如何在广义数据库中检查函数的返回值?

是否可以检查 gdb 中函数的返回值,假设返回值是分配给变量的 没有

66698 次浏览

是的,只需键入 print $eax检查 EAX寄存器。对于大多数函数,返回值存储在该寄存器中,即使没有使用它。

这种情况的例外是返回大于32位的类型的函数,特别是64位整数(long long)、 doublestructsclasses

另一个例外是如果您没有运行在 Intel 架构上。在这种情况下,如果有的话,您必须找出使用哪个寄存器。

我想有更好的方法可以做到这一点,但是 完成命令会一直执行,直到弹出当前堆栈帧并输出返回值为止——给定程序

int fun() {
return 42;
}


int main( int argc, char *v[] ) {
fun();
return 0;
}

你可以像这样调试它

(gdb) r
Starting program: /usr/home/hark/a.out


Breakpoint 1, fun () at test.c:2
2               return 42;
(gdb) finish
Run till exit from #0  fun () at test.c:2
main () at test.c:7
7               return 0;
Value returned is $1 = 42
(gdb)

finish命令可以缩写为 fin。不要使用 f,这是 frame命令的缩写!

这里是如何做到这一点,没有符号。

gdb ls
This GDB was configured as "ppc64-yellowdog-linux-gnu"...
(no debugging symbols found)
Using host libthread_db library "/lib64/libthread_db.so.1".


(gdb) break __libc_start_main
Breakpoint 1 at 0x10013cb0
(gdb) r
Starting program: /bin/ls
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
Breakpoint 1 at 0xfdfed3c
(no debugging symbols found)
[Thread debugging using libthread_db enabled]
[New Thread 4160418656 (LWP 10650)]
(no debugging symbols found)
(no debugging symbols found)
[Switching to Thread 4160418656 (LWP 10650)]


Breakpoint 1, 0x0fdfed3c in __libc_start_main () from /lib/libc.so.6
(gdb) info frame
Stack level 0, frame at 0xffd719a0:
pc = 0xfdfed3c in __libc_start_main; saved pc 0x0
called by frame at 0x0
Arglist at 0xffd71970, args:
Locals at 0xffd71970, Previous frame's sp is 0xffd719a0
Saved registers:
r24 at 0xffd71980, r25 at 0xffd71984, r26 at 0xffd71988, r27 at 0xffd7198c,
r28 at 0xffd71990, r29 at 0xffd71994, r30 at 0xffd71998, r31 at 0xffd7199c,
pc at 0xffd719a4, lr at 0xffd719a4
(gdb) frame 0
#0  0x0fdfed3c in __libc_start_main () from /lib/libc.so.6
(gdb) info fr
Stack level 0, frame at 0xffd719a0:
pc = 0xfdfed3c in __libc_start_main; saved pc 0x0
called by frame at 0x0
Arglist at 0xffd71970, args:
Locals at 0xffd71970, Previous frame's sp is 0xffd719a0
Saved registers:
r24 at 0xffd71980, r25 at 0xffd71984, r26 at 0xffd71988, r27 at 0xffd7198c,
r28 at 0xffd71990, r29 at 0xffd71994, r30 at 0xffd71998, r31 at 0xffd7199c,
pc at 0xffd719a4, lr at 0xffd719a4

格式设置有点混乱,注意使用“ info frame”检查框架,使用“ frame #”将上下文导航到另一个上下文(在堆栈中上下移动)

还有一个缩写的堆栈来帮忙。