ARC: only trust contiguous run of trusted sealers at top of chain

When collecting trusted ARC instances, walk the chain from newest to
oldest and stop at the first untrusted sealer.  An untrusted hop means
anything older than it cannot be trusted either, since that untrusted
intermediary could have forged the older AAR headers.  Previously any
seal signed by a trusted domain was accepted regardless of position,
which could allow a trusted sealer downstream of an untrusted hop to
vouch for results that were never actually verified by a trusted party.

git-svn-id: https://svn.apache.org/repos/asf/spamassassin/trunk@1932878 13f79535-47bb-0310-9956-ffa450edef68
1 file changed