FA-33681 / Menu interactions / Open access
Fatal malformed menu definition is replaced with unsafe stale content · case 01
Fatal malformed menu definition is replaced with unsafe stale content.
ROOT CAUSE
The menu-provider-error-boundary model applies `p['fallback']` at its fatal operation instead of the stipulated transformation.
VERIFIED REPAIR
Apply `p['fallback'] if not p['fatal'] else []` at fatal.
Unsuccessful approach: The attempted repair `[] if not p['fatal'] else p['fallback']` still violates the fatal oracle.
Case contract
A failed menu provider is isolated to its owned section; fallback content and error records are distinct, and recovery clears only that provider error.
Why this case matters
Cascading and context menus require coherent command and session state as content changes.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
if action == 'isolate':
return [x for x in p['rows'] if x['provider']!=p['failed']]
if action == 'fallback':
return p['fallback'] if p['failed'] else p['content']
if action == 'error-record':
return {'provider':p['provider'],'code':p['code'],'generation':p['generation']}
if action == 'recovery':
return {k:v for k,v in p['errors'].items() if k!=p['provider']}
if action == 'fatal':
return p['fallback']
if action == 'retry-budget':
return max(0,p['budget']-p['attempts'])
return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('isolate contract', solve('isolate', {'rows':[{'provider':'a','id':N},{'provider':'b','id':N+1}],'failed':'a'}), [{'provider':'b','id':N+1}])
check('fallback contract', solve('fallback', {'failed':True,'fallback':[N],'content':[N+1]}), [N])
check('error-record contract', solve('error-record', {'provider':'child','root':'root','code':'parse','generation':N}), {'provider':'child','code':'parse','generation':N})
check('recovery contract', solve('recovery', {'errors':{'a':N,'b':N+1},'provider':'a'}), {'b':N+1})
check('fatal contract', solve('fatal', {'fallback':[N],'fatal':True}), [])
check('retry-budget contract', solve('retry-budget', {'budget':N+4,'attempts':3}), N+1)
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| isolate contract | [{'id': 2, 'provider': 'b'}] | [{'id': 2, 'provider': 'b'}] | Passed |
| fallback contract | [1] | [1] | Passed |
| error-record contract | {'code': 'parse', 'generation': 1, 'provider': 'child'} | {'code': 'parse', 'generation': 1, 'provider': 'child'} | Passed |
| recovery contract | {'b': 2} | {'b': 2} | Passed |
| fatal contract | [1] | [] | Failed |
| retry-budget contract | 2 | 2 | Passed |
| unknown operation | {'error': 'unsupported menu operation'} | {'error': 'unsupported menu operation'} | Passed |
SHA-256 / b3e005e876bf73d77ad5b0ed8255025938e6473776d7e07326b5fec2b837fdad
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
if action == 'isolate':
return [x for x in p['rows'] if x['provider']!=p['failed']]
if action == 'fallback':
return p['fallback'] if p['failed'] else p['content']
if action == 'error-record':
return {'provider':p['provider'],'code':p['code'],'generation':p['generation']}
if action == 'recovery':
return {k:v for k,v in p['errors'].items() if k!=p['provider']}
if action == 'fatal':
return [] if not p['fatal'] else p['fallback']
if action == 'retry-budget':
return max(0,p['budget']-p['attempts'])
return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('isolate contract', solve('isolate', {'rows':[{'provider':'a','id':N},{'provider':'b','id':N+1}],'failed':'a'}), [{'provider':'b','id':N+1}])
check('fallback contract', solve('fallback', {'failed':True,'fallback':[N],'content':[N+1]}), [N])
check('error-record contract', solve('error-record', {'provider':'child','root':'root','code':'parse','generation':N}), {'provider':'child','code':'parse','generation':N})
check('recovery contract', solve('recovery', {'errors':{'a':N,'b':N+1},'provider':'a'}), {'b':N+1})
check('fatal contract', solve('fatal', {'fallback':[N],'fatal':True}), [])
check('retry-budget contract', solve('retry-budget', {'budget':N+4,'attempts':3}), N+1)
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| isolate contract | [{'id': 2, 'provider': 'b'}] | [{'id': 2, 'provider': 'b'}] | Passed |
| fallback contract | [1] | [1] | Passed |
| error-record contract | {'code': 'parse', 'generation': 1, 'provider': 'child'} | {'code': 'parse', 'generation': 1, 'provider': 'child'} | Passed |
| recovery contract | {'b': 2} | {'b': 2} | Passed |
| fatal contract | [1] | [] | Failed |
| retry-budget contract | 2 | 2 | Passed |
| unknown operation | {'error': 'unsupported menu operation'} | {'error': 'unsupported menu operation'} | Passed |
SHA-256 / 5c50b9f4926b7c2d1aef831c664163594257689d68ebc3f5a7d58f5c2bb8a20a
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
if action == 'isolate':
return [x for x in p['rows'] if x['provider']!=p['failed']]
if action == 'fallback':
return p['fallback'] if p['failed'] else p['content']
if action == 'error-record':
return {'provider':p['provider'],'code':p['code'],'generation':p['generation']}
if action == 'recovery':
return {k:v for k,v in p['errors'].items() if k!=p['provider']}
if action == 'fatal':
return p['fallback'] if not p['fatal'] else []
if action == 'retry-budget':
return max(0,p['budget']-p['attempts'])
return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('isolate contract', solve('isolate', {'rows':[{'provider':'a','id':N},{'provider':'b','id':N+1}],'failed':'a'}), [{'provider':'b','id':N+1}])
check('fallback contract', solve('fallback', {'failed':True,'fallback':[N],'content':[N+1]}), [N])
check('error-record contract', solve('error-record', {'provider':'child','root':'root','code':'parse','generation':N}), {'provider':'child','code':'parse','generation':N})
check('recovery contract', solve('recovery', {'errors':{'a':N,'b':N+1},'provider':'a'}), {'b':N+1})
check('fatal contract', solve('fatal', {'fallback':[N],'fatal':True}), [])
check('retry-budget contract', solve('retry-budget', {'budget':N+4,'attempts':3}), N+1)
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| isolate contract | [{'id': 2, 'provider': 'b'}] | [{'id': 2, 'provider': 'b'}] | Passed |
| fallback contract | [1] | [1] | Passed |
| error-record contract | {'code': 'parse', 'generation': 1, 'provider': 'child'} | {'code': 'parse', 'generation': 1, 'provider': 'child'} | Passed |
| recovery contract | {'b': 2} | {'b': 2} | Passed |
| fatal contract | [] | [] | Passed |
| retry-budget contract | 2 | 2 | Passed |
| unknown operation | {'error': 'unsupported menu operation'} | {'error': 'unsupported menu operation'} | Passed |
SHA-256 / 44cff4c146a29b2f1b1931cddf3828115c1b1f56dc741a80369330057c847753
Verification & scope
Offline supplied-valid-payload model; excludes DOM, keyboard, focus, selection, announcements and browser conformance. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:42:24.720440+00:00.
Case digest / fff6c55308011a0c677092b0efea0c0742dd7f0f52fc4355cc3334f4c897e41c