New installs start with the hashed-address blocklist off, and DNSBL zones read right
Personal-data catalog spec, default D5 (settled 2026-09-28; built after the v0.16.24 import's spam-rules loader landed). msbl.org's EBL is sent a SHA-1 of every email address it's asked about. A new install's first boot now leaves a note, and the rules update, once the bundled rules are in, switches STWT_MSBL_EBL_EMAIL off and forgets the note, so it happens once; the loader keeps that switch through later updates. An existing server has no note and keeps every blocklist as it is. Also fixes the data inventory's DNSBL endpoints: a zone is an expression (`ip_reverse + '.zen.spamhaus.org'`, conditional branches, `hash(email, 'sha1') + '.ebl.msbl.org'`), and the zone names are now the quoted literals that start with a dot, from every branch, rather than the expression's text. Tested: unit test for the zone rule; the compliance system test (no note, no change; the inventory lists ebl.msbl.org, not a hash; with the note the blocklist goes off; the note works once); the system suite; fork checks.
This commit is contained in:
@@ -88,13 +88,31 @@ fn days(duration: Option<&Duration>) -> Days {
|
||||
}
|
||||
}
|
||||
|
||||
/// An expression's text, if it is a plain constant (a zone, a switch).
|
||||
fn expression_text(value: &Value) -> Option<String> {
|
||||
match value {
|
||||
Value::String(s) => Some(s.clone()),
|
||||
Value::Object(o) => o.get("else").and_then(|v| v.as_str()).map(str::to_string),
|
||||
_ => None,
|
||||
/// The zones a DNSBL's zone expression can query: each quoted literal that
|
||||
/// starts with a dot, in any branch (`ip_reverse + '.zen.spamhaus.org'`).
|
||||
fn zone_hosts(value: &Value) -> Vec<String> {
|
||||
let mut hosts = Vec::new();
|
||||
let mut texts = Vec::new();
|
||||
fn collect<'a>(value: &'a Value, texts: &mut Vec<&'a str>) {
|
||||
match value {
|
||||
Value::String(s) => texts.push(s),
|
||||
Value::Array(items) => items.iter().for_each(|v| collect(v, texts)),
|
||||
Value::Object(map) => map.values().for_each(|v| collect(v, texts)),
|
||||
_ => {}
|
||||
}
|
||||
}
|
||||
collect(value, &mut texts);
|
||||
for text in texts {
|
||||
for literal in text.split('\'').skip(1).step_by(2) {
|
||||
if let Some(zone) = literal.strip_prefix('.')
|
||||
&& zone.contains('.')
|
||||
&& !hosts.iter().any(|h| h == zone)
|
||||
{
|
||||
hosts.push(zone.to_string());
|
||||
}
|
||||
}
|
||||
}
|
||||
hosts
|
||||
}
|
||||
|
||||
impl Server {
|
||||
@@ -263,7 +281,7 @@ impl Server {
|
||||
let value = serde_json::to_value(&server.object).unwrap_or_default();
|
||||
if value.get("enable").and_then(Value::as_bool).unwrap_or(false) {
|
||||
dnsbl_on = true;
|
||||
if let Some(zone) = value.get("zone").and_then(expression_text) {
|
||||
for zone in value.get("zone").map(zone_hosts).unwrap_or_default() {
|
||||
endpoint(&mut facts, "spam-dnsbl", zone);
|
||||
}
|
||||
}
|
||||
@@ -397,6 +415,16 @@ mod tests {
|
||||
assert_eq!(remote_host(&json!({"@type": "S3", "bucket": "mail"})), Some("S3".into()));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn zones_come_from_every_branch() {
|
||||
let zone = json!({"else": "false", "match": {"0": {"if": "location == 'tcp'",
|
||||
"then": "ip_reverse + '.rep.mailspike.net'"}}});
|
||||
assert_eq!(zone_hosts(&zone), vec!["rep.mailspike.net"]);
|
||||
let zone = json!({"else": "hash(email, 'sha1') + '.ebl.msbl.org'", "match": {}});
|
||||
assert_eq!(zone_hosts(&zone), vec!["ebl.msbl.org"], "not 'sha1'");
|
||||
assert!(zone_hosts(&json!({"else": "false"})).is_empty());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn days_round_up() {
|
||||
assert_eq!(days(Some(&Duration::from_millis(86_400_000))), Days::Days(1));
|
||||
|
||||
Reference in New Issue
Block a user