python / python/cpython

smtplib.quoteaddr() returns malformed angle-bracket address for input '<'

未关闭
#145,552 4 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

stdlib topic-email type-bug
主要语言
Python
星标
77.2k
派生
35.9k
PR 合并指标
PR 指标待抓取

描述

Bug report

Description

smtplib.quoteaddr() formats addresses for SMTP MAIL FROM: and RCPT TO: commands per RFC 821, which requires angle-bracket format (<addr>). It first delegates to email.utils.parseaddr(); when parsing succeeds, the result is correctly wrapped in <...>.

When parseaddr fails — which happens for inputs that don't resemble any recognizable email address format, like '<', '< ', or '@' — a fallback path kicks in. The fallback checks if the input starts with < and returns it verbatim, without verifying it also ends with >. This produces structurally invalid output (e.g. MAIL FROM:< instead of MAIL FROM:<>).

The existing code intentionally chooses to be lenient with unparseable input rather than raising an exception (the comment reads "use it as is and hope for the best"). Given that design choice, the output should at least be structurally valid — a half-open < with no > is neither rejecting bad input nor producing well-formed protocol output.

Reproducer

from smtplib import quoteaddr

print(repr(quoteaddr('<')))    # '<'  — missing closing >
print(repr(quoteaddr('< ')))   # '< ' — missing closing >
print(repr(quoteaddr('<user@example.com')))  # '<user@example.com' — missing >
CPython versions tested on:

CPython main branch

Operating systems tested on:

No response

Linked PRs
  • gh-145553

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

调研方向

从 smtplib.quoteaddr() 开始,检查 email.utils.parseaddr() 无法解析输入时使用的 fallback。在进行更改之前,先查看链接的 PR gh-145553,然后为 reproducer 中显示的格式错误输入添加覆盖测试,并验证返回的地址在结构上有效。

由索引模型根据 Issue 内容生成。

评估

技术栈
python
领域
networking
Issue 类型
缺陷
难度
2/5
预计耗时
1-3 小时
活跃度
停滞
描述清晰度
描述清楚
新手友好度
35/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。