Binutils

mohitmishra786/low-level-dev-skills/skills/binaries/binutils

作者 mohitmishra786bdc58472fa9f无许可证253 个星标收录于 2026年10月9日更新于 2026年10月9日仓库3个月前更新

GNU binutils skill for binary manipulation and analysis. Use when using ar for static libraries, strip or objcopy for binary processing, addr2line for converting addresses to source locations, strings for text extraction, or c++filt for C++ name demangling. Activates on queries about ar, strip, objcopy, addr2line, strings, c++filt, ranlib, or binary post-processing tasks.

AI 生成的概览

指导代理使用 GNU binutils 工具进行二进制操作、静态库管理、剥离、地址映射和符号还原。

功能
该技能为 GNU binutils 工具集提供命令指导,涵盖用于静态库管理的 ar、用于二进制处理的 strip 和 objcopy、用于地址到源码映射的 addr2line、用于 C++ 符号还原的 c++filt,以及用于文本提取的 strings。它还包含 readelf 和 objdump 的快速参考,以及交叉编译版 binutils 的说明。它产出的是命令示例和工作流程,而非可执行脚本。
适用场景
适用于处理已编译二进制文件的场景,例如创建或检查静态库、剥离调试信息、将崩溃地址转换为源码行、还原 C++ 符号或提取可打印字符串。它也适用于使用带目标前缀 binutils 的交叉编译工具链。
运行要求
需要在系统上安装 GNU binutils 工具(ar、strip、objcopy、addr2line、c++filt、strings、ranlib)。该技能不附带脚本,仅为说明文档,并附有可选的参考速查表。

GNU Binutils

Purpose

Guide agents through the binutils toolset for binary manipulation: static libraries, stripping, address-to-source mapping, and symbol demangling.

Triggers

  • "How do I create a static library?"
  • "How do I strip a binary but keep a debug file?"
  • "I have an address from a crash — how do I find the source line?"
  • "How do I demangle a C++ symbol name?"
  • "How do I extract/replace sections in a binary?"

Workflow

1. ar — static library management

bash
# Create static libraryar rcs libfoo.a foo.o bar.o baz.o
# List contentsar t libfoo.a
# Extract an objectar x libfoo.a foo.o
# Add/replace an objectar r libfoo.a newbar.o
# Delete an objectar d libfoo.a oldbar.o
# Show symbol indexnm libfoo.a
# Rebuild symbol index (after modifying archive externally)ranlib libfoo.a

For LTO archives: use gcc-ar/gcc-ranlib or llvm-ar instead of plain ar.

2. strip — remove debug info

bash
# Strip all debug info (reduce binary size)strip --strip-all prog
# Strip only debug sections (keep symbol table)strip --strip-debug prog
# Strip unneeded symbols (keep needed for linking)strip --strip-unneeded prog
# In-placestrip prog
# To a new filestrip -o prog.stripped prog

3. objcopy — binary section manipulation

bash
# Separate debug info from binaryobjcopy --only-keep-debug prog prog.debugobjcopy --strip-debug prog
# Add debuglink (GDB finds prog.debug automatically)objcopy --add-gnu-debuglink=prog.debug prog
# Convert binary to another formatobjcopy -O binary prog prog.bin      # raw binary (embedded)objcopy -O srec prog prog.srec       # Motorola S-record
# Add a section from a fileobjcopy --add-section .resources=data.bin prog
# Remove a sectionobjcopy --remove-section .comment prog
# Change section flagsobjcopy --set-section-flags .data=alloc,contents,load,readonly prog
# Embed a binary file as a symbolobjcopy -I binary -O elf64-x86-64 \    --rename-section .data=.rodata,alloc,load,readonly,data,contents \    data.bin data.o# Then link data.o; access via _binary_data_bin_start / _binary_data_bin_end

4. addr2line — address to source

bash
# Convert a crash address to source:lineaddr2line -e prog -f 0x400a12# Output:# my_function# /home/user/src/main.c:42
# Multiple addressesaddr2line -e prog -f 0x400a12 0x400b34 0x400c56
# Inline frames (-i)addr2line -e prog -f -i 0x400a12
# Common use: pipe from backtrace outputcat crash.log | grep '0x[0-9a-f]' | grep -o '0x[0-9a-f]*' | \  addr2line -e prog -f -i

Requires the binary to have debug info (compiled with -g). For stripped binaries, use the unstripped version or a .debug file.

5. c++filt — demangle C++ symbols

bash
# Demangle a single symbolc++filt _ZN3foo3barEv# Output: foo::bar()
# Demangle from nm outputnm prog | c++filt
# Demangle from crash logcat crash.log | c++filt

Alternative: nm -C prog (demangle directly in nm).

6. strings — extract printable strings

bash
strings prog                    # all strings >= 4 charsstrings -n 8 prog               # minimum length 8strings -t x prog               # with offset (hex)strings -t d prog               # with offset (decimal)
# Search for specific stringsstrings prog | grep "version"strings prog | grep "Copyright"

7. readelf and objdump quick reference

(Full coverage in skills/binaries/elf-inspection)

bash
# Symbol lookup for crash address (alternative to addr2line)objdump -d -M intel prog | grep -A5 "400a12:"
# Find which object file defines a symbolobjdump -t prog | grep my_function

8. Cross-binutils

For cross-compilation, use the target-prefixed versions:

bash
aarch64-linux-gnu-strip progaarch64-linux-gnu-objcopy --only-keep-debug prog prog.debugaarch64-linux-gnu-addr2line -e prog 0x400a12arm-none-eabi-nm libfirmware.a

For a complete command cheatsheet covering all tools (ar, strip, objcopy, addr2line, strings, c++filt), see references/cheatsheet.md [blocked].

Related skills

  • Use skills/binaries/elf-inspection for readelf, nm, ldd, objdump inspection
  • Use skills/binaries/linkers-lto for linker flags and LTO
  • Use skills/debuggers/core-dumps for debug file management with objcopy --add-gnu-debuglink

来源与署名

来源:mohitmishra786/low-level-dev-skills位于skills/binaries/binutils提交bdc5847

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架