FAILURE MAP
← Case archive

FA-74170 / Feature flag rollout bucketing / Member archive

Network allowlist clause: A bare address allows every source · case 05

Listing a single office IP without "/32" opens the feature to the whole internet.

Member previewVariant 5 · 3 implementations · 8 checks per implementation

Case contract

ip is dotted-quad IPv4 with octets 0..255 (else return None). Each cidr is "a.b.c.d/n" with 0 <= n <= 32, or a bare address meaning /32; malformed entries are skipped. An entry matches when the top n bits of ip and of its address agree (host bits of the entry are ignored). Return [True, index of first match] or [False, -1].

Why this case matters

Office and VPN allowlists gate internal features by source network.

One recorded failure

Sample boundary fixture

This sample comes from the broken implementation of a controlled reproducer.

Boundary fixtureActualExpectedOutcome
bare address means host route[true, 0][false, -1]Failed

MEMBER ARCHIVE

The complete case is available to members.

This record includes three runnable implementations, regression fixtures, execution results, and source hashes.

Member access is invitation-based. Sign in with your invited account to inspect the sources.

Sign in to the archive ↗