Check vl first
The current vl determines the number of body elements. Typical code executes vsetvli, vsetivli, or vsetvl before this instruction.
Vector GHASH add-multiply: update partial hash in vd using ciphertext vs1 and hash subkey vs2.
vghsh.vv performs a GHASH add-multiply over 128-bit element groups with SEW=32. It reads partial hash Y_i from vd, ciphertext X_i from vs1, hash subkey H from vs2, and writes updated partial hash Y_{i+1} to vd.
VGHSH.VV is a Zvkg vector instruction for vector GHASH add-multiply. This page is checked against the official vector crypto extension and V-extension execution model.
When reading VGHSH.VV, do not stop at the mnemonic. Official V-extension semantics also depend on the current vl, vtype, and mask state. .vv: two vector sources participate element by element.
The current vl determines the number of body elements. Typical code executes vsetvli, vsetivli, or vsetvl before this instruction.
The current vtype supplies SEW, LMUL, tail policy, and mask policy; these affect element width, register-group size, and inactive/tail destination elements.
For ordinary vector instructions with vm, vm=0 uses v0 as the execution mask and vm=1 is unmasked. A few forms such as VMERGE use v0 as data-selection input.
Understand this scenario with real code like «vghsh.vv vd, vs2, vs1».
Understand this scenario with real code like «vghsh.vv vd, vs2, vs1».
No. This element-group crypto instruction has no vm operand; ordinary RVV mask syntax should not be added to examples.
This instruction fixes SEW=32 and executes on 128-bit element groups; other SEW values are reserved/illegal cases.