FA-26596 / HTTP ranges / Open access
Oversized backend reads do not leak bytes outside the response budget · case 01
Oversized backend reads do not leak bytes outside the response budget.
ROOT CAUSE
The stream-read-result-cap decision uses return [data,""].
VERIFIED REPAIR
Apply the bounded decision exactly: return [data[:remaining],data[remaining:]]
Unsuccessful approach: The partial repair uses return [data[:remaining],""], which still violates the stated contract.
Case contract
Backend may return more ASCII bytes than requested. Emit at most remaining bytes and return [emitted,unconsumed], preserving the suffix.
Why this case matters
Range responses combine representation identity, conditional requests, framing, and partial-object state.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(data, remaining):
return [data,""]
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('stream-read-result-cap fixture 0', solve("abc"*N,N), [("abc"*N)[:N],("abc"*N)[N:]])
check('stream-read-result-cap fixture 1', solve("abc",0), ["","abc"])
check('stream-read-result-cap fixture 2', solve("abc",3), ["abc",""])
check('stream-read-result-cap fixture 3', solve("abc",5), ["abc",""])
check('stream-read-result-cap fixture 4', solve("",N), ["",""])
check('stream-read-result-cap fixture 5', solve("abcd",2), ["ab","cd"])
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| stream-read-result-cap fixture 0 | ['abc', ''] | ['a', 'bc'] | Failed |
| stream-read-result-cap fixture 1 | ['abc', ''] | ['', 'abc'] | Failed |
| stream-read-result-cap fixture 2 | ['abc', ''] | ['abc', ''] | Passed |
| stream-read-result-cap fixture 3 | ['abc', ''] | ['abc', ''] | Passed |
| stream-read-result-cap fixture 4 | ['', ''] | ['', ''] | Passed |
| stream-read-result-cap fixture 5 | ['abcd', ''] | ['ab', 'cd'] | Failed |
SHA-256 / ef4f29114e56a56d0483f066c19343a0ee726a1d71ae191333053b1d30c67bd0
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(data, remaining):
return [data[:remaining],""]
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('stream-read-result-cap fixture 0', solve("abc"*N,N), [("abc"*N)[:N],("abc"*N)[N:]])
check('stream-read-result-cap fixture 1', solve("abc",0), ["","abc"])
check('stream-read-result-cap fixture 2', solve("abc",3), ["abc",""])
check('stream-read-result-cap fixture 3', solve("abc",5), ["abc",""])
check('stream-read-result-cap fixture 4', solve("",N), ["",""])
check('stream-read-result-cap fixture 5', solve("abcd",2), ["ab","cd"])
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| stream-read-result-cap fixture 0 | ['a', ''] | ['a', 'bc'] | Failed |
| stream-read-result-cap fixture 1 | ['', ''] | ['', 'abc'] | Failed |
| stream-read-result-cap fixture 2 | ['abc', ''] | ['abc', ''] | Passed |
| stream-read-result-cap fixture 3 | ['abc', ''] | ['abc', ''] | Passed |
| stream-read-result-cap fixture 4 | ['', ''] | ['', ''] | Passed |
| stream-read-result-cap fixture 5 | ['ab', ''] | ['ab', 'cd'] | Failed |
SHA-256 / 9262b675e421a04e973c8aeb1f18540c94ad8968a99ef3f3322a811d495d4453
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(data, remaining):
return [data[:remaining],data[remaining:]]
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('stream-read-result-cap fixture 0', solve("abc"*N,N), [("abc"*N)[:N],("abc"*N)[N:]])
check('stream-read-result-cap fixture 1', solve("abc",0), ["","abc"])
check('stream-read-result-cap fixture 2', solve("abc",3), ["abc",""])
check('stream-read-result-cap fixture 3', solve("abc",5), ["abc",""])
check('stream-read-result-cap fixture 4', solve("",N), ["",""])
check('stream-read-result-cap fixture 5', solve("abcd",2), ["ab","cd"])
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| stream-read-result-cap fixture 0 | ['a', 'bc'] | ['a', 'bc'] | Passed |
| stream-read-result-cap fixture 1 | ['', 'abc'] | ['', 'abc'] | Passed |
| stream-read-result-cap fixture 2 | ['abc', ''] | ['abc', ''] | Passed |
| stream-read-result-cap fixture 3 | ['abc', ''] | ['abc', ''] | Passed |
| stream-read-result-cap fixture 4 | ['', ''] | ['', ''] | Passed |
| stream-read-result-cap fixture 5 | ['ab', 'cd'] | ['ab', 'cd'] | Passed |
SHA-256 / 00923dc97e1b0f9c4ffdc442970114f4f2edd333b7ad7eb31afd61f0338e663b
Verification & scope
Deterministic simplified range service, with stipulated local policies and already parsed trusted inputs; not a complete HTTP implementation. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:41:17.481603+00:00.
Case digest / 80a21c9d6d2b683a529ce9dcc93444bf3f568384cbd49e53be304820672885f5