FAILURE MAP
← Case archive

FA-89456 / Instruction set emulation / Open access

U-type immediate returned unshifted · case 01

lui loads the 20-bit field without shifting it into the upper bits.

Verified by executionVariant 1 · 10 checks per implementationDownload source bundle ↓JSON ↗

ROOT CAUSE

The decoder returns the raw upper field instead of the field in bits 31:12.

VERIFIED REPAIR

Keep the field in place (word & 0xFFFFF000) and interpret as signed 32-bit.

Unsuccessful approach: Masking without the signed interpretation reports negative upper immediates as large positives.

Case contract

Input [word]: a 32-bit instruction. By opcode (low 7 bits): I-type 0x13/0x03/0x67 imm = sext(word[31:20]); S-type 0x23 imm = sext(word[31:25]:word[11:7]); B-type 0x63 imm = sext(word[31]:word[7]:word[30:25]:word[11:8]:0) (13 bits); U-type 0x37/0x17 imm = word & 0xFFFFF000 as signed 32-bit; J-type 0x6F imm = sext(word[31]:word[19:12]:word[20]:word[30:21]:0) (21 bits). Return [format, imm].

Why this case matters

Instruction decoders reassemble scattered immediate bits; a single misplaced bit sends branches and stores to the wrong address.

1 / The failure

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(*args):
    word = args[0]
    op = word & 0x7F
    def sx(v, bits):
        return v - (1 << bits) if v >> (bits - 1) & 1 else v
    if op in (0x13, 0x03, 0x67):
        return ['I', sx(word >> 20, 12)]
    if op == 0x23:
        return ['S', sx(((word >> 25) << 5) | ((word >> 7) & 0x1F), 12)]
    if op == 0x63:
        v = ((word >> 31) & 1) << 12 | ((word >> 7) & 1) << 11 | ((word >> 25) & 0x3F) << 5 | ((word >> 8) & 0xF) << 1
        return ['B', sx(v, 13)]
    if op in (0x37, 0x17):
        return ['U', word >> 12]
    if op == 0x6F:
        v = ((word >> 31) & 1) << 20 | ((word >> 12) & 0xFF) << 12 | ((word >> 20) & 1) << 11 | ((word >> 21) & 0x3FF) << 1
        return ['J', sx(v, 21)]
    return ['?', 0]
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('addi negative immediate', [4255351443], ['I', -38]), ('load positive immediate', [2145494147], ['I', 2046]), ('store negative offset', [2180064931], ['S', -2035]), ('store small offset with funct3', [8516259], ['S', 5]), ('branch backward', [2149634403], ['B', -4094]), ('branch forward bit 11 set', [4293091], ['B', 2050]), ('lui upper immediate negative', [4294960439], ['U', -8192]), ('auipc upper immediate positive', [305422487], ['U', 305422336]), ('jal backward', [3246387439], ['J', -1002]), ('jal forward large', [2093167], ['J', 1046528])], [('addi negative immediate', [4216554131], ['I', -75]), ('load positive immediate', [2144445571], ['I', 2045]), ('store negative offset', [2180066595], ['S', -2022]), ('store small offset with funct3', [8516387], ['S', 6]), ('branch backward', [2149634659], ['B', -4092]), ('branch forward bit 11 set', [4293347], ['B', 2052]), ('lui upper immediate negative', [4294956343], ['U', -12288]), ('auipc upper immediate positive', [305426583], ['U', 305426432]), ('jal backward', [2197811439], ['J', -2002]), ('jal forward large', [3141743], ['J', 1044482])], [('addi negative immediate', [4177756819], ['I', -112]), ('load positive immediate', [2143396995], ['I', 2044]), ('store negative offset', [2213618595], ['S', -2009]), ('store small offset with funct3', [8516515], ['S', 7]), ('branch backward', [2149634915], ['B', -4090]), ('branch forward bit 11 set', [4293603], ['B', 2054]), ('lui upper immediate negative', [4294952247], ['U', -16384]), ('auipc upper immediate positive', [305430679], ['U', 305430528]), ('jal backward', [3295670511], ['J', -3002]), ('jal forward large', [6283375], ['J', 1042436])], [('addi negative immediate', [4138959507], ['I', -149]), ('load positive immediate', [2142348419], ['I', 2043]), ('store negative offset', [2213620259], ['S', -1996]), ('store small offset with funct3', [8516643], ['S', 8]), ('branch backward', [2149635171], ['B', -4088]), ('branch forward bit 11 set', [4293859], ['B', 2056]), ('lui upper immediate negative', [4294948151], ['U', -20480]), ('auipc upper immediate positive', [305434775], ['U', 305434624]), ('jal backward', [2247094511], ['J', -4002]), ('jal forward large', [7331951], ['J', 1040390])], [('addi negative immediate', [4100162195], ['I', -186]), ('load positive immediate', [2141299843], ['I', 2042]), ('store negative offset', [2247172259], ['S', -1983]), ('store small offset with funct3', [8516771], ['S', 9]), ('branch backward', [2149635427], ['B', -4086]), ('branch forward bit 11 set', [4294115], ['B', 2058]), ('lui upper immediate negative', [4294944055], ['U', -24576]), ('auipc upper immediate positive', [305438871], ['U', 305438720]), ('jal backward', [3347046639], ['J', -5002]), ('jal forward large', [10473583], ['J', 1038344])]]
for label, args, expected in fixtures[N-1]:
    check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
addi negative immediate['I', -38]['I', -38]Passed
load positive immediate['I', 2046]['I', 2046]Passed
store negative offset['S', -2035]['S', -2035]Passed
store small offset with funct3['S', 5]['S', 5]Passed
branch backward['B', -4094]['B', -4094]Passed
branch forward bit 11 set['B', 2050]['B', 2050]Passed
lui upper immediate negative['U', 1048574]['U', -8192]Failed
auipc upper immediate positive['U', 74566]['U', 305422336]Failed
jal backward['J', -1002]['J', -1002]Passed
jal forward large['J', 1046528]['J', 1046528]Passed

SHA-256 / 367c5bbbc2b7b31f8160ce53396b6961bb073c689a15a9a1401e326ab8a62d47

2 / The unsuccessful fix

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(*args):
    word = args[0]
    op = word & 0x7F
    def sx(v, bits):
        return v - (1 << bits) if v >> (bits - 1) & 1 else v
    if op in (0x13, 0x03, 0x67):
        return ['I', sx(word >> 20, 12)]
    if op == 0x23:
        return ['S', sx(((word >> 25) << 5) | ((word >> 7) & 0x1F), 12)]
    if op == 0x63:
        v = ((word >> 31) & 1) << 12 | ((word >> 7) & 1) << 11 | ((word >> 25) & 0x3F) << 5 | ((word >> 8) & 0xF) << 1
        return ['B', sx(v, 13)]
    if op in (0x37, 0x17):
        return ['U', word & 0xFFFFF000]
    if op == 0x6F:
        v = ((word >> 31) & 1) << 20 | ((word >> 12) & 0xFF) << 12 | ((word >> 20) & 1) << 11 | ((word >> 21) & 0x3FF) << 1
        return ['J', sx(v, 21)]
    return ['?', 0]
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('addi negative immediate', [4255351443], ['I', -38]), ('load positive immediate', [2145494147], ['I', 2046]), ('store negative offset', [2180064931], ['S', -2035]), ('store small offset with funct3', [8516259], ['S', 5]), ('branch backward', [2149634403], ['B', -4094]), ('branch forward bit 11 set', [4293091], ['B', 2050]), ('lui upper immediate negative', [4294960439], ['U', -8192]), ('auipc upper immediate positive', [305422487], ['U', 305422336]), ('jal backward', [3246387439], ['J', -1002]), ('jal forward large', [2093167], ['J', 1046528])], [('addi negative immediate', [4216554131], ['I', -75]), ('load positive immediate', [2144445571], ['I', 2045]), ('store negative offset', [2180066595], ['S', -2022]), ('store small offset with funct3', [8516387], ['S', 6]), ('branch backward', [2149634659], ['B', -4092]), ('branch forward bit 11 set', [4293347], ['B', 2052]), ('lui upper immediate negative', [4294956343], ['U', -12288]), ('auipc upper immediate positive', [305426583], ['U', 305426432]), ('jal backward', [2197811439], ['J', -2002]), ('jal forward large', [3141743], ['J', 1044482])], [('addi negative immediate', [4177756819], ['I', -112]), ('load positive immediate', [2143396995], ['I', 2044]), ('store negative offset', [2213618595], ['S', -2009]), ('store small offset with funct3', [8516515], ['S', 7]), ('branch backward', [2149634915], ['B', -4090]), ('branch forward bit 11 set', [4293603], ['B', 2054]), ('lui upper immediate negative', [4294952247], ['U', -16384]), ('auipc upper immediate positive', [305430679], ['U', 305430528]), ('jal backward', [3295670511], ['J', -3002]), ('jal forward large', [6283375], ['J', 1042436])], [('addi negative immediate', [4138959507], ['I', -149]), ('load positive immediate', [2142348419], ['I', 2043]), ('store negative offset', [2213620259], ['S', -1996]), ('store small offset with funct3', [8516643], ['S', 8]), ('branch backward', [2149635171], ['B', -4088]), ('branch forward bit 11 set', [4293859], ['B', 2056]), ('lui upper immediate negative', [4294948151], ['U', -20480]), ('auipc upper immediate positive', [305434775], ['U', 305434624]), ('jal backward', [2247094511], ['J', -4002]), ('jal forward large', [7331951], ['J', 1040390])], [('addi negative immediate', [4100162195], ['I', -186]), ('load positive immediate', [2141299843], ['I', 2042]), ('store negative offset', [2247172259], ['S', -1983]), ('store small offset with funct3', [8516771], ['S', 9]), ('branch backward', [2149635427], ['B', -4086]), ('branch forward bit 11 set', [4294115], ['B', 2058]), ('lui upper immediate negative', [4294944055], ['U', -24576]), ('auipc upper immediate positive', [305438871], ['U', 305438720]), ('jal backward', [3347046639], ['J', -5002]), ('jal forward large', [10473583], ['J', 1038344])]]
for label, args, expected in fixtures[N-1]:
    check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
addi negative immediate['I', -38]['I', -38]Passed
load positive immediate['I', 2046]['I', 2046]Passed
store negative offset['S', -2035]['S', -2035]Passed
store small offset with funct3['S', 5]['S', 5]Passed
branch backward['B', -4094]['B', -4094]Passed
branch forward bit 11 set['B', 2050]['B', 2050]Passed
lui upper immediate negative['U', 4294959104]['U', -8192]Failed
auipc upper immediate positive['U', 305422336]['U', 305422336]Passed
jal backward['J', -1002]['J', -1002]Passed
jal forward large['J', 1046528]['J', 1046528]Passed

SHA-256 / 6accbe149204d78c99c42e751b92dab2ab97f310ca14a50c6fc2c7bd57c0501f

3 / The verified repair

Exit 0
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(*args):
    word = args[0]
    op = word & 0x7F
    def sx(v, bits):
        return v - (1 << bits) if v >> (bits - 1) & 1 else v
    if op in (0x13, 0x03, 0x67):
        return ['I', sx(word >> 20, 12)]
    if op == 0x23:
        return ['S', sx(((word >> 25) << 5) | ((word >> 7) & 0x1F), 12)]
    if op == 0x63:
        v = ((word >> 31) & 1) << 12 | ((word >> 7) & 1) << 11 | ((word >> 25) & 0x3F) << 5 | ((word >> 8) & 0xF) << 1
        return ['B', sx(v, 13)]
    if op in (0x37, 0x17):
        return ['U', sx(word & 0xFFFFF000, 32)]
    if op == 0x6F:
        v = ((word >> 31) & 1) << 20 | ((word >> 12) & 0xFF) << 12 | ((word >> 20) & 1) << 11 | ((word >> 21) & 0x3FF) << 1
        return ['J', sx(v, 21)]
    return ['?', 0]
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('addi negative immediate', [4255351443], ['I', -38]), ('load positive immediate', [2145494147], ['I', 2046]), ('store negative offset', [2180064931], ['S', -2035]), ('store small offset with funct3', [8516259], ['S', 5]), ('branch backward', [2149634403], ['B', -4094]), ('branch forward bit 11 set', [4293091], ['B', 2050]), ('lui upper immediate negative', [4294960439], ['U', -8192]), ('auipc upper immediate positive', [305422487], ['U', 305422336]), ('jal backward', [3246387439], ['J', -1002]), ('jal forward large', [2093167], ['J', 1046528])], [('addi negative immediate', [4216554131], ['I', -75]), ('load positive immediate', [2144445571], ['I', 2045]), ('store negative offset', [2180066595], ['S', -2022]), ('store small offset with funct3', [8516387], ['S', 6]), ('branch backward', [2149634659], ['B', -4092]), ('branch forward bit 11 set', [4293347], ['B', 2052]), ('lui upper immediate negative', [4294956343], ['U', -12288]), ('auipc upper immediate positive', [305426583], ['U', 305426432]), ('jal backward', [2197811439], ['J', -2002]), ('jal forward large', [3141743], ['J', 1044482])], [('addi negative immediate', [4177756819], ['I', -112]), ('load positive immediate', [2143396995], ['I', 2044]), ('store negative offset', [2213618595], ['S', -2009]), ('store small offset with funct3', [8516515], ['S', 7]), ('branch backward', [2149634915], ['B', -4090]), ('branch forward bit 11 set', [4293603], ['B', 2054]), ('lui upper immediate negative', [4294952247], ['U', -16384]), ('auipc upper immediate positive', [305430679], ['U', 305430528]), ('jal backward', [3295670511], ['J', -3002]), ('jal forward large', [6283375], ['J', 1042436])], [('addi negative immediate', [4138959507], ['I', -149]), ('load positive immediate', [2142348419], ['I', 2043]), ('store negative offset', [2213620259], ['S', -1996]), ('store small offset with funct3', [8516643], ['S', 8]), ('branch backward', [2149635171], ['B', -4088]), ('branch forward bit 11 set', [4293859], ['B', 2056]), ('lui upper immediate negative', [4294948151], ['U', -20480]), ('auipc upper immediate positive', [305434775], ['U', 305434624]), ('jal backward', [2247094511], ['J', -4002]), ('jal forward large', [7331951], ['J', 1040390])], [('addi negative immediate', [4100162195], ['I', -186]), ('load positive immediate', [2141299843], ['I', 2042]), ('store negative offset', [2247172259], ['S', -1983]), ('store small offset with funct3', [8516771], ['S', 9]), ('branch backward', [2149635427], ['B', -4086]), ('branch forward bit 11 set', [4294115], ['B', 2058]), ('lui upper immediate negative', [4294944055], ['U', -24576]), ('auipc upper immediate positive', [305438871], ['U', 305438720]), ('jal backward', [3347046639], ['J', -5002]), ('jal forward large', [10473583], ['J', 1038344])]]
for label, args, expected in fixtures[N-1]:
    check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
addi negative immediate['I', -38]['I', -38]Passed
load positive immediate['I', 2046]['I', 2046]Passed
store negative offset['S', -2035]['S', -2035]Passed
store small offset with funct3['S', 5]['S', 5]Passed
branch backward['B', -4094]['B', -4094]Passed
branch forward bit 11 set['B', 2050]['B', 2050]Passed
lui upper immediate negative['U', -8192]['U', -8192]Passed
auipc upper immediate positive['U', 305422336]['U', 305422336]Passed
jal backward['J', -1002]['J', -1002]Passed
jal forward large['J', 1046528]['J', 1046528]Passed

SHA-256 / bb2958d9d5dc57d0aad86b47b35e15f4a21abb52ce2ad8e8fa422d032a51cf98

Verification & scope

A deterministic bounded teaching model of one emulator rule; the instruction semantics are a stipulated contract inspired by common ISAs and are not a claim of cycle-exact or architectural conformance. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.

Observations recorded using Python 3.12.14 at 2026-09-29T14:51:17.502661+00:00.

Case digest / 1122b4877a64e4615523edc0f5caa363607bd4e9932937908ec75e86adefd48f