Linux x86平台i386架构下,系统调用分为如下三步:
把系统调用号放在eax寄存器内,不同的系统调用号对应不同的功能。系统调用号定义在/usr/include/asm/unistd_32.h头文件中。
根据系统调用的需要,把对应的参数放入ebx, ecx, edx, esi, edi和ebp寄存器。
调用int 0x80中断,这会触发系统调用机制,内核会根据eax寄存器中的系统调用号,来调用对应的内核函数处理该系统调用。
举个例子,open系统调用的汇编如下:
mov eax, 5 ; sys_open系统调用号
mov ebx, filename ; 文件名
mov ecx, flags ; 文件标志
mov edx, mode ; 文件权限模式
int 0x80 ; 调用中断
主要步骤:
eax寄存器中放入sys_open的系统调用号5
因为open系统调用需要文件名、文件标志和权限模式三个参数,所以分别放入ebx, ecx 和edx寄存器
调用int 0x80系统调用中断,内核就会调用对应的open系统调用函数
系统调用返回值会放在eax寄存器中。
总的来说,Linux x86平台的系统调用通过使用系统调用号和相应的参数,调用int 0x80中断,从而跳转到内核实现具体的系统调用功能。
| 调用号 | 名称 | 系统名称 |
|---|---|---|
| 0 | restart_syscall | sys_restart_syscall |
| 1 | exit | sys_exit |
| 2 | fork | sys_fork |
| 3 | read | sys_read |
| 4 | write | sys_write |
| 5 | open | sys_open |
| 6 | close | sys_close |
| 7 | waitpid | sys_waitpid |
| 8 | creat | sys_creat |
| 9 | link | sys_link |
| 10 | unlink | sys_unlink |
| 11 | execve | sys_execve |
| 12 | chdir | sys_chdir |
| 13 | time | sys_time32 |
| 14 | mknod | sys_mknod |
| 15 | chmod | sys_chmod |
| 16 | lchown | sys_lchown16 |
| 17 | break | |
| 18 | oldstat | sys_stat |
| 19 | lseek | sys_lseek |
| 20 | getpid | sys_getpid |
| 21 | mount | sys_mount |
| 22 | umount | sys_oldumount |
| 23 | setuid | sys_setuid16 |
| 24 | getuid | sys_getuid16 |
| 25 | stime | sys_stime32 |
| 26 | ptrace | sys_ptrace |
| 27 | alarm | sys_alarm |
| 28 | oldfstat | sys_fstat |
| 29 | pause | sys_pause |
| 30 | utime | sys_utime32 |
| 31 | stty | |
| 32 | gtty | |
| 33 | access | sys_access |
| 34 | nice | sys_nice |
| 35 | ftime | |
| 36 | sync | sys_sync |
| 37 | kill | sys_kill |
| 38 | rename | sys_rename |
| 39 | mkdir | sys_mkdir |
| 40 | rmdir | sys_rmdir |
| 41 | dup | sys_dup |
| 42 | pipe | sys_pipe |
| 43 | times | sys_times |
| 44 | prof | |
| 45 | brk | sys_brk |
| 46 | setgid | sys_setgid16 |
| 47 | getgid | sys_getgid16 |
| 48 | signal | sys_signal |
| 49 | geteuid | sys_geteuid16 |
| 50 | getegid | sys_getegid16 |
| 51 | acct | sys_acct |
| 52 | umount2 | sys_umount |
| 53 | lock | |
| 54 | ioctl | sys_ioctl |
| 55 | fcntl | sys_fcntl |
| 56 | mpx | |
| 57 | setpgid | sys_setpgid |
| 58 | ulimit | |
| 59 | oldolduname | sys_olduname |
| 60 | umask | sys_umask |
| 61 | chroot | sys_chroot |
| 62 | ustat | sys_ustat |
| 63 | dup2 | sys_dup2 |
| 64 | getppid | sys_getppid |
| 65 | getpgrp | sys_getpgrp |
| 66 | setsid | sys_setsid |
| 67 | sigaction | sys_sigaction |
| 68 | sgetmask | sys_sgetmask |
| 69 | ssetmask | sys_ssetmask |
| 70 | setreuid | sys_setreuid16 |
| 71 | setregid | sys_setregid16 |
| 72 | sigsuspend | sys_sigsuspend |
| 73 | sigpending | sys_sigpending |
| 74 | sethostname | sys_sethostname |
| 75 | setrlimit | sys_setrlimit |
| 76 | getrlimit | sys_old_getrlimit |
| 77 | getrusage | sys_getrusage |
| 78 | gettimeofday | sys_gettimeofday |
| 79 | settimeofday | sys_settimeofday |
| 80 | getgroups | sys_getgroups16 |
| 81 | setgroups | sys_setgroups16 |
| 82 | select | sys_old_select |
| 83 | symlink | sys_symlink |
| 84 | oldlstat | sys_lstat |
| 85 | readlink | sys_readlink |
| 86 | uselib | sys_uselib |
| 87 | swapon | sys_swapon |
| 88 | reboot | sys_reboot |
| 89 | readdir | sys_old_readdir |
| 90 | mmap | sys_old_mmap |
| 91 | munmap | sys_munmap |
| 92 | truncate | sys_truncate |
| 93 | ftruncate | sys_ftruncate |
| 94 | fchmod | sys_fchmod |
| 95 | fchown | sys_fchown16 |
| 96 | getpriority | sys_getpriority |
| 97 | setpriority | sys_setpriority |
| 98 | profil | |
| 99 | statfs | sys_statfs |
| 100 | fstatfs | sys_fstatfs |
| 101 | ioperm | sys_ioperm |
| 102 | socketcall | sys_socketcall |
| 103 | syslog | sys_syslog |
| 104 | setitimer | sys_setitimer |
| 105 | getitimer | sys_getitimer |
| 106 | stat | sys_newstat |
| 107 | lstat | sys_newlstat |
| 108 | fstat | sys_newfstat |
| 109 | olduname | sys_uname |
| 110 | iopl | sys_iopl |
| 111 | vhangup | sys_vhangup |
| 112 | idle | |
| 113 | vm86old | sys_vm86old |
| 114 | wait4 | sys_wait4 |
| 115 | swapoff | sys_swapoff |
| 116 | sysinfo | sys_sysinfo |
| 117 | ipc | sys_ipc |
| 118 | fsync | sys_fsync |
| 119 | sigreturn | sys_sigreturn |
| 120 | clone | sys_clone |
| 121 | setdomainname | sys_setdomainname |
| 122 | uname | sys_newuname |
| 123 | modify_ldt | sys_modify_ldt |
| 124 | adjtimex | sys_adjtimex_time32 |
| 125 | mprotect | sys_mprotect |
| 126 | sigprocmask | sys_sigprocmask |
| 127 | create_module | |
| 128 | init_module | sys_init_module |
| 129 | delete_module | sys_delete_module |
| 130 | get_kernel_syms | |
| 131 | quotactl | sys_quotactl |
| 132 | getpgid | sys_getpgid |
| 133 | fchdir | sys_fchdir |
| 134 | bdflush | sys_ni_syscall |
| 135 | sysfs | sys_sysfs |
| 136 | personality | sys_personality |
| 137 | afs_syscall | |
| 138 | setfsuid | sys_setfsuid16 |
| 139 | setfsgid | sys_setfsgid16 |
| 140 | _llseek | sys_llseek |
| 141 | getdents | sys_getdents |
| 142 | _newselect | sys_select |
| 143 | flock | sys_flock |
| 144 | msync | sys_msync |
| 145 | readv | sys_readv |
| 146 | writev | sys_writev |
| 147 | getsid | sys_getsid |
| 148 | fdatasync | sys_fdatasync |
| 149 | _sysctl | sys_ni_syscall |
| 150 | mlock | sys_mlock |
| 151 | munlock | sys_munlock |
| 152 | mlockall | sys_mlockall |
| 153 | munlockall | sys_munlockall |
| 154 | sched_setparam | sys_sched_setparam |
| 155 | sched_getparam | sys_sched_getparam |
| 156 | sched_setscheduler | sys_sched_setscheduler |
| 157 | sched_getscheduler | sys_sched_getscheduler |
| 158 | sched_yield | sys_sched_yield |
| 159 | sched_get_priority_max | sys_sched_get_priority_max |
| 160 | sched_get_priority_min | sys_sched_get_priority_min |
| 161 | sched_rr_get_interval | sys_sched_rr_get_interval_time32 |
| 162 | nanosleep | sys_nanosleep_time32 |
| 163 | mremap | sys_mremap |
| 164 | setresuid | sys_setresuid16 |
| 165 | getresuid | sys_getresuid16 |
| 166 | vm86 | sys_vm86 |
| 167 | query_module | |
| 168 | poll | sys_poll |
| 169 | nfsservctl | |
| 170 | setresgid | sys_setresgid16 |
| 171 | getresgid | sys_getresgid16 |
| 172 | prctl | sys_prctl |
| 173 | rt_sigreturn | sys_rt_sigreturn |
| 174 | rt_sigaction | sys_rt_sigaction |
| 175 | rt_sigprocmask | sys_rt_sigprocmask |
| 176 | rt_sigpending | sys_rt_sigpending |
| 177 | rt_sigtimedwait | sys_rt_sigtimedwait_time32 |
| 178 | rt_sigqueueinfo | sys_rt_sigqueueinfo |
| 179 | rt_sigsuspend | sys_rt_sigsuspend |
| 180 | pread64 | sys_ia32_pread64 |
| 181 | pwrite64 | sys_ia32_pwrite64 |
| 182 | chown | sys_chown16 |
| 183 | getcwd | sys_getcwd |
| 184 | capget | sys_capget |
| 185 | capset | sys_capset |
| 186 | sigaltstack | sys_sigaltstack |
| 187 | sendfile | sys_sendfile |
| 188 | getpmsg | |
| 189 | putpmsg | |
| 190 | vfork | sys_vfork |
| 191 | ugetrlimit | sys_getrlimit |
| 192 | mmap2 | sys_mmap_pgoff |
| 193 | truncate64 | sys_ia32_truncate64 |
| 194 | ftruncate64 | sys_ia32_ftruncate64 |
| 195 | stat64 | sys_stat64 |
| 196 | lstat64 | sys_lstat64 |
| 197 | fstat64 | sys_fstat64 |
| 198 | lchown32 | sys_lchown |
| 199 | getuid32 | sys_getuid |
| 200 | getgid32 | sys_getgid |
| 201 | geteuid32 | sys_geteuid |
| 202 | getegid32 | sys_getegid |
| 203 | setreuid32 | sys_setreuid |
| 204 | setregid32 | sys_setregid |
| 205 | getgroups32 | sys_getgroups |
| 206 | setgroups32 | sys_setgroups |
| 207 | fchown32 | sys_fchown |
| 208 | setresuid32 | sys_setresuid |
| 209 | getresuid32 | sys_getresuid |
| 210 | setresgid32 | sys_setresgid |
| 211 | getresgid32 | sys_getresgid |
| 212 | chown32 | sys_chown |
| 213 | setuid32 | sys_setuid |
| 214 | setgid32 | sys_setgid |
| 215 | setfsuid32 | sys_setfsuid |
| 216 | setfsgid32 | sys_setfsgid |
| 217 | pivot_root | sys_pivot_root |
| 218 | mincore | sys_mincore |
| 219 | madvise | sys_madvise |
| 220 | getdents64 | sys_getdents64 |
| 221 | fcntl64 | sys_fcntl64 |
| # 222 is unused | ||
| # 223 is unused | ||
| 224 | gettid | sys_gettid |
| 225 | readahead | sys_ia32_readahead |
| 226 | setxattr | sys_setxattr |
| 227 | lsetxattr | sys_lsetxattr |
| 228 | fsetxattr | sys_fsetxattr |
| 229 | getxattr | sys_getxattr |
| 230 | lgetxattr | sys_lgetxattr |
| 231 | fgetxattr | sys_fgetxattr |
| 232 | listxattr | sys_listxattr |
| 233 | llistxattr | sys_llistxattr |
| 234 | flistxattr | sys_flistxattr |
| 235 | removexattr | sys_removexattr |
| 236 | lremovexattr | sys_lremovexattr |
| 237 | fremovexattr | sys_fremovexattr |
| 238 | tkill | sys_tkill |
| 239 | sendfile64 | sys_sendfile64 |
| 240 | futex | sys_futex_time32 |
| 241 | sched_setaffinity | sys_sched_setaffinity |
| 242 | sched_getaffinity | sys_sched_getaffinity |
| 243 | set_thread_area | sys_set_thread_area |
| 244 | get_thread_area | sys_get_thread_area |
| 245 | io_setup | sys_io_setup |
| 246 | io_destroy | sys_io_destroy |
| 247 | io_getevents | sys_io_getevents_time32 |
| 248 | io_submit | sys_io_submit |
| 249 | io_cancel | sys_io_cancel |
| 250 | fadvise64 | sys_ia32_fadvise64 |
| # 251 is available for reuse (was briefly sys_set_zone_reclaim) | ||
| 252 | exit_group | sys_exit_group |
| 253 | lookup_dcookie | sys_lookup_dcookie |
| 254 | epoll_create | sys_epoll_create |
| 255 | epoll_ctl | sys_epoll_ctl |
| 256 | epoll_wait | sys_epoll_wait |
| 257 | remap_file_pages | sys_remap_file_pages |
| 258 | set_tid_address | sys_set_tid_address |
| 259 | timer_create | sys_timer_create |
| 260 | timer_settime | sys_timer_settime32 |
| 261 | timer_gettime | sys_timer_gettime32 |
| 262 | timer_getoverrun | sys_timer_getoverrun |
| 263 | timer_delete | sys_timer_delete |
| 264 | clock_settime | sys_clock_settime32 |
| 265 | clock_gettime | sys_clock_gettime32 |
| 266 | clock_getres | sys_clock_getres_time32 |
| 267 | clock_nanosleep | sys_clock_nanosleep_time32 |
| 268 | statfs64 | sys_statfs64 |
| 269 | fstatfs64 | sys_fstatfs64 |
| 270 | tgkill | sys_tgkill |
| 271 | utimes | sys_utimes_time32 |
| 272 | fadvise64_64 | sys_ia32_fadvise64_64 |
| 273 | vserver | |
| 274 | mbind | sys_mbind |
| 275 | get_mempolicy | sys_get_mempolicy |
| 276 | set_mempolicy | sys_set_mempolicy |
| 277 | mq_open | sys_mq_open |
| 278 | mq_unlink | sys_mq_unlink |
| 279 | mq_timedsend | sys_mq_timedsend_time32 |
| 280 | mq_timedreceive | sys_mq_timedreceive_time32 |
| 281 | mq_notify | sys_mq_notify |
| 282 | mq_getsetattr | sys_mq_getsetattr |
| 283 | kexec_load | sys_kexec_load |
| 284 | waitid | sys_waitid |
| # 285 sys_setaltroot | ||
| 286 | add_key | sys_add_key |
| 287 | request_key | sys_request_key |
| 288 | keyctl | sys_keyctl |
| 289 | ioprio_set | sys_ioprio_set |
| 290 | ioprio_get | sys_ioprio_get |
| 291 | inotify_init | sys_inotify_init |
| 292 | inotify_add_watch | sys_inotify_add_watch |
| 293 | inotify_rm_watch | sys_inotify_rm_watch |
| 294 | migrate_pages | sys_migrate_pages |
| 295 | openat | sys_openat |
| 296 | mkdirat | sys_mkdirat |
| 297 | mknodat | sys_mknodat |
| 298 | fchownat | sys_fchownat |
| 299 | futimesat | sys_futimesat_time32 |
| 300 | fstatat64 | sys_fstatat64 |
| 301 | unlinkat | sys_unlinkat |
| 302 | renameat | sys_renameat |
| 303 | linkat | sys_linkat |
| 304 | symlinkat | sys_symlinkat |
| 305 | readlinkat | sys_readlinkat |
| 306 | fchmodat | sys_fchmodat |
| 307 | faccessat | sys_faccessat |
| 308 | pselect6 | sys_pselect6_time32 |
| 309 | ppoll | sys_ppoll_time32 |
| 310 | unshare | sys_unshare |
| 311 | set_robust_list | sys_set_robust_list |
| 312 | get_robust_list | sys_get_robust_list |
| 313 | splice | sys_splice |
| 314 | sync_file_range | sys_ia32_sync_file_range |
| 315 | tee | sys_tee |
| 316 | vmsplice | sys_vmsplice |
| 317 | move_pages | sys_move_pages |
| 318 | getcpu | sys_getcpu |
| 319 | epoll_pwait | sys_epoll_pwait |
| 320 | utimensat | sys_utimensat_time32 |
| 321 | signalfd | sys_signalfd |
| 322 | timerfd_create | sys_timerfd_create |
| 323 | eventfd | sys_eventfd |
| 324 | fallocate | sys_ia32_fallocate |
| 325 | timerfd_settime | sys_timerfd_settime32 |
| 326 | timerfd_gettime | sys_timerfd_gettime32 |
| 327 | signalfd4 | sys_signalfd4 |
| 328 | eventfd2 | sys_eventfd2 |
| 329 | epoll_create1 | sys_epoll_create1 |
| 330 | dup3 | sys_dup3 |
| 331 | pipe2 | sys_pipe2 |
| 332 | inotify_init1 | sys_inotify_init1 |
| 333 | preadv | sys_preadv |
| 334 | pwritev | sys_pwritev |
| 335 | rt_tgsigqueueinfo | sys_rt_tgsigqueueinfo |
| 336 | perf_event_open | sys_perf_event_open |
| 337 | recvmmsg | sys_recvmmsg_time32 |
| 338 | fanotify_init | sys_fanotify_init |
| 339 | fanotify_mark | sys_fanotify_mark |
| 340 | prlimit64 | sys_prlimit64 |
| 341 | name_to_handle_at | sys_name_to_handle_at |
| 342 | open_by_handle_at | sys_open_by_handle_at |
| 343 | clock_adjtime | sys_clock_adjtime32 |
| 344 | syncfs | sys_syncfs |
| 345 | sendmmsg | sys_sendmmsg |
| 346 | setns | sys_setns |
| 347 | process_vm_readv | sys_process_vm_readv |
| 348 | process_vm_writev | sys_process_vm_writev |
| 349 | kcmp | sys_kcmp |
| 350 | finit_module | sys_finit_module |
| 351 | sched_setattr | sys_sched_setattr |
| 352 | sched_getattr | sys_sched_getattr |
| 353 | renameat2 | sys_renameat2 |
| 354 | seccomp | sys_seccomp |
| 355 | getrandom | sys_getrandom |
| 356 | memfd_create | sys_memfd_create |
| 357 | bpf | sys_bpf |
| 358 | execveat | sys_execveat |
| 359 | socket | sys_socket |
| 360 | socketpair | sys_socketpair |
| 361 | bind | sys_bind |
| 362 | connect | sys_connect |
| 363 | listen | sys_listen |
| 364 | accept4 | sys_accept4 |
| 365 | getsockopt | sys_getsockopt |
| 366 | setsockopt | sys_setsockopt |
| 367 | getsockname | sys_getsockname |
| 368 | getpeername | sys_getpeername |
| 369 | sendto | sys_sendto |
| 370 | sendmsg | sys_sendmsg |
| 371 | recvfrom | sys_recvfrom |
| 372 | recvmsg | sys_recvmsg |
| 373 | shutdown | sys_shutdown |
| 374 | userfaultfd | sys_userfaultfd |
| 375 | membarrier | sys_membarrier |
| 376 | mlock2 | sys_mlock2 |
| 377 | copy_file_range | sys_copy_file_range |
| 378 | preadv2 | sys_preadv2 |
| 379 | pwritev2 | sys_pwritev2 |
| 380 | pkey_mprotect | sys_pkey_mprotect |
| 381 | pkey_alloc | sys_pkey_alloc |
| 382 | pkey_free | sys_pkey_free |
| 383 | statx | sys_statx |
| 384 | arch_prctl | sys_arch_prctl |
| 385 | io_pgetevents | sys_io_pgetevents_time32 |
| 386 | rseq | sys_rseq |
| 393 | semget | sys_semget |
| 394 | semctl | sys_semctl |
| 395 | shmget | sys_shmget |
| 396 | shmctl | sys_shmctl |
| 397 | shmat | sys_shmat |
| 398 | shmdt | sys_shmdt |
| 399 | msgget | sys_msgget |
| 400 | msgsnd | sys_msgsnd |
| 401 | msgrcv | sys_msgrcv |
| 402 | msgctl | sys_msgctl |
| 403 | clock_gettime64 | sys_clock_gettime |
| 404 | clock_settime64 | sys_clock_settime |
| 405 | clock_adjtime64 | sys_clock_adjtime |
| 406 | clock_getres_time64 | sys_clock_getres |
| 407 | clock_nanosleep_time64 | sys_clock_nanosleep |
| 408 | timer_gettime64 | sys_timer_gettime |
| 409 | timer_settime64 | sys_timer_settime |
| 410 | timerfd_gettime64 | sys_timerfd_gettime |
| 411 | timerfd_settime64 | sys_timerfd_settime |
| 412 | utimensat_time64 | sys_utimensat |
| 413 | pselect6_time64 | sys_pselect6 |
| 414 | ppoll_time64 | sys_ppoll |
| 416 | io_pgetevents_time64 | sys_io_pgetevents |
| 417 | recvmmsg_time64 | sys_recvmmsg |
| 418 | mq_timedsend_time64 | sys_mq_timedsend |
| 419 | mq_timedreceive_time64 | sys_mq_timedreceive |
| 420 | semtimedop_time64 | sys_semtimedop |
| 421 | rt_sigtimedwait_time64 | sys_rt_sigtimedwait |
| 422 | futex_time64 | sys_futex |
| 423 | sched_rr_get_interval_time64 | sys_sched_rr_get_interval |
| 424 | pidfd_send_signal | sys_pidfd_send_signal |
| 425 | io_uring_setup | sys_io_uring_setup |
| 426 | io_uring_enter | sys_io_uring_enter |
| 427 | io_uring_register | sys_io_uring_register |
| 428 | open_tree | sys_open_tree |
| 429 | move_mount | sys_move_mount |
| 430 | fsopen | sys_fsopen |
| 431 | fsconfig | sys_fsconfig |
| 432 | fsmount | sys_fsmount |
| 433 | fspick | sys_fspick |
| 434 | pidfd_open | sys_pidfd_open |
| 435 | clone3 | sys_clone3 |
| 436 | close_range | sys_close_range |
| 437 | openat2 | sys_openat2 |
| 438 | pidfd_getfd | sys_pidfd_getfd |
| 439 | faccessat2 | sys_faccessat2 |
| 440 | process_madvise | sys_process_madvise |
| 441 | epoll_pwait2 | sys_epoll_pwait2 |
| 442 | mount_setattr | sys_mount_setattr |
| 443 | quotactl_fd | sys_quotactl_fd |
| 444 | landlock_create_ruleset | sys_landlock_create_ruleset |
| 445 | landlock_add_rule | sys_landlock_add_rule |
| 446 | landlock_restrict_self | sys_landlock_restrict_self |
| 447 | memfd_secret | sys_memfd_secret |
| 448 | process_mrelease | sys_process_mrelease |
| 449 | futex_waitv | sys_futex_waitv |
| 450 | set_mempolicy_home_node | sys_set_mempolicy_home_node |
| 451 | pmadv_ksm | sys_pmadv_ksm |
Linuxx86平台的系统调用通过设置系统调用号在eax寄存器,将参数放入其他寄存器,然后调用int0x80中断,内核依据调用号执行相应功能,如open、close等。系统调用返回值存储在eax寄存器。
1211

被折叠的 条评论
为什么被折叠?



