{"doc_urls":["intro.html#notes","tools/index.html#tools","tools/zsh.html#zsh1","tools/zsh.html#keybindings","tools/zsh.html#parameter","tools/zsh.html#variables","tools/zsh.html#expansion-flags","tools/zsh.html#argument-parsing-with-zparseopts","tools/zsh.html#example","tools/zsh.html#regular-expressions","tools/zsh.html#completion","tools/zsh.html#installation","tools/zsh.html#completion-variables","tools/zsh.html#completion-functions","tools/zsh.html#example","tools/bash.html#bash1","tools/bash.html#expansion","tools/bash.html#generator","tools/bash.html#parameter","tools/bash.html#pathname","tools/bash.html#io-redirection","tools/bash.html#explanation","tools/bash.html#argument-parsing-with-getopts","tools/bash.html#example","tools/bash.html#regular-expressions","tools/bash.html#completion","tools/bash.html#example","tools/fish.html#fish1","tools/fish.html#quick-info","tools/fish.html#variables","tools/fish.html#setunset-variables","tools/fish.html#lists","tools/fish.html#special-variables-lists","tools/fish.html#command-handling","tools/fish.html#io-redirection","tools/fish.html#control-flow","tools/fish.html#if--else","tools/fish.html#switch","tools/fish.html#while-loop","tools/fish.html#for-loop","tools/fish.html#functions","tools/fish.html#autoloading","tools/fish.html#helper","tools/fish.html#prompt","tools/fish.html#useful-builtins","tools/fish.html#keymaps","tools/fish.html#debug","tools/tmux.html#tmux1","tools/tmux.html#tmux-cli","tools/tmux.html#scripting","tools/tmux.html#bindings","tools/tmux.html#command-mode","tools/git.html#git1","tools/git.html#staging","tools/git.html#remote","tools/git.html#branching","tools/git.html#tags","tools/git.html#log--commit-history","tools/git.html#diff--commit-info","tools/git.html#patching","tools/git.html#resetting","tools/git.html#submodules","tools/git.html#inspection","tools/git.html#revision-specifier","tools/awk.html#awk1","tools/awk.html#input-processing","tools/awk.html#program","tools/awk.html#special-pattern","tools/awk.html#special-variables","tools/awk.html#special-statements--functions","tools/awk.html#examples","tools/awk.html#filter-records","tools/awk.html#access-last-fields-in-records","tools/awk.html#capture-in-variables","tools/awk.html#run-shell-command-and-capture-output","tools/emacs.html#emacs1","tools/emacs.html#help","tools/emacs.html#package-manager","tools/emacs.html#window","tools/emacs.html#buffer","tools/emacs.html#ibuffer","tools/emacs.html#isearch","tools/emacs.html#occur","tools/emacs.html#grep","tools/emacs.html#yankpaste","tools/emacs.html#register","tools/emacs.html#blockrect","tools/emacs.html#mass-edit","tools/emacs.html#narrow","tools/emacs.html#org","tools/emacs.html#org-source","tools/emacs.html#comapny","tools/emacs.html#tags","tools/emacs.html#lisp","tools/emacs.html#ido","tools/emacs.html#evil","tools/emacs.html#dired","tools/gpg.html#gpg1","tools/gpg.html#generate-new-keypair","tools/gpg.html#list-keys","tools/gpg.html#edit-keys","tools/gpg.html#export--import-keys","tools/gpg.html#search--send-keys","tools/gpg.html#encrypt-passphrase","tools/gpg.html#encrypt-public-key","tools/gpg.html#signing","tools/gpg.html#signing-detached","tools/gpg.html#abbreviations","tools/gpg.html#keyservers","tools/gdb.html#gdb1","tools/gdb.html#cli","tools/gdb.html#interactive-usage","tools/gdb.html#misc","tools/gdb.html#breakpoints","tools/gdb.html#inspection","tools/gdb.html#signal-handling","tools/gdb.html#source-file-locations","tools/gdb.html#configuration","tools/gdb.html#user-commands-macros","tools/gdb.html#hooks","tools/gdb.html#examples","tools/gdb.html#automatically-print-next-instr","tools/gdb.html#conditional-breakpoints","tools/gdb.html#catch-sigsegv-and-execute-commands","tools/gdb.html#run-backtrace-on-thread-1-batch-mode","tools/gdb.html#script-gdb-for-automating-debugging-sessions","tools/gdb.html#know-bugs","tools/gdb.html#workaround-command--finish-bug","tools/radare2.html#radare21","tools/radare2.html#print","tools/radare2.html#flags","tools/radare2.html#help","tools/radare2.html#relocation","tools/qemu.html#qemu1","tools/qemu.html#keybindings","tools/qemu.html#vm-config-snippet","tools/qemu.html#cpu--ram","tools/qemu.html#graphic--display","tools/qemu.html#boot-menu","tools/qemu.html#block-devices","tools/qemu.html#usb","tools/qemu.html#debugging","tools/qemu.html#io-redirection","tools/qemu.html#network","tools/qemu.html#shared-drives","tools/qemu.html#tracing","tools/qemu.html#vm-snapshots","tools/qemu.html#appendix-direct-kernel-boot","tools/qemu.html#references","monitor/index.html#resource-analysis--monitor","monitor/lsof.html#lsof8","monitor/lsof.html#examples","monitor/lsof.html#file-flags","monitor/lsof.html#open-tcp-connections","monitor/lsof.html#open-connection-to-specific-host","monitor/lsof.html#open-connection-to-specific-port","monitor/lsof.html#ipv4-tcp-connections-in-established-state","monitor/ss.html#ss8","monitor/ss.html#examples","monitor/pidstat.html#pidstat1","monitor/pidstat.html#page-fault-and-memory-utilization","monitor/pidstat.html#io-statistics","monitor/pgrep.html#pgrep1","monitor/pgrep.html#debug-newest-process","monitor/pmap.html#pmap1","monitor/pstack.html#pstack1","trace_profile/index.html#trace-and-profile","trace_profile/strace.html#strace1","trace_profile/strace.html#examples","trace_profile/ltrace.html#ltrace1","trace_profile/ltrace.html#example","trace_profile/perf.html#perf1","trace_profile/perf.html#flamegraph","trace_profile/perf.html#flamegraph-with-single-event-trace","trace_profile/perf.html#flamegraph-with-multiple-event-traces","trace_profile/oprofile.html#oprofile","trace_profile/time.html#usrbintime1","binary/index.html#binary","binary/od.html#od1","binary/od.html#ascii-to-hex-string","binary/od.html#extract-parts-of-file","binary/xxd.html#xxd1","binary/xxd.html#ascii-to-hex-stream","binary/xxd.html#hex-to-binary-stream","binary/xxd.html#ascii-to-binary","binary/xxd.html#ascii-to-c-array-hex-encoded","binary/readelf.html#readelf1","binary/objdump.html#objdump1","binary/objdump.html#disassemble-section","binary/nm.html#nm1","development/index.html#development","development/c++filt.html#cfilt1","development/c++filt.html#demangle-symbol","development/c++filt.html#demangle-stream","development/c++.html#c","development/c++.html#type-deduction","development/glibc.html#glibc","development/glibc.html#malloc-tracer--mtrace3","development/glibc.html#malloc-check--mallopt3","development/gcc.html#gcc1","development/gcc.html#cli","development/gcc.html#preprocessing","development/gcc.html#builtins","development/gcc.html#__builtin_expectexpr-cond","development/gcc.html#abi-linux","development/make.html#make1","development/make.html#anatomy-of-make-rules","development/make.html#pattern-rules--automatic-variables","development/make.html#pattern-rules","development/make.html#automatic-variables","development/make.html#useful-functions","development/make.html#substitution-references","development/make.html#filter","development/make.html#filter-out","development/make.html#abspath","development/ld.so.html#ldso8","development/ld.so.html#environment-variables","development/ld.so.html#ld_preload-initialization-order-and-link-map","development/ld.so.html#dynamic-linking-x86_64","arch/index.html#arch","arch/x86_64.html#x86_64","arch/x86_64.html#registers","arch/x86_64.html#general-purpose-register","arch/x86_64.html#special-register","arch/x86_64.html#flags-register","arch/x86_64.html#model-specific-register-msr","arch/x86_64.html#size-directives","arch/x86_64.html#addressing","arch/x86_64.html#string-instructions","arch/x86_64.html#example-simple-memset","arch/x86_64.html#sysv-x86_64-abi","arch/x86_64.html#passing-arguments-to-functions","arch/x86_64.html#return-values-from-functions","arch/x86_64.html#caller-saved-registers","arch/x86_64.html#callee-saved-registers","arch/x86_64.html#stack","arch/x86_64.html#function-prologue--epilogue","arch/x86_64.html#asm-skeleton","arch/x86_64.html#references","arch/arm64.html#arm64","arch/arm64.html#registers","arch/arm64.html#general-purpose-registers","arch/arm64.html#special-registers-per-el","arch/arm64.html#instructions-cheatsheet","arch/arm64.html#accessing-system-registers","arch/arm64.html#control-flow","arch/arm64.html#addressing","arch/arm64.html#offset","arch/arm64.html#index","arch/arm64.html#pair-access","arch/arm64.html#procedure-call-standard-arm64--aapcs64-","arch/arm64.html#passing-arguments-to-functions","arch/arm64.html#return-values-from-functions","arch/arm64.html#callee-saved-registers","arch/arm64.html#stack","arch/arm64.html#frame-chain","arch/arm64.html#function-prologue--epilogue","arch/arm64.html#asm-skeleton","arch/arm64.html#references","arch/armv7.html#armv7a","arch/armv7.html#registers","arch/armv7.html#general-purpose-registers","arch/armv7.html#special-registers","arch/armv7.html#cpsr-register","arch/armv7.html#instructions-cheatsheet","arch/armv7.html#accessing-system-registers","arch/armv7.html#control-flow","arch/armv7.html#loadstore","arch/armv7.html#procedure-call-standard-arm--aapcs32-","arch/armv7.html#passing-arguments-to-functions","arch/armv7.html#return-values-from-functions","arch/armv7.html#callee-saved-registers","arch/armv7.html#stack","arch/armv7.html#frame-chain","arch/armv7.html#function-prologue--epilogue","arch/armv7.html#asm-skeleton","arch/armv7.html#references"],"index":{"documentStore":{"docInfo":{"0":{"body":8,"breadcrumbs":1,"title":1},"1":{"body":11,"breadcrumbs":1,"title":1},"10":{"body":0,"breadcrumbs":2,"title":1},"100":{"body":55,"breadcrumbs":3,"title":2},"101":{"body":10,"breadcrumbs":4,"title":3},"102":{"body":14,"breadcrumbs":4,"title":3},"103":{"body":19,"breadcrumbs":3,"title":2},"104":{"body":26,"breadcrumbs":4,"title":3},"105":{"body":46,"breadcrumbs":2,"title":1},"106":{"body":32,"breadcrumbs":3,"title":2},"107":{"body":12,"breadcrumbs":2,"title":1},"108":{"body":3,"breadcrumbs":2,"title":1},"109":{"body":0,"breadcrumbs":2,"title":1},"11":{"body":36,"breadcrumbs":2,"title":1},"110":{"body":42,"breadcrumbs":2,"title":1},"111":{"body":0,"breadcrumbs":3,"title":2},"112":{"body":66,"breadcrumbs":2,"title":1},"113":{"body":103,"breadcrumbs":2,"title":1},"114":{"body":22,"breadcrumbs":2,"title":1},"115":{"body":42,"breadcrumbs":3,"title":2},"116":{"body":33,"breadcrumbs":4,"title":3},"117":{"body":72,"breadcrumbs":2,"title":1},"118":{"body":25,"breadcrumbs":4,"title":3},"119":{"body":24,"breadcrumbs":2,"title":1},"12":{"body":25,"breadcrumbs":3,"title":2},"120":{"body":0,"breadcrumbs":2,"title":1},"121":{"body":24,"breadcrumbs":5,"title":4},"122":{"body":25,"breadcrumbs":3,"title":2},"123":{"body":13,"breadcrumbs":5,"title":4},"124":{"body":9,"breadcrumbs":7,"title":6},"125":{"body":36,"breadcrumbs":6,"title":5},"126":{"body":0,"breadcrumbs":3,"title":2},"127":{"body":27,"breadcrumbs":5,"title":4},"128":{"body":0,"breadcrumbs":2,"title":1},"129":{"body":11,"breadcrumbs":2,"title":1},"13":{"body":89,"breadcrumbs":3,"title":2},"130":{"body":16,"breadcrumbs":2,"title":1},"131":{"body":9,"breadcrumbs":2,"title":1},"132":{"body":15,"breadcrumbs":2,"title":1},"133":{"body":11,"breadcrumbs":2,"title":1},"134":{"body":31,"breadcrumbs":2,"title":1},"135":{"body":37,"breadcrumbs":4,"title":3},"136":{"body":40,"breadcrumbs":3,"title":2},"137":{"body":30,"breadcrumbs":3,"title":2},"138":{"body":10,"breadcrumbs":3,"title":2},"139":{"body":105,"breadcrumbs":3,"title":2},"14":{"body":77,"breadcrumbs":2,"title":1},"140":{"body":41,"breadcrumbs":2,"title":1},"141":{"body":18,"breadcrumbs":2,"title":1},"142":{"body":48,"breadcrumbs":3,"title":2},"143":{"body":11,"breadcrumbs":2,"title":1},"144":{"body":22,"breadcrumbs":3,"title":2},"145":{"body":32,"breadcrumbs":2,"title":1},"146":{"body":44,"breadcrumbs":3,"title":2},"147":{"body":30,"breadcrumbs":5,"title":4},"148":{"body":22,"breadcrumbs":2,"title":1},"149":{"body":6,"breadcrumbs":3,"title":3},"15":{"body":0,"breadcrumbs":2,"title":1},"150":{"body":102,"breadcrumbs":4,"title":1},"151":{"body":0,"breadcrumbs":4,"title":1},"152":{"body":10,"breadcrumbs":5,"title":2},"153":{"body":21,"breadcrumbs":6,"title":3},"154":{"body":9,"breadcrumbs":7,"title":4},"155":{"body":10,"breadcrumbs":7,"title":4},"156":{"body":4,"breadcrumbs":8,"title":5},"157":{"body":52,"breadcrumbs":4,"title":1},"158":{"body":28,"breadcrumbs":4,"title":1},"159":{"body":26,"breadcrumbs":4,"title":1},"16":{"body":0,"breadcrumbs":2,"title":1},"160":{"body":50,"breadcrumbs":7,"title":4},"161":{"body":6,"breadcrumbs":5,"title":2},"162":{"body":22,"breadcrumbs":4,"title":1},"163":{"body":14,"breadcrumbs":6,"title":3},"164":{"body":12,"breadcrumbs":4,"title":1},"165":{"body":6,"breadcrumbs":4,"title":1},"166":{"body":5,"breadcrumbs":2,"title":2},"167":{"body":70,"breadcrumbs":3,"title":1},"168":{"body":25,"breadcrumbs":3,"title":1},"169":{"body":27,"breadcrumbs":3,"title":1},"17":{"body":16,"breadcrumbs":2,"title":1},"170":{"body":11,"breadcrumbs":3,"title":1},"171":{"body":128,"breadcrumbs":3,"title":1},"172":{"body":0,"breadcrumbs":3,"title":1},"173":{"body":15,"breadcrumbs":6,"title":4},"174":{"body":17,"breadcrumbs":6,"title":4},"175":{"body":43,"breadcrumbs":3,"title":1},"176":{"body":6,"breadcrumbs":3,"title":1},"177":{"body":5,"breadcrumbs":1,"title":1},"178":{"body":45,"breadcrumbs":2,"title":1},"179":{"body":34,"breadcrumbs":4,"title":3},"18":{"body":69,"breadcrumbs":2,"title":1},"180":{"body":76,"breadcrumbs":4,"title":3},"181":{"body":19,"breadcrumbs":2,"title":1},"182":{"body":6,"breadcrumbs":4,"title":3},"183":{"body":7,"breadcrumbs":4,"title":3},"184":{"body":11,"breadcrumbs":3,"title":2},"185":{"body":15,"breadcrumbs":6,"title":5},"186":{"body":55,"breadcrumbs":2,"title":1},"187":{"body":36,"breadcrumbs":2,"title":1},"188":{"body":8,"breadcrumbs":3,"title":2},"189":{"body":7,"breadcrumbs":2,"title":1},"19":{"body":93,"breadcrumbs":2,"title":1},"190":{"body":7,"breadcrumbs":1,"title":1},"191":{"body":0,"breadcrumbs":2,"title":1},"192":{"body":3,"breadcrumbs":3,"title":2},"193":{"body":10,"breadcrumbs":3,"title":2},"194":{"body":0,"breadcrumbs":2,"title":1},"195":{"body":14,"breadcrumbs":3,"title":2},"196":{"body":0,"breadcrumbs":2,"title":1},"197":{"body":62,"breadcrumbs":4,"title":3},"198":{"body":34,"breadcrumbs":4,"title":3},"199":{"body":0,"breadcrumbs":2,"title":1},"2":{"body":0,"breadcrumbs":2,"title":1},"20":{"body":24,"breadcrumbs":3,"title":2},"200":{"body":0,"breadcrumbs":2,"title":1},"201":{"body":15,"breadcrumbs":2,"title":1},"202":{"body":0,"breadcrumbs":2,"title":1},"203":{"body":90,"breadcrumbs":3,"title":2},"204":{"body":9,"breadcrumbs":3,"title":2},"205":{"body":0,"breadcrumbs":2,"title":1},"206":{"body":27,"breadcrumbs":4,"title":3},"207":{"body":0,"breadcrumbs":5,"title":4},"208":{"body":36,"breadcrumbs":3,"title":2},"209":{"body":68,"breadcrumbs":3,"title":2},"21":{"body":26,"breadcrumbs":2,"title":1},"210":{"body":0,"breadcrumbs":3,"title":2},"211":{"body":14,"breadcrumbs":3,"title":2},"212":{"body":16,"breadcrumbs":2,"title":1},"213":{"body":17,"breadcrumbs":3,"title":2},"214":{"body":23,"breadcrumbs":2,"title":1},"215":{"body":0,"breadcrumbs":2,"title":1},"216":{"body":38,"breadcrumbs":3,"title":2},"217":{"body":128,"breadcrumbs":6,"title":5},"218":{"body":246,"breadcrumbs":4,"title":3},"219":{"body":3,"breadcrumbs":1,"title":1},"22":{"body":64,"breadcrumbs":4,"title":3},"220":{"body":21,"breadcrumbs":2,"title":1},"221":{"body":0,"breadcrumbs":2,"title":1},"222":{"body":62,"breadcrumbs":4,"title":3},"223":{"body":15,"breadcrumbs":3,"title":2},"224":{"body":95,"breadcrumbs":3,"title":2},"225":{"body":14,"breadcrumbs":5,"title":4},"226":{"body":40,"breadcrumbs":3,"title":2},"227":{"body":40,"breadcrumbs":2,"title":1},"228":{"body":116,"breadcrumbs":3,"title":2},"229":{"body":17,"breadcrumbs":4,"title":3},"23":{"body":35,"breadcrumbs":2,"title":1},"230":{"body":0,"breadcrumbs":4,"title":3},"231":{"body":40,"breadcrumbs":4,"title":3},"232":{"body":23,"breadcrumbs":4,"title":3},"233":{"body":14,"breadcrumbs":4,"title":3},"234":{"body":15,"breadcrumbs":4,"title":3},"235":{"body":29,"breadcrumbs":2,"title":1},"236":{"body":31,"breadcrumbs":4,"title":3},"237":{"body":94,"breadcrumbs":3,"title":2},"238":{"body":47,"breadcrumbs":2,"title":1},"239":{"body":14,"breadcrumbs":2,"title":1},"24":{"body":58,"breadcrumbs":3,"title":2},"240":{"body":0,"breadcrumbs":2,"title":1},"241":{"body":40,"breadcrumbs":4,"title":3},"242":{"body":52,"breadcrumbs":5,"title":4},"243":{"body":0,"breadcrumbs":3,"title":2},"244":{"body":18,"breadcrumbs":4,"title":3},"245":{"body":38,"breadcrumbs":3,"title":2},"246":{"body":0,"breadcrumbs":2,"title":1},"247":{"body":47,"breadcrumbs":2,"title":1},"248":{"body":18,"breadcrumbs":2,"title":1},"249":{"body":18,"breadcrumbs":3,"title":2},"25":{"body":123,"breadcrumbs":2,"title":1},"250":{"body":0,"breadcrumbs":6,"title":5},"251":{"body":35,"breadcrumbs":4,"title":3},"252":{"body":8,"breadcrumbs":4,"title":3},"253":{"body":3,"breadcrumbs":4,"title":3},"254":{"body":27,"breadcrumbs":2,"title":1},"255":{"body":52,"breadcrumbs":3,"title":2},"256":{"body":36,"breadcrumbs":4,"title":3},"257":{"body":141,"breadcrumbs":3,"title":2},"258":{"body":27,"breadcrumbs":2,"title":1},"259":{"body":10,"breadcrumbs":2,"title":1},"26":{"body":66,"breadcrumbs":2,"title":1},"260":{"body":0,"breadcrumbs":2,"title":1},"261":{"body":23,"breadcrumbs":4,"title":3},"262":{"body":8,"breadcrumbs":3,"title":2},"263":{"body":55,"breadcrumbs":3,"title":2},"264":{"body":0,"breadcrumbs":3,"title":2},"265":{"body":18,"breadcrumbs":4,"title":3},"266":{"body":50,"breadcrumbs":3,"title":2},"267":{"body":79,"breadcrumbs":2,"title":1},"268":{"body":0,"breadcrumbs":6,"title":5},"269":{"body":44,"breadcrumbs":4,"title":3},"27":{"body":0,"breadcrumbs":2,"title":1},"270":{"body":11,"breadcrumbs":4,"title":3},"271":{"body":3,"breadcrumbs":4,"title":3},"272":{"body":26,"breadcrumbs":2,"title":1},"273":{"body":65,"breadcrumbs":3,"title":2},"274":{"body":19,"breadcrumbs":4,"title":3},"275":{"body":165,"breadcrumbs":3,"title":2},"276":{"body":21,"breadcrumbs":2,"title":1},"28":{"body":19,"breadcrumbs":3,"title":2},"29":{"body":19,"breadcrumbs":2,"title":1},"3":{"body":96,"breadcrumbs":2,"title":1},"30":{"body":25,"breadcrumbs":3,"title":2},"31":{"body":51,"breadcrumbs":2,"title":1},"32":{"body":39,"breadcrumbs":4,"title":3},"33":{"body":8,"breadcrumbs":3,"title":2},"34":{"body":8,"breadcrumbs":3,"title":2},"35":{"body":0,"breadcrumbs":3,"title":2},"36":{"body":10,"breadcrumbs":1,"title":0},"37":{"body":14,"breadcrumbs":2,"title":1},"38":{"body":4,"breadcrumbs":2,"title":1},"39":{"body":5,"breadcrumbs":2,"title":1},"4":{"body":88,"breadcrumbs":2,"title":1},"40":{"body":11,"breadcrumbs":2,"title":1},"41":{"body":24,"breadcrumbs":2,"title":1},"42":{"body":24,"breadcrumbs":2,"title":1},"43":{"body":19,"breadcrumbs":2,"title":1},"44":{"body":24,"breadcrumbs":3,"title":2},"45":{"body":28,"breadcrumbs":2,"title":1},"46":{"body":19,"breadcrumbs":2,"title":1},"47":{"body":19,"breadcrumbs":2,"title":1},"48":{"body":86,"breadcrumbs":3,"title":2},"49":{"body":119,"breadcrumbs":2,"title":1},"5":{"body":79,"breadcrumbs":2,"title":1},"50":{"body":128,"breadcrumbs":2,"title":1},"51":{"body":24,"breadcrumbs":3,"title":2},"52":{"body":0,"breadcrumbs":2,"title":1},"53":{"body":7,"breadcrumbs":2,"title":1},"54":{"body":21,"breadcrumbs":2,"title":1},"55":{"body":77,"breadcrumbs":2,"title":1},"56":{"body":45,"breadcrumbs":2,"title":1},"57":{"body":46,"breadcrumbs":4,"title":3},"58":{"body":51,"breadcrumbs":4,"title":3},"59":{"body":109,"breadcrumbs":2,"title":1},"6":{"body":51,"breadcrumbs":3,"title":2},"60":{"body":50,"breadcrumbs":2,"title":1},"61":{"body":64,"breadcrumbs":2,"title":1},"62":{"body":27,"breadcrumbs":2,"title":1},"63":{"body":28,"breadcrumbs":3,"title":2},"64":{"body":18,"breadcrumbs":2,"title":1},"65":{"body":45,"breadcrumbs":3,"title":2},"66":{"body":37,"breadcrumbs":2,"title":1},"67":{"body":29,"breadcrumbs":3,"title":2},"68":{"body":29,"breadcrumbs":3,"title":2},"69":{"body":86,"breadcrumbs":4,"title":3},"7":{"body":48,"breadcrumbs":4,"title":3},"70":{"body":0,"breadcrumbs":2,"title":1},"71":{"body":18,"breadcrumbs":3,"title":2},"72":{"body":19,"breadcrumbs":5,"title":4},"73":{"body":39,"breadcrumbs":3,"title":2},"74":{"body":25,"breadcrumbs":6,"title":5},"75":{"body":0,"breadcrumbs":2,"title":1},"76":{"body":74,"breadcrumbs":2,"title":1},"77":{"body":21,"breadcrumbs":3,"title":2},"78":{"body":40,"breadcrumbs":2,"title":1},"79":{"body":50,"breadcrumbs":2,"title":1},"8":{"body":40,"breadcrumbs":2,"title":1},"80":{"body":77,"breadcrumbs":2,"title":1},"81":{"body":57,"breadcrumbs":2,"title":1},"82":{"body":51,"breadcrumbs":2,"title":1},"83":{"body":24,"breadcrumbs":2,"title":1},"84":{"body":43,"breadcrumbs":2,"title":1},"85":{"body":24,"breadcrumbs":2,"title":1},"86":{"body":19,"breadcrumbs":2,"title":1},"87":{"body":32,"breadcrumbs":3,"title":2},"88":{"body":22,"breadcrumbs":2,"title":1},"89":{"body":39,"breadcrumbs":2,"title":1},"9":{"body":46,"breadcrumbs":3,"title":2},"90":{"body":23,"breadcrumbs":3,"title":2},"91":{"body":26,"breadcrumbs":2,"title":1},"92":{"body":38,"breadcrumbs":2,"title":1},"93":{"body":49,"breadcrumbs":2,"title":1},"94":{"body":24,"breadcrumbs":2,"title":1},"95":{"body":28,"breadcrumbs":2,"title":1},"96":{"body":16,"breadcrumbs":2,"title":1},"97":{"body":21,"breadcrumbs":2,"title":1},"98":{"body":4,"breadcrumbs":4,"title":3},"99":{"body":13,"breadcrumbs":3,"title":2}},"docs":{"0":{"body":"A personal collection of notes and cheatsheets. Source code is located at johannst/notes .","breadcrumbs":"Notes","id":"0","title":"Notes"},"1":{"body":"zsh bash fish tmux git awk emacs gpg gdb radare2 qemu","breadcrumbs":"Tools","id":"1","title":"Tools"},"10":{"body":"","breadcrumbs":"Tools » Completion","id":"10","title":"Completion"},"100":{"body":"gpg --edit-key Gives prompt to modify KEY ID, common commands: help show help\nsave save & quit list list keys and user IDs\nkey select subkey \nuid select user ID expire change expiration of selected key adduid add user ID\ndeluid delete selected user ID addkey add subkey\ndelkey delete selected subkey","breadcrumbs":"Tools » Edit keys","id":"100","title":"Edit keys"},"101":{"body":"gpg --export --armor --output \ngpg --import ","breadcrumbs":"Tools » Export & Import Keys","id":"101","title":"Export & Import Keys"},"102":{"body":"gpg --keyserver --send-keys \ngpg --keyserver --search-keys ","breadcrumbs":"Tools » Search & Send keys","id":"102","title":"Search & Send keys"},"103":{"body":"Encrypt file using passphrase and write encrypted data to .gpg. gpg --symmetric # Decrypt using passphrase\ngpg -o --decrypt .gpg","breadcrumbs":"Tools » Encrypt (passphrase)","id":"103","title":"Encrypt (passphrase)"},"104":{"body":"Encrypt file with public key of specified recipient and write encrypted data to .gpg. gpg --encrypt -r foo@bar.de # Decrypt at foos side (private key required)\ngpg -o --decrypt .gpg","breadcrumbs":"Tools » Encrypt (public key)","id":"104","title":"Encrypt (public key)"},"105":{"body":"Generate a signed file and write to .gpg. gpg --sign -u foor@bar.de # Verify\ngpg --verify # Extract content from signed file\ngpg -o --decrypt .gpg Without -u use first private key in list gpg -K for signing. Files can also be signed and encrypted at once, gpg will first sign the file and then encrypt it. gpg --sign --encrypt ","breadcrumbs":"Tools » Signing","id":"105","title":"Signing"},"106":{"body":"Generate a detached signature and write to .asc. Send .asc along with when distributing. gpg --detach-sign --armor -u foor@bar.de # Verify\ngpg --verify .asc Without -u use first private key in list gpg -K for signing.","breadcrumbs":"Tools » Signing (detached)","id":"106","title":"Signing (detached)"},"107":{"body":"sec secret key ssb secret subkey pub public key sub public subkey","breadcrumbs":"Tools » Abbreviations","id":"107","title":"Abbreviations"},"108":{"body":"http://pgp.mit.edu http://keyserver.ubuntu.com hkps://pgp.mailbox.org","breadcrumbs":"Tools » Keyservers","id":"108","title":"Keyservers"},"109":{"body":"","breadcrumbs":"Tools » gdb(1)","id":"109","title":"gdb(1)"},"11":{"body":"Completion functions are provided via files and need to be placed in a location covered by $fpath. By convention the completion files are names as _. A completion skeleton for the command foo, stored in _foo #compdef _foo foo function _foo() { ...\n} Alternatively one can install a completion function explicitly by calling compdef .","breadcrumbs":"Tools » Installation","id":"11","title":"Installation"},"110":{"body":"gdb [opts] [prg [-c coredump | -p pid]] gdb [opts] --args prg opts: -p attach to pid -c use -x execute script before prompt -ex execute command before prompt --tty set I/O tty for debugee","breadcrumbs":"Tools » CLI","id":"110","title":"CLI"},"111":{"body":"","breadcrumbs":"Tools » Interactive usage","id":"111","title":"Interactive usage"},"112":{"body":"tty Set as tty for debugee. Make sure nobody reads from target tty, easiest is to spawn a shell and run following in target tty: > while true; do sleep 1024; done sharedlibrary [] Load symbols of shared libs loaded by debugee. Optionally use to filter libs for symbol loading. display [/FMT] Print every time debugee stops. Eg print next instr, see examples below. undisplay [] Delete display expressions either all or one referenced by . info display List display expressions.","breadcrumbs":"Tools » Misc","id":"112","title":"Misc"},"113":{"body":"break [-qualified] thread Set a breakpoint only for a specific thread. -qualified: Treat as fully qualified symbol (quiet handy to set breakpoints on C symbols in C++ contexts) break if Set conditional breakpoint (see examples below). delete [] Delete breakpoint either all or one referenced by . info break List breakpoints. cond Make existing breakpoint conditional with . tbreak Set temporary breakpoint, will be deleted when hit. Same syntax as `break`. rbreak Set breakpoints matching , where matching internally is done on: .*.* command [] Define commands to run after breakpoint hit. If is not specified attach command to last created breakpoint. Command block terminated with 'end' token. : Space separates list, eg 'command 2 5-8' to run command for breakpoints: 2,5,6,7,8.","breadcrumbs":"Tools » Breakpoints","id":"113","title":"Breakpoints"},"114":{"body":"info functions [] List functions matching . List all functions if no provided. info variables [] List variables matching . List all variables if no provided.","breadcrumbs":"Tools » Inspection","id":"114","title":"Inspection"},"115":{"body":"info handle [] Print how to handle . If no specified print for all signals. handle Configure how gdb handles sent to debugee. : stop/nostop Catch signal in gdb and break. print/noprint Print message when gdb catches signal. pass/nopass Pass signal down to debugee. catch signal Create a catchpoint for .","breadcrumbs":"Tools » Signal handling","id":"115","title":"Signal handling"},"116":{"body":"dir Add to the beginning of the searh path for source files. show dir Show current search path. set substitute-path Add substitution rule checked during source file lookup. show substitute-path Show current substitution rules.","breadcrumbs":"Tools » Source file locations","id":"116","title":"Source file locations"},"117":{"body":"set follow-fork-mode Specify which process to follow when debuggee makes a fork(2) syscall. set pagination Turn on/off gdb's pagination. set breakpoint pending on: always set pending breakpoints. off: error when trying to set pending breakpoints. auto: interatively query user to set breakpoint. set print pretty Turn on/off pertty printing of structures. set logging Enable output logging to file (default gdb.txt). set logging file Change output log file to set logging redirect on: only log to file. off: log to file and tty.","breadcrumbs":"Tools » Configuration","id":"117","title":"Configuration"},"118":{"body":"Gdb allows to create & document user commands as follows: define # cmds end document # docu end To get all user commands or documentations one can use: help user-defined help ","breadcrumbs":"Tools » User commands (macros)","id":"118","title":"User commands (macros)"},"119":{"body":"Gdb allows to create two types of command hooks hook- will be run before hookpost- will be run after define hook- # cmds end define hookpost- # cmds end","breadcrumbs":"Tools » Hooks","id":"119","title":"Hooks"},"12":{"body":"Following variables are available in Completion functions: $words # array with command line in words\n$#words # number words\n$CURRENT # index into $words for cursor position\n$words[CURRENT-1] # previous word (relative to cursor position)","breadcrumbs":"Tools » Completion Variables","id":"12","title":"Completion Variables"},"120":{"body":"","breadcrumbs":"Tools » Examples","id":"120","title":"Examples"},"121":{"body":"When ever the debugee stops automatically print the memory at the current instruction pointer ($rip x86) and format as instruction /i. # rip - x86 display /i $rip # step instruction, after the step the next instruction is automatically printed si","breadcrumbs":"Tools » Automatically print next instr","id":"121","title":"Automatically print next instr"},"122":{"body":"Create conditional breakpoints for a function void foo(int i) in the debugee. # Create conditional breakpoint b foo if i == 42 b foo # would create bp 2 # Make existing breakpoint conditional cond 2 if i == 7","breadcrumbs":"Tools » Conditional breakpoints","id":"122","title":"Conditional breakpoints"},"123":{"body":"This creates a catchpoint for the SIGSEGV signal and attached the command to it. catch signal SIGSEGV command bt c end","breadcrumbs":"Tools » Catch SIGSEGV and execute commands","id":"123","title":"Catch SIGSEGV and execute commands"},"124":{"body":"gdb --batch -ex 'thread 1' -ex 'bt' -p ","breadcrumbs":"Tools » Run backtrace on thread 1 (batch mode)","id":"124","title":"Run backtrace on thread 1 (batch mode)"},"125":{"body":"To script gdb add commands into a file and pass it to gdb via -x. For example create run.gdb: set pagination off break mmap command info reg rdi rsi rdx bt c end #initial drop c This script can be used as: gdb --batch -x ./run.gdb -p ","breadcrumbs":"Tools » Script gdb for automating debugging sessions","id":"125","title":"Script gdb for automating debugging sessions"},"126":{"body":"","breadcrumbs":"Tools » Know Bugs","id":"126","title":"Know Bugs"},"127":{"body":"When using finish inside a command block, commands after finish are not executed. To workaround that bug one can create a wrapper function which calls finish. define handler bt finish info reg rax end command handler end","breadcrumbs":"Tools » Workaround command + finish bug","id":"127","title":"Workaround command + finish bug"},"128":{"body":"","breadcrumbs":"Tools » radare2(1)","id":"128","title":"radare2(1)"},"129":{"body":"pd [@ ] # print disassembly for instructions # with optional temporary seek to ","breadcrumbs":"Tools » print","id":"129","title":"print"},"13":{"body":"_describe simple completion, just words + description _arguments sophisticated completion, allow to specify actions Completion with _describe _describe MSG COMP MSG simple string with header message COMP array of completions where each entry is \"opt:description\" function _foo() { local -a opts opts=('bla:desc for bla' 'blu:desc for blu') _describe 'foo-msg' opts\n}\ncompdef _foo foo foo -- foo-msg --\nbla -- desc for bla\nblu -- desc for blu Completion with _arguments _arguments SPEC [SPEC...] where SPEC can have one of the following forms: OPT[DESC]:MSG:ACTION N:MSG:ACTION Available actions (op1 op2) list possible matches\n->VAL set $state=VAL and continue, `$state` can be checked later in switch case\nFUNC call func to generate matches\n{STR} evaluate `STR` to generate matches","breadcrumbs":"Tools » Completion Functions","id":"13","title":"Completion Functions"},"130":{"body":"fs # list flag-spaces fs # select flag-space f # print flags of selected flag-space","breadcrumbs":"Tools » flags","id":"130","title":"flags"},"131":{"body":"?*~ # '?*' list all commands and '~' grep for ?*~... # '..' less mode /'...' interactive search","breadcrumbs":"Tools » help","id":"131","title":"help"},"132":{"body":"> r2 -B # open mapped to addr oob # reopen current file at ","breadcrumbs":"Tools » relocation","id":"132","title":"relocation"},"133":{"body":"All the examples & notes use qemu-system-x86_64 but in most cases this can be swapped with the system emulator for other architectures.","breadcrumbs":"Tools » qemu(1)","id":"133","title":"qemu(1)"},"134":{"body":"Graphic mode: Ctrl+Alt+g release mouse capture from VM Ctrl+Alt+1 switch to display of VM\nCtrl+Alt+2 switch to qemu monitor No graphic mode: Ctrl+a h print help\nCtrl+a x exit emulator\nCtrl+a c switch between monitor and console","breadcrumbs":"Tools » Keybindings","id":"134","title":"Keybindings"},"135":{"body":"Following command-line gives a good starting point to assemble a VM: qemu-system-x86_64 \\ -cpu host -enable-kvm -smp 4 \\ -m 8G \\ -vga virtio -display sdl,gl=on \\ -boot menu=on \\ -cdrom \\ -hda \\ -device qemu-xhci,id=xhci \\ -device usb-host,bus=xhci.0,vendorid=0x05e1,productid=0x0408,id=capture-card","breadcrumbs":"Tools » VM config snippet","id":"135","title":"VM config snippet"},"136":{"body":"# Emulate host CPU in guest VM, enabling all supported host featured (requires KVM).\n# List available CPUs `qemu-system-x86_64 -cpu help`.\n-cpu host # Enable KVM instead software emulation.\n-enable-kvm # Configure number of guest CPUs.\n-smp # Configure size of guest RAM.\n-m 8G","breadcrumbs":"Tools » CPU & RAM","id":"136","title":"CPU & RAM"},"137":{"body":"# Use sdl window as display and enable openGL context.\n-display sdl,gl=on # Use vnc server as display (eg on display `:42` here).\n-display vnc=localhost:42 # Confifure virtio as 3D video graphic accelerator (requires virgl in guest).\n-vga virtio","breadcrumbs":"Tools » Graphic & Display","id":"137","title":"Graphic & Display"},"138":{"body":"# Enables boot menu to select boot device (enter with `ESC`).\n-boot menu=on","breadcrumbs":"Tools » Boot Menu","id":"138","title":"Boot Menu"},"139":{"body":"# Attach cdrom drive with iso to a VM.\n-cdrom # Attach disk drive to a VM.\n-hda # Generic way to configure & attach a drive to a VM.\n-drive file=,format=qcow2 Create a disk with qemu-img To create a qcow2 disk (qemu copy-on-write) of size 10G: qemu-img create -f qcow2 disk.qcow2 10G The disk does not contain any partitions or a partition table. We can format the disk from within the guest as following example: # Create `gpt` partition table.\nsudo parted /dev/sda mktable gpt # Create two equally sized primary partitions.\nsudo parted /dev/sda mkpart primary 0% 50%\nsudo parted /dev/sda mkpart primary 50% 100% # Create filesystem on each partition.\nsudo mkfs.ext3 /dev/sda1\nsudo mkfs.ext4 /dev/sda2 lsblk -f /dev/sda NAME FSTYPE LABEL UUID FSAVAIL FSUSE% MOUNTPOINT sda ├─sda1 ext3 .... └─sda2 ext4 ....","breadcrumbs":"Tools » Block devices","id":"139","title":"Block devices"},"14":{"body":"Skeleton to copy/paste for writing simple completions. Assume a program foo with the following interface: foo -c green|red|blue -s low|high -f -d -h The completion handler could be implemented as follows in a file called _foo: #compdef _foo foo function _foo_color() { local colors=() colors+=('green:green color') colors+=('red:red color') colors+=('blue:blue color') _describe \"color\" colors\n} function _foo() { _arguments \\ \"-c[define color]:color:->s_color\" \\ \"-s[select sound]:sound:(low high)\" \\ \"-f[select file]:file:_files\" \\ \"-d[select dir]:dir:_files -/\" \\ \"-h[help]\" case $state in s_color) _foo_color;; esac\n} _files is a zsh builtin utility function to complete files/dirs see zsh completion functions zsh completion utility functions","breadcrumbs":"Tools » Example","id":"14","title":"Example"},"140":{"body":"Host Controller # Add XHCI USB controller to the VM (supports USB 3.0, 2.0, 1.1).\n# `id=xhci` creates a usb bus named `xhci`.\n-device qemu-xhci,id=xhci USB Device # Pass-through USB device from host identified by vendorid & productid and\n# attach to usb bus `xhci.0` (defined with controller `id`).\n-device usb-host,bus=xhci.0,vendorid=0x05e1,productid=0x0408","breadcrumbs":"Tools » USB","id":"140","title":"USB"},"141":{"body":"# Open gdbstub on tcp `` (`-s` shorthand for `-gdb tcp::1234`).\n-gdb tcp:: # Freeze guest CPU at startup and wait for debugger connection.\n-S","breadcrumbs":"Tools » Debugging","id":"141","title":"Debugging"},"142":{"body":"# Create raw tcp server for `serial IO` and wait until a client connects\n# before executing the guest.\n-serial tcp:localhost:12345,server,wait # Create telnet server for `serial IO` and wait until a client connects\n# before executing the guest.\n-serial telnet:localhost:12345,server,wait # Configure redirection for the QEMU `mointor`, arguments similar to `-serial`\n# above.\n-monitor ... In server mode use nowait to execute guest without waiting for a client connection.","breadcrumbs":"Tools » IO redirection","id":"142","title":"IO redirection"},"143":{"body":"# Redirect host tcp port `1234` to guest port `4321`.\n-nic user,hostfwd=tcp:localhost:1234-:4321","breadcrumbs":"Tools » Network","id":"143","title":"Network"},"144":{"body":"# Attach a `virtio-9p-pci` device to the VM.\n# The guest requires 9p support and can mount the shared drive as:\n# mount -t 9p -o trans=virtio someName /mnt\n-virtfs local,id=someName,path=,mount_tag=someName,security_model=none","breadcrumbs":"Tools » Shared drives","id":"144","title":"Shared drives"},"145":{"body":"# List name of all trace points.\n-trace help # Enable trace points matching pattern and optionally write trace to file.\n-trace [,file=] # Enable trace points for all events listed in the file.\n# File must contain one event/pattern per line.\n-trace events=","breadcrumbs":"Tools » Tracing","id":"145","title":"Tracing"},"146":{"body":"VM snapshots require that there is at least on qcow2 disk attached to the VM ([VM Snapshots][qemu-doc-snapshot]). Commands for qemu [Monitor][qemu-doc-monitor] or [QMP][qemu-doc-qmp]: # List available snapshots.\ninfo snapshots # Create/Load/Delete snapshot with name \nsavevm \nloadvm \ndelvm The snapshot can also be directly specified when invoking qemu as: qemu-system-x86_64 \\ -loadvm \\ ...","breadcrumbs":"Tools » VM snapshots","id":"146","title":"VM snapshots"},"147":{"body":"Example command line to directly boot a Kernel with an initrd ramdisk. qemu-system-x86_64 \\ -cpu host \\ -enable-kvm \\ -kernel /arch/x86/boot/bzImage \\ -append \"earlyprintk=ttyS0 console=ttyS0 nokaslr init=/init debug\" \\ -initrd /initramfs.cpio.gz \\ ... Instructions to build a minimal Kernel and initrd .","breadcrumbs":"Tools » Appendix: Direct Kernel boot","id":"147","title":"Appendix: Direct Kernel boot"},"148":{"body":"QEMU USB QEMU IMG QEMU Tools QEMU System QEMU Invocation (command line args) QEMU Monitor QEMU machine protocol (QMP) QEMU VM Snapshots","breadcrumbs":"Tools » References","id":"148","title":"References"},"149":{"body":"lsof ss pidstat pgrep pmap pstack","breadcrumbs":"Resource analysis & monitor","id":"149","title":"Resource analysis & monitor"},"15":{"body":"","breadcrumbs":"Tools » bash(1)","id":"15","title":"bash(1)"},"150":{"body":"lsof -r ..... repeatedly execute command ervery seconds -a ......... AND slection filters instead ORing (OR: default) -p ... filter by +fg ........ show file flags for file descripros -n ......... don't convert network addr to hostnames -P ......... don't convert network port to service names -i <@h[:p]>. show connections to h (hostname|ip addr) with optional port p -s ... in conjunction with '-i' filter for protocol

in state -U ......... show unix domain sockets ('@' indicates abstract sock name, see unix(7)) file flags: R/W/RW ..... read/write/read-write CR ......... create AP ......... append TR ......... truncate -s protocols TCP, UDP -s states (TCP) CLOSED, IDLE, BOUND, LISTEN, ESTABLISHED, SYN_SENT, SYN_RCDV, ESTABLISHED, CLOSE_WAIT, FIN_WAIT1, CLOSING, LAST_ACK, FIN_WAIT_2, TIME_WAIT -s states (UDP) Unbound, Idle","breadcrumbs":"Resource analysis & monitor » lsof(8)","id":"150","title":"lsof(8)"},"151":{"body":"","breadcrumbs":"Resource analysis & monitor » Examples","id":"151","title":"Examples"},"152":{"body":"Show open files with file flags for process: lsof +fg -p ","breadcrumbs":"Resource analysis & monitor » File flags","id":"152","title":"File flags"},"153":{"body":"Show open tcp connections for $USER: lsof -a -u $USER -i TCP Note : -a ands the results. If -a is not given all open files matching $USER and all tcp connections are listed ( ored ).","breadcrumbs":"Resource analysis & monitor » Open TCP connections","id":"153","title":"Open TCP connections"},"154":{"body":"Show open connections to localhost for $USER: lsof -a -u $USER -i @localhost","breadcrumbs":"Resource analysis & monitor » Open connection to specific host","id":"154","title":"Open connection to specific host"},"155":{"body":"Show open connections to port :1234 for $USER: lsof -a -u $USER -i :1234","breadcrumbs":"Resource analysis & monitor » Open connection to specific port","id":"155","title":"Open connection to specific port"},"156":{"body":"lsof -i 4TCP -s TCP:ESTABLISHED","breadcrumbs":"Resource analysis & monitor » IPv4 TCP connections in ESTABLISHED state","id":"156","title":"IPv4 TCP connections in ESTABLISHED state"},"157":{"body":"ss [option] [filter] [option] -p ..... Show process using socket -l ..... Show sockets in listening state -4/-6 .. Show IPv4/6 sockets -x ..... Show unix sockets -n ..... Show numeric ports (no resolve) -O ..... Oneline output per socket [filter] dport/sport PORT .... Filter for destination/source port dst/src ADDR ........ Filter for destination/source address and/or .............. Logic operator ==/!= ............... Comparison operator (EXPR) .............. Group exprs","breadcrumbs":"Resource analysis & monitor » ss(8)","id":"157","title":"ss(8)"},"158":{"body":"Show all tcp IPv4 sockets connecting to port 443: ss -4 'dport 443' Show all tcp IPv4 sockets that don't connect to port 443 or connect to address 1.2.3.4. ss -4 'dport != 443 or dst 1.2.3.4'","breadcrumbs":"Resource analysis & monitor » Examples","id":"158","title":"Examples"},"159":{"body":"pidstat [opt] [interval] [cont] -U [user] show username instead UID, optionally only show for user -r memory statistics -d I/O statistics -h single line per process and no lines with average","breadcrumbs":"Resource analysis & monitor » pidstat(1)","id":"159","title":"pidstat(1)"},"16":{"body":"","breadcrumbs":"Tools » Expansion","id":"16","title":"Expansion"},"160":{"body":"pidstat -r -p [interval] [count] minor_pagefault: Happens when the page needed is already in memory but not allocated to the faulting process, in that case the kernel only has to create a new page-table entry pointing to the shared physical page (not required to load a memory page from disk). major_pagefault: Happens when the page needed is NOT in memory, the kernel has to create a new page-table entry and populate the physical page (required to load a memory page from disk).","breadcrumbs":"Resource analysis & monitor » Page fault and memory utilization","id":"160","title":"Page fault and memory utilization"},"161":{"body":"pidstat -d -p [interval] [count]","breadcrumbs":"Resource analysis & monitor » I/O statistics","id":"161","title":"I/O statistics"},"162":{"body":"pgrep [opts] -n only list newest matching process -u only show matching for user -l additionally list command -a additionally list command + arguments","breadcrumbs":"Resource analysis & monitor » pgrep(1)","id":"162","title":"pgrep(1)"},"163":{"body":"For example attach gdb to newest zsh process from $USER. gdb -p $(pgrep -n -u $USER zsh)","breadcrumbs":"Resource analysis & monitor » Debug newest process","id":"163","title":"Debug newest process"},"164":{"body":"pmap Dump virtual memory map of process. Compared to /proc//maps it shows the size of the mappings.","breadcrumbs":"Resource analysis & monitor » pmap(1)","id":"164","title":"pmap(1)"},"165":{"body":"pstack Dump stack for all threads of process.","breadcrumbs":"Resource analysis & monitor » pstack(1)","id":"165","title":"pstack(1)"},"166":{"body":"strace ltrace perf OProfile time","breadcrumbs":"Trace and Profile","id":"166","title":"Trace and Profile"},"167":{"body":"strace [opts] [prg] -f .......... follow child processes on fork(2) -p .... attach to running process -s ... max string size, truncate of longer (default: 32) -e ... expression for trace filtering -o ... log output into -c .......... dump syscall statitics at the end -k .......... dump stack trace for each syscall : trace=syscall[,syscall] .... trace only syscall listed trace=file ................. trace all syscall that take a filename as arg trace=process .............. trace process management related syscalls trace=signal ............... trace signal related syscalls signal ..................... trace signals delivered to the process","breadcrumbs":"Trace and Profile » strace(1)","id":"167","title":"strace(1)"},"168":{"body":"Trace open(2) & socket(2) syscalls for a running process + child processes: strace -f -e trace=open,socket -p Trace signals delivered to a running process: strace -f -e signal -p ","breadcrumbs":"Trace and Profile » Examples","id":"168","title":"Examples"},"169":{"body":"ltrace [opts] [prg] -f .......... follow child processes on fork(2) -p .... attach to running process -o ... log output into -l . show who calls into lib matched by -C .......... demangle","breadcrumbs":"Trace and Profile » ltrace(1)","id":"169","title":"ltrace(1)"},"17":{"body":"# generate sequence from n to m\n{n..m}\n# generate sequence from n to m step by s\n{n..m..s} # expand cartesian product\n{a,b}{c,d}","breadcrumbs":"Tools » Generator","id":"17","title":"Generator"},"170":{"body":"List which program/libs call into libstdc++: ltrace -l '*libstdc++*' -C -o ltrace.log ./main","breadcrumbs":"Trace and Profile » Example","id":"170","title":"Example"},"171":{"body":"perf list show supported hw/sw events perf stat -p .. show stats for running process -I ... show stats periodically over interval -e ... filter for events perf top -p .. show stats for running process -F ... sampling frequency -K ........ hide kernel threads perf record -p ............... record stats for running process -F ................ sampling frequency --call-graph .. [fp, dwarf, lbr] method how to caputre backtrace fp : use frame-pointer, need to compile with -fno-omit-frame-pointer dwarf: use .cfi debug information lbr : use hardware last branch record facility -g ..................... short-hand for --call-graph fp -e ................ filter for events perf report -n .................... annotate symbols with nr of samples --stdio ............... report to stdio, if not presen tui mode -g graph,0.5,caller ... show caller based call chains with value >0.5 Useful : page-faults minor-faults major-faults cpu-cycles` task-clock","breadcrumbs":"Trace and Profile » perf(1)","id":"171","title":"perf(1)"},"172":{"body":"","breadcrumbs":"Trace and Profile » Flamegraph","id":"172","title":"Flamegraph"},"173":{"body":"perf record -g -e cpu-cycles -p \nperf script | FlameGraph/stackcollapse-perf.pl | FlameGraph/flamegraph.pl > cycles-flamegraph.svg","breadcrumbs":"Trace and Profile » Flamegraph with single event trace","id":"173","title":"Flamegraph with single event trace"},"174":{"body":"perf record -g -e cpu-cycles,page-faults -p \nperf script --per-event-dump\n# fold & generate as above","breadcrumbs":"Trace and Profile » Flamegraph with multiple event traces","id":"174","title":"Flamegraph with multiple event traces"},"175":{"body":"operf -g -p -g ...... caputre call-graph information opreport [opt] FILE show time spent per binary image -l ...... show time spent per symbol -c ...... show callgraph information (see below) -a ...... add column with time spent accumulated over child nodes ophelp show supported hw/sw events","breadcrumbs":"Trace and Profile » OProfile","id":"175","title":"OProfile"},"176":{"body":"# statistics of process run\n/usr/bin/time -v ","breadcrumbs":"Trace and Profile » /usr/bin/time(1)","id":"176","title":"/usr/bin/time(1)"},"177":{"body":"od xxd readelf objdump nm","breadcrumbs":"Binary","id":"177","title":"Binary"},"178":{"body":"od [opts] -An don't print addr info -tx4 print hex in 4 byte chunks -ta print as named character -tc printable chars or backslash escape -w4 print 4 bytes per line -j skip bytes from (hex if start with 0x) -N dump bytes (hex of start with 0x)","breadcrumbs":"Binary » od(1)","id":"178","title":"od(1)"},"179":{"body":"echo -n AAAABBBB | od -An -w4 -tx4 >> 41414141 >> 42424242 echo -n '\\x7fELF\\n' | od -tx1 -ta -tc >> 0000000 7f 45 4c 46 0a # tx1 >> del E L F nl # ta >> 177 E L F \\n # tc","breadcrumbs":"Binary » ASCII to hex string","id":"179","title":"ASCII to hex string"},"18":{"body":"# default value\nbar=${foo:-some_val} # if $foo set, then bar=$foo else bar=some_val # alternate value\nbar=${foo:+bla $foo} # if $foo set, then bar=\"bla $foo\" else bar=\"\" # check param set\nbar=${foo:?msg} # if $foo set, then bar=$foo else exit and print msg # indirect\nFOO=foo\nBAR=FOO\nbar=${!BAR} # deref value of BAR -> bar=$FOO # prefix\n${foo#prefix} # remove prefix when expanding $foo\n# suffix\n${foo%suffix} # remove suffix when expanding $foo # substitute\n${foo/pattern/string} # replace pattern with string when expanding foo\n# pattern starts with\n# '/' replace all occurences of pattern\n# '#' pattern match at beginning\n# '%' pattern match at end Note: prefix/suffix/pattern are expanded as pathnames .","breadcrumbs":"Tools » Parameter","id":"18","title":"Parameter"},"180":{"body":"For example .rodata section from an elf file. We can use readelf to get the offset into the file where the .rodata section starts. readelf -W -S foo >> Section Headers: >> [Nr] Name Type Address Off Size ES Flg Lk Inf Al >> ... >> [15] .rodata PROGBITS 00000000004009c0 0009c0 000030 00 A 0 0 16 With the offset of -j 0x0009c0 we can dump -N 0x30 bytes from the beginning of the .rodata section as follows: od -j 0x0009c0 -N 0x30 -tx4 -w4 foo >> 0004700 00020001 >> 0004704 00000000 >> * >> 0004740 00000001 >> 0004744 00000002 >> 0004750 00000003 >> 0004754 00000004 Note : Numbers starting with 0x will be interpreted as hex by od.","breadcrumbs":"Binary » Extract parts of file","id":"180","title":"Extract parts of file"},"181":{"body":"xxd [opts] -p dump continuous hexdump -r convert hexdump into binary ('revert') -e dump as little endian mode -i output as C array","breadcrumbs":"Binary » xxd(1)","id":"181","title":"xxd(1)"},"182":{"body":"echo -n 'aabb' | xxd -p >> 61616262","breadcrumbs":"Binary » ASCII to hex stream","id":"182","title":"ASCII to hex stream"},"183":{"body":"echo -n '61616262' | xxd -p -r >> aabb","breadcrumbs":"Binary » Hex to binary stream","id":"183","title":"Hex to binary stream"},"184":{"body":"echo -n '\\x7fELF' | xxd -p | xxd -p -r | file -p - >> ELF","breadcrumbs":"Binary » ASCII to binary","id":"184","title":"ASCII to binary"},"185":{"body":"xxd -i <(echo -n '\\x7fELF') >> unsigned char _proc_self_fd_11[] = { >> 0x7f, 0x45, 0x4c, 0x46 >> }; >> unsigned int _proc_self_fd_11_len = 4;","breadcrumbs":"Binary » ASCII to C array (hex encoded)","id":"185","title":"ASCII to C array (hex encoded)"},"186":{"body":"readelf [opts] -W|--wide wide output, dont break output at 80 chars -h print ELF header -S print section headers -l print program headers + segment mapping -d print .dynamic section (dynamic link information) --syms print symbol tables (.symtab .dynsym) --dyn-syms print dynamic symbol table (exported symbols for dynamic linker) -r print relocation sections (.rel.*, .rela.*)","breadcrumbs":"Binary » readelf(1)","id":"186","title":"readelf(1)"},"187":{"body":"objdump [opts] -M intel use intil syntax -d disassemble text section -D disassemble all sections -S mix disassembly with source code -C demangle -j

display info for section --[no-]show-raw-insn [dont] show object code next to disassembly","breadcrumbs":"Binary » objdump(1)","id":"187","title":"objdump(1)"},"188":{"body":"For example .plt section: objdump -j .plt -d ","breadcrumbs":"Binary » Disassemble section","id":"188","title":"Disassemble section"},"189":{"body":"nm [opts] -C demangle -u undefined only","breadcrumbs":"Binary » nm(1)","id":"189","title":"nm(1)"},"19":{"body":"* match any string\n? match any single char\n\\\\ match backslash\n[abc] match any char of 'a' 'b' 'c'\n[a-z] match any char between 'a' - 'z'\n[^ab] negate, match all not 'a' 'b'\n[:class:] match any char in class, available: alnum,alpha,ascii,blank,cntrl,digit,graph,lower, print,punct,space,upper,word,xdigit Wit extglob shell option enabled it is possible to have more powerful patterns. In the following pattern-list is one ore more patterns separated by | char. ?(pattern-list) matches zero or one occurrence of the given patterns\n*(pattern-list) matches zero or more occurrences of the given patterns\n+(pattern-list) matches one or more occurrences of the given patterns\n@(pattern-list) matches one of the given patterns\n!(pattern-list) matches anything except one of the given patterns Note: shopt -s extglob/shopt -u extglob to enable/disable extglob option.","breadcrumbs":"Tools » Pathname","id":"19","title":"Pathname"},"190":{"body":"c++filt c++ glibc gcc [make] (./make.md) ld.so","breadcrumbs":"Development","id":"190","title":"Development"},"191":{"body":"","breadcrumbs":"Development » c++filt(1)","id":"191","title":"c++filt(1)"},"192":{"body":"c++-filt ","breadcrumbs":"Development » Demangle symbol","id":"192","title":"Demangle symbol"},"193":{"body":"For example dynamic symbol table: readelf -W --dyn-syms | c++filt","breadcrumbs":"Development » Demangle stream","id":"193","title":"Demangle stream"},"194":{"body":"","breadcrumbs":"Development » c++","id":"194","title":"c++"},"195":{"body":"Force compile error to see what auto is deduced to. auto foo = bar(); // force compile error\ntypename decltype(foo)::_;","breadcrumbs":"Development » Type deduction","id":"195","title":"Type deduction"},"196":{"body":"","breadcrumbs":"Development » glibc","id":"196","title":"glibc"},"197":{"body":"Trace memory allocation and de-allocation to detect memory leaks. Need to call mtrace(3) to install the tracing hooks. If we can't modify the binary to call mtrace we can create a small shared library and pre-load it. // libmtrace.c\n#include \n__attribute__((constructor)) static void init_mtrace() { mtrace(); } Compile as: gcc -shared -fPIC -o libmtrace.so libmtrace.c To generate the trace file run: export MALLOC_TRACE=\nLD_PRELOAD=./libmtrace.so Note : If MALLOC_TRACE is not set mtrace won't install tracing hooks. To get the results of the trace file: mtrace $MALLOC_TRACE","breadcrumbs":"Development » malloc tracer mtrace(3)","id":"197","title":"malloc tracer mtrace(3)"},"198":{"body":"Configure action when glibc detects memory error. export MALLOC_CHECK_= Useful values: 1 print detailed error & continue\n3 print detailed error + stack trace + memory mappings & abort\n7 print simple error message + stack trace + memory mappings & abort","breadcrumbs":"Development » malloc check mallopt(3)","id":"198","title":"malloc check mallopt(3)"},"199":{"body":"","breadcrumbs":"Development » gcc(1)","id":"199","title":"gcc(1)"},"2":{"body":"","breadcrumbs":"Tools » zsh(1)","id":"2","title":"zsh(1)"},"20":{"body":"Note: The trick with bash I/O redirection is to interpret from left-to-right. # stdout & stderr to file\ncommand >file 2>&1\n# equivalent\ncommand &>file # stderr to stdout & stdout to file\ncommand 2>&1 >file","breadcrumbs":"Tools » I/O redirection","id":"20","title":"I/O redirection"},"200":{"body":"","breadcrumbs":"Development » CLI","id":"200","title":"CLI"},"201":{"body":"While debugging can be helpful to just pre-process files. gcc -E [-dM] ... -E run only preprocessor -dM list only #define statements","breadcrumbs":"Development » Preprocessing","id":"201","title":"Preprocessing"},"202":{"body":"","breadcrumbs":"Development » Builtins","id":"202","title":"Builtins"},"203":{"body":"Give the compiler a hint which branch is hot, so it can lay out the code accordingly to reduce number of jump instructions. See on compiler explorer . echo \"\nextern void foo();\nextern void bar();\nvoid run0(int x) { if (__builtin_expect(x,0)) { foo(); } else { bar(); }\n}\nvoid run1(int x) { if (__builtin_expect(x,1)) { foo(); } else { bar(); }\n}\n\" | gcc -O2 -S -masm=intel -o /dev/stdout -xc - Will generate something similar to the following. run0: bar is on the path without branch run1: foo is on the path without branch run0: test edi, edi jne .L4 xor eax, eax jmp bar\n.L4: xor eax, eax jmp foo\nrun1: test edi, edi je .L6 xor eax, eax jmp foo\n.L6: xor eax, eax jmp bar","breadcrumbs":"Development » __builtin_expect(expr, cond)","id":"203","title":"__builtin_expect(expr, cond)"},"204":{"body":"C ABI - SystemV ABI C++ ABI - C++ Itanium ABI","breadcrumbs":"Development » ABI (Linux)","id":"204","title":"ABI (Linux)"},"205":{"body":"","breadcrumbs":"Development » make(1)","id":"205","title":"make(1)"},"206":{"body":"target .. : prerequisite .. recipe .. target: an output generated by the rule prerequisite: an input that is used to generate the target recipe: list of actions to generate the output from the input Use make -p to print all rules and variables (implicitly + explicitly defined).","breadcrumbs":"Development » Anatomy of make rules","id":"206","title":"Anatomy of make rules"},"207":{"body":"","breadcrumbs":"Development » Pattern rules & Automatic variables","id":"207","title":"Pattern rules & Automatic variables"},"208":{"body":"A pattern rule contains the % char (exactly one of them) and look like this example: %.o : %.c $(CC) -c $(CFLAGS) $(CPPFLAGS) $< -o $@ The target matches files of the pattern %.o, where % matches any none-empty substring and other character match just them self. The substring matched by % is called the stem. % in the prerequisite stands for the matched stem in the target.","breadcrumbs":"Development » Pattern rules","id":"208","title":"Pattern rules"},"209":{"body":"As targets and prerequisites in pattern rules can't be spelled explicitly in the recipe, make provides a set of automatic variables to work with: $@: Name of the target that triggered the rule. $<: Name of the first prerequisite. $^: Names of all prerequisites (without duplicates). $+: Names of all prerequisites (with duplicates). $*: Stem of the pattern rule. # file: Makefile all: foobar blabla foo% bla%: aaa bbb bbb @echo \"@ = $@\" @echo \"< = $<\" @echo \"^ = $^\" @echo \"+ = $+\" @echo \"* = $*\" @echo \"----\" aaa:\nbbb: Running above Makefile gives: @ = foobar\n< = aaa\n^ = aaa bbb\n+ = aaa bbb bbb\n* = bar\n----\n@ = blabla\n< = aaa\n^ = aaa bbb\n+ = aaa bbb bbb\n* = bla\n----","breadcrumbs":"Development » Automatic variables","id":"209","title":"Automatic variables"},"21":{"body":"j>&i Duplicate fd i to fd j, making j a copy of i. See dup2(2) . Example: command 2>&1 >file duplicate fd 1 to fd 2, effectively redirecting stderr to stdout redirect stdout to file","breadcrumbs":"Tools » Explanation","id":"21","title":"Explanation"},"210":{"body":"","breadcrumbs":"Development » Useful functions","id":"210","title":"Useful functions"},"211":{"body":"Substitute strings matching pattern in a list. in := a.o l.a c.o\nout := $(in:.o=.c)\n# => out = a.c l.a c.c","breadcrumbs":"Development » Substitution references","id":"211","title":"Substitution references"},"212":{"body":"Keep strings matching a pattern in a list. in := a.a b.b c.c d.d\nout := $(filter %.b %.c, $(in))\n# => out = b.b c.c","breadcrumbs":"Development » filter","id":"212","title":"filter"},"213":{"body":"Remove strings matching a pattern from a list. in := a.a b.b c.c d.d\nout := $(filter-out %.b %.c, $(in))\n# => out = a.a d.d","breadcrumbs":"Development » filter-out","id":"213","title":"filter-out"},"214":{"body":"Resolve each file name as absolute path (don't resolve symlinks). $(abspath fname1 fname2 ..) ### `realpath`\nResolve each file name as canonical path.\n```make\n$(realpath fname1 fname2 ..)","breadcrumbs":"Development » abspath","id":"214","title":"abspath"},"215":{"body":"","breadcrumbs":"Development » ld.so(8)","id":"215","title":"ld.so(8)"},"216":{"body":"LD_PRELOAD= colon separated list of libso's to be pre loaded LD_DEBUG= comma separated list of debug options =help list available options =libs show library search path =files processing of input files =symbols show search path for symbol lookup =bindings show against which definition a symbol is bound","breadcrumbs":"Development » Environment Variables","id":"216","title":"Environment Variables"},"217":{"body":"Libraries specified in LD_PRELOAD are loaded from left-to-right but initialized from right-to-left. > ldd ./main >> libc.so.6 => /usr/lib/libc.so.6 > LD_PRELOAD=liba.so:libb.so ./main --> preloaded in this order <-- initialized in this order The preload order determines: the order libraries are inserted into the link map the initialization order for libraries For the example listed above the resulting link map will look like the following: +------+ +------+ +------+ +------+ | main | -> | liba | -> | libb | -> | libc | +------+ +------+ +------+ +------+ This can be seen when running with LD_DEBUG=files: > LD_DEBUG=files LD_PRELOAD=liba.so:libb.so ./main # load order (-> determines link map) >> file=liba.so [0]; generating link map >> file=libb.so [0]; generating link map >> file=libc.so.6 [0]; generating link map # init order >> calling init: /usr/lib/libc.so.6 >> calling init: /libb.so >> calling init: /liba.so >> initialize program: ./main To verify the link map order we let ld.so resolve the memcpy(3) libc symbol (used in main ) dynamically, while enabling LD_DEBUG=symbols,bindings to see the resolving in action. > LD_DEBUG=symbols,bindings LD_PRELOAD=liba.so:libb.so ./main >> symbol=memcpy; lookup in file=./main [0] >> symbol=memcpy; lookup in file=/liba.so [0] >> symbol=memcpy; lookup in file=/libb.so [0] >> symbol=memcpy; lookup in file=/usr/lib/libc.so.6 [0] >> binding file ./main [0] to /usr/lib/libc.so.6 [0]: normal symbol `memcpy' [GLIBC_2.14]","breadcrumbs":"Development » LD_PRELOAD: Initialization Order and Link Map","id":"217","title":"LD_PRELOAD: Initialization Order and Link Map"},"218":{"body":"Dynamic linking basically works via one indirect jump. It uses a combination of function trampolines (.plt section) and a function pointer table (.got.plt section). On the first call the trampoline sets up some metadata and then jumps to the ld.so runtime resolve function, which in turn patches the table with the correct function pointer. .plt ....... procedure linkage table, contains function trampolines, usually located in code segment (rx permission) .got.plt ... global offset table for .plt, holds the function pointer table Using radare2 we can analyze this in more detail: [0x00401040]> pd 4 @ section..got.plt ;-- section..got.plt: ;-- .got.plt: ; [22] -rw- section size 32 named .got.plt ;-- _GLOBAL_OFFSET_TABLE_: [0] 0x00404000 .qword 0x0000000000403e10 ; section..dynamic [1] 0x00404008 .qword 0x0000000000000000 ; CODE XREF from section..plt @ +0x6 [2] 0x00404010 .qword 0x0000000000000000 ;-- reloc.puts: ; CODE XREF from sym.imp.puts @ 0x401030 [3] 0x00404018 .qword 0x0000000000401036 ; RELOC 64 puts [0x00401040]> pd 6 @ section..plt ;-- section..plt: ;-- .plt: ; [12] -r-x section size 32 named .plt ┌─> 0x00401020 ff35e22f0000 push qword [0x00404008] ╎ 0x00401026 ff25e42f0000 jmp qword [0x00404010] ╎ 0x0040102c 0f1f4000 nop dword [rax] ┌ 6: int sym.imp.puts (const char *s); └ ╎ 0x00401030 ff25e22f0000 jmp qword [reloc.puts] ╎ 0x00401036 6800000000 push 0 └─< 0x0040103b e9e0ffffff jmp sym..plt At address 0x00401030 in the .plt section we see the indirect jump for puts using the function pointer in _GLOBAL_OFFSET_TABLE_[3] (GOT). GOT[3] initially points to instruction after the puts trampoline 0x00401036. This pushes the relocation index 0 and then jumps to the first trampoline 0x00401020. The first trampoline jumps to GOT[2] which will be filled at program startup by the ld.so with its resolve function. The ld.so resolve function fixes the relocation referenced by the relocation index pushed by the puts trampoline. The relocation entry at index 0 tells the resolve function which symbol to search for and where to put the function pointer: > readelf -r
>> Relocation section '.rela.plt' at offset 0x4b8 contains 1 entry: >> Offset Info Type Sym. Value Sym. Name + Addend >> 000000404018 000200000007 R_X86_64_JUMP_SLO 0000000000000000 puts@GLIBC_2.2.5 + 0 As we can see the offset from relocation at index 0 points to GOT[3].","breadcrumbs":"Development » Dynamic Linking (x86_64)","id":"218","title":"Dynamic Linking (x86_64)"},"219":{"body":"x86_64 arm64 armv7","breadcrumbs":"Arch","id":"219","title":"Arch"},"22":{"body":"The getopts builtin uses following global variables: OPTARG, value of last option argument OPTIND, index of the next argument to process (user must reset) OPTERR, display errors if set to 1 getopts [] specifies the names of supported options, eg f:c f: means -f option with an argument c means -c option without an argument specifies a variable name which getopts fills with the last parsed option argument optionally specify argument string to parse, by default getopts parses $@","breadcrumbs":"Tools » Argument parsing with getopts","id":"22","title":"Argument parsing with getopts"},"220":{"body":"keywords: x86_64, x86, abi 64bit synonyms: x86_64, x64, amd64, intel 64 32bit synonyms: x86, ia32, i386 ISA type: CISC Endianness: little","breadcrumbs":"Arch » x86_64","id":"220","title":"x86_64"},"221":{"body":"","breadcrumbs":"Arch » Registers","id":"221","title":"Registers"},"222":{"body":"bytes\n[7:0] [3:0] [1:0] [1] [0] desc\n----------------------------------------------------------\nrax eax ax ah al accumulator\nrbx ebx bx bh bl base register\nrcx ecx cx ch cl counter\nrdx edx dx dh dl data register\nrsi esi si - sil source index\nrdi edi di - dil destination index\nrbp ebp bp - bpl base pointer\nrsp esp sp - spl stack pointer\nr8-15 rNd rNw - rNb","breadcrumbs":"Arch » General purpose register","id":"222","title":"General purpose register"},"223":{"body":"bytes\n[7:0] [3:0] [1:0] desc\n---------------------------------------------------\nrflags eflags flags flags register\nrip eip ip instruction pointer","breadcrumbs":"Arch » Special register","id":"223","title":"Special register"},"224":{"body":"rflags\nbits desc instr comment\n-------------------------------------------------------------------------------------------------------------- [21] ID identification ability to set/clear -> indicates support for CPUID instr [18] AC alignment check alignment exception for PL 3 (user), requires CR0.AM\n[13:12] IOPL io privilege level [11] OF overflow flag [10] DF direction flag cld/std [9] IF interrupt enable cli/sti [7] SF sign flag [6] ZF zero flag [4] AF auxiliary carry flag [2] PF parity flag [0] CF carry flag Change flag bits with pushf / popf instructions: pushfd // push flags (4bytes) onto stack\nor dword ptr [esp], (1 << 18) // enable AC flag\npopfd // pop flags (4byte) from stack There is also pushfq / popfq to push and pop all 8 bytes of rflags.","breadcrumbs":"Arch » FLAGS register","id":"224","title":"FLAGS register"},"225":{"body":"rdmsr // Read MSR register, effectively does EDX:EAX <- MSR[ECX]\nwrmsr // Write MSR register, effectively does MSR[ECX] <- EDX:EAX","breadcrumbs":"Arch » Model Specific Register (MSR)","id":"225","title":"Model Specific Register (MSR)"},"226":{"body":"Explicitly specify size of the operation. mov byte ptr [rax], 0xff // save 1 byte(s) at [rax]\nmov word ptr [rax], 0xff // save 2 byte(s) at [rax]\nmov dword ptr [rax], 0xff // save 4 byte(s) at [rax]\nmov qword ptr [rax], 0xff // save 8 byte(s) at [rax]","breadcrumbs":"Arch » Size directives","id":"226","title":"Size directives"},"227":{"body":"mov qword ptr [rax], rbx // save val in rbx at [rax]\nmov qword ptr [imm], rbx // save val in rbx at [imm]\nmov rax, qword ptr [rbx+4*rcx] // load val at [rbx+4*rcx] into rax rip relative addressing: lea rax, [rip+.my_str] // load addr of .my_str into rax\n...\n.my_str:\n.asciz \"Foo\"","breadcrumbs":"Arch » Addressing","id":"227","title":"Addressing"},"228":{"body":"The operand size of a string instruction is defined by the instruction suffix b | w | d | q. Source and destination registers are modified according to the direction flag (DF) in the flags register DF=0 increment src/dest registers DF=1 decrement src/dest registers Following explanation assumes byte operands with DF=0: movsb // move data from string to string // ES:[DI] <- DS:[SI] // DI <- DI + 1 // SI <- SI + 1 lodsb // load string // AL <- DS:[SI] // SI <- SI + 1 stosb // store string // ES:[DI] <- AL // DI <- DI + 1 cmpsb // compare string operands // DS:[SI] - ES:[DI] ; set status flag (eg ZF) // SI <- SI + 1 // DI <- DI + 1 scasb // scan string // AL - ES:[DI] ; set status flag (eg ZF) // DI <- DI + 1 String operations can be repeated: rep // repeat until rcx = 0\nrepz // repeat until rcx = 0 or while ZF = 0\nrepnz // repeat until rcx = 0 or while ZF = 1","breadcrumbs":"Arch » String instructions","id":"228","title":"String instructions"},"229":{"body":"// memset (dest, 0xaa /* char */, 0x10 /* len */) lea di, [dest]\nmov al, 0xaa\nmov cx, 0x10\nrep stosb","breadcrumbs":"Arch » Example: Simple memset","id":"229","title":"Example: Simple memset"},"23":{"body":"#!/bin/bash\nfunction parse_args() { while getopts \"f:c\" PARAM; do case $PARAM in f) echo \"GOT -f $OPTARG\";; c) echo \"GOT -c\";; *) echo \"ERR: print usage\"; exit 1;; esac done # users responsibility to reset OPTIND OPTIND=1\n} parse_args -f xxx -c\nparse_args -f yyy","breadcrumbs":"Tools » Example","id":"23","title":"Example"},"230":{"body":"","breadcrumbs":"Arch » SysV x86_64 ABI","id":"230","title":"SysV x86_64 ABI"},"231":{"body":"Integer/Pointer arguments reg arg\n-----------\nrdi 1\nrsi 2\nrdx 3\nrcx 4\nr8 5\nr9 6 Floating point arguments reg arg\n-----------\nxmm0 1 .. ..\nxmm7 8 Additional arguments are passed on the stack. Arguments are pushed right-to-left (RTL), meaning next arguments are closer to current rsp.","breadcrumbs":"Arch » Passing arguments to functions","id":"231","title":"Passing arguments to functions"},"232":{"body":"Integer/Pointer return values reg size\n-----------------\nrax 64 bit\nrax+rdx 128 bit Floating point return values: reg size\n-------------------\nxmm0 64 bit\nxmm0+xmm1 128 bit","breadcrumbs":"Arch » Return values from functions","id":"232","title":"Return values from functions"},"233":{"body":"Caller must save these registers if they should be preserved across function calls. rax rcx rdx rsi rdi rsp r8 - r11","breadcrumbs":"Arch » Caller saved registers","id":"233","title":"Caller saved registers"},"234":{"body":"Caller can expect these registers to be preserved across function calls. Callee must must save these registers in case they are used. rbx rbp r12 – r15","breadcrumbs":"Arch » Callee saved registers","id":"234","title":"Callee saved registers"},"235":{"body":"grows downwards frames aligned on 16 byte boundary Hi ADDR | +------------+ | | prev frame | | +------------+ <--- 16 byte aligned (X & ~0xf) | [rbp+8] | saved RIP | | [rbp] | saved RBP | | [rbp-8] | func stack | | | ... | v +------------+\nLo ADDR","breadcrumbs":"Arch » Stack","id":"235","title":"Stack"},"236":{"body":"prologue push rbp // save caller base pointer\nmov rbp, rsp // save caller stack pointer epilogue mov rsp, rbp // restore caller stack pointer\npop rbp // restore caller base pointer Equivalent to leave instruction.","breadcrumbs":"Arch » Function prologue & epilogue","id":"236","title":"Function prologue & epilogue"},"237":{"body":"Small assembler skeleton, ready to use with following properties: use raw Linux syscalls (man 2 syscall for ABI) no C runtime (crt) gnu assembler gas intel syntax # file: greet.s .intel_syntax noprefix .section .text, \"ax\", @progbits .global _start\n_start: mov rdi, 1 # fd lea rsi, [rip + greeting] # buf mov rdx, [rip + greeting_len] # count mov rax, 1 # write(2) syscall nr syscall mov rdi, 0 # exit code mov rax, 60 # exit(2) syscall nr syscall .section .rdonly, \"a\", @progbits\ngreeting: .asciz \"Hi ASM-World!\\n\"\ngreeting_len: .int .-greeting Syscall numbers are defined in /usr/include/asm/unistd.h. To compile and run: > gcc -o greet greet.s -nostartfiles -nostdlib && ./greet\nHi ASM-World!","breadcrumbs":"Arch » ASM skeleton","id":"237","title":"ASM skeleton"},"238":{"body":"SystemV AMD64 ABI AMD64 Vol1: Application Programming AMD64 Vol2: System Programming AMD64 Vol3: General-Purpose & System Instructions X86_64 Cheat-Sheet Intel 64 Vol1: Basic Architecture Intel 64 Vol2: Instruction Set Reference Intel 64 Vol3: System Programming Guide GNU Assembler GNU Assembler Directives GNU Assembler x86_64 dependent features","breadcrumbs":"Arch » References","id":"238","title":"References"},"239":{"body":"keywords: arm64, aarch64, abi 64bit synonyms: arm64, aarch64 ISA type: RISC Endianness: little, big","breadcrumbs":"Arch » arm64","id":"239","title":"arm64"},"24":{"body":"Bash supports regular expression matching with the binary operator =~. The match results can be accessed via the $BASH_REMATCH variable: ${BASH_REMATCH[0]} contains the full match ${BASH_REMATCH[1]} contains match of the first capture group INPUT='title foo : 1234'\nREGEX='^title (.+) : ([0-9]+)$'\nif [[ $INPUT =~ $REGEX ]]; then echo \"${BASH_REMATCH[0]}\" # title foo : 1234 echo \"${BASH_REMATCH[1]}\" # foo echo \"${BASH_REMATCH[2]}\" # 1234\nfi Caution : When specifying a regex in the [[ ]] block directly, quotes will be treated as part of the pattern. [[ $INPUT =~ \"foo\" ]] will match against \"foo\" not foo!","breadcrumbs":"Tools » Regular Expressions","id":"24","title":"Regular Expressions"},"240":{"body":"","breadcrumbs":"Arch » Registers","id":"240","title":"Registers"},"241":{"body":"bytes\n[7:0] [3:0] desc\n---------------------------------------------\nx0-x28 w0-w28 general purpose registers\nx29 w29 frame pointer (FP)\nx30 w30 link register (LR)\nsp wsp stack pointer (SP)\npc program counter (PC)\nxzr wzr zero register Write to wN register clears upper 32bit.","breadcrumbs":"Arch » General purpose registers","id":"241","title":"General purpose registers"},"242":{"body":"bytes\n[7:0] desc\n---------------------------------------------\nsp_el0 stack pointer EL0 sp_el1 stack pointer EL1\nelr_el1 exception link register EL1\nspsr_el1 saved process status register EL1 sp_el2 stack pointer EL2\nelr_el2 exception link register EL2\nspsr_el2 saved process status register EL2 sp_el3 stack pointer EL3\nelr_el3 exception link register EL3\nspsr_el3 saved process status register EL3","breadcrumbs":"Arch » Special registers per EL","id":"242","title":"Special registers per EL"},"243":{"body":"","breadcrumbs":"Arch » Instructions cheatsheet","id":"243","title":"Instructions cheatsheet"},"244":{"body":"Reading from system registers: mrs x0, vbar_el1 // move vbar_el1 into x0 Writing to system registers: msr vbar_el1, x0 // move x0 into vbar_el1","breadcrumbs":"Arch » Accessing system registers","id":"244","title":"Accessing system registers"},"245":{"body":"b // relative forward/back branch\nbr // absolute branch to address in register Xn // branch & link, store return address in X30 (LR)\nbl // relative forward/back branch\nblr // absolute branch to address in register Xn ret {Xn} // return to address in X30, or Xn if supplied","breadcrumbs":"Arch » Control Flow","id":"245","title":"Control Flow"},"246":{"body":"","breadcrumbs":"Arch » Addressing","id":"246","title":"Addressing"},"247":{"body":"ldr x0, [x1] // x0 = [x1]\nldr x0, [x1, 8] // x0 = [x1 + 8]\nldr x0, [x1, x2, lsl #3] // x0 = [x1 + (x2<<3)]\nldr x0, [x1, w2, stxw] // x0 = [x1 + sign_ext(w2)]\nldr x0, [x1, w2, stxw #3] // x0 = [x1 + (sign_ext(w2)<<3)] Shift amount can either be 0 or log2(access_size_bytes). Eg for 8byte access it can either be {0, 3}.","breadcrumbs":"Arch » Offset","id":"247","title":"Offset"},"248":{"body":"ldr x0, [x1, 8]! // pre-inc : x1+=8; x0 = [x1]\nldr x0, [x1], 8 // post-inc: x0 = [x1]; x1+=8","breadcrumbs":"Arch » Index","id":"248","title":"Index"},"249":{"body":"ldp x1, x2, [x0] // x1 = [x0]; x2 = [x0 + 8]\nstp x1, x2, [x0] // [x0] = x1; [x0 + 8] = x2","breadcrumbs":"Arch » Pair access","id":"249","title":"Pair access"},"25":{"body":"The complete builtin is used to interact with the completion system. complete # print currently installed completion handler\ncomplete -F # install as completion handler for \ncomplete -r # uninstall completion handler for Variables available in completion functions: # in\n$1 # \n$2 # current word\n$3 # privous word COMP_WORDS # array with current command line words\nCOMP_CWORD # index into COMP_WORDS with current cursor position # out\nCOMPREPLY # array with possible completions The compgen builtin is used to generate possible matches by comparing word against words generated by option. compgen