FA-33401 / Menu interactions / Open access
Menu patch silently appends content after its anchor disappeared · case 01
Menu patch silently appends content after its anchor disappeared.
ROOT CAUSE
The menu-patch-transaction model applies `'apply'` at its missing-anchor operation instead of the stipulated transformation.
VERIFIED REPAIR
Apply `'reject' if p['anchor'] not in p['rows'] else 'apply'` at missing-anchor.
Unsuccessful approach: The attempted repair `'append' if p['anchor'] not in p['rows'] else 'apply'` still violates the missing-anchor oracle.
Case contract
Provider menu patches apply to one base revision atomically; row edits use stable IDs and insertion anchors, while missing anchors reject the patch.
Why this case matters
Cascading and context menus require coherent command and session state as content changes.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
if action == 'base':
return p['base']==p['revision']
if action == 'insert-after':
return p['rows'][:p['rows'].index(p['anchor'])+1]+[p['new']]+p['rows'][p['rows'].index(p['anchor'])+1:]
if action == 'missing-anchor':
return 'apply'
if action == 'rollback':
return p['before'] if p['failed'] else p['working']
if action == 'replace-kind':
return dict(p['replacement'],id=p['old']['id'])
if action == 'revision-step':
return p['base']+int(p['committed'])
return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('base contract', solve('base', {'base':N,'revision':N+1}), False)
check('insert-after contract', solve('insert-after', {'rows':['a','b'],'anchor':'a','new':N}), ['a',N,'b'])
check('missing-anchor contract', solve('missing-anchor', {'rows':[N],'anchor':N+1}), 'reject')
check('rollback contract', solve('rollback', {'before':[N,N+1],'working':[N+2],'failed':True}), [N,N+1])
check('replace-kind contract', solve('replace-kind', {'old':{'id':N,'kind':'command','handler':'old'},'replacement':{'kind':'submenu','children':[N+1]}}), {'id':N,'kind':'submenu','children':[N+1]})
check('revision-step contract', solve('revision-step', {'base':N,'committed':True,'operation_count':3}), N+1)
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
check('failed patch retains revision',solve('revision-step',{'base':N,'committed':False,'operation_count':2}),N)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| base contract | False | False | Passed |
| insert-after contract | ['a', 1, 'b'] | ['a', 1, 'b'] | Passed |
| missing-anchor contract | apply | reject | Failed |
| rollback contract | [1, 2] | [1, 2] | Passed |
| replace-kind contract | {'children': [2], 'id': 1, 'kind': 'submenu'} | {'children': [2], 'id': 1, 'kind': 'submenu'} | Passed |
| revision-step contract | 2 | 2 | Passed |
| unknown operation | {'error': 'unsupported menu operation'} | {'error': 'unsupported menu operation'} | Passed |
| failed patch retains revision | 1 | 1 | Passed |
SHA-256 / a3d2c7cea3473a429989f64a41c0182632042f43da55485c9c3a73436cbac0f6
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
if action == 'base':
return p['base']==p['revision']
if action == 'insert-after':
return p['rows'][:p['rows'].index(p['anchor'])+1]+[p['new']]+p['rows'][p['rows'].index(p['anchor'])+1:]
if action == 'missing-anchor':
return 'append' if p['anchor'] not in p['rows'] else 'apply'
if action == 'rollback':
return p['before'] if p['failed'] else p['working']
if action == 'replace-kind':
return dict(p['replacement'],id=p['old']['id'])
if action == 'revision-step':
return p['base']+int(p['committed'])
return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('base contract', solve('base', {'base':N,'revision':N+1}), False)
check('insert-after contract', solve('insert-after', {'rows':['a','b'],'anchor':'a','new':N}), ['a',N,'b'])
check('missing-anchor contract', solve('missing-anchor', {'rows':[N],'anchor':N+1}), 'reject')
check('rollback contract', solve('rollback', {'before':[N,N+1],'working':[N+2],'failed':True}), [N,N+1])
check('replace-kind contract', solve('replace-kind', {'old':{'id':N,'kind':'command','handler':'old'},'replacement':{'kind':'submenu','children':[N+1]}}), {'id':N,'kind':'submenu','children':[N+1]})
check('revision-step contract', solve('revision-step', {'base':N,'committed':True,'operation_count':3}), N+1)
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
check('failed patch retains revision',solve('revision-step',{'base':N,'committed':False,'operation_count':2}),N)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| base contract | False | False | Passed |
| insert-after contract | ['a', 1, 'b'] | ['a', 1, 'b'] | Passed |
| missing-anchor contract | append | reject | Failed |
| rollback contract | [1, 2] | [1, 2] | Passed |
| replace-kind contract | {'children': [2], 'id': 1, 'kind': 'submenu'} | {'children': [2], 'id': 1, 'kind': 'submenu'} | Passed |
| revision-step contract | 2 | 2 | Passed |
| unknown operation | {'error': 'unsupported menu operation'} | {'error': 'unsupported menu operation'} | Passed |
| failed patch retains revision | 1 | 1 | Passed |
SHA-256 / 0454cf9296a33890224178ddce275e3657844a2bb7e0d07868d54b6c891e18a7
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
if action == 'base':
return p['base']==p['revision']
if action == 'insert-after':
return p['rows'][:p['rows'].index(p['anchor'])+1]+[p['new']]+p['rows'][p['rows'].index(p['anchor'])+1:]
if action == 'missing-anchor':
return 'reject' if p['anchor'] not in p['rows'] else 'apply'
if action == 'rollback':
return p['before'] if p['failed'] else p['working']
if action == 'replace-kind':
return dict(p['replacement'],id=p['old']['id'])
if action == 'revision-step':
return p['base']+int(p['committed'])
return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('base contract', solve('base', {'base':N,'revision':N+1}), False)
check('insert-after contract', solve('insert-after', {'rows':['a','b'],'anchor':'a','new':N}), ['a',N,'b'])
check('missing-anchor contract', solve('missing-anchor', {'rows':[N],'anchor':N+1}), 'reject')
check('rollback contract', solve('rollback', {'before':[N,N+1],'working':[N+2],'failed':True}), [N,N+1])
check('replace-kind contract', solve('replace-kind', {'old':{'id':N,'kind':'command','handler':'old'},'replacement':{'kind':'submenu','children':[N+1]}}), {'id':N,'kind':'submenu','children':[N+1]})
check('revision-step contract', solve('revision-step', {'base':N,'committed':True,'operation_count':3}), N+1)
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
check('failed patch retains revision',solve('revision-step',{'base':N,'committed':False,'operation_count':2}),N)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| base contract | False | False | Passed |
| insert-after contract | ['a', 1, 'b'] | ['a', 1, 'b'] | Passed |
| missing-anchor contract | reject | reject | Passed |
| rollback contract | [1, 2] | [1, 2] | Passed |
| replace-kind contract | {'children': [2], 'id': 1, 'kind': 'submenu'} | {'children': [2], 'id': 1, 'kind': 'submenu'} | Passed |
| revision-step contract | 2 | 2 | Passed |
| unknown operation | {'error': 'unsupported menu operation'} | {'error': 'unsupported menu operation'} | Passed |
| failed patch retains revision | 1 | 1 | Passed |
SHA-256 / 4341cb1e599737923927c9d3369e6fa374b1b9fe48279893021dda6e66841324
Verification & scope
Offline supplied-valid-payload model; excludes DOM, keyboard, focus, selection, announcements and browser conformance. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:42:22.077267+00:00.
Case digest / 24fa6053efefeb1e555833aaaf430c20e8c7a912fe2d9e1d1fa78f2bf68f4e41