Re: [PATCH] Fix mml-quoting in responses where pgp-signing is enabled
authorJani Nikula <jani@nikula.org>
Sat, 3 Mar 2012 23:36:29 +0000 (01:36 +0200)
committerW. Trevor King <wking@tremily.us>
Fri, 7 Nov 2014 17:45:14 +0000 (09:45 -0800)
b4/cb9670740218cb0638d4f069d4c439146bd6a4 [new file with mode: 0644]

diff --git a/b4/cb9670740218cb0638d4f069d4c439146bd6a4 b/b4/cb9670740218cb0638d4f069d4c439146bd6a4
new file mode 100644 (file)
index 0000000..b3e57dd
--- /dev/null
@@ -0,0 +1,123 @@
+Return-Path: <jani@nikula.org>\r
+X-Original-To: notmuch@notmuchmail.org\r
+Delivered-To: notmuch@notmuchmail.org\r
+Received: from localhost (localhost [127.0.0.1])\r
+       by olra.theworths.org (Postfix) with ESMTP id 16FE3431FAF\r
+       for <notmuch@notmuchmail.org>; Sat,  3 Mar 2012 15:36:37 -0800 (PST)\r
+X-Virus-Scanned: Debian amavisd-new at olra.theworths.org\r
+X-Spam-Flag: NO\r
+X-Spam-Score: -0.7\r
+X-Spam-Level: \r
+X-Spam-Status: No, score=-0.7 tagged_above=-999 required=5\r
+       tests=[RCVD_IN_DNSWL_LOW=-0.7] autolearn=disabled\r
+Received: from olra.theworths.org ([127.0.0.1])\r
+       by localhost (olra.theworths.org [127.0.0.1]) (amavisd-new, port 10024)\r
+       with ESMTP id bXT-GUqATMCf for <notmuch@notmuchmail.org>;\r
+       Sat,  3 Mar 2012 15:36:35 -0800 (PST)\r
+Received: from mail-lpp01m010-f53.google.com (mail-lpp01m010-f53.google.com\r
+       [209.85.215.53]) (using TLSv1 with cipher RC4-SHA (128/128 bits))\r
+       (No client certificate requested)\r
+       by olra.theworths.org (Postfix) with ESMTPS id ADF9E431FAE\r
+       for <notmuch@notmuchmail.org>; Sat,  3 Mar 2012 15:36:34 -0800 (PST)\r
+Received: by lahc1 with SMTP id c1so3588507lah.26\r
+       for <notmuch@notmuchmail.org>; Sat, 03 Mar 2012 15:36:33 -0800 (PST)\r
+Received-SPF: pass (google.com: domain of jani@nikula.org designates\r
+       10.112.103.228 as permitted sender) client-ip=10.112.103.228; \r
+Authentication-Results: mr.google.com;\r
+       spf=pass (google.com: domain of jani@nikula.org\r
+       designates 10.112.103.228 as permitted sender)\r
+       smtp.mail=jani@nikula.org\r
+Received: from mr.google.com ([10.112.103.228])\r
+       by 10.112.103.228 with SMTP id fz4mr6491577lbb.99.1330817793231\r
+       (num_hops = 1); Sat, 03 Mar 2012 15:36:33 -0800 (PST)\r
+Received: by 10.112.103.228 with SMTP id fz4mr5307297lbb.99.1330817793076;\r
+       Sat, 03 Mar 2012 15:36:33 -0800 (PST)\r
+Received: from localhost (dsl-hkibrasgw4-fe50f800-253.dhcp.inet.fi.\r
+       [84.248.80.253])\r
+       by mx.google.com with ESMTPS id fl2sm15225898lbb.4.2012.03.03.15.36.31\r
+       (version=SSLv3 cipher=OTHER); Sat, 03 Mar 2012 15:36:32 -0800 (PST)\r
+From: Jani Nikula <jani@nikula.org>\r
+To: Tim Bielawa <tbielawa@redhat.com>, notmuch@notmuchmail.org\r
+Subject: Re: [PATCH] Fix mml-quoting in responses where pgp-signing is enabled\r
+In-Reply-To: <1330812262-28272-1-git-send-email-tbielawa@redhat.com>\r
+References: <1330812262-28272-1-git-send-email-tbielawa@redhat.com>\r
+User-Agent: Notmuch/0.11.1+295~g780f284 (http://notmuchmail.org) Emacs/23.3.1\r
+       (i686-pc-linux-gnu)\r
+Date: Sun, 04 Mar 2012 01:36:29 +0200\r
+Message-ID: <87ty25fe9u.fsf@nikula.org>\r
+MIME-Version: 1.0\r
+Content-Type: text/plain; charset=us-ascii\r
+X-Gm-Message-State:\r
+ ALoCoQnRWkKHP28R+OCe08SWbBS2xNcci14RgspHbtiLGrsyVY5WLEkyDpqtXMoXFhN0cG2bdBRK\r
+X-BeenThere: notmuch@notmuchmail.org\r
+X-Mailman-Version: 2.1.13\r
+Precedence: list\r
+List-Id: "Use and development of the notmuch mail system."\r
+       <notmuch.notmuchmail.org>\r
+List-Unsubscribe: <http://notmuchmail.org/mailman/options/notmuch>,\r
+       <mailto:notmuch-request@notmuchmail.org?subject=unsubscribe>\r
+List-Archive: <http://notmuchmail.org/pipermail/notmuch>\r
+List-Post: <mailto:notmuch@notmuchmail.org>\r
+List-Help: <mailto:notmuch-request@notmuchmail.org?subject=help>\r
+List-Subscribe: <http://notmuchmail.org/mailman/listinfo/notmuch>,\r
+       <mailto:notmuch-request@notmuchmail.org?subject=subscribe>\r
+X-List-Received-Date: Sat, 03 Mar 2012 23:36:37 -0000\r
+\r
+On Sat,  3 Mar 2012 17:04:22 -0500, Tim Bielawa <tbielawa@redhat.com> wrote:\r
+> The addition of mml-quote-region (notmuch-mua.el) in 2c6710e3 breaks\r
+> automatic signing in replies. When replies are mml-quoted and signing\r
+> is enabled by default the "<#part sign=pgpmime>" string will appear on\r
+> line 1. This will be consumed during the application of the\r
+> mml-quote-region function and transform into the inert string\r
+> "<#!part sign=pgpmime>". The result is that responses will no longer\r
+> be signed by default.\r
+> \r
+> This fix moves the point forward one line before applying the quoting\r
+> function.\r
+> \r
+> Consideration: Clients not signing mail by default. The first line of\r
+> their responses would be skipped when the quoting function is\r
+> applied. This string takes this general form:\r
+> \r
+>     On Sat, 03 Mar 2012 12:55:14 -0800, notmuch-request@notmuchmail.org wrote:\r
+> \r
+> Because the string is generated by notmuch I don't believe this fix\r
+> introduces the possibility for malicious mml commands being omitted\r
+> from the quoting.\r
+\r
+Hmm, would it work to mml quote the reply *before* extracting it from\r
+the temp buffer, like below? It would handle not mml quoting the user's\r
+signature too. Completely untested...\r
+\r
+BR,\r
+Jani.\r
+\r
+\r
+diff --git a/emacs/notmuch-mua.el b/emacs/notmuch-mua.el\r
+index 4be7c13..13244eb 100644\r
+--- a/emacs/notmuch-mua.el\r
++++ b/emacs/notmuch-mua.el\r
+@@ -95,6 +95,9 @@ list."\r
+             (goto-char (point-min))\r
+             (setq headers (mail-header-extract)))))\r
+       (forward-line 1)\r
++      ;; Original message may contain (malicious) MML tags. We must\r
++      ;; properly quote them in the reply.\r
++      (mml-quote-region (point) (point-max))\r
+       (setq body (buffer-substring (point) (point-max))))\r
+     ;; If sender is non-nil, set the From: header to its value.\r
+     (when sender\r
+@@ -116,12 +119,7 @@ list."\r
+     (push-mark))\r
+   (set-buffer-modified-p nil)\r
+ \r
+-  (message-goto-body)\r
+-  ;; Original message may contain (malicious) MML tags.  We must\r
+-  ;; properly quote them in the reply.  Note that using `point-max'\r
+-  ;; instead of `mark' here is wrong.  The buffer may include user's\r
+-  ;; signature which should not be MML-quoted.\r
+-  (mml-quote-region (point) (mark)))\r
++  (message-goto-body))\r
+ \r
+ (defun notmuch-mua-forward-message ()\r
+   (message-forward)\r