FA-90296 / Bytecode virtual machines / Open access
Wordcode prefixes: absolute jump targets in instruction units · case 01
Absolute jumps land at half their intended byte offset.
ROOT CAUSE
The argument counts two-byte instructions but is used as a byte offset.
THE FAILURE
The argument counts two-byte instructions but is used as a byte offset.
Unsuccessful approach: Adding 2 after scaling points one instruction past the target.
Case contract
Two-byte wordcode (opcode, arg). EXTENDED_ARG (144) prefixes build wider arguments: each prefix ORs its byte into an accumulator that is then shifted left 8; the real instruction ORs its own byte in and resets the accumulator. Each decoded instruction reports [start of its first prefix, own offset, name, full arg, jump target in bytes]: JUMP_FORWARD (110) targets the next instruction plus 2*arg, JUMP_ABSOLUTE (113) targets 2*arg. A prefix at the end reports ["dangling-extended-arg", start]. A trailing odd byte is ignored.
Why this case matters
Instruction prefixes change argument width and jump targets in wordcode interpreters.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(code):
names = {100: 'LOAD_CONST', 110: 'JUMP_FORWARD', 113: 'JUMP_ABSOLUTE', 83: 'RETURN_VALUE', 9: 'NOP'}
out = []
ext = 0
start = None
for off in range(0, len(code) - 1, 2):
op, arg = code[off], code[off + 1]
if start is None:
start = off
if op == 144:
ext = (ext | arg) << 8
continue
full = ext | arg
ext = 0
target = None
if op == 110:
target = off + 2 + full * 2
elif op == 113:
target = full
out.append([start, off, names.get(op, 'UNKNOWN'), full, target])
start = None
if start is not None:
out.append(['dangling-extended-arg', start])
return out
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
cases = [[('regression: prefixed absolute jump',
([100, 1, 144, 1, 113, 4, 83, 0],),
[[0, 0, 'LOAD_CONST', 1, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
('two prefixes accumulate', ([144, 1, 144, 3, 100, 3],), [[0, 4, 'LOAD_CONST', 66307, None]]),
('prefix does not leak into the next instruction',
([144, 1, 100, 0, 100, 6],),
[[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 6, None]]),
('prefixed forward jump is relative to the next instruction',
([9, 0, 144, 1, 110, 1, 83, 0],),
[[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 257, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
('absolute jump target in bytes',
([113, 1, 83, 0],),
[[0, 0, 'JUMP_ABSOLUTE', 1, 2], [2, 2, 'RETURN_VALUE', 0, None]]),
('trailing prefix with zero argument',
([100, 1, 144, 0],),
[[0, 0, 'LOAD_CONST', 1, None], ['dangling-extended-arg', 2]]),
('control: unknown opcode and odd trailing byte',
([7, 1, 83, 0, 9],),
[[0, 0, 'UNKNOWN', 1, None], [2, 2, 'RETURN_VALUE', 0, None]])],
[('regression: prefixed absolute jump',
([100, 2, 144, 1, 113, 4, 83, 0],),
[[0, 0, 'LOAD_CONST', 2, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
('two prefixes accumulate', ([144, 1, 144, 4, 100, 3],), [[0, 4, 'LOAD_CONST', 66563, None]]),
('prefix does not leak into the next instruction',
([144, 1, 100, 0, 100, 7],),
[[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 7, None]]),
('prefixed forward jump is relative to the next instruction',
([9, 0, 144, 1, 110, 2, 83, 0],),
[[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 258, 522], [6, 6, 'RETURN_VALUE', 0, None]]),
('absolute jump target in bytes',
([113, 2, 83, 0],),
[[0, 0, 'JUMP_ABSOLUTE', 2, 4], [2, 2, 'RETURN_VALUE', 0, None]]),
('trailing prefix with zero argument',
([100, 2, 144, 0],),
[[0, 0, 'LOAD_CONST', 2, None], ['dangling-extended-arg', 2]]),
('control: unknown opcode and odd trailing byte',
([7, 2, 83, 0, 9],),
[[0, 0, 'UNKNOWN', 2, None], [2, 2, 'RETURN_VALUE', 0, None]])],
[('regression: prefixed absolute jump',
([100, 3, 144, 1, 113, 4, 83, 0],),
[[0, 0, 'LOAD_CONST', 3, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
('two prefixes accumulate', ([144, 1, 144, 5, 100, 3],), [[0, 4, 'LOAD_CONST', 66819, None]]),
('prefix does not leak into the next instruction',
([144, 1, 100, 0, 100, 8],),
[[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 8, None]]),
('prefixed forward jump is relative to the next instruction',
([9, 0, 144, 1, 110, 3, 83, 0],),
[[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 259, 524], [6, 6, 'RETURN_VALUE', 0, None]]),
('absolute jump target in bytes',
([113, 3, 83, 0],),
[[0, 0, 'JUMP_ABSOLUTE', 3, 6], [2, 2, 'RETURN_VALUE', 0, None]]),
('trailing prefix with zero argument',
([100, 3, 144, 0],),
[[0, 0, 'LOAD_CONST', 3, None], ['dangling-extended-arg', 2]]),
('control: unknown opcode and odd trailing byte',
([7, 3, 83, 0, 9],),
[[0, 0, 'UNKNOWN', 3, None], [2, 2, 'RETURN_VALUE', 0, None]])],
[('regression: prefixed absolute jump',
([100, 4, 144, 1, 113, 4, 83, 0],),
[[0, 0, 'LOAD_CONST', 4, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
('two prefixes accumulate', ([144, 1, 144, 6, 100, 3],), [[0, 4, 'LOAD_CONST', 67075, None]]),
('prefix does not leak into the next instruction',
([144, 1, 100, 0, 100, 9],),
[[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 9, None]]),
('prefixed forward jump is relative to the next instruction',
([9, 0, 144, 1, 110, 4, 83, 0],),
[[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 260, 526], [6, 6, 'RETURN_VALUE', 0, None]]),
('absolute jump target in bytes',
([113, 4, 83, 0],),
[[0, 0, 'JUMP_ABSOLUTE', 4, 8], [2, 2, 'RETURN_VALUE', 0, None]]),
('trailing prefix with zero argument',
([100, 4, 144, 0],),
[[0, 0, 'LOAD_CONST', 4, None], ['dangling-extended-arg', 2]]),
('control: unknown opcode and odd trailing byte',
([7, 4, 83, 0, 9],),
[[0, 0, 'UNKNOWN', 4, None], [2, 2, 'RETURN_VALUE', 0, None]])],
[('regression: prefixed absolute jump',
([100, 5, 144, 1, 113, 4, 83, 0],),
[[0, 0, 'LOAD_CONST', 5, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
('two prefixes accumulate', ([144, 1, 144, 7, 100, 3],), [[0, 4, 'LOAD_CONST', 67331, None]]),
('prefix does not leak into the next instruction',
([144, 1, 100, 0, 100, 10],),
[[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 10, None]]),
('prefixed forward jump is relative to the next instruction',
([9, 0, 144, 1, 110, 5, 83, 0],),
[[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 261, 528], [6, 6, 'RETURN_VALUE', 0, None]]),
('absolute jump target in bytes',
([113, 5, 83, 0],),
[[0, 0, 'JUMP_ABSOLUTE', 5, 10], [2, 2, 'RETURN_VALUE', 0, None]]),
('trailing prefix with zero argument',
([100, 5, 144, 0],),
[[0, 0, 'LOAD_CONST', 5, None], ['dangling-extended-arg', 2]]),
('control: unknown opcode and odd trailing byte',
([7, 5, 83, 0, 9],),
[[0, 0, 'UNKNOWN', 5, None], [2, 2, 'RETURN_VALUE', 0, None]])]]
for label, args, expected in cases[N - 1]:
check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| regression: prefixed absolute jump | [[0, 0, 'LOAD_CONST', 1, None], [2, 4, 'JUMP_ABSOLUTE', 260, 260], [6, 6, 'RETURN_VALUE', 0, None]] | [[0, 0, 'LOAD_CONST', 1, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]] | Failed |
| two prefixes accumulate | [[0, 4, 'LOAD_CONST', 66307, None]] | [[0, 4, 'LOAD_CONST', 66307, None]] | Passed |
| prefix does not leak into the next instruction | [[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 6, None]] | [[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 6, None]] | Passed |
| prefixed forward jump is relative to the next instruction | [[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 257, 520], [6, 6, 'RETURN_VALUE', 0, None]] | [[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 257, 520], [6, 6, 'RETURN_VALUE', 0, None]] | Passed |
| absolute jump target in bytes | [[0, 0, 'JUMP_ABSOLUTE', 1, 1], [2, 2, 'RETURN_VALUE', 0, None]] | [[0, 0, 'JUMP_ABSOLUTE', 1, 2], [2, 2, 'RETURN_VALUE', 0, None]] | Failed |
| trailing prefix with zero argument | [[0, 0, 'LOAD_CONST', 1, None], ['dangling-extended-arg', 2]] | [[0, 0, 'LOAD_CONST', 1, None], ['dangling-extended-arg', 2]] | Passed |
| control: unknown opcode and odd trailing byte | [[0, 0, 'UNKNOWN', 1, None], [2, 2, 'RETURN_VALUE', 0, None]] | [[0, 0, 'UNKNOWN', 1, None], [2, 2, 'RETURN_VALUE', 0, None]] | Passed |
SHA-256 / 6015e8d175b2396f7a3fd2782be8e6f0e65a5bc06e7ea8d3d587fde45de73b6d
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(code):
names = {100: 'LOAD_CONST', 110: 'JUMP_FORWARD', 113: 'JUMP_ABSOLUTE', 83: 'RETURN_VALUE', 9: 'NOP'}
out = []
ext = 0
start = None
for off in range(0, len(code) - 1, 2):
op, arg = code[off], code[off + 1]
if start is None:
start = off
if op == 144:
ext = (ext | arg) << 8
continue
full = ext | arg
ext = 0
target = None
if op == 110:
target = off + 2 + full * 2
elif op == 113:
target = full * 2 + 2
out.append([start, off, names.get(op, 'UNKNOWN'), full, target])
start = None
if start is not None:
out.append(['dangling-extended-arg', start])
return out
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
cases = [[('regression: prefixed absolute jump',
([100, 1, 144, 1, 113, 4, 83, 0],),
[[0, 0, 'LOAD_CONST', 1, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
('two prefixes accumulate', ([144, 1, 144, 3, 100, 3],), [[0, 4, 'LOAD_CONST', 66307, None]]),
('prefix does not leak into the next instruction',
([144, 1, 100, 0, 100, 6],),
[[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 6, None]]),
('prefixed forward jump is relative to the next instruction',
([9, 0, 144, 1, 110, 1, 83, 0],),
[[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 257, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
('absolute jump target in bytes',
([113, 1, 83, 0],),
[[0, 0, 'JUMP_ABSOLUTE', 1, 2], [2, 2, 'RETURN_VALUE', 0, None]]),
('trailing prefix with zero argument',
([100, 1, 144, 0],),
[[0, 0, 'LOAD_CONST', 1, None], ['dangling-extended-arg', 2]]),
('control: unknown opcode and odd trailing byte',
([7, 1, 83, 0, 9],),
[[0, 0, 'UNKNOWN', 1, None], [2, 2, 'RETURN_VALUE', 0, None]])],
[('regression: prefixed absolute jump',
([100, 2, 144, 1, 113, 4, 83, 0],),
[[0, 0, 'LOAD_CONST', 2, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
('two prefixes accumulate', ([144, 1, 144, 4, 100, 3],), [[0, 4, 'LOAD_CONST', 66563, None]]),
('prefix does not leak into the next instruction',
([144, 1, 100, 0, 100, 7],),
[[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 7, None]]),
('prefixed forward jump is relative to the next instruction',
([9, 0, 144, 1, 110, 2, 83, 0],),
[[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 258, 522], [6, 6, 'RETURN_VALUE', 0, None]]),
('absolute jump target in bytes',
([113, 2, 83, 0],),
[[0, 0, 'JUMP_ABSOLUTE', 2, 4], [2, 2, 'RETURN_VALUE', 0, None]]),
('trailing prefix with zero argument',
([100, 2, 144, 0],),
[[0, 0, 'LOAD_CONST', 2, None], ['dangling-extended-arg', 2]]),
('control: unknown opcode and odd trailing byte',
([7, 2, 83, 0, 9],),
[[0, 0, 'UNKNOWN', 2, None], [2, 2, 'RETURN_VALUE', 0, None]])],
[('regression: prefixed absolute jump',
([100, 3, 144, 1, 113, 4, 83, 0],),
[[0, 0, 'LOAD_CONST', 3, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
('two prefixes accumulate', ([144, 1, 144, 5, 100, 3],), [[0, 4, 'LOAD_CONST', 66819, None]]),
('prefix does not leak into the next instruction',
([144, 1, 100, 0, 100, 8],),
[[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 8, None]]),
('prefixed forward jump is relative to the next instruction',
([9, 0, 144, 1, 110, 3, 83, 0],),
[[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 259, 524], [6, 6, 'RETURN_VALUE', 0, None]]),
('absolute jump target in bytes',
([113, 3, 83, 0],),
[[0, 0, 'JUMP_ABSOLUTE', 3, 6], [2, 2, 'RETURN_VALUE', 0, None]]),
('trailing prefix with zero argument',
([100, 3, 144, 0],),
[[0, 0, 'LOAD_CONST', 3, None], ['dangling-extended-arg', 2]]),
('control: unknown opcode and odd trailing byte',
([7, 3, 83, 0, 9],),
[[0, 0, 'UNKNOWN', 3, None], [2, 2, 'RETURN_VALUE', 0, None]])],
[('regression: prefixed absolute jump',
([100, 4, 144, 1, 113, 4, 83, 0],),
[[0, 0, 'LOAD_CONST', 4, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
('two prefixes accumulate', ([144, 1, 144, 6, 100, 3],), [[0, 4, 'LOAD_CONST', 67075, None]]),
('prefix does not leak into the next instruction',
([144, 1, 100, 0, 100, 9],),
[[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 9, None]]),
('prefixed forward jump is relative to the next instruction',
([9, 0, 144, 1, 110, 4, 83, 0],),
[[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 260, 526], [6, 6, 'RETURN_VALUE', 0, None]]),
('absolute jump target in bytes',
([113, 4, 83, 0],),
[[0, 0, 'JUMP_ABSOLUTE', 4, 8], [2, 2, 'RETURN_VALUE', 0, None]]),
('trailing prefix with zero argument',
([100, 4, 144, 0],),
[[0, 0, 'LOAD_CONST', 4, None], ['dangling-extended-arg', 2]]),
('control: unknown opcode and odd trailing byte',
([7, 4, 83, 0, 9],),
[[0, 0, 'UNKNOWN', 4, None], [2, 2, 'RETURN_VALUE', 0, None]])],
[('regression: prefixed absolute jump',
([100, 5, 144, 1, 113, 4, 83, 0],),
[[0, 0, 'LOAD_CONST', 5, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
('two prefixes accumulate', ([144, 1, 144, 7, 100, 3],), [[0, 4, 'LOAD_CONST', 67331, None]]),
('prefix does not leak into the next instruction',
([144, 1, 100, 0, 100, 10],),
[[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 10, None]]),
('prefixed forward jump is relative to the next instruction',
([9, 0, 144, 1, 110, 5, 83, 0],),
[[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 261, 528], [6, 6, 'RETURN_VALUE', 0, None]]),
('absolute jump target in bytes',
([113, 5, 83, 0],),
[[0, 0, 'JUMP_ABSOLUTE', 5, 10], [2, 2, 'RETURN_VALUE', 0, None]]),
('trailing prefix with zero argument',
([100, 5, 144, 0],),
[[0, 0, 'LOAD_CONST', 5, None], ['dangling-extended-arg', 2]]),
('control: unknown opcode and odd trailing byte',
([7, 5, 83, 0, 9],),
[[0, 0, 'UNKNOWN', 5, None], [2, 2, 'RETURN_VALUE', 0, None]])]]
for label, args, expected in cases[N - 1]:
check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| regression: prefixed absolute jump | [[0, 0, 'LOAD_CONST', 1, None], [2, 4, 'JUMP_ABSOLUTE', 260, 522], [6, 6, 'RETURN_VALUE', 0, None]] | [[0, 0, 'LOAD_CONST', 1, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]] | Failed |
| two prefixes accumulate | [[0, 4, 'LOAD_CONST', 66307, None]] | [[0, 4, 'LOAD_CONST', 66307, None]] | Passed |
| prefix does not leak into the next instruction | [[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 6, None]] | [[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 6, None]] | Passed |
| prefixed forward jump is relative to the next instruction | [[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 257, 520], [6, 6, 'RETURN_VALUE', 0, None]] | [[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 257, 520], [6, 6, 'RETURN_VALUE', 0, None]] | Passed |
| absolute jump target in bytes | [[0, 0, 'JUMP_ABSOLUTE', 1, 4], [2, 2, 'RETURN_VALUE', 0, None]] | [[0, 0, 'JUMP_ABSOLUTE', 1, 2], [2, 2, 'RETURN_VALUE', 0, None]] | Failed |
| trailing prefix with zero argument | [[0, 0, 'LOAD_CONST', 1, None], ['dangling-extended-arg', 2]] | [[0, 0, 'LOAD_CONST', 1, None], ['dangling-extended-arg', 2]] | Passed |
| control: unknown opcode and odd trailing byte | [[0, 0, 'UNKNOWN', 1, None], [2, 2, 'RETURN_VALUE', 0, None]] | [[0, 0, 'UNKNOWN', 1, None], [2, 2, 'RETURN_VALUE', 0, None]] | Passed |
SHA-256 / 72290b7920a49baec04c57d96f7685c039afad03f03e818ef619f3c1769f59d5
HELD IN THE MEMBER ARCHIVE
The verified repair and its recorded checks are member-only.
This mechanism has 7 recorded checks per implementation. The open-access tier publishes the failure and the unsuccessful fix; the repaired source that passes every check, and the observations that prove it, are available to members.
Every case sharing this mechanism uses the same contract and the same repair, so this one record is held back for all of them.
Member access is invitation-based. Sign in with your invited account to inspect the repair.
Sign in to the archive ↗Verification & scope
A deterministic, bounded teaching model of one bytecode virtual machine mechanism with a stipulated instruction encoding; it is not a production VM and claims no conformance to any real specification. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:51:25.327950+00:00.
Case digest / 9baaabb8da6946a24690b6f4f600b42eb14cbd81fe2698527dafc3222c9d665c