FA-74161 / Feature flag rollout bucketing / Open access
Network allowlist clause: Octets above 255 are accepted · case 01
An entry such as 1.0.0.256/8 is parsed into an unrelated network instead of being skipped.
ROOT CAUSE
Octet validation checks only that each part is made of digits.
VERIFIED REPAIR
Reject octets greater than 255.
Unsuccessful approach: Rejecting 255 itself refuses broadcast-style addresses that are valid.
Case contract
ip is dotted-quad IPv4 with octets 0..255 (else return None). Each cidr is "a.b.c.d/n" with 0 <= n <= 32, or a bare address meaning /32; malformed entries are skipped. An entry matches when the top n bits of ip and of its address agree (host bits of the entry are ignored). Return [True, index of first match] or [False, -1].
Why this case matters
Office and VPN allowlists gate internal features by source network.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(ip, cidrs):
def parse(s):
parts = s.split('.')
if len(parts) != 4 or not all(p.isdigit() for p in parts):
return None
v = 0
for p in parts:
v = v * 256 + int(p)
return v
addr = parse(ip)
if addr is None:
return None
for i, c in enumerate(cidrs):
net, _, bits = c.partition('/')
bits = bits or '32'
base = parse(net)
if base is None or not bits.isdigit() or int(bits) > 32:
continue
n = int(bits)
mask = ((1 << n) - 1) << (32 - n)
if addr & mask == base & mask:
return [True, i]
return [False, -1]
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('slash 24 matches inside the network', ['10.1.2.3', ['192.168.0.0/16', '10.1.2.0/24']], [True, 1]),
('slash 0 matches everything', ['8.8.8.8', ['0.0.0.0/0']], [True, 0]),
('octet 256 in an entry is malformed', ['1.0.0.0', ['1.0.0.256/8']], [False, -1]),
('octet 255 is valid', ['192.168.0.255', ['192.168.0.255']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('invalid ip returns None', ['10.0.0.300', ['0.0.0.0/0']], None),
('network sample 1', ['10.1.2.0', ['8.8.8.0', '10.1.2.3/32', '10.0.0.0/8']], [True, 2]),
('network sample 2', ['8.8.8.8', ['10.1.2.3/32']], [False, -1])],
[('slash 0 matches everything', ['8.8.8.8', ['0.0.0.0/0']], [True, 0]),
('octet 256 in an entry is malformed', ['1.0.0.0', ['1.0.0.256/8']], [False, -1]),
('octet 255 is valid', ['192.168.0.255', ['192.168.0.255']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('entry with host bits still matches its network', ['10.1.2.9', ['10.1.2.77/24']], [True, 0]),
('invalid ip returns None', ['10.0.0.300', ['0.0.0.0/0']], None),
('network sample 34', ['10.0.0.300', ['10.0.0.0/8']], None),
('network sample 55', ['255.255.255.255', ['192.168.1.0/24', '0.0.0.0/0']], [True, 1])],
[('octet 256 in an entry is malformed', ['1.0.0.0', ['1.0.0.256/8']], [False, -1]),
('octet 255 is valid', ['192.168.0.255', ['192.168.0.255']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('entry with host bits still matches its network', ['10.1.2.9', ['10.1.2.77/24']], [True, 0]),
('network address itself matches', ['10.1.2.0', ['10.1.2.0/24']], [True, 0]),
('invalid ip returns None', ['10.0.0.300', ['0.0.0.0/0']], None),
('network sample 11', ['10.1.2.3', ['192.168.1.0/24']], [False, -1]),
('network sample 20', ['192.168.0.255', ['172.16.5.4/30', '192.168.1.0/24']], [False, -1])],
[('octet 255 is valid', ['192.168.0.255', ['192.168.0.255']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('entry with host bits still matches its network', ['10.1.2.9', ['10.1.2.77/24']], [True, 0]),
('network address itself matches', ['10.1.2.0', ['10.1.2.0/24']], [True, 0]),
('invalid ip returns None', ['10.0.0.300', ['0.0.0.0/0']], None),
('network sample 16', ['10.1.2.0', ['1.0.0.256/8']], [False, -1]),
('network sample 40', ['10.0.0.300', ['10.0.0.0/8', '10.1.2.0/24', '172.16.5.4/30']], None),
('network sample 60', ['255.255.255.255', ['10.0.0.0/33', '10.1.2.3/32', '10.1.2.77/24']], [False, -1])],
[('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('entry with host bits still matches its network', ['10.1.2.9', ['10.1.2.77/24']], [True, 0]),
('network address itself matches', ['10.1.2.0', ['10.1.2.0/24']], [True, 0]),
('invalid ip returns None', ['10.0.0.300', ['0.0.0.0/0']], None),
('prefix longer than 32 is skipped', ['10.0.0.1', ['10.0.0.0/33', '10.0.0.0/8']], [True, 1]),
('network sample 13', ['10.0.0.300', ['10.0.0.0/33', '192.168.0.0/16', '10.1.2.3']], None),
('network sample 21', ['10.1.2.3', ['10.1.2.3', '192.168.1.0/24']], [True, 0]),
('network sample 51', ['255.255.255.255', ['10.1.2.3', '172.16.0.0/12', '8.8.8.0']], [False, -1])]]
for label, args, expected in fixtures[N - 1]:
check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| slash 24 matches inside the network | [True, 1] | [True, 1] | Passed |
| slash 0 matches everything | [True, 0] | [True, 0] | Passed |
| octet 256 in an entry is malformed | [True, 0] | [False, -1] | Failed |
| octet 255 is valid | [True, 0] | [True, 0] | Passed |
| bare address means host route | [False, -1] | [False, -1] | Passed |
| invalid ip returns None | [True, 0] | None | Failed |
| network sample 1 | [True, 2] | [True, 2] | Passed |
| network sample 2 | [False, -1] | [False, -1] | Passed |
SHA-256 / f5aabe810ec150d60ee38281d4241a2ee14d26491129f081c7579680e1ab977c
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(ip, cidrs):
def parse(s):
parts = s.split('.')
if len(parts) != 4 or not all(p.isdigit() and int(p) < 255 for p in parts):
return None
v = 0
for p in parts:
v = v * 256 + int(p)
return v
addr = parse(ip)
if addr is None:
return None
for i, c in enumerate(cidrs):
net, _, bits = c.partition('/')
bits = bits or '32'
base = parse(net)
if base is None or not bits.isdigit() or int(bits) > 32:
continue
n = int(bits)
mask = ((1 << n) - 1) << (32 - n)
if addr & mask == base & mask:
return [True, i]
return [False, -1]
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('slash 24 matches inside the network', ['10.1.2.3', ['192.168.0.0/16', '10.1.2.0/24']], [True, 1]),
('slash 0 matches everything', ['8.8.8.8', ['0.0.0.0/0']], [True, 0]),
('octet 256 in an entry is malformed', ['1.0.0.0', ['1.0.0.256/8']], [False, -1]),
('octet 255 is valid', ['192.168.0.255', ['192.168.0.255']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('invalid ip returns None', ['10.0.0.300', ['0.0.0.0/0']], None),
('network sample 1', ['10.1.2.0', ['8.8.8.0', '10.1.2.3/32', '10.0.0.0/8']], [True, 2]),
('network sample 2', ['8.8.8.8', ['10.1.2.3/32']], [False, -1])],
[('slash 0 matches everything', ['8.8.8.8', ['0.0.0.0/0']], [True, 0]),
('octet 256 in an entry is malformed', ['1.0.0.0', ['1.0.0.256/8']], [False, -1]),
('octet 255 is valid', ['192.168.0.255', ['192.168.0.255']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('entry with host bits still matches its network', ['10.1.2.9', ['10.1.2.77/24']], [True, 0]),
('invalid ip returns None', ['10.0.0.300', ['0.0.0.0/0']], None),
('network sample 34', ['10.0.0.300', ['10.0.0.0/8']], None),
('network sample 55', ['255.255.255.255', ['192.168.1.0/24', '0.0.0.0/0']], [True, 1])],
[('octet 256 in an entry is malformed', ['1.0.0.0', ['1.0.0.256/8']], [False, -1]),
('octet 255 is valid', ['192.168.0.255', ['192.168.0.255']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('entry with host bits still matches its network', ['10.1.2.9', ['10.1.2.77/24']], [True, 0]),
('network address itself matches', ['10.1.2.0', ['10.1.2.0/24']], [True, 0]),
('invalid ip returns None', ['10.0.0.300', ['0.0.0.0/0']], None),
('network sample 11', ['10.1.2.3', ['192.168.1.0/24']], [False, -1]),
('network sample 20', ['192.168.0.255', ['172.16.5.4/30', '192.168.1.0/24']], [False, -1])],
[('octet 255 is valid', ['192.168.0.255', ['192.168.0.255']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('entry with host bits still matches its network', ['10.1.2.9', ['10.1.2.77/24']], [True, 0]),
('network address itself matches', ['10.1.2.0', ['10.1.2.0/24']], [True, 0]),
('invalid ip returns None', ['10.0.0.300', ['0.0.0.0/0']], None),
('network sample 16', ['10.1.2.0', ['1.0.0.256/8']], [False, -1]),
('network sample 40', ['10.0.0.300', ['10.0.0.0/8', '10.1.2.0/24', '172.16.5.4/30']], None),
('network sample 60', ['255.255.255.255', ['10.0.0.0/33', '10.1.2.3/32', '10.1.2.77/24']], [False, -1])],
[('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('entry with host bits still matches its network', ['10.1.2.9', ['10.1.2.77/24']], [True, 0]),
('network address itself matches', ['10.1.2.0', ['10.1.2.0/24']], [True, 0]),
('invalid ip returns None', ['10.0.0.300', ['0.0.0.0/0']], None),
('prefix longer than 32 is skipped', ['10.0.0.1', ['10.0.0.0/33', '10.0.0.0/8']], [True, 1]),
('network sample 13', ['10.0.0.300', ['10.0.0.0/33', '192.168.0.0/16', '10.1.2.3']], None),
('network sample 21', ['10.1.2.3', ['10.1.2.3', '192.168.1.0/24']], [True, 0]),
('network sample 51', ['255.255.255.255', ['10.1.2.3', '172.16.0.0/12', '8.8.8.0']], [False, -1])]]
for label, args, expected in fixtures[N - 1]:
check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| slash 24 matches inside the network | [True, 1] | [True, 1] | Passed |
| slash 0 matches everything | [True, 0] | [True, 0] | Passed |
| octet 256 in an entry is malformed | [False, -1] | [False, -1] | Passed |
| octet 255 is valid | None | [True, 0] | Failed |
| bare address means host route | [False, -1] | [False, -1] | Passed |
| invalid ip returns None | None | None | Passed |
| network sample 1 | [True, 2] | [True, 2] | Passed |
| network sample 2 | [False, -1] | [False, -1] | Passed |
SHA-256 / 19e398f8dd7ee9d2d56294b7936c81cc388a9e083288b683a6dc394807fd6c82
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(ip, cidrs):
def parse(s):
parts = s.split('.')
if len(parts) != 4 or not all(p.isdigit() and int(p) <= 255 for p in parts):
return None
v = 0
for p in parts:
v = v * 256 + int(p)
return v
addr = parse(ip)
if addr is None:
return None
for i, c in enumerate(cidrs):
net, _, bits = c.partition('/')
bits = bits or '32'
base = parse(net)
if base is None or not bits.isdigit() or int(bits) > 32:
continue
n = int(bits)
mask = ((1 << n) - 1) << (32 - n)
if addr & mask == base & mask:
return [True, i]
return [False, -1]
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('slash 24 matches inside the network', ['10.1.2.3', ['192.168.0.0/16', '10.1.2.0/24']], [True, 1]),
('slash 0 matches everything', ['8.8.8.8', ['0.0.0.0/0']], [True, 0]),
('octet 256 in an entry is malformed', ['1.0.0.0', ['1.0.0.256/8']], [False, -1]),
('octet 255 is valid', ['192.168.0.255', ['192.168.0.255']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('invalid ip returns None', ['10.0.0.300', ['0.0.0.0/0']], None),
('network sample 1', ['10.1.2.0', ['8.8.8.0', '10.1.2.3/32', '10.0.0.0/8']], [True, 2]),
('network sample 2', ['8.8.8.8', ['10.1.2.3/32']], [False, -1])],
[('slash 0 matches everything', ['8.8.8.8', ['0.0.0.0/0']], [True, 0]),
('octet 256 in an entry is malformed', ['1.0.0.0', ['1.0.0.256/8']], [False, -1]),
('octet 255 is valid', ['192.168.0.255', ['192.168.0.255']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('entry with host bits still matches its network', ['10.1.2.9', ['10.1.2.77/24']], [True, 0]),
('invalid ip returns None', ['10.0.0.300', ['0.0.0.0/0']], None),
('network sample 34', ['10.0.0.300', ['10.0.0.0/8']], None),
('network sample 55', ['255.255.255.255', ['192.168.1.0/24', '0.0.0.0/0']], [True, 1])],
[('octet 256 in an entry is malformed', ['1.0.0.0', ['1.0.0.256/8']], [False, -1]),
('octet 255 is valid', ['192.168.0.255', ['192.168.0.255']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('entry with host bits still matches its network', ['10.1.2.9', ['10.1.2.77/24']], [True, 0]),
('network address itself matches', ['10.1.2.0', ['10.1.2.0/24']], [True, 0]),
('invalid ip returns None', ['10.0.0.300', ['0.0.0.0/0']], None),
('network sample 11', ['10.1.2.3', ['192.168.1.0/24']], [False, -1]),
('network sample 20', ['192.168.0.255', ['172.16.5.4/30', '192.168.1.0/24']], [False, -1])],
[('octet 255 is valid', ['192.168.0.255', ['192.168.0.255']], [True, 0]),
('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('entry with host bits still matches its network', ['10.1.2.9', ['10.1.2.77/24']], [True, 0]),
('network address itself matches', ['10.1.2.0', ['10.1.2.0/24']], [True, 0]),
('invalid ip returns None', ['10.0.0.300', ['0.0.0.0/0']], None),
('network sample 16', ['10.1.2.0', ['1.0.0.256/8']], [False, -1]),
('network sample 40', ['10.0.0.300', ['10.0.0.0/8', '10.1.2.0/24', '172.16.5.4/30']], None),
('network sample 60', ['255.255.255.255', ['10.0.0.0/33', '10.1.2.3/32', '10.1.2.77/24']], [False, -1])],
[('bare address means host route', ['10.1.2.4', ['10.1.2.3']], [False, -1]),
('entry with host bits still matches its network', ['10.1.2.9', ['10.1.2.77/24']], [True, 0]),
('network address itself matches', ['10.1.2.0', ['10.1.2.0/24']], [True, 0]),
('invalid ip returns None', ['10.0.0.300', ['0.0.0.0/0']], None),
('prefix longer than 32 is skipped', ['10.0.0.1', ['10.0.0.0/33', '10.0.0.0/8']], [True, 1]),
('network sample 13', ['10.0.0.300', ['10.0.0.0/33', '192.168.0.0/16', '10.1.2.3']], None),
('network sample 21', ['10.1.2.3', ['10.1.2.3', '192.168.1.0/24']], [True, 0]),
('network sample 51', ['255.255.255.255', ['10.1.2.3', '172.16.0.0/12', '8.8.8.0']], [False, -1])]]
for label, args, expected in fixtures[N - 1]:
check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| slash 24 matches inside the network | [True, 1] | [True, 1] | Passed |
| slash 0 matches everything | [True, 0] | [True, 0] | Passed |
| octet 256 in an entry is malformed | [False, -1] | [False, -1] | Passed |
| octet 255 is valid | [True, 0] | [True, 0] | Passed |
| bare address means host route | [False, -1] | [False, -1] | Passed |
| invalid ip returns None | None | None | Passed |
| network sample 1 | [True, 2] | [True, 2] | Passed |
| network sample 2 | [False, -1] | [False, -1] | Passed |
SHA-256 / f86d35d9c0b951f2f41ee1a5f38d68f7c7af146e90c8ecef897876d5cc89984b
Verification & scope
A deterministic toy flag-evaluation model with a stipulated contract; it does not reproduce any vendor SDK byte for byte. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:48:54.133796+00:00.
Case digest / 915b82e768bab4a84d9035481163226b0758a70062b6d6664ed825888674ede8