Greetings,

This is my first time posting to this list.  I'm one of the authors on the 
DKIM2 spec, and I'm keen to have mailman support DKIM2 even in the early drafts.

I've been working on DKIM2 support for Mailman for a little while, there's a 
patched copy running on mailman.dkim2.com with my patches, and branches on top 
of master, 3.3.10 and 3.3.8 in my fork at https://github.com/brong/mailman

*DKIM2*

The IETF DKIM working group is working on DKIM2, a replacement for DKIM and 
ARC.  At this stage, the working group believes that the draft specification at 
https://datatracker.ietf.org/doc/draft-ietf-dkim-dkim2-spec/ is in a fit state 
for interoperability testing.

DKIM2 has three important new properties:
 • Envelope addresses are signed (fixes DKIM replay); at every hop
 • Envelope from aligns with signing domain (fixes backscatter)
 • Changes are reversible and described by a recipe (not need to trust 
intermediates, you can verify
The proposed changes to Mailman in order to support DKIM2 are focused very much 
on the last one, the recipes.  Since you have to describe the changes you are 
making, it is sensible to make the minimum possible changes!

To this end, there are a couple of pre-cursor changes.  I'm just pasting the 
commit message here, since it describes what's involved pretty well.  It think 
these are good changes regardless of DKIM2.

 *Preserve the original Content-Transfer-Encoding when decorating*

    When a header or footer is added to a single-part text message, keep the
    body's existing encoding instead of letting the email library choose a
    new one and silently re-encode every line:

    - 7bit/8bit: concatenate the decoded text and store the result with the
      same CTE, upgrading 7bit to 8bit only if the result contains high
      bytes.

    - quoted-printable: concatenate at the raw QP level.  Only the header
      and footer text is freshly QP-encoded; the original body lines remain
      byte-identical, including unnecessarily quoted characters (=48 for
      'H') and non-standard soft line break positions.

    - base64: decode, concatenate, and re-encode at the line width the
      original used.  Base64 is deterministic, so every complete line before
      the original's last line is unchanged; only that last line (its
      padding disappears) and the appended footer lines differ.  The message
      stays single-part instead of being MIME-wrapped into multipart/mixed.

    Any other CTE, or a failure in one of these paths, falls through to MIME
    wrapping as before.  The decorate.rst doctest for mixed-charset messages
    is updated for the QP-preserving behaviour.

diffstat:
 decorate.py       |  165 
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++-------------------------
 docs/decorate.rst |   14 ++++++++++----
 2 files changed, 150 insertions(+), 29 deletions(-)

Then of course there's the DKIM2 changes themselves, which track what was 
edited and build a "Message-Instance" header describing the changes, this is a 
bigger set of code changes:

 DKIM2-MESSAGE-INSTANCE.md                           |  215 +++++++++++++++++++
 src/mailman/config/schema.cfg                       |    7
 src/mailman/handlers/message_instance.py            | 1275 
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
 src/mailman/handlers/tests/test_message_instance.py | 1733 
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
 src/mailman/handlers/tests/test_mi_null_recipe.py   |   34 +++
 src/mailman/handlers/tests/test_mi_roundtrip.py     |  241 
+++++++++++++++++++++
 src/mailman/mta/bulk.py                             |    5
 src/mailman/mta/deliver.py                          |    5
 src/mailman/mta/message_instance.py                 |   31 ++
 src/mailman/pipelines/builtin.py                    |    2
 10 files changed, 3546 insertions(+), 2 deletions(-)

It's mostly just a couple of hook locations for the changes, and a new file 
which calculates the message-instance.  Plus a chunk of tests.

NOTE: this is largely Claude's work, with me guiding the output and reviewing 
the shape, but not the raw code itself.  I'm prepared to spend more time on 
human review and making this high quality if the project is willing to take my 
work on it.

Cheers,

Bron.

--
  Bron Gondwana, CEO, Fastmail Pty Ltd / Fastmail US LLC
  [email protected]
_______________________________________________
Mailman-Developers mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://mail.python.org/mailman3/lists/mailman-developers.python.org/
Mailman FAQ: https://wiki.list.org/x/AgA3

Security Policy: https://wiki.list.org/x/QIA9

Reply via email to