You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GNU汇编疑问:-4(%rbp)为何未覆盖栈上的帧指针?

Why movl %edi, -0x4(%rbp) is safe in x86-64 stack frames

Great question—this is a common point of confusion when first unpacking x86-64 stack frame mechanics! Let's break down exactly what's happening here, step by step.

First, let's recap the stack frame setup instructions you provided:

_sum:
0000000100000f60 pushq %rbp
0000000100000f61 movq %rsp, %rbp
0000000100000f64 movl %edi, -0x4(%rbp)
0000000100000f67 movl %esi, -0x8(%rbp)

Key Background: x86-64 Stack Growth

The x86-64 stack grows downward—meaning stack addresses decrease as you push more data onto the stack. When you execute pushq %rbp, two things happen:

  1. The stack pointer %rsp is decremented by 8 (since q denotes an 8-byte operation).
  2. The current value of %rbp is written to the memory location now pointed to by %rsp.

What movq %rsp, %rbp Does

After pushing %rbp, we set %rbp equal to %rsp. This makes %rbp the base pointer for the current function's stack frame, pointing directly to the start of the saved %rbp value (which occupies 8 bytes of memory, from %rbp to %rbp + 7).

Why -0x4(%rbp) Doesn't Overwrite Saved %rbp

When we execute movl %edi, -0x4(%rbp), we're writing to the memory address calculated as %rbp - 4. Since %rbp points to the start of the saved %rbp value, subtracting 4 moves us to an address below (lower numerical value) the saved %rbp—this is unused stack space reserved for the function's local variables, and it doesn't overlap with the 8 bytes of the saved %rbp at all.

Let's use concrete addresses to make this tangible:

  • Suppose before pushq %rbp, %rsp is 0x1000.
  • After pushq %rbp, %rsp becomes 0x0FF8, and the original %rbp value is stored in addresses 0x0FF8 to 0x0FFF.
  • movq %rsp, %rbp sets %rbp to 0x0FF8.
  • movl %edi, -0x4(%rbp) writes to 0x0FF8 - 4 = 0x0FF4 (covering 0x0FF4 to 0x0FF7), which is completely separate from the saved %rbp's space (0x0FF8 to 0x0FFF).

Final Notes

  • The negative offsets from %rbp are standard for accessing local variables in x86-64 stack frames—they're designed to avoid interfering with the saved %rbp (or the return address, which is stored higher up in the stack).
  • As you noted, %edi and %esi hold the first two integer arguments to the sum function; storing them in the stack frame is a safe way to preserve their values for use later in the function.

内容的提问来源于stack exchange,提问作者acomplex

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 06:31:35