36 ms·
That makes sense, as you're fucked by any false positive. If it's a graph of potential stacks, though, wouldn't you eventually find the one that unwinds, if on
by jsolson 3y ago
That makes sense, as you're fucked by any false positive.
If it's a graph of potential stacks, though, wouldn't you eventually find the one that unwinds, if one exists?
- loeg 3y agoGP mentioned in another comment that they don't actually follow the algorithm described by userbinator -- checking the return address for a preceding call -- which would increase the number of false positives a lot.
- haileys 3y agoThe thing that makes this tricky is that x86 is a variable length instruction set: you don't know where the preceding call instruction might begin, and you can't decode backwards. You can do it speculatively, but ambiguities are still possible.
- ghusbands 3y agoGiven that the full technique apparently works well for userbinator, we can assume that this isn't a very significant issue. The chances of a phantom call instruction will be pretty low, and there's a fairly low maximum instruction length.
- loeg 3y agoYes, but checking for valid CALL instructions is probably sufficiently accurate.