{"abstract":"Private packages are published publicly.","category":"Packaging","checks":7,"contract":"Reject an immutable version with changed digest; skip equal published digests; reject missing attestations; reject private packages on public registries; otherwise publish. Existing equality takes precedence over publication checks.","evaluation_group":"xt-publish-plan","failed_approach":"The attempted repair substitutes if private and registry != 'public':. Fixture 5 still yields 'publish' instead of 'private-package'.","family":"xt-publish-plan-private-public","id":"FA-10001","implementations":{"attempt":{"sha256":"d60308fc51136fd518b1f36d72d5b39bd8720b6fd0715b6441cd8fd96a75defd","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(version, digest, existing, attested, private, registry):\n    if version in existing:\n        if existing[version] == digest: return 'skip'\n        return 'immutable-conflict'\n    if not attested: return 'missing-attestation'\n    if private and registry != 'public': return 'private-package'\n    return 'publish'\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\ncheck('fixture 1', solve('1', 'a', {}, True, False, 'public'), 'publish')\ncheck('fixture 2', solve('1', 'a', {'1': 'a'}, False, True, 'public'), 'skip')\ncheck('fixture 3', solve('1', 'a', {'1': 'b'}, True, False, 'public'), 'immutable-conflict')\ncheck('fixture 4', solve('1', 'a', {}, False, False, 'public'), 'missing-attestation')\ncheck('fixture 5', solve('1', 'a', {}, True, True, 'public'), 'private-package')\ncheck('fixture 6', solve('1', 'a', {}, True, True, 'private'), 'publish')\ncheck('fixture 7', solve('2', 'a', {'1': 'b'}, True, False, 'public'), 'publish')\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"},"broken":{"sha256":"3a938de4b6f3760fc5823dbcd35dc04cda0df3c11c41e18f3652d17087448a75","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(version, digest, existing, attested, private, registry):\n    if version in existing:\n        if existing[version] == digest: return 'skip'\n        return 'immutable-conflict'\n    if not attested: return 'missing-attestation'\n    if False: return 'private-package'\n    return 'publish'\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\ncheck('fixture 1', solve('1', 'a', {}, True, False, 'public'), 'publish')\ncheck('fixture 2', solve('1', 'a', {'1': 'a'}, False, True, 'public'), 'skip')\ncheck('fixture 3', solve('1', 'a', {'1': 'b'}, True, False, 'public'), 'immutable-conflict')\ncheck('fixture 4', solve('1', 'a', {}, False, False, 'public'), 'missing-attestation')\ncheck('fixture 5', solve('1', 'a', {}, True, True, 'public'), 'private-package')\ncheck('fixture 6', solve('1', 'a', {}, True, True, 'private'), 'publish')\ncheck('fixture 7', solve('2', 'a', {'1': 'b'}, True, False, 'public'), 'publish')\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"},"fixed":{"sha256":"547ca9fee9b6a8d368115b3a6c8eda59df0d444f3bf68ecea0f97f67e9e723db","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(version, digest, existing, attested, private, registry):\n    if version in existing:\n        if existing[version] == digest: return 'skip'\n        return 'immutable-conflict'\n    if not attested: return 'missing-attestation'\n    if private and registry == 'public': return 'private-package'\n    return 'publish'\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\ncheck('fixture 1', solve('1', 'a', {}, True, False, 'public'), 'publish')\ncheck('fixture 2', solve('1', 'a', {'1': 'a'}, False, True, 'public'), 'skip')\ncheck('fixture 3', solve('1', 'a', {'1': 'b'}, True, False, 'public'), 'immutable-conflict')\ncheck('fixture 4', solve('1', 'a', {}, False, False, 'public'), 'missing-attestation')\ncheck('fixture 5', solve('1', 'a', {}, True, True, 'public'), 'private-package')\ncheck('fixture 6', solve('1', 'a', {}, True, True, 'private'), 'publish')\ncheck('fixture 7', solve('2', 'a', {'1': 'b'}, True, False, 'public'), 'publish')\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"}},"limitations":" This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.","method":"Deterministic executable model with adversarial boundary fixtures.","provenance":{"created_by":"Failure Map","dependencies":"Python standard library","family":"xt-publish-plan-private-public","generated_at":"2026-09-29T14:38:34.902214+00:00","license":"CC0-1.0","python":"3.12.14","seed":1,"split":"open-access"},"relevance":"An offline model of package publication plan, suitable for testing build and release tooling without external services.","repair":"Block public publication of private packages.","root_cause":"The implementation substitutes if False: for if private and registry == 'public':, so private packages are published publicly.","sha256":"18af143be4bbb3a70457ee3879fb7256a32257c6cee3c31a1030155f169640b5","title":"Package publication plan: Private packages are published publicly · case 01","variant":1,"variant_policy":"Five numbered records share a model and may reuse boundary fixtures.","verification":{"attempt":{"elapsed_ms":41.46,"exit_code":1,"observations":[{"actual":"publish","check":"fixture 1","expected":"publish","passed":true},{"actual":"skip","check":"fixture 2","expected":"skip","passed":true},{"actual":"immutable-conflict","check":"fixture 3","expected":"immutable-conflict","passed":true},{"actual":"missing-attestation","check":"fixture 4","expected":"missing-attestation","passed":true},{"actual":"publish","check":"fixture 5","expected":"private-package","passed":false},{"actual":"private-package","check":"fixture 6","expected":"publish","passed":false},{"actual":"publish","check":"fixture 7","expected":"publish","passed":true}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"fixture 1\", \"actual\": \"publish\", \"expected\": \"publish\", \"passed\": true}, {\"check\": \"fixture 2\", \"actual\": \"skip\", \"expected\": \"skip\", \"passed\": true}, {\"check\": \"fixture 3\", \"actual\": \"immutable-conflict\", \"expected\": \"immutable-conflict\", \"passed\": true}, {\"check\": \"fixture 4\", \"actual\": \"missing-attestation\", \"expected\": \"missing-attestation\", \"passed\": true}, {\"check\": \"fixture 5\", \"actual\": \"publish\", \"expected\": \"private-package\", \"passed\": false}, {\"check\": \"fixture 6\", \"actual\": \"private-package\", \"expected\": \"publish\", \"passed\": false}, {\"check\": \"fixture 7\", \"actual\": \"publish\", \"expected\": \"publish\", \"passed\": true}], \"passed\": false}\n"},"broken":{"elapsed_ms":41.255,"exit_code":1,"observations":[{"actual":"publish","check":"fixture 1","expected":"publish","passed":true},{"actual":"skip","check":"fixture 2","expected":"skip","passed":true},{"actual":"immutable-conflict","check":"fixture 3","expected":"immutable-conflict","passed":true},{"actual":"missing-attestation","check":"fixture 4","expected":"missing-attestation","passed":true},{"actual":"publish","check":"fixture 5","expected":"private-package","passed":false},{"actual":"publish","check":"fixture 6","expected":"publish","passed":true},{"actual":"publish","check":"fixture 7","expected":"publish","passed":true}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"fixture 1\", \"actual\": \"publish\", \"expected\": \"publish\", \"passed\": true}, {\"check\": \"fixture 2\", \"actual\": \"skip\", \"expected\": \"skip\", \"passed\": true}, {\"check\": \"fixture 3\", \"actual\": \"immutable-conflict\", \"expected\": \"immutable-conflict\", \"passed\": true}, {\"check\": \"fixture 4\", \"actual\": \"missing-attestation\", \"expected\": \"missing-attestation\", \"passed\": true}, {\"check\": \"fixture 5\", \"actual\": \"publish\", \"expected\": \"private-package\", \"passed\": false}, {\"check\": \"fixture 6\", \"actual\": \"publish\", \"expected\": \"publish\", \"passed\": true}, {\"check\": \"fixture 7\", \"actual\": \"publish\", \"expected\": \"publish\", \"passed\": true}], \"passed\": false}\n"},"fixed":{"elapsed_ms":41.385,"exit_code":0,"observations":[{"actual":"publish","check":"fixture 1","expected":"publish","passed":true},{"actual":"skip","check":"fixture 2","expected":"skip","passed":true},{"actual":"immutable-conflict","check":"fixture 3","expected":"immutable-conflict","passed":true},{"actual":"missing-attestation","check":"fixture 4","expected":"missing-attestation","passed":true},{"actual":"private-package","check":"fixture 5","expected":"private-package","passed":true},{"actual":"publish","check":"fixture 6","expected":"publish","passed":true},{"actual":"publish","check":"fixture 7","expected":"publish","passed":true}],"passed":true,"stderr":"","stdout":"{\"observations\": [{\"check\": \"fixture 1\", \"actual\": \"publish\", \"expected\": \"publish\", \"passed\": true}, {\"check\": \"fixture 2\", \"actual\": \"skip\", \"expected\": \"skip\", \"passed\": true}, {\"check\": \"fixture 3\", \"actual\": \"immutable-conflict\", \"expected\": \"immutable-conflict\", \"passed\": true}, {\"check\": \"fixture 4\", \"actual\": \"missing-attestation\", \"expected\": \"missing-attestation\", \"passed\": true}, {\"check\": \"fixture 5\", \"actual\": \"private-package\", \"expected\": \"private-package\", \"passed\": true}, {\"check\": \"fixture 6\", \"actual\": \"publish\", \"expected\": \"publish\", \"passed\": true}, {\"check\": \"fixture 7\", \"actual\": \"publish\", \"expected\": \"publish\", \"passed\": true}], \"passed\": true}\n"}},"verified":true,"visibility":"public"}