Why x86's undefined instruction is called ud2, not ud

Why is the x86 undefined instruction called ud2? Why 2?

The x86 ud2 instruction reliably triggers an invalid opcode exception, but why the '2'? Raymond Chen traces its origin to two competing byte sequences: 0F FF and 0F B9. Intel later made the behavior official, retroactively naming them ud0 and ud1, while ud2 became the recommended choice because it is a clean two-byte instruction with no parameters, avoiding decode quirks that could cause access violations instead of invalid opcode exceptions.

With a sufficient number of users, all observable behaviors will be depended upon by somebody.
  1. hacker_homie

    Thus finally the 0F FF believers were rewarded by being give the honor of op code UD0 making it the one and true original invalid opcode permanently disgracing the 0F B9 adherents with the shame of UD1.

  2. 349ru3h4f03

    Nowadays UD0 UD1 UD2 are in the SDM and APM.

    We also got UDB (D6), the one-byte variant that arrived with x86-64 for 64-bit mode.

    And we have always had UDW (FF FF), aka group #5 (1st FF) with a modrm byte of mod=11b r/m=111b (/7) reg=111b (2nd FF) -- that one matters for memory with all bits set to 1, or for buses terminated to all 1 when no device claims an access.

  3. gtirloni

    I recently had to debug builds that failed randomly and a ud2 from V8 was there waiting for me.

  4. Neywiny

    I'm not much of an x86 person but on other architectures you can raise software interrupts/exceptions. Does x86 not have this or did those facilities not cover enough use cases?

  5. ordu

    > It’s called ud2 because the 0F FF variant was retroactively named ud0, and the 0F B9 variant was retroactively named ud1, leaving ud2 as the recommended undefined opcode.

    It was a surprise for me as a reader. When I came to this sentence I assumed that 0f ff would become #1 and 0fb9 -- #2. But no, Intel counts from zero, so there is a third ud.

More from this day

2026-09-13