FA-56341 / Auction allocation rules / Open access
Sealed envelope: replacement digest · case 01
An old sealed envelope remains revealable after a replacement commit.
ROOT CAUSE
An old sealed envelope remains revealable after a replacement commit.
VERIFIED REPAIR
Compare the reveal only with the last accepted commitment.
Unsuccessful approach: The attempted repair uses x["revealed"] == (x["commits"][0] if x["commits"] else None); the explicit regression cases demonstrate that this still violates the stipulated auction rule.
Case contract
Stipulated sealed-bid envelope processing: one bidder, one lot, a commit and reveal phase. A replacement commit invalidates an earlier digest. Reveal payloads are immutable, phase counters are integers, and byte strings are represented by ordinary strings. Output named admission decisions and retained payloads. Named decision replacement-digest: Compare the reveal only with the last accepted commitment.
Why this case matters
Offline administrative auction model for software failure analysis.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(x):
v0 = x["revealed"] in x["commits"]
v1 = x["commit_round"] < x["reveal_round"] <= x["close"]
v2 = None if x["withdrawn"] else x["digest"]
v3 = [] if x["opened"] else x["payloads"][:1]
v4 = next((p for p,v in zip(x["payloads"],x["valid"]) if v),None)
v5 = x["nonce"] == x["required_nonce"]
v6 = x["owner"] == x["signer"]
v7 = x["sealed_value"] if x["opened"] else x["public_value"]
v8 = x["lot"] == x["reveal_lot"]
v9 = sum(1 for v in x["valid"] if v)
return {'replacement-digest':v0,'reveal-phase':v1,'withdrawal-tombstone':v2,'replay-disclosure':v3,'first-valid-reveal':v4,'nonce-binding':v5,'signer-binding':v6,'preopening-secrecy':v7,'lot-binding':v8,'verified-reveal-count':v9}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [('normal contract', {'digest': 'v2', 'revealed': 'v1', 'commit_round': 1, 'reveal_round': 2, 'close': 2, 'withdrawn': False, 'opened': False, 'commits': ['v1', 'v2'], 'payloads': ['red', 'blue'], 'valid': [False, True], 'reveal_count': 2, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [False, False, False, False, False]), ('two verified envelopes', {'digest': 'v2', 'revealed': 'v1', 'commit_round': 1, 'reveal_round': 2, 'close': 2, 'withdrawn': False, 'opened': False, 'commits': ['v1', 'v2'], 'payloads': ['red', 'blue'], 'valid': [True, True], 'reveal_count': 2, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [False, False, False, False, False]), ('valid last envelope', {'digest': 'v2', 'revealed': 'v2', 'commit_round': 1, 'reveal_round': 2, 'close': 2, 'withdrawn': False, 'opened': False, 'commits': ['v1', 'v2'], 'payloads': ['red', 'blue'], 'valid': [False, True], 'reveal_count': 2, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [True, True, True, True, True]), ('first envelope only', {'digest': 'v1', 'revealed': 'v1', 'commit_round': 1, 'reveal_round': 2, 'close': 2, 'withdrawn': False, 'opened': False, 'commits': ['v1'], 'payloads': ['red'], 'valid': [True], 'reveal_count': 1, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [True, True, True, True, True]), ('no envelopes', {'digest': 'v2', 'revealed': 'v1', 'commit_round': 1, 'reveal_round': 2, 'close': 2, 'withdrawn': False, 'opened': False, 'commits': [], 'payloads': [], 'valid': [], 'reveal_count': 0, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [False, False, False, False, False]), ('withdrawn before opening', {'digest': 'v2', 'revealed': 'v1', 'commit_round': 1, 'reveal_round': 2, 'close': 2, 'withdrawn': True, 'opened': False, 'commits': ['v1', 'v2'], 'payloads': ['red', 'blue'], 'valid': [False, True], 'reveal_count': 2, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [False, False, False, False, False]), ('opened envelope replay', {'digest': 'v2', 'revealed': 'v1', 'commit_round': 1, 'reveal_round': 2, 'close': 2, 'withdrawn': False, 'opened': True, 'commits': ['v1', 'v2'], 'payloads': ['red', 'blue'], 'valid': [False, True], 'reveal_count': 2, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [False, False, False, False, False]), ('outside reveal round', {'digest': 'v2', 'revealed': 'v1', 'commit_round': 1, 'reveal_round': 3, 'close': 2, 'withdrawn': False, 'opened': False, 'commits': ['v1', 'v2'], 'payloads': ['red', 'blue'], 'valid': [False, True], 'reveal_count': 2, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [False, False, False, False, False]), ('same-round premature reveal', {'digest': 'v2', 'revealed': 'v1', 'commit_round': 1, 'reveal_round': 1, 'close': 2, 'withdrawn': False, 'opened': False, 'commits': ['v1', 'v2'], 'payloads': ['red', 'blue'], 'valid': [False, True], 'reveal_count': 2, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [False, False, False, False, False])]
def vary(value):
if type(value) is int: return value*N
if isinstance(value,list): return [vary(v) for v in value]
if isinstance(value,dict): return {k:(v if k in ['count', 'delivery_index', 'disputed', 'maximum_set', 'minimum_set', 'reveal_count', 'stage', 'threshold', 'waived'] else vary(v)) for k,v in value.items()}
return value
for label, request, expected in fixtures:
check(label, solve(vary(request))['replacement-digest'], expected[N-1])
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| normal contract | True | False | Failed |
| two verified envelopes | True | False | Failed |
| valid last envelope | True | True | Passed |
| first envelope only | True | True | Passed |
| no envelopes | False | False | Passed |
| withdrawn before opening | True | False | Failed |
| opened envelope replay | True | False | Failed |
| outside reveal round | True | False | Failed |
| same-round premature reveal | True | False | Failed |
SHA-256 / f48b0949f0995fcd5bcc325d04d808943f0c78bb98c51d31a9188f3cc1d7bb46
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(x):
v0 = x["revealed"] == (x["commits"][0] if x["commits"] else None)
v1 = x["commit_round"] < x["reveal_round"] <= x["close"]
v2 = None if x["withdrawn"] else x["digest"]
v3 = [] if x["opened"] else x["payloads"][:1]
v4 = next((p for p,v in zip(x["payloads"],x["valid"]) if v),None)
v5 = x["nonce"] == x["required_nonce"]
v6 = x["owner"] == x["signer"]
v7 = x["sealed_value"] if x["opened"] else x["public_value"]
v8 = x["lot"] == x["reveal_lot"]
v9 = sum(1 for v in x["valid"] if v)
return {'replacement-digest':v0,'reveal-phase':v1,'withdrawal-tombstone':v2,'replay-disclosure':v3,'first-valid-reveal':v4,'nonce-binding':v5,'signer-binding':v6,'preopening-secrecy':v7,'lot-binding':v8,'verified-reveal-count':v9}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [('normal contract', {'digest': 'v2', 'revealed': 'v1', 'commit_round': 1, 'reveal_round': 2, 'close': 2, 'withdrawn': False, 'opened': False, 'commits': ['v1', 'v2'], 'payloads': ['red', 'blue'], 'valid': [False, True], 'reveal_count': 2, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [False, False, False, False, False]), ('two verified envelopes', {'digest': 'v2', 'revealed': 'v1', 'commit_round': 1, 'reveal_round': 2, 'close': 2, 'withdrawn': False, 'opened': False, 'commits': ['v1', 'v2'], 'payloads': ['red', 'blue'], 'valid': [True, True], 'reveal_count': 2, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [False, False, False, False, False]), ('valid last envelope', {'digest': 'v2', 'revealed': 'v2', 'commit_round': 1, 'reveal_round': 2, 'close': 2, 'withdrawn': False, 'opened': False, 'commits': ['v1', 'v2'], 'payloads': ['red', 'blue'], 'valid': [False, True], 'reveal_count': 2, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [True, True, True, True, True]), ('first envelope only', {'digest': 'v1', 'revealed': 'v1', 'commit_round': 1, 'reveal_round': 2, 'close': 2, 'withdrawn': False, 'opened': False, 'commits': ['v1'], 'payloads': ['red'], 'valid': [True], 'reveal_count': 1, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [True, True, True, True, True]), ('no envelopes', {'digest': 'v2', 'revealed': 'v1', 'commit_round': 1, 'reveal_round': 2, 'close': 2, 'withdrawn': False, 'opened': False, 'commits': [], 'payloads': [], 'valid': [], 'reveal_count': 0, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [False, False, False, False, False]), ('withdrawn before opening', {'digest': 'v2', 'revealed': 'v1', 'commit_round': 1, 'reveal_round': 2, 'close': 2, 'withdrawn': True, 'opened': False, 'commits': ['v1', 'v2'], 'payloads': ['red', 'blue'], 'valid': [False, True], 'reveal_count': 2, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [False, False, False, False, False]), ('opened envelope replay', {'digest': 'v2', 'revealed': 'v1', 'commit_round': 1, 'reveal_round': 2, 'close': 2, 'withdrawn': False, 'opened': True, 'commits': ['v1', 'v2'], 'payloads': ['red', 'blue'], 'valid': [False, True], 'reveal_count': 2, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [False, False, False, False, False]), ('outside reveal round', {'digest': 'v2', 'revealed': 'v1', 'commit_round': 1, 'reveal_round': 3, 'close': 2, 'withdrawn': False, 'opened': False, 'commits': ['v1', 'v2'], 'payloads': ['red', 'blue'], 'valid': [False, True], 'reveal_count': 2, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [False, False, False, False, False]), ('same-round premature reveal', {'digest': 'v2', 'revealed': 'v1', 'commit_round': 1, 'reveal_round': 1, 'close': 2, 'withdrawn': False, 'opened': False, 'commits': ['v1', 'v2'], 'payloads': ['red', 'blue'], 'valid': [False, True], 'reveal_count': 2, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [False, False, False, False, False])]
def vary(value):
if type(value) is int: return value*N
if isinstance(value,list): return [vary(v) for v in value]
if isinstance(value,dict): return {k:(v if k in ['count', 'delivery_index', 'disputed', 'maximum_set', 'minimum_set', 'reveal_count', 'stage', 'threshold', 'waived'] else vary(v)) for k,v in value.items()}
return value
for label, request, expected in fixtures:
check(label, solve(vary(request))['replacement-digest'], expected[N-1])
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| normal contract | True | False | Failed |
| two verified envelopes | True | False | Failed |
| valid last envelope | False | True | Failed |
| first envelope only | True | True | Passed |
| no envelopes | False | False | Passed |
| withdrawn before opening | True | False | Failed |
| opened envelope replay | True | False | Failed |
| outside reveal round | True | False | Failed |
| same-round premature reveal | True | False | Failed |
SHA-256 / cd4bdb7d3395dbd8212b193f8fa559d4b19416f23a9cfbf1cf76b8b23986663f
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(x):
v0 = x["revealed"] == (x["commits"][-1] if x["commits"] else None)
v1 = x["commit_round"] < x["reveal_round"] <= x["close"]
v2 = None if x["withdrawn"] else x["digest"]
v3 = [] if x["opened"] else x["payloads"][:1]
v4 = next((p for p,v in zip(x["payloads"],x["valid"]) if v),None)
v5 = x["nonce"] == x["required_nonce"]
v6 = x["owner"] == x["signer"]
v7 = x["sealed_value"] if x["opened"] else x["public_value"]
v8 = x["lot"] == x["reveal_lot"]
v9 = sum(1 for v in x["valid"] if v)
return {'replacement-digest':v0,'reveal-phase':v1,'withdrawal-tombstone':v2,'replay-disclosure':v3,'first-valid-reveal':v4,'nonce-binding':v5,'signer-binding':v6,'preopening-secrecy':v7,'lot-binding':v8,'verified-reveal-count':v9}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [('normal contract', {'digest': 'v2', 'revealed': 'v1', 'commit_round': 1, 'reveal_round': 2, 'close': 2, 'withdrawn': False, 'opened': False, 'commits': ['v1', 'v2'], 'payloads': ['red', 'blue'], 'valid': [False, True], 'reveal_count': 2, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [False, False, False, False, False]), ('two verified envelopes', {'digest': 'v2', 'revealed': 'v1', 'commit_round': 1, 'reveal_round': 2, 'close': 2, 'withdrawn': False, 'opened': False, 'commits': ['v1', 'v2'], 'payloads': ['red', 'blue'], 'valid': [True, True], 'reveal_count': 2, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [False, False, False, False, False]), ('valid last envelope', {'digest': 'v2', 'revealed': 'v2', 'commit_round': 1, 'reveal_round': 2, 'close': 2, 'withdrawn': False, 'opened': False, 'commits': ['v1', 'v2'], 'payloads': ['red', 'blue'], 'valid': [False, True], 'reveal_count': 2, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [True, True, True, True, True]), ('first envelope only', {'digest': 'v1', 'revealed': 'v1', 'commit_round': 1, 'reveal_round': 2, 'close': 2, 'withdrawn': False, 'opened': False, 'commits': ['v1'], 'payloads': ['red'], 'valid': [True], 'reveal_count': 1, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [True, True, True, True, True]), ('no envelopes', {'digest': 'v2', 'revealed': 'v1', 'commit_round': 1, 'reveal_round': 2, 'close': 2, 'withdrawn': False, 'opened': False, 'commits': [], 'payloads': [], 'valid': [], 'reveal_count': 0, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [False, False, False, False, False]), ('withdrawn before opening', {'digest': 'v2', 'revealed': 'v1', 'commit_round': 1, 'reveal_round': 2, 'close': 2, 'withdrawn': True, 'opened': False, 'commits': ['v1', 'v2'], 'payloads': ['red', 'blue'], 'valid': [False, True], 'reveal_count': 2, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [False, False, False, False, False]), ('opened envelope replay', {'digest': 'v2', 'revealed': 'v1', 'commit_round': 1, 'reveal_round': 2, 'close': 2, 'withdrawn': False, 'opened': True, 'commits': ['v1', 'v2'], 'payloads': ['red', 'blue'], 'valid': [False, True], 'reveal_count': 2, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [False, False, False, False, False]), ('outside reveal round', {'digest': 'v2', 'revealed': 'v1', 'commit_round': 1, 'reveal_round': 3, 'close': 2, 'withdrawn': False, 'opened': False, 'commits': ['v1', 'v2'], 'payloads': ['red', 'blue'], 'valid': [False, True], 'reveal_count': 2, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [False, False, False, False, False]), ('same-round premature reveal', {'digest': 'v2', 'revealed': 'v1', 'commit_round': 1, 'reveal_round': 1, 'close': 2, 'withdrawn': False, 'opened': False, 'commits': ['v1', 'v2'], 'payloads': ['red', 'blue'], 'valid': [False, True], 'reveal_count': 2, 'nonce': 'n', 'required_nonce': 'n', 'owner': 'alice', 'signer': 'alice', 'sealed_value': 9, 'public_value': 0, 'lot': 'A', 'reveal_lot': 'A'}, [False, False, False, False, False])]
def vary(value):
if type(value) is int: return value*N
if isinstance(value,list): return [vary(v) for v in value]
if isinstance(value,dict): return {k:(v if k in ['count', 'delivery_index', 'disputed', 'maximum_set', 'minimum_set', 'reveal_count', 'stage', 'threshold', 'waived'] else vary(v)) for k,v in value.items()}
return value
for label, request, expected in fixtures:
check(label, solve(vary(request))['replacement-digest'], expected[N-1])
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| normal contract | False | False | Passed |
| two verified envelopes | False | False | Passed |
| valid last envelope | True | True | Passed |
| first envelope only | True | True | Passed |
| no envelopes | False | False | Passed |
| withdrawn before opening | False | False | Passed |
| opened envelope replay | False | False | Passed |
| outside reveal round | False | False | Passed |
| same-round premature reveal | False | False | Passed |
SHA-256 / eb298dc76cd03338c3d2696bf8fe2d7eecb98faec6d0544f809b4c81e36ba5fe
Verification & scope
Stipulated toy auction rules, not a venue specification, financial advice, optimization claim, or live trading implementation. Nonnegative integer inputs and internally aligned list fields only. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:46:06.294148+00:00.
Case digest / 577ebda611c009f1b78e5166454c8883e1c887d185f626cec9beaf9908bb2421