FA-11916 / Scientific pipeline provenance / Open access
A specimen custody ledger accepts a transfer from a noncustodian · case 01
A specimen is reported at its destination despite a broken handoff chain.
ROOT CAUSE
Only the final recipient is retained, discarding continuity of custody.
VERIFIED REPAIR
Walk signed handoffs in order and require each sender to be the current holder; reject the entire inconsistent ledger.
Unsuccessful approach: Checking only the initial sender misses a broken later handoff.
Case contract
Given initial specimen holder and chronological [sender,recipient] handoffs, return final holder if every sender equals the preceding holder; otherwise None. Empty history preserves initial holder. Names are nonempty strings; self handoffs are permitted.
Why this case matters
A deterministic offline model of scientific specimen processing and provenance; explicit fixtures test the stated bookkeeping or processing acceptance rule.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(initial, handoffs):
return handoffs[-1][1] if handoffs else initial
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
lab='lab'+str(N)
check('later sender mismatch', solve('collector', [('collector',lab),('stranger','archive')]), None)
check('initial sender mismatch', solve('collector', [('stranger',lab)]), None)
check('continuous chain', solve('collector', [('collector',lab),(lab,'archive')]), 'archive')
check('no transfer', solve(lab, []), lab)
check('self transfer', solve(lab, [(lab,lab)]), lab)
check('return to origin', solve('collector', [('collector',lab),(lab,'collector')]), 'collector')
check('invalid middle cannot be healed', solve('collector', [('collector',lab),('other','archive'),('archive',lab)]), None)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| later sender mismatch | archive | None | Failed |
| initial sender mismatch | lab1 | None | Failed |
| continuous chain | archive | archive | Passed |
| no transfer | lab1 | lab1 | Passed |
| self transfer | lab1 | lab1 | Passed |
| return to origin | collector | collector | Passed |
| invalid middle cannot be healed | lab1 | None | Failed |
SHA-256 / 922b788a383cb27c6b338fabbb546d8dacb864f3d108961ced615c70cf8ea6c5
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(initial, handoffs):
if handoffs and handoffs[0][0]!=initial: return None
return handoffs[-1][1] if handoffs else initial
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
lab='lab'+str(N)
check('later sender mismatch', solve('collector', [('collector',lab),('stranger','archive')]), None)
check('initial sender mismatch', solve('collector', [('stranger',lab)]), None)
check('continuous chain', solve('collector', [('collector',lab),(lab,'archive')]), 'archive')
check('no transfer', solve(lab, []), lab)
check('self transfer', solve(lab, [(lab,lab)]), lab)
check('return to origin', solve('collector', [('collector',lab),(lab,'collector')]), 'collector')
check('invalid middle cannot be healed', solve('collector', [('collector',lab),('other','archive'),('archive',lab)]), None)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| later sender mismatch | archive | None | Failed |
| initial sender mismatch | None | None | Passed |
| continuous chain | archive | archive | Passed |
| no transfer | lab1 | lab1 | Passed |
| self transfer | lab1 | lab1 | Passed |
| return to origin | collector | collector | Passed |
| invalid middle cannot be healed | lab1 | None | Failed |
SHA-256 / 4243698974c83e76089ce59267bdd16fd64c49129c9787abf06de9d6c9b634db
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(initial, handoffs):
holder=initial
for sender,recipient in handoffs:
if sender!=holder: return None
holder=recipient
return holder
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
lab='lab'+str(N)
check('later sender mismatch', solve('collector', [('collector',lab),('stranger','archive')]), None)
check('initial sender mismatch', solve('collector', [('stranger',lab)]), None)
check('continuous chain', solve('collector', [('collector',lab),(lab,'archive')]), 'archive')
check('no transfer', solve(lab, []), lab)
check('self transfer', solve(lab, [(lab,lab)]), lab)
check('return to origin', solve('collector', [('collector',lab),(lab,'collector')]), 'collector')
check('invalid middle cannot be healed', solve('collector', [('collector',lab),('other','archive'),('archive',lab)]), None)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| later sender mismatch | None | None | Passed |
| initial sender mismatch | None | None | Passed |
| continuous chain | archive | archive | Passed |
| no transfer | lab1 | lab1 | Passed |
| self transfer | lab1 | lab1 | Passed |
| return to origin | collector | collector | Passed |
| invalid middle cannot be healed | None | None | Passed |
SHA-256 / 34d17063505ab703fb1d9f34480a1609863383f06302e22b4610a722f4d16d7c
Verification & scope
Symbolic in-memory model only; not instrument safety guidance or a production scientific validation. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:38:52.186735+00:00.
Case digest / ad1ae1698fad0648125fb3908e76a6a20cff79d47d5e3997bb0f3773604dfa98