Re: [patch] extra paranoia using unix domain sockets

2004-10-27 Thread Daniel Quinlan
[EMAIL PROTECTED] (Justin Mason) writes: > BTW we really need to go via bugzilla to discuss this. history > has shown that there are too many issues and patches to deal with > via the lists alone, and they *will* get lost that way. Dean thinks the bugzilla license is onerous: i have a bug to

[Bug 3916] replace RCVD_IN_RFC_IPWHOIS

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3916 [EMAIL PROTECTED] changed: What|Removed |Added Severity|major |minor Summary|deprecate

[Bug 3934] New: allow safe use of spamd on a multiuser machine using UNIX domain sockets and setgid spamc

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3934 Summary: allow safe use of spamd on a multiuser machine using UNIX domain sockets and setgid spamc Product: Spamassassin Version: 3.0.1 Platform: Other OS/Version: other

Re: debug levels in trunk

2004-10-27 Thread Justin Mason
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Daniel Quinlan writes: > was: Re: [Bug 3931] [review] remove the annoying 'inhibited further > callbacks' debug message > > >> (a) new debug code in 3.1.0 doesn't have higher debug levels > > > Really? That kind of sucks (although we never really

[Bug 3934] allow safe use of spamd on a multiuser machine using UNIX domain sockets and setgid spamc

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3934 [EMAIL PROTECTED] changed: What|Removed |Added CC||[EMAIL PROTECTED] --- You

debug levels in trunk

2004-10-27 Thread Daniel Quinlan
was: Re: [Bug 3931] [review] remove the annoying 'inhibited further callbacks' debug message >> (a) new debug code in 3.1.0 doesn't have higher debug levels > Really? That kind of sucks (although we never really used it anyway...) While we have debug levels in trunk ... - dbg()debugg

Re: [patch] extra paranoia using unix domain sockets

2004-10-27 Thread Justin Mason
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ok, opened as http://bugzilla.spamassassin.org/show_bug.cgi?id=3934 BTW we really need to go via bugzilla to discuss this. history has shown that there are too many issues and patches to deal with via the lists alone, and they *will* get lost that wa

[Bug 3933] Add summary of important config options you should set first.

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3933 --- Additional Comments From [EMAIL PROTECTED] 2004-10-27 14:41 --- would make a great Wiki page, and it'd be fine to place a VERY prominent link to that in the POD I think. the POD as it stands is too verbose -- adding more text

[Bug 3933] Add summary of important config options you should set first.

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3933 --- Additional Comments From [EMAIL PROTECTED] 2004-10-27 14:21 --- The information is available in the Mail::SpamAssassin::Conf docs but I feel the problem is due to the size of that file the information does not jump out at you

[Bug 3933] Add summary of important config options you should set first.

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3933 --- Additional Comments From [EMAIL PROTECTED] 2004-10-27 14:20 --- It does but I feel it might slip past the user if it's not included in some way in the distro. You do have the final say over these things, I'm just giving my s

[Bug 3930] URIDNSBL plugin does not honor config option to limit URLs.

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3930 [EMAIL PROTECTED] changed: What|Removed |Added Target Milestone|Future |3.0.2 --- Additional Comment

Re: [patch] extra paranoia using unix domain sockets

2004-10-27 Thread dean gaudet
On Wed, 27 Oct 2004, Justin Mason wrote: > Both will break existing usage at other sites; some thought for backwards > compatibility is required before we could apply those to the distribution. > In particular, defaulting to only allowing -u for root would break > a *lot* of existing users running

[Bug 3931] [review] remove the annoying 'inhibited further callbacks' debug message

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3931 --- Additional Comments From [EMAIL PROTECTED] 2004-10-27 14:16 --- Subject: Re: [review] remove the annoying 'inhibited further callbacks' debug message On Wed, Oct 27, 2004 at 12:56:41PM -0700, [EMAIL PROTECTED] wrote: > (a) n

[Bug 3933] Add summary of important config options you should set first.

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3933 --- Additional Comments From [EMAIL PROTECTED] 2004-10-27 14:14 --- Subject: Re: New: Add summary of important config options you should set first. On Wed, Oct 27, 2004 at 02:12:35PM -0700, [EMAIL PROTECTED] wrote: > I think it w

[Bug 3933] New: Add summary of important config options you should set first.

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3933 Summary: Add summary of important config options you should set first. Product: Spamassassin Version: 3.0.1 Platform: Other OS/Version: All Status: NEW

[Bug 3680] Empty A HREF tag obfuscations

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3680 [EMAIL PROTECTED] changed: What|Removed |Added Status|NEW |RESOLVED Resolution|

[Bug 3924] URIDNSBL plugin crashes with certain messages

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3924 --- Additional Comments From [EMAIL PROTECTED] 2004-10-27 13:49 --- > to demonstrate the peoblem with Net::DNS being involved. That should have been to demonstrate the problem without Net::DNS being involved. --- You are

Help with bug 3917

2004-10-27 Thread Sidney Markowitz
Fred, I noticed you mentioned in a bug comment about getting some information using Ethereal. If you are also running Cygwin, could you help a bit with bug #3917? I'm stuck because of some firewall issues that I have not yet tracked down on the home machine where I can test. What I'm trying to

[Bug 3924] URIDNSBL plugin crashes with certain messages

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3924 --- Additional Comments From [EMAIL PROTECTED] 2004-10-27 13:30 --- > Should I move this into a security ticket If you do, you and I won't get to see it :-( [Insert rant about security measures that make security more difficult].

[Bug 3931] [review] remove the annoying 'inhibited further callbacks' debug message

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3931 --- Additional Comments From [EMAIL PROTECTED] 2004-10-27 13:09 --- Subject: Re: [review] remove the annoying 'inhibited further callbacks' debug message +1 to remove --- You are receiving this mail because: --- You

[Bug 3931] [review] remove the annoying 'inhibited further callbacks' debug message

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3931 --- Additional Comments From [EMAIL PROTECTED] 2004-10-27 12:56 --- (a) new debug code in 3.1.0 doesn't have higher debug levels (b) I don't think anyone really needs to know this at all. I wrote it, and it's never been a useful

Re: [patch] extra paranoia using unix domain sockets

2004-10-27 Thread Justin Mason
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 dean gaudet writes: > i wasn't ever fond of spamd trusting the User supplied by spamc -- and > while identd is an OK hack for folks who run spamd on a network, it seems > overkill for someone running spamd on localhost only. using unix domain > so

[Bug 3925] Remove akamai.com from dns startup test.

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3925 --- Additional Comments From [EMAIL PROTECTED] 2004-10-27 12:39 --- I agree it's a win32 issue and no kludges and no need to switch to a different domain but let's return back to my comment #6 where I noticed it might be doing so

[Bug 3931] [review] remove the annoying 'inhibited further callbacks' debug message

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3931 --- Additional Comments From [EMAIL PROTECTED] 2004-10-27 12:18 --- instead of disabling it, why not just make it require a higher debug level? --- You are receiving this mail because: --- You are the assignee for the bu

[Bug 3924] URIDNSBL plugin crashes with certain messages

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3924 --- Additional Comments From [EMAIL PROTECTED] 2004-10-27 12:17 --- I already did this Justin, (great minds think alike) I found the point where it crashes. Should I move this into a security ticket, this is a potential DOS on SA

[patch] extra paranoia using unix domain sockets

2004-10-27 Thread dean gaudet
i wasn't ever fond of spamd trusting the User supplied by spamc -- and while identd is an OK hack for folks who run spamd on a network, it seems overkill for someone running spamd on localhost only. using unix domain sockets there are two ways to increase the paranoia -- one would be to pass c

[Bug 3924] URIDNSBL plugin crashes with certain messages

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3924 --- Additional Comments From [EMAIL PROTECTED] 2004-10-27 12:12 --- Subject: Re: URIDNSBL plugin crashes with certain messages On Wed, Oct 27, 2004 at 11:46:38AM -0700, [EMAIL PROTECTED] wrote: > Done it's bug 3930 Theo, what di

[Bug 3924] URIDNSBL plugin crashes with certain messages

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3924 --- Additional Comments From [EMAIL PROTECTED] 2004-10-27 12:00 --- I suspect we may be the first people to hit Net::DNS on the win32 platform with this load level. a standalone test case using a static set of domains and Net::DNS

[Bug 3931] [review] remove the annoying 'inhibited further callbacks' debug message

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3931 [EMAIL PROTECTED] changed: What|Removed |Added Target Milestone|Future |3.0.2 --- You are receivin

[Bug 3931] [review] remove the annoying 'inhibited further callbacks' debug message

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3931 --- Additional Comments From [EMAIL PROTECTED] 2004-10-27 11:58 --- Created an attachment (id=2491) --> (http://bugzilla.spamassassin.org/attachment.cgi?id=2491&action=view) fix just comments the debug line. pls vote for 3.0.2,

[Bug 3931] New: [review] remove the annoying 'inhibited further callbacks' debug message

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3931 Summary: [review] remove the annoying 'inhibited further callbacks' debug message Product: Spamassassin Version: 3.0.1 Platform: Other OS/Version: other Status:

Re: svn commit: rev 55716 - spamassassin/trunk/lib/Mail/SpamAssassin/Plugin

2004-10-27 Thread Justin Mason
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Theo Van Dinter writes: > Errr. The code already does that in the new() area: > > $mailsaobject->{conf}->{razor2_timeout} = 10; > > On Wed, Oct 27, 2004 at 04:51:38PM -, [EMAIL PROTECTED] wrote: > > - my $timeout=$self->{main}->{conf}->{razo

[Bug 3924] URIDNSBL plugin crashes with certain messages

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3924 --- Additional Comments From [EMAIL PROTECTED] 2004-10-27 11:46 --- Done it's bug 3930 Theo, what did you mean in comment #9? I had a feeling this might have something to do with it. --- You are receiving this mail becaus

[Bug 3930] New: URIDNSBL plugin does not honor config option to limit URLs.

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3930 Summary: URIDNSBL plugin does not honor config option to limit URLs. Product: Spamassassin Version: 3.0.1 Platform: Other OS/Version: other Status: NEW

[Bug 3924] URIDNSBL plugin crashes with certain messages

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3924 --- Additional Comments From [EMAIL PROTECTED] 2004-10-27 11:41 --- Subject: Re: URIDNSBL plugin crashes with certain messages On Wed, Oct 27, 2004 at 11:40:57AM -0700, [EMAIL PROTECTED] wrote: > Ok, I verified using ethereal tha

[Bug 3924] URIDNSBL plugin crashes with certain messages

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3924 --- Additional Comments From [EMAIL PROTECTED] 2004-10-27 11:40 --- Ok, I verified using ethereal that surbl is not using the default value of 20 to limit the number of lookups performed. If this was fixed, it might fix the prob

[Bug 3924] URIDNSBL plugin crashes with certain messages

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3924 --- Additional Comments From [EMAIL PROTECTED] 2004-10-27 11:23 --- Subject: Re: URIDNSBL plugin crashes with certain messages On Wed, Oct 27, 2004 at 11:12:25AM -0700, [EMAIL PROTECTED] wrote: > P.S. URIDNSBL does have a defaul

Re: svn commit: rev 55716 - spamassassin/trunk/lib/Mail/SpamAssassin/Plugin

2004-10-27 Thread Theo Van Dinter
Errr. The code already does that in the new() area: $mailsaobject->{conf}->{razor2_timeout} = 10; On Wed, Oct 27, 2004 at 04:51:38PM -, [EMAIL PROTECTED] wrote: > - my $timeout=$self->{main}->{conf}->{razor_timeout}; > + my $timeout=$self->{main}->{conf}->{razor_timeout} || 10; So the c

[Bug 3924] URIDNSBL plugin crashes with certain messages

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3924 --- Additional Comments From [EMAIL PROTECTED] 2004-10-27 11:12 --- I hacked my way around and found the same thing you did. If I can be of assistance to help your testing I am here for another 5 hours plus I can work on this fr

[Bug 3924] URIDNSBL plugin crashes with certain messages

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3924 --- Additional Comments From [EMAIL PROTECTED] 2004-10-27 10:45 --- I've done some more tests, but haven't nailed this yet. I determined that it is not a matter of running out of file handles (descriptors). It does feel like some b

[Bug 3922] [review] "make test" failure for dnsbl on Solaris

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3922 [EMAIL PROTECTED] changed: What|Removed |Added Status|RESOLVED|REOPENED Resolution|FIXED

[Bug 3899] "Insecure dependency" error from SA3

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3899 [EMAIL PROTECTED] changed: What|Removed |Added Version|3.0.0 |3.0.1 --- Additional Comment

[Bug 3922] [review] "make test" failure for dnsbl on Solaris

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3922 [EMAIL PROTECTED] changed: What|Removed |Added Status|NEW |RESOLVED Resolution|

[Bug 3826] [review] spamd keeps user_prefs between scans with different users

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3826 --- Additional Comments From [EMAIL PROTECTED] 2004-10-27 05:07 --- Subject: Re: [review] spamd keeps user_prefs between scans with different users > > synopsis: config leak across spamd child sessions > version: 3.0.1 > > one

[Bug 3826] [review] spamd keeps user_prefs between scans with different users

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3826 [EMAIL PROTECTED] changed: What|Removed |Added Status|RESOLVED|REOPENED Resolution|FIXED

[patch] increase paranoia when --max-conn-per-child=1

2004-10-27 Thread dean gaudet
when --max-conn-per-child=1 spamd children should drop root completely as early as possible. actually i'd also suggest that when $setuid_to_user you default $clients_per_child to 1 rather than 200 ... the extra paranoia is worth more than the possibility of perf gain for most folks. sorry -- i

[Bug 2754] FROM_OTHERS rule causes FP

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=2754 --- Additional Comments From [EMAIL PROTECTED] 2004-10-26 21:38 --- It remains a good spam rule here. With the lower score in 3.0.x, I think we're OK. I'm on the road and so cannot do a full mass-check at this time, but a quick

[Bug 3841] Crashes when run multithreaded

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3841 [EMAIL PROTECTED] changed: What|Removed |Added Status|NEW |RESOLVED Resolution|

[Bug 3924] URIDNSBL plugin crashes with certain messages

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3924 --- Additional Comments From [EMAIL PROTECTED] 2004-10-26 18:39 --- At the time of the crash the handle count is 1,112 Memory usage is only 28,500k so that looks good. These numbers are exactly the same for multiple runs so it look

[Bug 2754] FROM_OTHERS rule causes FP

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=2754 --- Additional Comments From [EMAIL PROTECTED] 2004-10-26 18:29 --- we could even drop it at this stage. 0.105 0.1571 0.00350.978 0.561.82 FROM_OFFERS --- You are receiving this mail because: --- You a

[Bug 3806] [review] Sys::Hostname::Long renames host to --fqdn when run as root

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3806 --- Additional Comments From [EMAIL PROTECTED] 2004-10-26 18:23 --- I don't think that the check against HAS_NET_DNS has anything to do with blaming NET::DNS for the problem. I expect that it is there because you can not run the t

[Bug 2618] OPT_IN_CAPS false positive

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=2618 [EMAIL PROTECTED] changed: What|Removed |Added Status|NEW |RESOLVED Resolution|

[Bug 2618] OPT_IN_CAPS false positive

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=2618 [EMAIL PROTECTED] changed: What|Removed |Added CC||dev@spamassassin.apache.org

[Bug 2754] FROM_OTHERS rule causes FP

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=2754 --- Additional Comments From [EMAIL PROTECTED] 2004-10-26 18:02 --- The score is now lower... do we still want to change this rule? score FROM_OFFERS 1.822 0.861 2.243 1.491 --- You are receiving this mail because: ---

[Bug 2926] __FROM_PHONE should check for a leading 1

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=2926 [EMAIL PROTECTED] changed: What|Removed |Added Status|NEW |RESOLVED Resolution|

[Bug 3924] URIDNSBL plugin crashes with certain messages

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3924 --- Additional Comments From [EMAIL PROTECTED] 2004-10-26 17:54 --- Another thing for Fred or anyone else who can to check before I can: In Task Manager, select the Processes tab, then View | Select Columns menu and click the chec

[Bug 2926] __FROM_PHONE should check for a leading 1

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=2926 [EMAIL PROTECTED] changed: What|Removed |Added CC||dev@spamassassin.apache.org

[Bug 3929] Consider email aliases to find user for storing prefs and bayes data

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3929 --- Additional Comments From [EMAIL PROTECTED] 2004-10-26 17:46 --- Created an attachment (id=2490) --> (http://bugzilla.spamassassin.org/attachment.cgi?id=2490&action=view) Proposed patch to spamd 3.0.1 --- You are receiv

[Bug 3929] New: Consider email aliases to find user for storing prefs and bayes data

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3929 Summary: Consider email aliases to find user for storing prefs and bayes data Product: Spamassassin Version: 3.0.1 Platform: Other OS/Version: Linux Status: NEW

[Bug 3928] False Positive with MSGID_DOLLARS

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3928 [EMAIL PROTECTED] changed: What|Removed |Added Status|NEW |RESOLVED Resolution|

[Bug 3928] False Positive with MSGID_DOLLARS

2004-10-27 Thread bugzilla-daemon
http://bugzilla.spamassassin.org/show_bug.cgi?id=3928 --- Additional Comments From [EMAIL PROTECTED] 2004-10-26 17:12 --- Created an attachment (id=2489) --> (http://bugzilla.spamassassin.org/attachment.cgi?id=2489&action=view) MSGID_DOLLARS false positive --- You are receiv