FAILURE MAP
← Case archive

FA-89766 / Instruction set emulation / Open access

MPIE captures the already cleared enable · case 01

After mret interrupts stay disabled even though they were enabled before the trap.

Verified by executionVariant 1 · 8 checks per implementationDownload source bundle ↓JSON ↗

ROOT CAUSE

MIE is cleared before it is copied into MPIE.

THE FAILURE

MIE is cleared before it is copied into MPIE.

Unsuccessful approach: Forcing MPIE to 1 re-enables interrupts that were disabled before the trap.

Case contract

Input [pc, priv, mie, mtvec, events]; MPIE, MPP, mcause, mepc start 0. step: pc += 4. ecall: exception cause 8 + priv (U 8, S 9, M 11). illegal: cause 2. irq k: interrupt cause 2^31 | k, taken only if priv < 3 or MIE. Trap: mepc = pc, mcause = cause, MPIE = MIE, MIE = 0, MPP = priv, priv = 3, pc = mtvec base (mtvec & ~3), plus 4*k for interrupts when mtvec mode (low 2 bits) is 1. mret: MIE = MPIE, MPIE = 1, priv = MPP, MPP = 0, pc = mepc. Return [pc, priv, MIE, MPIE, MPP, mcause, mepc] after each event.

Why this case matters

Trap and return sequencing defines how emulated operating systems handle syscalls and interrupts; one misordered status update corrupts the interrupt enable state.

1 / The failure

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(*args):
    pc, priv, mie, mtvec, events = args
    mpie = mpp = mcause = mepc = 0
    log = []
    for ev in events:
        kind = ev[0]
        trap = None
        if kind == 'step':
            pc += 4
        elif kind == 'ecall':
            trap = 8 + priv
        elif kind == 'illegal':
            trap = 2
        elif kind == 'irq':
            if priv < 3 or mie:
                trap = (1 << 31) | ev[1]
        elif kind == 'mret':
            mie = mpie
            mpie = 1
            priv = mpp
            mpp = 0
            pc = mepc
        if trap is not None:
            mepc = pc
            mcause = trap
            mie = 0
            mpie = mie
            mpp = priv
            priv = 3
            base = mtvec & ~3
            pc = base + 4 * (trap & 0x7FFFFFFF) if (mtvec & 3) == 1 and trap >> 31 else base
        log.append([pc, priv, mie, mpie, mpp, mcause, mepc])
    return log
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('user ecall and return', [1028, 0, 1, 4096, [['step'], ['ecall'], ['step'], ['mret']]], [[1032, 0, 1, 0, 0, 0, 0], [4096, 3, 0, 1, 0, 8, 1032], [4100, 3, 0, 1, 0, 8, 1032], [1032, 0, 1, 1, 0, 8, 1032]]), ('supervisor and machine ecall', [1024, 1, 0, 4096, [['ecall'], ['ecall'], ['mret'], ['mret']]], [[4096, 3, 0, 0, 1, 9, 1024], [4096, 3, 0, 0, 3, 11, 4096], [4096, 3, 0, 1, 0, 11, 4096], [4096, 0, 1, 1, 0, 11, 4096]]), ('supervisor interrupt with mie clear', [1280, 1, 0, 4097, [['irq', 7], ['mret'], ['step']]], [[4124, 3, 0, 0, 1, 2147483655, 1280], [1280, 1, 0, 1, 0, 2147483655, 1280], [1284, 1, 0, 1, 0, 2147483655, 1280]]), ('machine interrupt masked then enabled', [1536, 3, 0, 4097, [['irq', 3], ['step'], ['mret'], ['irq', 10]]], [[1536, 3, 0, 0, 0, 0, 0], [1540, 3, 0, 0, 0, 0, 0], [0, 0, 0, 1, 0, 0, 0], [4136, 3, 0, 0, 0, 2147483658, 0]]), ('machine interrupt enabled saves mie', [1792, 3, 1, 8192, [['irq', 7], ['mret'], ['step']]], [[8192, 3, 0, 1, 3, 2147483655, 1792], [1792, 3, 1, 1, 0, 2147483655, 1792], [1796, 3, 1, 1, 0, 2147483655, 1792]]), ('vectored mode exceptions go to base', [2048, 0, 1, 12289, [['illegal'], ['mret'], ['ecall']]], [[12288, 3, 0, 1, 0, 2, 2048], [2048, 0, 1, 1, 0, 2, 2048], [12288, 3, 0, 1, 0, 8, 2048]]), ('reserved mode bits masked', [2560, 1, 1, 4354, [['ecall'], ['mret']]], [[4352, 3, 0, 1, 1, 9, 2560], [2560, 1, 1, 1, 0, 9, 2560]]), ('nested trap overwrites mpp', [2304, 0, 1, 4096, [['ecall'], ['illegal'], ['mret'], ['mret'], ['step']]], [[4096, 3, 0, 1, 0, 8, 2304], [4096, 3, 0, 0, 3, 2, 4096], [4096, 3, 0, 1, 0, 2, 4096], [4096, 0, 1, 1, 0, 2, 4096], [4100, 0, 1, 1, 0, 2, 4096]])], [('user ecall and return', [1032, 0, 1, 4096, [['step'], ['ecall'], ['step'], ['mret']]], [[1036, 0, 1, 0, 0, 0, 0], [4096, 3, 0, 1, 0, 8, 1036], [4100, 3, 0, 1, 0, 8, 1036], [1036, 0, 1, 1, 0, 8, 1036]]), ('supervisor and machine ecall', [1024, 1, 0, 4096, [['ecall'], ['ecall'], ['mret'], ['mret']]], [[4096, 3, 0, 0, 1, 9, 1024], [4096, 3, 0, 0, 3, 11, 4096], [4096, 3, 0, 1, 0, 11, 4096], [4096, 0, 1, 1, 0, 11, 4096]]), ('supervisor interrupt with mie clear', [1280, 1, 0, 4097, [['irq', 7], ['mret'], ['step']]], [[4124, 3, 0, 0, 1, 2147483655, 1280], [1280, 1, 0, 1, 0, 2147483655, 1280], [1284, 1, 0, 1, 0, 2147483655, 1280]]), ('machine interrupt masked then enabled', [1536, 3, 0, 4097, [['irq', 3], ['step'], ['mret'], ['irq', 11]]], [[1536, 3, 0, 0, 0, 0, 0], [1540, 3, 0, 0, 0, 0, 0], [0, 0, 0, 1, 0, 0, 0], [4140, 3, 0, 0, 0, 2147483659, 0]]), ('machine interrupt enabled saves mie', [1792, 3, 1, 8192, [['irq', 7], ['mret'], ['step']]], [[8192, 3, 0, 1, 3, 2147483655, 1792], [1792, 3, 1, 1, 0, 2147483655, 1792], [1796, 3, 1, 1, 0, 2147483655, 1792]]), ('vectored mode exceptions go to base', [2048, 0, 1, 12289, [['illegal'], ['mret'], ['ecall']]], [[12288, 3, 0, 1, 0, 2, 2048], [2048, 0, 1, 1, 0, 2, 2048], [12288, 3, 0, 1, 0, 8, 2048]]), ('reserved mode bits masked', [2560, 1, 1, 4610, [['ecall'], ['mret']]], [[4608, 3, 0, 1, 1, 9, 2560], [2560, 1, 1, 1, 0, 9, 2560]]), ('nested trap overwrites mpp', [2304, 0, 1, 4096, [['ecall'], ['illegal'], ['mret'], ['mret'], ['step'], ['step']]], [[4096, 3, 0, 1, 0, 8, 2304], [4096, 3, 0, 0, 3, 2, 4096], [4096, 3, 0, 1, 0, 2, 4096], [4096, 0, 1, 1, 0, 2, 4096], [4100, 0, 1, 1, 0, 2, 4096], [4104, 0, 1, 1, 0, 2, 4096]])], [('user ecall and return', [1036, 0, 1, 4096, [['step'], ['ecall'], ['step'], ['mret']]], [[1040, 0, 1, 0, 0, 0, 0], [4096, 3, 0, 1, 0, 8, 1040], [4100, 3, 0, 1, 0, 8, 1040], [1040, 0, 1, 1, 0, 8, 1040]]), ('supervisor and machine ecall', [1024, 1, 0, 4096, [['ecall'], ['ecall'], ['mret'], ['mret']]], [[4096, 3, 0, 0, 1, 9, 1024], [4096, 3, 0, 0, 3, 11, 4096], [4096, 3, 0, 1, 0, 11, 4096], [4096, 0, 1, 1, 0, 11, 4096]]), ('supervisor interrupt with mie clear', [1280, 1, 0, 4097, [['irq', 7], ['mret'], ['step']]], [[4124, 3, 0, 0, 1, 2147483655, 1280], [1280, 1, 0, 1, 0, 2147483655, 1280], [1284, 1, 0, 1, 0, 2147483655, 1280]]), ('machine interrupt masked then enabled', [1536, 3, 0, 4097, [['irq', 3], ['step'], ['mret'], ['irq', 10]]], [[1536, 3, 0, 0, 0, 0, 0], [1540, 3, 0, 0, 0, 0, 0], [0, 0, 0, 1, 0, 0, 0], [4136, 3, 0, 0, 0, 2147483658, 0]]), ('machine interrupt enabled saves mie', [1792, 3, 1, 8192, [['irq', 7], ['mret'], ['step']]], [[8192, 3, 0, 1, 3, 2147483655, 1792], [1792, 3, 1, 1, 0, 2147483655, 1792], [1796, 3, 1, 1, 0, 2147483655, 1792]]), ('vectored mode exceptions go to base', [2048, 0, 1, 12289, [['illegal'], ['mret'], ['ecall']]], [[12288, 3, 0, 1, 0, 2, 2048], [2048, 0, 1, 1, 0, 2, 2048], [12288, 3, 0, 1, 0, 8, 2048]]), ('reserved mode bits masked', [2560, 1, 1, 4866, [['ecall'], ['mret']]], [[4864, 3, 0, 1, 1, 9, 2560], [2560, 1, 1, 1, 0, 9, 2560]]), ('nested trap overwrites mpp', [2304, 0, 1, 4096, [['ecall'], ['illegal'], ['mret'], ['mret'], ['step'], ['step'], ['step']]], [[4096, 3, 0, 1, 0, 8, 2304], [4096, 3, 0, 0, 3, 2, 4096], [4096, 3, 0, 1, 0, 2, 4096], [4096, 0, 1, 1, 0, 2, 4096], [4100, 0, 1, 1, 0, 2, 4096], [4104, 0, 1, 1, 0, 2, 4096], [4108, 0, 1, 1, 0, 2, 4096]])], [('user ecall and return', [1040, 0, 1, 4096, [['step'], ['ecall'], ['step'], ['mret']]], [[1044, 0, 1, 0, 0, 0, 0], [4096, 3, 0, 1, 0, 8, 1044], [4100, 3, 0, 1, 0, 8, 1044], [1044, 0, 1, 1, 0, 8, 1044]]), ('supervisor and machine ecall', [1024, 1, 0, 4096, [['ecall'], ['ecall'], ['mret'], ['mret']]], [[4096, 3, 0, 0, 1, 9, 1024], [4096, 3, 0, 0, 3, 11, 4096], [4096, 3, 0, 1, 0, 11, 4096], [4096, 0, 1, 1, 0, 11, 4096]]), ('supervisor interrupt with mie clear', [1280, 1, 0, 4097, [['irq', 7], ['mret'], ['step']]], [[4124, 3, 0, 0, 1, 2147483655, 1280], [1280, 1, 0, 1, 0, 2147483655, 1280], [1284, 1, 0, 1, 0, 2147483655, 1280]]), ('machine interrupt masked then enabled', [1536, 3, 0, 4097, [['irq', 3], ['step'], ['mret'], ['irq', 11]]], [[1536, 3, 0, 0, 0, 0, 0], [1540, 3, 0, 0, 0, 0, 0], [0, 0, 0, 1, 0, 0, 0], [4140, 3, 0, 0, 0, 2147483659, 0]]), ('machine interrupt enabled saves mie', [1792, 3, 1, 8192, [['irq', 7], ['mret'], ['step']]], [[8192, 3, 0, 1, 3, 2147483655, 1792], [1792, 3, 1, 1, 0, 2147483655, 1792], [1796, 3, 1, 1, 0, 2147483655, 1792]]), ('vectored mode exceptions go to base', [2048, 0, 1, 12289, [['illegal'], ['mret'], ['ecall']]], [[12288, 3, 0, 1, 0, 2, 2048], [2048, 0, 1, 1, 0, 2, 2048], [12288, 3, 0, 1, 0, 8, 2048]]), ('reserved mode bits masked', [2560, 1, 1, 5122, [['ecall'], ['mret']]], [[5120, 3, 0, 1, 1, 9, 2560], [2560, 1, 1, 1, 0, 9, 2560]]), ('nested trap overwrites mpp', [2304, 0, 1, 4096, [['ecall'], ['illegal'], ['mret'], ['mret'], ['step'], ['step'], ['step'], ['step']]], [[4096, 3, 0, 1, 0, 8, 2304], [4096, 3, 0, 0, 3, 2, 4096], [4096, 3, 0, 1, 0, 2, 4096], [4096, 0, 1, 1, 0, 2, 4096], [4100, 0, 1, 1, 0, 2, 4096], [4104, 0, 1, 1, 0, 2, 4096], [4108, 0, 1, 1, 0, 2, 4096], [4112, 0, 1, 1, 0, 2, 4096]])], [('user ecall and return', [1044, 0, 1, 4096, [['step'], ['ecall'], ['step'], ['mret']]], [[1048, 0, 1, 0, 0, 0, 0], [4096, 3, 0, 1, 0, 8, 1048], [4100, 3, 0, 1, 0, 8, 1048], [1048, 0, 1, 1, 0, 8, 1048]]), ('supervisor and machine ecall', [1024, 1, 0, 4096, [['ecall'], ['ecall'], ['mret'], ['mret']]], [[4096, 3, 0, 0, 1, 9, 1024], [4096, 3, 0, 0, 3, 11, 4096], [4096, 3, 0, 1, 0, 11, 4096], [4096, 0, 1, 1, 0, 11, 4096]]), ('supervisor interrupt with mie clear', [1280, 1, 0, 4097, [['irq', 7], ['mret'], ['step']]], [[4124, 3, 0, 0, 1, 2147483655, 1280], [1280, 1, 0, 1, 0, 2147483655, 1280], [1284, 1, 0, 1, 0, 2147483655, 1280]]), ('machine interrupt masked then enabled', [1536, 3, 0, 4097, [['irq', 3], ['step'], ['mret'], ['irq', 10]]], [[1536, 3, 0, 0, 0, 0, 0], [1540, 3, 0, 0, 0, 0, 0], [0, 0, 0, 1, 0, 0, 0], [4136, 3, 0, 0, 0, 2147483658, 0]]), ('machine interrupt enabled saves mie', [1792, 3, 1, 8192, [['irq', 7], ['mret'], ['step']]], [[8192, 3, 0, 1, 3, 2147483655, 1792], [1792, 3, 1, 1, 0, 2147483655, 1792], [1796, 3, 1, 1, 0, 2147483655, 1792]]), ('vectored mode exceptions go to base', [2048, 0, 1, 12289, [['illegal'], ['mret'], ['ecall']]], [[12288, 3, 0, 1, 0, 2, 2048], [2048, 0, 1, 1, 0, 2, 2048], [12288, 3, 0, 1, 0, 8, 2048]]), ('reserved mode bits masked', [2560, 1, 1, 5378, [['ecall'], ['mret']]], [[5376, 3, 0, 1, 1, 9, 2560], [2560, 1, 1, 1, 0, 9, 2560]]), ('nested trap overwrites mpp', [2304, 0, 1, 4096, [['ecall'], ['illegal'], ['mret'], ['mret'], ['step'], ['step'], ['step'], ['step'], ['step']]], [[4096, 3, 0, 1, 0, 8, 2304], [4096, 3, 0, 0, 3, 2, 4096], [4096, 3, 0, 1, 0, 2, 4096], [4096, 0, 1, 1, 0, 2, 4096], [4100, 0, 1, 1, 0, 2, 4096], [4104, 0, 1, 1, 0, 2, 4096], [4108, 0, 1, 1, 0, 2, 4096], [4112, 0, 1, 1, 0, 2, 4096], [4116, 0, 1, 1, 0, 2, 4096]])]]
for label, args, expected in fixtures[N-1]:
    check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
user ecall and return[[1032, 0, 1, 0, 0, 0, 0], [4096, 3, 0, 0, 0, 8, 1032], [4100, 3, 0, 0, 0, 8, 1032], [1032, 0, 0, 1, 0, 8, 1032]][[1032, 0, 1, 0, 0, 0, 0], [4096, 3, 0, 1, 0, 8, 1032], [4100, 3, 0, 1, 0, 8, 1032], [1032, 0, 1, 1, 0, 8, 1032]]Failed
supervisor and machine ecall[[4096, 3, 0, 0, 1, 9, 1024], [4096, 3, 0, 0, 3, 11, 4096], [4096, 3, 0, 1, 0, 11, 4096], [4096, 0, 1, 1, 0, 11, 4096]][[4096, 3, 0, 0, 1, 9, 1024], [4096, 3, 0, 0, 3, 11, 4096], [4096, 3, 0, 1, 0, 11, 4096], [4096, 0, 1, 1, 0, 11, 4096]]Passed
supervisor interrupt with mie clear[[4124, 3, 0, 0, 1, 2147483655, 1280], [1280, 1, 0, 1, 0, 2147483655, 1280], [1284, 1, 0, 1, 0, 2147483655, 1280]][[4124, 3, 0, 0, 1, 2147483655, 1280], [1280, 1, 0, 1, 0, 2147483655, 1280], [1284, 1, 0, 1, 0, 2147483655, 1280]]Passed
machine interrupt masked then enabled[[1536, 3, 0, 0, 0, 0, 0], [1540, 3, 0, 0, 0, 0, 0], [0, 0, 0, 1, 0, 0, 0], [4136, 3, 0, 0, 0, 2147483658, 0]][[1536, 3, 0, 0, 0, 0, 0], [1540, 3, 0, 0, 0, 0, 0], [0, 0, 0, 1, 0, 0, 0], [4136, 3, 0, 0, 0, 2147483658, 0]]Passed
machine interrupt enabled saves mie[[8192, 3, 0, 0, 3, 2147483655, 1792], [1792, 3, 0, 1, 0, 2147483655, 1792], [1796, 3, 0, 1, 0, 2147483655, 1792]][[8192, 3, 0, 1, 3, 2147483655, 1792], [1792, 3, 1, 1, 0, 2147483655, 1792], [1796, 3, 1, 1, 0, 2147483655, 1792]]Failed
vectored mode exceptions go to base[[12288, 3, 0, 0, 0, 2, 2048], [2048, 0, 0, 1, 0, 2, 2048], [12288, 3, 0, 0, 0, 8, 2048]][[12288, 3, 0, 1, 0, 2, 2048], [2048, 0, 1, 1, 0, 2, 2048], [12288, 3, 0, 1, 0, 8, 2048]]Failed
reserved mode bits masked[[4352, 3, 0, 0, 1, 9, 2560], [2560, 1, 0, 1, 0, 9, 2560]][[4352, 3, 0, 1, 1, 9, 2560], [2560, 1, 1, 1, 0, 9, 2560]]Failed
nested trap overwrites mpp[[4096, 3, 0, 0, 0, 8, 2304], [4096, 3, 0, 0, 3, 2, 4096], [4096, 3, 0, 1, 0, 2, 4096], [4096, 0, 1, 1, 0, 2, 4096], [4100, 0, 1, 1, 0, 2, 4096]][[4096, 3, 0, 1, 0, 8, 2304], [4096, 3, 0, 0, 3, 2, 4096], [4096, 3, 0, 1, 0, 2, 4096], [4096, 0, 1, 1, 0, 2, 4096], [4100, 0, 1, 1, 0, 2, 4096]]Failed

SHA-256 / ffa7c9bbca5dfc4670693eaa600957e17b7bb965c1b7ed0cda7c5e890d03df00

2 / The unsuccessful fix

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(*args):
    pc, priv, mie, mtvec, events = args
    mpie = mpp = mcause = mepc = 0
    log = []
    for ev in events:
        kind = ev[0]
        trap = None
        if kind == 'step':
            pc += 4
        elif kind == 'ecall':
            trap = 8 + priv
        elif kind == 'illegal':
            trap = 2
        elif kind == 'irq':
            if priv < 3 or mie:
                trap = (1 << 31) | ev[1]
        elif kind == 'mret':
            mie = mpie
            mpie = 1
            priv = mpp
            mpp = 0
            pc = mepc
        if trap is not None:
            mepc = pc
            mcause = trap
            mpie = 1
            mie = 0
            mpp = priv
            priv = 3
            base = mtvec & ~3
            pc = base + 4 * (trap & 0x7FFFFFFF) if (mtvec & 3) == 1 and trap >> 31 else base
        log.append([pc, priv, mie, mpie, mpp, mcause, mepc])
    return log
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[('user ecall and return', [1028, 0, 1, 4096, [['step'], ['ecall'], ['step'], ['mret']]], [[1032, 0, 1, 0, 0, 0, 0], [4096, 3, 0, 1, 0, 8, 1032], [4100, 3, 0, 1, 0, 8, 1032], [1032, 0, 1, 1, 0, 8, 1032]]), ('supervisor and machine ecall', [1024, 1, 0, 4096, [['ecall'], ['ecall'], ['mret'], ['mret']]], [[4096, 3, 0, 0, 1, 9, 1024], [4096, 3, 0, 0, 3, 11, 4096], [4096, 3, 0, 1, 0, 11, 4096], [4096, 0, 1, 1, 0, 11, 4096]]), ('supervisor interrupt with mie clear', [1280, 1, 0, 4097, [['irq', 7], ['mret'], ['step']]], [[4124, 3, 0, 0, 1, 2147483655, 1280], [1280, 1, 0, 1, 0, 2147483655, 1280], [1284, 1, 0, 1, 0, 2147483655, 1280]]), ('machine interrupt masked then enabled', [1536, 3, 0, 4097, [['irq', 3], ['step'], ['mret'], ['irq', 10]]], [[1536, 3, 0, 0, 0, 0, 0], [1540, 3, 0, 0, 0, 0, 0], [0, 0, 0, 1, 0, 0, 0], [4136, 3, 0, 0, 0, 2147483658, 0]]), ('machine interrupt enabled saves mie', [1792, 3, 1, 8192, [['irq', 7], ['mret'], ['step']]], [[8192, 3, 0, 1, 3, 2147483655, 1792], [1792, 3, 1, 1, 0, 2147483655, 1792], [1796, 3, 1, 1, 0, 2147483655, 1792]]), ('vectored mode exceptions go to base', [2048, 0, 1, 12289, [['illegal'], ['mret'], ['ecall']]], [[12288, 3, 0, 1, 0, 2, 2048], [2048, 0, 1, 1, 0, 2, 2048], [12288, 3, 0, 1, 0, 8, 2048]]), ('reserved mode bits masked', [2560, 1, 1, 4354, [['ecall'], ['mret']]], [[4352, 3, 0, 1, 1, 9, 2560], [2560, 1, 1, 1, 0, 9, 2560]]), ('nested trap overwrites mpp', [2304, 0, 1, 4096, [['ecall'], ['illegal'], ['mret'], ['mret'], ['step']]], [[4096, 3, 0, 1, 0, 8, 2304], [4096, 3, 0, 0, 3, 2, 4096], [4096, 3, 0, 1, 0, 2, 4096], [4096, 0, 1, 1, 0, 2, 4096], [4100, 0, 1, 1, 0, 2, 4096]])], [('user ecall and return', [1032, 0, 1, 4096, [['step'], ['ecall'], ['step'], ['mret']]], [[1036, 0, 1, 0, 0, 0, 0], [4096, 3, 0, 1, 0, 8, 1036], [4100, 3, 0, 1, 0, 8, 1036], [1036, 0, 1, 1, 0, 8, 1036]]), ('supervisor and machine ecall', [1024, 1, 0, 4096, [['ecall'], ['ecall'], ['mret'], ['mret']]], [[4096, 3, 0, 0, 1, 9, 1024], [4096, 3, 0, 0, 3, 11, 4096], [4096, 3, 0, 1, 0, 11, 4096], [4096, 0, 1, 1, 0, 11, 4096]]), ('supervisor interrupt with mie clear', [1280, 1, 0, 4097, [['irq', 7], ['mret'], ['step']]], [[4124, 3, 0, 0, 1, 2147483655, 1280], [1280, 1, 0, 1, 0, 2147483655, 1280], [1284, 1, 0, 1, 0, 2147483655, 1280]]), ('machine interrupt masked then enabled', [1536, 3, 0, 4097, [['irq', 3], ['step'], ['mret'], ['irq', 11]]], [[1536, 3, 0, 0, 0, 0, 0], [1540, 3, 0, 0, 0, 0, 0], [0, 0, 0, 1, 0, 0, 0], [4140, 3, 0, 0, 0, 2147483659, 0]]), ('machine interrupt enabled saves mie', [1792, 3, 1, 8192, [['irq', 7], ['mret'], ['step']]], [[8192, 3, 0, 1, 3, 2147483655, 1792], [1792, 3, 1, 1, 0, 2147483655, 1792], [1796, 3, 1, 1, 0, 2147483655, 1792]]), ('vectored mode exceptions go to base', [2048, 0, 1, 12289, [['illegal'], ['mret'], ['ecall']]], [[12288, 3, 0, 1, 0, 2, 2048], [2048, 0, 1, 1, 0, 2, 2048], [12288, 3, 0, 1, 0, 8, 2048]]), ('reserved mode bits masked', [2560, 1, 1, 4610, [['ecall'], ['mret']]], [[4608, 3, 0, 1, 1, 9, 2560], [2560, 1, 1, 1, 0, 9, 2560]]), ('nested trap overwrites mpp', [2304, 0, 1, 4096, [['ecall'], ['illegal'], ['mret'], ['mret'], ['step'], ['step']]], [[4096, 3, 0, 1, 0, 8, 2304], [4096, 3, 0, 0, 3, 2, 4096], [4096, 3, 0, 1, 0, 2, 4096], [4096, 0, 1, 1, 0, 2, 4096], [4100, 0, 1, 1, 0, 2, 4096], [4104, 0, 1, 1, 0, 2, 4096]])], [('user ecall and return', [1036, 0, 1, 4096, [['step'], ['ecall'], ['step'], ['mret']]], [[1040, 0, 1, 0, 0, 0, 0], [4096, 3, 0, 1, 0, 8, 1040], [4100, 3, 0, 1, 0, 8, 1040], [1040, 0, 1, 1, 0, 8, 1040]]), ('supervisor and machine ecall', [1024, 1, 0, 4096, [['ecall'], ['ecall'], ['mret'], ['mret']]], [[4096, 3, 0, 0, 1, 9, 1024], [4096, 3, 0, 0, 3, 11, 4096], [4096, 3, 0, 1, 0, 11, 4096], [4096, 0, 1, 1, 0, 11, 4096]]), ('supervisor interrupt with mie clear', [1280, 1, 0, 4097, [['irq', 7], ['mret'], ['step']]], [[4124, 3, 0, 0, 1, 2147483655, 1280], [1280, 1, 0, 1, 0, 2147483655, 1280], [1284, 1, 0, 1, 0, 2147483655, 1280]]), ('machine interrupt masked then enabled', [1536, 3, 0, 4097, [['irq', 3], ['step'], ['mret'], ['irq', 10]]], [[1536, 3, 0, 0, 0, 0, 0], [1540, 3, 0, 0, 0, 0, 0], [0, 0, 0, 1, 0, 0, 0], [4136, 3, 0, 0, 0, 2147483658, 0]]), ('machine interrupt enabled saves mie', [1792, 3, 1, 8192, [['irq', 7], ['mret'], ['step']]], [[8192, 3, 0, 1, 3, 2147483655, 1792], [1792, 3, 1, 1, 0, 2147483655, 1792], [1796, 3, 1, 1, 0, 2147483655, 1792]]), ('vectored mode exceptions go to base', [2048, 0, 1, 12289, [['illegal'], ['mret'], ['ecall']]], [[12288, 3, 0, 1, 0, 2, 2048], [2048, 0, 1, 1, 0, 2, 2048], [12288, 3, 0, 1, 0, 8, 2048]]), ('reserved mode bits masked', [2560, 1, 1, 4866, [['ecall'], ['mret']]], [[4864, 3, 0, 1, 1, 9, 2560], [2560, 1, 1, 1, 0, 9, 2560]]), ('nested trap overwrites mpp', [2304, 0, 1, 4096, [['ecall'], ['illegal'], ['mret'], ['mret'], ['step'], ['step'], ['step']]], [[4096, 3, 0, 1, 0, 8, 2304], [4096, 3, 0, 0, 3, 2, 4096], [4096, 3, 0, 1, 0, 2, 4096], [4096, 0, 1, 1, 0, 2, 4096], [4100, 0, 1, 1, 0, 2, 4096], [4104, 0, 1, 1, 0, 2, 4096], [4108, 0, 1, 1, 0, 2, 4096]])], [('user ecall and return', [1040, 0, 1, 4096, [['step'], ['ecall'], ['step'], ['mret']]], [[1044, 0, 1, 0, 0, 0, 0], [4096, 3, 0, 1, 0, 8, 1044], [4100, 3, 0, 1, 0, 8, 1044], [1044, 0, 1, 1, 0, 8, 1044]]), ('supervisor and machine ecall', [1024, 1, 0, 4096, [['ecall'], ['ecall'], ['mret'], ['mret']]], [[4096, 3, 0, 0, 1, 9, 1024], [4096, 3, 0, 0, 3, 11, 4096], [4096, 3, 0, 1, 0, 11, 4096], [4096, 0, 1, 1, 0, 11, 4096]]), ('supervisor interrupt with mie clear', [1280, 1, 0, 4097, [['irq', 7], ['mret'], ['step']]], [[4124, 3, 0, 0, 1, 2147483655, 1280], [1280, 1, 0, 1, 0, 2147483655, 1280], [1284, 1, 0, 1, 0, 2147483655, 1280]]), ('machine interrupt masked then enabled', [1536, 3, 0, 4097, [['irq', 3], ['step'], ['mret'], ['irq', 11]]], [[1536, 3, 0, 0, 0, 0, 0], [1540, 3, 0, 0, 0, 0, 0], [0, 0, 0, 1, 0, 0, 0], [4140, 3, 0, 0, 0, 2147483659, 0]]), ('machine interrupt enabled saves mie', [1792, 3, 1, 8192, [['irq', 7], ['mret'], ['step']]], [[8192, 3, 0, 1, 3, 2147483655, 1792], [1792, 3, 1, 1, 0, 2147483655, 1792], [1796, 3, 1, 1, 0, 2147483655, 1792]]), ('vectored mode exceptions go to base', [2048, 0, 1, 12289, [['illegal'], ['mret'], ['ecall']]], [[12288, 3, 0, 1, 0, 2, 2048], [2048, 0, 1, 1, 0, 2, 2048], [12288, 3, 0, 1, 0, 8, 2048]]), ('reserved mode bits masked', [2560, 1, 1, 5122, [['ecall'], ['mret']]], [[5120, 3, 0, 1, 1, 9, 2560], [2560, 1, 1, 1, 0, 9, 2560]]), ('nested trap overwrites mpp', [2304, 0, 1, 4096, [['ecall'], ['illegal'], ['mret'], ['mret'], ['step'], ['step'], ['step'], ['step']]], [[4096, 3, 0, 1, 0, 8, 2304], [4096, 3, 0, 0, 3, 2, 4096], [4096, 3, 0, 1, 0, 2, 4096], [4096, 0, 1, 1, 0, 2, 4096], [4100, 0, 1, 1, 0, 2, 4096], [4104, 0, 1, 1, 0, 2, 4096], [4108, 0, 1, 1, 0, 2, 4096], [4112, 0, 1, 1, 0, 2, 4096]])], [('user ecall and return', [1044, 0, 1, 4096, [['step'], ['ecall'], ['step'], ['mret']]], [[1048, 0, 1, 0, 0, 0, 0], [4096, 3, 0, 1, 0, 8, 1048], [4100, 3, 0, 1, 0, 8, 1048], [1048, 0, 1, 1, 0, 8, 1048]]), ('supervisor and machine ecall', [1024, 1, 0, 4096, [['ecall'], ['ecall'], ['mret'], ['mret']]], [[4096, 3, 0, 0, 1, 9, 1024], [4096, 3, 0, 0, 3, 11, 4096], [4096, 3, 0, 1, 0, 11, 4096], [4096, 0, 1, 1, 0, 11, 4096]]), ('supervisor interrupt with mie clear', [1280, 1, 0, 4097, [['irq', 7], ['mret'], ['step']]], [[4124, 3, 0, 0, 1, 2147483655, 1280], [1280, 1, 0, 1, 0, 2147483655, 1280], [1284, 1, 0, 1, 0, 2147483655, 1280]]), ('machine interrupt masked then enabled', [1536, 3, 0, 4097, [['irq', 3], ['step'], ['mret'], ['irq', 10]]], [[1536, 3, 0, 0, 0, 0, 0], [1540, 3, 0, 0, 0, 0, 0], [0, 0, 0, 1, 0, 0, 0], [4136, 3, 0, 0, 0, 2147483658, 0]]), ('machine interrupt enabled saves mie', [1792, 3, 1, 8192, [['irq', 7], ['mret'], ['step']]], [[8192, 3, 0, 1, 3, 2147483655, 1792], [1792, 3, 1, 1, 0, 2147483655, 1792], [1796, 3, 1, 1, 0, 2147483655, 1792]]), ('vectored mode exceptions go to base', [2048, 0, 1, 12289, [['illegal'], ['mret'], ['ecall']]], [[12288, 3, 0, 1, 0, 2, 2048], [2048, 0, 1, 1, 0, 2, 2048], [12288, 3, 0, 1, 0, 8, 2048]]), ('reserved mode bits masked', [2560, 1, 1, 5378, [['ecall'], ['mret']]], [[5376, 3, 0, 1, 1, 9, 2560], [2560, 1, 1, 1, 0, 9, 2560]]), ('nested trap overwrites mpp', [2304, 0, 1, 4096, [['ecall'], ['illegal'], ['mret'], ['mret'], ['step'], ['step'], ['step'], ['step'], ['step']]], [[4096, 3, 0, 1, 0, 8, 2304], [4096, 3, 0, 0, 3, 2, 4096], [4096, 3, 0, 1, 0, 2, 4096], [4096, 0, 1, 1, 0, 2, 4096], [4100, 0, 1, 1, 0, 2, 4096], [4104, 0, 1, 1, 0, 2, 4096], [4108, 0, 1, 1, 0, 2, 4096], [4112, 0, 1, 1, 0, 2, 4096], [4116, 0, 1, 1, 0, 2, 4096]])]]
for label, args, expected in fixtures[N-1]:
    check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
user ecall and return[[1032, 0, 1, 0, 0, 0, 0], [4096, 3, 0, 1, 0, 8, 1032], [4100, 3, 0, 1, 0, 8, 1032], [1032, 0, 1, 1, 0, 8, 1032]][[1032, 0, 1, 0, 0, 0, 0], [4096, 3, 0, 1, 0, 8, 1032], [4100, 3, 0, 1, 0, 8, 1032], [1032, 0, 1, 1, 0, 8, 1032]]Passed
supervisor and machine ecall[[4096, 3, 0, 1, 1, 9, 1024], [4096, 3, 0, 1, 3, 11, 4096], [4096, 3, 1, 1, 0, 11, 4096], [4096, 0, 1, 1, 0, 11, 4096]][[4096, 3, 0, 0, 1, 9, 1024], [4096, 3, 0, 0, 3, 11, 4096], [4096, 3, 0, 1, 0, 11, 4096], [4096, 0, 1, 1, 0, 11, 4096]]Failed
supervisor interrupt with mie clear[[4124, 3, 0, 1, 1, 2147483655, 1280], [1280, 1, 1, 1, 0, 2147483655, 1280], [1284, 1, 1, 1, 0, 2147483655, 1280]][[4124, 3, 0, 0, 1, 2147483655, 1280], [1280, 1, 0, 1, 0, 2147483655, 1280], [1284, 1, 0, 1, 0, 2147483655, 1280]]Failed
machine interrupt masked then enabled[[1536, 3, 0, 0, 0, 0, 0], [1540, 3, 0, 0, 0, 0, 0], [0, 0, 0, 1, 0, 0, 0], [4136, 3, 0, 1, 0, 2147483658, 0]][[1536, 3, 0, 0, 0, 0, 0], [1540, 3, 0, 0, 0, 0, 0], [0, 0, 0, 1, 0, 0, 0], [4136, 3, 0, 0, 0, 2147483658, 0]]Failed
machine interrupt enabled saves mie[[8192, 3, 0, 1, 3, 2147483655, 1792], [1792, 3, 1, 1, 0, 2147483655, 1792], [1796, 3, 1, 1, 0, 2147483655, 1792]][[8192, 3, 0, 1, 3, 2147483655, 1792], [1792, 3, 1, 1, 0, 2147483655, 1792], [1796, 3, 1, 1, 0, 2147483655, 1792]]Passed
vectored mode exceptions go to base[[12288, 3, 0, 1, 0, 2, 2048], [2048, 0, 1, 1, 0, 2, 2048], [12288, 3, 0, 1, 0, 8, 2048]][[12288, 3, 0, 1, 0, 2, 2048], [2048, 0, 1, 1, 0, 2, 2048], [12288, 3, 0, 1, 0, 8, 2048]]Passed
reserved mode bits masked[[4352, 3, 0, 1, 1, 9, 2560], [2560, 1, 1, 1, 0, 9, 2560]][[4352, 3, 0, 1, 1, 9, 2560], [2560, 1, 1, 1, 0, 9, 2560]]Passed
nested trap overwrites mpp[[4096, 3, 0, 1, 0, 8, 2304], [4096, 3, 0, 1, 3, 2, 4096], [4096, 3, 1, 1, 0, 2, 4096], [4096, 0, 1, 1, 0, 2, 4096], [4100, 0, 1, 1, 0, 2, 4096]][[4096, 3, 0, 1, 0, 8, 2304], [4096, 3, 0, 0, 3, 2, 4096], [4096, 3, 0, 1, 0, 2, 4096], [4096, 0, 1, 1, 0, 2, 4096], [4100, 0, 1, 1, 0, 2, 4096]]Failed

SHA-256 / 17705085df001a719fab043c69f76d9a455d53bf1cc6d3cdb93fa6acba172af9

HELD IN THE MEMBER ARCHIVE

The verified repair and its recorded checks are member-only.

This mechanism has 8 recorded checks per implementation. The open-access tier publishes the failure and the unsuccessful fix; the repaired source that passes every check, and the observations that prove it, are available to members.

Every case sharing this mechanism uses the same contract and the same repair, so this one record is held back for all of them.

Member access is invitation-based. Sign in with your invited account to inspect the repair.

Sign in to the archive ↗

Verification & scope

A deterministic bounded teaching model of one emulator rule; the instruction semantics are a stipulated contract inspired by common ISAs and are not a claim of cycle-exact or architectural conformance. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.

Observations recorded using Python 3.12.14 at 2026-09-29T14:51:20.582092+00:00.

Case digest / ab3cf32a35890694211edae260a5d49b3ed1d8c5c7e3b5b89052b546087a825b