FAILURE MAP
← Case archive

FA-11561 / Filesystem semantics / Open access

Permission evaluation falls through from owner to other · case 01

Permission evaluation falls through from owner to other.

Verified by executionVariant 1 · 6 checks per implementationDownload source bundle ↓JSON ↗

ROOT CAUSE

All applicable classes are ORed instead of selecting exactly one owner/group/other class.

VERIFIED REPAIR

Select the owner class first, else matching group, else other, then test the requested bit.

Unsuccessful approach: Choosing the strongest available class still grants permissions explicitly absent from the selected class.

Case contract

Deterministic in-memory filesystem model. POSIX-style basic permission model without ACLs or superuser: owner and group_match booleans select one class; bit is 1,2,or4. Return whether selected class grants it.

Why this case matters

An offline semantic experiment for file API clients; it models only the stated operations, not a complete operating system.

1 / The failure

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(mode, owner, group_match, bit):
    return bool(((mode>>6 if owner else 0) | (mode>>3 if group_match else 0) | mode) & bit)
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('owner denial cannot fall through',solve(0o004,True,False,4),False)
check('group denial cannot fall through',solve(0o004,False,True,4),False)
check('owner wins despite matching group',solve(0o040,True,True,4),False)
check('owner allowed',solve(0o400,True,False,4),True)
check('other allowed',solve(0o001,False,False,1),True)
check('varying unrelated mode bits',solve(N<<6,False,False,2),False)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
owner denial cannot fall throughTrueFalseFailed
group denial cannot fall throughTrueFalseFailed
owner wins despite matching groupTrueFalseFailed
owner allowedTrueTruePassed
other allowedTrueTruePassed
varying unrelated mode bitsFalseFalsePassed

SHA-256 / 5176547cdb322f0fb7a9c03eea18d8b9354cf434019a790bedca4b6dc37e0b9b

2 / The unsuccessful fix

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(mode, owner, group_match, bit):
    return bool(max((mode>>6)&7 if owner else 0,(mode>>3)&7 if group_match else 0,mode&7)&bit)
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('owner denial cannot fall through',solve(0o004,True,False,4),False)
check('group denial cannot fall through',solve(0o004,False,True,4),False)
check('owner wins despite matching group',solve(0o040,True,True,4),False)
check('owner allowed',solve(0o400,True,False,4),True)
check('other allowed',solve(0o001,False,False,1),True)
check('varying unrelated mode bits',solve(N<<6,False,False,2),False)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
owner denial cannot fall throughTrueFalseFailed
group denial cannot fall throughTrueFalseFailed
owner wins despite matching groupTrueFalseFailed
owner allowedTrueTruePassed
other allowedTrueTruePassed
varying unrelated mode bitsFalseFalsePassed

SHA-256 / b8083cb2f23566cba50a5b37b5f9e95e2ace2ee242e7e6b0daa2b1f17dd0b62e

3 / The verified repair

Exit 0
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(mode, owner, group_match, bit):
    bits = (mode>>6)&7 if owner else (mode>>3)&7 if group_match else mode&7
    return bool(bits & bit)
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('owner denial cannot fall through',solve(0o004,True,False,4),False)
check('group denial cannot fall through',solve(0o004,False,True,4),False)
check('owner wins despite matching group',solve(0o040,True,True,4),False)
check('owner allowed',solve(0o400,True,False,4),True)
check('other allowed',solve(0o001,False,False,1),True)
check('varying unrelated mode bits',solve(N<<6,False,False,2),False)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
owner denial cannot fall throughFalseFalsePassed
group denial cannot fall throughFalseFalsePassed
owner wins despite matching groupFalseFalsePassed
owner allowedTrueTruePassed
other allowedTrueTruePassed
varying unrelated mode bitsFalseFalsePassed

SHA-256 / 318d55f959ad7096a9cae33b31e34cb77a4fe728fead66b46480bd117ae08237

Verification & scope

This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.

Observations recorded using Python 3.12.14 at 2026-09-29T14:38:49.052671+00:00.

Case digest / 263ca0d5c3cede26cd550354e0a885ddab586b9d9b369a6f3f538e5dc937e8dc