FAILURE MAP
← Case archive

FA-27326 / HTTP ranges / Open access

A range client removes transfer framing before applying representation offsets: the decoded byte cap is enforced across all chunks · case 01

A range client removes transfer framing before applying representation offsets: the decoded byte cap is enforced across all chunks.

Verified by executionVariant 1 · 11 checks per implementationDownload source bundle ↓JSON ↗

ROOT CAUSE

The chunked-origin-body-cumulative-limit decision uses data=x['wire'] pos=0 body='' trailers=[] while True: end=data.find('\r\n',pos) if end<0: return None digits=data[pos:end].split(';',1)[0] if not 1<=len(digits)<=2 or any(c not in '0123456789abcdefABCDEF' for c in digits): return None size=int(digits,16) pos=end+2 if size==0: while True: end=data.find('\r\n',pos) if end<0: return None line=data[pos:end] pos=end+2 if not line: break if ':' not in line: return None trailers.append(line) if pos!=len(data): return None return [body[x['start']:x['stop']],len(body),trailers] if pos+size+2>len(data): return None if data[pos+size:pos+size+2]!='\r\n': return None body+=data[pos:pos+size] if size>x['limit']: return None pos+=size+2.

VERIFIED REPAIR

Apply the bounded decision exactly: data=x['wire'] pos=0 body='' trailers=[] while True: end=data.find('\r\n',pos) if end<0: return None digits=data[pos:end].split(';',1)[0] if not 1<=len(digits)<=2 or any(c not in '0123456789abcdefABCDEF' for c in digits): return None size=int(digits,16) pos=end+2 if size==0: while True: end=data.find('\r\n',pos) if end<0: return None line=data[pos:end] pos=end+2 if not line: break if ':' not in line: return None trailers.append(line) if pos!=len(data): return None return [body[x['start']:x['stop']],len(body),trailers] if pos+size+2>len(data): return None if data[pos+size:pos+size+2]!='\r\n': return None body+=data[pos:pos+size] if len(body)>x['limit']: return None pos+=size+2

Unsuccessful approach: The partial repair uses data=x['wire'] pos=0 body='' trailers=[] while True: end=data.find('\r\n',pos) if end<0: return None digits=data[pos:end].split(';',1)[0] if not 1<=len(digits)<=2 or any(c not in '0123456789abcdefABCDEF' for c in digits): return None size=int(digits,16) pos=end+2 if size==0: while True: end=data.find('\r\n',pos) if end<0: return None line=data[pos:end] pos=end+2 if not line: break if ':' not in line: return None trailers.append(line) if pos!=len(data): return None return [body[x['start']:x['stop']],len(body),trailers] if pos+size+2>len(data): return None if data[pos+size:pos+size+2]!='\r\n': return None body+=data[pos:pos+size] if len(body)>x['limit']+size: return None pos+=size+2, which still violates the stated contract.

Case contract

Decode a complete bounded ASCII chunked origin body. Size lines use 1..2 hexadecimal digits with optional semicolon extensions, followed by exact CRLF; each data chunk has exact trailing CRLF. A zero chunk ends data and introduces colon-bearing trailer lines terminated by an empty CRLF line. No bytes may follow trailers. Enforce cumulative decoded-byte limit x.limit. Return [decoded[start:stop],decoded-length,trailer-lines] or None. This controlled framing model does not implement general HTTP headers.

Why this case matters

Range responses combine representation identity, conditional requests, framing, and partial-object state.

1 / The failure

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(x):
    data=x['wire']
    pos=0
    body=''
    trailers=[]
    while True:
        end=data.find('\r\n',pos)
        if end<0: return None
        digits=data[pos:end].split(';',1)[0]
        if not 1<=len(digits)<=2 or any(c not in '0123456789abcdefABCDEF' for c in digits): return None
        size=int(digits,16)
        pos=end+2
        if size==0:
            while True:
                end=data.find('\r\n',pos)
                if end<0: return None
                line=data[pos:end]
                pos=end+2
                if not line: break
                if ':' not in line: return None
                trailers.append(line)
            if pos!=len(data): return None
            return [body[x['start']:x['stop']],len(body),trailers]
        if pos+size+2>len(data): return None
        if data[pos+size:pos+size+2]!='\r\n': return None
        body+=data[pos:pos+size]
        if size>x['limit']: return None
        pos+=size+2
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('cumulative-limit fixture 0', json.loads(json.dumps(solve({'wire':'A;foo=bar\r\n0123456789\r\n0\r\nX:y\r\n\r\n','start':2,'stop':6,'limit':20}))), json.loads(json.dumps(['2345',10,['X:y']])))
check('cumulative-limit fixture 1', json.loads(json.dumps(solve({'wire':'2\r\nab\r\n3\r\ncde\r\n0\r\n\r\n','start':1,'stop':4,'limit':5}))), json.loads(json.dumps(['bcd',5,[]])))
check('cumulative-limit fixture 2', json.loads(json.dumps(solve({'wire':'0\r\n\r\n','start':0,'stop':3,'limit':0}))), json.loads(json.dumps(['',0,[]])))
check('cumulative-limit fixture 3', json.loads(json.dumps(solve({'wire':'1;z=q\r\nx\r\n0\r\n\r\n','start':0,'stop':1,'limit':1}))), json.loads(json.dumps(['x',1,[]])))
check('cumulative-limit fixture 4', json.loads(json.dumps(solve({'wire':'1\r\nxXX0\r\n\r\n','start':0,'stop':1,'limit':2}))), json.loads(json.dumps(None)))
check('cumulative-limit fixture 5', json.loads(json.dumps(solve({'wire':'1\r\nx\r\n0\r\n\r\nextra','start':0,'stop':1,'limit':2}))), json.loads(json.dumps(None)))
check('cumulative-limit fixture 6', json.loads(json.dumps(solve({'wire':'1\r\nx\r\n0\r\nBadTrailer\r\n\r\n','start':0,'stop':1,'limit':2}))), json.loads(json.dumps(None)))
check('cumulative-limit fixture 7', json.loads(json.dumps(solve({'wire':'2\r\nab\r\n2\r\ncd\r\n0\r\n\r\n','start':0,'stop':4,'limit':3}))), json.loads(json.dumps(None)))
check('cumulative-limit fixture 8', json.loads(json.dumps(solve({'wire':'1\r\nx\r\n0\r\nX:a\r\nY:b\r\n\r\n','start':0,'stop':1,'limit':2}))), json.loads(json.dumps(['x',1,['X:a','Y:b']])))
check('cumulative-limit fixture 9', json.loads(json.dumps(solve({'wire':format(N,"x")+"\r\n"+"p"*N+"\r\n0\r\n\r\n",'start':0,'stop':N,'limit':10}))), json.loads(json.dumps(["p"*N,N,[]])))
check('cumulative-limit fixture 10', json.loads(json.dumps(solve({'wire':'10\r\nabcdefghijklmnop\r\n0\r\n\r\n','start':12,'stop':16,'limit':16}))), json.loads(json.dumps(['mnop',16,[]])))
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
cumulative-limit fixture 0['2345', 10, ['X:y']]['2345', 10, ['X:y']]Passed
cumulative-limit fixture 1['bcd', 5, []]['bcd', 5, []]Passed
cumulative-limit fixture 2['', 0, []]['', 0, []]Passed
cumulative-limit fixture 3['x', 1, []]['x', 1, []]Passed
cumulative-limit fixture 4NoneNonePassed
cumulative-limit fixture 5NoneNonePassed
cumulative-limit fixture 6NoneNonePassed
cumulative-limit fixture 7['abcd', 4, []]NoneFailed
cumulative-limit fixture 8['x', 1, ['X:a', 'Y:b']]['x', 1, ['X:a', 'Y:b']]Passed
cumulative-limit fixture 9['p', 1, []]['p', 1, []]Passed
cumulative-limit fixture 10['mnop', 16, []]['mnop', 16, []]Passed

SHA-256 / ac45db31c2c0b168671c0fd894c05a01649f7f4286b4dfb3093803b495416cbd

2 / The unsuccessful fix

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(x):
    data=x['wire']
    pos=0
    body=''
    trailers=[]
    while True:
        end=data.find('\r\n',pos)
        if end<0: return None
        digits=data[pos:end].split(';',1)[0]
        if not 1<=len(digits)<=2 or any(c not in '0123456789abcdefABCDEF' for c in digits): return None
        size=int(digits,16)
        pos=end+2
        if size==0:
            while True:
                end=data.find('\r\n',pos)
                if end<0: return None
                line=data[pos:end]
                pos=end+2
                if not line: break
                if ':' not in line: return None
                trailers.append(line)
            if pos!=len(data): return None
            return [body[x['start']:x['stop']],len(body),trailers]
        if pos+size+2>len(data): return None
        if data[pos+size:pos+size+2]!='\r\n': return None
        body+=data[pos:pos+size]
        if len(body)>x['limit']+size: return None
        pos+=size+2
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('cumulative-limit fixture 0', json.loads(json.dumps(solve({'wire':'A;foo=bar\r\n0123456789\r\n0\r\nX:y\r\n\r\n','start':2,'stop':6,'limit':20}))), json.loads(json.dumps(['2345',10,['X:y']])))
check('cumulative-limit fixture 1', json.loads(json.dumps(solve({'wire':'2\r\nab\r\n3\r\ncde\r\n0\r\n\r\n','start':1,'stop':4,'limit':5}))), json.loads(json.dumps(['bcd',5,[]])))
check('cumulative-limit fixture 2', json.loads(json.dumps(solve({'wire':'0\r\n\r\n','start':0,'stop':3,'limit':0}))), json.loads(json.dumps(['',0,[]])))
check('cumulative-limit fixture 3', json.loads(json.dumps(solve({'wire':'1;z=q\r\nx\r\n0\r\n\r\n','start':0,'stop':1,'limit':1}))), json.loads(json.dumps(['x',1,[]])))
check('cumulative-limit fixture 4', json.loads(json.dumps(solve({'wire':'1\r\nxXX0\r\n\r\n','start':0,'stop':1,'limit':2}))), json.loads(json.dumps(None)))
check('cumulative-limit fixture 5', json.loads(json.dumps(solve({'wire':'1\r\nx\r\n0\r\n\r\nextra','start':0,'stop':1,'limit':2}))), json.loads(json.dumps(None)))
check('cumulative-limit fixture 6', json.loads(json.dumps(solve({'wire':'1\r\nx\r\n0\r\nBadTrailer\r\n\r\n','start':0,'stop':1,'limit':2}))), json.loads(json.dumps(None)))
check('cumulative-limit fixture 7', json.loads(json.dumps(solve({'wire':'2\r\nab\r\n2\r\ncd\r\n0\r\n\r\n','start':0,'stop':4,'limit':3}))), json.loads(json.dumps(None)))
check('cumulative-limit fixture 8', json.loads(json.dumps(solve({'wire':'1\r\nx\r\n0\r\nX:a\r\nY:b\r\n\r\n','start':0,'stop':1,'limit':2}))), json.loads(json.dumps(['x',1,['X:a','Y:b']])))
check('cumulative-limit fixture 9', json.loads(json.dumps(solve({'wire':format(N,"x")+"\r\n"+"p"*N+"\r\n0\r\n\r\n",'start':0,'stop':N,'limit':10}))), json.loads(json.dumps(["p"*N,N,[]])))
check('cumulative-limit fixture 10', json.loads(json.dumps(solve({'wire':'10\r\nabcdefghijklmnop\r\n0\r\n\r\n','start':12,'stop':16,'limit':16}))), json.loads(json.dumps(['mnop',16,[]])))
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
cumulative-limit fixture 0['2345', 10, ['X:y']]['2345', 10, ['X:y']]Passed
cumulative-limit fixture 1['bcd', 5, []]['bcd', 5, []]Passed
cumulative-limit fixture 2['', 0, []]['', 0, []]Passed
cumulative-limit fixture 3['x', 1, []]['x', 1, []]Passed
cumulative-limit fixture 4NoneNonePassed
cumulative-limit fixture 5NoneNonePassed
cumulative-limit fixture 6NoneNonePassed
cumulative-limit fixture 7['abcd', 4, []]NoneFailed
cumulative-limit fixture 8['x', 1, ['X:a', 'Y:b']]['x', 1, ['X:a', 'Y:b']]Passed
cumulative-limit fixture 9['p', 1, []]['p', 1, []]Passed
cumulative-limit fixture 10['mnop', 16, []]['mnop', 16, []]Passed

SHA-256 / fd6c504383be0f66c5f70f61a3b5b578c77a3b3ce127f788c87c162cdb13fe9a

3 / The verified repair

Exit 0
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(x):
    data=x['wire']
    pos=0
    body=''
    trailers=[]
    while True:
        end=data.find('\r\n',pos)
        if end<0: return None
        digits=data[pos:end].split(';',1)[0]
        if not 1<=len(digits)<=2 or any(c not in '0123456789abcdefABCDEF' for c in digits): return None
        size=int(digits,16)
        pos=end+2
        if size==0:
            while True:
                end=data.find('\r\n',pos)
                if end<0: return None
                line=data[pos:end]
                pos=end+2
                if not line: break
                if ':' not in line: return None
                trailers.append(line)
            if pos!=len(data): return None
            return [body[x['start']:x['stop']],len(body),trailers]
        if pos+size+2>len(data): return None
        if data[pos+size:pos+size+2]!='\r\n': return None
        body+=data[pos:pos+size]
        if len(body)>x['limit']: return None
        pos+=size+2
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('cumulative-limit fixture 0', json.loads(json.dumps(solve({'wire':'A;foo=bar\r\n0123456789\r\n0\r\nX:y\r\n\r\n','start':2,'stop':6,'limit':20}))), json.loads(json.dumps(['2345',10,['X:y']])))
check('cumulative-limit fixture 1', json.loads(json.dumps(solve({'wire':'2\r\nab\r\n3\r\ncde\r\n0\r\n\r\n','start':1,'stop':4,'limit':5}))), json.loads(json.dumps(['bcd',5,[]])))
check('cumulative-limit fixture 2', json.loads(json.dumps(solve({'wire':'0\r\n\r\n','start':0,'stop':3,'limit':0}))), json.loads(json.dumps(['',0,[]])))
check('cumulative-limit fixture 3', json.loads(json.dumps(solve({'wire':'1;z=q\r\nx\r\n0\r\n\r\n','start':0,'stop':1,'limit':1}))), json.loads(json.dumps(['x',1,[]])))
check('cumulative-limit fixture 4', json.loads(json.dumps(solve({'wire':'1\r\nxXX0\r\n\r\n','start':0,'stop':1,'limit':2}))), json.loads(json.dumps(None)))
check('cumulative-limit fixture 5', json.loads(json.dumps(solve({'wire':'1\r\nx\r\n0\r\n\r\nextra','start':0,'stop':1,'limit':2}))), json.loads(json.dumps(None)))
check('cumulative-limit fixture 6', json.loads(json.dumps(solve({'wire':'1\r\nx\r\n0\r\nBadTrailer\r\n\r\n','start':0,'stop':1,'limit':2}))), json.loads(json.dumps(None)))
check('cumulative-limit fixture 7', json.loads(json.dumps(solve({'wire':'2\r\nab\r\n2\r\ncd\r\n0\r\n\r\n','start':0,'stop':4,'limit':3}))), json.loads(json.dumps(None)))
check('cumulative-limit fixture 8', json.loads(json.dumps(solve({'wire':'1\r\nx\r\n0\r\nX:a\r\nY:b\r\n\r\n','start':0,'stop':1,'limit':2}))), json.loads(json.dumps(['x',1,['X:a','Y:b']])))
check('cumulative-limit fixture 9', json.loads(json.dumps(solve({'wire':format(N,"x")+"\r\n"+"p"*N+"\r\n0\r\n\r\n",'start':0,'stop':N,'limit':10}))), json.loads(json.dumps(["p"*N,N,[]])))
check('cumulative-limit fixture 10', json.loads(json.dumps(solve({'wire':'10\r\nabcdefghijklmnop\r\n0\r\n\r\n','start':12,'stop':16,'limit':16}))), json.loads(json.dumps(['mnop',16,[]])))
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
cumulative-limit fixture 0['2345', 10, ['X:y']]['2345', 10, ['X:y']]Passed
cumulative-limit fixture 1['bcd', 5, []]['bcd', 5, []]Passed
cumulative-limit fixture 2['', 0, []]['', 0, []]Passed
cumulative-limit fixture 3['x', 1, []]['x', 1, []]Passed
cumulative-limit fixture 4NoneNonePassed
cumulative-limit fixture 5NoneNonePassed
cumulative-limit fixture 6NoneNonePassed
cumulative-limit fixture 7NoneNonePassed
cumulative-limit fixture 8['x', 1, ['X:a', 'Y:b']]['x', 1, ['X:a', 'Y:b']]Passed
cumulative-limit fixture 9['p', 1, []]['p', 1, []]Passed
cumulative-limit fixture 10['mnop', 16, []]['mnop', 16, []]Passed

SHA-256 / a5ba6f3b7b6ef1b083d8ebbbd2f3d978d75a7da94d2ce8a858f54bc6364bfacf

Verification & scope

Deterministic simplified range service, with stipulated local policies and already parsed trusted inputs; not a complete HTTP implementation. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.

Observations recorded using Python 3.12.14 at 2026-09-29T14:41:24.029506+00:00.

Case digest / 77a1a47e191f7120b3c90008bd4d3dbfa9ab647de29db3e6fdd932ff17727346