为何GDB仅显示函数地址栈,不展示手动push的栈修改?
push %rcx in Its Stack Trace Display? Great question! Let's break down why GDB's stack trace only reflects function call addresses and ignores your manual push %rcx instruction:
1. GDB's Stack Trace Tracks Function Call Chains, Not Raw Stack Memory
First, the stack view you're seeing isn't a full dump of every value on the stack—it's a parsed view of the function call chain. GDB isn't designed to show arbitrary stack data; it's specifically looking for evidence of function invocations to build a readable call history.
2. How GDB Identifies Valid Function Calls
When you run call func, the x86 call instruction does two critical things that GDB relies on:
- Jumps to the entry point of
func - Automatically pushes the return address (the address of the instruction immediately after
call func) onto the stack
GDB uses this return address to build the stack trace: it maps the address to a function via the binary's symbol table, then walks up the stack using standard frame structures (like the RBP-linked frame chain or DWARF debugging info) to find the next return address from the caller function.
3. Manual push %rcx Doesn't Fit GDB's Expected Pattern
Your push %rcx instruction only copies the value of the RCX register onto the stack. To GDB, this is just arbitrary data—there's nothing about this value that signals a function call. It's not a return address (it doesn't point to an instruction in your binary that follows a call), and it doesn't match the structure of a function stack frame that GDB looks for when building a backtrace.
Even though push %rcx modifies rsp, it doesn't leave the kind of trace GDB uses to track function calls. That's why adding or removing it has no effect on the stack trace display.
4. To Verify Your Manual Push, Inspect Raw Stack Memory
If you want to confirm that push %rcx is modifying the stack, use GDB's memory inspection commands instead of the backtrace. For example:
# Print the top 10 64-bit values on the stack x/10xg $rsp
You'll see the value from %rcx sitting on the stack (right before the return address pushed by call func if you run push %rcx first).
内容的提问来源于stack exchange,提问作者samuelbrody1249

