SUBG

Subtract with tag

This instruction subtracts an immediate value scaled by the Tag Granule from the address in the source register, modifies the Logical Address Tag of the address using an immediate value, and writes the result to the destination register. Tags specified in GCR_EL1.Exclude are excluded from the possible outputs when modifying the Logical Address Tag.

Encoding: Integer

Variants: FEAT_MTE (ARMv8.5)

313029282726252423222120191817161514131211109876543210
1101000110(0)(0)
sfopSimm6op3imm4RnRd

SUBG <Xd|SP>, <Xn|SP>, #<uimm6>, #<uimm4>

Decoding algorithm

if !IsFeatureImplemented(FEAT_MTE) then EndOfDecode(Decode_UNDEF);
constant integer d = UInt(Rd);
constant integer n = UInt(Rn);
constant bits(4) tag_offset = imm4;
constant bits(64) offset = LSL(ZeroExtend(imm6, 64), LOG2_TAG_GRANULE);

Operation

constant bits(64) operand1 = if n == 31 then SP[64] else X[n, 64];
constant bits(4) start_tag = AArch64.AllocationTagFromAddress(operand1);
constant bits(16) exclude = GCR_EL1.Exclude;
bits(64) result;
bits(4) rtag;

if AArch64.AllocationTagAccessIsEnabled(PSTATE.EL) then
    rtag = AArch64.ChooseNonExcludedTag(start_tag, tag_offset, exclude);
else
    rtag = '0000';

(result, -) = AddWithCarry(operand1, NOT(offset), '1');

result = AArch64.AddressWithAllocationTag(result, rtag);

if d == 31 then
    SP[64] = result;
else
    X[d, 64] = result;

Explanations

<Xd|SP>: Is the 64-bit name of the destination general-purpose register or stack pointer, encoded in the "Rd" field.
<Xn|SP>: Is the 64-bit name of the source general-purpose register or stack pointer, encoded in the "Rn" field.
<uimm6>: Is an unsigned immediate, a multiple of 16 in the range 0 to 1008, encoded in the "imm6" field.
<uimm4>: Is an unsigned immediate, in the range 0 to 15, encoded in the "imm4" field.