Appendix A Opcode Map
Appendix A Opcode Map
Appendix A Opcode Map
Title: Appendix A Opcode Map
----------------------------------------------------------------------------
The opcode tables that follow aid in interpreting 80386 object code. Use
the high-order four bits of the opcode as an index to a row of the opcode
table; use the low-order four bits as an index to a column of the table. If
the opcode is 0FH, refer to the two-byte opcode table and use the second
byte of the opcode to index the rows and columns of that table.
Key to Abbreviations
Title: Key to Abbreviations
Operands are identified by a two-character code of the form Zz. The first
character, an uppercase letter, specifies the addressing method; the second
character, a lowercase letter, specifies the type of operand.
Codes for Addressing Method
Title: Codes for Addressing Method
A Direct address; the instruction has no modR/M byte; the address of the
operand is encoded in the instruction; no base register, index register,
or scaling factor can be applied; e.g., far JMP (EA).
C The reg field of the modR/M byte selects a control register; e.g., MOV
(0F20, 0F22).
D The reg field of the modR/M byte selects a debug register; e.g., MOV
(0F21,0F23).
E A modR/M byte follows the opcode and specifies the operand. The operand
is either a general register or a memory address. If it is a memory
address, the address is computed from a segment register and any of the
following values: a base register, an index register, a scaling factor,
a displacement.
F Flags Register.
G The reg field of the modR/M byte selects a general register; e.g., ADD
(00).
I Immediate data. The value of the operand is encoded in subsequent bytes
of the instruction.
J The instruction contains a relative offset to be added to the
instruction pointer register; e.g., JMP short, LOOP.
M The modR/M byte may refer only to memory; e.g., BOUND, LES, LDS, LSS,
LFS, LGS.
O The instruction has no modR/M byte; the offset of the operand is coded as
a word or double word (depending on address size attribute) in the
instruction. No base register, index register, or scaling factor can be
applied; e.g., MOV (A0-A3).
R The mod field of the modR/M byte may refer only to a general register;
e.g., MOV (0F20-0F24, 0F26).
S The reg field of the modR/M byte selects a segment register; e.g., MOV
(8C,8E).
T The reg field of the modR/M byte selects a test register; e.g., MOV
(0F24,0F26).
X Memory addressed by DS:SI; e.g., MOVS, COMPS, OUTS, LODS, SCAS.
Y Memory addressed by ES:DI; e.g., MOVS, CMPS, INS, STOS.
Codes for Operant Type
Title: Codes for Operant Type
a Two one-word operands in memory or two double-word operands in memory,
depending on operand size attribute (used only by BOUND).
b Byte (regardless of operand size attribute)
c Byte or word, depending on operand size attribute.
d Double word (regardless of operand size attribute)
p 32-bit or 48-bit pointer, depending on operand size attribute.
s Six-byte pseudo-descriptor
v Word or double word, depending on operand size attribute.
w Word (regardless of operand size attribute)
Register Codes
Title: Register Codes
When an operand is a specific register encoded in the opcode, the register
is identified by its name; e.g., AX, CL, or ESI. The name of the register
indicates whether the register is 32-, 16-, or 8-bits wide. A register
identifier of the form eXX is used when the width of the register depends on
the operand size attribute; for example, eAX indicates that the AX register
is used when the operand size attribute is 16 and the EAX register is used
when the operand size attribute is 32.
One-Byte Opcode Map I
Title: One-Byte Opcode Map I
0 1 2 3 4 5 6 7
+---------------------------------------------------------------------------+
| ADD | PUSH | POP |
0|---------------------------------------------------------| | |
| Eb,Gb | Ev,Gv | Gb,Eb | Gv,Ev | AL,Ib | eAX,Iv | ES | ES |
|---------------------------------------------------------+--------+--------|
| ADC | PUSH | POP |
1|---------------------------------------------------------| | |
| Eb,Gb | Ev,Gv | Gb,Eb | Gv,Ev | AL,Ib | eAX,Iv | SS | SS |
|---------------------------------------------------------+--------+--------|
| AND | SEG | |
2|---------------------------------------------------------| | DAA |
| Eb,Gb | Ev,Gv | Gb,Eb | Gv,Ev | AL,Ib | eAX,Iv | =ES | |
|---------------------------------------------------------+--------+--------|
| XOR | SEG | |
3|---------------------------------------------------------| | AAA |
| Eb,Gb | Ev,Gv | Gb,Eb | Gv,Ev | AL,Ib | eAX,Iv | =SS | |
|---------------------------------------------------------------------------|
| INC general register |
4|---------------------------------------------------------------------------|
| eAX | eCX | eDX | eBX | eSP | eBP | eSI | eDI |
|---------------------------------------------------------------------------|
| PUSH general register |
5|---------------------------------------------------------------------------|
| eAX | eCX | eDX | eBX | eSP | eBP | eSI | eDI |
|--------+--------+---------+---------+---------+---------+--------+--------|
| | | BOUND | ARPL | SEG | SEG | Operand| Address|
6| PUSHA | POPA | | | | | | |
| | | Gv,Ma | Ew,Rw | =FS | =GS | Size | Size |
|---------------------------------------------------------------------------|
| Short displacement jump of condition (Jb) |
7|---------------------------------------------------------------------------|
| JO | JNO | JB | JNB | JZ | JNZ | JBE | JNBE |
|-----------------+---------+---------+-------------------+-----------------|
| Immediate Grpl | | Grpl | TEST | XCNG |
8|-----------------| | |-------------------+-----------------|
| Eb,Ib | Ev,Iv | | Ev,Iv | Eb,Gb | Ev,Gv | Eb,Gb | Ev,Gv |
|--------+------------------------------------------------------------------|
| | XCHG word or double-word register with eAX |
9| NOP |------------------------------------------------------------------|
| | eCX | eDX | eBX | eSP | eBP | eSI | eDI |
|-------------------------------------+---------+---------+--------+--------|
| MOV | MOVSB | MOVSW/D | CMPSB |CMPSW/D |
A|-------------------------------------| | | | |
| AL,Ob | eAX,Ov | Ob,AL | Ov,eAX | Xb,Yb | Xv,Yv | Xb,Yb | Xv,Yv |
|---------------------------------------------------------------------------|
| MOV immediate byte into byte register |
B|---------------------------------------------------------------------------|
| AL | CL | DL | BL | AH | CH | DH | BH |
|-----------------+-------------------+---------+---------+-----------------|
| Shift Grp2 | RET near | LES | LDS | MOV |
C|-----------------+-------------------| | |-----------------|
| Eb,Ib | Ev,Iv | Iw | | Gv,Mp | Gv,Mp | Eb,Ib | Ev,Iv |
|-------------------------------------+---------+---------+--------+--------|
| Shift Grp2 | | | | |
D|-------------------------------------| AAM | AAD | | XLAT |
| Eb,1 | Ev,1 | Eb,CL | Ev,CL | | | | |
|--------+--------+---------+---------+-------------------+-----------------|
|LOOPNE | LOOPE | LOOP | JCXZ | IN | OUT |
E| | | | |-------------------+-----------------|
| Jb | Jb | Jb | Jb | AL,Ib | eAX,Ib | Ib,AL | Ib,eAX |
|--------+--------+---------+---------+---------+---------+-----------------|
| | | | REP | | | Unary Grp3 |
F| LOCK | | REPNE | | HLT | CMC |-----------------|
| | | | REPE | | | Eb | Ev |
+---------------------------------------------------------------------------+
See Also: "One-Byte Opcode Map II" "Two-Byte Opcode Map I"
One-Byte Opcode Map II
Title: One-Byte Opcode Map II
8 9 A B C D E F
+---------------------------------------------------------------------------+
| OR | PUSH | 2-byte |
0|---------------------------------------------------------| | |
| Eb,Gb | Ev,Gv | Gb,Eb | Gv,Ev | AL,Ib | eAX,Iv | CS | escape |
|---------------------------------------------------------+--------+--------|
| SBB | PUSH | POP |
1|---------------------------------------------------------| | |
| Eb,Gb | Ev,Gv | Gb,Eb | Gv,Ev | AL,Ib | eAX,Iv | DS | DS |
|---------------------------------------------------------+--------+--------|
| SUB | SEG | |
2|---------------------------------------------------------| | DAS |
| Eb,Gb | Ev,Gv | Gb,Eb | Gv,Ev | AL,Ib | eAX,Iv | =CS | |
|---------------------------------------------------------+--------+--------|
| CMP | SEG | |
3|---------------------------------------------------------| | AAS |
| Eb,Gb | Ev,Gv | Gb,Eb | Gv,Ev | AL,Ib | eAX,Iv | =CS | |
|---------------------------------------------------------------------------|
| DEC general register |
4|---------------------------------------------------------------------------|
| eAX | eCX | eDX | eBX | eSP | eBP | eSI | eDI |
|---------------------------------------------------------------------------|
| POP into general register |
5|---------------------------------------------------------------------------|
| eAX | eCX | eDX | eBX | eSP | eBP | eSI | eDI |
|--------+--------+---------+---------+---------+---------+--------+--------|
| PUSH | IMUL | PUSH | IMUL | INSB | INSW/D | OUTSB |OUTSW/D |
6| | | | | | | | |
| Ib | GvEvIv | Ib | GvEvIv | Yb,DX | Yb,DX | Dx,Xb | DX,Xv |
|---------------------------------------------------------------------------|
| Short-displacement jump on condition(Jb) |
7|---------------------------------------------------------------------------|
| JS | JNS | JP | JNP | JL | JNL | JLE | JNLE |
|-------------------------------------+---------+---------+--------+--------|
| MOV | MOV | LEA | MOV | POP |
8|-------------------------------------| | | | |
| Eb,Gb | Ev,Gv | Gb,Eb | Gv,Ev | Ew,Sw | Gv,M | Sw,Ew | Ev |
|--------+--------+---------+---------+---------+---------+--------+--------|
| | | CALL | | PUSHF | POPF | | |
9| CBW | CWD | | WAIT | | | SAHF | LAHF |
| | | Ap | | Fv | Fv | | |
|-----------------+---------+---------+---------+---------+--------+--------|
| TEST | STOSB | STOSW/D | LODSB | LODSW/D | SCASB |SCASW/D |
A|-----------------| | | | | | |
| AL,Ib |eAX,Iv | Yb,AL | Yv,eAX | AL,Xb | eAX,Xv | AL,Xb |eAX,Xv |
|---------------------------------------------------------------------------|
| MOV immediate word or double into word or double register |
B|---------------------------------------------------------------------------|
| eAX | eCX | eDX | eBX | eSP | eBP | eSI | eDI |
|--------+--------+-------------------+---------+---------+--------+--------|
| ENTER | | RET far | INT | INT | | |
C| | LEAVE |-------------------| | | INTO | IRET |
| Iw,Ib | | Iw | | 3 | Ib | | |
|---------------------------------------------------------------------------|
| |
D| ESC(Escape to coprocessor instruction set) |
| |
|---------------------------------------------------------------------------|
| CALL | JNP | IN | OUT |
E| |----------------------------+-------------------+-----------------|
| Av | Jv | Ap | Jb | AL,DX | eAX,DX | DX,AL | DX,eAX |
|--------+--------+---------+---------+---------+---------+--------+--------|
| | | | | | |INC/DEC |Indirct |
F| CLC | STC | CLI | STI | CLD | STD | | |
| | | | | | | Grp4 | Grp5 |
+---------------------------------------------------------------------------+
See Also: "One-Byte Opcode Map I" "Two-Byte Opcode Map I"
Two-Byte Opcode Map I
Title: Two-Byte Opcode Map I (first byte is 0FH)
0 1 2 3 4 5 6 7
+---------------------------------------------------------------------------+
| | | LAR | LSL | | | | |
0| Grp6 | Grp7 | | | | | CLTS | |
| | | Gw,Ew | Gv,Ew | | | | |
|--------+--------+---------+---------+---------+---------+--------+--------|
| | | | | | | | |
1| | | | | | | | |
| | | | | | | | |
|--------+--------+---------+---------+---------+---------+--------+--------|
| MOV | MOV | MOV | MOV | MOV | | MOV | |
2| | | | | | | | |
| Cd,Rd | Dd,Rd | Rd,Cd | Rd,Dd | Td,Rd | | Rd,Td | |
|--------+--------+---------+---------+---------+---------+--------+--------|
| | | | | | | | |
3| | | | | | | | |
| | | | | | | | |
|--------+--------+---------+---------+---------+---------+--------+--------|
| | | | | | | | |
4| | | | | | | | |
| | | | | | | | |
|--------+--------+---------+---------+---------+---------+--------+--------|
| | | | | | | | |
5| | | | | | | | |
| | | | | | | | |
|--------+--------+---------+---------+---------+---------+--------+--------|
| | | | | | | | |
6| | | | | | | | |
| | | | | | | | |
|--------+--------+---------+---------+---------+---------+--------+--------|
| | | | | | | | |
7| | | | | | | | |
| | | | | | | | |
|---------------------------------------------------------------------------|
| Long-displacement jump on condition (Jv) |
8|---------------------------------------------------------------------------|
| JO | JNO | JB | JNB | JZ | JNZ | JBE | JNBE |
|---------------------------------------------------------------------------|
| Byte Set on condition (Eb) |
9|---------------------------------------------------------------------------|
| SETO | SETNO | SETB | SETNB | SETZ | SETNZ | SETBE | SETNBE |
|--------+--------+---------+---------+---------+---------+--------+--------|
| PUSH | POP | | BT | SHLD | SHLD | | |
A| | | | | | | | |
| FS | FS | | Ev,Gv | EvGvIb | EvGvCL | | |
|--------+--------+---------+---------+---------+---------+-----------------|
| | | LSS | BTR | LFS | LGS | MOVZX |
B| | | | | | |-----------------|
| | | Mp | Ev,Gv | Mp | Mp | Gv,Eb | Gv,Ew |
|--------+--------+---------+---------+---------+---------+--------+--------|
| | | | | | | | |
C| | | | | | | | |
| | | | | | | | |
|--------+--------+---------+---------+---------+---------+--------+--------|
| | | | | | | | |
D| | | | | | | | |
| | | | | | | | |
|--------+--------+---------+---------+---------+---------+--------+--------|
| | | | | | | | |
E| | | | | | | | |
| | | | | | | | |
|--------+--------+---------+---------+---------+---------+--------+--------|
| | | | | | | | |
F| | | | | | | | |
| | | | | | | | |
+---------------------------------------------------------------------------+
See Also: "Two-Byte Opcode Map II" "One-Byte Opcode Map I"
Two-Byte Opcode Map II
Title: Two-Byte Opcode Map II (first byte is 0FH)
8 9 A B C D E F
+---------------------------------------------------------------------------+
| | | | | | | | |
0| | | | | | | | |
| | | | | | | | |
|--------+--------+---------+---------+---------+---------+--------+--------|
| | | | | | | | |
1| | | | | | | | |
| | | | | | | | |
|--------+--------+---------+---------+---------+---------+--------+--------|
| | | | | | | | |
2| | | | | | | | |
| | | | | | | | |
|--------+--------+---------+---------+---------+---------+--------+--------|
| | | | | | | | |
3| | | | | | | | |
| | | | | | | | |
|--------+--------+---------+---------+---------+---------+--------+--------|
| | | | | | | | |
4| | | | | | | | |
| | | | | | | | |
|--------+--------+---------+---------+---------+---------+--------+--------|
| | | | | | | | |
5| | | | | | | | |
| | | | | | | | |
|--------+--------+---------+---------+---------+---------+--------+--------|
| | | | | | | | |
6| | | | | | | | |
| | | | | | | | |
|--------+--------+---------+---------+---------+---------+--------+--------|
| | | | | | | | |
7| | | | | | | | |
| | | | | | | | |
|---------------------------------------------------------------------------|
| Long-displacement jump on condition (Jv) |
8|---------------------------------------------------------------------------|
| JS | JNS | JP | JNP | JL | JNL | JLE | JNLE |
|--------+--------+---------+---------+---------+---------+--------+--------|
| | | | | | | | |
9| SETS | SETNS | SETP | SETNP | SETL | SETNL | SETLE | SETNLE |
| | | | | | | | |
|--------+--------+---------+---------+---------+---------+--------+--------|
| PUSH | POP | | BTS | SHRD | SHRD | | IMUL |
A| | | | | | | | |
| GS | GS | | Ev,Gv | EvGvIb | EvGvCL | | Gv,Ev |
|--------+--------+---------+---------+---------+---------+-----------------|
| | | Grp-8 | BTC | BSF | BSR | MOVSX |
B| | | | | | |-----------------|
| | | Ev,Ib | Ev,Gv | Gv,Ev | Gv,Ev | Gv,Eb Gv,Ew |
|--------+--------+---------+---------+---------+---------+-----------------|
| | | | | | | | |
C| | | | | | | | |
| | | | | | | | |
|--------+--------+---------+---------+---------+---------+--------+--------|
| | | | | | | | |
D| | | | | | | | |
| | | | | | | | |
|--------+--------+---------+---------+---------+---------+--------+--------|
| | | | | | | | |
E| | | | | | | | |
| | | | | | | | |
|--------+--------+---------+---------+---------+---------+--------+--------|
| | | | | | | | |
F| | | | | | | | |
| | | | | | | | |
+---------------------------------------------------------------------------+
See Also: "Two-Byte Opcode Map I" "One-Byte Opcode Map I"