FA-26441 / HTTP ranges / Open access
Multipart delimiters cannot occur at payload line boundaries · case 01
Multipart delimiters cannot occur at payload line boundaries.
ROOT CAUSE
The multipart-boundary-collision decision uses return candidate.
VERIFIED REPAIR
Apply the bounded decision exactly: while any(p.startswith("--"+candidate) or ("\r\n--"+candidate) in p for p in parts): candidate += "x" return candidate
Unsuccessful approach: The partial repair uses return candidate+"x" if any(("--"+candidate) in p for p in parts) else candidate, which still violates the stated contract.
Case contract
Choose candidate, candidate+x, ... until no part contains a line starting --candidate. Parts are ASCII strings; only start of body or after CRLF is a line boundary.
Why this case matters
Range responses combine representation identity, conditional requests, framing, and partial-object state.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(candidate, parts):
return candidate
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('multipart-boundary-collision fixture 0', solve("b"+str(N),["--b"+str(N),"--b"+str(N)+"x"]), "b"+str(N)+"xx")
check('multipart-boundary-collision fixture 1', solve("b",["abc--b"]), "b")
check('multipart-boundary-collision fixture 2', solve("b",["x\r\n--b"]), "bx")
check('multipart-boundary-collision fixture 3', solve("b",[]), "b")
check('multipart-boundary-collision fixture 4', solve("b",[""]), "b")
check('multipart-boundary-collision fixture 5', solve("b",["--other"]), "b")
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| multipart-boundary-collision fixture 0 | b1 | b1xx | Failed |
| multipart-boundary-collision fixture 1 | b | b | Passed |
| multipart-boundary-collision fixture 2 | b | bx | Failed |
| multipart-boundary-collision fixture 3 | b | b | Passed |
| multipart-boundary-collision fixture 4 | b | b | Passed |
| multipart-boundary-collision fixture 5 | b | b | Passed |
SHA-256 / 137503b52dd64bcf4b8931b0193bd95c669ae3ac0bc4e341c4c86c5055c5af09
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(candidate, parts):
return candidate+"x" if any(("--"+candidate) in p for p in parts) else candidate
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('multipart-boundary-collision fixture 0', solve("b"+str(N),["--b"+str(N),"--b"+str(N)+"x"]), "b"+str(N)+"xx")
check('multipart-boundary-collision fixture 1', solve("b",["abc--b"]), "b")
check('multipart-boundary-collision fixture 2', solve("b",["x\r\n--b"]), "bx")
check('multipart-boundary-collision fixture 3', solve("b",[]), "b")
check('multipart-boundary-collision fixture 4', solve("b",[""]), "b")
check('multipart-boundary-collision fixture 5', solve("b",["--other"]), "b")
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| multipart-boundary-collision fixture 0 | b1x | b1xx | Failed |
| multipart-boundary-collision fixture 1 | bx | b | Failed |
| multipart-boundary-collision fixture 2 | bx | bx | Passed |
| multipart-boundary-collision fixture 3 | b | b | Passed |
| multipart-boundary-collision fixture 4 | b | b | Passed |
| multipart-boundary-collision fixture 5 | b | b | Passed |
SHA-256 / 21d94157d62945c211dd76f9f7ee676344fea0224b333045fd520b71b167e87c
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(candidate, parts):
while any(p.startswith("--"+candidate) or ("\r\n--"+candidate) in p for p in parts):
candidate += "x"
return candidate
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('multipart-boundary-collision fixture 0', solve("b"+str(N),["--b"+str(N),"--b"+str(N)+"x"]), "b"+str(N)+"xx")
check('multipart-boundary-collision fixture 1', solve("b",["abc--b"]), "b")
check('multipart-boundary-collision fixture 2', solve("b",["x\r\n--b"]), "bx")
check('multipart-boundary-collision fixture 3', solve("b",[]), "b")
check('multipart-boundary-collision fixture 4', solve("b",[""]), "b")
check('multipart-boundary-collision fixture 5', solve("b",["--other"]), "b")
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| multipart-boundary-collision fixture 0 | b1xx | b1xx | Passed |
| multipart-boundary-collision fixture 1 | b | b | Passed |
| multipart-boundary-collision fixture 2 | bx | bx | Passed |
| multipart-boundary-collision fixture 3 | b | b | Passed |
| multipart-boundary-collision fixture 4 | b | b | Passed |
| multipart-boundary-collision fixture 5 | b | b | Passed |
SHA-256 / e7ca246abaad902dfb647ff920debec0292fd162d53da3aa7021ce5e49f5d14f
Verification & scope
Deterministic simplified range service, with stipulated local policies and already parsed trusted inputs; not a complete HTTP implementation. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:41:16.089451+00:00.
Case digest / 70f8c10f901e5951b8df19390817102b0ab08ba350cb250c0b53c3793191fab4