FA-32901 / Menu interactions / Open access
Menu argument binding loses a parameter namespace boundary · case 01
Menu argument binding loses a parameter namespace boundary.
ROOT CAUSE
The command-argument-binding model applies `p['name']` at its prefix operation instead of the stipulated transformation.
VERIFIED REPAIR
Apply `p['namespace']+'.'+p['name']` at prefix.
Unsuccessful approach: The attempted repair `p['namespace']+p['name']` still violates the prefix oracle.
Case contract
Menu entries bind explicit invocation arguments, permit caller overrides only for allowed names, and distinguish missing values from explicit null.
Why this case matters
Cascading and context menus require coherent command and session state as content changes.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
if action == 'bound-order':
return p['bound']+p['runtime']
if action == 'allowlist':
return {k:v for k,v in p['caller'].items() if k in p['allowed']}
if action == 'explicit-null':
return p['args']['target'] if 'target' in p['args'] else p['default']
if action == 'required':
return sorted(set(p['required'])-set(p['args']))
if action == 'prefix':
return p['name']
if action == 'frozen-list':
return p['captured'][:]
return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('bound-order contract', solve('bound-order', {'bound':['document',N],'runtime':['copy']}), ['document',N,'copy'])
check('allowlist contract', solve('allowlist', {'caller':{'count':N,'owner':'rogue'},'allowed':['count']}), {'count':N})
check('explicit-null contract', solve('explicit-null', {'args':{'target':None},'default':N}), None)
check('required contract', solve('required', {'required':['a','b'],'args':{'a':N,'c':1}}), ['b'])
check('prefix contract', solve('prefix', {'namespace':'item'+str(N),'name':'mode'}), 'item'+str(N)+'.mode')
check('frozen-list contract', solve('frozen-list', {'captured':list(range(N+2)),'live':[-1]}), list(range(N+2)))
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| bound-order contract | ['document', 1, 'copy'] | ['document', 1, 'copy'] | Passed |
| allowlist contract | {'count': 1} | {'count': 1} | Passed |
| explicit-null contract | None | None | Passed |
| required contract | ['b'] | ['b'] | Passed |
| prefix contract | mode | item1.mode | Failed |
| frozen-list contract | [0, 1, 2] | [0, 1, 2] | Passed |
| unknown operation | {'error': 'unsupported menu operation'} | {'error': 'unsupported menu operation'} | Passed |
SHA-256 / e9da744b174a3b12547b74fee43d9dbe34e5eb38ccb31e0da7192af55171cdf4
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
if action == 'bound-order':
return p['bound']+p['runtime']
if action == 'allowlist':
return {k:v for k,v in p['caller'].items() if k in p['allowed']}
if action == 'explicit-null':
return p['args']['target'] if 'target' in p['args'] else p['default']
if action == 'required':
return sorted(set(p['required'])-set(p['args']))
if action == 'prefix':
return p['namespace']+p['name']
if action == 'frozen-list':
return p['captured'][:]
return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('bound-order contract', solve('bound-order', {'bound':['document',N],'runtime':['copy']}), ['document',N,'copy'])
check('allowlist contract', solve('allowlist', {'caller':{'count':N,'owner':'rogue'},'allowed':['count']}), {'count':N})
check('explicit-null contract', solve('explicit-null', {'args':{'target':None},'default':N}), None)
check('required contract', solve('required', {'required':['a','b'],'args':{'a':N,'c':1}}), ['b'])
check('prefix contract', solve('prefix', {'namespace':'item'+str(N),'name':'mode'}), 'item'+str(N)+'.mode')
check('frozen-list contract', solve('frozen-list', {'captured':list(range(N+2)),'live':[-1]}), list(range(N+2)))
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| bound-order contract | ['document', 1, 'copy'] | ['document', 1, 'copy'] | Passed |
| allowlist contract | {'count': 1} | {'count': 1} | Passed |
| explicit-null contract | None | None | Passed |
| required contract | ['b'] | ['b'] | Passed |
| prefix contract | item1mode | item1.mode | Failed |
| frozen-list contract | [0, 1, 2] | [0, 1, 2] | Passed |
| unknown operation | {'error': 'unsupported menu operation'} | {'error': 'unsupported menu operation'} | Passed |
SHA-256 / 109347d3a04848b158d914a70b268c0e0f0f9534448cdf7096032a1e643d0982
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
if action == 'bound-order':
return p['bound']+p['runtime']
if action == 'allowlist':
return {k:v for k,v in p['caller'].items() if k in p['allowed']}
if action == 'explicit-null':
return p['args']['target'] if 'target' in p['args'] else p['default']
if action == 'required':
return sorted(set(p['required'])-set(p['args']))
if action == 'prefix':
return p['namespace']+'.'+p['name']
if action == 'frozen-list':
return p['captured'][:]
return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('bound-order contract', solve('bound-order', {'bound':['document',N],'runtime':['copy']}), ['document',N,'copy'])
check('allowlist contract', solve('allowlist', {'caller':{'count':N,'owner':'rogue'},'allowed':['count']}), {'count':N})
check('explicit-null contract', solve('explicit-null', {'args':{'target':None},'default':N}), None)
check('required contract', solve('required', {'required':['a','b'],'args':{'a':N,'c':1}}), ['b'])
check('prefix contract', solve('prefix', {'namespace':'item'+str(N),'name':'mode'}), 'item'+str(N)+'.mode')
check('frozen-list contract', solve('frozen-list', {'captured':list(range(N+2)),'live':[-1]}), list(range(N+2)))
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| bound-order contract | ['document', 1, 'copy'] | ['document', 1, 'copy'] | Passed |
| allowlist contract | {'count': 1} | {'count': 1} | Passed |
| explicit-null contract | None | None | Passed |
| required contract | ['b'] | ['b'] | Passed |
| prefix contract | item1.mode | item1.mode | Passed |
| frozen-list contract | [0, 1, 2] | [0, 1, 2] | Passed |
| unknown operation | {'error': 'unsupported menu operation'} | {'error': 'unsupported menu operation'} | Passed |
SHA-256 / e9a6ad2d3cf8e549088ca230c5ec0b9e07f74fb3c7466fa8a7001a7566aa9543
Verification & scope
Offline supplied-valid-payload model; excludes DOM, keyboard, focus, selection, announcements and browser conformance. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:42:16.924839+00:00.
Case digest / 7a41514ac1c6fbc8302b270807a089475ee25d7406ed1c5498d7803b7600ed72