FAILURE MAP
← Case archive

FA-6626 / HTTP semantics / Open access

CONNECT uses authority form and server-wide OPTIONS uses asterisk form · case 01

CONNECT uses authority form and server-wide OPTIONS uses asterisk form.

Verified by executionVariant 1 · 4 checks per implementationDownload source bundle ↓JSON ↗

ROOT CAUSE

The faulty implementation uses `'absolute' if '://' in target else 'origin'` for the request-target-form decision.

VERIFIED REPAIR

Apply the explicit request-target-form contract, including the tested boundary and negative cases.

Unsuccessful approach: The attempted repair uses `'authority' if method == 'CONNECT' else ('asterisk' if target == '*' else 'origin')` and still violates a separate fixture.

Case contract

CONNECT uses authority form and server-wide OPTIONS uses asterisk form: return the result specified by the explicit input/output boundary fixtures.

Why this case matters

This deterministic http semantics model isolates the request-target-form policy at a network component boundary.

1 / The failure

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json
import ipaddress
import re
from urllib.parse import urlsplit, urljoin
N = 1
observations = []
def solve(method, target):
    return 'absolute' if '://' in target else 'origin'
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
_fixtures = ["check('fixture 1', solve('CONNECT', 'host:443'), 'authority')", "check('fixture 2', solve('OPTIONS', '*'), 'asterisk')", "check('fixture 3', solve('GET', 'https://h/a'), 'absolute')", "check('fixture 4', solve('GET', '/a'), 'origin')"]
for _line in _fixtures[N % len(_fixtures):] + _fixtures[:N % len(_fixtures)]:
    exec(_line)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
fixture 2originasteriskFailed
fixture 3absoluteabsolutePassed
fixture 4originoriginPassed
fixture 1originauthorityFailed

SHA-256 / a9bff85a174c14762e304fb626cb65ffe90fd2a96eceb0533dd3059404c4b063

2 / The unsuccessful fix

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json
import ipaddress
import re
from urllib.parse import urlsplit, urljoin
N = 1
observations = []
def solve(method, target):
    return 'authority' if method == 'CONNECT' else ('asterisk' if target == '*' else 'origin')
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
_fixtures = ["check('fixture 1', solve('CONNECT', 'host:443'), 'authority')", "check('fixture 2', solve('OPTIONS', '*'), 'asterisk')", "check('fixture 3', solve('GET', 'https://h/a'), 'absolute')", "check('fixture 4', solve('GET', '/a'), 'origin')"]
for _line in _fixtures[N % len(_fixtures):] + _fixtures[:N % len(_fixtures)]:
    exec(_line)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
fixture 2asteriskasteriskPassed
fixture 3originabsoluteFailed
fixture 4originoriginPassed
fixture 1authorityauthorityPassed

SHA-256 / a14396cfa7019d4d68f45a8a1878e31bcd47769ea62753f1056e1bf6125a95b8

3 / The verified repair

Exit 0
"""Failure Map reference implementation. Python standard library only."""
import json
import ipaddress
import re
from urllib.parse import urlsplit, urljoin
N = 1
observations = []
def solve(method, target):
    return 'authority' if method == 'CONNECT' else ('asterisk' if method == 'OPTIONS' and target == '*' else ('absolute' if '://' in target else 'origin'))
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
_fixtures = ["check('fixture 1', solve('CONNECT', 'host:443'), 'authority')", "check('fixture 2', solve('OPTIONS', '*'), 'asterisk')", "check('fixture 3', solve('GET', 'https://h/a'), 'absolute')", "check('fixture 4', solve('GET', '/a'), 'origin')"]
for _line in _fixtures[N % len(_fixtures):] + _fixtures[:N % len(_fixtures)]:
    exec(_line)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
fixture 2asteriskasteriskPassed
fixture 3absoluteabsolutePassed
fixture 4originoriginPassed
fixture 1authorityauthorityPassed

SHA-256 / c202468833ea1a2ba9bffd9555123deb3e9724d89b3e60793f56b8311691953b

Verification & scope

Bounded deterministic policy model over validated inputs; not a complete protocol stack or an interoperability claim. The five variants rotate the same explicit fixture set. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.

Observations recorded using Python 3.12.14 at 2026-09-29T14:38:03.794618+00:00.

Case digest / 10a78f04b4120417dbeeb8182ffd994268df80f51f85783fcee9502a98393ae1