{"abstract":"Two-byte opcodes are one byte short and the second opcode byte is read as ModRM.","category":"Instruction set emulation","checks":8,"contract":"Input [code]: a byte list decoded as a toy x86-like ISA. Prefixes 0x66 (operand size 16), 0x67 (address size 16), 0xF0/0xF2/0xF3 in any order. 0x0F escapes to a two-byte opcode. ModRM follows 01/03/89/8B/81/83/0F AF. Immediates: 81, B8-BF, E8, 0F 84 take the operand size (2 or 4 bytes); 83 and EB take 1. 32-bit ModRM: mod 3 none; rm 4 adds a SIB byte and a SIB base of 5 with mod 0 adds disp32; mod 0 rm 5 adds disp32; mod 1 disp8; mod 2 disp32. 16-bit ModRM: mod 0 rm 6 or mod 2 add disp16, mod 1 disp8, no SIB. Return the length of each instruction.","contract_signature":"*args","evaluation_group":"w2-instruction-set-emulation-length-decoder","failed_approach":"Consuming it but treating it as a one-byte opcode loses the two-byte table.","family":"w2-instruction-set-emulation-length-decoder-two-byte-opcode-escape","id":"FA-89616","implementations":{"attempt":{"sha256":"37678ba3b39b531f08fcfbce5bb3efdc6bdaf139dadef78513a20cddb3ced74a","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(*args):\n    code = args[0]\n    def b(k):\n        return code[k] if k < len(code) else 0\n    i = 0\n    lens = []\n    while i < len(code):\n        start = i\n        osz = 4\n        asz = 4\n        while b(i) in (0x66, 0x67, 0xF0, 0xF2, 0xF3):\n            if b(i) == 0x66: osz = 2\n            if b(i) == 0x67: asz = 2\n            i += 1\n        op = b(i)\n        i += 1\n        if op == 0x0F:\n            op = b(i)\n            i += 1\n        modrm = op in (0x01, 0x03, 0x89, 0x8B, 0x81, 0x83, 0x0FAF)\n        imm = {0x81: osz, 0x83: 1, 0xE8: osz, 0xEB: 1, 0x0F84: osz}.get(op, osz if 0xB8 <= op <= 0xBF else 0)\n        if modrm:\n            m = b(i)\n            i += 1\n            mod, rm = m >> 6, m & 7\n            if mod != 3:\n                if asz == 2:\n                    i += 2 if (mod == 0 and rm == 6) or mod == 2 else mod\n                else:\n                    if rm == 4:\n                        base = b(i) & 7\n                        i += 1\n                        if mod == 0 and base == 5:\n                            i += 4\n                    i += 4 if (mod == 0 and rm == 5) or mod == 2 else mod\n        i += imm\n        lens.append(i - start)\n    return lens\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\nfixtures = [[('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144]], [1, 2, 3, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195]], [3, 4, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144]], [1, 2, 3, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195]], [3, 4, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195]], [3, 4, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])]]\nfor label, args, expected in fixtures[N-1]:\n    check(label, solve(*args), expected)\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"},"broken":{"sha256":"bb4eb6303b9d29fab85c1038879d91aacc5d819ffe0fd6e5e9e62b7a3fc555e9","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(*args):\n    code = args[0]\n    def b(k):\n        return code[k] if k < len(code) else 0\n    i = 0\n    lens = []\n    while i < len(code):\n        start = i\n        osz = 4\n        asz = 4\n        while b(i) in (0x66, 0x67, 0xF0, 0xF2, 0xF3):\n            if b(i) == 0x66: osz = 2\n            if b(i) == 0x67: asz = 2\n            i += 1\n        op = b(i)\n        i += 1\n        if op == 0x0F:\n            op = 0x0F00 | b(i)\n        modrm = op in (0x01, 0x03, 0x89, 0x8B, 0x81, 0x83, 0x0FAF)\n        imm = {0x81: osz, 0x83: 1, 0xE8: osz, 0xEB: 1, 0x0F84: osz}.get(op, osz if 0xB8 <= op <= 0xBF else 0)\n        if modrm:\n            m = b(i)\n            i += 1\n            mod, rm = m >> 6, m & 7\n            if mod != 3:\n                if asz == 2:\n                    i += 2 if (mod == 0 and rm == 6) or mod == 2 else mod\n                else:\n                    if rm == 4:\n                        base = b(i) & 7\n                        i += 1\n                        if mod == 0 and base == 5:\n                            i += 4\n                    i += 4 if (mod == 0 and rm == 5) or mod == 2 else mod\n        i += imm\n        lens.append(i - start)\n    return lens\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\nfixtures = [[('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144]], [1, 2, 3, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195]], [3, 4, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144]], [1, 2, 3, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195]], [3, 4, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195]], [3, 4, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])]]\nfor label, args, expected in fixtures[N-1]:\n    check(label, solve(*args), expected)\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"}},"limitations":"A deterministic bounded teaching model of one emulator rule; the instruction semantics are a stipulated contract inspired by common ISAs and are not a claim of cycle-exact or architectural conformance. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.","method":"Deterministic executable model with adversarial boundary fixtures.","provenance":{"created_by":"Failure Map","dependencies":"Python standard library","family":"w2-instruction-set-emulation-length-decoder-two-byte-opcode-escape","generated_at":"2026-09-29T14:51:19.175818+00:00","license":"CC0-1.0","python":"3.12.14","seed":1,"split":"open-access"},"relevance":"Emulators and disassemblers must find instruction boundaries exactly; one wrong length desynchronises all following decoding.","root_cause":"The escape handler looks at the second byte but does not advance past it.","sha256":"562d44dd615fcc96935cd7c862ad66f2964ab2e95f1d7c1ad6ca484c6681314a","title":"Second opcode byte not consumed · case 01","variant":1,"variant_policy":"Five numbered records share a model and may reuse boundary fixtures.","verified":true,"visibility":"public","verification":{"attempt":{"elapsed_ms":39.805,"exit_code":1,"observations":[{"actual":[1,2,3,1,1],"check":"plain one-byte and modrm forms","expected":[1,2,3,1,1],"passed":true},{"actual":[7,4,4,1],"check":"sib with disp32 base","expected":[7,4,4,1],"passed":true},{"actual":[4,5,5],"check":"operand size prefix on immediates","expected":[4,5,5],"passed":true},{"actual":[5,1,6],"check":"prefix after rep","expected":[5,1,6],"passed":true},{"actual":[3,4,1],"check":"sign-extended imm8 form","expected":[3,4,1],"passed":true},{"actual":[5,4,5],"check":"16-bit addressing","expected":[5,4,5],"passed":true},{"actual":[2,2,1,1,2,1,1],"check":"two-byte opcodes","expected":[6,3,1],"passed":false},{"actual":[6,6,2],"check":"rip-less disp32 and disp32 mod 2","expected":[6,6,2],"passed":true}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"plain one-byte and modrm forms\", \"actual\": [1, 2, 3, 1, 1], \"expected\": [1, 2, 3, 1, 1], \"passed\": true}, {\"check\": \"sib with disp32 base\", \"actual\": [7, 4, 4, 1], \"expected\": [7, 4, 4, 1], \"passed\": true}, {\"check\": \"operand size prefix on immediates\", \"actual\": [4, 5, 5], \"expected\": [4, 5, 5], \"passed\": true}, {\"check\": \"prefix after rep\", \"actual\": [5, 1, 6], \"expected\": [5, 1, 6], \"passed\": true}, {\"check\": \"sign-extended imm8 form\", \"actual\": [3, 4, 1], \"expected\": [3, 4, 1], \"passed\": true}, {\"check\": \"16-bit addressing\", \"actual\": [5, 4, 5], \"expected\": [5, 4, 5], \"passed\": true}, {\"check\": \"two-byte opcodes\", \"actual\": [2, 2, 1, 1, 2, 1, 1], \"expected\": [6, 3, 1], \"passed\": false}, {\"check\": \"rip-less disp32 and disp32 mod 2\", \"actual\": [6, 6, 2], \"expected\": [6, 6, 2], \"passed\": true}], \"passed\": false}\n"},"broken":{"elapsed_ms":40.602,"exit_code":1,"observations":[{"actual":[1,2,3,1,1],"check":"plain one-byte and modrm forms","expected":[1,2,3,1,1],"passed":true},{"actual":[7,4,4,1],"check":"sib with disp32 base","expected":[7,4,4,1],"passed":true},{"actual":[4,5,5],"check":"operand size prefix on immediates","expected":[4,5,5],"passed":true},{"actual":[5,1,6],"check":"prefix after rep","expected":[5,1,6],"passed":true},{"actual":[3,4,1],"check":"sign-extended imm8 form","expected":[3,4,1],"passed":true},{"actual":[5,4,5],"check":"16-bit addressing","expected":[5,4,5],"passed":true},{"actual":[5,1,6],"check":"two-byte opcodes","expected":[6,3,1],"passed":false},{"actual":[6,6,2],"check":"rip-less disp32 and disp32 mod 2","expected":[6,6,2],"passed":true}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"plain one-byte and modrm forms\", \"actual\": [1, 2, 3, 1, 1], \"expected\": [1, 2, 3, 1, 1], \"passed\": true}, {\"check\": \"sib with disp32 base\", \"actual\": [7, 4, 4, 1], \"expected\": [7, 4, 4, 1], \"passed\": true}, {\"check\": \"operand size prefix on immediates\", \"actual\": [4, 5, 5], \"expected\": [4, 5, 5], \"passed\": true}, {\"check\": \"prefix after rep\", \"actual\": [5, 1, 6], \"expected\": [5, 1, 6], \"passed\": true}, {\"check\": \"sign-extended imm8 form\", \"actual\": [3, 4, 1], \"expected\": [3, 4, 1], \"passed\": true}, {\"check\": \"16-bit addressing\", \"actual\": [5, 4, 5], \"expected\": [5, 4, 5], \"passed\": true}, {\"check\": \"two-byte opcodes\", \"actual\": [5, 1, 6], \"expected\": [6, 3, 1], \"passed\": false}, {\"check\": \"rip-less disp32 and disp32 mod 2\", \"actual\": [6, 6, 2], \"expected\": [6, 6, 2], \"passed\": true}], \"passed\": false}\n"}},"member_only":{"stages":["fixed"],"fields":["implementations.fixed","verification.fixed","harness","repair"],"note":"The verified repair, its recorded checks, the repair description, and the scoring harness are available to members."}}