Files
hcornet ffe6ae1a2c
CI / test (push) Successful in 13s
CI / security (push) Successful in 5s
CI / Promote to main (push) Skipped
CI / Build and publish the lists (push) Successful in 3m20s
0.7.11: names covered, analyst files
2026-10-04 18:50:04 +02:00
..
2026-10-04 18:50:04 +02:00

analyst/ — the files written by warda-analyst

Never edit these files by hand. The service warda-analyst writes them, by a commit on the branch develop, each time its team approves or withdraws a name. It rewrites a whole file at each publication: a change made by hand is lost at the next one. A name to add or to remove by hand goes in the files of the owner (extra/, allow.txt).

File Role
add/<category>.txt names the analysis of Warda confirmed, added to that category as extra/<category>.txt does (never csam, never the bundle base)
remove.txt names confirmed as harmless and wrongly blocked: removed with their subdomains from the protection lists only (below)

A missing file, or no file at all, means no name. Nothing else may be in this directory but this README.md.

Where the removals apply

A name of remove.txt is removed, with its subdomains, from the categories named by remove_from of [analyst] in taxonomy.toml (ads, tracking, phishing, security) and from nothing else. It leaves the bundles built from them (base) and does not come back through an includes (security includes phishing). It is never removed from another category (adult, gambling…) nor from a site type: the team clears a name because it is no threat and no tracker, which says nothing of what the site is about. Only allow.txt, a file of the owner, removes a name from every list.

How they are checked

python3 scripts/build.py --check (the CI, on every push) refuses:

  • anything else in this directory: a file with another name (removed.txt, add/ads.TXT), a sub-directory, a link, remove.txt that is not a file;
  • a line that is neither a comment (it starts with #) nor exactly one name in its normalised form: lower case, no trailing dot, no space, no empty line, no *., no comment after the name, no byte order mark, no carriage return;
  • names that are not sorted (in the order of their bytes, as sort.Strings of Go and sorted of Python give it), or a name written twice;
  • a file add/<x>.txt whose <x> is not a category that public sources may fill;
  • a name added and removed at once, whichever covers the other: the same name in an add/ file and in remove.txt, an added name under a removed one, a removed name under an added one;
  • more names than the budgets max_add (all the add/ files together) and max_remove of [analyst] in taxonomy.toml.

A refused commit fails the CI of develop and is not promoted to main. The lists are still built every day from main, with the files of this directory as they are there: those of the last commit that passed.

In the build

Files that passed the check never stop the build, and what the build does not apply is said in its log and in manifest.json (analyst):

  • A line of remove.txt that would take too much out is not applied. The build counts the names under each line in the lists the removals apply to; over max_effect (100, [analyst] in taxonomy.toml) the line is left out and listed in analyst.skipped with its count. co.uk or github.io are valid names: only the build knows that thousands of sites are under them.
  • A removed name that stays blocked is reported. When a source or extra/ lists a parent of it in one of those lists, the boxes still block it: the build warns and lists it in analyst.covered (the name, the parent, the file; 1,000 entries at most).
  • The guards look at the sources only. The budget of each file, the minimum size of base.txt and the guard against the previous manifest are checked on the lists built without these files: added names cannot hide a collapse of the sources.
  • What goes wrong because of these files is not published. If a list goes over its budget or over the size limit, if base.txt goes under its minimum, or if a list loses more than half of its entries, only once these files are applied, the lists are built without any of them: analyst.status is then ignored: <why> instead of applied, and the log says IGNORED.
  • allow.txt and protect.txt still win over an added name.

In the headers of the lists, LICENSES.md and manifest.json, the added names are attributed to the source warda-analyst (https://warda-dns.com), as own data of this repository; manifest.json gives their count per category (analyst.add).