1 ;;; spam.el --- Identifying spam
2 ;; Copyright (C) 2002, 2003 Free Software Foundation, Inc.
4 ;; Author: Lars Magne Ingebrigtsen <larsi@gnus.org>
7 ;; This file is part of GNU Emacs.
9 ;; GNU Emacs is free software; you can redistribute it and/or modify
10 ;; it under the terms of the GNU General Public License as published by
11 ;; the Free Software Foundation; either version 2, or (at your option)
14 ;; GNU Emacs is distributed in the hope that it will be useful,
15 ;; but WITHOUT ANY WARRANTY; without even the implied warranty of
16 ;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17 ;; GNU General Public License for more details.
19 ;; You should have received a copy of the GNU General Public License
20 ;; along with GNU Emacs; see the file COPYING. If not, write to the
21 ;; Free Software Foundation, Inc., 59 Temple Place - Suite 330,
22 ;; Boston, MA 02111-1307, USA.
26 ;;; This module addresses a few aspects of spam control under Gnus. Page
27 ;;; breaks are used for grouping declarations and documentation relating to
28 ;;; each particular aspect.
30 ;;; The integration with Gnus is not yet complete. See various `FIXME'
31 ;;; comments, below, for supplementary explanations or discussions.
33 ;;; Several TODO items are marked as such
37 (eval-when-compile (require 'cl))
41 (require 'gnus-uu) ; because of key prefix issues
42 (require 'gnus) ; for the definitions of group content classification and spam processors
43 (require 'message) ;for the message-fetch-field functions
45 ;; for nnimap-split-download-body-default
46 (eval-when-compile (require 'nnimap))
48 ;; autoload executable-find
50 ;; executable-find is not autoloaded in Emacs 20
51 (autoload 'executable-find "executable"))
55 (autoload 'query-dig "dig"))
57 ;; autoload spam-report
59 (autoload 'spam-report-gmane "spam-report"))
63 (autoload 'query-dns "dns"))
68 "Spam configuration.")
70 (defcustom spam-directory "~/News/spam/"
71 "Directory for spam whitelists and blacklists."
75 (defcustom spam-move-spam-nonspam-groups-only t
76 "Whether spam should be moved in non-spam groups only.
77 When nil, only ham and unclassified groups will have their spam moved
78 to the spam-process-destination. When t, spam will also be moved from
83 (defcustom spam-process-ham-in-nonham-groups nil
84 "Whether ham should be processed in non-ham groups."
88 (defcustom spam-process-ham-in-spam-groups nil
89 "Whether ham should be processed in spam groups."
93 (defcustom spam-mark-only-unseen-as-spam t
94 "Whether only unseen articles should be marked as spam in spam
95 groups. When nil, all unread articles in a spam group are marked as
96 spam. Set this if you want to leave an article unread in a spam group
97 without losing it to the automatic spam-marking process."
101 (defcustom spam-mark-ham-unread-before-move-from-spam-group nil
102 "Whether ham should be marked unread before it's moved out of a spam
103 group according to ham-process-destination. This variable is an
104 official entry in the international Longest Variable Name
109 (defcustom spam-whitelist (expand-file-name "whitelist" spam-directory)
110 "The location of the whitelist.
111 The file format is one regular expression per line.
112 The regular expression is matched against the address."
116 (defcustom spam-blacklist (expand-file-name "blacklist" spam-directory)
117 "The location of the blacklist.
118 The file format is one regular expression per line.
119 The regular expression is matched against the address."
123 (defcustom spam-use-dig t
124 "Whether query-dig should be used instead of query-dns."
128 (defcustom spam-use-blacklist nil
129 "Whether the blacklist should be used by spam-split."
133 (defcustom spam-use-whitelist nil
134 "Whether the whitelist should be used by spam-split."
138 (defcustom spam-use-whitelist-exclusive nil
139 "Whether whitelist-exclusive should be used by spam-split.
140 Exclusive whitelisting means that all messages from senders not in the whitelist
141 are considered spam."
145 (defcustom spam-use-blackholes nil
146 "Whether blackholes should be used by spam-split."
150 (defcustom spam-use-hashcash nil
151 "Whether hashcash payments should be detected by spam-split."
155 (defcustom spam-use-regex-headers nil
156 "Whether a header regular expression match should be used by spam-split.
157 Also see the variables `spam-regex-headers-spam' and `spam-regex-headers-ham'."
161 (defcustom spam-use-regex-body nil
162 "Whether a body regular expression match should be used by spam-split.
163 Also see the variables `spam-regex-body-spam' and `spam-regex-body-ham'."
167 (defcustom spam-use-bogofilter-headers nil
168 "Whether bogofilter headers should be used by spam-split.
169 Enable this if you pre-process messages with Bogofilter BEFORE Gnus sees them."
173 (defcustom spam-use-bogofilter nil
174 "Whether bogofilter should be invoked by spam-split.
175 Enable this if you want Gnus to invoke Bogofilter on new messages."
179 (defcustom spam-use-BBDB nil
180 "Whether BBDB should be used by spam-split."
184 (defcustom spam-use-BBDB-exclusive nil
185 "Whether BBDB-exclusive should be used by spam-split.
186 Exclusive BBDB means that all messages from senders not in the BBDB are
191 (defcustom spam-use-ifile nil
192 "Whether ifile should be used by spam-split."
196 (defcustom spam-use-stat nil
197 "Whether spam-stat should be used by spam-split."
201 (defcustom spam-use-spamoracle nil
202 "Whether spamoracle should be used by spam-split."
206 (defcustom spam-install-hooks (or
210 spam-use-whitelist-exclusive
213 spam-use-regex-headers
215 spam-use-bogofilter-headers
218 spam-use-BBDB-exclusive
222 "Whether the spam hooks should be installed, default to t if one of
223 the spam-use-* variables is set."
224 :group 'gnus-registry
227 (defcustom spam-split-group "spam"
228 "Group name where incoming spam should be put by spam-split."
232 ;;; TODO: deprecate this variable, it's confusing since it's a list of strings, not regular expressions
233 (defcustom spam-junk-mailgroups (cons spam-split-group '("mail.junk" "poste.pourriel"))
234 "Mailgroups with spam contents.
235 All unmarked article in such group receive the spam mark on group entry."
236 :type '(repeat (string :tag "Group"))
239 (defcustom spam-blackhole-servers '("bl.spamcop.net" "relays.ordb.org"
240 "dev.null.dk" "relays.visi.com")
241 "List of blackhole servers."
242 :type '(repeat (string :tag "Server"))
245 (defcustom spam-blackhole-good-server-regex nil
246 "String matching IP addresses that should not be checked in the blackholes"
247 :type '(radio (const nil)
248 (regexp :format "%t: %v\n" :size 0))
251 (defcustom spam-face 'gnus-splash-face
252 "Face for spam-marked articles"
256 (defcustom spam-regex-headers-spam '("^X-Spam-Flag: YES")
257 "Regular expression for positive header spam matches"
258 :type '(repeat (regexp :tag "Regular expression to match spam header"))
261 (defcustom spam-regex-headers-ham '("^X-Spam-Flag: NO")
262 "Regular expression for positive header ham matches"
263 :type '(repeat (regexp :tag "Regular expression to match ham header"))
266 (defcustom spam-regex-body-spam '()
267 "Regular expression for positive body spam matches"
268 :type '(repeat (regexp :tag "Regular expression to match spam body"))
271 (defcustom spam-regex-body-ham '()
272 "Regular expression for positive body ham matches"
273 :type '(repeat (regexp :tag "Regular expression to match ham body"))
276 (defgroup spam-ifile nil
277 "Spam ifile configuration."
280 (defcustom spam-ifile-path (executable-find "ifile")
281 "File path of the ifile executable program."
282 :type '(choice (file :tag "Location of ifile")
283 (const :tag "ifile is not installed"))
286 (defcustom spam-ifile-database-path nil
287 "File path of the ifile database."
288 :type '(choice (file :tag "Location of the ifile database")
289 (const :tag "Use the default"))
292 (defcustom spam-ifile-spam-category "spam"
293 "Name of the spam ifile category."
297 (defcustom spam-ifile-ham-category nil
298 "Name of the ham ifile category. If nil, the current group name will
300 :type '(choice (string :tag "Use a fixed category")
301 (const :tag "Use the current group name"))
304 (defcustom spam-ifile-all-categories nil
305 "Whether the ifile check will return all categories, or just spam.
306 Set this to t if you want to use the spam-split invocation of ifile as
307 your main source of newsgroup names."
311 (defgroup spam-bogofilter nil
312 "Spam bogofilter configuration."
315 (defcustom spam-bogofilter-path (executable-find "bogofilter")
316 "File path of the Bogofilter executable program."
317 :type '(choice (file :tag "Location of bogofilter")
318 (const :tag "Bogofilter is not installed"))
319 :group 'spam-bogofilter)
321 (defcustom spam-bogofilter-header "X-Bogosity"
322 "The header that Bogofilter inserts in messages."
324 :group 'spam-bogofilter)
326 (defcustom spam-bogofilter-spam-switch "-s"
327 "The switch that Bogofilter uses to register spam messages."
329 :group 'spam-bogofilter)
331 (defcustom spam-bogofilter-ham-switch "-n"
332 "The switch that Bogofilter uses to register ham messages."
334 :group 'spam-bogofilter)
336 (defcustom spam-bogofilter-bogosity-positive-spam-header "^\\(Yes\\|Spam\\)"
337 "The regex on `spam-bogofilter-header' for positive spam identification."
339 :group 'spam-bogofilter)
341 (defcustom spam-bogofilter-database-directory nil
342 "Directory path of the Bogofilter databases."
343 :type '(choice (directory :tag "Location of the Bogofilter database directory")
344 (const :tag "Use the default"))
347 (defgroup spam-spamoracle nil
348 "Spam ifile configuration."
351 (defcustom spam-spamoracle-database nil
352 "Location of spamoracle database file. When nil, use the default
353 spamoracle database."
354 :type '(choice (directory :tag "Location of spamoracle database file.")
355 (const :tag "Use the default"))
356 :group 'spam-spamoracle)
358 (defcustom spam-spamoracle-binary (executable-find "spamoracle")
359 "Location of the spamoracle binary."
360 :type '(choice (directory :tag "Location of the spamoracle binary")
361 (const :tag "Use the default"))
362 :group 'spam-spamoracle)
364 ;;; Key bindings for spam control.
366 (gnus-define-keys gnus-summary-mode-map
367 "St" spam-bogofilter-score
368 "Sx" gnus-summary-mark-as-spam
369 "Mst" spam-bogofilter-score
370 "Msx" gnus-summary-mark-as-spam
371 "\M-d" gnus-summary-mark-as-spam)
373 ;; convenience functions
374 (defun spam-group-ham-mark-p (group mark &optional spam)
375 (when (stringp group)
376 (let* ((marks (spam-group-ham-marks group spam))
377 (marks (if (symbolp mark)
379 (mapcar 'symbol-value marks))))
382 (defun spam-group-spam-mark-p (group mark)
383 (spam-group-ham-mark-p group mark t))
385 (defun spam-group-ham-marks (group &optional spam)
386 (when (stringp group)
387 (let* ((marks (if spam
388 (gnus-parameter-spam-marks group)
389 (gnus-parameter-ham-marks group)))
391 (marks (if (listp (car marks)) (car marks) marks)))
394 (defun spam-group-spam-marks (group)
395 (spam-group-ham-marks group t))
397 (defun spam-group-spam-contents-p (group)
399 (or (member group spam-junk-mailgroups)
400 (memq 'gnus-group-spam-classification-spam
401 (gnus-parameter-spam-contents group)))
404 (defun spam-group-ham-contents-p (group)
406 (memq 'gnus-group-spam-classification-ham
407 (gnus-parameter-spam-contents group))
410 (defun spam-group-processor-p (group processor)
411 (if (and (stringp group)
413 (member processor (car (gnus-parameter-spam-process group)))
416 (defun spam-group-spam-processor-report-gmane-p (group)
417 (spam-group-processor-p group 'gnus-group-spam-exit-processor-report-gmane))
419 (defun spam-group-spam-processor-bogofilter-p (group)
420 (spam-group-processor-p group 'gnus-group-spam-exit-processor-bogofilter))
422 (defun spam-group-spam-processor-blacklist-p (group)
423 (spam-group-processor-p group 'gnus-group-spam-exit-processor-blacklist))
425 (defun spam-group-spam-processor-ifile-p (group)
426 (spam-group-processor-p group 'gnus-group-spam-exit-processor-ifile))
428 (defun spam-group-ham-processor-ifile-p (group)
429 (spam-group-processor-p group 'gnus-group-ham-exit-processor-ifile))
431 (defun spam-group-spam-processor-spamoracle-p (group)
432 (spam-group-processor-p group 'gnus-group-spam-exit-processor-spamoracle))
434 (defun spam-group-ham-processor-bogofilter-p (group)
435 (spam-group-processor-p group 'gnus-group-ham-exit-processor-bogofilter))
437 (defun spam-group-spam-processor-stat-p (group)
438 (spam-group-processor-p group 'gnus-group-spam-exit-processor-stat))
440 (defun spam-group-ham-processor-stat-p (group)
441 (spam-group-processor-p group 'gnus-group-ham-exit-processor-stat))
443 (defun spam-group-ham-processor-whitelist-p (group)
444 (spam-group-processor-p group 'gnus-group-ham-exit-processor-whitelist))
446 (defun spam-group-ham-processor-BBDB-p (group)
447 (spam-group-processor-p group 'gnus-group-ham-exit-processor-BBDB))
449 (defun spam-group-ham-processor-copy-p (group)
450 (spam-group-processor-p group 'gnus-group-ham-exit-processor-copy))
452 (defun spam-group-ham-processor-spamoracle-p (group)
453 (spam-group-processor-p group 'gnus-group-ham-exit-processor-spamoracle))
455 ;;; Summary entry and exit processing.
457 (defun spam-summary-prepare ()
458 (spam-mark-junk-as-spam-routine))
460 ;; The spam processors are invoked for any group, spam or ham or neither
461 (defun spam-summary-prepare-exit ()
462 (unless gnus-group-is-exiting-without-update-p
463 (gnus-message 6 "Exiting summary buffer and applying spam rules")
464 (when (and spam-bogofilter-path
465 (spam-group-spam-processor-bogofilter-p gnus-newsgroup-name))
466 (gnus-message 5 "Registering spam with bogofilter")
467 (spam-bogofilter-register-spam-routine))
469 (when (and spam-ifile-path
470 (spam-group-spam-processor-ifile-p gnus-newsgroup-name))
471 (gnus-message 5 "Registering spam with ifile")
472 (spam-ifile-register-spam-routine))
474 (when (spam-group-spam-processor-spamoracle-p gnus-newsgroup-name)
475 (gnus-message 5 "Registering spam with spamoracle")
476 (spam-spamoracle-learn-spam))
478 (when (spam-group-spam-processor-stat-p gnus-newsgroup-name)
479 (gnus-message 5 "Registering spam with spam-stat")
480 (spam-stat-register-spam-routine))
482 (when (spam-group-spam-processor-blacklist-p gnus-newsgroup-name)
483 (gnus-message 5 "Registering spam with the blacklist")
484 (spam-blacklist-register-routine))
486 (when (spam-group-spam-processor-report-gmane-p gnus-newsgroup-name)
487 (gnus-message 5 "Registering spam with the Gmane report")
488 (spam-report-gmane-register-routine))
490 (if spam-move-spam-nonspam-groups-only
491 (when (not (spam-group-spam-contents-p gnus-newsgroup-name))
492 (spam-mark-spam-as-expired-and-move-routine
493 (gnus-parameter-spam-process-destination gnus-newsgroup-name)))
494 (gnus-message 5 "Marking spam as expired and moving it to %s" gnus-newsgroup-name)
495 (spam-mark-spam-as-expired-and-move-routine
496 (gnus-parameter-spam-process-destination gnus-newsgroup-name)))
498 ;; now we redo spam-mark-spam-as-expired-and-move-routine to only
499 ;; expire spam, in case the above did not expire them
500 (gnus-message 5 "Marking spam as expired without moving it")
501 (spam-mark-spam-as-expired-and-move-routine nil)
503 (when (or (spam-group-ham-contents-p gnus-newsgroup-name)
504 (and (spam-group-spam-contents-p gnus-newsgroup-name)
505 spam-process-ham-in-spam-groups)
506 spam-process-ham-in-nonham-groups)
507 (when (spam-group-ham-processor-whitelist-p gnus-newsgroup-name)
508 (gnus-message 5 "Registering ham with the whitelist")
509 (spam-whitelist-register-routine))
510 (when (spam-group-ham-processor-ifile-p gnus-newsgroup-name)
511 (gnus-message 5 "Registering ham with ifile")
512 (spam-ifile-register-ham-routine))
513 (when (spam-group-ham-processor-bogofilter-p gnus-newsgroup-name)
514 (gnus-message 5 "Registering ham with Bogofilter")
515 (spam-bogofilter-register-ham-routine))
516 (when (spam-group-ham-processor-stat-p gnus-newsgroup-name)
517 (gnus-message 5 "Registering ham with spam-stat")
518 (spam-stat-register-ham-routine))
519 (when (spam-group-ham-processor-BBDB-p gnus-newsgroup-name)
520 (gnus-message 5 "Registering ham with the BBDB")
521 (spam-BBDB-register-routine))
522 (when (spam-group-ham-processor-spamoracle-p gnus-newsgroup-name)
523 (gnus-message 5 "Registering ham with spamoracle")
524 (spam-spamoracle-learn-ham)))
526 (when (spam-group-ham-processor-copy-p gnus-newsgroup-name)
527 (gnus-message 5 "Copying ham")
528 (spam-ham-copy-routine
529 (gnus-parameter-ham-process-destination gnus-newsgroup-name)))
531 ;; now move all ham articles out of spam groups
532 (when (spam-group-spam-contents-p gnus-newsgroup-name)
533 (gnus-message 5 "Moving ham messages from spam group")
534 (spam-ham-move-routine
535 (gnus-parameter-ham-process-destination gnus-newsgroup-name)))))
537 (defun spam-mark-junk-as-spam-routine ()
538 ;; check the global list of group names spam-junk-mailgroups and the
540 (when (spam-group-spam-contents-p gnus-newsgroup-name)
541 (gnus-message 5 "Marking %s articles as spam"
542 (if spam-mark-only-unseen-as-spam
545 (let ((articles (if spam-mark-only-unseen-as-spam
546 gnus-newsgroup-unseen
547 gnus-newsgroup-unreads)))
548 (dolist (article articles)
549 (gnus-summary-mark-article article gnus-spam-mark)))))
551 (defun spam-mark-spam-as-expired-and-move-routine (&rest groups)
552 (gnus-summary-kill-process-mark)
553 (let ((articles gnus-newsgroup-articles)
555 (dolist (article articles)
556 (when (eq (gnus-summary-article-mark article) gnus-spam-mark)
557 (gnus-summary-mark-article article gnus-expirable-mark)
558 (push article tomove)))
560 ;; now do the actual copies
561 (dolist (group groups)
564 (dolist (article tomove)
565 (gnus-summary-set-process-mark article))
567 (gnus-summary-copy-article nil group))))
569 ;; now delete the articles
570 (dolist (article tomove)
571 (gnus-summary-set-process-mark article))
573 (gnus-summary-delete-article nil)))
575 (gnus-summary-yank-process-mark))
577 (defun spam-ham-copy-or-move-routine (copy &rest groups)
578 (gnus-summary-kill-process-mark)
579 (let ((articles gnus-newsgroup-articles)
581 (dolist (article articles)
582 (when (spam-group-ham-mark-p gnus-newsgroup-name
583 (gnus-summary-article-mark article))
584 (push article todo)))
586 ;; now do the actual move
587 (dolist (group groups)
589 (dolist (article todo)
590 (when spam-mark-ham-unread-before-move-from-spam-group
591 (gnus-summary-mark-article article gnus-unread-mark))
592 (gnus-summary-set-process-mark article))
593 (gnus-summary-copy-article nil group)))
595 ;; now delete the articles
596 (dolist (article todo)
597 (gnus-summary-set-process-mark article))
599 (gnus-summary-delete-article nil)))
601 (gnus-summary-yank-process-mark))
603 (defun spam-ham-copy-routine (&rest groups)
604 (spam-ham-copy-or-move-routine t groups))
606 (defun spam-ham-move-routine (&rest groups)
607 (spam-ham-copy-or-move-routine nil groups))
609 (defun spam-generic-register-routine (spam-func ham-func)
610 (let ((articles gnus-newsgroup-articles)
611 article mark ham-articles spam-articles)
614 (setq article (pop articles)
615 mark (gnus-summary-article-mark article))
616 (cond ((spam-group-spam-mark-p gnus-newsgroup-name mark)
617 (push article spam-articles))
618 ((memq article gnus-newsgroup-saved))
619 ((spam-group-ham-mark-p gnus-newsgroup-name mark)
620 (push article ham-articles))))
622 (when (and ham-articles ham-func)
623 (mapc ham-func ham-articles)) ; we use mapc because unlike
624 ; mapcar it discards the
626 (when (and spam-articles spam-func)
627 (mapc spam-func spam-articles)))) ; we use mapc because unlike
628 ; mapcar it discards the
632 (defalias 'spam-point-at-eol (if (fboundp 'point-at-eol)
634 'line-end-position)))
636 (defun spam-get-article-as-string (article)
637 (let ((article-buffer (spam-get-article-as-buffer article))
640 (save-window-excursion
641 (set-buffer article-buffer)
642 (setq article-string (buffer-string))))
645 (defun spam-get-article-as-buffer (article)
646 (let ((article-buffer))
647 (when (numberp article)
648 (save-window-excursion
649 (gnus-summary-goto-subject article)
650 (gnus-summary-show-article t)
651 (setq article-buffer (get-buffer gnus-article-buffer))))
655 ;; (defun spam-get-article-as-filename (article)
656 ;; (let ((article-filename))
657 ;; (when (numberp article)
658 ;; (nnml-possibly-change-directory (gnus-group-real-name gnus-newsgroup-name))
659 ;; (setq article-filename (expand-file-name (int-to-string article) nnml-current-directory)))
660 ;; (if (file-exists-p article-filename)
664 (defun spam-fetch-field-from-fast (article)
665 "Fetch the `from' field quickly, using the internal gnus-data-list function"
666 (if (and (numberp article)
667 (assoc article (gnus-data-list nil)))
668 (mail-header-from (gnus-data-header (assoc article (gnus-data-list nil))))
671 (defun spam-fetch-field-subject-fast (article)
672 "Fetch the `subject' field quickly, using the internal gnus-data-list function"
673 (if (and (numberp article)
674 (assoc article (gnus-data-list nil)))
675 (mail-header-subject (gnus-data-header (assoc article (gnus-data-list nil))))
679 ;;;; Spam determination.
681 (defvar spam-list-of-checks
682 '((spam-use-blacklist . spam-check-blacklist)
683 (spam-use-regex-headers . spam-check-regex-headers)
684 (spam-use-regex-body . spam-check-regex-body)
685 (spam-use-whitelist . spam-check-whitelist)
686 (spam-use-BBDB . spam-check-BBDB)
687 (spam-use-ifile . spam-check-ifile)
688 (spam-use-spamoracle . spam-check-spamoracle)
689 (spam-use-stat . spam-check-stat)
690 (spam-use-blackholes . spam-check-blackholes)
691 (spam-use-hashcash . spam-check-hashcash)
692 (spam-use-bogofilter-headers . spam-check-bogofilter-headers)
693 (spam-use-bogofilter . spam-check-bogofilter))
694 "The spam-list-of-checks list contains pairs associating a parameter
695 variable with a spam checking function. If the parameter variable is
696 true, then the checking function is called, and its value decides what
697 happens. Each individual check may return nil, t, or a mailgroup
698 name. The value nil means that the check does not yield a decision,
699 and so, that further checks are needed. The value t means that the
700 message is definitely not spam, and that further spam checks should be
701 inhibited. Otherwise, a mailgroup name is returned where the mail
702 should go, and further checks are also inhibited. The usual mailgroup
703 name is the value of `spam-split-group', meaning that the message is
706 (defvar spam-list-of-statistical-checks
707 '(spam-use-ifile spam-use-regex-body spam-use-stat spam-use-bogofilter spam-use-spamoracle)
708 "The spam-list-of-statistical-checks list contains all the mail
709 splitters that need to have the full message body available.")
711 ;;;TODO: modify to invoke self with each specific check if invoked without specific checks
712 (defun spam-split (&rest specific-checks)
713 "Split this message into the `spam' group if it is spam.
714 This function can be used as an entry in `nnmail-split-fancy', for
715 example like this: (: spam-split). It can take checks as parameters.
717 See the Info node `(gnus)Fancy Mail Splitting' for more details."
721 (dolist (check spam-list-of-statistical-checks)
722 (when (symbol-value check)
724 (gnus-message 8 "spam-split: widening the buffer (%s requires it)"
727 ;; (progn (widen) (debug (buffer-string)))
728 (let ((list-of-checks spam-list-of-checks)
730 (while (and list-of-checks (not decision))
731 (let ((pair (pop list-of-checks)))
732 (when (and (symbol-value (car pair))
733 (or (null specific-checks)
734 (memq (car pair) specific-checks)))
735 (gnus-message 5 "spam-split: calling the %s function" (symbol-name (cdr pair)))
736 (setq decision (funcall (cdr pair))))))
741 (defun spam-setup-widening ()
742 (dolist (check spam-list-of-statistical-checks)
743 (when (symbol-value check)
744 (setq nnimap-split-download-body-default t))))
749 (defun spam-check-regex-body ()
750 (let ((spam-regex-headers-ham spam-regex-body-ham)
751 (spam-regex-headers-spam spam-regex-body-spam))
752 (spam-check-regex-headers t)))
757 (defun spam-check-regex-headers (&optional body)
758 (let ((type (if body "body" "header"))
760 (dolist (h-regex spam-regex-headers-ham)
762 (goto-char (point-min))
763 (when (re-search-forward h-regex nil t)
764 (message "Ham regex %s search positive." type)
766 (dolist (s-regex spam-regex-headers-spam)
768 (goto-char (point-min))
769 (when (re-search-forward s-regex nil t)
770 (message "Spam regex %s search positive." type)
772 (setq ret spam-split-group))))
778 (defun spam-reverse-ip-string (ip)
781 (nreverse (split-string ip "\\."))
784 (defun spam-check-blackholes ()
785 "Check the Received headers for blackholed relays."
786 (let ((headers (nnmail-fetch-field "received"))
791 (goto-char (point-min))
792 (gnus-message 5 "Checking headers for relay addresses")
793 (while (re-search-forward
794 "\\([0-9]+\\.[0-9]+\\.[0-9]+\\.[0-9]+\\)" nil t)
795 (gnus-message 9 "Blackhole search found host IP %s." (match-string 1))
796 (push (spam-reverse-ip-string (match-string 1))
798 (dolist (server spam-blackhole-servers)
800 (unless (and spam-blackhole-good-server-regex
801 ;; match the good-server-regex against the reversed (again) IP string
803 spam-blackhole-good-server-regex
804 (spam-reverse-ip-string ip)))
806 (let ((query-string (concat ip "." server)))
808 (let ((query-result (query-dig query-string)))
810 (gnus-message 5 "(DIG): positive blackhole check '%s'"
812 (push (list ip server query-result)
814 ;; else, if not using dig.el
815 (when (query-dns query-string)
816 (gnus-message 5 "positive blackhole check")
817 (push (list ip server (query-dns query-string 'TXT))
828 (defun spam-check-hashcash ()
829 "Check the headers for hashcash payments."
830 (mail-check-payment))) ;mail-check-payment returns a boolean
833 (defalias 'mail-check-payment 'ignore)
834 (defalias 'spam-check-hashcash 'ignore))))
838 ;;; original idea for spam-check-BBDB from Alexander Kotelnikov
839 ;;; <sacha@giotto.sj.ru>
841 ;; all this is done inside a condition-case to trap errors
848 (defun spam-enter-ham-BBDB (from)
849 "Enter an address into the BBDB; implies ham (non-spam) sender"
851 (let* ((parsed-address (gnus-extract-address-components from))
852 (name (or (car parsed-address) "Ham Sender"))
853 (net-address (car (cdr parsed-address))))
854 (gnus-message 5 "Adding address %s to BBDB" from)
855 (when (and net-address
856 (not (bbdb-search-simple nil net-address)))
857 (bbdb-create-internal name nil net-address nil nil
858 "ham sender added by spam.el")))))
860 (defun spam-BBDB-register-routine ()
861 (spam-generic-register-routine
866 (spam-enter-ham-BBDB (spam-fetch-field-from-fast article)))))
868 (defun spam-check-BBDB ()
869 "Mail from people in the BBDB is classified as ham or non-spam"
870 (let ((who (nnmail-fetch-field "from")))
872 (setq who (cadr (gnus-extract-address-components who)))
873 (if (bbdb-search-simple nil who)
875 (if spam-use-BBDB-exclusive
880 (defalias 'bbdb-search-simple 'ignore)
881 (defalias 'spam-check-BBDB 'ignore)
882 (defalias 'spam-BBDB-register-routine 'ignore)
883 (defalias 'spam-enter-ham-BBDB 'ignore)
884 (defalias 'bbdb-create-internal 'ignore)
885 (defalias 'bbdb-records 'ignore))))
890 ;;; check the ifile backend; return nil if the mail was NOT classified
893 (defun spam-get-ifile-database-parameter ()
894 "Get the command-line parameter for ifile's database from spam-ifile-database-path."
895 (if spam-ifile-database-path
896 (format "--db-file=%s" spam-ifile-database-path)
899 (defun spam-check-ifile ()
900 "Check the ifile backend for the classification of this message"
901 (let ((article-buffer-name (buffer-name))
904 (let ((temp-buffer-name (buffer-name))
905 (db-param (spam-get-ifile-database-parameter)))
907 (set-buffer article-buffer-name)
909 (call-process-region (point-min) (point-max) spam-ifile-path
910 nil temp-buffer-name nil "-q" "-c" db-param)
911 (call-process-region (point-min) (point-max) spam-ifile-path
912 nil temp-buffer-name nil "-q" "-c")))
913 (goto-char (point-min))
915 (setq category (buffer-substring (point) (spam-point-at-eol))))
916 (when (not (zerop (length category))) ; we need a category here
917 (if spam-ifile-all-categories
918 (setq return category)
919 ;; else, if spam-ifile-all-categories is not set...
920 (when (string-equal spam-ifile-spam-category category)
921 (setq return spam-split-group))))))
924 (defun spam-ifile-register-with-ifile (article-string category)
925 "Register an article, given as a string, with a category.
926 Uses `gnus-newsgroup-name' if category is nil (for ham registration)."
927 (when (stringp article-string)
928 (let ((category (or category gnus-newsgroup-name))
929 (db-param (spam-get-ifile-database-parameter)))
931 (insert article-string)
933 (call-process-region (point-min) (point-max) spam-ifile-path
935 "-h" "-i" category db-param)
936 (call-process-region (point-min) (point-max) spam-ifile-path
938 "-h" "-i" category))))))
940 (defun spam-ifile-register-spam-routine ()
941 (spam-generic-register-routine
943 (spam-ifile-register-with-ifile
944 (spam-get-article-as-string article) spam-ifile-spam-category))
947 (defun spam-ifile-register-ham-routine ()
948 (spam-generic-register-routine
951 (spam-ifile-register-with-ifile
952 (spam-get-article-as-string article) spam-ifile-ham-category))))
959 (let ((spam-stat-install-hooks nil))
960 (require 'spam-stat))
962 (defun spam-check-stat ()
963 "Check the spam-stat backend for the classification of this message"
964 (let ((spam-stat-split-fancy-spam-group spam-split-group) ; override
965 (spam-stat-buffer (buffer-name)) ; stat the current buffer
967 (spam-stat-split-fancy)))
969 (defun spam-stat-register-spam-routine ()
970 (spam-generic-register-routine
972 (let ((article-string (spam-get-article-as-string article)))
974 (insert article-string)
975 (spam-stat-buffer-is-spam))))
978 (defun spam-stat-register-ham-routine ()
979 (spam-generic-register-routine
982 (let ((article-string (spam-get-article-as-string article)))
984 (insert article-string)
985 (spam-stat-buffer-is-non-spam))))))
987 (defun spam-maybe-spam-stat-load ()
988 (when spam-use-stat (spam-stat-load)))
990 (defun spam-maybe-spam-stat-save ()
991 (when spam-use-stat (spam-stat-save))))
994 (defalias 'spam-maybe-spam-stat-load 'ignore)
995 (defalias 'spam-maybe-spam-stat-save 'ignore)
996 (defalias 'spam-stat-register-ham-routine 'ignore)
997 (defalias 'spam-stat-register-spam-routine 'ignore)
998 (defalias 'spam-stat-buffer-is-spam 'ignore)
999 (defalias 'spam-stat-buffer-is-non-spam 'ignore)
1000 (defalias 'spam-stat-split-fancy 'ignore)
1001 (defalias 'spam-stat-load 'ignore)
1002 (defalias 'spam-stat-save 'ignore)
1003 (defalias 'spam-check-stat 'ignore))))
1007 ;;;; Blacklists and whitelists.
1009 (defvar spam-whitelist-cache nil)
1010 (defvar spam-blacklist-cache nil)
1012 (defun spam-enter-whitelist (address)
1013 "Enter ADDRESS into the whitelist."
1014 (interactive "sAddress: ")
1015 (spam-enter-list address spam-whitelist)
1016 (setq spam-whitelist-cache nil))
1018 (defun spam-enter-blacklist (address)
1019 "Enter ADDRESS into the blacklist."
1020 (interactive "sAddress: ")
1021 (spam-enter-list address spam-blacklist)
1022 (setq spam-blacklist-cache nil))
1024 (defun spam-enter-list (address file)
1025 "Enter ADDRESS into the given FILE, either the whitelist or the blacklist."
1026 (unless (file-exists-p (file-name-directory file))
1027 (make-directory (file-name-directory file) t))
1030 (find-file-noselect file))
1031 (goto-char (point-min))
1032 (unless (re-search-forward (regexp-quote address) nil t)
1033 (goto-char (point-max))
1036 (insert address "\n")
1039 ;;; returns t if the sender is in the whitelist, nil or spam-split-group otherwise
1040 (defun spam-check-whitelist ()
1041 ;; FIXME! Should it detect when file timestamps change?
1042 (unless spam-whitelist-cache
1043 (setq spam-whitelist-cache (spam-parse-list spam-whitelist)))
1044 (if (spam-from-listed-p spam-whitelist-cache)
1046 (if spam-use-whitelist-exclusive
1050 (defun spam-check-blacklist ()
1051 ;; FIXME! Should it detect when file timestamps change?
1052 (unless spam-blacklist-cache
1053 (setq spam-blacklist-cache (spam-parse-list spam-blacklist)))
1054 (and (spam-from-listed-p spam-blacklist-cache) spam-split-group))
1056 (defun spam-parse-list (file)
1057 (when (file-readable-p file)
1058 (let (contents address)
1060 (insert-file-contents file)
1062 (setq address (buffer-substring (point) (spam-point-at-eol)))
1064 ;; insert the e-mail address if detected, otherwise the raw data
1065 (unless (zerop (length address))
1066 (let ((pure-address (cadr (gnus-extract-address-components address))))
1067 (push (or pure-address address) contents)))))
1068 (nreverse contents))))
1070 (defun spam-from-listed-p (cache)
1071 (let ((from (nnmail-fetch-field "from"))
1074 (let ((address (pop cache)))
1075 (unless (zerop (length address)) ; 0 for a nil address too
1076 (setq address (regexp-quote address))
1077 ;; fix regexp-quote's treatment of user-intended regexes
1078 (while (string-match "\\\\\\*" address)
1079 (setq address (replace-match ".*" t t address))))
1080 (when (and address (string-match address from))
1085 (defun spam-blacklist-register-routine ()
1086 (spam-generic-register-routine
1087 ;; the spam function
1089 (let ((from (spam-fetch-field-from-fast article)))
1090 (when (stringp from)
1091 (spam-enter-blacklist from))))
1095 (defun spam-whitelist-register-routine ()
1096 (spam-generic-register-routine
1097 ;; the spam function
1101 (let ((from (spam-fetch-field-from-fast article)))
1102 (when (stringp from)
1103 (spam-enter-whitelist from))))))
1106 ;;;; Spam-report glue
1107 (defun spam-report-gmane-register-routine ()
1108 (spam-generic-register-routine
1114 (defun spam-check-bogofilter-headers (&optional score)
1115 (let ((header (nnmail-fetch-field spam-bogofilter-header)))
1116 (when header ; return nil when no header
1117 (if score ; scoring mode
1118 (if (string-match "spamicity=\\([0-9.]+\\)" header)
1119 (match-string 1 header)
1121 ;; spam detection mode
1122 (when (string-match spam-bogofilter-bogosity-positive-spam-header
1124 spam-split-group)))))
1126 ;; return something sensible if the score can't be determined
1127 (defun spam-bogofilter-score ()
1128 "Get the Bogofilter spamicity score"
1130 (save-window-excursion
1131 (gnus-summary-show-article t)
1132 (set-buffer gnus-article-buffer)
1133 (let ((score (or (spam-check-bogofilter-headers t)
1134 (spam-check-bogofilter t))))
1135 (message "Spamicity score %s" score)
1137 (gnus-summary-show-article)))
1139 (defun spam-check-bogofilter (&optional score)
1140 "Check the Bogofilter backend for the classification of this message"
1141 (let ((article-buffer-name (buffer-name))
1144 (let ((temp-buffer-name (buffer-name)))
1146 (set-buffer article-buffer-name)
1147 (if spam-bogofilter-database-directory
1148 (call-process-region (point-min) (point-max)
1149 spam-bogofilter-path
1150 nil temp-buffer-name nil "-v"
1151 "-d" spam-bogofilter-database-directory)
1152 (call-process-region (point-min) (point-max) spam-bogofilter-path
1153 nil temp-buffer-name nil "-v")))
1154 (setq return (spam-check-bogofilter-headers score))))
1157 (defun spam-bogofilter-register-with-bogofilter (article-string spam)
1158 "Register an article, given as a string, as spam or non-spam."
1159 (when (stringp article-string)
1160 (let ((switch (if spam spam-bogofilter-spam-switch
1161 spam-bogofilter-ham-switch)))
1163 (insert article-string)
1164 (if spam-bogofilter-database-directory
1165 (call-process-region (point-min) (point-max)
1166 spam-bogofilter-path
1167 nil nil nil "-v" switch
1168 "-d" spam-bogofilter-database-directory)
1169 (call-process-region (point-min) (point-max) spam-bogofilter-path
1170 nil nil nil "-v" switch))))))
1172 (defun spam-bogofilter-register-spam-routine ()
1173 (spam-generic-register-routine
1175 (spam-bogofilter-register-with-bogofilter
1176 (spam-get-article-as-string article) t))
1179 (defun spam-bogofilter-register-ham-routine ()
1180 (spam-generic-register-routine
1183 (spam-bogofilter-register-with-bogofilter
1184 (spam-get-article-as-string article) nil))))
1188 (defun spam-check-spamoracle ()
1189 "Run spamoracle on an article to determine whether it's spam."
1190 (let ((article-buffer-name (buffer-name)))
1192 (let ((temp-buffer-name (buffer-name)))
1194 (set-buffer article-buffer-name)
1196 (apply 'call-process-region
1197 (point-min) (point-max)
1198 spam-spamoracle-binary
1199 nil temp-buffer-name nil
1200 (if spam-spamoracle-database
1201 `("-f" ,spam-spamoracle-database "mark")
1205 (set-buffer temp-buffer-name)
1206 (goto-char (point-min))
1207 (when (re-search-forward "^X-Spam: yes;" nil t)
1209 (error "Error running spamoracle" status))))))))
1211 (defun spam-spamoracle-learn (article article-is-spam-p)
1212 "Run spamoracle in training mode."
1214 (let ((temp-buffer-name (buffer-name)))
1216 (goto-char (point-min))
1217 (insert (spam-get-article-as-string article))
1218 (let* ((arg (if article-is-spam-p "-spam" "-good"))
1220 (apply 'call-process-region
1221 (point-min) (point-max)
1222 spam-spamoracle-binary
1223 nil temp-buffer-name nil
1224 (if spam-spamoracle-database
1225 `("-f" ,spam-spamoracle-database
1228 (when (not (zerop status))
1229 (error "Error running spamoracle" status)))))))
1231 (defun spam-spamoracle-learn-ham ()
1232 (spam-generic-register-routine
1235 (spam-spamoracle-learn article nil))))
1237 (defun spam-spamoracle-learn-spam ()
1238 (spam-generic-register-routine
1240 (spam-spamoracle-learn article t))
1246 (defun spam-initialize ()
1247 "Install the spam.el hooks and do other initialization"
1249 (setq spam-install-hooks t)
1250 ;; TODO: How do we redo this every time spam-face is customized?
1251 (push '((eq mark gnus-spam-mark) . spam-face)
1252 gnus-summary-highlight)
1253 ;; Add hooks for loading and saving the spam stats
1255 (add-hook 'gnus-save-newsrc-hook 'spam-maybe-spam-stat-save)
1256 (add-hook 'gnus-get-top-new-news-hook 'spam-maybe-spam-stat-load)
1257 (add-hook 'gnus-startup-hook 'spam-maybe-spam-stat-load))
1258 (add-hook 'gnus-summary-prepare-exit-hook 'spam-summary-prepare-exit)
1259 (add-hook 'gnus-summary-prepare-hook 'spam-summary-prepare)
1260 (add-hook 'gnus-get-new-news-hook 'spam-setup-widening))
1262 (defun spam-unload-hook ()
1263 "Uninstall the spam.el hooks"
1265 (remove-hook 'gnus-save-newsrc-hook 'spam-maybe-spam-stat-save)
1266 (remove-hook 'gnus-get-top-new-news-hook 'spam-maybe-spam-stat-load)
1267 (remove-hook 'gnus-startup-hook 'spam-maybe-spam-stat-load)
1268 (remove-hook 'gnus-summary-prepare-exit-hook 'spam-summary-prepare-exit)
1269 (remove-hook 'gnus-summary-prepare-hook 'spam-summary-prepare)
1270 (remove-hook 'gnus-get-new-news-hook 'spam-setup-widening))
1272 (when spam-install-hooks
1277 ;;; spam.el ends here.