FA-4041 / Markup / Open access
HTML escaping double-escapes the entities it just generated · case 01
HTML escaping double-escapes the entities it just generated.
ROOT CAUSE
The implementation applies an operation whose text or grammar semantics violate this contract: Escape only ampersand and less-than once from original text.
VERIFIED REPAIR
Implement the complete stated contract, including the boundary fixtures: Escape only ampersand and less-than once from original text.
Unsuccessful approach: The attempted repair handles the primary example but still violates a separate boundary of the same contract.
Case contract
Escape only ampersand and less-than once from original text.
Why this case matters
A local executable model for consumers of structured text; oracle values are authored literals, not outputs copied from the repaired implementation.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import re, unicodedata, json, csv, io, html, base64, binascii, codecs, struct
from urllib.parse import quote, unquote, unquote_to_bytes, urlencode, parse_qsl, urlsplit, urlunsplit
from email.header import decode_header, make_header
from email.utils import getaddresses
from xml.etree import ElementTree as ET
import shlex, string, textwrap
N = 1
observations = []
def solve(x):
try:
return x.replace('<','<').replace('&','&')
except Exception as exc:
return {"error": type(exc).__name__}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('boundary 1', solve('<'), '<')
check('boundary 2', solve('&'), '&')
check('boundary 3', solve('<'), '&lt;')
check('boundary 4', solve('a>b'), 'a>b')
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| boundary 1 | &lt; | < | Failed |
| boundary 2 | & | & | Passed |
| boundary 3 | &lt; | &lt; | Passed |
| boundary 4 | a>b | a>b | Passed |
SHA-256 / 388cf91212cc0ab5974c43f3e94a862e52a925942ddfcd902f1a74be06b2de1b
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import re, unicodedata, json, csv, io, html, base64, binascii, codecs, struct
from urllib.parse import quote, unquote, unquote_to_bytes, urlencode, parse_qsl, urlsplit, urlunsplit
from email.header import decode_header, make_header
from email.utils import getaddresses
from xml.etree import ElementTree as ET
import shlex, string, textwrap
N = 1
observations = []
def solve(x):
try:
return x.replace('<','<')
except Exception as exc:
return {"error": type(exc).__name__}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('boundary 1', solve('<'), '<')
check('boundary 2', solve('&'), '&')
check('boundary 3', solve('<'), '&lt;')
check('boundary 4', solve('a>b'), 'a>b')
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| boundary 1 | < | < | Passed |
| boundary 2 | & | & | Failed |
| boundary 3 | < | &lt; | Failed |
| boundary 4 | a>b | a>b | Passed |
SHA-256 / ddb181f3f4d2256e0f2bbeac2e1851159b73eb5fd99e74277425582946e91eb1
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
import re, unicodedata, json, csv, io, html, base64, binascii, codecs, struct
from urllib.parse import quote, unquote, unquote_to_bytes, urlencode, parse_qsl, urlsplit, urlunsplit
from email.header import decode_header, make_header
from email.utils import getaddresses
from xml.etree import ElementTree as ET
import shlex, string, textwrap
N = 1
observations = []
def solve(x):
try:
return x.replace('&','&').replace('<','<')
except Exception as exc:
return {"error": type(exc).__name__}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('boundary 1', solve('<'), '<')
check('boundary 2', solve('&'), '&')
check('boundary 3', solve('<'), '&lt;')
check('boundary 4', solve('a>b'), 'a>b')
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| boundary 1 | < | < | Passed |
| boundary 2 | & | & | Passed |
| boundary 3 | &lt; | &lt; | Passed |
| boundary 4 | a>b | a>b | Passed |
SHA-256 / ae6542126fb8bf6fa61297bcd7f194b0ba58165d6986b620f0aaab0268fe5d74
Verification & scope
This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:37:34.769767+00:00.
Case digest / 63367688b2248356163d83f552d758bfe06079104e011fe225eacf5e01c6e2b4