FAILURE MAP
← Case archive

FA-9781 / Configuration / Open access

Access policy decision combination: Disabled deny rules remain effective · case 01

Disabled deny rules remain effective.

Verified by executionVariant 1 · 8 checks per implementationDownload source bundle ↓JSON ↗

ROOT CAUSE

The implementation substitutes if True and for if enabled and, so disabled deny rules remain effective.

THE FAILURE

The implementation substitutes if True and for if enabled and, so disabled deny rules remain effective.

Unsuccessful approach: The attempted repair substitutes if not enabled and. Fixture 3 still yields False instead of True.

Case contract

Return deny if any applicable explicit deny, allow if at least one applicable allow, otherwise the provided default. Ignore disabled and nonmatching rules. Unknown effects do not grant access.

Why this case matters

An offline model of access policy decision combination, suitable for testing build and release tooling without external services.

1 / The failure

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(rules, resource, default):
    effects = [effect for pattern, effect, enabled in rules if True and pattern in [resource, '*']]
    if 'deny' in effects: return False
    if 'allow' in effects: return True
    return default
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('fixture 1', solve([], 'a', False), False)
check('fixture 2', solve([], 'a', True), True)
check('fixture 3', solve([('a', 'allow', True)], 'a', False), True)
check('fixture 4', solve([('a', 'deny', True), ('a', 'allow', True)], 'a', True), False)
check('fixture 5', solve([('a', 'deny', False)], 'a', True), True)
check('fixture 6', solve([('b', 'allow', True)], 'a', False), False)
check('fixture 7', solve([('*', 'allow', True)], 'a', False), True)
check('fixture 8', solve([('a', 'unknown', True)], 'a', False), False)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
fixture 1FalseFalsePassed
fixture 2TrueTruePassed
fixture 3TrueTruePassed
fixture 4FalseFalsePassed
fixture 5FalseTrueFailed
fixture 6FalseFalsePassed
fixture 7TrueTruePassed
fixture 8FalseFalsePassed

SHA-256 / 1fdb9bc38b7d87b532893b2e4f52b9a9dd67e49da21bc190f23337c288dc8db8

2 / The unsuccessful fix

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(rules, resource, default):
    effects = [effect for pattern, effect, enabled in rules if not enabled and pattern in [resource, '*']]
    if 'deny' in effects: return False
    if 'allow' in effects: return True
    return default
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('fixture 1', solve([], 'a', False), False)
check('fixture 2', solve([], 'a', True), True)
check('fixture 3', solve([('a', 'allow', True)], 'a', False), True)
check('fixture 4', solve([('a', 'deny', True), ('a', 'allow', True)], 'a', True), False)
check('fixture 5', solve([('a', 'deny', False)], 'a', True), True)
check('fixture 6', solve([('b', 'allow', True)], 'a', False), False)
check('fixture 7', solve([('*', 'allow', True)], 'a', False), True)
check('fixture 8', solve([('a', 'unknown', True)], 'a', False), False)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
fixture 1FalseFalsePassed
fixture 2TrueTruePassed
fixture 3FalseTrueFailed
fixture 4TrueFalseFailed
fixture 5FalseTrueFailed
fixture 6FalseFalsePassed
fixture 7FalseTrueFailed
fixture 8FalseFalsePassed

SHA-256 / 2d397ac8e1697ce39ebc5294ed91a769d68fa3bbe4c4c1d27c12077d3527933c

HELD IN THE MEMBER ARCHIVE

The verified repair and its recorded checks are member-only.

This mechanism has 8 recorded checks per implementation. The open-access tier publishes the failure and the unsuccessful fix; the repaired source that passes every check, and the observations that prove it, are available to members.

Every case sharing this mechanism uses the same contract and the same repair, so this one record is held back for all of them.

Member access is invitation-based. Sign in with your invited account to inspect the repair.

Sign in to the archive ↗

Verification & scope

This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.

Observations recorded using Python 3.12.14 at 2026-09-29T14:38:33.242105+00:00.

Case digest / 3a9f4a444bbd3c4dd24187cf33e0b3bce9680786899589e0f663f87b1830d563