FAILURE MAP
← Case archive

FA-90301 / Bytecode virtual machines / Open access

Wordcode prefixes: instruction start moves past its prefixes · case 01

Jump tables and line maps point into the middle of prefixed instructions.

Verified by executionVariant 1 · 7 checks per implementationDownload source bundle ↓JSON ↗

ROOT CAUSE

The start offset is overwritten for every code unit, so it ends up at the real opcode.

VERIFIED REPAIR

Record the start at the first prefix and keep it until the instruction completes.

Unsuccessful approach: Resetting the start on the real opcode has the same effect for every prefixed instruction.

Case contract

Two-byte wordcode (opcode, arg). EXTENDED_ARG (144) prefixes build wider arguments: each prefix ORs its byte into an accumulator that is then shifted left 8; the real instruction ORs its own byte in and resets the accumulator. Each decoded instruction reports [start of its first prefix, own offset, name, full arg, jump target in bytes]: JUMP_FORWARD (110) targets the next instruction plus 2*arg, JUMP_ABSOLUTE (113) targets 2*arg. A prefix at the end reports ["dangling-extended-arg", start]. A trailing odd byte is ignored.

Why this case matters

Instruction prefixes change argument width and jump targets in wordcode interpreters.

1 / The failure

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(code):
    names = {100: 'LOAD_CONST', 110: 'JUMP_FORWARD', 113: 'JUMP_ABSOLUTE', 83: 'RETURN_VALUE', 9: 'NOP'}
    out = []
    ext = 0
    start = None
    for off in range(0, len(code) - 1, 2):
        op, arg = code[off], code[off + 1]
        start = off
        if op == 144:
            ext = (ext | arg) << 8
            continue
        full = ext | arg
        ext = 0
        target = None
        if op == 110:
            target = off + 2 + full * 2
        elif op == 113:
            target = full * 2
        out.append([start, off, names.get(op, 'UNKNOWN'), full, target])
        start = None
    if start is not None:
        out.append(['dangling-extended-arg', start])
    return out
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
cases = [[('regression: prefixed absolute jump',
   ([100, 1, 144, 1, 113, 4, 83, 0],),
   [[0, 0, 'LOAD_CONST', 1, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('two prefixes accumulate', ([144, 1, 144, 3, 100, 3],), [[0, 4, 'LOAD_CONST', 66307, None]]),
  ('prefix does not leak into the next instruction',
   ([144, 1, 100, 0, 100, 6],),
   [[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 6, None]]),
  ('prefixed forward jump is relative to the next instruction',
   ([9, 0, 144, 1, 110, 1, 83, 0],),
   [[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 257, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('absolute jump target in bytes',
   ([113, 1, 83, 0],),
   [[0, 0, 'JUMP_ABSOLUTE', 1, 2], [2, 2, 'RETURN_VALUE', 0, None]]),
  ('trailing prefix with zero argument',
   ([100, 1, 144, 0],),
   [[0, 0, 'LOAD_CONST', 1, None], ['dangling-extended-arg', 2]]),
  ('control: unknown opcode and odd trailing byte',
   ([7, 1, 83, 0, 9],),
   [[0, 0, 'UNKNOWN', 1, None], [2, 2, 'RETURN_VALUE', 0, None]])],
 [('regression: prefixed absolute jump',
   ([100, 2, 144, 1, 113, 4, 83, 0],),
   [[0, 0, 'LOAD_CONST', 2, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('two prefixes accumulate', ([144, 1, 144, 4, 100, 3],), [[0, 4, 'LOAD_CONST', 66563, None]]),
  ('prefix does not leak into the next instruction',
   ([144, 1, 100, 0, 100, 7],),
   [[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 7, None]]),
  ('prefixed forward jump is relative to the next instruction',
   ([9, 0, 144, 1, 110, 2, 83, 0],),
   [[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 258, 522], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('absolute jump target in bytes',
   ([113, 2, 83, 0],),
   [[0, 0, 'JUMP_ABSOLUTE', 2, 4], [2, 2, 'RETURN_VALUE', 0, None]]),
  ('trailing prefix with zero argument',
   ([100, 2, 144, 0],),
   [[0, 0, 'LOAD_CONST', 2, None], ['dangling-extended-arg', 2]]),
  ('control: unknown opcode and odd trailing byte',
   ([7, 2, 83, 0, 9],),
   [[0, 0, 'UNKNOWN', 2, None], [2, 2, 'RETURN_VALUE', 0, None]])],
 [('regression: prefixed absolute jump',
   ([100, 3, 144, 1, 113, 4, 83, 0],),
   [[0, 0, 'LOAD_CONST', 3, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('two prefixes accumulate', ([144, 1, 144, 5, 100, 3],), [[0, 4, 'LOAD_CONST', 66819, None]]),
  ('prefix does not leak into the next instruction',
   ([144, 1, 100, 0, 100, 8],),
   [[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 8, None]]),
  ('prefixed forward jump is relative to the next instruction',
   ([9, 0, 144, 1, 110, 3, 83, 0],),
   [[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 259, 524], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('absolute jump target in bytes',
   ([113, 3, 83, 0],),
   [[0, 0, 'JUMP_ABSOLUTE', 3, 6], [2, 2, 'RETURN_VALUE', 0, None]]),
  ('trailing prefix with zero argument',
   ([100, 3, 144, 0],),
   [[0, 0, 'LOAD_CONST', 3, None], ['dangling-extended-arg', 2]]),
  ('control: unknown opcode and odd trailing byte',
   ([7, 3, 83, 0, 9],),
   [[0, 0, 'UNKNOWN', 3, None], [2, 2, 'RETURN_VALUE', 0, None]])],
 [('regression: prefixed absolute jump',
   ([100, 4, 144, 1, 113, 4, 83, 0],),
   [[0, 0, 'LOAD_CONST', 4, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('two prefixes accumulate', ([144, 1, 144, 6, 100, 3],), [[0, 4, 'LOAD_CONST', 67075, None]]),
  ('prefix does not leak into the next instruction',
   ([144, 1, 100, 0, 100, 9],),
   [[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 9, None]]),
  ('prefixed forward jump is relative to the next instruction',
   ([9, 0, 144, 1, 110, 4, 83, 0],),
   [[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 260, 526], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('absolute jump target in bytes',
   ([113, 4, 83, 0],),
   [[0, 0, 'JUMP_ABSOLUTE', 4, 8], [2, 2, 'RETURN_VALUE', 0, None]]),
  ('trailing prefix with zero argument',
   ([100, 4, 144, 0],),
   [[0, 0, 'LOAD_CONST', 4, None], ['dangling-extended-arg', 2]]),
  ('control: unknown opcode and odd trailing byte',
   ([7, 4, 83, 0, 9],),
   [[0, 0, 'UNKNOWN', 4, None], [2, 2, 'RETURN_VALUE', 0, None]])],
 [('regression: prefixed absolute jump',
   ([100, 5, 144, 1, 113, 4, 83, 0],),
   [[0, 0, 'LOAD_CONST', 5, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('two prefixes accumulate', ([144, 1, 144, 7, 100, 3],), [[0, 4, 'LOAD_CONST', 67331, None]]),
  ('prefix does not leak into the next instruction',
   ([144, 1, 100, 0, 100, 10],),
   [[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 10, None]]),
  ('prefixed forward jump is relative to the next instruction',
   ([9, 0, 144, 1, 110, 5, 83, 0],),
   [[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 261, 528], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('absolute jump target in bytes',
   ([113, 5, 83, 0],),
   [[0, 0, 'JUMP_ABSOLUTE', 5, 10], [2, 2, 'RETURN_VALUE', 0, None]]),
  ('trailing prefix with zero argument',
   ([100, 5, 144, 0],),
   [[0, 0, 'LOAD_CONST', 5, None], ['dangling-extended-arg', 2]]),
  ('control: unknown opcode and odd trailing byte',
   ([7, 5, 83, 0, 9],),
   [[0, 0, 'UNKNOWN', 5, None], [2, 2, 'RETURN_VALUE', 0, None]])]]
for label, args, expected in cases[N - 1]:
    check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
regression: prefixed absolute jump[[0, 0, 'LOAD_CONST', 1, None], [4, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]][[0, 0, 'LOAD_CONST', 1, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]Failed
two prefixes accumulate[[4, 4, 'LOAD_CONST', 66307, None]][[0, 4, 'LOAD_CONST', 66307, None]]Failed
prefix does not leak into the next instruction[[2, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 6, None]][[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 6, None]]Failed
prefixed forward jump is relative to the next instruction[[0, 0, 'NOP', 0, None], [4, 4, 'JUMP_FORWARD', 257, 520], [6, 6, 'RETURN_VALUE', 0, None]][[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 257, 520], [6, 6, 'RETURN_VALUE', 0, None]]Failed
absolute jump target in bytes[[0, 0, 'JUMP_ABSOLUTE', 1, 2], [2, 2, 'RETURN_VALUE', 0, None]][[0, 0, 'JUMP_ABSOLUTE', 1, 2], [2, 2, 'RETURN_VALUE', 0, None]]Passed
trailing prefix with zero argument[[0, 0, 'LOAD_CONST', 1, None], ['dangling-extended-arg', 2]][[0, 0, 'LOAD_CONST', 1, None], ['dangling-extended-arg', 2]]Passed
control: unknown opcode and odd trailing byte[[0, 0, 'UNKNOWN', 1, None], [2, 2, 'RETURN_VALUE', 0, None]][[0, 0, 'UNKNOWN', 1, None], [2, 2, 'RETURN_VALUE', 0, None]]Passed

SHA-256 / e20a09bd377a90e4cad1c919650dcd709da9fbd5d179ea2a9af0b18ee0bdd66c

2 / The unsuccessful fix

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(code):
    names = {100: 'LOAD_CONST', 110: 'JUMP_FORWARD', 113: 'JUMP_ABSOLUTE', 83: 'RETURN_VALUE', 9: 'NOP'}
    out = []
    ext = 0
    start = None
    for off in range(0, len(code) - 1, 2):
        op, arg = code[off], code[off + 1]
        if start is None or op != 144:
            start = off
        if op == 144:
            ext = (ext | arg) << 8
            continue
        full = ext | arg
        ext = 0
        target = None
        if op == 110:
            target = off + 2 + full * 2
        elif op == 113:
            target = full * 2
        out.append([start, off, names.get(op, 'UNKNOWN'), full, target])
        start = None
    if start is not None:
        out.append(['dangling-extended-arg', start])
    return out
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
cases = [[('regression: prefixed absolute jump',
   ([100, 1, 144, 1, 113, 4, 83, 0],),
   [[0, 0, 'LOAD_CONST', 1, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('two prefixes accumulate', ([144, 1, 144, 3, 100, 3],), [[0, 4, 'LOAD_CONST', 66307, None]]),
  ('prefix does not leak into the next instruction',
   ([144, 1, 100, 0, 100, 6],),
   [[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 6, None]]),
  ('prefixed forward jump is relative to the next instruction',
   ([9, 0, 144, 1, 110, 1, 83, 0],),
   [[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 257, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('absolute jump target in bytes',
   ([113, 1, 83, 0],),
   [[0, 0, 'JUMP_ABSOLUTE', 1, 2], [2, 2, 'RETURN_VALUE', 0, None]]),
  ('trailing prefix with zero argument',
   ([100, 1, 144, 0],),
   [[0, 0, 'LOAD_CONST', 1, None], ['dangling-extended-arg', 2]]),
  ('control: unknown opcode and odd trailing byte',
   ([7, 1, 83, 0, 9],),
   [[0, 0, 'UNKNOWN', 1, None], [2, 2, 'RETURN_VALUE', 0, None]])],
 [('regression: prefixed absolute jump',
   ([100, 2, 144, 1, 113, 4, 83, 0],),
   [[0, 0, 'LOAD_CONST', 2, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('two prefixes accumulate', ([144, 1, 144, 4, 100, 3],), [[0, 4, 'LOAD_CONST', 66563, None]]),
  ('prefix does not leak into the next instruction',
   ([144, 1, 100, 0, 100, 7],),
   [[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 7, None]]),
  ('prefixed forward jump is relative to the next instruction',
   ([9, 0, 144, 1, 110, 2, 83, 0],),
   [[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 258, 522], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('absolute jump target in bytes',
   ([113, 2, 83, 0],),
   [[0, 0, 'JUMP_ABSOLUTE', 2, 4], [2, 2, 'RETURN_VALUE', 0, None]]),
  ('trailing prefix with zero argument',
   ([100, 2, 144, 0],),
   [[0, 0, 'LOAD_CONST', 2, None], ['dangling-extended-arg', 2]]),
  ('control: unknown opcode and odd trailing byte',
   ([7, 2, 83, 0, 9],),
   [[0, 0, 'UNKNOWN', 2, None], [2, 2, 'RETURN_VALUE', 0, None]])],
 [('regression: prefixed absolute jump',
   ([100, 3, 144, 1, 113, 4, 83, 0],),
   [[0, 0, 'LOAD_CONST', 3, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('two prefixes accumulate', ([144, 1, 144, 5, 100, 3],), [[0, 4, 'LOAD_CONST', 66819, None]]),
  ('prefix does not leak into the next instruction',
   ([144, 1, 100, 0, 100, 8],),
   [[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 8, None]]),
  ('prefixed forward jump is relative to the next instruction',
   ([9, 0, 144, 1, 110, 3, 83, 0],),
   [[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 259, 524], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('absolute jump target in bytes',
   ([113, 3, 83, 0],),
   [[0, 0, 'JUMP_ABSOLUTE', 3, 6], [2, 2, 'RETURN_VALUE', 0, None]]),
  ('trailing prefix with zero argument',
   ([100, 3, 144, 0],),
   [[0, 0, 'LOAD_CONST', 3, None], ['dangling-extended-arg', 2]]),
  ('control: unknown opcode and odd trailing byte',
   ([7, 3, 83, 0, 9],),
   [[0, 0, 'UNKNOWN', 3, None], [2, 2, 'RETURN_VALUE', 0, None]])],
 [('regression: prefixed absolute jump',
   ([100, 4, 144, 1, 113, 4, 83, 0],),
   [[0, 0, 'LOAD_CONST', 4, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('two prefixes accumulate', ([144, 1, 144, 6, 100, 3],), [[0, 4, 'LOAD_CONST', 67075, None]]),
  ('prefix does not leak into the next instruction',
   ([144, 1, 100, 0, 100, 9],),
   [[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 9, None]]),
  ('prefixed forward jump is relative to the next instruction',
   ([9, 0, 144, 1, 110, 4, 83, 0],),
   [[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 260, 526], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('absolute jump target in bytes',
   ([113, 4, 83, 0],),
   [[0, 0, 'JUMP_ABSOLUTE', 4, 8], [2, 2, 'RETURN_VALUE', 0, None]]),
  ('trailing prefix with zero argument',
   ([100, 4, 144, 0],),
   [[0, 0, 'LOAD_CONST', 4, None], ['dangling-extended-arg', 2]]),
  ('control: unknown opcode and odd trailing byte',
   ([7, 4, 83, 0, 9],),
   [[0, 0, 'UNKNOWN', 4, None], [2, 2, 'RETURN_VALUE', 0, None]])],
 [('regression: prefixed absolute jump',
   ([100, 5, 144, 1, 113, 4, 83, 0],),
   [[0, 0, 'LOAD_CONST', 5, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('two prefixes accumulate', ([144, 1, 144, 7, 100, 3],), [[0, 4, 'LOAD_CONST', 67331, None]]),
  ('prefix does not leak into the next instruction',
   ([144, 1, 100, 0, 100, 10],),
   [[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 10, None]]),
  ('prefixed forward jump is relative to the next instruction',
   ([9, 0, 144, 1, 110, 5, 83, 0],),
   [[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 261, 528], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('absolute jump target in bytes',
   ([113, 5, 83, 0],),
   [[0, 0, 'JUMP_ABSOLUTE', 5, 10], [2, 2, 'RETURN_VALUE', 0, None]]),
  ('trailing prefix with zero argument',
   ([100, 5, 144, 0],),
   [[0, 0, 'LOAD_CONST', 5, None], ['dangling-extended-arg', 2]]),
  ('control: unknown opcode and odd trailing byte',
   ([7, 5, 83, 0, 9],),
   [[0, 0, 'UNKNOWN', 5, None], [2, 2, 'RETURN_VALUE', 0, None]])]]
for label, args, expected in cases[N - 1]:
    check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
regression: prefixed absolute jump[[0, 0, 'LOAD_CONST', 1, None], [4, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]][[0, 0, 'LOAD_CONST', 1, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]Failed
two prefixes accumulate[[4, 4, 'LOAD_CONST', 66307, None]][[0, 4, 'LOAD_CONST', 66307, None]]Failed
prefix does not leak into the next instruction[[2, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 6, None]][[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 6, None]]Failed
prefixed forward jump is relative to the next instruction[[0, 0, 'NOP', 0, None], [4, 4, 'JUMP_FORWARD', 257, 520], [6, 6, 'RETURN_VALUE', 0, None]][[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 257, 520], [6, 6, 'RETURN_VALUE', 0, None]]Failed
absolute jump target in bytes[[0, 0, 'JUMP_ABSOLUTE', 1, 2], [2, 2, 'RETURN_VALUE', 0, None]][[0, 0, 'JUMP_ABSOLUTE', 1, 2], [2, 2, 'RETURN_VALUE', 0, None]]Passed
trailing prefix with zero argument[[0, 0, 'LOAD_CONST', 1, None], ['dangling-extended-arg', 2]][[0, 0, 'LOAD_CONST', 1, None], ['dangling-extended-arg', 2]]Passed
control: unknown opcode and odd trailing byte[[0, 0, 'UNKNOWN', 1, None], [2, 2, 'RETURN_VALUE', 0, None]][[0, 0, 'UNKNOWN', 1, None], [2, 2, 'RETURN_VALUE', 0, None]]Passed

SHA-256 / d0a5173d5efcddff78166d63aa87d088bde2b08b341da3aa9fa9f26e7b875b8b

3 / The verified repair

Exit 0
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(code):
    names = {100: 'LOAD_CONST', 110: 'JUMP_FORWARD', 113: 'JUMP_ABSOLUTE', 83: 'RETURN_VALUE', 9: 'NOP'}
    out = []
    ext = 0
    start = None
    for off in range(0, len(code) - 1, 2):
        op, arg = code[off], code[off + 1]
        if start is None:
            start = off
        if op == 144:
            ext = (ext | arg) << 8
            continue
        full = ext | arg
        ext = 0
        target = None
        if op == 110:
            target = off + 2 + full * 2
        elif op == 113:
            target = full * 2
        out.append([start, off, names.get(op, 'UNKNOWN'), full, target])
        start = None
    if start is not None:
        out.append(['dangling-extended-arg', start])
    return out
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
cases = [[('regression: prefixed absolute jump',
   ([100, 1, 144, 1, 113, 4, 83, 0],),
   [[0, 0, 'LOAD_CONST', 1, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('two prefixes accumulate', ([144, 1, 144, 3, 100, 3],), [[0, 4, 'LOAD_CONST', 66307, None]]),
  ('prefix does not leak into the next instruction',
   ([144, 1, 100, 0, 100, 6],),
   [[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 6, None]]),
  ('prefixed forward jump is relative to the next instruction',
   ([9, 0, 144, 1, 110, 1, 83, 0],),
   [[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 257, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('absolute jump target in bytes',
   ([113, 1, 83, 0],),
   [[0, 0, 'JUMP_ABSOLUTE', 1, 2], [2, 2, 'RETURN_VALUE', 0, None]]),
  ('trailing prefix with zero argument',
   ([100, 1, 144, 0],),
   [[0, 0, 'LOAD_CONST', 1, None], ['dangling-extended-arg', 2]]),
  ('control: unknown opcode and odd trailing byte',
   ([7, 1, 83, 0, 9],),
   [[0, 0, 'UNKNOWN', 1, None], [2, 2, 'RETURN_VALUE', 0, None]])],
 [('regression: prefixed absolute jump',
   ([100, 2, 144, 1, 113, 4, 83, 0],),
   [[0, 0, 'LOAD_CONST', 2, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('two prefixes accumulate', ([144, 1, 144, 4, 100, 3],), [[0, 4, 'LOAD_CONST', 66563, None]]),
  ('prefix does not leak into the next instruction',
   ([144, 1, 100, 0, 100, 7],),
   [[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 7, None]]),
  ('prefixed forward jump is relative to the next instruction',
   ([9, 0, 144, 1, 110, 2, 83, 0],),
   [[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 258, 522], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('absolute jump target in bytes',
   ([113, 2, 83, 0],),
   [[0, 0, 'JUMP_ABSOLUTE', 2, 4], [2, 2, 'RETURN_VALUE', 0, None]]),
  ('trailing prefix with zero argument',
   ([100, 2, 144, 0],),
   [[0, 0, 'LOAD_CONST', 2, None], ['dangling-extended-arg', 2]]),
  ('control: unknown opcode and odd trailing byte',
   ([7, 2, 83, 0, 9],),
   [[0, 0, 'UNKNOWN', 2, None], [2, 2, 'RETURN_VALUE', 0, None]])],
 [('regression: prefixed absolute jump',
   ([100, 3, 144, 1, 113, 4, 83, 0],),
   [[0, 0, 'LOAD_CONST', 3, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('two prefixes accumulate', ([144, 1, 144, 5, 100, 3],), [[0, 4, 'LOAD_CONST', 66819, None]]),
  ('prefix does not leak into the next instruction',
   ([144, 1, 100, 0, 100, 8],),
   [[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 8, None]]),
  ('prefixed forward jump is relative to the next instruction',
   ([9, 0, 144, 1, 110, 3, 83, 0],),
   [[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 259, 524], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('absolute jump target in bytes',
   ([113, 3, 83, 0],),
   [[0, 0, 'JUMP_ABSOLUTE', 3, 6], [2, 2, 'RETURN_VALUE', 0, None]]),
  ('trailing prefix with zero argument',
   ([100, 3, 144, 0],),
   [[0, 0, 'LOAD_CONST', 3, None], ['dangling-extended-arg', 2]]),
  ('control: unknown opcode and odd trailing byte',
   ([7, 3, 83, 0, 9],),
   [[0, 0, 'UNKNOWN', 3, None], [2, 2, 'RETURN_VALUE', 0, None]])],
 [('regression: prefixed absolute jump',
   ([100, 4, 144, 1, 113, 4, 83, 0],),
   [[0, 0, 'LOAD_CONST', 4, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('two prefixes accumulate', ([144, 1, 144, 6, 100, 3],), [[0, 4, 'LOAD_CONST', 67075, None]]),
  ('prefix does not leak into the next instruction',
   ([144, 1, 100, 0, 100, 9],),
   [[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 9, None]]),
  ('prefixed forward jump is relative to the next instruction',
   ([9, 0, 144, 1, 110, 4, 83, 0],),
   [[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 260, 526], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('absolute jump target in bytes',
   ([113, 4, 83, 0],),
   [[0, 0, 'JUMP_ABSOLUTE', 4, 8], [2, 2, 'RETURN_VALUE', 0, None]]),
  ('trailing prefix with zero argument',
   ([100, 4, 144, 0],),
   [[0, 0, 'LOAD_CONST', 4, None], ['dangling-extended-arg', 2]]),
  ('control: unknown opcode and odd trailing byte',
   ([7, 4, 83, 0, 9],),
   [[0, 0, 'UNKNOWN', 4, None], [2, 2, 'RETURN_VALUE', 0, None]])],
 [('regression: prefixed absolute jump',
   ([100, 5, 144, 1, 113, 4, 83, 0],),
   [[0, 0, 'LOAD_CONST', 5, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('two prefixes accumulate', ([144, 1, 144, 7, 100, 3],), [[0, 4, 'LOAD_CONST', 67331, None]]),
  ('prefix does not leak into the next instruction',
   ([144, 1, 100, 0, 100, 10],),
   [[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 10, None]]),
  ('prefixed forward jump is relative to the next instruction',
   ([9, 0, 144, 1, 110, 5, 83, 0],),
   [[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 261, 528], [6, 6, 'RETURN_VALUE', 0, None]]),
  ('absolute jump target in bytes',
   ([113, 5, 83, 0],),
   [[0, 0, 'JUMP_ABSOLUTE', 5, 10], [2, 2, 'RETURN_VALUE', 0, None]]),
  ('trailing prefix with zero argument',
   ([100, 5, 144, 0],),
   [[0, 0, 'LOAD_CONST', 5, None], ['dangling-extended-arg', 2]]),
  ('control: unknown opcode and odd trailing byte',
   ([7, 5, 83, 0, 9],),
   [[0, 0, 'UNKNOWN', 5, None], [2, 2, 'RETURN_VALUE', 0, None]])]]
for label, args, expected in cases[N - 1]:
    check(label, solve(*args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
regression: prefixed absolute jump[[0, 0, 'LOAD_CONST', 1, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]][[0, 0, 'LOAD_CONST', 1, None], [2, 4, 'JUMP_ABSOLUTE', 260, 520], [6, 6, 'RETURN_VALUE', 0, None]]Passed
two prefixes accumulate[[0, 4, 'LOAD_CONST', 66307, None]][[0, 4, 'LOAD_CONST', 66307, None]]Passed
prefix does not leak into the next instruction[[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 6, None]][[0, 2, 'LOAD_CONST', 256, None], [4, 4, 'LOAD_CONST', 6, None]]Passed
prefixed forward jump is relative to the next instruction[[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 257, 520], [6, 6, 'RETURN_VALUE', 0, None]][[0, 0, 'NOP', 0, None], [2, 4, 'JUMP_FORWARD', 257, 520], [6, 6, 'RETURN_VALUE', 0, None]]Passed
absolute jump target in bytes[[0, 0, 'JUMP_ABSOLUTE', 1, 2], [2, 2, 'RETURN_VALUE', 0, None]][[0, 0, 'JUMP_ABSOLUTE', 1, 2], [2, 2, 'RETURN_VALUE', 0, None]]Passed
trailing prefix with zero argument[[0, 0, 'LOAD_CONST', 1, None], ['dangling-extended-arg', 2]][[0, 0, 'LOAD_CONST', 1, None], ['dangling-extended-arg', 2]]Passed
control: unknown opcode and odd trailing byte[[0, 0, 'UNKNOWN', 1, None], [2, 2, 'RETURN_VALUE', 0, None]][[0, 0, 'UNKNOWN', 1, None], [2, 2, 'RETURN_VALUE', 0, None]]Passed

SHA-256 / 726ae4a7a646ac218f5ff9541282d50975e4ce08bafd0b6788f45cd018ca7edd

Verification & scope

A deterministic, bounded teaching model of one bytecode virtual machine mechanism with a stipulated instruction encoding; it is not a production VM and claims no conformance to any real specification. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.

Observations recorded using Python 3.12.14 at 2026-09-29T14:51:25.329626+00:00.

Case digest / 68116004f8ccce3a187a8d6424f220d6000c2d4e80e0f70de4dcdf47d03a9222