- 论坛徽章:
- 0
|
下面是截取得一个函数:
0000001e <gas_netlink_uninit>:
1e: 53 push %ebx
1f: b9 01 00 00 00 mov $0x1,%ecx
24: 83 ec 04 sub $0x4,%esp
27: a1 00 00 00 00 mov 0x0,%eax
2c: ba 0f 00 00 00 mov $0xf,%edx
31: 8b 58 04 mov 0x4(%eax),%ebx
34: 8b 00 mov (%eax),%eax
36: e8 fc ff ff ff call 37 <gas_netlink_uninit+0x19>
3b: 8b 43 48 mov 0x48(%ebx),%eax
3e: ba 03 00 00 00 mov $0x3,%edx
43: b9 01 00 00 00 mov $0x1,%ecx
48: c7 04 24 00 00 00 00 movl $0x0,(%esp)
4f: e8 fc ff ff ff call 50 <gas_netlink_uninit+0x32>
54: a1 00 00 00 00 mov 0x0,%eax
59: 83 c0 6c add $0x6c,%eax
5c: e8 fc ff ff ff call 5d <gas_netlink_uninit+0x3f>
61: 8b 83 20 01 00 00 mov 0x120(%ebx),%eax
67: e8 fc ff ff ff call 68 <gas_netlink_uninit+0x4a>
6c: a1 00 00 00 00 mov 0x0,%eax
71: e8 fc ff ff ff call 72 <gas_netlink_uninit+0x54>
76: c7 05 00 00 00 00 00 movl $0x0,0x0
7d: 00 00 00
80: 5a pop %edx
81: 5b pop %ebx
82: c3 ret
问题如下:
1.27: a1 00 00 00 00 mov 0x0,%eax 这一行中, mov 后面的0x0表示的是什么? 如果是立即数应该是$0x0才对
2.36: e8 fc ff ff ff call 37 <gas_netlink_uninit+0x19>.这里的call后面的37表示的是什么, 在这个代码中没有37这一行,比较疑惑 |
|