0Pricing
Reverse Engineering & Binary Analysis Basics · درس

المكدس واتفاقيات استدعاء الدوال

تعمّق في كيفية تمرير الدوال للوسائط وإرجاع القيم وإدارة إطار المكدس، وهي معرفة تجعل قراءة الشيفرة المفككة ممكنة.

المكدس واتفاقيات استدعاء الدوال درس مجاني في Reverse Engineering & Binary Analysis Basics على CoddyKit. هذا هو الدرس 4 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في Reverse Engineering & Binary Analysis Basics، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة Reverse Engineering & Binary Analysis Basics 4 دروس في المجموع.

بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.

Beyond a Single Call

You can read basic x86/x64 instructions and follow control flow. To truly understand function calls you must know the stack and calling conventions.

These rules govern how arguments arrive and how cleanup happens.

What the Stack Is

The stack is a region of memory that grows downward (toward lower addresses). It stores return addresses, saved registers, and local variables.

  • push decrements RSP and writes
  • pop reads and increments RSP
push rax   ; rsp -= 8, [rsp] = rax
pop  rbx   ; rbx = [rsp], rsp += 8

RSP and RBP

Two registers track the stack:

  • RSP (stack pointer) points to the current top
  • RBP (base pointer) anchors the current frame

Locals are addressed relative to RBP, like [rbp-8].

The Function Prologue

Most functions begin with a prologue that sets up the frame: save the old base pointer, then point RBP at the new frame.

push rbp
mov  rbp, rsp
sub  rsp, 0x20   ; reserve 32 bytes for locals

The Function Epilogue

The epilogue reverses the prologue, restoring the caller's frame before returning.

mov rsp, rbp
pop rbp
ret

Calling Conventions

A calling convention is the contract for passing arguments and returning values.

  • Where arguments go (registers or stack)
  • Who cleans up the stack
  • Which registers must be preserved

System V AMD64 (Linux x64)

On Linux x64 the first six integer arguments go in registers: rdi, rsi, rdx, rcx, r8, r9. The return value comes back in rax.

Extra arguments spill onto the stack.

; foo(1, 2, 3)
mov edi, 1
mov esi, 2
mov edx, 3
call foo

Microsoft x64 Convention

Windows x64 uses different registers: the first four arguments go in rcx, rdx, r8, r9, and the caller reserves 32 bytes of shadow space.

Recognizing the OS tells you which mapping to apply when reading arguments.

; Windows: bar(a, b)
mov rcx, a
mov rdx, b
sub rsp, 0x28   ; shadow space + alignment
call bar

Caller-Saved vs Callee-Saved

Some registers may be clobbered by a call (caller-saved), others must be preserved (callee-saved).

Seeing a function push rbx, rbp, and r12-r15 in its prologue is a strong hint about which registers it intends to use.

Reading Arguments in Practice

When you land in a function, mapping registers to arguments lets you label them. If the code reads rdi first on Linux, that is argument one.

This is how raw disassembly becomes readable pseudocode like send(sock, buf, len).

Stack-Passed Arguments

When a function has more arguments than the convention allows in registers, the extras are pushed onto the stack by the caller. The callee reads them at positive offsets from RBP, like [rbp+0x10].

Spotting these accesses helps you recover the full argument list.

; 7th System V argument
mov rax, [rbp+0x10]

Quick Check

Under the System V AMD64 convention, which register holds the FIRST integer argument?

Recap

You can now decode function calls at the metal level:

  • Stack grows down; RSP tops it, RBP anchors the frame
  • Prologue/epilogue set up and tear down frames
  • Calling conventions map registers to arguments (System V vs Microsoft x64)

This turns opaque disassembly into recognizable function signatures.

الأسئلة الشائعة

هل درس «المكدس واتفاقيات استدعاء الدوال» مجاني؟

نعم — نص درس «المكدس واتفاقيات استدعاء الدوال» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة Reverse Engineering & Binary Analysis Basics، انتقل إلى CoddyKit PRO. تتضمن دورة Reverse Engineering & Binary Analysis Basics 4 دروس في المجموع.

ماذا ستتعلم في «المكدس واتفاقيات استدعاء الدوال»؟

تعمّق في كيفية تمرير الدوال للوسائط وإرجاع القيم وإدارة إطار المكدس، وهي معرفة تجعل قراءة الشيفرة المفككة ممكنة. تتمرن على Reverse Engineering & Binary Analysis Basics مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.

هل أحتاج إلى خبرة سابقة لأبدأ Reverse Engineering & Binary Analysis Basics؟

لا تُشترط خبرة سابقة. Reverse Engineering & Binary Analysis Basics على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 4 من أصل 4.

كم من الوقت يستغرق درس «المكدس واتفاقيات استدعاء الدوال»؟

معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.

هل يمكنني كتابة وتشغيل أكواد في درس Reverse Engineering & Binary Analysis Basics هذا؟

نعم. كل درس في Reverse Engineering & Binary Analysis Basics يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.

جميع الدروس في هذه الدورة

  1. أساسيات Assembly لـ x86/x64
  2. السجلات وعمليات الذاكرة
  3. تدفق التحكم واستدعاءات الدوال
  4. المكدس واتفاقيات استدعاء الدوال
← العودة إلى Reverse Engineering & Binary Analysis Basics