FA-3701 / Binary formats / Open access
An unknown TLV tag shifts the next record boundary · case 01
An unknown TLV tag shifts the next record boundary.
ROOT CAUSE
The implementation applies an operation whose text or grammar semantics violate this contract: Decode tag,length,value records, returning values for tag 1 and skipping unknown tags; malformed input returns None.
THE FAILURE
The implementation applies an operation whose text or grammar semantics violate this contract: Decode tag,length,value records, returning values for tag 1 and skipping unknown tags; malformed input returns None.
Unsuccessful approach: The attempted repair handles the primary example but still violates a separate boundary of the same contract.
Case contract
Decode tag,length,value records, returning values for tag 1 and skipping unknown tags; malformed input returns None.
Why this case matters
A local executable model for consumers of structured text; oracle values are authored literals, not outputs copied from the repaired implementation.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import re, unicodedata, json, csv, io, html, base64, binascii, codecs, struct
from urllib.parse import quote, unquote, unquote_to_bytes, urlencode, parse_qsl, urlsplit, urlunsplit
from email.header import decode_header, make_header
from email.utils import getaddresses
from xml.etree import ElementTree as ET
import shlex, string, textwrap
N = 1
observations = []
def solve(x):
try:
return [x[i+2] for i in range(0,len(x)-2,3) if x[i]==1]
except Exception as exc:
return {"error": type(exc).__name__}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('boundary 1', solve([2, 2, 8, 9, 1, 1, 7]), [[7]])
check('boundary 2', solve([1, 0]), [[]])
check('boundary 3', solve([1, 2, 9]), None)
check('boundary 4', solve([]), [])
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| boundary 1 | [] | [[7]] | Failed |
| boundary 2 | [] | [[]] | Failed |
| boundary 3 | [9] | None | Failed |
| boundary 4 | [] | [] | Passed |
SHA-256 / 8a129677f6a83c393c2c303d76a008ec5875d51bc3fa198cbf2305408218d078
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import re, unicodedata, json, csv, io, html, base64, binascii, codecs, struct
from urllib.parse import quote, unquote, unquote_to_bytes, urlencode, parse_qsl, urlsplit, urlunsplit
from email.header import decode_header, make_header
from email.utils import getaddresses
from xml.etree import ElementTree as ET
import shlex, string, textwrap
N = 1
observations = []
def solve(x):
try:
out=[]
i=0
while i<len(x):
if i+2>len(x): return None
t,n=x[i:i+2]
if i+2+n>len(x): return None
if t==1: out.append(x[i+2:i+2+n])
i+=3
return out
except Exception as exc:
return {"error": type(exc).__name__}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('boundary 1', solve([2, 2, 8, 9, 1, 1, 7]), [[7]])
check('boundary 2', solve([1, 0]), [[]])
check('boundary 3', solve([1, 2, 9]), None)
check('boundary 4', solve([]), [])
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| boundary 1 | None | [[7]] | Failed |
| boundary 2 | [[]] | [[]] | Passed |
| boundary 3 | None | None | Passed |
| boundary 4 | [] | [] | Passed |
SHA-256 / 84ed006d5083b20a70c2119b74ddfa885b7fd5496af5c01869c91167c5fa081c
HELD IN THE MEMBER ARCHIVE
The verified repair and its recorded checks are member-only.
This mechanism has 4 recorded checks per implementation. The open-access tier publishes the failure and the unsuccessful fix; the repaired source that passes every check, and the observations that prove it, are available to members.
Every case sharing this mechanism uses the same contract and the same repair, so this one record is held back for all of them.
Member access is invitation-based. Sign in with your invited account to inspect the repair.
Sign in to the archive ↗Verification & scope
This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:37:29.570534+00:00.
Case digest / e89b9f9459a308f5d8a17c5710b4331878a2663d6d4e11228d0ce5cafde6a7a0