FA-32556 / Menu interactions / Open access
Submenu child enumeration leaks sibling commands · case 01
Submenu child enumeration leaks sibling commands.
ROOT CAUSE
The submenu-definition model applies `[x['id'] for x in p['nodes']]` at its children operation instead of the stipulated transformation.
VERIFIED REPAIR
Apply `[x['id'] for x in p['nodes'] if x['parent']==p['parent']]` at children.
Unsuccessful approach: The attempted repair `[x['id'] for x in p['nodes'] if x['id']==p['parent']]` still violates the children oracle.
Case contract
Menu definitions validate presentation identity separately from semantic command identity. Split-menu defaults belong to immediate command children; ancestry and depth remain bounded.
Why this case matters
Cascading and context menus require coherent command and session state as content changes.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
if action == 'roots':
return [x['id'] for x in p if x['parent'] is None]
if action == 'children':
return [x['id'] for x in p['nodes']]
if action == 'split-default':
return p['default'] in [x['command'] for x in p['children'] if x['kind']=='command']
if action == 'self-cycle':
return any(x['id']==x['parent'] for x in p)
if action == 'presentation-ids':
return len({x['row'] for x in p})==len(p)
if action == 'depth-budget':
return p['depth']+p['incoming']<=p['limit']
return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('roots contract', solve('roots', [{'id':0,'parent':None},{'id':N,'parent':0}]), [0])
check('children contract', solve('children', {'parent':'a','nodes':[{'id':N,'parent':'a'},{'id':N+1,'parent':'b'}]}), [N])
check('split-default contract', solve('split-default', {'default':'remote'+str(N),'registry':['remote'+str(N)],'children':[{'kind':'submenu','descendants':['remote'+str(N)]}]}), False)
check('self-cycle contract', solve('self-cycle', [{'id':N,'parent':N},{'id':N+1,'parent':None}]), True)
check('presentation-ids contract', solve('presentation-ids', [{'row':N,'command':'copy','label':'Copy'},{'row':N+1,'command':'copy','label':'Copy'}]), True)
check('depth-budget contract', solve('depth-budget', {'depth':N+2,'incoming':4,'limit':N+4}), False)
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| roots contract | [0] | [0] | Passed |
| children contract | [1, 2] | [1] | Failed |
| split-default contract | False | False | Passed |
| self-cycle contract | True | True | Passed |
| presentation-ids contract | True | True | Passed |
| depth-budget contract | False | False | Passed |
| unknown operation | {'error': 'unsupported menu operation'} | {'error': 'unsupported menu operation'} | Passed |
SHA-256 / a5f834484a64ede8b5df82cfa66d227cc98cf098e1e6b0e8e2d5264ed1fa0269
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
if action == 'roots':
return [x['id'] for x in p if x['parent'] is None]
if action == 'children':
return [x['id'] for x in p['nodes'] if x['id']==p['parent']]
if action == 'split-default':
return p['default'] in [x['command'] for x in p['children'] if x['kind']=='command']
if action == 'self-cycle':
return any(x['id']==x['parent'] for x in p)
if action == 'presentation-ids':
return len({x['row'] for x in p})==len(p)
if action == 'depth-budget':
return p['depth']+p['incoming']<=p['limit']
return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('roots contract', solve('roots', [{'id':0,'parent':None},{'id':N,'parent':0}]), [0])
check('children contract', solve('children', {'parent':'a','nodes':[{'id':N,'parent':'a'},{'id':N+1,'parent':'b'}]}), [N])
check('split-default contract', solve('split-default', {'default':'remote'+str(N),'registry':['remote'+str(N)],'children':[{'kind':'submenu','descendants':['remote'+str(N)]}]}), False)
check('self-cycle contract', solve('self-cycle', [{'id':N,'parent':N},{'id':N+1,'parent':None}]), True)
check('presentation-ids contract', solve('presentation-ids', [{'row':N,'command':'copy','label':'Copy'},{'row':N+1,'command':'copy','label':'Copy'}]), True)
check('depth-budget contract', solve('depth-budget', {'depth':N+2,'incoming':4,'limit':N+4}), False)
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| roots contract | [0] | [0] | Passed |
| children contract | [] | [1] | Failed |
| split-default contract | False | False | Passed |
| self-cycle contract | True | True | Passed |
| presentation-ids contract | True | True | Passed |
| depth-budget contract | False | False | Passed |
| unknown operation | {'error': 'unsupported menu operation'} | {'error': 'unsupported menu operation'} | Passed |
SHA-256 / 99413142cb96f344e12dd765109e614e6c5a2fc78bb745dc4e69357b1e1e3e32
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
if action == 'roots':
return [x['id'] for x in p if x['parent'] is None]
if action == 'children':
return [x['id'] for x in p['nodes'] if x['parent']==p['parent']]
if action == 'split-default':
return p['default'] in [x['command'] for x in p['children'] if x['kind']=='command']
if action == 'self-cycle':
return any(x['id']==x['parent'] for x in p)
if action == 'presentation-ids':
return len({x['row'] for x in p})==len(p)
if action == 'depth-budget':
return p['depth']+p['incoming']<=p['limit']
return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('roots contract', solve('roots', [{'id':0,'parent':None},{'id':N,'parent':0}]), [0])
check('children contract', solve('children', {'parent':'a','nodes':[{'id':N,'parent':'a'},{'id':N+1,'parent':'b'}]}), [N])
check('split-default contract', solve('split-default', {'default':'remote'+str(N),'registry':['remote'+str(N)],'children':[{'kind':'submenu','descendants':['remote'+str(N)]}]}), False)
check('self-cycle contract', solve('self-cycle', [{'id':N,'parent':N},{'id':N+1,'parent':None}]), True)
check('presentation-ids contract', solve('presentation-ids', [{'row':N,'command':'copy','label':'Copy'},{'row':N+1,'command':'copy','label':'Copy'}]), True)
check('depth-budget contract', solve('depth-budget', {'depth':N+2,'incoming':4,'limit':N+4}), False)
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| roots contract | [0] | [0] | Passed |
| children contract | [1] | [1] | Passed |
| split-default contract | False | False | Passed |
| self-cycle contract | True | True | Passed |
| presentation-ids contract | True | True | Passed |
| depth-budget contract | False | False | Passed |
| unknown operation | {'error': 'unsupported menu operation'} | {'error': 'unsupported menu operation'} | Passed |
SHA-256 / 87edc5470e1c55a26ad5390aef049f049534f836382f0a1d0c745b799c293acf
Verification & scope
Offline supplied-valid-payload model; excludes DOM, keyboard, focus, selection, announcements and browser conformance. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:42:13.372125+00:00.
Case digest / af3c4dfc278b73dfe063ead62ec8b5c1535d2ce4899356ae13977f0377bd9c83