Locked Out of Everything — Python Bug Hunt

Inspired by Facebook's October 2021 outage: a routine command withdrew the routes announcing their OWN backbone — including the ones engineers needed to log…

  • Language: Python
  • Layer: Backend
  • Difficulty: Medium
  • Concepts: Networking, Validation
  • Modelled on: Facebook · 2021
  • Visible tests: a normal withdrawal removes the listed routes; the management route is untouchable; withdrawing every route is refused
  • Reward: 50 XP for a complete fix

Briefing

Inspired by Facebook's October 2021 outage: a routine command withdrew the routes announcing their OWN backbone — including the ones engineers needed to log in and fix it. Badge readers stopped working. Someone reportedly needed an angle grinder.

routes.py plans a route withdrawal. It must protect the management network and never withdraw everything.

Bug report

BUG-BGP-104 · Priority: Existential · Reported by: network eng

plan_withdrawal(announced, to_withdraw) rules:

  • "mgmt/16" is sacred: it survives every withdrawal
  • at least one route must remain announced, else raise ValueError
  • returns the routes still announced, in their original order

Observed: the audit command withdrew mgmt/16 and then everything else.

Logs

[bgp] withdrawing 214/214 routes
[noc] dashboards unreachable; DNS gone; door badges offline

The code as shipped

src/net/routes.py (editable)

# Plans a BGP route withdrawal.

MGMT_ROUTE = "mgmt/16"

def plan_withdrawal(announced, to_withdraw):
    remaining = []
    for route in announced:
        if route not in to_withdraw:
            remaining.append(route)
    return remaining

Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More Python bug hunts.