Morning All,
After a few thoughts on limits, it appears that any duplicate subtest
hits are best combined for debug output.
Any thoughts on the attached? It looks like it will help me with rule
development while support rules with valid but large maxhits like __LOWER_E
Regards,
KAM
On 5/31/2019 10:30 AM, Bill Cole wrote:
> On 30 May 2019, at 20:35, Kevin A. McGrail wrote:
>
>> I was curious if anyone noticed the debug output for subtests has gotten
>> insane:
>
> It got a little discussion on users@ when I created those rules.
>
> [...]
>
>> 72_active.cf: body __LOWER_E /e/
>> 72_active.cf: tflags __LOWER_E multiple maxhits=230
>>
>> 72_active.cf: body __E_LIKE_LETTER /<lcase_e>/
>> 72_active.cf: tflags __E_LIKE_LETTER multiple maxhits=320
>>
>> Assuming those maxhits are correct,
>
> They are. In fact they were carefully tuned to catch the targeted
> extortion spam.
>
>> maybe we need something in the debug
>> output that says __E_LIKE_LETTER (number of hits if more than 1).
>
> That would be a useful enhancement even without my flagrant log
> vandalism.
>
--
Kevin A. McGrail
Member, Apache Software Foundation
Chair Emeritus Apache SpamAssassin Project
https://www.linkedin.com/in/kmcgrail - 703.798.0171
Index: lib/Mail/SpamAssassin/PerMsgStatus.pm
===================================================================
--- lib/Mail/SpamAssassin/PerMsgStatus.pm (revision 1860582)
+++ lib/Mail/SpamAssassin/PerMsgStatus.pm (working copy)
@@ -769,7 +769,38 @@
sub get_names_of_subtests_hit {
my ($self) = @_;
- return join(',', sort @{$self->{subtest_names_hit}});
+ #return join(',', sort @{$self->{subtest_names_hit}});
+
+ #This routine prints only one instance of a subrule hit with a count of how
many times it hit if greater than 1
+ my (%subtest_names_hit, $i, $key, @keys, @sorted, $string, $rule,
$total_hits, $deduplicated_hits);
+
+ $total_hits = scalar(@{$self->{subtest_names_hit}});
+
+ for ($i=0; $i < $total_hits; $i++) {
+ $rule = ${$self->{subtest_names_hit}}[$i];
+ $subtest_names_hit{$rule}++;
+ }
+
+ foreach $key (keys %subtest_names_hit) {
+ push (@keys, $key);
+ }
+ @sorted = sort @keys;
+
+ $deduplicated_hits = scalar(@sorted);
+
+ for ($i=0; $i < $deduplicated_hits; $i++) {
+ $string .= $sorted[$i];
+ if ($subtest_names_hit{$sorted[$i]} > 1) {
+ $string .= "($subtest_names_hit{$sorted[$i]})"
+ }
+ $string .= ",";
+ }
+
+ $string =~ s/,$//;
+
+ $string .= " (Total Subtest Hits: $total_hits / Deduplicated Total Hits:
$deduplicated_hits)";
+
+ return $string;
}
###########################################################################