LAR

Load Access Rights

stableVMJITAOTinstruction

Encodings

OpcodeInstructionOp/En64-bitCompat/LegacyDescription
0F 02 /rLAR r16, r16/m16RMValidValidLoad access rights from specified descriptor.
0F 02 /rLAR r32, r32/m161RMValidValidLoad access rights from specified descriptor.
REX.W + 0F 02/rLAR r32, r64/m161RMValidNot encodableLoad access rights from specified descriptor.

Operand encoding

Each mode is a value of the Op/En column above. It says which field of the encoded instruction carries each operand, in the order they are written, and whether the instruction reads it, writes it or both.

RM

  1. modrm.reg escrituraModRM byte, reg field (bits 5-3)
  2. modrm.rm lecturaModRM byte, r/m field (bits 2-0); with the SIB byte and the displacement when the mod field asks for them

Measured cost

Loading measurements from arch-data...

Flags named

Description

Loads the access rights from the segment descriptor specified by the second operand (source operand) into the first operand (destination operand) and sets the ZF flag in the EFLAGS register. The source operand (which can be a register or a memory location) contains the segment selector for the segment descriptor being accessed. If the source operand is a memory address, only 16 bits of data are accessed. The destination operand is a generalpurpose register.

The processor performs access checks as part of the loading process. Once loaded in the destination register, software can perform additional checks on the access rights information.

The access rights for a segment descriptor include fields located in the second doubleword (bytes 47) of the segment descriptor. The following fields are loaded by the LAR instruction:

-- Bits 19:16 are undefined.

-- Bit 20 returns the software-available bit in the descriptor.

-- Bit 21 returns the L flag.

-- Bit 22 returns the D/B flag.

-- Bit 23 returns the G flag.

-- Bits 31:24 are returned as 0.

When the operand size is 16 bits, only the low 16 bits identified above are returned; the upper bits of the destination are unmodified. When the operand size is 32 bits, the 32-bit value identified above is loaded into the destination operand; the upper bits of the destination are cleared. When the operand is 64 bits, the 32-bit value is zeroextended to 64 bits and loaded into the destination operand. (The behavior with 32-bit and 64-bit operand sizes is identical.)

This instruction performs the following checks before it loads the access rights in the destination register:

accessed

(can be accessed with) the LAR instruction. The valid system segment and gate descriptor types are given in

*If the segment is not a conforming code segment, it checks that the specified segment descriptor is visible at
the CPL (that is, if the CPL and the RPL of the segment selector are less than or equal to the DPL of the segment
selector).

Segment and Gate Types

*If the segment is not a conforming code segment, it checks that the specified segment descriptor is visible at
the CPL (that is, if the CPL and the RPL of the segment selector are less than or equal to the DPL of the segment
selector).

Operation

IF Offset(SRC) > descriptor table limit
    THEN
          ZF := 0;
    ELSE
          SegmentDescriptor := descriptor referenced by SRC;

        IF SegmentDescriptor(Type)  conforming code segment

          and (CPL > DPL) or (RPL > DPL)
          or SegmentDescriptor(Type) is not valid for instruction

                THEN
                      ZF := 0;

                ELSE
                      DEST := access rights from SegmentDescriptor as given in Description section;
                      ZF := 1;

          FI;
FI;

Flags affected

The ZF flag is set to 1 if the access rights are loaded successfully; otherwise, it is cleared to 0.

Exceptions

Protected mode
#GP(0)If a memory operand effective address is outside the CS, DS, ES, FS, or GS segment limit. If the DS, ES, FS, or GS register is used to access memory and it contains a NULL segment selector.
#SS(0)If a memory operand effective address is outside the SS segment limit. #PF(fault-code) If a page fault occurs.
#AC(0)If alignment checking is enabled and the memory operand effective address is unaligned while the current privilege level is 3.
#UDIf the LOCK prefix is used.
Real address mode
#UDThe LAR instruction is not recognized in real-address mode.
Virtual-8086 mode
#UDThe LAR instruction cannot be executed in virtual-8086 mode.
Compatibility mode
Same exceptions as in protected mode.
64-bit mode
#SS(0)If the memory operand effective address referencing the SS segment is in a non-canonical form.
#GP(0)If the memory operand effective address is in a non-canonical form. #PF(fault-code) If a page fault occurs.
#AC(0)If alignment checking is enabled and the memory operand effective address is unaligned while the current privilege level is 3.
#UDIf the LOCK prefix is used.

Sources