FA-6626 / HTTP semantics / Open access
CONNECT uses authority form and server-wide OPTIONS uses asterisk form · case 01
CONNECT uses authority form and server-wide OPTIONS uses asterisk form.
ROOT CAUSE
The faulty implementation uses `'absolute' if '://' in target else 'origin'` for the request-target-form decision.
VERIFIED REPAIR
Apply the explicit request-target-form contract, including the tested boundary and negative cases.
Unsuccessful approach: The attempted repair uses `'authority' if method == 'CONNECT' else ('asterisk' if target == '*' else 'origin')` and still violates a separate fixture.
Case contract
CONNECT uses authority form and server-wide OPTIONS uses asterisk form: return the result specified by the explicit input/output boundary fixtures.
Why this case matters
This deterministic http semantics model isolates the request-target-form policy at a network component boundary.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import ipaddress
import re
from urllib.parse import urlsplit, urljoin
N = 1
observations = []
def solve(method, target):
return 'absolute' if '://' in target else 'origin'
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
_fixtures = ["check('fixture 1', solve('CONNECT', 'host:443'), 'authority')", "check('fixture 2', solve('OPTIONS', '*'), 'asterisk')", "check('fixture 3', solve('GET', 'https://h/a'), 'absolute')", "check('fixture 4', solve('GET', '/a'), 'origin')"]
for _line in _fixtures[N % len(_fixtures):] + _fixtures[:N % len(_fixtures)]:
exec(_line)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| fixture 2 | origin | asterisk | Failed |
| fixture 3 | absolute | absolute | Passed |
| fixture 4 | origin | origin | Passed |
| fixture 1 | origin | authority | Failed |
SHA-256 / a9bff85a174c14762e304fb626cb65ffe90fd2a96eceb0533dd3059404c4b063
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import ipaddress
import re
from urllib.parse import urlsplit, urljoin
N = 1
observations = []
def solve(method, target):
return 'authority' if method == 'CONNECT' else ('asterisk' if target == '*' else 'origin')
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
_fixtures = ["check('fixture 1', solve('CONNECT', 'host:443'), 'authority')", "check('fixture 2', solve('OPTIONS', '*'), 'asterisk')", "check('fixture 3', solve('GET', 'https://h/a'), 'absolute')", "check('fixture 4', solve('GET', '/a'), 'origin')"]
for _line in _fixtures[N % len(_fixtures):] + _fixtures[:N % len(_fixtures)]:
exec(_line)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| fixture 2 | asterisk | asterisk | Passed |
| fixture 3 | origin | absolute | Failed |
| fixture 4 | origin | origin | Passed |
| fixture 1 | authority | authority | Passed |
SHA-256 / a14396cfa7019d4d68f45a8a1878e31bcd47769ea62753f1056e1bf6125a95b8
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
import ipaddress
import re
from urllib.parse import urlsplit, urljoin
N = 1
observations = []
def solve(method, target):
return 'authority' if method == 'CONNECT' else ('asterisk' if method == 'OPTIONS' and target == '*' else ('absolute' if '://' in target else 'origin'))
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
_fixtures = ["check('fixture 1', solve('CONNECT', 'host:443'), 'authority')", "check('fixture 2', solve('OPTIONS', '*'), 'asterisk')", "check('fixture 3', solve('GET', 'https://h/a'), 'absolute')", "check('fixture 4', solve('GET', '/a'), 'origin')"]
for _line in _fixtures[N % len(_fixtures):] + _fixtures[:N % len(_fixtures)]:
exec(_line)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| fixture 2 | asterisk | asterisk | Passed |
| fixture 3 | absolute | absolute | Passed |
| fixture 4 | origin | origin | Passed |
| fixture 1 | authority | authority | Passed |
SHA-256 / c202468833ea1a2ba9bffd9555123deb3e9724d89b3e60793f56b8311691953b
Verification & scope
Bounded deterministic policy model over validated inputs; not a complete protocol stack or an interoperability claim. The five variants rotate the same explicit fixture set. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:38:03.794618+00:00.
Case digest / 10a78f04b4120417dbeeb8182ffd994268df80f51f85783fcee9502a98393ae1