FA-74316 / Feature flag rollout bucketing / Open access
Seeded weighted rollout: Sixteen hex digits overflow the unit interval · case 01
Nearly every user gets a bucket far above 1 and falls into the last variation.
ROOT CAUSE
Sixteen hex digits are parsed but divided by the fifteen-digit maximum.
VERIFIED REPAIR
Parse fifteen hex digits and divide by 0xFFFFFFFFFFFFFFF.
Unsuccessful approach: Restoring fifteen digits but dividing by the 64-bit maximum squeezes every bucket toward zero.
Case contract
Hash text is (str(seed) if seed is not None else flag_key + "." + salt) + "." + ident, plus "." + secondary when secondary is not None (an empty string still counts). bucket = int(first 15 hex digits of sha1(text), 16) / 0xFFFFFFFFFFFFFFF. weights are in 1/100000 units; return the first index whose cumulative weight / 100000 exceeds the bucket, else the last index, as [index, round(bucket, 6)].
Why this case matters
Seeds let several flags share one bucketing so a cohort sees consistent variations.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import hashlib
N = 1
observations = []
def solve(flag_key, salt, ident, secondary, seed, weights):
prefix = str(seed) if seed is not None else flag_key + '.' + salt
text = prefix + '.' + ident
if secondary is not None:
text += '.' + secondary
bucket = int(hashlib.sha1(text.encode()).hexdigest()[:16], 16) / float(0xFFFFFFFFFFFFFFF)
acc = 0
for index, w in enumerate(weights):
acc += w
if bucket < acc / 100000.0:
return [index, round(bucket, 6)]
return [len(weights) - 1, round(bucket, 6)]
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('seed zero is a real seed', ['flag-a', 's', 'id1', None, 0, [50000, 50000]], [0, 0.331393]),
('seed replaces flag key and salt', ['flag-b', 's', 'id2', None, 7, [30000, 70000]], [1, 0.855827]),
('empty secondary is still appended', ['flag-a', 's', 'id3', '', None, [50000, 50000]], [1, 0.891663]),
('non-empty secondary', ['flag-a', 's', 'id4', 'eu', None, [10000, 90000]], [1, 0.975219]),
('weights short of total go to last index',
['flag-b', 'salt2', 'id5', None, None, [10000, 10000]],
[1, 0.233147]),
('zero-weight first variation', ['flag-b', 's', 'id6', None, None, [0, 100000]], [1, 0.255084]),
('rollout sample 1', ['flag-b', 'salt2', 'id120', '', 0, [0, 60000, 40000]], [2, 0.88242]),
('rollout sample 2', ['flag-b', 's', 'id212', 'x', 61, [25000, 25000, 25000]], [1, 0.37423])],
[('seed replaces flag key and salt', ['flag-b', 's', 'id2', None, 7, [30000, 70000]], [1, 0.855827]),
('empty secondary is still appended', ['flag-a', 's', 'id3', '', None, [50000, 50000]], [1, 0.891663]),
('non-empty secondary', ['flag-a', 's', 'id4', 'eu', None, [10000, 90000]], [1, 0.975219]),
('weights short of total go to last index',
['flag-b', 'salt2', 'id5', None, None, [10000, 10000]],
[1, 0.233147]),
('zero-weight first variation', ['flag-b', 's', 'id6', None, None, [0, 100000]], [1, 0.255084]),
('rollout sample 2', ['flag-b', 's', 'id212', 'x', 61, [25000, 25000, 25000]], [1, 0.37423]),
('rollout sample 6', ['flag-b', 'salt2', 'id765', None, 7, [10000, 20000, 70000]], [2, 0.464498]),
('rollout sample 7', ['flag-a', 's', 'id556', None, None, [30000, 30000]], [1, 0.522407])],
[('seed zero is a real seed', ['flag-a', 's', 'id1', None, 0, [50000, 50000]], [0, 0.331393]),
('empty secondary is still appended', ['flag-a', 's', 'id3', '', None, [50000, 50000]], [1, 0.891663]),
('non-empty secondary', ['flag-a', 's', 'id4', 'eu', None, [10000, 90000]], [1, 0.975219]),
('weights short of total go to last index',
['flag-b', 'salt2', 'id5', None, None, [10000, 10000]],
[1, 0.233147]),
('zero-weight first variation', ['flag-b', 's', 'id6', None, None, [0, 100000]], [1, 0.255084]),
('rollout sample 9', ['flag-a', 's', 'id324', 'eu', 7, [10000, 20000, 70000]], [2, 0.936832]),
('rollout sample 11', ['flag-a', 'salt2', 'id773', '', 7, [0, 60000, 40000]], [1, 0.477906]),
('rollout sample 12', ['flag-b', 'salt2', 'id724', '', None, [0, 60000, 40000]], [1, 0.353275])],
[('seed zero is a real seed', ['flag-a', 's', 'id1', None, 0, [50000, 50000]], [0, 0.331393]),
('seed replaces flag key and salt', ['flag-b', 's', 'id2', None, 7, [30000, 70000]], [1, 0.855827]),
('non-empty secondary', ['flag-a', 's', 'id4', 'eu', None, [10000, 90000]], [1, 0.975219]),
('weights short of total go to last index',
['flag-b', 'salt2', 'id5', None, None, [10000, 10000]],
[1, 0.233147]),
('zero-weight first variation', ['flag-b', 's', 'id6', None, None, [0, 100000]], [1, 0.255084]),
('rollout sample 16', ['flag-b', 'salt2', 'id229', 'eu', 61, [10000, 20000, 70000]], [2, 0.315757]),
('rollout sample 17', ['flag-b', 's', 'id105', None, None, [0, 60000, 40000]], [2, 0.791823]),
('rollout sample 18', ['flag-b', 's', 'id67', '', None, [99999]], [0, 0.488251])],
[('seed zero is a real seed', ['flag-a', 's', 'id1', None, 0, [50000, 50000]], [0, 0.331393]),
('seed replaces flag key and salt', ['flag-b', 's', 'id2', None, 7, [30000, 70000]], [1, 0.855827]),
('empty secondary is still appended', ['flag-a', 's', 'id3', '', None, [50000, 50000]], [1, 0.891663]),
('weights short of total go to last index',
['flag-b', 'salt2', 'id5', None, None, [10000, 10000]],
[1, 0.233147]),
('zero-weight first variation', ['flag-b', 's', 'id6', None, None, [0, 100000]], [1, 0.255084]),
('rollout sample 21', ['flag-a', 'salt2', 'id352', '', None, [99999]], [0, 0.94531]),
('rollout sample 22', ['flag-a', 'salt2', 'id349', '', 0, [50000, 50000]], [0, 0.298678]),
('rollout sample 23', ['flag-b', 's', 'id120', None, 61, [99999]], [0, 0.42147])]]
for label, args, expected in fixtures[N - 1]:
check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| seed zero is a real seed | [1, 5.302286] | [0, 0.331393] | Failed |
| seed replaces flag key and salt | [1, 13.693229] | [1, 0.855827] | Failed |
| empty secondary is still appended | [1, 14.266614] | [1, 0.891663] | Failed |
| non-empty secondary | [1, 15.603502] | [1, 0.975219] | Failed |
| weights short of total go to last index | [1, 3.730357] | [1, 0.233147] | Failed |
| zero-weight first variation | [1, 4.081349] | [1, 0.255084] | Failed |
| rollout sample 1 | [2, 14.118714] | [2, 0.88242] | Failed |
| rollout sample 2 | [2, 5.987677] | [1, 0.37423] | Failed |
SHA-256 / 373c4efd37de5bdaafab834ae35b9c348b066a43a7d50f22a6dbf411f9981adb
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import hashlib
N = 1
observations = []
def solve(flag_key, salt, ident, secondary, seed, weights):
prefix = str(seed) if seed is not None else flag_key + '.' + salt
text = prefix + '.' + ident
if secondary is not None:
text += '.' + secondary
bucket = int(hashlib.sha1(text.encode()).hexdigest()[:15], 16) / float(0xFFFFFFFFFFFFFFFF)
acc = 0
for index, w in enumerate(weights):
acc += w
if bucket < acc / 100000.0:
return [index, round(bucket, 6)]
return [len(weights) - 1, round(bucket, 6)]
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('seed zero is a real seed', ['flag-a', 's', 'id1', None, 0, [50000, 50000]], [0, 0.331393]),
('seed replaces flag key and salt', ['flag-b', 's', 'id2', None, 7, [30000, 70000]], [1, 0.855827]),
('empty secondary is still appended', ['flag-a', 's', 'id3', '', None, [50000, 50000]], [1, 0.891663]),
('non-empty secondary', ['flag-a', 's', 'id4', 'eu', None, [10000, 90000]], [1, 0.975219]),
('weights short of total go to last index',
['flag-b', 'salt2', 'id5', None, None, [10000, 10000]],
[1, 0.233147]),
('zero-weight first variation', ['flag-b', 's', 'id6', None, None, [0, 100000]], [1, 0.255084]),
('rollout sample 1', ['flag-b', 'salt2', 'id120', '', 0, [0, 60000, 40000]], [2, 0.88242]),
('rollout sample 2', ['flag-b', 's', 'id212', 'x', 61, [25000, 25000, 25000]], [1, 0.37423])],
[('seed replaces flag key and salt', ['flag-b', 's', 'id2', None, 7, [30000, 70000]], [1, 0.855827]),
('empty secondary is still appended', ['flag-a', 's', 'id3', '', None, [50000, 50000]], [1, 0.891663]),
('non-empty secondary', ['flag-a', 's', 'id4', 'eu', None, [10000, 90000]], [1, 0.975219]),
('weights short of total go to last index',
['flag-b', 'salt2', 'id5', None, None, [10000, 10000]],
[1, 0.233147]),
('zero-weight first variation', ['flag-b', 's', 'id6', None, None, [0, 100000]], [1, 0.255084]),
('rollout sample 2', ['flag-b', 's', 'id212', 'x', 61, [25000, 25000, 25000]], [1, 0.37423]),
('rollout sample 6', ['flag-b', 'salt2', 'id765', None, 7, [10000, 20000, 70000]], [2, 0.464498]),
('rollout sample 7', ['flag-a', 's', 'id556', None, None, [30000, 30000]], [1, 0.522407])],
[('seed zero is a real seed', ['flag-a', 's', 'id1', None, 0, [50000, 50000]], [0, 0.331393]),
('empty secondary is still appended', ['flag-a', 's', 'id3', '', None, [50000, 50000]], [1, 0.891663]),
('non-empty secondary', ['flag-a', 's', 'id4', 'eu', None, [10000, 90000]], [1, 0.975219]),
('weights short of total go to last index',
['flag-b', 'salt2', 'id5', None, None, [10000, 10000]],
[1, 0.233147]),
('zero-weight first variation', ['flag-b', 's', 'id6', None, None, [0, 100000]], [1, 0.255084]),
('rollout sample 9', ['flag-a', 's', 'id324', 'eu', 7, [10000, 20000, 70000]], [2, 0.936832]),
('rollout sample 11', ['flag-a', 'salt2', 'id773', '', 7, [0, 60000, 40000]], [1, 0.477906]),
('rollout sample 12', ['flag-b', 'salt2', 'id724', '', None, [0, 60000, 40000]], [1, 0.353275])],
[('seed zero is a real seed', ['flag-a', 's', 'id1', None, 0, [50000, 50000]], [0, 0.331393]),
('seed replaces flag key and salt', ['flag-b', 's', 'id2', None, 7, [30000, 70000]], [1, 0.855827]),
('non-empty secondary', ['flag-a', 's', 'id4', 'eu', None, [10000, 90000]], [1, 0.975219]),
('weights short of total go to last index',
['flag-b', 'salt2', 'id5', None, None, [10000, 10000]],
[1, 0.233147]),
('zero-weight first variation', ['flag-b', 's', 'id6', None, None, [0, 100000]], [1, 0.255084]),
('rollout sample 16', ['flag-b', 'salt2', 'id229', 'eu', 61, [10000, 20000, 70000]], [2, 0.315757]),
('rollout sample 17', ['flag-b', 's', 'id105', None, None, [0, 60000, 40000]], [2, 0.791823]),
('rollout sample 18', ['flag-b', 's', 'id67', '', None, [99999]], [0, 0.488251])],
[('seed zero is a real seed', ['flag-a', 's', 'id1', None, 0, [50000, 50000]], [0, 0.331393]),
('seed replaces flag key and salt', ['flag-b', 's', 'id2', None, 7, [30000, 70000]], [1, 0.855827]),
('empty secondary is still appended', ['flag-a', 's', 'id3', '', None, [50000, 50000]], [1, 0.891663]),
('weights short of total go to last index',
['flag-b', 'salt2', 'id5', None, None, [10000, 10000]],
[1, 0.233147]),
('zero-weight first variation', ['flag-b', 's', 'id6', None, None, [0, 100000]], [1, 0.255084]),
('rollout sample 21', ['flag-a', 'salt2', 'id352', '', None, [99999]], [0, 0.94531]),
('rollout sample 22', ['flag-a', 'salt2', 'id349', '', 0, [50000, 50000]], [0, 0.298678]),
('rollout sample 23', ['flag-b', 's', 'id120', None, 61, [99999]], [0, 0.42147])]]
for label, args, expected in fixtures[N - 1]:
check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| seed zero is a real seed | [0, 0.020712] | [0, 0.331393] | Failed |
| seed replaces flag key and salt | [0, 0.053489] | [1, 0.855827] | Failed |
| empty secondary is still appended | [0, 0.055729] | [1, 0.891663] | Failed |
| non-empty secondary | [0, 0.060951] | [1, 0.975219] | Failed |
| weights short of total go to last index | [0, 0.014572] | [1, 0.233147] | Failed |
| zero-weight first variation | [1, 0.015943] | [1, 0.255084] | Failed |
| rollout sample 1 | [1, 0.055151] | [2, 0.88242] | Failed |
| rollout sample 2 | [0, 0.023389] | [1, 0.37423] | Failed |
SHA-256 / c82a1b15e780e0daf11fff079df66f5c0058e2353b6dc4b8db0f2b42739905c8
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
import hashlib
N = 1
observations = []
def solve(flag_key, salt, ident, secondary, seed, weights):
prefix = str(seed) if seed is not None else flag_key + '.' + salt
text = prefix + '.' + ident
if secondary is not None:
text += '.' + secondary
bucket = int(hashlib.sha1(text.encode()).hexdigest()[:15], 16) / float(0xFFFFFFFFFFFFFFF)
acc = 0
for index, w in enumerate(weights):
acc += w
if bucket < acc / 100000.0:
return [index, round(bucket, 6)]
return [len(weights) - 1, round(bucket, 6)]
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('seed zero is a real seed', ['flag-a', 's', 'id1', None, 0, [50000, 50000]], [0, 0.331393]),
('seed replaces flag key and salt', ['flag-b', 's', 'id2', None, 7, [30000, 70000]], [1, 0.855827]),
('empty secondary is still appended', ['flag-a', 's', 'id3', '', None, [50000, 50000]], [1, 0.891663]),
('non-empty secondary', ['flag-a', 's', 'id4', 'eu', None, [10000, 90000]], [1, 0.975219]),
('weights short of total go to last index',
['flag-b', 'salt2', 'id5', None, None, [10000, 10000]],
[1, 0.233147]),
('zero-weight first variation', ['flag-b', 's', 'id6', None, None, [0, 100000]], [1, 0.255084]),
('rollout sample 1', ['flag-b', 'salt2', 'id120', '', 0, [0, 60000, 40000]], [2, 0.88242]),
('rollout sample 2', ['flag-b', 's', 'id212', 'x', 61, [25000, 25000, 25000]], [1, 0.37423])],
[('seed replaces flag key and salt', ['flag-b', 's', 'id2', None, 7, [30000, 70000]], [1, 0.855827]),
('empty secondary is still appended', ['flag-a', 's', 'id3', '', None, [50000, 50000]], [1, 0.891663]),
('non-empty secondary', ['flag-a', 's', 'id4', 'eu', None, [10000, 90000]], [1, 0.975219]),
('weights short of total go to last index',
['flag-b', 'salt2', 'id5', None, None, [10000, 10000]],
[1, 0.233147]),
('zero-weight first variation', ['flag-b', 's', 'id6', None, None, [0, 100000]], [1, 0.255084]),
('rollout sample 2', ['flag-b', 's', 'id212', 'x', 61, [25000, 25000, 25000]], [1, 0.37423]),
('rollout sample 6', ['flag-b', 'salt2', 'id765', None, 7, [10000, 20000, 70000]], [2, 0.464498]),
('rollout sample 7', ['flag-a', 's', 'id556', None, None, [30000, 30000]], [1, 0.522407])],
[('seed zero is a real seed', ['flag-a', 's', 'id1', None, 0, [50000, 50000]], [0, 0.331393]),
('empty secondary is still appended', ['flag-a', 's', 'id3', '', None, [50000, 50000]], [1, 0.891663]),
('non-empty secondary', ['flag-a', 's', 'id4', 'eu', None, [10000, 90000]], [1, 0.975219]),
('weights short of total go to last index',
['flag-b', 'salt2', 'id5', None, None, [10000, 10000]],
[1, 0.233147]),
('zero-weight first variation', ['flag-b', 's', 'id6', None, None, [0, 100000]], [1, 0.255084]),
('rollout sample 9', ['flag-a', 's', 'id324', 'eu', 7, [10000, 20000, 70000]], [2, 0.936832]),
('rollout sample 11', ['flag-a', 'salt2', 'id773', '', 7, [0, 60000, 40000]], [1, 0.477906]),
('rollout sample 12', ['flag-b', 'salt2', 'id724', '', None, [0, 60000, 40000]], [1, 0.353275])],
[('seed zero is a real seed', ['flag-a', 's', 'id1', None, 0, [50000, 50000]], [0, 0.331393]),
('seed replaces flag key and salt', ['flag-b', 's', 'id2', None, 7, [30000, 70000]], [1, 0.855827]),
('non-empty secondary', ['flag-a', 's', 'id4', 'eu', None, [10000, 90000]], [1, 0.975219]),
('weights short of total go to last index',
['flag-b', 'salt2', 'id5', None, None, [10000, 10000]],
[1, 0.233147]),
('zero-weight first variation', ['flag-b', 's', 'id6', None, None, [0, 100000]], [1, 0.255084]),
('rollout sample 16', ['flag-b', 'salt2', 'id229', 'eu', 61, [10000, 20000, 70000]], [2, 0.315757]),
('rollout sample 17', ['flag-b', 's', 'id105', None, None, [0, 60000, 40000]], [2, 0.791823]),
('rollout sample 18', ['flag-b', 's', 'id67', '', None, [99999]], [0, 0.488251])],
[('seed zero is a real seed', ['flag-a', 's', 'id1', None, 0, [50000, 50000]], [0, 0.331393]),
('seed replaces flag key and salt', ['flag-b', 's', 'id2', None, 7, [30000, 70000]], [1, 0.855827]),
('empty secondary is still appended', ['flag-a', 's', 'id3', '', None, [50000, 50000]], [1, 0.891663]),
('weights short of total go to last index',
['flag-b', 'salt2', 'id5', None, None, [10000, 10000]],
[1, 0.233147]),
('zero-weight first variation', ['flag-b', 's', 'id6', None, None, [0, 100000]], [1, 0.255084]),
('rollout sample 21', ['flag-a', 'salt2', 'id352', '', None, [99999]], [0, 0.94531]),
('rollout sample 22', ['flag-a', 'salt2', 'id349', '', 0, [50000, 50000]], [0, 0.298678]),
('rollout sample 23', ['flag-b', 's', 'id120', None, 61, [99999]], [0, 0.42147])]]
for label, args, expected in fixtures[N - 1]:
check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| seed zero is a real seed | [0, 0.331393] | [0, 0.331393] | Passed |
| seed replaces flag key and salt | [1, 0.855827] | [1, 0.855827] | Passed |
| empty secondary is still appended | [1, 0.891663] | [1, 0.891663] | Passed |
| non-empty secondary | [1, 0.975219] | [1, 0.975219] | Passed |
| weights short of total go to last index | [1, 0.233147] | [1, 0.233147] | Passed |
| zero-weight first variation | [1, 0.255084] | [1, 0.255084] | Passed |
| rollout sample 1 | [2, 0.88242] | [2, 0.88242] | Passed |
| rollout sample 2 | [1, 0.37423] | [1, 0.37423] | Passed |
SHA-256 / e5a286b896d35d2278861cccfb1701c588d8b6ad1a4189f77b4a6b780953395d
Verification & scope
A deterministic toy flag-evaluation model with a stipulated contract; it does not reproduce any vendor SDK byte for byte. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:48:55.514527+00:00.
Case digest / f37018b2b28bfadb64b5344db716177b7e4a5171eff5640b51bd969673450b1a