Home/Instructions/VCLMULH-VX
VCLMULH.VX

RISC-V VCLMULH.VX Instruction Details

Instruction ManualV-type

Vector-scalar carry-less multiply high: GF(2) multiply with broadcast rs1, high SEW bits

Instruction Syntax

vclmulh.vx vd, vs2, rs1, vm
Operand Breakdown
vd: destination vector register group.
vs2/vs1 or scalar source: selected by suffixes such as .vv, .vx, .vi, or .vf.
vm: when present, vm=0 uses v0 as the execution mask and vm=1 is unmasked.
ZvbcVector CryptoBit Manipulation

Instruction Behavior

vclmulh.vx is the Zvbc vector-scalar carry-less multiply-high instruction. X(rs1) is zero-extended or truncated to 64 bits, polynomial-multiplied with each vs2[i] over GF(2), and bits 127:64 of the 128-bit product are returned. It is defined only when SEW=64; other SEW encodings are reserved.

VCLMULH.VX Decode & Execute Animation

This bounded model shows only lane 0 ISA-visible state; it does not model a pipeline, a cryptographic protocol, or unspecified inactive/tail values.

Bounded execution context
32-bit OP-V encoding fields
31..26
funct6
001101
25
vm
1
24..20
vs2
01000
19..15
rs1
01011
14..12
funct3
110
11..7
vd
00100
6..0
OP-V
1010111
Execution data path

funct6=001101, funct3=110, Zvbc

v4[0] <- pending

Quick Understanding & Search Notes

VCLMULH.VX is a Zvbc vector instruction for vector-scalar carry-less multiply high. This page is checked against the official vector crypto extension and V-extension execution model.

The scalar and each element are carry-less multiplied, returning high SEW bits; SEW=64.
It follows V-extension vl, vstart, vtype, and optional vm mask rules.
Zvbc vclmul/vclmulh are defined only for SEW=64.

Vector Execution Context

When reading VCLMULH.VX, do not stop at the mnemonic. Official V-extension semantics also depend on the current vl, vtype, and mask state. .vx: one vector source and one integer scalar source participate.

Check vl first

The current vl determines the number of body elements. Typical code executes vsetvli, vsetivli, or vsetvl before this instruction.

Then check vtype

The current vtype supplies SEW, LMUL, tail policy, and mask policy; these affect element width, register-group size, and inactive/tail destination elements.

Then check vm/v0

For ordinary vector instructions with vm, vm=0 uses v0 as the execution mask and vm=1 is unmasked. A few forms such as VMERGE use v0 as data-selection input.

Official source: RISC-V V Standard Extension for Vector Operations

Common Usage Scenarios

Crypto & Security

Understand this scenario with real code like «vclmulh.vx vd, vs2, a1».

Vector Acceleration

Understand this scenario with real code like «vclmulh.vx vd, vs2, a1».

Pre-Use Checklist

Syntax Check
  • Confirm the current instruction format is V-type.
  • Confirm the operand order matches the example.
Semantic Check
  • Ensure the destination register usage is compatible with the calling convention.
  • Confirm this is not the lower-level form of a pseudo-instruction expansion.

Pitfalls / Common Confusions

SEW=64. Returns high 64 bits.

FAQ

Can VCLMULH.VX always use a v0.t mask?

It can use v0.t; omitting it gives vm=1. With vm=0, v0 is the EEW=1 mask, so a normal data source or destination cannot also reuse v0; that encoding is reserved.

What determines the element width for VCLMULH.VX?

The current vtype SEW determines it, subject to any instruction-specific SEW restrictions in the extension.