FAILURE MAP
← Case archive

FA-9796 / Configuration / Open access

Access policy decision combination: Unknown effects grant access · case 01

Unknown effects grant access.

Verified by executionVariant 1 · 8 checks per implementationDownload source bundle ↓JSON ↗

ROOT CAUSE

The implementation substitutes if effects: return True for if 'allow' in effects: return True, so unknown effects grant access.

VERIFIED REPAIR

Require an explicit applicable allow.

Unsuccessful approach: The attempted repair substitutes if 'deny' not in effects: return True. Fixture 1 still yields True instead of False.

Case contract

Return deny if any applicable explicit deny, allow if at least one applicable allow, otherwise the provided default. Ignore disabled and nonmatching rules. Unknown effects do not grant access.

Why this case matters

An offline model of access policy decision combination, suitable for testing build and release tooling without external services.

1 / The failure

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(rules, resource, default):
    effects = [effect for pattern, effect, enabled in rules if enabled and pattern in [resource, '*']]
    if 'deny' in effects: return False
    if effects: return True
    return default
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('fixture 1', solve([], 'a', False), False)
check('fixture 2', solve([], 'a', True), True)
check('fixture 3', solve([('a', 'allow', True)], 'a', False), True)
check('fixture 4', solve([('a', 'deny', True), ('a', 'allow', True)], 'a', True), False)
check('fixture 5', solve([('a', 'deny', False)], 'a', True), True)
check('fixture 6', solve([('b', 'allow', True)], 'a', False), False)
check('fixture 7', solve([('*', 'allow', True)], 'a', False), True)
check('fixture 8', solve([('a', 'unknown', True)], 'a', False), False)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
fixture 1FalseFalsePassed
fixture 2TrueTruePassed
fixture 3TrueTruePassed
fixture 4FalseFalsePassed
fixture 5TrueTruePassed
fixture 6FalseFalsePassed
fixture 7TrueTruePassed
fixture 8TrueFalseFailed

SHA-256 / 3053362eef7036d5a7f92576b8ee7145b6ce413c91ee93f42e09c7dd6f13d691

2 / The unsuccessful fix

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(rules, resource, default):
    effects = [effect for pattern, effect, enabled in rules if enabled and pattern in [resource, '*']]
    if 'deny' in effects: return False
    if 'deny' not in effects: return True
    return default
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('fixture 1', solve([], 'a', False), False)
check('fixture 2', solve([], 'a', True), True)
check('fixture 3', solve([('a', 'allow', True)], 'a', False), True)
check('fixture 4', solve([('a', 'deny', True), ('a', 'allow', True)], 'a', True), False)
check('fixture 5', solve([('a', 'deny', False)], 'a', True), True)
check('fixture 6', solve([('b', 'allow', True)], 'a', False), False)
check('fixture 7', solve([('*', 'allow', True)], 'a', False), True)
check('fixture 8', solve([('a', 'unknown', True)], 'a', False), False)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
fixture 1TrueFalseFailed
fixture 2TrueTruePassed
fixture 3TrueTruePassed
fixture 4FalseFalsePassed
fixture 5TrueTruePassed
fixture 6TrueFalseFailed
fixture 7TrueTruePassed
fixture 8TrueFalseFailed

SHA-256 / e28324e325ad0ebe0d00703e55fc69c6853d17969747102058536a668820cb7e

3 / The verified repair

Exit 0
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(rules, resource, default):
    effects = [effect for pattern, effect, enabled in rules if enabled and pattern in [resource, '*']]
    if 'deny' in effects: return False
    if 'allow' in effects: return True
    return default
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('fixture 1', solve([], 'a', False), False)
check('fixture 2', solve([], 'a', True), True)
check('fixture 3', solve([('a', 'allow', True)], 'a', False), True)
check('fixture 4', solve([('a', 'deny', True), ('a', 'allow', True)], 'a', True), False)
check('fixture 5', solve([('a', 'deny', False)], 'a', True), True)
check('fixture 6', solve([('b', 'allow', True)], 'a', False), False)
check('fixture 7', solve([('*', 'allow', True)], 'a', False), True)
check('fixture 8', solve([('a', 'unknown', True)], 'a', False), False)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
fixture 1FalseFalsePassed
fixture 2TrueTruePassed
fixture 3TrueTruePassed
fixture 4FalseFalsePassed
fixture 5TrueTruePassed
fixture 6FalseFalsePassed
fixture 7TrueTruePassed
fixture 8FalseFalsePassed

SHA-256 / 0f3886ac8993dc06cf67098e74d07e6725a84047428149241f03533f9290d603

Verification & scope

This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.

Observations recorded using Python 3.12.14 at 2026-09-29T14:38:33.162056+00:00.

Case digest / 2d865603301f211d3214f41912746549e0f48235f0ea963addad4def1a825b0f