FA-11561 / Filesystem semantics / Open access
Permission evaluation falls through from owner to other · case 01
Permission evaluation falls through from owner to other.
ROOT CAUSE
All applicable classes are ORed instead of selecting exactly one owner/group/other class.
VERIFIED REPAIR
Select the owner class first, else matching group, else other, then test the requested bit.
Unsuccessful approach: Choosing the strongest available class still grants permissions explicitly absent from the selected class.
Case contract
Deterministic in-memory filesystem model. POSIX-style basic permission model without ACLs or superuser: owner and group_match booleans select one class; bit is 1,2,or4. Return whether selected class grants it.
Why this case matters
An offline semantic experiment for file API clients; it models only the stated operations, not a complete operating system.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(mode, owner, group_match, bit):
return bool(((mode>>6 if owner else 0) | (mode>>3 if group_match else 0) | mode) & bit)
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('owner denial cannot fall through',solve(0o004,True,False,4),False)
check('group denial cannot fall through',solve(0o004,False,True,4),False)
check('owner wins despite matching group',solve(0o040,True,True,4),False)
check('owner allowed',solve(0o400,True,False,4),True)
check('other allowed',solve(0o001,False,False,1),True)
check('varying unrelated mode bits',solve(N<<6,False,False,2),False)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| owner denial cannot fall through | True | False | Failed |
| group denial cannot fall through | True | False | Failed |
| owner wins despite matching group | True | False | Failed |
| owner allowed | True | True | Passed |
| other allowed | True | True | Passed |
| varying unrelated mode bits | False | False | Passed |
SHA-256 / 5176547cdb322f0fb7a9c03eea18d8b9354cf434019a790bedca4b6dc37e0b9b
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(mode, owner, group_match, bit):
return bool(max((mode>>6)&7 if owner else 0,(mode>>3)&7 if group_match else 0,mode&7)&bit)
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('owner denial cannot fall through',solve(0o004,True,False,4),False)
check('group denial cannot fall through',solve(0o004,False,True,4),False)
check('owner wins despite matching group',solve(0o040,True,True,4),False)
check('owner allowed',solve(0o400,True,False,4),True)
check('other allowed',solve(0o001,False,False,1),True)
check('varying unrelated mode bits',solve(N<<6,False,False,2),False)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| owner denial cannot fall through | True | False | Failed |
| group denial cannot fall through | True | False | Failed |
| owner wins despite matching group | True | False | Failed |
| owner allowed | True | True | Passed |
| other allowed | True | True | Passed |
| varying unrelated mode bits | False | False | Passed |
SHA-256 / b8083cb2f23566cba50a5b37b5f9e95e2ace2ee242e7e6b0daa2b1f17dd0b62e
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(mode, owner, group_match, bit):
bits = (mode>>6)&7 if owner else (mode>>3)&7 if group_match else mode&7
return bool(bits & bit)
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('owner denial cannot fall through',solve(0o004,True,False,4),False)
check('group denial cannot fall through',solve(0o004,False,True,4),False)
check('owner wins despite matching group',solve(0o040,True,True,4),False)
check('owner allowed',solve(0o400,True,False,4),True)
check('other allowed',solve(0o001,False,False,1),True)
check('varying unrelated mode bits',solve(N<<6,False,False,2),False)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| owner denial cannot fall through | False | False | Passed |
| group denial cannot fall through | False | False | Passed |
| owner wins despite matching group | False | False | Passed |
| owner allowed | True | True | Passed |
| other allowed | True | True | Passed |
| varying unrelated mode bits | False | False | Passed |
SHA-256 / 318d55f959ad7096a9cae33b31e34cb77a4fe728fead66b46480bd117ae08237
Verification & scope
This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:38:49.052671+00:00.
Case digest / 263ca0d5c3cede26cd550354e0a885ddab586b9d9b369a6f3f538e5dc937e8dc