FA-76781 / Email MIME structure / Open access
Inject a mailing-list footer without breaking the message: encoded body wrap · case 01
A footer is appended as plain text to a base64-encoded body, corrupting its last block.
ROOT CAUSE
The encoded body wrap decision evaluates `cte != 'binary'` where the contract requires `cte in ('7bit', '8bit', 'quoted-printable')`.
VERIFIED REPAIR
Use `cte in ('7bit', '8bit', 'quoted-printable')` for the encoded body wrap decision and keep every other rule of the model unchanged.
Unsuccessful approach: Wrapping quoted-printable bodies is unnecessary; the contract appends to them in place. The attempted `cte in ('7bit', '8bit')` still disagrees with a fixture.
Case contract
A top-level text/plain body in 7bit, 8bit or quoted-printable (default 7bit, case-insensitive) gets the footer appended in place ("text+footer"). A multipart/mixed gets a text/plain footer part appended after its children. Everything else (alternative, signed, encrypted, html, base64 text) is wrapped: mixed(<type>,text/plain). Output is a compact structure string.
Why this case matters
List managers that edit signed or encoded bodies in place break signatures and corrupt content.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(node):
t = node['type'].lower()
cte = (node.get('cte') or '7bit').lower()
if t == 'text/plain' and cte != 'binary':
return 'text+footer'
if t == 'multipart/mixed':
return 'mixed(' + ','.join(c['type'].lower() for c in node['parts']) + ',text/plain)'
return 'mixed(' + t + ',text/plain)'
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
_CASES = {1: [('base64 text body', ({'type': 'text/plain', 'cte': 'BASE64'},), 'mixed(text/plain,text/plain)'), ('quoted-printable text body', ({'type': 'text/plain', 'cte': 'quoted-printable'},), 'text+footer'), ('signed message', ({'type': 'multipart/signed', 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), 'mixed(multipart/signed,text/plain)'), ('encrypted message', ({'type': 'multipart/encrypted', 'parts': [{'type': 'application/pgp-encrypted'}, {'type': 'application/octet-stream'}]},), 'mixed(multipart/encrypted,text/plain)'), ('html body', ({'type': 'text/html'},), 'mixed(text/html,text/plain)'), ('enriched body', ({'type': 'text/enriched', 'cte': '7bit'},), 'mixed(text/enriched,text/plain)'), ('mixed message', ({'type': 'multipart/mixed', 'parts': [{'type': 'text/plain'}, {'type': 'image/png'}]},), 'mixed(text/plain,image/png,text/plain)')], 2: [('base64 text body', ({'type': 'text/plain', 'cte': 'BASE64'},), 'mixed(text/plain,text/plain)'), ('quoted-printable text body', ({'type': 'text/plain', 'cte': 'quoted-printable'},), 'text+footer'), ('signed message', ({'type': 'multipart/signed', 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), 'mixed(multipart/signed,text/plain)'), ('encrypted message', ({'type': 'multipart/encrypted', 'parts': [{'type': 'application/pgp-encrypted'}, {'type': 'application/octet-stream'}]},), 'mixed(multipart/encrypted,text/plain)'), ('html body', ({'type': 'text/html'},), 'mixed(text/html,text/plain)'), ('enriched body', ({'type': 'text/enriched', 'cte': '7bit'},), 'mixed(text/enriched,text/plain)'), ('mixed message', ({'type': 'multipart/mixed', 'parts': [{'type': 'text/plain'}, {'type': 'image/png'}, {'type': 'image/png'}]},), 'mixed(text/plain,image/png,image/png,text/plain)')], 3: [('base64 text body', ({'type': 'text/plain', 'cte': 'BASE64'},), 'mixed(text/plain,text/plain)'), ('quoted-printable text body', ({'type': 'text/plain', 'cte': 'quoted-printable'},), 'text+footer'), ('signed message', ({'type': 'multipart/signed', 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), 'mixed(multipart/signed,text/plain)'), ('encrypted message', ({'type': 'multipart/encrypted', 'parts': [{'type': 'application/pgp-encrypted'}, {'type': 'application/octet-stream'}]},), 'mixed(multipart/encrypted,text/plain)'), ('html body', ({'type': 'text/html'},), 'mixed(text/html,text/plain)'), ('enriched body', ({'type': 'text/enriched', 'cte': '7bit'},), 'mixed(text/enriched,text/plain)'), ('mixed message', ({'type': 'multipart/mixed', 'parts': [{'type': 'text/plain'}, {'type': 'image/png'}, {'type': 'image/png'}, {'type': 'image/png'}]},), 'mixed(text/plain,image/png,image/png,image/png,text/plain)')], 4: [('base64 text body', ({'type': 'text/plain', 'cte': 'BASE64'},), 'mixed(text/plain,text/plain)'), ('quoted-printable text body', ({'type': 'text/plain', 'cte': 'quoted-printable'},), 'text+footer'), ('signed message', ({'type': 'multipart/signed', 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), 'mixed(multipart/signed,text/plain)'), ('encrypted message', ({'type': 'multipart/encrypted', 'parts': [{'type': 'application/pgp-encrypted'}, {'type': 'application/octet-stream'}]},), 'mixed(multipart/encrypted,text/plain)'), ('html body', ({'type': 'text/html'},), 'mixed(text/html,text/plain)'), ('enriched body', ({'type': 'text/enriched', 'cte': '7bit'},), 'mixed(text/enriched,text/plain)'), ('mixed message', ({'type': 'multipart/mixed', 'parts': [{'type': 'text/plain'}, {'type': 'image/png'}, {'type': 'image/png'}, {'type': 'image/png'}, {'type': 'image/png'}]},), 'mixed(text/plain,image/png,image/png,image/png,image/png,text/plain)')], 5: [('base64 text body', ({'type': 'text/plain', 'cte': 'BASE64'},), 'mixed(text/plain,text/plain)'), ('quoted-printable text body', ({'type': 'text/plain', 'cte': 'quoted-printable'},), 'text+footer'), ('signed message', ({'type': 'multipart/signed', 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), 'mixed(multipart/signed,text/plain)'), ('encrypted message', ({'type': 'multipart/encrypted', 'parts': [{'type': 'application/pgp-encrypted'}, {'type': 'application/octet-stream'}]},), 'mixed(multipart/encrypted,text/plain)'), ('html body', ({'type': 'text/html'},), 'mixed(text/html,text/plain)'), ('enriched body', ({'type': 'text/enriched', 'cte': '7bit'},), 'mixed(text/enriched,text/plain)'), ('mixed message', ({'type': 'multipart/mixed', 'parts': [{'type': 'text/plain'}, {'type': 'image/png'}, {'type': 'image/png'}, {'type': 'image/png'}, {'type': 'image/png'}, {'type': 'image/png'}]},), 'mixed(text/plain,image/png,image/png,image/png,image/png,image/png,text/plain)')]}
for _label, _args, _expected in _CASES[N]:
check(_label, solve(*_args), _expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| base64 text body | text+footer | mixed(text/plain,text/plain) | Failed |
| quoted-printable text body | text+footer | text+footer | Passed |
| signed message | mixed(multipart/signed,text/plain) | mixed(multipart/signed,text/plain) | Passed |
| encrypted message | mixed(multipart/encrypted,text/plain) | mixed(multipart/encrypted,text/plain) | Passed |
| html body | mixed(text/html,text/plain) | mixed(text/html,text/plain) | Passed |
| enriched body | mixed(text/enriched,text/plain) | mixed(text/enriched,text/plain) | Passed |
| mixed message | mixed(text/plain,image/png,text/plain) | mixed(text/plain,image/png,text/plain) | Passed |
SHA-256 / 88de792aaff41f037f70ab267245d820eef72554f3a087df6fb54d0e51cb3df9
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(node):
t = node['type'].lower()
cte = (node.get('cte') or '7bit').lower()
if t == 'text/plain' and cte in ('7bit', '8bit'):
return 'text+footer'
if t == 'multipart/mixed':
return 'mixed(' + ','.join(c['type'].lower() for c in node['parts']) + ',text/plain)'
return 'mixed(' + t + ',text/plain)'
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
_CASES = {1: [('base64 text body', ({'type': 'text/plain', 'cte': 'BASE64'},), 'mixed(text/plain,text/plain)'), ('quoted-printable text body', ({'type': 'text/plain', 'cte': 'quoted-printable'},), 'text+footer'), ('signed message', ({'type': 'multipart/signed', 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), 'mixed(multipart/signed,text/plain)'), ('encrypted message', ({'type': 'multipart/encrypted', 'parts': [{'type': 'application/pgp-encrypted'}, {'type': 'application/octet-stream'}]},), 'mixed(multipart/encrypted,text/plain)'), ('html body', ({'type': 'text/html'},), 'mixed(text/html,text/plain)'), ('enriched body', ({'type': 'text/enriched', 'cte': '7bit'},), 'mixed(text/enriched,text/plain)'), ('mixed message', ({'type': 'multipart/mixed', 'parts': [{'type': 'text/plain'}, {'type': 'image/png'}]},), 'mixed(text/plain,image/png,text/plain)')], 2: [('base64 text body', ({'type': 'text/plain', 'cte': 'BASE64'},), 'mixed(text/plain,text/plain)'), ('quoted-printable text body', ({'type': 'text/plain', 'cte': 'quoted-printable'},), 'text+footer'), ('signed message', ({'type': 'multipart/signed', 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), 'mixed(multipart/signed,text/plain)'), ('encrypted message', ({'type': 'multipart/encrypted', 'parts': [{'type': 'application/pgp-encrypted'}, {'type': 'application/octet-stream'}]},), 'mixed(multipart/encrypted,text/plain)'), ('html body', ({'type': 'text/html'},), 'mixed(text/html,text/plain)'), ('enriched body', ({'type': 'text/enriched', 'cte': '7bit'},), 'mixed(text/enriched,text/plain)'), ('mixed message', ({'type': 'multipart/mixed', 'parts': [{'type': 'text/plain'}, {'type': 'image/png'}, {'type': 'image/png'}]},), 'mixed(text/plain,image/png,image/png,text/plain)')], 3: [('base64 text body', ({'type': 'text/plain', 'cte': 'BASE64'},), 'mixed(text/plain,text/plain)'), ('quoted-printable text body', ({'type': 'text/plain', 'cte': 'quoted-printable'},), 'text+footer'), ('signed message', ({'type': 'multipart/signed', 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), 'mixed(multipart/signed,text/plain)'), ('encrypted message', ({'type': 'multipart/encrypted', 'parts': [{'type': 'application/pgp-encrypted'}, {'type': 'application/octet-stream'}]},), 'mixed(multipart/encrypted,text/plain)'), ('html body', ({'type': 'text/html'},), 'mixed(text/html,text/plain)'), ('enriched body', ({'type': 'text/enriched', 'cte': '7bit'},), 'mixed(text/enriched,text/plain)'), ('mixed message', ({'type': 'multipart/mixed', 'parts': [{'type': 'text/plain'}, {'type': 'image/png'}, {'type': 'image/png'}, {'type': 'image/png'}]},), 'mixed(text/plain,image/png,image/png,image/png,text/plain)')], 4: [('base64 text body', ({'type': 'text/plain', 'cte': 'BASE64'},), 'mixed(text/plain,text/plain)'), ('quoted-printable text body', ({'type': 'text/plain', 'cte': 'quoted-printable'},), 'text+footer'), ('signed message', ({'type': 'multipart/signed', 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), 'mixed(multipart/signed,text/plain)'), ('encrypted message', ({'type': 'multipart/encrypted', 'parts': [{'type': 'application/pgp-encrypted'}, {'type': 'application/octet-stream'}]},), 'mixed(multipart/encrypted,text/plain)'), ('html body', ({'type': 'text/html'},), 'mixed(text/html,text/plain)'), ('enriched body', ({'type': 'text/enriched', 'cte': '7bit'},), 'mixed(text/enriched,text/plain)'), ('mixed message', ({'type': 'multipart/mixed', 'parts': [{'type': 'text/plain'}, {'type': 'image/png'}, {'type': 'image/png'}, {'type': 'image/png'}, {'type': 'image/png'}]},), 'mixed(text/plain,image/png,image/png,image/png,image/png,text/plain)')], 5: [('base64 text body', ({'type': 'text/plain', 'cte': 'BASE64'},), 'mixed(text/plain,text/plain)'), ('quoted-printable text body', ({'type': 'text/plain', 'cte': 'quoted-printable'},), 'text+footer'), ('signed message', ({'type': 'multipart/signed', 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), 'mixed(multipart/signed,text/plain)'), ('encrypted message', ({'type': 'multipart/encrypted', 'parts': [{'type': 'application/pgp-encrypted'}, {'type': 'application/octet-stream'}]},), 'mixed(multipart/encrypted,text/plain)'), ('html body', ({'type': 'text/html'},), 'mixed(text/html,text/plain)'), ('enriched body', ({'type': 'text/enriched', 'cte': '7bit'},), 'mixed(text/enriched,text/plain)'), ('mixed message', ({'type': 'multipart/mixed', 'parts': [{'type': 'text/plain'}, {'type': 'image/png'}, {'type': 'image/png'}, {'type': 'image/png'}, {'type': 'image/png'}, {'type': 'image/png'}]},), 'mixed(text/plain,image/png,image/png,image/png,image/png,image/png,text/plain)')]}
for _label, _args, _expected in _CASES[N]:
check(_label, solve(*_args), _expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| base64 text body | mixed(text/plain,text/plain) | mixed(text/plain,text/plain) | Passed |
| quoted-printable text body | mixed(text/plain,text/plain) | text+footer | Failed |
| signed message | mixed(multipart/signed,text/plain) | mixed(multipart/signed,text/plain) | Passed |
| encrypted message | mixed(multipart/encrypted,text/plain) | mixed(multipart/encrypted,text/plain) | Passed |
| html body | mixed(text/html,text/plain) | mixed(text/html,text/plain) | Passed |
| enriched body | mixed(text/enriched,text/plain) | mixed(text/enriched,text/plain) | Passed |
| mixed message | mixed(text/plain,image/png,text/plain) | mixed(text/plain,image/png,text/plain) | Passed |
SHA-256 / 193776c1f3a1a58b9b9e4ea0fe507607fffd4c7bc8b67114175b2b55be3fa480
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(node):
t = node['type'].lower()
cte = (node.get('cte') or '7bit').lower()
if t == 'text/plain' and cte in ('7bit', '8bit', 'quoted-printable'):
return 'text+footer'
if t == 'multipart/mixed':
return 'mixed(' + ','.join(c['type'].lower() for c in node['parts']) + ',text/plain)'
return 'mixed(' + t + ',text/plain)'
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
_CASES = {1: [('base64 text body', ({'type': 'text/plain', 'cte': 'BASE64'},), 'mixed(text/plain,text/plain)'), ('quoted-printable text body', ({'type': 'text/plain', 'cte': 'quoted-printable'},), 'text+footer'), ('signed message', ({'type': 'multipart/signed', 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), 'mixed(multipart/signed,text/plain)'), ('encrypted message', ({'type': 'multipart/encrypted', 'parts': [{'type': 'application/pgp-encrypted'}, {'type': 'application/octet-stream'}]},), 'mixed(multipart/encrypted,text/plain)'), ('html body', ({'type': 'text/html'},), 'mixed(text/html,text/plain)'), ('enriched body', ({'type': 'text/enriched', 'cte': '7bit'},), 'mixed(text/enriched,text/plain)'), ('mixed message', ({'type': 'multipart/mixed', 'parts': [{'type': 'text/plain'}, {'type': 'image/png'}]},), 'mixed(text/plain,image/png,text/plain)')], 2: [('base64 text body', ({'type': 'text/plain', 'cte': 'BASE64'},), 'mixed(text/plain,text/plain)'), ('quoted-printable text body', ({'type': 'text/plain', 'cte': 'quoted-printable'},), 'text+footer'), ('signed message', ({'type': 'multipart/signed', 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), 'mixed(multipart/signed,text/plain)'), ('encrypted message', ({'type': 'multipart/encrypted', 'parts': [{'type': 'application/pgp-encrypted'}, {'type': 'application/octet-stream'}]},), 'mixed(multipart/encrypted,text/plain)'), ('html body', ({'type': 'text/html'},), 'mixed(text/html,text/plain)'), ('enriched body', ({'type': 'text/enriched', 'cte': '7bit'},), 'mixed(text/enriched,text/plain)'), ('mixed message', ({'type': 'multipart/mixed', 'parts': [{'type': 'text/plain'}, {'type': 'image/png'}, {'type': 'image/png'}]},), 'mixed(text/plain,image/png,image/png,text/plain)')], 3: [('base64 text body', ({'type': 'text/plain', 'cte': 'BASE64'},), 'mixed(text/plain,text/plain)'), ('quoted-printable text body', ({'type': 'text/plain', 'cte': 'quoted-printable'},), 'text+footer'), ('signed message', ({'type': 'multipart/signed', 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), 'mixed(multipart/signed,text/plain)'), ('encrypted message', ({'type': 'multipart/encrypted', 'parts': [{'type': 'application/pgp-encrypted'}, {'type': 'application/octet-stream'}]},), 'mixed(multipart/encrypted,text/plain)'), ('html body', ({'type': 'text/html'},), 'mixed(text/html,text/plain)'), ('enriched body', ({'type': 'text/enriched', 'cte': '7bit'},), 'mixed(text/enriched,text/plain)'), ('mixed message', ({'type': 'multipart/mixed', 'parts': [{'type': 'text/plain'}, {'type': 'image/png'}, {'type': 'image/png'}, {'type': 'image/png'}]},), 'mixed(text/plain,image/png,image/png,image/png,text/plain)')], 4: [('base64 text body', ({'type': 'text/plain', 'cte': 'BASE64'},), 'mixed(text/plain,text/plain)'), ('quoted-printable text body', ({'type': 'text/plain', 'cte': 'quoted-printable'},), 'text+footer'), ('signed message', ({'type': 'multipart/signed', 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), 'mixed(multipart/signed,text/plain)'), ('encrypted message', ({'type': 'multipart/encrypted', 'parts': [{'type': 'application/pgp-encrypted'}, {'type': 'application/octet-stream'}]},), 'mixed(multipart/encrypted,text/plain)'), ('html body', ({'type': 'text/html'},), 'mixed(text/html,text/plain)'), ('enriched body', ({'type': 'text/enriched', 'cte': '7bit'},), 'mixed(text/enriched,text/plain)'), ('mixed message', ({'type': 'multipart/mixed', 'parts': [{'type': 'text/plain'}, {'type': 'image/png'}, {'type': 'image/png'}, {'type': 'image/png'}, {'type': 'image/png'}]},), 'mixed(text/plain,image/png,image/png,image/png,image/png,text/plain)')], 5: [('base64 text body', ({'type': 'text/plain', 'cte': 'BASE64'},), 'mixed(text/plain,text/plain)'), ('quoted-printable text body', ({'type': 'text/plain', 'cte': 'quoted-printable'},), 'text+footer'), ('signed message', ({'type': 'multipart/signed', 'parts': [{'type': 'text/plain'}, {'type': 'application/pgp-signature'}]},), 'mixed(multipart/signed,text/plain)'), ('encrypted message', ({'type': 'multipart/encrypted', 'parts': [{'type': 'application/pgp-encrypted'}, {'type': 'application/octet-stream'}]},), 'mixed(multipart/encrypted,text/plain)'), ('html body', ({'type': 'text/html'},), 'mixed(text/html,text/plain)'), ('enriched body', ({'type': 'text/enriched', 'cte': '7bit'},), 'mixed(text/enriched,text/plain)'), ('mixed message', ({'type': 'multipart/mixed', 'parts': [{'type': 'text/plain'}, {'type': 'image/png'}, {'type': 'image/png'}, {'type': 'image/png'}, {'type': 'image/png'}, {'type': 'image/png'}]},), 'mixed(text/plain,image/png,image/png,image/png,image/png,image/png,text/plain)')]}
for _label, _args, _expected in _CASES[N]:
check(_label, solve(*_args), _expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| base64 text body | mixed(text/plain,text/plain) | mixed(text/plain,text/plain) | Passed |
| quoted-printable text body | text+footer | text+footer | Passed |
| signed message | mixed(multipart/signed,text/plain) | mixed(multipart/signed,text/plain) | Passed |
| encrypted message | mixed(multipart/encrypted,text/plain) | mixed(multipart/encrypted,text/plain) | Passed |
| html body | mixed(text/html,text/plain) | mixed(text/html,text/plain) | Passed |
| enriched body | mixed(text/enriched,text/plain) | mixed(text/enriched,text/plain) | Passed |
| mixed message | mixed(text/plain,image/png,text/plain) | mixed(text/plain,image/png,text/plain) | Passed |
SHA-256 / aa0cf18ed62290d1a299e4e3f7be4f347f873cdf7f2a15ecedfe487c48f1cd52
Verification & scope
Stipulated offline model over pre-parsed MIME dictionaries; not a conforming MIME parser, generator or mail client. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:49:19.350171+00:00.
Case digest / 974262b701ac73ef806b4620607e305b806b237399436f811b9423323643b52a