Intel 64 and IA-32 Architectures. Software Developer’s Manual (Collection, 2023) - page 110

 

  Index      Manuals     Intel 64 and IA-32 Architectures. Software Developer’s Manual (Collection, 2023)

 

Search            copyright infringement  

 

   

 

   

 

Content      ..     108      109      110      111     ..

 

 

 

Intel 64 and IA-32 Architectures. Software Developer’s Manual (Collection, 2023) - page 110

 

 

OPCODE MAP
Table A-3. Two-byte Opcode Map: 00H — 77H (First Byte is 0FH) *
pfx
0
1
2
3
4
5
6
7
Grp 61A
Grp 71A
LAR
LSL
SYSCALLo64
CLTS
SYSRETo64
0
Gv, Ew
Gv, Ew
vmovups
vmovups
vmovlps
vmovlps
vunpcklps
vunpckhps
vmovhpsv1
vmovhpsv1
Vps, Wps
Wps, Vps
Vq, Hq, Mq
Mq, Vq
Vx, Hx, Wx
Vx, Hx, Wx
Vdq, Hq, Mq
Mq, Vq
vmovhlps
vmovlhps
Vq, Hq, Uq
Vdq, Hq, Uq
1
vmovupd
vmovupd
vmovlpd
vmovlpd
vunpcklpd
vunpckhpd
vmovhpdv1
vmovhpdv1
66
Vpd, Wpd
Wpd,Vpd
Vq, Hq, Mq
Mq, Vq
Vx,Hx,Wx
Vx,Hx,Wx
Vdq, Hq, Mq
Mq, Vq
vmovss
vmovss
vmovsldup
vmovshdup
F3
Vx, Hx, Wss
Wss, Hx, Vss
Vx, Wx
Vx, Wx
vmovsd
vmovsd
vmovddup
F2
Vx, Hx, Wsd
Wsd, Hx, Vsd
Vx, Wx
MOV
MOV
MOV
MOV
Rd, Cd
Rd, Dd
Cd, Rd
Dd, Rd
2
WRMSR
RDTSC
RDMSR
RDPMC
SYSENTER
SYSEXIT
GETSEC
3
CMOVcc, (Gv, Ev) - Conditional Move
4
O
NO
B/C/NAE
AE/NB/NC
E/Z
NE/NZ
BE/NA
A/NBE
vmovmskps
vsqrtps
vrsqrtps
vrcpps
vandps
vandnps
vorps
vxorps
Gy, Ups
Vps, Wps
Vps, Wps
Vps, Wps
Vps, Hps, Wps
Vps, Hps, Wps
Vps, Hps, Wps
Vps, Hps, Wps
vmovmskpd
vsqrtpd
vandpd
vandnpd
vorpd
vxorpd
66
5
Gy,Upd
Vpd, Wpd
Vpd, Hpd, Wpd
Vpd, Hpd, Wpd
Vpd, Hpd, Wpd
Vpd, Hpd, Wpd
vsqrtss
vrsqrtss
vrcpss
F3
Vss, Hss, Wss
Vss, Hss, Wss
Vss, Hss, Wss
vsqrtsd
F2
Vsd, Hsd, Wsd
punpcklbw
punpcklwd
punpckldq
packsswb
pcmpgtb
pcmpgtw
pcmpgtd
packuswb
Pq, Qd
Pq, Qd
Pq, Qd
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
6
vpunpcklbw
vpunpcklwd
vpunpckldq
vpacksswb
vpcmpgtb
vpcmpgtw
vpcmpgtd
vpackuswb
66
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
F3
pshufw
(Grp 121A)
(Grp 131A)
(Grp 141A)
pcmpeqb
pcmpeqw
pcmpeqd
emms
Pq, Qq, Ib
Pq, Qq
Pq, Qq
Pq, Qq
vzeroupperv
vzeroallv
vpshufd
vpcmpeqb
vpcmpeqw
vpcmpeqd
7
66
Vx, Wx, Ib
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
vpshufhw
F3
Vx, Wx, Ib
vpshuflw
F2
Vx, Wx, Ib
Vol. 2D A-9
OPCODE MAP
Table A-3. Two-byte Opcode Map: 08H — 7FH (First Byte is 0FH) *
pfx
8
9
A
B
C
D
E
F
INVD
WBINVD
2-byte Illegal
prefetchw(/1)
0
Opcodes
Ev
UD21B
Prefetch1C
Reserved-NOP
bndldx
bndstx
Reserved-NOP
NOP /0 Ev
(Grp 161A)
66
bndmov
bndmov
1
F3
bndcl
bndmk
bndcu
bndcn
F2
vmovaps
vmovaps
cvtpi2ps
vmovntps
cvttps2pi
cvtps2pi
vucomiss
vcomiss
Vps, Wps
Wps, Vps
Vps, Qpi
Mps, Vps
Ppi, Wps
Ppi, Wps
Vss, Wss
Vss, Wss
vmovapd
vmovapd
cvtpi2pd
vmovntpd
cvttpd2pi
cvtpd2pi
vucomisd
vcomisd
66
Vpd, Wpd
Wpd,Vpd
Vpd, Qpi
Mpd, Vpd
Ppi, Wpd
Qpi, Wpd
Vsd, Wsd
Vsd, Wsd
2
vcvtsi2ss
vcvttss2si
vcvtss2si
F3
Vss, Hss, Ey
Gy, Wss
Gy, Wss
vcvtsi2sd
vcvttsd2si
vcvtsd2si
F2
Vsd, Hsd, Ey
Gy, Wsd
Gy, Wsd
3-byte escape
3-byte escape
3
(Table A-4)
(Table A-5)
CMOVcc(Gv, Ev) - Conditional Move
S
NS
P/PE
NP/PO
L/NGE
NL/GE
LE/NG
NLE/G
4
vaddps
vmulps
vcvtps2pd
vcvtdq2ps
vsubps
vminps
vdivps
vmaxps
Vps, Hps, Wps
Vps, Hps, Wps
Vpd, Wps
Vps, Wdq
Vps, Hps, Wps
Vps, Hps, Wps
Vps, Hps, Wps
Vps, Hps, Wps
vaddpd
vmulpd
vcvtpd2ps
vcvtps2dq
vsubpd
vminpd
vdivpd
vmaxpd
66
Vpd, Hpd, Wpd
Vpd, Hpd, Wpd
Vps, Wpd
Vdq, Wps
Vpd, Hpd, Wpd
Vpd, Hpd, Wpd
Vpd, Hpd, Wpd
Vpd, Hpd, Wpd
5
vaddss
vmulss
vcvtss2sd
vcvttps2dq
vsubss
vminss
vdivss
vmaxss
F3
Vss, Hss, Wss
Vss, Hss, Wss
Vsd, Hx, Wss
Vdq, Wps
Vss, Hss, Wss
Vss, Hss, Wss
Vss, Hss, Wss
Vss, Hss, Wss
vaddsd
vmulsd
vcvtsd2ss
vsubsd
vminsd
vdivsd
vmaxsd
F2
Vsd, Hsd, Wsd
Vsd, Hsd, Wsd
Vss, Hx, Wsd
Vsd, Hsd, Wsd
Vsd, Hsd, Wsd
Vsd, Hsd, Wsd
Vsd, Hsd, Wsd
punpckhbw
punpckhwd
punpckhdq
packssdw
movd/q
movq
Pq, Qd
Pq, Qd
Pq, Qd
Pq, Qd
Pd, Ey
Pq, Qq
vpunpckhbw
vpunpckhwd
vpunpckhdq
vpackssdw
vpunpcklqdq
vpunpckhqdq
vmovd/q
vmovdqa
6
66
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vy, Ey
Vx, Wx
vmovdqu
F3
Vx, Wx
VMREAD
VMWRITE
movd/q
movq
Ey, Gy
Gy, Ey
Ey, Pd
Qq, Pq
vhaddpd
vhsubpd
vmovd/q
vmovdqa
66
Vpd, Hpd, Wpd
Vpd, Hpd, Wpd
Ey, Vy
Wx,Vx
7
vmovq
vmovdqu
F3
Vq, Wq
Wx,Vx
vhaddps
vhsubps
Vps, Hps, Wps
Vps, Hps, Wps
F2
A-10
Vol. 2D
OPCODE MAP
Table A-3. Two-byte Opcode Map: 80H — F7H (First Byte is 0FH) *
pfx
0
1
2
3
4
5
6
7
Jccf64, Jz - Long-displacement jump on condition
8
O
NO
B/CNAE
AE/NB/NC
E/Z
NE/NZ
BE/NA
A/NBE
SETcc, Eb - Byte Set on condition
9
O
NO
B/C/NAE
AE/NB/NC
E/Z
NE/NZ
BE/NA
A/NBE
PUSHd64
POPd64
CPUID
BT
SHLD
SHLD
A
FS
FS
Ev, Gv
Ev, Gv, Ib
Ev, Gv, CL
CMPXCHG
LSS
BTR
LFS
LGS
MOVZX
B
Gv, Mp
Ev, Gv
Gv, Mp
Gv, Mp
Eb, Gb
Ev, Gv
Gv, Eb
Gv, Ew
XADD
XADD
vcmpps
movnti
pinsrw
pextrw
vshufps
Grp 91A
Eb, Gb
Ev, Gv
Vps,Hps,Wps,Ib
My, Gy
Pq,Ry/Mw,Ib
Gd, Nq, Ib
Vps,Hps,Wps,Ib
vcmppd
vpinsrw
vpextrw
vshufpd
66
Vpd,Hpd,Wpd,Ib
Vdq,Hdq,Ry/Mw,Ib
Gd, Udq, Ib
Vpd,Hpd,Wpd,Ib
C
vcmpss
F3
Vss,Hss,Wss,Ib
vcmpsd
F2
Vsd,Hsd,Wsd,Ib
psrlw
psrld
psrlq
paddq
pmullw
pmovmskb
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
Gd, Nq
vaddsubpd
vpsrlw
vpsrld
vpsrlq
vpaddq
vpmullw
vmovq
vpmovmskb
66
Vpd, Hpd, Wpd
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Wq, Vq
Gd, Ux
D
movq2dq
F3
Vdq, Nq
vaddsubps
movdq2q
F2
Vps, Hps, Wps
Pq, Uq
pavgb
psraw
psrad
pavgw
pmulhuw
pmulhw
movntq
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
Mq, Pq
vpavgb
vpsraw
vpsrad
vpavgw
vpmulhuw
vpmulhw
vcvttpd2dq
vmovntdq
66
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Wpd
Mx, Vx
E
vcvtdq2pd
F3
Vx, Wpd
vcvtpd2dq
F2
Vx, Wpd
psllw
pslld
psllq
pmuludq
pmaddwd
psadbw
maskmovq
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Nq
vpsllw
vpslld
vpsllq
vpmuludq
vpmaddwd
vpsadbw
vmaskmovdqu
F
66
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vdq, Udq
vlddqu
F2
Vx, Mx
Vol. 2D A-11
OPCODE MAP
Table A-3. Two-byte Opcode Map: 88H — FFH (First Byte is 0FH) *
pfx
8
9
A
B
C
D
E
F
Jccf64, Jz - Long-displacement jump on condition
8
S
NS
P/PE
NP/PO
L/NGE
NL/GE
LE/NG
NLE/G
SETcc, Eb - Byte Set on condition
9
S
NS
P/PE
NP/PO
L/NGE
NL/GE
LE/NG
NLE/G
d64
PUSH
POPd64
RSM
BTS
SHRD
SHRD
(Grp 151A)1C
IMUL
A
GS
GS
Ev, Gv
Ev, Gv, Ib
Ev, Gv, CL
Gv, Ev
JMPE
Grp 101A
Grp 81A
BTC
BSF
BSR
MOVSX
(reserved for
Invalid Opcode1B
Ev, Ib
Ev, Gv
Gv, Ev
Gv, Ev
Gv, Eb
Gv, Ew
B
emulator on IPF)
POPCNT
TZCNT
LZCNT
F3
Gv, Ev
Gv, Ev
Gv, Ev
BSWAP
RAX/EAX/
RCX/ECX/
RDX/EDX/
RBX/EBX/
RSP/ESP/
RBP/EBP/
RSI/ESI/
RDI/EDI/
R8/R8D
R9/R9D
R10/R10D
R11/R11D
R12/R12D
R13/R13D
R14/R14D
R15/R15D
C
psubusb
psubusw
pminub
pand
paddusb
paddusw
pmaxub
pandn
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
vpsubusb
vpsubusw
vpminub
vpand
vpaddusb
vpaddusw
vpmaxub
vpandn
66
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
D
F3
F2
psubsb
psubsw
pminsw
por
paddsb
paddsw
pmaxsw
pxor
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
vpsubsb
vpsubsw
vpminsw
vpor
vpaddsb
vpaddsw
vpmaxsw
vpxor
66
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
E
F3
F2
psubb
psubw
psubd
psubq
paddb
paddw
paddd
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
UD0
vpsubb
vpsubw
vpsubd
vpsubq
vpaddb
vpaddw
vpaddd
F
66
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
F2
NOTES:
* All blanks in all opcode maps are reserved and must not be used. Do not depend on the operation of undefined or reserved locations.
A-12
Vol. 2D
OPCODE MAP
Table A-4. Three-byte Opcode Map: 00H — F7H (First Two Bytes are 0F 38H) *
pfx
0
1
2
3
4
5
6
7
pshufb
phaddw
phaddd
phaddsw
pmaddubsw
phsubw
phsubd
phsubsw
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
0
vpshufb
vphaddw
vphaddd
vphaddsw
vpmaddubsw
vphsubw
vphsubd
vphsubsw
66
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
pblendvb
vcvtph2psv
blendvps
blendvpd
vpermpsv
vptest
Vdq, Wdq
Vx, Wx, Ib
Vdq, Wdq
Vdq, Wdq
Vqq, Hqq, Wqq
Vx, Wx
1
66
vpmovsxbw
vpmovsxbd
vpmovsxbq
vpmovsxwd
vpmovsxwq
vpmovsxdq
2
66
Vx, Ux/Mq
Vx, Ux/Md
Vx, Ux/Mw
Vx, Ux/Mq
Vx, Ux/Md
Vx, Ux/Mq
vpmovzxbw
vpmovzxbd
vpmovzxbq
vpmovzxwd
vpmovzxwq
vpmovzxdq
vpermd
v
vpcmpgtq
3
66
Vx, Ux/Mq
Vx, Ux/Md
Vx, Ux/Mw
Vx, Ux/Mq
Vx, Ux/Md
Vx, Ux/Mq
Vqq, Hqq, Wqq
Vx, Hx, Wx
v
vpmulld
vphminposuw
vpsrlvd/q
vpsravdv
vpsllvd/qv
4
66
Vx, Hx, Wx
Vdq, Wdq
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
5
6
7
INVEPT
INVVPID
INVPCID
Gy, Mdq
Gy, Mdq
Gy, Mdq
8
66
vgatherdd/qv
vgatherqd/qv
vgatherdps/dv
vgatherqps/dv
vfmaddsub132ps/dv
vfmsubadd132ps/dv
9
66
Vx,Hx,Wx
Vx,Hx,Wx
Vx,Hx,Wx
Vx,Hx,Wx
Vx,Hx,Wx
Vx,Hx,Wx
vfmaddsub213ps/dv
vfmsubadd213ps/dv
A
66
Vx,Hx,Wx
Vx,Hx,Wx
vfmaddsub231ps/dv
vfmsubadd231ps/dv
B
66
Vx,Hx,Wx
Vx,Hx,Wx
C
D
E
MOVBE
MOVBE
ANDNv
BZHIv
BEXTRv
Gy, My
My, Gy
Gy, By, Ey
Gy, Ey, By
Gy, Ey, By
v
MOVBE
MOVBE
ADCX
SHLX
66
Gw, Mw
Mw, Gw
Gy, Ey
Gy, Ey, By
PEXT
v
ADOX
SARXv
F
F3
Grp 171A
Gy, By, Ey
Gy, Ey
Gy, Ey, By
v
CRC32
CRC32
PDEP
MULXv
SHRXv
F2
Gd, Eb
Gd, Ey
Gy, By, Ey
By,Gy,rDX,Ey
Gy, Ey, By
66 &
CRC32
CRC32
F2
Gd, Eb
Gd, Ew
Vol. 2D A-13
OPCODE MAP
Table A-4. Three-byte Opcode Map: 08H — FFH (First Two Bytes are 0F 38H) *
pfx
8
9
A
B
C
D
E
F
psignb
psignw
psignd
pmulhrsw
Pq, Qq
Pq, Qq
Pq, Qq
Pq, Qq
0
vpsignb
vpsignw
vpsignd
vpmulhrsw
vpermilpsv
vpermilpdv
vtestpsv
vtestpdv
66
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx,Hx,Wx
Vx,Hx,Wx
Vx, Wx
Vx, Wx
pabsb
pabsw
pabsd
1
Pq, Qq
Pq, Qq
Pq, Qq
vbroadcastssv
vbroadcastsdv Vqq,
vbroadcastf128v Vqq,
vpabsb
vpabsw
vpabsd
66
Vx, Wd
Wq
Mdq
Vx, Wx
Vx, Wx
Vx, Wx
vpmuldq
vpcmpeqq
vmovntdqa
vpackusdw
vmaskmovpsv
vmaskmovpdv
vmaskmovpsv
vmaskmovpdv
2
66
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Mx
Vx, Hx, Wx
Vx,Hx,Mx
Vx,Hx,Mx
Mx,Hx,Vx
Mx,Hx,Vx
vpminsb
vpminsd
vpminuw
vpminud
vpmaxsb
vpmaxsd
vpmaxuw
vpmaxud
3
66
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
4
vpbroadcastdv
vpbroadcastqv
vbroadcasti128v
5
66
Vx, Wx
Vx, Wx
Vqq, Mdq
6
vpbroadcastbv
vpbroadcastwv
7
66
Vx, Wx
Vx, Wx
vpmaskmovd/qv
vpmaskmovd/qv
8
66
Vx,Hx,Mx
Mx,Vx,Hx
vfmadd132ps/dv
vfmadd132ss/dv
vfmsub132ps/dv
vfmsub132ss/dv
vfnmadd132ps/dv
vfnmadd132ss/dv
vfnmsub132ps/dv
vfnmsub132ss/dv
9
66
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
vfmadd213ps/dv
vfmadd213ss/dv
vfmsub213ps/dv
vfmsub213ss/dv
vfnmadd213ps/dv
vfnmadd213ss/dv
vfnmsub213ps/dv
vfnmsub213ss/dv
A
66
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
vfmadd231ps/dv
vfmadd231ss/dv
vfmsub231ps/dv
vfmsub231ss/dv
vfnmadd231ps/dv
vfnmadd231ss/dv
vfnmsub231ps/dv
vfnmsub231ss/dv
B
66
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
Vx, Hx, Wx
sha1nexte
sha1msg1
sha1msg2
sha256rnds2
sha256msg1
sha256msg2
C
Vdq,Wdq
Vdq,Wdq
Vdq,Wdq
Vdq,Wdq
Vdq,Wdq
Vdq,Wdq
66
VAESIMC
VAESENC
VAESENCLAST
VAESDEC
VAESDECLAST
D
66
Vdq, Wdq
Vdq,Hdq,Wdq
Vdq,Hdq,Wdq
Vdq,Hdq,Wdq
Vdq,Hdq,Wdq
E
66
F
F3
F2
66 & F2
NOTES:
* All blanks in all opcode maps are reserved and must not be used. Do not depend on the operation of undefined or reserved locations.
A-14
Vol. 2D
OPCODE MAP
Table A-5. Three-byte Opcode Map: 00H — F7H (First two bytes are 0F 3AH) *
pfx
0
1
2
3
4
5
6
7
vpermqv
vpermpdv
vpblenddv
vpermilpsv
vpermilpdv
vperm2f128v
Vqq, Wqq, Ib
Vqq, Wqq, Ib
Vx,Hx,Wx,Ib
Vx, Wx, Ib
Vx, Wx, Ib
Vqq,Hqq,Wqq,Ib
0
66
vpextrb
vpextrw
vpextrd/q
vextractps
1
66
Rd/Mb, Vdq, Ib
Rd/Mw, Vdq, Ib
Ey, Vdq, Ib
Ed, Vdq, Ib
vpinsrb
vinsertps
vpinsrd/q
2
66
Vdq,Hdq,Ry/Mb,Ib
Vdq,Hdq,Udq/Md,Ib
Vdq,Hdq,Ey,Ib
3
v
vdpps
vdppd
vmpsadbw
vpclmulqdq
vperm2i128
4
66
Vx,Hx,Wx,Ib
Vdq,Hdq,Wdq,Ib
Vx,Hx,Wx,Ib
Vdq,Hdq,Wdq,Ib
Vqq,Hqq,Wqq,Ib
5
vpcmpestrm
vpcmpestri
vpcmpistrm
vpcmpistri
6
66
Vdq, Wdq, Ib
Vdq, Wdq, Ib
Vdq, Wdq, Ib
Vdq, Wdq, Ib
7
8
9
A
B
C
D
E
F
RORXv
F2
Gy, Ey, Ib
Vol. 2D A-15
OPCODE MAP
Table A-5. Three-byte Opcode Map: 08H — FFH (First Two Bytes are 0F 3AH) *
pfx
8
9
A
B
C
D
E
F
palignr
0
Pq, Qq, Ib
vroundps
vroundpd
vroundss
vroundsd
vblendps
vblendpd
vpblendw
vpalignr
66
Vx,Wx,Ib
Vx,Wx,Ib
Vss,Wss,Ib
Vsd,Wsd,Ib
Vx,Hx,Wx,Ib
Vx,Hx,Wx,Ib
Vx,Hx,Wx,Ib
Vx,Hx,Wx,Ib
vinsertf128v
vextractf128v
vcvtps2phv
1
66
Vqq,Hqq,Wqq,Ib
Wdq,Vqq,Ib
Wx, Vx, Ib
2
vinserti128v
vextracti128v
3
66
Vqq,Hqq,Wqq,Ib
Wdq,Vqq,Ib
v
vblendvps
vblendvpdv
vpblendvbv
4
66
Vx,Hx,Wx,Lx
Vx,Hx,Wx,Lx
Vx,Hx,Wx,Lx
5
6
7
8
9
A
B
sha1rnds4
C
Vdq,Wdq,Ib
VAESKEYGEN
D
66
Vdq, Wdq, Ib
E
F
NOTES:
* All blanks in all opcode maps are reserved and must not be used. Do not depend on the operation of undefined or reserved locations.
A-16
Vol. 2D
OPCODE MAP
A.4
OPCODE EXTENSIONS FOR ONE-BYTE AND TWO-BYTE OPCODES
Some 1-byte and 2-byte opcodes use bits 3-5 of the ModR/M byte (the nnn field in Figure A-1) as an extension of
the opcode.
mod
nnn
R/M
Figure A-1. ModR/M Byte nnn Field (Bits 5, 4, and 3)
Opcodes that have opcode extensions are indicated in Table A-6 and organized by group number. Group numbers
(from 1 to 16, second column) provide a table entry point. The encoding for the r/m field for each instruction can
be established using the third column of the table.
A.4.1
Opcode Look-up Examples Using Opcode Extensions
An Example is provided below.
Example A-4. Interpreting an ADD Instruction
An ADD instruction with a 1-byte opcode of 80H is a Group 1 instruction:
Table A-6 indicates that the opcode extension field encoded in the ModR/M byte for this instruction is 000B.
The r/m field can be encoded to access a register (11B) or a memory address using a specified addressing
mode (for example: mem = 00B, 01B, 10B).
Example A-5. Looking Up 0F01C3H
Look up opcode 0F01C3 for a VMRESUME instruction by using Table A-2, Table A-3, and Table A-6:
0F indicates that this instruction is in the 2-byte opcode map.
01 (row 0, column 1 in Table A-3) reveals that this opcode is in Group 7 of Table A-6.
C3 is the ModR/M byte. The first two bits of C3 are 11B. This tells us to look at the second of the Group 7 rows
in Table A-6.
The Op/Reg bits [5,4,3] are 000B. This tells us to look in the 000 column for Group 7.
Finally, the R/M bits [2,1,0] are 011B. This identifies the opcode as the VMRESUME instruction.
A.4.2
Opcode Extension Tables
See Table A-6 below.
Vol. 2D A-17
OPCODE MAP
Table A-6. Opcode Extensions for One- and Two-byte Opcodes by Group Number *
Encoding of Bits 5,4,3 of the ModR/M Byte (bits 2,1,0 in parenthesis)
Opcode
Group
Mod 7,6
pfx
000
001
010
011
100
101
110
111
80-83
1
mem, 11B
ADD
OR
ADC
SBB
AND
SUB
XOR
CMP
8F
1A
mem, 11B
POP
C0,C1 reg, imm
mem, 11B
ROL
ROR
RCL
RCR
SHL/SAL
SHR
SAR
D0, D1 reg, 1
2
D2, D3 reg, CL
mem, 11B
TEST
NOT
NEG
MUL
IMUL
DIV
IDIV
F6, F7
3
Ib/Iz
AL/rAX
AL/rAX
AL/rAX
AL/rAX
mem, 11B
INC
DEC
FE
4
Eb
Eb
mem, 11B
INC
DEC
near CALL
f64
far CALL
near JMPf64
far JMP
PUSHd64
FF
5
Ev
Ev
Ev
Ep
Ev
Mp
Ev
mem, 11B
SLDT
STR
LLDT
LTR
VERR
VERW
0F 00
6
Rv/Mw
Rv/Mw
Ew
Ew
Ew
Ew
mem
SGDT
SIDT
LGDT
LIDT
SMSW
LMSW
INVLPG
Ms
Ms
Ms
Ms
Mw/Rv
Ew
Mb
11B
VMCALL (001)
MONITOR
XGETBV (000)
SWAPGS
VMLAUNCH
(000)
XSETBV (001)
o64(000)
0F 01
7
(010)
MWAIT (001)
RDTSCP (001)
VMFUNC
VMRESUME
CLAC (010)
(100)
(011) VMXOFF
STAC (011)
XEND (101)
(100)
ENCLS (111)
XTEST (110)
ENCLU(111)
0F BA
8
mem, 11B
BT
BTS
BTR
BTC
CMPXCH8B Mq
VMPTRLD
VMPTRST
CMPXCHG16B
Mq
Mq
Mdq
mem
66
VMCLEAR
Mq
0F C7
9
F3
VMXON
Mq
RDRAND
RDSEED
Rv
Rv
11B
F3
RDPID
Rd/q
mem
UD1
0F B9
10
11B
mem
MOV
C6
Eb, Ib
11B
XABORT (000) Ib
11
mem
MOV
C7
Ev, Iz
11B
XBEGIN (000) Jz
mem
psrlw
psraw
psllw
0F 71
12
Nq, Ib
Nq, Ib
Nq, Ib
11B
66
vpsrlw
vpsraw
vpsllw
Hx,Ux,Ib
Hx,Ux,Ib
Hx,Ux,Ib
mem
psrld
psrad
pslld
0F 72
13
Nq, Ib
Nq, Ib
Nq, Ib
11B
66
vpsrld
vpsrad
vpslld
Hx,Ux,Ib
Hx,Ux,Ib
Hx,Ux,Ib
mem
psrlq
psllq
0F 73
14
Nq, Ib
Nq, Ib
11B
66
vpsrlq
vpsrldq
vpsllq
vpslldq
Hx,Ux,Ib
Hx,Ux,Ib
Hx,Ux,Ib
Hx,Ux,Ib
A-18
Vol. 2D
OPCODE MAP
Table A-6. Opcode Extensions for One- and Two-byte Opcodes by Group Number * (Contd.)
Encoding of Bits 5,4,3 of the ModR/M Byte (bits 2,1,0 in parenthesis)
Opcode
Group
Mod 7,6
pfx
000
001
010
011
100
101
110
111
mem
fxsave
fxrstor
ldmxcsr
stmxcsr
XSAVE
XRSTOR
XSAVEOPT
clflush
lfence
mfence
sfence
0F AE
15
F3
RDFSBASE
RDGSBASE
WRFSBASE
WRGSBASE
11B
Ry
Ry
Ry
Ry
prefetch
prefetch
prefetch
prefetch
Reserved NOP
mem
NTA
T0
T1
T2
0F 18
16
11B
Reserved NOP
mem
BLSRv
BLSMSKv
BLSIv
VEX.0F38 F3
17
By, Ey
By, Ey
By, Ey
11B
NOTES:
* All blanks in all opcode maps are reserved and must not be used. Do not depend on the operation of undefined or reserved locations.
Vol. 2D A-19
OPCODE MAP
A.5
ESCAPE OPCODE INSTRUCTIONS
Opcode maps for coprocessor escape instruction opcodes (x87 floating-point instruction opcodes) are in Table A-7
through Table A-22. These maps are grouped by the first byte of the opcode, from D8-DF. Each of these opcodes
has a ModR/M byte. If the ModR/M byte is within the range of 00H-BFH, bits 3-5 of the ModR/M byte are used as
an opcode extension, similar to the technique used for 1-and 2-byte opcodes (see A.4). If the ModR/M byte is
outside the range of 00H through BFH, the entire ModR/M byte is used as an opcode extension.
A.5.1
Opcode Look-up Examples for Escape Instruction Opcodes
Examples are provided below.
Example A-6. Opcode with ModR/M Byte in the 00H through BFH Range
DD0504000000H can be interpreted as follows:
The instruction encoded with this opcode can be located in Section . Since the ModR/M byte (05H) is within the
00H through BFH range, bits 3 through 5 (000) of this byte indicate the opcode for an FLD double-real
instruction (see Table A-9).
The double-real value to be loaded is at 00000004H (the 32-bit displacement that follows and belongs to this
opcode).
Example A-7. Opcode with ModR/M Byte outside the 00H through BFH Range
D8C1H can be interpreted as follows:
This example illustrates an opcode with a ModR/M byte outside the range of 00H through BFH. The instruction
can be located in Section A.4.
In Table A-8, the ModR/M byte C1H indicates row C, column 1 (the FADD instruction using ST(0), ST(1) as
operands).
A.5.2
Escape Opcode Instruction Tables
Tables are listed below.
A.5.2.1
Escape Opcodes with D8 as First Byte
Table A-7 and A-8 contain maps for the escape instruction opcodes that begin with D8H. Table A-7 shows the map if the ModR/M
byte is in the range of 00H-BFH. Here, the value of bits 3-5 (the nnn field in Figure A-1) selects the instruction.
Table A-7. D8 Opcode Map When ModR/M Byte is Within 00H to BFH *
nnn Field of ModR/M Byte (refer to Figure A.4)
000B
001B
010B
011B
100B
101B
110B
111B
FADD
FMUL
FCOM
FCOMP
FSUB
FSUBR
FDIV
FDIVR
single-real
single-real
single-real
single-real
single-real
single-real
single-real
single-real
NOTES:
* All blanks in all opcode maps are reserved and must not be used. Do not depend on the operation of undefined or reserved locations.
A-20
Vol. 2D
OPCODE MAP
Table A-8 shows the map if the ModR/M byte is outside the range of 00H-BFH. Here, the first digit of the ModR/M byte selects the
table row and the second digit selects the column.
Table A-8. D8 Opcode Map When ModR/M Byte is Outside 00H to BFH *
0
1
2
3
4
5
6
7
C
FADD
ST(0),ST(0)
ST(0),ST(1)
ST(0),ST(2)
ST(0),ST(3)
ST(0),ST(4)
ST(0),ST(5)
ST(0),ST(6)
ST(0),ST(7)
D
FCOM
ST(0),ST(0)
ST(0),ST(1)
ST(0),T(2)
ST(0),ST(3)
ST(0),ST(4)
ST(0),ST(5)
ST(0),ST(6)
ST(0),ST(7)
E
FSUB
ST(0),ST(0)
ST(0),ST(1)
ST(0),ST(2)
ST(0),ST(3)
ST(0),ST(4)
ST(0),ST(5)
ST(0),ST(6)
ST(0),ST(7)
F
FDIV
ST(0),ST(0)
ST(0),ST(1)
ST(0),ST(2)
ST(0),ST(3)
ST(0),ST(4)
ST(0),ST(5)
ST(0),ST(6)
ST(0),ST(7)
8
9
A
B
C
D
E
F
C
FMUL
ST(0),ST(0)
ST(0),ST(1)
ST(0),ST(2)
ST(0),ST(3)
ST(0),ST(4)
ST(0),ST(5)
ST(0),ST(6)
ST(0),ST(7)
D
FCOMP
ST(0),ST(0)
ST(0),ST(1)
ST(0),T(2)
ST(0),ST(3)
ST(0),ST(4)
ST(0),ST(5)
ST(0),ST(6)
ST(0),ST(7)
E
FSUBR
ST(0),ST(0)
ST(0),ST(1)
ST(0),ST(2)
ST(0),ST(3)
ST(0),ST(4)
ST(0),ST(5)
ST(0),ST(6)
ST(0),ST(7)
F
FDIVR
ST(0),ST(0)
ST(0),ST(1)
ST(0),ST(2)
ST(0),ST(3)
ST(0),ST(4)
ST(0),ST(5)
ST(0),ST(6)
ST(0),ST(7)
NOTES:
* All blanks in all opcode maps are reserved and must not be used. Do not depend on the operation of undefined or reserved locations.
A.5.2.2
Escape Opcodes with D9 as First Byte
Table A-9 and A-10 contain maps for escape instruction opcodes that begin with D9H. Table A-9 shows the map if the ModR/M
byte is in the range of 00H-BFH. Here, the value of bits 3-5 (the nnn field in Figure A-1) selects the instruction.
Table A-9. D9 Opcode Map When ModR/M Byte is Within 00H to BFH *
nnn Field of ModR/M Byte
000B
001B
010B
011B
100B
101B
110B
111B
FLD
FST
FSTP
FLDENV
FLDCW
FSTENV
FSTCW
single-real
single-real
single-real
14/28 bytes
2 bytes
14/28 bytes
2 bytes
NOTES:
* All blanks in all opcode maps are reserved and must not be used. Do not depend on the operation of undefined or reserved locations.
Vol. 2D A-21
OPCODE MAP
Table A-10 shows the map if the ModR/M byte is outside the range of 00H-BFH. Here, the first digit of the ModR/M byte selects
the table row and the second digit selects the column.
Table A-10. D9 Opcode Map When ModR/M Byte is Outside 00H to BFH *
0
1
2
3
4
5
6
7
C
FLD
ST(0),ST(0)
ST(0),ST(1)
ST(0),ST(2)
ST(0),ST(3)
ST(0),ST(4)
ST(0),ST(5)
ST(0),ST(6)
ST(0),ST(7)
D
FNOP
E
FCHS
FABS
FTST
FXAM
F
F2XM1
FYL2X
FPTAN
FPATAN
FXTRACT
FPREM1
FDECSTP
FINCSTP
8
9
A
B
C
D
E
F
C
FXCH
ST(0),ST(0)
ST(0),ST(1)
ST(0),ST(2)
ST(0),ST(3)
ST(0),ST(4)
ST(0),ST(5)
ST(0),ST(6)
ST(0),ST(7)
D
E
FLD1
FLDL2T
FLDL2E
FLDPI
FLDLG2
FLDLN2
FLDZ
F
FPREM
FYL2XP1
FSQRT
FSINCOS
FRNDINT
FSCALE
FSIN
FCOS
NOTES:
* All blanks in all opcode maps are reserved and must not be used. Do not depend on the operation of undefined or reserved locations.
A.5.2.3
Escape Opcodes with DA as First Byte
Table A-11 and A-12 contain maps for escape instruction opcodes that begin with DAH. Table A-11 shows the map if the ModR/M
byte is in the range of 00H-BFH. Here, the value of bits 3-5 (the nnn field in Figure A-1) selects the instruction.
Table A-11. DA Opcode Map When ModR/M Byte is Within 00H to BFH *
nnn Field of ModR/M Byte
000B
001B
010B
011B
100B
101B
110B
111B
FIADD
FIMUL
FICOM
FICOMP
FISUB
FISUBR
FIDIV
FIDIVR
dword-integer
dword-integer
dword-integer
dword-integer
dword-integer
dword-integer
dword-integer
dword-integer
NOTES:
* All blanks in all opcode maps are reserved and must not be used. Do not depend on the operation of undefined or reserved locations.
A-22
Vol. 2D
OPCODE MAP
Table A-12 shows the map if the ModR/M byte is outside the range of 00H-BFH. Here, the first digit of the ModR/M byte selects
the table row and the second digit selects the column.
Table A-12. DA Opcode Map When ModR/M Byte is Outside 00H to BFH *
0
1
2
3
4
5
6
7
C
FCMOVB
ST(0),ST(0)
ST(0),ST(1)
ST(0),ST(2)
ST(0),ST(3)
ST(0),ST(4)
ST(0),ST(5)
ST(0),ST(6)
ST(0),ST(7)
D
FCMOVBE
ST(0),ST(0)
ST(0),ST(1)
ST(0),ST(2)
ST(0),ST(3)
ST(0),ST(4)
ST(0),ST(5)
ST(0),ST(6)
ST(0),ST(7)
E
F
8
9
A
B
C
D
E
F
C
FCMOVE
ST(0),ST(0)
ST(0),ST(1)
ST(0),ST(2)
ST(0),ST(3)
ST(0),ST(4)
ST(0),ST(5)
ST(0),ST(6)
ST(0),ST(7)
D
FCMOVU
ST(0),ST(0)
ST(0),ST(1)
ST(0),ST(2)
ST(0),ST(3)
ST(0),ST(4)
ST(0),ST(5)
ST(0),ST(6)
ST(0),ST(7)
E
FUCOMPP
F
NOTES:
* All blanks in all opcode maps are reserved and must not be used. Do not depend on the operation of undefined or reserved locations.
A.5.2.4
Escape Opcodes with DB as First Byte
Table A-13 and A-14 contain maps for escape instruction opcodes that begin with DBH. Table A-13 shows the map if the ModR/M
byte is in the range of 00H-BFH. Here, the value of bits 3-5 (the nnn field in Figure A-1) selects the instruction.
Table A-13. DB Opcode Map When ModR/M Byte is Within 00H to BFH *
nnn Field of ModR/M Byte
000B
001B
010B
011B
100B
101B
110B
111B
FILD
FISTTP
FIST
FISTP
FLD
FSTP
dword-integer
dword-integer
dword-integer
dword-integer
extended-real
extended-real
NOTES:
* All blanks in all opcode maps are reserved and must not be used. Do not depend on the operation of undefined or reserved locations.
Vol. 2D A-23
OPCODE MAP
Table A-14 shows the map if the ModR/M byte is outside the range of 00H-BFH. Here, the first digit of the ModR/M byte selects
the table row and the second digit selects the column.
Table A-14. DB Opcode Map When ModR/M Byte is Outside 00H to BFH *
0
1
2
3
4
5
6
7
C
FCMOVNB
ST(0),ST(0)
ST(0),ST(1)
ST(0),ST(2)
ST(0),ST(3)
ST(0),ST(4)
ST(0),ST(5)
ST(0),ST(6)
ST(0),ST(7)
D
FCMOVNBE
ST(0),ST(0)
ST(0),ST(1)
ST(0),ST(2)
ST(0),ST(3)
ST(0),ST(4)
ST(0),ST(5)
ST(0),ST(6)
ST(0),ST(7)
E
FCLEX
FINIT
F
FCOMI
ST(0),ST(0)
ST(0),ST(1)
ST(0),ST(2)
ST(0),ST(3)
ST(0),ST(4)
ST(0),ST(5)
ST(0),ST(6)
ST(0),ST(7)
8
9
A
B
C
D
E
F
C
FCMOVNE
ST(0),ST(0)
ST(0),ST(1)
ST(0),ST(2)
ST(0),ST(3)
ST(0),ST(4)
ST(0),ST(5)
ST(0),ST(6)
ST(0),ST(7)
D
FCMOVNU
ST(0),ST(0)
ST(0),ST(1)
ST(0),ST(2)
ST(0),ST(3)
ST(0),ST(4)
ST(0),ST(5)
ST(0),ST(6)
ST(0),ST(7)
E
FUCOMI
ST(0),ST(0)
ST(0),ST(1)
ST(0),ST(2)
ST(0),ST(3)
ST(0),ST(4)
ST(0),ST(5)
ST(0),ST(6)
ST(0),ST(7)
F
NOTES:
* All blanks in all opcode maps are reserved and must not be used. Do not depend on the operation of undefined or reserved locations.
A.5.2.5
Escape Opcodes with DC as First Byte
Table A-15 and A-16 contain maps for escape instruction opcodes that begin with DCH. Table A-15 shows the map if the ModR/M
byte is in the range of 00H-BFH. Here, the value of bits 3-5 (the nnn field in Figure A-1) selects the instruction.
Table A-15. DC Opcode Map When ModR/M Byte is Within 00H to BFH *
nnn Field of ModR/M Byte (refer to Figure A-1)
000B
001B
010B
011B
100B
101B
110B
111B
FADD
FMUL
FCOM
FCOMP
FSUB
FSUBR
FDIV
FDIVR
double-real
double-real
double-real
double-real
double-real
double-real
double-real
double-real
NOTES:
* All blanks in all opcode maps are reserved and must not be used. Do not depend on the operation of undefined or reserved locations.
A-24
Vol. 2D
OPCODE MAP
Table A-16 shows the map if the ModR/M byte is outside the range of 00H-BFH. In this case the first digit of the ModR/M byte
selects the table row and the second digit selects the column.
Table A-16. DC Opcode Map When ModR/M Byte is Outside 00H to BFH *
0
1
2
3
4
5
6
7
C
FADD
ST(0),ST(0)
ST(1),ST(0)
ST(2),ST(0)
ST(3),ST(0)
ST(4),ST(0)
ST(5),ST(0)
ST(6),ST(0)
ST(7),ST(0)
D
E
FSUBR
ST(0),ST(0)
ST(1),ST(0)
ST(2),ST(0)
ST(3),ST(0)
ST(4),ST(0)
ST(5),ST(0)
ST(6),ST(0)
ST(7),ST(0)
F
FDIVR
ST(0),ST(0)
ST(1),ST(0)
ST(2),ST(0)
ST(3),ST(0)
ST(4),ST(0)
ST(5),ST(0)
ST(6),ST(0)
ST(7),ST(0)
8
9
A
B
C
D
E
F
C
FMUL
ST(0),ST(0)
ST(1),ST(0)
ST(2),ST(0)
ST(3),ST(0)
ST(4),ST(0)
ST(5),ST(0)
ST(6),ST(0)
ST(7),ST(0)
D
E
FSUB
ST(0),ST(0)
ST(1),ST(0)
ST(2),ST(0)
ST(3),ST(0)
ST(4),ST(0)
ST(5),ST(0)
ST(6),ST(0)
ST(7),ST(0)
F
FDIV
ST(0),ST(0)
ST(1),ST(0)
ST(2),ST(0)
ST(3),ST(0)
ST(4),ST(0)
ST(5),ST(0)
ST(6),ST(0)
ST(7),ST(0)
NOTES:
* All blanks in all opcode maps are reserved and must not be used. Do not depend on the operation of undefined or reserved locations.
A.5.2.6
Escape Opcodes with DD as First Byte
Table A-17 and A-18 contain maps for escape instruction opcodes that begin with DDH. Table A-17 shows the map if the ModR/M
byte is in the range of 00H-BFH. Here, the value of bits 3-5 (the nnn field in Figure A-1) selects the instruction.
Table A-17. DD Opcode Map When ModR/M Byte is Within 00H to BFH *
nnn Field of ModR/M Byte
000B
001B
010B
011B
100B
101B
110B
111B
FLD
FISTTP
FST
FSTP
FRSTOR
FSAVE
FSTSW
double-real
integer64
double-real
double-real
98/108bytes
98/108bytes
2 bytes
NOTES:
* All blanks in all opcode maps are reserved and must not be used. Do not depend on the operation of undefined or reserved locations.
Vol. 2D A-25
OPCODE MAP
Table A-18 shows the map if the ModR/M byte is outside the range of 00H-BFH. The first digit of the ModR/M byte selects the table
row and the second digit selects the column.
Table A-18. DD Opcode Map When ModR/M Byte is Outside 00H to BFH *
0
1
2
3
4
5
6
7
C
FFREE
ST(0)
ST(1)
ST(2)
ST(3)
ST(4)
ST(5)
ST(6)
ST(7)
D
FST
ST(0)
ST(1)
ST(2)
ST(3)
ST(4)
ST(5)
ST(6)
ST(7)
E
FUCOM
ST(0),ST(0)
ST(1),ST(0)
ST(2),ST(0)
ST(3),ST(0)
ST(4),ST(0)
ST(5),ST(0)
ST(6),ST(0)
ST(7),ST(0)
F
8
9
A
B
C
D
E
F
C
D
FSTP
ST(0)
ST(1)
ST(2)
ST(3)
ST(4)
ST(5)
ST(6)
ST(7)
E
FUCOMP
ST(0)
ST(1)
ST(2)
ST(3)
ST(4)
ST(5)
ST(6)
ST(7)
F
NOTES:
* All blanks in all opcode maps are reserved and must not be used. Do not depend on the operation of undefined or reserved locations.
A.5.2.7
Escape Opcodes with DE as First Byte
Table A-19 and A-20 contain opcode maps for escape instruction opcodes that begin with DEH. Table A-19 shows the opcode map
if the ModR/M byte is in the range of 00H-BFH. In this case, the value of bits 3-5 (the nnn field in Figure A-1) selects the instruc-
tion.
Table A-19. DE Opcode Map When ModR/M Byte is Within 00H to BFH *
nnn Field of ModR/M Byte
000B
001B
010B
011B
100B
101B
110B
111B
FIADD
FIMUL
FICOM
FICOMP
FISUB
FISUBR
FIDIV
FIDIVR
word-integer
word-integer
word-integer
word-integer
word-integer
word-integer
word-integer
word-integer
NOTES:
* All blanks in all opcode maps are reserved and must not be used. Do not depend on the operation of undefined or reserved locations.
A-26
Vol. 2D
OPCODE MAP
Table A-20 shows the opcode map if the ModR/M byte is outside the range of 00H-BFH. The first digit of the ModR/M byte selects
the table row and the second digit selects the column.
Table A-20. DE Opcode Map When ModR/M Byte is Outside 00H to BFH *
0
1
2
3
4
5
6
7
C
FADDP
ST(0),ST(0)
ST(1),ST(0)
ST(2),ST(0)
ST(3),ST(0)
ST(4),ST(0)
ST(5),ST(0)
ST(6),ST(0)
ST(7),ST(0)
D
E
FSUBRP
ST(0),ST(0)
ST(1),ST(0)
ST(2),ST(0)
ST(3),ST(0)
ST(4),ST(0)
ST(5),ST(0)
ST(6),ST(0)
ST(7),ST(0)
F
FDIVRP
ST(0),ST(0)
ST(1),ST(0)
ST(2),ST(0)
ST(3),ST(0)
ST(4),ST(0)
ST(5),ST(0)
ST(6),ST(0)
ST(7),ST(0)
8
9
A
B
C
D
E
F
C
FMULP
ST(0),ST(0)
ST(1),ST(0)
ST(2),ST(0)
ST(3),ST(0)
ST(4),ST(0)
ST(5),ST(0)
ST(6),ST(0)
ST(7),ST(0)
D
FCOMPP
E
FSUBP
ST(0),ST(0)
ST(1),ST(0)
ST(2),ST(0)
ST(3),ST(0)
ST(4),ST(0)
ST(5),ST(0)
ST(6),ST(0)
ST(7),ST(0)
F
FDIVP
ST(0),ST(0)
ST(1),ST(0)
ST(2),ST(0).
ST(3),ST(0)
ST(4),ST(0)
ST(5),ST(0)
ST(6),ST(0)
ST(7),ST(0)
NOTES:
* All blanks in all opcode maps are reserved and must not be used. Do not depend on the operation of undefined or reserved locations.
A.5.2.8
Escape Opcodes with DF As First Byte
Table A-21 and A-22 contain the opcode maps for escape instruction opcodes that begin with DFH. Table A-21 shows the opcode
map if the ModR/M byte is in the range of 00H-BFH. Here, the value of bits 3-5 (the nnn field in Figure A-1) selects the instruction.
Table A-21. DF Opcode Map When ModR/M Byte is Within 00H to BFH *
nnn Field of ModR/M Byte
000B
001B
010B
011B
100B
101B
110B
111B
FILD
FISTTP
FIST
FISTP
FBLD
FILD
FBSTP
FISTP
word-integer
word-integer
word-integer
word-integer
packed-BCD
qword-integer
packed-BCD
qword-integer
NOTES:
* All blanks in all opcode maps are reserved and must not be used. Do not depend on the operation of undefined or reserved locations.
Vol. 2D A-27
OPCODE MAP
Table A-22 shows the opcode map if the ModR/M byte is outside the range of 00H-BFH. The first digit of the ModR/M byte selects
the table row and the second digit selects the column.
Table A-22. DF Opcode Map When ModR/M Byte is Outside 00H to BFH *
0
1
2
3
4
5
6
7
C
D
E
FSTSW
AX
F
FCOMIP
ST(0),ST(0)
ST(0),ST(1)
ST(0),ST(2)
ST(0),ST(3)
ST(0),ST(4)
ST(0),ST(5)
ST(0),ST(6)
ST(0),ST(7)
8
9
A
B
C
D
E
F
C
D
E
FUCOMIP
ST(0),ST(0)
ST(0),ST(1)
ST(0),ST(2)
ST(0),ST(3)
ST(0),ST(4)
ST(0),ST(5)
ST(0),ST(6)
ST(0),ST(7)
F
NOTES:
* All blanks in all opcode maps are reserved and must not be used. Do not depend on the operation of undefined or reserved locations.
A-28
Vol. 2D
OPCODE MAP
Vol. 2D A-29
OPCODE MAP
A-30
Vol. 2D
APPENDIX B
INSTRUCTION FORMATS AND ENCODINGS
This appendix provides machine instruction formats and encodings of IA-32 instructions. The first section describes
the IA-32 architecture’s machine instruction format. The remaining sections show the formats and encoding of
general-purpose, MMX, P6 family, SSE/SSE2/SSE3, x87 FPU instructions, and VMX instructions. Those instruction
formats also apply to Intel 64 architecture. Instruction formats used in 64-bit mode are provided as supersets of
the above.
B.1
MACHINE INSTRUCTION FORMAT
All Intel Architecture instructions are encoded using subsets of the general machine instruction format shown in
Figure B-1. Each instruction consists of:
an opcode
a register and/or address mode specifier consisting of the ModR/M byte and sometimes the scale-index-base
(SIB) byte (if required)
a displacement and an immediate data field (if required)
7 6 5 4 3 2 1 0
7 6 5 4 3 2 1 0
7 6 5 4 3 2 1 0
Legacy Prefixes
REX Prefixes
T T T T T T T T
T T T T T T T T
T T T T T T T T
Grp
1, Grp 2,
(optional)
Grp 3, Grp 4
1, 2, or 3 Byte Opcodes (T = Opcode
7-6
5-3
2-0
7-6
5-3
2-0
Mod Reg* R/M
Scale Index Base
d32 | 16 | 8 | None
d32 | 16 | 8 | None
ModR/M Byte
SIB Byte
Address Displacement
Immediate Data
(4, 2, 1 Bytes or None)
(4,2,1 Bytes or None)
Register and/or Address
NOTE:
Mode Specifier
* The Reg Field may be used as an
opcode extension field (TTT) and as a
way to encode diagnostic registers
(eee).
Figure B-1. General Machine Instruction Format
The following sections discuss this format.
B.1.1
Legacy Prefixes
The legacy prefixes noted in Figure B-1 include 66H, 67H, F2H, and F3H. They are optional, except when F2H, F3H,
and 66H are used in instruction extensions. Legacy prefixes must be placed before REX prefixes.
Refer to Chapter 2, “Instruction Format,” in the Intel® 64 and IA-32 Architectures Software Developer’s Manual,
Volume 2A, for more information on legacy prefixes.
Vol. 2D B-1
INSTRUCTION FORMATS AND ENCODINGS
B.1.2
REX Prefixes
REX prefixes are a set of 16 opcodes that span one row of the opcode map and occupy entries 40H to 4FH. These
opcodes represent valid instructions (INC or DEC) in IA-32 operating modes and in compatibility mode. In 64-bit
mode, the same opcodes represent the instruction prefix REX and are not treated as individual instructions.
Refer to Chapter 2, “Instruction Format,” in the Intel® 64 and IA-32 Architectures Software Developer’s Manual,
Volume 2A, for more information on REX prefixes.
B.1.3
Opcode Fields
The primary opcode for an instruction is encoded in one to three bytes of the instruction. Within the primary
opcode, smaller encoding fields may be defined. These fields vary according to the class of operation being
performed.
Almost all instructions that refer to a register and/or memory operand have a register and/or address mode byte
following the opcode. This byte, the ModR/M byte, consists of the mod field (2 bits), the reg field (3 bits; this field
is sometimes an opcode extension), and the R/M field (3 bits). Certain encodings of the ModR/M byte indicate that
a second address mode byte, the SIB byte, must be used.
If the addressing mode specifies a displacement, the displacement value is placed immediately following the
ModR/M byte or SIB byte. Possible sizes are 8, 16, or 32 bits. If the instruction specifies an immediate value, the
immediate value follows any displacement bytes. The immediate, if specified, is always the last field of the instruc-
tion.
Refer to Chapter 2, “Instruction Format,” in the Intel® 64 and IA-32 Architectures Software Developer’s Manual,
Volume 2A, for more information on opcodes.
B.1.4
Special Fields
Table B-1 lists bit fields that appear in certain instructions, sometimes within the opcode bytes. All of these fields
(except the d bit) occur in the general-purpose instruction formats in Table B-13.
Table B-1. Special Fields Within Instruction Encodings
Number of
Field Name
Description
Bits
reg
General-register specifier (see Table B-4 or B-5).
3
w
Specifies if data is byte or full-sized, where full-sized is 16 or 32 bits (see Table B-6).
1
s
Specifies sign extension of an immediate field (see Table B-7).
1
sreg2
Segment register specifier for CS, SS, DS, ES (see Table B-8).
2
sreg3
Segment register specifier for CS, SS, DS, ES, FS, GS (see Table B-8).
3
eee
Specifies a special-purpose (control or debug) register (see Table B-9).
3
tttn
For conditional instructions, specifies a condition asserted or negated (see Table B-12).
4
d
Specifies direction of data operation (see Table B-11).
1
B-2
Vol. 2D
INSTRUCTION FORMATS AND ENCODINGS
B.1.4.1
Reg Field (reg) for Non-64-Bit Modes
The reg field in the ModR/M byte specifies a general-purpose register operand. The group of registers specified is
modified by the presence and state of the w bit in an encoding (refer to Section B.1.4.3). Table B-2 shows the
encoding of the reg field when the w bit is not present in an encoding; Table B-3 shows the encoding of the reg field
when the w bit is present.
Table B-2. Encoding of reg Field When w Field is Not Present in Instruction
Register Selected during
Register Selected during
reg Field
16-Bit Data Operations
32-Bit Data Operations
000
AX
EAX
001
CX
ECX
010
DX
EDX
011
BX
EBX
100
SP
ESP
101
BP
EBP
110
SI
ESI
111
DI
EDI
Table B-3. Encoding of reg Field When w Field is Present in Instruction
Register Specified by reg Field
Register Specified by reg Field
During 16-Bit Data Operations
During 32-Bit Data Operations
Function of w Field
Function of w Field
reg
reg
When w = 0
When w = 1
When w = 0
When w = 1
000
AL
AX
000
AL
EAX
001
CL
CX
001
CL
ECX
010
DL
DX
010
DL
EDX
011
BL
BX
011
BL
EBX
100
AH
SP
100
AH
ESP
101
CH
BP
101
CH
EBP
110
DH
SI
110
DH
ESI
111
BH
DI
111
BH
EDI
Vol. 2D B-3
INSTRUCTION FORMATS AND ENCODINGS
B.1.4.2
Reg Field (reg) for 64-Bit Mode
Just like in non-64-bit modes, the reg field in the ModR/M byte specifies a general-purpose register operand. The
group of registers specified is modified by the presence of and state of the w bit in an encoding (refer to Section
B.1.4.3). Table B-4 shows the encoding of the reg field when the w bit is not present in an encoding; Table B-5
shows the encoding of the reg field when the w bit is present.
Table B-4. Encoding of reg Field When w Field is Not Present in Instruction
Register Selected during
Register Selected during
Register Selected during
reg Field
16-Bit Data Operations
32-Bit Data Operations
64-Bit Data Operations
000
AX
EAX
RAX
001
CX
ECX
RCX
010
DX
EDX
RDX
011
BX
EBX
RBX
100
SP
ESP
RSP
101
BP
EBP
RBP
110
SI
ESI
RSI
111
DI
EDI
RDI
Table B-5. Encoding of reg Field When w Field is Present in Instruction
Register Specified by reg Field
Register Specified by reg Field
During 16-Bit Data Operations
During 32-Bit Data Operations
Function of w Field
Function of w Field
reg
reg
When w = 0
When w = 1
When w = 0
When w = 1
000
AL
AX
000
AL
EAX
001
CL
CX
001
CL
ECX
010
DL
DX
010
DL
EDX
011
BL
BX
011
BL
EBX
100
AH1
SP
100
AH*
ESP
101
CH1
BP
101
CH*
EBP
110
DH1
SI
110
DH*
ESI
111
BH1
DI
111
BH*
EDI
NOTES:
1. AH, CH, DH, BH can not be encoded when REX prefix is used. Such an expression defaults to the low byte.
B.1.4.3
Encoding of Operand Size (w) Bit
The current operand-size attribute determines whether the processor is performing 16-bit, 32-bit or 64-bit opera-
tions. Within the constraints of the current operand-size attribute, the operand-size bit (w) can be used to indicate
operations on 8-bit operands or the full operand size specified with the operand-size attribute. Table B-6 shows the
encoding of the w bit depending on the current operand-size attribute.
Table B-6. Encoding of Operand Size (w) Bit
Operand Size When
Operand Size When
w Bit
Operand-Size Attribute is 16 Bits
Operand-Size Attribute is 32 Bits
0
8 Bits
8 Bits
1
16 Bits
32 Bits
B-4
Vol. 2D
INSTRUCTION FORMATS AND ENCODINGS
B.1.4.4
Sign-Extend (s) Bit
The sign-extend (s) bit occurs in instructions with immediate data fields that are being extended from 8 bits to 16
or 32 bits. See Table B-7.
Table B-7. Encoding of Sign-Extend (s) Bit
Effect on 8-Bit
Effect on 16- or 32-Bit
s
Immediate Data
Immediate Data
0
None
None
1
Sign-extend to fill 16-bit or 32-bit destination
None
B.1.4.5
Segment Register (sreg) Field
When an instruction operates on a segment register, the reg field in the ModR/M byte is called the sreg field and is
used to specify the segment register. Table B-8 shows the encoding of the sreg field. This field is sometimes a 2-bit
field (sreg2) and other times a 3-bit field (sreg3).
Table B-8. Encoding of the Segment Register (sreg) Field
2-Bit sreg2 Field
Segment Register Selected
3-Bit sreg3 Field
Segment Register Selected
00
ES
000
ES
01
CS
001
CS
10
SS
010
SS
11
DS
011
DS
100
FS
101
GS
110
Reserved1
111
Reserved
NOTES:
1. Do not use reserved encodings.
B.1.4.6
Special-Purpose Register (eee) Field
When control or debug registers are referenced in an instruction they are encoded in the eee field, located in bits 5
though 3 of the ModR/M byte (an alternate encoding of the sreg field). See Table B-9.
Table B-9. Encoding of Special-Purpose Register (eee) Field
eee
Control Register
Debug Register
000
CR0
DR0
001
Reserved1
DR1
010
CR2
DR2
011
CR3
DR3
100
CR4
Reserved
101
Reserved
Reserved
110
Reserved
DR6
111
Reserved
DR7
NOTES:
1. Do not use reserved encodings.
Vol. 2D B-5
INSTRUCTION FORMATS AND ENCODINGS
B.1.4.7
Condition Test (tttn) Field
For conditional instructions (such as conditional jumps and set on condition), the condition test field (tttn) is
encoded for the condition being tested. The ttt part of the field gives the condition to test and the n part indicates
whether to use the condition (n = 0) or its negation (n = 1).
For 1-byte primary opcodes, the tttn field is located in bits 3, 2, 1, and 0 of the opcode byte.
For 2-byte primary opcodes, the tttn field is located in bits 3, 2, 1, and 0 of the second opcode byte.
Table B-10 shows the encoding of the tttn field.
Table B-10. Encoding of Conditional Test (tttn) Field
t t t n
Mnemonic
Condition
0000
O
Overflow
0001
NO
No overflow
0010
B, NAE
Below, Not above or equal
0011
NB, AE
Not below, Above or equal
0100
E, Z
Equal, Zero
0101
NE, NZ
Not equal, Not zero
0110
BE, NA
Below or equal, Not above
0111
NBE, A
Not below or equal, Above
1000
S
Sign
1001
NS
Not sign
1010
P, PE
Parity, Parity Even
1011
NP, PO
Not parity, Parity Odd
1100
L, NGE
Less than, Not greater than or equal to
1101
NL, GE
Not less than, Greater than or equal to
1110
LE, NG
Less than or equal to, Not greater than
1111
NLE, G
Not less than or equal to, Greater than
B.1.4.8
Direction (d) Bit
In many two-operand instructions, a direction bit (d) indicates which operand is considered the source and which
is the destination. See Table B-11.
When used for integer instructions, the d bit is located at bit 1 of a 1-byte primary opcode. Note that this bit
does not appear as the symbol “d” in Table B-13; the actual encoding of the bit as 1 or 0 is given.
When used for floating-point instructions (in Table B-16), the d bit is shown as bit 2 of the first byte of the
primary opcode.
Table B-11. Encoding of Operation Direction (d) Bit
d
Source
Destination
0
reg Field
ModR/M or SIB Byte
1
ModR/M or SIB Byte
reg Field
B.1.5
Other Notes
Table B-12 contains notes on particular encodings. These notes are indicated in the tables shown in the following
sections by superscripts.
B-6
Vol. 2D
INSTRUCTION FORMATS AND ENCODINGS
Table B-12. Notes on Instruction Encoding
Symbol
Note
A
A value of 11B in bits 7 and 6 of the ModR/M byte is reserved.
B
A value of 01B (or 10B) in bits 7 and 6 of the ModR/M byte is reserved.
B.2
GENERAL-PURPOSE INSTRUCTION FORMATS AND ENCODINGS FOR NON-
64-BIT MODES
Table B-13 shows machine instruction formats and encodings for general purpose instructions in non-64-bit
modes.
Table B-13. General Purpose Instruction Formats and Encodings for Non-64-Bit Modes
Instruction and Format
Encoding
AAA - ASCII Adjust after Addition
0011 0111
AAD - ASCII Adjust AX before Division
1101 0101 : 0000 1010
AAM - ASCII Adjust AX after Multiply
1101 0100 : 0000 1010
AAS - ASCII Adjust AL after Subtraction
0011 1111
ADC - ADD with Carry
register1 to register2
0001 000w : 11 reg1 reg2
register2 to register1
0001 001w : 11 reg1 reg2
memory to register
0001 001w : mod reg r/m
register to memory
0001 000w : mod reg r/m
immediate to register
1000 00sw : 11 010 reg : immediate data
immediate to AL, AX, or EAX
0001 010w : immediate data
immediate to memory
1000 00sw : mod 010 r/m : immediate data
ADD - Add
register1 to register2
0000 000w : 11 reg1 reg2
register2 to register1
0000 001w : 11 reg1 reg2
memory to register
0000 001w : mod reg r/m
register to memory
0000 000w : mod reg r/m
immediate to register
1000 00sw : 11 000 reg : immediate data
immediate to AL, AX, or EAX
0000 010w : immediate data
immediate to memory
1000 00sw : mod 000 r/m : immediate data
AND - Logical AND
register1 to register2
0010 000w : 11 reg1 reg2
register2 to register1
0010 001w : 11 reg1 reg2
memory to register
0010 001w : mod reg r/m
register to memory
0010 000w : mod reg r/m
immediate to register
1000 00sw : 11 100 reg : immediate data
immediate to AL, AX, or EAX
0010 010w : immediate data
immediate to memory
1000 00sw : mod 100 r/m : immediate data
Vol. 2D B-7
INSTRUCTION FORMATS AND ENCODINGS
Table B-13. General Purpose Instruction Formats and Encodings for Non-64-Bit Modes (Contd.)
Instruction and Format
Encoding
ARPL - Adjust RPL Field of Selector
from register
0110 0011 : 11 reg1 reg2
from memory
0110 0011 : mod reg r/m
BOUND - Check Array Against Bounds
0110 0010 : modA reg r/m
BSF - Bit Scan Forward
register1, register2
0000 1111 : 1011 1100 : 11 reg1 reg2
memory, register
0000 1111 : 1011 1100 : mod reg r/m
BSR - Bit Scan Reverse
register1, register2
0000 1111 : 1011 1101 : 11 reg1 reg2
memory, register
0000 1111 : 1011 1101 : mod reg r/m
BSWAP - Byte Swap
0000 1111 : 1100 1 reg
BT - Bit Test
register, immediate
0000 1111 : 1011 1010 : 11 100 reg: imm8 data
memory, immediate
0000 1111 : 1011 1010 : mod 100 r/m : imm8 data
register1, register2
0000 1111 : 1010 0011 : 11 reg2 reg1
memory, reg
0000 1111 : 1010 0011 : mod reg r/m
BTC - Bit Test and Complement
register, immediate
0000 1111 : 1011 1010 : 11 111 reg: imm8 data
memory, immediate
0000 1111 : 1011 1010 : mod 111 r/m : imm8 data
register1, register2
0000 1111 : 1011 1011 : 11 reg2 reg1
memory, reg
0000 1111 : 1011 1011 : mod reg r/m
BTR - Bit Test and Reset
register, immediate
0000 1111 : 1011 1010 : 11 110 reg: imm8 data
memory, immediate
0000 1111 : 1011 1010 : mod 110 r/m : imm8 data
register1, register2
0000 1111 : 1011 0011 : 11 reg2 reg1
memory, reg
0000 1111 : 1011 0011 : mod reg r/m
BTS - Bit Test and Set
register, immediate
0000 1111 : 1011 1010 : 11 101 reg: imm8 data
memory, immediate
0000 1111 : 1011 1010 : mod 101 r/m : imm8 data
register1, register2
0000 1111 : 1010 1011 : 11 reg2 reg1
memory, reg
0000 1111 : 1010 1011 : mod reg r/m
CALL - Call Procedure (in same segment)
direct
1110 1000 : full displacement
register indirect
1111 1111 : 11 010 reg
memory indirect
1111 1111 : mod 010 r/m
CALL - Call Procedure (in other segment)
direct
1001 1010 : unsigned full offset, selector
indirect
1111 1111 : mod 011 r/m
B-8
Vol. 2D
INSTRUCTION FORMATS AND ENCODINGS
Table B-13. General Purpose Instruction Formats and Encodings for Non-64-Bit Modes (Contd.)
Instruction and Format
Encoding
CBW - Convert Byte to Word
1001 1000
CDQ - Convert Doubleword to Qword
1001 1001
CLC - Clear Carry Flag
1111 1000
CLD - Clear Direction Flag
1111 1100
CLI - Clear Interrupt Flag
1111 1010
CLTS - Clear Task-Switched Flag in CR0
0000 1111 : 0000 0110
CMC - Complement Carry Flag
1111 0101
CMP - Compare Two Operands
register1 with register2
0011 100w : 11 reg1 reg2
register2 with register1
0011 101w : 11 reg1 reg2
memory with register
0011 100w : mod reg r/m
register with memory
0011 101w : mod reg r/m
immediate with register
1000 00sw : 11 111 reg : immediate data
immediate with AL, AX, or EAX
0011 110w : immediate data
immediate with memory
1000 00sw : mod 111 r/m : immediate data
CMPS/CMPSB/CMPSW/CMPSD - Compare String Operands
1010 011w
CMPXCHG - Compare and Exchange
register1, register2
0000 1111 : 1011 000w : 11 reg2 reg1
memory, register
0000 1111 : 1011 000w : mod reg r/m
CPUID - CPU Identification
0000 1111 : 1010 0010
CWD - Convert Word to Doubleword
1001 1001
CWDE - Convert Word to Doubleword
1001 1000
DAA - Decimal Adjust AL after Addition
0010 0111
DAS - Decimal Adjust AL after Subtraction
0010 1111
DEC - Decrement by 1
register
1111 111w : 11 001 reg
register (alternate encoding)
0100 1 reg
memory
1111 111w : mod 001 r/m
DIV - Unsigned Divide
AL, AX, or EAX by register
1111 011w : 11 110 reg
AL, AX, or EAX by memory
1111 011w : mod 110 r/m
HLT - Halt
1111 0100
IDIV - Signed Divide
AL, AX, or EAX by register
1111 011w : 11 111 reg
AL, AX, or EAX by memory
1111 011w : mod 111 r/m
Vol. 2D B-9
INSTRUCTION FORMATS AND ENCODINGS
Table B-13. General Purpose Instruction Formats and Encodings for Non-64-Bit Modes (Contd.)
Instruction and Format
Encoding
IMUL - Signed Multiply
AL, AX, or EAX with register
1111 011w : 11 101 reg
AL, AX, or EAX with memory
1111 011w : mod 101 reg
register1 with register2
0000 1111 : 1010 1111 : 11 : reg1 reg2
register with memory
0000 1111 : 1010 1111 : mod reg r/m
register1 with immediate to register2
0110 10s1 : 11 reg1 reg2 : immediate data
memory with immediate to register
0110 10s1 : mod reg r/m : immediate data
IN - Input From Port
fixed port
1110 010w : port number
variable port
1110 110w
INC - Increment by 1
reg
1111 111w : 11 000 reg
reg (alternate encoding)
0100 0 reg
memory
1111 111w : mod 000 r/m
INS - Input from DX Port
0110 110w
INT n - Interrupt Type n
1100 1101 : type
INT - Single-Step Interrupt 3
1100 1100
INTO - Interrupt 4 on Overflow
1100 1110
INVD - Invalidate Cache
0000 1111 : 0000 1000
INVLPG - Invalidate TLB Entry
0000 1111 : 0000 0001 : mod 111 r/m
INVPCID - Invalidate Process-Context Identifier
0110 0110:0000 1111:0011 1000:1000 0010: mod reg r/m
IRET/IRETD - Interrupt Return
1100 1111
Jcc - Jump if Condition is Met
8-bit displacement
0111 tttn : 8-bit displacement
full displacement
0000 1111 : 1000 tttn : full displacement
JCXZ/JECXZ - Jump on CX/ECX Zero
Address-size prefix differentiates JCXZ
1110 0011 : 8-bit displacement
and JECXZ
JMP - Unconditional Jump (to same segment)
short
1110 1011 : 8-bit displacement
direct
1110 1001 : full displacement
register indirect
1111 1111 : 11 100 reg
memory indirect
1111 1111 : mod 100 r/m
JMP - Unconditional Jump (to other segment)
direct intersegment
1110 1010 : unsigned full offset, selector
indirect intersegment
1111 1111 : mod 101 r/m
LAHF - Load Flags into AHRegister
1001 1111
B-10
Vol. 2D
INSTRUCTION FORMATS AND ENCODINGS
Table B-13. General Purpose Instruction Formats and Encodings for Non-64-Bit Modes (Contd.)
Instruction and Format
Encoding
LAR - Load Access Rights Byte
from register
0000 1111 : 0000 0010 : 11 reg1 reg2
from memory
0000 1111 : 0000 0010 : mod reg r/m
LDS - Load Pointer to DS
1100 0101 : modA,B reg r/m
LEA - Load Effective Address
1000 1101 : modA reg r/m
LEAVE - High Level Procedure Exit
1100 1001
LES - Load Pointer to ES
1100 0100 : modA,B reg r/m
LFS - Load Pointer to FS
0000 1111 : 1011 0100 : modA reg r/m
LGDT - Load Global Descriptor Table Register
0000 1111 : 0000 0001 : modA 010 r/m
LGS - Load Pointer to GS
0000 1111 : 1011 0101 : modA reg r/m
LIDT - Load Interrupt Descriptor Table Register
0000 1111 : 0000 0001 : modA 011 r/m
LLDT - Load Local Descriptor Table Register
LDTR from register
0000 1111 : 0000 0000 : 11 010 reg
LDTR from memory
0000 1111 : 0000 0000 : mod 010 r/m
LMSW - Load Machine Status Word
from register
0000 1111 : 0000 0001 : 11 110 reg
from memory
0000 1111 : 0000 0001 : mod 110 r/m
LOCK - Assert LOCK# Signal Prefix
1111 0000
LODS/LODSB/LODSW/LODSD - Load String Operand
1010 110w
LOOP - Loop Count
1110 0010 : 8-bit displacement
LOOPZ/LOOPE - Loop Count while Zero/Equal
1110 0001 : 8-bit displacement
LOOPNZ/LOOPNE - Loop Count while not Zero/Equal
1110 0000 : 8-bit displacement
LSL - Load Segment Limit
from register
0000 1111 : 0000 0011 : 11 reg1 reg2
from memory
0000 1111 : 0000 0011 : mod reg r/m
LSS - Load Pointer to SS
0000 1111 : 1011 0010 : modA reg r/m
LTR - Load Task Register
from register
0000 1111 : 0000 0000 : 11 011 reg
from memory
0000 1111 : 0000 0000 : mod 011 r/m
MOV - Move Data
register1 to register2
1000 100w : 11 reg1 reg2
register2 to register1
1000 101w : 11 reg1 reg2
memory to reg
1000 101w : mod reg r/m
reg to memory
1000 100w : mod reg r/m
immediate to register
1100 011w : 11 000 reg : immediate data
immediate to register (alternate encoding)
1011 w reg : immediate data
immediate to memory
1100 011w : mod 000 r/m : immediate data
memory to AL, AX, or EAX
1010 000w : full displacement
Vol. 2D B-11
INSTRUCTION FORMATS AND ENCODINGS
Table B-13. General Purpose Instruction Formats and Encodings for Non-64-Bit Modes (Contd.)
Instruction and Format
Encoding
AL, AX, or EAX to memory
1010 001w : full displacement
MOV - Move to/from Control Registers
CR0 from register
0000 1111 : 0010 0010 : -- 000 reg
CR2 from register
0000 1111 : 0010 0010 : -- 010reg
CR3 from register
0000 1111 : 0010 0010 : -- 011 reg
CR4 from register
0000 1111 : 0010 0010 : -- 100 reg
register from CR0-CR4
0000 1111 : 0010 0000 : -- eee reg
MOV - Move to/from Debug Registers
DR0-DR3 from register
0000 1111 : 0010 0011 : -- eee reg
DR4-DR5 from register
0000 1111 : 0010 0011 : -- eee reg
DR6-DR7 from register
0000 1111 : 0010 0011 : -- eee reg
register from DR6-DR7
0000 1111 : 0010 0001 : -- eee reg
register from DR4-DR5
0000 1111 : 0010 0001 : -- eee reg
register from DR0-DR3
0000 1111 : 0010 0001 : -- eee reg
MOV - Move to/from Segment Registers
register to segment register
1000 1110 : 11 sreg3 reg
register to SS
1000 1110 : 11 sreg3 reg
memory to segment reg
1000 1110 : mod sreg3 r/m
memory to SS
1000 1110 : mod sreg3 r/m
segment register to register
1000 1100 : 11 sreg3 reg
segment register to memory
1000 1100 : mod sreg3 r/m
MOVBE - Move data after swapping bytes
memory to register
0000 1111 : 0011 1000:1111 0000 : mod reg r/m
register to memory
0000 1111 : 0011 1000:1111 0001 : mod reg r/m
MOVS/MOVSB/MOVSW/MOVSD - Move Data from String to
1010 010w
String
MOVSX - Move with Sign-Extend
memory to reg
0000 1111 : 1011 111w : mod reg r/m
MOVZX - Move with Zero-Extend
register2 to register1
0000 1111 : 1011 011w : 11 reg1 reg2
memory to register
0000 1111 : 1011 011w : mod reg r/m
MUL - Unsigned Multiply
AL, AX, or EAX with register
1111 011w : 11 100 reg
AL, AX, or EAX with memory
1111 011w : mod 100 r/m
NEG - Two's Complement Negation
register
1111 011w : 11 011 reg
memory
1111 011w : mod 011 r/m
NOP - No Operation
1001 0000
B-12
Vol. 2D
INSTRUCTION FORMATS AND ENCODINGS
Table B-13. General Purpose Instruction Formats and Encodings for Non-64-Bit Modes (Contd.)
Instruction and Format
Encoding
NOP - Multi-byte No Operation1
register
0000 1111 0001 1111 : 11 000 reg
memory
0000 1111 0001 1111 : mod 000 r/m
NOT - One's Complement Negation
register
1111 011w : 11 010 reg
memory
1111 011w : mod 010 r/m
OR - Logical Inclusive OR
register1 to register2
0000 100w : 11 reg1 reg2
register2 to register1
0000 101w : 11 reg1 reg2
memory to register
0000 101w : mod reg r/m
register to memory
0000 100w : mod reg r/m
immediate to register
1000 00sw : 11 001 reg : immediate data
immediate to AL, AX, or EAX
0000 110w : immediate data
immediate to memory
1000 00sw : mod 001 r/m : immediate data
OUT - Output to Port
fixed port
1110 011w : port number
variable port
1110 111w
OUTS - Output to DX Port
0110 111w
POP - Pop a Word from the Stack
register
1000 1111 : 11 000 reg
register (alternate encoding)
0101 1 reg
memory
1000 1111 : mod 000 r/m
POP - Pop a Segment Register from the Stack (Note: CS cannot be sreg2 in this usage.)
segment register DS, ES
000 sreg2 111
segment register SS
000 sreg2 111
segment register FS, GS
0000 1111: 10 sreg3 001
POPA/POPAD - Pop All General Registers
0110 0001
POPF/POPFD - Pop Stack into FLAGS or EFLAGS Register
1001 1101
PUSH - Push Operand onto the Stack
register
1111 1111 : 11 110 reg
register (alternate encoding)
0101 0 reg
memory
1111 1111 : mod 110 r/m
immediate
0110 10s0 : immediate data
PUSH - Push Segment Register onto the Stack
segment register CS,DS,ES,SS
000 sreg2 110
segment register FS,GS
0000 1111: 10 sreg3 000
PUSHA/PUSHAD - Push All General Registers
0110 0000
Vol. 2D
B-13
INSTRUCTION FORMATS AND ENCODINGS
Table B-13. General Purpose Instruction Formats and Encodings for Non-64-Bit Modes (Contd.)
Instruction and Format
Encoding
PUSHF/PUSHFD - Push Flags Register onto the Stack
1001 1100
RCL - Rotate thru Carry Left
register by 1
1101 000w : 11 010 reg
memory by 1
1101 000w : mod 010 r/m
register by CL
1101 001w : 11 010 reg
memory by CL
1101 001w : mod 010 r/m
register by immediate count
1100 000w : 11 010 reg : imm8 data
memory by immediate count
1100 000w : mod 010 r/m : imm8 data
RCR - Rotate thru Carry Right
register by 1
1101 000w : 11 011 reg
memory by 1
1101 000w : mod 011 r/m
register by CL
1101 001w : 11 011 reg
memory by CL
1101 001w : mod 011 r/m
register by immediate count
1100 000w : 11 011 reg : imm8 data
memory by immediate count
1100 000w : mod 011 r/m : imm8 data
RDMSR - Read from Model-Specific Register
0000 1111 : 0011 0010
RDPMC - Read Performance Monitoring Counters
0000 1111 : 0011 0011
RDTSC - Read Time-Stamp Counter
0000 1111 : 0011 0001
RDTSCP - Read Time-Stamp Counter and Processor ID
0000 1111 : 0000 0001: 1111 1001
REP INS - Input String
1111 0011 : 0110 110w
REP LODS - Load String
1111 0011 : 1010 110w
REP MOVS - Move String
1111 0011 : 1010 010w
REP OUTS - Output String
1111 0011 : 0110 111w
REP STOS - Store String
1111 0011 : 1010 101w
REPE CMPS - Compare String
1111 0011 : 1010 011w
REPE SCAS - Scan String
1111 0011 : 1010 111w
REPNE CMPS - Compare String
1111 0010 : 1010 011w
REPNE SCAS - Scan String
1111 0010 : 1010 111w
RET - Return from Procedure (to same segment)
no argument
1100 0011
adding immediate to SP
1100 0010 : 16-bit displacement
RET - Return from Procedure (to other segment)
intersegment
1100 1011
adding immediate to SP
1100 1010 : 16-bit displacement
B-14
Vol. 2D
INSTRUCTION FORMATS AND ENCODINGS
Table B-13. General Purpose Instruction Formats and Encodings for Non-64-Bit Modes (Contd.)
Instruction and Format
Encoding
ROL - Rotate Left
register by 1
1101 000w : 11 000 reg
memory by 1
1101 000w : mod 000 r/m
register by CL
1101 001w : 11 000 reg
memory by CL
1101 001w : mod 000 r/m
register by immediate count
1100 000w : 11 000 reg : imm8 data
memory by immediate count
1100 000w : mod 000 r/m : imm8 data
ROR - Rotate Right
register by 1
1101 000w : 11 001 reg
memory by 1
1101 000w : mod 001 r/m
register by CL
1101 001w : 11 001 reg
memory by CL
1101 001w : mod 001 r/m
register by immediate count
1100 000w : 11 001 reg : imm8 data
memory by immediate count
1100 000w : mod 001 r/m : imm8 data
RSM - Resume from System Management Mode
0000 1111 : 1010 1010
SAHF - Store AH into Flags
1001 1110
SAL - Shift Arithmetic Left
same instruction as SHL
SAR - Shift Arithmetic Right
register by 1
1101 000w : 11 111 reg
memory by 1
1101 000w : mod 111 r/m
register by CL
1101 001w : 11 111 reg
memory by CL
1101 001w : mod 111 r/m
register by immediate count
1100 000w : 11 111 reg : imm8 data
memory by immediate count
1100 000w : mod 111 r/m : imm8 data
SBB - Integer Subtraction with Borrow
register1 to register2
0001 100w : 11 reg1 reg2
register2 to register1
0001 101w : 11 reg1 reg2
memory to register
0001 101w : mod reg r/m
register to memory
0001 100w : mod reg r/m
immediate to register
1000 00sw : 11 011 reg : immediate data
immediate to AL, AX, or EAX
0001 110w : immediate data
immediate to memory
1000 00sw : mod 011 r/m : immediate data
SCAS/SCASB/SCASW/SCASD - Scan String
1010 111w
SETcc - Byte Set on Condition
register
0000 1111 : 1001 tttn : 11 000 reg
memory
0000 1111 : 1001 tttn : mod 000 r/m
SGDT - Store Global Descriptor Table Register
0000 1111 : 0000 0001 : modA 000 r/m
Vol. 2D B-15
INSTRUCTION FORMATS AND ENCODINGS
Table B-13. General Purpose Instruction Formats and Encodings for Non-64-Bit Modes (Contd.)
Instruction and Format
Encoding
SHL - Shift Left
register by 1
1101 000w : 11 100 reg
memory by 1
1101 000w : mod 100 r/m
register by CL
1101 001w : 11 100 reg
memory by CL
1101 001w : mod 100 r/m
register by immediate count
1100 000w : 11 100 reg : imm8 data
memory by immediate count
1100 000w : mod 100 r/m : imm8 data
SHLD - Double Precision Shift Left
register by immediate count
0000 1111 : 1010 0100 : 11 reg2 reg1 : imm8
memory by immediate count
0000 1111 : 1010 0100 : mod reg r/m : imm8
register by CL
0000 1111 : 1010 0101 : 11 reg2 reg1
memory by CL
0000 1111 : 1010 0101 : mod reg r/m
SHR - Shift Right
register by 1
1101 000w : 11 101 reg
memory by 1
1101 000w : mod 101 r/m
register by CL
1101 001w : 11 101 reg
memory by CL
1101 001w : mod 101 r/m
register by immediate count
1100 000w : 11 101 reg : imm8 data
memory by immediate count
1100 000w : mod 101 r/m : imm8 data
SHRD - Double Precision Shift Right
register by immediate count
0000 1111 : 1010 1100 : 11 reg2 reg1 : imm8
memory by immediate count
0000 1111 : 1010 1100 : mod reg r/m : imm8
register by CL
0000 1111 : 1010 1101 : 11 reg2 reg1
memory by CL
0000 1111 : 1010 1101 : mod reg r/m
SIDT - Store Interrupt Descriptor Table Register
0000 1111 : 0000 0001 : modA 001 r/m
SLDT - Store Local Descriptor Table Register
to register
0000 1111 : 0000 0000 : 11 000 reg
to memory
0000 1111 : 0000 0000 : mod 000 r/m
SMSW - Store Machine Status Word
to register
0000 1111 : 0000 0001 : 11 100 reg
to memory
0000 1111 : 0000 0001 : mod 100 r/m
STC - Set Carry Flag
1111 1001
STD - Set Direction Flag
1111 1101
STI - Set Interrupt Flag
1111 1011
STOS/STOSB/STOSW/STOSD - Store String Data
1010 101w
STR - Store Task Register
to register
0000 1111 : 0000 0000 : 11 001 reg
to memory
0000 1111 : 0000 0000 : mod 001 r/m
B-16
Vol. 2D
INSTRUCTION FORMATS AND ENCODINGS
Table B-13. General Purpose Instruction Formats and Encodings for Non-64-Bit Modes (Contd.)
Instruction and Format
Encoding
SUB - Integer Subtraction
register1 to register2
0010 100w : 11 reg1 reg2
register2 to register1
0010 101w : 11 reg1 reg2
memory to register
0010 101w : mod reg r/m
register to memory
0010 100w : mod reg r/m
immediate to register
1000 00sw : 11 101 reg : immediate data
immediate to AL, AX, or EAX
0010 110w : immediate data
immediate to memory
1000 00sw : mod 101 r/m : immediate data
TEST - Logical Compare
register1 and register2
1000 010w : 11 reg1 reg2
memory and register
1000 010w : mod reg r/m
immediate and register
1111 011w : 11 000 reg : immediate data
immediate and AL, AX, or EAX
1010 100w : immediate data
immediate and memory
1111 011w : mod 000 r/m : immediate data
UD0 - Undefined instruction
0000 1111 : 1111 1111
UD1 - Undefined instruction
0000 1111 : 0000 1011
UD2 - Undefined instruction
0000 FFFF : 0000 1011
VERR - Verify a Segment for Reading
register
0000 1111 : 0000 0000 : 11 100 reg
memory
0000 1111 : 0000 0000 : mod 100 r/m
VERW - Verify a Segment for Writing
register
0000 1111 : 0000 0000 : 11 101 reg
memory
0000 1111 : 0000 0000 : mod 101 r/m
WAIT - Wait
1001 1011
WBINVD - Writeback and Invalidate Data Cache
0000 1111 : 0000 1001
WRMSR - Write to Model-Specific Register
0000 1111 : 0011 0000
XADD - Exchange and Add
register1, register2
0000 1111 : 1100 000w : 11 reg2 reg1
memory, reg
0000 1111 : 1100 000w : mod reg r/m
XCHG - Exchange Register/Memory with Register
register1 with register2
1000 011w : 11 reg1 reg2
AX or EAX with reg
1001 0 reg
memory with reg
1000 011w : mod reg r/m
XLAT/XLATB - Table Look-up Translation
1101 0111
XOR - Logical Exclusive OR
register1 to register2
0011 000w : 11 reg1 reg2
register2 to register1
0011 001w : 11 reg1 reg2
memory to register
0011 001w : mod reg r/m
Vol. 2D B-17
INSTRUCTION FORMATS AND ENCODINGS
Table B-13. General Purpose Instruction Formats and Encodings for Non-64-Bit Modes (Contd.)
Instruction and Format
Encoding
register to memory
0011 000w : mod reg r/m
immediate to register
1000 00sw : 11 110 reg : immediate data
immediate to AL, AX, or EAX
0011 010w : immediate data
immediate to memory
1000 00sw : mod 110 r/m : immediate data
Prefix Bytes
address size
0110 0111
LOCK
1111 0000
operand size
0110 0110
CS segment override
0010 1110
DS segment override
0011 1110
ES segment override
0010 0110
FS segment override
0110 0100
GS segment override
0110 0101
SS segment override
0011 0110
NOTES:
1. The multi-byte NOP instruction does not alter the content of the register and will not issue a memory operation.
B.2.1
General Purpose Instruction Formats and Encodings for 64-Bit Mode
Table B-15 shows machine instruction formats and encodings for general purpose instructions in 64-bit mode.
Table B-14. Special Symbols
Symbol
Application
S
If the value of REX.W. is 1, it overrides the presence of 66H.
w
The value of bit W. in REX is has no effect.
Table B-15. General Purpose Instruction Formats and Encodings for 64-Bit Mode
Instruction and Format
Encoding
ADC - ADD with Carry
register1 to register2
0100 0R0B : 0001 000w : 11 reg1 reg2
qwordregister1 to qwordregister2
0100 1R0B : 0001 0001 : 11 qwordreg1 qwordreg2
register2 to register1
0100 0R0B : 0001 001w : 11 reg1 reg2
qwordregister1 to qwordregister2
0100 1R0B : 0001 0011 : 11 qwordreg1 qwordreg2
memory to register
0100 0RXB : 0001 001w : mod reg r/m
memory to qwordregister
0100 1RXB : 0001 0011 : mod qwordreg r/m
register to memory
0100 0RXB : 0001 000w : mod reg r/m
qwordregister to memory
0100 1RXB : 0001 0001 : mod qwordreg r/m
immediate to register
0100 000B : 1000 00sw : 11 010 reg : immediate
immediate to qwordregister
0100 100B : 1000 0001 : 11 010 qwordreg : imm32
immediate to qwordregister
0100 1R0B : 1000 0011 : 11 010 qwordreg : imm8
B-18
Vol. 2D
INSTRUCTION FORMATS AND ENCODINGS
Table B-15. General Purpose Instruction Formats and Encodings for 64-Bit Mode (Contd.)
Instruction and Format
Encoding
immediate to AL, AX, or EAX
0001 010w : immediate data
immediate to RAX
0100 1000 : 0000 0101 : imm32
immediate to memory
0100 00XB : 1000 00sw : mod 010 r/m : immediate
immediate32 to memory64
0100 10XB : 1000 0001 : mod 010 r/m : imm32
immediate8 to memory64
0100 10XB : 1000 0031 : mod 010 r/m : imm8
ADD - Add
register1 to register2
0100 0R0B : 0000 000w : 11 reg1 reg2
qwordregister1 to qwordregister2
0100 1R0B 0000 0000 : 11 qwordreg1 qwordreg2
register2 to register1
0100 0R0B : 0000 001w : 11 reg1 reg2
qwordregister1 to qwordregister2
0100 1R0B 0000 0010 : 11 qwordreg1 qwordreg2
memory to register
0100 0RXB : 0000 001w : mod reg r/m
memory64 to qwordregister
0100 1RXB : 0000 0000 : mod qwordreg r/m
register to memory
0100 0RXB : 0000 000w : mod reg r/m
qwordregister to memory64
0100 1RXB : 0000 0011 : mod qwordreg r/m
immediate to register
0100 0000B : 1000 00sw : 11 000 reg : immediate data
immediate32 to qwordregister
0100 100B : 1000 0001 : 11 010 qwordreg : imm
immediate to AL, AX, or EAX
0000 010w : immediate8
immediate to RAX
0100 1000 : 0000 0101 : imm32
immediate to memory
0100 00XB : 1000 00sw : mod 000 r/m : immediate
immediate32 to memory64
0100 10XB : 1000 0001 : mod 010 r/m : imm32
immediate8 to memory64
0100 10XB : 1000 0011 : mod 010 r/m : imm8
AND - Logical AND
register1 to register2
0100 0R0B 0010 000w : 11 reg1 reg2
qwordregister1 to qwordregister2
0100 1R0B 0010 0001 : 11 qwordreg1 qwordreg2
register2 to register1
0100 0R0B 0010 001w : 11 reg1 reg2
register1 to register2
0100 1R0B 0010 0011 : 11 qwordreg1 qwordreg2
memory to register
0100 0RXB 0010 001w : mod reg r/m
memory64 to qwordregister
0100 1RXB : 0010 0011 : mod qwordreg r/m
register to memory
0100 0RXB : 0010 000w : mod reg r/m
qwordregister to memory64
0100 1RXB : 0010 0001 : mod qwordreg r/m
immediate to register
0100 000B : 1000 00sw : 11 100 reg : immediate
immediate32 to qwordregister
0100 100B 1000 0001 : 11 100 qwordreg : imm32
immediate to AL, AX, or EAX
0010 010w : immediate
immediate32 to RAX
0100 1000 0010 1001 : imm32
immediate to memory
0100 00XB : 1000 00sw : mod 100 r/m : immediate
immediate32 to memory64
0100 10XB : 1000 0001 : mod 100 r/m : immediate32
immediate8 to memory64
0100 10XB : 1000 0011 : mod 100 r/m : imm8
BSF - Bit Scan Forward
Vol. 2D B-19
INSTRUCTION FORMATS AND ENCODINGS
Table B-15. General Purpose Instruction Formats and Encodings for 64-Bit Mode (Contd.)
Instruction and Format
Encoding
register1, register2
0100 0R0B 0000 1111 : 1011 1100 : 11 reg1 reg2
qwordregister1, qwordregister2
0100 1R0B 0000 1111 : 1011 1100 : 11 qwordreg1
qwordreg2
memory, register
0100 0RXB 0000 1111 : 1011 1100 : mod reg r/m
memory64, qwordregister
0100 1RXB 0000 1111 : 1011 1100 : mod qwordreg r/m
BSR - Bit Scan Reverse
register1, register2
0100 0R0B 0000 1111 : 1011 1101 : 11 reg1 reg2
qwordregister1, qwordregister2
0100 1R0B 0000 1111 : 1011 1101 : 11 qwordreg1
qwordreg2
memory, register
0100 0RXB 0000 1111 : 1011 1101 : mod reg r/m
memory64, qwordregister
0100 1RXB 0000 1111 : 1011 1101 : mod qwordreg r/m
BSWAP - Byte Swap
0000 1111 : 1100 1 reg
BSWAP - Byte Swap
0100 100B 0000 1111 : 1100 1 qwordreg
BT - Bit Test
register, immediate
0100 000B 0000 1111 : 1011 1010 : 11 100 reg: imm8
qwordregister, immediate8
0100 100B 1111 : 1011 1010 : 11 100 qwordreg: imm8 data
memory, immediate
0100 00XB 0000 1111 : 1011 1010 : mod 100 r/m : imm8
memory64, immediate8
0100 10XB 0000 1111 : 1011 1010 : mod 100 r/m : imm8 data
register1, register2
0100 0R0B 0000 1111 : 1010 0011 : 11 reg2 reg1
qwordregister1, qwordregister2
0100 1R0B 0000 1111 : 1010 0011 : 11 qwordreg2
qwordreg1
memory, reg
0100 0RXB 0000 1111 : 1010 0011 : mod reg r/m
memory, qwordreg
0100 1RXB 0000 1111 : 1010 0011 : mod qwordreg r/m
BTC - Bit Test and Complement
register, immediate
0100 000B 0000 1111 : 1011 1010 : 11 111 reg: imm8
qwordregister, immediate8
0100 100B 0000 1111 : 1011 1010 : 11 111 qwordreg: imm8
memory, immediate
0100 00XB 0000 1111 : 1011 1010 : mod 111 r/m : imm8
memory64, immediate8
0100 10XB 0000 1111 : 1011 1010 : mod 111 r/m : imm8
register1, register2
0100 0R0B 0000 1111 : 1011 1011 : 11 reg2 reg1
qwordregister1, qwordregister2
0100 1R0B 0000 1111 : 1011 1011 : 11 qwordreg2
qwordreg1
memory, register
0100 0RXB 0000 1111 : 1011 1011 : mod reg r/m
memory, qwordreg
0100 1RXB 0000 1111 : 1011 1011 : mod qwordreg r/m
BTR - Bit Test and Reset
register, immediate
0100 000B 0000 1111 : 1011 1010 : 11 110 reg: imm8
qwordregister, immediate8
0100 100B 0000 1111 : 1011 1010 : 11 110 qwordreg: imm8
memory, immediate
0100 00XB 0000 1111 : 1011 1010 : mod 110 r/m : imm8
memory64, immediate8
0100 10XB 0000 1111 : 1011 1010 : mod 110 r/m : imm8
register1, register2
0100 0R0B 0000 1111 : 1011 0011 : 11 reg2 reg1
B-20
Vol. 2D
INSTRUCTION FORMATS AND ENCODINGS
Table B-15. General Purpose Instruction Formats and Encodings for 64-Bit Mode (Contd.)
Instruction and Format
Encoding
qwordregister1, qwordregister2
0100 1R0B 0000 1111 : 1011 0011 : 11 qwordreg2
qwordreg1
memory, register
0100 0RXB 0000 1111 : 1011 0011 : mod reg r/m
memory64, qwordreg
0100 1RXB 0000 1111 : 1011 0011 : mod qwordreg r/m
BTS - Bit Test and Set
register, immediate
0100 000B 0000 1111 : 1011 1010 : 11 101 reg: imm8
qwordregister, immediate8
0100 100B 0000 1111 : 1011 1010 : 11 101 qwordreg: imm8
memory, immediate
0100 00XB 0000 1111 : 1011 1010 : mod 101 r/m : imm8
memory64, immediate8
0100 10XB 0000 1111 : 1011 1010 : mod 101 r/m : imm8
register1, register2
0100 0R0B 0000 1111 : 1010 1011 : 11 reg2 reg1
qwordregister1, qwordregister2
0100 1R0B 0000 1111 : 1010 1011 : 11 qwordreg2
qwordreg1
memory, register
0100 0RXB 0000 1111 : 1010 1011 : mod reg r/m
memory64, qwordreg
0100 1RXB 0000 1111 : 1010 1011 : mod qwordreg r/m
CALL - Call Procedure (in same segment)
direct
1110 1000 : displacement32
register indirect
0100 WR00w 1111 1111 : 11 010 reg
memory indirect
0100 W0XBw 1111 1111 : mod 010 r/m
CALL - Call Procedure (in other segment)
indirect
1111 1111 : mod 011 r/m
indirect
0100 10XB 0100 1000 1111 1111 : mod 011 r/m
CBW - Convert Byte to Word
1001 1000
CDQ - Convert Doubleword to Qword+
1001 1001
CDQE - RAX, Sign-Extend of EAX
0100 1000 1001 1001
CLC - Clear Carry Flag
1111 1000
CLD - Clear Direction Flag
1111 1100
CLI - Clear Interrupt Flag
1111 1010
CLTS - Clear Task-Switched Flag in CR0
0000 1111 : 0000 0110
CMC - Complement Carry Flag
1111 0101
CMP - Compare Two Operands
register1 with register2
0100 0R0B 0011 100w : 11 reg1 reg2
qwordregister1 with qwordregister2
0100 1R0B 0011 1001 : 11 qwordreg1 qwordreg2
register2 with register1
0100 0R0B 0011 101w : 11 reg1 reg2
qwordregister2 with qwordregister1
0100 1R0B 0011 101w : 11 qwordreg1 qwordreg2
memory with register
0100 0RXB 0011 100w : mod reg r/m
memory64 with qwordregister
0100 1RXB 0011 1001 : mod qwordreg r/m
register with memory
0100 0RXB 0011 101w : mod reg r/m
qwordregister with memory64
0100 1RXB 0011 101w1 : mod qwordreg r/m
immediate with register
0100 000B 1000 00sw : 11 111 reg : imm
Vol. 2D B-21
INSTRUCTION FORMATS AND ENCODINGS
Table B-15. General Purpose Instruction Formats and Encodings for 64-Bit Mode (Contd.)
Instruction and Format
Encoding
immediate32 with qwordregister
0100 100B 1000 0001 : 11 111 qwordreg : imm64
immediate with AL, AX, or EAX
0011 110w : imm
immediate32 with RAX
0100 1000 0011 1101 : imm32
immediate with memory
0100 00XB 1000 00sw : mod 111 r/m : imm
immediate32 with memory64
0100 1RXB 1000 0001 : mod 111 r/m : imm64
immediate8 with memory64
0100 1RXB 1000 0011 : mod 111 r/m : imm8
CMPS/CMPSB/CMPSW/CMPSD/CMPSQ - Compare String Operands
compare string operands [ X at DS:(E)SI with Y at ES:(E)DI ]
1010 011w
qword at address RSI with qword at address RDI
0100 1000 1010 0111
CMPXCHG - Compare and Exchange
register1, register2
0000 1111 : 1011 000w : 11 reg2 reg1
byteregister1, byteregister2
0100 000B 0000 1111 : 1011 0000 : 11 bytereg2 reg1
qwordregister1, qwordregister2
0100 100B 0000 1111 : 1011 0001 : 11 qwordreg2 reg1
memory, register
0000 1111 : 1011 000w : mod reg r/m
memory8, byteregister
0100 00XB 0000 1111 : 1011 0000 : mod bytereg r/m
memory64, qwordregister
0100 10XB 0000 1111 : 1011 0001 : mod qwordreg r/m
CPUID - CPU Identification
0000 1111 : 1010 0010
CQO - Sign-Extend RAX
0100 1000 1001 1001
CWD - Convert Word to Doubleword
1001 1001
CWDE - Convert Word to Doubleword
1001 1000
DEC - Decrement by 1
register
0100 000B 1111 111w : 11 001 reg
qwordregister
0100 100B 1111 1111 : 11 001 qwordreg
memory
0100 00XB 1111 111w : mod 001 r/m
memory64
0100 10XB 1111 1111 : mod 001 r/m
DIV - Unsigned Divide
AL, AX, or EAX by register
0100 000B 1111 011w : 11 110 reg
Divide RDX:RAX by qwordregister
0100 100B 1111 0111 : 11 110 qwordreg
AL, AX, or EAX by memory
0100 00XB 1111 011w : mod 110 r/m
Divide RDX:RAX by memory64
0100 10XB 1111 0111 : mod 110 r/m
ENTER - Make Stack Frame for High Level Procedure
1100 1000 : 16-bit displacement : 8-bit level (L)
HLT - Halt
1111 0100
IDIV - Signed Divide
AL, AX, or EAX by register
0100 000B 1111 011w : 11 111 reg
RDX:RAX by qwordregister
0100 100B 1111 0111 : 11 111 qwordreg
AL, AX, or EAX by memory
0100 00XB 1111 011w : mod 111 r/m
RDX:RAX by memory64
0100 10XB 1111 0111 : mod 111 r/m
IMUL - Signed Multiply
B-22
Vol. 2D
INSTRUCTION FORMATS AND ENCODINGS
Table B-15. General Purpose Instruction Formats and Encodings for 64-Bit Mode (Contd.)
Instruction and Format
Encoding
AL, AX, or EAX with register
0100 000B 1111 011w : 11 101 reg
RDX:RAX := RAX with qwordregister
0100 100B 1111 0111 : 11 101 qwordreg
AL, AX, or EAX with memory
0100 00XB 1111 011w : mod 101 r/m
RDX:RAX := RAX with memory64
0100 10XB 1111 0111 : mod 101 r/m
register1 with register2
0000 1111 : 1010 1111 : 11 : reg1 reg2
qwordregister1 := qwordregister1 with qwordregister2
0100 1R0B 0000 1111 : 1010 1111 : 11 : qwordreg1
qwordreg2
register with memory
0100 0RXB 0000 1111 : 1010 1111 : mod reg r/m
qwordregister := qwordregister with memory64
0100 1RXB 0000 1111 : 1010 1111 : mod qwordreg r/m
register1 with immediate to register2
0100 0R0B 0110 10s1 : 11 reg1 reg2 : imm
qwordregister1 := qwordregister2 with sign-extended
0100 1R0B 0110 1011 : 11 qwordreg1 qwordreg2 : imm8
immediate8
qwordregister1 := qwordregister2 with immediate32
0100 1R0B 0110 1001 : 11 qwordreg1 qwordreg2 : imm32
memory with immediate to register
0100 0RXB 0110 10s1 : mod reg r/m : imm
qwordregister := memory64 with sign-extended immediate8
0100 1RXB 0110 1011 : mod qwordreg r/m : imm8
qwordregister := memory64 with immediate32
0100 1RXB 0110 1001 : mod qwordreg r/m : imm32
IN - Input From Port
fixed port
1110 010w : port number
variable port
1110 110w
INC - Increment by 1
reg
0100 000B 1111 111w : 11 000 reg
qwordreg
0100 100B 1111 1111 : 11 000 qwordreg
memory
0100 00XB 1111 111w : mod 000 r/m
memory64
0100 10XB 1111 1111 : mod 000 r/m
INS - Input from DX Port
0110 110w
INT n - Interrupt Type n
1100 1101 : type
INT - Single-Step Interrupt 3
1100 1100
INTO - Interrupt 4 on Overflow
1100 1110
INVD - Invalidate Cache
0000 1111 : 0000 1000
INVLPG - Invalidate TLB Entry
0000 1111 : 0000 0001 : mod 111 r/m
INVPCID - Invalidate Process-Context Identifier
0110 0110:0000 1111:0011 1000:1000 0010: mod reg r/m
IRETO - Interrupt Return
1100 1111
Jcc - Jump if Condition is Met
8-bit displacement
0111 tttn : 8-bit displacement
displacements (excluding 16-bit relative offsets)
0000 1111 : 1000 tttn : displacement32
JCXZ/JECXZ - Jump on CX/ECX Zero
Address-size prefix differentiates JCXZ and JECXZ
1110 0011 : 8-bit displacement
JMP - Unconditional Jump (to same segment)
short
1110 1011 : 8-bit displacement
Vol. 2D B-23
INSTRUCTION FORMATS AND ENCODINGS
Table B-15. General Purpose Instruction Formats and Encodings for 64-Bit Mode (Contd.)
Instruction and Format
Encoding
direct
1110 1001 : displacement32
register indirect
0100 W00Bw : 1111 1111 : 11 100 reg
memory indirect
0100 W0XBw : 1111 1111 : mod 100 r/m
JMP - Unconditional Jump (to other segment)
indirect intersegment
0100 00XB : 1111 1111 : mod 101 r/m
64-bit indirect intersegment
0100 10XB : 1111 1111 : mod 101 r/m
LAR - Load Access Rights Byte
from register
0100 0R0B : 0000 1111 : 0000 0010 : 11 reg1 reg2
from dwordregister to qwordregister, masked by 00FxFF00H
0100 WR0B : 0000 1111 : 0000 0010 : 11 qwordreg1
dwordreg2
from memory
0100 0RXB : 0000 1111 : 0000 0010 : mod reg r/m
from memory32 to qwordregister, masked by 00FxFF00H
0100 WRXB 0000 1111 : 0000 0010 : mod r/m
LEA - Load Effective Address
in wordregister/dwordregister
0100 0RXB : 1000 1101 : modA reg r/m
in qwordregister
0100 1RXB : 1000 1101 : modA qwordreg r/m
LEAVE - High Level Procedure Exit
1100 1001
LFS - Load Pointer to FS
FS:r16/r32 with far pointer from memory
0100 0RXB : 0000 1111 : 1011 0100 : modA reg r/m
FS:r64 with far pointer from memory
0100 1RXB : 0000 1111 : 1011 0100 : modA qwordreg r/m
LGDT - Load Global Descriptor Table Register
0100 10XB : 0000 1111 : 0000 0001 : modA 010 r/m
LGS - Load Pointer to GS
GS:r16/r32 with far pointer from memory
0100 0RXB : 0000 1111 : 1011 0101 : modA reg r/m
GS:r64 with far pointer from memory
0100 1RXB : 0000 1111 : 1011 0101 : modA qwordreg r/m
LIDT - Load Interrupt Descriptor Table Register
0100 10XB : 0000 1111 : 0000 0001 : modA 011 r/m
LLDT - Load Local Descriptor Table Register
LDTR from register
0100 000B : 0000 1111 : 0000 0000 : 11 010 reg
LDTR from memory
0100 00XB :0000 1111 : 0000 0000 : mod 010 r/m
LMSW - Load Machine Status Word
from register
0100 000B : 0000 1111 : 0000 0001 : 11 110 reg
from memory
0100 00XB :0000 1111 : 0000 0001 : mod 110 r/m
LOCK - Assert LOCK# Signal Prefix
1111 0000
LODS/LODSB/LODSW/LODSD/LODSQ - Load String Operand
at DS:(E)SI to AL/EAX/EAX
1010 110w
at (R)SI to RAX
0100 1000 1010 1101
LOOP - Loop Count
if count 0, 8-bit displacement
1110 0010
if count 0, RIP + 8-bit displacement sign-extended to 64-bits
0100 1000 1110 0010
LOOPE - Loop Count while Zero/Equal
B-24
Vol. 2D
INSTRUCTION FORMATS AND ENCODINGS
Table B-15. General Purpose Instruction Formats and Encodings for 64-Bit Mode (Contd.)
Instruction and Format
Encoding
if count 0 & ZF =1, 8-bit displacement
1110 0001
if count 0 & ZF = 1, RIP + 8-bit displacement sign-extended to
0100 1000 1110 0001
64-bits
LOOPNE/LOOPNZ - Loop Count while not Zero/Equal
if count 0 & ZF = 0, 8-bit displacement
1110 0000
if count 0 & ZF = 0, RIP + 8-bit displacement sign-extended to
0100 1000 1110 0000
64-bits
LSL - Load Segment Limit
from register
0000 1111 : 0000 0011 : 11 reg1 reg2
from qwordregister
0100 1R00 0000 1111 : 0000 0011 : 11 qwordreg1 reg2
from memory16
0000 1111 : 0000 0011 : mod reg r/m
from memory64
0100 1RXB 0000 1111 : 0000 0011 : mod qwordreg r/m
LSS - Load Pointer to SS
SS:r16/r32 with far pointer from memory
0100 0RXB : 0000 1111 : 1011 0010 : modA reg r/m
SS:r64 with far pointer from memory
0100 1WXB : 0000 1111 : 1011 0010 : modA qwordreg r/m
LTR - Load Task Register
from register
0100 0R00 : 0000 1111 : 0000 0000 : 11 011 reg
from memory
0100 00XB : 0000 1111 : 0000 0000 : mod 011 r/m
MOV - Move Data
register1 to register2
0100 0R0B : 1000 100w : 11 reg1 reg2
qwordregister1 to qwordregister2
0100 1R0B 1000 1001 : 11 qwordeg1 qwordreg2
register2 to register1
0100 0R0B : 1000 101w : 11 reg1 reg2
qwordregister2 to qwordregister1
0100 1R0B 1000 1011 : 11 qwordreg1 qwordreg2
memory to reg
0100 0RXB : 1000 101w : mod reg r/m
memory64 to qwordregister
0100 1RXB 1000 1011 : mod qwordreg r/m
reg to memory
0100 0RXB : 1000 100w : mod reg r/m
qwordregister to memory64
0100 1RXB 1000 1001 : mod qwordreg r/m
immediate to register
0100 000B : 1100 011w : 11 000 reg : imm
immediate32 to qwordregister (zero extend)
0100 100B 1100 0111 : 11 000 qwordreg : imm32
immediate to register (alternate encoding)
0100 000B : 1011 w reg : imm
immediate64 to qwordregister (alternate encoding)
0100 100B 1011 1000 reg : imm64
immediate to memory
0100 00XB : 1100 011w : mod 000 r/m : imm
immediate32 to memory64 (zero extend)
0100 10XB 1100 0111 : mod 000 r/m : imm32
memory to AL, AX, or EAX
0100 0000 : 1010 000w : displacement
memory64 to RAX
0100 1000 1010 0001 : displacement64
AL, AX, or EAX to memory
0100 0000 : 1010 001w : displacement
RAX to memory64
0100 1000 1010 0011 : displacement64
MOV - Move to/from Control Registers
CR0-CR4 from register
0100 0R0B : 0000 1111 : 0010 0010 : 11 eee reg (eee = CR#)
Vol. 2D B-25
INSTRUCTION FORMATS AND ENCODINGS
Table B-15. General Purpose Instruction Formats and Encodings for 64-Bit Mode (Contd.)
Instruction and Format
Encoding
CRx from qwordregister
0100 1R0B : 0000 1111 : 0010 0010 : 11 eee qwordreg (Reee
= CR#)
register from CR0-CR4
0100 0R0B : 0000 1111 : 0010 0000 : 11 eee reg (eee = CR#)
qwordregister from CRx
0100 1R0B 0000 1111 : 0010 0000 : 11 eee qwordreg
(Reee = CR#)
MOV - Move to/from Debug Registers
DR0-DR7 from register
0000 1111 : 0010 0011 : 11 eee reg (eee = DR#)
DR0-DR7 from quadregister
0100 10OB 0000 1111 : 0010 0011 : 11 eee reg (eee = DR#)
register from DR0-DR7
0000 1111 : 0010 0001 : 11 eee reg (eee = DR#)
quadregister from DR0-DR7
0100 10OB 0000 1111 : 0010 0001 : 11 eee quadreg (eee =
DR#)
MOV - Move to/from Segment Registers
register to segment register
0100 W00Bw : 1000 1110 : 11 sreg reg
register to SS
0100 000B : 1000 1110 : 11 sreg reg
memory to segment register
0100 00XB : 1000 1110 : mod sreg r/m
memory64 to segment register (lower 16 bits)
0100 10XB 1000 1110 : mod sreg r/m
memory to SS
0100 00XB : 1000 1110 : mod sreg r/m
segment register to register
0100 000B : 1000 1100 : 11 sreg reg
segment register to qwordregister (zero extended)
0100 100B 1000 1100 : 11 sreg qwordreg
segment register to memory
0100 00XB : 1000 1100 : mod sreg r/m
segment register to memory64 (zero extended)
0100 10XB 1000 1100 : mod sreg3 r/m
MOVBE - Move data after swapping bytes
memory to register
0100 0RXB : 0000 1111 : 0011 1000:1111 0000 : mod reg r/m
memory64 to qwordregister
0100 1RXB : 0000 1111 : 0011 1000:1111 0000 : mod reg r/m
register to memory
0100 0RXB :0000 1111 : 0011 1000:1111 0001 : mod reg r/m
qwordregister to memory64
0100 1RXB :0000 1111 : 0011 1000:1111 0001 : mod reg r/m
MOVS/MOVSB/MOVSW/MOVSD/MOVSQ - Move Data from String to String
Move data from string to string
1010 010w
Move data from string to string (qword)
0100 1000 1010 0101
MOVSX/MOVSXD - Move with Sign-Extend
register2 to register1
0100 0R0B : 0000 1111 : 1011 111w : 11 reg1 reg2
byteregister2 to qwordregister1 (sign-extend)
0100 1R0B 0000 1111 : 1011 1110 : 11 quadreg1 bytereg2
wordregister2 to qwordregister1
0100 1R0B 0000 1111 : 1011 1111 : 11 quadreg1 wordreg2
dwordregister2 to qwordregister1
0100 1R0B 0110 0011 : 11 quadreg1 dwordreg2
memory to register
0100 0RXB : 0000 1111 : 1011 111w : mod reg r/m
memory8 to qwordregister (sign-extend)
0100 1RXB 0000 1111 : 1011 1110 : mod qwordreg r/m
memory16 to qwordregister
0100 1RXB 0000 1111 : 1011 1111 : mod qwordreg r/m
memory32 to qwordregister
0100 1RXB 0110 0011 : mod qwordreg r/m
MOVZX - Move with Zero-Extend
B-26
Vol. 2D
INSTRUCTION FORMATS AND ENCODINGS
Table B-15. General Purpose Instruction Formats and Encodings for 64-Bit Mode (Contd.)
Instruction and Format
Encoding
register2 to register1
0100 0R0B : 0000 1111 : 1011 011w : 11 reg1 reg2
dwordregister2 to qwordregister1
0100 1R0B 0000 1111 : 1011 0111 : 11 qwordreg1
dwordreg2
memory to register
0100 0RXB : 0000 1111 : 1011 011w : mod reg r/m
memory32 to qwordregister
0100 1RXB 0000 1111 : 1011 0111 : mod qwordreg r/m
MUL - Unsigned Multiply
AL, AX, or EAX with register
0100 000B : 1111 011w : 11 100 reg
RAX with qwordregister (to RDX:RAX)
0100 100B 1111 0111 : 11 100 qwordreg
AL, AX, or EAX with memory
0100 00XB 1111 011w : mod 100 r/m
RAX with memory64 (to RDX:RAX)
0100 10XB 1111 0111 : mod 100 r/m
NEG - Two's Complement Negation
register
0100 000B : 1111 011w : 11 011 reg
qwordregister
0100 100B 1111 0111 : 11 011 qwordreg
memory
0100 00XB : 1111 011w : mod 011 r/m
memory64
0100 10XB 1111 0111 : mod 011 r/m
NOP - No Operation
1001 0000
NOT - One's Complement Negation
register
0100 000B : 1111 011w : 11 010 reg
qwordregister
0100 000B 1111 0111 : 11 010 qwordreg
memory
0100 00XB : 1111 011w : mod 010 r/m
memory64
0100 1RXB 1111 0111 : mod 010 r/m
OR - Logical Inclusive OR
register1 to register2
0000 100w : 11 reg1 reg2
byteregister1 to byteregister2
0100 0R0B 0000 1000 : 11 bytereg1 bytereg2
qwordregister1 to qwordregister2
0100 1R0B 0000 1001 : 11 qwordreg1 qwordreg2
register2 to register1
0000 101w : 11 reg1 reg2
byteregister2 to byteregister1
0100 0R0B 0000 1010 : 11 bytereg1 bytereg2
qwordregister2 to qwordregister1
0100 0R0B 0000 1011 : 11 qwordreg1 qwordreg2
memory to register
0000 101w : mod reg r/m
memory8 to byteregister
0100 0RXB 0000 1010 : mod bytereg r/m
memory8 to qwordregister
0100 0RXB 0000 1011 : mod qwordreg r/m
register to memory
0000 100w : mod reg r/m
byteregister to memory8
0100 0RXB 0000 1000 : mod bytereg r/m
qwordregister to memory64
0100 1RXB 0000 1001 : mod qwordreg r/m
immediate to register
1000 00sw : 11 001 reg : imm
immediate8 to byteregister
0100 000B 1000 0000 : 11 001 bytereg : imm8
immediate32 to qwordregister
0100 000B 1000 0001 : 11 001 qwordreg : imm32
immediate8 to qwordregister
0100 000B 1000 0011 : 11 001 qwordreg : imm8
immediate to AL, AX, or EAX
0000 110w : imm
Vol. 2D
B-27
INSTRUCTION FORMATS AND ENCODINGS
Table B-15. General Purpose Instruction Formats and Encodings for 64-Bit Mode (Contd.)
Instruction and Format
Encoding
immediate64 to RAX
0100 1000 0000 1101 : imm64
immediate to memory
1000 00sw : mod 001 r/m : imm
immediate8 to memory8
0100 00XB 1000 0000 : mod 001 r/m : imm8
immediate32 to memory64
0100 00XB 1000 0001 : mod 001 r/m : imm32
immediate8 to memory64
0100 00XB 1000 0011 : mod 001 r/m : imm8
OUT - Output to Port
fixed port
1110 011w : port number
variable port
1110 111w
OUTS - Output to DX Port
output to DX Port
0110 111w
POP - Pop a Value from the Stack
wordregister
0101 0101 : 0100 000B : 1000 1111 : 11 000 reg16
qwordregister
0100 W00BS : 1000 1111 : 11 000 reg64
wordregister (alternate encoding)
0101 0101 : 0100 000B : 0101 1 reg16
qwordregister (alternate encoding)
0100 W00B : 0101 1 reg64
memory64
0100 W0XBS : 1000 1111 : mod 000 r/m
memory16
0101 0101 : 0100 00XB 1000 1111 : mod 000 r/m
POP - Pop a Segment Register from the Stack
(Note: CS cannot be sreg2 in this usage.)
segment register FS, GS
0000 1111: 10 sreg3 001
POPF/POPFQ - Pop Stack into FLAGS/RFLAGS Register
pop stack to FLAGS register
0101 0101 : 1001 1101
pop Stack to RFLAGS register
0100 1000 1001 1101
PUSH - Push Operand onto the Stack
wordregister
0101 0101 : 0100 000B : 1111 1111 : 11 110 reg16
qwordregister
0100 W00BS : 1111 1111 : 11 110 reg64
wordregister (alternate encoding)
0101 0101 : 0100 000B : 0101 0 reg16
qwordregister (alternate encoding)
0100 W00BS : 0101 0 reg64
memory16
0101 0101 : 0100 000B : 1111 1111 : mod 110 r/m
memory64
0100 W00BS : 1111 1111 : mod 110 r/m
immediate8
0110 1010 : imm8
immediate16
0101 0101 : 0110 1000 : imm16
immediate64
0110 1000 : imm64
PUSH - Push Segment Register onto the Stack
segment register FS,GS
0000 1111: 10 sreg3 000
PUSHF/PUSHFD - Push Flags Register onto the Stack
1001 1100
RCL - Rotate thru Carry Left
register by 1
0100 000B : 1101 000w : 11 010 reg
qwordregister by 1
0100 100B 1101 0001 : 11 010 qwordreg
B-28
Vol. 2D

 

 

 

 

 

 

 

Content      ..     108      109      110      111     ..