FA-4446 / Runtime and resources / Open access
Last owner triggers destruction · case 01
The operation returns a result or retained state that violates this contract: A local shared-ownership model executes [operation,handle,argument] commands. Only owners retain the resource. Output is one result per command; weak and borrowed handles do not retain it. Dropping the final owner destroys the object, but dropping a borrower must not destroy a still-owned object.
ROOT CAUSE
Dropping the final owner destroys the object, but dropping a borrower must not destroy a still-owned object. The broken transition violates that invariant.
VERIFIED REPAIR
A local shared-ownership model executes [operation,handle,argument] commands. Only owners retain the resource. Output is one result per command; weak and borrowed handles do not retain it. Dropping the final owner destroys the object, but dropping a borrower must not destroy a still-owned object.
Unsuccessful approach: The attempted transition changes the behavior but still violates the same invariant in at least one independent regression fixture.
Case contract
A local shared-ownership model executes [operation,handle,argument] commands. Only owners retain the resource. Output is one result per command; weak and borrowed handles do not retain it. Dropping the final owner destroys the object, but dropping a borrower must not destroy a still-owned object. Inputs are the finite Python values shown by the executable fixtures; no concurrent execution is assumed.
Why this case matters
A controlled local-runtime regression for collection APIs, language semantics, or ownership wrappers. Fixtures include boundary and interaction cases.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(x, y=None):
h={'root':'owner'}; destroyed=False; out=[]
for op,k,arg in x:
owners=lambda: sum(v=='owner' for v in h.values())
if op=='clone':
ok=h.get(arg)=='owner' and k not in h and not destroyed
if ok: h[k]='owner'
out.append(ok)
elif op=='borrow':
ok=h.get(arg)=='owner' and k not in h and not destroyed
if ok: h[k]='borrow'
out.append(ok)
elif op=='weak':
ok=k not in h
if ok: h[k]='weak'
out.append(ok)
elif op=='upgrade':
ok=h.get(k)=='weak' and owners()>0 and arg not in h and not destroyed
if ok: h[arg]='owner'
out.append(ok)
elif op=='drop':
existed=k in h
kind=h.pop(k,None)
if kind is not None: destroyed=True
out.append(existed)
elif op=='move':
ok=k in h and arg not in h
if ok:
h[arg]=h[k]
del h[k]
out.append(ok)
elif op=='use':
out.append(h.get(k) in ('owner','borrow') and owners()>0 and not destroyed)
elif op=='unique':
out.append(h.get(k)=='owner' and owners()==1 and not destroyed)
elif op=='inspect':
out.append([owners(),destroyed,sorted(h)])
return out
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('borrow cannot clone or outlive resource', solve([['borrow', 'b', 'root'], ['clone', 'c', 'b'], ['weak', 'w', None], ['use', 'w', None], ['unique', 'root', None], ['unique', 'b', None], ['drop', 'root', None], ['use', 'b', None], ['upgrade', 'w', 'c'], ['inspect', None, None]]), [True, False, True, False, True, False, True, False, False, [0, True, ['b', 'w']]])
check('clones prevent premature destruction', solve([['clone', 'c', 'root'], ['drop', 'root', None], ['use', 'c', None], ['inspect', None, None], ['drop', 'c', None], ['inspect', None, None]]), [True, True, True, [1, False, ['c']], True, [0, True, []]])
check('destination collisions preserve all handles', solve([['clone', 'c', 'root'], ['borrow', 'b', 'root'], ['clone', 'b', 'root'], ['borrow', 'c', 'root'], ['weak', 'w', None], ['upgrade', 'w', 'b'], ['move', 'root', 'c'], ['move', 'root', 'root'], ['inspect', None, None]]), [True, True, False, False, True, False, False, False, [2, False, ['b', 'c', 'root', 'w']]])
check('move and borrower release preserve ownership', solve([['borrow', 'b', 'root'], ['drop', 'b', None], ['move', 'root', 'new'], ['use', 'root', None], ['borrow', 'b', 'new'], ['weak', 'w', None], ['upgrade', 'w', 'c'], ['borrow', 'z', 'b'], ['inspect', None, None]]), [True, True, True, False, True, True, True, False, [2, False, ['b', 'c', 'new', 'w']]])
check('weak collision cannot discard owner', solve([['weak','root',None],['inspect',None,None]]), [False,[1,False,['root']]])
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| borrow cannot clone or outlive resource | [True, False, True, False, True, False, True, False, False, [0, True, ['b', 'w']]] | [True, False, True, False, True, False, True, False, False, [0, True, ['b', 'w']]] | Passed |
| clones prevent premature destruction | [True, True, False, [1, True, ['c']], True, [0, True, []]] | [True, True, True, [1, False, ['c']], True, [0, True, []]] | Failed |
| destination collisions preserve all handles | [True, True, False, False, True, False, False, False, [2, False, ['b', 'c', 'root', 'w']]] | [True, True, False, False, True, False, False, False, [2, False, ['b', 'c', 'root', 'w']]] | Passed |
| move and borrower release preserve ownership | [True, True, True, False, False, True, False, False, [1, True, ['new', 'w']]] | [True, True, True, False, True, True, True, False, [2, False, ['b', 'c', 'new', 'w']]] | Failed |
| weak collision cannot discard owner | [False, [1, False, ['root']]] | [False, [1, False, ['root']]] | Passed |
SHA-256 / a5d74596c86253e8ac0e8c9cb93b702179e284748f01f89dfba8c773f66196f2
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(x, y=None):
h={'root':'owner'}; destroyed=False; out=[]
for op,k,arg in x:
owners=lambda: sum(v=='owner' for v in h.values())
if op=='clone':
ok=h.get(arg)=='owner' and k not in h and not destroyed
if ok: h[k]='owner'
out.append(ok)
elif op=='borrow':
ok=h.get(arg)=='owner' and k not in h and not destroyed
if ok: h[k]='borrow'
out.append(ok)
elif op=='weak':
ok=k not in h
if ok: h[k]='weak'
out.append(ok)
elif op=='upgrade':
ok=h.get(k)=='weak' and owners()>0 and arg not in h and not destroyed
if ok: h[arg]='owner'
out.append(ok)
elif op=='drop':
existed=k in h
kind=h.pop(k,None)
if kind=='owner': destroyed=True
out.append(existed)
elif op=='move':
ok=k in h and arg not in h
if ok:
h[arg]=h[k]
del h[k]
out.append(ok)
elif op=='use':
out.append(h.get(k) in ('owner','borrow') and owners()>0 and not destroyed)
elif op=='unique':
out.append(h.get(k)=='owner' and owners()==1 and not destroyed)
elif op=='inspect':
out.append([owners(),destroyed,sorted(h)])
return out
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('borrow cannot clone or outlive resource', solve([['borrow', 'b', 'root'], ['clone', 'c', 'b'], ['weak', 'w', None], ['use', 'w', None], ['unique', 'root', None], ['unique', 'b', None], ['drop', 'root', None], ['use', 'b', None], ['upgrade', 'w', 'c'], ['inspect', None, None]]), [True, False, True, False, True, False, True, False, False, [0, True, ['b', 'w']]])
check('clones prevent premature destruction', solve([['clone', 'c', 'root'], ['drop', 'root', None], ['use', 'c', None], ['inspect', None, None], ['drop', 'c', None], ['inspect', None, None]]), [True, True, True, [1, False, ['c']], True, [0, True, []]])
check('destination collisions preserve all handles', solve([['clone', 'c', 'root'], ['borrow', 'b', 'root'], ['clone', 'b', 'root'], ['borrow', 'c', 'root'], ['weak', 'w', None], ['upgrade', 'w', 'b'], ['move', 'root', 'c'], ['move', 'root', 'root'], ['inspect', None, None]]), [True, True, False, False, True, False, False, False, [2, False, ['b', 'c', 'root', 'w']]])
check('move and borrower release preserve ownership', solve([['borrow', 'b', 'root'], ['drop', 'b', None], ['move', 'root', 'new'], ['use', 'root', None], ['borrow', 'b', 'new'], ['weak', 'w', None], ['upgrade', 'w', 'c'], ['borrow', 'z', 'b'], ['inspect', None, None]]), [True, True, True, False, True, True, True, False, [2, False, ['b', 'c', 'new', 'w']]])
check('weak collision cannot discard owner', solve([['weak','root',None],['inspect',None,None]]), [False,[1,False,['root']]])
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| borrow cannot clone or outlive resource | [True, False, True, False, True, False, True, False, False, [0, True, ['b', 'w']]] | [True, False, True, False, True, False, True, False, False, [0, True, ['b', 'w']]] | Passed |
| clones prevent premature destruction | [True, True, False, [1, True, ['c']], True, [0, True, []]] | [True, True, True, [1, False, ['c']], True, [0, True, []]] | Failed |
| destination collisions preserve all handles | [True, True, False, False, True, False, False, False, [2, False, ['b', 'c', 'root', 'w']]] | [True, True, False, False, True, False, False, False, [2, False, ['b', 'c', 'root', 'w']]] | Passed |
| move and borrower release preserve ownership | [True, True, True, False, True, True, True, False, [2, False, ['b', 'c', 'new', 'w']]] | [True, True, True, False, True, True, True, False, [2, False, ['b', 'c', 'new', 'w']]] | Passed |
| weak collision cannot discard owner | [False, [1, False, ['root']]] | [False, [1, False, ['root']]] | Passed |
SHA-256 / 8c28cc4c10ec7e8bcb35961c299efeb275222b55fe7d2bdf639b1bb4c6e532fe
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(x, y=None):
h={'root':'owner'}; destroyed=False; out=[]
for op,k,arg in x:
owners=lambda: sum(v=='owner' for v in h.values())
if op=='clone':
ok=h.get(arg)=='owner' and k not in h and not destroyed
if ok: h[k]='owner'
out.append(ok)
elif op=='borrow':
ok=h.get(arg)=='owner' and k not in h and not destroyed
if ok: h[k]='borrow'
out.append(ok)
elif op=='weak':
ok=k not in h
if ok: h[k]='weak'
out.append(ok)
elif op=='upgrade':
ok=h.get(k)=='weak' and owners()>0 and arg not in h and not destroyed
if ok: h[arg]='owner'
out.append(ok)
elif op=='drop':
existed=k in h
kind=h.pop(k,None)
if kind=='owner' and owners()==0: destroyed=True
out.append(existed)
elif op=='move':
ok=k in h and arg not in h
if ok:
h[arg]=h[k]
del h[k]
out.append(ok)
elif op=='use':
out.append(h.get(k) in ('owner','borrow') and owners()>0 and not destroyed)
elif op=='unique':
out.append(h.get(k)=='owner' and owners()==1 and not destroyed)
elif op=='inspect':
out.append([owners(),destroyed,sorted(h)])
return out
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('borrow cannot clone or outlive resource', solve([['borrow', 'b', 'root'], ['clone', 'c', 'b'], ['weak', 'w', None], ['use', 'w', None], ['unique', 'root', None], ['unique', 'b', None], ['drop', 'root', None], ['use', 'b', None], ['upgrade', 'w', 'c'], ['inspect', None, None]]), [True, False, True, False, True, False, True, False, False, [0, True, ['b', 'w']]])
check('clones prevent premature destruction', solve([['clone', 'c', 'root'], ['drop', 'root', None], ['use', 'c', None], ['inspect', None, None], ['drop', 'c', None], ['inspect', None, None]]), [True, True, True, [1, False, ['c']], True, [0, True, []]])
check('destination collisions preserve all handles', solve([['clone', 'c', 'root'], ['borrow', 'b', 'root'], ['clone', 'b', 'root'], ['borrow', 'c', 'root'], ['weak', 'w', None], ['upgrade', 'w', 'b'], ['move', 'root', 'c'], ['move', 'root', 'root'], ['inspect', None, None]]), [True, True, False, False, True, False, False, False, [2, False, ['b', 'c', 'root', 'w']]])
check('move and borrower release preserve ownership', solve([['borrow', 'b', 'root'], ['drop', 'b', None], ['move', 'root', 'new'], ['use', 'root', None], ['borrow', 'b', 'new'], ['weak', 'w', None], ['upgrade', 'w', 'c'], ['borrow', 'z', 'b'], ['inspect', None, None]]), [True, True, True, False, True, True, True, False, [2, False, ['b', 'c', 'new', 'w']]])
check('weak collision cannot discard owner', solve([['weak','root',None],['inspect',None,None]]), [False,[1,False,['root']]])
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| borrow cannot clone or outlive resource | [True, False, True, False, True, False, True, False, False, [0, True, ['b', 'w']]] | [True, False, True, False, True, False, True, False, False, [0, True, ['b', 'w']]] | Passed |
| clones prevent premature destruction | [True, True, True, [1, False, ['c']], True, [0, True, []]] | [True, True, True, [1, False, ['c']], True, [0, True, []]] | Passed |
| destination collisions preserve all handles | [True, True, False, False, True, False, False, False, [2, False, ['b', 'c', 'root', 'w']]] | [True, True, False, False, True, False, False, False, [2, False, ['b', 'c', 'root', 'w']]] | Passed |
| move and borrower release preserve ownership | [True, True, True, False, True, True, True, False, [2, False, ['b', 'c', 'new', 'w']]] | [True, True, True, False, True, True, True, False, [2, False, ['b', 'c', 'new', 'w']]] | Passed |
| weak collision cannot discard owner | [False, [1, False, ['root']]] | [False, [1, False, ['root']]] | Passed |
SHA-256 / 1017562ac69b04380bb05ee5f95a1f6a25e17e1dd8871b2c7685d7c460c6f600
Verification & scope
This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:37:39.280579+00:00.
Case digest / 2a9acb6fb5bf93d36baf875b3aa9fc1a9926b2150b062aebe7572aff2c53f124