Morning All,

After a few thoughts on limits, it appears that any duplicate subtest
hits are best combined for debug output.

Any thoughts on the attached?  It looks like it will help me with rule
development while support rules with valid but large maxhits like __LOWER_E

Regards,
KAM

On 5/31/2019 10:30 AM, Bill Cole wrote:
> On 30 May 2019, at 20:35, Kevin A. McGrail wrote:
>
>> I was curious if anyone noticed the debug output for subtests has gotten
>> insane:
>
> It got a little discussion on users@ when I created those rules.
>
> [...]
>
>> 72_active.cf:    body            __LOWER_E       /e/
>> 72_active.cf:    tflags          __LOWER_E       multiple maxhits=230
>>
>> 72_active.cf:    body            __E_LIKE_LETTER /<lcase_e>/
>> 72_active.cf:    tflags          __E_LIKE_LETTER multiple maxhits=320
>>
>> Assuming those maxhits are correct,
>
> They are. In fact they were carefully tuned to catch the targeted
> extortion spam.
>
>> maybe we need something in the debug
>> output that says __E_LIKE_LETTER (number of hits if more than 1).
>
> That would be a useful enhancement even without my flagrant log
> vandalism.
>

-- 
Kevin A. McGrail
Member, Apache Software Foundation
Chair Emeritus Apache SpamAssassin Project
https://www.linkedin.com/in/kmcgrail - 703.798.0171

Index: lib/Mail/SpamAssassin/PerMsgStatus.pm
===================================================================
--- lib/Mail/SpamAssassin/PerMsgStatus.pm       (revision 1860582)
+++ lib/Mail/SpamAssassin/PerMsgStatus.pm       (working copy)
@@ -769,7 +769,38 @@
 sub get_names_of_subtests_hit {
   my ($self) = @_;
 
-  return join(',', sort @{$self->{subtest_names_hit}});
+  #return join(',', sort @{$self->{subtest_names_hit}});
+
+  #This routine prints only one instance of a subrule hit with a count of how 
many times it hit if greater than 1
+  my (%subtest_names_hit, $i, $key, @keys, @sorted, $string, $rule, 
$total_hits, $deduplicated_hits);  
+
+  $total_hits = scalar(@{$self->{subtest_names_hit}});
+
+  for ($i=0; $i < $total_hits; $i++) {
+    $rule = ${$self->{subtest_names_hit}}[$i]; 
+    $subtest_names_hit{$rule}++; 
+  }
+
+  foreach $key (keys %subtest_names_hit) {
+    push (@keys, $key);
+  }
+  @sorted = sort @keys;
+
+  $deduplicated_hits = scalar(@sorted);
+
+  for ($i=0; $i < $deduplicated_hits; $i++) {
+    $string .= $sorted[$i];
+    if ($subtest_names_hit{$sorted[$i]} > 1) {
+      $string .= "($subtest_names_hit{$sorted[$i]})"
+    }
+    $string .= ",";
+  }
+
+  $string =~ s/,$//;
+
+  $string .= " (Total Subtest Hits: $total_hits / Deduplicated Total Hits: 
$deduplicated_hits)";
+
+  return $string;
 }
 
 ###########################################################################

Reply via email to