Skip to content

mailbox.MH.__setitem__() can destroy a message when replacement fails #156312

Description

@lpyu001

Bug description:

Summary

`When mailbox.MH replaces an existing message with an invalid str, it correctly raises ValueError, but the original message file may already have been truncated to empty. In other words, the replacement fails while also destroying the existing message content, resulting in data loss.

Affected public API: mailbox.MH.__setitem__().

Minimal reproducer

Run this against CPython before the fix:

import mailbox
import tempfile

with tempfile.TemporaryDirectory() as path:
    box = mailbox.MH(path)
    key = box.add(b"Subject: original\n\noriginal body\n")
    original = box.get_bytes(key)

    try:
        box[key] = "Subject: caf\u00e9\n\nreplacement body\n"
    except ValueError as exc:
        print(type(exc).__name__, exc)

    print("in-memory:", box.get_bytes(key))
    box.close()

    reopened = mailbox.MH(path)
    print("reopened:", reopened.get_bytes(key))
    assert reopened.get_bytes(key) == original

Actual result before the fix:

ValueError String input must be ASCII-only; use bytes or a Message instead
in-memory: b''
reopened: b''
AssertionError

Expected result:

ValueError String input must be ASCII-only; use bytes or a Message instead
in-memory: b'Subject: original\n\noriginal body\n'
reopened: b'Subject: original\n\noriginal body\n'

The same problem occurs if a file-like message object raises while it is being read: the old message is replaced with the bytes written before the exception.

Root cause

MH.__setitem__() performed these operations in this order:

open existing message
-> open the same path with O_TRUNC
-> serialize the replacement with _dump_message()
-> propagate a serialization error

O_TRUNC changes the existing message file before _dump_message() validates or fully reads the replacement. For a non-ASCII str, _dump_message() calls _string_to_bytes() and raises ValueError immediately, leaving the already truncated file in place. There is no rollback path.

CPython versions tested on:

CPython main branch

Operating systems tested on:

Linux

Linked PRs

Metadata

Metadata

Assignees

No one assigned

    Labels

    stdlibStandard Library Python modules in the Lib/ directorytopic-emailtype-bugAn unexpected behavior, bug, or error

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions