Home/Instructions/VCLMUL-VV
VCLMUL.VV

RISC-V VCLMUL.VV Instruction Details

Instruction ManualR-type

Vector carry-less multiply (low result): GF(2) polynomial multiply returning low SEW bits

Instruction Syntax

vclmul.vv vd, vs2, vs1, vm
Operand Breakdown
vd: destination vector register group.
vs2/vs1 or scalar source: selected by suffixes such as .vv, .vx, .vi, or .vf.
vm: when present, vm=0 uses v0 as the execution mask and vm=1 is unmasked.
ZvbcVector CryptoBit Manipulation

Instruction Behavior

vclmul.vv is the Zvbc vector carry-less multiply. Performs polynomial multiplication in GF(2) on vs1[i] and vs2[i], returning low SEW bits of the product to vd[i]. This is the standard CLMUL operation. Supports SEW=64.

Quick Understanding & Search Notes

VCLMUL.VV is a Zvbc vector instruction for vector carry-less multiply low. This page is checked against the official vector crypto extension and V-extension execution model.

Performs GF(2) polynomial multiplication and returns the low SEW bits; Zvbc defines it only for SEW=64.
It follows V-extension vl, vstart, vtype, and optional vm mask rules.
Zvbc vclmul/vclmulh are defined only for SEW=64.

Vector Execution Context

When reading VCLMUL.VV, do not stop at the mnemonic. Official V-extension semantics also depend on the current vl, vtype, and mask state. .vv: two vector sources participate element by element.

Check vl first

The current vl determines the number of body elements. Typical code executes vsetvli, vsetivli, or vsetvl before this instruction.

Then check vtype

The current vtype supplies SEW, LMUL, tail policy, and mask policy; these affect element width, register-group size, and inactive/tail destination elements.

Then check vm/v0

For ordinary vector instructions with vm, vm=0 uses v0 as the execution mask and vm=1 is unmasked. A few forms such as VMERGE use v0 as data-selection input.

Official source: RISC-V V Standard Extension for Vector Operations

Common Usage Scenarios

Crypto & Security

Understand this scenario with real code like «vclmul.vv vd, vs2, vs1».

Vector Acceleration

Understand this scenario with real code like «vclmul.vv vd, vs2, vs1».

Pre-Use Checklist

Syntax Check
  • Confirm the current instruction format is R-type.
  • Confirm the operand order matches the example.
Semantic Check
  • Ensure the destination register usage is compatible with the calling convention.
  • Confirm this is not the lower-level form of a pseudo-instruction expansion.

Pitfalls / Common Confusions

Carry-less (GF(2) polynomial) multiply, not integer multiply.
Returns low SEW bits; high SEW bits use vclmulh. SEW=64.

FAQ

Can VCLMUL.VV always use a v0.t mask?

It can use the vm mask operand shown in the syntax; omitting it gives the unmasked form.

What determines the element width for VCLMUL.VV?

The current vtype SEW determines it, subject to any instruction-specific SEW restrictions in the extension.