What the corpus found
Nine defects, and one shape: a constant that looks right, builds a graph of exactly the right width, and means the opposite of what it says.
This is the page worth reading twice. The corpus exists to find bugs in the tools, and it has found nine. They are listed here in full because the pattern is the actual finding: almost none of them are arithmetic mistakes, and almost all of them are things that compile, build a graph of the right shape, and produce a plausible answer.
The first four came from crc3 — a three-bit LFSR, one byte per cycle, the smallest design in the corpus with a register and a bit stream. They were found by 471 tests of the tools not having found them.
Step by step
- 01
sll and srl were swapped, for the entire life of the project
The two shift directions were exactly backwards from A1 through A2. Every crate agreed with every other crate about it, because they were all wrong the same way and each was the other's golden model. Only a design with an external reference — an algorithm that has a published answer — could break the tie.
// What the corpus found, and what 471 tests of the tools did not. design.sll(&value, 1)?; // had been shifting right design.srl(&value, 1)?; // had been shifting left
- 02
The FNV-1a offset basis was one digit wrong
0xcbf2_9ce4_8423_2325where the published constant is0xcbf2_9ce4_8422_2325. The multiplier was correct. The failure was caught only by the published check vectors, because the test's own first assertion used the same wrong constant and therefore agreed with itself.// A constant copied into both the code and its own test is not checked twice. assert_eq!(fnv1a(b"", 0), 0xcbf2_9ce4_8423_2325); // passes: same wrong constant assert_eq!(fnv1a(b"a", 0), 0xaf63_dc4c_8601_ec8c); // fails: the published vector
- 03
The IP rebase sliced from the wrong end
bytetreats index zero as the most significant byte, so dropping the Ethernet header has to keep the window's low bits. The code sliced fromoffset * 8, which reads as though index zero were the least significant. Every IP field read as the byte eight earlier, the checksum never verified, andvalidwas stuck low.// Reads plausibly, means the opposite: // let window = &frame[header..]; // wrong end let window = &frame[frame.len() - 64..]; // what "byte" means
- 04
FSE gave its rarest symbol the most expensive transition
A normalised count of
-1means "rarer than one symbol in the whole table". The state arithmetic that is correct for every positive count gave itnbBits = tableLog— a transition spanning the entire table, on a symbol that occurs once intableSizeof them. It getsnbBits = 0andnewState = 0.// The one case the general arithmetic does not describe. let (nb_bits, new_state) = if low_probability[symbol] { (0, 0) } else { let nb_bits = table_log - highbit32(number); (nb_bits, (number << nb_bits) - table_size) }; - 05
The FSE initial state was assembled backwards
The state register shifted left and inserted at the bottom, so the bit that arrives first — the state's *low* bit — ended up as its most significant. A reversed state is a state that exists, decodes plausibly, and is wrong from the first symbol on. The design now shifts right and inserts at the top.
- 06
The bits that build the state were left in the decode buffer
So the first transition read the initial state back as its own
lowbits. The first symbol was right and every symbol after it was wrong, which is exactly the shape that survives a spot check. - 07
A test that passed for the wrong reason
read_stored_blockcompared DEFLATE's sixteen-bit complement as a sixty-four-bit one, solen != !nlenwas true for every stored block ever written, including correct ones. And the test asserting that a *broken* complement is refused was passing because of the bug rather than despite it.// Wrong: a 64-bit complement no 16-bit length can equal. if len as u64 != !nlen as u64 { return None; } // Right: the complement is over the sixteen-bit field. if len as u32 != (!nlen as u32 & 0xffff) { return None; } - 08
A harness that stopped one cycle early
The DEFLATE bit-stream driver exited on the cycle the last byte was *loaded*, so that byte's eight bits never shifted out. Every round trip came up six to eight bits short and looked like a bit-order defect — the most expensive kind of wrong, because it sends you looking in the format instead of the harness.
- 09
A claim that measurement contradicted
The
huffmanmodule documented "one symbol per cycle, which is the point". Measured: a decode spendscode_lenbits and the host supplies one bit per cycle, so the rate is one symbol per code length — seven, for DEFLATE's shortest fixed code. It is one per cycle only for the one-bit single-symbol code.fse*can* do it, because an FSE transition may cost zero bits, and that difference is the whole distinction between the two decoders.7cycles per symbolthe real rate for DEFLATE's shortest fixed code — the docs said one
What bites
The recurring shape
A constant that looks right, builds a graph of exactly the right width, and means the opposite of what it says.
sll/srl, the FNV basis, the IP rebase, the FSE bit order, the 64-bit complement — five of the nine are this, and not one of them would be caught by a test that asserted the shape instead of the value.Self-consistency proves nothing
Every round trip in this project that passes without an external reference proves only that the design agrees with the thing it was compared against. Four of the failures above were found by exactly the checks that were *not* self-consistent: a published vector, the RFC's own code assignment, a hand-derived table.
Notes
- measured
811 tests, and the corpus still found the bugs
The tool crates' own tests are not bad; they were aimed at the wrong things. The change that found the last nine defects was not more tests. It was writing a design that has an answer somewhere outside this repository.
- decision
Write the finding down
Every one of these is in
DETAILS.mdin the repository, with the mechanism rather than just the diff. A bug fixed without the shape recorded is a bug that gets reintroduced by the next person who makes the same reasonable assumption.