Stack function-function calling process of an advanced language disassembly Program

Source: Internet
Author: User

Transfer others' articles

 

[Source: Author: iiprogram 2006-04-27 Source: pcdog.com]

Abstract: This article describes the assembly process of function calls in the advanced language after the advanced language is compiled into the assembly language.

Body: after a high-level language is compiled into an assembler, the process of calling a function in the advanced language is as follows:

1. Add function parameters to the stack. The first parameter is at the top of the stack, and the last parameter is at the bottom of the stack.

 

2. Execute the call command, call the function, and enter the function code space.

A. Execute the call command and add the address of the next code line of the Call command to the stack.

B. after entering the function code space, put the base address pointer EBP into the stack, then let the base address pointer EBP point to the top of the current stack, and use it to access function input parameters in the stack and other data in the stack.

C. The stack pointer ESP reduces a value, such as 44 h, and moves up a distance to leave a space for the function as a temporary storage area.

{

// After the above preparations are completed, the function is officially executed, as shown below.

D. import values from other pointers or registers into the stack so that these registers can be used in functions.

E. Run the code.

F. Execute return () to return the execution result and store the returned value to eax.

G. in step 2. D, the pointer goes out of the stack.

}

H. Pass the EBP value to the stack pointer ESP so that the ESP is restored to the value before 2.c. The value of EBP is at the top of the stack.

I. The base address pointer EBP goes out of the stack and is restored to the EBP value before 2. B.

J. Execute the RET command. The address of the "call function" goes out of the stack. This function returns to the next line of the Call Command.

3. The function returns to the next line of the Call Command and adds a value to the stack pointer to restore the stack pointer to the value before step 1 is executed. This value is the total length of the first entry stack parameter.

Note:

1. The stack pointer ESP points to the cursor bit of the new incoming stack data at the top of the stack.

2. The offset pointer in the mov command points to the cursor bit of the data that is "mov. The following command uploads the EBP + 8 to EBP + 11 four bytes to the eax register.

00402048 mov eax, dword ptr [EBP + 8]

An example is as follows:

Function calls in advanced language code are as follows:

117: Br = T1 (P );

The Assembly Code is as follows:

00401fb8 mov ECx, dword ptr [ebp-8]; add parameters to ECx registers

00401fbb push ECx; parameter into Stack

00401fbc call @ ILT + 10 (T1) (0040100f); function call, next line address 00401fc1 into Stack

00401fc1 add ESP, 4; function return, stack pointer plus 4, restore to the value of 00401fb8

00401fc4 mov dword ptr [ebp-10h], eax; extract the function return value in advanced language from eax and put it in the BR variable

The T1 function is as follows:

125: bool T1 (void * P)

126 :{

00402030 push EBP; EBP into Stack

00402031 mov EBP, esp; EBP points to the top of the stack at this time

00402033 sub ESP, 44 h; esp reduces a value and leaves a storage Zone

00402036 push EBX; Add the values of the three registers to the stack so that they can be used in functions.

00402037 push ESI;

00402038 push EDI;

00402039 Lea EDI, [ebp-44h];

0040203c mov ECx, 11 h;

00402041 mov eax, 0 cccccccch;

00402046 rep STOs dword ptr [EDI];

127: int * q = (int *) P ;;

00402048 mov eax, dword ptr [EBP + 8]; EBP + 8 points to the bitwise address of the function input parameter;

If it is EBP + 4, it points to the second bit of the return address 00401fc1 of the function, and the value is C1.

0040204b mov dword ptr [ebp-4], eax;

128: Return 0 ;;

0040204e XOR eax, eax; the returned values are put into the eax register.

129 :}

00402050 pop EDI; three register output stacks

00402051 pop ESI;

00402052 pop ebx;

00402053 mov ESP, EBP; esp Restoration

00402055 pop EBP; EBP goes out of the stack, and its value is restored.

00402056 ret; return the Code address stored on the top of the stack: 00401fc1

If the return address is modified unfortunately, the program will encounter an accident.

The above assembly code is compiled by VC ++ 6.0.

After the EBP stack is added to the stack:

Low Level

Zookeeper

Memory Address Stack

Zookeeper

0012f600 ├ ── ─ ┤ ← EDI = 0012f600

0012f604 ├ ── ┄ ─ ── ┤

Memory size of 44h

Zookeeper

0012f640 0000-000000000000000000000000-0000

0012f644 ├ ── ─ ┤ ← EBP points to this unit after being assigned a value. At this time, EBP = 0012f644

│ AC F6 12 00 │ EBP value is the value before ESP

0012f648 ├ ── ─ ──

│ C1 1f 40 00 │ return address

0012f64c ├ ── ─ ┤ %ebp + 8

│ A0 F6 12 00 │ value of the real parameter P of the Function

0012f650 ├ ── ─ ──

├ ── ─ ┤

Zookeeper

Note: memory storage space stacks are arranged from high to low. The addresses marked on the left are the two-digit addresses of the lower right storage unit. For example, 0012f644 points to the AC byte of 0012f6ac, And the AC is at the top of the stack. In the figure, the content in the memory is written from low to high. "AC F6 12 00" = 0x0012f6ac

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.