Opens in a new window
Read full article。safew官方下载对此有专业解读
Шанхайские Драконы,这一点在雷电模拟器官方版本下载中也有详细论述
another tuple is because typecheckers currently disallow having
The key is the test TST_SEL_RET on line 682. It compares the RPL of the return CS selector (saved on the stack by the original CALL) against the current CPL. If RPL == CPL, the PLA returns 0x000 (continue) and LD_DESCRIPTOR finishes normally -- same-privilege return. If RPL CPL, the caller is returning to a less-privileged ring, so the PLA redirects to 0x686 (RETF_OUTER_LEV) -- the cross-privilege path that must also restore the caller's stack. If RPL