关于GDB反汇编中-0xc(%rbp)的位置及偏移字符含义的技术问询
Hey Jonathon, great questions—reverse engineering assembly can definitely throw you off with syntax quirks like this, so let’s unpack both points clearly.
1. What memory location does -0xc(%rbp) correspond to?
The %rbp register is the base pointer, which acts as a fixed reference point for the current function’s stack frame. In most x86/x86_64 calling conventions, %rbp points to the bottom of the stack frame (where the previous frame’s base pointer was stored).
When you see -0xc(%rbp), this uses displacement addressing mode: it means "take the address stored in %rbp, subtract 0xc (hexadecimal), and use that resulting address as the target memory location". Since the stack grows downward (toward lower memory addresses) on these systems, negative offsets from %rbp refer to the region of the stack frame reserved for local variables or temporary values.
2. What does the "c" in -0xc(%rbp) mean?
That "c" is just a hexadecimal digit! Hexadecimal uses digits 0-9 and letters A-F (or lowercase a-f) to represent values 0-15. In this case:
0xcin hex = 12 in decimal.
So -0xc(%rbp) translates directly to "12 bytes below the address stored in %rbp". It’s easy to link the letter "c" to the C programming language, but this has no connection—it’s just standard compact notation used in assembly (and GDB’s disassembly output) for numbers, especially common for stack offsets that align with word/dword/qword sizes.
To tie it all together, the instruction mov %eax,-0xc(%rbp) simply copies the value from the %eax register into the memory address 12 bytes below the current base pointer—this is almost certainly storing a local variable from a register back onto the stack.
内容的提问来源于stack exchange,提问作者Jonathon Addy

