From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (qmail 12644 invoked by alias); 4 Nov 2008 22:31:16 -0000 Received: (qmail 12566 invoked by uid 22791); 4 Nov 2008 22:31:15 -0000 X-Spam-Check-By: sourceware.org Received: from mail.codesourcery.com (HELO mail.codesourcery.com) (65.74.133.4) by sourceware.org (qpsmtpd/0.31) with ESMTP; Tue, 04 Nov 2008 22:30:21 +0000 Received: (qmail 24551 invoked from network); 4 Nov 2008 22:30:19 -0000 Received: from unknown (HELO orlando.local) (pedro@127.0.0.2) by mail.codesourcery.com with ESMTPA; 4 Nov 2008 22:30:19 -0000 From: Pedro Alves To: gdb-patches@sourceware.org Subject: Re: [PATCH 1/4] 'catch syscall' feature -- =?utf-8?q?=09Architecture-independent=09part?= Date: Tue, 04 Nov 2008 22:31:00 -0000 User-Agent: KMail/1.9.10 Cc: Thiago Jung Bauermann , Eli Zaretskii , =?utf-8?q?S=C3=A9rgio_Durigan_J=C3=BAnior?= References: <1225773079.24532.52.camel@miki> <1225836687.20764.21.camel@localhost.localdomain> In-Reply-To: <1225836687.20764.21.camel@localhost.localdomain> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Content-Disposition: inline Message-Id: <200811042230.27666.pedro@codesourcery.com> X-IsSubscribed: yes Mailing-List: contact gdb-patches-help@sourceware.org; run by ezmlm Precedence: bulk List-Id: List-Subscribe: List-Archive: List-Post: List-Help: , Sender: gdb-patches-owner@sourceware.org X-SW-Source: 2008-11/txt/msg00062.txt.bz2 On Tuesday 04 November 2008 22:11:27, Thiago Jung Bauermann wrote: > El mar, 04-11-2008 a las 23:12 +0200, Eli Zaretskii escribi=C3=B3: > > Who said that a syscall is necessarily defined by some number? >=20 > I assumed every OS used numbers to define syscalls ... >=20 > > More generally, let's say I'd like to implement support for this on > > Windows -- how would I need to go about it? >=20 > ... but from what you are saying it seems that in Windows it's > different. What's the proper datatype to represent a syscall there? Depends on what you're calling a syscall on Windows. If talking about userland->kernel calls, similarly to this new feature, an integer. http://www.metasploit.com/users/opcode/syscalls.html http://www.codeguru.com/cpp/w-p/system/devicedriverdevelopment/article.php= /c8035 strace-like tracers on Windows are usually more interested in tracing calls to all kinds of dlls, and they usually do so by playing games with the import tables, I believe. --=20 Pedro Alves