FA-27056 / HTTP ranges / Open access
A proxy coalesces nearby requested spans into economical origin reads: coalescing cannot fetch forbidden bytes absent from requested payloads · case 01
A proxy coalesces nearby requested spans into economical origin reads: coalescing cannot fetch forbidden bytes absent from requested payloads.
ROOT CAUSE
The coalesced-origin-fetch-protected-gap decision uses rows=[(a,b,i) for i,(a,b) in enumerate(x['requests']) if a<b] rows.sort(key=lambda r:(r[0],r[1])) fetches=[] assignments={} for a,b,i in rows: merge=bool(fetches) and a<=fetches[-1][1]+x['gap'] if False: merge=False if merge: index=len(fetches)-1 fetches[index][1]=max(fetches[index][1],b) else: index=len(fetches) fetches.append([a,b]) assignments[i]=index mapping=[] for i,(a,b) in enumerate(x['requests']): if a==b: mapping.append(None); continue index=assignments[i] mapping.append([index,a-fetches[index][0],b-a]) return [fetches,mapping].
VERIFIED REPAIR
Apply the bounded decision exactly: rows=[(a,b,i) for i,(a,b) in enumerate(x['requests']) if a<b] rows.sort(key=lambda r:(r[0],r[1])) fetches=[] assignments={} for a,b,i in rows: merge=bool(fetches) and a<=fetches[-1][1]+x['gap'] if merge and any(p in x['forbidden'] for p in range(fetches[-1][1],a)): merge=False if merge: index=len(fetches)-1 fetches[index][1]=max(fetches[index][1],b) else: index=len(fetches) fetches.append([a,b]) assignments[i]=index mapping=[] for i,(a,b) in enumerate(x['requests']): if a==b: mapping.append(None); continue index=assignments[i] mapping.append([index,a-fetches[index][0],b-a]) return [fetches,mapping]
Unsuccessful approach: The partial repair uses rows=[(a,b,i) for i,(a,b) in enumerate(x['requests']) if a<b] rows.sort(key=lambda r:(r[0],r[1])) fetches=[] assignments={} for a,b,i in rows: merge=bool(fetches) and a<=fetches[-1][1]+x['gap'] if merge and fetches[-1][1] in x['forbidden']: merge=False if merge: index=len(fetches)-1 fetches[index][1]=max(fetches[index][1],b) else: index=len(fetches) fetches.append([a,b]) assignments[i]=index mapping=[] for i,(a,b) in enumerate(x['requests']): if a==b: mapping.append(None); continue index=assignments[i] mapping.append([index,a-fetches[index][0],b-a]) return [fetches,mapping], which still violates the stated contract.
Case contract
x contains request rows [start,stop] with half-open nonnegative bounds, a nonnegative max-gap, and a set of forbidden byte positions. Empty requests contribute no work. Sort requests by start/stop, merge overlapping or nearby reads only if the gap has no forbidden byte. Return fetch spans and, in original request order, [fetch-index,offset-within-fetch,count] mappings. Empty requests map to null. This model plans origin reads only and does not redefine inclusive wire range semantics.
Why this case matters
Range responses combine representation identity, conditional requests, framing, and partial-object state.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(x):
rows=[(a,b,i) for i,(a,b) in enumerate(x['requests']) if a<b]
rows.sort(key=lambda r:(r[0],r[1]))
fetches=[]
assignments={}
for a,b,i in rows:
merge=bool(fetches) and a<=fetches[-1][1]+x['gap']
if False: merge=False
if merge:
index=len(fetches)-1
fetches[index][1]=max(fetches[index][1],b)
else:
index=len(fetches)
fetches.append([a,b])
assignments[i]=index
mapping=[]
for i,(a,b) in enumerate(x['requests']):
if a==b: mapping.append(None); continue
index=assignments[i]
mapping.append([index,a-fetches[index][0],b-a])
return [fetches,mapping]
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('protected-gap fixture 0', json.loads(json.dumps(solve({'requests':[[4,6],[0,2]],'gap':2,'forbidden':[]}))), json.loads(json.dumps([[[0,6]],[[0,4,2],[0,0,2]]])))
check('protected-gap fixture 1', json.loads(json.dumps(solve({'requests':[[0,2],[4,6]],'gap':2,'forbidden':[3]}))), json.loads(json.dumps([[[0,2],[4,6]],[[0,0,2],[1,0,2]]])))
check('protected-gap fixture 2', json.loads(json.dumps(solve({'requests':[[0,5],[2,3]],'gap':0,'forbidden':[]}))), json.loads(json.dumps([[[0,5]],[[0,0,5],[0,2,1]]])))
check('protected-gap fixture 3', json.loads(json.dumps(solve({'requests':[[0,2],[2,4]],'gap':0,'forbidden':[]}))), json.loads(json.dumps([[[0,4]],[[0,0,2],[0,2,2]]])))
check('protected-gap fixture 4', json.loads(json.dumps(solve({'requests':[[0,0],[3,3]],'gap':0,'forbidden':[]}))), json.loads(json.dumps([[],[None,None]])))
check('protected-gap fixture 5', json.loads(json.dumps(solve({'requests':[[2,4],[8,9]],'gap':1,'forbidden':[]}))), json.loads(json.dumps([[[2,4],[8,9]],[[0,0,2],[1,0,1]]])))
check('protected-gap fixture 6', json.loads(json.dumps(solve({'requests':[[0,N],[N,2*N]],'gap':0,'forbidden':[]}))), json.loads(json.dumps([[[0,2*N]],[[0,0,N],[0,N,N]]])))
check('protected-gap fixture 7', json.loads(json.dumps(solve({'requests':[],'gap':0,'forbidden':[]}))), json.loads(json.dumps([[],[]])))
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| protected-gap fixture 0 | [[[0, 6]], [[0, 4, 2], [0, 0, 2]]] | [[[0, 6]], [[0, 4, 2], [0, 0, 2]]] | Passed |
| protected-gap fixture 1 | [[[0, 6]], [[0, 0, 2], [0, 4, 2]]] | [[[0, 2], [4, 6]], [[0, 0, 2], [1, 0, 2]]] | Failed |
| protected-gap fixture 2 | [[[0, 5]], [[0, 0, 5], [0, 2, 1]]] | [[[0, 5]], [[0, 0, 5], [0, 2, 1]]] | Passed |
| protected-gap fixture 3 | [[[0, 4]], [[0, 0, 2], [0, 2, 2]]] | [[[0, 4]], [[0, 0, 2], [0, 2, 2]]] | Passed |
| protected-gap fixture 4 | [[], [None, None]] | [[], [None, None]] | Passed |
| protected-gap fixture 5 | [[[2, 4], [8, 9]], [[0, 0, 2], [1, 0, 1]]] | [[[2, 4], [8, 9]], [[0, 0, 2], [1, 0, 1]]] | Passed |
| protected-gap fixture 6 | [[[0, 2]], [[0, 0, 1], [0, 1, 1]]] | [[[0, 2]], [[0, 0, 1], [0, 1, 1]]] | Passed |
| protected-gap fixture 7 | [[], []] | [[], []] | Passed |
SHA-256 / 4bebf5ab33296cf6c133d5f32d13bcd0d6c59c299c0ea298b4d2b0111b06f093
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(x):
rows=[(a,b,i) for i,(a,b) in enumerate(x['requests']) if a<b]
rows.sort(key=lambda r:(r[0],r[1]))
fetches=[]
assignments={}
for a,b,i in rows:
merge=bool(fetches) and a<=fetches[-1][1]+x['gap']
if merge and fetches[-1][1] in x['forbidden']: merge=False
if merge:
index=len(fetches)-1
fetches[index][1]=max(fetches[index][1],b)
else:
index=len(fetches)
fetches.append([a,b])
assignments[i]=index
mapping=[]
for i,(a,b) in enumerate(x['requests']):
if a==b: mapping.append(None); continue
index=assignments[i]
mapping.append([index,a-fetches[index][0],b-a])
return [fetches,mapping]
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('protected-gap fixture 0', json.loads(json.dumps(solve({'requests':[[4,6],[0,2]],'gap':2,'forbidden':[]}))), json.loads(json.dumps([[[0,6]],[[0,4,2],[0,0,2]]])))
check('protected-gap fixture 1', json.loads(json.dumps(solve({'requests':[[0,2],[4,6]],'gap':2,'forbidden':[3]}))), json.loads(json.dumps([[[0,2],[4,6]],[[0,0,2],[1,0,2]]])))
check('protected-gap fixture 2', json.loads(json.dumps(solve({'requests':[[0,5],[2,3]],'gap':0,'forbidden':[]}))), json.loads(json.dumps([[[0,5]],[[0,0,5],[0,2,1]]])))
check('protected-gap fixture 3', json.loads(json.dumps(solve({'requests':[[0,2],[2,4]],'gap':0,'forbidden':[]}))), json.loads(json.dumps([[[0,4]],[[0,0,2],[0,2,2]]])))
check('protected-gap fixture 4', json.loads(json.dumps(solve({'requests':[[0,0],[3,3]],'gap':0,'forbidden':[]}))), json.loads(json.dumps([[],[None,None]])))
check('protected-gap fixture 5', json.loads(json.dumps(solve({'requests':[[2,4],[8,9]],'gap':1,'forbidden':[]}))), json.loads(json.dumps([[[2,4],[8,9]],[[0,0,2],[1,0,1]]])))
check('protected-gap fixture 6', json.loads(json.dumps(solve({'requests':[[0,N],[N,2*N]],'gap':0,'forbidden':[]}))), json.loads(json.dumps([[[0,2*N]],[[0,0,N],[0,N,N]]])))
check('protected-gap fixture 7', json.loads(json.dumps(solve({'requests':[],'gap':0,'forbidden':[]}))), json.loads(json.dumps([[],[]])))
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| protected-gap fixture 0 | [[[0, 6]], [[0, 4, 2], [0, 0, 2]]] | [[[0, 6]], [[0, 4, 2], [0, 0, 2]]] | Passed |
| protected-gap fixture 1 | [[[0, 6]], [[0, 0, 2], [0, 4, 2]]] | [[[0, 2], [4, 6]], [[0, 0, 2], [1, 0, 2]]] | Failed |
| protected-gap fixture 2 | [[[0, 5]], [[0, 0, 5], [0, 2, 1]]] | [[[0, 5]], [[0, 0, 5], [0, 2, 1]]] | Passed |
| protected-gap fixture 3 | [[[0, 4]], [[0, 0, 2], [0, 2, 2]]] | [[[0, 4]], [[0, 0, 2], [0, 2, 2]]] | Passed |
| protected-gap fixture 4 | [[], [None, None]] | [[], [None, None]] | Passed |
| protected-gap fixture 5 | [[[2, 4], [8, 9]], [[0, 0, 2], [1, 0, 1]]] | [[[2, 4], [8, 9]], [[0, 0, 2], [1, 0, 1]]] | Passed |
| protected-gap fixture 6 | [[[0, 2]], [[0, 0, 1], [0, 1, 1]]] | [[[0, 2]], [[0, 0, 1], [0, 1, 1]]] | Passed |
| protected-gap fixture 7 | [[], []] | [[], []] | Passed |
SHA-256 / 61413f63a2529cd67fbdcb0a58a93c639d9746bb0f3b566b9e8779bd4c31a378
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(x):
rows=[(a,b,i) for i,(a,b) in enumerate(x['requests']) if a<b]
rows.sort(key=lambda r:(r[0],r[1]))
fetches=[]
assignments={}
for a,b,i in rows:
merge=bool(fetches) and a<=fetches[-1][1]+x['gap']
if merge and any(p in x['forbidden'] for p in range(fetches[-1][1],a)): merge=False
if merge:
index=len(fetches)-1
fetches[index][1]=max(fetches[index][1],b)
else:
index=len(fetches)
fetches.append([a,b])
assignments[i]=index
mapping=[]
for i,(a,b) in enumerate(x['requests']):
if a==b: mapping.append(None); continue
index=assignments[i]
mapping.append([index,a-fetches[index][0],b-a])
return [fetches,mapping]
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('protected-gap fixture 0', json.loads(json.dumps(solve({'requests':[[4,6],[0,2]],'gap':2,'forbidden':[]}))), json.loads(json.dumps([[[0,6]],[[0,4,2],[0,0,2]]])))
check('protected-gap fixture 1', json.loads(json.dumps(solve({'requests':[[0,2],[4,6]],'gap':2,'forbidden':[3]}))), json.loads(json.dumps([[[0,2],[4,6]],[[0,0,2],[1,0,2]]])))
check('protected-gap fixture 2', json.loads(json.dumps(solve({'requests':[[0,5],[2,3]],'gap':0,'forbidden':[]}))), json.loads(json.dumps([[[0,5]],[[0,0,5],[0,2,1]]])))
check('protected-gap fixture 3', json.loads(json.dumps(solve({'requests':[[0,2],[2,4]],'gap':0,'forbidden':[]}))), json.loads(json.dumps([[[0,4]],[[0,0,2],[0,2,2]]])))
check('protected-gap fixture 4', json.loads(json.dumps(solve({'requests':[[0,0],[3,3]],'gap':0,'forbidden':[]}))), json.loads(json.dumps([[],[None,None]])))
check('protected-gap fixture 5', json.loads(json.dumps(solve({'requests':[[2,4],[8,9]],'gap':1,'forbidden':[]}))), json.loads(json.dumps([[[2,4],[8,9]],[[0,0,2],[1,0,1]]])))
check('protected-gap fixture 6', json.loads(json.dumps(solve({'requests':[[0,N],[N,2*N]],'gap':0,'forbidden':[]}))), json.loads(json.dumps([[[0,2*N]],[[0,0,N],[0,N,N]]])))
check('protected-gap fixture 7', json.loads(json.dumps(solve({'requests':[],'gap':0,'forbidden':[]}))), json.loads(json.dumps([[],[]])))
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| protected-gap fixture 0 | [[[0, 6]], [[0, 4, 2], [0, 0, 2]]] | [[[0, 6]], [[0, 4, 2], [0, 0, 2]]] | Passed |
| protected-gap fixture 1 | [[[0, 2], [4, 6]], [[0, 0, 2], [1, 0, 2]]] | [[[0, 2], [4, 6]], [[0, 0, 2], [1, 0, 2]]] | Passed |
| protected-gap fixture 2 | [[[0, 5]], [[0, 0, 5], [0, 2, 1]]] | [[[0, 5]], [[0, 0, 5], [0, 2, 1]]] | Passed |
| protected-gap fixture 3 | [[[0, 4]], [[0, 0, 2], [0, 2, 2]]] | [[[0, 4]], [[0, 0, 2], [0, 2, 2]]] | Passed |
| protected-gap fixture 4 | [[], [None, None]] | [[], [None, None]] | Passed |
| protected-gap fixture 5 | [[[2, 4], [8, 9]], [[0, 0, 2], [1, 0, 1]]] | [[[2, 4], [8, 9]], [[0, 0, 2], [1, 0, 1]]] | Passed |
| protected-gap fixture 6 | [[[0, 2]], [[0, 0, 1], [0, 1, 1]]] | [[[0, 2]], [[0, 0, 1], [0, 1, 1]]] | Passed |
| protected-gap fixture 7 | [[], []] | [[], []] | Passed |
SHA-256 / 88db453259295c378761d1956e1271afd4ba48777fb44d6f9f94cb01e9478698
Verification & scope
Deterministic simplified range service, with stipulated local policies and already parsed trusted inputs; not a complete HTTP implementation. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:41:21.609704+00:00.
Case digest / e23ac945ffcd5725a7f849ca8d98e25de5909a6956d652cb0ef30fb65e87f807