{"abstract":"Unauthorized range probes hide whether the object exists.","category":"HTTP ranges","checks":6,"contract":"Local concealment policy returns [403,empty] for unauthorized users before object existence; authorized absent objects return 404, present objects 206.","evaluation_group":"s3-http_ranges-representation","failed_approach":"The partial repair uses return [404,\"\"] if not authorized else ([206,part] if exists else [404,\"\"]), which still violates the stated contract.","family":"s3-http_ranges-authorization-before-object-existence","id":"FA-26436","implementations":{"attempt":{"sha256":"bd888715472f445efb33ed375d90178e9dd85574a35997dd90bbee1861598348","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(authorized, exists, part):\n    return [404,\"\"] if not authorized else ([206,part] if exists else [404,\"\"])\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\ncheck('authorization-before-object-existence fixture 0', solve(False,False,\"p\"*N), [403,\"\"])\ncheck('authorization-before-object-existence fixture 1', solve(False,True,\"p\"), [403,\"\"])\ncheck('authorization-before-object-existence fixture 2', solve(True,False,\"p\"), [404,\"\"])\ncheck('authorization-before-object-existence fixture 3', solve(True,True,\"p\"*N), [206,\"p\"*N])\ncheck('authorization-before-object-existence fixture 4', solve(False,False,\"\"), [403,\"\"])\ncheck('authorization-before-object-existence fixture 5', solve(True,True,\"\"), [206,\"\"])\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"},"broken":{"sha256":"30cf7714f038877919218a2400e9ce8131f1e30680cb86df5b2e3f078bc7c0ee","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(authorized, exists, part):\n    return [404,\"\"] if not exists else ([206,part] if authorized else [403,\"\"])\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\ncheck('authorization-before-object-existence fixture 0', solve(False,False,\"p\"*N), [403,\"\"])\ncheck('authorization-before-object-existence fixture 1', solve(False,True,\"p\"), [403,\"\"])\ncheck('authorization-before-object-existence fixture 2', solve(True,False,\"p\"), [404,\"\"])\ncheck('authorization-before-object-existence fixture 3', solve(True,True,\"p\"*N), [206,\"p\"*N])\ncheck('authorization-before-object-existence fixture 4', solve(False,False,\"\"), [403,\"\"])\ncheck('authorization-before-object-existence fixture 5', solve(True,True,\"\"), [206,\"\"])\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"},"fixed":{"sha256":"95d1891e10d3e8e3d5a71113e9d471beac0040b9b39404272811571d81fdfdb6","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(authorized, exists, part):\n    return [403,\"\"] if not authorized else ([206,part] if exists else [404,\"\"])\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\ncheck('authorization-before-object-existence fixture 0', solve(False,False,\"p\"*N), [403,\"\"])\ncheck('authorization-before-object-existence fixture 1', solve(False,True,\"p\"), [403,\"\"])\ncheck('authorization-before-object-existence fixture 2', solve(True,False,\"p\"), [404,\"\"])\ncheck('authorization-before-object-existence fixture 3', solve(True,True,\"p\"*N), [206,\"p\"*N])\ncheck('authorization-before-object-existence fixture 4', solve(False,False,\"\"), [403,\"\"])\ncheck('authorization-before-object-existence fixture 5', solve(True,True,\"\"), [206,\"\"])\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"}},"limitations":"Deterministic simplified range service, with stipulated local policies and already parsed trusted inputs; not a complete HTTP implementation. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.","method":"Deterministic executable model with adversarial boundary fixtures.","provenance":{"created_by":"Failure Map","dependencies":"Python standard library","family":"s3-http_ranges-authorization-before-object-existence","generated_at":"2026-09-29T14:41:15.969156+00:00","license":"CC0-1.0","python":"3.12.14","seed":1,"split":"open-access"},"relevance":"Range responses combine representation identity, conditional requests, framing, and partial-object state.","repair":"Apply the bounded decision exactly: return [403,\"\"] if not authorized else ([206,part] if exists else [404,\"\"])","root_cause":"The authorization-before-object-existence decision uses return [404,\"\"] if not exists else ([206,part] if authorized else [403,\"\"]).","sha256":"18b3fbb3b32ee8f2469d44de091f192a99b7bd38b00a06c5caf54982ccef222e","title":"Unauthorized range probes hide whether the object exists · case 01","variant":1,"variant_policy":"Five numbered records share a model and may reuse boundary fixtures.","verification":{"attempt":{"elapsed_ms":41.086,"exit_code":1,"observations":[{"actual":[404,""],"check":"authorization-before-object-existence fixture 0","expected":[403,""],"passed":false},{"actual":[404,""],"check":"authorization-before-object-existence fixture 1","expected":[403,""],"passed":false},{"actual":[404,""],"check":"authorization-before-object-existence fixture 2","expected":[404,""],"passed":true},{"actual":[206,"p"],"check":"authorization-before-object-existence fixture 3","expected":[206,"p"],"passed":true},{"actual":[404,""],"check":"authorization-before-object-existence fixture 4","expected":[403,""],"passed":false},{"actual":[206,""],"check":"authorization-before-object-existence fixture 5","expected":[206,""],"passed":true}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"authorization-before-object-existence fixture 0\", \"actual\": [404, \"\"], \"expected\": [403, \"\"], \"passed\": false}, {\"check\": \"authorization-before-object-existence fixture 1\", \"actual\": [404, \"\"], \"expected\": [403, \"\"], \"passed\": false}, {\"check\": \"authorization-before-object-existence fixture 2\", \"actual\": [404, \"\"], \"expected\": [404, \"\"], \"passed\": true}, {\"check\": \"authorization-before-object-existence fixture 3\", \"actual\": [206, \"p\"], \"expected\": [206, \"p\"], \"passed\": true}, {\"check\": \"authorization-before-object-existence fixture 4\", \"actual\": [404, \"\"], \"expected\": [403, \"\"], \"passed\": false}, {\"check\": \"authorization-before-object-existence fixture 5\", \"actual\": [206, \"\"], \"expected\": [206, \"\"], \"passed\": true}], \"passed\": false}\n"},"broken":{"elapsed_ms":39.605,"exit_code":1,"observations":[{"actual":[404,""],"check":"authorization-before-object-existence fixture 0","expected":[403,""],"passed":false},{"actual":[403,""],"check":"authorization-before-object-existence fixture 1","expected":[403,""],"passed":true},{"actual":[404,""],"check":"authorization-before-object-existence fixture 2","expected":[404,""],"passed":true},{"actual":[206,"p"],"check":"authorization-before-object-existence fixture 3","expected":[206,"p"],"passed":true},{"actual":[404,""],"check":"authorization-before-object-existence fixture 4","expected":[403,""],"passed":false},{"actual":[206,""],"check":"authorization-before-object-existence fixture 5","expected":[206,""],"passed":true}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"authorization-before-object-existence fixture 0\", \"actual\": [404, \"\"], \"expected\": [403, \"\"], \"passed\": false}, {\"check\": \"authorization-before-object-existence fixture 1\", \"actual\": [403, \"\"], \"expected\": [403, \"\"], \"passed\": true}, {\"check\": \"authorization-before-object-existence fixture 2\", \"actual\": [404, \"\"], \"expected\": [404, \"\"], \"passed\": true}, {\"check\": \"authorization-before-object-existence fixture 3\", \"actual\": [206, \"p\"], \"expected\": [206, \"p\"], \"passed\": true}, {\"check\": \"authorization-before-object-existence fixture 4\", \"actual\": [404, \"\"], \"expected\": [403, \"\"], \"passed\": false}, {\"check\": \"authorization-before-object-existence fixture 5\", \"actual\": [206, \"\"], \"expected\": [206, \"\"], \"passed\": true}], \"passed\": false}\n"},"fixed":{"elapsed_ms":39.259,"exit_code":0,"observations":[{"actual":[403,""],"check":"authorization-before-object-existence fixture 0","expected":[403,""],"passed":true},{"actual":[403,""],"check":"authorization-before-object-existence fixture 1","expected":[403,""],"passed":true},{"actual":[404,""],"check":"authorization-before-object-existence fixture 2","expected":[404,""],"passed":true},{"actual":[206,"p"],"check":"authorization-before-object-existence fixture 3","expected":[206,"p"],"passed":true},{"actual":[403,""],"check":"authorization-before-object-existence fixture 4","expected":[403,""],"passed":true},{"actual":[206,""],"check":"authorization-before-object-existence fixture 5","expected":[206,""],"passed":true}],"passed":true,"stderr":"","stdout":"{\"observations\": [{\"check\": \"authorization-before-object-existence fixture 0\", \"actual\": [403, \"\"], \"expected\": [403, \"\"], \"passed\": true}, {\"check\": \"authorization-before-object-existence fixture 1\", \"actual\": [403, \"\"], \"expected\": [403, \"\"], \"passed\": true}, {\"check\": \"authorization-before-object-existence fixture 2\", \"actual\": [404, \"\"], \"expected\": [404, \"\"], \"passed\": true}, {\"check\": \"authorization-before-object-existence fixture 3\", \"actual\": [206, \"p\"], \"expected\": [206, \"p\"], \"passed\": true}, {\"check\": \"authorization-before-object-existence fixture 4\", \"actual\": [403, \"\"], \"expected\": [403, \"\"], \"passed\": true}, {\"check\": \"authorization-before-object-existence fixture 5\", \"actual\": [206, \"\"], \"expected\": [206, \"\"], \"passed\": true}], \"passed\": true}\n"}},"verified":true,"visibility":"public"}