{"abstract":"A context-specific sanitizer clears unrelated taint.","category":"Static analysis soundness","checks":6,"contract":"Given hazard names and a sanitizer certificate name, remove exactly that name from the hazard set and return sorted remaining names. Unknown certificates remove nothing.","contract_signature":"hazards, certificate","evaluation_group":"model-930fb38d0723fc9b","failed_approach":"Keeping only the certified kind inverts the certificate meaning and loses unrelated taint.","family":"z-static_analysis-sanitizer-context","id":"FA-11506","implementations":{"attempt":{"sha256":"57cd59eb12beaffaebaee64db6c12c5843fe4c5b3afd34a834a4e5c3d2a9cff4","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(hazards, certificate):\n    return sorted(set(hazards) & {certificate})\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\nh='sink'+str(N)\ncheck('sql certificate preserves html',solve(['sql',h],'sql'),[h])\ncheck('html certificate preserves sql',solve(['sql',h],h),['sql'])\ncheck('unknown certificate',solve([h],'other'),[h])\ncheck('matching certificate',solve([h],h),[])\ncheck('empty hazards',solve([],h),[])\ncheck('duplicate hazards',solve([h,h,'sql'],'sql'),[h])\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"},"broken":{"sha256":"bb9f1c9525099ce7bceb723de8cb5d09eeb0e376b6109af3ad61737cde84cdcd","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(hazards, certificate):\n    return [] if certificate else sorted(set(hazards))\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\nh='sink'+str(N)\ncheck('sql certificate preserves html',solve(['sql',h],'sql'),[h])\ncheck('html certificate preserves sql',solve(['sql',h],h),['sql'])\ncheck('unknown certificate',solve([h],'other'),[h])\ncheck('matching certificate',solve([h],h),[])\ncheck('empty hazards',solve([],h),[])\ncheck('duplicate hazards',solve([h,h,'sql'],'sql'),[h])\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"}},"limitations":" This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.","method":"Deterministic executable model with adversarial boundary fixtures.","provenance":{"created_by":"Failure Map","dependencies":"Python standard library","family":"z-static_analysis-sanitizer-context","generated_at":"2026-09-29T14:38:48.603094+00:00","license":"CC0-1.0","python":"3.12.14","seed":1,"split":"open-access"},"relevance":"A deterministic offline analysis model exposing a specific soundness or precision boundary; it does not implement a complete language analyzer.","root_cause":"A sanitizer clears all taint kinds rather than the kind it certifies.","sha256":"cfbc4eabffd38afd78b1e1e9db9b227f2d579ad6f2199ee6590e811d92f83c3d","title":"A context-specific sanitizer clears unrelated taint · case 01","variant":1,"variant_policy":"Five numbered records share a model and may reuse boundary fixtures.","verified":true,"visibility":"public","verification":{"attempt":{"elapsed_ms":37.316,"exit_code":1,"observations":[{"actual":["sql"],"check":"sql certificate preserves html","expected":["sink1"],"passed":false},{"actual":["sink1"],"check":"html certificate preserves sql","expected":["sql"],"passed":false},{"actual":[],"check":"unknown certificate","expected":["sink1"],"passed":false},{"actual":["sink1"],"check":"matching certificate","expected":[],"passed":false},{"actual":[],"check":"empty hazards","expected":[],"passed":true},{"actual":["sql"],"check":"duplicate hazards","expected":["sink1"],"passed":false}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"sql certificate preserves html\", \"actual\": [\"sql\"], \"expected\": [\"sink1\"], \"passed\": false}, {\"check\": \"html certificate preserves sql\", \"actual\": [\"sink1\"], \"expected\": [\"sql\"], \"passed\": false}, {\"check\": \"unknown certificate\", \"actual\": [], \"expected\": [\"sink1\"], \"passed\": false}, {\"check\": \"matching certificate\", \"actual\": [\"sink1\"], \"expected\": [], \"passed\": false}, {\"check\": \"empty hazards\", \"actual\": [], \"expected\": [], \"passed\": true}, {\"check\": \"duplicate hazards\", \"actual\": [\"sql\"], \"expected\": [\"sink1\"], \"passed\": false}], \"passed\": false}\n"},"broken":{"elapsed_ms":39.245,"exit_code":1,"observations":[{"actual":[],"check":"sql certificate preserves html","expected":["sink1"],"passed":false},{"actual":[],"check":"html certificate preserves sql","expected":["sql"],"passed":false},{"actual":[],"check":"unknown certificate","expected":["sink1"],"passed":false},{"actual":[],"check":"matching certificate","expected":[],"passed":true},{"actual":[],"check":"empty hazards","expected":[],"passed":true},{"actual":[],"check":"duplicate hazards","expected":["sink1"],"passed":false}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"sql certificate preserves html\", \"actual\": [], \"expected\": [\"sink1\"], \"passed\": false}, {\"check\": \"html certificate preserves sql\", \"actual\": [], \"expected\": [\"sql\"], \"passed\": false}, {\"check\": \"unknown certificate\", \"actual\": [], \"expected\": [\"sink1\"], \"passed\": false}, {\"check\": \"matching certificate\", \"actual\": [], \"expected\": [], \"passed\": true}, {\"check\": \"empty hazards\", \"actual\": [], \"expected\": [], \"passed\": true}, {\"check\": \"duplicate hazards\", \"actual\": [], \"expected\": [\"sink1\"], \"passed\": false}], \"passed\": false}\n"}},"member_only":{"stages":["fixed"],"fields":["implementations.fixed","verification.fixed","harness","repair"],"note":"The verified repair, its recorded checks, the repair description, and the scoring harness are available to members."}}