FA-89606 / Instruction set emulation / Open access
Sign-extended imm8 form decoded with a full immediate · case 01
Opcode 0x83 swallows three extra bytes.
ROOT CAUSE
The 0x83 group is given an operand-size immediate like 0x81.
VERIFIED REPAIR
0x83 always carries a single immediate byte.
Unsuccessful approach: A two-byte immediate is still wrong.
Case contract
Input [code]: a byte list decoded as a toy x86-like ISA. Prefixes 0x66 (operand size 16), 0x67 (address size 16), 0xF0/0xF2/0xF3 in any order. 0x0F escapes to a two-byte opcode. ModRM follows 01/03/89/8B/81/83/0F AF. Immediates: 81, B8-BF, E8, 0F 84 take the operand size (2 or 4 bytes); 83 and EB take 1. 32-bit ModRM: mod 3 none; rm 4 adds a SIB byte and a SIB base of 5 with mod 0 adds disp32; mod 0 rm 5 adds disp32; mod 1 disp8; mod 2 disp32. 16-bit ModRM: mod 0 rm 6 or mod 2 add disp16, mod 1 disp8, no SIB. Return the length of each instruction.
Why this case matters
Emulators and disassemblers must find instruction boundaries exactly; one wrong length desynchronises all following decoding.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(*args):
code = args[0]
def b(k):
return code[k] if k < len(code) else 0
i = 0
lens = []
while i < len(code):
start = i
osz = 4
asz = 4
while b(i) in (0x66, 0x67, 0xF0, 0xF2, 0xF3):
if b(i) == 0x66: osz = 2
if b(i) == 0x67: asz = 2
i += 1
op = b(i)
i += 1
if op == 0x0F:
op = 0x0F00 | b(i)
i += 1
modrm = op in (0x01, 0x03, 0x89, 0x8B, 0x81, 0x83, 0x0FAF)
imm = {0x81: osz, 0x83: osz, 0xE8: osz, 0xEB: 1, 0x0F84: osz}.get(op, osz if 0xB8 <= op <= 0xBF else 0)
if modrm:
m = b(i)
i += 1
mod, rm = m >> 6, m & 7
if mod != 3:
if asz == 2:
i += 2 if (mod == 0 and rm == 6) or mod == 2 else mod
else:
if rm == 4:
base = b(i) & 7
i += 1
if mod == 0 and base == 5:
i += 4
i += 4 if (mod == 0 and rm == 5) or mod == 2 else mod
i += imm
lens.append(i - start)
return lens
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144]], [1, 2, 3, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195]], [3, 4, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144]], [1, 2, 3, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195]], [3, 4, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195]], [3, 4, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])]]
for label, args, expected in fixtures[N-1]:
check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| plain one-byte and modrm forms | [1, 2, 3, 1, 1] | [1, 2, 3, 1, 1] | Passed |
| sib with disp32 base | [7, 4, 4, 1] | [7, 4, 4, 1] | Passed |
| operand size prefix on immediates | [4, 5, 5] | [4, 5, 5] | Passed |
| prefix after rep | [5, 1, 6] | [5, 1, 6] | Passed |
| sign-extended imm8 form | [6, 1, 1] | [3, 4, 1] | Failed |
| 16-bit addressing | [5, 4, 5] | [5, 4, 5] | Passed |
| two-byte opcodes | [6, 3, 1] | [6, 3, 1] | Passed |
| rip-less disp32 and disp32 mod 2 | [6, 6, 2] | [6, 6, 2] | Passed |
SHA-256 / 15801bd2941893803c761cc6cfa812cb785effea04db14b09ab52a9fc3075eda
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(*args):
code = args[0]
def b(k):
return code[k] if k < len(code) else 0
i = 0
lens = []
while i < len(code):
start = i
osz = 4
asz = 4
while b(i) in (0x66, 0x67, 0xF0, 0xF2, 0xF3):
if b(i) == 0x66: osz = 2
if b(i) == 0x67: asz = 2
i += 1
op = b(i)
i += 1
if op == 0x0F:
op = 0x0F00 | b(i)
i += 1
modrm = op in (0x01, 0x03, 0x89, 0x8B, 0x81, 0x83, 0x0FAF)
imm = {0x81: osz, 0x83: 2, 0xE8: osz, 0xEB: 1, 0x0F84: osz}.get(op, osz if 0xB8 <= op <= 0xBF else 0)
if modrm:
m = b(i)
i += 1
mod, rm = m >> 6, m & 7
if mod != 3:
if asz == 2:
i += 2 if (mod == 0 and rm == 6) or mod == 2 else mod
else:
if rm == 4:
base = b(i) & 7
i += 1
if mod == 0 and base == 5:
i += 4
i += 4 if (mod == 0 and rm == 5) or mod == 2 else mod
i += imm
lens.append(i - start)
return lens
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144]], [1, 2, 3, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195]], [3, 4, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144]], [1, 2, 3, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195]], [3, 4, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195]], [3, 4, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])]]
for label, args, expected in fixtures[N-1]:
check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| plain one-byte and modrm forms | [1, 2, 3, 1, 1] | [1, 2, 3, 1, 1] | Passed |
| sib with disp32 base | [7, 4, 4, 1] | [7, 4, 4, 1] | Passed |
| operand size prefix on immediates | [4, 5, 5] | [4, 5, 5] | Passed |
| prefix after rep | [5, 1, 6] | [5, 1, 6] | Passed |
| sign-extended imm8 form | [4, 1, 1, 1, 1] | [3, 4, 1] | Failed |
| 16-bit addressing | [5, 4, 5] | [5, 4, 5] | Passed |
| two-byte opcodes | [6, 3, 1] | [6, 3, 1] | Passed |
| rip-less disp32 and disp32 mod 2 | [6, 6, 2] | [6, 6, 2] | Passed |
SHA-256 / e7a4024fdb5f442277caf0c202d56da0567e0d6401d8708065373200c7896e64
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(*args):
code = args[0]
def b(k):
return code[k] if k < len(code) else 0
i = 0
lens = []
while i < len(code):
start = i
osz = 4
asz = 4
while b(i) in (0x66, 0x67, 0xF0, 0xF2, 0xF3):
if b(i) == 0x66: osz = 2
if b(i) == 0x67: asz = 2
i += 1
op = b(i)
i += 1
if op == 0x0F:
op = 0x0F00 | b(i)
i += 1
modrm = op in (0x01, 0x03, 0x89, 0x8B, 0x81, 0x83, 0x0FAF)
imm = {0x81: osz, 0x83: 1, 0xE8: osz, 0xEB: 1, 0x0F84: osz}.get(op, osz if 0xB8 <= op <= 0xBF else 0)
if modrm:
m = b(i)
i += 1
mod, rm = m >> 6, m & 7
if mod != 3:
if asz == 2:
i += 2 if (mod == 0 and rm == 6) or mod == 2 else mod
else:
if rm == 4:
base = b(i) & 7
i += 1
if mod == 0 and base == 5:
i += 4
i += 4 if (mod == 0 and rm == 5) or mod == 2 else mod
i += imm
lens.append(i - start)
return lens
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144]], [1, 2, 3, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195]], [3, 4, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144]], [1, 2, 3, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195]], [3, 4, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195]], [3, 4, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])]]
for label, args, expected in fixtures[N-1]:
check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| plain one-byte and modrm forms | [1, 2, 3, 1, 1] | [1, 2, 3, 1, 1] | Passed |
| sib with disp32 base | [7, 4, 4, 1] | [7, 4, 4, 1] | Passed |
| operand size prefix on immediates | [4, 5, 5] | [4, 5, 5] | Passed |
| prefix after rep | [5, 1, 6] | [5, 1, 6] | Passed |
| sign-extended imm8 form | [3, 4, 1] | [3, 4, 1] | Passed |
| 16-bit addressing | [5, 4, 5] | [5, 4, 5] | Passed |
| two-byte opcodes | [6, 3, 1] | [6, 3, 1] | Passed |
| rip-less disp32 and disp32 mod 2 | [6, 6, 2] | [6, 6, 2] | Passed |
SHA-256 / 6646db4e46da04f84a39ca3d6711b8b9ac58dbf8330d7d962bf464568ee47ca1
Verification & scope
A deterministic bounded teaching model of one emulator rule; the instruction semantics are a stipulated contract inspired by common ISAs and are not a claim of cycle-exact or architectural conformance. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:51:18.829939+00:00.
Case digest / 5ae5f1f2301a8dde43add5526211ab884ed991d0194f6cb1110696030795d73a