Micron Document
<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Intel microcode</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Intel_microcode"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Intel_microcode rootpage-Intel_microcode skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Intel microcode</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<p><b>Intel microcode</b> is <a href="Microcode" title="Microcode">microcode</a> that runs inside <a href="X86" title="X86">x86</a> processors made by <a href="Intel" title="Intel">Intel</a>. Since the <a href="P6_(microarchitecture)" title="P6 (microarchitecture)">P6 microarchitecture</a> introduced in the mid-1990s, the microcode programs can be <a href="Patch_(computing)" title="Patch (computing)">patched</a> by the operating system or <a href="BIOS" title="BIOS">BIOS</a> firmware to work around bugs found in the CPU after release.<sup id="cite_ref-gwennap-20070915_1-0" class="reference"><a href="#cite_note-gwennap-20070915-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> Intel had originally designed microcode updates for processor debugging under its <a href="Design_for_testing" title="Design for testing">design for testing</a> (DFT) initiative.<sup id="cite_ref-intel-dft-1998_2-0" class="reference"><a href="#cite_note-intel-dft-1998-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>
</p><p>Following the <a href="Pentium_FDIV_bug" title="Pentium FDIV bug">Pentium FDIV bug</a>, the <a href="Patchable_microcode" class="mw-redirect" title="Patchable microcode">patchable microcode</a> function took on a wider purpose to allow in-field updating without needing to do a <a href="Product_recall" title="Product recall">product recall</a>.<sup id="cite_ref-gwennap-20070915_1-1" class="reference"><a href="#cite_note-gwennap-20070915-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>
</p><p>In the P6 and later microarchitectures, <a href="X86_instruction_listings" title="X86 instruction listings">x86 instructions</a> are internally converted into simpler <a href="Reduced_instruction_set_computer" title="Reduced instruction set computer">RISC</a>-style <a href="Micro-operation" title="Micro-operation">micro-operations</a> that are specific to a particular processor and <a href="Stepping_level" title="Stepping level">stepping level</a>.<sup id="cite_ref-gwennap-20070915_1-2" class="reference"><a href="#cite_note-gwennap-20070915-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Pre-P6_microcode">Pre-P6 microcode</h2></div>
<p>On the <a href="Intel_80486" class="mw-redirect" title="Intel 80486">Intel 80486</a> and AMD <a href="Am486" title="Am486">Am486</a> there are approximately 5000 lines of microcode assembly, totalling approximately 240 Kbits stored in the microcode <a href="Read-only_memory" title="Read-only memory">ROM</a>.<sup id="cite_ref-trumbull-1994_3-0" class="reference"><a href="#cite_note-trumbull-1994-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="P6_and_later_micro-operations">P6 and later micro-operations</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1236090951">
/* start https://en.wikipedia.org/ */


.mw-parser-output .hatnote{font-style:italic}.mw-parser-output div.hatnote{padding-left:1.6em;margin-bottom:0.5em}.mw-parser-output .hatnote i{font-style:normal}.mw-parser-output .hatnote+link+.hatnote{margin-top:-0.5em}@media print{body.ns-0 .mw-parser-output .hatnote{display:none!important}}


/* end https://en.wikipedia.org/ */
</style><div role="note" class="hatnote navigation-not-searchable">Main article: <a href="Micro-operation" title="Micro-operation">Micro-operation</a></div>
<p>Starting with the Pentium Pro, in most Intel x86 processors, instructions are converted by the instruction fetch and decode unit to sequences of processor-specific micro-operations that are directly executed by the processor. For the instructions that are implemented in microcode, the microcode consists of micro-operations fetched from on-chip memory.<sup id="cite_ref-pentium-pro-tour_4-0" class="reference"><a href="#cite_note-pentium-pro-tour-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup>
</p><p>On the Pentium Pro, each micro-operation is 72-bits wide,<sup id="cite_ref-5" class="reference"><a href="#cite_note-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup><sup class="reference nowrap"><span title="Page / location: 43">: 43 </span></sup> or 118-bits wide.<sup id="cite_ref-linley-19950216_6-0" class="reference"><a href="#cite_note-linley-19950216-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup><sup class="reference nowrap"><span title="Page / location: 2">: 2 </span></sup><sup id="cite_ref-asanovic-2002_7-0" class="reference"><a href="#cite_note-asanovic-2002-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup><sup class="reference nowrap"><span title="Page / location: 14">: 14 </span></sup> This includes an opcode, two source fields, and one destination field,<sup id="cite_ref-colwell-steck-19950412_8-0" class="reference"><a href="#cite_note-colwell-steck-19950412-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup><sup class="reference nowrap"><span title="Page / location: 7">: 7 </span></sup> with the ability to hold a 32-bit immediate value.<sup id="cite_ref-linley-19950216_6-1" class="reference"><a href="#cite_note-linley-19950216-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-asanovic-2002_7-1" class="reference"><a href="#cite_note-asanovic-2002-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup><sup class="reference nowrap"><span title="Page / location: 14">: 14 </span></sup> The Pentium Pro is able to detect <a href="Parity_error" class="mw-redirect" title="Parity error">parity errors</a> in its internal microcode <abbr title="Read-Only Memory">ROM</abbr> and report these via the <a href="Machine_Check_Architecture" title="Machine Check Architecture">Machine Check Architecture</a>.<sup id="cite_ref-9" class="reference"><a href="#cite_note-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup>
</p><p>Micro-operations have a consistent format with up to three source inputs, and two destination outputs.<sup id="cite_ref-ronen-2005018_10-0" class="reference"><a href="#cite_note-ronen-2005018-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup> The processor performs <a href="Register_renaming" title="Register renaming">register renaming</a> to map these inputs to and from the real <a href="Register_file" title="Register file">register file</a> (RRF) before and after their execution.<sup id="cite_ref-ronen-2005018_10-1" class="reference"><a href="#cite_note-ronen-2005018-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup> <a href="Out-of-order_execution" title="Out-of-order execution">Out-of-order execution</a> is used, so the micro-operations and instructions they represent may not appear in the same order.
</p><p>During development of the Pentium Pro, several microcode fixes were included between the A2 and B0 steppings.<sup id="cite_ref-papworth-199604_11-0" class="reference"><a href="#cite_note-papworth-199604-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup> For the Pentium II (based on the P6 Pentium Pro), additional micro-operations were added to support the <a href="MMX_(instruction_set)" title="MMX (instruction set)">MMX instruction set</a>.<sup id="cite_ref-kagan-et-al-1997_12-0" class="reference"><a href="#cite_note-kagan-et-al-1997-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup> In several cases, "microcode assists" were added to handle rare corner-cases in a reliable way.<sup id="cite_ref-kagan-et-al-1997_12-1" class="reference"><a href="#cite_note-kagan-et-al-1997-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup>
</p><p>The Pentium 4 can have 126 micro-operations in flight at the same time.<sup id="cite_ref-hinton-et-al-2001_13-0" class="reference"><a href="#cite_note-hinton-et-al-2001-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup><sup class="reference nowrap"><span title="Page / location: 10">: 10 </span></sup> Micro-operations are decoded and stored in an Execution Trace Cache with 12,000 entries, to avoid repeated decoding of the same x86 instructions.<sup id="cite_ref-hinton-et-al-2001_13-1" class="reference"><a href="#cite_note-hinton-et-al-2001-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup><sup class="reference nowrap"><span title="Page / location: 5">: 5 </span></sup> Groups of six micro-operations are packed into a trace line.<sup id="cite_ref-hinton-et-al-2001_13-2" class="reference"><a href="#cite_note-hinton-et-al-2001-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup><sup class="reference nowrap"><span title="Page / location: 5">: 5 </span></sup> Micro-operations can borrow extra immediate data space within the same cache-line.<sup id="cite_ref-fog-micro-2020_14-0" class="reference"><a href="#cite_note-fog-micro-2020-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup><sup class="reference nowrap"><span title="Page / location: 49">: 49 </span></sup> Complex instructions, such as exception handling, result in jumping to the microcode ROM.<sup id="cite_ref-hinton-et-al-2001_13-3" class="reference"><a href="#cite_note-hinton-et-al-2001-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup><sup class="reference nowrap"><span title="Page / location: 6">: 6 </span></sup> During development of the Pentium 4, microcode accounted for 14% of processor bugs versus 30% of processor bugs during development of the Pentium Pro.<sup id="cite_ref-bentley-rand-2001_15-0" class="reference"><a href="#cite_note-bentley-rand-2001-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup><sup class="reference nowrap"><span title="Page / location: 35">: 35 </span></sup>
</p><p>The <a href="Intel_Core_(microarchitecture)" title="Intel Core (microarchitecture)">Intel Core microarchitecture</a> introduced in 2006 added "<a href="Macro-Ops_Fusion" class="mw-redirect" title="Macro-Ops Fusion">macro-operations fusion</a>" for some common pairs of instructions including comparison followed by a jump.<sup id="cite_ref-gelas-20060501_16-0" class="reference"><a href="#cite_note-gelas-20060501-16"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup> The instruction decoders in the Core convert x86 instructions into microcode in three different ways:
</p>
<table class="wikitable">
<caption>Conversion of x86 instructions to micro-operations on Core<sup id="cite_ref-gelas-20060501_16-1" class="reference"><a href="#cite_note-gelas-20060501-16"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup>
</caption>
<tbody><tr>
<th>x86 instructions</th>
<th>x86 decoders</th>
<th style="text-align:center;">micro-operations
</th></tr>
<tr>
<td>common</td>
<td>simple decoder × 3</td>
<td style="text-align:center;">1–3
</td></tr>
<tr>
<td>most others</td>
<td>complex decoder × 1</td>
<td style="text-align:center;">≤4
</td></tr>
<tr>
<td>very complex</td>
<td>microcode sequencer</td>
<td style="text-align:center;">many
</td></tr></tbody></table>
<p>For Intel's <a href="Hyper-threading" title="Hyper-threading">hyper-threading</a> implementation of <a href="Simultaneous_multithreading" title="Simultaneous multithreading">simultaneous multithreading</a>, the microcode ROM, trace cache, and instruction decoders are shared, but the micro-operation queue is not shared.<sup id="cite_ref-kim-et-al-2004_17-0" class="reference"><a href="#cite_note-kim-et-al-2004-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Update_facility">Update facility</h2></div>
<p>In the mid-1990s, a facility for supplying new microcode was initially referred to as the Pentium Pro <b>BIOS Update Feature</b>.<sup id="cite_ref-intel-bios-19960112_18-0" class="reference"><a href="#cite_note-intel-bios-19960112-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Stiller_1996_19-0" class="reference"><a href="#cite_note-Stiller_1996-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup> It was intended that user-mode applications should make a <a href="BIOS_interrupt_call" title="BIOS interrupt call">BIOS interrupt call</a> to supply a new "BIOS Update Data Block", which the BIOS would partially validate and save to <a href="Nonvolatile_BIOS_memory" title="Nonvolatile BIOS memory">nonvolatile BIOS memory</a>; this could be supplied to the installed processors on next boot.<sup id="cite_ref-intel-bios-19960112_18-1" class="reference"><a href="#cite_note-intel-bios-19960112-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup>
</p><p>Intel distributed a program called <code>BUP_UTIL.EXE</code>, renamed <code>CHECKUP3.EXE</code> that could be run under <a href="DOS" title="DOS">DOS</a>. Collections of multiple microcode updates were concatenated together and numerically numbered with the extension <code>.PDB</code>, such as <code>PEP6.PDB</code>.<sup id="cite_ref-mueller-199809_20-0" class="reference"><a href="#cite_note-mueller-199809-20"><span class="cite-bracket">[</span>20<span class="cite-bracket">]</span></a></sup><sup class="reference nowrap"><span title="Page / location: 79">: 79 </span></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Processor_interface">Processor interface</h3></div>
<p>The processor boots up using a set of microcode held inside the processor and stored in an internal <a href="Read-only_memory" title="Read-only memory">ROM</a>.<sup id="cite_ref-gwennap-20070915_1-3" class="reference"><a href="#cite_note-gwennap-20070915-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> A microcode update populates a separate <a href="Static_random-access_memory" title="Static random-access memory">SRAM</a> and set of "match registers" that act as <a href="Breakpoint" title="Breakpoint">breakpoints</a> within the microcode ROM, to allow <a href="Branch_(computer_science)" title="Branch (computer science)">jumping</a> to the updated list of micro-operations in the SRAM.<sup id="cite_ref-gwennap-20070915_1-4" class="reference"><a href="#cite_note-gwennap-20070915-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> A match is performed between the Microcode Instruction Pointer (UIP) all of the match registers, with any match resulting in a jump to the corresponding destination microcode address.<sup id="cite_ref-intel-dft-1998_2-1" class="reference"><a href="#cite_note-intel-dft-1998-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup><sup class="reference nowrap"><span title="Page / location: 3">: 3 </span></sup> In the original P6 architecture there is space in the SRAM for 60 micro-operations, and multiple match/destination register pairs.<sup id="cite_ref-gwennap-20070915_1-5" class="reference"><a href="#cite_note-gwennap-20070915-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-intel-dft-1998_2-2" class="reference"><a href="#cite_note-intel-dft-1998-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup><sup class="reference nowrap"><span title="Page / location: 3">: 3 </span></sup> It takes one processor <a href="Instruction_cycle" title="Instruction cycle">instruction cycle</a> to jump from ROM microcode to patched microcode held in SRAM.<sup id="cite_ref-gwennap-20070915_1-6" class="reference"><a href="#cite_note-gwennap-20070915-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> Match registers consist of a microcode match address, and a microcode destination address.<sup id="cite_ref-chen-ahn-20141211_21-0" class="reference"><a href="#cite_note-chen-ahn-20141211-21"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup>
</p><p>The processor must be in <a href="Protection_ring" title="Protection ring">protection ring</a> zero ("<span class="nowrap">Ring 0</span>") in order to initiate a microcode update.<sup id="cite_ref-chen-ahn-20141211_21-1" class="reference"><a href="#cite_note-chen-ahn-20141211-21"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup><sup class="reference nowrap"><span title="Page / location: 1">: 1 </span></sup> Each CPU in a <a href="Symmetric_multiprocessing" title="Symmetric multiprocessing">symmetric multiprocessing</a> arrangement needs to be updated individually.<sup id="cite_ref-chen-ahn-20141211_21-2" class="reference"><a href="#cite_note-chen-ahn-20141211-21"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup><sup class="reference nowrap"><span title="Page / location: 1">: 1 </span></sup>
</p><p>An update is initiated by placing its address in <code>eax</code> register, setting <code>ecx = 0x79</code>, and executing a <code>wrmsr</code> (Write <a href="Model-specific_register" title="Model-specific register">model-specific register</a>).<sup id="cite_ref-shanley-1998_22-0" class="reference"><a href="#cite_note-shanley-1998-22"><span class="cite-bracket">[</span>22<span class="cite-bracket">]</span></a></sup><sup class="reference nowrap"><span title="Page / location: 435">: 435 </span></sup>
</p>
<div class="mw-heading mw-heading4"><h4 id="Microcode_update_format">Microcode update format</h4></div>
<p>Intel distributes microcode updates as a 2,048 (2 kilobyte) <a href="Binary_blob" title="Binary blob">binary blob</a>.<sup id="cite_ref-gwennap-20070915_1-7" class="reference"><a href="#cite_note-gwennap-20070915-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> The update contains information about which processors it is designed for, so that this can be checked against the result of the <a href="CPUID" title="CPUID">CPUID</a> instruction.<sup id="cite_ref-gwennap-20070915_1-8" class="reference"><a href="#cite_note-gwennap-20070915-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> The structure is a 48-byte header, followed by 2,000 bytes intended to be read directly by the processor to be updated:<sup id="cite_ref-gwennap-20070915_1-9" class="reference"><a href="#cite_note-gwennap-20070915-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>
</p>
<ol><li>A microcode program that is executed by the processor during the microcode update process.<sup id="cite_ref-gwennap-20070915_1-10" class="reference"><a href="#cite_note-gwennap-20070915-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> This microcode is able to reconfigure and enable or disable components using a special register, and it must update the breakpoint match registers.<sup id="cite_ref-gwennap-20070915_1-11" class="reference"><a href="#cite_note-gwennap-20070915-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup></li>
<li>Up to sixty patched micro-operations to be populated into the SRAM.<sup id="cite_ref-gwennap-20070915_1-12" class="reference"><a href="#cite_note-gwennap-20070915-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Padding_(cryptography)" title="Padding (cryptography)">Padding</a> consisting of random values, to obfuscate understanding of the format of the microcode update.<sup id="cite_ref-gwennap-20070915_1-13" class="reference"><a href="#cite_note-gwennap-20070915-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup></li></ol>
<p>Each block is encoded differently, and the majority of the 2,000 bytes are not used as configuration program and SRAM micro-operation contents themselves are much smaller.<sup id="cite_ref-gwennap-20070915_1-14" class="reference"><a href="#cite_note-gwennap-20070915-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> Final determination and validation of whether an update can be applied to a processor is performed during <a href="Decryption" class="mw-redirect" title="Decryption">decryption</a> via the processor.<sup id="cite_ref-intel-bios-19960112_18-2" class="reference"><a href="#cite_note-intel-bios-19960112-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup> Each microcode update is specific to a particular CPU revision, and is designed to be rejected by CPUs with a different <a href="Stepping_level" title="Stepping level">stepping level</a>. Microcode updates are encrypted to prevent tampering and to enable validation.<sup id="cite_ref-23" class="reference"><a href="#cite_note-23"><span class="cite-bracket">[</span>23<span class="cite-bracket">]</span></a></sup>
</p><p>With the Pentium there are two layers of encryption and the precise details explicitly <em>not</em> documented by Intel, instead being only known to fewer than ten employees.<sup id="cite_ref-wolfe-1997_24-0" class="reference"><a href="#cite_note-wolfe-1997-24"><span class="cite-bracket">[</span>24<span class="cite-bracket">]</span></a></sup>
</p><p>Microcode updates for <a href="Intel_Atom" title="Intel Atom">Intel Atom</a>, <a href="Nehalem_(microarchitecture)" title="Nehalem (microarchitecture)">Nehalem</a> and <a href="Sandy_Bridge" title="Sandy Bridge">Sandy Bridge</a> additionally contain an extra 520-byte header containing a 2048-bit <a href="RSA_(cryptosystem)" class="mw-redirect" title="RSA (cryptosystem)">RSA</a> modulus with an exponent of 17 decimal.<sup id="cite_ref-chen-ahn-20141211_21-3" class="reference"><a href="#cite_note-chen-ahn-20141211-21"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup><sup class="reference nowrap"><span title="Page / location: 7, 8">: 7, 8 </span></sup>
</p>
<table class="wikitable">
<caption>Observed Intel microcode data-block lengths (in bytes)<sup id="cite_ref-chen-ahn-20141211_21-4" class="reference"><a href="#cite_note-chen-ahn-20141211-21"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup><sup class="reference nowrap"><span title="Page / location: 16">: 16 </span></sup>
</caption>
<tbody><tr>
<th>Micro architecture</th>
<th>Example processors</th>
<th>Supplied length</th>
<th>Functional length</th>
<th>Suspected encoding
</th></tr>
<tr>
<td>P6</td>
<td><span class="nowrap">Pentium Pro</span></td>
<td style="text-align:right;">2000</td>
<td style="text-align:right;">864; 872; 944; 1968</td>
<td rowspan="2">64-bit block cipher
</td></tr>
<tr>
<td>Core</td>
<td>PIII … <span class="nowrap">Core 2</span></td>
<td style="text-align:right;">4048</td>
<td style="text-align:right;">3096
</td></tr>
<tr>
<td>Netburst</td>
<td><span class="nowrap"><abbr title="Pentium 4">P4</abbr></span>, <span class="nowrap">Pentium D</span>, Celeron</td>
<td style="text-align:right;">2000–7120</td>
<td style="text-align:right;">2000 + N*1024</td>
<td>chained block cipher
</td></tr>
<tr>
<td>Atom, Nehalem, <span class="nowrap">Sandy Bridge</span></td>
<td><span class="nowrap">Core i3/i5/i7</span></td>
<td style="text-align:right;">976–16336</td>
<td style="text-align:right;">976 + N*1024; 5120</td>
<td>AES + RSA signature
</td></tr></tbody></table>
<div class="mw-heading mw-heading2"><h2 id="Debugging">Debugging</h2></div>
<p>Special debugging-specific microcode can be loaded to enable Extended Execution Trace, which then outputs extra information via the Breakpoint Monitor Pins.<sup id="cite_ref-hardice_25-0" class="reference"><a href="#cite_note-hardice-25"><span class="cite-bracket">[</span>25<span class="cite-bracket">]</span></a></sup> On the Pentium 4, loading special microcode can give access to Microcode Extended Execution Trace mode.<sup id="cite_ref-hardice_25-1" class="reference"><a href="#cite_note-hardice-25"><span class="cite-bracket">[</span>25<span class="cite-bracket">]</span></a></sup> When using the <a href="JTAG" title="JTAG">JTAG</a> Test Access Port (TAP), a pair of Breakpoint Control registers allow breaking on microcode addresses.<sup id="cite_ref-hardice_25-2" class="reference"><a href="#cite_note-hardice-25"><span class="cite-bracket">[</span>25<span class="cite-bracket">]</span></a></sup>
</p><p>During the mid-1980s <a href="NEC" title="NEC">NEC</a> and Intel had a long-running US federal court case about microcode copyright.<sup id="cite_ref-elkins-1990_26-0" class="reference"><a href="#cite_note-elkins-1990-26"><span class="cite-bracket">[</span>26<span class="cite-bracket">]</span></a></sup> NEC had been acting as a <a href="Second_source" title="Second source">second source</a> for <a href="Intel_8086" title="Intel 8086">Intel 8086</a> CPUs with its NEC μPD8086, and held long-term patent and copyright cross-licensing agreements with Intel. In August 1982 Intel sued NEC for copyright infringement over the microcode implementation.<sup id="cite_ref-hinckley-198701_27-0" class="reference"><a href="#cite_note-hinckley-198701-27"><span class="cite-bracket">[</span>27<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-leong-19880328_28-0" class="reference"><a href="#cite_note-leong-19880328-28"><span class="cite-bracket">[</span>28<span class="cite-bracket">]</span></a></sup> NEC prevailed by demonstrating via <a href="Clean_room_design" class="mw-redirect" title="Clean room design">cleanroom software engineering</a> that the similarities in the implementation of microcode on its V20 and V30 processors was the result of the restrictions demanded by the architecture, rather than via copying.<sup id="cite_ref-elkins-1990_26-1" class="reference"><a href="#cite_note-elkins-1990-26"><span class="cite-bracket">[</span>26<span class="cite-bracket">]</span></a></sup>
</p><p>The <a href="Intel_386" class="mw-redirect" title="Intel 386">Intel 386</a> can perform a <a href="Built-in_self-test" title="Built-in self-test">built-in self-test</a> of the microcode and <a href="Programmable_logic_array" title="Programmable logic array">programmable logic arrays</a>, with the value of the self-test placed in the <code>EAX</code> register.<sup id="cite_ref-intel-386-dx-199512_29-0" class="reference"><a href="#cite_note-intel-386-dx-199512-29"><span class="cite-bracket">[</span>29<span class="cite-bracket">]</span></a></sup> During the BIST, the microprogram counter is re-used to walk through all of the ROMs, with the results being collated via a network of multiple-input signature registers (MISRs) and linear-feedback shift registers.<sup id="cite_ref-30" class="reference"><a href="#cite_note-30"><span class="cite-bracket">[</span>30<span class="cite-bracket">]</span></a></sup> On start up of the <a href="Intel_486" class="mw-redirect" title="Intel 486">Intel 486</a>, a hardware-controlled BIST runs for 2<sup>20</sup> clock cycles to check various arrays including the microcode ROM, after which control is transferred to the microcode for further self-testing of registers and computation units.<sup id="cite_ref-gelsinger-1999_31-0" class="reference"><a href="#cite_note-gelsinger-1999-31"><span class="cite-bracket">[</span>31<span class="cite-bracket">]</span></a></sup> The Intel 486 microcode ROM has 250,000 transistors.<sup id="cite_ref-gelsinger-1999_31-1" class="reference"><a href="#cite_note-gelsinger-1999-31"><span class="cite-bracket">[</span>31<span class="cite-bracket">]</span></a></sup>
</p><p>AMD had a long-term contract to reuse Intel's 286, 386 and 486 microcode.<sup id="cite_ref-infoworld-20041017_32-0" class="reference"><a href="#cite_note-infoworld-20041017-32"><span class="cite-bracket">[</span>32<span class="cite-bracket">]</span></a></sup> In October 2004, a court ruled that the agreement did not cover AMD distributing Intel's 486 <a href="In-circuit_emulation" title="In-circuit emulation">in-circuit emulation</a> (ICE) microcode.<sup id="cite_ref-infoworld-20041017_32-1" class="reference"><a href="#cite_note-infoworld-20041017-32"><span class="cite-bracket">[</span>32<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Direct_Access_Testing">Direct Access Testing</h3></div>
<p>Direct Access Testing (DAT) is included in Intel CPUs as part of the <a href="Design_for_testing" title="Design for testing">design for testing</a> (DFT) and Design for Debug (DFD) initiatives allow full coverage testing of individual CPUs prior to sale.<sup id="cite_ref-wu-2004_33-0" class="reference"><a href="#cite_note-wu-2004-33"><span class="cite-bracket">[</span>33<span class="cite-bracket">]</span></a></sup>
</p><p>In May 2020, a script reading directly from the Control Register Bus (CRBUS)<sup id="cite_ref-34" class="reference"><a href="#cite_note-34"><span class="cite-bracket">[</span>34<span class="cite-bracket">]</span></a></sup> (after exploiting "Red Unlock" in JTAG USB-A to USB-A 3.0 with Debugging Capabilities, without D+, D− and Vcc<sup id="cite_ref-35" class="reference"><a href="#cite_note-35"><span class="cite-bracket">[</span>35<span class="cite-bracket">]</span></a></sup>) was used to read from the Local Direct Access Test (LDAT) port of the Intel <a href="Goldmont" title="Goldmont">Goldmont</a> CPU and the loaded microcode and patch arrays were read.<sup id="cite_ref-ermolev-20200519-2_36-0" class="reference"><a href="#cite_note-ermolev-20200519-2-36"><span class="cite-bracket">[</span>36<span class="cite-bracket">]</span></a></sup> These arrays are only accessible after the CPU has been put into a specific mode, and consist of five arrays accessed through offset 0x6a0:<sup id="cite_ref-bosch-20200522_37-0" class="reference"><a href="#cite_note-bosch-20200522-37"><span class="cite-bracket">[</span>37<span class="cite-bracket">]</span></a></sup>
</p>
<div><ol start="0"><li>ROM: Microcode triads</li><li>ROM: Sequence Words</li><li>RAM: Sequence Words (updatable)</li><li>RAM: Match/Patch pairs (updatable)</li><li>RAM: Microcode triads (updatable)</li></ol></div>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */


.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}


/* end https://en.wikipedia.org/ */
</style><div class="reflist">
<div class="mw-references-wrap mw-references-columns"><ol class="references">
<li id="cite_note-gwennap-20070915-1"><span class="mw-cite-backlink">^ <a href="#cite_ref-gwennap-20070915_1-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-gwennap-20070915_1-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-gwennap-20070915_1-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-gwennap-20070915_1-3"><sup><i><b>d</b></i></sup></a> <a href="#cite_ref-gwennap-20070915_1-4"><sup><i><b>e</b></i></sup></a> <a href="#cite_ref-gwennap-20070915_1-5"><sup><i><b>f</b></i></sup></a> <a href="#cite_ref-gwennap-20070915_1-6"><sup><i><b>g</b></i></sup></a> <a href="#cite_ref-gwennap-20070915_1-7"><sup><i><b>h</b></i></sup></a> <a href="#cite_ref-gwennap-20070915_1-8"><sup><i><b>i</b></i></sup></a> <a href="#cite_ref-gwennap-20070915_1-9"><sup><i><b>j</b></i></sup></a> <a href="#cite_ref-gwennap-20070915_1-10"><sup><i><b>k</b></i></sup></a> <a href="#cite_ref-gwennap-20070915_1-11"><sup><i><b>l</b></i></sup></a> <a href="#cite_ref-gwennap-20070915_1-12"><sup><i><b>m</b></i></sup></a> <a href="#cite_ref-gwennap-20070915_1-13"><sup><i><b>n</b></i></sup></a> <a href="#cite_ref-gwennap-20070915_1-14"><sup><i><b>o</b></i></sup></a></span> <span class="reference-text"><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */


.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}


/* end https://en.wikipedia.org/ */
</style><cite id="CITEREFGwennap1997" class="citation news cs1">Gwennap, Linley (15 September 1997). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20091221182054/https://www.ele.uva.es/~jesman/BigSeti/ftp/Cajon_Desastre/MPR/111204.pdf">"P6 Microcode Can Be Patched"</a> <span class="cs1-format">(PDF)</span>. <i><a href="Microprocessor_Report" title="Microprocessor Report">Microprocessor Report</a></i>. Archived from <a rel="nofollow" class="external text" href="https://www.ele.uva.es/~jesman/BigSeti/ftp/Cajon_Desastre/MPR/111204.pdf">the original</a> <span class="cs1-format">(PDF)</span> on 21 December 2009<span class="reference-accessdate">. Retrieved <span class="nowrap">23 January</span> 2018</span>. <q>Intel has implemented a microcode patch capability in its <a href="P6_(microarchitecture)" title="P6 (microarchitecture)">P6</a> processors, including <a href="Pentium_Pro" title="Pentium Pro">Pentium Pro</a> and <a href="Pentium_II" title="Pentium II">Pentium II</a> … allows the microcode to be altered after the processor is fabricated, repairing bugs that are found after the processor is designed. … originally intended the feature to be used only for debugging, but after dealing with the expense of the <a href="Pentium_FDIV_bug" title="Pentium FDIV bug">Pentium FDIV bug</a> … Intel decided to make it usable in the field. … P6 chip contains a complete set of microcode in an internal <a href="Read-only_memory" title="Read-only memory">ROM</a> … BIOS writes a memory address into a special CPU register to trigger a download sequence … P6 processors contain a small <a href="Static_random-access_memory" title="Static random-access memory">SRAM</a> that holds up to 60 microinstructions. The patch code is downloaded into this SRAM … also contains a set of "match" registers that cause a trap when a particular microcode address is encountered. (This is similar to the "instruction <a href="Breakpoint" title="Breakpoint">breakpoint</a>" capability used to debug <a href="Assembly_language" title="Assembly language">assembly code</a>.) This trap, which takes a single cycle to process, vectors microcode execution into the patch RAM. … downloaded microcode consists of two segments. … first is an initialization routine that is run immediately … also initializes the match registers, if necessary. … second segment contains one or more patches that remain in the patch RAM during normal operation and are accessed via a match-register trap. … original microcode is stored in ROM, … match registers allow the operation of the microcode to be changed. In this way, an <a href="X86_assembly_language" title="X86 assembly language">x86 instruction</a> that is operating incorrectly can be repaired, assuming it is implemented in microcode. … a patch is created to replace a section of the original microcode, performing the correct operation and then <a href="Branch_(computer_science)" title="Branch (computer science)">jumping</a> back. … number of match registers, … more than one. … single bug, … might require multiple patches, and some bugs are too complex to repair … mechanism could allow multiple bugs to be fixed, … features of the P6 processor can be disabled via a special register … 2,048-byte block of data. The block contains a 48-byte header—which includes a date code, the <a href="CPUID" title="CPUID">CPU ID</a> (which includes the <a href="Stepping_level" title="Stepping level">stepping level</a>) of the target processor, and a checksum—and 2,000 bytes of data to be downloaded by the processor. … checksum … is not used by the CPU. … 2,000 data bytes are encrypted in a way that Intel claims will be extremely difficult to break. The bytes are divided into blocks of varying lengths, each of which is encoded differently. … typically much smaller than 2,000 bytes, the remaining data is random noise intended to confuse anyone attempting to break the encryption. … Intel has not published any information on the format of its microcode, … is deliberately designed to be difficult to understand. Only a small number of Intel employees know the P6 microcode formats.</q></cite></span>
</li>
<li id="cite_note-intel-dft-1998-2"><span class="mw-cite-backlink">^ <a href="#cite_ref-intel-dft-1998_2-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-intel-dft-1998_2-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-intel-dft-1998_2-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFYeoh_Eng_HongLim_Seong_LeongWong_Yik_ChoongLock_Choon_Hou1998" class="citation journal cs1">Yeoh Eng Hong; Lim Seong Leong; Wong Yik Choong; Lock Choon Hou; Mahmud Adnan (20 April 1998). Chao, Lin (ed.). <a rel="nofollow" class="external text" href="https://www.intel.com/content/dam/www/public/us/en/documents/research/1998-vol02-iss-2-intel-technology-journal.pdf">"An Overview of Advanced Failure Analysis Techniques for Pentium and Pentium Pro Microprocessors"</a> <span class="cs1-format">(PDF)</span>. <i>Intel Technology Journal</i> (Q2). <q>Pentium Pro microprocessor ... Micropatching <abbr title="Design For Testability">DFT</abbr> feature. ... consists of two key elements: the microcode patch RAM and several pairs of Match and Destination registers. ... Microcode Instruction Pointer (UIP) matches the content of a Match register, the UIP will be reloaded with a new address from the Destination register. ... <abbr title="Microcode Instruction Pointer">UIP</abbr> for the reset subroutine can be set in the Match register ... thereby bypassing the reset subroutine altogether.</q></cite></span>
</li>
<li id="cite_note-trumbull-1994-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-trumbull-1994_3-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFTrumbull1994" class="citation report cs1">Trumbull, Patricia V. (1994-10-07). <a rel="nofollow" class="external text" href="https://ir.amd.com/sec-filings/content/0000898430-94-000804/EX-99_1.txt">Intel Corporation v. Advanced Micro Devices</a> (Findings of fact and conclusions of law following "<a href="In-circuit_emulation" title="In-circuit emulation">ICE</a>" module of trial). <a href="United_States_District_Court_for_the_Northern_District_of_California" title="United States District Court for the Northern District of California">United States District Court for the Northern District of California</a>. San Jose<span class="reference-accessdate">. Retrieved <span class="nowrap">2021-05-10</span></span> – via <a href="Advanced_Micro_Devices" class="mw-redirect" title="Advanced Micro Devices">Advanced Micro Devices</a>. <q>Twelve pins are affiliated with the "ICE" circuitry. … AMD 486DXL and DXLV connect three pins associated with "<a href="In-circuit_emulation" title="In-circuit emulation">ICE</a>" in order to implement its "<a href="System_Management_Mode" title="System Management Mode">SMM</a>" feature. … 250 lines or 12,032 bits of the "ICE" microcode in the <a href="Intel_80486" class="mw-redirect" title="Intel 80486">486</a>. "<a href="In-circuit_emulation" title="In-circuit emulation">ICE</a>" constitutes about five percent of the total 486 microcode. … two lines … (used to set the "<a href="In-circuit_emulation" title="In-circuit emulation">ICE</a>" mode "<a href="Flip-flop_(electronics)" title="Flip-flop (electronics)">flip flop</a>") … blue coded lines of microcode are associated with production testing and not used for "<a href="In-circuit_emulation" title="In-circuit emulation">ICE</a>" related purposes. … Seventy-five red coded lines were used by Intel to perform "<a href="System_Management_Mode" title="System Management Mode">SMM</a>" in its 486SL, a data sheet function of this version of the chip. About 32 yellow coded lines perform routine operations which are not unique to "ICE." About two lines remain dedicated solely to "ICE."</q></cite></span>
</li>
<li id="cite_note-pentium-pro-tour-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-pentium-pro-tour_4-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/19961220080210/http://www.intel.com/procs/ppro/info/p6white/index.htm">"A Tour of the Pentium Pro Processor Microarchitecture"</a>. <i>Intel</i>. Archived from <a rel="nofollow" class="external text" href="http://www.intel.com/procs/ppro/info/p6white/index.htm">the original</a> on 1996-12-20.</cite></span>
</li>
<li id="cite_note-5"><span class="mw-cite-backlink"><b><a href="#cite_ref-5">^</a></b></span> <span class="reference-text"><cite id="CITEREFKubiatowicz2004" class="citation journal cs1">Kubiatowicz, John (3 May 2004). <a rel="nofollow" class="external text" href="https://people.eecs.berkeley.edu/~kubitron/courses/cs152-S04/lectures/lec25-power.pdf">"Dynamic Scheduling in P6 (Pentium Pro, II, III)"</a> <span class="cs1-format">(PDF)</span>. <i>Low Power Design, Advanced Intel Processors</i>. CS152 Computer Architecture and Engineering (Lecture 25). <q>Complex 80x86 instructions are executed by a conventional microprogram (<abbr title="8192">8K</abbr> x 72 bits) that issues long sequences of micro-operations</q></cite></span>
</li>
<li id="cite_note-linley-19950216-6"><span class="mw-cite-backlink">^ <a href="#cite_ref-linley-19950216_6-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-linley-19950216_6-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFGwennap1995" class="citation news cs1">Gwennap, Linley (16 February 1995). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20181008134943/https://pdfs.semanticscholar.org/fe2b/b73d7046a6ed87ce9b18d62f194d67fa2100.pdf">"Intel's P6 Uses Decoupled Superscalar Design"</a> <span class="cs1-format">(PDF)</span>. <i><a href="Microprocessor_Report" title="Microprocessor Report">Microprocessor Report</a></i>. Vol.&nbsp;9, no.&nbsp;2. MicroDesign Resources. pp.&nbsp;<span class="nowrap">1–</span>7. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:14414612">14414612</a>. Archived from <a rel="nofollow" class="external text" href="https://pdfs.semanticscholar.org/fe2b/b73d7046a6ed87ce9b18d62f194d67fa2100.pdf">the original</a> <span class="cs1-format">(PDF)</span> on 8 October 2018. <q>P6 uops have a fixed length of 118 bits, using a regular structure to encode an operation, two sources, and a destination. The source and destination fields are each wide enough to contain a 32-bit operand.</q></cite></span>
</li>
<li id="cite_note-asanovic-2002-7"><span class="mw-cite-backlink">^ <a href="#cite_ref-asanovic-2002_7-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-asanovic-2002_7-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFAsanovic2002" class="citation journal cs1"><a href="Krste_Asanovi%C4%87" title="Krste Asanović">Asanovic, Krste</a> (2002). <a rel="nofollow" class="external text" href="https://dspace.mit.edu/bitstream/handle/1721.1/35849/6-823Spring-2002/NR/rdonlyres/Electrical-Engineering-and-Computer-Science/6-823Computer-System-ArchitectureSpring2002/4E0FC5FE-6F01-43D7-95FE-91E32EB349CF/0/lecture20.pdf">"P6 uops"</a> <span class="cs1-format">(PDF)</span>. <i>Microprocessor Evolution: 4004 to Pentium Pro</i> (Spring): 14<span class="reference-accessdate">. Retrieved <span class="nowrap">23 January</span> 2018</span>. <q>Each uop has fixed format of around 118 bits … – opcode, two sources, and destination … – sources and destination fields are 32-bits wide to hold immediate or operand</q></cite></span>
</li>
<li id="cite_note-colwell-steck-19950412-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-colwell-steck-19950412_8-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFColwellSteckIntel_Corporation1995" class="citation web cs1">Colwell, Robert P.; Steck, Randy L.; Intel Corporation (1995-04-12). <a rel="nofollow" class="external text" href="http://datasheets.chipdb.org/Intel/x86/P6/p6updt.pdf">"A 0.6 μm BiCMOS Processor With Dynamic Execution"</a> <span class="cs1-format">(PDF)</span>. p.&nbsp;7<span class="reference-accessdate">. Retrieved <span class="nowrap">2020-05-27</span></span>. <q>Micro-ops are the atomic unit of work in the P6 processor and are comprised of an opcode, two source and one destination operand. These micro-ops are fixed length and are more general than the Pentium(R) processor's microcode since they need to be scheduled.</q></cite></span>
</li>
<li id="cite_note-9"><span class="mw-cite-backlink"><b><a href="#cite_ref-9">^</a></b></span> <span class="reference-text"><cite class="citation report cs1 cs1-prop-long-vol cs1-prop-unfit"><a rel="nofollow" class="external text" href="http://folk.uio.no/inf242/doc/242692_1.pdf">16.6.1. Simple Error Codes</a> <span class="cs1-format">(PDF)</span>. <i>Machine Check Architecture</i> (Report). Pentium® Pro Family Developer's Manual. Vol.&nbsp;3: Operating System Writer's Guide. 3 January 1996. p.&nbsp;401. Archived from the original on 6 September 2001<span class="reference-accessdate">. Retrieved <span class="nowrap">1 October</span> 2018</span>. <q>unique codes indicate global error information … Microcode ROM Parity Error</q></cite></span>
</li>
<li id="cite_note-ronen-2005018-10"><span class="mw-cite-backlink">^ <a href="#cite_ref-ronen-2005018_10-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-ronen-2005018_10-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFRonenIntel_Labs2005" class="citation report cs1">Ronen, Ronny; Intel Labs (18 January 2005). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20070416221626/http://www.cs.tau.ac.il/~afek/p6tx050111.pdf">Micro Operations (Uops)</a> <span class="cs1-format">(PDF)</span>. <i>The Pentium II/III Processor "Compiler on a Chip"</i> (Report). Haifa: <a href="Tel_Aviv_University" title="Tel Aviv University">Tel Aviv University</a>. pp.&nbsp;26, 31, 32, 43, 44, 46. Archived from <a rel="nofollow" class="external text" href="http://www.cs.tau.ac.il/~afek/p6tx050111.pdf">the original</a> <span class="cs1-format">(PDF)</span> on 16 April 2007<span class="reference-accessdate">. Retrieved <span class="nowrap">23 January</span> 2018</span>. <q>Each "<a href="Complex_instruction_set_computer" title="Complex instruction set computer">CISC</a>" <abbr title="instruction">inst</abbr> is broken into one or more <a href="Micro-operation" title="Micro-operation">uops</a> … Canonical representation of <abbr title="source">src</abbr>/<abbr title="destination">dest</abbr> (3 <abbr title="source">src</abbr>, 2 <abbr title="destination">dest</abbr>) … e.g., <code>pop eax</code> becomes <code>esp1&lt;-esp0+4, eax1&lt;-[esp0]</code> … <abbr title="Instruction Decoder">ID</abbr>: Convert instructions into <abbr title="micro-operations">uops</abbr>. Buffers up to 6 <abbr title="micro-operations">uops</abbr> … <abbr title="Allocation">Alloc</abbr> &amp; <abbr title="Register Alias Table">RAT</abbr> … able to work on up to 3 <abbr title="micro-operations">uops</abbr> per clock … Reservation station (RS) … Pool of all "not yet executed" <abbr title="micro-operations">uops</abbr> (up to 20) … In order Retirement: … Retires up to 3 <abbr title="micro-operations">uops</abbr> per clock … <abbr title="Out Of Order">OOO</abbr> Cluster … Up to 5 resource-ready <abbr title="micro-operations">uops</abbr> are selected, and dispatched per clock</q></cite></span>
</li>
<li id="cite_note-papworth-199604-11"><span class="mw-cite-backlink"><b><a href="#cite_ref-papworth-199604_11-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFPapworthIntel_Corporation1996" class="citation news cs1">Papworth, David B.; Intel Corporation (April 1996). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20181008095801/http://web.cecs.pdx.edu/~berkina/R10_papworth_ieeemicro_1996.pdf">"Tuning the Pentium Pro Microarchitecture"</a> <span class="cs1-format">(PDF)</span>. <i>IEEE Micro</i>. p.&nbsp;14. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a>&nbsp;<a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/0272-1732">0272-1732</a>. Archived from <a rel="nofollow" class="external text" href="http://web.cecs.pdx.edu/~berkina/R10_papworth_ieeemicro_1996.pdf">the original</a> <span class="cs1-format">(PDF)</span> on 8 October 2018<span class="reference-accessdate">. Retrieved <span class="nowrap">8 October</span> 2018</span>. <q>B0 stepping incorporated several microcode bugs and speed path fixes for problems discovered on the A-step silicon</q></cite></span>
</li>
<li id="cite_note-kagan-et-al-1997-12"><span class="mw-cite-backlink">^ <a href="#cite_ref-kagan-et-al-1997_12-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-kagan-et-al-1997_12-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFKaganGochmanOrenstienLin1997" class="citation journal cs1">Kagan, Michael; Gochman, Simcha; Orenstien, Doron; Lin, Derrick (1997). <a rel="nofollow" class="external text" href="https://www.smtnet.com/library/files/upload/pentium-microarchitecture.pdf">"MMX Microarchitecture of Pentium Processors With MMX Technology and Pentium II Microprocessors"</a> <span class="cs1-format">(PDF)</span>. <i>Intel Technology Journal</i> (Q3): 6, 7. <q>Pentium II processor's microarchitecture is similar to that of the Pentium Pro microprocessor … modified to convert the new <a href="MMX_(instruction_set)" title="MMX (instruction set)">MMX</a> instructions to Pentium Pro processor-specific uops (new Single Instruction Multiple Data [SIMD] uops were added to implement the new functionality). … A microcode assist was created to correct the problem and redo the operation. An assist is a customer-invisible event that flushes out the machine and allows microcode to handle rare but difficult-to-handle problems. Since all MMX instructions zero the <abbr title="Top of Stack">TOS</abbr>, the assist needs to write the <abbr title="Top of Stack">TOS</abbr> to zero and restart the operation. … Illegal opcodes that are instruction holes in the MMX instruction opcode map are defined to generate a one uop assist call. This assist call instructs the ROB to flush the machine and causes an assist microcode flow to cause the processor to handle illegal opcode faults.</q></cite></span>
</li>
<li id="cite_note-hinton-et-al-2001-13"><span class="mw-cite-backlink">^ <a href="#cite_ref-hinton-et-al-2001_13-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-hinton-et-al-2001_13-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-hinton-et-al-2001_13-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-hinton-et-al-2001_13-3"><sup><i><b>d</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFHintonSagerUptonBoggs2001" class="citation news cs1">Hinton, Glenn; Sager, Dave; Upton, Mike; Boggs, Darrell; Carmean, Doug; Kyker, Alan; Roussel, Patrice (2001). Chao, Lin (ed.). <a rel="nofollow" class="external text" href="https://www.intel.com/content/dam/www/public/us/en/documents/research/2001-vol05-iss-1-intel-technology-journal.pdf">"The Microarchitecture of the Pentium 4 Processor"</a> <span class="cs1-format">(PDF)</span>. <i>Intel Technology Journal</i>. No.&nbsp;Q1. <q>IA-32 instruction bytes are then decoded into basic operations called uops (micro-operations) … advanced form of a Level 1 (L1) instruction cache called the Execution Trace Cache … between the instruction decode logic and the execution core … to store the already decoded … uops. … instructions are decoded once … then used repeatedly from there … has a capacity to hold up to 12K uops … similar hit rate to an 8K to 16K byte conventional instruction cache. … packs the uops into groups of six uops per trace line … microcode ROM … for complex IA-32 instructions, such as string move, and for fault and interrupt handling … Trace Cache jumps into the microcode ROM which then issues the uops … After the microcode ROM finishes sequencing uops … front end of the machine resumes fetching uops from the Trace Cache. … deep buffering of the Pentium 4 processor (126 uops and 48 loads in flight)</q></cite></span>
</li>
<li id="cite_note-fog-micro-2020-14"><span class="mw-cite-backlink"><b><a href="#cite_ref-fog-micro-2020_14-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFFog2020" class="citation web cs1">Fog, Agner (2020-05-25). <a rel="nofollow" class="external text" href="https://www.agner.org/optimize/microarchitecture.pdf">"The microarchitecture of Intel, AMD and VIA CPUs"</a> <span class="cs1-format">(PDF)</span> (An optimization guide for assembly programmers and compiler makers). Technical University of Denmark. p.&nbsp;49. <q>… If a μop has an immediate 32-bit operand outside the ±2<sup>15</sup> interval so that it cannot be represented as a 16-bit signed integer, then it will use two trace cache entries unless it can borrow storage space from a nearby μop. … A μop in need of extra storage space can borrow 16 bits of extra storage space from a nearby μop that doesn't need its own data space.</q></cite></span>
</li>
<li id="cite_note-bentley-rand-2001-15"><span class="mw-cite-backlink"><b><a href="#cite_ref-bentley-rand-2001_15-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFBentleyGray2001" class="citation journal cs1">Bentley, Bob; Gray, Rand (2001). Chao, Lin (ed.). <a rel="nofollow" class="external text" href="https://www.intel.com/content/dam/www/public/us/en/documents/research/2001-vol05-iss-1-intel-technology-journal.pdf">"Validating The Intel® Pentium® 4 Processor"</a> <span class="cs1-format">(PDF)</span>. <i>Intel Technology Journal</i> (Q1): <span class="nowrap">29–</span>26. <q>Bug Discussion</q></cite></span>
</li>
<li id="cite_note-gelas-20060501-16"><span class="mw-cite-backlink">^ <a href="#cite_ref-gelas-20060501_16-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-gelas-20060501_16-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFDe_Gelas2006" class="citation news cs1">De Gelas, Johan (1 May 2006). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20100812052659/http://www.anandtech.com/show/1998/3">"Intel Core versus AMD's K8 architecture"</a>. <i><a href="AnandTech" title="AnandTech">AnandTech</a></i>. p.&nbsp;3. Archived from <a rel="nofollow" class="external text" href="https://www.anandtech.com/show/1998/3">the original</a> on August 12, 2010<span class="reference-accessdate">. Retrieved <span class="nowrap">23 January</span> 2018</span>. <q>Core architecture is equipped with four x86 decoders, 3 simple decoders and 1 complex decoder … to translate the 1 to 15 byte variable length x86 instructions into … fixed length RISC-like instructions (called micro-ops). … common x86 instructions are translated into a single micro-op … complex decoder is responsible for the instructions that produce up to 4 micro-ops. … really long and complex x86 instructions are handled by a microcode sequencer. … macro-op fusion … the x86 compare instruction (<code><abbr title="Compare">CMP</abbr></code>) is fused with a jump (<code><abbr title="Jump Not Equal to Target">JNE TARG</abbr></code>).</q></cite></span>
</li>
<li id="cite_note-kim-et-al-2004-17"><span class="mw-cite-backlink"><b><a href="#cite_ref-kim-et-al-2004_17-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFKimShih-wei_LiaoWangdel_Cuvillo2004" class="citation web cs1">Kim, Dongkeun; Shih-wei Liao, Steve; Wang, Perry H.; del Cuvillo, Juan; Tian, Xinmin; Zou, Xiang; Wang, Hong; Yeung, Donald; Girkar, Milind; Shen, John P. (11 January 2004). <a rel="nofollow" class="external text" href="http://maggini.eng.umd.edu/pub/pre-exec-cgo2004.pdf">"Physical Experimentation with Prefetching Helper Threads on Intels Hyper-Threaded Processors"</a> <span class="cs1-format">(PDF)</span>. pp.&nbsp;4, 5<span class="reference-accessdate">. Retrieved <span class="nowrap">24 January</span> 2018</span>. <q>L1 Trace cache: 12K micro-ops, 8-way set associative, 6 micro-ops per line … Shared: Trace cache, … <abbr title="Intel Architecture 32-bit">IA-32</abbr> instruction decode, Microcode ROM, <abbr title="Micro-operation">Uop</abbr> retirement logic, … Partitioned: Uop queue</q></cite></span>
</li>
<li id="cite_note-intel-bios-19960112-18"><span class="mw-cite-backlink">^ <a href="#cite_ref-intel-bios-19960112_18-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-intel-bios-19960112_18-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-intel-bios-19960112_18-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite class="citation report cs1"><a rel="nofollow" class="external text" href="http://datasheets.chipdb.org/Intel/x86/Pentium%20Pro/PPPBIOS.PDF">8: Pentium Pro Processor BIOS Update Feature</a> <span class="cs1-format">(PDF)</span> (Report). 2.0. Intel. 12 January 1996. p.&nbsp;45<span class="reference-accessdate">. Retrieved <span class="nowrap">3 November</span> 2020</span>. <q>authentication procedure relies upon the decryption provided by the processor to verify an update from a potentially hostile sources.</q></cite></span>
</li>
<li id="cite_note-Stiller_1996-19"><span class="mw-cite-backlink"><b><a href="#cite_ref-Stiller_1996_19-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFStillerPaul1996" class="citation magazine cs1 cs1-prop-foreign-lang-source">Stiller, Andreas; Paul, Matthias R. (1996-05-12). <a rel="nofollow" class="external text" href="https://www.heise.de/ct/artikel/Prozessorgefluester-284546.html">"Prozessorgeflüster"</a>. <i><a href="C't_%E2%80%93_magazin_f%C3%BCr_computertechnik" class="mw-redirect" title="C't – magazin für computertechnik">c't – magazin für computertechnik</a></i>. Trends &amp; News / aktuell - Prozessoren (in German). Vol.&nbsp;1996, no.&nbsp;6. <a href="Verlag_Heinz_Heise_GmbH_%26_Co_KG" class="mw-redirect" title="Verlag Heinz Heise GmbH &amp; Co KG">Verlag Heinz Heise GmbH &amp; Co KG</a>. p.&nbsp;20. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a>&nbsp;<a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/0724-8679">0724-8679</a>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20170828172141/https://www.heise.de/ct/artikel/Prozessorgefluester-284546.html">Archived</a> from the original on 2017-08-28<span class="reference-accessdate">. Retrieved <span class="nowrap">2017-08-28</span></span>.</cite></span>
</li>
<li id="cite_note-mueller-199809-20"><span class="mw-cite-backlink"><b><a href="#cite_ref-mueller-199809_20-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFMuellerZacker1998" class="citation book cs1">Mueller, Scott; Zacker, Craig (September 1998). Minatel, Jim; Byus, Jill; Kughen, Rick (eds.). <a rel="nofollow" class="external text" href="http://computarium.lcd.lu/library/PDF/MUELLER_Upgrading_and_Repairing_PCs_1998.pdf"><i>Upgrading and Repairing PCs</i></a> <span class="cs1-format">(PDF)</span> (Tenth Anniversary&nbsp;ed.). <a href="Que_Publishing" class="mw-redirect" title="Que Publishing">Que Publishing</a>. p.&nbsp;79. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>0-7897-1636-4</bdi><span class="reference-accessdate">. Retrieved <span class="nowrap">1 October</span> 2018</span>. <q>Processor Steppings (Revisions) and Microcode Update Revisions Supported by the Update Database File PEP6.PDB … Using the processor update utility (CHECKUP3.EXE), … can easily verify … the correct microcode update</q></cite></span>
</li>
<li id="cite_note-chen-ahn-20141211-21"><span class="mw-cite-backlink">^ <a href="#cite_ref-chen-ahn-20141211_21-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-chen-ahn-20141211_21-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-chen-ahn-20141211_21-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-chen-ahn-20141211_21-3"><sup><i><b>d</b></i></sup></a> <a href="#cite_ref-chen-ahn-20141211_21-4"><sup><i><b>e</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFChenAhn2014" class="citation web cs1">Chen, Daming Dominic; Ahn, Gail-Joon (11 December 2014). <a rel="nofollow" class="external text" href="https://www.dcddcc.com/docs/2014_paper_microcode.pdf">"Security Analysis of x86 Processor Microcode"</a> <span class="cs1-format">(PDF)</span>. <a href="Arizona_State_University" title="Arizona State University">Arizona State University</a>. pp.&nbsp;1, 5, 7<span class="reference-accessdate">. Retrieved <span class="nowrap">23 January</span> 2018</span>. <q>supervisor privileges (ring zero) are required to update processor microcode … Since the 1970s, processor manufacturers have decoded the x86 … into a sequence of … (RISC) micro-operations (uops) … introduced writable patch memory to provide an update mechanism for implementing dynamic debugging capabilities and correcting processor errata, especially after the infamous <a href="Pentium_FDIV_bug" title="Pentium FDIV bug">Pentium FDIV bug</a> of 1994. … P6 (Pentium Pro) microarchitecture in 1995, … <a href="AMD_K7" class="mw-redirect" title="AMD K7">K7 microarchitecture</a> in 1999 … with <a href="Symmetric_multiprocessing" title="Symmetric multiprocessing">symmetric multiprocessing</a> (SMP) … should be executed synchronously on each logical processor … patch RAM in addition to the <abbr title="Microcode read-only memory">MROM</abbr> … up to 60 microinstructions, with patching implemented by pairs of match and destination registers. … a 520 byte block containing a 2048-bit RSA modulus that appears to be constant within each processor family. This is followed by a four byte RSA exponent with the fixed value 11h</q></cite></span>
</li>
<li id="cite_note-shanley-1998-22"><span class="mw-cite-backlink"><b><a href="#cite_ref-shanley-1998_22-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFShanley1998" class="citation book cs1">Shanley, T. (1998). <a rel="nofollow" class="external text" href="https://books.google.com/books?id=MLJClvCYh34C&amp;pg=PA432"><i>Pentium Pro and Pentium II System Architecture</i></a>. Addison-Wesley Professional. p.&nbsp;435. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>9780201309737</bdi>.</cite></span>
</li>
<li id="cite_note-23"><span class="mw-cite-backlink"><b><a href="#cite_ref-23">^</a></b></span> <span class="reference-text"><cite id="CITEREFWolfe1997" class="citation magazine cs1">Wolfe, Alexander (30 June 1997). <a rel="nofollow" class="external text" href="https://web.archive.org/web/19991113012445/http://www.techweb.com/se/directlink.cgi?EET19970630S0007">"Intel preps plan to bust bugs in Pentium MPUs"</a>. <i><a href="EE_Times" title="EE Times">EE Times</a></i>. No.&nbsp;960. Archived from <a rel="nofollow" class="external text" href="http://www.techweb.com/se/directlink.cgi?EET19970630S0007">the original</a> on 1999-11-13<span class="reference-accessdate">. Retrieved <span class="nowrap">3 October</span> 2018</span> – via <a href="CMP_Technology" class="mw-redirect" title="CMP Technology">Techweb</a>. <q>obscure moniker "BIOS Update Feature." … "Each BIOS Update is tailored for a particular stepping of [a] processor," … data block is mapped directly-… after decryption-to the microcode itself.</q></cite></span>
</li>
<li id="cite_note-wolfe-1997-24"><span class="mw-cite-backlink"><b><a href="#cite_ref-wolfe-1997_24-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFWolfe1997" class="citation magazine cs1">Wolfe, Alexander (30 June 1997). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20030309102752/http://www.eetimes.com/news/97/963news/hole.html">"Hole seen in Intel's bug-busting feature"</a>. <i><a href="EE_Times" title="EE Times">EE Times</a></i>. Santa Clara. Archived from <a rel="nofollow" class="external text" href="http://www.eetimes.com/news/97/963news/hole.html">the original</a> on 2003-03-09. <q>Ajay Malhortra, a technical marketing manager based here at Intel's microprocessor group. "Not only is the data block containing the microcode patch encrypted, but once the processor examines the header of the BIOS update, there are two levels of encryption in the processor that must occur before it will successfully load the update." … closely guarded secret. "There is no documentation," said Frank Binns, an architect in Intel's microprocessor group. "It's not as if you can get an Intel 'Red Book' with this stuff written down. It's actually in the heads of less than 10 people in the whole of Intel."</q></cite></span>
</li>
<li id="cite_note-hardice-25"><span class="mw-cite-backlink">^ <a href="#cite_ref-hardice_25-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-hardice_25-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-hardice_25-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.hardice.org/hardice/reference/intel/probe-mode/details-of-intel-probe-mode">"Details of Intel Probe mode"</a>. <i>Hardice</i><span class="reference-accessdate">. Retrieved <span class="nowrap">23 January</span> 2018</span>. <q>emit a packet over the <abbr title="0-7 pins; Breakpoint Monitor Pins 0‒7">BPM</abbr> when special instructions are executed … To enable Extended Execution Trace, special microcode patches must be applied … For the Pentium 4 only, there exists a second type … called microcode Extended Execution Trace … Control Register Bus in turn allows access to internal arrays and functions on the processor, such as accessing the <abbr title="Last Level Cache">LLC</abbr> and the microcode/<abbr title="VFuse">Virtual Fuse</abbr> PROM. … that sits on the CPU package but is not within the CPU silicon die. This PROM also contains the microcode that the CPU loads during cold boot. … breakpoint on a 48-bit microcode address … accessed by the <abbr title="Test Access Port">TAP</abbr> commands <abbr title="Breakpoint Control A">BRKPTCTLA</abbr> and <abbr title="Breakpoint Control B">BRKPTCTLB</abbr>.</q></cite></span>
</li>
<li id="cite_note-elkins-1990-26"><span class="mw-cite-backlink">^ <a href="#cite_ref-elkins-1990_26-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-elkins-1990_26-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFElkins1990" class="citation journal cs1">Elkins, David S. (Winter 1990). <a rel="nofollow" class="external text" href="https://repository.jmls.edu/cgi/viewcontent.cgi?article=1423&amp;context=jitpl">"NEC v. Intel: A Guide to Using "Clean Room" Procedures as Evidence"</a>. <i>Computer/Law Journal</i>. <b>10</b> (4): 453. <q>NEC's use of its <a href="Cleanroom_software_engineering" title="Cleanroom software engineering">clean room procedures</a> as trial evidence … <a href="William_Percival_Gray" title="William Percival Gray">Judge Gray</a> defined microcode … within the Copyright Act's definition of a "computer program," … Intel's microcode is copyrightable. … Intel's microcode did not contain the required copyright notice. … copyrights had been forfeited. … Intel was left with no basis for its claim of copying</q></cite></span>
</li>
<li id="cite_note-hinckley-198701-27"><span class="mw-cite-backlink"><b><a href="#cite_ref-hinckley-198701_27-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFHinckley1987" class="citation journal cs1">Hinckley, Robert C. (January 1987). <a rel="nofollow" class="external text" href="https://digitalcommons.law.scu.edu/cgi/viewcontent.cgi?article=1031&amp;context=chtlj">"NEC v. Intel: Will Hardware Be Drawn into the Black Hole of Copyright Editors'"</a>. <i>Santa Clara High Technology Law Journal</i>. <b>3</b> (1). <q>Appendix: Microcode formats; <a href="Intel_8086" title="Intel 8086">8086</a>/8088 Format; <a href="NEC_V20" title="NEC V20">V20</a>/V30 format</q></cite></span>
</li>
<li id="cite_note-leong-19880328-28"><span class="mw-cite-backlink"><b><a href="#cite_ref-leong-19880328_28-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFLeong1988" class="citation magazine cs1">Leong, Kathy Chin (28 March 1988). <a rel="nofollow" class="external text" href="https://books.google.com/books?id=JRgDwCkMX_cC&amp;pg=PP84">"Intel witness recants story"</a>. <i><a href="Computerworld" title="Computerworld">Computerworld</a></i>. Vol.&nbsp;22, no.&nbsp;13. San Jose. pp.&nbsp;83, 84. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a>&nbsp;<a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/0010-4841">0010-4841</a><span class="reference-accessdate">. Retrieved <span class="nowrap">2 October</span> 2018</span>.</cite></span>
</li>
<li id="cite_note-intel-386-dx-199512-29"><span class="mw-cite-backlink"><b><a href="#cite_ref-intel-386-dx-199512_29-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1 cs1-prop-unfit"><a rel="nofollow" class="external text" href="http://pdf.datasheetcatalog.com/datasheet/Intel/mXtuvqv.pdf">"Intel386 DX Microprocessor 32-BIT CHMOS Microprocessor with Integrated Memory Management"</a> <span class="cs1-format">(PDF)</span>. December 1995. Archived from the original on 3 September 2004. <q>self-test checks the function of all of the Control ROM … EAX register will contain a signature of 00000000h indicating the Intel386 DX passed its self-test of microcode and major <a href="Programmable_logic_array" title="Programmable logic array">PLA</a> contents</q></cite></span>
</li>
<li id="cite_note-30"><span class="mw-cite-backlink"><b><a href="#cite_ref-30">^</a></b></span> <span class="reference-text"><cite class="citation journal cs1"><a rel="nofollow" class="external text" href="https://nptel.ac.in/courses/Webcourse-contents/IIT%20Kharagpur/Embedded%20systems/Pdf/Lesson-40.pdf">"5.1 Exhaustive Test in the Intel 80386"</a> <span class="cs1-format">(PDF)</span>. <i>Built-In-Self-Test (BIST) for Embedded Systems</i>. Testing of Embedded System. <a href="IIT_Kharagpur" title="IIT Kharagpur">IIT Kharagpur</a>: 21. 7 October 2006<span class="reference-accessdate">. Retrieved <span class="nowrap">6 October</span> 2018</span>. <q>For ROMs, the patterns are generated by the microprogram counter which is part of the normal logic.</q></cite></span>
</li>
<li id="cite_note-gelsinger-1999-31"><span class="mw-cite-backlink">^ <a href="#cite_ref-gelsinger-1999_31-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-gelsinger-1999_31-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFGelsingerlyengarKrauskopfNadir1999" class="citation conference cs1"><a href="Pat_Gelsinger" title="Pat Gelsinger">Gelsinger, Patrick</a>; lyengar, Sundar; Krauskopf, Joseph; Nadir, James; Intel (1999). <a rel="nofollow" class="external text" href="https://www.computer.org/csdl/proceedings/iccd/1989/1971/00/00063355.pdf"><i>Computer Aided Design and Built In Self Test on the i486™ CPU</i></a> <span class="cs1-format">(PDF)</span>. 1989 IEEE International Conference on Computer Design: VLSI in Computers and Processors. IEEE. pp.&nbsp;<span class="nowrap">200–</span>201.</cite></span>
</li>
<li id="cite_note-infoworld-20041017-32"><span class="mw-cite-backlink">^ <a href="#cite_ref-infoworld-20041017_32-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-infoworld-20041017_32-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation news cs1"><a rel="nofollow" class="external text" href="https://books.google.com/books?id=ZDgEAAAAMBAJ&amp;pg=PA5">"Court ruling against AMD causes some concern"</a>. <i><a href="InfoWorld" title="InfoWorld">InfoWorld</a></i>. 17 October 1994. p.&nbsp;5<span class="reference-accessdate">. Retrieved <span class="nowrap">24 January</span> 2018</span>. <q>The decision by the federal district court in San Jose, Calif., said that AMD does not have the right to use Intel's <a href="In-circuit_emulation" title="In-circuit emulation">in-circuit emulation</a> (ICE) code in the AMD microprocessors. This code is present on all AMD 486s but is only used in a low-power 486-DXL and 486-DXLV processors. … AMD has started to rework its entire line of 486s to eliminate the code.</q></cite></span>
</li>
<li id="cite_note-wu-2004-33"><span class="mw-cite-backlink"><b><a href="#cite_ref-wu-2004_33-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFWuLinReddyJaber2004" class="citation web cs1">Wu, David M.; Lin, Mike; Reddy, Madhukar; Jaber, Talal; Sabbavarapu, Anil; Thatcher, Larry; Intel Corporation (2004). <a rel="nofollow" class="external text" href="https://eecs.ceas.uc.edu/~jonewb/TESTING/Papers/Intel.pdf">"An An optimized DFT and test pattern generation strategy for an Intel high performance microprocessor"</a> <span class="cs1-format">(PDF)</span>. pp.&nbsp;38, 43, 44. <q>Direct Access Testing (DAT) for array access and diagnosis and Programmable Weak Write Test Mode (PWWTM) for memory cell stability test to reduce the test time. … Array <abbr title="Design for Test">DFT</abbr> test strategy is to use PBIST (Programmable Built-In Self Test) to test the second level cache and use DAT to test the remaining arrays … PBIST is available through the JTAG TAP controller. … DAT mode in PX as shown in Figure 4 … PX has more arrays (&gt;110) … array test coverage of PX is 99.3% ‒ the highest in Pentium 4 family</q></cite></span>
</li>
<li id="cite_note-34"><span class="mw-cite-backlink"><b><a href="#cite_ref-34">^</a></b></span> <span class="reference-text"><cite id="CITEREFTeam2020" class="citation web cs1">Team, uCode Research (25 May 2020). <a rel="nofollow" class="external text" href="https://github.com/chip-red-pill/crbus_scripts">"chip-red-pill/crbus_scripts"</a>. <i><a href="GitHub" title="GitHub">GitHub</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">26 May</span> 2020</span>.</cite></span>
</li>
<li id="cite_note-35"><span class="mw-cite-backlink"><b><a href="#cite_ref-35">^</a></b></span> <span class="reference-text"><cite id="CITEREFPositive_Research2020" class="citation cs2">Positive Research (2020-07-21), <a rel="nofollow" class="external text" href="https://github.com/ptresearch/IntelTXE-PoC"><i>ptresearch/IntelTXE-PoC</i></a><span class="reference-accessdate">, retrieved <span class="nowrap">2020-07-25</span></span></cite></span>
</li>
<li id="cite_note-ermolev-20200519-2-36"><span class="mw-cite-backlink"><b><a href="#cite_ref-ermolev-20200519-2_36-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFErmolov2020" class="citation web cs1">Ermolov, Mark [@_markel___] (2020-05-19). <a rel="nofollow" class="external text" href="https://x.com/_markel___/status/1262697756805795841">"Using the Local Direct Access Test (LDAT) DFT feature of Intel Atom CPU, we dumped Microcode Sequencer ROM. Also, we extracted what we think is IROM (Immediates for uops) and even managed to modify MS Patch RAM and Match/Patch registers"</a> (<a href="Tweet_(social_media)" title="Tweet (social media)">Tweet</a>) – via <a href="Twitter" title="Twitter">Twitter</a>.</cite></span>
</li>
<li id="cite_note-bosch-20200522-37"><span class="mw-cite-backlink"><b><a href="#cite_ref-bosch-20200522_37-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFBosch2020" class="citation web cs1">Bosch, Peter (2020-05-22). <a rel="nofollow" class="external text" href="https://pbx.sh/ldat/">"Intel LDAT notes"</a><span class="reference-accessdate">. Retrieved <span class="nowrap">2020-05-26</span></span>. <q>PDAT CR: 0x6A0; Array Select: 0‒4</q></cite></span>
</li>
</ol></div></div>
<div class="mw-heading mw-heading2"><h2 id="Further_reading">Further reading</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239549316">
/* start https://en.wikipedia.org/ */


.mw-parser-output .refbegin{margin-bottom:0.5em}.mw-parser-output .refbegin-hanging-indents>ul{margin-left:0}.mw-parser-output .refbegin-hanging-indents>ul>li{margin-left:0;padding-left:3.2em;text-indent:-3.2em}.mw-parser-output .refbegin-hanging-indents ul,.mw-parser-output .refbegin-hanging-indents ul li{list-style:none}@media(max-width:720px){.mw-parser-output .refbegin-hanging-indents>ul>li{padding-left:1.6em;text-indent:-1.6em}}.mw-parser-output .refbegin-columns{margin-top:0.3em}.mw-parser-output .refbegin-columns ul{margin-top:0}.mw-parser-output .refbegin-columns li{page-break-inside:avoid;break-inside:avoid-column}@media screen{.mw-parser-output .refbegin{font-size:90%}}


/* end https://en.wikipedia.org/ */
</style><div class="refbegin" style="">
<ul><li><style data-mw-deduplicate="TemplateStyles:r1041539562">
/* start https://en.wikipedia.org/ */


.mw-parser-output .citation{word-wrap:break-word}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}


/* end https://en.wikipedia.org/ */
</style><span class="citation patent" id="CITEREFPapworthFettermanGlewLawrence_O._Smith_(III),_Michael_M._Hancock,_first=Beth_Schultz1995"><a rel="nofollow" class="external text" href="https://worldwide.espacenet.com/textdoc?DB=EPODOC&amp;IDX=US5404473">US patent 5404473</a>, Papworth, David B.; Fetterman, Michael A. &amp; Glew, Andrew F. et al., "Apparatus and method for handling string operations in a pipelined processor", published 1995-04-04, assigned to <a href="Intel" title="Intel">Intel</a></span><span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Apatent&amp;rft.number=5404473&amp;rft.cc=US&amp;rft.title=Apparatus+and+method+for+handling+string+operations+in+a+pipelined+processor&amp;rft.inventor=Papworth&amp;rft.assignee=%5B%5BIntel%5D%5D&amp;rft.appldate=1994-03-01&amp;rft.pubdate=1995-04-04&amp;rft.prioritydate=1994-03-01"><span style="display: none;">&nbsp;</span></span> "the first <abbr title="Control micro operations">Cuops</abbr> in a REP swing operation loads the <abbr title="micro sequencer">MS</abbr> Loop Counter with the number of iterations remaining after the unrolled iterations are executed. … a small number of iterations (e.g., seven), are sent during the time it takes for the Loop Counter in the MS to be loaded. This unrolled code is executed conditionally based on the value of (E)CX … remaining three iterations are turned into <a href="NOP_(code)" title="NOP (code)">NOPS</a>."</li>
<li><span class="citation patent" id="CITEREFBoggsBrownHancockParker1996"><a rel="nofollow" class="external text" href="https://worldwide.espacenet.com/textdoc?DB=EPODOC&amp;IDX=US5559974">US patent 5559974</a>, Boggs, Darrell D.; Brown, Gary L. &amp; Hancock, Michael M. et al., "Decoder having independently loaded micro-alias and macro-alias registers accessible simultaneously by one micro-operation", published 1996-09-24, assigned to <a href="Intel" title="Intel">Intel</a></span><span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Apatent&amp;rft.number=5559974&amp;rft.cc=US&amp;rft.title=Decoder+having+independently+loaded+micro-alias+and+macro-alias+registers+accessible+simultaneously+by+one+micro-operation&amp;rft.inventor=Boggs&amp;rft.assignee=%5B%5BIntel%5D%5D&amp;rft.appldate=1996-09-24&amp;rft.pubdate=1996-09-24&amp;rft.prioritydate=1994-03-01"><span style="display: none;">&nbsp;</span></span></li>
<li><span class="citation patent" id="CITEREFBoggsBrownHancockDonald_D._Parker,_Gail_M._Rupnick1996"><a rel="nofollow" class="external text" href="https://worldwide.espacenet.com/textdoc?DB=EPODOC&amp;IDX=US5566298">US patent 5566298</a>, Boggs, Darrell D.; Brown, Gary L. &amp; Hancock, Michael M. et al., "Method for state recovery during assist and restart in a decoder having an alias mechanism", published 1996-10-15, assigned to <a href="Intel" title="Intel">Intel</a></span><span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Apatent&amp;rft.number=5566298&amp;rft.cc=US&amp;rft.title=Method+for+state+recovery+during+assist+and+restart+in+a+decoder+having+an+alias+mechanism&amp;rft.inventor=Boggs&amp;rft.assignee=%5B%5BIntel%5D%5D&amp;rft.appldate=1994-03-01&amp;rft.pubdate=1996-10-15&amp;rft.prioritydate=1994-03-01"><span style="display: none;">&nbsp;</span></span> "… control returns to the Micro-operation Sequence (MS) unit to issue further error correction Control micro-operations (Cuops). In order to simplify restart, the Cuops originating from the error-causing macroinstruction supplied by the translate programmable logic arrays (XLAT PLAs) are loaded into the Cuop registers, with their valid bits unasserted."</li>
<li><span class="citation patent" id="CITEREFBrownParker1997"><a rel="nofollow" class="external text" href="https://worldwide.espacenet.com/textdoc?DB=EPODOC&amp;IDX=US5600806">US patent 5600806</a>, Brown, Gary L. &amp; Parker, Donald D., "Method and apparatus for aligning an instruction boundary in variable length macroinstructions with an instruction buffer", published 1997-02-04, assigned to <a href="Intel" title="Intel">Intel</a></span><span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Apatent&amp;rft.number=5600806&amp;rft.cc=US&amp;rft.title=Method+and+apparatus+for+aligning+an+instruction+boundary+in+variable+length+macroinstructions+with+an+instruction+buffer&amp;rft.inventor=Brown&amp;rft.assignee=%5B%5BIntel%5D%5D&amp;rft.pubdate=1997-02-04&amp;rft.prioritydate=1994-03-01"><span style="display: none;">&nbsp;</span></span> "ADD, XOR, SUB, AND, and OR, which are implemented with one generic Cuop. Another group of instructions representable by only one <abbr title="Control micro-operation">Cuop</abbr> includes <abbr title="Add with Carry">ADC</abbr> and <abbr title="Subtract with Borrow">SBB</abbr></li>
<li><span class="citation patent" id="CITEREFCarbineBrownParker2013"><a rel="nofollow" class="external text" href="https://worldwide.espacenet.com/textdoc?DB=EPODOC&amp;IDX=US5630083">US patent 5630083</a>, Carbine, Adrian L.; Brown, Gary L. &amp; Parker, Donald D., "Decoder for decoding multiple instructions in parallel", published 2013-03-01, assigned to <a href="Intel" title="Intel">Intel</a></span><span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Apatent&amp;rft.number=5630083&amp;rft.cc=US&amp;rft.title=Decoder+for+decoding+multiple+instructions+in+parallel&amp;rft.inventor=Carbine&amp;rft.assignee=%5B%5BIntel%5D%5D&amp;rft.appldate=1996-07-03&amp;rft.pubdate=2013-03-01&amp;rft.prioritydate=1994-03-01"><span style="display: none;">&nbsp;</span></span></li>
<li><span class="citation patent" id="CITEREFWilson,_Jr.MillerRhodehamelAdrian_Carbine,_Derek_B._I._Feltham,_Sumeet_Agrawal2000"><a rel="nofollow" class="external text" href="https://worldwide.espacenet.com/textdoc?DB=EPODOC&amp;IDX=US6055656">US patent 6055656</a>, Wilson, Jr., James A.; Miller, Anthony C. &amp; Rhodehamel, Michael W. et al., "Control register bus access through a standardized test access port", published 2000-04-25, assigned to <a href="Intel" title="Intel">Intel</a></span><span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Apatent&amp;rft.number=6055656&amp;rft.cc=US&amp;rft.title=Control+register+bus+access+through+a+standardized+test+access+port&amp;rft.inventor=Wilson%2C+Jr.&amp;rft.assignee=%5B%5BIntel%5D%5D&amp;rft.appldate=1995-05-02&amp;rft.pubdate=2000-04-25&amp;rft.prioritydate=1995-05-02"><span style="display: none;">&nbsp;</span></span></li>
<li><span class="citation patent" id="CITEREFSutton2003"><a rel="nofollow" class="external text" href="https://worldwide.espacenet.com/textdoc?DB=EPODOC&amp;IDX=US20030196096">US patent 20030196096</a>, Sutton, James A., "Microcode patch authentication", published 2003-10-16</span><span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Apatent&amp;rft.number=20030196096&amp;rft.cc=US&amp;rft.title=Microcode+patch+authentication&amp;rft.inventor=Sutton&amp;rft.appldate=2002-04-12&amp;rft.pubdate=2003-10-16"><span style="display: none;">&nbsp;</span></span></li>
<li><span class="citation patent" id="CITEREFGlewRodgers1999"><a rel="nofollow" class="external text" href="https://worldwide.espacenet.com/textdoc?DB=EPODOC&amp;IDX=US5948097">US patent 5948097</a>, Glew, Andrew &amp; Rodgers, Scott Dion, "Method and apparatus for changing privilege levels in a computer system without use of a call gate", published 1999-09-07, assigned to <a href="Intel" title="Intel">Intel</a></span><span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Apatent&amp;rft.number=5948097&amp;rft.cc=US&amp;rft.title=Method+and+apparatus+for+changing+privilege+levels+in+a+computer+system+without+use+of+a+call+gate&amp;rft.inventor=Glew&amp;rft.assignee=%5B%5BIntel%5D%5D&amp;rft.appldate=1996-08-29&amp;rft.pubdate=1999-09-07&amp;rft.prioritydate=1996-08-29"><span style="display: none;">&nbsp;</span></span> "SYSENTER and SYSEXIT are assembly-language instructions that may be executed on an Intel architecture processor, such as the Pentium Pro processor … micro-operation is determined to be ready when its source fields have been filled with appropriate data … instruction decode unit comprises one or more translate (XLAT) programmable logic arrays (PLAs) that decode each instruction in to one or more micro-operations. … SYSENTER and SYSEXIT instructions are decoded in to micro-operations that perform the steps illustrated in FIGS. 5 and 6, respectively."</li>
<li><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://opensource.apple.com/source/xnu/xnu-3789.41.3/osfmk/i386/ucode.c.auto.html">"Microcode updater interface sysctl"</a> <span class="cs1-format">(<code>ucode.c</code> driver)</span>. <i><a href="XNU" title="XNU">XNU</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">24 January</span> 2018</span>. <q><code>#define IA32_BIOS_UPDT_TRIG (0x79) /* microcode update trigger MSR */</code></q></cite></li>
<li><cite id="CITEREFSivaramFanYiin2002" class="citation conference cs1">Sivaram, A. T.; Fan, Daniel; Yiin, A. (2002-10-10). "Efficient embedded memory testing with APG". <i>Proceedings. International Test Conference</i>. Vol.&nbsp;1. Baltimore, Maryland: IEEE. pp.&nbsp;<span class="nowrap">47–</span>54. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FTEST.2002.1041744">10.1109/TEST.2002.1041744</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>0-7803-7542-4</bdi>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a>&nbsp;<a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/1089-3539">1089-3539</a>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:19579807">19579807</a>.</cite></li>
<li><cite id="CITEREFBosch2020" class="citation web cs1">Bosch, Peter (2020-10-01). <a rel="nofollow" class="external text" href="https://www.youtube.com/watch?v=4oFOpDflJMA">"Under the hood of a CPU: Reverse Engineering the P6 microcode"</a>. <i><a href="YouTube" title="YouTube">YouTube</a></i>. Netherlands<span class="reference-accessdate">. Retrieved <span class="nowrap">2020-11-01</span></span>.</cite></li></ul>
</div>
<div class="mw-heading mw-heading2"><h2 id="External_links">External links</h2></div>
<ul><li><a rel="nofollow" class="external text" href="https://github.com/chip-red-pill/uCodeDisasm">uCodeDisasm</a> — Intel microcode disassembler in Python (from CRBUS), names of uops</li></ul></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-08-06" href="https://en.wikipedia.org/wiki/?title=Intel_microcode&amp;oldid=1304462460">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>

</body></html>