FA-74156 / Feature flag rollout bucketing / Open access
Network allowlist clause: The prefix mask selects low-order bits · case 01
A /24 rule compares the last three octets, so unrelated networks match.
ROOT CAUSE
The mask is (1 << n) - 1 without shifting it into the high-order bits.
VERIFIED REPAIR
Shift the n one-bits to the top of the 32-bit word.
Unsuccessful approach: Treating /0 as a host match inverts the meaning of the catch-all entry.
Case contract
ip is dotted-quad IPv4 with octets 0..255 (else return None). Each cidr is "a.b.c.d/n" with 0 <= n <= 32, or a bare address meaning /32; malformed entries are skipped. An entry matches when the top n bits of ip and of its address agree (host bits of the entry are ignored). Return [True, index of first match] or [False, -1].
Why this case matters
Office and VPN allowlists gate internal features by source network.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(ip, cidrs):
def parse(s):
parts = s.split('.')
if len(parts) != 4 or not all(p.isdigit() and int(p) <= 255 for p in parts):
return None
v = 0
for p in parts:
v = v * 256 + int(p)
return v
addr = parse(ip)
if addr is None:
return None
for i, c in enumerate(cidrs):
net, _, bits = c.partition('/')
bits = bits or '32'
base = parse(net)
if base is None or not bits.isdigit() or int(bits) > 32:
continue
n = int(bits)
mask = (1 << n) - 1
if addr & mask == base & mask:
return [True, i]
return [False, -1]
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('slash 24 matches inside the network', ['10.1.2.3', ['192.168.0.0/16', '10.1.2.0/24']], [True, 1]),
('slash 0 matches everything', ['8.8.8.8', ['0.0.0.0/0']], [True, 0]),
('octet 256 in an entry is malformed', ['1.0.0.0', ['1.0.0.256/8']], [False, -1]),
('octet 255 is valid', ['192.168.0.255', ['192.168.0.255']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('prefix longer than 32 is skipped', ['10.0.0.1', ['10.0.0.0/33', '10.0.0.0/8']], [True, 1]),
('network sample 1', ['10.1.2.0', ['8.8.8.0', '10.1.2.3/32', '10.0.0.0/8']], [True, 2]),
('network sample 2', ['8.8.8.8', ['10.1.2.3/32']], [False, -1])],
[('slash 0 matches everything', ['8.8.8.8', ['0.0.0.0/0']], [True, 0]),
('octet 256 in an entry is malformed', ['1.0.0.0', ['1.0.0.256/8']], [False, -1]),
('octet 255 is valid', ['192.168.0.255', ['192.168.0.255']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('entry with host bits still matches its network', ['10.1.2.9', ['10.1.2.77/24']], [True, 0]),
('prefix longer than 32 is skipped', ['10.0.0.1', ['10.0.0.0/33', '10.0.0.0/8']], [True, 1]),
('network sample 6', ['172.16.5.4', ['192.168.0.0/16', '8.8.8.0', '10.1.2.77/24']], [False, -1]),
('network sample 55', ['255.255.255.255', ['192.168.1.0/24', '0.0.0.0/0']], [True, 1])],
[('octet 256 in an entry is malformed', ['1.0.0.0', ['1.0.0.256/8']], [False, -1]),
('octet 255 is valid', ['192.168.0.255', ['192.168.0.255']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('entry with host bits still matches its network', ['10.1.2.9', ['10.1.2.77/24']], [True, 0]),
('network address itself matches', ['10.1.2.0', ['10.1.2.0/24']], [True, 0]),
('prefix longer than 32 is skipped', ['10.0.0.1', ['10.0.0.0/33', '10.0.0.0/8']], [True, 1]),
('network sample 11', ['10.1.2.3', ['192.168.1.0/24']], [False, -1]),
('network sample 25', ['172.16.5.4', ['10.1.2.0/31', '0.0.0.0/0', '8.8.8.0']], [True, 1])],
[('octet 255 is valid', ['192.168.0.255', ['192.168.0.255']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('entry with host bits still matches its network', ['10.1.2.9', ['10.1.2.77/24']], [True, 0]),
('network address itself matches', ['10.1.2.0', ['10.1.2.0/24']], [True, 0]),
('invalid ip returns None', ['10.0.0.300', ['0.0.0.0/0']], None),
('network sample 7', ['10.1.2.0', ['0.0.0.0/0']], [True, 0]),
('network sample 16', ['10.1.2.0', ['1.0.0.256/8']], [False, -1]),
('network sample 43', ['0.0.0.0', ['10.0.0.0/8']], [False, -1])],
[('slash 0 matches everything', ['8.8.8.8', ['0.0.0.0/0']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('entry with host bits still matches its network', ['10.1.2.9', ['10.1.2.77/24']], [True, 0]),
('network address itself matches', ['10.1.2.0', ['10.1.2.0/24']], [True, 0]),
('invalid ip returns None', ['10.0.0.300', ['0.0.0.0/0']], None),
('prefix longer than 32 is skipped', ['10.0.0.1', ['10.0.0.0/33', '10.0.0.0/8']], [True, 1]),
('network sample 21', ['10.1.2.3', ['10.1.2.3', '192.168.1.0/24']], [True, 0]),
('network sample 45', ['10.1.2.3', ['10.0.0.0/8', '8.8.8.0', '192.168.1.0/24']], [True, 0])]]
for label, args, expected in fixtures[N - 1]:
check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| slash 24 matches inside the network | [False, -1] | [True, 1] | Failed |
| slash 0 matches everything | [True, 0] | [True, 0] | Passed |
| octet 256 in an entry is malformed | [False, -1] | [False, -1] | Passed |
| octet 255 is valid | [True, 0] | [True, 0] | Passed |
| bare address means host route | [False, -1] | [False, -1] | Passed |
| prefix longer than 32 is skipped | [False, -1] | [True, 1] | Failed |
| network sample 1 | [True, 2] | [True, 2] | Passed |
| network sample 2 | [False, -1] | [False, -1] | Passed |
SHA-256 / 03cb1a91c8f2bc854633440466c496046d400d01487013788a65580bd59c64ad
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(ip, cidrs):
def parse(s):
parts = s.split('.')
if len(parts) != 4 or not all(p.isdigit() and int(p) <= 255 for p in parts):
return None
v = 0
for p in parts:
v = v * 256 + int(p)
return v
addr = parse(ip)
if addr is None:
return None
for i, c in enumerate(cidrs):
net, _, bits = c.partition('/')
bits = bits or '32'
base = parse(net)
if base is None or not bits.isdigit() or int(bits) > 32:
continue
n = int(bits)
mask = (0xFFFFFFFF << (32 - n)) & 0xFFFFFFFF if n else 0xFFFFFFFF
if addr & mask == base & mask:
return [True, i]
return [False, -1]
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('slash 24 matches inside the network', ['10.1.2.3', ['192.168.0.0/16', '10.1.2.0/24']], [True, 1]),
('slash 0 matches everything', ['8.8.8.8', ['0.0.0.0/0']], [True, 0]),
('octet 256 in an entry is malformed', ['1.0.0.0', ['1.0.0.256/8']], [False, -1]),
('octet 255 is valid', ['192.168.0.255', ['192.168.0.255']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('prefix longer than 32 is skipped', ['10.0.0.1', ['10.0.0.0/33', '10.0.0.0/8']], [True, 1]),
('network sample 1', ['10.1.2.0', ['8.8.8.0', '10.1.2.3/32', '10.0.0.0/8']], [True, 2]),
('network sample 2', ['8.8.8.8', ['10.1.2.3/32']], [False, -1])],
[('slash 0 matches everything', ['8.8.8.8', ['0.0.0.0/0']], [True, 0]),
('octet 256 in an entry is malformed', ['1.0.0.0', ['1.0.0.256/8']], [False, -1]),
('octet 255 is valid', ['192.168.0.255', ['192.168.0.255']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('entry with host bits still matches its network', ['10.1.2.9', ['10.1.2.77/24']], [True, 0]),
('prefix longer than 32 is skipped', ['10.0.0.1', ['10.0.0.0/33', '10.0.0.0/8']], [True, 1]),
('network sample 6', ['172.16.5.4', ['192.168.0.0/16', '8.8.8.0', '10.1.2.77/24']], [False, -1]),
('network sample 55', ['255.255.255.255', ['192.168.1.0/24', '0.0.0.0/0']], [True, 1])],
[('octet 256 in an entry is malformed', ['1.0.0.0', ['1.0.0.256/8']], [False, -1]),
('octet 255 is valid', ['192.168.0.255', ['192.168.0.255']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('entry with host bits still matches its network', ['10.1.2.9', ['10.1.2.77/24']], [True, 0]),
('network address itself matches', ['10.1.2.0', ['10.1.2.0/24']], [True, 0]),
('prefix longer than 32 is skipped', ['10.0.0.1', ['10.0.0.0/33', '10.0.0.0/8']], [True, 1]),
('network sample 11', ['10.1.2.3', ['192.168.1.0/24']], [False, -1]),
('network sample 25', ['172.16.5.4', ['10.1.2.0/31', '0.0.0.0/0', '8.8.8.0']], [True, 1])],
[('octet 255 is valid', ['192.168.0.255', ['192.168.0.255']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('entry with host bits still matches its network', ['10.1.2.9', ['10.1.2.77/24']], [True, 0]),
('network address itself matches', ['10.1.2.0', ['10.1.2.0/24']], [True, 0]),
('invalid ip returns None', ['10.0.0.300', ['0.0.0.0/0']], None),
('network sample 7', ['10.1.2.0', ['0.0.0.0/0']], [True, 0]),
('network sample 16', ['10.1.2.0', ['1.0.0.256/8']], [False, -1]),
('network sample 43', ['0.0.0.0', ['10.0.0.0/8']], [False, -1])],
[('slash 0 matches everything', ['8.8.8.8', ['0.0.0.0/0']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('entry with host bits still matches its network', ['10.1.2.9', ['10.1.2.77/24']], [True, 0]),
('network address itself matches', ['10.1.2.0', ['10.1.2.0/24']], [True, 0]),
('invalid ip returns None', ['10.0.0.300', ['0.0.0.0/0']], None),
('prefix longer than 32 is skipped', ['10.0.0.1', ['10.0.0.0/33', '10.0.0.0/8']], [True, 1]),
('network sample 21', ['10.1.2.3', ['10.1.2.3', '192.168.1.0/24']], [True, 0]),
('network sample 45', ['10.1.2.3', ['10.0.0.0/8', '8.8.8.0', '192.168.1.0/24']], [True, 0])]]
for label, args, expected in fixtures[N - 1]:
check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| slash 24 matches inside the network | [True, 1] | [True, 1] | Passed |
| slash 0 matches everything | [False, -1] | [True, 0] | Failed |
| octet 256 in an entry is malformed | [False, -1] | [False, -1] | Passed |
| octet 255 is valid | [True, 0] | [True, 0] | Passed |
| bare address means host route | [False, -1] | [False, -1] | Passed |
| prefix longer than 32 is skipped | [True, 1] | [True, 1] | Passed |
| network sample 1 | [True, 2] | [True, 2] | Passed |
| network sample 2 | [False, -1] | [False, -1] | Passed |
SHA-256 / 7c5c9977997d00a1893c4405e9869d6ea1ff5823487b2402a7901f8f154052b1
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(ip, cidrs):
def parse(s):
parts = s.split('.')
if len(parts) != 4 or not all(p.isdigit() and int(p) <= 255 for p in parts):
return None
v = 0
for p in parts:
v = v * 256 + int(p)
return v
addr = parse(ip)
if addr is None:
return None
for i, c in enumerate(cidrs):
net, _, bits = c.partition('/')
bits = bits or '32'
base = parse(net)
if base is None or not bits.isdigit() or int(bits) > 32:
continue
n = int(bits)
mask = ((1 << n) - 1) << (32 - n)
if addr & mask == base & mask:
return [True, i]
return [False, -1]
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('slash 24 matches inside the network', ['10.1.2.3', ['192.168.0.0/16', '10.1.2.0/24']], [True, 1]),
('slash 0 matches everything', ['8.8.8.8', ['0.0.0.0/0']], [True, 0]),
('octet 256 in an entry is malformed', ['1.0.0.0', ['1.0.0.256/8']], [False, -1]),
('octet 255 is valid', ['192.168.0.255', ['192.168.0.255']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('prefix longer than 32 is skipped', ['10.0.0.1', ['10.0.0.0/33', '10.0.0.0/8']], [True, 1]),
('network sample 1', ['10.1.2.0', ['8.8.8.0', '10.1.2.3/32', '10.0.0.0/8']], [True, 2]),
('network sample 2', ['8.8.8.8', ['10.1.2.3/32']], [False, -1])],
[('slash 0 matches everything', ['8.8.8.8', ['0.0.0.0/0']], [True, 0]),
('octet 256 in an entry is malformed', ['1.0.0.0', ['1.0.0.256/8']], [False, -1]),
('octet 255 is valid', ['192.168.0.255', ['192.168.0.255']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('entry with host bits still matches its network', ['10.1.2.9', ['10.1.2.77/24']], [True, 0]),
('prefix longer than 32 is skipped', ['10.0.0.1', ['10.0.0.0/33', '10.0.0.0/8']], [True, 1]),
('network sample 6', ['172.16.5.4', ['192.168.0.0/16', '8.8.8.0', '10.1.2.77/24']], [False, -1]),
('network sample 55', ['255.255.255.255', ['192.168.1.0/24', '0.0.0.0/0']], [True, 1])],
[('octet 256 in an entry is malformed', ['1.0.0.0', ['1.0.0.256/8']], [False, -1]),
('octet 255 is valid', ['192.168.0.255', ['192.168.0.255']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('entry with host bits still matches its network', ['10.1.2.9', ['10.1.2.77/24']], [True, 0]),
('network address itself matches', ['10.1.2.0', ['10.1.2.0/24']], [True, 0]),
('prefix longer than 32 is skipped', ['10.0.0.1', ['10.0.0.0/33', '10.0.0.0/8']], [True, 1]),
('network sample 11', ['10.1.2.3', ['192.168.1.0/24']], [False, -1]),
('network sample 25', ['172.16.5.4', ['10.1.2.0/31', '0.0.0.0/0', '8.8.8.0']], [True, 1])],
[('octet 255 is valid', ['192.168.0.255', ['192.168.0.255']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('entry with host bits still matches its network', ['10.1.2.9', ['10.1.2.77/24']], [True, 0]),
('network address itself matches', ['10.1.2.0', ['10.1.2.0/24']], [True, 0]),
('invalid ip returns None', ['10.0.0.300', ['0.0.0.0/0']], None),
('network sample 7', ['10.1.2.0', ['0.0.0.0/0']], [True, 0]),
('network sample 16', ['10.1.2.0', ['1.0.0.256/8']], [False, -1]),
('network sample 43', ['0.0.0.0', ['10.0.0.0/8']], [False, -1])],
[('slash 0 matches everything', ['8.8.8.8', ['0.0.0.0/0']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('entry with host bits still matches its network', ['10.1.2.9', ['10.1.2.77/24']], [True, 0]),
('network address itself matches', ['10.1.2.0', ['10.1.2.0/24']], [True, 0]),
('invalid ip returns None', ['10.0.0.300', ['0.0.0.0/0']], None),
('prefix longer than 32 is skipped', ['10.0.0.1', ['10.0.0.0/33', '10.0.0.0/8']], [True, 1]),
('network sample 21', ['10.1.2.3', ['10.1.2.3', '192.168.1.0/24']], [True, 0]),
('network sample 45', ['10.1.2.3', ['10.0.0.0/8', '8.8.8.0', '192.168.1.0/24']], [True, 0])]]
for label, args, expected in fixtures[N - 1]:
check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| slash 24 matches inside the network | [True, 1] | [True, 1] | Passed |
| slash 0 matches everything | [True, 0] | [True, 0] | Passed |
| octet 256 in an entry is malformed | [False, -1] | [False, -1] | Passed |
| octet 255 is valid | [True, 0] | [True, 0] | Passed |
| bare address means host route | [False, -1] | [False, -1] | Passed |
| prefix longer than 32 is skipped | [True, 1] | [True, 1] | Passed |
| network sample 1 | [True, 2] | [True, 2] | Passed |
| network sample 2 | [False, -1] | [False, -1] | Passed |
SHA-256 / 1484f0a83865de0e3ab49faddbc365cec44d287fb99a8f1c5541e115dac9deec
Verification & scope
A deterministic toy flag-evaluation model with a stipulated contract; it does not reproduce any vendor SDK byte for byte. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:48:53.996881+00:00.
Case digest / e486c0840f3424ba169a8e576af1afad4564a82f68a496001abb48dbc4a52ea3