{"abstract":"Store addresses use the source register number as the low offset bits.","category":"Instruction set emulation","checks":10,"contract":"Input [word]: a 32-bit instruction. By opcode (low 7 bits): I-type 0x13/0x03/0x67 imm = sext(word[31:20]); S-type 0x23 imm = sext(word[31:25]:word[11:7]); B-type 0x63 imm = sext(word[31]:word[7]:word[30:25]:word[11:8]:0) (13 bits); U-type 0x37/0x17 imm = word & 0xFFFFF000 as signed 32-bit; J-type 0x6F imm = sext(word[31]:word[19:12]:word[20]:word[30:21]:0) (21 bits). Return [format, imm].","contract_signature":"*args","evaluation_group":"w2-instruction-set-emulation-rv-immediates","failed_approach":"A six-bit mask pulls funct3 bit 12 into the offset.","family":"w2-instruction-set-emulation-rv-immediates-s-type-low-field","id":"FA-89446","implementations":{"attempt":{"sha256":"b7ee7cf43e17b506801bd92106da2dbb20279994ae251a38cc82303f3727813b","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(*args):\n    word = args[0]\n    op = word & 0x7F\n    def sx(v, bits):\n        return v - (1 << bits) if v >> (bits - 1) & 1 else v\n    if op in (0x13, 0x03, 0x67):\n        return ['I', sx(word >> 20, 12)]\n    if op == 0x23:\n        return ['S', sx(((word >> 25) << 5) | ((word >> 7) & 0x3F), 12)]\n    if op == 0x63:\n        v = ((word >> 31) & 1) << 12 | ((word >> 7) & 1) << 11 | ((word >> 25) & 0x3F) << 5 | ((word >> 8) & 0xF) << 1\n        return ['B', sx(v, 13)]\n    if op in (0x37, 0x17):\n        return ['U', sx(word & 0xFFFFF000, 32)]\n    if op == 0x6F:\n        v = ((word >> 31) & 1) << 20 | ((word >> 12) & 0xFF) << 12 | ((word >> 20) & 1) << 11 | ((word >> 21) & 0x3FF) << 1\n        return ['J', sx(v, 21)]\n    return ['?', 0]\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\nfixtures = [[('addi negative immediate', [4255351443], ['I', -38]), ('load positive immediate', [2145494147], ['I', 2046]), ('store negative offset', [2180064931], ['S', -2035]), ('store small offset with funct3', [8516259], ['S', 5]), ('branch backward', [2149634403], ['B', -4094]), ('branch forward bit 11 set', [4293091], ['B', 2050]), ('lui upper immediate negative', [4294960439], ['U', -8192]), ('auipc upper immediate positive', [305422487], ['U', 305422336]), ('jal backward', [3246387439], ['J', -1002]), ('jal forward large', [2093167], ['J', 1046528])], [('addi negative immediate', [4216554131], ['I', -75]), ('load positive immediate', [2144445571], ['I', 2045]), ('store negative offset', [2180066595], ['S', -2022]), ('store small offset with funct3', [8516387], ['S', 6]), ('branch backward', [2149634659], ['B', -4092]), ('branch forward bit 11 set', [4293347], ['B', 2052]), ('lui upper immediate negative', [4294956343], ['U', -12288]), ('auipc upper immediate positive', [305426583], ['U', 305426432]), ('jal backward', [2197811439], ['J', -2002]), ('jal forward large', [3141743], ['J', 1044482])], [('addi negative immediate', [4177756819], ['I', -112]), ('load positive immediate', [2143396995], ['I', 2044]), ('store negative offset', [2213618595], ['S', -2009]), ('store small offset with funct3', [8516515], ['S', 7]), ('branch backward', [2149634915], ['B', -4090]), ('branch forward bit 11 set', [4293603], ['B', 2054]), ('lui upper immediate negative', [4294952247], ['U', -16384]), ('auipc upper immediate positive', [305430679], ['U', 305430528]), ('jal backward', [3295670511], ['J', -3002]), ('jal forward large', [6283375], ['J', 1042436])], [('addi negative immediate', [4138959507], ['I', -149]), ('load positive immediate', [2142348419], ['I', 2043]), ('store negative offset', [2213620259], ['S', -1996]), ('store small offset with funct3', [8516643], ['S', 8]), ('branch backward', [2149635171], ['B', -4088]), ('branch forward bit 11 set', [4293859], ['B', 2056]), ('lui upper immediate negative', [4294948151], ['U', -20480]), ('auipc upper immediate positive', [305434775], ['U', 305434624]), ('jal backward', [2247094511], ['J', -4002]), ('jal forward large', [7331951], ['J', 1040390])], [('addi negative immediate', [4100162195], ['I', -186]), ('load positive immediate', [2141299843], ['I', 2042]), ('store negative offset', [2247172259], ['S', -1983]), ('store small offset with funct3', [8516771], ['S', 9]), ('branch backward', [2149635427], ['B', -4086]), ('branch forward bit 11 set', [4294115], ['B', 2058]), ('lui upper immediate negative', [4294944055], ['U', -24576]), ('auipc upper immediate positive', [305438871], ['U', 305438720]), ('jal backward', [3347046639], ['J', -5002]), ('jal forward large', [10473583], ['J', 1038344])]]\nfor label, args, expected in fixtures[N-1]:\n    check(label, solve(*args), expected)\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"},"broken":{"sha256":"f7ca6ab2ec850eea91d0277464733f0eeedf13b45bf08e7238e9349e1b74154f","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(*args):\n    word = args[0]\n    op = word & 0x7F\n    def sx(v, bits):\n        return v - (1 << bits) if v >> (bits - 1) & 1 else v\n    if op in (0x13, 0x03, 0x67):\n        return ['I', sx(word >> 20, 12)]\n    if op == 0x23:\n        return ['S', sx(((word >> 25) << 5) | ((word >> 20) & 0x1F), 12)]\n    if op == 0x63:\n        v = ((word >> 31) & 1) << 12 | ((word >> 7) & 1) << 11 | ((word >> 25) & 0x3F) << 5 | ((word >> 8) & 0xF) << 1\n        return ['B', sx(v, 13)]\n    if op in (0x37, 0x17):\n        return ['U', sx(word & 0xFFFFF000, 32)]\n    if op == 0x6F:\n        v = ((word >> 31) & 1) << 20 | ((word >> 12) & 0xFF) << 12 | ((word >> 20) & 1) << 11 | ((word >> 21) & 0x3FF) << 1\n        return ['J', sx(v, 21)]\n    return ['?', 0]\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\nfixtures = [[('addi negative immediate', [4255351443], ['I', -38]), ('load positive immediate', [2145494147], ['I', 2046]), ('store negative offset', [2180064931], ['S', -2035]), ('store small offset with funct3', [8516259], ['S', 5]), ('branch backward', [2149634403], ['B', -4094]), ('branch forward bit 11 set', [4293091], ['B', 2050]), ('lui upper immediate negative', [4294960439], ['U', -8192]), ('auipc upper immediate positive', [305422487], ['U', 305422336]), ('jal backward', [3246387439], ['J', -1002]), ('jal forward large', [2093167], ['J', 1046528])], [('addi negative immediate', [4216554131], ['I', -75]), ('load positive immediate', [2144445571], ['I', 2045]), ('store negative offset', [2180066595], ['S', -2022]), ('store small offset with funct3', [8516387], ['S', 6]), ('branch backward', [2149634659], ['B', -4092]), ('branch forward bit 11 set', [4293347], ['B', 2052]), ('lui upper immediate negative', [4294956343], ['U', -12288]), ('auipc upper immediate positive', [305426583], ['U', 305426432]), ('jal backward', [2197811439], ['J', -2002]), ('jal forward large', [3141743], ['J', 1044482])], [('addi negative immediate', [4177756819], ['I', -112]), ('load positive immediate', [2143396995], ['I', 2044]), ('store negative offset', [2213618595], ['S', -2009]), ('store small offset with funct3', [8516515], ['S', 7]), ('branch backward', [2149634915], ['B', -4090]), ('branch forward bit 11 set', [4293603], ['B', 2054]), ('lui upper immediate negative', [4294952247], ['U', -16384]), ('auipc upper immediate positive', [305430679], ['U', 305430528]), ('jal backward', [3295670511], ['J', -3002]), ('jal forward large', [6283375], ['J', 1042436])], [('addi negative immediate', [4138959507], ['I', -149]), ('load positive immediate', [2142348419], ['I', 2043]), ('store negative offset', [2213620259], ['S', -1996]), ('store small offset with funct3', [8516643], ['S', 8]), ('branch backward', [2149635171], ['B', -4088]), ('branch forward bit 11 set', [4293859], ['B', 2056]), ('lui upper immediate negative', [4294948151], ['U', -20480]), ('auipc upper immediate positive', [305434775], ['U', 305434624]), ('jal backward', [2247094511], ['J', -4002]), ('jal forward large', [7331951], ['J', 1040390])], [('addi negative immediate', [4100162195], ['I', -186]), ('load positive immediate', [2141299843], ['I', 2042]), ('store negative offset', [2247172259], ['S', -1983]), ('store small offset with funct3', [8516771], ['S', 9]), ('branch backward', [2149635427], ['B', -4086]), ('branch forward bit 11 set', [4294115], ['B', 2058]), ('lui upper immediate negative', [4294944055], ['U', -24576]), ('auipc upper immediate positive', [305438871], ['U', 305438720]), ('jal backward', [3347046639], ['J', -5002]), ('jal forward large', [10473583], ['J', 1038344])]]\nfor label, args, expected in fixtures[N-1]:\n    check(label, solve(*args), expected)\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"}},"limitations":"A deterministic bounded teaching model of one emulator rule; the instruction semantics are a stipulated contract inspired by common ISAs and are not a claim of cycle-exact or architectural conformance. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.","method":"Deterministic executable model with adversarial boundary fixtures.","provenance":{"created_by":"Failure Map","dependencies":"Python standard library","family":"w2-instruction-set-emulation-rv-immediates-s-type-low-field","generated_at":"2026-09-29T14:51:17.534472+00:00","license":"CC0-1.0","python":"3.12.14","seed":1,"split":"open-access"},"relevance":"Instruction decoders reassemble scattered immediate bits; a single misplaced bit sends branches and stores to the wrong address.","root_cause":"The S-type immediate is assembled like an I-type, reading bits 24:20.","sha256":"4d51156653eb2de91c08b0857382df3995a50c908c5f5ecb8ef3aeed71800f89","title":"Store offset low bits taken from the rs2 field · case 01","variant":1,"variant_policy":"Five numbered records share a model and may reuse boundary fixtures.","verified":true,"visibility":"public","verification":{"attempt":{"elapsed_ms":40.27,"exit_code":1,"observations":[{"actual":["I",-38],"check":"addi negative immediate","expected":["I",-38],"passed":true},{"actual":["I",2046],"check":"load positive immediate","expected":["I",2046],"passed":true},{"actual":["S",-2035],"check":"store negative offset","expected":["S",-2035],"passed":true},{"actual":["S",37],"check":"store small offset with funct3","expected":["S",5],"passed":false},{"actual":["B",-4094],"check":"branch backward","expected":["B",-4094],"passed":true},{"actual":["B",2050],"check":"branch forward bit 11 set","expected":["B",2050],"passed":true},{"actual":["U",-8192],"check":"lui upper immediate negative","expected":["U",-8192],"passed":true},{"actual":["U",305422336],"check":"auipc upper immediate positive","expected":["U",305422336],"passed":true},{"actual":["J",-1002],"check":"jal backward","expected":["J",-1002],"passed":true},{"actual":["J",1046528],"check":"jal forward large","expected":["J",1046528],"passed":true}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"addi negative immediate\", \"actual\": [\"I\", -38], \"expected\": [\"I\", -38], \"passed\": true}, {\"check\": \"load positive immediate\", \"actual\": [\"I\", 2046], \"expected\": [\"I\", 2046], \"passed\": true}, {\"check\": \"store negative offset\", \"actual\": [\"S\", -2035], \"expected\": [\"S\", -2035], \"passed\": true}, {\"check\": \"store small offset with funct3\", \"actual\": [\"S\", 37], \"expected\": [\"S\", 5], \"passed\": false}, {\"check\": \"branch backward\", \"actual\": [\"B\", -4094], \"expected\": [\"B\", -4094], \"passed\": true}, {\"check\": \"branch forward bit 11 set\", \"actual\": [\"B\", 2050], \"expected\": [\"B\", 2050], \"passed\": true}, {\"check\": \"lui upper immediate negative\", \"actual\": [\"U\", -8192], \"expected\": [\"U\", -8192], \"passed\": true}, {\"check\": \"auipc upper immediate positive\", \"actual\": [\"U\", 305422336], \"expected\": [\"U\", 305422336], \"passed\": true}, {\"check\": \"jal backward\", \"actual\": [\"J\", -1002], \"expected\": [\"J\", -1002], \"passed\": true}, {\"check\": \"jal forward large\", \"actual\": [\"J\", 1046528], \"expected\": [\"J\", 1046528], \"passed\": true}], \"passed\": false}\n"},"broken":{"elapsed_ms":41.767,"exit_code":1,"observations":[{"actual":["I",-38],"check":"addi negative immediate","expected":["I",-38],"passed":true},{"actual":["I",2046],"check":"load positive immediate","expected":["I",2046],"passed":true},{"actual":["S",-2017],"check":"store negative offset","expected":["S",-2035],"passed":false},{"actual":["S",8],"check":"store small offset with funct3","expected":["S",5],"passed":false},{"actual":["B",-4094],"check":"branch backward","expected":["B",-4094],"passed":true},{"actual":["B",2050],"check":"branch forward bit 11 set","expected":["B",2050],"passed":true},{"actual":["U",-8192],"check":"lui upper immediate negative","expected":["U",-8192],"passed":true},{"actual":["U",305422336],"check":"auipc upper immediate positive","expected":["U",305422336],"passed":true},{"actual":["J",-1002],"check":"jal backward","expected":["J",-1002],"passed":true},{"actual":["J",1046528],"check":"jal forward large","expected":["J",1046528],"passed":true}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"addi negative immediate\", \"actual\": [\"I\", -38], \"expected\": [\"I\", -38], \"passed\": true}, {\"check\": \"load positive immediate\", \"actual\": [\"I\", 2046], \"expected\": [\"I\", 2046], \"passed\": true}, {\"check\": \"store negative offset\", \"actual\": [\"S\", -2017], \"expected\": [\"S\", -2035], \"passed\": false}, {\"check\": \"store small offset with funct3\", \"actual\": [\"S\", 8], \"expected\": [\"S\", 5], \"passed\": false}, {\"check\": \"branch backward\", \"actual\": [\"B\", -4094], \"expected\": [\"B\", -4094], \"passed\": true}, {\"check\": \"branch forward bit 11 set\", \"actual\": [\"B\", 2050], \"expected\": [\"B\", 2050], \"passed\": true}, {\"check\": \"lui upper immediate negative\", \"actual\": [\"U\", -8192], \"expected\": [\"U\", -8192], \"passed\": true}, {\"check\": \"auipc upper immediate positive\", \"actual\": [\"U\", 305422336], \"expected\": [\"U\", 305422336], \"passed\": true}, {\"check\": \"jal backward\", \"actual\": [\"J\", -1002], \"expected\": [\"J\", -1002], \"passed\": true}, {\"check\": \"jal forward large\", \"actual\": [\"J\", 1046528], \"expected\": [\"J\", 1046528], \"passed\": true}], \"passed\": false}\n"}},"member_only":{"stages":["fixed"],"fields":["implementations.fixed","verification.fixed","harness","repair"],"note":"The verified repair, its recorded checks, the repair description, and the scoring harness are available to members."}}