{"abstract":"ModRM operands under the 0x67 prefix get SIB and disp32 lengths.","category":"Instruction set emulation","checks":8,"contract":"Input [code]: a byte list decoded as a toy x86-like ISA. Prefixes 0x66 (operand size 16), 0x67 (address size 16), 0xF0/0xF2/0xF3 in any order. 0x0F escapes to a two-byte opcode. ModRM follows 01/03/89/8B/81/83/0F AF. Immediates: 81, B8-BF, E8, 0F 84 take the operand size (2 or 4 bytes); 83 and EB take 1. 32-bit ModRM: mod 3 none; rm 4 adds a SIB byte and a SIB base of 5 with mod 0 adds disp32; mod 0 rm 5 adds disp32; mod 1 disp8; mod 2 disp32. 16-bit ModRM: mod 0 rm 6 or mod 2 add disp16, mod 1 disp8, no SIB. Return the length of each instruction.","contract_signature":"*args","evaluation_group":"w2-instruction-set-emulation-length-decoder","failed_approach":"Leaving mod 0 on the 32-bit path misses the disp16 of rm 6.","family":"w2-instruction-set-emulation-length-decoder-address-size-prefix","id":"FA-89611","implementations":{"attempt":{"sha256":"c1bde23dc779472663a2e4a27d51d9768973b71117308c23f3e4ac3f7086dff8","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(*args):\n    code = args[0]\n    def b(k):\n        return code[k] if k < len(code) else 0\n    i = 0\n    lens = []\n    while i < len(code):\n        start = i\n        osz = 4\n        asz = 4\n        while b(i) in (0x66, 0x67, 0xF0, 0xF2, 0xF3):\n            if b(i) == 0x66: osz = 2\n            if b(i) == 0x67: asz = 2\n            i += 1\n        op = b(i)\n        i += 1\n        if op == 0x0F:\n            op = 0x0F00 | b(i)\n            i += 1\n        modrm = op in (0x01, 0x03, 0x89, 0x8B, 0x81, 0x83, 0x0FAF)\n        imm = {0x81: osz, 0x83: 1, 0xE8: osz, 0xEB: 1, 0x0F84: osz}.get(op, osz if 0xB8 <= op <= 0xBF else 0)\n        if modrm:\n            m = b(i)\n            i += 1\n            mod, rm = m >> 6, m & 7\n            if mod != 3:\n                if asz == 2 and mod != 0:\n                    i += 2 if (mod == 0 and rm == 6) or mod == 2 else mod\n                else:\n                    if rm == 4:\n                        base = b(i) & 7\n                        i += 1\n                        if mod == 0 and base == 5:\n                            i += 4\n                    i += 4 if (mod == 0 and rm == 5) or mod == 2 else mod\n        i += imm\n        lens.append(i - start)\n    return lens\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\nfixtures = [[('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144]], [1, 2, 3, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195]], [3, 4, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144]], [1, 2, 3, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195]], [3, 4, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195]], [3, 4, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])]]\nfor label, args, expected in fixtures[N-1]:\n    check(label, solve(*args), expected)\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"},"broken":{"sha256":"bcb761b4addfba7536877f045449efd0ffcbd9f697fed811fec073d6a29d9e0d","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(*args):\n    code = args[0]\n    def b(k):\n        return code[k] if k < len(code) else 0\n    i = 0\n    lens = []\n    while i < len(code):\n        start = i\n        osz = 4\n        asz = 4\n        while b(i) in (0x66, 0x67, 0xF0, 0xF2, 0xF3):\n            if b(i) == 0x66: osz = 2\n            if b(i) == 0x67: asz = 2\n            i += 1\n        op = b(i)\n        i += 1\n        if op == 0x0F:\n            op = 0x0F00 | b(i)\n            i += 1\n        modrm = op in (0x01, 0x03, 0x89, 0x8B, 0x81, 0x83, 0x0FAF)\n        imm = {0x81: osz, 0x83: 1, 0xE8: osz, 0xEB: 1, 0x0F84: osz}.get(op, osz if 0xB8 <= op <= 0xBF else 0)\n        if modrm:\n            m = b(i)\n            i += 1\n            mod, rm = m >> 6, m & 7\n            if mod != 3:\n                if False:\n                    i += 2 if (mod == 0 and rm == 6) or mod == 2 else mod\n                else:\n                    if rm == 4:\n                        base = b(i) & 7\n                        i += 1\n                        if mod == 0 and base == 5:\n                            i += 4\n                    i += 4 if (mod == 0 and rm == 5) or mod == 2 else mod\n        i += imm\n        lens.append(i - start)\n    return lens\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\nfixtures = [[('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144]], [1, 2, 3, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195]], [3, 4, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144]], [1, 2, 3, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195]], [3, 4, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195]], [3, 4, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])]]\nfor label, args, expected in fixtures[N-1]:\n    check(label, solve(*args), expected)\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"}},"limitations":"A deterministic bounded teaching model of one emulator rule; the instruction semantics are a stipulated contract inspired by common ISAs and are not a claim of cycle-exact or architectural conformance. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.","method":"Deterministic executable model with adversarial boundary fixtures.","provenance":{"created_by":"Failure Map","dependencies":"Python standard library","family":"w2-instruction-set-emulation-length-decoder-address-size-prefix","generated_at":"2026-09-29T14:51:19.175818+00:00","license":"CC0-1.0","python":"3.12.14","seed":1,"split":"open-access"},"relevance":"Emulators and disassemblers must find instruction boundaries exactly; one wrong length desynchronises all following decoding.","root_cause":"The address-size prefix is recorded but never changes ModRM decoding.","sha256":"8224de21b704d7ae15f585168aae6872c65d9a6105f210446982b75d2df49968","title":"16-bit addressing decoded with 32-bit rules · case 01","variant":1,"variant_policy":"Five numbered records share a model and may reuse boundary fixtures.","verified":true,"visibility":"public","verification":{"attempt":{"elapsed_ms":38.602,"exit_code":1,"observations":[{"actual":[1,2,3,1,1],"check":"plain one-byte and modrm forms","expected":[1,2,3,1,1],"passed":true},{"actual":[7,4,4,1],"check":"sib with disp32 base","expected":[7,4,4,1],"passed":true},{"actual":[4,5,5],"check":"operand size prefix on immediates","expected":[4,5,5],"passed":true},{"actual":[5,1,6],"check":"prefix after rep","expected":[5,1,6],"passed":true},{"actual":[3,4,1],"check":"sign-extended imm8 form","expected":[3,4,1],"passed":true},{"actual":[3,1,1,4,5],"check":"16-bit addressing","expected":[5,4,5],"passed":false},{"actual":[6,3,1],"check":"two-byte opcodes","expected":[6,3,1],"passed":true},{"actual":[6,6,2],"check":"rip-less disp32 and disp32 mod 2","expected":[6,6,2],"passed":true}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"plain one-byte and modrm forms\", \"actual\": [1, 2, 3, 1, 1], \"expected\": [1, 2, 3, 1, 1], \"passed\": true}, {\"check\": \"sib with disp32 base\", \"actual\": [7, 4, 4, 1], \"expected\": [7, 4, 4, 1], \"passed\": true}, {\"check\": \"operand size prefix on immediates\", \"actual\": [4, 5, 5], \"expected\": [4, 5, 5], \"passed\": true}, {\"check\": \"prefix after rep\", \"actual\": [5, 1, 6], \"expected\": [5, 1, 6], \"passed\": true}, {\"check\": \"sign-extended imm8 form\", \"actual\": [3, 4, 1], \"expected\": [3, 4, 1], \"passed\": true}, {\"check\": \"16-bit addressing\", \"actual\": [3, 1, 1, 4, 5], \"expected\": [5, 4, 5], \"passed\": false}, {\"check\": \"two-byte opcodes\", \"actual\": [6, 3, 1], \"expected\": [6, 3, 1], \"passed\": true}, {\"check\": \"rip-less disp32 and disp32 mod 2\", \"actual\": [6, 6, 2], \"expected\": [6, 6, 2], \"passed\": true}], \"passed\": false}\n"},"broken":{"elapsed_ms":43.796,"exit_code":1,"observations":[{"actual":[1,2,3,1,1],"check":"plain one-byte and modrm forms","expected":[1,2,3,1,1],"passed":true},{"actual":[7,4,4,1],"check":"sib with disp32 base","expected":[7,4,4,1],"passed":true},{"actual":[4,5,5],"check":"operand size prefix on immediates","expected":[4,5,5],"passed":true},{"actual":[5,1,6],"check":"prefix after rep","expected":[5,1,6],"passed":true},{"actual":[3,4,1],"check":"sign-extended imm8 form","expected":[3,4,1],"passed":true},{"actual":[3,1,1,4,7],"check":"16-bit addressing","expected":[5,4,5],"passed":false},{"actual":[6,3,1],"check":"two-byte opcodes","expected":[6,3,1],"passed":true},{"actual":[6,6,2],"check":"rip-less disp32 and disp32 mod 2","expected":[6,6,2],"passed":true}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"plain one-byte and modrm forms\", \"actual\": [1, 2, 3, 1, 1], \"expected\": [1, 2, 3, 1, 1], \"passed\": true}, {\"check\": \"sib with disp32 base\", \"actual\": [7, 4, 4, 1], \"expected\": [7, 4, 4, 1], \"passed\": true}, {\"check\": \"operand size prefix on immediates\", \"actual\": [4, 5, 5], \"expected\": [4, 5, 5], \"passed\": true}, {\"check\": \"prefix after rep\", \"actual\": [5, 1, 6], \"expected\": [5, 1, 6], \"passed\": true}, {\"check\": \"sign-extended imm8 form\", \"actual\": [3, 4, 1], \"expected\": [3, 4, 1], \"passed\": true}, {\"check\": \"16-bit addressing\", \"actual\": [3, 1, 1, 4, 7], \"expected\": [5, 4, 5], \"passed\": false}, {\"check\": \"two-byte opcodes\", \"actual\": [6, 3, 1], \"expected\": [6, 3, 1], \"passed\": true}, {\"check\": \"rip-less disp32 and disp32 mod 2\", \"actual\": [6, 6, 2], \"expected\": [6, 6, 2], \"passed\": true}], \"passed\": false}\n"}},"member_only":{"stages":["fixed"],"fields":["implementations.fixed","verification.fixed","harness","repair"],"note":"The verified repair, its recorded checks, the repair description, and the scoring harness are available to members."}}