FA-26436 / HTTP ranges / Open access
Unauthorized range probes hide whether the object exists · case 01
Unauthorized range probes hide whether the object exists.
ROOT CAUSE
The authorization-before-object-existence decision uses return [404,""] if not exists else ([206,part] if authorized else [403,""]).
VERIFIED REPAIR
Apply the bounded decision exactly: return [403,""] if not authorized else ([206,part] if exists else [404,""])
Unsuccessful approach: The partial repair uses return [404,""] if not authorized else ([206,part] if exists else [404,""]), which still violates the stated contract.
Case contract
Local concealment policy returns [403,empty] for unauthorized users before object existence; authorized absent objects return 404, present objects 206.
Why this case matters
Range responses combine representation identity, conditional requests, framing, and partial-object state.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(authorized, exists, part):
return [404,""] if not exists else ([206,part] if authorized else [403,""])
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('authorization-before-object-existence fixture 0', solve(False,False,"p"*N), [403,""])
check('authorization-before-object-existence fixture 1', solve(False,True,"p"), [403,""])
check('authorization-before-object-existence fixture 2', solve(True,False,"p"), [404,""])
check('authorization-before-object-existence fixture 3', solve(True,True,"p"*N), [206,"p"*N])
check('authorization-before-object-existence fixture 4', solve(False,False,""), [403,""])
check('authorization-before-object-existence fixture 5', solve(True,True,""), [206,""])
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| authorization-before-object-existence fixture 0 | [404, ''] | [403, ''] | Failed |
| authorization-before-object-existence fixture 1 | [403, ''] | [403, ''] | Passed |
| authorization-before-object-existence fixture 2 | [404, ''] | [404, ''] | Passed |
| authorization-before-object-existence fixture 3 | [206, 'p'] | [206, 'p'] | Passed |
| authorization-before-object-existence fixture 4 | [404, ''] | [403, ''] | Failed |
| authorization-before-object-existence fixture 5 | [206, ''] | [206, ''] | Passed |
SHA-256 / 30cf7714f038877919218a2400e9ce8131f1e30680cb86df5b2e3f078bc7c0ee
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(authorized, exists, part):
return [404,""] if not authorized else ([206,part] if exists else [404,""])
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('authorization-before-object-existence fixture 0', solve(False,False,"p"*N), [403,""])
check('authorization-before-object-existence fixture 1', solve(False,True,"p"), [403,""])
check('authorization-before-object-existence fixture 2', solve(True,False,"p"), [404,""])
check('authorization-before-object-existence fixture 3', solve(True,True,"p"*N), [206,"p"*N])
check('authorization-before-object-existence fixture 4', solve(False,False,""), [403,""])
check('authorization-before-object-existence fixture 5', solve(True,True,""), [206,""])
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| authorization-before-object-existence fixture 0 | [404, ''] | [403, ''] | Failed |
| authorization-before-object-existence fixture 1 | [404, ''] | [403, ''] | Failed |
| authorization-before-object-existence fixture 2 | [404, ''] | [404, ''] | Passed |
| authorization-before-object-existence fixture 3 | [206, 'p'] | [206, 'p'] | Passed |
| authorization-before-object-existence fixture 4 | [404, ''] | [403, ''] | Failed |
| authorization-before-object-existence fixture 5 | [206, ''] | [206, ''] | Passed |
SHA-256 / bd888715472f445efb33ed375d90178e9dd85574a35997dd90bbee1861598348
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(authorized, exists, part):
return [403,""] if not authorized else ([206,part] if exists else [404,""])
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('authorization-before-object-existence fixture 0', solve(False,False,"p"*N), [403,""])
check('authorization-before-object-existence fixture 1', solve(False,True,"p"), [403,""])
check('authorization-before-object-existence fixture 2', solve(True,False,"p"), [404,""])
check('authorization-before-object-existence fixture 3', solve(True,True,"p"*N), [206,"p"*N])
check('authorization-before-object-existence fixture 4', solve(False,False,""), [403,""])
check('authorization-before-object-existence fixture 5', solve(True,True,""), [206,""])
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| authorization-before-object-existence fixture 0 | [403, ''] | [403, ''] | Passed |
| authorization-before-object-existence fixture 1 | [403, ''] | [403, ''] | Passed |
| authorization-before-object-existence fixture 2 | [404, ''] | [404, ''] | Passed |
| authorization-before-object-existence fixture 3 | [206, 'p'] | [206, 'p'] | Passed |
| authorization-before-object-existence fixture 4 | [403, ''] | [403, ''] | Passed |
| authorization-before-object-existence fixture 5 | [206, ''] | [206, ''] | Passed |
SHA-256 / 95d1891e10d3e8e3d5a71113e9d471beac0040b9b39404272811571d81fdfdb6
Verification & scope
Deterministic simplified range service, with stipulated local policies and already parsed trusted inputs; not a complete HTTP implementation. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:41:15.969156+00:00.
Case digest / 18b3fbb3b32ee8f2469d44de091f192a99b7bd38b00a06c5caf54982ccef222e