FA-89616 / Instruction set emulation / Open access
Second opcode byte not consumed · case 01
Two-byte opcodes are one byte short and the second opcode byte is read as ModRM.
ROOT CAUSE
The escape handler looks at the second byte but does not advance past it.
VERIFIED REPAIR
Consume the second opcode byte after 0x0F.
Unsuccessful approach: Consuming it but treating it as a one-byte opcode loses the two-byte table.
Case contract
Input [code]: a byte list decoded as a toy x86-like ISA. Prefixes 0x66 (operand size 16), 0x67 (address size 16), 0xF0/0xF2/0xF3 in any order. 0x0F escapes to a two-byte opcode. ModRM follows 01/03/89/8B/81/83/0F AF. Immediates: 81, B8-BF, E8, 0F 84 take the operand size (2 or 4 bytes); 83 and EB take 1. 32-bit ModRM: mod 3 none; rm 4 adds a SIB byte and a SIB base of 5 with mod 0 adds disp32; mod 0 rm 5 adds disp32; mod 1 disp8; mod 2 disp32. 16-bit ModRM: mod 0 rm 6 or mod 2 add disp16, mod 1 disp8, no SIB. Return the length of each instruction.
Why this case matters
Emulators and disassemblers must find instruction boundaries exactly; one wrong length desynchronises all following decoding.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(*args):
code = args[0]
def b(k):
return code[k] if k < len(code) else 0
i = 0
lens = []
while i < len(code):
start = i
osz = 4
asz = 4
while b(i) in (0x66, 0x67, 0xF0, 0xF2, 0xF3):
if b(i) == 0x66: osz = 2
if b(i) == 0x67: asz = 2
i += 1
op = b(i)
i += 1
if op == 0x0F:
op = 0x0F00 | b(i)
modrm = op in (0x01, 0x03, 0x89, 0x8B, 0x81, 0x83, 0x0FAF)
imm = {0x81: osz, 0x83: 1, 0xE8: osz, 0xEB: 1, 0x0F84: osz}.get(op, osz if 0xB8 <= op <= 0xBF else 0)
if modrm:
m = b(i)
i += 1
mod, rm = m >> 6, m & 7
if mod != 3:
if asz == 2:
i += 2 if (mod == 0 and rm == 6) or mod == 2 else mod
else:
if rm == 4:
base = b(i) & 7
i += 1
if mod == 0 and base == 5:
i += 4
i += 4 if (mod == 0 and rm == 5) or mod == 2 else mod
i += imm
lens.append(i - start)
return lens
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144]], [1, 2, 3, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195]], [3, 4, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144]], [1, 2, 3, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195]], [3, 4, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195]], [3, 4, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])]]
for label, args, expected in fixtures[N-1]:
check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| plain one-byte and modrm forms | [1, 2, 3, 1, 1] | [1, 2, 3, 1, 1] | Passed |
| sib with disp32 base | [7, 4, 4, 1] | [7, 4, 4, 1] | Passed |
| operand size prefix on immediates | [4, 5, 5] | [4, 5, 5] | Passed |
| prefix after rep | [5, 1, 6] | [5, 1, 6] | Passed |
| sign-extended imm8 form | [3, 4, 1] | [3, 4, 1] | Passed |
| 16-bit addressing | [5, 4, 5] | [5, 4, 5] | Passed |
| two-byte opcodes | [5, 1, 6] | [6, 3, 1] | Failed |
| rip-less disp32 and disp32 mod 2 | [6, 6, 2] | [6, 6, 2] | Passed |
SHA-256 / bb4eb6303b9d29fab85c1038879d91aacc5d819ffe0fd6e5e9e62b7a3fc555e9
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(*args):
code = args[0]
def b(k):
return code[k] if k < len(code) else 0
i = 0
lens = []
while i < len(code):
start = i
osz = 4
asz = 4
while b(i) in (0x66, 0x67, 0xF0, 0xF2, 0xF3):
if b(i) == 0x66: osz = 2
if b(i) == 0x67: asz = 2
i += 1
op = b(i)
i += 1
if op == 0x0F:
op = b(i)
i += 1
modrm = op in (0x01, 0x03, 0x89, 0x8B, 0x81, 0x83, 0x0FAF)
imm = {0x81: osz, 0x83: 1, 0xE8: osz, 0xEB: 1, 0x0F84: osz}.get(op, osz if 0xB8 <= op <= 0xBF else 0)
if modrm:
m = b(i)
i += 1
mod, rm = m >> 6, m & 7
if mod != 3:
if asz == 2:
i += 2 if (mod == 0 and rm == 6) or mod == 2 else mod
else:
if rm == 4:
base = b(i) & 7
i += 1
if mod == 0 and base == 5:
i += 4
i += 4 if (mod == 0 and rm == 5) or mod == 2 else mod
i += imm
lens.append(i - start)
return lens
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144]], [1, 2, 3, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195]], [3, 4, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144]], [1, 2, 3, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195]], [3, 4, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195]], [3, 4, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])]]
for label, args, expected in fixtures[N-1]:
check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| plain one-byte and modrm forms | [1, 2, 3, 1, 1] | [1, 2, 3, 1, 1] | Passed |
| sib with disp32 base | [7, 4, 4, 1] | [7, 4, 4, 1] | Passed |
| operand size prefix on immediates | [4, 5, 5] | [4, 5, 5] | Passed |
| prefix after rep | [5, 1, 6] | [5, 1, 6] | Passed |
| sign-extended imm8 form | [3, 4, 1] | [3, 4, 1] | Passed |
| 16-bit addressing | [5, 4, 5] | [5, 4, 5] | Passed |
| two-byte opcodes | [2, 2, 1, 1, 2, 1, 1] | [6, 3, 1] | Failed |
| rip-less disp32 and disp32 mod 2 | [6, 6, 2] | [6, 6, 2] | Passed |
SHA-256 / 37678ba3b39b531f08fcfbce5bb3efdc6bdaf139dadef78513a20cddb3ced74a
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(*args):
code = args[0]
def b(k):
return code[k] if k < len(code) else 0
i = 0
lens = []
while i < len(code):
start = i
osz = 4
asz = 4
while b(i) in (0x66, 0x67, 0xF0, 0xF2, 0xF3):
if b(i) == 0x66: osz = 2
if b(i) == 0x67: asz = 2
i += 1
op = b(i)
i += 1
if op == 0x0F:
op = 0x0F00 | b(i)
i += 1
modrm = op in (0x01, 0x03, 0x89, 0x8B, 0x81, 0x83, 0x0FAF)
imm = {0x81: osz, 0x83: 1, 0xE8: osz, 0xEB: 1, 0x0F84: osz}.get(op, osz if 0xB8 <= op <= 0xBF else 0)
if modrm:
m = b(i)
i += 1
mod, rm = m >> 6, m & 7
if mod != 3:
if asz == 2:
i += 2 if (mod == 0 and rm == 6) or mod == 2 else mod
else:
if rm == 4:
base = b(i) & 7
i += 1
if mod == 0 and base == 5:
i += 4
i += 4 if (mod == 0 and rm == 5) or mod == 2 else mod
i += imm
lens.append(i - start)
return lens
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144]], [1, 2, 3, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195]], [3, 4, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144]], [1, 2, 3, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195]], [3, 4, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195]], [3, 4, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 254]], [6, 6, 2])], [('plain one-byte and modrm forms', [[144, 137, 195, 139, 69, 8, 195, 144, 144, 144, 144, 144]], [1, 2, 3, 1, 1, 1, 1, 1, 1]), ('sib with disp32 base', [[139, 4, 37, 1, 2, 3, 4, 139, 68, 36, 16, 139, 68, 37, 16, 144]], [7, 4, 4, 1]), ('operand size prefix on immediates', [[102, 184, 52, 18, 102, 129, 192, 1, 0, 184, 1, 2, 3, 4]], [4, 5, 5]), ('prefix after rep', [[243, 102, 184, 52, 18, 144, 144, 144, 144, 144, 240, 102, 129, 192, 16, 0]], [5, 1, 1, 1, 1, 1, 6]), ('sign-extended imm8 form', [[131, 192, 1, 131, 69, 8, 255, 195, 195, 195, 195, 195]], [3, 4, 1, 1, 1, 1, 1]), ('16-bit addressing', [[103, 139, 6, 52, 18, 103, 139, 71, 2, 103, 139, 135, 0, 16]], [5, 4, 5]), ('two-byte opcodes', [[15, 132, 1, 0, 0, 0, 15, 175, 193, 144]], [6, 3, 1]), ('rip-less disp32 and disp32 mod 2', [[139, 5, 0, 0, 1, 0, 139, 128, 0, 1, 0, 0, 235, 255]], [6, 6, 2])]]
for label, args, expected in fixtures[N-1]:
check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| plain one-byte and modrm forms | [1, 2, 3, 1, 1] | [1, 2, 3, 1, 1] | Passed |
| sib with disp32 base | [7, 4, 4, 1] | [7, 4, 4, 1] | Passed |
| operand size prefix on immediates | [4, 5, 5] | [4, 5, 5] | Passed |
| prefix after rep | [5, 1, 6] | [5, 1, 6] | Passed |
| sign-extended imm8 form | [3, 4, 1] | [3, 4, 1] | Passed |
| 16-bit addressing | [5, 4, 5] | [5, 4, 5] | Passed |
| two-byte opcodes | [6, 3, 1] | [6, 3, 1] | Passed |
| rip-less disp32 and disp32 mod 2 | [6, 6, 2] | [6, 6, 2] | Passed |
SHA-256 / 6646db4e46da04f84a39ca3d6711b8b9ac58dbf8330d7d962bf464568ee47ca1
Verification & scope
A deterministic bounded teaching model of one emulator rule; the instruction semantics are a stipulated contract inspired by common ISAs and are not a claim of cycle-exact or architectural conformance. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:51:19.175818+00:00.
Case digest / 5abc56946453a12aa6c69071ffa5038a0a713220aa592a5bec4d377714b2b6bb