FA-9781 / Configuration / Open access
Access policy decision combination: Disabled deny rules remain effective · case 01
Disabled deny rules remain effective.
ROOT CAUSE
The implementation substitutes if True and for if enabled and, so disabled deny rules remain effective.
THE FAILURE
The implementation substitutes if True and for if enabled and, so disabled deny rules remain effective.
Unsuccessful approach: The attempted repair substitutes if not enabled and. Fixture 3 still yields False instead of True.
Case contract
Return deny if any applicable explicit deny, allow if at least one applicable allow, otherwise the provided default. Ignore disabled and nonmatching rules. Unknown effects do not grant access.
Why this case matters
An offline model of access policy decision combination, suitable for testing build and release tooling without external services.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(rules, resource, default):
effects = [effect for pattern, effect, enabled in rules if True and pattern in [resource, '*']]
if 'deny' in effects: return False
if 'allow' in effects: return True
return default
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('fixture 1', solve([], 'a', False), False)
check('fixture 2', solve([], 'a', True), True)
check('fixture 3', solve([('a', 'allow', True)], 'a', False), True)
check('fixture 4', solve([('a', 'deny', True), ('a', 'allow', True)], 'a', True), False)
check('fixture 5', solve([('a', 'deny', False)], 'a', True), True)
check('fixture 6', solve([('b', 'allow', True)], 'a', False), False)
check('fixture 7', solve([('*', 'allow', True)], 'a', False), True)
check('fixture 8', solve([('a', 'unknown', True)], 'a', False), False)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| fixture 1 | False | False | Passed |
| fixture 2 | True | True | Passed |
| fixture 3 | True | True | Passed |
| fixture 4 | False | False | Passed |
| fixture 5 | False | True | Failed |
| fixture 6 | False | False | Passed |
| fixture 7 | True | True | Passed |
| fixture 8 | False | False | Passed |
SHA-256 / 1fdb9bc38b7d87b532893b2e4f52b9a9dd67e49da21bc190f23337c288dc8db8
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(rules, resource, default):
effects = [effect for pattern, effect, enabled in rules if not enabled and pattern in [resource, '*']]
if 'deny' in effects: return False
if 'allow' in effects: return True
return default
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('fixture 1', solve([], 'a', False), False)
check('fixture 2', solve([], 'a', True), True)
check('fixture 3', solve([('a', 'allow', True)], 'a', False), True)
check('fixture 4', solve([('a', 'deny', True), ('a', 'allow', True)], 'a', True), False)
check('fixture 5', solve([('a', 'deny', False)], 'a', True), True)
check('fixture 6', solve([('b', 'allow', True)], 'a', False), False)
check('fixture 7', solve([('*', 'allow', True)], 'a', False), True)
check('fixture 8', solve([('a', 'unknown', True)], 'a', False), False)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| fixture 1 | False | False | Passed |
| fixture 2 | True | True | Passed |
| fixture 3 | False | True | Failed |
| fixture 4 | True | False | Failed |
| fixture 5 | False | True | Failed |
| fixture 6 | False | False | Passed |
| fixture 7 | False | True | Failed |
| fixture 8 | False | False | Passed |
SHA-256 / 2d397ac8e1697ce39ebc5294ed91a769d68fa3bbe4c4c1d27c12077d3527933c
HELD IN THE MEMBER ARCHIVE
The verified repair and its recorded checks are member-only.
This mechanism has 8 recorded checks per implementation. The open-access tier publishes the failure and the unsuccessful fix; the repaired source that passes every check, and the observations that prove it, are available to members.
Every case sharing this mechanism uses the same contract and the same repair, so this one record is held back for all of them.
Member access is invitation-based. Sign in with your invited account to inspect the repair.
Sign in to the archive ↗Verification & scope
This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:38:33.242105+00:00.
Case digest / 3a9f4a444bbd3c4dd24187cf33e0b3bce9680786899589e0f663f87b1830d563