Bundle the spam filter rules with the server
The server fetched upstream's latest published rules from GitHub at run time: a version nobody here tested, code-like expressions from an account we don't control, and the upstream name as a default in the admin form. The published rules of spam-filter v3.0.2 are now embedded (resources/spam-filter/, MIT, in THIRD-PARTY.md) and used whenever no other source is configured. An empty setting and upstream's old default both mean the bundled rules, so existing installs switch without a settings change; the URL stays an operator override (https:// or file://). The schema default is dropped and its description says what empty means, and the strip's rename pass does the same to each import. Rules load on first boot as before, and again whenever the bundled version differs from the last one loaded, which only adds missing rules and tags. That brings the AI classifier's LLM_* scores to installs that predate them: production has none today. upstream-watch now also opens an issue when spam-filter publishes a newer release; resources/spam-filter/README.md says how to take it. The antispam test now runs on the bundled rules, the path production takes; SPAM_RULES_URL tests another set. Unit tests cover the URL handling and that the bundled rules parse and score the AI tags as the AI spec says.
This commit is contained in:
@@ -23,6 +23,6 @@ crates/migration/src/lib.rs "STALWART_SPAM_CLASSIFIER_MODEL.lz4"
|
||||
crates/migration/src/lib.rs "STALWART_SPAM_TRAIN_DATA.lz4"
|
||||
crates/types/src/branding.rs "STALWART"
|
||||
|
||||
# OPEN, not yet decided (2026-09-22): upstream's published spam-filter rules,
|
||||
# which the server downloads at runtime from this address.
|
||||
crates/registry/src/schema/structs_impl.rs "https://github.com/stalwartlabs/spam-filter/releases/latest/download/spam-filter-rules.json.gz"
|
||||
# Upstream's old default rules source, read only to treat it as unset: the
|
||||
# server uses the rules bundled with it (resources/spam-filter/).
|
||||
crates/common/src/manager/spam_rules.rs "https://github.com/stalwartlabs/spam-filter/releases/latest/download/spam-filter-rules.json.gz"
|
||||
|
||||
@@ -46,6 +46,10 @@ TEXT_RENAMES = [
|
||||
# that must match their containers and identity provider (database users,
|
||||
# passwords, an OIDC audience), and name their databases explicitly.
|
||||
('"stalwart".to_string()', '"inbuxa".to_string()', ('crates',)),
|
||||
# The spam filter rules ship with the server (common::manager::spam_rules);
|
||||
# upstream's default of fetching its latest from GitHub becomes unset.
|
||||
('spam_filter_rules_url: Some("https://github.com/stalwartlabs/spam-filter/releases/latest/download/spam-filter-rules.json.gz".to_string()),',
|
||||
'spam_filter_rules_url: None,', ('crates',)),
|
||||
]
|
||||
ROOTS = ('crates', 'tests', 'resources')
|
||||
SKIP_SUFFIXES = {'.md', '.txt'}
|
||||
@@ -58,6 +62,10 @@ SCHEMA_HASH = Path('resources/schema/schema.json.sha256')
|
||||
SCHEMA_RENAMES = [
|
||||
('"stalwart"', '"inbuxa"'),
|
||||
('vnd.stalwart', 'vnd.inbuxa'),
|
||||
# The bundled spam rules: no default URL, and say what empty means.
|
||||
('"spamFilterRulesUrl":"https://github.com/stalwartlabs/spam-filter/releases/latest/download/spam-filter-rules.json.gz",', ''),
|
||||
('"URL to download spam filter rules from"',
|
||||
'"URL to download spam filter rules from. Empty uses the rules bundled with the server."'),
|
||||
]
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user