> For the complete documentation index, see [llms.txt](https://docs.hex-rays.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.hex-rays.com/ida-9.5/core/decompiler/concepts/isa_extensions.md).

# Instruction set architecture extensions

The decompiler supports many different extensions to common instruction set architectures. The full list is available in the [Supported extensions](#supported-extensions) section at the end of this page.

The instructions from these extensions are represented by IDA in two different ways: They can be lifted directly into microcode, in which case they are turned into C-like operations, or they are represented by special [intrinsic](http://en.wikipedia.org/wiki/Intrinsic_function) functions. In order to support these operations, the decompiler also introduces the necessary `__m128`, `__m256`, etc. types.

For example, the **SSE** floating point conversion instructions such as [`CVTSI2SS`](https://intel.github.io/SDM/sdm.html?instr=CVTSI2SS) are lifted directly into C-like code, which is converted directly to a microcode floating point cast:

```
; assembly
mov     eax, [rsp+arg_0]
cvtsi2ss xmm0, eax
movss   [rsp+var_4], xmm0
```

```
; microcode
mov    [rsp+arg_0].4, eax.4
i2f    eax.4, xmm0.4
mov    xmm0.4, [rsp+var_4].4
```

```c
// pseudocode
v1 = (float)a1;
```

Meanwhile, an instruction that is unfeasible to be lifted into microcode is represented via an intrinsic call. For example, the **AVX2** [`VBROADCASTI128`](https://intel.github.io/SDM/sdm.html?instr=VPBROADCAST) instruction:

```
; assembly
mov     rax, [rsp+arg_0]
vbroadcasti128 ymm0, xmmword ptr [rax]
vmovdqu ymmword ptr [rsp+var_20], ymm0
```

```
; microcode
mov    [rsp+arg_0].8, rax.8
ldx    ds.2, rax.8, kr00.16
call   !_mm256_broadcastsi128_si256<fast:__m128i kr00.16>.32 => ymm0.32
mov    ymm0.32, [rsp+var_20].32
```

```c
// pseudocode
v1 = _mm256_broadcastsi128_si256(*(__m128i *)a1);
```

While everything works automatically, the following points are worth noting:

* Newer versions of IDA generally support more instruction set extensions than older ones.
* Some intrinsic functions work with **XMM** constant values (16 bytes long). Modern compilers do not accept 16-byte constants yet but the decompiler may generate them when needed.
* Sometimes it is better to represent instruction code using inline assembly rather than with intrinsic functions. If the decompiler detects SSE instructions in the current function, it adds a one more item to the popup menu. This item allows the user to enable or disable SSE intrinsic functions for the whole database. This setting is remembered in the database. It can also be modified in the [configuration file](/ida-9.5/core/decompiler/reference/config.md#ho_sse_intrinsics) for new databases.
* Certain scalar instructions (such as `minss`/`maxss`) are mapped into their [math.h](https://en.wikipedia.org/wiki/C_mathematical_functions#Overview_of_functions) equivalents
* The decompiler uses intrinsic function names as defined by Microsoft and Intel.
* The decompiler does not track the state of the x87 and mmx registers. It is assumed that the compiler generated code correctly handles transitions between x87 and mmx registers.
* Some intrinsic functions are not supported because of their prototype. For example, the [\_\_cpuid(int a\[4\], int b)](https://msdn.microsoft.com/en-us/library/hskdteyh\(v=vs.140\).aspx) function is not handled because it requires an array of 4 integers. We assume that most **cpuid** instructions will be used without any arrays, so adding such an intrinsic function will obscure things rather than to make the code more readable.
* Feel free to report all anomalies and problems with intrinsic functions using the [Send database](https://github.com/HexRaysSA/ida-docs/blob/9.4/ida-actions/hx_sendidb.md) command. This will help us to improve the decompiler and make it more robust. Thank you!

## Supported extensions

* **x86 / x86-64**
  * **x87** floating point unit
  * **MMX** and **3DNow!** (including the 3DNow! extensions)
  * **SSE**, **SSE2**, **SSE3**, **SSSE3**, **SSE4.1**, **SSE4.2** and **SSE4a**
  * **POPCNT**, **LZCNT**, **BMI1** and **BMI2**
  * **RDRAND** and **RDSEED**
  * **FXSAVE/XSAVE** state management
  * **PREFETCHW** and **PREFETCHWT1**
  * **CET** indirect branch tracking (`endbr32`/`endbr64`)
  * **AMD-V (SVM)** and **Intel VT-x (VMX)** virtualization instructions
  * **AVX**, **AVX2**, **FMA** and **F16C** (AVX lifter)
  * **AVX-512**: F, VL, BW, DQ, CD, IFMA, VBMI, VBMI2, VNNI, BITALG, VPOPCNTDQ, VP2INTERSECT, BF16, FP16, ER, PF, 4FMAPS and 4VNNIW, including masked (merge/zero) EVEX forms and opmask (k-register) operations (AVX lifter)
  * **AVX10** (AVX lifter)
  * **GFNI**, **VAES**, **VPCLMULQDQ** and **SHA** (SHA-1/SHA-256) (AVX lifter)
  * **CLFLUSHOPT** and **CLWB** cache control (AVX lifter)
* **ARM / AArch64**
  * **Thumb** and **Thumb-2**
  * **VFP** (including the ARMv5TE extensions)
  * **NEON** (Advanced SIMD), including scalar SIMD forms and half precision (**FP16**) data
  * **Cryptographic extensions**: AES, SHA-1, SHA-256, SHA-512, SHA3 and polynomial multiply
  * **ARMv8.1**: **LSE** atomics (`cas`, `swp`, `ldadd`, `ldclr`, `ldeor`, `ldset`) and **RDM** rounding doubling multiply
  * **ARMv8.3**: **Pointer Authentication** (PAuth, including PAuth\_LR forms)
  * **ARMv8.4**: **FlagM** flag manipulation (`cfinv`, `rmif`, `setf8`, `setf16`, `axflag`, `xaflag`)
  * **ARMv8.5**: **Memory Tagging Extension** (MTE) and **Branch Target Identification** (BTI)
  * **ARMv8.6**: **I8MM** integer matrix multiply
  * **CSSC** (Common Short Sequence Compression)
  * **SVE** and **SME** (initial support: vector/predicate loads and stores, `svcntb`/`svptrue` helpers, ZA and ZT0 state)
* **PowerPC**
  * **AltiVec/VMX** (including the Cell BE extension and Xenon VMX128 save/restore helpers)
  * **VSX** (Vector-Scalar Extension)
  * **SPE** (Signal Processing Engine) and **Embedded Floating Point** (EFP, EFP 2.0)
  * **Decimal Floating Point** (DFP)
  * **Power ISA 2.06** and **3.0** additions (`popcnt*`, `bpermd`, `isel`, `cnttz*`, `ldbrx`/`stdbrx`, `lq`/`stq`)
  * **Book E** and embedded controller instructions (Freescale e200z6, **VLE**)
* **MIPS**
  * **MIPS16e**, **microMIPS** and **nanoMIPS**
  * **MIPS32/MIPS64 Release 6** (compact branches, `sel*`, `mul`/`muh`/`div`/`mod`, `cmp.cond.fmt`, `bc1eqz`/`bc1nez`)
  * **FPU** (coprocessor 1) single and double precision
  * **MT ASE** thread control and **DSP ASE** indexed loads
  * **Cavium Octeon** and **Sony Allegrex** (PSP) vendor instructions
* **RISC-V**
  * **RV32I/RV64I** base with the **M**, **A** (including `amocas`), **F**, **D** and **C** standard extensions
  * **Zicsr**, **Zifencei**, **Zihintpause**, **Zihintntl** and **Zawrs**
  * **Zba**, **Zbb**, **Zbc**, **Zbs** and **Zbkb** bit manipulation
  * **Zcmp** and **Zcmt** code size reduction
  * Vendor extensions: **T-Head** (XTHead), **Andes** (XAndesPerf), **Hazard3** and **Soteria** (Xsoteria)
* **Hexagon (QDSP6)**
  * scalar **SIMD** and **DSP** operations on register pairs
  * **HVX** vector and predicate registers (HVX operations are represented as intrinsics)
* **ARC**
  * **ARCompact** and **ARCv2** (multiply, 64-bit multiply, divide/remainder, `norm`, `swap`, bit field extract)
* **V850 / RH850**
  * **V850E/E1/ES**, **V850E2**, **V850E2M** and **RH850** instruction set extensions (saturation, bit manipulation, `caxi`/`cll` atomics, `snooze`, `sync*`)

See also: [Failures and troubleshooting](/ida-9.5/core/decompiler/failures.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.hex-rays.com/ida-9.5/core/decompiler/concepts/isa_extensions.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
