1 ;;; spam.el --- Identifying spam
2 ;; Copyright (C) 2002, 2003 Free Software Foundation, Inc.
4 ;; Author: Lars Magne Ingebrigtsen <larsi@gnus.org>
7 ;; This file is part of GNU Emacs.
9 ;; GNU Emacs is free software; you can redistribute it and/or modify
10 ;; it under the terms of the GNU General Public License as published by
11 ;; the Free Software Foundation; either version 2, or (at your option)
14 ;; GNU Emacs is distributed in the hope that it will be useful,
15 ;; but WITHOUT ANY WARRANTY; without even the implied warranty of
16 ;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17 ;; GNU General Public License for more details.
19 ;; You should have received a copy of the GNU General Public License
20 ;; along with GNU Emacs; see the file COPYING. If not, write to the
21 ;; Free Software Foundation, Inc., 59 Temple Place - Suite 330,
22 ;; Boston, MA 02111-1307, USA.
26 ;;; This module addresses a few aspects of spam control under Gnus. Page
27 ;;; breaks are used for grouping declarations and documentation relating to
28 ;;; each particular aspect.
30 ;;; The integration with Gnus is not yet complete. See various `FIXME'
31 ;;; comments, below, for supplementary explanations or discussions.
33 ;;; Several TODO items are marked as such
37 (eval-when-compile (require 'cl))
41 (require 'gnus-uu) ; because of key prefix issues
42 (require 'gnus) ; for the definitions of group content classification and spam processors
43 (require 'message) ;for the message-fetch-field functions
45 ;; for nnimap-split-download-body-default
46 (eval-when-compile (require 'nnimap))
48 ;; autoload executable-find
50 ;; executable-find is not autoloaded in Emacs 20
51 (autoload 'executable-find "executable"))
55 (autoload 'query-dig "dig"))
57 ;; autoload spam-report
59 (autoload 'spam-report-gmane "spam-report"))
61 ;; autoload gnus-registry
63 (autoload 'gnus-registry-store-extra-entry "gnus-registry")
64 (autoload 'gnus-registry-fetch-extra "gnus-registry"))
68 (autoload 'query-dns "dns"))
73 "Spam configuration.")
75 (defcustom spam-directory "~/News/spam/"
76 "Directory for spam whitelists and blacklists."
80 (defcustom spam-move-spam-nonspam-groups-only t
81 "Whether spam should be moved in non-spam groups only.
82 When t, only ham and unclassified groups will have their spam moved
83 to the spam-process-destination. When nil, spam will also be moved from
88 (defcustom spam-process-ham-in-nonham-groups nil
89 "Whether ham should be processed in non-ham groups."
93 (defcustom spam-log-to-registry nil
94 "Whether spam/ham processing should be logged in the registry."
98 (defcustom spam-process-ham-in-spam-groups nil
99 "Whether ham should be processed in spam groups."
103 (defcustom spam-mark-only-unseen-as-spam t
104 "Whether only unseen articles should be marked as spam in spam
105 groups. When nil, all unread articles in a spam group are marked as
106 spam. Set this if you want to leave an article unread in a spam group
107 without losing it to the automatic spam-marking process."
111 (defcustom spam-mark-ham-unread-before-move-from-spam-group nil
112 "Whether ham should be marked unread before it's moved out of a spam
113 group according to ham-process-destination. This variable is an
114 official entry in the international Longest Variable Name
119 (defcustom spam-whitelist (expand-file-name "whitelist" spam-directory)
120 "The location of the whitelist.
121 The file format is one regular expression per line.
122 The regular expression is matched against the address."
126 (defcustom spam-blacklist (expand-file-name "blacklist" spam-directory)
127 "The location of the blacklist.
128 The file format is one regular expression per line.
129 The regular expression is matched against the address."
133 (defcustom spam-use-dig t
134 "Whether query-dig should be used instead of query-dns."
138 (defcustom spam-use-blacklist nil
139 "Whether the blacklist should be used by spam-split."
143 (defcustom spam-use-whitelist nil
144 "Whether the whitelist should be used by spam-split."
148 (defcustom spam-use-whitelist-exclusive nil
149 "Whether whitelist-exclusive should be used by spam-split.
150 Exclusive whitelisting means that all messages from senders not in the whitelist
151 are considered spam."
155 (defcustom spam-use-blackholes nil
156 "Whether blackholes should be used by spam-split."
160 (defcustom spam-use-hashcash nil
161 "Whether hashcash payments should be detected by spam-split."
165 (defcustom spam-use-regex-headers nil
166 "Whether a header regular expression match should be used by spam-split.
167 Also see the variables `spam-regex-headers-spam' and `spam-regex-headers-ham'."
171 (defcustom spam-use-regex-body nil
172 "Whether a body regular expression match should be used by spam-split.
173 Also see the variables `spam-regex-body-spam' and `spam-regex-body-ham'."
177 (defcustom spam-use-bogofilter-headers nil
178 "Whether bogofilter headers should be used by spam-split.
179 Enable this if you pre-process messages with Bogofilter BEFORE Gnus sees them."
183 (defcustom spam-use-bogofilter nil
184 "Whether bogofilter should be invoked by spam-split.
185 Enable this if you want Gnus to invoke Bogofilter on new messages."
189 (defcustom spam-use-BBDB nil
190 "Whether BBDB should be used by spam-split."
194 (defcustom spam-use-BBDB-exclusive nil
195 "Whether BBDB-exclusive should be used by spam-split.
196 Exclusive BBDB means that all messages from senders not in the BBDB are
201 (defcustom spam-use-ifile nil
202 "Whether ifile should be used by spam-split."
206 (defcustom spam-use-stat nil
207 "Whether spam-stat should be used by spam-split."
211 (defcustom spam-use-spamoracle nil
212 "Whether spamoracle should be used by spam-split."
216 (defcustom spam-install-hooks (or
220 spam-use-whitelist-exclusive
223 spam-use-regex-headers
225 spam-use-bogofilter-headers
228 spam-use-BBDB-exclusive
232 "Whether the spam hooks should be installed, default to t if one of
233 the spam-use-* variables is set."
237 (defcustom spam-split-group "spam"
238 "Group name where incoming spam should be put by spam-split."
242 ;;; TODO: deprecate this variable, it's confusing since it's a list of strings, not regular expressions
243 (defcustom spam-junk-mailgroups (cons spam-split-group '("mail.junk" "poste.pourriel"))
244 "Mailgroups with spam contents.
245 All unmarked article in such group receive the spam mark on group entry."
246 :type '(repeat (string :tag "Group"))
249 (defcustom spam-blackhole-servers '("bl.spamcop.net" "relays.ordb.org"
250 "dev.null.dk" "relays.visi.com")
251 "List of blackhole servers."
252 :type '(repeat (string :tag "Server"))
255 (defcustom spam-blackhole-good-server-regex nil
256 "String matching IP addresses that should not be checked in the blackholes"
257 :type '(radio (const nil)
258 (regexp :format "%t: %v\n" :size 0))
261 (defcustom spam-face 'gnus-splash-face
262 "Face for spam-marked articles"
266 (defcustom spam-regex-headers-spam '("^X-Spam-Flag: YES")
267 "Regular expression for positive header spam matches"
268 :type '(repeat (regexp :tag "Regular expression to match spam header"))
271 (defcustom spam-regex-headers-ham '("^X-Spam-Flag: NO")
272 "Regular expression for positive header ham matches"
273 :type '(repeat (regexp :tag "Regular expression to match ham header"))
276 (defcustom spam-regex-body-spam '()
277 "Regular expression for positive body spam matches"
278 :type '(repeat (regexp :tag "Regular expression to match spam body"))
281 (defcustom spam-regex-body-ham '()
282 "Regular expression for positive body ham matches"
283 :type '(repeat (regexp :tag "Regular expression to match ham body"))
286 (defgroup spam-ifile nil
287 "Spam ifile configuration."
290 (defcustom spam-ifile-path (executable-find "ifile")
291 "File path of the ifile executable program."
292 :type '(choice (file :tag "Location of ifile")
293 (const :tag "ifile is not installed"))
296 (defcustom spam-ifile-database-path nil
297 "File path of the ifile database."
298 :type '(choice (file :tag "Location of the ifile database")
299 (const :tag "Use the default"))
302 (defcustom spam-ifile-spam-category "spam"
303 "Name of the spam ifile category."
307 (defcustom spam-ifile-ham-category nil
308 "Name of the ham ifile category. If nil, the current group name will
310 :type '(choice (string :tag "Use a fixed category")
311 (const :tag "Use the current group name"))
314 (defcustom spam-ifile-all-categories nil
315 "Whether the ifile check will return all categories, or just spam.
316 Set this to t if you want to use the spam-split invocation of ifile as
317 your main source of newsgroup names."
321 (defgroup spam-bogofilter nil
322 "Spam bogofilter configuration."
325 (defcustom spam-bogofilter-path (executable-find "bogofilter")
326 "File path of the Bogofilter executable program."
327 :type '(choice (file :tag "Location of bogofilter")
328 (const :tag "Bogofilter is not installed"))
329 :group 'spam-bogofilter)
331 (defcustom spam-bogofilter-header "X-Bogosity"
332 "The header that Bogofilter inserts in messages."
334 :group 'spam-bogofilter)
336 (defcustom spam-bogofilter-spam-switch "-s"
337 "The switch that Bogofilter uses to register spam messages."
339 :group 'spam-bogofilter)
341 (defcustom spam-bogofilter-ham-switch "-n"
342 "The switch that Bogofilter uses to register ham messages."
344 :group 'spam-bogofilter)
346 (defcustom spam-bogofilter-bogosity-positive-spam-header "^\\(Yes\\|Spam\\)"
347 "The regex on `spam-bogofilter-header' for positive spam identification."
349 :group 'spam-bogofilter)
351 (defcustom spam-bogofilter-database-directory nil
352 "Directory path of the Bogofilter databases."
353 :type '(choice (directory :tag "Location of the Bogofilter database directory")
354 (const :tag "Use the default"))
357 (defgroup spam-spamoracle nil
358 "Spam ifile configuration."
361 (defcustom spam-spamoracle-database nil
362 "Location of spamoracle database file. When nil, use the default
363 spamoracle database."
364 :type '(choice (directory :tag "Location of spamoracle database file.")
365 (const :tag "Use the default"))
366 :group 'spam-spamoracle)
368 (defcustom spam-spamoracle-binary (executable-find "spamoracle")
369 "Location of the spamoracle binary."
370 :type '(choice (directory :tag "Location of the spamoracle binary")
371 (const :tag "Use the default"))
372 :group 'spam-spamoracle)
374 ;;; Key bindings for spam control.
376 (gnus-define-keys gnus-summary-mode-map
377 "St" spam-bogofilter-score
378 "Sx" gnus-summary-mark-as-spam
379 "Mst" spam-bogofilter-score
380 "Msx" gnus-summary-mark-as-spam
381 "\M-d" gnus-summary-mark-as-spam)
383 ;; convenience functions
384 (defun spam-group-ham-mark-p (group mark &optional spam)
385 (when (stringp group)
386 (let* ((marks (spam-group-ham-marks group spam))
387 (marks (if (symbolp mark)
389 (mapcar 'symbol-value marks))))
392 (defun spam-group-spam-mark-p (group mark)
393 (spam-group-ham-mark-p group mark t))
395 (defun spam-group-ham-marks (group &optional spam)
396 (when (stringp group)
397 (let* ((marks (if spam
398 (gnus-parameter-spam-marks group)
399 (gnus-parameter-ham-marks group)))
401 (marks (if (listp (car marks)) (car marks) marks)))
404 (defun spam-group-spam-marks (group)
405 (spam-group-ham-marks group t))
407 (defun spam-group-spam-contents-p (group)
409 (or (member group spam-junk-mailgroups)
410 (memq 'gnus-group-spam-classification-spam
411 (gnus-parameter-spam-contents group)))
414 (defun spam-group-ham-contents-p (group)
416 (memq 'gnus-group-spam-classification-ham
417 (gnus-parameter-spam-contents group))
420 (defun spam-group-processor-p (group processor)
421 (if (and (stringp group)
423 (member processor (car (gnus-parameter-spam-process group)))
426 (defun spam-group-spam-processor-report-gmane-p (group)
427 (spam-group-processor-p group 'gnus-group-spam-exit-processor-report-gmane))
429 (defun spam-group-spam-processor-bogofilter-p (group)
430 (spam-group-processor-p group 'gnus-group-spam-exit-processor-bogofilter))
432 (defun spam-group-spam-processor-blacklist-p (group)
433 (spam-group-processor-p group 'gnus-group-spam-exit-processor-blacklist))
435 (defun spam-group-spam-processor-ifile-p (group)
436 (spam-group-processor-p group 'gnus-group-spam-exit-processor-ifile))
438 (defun spam-group-ham-processor-ifile-p (group)
439 (spam-group-processor-p group 'gnus-group-ham-exit-processor-ifile))
441 (defun spam-group-spam-processor-spamoracle-p (group)
442 (spam-group-processor-p group 'gnus-group-spam-exit-processor-spamoracle))
444 (defun spam-group-ham-processor-bogofilter-p (group)
445 (spam-group-processor-p group 'gnus-group-ham-exit-processor-bogofilter))
447 (defun spam-group-spam-processor-stat-p (group)
448 (spam-group-processor-p group 'gnus-group-spam-exit-processor-stat))
450 (defun spam-group-ham-processor-stat-p (group)
451 (spam-group-processor-p group 'gnus-group-ham-exit-processor-stat))
453 (defun spam-group-ham-processor-whitelist-p (group)
454 (spam-group-processor-p group 'gnus-group-ham-exit-processor-whitelist))
456 (defun spam-group-ham-processor-BBDB-p (group)
457 (spam-group-processor-p group 'gnus-group-ham-exit-processor-BBDB))
459 (defun spam-group-ham-processor-copy-p (group)
460 (spam-group-processor-p group 'gnus-group-ham-exit-processor-copy))
462 (defun spam-group-ham-processor-spamoracle-p (group)
463 (spam-group-processor-p group 'gnus-group-ham-exit-processor-spamoracle))
465 ;;; Summary entry and exit processing.
467 (defun spam-summary-prepare ()
468 (spam-mark-junk-as-spam-routine))
470 ;; The spam processors are invoked for any group, spam or ham or neither
471 (defun spam-summary-prepare-exit ()
472 (unless gnus-group-is-exiting-without-update-p
473 (gnus-message 6 "Exiting summary buffer and applying spam rules")
474 (when (and spam-bogofilter-path
475 (spam-group-spam-processor-bogofilter-p gnus-newsgroup-name))
476 (gnus-message 5 "Registering spam with bogofilter")
477 (spam-bogofilter-register-spam-routine))
479 (when (and spam-ifile-path
480 (spam-group-spam-processor-ifile-p gnus-newsgroup-name))
481 (gnus-message 5 "Registering spam with ifile")
482 (spam-ifile-register-spam-routine))
484 (when (spam-group-spam-processor-spamoracle-p gnus-newsgroup-name)
485 (gnus-message 5 "Registering spam with spamoracle")
486 (spam-spamoracle-learn-spam))
488 (when (spam-group-spam-processor-stat-p gnus-newsgroup-name)
489 (gnus-message 5 "Registering spam with spam-stat")
490 (spam-stat-register-spam-routine))
492 (when (spam-group-spam-processor-blacklist-p gnus-newsgroup-name)
493 (gnus-message 5 "Registering spam with the blacklist")
494 (spam-blacklist-register-routine))
496 (when (spam-group-spam-processor-report-gmane-p gnus-newsgroup-name)
497 (gnus-message 5 "Registering spam with the Gmane report")
498 (spam-report-gmane-register-routine))
500 (if spam-move-spam-nonspam-groups-only
501 (when (not (spam-group-spam-contents-p gnus-newsgroup-name))
502 (spam-mark-spam-as-expired-and-move-routine
503 (gnus-parameter-spam-process-destination gnus-newsgroup-name)))
504 (gnus-message 5 "Marking spam as expired and moving it to %s" gnus-newsgroup-name)
505 (spam-mark-spam-as-expired-and-move-routine
506 (gnus-parameter-spam-process-destination gnus-newsgroup-name)))
508 ;; now we redo spam-mark-spam-as-expired-and-move-routine to only
509 ;; expire spam, in case the above did not expire them
510 (gnus-message 5 "Marking spam as expired without moving it")
511 (spam-mark-spam-as-expired-and-move-routine nil)
513 (when (or (spam-group-ham-contents-p gnus-newsgroup-name)
514 (and (spam-group-spam-contents-p gnus-newsgroup-name)
515 spam-process-ham-in-spam-groups)
516 spam-process-ham-in-nonham-groups)
517 (when (spam-group-ham-processor-whitelist-p gnus-newsgroup-name)
518 (gnus-message 5 "Registering ham with the whitelist")
519 (spam-whitelist-register-routine))
520 (when (spam-group-ham-processor-ifile-p gnus-newsgroup-name)
521 (gnus-message 5 "Registering ham with ifile")
522 (spam-ifile-register-ham-routine))
523 (when (spam-group-ham-processor-bogofilter-p gnus-newsgroup-name)
524 (gnus-message 5 "Registering ham with Bogofilter")
525 (spam-bogofilter-register-ham-routine))
526 (when (spam-group-ham-processor-stat-p gnus-newsgroup-name)
527 (gnus-message 5 "Registering ham with spam-stat")
528 (spam-stat-register-ham-routine))
529 (when (spam-group-ham-processor-BBDB-p gnus-newsgroup-name)
530 (gnus-message 5 "Registering ham with the BBDB")
531 (spam-BBDB-register-routine))
532 (when (spam-group-ham-processor-spamoracle-p gnus-newsgroup-name)
533 (gnus-message 5 "Registering ham with spamoracle")
534 (spam-spamoracle-learn-ham)))
536 (when (spam-group-ham-processor-copy-p gnus-newsgroup-name)
537 (gnus-message 5 "Copying ham")
538 (spam-ham-copy-routine
539 (gnus-parameter-ham-process-destination gnus-newsgroup-name)))
541 ;; now move all ham articles out of spam groups
542 (when (spam-group-spam-contents-p gnus-newsgroup-name)
543 (gnus-message 5 "Moving ham messages from spam group")
544 (spam-ham-move-routine
545 (gnus-parameter-ham-process-destination gnus-newsgroup-name)))))
547 (defun spam-mark-junk-as-spam-routine ()
548 ;; check the global list of group names spam-junk-mailgroups and the
550 (when (spam-group-spam-contents-p gnus-newsgroup-name)
551 (gnus-message 5 "Marking %s articles as spam"
552 (if spam-mark-only-unseen-as-spam
555 (let ((articles (if spam-mark-only-unseen-as-spam
556 gnus-newsgroup-unseen
557 gnus-newsgroup-unreads)))
558 (dolist (article articles)
559 (gnus-summary-mark-article article gnus-spam-mark)))))
561 (defun spam-mark-spam-as-expired-and-move-routine (&rest groups)
562 (gnus-summary-kill-process-mark)
563 (let ((articles gnus-newsgroup-articles)
564 article tomove deletep)
565 (dolist (article articles)
566 (when (eq (gnus-summary-article-mark article) gnus-spam-mark)
567 (gnus-summary-mark-article article gnus-expirable-mark)
568 (push article tomove)))
570 ;; now do the actual copies
571 (dolist (group groups)
574 (dolist (article tomove)
575 (gnus-summary-set-process-mark article))
577 (if (> (length groups) 1)
579 (gnus-summary-copy-article nil group)
581 (gnus-summary-move-article nil group)))))
583 ;; now delete the articles, if there was a copy done
585 (dolist (article tomove)
586 (gnus-summary-set-process-mark article))
588 (let ((gnus-novice-user nil)) ; don't ask me if I'm sure
589 (gnus-summary-delete-article nil))))
591 (gnus-summary-yank-process-mark)))
593 (defun spam-ham-copy-or-move-routine (copy groups)
594 (gnus-summary-kill-process-mark)
595 (let ((articles gnus-newsgroup-articles)
596 article mark todo deletep)
597 (dolist (article articles)
598 (when (spam-group-ham-mark-p gnus-newsgroup-name
599 (gnus-summary-article-mark article))
600 (push article todo)))
602 ;; now do the actual move
603 (dolist (group groups)
604 (when (and todo (stringp group))
605 (dolist (article todo)
606 (when spam-mark-ham-unread-before-move-from-spam-group
607 (gnus-summary-mark-article article gnus-unread-mark))
608 (gnus-summary-set-process-mark article))
610 (if (> (length groups) 1)
612 (gnus-summary-copy-article nil group)
614 (gnus-summary-move-article nil group))))
616 ;; now delete the articles, unless a) copy is t, and when there was a copy done
617 ;; b) a move was done to a single group
620 (dolist (article todo)
621 (gnus-summary-set-process-mark article))
623 (let ((gnus-novice-user nil)) ; don't ask me if I'm sure
624 (gnus-summary-delete-article nil))))))
626 (gnus-summary-yank-process-mark))
628 (defun spam-ham-copy-routine (&rest groups)
629 (spam-ham-copy-or-move-routine t groups))
631 (defun spam-ham-move-routine (&rest groups)
632 (spam-ham-copy-or-move-routine nil groups))
634 (defun spam-generic-register-routine (spam-func ham-func)
635 (let ((articles gnus-newsgroup-articles)
636 article mark ham-articles spam-articles)
639 (setq article (pop articles)
640 mark (gnus-summary-article-mark article))
641 (cond ((spam-group-spam-mark-p gnus-newsgroup-name mark)
642 (push article spam-articles))
643 ((memq article gnus-newsgroup-saved))
644 ((spam-group-ham-mark-p gnus-newsgroup-name mark)
645 (push article ham-articles))))
647 (when (and ham-articles ham-func)
648 (mapc ham-func ham-articles)) ; we use mapc because unlike
649 ; mapcar it discards the
651 (when (and spam-articles spam-func)
652 (mapc spam-func spam-articles)))) ; we use mapc because unlike
653 ; mapcar it discards the
657 (defalias 'spam-point-at-eol (if (fboundp 'point-at-eol)
659 'line-end-position)))
661 (defun spam-get-article-as-string (article)
662 (let ((article-buffer (spam-get-article-as-buffer article))
665 (save-window-excursion
666 (set-buffer article-buffer)
667 (setq article-string (buffer-string))))
670 (defun spam-get-article-as-buffer (article)
671 (let ((article-buffer))
672 (when (numberp article)
673 (save-window-excursion
674 (gnus-summary-goto-subject article)
675 (gnus-summary-show-article t)
676 (setq article-buffer (get-buffer gnus-article-buffer))))
680 ;; (defun spam-get-article-as-filename (article)
681 ;; (let ((article-filename))
682 ;; (when (numberp article)
683 ;; (nnml-possibly-change-directory (gnus-group-real-name gnus-newsgroup-name))
684 ;; (setq article-filename (expand-file-name (int-to-string article) nnml-current-directory)))
685 ;; (if (file-exists-p article-filename)
689 (defun spam-fetch-field-from-fast (article)
690 "Fetch the `from' field quickly, using the internal gnus-data-list function"
691 (if (and (numberp article)
692 (assoc article (gnus-data-list nil)))
693 (mail-header-from (gnus-data-header (assoc article (gnus-data-list nil))))
696 (defun spam-fetch-field-subject-fast (article)
697 "Fetch the `subject' field quickly, using the internal gnus-data-list function"
698 (if (and (numberp article)
699 (assoc article (gnus-data-list nil)))
700 (mail-header-subject (gnus-data-header (assoc article (gnus-data-list nil))))
703 (defun spam-fetch-field-message-id-fast (article)
704 "Fetch the `subject' field quickly, using the internal gnus-data-list function"
705 (if (and (numberp article)
706 (assoc article (gnus-data-list nil)))
707 (mail-header-message-id (gnus-data-header (assoc article (gnus-data-list nil))))
711 ;;;; Spam determination.
713 (defvar spam-list-of-checks
714 '((spam-use-blacklist . spam-check-blacklist)
715 (spam-use-regex-headers . spam-check-regex-headers)
716 (spam-use-regex-body . spam-check-regex-body)
717 (spam-use-whitelist . spam-check-whitelist)
718 (spam-use-BBDB . spam-check-BBDB)
719 (spam-use-ifile . spam-check-ifile)
720 (spam-use-spamoracle . spam-check-spamoracle)
721 (spam-use-stat . spam-check-stat)
722 (spam-use-blackholes . spam-check-blackholes)
723 (spam-use-hashcash . spam-check-hashcash)
724 (spam-use-bogofilter-headers . spam-check-bogofilter-headers)
725 (spam-use-bogofilter . spam-check-bogofilter))
726 "The spam-list-of-checks list contains pairs associating a parameter
727 variable with a spam checking function. If the parameter variable is
728 true, then the checking function is called, and its value decides what
729 happens. Each individual check may return nil, t, or a mailgroup
730 name. The value nil means that the check does not yield a decision,
731 and so, that further checks are needed. The value t means that the
732 message is definitely not spam, and that further spam checks should be
733 inhibited. Otherwise, a mailgroup name is returned where the mail
734 should go, and further checks are also inhibited. The usual mailgroup
735 name is the value of `spam-split-group', meaning that the message is
738 (defvar spam-list-of-statistical-checks
739 '(spam-use-ifile spam-use-regex-body spam-use-stat spam-use-bogofilter spam-use-spamoracle)
740 "The spam-list-of-statistical-checks list contains all the mail
741 splitters that need to have the full message body available.")
743 ;;;TODO: modify to invoke self with each specific check if invoked without specific checks
744 (defun spam-split (&rest specific-checks)
745 "Split this message into the `spam' group if it is spam.
746 This function can be used as an entry in `nnmail-split-fancy',
747 for example like this: (: spam-split). It can take checks as
748 parameters. A string as a parameter will set the
749 spam-split-group to that string.
751 See the Info node `(gnus)Fancy Mail Splitting' for more details."
753 (let ((spam-split-group-choice spam-split-group))
754 (dolist (check specific-checks)
755 (when (stringp check)
756 (setq spam-split-group-choice check)
757 (setq specific-checks (delq check specific-checks))))
759 (let ((spam-split-group spam-split-group-choice))
762 (dolist (check spam-list-of-statistical-checks)
763 (when (and (symbolp check) (symbol-value check))
765 (gnus-message 8 "spam-split: widening the buffer (%s requires it)"
768 ;; (progn (widen) (debug (buffer-string)))
769 (let ((list-of-checks spam-list-of-checks)
771 (while (and list-of-checks (not decision))
772 (let ((pair (pop list-of-checks)))
773 (when (and (symbol-value (car pair))
774 (or (null specific-checks)
775 (memq (car pair) specific-checks)))
776 (gnus-message 5 "spam-split: calling the %s function"
777 (symbol-name (cdr pair)))
778 (setq decision (funcall (cdr pair))))))
783 ;;; log a ham- or spam-processor invocation to the registry
784 (defun spam-log-processing-to-registry (id type classification check group)
785 (when spam-log-to-registry
786 (if (and (stringp id)
788 (or (eq type 'incoming)
790 (or (eq classification 'spam)
791 (eq classification 'ham))
792 (assoc check spam-list-of-checks))
793 (let ((cell-list (cdr-safe (gnus-registry-fetch-extra id type)))
794 (cell (list classification check group)))
795 (push cell cell-list)
796 (gnus-registry-store-extra-entry
801 (gnus-message 5 (format "%s called with bad ID, type, check, or group"
802 "spam-log-processing-to-registry")))))
804 ;;; check if a ham- or spam-processor registration needs to be undone
805 (defun spam-log-unregistration-needed-p (id type classification check)
806 (when spam-log-to-registry
807 (if (and (stringp id)
808 (or (eq type 'incoming)
810 (or (eq classification 'spam)
811 (eq classification 'ham))
812 (assoc check spam-list-of-checks))
813 (let ((cell-list (cdr-safe (gnus-registry-fetch-extra id type)))
815 (dolist (cell cell-list)
817 (when (and (eq classification (nth 0 cell))
818 (eq check (nth 1 cell)))
822 (gnus-message 5 (format "%s called with bad ID, type, check, or group"
823 "spam-log-unregistration-needed-p"))
826 ;;; set up IMAP widening if it's necessary
827 (defun spam-setup-widening ()
828 (dolist (check spam-list-of-statistical-checks)
829 (when (symbol-value check)
830 (setq nnimap-split-download-body-default t))))
835 (defun spam-check-regex-body ()
836 (let ((spam-regex-headers-ham spam-regex-body-ham)
837 (spam-regex-headers-spam spam-regex-body-spam))
838 (spam-check-regex-headers t)))
843 (defun spam-check-regex-headers (&optional body)
844 (let ((type (if body "body" "header"))
846 (dolist (h-regex spam-regex-headers-ham)
848 (goto-char (point-min))
849 (when (re-search-forward h-regex nil t)
850 (message "Ham regex %s search positive." type)
852 (dolist (s-regex spam-regex-headers-spam)
854 (goto-char (point-min))
855 (when (re-search-forward s-regex nil t)
856 (message "Spam regex %s search positive." type)
858 (setq ret spam-split-group))))
864 (defun spam-reverse-ip-string (ip)
867 (nreverse (split-string ip "\\."))
870 (defun spam-check-blackholes ()
871 "Check the Received headers for blackholed relays."
872 (let ((headers (nnmail-fetch-field "received"))
877 (goto-char (point-min))
878 (gnus-message 5 "Checking headers for relay addresses")
879 (while (re-search-forward
880 "\\([0-9]+\\.[0-9]+\\.[0-9]+\\.[0-9]+\\)" nil t)
881 (gnus-message 9 "Blackhole search found host IP %s." (match-string 1))
882 (push (spam-reverse-ip-string (match-string 1))
884 (dolist (server spam-blackhole-servers)
886 (unless (and spam-blackhole-good-server-regex
887 ;; match the good-server-regex against the reversed (again) IP string
889 spam-blackhole-good-server-regex
890 (spam-reverse-ip-string ip)))
892 (let ((query-string (concat ip "." server)))
894 (let ((query-result (query-dig query-string)))
896 (gnus-message 5 "(DIG): positive blackhole check '%s'"
898 (push (list ip server query-result)
900 ;; else, if not using dig.el
901 (when (query-dns query-string)
902 (gnus-message 5 "positive blackhole check")
903 (push (list ip server (query-dns query-string 'TXT))
914 (defun spam-check-hashcash ()
915 "Check the headers for hashcash payments."
916 (mail-check-payment))) ;mail-check-payment returns a boolean
919 (defalias 'mail-check-payment 'ignore)
920 (defalias 'spam-check-hashcash 'ignore))))
924 ;;; original idea for spam-check-BBDB from Alexander Kotelnikov
925 ;;; <sacha@giotto.sj.ru>
927 ;; all this is done inside a condition-case to trap errors
934 (defun spam-enter-ham-BBDB (from)
935 "Enter an address into the BBDB; implies ham (non-spam) sender"
937 (let* ((parsed-address (gnus-extract-address-components from))
938 (name (or (car parsed-address) "Ham Sender"))
939 (net-address (car (cdr parsed-address))))
940 (gnus-message 5 "Adding address %s to BBDB" from)
941 (when (and net-address
942 (not (bbdb-search-simple nil net-address)))
943 (bbdb-create-internal name nil net-address nil nil
944 "ham sender added by spam.el")))))
946 (defun spam-BBDB-register-routine ()
947 (spam-generic-register-routine
952 (spam-log-processing-to-registry
953 (spam-fetch-field-message-id-fast article)
958 (spam-enter-ham-BBDB (spam-fetch-field-from-fast article)))))
960 (defun spam-check-BBDB ()
961 "Mail from people in the BBDB is classified as ham or non-spam"
962 (let ((who (nnmail-fetch-field "from")))
964 (setq who (cadr (gnus-extract-address-components who)))
965 (if (bbdb-search-simple nil who)
967 (if spam-use-BBDB-exclusive
972 (defalias 'bbdb-search-simple 'ignore)
973 (defalias 'spam-check-BBDB 'ignore)
974 (defalias 'spam-BBDB-register-routine 'ignore)
975 (defalias 'spam-enter-ham-BBDB 'ignore)
976 (defalias 'bbdb-create-internal 'ignore)
977 (defalias 'bbdb-records 'ignore))))
982 ;;; check the ifile backend; return nil if the mail was NOT classified
985 (defun spam-get-ifile-database-parameter ()
986 "Get the command-line parameter for ifile's database from spam-ifile-database-path."
987 (if spam-ifile-database-path
988 (format "--db-file=%s" spam-ifile-database-path)
991 (defun spam-check-ifile ()
992 "Check the ifile backend for the classification of this message"
993 (let ((article-buffer-name (buffer-name))
996 (let ((temp-buffer-name (buffer-name))
997 (db-param (spam-get-ifile-database-parameter)))
999 (set-buffer article-buffer-name)
1001 (call-process-region (point-min) (point-max) spam-ifile-path
1002 nil temp-buffer-name nil "-q" "-c" db-param)
1003 (call-process-region (point-min) (point-max) spam-ifile-path
1004 nil temp-buffer-name nil "-q" "-c")))
1005 (goto-char (point-min))
1007 (setq category (buffer-substring (point) (spam-point-at-eol))))
1008 (when (not (zerop (length category))) ; we need a category here
1009 (if spam-ifile-all-categories
1010 (setq return category)
1011 ;; else, if spam-ifile-all-categories is not set...
1012 (when (string-equal spam-ifile-spam-category category)
1013 (setq return spam-split-group))))))
1016 (defun spam-ifile-register-with-ifile (article-string category)
1017 "Register an article, given as a string, with a category.
1018 Uses `gnus-newsgroup-name' if category is nil (for ham registration)."
1019 (when (stringp article-string)
1020 (let ((category (or category gnus-newsgroup-name))
1021 (db-param (spam-get-ifile-database-parameter)))
1023 (insert article-string)
1025 (call-process-region (point-min) (point-max) spam-ifile-path
1027 "-h" "-i" category db-param)
1028 (call-process-region (point-min) (point-max) spam-ifile-path
1030 "-h" "-i" category))))))
1032 (defun spam-ifile-register-spam-routine ()
1033 (spam-generic-register-routine
1035 (spam-log-processing-to-registry
1036 (spam-fetch-field-message-id-fast article)
1040 gnus-newsgroup-name)
1041 (spam-ifile-register-with-ifile
1042 (spam-get-article-as-string article) spam-ifile-spam-category))
1045 (defun spam-ifile-register-ham-routine ()
1046 (spam-generic-register-routine
1049 (spam-log-processing-to-registry
1050 (spam-fetch-field-message-id-fast article)
1054 gnus-newsgroup-name)
1055 (spam-ifile-register-with-ifile
1056 (spam-get-article-as-string article) spam-ifile-ham-category))))
1063 (let ((spam-stat-install-hooks nil))
1064 (require 'spam-stat))
1066 (defun spam-check-stat ()
1067 "Check the spam-stat backend for the classification of this message"
1068 (let ((spam-stat-split-fancy-spam-group spam-split-group) ; override
1069 (spam-stat-buffer (buffer-name)) ; stat the current buffer
1071 (spam-stat-split-fancy)))
1073 (defun spam-stat-register-spam-routine ()
1074 (spam-generic-register-routine
1076 (spam-log-processing-to-registry
1077 (spam-fetch-field-message-id-fast article)
1081 gnus-newsgroup-name)
1082 (let ((article-string (spam-get-article-as-string article)))
1084 (insert article-string)
1085 (spam-stat-buffer-is-spam))))
1088 (defun spam-stat-register-ham-routine ()
1089 (spam-generic-register-routine
1092 (spam-log-processing-to-registry
1093 (spam-fetch-field-message-id-fast article)
1097 gnus-newsgroup-name)
1098 (let ((article-string (spam-get-article-as-string article)))
1100 (insert article-string)
1101 (spam-stat-buffer-is-non-spam))))))
1103 (defun spam-maybe-spam-stat-load ()
1104 (when spam-use-stat (spam-stat-load)))
1106 (defun spam-maybe-spam-stat-save ()
1107 (when spam-use-stat (spam-stat-save))))
1110 (defalias 'spam-maybe-spam-stat-load 'ignore)
1111 (defalias 'spam-maybe-spam-stat-save 'ignore)
1112 (defalias 'spam-stat-register-ham-routine 'ignore)
1113 (defalias 'spam-stat-register-spam-routine 'ignore)
1114 (defalias 'spam-stat-buffer-is-spam 'ignore)
1115 (defalias 'spam-stat-buffer-is-non-spam 'ignore)
1116 (defalias 'spam-stat-split-fancy 'ignore)
1117 (defalias 'spam-stat-load 'ignore)
1118 (defalias 'spam-stat-save 'ignore)
1119 (defalias 'spam-check-stat 'ignore))))
1123 ;;;; Blacklists and whitelists.
1125 (defvar spam-whitelist-cache nil)
1126 (defvar spam-blacklist-cache nil)
1128 (defun spam-enter-whitelist (address)
1129 "Enter ADDRESS into the whitelist."
1130 (interactive "sAddress: ")
1131 (spam-enter-list address spam-whitelist)
1132 (setq spam-whitelist-cache nil))
1134 (defun spam-enter-blacklist (address)
1135 "Enter ADDRESS into the blacklist."
1136 (interactive "sAddress: ")
1137 (spam-enter-list address spam-blacklist)
1138 (setq spam-blacklist-cache nil))
1140 (defun spam-enter-list (address file)
1141 "Enter ADDRESS into the given FILE, either the whitelist or the blacklist."
1142 (unless (file-exists-p (file-name-directory file))
1143 (make-directory (file-name-directory file) t))
1146 (find-file-noselect file))
1147 (goto-char (point-min))
1148 (unless (re-search-forward (regexp-quote address) nil t)
1149 (goto-char (point-max))
1152 (insert address "\n")
1155 ;;; returns t if the sender is in the whitelist, nil or spam-split-group otherwise
1156 (defun spam-check-whitelist ()
1157 ;; FIXME! Should it detect when file timestamps change?
1158 (unless spam-whitelist-cache
1159 (setq spam-whitelist-cache (spam-parse-list spam-whitelist)))
1160 (if (spam-from-listed-p spam-whitelist-cache)
1162 (if spam-use-whitelist-exclusive
1166 (defun spam-check-blacklist ()
1167 ;; FIXME! Should it detect when file timestamps change?
1168 (unless spam-blacklist-cache
1169 (setq spam-blacklist-cache (spam-parse-list spam-blacklist)))
1170 (and (spam-from-listed-p spam-blacklist-cache) spam-split-group))
1172 (defun spam-parse-list (file)
1173 (when (file-readable-p file)
1174 (let (contents address)
1176 (insert-file-contents file)
1178 (setq address (buffer-substring (point) (spam-point-at-eol)))
1180 ;; insert the e-mail address if detected, otherwise the raw data
1181 (unless (zerop (length address))
1182 (let ((pure-address (cadr (gnus-extract-address-components address))))
1183 (push (or pure-address address) contents)))))
1184 (nreverse contents))))
1186 (defun spam-from-listed-p (cache)
1187 (let ((from (nnmail-fetch-field "from"))
1190 (let ((address (pop cache)))
1191 (unless (zerop (length address)) ; 0 for a nil address too
1192 (setq address (regexp-quote address))
1193 ;; fix regexp-quote's treatment of user-intended regexes
1194 (while (string-match "\\\\\\*" address)
1195 (setq address (replace-match ".*" t t address))))
1196 (when (and address (string-match address from))
1201 (defun spam-blacklist-register-routine ()
1202 (spam-generic-register-routine
1203 ;; the spam function
1205 (spam-log-processing-to-registry
1206 (spam-fetch-field-message-id-fast article)
1210 gnus-newsgroup-name)
1211 (let ((from (spam-fetch-field-from-fast article)))
1212 (when (stringp from)
1213 (spam-enter-blacklist from))))
1217 (defun spam-whitelist-register-routine ()
1218 (spam-generic-register-routine
1219 ;; the spam function
1223 (spam-log-processing-to-registry
1224 (spam-fetch-field-message-id-fast article)
1228 gnus-newsgroup-name)
1229 (let ((from (spam-fetch-field-from-fast article)))
1230 (when (stringp from)
1231 (spam-enter-whitelist from))))))
1234 ;;;; Spam-report glue
1235 (defun spam-report-gmane-register-routine ()
1236 (spam-generic-register-routine
1242 (defun spam-check-bogofilter-headers (&optional score)
1243 (let ((header (nnmail-fetch-field spam-bogofilter-header)))
1244 (when header ; return nil when no header
1245 (if score ; scoring mode
1246 (if (string-match "spamicity=\\([0-9.]+\\)" header)
1247 (match-string 1 header)
1249 ;; spam detection mode
1250 (when (string-match spam-bogofilter-bogosity-positive-spam-header
1252 spam-split-group)))))
1254 ;; return something sensible if the score can't be determined
1255 (defun spam-bogofilter-score ()
1256 "Get the Bogofilter spamicity score"
1258 (save-window-excursion
1259 (gnus-summary-show-article t)
1260 (set-buffer gnus-article-buffer)
1261 (let ((score (or (spam-check-bogofilter-headers t)
1262 (spam-check-bogofilter t))))
1263 (message "Spamicity score %s" score)
1265 (gnus-summary-show-article)))
1267 (defun spam-check-bogofilter (&optional score)
1268 "Check the Bogofilter backend for the classification of this message"
1269 (let ((article-buffer-name (buffer-name))
1272 (let ((temp-buffer-name (buffer-name)))
1274 (set-buffer article-buffer-name)
1275 (if spam-bogofilter-database-directory
1276 (call-process-region (point-min) (point-max)
1277 spam-bogofilter-path
1278 nil temp-buffer-name nil "-v"
1279 "-d" spam-bogofilter-database-directory)
1280 (call-process-region (point-min) (point-max) spam-bogofilter-path
1281 nil temp-buffer-name nil "-v")))
1282 (setq return (spam-check-bogofilter-headers score))))
1285 (defun spam-bogofilter-register-with-bogofilter (article-string spam)
1286 "Register an article, given as a string, as spam or non-spam."
1287 (when (stringp article-string)
1288 (let ((switch (if spam spam-bogofilter-spam-switch
1289 spam-bogofilter-ham-switch)))
1291 (insert article-string)
1292 (if spam-bogofilter-database-directory
1293 (call-process-region (point-min) (point-max)
1294 spam-bogofilter-path
1295 nil nil nil "-v" switch
1296 "-d" spam-bogofilter-database-directory)
1297 (call-process-region (point-min) (point-max) spam-bogofilter-path
1298 nil nil nil "-v" switch))))))
1300 (defun spam-bogofilter-register-spam-routine ()
1301 (spam-generic-register-routine
1303 (spam-log-processing-to-registry
1304 (spam-fetch-field-message-id-fast article)
1307 'spam-use-bogofilter
1308 gnus-newsgroup-name)
1309 (spam-bogofilter-register-with-bogofilter
1310 (spam-get-article-as-string article) t))
1313 (defun spam-bogofilter-register-ham-routine ()
1314 (spam-generic-register-routine
1317 (spam-log-processing-to-registry
1318 (spam-fetch-field-message-id-fast article)
1321 'spam-use-bogofilter
1322 gnus-newsgroup-name)
1323 (spam-bogofilter-register-with-bogofilter
1324 (spam-get-article-as-string article) nil))))
1328 (defun spam-check-spamoracle ()
1329 "Run spamoracle on an article to determine whether it's spam."
1330 (let ((article-buffer-name (buffer-name)))
1332 (let ((temp-buffer-name (buffer-name)))
1334 (set-buffer article-buffer-name)
1336 (apply 'call-process-region
1337 (point-min) (point-max)
1338 spam-spamoracle-binary
1339 nil temp-buffer-name nil
1340 (if spam-spamoracle-database
1341 `("-f" ,spam-spamoracle-database "mark")
1345 (set-buffer temp-buffer-name)
1346 (goto-char (point-min))
1347 (when (re-search-forward "^X-Spam: yes;" nil t)
1349 (error "Error running spamoracle" status))))))))
1351 (defun spam-spamoracle-learn (article article-is-spam-p)
1352 "Run spamoracle in training mode."
1354 (let ((temp-buffer-name (buffer-name)))
1356 (goto-char (point-min))
1357 (insert (spam-get-article-as-string article))
1358 (let* ((arg (if article-is-spam-p "-spam" "-good"))
1360 (apply 'call-process-region
1361 (point-min) (point-max)
1362 spam-spamoracle-binary
1363 nil temp-buffer-name nil
1364 (if spam-spamoracle-database
1365 `("-f" ,spam-spamoracle-database
1368 (when (not (zerop status))
1369 (error "Error running spamoracle" status)))))))
1371 (defun spam-spamoracle-learn-ham ()
1372 (spam-generic-register-routine
1375 (spam-log-processing-to-registry
1376 (spam-fetch-field-message-id-fast article)
1379 'spam-use-spamoracle
1380 gnus-newsgroup-name)
1381 (spam-spamoracle-learn article nil))))
1383 (defun spam-spamoracle-learn-spam ()
1384 (spam-generic-register-routine
1386 (spam-log-processing-to-registry
1387 (spam-fetch-field-message-id-fast article)
1390 'spam-use-spamoracle
1391 gnus-newsgroup-name)
1392 (spam-spamoracle-learn article t))
1398 (defun spam-initialize ()
1399 "Install the spam.el hooks and do other initialization"
1401 (setq spam-install-hooks t)
1402 ;; TODO: How do we redo this every time spam-face is customized?
1403 (push '((eq mark gnus-spam-mark) . spam-face)
1404 gnus-summary-highlight)
1405 ;; Add hooks for loading and saving the spam stats
1407 (add-hook 'gnus-save-newsrc-hook 'spam-maybe-spam-stat-save)
1408 (add-hook 'gnus-get-top-new-news-hook 'spam-maybe-spam-stat-load)
1409 (add-hook 'gnus-startup-hook 'spam-maybe-spam-stat-load))
1410 (add-hook 'gnus-summary-prepare-exit-hook 'spam-summary-prepare-exit)
1411 (add-hook 'gnus-summary-prepare-hook 'spam-summary-prepare)
1412 (add-hook 'gnus-get-new-news-hook 'spam-setup-widening))
1414 (defun spam-unload-hook ()
1415 "Uninstall the spam.el hooks"
1417 (remove-hook 'gnus-save-newsrc-hook 'spam-maybe-spam-stat-save)
1418 (remove-hook 'gnus-get-top-new-news-hook 'spam-maybe-spam-stat-load)
1419 (remove-hook 'gnus-startup-hook 'spam-maybe-spam-stat-load)
1420 (remove-hook 'gnus-summary-prepare-exit-hook 'spam-summary-prepare-exit)
1421 (remove-hook 'gnus-summary-prepare-hook 'spam-summary-prepare)
1422 (remove-hook 'gnus-get-new-news-hook 'spam-setup-widening))
1424 (when spam-install-hooks
1429 ;;; spam.el ends here.