FAILURE MAP
← Case archive

FA-53526 / Accessibility interaction semantics / Open access

Unloaded embedded documents expose cached children · case 01

Unloaded embedded documents expose cached children.

Verified by executionVariant 1 · 7 checks per implementationDownload source bundle ↓JSON ↗

ROOT CAUSE

The load barrier decision in the embedded document adapter violates its declared contract.

THE FAILURE

The load barrier decision in the embedded document adapter violates its declared contract.

Unsuccessful approach: The local repair substitutes can = (loaded or same) and allowed and bool(child) and child != doc but still mishandles the regression fixtures.

Case contract

Input [host_id,host_doc,child_doc,loaded,same_origin,allow_read,host_name,child_title,children,defunct]. Return None if defunct. Otherwise return a host bridge object. Child document may only be traversed when loaded and allow_read; same_origin alone grants no reading. Expose children in original order, including repeated distinct IDs, prefixed with child_doc and colon; child document ID cannot be empty or equal to host document. Name prefers a nonempty host name, then child title only if traversal allowed, otherwise empty. Busy means not loaded; unavailable means loaded but traversal forbidden. Relation is [host_id,child_doc] only for traversable children. Source lists never include the host itself.

Why this case matters

Offline accessibility bridge model with explicit policy; useful for testing semantic API adapters independently of browser implementations.

1 / The failure

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(data):
    host,doc,child,loaded,same,allowed,name,title,children,dead = data
    if dead: return None
    can = allowed and bool(child) and child != doc
    safe = [ident for ident in children if ident != host]
    return {'id':host,'name':name if name else (title if can else ''),'busy':not loaded,'unavailable':loaded and not can,'children':[child+':'+ident for ident in safe] if can else [],'relation':[host,child] if can else None}
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('allowed foreign document', solve(['host','d','c',True,False,True,'','Title'+str(N),['a','b','a'],False],), {'id':'host','name':'Title'+str(N),'busy':False,'unavailable':False,'children':['c:a','c:b','c:a'],'relation':['host','c']})
check('same origin no permission', solve(['host','d','c',True,True,False,'','Secret',['a'],False],), {'id':'host','name':'','busy':False,'unavailable':True,'children':[],'relation':None})
check('not loaded', solve(['host','d','c',False,True,True,'Frame','Title',['a'],False],), {'id':'host','name':'Frame','busy':True,'unavailable':False,'children':[],'relation':None})
check('dead host', solve(['host','d','c',True,True,True,'Frame','Title',['a'],True],), None)
check('self document', solve(['host','d','d',True,True,True,'Frame','Title',['a'],False],), {'id':'host','name':'Frame','busy':False,'unavailable':True,'children':[],'relation':None})
check('empty child identifier', solve(['host','d','',True,True,True,'Frame','Title',['a'],False],), {'id':'host','name':'Frame','busy':False,'unavailable':True,'children':[],'relation':None})
check('host filtered', solve(['host','d','c',True,True,True,'Frame','Title',['a','host','b'],False],), {'id':'host','name':'Frame','busy':False,'unavailable':False,'children':['c:a','c:b'],'relation':['host','c']})
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
allowed foreign document{'busy': False, 'children': ['c:a', 'c:b', 'c:a'], 'id': 'host', 'name': 'Title1', 'relation': ['host', 'c'], 'unavailable': False}{'busy': False, 'children': ['c:a', 'c:b', 'c:a'], 'id': 'host', 'name': 'Title1', 'relation': ['host', 'c'], 'unavailable': False}Passed
same origin no permission{'busy': False, 'children': [], 'id': 'host', 'name': '', 'relation': None, 'unavailable': True}{'busy': False, 'children': [], 'id': 'host', 'name': '', 'relation': None, 'unavailable': True}Passed
not loaded{'busy': True, 'children': ['c:a'], 'id': 'host', 'name': 'Frame', 'relation': ['host', 'c'], 'unavailable': False}{'busy': True, 'children': [], 'id': 'host', 'name': 'Frame', 'relation': None, 'unavailable': False}Failed
dead hostNoneNonePassed
self document{'busy': False, 'children': [], 'id': 'host', 'name': 'Frame', 'relation': None, 'unavailable': True}{'busy': False, 'children': [], 'id': 'host', 'name': 'Frame', 'relation': None, 'unavailable': True}Passed
empty child identifier{'busy': False, 'children': [], 'id': 'host', 'name': 'Frame', 'relation': None, 'unavailable': True}{'busy': False, 'children': [], 'id': 'host', 'name': 'Frame', 'relation': None, 'unavailable': True}Passed
host filtered{'busy': False, 'children': ['c:a', 'c:b'], 'id': 'host', 'name': 'Frame', 'relation': ['host', 'c'], 'unavailable': False}{'busy': False, 'children': ['c:a', 'c:b'], 'id': 'host', 'name': 'Frame', 'relation': ['host', 'c'], 'unavailable': False}Passed

SHA-256 / f62b93fb1bc217465a84fd66a91b79ea3a6a373bd91aaa193d68d5c211722a23

2 / The unsuccessful fix

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(data):
    host,doc,child,loaded,same,allowed,name,title,children,dead = data
    if dead: return None
    can = (loaded or same) and allowed and bool(child) and child != doc
    safe = [ident for ident in children if ident != host]
    return {'id':host,'name':name if name else (title if can else ''),'busy':not loaded,'unavailable':loaded and not can,'children':[child+':'+ident for ident in safe] if can else [],'relation':[host,child] if can else None}
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
check('allowed foreign document', solve(['host','d','c',True,False,True,'','Title'+str(N),['a','b','a'],False],), {'id':'host','name':'Title'+str(N),'busy':False,'unavailable':False,'children':['c:a','c:b','c:a'],'relation':['host','c']})
check('same origin no permission', solve(['host','d','c',True,True,False,'','Secret',['a'],False],), {'id':'host','name':'','busy':False,'unavailable':True,'children':[],'relation':None})
check('not loaded', solve(['host','d','c',False,True,True,'Frame','Title',['a'],False],), {'id':'host','name':'Frame','busy':True,'unavailable':False,'children':[],'relation':None})
check('dead host', solve(['host','d','c',True,True,True,'Frame','Title',['a'],True],), None)
check('self document', solve(['host','d','d',True,True,True,'Frame','Title',['a'],False],), {'id':'host','name':'Frame','busy':False,'unavailable':True,'children':[],'relation':None})
check('empty child identifier', solve(['host','d','',True,True,True,'Frame','Title',['a'],False],), {'id':'host','name':'Frame','busy':False,'unavailable':True,'children':[],'relation':None})
check('host filtered', solve(['host','d','c',True,True,True,'Frame','Title',['a','host','b'],False],), {'id':'host','name':'Frame','busy':False,'unavailable':False,'children':['c:a','c:b'],'relation':['host','c']})
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
allowed foreign document{'busy': False, 'children': ['c:a', 'c:b', 'c:a'], 'id': 'host', 'name': 'Title1', 'relation': ['host', 'c'], 'unavailable': False}{'busy': False, 'children': ['c:a', 'c:b', 'c:a'], 'id': 'host', 'name': 'Title1', 'relation': ['host', 'c'], 'unavailable': False}Passed
same origin no permission{'busy': False, 'children': [], 'id': 'host', 'name': '', 'relation': None, 'unavailable': True}{'busy': False, 'children': [], 'id': 'host', 'name': '', 'relation': None, 'unavailable': True}Passed
not loaded{'busy': True, 'children': ['c:a'], 'id': 'host', 'name': 'Frame', 'relation': ['host', 'c'], 'unavailable': False}{'busy': True, 'children': [], 'id': 'host', 'name': 'Frame', 'relation': None, 'unavailable': False}Failed
dead hostNoneNonePassed
self document{'busy': False, 'children': [], 'id': 'host', 'name': 'Frame', 'relation': None, 'unavailable': True}{'busy': False, 'children': [], 'id': 'host', 'name': 'Frame', 'relation': None, 'unavailable': True}Passed
empty child identifier{'busy': False, 'children': [], 'id': 'host', 'name': 'Frame', 'relation': None, 'unavailable': True}{'busy': False, 'children': [], 'id': 'host', 'name': 'Frame', 'relation': None, 'unavailable': True}Passed
host filtered{'busy': False, 'children': ['c:a', 'c:b'], 'id': 'host', 'name': 'Frame', 'relation': ['host', 'c'], 'unavailable': False}{'busy': False, 'children': ['c:a', 'c:b'], 'id': 'host', 'name': 'Frame', 'relation': ['host', 'c'], 'unavailable': False}Passed

SHA-256 / 5470889e86da9d3456fe9936f61df3ed7d1203af035a37bcb0f69c6a24169886

HELD IN THE MEMBER ARCHIVE

The verified repair and its recorded checks are member-only.

This mechanism has 7 recorded checks per implementation. The open-access tier publishes the failure and the unsuccessful fix; the repaired source that passes every check, and the observations that prove it, are available to members.

Every case sharing this mechanism uses the same contract and the same repair, so this one record is held back for all of them.

Member access is invitation-based. Sign in with your invited account to inspect the repair.

Sign in to the archive ↗

Verification & scope

Stipulated finite adapter contract, not a claim of platform accessibility or ARIA conformance. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.

Observations recorded using Python 3.12.14 at 2026-09-29T14:45:40.110418+00:00.

Case digest / bdb965b0fcb8e8994a91c084d1e003bd2598f5b6c27efdf5f09823f9136cd776