FAILURE MAP
← Case archive

FA-89611 / Instruction set emulation / Open access

16-bit addressing decoded with 32-bit rules · case 01

ModRM operands under the 0x67 prefix get SIB and disp32 lengths.

Verified by executionVariant 1 · 8 checks per implementationDownload source bundle ↓JSON ↗

ROOT CAUSE

The address-size prefix is recorded but never changes ModRM decoding.

VERIFIED REPAIR

Use 16-bit ModRM displacement rules when the address size is 16.

Unsuccessful approach: Leaving mod 0 on the 32-bit path misses the disp16 of rm 6.

Case contract

Input [code]: a byte list decoded as a toy x86-like ISA. Prefixes 0x66 (operand size 16), 0x67 (address size 16), 0xF0/0xF2/0xF3 in any order. 0x0F escapes to a two-byte opcode. ModRM follows 01/03/89/8B/81/83/0F AF. Immediates: 81, B8-BF, E8, 0F 84 take the operand size (2 or 4 bytes); 83 and EB take 1. 32-bit ModRM: mod 3 none; rm 4 adds a SIB byte and a SIB base of 5 with mod 0 adds disp32; mod 0 rm 5 adds disp32; mod 1 disp8; mod 2 disp32. 16-bit ModRM: mod 0 rm 6 or mod 2 add disp16, mod 1 disp8, no SIB. Return the length of each instruction.

Why this case matters

Emulators and disassemblers must find instruction boundaries exactly; one wrong length desynchronises all following decoding.

1 / The failure

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(*args):
    code = args[0]
    def b(k):
        return code[k] if k < len(code) else 0
    i = 0
    lens = []
    while i < len(code):
        start = i
        osz = 4
        asz = 4
        while b(i) in (0x66, 0x67, 0xF0, 0xF2, 0xF3):
            if b(i) == 0x66: osz = 2
            if b(i) == 0x67: asz = 2
            i += 1
        op = b(i)
        i += 1
        if op == 0x0F:
            op = 0x0F00 | b(i)
            i += 1
        modrm = op in (0x01, 0x03, 0x89, 0x8B, 0x81, 0x83, 0x0FAF)
        imm = {0x81: osz, 0x83: 1, 0xE8: osz, 0xEB: 1, 0x0F84: osz}.get(op, osz if 0xB8 <= op <= 0xBF else 0)
        if modrm:
            m = b(i)
            i += 1
            mod, rm = m >> 6, m & 7
            if mod != 3:
                if False:
                    i += 2 if (mod == 0 and rm == 6) or mod == 2 else mod
                else:
                    if rm == 4:
                        base = b(i) & 7
                        i += 1
                        if mod == 0 and base == 5:
                            i += 4
                    i += 4 if (mod == 0 and rm == 5) or mod == 2 else mod
        i += imm
        lens.append(i - start)
    return lens
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144]], [1, 2, 3, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195]], [3, 4, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144]], [1, 2, 3, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195]], [3, 4, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195]], [3, 4, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])]]
for label, args, expected in fixtures[N-1]:
    check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
plain one-byte and modrm forms[1, 2, 3, 1, 1][1, 2, 3, 1, 1]Passed
sib with disp32 base[7, 4, 4, 1][7, 4, 4, 1]Passed
operand size prefix on immediates[4, 5, 5][4, 5, 5]Passed
prefix after rep[5, 1, 6][5, 1, 6]Passed
sign-extended imm8 form[3, 4, 1][3, 4, 1]Passed
16-bit addressing[3, 1, 1, 4, 7][5, 4, 5]Failed
two-byte opcodes[6, 3, 1][6, 3, 1]Passed
rip-less disp32 and disp32 mod 2[6, 6, 2][6, 6, 2]Passed

SHA-256 / bcb761b4addfba7536877f045449efd0ffcbd9f697fed811fec073d6a29d9e0d

2 / The unsuccessful fix

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(*args):
    code = args[0]
    def b(k):
        return code[k] if k < len(code) else 0
    i = 0
    lens = []
    while i < len(code):
        start = i
        osz = 4
        asz = 4
        while b(i) in (0x66, 0x67, 0xF0, 0xF2, 0xF3):
            if b(i) == 0x66: osz = 2
            if b(i) == 0x67: asz = 2
            i += 1
        op = b(i)
        i += 1
        if op == 0x0F:
            op = 0x0F00 | b(i)
            i += 1
        modrm = op in (0x01, 0x03, 0x89, 0x8B, 0x81, 0x83, 0x0FAF)
        imm = {0x81: osz, 0x83: 1, 0xE8: osz, 0xEB: 1, 0x0F84: osz}.get(op, osz if 0xB8 <= op <= 0xBF else 0)
        if modrm:
            m = b(i)
            i += 1
            mod, rm = m >> 6, m & 7
            if mod != 3:
                if asz == 2 and mod != 0:
                    i += 2 if (mod == 0 and rm == 6) or mod == 2 else mod
                else:
                    if rm == 4:
                        base = b(i) & 7
                        i += 1
                        if mod == 0 and base == 5:
                            i += 4
                    i += 4 if (mod == 0 and rm == 5) or mod == 2 else mod
        i += imm
        lens.append(i - start)
    return lens
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144]], [1, 2, 3, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195]], [3, 4, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144]], [1, 2, 3, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195]], [3, 4, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195]], [3, 4, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])]]
for label, args, expected in fixtures[N-1]:
    check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
plain one-byte and modrm forms[1, 2, 3, 1, 1][1, 2, 3, 1, 1]Passed
sib with disp32 base[7, 4, 4, 1][7, 4, 4, 1]Passed
operand size prefix on immediates[4, 5, 5][4, 5, 5]Passed
prefix after rep[5, 1, 6][5, 1, 6]Passed
sign-extended imm8 form[3, 4, 1][3, 4, 1]Passed
16-bit addressing[3, 1, 1, 4, 5][5, 4, 5]Failed
two-byte opcodes[6, 3, 1][6, 3, 1]Passed
rip-less disp32 and disp32 mod 2[6, 6, 2][6, 6, 2]Passed

SHA-256 / c1bde23dc779472663a2e4a27d51d9768973b71117308c23f3e4ac3f7086dff8

3 / The verified repair

Exit 0
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(*args):
    code = args[0]
    def b(k):
        return code[k] if k < len(code) else 0
    i = 0
    lens = []
    while i < len(code):
        start = i
        osz = 4
        asz = 4
        while b(i) in (0x66, 0x67, 0xF0, 0xF2, 0xF3):
            if b(i) == 0x66: osz = 2
            if b(i) == 0x67: asz = 2
            i += 1
        op = b(i)
        i += 1
        if op == 0x0F:
            op = 0x0F00 | b(i)
            i += 1
        modrm = op in (0x01, 0x03, 0x89, 0x8B, 0x81, 0x83, 0x0FAF)
        imm = {0x81: osz, 0x83: 1, 0xE8: osz, 0xEB: 1, 0x0F84: osz}.get(op, osz if 0xB8 <= op <= 0xBF else 0)
        if modrm:
            m = b(i)
            i += 1
            mod, rm = m >> 6, m & 7
            if mod != 3:
                if asz == 2:
                    i += 2 if (mod == 0 and rm == 6) or mod == 2 else mod
                else:
                    if rm == 4:
                        base = b(i) & 7
                        i += 1
                        if mod == 0 and base == 5:
                            i += 4
                    i += 4 if (mod == 0 and rm == 5) or mod == 2 else mod
        i += imm
        lens.append(i - start)
    return lens
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144]], [1, 2, 3, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195]], [3, 4, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144]], [1, 2, 3, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195]], [3, 4, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195]], [3, 4, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])]]
for label, args, expected in fixtures[N-1]:
    check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
plain one-byte and modrm forms[1, 2, 3, 1, 1][1, 2, 3, 1, 1]Passed
sib with disp32 base[7, 4, 4, 1][7, 4, 4, 1]Passed
operand size prefix on immediates[4, 5, 5][4, 5, 5]Passed
prefix after rep[5, 1, 6][5, 1, 6]Passed
sign-extended imm8 form[3, 4, 1][3, 4, 1]Passed
16-bit addressing[5, 4, 5][5, 4, 5]Passed
two-byte opcodes[6, 3, 1][6, 3, 1]Passed
rip-less disp32 and disp32 mod 2[6, 6, 2][6, 6, 2]Passed

SHA-256 / 6646db4e46da04f84a39ca3d6711b8b9ac58dbf8330d7d962bf464568ee47ca1

Verification & scope

A deterministic bounded teaching model of one emulator rule; the instruction semantics are a stipulated contract inspired by common ISAs and are not a claim of cycle-exact or architectural conformance. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.

Observations recorded using Python 3.12.14 at 2026-09-29T14:51:19.004246+00:00.

Case digest / d8994410259f7fb577b83e6109af8e562bb3a496296859b54788d517f9adeed7