What the x86-64 syscall instruction does in the instant it runs, single-stepped in gdb
tetsuoai · x · 2026-09-14
The author disassembles what happens in the instant a syscall executes, verified by single-stepping in gdb and again inside a kernel booted under QEMU:
- syscall saves the return address in rcx and flags in r11
- It loads the kernel entry point from LSTAR and a ring 0 code segment from STAR, and masks interrupts
- Counterintuitive detail: syscall pushes nothing and switches no stack — the kernel's first instructions run swapgs and set up their own stack
More from Fun
- Gary Marcus mocks AI labs: OpenAI and Anthropic don't want to be the next Juicero — GaryMarcus · 2026-09-14
- There's now only one stage of discovery: OpenAI and Anthropic employees push a button — lpachter · 2026-09-14
- Meta gives free AR glasses to every blind veteran in America — GavinSBaker · 2026-09-14
- Eliezer Yudkowsky recalls crying when he realized deep learning scaling was working — JacquesThibs · 2026-09-14
- Radiologists strike again: Hinton's 2016 automation prediction becomes an AI-circle joke — QuintinPope5 · 2026-09-14
- The 2028 agent joke: saves you 23¢, triggers a diplomatic incident — steipete · 2026-09-14