FA-27291 / HTTP ranges / Open access
A range client removes transfer framing before applying representation offsets: chunk lengths use hexadecimal representation · case 01
A range client removes transfer framing before applying representation offsets: chunk lengths use hexadecimal representation.
ROOT CAUSE
The chunked-origin-body-hexadecimal-size decision uses data=x['wire'] pos=0 body='' trailers=[] while True: end=data.find('\r\n',pos) if end<0: return None digits=data[pos:end].split(';',1)[0] if not 1<=len(digits)<=2 or any(c not in '0123456789abcdefABCDEF' for c in digits): return None size=int(digits,10) if digits.isdecimal() else 0 pos=end+2 if size==0: while True: end=data.find('\r\n',pos) if end<0: return None line=data[pos:end] pos=end+2 if not line: break if ':' not in line: return None trailers.append(line) if pos!=len(data): return None return [body[x['start']:x['stop']],len(body),trailers] if pos+size+2>len(data): return None if data[pos+size:pos+size+2]!='\r\n': return None body+=data[pos:pos+size] if len(body)>x['limit']: return None pos+=size+2.
VERIFIED REPAIR
Apply the bounded decision exactly: data=x['wire'] pos=0 body='' trailers=[] while True: end=data.find('\r\n',pos) if end<0: return None digits=data[pos:end].split(';',1)[0] if not 1<=len(digits)<=2 or any(c not in '0123456789abcdefABCDEF' for c in digits): return None size=int(digits,16) pos=end+2 if size==0: while True: end=data.find('\r\n',pos) if end<0: return None line=data[pos:end] pos=end+2 if not line: break if ':' not in line: return None trailers.append(line) if pos!=len(data): return None return [body[x['start']:x['stop']],len(body),trailers] if pos+size+2>len(data): return None if data[pos+size:pos+size+2]!='\r\n': return None body+=data[pos:pos+size] if len(body)>x['limit']: return None pos+=size+2
Unsuccessful approach: The partial repair uses data=x['wire'] pos=0 body='' trailers=[] while True: end=data.find('\r\n',pos) if end<0: return None digits=data[pos:end].split(';',1)[0] if not 1<=len(digits)<=2 or any(c not in '0123456789abcdefABCDEF' for c in digits): return None size=int(digits,16) if not digits.isdecimal() else int(digits,10) pos=end+2 if size==0: while True: end=data.find('\r\n',pos) if end<0: return None line=data[pos:end] pos=end+2 if not line: break if ':' not in line: return None trailers.append(line) if pos!=len(data): return None return [body[x['start']:x['stop']],len(body),trailers] if pos+size+2>len(data): return None if data[pos+size:pos+size+2]!='\r\n': return None body+=data[pos:pos+size] if len(body)>x['limit']: return None pos+=size+2, which still violates the stated contract.
Case contract
Decode a complete bounded ASCII chunked origin body. Size lines use 1..2 hexadecimal digits with optional semicolon extensions, followed by exact CRLF; each data chunk has exact trailing CRLF. A zero chunk ends data and introduces colon-bearing trailer lines terminated by an empty CRLF line. No bytes may follow trailers. Enforce cumulative decoded-byte limit x.limit. Return [decoded[start:stop],decoded-length,trailer-lines] or None. This controlled framing model does not implement general HTTP headers.
Why this case matters
Range responses combine representation identity, conditional requests, framing, and partial-object state.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(x):
data=x['wire']
pos=0
body=''
trailers=[]
while True:
end=data.find('\r\n',pos)
if end<0: return None
digits=data[pos:end].split(';',1)[0]
if not 1<=len(digits)<=2 or any(c not in '0123456789abcdefABCDEF' for c in digits): return None
size=int(digits,10) if digits.isdecimal() else 0
pos=end+2
if size==0:
while True:
end=data.find('\r\n',pos)
if end<0: return None
line=data[pos:end]
pos=end+2
if not line: break
if ':' not in line: return None
trailers.append(line)
if pos!=len(data): return None
return [body[x['start']:x['stop']],len(body),trailers]
if pos+size+2>len(data): return None
if data[pos+size:pos+size+2]!='\r\n': return None
body+=data[pos:pos+size]
if len(body)>x['limit']: return None
pos+=size+2
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('hexadecimal-size fixture 0', json.loads(json.dumps(solve({'wire':'A;foo=bar\r\n0123456789\r\n0\r\nX:y\r\n\r\n','start':2,'stop':6,'limit':20}))), json.loads(json.dumps(['2345',10,['X:y']])))
check('hexadecimal-size fixture 1', json.loads(json.dumps(solve({'wire':'2\r\nab\r\n3\r\ncde\r\n0\r\n\r\n','start':1,'stop':4,'limit':5}))), json.loads(json.dumps(['bcd',5,[]])))
check('hexadecimal-size fixture 2', json.loads(json.dumps(solve({'wire':'0\r\n\r\n','start':0,'stop':3,'limit':0}))), json.loads(json.dumps(['',0,[]])))
check('hexadecimal-size fixture 3', json.loads(json.dumps(solve({'wire':'1;z=q\r\nx\r\n0\r\n\r\n','start':0,'stop':1,'limit':1}))), json.loads(json.dumps(['x',1,[]])))
check('hexadecimal-size fixture 4', json.loads(json.dumps(solve({'wire':'1\r\nxXX0\r\n\r\n','start':0,'stop':1,'limit':2}))), json.loads(json.dumps(None)))
check('hexadecimal-size fixture 5', json.loads(json.dumps(solve({'wire':'1\r\nx\r\n0\r\n\r\nextra','start':0,'stop':1,'limit':2}))), json.loads(json.dumps(None)))
check('hexadecimal-size fixture 6', json.loads(json.dumps(solve({'wire':'1\r\nx\r\n0\r\nBadTrailer\r\n\r\n','start':0,'stop':1,'limit':2}))), json.loads(json.dumps(None)))
check('hexadecimal-size fixture 7', json.loads(json.dumps(solve({'wire':'2\r\nab\r\n2\r\ncd\r\n0\r\n\r\n','start':0,'stop':4,'limit':3}))), json.loads(json.dumps(None)))
check('hexadecimal-size fixture 8', json.loads(json.dumps(solve({'wire':'1\r\nx\r\n0\r\nX:a\r\nY:b\r\n\r\n','start':0,'stop':1,'limit':2}))), json.loads(json.dumps(['x',1,['X:a','Y:b']])))
check('hexadecimal-size fixture 9', json.loads(json.dumps(solve({'wire':format(N,"x")+"\r\n"+"p"*N+"\r\n0\r\n\r\n",'start':0,'stop':N,'limit':10}))), json.loads(json.dumps(["p"*N,N,[]])))
check('hexadecimal-size fixture 10', json.loads(json.dumps(solve({'wire':'10\r\nabcdefghijklmnop\r\n0\r\n\r\n','start':12,'stop':16,'limit':16}))), json.loads(json.dumps(['mnop',16,[]])))
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| hexadecimal-size fixture 0 | None | ['2345', 10, ['X:y']] | Failed |
| hexadecimal-size fixture 1 | ['bcd', 5, []] | ['bcd', 5, []] | Passed |
| hexadecimal-size fixture 2 | ['', 0, []] | ['', 0, []] | Passed |
| hexadecimal-size fixture 3 | ['x', 1, []] | ['x', 1, []] | Passed |
| hexadecimal-size fixture 4 | None | None | Passed |
| hexadecimal-size fixture 5 | None | None | Passed |
| hexadecimal-size fixture 6 | None | None | Passed |
| hexadecimal-size fixture 7 | None | None | Passed |
| hexadecimal-size fixture 8 | ['x', 1, ['X:a', 'Y:b']] | ['x', 1, ['X:a', 'Y:b']] | Passed |
| hexadecimal-size fixture 9 | ['p', 1, []] | ['p', 1, []] | Passed |
| hexadecimal-size fixture 10 | None | ['mnop', 16, []] | Failed |
SHA-256 / cae223d709928c034c9d92a039a7d114c3ee610351da245b3731f62e4fd9fdf7
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(x):
data=x['wire']
pos=0
body=''
trailers=[]
while True:
end=data.find('\r\n',pos)
if end<0: return None
digits=data[pos:end].split(';',1)[0]
if not 1<=len(digits)<=2 or any(c not in '0123456789abcdefABCDEF' for c in digits): return None
size=int(digits,16) if not digits.isdecimal() else int(digits,10)
pos=end+2
if size==0:
while True:
end=data.find('\r\n',pos)
if end<0: return None
line=data[pos:end]
pos=end+2
if not line: break
if ':' not in line: return None
trailers.append(line)
if pos!=len(data): return None
return [body[x['start']:x['stop']],len(body),trailers]
if pos+size+2>len(data): return None
if data[pos+size:pos+size+2]!='\r\n': return None
body+=data[pos:pos+size]
if len(body)>x['limit']: return None
pos+=size+2
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('hexadecimal-size fixture 0', json.loads(json.dumps(solve({'wire':'A;foo=bar\r\n0123456789\r\n0\r\nX:y\r\n\r\n','start':2,'stop':6,'limit':20}))), json.loads(json.dumps(['2345',10,['X:y']])))
check('hexadecimal-size fixture 1', json.loads(json.dumps(solve({'wire':'2\r\nab\r\n3\r\ncde\r\n0\r\n\r\n','start':1,'stop':4,'limit':5}))), json.loads(json.dumps(['bcd',5,[]])))
check('hexadecimal-size fixture 2', json.loads(json.dumps(solve({'wire':'0\r\n\r\n','start':0,'stop':3,'limit':0}))), json.loads(json.dumps(['',0,[]])))
check('hexadecimal-size fixture 3', json.loads(json.dumps(solve({'wire':'1;z=q\r\nx\r\n0\r\n\r\n','start':0,'stop':1,'limit':1}))), json.loads(json.dumps(['x',1,[]])))
check('hexadecimal-size fixture 4', json.loads(json.dumps(solve({'wire':'1\r\nxXX0\r\n\r\n','start':0,'stop':1,'limit':2}))), json.loads(json.dumps(None)))
check('hexadecimal-size fixture 5', json.loads(json.dumps(solve({'wire':'1\r\nx\r\n0\r\n\r\nextra','start':0,'stop':1,'limit':2}))), json.loads(json.dumps(None)))
check('hexadecimal-size fixture 6', json.loads(json.dumps(solve({'wire':'1\r\nx\r\n0\r\nBadTrailer\r\n\r\n','start':0,'stop':1,'limit':2}))), json.loads(json.dumps(None)))
check('hexadecimal-size fixture 7', json.loads(json.dumps(solve({'wire':'2\r\nab\r\n2\r\ncd\r\n0\r\n\r\n','start':0,'stop':4,'limit':3}))), json.loads(json.dumps(None)))
check('hexadecimal-size fixture 8', json.loads(json.dumps(solve({'wire':'1\r\nx\r\n0\r\nX:a\r\nY:b\r\n\r\n','start':0,'stop':1,'limit':2}))), json.loads(json.dumps(['x',1,['X:a','Y:b']])))
check('hexadecimal-size fixture 9', json.loads(json.dumps(solve({'wire':format(N,"x")+"\r\n"+"p"*N+"\r\n0\r\n\r\n",'start':0,'stop':N,'limit':10}))), json.loads(json.dumps(["p"*N,N,[]])))
check('hexadecimal-size fixture 10', json.loads(json.dumps(solve({'wire':'10\r\nabcdefghijklmnop\r\n0\r\n\r\n','start':12,'stop':16,'limit':16}))), json.loads(json.dumps(['mnop',16,[]])))
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| hexadecimal-size fixture 0 | ['2345', 10, ['X:y']] | ['2345', 10, ['X:y']] | Passed |
| hexadecimal-size fixture 1 | ['bcd', 5, []] | ['bcd', 5, []] | Passed |
| hexadecimal-size fixture 2 | ['', 0, []] | ['', 0, []] | Passed |
| hexadecimal-size fixture 3 | ['x', 1, []] | ['x', 1, []] | Passed |
| hexadecimal-size fixture 4 | None | None | Passed |
| hexadecimal-size fixture 5 | None | None | Passed |
| hexadecimal-size fixture 6 | None | None | Passed |
| hexadecimal-size fixture 7 | None | None | Passed |
| hexadecimal-size fixture 8 | ['x', 1, ['X:a', 'Y:b']] | ['x', 1, ['X:a', 'Y:b']] | Passed |
| hexadecimal-size fixture 9 | ['p', 1, []] | ['p', 1, []] | Passed |
| hexadecimal-size fixture 10 | None | ['mnop', 16, []] | Failed |
SHA-256 / cd30adeb998c196beed523ac51105afd9463fcfc5c19db0f8c82d0abc651d422
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(x):
data=x['wire']
pos=0
body=''
trailers=[]
while True:
end=data.find('\r\n',pos)
if end<0: return None
digits=data[pos:end].split(';',1)[0]
if not 1<=len(digits)<=2 or any(c not in '0123456789abcdefABCDEF' for c in digits): return None
size=int(digits,16)
pos=end+2
if size==0:
while True:
end=data.find('\r\n',pos)
if end<0: return None
line=data[pos:end]
pos=end+2
if not line: break
if ':' not in line: return None
trailers.append(line)
if pos!=len(data): return None
return [body[x['start']:x['stop']],len(body),trailers]
if pos+size+2>len(data): return None
if data[pos+size:pos+size+2]!='\r\n': return None
body+=data[pos:pos+size]
if len(body)>x['limit']: return None
pos+=size+2
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('hexadecimal-size fixture 0', json.loads(json.dumps(solve({'wire':'A;foo=bar\r\n0123456789\r\n0\r\nX:y\r\n\r\n','start':2,'stop':6,'limit':20}))), json.loads(json.dumps(['2345',10,['X:y']])))
check('hexadecimal-size fixture 1', json.loads(json.dumps(solve({'wire':'2\r\nab\r\n3\r\ncde\r\n0\r\n\r\n','start':1,'stop':4,'limit':5}))), json.loads(json.dumps(['bcd',5,[]])))
check('hexadecimal-size fixture 2', json.loads(json.dumps(solve({'wire':'0\r\n\r\n','start':0,'stop':3,'limit':0}))), json.loads(json.dumps(['',0,[]])))
check('hexadecimal-size fixture 3', json.loads(json.dumps(solve({'wire':'1;z=q\r\nx\r\n0\r\n\r\n','start':0,'stop':1,'limit':1}))), json.loads(json.dumps(['x',1,[]])))
check('hexadecimal-size fixture 4', json.loads(json.dumps(solve({'wire':'1\r\nxXX0\r\n\r\n','start':0,'stop':1,'limit':2}))), json.loads(json.dumps(None)))
check('hexadecimal-size fixture 5', json.loads(json.dumps(solve({'wire':'1\r\nx\r\n0\r\n\r\nextra','start':0,'stop':1,'limit':2}))), json.loads(json.dumps(None)))
check('hexadecimal-size fixture 6', json.loads(json.dumps(solve({'wire':'1\r\nx\r\n0\r\nBadTrailer\r\n\r\n','start':0,'stop':1,'limit':2}))), json.loads(json.dumps(None)))
check('hexadecimal-size fixture 7', json.loads(json.dumps(solve({'wire':'2\r\nab\r\n2\r\ncd\r\n0\r\n\r\n','start':0,'stop':4,'limit':3}))), json.loads(json.dumps(None)))
check('hexadecimal-size fixture 8', json.loads(json.dumps(solve({'wire':'1\r\nx\r\n0\r\nX:a\r\nY:b\r\n\r\n','start':0,'stop':1,'limit':2}))), json.loads(json.dumps(['x',1,['X:a','Y:b']])))
check('hexadecimal-size fixture 9', json.loads(json.dumps(solve({'wire':format(N,"x")+"\r\n"+"p"*N+"\r\n0\r\n\r\n",'start':0,'stop':N,'limit':10}))), json.loads(json.dumps(["p"*N,N,[]])))
check('hexadecimal-size fixture 10', json.loads(json.dumps(solve({'wire':'10\r\nabcdefghijklmnop\r\n0\r\n\r\n','start':12,'stop':16,'limit':16}))), json.loads(json.dumps(['mnop',16,[]])))
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| hexadecimal-size fixture 0 | ['2345', 10, ['X:y']] | ['2345', 10, ['X:y']] | Passed |
| hexadecimal-size fixture 1 | ['bcd', 5, []] | ['bcd', 5, []] | Passed |
| hexadecimal-size fixture 2 | ['', 0, []] | ['', 0, []] | Passed |
| hexadecimal-size fixture 3 | ['x', 1, []] | ['x', 1, []] | Passed |
| hexadecimal-size fixture 4 | None | None | Passed |
| hexadecimal-size fixture 5 | None | None | Passed |
| hexadecimal-size fixture 6 | None | None | Passed |
| hexadecimal-size fixture 7 | None | None | Passed |
| hexadecimal-size fixture 8 | ['x', 1, ['X:a', 'Y:b']] | ['x', 1, ['X:a', 'Y:b']] | Passed |
| hexadecimal-size fixture 9 | ['p', 1, []] | ['p', 1, []] | Passed |
| hexadecimal-size fixture 10 | ['mnop', 16, []] | ['mnop', 16, []] | Passed |
SHA-256 / d6de52b51aa93d30af0cc9beec37b19b7be5a17a9da048677268f525bf90d76f
Verification & scope
Deterministic simplified range service, with stipulated local policies and already parsed trusted inputs; not a complete HTTP implementation. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:41:23.853899+00:00.
Case digest / 54a31f10e35245fc6b43dd2d8921bdddfb8455db47cfaa5c790d793d71a6460f