{"abstract":"A signed entity with a third, unsigned part is accepted, letting content ride along outside the signature.","category":"Email MIME structure","checks":9,"contract":"Parameter names are case-insensitive. Findings, in order: not-signed (and stop) unless type is multipart/signed; missing-protocol; part-count (and stop) unless exactly two parts; protocol-mismatch when a protocol exists and the second part's type differs from it (case-insensitive); missing-micalg, or micalg-mismatch when a protocol exists and the micalg family disagrees (pgp-* exactly when the protocol is application/pgp-signature); unprotected-8bit when the signed first part uses 8bit or binary transfer encoding.","contract_signature":"node","evaluation_group":"w2-email_mime_structure-signed-structure","failed_approach":"Rejecting only a repeated signature part still accepts other trailing parts. The attempted `if len(parts) < 2 or (len(parts) > 2 and parts[2]['type'].lower() == proto):` still disagrees with a fixture.","family":"w2-email_mime_structure-signed-structure-exact-part-count","id":"FA-76611","implementations":{"attempt":{"sha256":"1e18593aa6f7ae95735015bd552d4cf8417c21c0574cf93482c194f4c52cf874","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(node):\n    if node['type'].lower() != 'multipart/signed':\n        return ['not-signed']\n    issues = []\n    params = {k.lower(): v for k, v in node.get('params', {}).items()}\n    proto = (params.get('protocol') or '').lower()\n    if not proto:\n        issues.append('missing-protocol')\n    parts = node.get('parts', [])\n    if len(parts) < 2 or (len(parts) > 2 and parts[2]['type'].lower() == proto):\n        issues.append('part-count')\n        return issues\n    if proto and parts[1]['type'].lower() != proto:\n        issues.append('protocol-mismatch')\n    micalg = (params.get('micalg') or '').lower()\n    if not micalg:\n        issues.append('missing-micalg')\n    elif proto and micalg.startswith('pgp-') != (proto == 'application/pgp-signature'):\n        issues.append('micalg-mismatch')\n    if (parts[0].get('cte') or '7bit').lower() in ('8bit', 'binary'):\n        issues.append('unprotected-8bit')\n    return issues\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\n_CASES = {1: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 2: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 3: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha128'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 4: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 5: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])]}\nfor _label, _args, _expected in _CASES[N]:\n    check(_label, solve(*_args), _expected)\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"},"broken":{"sha256":"e636819a6152fa239735f3c5067d8151f2f3151fddd4ebc82b42bc836a4be934","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(node):\n    if node['type'].lower() != 'multipart/signed':\n        return ['not-signed']\n    issues = []\n    params = {k.lower(): v for k, v in node.get('params', {}).items()}\n    proto = (params.get('protocol') or '').lower()\n    if not proto:\n        issues.append('missing-protocol')\n    parts = node.get('parts', [])\n    if len(parts) < 2:\n        issues.append('part-count')\n        return issues\n    if proto and parts[1]['type'].lower() != proto:\n        issues.append('protocol-mismatch')\n    micalg = (params.get('micalg') or '').lower()\n    if not micalg:\n        issues.append('missing-micalg')\n    elif proto and micalg.startswith('pgp-') != (proto == 'application/pgp-signature'):\n        issues.append('micalg-mismatch')\n    if (parts[0].get('cte') or '7bit').lower() in ('8bit', 'binary'):\n        issues.append('unprotected-8bit')\n    return issues\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\n_CASES = {1: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 2: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 3: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha128'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 4: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 5: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])]}\nfor _label, _args, _expected in _CASES[N]:\n    check(_label, solve(*_args), _expected)\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"}},"limitations":"Stipulated offline model over pre-parsed MIME dictionaries; not a conforming MIME parser, generator or mail client. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.","method":"Deterministic executable model with adversarial boundary fixtures.","provenance":{"created_by":"Failure Map","dependencies":"Python standard library","family":"w2-email_mime_structure-signed-structure-exact-part-count","generated_at":"2026-09-29T14:49:18.019860+00:00","license":"CC0-1.0","python":"3.12.14","seed":1,"split":"open-access"},"relevance":"Signed mail is only verifiable when its structure is exact; lax checks accept tampered or unverifiable messages.","root_cause":"The exact part count decision evaluates `if len(parts) < 2:` where the contract requires `if len(parts) != 2:`.","sha256":"5e3433eb88650e64e6e7f292535b6548bc8cc764ffb9e5b2096cf37750141035","title":"Validate the structure of a multipart/signed entity: exact part count · case 01","variant":1,"variant_policy":"N selects a different enumerated fixture set (renamed identifiers, part counts and sizes); boundary fixtures recur across variants.","verified":true,"visibility":"public","verification":{"attempt":{"elapsed_ms":42.05,"exit_code":1,"observations":[{"actual":[],"check":"mixed-case parameter names","expected":[],"passed":true},{"actual":[],"check":"extra third part","expected":["part-count"],"passed":false},{"actual":[],"check":"mixed-case protocol and part type","expected":[],"passed":true},{"actual":[],"check":"S/MIME signature","expected":[],"passed":true},{"actual":["micalg-mismatch"],"check":"cross-family micalg","expected":["micalg-mismatch"],"passed":true},{"actual":["unprotected-8bit"],"check":"8bit signed content","expected":["unprotected-8bit"],"passed":true},{"actual":["unprotected-8bit"],"check":"binary signed content","expected":["unprotected-8bit"],"passed":true},{"actual":["missing-protocol"],"check":"missing protocol with S/MIME part","expected":["missing-protocol"],"passed":true},{"actual":["not-signed"],"check":"not signed","expected":["not-signed"],"passed":true}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"mixed-case parameter names\", \"actual\": [], \"expected\": [], \"passed\": true}, {\"check\": \"extra third part\", \"actual\": [], \"expected\": [\"part-count\"], \"passed\": false}, {\"check\": \"mixed-case protocol and part type\", \"actual\": [], \"expected\": [], \"passed\": true}, {\"check\": \"S/MIME signature\", \"actual\": [], \"expected\": [], \"passed\": true}, {\"check\": \"cross-family micalg\", \"actual\": [\"micalg-mismatch\"], \"expected\": [\"micalg-mismatch\"], \"passed\": true}, {\"check\": \"8bit signed content\", \"actual\": [\"unprotected-8bit\"], \"expected\": [\"unprotected-8bit\"], \"passed\": true}, {\"check\": \"binary signed content\", \"actual\": [\"unprotected-8bit\"], \"expected\": [\"unprotected-8bit\"], \"passed\": true}, {\"check\": \"missing protocol with S/MIME part\", \"actual\": [\"missing-protocol\"], \"expected\": [\"missing-protocol\"], \"passed\": true}, {\"check\": \"not signed\", \"actual\": [\"not-signed\"], \"expected\": [\"not-signed\"], \"passed\": true}], \"passed\": false}\n"},"broken":{"elapsed_ms":41.18,"exit_code":1,"observations":[{"actual":[],"check":"mixed-case parameter names","expected":[],"passed":true},{"actual":[],"check":"extra third part","expected":["part-count"],"passed":false},{"actual":[],"check":"mixed-case protocol and part type","expected":[],"passed":true},{"actual":[],"check":"S/MIME signature","expected":[],"passed":true},{"actual":["micalg-mismatch"],"check":"cross-family micalg","expected":["micalg-mismatch"],"passed":true},{"actual":["unprotected-8bit"],"check":"8bit signed content","expected":["unprotected-8bit"],"passed":true},{"actual":["unprotected-8bit"],"check":"binary signed content","expected":["unprotected-8bit"],"passed":true},{"actual":["missing-protocol"],"check":"missing protocol with S/MIME part","expected":["missing-protocol"],"passed":true},{"actual":["not-signed"],"check":"not signed","expected":["not-signed"],"passed":true}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"mixed-case parameter names\", \"actual\": [], \"expected\": [], \"passed\": true}, {\"check\": \"extra third part\", \"actual\": [], \"expected\": [\"part-count\"], \"passed\": false}, {\"check\": \"mixed-case protocol and part type\", \"actual\": [], \"expected\": [], \"passed\": true}, {\"check\": \"S/MIME signature\", \"actual\": [], \"expected\": [], \"passed\": true}, {\"check\": \"cross-family micalg\", \"actual\": [\"micalg-mismatch\"], \"expected\": [\"micalg-mismatch\"], \"passed\": true}, {\"check\": \"8bit signed content\", \"actual\": [\"unprotected-8bit\"], \"expected\": [\"unprotected-8bit\"], \"passed\": true}, {\"check\": \"binary signed content\", \"actual\": [\"unprotected-8bit\"], \"expected\": [\"unprotected-8bit\"], \"passed\": true}, {\"check\": \"missing protocol with S/MIME part\", \"actual\": [\"missing-protocol\"], \"expected\": [\"missing-protocol\"], \"passed\": true}, {\"check\": \"not signed\", \"actual\": [\"not-signed\"], \"expected\": [\"not-signed\"], \"passed\": true}], \"passed\": false}\n"}},"member_only":{"stages":["fixed"],"fields":["implementations.fixed","verification.fixed","harness","repair"],"note":"The verified repair, its recorded checks, the repair description, and the scoring harness are available to members."}}