git-send-email: use sanitized address when reading mbox body

Addresses that are mentioned on the trailers in the commit log messages (e.g., "Reviewed-by") are added to the "Cc:" list by "git send-email". These hand-written addresses, however, may be malformed (e.g., having unquoted "." and other punctutation marks in the display-name part) and can upset MTA. The code does use the sanitize_address() helper on these address-looking strings to turn them into valid addresses, but it is used only to see if the address should be suppressed. The original string taken from the message is added to the @cc list if the code decides the address is not suppressed. Because the addresses on trailer lines are hand-written and more likely to contain malformed addresses, when adding to the @cc list, use the result from sanitize_address, not the original. Note that we do not modify the behaviour for addresses taken from the e-mail headers, as they are more likely to be machine generated and well-formed. Signed-off-by: Csókás, Bence <csokas.bence@prolan.hu> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Csókás, Bence committed Jul 1, 2024 at 11:01 UTC c852531f451331eb9d5ba57d154b0e150246a438
2 files changed +45 -2
git-send-email.perl
+2 -2
@@ -1844,9 +1844,9 @@ sub pre_process_file {
1844 $what, $_) unless $quiet;
1845 next;
1846 }
1847 - push @cc, $c;
1847 + push @cc, $sc;
1848 printf(__("(body) Adding cc: %s from line '%s'\n"),
1849 - $c, $_) unless $quiet;
1849 + $sc, $_) unless $quiet;
1850 }
1851 }
1852 close $fh;
t/t9001-send-email.sh
+43
@@ -1299,6 +1299,49 @@ test_expect_success $PREREQ 'utf8 sender is not duplicated' '
1299 test_line_count = 1 msgfrom
1300 '
1301
1302 +test_expect_success $PREREQ 'setup expect for cc list' "
1303 +cat >expected-cc <<\EOF
1304 +!recipient@example.com!
1305 +!author@example.com!
1306 +!one@example.com!
1307 +!os@example.com!
1308 +!odd_?=mail@example.com!
1309 +!doug@example.com!
1310 +!codev@example.com!
1311 +!thor.au@example.com!
1312 +EOF
1313 +"
1314 +
1315 +test_expect_success $PREREQ 'cc list is sanitized' '
1316 + clean_fake_sendmail &&
1317 + test_commit weird_cc_body &&
1318 + test_when_finished "git reset --hard HEAD^" &&
1319 + git commit --amend -F - <<-EOF &&
1320 + Test Cc: sanitization.
1321 +
1322 + Cc: Person, One <one@example.com>
1323 + Cc: Ronnie O${SQ}Sullivan <os@example.com>
1324 + Reviewed-by: Füñný Nâmé <odd_?=mail@example.com>
1325 + Reported-by: bugger on Jira
1326 + Reported-by: Douglas Reporter <doug@example.com> [from Jira profile]
1327 + BugID: 12345
1328 + Co-developed-by: "C. O. Developer" <codev@example.com>
1329 + Signed-off-by: A. U. Thor <thor.au@example.com>
1330 + EOF
1331 + git send-email -1 --to=recipient@example.com \
1332 + --smtp-server="$(pwd)/fake.sendmail" >actual-show-all-headers &&
1333 + test_cmp expected-cc commandline1 &&
1334 + test_grep "^(body) Adding cc: \"Person, One\" <one@example.com>" actual-show-all-headers &&
1335 + test_grep "^(body) Adding cc: Ronnie O${SQ}Sullivan <os@example.com>" actual-show-all-headers &&
1336 + test_grep "^(body) Adding cc: =?UTF-8?q?F=C3=BC=C3=B1n=C3=BD=20N=C3=A2m=C3=A9?="\
1337 +" <odd_?=mail@example.com>" actual-show-all-headers &&
1338 + test_grep "^(body) Ignoring Reported-by .* bugger on Jira" actual-show-all-headers &&
1339 + test_grep "^(body) Adding cc: Douglas Reporter <doug@example.com>" actual-show-all-headers &&
1340 + test_grep ! "12345" actual-show-all-headers &&
1341 + test_grep "^(body) Adding cc: \"C. O. Developer\" <codev@example.com>" actual-show-all-headers &&
1342 + test_grep "^(body) Adding cc: \"A. U. Thor\" <thor.au@example.com>" actual-show-all-headers
1343 +'
1344 +
1345 test_expect_success $PREREQ 'sendemail.composeencoding works' '
1346 clean_fake_sendmail &&
1347 git config sendemail.composeencoding iso-8859-1 &&