FAILURE MAP
← Case archive

FA-26796 / HTTP ranges / Open access

Boundary-like substrings inside part bodies remain payload data · case 01

Boundary-like substrings inside part bodies remain payload data.

Verified by executionVariant 1 · 6 checks per implementationDownload source bundle ↓JSON ↗

ROOT CAUSE

The multipart-client-line-anchoring decision uses return body.find("--"+boundary).

VERIFIED REPAIR

Apply the bounded decision exactly: if body.startswith("--"+boundary): return 0 p=body.find("\r\n--"+boundary) return p+2 if p>=0 else -1

Unsuccessful approach: The partial repair uses return body.find("\r\n--"+boundary)+2 if "\r\n--"+boundary in body else -1, which still violates the stated contract.

Case contract

Return position of first delimiter at start or immediately after CRLF, or -1. Delimiter bytes are --boundary; interior lookalikes are ignored.

Why this case matters

Range responses combine representation identity, conditional requests, framing, and partial-object state.

1 / The failure

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(body, boundary):
    return body.find("--"+boundary)
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('multipart-client-line-anchoring fixture 0', solve("x--b"+str(N),"b"+str(N)), -1)
check('multipart-client-line-anchoring fixture 1', solve("--b"+str(N),"b"+str(N)), 0)
check('multipart-client-line-anchoring fixture 2', solve("abc\r\n--b","b"), 5)
check('multipart-client-line-anchoring fixture 3', solve("abc","b"), -1)
check('multipart-client-line-anchoring fixture 4', solve("","b"), -1)
check('multipart-client-line-anchoring fixture 5', solve("x--b\r\n--b","b"), 6)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
multipart-client-line-anchoring fixture 01-1Failed
multipart-client-line-anchoring fixture 100Passed
multipart-client-line-anchoring fixture 255Passed
multipart-client-line-anchoring fixture 3-1-1Passed
multipart-client-line-anchoring fixture 4-1-1Passed
multipart-client-line-anchoring fixture 516Failed

SHA-256 / 0b516975fcf62584597afc4f54d78034682f43aa979ba3407bf4082562ad0412

2 / The unsuccessful fix

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(body, boundary):
    return body.find("\r\n--"+boundary)+2 if "\r\n--"+boundary in body else -1
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('multipart-client-line-anchoring fixture 0', solve("x--b"+str(N),"b"+str(N)), -1)
check('multipart-client-line-anchoring fixture 1', solve("--b"+str(N),"b"+str(N)), 0)
check('multipart-client-line-anchoring fixture 2', solve("abc\r\n--b","b"), 5)
check('multipart-client-line-anchoring fixture 3', solve("abc","b"), -1)
check('multipart-client-line-anchoring fixture 4', solve("","b"), -1)
check('multipart-client-line-anchoring fixture 5', solve("x--b\r\n--b","b"), 6)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
multipart-client-line-anchoring fixture 0-1-1Passed
multipart-client-line-anchoring fixture 1-10Failed
multipart-client-line-anchoring fixture 255Passed
multipart-client-line-anchoring fixture 3-1-1Passed
multipart-client-line-anchoring fixture 4-1-1Passed
multipart-client-line-anchoring fixture 566Passed

SHA-256 / 6e538e164d89d94cbea4ea22c9bb8aa0dca1d58d87cb821a965029dfb50b4faf

3 / The verified repair

Exit 0
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(body, boundary):
    if body.startswith("--"+boundary): return 0
    p=body.find("\r\n--"+boundary)
    return p+2 if p>=0 else -1
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('multipart-client-line-anchoring fixture 0', solve("x--b"+str(N),"b"+str(N)), -1)
check('multipart-client-line-anchoring fixture 1', solve("--b"+str(N),"b"+str(N)), 0)
check('multipart-client-line-anchoring fixture 2', solve("abc\r\n--b","b"), 5)
check('multipart-client-line-anchoring fixture 3', solve("abc","b"), -1)
check('multipart-client-line-anchoring fixture 4', solve("","b"), -1)
check('multipart-client-line-anchoring fixture 5', solve("x--b\r\n--b","b"), 6)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
multipart-client-line-anchoring fixture 0-1-1Passed
multipart-client-line-anchoring fixture 100Passed
multipart-client-line-anchoring fixture 255Passed
multipart-client-line-anchoring fixture 3-1-1Passed
multipart-client-line-anchoring fixture 4-1-1Passed
multipart-client-line-anchoring fixture 566Passed

SHA-256 / 800e4cd2f0724309b30d9a3c42256fcf4ba0e6a0cc165d7b13cdd44a62b96259

Verification & scope

Deterministic simplified range service, with stipulated local policies and already parsed trusted inputs; not a complete HTTP implementation. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.

Observations recorded using Python 3.12.14 at 2026-09-29T14:41:19.223056+00:00.

Case digest / f744484684ffdafda3c3cc10a7efb6807428464685d265086096ee948936c103