--- /dev/null
+Return-Path: <tbielawa@redhat.com>\r
+X-Original-To: notmuch@notmuchmail.org\r
+Delivered-To: notmuch@notmuchmail.org\r
+Received: from localhost (localhost [127.0.0.1])\r
+ by olra.theworths.org (Postfix) with ESMTP id BC4FA431FAF\r
+ for <notmuch@notmuchmail.org>; Sat, 3 Mar 2012 15:54:57 -0800 (PST)\r
+X-Virus-Scanned: Debian amavisd-new at olra.theworths.org\r
+X-Spam-Flag: NO\r
+X-Spam-Score: -5\r
+X-Spam-Level: \r
+X-Spam-Status: No, score=-5 tagged_above=-999 required=5\r
+ tests=[RCVD_IN_DNSWL_HI=-5] autolearn=disabled\r
+Received: from olra.theworths.org ([127.0.0.1])\r
+ by localhost (olra.theworths.org [127.0.0.1]) (amavisd-new, port 10024)\r
+ with ESMTP id qS7xfar0+lgA for <notmuch@notmuchmail.org>;\r
+ Sat, 3 Mar 2012 15:54:57 -0800 (PST)\r
+Received: from mx4-phx2.redhat.com (mx4-phx2.redhat.com [209.132.183.25])\r
+ by olra.theworths.org (Postfix) with ESMTP id ECE54431FAE\r
+ for <notmuch@notmuchmail.org>; Sat, 3 Mar 2012 15:54:56 -0800 (PST)\r
+Received: from zmail10.collab.prod.int.phx2.redhat.com\r
+ (zmail10.collab.prod.int.phx2.redhat.com [10.5.83.12])\r
+ by mx4-phx2.redhat.com (8.13.8/8.13.8) with ESMTP id q23NstD0031277;\r
+ Sat, 3 Mar 2012 18:54:55 -0500\r
+To: notmuch@notmuchmail.org, jani@nikula.org\r
+From: Tim Bielawa <tbielawa@redhat.com>\r
+Date: Sat, 03 Mar 2012 18:54:55 -0500 (EST)\r
+X-Mailer: TouchDown\r
+X-Mailer: Zimbra 7.1.2_GA_3268 (MobileSync - TouchDown(MSRPC)/7.1.00012/)\r
+MIME-Version: 1.0\r
+Subject: Re: [PATCH] Fix mml-quoting in responses where pgp-signing is enabled\r
+Content-Type: multipart/mixed;boundary="__1330818891440TOUCHDOWN_BOUNDARY__"\r
+Message-ID: <817359227.7576598.1330818895565.JavaMail.root@zmail10.collab.prod.int.phx2.redhat.com>\r
+X-BeenThere: notmuch@notmuchmail.org\r
+X-Mailman-Version: 2.1.13\r
+Precedence: list\r
+List-Id: "Use and development of the notmuch mail system."\r
+ <notmuch.notmuchmail.org>\r
+List-Unsubscribe: <http://notmuchmail.org/mailman/options/notmuch>,\r
+ <mailto:notmuch-request@notmuchmail.org?subject=unsubscribe>\r
+List-Archive: <http://notmuchmail.org/pipermail/notmuch>\r
+List-Post: <mailto:notmuch@notmuchmail.org>\r
+List-Help: <mailto:notmuch-request@notmuchmail.org?subject=help>\r
+List-Subscribe: <http://notmuchmail.org/mailman/listinfo/notmuch>,\r
+ <mailto:notmuch-request@notmuchmail.org?subject=subscribe>\r
+X-List-Received-Date: Sat, 03 Mar 2012 23:54:57 -0000\r
+\r
+--__1330818891440TOUCHDOWN_BOUNDARY__\r
+Content-Type: text/plain; charset=UTF-8\r
+Content-Transfer-Encoding: 7bit\r
+\r
+Great point, I considered that too after I authored the original patch. It's a better approach I think. I'll try and give it a test run later tonight.\r
+\r
+\r
+-----Original Message-----\r
+From: Jani Nikula [jani@nikula.org]\r
+Received: Saturday, 03 Mar 2012, 6:36pm\r
+To: Tim Bielawa [tbielawa@redhat.com]; notmuch@notmuchmail.org\r
+Subject: Re: [PATCH] Fix mml-quoting in responses where pgp-signing is enabled\r
+\r
+\r
+On Sat, 3 Mar 2012 17:04:22 -0500, Tim Bielawa <tbielawa@redhat.com> wrote:\r
+> The addition of mml-quote-region (notmuch-mua.el) in 2c6710e3 breaks\r
+> automatic signing in replies. When replies are mml-quoted and signing\r
+> is enabled by default the "<#part sign=pgpmime>" string will appear on\r
+> line 1. This will be consumed during the application of the\r
+> mml-quote-region function and transform into the inert string\r
+> "<#!part sign=pgpmime>". The result is that responses will no longer\r
+> be signed by default.\r
+> \r
+> This fix moves the point forward one line before applying the quoting\r
+> function.\r
+> \r
+> Consideration: Clients not signing mail by default. The first line of\r
+> their responses would be skipped when the quoting function is\r
+> applied. This string takes this general form:\r
+> \r
+> On Sat, 03 Mar 2012 12:55:14 -0800, notmuch-request@notmuchmail.org wrote:\r
+> \r
+> Because the string is generated by notmuch I don't believe this fix\r
+> introduces the possibility for malicious mml commands being omitted\r
+> from the quoting.\r
+\r
+Hmm, would it work to mml quote the reply *before* extracting it from\r
+the temp buffer, like below? It would handle not mml quoting the user's\r
+signature too. Completely untested...\r
+\r
+BR,\r
+Jani.\r
+\r
+\r
+diff --git a/emacs/notmuch-mua.el b/emacs/notmuch-mua.el\r
+index 4be7c13..13244eb 100644\r
+--- a/emacs/notmuch-mua.el\r
++++ b/emacs/notmuch-mua.el\r
+@@ -95,6 +95,9 @@ list."\r
+ (goto-char (point-min))\r
+ (setq headers (mail-header-extract)))))\r
+ (forward-line 1)\r
++ ;; Original message may contain (malicious) MML tags. We must\r
++ ;; properly quote them in the reply.\r
++ (mml-quote-region (point) (point-max))\r
+ (setq body (buffer-substring (point) (point-max))))\r
+ ;; If sender is non-nil, set the From: header to its value.\r
+ (when sender\r
+@@ -116,12 +119,7 @@ list."\r
+ (push-mark))\r
+ (set-buffer-modified-p nil)\r
+ \r
+- (message-goto-body)\r
+- ;; Original message may contain (malicious) MML tags. We must\r
+- ;; properly quote them in the reply. Note that using `point-max'\r
+- ;; instead of `mark' here is wrong. The buffer may include user's\r
+- ;; signature which should not be MML-quoted.\r
+- (mml-quote-region (point) (mark)))\r
++ (message-goto-body))\r
+ \r
+ (defun notmuch-mua-forward-message ()\r
+ (message-forward)\r
+\r
+--__1330818891440TOUCHDOWN_BOUNDARY__--\r