{"abstract":"Downgrades ignore the explicit policy.","category":"Deployment models","checks":6,"contract":"Reject unknown targets, reject downgrade unless allowed, skip identical digests, reject missing test evidence, otherwise update target to candidate digest and version while preserving other environments.","contract_signature":"environments, target, version, digest, tested, allow_downgrade","evaluation_group":"xt-promotion-plan","failed_approach":"The attempted repair substitutes version < old_version. Fixture 3 still yields 'downgrade' instead of {'prod': (1, 'a')}.","family":"xt-promotion-plan-downgrade-guard","id":"FA-10211","implementations":{"attempt":{"sha256":"96691fe37328dd48d6723ba68e8aa2c59cf6f03c453bdadd802492307b720f6b","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(environments, target, version, digest, tested, allow_downgrade):\n    if target not in environments: return 'unknown'\n    old_version, old_digest = environments[target]\n    if version < old_version: return 'downgrade'\n    if digest == old_digest: return 'unchanged'\n    if not tested: return 'untested'\n    result = dict(environments)\n    result[target] = (version, digest)\n    return result\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\ncheck('fixture 1', solve({}, 'prod', 1, 'a', True, False), 'unknown')\ncheck('fixture 2', solve({'prod': (2, 'b')}, 'prod', 1, 'a', True, False), 'downgrade')\ncheck('fixture 3', solve({'prod': (2, 'b')}, 'prod', 1, 'a', True, True), {'prod': (1, 'a')})\ncheck('fixture 4', solve({'prod': (1, 'a')}, 'prod', 1, 'a', False, False), 'unchanged')\ncheck('fixture 5', solve({'prod': (1, 'a')}, 'prod', 2, 'b', False, False), 'untested')\ncheck('fixture 6', solve({'prod': (1, 'a'), 'stage': (2, 'b')}, 'prod', 2, 'b', True, False), {'prod': (2, 'b'), 'stage': (2, 'b')})\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"},"broken":{"sha256":"292c5352e943a516fda7b461ff3981a6c26c96d6b68fdf1a1f6b249b24eaf3bc","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(environments, target, version, digest, tested, allow_downgrade):\n    if target not in environments: return 'unknown'\n    old_version, old_digest = environments[target]\n    if False: return 'downgrade'\n    if digest == old_digest: return 'unchanged'\n    if not tested: return 'untested'\n    result = dict(environments)\n    result[target] = (version, digest)\n    return result\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\ncheck('fixture 1', solve({}, 'prod', 1, 'a', True, False), 'unknown')\ncheck('fixture 2', solve({'prod': (2, 'b')}, 'prod', 1, 'a', True, False), 'downgrade')\ncheck('fixture 3', solve({'prod': (2, 'b')}, 'prod', 1, 'a', True, True), {'prod': (1, 'a')})\ncheck('fixture 4', solve({'prod': (1, 'a')}, 'prod', 1, 'a', False, False), 'unchanged')\ncheck('fixture 5', solve({'prod': (1, 'a')}, 'prod', 2, 'b', False, False), 'untested')\ncheck('fixture 6', solve({'prod': (1, 'a'), 'stage': (2, 'b')}, 'prod', 2, 'b', True, False), {'prod': (2, 'b'), 'stage': (2, 'b')})\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"}},"limitations":" This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.","method":"Deterministic executable model with adversarial boundary fixtures.","provenance":{"created_by":"Failure Map","dependencies":"Python standard library","family":"xt-promotion-plan-downgrade-guard","generated_at":"2026-09-29T14:38:37.037536+00:00","license":"CC0-1.0","python":"3.12.14","seed":1,"split":"open-access"},"relevance":"An offline model of environment promotion plan, suitable for testing build and release tooling without external services.","root_cause":"The implementation substitutes False for version < old_version and not allow_downgrade, so downgrades ignore the explicit policy.","sha256":"b4c67e5ce07a5ef9308ec8ff6c3ab4ec2ef8dd2b84806a800f81f679d3700398","title":"Environment promotion plan: Downgrades ignore the explicit policy · case 01","variant":1,"variant_policy":"Five numbered records share a model and may reuse boundary fixtures.","verified":true,"visibility":"public","verification":{"attempt":{"elapsed_ms":40.447,"exit_code":1,"observations":[{"actual":"unknown","check":"fixture 1","expected":"unknown","passed":true},{"actual":"downgrade","check":"fixture 2","expected":"downgrade","passed":true},{"actual":"downgrade","check":"fixture 3","expected":{"prod":[1,"a"]},"passed":false},{"actual":"unchanged","check":"fixture 4","expected":"unchanged","passed":true},{"actual":"untested","check":"fixture 5","expected":"untested","passed":true},{"actual":{"prod":[2,"b"],"stage":[2,"b"]},"check":"fixture 6","expected":{"prod":[2,"b"],"stage":[2,"b"]},"passed":true}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"fixture 1\", \"actual\": \"unknown\", \"expected\": \"unknown\", \"passed\": true}, {\"check\": \"fixture 2\", \"actual\": \"downgrade\", \"expected\": \"downgrade\", \"passed\": true}, {\"check\": \"fixture 3\", \"actual\": \"downgrade\", \"expected\": {\"prod\": [1, \"a\"]}, \"passed\": false}, {\"check\": \"fixture 4\", \"actual\": \"unchanged\", \"expected\": \"unchanged\", \"passed\": true}, {\"check\": \"fixture 5\", \"actual\": \"untested\", \"expected\": \"untested\", \"passed\": true}, {\"check\": \"fixture 6\", \"actual\": {\"prod\": [2, \"b\"], \"stage\": [2, \"b\"]}, \"expected\": {\"prod\": [2, \"b\"], \"stage\": [2, \"b\"]}, \"passed\": true}], \"passed\": false}\n"},"broken":{"elapsed_ms":42.252,"exit_code":1,"observations":[{"actual":"unknown","check":"fixture 1","expected":"unknown","passed":true},{"actual":{"prod":[1,"a"]},"check":"fixture 2","expected":"downgrade","passed":false},{"actual":{"prod":[1,"a"]},"check":"fixture 3","expected":{"prod":[1,"a"]},"passed":true},{"actual":"unchanged","check":"fixture 4","expected":"unchanged","passed":true},{"actual":"untested","check":"fixture 5","expected":"untested","passed":true},{"actual":{"prod":[2,"b"],"stage":[2,"b"]},"check":"fixture 6","expected":{"prod":[2,"b"],"stage":[2,"b"]},"passed":true}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"fixture 1\", \"actual\": \"unknown\", \"expected\": \"unknown\", \"passed\": true}, {\"check\": \"fixture 2\", \"actual\": {\"prod\": [1, \"a\"]}, \"expected\": \"downgrade\", \"passed\": false}, {\"check\": \"fixture 3\", \"actual\": {\"prod\": [1, \"a\"]}, \"expected\": {\"prod\": [1, \"a\"]}, \"passed\": true}, {\"check\": \"fixture 4\", \"actual\": \"unchanged\", \"expected\": \"unchanged\", \"passed\": true}, {\"check\": \"fixture 5\", \"actual\": \"untested\", \"expected\": \"untested\", \"passed\": true}, {\"check\": \"fixture 6\", \"actual\": {\"prod\": [2, \"b\"], \"stage\": [2, \"b\"]}, \"expected\": {\"prod\": [2, \"b\"], \"stage\": [2, \"b\"]}, \"passed\": true}], \"passed\": false}\n"}},"member_only":{"stages":["fixed"],"fields":["implementations.fixed","verification.fixed","harness","repair"],"note":"The verified repair, its recorded checks, the repair description, and the scoring harness are available to members."}}