277

I was wondering how to use GCC on my C source file to dump a mnemonic version of the machine code so I could see what my code was being compiled into. You can do this with Java but I haven't been able to find a way with GCC.

I am trying to re-write a C method in assembly and seeing how GCC does it would be a big help.

Ryan Tenney
  • 1,805
  • 2
  • 16
  • 29
James
  • 3,272
  • 3
  • 20
  • 21
  • 28
    note that 'bytecode' typically means the code consumed by a VM, like JVM or .NET's CLR. The output of GCC is better called 'machine code', 'machine language', or 'assembly language' – Javier Aug 17 '09 at 19:27
  • 2
    I added an answer using godbolt since it is a very powerful tool for rapidly experimenting with how different options effect your code generation. – Shafik Yaghmour Sep 12 '14 at 02:35
  • http://stackoverflow.com/a/19083877/995714 – phuclv Nov 30 '14 at 06:33
  • Possible duplicate of [How do you get assembler output from C/C++ source in gcc?](http://stackoverflow.com/questions/137038/how-do-you-get-assembler-output-from-c-c-source-in-gcc) – Ciro Santilli新疆棉花TRUMP BAN BAD Oct 15 '15 at 20:21
  • For more tips on making the asm output human readable, see also: [How to remove “noise” from GCC/clang assembly output?](http://stackoverflow.com/a/38552509/224132) – Peter Cordes Sep 05 '16 at 20:46
  • 1
    Answered here: https://stackoverflow.com/questions/137038/how-do-you-get-assembler-output-from-c-c-source-in-gcc Use the -S option to gcc (or g++). – knowledge_is_power Jul 26 '17 at 19:38

10 Answers10

352

If you compile with debug symbols, you can use objdump to produce a more readable disassembly.

>objdump --help
[...]
-S, --source             Intermix source code with disassembly
-l, --line-numbers       Include line numbers and filenames in output

objdump -drwC -Mintel is nice:

  • -r shows symbol names on relocations (so you'd see puts in the call instruction below)
  • -R shows dynamic-linking relocations / symbol names (useful on shared libraries)
  • -C demangles C++ symbol names
  • -w is "wide" mode: it doesn't line-wrap the machine-code bytes
  • -Mintel: use GAS/binutils MASM-like .intel_syntax noprefix syntax instead of AT&T
  • -S: interleave source lines with disassembly.

You could put something like alias disas="objdump -drwCS -Mintel" in your ~/.bashrc


Example:

> gcc -g -c test.c
> objdump -d -M intel -S test.o

test.o:     file format elf32-i386


Disassembly of section .text:

00000000 <main>:
#include <stdio.h>

int main(void)
{
   0:   55                      push   ebp
   1:   89 e5                   mov    ebp,esp
   3:   83 e4 f0                and    esp,0xfffffff0
   6:   83 ec 10                sub    esp,0x10
    puts("test");
   9:   c7 04 24 00 00 00 00    mov    DWORD PTR [esp],0x0
  10:   e8 fc ff ff ff          call   11 <main+0x11>

    return 0;
  15:   b8 00 00 00 00          mov    eax,0x0
}
  1a:   c9                      leave  
  1b:   c3                      ret

Note that this isn't using -r so the call rel32=-4 isn't annotated with the puts symbol name. And looks like a broken call that jumps into the middle of the call instruction in main. Remember that the rel32 displacement in the call encoding is just a placeholder until the linker fills in a real offset (to a PLT stub in this case, unless you statically link libc).

Peter Cordes
  • 245,674
  • 35
  • 423
  • 606
Bastien Léonard
  • 55,374
  • 18
  • 76
  • 92
116

If you give GCC the flag -fverbose-asm, it will

Put extra commentary information in the generated assembly code to make it more readable.

[...] The added comments include:

  • information on the compiler version and command-line options,
  • the source code lines associated with the assembly instructions, in the form FILENAME:LINENUMBER:CONTENT OF LINE,
  • hints on which high-level expressions correspond to the various assembly instruction operands.
Cristian Ciupitu
  • 18,164
  • 7
  • 46
  • 70
Kasper
  • 2,243
  • 2
  • 16
  • 15
  • But then, I would lost all the switch used for `objdump` - `objdump -drwCS -Mintel`, so how can I use something like `verbose` with `objdump`? So that I can have comments in asm code, as does `-fverbose-asm` in gcc? – Herdsman Jan 10 '20 at 17:08
  • 3
    @Herdsman: you can't. The extra stuff `-fverbose-asm` adds is in the form of comments in the asm syntax of the output, not directives that will put anything extra in the `.o` file. It's all discarded at assemble time. Look at compiler asm output *instead* of disassembly, e.g. on https://godbolt.org/ where you can easily match it up with the source line via mouseover and color highlighting of corresponding source / asm lines. [How to remove "noise" from GCC/clang assembly output?](https://stackoverflow.com/q/38552116) – Peter Cordes May 09 '20 at 19:16
80

Use the -S (note: capital S) switch to GCC, and it will emit the assembly code to a file with a .s extension. For example, the following command:

gcc -O2 -S foo.c

will leave the generated assembly code on the file foo.s.

Ripped straight from http://www.delorie.com/djgpp/v2faq/faq8_20.html (but removing erroneous -c)

Community
  • 1
  • 1
Andrew Keeton
  • 18,949
  • 6
  • 40
  • 68
  • 36
    You shouldn't mix -c and -S, only use one of them. In this case, one is overriding the other, probably depending on the order in which they're used. – Adam Rosenfield Aug 17 '09 at 19:28
  • 4
    @AdamRosenfield Any reference about 'shouldn't mix -c and -S'? If it is true, we may should remind the author and edit it. – Tony Aug 05 '14 at 11:55
  • 5
    @Tony: https://gcc.gnu.org/onlinedocs/gcc/Overall-Options.html#Overall-Options "You can use ... ***one*** of the options -c, -S, or -E to say where gcc is to stop." – Nate Eldredge Apr 10 '16 at 00:32
  • 1
    If you want all the intermediate outputs, use `gcc -march=native -O3 -save-temps`. You can still use `-c` to stop at object-file creation without trying to link, or whatever. – Peter Cordes Jun 02 '18 at 01:21
  • 2
    `-save-temps` is interesting as it dumps in one go the exact code generated code, whereas the other option of calling the compiler with `-S` means compiling twice, and possibly with different options. **But** `-save-temps` dumps all in the current directory, which is kind of messy. Looks like it is more intended as a debug option for GCC rather than a tool to inspect your code. – Stéphane Gourichon Jan 22 '20 at 18:16
  • 1
    @StéphaneGourichon: That's correct; more for debugging / creating compiler bug reports than for this use-case. I never use `-save-temps` for looking at how some source compiled to asm, either `-masm=intel -S -o- | less`, disassemble the `.o` or executable, or put it on https://godbolt.org/. – Peter Cordes May 09 '20 at 19:20
53

Using the -S switch to GCC on x86 based systems produces a dump of AT&T syntax, by default, which can be specified with the -masm=att switch, like so:

gcc -S -masm=att code.c

Whereas if you'd like to produce a dump in Intel syntax, you could use the -masm=intel switch, like so:

gcc -S -masm=intel code.c

(Both produce dumps of code.c into their various syntax, into the file code.s respectively)

In order to produce similar effects with objdump, you'd want to use the --disassembler-options= intel/att switch, an example (with code dumps to illustrate the differences in syntax):

 $ objdump -d --disassembler-options=att code.c
 080483c4 <main>:
 80483c4:   8d 4c 24 04             lea    0x4(%esp),%ecx
 80483c8:   83 e4 f0                and    $0xfffffff0,%esp
 80483cb:   ff 71 fc                pushl  -0x4(%ecx)
 80483ce:   55                      push   %ebp
 80483cf:   89 e5                   mov    %esp,%ebp
 80483d1:   51                      push   %ecx
 80483d2:   83 ec 04                sub    $0x4,%esp
 80483d5:   c7 04 24 b0 84 04 08    movl   $0x80484b0,(%esp)
 80483dc:   e8 13 ff ff ff          call   80482f4 <puts@plt>
 80483e1:   b8 00 00 00 00          mov    $0x0,%eax
 80483e6:   83 c4 04                add    $0x4,%esp 
 80483e9:   59                      pop    %ecx
 80483ea:   5d                      pop    %ebp
 80483eb:   8d 61 fc                lea    -0x4(%ecx),%esp
 80483ee:   c3                      ret
 80483ef:   90                      nop

and

$ objdump -d --disassembler-options=intel code.c
 080483c4 <main>:
 80483c4:   8d 4c 24 04             lea    ecx,[esp+0x4]
 80483c8:   83 e4 f0                and    esp,0xfffffff0
 80483cb:   ff 71 fc                push   DWORD PTR [ecx-0x4]
 80483ce:   55                      push   ebp
 80483cf:   89 e5                   mov    ebp,esp
 80483d1:   51                      push   ecx
 80483d2:   83 ec 04                sub    esp,0x4
 80483d5:   c7 04 24 b0 84 04 08    mov    DWORD PTR [esp],0x80484b0
 80483dc:   e8 13 ff ff ff          call   80482f4 <puts@plt>
 80483e1:   b8 00 00 00 00          mov    eax,0x0
 80483e6:   83 c4 04                add    esp,0x4
 80483e9:   59                      pop    ecx
 80483ea:   5d                      pop    ebp
 80483eb:   8d 61 fc                lea    esp,[ecx-0x4]
 80483ee:   c3                      ret    
 80483ef:   90                      nop
Toby Speight
  • 23,550
  • 47
  • 57
  • 84
amaterasu
  • 970
  • 6
  • 8
34

godbolt is a very useful tool, they list only has C++ compilers but you can use -x c flag in order to get it treat the code as C. It will then generate an assembly listing for your code side by side and you can use the Colourise option to generate colored bars to visually indicate which source code maps to the generated assembly. For example the following code:

#include <stdio.h>

void func()
{
  printf( "hello world\n" ) ;
}

using the following command line:

-x c -std=c99 -O3

and Colourise would generate the following:

enter image description here

Arnie97
  • 905
  • 5
  • 17
Shafik Yaghmour
  • 143,425
  • 33
  • 399
  • 682
  • It would be nice to know how godbolt filters work: .LC0, .text, //, and Intel. Intel is easy `-masm=intel` but what about the rest? – Z boson Feb 22 '17 at 08:01
  • I guess it is explained here http://stackoverflow.com/a/38552509/2542702 – Z boson Feb 22 '17 at 08:02
  • godbolt do support C (along with a ton of other languages like Rust, D, Pascal...). It's just that there are much fewer C compilers, so it's still better to use C++ compilers with `-x c` – phuclv Apr 27 '19 at 09:34
  • Why are the strings different between the source and the assembly? The newline has been stripped at the end – OmarL Mar 19 '21 at 10:38
23

Did you try gcc -S -fverbose-asm -O source.c then look into the generated source.s assembler file ?

The generated assembler code goes into source.s (you could override that with -o assembler-filename ); the -fverbose-asm option asks the compiler to emit some assembler comments "explaining" the generated assembler code. The -O option asks the compiler to optimize a bit (it could optimize more with -O2 or -O3).

If you want to understand what gcc is doing try passing -fdump-tree-all but be cautious: you'll get hundreds of dump files.

BTW, GCC is extensible thru plugins or with MELT (a high level domain specific language to extend GCC; which I abandoned in 2017)

Basile Starynkevitch
  • 1
  • 16
  • 251
  • 479
  • maybe mention that the output will be in `source.s`, since a lot of people would expect a printout on the console. – RubenLaguna Jul 02 '15 at 08:41
  • 1
    @ecerulm: `-S -o-` dumps to stdout. `-masm=intel` is helpful if you want to use NASM/YASM syntax. (but it uses `qword ptr [mem]`, rather than just `qword`, so it's more like Intel/MASM than NASM/YASM). http://gcc.godbolt.org/ does a nice job of tidying up the dump: optionally stripping comment-only lines, unused labels, and assembler directives. – Peter Cordes Jan 30 '16 at 23:06
  • 2
    Forgot to mention: If you're looking for "similar to the source but without the noise of store/reload after every source line", then `-Og` is even better than `-O1`. It means "optimize for debugging" and makes asm without too many tricky / hard-to-follow optimizations that does everything the source says. It's been available since gcc4.8, but clang 3.7 still doesn't have it. IDK if they decided against it or what. – Peter Cordes Jan 31 '16 at 13:41
19

You can use gdb for this like objdump.

This excerpt is taken from http://sources.redhat.com/gdb/current/onlinedocs/gdb_9.html#SEC64


Here is an example showing mixed source+assembly for Intel x86:

  (gdb) disas /m main
Dump of assembler code for function main:
5       {
0x08048330 :    push   %ebp
0x08048331 :    mov    %esp,%ebp
0x08048333 :    sub    $0x8,%esp
0x08048336 :    and    $0xfffffff0,%esp
0x08048339 :    sub    $0x10,%esp

6         printf ("Hello.\n");
0x0804833c :   movl   $0x8048440,(%esp)
0x08048343 :   call   0x8048284 

7         return 0;
8       }
0x08048348 :   mov    $0x0,%eax
0x0804834d :   leave
0x0804834e :   ret

End of assembler dump.
agf
  • 148,965
  • 36
  • 267
  • 227
Vishal Sagar
  • 518
  • 2
  • 4
  • 13
  • 1
    archieved link: https://web.archive.org/web/20090412112833/http://sourceware.org:80/gdb/current/onlinedocs/gdb_9.html – vlad4378 May 10 '17 at 17:53
  • And to switch GDB's disassembler to Intel syntax, use `set disassembly-flavor intel` command. – Ruslan May 30 '18 at 16:26
13

Use the -S (note: capital S) switch to GCC, and it will emit the assembly code to a file with a .s extension. For example, the following command:

gcc -O2 -S -c foo.c

codymanix
  • 25,944
  • 18
  • 83
  • 142
4

I haven't given a shot to gcc, but in case of g++. The command below works for me. -g for debug build and -Wa,-adhln is passed to assembler for listing with source code

g++ -g -Wa,-adhln src.cpp

DAG
  • 347
  • 2
  • 7
  • It works for gcc too! -Wa,... is for command line options for the assembler part (execute in gcc/g++ after C/++ compilation). It invokes as internally (as.exe in Windows). See >as --help as command line to see more help – Hartmut Schorrig Apr 17 '20 at 15:28
0

use -Wa,-adhln as option on gcc or g++ to produce a listing output to stdout.

-Wa,... is for command line options for the assembler part (execute in gcc/g++ after C/++ compilation). It invokes as internally (as.exe in Windows). See

>as --help

as command line to see more help for the assembler tool inside gcc