You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

进程加载可执行文件的内存挑战及JMP至未加载区域的OS处理问询

What Happens When a JMP Targets an Unloaded Address in Windows?

Great question—this cuts to the core of how Windows balances memory efficiency and program execution with virtual memory and on-demand loading. Let’s walk through exactly what goes down:

1. First, The Setup: Virtual Memory & Partial Loading

Windows uses virtual memory to give every process its own isolated address space. When you launch an executable, it doesn’t dump the entire file into RAM right away—instead, it creates a memory mapping that links sections of the exe/dll (like code, data) to ranges of the process’s virtual address space. Physical RAM is only allocated for those pages when the program actually needs to access them.

2. The CPU Flags a Problem: Page Fault Exception

When your program runs a JMP instruction targeting an address that’s in its valid virtual address space but hasn’t been loaded into physical RAM yet, the CPU checks the page table entry (PTE) for that address. The PTE will mark the page as "not present" but still valid (meaning it’s part of the process’s mapped executable).

At this point, the CPU pauses execution immediately, saves the process’s current state, and triggers a page fault exception (interrupt 0xE on x86 systems). This is the CPU’s way of yelling to the OS: "Hey, I need this page—can you get it for me?"

3. The OS Kernel Steps In to Fix It

Windows kernel’s exception handler takes over and does a few key checks:

  • Is the address valid? First, it verifies if the target address is actually part of the process’s allowed address space. If it’s a random, unmapped address (like jumping to 0x00000000 for no reason), this is an invalid access. The kernel will terminate the process with an Access Violation error—you’ve probably seen this as a "Program has stopped working" dialog.
  • Valid but unloaded? If the address is legitimate but just not loaded into RAM, the kernel:
    1. Locates the corresponding page data in the executable file on disk.
    2. Grabs a free physical RAM page.
    3. Reads the required page from disk into that RAM page.
    4. Updates the process’s page table to mark the virtual address as now mapped to the physical RAM page.
  • Once everything is set, the kernel restores the process’s state and tells the CPU to re-run the JMP instruction. This time, the page is present in RAM, so the jump works and execution continues like nothing happened.

4. Edge Cases to Note

  • If the disk read fails (e.g., the executable is corrupted, or the file was deleted mid-execution), the kernel can’t resolve the page fault. It’ll still kill the process with an error.
  • For "copy-on-write" pages (like initialized data sections), a similar page fault occurs if the process writes to the page. Instead of reading from disk, the kernel creates a private copy of the page in RAM so the original file data stays intact.

内容的提问来源于stack exchange,提问作者Farshid

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:25:46