FA-33696 / Menu interactions / Open access
Cancelled menu confirmation leaves an executable pending intent · case 01
Cancelled menu confirmation leaves an executable pending intent.
ROOT CAUSE
The menu-command-confirmation model applies `p['pending']` at its cancel operation instead of the stipulated transformation.
VERIFIED REPAIR
Apply `None` at cancel.
Unsuccessful approach: The attempted repair `{'cancelled':True,'intent':p['pending']}` still violates the cancel oracle.
Case contract
A confirmation launched from a menu freezes command intent; confirm executes exactly that intent, cancellation discards it, and stale documents require reconfirmation.
Why this case matters
Cascading and context menus require coherent command and session state as content changes.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
if action == 'intent':
return {'command':p['command'],'targets':p['captured'],'arguments':p['arguments']}
if action == 'cancel':
return p['pending']
if action == 'consume':
return {'execute':p['intent'],'pending':None}
if action == 'revision':
return 'execute' if p['captured_revision']==p['live_revision'] else 'reconfirm'
if action == 'destructive-count':
return sum(x['destructive'] for x in p)
if action == 'return-menu':
return p['menu'] if p['menu_live'] else None
return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('intent contract', solve('intent', {'command':'delete','captured':[N],'current':[N+1],'arguments':{'permanent':True}}), {'command':'delete','targets':[N],'arguments':{'permanent':True}})
check('cancel contract', solve('cancel', {'pending':{'target':N}}), None)
check('consume contract', solve('consume', {'intent':{'id':N}}), {'execute':{'id':N},'pending':None})
check('revision contract', solve('revision', {'captured_revision':N,'live_revision':N+1}), 'reconfirm')
check('destructive-count contract', solve('destructive-count', [{'destructive':True,'id':N},{'destructive':True,'id':N+1},{'destructive':False,'id':N+2}]), 2)
check('return-menu contract', solve('return-menu', {'menu':N,'menu_live':False,'fallback':'root'}), None)
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| intent contract | {'arguments': {'permanent': True}, 'command': 'delete', 'targets': [1]} | {'arguments': {'permanent': True}, 'command': 'delete', 'targets': [1]} | Passed |
| cancel contract | {'target': 1} | None | Failed |
| consume contract | {'execute': {'id': 1}, 'pending': None} | {'execute': {'id': 1}, 'pending': None} | Passed |
| revision contract | reconfirm | reconfirm | Passed |
| destructive-count contract | 2 | 2 | Passed |
| return-menu contract | None | None | Passed |
| unknown operation | {'error': 'unsupported menu operation'} | {'error': 'unsupported menu operation'} | Passed |
SHA-256 / c7c17aa82d70d8334b0ad88e226f9602a37442b492aabaaa8d95bdb9534b08e7
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
if action == 'intent':
return {'command':p['command'],'targets':p['captured'],'arguments':p['arguments']}
if action == 'cancel':
return {'cancelled':True,'intent':p['pending']}
if action == 'consume':
return {'execute':p['intent'],'pending':None}
if action == 'revision':
return 'execute' if p['captured_revision']==p['live_revision'] else 'reconfirm'
if action == 'destructive-count':
return sum(x['destructive'] for x in p)
if action == 'return-menu':
return p['menu'] if p['menu_live'] else None
return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('intent contract', solve('intent', {'command':'delete','captured':[N],'current':[N+1],'arguments':{'permanent':True}}), {'command':'delete','targets':[N],'arguments':{'permanent':True}})
check('cancel contract', solve('cancel', {'pending':{'target':N}}), None)
check('consume contract', solve('consume', {'intent':{'id':N}}), {'execute':{'id':N},'pending':None})
check('revision contract', solve('revision', {'captured_revision':N,'live_revision':N+1}), 'reconfirm')
check('destructive-count contract', solve('destructive-count', [{'destructive':True,'id':N},{'destructive':True,'id':N+1},{'destructive':False,'id':N+2}]), 2)
check('return-menu contract', solve('return-menu', {'menu':N,'menu_live':False,'fallback':'root'}), None)
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| intent contract | {'arguments': {'permanent': True}, 'command': 'delete', 'targets': [1]} | {'arguments': {'permanent': True}, 'command': 'delete', 'targets': [1]} | Passed |
| cancel contract | {'cancelled': True, 'intent': {'target': 1}} | None | Failed |
| consume contract | {'execute': {'id': 1}, 'pending': None} | {'execute': {'id': 1}, 'pending': None} | Passed |
| revision contract | reconfirm | reconfirm | Passed |
| destructive-count contract | 2 | 2 | Passed |
| return-menu contract | None | None | Passed |
| unknown operation | {'error': 'unsupported menu operation'} | {'error': 'unsupported menu operation'} | Passed |
SHA-256 / 29eec58fdbacad5b59e935ea402f69c7427d7a408b61f526c33e33430251c4d7
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
if action == 'intent':
return {'command':p['command'],'targets':p['captured'],'arguments':p['arguments']}
if action == 'cancel':
return None
if action == 'consume':
return {'execute':p['intent'],'pending':None}
if action == 'revision':
return 'execute' if p['captured_revision']==p['live_revision'] else 'reconfirm'
if action == 'destructive-count':
return sum(x['destructive'] for x in p)
if action == 'return-menu':
return p['menu'] if p['menu_live'] else None
return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('intent contract', solve('intent', {'command':'delete','captured':[N],'current':[N+1],'arguments':{'permanent':True}}), {'command':'delete','targets':[N],'arguments':{'permanent':True}})
check('cancel contract', solve('cancel', {'pending':{'target':N}}), None)
check('consume contract', solve('consume', {'intent':{'id':N}}), {'execute':{'id':N},'pending':None})
check('revision contract', solve('revision', {'captured_revision':N,'live_revision':N+1}), 'reconfirm')
check('destructive-count contract', solve('destructive-count', [{'destructive':True,'id':N},{'destructive':True,'id':N+1},{'destructive':False,'id':N+2}]), 2)
check('return-menu contract', solve('return-menu', {'menu':N,'menu_live':False,'fallback':'root'}), None)
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| intent contract | {'arguments': {'permanent': True}, 'command': 'delete', 'targets': [1]} | {'arguments': {'permanent': True}, 'command': 'delete', 'targets': [1]} | Passed |
| cancel contract | None | None | Passed |
| consume contract | {'execute': {'id': 1}, 'pending': None} | {'execute': {'id': 1}, 'pending': None} | Passed |
| revision contract | reconfirm | reconfirm | Passed |
| destructive-count contract | 2 | 2 | Passed |
| return-menu contract | None | None | Passed |
| unknown operation | {'error': 'unsupported menu operation'} | {'error': 'unsupported menu operation'} | Passed |
SHA-256 / 4a26eb3598423d13c1ff1ba81eed79ec8b5189741b3f8d7b5c63f13dc555c5e7
Verification & scope
Offline supplied-valid-payload model; excludes DOM, keyboard, focus, selection, announcements and browser conformance. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:42:24.812782+00:00.
Case digest / df0e19263a4656ddef67a830ec269e5c60fed1cdf90f7bb876b3b6b46bfb102e