FA-9981 / Packaging / Open access
Package publication plan: An unrelated published version blocks a new release · case 01
An unrelated published version blocks a new release.
ROOT CAUSE
The implementation substitutes if existing: version = next(iter(existing)) for if version in existing:, so an unrelated published version blocks a new release.
VERIFIED REPAIR
Look up only the exact version being published.
Unsuccessful approach: The attempted repair substitutes if version not in existing and existing: version = next(iter(existing)). Fixture 2 still yields 'missing-attestation' instead of 'skip'.
Case contract
Reject an immutable version with changed digest; skip equal published digests; reject missing attestations; reject private packages on public registries; otherwise publish. Existing equality takes precedence over publication checks.
Why this case matters
An offline model of package publication plan, suitable for testing build and release tooling without external services.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(version, digest, existing, attested, private, registry):
if existing:
version = next(iter(existing))
if existing[version] == digest: return 'skip'
return 'immutable-conflict'
if not attested: return 'missing-attestation'
if private and registry == 'public': return 'private-package'
return 'publish'
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('fixture 1', solve('1', 'a', {}, True, False, 'public'), 'publish')
check('fixture 2', solve('1', 'a', {'1': 'a'}, False, True, 'public'), 'skip')
check('fixture 3', solve('1', 'a', {'1': 'b'}, True, False, 'public'), 'immutable-conflict')
check('fixture 4', solve('1', 'a', {}, False, False, 'public'), 'missing-attestation')
check('fixture 5', solve('1', 'a', {}, True, True, 'public'), 'private-package')
check('fixture 6', solve('1', 'a', {}, True, True, 'private'), 'publish')
check('fixture 7', solve('2', 'a', {'1': 'b'}, True, False, 'public'), 'publish')
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| fixture 1 | publish | publish | Passed |
| fixture 2 | skip | skip | Passed |
| fixture 3 | immutable-conflict | immutable-conflict | Passed |
| fixture 4 | missing-attestation | missing-attestation | Passed |
| fixture 5 | private-package | private-package | Passed |
| fixture 6 | publish | publish | Passed |
| fixture 7 | immutable-conflict | publish | Failed |
SHA-256 / e82fe1fc952e9b15de74f44d37936de18939eebfd17161f263857d0e4e4f8d96
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(version, digest, existing, attested, private, registry):
if version not in existing and existing:
version = next(iter(existing))
if existing[version] == digest: return 'skip'
return 'immutable-conflict'
if not attested: return 'missing-attestation'
if private and registry == 'public': return 'private-package'
return 'publish'
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('fixture 1', solve('1', 'a', {}, True, False, 'public'), 'publish')
check('fixture 2', solve('1', 'a', {'1': 'a'}, False, True, 'public'), 'skip')
check('fixture 3', solve('1', 'a', {'1': 'b'}, True, False, 'public'), 'immutable-conflict')
check('fixture 4', solve('1', 'a', {}, False, False, 'public'), 'missing-attestation')
check('fixture 5', solve('1', 'a', {}, True, True, 'public'), 'private-package')
check('fixture 6', solve('1', 'a', {}, True, True, 'private'), 'publish')
check('fixture 7', solve('2', 'a', {'1': 'b'}, True, False, 'public'), 'publish')
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| fixture 1 | publish | publish | Passed |
| fixture 2 | missing-attestation | skip | Failed |
| fixture 3 | publish | immutable-conflict | Failed |
| fixture 4 | missing-attestation | missing-attestation | Passed |
| fixture 5 | private-package | private-package | Passed |
| fixture 6 | publish | publish | Passed |
| fixture 7 | immutable-conflict | publish | Failed |
SHA-256 / 5461b29d73e716e75ad6a825b4034c095788f688bf32aadcf5e09fb7b434f3a6
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(version, digest, existing, attested, private, registry):
if version in existing:
if existing[version] == digest: return 'skip'
return 'immutable-conflict'
if not attested: return 'missing-attestation'
if private and registry == 'public': return 'private-package'
return 'publish'
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('fixture 1', solve('1', 'a', {}, True, False, 'public'), 'publish')
check('fixture 2', solve('1', 'a', {'1': 'a'}, False, True, 'public'), 'skip')
check('fixture 3', solve('1', 'a', {'1': 'b'}, True, False, 'public'), 'immutable-conflict')
check('fixture 4', solve('1', 'a', {}, False, False, 'public'), 'missing-attestation')
check('fixture 5', solve('1', 'a', {}, True, True, 'public'), 'private-package')
check('fixture 6', solve('1', 'a', {}, True, True, 'private'), 'publish')
check('fixture 7', solve('2', 'a', {'1': 'b'}, True, False, 'public'), 'publish')
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| fixture 1 | publish | publish | Passed |
| fixture 2 | skip | skip | Passed |
| fixture 3 | immutable-conflict | immutable-conflict | Passed |
| fixture 4 | missing-attestation | missing-attestation | Passed |
| fixture 5 | private-package | private-package | Passed |
| fixture 6 | publish | publish | Passed |
| fixture 7 | publish | publish | Passed |
SHA-256 / 547ca9fee9b6a8d368115b3a6c8eda59df0d444f3bf68ecea0f97f67e9e723db
Verification & scope
This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:38:34.800557+00:00.
Case digest / 3f7dc453f45385fdf50cb886341338c22638c7973e1bcf0a25cc110b3b242e48