Elf Inspection

mohitmishra786/low-level-dev-skills/skills/binaries/elf-inspection

作者 mohitmishra786bdc58472fa9f无许可证253 个星标收录于 2026年10月9日更新于 2026年10月9日仓库3个月前更新

ELF binary inspection skill for Linux. Use when examining ELF executables or shared libraries with readelf, objdump, nm, or ldd to understand symbol visibility, section layout, dynamic dependencies, build IDs, or relocation entries. Activates on queries about ELF format, shared library dependencies, symbol tables, section sizes, DWARF debug info in binaries, binary bloat analysis, or undefined symbol errors.

AI 生成的概览

指导使用 readelf、objdump、nm 和 ldd 检查 Linux ELF 二进制文件,查看符号、节区和依赖。

功能
该技能提供检查 Linux ELF 可执行文件和共享库的参考工作流。内容涵盖使用 file 和 size 快速概览、使用 ldd 查看动态依赖、使用 nm 查看符号表、使用 readelf 查看节区、头部和重定位,以及使用 objdump 反汇编。还包括二进制加固检查、节区大小膨胀分析、构建 ID 查询,以及未定义符号和二进制过大的诊断流程,并附有速查表参考。
适用场景
适用于检查 ELF 可执行文件或共享库,以了解符号可见性、节区布局、动态依赖、构建 ID 或重定位条目。也用于诊断链接错误,例如未定义引用或运行时找不到符号,检查调试信息是否存在,以及分析二进制文件大小。
运行要求
需要 Linux 二进制分析工具:file、size、ldd、nm、readelf 和 objdump。可选工具为 checksec 和 bloaty,需单独安装。该技能不附带脚本,仅为说明文档,并包含一份速查表参考。

ELF Inspection

Purpose

Guide agents through inspecting Linux ELF binaries: symbol tables, section layout, dynamic linking, debug info, and diagnosing linker errors.

Triggers

  • "What libraries does this binary depend on?"
  • "Why is this binary so large?"
  • "I have an undefined reference or symbol not found at runtime"
  • "How do I check if debug info is in this binary?"
  • "How do I find what symbols a library exports?"
  • "How do I check if a binary is PIE / has RELRO?"

Workflow

1. Quick overview: file and size

bash
file prog                    # type, arch, linkage, stripped or notsize prog                    # section sizes: text, data, bsssize --format=sysv prog      # detailed per-section breakdown

2. Dynamic dependencies: ldd

bash
ldd ./prog                   # show all shared lib dependenciesldd -v ./prog                # verbose: include symbol versions
# Check why a library is loadedldd ./prog | grep libssl
# For a library (not an executable)ldd ./libfoo.so

If ldd shows not found, the shared library is missing from LD_LIBRARY_PATH or /etc/ld.so.conf.

Fix:

bash
export LD_LIBRARY_PATH=/path/to/libs:$LD_LIBRARY_PATH# Or install the library and run ldconfigsudo ldconfig

3. Symbols: nm

bash
nm prog                       # all symbols (T=text, D=data, U=undefined, etc.)nm -D ./libfoo.so             # dynamic symbols onlynm -C prog                    # demangle C++ symbolsnm --defined-only prog        # only defined symbolsnm -u prog                    # only undefined (needed) symbolsnm -S prog                    # include symbol size
# Search for a symbolnm -D /usr/lib/libssl.so | grep SSL_read

Symbol type codes:

  • T / t — text (code): global / local
  • D / d — data (initialised): global / local
  • B / b — BSS (uninitialised): global / local
  • R / r — read-only data: global / local
  • U — undefined (needs to be provided at link time)
  • W / w — weak symbol

4. Sections: readelf

bash
readelf -h prog               # ELF header (arch, type, entry point)readelf -S prog               # all sectionsreadelf -l prog               # program headers (segments)readelf -d prog               # dynamic section (like ldd but raw)readelf -s prog               # symbol tablereadelf -r prog               # relocationsreadelf -n prog               # notes (build ID, ABI tag)readelf --debug-dump=info prog | head -100  # DWARF inforeadelf -a prog               # all of the above

5. Disassembly and source: objdump

bash
# Disassemble all code sectionsobjdump -d progobjdump -d -M intel prog      # Intel syntax
# Disassemble + intermix source (needs -g at compile time)objdump -d -S prog
# Disassemble specific symbolobjdump -d prog | awk '/^[0-9a-f]+ <main>:/,/^$/'
# All sections (including data)objdump -D prog
# Header infoobjdump -f progobjdump -p prog               # private headers (including needed libs)

6. Binary hardening check

bash
# Check for PIE, RELRO, stack canary, NX# Use checksec (install separately)checksec --file=prog
# Manual checks:readelf -h prog | grep Type           # ET_DYN = PIE, ET_EXEC = non-PIEreadelf -d prog | grep GNU_RELRO      # RELRO presentreadelf -d prog | grep BIND_NOW       # full RELROreadelf -s prog | grep __stack_chk    # stack protectorreadelf -l prog | grep GNU_STACK      # NX bit (RW = no exec, RWE = exec stack)

7. Section size analysis (binary bloat)

bash
# Detailed section sizessize --format=sysv prog | sort -k2 -nr | head -20
# Per-object contribution (with -Wl,--print-map or bloaty)# Bloaty (install separately): https://github.com/google/bloatybloaty prog
# Check stripped vs notfile progstrip --strip-all -o prog.stripped progls -lh prog prog.stripped

8. Build ID

Build IDs uniquely identify a binary/library build, enabling debuginfod lookups.

bash
readelf -n prog | grep 'Build ID'# orfile prog | grep BuildID

9. Common diagnosis flows

"undefined symbol at runtime"

bash
# Which library was expected to provide it?nm -D libfoo.so | grep mysymbol# Is the library in the runtime path?ldd ./prog | grep libfoo# Check LD_PRELOAD / LD_LIBRARY_PATH

"binary is too large"

bash
size --format=sysv prog | sort -k2 -nr | headnm -S --defined-only prog | sort -k2 -nr | head -20objdump -d prog | awk '/^[0-9a-f]+ </{fn=$2} /^[0-9a-f]/{count[fn]++} END{for(f in count) print count[f], f}' | sort -nr | head -20

For a quick reference, see references/cheatsheet.md [blocked].

Related skills

  • Use skills/binaries/linkers-lto for linker flags and LTO
  • Use skills/binaries/binutils for ar, strip, objcopy, addr2line
  • Use skills/debuggers/core-dumps for build ID and debuginfod usage

来源与署名

来源:mohitmishra786/low-level-dev-skills位于skills/binaries/elf-inspection提交bdc5847

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架