Elf Inspection

mohitmishra786/low-level-dev-skills/skills/binaries/elf-inspection

by mohitmishra786bdc58472fa9fNo license253 starsListed Oct 9, 2026Updated Oct 9, 2026Repository updated 3 months ago

ELF binary inspection skill for Linux. Use when examining ELF executables or shared libraries with readelf, objdump, nm, or ldd to understand symbol visibility, section layout, dynamic dependencies, build IDs, or relocation entries. Activates on queries about ELF format, shared library dependencies, symbol tables, section sizes, DWARF debug info in binaries, binary bloat analysis, or undefined symbol errors.

Instructions onlySoftware Development
AI-generated overview

Guides inspection of Linux ELF binaries using readelf, objdump, nm and ldd to examine symbols, sections and dependencies.

What it does
This skill provides a reference workflow for inspecting Linux ELF executables and shared libraries. It covers quick overviews with file and size, dynamic dependencies with ldd, symbol tables with nm, sections, headers and relocations with readelf, and disassembly with objdump. It also includes binary hardening checks, section-size bloat analysis, build ID lookup, and diagnosis flows for undefined symbols and oversized binaries, plus a cheatsheet reference.
When to use it
Use it when examining ELF executables or shared libraries to understand symbol visibility, section layout, dynamic dependencies, build IDs or relocation entries. It is also meant for diagnosing linker errors such as undefined references or symbols missing at runtime, checking debug info presence, and analyzing binary size.
Requirements
Requires Linux binary analysis tools: file, size, ldd, nm, readelf and objdump. Optional tools mentioned are checksec and bloaty, which must be installed separately. No scripts are shipped; the skill is instructions only, with a reference cheatsheet.

ELF Inspection

Purpose

Guide agents through inspecting Linux ELF binaries: symbol tables, section layout, dynamic linking, debug info, and diagnosing linker errors.

Triggers

  • "What libraries does this binary depend on?"
  • "Why is this binary so large?"
  • "I have an undefined reference or symbol not found at runtime"
  • "How do I check if debug info is in this binary?"
  • "How do I find what symbols a library exports?"
  • "How do I check if a binary is PIE / has RELRO?"

Workflow

1. Quick overview: file and size

bash
file prog                    # type, arch, linkage, stripped or notsize prog                    # section sizes: text, data, bsssize --format=sysv prog      # detailed per-section breakdown

2. Dynamic dependencies: ldd

bash
ldd ./prog                   # show all shared lib dependenciesldd -v ./prog                # verbose: include symbol versions
# Check why a library is loadedldd ./prog | grep libssl
# For a library (not an executable)ldd ./libfoo.so

If ldd shows not found, the shared library is missing from LD_LIBRARY_PATH or /etc/ld.so.conf.

Fix:

bash
export LD_LIBRARY_PATH=/path/to/libs:$LD_LIBRARY_PATH# Or install the library and run ldconfigsudo ldconfig

3. Symbols: nm

bash
nm prog                       # all symbols (T=text, D=data, U=undefined, etc.)nm -D ./libfoo.so             # dynamic symbols onlynm -C prog                    # demangle C++ symbolsnm --defined-only prog        # only defined symbolsnm -u prog                    # only undefined (needed) symbolsnm -S prog                    # include symbol size
# Search for a symbolnm -D /usr/lib/libssl.so | grep SSL_read

Symbol type codes:

  • T / t — text (code): global / local
  • D / d — data (initialised): global / local
  • B / b — BSS (uninitialised): global / local
  • R / r — read-only data: global / local
  • U — undefined (needs to be provided at link time)
  • W / w — weak symbol

4. Sections: readelf

bash
readelf -h prog               # ELF header (arch, type, entry point)readelf -S prog               # all sectionsreadelf -l prog               # program headers (segments)readelf -d prog               # dynamic section (like ldd but raw)readelf -s prog               # symbol tablereadelf -r prog               # relocationsreadelf -n prog               # notes (build ID, ABI tag)readelf --debug-dump=info prog | head -100  # DWARF inforeadelf -a prog               # all of the above

5. Disassembly and source: objdump

bash
# Disassemble all code sectionsobjdump -d progobjdump -d -M intel prog      # Intel syntax
# Disassemble + intermix source (needs -g at compile time)objdump -d -S prog
# Disassemble specific symbolobjdump -d prog | awk '/^[0-9a-f]+ <main>:/,/^$/'
# All sections (including data)objdump -D prog
# Header infoobjdump -f progobjdump -p prog               # private headers (including needed libs)

6. Binary hardening check

bash
# Check for PIE, RELRO, stack canary, NX# Use checksec (install separately)checksec --file=prog
# Manual checks:readelf -h prog | grep Type           # ET_DYN = PIE, ET_EXEC = non-PIEreadelf -d prog | grep GNU_RELRO      # RELRO presentreadelf -d prog | grep BIND_NOW       # full RELROreadelf -s prog | grep __stack_chk    # stack protectorreadelf -l prog | grep GNU_STACK      # NX bit (RW = no exec, RWE = exec stack)

7. Section size analysis (binary bloat)

bash
# Detailed section sizessize --format=sysv prog | sort -k2 -nr | head -20
# Per-object contribution (with -Wl,--print-map or bloaty)# Bloaty (install separately): https://github.com/google/bloatybloaty prog
# Check stripped vs notfile progstrip --strip-all -o prog.stripped progls -lh prog prog.stripped

8. Build ID

Build IDs uniquely identify a binary/library build, enabling debuginfod lookups.

bash
readelf -n prog | grep 'Build ID'# orfile prog | grep BuildID

9. Common diagnosis flows

"undefined symbol at runtime"

bash
# Which library was expected to provide it?nm -D libfoo.so | grep mysymbol# Is the library in the runtime path?ldd ./prog | grep libfoo# Check LD_PRELOAD / LD_LIBRARY_PATH

"binary is too large"

bash
size --format=sysv prog | sort -k2 -nr | headnm -S --defined-only prog | sort -k2 -nr | head -20objdump -d prog | awk '/^[0-9a-f]+ </{fn=$2} /^[0-9a-f]/{count[fn]++} END{for(f in count) print count[f], f}' | sort -nr | head -20

For a quick reference, see references/cheatsheet.md [blocked].

Related skills

  • Use skills/binaries/linkers-lto for linker flags and LTO
  • Use skills/binaries/binutils for ar, strip, objcopy, addr2line
  • Use skills/debuggers/core-dumps for build ID and debuginfod usage

Source and attribution

Source:mohitmishra786/low-level-dev-skillsinskills/binaries/elf-inspectionat commitbdc5847

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal