For example, on a 64-bit arch, this code would be sus.
syscall(__NR_syscall_taking_6_args, 1, 2, 3, 4, 5, 6);
Quiz: why
PS: it's a common mistake, so I thought I'd save you a trip down the debugging rabbit hole.
For example, on a 64-bit arch, this code would be sus.
syscall(__NR_syscall_taking_6_args, 1, 2, 3, 4, 5, 6);
Quiz: why
PS: it's a common mistake, so I thought I'd save you a trip down the debugging rabbit hole.
This is a huge edgecase but is 8(%rsp) guaranteed to be readable memory
#include <sys/syscall.h>
#include <unistd.h>
#include <alloca.h>
#include <string.h>
void s(long a, long b, long c, long d, long e, long f, long g) {
}
int main(void) {
long a = 0xFFFFFFFFFFFFFFFF;
s(a, a, a, a, a, a, a);
syscall(9999, 1, 2, 3, 4, 5, 6);
return 0;
}
Now, strace shows: $ strace -e process_vm_readv ./a
process_vm_readv(1, 0x2, 3, 0x4, 5, 18446744069414584326) = -1 EINVAL (Invalid argument)
objdump -d a 117f: 48 c7 45 f0 ff ff ff movq $0xffffffffffffffff,-0x10(%rbp)
1186: ff
1187: 48 8b 7d f0 mov -0x10(%rbp),%rdi
118b: 48 8b 75 f0 mov -0x10(%rbp),%rsi
118f: 48 8b 55 f0 mov -0x10(%rbp),%rdx
1193: 48 8b 4d f0 mov -0x10(%rbp),%rcx
1197: 4c 8b 45 f0 mov -0x10(%rbp),%r8
119b: 4c 8b 4d f0 mov -0x10(%rbp),%r9
119f: 48 8b 45 f0 mov -0x10(%rbp),%rax
11a3: 48 89 04 24 mov %rax,(%rsp)
11a7: e8 94 ff ff ff call 1140 <s>
11ac: bf 36 01 00 00 mov $0x136,%edi
11b1: be 01 00 00 00 mov $0x1,%esi
11b6: ba 02 00 00 00 mov $0x2,%edx
11bb: b9 03 00 00 00 mov $0x3,%ecx
11c0: 41 b8 04 00 00 00 mov $0x4,%r8d
11c6: 41 b9 05 00 00 00 mov $0x5,%r9d
11cc: c7 04 24 06 00 00 00 movl $0x6,(%rsp)
11d3: b0 00 mov $0x0,%al
11d5: e8 56 fe ff ff call 1030 <syscall@plt>
Only 4 bytes are put on the stack, but syscall will read 8.It's tricky if one doesn't control types of arguments used in vararg.
They didn't claim to save work, they claimed to save hitting a bug, and having to debug it.
They said the word "vararg". They gave you everything.
They gave me everything to dismiss their claim.
Here's a free dollar. "Only one?"
They said the word "vararg". That is everything. You take that, and you say "oh shit, right, thanks for the heads up" or if you don't already know what's so special about that, you do know they obviously said that for some reason so you fucking google it.
Either way, they pointed you in the right direction, and that is helpful.
The further reading that you find so unbearable takes you exactly the same time to read something that has already been written and is just sitting out there to look up for free, as to read something you demand they write again on the spot bespoke for you.
And since as you say they aren't a proffessor or colleague you personally know and respect, why do you care if they write out a full article or just a pointer? You just said you don't trust a rando. You don't trust their full article anyway.
Once again, you assume the conclusion that their comment is helpful and correct and meaningful, and you work backwards to excuse their poor explanation that they justified with "let's say it's a quiz".
And if you don't like my reply, take your own advice and go away. Why do you care what I think of their phrasing? You're not going to get me to stop anyway, or the dozens or people who upvoted me.
Or keep swearing at me and getting downvoted, whatever floats your boat.
How do you justify complaining about how little they wrote for you when you will ignore them anyway, because "how do I know they are pointing me in the right direction?"
You can't have it both ways at the same time.
This is such a weird discussion honestly. I don't know what you want of me, but I sure can't wait for your next strawman!
Need to cast them to long or size_t or whatever to prevent this.