FAILURE MAP
← Case archive

FA-33831 / Menu interactions / Open access

Menu usage event leaks captured command arguments · case 01

Menu usage event leaks captured command arguments.

Verified by executionVariant 1 · 7 checks per implementationDownload source bundle ↓JSON ↗

ROOT CAUSE

The menu-usage-accounting model applies `p` at its arguments operation instead of the stipulated transformation.

THE FAILURE

The menu-usage-accounting model applies `p` at its arguments operation instead of the stipulated transformation.

Unsuccessful approach: The attempted repair `{k:v for k,v in p.items() if k!='target'}` still violates the arguments oracle.

Case contract

Menu metrics distinguish impressions, command invocation and completed execution; root sessions and menu paths remain separate dimensions and sensitive arguments are excluded.

Why this case matters

Cascading and context menus require coherent command and session state as content changes.

1 / The failure

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
    if action == 'impression-once':
        return len(set(p))
    if action == 'invoked-vs-success':
        return {'invoked':len(p),'succeeded':sum(x['success'] for x in p)}
    if action == 'path-dimension':
        return '/'.join(p['path'])
    if action == 'duration':
        return max(0,p['closed']-p['opened'])
    if action == 'arguments':
        return p
    if action == 'session-count':
        return len({x['root_session'] for x in p})
    return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('impression-once contract', solve('impression-once', [N,N,N+1]), 2)
check('invoked-vs-success contract', solve('invoked-vs-success', [{'success':True,'id':N},{'success':False,'id':N+1}]), {'invoked':2,'succeeded':1})
check('path-dimension contract', solve('path-dimension', {'path':['root','tools',str(N)]}), 'root/tools/'+str(N))
check('duration contract', solve('duration', {'opened':N,'closed':N+7}), 7)
check('arguments contract', solve('arguments', {'command':'copy','path':['root'], 'arguments':{'doc':N},'target':'doc'}), {'command':'copy','path':['root']})
check('session-count contract', solve('session-count', [{'root_session':N,'surface':'a'},{'root_session':N,'surface':'b'}]), 1)
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
impression-once contract22Passed
invoked-vs-success contract{'invoked': 2, 'succeeded': 1}{'invoked': 2, 'succeeded': 1}Passed
path-dimension contractroot/tools/1root/tools/1Passed
duration contract77Passed
arguments contract{'arguments': {'doc': 1}, 'command': 'copy', 'path': ['root'], 'target': 'doc'}{'command': 'copy', 'path': ['root']}Failed
session-count contract11Passed
unknown operation{'error': 'unsupported menu operation'}{'error': 'unsupported menu operation'}Passed

SHA-256 / 3ac34e2caa80aae131f3a6afb4825e40fb26561e1a063ec93b2087fc274140fc

2 / The unsuccessful fix

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json
import math
import unicodedata
N = 1
observations = []
def solve(action, p):
    if action == 'impression-once':
        return len(set(p))
    if action == 'invoked-vs-success':
        return {'invoked':len(p),'succeeded':sum(x['success'] for x in p)}
    if action == 'path-dimension':
        return '/'.join(p['path'])
    if action == 'duration':
        return max(0,p['closed']-p['opened'])
    if action == 'arguments':
        return {k:v for k,v in p.items() if k!='target'}
    if action == 'session-count':
        return len({x['root_session'] for x in p})
    return {'error': 'unsupported menu operation'}
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('impression-once contract', solve('impression-once', [N,N,N+1]), 2)
check('invoked-vs-success contract', solve('invoked-vs-success', [{'success':True,'id':N},{'success':False,'id':N+1}]), {'invoked':2,'succeeded':1})
check('path-dimension contract', solve('path-dimension', {'path':['root','tools',str(N)]}), 'root/tools/'+str(N))
check('duration contract', solve('duration', {'opened':N,'closed':N+7}), 7)
check('arguments contract', solve('arguments', {'command':'copy','path':['root'], 'arguments':{'doc':N},'target':'doc'}), {'command':'copy','path':['root']})
check('session-count contract', solve('session-count', [{'root_session':N,'surface':'a'},{'root_session':N,'surface':'b'}]), 1)
check('unknown operation', solve('unknown', {}), {'error': 'unsupported menu operation'})
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
impression-once contract22Passed
invoked-vs-success contract{'invoked': 2, 'succeeded': 1}{'invoked': 2, 'succeeded': 1}Passed
path-dimension contractroot/tools/1root/tools/1Passed
duration contract77Passed
arguments contract{'arguments': {'doc': 1}, 'command': 'copy', 'path': ['root']}{'command': 'copy', 'path': ['root']}Failed
session-count contract11Passed
unknown operation{'error': 'unsupported menu operation'}{'error': 'unsupported menu operation'}Passed

SHA-256 / 97487ec2afb0f0650d59f3095732a78472a9d3700ba3f8413ab7d6d3a90b16f1

HELD IN THE MEMBER ARCHIVE

The verified repair and its recorded checks are member-only.

This mechanism has 7 recorded checks per implementation. The open-access tier publishes the failure and the unsuccessful fix; the repaired source that passes every check, and the observations that prove it, are available to members.

Every case sharing this mechanism uses the same contract and the same repair, so this one record is held back for all of them.

Member access is invitation-based. Sign in with your invited account to inspect the repair.

Sign in to the archive ↗

Verification & scope

Offline supplied-valid-payload model; excludes DOM, keyboard, focus, selection, announcements and browser conformance. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.

Observations recorded using Python 3.12.14 at 2026-09-29T14:42:26.125757+00:00.

Case digest / 9319828b073973992d44e96a5bb8d403c01a01a8d226c2d675c98ac16af4c455