Two independent routes can each produce the same defect on their own. How does decomposing it as alternatives change what counts as fixed?
answer
- One chain hides the other routes
- Any-one-of branches versus all-of conditions
- Closing one branch lowers frequency only
- Hunt the step every branch crosses
- Unclosed branches are recorded, not forgotten
basics
~20 sEach route reaches the same failure on its own, so closing one leaves the defect reachable. Decomposing as alternatives makes the other routes explicit, forces verification along each, and exposes any shared step where one change closes them all.
solid answer
~50 sA single chain still terminates on a multi-route failure — on whichever route the first reproduction took — and records nothing about the choice it made. Decomposing the failure into alternatives instead states the failure once and marks, at each node, whether **any one** branch is enough on its own or whether **all** the conditions must coincide. That changes three things. Fixing one branch lowers how often the failure occurs without closing it, so the honest outcome names the routes still open. Verification follows the branches rather than the original report, exercising each separately. And the branch list becomes the closing checklist: closed means every branch fixed or explicitly accepted. The payoff is the shared step every branch crosses — a value nothing checks, an operation not safe to repeat. One change there closes the whole set, and finding it is why the heavier shape earns its cost.
code
pseudocode · 16 linesTOP EVENT: an order is charged twice for one confirmed purchase
ANY-ONE-OF:
branch A: a timeout retry re-sends the same submission
branch B: two operators submit the same form within seconds
branch C: a stored submission is replayed during recovery
fix(branch A) -> failure still reachable through B and C
rate falls, defect is NOT closed
shared_step = the point every branch crosses:
submission accepted without a repeat-safe key
fix(shared_step) -> A, B and C all closed by one change
CLOSED WHEN: for every branch -> fixed OR accepted(with the condition
that would make it matter again)go deeper
Be ready to say that the same failure can be reached more than one way, and that fixing the route you were shown does not always stop it happening. Noticing that two reports reproduce differently is the contribution expected here.
Explain the difference between branches where any one alone is enough and conditions that must all coincide, and what each means for a fix. Interviewers want you to say that breaking one required condition closes an all-of failure but not an any-one-of failure.
Show that verification follows the decomposition. Describe exercising each branch separately, hunting for a shared step that closes several at once, and recording branches you consciously leave open together with the condition that would make them matter.
Own the standard for calling such a defect closed. Weigh chasing every branch against closing the routes that carry real traffic and accepting the rest in writing, and be able to say what about a given product decides which way that goes.
## A single chain quietly picks a route the evidence has not chosen When a defect can be produced in more than one way, a chain of why-questions still terminates. It terminates on whichever route the first reproduction happened to take, because that is the only route in front of the person drawing it. Nothing in the drawing records that a choice was made. The fix lands on that route, the failure keeps happening at a lower rate, and the next report arrives looking enough like the first to be closed as a duplicate. Decomposing the failure into **alternatives** is the repair. You state the failure once as a top event, then ask at each node what could produce it, and you mark whether **any one** of the branches below is sufficient on its own or whether **all of them** must coincide. The drawing now carries the thing the chain hid: how many live routes exist. ## Any-one-of versus all-of | Combination at a node | What it means | What closes the failure | How you verify | | --- | --- | --- | --- | | any one of the branches | each branch alone produces the failure | every branch closed, or the leftovers accepted in writing | exercise each branch separately | | all of the branches together | the failure needs the conditions to coincide | breaking any single one of the conditions | reproduce with each condition removed in turn | The two combinations invert each other, and getting them the wrong way round is expensive in both directions. Treating an any-one-of failure as all-of leads a team to think one fix was enough. Treating an all-of failure as any-one-of leads it to fix three things when one would have done, and to carry two changes of risk it did not need. ## What multiplicity changes about the fix 1. **Closing one branch changes the rate, not the existence.** The honest statement after fixing one route is *this route is closed and the failure is now reachable by two others*, not *fixed*. 2. **Verification follows the branches, not the report.** Re-running the original reproduction proves only the route you were shown. Each remaining branch needs its own exercise, and where a branch cannot be exercised, that is a finding to write down. 3. **The branch list becomes the closing checklist.** A defect of this kind is closed when every branch is either fixed or explicitly accepted, with the condition that would make an accepted one matter again. 4. **A shared step is the prize.** Very often every branch passes through one common point — a value nothing checks, an operation that is not safe to repeat, a boundary where a rule is enforced nowhere. One change there closes all the branches at once, and finding it is the main reason the decomposition is worth its cost. 5. **Branches nobody can reproduce are hypotheses.** Keep them, mark them as unreproduced, and do not spend fix effort on them ahead of the routes that are real. ## Finding the shared step Walk the branches side by side rather than one at a time and look for the point they all pass through. A practical test: take a candidate step and ask, for each branch in turn, whether the failure would still occur if that step behaved correctly. If the answer is no for every branch, you have the shared step and one change closes the set. If it is no for two of three, you have a partial fix and one route left, which is still worth knowing before you write the outcome. The opposite trap is a tree that is really one route drawn twice. Two branches are genuinely independent only if you can produce the failure through one while the condition the other depends on is absent. If removing a single condition kills both branches, merge them — an inflated tree spreads verification effort over routes that do not exist and makes the analysis look more thorough than it is. ## When the heavier shape is not worth it The decomposition costs real time: a precisely stated top event, branches that have to be reproduced individually, and a verification pass per branch. It earns that when the failure has already been reached by different routes, when reports disagree about how to reproduce it, or when the failure is severe enough that a partial fix is not acceptable. When the failure has only ever been produced one way and nobody can describe a second route, drawing branches manufactures hypotheses; a chain with well-evidenced links is the cheaper honest answer, and you switch shapes the day a second route turns up.
- How do you tell a genuine second route from the same route drawn twice?Reproduce them against each other. Two branches are independent only if the failure can be produced through one while the condition the other depends on is absent. If removing a single condition kills both, they are one route described two ways, and merging them keeps the decomposition honest rather than impressively wide.
- What changes when the conditions must all coincide rather than each being enough alone?The fix gets cheaper and the verification gets more specific. Breaking any single one of the required conditions prevents the failure, so you choose the condition that is safest and least costly to break. Verification then reproduces the failure with each condition removed in turn, which also confirms the conditions really were all required.
- When is the extra effort of an alternative decomposition not worth it?When the failure has only ever been produced one way and nobody can describe a second route. Drawing branches nobody can reproduce manufactures hypotheses and spreads verification effort over routes that may not exist. A chain with well-evidenced links is cheaper and just as honest; switch shapes the day a second route reaches the same failure.
A building with three unlocked doors: bolting one lowers how often strangers wander in and changes nothing about whether they can.
saying these in an interview costs you the question
- Calls a defect closed after fixing the reported route
- Draws one chain when reports differ in reproduction
- Treats two spellings of one route as independent
- Verifies only the route the original report used
- Leaves unclosed branches out of the written outcome
- Confuses conditions that must coincide with alternatives