FA-76606 / Email MIME structure / Open access
Validate the structure of a multipart/signed entity: parameter name case · case 01
A header written with "Protocol=" or "MICALG=" is reported as missing both parameters.
ROOT CAUSE
The parameter name case decision evaluates `params = dict(node.get('params', {}))` where the contract requires `params = {k.lower(): v for k, v in node.get('params', {}).items()}`.
VERIFIED REPAIR
Use `params = {k.lower(): v for k, v in node.get('params', {}).items()}` for the parameter name case decision and keep every other rule of the model unchanged.
Unsuccessful approach: Trimming parameter names does not fold their case. The attempted `params = {k.strip(): v for k, v in node.get('params', {}).items()}` still disagrees with a fixture.
Case contract
Parameter names are case-insensitive. Findings, in order: not-signed (and stop) unless type is multipart/signed; missing-protocol; part-count (and stop) unless exactly two parts; protocol-mismatch when a protocol exists and the second part's type differs from it (case-insensitive); missing-micalg, or micalg-mismatch when a protocol exists and the micalg family disagrees (pgp-* exactly when the protocol is application/pgp-signature); unprotected-8bit when the signed first part uses 8bit or binary transfer encoding.
Why this case matters
Signed mail is only verifiable when its structure is exact; lax checks accept tampered or unverifiable messages.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(node):
if node['type'].lower() != 'multipart/signed':
return ['not-signed']
issues = []
params = dict(node.get('params', {}))
proto = (params.get('protocol') or '').lower()
if not proto:
issues.append('missing-protocol')
parts = node.get('parts', [])
if len(parts) != 2:
issues.append('part-count')
return issues
if proto and parts[1]['type'].lower() != proto:
issues.append('protocol-mismatch')
micalg = (params.get('micalg') or '').lower()
if not micalg:
issues.append('missing-micalg')
elif proto and micalg.startswith('pgp-') != (proto == 'application/pgp-signature'):
issues.append('micalg-mismatch')
if (parts[0].get('cte') or '7bit').lower() in ('8bit', 'binary'):
issues.append('unprotected-8bit')
return issues
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
_CASES = {1: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 2: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 3: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha128'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 4: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 5: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])]}
for _label, _args, _expected in _CASES[N]:
check(_label, solve(*_args), _expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| mixed-case parameter names | ['missing-protocol', 'missing-micalg'] | [] | Failed |
| extra third part | ['part-count'] | ['part-count'] | Passed |
| mixed-case protocol and part type | [] | [] | Passed |
| S/MIME signature | [] | [] | Passed |
| cross-family micalg | ['micalg-mismatch'] | ['micalg-mismatch'] | Passed |
| 8bit signed content | ['unprotected-8bit'] | ['unprotected-8bit'] | Passed |
| binary signed content | ['unprotected-8bit'] | ['unprotected-8bit'] | Passed |
| missing protocol with S/MIME part | ['missing-protocol'] | ['missing-protocol'] | Passed |
| not signed | ['not-signed'] | ['not-signed'] | Passed |
SHA-256 / fab44e1fd29b8294fb39a444bd37bcf49f47b50e9e21dbe8909e5e70824cca7c
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(node):
if node['type'].lower() != 'multipart/signed':
return ['not-signed']
issues = []
params = {k.strip(): v for k, v in node.get('params', {}).items()}
proto = (params.get('protocol') or '').lower()
if not proto:
issues.append('missing-protocol')
parts = node.get('parts', [])
if len(parts) != 2:
issues.append('part-count')
return issues
if proto and parts[1]['type'].lower() != proto:
issues.append('protocol-mismatch')
micalg = (params.get('micalg') or '').lower()
if not micalg:
issues.append('missing-micalg')
elif proto and micalg.startswith('pgp-') != (proto == 'application/pgp-signature'):
issues.append('micalg-mismatch')
if (parts[0].get('cte') or '7bit').lower() in ('8bit', 'binary'):
issues.append('unprotected-8bit')
return issues
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
_CASES = {1: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 2: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 3: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha128'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 4: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 5: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])]}
for _label, _args, _expected in _CASES[N]:
check(_label, solve(*_args), _expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| mixed-case parameter names | ['missing-protocol', 'missing-micalg'] | [] | Failed |
| extra third part | ['part-count'] | ['part-count'] | Passed |
| mixed-case protocol and part type | [] | [] | Passed |
| S/MIME signature | [] | [] | Passed |
| cross-family micalg | ['micalg-mismatch'] | ['micalg-mismatch'] | Passed |
| 8bit signed content | ['unprotected-8bit'] | ['unprotected-8bit'] | Passed |
| binary signed content | ['unprotected-8bit'] | ['unprotected-8bit'] | Passed |
| missing protocol with S/MIME part | ['missing-protocol'] | ['missing-protocol'] | Passed |
| not signed | ['not-signed'] | ['not-signed'] | Passed |
SHA-256 / 6087ff22268238677ea7ae6f949ee6529b7f566f3e7ba3df258f99991e5c1767
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(node):
if node['type'].lower() != 'multipart/signed':
return ['not-signed']
issues = []
params = {k.lower(): v for k, v in node.get('params', {}).items()}
proto = (params.get('protocol') or '').lower()
if not proto:
issues.append('missing-protocol')
parts = node.get('parts', [])
if len(parts) != 2:
issues.append('part-count')
return issues
if proto and parts[1]['type'].lower() != proto:
issues.append('protocol-mismatch')
micalg = (params.get('micalg') or '').lower()
if not micalg:
issues.append('missing-micalg')
elif proto and micalg.startswith('pgp-') != (proto == 'application/pgp-signature'):
issues.append('micalg-mismatch')
if (parts[0].get('cte') or '7bit').lower() in ('8bit', 'binary'):
issues.append('unprotected-8bit')
return issues
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
_CASES = {1: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 2: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 3: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha128'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 4: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 5: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])]}
for _label, _args, _expected in _CASES[N]:
check(_label, solve(*_args), _expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| mixed-case parameter names | [] | [] | Passed |
| extra third part | ['part-count'] | ['part-count'] | Passed |
| mixed-case protocol and part type | [] | [] | Passed |
| S/MIME signature | [] | [] | Passed |
| cross-family micalg | ['micalg-mismatch'] | ['micalg-mismatch'] | Passed |
| 8bit signed content | ['unprotected-8bit'] | ['unprotected-8bit'] | Passed |
| binary signed content | ['unprotected-8bit'] | ['unprotected-8bit'] | Passed |
| missing protocol with S/MIME part | ['missing-protocol'] | ['missing-protocol'] | Passed |
| not signed | ['not-signed'] | ['not-signed'] | Passed |
SHA-256 / 2a5d93fad294dc0b9ce96dca553f5c817a84b85ecfd8cddfd2cb3579b17d87a0
Verification & scope
Stipulated offline model over pre-parsed MIME dictionaries; not a conforming MIME parser, generator or mail client. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:49:17.891330+00:00.
Case digest / 68f02290f0ed1a0c8d9a8313ec27a013a443fa117b3d2af62efc3342be4f8733