FAILURE MAP
← Case archive

FA-26441 / HTTP ranges / Open access

Multipart delimiters cannot occur at payload line boundaries · case 01

Multipart delimiters cannot occur at payload line boundaries.

Verified by executionVariant 1 · 6 checks per implementationDownload source bundle ↓JSON ↗

ROOT CAUSE

The multipart-boundary-collision decision uses return candidate.

VERIFIED REPAIR

Apply the bounded decision exactly: while any(p.startswith("--"+candidate) or ("\r\n--"+candidate) in p for p in parts): candidate += "x" return candidate

Unsuccessful approach: The partial repair uses return candidate+"x" if any(("--"+candidate) in p for p in parts) else candidate, which still violates the stated contract.

Case contract

Choose candidate, candidate+x, ... until no part contains a line starting --candidate. Parts are ASCII strings; only start of body or after CRLF is a line boundary.

Why this case matters

Range responses combine representation identity, conditional requests, framing, and partial-object state.

1 / The failure

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(candidate, parts):
    return candidate
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('multipart-boundary-collision fixture 0', solve("b"+str(N),["--b"+str(N),"--b"+str(N)+"x"]), "b"+str(N)+"xx")
check('multipart-boundary-collision fixture 1', solve("b",["abc--b"]), "b")
check('multipart-boundary-collision fixture 2', solve("b",["x\r\n--b"]), "bx")
check('multipart-boundary-collision fixture 3', solve("b",[]), "b")
check('multipart-boundary-collision fixture 4', solve("b",[""]), "b")
check('multipart-boundary-collision fixture 5', solve("b",["--other"]), "b")
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
multipart-boundary-collision fixture 0b1b1xxFailed
multipart-boundary-collision fixture 1bbPassed
multipart-boundary-collision fixture 2bbxFailed
multipart-boundary-collision fixture 3bbPassed
multipart-boundary-collision fixture 4bbPassed
multipart-boundary-collision fixture 5bbPassed

SHA-256 / 137503b52dd64bcf4b8931b0193bd95c669ae3ac0bc4e341c4c86c5055c5af09

2 / The unsuccessful fix

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(candidate, parts):
    return candidate+"x" if any(("--"+candidate) in p for p in parts) else candidate
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('multipart-boundary-collision fixture 0', solve("b"+str(N),["--b"+str(N),"--b"+str(N)+"x"]), "b"+str(N)+"xx")
check('multipart-boundary-collision fixture 1', solve("b",["abc--b"]), "b")
check('multipart-boundary-collision fixture 2', solve("b",["x\r\n--b"]), "bx")
check('multipart-boundary-collision fixture 3', solve("b",[]), "b")
check('multipart-boundary-collision fixture 4', solve("b",[""]), "b")
check('multipart-boundary-collision fixture 5', solve("b",["--other"]), "b")
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
multipart-boundary-collision fixture 0b1xb1xxFailed
multipart-boundary-collision fixture 1bxbFailed
multipart-boundary-collision fixture 2bxbxPassed
multipart-boundary-collision fixture 3bbPassed
multipart-boundary-collision fixture 4bbPassed
multipart-boundary-collision fixture 5bbPassed

SHA-256 / 21d94157d62945c211dd76f9f7ee676344fea0224b333045fd520b71b167e87c

3 / The verified repair

Exit 0
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(candidate, parts):
    while any(p.startswith("--"+candidate) or ("\r\n--"+candidate) in p for p in parts):
        candidate += "x"
    return candidate
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('multipart-boundary-collision fixture 0', solve("b"+str(N),["--b"+str(N),"--b"+str(N)+"x"]), "b"+str(N)+"xx")
check('multipart-boundary-collision fixture 1', solve("b",["abc--b"]), "b")
check('multipart-boundary-collision fixture 2', solve("b",["x\r\n--b"]), "bx")
check('multipart-boundary-collision fixture 3', solve("b",[]), "b")
check('multipart-boundary-collision fixture 4', solve("b",[""]), "b")
check('multipart-boundary-collision fixture 5', solve("b",["--other"]), "b")
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
multipart-boundary-collision fixture 0b1xxb1xxPassed
multipart-boundary-collision fixture 1bbPassed
multipart-boundary-collision fixture 2bxbxPassed
multipart-boundary-collision fixture 3bbPassed
multipart-boundary-collision fixture 4bbPassed
multipart-boundary-collision fixture 5bbPassed

SHA-256 / e7ca246abaad902dfb647ff920debec0292fd162d53da3aa7021ce5e49f5d14f

Verification & scope

Deterministic simplified range service, with stipulated local policies and already parsed trusted inputs; not a complete HTTP implementation. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.

Observations recorded using Python 3.12.14 at 2026-09-29T14:41:16.089451+00:00.

Case digest / 70f8c10f901e5951b8df19390817102b0ab08ba350cb250c0b53c3793191fab4