Title: email.generator.Generator ignores policy when using `multipart/signed` → ruins signing · Issue #99533 · python/cpython · GitHub
Open Graph Title: email.generator.Generator ignores policy when using `multipart/signed` → ruins signing · Issue #99533 · python/cpython
X Title: email.generator.Generator ignores policy when using `multipart/signed` → ruins signing · Issue #99533 · python/cpython
Description: Bug report EmailMessage behaves differently when being set to multipart/signed mimetype. from email.message import EmailMessage inner = EmailMessage() inner.add_attachment("some data", "text/plain", filename="*"*35) outer1 = EmailMessage...
Open Graph Description: Bug report EmailMessage behaves differently when being set to multipart/signed mimetype. from email.message import EmailMessage inner = EmailMessage() inner.add_attachment("some data", "text/plain"...
X Description: Bug report EmailMessage behaves differently when being set to multipart/signed mimetype. from email.message import EmailMessage inner = EmailMessage() inner.add_attachment("some data", &q...
Opengraph URL: https://github.com/python/cpython/issues/99533
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"email.generator.Generator ignores policy when using `multipart/signed` → ruins signing","articleBody":"# Bug report\r\n\r\nEmailMessage behaves differently when being set to `multipart/signed` mimetype.\r\n\r\n```python3\r\nfrom email.message import EmailMessage\r\n\r\ninner = EmailMessage()\r\ninner.add_attachment(\"some data\", \"text/plain\", filename=\"*\"*35)\r\n\r\nouter1 = EmailMessage()\r\nouter1.set_type(\"multipart/signed\") # affected by generator.py/_handle_multipart_signed\r\nouter1.attach(inner)\r\n\r\nouter2 = EmailMessage()\r\nouter2.set_type(\"multipart/signeX\") # not affected by generator.py/_handle_multipart_signed\r\nouter2.attach(inner)\r\n\r\n# When accessing given submessage, nothing weird happens\r\nouter1.get_payload()[0].as_string() == outer2.get_payload()[0].as_string() # True\r\n\r\n# However, when accessing whole message at once, headers folding change for the outer1 `multipart/signed` message\r\ninner.as_string() in outer1.as_string() # !False!\r\ninner.as_string() in outer2.as_string() # True\r\n```\r\n\r\nThis is due to a 13 years old [generator.py](https://github.com/python/cpython/blob/00437ad30454005bc82fca75dfbabf6c95f3ea6a/Lib/email/generator.py#L319) code that for an unknown reason rewrites the policy so that no header was folded:\r\n\r\n```python3\r\n def _handle_multipart_signed(self, msg):\r\n # The contents of signed parts has to stay unmodified in order to keep\r\n # the signature intact per RFC1847 2.1, so we disable header wrapping.\r\n # RDM: This isn't enough to completely preserve the part, but it helps.\r\n p = self.policy\r\n self.policy = p.clone(max_line_length=0)\r\n try:\r\n self._handle_multipart(msg)\r\n finally:\r\n self.policy = p\r\n```\r\n\r\nAs a result, when I GPG-sign the `inner` message and attach it to a wrapping-`outer` message along with the signature (which is the right thing), the signature is void because policy being ignored, the headers folding got disabled on the output. I understand the method `_handle_multipart_signed` should help the message signing but it ruins it instead. One dirty solution would be to set the policy to `max_line_length=0` which fails for whatever reason:\r\n\r\n```python3\r\nfrom email import policy\r\npol = policy.default.clone(max_line_length=0)\r\ninner = EmailMessage(policy=pol)\r\ninner.add_attachment(\"some data\", \"text/plain\", filename=\"*\"*35) # ValueError: maxlinelen must be at least 4\r\n```\r\n\r\nTherefore, I am not able to sign the `inner` message with the headers fold (as it is output unfold), not I am able to sign the `inner` message with the headers unfold (as `ValueError` prevents me to set the policy to not stop folding headers).\r\n\r\nSo my proposal is to remove `_handle_multipart_signed` altogether (which would be sufficient) or to find a use-case where it does make sense (I could not find any).\r\n\r\n# Your environment\r\n\r\n- CPython versions tested on: Python 3.10.6\r\n- Operating system and architecture: Ubuntu 22.04.1 LTS x86_64\r\n\n\n\u003c!-- gh-linked-prs --\u003e\n### Linked PRs\n* gh-100204\n\u003c!-- /gh-linked-prs --\u003e\n","author":{"url":"https://github.com/e3rd","@type":"Person","name":"e3rd"},"datePublished":"2022-11-16T14:05:00.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":0},"url":"https://github.com/99533/cpython/issues/99533"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:ae7a7bac-e652-610d-f3f3-96c2ef537819 |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | CB80:46801:F5BADF:147400D:69699150 |
| html-safe-nonce | 346fbd6d6d9e8a1a1fdd598d4142368fee09bb1590fd147a7dfb219087fe9209 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJDQjgwOjQ2ODAxOkY1QkFERjoxNDc0MDBEOjY5Njk5MTUwIiwidmlzaXRvcl9pZCI6IjYxMTk5OTkzMjY3NjQyNDEyMzIiLCJyZWdpb25fZWRnZSI6ImlhZCIsInJlZ2lvbl9yZW5kZXIiOiJpYWQifQ== |
| visitor-hmac | 2be7506a353486233741e84a446ca6cc9eea14aa642f62d0ac35c89ede8728e2 |
| hovercard-subject-tag | issue:1451668742 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/python/cpython/99533/issue_layout |
| twitter:image | https://opengraph.githubassets.com/9f7c327ca5c8dfa38ed281be3afaef4642ffef934e7664fbfb9273293f289b4c/python/cpython/issues/99533 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/9f7c327ca5c8dfa38ed281be3afaef4642ffef934e7664fbfb9273293f289b4c/python/cpython/issues/99533 |
| og:image:alt | Bug report EmailMessage behaves differently when being set to multipart/signed mimetype. from email.message import EmailMessage inner = EmailMessage() inner.add_attachment("some data", "text/plain"... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | e3rd |
| hostname | github.com |
| expected-hostname | github.com |
| None | 3542e147982176a7ebaa23dfb559c8af16f721c03ec560c68c56b64a0f35e751 |
| turbo-cache-control | no-preview |
| go-import | github.com/python/cpython git https://github.com/python/cpython.git |
| octolytics-dimension-user_id | 1525981 |
| octolytics-dimension-user_login | python |
| octolytics-dimension-repository_id | 81598961 |
| octolytics-dimension-repository_nwo | python/cpython |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 81598961 |
| octolytics-dimension-repository_network_root_nwo | python/cpython |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | af80af7cc9e3de9c336f18b208a600950a3c187c |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width