pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: pkgsrc/mail/rspamd



Module Name:    pkgsrc
Committed By:   wiz
Date:           Mon Jul 27 15:26:07 UTC 2026

Modified Files:
        pkgsrc/mail/rspamd: Makefile PLIST cfgfiles.mk distinfo

Log Message:
rspamd: update to 4.1.3.

4.1.3: 25 Jul 2026

  ** Incompatible changes **
  * [Rework] WebUI: Drop jQuery dependency (all modules migrated to native DOM and XMLHttpRequest)
  * [Rework] WebUI: Drop the Font Awesome framework in favour of a local subset SVG sprite
  * [Rework] dkim: Scope HAVE_ED25519 to OpenSSL key parsing, so ed25519 verification works on OpenSSL builds without it

  ** Features **
  * [Feature] fuzzy_check: Structured match results, diagnostics API and task:get_fuzzy_results()
  * [Feature] fuzzy_check: Anchor the probability weight curve at the match threshold (prob_bias, prob_power)
  * [Feature] fuzzy: Persist shingle sets with digests in redis, fixing orphaned slots on DEL and decay on REFRESH
  * [Feature] fuzzy: Per-hash introspection via rspamadm control fuzzyhash
  * [Feature] fuzzy: Track unkeyed clients in fuzzystat
  * [Feature] rspamadm: Add fuzzy_hash command
  * [Feature] clickhouse: Export fuzzy match details (schema version 11)
  * [Feature] milter_headers: Annotate the X-Rspamd-Fuzzy header with rule, flag, probability and timestamp
  * [Feature] lua_http: Add forbid_local option to block requests to local networks, enabled by default in url_redirector
  * [Feature] lua_feedback_parsers: Enrich sparse ARF reports from the original message headers

  ** Bug fixes **
  * [CritFix] dkim: Bound bh= length before the body hash comparison (out-of-bounds read via ed25519 signatures)
  * [CritFix] fuzzy: Release TCP session ownership exactly once (use-after-free on aborted connections)
  * [CritFix] protocol: Validate shared memory segment bounds and reject non-regular segments
  * [CritFix] http: Fix shared body storage lifecycle (double free, descriptor 0 leak and closing an unrelated socket)
  * [Fix] dkim: Bound public key size and modulus width from DNS
  * [Fix] dkim: Stop reading before the body slice in empty line skipping
  * [Fix] dkim: Apply max_sigs before any work and count every signature header
  * [Fix] dkim: Bound the number of h= header list items
  * [Fix] spf: Return permerror when a DNS limit is hit
  * [Fix] spf: Enforce the include/redirect nesting limit
  * [Fix] spf: Bound address lookups spawned by mx/ptr expansion (max_dns_expansions)
  * [Fix] spf: Use the enclosing element for exists
  * [Fix] fuzzy: Check admission before parsing UDP commands, and rate limit PING and STAT
  * [Fix] fuzzy: Fix stack overread in the sqlite backend id
  * [Fix] fuzzy_check: Log the rule and the server for error replies
  * [Fix] ragel: Bound nested comment depth in the header parsers
  * [Fix] mime_parser: Bound parser resource usage
  * [Fix] mime_headers: Bound parser resource usage
  * [Fix] content_type: Bound parameters per header and fix RFC 2231 continuation ordering
  * [Fix] message: Bound per-part newline metadata and make the budget task-global
  * [Fix] message: Link plain text parts to their HTML alternative
  * [Fix] message: Bound alt-part linking and fasttext langdet cost
  * [Fix] html: Eliminate DOM recursion to survive deeply nested messages
  * [Fix] html: Bound attributes per tag and per task
  * [Fix] html: Cap synthetic tags and fix the balance loop
  * [Fix] html: Correct image style dimension parsing
  * [Fix] images: Avoid quadratic Content-ID linking
  * [Fix] archives: Bound metadata resource usage
  * [Fix] 7zip: Bound folder count and guarantee parser progress
  * [Fix] url: Enforce max_urls at the central insertion boundary
  * [Fix] url_suspect: Drop dead branch in the user field check and skip mailto URLs
  * [Fix] task: Bound zstd decompression by max_message and plug an error-path leak
  * [Fix] zstd: Share one bounded decompression helper across HTTP, proxy and maps
  * [Fix] http: Bound request bodies on the controller, proxy and control sockets
  * [Fix] http: Enforce the read deadline when data is pending at timer expiry
  * [Fix] map: Bound remote HTTP map sizes, compressed and decompressed (max_map_size)
  * [Fix] maps: Map the signature file as a file, not as shmem
  * [Fix] maps: Redact credentials from map error logs
  * [Fix] util: Harden the shared memory mapping helpers
  * [Fix] lua_http: Bound HTTP responses by default (max_lua_http_response)
  * [Fix] lua_http: Deliver errors to coroutine callers
  * [Fix] lua_tcp: Make the connection ref release one-shot to avoid a double free
  * [Fix] lua_content/pdf: Emit newlines for Td/TD line breaks
  * [Fix] cfg: Warn when a module section is defined multiple times
  * [Fix] WebUI: Route a malformed /stat response to the login dialog
  * [Fix] WebUI: Restore smooth scroll on the Scan tab
  * [Fix] WebUI: Stop the refresh spinner restarting mid fan-out
  * [Fix] WebUI: Guard the optional fuzzy_hashes key and other jQuery-removal regressions

4.1.2: 21 Jul 2026

  ** Incompatible changes **
  * [Rework] lua_task: Make the 'orig' address flavour return only the wire addresses when a rewrite preserved the originals
  * [Rework] WebUI: Migrate all tables from FooTable to Tabulator (per-column filters, global history/scan search) and remove FooTable

  ** Features **
  * [Feature] composites: Add per-symbol Lua conditions and explicit dependencies
  * [Feature] configdump: Show symcache flags in --symbol-details
  * [Feature] neural: Add static_embed provider (WordPiece subword tokenizer over a static embedding matrix, with per-token vector access)
  * [Feature] neural: Add forced-learn minimal-scan fast path and train.frozen control to stop automatic training
  * [Feature] rspamadm: Discover command modules from external directories (rspamadm.d and RSPAMADM_COMMAND_PATH)
  * [Feature] rspamadm: Allow reading the password from the environment for automation
  * [Feature] settings: Add apply policy option (implicit_allow) with additive symbols_enabled and strict explicit_enable gating

  ** Bug fixes **
  * [CritFix] mime_parser: Bound message/rfc822 recursion depth (remote DoS via deeply nested messages)
  * [Fix] aliases: Refuse to rewrite From address domains (SPF, DKIM and DMARC key on the sender identity)
  * [Fix] aliases: Never rewrite the googlemail.com domain to gmail.com
  * [Fix] dmarc: Evaluate the From and envelope domains as seen in the message, not after alias rewriting
  * [Fix] spf: Check the original envelope sender even if it was rewritten
  * [Fix] forged_recipients: Compare envelope and header addresses as they were transmitted
  * [Fix] mime: Split address lists on semicolons as well as commas (Outlook-style recipient lists)
  * [Fix] fuzzy: Skip injected (computed) parts on learn and check
  * [Fix] phishing: Don't penalise the same label under another TLD (brand.co.uk displayed over brand.com)
  * [Fix] maps: Anchor glob map patterns to match the whole subject; entries relying on substring matching need explicit wildcards
  * [Fix] lua_selectors: Reject selectors that parse only as a prefix instead of silently evaluating the truncated part
  * [Fix] lua_selectors: Don't crash the scan on a method call missing on the extracted value
  * [Fix] lua_cryptobox: Pass the padded nonce to secretbox encrypt/decrypt (out-of-bounds read with short nonces)
  * [Fix] lua_kann: Fix load({filename}) argument index and save() return value
  * [Fix] gpt: Don't send a duplicate request when context_augment invokes its callback synchronously
  * [Fix] icap: Fix insertion of HTTP header in get_http_headers
  * [Fix] dmarc_report: Don't call blocking sleep from an async callback when throttling batches
  * [Fix] Lua 5.5 compatibility: do not assign to for-loop variables (fixes startup error in Jinja templates via lupa)


To generate a diff of this commit:
cvs rdiff -u -r1.136 -r1.137 pkgsrc/mail/rspamd/Makefile
cvs rdiff -u -r1.42 -r1.43 pkgsrc/mail/rspamd/PLIST
cvs rdiff -u -r1.21 -r1.22 pkgsrc/mail/rspamd/cfgfiles.mk
cvs rdiff -u -r1.75 -r1.76 pkgsrc/mail/rspamd/distinfo

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: pkgsrc/mail/rspamd/Makefile
diff -u pkgsrc/mail/rspamd/Makefile:1.136 pkgsrc/mail/rspamd/Makefile:1.137
--- pkgsrc/mail/rspamd/Makefile:1.136   Mon Jul  6 09:22:17 2026
+++ pkgsrc/mail/rspamd/Makefile Mon Jul 27 15:26:07 2026
@@ -1,8 +1,8 @@
-# $NetBSD: Makefile,v 1.136 2026/07/06 09:22:17 wiz Exp $
+# $NetBSD: Makefile,v 1.137 2026/07/27 15:26:07 wiz Exp $
 #
 # When updating this, run 'make cfgfiles'.
 
-DISTNAME=      rspamd-4.1.1
+DISTNAME=      rspamd-4.1.3
 CATEGORIES=    mail
 MASTER_SITES=  ${MASTER_SITE_GITHUB:=rspamd/}
 

Index: pkgsrc/mail/rspamd/PLIST
diff -u pkgsrc/mail/rspamd/PLIST:1.42 pkgsrc/mail/rspamd/PLIST:1.43
--- pkgsrc/mail/rspamd/PLIST:1.42       Mon Jul  6 09:22:17 2026
+++ pkgsrc/mail/rspamd/PLIST    Mon Jul 27 15:26:07 2026
@@ -1,4 +1,4 @@
-@comment $NetBSD: PLIST,v 1.42 2026/07/06 09:22:17 wiz Exp $
+@comment $NetBSD: PLIST,v 1.43 2026/07/27 15:26:07 wiz Exp $
 bin/mapstats
 bin/rspamadm
 bin/rspamadm-${PKGVERSION}
@@ -257,6 +257,7 @@ share/rspamd/lualib/plugins/dmarc.lua
 share/rspamd/lualib/plugins/neural.lua
 share/rspamd/lualib/plugins/neural/providers/fasttext_embed.lua
 share/rspamd/lualib/plugins/neural/providers/llm.lua
+share/rspamd/lualib/plugins/neural/providers/static_embed.lua
 share/rspamd/lualib/plugins/neural/providers/symbols.lua
 share/rspamd/lualib/plugins/neural/providers/text_hash.lua
 share/rspamd/lualib/plugins/ratelimit.lua
@@ -288,6 +289,7 @@ share/rspamd/lualib/rspamadm/dkim_keygen
 share/rspamd/lualib/rspamadm/dmarc_report.lua
 share/rspamd/lualib/rspamadm/dns_tool.lua
 share/rspamd/lualib/rspamadm/fuzzy_convert.lua
+share/rspamd/lualib/rspamadm/fuzzy_hash.lua
 share/rspamd/lualib/rspamadm/fuzzy_ping.lua
 share/rspamd/lualib/rspamadm/fuzzy_stat.lua
 share/rspamd/lualib/rspamadm/grep.lua
@@ -386,35 +388,36 @@ share/rspamd/www/ARCHITECTURE.md
 share/rspamd/www/README.md
 share/rspamd/www/apple-touch-icon.png
 share/rspamd/www/browserconfig.xml
-share/rspamd/www/css/FooTable.FontAwesome.css
 share/rspamd/www/css/bootstrap.min.css
 share/rspamd/www/css/codejar-linenumbers.css
 share/rspamd/www/css/d3evolution.css
 share/rspamd/www/css/d3pie.css
-share/rspamd/www/css/footable.standalone.min.css
+share/rspamd/www/css/icons.css
 share/rspamd/www/css/nprogress.css
 share/rspamd/www/css/prism.css
 share/rspamd/www/css/rspamd.css
-share/rspamd/www/css/svg-with-js.min.css
+share/rspamd/www/css/tabulator_bs5.min.css
 share/rspamd/www/favicon-16x16.png
 share/rspamd/www/favicon-32x32.png
 share/rspamd/www/favicon.ico
 share/rspamd/www/img/asc.png
 share/rspamd/www/img/desc.png
 share/rspamd/www/img/drop-area.svg
+share/rspamd/www/img/icons.svg
 share/rspamd/www/img/rspamd_logo_navbar.png
 share/rspamd/www/img/rspamd_logo_navbar_dark.png
 share/rspamd/www/index.html
 share/rspamd/www/js/app/common.js
 share/rspamd/www/js/app/config.js
-share/rspamd/www/js/app/footable-fontawesome.js
 share/rspamd/www/js/app/graph.js
 share/rspamd/www/js/app/history.js
+share/rspamd/www/js/app/icons.js
 share/rspamd/www/js/app/libft.js
 share/rspamd/www/js/app/rspamd.js
 share/rspamd/www/js/app/selectors.js
 share/rspamd/www/js/app/stats.js
 share/rspamd/www/js/app/symbols.js
+share/rspamd/www/js/app/tab-utils.js
 share/rspamd/www/js/app/upload.js
 share/rspamd/www/js/lib/bootstrap.bundle.min.js
 share/rspamd/www/js/lib/codejar-linenumbers.min.js
@@ -422,14 +425,10 @@ share/rspamd/www/js/lib/codejar.min.js
 share/rspamd/www/js/lib/d3.min.js
 share/rspamd/www/js/lib/d3evolution.min.js
 share/rspamd/www/js/lib/d3pie.min.js
-share/rspamd/www/js/lib/fontawesome.min.js
-share/rspamd/www/js/lib/footable.min.js
-share/rspamd/www/js/lib/jquery-3.7.1.min.js
-share/rspamd/www/js/lib/jquery.stickytabs.min.js
 share/rspamd/www/js/lib/nprogress.min.js
 share/rspamd/www/js/lib/prism.js
 share/rspamd/www/js/lib/require.min.js
-share/rspamd/www/js/lib/solid.min.js
+share/rspamd/www/js/lib/tabulator.min.js
 share/rspamd/www/js/lib/visibility.min.js
 share/rspamd/www/js/main.js
 share/rspamd/www/mstile-150x150.png

Index: pkgsrc/mail/rspamd/cfgfiles.mk
diff -u pkgsrc/mail/rspamd/cfgfiles.mk:1.21 pkgsrc/mail/rspamd/cfgfiles.mk:1.22
--- pkgsrc/mail/rspamd/cfgfiles.mk:1.21 Mon Jul  6 09:22:17 2026
+++ pkgsrc/mail/rspamd/cfgfiles.mk      Mon Jul 27 15:26:07 2026
@@ -1,4 +1,4 @@
-# $NetBSD: cfgfiles.mk,v 1.21 2026/07/06 09:22:17 wiz Exp $
+# $NetBSD: cfgfiles.mk,v 1.22 2026/07/27 15:26:07 wiz Exp $
 # Do not edit, regenerate using 'make cfgfiles'
 CFGFILES=      actions.conf common.conf composites.conf groups.conf lang_detection.inc local.d/antivirus.conf.example local.d/module.conf.example logging.inc lua.local.d/maps/example.lua.example 
lua.local.d/module.lua.example lua.local.d/regexps/example.lua.example lua.local.d/selectors/example.lua.example maps.d/dmarc_whitelist.inc maps.d/exe_clickbait.inc maps.d/maillist.inc maps.d/mid.inc 
maps.d/mime_types.inc maps.d/redirectors.inc maps.d/spf_dkim_whitelist.inc maps.d/surbl-whitelist.inc maps.d/suspicious_tlds.inc metrics.conf modules.conf modules.d/aliases.conf 
modules.d/antivirus.conf modules.d/arc.conf modules.d/asn.conf modules.d/aws_s3.conf modules.d/bayes_expiry.conf modules.d/bimi.conf modules.d/chartable.conf modules.d/clickhouse.conf 
modules.d/contextal.conf modules.d/dcc.conf modules.d/dkim.conf modules.d/dkim_signing.conf modules.d/dmarc.conf modules.d/elastic.conf modules.d/emails.conf modules.d/external_relay.conf 
modules.d/external_services.conf modules.d/force_actions.
 conf modules.d/forged_recipients.conf modules.d/fuzzy_check.conf modules.d/gpt.conf modules.d/greylist.conf modules.d/hfilter.conf modules.d/history_redis.conf modules.d/http_headers.conf 
modules.d/known_senders.conf modules.d/maillist.conf modules.d/metadata_exporter.conf modules.d/metric_exporter.conf modules.d/mid.conf modules.d/milter_headers.conf modules.d/mime_types.conf 
modules.d/multimap.conf modules.d/mx_check.conf modules.d/neural.conf modules.d/neural_autolearn.conf modules.d/once_received.conf modules.d/p0f.conf modules.d/phishing.conf modules.d/ratelimit.conf 
modules.d/rbl.conf modules.d/redis.conf modules.d/regexp.conf modules.d/replies.conf modules.d/reputation.conf modules.d/rspamd_update.conf modules.d/spamassassin.conf modules.d/spamtrap.conf 
modules.d/spf.conf modules.d/surbl.conf modules.d/trie.conf modules.d/url_redirector.conf modules.d/url_suspect.conf modules.d/whitelist.conf modules.local.d/module.conf.example options.inc 
override.d/module.conf.example rspam
 d.conf scores.d/content_group.conf scores.d/fuzzy_group.conf scores.d/headers_group.conf scores.d/hfilter_group.conf scores.d/mime_types_group.conf scores.d/mua_group.conf 
scores.d/phishing_group.conf scores.d/policies_group.conf scores.d/rbl_group.conf scores.d/statistics_group.conf scores.d/subject_group.conf scores.d/surbl_group.conf scores.d/url_suspect_group.conf 
scores.d/whitelist_group.conf settings.conf statistic.conf worker-controller.inc worker-fuzzy.inc worker-normal.inc worker-proxy.inc
 

Index: pkgsrc/mail/rspamd/distinfo
diff -u pkgsrc/mail/rspamd/distinfo:1.75 pkgsrc/mail/rspamd/distinfo:1.76
--- pkgsrc/mail/rspamd/distinfo:1.75    Mon Jul  6 09:22:17 2026
+++ pkgsrc/mail/rspamd/distinfo Mon Jul 27 15:26:07 2026
@@ -1,8 +1,8 @@
-$NetBSD: distinfo,v 1.75 2026/07/06 09:22:17 wiz Exp $
+$NetBSD: distinfo,v 1.76 2026/07/27 15:26:07 wiz Exp $
 
-BLAKE2s (rspamd-4.1.1.tar.gz) = 6400093a731044fb104a98004de8aa9ba48387f186c4256d8028796fb7ce932e
-SHA512 (rspamd-4.1.1.tar.gz) = 80f77fe641ae77c2cf874bcc5e7cf854a3a0f1ae9386a49f6497c99486d49ddfc52d311d593dd811d4c13acdadcf7377ee818bac7e48eb2e479526f19741581d
-Size (rspamd-4.1.1.tar.gz) = 7200250 bytes
+BLAKE2s (rspamd-4.1.3.tar.gz) = a8e38df180b97f812aaa1e8fdd0992c110bccde8f729b7e25ac71840941518e9
+SHA512 (rspamd-4.1.3.tar.gz) = 6595941105c75255e7e624a8fff98e290ff0cbc2f425c7a396abacc40a8e4151a4cb990ecf29cefaddf8ea484df8aba6687863883a73f83e880342d85b2f32d3
+Size (rspamd-4.1.3.tar.gz) = 7071322 bytes
 SHA1 (patch-CMakeLists.txt) = 25a1264b573d5a1f7ff9a1ac7b8453c5d9cb0a06
 SHA1 (patch-cmake_Toolset.cmake) = fbc4027fedb4261ce913701ebbb32d8395bc7783
 SHA1 (patch-contrib_fpconv_fpconv.c) = b1ec2b07570674458e69020ccbf25f0374d894f6



Home | Main Index | Thread Index | Old Index