You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过逆向工程从x86汇编还原C语言mystery函数

Unpacking the mystery and mystery_util x86 Assembly Functions

Alright, let's dig into this x86 assembly code to figure out what these functions do. We'll start with the complete mystery_util helper function first, since its full assembly is provided, then touch on the partial mystery code you shared.

Breaking Down mystery_util (Signature: int mystery_util(int n))

In x86-64 System V ABI (the common calling convention for Linux/macOS), the first integer argument is passed in %edi, and the return value is stored in %eax. Let's walk through each instruction:

  • 400526: mov %edi,%eax:Copy the input parameter n (from %edi) into %eax—this sets up our return value register with the raw input first.
  • 400528: shr %eax:Perform a logical right shift on %eax by 1 bit. For non-negative integers, this is exactly equivalent to dividing by 2 and discarding the remainder. For negative integers, note that logical shift zero-fills the top bit, which will flip the sign to positive (unlike arithmetic shift sar, which preserves the sign bit).
  • 40052a: and $0x1,%edi:Do a bitwise AND of n with 0x1 to isolate the least significant bit. This gives us 1 if n is odd, 0 if n is even.
  • 40052d: add %edi,%eax:Add that 0/1 result to our shifted value in %eax.
  • 40052f: c3 retq:Return the final value in %eax to the caller.

What does mystery_util actually compute?

For non-negative integers (the likely intended use case here), this function calculates the ceiling of n divided by 2, or equivalently (n + 1) // 2 using integer division:

  • If n is even: n/2 + 0 = n/2 (which matches (n+1)//2 since even n +1 divided by 2 still truncates to n/2)
  • If n is odd: (n//2) + 1 = (n+1)//2

Test it with examples:

  • mystery_util(4) → 4 >> 1 + 0 = 2 + 0 = 2
  • mystery_util(5) → 5 >> 1 + 1 = 2 + 1 = 3
  • mystery_util(0) → 0 + 0 = 0

For negative inputs, the behavior is quirky (e.g., mystery_util(-3) would return 2147483647 for 32-bit ints) because of the logical shift, but that's probably not the intended use case here.

Partial Look at mystery (Signature: int mystery(int n))

The mystery function starts with two instructions, but the second one is truncated:

  • 400530: mov %edi,%eax:Copy the input n into %eax, just like mystery_util does initially.
  • 400532: 8d 3c fd 00 0...:The opcode 8d tells us this is an lea (load effective address) instruction. The full instruction would look something like lea 0x00000000(,%edi,4),%edi (scaling n by 4) or a similar memory calculation, but we can't fully reverse-engineer mystery without the complete assembly for this line and the rest of the function.

内容的提问来源于stack exchange,提问作者minturtle

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 10:40:28