Linux Assembly How To: “Hello, World”
tldp.org
tldp.org
Well, that's a touch out-of-date :)
All the same, I do find it fun to see the set of articles recently trying to show modern programmers that assembly isn't as terrifying as people make it out to be. My own opinion is that, though asm tends to be a bit more verbose and tedious than other higher-level languages, it looks like it's also dramatically simpler in a lot of ways.
For examle, the Heavything[1] library from 2ton suggests to me that asm can still be used for high-performance applications today.
Good find and a fun read!
Having written the aforementioned, I thought maybe y'all would be interested in a very very lightweight version of same done w/ my assembler of choice (only because it reminds me of Turbo Assembler from way back in the day).
format ELF64 executable
_start:
mov eax, 1 ; syscall # = write
mov edi, 1 ; man 2 write arg1 == our fd, stdout
mov esi, .msg ; "" arg2 == const void *buf
mov edx, .msglen ; "" arg3 == size_t count
syscall
mov eax, 60 ; syscall # = exit
xor edi, edi ; man 2 exit arg1 == status
syscall
.msg:
db 'Greetings, HackerNews!',10
.msglen = $ - .msg
I don't think it gets much clearer or simpler than that, and more so that "man 2 xxx" provides all of the information you need for syscall goods anyway, it really isn't that bad :-)if you compile this with fasm (http://www.flatassembler.net/) it produces a 174 byte ELF64 (and if we wanted to have some fun, we could lower that number by quite a bit still).
Cheers!
Edit: leading spaces for code
mov rax, 0xdeadbeefThe most "immediately" (pun intended) obvious size optimisation would be to do this:
push 1
pop eax
mov edi, eax
...
push .msglen
pop edx
...
push 60
pop eax
...which should save 9 bytes. Note that 174 bytes is still a far ways off from the equivalent under DOS, which would be... 95 BA 07 01 CD 21 C3 47 72 65 65 74 69 6E 67 73
2C 20 48 61 63 6B 65 72 4E 65 77 73 21 0D 0A 24
...these 32 bytes, 25 of which is the message itself.One of my earliest introductions to the ELF format was "A Whirlwind Tutorial on Creating Really Teensy ELF Executables for Linux" (http://www.muppetlabs.com/~breadbox/software/tiny/teensy.htm...), which I still highly recommend.
Since then, I have packaged heavything's whole showcase for Arch[1] (mainly because I'm quite interested in using rwasa for my own website but also so that other Archers may reap the benefits as well).
Keep up the awesome work!
http://wiki.osdev.org/SYSENTER
I say "faster" above, and that's true for all chips since the Pentium 4, if not earlier, but it isn't true on all 32-bit x86 chips. It isn't even true on all 32-bit x86 chips which have the opcode. So the Linux kernel has a special trick such that all binaries always use the fastest syscall method, regardless of which kind of system they were compiled for: linux-gate.so.1 also known as linux-vdso.so.1
This isn't actually a file on disk, it's just some machine code the kernel maps into the process address space which syscalls indirect through, because the kernel knows more about the hardware than applications.
http://www.trilithium.com/johan/2005/08/linux-gate/
vDSO even stands for virtual Dynamic Shared Object:
http://man7.org/linux/man-pages/man7/vdso.7.html
Aside from being virtual, it's a normal ELF shared object, with symbol names and versoning and the functions use the normal C calling convention.
Linux: http://www.securitytube.net/groups?operation=view&groupId=5
Windows: http://www.securitytube.net/groups?operation=view&groupId=6
Some good resources here too http://www.opensecuritytraining.info/Training.html
There appeared to be relatively few examples of modern (well, 64 bit) Linux assembly out there, though quite a few relatively out of date documents like the one posted; documentation like the 64bit Linux System Call table were exceptionally useful [3].
[1] https://gist.github.com/bobbo/e1e980262f2ddc8db3b8
[2] https://news.ycombinator.com/item?id=9948749
[3] http://blog.rchapman.org/post/36801038863/linux-system-call-...
gcc -nostdlib hello.S -o hello
This example uses the old 32-bit syscall invocation mechanism, which works fine under 64-bit Linux. It might be a useful exercise to try porting this program to the 64-bit syscall convention.Oh, interesting. I didn't know you could do that with gcc. Thanks for the tip!
This example uses the old 32-bit syscall invocation mechanism, which works fine under 64-bit Linux. It might be a useful exercise to try porting this program to the 64-bit syscall convention.
I wasn't familiar with the difference, but some googling turned up this SO discussion which seems relevant. Maybe I will try making the change and see if I can get this to run with pure 64 bit code.
http://stackoverflow.com/questions/8510333/x86-64-assembly-l...
[0] https://github.com/lpsantil/rt0/blob/master/src/lib/syscall....
Ah, that is very handy, and very illustrative. Thanks for sharing!
https://www.google.com/search?q=Bartlett+programming+from+th...
$ ld -o hello hello.o
ld: i386 architecture of input file `hello.o' is incompatible with i386:x86-64 output
$ nasm -f elf64 hello.asm
$ ld -o hello hello.o
$ ./hello
hello, friend