FAILURE MAP
← Case archive

FA-26596 / HTTP ranges / Open access

Oversized backend reads do not leak bytes outside the response budget · case 01

Oversized backend reads do not leak bytes outside the response budget.

Verified by executionVariant 1 · 6 checks per implementationDownload source bundle ↓JSON ↗

ROOT CAUSE

The stream-read-result-cap decision uses return [data,""].

VERIFIED REPAIR

Apply the bounded decision exactly: return [data[:remaining],data[remaining:]]

Unsuccessful approach: The partial repair uses return [data[:remaining],""], which still violates the stated contract.

Case contract

Backend may return more ASCII bytes than requested. Emit at most remaining bytes and return [emitted,unconsumed], preserving the suffix.

Why this case matters

Range responses combine representation identity, conditional requests, framing, and partial-object state.

1 / The failure

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(data, remaining):
    return [data,""]
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('stream-read-result-cap fixture 0', solve("abc"*N,N), [("abc"*N)[:N],("abc"*N)[N:]])
check('stream-read-result-cap fixture 1', solve("abc",0), ["","abc"])
check('stream-read-result-cap fixture 2', solve("abc",3), ["abc",""])
check('stream-read-result-cap fixture 3', solve("abc",5), ["abc",""])
check('stream-read-result-cap fixture 4', solve("",N), ["",""])
check('stream-read-result-cap fixture 5', solve("abcd",2), ["ab","cd"])
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
stream-read-result-cap fixture 0['abc', '']['a', 'bc']Failed
stream-read-result-cap fixture 1['abc', '']['', 'abc']Failed
stream-read-result-cap fixture 2['abc', '']['abc', '']Passed
stream-read-result-cap fixture 3['abc', '']['abc', '']Passed
stream-read-result-cap fixture 4['', '']['', '']Passed
stream-read-result-cap fixture 5['abcd', '']['ab', 'cd']Failed

SHA-256 / ef4f29114e56a56d0483f066c19343a0ee726a1d71ae191333053b1d30c67bd0

2 / The unsuccessful fix

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(data, remaining):
    return [data[:remaining],""]
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('stream-read-result-cap fixture 0', solve("abc"*N,N), [("abc"*N)[:N],("abc"*N)[N:]])
check('stream-read-result-cap fixture 1', solve("abc",0), ["","abc"])
check('stream-read-result-cap fixture 2', solve("abc",3), ["abc",""])
check('stream-read-result-cap fixture 3', solve("abc",5), ["abc",""])
check('stream-read-result-cap fixture 4', solve("",N), ["",""])
check('stream-read-result-cap fixture 5', solve("abcd",2), ["ab","cd"])
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
stream-read-result-cap fixture 0['a', '']['a', 'bc']Failed
stream-read-result-cap fixture 1['', '']['', 'abc']Failed
stream-read-result-cap fixture 2['abc', '']['abc', '']Passed
stream-read-result-cap fixture 3['abc', '']['abc', '']Passed
stream-read-result-cap fixture 4['', '']['', '']Passed
stream-read-result-cap fixture 5['ab', '']['ab', 'cd']Failed

SHA-256 / 9262b675e421a04e973c8aeb1f18540c94ad8968a99ef3f3322a811d495d4453

3 / The verified repair

Exit 0
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(data, remaining):
    return [data[:remaining],data[remaining:]]
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('stream-read-result-cap fixture 0', solve("abc"*N,N), [("abc"*N)[:N],("abc"*N)[N:]])
check('stream-read-result-cap fixture 1', solve("abc",0), ["","abc"])
check('stream-read-result-cap fixture 2', solve("abc",3), ["abc",""])
check('stream-read-result-cap fixture 3', solve("abc",5), ["abc",""])
check('stream-read-result-cap fixture 4', solve("",N), ["",""])
check('stream-read-result-cap fixture 5', solve("abcd",2), ["ab","cd"])
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
stream-read-result-cap fixture 0['a', 'bc']['a', 'bc']Passed
stream-read-result-cap fixture 1['', 'abc']['', 'abc']Passed
stream-read-result-cap fixture 2['abc', '']['abc', '']Passed
stream-read-result-cap fixture 3['abc', '']['abc', '']Passed
stream-read-result-cap fixture 4['', '']['', '']Passed
stream-read-result-cap fixture 5['ab', 'cd']['ab', 'cd']Passed

SHA-256 / 00923dc97e1b0f9c4ffdc442970114f4f2edd333b7ad7eb31afd61f0338e663b

Verification & scope

Deterministic simplified range service, with stipulated local policies and already parsed trusted inputs; not a complete HTTP implementation. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.

Observations recorded using Python 3.12.14 at 2026-09-29T14:41:17.481603+00:00.

Case digest / 80a21c9d6d2b683a529ce9dcc93444bf3f568384cbd49e53be304820672885f5