FA-6971 / Proxy forwarding / Open access
Untrusted peer cannot supply forwarding identity · case 01
Untrusted peer cannot supply forwarding identity.
ROOT CAUSE
The faulty implementation uses `chain` for the untrusted-peer-cannot-supply-forwarding-identity decision.
VERIFIED REPAIR
Apply the explicit untrusted-peer-cannot-supply-forwarding-identity contract, including the tested boundary and negative cases.
Unsuccessful approach: The attempted repair uses `[peer]` and still violates a separate fixture.
Case contract
Bounded offline decision model: untrusted peer cannot supply forwarding identity. Inputs are already validated protocol fields; the explicit fixtures define the supported policy, not a complete protocol implementation.
Why this case matters
This deterministic proxy forwarding model isolates the untrusted-peer-cannot-supply-forwarding-identity policy at a network component boundary.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import ipaddress
import re
from urllib.parse import urlsplit, urljoin
N = 1
observations = []
def solve(peer, chain, trusted):
return chain
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
_fixtures = ["check('fixture 1', solve('p', ['c'], ['p']), ['c'])", "check('fixture 2', solve('p', ['spoof'], []), ['p'])", "check('fixture 3', solve('p', [], []), ['p'])", "check('fixture 4', solve('p', [], ['p']), [])"]
for _line in _fixtures[N % len(_fixtures):] + _fixtures[:N % len(_fixtures)]:
exec(_line)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| fixture 2 | ['spoof'] | ['p'] | Failed |
| fixture 3 | [] | ['p'] | Failed |
| fixture 4 | [] | [] | Passed |
| fixture 1 | ['c'] | ['c'] | Passed |
SHA-256 / 199fdd0271a803359fd483736b987afcf60642aae956c672e041cee9b27c2d33
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import ipaddress
import re
from urllib.parse import urlsplit, urljoin
N = 1
observations = []
def solve(peer, chain, trusted):
return [peer]
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
_fixtures = ["check('fixture 1', solve('p', ['c'], ['p']), ['c'])", "check('fixture 2', solve('p', ['spoof'], []), ['p'])", "check('fixture 3', solve('p', [], []), ['p'])", "check('fixture 4', solve('p', [], ['p']), [])"]
for _line in _fixtures[N % len(_fixtures):] + _fixtures[:N % len(_fixtures)]:
exec(_line)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| fixture 2 | ['p'] | ['p'] | Passed |
| fixture 3 | ['p'] | ['p'] | Passed |
| fixture 4 | ['p'] | [] | Failed |
| fixture 1 | ['p'] | ['c'] | Failed |
SHA-256 / ac3377d9993b7942cc0cc9c75dfbbdc7802e270b9774d53cd9d61ed119fa32f5
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
import ipaddress
import re
from urllib.parse import urlsplit, urljoin
N = 1
observations = []
def solve(peer, chain, trusted):
return chain if peer in trusted else [peer]
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
_fixtures = ["check('fixture 1', solve('p', ['c'], ['p']), ['c'])", "check('fixture 2', solve('p', ['spoof'], []), ['p'])", "check('fixture 3', solve('p', [], []), ['p'])", "check('fixture 4', solve('p', [], ['p']), [])"]
for _line in _fixtures[N % len(_fixtures):] + _fixtures[:N % len(_fixtures)]:
exec(_line)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| fixture 2 | ['p'] | ['p'] | Passed |
| fixture 3 | ['p'] | ['p'] | Passed |
| fixture 4 | [] | [] | Passed |
| fixture 1 | ['c'] | ['c'] | Passed |
SHA-256 / 4f00bd9150f57585e04ae597032bbd796a7bcfecac9c748df96478968a2427c8
Verification & scope
Bounded deterministic policy model over validated inputs; not a complete protocol stack or an interoperability claim. The five variants rotate the same explicit fixture set. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:38:07.154470+00:00.
Case digest / d1e7e43ebf393376efa7a391756effec67d38c1dd133487ec467d18057a7c01c