3 ms·
Another interesting article by raymond chen on this topic: https://blogs.msdn.microsoft.com/oldnewthing/20110921-00/?p=9583 https://blogs.msdn.microsoft.com/old
by RandomBK 11y ago
Another interesting article by raymond chen on this topic: https://blogs.msdn.microsoft.com/oldnewthing/20110921-00/?p=9583 https://blogs.msdn.microsoft.com/oldnewthing/20110921-00/?p=...
I believe it's where the "ms" in "ms_hook_prologue" came from.
- andyjohnson0 11y agoThere was some discussion of Raymond Chen's article a couple of months back [1]. According to the present article GCC emits an eight byte prologue (LEA RSP,[RSP+0x0]) at the start of the function, but Raymond Chen says that Microsoft's compiler emits five NOPS before the function start address and an overwritable two byte prologue (MOV EDI, EDI) at the start of the function itself. To me, Microsoft's approach seems more efficient - but I've never written any serious x86 assembly. Anybody knowledgeable want to comment on this? [1] https://news.ycombinator.com/item?id=11063700 https://news.ycombinator.com/item?id=11063700
- cfallin 11y agoOne thing that comes to mind is that GCC's version could have a bit more overhead due to ESP-folding [0]. Basically, reading ESP/RSP directly can incur some overhead, because the register renamer is playing tricks to avoid actually adjusting the stack pointer on every push/pop until you actually read the stack pointer's value. It's unclear here why GCC chose RSP over some other register. [0] the only reference I could find at the moment, but I've seen it documented elsewhere too: http://homepage.ntlworld.com/jonathan.deboynepollard/FGA/function-perilogues.html http://homepage.ntlworld.com/jonathan.deboynepollard/FGA/fun...