FAILURE MAP
← Case archive

FA-26436 / HTTP ranges / Open access

Unauthorized range probes hide whether the object exists · case 01

Unauthorized range probes hide whether the object exists.

Verified by executionVariant 1 · 6 checks per implementationDownload source bundle ↓JSON ↗

ROOT CAUSE

The authorization-before-object-existence decision uses return [404,""] if not exists else ([206,part] if authorized else [403,""]).

VERIFIED REPAIR

Apply the bounded decision exactly: return [403,""] if not authorized else ([206,part] if exists else [404,""])

Unsuccessful approach: The partial repair uses return [404,""] if not authorized else ([206,part] if exists else [404,""]), which still violates the stated contract.

Case contract

Local concealment policy returns [403,empty] for unauthorized users before object existence; authorized absent objects return 404, present objects 206.

Why this case matters

Range responses combine representation identity, conditional requests, framing, and partial-object state.

1 / The failure

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(authorized, exists, part):
    return [404,""] if not exists else ([206,part] if authorized else [403,""])
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('authorization-before-object-existence fixture 0', solve(False,False,"p"*N), [403,""])
check('authorization-before-object-existence fixture 1', solve(False,True,"p"), [403,""])
check('authorization-before-object-existence fixture 2', solve(True,False,"p"), [404,""])
check('authorization-before-object-existence fixture 3', solve(True,True,"p"*N), [206,"p"*N])
check('authorization-before-object-existence fixture 4', solve(False,False,""), [403,""])
check('authorization-before-object-existence fixture 5', solve(True,True,""), [206,""])
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
authorization-before-object-existence fixture 0[404, ''][403, '']Failed
authorization-before-object-existence fixture 1[403, ''][403, '']Passed
authorization-before-object-existence fixture 2[404, ''][404, '']Passed
authorization-before-object-existence fixture 3[206, 'p'][206, 'p']Passed
authorization-before-object-existence fixture 4[404, ''][403, '']Failed
authorization-before-object-existence fixture 5[206, ''][206, '']Passed

SHA-256 / 30cf7714f038877919218a2400e9ce8131f1e30680cb86df5b2e3f078bc7c0ee

2 / The unsuccessful fix

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(authorized, exists, part):
    return [404,""] if not authorized else ([206,part] if exists else [404,""])
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('authorization-before-object-existence fixture 0', solve(False,False,"p"*N), [403,""])
check('authorization-before-object-existence fixture 1', solve(False,True,"p"), [403,""])
check('authorization-before-object-existence fixture 2', solve(True,False,"p"), [404,""])
check('authorization-before-object-existence fixture 3', solve(True,True,"p"*N), [206,"p"*N])
check('authorization-before-object-existence fixture 4', solve(False,False,""), [403,""])
check('authorization-before-object-existence fixture 5', solve(True,True,""), [206,""])
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
authorization-before-object-existence fixture 0[404, ''][403, '']Failed
authorization-before-object-existence fixture 1[404, ''][403, '']Failed
authorization-before-object-existence fixture 2[404, ''][404, '']Passed
authorization-before-object-existence fixture 3[206, 'p'][206, 'p']Passed
authorization-before-object-existence fixture 4[404, ''][403, '']Failed
authorization-before-object-existence fixture 5[206, ''][206, '']Passed

SHA-256 / bd888715472f445efb33ed375d90178e9dd85574a35997dd90bbee1861598348

3 / The verified repair

Exit 0
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(authorized, exists, part):
    return [403,""] if not authorized else ([206,part] if exists else [404,""])
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('authorization-before-object-existence fixture 0', solve(False,False,"p"*N), [403,""])
check('authorization-before-object-existence fixture 1', solve(False,True,"p"), [403,""])
check('authorization-before-object-existence fixture 2', solve(True,False,"p"), [404,""])
check('authorization-before-object-existence fixture 3', solve(True,True,"p"*N), [206,"p"*N])
check('authorization-before-object-existence fixture 4', solve(False,False,""), [403,""])
check('authorization-before-object-existence fixture 5', solve(True,True,""), [206,""])
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
authorization-before-object-existence fixture 0[403, ''][403, '']Passed
authorization-before-object-existence fixture 1[403, ''][403, '']Passed
authorization-before-object-existence fixture 2[404, ''][404, '']Passed
authorization-before-object-existence fixture 3[206, 'p'][206, 'p']Passed
authorization-before-object-existence fixture 4[403, ''][403, '']Passed
authorization-before-object-existence fixture 5[206, ''][206, '']Passed

SHA-256 / 95d1891e10d3e8e3d5a71113e9d471beac0040b9b39404272811571d81fdfdb6

Verification & scope

Deterministic simplified range service, with stipulated local policies and already parsed trusted inputs; not a complete HTTP implementation. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.

Observations recorded using Python 3.12.14 at 2026-09-29T14:41:15.969156+00:00.

Case digest / 18b3fbb3b32ee8f2469d44de091f192a99b7bd38b00a06c5caf54982ccef222e