File: access_below_sp.c

package info (click to toggle)
valgrind 1%3A3.24.0-3
  • links: PTS, VCS
  • area: main
  • in suites: trixie
  • size: 176,332 kB
  • sloc: ansic: 795,029; exp: 26,134; xml: 23,472; asm: 14,393; cpp: 9,397; makefile: 7,464; sh: 6,122; perl: 5,446; python: 1,498; javascript: 981; awk: 166; csh: 1
file content (39 lines) | stat: -rw-r--r-- 765 bytes parent folder | download | duplicates (5)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39

#include <stdio.h>


#define COMPILER_BARRIER  __asm__ __volatile("":::"cc","memory")

/* force the kernel to map in 15k below SP, so we can safely poke
   around there. */
__attribute__((noinline)) void make_below_sp_safe ( void )
{
   const int N = 15000;
   unsigned char a[N];
   int i;

   for (i = 0; i < N; i++) {
      a[i] = i & 0xFF;
   }

   COMPILER_BARRIER;

   unsigned int r = 0;
   for (i = 0; i < N; i++) {
      r = (r << 1) | (r >> 31);
      r ^= (unsigned int)a[i];
   }
   fprintf(stderr, "Checksum: %08x\n", r);
}


int main ( void )
{
   make_below_sp_safe();

   unsigned int res;
   __asm__ __volatile__("movl -8192(%%rsp), %0"
                        : "=r"(res) : : "memory","cc");
   fprintf(stderr, "Got %08x\n", res);
   return 0;
}