Skip to content

email.utils.decode_params misinterprets apostrophes in unencoded RFC 2231 initial segments #158712

Description

@augusto-rehfeldt

Bug report

Bug description:

Documented behaviour: The email.utils.decode_params documentation promises: "Decode parameters list according to RFC 2231." RFC 2231 section 4 places charset and language information in the initial encoded segment; an unencoded initial segment contains ordinary parameter text.

Expected: [('text/plain', ''), ('filename', (None, None, '"a'b'c"'))]

Actual: [('text/plain', ''), ('filename', ('a', 'b', '"c"'))]

import email.utils as u
import re
from urllib.parse import unquote

p = [('text/plain', ''), ('filename*0', "a'b'"), ('filename*1*', '%63')]
# RFC 2231: contiguous segments; only the starred segment is encoded.
valid = (p[0] == ('text/plain', '') and
         [k for k, v in p[1:]] == ['filename*0', 'filename*1*'] and
         re.fullmatch(r"[A-Za-z0-9']+", p[1][1]) and
         re.fullmatch(r"(?:%[0-9a-fA-F]{2})+", p[2][1]))
if not valid:
    print('REFUTATION REJECTED: invalid RFC 2231 input')
else:
    value = p[1][1] + unquote(p[2][1])
    quoted = '"' + value.replace('\\', '\\\\').replace('"', '\\"') + '"'
    expected = [p[0], ('filename', (None, None, quoted))]
    actual = u.decode_params(p.copy())
    if actual != expected:
        print('REFUTATION CONFIRMED:', 'input=', repr(p),
              'actual=', repr(actual), 'expected=', repr(expected))
    else:
        print('REFUTATION REJECTED: actual matches documented expectation')

Output on Python 3.14.6 (Windows-11-10.0.26220-SP0), standard library email.utils:

REFUTATION CONFIRMED: input= [('text/plain', ''), ('filename*0', "a'b'"), ('filename*1*', '%63')] actual= [('text/plain', ''), ('filename', ('a', 'b', '"c"'))] expected= [('text/plain', ''), ('filename', (None, None, '"a\'b\'c"'))]

This report was found and written by an automated property-testing tool I run (bugforge). The reproducer above was executed and its output is pasted unedited; no person reviewed the report before it was filed. The search script is in https://github.com/augusto-rehfeldt/bugforge-results/tree/main/email.utils-20261003-060025-c2

CPython versions tested on:

3.14

Operating systems tested on:

Windows

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions