{"abstract":"Keys containing \":\" become \"%253A\", so multi-context keys disagree with other SDKs.","category":"Feature flag rollout bucketing","checks":8,"contract":"contexts maps kind -> key. Empty input or any empty key -> None. A context containing only the kind \"user\" is keyed by the bare user key. Otherwise join, over kinds in sorted order, kind + \":\" + escaped key with \":\", where escaping replaces \"%\" by \"%25\" and then \":\" by \"%3A\".","contract_signature":"contexts","evaluation_group":"w2-feature-flag-rollout-bucketing-multi-context-key","failed_approach":"Escaping only colons leaves literal \"%3A\" in keys indistinguishable from escaped colons.","family":"w2-feature-flag-rollout-bucketing-multi-context-key-escape-order","id":"FA-74131","implementations":{"attempt":{"sha256":"070993e1e36da1400b72d5874aa155acdb883fb69eed4d2f1a6c0daac88f4182","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(contexts):\n    def esc(s):\n        return s.replace(':', '%3A')\n    if not contexts or any(k == '' for k in contexts.values()):\n        return None\n    if list(contexts) == ['user']:\n        return contexts['user']\n    return ':'.join(kind + ':' + esc(contexts[kind]) for kind in sorted(contexts))\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\nfixtures = [[('percent is escaped before colon', [{'org': 'a:b', 'user': '50%'}], 'org:a%3Ab:user:50%25'),\n  ('already escaped text is escaped again', [{'org': 'x%3Ay', 'user': 'bob'}], 'org:x%253Ay:user:bob'),\n  ('kinds are sorted regardless of insertion', [{'user': 'bob', 'org': 'acme'}], 'org:acme:user:bob'),\n  ('single non-user kind is prefixed', [{'org': 'acme'}], 'org:acme'),\n  ('single user kind stays bare with colon', [{'user': 'a:b'}], 'a:b'),\n  ('context sample 1', [{'device': '50%', 'user': 'z', 'app': 'a:b'}], 'app:a%3Ab:device:50%25:user:z'),\n  ('context sample 2', [{'device': 'acme', 'user': 'z', 'org': 'z'}], 'device:acme:org:z:user:z'),\n  ('context sample 3',\n   [{'app': 'k:1%', 'user': 'acme', 'device': 'bob'}],\n   'app:k%3A1%25:device:bob:user:acme')],\n [('percent is escaped before colon', [{'org': 'a:b', 'user': '50%'}], 'org:a%3Ab:user:50%25'),\n  ('already escaped text is escaped again', [{'org': 'x%3Ay', 'user': 'bob'}], 'org:x%253Ay:user:bob'),\n  ('kinds are sorted regardless of insertion', [{'user': 'bob', 'org': 'acme'}], 'org:acme:user:bob'),\n  ('single non-user kind is prefixed', [{'org': 'acme'}], 'org:acme'),\n  ('single user kind stays bare with colon', [{'user': 'a:b'}], 'a:b'),\n  ('empty key is invalid', [{'org': 'acme', 'user': ''}], None),\n  ('context sample 11', [{'org': 'x%3Ay', 'app': 'a:b', 'device': 'z'}], 'app:a%3Ab:device:z:org:x%253Ay'),\n  ('context sample 13', [{'app': 'x%3Ay'}], 'app:x%253Ay')],\n [('kinds are sorted regardless of insertion', [{'user': 'bob', 'org': 'acme'}], 'org:acme:user:bob'),\n  ('single non-user kind is prefixed', [{'org': 'acme'}], 'org:acme'),\n  ('single user kind stays bare with colon', [{'user': 'a:b'}], 'a:b'),\n  ('empty key is invalid', [{'org': 'acme', 'user': ''}], None),\n  ('empty mapping is invalid', [{}], None),\n  ('context sample 11', [{'org': 'x%3Ay', 'app': 'a:b', 'device': 'z'}], 'app:a%3Ab:device:z:org:x%253Ay'),\n  ('context sample 22', [{'org': 'x%3Ay'}], 'org:x%253Ay'),\n  ('context sample 54',\n   [{'user': 'x%3Ay', 'app': 'k:1%', 'org': 'acme'}],\n   'app:k%3A1%25:org:acme:user:x%253Ay')],\n [('single non-user kind is prefixed', [{'org': 'acme'}], 'org:acme'),\n  ('single user kind stays bare with colon', [{'user': 'a:b'}], 'a:b'),\n  ('empty key is invalid', [{'org': 'acme', 'user': ''}], None),\n  ('empty mapping is invalid', [{}], None),\n  ('three kinds', [{'device': 'd1', 'app': 'z', 'user': 'bob'}], 'app:z:device:d1:user:bob'),\n  ('context sample 6', [{'device': 'bob', 'org': 'a:b'}], 'device:bob:org:a%3Ab'),\n  ('context sample 16', [{'org': 'x%3Ay', 'app': 'z'}], 'app:z:org:x%253Ay'),\n  ('context sample 39', [{'device': 'acme', 'org': 'k:1%'}], 'device:acme:org:k%3A1%25')],\n [('percent is escaped before colon', [{'org': 'a:b', 'user': '50%'}], 'org:a%3Ab:user:50%25'),\n  ('single user kind stays bare with colon', [{'user': 'a:b'}], 'a:b'),\n  ('empty key is invalid', [{'org': 'acme', 'user': ''}], None),\n  ('empty mapping is invalid', [{}], None),\n  ('three kinds', [{'device': 'd1', 'app': 'z', 'user': 'bob'}], 'app:z:device:d1:user:bob'),\n  ('context sample 21', [{'org': 'x%3Ay', 'app': 'z'}], 'app:z:org:x%253Ay'),\n  ('context sample 39', [{'device': 'acme', 'org': 'k:1%'}], 'device:acme:org:k%3A1%25'),\n  ('context sample 51', [{'org': 'x%3Ay', 'app': 'z', 'user': 'z'}], 'app:z:org:x%253Ay:user:z')]]\nfor label, args, expected in fixtures[N - 1]:\n    check(label, solve(*args), expected)\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"},"broken":{"sha256":"cc7a5452d6d1247a70c20f1eca6748bcefe445cd8b4d223476dbee96dd058cb3","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(contexts):\n    def esc(s):\n        return s.replace(':', '%3A').replace('%', '%25')\n    if not contexts or any(k == '' for k in contexts.values()):\n        return None\n    if list(contexts) == ['user']:\n        return contexts['user']\n    return ':'.join(kind + ':' + esc(contexts[kind]) for kind in sorted(contexts))\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\nfixtures = [[('percent is escaped before colon', [{'org': 'a:b', 'user': '50%'}], 'org:a%3Ab:user:50%25'),\n  ('already escaped text is escaped again', [{'org': 'x%3Ay', 'user': 'bob'}], 'org:x%253Ay:user:bob'),\n  ('kinds are sorted regardless of insertion', [{'user': 'bob', 'org': 'acme'}], 'org:acme:user:bob'),\n  ('single non-user kind is prefixed', [{'org': 'acme'}], 'org:acme'),\n  ('single user kind stays bare with colon', [{'user': 'a:b'}], 'a:b'),\n  ('context sample 1', [{'device': '50%', 'user': 'z', 'app': 'a:b'}], 'app:a%3Ab:device:50%25:user:z'),\n  ('context sample 2', [{'device': 'acme', 'user': 'z', 'org': 'z'}], 'device:acme:org:z:user:z'),\n  ('context sample 3',\n   [{'app': 'k:1%', 'user': 'acme', 'device': 'bob'}],\n   'app:k%3A1%25:device:bob:user:acme')],\n [('percent is escaped before colon', [{'org': 'a:b', 'user': '50%'}], 'org:a%3Ab:user:50%25'),\n  ('already escaped text is escaped again', [{'org': 'x%3Ay', 'user': 'bob'}], 'org:x%253Ay:user:bob'),\n  ('kinds are sorted regardless of insertion', [{'user': 'bob', 'org': 'acme'}], 'org:acme:user:bob'),\n  ('single non-user kind is prefixed', [{'org': 'acme'}], 'org:acme'),\n  ('single user kind stays bare with colon', [{'user': 'a:b'}], 'a:b'),\n  ('empty key is invalid', [{'org': 'acme', 'user': ''}], None),\n  ('context sample 11', [{'org': 'x%3Ay', 'app': 'a:b', 'device': 'z'}], 'app:a%3Ab:device:z:org:x%253Ay'),\n  ('context sample 13', [{'app': 'x%3Ay'}], 'app:x%253Ay')],\n [('kinds are sorted regardless of insertion', [{'user': 'bob', 'org': 'acme'}], 'org:acme:user:bob'),\n  ('single non-user kind is prefixed', [{'org': 'acme'}], 'org:acme'),\n  ('single user kind stays bare with colon', [{'user': 'a:b'}], 'a:b'),\n  ('empty key is invalid', [{'org': 'acme', 'user': ''}], None),\n  ('empty mapping is invalid', [{}], None),\n  ('context sample 11', [{'org': 'x%3Ay', 'app': 'a:b', 'device': 'z'}], 'app:a%3Ab:device:z:org:x%253Ay'),\n  ('context sample 22', [{'org': 'x%3Ay'}], 'org:x%253Ay'),\n  ('context sample 54',\n   [{'user': 'x%3Ay', 'app': 'k:1%', 'org': 'acme'}],\n   'app:k%3A1%25:org:acme:user:x%253Ay')],\n [('single non-user kind is prefixed', [{'org': 'acme'}], 'org:acme'),\n  ('single user kind stays bare with colon', [{'user': 'a:b'}], 'a:b'),\n  ('empty key is invalid', [{'org': 'acme', 'user': ''}], None),\n  ('empty mapping is invalid', [{}], None),\n  ('three kinds', [{'device': 'd1', 'app': 'z', 'user': 'bob'}], 'app:z:device:d1:user:bob'),\n  ('context sample 6', [{'device': 'bob', 'org': 'a:b'}], 'device:bob:org:a%3Ab'),\n  ('context sample 16', [{'org': 'x%3Ay', 'app': 'z'}], 'app:z:org:x%253Ay'),\n  ('context sample 39', [{'device': 'acme', 'org': 'k:1%'}], 'device:acme:org:k%3A1%25')],\n [('percent is escaped before colon', [{'org': 'a:b', 'user': '50%'}], 'org:a%3Ab:user:50%25'),\n  ('single user kind stays bare with colon', [{'user': 'a:b'}], 'a:b'),\n  ('empty key is invalid', [{'org': 'acme', 'user': ''}], None),\n  ('empty mapping is invalid', [{}], None),\n  ('three kinds', [{'device': 'd1', 'app': 'z', 'user': 'bob'}], 'app:z:device:d1:user:bob'),\n  ('context sample 21', [{'org': 'x%3Ay', 'app': 'z'}], 'app:z:org:x%253Ay'),\n  ('context sample 39', [{'device': 'acme', 'org': 'k:1%'}], 'device:acme:org:k%3A1%25'),\n  ('context sample 51', [{'org': 'x%3Ay', 'app': 'z', 'user': 'z'}], 'app:z:org:x%253Ay:user:z')]]\nfor label, args, expected in fixtures[N - 1]:\n    check(label, solve(*args), expected)\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"}},"limitations":"A deterministic toy flag-evaluation model with a stipulated contract; it does not reproduce any vendor SDK byte for byte. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.","method":"Deterministic executable model with adversarial boundary fixtures.","provenance":{"created_by":"Failure Map","dependencies":"Python standard library","family":"w2-feature-flag-rollout-bucketing-multi-context-key-escape-order","generated_at":"2026-09-29T14:48:53.867226+00:00","license":"CC0-1.0","python":"3.12.14","seed":1,"split":"open-access"},"relevance":"Canonical context keys feed bucketing and caches; two spellings of one context split its traffic.","root_cause":"The \":\" -> \"%3A\" replacement runs first and its \"%\" is then escaped again.","sha256":"b2b7b37e536931000040103aaa6a2c22018eeb22e80a8b5c9792bfd27350793c","title":"Multi-context canonical key: Colons are escaped before percent signs · case 01","variant":1,"variant_policy":"Five numbered records share a model and may reuse boundary fixtures.","verified":true,"visibility":"public","verification":{"attempt":{"elapsed_ms":40.661,"exit_code":1,"observations":[{"actual":"org:a%3Ab:user:50%","check":"percent is escaped before colon","expected":"org:a%3Ab:user:50%25","passed":false},{"actual":"org:x%3Ay:user:bob","check":"already escaped text is escaped again","expected":"org:x%253Ay:user:bob","passed":false},{"actual":"org:acme:user:bob","check":"kinds are sorted regardless of insertion","expected":"org:acme:user:bob","passed":true},{"actual":"org:acme","check":"single non-user kind is prefixed","expected":"org:acme","passed":true},{"actual":"a:b","check":"single user kind stays bare with colon","expected":"a:b","passed":true},{"actual":"app:a%3Ab:device:50%:user:z","check":"context sample 1","expected":"app:a%3Ab:device:50%25:user:z","passed":false},{"actual":"device:acme:org:z:user:z","check":"context sample 2","expected":"device:acme:org:z:user:z","passed":true},{"actual":"app:k%3A1%:device:bob:user:acme","check":"context sample 3","expected":"app:k%3A1%25:device:bob:user:acme","passed":false}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"percent is escaped before colon\", \"actual\": \"org:a%3Ab:user:50%\", \"expected\": \"org:a%3Ab:user:50%25\", \"passed\": false}, {\"check\": \"already escaped text is escaped again\", \"actual\": \"org:x%3Ay:user:bob\", \"expected\": \"org:x%253Ay:user:bob\", \"passed\": false}, {\"check\": \"kinds are sorted regardless of insertion\", \"actual\": \"org:acme:user:bob\", \"expected\": \"org:acme:user:bob\", \"passed\": true}, {\"check\": \"single non-user kind is prefixed\", \"actual\": \"org:acme\", \"expected\": \"org:acme\", \"passed\": true}, {\"check\": \"single user kind stays bare with colon\", \"actual\": \"a:b\", \"expected\": \"a:b\", \"passed\": true}, {\"check\": \"context sample 1\", \"actual\": \"app:a%3Ab:device:50%:user:z\", \"expected\": \"app:a%3Ab:device:50%25:user:z\", \"passed\": false}, {\"check\": \"context sample 2\", \"actual\": \"device:acme:org:z:user:z\", \"expected\": \"device:acme:org:z:user:z\", \"passed\": true}, {\"check\": \"context sample 3\", \"actual\": \"app:k%3A1%:device:bob:user:acme\", \"expected\": \"app:k%3A1%25:device:bob:user:acme\", \"passed\": false}], \"passed\": false}\n"},"broken":{"elapsed_ms":39.473,"exit_code":1,"observations":[{"actual":"org:a%253Ab:user:50%25","check":"percent is escaped before colon","expected":"org:a%3Ab:user:50%25","passed":false},{"actual":"org:x%253Ay:user:bob","check":"already escaped text is escaped again","expected":"org:x%253Ay:user:bob","passed":true},{"actual":"org:acme:user:bob","check":"kinds are sorted regardless of insertion","expected":"org:acme:user:bob","passed":true},{"actual":"org:acme","check":"single non-user kind is prefixed","expected":"org:acme","passed":true},{"actual":"a:b","check":"single user kind stays bare with colon","expected":"a:b","passed":true},{"actual":"app:a%253Ab:device:50%25:user:z","check":"context sample 1","expected":"app:a%3Ab:device:50%25:user:z","passed":false},{"actual":"device:acme:org:z:user:z","check":"context sample 2","expected":"device:acme:org:z:user:z","passed":true},{"actual":"app:k%253A1%25:device:bob:user:acme","check":"context sample 3","expected":"app:k%3A1%25:device:bob:user:acme","passed":false}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"percent is escaped before colon\", \"actual\": \"org:a%253Ab:user:50%25\", \"expected\": \"org:a%3Ab:user:50%25\", \"passed\": false}, {\"check\": \"already escaped text is escaped again\", \"actual\": \"org:x%253Ay:user:bob\", \"expected\": \"org:x%253Ay:user:bob\", \"passed\": true}, {\"check\": \"kinds are sorted regardless of insertion\", \"actual\": \"org:acme:user:bob\", \"expected\": \"org:acme:user:bob\", \"passed\": true}, {\"check\": \"single non-user kind is prefixed\", \"actual\": \"org:acme\", \"expected\": \"org:acme\", \"passed\": true}, {\"check\": \"single user kind stays bare with colon\", \"actual\": \"a:b\", \"expected\": \"a:b\", \"passed\": true}, {\"check\": \"context sample 1\", \"actual\": \"app:a%253Ab:device:50%25:user:z\", \"expected\": \"app:a%3Ab:device:50%25:user:z\", \"passed\": false}, {\"check\": \"context sample 2\", \"actual\": \"device:acme:org:z:user:z\", \"expected\": \"device:acme:org:z:user:z\", \"passed\": true}, {\"check\": \"context sample 3\", \"actual\": \"app:k%253A1%25:device:bob:user:acme\", \"expected\": \"app:k%3A1%25:device:bob:user:acme\", \"passed\": false}], \"passed\": false}\n"}},"member_only":{"stages":["fixed"],"fields":["implementations.fixed","verification.fixed","harness","repair"],"note":"The verified repair, its recorded checks, the repair description, and the scoring harness are available to members."}}