From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4ht3Nv4X0Cz2yqB for ; Sun, 27 Sep 2026 12:17:51 +0000 (UTC) Received: from mail01.ipfire.org (mail01.haj.ipfire.org [IPv6:2001:678:b28::25]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4ht3Nr229vz2xJ1 for ; Sun, 27 Sep 2026 12:17:48 +0000 (UTC) Received: from out.smtpout.orange.fr (out-69.smtpout.orange.fr [193.252.22.69]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "*.smtpout.orange.fr", Issuer "DigiCert Global G2 TLS RSA SHA256 2020 CA1" (verified OK)) by mail01.ipfire.org (Postfix) with ESMTPS id 4ht3Nn67xqz7Y for ; Sun, 27 Sep 2026 12:17:45 +0000 (UTC) Authentication-Results: mail01.ipfire.org; dkim=pass header.d=orange.fr header.s=t20230301 header.b=Z2HE7l0y; spf=pass (mail01.ipfire.org: domain of p27m@orange.fr designates 193.252.22.69 as permitted sender) smtp.mailfrom=p27m@orange.fr; dmarc=pass (policy=quarantine) header.from=orange.fr ARC-Seal: i=1; a=rsa-sha256; d=lists.ipfire.org; s=202003rsa; cv=none; t=1790511466; b=C83K4aJ1EnVS9UPEtS6nS6Yuxq85RCZgdrNoLHHHoLtEN62akLM/TjMYSbr5wNG82H5cEw WNj3Qg+Q78klHep0IHNG0BkE9R3H8Z9dACpOF0A8qOeKyJKIy+OmYClJrwdwwbkZ3WkuLP l00Kuuo5kvCFTnVCQE0qWlGPSqZ6SnyaLuMMXss1qaQVrmIG42vm7IkdJC5Zoxak8j8bMP aCPkhXwz1KJfJW8tzZ09sOrt8B6KmbeKJEa/GoOnrTNK9mPhqE4iAeLpoJWMMDBazNoGQ4 UxOsKBEymCX1rEbr/5F0fXqqRmTQCmTmKeFBhwRyjC1fEVtH04+OPpmeDjeY0A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=lists.ipfire.org; s=202003rsa; t=1790511466; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=M+FxpDqYsjX+es6hqRE7EPt+3ESXzyzJ0+XbU6rFT80=; b=AW20w1V5w0yJuQdwPCvr0EqskCKWFv52JChCTdEYDD640ewGfnmNuQGb+23HivabRlwi7O 70DEnGiTn+hiEveGl49ezLbsTr7gcvbhOytfPmb1oiHJbXyK2OU+MGY9y8CIKbafFHVVvT 03kaW23wOxr/DTugnqq7wvNSG7TaFyh64fCuhWVLsLhKbW+u+q7uoJCvzbPZHQk1tZ9Uci uI/YnlksynrIQYkCS8j9+ZRza0puo63M7DvUjU6JUaBChPxK7Ea6Ea3Stqg0Mm/n+WE6fA dLHoR1FaWfX7uc8PBz6Nt+sgk+BqvvAIk6ghaEva+Ru1R1B5E3hOx0oFj6tMxQ== ARC-Authentication-Results: i=1; mail01.ipfire.org; dkim=pass header.d=orange.fr header.s=t20230301 header.b=Z2HE7l0y; spf=pass (mail01.ipfire.org: domain of p27m@orange.fr designates 193.252.22.69 as permitted sender) smtp.mailfrom=p27m@orange.fr; dmarc=pass (policy=quarantine) header.from=orange.fr Received: from [192.168.20.32] ([176.146.212.228]) by smtp.orange.fr with ESMTPSA id AnpAxSxCfvDa9AnpAxFASf; Sun, 27 Sep 2026 14:17:45 +0200 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=orange.fr; s=t20230301; t=1790511465; bh=M+FxpDqYsjX+es6hqRE7EPt+3ESXzyzJ0+XbU6rFT80=; h=Message-ID:Date:MIME-Version:Subject:To:From; b=Z2HE7l0ytT/AksOn/r1g1e1QAjyxUDQqPPLhQpQ8Nt0XeSVS8IbmynWrE0RtLmIC7 09NPrjpyNxkL6JlV3Q7hXFapRooU8z/JH8QGMd4uL+cmvpCslDfxOzEy0R6YPJd1Rx 8/v1lI6b2TwcuKQ/RJiHo/sMxdhRJlMwtlGwMv+WlgUYC8DGjVwncg7wG3aO5MO2vT 947Ze8ynNQIC9uKp3kW/go5DmGsIYTXeGFyEHk27EGOiHUZ27AnABznwx9KlwlA/a9 DJwibOrloWJjzSsN4m0o/Pmw6ZBLZDwFR/1bgeED0Ty62wcrC6Os8bKeNm84U5i/us GrnSzH2uPyFAA== X-ME-Helo: [192.168.20.32] X-ME-Auth: cDI3bUBvcmFuZ2UuZnI= X-ME-Date: Sun, 27 Sep 2026 14:17:45 +0200 X-ME-IP: 176.146.212.228 Message-ID: Date: Sun, 27 Sep 2026 14:17:45 +0200 Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] urlfilter: Remove bundled Toulouse blacklist To: development@lists.ipfire.org References: <20260827091639.4064898-1-p27m@orange.fr> <217EBED3-D400-4695-A345-816C7DD47207@ipfire.org> <6C039B7E-2BAF-45B7-9C87-A7D008EF3443@ipfire.org> Content-Language: fr, en-US From: p27m In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit X-Rspamd-Action: no action X-Spamd-Result: default: False [-5.90 / 11.00]; NEURAL_HAM(-3.00)[-1.000]; BAYES_HAM(-3.00)[100.00%]; HFILTER_HELO_IP_A(1.00)[out.smtpout.orange.fr]; DMARC_POLICY_ALLOW(-0.50)[orange.fr,quarantine]; R_SPF_ALLOW(-0.20)[+ip4:193.252.22.0/25]; ONCE_RECEIVED(0.20)[]; R_DKIM_ALIGNED(-0.10)[strict]; MX_GOOD(-0.10)[smtp-in.orange.fr]; MIME_GOOD(-0.10)[text/plain]; R_DKIM_ALLOW(-0.10)[orange.fr:s=t20230301]; TO_MATCH_ENVRCPT_ALL(0.00)[]; FROM_HAS_DN(0.00)[]; RCPT_COUNT_ONE(0.00)[1]; MIME_TRACE(0.00)[0:+]; ARC_SIGNED(0.00)[lists.ipfire.org:s=202003rsa:i=1]; ARC_NA(0.00)[]; FREEMAIL_ENVFROM(0.00)[orange.fr]; FREEMAIL_FROM(0.00)[orange.fr]; DKIM_TRACE(0.00)[orange.fr:+]; IP_REPUTATION_SPAM(0.00)[asn: 3215(0.00), country: FR(0.00), ip: 193.252.22.69(0.00)]; RCVD_IN_DNSWL_NONE(0.00)[193.252.22.69:from]; RECEIVED_SPAMHAUS_PBL(0.00)[176.146.212.228:received]; TO_DN_NONE(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; RCVD_TLS_ALL(0.00)[]; MID_RHS_MATCH_FROM(0.00)[]; ASN(0.00)[asn:3215, ipnet:193.252.20.0/22, country:FR]; RCVD_VIA_SMTP_AUTH(0.00)[]; DKIM_REPUTATION(0.00)[0]; RCVD_COUNT_ONE(0.00)[1]; DWL_DNSWL_NONE(0.00)[orange.fr:dkim] X-Rspamd-Queue-Id: 4ht3Nn67xqz7Y X-Rspamd-Server: mail01.haj.ipfire.org Hi Adolf, Thank you for following up on this. The |blacklists.tar.gz| Toulouse blocklist currently present in the IPFire repository dates back to 2015 and is one of the remaining parts inherited from the old IPCop URL Filter add-on. It is not part of the SquidGuard package itself. Replacing |blacklists.tar.gz| with a newer version would indeed be a viable solution to the current problem with directories being replaced by symlinks. It should work without any code changes. However, this would only be a workaround for the underlying problem. There is no guarantee that the structure of the Toulouse blocklist will not change again in the future, in which case the same problem could reappear. I also wonder whether it makes sense to continue installing a blocklist which may become obsolete again relatively quickly, or potentially disappear altogether. There is already a blocklist maintained by IPFire at: https://dbl.ipfire.org/lists/squidguard.tar.gz It might therefore make more sense to use this list as the bundled default instead. However, this would not address the problem when restoring a backup containing a Toulouse blocklist that was previously in use by the user. The restore process could still encounter the same directory/symlink conflict. The solution I proposed is intended to address both aspects: removing the obsolete bundled Toulouse list and making the restore process safe in case an older Toulouse list is present in a backup. That said, you are the experts on the IPFire codebase and its long-term maintenance, so I will of course leave the final choice to you. Regards, Philippe Le 27/09/2026 à 12:44, Adolf Belka a écrit : > Hi All, > > I am following up on this as it has not had any follow-up for a while.. > > If there is a concern on the potential impact of not having any > bundled Toulouse blocklist in the URL Filter, an alternative would be > to have a newer version of the Toulouse Blocklist that includes the > symlinks approach that Toulouse started using earlier this year. > > Would that be a viable approach? That would then keep the current > default status of having a blocklist defined but using one that has > the symlinks and therefore does not end up with the problem of trying > to create a symlink with the same name as an existing file. > > Regards, > > Adolf.