{"abstract":"Permission evaluation falls through from owner to other.","category":"Filesystem semantics","checks":6,"contract":"Deterministic in-memory filesystem model. POSIX-style basic permission model without ACLs or superuser: owner and group_match booleans select one class; bit is 1,2,or4. Return whether selected class grants it.","evaluation_group":"model-dc598ac2a8bec9fa","failed_approach":"Choosing the strongest available class still grants permissions explicitly absent from the selected class.","family":"z-filesystems-permission-class","id":"FA-11561","implementations":{"attempt":{"sha256":"b8083cb2f23566cba50a5b37b5f9e95e2ace2ee242e7e6b0daa2b1f17dd0b62e","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(mode, owner, group_match, bit):\n    return bool(max((mode>>6)&7 if owner else 0,(mode>>3)&7 if group_match else 0,mode&7)&bit)\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\ncheck('owner denial cannot fall through',solve(0o004,True,False,4),False)\ncheck('group denial cannot fall through',solve(0o004,False,True,4),False)\ncheck('owner wins despite matching group',solve(0o040,True,True,4),False)\ncheck('owner allowed',solve(0o400,True,False,4),True)\ncheck('other allowed',solve(0o001,False,False,1),True)\ncheck('varying unrelated mode bits',solve(N<<6,False,False,2),False)\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"},"broken":{"sha256":"5176547cdb322f0fb7a9c03eea18d8b9354cf434019a790bedca4b6dc37e0b9b","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(mode, owner, group_match, bit):\n    return bool(((mode>>6 if owner else 0) | (mode>>3 if group_match else 0) | mode) & bit)\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\ncheck('owner denial cannot fall through',solve(0o004,True,False,4),False)\ncheck('group denial cannot fall through',solve(0o004,False,True,4),False)\ncheck('owner wins despite matching group',solve(0o040,True,True,4),False)\ncheck('owner allowed',solve(0o400,True,False,4),True)\ncheck('other allowed',solve(0o001,False,False,1),True)\ncheck('varying unrelated mode bits',solve(N<<6,False,False,2),False)\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"},"fixed":{"sha256":"318d55f959ad7096a9cae33b31e34cb77a4fe728fead66b46480bd117ae08237","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(mode, owner, group_match, bit):\n    bits = (mode>>6)&7 if owner else (mode>>3)&7 if group_match else mode&7\n    return bool(bits & bit)\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\ncheck('owner denial cannot fall through',solve(0o004,True,False,4),False)\ncheck('group denial cannot fall through',solve(0o004,False,True,4),False)\ncheck('owner wins despite matching group',solve(0o040,True,True,4),False)\ncheck('owner allowed',solve(0o400,True,False,4),True)\ncheck('other allowed',solve(0o001,False,False,1),True)\ncheck('varying unrelated mode bits',solve(N<<6,False,False,2),False)\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"}},"limitations":" This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.","method":"Deterministic executable model with adversarial boundary fixtures.","provenance":{"created_by":"Failure Map","dependencies":"Python standard library","family":"z-filesystems-permission-class","generated_at":"2026-09-29T14:38:49.052671+00:00","license":"CC0-1.0","python":"3.12.14","seed":1,"split":"open-access"},"relevance":"An offline semantic experiment for file API clients; it models only the stated operations, not a complete operating system.","repair":"Select the owner class first, else matching group, else other, then test the requested bit.","root_cause":"All applicable classes are ORed instead of selecting exactly one owner/group/other class.","sha256":"263ca0d5c3cede26cd550354e0a885ddab586b9d9b369a6f3f538e5dc937e8dc","title":"Permission evaluation falls through from owner to other · case 01","variant":1,"variant_policy":"Five numbered records share a model and may reuse boundary fixtures.","verification":{"attempt":{"elapsed_ms":39.374,"exit_code":1,"observations":[{"actual":true,"check":"owner denial cannot fall through","expected":false,"passed":false},{"actual":true,"check":"group denial cannot fall through","expected":false,"passed":false},{"actual":true,"check":"owner wins despite matching group","expected":false,"passed":false},{"actual":true,"check":"owner allowed","expected":true,"passed":true},{"actual":true,"check":"other allowed","expected":true,"passed":true},{"actual":false,"check":"varying unrelated mode bits","expected":false,"passed":true}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"owner denial cannot fall through\", \"actual\": true, \"expected\": false, \"passed\": false}, {\"check\": \"group denial cannot fall through\", \"actual\": true, \"expected\": false, \"passed\": false}, {\"check\": \"owner wins despite matching group\", \"actual\": true, \"expected\": false, \"passed\": false}, {\"check\": \"owner allowed\", \"actual\": true, \"expected\": true, \"passed\": true}, {\"check\": \"other allowed\", \"actual\": true, \"expected\": true, \"passed\": true}, {\"check\": \"varying unrelated mode bits\", \"actual\": false, \"expected\": false, \"passed\": true}], \"passed\": false}\n"},"broken":{"elapsed_ms":42.108,"exit_code":1,"observations":[{"actual":true,"check":"owner denial cannot fall through","expected":false,"passed":false},{"actual":true,"check":"group denial cannot fall through","expected":false,"passed":false},{"actual":true,"check":"owner wins despite matching group","expected":false,"passed":false},{"actual":true,"check":"owner allowed","expected":true,"passed":true},{"actual":true,"check":"other allowed","expected":true,"passed":true},{"actual":false,"check":"varying unrelated mode bits","expected":false,"passed":true}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"owner denial cannot fall through\", \"actual\": true, \"expected\": false, \"passed\": false}, {\"check\": \"group denial cannot fall through\", \"actual\": true, \"expected\": false, \"passed\": false}, {\"check\": \"owner wins despite matching group\", \"actual\": true, \"expected\": false, \"passed\": false}, {\"check\": \"owner allowed\", \"actual\": true, \"expected\": true, \"passed\": true}, {\"check\": \"other allowed\", \"actual\": true, \"expected\": true, \"passed\": true}, {\"check\": \"varying unrelated mode bits\", \"actual\": false, \"expected\": false, \"passed\": true}], \"passed\": false}\n"},"fixed":{"elapsed_ms":38.062,"exit_code":0,"observations":[{"actual":false,"check":"owner denial cannot fall through","expected":false,"passed":true},{"actual":false,"check":"group denial cannot fall through","expected":false,"passed":true},{"actual":false,"check":"owner wins despite matching group","expected":false,"passed":true},{"actual":true,"check":"owner allowed","expected":true,"passed":true},{"actual":true,"check":"other allowed","expected":true,"passed":true},{"actual":false,"check":"varying unrelated mode bits","expected":false,"passed":true}],"passed":true,"stderr":"","stdout":"{\"observations\": [{\"check\": \"owner denial cannot fall through\", \"actual\": false, \"expected\": false, \"passed\": true}, {\"check\": \"group denial cannot fall through\", \"actual\": false, \"expected\": false, \"passed\": true}, {\"check\": \"owner wins despite matching group\", \"actual\": false, \"expected\": false, \"passed\": true}, {\"check\": \"owner allowed\", \"actual\": true, \"expected\": true, \"passed\": true}, {\"check\": \"other allowed\", \"actual\": true, \"expected\": true, \"passed\": true}, {\"check\": \"varying unrelated mode bits\", \"actual\": false, \"expected\": false, \"passed\": true}], \"passed\": true}\n"}},"verified":true,"visibility":"public"}