[PATCH] Fix mml-quoting in responses where pgp-signing is enabled
authorTim Bielawa <tbielawa@redhat.com>
Sat, 3 Mar 2012 22:04:22 +0000 (17:04 +1900)
committerW. Trevor King <wking@tremily.us>
Fri, 7 Nov 2014 17:45:13 +0000 (09:45 -0800)
ee/26490d51a310518fbe26e6a9d95cb9b7c69179 [new file with mode: 0644]

diff --git a/ee/26490d51a310518fbe26e6a9d95cb9b7c69179 b/ee/26490d51a310518fbe26e6a9d95cb9b7c69179
new file mode 100644 (file)
index 0000000..ecd251c
--- /dev/null
@@ -0,0 +1,109 @@
+Return-Path: <tbielawa@redhat.com>\r
+X-Original-To: notmuch@notmuchmail.org\r
+Delivered-To: notmuch@notmuchmail.org\r
+Received: from localhost (localhost [127.0.0.1])\r
+       by olra.theworths.org (Postfix) with ESMTP id 023B4431FAF\r
+       for <notmuch@notmuchmail.org>; Sat,  3 Mar 2012 14:04:24 -0800 (PST)\r
+X-Virus-Scanned: Debian amavisd-new at olra.theworths.org\r
+X-Spam-Flag: NO\r
+X-Spam-Score: -5\r
+X-Spam-Level: \r
+X-Spam-Status: No, score=-5 tagged_above=-999 required=5\r
+       tests=[RCVD_IN_DNSWL_HI=-5] autolearn=disabled\r
+Received: from olra.theworths.org ([127.0.0.1])\r
+       by localhost (olra.theworths.org [127.0.0.1]) (amavisd-new, port 10024)\r
+       with ESMTP id XsH9TmQCrV49 for <notmuch@notmuchmail.org>;\r
+       Sat,  3 Mar 2012 14:04:24 -0800 (PST)\r
+Received: from mx1.redhat.com (mx1.redhat.com [209.132.183.28])\r
+       by olra.theworths.org (Postfix) with ESMTP id 527AC431FAE\r
+       for <notmuch@notmuchmail.org>; Sat,  3 Mar 2012 14:04:24 -0800 (PST)\r
+Received: from int-mx09.intmail.prod.int.phx2.redhat.com\r
+       (int-mx09.intmail.prod.int.phx2.redhat.com [10.5.11.22])\r
+       by mx1.redhat.com (8.14.4/8.14.4) with ESMTP id q23M4NF1018015\r
+       (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK)\r
+       for <notmuch@notmuchmail.org>; Sat, 3 Mar 2012 17:04:23 -0500\r
+Received: from localhost.localdomain (ovpn-113-28.phx2.redhat.com\r
+       [10.3.113.28])\r
+       by int-mx09.intmail.prod.int.phx2.redhat.com (8.14.4/8.14.4) with ESMTP\r
+       id q23M4MVC007561\r
+       (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO)\r
+       for <notmuch@notmuchmail.org>; Sat, 3 Mar 2012 17:04:23 -0500\r
+From: Tim Bielawa <tbielawa@redhat.com>\r
+To: notmuch@notmuchmail.org\r
+Subject: [PATCH] Fix mml-quoting in responses where pgp-signing is enabled\r
+Date: Sat,  3 Mar 2012 17:04:22 -0500\r
+Message-Id: <1330812262-28272-1-git-send-email-tbielawa@redhat.com>\r
+X-Scanned-By: MIMEDefang 2.68 on 10.5.11.22\r
+X-BeenThere: notmuch@notmuchmail.org\r
+X-Mailman-Version: 2.1.13\r
+Precedence: list\r
+List-Id: "Use and development of the notmuch mail system."\r
+       <notmuch.notmuchmail.org>\r
+List-Unsubscribe: <http://notmuchmail.org/mailman/options/notmuch>,\r
+       <mailto:notmuch-request@notmuchmail.org?subject=unsubscribe>\r
+List-Archive: <http://notmuchmail.org/pipermail/notmuch>\r
+List-Post: <mailto:notmuch@notmuchmail.org>\r
+List-Help: <mailto:notmuch-request@notmuchmail.org?subject=help>\r
+List-Subscribe: <http://notmuchmail.org/mailman/listinfo/notmuch>,\r
+       <mailto:notmuch-request@notmuchmail.org?subject=subscribe>\r
+X-List-Received-Date: Sat, 03 Mar 2012 22:04:25 -0000\r
+\r
+The addition of mml-quote-region (notmuch-mua.el) in 2c6710e3 breaks\r
+automatic signing in replies. When replies are mml-quoted and signing\r
+is enabled by default the "<#part sign=pgpmime>" string will appear on\r
+line 1. This will be consumed during the application of the\r
+mml-quote-region function and transform into the inert string\r
+"<#!part sign=pgpmime>". The result is that responses will no longer\r
+be signed by default.\r
+\r
+This fix moves the point forward one line before applying the quoting\r
+function.\r
+\r
+Consideration: Clients not signing mail by default. The first line of\r
+their responses would be skipped when the quoting function is\r
+applied. This string takes this general form:\r
+\r
+    On Sat, 03 Mar 2012 12:55:14 -0800, notmuch-request@notmuchmail.org wrote:\r
+\r
+Because the string is generated by notmuch I don't believe this fix\r
+introduces the possibility for malicious mml commands being omitted\r
+from the quoting.\r
+---\r
+ emacs/notmuch-mua.el |   15 +++++++++++++--\r
+ 1 files changed, 13 insertions(+), 2 deletions(-)\r
+\r
+diff --git a/emacs/notmuch-mua.el b/emacs/notmuch-mua.el\r
+index 4be7c13..d8ab2c0 100644\r
+--- a/emacs/notmuch-mua.el\r
++++ b/emacs/notmuch-mua.el\r
+@@ -114,14 +114,25 @@ list."\r
+       (goto-char (point-max)))\r
+     (insert body)\r
+     (push-mark))\r
+-  (set-buffer-modified-p nil)\r
+ \r
+   (message-goto-body)\r
+   ;; Original message may contain (malicious) MML tags.  We must\r
+   ;; properly quote them in the reply.  Note that using `point-max'\r
+   ;; instead of `mark' here is wrong.  The buffer may include user's\r
+   ;; signature which should not be MML-quoted.\r
+-  (mml-quote-region (point) (mark)))\r
++  ;;\r
++  ;; Note also that we skip the first line of the response as it is\r
++  ;; either: the "<#part sign=pgpmime>" string when clients use\r
++  ;; automatic signing, or it is the generated string from notmuch\r
++  ;; indicating the date and author of the message which is being\r
++  ;; responded to, "on date x, y z -0000, foo@bar.com wrote:"\r
++  (forward-line 1)\r
++  (mml-quote-region (point) (mark))\r
++\r
++  ;; Quoting the message may modify the contents of the buffer,\r
++  ;; however, we shouldn't consider mml-quoting a modification because\r
++  ;; it's preformed by the mua, not the user.\r
++  (set-buffer-modified-p nil))\r
+ \r
+ (defun notmuch-mua-forward-message ()\r
+   (message-forward)\r
+-- \r
+1.7.4.4\r
+\r