FA-33186 / Menu interactions / Open access
Closing one menu disposes a provider still used by another surface · case 01
Closing one menu disposes a provider still used by another surface.
ROOT CAUSE
The menu-provider-leases model applies `[]` at its release operation instead of the stipulated transformation.
VERIFIED REPAIR
Apply `sorted(p['holders']-{p['id']})` at release.
Unsuccessful approach: The attempted repair `sorted(p['holders'])` still violates the release oracle.
Case contract
Providers can be shared by multiple menu surfaces; leases control attachment lifetime and only visible subscribers receive presentation updates.
Why this case matters
Cascading and context menus require coherent command and session state as content changes.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
if action == 'acquire':
return sorted(p['holders'] | {p['id']})
if action == 'release':
return []
if action == 'dispose':
return not p['holders']
if action == 'visible-recipients':
return [x['id'] for x in p if x['visible'] and x['attached']]
if action == 'load-more':
return p['next'] is not None and not p['pending_page']
if action == 'new-load':
return not p['loaded'] and not p['pending']
return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('acquire contract', solve('acquire', {'holders':{'a'},'id':'b'+str(N)}), ['a','b'+str(N)])
check('release contract', solve('release', {'holders':{'a','b'+str(N)},'id':'a'}), ['b'+str(N)])
check('dispose contract', solve('dispose', {'holders':['menu'+str(N)]}), False)
check('visible-recipients contract', solve('visible-recipients', [{'id':N,'visible':False,'attached':True},{'id':N+1,'visible':True,'attached':False}]), [])
check('load-more contract', solve('load-more', {'next':'cursor'+str(N),'pending_page':True}), False)
check('new-load contract', solve('new-load', {'loaded':False,'pending':True,'leases':N}), False)
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
check('empty opaque cursor is valid',solve('load-more',{'next':'','pending_page':False,'generation':N}),True)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| acquire contract | ['a', 'b1'] | ['a', 'b1'] | Passed |
| release contract | [] | ['b1'] | Failed |
| dispose contract | False | False | Passed |
| visible-recipients contract | [] | [] | Passed |
| load-more contract | False | False | Passed |
| new-load contract | False | False | Passed |
| unknown operation | {'error': 'unsupported menu operation'} | {'error': 'unsupported menu operation'} | Passed |
| empty opaque cursor is valid | True | True | Passed |
SHA-256 / 6d346691529b2fa7146fb9a93209bc56e514505b63723b797a8d5a713d35eff5
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
if action == 'acquire':
return sorted(p['holders'] | {p['id']})
if action == 'release':
return sorted(p['holders'])
if action == 'dispose':
return not p['holders']
if action == 'visible-recipients':
return [x['id'] for x in p if x['visible'] and x['attached']]
if action == 'load-more':
return p['next'] is not None and not p['pending_page']
if action == 'new-load':
return not p['loaded'] and not p['pending']
return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('acquire contract', solve('acquire', {'holders':{'a'},'id':'b'+str(N)}), ['a','b'+str(N)])
check('release contract', solve('release', {'holders':{'a','b'+str(N)},'id':'a'}), ['b'+str(N)])
check('dispose contract', solve('dispose', {'holders':['menu'+str(N)]}), False)
check('visible-recipients contract', solve('visible-recipients', [{'id':N,'visible':False,'attached':True},{'id':N+1,'visible':True,'attached':False}]), [])
check('load-more contract', solve('load-more', {'next':'cursor'+str(N),'pending_page':True}), False)
check('new-load contract', solve('new-load', {'loaded':False,'pending':True,'leases':N}), False)
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
check('empty opaque cursor is valid',solve('load-more',{'next':'','pending_page':False,'generation':N}),True)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| acquire contract | ['a', 'b1'] | ['a', 'b1'] | Passed |
| release contract | ['a', 'b1'] | ['b1'] | Failed |
| dispose contract | False | False | Passed |
| visible-recipients contract | [] | [] | Passed |
| load-more contract | False | False | Passed |
| new-load contract | False | False | Passed |
| unknown operation | {'error': 'unsupported menu operation'} | {'error': 'unsupported menu operation'} | Passed |
| empty opaque cursor is valid | True | True | Passed |
SHA-256 / c962b998470017c1a2469557af2642d97d9caa98d51456fef5167a924148801b
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
if action == 'acquire':
return sorted(p['holders'] | {p['id']})
if action == 'release':
return sorted(p['holders']-{p['id']})
if action == 'dispose':
return not p['holders']
if action == 'visible-recipients':
return [x['id'] for x in p if x['visible'] and x['attached']]
if action == 'load-more':
return p['next'] is not None and not p['pending_page']
if action == 'new-load':
return not p['loaded'] and not p['pending']
return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('acquire contract', solve('acquire', {'holders':{'a'},'id':'b'+str(N)}), ['a','b'+str(N)])
check('release contract', solve('release', {'holders':{'a','b'+str(N)},'id':'a'}), ['b'+str(N)])
check('dispose contract', solve('dispose', {'holders':['menu'+str(N)]}), False)
check('visible-recipients contract', solve('visible-recipients', [{'id':N,'visible':False,'attached':True},{'id':N+1,'visible':True,'attached':False}]), [])
check('load-more contract', solve('load-more', {'next':'cursor'+str(N),'pending_page':True}), False)
check('new-load contract', solve('new-load', {'loaded':False,'pending':True,'leases':N}), False)
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
check('empty opaque cursor is valid',solve('load-more',{'next':'','pending_page':False,'generation':N}),True)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| acquire contract | ['a', 'b1'] | ['a', 'b1'] | Passed |
| release contract | ['b1'] | ['b1'] | Passed |
| dispose contract | False | False | Passed |
| visible-recipients contract | [] | [] | Passed |
| load-more contract | False | False | Passed |
| new-load contract | False | False | Passed |
| unknown operation | {'error': 'unsupported menu operation'} | {'error': 'unsupported menu operation'} | Passed |
| empty opaque cursor is valid | True | True | Passed |
SHA-256 / 240bb7f27608ed88d3489ba59a84e602796817ee4fb98c005103f318844a3113
Verification & scope
Offline supplied-valid-payload model; excludes DOM, keyboard, focus, selection, announcements and browser conformance. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:42:19.782726+00:00.
Case digest / 61f21eec42bd0afd516a1a04f332de128d975a25221a1958785e5b47f43bc06d