2008-04-11 05:36:07 +02:00
|
|
|
#/**@file
|
|
|
|
# Low leve IA32 specific debug support functions.
|
|
|
|
#
|
2011-05-17 10:35:20 +02:00
|
|
|
# Copyright (c) 2006 - 2011, Intel Corporation. All rights reserved.<BR>
|
2010-04-24 11:33:45 +02:00
|
|
|
# This program and the accompanying materials
|
2008-04-11 05:36:07 +02:00
|
|
|
# are licensed and made available under the terms and conditions of the BSD License
|
|
|
|
# which accompanies this distribution. The full text of the license may be found at
|
|
|
|
# http://opensource.org/licenses/bsd-license.php
|
|
|
|
#
|
|
|
|
# THE PROGRAM IS DISTRIBUTED UNDER THE BSD LICENSE ON AN "AS IS" BASIS,
|
|
|
|
# WITHOUT WARRANTIES OR REPRESENTATIONS OF ANY KIND, EITHER EXPRESS OR IMPLIED.
|
|
|
|
#
|
|
|
|
#**/
|
2007-07-03 16:09:20 +02:00
|
|
|
|
2009-05-20 12:22:09 +02:00
|
|
|
ASM_GLOBAL ASM_PFX(OrigVector)
|
|
|
|
ASM_GLOBAL ASM_PFX(InterruptEntryStub)
|
|
|
|
ASM_GLOBAL ASM_PFX(StubSize)
|
|
|
|
ASM_GLOBAL ASM_PFX(CommonIdtEntry)
|
|
|
|
ASM_GLOBAL ASM_PFX(FxStorSupport)
|
2007-07-03 16:09:20 +02:00
|
|
|
|
2008-12-16 10:21:45 +01:00
|
|
|
ASM_PFX(StubSize): .long ASM_PFX(InterruptEntryStubEnd) - ASM_PFX(InterruptEntryStub)
|
2007-07-03 16:09:20 +02:00
|
|
|
ASM_PFX(AppEsp): .long 0x11111111 # ?
|
|
|
|
ASM_PFX(DebugEsp): .long 0x22222222 # ?
|
|
|
|
ASM_PFX(ExtraPush): .long 0x33333333 # ?
|
|
|
|
ASM_PFX(ExceptData): .long 0x44444444 # ?
|
|
|
|
ASM_PFX(Eflags): .long 0x55555555 # ?
|
|
|
|
ASM_PFX(OrigVector): .long 0x66666666 # ?
|
|
|
|
|
2008-12-16 10:21:45 +01:00
|
|
|
#------------------------------------------------------------------------------
|
|
|
|
# BOOLEAN
|
|
|
|
# FxStorSupport (
|
|
|
|
# void
|
|
|
|
# )
|
|
|
|
#
|
|
|
|
# Abstract: Returns TRUE if FxStor instructions are supported
|
|
|
|
#
|
2009-05-20 12:22:09 +02:00
|
|
|
ASM_GLOBAL ASM_PFX(FxStorSupport)
|
2007-07-03 16:09:20 +02:00
|
|
|
ASM_PFX(FxStorSupport):
|
2008-12-16 10:21:45 +01:00
|
|
|
#
|
|
|
|
# cpuid corrupts ebx which must be preserved per the C calling convention
|
|
|
|
#
|
2007-07-03 16:09:20 +02:00
|
|
|
push %ebx
|
|
|
|
mov $0x1,%eax
|
2008-04-11 05:36:07 +02:00
|
|
|
cpuid
|
2007-07-03 16:09:20 +02:00
|
|
|
mov %edx,%eax
|
|
|
|
and $0x1000000,%eax
|
|
|
|
shr $0x18,%eax
|
|
|
|
pop %ebx
|
2008-04-11 05:36:07 +02:00
|
|
|
ret
|
2008-12-16 10:21:45 +01:00
|
|
|
#------------------------------------------------------------------------------
|
|
|
|
# void
|
|
|
|
# Vect2Desc (
|
|
|
|
# DESCRIPTOR * DestDesc,
|
|
|
|
# void (*Vector) (void)
|
|
|
|
# )
|
|
|
|
#
|
|
|
|
# Abstract: Encodes an IDT descriptor with the given physical address
|
|
|
|
#
|
2007-07-03 16:09:20 +02:00
|
|
|
|
2009-05-20 12:22:09 +02:00
|
|
|
ASM_GLOBAL ASM_PFX(Vect2Desc)
|
2007-07-03 16:09:20 +02:00
|
|
|
ASM_PFX(Vect2Desc):
|
|
|
|
push %ebp
|
|
|
|
mov %esp,%ebp
|
|
|
|
mov 0xc(%ebp),%eax
|
|
|
|
mov 0x8(%ebp),%ecx
|
|
|
|
mov %ax,(%ecx)
|
|
|
|
movw $0x20,0x2(%ecx)
|
|
|
|
movw $0x8e00,0x4(%ecx)
|
|
|
|
shr $0x10,%eax
|
|
|
|
mov %ax,0x6(%ecx)
|
2008-04-11 05:36:07 +02:00
|
|
|
leave
|
|
|
|
ret
|
2007-07-03 16:09:20 +02:00
|
|
|
|
2009-05-20 12:22:09 +02:00
|
|
|
ASM_GLOBAL ASM_PFX(InterruptEntryStub)
|
2007-07-03 16:09:20 +02:00
|
|
|
ASM_PFX(InterruptEntryStub):
|
2008-12-16 10:21:45 +01:00
|
|
|
mov %esp,0x0 # save stack top
|
|
|
|
mov $0x0,%esp # switch to debugger stack
|
|
|
|
push $0x0 # push vector number - will be modified before installed
|
|
|
|
jmp ASM_PFX(CommonIdtEntry) # jump CommonIdtEntry
|
2009-05-20 12:22:09 +02:00
|
|
|
ASM_GLOBAL ASM_PFX(InterruptEntryStubEnd)
|
2007-07-03 16:09:20 +02:00
|
|
|
ASM_PFX(InterruptEntryStubEnd):
|
|
|
|
|
2008-12-16 10:21:45 +01:00
|
|
|
#------------------------------------------------------------------------------
|
|
|
|
# CommonIdtEntry
|
|
|
|
#
|
|
|
|
# Abstract: This code is not a function, but is the common part for all IDT
|
|
|
|
# vectors.
|
|
|
|
#
|
2009-05-20 12:22:09 +02:00
|
|
|
ASM_GLOBAL ASM_PFX(CommonIdtEntry)
|
2007-07-03 16:09:20 +02:00
|
|
|
ASM_PFX(CommonIdtEntry):
|
2008-12-16 10:21:45 +01:00
|
|
|
##
|
|
|
|
## At this point, the stub has saved the current application stack esp into AppEsp
|
|
|
|
## and switched stacks to the debug stack, where it pushed the vector number
|
|
|
|
##
|
|
|
|
## The application stack looks like this:
|
|
|
|
##
|
|
|
|
## ...
|
|
|
|
## (last application stack entry)
|
|
|
|
## eflags from interrupted task
|
|
|
|
## CS from interrupted task
|
|
|
|
## EIP from interrupted task
|
|
|
|
## Error code <-------------------- Only present for some exeption types
|
|
|
|
##
|
|
|
|
##
|
|
|
|
|
|
|
|
|
|
|
|
## The stub switched us to the debug stack and pushed the interrupt number.
|
|
|
|
##
|
|
|
|
## Next, construct the context record. It will be build on the debug stack by
|
|
|
|
## pushing the registers in the correct order so as to create the context structure
|
|
|
|
## on the debug stack. The context record must be built from the end back to the
|
|
|
|
## beginning because the stack grows down...
|
|
|
|
#
|
|
|
|
## For reference, the context record looks like this:
|
|
|
|
##
|
|
|
|
## typedef
|
|
|
|
## struct {
|
|
|
|
## UINT32 ExceptionData;
|
|
|
|
## FX_SAVE_STATE_IA32 FxSaveState;
|
|
|
|
## UINT32 Dr0, Dr1, Dr2, Dr3, Dr6, Dr7;
|
|
|
|
## UINT32 Cr0, Cr2, Cr3, Cr4;
|
|
|
|
## UINT32 EFlags;
|
|
|
|
## UINT32 Ldtr, Tr;
|
|
|
|
## UINT32 Gdtr[2], Idtr[2];
|
|
|
|
## UINT32 Eip;
|
|
|
|
## UINT32 Gs, Fs, Es, Ds, Cs, Ss;
|
|
|
|
## UINT32 Edi, Esi, Ebp, Esp, Ebx, Edx, Ecx, Eax;
|
|
|
|
## } SYSTEM_CONTEXT_IA32; // 32 bit system context record
|
|
|
|
|
|
|
|
## UINT32 Edi, Esi, Ebp, Esp, Ebx, Edx, Ecx, Eax;
|
2008-04-11 05:36:07 +02:00
|
|
|
pusha
|
2008-12-16 10:21:45 +01:00
|
|
|
## Save interrupt state eflags register...
|
2008-04-11 05:36:07 +02:00
|
|
|
pushf
|
2007-07-03 16:09:20 +02:00
|
|
|
pop %eax
|
2008-12-16 10:21:45 +01:00
|
|
|
## We need to determine if any extra data was pushed by the exception, and if so, save it
|
|
|
|
## To do this, we check the exception number pushed by the stub, and cache the
|
|
|
|
## result in a variable since we'll need this again.
|
2007-07-03 16:09:20 +02:00
|
|
|
mov %eax,0x0
|
|
|
|
cmpl $0x8,0x0
|
|
|
|
jne ASM_PFX(CommonIdtEntry+0x20)
|
|
|
|
movl $0x1,0x0
|
|
|
|
jmp ASM_PFX(CommonIdtEntry+0xa8)
|
|
|
|
cmpl $0xa,0x0
|
|
|
|
jne ASM_PFX(CommonIdtEntry+0x35)
|
|
|
|
movl $0x1,0x0
|
|
|
|
jmp ASM_PFX(CommonIdtEntry+0xa8)
|
|
|
|
cmpl $0xb,0x0
|
|
|
|
jne ASM_PFX(CommonIdtEntry+0x4a)
|
|
|
|
movl $0x1,0x0
|
|
|
|
jmp ASM_PFX(CommonIdtEntry+0xa8)
|
|
|
|
cmpl $0xc,0x0
|
|
|
|
jne ASM_PFX(CommonIdtEntry+0x5f)
|
|
|
|
movl $0x1,0x0
|
|
|
|
jmp ASM_PFX(CommonIdtEntry+0xa8)
|
|
|
|
cmpl $0xd,0x0
|
|
|
|
jne ASM_PFX(CommonIdtEntry+0x74)
|
|
|
|
movl $0x1,0x0
|
|
|
|
jmp ASM_PFX(CommonIdtEntry+0xa8)
|
|
|
|
cmpl $0xe,0x0
|
|
|
|
jne ASM_PFX(CommonIdtEntry+0x89)
|
|
|
|
movl $0x1,0x0
|
|
|
|
jmp ASM_PFX(CommonIdtEntry+0xa8)
|
|
|
|
cmpl $0x11,0x0
|
|
|
|
jne ASM_PFX(CommonIdtEntry+0x9e)
|
|
|
|
movl $0x1,0x0
|
|
|
|
jmp ASM_PFX(CommonIdtEntry+0xa8)
|
|
|
|
movl $0x0,0x0
|
2008-12-16 10:21:45 +01:00
|
|
|
## If there's some extra data, save it also, and modify the saved AppEsp to effectively
|
|
|
|
## pop this value off the application's stack.
|
|
|
|
|
2007-07-03 16:09:20 +02:00
|
|
|
cmpl $0x1,0x0
|
|
|
|
jne ASM_PFX(CommonIdtEntry+0xc8)
|
|
|
|
mov 0x0,%eax
|
|
|
|
mov (%eax),%ebx
|
|
|
|
mov %ebx,0x0
|
|
|
|
add $0x4,%eax
|
|
|
|
mov %eax,0x0
|
|
|
|
jmp ASM_PFX(CommonIdtEntry+0xd2)
|
|
|
|
movl $0x0,0x0
|
2008-12-16 10:21:45 +01:00
|
|
|
## The "pushad" above pushed the debug stack esp. Since what we're actually doing
|
|
|
|
## is building the context record on the debug stack, we need to save the pushed
|
|
|
|
## debug ESP, and replace it with the application's last stack entry...
|
2007-07-03 16:09:20 +02:00
|
|
|
mov 0xc(%esp),%eax
|
|
|
|
mov %eax,0x0
|
|
|
|
mov 0x0,%eax
|
|
|
|
add $0xc,%eax
|
2008-12-16 10:21:45 +01:00
|
|
|
# application stack has eflags, cs, & eip, so
|
|
|
|
# last actual application stack entry is
|
|
|
|
# 12 bytes into the application stack.
|
2007-07-03 16:09:20 +02:00
|
|
|
mov %eax,0xc(%esp)
|
2008-12-16 10:21:45 +01:00
|
|
|
## continue building context record
|
|
|
|
## UINT32 Gs, Fs, Es, Ds, Cs, Ss; insure high 16 bits of each is zero
|
2007-07-03 16:09:20 +02:00
|
|
|
mov %ss,%eax
|
|
|
|
push %eax
|
2008-12-16 10:21:45 +01:00
|
|
|
|
|
|
|
# CS from application is one entry back in application stack
|
2007-07-03 16:09:20 +02:00
|
|
|
mov 0x0,%eax
|
|
|
|
movzwl 0x4(%eax),%eax
|
|
|
|
push %eax
|
|
|
|
mov %ds,%eax
|
|
|
|
push %eax
|
|
|
|
mov %es,%eax
|
|
|
|
push %eax
|
|
|
|
mov %fs,%eax
|
|
|
|
push %eax
|
|
|
|
mov %gs,%eax
|
|
|
|
push %eax
|
2008-12-16 10:21:45 +01:00
|
|
|
|
|
|
|
## UINT32 Eip;
|
|
|
|
# Eip from application is on top of application stack
|
2007-07-03 16:09:20 +02:00
|
|
|
mov 0x0,%eax
|
|
|
|
pushl (%eax)
|
2008-12-16 10:21:45 +01:00
|
|
|
|
|
|
|
## UINT32 Gdtr[2], Idtr[2];
|
2007-07-03 16:09:20 +02:00
|
|
|
push $0x0
|
|
|
|
push $0x0
|
|
|
|
sidtl (%esp)
|
|
|
|
push $0x0
|
|
|
|
push $0x0
|
|
|
|
sgdtl (%esp)
|
2008-12-16 10:21:45 +01:00
|
|
|
|
|
|
|
## UINT32 Ldtr, Tr;
|
2007-07-03 16:09:20 +02:00
|
|
|
xor %eax,%eax
|
|
|
|
str %eax
|
|
|
|
push %eax
|
|
|
|
sldt %eax
|
|
|
|
push %eax
|
2008-12-16 10:21:45 +01:00
|
|
|
|
|
|
|
## UINT32 EFlags;
|
|
|
|
## Eflags from application is two entries back in application stack
|
2007-07-03 16:09:20 +02:00
|
|
|
mov 0x0,%eax
|
|
|
|
pushl 0x8(%eax)
|
2008-12-16 10:21:45 +01:00
|
|
|
|
|
|
|
## UINT32 Cr0, Cr1, Cr2, Cr3, Cr4;
|
|
|
|
## insure FXSAVE/FXRSTOR is enabled in CR4...
|
|
|
|
## ... while we're at it, make sure DE is also enabled...
|
2007-07-03 16:09:20 +02:00
|
|
|
mov %cr4,%eax
|
|
|
|
or $0x208,%eax
|
|
|
|
mov %eax,%cr4
|
|
|
|
push %eax
|
|
|
|
mov %cr3,%eax
|
|
|
|
push %eax
|
|
|
|
mov %cr2,%eax
|
|
|
|
push %eax
|
|
|
|
push $0x0
|
|
|
|
mov %cr0,%eax
|
|
|
|
push %eax
|
2008-12-16 10:21:45 +01:00
|
|
|
|
|
|
|
## UINT32 Dr0, Dr1, Dr2, Dr3, Dr6, Dr7;
|
2007-07-03 16:09:20 +02:00
|
|
|
mov %db7,%eax
|
|
|
|
push %eax
|
2008-12-16 10:21:45 +01:00
|
|
|
|
|
|
|
## clear Dr7 while executing debugger itself
|
2007-07-03 16:09:20 +02:00
|
|
|
xor %eax,%eax
|
|
|
|
mov %eax,%db7
|
|
|
|
mov %db6,%eax
|
|
|
|
push %eax
|
2008-12-16 10:21:45 +01:00
|
|
|
|
|
|
|
## insure all status bits in dr6 are clear...
|
2007-07-03 16:09:20 +02:00
|
|
|
xor %eax,%eax
|
|
|
|
mov %eax,%db6
|
|
|
|
mov %db3,%eax
|
|
|
|
push %eax
|
|
|
|
mov %db2,%eax
|
|
|
|
push %eax
|
|
|
|
mov %db1,%eax
|
|
|
|
push %eax
|
|
|
|
mov %db0,%eax
|
|
|
|
push %eax
|
2008-12-16 10:21:45 +01:00
|
|
|
|
|
|
|
## FX_SAVE_STATE_IA32 FxSaveState;
|
2007-07-03 16:09:20 +02:00
|
|
|
sub $0x200,%esp
|
|
|
|
mov %esp,%edi
|
2008-12-16 10:21:45 +01:00
|
|
|
# IMPORTANT!! The debug stack has been carefully constructed to
|
|
|
|
# insure that esp and edi are 16 byte aligned when we get here.
|
|
|
|
# They MUST be. If they are not, a GP fault will occur.
|
2007-07-03 16:09:20 +02:00
|
|
|
fxsave (%edi)
|
2008-12-16 10:21:45 +01:00
|
|
|
|
2011-05-17 10:35:20 +02:00
|
|
|
## UEFI calling convention for IA32 requires that Direction flag in EFLAGs is clear
|
|
|
|
cld
|
|
|
|
|
2008-12-16 10:21:45 +01:00
|
|
|
## UINT32 ExceptionData;
|
2007-07-03 16:09:20 +02:00
|
|
|
mov 0x0,%eax
|
|
|
|
push %eax
|
2008-12-16 10:21:45 +01:00
|
|
|
|
|
|
|
# call to C code which will in turn call registered handler
|
|
|
|
# pass in the vector number
|
2007-07-03 16:09:20 +02:00
|
|
|
mov %esp,%eax
|
|
|
|
push %eax
|
|
|
|
mov 0x0,%eax
|
|
|
|
push %eax
|
|
|
|
call ASM_PFX(CommonIdtEntry+0x184)
|
|
|
|
add $0x8,%esp
|
2008-12-16 10:21:45 +01:00
|
|
|
|
|
|
|
# restore context...
|
|
|
|
## UINT32 ExceptionData;
|
2007-07-03 16:09:20 +02:00
|
|
|
add $0x4,%esp
|
2008-12-16 10:21:45 +01:00
|
|
|
|
|
|
|
## FX_SAVE_STATE_IA32 FxSaveState;
|
2007-07-03 16:09:20 +02:00
|
|
|
mov %esp,%esi
|
|
|
|
fxrstor (%esi)
|
|
|
|
add $0x200,%esp
|
2008-12-16 10:21:45 +01:00
|
|
|
|
|
|
|
## UINT32 Dr0, Dr1, Dr2, Dr3, Dr6, Dr7;
|
2007-07-03 16:09:20 +02:00
|
|
|
pop %eax
|
|
|
|
mov %eax,%db0
|
|
|
|
pop %eax
|
|
|
|
mov %eax,%db1
|
|
|
|
pop %eax
|
|
|
|
mov %eax,%db2
|
|
|
|
pop %eax
|
|
|
|
mov %eax,%db3
|
2008-12-16 10:21:45 +01:00
|
|
|
|
|
|
|
## skip restore of dr6. We cleared dr6 during the context save.
|
2007-07-03 16:09:20 +02:00
|
|
|
add $0x4,%esp
|
|
|
|
pop %eax
|
|
|
|
mov %eax,%db7
|
2008-12-16 10:21:45 +01:00
|
|
|
|
|
|
|
## UINT32 Cr0, Cr1, Cr2, Cr3, Cr4;
|
2007-07-03 16:09:20 +02:00
|
|
|
pop %eax
|
|
|
|
mov %eax,%cr0
|
|
|
|
add $0x4,%esp
|
|
|
|
pop %eax
|
|
|
|
mov %eax,%cr2
|
|
|
|
pop %eax
|
|
|
|
mov %eax,%cr3
|
|
|
|
pop %eax
|
|
|
|
mov %eax,%cr4
|
2008-12-16 10:21:45 +01:00
|
|
|
|
|
|
|
## UINT32 EFlags;
|
2007-07-03 16:09:20 +02:00
|
|
|
mov 0x0,%eax
|
|
|
|
popl 0x8(%eax)
|
2008-12-16 10:21:45 +01:00
|
|
|
|
|
|
|
## UINT32 Ldtr, Tr;
|
|
|
|
## UINT32 Gdtr[2], Idtr[2];
|
|
|
|
## Best not let anyone mess with these particular registers...
|
2007-07-03 16:09:20 +02:00
|
|
|
add $0x18,%esp
|
2008-12-16 10:21:45 +01:00
|
|
|
|
|
|
|
## UINT32 Eip;
|
2007-07-03 16:09:20 +02:00
|
|
|
popl (%eax)
|
2008-12-16 10:21:45 +01:00
|
|
|
|
|
|
|
## UINT32 SegGs, SegFs, SegEs, SegDs, SegCs, SegSs;
|
|
|
|
## NOTE - modified segment registers could hang the debugger... We
|
|
|
|
## could attempt to insulate ourselves against this possibility,
|
|
|
|
## but that poses risks as well.
|
|
|
|
##
|
|
|
|
|
2007-07-03 16:09:20 +02:00
|
|
|
pop %gs
|
|
|
|
pop %fs
|
|
|
|
pop %es
|
|
|
|
pop %ds
|
|
|
|
popl 0x4(%eax)
|
|
|
|
pop %ss
|
|
|
|
mov 0xc(%esp),%ebx
|
2008-12-16 10:21:45 +01:00
|
|
|
|
|
|
|
## The next stuff to restore is the general purpose registers that were pushed
|
|
|
|
## using the "pushad" instruction.
|
|
|
|
##
|
|
|
|
## The value of ESP as stored in the context record is the application ESP
|
|
|
|
## including the 3 entries on the application stack caused by the exception
|
|
|
|
## itself. It may have been modified by the debug agent, so we need to
|
|
|
|
## determine if we need to relocate the application stack.
|
|
|
|
|
|
|
|
mov 0x0,%eax # move the potentially modified AppEsp into ebx
|
2007-07-03 16:09:20 +02:00
|
|
|
add $0xc,%eax
|
|
|
|
cmp %eax,%ebx
|
|
|
|
je ASM_PFX(CommonIdtEntry+0x202)
|
|
|
|
mov 0x0,%eax
|
2008-12-16 10:21:45 +01:00
|
|
|
mov (%eax),%ecx # EIP
|
2007-07-03 16:09:20 +02:00
|
|
|
mov %ecx,(%ebx)
|
2008-12-16 10:21:45 +01:00
|
|
|
mov 0x4(%eax),%ecx # CS
|
2007-07-03 16:09:20 +02:00
|
|
|
mov %ecx,0x4(%ebx)
|
2008-12-16 10:21:45 +01:00
|
|
|
mov 0x8(%eax),%ecx # EFLAGS
|
2007-07-03 16:09:20 +02:00
|
|
|
mov %ecx,0x8(%ebx)
|
2008-12-16 10:21:45 +01:00
|
|
|
|
|
|
|
mov %ebx,%eax # modify the saved AppEsp to the new AppEsp
|
2007-07-03 16:09:20 +02:00
|
|
|
mov %eax,0x0
|
2008-12-16 10:21:45 +01:00
|
|
|
mov 0x0,%eax # restore the DebugEsp on the debug stack
|
|
|
|
# so our "popad" will not cause a stack switch
|
|
|
|
mov %eax,0xc(%esp)
|
2007-07-03 16:09:20 +02:00
|
|
|
cmpl $0x68,0x0
|
|
|
|
jne PhonyIretd+0xd
|
2008-12-16 10:21:45 +01:00
|
|
|
## Restore eflags so when we chain, the flags will be exactly as if we were never here.
|
|
|
|
## We gin up the stack to do an iretd so we can get ALL the flags.
|
2007-07-03 16:09:20 +02:00
|
|
|
mov 0x0,%eax
|
|
|
|
mov 0x8(%eax),%ebx
|
2008-12-16 10:21:45 +01:00
|
|
|
and $0xfffffcff,%ebx # special handling for IF and TF
|
2007-07-03 16:09:20 +02:00
|
|
|
push %ebx
|
|
|
|
push %cs
|
|
|
|
push $0x0
|
2008-04-11 05:36:07 +02:00
|
|
|
iret
|
2007-07-03 16:09:20 +02:00
|
|
|
|
|
|
|
PhonyIretd:
|
2008-12-16 10:21:45 +01:00
|
|
|
## UINT32 Edi, Esi, Ebp, Esp, Ebx, Edx, Ecx, Eax;
|
2008-04-11 05:36:07 +02:00
|
|
|
popa
|
2008-12-16 10:21:45 +01:00
|
|
|
|
|
|
|
## Switch back to application stack
|
2007-07-03 16:09:20 +02:00
|
|
|
mov 0x0,%esp
|
|
|
|
jmp *0x0
|
2008-12-16 10:21:45 +01:00
|
|
|
## Jump to original handler
|
|
|
|
## UINT32 Edi, Esi, Ebp, Esp, Ebx, Edx, Ecx, Eax;
|
2008-04-11 05:36:07 +02:00
|
|
|
popa
|
2008-12-16 10:21:45 +01:00
|
|
|
## Switch back to application stack
|
2007-07-03 16:09:20 +02:00
|
|
|
mov 0x0,%esp
|
2008-12-16 10:21:45 +01:00
|
|
|
|
|
|
|
## We're outa here...
|
2008-04-11 05:36:07 +02:00
|
|
|
iret
|