FA-26796 / HTTP ranges / Open access
Boundary-like substrings inside part bodies remain payload data · case 01
Boundary-like substrings inside part bodies remain payload data.
ROOT CAUSE
The multipart-client-line-anchoring decision uses return body.find("--"+boundary).
VERIFIED REPAIR
Apply the bounded decision exactly: if body.startswith("--"+boundary): return 0 p=body.find("\r\n--"+boundary) return p+2 if p>=0 else -1
Unsuccessful approach: The partial repair uses return body.find("\r\n--"+boundary)+2 if "\r\n--"+boundary in body else -1, which still violates the stated contract.
Case contract
Return position of first delimiter at start or immediately after CRLF, or -1. Delimiter bytes are --boundary; interior lookalikes are ignored.
Why this case matters
Range responses combine representation identity, conditional requests, framing, and partial-object state.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(body, boundary):
return body.find("--"+boundary)
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('multipart-client-line-anchoring fixture 0', solve("x--b"+str(N),"b"+str(N)), -1)
check('multipart-client-line-anchoring fixture 1', solve("--b"+str(N),"b"+str(N)), 0)
check('multipart-client-line-anchoring fixture 2', solve("abc\r\n--b","b"), 5)
check('multipart-client-line-anchoring fixture 3', solve("abc","b"), -1)
check('multipart-client-line-anchoring fixture 4', solve("","b"), -1)
check('multipart-client-line-anchoring fixture 5', solve("x--b\r\n--b","b"), 6)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| multipart-client-line-anchoring fixture 0 | 1 | -1 | Failed |
| multipart-client-line-anchoring fixture 1 | 0 | 0 | Passed |
| multipart-client-line-anchoring fixture 2 | 5 | 5 | Passed |
| multipart-client-line-anchoring fixture 3 | -1 | -1 | Passed |
| multipart-client-line-anchoring fixture 4 | -1 | -1 | Passed |
| multipart-client-line-anchoring fixture 5 | 1 | 6 | Failed |
SHA-256 / 0b516975fcf62584597afc4f54d78034682f43aa979ba3407bf4082562ad0412
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(body, boundary):
return body.find("\r\n--"+boundary)+2 if "\r\n--"+boundary in body else -1
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('multipart-client-line-anchoring fixture 0', solve("x--b"+str(N),"b"+str(N)), -1)
check('multipart-client-line-anchoring fixture 1', solve("--b"+str(N),"b"+str(N)), 0)
check('multipart-client-line-anchoring fixture 2', solve("abc\r\n--b","b"), 5)
check('multipart-client-line-anchoring fixture 3', solve("abc","b"), -1)
check('multipart-client-line-anchoring fixture 4', solve("","b"), -1)
check('multipart-client-line-anchoring fixture 5', solve("x--b\r\n--b","b"), 6)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| multipart-client-line-anchoring fixture 0 | -1 | -1 | Passed |
| multipart-client-line-anchoring fixture 1 | -1 | 0 | Failed |
| multipart-client-line-anchoring fixture 2 | 5 | 5 | Passed |
| multipart-client-line-anchoring fixture 3 | -1 | -1 | Passed |
| multipart-client-line-anchoring fixture 4 | -1 | -1 | Passed |
| multipart-client-line-anchoring fixture 5 | 6 | 6 | Passed |
SHA-256 / 6e538e164d89d94cbea4ea22c9bb8aa0dca1d58d87cb821a965029dfb50b4faf
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(body, boundary):
if body.startswith("--"+boundary): return 0
p=body.find("\r\n--"+boundary)
return p+2 if p>=0 else -1
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('multipart-client-line-anchoring fixture 0', solve("x--b"+str(N),"b"+str(N)), -1)
check('multipart-client-line-anchoring fixture 1', solve("--b"+str(N),"b"+str(N)), 0)
check('multipart-client-line-anchoring fixture 2', solve("abc\r\n--b","b"), 5)
check('multipart-client-line-anchoring fixture 3', solve("abc","b"), -1)
check('multipart-client-line-anchoring fixture 4', solve("","b"), -1)
check('multipart-client-line-anchoring fixture 5', solve("x--b\r\n--b","b"), 6)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| multipart-client-line-anchoring fixture 0 | -1 | -1 | Passed |
| multipart-client-line-anchoring fixture 1 | 0 | 0 | Passed |
| multipart-client-line-anchoring fixture 2 | 5 | 5 | Passed |
| multipart-client-line-anchoring fixture 3 | -1 | -1 | Passed |
| multipart-client-line-anchoring fixture 4 | -1 | -1 | Passed |
| multipart-client-line-anchoring fixture 5 | 6 | 6 | Passed |
SHA-256 / 800e4cd2f0724309b30d9a3c42256fcf4ba0e6a0cc165d7b13cdd44a62b96259
Verification & scope
Deterministic simplified range service, with stipulated local policies and already parsed trusted inputs; not a complete HTTP implementation. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:41:19.223056+00:00.
Case digest / f744484684ffdafda3c3cc10a7efb6807428464685d265086096ee948936c103