FAILURE MAP
← Case archive

FA-32886 / Menu interactions / Open access

Context menu caller overrides protected command arguments · case 01

Context menu caller overrides protected command arguments.

Verified by executionVariant 1 · 7 checks per implementationDownload source bundle ↓JSON ↗

ROOT CAUSE

The command-argument-binding model applies `p['caller']` at its allowlist operation instead of the stipulated transformation.

VERIFIED REPAIR

Apply `{k:v for k,v in p['caller'].items() if k in p['allowed']}` at allowlist.

Unsuccessful approach: The attempted repair `{k:v for k,v in p['caller'].items() if k not in p['allowed']}` still violates the allowlist oracle.

Case contract

Menu entries bind explicit invocation arguments, permit caller overrides only for allowed names, and distinguish missing values from explicit null.

Why this case matters

Cascading and context menus require coherent command and session state as content changes.

1 / The failure

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
    if action == 'bound-order':
        return p['bound']+p['runtime']
    if action == 'allowlist':
        return p['caller']
    if action == 'explicit-null':
        return p['args']['target'] if 'target' in p['args'] else p['default']
    if action == 'required':
        return sorted(set(p['required'])-set(p['args']))
    if action == 'prefix':
        return p['namespace']+'.'+p['name']
    if action == 'frozen-list':
        return p['captured'][:]
    return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('bound-order contract', solve('bound-order', {'bound':['document',N],'runtime':['copy']}), ['document',N,'copy'])
check('allowlist contract', solve('allowlist', {'caller':{'count':N,'owner':'rogue'},'allowed':['count']}), {'count':N})
check('explicit-null contract', solve('explicit-null', {'args':{'target':None},'default':N}), None)
check('required contract', solve('required', {'required':['a','b'],'args':{'a':N,'c':1}}), ['b'])
check('prefix contract', solve('prefix', {'namespace':'item'+str(N),'name':'mode'}), 'item'+str(N)+'.mode')
check('frozen-list contract', solve('frozen-list', {'captured':list(range(N+2)),'live':[-1]}), list(range(N+2)))
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
bound-order contract['document', 1, 'copy']['document', 1, 'copy']Passed
allowlist contract{'count': 1, 'owner': 'rogue'}{'count': 1}Failed
explicit-null contractNoneNonePassed
required contract['b']['b']Passed
prefix contractitem1.modeitem1.modePassed
frozen-list contract[0, 1, 2][0, 1, 2]Passed
unknown operation{'error': 'unsupported menu operation'}{'error': 'unsupported menu operation'}Passed

SHA-256 / 558426a462e85861c8daebe7bbaae362946566bc43cae629ff5661c4001a0989

2 / The unsuccessful fix

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
    if action == 'bound-order':
        return p['bound']+p['runtime']
    if action == 'allowlist':
        return {k:v for k,v in p['caller'].items() if k not in p['allowed']}
    if action == 'explicit-null':
        return p['args']['target'] if 'target' in p['args'] else p['default']
    if action == 'required':
        return sorted(set(p['required'])-set(p['args']))
    if action == 'prefix':
        return p['namespace']+'.'+p['name']
    if action == 'frozen-list':
        return p['captured'][:]
    return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('bound-order contract', solve('bound-order', {'bound':['document',N],'runtime':['copy']}), ['document',N,'copy'])
check('allowlist contract', solve('allowlist', {'caller':{'count':N,'owner':'rogue'},'allowed':['count']}), {'count':N})
check('explicit-null contract', solve('explicit-null', {'args':{'target':None},'default':N}), None)
check('required contract', solve('required', {'required':['a','b'],'args':{'a':N,'c':1}}), ['b'])
check('prefix contract', solve('prefix', {'namespace':'item'+str(N),'name':'mode'}), 'item'+str(N)+'.mode')
check('frozen-list contract', solve('frozen-list', {'captured':list(range(N+2)),'live':[-1]}), list(range(N+2)))
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
bound-order contract['document', 1, 'copy']['document', 1, 'copy']Passed
allowlist contract{'owner': 'rogue'}{'count': 1}Failed
explicit-null contractNoneNonePassed
required contract['b']['b']Passed
prefix contractitem1.modeitem1.modePassed
frozen-list contract[0, 1, 2][0, 1, 2]Passed
unknown operation{'error': 'unsupported menu operation'}{'error': 'unsupported menu operation'}Passed

SHA-256 / d1bed96f0db07f9b0b67967071029dc1ba99f328b06614e22c8865eb9be8e410

3 / The verified repair

Exit 0
"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
    if action == 'bound-order':
        return p['bound']+p['runtime']
    if action == 'allowlist':
        return {k:v for k,v in p['caller'].items() if k in p['allowed']}
    if action == 'explicit-null':
        return p['args']['target'] if 'target' in p['args'] else p['default']
    if action == 'required':
        return sorted(set(p['required'])-set(p['args']))
    if action == 'prefix':
        return p['namespace']+'.'+p['name']
    if action == 'frozen-list':
        return p['captured'][:]
    return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('bound-order contract', solve('bound-order', {'bound':['document',N],'runtime':['copy']}), ['document',N,'copy'])
check('allowlist contract', solve('allowlist', {'caller':{'count':N,'owner':'rogue'},'allowed':['count']}), {'count':N})
check('explicit-null contract', solve('explicit-null', {'args':{'target':None},'default':N}), None)
check('required contract', solve('required', {'required':['a','b'],'args':{'a':N,'c':1}}), ['b'])
check('prefix contract', solve('prefix', {'namespace':'item'+str(N),'name':'mode'}), 'item'+str(N)+'.mode')
check('frozen-list contract', solve('frozen-list', {'captured':list(range(N+2)),'live':[-1]}), list(range(N+2)))
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
bound-order contract['document', 1, 'copy']['document', 1, 'copy']Passed
allowlist contract{'count': 1}{'count': 1}Passed
explicit-null contractNoneNonePassed
required contract['b']['b']Passed
prefix contractitem1.modeitem1.modePassed
frozen-list contract[0, 1, 2][0, 1, 2]Passed
unknown operation{'error': 'unsupported menu operation'}{'error': 'unsupported menu operation'}Passed

SHA-256 / e9a6ad2d3cf8e549088ca230c5ec0b9e07f74fb3c7466fa8a7001a7566aa9543

Verification & scope

Offline supplied-valid-payload model; excludes DOM, keyboard, focus, selection, announcements and browser conformance. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.

Observations recorded using Python 3.12.14 at 2026-09-29T14:42:16.750835+00:00.

Case digest / ed81569e39b8dbc7483ba53908e464dff8e63d50d2c24d76217e8cf66737d6ae