FA-89451 / Instruction set emulation / Open access
Branch immediate bits 11 and 12 swapped · case 01
Branches with only one of offset bits 11/12 set go to the wrong target and may flip direction.
ROOT CAUSE
word[7] is placed at imm[12] and word[31] at imm[11].
VERIFIED REPAIR
word[31] is imm[12] (sign) and word[7] is imm[11].
Unsuccessful approach: Dropping word[7] into imm[0] breaks the always-even branch offset.
Case contract
Input [word]: a 32-bit instruction. By opcode (low 7 bits): I-type 0x13/0x03/0x67 imm = sext(word[31:20]); S-type 0x23 imm = sext(word[31:25]:word[11:7]); B-type 0x63 imm = sext(word[31]:word[7]:word[30:25]:word[11:8]:0) (13 bits); U-type 0x37/0x17 imm = word & 0xFFFFF000 as signed 32-bit; J-type 0x6F imm = sext(word[31]:word[19:12]:word[20]:word[30:21]:0) (21 bits). Return [format, imm].
Why this case matters
Instruction decoders reassemble scattered immediate bits; a single misplaced bit sends branches and stores to the wrong address.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(*args):
word = args[0]
op = word & 0x7F
def sx(v, bits):
return v - (1 << bits) if v >> (bits - 1) & 1 else v
if op in (0x13, 0x03, 0x67):
return ['I', sx(word >> 20, 12)]
if op == 0x23:
return ['S', sx(((word >> 25) << 5) | ((word >> 7) & 0x1F), 12)]
if op == 0x63:
v = ((word >> 7) & 1) << 12 | ((word >> 31) & 1) << 11 | ((word >> 25) & 0x3F) << 5 | ((word >> 8) & 0xF) << 1
return ['B', sx(v, 13)]
if op in (0x37, 0x17):
return ['U', sx(word & 0xFFFFF000, 32)]
if op == 0x6F:
v = ((word >> 31) & 1) << 20 | ((word >> 12) & 0xFF) << 12 | ((word >> 20) & 1) << 11 | ((word >> 21) & 0x3FF) << 1
return ['J', sx(v, 21)]
return ['?', 0]
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('addi negative immediate', [4255351443], ['I', -38]), ('load positive immediate', [2145494147], ['I', 2046]), ('store negative offset', [2180064931], ['S', -2035]), ('store small offset with funct3', [8516259], ['S', 5]), ('branch backward', [2149634403], ['B', -4094]), ('branch forward bit 11 set', [4293091], ['B', 2050]), ('lui upper immediate negative', [4294960439], ['U', -8192]), ('auipc upper immediate positive', [305422487], ['U', 305422336]), ('jal backward', [3246387439], ['J', -1002]), ('jal forward large', [2093167], ['J', 1046528])], [('addi negative immediate', [4216554131], ['I', -75]), ('load positive immediate', [2144445571], ['I', 2045]), ('store negative offset', [2180066595], ['S', -2022]), ('store small offset with funct3', [8516387], ['S', 6]), ('branch backward', [2149634659], ['B', -4092]), ('branch forward bit 11 set', [4293347], ['B', 2052]), ('lui upper immediate negative', [4294956343], ['U', -12288]), ('auipc upper immediate positive', [305426583], ['U', 305426432]), ('jal backward', [2197811439], ['J', -2002]), ('jal forward large', [3141743], ['J', 1044482])], [('addi negative immediate', [4177756819], ['I', -112]), ('load positive immediate', [2143396995], ['I', 2044]), ('store negative offset', [2213618595], ['S', -2009]), ('store small offset with funct3', [8516515], ['S', 7]), ('branch backward', [2149634915], ['B', -4090]), ('branch forward bit 11 set', [4293603], ['B', 2054]), ('lui upper immediate negative', [4294952247], ['U', -16384]), ('auipc upper immediate positive', [305430679], ['U', 305430528]), ('jal backward', [3295670511], ['J', -3002]), ('jal forward large', [6283375], ['J', 1042436])], [('addi negative immediate', [4138959507], ['I', -149]), ('load positive immediate', [2142348419], ['I', 2043]), ('store negative offset', [2213620259], ['S', -1996]), ('store small offset with funct3', [8516643], ['S', 8]), ('branch backward', [2149635171], ['B', -4088]), ('branch forward bit 11 set', [4293859], ['B', 2056]), ('lui upper immediate negative', [4294948151], ['U', -20480]), ('auipc upper immediate positive', [305434775], ['U', 305434624]), ('jal backward', [2247094511], ['J', -4002]), ('jal forward large', [7331951], ['J', 1040390])], [('addi negative immediate', [4100162195], ['I', -186]), ('load positive immediate', [2141299843], ['I', 2042]), ('store negative offset', [2247172259], ['S', -1983]), ('store small offset with funct3', [8516771], ['S', 9]), ('branch backward', [2149635427], ['B', -4086]), ('branch forward bit 11 set', [4294115], ['B', 2058]), ('lui upper immediate negative', [4294944055], ['U', -24576]), ('auipc upper immediate positive', [305438871], ['U', 305438720]), ('jal backward', [3347046639], ['J', -5002]), ('jal forward large', [10473583], ['J', 1038344])]]
for label, args, expected in fixtures[N-1]:
check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| addi negative immediate | ['I', -38] | ['I', -38] | Passed |
| load positive immediate | ['I', 2046] | ['I', 2046] | Passed |
| store negative offset | ['S', -2035] | ['S', -2035] | Passed |
| store small offset with funct3 | ['S', 5] | ['S', 5] | Passed |
| branch backward | ['B', 2050] | ['B', -4094] | Failed |
| branch forward bit 11 set | ['B', -4094] | ['B', 2050] | Failed |
| lui upper immediate negative | ['U', -8192] | ['U', -8192] | Passed |
| auipc upper immediate positive | ['U', 305422336] | ['U', 305422336] | Passed |
| jal backward | ['J', -1002] | ['J', -1002] | Passed |
| jal forward large | ['J', 1046528] | ['J', 1046528] | Passed |
SHA-256 / 6c9008f4d2c44f338d939a2c51daf86c4cfd45a05ef6ba2dbd8e4b1f00af907f
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(*args):
word = args[0]
op = word & 0x7F
def sx(v, bits):
return v - (1 << bits) if v >> (bits - 1) & 1 else v
if op in (0x13, 0x03, 0x67):
return ['I', sx(word >> 20, 12)]
if op == 0x23:
return ['S', sx(((word >> 25) << 5) | ((word >> 7) & 0x1F), 12)]
if op == 0x63:
v = ((word >> 31) & 1) << 12 | ((word >> 7) & 1) | ((word >> 25) & 0x3F) << 5 | ((word >> 8) & 0xF) << 1
return ['B', sx(v, 13)]
if op in (0x37, 0x17):
return ['U', sx(word & 0xFFFFF000, 32)]
if op == 0x6F:
v = ((word >> 31) & 1) << 20 | ((word >> 12) & 0xFF) << 12 | ((word >> 20) & 1) << 11 | ((word >> 21) & 0x3FF) << 1
return ['J', sx(v, 21)]
return ['?', 0]
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('addi negative immediate', [4255351443], ['I', -38]), ('load positive immediate', [2145494147], ['I', 2046]), ('store negative offset', [2180064931], ['S', -2035]), ('store small offset with funct3', [8516259], ['S', 5]), ('branch backward', [2149634403], ['B', -4094]), ('branch forward bit 11 set', [4293091], ['B', 2050]), ('lui upper immediate negative', [4294960439], ['U', -8192]), ('auipc upper immediate positive', [305422487], ['U', 305422336]), ('jal backward', [3246387439], ['J', -1002]), ('jal forward large', [2093167], ['J', 1046528])], [('addi negative immediate', [4216554131], ['I', -75]), ('load positive immediate', [2144445571], ['I', 2045]), ('store negative offset', [2180066595], ['S', -2022]), ('store small offset with funct3', [8516387], ['S', 6]), ('branch backward', [2149634659], ['B', -4092]), ('branch forward bit 11 set', [4293347], ['B', 2052]), ('lui upper immediate negative', [4294956343], ['U', -12288]), ('auipc upper immediate positive', [305426583], ['U', 305426432]), ('jal backward', [2197811439], ['J', -2002]), ('jal forward large', [3141743], ['J', 1044482])], [('addi negative immediate', [4177756819], ['I', -112]), ('load positive immediate', [2143396995], ['I', 2044]), ('store negative offset', [2213618595], ['S', -2009]), ('store small offset with funct3', [8516515], ['S', 7]), ('branch backward', [2149634915], ['B', -4090]), ('branch forward bit 11 set', [4293603], ['B', 2054]), ('lui upper immediate negative', [4294952247], ['U', -16384]), ('auipc upper immediate positive', [305430679], ['U', 305430528]), ('jal backward', [3295670511], ['J', -3002]), ('jal forward large', [6283375], ['J', 1042436])], [('addi negative immediate', [4138959507], ['I', -149]), ('load positive immediate', [2142348419], ['I', 2043]), ('store negative offset', [2213620259], ['S', -1996]), ('store small offset with funct3', [8516643], ['S', 8]), ('branch backward', [2149635171], ['B', -4088]), ('branch forward bit 11 set', [4293859], ['B', 2056]), ('lui upper immediate negative', [4294948151], ['U', -20480]), ('auipc upper immediate positive', [305434775], ['U', 305434624]), ('jal backward', [2247094511], ['J', -4002]), ('jal forward large', [7331951], ['J', 1040390])], [('addi negative immediate', [4100162195], ['I', -186]), ('load positive immediate', [2141299843], ['I', 2042]), ('store negative offset', [2247172259], ['S', -1983]), ('store small offset with funct3', [8516771], ['S', 9]), ('branch backward', [2149635427], ['B', -4086]), ('branch forward bit 11 set', [4294115], ['B', 2058]), ('lui upper immediate negative', [4294944055], ['U', -24576]), ('auipc upper immediate positive', [305438871], ['U', 305438720]), ('jal backward', [3347046639], ['J', -5002]), ('jal forward large', [10473583], ['J', 1038344])]]
for label, args, expected in fixtures[N-1]:
check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| addi negative immediate | ['I', -38] | ['I', -38] | Passed |
| load positive immediate | ['I', 2046] | ['I', 2046] | Passed |
| store negative offset | ['S', -2035] | ['S', -2035] | Passed |
| store small offset with funct3 | ['S', 5] | ['S', 5] | Passed |
| branch backward | ['B', -4094] | ['B', -4094] | Passed |
| branch forward bit 11 set | ['B', 3] | ['B', 2050] | Failed |
| lui upper immediate negative | ['U', -8192] | ['U', -8192] | Passed |
| auipc upper immediate positive | ['U', 305422336] | ['U', 305422336] | Passed |
| jal backward | ['J', -1002] | ['J', -1002] | Passed |
| jal forward large | ['J', 1046528] | ['J', 1046528] | Passed |
SHA-256 / 5422eacef5ed211f9a22650c1425576bfc36d0944135764db2d319c805ef7e17
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(*args):
word = args[0]
op = word & 0x7F
def sx(v, bits):
return v - (1 << bits) if v >> (bits - 1) & 1 else v
if op in (0x13, 0x03, 0x67):
return ['I', sx(word >> 20, 12)]
if op == 0x23:
return ['S', sx(((word >> 25) << 5) | ((word >> 7) & 0x1F), 12)]
if op == 0x63:
v = ((word >> 31) & 1) << 12 | ((word >> 7) & 1) << 11 | ((word >> 25) & 0x3F) << 5 | ((word >> 8) & 0xF) << 1
return ['B', sx(v, 13)]
if op in (0x37, 0x17):
return ['U', sx(word & 0xFFFFF000, 32)]
if op == 0x6F:
v = ((word >> 31) & 1) << 20 | ((word >> 12) & 0xFF) << 12 | ((word >> 20) & 1) << 11 | ((word >> 21) & 0x3FF) << 1
return ['J', sx(v, 21)]
return ['?', 0]
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('addi negative immediate', [4255351443], ['I', -38]), ('load positive immediate', [2145494147], ['I', 2046]), ('store negative offset', [2180064931], ['S', -2035]), ('store small offset with funct3', [8516259], ['S', 5]), ('branch backward', [2149634403], ['B', -4094]), ('branch forward bit 11 set', [4293091], ['B', 2050]), ('lui upper immediate negative', [4294960439], ['U', -8192]), ('auipc upper immediate positive', [305422487], ['U', 305422336]), ('jal backward', [3246387439], ['J', -1002]), ('jal forward large', [2093167], ['J', 1046528])], [('addi negative immediate', [4216554131], ['I', -75]), ('load positive immediate', [2144445571], ['I', 2045]), ('store negative offset', [2180066595], ['S', -2022]), ('store small offset with funct3', [8516387], ['S', 6]), ('branch backward', [2149634659], ['B', -4092]), ('branch forward bit 11 set', [4293347], ['B', 2052]), ('lui upper immediate negative', [4294956343], ['U', -12288]), ('auipc upper immediate positive', [305426583], ['U', 305426432]), ('jal backward', [2197811439], ['J', -2002]), ('jal forward large', [3141743], ['J', 1044482])], [('addi negative immediate', [4177756819], ['I', -112]), ('load positive immediate', [2143396995], ['I', 2044]), ('store negative offset', [2213618595], ['S', -2009]), ('store small offset with funct3', [8516515], ['S', 7]), ('branch backward', [2149634915], ['B', -4090]), ('branch forward bit 11 set', [4293603], ['B', 2054]), ('lui upper immediate negative', [4294952247], ['U', -16384]), ('auipc upper immediate positive', [305430679], ['U', 305430528]), ('jal backward', [3295670511], ['J', -3002]), ('jal forward large', [6283375], ['J', 1042436])], [('addi negative immediate', [4138959507], ['I', -149]), ('load positive immediate', [2142348419], ['I', 2043]), ('store negative offset', [2213620259], ['S', -1996]), ('store small offset with funct3', [8516643], ['S', 8]), ('branch backward', [2149635171], ['B', -4088]), ('branch forward bit 11 set', [4293859], ['B', 2056]), ('lui upper immediate negative', [4294948151], ['U', -20480]), ('auipc upper immediate positive', [305434775], ['U', 305434624]), ('jal backward', [2247094511], ['J', -4002]), ('jal forward large', [7331951], ['J', 1040390])], [('addi negative immediate', [4100162195], ['I', -186]), ('load positive immediate', [2141299843], ['I', 2042]), ('store negative offset', [2247172259], ['S', -1983]), ('store small offset with funct3', [8516771], ['S', 9]), ('branch backward', [2149635427], ['B', -4086]), ('branch forward bit 11 set', [4294115], ['B', 2058]), ('lui upper immediate negative', [4294944055], ['U', -24576]), ('auipc upper immediate positive', [305438871], ['U', 305438720]), ('jal backward', [3347046639], ['J', -5002]), ('jal forward large', [10473583], ['J', 1038344])]]
for label, args, expected in fixtures[N-1]:
check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| addi negative immediate | ['I', -38] | ['I', -38] | Passed |
| load positive immediate | ['I', 2046] | ['I', 2046] | Passed |
| store negative offset | ['S', -2035] | ['S', -2035] | Passed |
| store small offset with funct3 | ['S', 5] | ['S', 5] | Passed |
| branch backward | ['B', -4094] | ['B', -4094] | Passed |
| branch forward bit 11 set | ['B', 2050] | ['B', 2050] | Passed |
| lui upper immediate negative | ['U', -8192] | ['U', -8192] | Passed |
| auipc upper immediate positive | ['U', 305422336] | ['U', 305422336] | Passed |
| jal backward | ['J', -1002] | ['J', -1002] | Passed |
| jal forward large | ['J', 1046528] | ['J', 1046528] | Passed |
SHA-256 / bb2958d9d5dc57d0aad86b47b35e15f4a21abb52ce2ad8e8fa422d032a51cf98
Verification & scope
A deterministic bounded teaching model of one emulator rule; the instruction semantics are a stipulated contract inspired by common ISAs and are not a claim of cycle-exact or architectural conformance. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:51:17.492447+00:00.
Case digest / 0deaf7dfb095e08daf1408e9bac10b75dadf4cc6137269a6099d40b81a9f3a21