2.1.6RC4 compiled from source has the bug as well, but it is manifested only under one condition (which debian package shows as well):
Directly trying to access the SPAM filter settings page by going to http://servername/cgi-bin/mailman/admin/listname/privacy/spam If you do this without being authenticated aforehand you are presented with a password dialogue. Entering the password (either global or list) leads to a page where the antispam rules are cleared and this is what gets stored in the configuration. If you login by going to http://servername/cgi-bin/mailman/admin/listname And descend to http://servername/cgi-bin/mailman/admin/listname/privacy/spam by following the links the SPAM filter rules remain intact. I am filing this with upstream as well. -- La Ch�telier's Law: If some stress is brought to bear on a system in equilibrium, the equilibrium is displaced in the direction which tends to undo the effect of the stress.

