mail/rspamd/distinfo:1.80
--- pkgsrc/mail/rspamd/distinfo:1.79 Sun Aug 16 13:17:03 2026
+++ pkgsrc/mail/rspamd/distinfo Sat Sep 26 10:50:07 2026
@@ -1,8 +1,8 @@
-$NetBSD: distinfo,v 1.79 2026/08/16 13:17:03 wiz Exp $
+$NetBSD: distinfo,v 1.80 2026/09/26 10:50:07 wiz Exp $
-BLAKE2s (rspamd-4.1.5.tar.gz) = 62189d72c54596dc131a775edaeea62966bdc77d452744c43b5c98405f927f99
-SHA512 (rspamd-4.1.5.tar.gz) = 6b6e7375025b0b72afc6260f41c55c39dc510b79df964383e2895685c43c2783881a174b09606632ef209c7d193979147246c6b8575e8329e8735b15aa4d5618
-Size (rspamd-4.1.5.tar.gz) = 7191230 bytes
+BLAKE2s (rspamd-4.2.0.tar.gz) = d0be15d25ca4257c01170fe0c1e3ac3d89f0bb50d1d1e8fa21d3ba8e9e7a31f9
+SHA512 (rspamd-4.2.0.tar.gz) = bf4b8e4c8bf99a590b7a3f532424fb705a08c28e7e77b583e12b6f855896dd31c6f0ddc8443a899b08aa09bd80616978ac0208dd78000bcd3b5faeb67e9dfba0
+Size (rspamd-4.2.0.tar.gz) = 7393821 bytes
SHA1 (patch-CMakeLists.txt) = 25a1264b573d5a1f7ff9a1ac7b8453c5d9cb0a06
SHA1 (patch-cmake_Toolset.cmake) = fbc4027fedb4261ce913701ebbb32d8395bc7783
SHA1 (patch-contrib_fpconv_fpconv.c) = b1ec2b07570674458e69020ccbf25f0374d894f6
Home |
Main Index |
Thread Index |
Old Index