--- /dev/null
+Return-Path: <tbielawa@redhat.com>\r
+X-Original-To: notmuch@notmuchmail.org\r
+Delivered-To: notmuch@notmuchmail.org\r
+Received: from localhost (localhost [127.0.0.1])\r
+ by olra.theworths.org (Postfix) with ESMTP id BF6EE431FAF\r
+ for <notmuch@notmuchmail.org>; Sat, 3 Mar 2012 17:12:27 -0800 (PST)\r
+X-Virus-Scanned: Debian amavisd-new at olra.theworths.org\r
+X-Spam-Flag: NO\r
+X-Spam-Score: -4.99\r
+X-Spam-Level: \r
+X-Spam-Status: No, score=-4.99 tagged_above=-999 required=5\r
+ tests=[RCVD_IN_DNSWL_HI=-5, T_MIME_NO_TEXT=0.01] autolearn=disabled\r
+Received: from olra.theworths.org ([127.0.0.1])\r
+ by localhost (olra.theworths.org [127.0.0.1]) (amavisd-new, port 10024)\r
+ with ESMTP id b1MhqliM2LFb for <notmuch@notmuchmail.org>;\r
+ Sat, 3 Mar 2012 17:12:26 -0800 (PST)\r
+Received: from mx1.redhat.com (mx1.redhat.com [209.132.183.28])\r
+ by olra.theworths.org (Postfix) with ESMTP id 8BE55431FAE\r
+ for <notmuch@notmuchmail.org>; Sat, 3 Mar 2012 17:12:26 -0800 (PST)\r
+Received: from int-mx10.intmail.prod.int.phx2.redhat.com\r
+ (int-mx10.intmail.prod.int.phx2.redhat.com [10.5.11.23])\r
+ by mx1.redhat.com (8.14.4/8.14.4) with ESMTP id q241CLMq011042\r
+ (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK);\r
+ Sat, 3 Mar 2012 20:12:22 -0500\r
+Received: from dehydrator.rdu.redhat.com (spatula.rdu.redhat.com\r
+ [10.11.95.223])\r
+ by int-mx10.intmail.prod.int.phx2.redhat.com (8.14.4/8.14.4) with ESMTP\r
+ id q241CLP7023182\r
+ (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);\r
+ Sat, 3 Mar 2012 20:12:21 -0500\r
+Received: from dehydrator.spatula.rdu.redhat.com (localhost [127.0.0.1])\r
+ by dehydrator.rdu.redhat.com (Postfix) with ESMTP id BC7E123347;\r
+ Sat, 3 Mar 2012 20:12:20 -0500 (EST)\r
+Received: (from tbielawa@localhost)\r
+ by dehydrator.spatula.rdu.redhat.com (8.14.5/8.14.5/Submit) id\r
+ q241CKBk027928; Sat, 3 Mar 2012 20:12:20 -0500\r
+X-Authentication-Warning: dehydrator.spatula.rdu.redhat.com: tbielawa set\r
+ sender to tbielawa@redhat.com using -f\r
+From: Tim Bielawa <tbielawa@redhat.com>\r
+To: Jani Nikula <jani@nikula.org>, notmuch@notmuchmail.org\r
+Subject: Re: [PATCH] Fix mml-quoting in responses where pgp-signing is enabled\r
+In-Reply-To: <87ty25fe9u.fsf@nikula.org>\r
+References: <1330812262-28272-1-git-send-email-tbielawa@redhat.com>\r
+ <87ty25fe9u.fsf@nikula.org>\r
+User-Agent: Notmuch/0.12~rc1 (http://notmuchmail.org) Emacs/23.3.1\r
+ (x86_64-redhat-linux-gnu)\r
+Date: Sat, 03 Mar 2012 20:12:12 -0500\r
+Message-ID: <87fwdptbir.fsf@dehydrator.spatula.rdu.redhat.com>\r
+MIME-Version: 1.0\r
+Content-Type: multipart/signed; boundary="=-=-=";\r
+ micalg=pgp-sha1; protocol="application/pgp-signature"\r
+X-Scanned-By: MIMEDefang 2.68 on 10.5.11.23\r
+X-BeenThere: notmuch@notmuchmail.org\r
+X-Mailman-Version: 2.1.13\r
+Precedence: list\r
+List-Id: "Use and development of the notmuch mail system."\r
+ <notmuch.notmuchmail.org>\r
+List-Unsubscribe: <http://notmuchmail.org/mailman/options/notmuch>,\r
+ <mailto:notmuch-request@notmuchmail.org?subject=unsubscribe>\r
+List-Archive: <http://notmuchmail.org/pipermail/notmuch>\r
+List-Post: <mailto:notmuch@notmuchmail.org>\r
+List-Help: <mailto:notmuch-request@notmuchmail.org?subject=help>\r
+List-Subscribe: <http://notmuchmail.org/mailman/listinfo/notmuch>,\r
+ <mailto:notmuch-request@notmuchmail.org?subject=subscribe>\r
+X-List-Received-Date: Sun, 04 Mar 2012 01:12:27 -0000\r
+\r
+--=-=-=\r
+Content-Transfer-Encoding: quoted-printable\r
+\r
+On Sun, 04 Mar 2012 01:36:29 +0200, Jani Nikula <jani@nikula.org> wrote:\r
+> On Sat, 3 Mar 2012 17:04:22 -0500, Tim Bielawa <tbielawa@redhat.com> wro=\r
+te:\r
+> > The addition of mml-quote-region (notmuch-mua.el) in 2c6710e3 breaks\r
+> > automatic signing in replies. When replies are mml-quoted and signing\r
+> > is enabled by default the "<#part sign=3Dpgpmime>" string will appear on\r
+> > line 1. This will be consumed during the application of the\r
+> > mml-quote-region function and transform into the inert string\r
+> > "<#!part sign=3Dpgpmime>". The result is that responses will no longer\r
+> > be signed by default.\r
+> >=20\r
+> > This fix moves the point forward one line before applying the quoting\r
+> > function.\r
+> >=20\r
+> > Consideration: Clients not signing mail by default. The first line of\r
+> > their responses would be skipped when the quoting function is\r
+> > applied. This string takes this general form:\r
+> >=20\r
+> > On Sat, 03 Mar 2012 12:55:14 -0800, notmuch-request@notmuchmail.org=\r
+ wrote:\r
+> >=20\r
+> > Because the string is generated by notmuch I don't believe this fix\r
+> > introduces the possibility for malicious mml commands being omitted\r
+> > from the quoting.\r
+>=20\r
+> Hmm, would it work to mml quote the reply *before* extracting it from\r
+> the temp buffer, like below? It would handle not mml quoting the user's\r
+> signature too. Completely untested...\r
+>=20\r
+> BR,\r
+> Jani.\r
+>=20\r
+>=20\r
+> diff --git a/emacs/notmuch-mua.el b/emacs/notmuch-mua.el\r
+> index 4be7c13..13244eb 100644\r
+> --- a/emacs/notmuch-mua.el\r
+> +++ b/emacs/notmuch-mua.el\r
+> @@ -95,6 +95,9 @@ list."\r
+> (goto-char (point-min))\r
+> (setq headers (mail-header-extract)))))\r
+> (forward-line 1)\r
+> + ;; Original message may contain (malicious) MML tags. We must\r
+> + ;; properly quote them in the reply.\r
+> + (mml-quote-region (point) (point-max))\r
+> (setq body (buffer-substring (point) (point-max))))\r
+> ;; If sender is non-nil, set the From: header to its value.\r
+> (when sender\r
+> @@ -116,12 +119,7 @@ list."\r
+> (push-mark))\r
+> (set-buffer-modified-p nil)\r
+>=20=20\r
+> - (message-goto-body)\r
+> - ;; Original message may contain (malicious) MML tags. We must\r
+> - ;; properly quote them in the reply. Note that using `point-max'\r
+> - ;; instead of `mark' here is wrong. The buffer may include user's\r
+> - ;; signature which should not be MML-quoted.\r
+> - (mml-quote-region (point) (mark)))\r
+> + (message-goto-body))\r
+>=20=20\r
+> (defun notmuch-mua-forward-message ()\r
+> (message-forward)\r
+\r
+Works great. Passes unit tests. Definitely a better approach than the\r
+original patch.\r
+\r
+> Notmuch test suite complete.\r
+> All 381 tests behaved as expected (2 expected failures).\r
+\r
++1 from me (this message replied to and signed using the new patch)\r
+\r
+=2D-=20\r
+Tim Bielawa\r
+\r
+--=-=-=\r
+Content-Type: application/pgp-signature\r
+\r
+-----BEGIN PGP SIGNATURE-----\r
+\r
+iEUEARECAAYFAk9SwWwACgkQrQXnXgMzrjeIUgCXe6PNcE8pXqOctSHHM05jKmNC\r
+iACgwdPsXMHAFnwZiI91vwTIn7/2CQA=\r
+=6TcP\r
+-----END PGP SIGNATURE-----\r
+--=-=-=--\r