{"abstract":"Unsigned provenance is ignored.","category":"Packaging","checks":7,"contract":"Reject an immutable version with changed digest; skip equal published digests; reject missing attestations; reject private packages on public registries; otherwise publish. Existing equality takes precedence over publication checks.","contract_signature":"version, digest, existing, attested, private, registry","evaluation_group":"xt-publish-plan","failed_approach":"The attempted repair substitutes if attested:. Fixture 1 still yields 'missing-attestation' instead of 'publish'.","family":"xt-publish-plan-attestation","id":"FA-9996","implementations":{"attempt":{"sha256":"9d487e919eead34cf38ff20fea51dfd67034faa01871293e929dc9691eb4027d","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(version, digest, existing, attested, private, registry):\n    if version in existing:\n        if existing[version] == digest: return 'skip'\n        return 'immutable-conflict'\n    if attested: return 'missing-attestation'\n    if private and registry == 'public': return 'private-package'\n    return 'publish'\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\ncheck('fixture 1', solve('1', 'a', {}, True, False, 'public'), 'publish')\ncheck('fixture 2', solve('1', 'a', {'1': 'a'}, False, True, 'public'), 'skip')\ncheck('fixture 3', solve('1', 'a', {'1': 'b'}, True, False, 'public'), 'immutable-conflict')\ncheck('fixture 4', solve('1', 'a', {}, False, False, 'public'), 'missing-attestation')\ncheck('fixture 5', solve('1', 'a', {}, True, True, 'public'), 'private-package')\ncheck('fixture 6', solve('1', 'a', {}, True, True, 'private'), 'publish')\ncheck('fixture 7', solve('2', 'a', {'1': 'b'}, True, False, 'public'), 'publish')\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"},"broken":{"sha256":"0884b52e2c993a4806729b5c20f7d3ca1eb3b87154cdd83313ab8c6078e6754a","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(version, digest, existing, attested, private, registry):\n    if version in existing:\n        if existing[version] == digest: return 'skip'\n        return 'immutable-conflict'\n    if False: return 'missing-attestation'\n    if private and registry == 'public': return 'private-package'\n    return 'publish'\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\ncheck('fixture 1', solve('1', 'a', {}, True, False, 'public'), 'publish')\ncheck('fixture 2', solve('1', 'a', {'1': 'a'}, False, True, 'public'), 'skip')\ncheck('fixture 3', solve('1', 'a', {'1': 'b'}, True, False, 'public'), 'immutable-conflict')\ncheck('fixture 4', solve('1', 'a', {}, False, False, 'public'), 'missing-attestation')\ncheck('fixture 5', solve('1', 'a', {}, True, True, 'public'), 'private-package')\ncheck('fixture 6', solve('1', 'a', {}, True, True, 'private'), 'publish')\ncheck('fixture 7', solve('2', 'a', {'1': 'b'}, True, False, 'public'), 'publish')\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"}},"limitations":" This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.","method":"Deterministic executable model with adversarial boundary fixtures.","provenance":{"created_by":"Failure Map","dependencies":"Python standard library","family":"xt-publish-plan-attestation","generated_at":"2026-09-29T14:38:34.902214+00:00","license":"CC0-1.0","python":"3.12.14","seed":1,"split":"open-access"},"relevance":"An offline model of package publication plan, suitable for testing build and release tooling without external services.","root_cause":"The implementation substitutes if False: for if not attested:, so unsigned provenance is ignored.","sha256":"d010f67ecf7f05d8d9529181b4ee5409748cd7d138f8b72209e5c4d3f1091ef9","title":"Package publication plan: Unsigned provenance is ignored · case 01","variant":1,"variant_policy":"Five numbered records share a model and may reuse boundary fixtures.","verified":true,"visibility":"public","verification":{"attempt":{"elapsed_ms":39.197,"exit_code":1,"observations":[{"actual":"missing-attestation","check":"fixture 1","expected":"publish","passed":false},{"actual":"skip","check":"fixture 2","expected":"skip","passed":true},{"actual":"immutable-conflict","check":"fixture 3","expected":"immutable-conflict","passed":true},{"actual":"publish","check":"fixture 4","expected":"missing-attestation","passed":false},{"actual":"missing-attestation","check":"fixture 5","expected":"private-package","passed":false},{"actual":"missing-attestation","check":"fixture 6","expected":"publish","passed":false},{"actual":"missing-attestation","check":"fixture 7","expected":"publish","passed":false}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"fixture 1\", \"actual\": \"missing-attestation\", \"expected\": \"publish\", \"passed\": false}, {\"check\": \"fixture 2\", \"actual\": \"skip\", \"expected\": \"skip\", \"passed\": true}, {\"check\": \"fixture 3\", \"actual\": \"immutable-conflict\", \"expected\": \"immutable-conflict\", \"passed\": true}, {\"check\": \"fixture 4\", \"actual\": \"publish\", \"expected\": \"missing-attestation\", \"passed\": false}, {\"check\": \"fixture 5\", \"actual\": \"missing-attestation\", \"expected\": \"private-package\", \"passed\": false}, {\"check\": \"fixture 6\", \"actual\": \"missing-attestation\", \"expected\": \"publish\", \"passed\": false}, {\"check\": \"fixture 7\", \"actual\": \"missing-attestation\", \"expected\": \"publish\", \"passed\": false}], \"passed\": false}\n"},"broken":{"elapsed_ms":37.826,"exit_code":1,"observations":[{"actual":"publish","check":"fixture 1","expected":"publish","passed":true},{"actual":"skip","check":"fixture 2","expected":"skip","passed":true},{"actual":"immutable-conflict","check":"fixture 3","expected":"immutable-conflict","passed":true},{"actual":"publish","check":"fixture 4","expected":"missing-attestation","passed":false},{"actual":"private-package","check":"fixture 5","expected":"private-package","passed":true},{"actual":"publish","check":"fixture 6","expected":"publish","passed":true},{"actual":"publish","check":"fixture 7","expected":"publish","passed":true}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"fixture 1\", \"actual\": \"publish\", \"expected\": \"publish\", \"passed\": true}, {\"check\": \"fixture 2\", \"actual\": \"skip\", \"expected\": \"skip\", \"passed\": true}, {\"check\": \"fixture 3\", \"actual\": \"immutable-conflict\", \"expected\": \"immutable-conflict\", \"passed\": true}, {\"check\": \"fixture 4\", \"actual\": \"publish\", \"expected\": \"missing-attestation\", \"passed\": false}, {\"check\": \"fixture 5\", \"actual\": \"private-package\", \"expected\": \"private-package\", \"passed\": true}, {\"check\": \"fixture 6\", \"actual\": \"publish\", \"expected\": \"publish\", \"passed\": true}, {\"check\": \"fixture 7\", \"actual\": \"publish\", \"expected\": \"publish\", \"passed\": true}], \"passed\": false}\n"}},"member_only":{"stages":["fixed"],"fields":["implementations.fixed","verification.fixed","harness","repair"],"note":"The verified repair, its recorded checks, the repair description, and the scoring harness are available to members."}}