FA-3211 / Markup / Open access
Attribute escaping leaves quote delimiters active · case 01
Attribute escaping leaves quote delimiters active.
ROOT CAUSE
The implementation applies an operation whose text or grammar semantics violate this contract: Escape ampersand, angle brackets and both quote characters for HTML attribute text.
VERIFIED REPAIR
Implement the complete stated contract, including the boundary fixtures: Escape ampersand, angle brackets and both quote characters for HTML attribute text.
Unsuccessful approach: The attempted repair handles the primary example but still violates a separate boundary of the same contract.
Case contract
Escape ampersand, angle brackets and both quote characters for HTML attribute text.
Why this case matters
A local executable model for consumers of structured text; oracle values are authored literals, not outputs copied from the repaired implementation.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import re, unicodedata, json, csv, io, html, base64, binascii, codecs, struct
from urllib.parse import quote, unquote, unquote_to_bytes, urlencode, parse_qsl, urlsplit, urlunsplit
from email.header import decode_header, make_header
from email.utils import getaddresses
from xml.etree import ElementTree as ET
import shlex, string, textwrap
N = 1
observations = []
def solve(x):
try:
return x.replace('<','<').replace('>','>')
except Exception as exc:
return {"error": type(exc).__name__}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('boundary 1', solve('"a"'), '"a"')
check('boundary 2', solve("'"), ''')
check('boundary 3', solve('<'), '&lt;')
check('boundary 4', solve('<>'), '<>')
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| boundary 1 | "a" | "a" | Failed |
| boundary 2 | ' | ' | Failed |
| boundary 3 | < | &lt; | Failed |
| boundary 4 | <> | <> | Passed |
SHA-256 / c33da5952b19237fe34e7b750b9bc382b16cc3eb3762abf7bb6288a309adf52b
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import re, unicodedata, json, csv, io, html, base64, binascii, codecs, struct
from urllib.parse import quote, unquote, unquote_to_bytes, urlencode, parse_qsl, urlsplit, urlunsplit
from email.header import decode_header, make_header
from email.utils import getaddresses
from xml.etree import ElementTree as ET
import shlex, string, textwrap
N = 1
observations = []
def solve(x):
try:
return html.escape(x,quote=False)
except Exception as exc:
return {"error": type(exc).__name__}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('boundary 1', solve('"a"'), '"a"')
check('boundary 2', solve("'"), ''')
check('boundary 3', solve('<'), '&lt;')
check('boundary 4', solve('<>'), '<>')
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| boundary 1 | "a" | "a" | Failed |
| boundary 2 | ' | ' | Failed |
| boundary 3 | &lt; | &lt; | Passed |
| boundary 4 | <> | <> | Passed |
SHA-256 / 916ee176e018f92e5273d59ed8fcc84a5a41dfa97f8ec731978821dd23402468
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
import re, unicodedata, json, csv, io, html, base64, binascii, codecs, struct
from urllib.parse import quote, unquote, unquote_to_bytes, urlencode, parse_qsl, urlsplit, urlunsplit
from email.header import decode_header, make_header
from email.utils import getaddresses
from xml.etree import ElementTree as ET
import shlex, string, textwrap
N = 1
observations = []
def solve(x):
try:
return html.escape(x,quote=True)
except Exception as exc:
return {"error": type(exc).__name__}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('boundary 1', solve('"a"'), '"a"')
check('boundary 2', solve("'"), ''')
check('boundary 3', solve('<'), '&lt;')
check('boundary 4', solve('<>'), '<>')
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| boundary 1 | "a" | "a" | Passed |
| boundary 2 | ' | ' | Passed |
| boundary 3 | &lt; | &lt; | Passed |
| boundary 4 | <> | <> | Passed |
SHA-256 / 759fb0c9e9bb1f4571f83a9d0bc911758e3c35f43a10271e25eccb7e929ec38e
Verification & scope
This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:37:22.572852+00:00.
Case digest / ced541658db7eea7577fe8e58b48f2a4fffdb23b0a7d98ca2c8c2452cd11f8c9