NAME

Mail::SpamAssassin::Handler::Archive - A MIME-part handler for archive files

SYNOPSIS

loadhandler  Mail::SpamAssassin::Handler::Archive

DESCRIPTION

A MIME-part handler that opens zip and rar archive attachments, extracts a bounded number of the files inside, and returns each as a child part. The handler framework then re-dispatches every extracted file by its effective_type (filename extension first), so an inner.js reaches the JavaScript handler, an inner.html reaches the HTML handler, an inner.pdf the PDF handler, an image the image handler, and a nested archive comes back to this handler -- all bounded by the framework's depth, part-count and byte budgets.

The handler is intentionally thin: its main job is to make the archive's contents visible to the other handlers and to ordinary body rules. It also provides one eval rule, check_archive_file_count, for matching on the number of files an archive declares (see "EVAL RULES").

REQUIREMENTS

zip

Extraction uses IO::Uncompress::Unzip, which is part of the core Perl distribution. It is loaded lazily; if it is somehow unavailable the handler still loads (with a warning at startup) and simply skips zip archives.

rar

Extraction shells out to the unrar executable. Set archive_unrar_path if it is not on the PATH. If it cannot be found, rar extraction is disabled with a debug message, so --lint never fails merely because the binary is absent.

CONFIGURATION

archive_max_files N (default: 2)

Extract at most N files from each archive. Bounds the work done downstream and is a countermeasure against archives that pack a very large number of entries.

archive_unrar_path /path/to/unrar

Full path to the unrar executable. If unset, the handler looks for unrar on the PATH.

EVAL RULES

check_archive_file_count(min[, max])

Fires when any archive in the message declares an entry count of at least min (and, if max is given and non-zero, at most max). The count is the archive's full declared total -- read from the zip End Of Central Directory record, or from unrar's member listing -- and is therefore independent of archive_max_files: an archive that packs thousands of files but from which only four are extracted still reports its true size. Useful for flagging archives that pack an implausible number of entries.

body  ARC_MANY_FILES   eval:check_archive_file_count(100)
body  ARC_FILES_RANGE  eval:check_archive_file_count(2,10)