• C

Tracing an interrupt-based program

I don't know where I should put this question in. I chose here anyway....
Hi, everyone. I have a problem for you concerning a set of
interrupt-based programs.
Its particulars are as follows:
  1. it contains a driver (written in C) which alters a high
     interrupt vector (i.e. driver.exe) and the main code is in here.

  for example:
      int_60h_entry proc near
           call get_string

      int_60h_entry endp

      get_string proc near   <--- this part is where I want to know of.
      get_string endp

  2. A calling program (i.e 1.exe) calls the interrupt vector

  for example:
       mov ax, 0ah
       int 60h     <--- the debugger traces over this point
       add sp, 4

 p.s: there is an interrupt entry point in the driver, in which there are
      cores and guts that I want to know of.

What I would like to do with these programs is:

   Using Turbo Debugger 5.0 to trace into the interrupt, but debugger
   only traces up to the point where it calls the interrupt (e.g. int 60h).
   Then it steps over it.

Do you guys know how to trace into the interrupt?
,from the calling program to the driver?

Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Assuming that the interrupt routine is in RAM (as opposed to ROM) which you seem to indicate (the driver is written in C), it should be possible.
What I generally do in such circumstances is to find the entry point of the interrupt handler (by looking at the interrupt vector table if need be), then put a breakpoint early in the interrupt handling code. Depending on your debugger and system, the first one may be a poor choice. Try and look down until registers have been saved, and interrupts reenabled (so that the keyboard will work), and put a breakpoint there.


Experts Exchange Solution brought to you by ConnectWise

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
P.S. the interrupt vector for int 60h on a PC will be at address:


Remember that the raw memory contents on Intel process is kind of backward. So if the contents at 0:180 is: DF D0 00 F0, the referenced address for the start of the interrupt routine will be: F000:D0DF

Sorry, for "Intel process" please read "Intel processors"

Get Cisco Certified in IT Security

There’s a high demand for IT security experts and network administrators who can safeguard the data that individuals, corporations, and governments rely on every day. Pursue your B.S. in Network Operations and Security and gain the credentials you need for this high-growth field.

If you are running on a 386 or later, find a copy of PDVIM.EXE
which is available on the depositories.   This is a Public
Domain Virtual Machine which when run will execute your program in a protected mode Dos Box and allows full interrupt and hardware tracing.   You can also get a more powerful registered version, but from your description, the PD version should suffice.   (PDVIM is a command line oriented system, and the debug commands are very similar to DOS's debug.)

You can easily step into every software interrupt using Turbo Debugger. Use following procedure:
Step through the program until the cursor (blue line) is at Int 60h (next step would execute the int).
Now press ALT+F10 and you will see a menu popping up.
Choose "Follow" and press ENTER. You will see now the begin of the INT 60h Handler. Set a breakpoint at the beginning (F2) of the handler (same line).
Now simply let the program run and you will see it will stop at the breakpoint in the interrupt handler. You can now trace through the handler ;).

You probably did this and it is unrelated to your question, but remember to put an 'iret' at the end of your interrupt handler (not just a 'ret').
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.