FA-33161 / Menu interactions / Open access
Dangling alias menu entry is considered executable · case 01
Dangling alias menu entry is considered executable.
ROOT CAUSE
The menu-aliases model applies `True` at its missing-target operation instead of the stipulated transformation.
VERIFIED REPAIR
Apply `p['target'] in p['registry']` at missing-target.
Unsuccessful approach: The attempted repair `p['alias'] in p['registry']` still violates the missing-target oracle.
Case contract
Menu aliases preserve display ownership while resolving an explicit one-level target; alias overrides affect presentation but never command identity.
Why this case matters
Cascading and context menus require coherent command and session state as content changes.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
if action == 'target':
return p['alias']['target']
if action == 'label-override':
return p['alias']['label'] if 'label' in p['alias'] else p['target']['label']
if action == 'missing-target':
return True
if action == 'self-alias':
return p['id']!=p['target']
if action == 'arguments':
return dict(p['target_args'],**p['alias_args'])
if action == 'owner':
return p['alias_parent']
return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('target contract', solve('target', {'alias':{'target':'cmd'+str(N),'id':'shortcut','parent':'tools'}}), 'cmd'+str(N))
check('label-override contract', solve('label-override', {'alias':{'label':'Quick '+str(N),'id':'shortcut'},'target':{'label':'Full'}}), 'Quick '+str(N))
check('missing-target contract', solve('missing-target', {'target':'missing'+str(N),'alias':'shortcut','registry':['shortcut']}), False)
check('self-alias contract', solve('self-alias', {'id':N,'target':N,'registry':[N]}), False)
check('arguments contract', solve('arguments', {'target_args':{'mode':'normal','count':1},'alias_args':{'count':N+1}}), {'mode':'normal','count':N+1})
check('owner contract', solve('owner', {'alias_parent':'quick'+str(N),'target_parent':'full','root':'r'}), 'quick'+str(N))
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| target contract | cmd1 | cmd1 | Passed |
| label-override contract | Quick 1 | Quick 1 | Passed |
| missing-target contract | True | False | Failed |
| self-alias contract | False | False | Passed |
| arguments contract | {'count': 2, 'mode': 'normal'} | {'count': 2, 'mode': 'normal'} | Passed |
| owner contract | quick1 | quick1 | Passed |
| unknown operation | {'error': 'unsupported menu operation'} | {'error': 'unsupported menu operation'} | Passed |
SHA-256 / f360e441bcf272fc0387a27aa4eb4f98b9650024492b0fb8e167824ccfa496e5
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
if action == 'target':
return p['alias']['target']
if action == 'label-override':
return p['alias']['label'] if 'label' in p['alias'] else p['target']['label']
if action == 'missing-target':
return p['alias'] in p['registry']
if action == 'self-alias':
return p['id']!=p['target']
if action == 'arguments':
return dict(p['target_args'],**p['alias_args'])
if action == 'owner':
return p['alias_parent']
return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('target contract', solve('target', {'alias':{'target':'cmd'+str(N),'id':'shortcut','parent':'tools'}}), 'cmd'+str(N))
check('label-override contract', solve('label-override', {'alias':{'label':'Quick '+str(N),'id':'shortcut'},'target':{'label':'Full'}}), 'Quick '+str(N))
check('missing-target contract', solve('missing-target', {'target':'missing'+str(N),'alias':'shortcut','registry':['shortcut']}), False)
check('self-alias contract', solve('self-alias', {'id':N,'target':N,'registry':[N]}), False)
check('arguments contract', solve('arguments', {'target_args':{'mode':'normal','count':1},'alias_args':{'count':N+1}}), {'mode':'normal','count':N+1})
check('owner contract', solve('owner', {'alias_parent':'quick'+str(N),'target_parent':'full','root':'r'}), 'quick'+str(N))
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| target contract | cmd1 | cmd1 | Passed |
| label-override contract | Quick 1 | Quick 1 | Passed |
| missing-target contract | True | False | Failed |
| self-alias contract | False | False | Passed |
| arguments contract | {'count': 2, 'mode': 'normal'} | {'count': 2, 'mode': 'normal'} | Passed |
| owner contract | quick1 | quick1 | Passed |
| unknown operation | {'error': 'unsupported menu operation'} | {'error': 'unsupported menu operation'} | Passed |
SHA-256 / bf50ba5ec5f6f5a7e7e9cc7f6ed6afab2f96b35eba8471e7c51ab2012f8e2450
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
if action == 'target':
return p['alias']['target']
if action == 'label-override':
return p['alias']['label'] if 'label' in p['alias'] else p['target']['label']
if action == 'missing-target':
return p['target'] in p['registry']
if action == 'self-alias':
return p['id']!=p['target']
if action == 'arguments':
return dict(p['target_args'],**p['alias_args'])
if action == 'owner':
return p['alias_parent']
return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('target contract', solve('target', {'alias':{'target':'cmd'+str(N),'id':'shortcut','parent':'tools'}}), 'cmd'+str(N))
check('label-override contract', solve('label-override', {'alias':{'label':'Quick '+str(N),'id':'shortcut'},'target':{'label':'Full'}}), 'Quick '+str(N))
check('missing-target contract', solve('missing-target', {'target':'missing'+str(N),'alias':'shortcut','registry':['shortcut']}), False)
check('self-alias contract', solve('self-alias', {'id':N,'target':N,'registry':[N]}), False)
check('arguments contract', solve('arguments', {'target_args':{'mode':'normal','count':1},'alias_args':{'count':N+1}}), {'mode':'normal','count':N+1})
check('owner contract', solve('owner', {'alias_parent':'quick'+str(N),'target_parent':'full','root':'r'}), 'quick'+str(N))
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| target contract | cmd1 | cmd1 | Passed |
| label-override contract | Quick 1 | Quick 1 | Passed |
| missing-target contract | False | False | Passed |
| self-alias contract | False | False | Passed |
| arguments contract | {'count': 2, 'mode': 'normal'} | {'count': 2, 'mode': 'normal'} | Passed |
| owner contract | quick1 | quick1 | Passed |
| unknown operation | {'error': 'unsupported menu operation'} | {'error': 'unsupported menu operation'} | Passed |
SHA-256 / 27113f8352ffe71c1788bed7fcedb31035f54cde2795872169928d269a87564c
Verification & scope
Offline supplied-valid-payload model; excludes DOM, keyboard, focus, selection, announcements and browser conformance. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:42:19.579614+00:00.
Case digest / 4e56d794256b1461b83926dfe131d2f3738b61e65c2fb737829bce095ab1c68e