FAILURE MAP
← Case archive

FA-76631 / Email MIME structure / Open access

Validate the structure of a multipart/signed entity: mismatch needs protocol · case 01

A missing protocol parameter is additionally reported as a protocol mismatch.

Verified by executionVariant 1 · 9 checks per implementationDownload source bundle ↓JSON ↗

ROOT CAUSE

The mismatch needs protocol decision evaluates `if parts[1]['type'].lower() != proto:` where the contract requires `if proto and parts[1]['type'].lower() != proto:`.

VERIFIED REPAIR

Use `if proto and parts[1]['type'].lower() != proto:` for the mismatch needs protocol decision and keep every other rule of the model unchanged.

Unsuccessful approach: Assuming a pgp protocol when none is given misreports S/MIME signature parts. The attempted `if parts[1]['type'].lower() != (proto or 'application/pgp-signature'):` still disagrees with a fixture.

Case contract

Parameter names are case-insensitive. Findings, in order: not-signed (and stop) unless type is multipart/signed; missing-protocol; part-count (and stop) unless exactly two parts; protocol-mismatch when a protocol exists and the second part's type differs from it (case-insensitive); missing-micalg, or micalg-mismatch when a protocol exists and the micalg family disagrees (pgp-* exactly when the protocol is application/pgp-signature); unprotected-8bit when the signed first part uses 8bit or binary transfer encoding.

Why this case matters

Signed mail is only verifiable when its structure is exact; lax checks accept tampered or unverifiable messages.

1 / The failure

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(node):
    if node['type'].lower() != 'multipart/signed':
        return ['not-signed']
    issues = []
    params = {k.lower(): v for k, v in node.get('params', {}).items()}
    proto = (params.get('protocol') or '').lower()
    if not proto:
        issues.append('missing-protocol')
    parts = node.get('parts', [])
    if len(parts) != 2:
        issues.append('part-count')
        return issues
    if parts[1]['type'].lower() != proto:
        issues.append('protocol-mismatch')
    micalg = (params.get('micalg') or '').lower()
    if not micalg:
        issues.append('missing-micalg')
    elif proto and micalg.startswith('pgp-') != (proto == 'application/pgp-signature'):
        issues.append('micalg-mismatch')
    if (parts[0].get('cte') or '7bit').lower() in ('8bit', 'binary'):
        issues.append('unprotected-8bit')
    return issues
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
_CASES = {1: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 2: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 3: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha128'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 4: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 5: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])]}
for _label, _args, _expected in _CASES[N]:
    check(_label, solve(*_args), _expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
mixed-case parameter names[][]Passed
extra third part['part-count']['part-count']Passed
mixed-case protocol and part type[][]Passed
S/MIME signature[][]Passed
cross-family micalg['micalg-mismatch']['micalg-mismatch']Passed
8bit signed content['unprotected-8bit']['unprotected-8bit']Passed
binary signed content['unprotected-8bit']['unprotected-8bit']Passed
missing protocol with S/MIME part['missing-protocol', 'protocol-mismatch']['missing-protocol']Failed
not signed['not-signed']['not-signed']Passed

SHA-256 / 3a01007509971b7e7c34d2a8dff9f277af8f91a9c828368c21902035b1e3a117

2 / The unsuccessful fix

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(node):
    if node['type'].lower() != 'multipart/signed':
        return ['not-signed']
    issues = []
    params = {k.lower(): v for k, v in node.get('params', {}).items()}
    proto = (params.get('protocol') or '').lower()
    if not proto:
        issues.append('missing-protocol')
    parts = node.get('parts', [])
    if len(parts) != 2:
        issues.append('part-count')
        return issues
    if parts[1]['type'].lower() != (proto or 'application/pgp-signature'):
        issues.append('protocol-mismatch')
    micalg = (params.get('micalg') or '').lower()
    if not micalg:
        issues.append('missing-micalg')
    elif proto and micalg.startswith('pgp-') != (proto == 'application/pgp-signature'):
        issues.append('micalg-mismatch')
    if (parts[0].get('cte') or '7bit').lower() in ('8bit', 'binary'):
        issues.append('unprotected-8bit')
    return issues
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
_CASES = {1: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 2: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 3: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha128'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 4: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 5: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])]}
for _label, _args, _expected in _CASES[N]:
    check(_label, solve(*_args), _expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
mixed-case parameter names[][]Passed
extra third part['part-count']['part-count']Passed
mixed-case protocol and part type[][]Passed
S/MIME signature[][]Passed
cross-family micalg['micalg-mismatch']['micalg-mismatch']Passed
8bit signed content['unprotected-8bit']['unprotected-8bit']Passed
binary signed content['unprotected-8bit']['unprotected-8bit']Passed
missing protocol with S/MIME part['missing-protocol', 'protocol-mismatch']['missing-protocol']Failed
not signed['not-signed']['not-signed']Passed

SHA-256 / 9ff487518ca7d3514162ea4091f1b9a9be3004a4e5e21b3199dd233629b9c12e

3 / The verified repair

Exit 0
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(node):
    if node['type'].lower() != 'multipart/signed':
        return ['not-signed']
    issues = []
    params = {k.lower(): v for k, v in node.get('params', {}).items()}
    proto = (params.get('protocol') or '').lower()
    if not proto:
        issues.append('missing-protocol')
    parts = node.get('parts', [])
    if len(parts) != 2:
        issues.append('part-count')
        return issues
    if proto and parts[1]['type'].lower() != proto:
        issues.append('protocol-mismatch')
    micalg = (params.get('micalg') or '').lower()
    if not micalg:
        issues.append('missing-micalg')
    elif proto and micalg.startswith('pgp-') != (proto == 'application/pgp-signature'):
        issues.append('micalg-mismatch')
    if (parts[0].get('cte') or '7bit').lower() in ('8bit', 'binary'):
        issues.append('unprotected-8bit')
    return issues
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
_CASES = {1: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 2: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 3: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha128'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 4: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])], 5: [('mixed-case parameter names', ({'type': 'multipart/signed', 'params': {'Protocol': 'application/pgp-signature', 'MICALG': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), []), ('extra third part', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}, {'type': 'image/png'}]},), ['part-count']), ('mixed-case protocol and part type', ({'type': 'multipart/signed', 'params': {'protocol': 'Application/pgp-signature', 'micalg': 'pgp-sha512'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/PGP-signature'}]},), []), ('S/MIME signature', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pkcs7-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'multipart/mixed'}, {'type': 'application/pkcs7-signature'}]},), []), ('cross-family micalg', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), ['micalg-mismatch']), ('8bit signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': '8bit'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('binary signed content', ({'type': 'multipart/signed', 'params': {'protocol': 'application/pgp-signature', 'micalg': 'pgp-sha256'}, 'parts': [{'type': 'text/plain', 'cte': 'BINARY'}, {'type': 'application/pgp-signature'}]},), ['unprotected-8bit']), ('missing protocol with S/MIME part', ({'type': 'multipart/signed', 'params': {'micalg': 'sha-256'}, 'parts': [{'type': 'text/plain'}, {'type': 'application/pkcs7-signature'}]},), ['missing-protocol']), ('not signed', ({'type': 'multipart/mixed', 'parts': []},), ['not-signed'])]}
for _label, _args, _expected in _CASES[N]:
    check(_label, solve(*_args), _expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
mixed-case parameter names[][]Passed
extra third part['part-count']['part-count']Passed
mixed-case protocol and part type[][]Passed
S/MIME signature[][]Passed
cross-family micalg['micalg-mismatch']['micalg-mismatch']Passed
8bit signed content['unprotected-8bit']['unprotected-8bit']Passed
binary signed content['unprotected-8bit']['unprotected-8bit']Passed
missing protocol with S/MIME part['missing-protocol']['missing-protocol']Passed
not signed['not-signed']['not-signed']Passed

SHA-256 / 2a5d93fad294dc0b9ce96dca553f5c817a84b85ecfd8cddfd2cb3579b17d87a0

Verification & scope

Stipulated offline model over pre-parsed MIME dictionaries; not a conforming MIME parser, generator or mail client. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.

Observations recorded using Python 3.12.14 at 2026-09-29T14:49:18.019860+00:00.

Case digest / e5ba6c6d1579cc64cab02ae066f5e2f1900bc1c71ad1015784c8099d7bd694f9