You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

解读汇编指令mov %fs:0x28,%rax:触发该指令的C代码场景

为什么非调用外部函数时也会出现栈保护指令?

Great question! That mov %fs:0x28,%rax instruction is part of the Stack Smashing Protector (SSP, also called ProPolice) used by GCC, Clang, and other compilers to defend against stack overflow attacks. You don't need to call external functions to trigger this—compilers will insert this protection for any function that meets certain criteria, regardless of whether it calls other code.

Here are the most common C code patterns that will cause the compiler to generate this stack canary setup, even in functions with no external calls:

  • Local character arrays (or any large stack-allocated array):If your function declares something like char buffer[64]; or int nums[100];, the compiler sees a high risk of stack overflow (especially for char arrays, which are often used with unsafe functions like strcpy()). It will automatically add the stack canary to protect the stack frame.
  • Variable-Length Arrays (VLAs):Any dynamically-sized stack array like int size = get_input(); char buf[size]; triggers stack protection, since the array's size isn't known at compile time and increases overflow risk.
  • Use of alloca():This function allocates memory directly on the stack, just like VLAs. Since it's dynamic and unbound, compilers will add stack canaries to functions that use it.
  • Large or complex stack frames:If your function has multiple local variables, nested block-scoped variables, or passes large structs by value (which get copied onto the stack), the compiler will enable stack protection to safeguard the expanded stack frame.
  • Compiler defaults:In most default compilation modes (like -O0 for debug or -O2 for release), compilers enable stack protection for all non-leaf functions (functions that call other functions) and many leaf functions (functions that don't call others) if they have any stack-allocated data that could be exploited. Even small functions with a single array can trigger this.

Looking at your assembly snippet:

0x000000000040054a <+4>: sub $0x40,%rsp
0x000000000040054e <+8>: mov %fs:0x28,%rax
...
0x000000000040055d <+23>: movl $0x17,-0x30(%rbp)

The sub $0x40,%rsp means the function is allocating 64 bytes of stack space, and the movl $0x17,-0x30(%rbp) is initializing a local variable at offset -0x30 from the base pointer. It's very likely this function has a local array or large stack variable that triggered the stack canary setup—no external function calls required.

内容的提问来源于stack exchange,提问作者Anon.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 07:06:04