Return from callgate function

Question about which tools to use, bugs, the best way to implement a function, etc should go here. Don't forget to see if your question is answered in the wiki first! When in doubt post here.
Post Reply
Posts: 2
Joined: Fri Apr 22, 2005 11:00 pm

Return from callgate function

Post by jj »


I'm newbit on OS kernel dev. I'm studying about callgate on ia32 protected mode.

Af far as I know, When user mode process call kernel mode module via callgate like following.


then, eip, cs, arguments(if any), esp, ss are pushed automatically, and control goes to callgate function. (to CALLGATE1_SELECTOR:offset)

My question:

in the callgate function, after performing proper work, I used instruction RET to return to user process. but, RET in callgate function POPed and restored only EIP. So cs, esp, ss of user mode process weren't restored.

Is there any other process that I miss about return processes of callgate? Is there any other specific instruction than RET instruction for returning of callgate?
User avatar
Posts: 60
Joined: Tue Feb 01, 2005 12:00 am

Re: Return from callgate function

Post by ManOfSteel »

It seems you're talking about an inter-privilege-level switch so you need a far return (retf), AFAIK.
Posts: 36
Joined: Sat Oct 30, 2004 11:00 pm
Location: Germany

Re: Return from callgate function

Post by frizzz »

ManOfSteel is right...
A call-gate-descriptor is meant to allow control over FAR-calls on the lowest level in the CPU (priviledge-level-control).
In fact you do not need a call-gate-descriptor, if want to call FAR (using the same priviledge level!). You only need the fitting selector and (of course) the fitting offset-adress of the procedure to call. In both cases you return in the same way : retf
Post Reply