{"abstract":"Different package bytes are treated as already published.","category":"Packaging","checks":7,"contract":"Reject an immutable version with changed digest; skip equal published digests; reject missing attestations; reject private packages on public registries; otherwise publish. Existing equality takes precedence over publication checks.","evaluation_group":"xt-publish-plan","failed_approach":"The attempted repair substitutes existing[version] != digest. Fixture 2 still yields 'immutable-conflict' instead of 'skip'.","family":"xt-publish-plan-digest-equality","id":"FA-9986","implementations":{"attempt":{"sha256":"0008260275b4c04918592cd0d59e5fb5c75c80503027292c403ec23de79aa94a","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(version, digest, existing, attested, private, registry):\n    if version in existing:\n        if existing[version] != digest: return 'skip'\n        return 'immutable-conflict'\n    if not attested: return 'missing-attestation'\n    if private and registry == 'public': return 'private-package'\n    return 'publish'\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\ncheck('fixture 1', solve('1', 'a', {}, True, False, 'public'), 'publish')\ncheck('fixture 2', solve('1', 'a', {'1': 'a'}, False, True, 'public'), 'skip')\ncheck('fixture 3', solve('1', 'a', {'1': 'b'}, True, False, 'public'), 'immutable-conflict')\ncheck('fixture 4', solve('1', 'a', {}, False, False, 'public'), 'missing-attestation')\ncheck('fixture 5', solve('1', 'a', {}, True, True, 'public'), 'private-package')\ncheck('fixture 6', solve('1', 'a', {}, True, True, 'private'), 'publish')\ncheck('fixture 7', solve('2', 'a', {'1': 'b'}, True, False, 'public'), 'publish')\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"},"broken":{"sha256":"27186545a22f88f6b4819f93fe1f7de881b656179d3effbe719c18809dedbd4c","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(version, digest, existing, attested, private, registry):\n    if version in existing:\n        if True: return 'skip'\n        return 'immutable-conflict'\n    if not attested: return 'missing-attestation'\n    if private and registry == 'public': return 'private-package'\n    return 'publish'\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\ncheck('fixture 1', solve('1', 'a', {}, True, False, 'public'), 'publish')\ncheck('fixture 2', solve('1', 'a', {'1': 'a'}, False, True, 'public'), 'skip')\ncheck('fixture 3', solve('1', 'a', {'1': 'b'}, True, False, 'public'), 'immutable-conflict')\ncheck('fixture 4', solve('1', 'a', {}, False, False, 'public'), 'missing-attestation')\ncheck('fixture 5', solve('1', 'a', {}, True, True, 'public'), 'private-package')\ncheck('fixture 6', solve('1', 'a', {}, True, True, 'private'), 'publish')\ncheck('fixture 7', solve('2', 'a', {'1': 'b'}, True, False, 'public'), 'publish')\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"},"fixed":{"sha256":"547ca9fee9b6a8d368115b3a6c8eda59df0d444f3bf68ecea0f97f67e9e723db","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(version, digest, existing, attested, private, registry):\n    if version in existing:\n        if existing[version] == digest: return 'skip'\n        return 'immutable-conflict'\n    if not attested: return 'missing-attestation'\n    if private and registry == 'public': return 'private-package'\n    return 'publish'\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\ncheck('fixture 1', solve('1', 'a', {}, True, False, 'public'), 'publish')\ncheck('fixture 2', solve('1', 'a', {'1': 'a'}, False, True, 'public'), 'skip')\ncheck('fixture 3', solve('1', 'a', {'1': 'b'}, True, False, 'public'), 'immutable-conflict')\ncheck('fixture 4', solve('1', 'a', {}, False, False, 'public'), 'missing-attestation')\ncheck('fixture 5', solve('1', 'a', {}, True, True, 'public'), 'private-package')\ncheck('fixture 6', solve('1', 'a', {}, True, True, 'private'), 'publish')\ncheck('fixture 7', solve('2', 'a', {'1': 'b'}, True, False, 'public'), 'publish')\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"}},"limitations":" This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.","method":"Deterministic executable model with adversarial boundary fixtures.","provenance":{"created_by":"Failure Map","dependencies":"Python standard library","family":"xt-publish-plan-digest-equality","generated_at":"2026-09-29T14:38:34.801804+00:00","license":"CC0-1.0","python":"3.12.14","seed":1,"split":"open-access"},"relevance":"An offline model of package publication plan, suitable for testing build and release tooling without external services.","repair":"Skip only when the immutable version has the same digest.","root_cause":"The implementation substitutes True for existing[version] == digest, so different package bytes are treated as already published.","sha256":"348874b937642ed6fbea08eb45c00e7f0b18165645046e3cffc464bb107fdc57","title":"Package publication plan: Different package bytes are treated as already published · case 01","variant":1,"variant_policy":"Five numbered records share a model and may reuse boundary fixtures.","verification":{"attempt":{"elapsed_ms":40.188,"exit_code":1,"observations":[{"actual":"publish","check":"fixture 1","expected":"publish","passed":true},{"actual":"immutable-conflict","check":"fixture 2","expected":"skip","passed":false},{"actual":"skip","check":"fixture 3","expected":"immutable-conflict","passed":false},{"actual":"missing-attestation","check":"fixture 4","expected":"missing-attestation","passed":true},{"actual":"private-package","check":"fixture 5","expected":"private-package","passed":true},{"actual":"publish","check":"fixture 6","expected":"publish","passed":true},{"actual":"publish","check":"fixture 7","expected":"publish","passed":true}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"fixture 1\", \"actual\": \"publish\", \"expected\": \"publish\", \"passed\": true}, {\"check\": \"fixture 2\", \"actual\": \"immutable-conflict\", \"expected\": \"skip\", \"passed\": false}, {\"check\": \"fixture 3\", \"actual\": \"skip\", \"expected\": \"immutable-conflict\", \"passed\": false}, {\"check\": \"fixture 4\", \"actual\": \"missing-attestation\", \"expected\": \"missing-attestation\", \"passed\": true}, {\"check\": \"fixture 5\", \"actual\": \"private-package\", \"expected\": \"private-package\", \"passed\": true}, {\"check\": \"fixture 6\", \"actual\": \"publish\", \"expected\": \"publish\", \"passed\": true}, {\"check\": \"fixture 7\", \"actual\": \"publish\", \"expected\": \"publish\", \"passed\": true}], \"passed\": false}\n"},"broken":{"elapsed_ms":39.106,"exit_code":1,"observations":[{"actual":"publish","check":"fixture 1","expected":"publish","passed":true},{"actual":"skip","check":"fixture 2","expected":"skip","passed":true},{"actual":"skip","check":"fixture 3","expected":"immutable-conflict","passed":false},{"actual":"missing-attestation","check":"fixture 4","expected":"missing-attestation","passed":true},{"actual":"private-package","check":"fixture 5","expected":"private-package","passed":true},{"actual":"publish","check":"fixture 6","expected":"publish","passed":true},{"actual":"publish","check":"fixture 7","expected":"publish","passed":true}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"fixture 1\", \"actual\": \"publish\", \"expected\": \"publish\", \"passed\": true}, {\"check\": \"fixture 2\", \"actual\": \"skip\", \"expected\": \"skip\", \"passed\": true}, {\"check\": \"fixture 3\", \"actual\": \"skip\", \"expected\": \"immutable-conflict\", \"passed\": false}, {\"check\": \"fixture 4\", \"actual\": \"missing-attestation\", \"expected\": \"missing-attestation\", \"passed\": true}, {\"check\": \"fixture 5\", \"actual\": \"private-package\", \"expected\": \"private-package\", \"passed\": true}, {\"check\": \"fixture 6\", \"actual\": \"publish\", \"expected\": \"publish\", \"passed\": true}, {\"check\": \"fixture 7\", \"actual\": \"publish\", \"expected\": \"publish\", \"passed\": true}], \"passed\": false}\n"},"fixed":{"elapsed_ms":39.162,"exit_code":0,"observations":[{"actual":"publish","check":"fixture 1","expected":"publish","passed":true},{"actual":"skip","check":"fixture 2","expected":"skip","passed":true},{"actual":"immutable-conflict","check":"fixture 3","expected":"immutable-conflict","passed":true},{"actual":"missing-attestation","check":"fixture 4","expected":"missing-attestation","passed":true},{"actual":"private-package","check":"fixture 5","expected":"private-package","passed":true},{"actual":"publish","check":"fixture 6","expected":"publish","passed":true},{"actual":"publish","check":"fixture 7","expected":"publish","passed":true}],"passed":true,"stderr":"","stdout":"{\"observations\": [{\"check\": \"fixture 1\", \"actual\": \"publish\", \"expected\": \"publish\", \"passed\": true}, {\"check\": \"fixture 2\", \"actual\": \"skip\", \"expected\": \"skip\", \"passed\": true}, {\"check\": \"fixture 3\", \"actual\": \"immutable-conflict\", \"expected\": \"immutable-conflict\", \"passed\": true}, {\"check\": \"fixture 4\", \"actual\": \"missing-attestation\", \"expected\": \"missing-attestation\", \"passed\": true}, {\"check\": \"fixture 5\", \"actual\": \"private-package\", \"expected\": \"private-package\", \"passed\": true}, {\"check\": \"fixture 6\", \"actual\": \"publish\", \"expected\": \"publish\", \"passed\": true}, {\"check\": \"fixture 7\", \"actual\": \"publish\", \"expected\": \"publish\", \"passed\": true}], \"passed\": true}\n"}},"verified":true,"visibility":"public"}