|
|
INSTRUCTION FORMAT
Table 2-14. Exception Class Description
Floating-Point
Exception Class
Instruction set
Mem arg
Exceptions (#XM)
AVX,
16/32 byte explicitly
Type 1
None
Legacy SSE
aligned
AVX,
16/32 byte not explicitly
Type 2
Yes
Legacy SSE
aligned
AVX,
Type 3
< 16 byte
Yes
Legacy SSE
AVX,
16/32 byte not explicitly
Type 4
No
Legacy SSE
aligned
AVX,
Type 5
< 16 byte
No
Legacy SSE
Type 6
AVX (no Legacy SSE)
Varies
(At present, none do)
AVX,
Type 7
None
None
Legacy SSE
Type 8
AVX
None
None
F16C
8 or 16 byte, Not explicitly
Yes
Type 11
aligned, no AC#
AVX2 Gathers
Not explicitly aligned, no
No
Type 12
AC#
See Table 2-15 for lists of instructions in each exception class.
Vol. 2A
2-23
INSTRUCTION FORMAT
Table 2-15. Instructions in each Exception Class
Exception Class
Instruction
Type 1
(V)MOVAPD, (V)MOVAPS, (V)MOVDQA, (V)MOVNTDQ, (V)MOVNTDQA, (V)MOVNTPD, (V)MOVNTPS
(V)ADDPD, (V)ADDPS, (V)ADDSUBPD, (V)ADDSUBPS, (V)CMPPD, (V)CMPPS, (V)CVTDQ2PS, (V)CVTPD2DQ,
(V)CVTPD2PS, (V)CVTPS2DQ, (V)CVTTPD2DQ, (V)CVTTPS2DQ, (V)DIVPD, (V)DIVPS, (V)DPPD*, (V)DPPS*,
VFMADD132PD, VFMADD213PD, VFMADD231PD, VFMADD132PS, VFMADD213PS, VFMADD231PS,
VFMADDSUB132PD, VFMADDSUB213PD, VFMADDSUB231PD, VFMADDSUB132PS, VFMADDSUB213PS,
VFMADDSUB231PS, VFMSUBADD132PD, VFMSUBADD213PD, VFMSUBADD231PD, VFMSUBADD132PS,
Type 2
VFMSUBADD213PS, VFMSUBADD231PS, VFMSUB132PD, VFMSUB213PD, VFMSUB231PD, VFMSUB132PS,
VFMSUB213PS, VFMSUB231PS, VFNMADD132PD, VFNMADD213PD, VFNMADD231PD, VFNMADD132PS,
VFNMADD213PS, VFNMADD231PS, VFNMSUB132PD, VFNMSUB213PD, VFNMSUB231PD, VFNMSUB132PS,
VFNMSUB213PS, VFNMSUB231PS, (V)HADDPD, (V)HADDPS, (V)HSUBPD, (V)HSUBPS, (V)MAXPD, (V)MAXPS,
(V)MINPD, (V)MINPS, (V)MULPD, (V)MULPS, (V)ROUNDPD, (V)ROUNDPS, (V)SQRTPD, (V)SQRTPS, (V)SUBPD,
(V)SUBPS
(V)ADDSD, (V)ADDSS, (V)CMPSD, (V)CMPSS, (V)COMISD, (V)COMISS, (V)CVTPS2PD, (V)CVTSD2SI, (V)CVTSD2SS,
(V)CVTSI2SD, (V)CVTSI2SS, (V)CVTSS2SD, (V)CVTSS2SI, (V)CVTTSD2SI, (V)CVTTSS2SI, (V)DIVSD, (V)DIVSS,
VFMADD132SD, VFMADD213SD, VFMADD231SD, VFMADD132SS, VFMADD213SS, VFMADD231SS,
VFMSUB132SD, VFMSUB213SD, VFMSUB231SD, VFMSUB132SS, VFMSUB213SS, VFMSUB231SS,
Type 3
VFNMADD132SD, VFNMADD213SD, VFNMADD231SD, VFNMADD132SS, VFNMADD213SS, VFNMADD231SS,
VFNMSUB132SD, VFNMSUB213SD, VFNMSUB231SD, VFNMSUB132SS, VFNMSUB213SS, VFNMSUB231SS,
(V)MAXSD, (V)MAXSS, (V)MINSD, (V)MINSS, (V)MULSD, (V)MULSS, (V)ROUNDSD, (V)ROUNDSS, (V)SQRTSD,
(V)SQRTSS, (V)SUBSD, (V)SUBSS, (V)UCOMISD, (V)UCOMISS
(V)AESDEC, (V)AESDECLAST, (V)AESENC, (V)AESENCLAST, (V)AESIMC, (V)AESKEYGENASSIST, (V)ANDPD,
(V)ANDPS, (V)ANDNPD, (V)ANDNPS, (V)BLENDPD, (V)BLENDPS, VBLENDVPD, VBLENDVPS, (V)LDDQU***,
(V)MASKMOVDQU, (V)PTEST, VTESTPS, VTESTPD, (V)MOVDQU*, (V)MOVSHDUP, (V)MOVSLDUP, (V)MOVUPD*,
(V)MOVUPS*, (V)MPSADBW, (V)ORPD, (V)ORPS, (V)PABSB, (V)PABSW, (V)PABSD, (V)PACKSSWB, (V)PACKSSDW,
(V)PACKUSWB, (V)PACKUSDW, (V)PADDB, (V)PADDW, (V)PADDD, (V)PADDQ, (V)PADDSB, (V)PADDSW,
(V)PADDUSB, (V)PADDUSW, (V)PALIGNR, (V)PAND, (V)PANDN, (V)PAVGB, (V)PAVGW, (V)PBLENDVB,
(V)PBLENDW, (V)PCMP(E/I)STRI/M***, (V)PCMPEQB, (V)PCMPEQW, (V)PCMPEQD, (V)PCMPEQQ, (V)PCMPGTB,
(V)PCMPGTW, (V)PCMPGTD, (V)PCMPGTQ, (V)PCLMULQDQ, (V)PHADDW, (V)PHADDD, (V)PHADDSW,
(V)PHMINPOSUW, (V)PHSUBD, (V)PHSUBW, (V)PHSUBSW, (V)PMADDWD, (V)PMADDUBSW, (V)PMAXSB,
Type 4
(V)PMAXSW, (V)PMAXSD, (V)PMAXUB, (V)PMAXUW, (V)PMAXUD, (V)PMINSB, (V)PMINSW, (V)PMINSD,
(V)PMINUB, (V)PMINUW, (V)PMINUD, (V)PMULHUW, (V)PMULHRSW, (V)PMULHW, (V)PMULLW, (V)PMULLD,
(V)PMULUDQ, (V)PMULDQ, (V)POR, (V)PSADBW, (V)PSHUFB, (V)PSHUFD, (V)PSHUFHW, (V)PSHUFLW, (V)PSIGNB,
(V)PSIGNW, (V)PSIGND, (V)PSLLW, (V)PSLLD, (V)PSLLQ, (V)PSRAW, (V)PSRAD, (V)PSRLW, (V)PSRLD, (V)PSRLQ,
(V)PSUBB, (V)PSUBW, (V)PSUBD, (V)PSUBQ, (V)PSUBSB, (V)PSUBSW, (V)PSUBUSB, (V)PSUBUSW,
(V)PUNPCKHBW, (V)PUNPCKHWD, (V)PUNPCKHDQ, (V)PUNPCKHQDQ, (V)PUNPCKLBW, (V)PUNPCKLWD,
(V)PUNPCKLDQ, (V)PUNPCKLQDQ, (V)PXOR, (V)RCPPS, (V)RSQRTPS, (V)SHUFPD, (V)SHUFPS, (V)UNPCKHPD,
(V)UNPCKHPS, (V)UNPCKLPD, (V)UNPCKLPS, (V)XORPD, (V)XORPS, VPBLENDD, VPERMD, VPERMPS, VPERMPD,
VPERMQ, VPSLLVD, VPSLLVQ, VPSRAVD, VPSRLVD, VPSRLVQ, VPERMILPD, VPERMILPS, VPERM2F128
(V)CVTDQ2PD, (V)EXTRACTPS, (V)INSERTPS, (V)MOVD, (V)MOVQ, (V)MOVDDUP, (V)MOVLPD, (V)MOVLPS,
(V)MOVHPD, (V)MOVHPS, (V)MOVSD, (V)MOVSS, (V)PEXTRB, (V)PEXTRD, (V)PEXTRW, (V)PEXTRQ, (V)PINSRB,
Type 5
(V)PINSRD, (V)PINSRW, (V)PINSRQ, PMOVSXBW, (V)RCPSS, (V)RSQRTSS, (V)PMOVSX/ZX, VLDMXCSR*,
VSTMXCSR
VEXTRACTF128/VEXTRACTFxxxx, VBROADCASTSS, VBROADCASTSD, VBROADCASTF128, VINSERTF128,
Type 6
VMASKMOVPS**, VMASKMOVPD**, VPMASKMOVD, VPMASKMOVQ, VBROADCASTI128, VPBROADCASTB,
VPBROADCASTD, VPBROADCASTW, VPBROADCASTQ, VEXTRACTI128, VINSERTI128, VPERM2I128
(V)MOVLHPS, (V)MOVHLPS, (V)MOVMSKPD, (V)MOVMSKPS, (V)PMOVMSKB, (V)PSLLDQ, (V)PSRLDQ, (V)PSLLW,
Type 7
(V)PSLLD, (V)PSLLQ, (V)PSRAW, (V)PSRAD, (V)PSRLW, (V)PSRLD, (V)PSRLQ
Type 8
VZEROALL, VZEROUPPER
Type 11
VCVTPH2PS, VCVTPS2PH
VGATHERDPS, VGATHERDPD, VGATHERQPS, VGATHERQPD, VPGATHERDD, VPGATHERDQ, VPGATHERQD,
Type 12
VPGATHERQQ
(*) - Additional exception restrictions are present - see the Instruction description for details
2-24
Vol. 2A
INSTRUCTION FORMAT
(**) - Instruction behavior on alignment check reporting with mask bits of less than all 1s are the same as with mask bits of all 1s, i.e., no
alignment checks are performed.
(***) - PCMPESTRI, PCMPESTRM, PCMPISTRI, PCMPISTRM, and LDDQU instructions do not cause #GP if the memory operand is not
aligned to 16-Byte boundary.
Table 2-15 classifies exception behaviors for AVX instructions. Within each class of exception conditions that are
listed in Table 2-18 through Table 2-27, certain subsets of AVX instructions may be subject to #UD exception
depending on the encoded value of the VEX.L field. Table 2-17 provides supplemental information of AVX instruc-
tions that may be subject to #UD exception if encoded with incorrect values in the VEX.W or VEX.L field.
Table 2-16. #UD Exception and VEX.W=1 Encoding
#UD If VEX.W = 1 in
Exception Class
#UD If VEX.W = 1 in all modes
non-64-bit modes
Type 1
Type 2
Type 3
VBLENDVPD, VBLENDVPS, VPBLENDVB, VTESTPD, VTESTPS, VPBLENDD, VPERMD,
Type 4
VPERMPS, VPERM2I128, VPSRAVD, VPERMILPD, VPERMILPS, VPERM2F128
Type 5
VEXTRACTF128, VBROADCASTSS, VBROADCASTSD, VBROADCASTF128,
Type 6
VINSERTF128, VMASKMOVPS, VMASKMOVPD, VBROADCASTI128,
VPBROADCASTB/W/D, VEXTRACTI128, VINSERTI128
Type 7
Type 8
Type 11
VCVTPH2PS, VCVTPS2PH
Type 12
Vol. 2A
2-25
INSTRUCTION FORMAT
Table 2-17. #UD Exception and VEX.L Field Encoding
Exception
#UD If (VEX.L = 1 && AVX2 not present && AVX
#UD If (VEX.L = 1 && AVX2
#UD If VEX.L = 0
Class
present)
present)
Type 1
VMOVNTDQA
VDPPD
VDPPD
Type 2
Type 3
VMASKMOVDQU, VMPSADBW, VPABSB/W/D,
VPCMP(E/I)STRI/M,
VPACKSSWB/DW, VPACKUSWB/DW, VPADDB/W/D,
PHMINPOSUW
VPADDQ, VPADDSB/W, VPADDUSB/W, VPALIGNR, VPAND,
VPANDN, VPAVGB/W, VPBLENDVB, VPBLENDW,
VPCMP(E/I)STRI/M, VPCMPEQB/W/D/Q, VPCMPGTB/W/D/Q,
VPHADDW/D, VPHADDSW, VPHMINPOSUW, VPHSUBD/W,
VPHSUBSW, VPMADDWD, VPMADDUBSW, VPMAXSB/W/D,
Type 4
VPMAXUB/W/D, VPMINSB/W/D, VPMINUB/W/D,
VPMULHUW, VPMULHRSW, VPMULHW/LW, VPMULLD,
VPMULUDQ, VPMULDQ, VPOR, VPSADBW, VPSHUFB/D,
VPSHUFHW/LW, VPSIGNB/W/D, VPSLLW/D/Q, VPSRAW/D,
VPSRLW/D/Q, VPSUBB/W/D/Q, VPSUBSB/W,
VPUNPCKHBW/WD/DQ, VPUNPCKHQDQ,
VPUNPCKLBW/WD/DQ, VPUNPCKLQDQ, VPXOR
VEXTRACTPS, VINSERTPS, VMOVD, VMOVQ, VMOVLPD,
Same as column 3
VMOVLPS, VMOVHPD, VMOVHPS, VPEXTRB, VPEXTRD,
Type 5
VPEXTRW, VPEXTRQ, VPINSRB, VPINSRD, VPINSRW,
VPINSRQ, VPMOVSX/ZX, VLDMXCSR, VSTMXCSR
VEXTRACTF128,
VPERM2F128,
Type 6
VBROADCASTSD,
VBROADCASTF128,
VINSERTF128,
VMOVLHPS, VMOVHLPS, VPMOVMSKB, VPSLLDQ,
VMOVLHPS, VMOVHLPS
Type 7
VPSRLDQ, VPSLLW, VPSLLD, VPSLLQ, VPSRAW, VPSRAD,
VPSRLW, VPSRLD, VPSRLQ
Type 8
Type 11
Type 12
2-26
Vol. 2A
INSTRUCTION FORMAT
2.5.1
Exceptions Type 1 (Aligned Memory Reference)
Table 2-18. Type 1 Class Exception Conditions
Exception
Cause of Exception
X
X
VEX prefix.
VEX prefix:
X
X
If XCR0[2:1] ? ‘11b’.
If CR4.OSXSAVE[bit 18]=0.
Invalid Opcode,
Legacy SSE instruction:
#UD
X
X
X
X
If CR0.EM[bit 2] = 1.
If CR4.OSFXSR[bit 9] = 0.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a VEX prefix.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Avail-
X
X
X
X
If CR0.TS[bit 3]=1.
able, #NM
X
For an illegal address in the SS segment.
Stack, #SS(0)
X
If a memory address referencing the SS segment is in a non-canonical form.
VEX.256: Memory operand is not 32-byte aligned.
X
X
VEX.128: Memory operand is not 16-byte aligned.
X
X
X
X
Legacy SSE: Memory operand is not 16-byte aligned.
General Protec-
For an illegal memory operand effective address in the CS, DS, ES, FS or GS seg-
tion, #GP(0)
X
ments.
X
If the memory address is in a non-canonical form.
X
X
If any part of the operand lies outside the effective address space from 0 to FFFFH.
Page Fault
X
X
X
For a page fault.
#PF(fault-code)
Vol. 2A
2-27
INSTRUCTION FORMAT
2.5.2
Exceptions Type 2 (>=16 Byte Memory Reference, Unaligned)
Table 2-19. Type 2 Class Exception Conditions
Exception
Cause of Exception
X
X
VEX prefix.
X
X
X
X
If an unmasked SIMD floating-point exception and CR4.OSXMMEXCPT[bit 10] = 0.
VEX prefix:
X
X
If XCR0[2:1] ? ‘11b’.
If CR4.OSXSAVE[bit 18]=0.
Invalid Opcode,
Legacy SSE instruction:
#UD
X
X
X
X
If CR0.EM[bit 2] = 1.
If CR4.OSFXSR[bit 9] = 0.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a VEX prefix.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Avail-
X
X
X
X
If CR0.TS[bit 3]=1.
able, #NM
X
For an illegal address in the SS segment.
Stack, #SS(0)
X
If a memory address referencing the SS segment is in a non-canonical form.
X
X
X
X
Legacy SSE: Memory operand is not 16-byte aligned.
General Protec-
X
For an illegal memory operand effective address in the CS, DS, ES, FS or GS segments.
tion, #GP(0)
X
If the memory address is in a non-canonical form.
X
X
If any part of the operand lies outside the effective address space from 0 to FFFFH.
Page Fault
X
X
X
For a page fault.
#PF(fault-code)
SIMD Floating-
point Exception,
X
X
X
X
If an unmasked SIMD floating-point exception and CR4.OSXMMEXCPT[bit 10] = 1.
#XM
2-28
Vol. 2A
INSTRUCTION FORMAT
2.5.3
Exceptions Type 3 (<16 Byte Memory Argument)
Table 2-20. Type 3 Class Exception Conditions
Exception
Cause of Exception
X
X
VEX prefix.
X
X
X
X
If an unmasked SIMD floating-point exception and CR4.OSXMMEXCPT[bit 10] = 0.
VEX prefix:
X
X
If XCR0[2:1] ? ‘11b’.
If CR4.OSXSAVE[bit 18]=0.
Invalid Opcode, #UD
Legacy SSE instruction:
X
X
X
X
If CR0.EM[bit 2] = 1.
If CR4.OSFXSR[bit 9] = 0.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a VEX prefix.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Available,
X
X
X
X
If CR0.TS[bit 3]=1.
#NM
X
For an illegal address in the SS segment.
Stack, #SS(0)
X
If a memory address referencing the SS segment is in a non-canonical form.
For an illegal memory operand effective address in the CS, DS, ES, FS or GS seg-
X
ments.
General Protection,
X
If the memory address is in a non-canonical form.
#GP(0)
If any part of the operand lies outside the effective address space from 0 to
X
X
FFFFH.
Page Fault
X
X
X
For a page fault.
#PF(fault-code)
Alignment Check
For 2, 4, or 8 byte memory access if alignment checking is enabled and an
X
X
X
#AC(0)
unaligned memory access is made while the current privilege level is 3.
SIMD Floating-point
X
X
X
X
If an unmasked SIMD floating-point exception and CR4.OSXMMEXCPT[bit 10] = 1.
Exception, #XM
Vol. 2A
2-29
INSTRUCTION FORMAT
2.5.4
Exceptions Type 4 (>=16 Byte Mem Arg, No Alignment, No Floating-point Exceptions)
Table 2-21. Type 4 Class Exception Conditions
Exception
Cause of Exception
X
X
VEX prefix.
VEX prefix:
X
X
If XCR0[2:1] ? ‘11b’.
If CR4.OSXSAVE[bit 18]=0.
Legacy SSE instruction:
Invalid Opcode, #UD
X
X
X
X
If CR0.EM[bit 2] = 1.
If CR4.OSFXSR[bit 9] = 0.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a VEX prefix.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Available,
X
X
X
X
If CR0.TS[bit 3]=1.
#NM
X
For an illegal address in the SS segment.
Stack, #SS(0)
X
If a memory address referencing the SS segment is in a non-canonical form.
X
X
X
X
Legacy SSE: Memory operand is not 16-byte aligned.1
For an illegal memory operand effective address in the CS, DS, ES, FS or GS seg-
X
General Protection,
ments.
#GP(0)
X
If the memory address is in a non-canonical form.
If any part of the operand lies outside the effective address space from 0 to
X
X
FFFFH.
Page Fault
X
X
X
For a page fault.
#PF(fault-code)
NOTES:
1. LDDQU, MOVUPD, MOVUPS, PCMPESTRI, PCMPESTRM, PCMPISTRI, and PCMPISTRM instructions do not cause #GP if the memory
operand is not aligned to 16-Byte boundary.
2-30
Vol. 2A
INSTRUCTION FORMAT
2.5.5
Exceptions Type 5 (<16 Byte Mem Arg and No FP Exceptions)
Table 2-22. Type 5 Class Exception Conditions
Exception
Cause of Exception
X
X
VEX prefix.
VEX prefix:
X
X
If XCR0[2:1] ? ‘11b’.
If CR4.OSXSAVE[bit 18]=0.
Legacy SSE instruction:
Invalid Opcode, #UD
X
X
X
X
If CR0.EM[bit 2] = 1.
If CR4.OSFXSR[bit 9] = 0.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a VEX prefix.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Available,
X
X
X
X
If CR0.TS[bit 3]=1.
#NM
X
For an illegal address in the SS segment.
Stack, #SS(0)
X
If a memory address referencing the SS segment is in a non-canonical form.
For an illegal memory operand effective address in the CS, DS, ES, FS or GS seg-
X
ments.
General Protection,
X
If the memory address is in a non-canonical form.
#GP(0)
If any part of the operand lies outside the effective address space from 0 to
X
X
FFFFH.
Page Fault
X
X
X
For a page fault.
#PF(fault-code)
Alignment Check
For 2, 4, or 8 byte memory access if alignment checking is enabled and an
X
X
X
#AC(0)
unaligned memory access is made while the current privilege level is 3.
Vol. 2A
2-31
INSTRUCTION FORMAT
2.5.6
Exceptions Type 6 (VEX-Encoded Instructions without Legacy SSE Analogues)
Note: At present, the AVX instructions in this category do not generate floating-point exceptions.
Table 2-23. Type 6 Class Exception Conditions
Exception
Cause of Exception
X
X
VEX prefix.
If XCR0[2:1] ? ‘11b’.
X
X
If CR4.OSXSAVE[bit 18]=0.
Invalid Opcode, #UD
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a VEX prefix.
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Available,
X
X
If CR0.TS[bit 3]=1.
#NM
X
For an illegal address in the SS segment.
Stack, #SS(0)
X
If a memory address referencing the SS segment is in a non-canonical form.
For an illegal memory operand effective address in the CS, DS, ES, FS or GS seg-
General Protection,
X
ments.
#GP(0)
X
If the memory address is in a non-canonical form.
Page Fault
X
X
For a page fault.
#PF(fault-code)
Alignment Check
For 2, 4, or 8 byte memory access if alignment checking is enabled and an
X
X
#AC(0)
unaligned memory access is made while the current privilege level is 3.
2-32
Vol. 2A
INSTRUCTION FORMAT
2.5.7
Exceptions Type 7 (No FP Exceptions, No Memory Arg)
Table 2-24. Type 7 Class Exception Conditions
Exception
Cause of Exception
X
X
VEX prefix.
VEX prefix:
X
X
If XCR0[2:1] ? ‘11b’.
If CR4.OSXSAVE[bit 18]=0.
Legacy SSE instruction:
Invalid Opcode, #UD
X
X
X
X
If CR0.EM[bit 2] = 1.
If CR4.OSFXSR[bit 9] = 0.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a VEX prefix.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Available,
X
X
If CR0.TS[bit 3]=1.
#NM
2.5.8
Exceptions Type 8 (AVX and No Memory Argument)
Table 2-25. Type 8 Class Exception Conditions
Exception
Cause of Exception
Invalid Opcode, #UD
X
X
Always in Real or Virtual-8086 mode.
X
X
If XCR0[2:1] ? ‘11b’.
If CR4.OSXSAVE[bit 18]=0.
If CPUID.01H.ECX.AVX[bit 28]=0.
If VEX.vvvv ? 1111B.
X
X
X
X
If proceeded by a LOCK prefix (F0H).
Device Not Available,
X
X
If CR0.TS[bit 3]=1.
#NM
Vol. 2A
2-33
INSTRUCTION FORMAT
2.5.9
Exceptions Type 11 (VEX-only, Mem Arg, No AC, Floating-point Exceptions)
Table 2-26. Type 11 Class Exception Conditions
Exception
Cause of Exception
Invalid Opcode, #UD
X
X
VEX prefix.
X
X
VEX prefix:
If XCR0[2:1] ? ‘11b’.
If CR4.OSXSAVE[bit 18]=0.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a VEX prefix.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Avail-
X
X
X
X
If CR0.TS[bit 3]=1.
able, #NM
Stack, #SS(0)
X
For an illegal address in the SS segment.
X
If a memory address referencing the SS segment is in a non-canonical form.
General Protection,
X
For an illegal memory operand effective address in the CS, DS, ES, FS or GS seg-
#GP(0)
ments.
X
If the memory address is in a non-canonical form.
X
X
If any part of the operand lies outside the effective address space from 0 to
FFFFH.
Page Fault #PF
X
X
X
For a page fault.
(fault-code)
SIMD Floating-Point
X
X
X
X
If an unmasked SIMD floating-point exception and CR4.OSXMMEXCPT[bit 10] = 1.
Exception, #XM
2-34
Vol. 2A
INSTRUCTION FORMAT
2.5.10 Exceptions Type 12 (VEX-only, VSIB Mem Arg, No AC, No Floating-point Exceptions)
Table 2-27. Type 12 Class Exception Conditions
Exception
Cause of Exception
Invalid Opcode, #UD
X
X
VEX prefix.
X
X
VEX prefix:
If XCR0[2:1] ? ‘11b’.
If CR4.OSXSAVE[bit 18]=0.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a VEX prefix.
X
X
X
NA
If address size attribute is 16 bit.
X
X
X
X
If ModR/M.mod = ‘11b’.
X
X
X
X
If ModR/M.rm ? ‘100b’.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
X
X
X
X
If any vector register is used more than once between the destination register,
mask register and the index register in VSIB addressing.
Device Not Available,
X
X
X
X
If CR0.TS[bit 3]=1.
#NM
Stack, #SS(0)
X
For an illegal address in the SS segment.
X
If a memory address referencing the SS segment is in a non-canonical form.
General Protection,
X
For an illegal memory operand effective address in the CS, DS, ES, FS or GS seg-
#GP(0)
ments.
X
If the memory address is in a non-canonical form.
X
X
If any part of the operand lies outside the effective address space from 0 to
FFFFH.
Page Fault #PF (fault-
X
X
X
For a page fault.
code)
2.6
VEX ENCODING SUPPORT FOR GPR INSTRUCTIONS
VEX prefix may be used to encode instructions that operate on neither YMM nor XMM registers. VEX-encoded
general-purpose-register instructions have the following properties:
• Instruction syntax support for three encodable operands.
• Encoding support for instruction syntax of non-destructive source operand, destination operand encoded via
VEX.vvvv, and destructive three-operand syntax.
• Elimination of escape opcode byte (0FH), two-byte escape via a compact bit field representation within the VEX
prefix.
• Elimination of the need to use REX prefix to encode the extended half of general-purpose register sets (R8-
R15) for direct register access or memory addressing.
• Flexible and more compact bit fields are provided in the VEX prefix to retain the full functionality provided by
REX prefix. REX.W, REX.X, REX.B functionalities are provided in the three-byte VEX prefix only.
• VEX-encoded GPR instructions are encoded with VEX.L=0.
Vol. 2A
2-35
INSTRUCTION FORMAT
Any VEX-encoded GPR instruction with a 66H, F2H, or F3H prefix preceding VEX will #UD.
Any VEX-encoded GPR instruction with a REX prefix proceeding VEX will #UD.
VEX-encoded GPR instructions are not supported in real and virtual 8086 modes.
2.6.1
Exceptions Type 13 (VEX-Encoded GPR Instructions)
The exception conditions applicable to VEX-encoded GPR instruction differs from those of legacy GPR instructions.
Table 2-28 lists VEX-encoded GPR instructions. The exception conditions for VEX-encoded GRP instructions are
found in Table 2-29 for those instructions which have a default operand size of 32 bits and 16-bit operand size is
not encodable.
Table 2-28. VEX-Encoded GPR Instructions
Exception Class
Instruction
Type 13
ANDN, BEXTR, BLSI, BLSMSK, BLSR, BZHI, MULX, PDEP, PEXT, RORX, SARX, SHLX, SHRX
(*) - Additional exception restrictions are present - see the Instruction description for details.
Table 2-29. Type 13 Class Exception Conditions
Exception
Cause of Exception
Invalid Opcode, #UD
X
X
X
X
If BMI1/BMI2 CPUID feature flag is ‘0’.
X
X
If a VEX prefix is present.
X
X
X
X
If VEX.L = 1.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a VEX prefix.
Stack, #SS(0)
X
X
X
For an illegal address in the SS segment.
X
If a memory address referencing the SS segment is in a non-canonical form.
General Protection,
X
For an illegal memory operand effective address in the CS, DS, ES, FS or GS seg-
#GP(0)
ments.
If the DS, ES, FS, or GS register is used to access memory and it contains a null
segment selector.
X
If the memory address is in a non-canonical form.
X
X
If any part of the operand lies outside the effective address space from 0 to
FFFFH.
Page Fault #PF(fault-
X
X
X
For a page fault.
code)
Alignment Check
X
X
X
For 2, 4, or 8 byte memory access if alignment checking is enabled and an
#AC(0)
unaligned memory access is made while the current privilege level is 3.
2.7
INTEL® AVX-512 ENCODING
The majority of the Intel AVX-512 family of instructions (operating on 512/256/128-bit vector register operands)
are encoded using a new prefix (called EVEX). Opmask instructions (operating on opmask register operands) are
encoded using the VEX prefix. The EVEX prefix has some parts resembling the instruction encoding scheme using
the VEX prefix, and many other capabilities not available with the VEX prefix.
2-36
Vol. 2A
INSTRUCTION FORMAT
The significant feature differences between EVEX and VEX are summarized below.
• EVEX is a 4-Byte prefix (the first byte must be 62H); VEX is either a 2-Byte (C5H is the first byte) or 3-Byte
(C4H is the first byte) prefix.
• EVEX prefix can encode 32 vector registers (XMM/YMM/ZMM) in 64-bit mode.
• EVEX prefix can encode an opmask register for conditional processing or selection control in EVEX-encoded
vector instructions. Opmask instructions, whose source/destination operands are opmask registers and treat
the content of an opmask register as a single value, are encoded using the VEX prefix.
• EVEX memory addressing with disp8 form uses a compressed disp8 encoding scheme to improve the encoding
density of the instruction byte stream.
• EVEX prefix can encode functionality that are specific to instruction classes (e.g., packed instruction with
“load+op” semantic can support embedded broadcast functionality, floating-point instruction with rounding
semantic can support static rounding functionality, floating-point instruction with non-rounding arithmetic
semantic can support “suppress all exceptions” functionality).
2.7.1
Instruction Format and EVEX
The placement of the EVEX prefix in an IA instruction is represented in Figure 2-10. Note that the values contained
within brackets are optional.
# of bytes:
4
1
1
1
2, 4
1
[Prefixes]
EVEX
Opcode
ModR/M
[SIB]
[Disp16,32]
[Immediate]
1
[Disp8*N]
Figure 2-10. Intel® AVX-512 Instruction Format and the EVEX Prefix
The EVEX prefix is a 4-byte prefix, with the first two bytes derived from unused encoding form of the 32-bit-mode-
only BOUND instruction. The layout of the EVEX prefix is shown in Figure 2-11. The first byte must be 62H, followed
by three payload bytes, denoted as P0, P1, and P2 individually or collectively as P[23:0] (see Figure 2-11).
EVEX
62H
P0
P1
P2
7
6
5
4
3
2
1
0
R
X
B
R’
0
m
m
m
P[7:0]
P0
7
6
5
4
3
2
1
0
P1
W
v
v
v
v
1
p
p
P[15:8]
7
6
5
4
3
2
1
0
P2
z
L’
L
b
V’
a
a
a
P[23:16]
Figure 2-11. Bit Field Layout of the EVEX Prefix1
NOTES:
1. See Table 2-30 for additional details on bit fields.
Vol. 2A
2-37
INSTRUCTION FORMAT
Table 2-30. EVEX Prefix Bit Field Functional Grouping
Notation
Bit field Group
Position
Comment
EVEX.mmm
Access to up to eight decoding maps
P[2:0]
Currently, only the following decoding maps are supported: 1,
2, 3, 5, and 6.
--
Reserved
P[3]
Must be 0.
EVEX.R’
High-16 register specifier modifier
P[4]
Combine with EVEX.R and ModR/M.reg. This bit is stored in
inverted format.
EVEX.RXB
Next-8 register specifier modifier
P[7:5]
Combine with ModR/M.reg, ModR/M.rm (base, index/vidx). This
field is encoded in bit inverted format.
EVEX.X
High-16 register specifier modifier
P[6]
Combine with EVEX.B and ModR/M.rm, when SIB/VSIB absent.
EVEX.pp
Compressed legacy prefix
P[9:8]
Identical to VEX.pp.
--
Fixed Value
P[10]
Must be 1.
EVEX.vvvv
VVVV register specifier
P[14:11]
Same as VEX.vvvv. This field is encoded in bit inverted format.
EVEX.W
Operand size promotion/Opcode
P[15]
extension
EVEX.aaa
Embedded opmask register specifier
P[18:16]
EVEX.V’
High-16 VVVV/VIDX register specifier
P[19]
Combine with EVEX.vvvv or when VSIB present. This bit is
stored in inverted format.
EVEX.b
Broadcast/RC/SAE Context
P[20]
EVEX.L’L
Vector length/RC
P[22:21]
EVEX.z
Zeroing/Merging
P[23]
The bit fields in P[23:0] are divided into the following functional groups (Table 2-30 provides a tabular summary):
• Reserved bits: P[3] must be 0, otherwise #UD.
• Fixed-value bit: P[10] must be 1, otherwise #UD.
• Compressed legacy prefix/escape bytes: P[1:0] is identical to the lowest 2 bits of VEX.mmmmm; P[9:8] is
identical to VEX.pp.
• EVEX.mmm: P[2:0] provides access to up to eight decoding maps. Currently, only the following decoding maps
are supported: 1, 2, 3, 5, and 6. Map ids 1, 2, and 3 are denoted by 0F, 0F38, and 0F3A, respectively, in the
instruction encoding descriptions.
• Operand specifier modifier bits for vector register, general purpose register, memory addressing: P[7:5] allows
access to the next set of 8 registers beyond the low 8 registers when combined with ModR/M register specifiers.
• Operand specifier modifier bit for vector register: P[4] (or EVEX.R’) allows access to the high 16 vector register
set when combined with P[7] and ModR/M.reg specifier; P[6] can also provide access to a high 16 vector
register when SIB or VSIB addressing are not needed.
• Non-destructive source /vector index operand specifier: P[19] and P[14:11] encode the second source vector
register operand in a non-destructive source syntax, vector index register operand can access an upper 16
vector register using P[19].
• Op-mask register specifiers: P[18:16] encodes op-mask register set k0-k7 in instructions operating on vector
registers.
• EVEX.W: P[15] is similar to VEX.W which serves either as opcode extension bit or operand size promotion to
64-bit in 64-bit mode.
• Vector destination merging/zeroing: P[23] encodes the destination result behavior which either zeroes the
masked elements or leave masked element unchanged.
• Broadcast/Static-rounding/SAE context bit: P[20] encodes multiple functionality, which differs across different
classes of instructions and can affect the meaning of the remaining field (EVEX.L’L). The functionality for the
following instruction classes are:
2-38
Vol. 2A
INSTRUCTION FORMAT
- Broadcasting a single element across the destination vector register: this applies to the instruction class
with Load+Op semantic where one of the source operand is from memory.
- Redirect L’L field (P[22:21]) as static rounding control for floating-point instructions with rounding
semantic. Static rounding control overrides MXCSR.RC field and implies “Suppress all exceptions” (SAE).
- Enable SAE for floating -point instructions with arithmetic semantic that is not rounding.
- For instruction classes outside of the afore-mentioned three classes, setting EVEX.b will cause #UD.
• Vector length/rounding control specifier: P[22:21] can serve one of three options.
- Vector length information for packed vector instructions.
- Ignored for instructions operating on vector register content as a single data element.
- Rounding control for floating-point instructions that have a rounding semantic and whose source and
destination operands are all vector registers.
2.7.2
Register Specifier Encoding and EVEX
EVEX-encoded instruction can access 8 opmask registers, 16 general-purpose registers and 32 vector registers in
64-bit mode (8 general-purpose registers and 8 vector registers in non-64-bit modes). EVEX-encoding can support
instruction syntax that access up to 4 instruction operands. Normal memory addressing modes and VSIB memory
addressing are supported with EVEX prefix encoding. The mapping of register operands used by various instruction
syntax and memory addressing in 64-bit mode are shown in Table 2-31. Opmask register encoding is described in
Section 2.7.3.
Table 2-31. 32-Register Support in 64-bit Mode Using EVEX with Embedded REX Bits
41
3
[2:0]
Reg. Type
Common Usages
REG
EVEX.R’
REX.R
modrm.reg
GPR, Vector
Destination or Source
VVVV
EVEX.V’
EVEX.vvvv
GPR, Vector
2ndSource or Destination
RM
EVEX.X
EVEX.B
modrm.r/m
GPR, Vector
1st Source or Destination
BASE
0
EVEX.B
modrm.r/m
GPR
memory addressing
INDEX
0
EVEX.X
sib.index
GPR
memory addressing
VIDX
EVEX.V’
EVEX.X
sib.index
Vector
VSIB memory addressing
NOTES:
1. Not applicable for accessing general purpose registers.
The mapping of register operands used by various instruction syntax and memory addressing in 32-bit modes are
shown in Table 2-32.
Table 2-32. EVEX Encoding Register Specifiers in 32-bit Mode
[2:0]
Reg. Type
Common Usages
REG
modrm.reg
GPR, Vector
Destination or Source
VVVV
EVEX.vvv
GPR, Vector
2nd Source or Destination
RM
modrm.r/m
GPR, Vector
1st Source or Destination
BASE
modrm.r/m
GPR
Memory Addressing
INDEX
sib.index
GPR
Memory Addressing
VIDX
sib.index
Vector
VSIB Memory Addressing
Vol. 2A
2-39
INSTRUCTION FORMAT
2.7.3
Opmask Register Encoding
There are eight opmask registers, k0-k7. Opmask register encoding falls into two categories:
• Opmask registers that are the source or destination operands of an instruction treating the content of opmask
register as a scalar value, are encoded using the VEX prefix scheme. It can support up to three operands using
standard modR/M byte’s reg field and rm field and VEX.vvvv. Such a scalar opmask instruction does not support
conditional update of the destination operand.
• An opmask register providing conditional processing and/or conditional update of the destination register of a
vector instruction is encoded using EVEX.aaa field (see Section 2.7.4).
• An opmask register serving as the destination or source operand of a vector instruction is encoded using
standard modR/M byte’s reg field and rm fields.
Table 2-33. Opmask Register Specifier Encoding
[2:0]
Register Access
Common Usages
REG
modrm.reg
k0-k7
Source
VVVV
VEX.vvvv
k0-k7
2nd Source
RM
modrm.r/m
k0-7
1st Source
{k1}
EVEX.aaa
k01-k7
Opmask
NOTES:
1. Instructions that overwrite the conditional mask in opmask do not permit using k0 as the embedded mask.
2.7.4
Masking Support in EVEX
EVEX can encode an opmask register to conditionally control per-element computational operation and updating of
result of an instruction to the destination operand. The predicate operand is known as the opmask register. The
EVEX.aaa field, P[18:16] of the EVEX prefix, is used to encode one out of a set of eight 64-bit architectural regis-
ters. Note that from this set of 8 architectural registers, only k1 through k7 can be addressed as predicate oper-
ands. k0 can be used as a regular source or destination but cannot be encoded as a predicate operand.
AVX-512 instructions support two types of masking with EVEX.z bit (P[23]) controlling the type of masking:
• Merging-masking, which is the default type of masking for EVEX-encoded vector instructions, preserves the old
value of each element of the destination where the corresponding mask bit has a 0. It corresponds to the case
of EVEX.z = 0.
• Zeroing-masking, is enabled by having the EVEX.z bit set to 1. In this case, an element of the destination is set
to 0 when the corresponding mask bit has a 0 value.
AVX-512 Foundation instructions can be divided into the following groups:
• Instructions which support “zeroing-masking”.
- Also allow merging-masking.
• Instructions which require aaa = 000.
- Do not allow any form of masking.
• Instructions which allow merging-masking but do not allow zeroing-masking.
- Require EVEX.z to be set to 0.
- This group is mostly composed of instructions that write to memory.
• Instructions which require aaa <> 000 do not allow EVEX.z to be set to 1.
— Allow merging-masking and do not allow zeroing-masking, e.g., gather instructions.
2-40
Vol. 2A
INSTRUCTION FORMAT
2.7.5
Compressed Displacement (disp8*N) Support in EVEX
For memory addressing using disp8 form, EVEX-encoded instructions always use a compressed displacement
scheme by multiplying disp8 in conjunction with a scaling factor N that is determined based on the vector length,
the value of EVEX.b bit (embedded broadcast) and the input element size of the instruction. In general, the factor
N corresponds to the number of bytes characterizing the internal memory operation of the input operand (e.g., 64
when the accessing a full 512-bit memory vector). The scale factor N is listed in Table 2-34 and Table 2-35 below,
where EVEX encoded instructions are classified using the tupletype attribute. The scale factor N of each tupletype
is listed based on the vector length (VL) and other factors affecting it.
Table 2-34 covers EVEX-encoded instructions which has a load semantic in conjunction with additional computa-
tional or data element movement operation, operating either on the full vector or half vector (due to conversion of
numerical precision from a wider format to narrower format). EVEX.b is supported for such instructions for data
element sizes which are either dword or qword (see Section 2.7.11).
EVEX-encoded instruction that are pure load/store, and “Load+op” instruction semantic that operate on data
element size less then dword do not support broadcasting using EVEX.b. These are listed in Table 2-35. Table 2-35
also includes many broadcast instructions which perform broadcast using a subset of data elements without using
EVEX.b. These instructions and a few data element size conversion instruction are covered in Table 2-35. Instruc-
tion classified in Table 2-35 do not use EVEX.b and EVEX.b must be 0, otherwise #UD will occur.
The tupletype will be referenced in the instruction operand encoding table in the reference page of each instruction,
providing the cross reference for the scaling factor N to encoding memory addressing operand.
Note that the disp8*N rules still apply when using 16b addressing.
Table 2-34. Compressed Displacement (DISP8*N) Affected by Embedded Broadcast
TupleType
EVEX.b
InputSize
EVEX.W
Broadcast
N (VL=128)
N (VL=256)
N (VL= 512)
Comment
0
32bit
0
none
16
32
64
1
32bit
0
{1tox}
4
4
4
Load+Op (Full Vector
Full
0
64bit
1
none
16
32
64
Dword/Qword)
1
64bit
1
{1tox}
8
8
8
0
32bit
0
none
8
16
32
Half
Load+Op (Half Vector)
1
32bit
0
{1tox}
4
4
4
Table 2-35. EVEX DISP8*N for Instructions Not Affected by Embedded Broadcast
TupleType
InputSize
EVEX.W
N (VL= 128)
N (VL= 256)
N (VL= 512)
Comment
Full Mem
N/A
N/A
16
32
64
Load/store or subDword full vector
8bit
N/A
1
1
1
16bit
N/A
2
2
2
Tuple1 Scalar
1Tuple
32bit
0
4
4
4
64bit
1
8
8
8
32bit
N/A
4
4
4
1 Tuple, memsize not affected by
Tuple1 Fixed
64bit
N/A
8
8
8
EVEX.W
32bit
0
8
8
8
Tuple2
Broadcast (2 elements)
64bit
1
NA
16
16
32bit
0
NA
16
16
Tuple4
Broadcast (4 elements)
64bit
1
NA
NA
32
Tuple8
32bit
0
NA
NA
32
Broadcast (8 elements)
Half Mem
N/A
N/A
8
16
32
SubQword Conversion
Quarter Mem
N/A
N/A
4
8
16
SubDword Conversion
Vol. 2A
2-41
INSTRUCTION FORMAT
Table 2-35. EVEX DISP8*N for Instructions Not Affected by Embedded Broadcast (Contd.)
TupleType
InputSize
EVEX.W
N (VL= 128)
N (VL= 256)
N (VL= 512)
Comment
Eighth Mem
N/A
N/A
2
4
8
SubWord Conversion
Mem128
N/A
N/A
16
16
16
Shift count from memory
MOVDDUP
N/A
N/A
8
32
64
VMOVDDUP
2.7.6
EVEX Encoding of Broadcast/Rounding/SAE Support
EVEX.b can provide three types of encoding context, depending on the instruction classes:
• Embedded broadcasting of one data element from a source memory operand to the destination for vector
instructions with “load+op” semantic.
• Static rounding control overriding MXCSR.RC for floating-point instructions with rounding semantic.
• “Suppress All exceptions” (SAE) overriding MXCSR mask control for floating-point arithmetic instructions that
do not have rounding semantic.
2.7.7
Embedded Broadcast Support in EVEX
EVEX encodes an embedded broadcast functionality that is supported on many vector instructions with 32-bit
(double word or single precision floating-point) and 64-bit data elements, and when the source operand is from
memory. EVEX.b (P[20]) bit is used to enable broadcast on load-op instructions. When enabled, only one element
is loaded from memory and broadcasted to all other elements instead of loading the full memory size.
The following instruction classes do not support embedded broadcasting:
• Instructions with only one scalar result is written to the vector destination.
• Instructions with explicit broadcast functionality provided by its opcode.
• Instruction semantic is a pure load or a pure store operation.
2.7.8
Static Rounding Support in EVEX
Static rounding control embedded in the EVEX encoding system applies only to register-to-register flavor of
floating-point instructions with rounding semantic at two distinct vector lengths: (i) scalar, (ii) 512-bit. In both
cases, the field EVEX.L’L expresses rounding mode control overriding MXCSR.RC if EVEX.b is set. When EVEX.b is
set, “suppress all exceptions” is implied. The processor behaves as if all MXCSR masking controls are set.
2.7.9
SAE Support in EVEX
The EVEX encoding system allows arithmetic floating-point instructions without rounding semantic to be encoded
with the SAE attribute. This capability applies to scalar and 512-bit vector lengths, register-to-register only, by
setting EVEX.b. When EVEX.b is set, “suppress all exceptions” is implied. The processor behaves as if all MXCSR
masking controls are set.
2.7.10 Vector Length Orthogonality
The architecture of EVEX encoding scheme can support SIMD instructions operating at multiple vector lengths.
Many AVX-512 Foundation instructions operate at 512-bit vector length. The vector length of EVEX encoded vector
instructions are generally determined using the L’L field in EVEX prefix, except for 512-bit floating-point, reg-reg
instructions with rounding semantic. The table below shows the vector length corresponding to various values of
the L’L bits. When EVEX is used to encode scalar instructions, L’L is generally ignored.
When EVEX.b bit is set for a register-register instructions with floating-point rounding semantic, the same two bits
P2[6:5] specifies rounding mode for the instruction, with implied SAE behavior. The mapping of different instruc-
tion classes relative to the embedded broadcast/rounding/SAE control and the EVEX.L’L fields are summarized in
Table 2-36.
2-42
Vol. 2A
INSTRUCTION FORMAT
Table 2-36. EVEX Embedded Broadcast/Rounding/SAE and Vector Length on Vector Instructions
Position
P2[4]
P2[6:5]
P2[6:5]
Broadcast/Rounding/SAE Context
EVEX.b
EVEX.L’L
EVEX.RC
Reg-reg, FP Instructions w/ rounding semantic or SAE
Enable static rounding
Vector length Implied
00b: SAE + RNE
control (SAE implied)
(512 bit or scalar)
01b: SAE + RD
10b: SAE + RU
11b: SAE + RZ
Load+op Instructions w/ memory source
Broadcast Control
00b: 128-bit
NA
01b: 256-bit
Other Instructions (
Must be 0 (otherwise
NA
10b: 512-bit
Explicit Load/Store/Broadcast/Gather/Scatter)
#UD)
11b: Reserved (#UD)
2.7.11 #UD Equations for EVEX
Instructions encoded using EVEX can face three types of UD conditions: state dependent, opcode independent and
opcode dependent.
2.7.11.1 State Dependent #UD
In general, attempts of execute an instruction, which required OS support for incremental extended state compo-
nent, will #UD if required state components were not enabled by OS. Table 2-37 lists instruction categories with
respect to required processor state components. Attempts to execute a given category of instructions while
enabled states were less than the required bit vector in XCR0 shown in Table 2-37 will cause #UD.
Table 2-37. OS XSAVE Enabling Requirements of Instruction Categories
Instruction Categories
Vector Register State Access
Required XCR0 Bit Vector [7:0]
Legacy SIMD prefix encoded Instructions (e.g SSE)
XMM
xxxxxx11b
VEX-encoded instructions operating on YMM
YMM
xxxxx111b
EVEX-encoded 128-bit instructions
ZMM
111xx111b
EVEX-encoded 256-bit instructions
ZMM
111xx111b
EVEX-encoded 512-bit instructions
ZMM
111xx111b
VEX-encoded instructions operating on opmask
k-reg
111xxx11b
2.7.11.2 Opcode Independent #UD
A number of bit fields in EVEX encoded instruction must obey mode-specific but opcode-independent patterns
listed in Table 2-38.
Table 2-38. Opcode Independent, State Dependent EVEX Bit Fields
Position
Notation
64-bit #UD
Non-64-bit #UD
P[3]
--
if > 0
if > 0
P[10]
--
if 0
if 0
P[2:0]
EVEX.mmm
if 000b, 100b, or 111b
if 000b, 100b, or 111b
P[7 : 6]
EVEX.RX
None (valid)
None (BOUND if EVEX.RX != 11b)
Vol. 2A
2-43
INSTRUCTION FORMAT
2.7.11.3 Opcode Dependent #UD
This section describes legal values for the rest of the EVEX bit fields. Table 2-39 lists the #UD conditions of EVEX
prefix bit fields which encodes or modifies register operands.
Table 2-39. #UD Conditions of Operand-Encoding EVEX Prefix Bit Fields
Notation
Position
Operand Encoding
64-bit #UD
Non-64-bit #UD
EVEX.R
P[7]
ModRM.reg encodes k-reg
If EVEX.R = 0
None (BOUND if
EVEX.RX != 11b)
ModRM.reg is opcode extension
None (ignored)
ModRM.reg encodes all other registers
None (valid)
EVEX.X
P[6]
ModRM.r/m encodes ZMM/YMM/XMM
None (valid)
ModRM.r/m encodes k-reg or GPR
None (ignored)
ModRM.r/m without SIB/VSIB
None (ignored)
ModRM.r/m with SIB/VSIB
None (valid)
EVEX.B
P[5]
ModRM.r/m encodes k-reg
None (ignored)
None (ignored)
ModRM.r/m encodes other registers
None (valid)
ModRM.r/m base present
None (valid)
ModRM.r/m base not present
None (ignored)
EVEX.R’
P[4]
ModRM.reg encodes k-reg or GPR
If 0
None (ignored)
ModRM.reg is opcode extension
None (ignored)
ModRM.reg encodes ZMM/YMM/XMM
None (valid)
EVEX.vvvv
P[14:11]
vvvv encodes ZMM/YMM/XMM
None (valid)
None (valid)
P[14] ignored
Otherwise
If != 1111b
If != 1111b
EVEX.V’
P[19]
Encodes ZMM/YMM/XMM
None (valid)
If 0
Otherwise
If 0
If 0
Table 2-40 lists the #UD conditions of instruction encoding of opmask register using EVEX.aaa and EVEX.z
Table 2-40. #UD Conditions of Opmask Related Encoding Field
Notation
Position
Operand Encoding
64-bit #UD
Non-64-bit #UD
EVEX.aaa
P[18:16]
Instructions do not use opmask for conditional processing1.
If aaa != 000b
If aaa != 000b
Opmask used as conditional processing mask and updated
If aaa = 000b
If aaa = 000b;
at completion2.
Opmask used as conditional processing.
None (valid3)
None (valid1)
EVEX.z
P[23]
Vector instruction using opmask as source or destination4.
If EVEX.z != 0
If EVEX.z != 0
Store instructions or gather/scatter instructions.
If EVEX.z != 0
If EVEX.z != 0
Instructions with EVEX.aaa = 000b.
If EVEX.z != 0
If EVEX.z != 0
VEX.vvvv
Varies
K-regs are instruction operands not mask control.
If vvvv = 0xxxb
None
NOTES:
1. E.g., VPBROADCASTMxxx, VPMOVM2x, VPMOVx2M.
2. E.g., Gather/Scatter family.
3. aaa can take any value. A value of 000 indicates that there is no masking on the instruction; in this case, all elements will be pro-
cessed as if there was a mask of ‘all ones’ regardless of the actual value in K0.
4. E.g., VFPCLASSPD/PS, VCMPB/D/Q/W family, VPMOVM2x, VPMOVx2M.
2-44
Vol. 2A
INSTRUCTION FORMAT
Table 2-41 lists the #UD conditions of EVEX bit fields that depends on the context of EVEX.b.
Table 2-41. #UD Conditions Dependent on EVEX.b Context
Notation
Position
Operand Encoding
64-bit #UD
Non-64-bit #UD
EVEX.L’Lb
P[22 : 20]
Reg-reg, FP instructions with rounding semantic.
None (valid1)
None (valid1)
Other reg-reg, FP instructions that can cause #XM.
None (valid2)
None (valid2)
Other reg-mem instructions in Table 2-34.
None (valid3)
None (valid3)
Other instruction classes4 in Table 2-35.
If EVEX.b = 1
If EVEX.b = 1
NOTES:
1. L’L specifies rounding control, see Table 2-36, supports {er} syntax.
2. L’L is ignored.
3. L’L specifies vector length, see Table 2-36, supports embedded broadcast syntax
4. L’L specifies either vector length or ignored.
2.7.12 Device Not Available
EVEX-encoded instructions follow the same rules when it comes to generating #NM (Device Not Available) excep-
tion. In particular, it is generated when CR0.TS[bit 3]= 1.
2.7.13 Scalar Instructions
EVEX-encoded scalar SIMD instructions can access up to 32 registers in 64-bit mode. Scalar instructions support
masking (using the least significant bit of the opmask register), but broadcasting is not supported.
2.8
EXCEPTION CLASSIFICATIONS OF EVEX-ENCODED INSTRUCTIONS
The exception behavior of EVEX-encoded instructions can be classified into the classes shown in the rest of this
section. The classification of EVEX-encoded instructions follow a similar framework as those of AVX and AVX2
instructions using the VEX prefix. Exception types for EVEX-encoded instructions are named in the style of
“E##” or with a suffix “E##XX”. The “##” designation generally follows that of AVX/AVX2 instructions. The
majority of EVEX encoded instruction with “Load+op” semantic supports memory fault suppression, which is repre-
sented by E##. The instructions with “Load+op” semantic but do not support fault suppression are named
“E##NF”. A summary table of exception classes by class names are shown below.
Table 2-42. EVEX-Encoded Instruction Exception Class Summary
Exception Class
Instruction set
Mem arg
(#XM)
Type E1
Vector Moves/Load/Stores
Explicitly aligned, w/ fault suppression
None
Type E1NF
Vector Non-temporal Stores
Explicitly aligned, no fault suppression
None
Type E2
FP Vector Load+op
Support fault suppression
Yes
Type E2NF
FP Vector Load+op
No fault suppression
Yes
Type E3
FP Scalar/Partial Vector, Load+Op
Support fault suppression
Yes
Type E3NF
FP Scalar/Partial Vector, Load+Op
No fault suppression
Yes
Type E4
Integer Vector Load+op
Support fault suppression
No
Type E4NF
Integer Vector Load+op
No fault suppression
No
Type E5
Legacy-like Promotion
Varies, Support fault suppression
No
Type E5NF
Legacy-like Promotion
Varies, No fault suppression
No
Vol. 2A
2-45
INSTRUCTION FORMAT
Table 2-42. EVEX-Encoded Instruction Exception Class Summary (Contd.)
Exception Class
Instruction set
Mem arg
(#XM)
Type E6
Post AVX Promotion
Varies, w/ fault suppression
No
Type E6NF
Post AVX Promotion
Varies, no fault suppression
No
Type E7NM
Register-to-register op
None
None
Type E9NF
Miscellaneous 128-bit
Vector-length Specific, no fault suppression
None
Type E10
Non-XF Scalar
Vector Length ignored, w/ fault suppression
None
Type E10NF
Non-XF Scalar
Vector Length ignored, no fault suppression
None
Type E11
VCVTPH2PS, VCVTPS2PH
Half Vector Length, w/ fault suppression
Yes
Type E12
Gather and Scatter Family
VSIB addressing, w/ fault suppression
None
Type E12NP
Gather and Scatter Prefetch Family
VSIB addressing, w/o page fault
None
Table 2-43 lists EVEX-encoded instruction mnemonic by exception classes.
Table 2-43. EVEX Instructions in Each Exception Class
Exception Class
Instruction
Type E1
VMOVAPD, VMOVAPS, VMOVDQA32, VMOVDQA64
Type E1NF
VMOVNTDQ, VMOVNTDQA, VMOVNTPD, VMOVNTPS
VADDPD, VADDPH, VADDPS, VCMPPD, VCMPPH, VCMPPS, VCVTDQ2PH, VCVTDQ2PS, VCVTPD2DQ, VCVTPD2PH,
VCVTPD2PS, VCVTPD2QQ, VCVTPD2UQQ, VCVTPD2UDQ, VCVTPH2DQ, VCVTPH2PD, VCVTPH2QQ, VCVTPH2UDQ,
VCVTPH2UQQ, VCVTPH2UW, VCVTPH2W, VCVTPS2DQ, VCVTPS2UDQS, VCVTQQ2PD, VCVTQQ2PH, VCVTQQ2PS,
VCVTTPD2DQ, VCVTTPD2QQ, VCVTTPD2UDQ, VCVTTPD2UQQ, VCVTTPH2DQ, VCVTTPH2QQ, VCVTTPH2UDQ,
VCVTTPH2UQQ, VCVTTPH2UW, VCVTTPH2W, VCVTTPS2DQ, VCVTTPS2UDQ, VCVTUDQ2PH, VCVTUDQ2PS,
VCVTUQQ2PD, VCVTUQQ2PH, VCVTUQQ2PS, VCVTUW2PH, VCVTW2PH, VDIVPD, VDIVPH, VDIVPS, VEXP2PD,
VEXP2PS, VFIXUPIMMPD, VFIXUPIMMPS, VFMADDxxxPD, VFMADDxxxPH, VFMADDxxxPS, VFMADDSUBxxxPD,
Type E2
VFMADDSUBxxxPH, VFMADDSUBxxxPS, VFMSUBADDxxxPD, VFMSUBADDxxxPH, VFMSUBADDxxxPS,
VFMSUBxxxPD, VFMSUBxxxPH, VFMSUBxxxPS, VFNMADDxxxPD, VFNMADDxxxPH, VFNMADDxxxPS,
VFNMSUBxxxPD, VFNMSUBxxxPH, VFNMSUBxxxPS, VGETEXPPD, VGETEXPPH, VGETEXPPS, VGETMANTPD,
VGETMANTPH, VGETMANTPS, VGETMANTSH, VMAXPD, VMAXPH, VMAXPS, VMINPD, VMINPH, VMINPS, VMULPD,
VMULPH, VMULPS, VRANGEPD, VRANGEPS, VREDUCEPD, VREDUCEPH, VREDUCEPS, VRNDSCALEPD,
VRNDSCALEPH, VRNDSCALEPS, VRCP28PD, VRCP28PS, VRSQRT28PD, VRSQRT28PS, VSCALEFPD, VSCALEFPS,
VSQRTPD, VSQRTPH, VSQRTPS, VSUBPD, VSUBPH, VSUBPS
VADDSD, VADDSH, VADDSS, VCMPSD, VCMPSH, VCMPSS, VCVTPS2QQ, VCVTPS2UQQ, VCVTPS2PD, VCVTSD2SH,
VCVTSD2SS, VCVTSH2SD, VCVTSH2SS, VCVTSS2SD, VCVTSS2SH, VCVTTPS2QQ, VCVTTPS2UQQ, VDIVSD, VDIVSH,
VDIVSS, VFMADDxxxSD, VFMADDxxxSH, VFMADDxxxSS, VFMSUBxxxSD, VFMSUBxxxSH, VFMSUBxxxSS,
VFNMADDxxxSD, VFNMADDxxxSH, VFNMADDxxxSS, VFNMSUBxxxSD, VFNMSUBxxxSH, VFNMSUBxxxSS,
Type E3
VFIXUPIMMSD, VFIXUPIMMSS, VGETEXPSD, VGETEXPSH, VGETEXPSS, VGETMANTSD, VGETMANTSH,
VGETMANTSS, VMAXSD, VMAXSH, VMAXSS, VMINSD, VMINSH, VMINSS, VMULSD, VMULSH, VMULSS, VRANGESD,
VRANGESS, VREDUCESD, VREDUCESH, VREDUCESS, VRNDSCALESD, VRNDSCALESH, VRNDSCALESS, VSCALEFSD,
VSCALEFSH, VSCALEFSS, VRCP28SD, VRCP28SS, VRSQRT28SD, VRSQRT28SS, VSQRTSD, VSQRTSH, VSQRTSS,
VSUBSD, VSUBSH, VSUBSS
VCOMISD, VCOMISH, VCOMISS, VCVTSD2SI, VCVTSD2USI, VCVTSH2SI, VCVTSH2USI, VCVTSI2SD, VCVTSI2SH,
Type E3NF
VCVTSI2SS, VCVTSS2SI, VCVTSS2USI, VCVTTSD2SI, VCVTTSD2USI, VCVTTSH2SI, VCVTTSH2USI, VCVTTSS2SI,
VCVTTSS2USI, VCVTUSI2SD, VCVTUSI2SH, VCVTUSI2SS, VUCOMISD, VUCOMISH, VUCOMISS
2-46
Vol. 2A
INSTRUCTION FORMAT
Table 2-43. EVEX Instructions in Each Exception Class (Contd.)
Exception Class
Instruction
VANDPD, VANDPS, VANDNPD, VANDNPS, VBLENDMPD, VBLENDMPS, VFCMADDCPH, VFCMULCPH, VFMADDCPH,
VFMULCPH, VFPCLASSPD, VFPCLASSPH, VFPCLASSPS, VORPD, VORPS, VPABSD, VPABSQ, VPADDD, VPADDQ,
VPANDD, VPANDQ, VPANDND, VPANDNQ, VPBLENDMB, VPBLENDMD, VPBLENDMQ, VPBLENDMW, VPCMPD,
VPCMPEQD, VPCMPEQQ, VPCMPGTD, VPCMPGTQ, VPCMPQ, VPCMPUD, VPCMPUQ, VPLZCNTD, VPLZCNTQ,
VPMADD52LUQ, VPMADD52HUQ, VPMAXSD, VPMAXSQ, VPMAXUD, VPMAXUQ, VPMINSD, VPMINSQ, VPMINUD,
Type E4
VPMINUQ, VPMULLD, VPMULLQ, VPMULUDQ, VPMULDQ, VPORD, VPORQ, VPROLD, VPROLQ, VPROLVD, VPROLVQ,
VPRORD, VPRORQ, VPRORVD, VPRORVQ, (VPSLLD, VPSLLQ, VPSRAD, VPSRAQ, VPSRAVW, VPSRAVD, VPSRAVW,
VPSRAVQ, VPSRLD, VPSRLQ)1, VPSUBD, VPSUBQ, VPSUBUSB, VPSUBUSW, VPTERNLOGD, VPTERNLOGQ,
VPTESTMD, VPTESTMQ, VPTESTNMD, VPTESTNMQ, VPXORD, VPXORQ, VPSLLVD, VPSLLVQ, VRCP14PD,
VRCP14PS, VRCPPH, VRSQRT14PD, VRSQRT14PS, VRSQRTPH, VXORPD, VXORPS
VCOMPRESSPD, VCOMPRESSPS, VEXPANDPD, VEXPANDPS, VMOVDQU8, VMOVDQU16, VMOVDQU32,
VMOVDQU64, VMOVUPD, VMOVUPS, VPABSB, VPABSW, VPADDB, VPADDW, VPADDSB, VPADDSW, VPADDUSB,
VPADDUSW, VPAVGB, VPAVGW, VPCMPB, VPCMPEQB, VPCMPEQW, VPCMPGTB, VPCMPGTW, VPCMPW, VPCMPUB,
E4.nb2
VPCMPUW, VPCOMPRESSD, VPCOMPRESSQ, VPEXPANDD, VPEXPANDQ, VPMAXSB, VPMAXSW, VPMAXUB,
VPMAXUW, VPMINSB, VPMINSW, VPMINUB, VPMINUW, VPMULHRSW, VPMULHUW, VPMULHW, VPMULLW,
VPSLLVW, VPSLLW, VPSRAW, VPSRLVW, VPSRLW, VPSUBB, VPSUBW, VPSUBSB, VPSUBSW, VPTESTMB,
VPTESTMW, VPTESTNMB, VPTESTNMW
VALIGND, VALIGNQ, VPACKSSDW, VPACKUSDW, VPCONFLICTD, VPCONFLICTQ, VPERMD, VPERMI2D, VPERMI2PS,
VPERMI2PD, VPERMI2Q, VPERMPD, VPERMPS, VPERMQ, VPERMT2D, VPERMT2PS, VPERMT2Q, VPERMT2PD,
Type E4NF
VPERMILPD, VPERMILPS, VPMULTISHIFTQB, VPSHUFD, VPUNPCKHDQ, VPUNPCKHQDQ, VPUNPCKLDQ,
VPUNPCKLQDQ, VSHUFF32X4, VSHUFF64X2, VSHUFI32X4, VSHUFI64X2, VSHUFPD, VSHUFPS, VUNPCKHPD,
VUNPCKHPS, VUNPCKLPD, VUNPCKLPS
VDBPSADBW, VPACKSSWB, VPACKUSWB, VPALIGNR, VPMADDWD, VPMADDUBSW, VMOVSHDUP, VMOVSLDUP,
VPSADBW, VPSHUFB, VPSHUFHW, VPSHUFLW, VPSLLDQ, VPSRLDQ, VPSLLW, VPSRAW, VPSRLW, (VPSLLD,
E4NF.nb2
VPSLLQ, VPSRAD, VPSRAQ, VPSRLD, VPSRLQ)3, VPUNPCKHBW, VPUNPCKHWD, VPUNPCKLBW, VPUNPCKLWD,
VPERMW, VPERMI2W, VPERMT2W
PMOVSXBW, PMOVSXBW, PMOVSXBD, PMOVSXBQ, PMOVSXWD, PMOVSXWQ, PMOVSXDQ, PMOVZXBW,
Type E5
PMOVZXBD, PMOVZXBQ, PMOVZXWD, PMOVZXWQ, PMOVZXDQ, VCVTDQ2PD, VCVTUDQ2PD, VMOVSH,
VPMOVSXxx, VPMOVZXxx,
Type E5NF
VMOVDDUP
VBROADCASTF32X2, VBROADCASTF32X4, VBROADCASTF64X2, VBROADCASTF32X8, VBROADCASTF64X4,
VBROADCASTI32X2, VBROADCASTI32X4, VBROADCASTI64X2, VBROADCASTI32X8, VBROADCASTI64X4,
VBROADCASTSD, VBROADCASTSS, VFPCLASSSD, VFPCLASSSS, VPBROADCASTB, VPBROADCASTD,
Type E6
VPBROADCASTW, VPBROADCASTQ, VPMOVQB, VPMOVSQB, VPMOVUSQB, VPMOVQW, VPMOVSQW, VPMOVUSQW,
VPMOVQD, VPMOVSQD, VPMOVUSQD, VPMOVDB, VPMOVSDB, VPMOVUSDB, VPMOVDW, VPMOVSDW,
VPMOVUSDW, VPMOVWB, VPMOVSWB, VPMOVUSWB
VEXTRACTF32X4, VEXTRACTF32X8, VEXTRACTF64X2, VEXTRACTF64X4, VEXTRACTI32X4, VEXTRACTI32X8,
Type E6NF
VEXTRACTI64X2, VEXTRACTI64X4, VINSERTF32X4, VINSERTF32X8, VINSERTF64X2, VINSERTF64X4,
VINSERTI32X4, VINSERTI32X8, VINSERTI64X2, VINSERTI64X4, VPBROADCASTMB2Q, VPBROADCASTMW2D
Type
VMOVHLPS, VMOVLHPS
E7NM.1284
(VPBROADCASTD, VPBROADCASTQ, VPBROADCASTB, VPBROADCASTW)5, VPMOVB2M, VPMOVD2M, VPMOVM2B,
Type E7NM.
VPMOVM2D, VPMOVM2Q, VPMOVM2W, VPMOVQ2M, VPMOVW2M
VEXTRACTPS, VINSERTPS, VMOVHPD, VMOVHPS, VMOVLPD, VMOVLPS, VMOVD, VMOVQ, VMOVW, VPEXTRB,
Type E9NF
VPEXTRD, VPEXTRW, VPEXTRQ, VPINSRB, VPINSRD, VPINSRW, VPINSRQ
VFCMADDCSH, VFMADDCSH, VFCMULCSH, VFMULCSH, VFPCLASSSH, VMOVSD, VMOVSS, VRCP14SD, VRCP14SS,
Type E10
VRCPSH, VRSQRT14SD, VRSQRT14SS, VRSQRTSH
Type E10NF
(VCVTSI2SD, VCVTUSI2SD)6
Type E11
VCVTPH2PS, VCVTPS2PH
Vol. 2A
2-47
INSTRUCTION FORMAT
Table 2-43. EVEX Instructions in Each Exception Class (Contd.)
Exception Class
Instruction
VGATHERDPS, VGATHERDPD, VGATHERQPS, VGATHERQPD, VPGATHERDD, VPGATHERDQ, VPGATHERQD,
Type E12
VPGATHERQQ, VPSCATTERDD, VPSCATTERDQ, VPSCATTERQD, VPSCATTERQQ, VSCATTERDPD, VSCATTERDPS,
VSCATTERQPD, VSCATTERQPS
VGATHERPF0DPD, VGATHERPF0DPS, VGATHERPF0QPD, VGATHERPF0QPS, VGATHERPF1DPD, VGATHERPF1DPS,
Type E12NP
VGATHERPF1QPD, VGATHERPF1QPS, VSCATTERPF0DPD, VSCATTERPF0DPS, VSCATTERPF0QPD,
VSCATTERPF0QPS, VSCATTERPF1DPD, VSCATTERPF1DPS, VSCATTERPF1QPD, VSCATTERPF1QPS
NOTES:
1. Operand encoding Full tupletype with immediate.
2. Embedded broadcast is not supported with the “.nb” suffix.
3. Operand encoding Mem128 tupletype.
4. #UD raised if EVEX.L’L !=00b (VL=128).
5. The source operand is a general purpose register.
6. W0 encoding only.
2-48
Vol. 2A
INSTRUCTION FORMAT
2.8.1
Exceptions Type E1 and E1NF of EVEX-Encoded Instructions
EVEX-encoded instructions with memory alignment restrictions, and supporting memory fault suppression follow
exception class E1.
Table 2-44. Type E1 Class Exception Conditions
Exception
Cause of Exception
X
X
If EVEX prefix present.
If CR4.OSXSAVE[bit 18]=0.
If any one of following conditions applies:
• State requirement, Table 2-37 not met.
• Opcode independent #UD condition in Table 2-38.
X
X
• Operand encoding #UD conditions in Table 2-39.
Invalid Opcode,
• Opmask encoding #UD condition of Table 2-40.
#UD
• EVEX.b encoding #UD condition of Table 2-41.
• Instruction specific EVEX.L'L restriction not met.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a EVEX prefix.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Avail-
X
X
X
X
If CR0.TS[bit 3]=1.
able, #NM
X
If fault suppression not set, and an illegal address in the SS segment.
Stack, #SS(0)
If fault suppression not set, and a memory address referencing the SS segment is in
X
a non-canonical form.
EVEX.512: Memory operand is not 64-byte aligned.
X
X
EVEX.256: Memory operand is not 32-byte aligned.
EVEX.128: Memory operand is not 16-byte aligned.
If fault suppression not set, and an illegal memory operand effective address in the
General Protection,
X
#GP(0)
CS, DS, ES, FS or GS segments.
X
If fault suppression not set, and the memory address is in a non-canonical form.
If fault suppression not set, and any part of the operand lies outside the effective
X
X
address space from 0 to FFFFH.
Page Fault
X
X
X
If fault suppression not set, and a page fault.
#PF(fault-code)
Vol. 2A
2-49
INSTRUCTION FORMAT
EVEX-encoded instructions with memory alignment restrictions, but do not support memory fault suppression
follow exception class E1NF.
Table 2-45. Type E1NF Class Exception Conditions
Exception
Cause of Exception
X
X
If EVEX prefix present.
If CR4.OSXSAVE[bit 18]=0.
If any one of following conditions applies:
• State requirement, Table 2-37 not met.
• Opcode independent #UD condition in Table 2-38.
X
X
• Operand encoding #UD conditions in Table 2-39.
Invalid Opcode,
• Opmask encoding #UD condition of Table 2-40.
#UD
• EVEX.b encoding #UD condition of Table 2-41.
• Instruction specific EVEX.L'L restriction not met.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a EVEX prefix.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Avail-
X
X
X
X
If CR0.TS[bit 3]=1.
able, #NM
X
For an illegal address in the SS segment.
Stack, #SS(0)
X
If a memory address referencing the SS segment is in a non-canonical form.
EVEX.512: Memory operand is not 64-byte aligned.
X
X
EVEX.256: Memory operand is not 32-byte aligned.
EVEX.128: Memory operand is not 16-byte aligned.
General Protection,
For an illegal memory operand effective address in the CS, DS, ES, FS or GS seg-
X
#GP(0)
ments.
X
If the memory address is in a non-canonical form.
X
X
If any part of the operand lies outside the effective address space from 0 to FFFFH.
Page Fault
X
X
X
For a page fault.
#PF(fault-code)
2-50
Vol. 2A
INSTRUCTION FORMAT
2.8.2
Exceptions Type E2 of EVEX-Encoded Instructions
EVEX-encoded vector instructions with arithmetic semantic follow exception class E2.
Table 2-46. Type E2 Class Exception Conditions
Exception
Cause of Exception
X
X
If EVEX prefix present.
X
X
X
X
If an unmasked SIMD floating-point exception and CR4.OSXMMEXCPT[bit 10] = 0.
If CR4.OSXSAVE[bit 18]=0.
If any one of following conditions applies:
• State requirement, Table 2-37 not met.
Invalid Opcode,
X
X
• Opcode independent #UD condition in Table 2-38.
#UD
• Operand encoding #UD conditions in Table 2-39.
• Opmask encoding #UD condition of Table 2-40.
• Instruction specific EVEX.L'L restriction not met.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a EVEX prefix.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Avail-
X
X
X
X
If CR0.TS[bit 3]=1.
able, #NM
X
If fault suppression not set, and an illegal address in the SS segment.
Stack, #SS(0)
If fault suppression not set, and a memory address referencing the SS segment is in a
X
non-canonical form.
If fault suppression not set, and an illegal memory operand effective address in the CS,
X
DS, ES, FS or GS segments.
General Protec-
X
If fault suppression not set, and the memory address is in a non-canonical form.
tion, #GP(0)
If fault suppression not set, and any part of the operand lies outside the effective
X
X
address space from 0 to FFFFH.
Page Fault
X
X
X
If fault suppression not set, and a page fault.
#PF(fault-code)
Alignment Check
For 2, 4, or 8 byte memory access if alignment checking is enabled and an unaligned
X
X
X
#AC(0)
memory access is made while the current privilege level is 3.
SIMD Floating-
If an unmasked SIMD floating-point exception, {sae} or {er} not set, and CR4.OSXMMEX-
point Exception,
X
X
X
X
CPT[bit 10] = 1.
#XM
Vol. 2A
2-51
INSTRUCTION FORMAT
2.8.3
Exceptions Type E3 and E3NF of EVEX-Encoded Instructions
EVEX-encoded scalar instructions with arithmetic semantic that support memory fault suppression follow exception
class E3.
Table 2-47. Type E3 Class Exception Conditions
Exception
Cause of Exception
X
X
If EVEX prefix present.
X
X
X
X
If an unmasked SIMD floating-point exception and CR4.OSXMMEXCPT[bit 10] = 0.
If CR4.OSXSAVE[bit 18]=0.
If any one of following conditions applies:
• State requirement, Table 2-37 not met.
X
X
• Opcode independent #UD condition in Table 2-38.
Invalid Opcode, #UD
• Operand encoding #UD conditions in Table 2-39.
• Opmask encoding #UD condition of Table 2-40.
• EVEX.b encoding #UD condition of Table 2-41.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a EVEX prefix.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Available,
X
X
X
X
If CR0.TS[bit 3]=1.
#NM
X
If fault suppression not set, and an illegal address in the SS segment.
Stack, #SS(0)
If fault suppression not set, and a memory address referencing the SS segment is
X
in a non-canonical form.
If fault suppression not set, and an illegal memory operand effective address in
X
the CS, DS, ES, FS or GS segments.
General Protection,
X
If fault suppression not set, and the memory address is in a non-canonical form.
#GP(0)
If fault suppression not set, and any part of the operand lies outside the effective
X
X
address space from 0 to FFFFH.
Page Fault #PF(fault-
X
X
X
If fault suppression not set, and a page fault.
code)
Alignment Check
For 2, 4, or 8 byte memory access if alignment checking is enabled and an
X
X
X
#AC(0)
unaligned memory access is made while the current privilege level is 3.
SIMD Floating-point
If an unmasked SIMD floating-point exception, {sae} or {er} not set, and CR4.OSX-
X
X
X
X
Exception, #XM
MMEXCPT[bit 10] = 1.
2-52
Vol. 2A
INSTRUCTION FORMAT
EVEX-encoded scalar instructions with arithmetic semantic that do not support memory fault suppression follow
exception class E3NF.
Table 2-48. Type E3NF Class Exception Conditions
Exception
Cause of Exception
X
X
EVEX prefix.
X
X
X
X
If an unmasked SIMD floating-point exception and CR4.OSXMMEXCPT[bit 10] = 0.
If CR4.OSXSAVE[bit 18]=0.
If any one of following conditions applies:
• State requirement, Table 2-37 not met.
X
X
• Opcode independent #UD condition in Table 2-38.
Invalid Opcode, #UD
• Operand encoding #UD conditions in Table 2-39.
• Opmask encoding #UD condition of Table 2-40.
• EVEX.b encoding #UD condition of Table 2-41.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a EVEX prefix.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Available,
X
X
X
X
If CR0.TS[bit 3]=1.
#NM
X
For an illegal address in the SS segment.
Stack, #SS(0)
X
If a memory address referencing the SS segment is in a non-canonical form.
For an illegal memory operand effective address in the CS, DS, ES, FS or GS seg-
X
ments.
General Protection,
X
If the memory address is in a non-canonical form.
#GP(0)
If any part of the operand lies outside the effective address space from 0 to
X
X
FFFFH.
Page Fault #PF(fault-
X
X
X
For a page fault.
code)
Alignment Check
For 2, 4, or 8 byte memory access if alignment checking is enabled and an
X
X
X
#AC(0)
unaligned memory access is made while the current privilege level is 3.
SIMD Floating-point
If an unmasked SIMD floating-point exception, {sae} or {er} not set, and CR4.OSX-
X
X
X
X
Exception, #XM
MMEXCPT[bit 10] = 1.
Vol. 2A
2-53
INSTRUCTION FORMAT
2.8.4
Exceptions Type E4 and E4NF of EVEX-Encoded Instructions
EVEX-encoded vector instructions that cause no SIMD FP exception and support memory fault suppression follow
exception class E4.
Table 2-49. Type E4 Class Exception Conditions
Exception
Cause of Exception
X
X
If EVEX prefix present.
If CR4.OSXSAVE[bit 18]=0.
If any one of following conditions applies:
• State requirement, Table 2-37 not met.
• Opcode independent #UD condition in Table 2-38.
X
X
• Operand encoding #UD conditions in Table 2-39.
• Opmask encoding #UD condition of Table 2-40.
Invalid Opcode, #UD
• EVEX.b encoding #UD condition of Table 2-41 and in E4.nb subclass (see E4.nb
entries in Table 2-43).
• Instruction specific EVEX.L'L restriction not met.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a EVEX prefix.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Available,
X
X
X
X
If CR0.TS[bit 3]=1.
#NM
X
If fault suppression not set, and an illegal address in the SS segment.
Stack, #SS(0)
If fault suppression not set, and a memory address referencing the SS segment is
X
in a non-canonical form.
If fault suppression not set, and an illegal memory operand effective address in
X
the CS, DS, ES, FS or GS segments.
General Protection,
#GP(0)
X
If fault suppression not set, and the memory address is in a non-canonical form.
If fault suppression not set, and any part of the operand lies outside the effective
X
X
address space from 0 to FFFFH.
Page Fault #PF(fault-
X
X
X
If fault suppression not set, and a page fault.
code)
Alignment Check
For 2, 4, or 8 byte memory access if alignment checking is enabled and an
X
X
X
#AC(0)
unaligned memory access is made while the current privilege level is 3.
2-54
Vol. 2A
INSTRUCTION FORMAT
EVEX-encoded vector instructions that do not cause SIMD FP exception nor support memory fault suppression
follow exception class E4NF.
Table 2-50. Type E4NF Class Exception Conditions
Exception
Cause of Exception
X
X
If EVEX prefix present.
If CR4.OSXSAVE[bit 18]=0.
If any one of following conditions applies:
• State requirement, Table 2-37 not met.
• Opcode independent #UD condition in Table 2-38.
X
X
• Operand encoding #UD conditions in Table 2-39.
• Opmask encoding #UD condition of Table 2-40.
Invalid Opcode, #UD
• EVEX.b encoding #UD condition of Table 2-41 and in E4NF.nb subclass (see
E4NF.nb entries in Table 2-43).
• Instruction specific EVEX.L'L restriction not met.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a EVEX prefix.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Available,
X
X
X
X
If CR0.TS[bit 3]=1.
#NM
X
For an illegal address in the SS segment.
Stack, #SS(0)
X
If a memory address referencing the SS segment is in a non-canonical form.
For an illegal memory operand effective address in the CS, DS, ES, FS or GS seg-
X
ments.
General Protection,
#GP(0)
X
If the memory address is in a non-canonical form.
If any part of the operand lies outside the effective address space from 0 to
X
X
FFFFH.
Page Fault #PF(fault-
X
X
X
For a page fault.
code)
Vol. 2A
2-55
INSTRUCTION FORMAT
2.8.5
Exceptions Type E5 and E5NF
EVEX-encoded scalar/partial-vector instructions that cause no SIMD FP exception and support memory fault
suppression follow exception class E5.
Table 2-51. Type E5 Class Exception Conditions
Exception
Cause of Exception
X
X
If EVEX prefix present.
If CR4.OSXSAVE[bit 18]=0.
If any one of following conditions applies:
• State requirement, Table 2-37 not met.
• Opcode independent #UD condition in Table 2-38.
X
X
• Operand encoding #UD conditions in Table 2-39.
Invalid Opcode, #UD
• Opmask encoding #UD condition of Table 2-40.
• EVEX.b encoding #UD condition of Table 2-41.
• Instruction specific EVEX.L'L restriction not met.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a EVEX prefix.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Available,
X
X
X
X
If CR0.TS[bit 3]=1.
#NM
X
If fault suppression not set, and an illegal address in the SS segment.
Stack, #SS(0)
If fault suppression not set, and a memory address referencing the SS segment is
X
in a non-canonical form.
If fault suppression not set, and an illegal memory operand effective address in the
X
CS, DS, ES, FS or GS segments.
General Protection,
X
If fault suppression not set, and the memory address is in a non-canonical form.
#GP(0)
If fault suppression not set, and any part of the operand lies outside the effective
X
X
address space from 0 to FFFFH.
Page Fault #PF(fault-
X
X
X
If fault suppression not set, and a page fault.
code)
Alignment Check
For 2, 4, or 8 byte memory access if alignment checking is enabled and an
X
X
X
#AC(0)
unaligned memory access is made while the current privilege level is 3.
EVEX-encoded scalar/partial vector instructions that do not cause SIMD FP exception nor support memory fault
suppression follow exception class E5NF.
2-56
Vol. 2A
INSTRUCTION FORMAT
Table 2-52. Type E5NF Class Exception Conditions
Exception
Cause of Exception
X
X
If EVEX prefix present.
If CR4.OSXSAVE[bit 18]=0.
If any one of following conditions applies:
• State requirement, Table 2-37 not met.
Opcode independent #UD condition in Table 2-38.
X
X •
• Operand encoding #UD conditions in Table 2-39.
Invalid Opcode, #UD
• Opmask encoding #UD condition of Table 2-40.
• EVEX.b encoding #UD condition of Table 2-41.
• Instruction specific EVEX.L'L restriction not met.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a EVEX prefix.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Available,
X
X
X
X
If CR0.TS[bit 3]=1.
#NM
X
If an illegal address in the SS segment.
Stack, #SS(0)
X
If a memory address referencing the SS segment is in a non-canonical form.
X
If an illegal memory operand effective address in the CS, DS, ES, FS or GS segments.
General Protection,
X
If the memory address is in a non-canonical form.
#GP(0)
If any part of the operand lies outside the effective address space from 0 to
X
X
FFFFH.
Page Fault #PF(fault-
X
X
X
For a page fault.
code)
Alignment Check
For 2, 4, or 8 byte memory access if alignment checking is enabled and an
X
X
X
#AC(0)
unaligned memory access is made while the current privilege level is 3.
Vol. 2A
2-57
INSTRUCTION FORMAT
2.8.6
Exceptions Type E6 and E6NF
Table 2-53. Type E6 Class Exception Conditions
Exception
Cause of Exception
X
X
If EVEX prefix present.
If CR4.OSXSAVE[bit 18]=0.
If any one of following conditions applies:
• State requirement, Table 2-37 not met.
Opcode independent #UD condition in Table 2-38.
X
X •
• Operand encoding #UD conditions in Table 2-39.
Invalid Opcode, #UD
• Opmask encoding #UD condition of Table 2-40.
• EVEX.b encoding #UD condition of Table 2-41.
• Instruction specific EVEX.L'L restriction not met.
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a EVEX prefix.
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Available,
X
X
If CR0.TS[bit 3]=1.
#NM
X
If fault suppression not set, and an illegal address in the SS segment.
Stack, #SS(0)
If fault suppression not set, and a memory address referencing the SS segment is
X
in a non-canonical form.
If fault suppression not set, and an illegal memory operand effective address in the
X
General Protection,
CS, DS, ES, FS or GS segments.
#GP(0)
X
If fault suppression not set, and the memory address is in a non-canonical form.
Page Fault #PF(fault-
X
X
If fault suppression not set, and a page fault.
code)
Alignment Check
For 2, 4, or 8 byte memory access if alignment checking is enabled and an
X
X
#AC(0)
unaligned memory access is made while the current privilege level is 3.
2-58
Vol. 2A
INSTRUCTION FORMAT
EVEX-encoded instructions that do not cause SIMD FP exception nor support memory fault suppression follow
exception class E6NF.
Table 2-54. Type E6NF Class Exception Conditions
Exception
Cause of Exception
Invalid Opcode, #UD
X
X
If EVEX prefix present.
If CR4.OSXSAVE[bit 18]=0.
If any one of following conditions applies:
• State requirement, Table 2-37 not met.
Opcode independent #UD condition in Table 2-38.
X
X •
• Operand encoding #UD conditions in Table 2-39.
• Opmask encoding #UD condition of Table 2-40.
• EVEX.b encoding #UD condition of Table 2-41.
• Instruction specific EVEX.L'L restriction not met.
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a EVEX prefix.
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Available,
X
X
If CR0.TS[bit 3]=1.
#NM
X
For an illegal address in the SS segment.
Stack, #SS(0)
X
If a memory address referencing the SS segment is in a non-canonical form.
For an illegal memory operand effective address in the CS, DS, ES, FS or GS seg-
X
General Protection,
ments.
#GP(0)
X
If the memory address is in a non-canonical form.
Page Fault #PF(fault-
X
X
For a page fault.
code)
Alignment Check
For 2, 4, or 8 byte memory access if alignment checking is enabled and an
X
X
#AC(0)
unaligned memory access is made while the current privilege level is 3.
Vol. 2A
2-59
INSTRUCTION FORMAT
2.8.7
Exceptions Type E7NM
EVEX-encoded instructions that cause no SIMD FP exception and do not reference memory follow exception class
E7NM.
Table 2-55. Type E7NM Class Exception Conditions
Exception
Cause of Exception
X
X
If EVEX prefix present.
If CR4.OSXSAVE[bit 18]=0.
If any one of following conditions applies:
• State requirement, Table 2-37 not met.
Opcode independent #UD condition in Table 2-38.
X
X •
• Operand encoding #UD conditions in Table 2-39.
Invalid Opcode, #UD
• Opmask encoding #UD condition of Table 2-40.
• EVEX.b encoding #UD condition of Table 2-41.
• Instruction specific EVEX.L’L restriction not met.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a EVEX prefix.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Available,
X
X
If CR0.TS[bit 3]=1.
#NM
2-60
Vol. 2A
INSTRUCTION FORMAT
2.8.8
Exceptions Type E9 and E9NF
EVEX-encoded vector or partial-vector instructions that do not cause no SIMD FP exception and support memory
fault suppression follow exception class E9.
Table 2-56. Type E9 Class Exception Conditions
Exception
Cause of Exception
X
X
If EVEX prefix present.
If CR4.OSXSAVE[bit 18]=0.
If any one of following conditions applies:
• State requirement, Table 2-37 not met.
Opcode independent #UD condition in Table 2-38.
X
X •
• Operand encoding #UD conditions in Table 2-39.
Invalid Opcode, #UD
• Opmask encoding #UD condition of Table 2-40.
• EVEX.b encoding #UD condition of Table 2-41.
• Instruction specific EVEX.L'L restriction not met.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a EVEX prefix.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Available,
X
X
X
X
If CR0.TS[bit 3]=1.
#NM
X
If fault suppression not set, and an illegal address in the SS segment.
Stack, #SS(0)
If fault suppression not set, and a memory address referencing the SS segment is
X
in a non-canonical form.
If fault suppression not set, and an illegal memory operand effective address in the
X
CS, DS, ES, FS or GS segments.
General Protection,
X
If fault suppression not set, and the memory address is in a non-canonical form.
#GP(0)
If fault suppression not set, and any part of the operand lies outside the effective
X
X
address space from 0 to FFFFH.
Page Fault #PF(fault-
X
X
X
If fault suppression not set, and a page fault.
code)
Alignment Check
For 2, 4, or 8 byte memory access if alignment checking is enabled and an
X
X
X
#AC(0)
unaligned memory access is made while the current privilege level is 3.
Vol. 2A
2-61
INSTRUCTION FORMAT
EVEX-encoded vector or partial-vector instructions that must be encoded with VEX.L’L = 0, do not cause SIMD FP
exception nor support memory fault suppression follow exception class E9NF.
Table 2-57. Type E9NF Class Exception Conditions
Exception
Cause of Exception
X
X
If EVEX prefix present.
If CR4.OSXSAVE[bit 18]=0.
If any one of following conditions applies:
• State requirement, Table 2-37 not met.
Opcode independent #UD condition in Table 2-38.
X
X •
• Operand encoding #UD conditions in Table 2-39.
Invalid Opcode, #UD
• Opmask encoding #UD condition of Table 2-40.
• EVEX.b encoding #UD condition of Table 2-41.
• Instruction specific EVEX.L'L restriction not met.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a EVEX prefix.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Available,
X
X
X
X
If CR0.TS[bit 3]=1.
#NM
X
If an illegal address in the SS segment.
Stack, #SS(0)
X
If a memory address referencing the SS segment is in a non-canonical form.
X
If an illegal memory operand effective address in the CS, DS, ES, FS or GS segments.
General Protection,
X
If the memory address is in a non-canonical form.
#GP(0)
If any part of the operand lies outside the effective address space from 0 to
X
X
FFFFH.
Page Fault #PF(fault-
X
X
X
For a page fault.
code)
Alignment Check
For 2, 4, or 8 byte memory access if alignment checking is enabled and an
X
X
X
#AC(0)
unaligned memory access is made while the current privilege level is 3.
2-62
Vol. 2A
INSTRUCTION FORMAT
2.8.9
Exceptions Type E10 and E10NF
EVEX-encoded scalar instructions that ignore EVEX.L’L vector length encoding, do not cause a SIMD FP exception,
and support memory fault suppression follow exception class E10.
Table 2-58. Type E10 Class Exception Conditions
Exception
Cause of Exception
X
X
If EVEX prefix present.
If CR4.OSXSAVE[bit 18]=0.
If any one of following conditions applies:
• State requirement, Table 2-37 not met.
X
X
• Opcode independent #UD condition in Table 2-38.
• Operand encoding #UD conditions in Table 2-39.
Invalid Opcode, #UD
• Opmask encoding #UD condition of Table 2-40.
• EVEX.b encoding #UD condition of Table 2-41.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a EVEX prefix.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Available,
X
X
X
X
If CR0.TS[bit 3]=1.
#NM
X
If fault suppression not set, and an illegal address in the SS segment.
Stack, #SS(0)
If fault suppression not set, and a memory address referencing the SS segment is
X
in a non-canonical form.
If fault suppression not set, and an illegal memory operand effective address in the
X
CS, DS, ES, FS or GS segments.
General Protection,
X
If fault suppression not set, and the memory address is in a non-canonical form.
#GP(0)
If fault suppression not set, and any part of the operand lies outside the effective
X
X
address space from 0 to FFFFH.
Page Fault #PF(fault-
X
X
X
If fault suppression not set, and a page fault.
code)
Alignment Check
For 2, 4, or 8 byte memory access if alignment checking is enabled and an
X
X
X
#AC(0)
unaligned memory access is made while the current privilege level is 3.
Vol. 2A
2-63
INSTRUCTION FORMAT
EVEX-encoded scalar instructions that ignore EVEX.L’L vector length encoding, do not cause a SIMD FP exception,
and do not support memory fault suppression follow exception class E10NF.
Table 2-59. Type E10NF Class Exception Conditions
Exception
Cause of Exception
X
X
If EVEX prefix present.
If CR4.OSXSAVE[bit 18]=0.
If any one of following conditions applies:
• State requirement, Table 2-37 not met.
X
X
• Opcode independent #UD condition in Table 2-38.
• Operand encoding #UD conditions in Table 2-39.
Invalid Opcode, #UD
• Opmask encoding #UD condition of Table 2-40.
• EVEX.b encoding #UD condition of Table 2-41.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a EVEX prefix.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Available,
X
X
X
X
If CR0.TS[bit 3]=1.
#NM
X
If fault suppression not set, and an illegal address in the SS segment.
Stack, #SS(0)
If fault suppression not set, and a memory address referencing the SS segment is
X
in a non-canonical form.
If fault suppression not set, and an illegal memory operand effective address in the
X
CS, DS, ES, FS or GS segments.
General Protection,
X
If fault suppression not set, and the memory address is in a non-canonical form.
#GP(0)
If fault suppression not set, and any part of the operand lies outside the effective
X
X
address space from 0 to FFFFH.
Page Fault #PF(fault-
X
X
X
If fault suppression not set, and a page fault.
code)
Alignment Check
For 2, 4, or 8 byte memory access if alignment checking is enabled and an
X
X
X
#AC(0)
unaligned memory access is made while the current privilege level is 3.
2-64
Vol. 2A
INSTRUCTION FORMAT
2.8.10 Exceptions Type E11 (EVEX-only, Mem Arg, No AC, Floating-point Exceptions)
EVEX-encoded instructions that can cause SIMD FP exception, memory operand support fault suppression but do
not cause #AC follow exception class E11.
Table 2-60. Type E11 Class Exception Conditions
Exception
Cause of Exception
Invalid Opcode, #UD
X
X
If EVEX prefix present.
X
X
If CR4.OSXSAVE[bit 18]=0.
If any one of following conditions applies:
• State requirement, Table 2-37 not met.
• Opcode independent #UD condition in Table 2-38.
• Operand encoding #UD conditions in Table 2-39.
• Opmask encoding #UD condition of Table 2-40.
• EVEX.b encoding #UD condition of Table 2-41.
• Instruction specific EVEX.L'L restriction not met.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a EVEX prefix.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
Device Not Available,
X
X
X
X
If CR0.TS[bit 3]=1.
#NM
Stack, #SS(0)
X
If fault suppression not set, and an illegal address in the SS segment.
X
If fault suppression not set, and a memory address referencing the SS segment is
in a non-canonical form.
General Protection,
X
If fault suppression not set, and an illegal memory operand effective address in the
#GP(0)
CS, DS, ES, FS or GS segments.
X
If fault suppression not set, and the memory address is in a non-canonical form.
X
X
If fault suppression not set, and any part of the operand lies outside the effective
address space from 0 to FFFFH.
Page Fault #PF (fault-
X
X
X
If fault suppression not set, and a page fault.
code)
SIMD Floating-Point
X
X
X
X
If an unmasked SIMD floating-point exception, {sae} not set, and CR4.OSXMMEX-
Exception, #XM
CPT[bit 10] = 1.
Vol. 2A
2-65
INSTRUCTION FORMAT
2.8.11 Exceptions Type E12 and E12NP (VSIB Mem Arg, No AC, No Floating-point Exceptions)
Table 2-61. Type E12 Class Exception Conditions
Exception
Cause of Exception
Invalid Opcode, #UD
X
X
If EVEX prefix present.
X
X
If CR4.OSXSAVE[bit 18]=0.
If any one of following conditions applies:
• State requirement, Table 2-37 not met.
• Opcode independent #UD condition in Table 2-38.
• Operand encoding #UD conditions in Table 2-39.
• Opmask encoding #UD condition of Table 2-40.
• EVEX.b encoding #UD condition of Table 2-41.
• Instruction specific EVEX.L'L restriction not met.
• If vvvv != 1111b.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a VEX prefix.
X
X
X
NA
If address size attribute is 16 bit.
X
X
X
X
If ModR/M.mod = ‘11b’.
X
X
X
X
If ModR/M.rm != ‘100b’.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
X
X
X
X
If k0 is used (gather or scatter operation).
X
X
X
X
If index = destination register (gather operation).
Device Not Available,
X
X
X
X
If CR0.TS[bit 3]=1.
#NM
Stack, #SS(0)
X
For an illegal address in the SS segment.
X
If a memory address referencing the SS segment is in a non-canonical form.
General Protection,
X
For an illegal memory operand effective address in the CS, DS, ES, FS or GS seg-
#GP(0)
ments.
X
If the memory address is in a non-canonical form.
X
X
If any part of the operand lies outside the effective address space from 0 to
FFFFH.
Page Fault #PF (fault-
X
X
X
For a page fault.
code)
2-66
Vol. 2A
INSTRUCTION FORMAT
EVEX-encoded prefetch instructions that do not cause #PF follow exception class E12NP.
Table 2-62. Type E12NP Class Exception Conditions
Exception
Cause of Exception
Invalid Opcode, #UD
X
X
If EVEX prefix present.
X
X
If CR4.OSXSAVE[bit 18]=0.
If any one of following conditions applies:
• State requirement, Table 2-37 not met.
• Opcode independent #UD condition in Table 2-38.
• Operand encoding #UD conditions in Table 2-39.
• Opmask encoding #UD condition of Table 2-40.
• EVEX.b encoding #UD condition of Table 2-41.
• Instruction specific EVEX.L'L restriction not met.
X
X
X
X
If preceded by a LOCK prefix (F0H).
X
X
If any REX, F2, F3, or 66 prefixes precede a VEX prefix.
X
X
X
NA
If address size attribute is 16 bit.
X
X
X
X
If ModR/M.mod = ‘11b’.
X
X
X
X
If ModR/M.rm != ‘100b’.
X
X
X
X
If any corresponding CPUID feature flag is ‘0’.
X
X
X
X
If k0 is used (gather or scatter operation).
Device Not Available,
X
X
X
X
If CR0.TS[bit 3]=1.
#NM
Vol. 2A
2-67
INSTRUCTION FORMAT
2.9
EXCEPTION CLASSIFICATIONS OF OPMASK INSTRUCTIONS, TYPE K20 AND
TYPE K21
The exception behavior of VEX-encoded opmask instructions are listed below.
2.9.1
Exceptions Type K20
Exception conditions of Opmask instructions that do not address memory are listed as Type K20.
Table 2-63. TYPE K20 Exception Definition (VEX-Encoded OpMask Instructions w/o Memory Arg)
Exception
Cause of Exception
Invalid Opcode, #UD
X
X
X
X
If relevant CPUID feature flag is ‘0’.
X
X
If a VEX prefix is present.
X
X
If CR4.OSXSAVE[bit 18]=0.
If any one of following conditions applies:
• State requirement, Table 2-37 not met.
• Opcode independent #UD condition in Table 2-38.
• Operand encoding #UD conditions in Table 2-39.
X
X
If any REX, F2, F3, or 66 prefixes precede a VEX prefix.
X
X
If ModRM:[7:6] != 11b.
Device Not Available,
X
X
X
X
If CR0.TS[bit 3]=1.
#NM
2-68
Vol. 2A
INSTRUCTION FORMAT
2.9.2
Exceptions Type K21
Exception conditions of Opmask instructions that address memory are listed as Type K21.
Table 2-64. TYPE K21 Exception Definition (VEX-Encoded OpMask Instructions Addressing Memory)
Exception
Cause of Exception
Invalid Opcode, #UD
X
X
X
X
If relevant CPUID feature flag is ‘0’.
X
X
If a VEX prefix is present.
X
X
If CR4.OSXSAVE[bit 18]=0.
If any one of following conditions applies:
• State requirement, Table 2-37 not met.
• Opcode independent #UD condition in Table 2-38.
• Operand encoding #UD conditions in Table 2-39.
Device Not Available,
X
X
X
X
If CR0.TS[bit 3]=1.
#NM
X
X
If any REX, F2, F3, or 66 prefixes precede a VEX prefix.
Stack, #SS(0)
X
X
X
For an illegal address in the SS segment.
X
If a memory address referencing the SS segment is in a non-canonical form.
General Protection,
X
For an illegal memory operand effective address in the CS, DS, ES, FS or GS seg-
#GP(0)
ments.
If the DS, ES, FS, or GS register is used to access memory and it contains a null
segment selector.
X
If the memory address is in a non-canonical form.
X
X
If any part of the operand lies outside the effective address space from 0 to
FFFFH.
Page Fault #PF(fault-
X
X
X
For a page fault.
code)
Alignment Check
X
X
X
For 2, 4, or 8 byte memory access if alignment checking is enabled and an
#AC(0)
unaligned memory access is made while the current privilege level is 3.
Vol. 2A
2-69
INSTRUCTION FORMAT
2.10
INTEL® AMX INSTRUCTION EXCEPTION CLASSES
Alignment exceptions: The Intel AMX instructions that access memory will never generate #AC exceptions.
Table 2-65. Intel® AMX Exception Classes
Class
Description
• #UD if preceded by LOCK, 66H, F2H, F3H or REX prefixes.
• #UD if CR4.OSXSAVE ≠ 1.
• #UD if XCR0[18:17] ≠ 0b11.
• #UD if IA32_EFER.LMA ≠ 1 OR CS.L ≠ 1.
• #UD if VVVV ≠ 0b1111.
AMX-E1
• #GP based on palette and configuration checks (see pseudocode).
• #GP if the memory address is in a non-canonical form.
• #SS(0) if the memory address referencing the SS segment is in a non-canonical form.
• #PF if a page fault occurs.
• #UD if preceded by LOCK, 66H, F2H, F3H or REX prefixes.
• #UD if CR4.OSXSAVE ≠ 1.
• #UD if XCR0[18:17] ≠ 0b11.
• #UD if IA32_EFER.LMA ≠ 1 OR CS.L ≠ 1.
AMX-E2
• #UD if VVVV ≠ 0b1111.
• #GP if the memory address is in a non-canonical form.
• #SS(0) if the memory address referencing the SS segment is in a non-canonical form.
• #PF if a page fault occurs.
• #UD if preceded by LOCK, 66H, F2H, F3H or REX prefixes.
• #UD if CR4.OSXSAVE ≠ 1.
• #UD if XCR0[18:17] ≠ 0b11.
• #UD if IA32_EFER.LMA ≠ 1 OR CS.L ≠ 1.
• #UD if VVVV ≠ 0b1111.
• #UD if not using SIB addressing.
• #UD if TILES_CONFIGURED == 0.
• #UD if tsrc or tdest are not valid tiles.
AMX-E3
• #UD if tsrc/tdest are ≥ palette_table[tilecfg.palette_id].max_names.
• #UD if tsrc.colbytes mod 4 ≠ 0 OR tdest.colbytes mod 4 ≠ 0.
• #UD if tilecfg.start_row ≥ tsrc.rows OR tilecfg.start_row ≥ tdest.rows.
• #GP if the memory address is in a non-canonical form.
• #SS(0) if the memory address referencing the SS segment is in a non-canonical form.
• #PF if any memory operand causes a page fault.
• #NM if XFD[18] == 1.
2-70
Vol. 2A
INSTRUCTION FORMAT
Table 2-65. Intel® AMX Exception Classes (Contd.)
Class
Description
• #UD if preceded by LOCK, 66H, F2H, F3H or REX prefixes.
• #UD if CR4.OSXSAVE ≠ 1.
• #UD if XCR0[18:17] ≠ 0b11.
• #UD if IA32_EFER.LMA ≠ 1 OR CS.L ≠ 1.
• #UD if srcdest == src1 OR src1 == src2 OR srcdest == src2.
• #UD if TILES_CONFIGURED == 0.
• #UD if srcdest.colbytes mod 4 ≠ 0.
• #UD if src1.colbytes mod 4 ≠ 0.
• #UD if src2.colbytes mod 4 ≠ 0.
AMX-E4
• #UD if srcdest/src1/src2 are not valid tiles.
• #UD if srcdest/src1/src2 are ≥ palette_table[tilecfg.palette_id].max_names.
• #UD if srcdest.colbytes ≠ src2.colbytes.
• #UD if srcdest.rows ≠ src1.rows.
• #UD if src1.colbytes / 4 ≠ src2.rows.
• #UD if srcdest.colbytes > tmul_maxn.
• #UD if src2.colbytes > tmul_maxn.
• #UD if src1.colbytes/4 > tmul_maxk.
• #UD if src2.rows > tmul_maxk.
• #NM if XFD[18] == 1.
• #UD if preceded by LOCK, 66H, F2H, F3H or REX prefixes.
• #UD if CR4.OSXSAVE ≠ 1.
• #UD if XCR0[18:17] ≠ 0b11.
• #UD if IA32_EFER.LMA ≠ 1 OR CS.L ≠ 1.
AMX-E5
• #UD if VVVV ≠ 0b1111.
• #UD if TILES_CONFIGURED == 0.
• #UD if tdest is not a valid tile.
• #UD if tdest is ≥ palette_table[tilecfg.palette_id].max_names.
• #NM if XFD[18] == 1.
• #UD if preceded by LOCK, 66H, F2H, F3H or REX prefixes.
• #UD if CR4.OSXSAVE ≠ 1.
AMX-E6
• #UD if XCR0[18:17] ≠ 0b11.
• #UD if IA32_EFER.LMA ≠ 1 OR CS.L ≠ 1.
• #UD if VVVV ≠ 0b1111.
Vol. 2A
2-71
INSTRUCTION FORMAT
2-72
Vol. 2A
CHAPTER 3
INSTRUCTION SET REFERENCE, A-L
This chapter describes the instruction set for the Intel 64 and IA-32 architectures (A-L) in IA-32e, protected,
virtual-8086, and real-address modes of operation. The set includes general-purpose, x87 FPU, MMX,
SSE/SSE2/SSE3/SSSE3/SSE4, AESNI/PCLMULQDQ, AVX, and system instructions. See also Chapter 4, “Instruc-
tion Set Reference, M-U,” in the Intel® 64 and IA-32 Architectures Software Developer’s Manual, Volume 2B;
Chapter 5, “Instruction Set Reference, V,” in the Intel® 64 and IA-32 Architectures Software Developer’s Manual,
Volume 2C; and Chapter 6, “Instruction Set Reference, W-Z,” in the Intel® 64 and IA-32 Architectures Software
Developer’s Manual, Volume 2D.
For each instruction, each operand combination is described. A description of the instruction and its operand, an
operational description, a description of the effect of the instructions on flags in the EFLAGS register, and a
summary of exceptions that can be generated are also provided.
3.1
INTERPRETING THE INSTRUCTION REFERENCE PAGES
This section describes the format of information contained in the instruction reference pages in this chapter. It
explains notational conventions and abbreviations used in these sections.
3.1.1
Instruction Format
The following is an example of the format used for each instruction description in this chapter. The heading below
introduces the example. The table below provides an example summary table.
CMC-Complement Carry Flag [this is an example]
Opcode
Instruction
Op/En
64/32-bit
CPUID
Description
Mode
Feature Flag
F5
CMC
ZO
V/V
N/A
Complement carry flag.
Instruction Operand Encoding
Op/En
Operand 1
Operand 2
Operand 3
Operand 4
ZO
N/A
N/A
N/A
N/A
Vol. 2A
3-1
INSTRUCTION SET REFERENCE, A-L
3.1.1.1
Opcode Column in the Instruction Summary Table (Instructions without VEX Prefix)
The “Opcode” column in the table above shows the object code produced for each form of the instruction. When
possible, codes are given as hexadecimal bytes in the same order in which they appear in memory. Definitions of
entries other than hexadecimal bytes are as follows:
•
NP - Indicates the use of 66/F2/F3 prefixes (beyond those already part of the instructions opcode) are not
allowed with the instruction. Such use will either cause an invalid-opcode exception (#UD) or result in the
encoding for a different instruction.
•
NFx - Indicates the use of F2/F3 prefixes (beyond those already part of the instructions opcode) are not
allowed with the instruction. Such use will either cause an invalid-opcode exception (#UD) or result in the
encoding for a different instruction.
•
REX.W - Indicates the use of a REX prefix that affects operand size or instruction semantics. The ordering of
the REX prefix and other optional/mandatory instruction prefixes are discussed Chapter 2. Note that REX
prefixes that promote legacy instructions to 64-bit behavior are not listed explicitly in the opcode column.
•
/digit - A digit between 0 and 7 indicates that the ModR/M byte of the instruction uses only the r/m (register
or memory) operand. The reg field contains the digit that provides an extension to the instruction's opcode.
•
/r - Indicates that the ModR/M byte of the instruction contains a register operand and an r/m operand.
•
cb, cw, cd, cp, co, ct - A 1-byte (cb), 2-byte (cw), 4-byte (cd), 6-byte (cp), 8-byte (co) or 10-byte (ct) value
following the opcode. This value is used to specify a code offset and possibly a new value for the code segment
register.
•
ib, iw, id, io - A 1-byte (ib), 2-byte (iw), 4-byte (id) or 8-byte (io) immediate operand to the instruction that
follows the opcode, ModR/M bytes or scale-indexing bytes. The opcode determines if the operand is a signed
value. All words, doublewords, and quadwords are given with the low-order byte first.
•
+rb, +rw, +rd, +ro - Indicated the lower 3 bits of the opcode byte is used to encode the register operand
without a modR/M byte. The instruction lists the corresponding hexadecimal value of the opcode byte with low
3 bits as 000b. In non-64-bit mode, a register code, from 0 through 7, is added to the hexadecimal value of the
opcode byte. In 64-bit mode, indicates the four bit field of REX.b and opcode[2:0] field encodes the register
operand of the instruction. “+ro” is applicable only in 64-bit mode. See Table 3-1 for the codes.
•
+i - A number used in floating-point instructions when one of the operands is ST(i) from the FPU register stack.
The number i (which can range from 0 to 7) is added to the hexadecimal byte given at the left of the plus sign
to form a single opcode byte.
Table 3-1. Register Codes Associated With +rb, +rw, +rd, +ro
byte register
word register
dword register
quadword register
(64-Bit Mode only)
AL
None
0
AX
None
0
EAX
None
0
RAX
None
0
CL
None
1
CX
None
1
ECX
None
1
RCX
None
1
DL
None
2
DX
None
2
EDX
None
2
RDX
None
2
BL
None
3
BX
None
3
EBX
None
3
RBX
None
3
AH
Not
4
SP
None
4
ESP
None
4
N/A
N/A
N/A
encodab
le (N.E.)
CH
N.E.
5
BP
None
5
EBP
None
5
N/A
N/A
N/A
DH
N.E.
6
SI
None
6
ESI
None
6
N/A
N/A
N/A
BH
N.E.
7
DI
None
7
EDI
None
7
N/A
N/A
N/A
SPL
Yes
4
SP
None
4
ESP
None
4
RSP
None
4
BPL
Yes
5
BP
None
5
EBP
None
5
RBP
None
5
3-2
Vol. 2A
INSTRUCTION SET REFERENCE, A-L
Table 3-1. Register Codes Associated With +rb, +rw, +rd, +ro (Contd.)
byte register
word register
dword register
quadword register
(64-Bit Mode only)
SIL
Yes
6
SI
None
6
ESI
None
6
RSI
None
6
DIL
Yes
7
DI
None
7
EDI
None
7
RDI
None
7
Registers R8 - R15 (see below): Available in 64-Bit Mode Only
R8B
Yes
0
R8W
Yes
0
R8D
Yes
0
R8
Yes
0
R9B
Yes
1
R9W
Yes
1
R9D
Yes
1
R9
Yes
1
R10B
Yes
2
R10W
Yes
2
R10D
Yes
2
R10
Yes
2
R11B
Yes
3
R11W
Yes
3
R11D
Yes
3
R11
Yes
3
R12B
Yes
4
R12W
Yes
4
R12D
Yes
4
R12
Yes
4
R13B
Yes
5
R13W
Yes
5
R13D
Yes
5
R13
Yes
5
R14B
Yes
6
R14W
Yes
6
R14D
Yes
6
R14
Yes
6
R15B
Yes
7
R15W
Yes
7
R15D
Yes
7
R15
Yes
7
3.1.1.2
Opcode Column in the Instruction Summary Table (Instructions with VEX prefix)
In the Instruction Summary Table, the Opcode column presents each instruction encoded using the VEX prefix in
following form (including the modR/M byte if applicable, the immediate byte if applicable):
VEX.[128,256].[66,F2,F3].0F/0F3A/0F38.[W0,W1] opcode [/r] [/ib,/is4]
• VEX - Indicates the presence of the VEX prefix is required. The VEX prefix can be encoded using the three-
byte form (the first byte is C4H), or using the two-byte form (the first byte is C5H). The two-byte form of VEX
only applies to those instructions that do not require the following fields to be encoded: VEX.mmmmm, VEX.W,
VEX.X, VEX.B. Refer to Section 2.3 for more detail on the VEX prefix.
The encoding of various sub-fields of the VEX prefix is described using the following notations:
- 128,256: VEX.L field can be 0 (denoted by VEX.128, VEX.L0, or VEX.LZ) or 1 (denoted by VEX.256 or
VEX.L1). The VEX.L field can be encoded using either the 2-byte or 3-byte form of the VEX prefix. The
presence of the notation VEX.256 or VEX.128 in the opcode column should be interpreted as follows:
• If VEX.256 is present in the opcode column: The semantics of the instruction must be encoded with
VEX.L = 1. An attempt to encode this instruction with VEX.L= 0 can result in one of two situations: (a)
if VEX.128 version is defined, the processor will behave according to the defined VEX.128 behavior; (b)
an #UD occurs if there is no VEX.128 version defined.
• If VEX.128 is present in the opcode column but there is no VEX.256 version defined for the same
opcode byte: Two situations apply: (a) For VEX-encoded, 128-bit SIMD integer instructions, software
must encode the instruction with VEX.L = 0. The processor will treat the opcode byte encoded with
VEX.L= 1 by causing an #UD exception; (b) For VEX-encoded, 128-bit packed floating-point instruc-
tions, software must encode the instruction with VEX.L = 0. The processor will treat the opcode byte
encoded with VEX.L= 1 by causing an #UD exception (e.g., VMOVLPS).
• If VEX.L0 or VEX.L1 is present in the opcode column: The specified VEX.L value is required for encoding
this instruction but does not have the connotation of specifying vector length.
• If VEX.LIG is present in the opcode column: The VEX.L value is ignored. This generally applies to VEX-
encoded scalar SIMD floating-point instructions. Scalar SIMD floating-point instruction can be distin-
guished from the mnemonic of the instruction. Generally, the last two letters of the instruction
mnemonic would be either “SS”, “SD”, or “SI” for SIMD floating-point conversion instructions.
• If VEX.LZ is present in the opcode column: The VEX.L must be encoded to be 0B, an #UD occurs if
VEX.L is not zero.
Vol. 2A
3-3
INSTRUCTION SET REFERENCE, A-L
- 66,F2,F3: The presence or absence of these values map to the VEX.pp field encodings. If absent, this
corresponds to VEX.pp=00B. If present, the corresponding VEX.pp value affects the “opcode” byte in the
same way as if a SIMD prefix (66H, F2H or F3H) does to the ensuing opcode byte. Thus a non-zero encoding
of VEX.pp may be considered as an implied 66H/F2H/F3H prefix. The VEX.pp field may be encoded using
either the 2-byte or 3-byte form of the VEX prefix.
- 0F,0F3A,0F38: The presence maps to a valid encoding of the VEX.mmmmm field. Only three encoded
values of VEX.mmmmm are defined as valid, corresponding to the escape byte sequence of 0FH, 0F3AH,
and 0F38H. The effect of a valid VEX.mmmmm encoding on the ensuing opcode byte is same as if the corre-
sponding escape byte sequence on the ensuing opcode byte for non-VEX encoded instructions. Thus a valid
encoding of VEX.mmmmm may be consider as an implies escape byte sequence of either 0FH, 0F3AH or
0F38H. The VEX.mmmmm field must be encoded using the 3-byte form of VEX prefix.
- 0F,0F3A,0F38 and 2-byte/3-byte VEX: The presence of 0F3A and 0F38 in the opcode column implies
that opcode can only be encoded by the three-byte form of VEX. The presence of 0F in the opcode column
does not preclude the opcode to be encoded by the two-byte of VEX if the semantics of the opcode does not
require any subfield of VEX not present in the two-byte form of the VEX prefix.
- W0: VEX.W=0.
- W1: VEX.W=1.
- The presence of W0/W1 in the opcode column applies to two situations: (a) it is treated as an extended
opcode bit, (b) the instruction semantics support an operand size promotion to 64-bit of a general-purpose
register operand or a 32-bit memory operand. The presence of W1 in the opcode column implies the opcode
must be encoded using the 3-byte form of the VEX prefix. The presence of W0 in the opcode column does
not preclude the opcode to be encoded using the C5H form of the VEX prefix, if the semantics of the opcode
does not require other VEX subfields not present in the two-byte form of the VEX prefix. Please see Section
2.3 on the subfield definitions within VEX.
- WIG: can use C5H form (if not requiring VEX.mmmmm) or VEX.W value is ignored in the C4H form of VEX
prefix.
- If WIG is present, the instruction may be encoded using either the two-byte form or the three-byte form of
VEX. When encoding the instruction using the three-byte form of VEX, the value of VEX.W is ignored.
•
opcode - Instruction opcode.
•
/is4 - An 8-bit immediate byte is present containing a source register specifier in either imm8[7:4] (for 64-bit
mode) or imm8[6:4] (for 32-bit mode), and instruction-specific payload in imm8[3:0].
•
In general, the encoding o f VEX.R, VEX.X, VEX.B field are not shown explicitly in the opcode column. The
encoding scheme of VEX.R, VEX.X, VEX.B fields must follow the rules defined in Section 2.3.
EVEX.[128,256,512,LLIG].[66,F2,F3].0F/0F3A/0F38.[W0,W1,WIG] opcode [/r] [ib]
• EVEX - The EVEX prefix is encoded using the four-byte form (the first byte is 62H). Refer to Section 2.7.1 for
more detail on the EVEX prefix.
The encoding of various sub-fields of the EVEX prefix is described using the following notations:
- 128, 256, 512, LLIG: This corresponds to the vector length; three values are allowed by EVEX: 512-bit,
256-bit and 128-bit. Alternatively, vector length is ignored (LIG) for certain instructions; this typically
applies to scalar instructions operating on one data element of a vector register.
- 66,F2,F3: The presence of these value maps to the EVEX.pp field encodings. The corresponding VEX.pp
value affects the “opcode” byte in the same way as if a SIMD prefix (66H, F2H or F3H) does to the ensuing
opcode byte. Thus a non-zero encoding of VEX.pp may be considered as an implied 66H/F2H/F3H prefix.
- 0F,0F3A,0F38: The presence maps to a valid encoding of the EVEX.mmm field. Only three encoded values
of EVEX.mmm are defined as valid, corresponding to the escape byte sequence of 0FH, 0F3AH, and 0F38H.
The effect of a valid EVEX.mmm encoding on the ensuing opcode byte is the same as if the corresponding
escape byte sequence on the ensuing opcode byte for non-EVEX encoded instructions. Thus a valid
encoding of EVEX.mmm may be considered as an implied escape byte sequence of either 0FH, 0F3AH or
0F38H.
- W0: EVEX.W=0.
3-4
Vol. 2A
INSTRUCTION SET REFERENCE, A-L
- W1: EVEX.W=1.
- WIG: EVEX.W bit ignored
• opcode - Instruction opcode.
• In general, the encoding of EVEX.R and R’, EVEX.X and X’, and EVEX.B and B’ fields are not shown explicitly in
the opcode column.
NOTE
Previously, the terms NDS, NDD, and DDS were used in instructions with an EVEX (or VEX) prefix.
These terms indicated that the vvvv field was valid for encoding, and specified register usage.
These terms are no longer necessary and are redundant with the instruction operand encoding
tables provided with each instruction. The instruction operand encoding tables give explicit details
on all operands, indicating where every operand is stored and if they are read or written. If vvvv is
not listed as an operand in the instruction operand encoding table, then EVEX (or VEX) vvvv must
be 0b1111.
3.1.1.3
Instruction Column in the Opcode Summary Table
The “Instruction” column gives the syntax of the instruction statement as it would appear in an ASM386 program.
The following is a list of the symbols used to represent operands in the instruction statements:
•
rel8 - A relative address in the range from 128 bytes before the end of the instruction to 127 bytes after the
end of the instruction.
•
rel16, rel32 - A relative address within the same code segment as the instruction assembled. The rel16
symbol applies to instructions with an operand-size attribute of 16 bits; the rel32 symbol applies to instructions
with an operand-size attribute of 32 bits.
•
ptr16:16, ptr16:32 - A far pointer, typically to a code segment different from that of the instruction. The
notation 16:16 indicates that the value of the pointer has two parts. The value to the left of the colon is a 16-
bit selector or value destined for the code segment register. The value to the right corresponds to the offset
within the destination segment. The ptr16:16 symbol is used when the instruction's operand-size attribute is
16 bits; the ptr16:32 symbol is used when the operand-size attribute is 32 bits.
•
r8 - One of the byte general-purpose registers: AL, CL, DL, BL, AH, CH, DH, BH, BPL, SPL, DIL, and SIL; or
one of the byte registers (R8B - R15B) available when using REX.R and 64-bit mode.
•
r16 - One of the word general-purpose registers: AX, CX, DX, BX, SP, BP, SI, DI; or one of the word registers
(R8-R15) available when using REX.R and 64-bit mode.
•
r32 - One of the doubleword general-purpose registers: EAX, ECX, EDX, EBX, ESP, EBP, ESI, EDI; or one of
the doubleword registers (R8D - R15D) available when using REX.R in 64-bit mode.
•
r64 - One of the quadword general-purpose registers: RAX, RBX, RCX, RDX, RDI, RSI, RBP, RSP, R8-R15.
These are available when using REX.R and 64-bit mode.
•
imm8 - An immediate byte value. The imm8 symbol is a signed number between -128 and +127 inclusive.
For instructions in which imm8 is combined with a word or doubleword operand, the immediate value is sign-
extended to form a word or doubleword. The upper byte of the word is filled with the topmost bit of the
immediate value.
•
imm16 - An immediate word value used for instructions whose operand-size attribute is 16 bits. This is a
number between -32,768 and +32,767 inclusive.
•
imm32 - An immediate doubleword value used for instructions whose operand-size attribute is 32
bits. It allows the use of a number between +2,147,483,647 and -2,147,483,648 inclusive.
•
imm64 - An immediate quadword value used for instructions whose operand-size attribute is 64 bits.
The value allows the use of a number between +9,223,372,036,854,775,807 and -
9,223,372,036,854,775,808 inclusive.
•
r/m8 - A byte operand that is either the contents of a byte general-purpose register (AL, CL, DL, BL, AH, CH,
DH, BH, BPL, SPL, DIL, and SIL) or a byte from memory. Byte registers R8B - R15B are available using REX.R
in 64-bit mode.
Vol. 2A
3-5
INSTRUCTION SET REFERENCE, A-L
•
r/m16 - A word general-purpose register or memory operand used for instructions whose operand-size
attribute is 16 bits. The word general-purpose registers are: AX, CX, DX, BX, SP, BP, SI, DI. The contents of
memory are found at the address provided by the effective address computation. Word registers R8W - R15W
are available using REX.R in 64-bit mode.
•
r/m32 - A doubleword general-purpose register or memory operand used for instructions whose operand-
size attribute is 32 bits. The doubleword general-purpose registers are: EAX, ECX, EDX, EBX, ESP, EBP, ESI,
EDI. The contents of memory are found at the address provided by the effective address computation.
Doubleword registers R8D - R15D are available when using REX.R in 64-bit mode.
•
r/m64 - A quadword general-purpose register or memory operand used for instructions whose operand-size
attribute is 64 bits when using REX.W. Quadword general-purpose registers are: RAX, RBX, RCX, RDX, RDI,
RSI, RBP, RSP, R8-R15; these are available only in 64-bit mode. The contents of memory are found at the
address provided by the effective address computation.
•
reg - A general-purpose register used for instructions when the width of the register does not matter to the
semantics of the operation of the instruction. The register can be r16, r32, or r64.
•
m - A 16-, 32- or 64-bit operand in memory.
•
m8 - A byte operand in memory, usually expressed as a variable or array name, but pointed to by the
DS:(E)SI or ES:(E)DI registers. In 64-bit mode, it is pointed to by the RSI or RDI registers.
•
m16 - A word operand in memory, usually expressed as a variable or array name, but pointed to by the
DS:(E)SI or ES:(E)DI registers. This nomenclature is used only with the string instructions.
•
m32 - A doubleword operand in memory. The contents of memory are found at the address provided by the
effective address computation.
•
m64 - A memory quadword operand in memory.
•
m128 - A memory double quadword operand in memory.
•
m16:16, m16:32 & m16:64 - A memory operand containing a far pointer composed of two numbers. The
number to the left of the colon corresponds to the pointer's segment selector. The number to the right
corresponds to its offset.
•
m16&32, m16&16, m32&32, m16&64 - A memory operand consisting of data item pairs whose sizes are
indicated on the left and the right side of the ampersand. All memory addressing modes are allowed. The
m16&16 and m32&32 operands are used by the BOUND instruction to provide an operand containing an upper
and lower bounds for array indices. The m16&32 operand is used by LIDT and LGDT to provide a word with
which to load the limit field, and a doubleword with which to load the base field of the corresponding GDTR and
IDTR registers. The m16&64 operand is used by LIDT and LGDT in 64-bit mode to provide a word with which to
load the limit field, and a quadword with which to load the base field of the corresponding GDTR and IDTR
registers.
•
m80bcd- A Binary Coded Decimal (BCD) operand in memory, 80 bits.
•
moffs8, moffs16, moffs32, moffs64 - A simple memory variable (memory offset) of type byte, word, or
doubleword used by some variants of the MOV instruction. The actual address is given by a simple offset
relative to the segment base. No ModR/M byte is used in the instruction. The number shown with moffs
indicates its size, which is determined by the address-size attribute of the instruction.
•
Sreg - A segment register. The segment register bit assignments are ES = 0, CS = 1, SS = 2, DS = 3, FS = 4,
and GS = 5.
•
m32fp, m64fp, m80fp - A single precision, double precision, and double extended-precision (respectively)
floating-point operand in memory. These symbols designate floating-point values that are used as operands for
x87 FPU floating-point instructions.
•
m16int, m32int, m64int - A word, doubleword, and quadword integer (respectively) operand in memory.
These symbols designate integers that are used as operands for x87 FPU integer instructions.
•
ST or ST(0) - The top element of the FPU register stack.
•
ST(i) - The ith element from the top of the FPU register stack (i := 0 through 7).
•
mm - An MMX register. The 64-bit MMX registers are: MM0 through MM7.
•
mm/m32 - The low order 32 bits of an MMX register or a 32-bit memory operand. The 64-bit MMX registers
are: MM0 through MM7. The contents of memory are found at the address provided by the effective address
computation.
3-6
Vol. 2A
INSTRUCTION SET REFERENCE, A-L
•
mm/m64 - An MMX register or a 64-bit memory operand. The 64-bit MMX registers are: MM0 through MM7.
The contents of memory are found at the address provided by the effective address computation.
•
xmm - An XMM register. The 128-bit XMM registers are: XMM0 through XMM7; XMM8 through XMM15 are
available using REX.R in 64-bit mode.
•
xmm/m32- An XMM register or a 32-bit memory operand. The 128-bit XMM registers are XMM0 through
XMM7; XMM8 through XMM15 are available using REX.R in 64-bit mode. The contents of memory are found at
the address provided by the effective address computation.
•
xmm/m64 - An XMM register or a 64-bit memory operand. The 128-bit SIMD floating-point registers are
XMM0 through XMM7; XMM8 through XMM15 are available using REX.R in 64-bit mode. The contents of
memory are found at the address provided by the effective address computation.
•
xmm/m128 - An XMM register or a 128-bit memory operand. The 128-bit XMM registers are XMM0 through
XMM7; XMM8 through XMM15 are available using REX.R in 64-bit mode. The contents of memory are found at
the address provided by the effective address computation.
•
<XMM0>- Indicates implied use of the XMM0 register.
When there is ambiguity, xmm1 indicates the first source operand using an XMM register and xmm2 the second
source operand using an XMM register.
Some instructions use the XMM0 register as the third source operand, indicated by <XMM0>. The use of the
third XMM register operand is implicit in the instruction encoding and does not affect the ModR/M encoding.
•
ymm - A YMM register. The 256-bit YMM registers are: YMM0 through YMM7; YMM8 through YMM15 are
available in 64-bit mode.
•
m256 - A 32-byte operand in memory. This nomenclature is used only with AVX instructions.
•
ymm/m256 - A YMM register or 256-bit memory operand.
•
<YMM0>- Indicates use of the YMM0 register as an implicit argument.
•
bnd - A 128-bit bounds register. BND0 through BND3.
•
mib - A memory operand using SIB addressing form, where the index register is not used in address calcu-
lation, Scale is ignored. Only the base and displacement are used in effective address calculation.
•
m512 - A 64-byte operand in memory.
•
zmm/m512 - A ZMM register or 512-bit memory operand.
•
{k1}{z} - A mask register used as instruction writemask. The 64-bit k registers are: k1 through k7.
Writemask specification is available exclusively via EVEX prefix. The masking can either be done as a merging-
masking, where the old values are preserved for masked out elements or as a zeroing masking. The type of
masking is determined by using the EVEX.z bit.
•
{k1} - Without {z}: a mask register used as instruction writemask for instructions that do not allow zeroing-
masking but support merging-masking. This corresponds to instructions that require the value of the aaa field
to be different than 0 (e.g., gather) and store-type instructions which allow only merging-masking.
•
k1 - A mask register used as a regular operand (either destination or source). The 64-bit k registers are: k0
through k7.
•
mV - A vector memory operand; the operand size is dependent on the instruction.
•
vm32{x,y, z} - A vector array of memory operands specified using VSIB memory addressing. The array of
memory addresses are specified using a common base register, a constant scale factor, and a vector index
register with individual elements of 32-bit index value in an XMM register (vm32x), a YMM register (vm32y) or
a ZMM register (vm32z).
•
vm64{x,y, z} - A vector array of memory operands specified using VSIB memory addressing. The array of
memory addresses are specified using a common base register, a constant scale factor, and a vector index
register with individual elements of 64-bit index value in an XMM register (vm64x), a YMM register (vm64y) or
a ZMM register (vm64z).
•
zmm/m512/m32bcst - An operand that can be a ZMM register, a 512-bit memory location or a 512-bit
vector loaded from a 32-bit memory location.
•
zmm/m512/m64bcst - An operand that can be a ZMM register, a 512-bit memory location or a 512-bit
vector loaded from a 64-bit memory location.
Vol. 2A
3-7
INSTRUCTION SET REFERENCE, A-L
• <ZMM0> - Indicates use of the ZMM0 register as an implicit argument.
• {er} - Indicates support for embedded rounding control, which is only applicable to the register-register form
of the instruction. This also implies support for SAE (Suppress All Exceptions).
• {sae} - Indicates support for SAE (Suppress All Exceptions). This is used for instructions that support SAE,
but do not support embedded rounding control.
• SRC1 - Denotes the first source operand in the instruction syntax of an instruction encoded with the
VEX/EVEX prefix and having two or more source operands.
• SRC2 - Denotes the second source operand in the instruction syntax of an instruction encoded with the
VEX/EVEX prefix and having two or more source operands.
• SRC3 - Denotes the third source operand in the instruction syntax of an instruction encoded with the
VEX/EVEX prefix and having three source operands.
• SRC - The source in a single-source instruction.
• DST - The destination in an instruction. This field is encoded by reg_field.
In the instruction encoding, the MODRM byte is represented several ways depending on the role it plays. The
MODRM byte has 3 fields: 2-bit MODRM.MOD field, a 3-bit MODRM.REG field and a 3-bit MODRM.RM field. When all
bits of the MODRM byte have fixed values for an instruction, the 2-hex nibble value of that byte is presented after
the opcode in the encoding boxes on the instruction description pages. When only some fields of the MODRM byte
must contain fixed values, those values are specified as follows:
• If only the MODRM.MOD must be 0b11, and MODRM.REG and MODRM.RM fields are unrestricted, this is
denoted as 11:rrr:bbb. The rrr correspond to the 3-bits of the MODRM.REG field and the bbb correspond to
the 3-bits of the MODMR.RM field.
• If the MODRM.MOD field is constrained to be a value other than 0b11, i.e., it must be one of 0b00, 0b01, or
0b10, then we use the notation !(11).
• If the MODRM.REG field had a specific required value, e.g., 0b101, that would be denoted as mm:101:bbb.
3.1.1.4
Operand Encoding Column in the Instruction Summary Table
The “operand encoding” column is abbreviated as Op/En in the Instruction Summary table heading. Instruction
operand encoding information is provided for each assembly instruction syntax using a letter to cross reference to
a row entry in the operand encoding definition table that follows the instruction summary table. The operand
encoding table in each instruction reference page lists each instruction operand (according to each instruction
syntax and operand ordering shown in the instruction column) relative to the ModRM byte, VEX.vvvv field or addi-
tional operand encoding placement.
EVEX encoded instructions employ compressed disp8*N encoding of the displacement bytes, where N is defined in
Table 2-34 and Table 2-35, according to tupletypes. The tupletype for an instruction is listed in the operand
encoding definition table where applicable.
NOTES
• The letters in the Op/En column of an instruction apply ONLY to the encoding definition table
immediately following the instruction summary table.
• In the encoding definition table, the letter ‘r’ within a pair of parenthesis denotes the content of
the operand will be read by the processor. The letter ‘w’ within a pair of parenthesis denotes the
content of the operand will be updated by the processor.
3.1.1.5
64/32-bit Mode Column in the Instruction Summary Table
The “64/32-bit Mode” column indicates whether the opcode sequence is supported in (a) 64-bit mode or (b) the
Compatibility mode and other IA-32 modes that apply in conjunction with the CPUID feature flag associated specific
instruction extensions.
The 64-bit mode support is to the left of the ‘slash’ and has the following notation:
• V - Supported.
• I - Not supported.
3-8
Vol. 2A
INSTRUCTION SET REFERENCE, A-L
• N.E. - Indicates an instruction syntax is not encodable in 64-bit mode (it may represent part of a sequence of
valid instructions in other modes).
• N.P. - Indicates the REX prefix does not affect the legacy instruction in 64-bit mode.
• N.I. - Indicates the opcode is treated as a new instruction in 64-bit mode.
• N.S. - Indicates an instruction syntax that requires an address override prefix in 64-bit mode and is not
supported. Using an address override prefix in 64-bit mode may result in model-specific execution behavior.
The Compatibility/Legacy Mode support is to the right of the ‘slash’ and has the following notation:
• V - Supported.
• I - Not supported.
• N.E. - Indicates an Intel 64 instruction mnemonics/syntax that is not encodable; the opcode sequence is not
applicable as an individual instruction in compatibility mode or IA-32 mode. The opcode may represent a valid
sequence of legacy IA-32 instructions.
3.1.1.6
CPUID Support Column in the Instruction Summary Table
The fourth column holds abbreviated CPUID feature flags (e.g., appropriate bit in CPUID.1.ECX, CPUID.1.EDX
for SSE/SSE2/SSE3/SSSE3/SSE4.1/SSE4.2/AESNI/PCLMULQDQ/AVX/RDRAND support) that indicate processor
support for the instruction. If the corresponding flag is ‘0’, the instruction will #UD.
3.1.1.7
Description Column in the Instruction Summary Table
The “Description” column briefly explains forms of the instruction.
3.1.1.8
Description Section
Each instruction is then described by number of information sections. The “Description” section describes the
purpose of the instructions and required operands in more detail.
Summary of terms that may be used in the description section:
• Legacy SSE - Refers to SSE, SSE2, SSE3, SSSE3, SSE4, AESNI, PCLMULQDQ, and any future instruction sets
referencing XMM registers and encoded without a VEX prefix.
• VEX.vvvv - The VEX bit field specifying a source or destination register (in 1’s complement form).
• rm_field - shorthand for the ModR/M r/m field and any REX.B
• reg_field - shorthand for the ModR/M reg field and any REX.R
3.1.1.9
Operation Section
The “Operation” section contains an algorithm description (frequently written in pseudo-code) for the instruction.
Algorithms are composed of the following elements:
• Comments are enclosed within the symbol pairs “(*” and “*)”.
• Compound statements are enclosed in keywords, such as: IF, THEN, ELSE, and FI for an if statement; DO and
OD for a do statement; or CASE... OF for a case statement.
• A register name implies the contents of the register. A register name enclosed in brackets implies the contents
of the location whose address is contained in that register. For example, ES:[DI] indicates the contents of the
location whose ES segment relative address is in register DI. [SI] indicates the contents of the address
contained in register SI relative to the SI register’s default segment (DS) or the overridden segment.
• Parentheses around the “E” in a general-purpose register name, such as (E)SI, indicates that the offset is read
from the SI register if the address-size attribute is 16, from the ESI register if the address-size attribute is 32.
Parentheses around the “R” in a general-purpose register name, (R)SI, in the presence of a 64-bit register
definition such as (R)SI, indicates that the offset is read from the 64-bit RSI register if the address-size
attribute is 64.
Vol. 2A
3-9
INSTRUCTION SET REFERENCE, A-L
• Brackets are used for memory operands where they mean that the contents of the memory location is a
segment-relative offset. For example, [SRC] indicates that the content of the source operand is a segment-
relative offset.
• A := B indicates that the value of B is assigned to A.
• The symbols =, ≠, >, <, ≥, and ≤ are relational operators used to compare two values: meaning equal, not
equal, greater or equal, less or equal, respectively. A relational expression such as A = B is TRUE if the value of
A is equal to B; otherwise it is FALSE.
• The expression “« COUNT” and “» COUNT” indicates that the destination operand should be shifted left or right
by the number of bits indicated by the count operand.
The following identifiers are used in the algorithmic descriptions:
•
OperandSize and AddressSize - The OperandSize identifier represents the operand-size attribute of the
instruction, which is 16, 32 or 64-bits. The AddressSize identifier represents the address-size attribute, which
is 16, 32 or 64-bits. For example, the following pseudo-code indicates that the operand-size attribute depends
on the form of the MOV instruction used.
IF Instruction = MOVW
THEN OperandSize := 16;
ELSE
IF Instruction = MOVD
THEN OperandSize := 32;
ELSE
IF Instruction = MOVQ
THEN OperandSize := 64;
FI;
FI;
FI;
See “Operand-Size and Address-Size Attributes” in Chapter 3 of the Intel® 64 and IA-32 Architectures Software
Developer’s Manual, Volume 1, for guidelines on how these attributes are determined.
•
StackAddrSize - Represents the stack address-size attribute associated with the instruction, which has a
value of 16, 32 or 64-bits. See “Address-Size Attribute for Stack” in Chapter 6, “Procedure Calls, Interrupts, and
Exceptions,” of the Intel® 64 and IA-32 Architectures Software Developer’s Manual, Volume 1.
•
SRC - Represents the source operand.
•
DEST - Represents the destination operand.
•
MAXVL - The maximum vector register width pertaining to the instruction. This is not the vector-length
encoding in the instruction's encoding but is instead determined by the current value of XCR0. For details, refer
to the table below. Note that the value of MAXVL is the largest of the features enabled. Future processors may
define new bits in XCR0 whose setting may imply other values for MAXVL.
MAXVL Definition
XCR0 Component
MAXVL
XCR0.SSE
128
XCR0.AVX
256
XCR0.{ZMM_Hi256, Hi16_ZMM, OPMASK}
512
The following functions are used in the algorithmic descriptions:
• ZeroExtend(value) - Returns a value zero-extended to the operand-size attribute of the instruction. For
example, if the operand-size attribute is 32, zero extending a byte value of -10 converts the byte from F6H to
a doubleword value of 000000F6H. If the value passed to the ZeroExtend function and the operand-size
attribute are the same size, ZeroExtend returns the value unaltered.
• SignExtend(value) - Returns a value sign-extended to the operand-size attribute of the instruction. For
example, if the operand-size attribute is 32, sign extending a byte containing the value -10 converts the byte
3-10
Vol. 2A
|
||
|
|
|