Binutils

mohitmishra786/low-level-dev-skills/skills/binaries/binutils

作者 mohitmishra786bdc58472fa9f無授權條款253 個星標收錄於 2026年10月9日更新於 2026年10月9日儲存庫3 個月前更新

GNU binutils skill for binary manipulation and analysis. Use when using ar for static libraries, strip or objcopy for binary processing, addr2line for converting addresses to source locations, strings for text extraction, or c++filt for C++ name demangling. Activates on queries about ar, strip, objcopy, addr2line, strings, c++filt, ranlib, or binary post-processing tasks.

AI 產生的概覽

引導代理使用 GNU binutils 工具進行二進位操作、靜態函式庫管理、剝離、位址對應與符號還原。

功能
此技能為 GNU binutils 工具集提供指令指引,涵蓋用於靜態函式庫管理的 ar、用於二進位處理的 strip 與 objcopy、用於位址對應原始碼的 addr2line、用於 C++ 符號還原的 c++filt,以及用於擷取文字的 strings。它也包含 readelf 與 objdump 的快速參考,以及交叉編譯版 binutils 的說明。它產出的是指令範例與工作流程,而非可執行指令碼。
適用情境
適用於處理已編譯二進位檔的情境,例如建立或檢查靜態函式庫、剝離除錯資訊、將當機位址轉換為原始碼行、還原 C++ 符號或擷取可列印字串。它也適用於使用帶目標前綴 binutils 的交叉編譯工具鏈。
執行需求
需要在系統上安裝 GNU binutils 工具(ar、strip、objcopy、addr2line、c++filt、strings、ranlib)。此技能不附帶指令碼,僅為說明文件,並附有選用的參考速查表。

GNU Binutils

Purpose

Guide agents through the binutils toolset for binary manipulation: static libraries, stripping, address-to-source mapping, and symbol demangling.

Triggers

  • "How do I create a static library?"
  • "How do I strip a binary but keep a debug file?"
  • "I have an address from a crash — how do I find the source line?"
  • "How do I demangle a C++ symbol name?"
  • "How do I extract/replace sections in a binary?"

Workflow

1. ar — static library management

bash
# Create static libraryar rcs libfoo.a foo.o bar.o baz.o
# List contentsar t libfoo.a
# Extract an objectar x libfoo.a foo.o
# Add/replace an objectar r libfoo.a newbar.o
# Delete an objectar d libfoo.a oldbar.o
# Show symbol indexnm libfoo.a
# Rebuild symbol index (after modifying archive externally)ranlib libfoo.a

For LTO archives: use gcc-ar/gcc-ranlib or llvm-ar instead of plain ar.

2. strip — remove debug info

bash
# Strip all debug info (reduce binary size)strip --strip-all prog
# Strip only debug sections (keep symbol table)strip --strip-debug prog
# Strip unneeded symbols (keep needed for linking)strip --strip-unneeded prog
# In-placestrip prog
# To a new filestrip -o prog.stripped prog

3. objcopy — binary section manipulation

bash
# Separate debug info from binaryobjcopy --only-keep-debug prog prog.debugobjcopy --strip-debug prog
# Add debuglink (GDB finds prog.debug automatically)objcopy --add-gnu-debuglink=prog.debug prog
# Convert binary to another formatobjcopy -O binary prog prog.bin      # raw binary (embedded)objcopy -O srec prog prog.srec       # Motorola S-record
# Add a section from a fileobjcopy --add-section .resources=data.bin prog
# Remove a sectionobjcopy --remove-section .comment prog
# Change section flagsobjcopy --set-section-flags .data=alloc,contents,load,readonly prog
# Embed a binary file as a symbolobjcopy -I binary -O elf64-x86-64 \    --rename-section .data=.rodata,alloc,load,readonly,data,contents \    data.bin data.o# Then link data.o; access via _binary_data_bin_start / _binary_data_bin_end

4. addr2line — address to source

bash
# Convert a crash address to source:lineaddr2line -e prog -f 0x400a12# Output:# my_function# /home/user/src/main.c:42
# Multiple addressesaddr2line -e prog -f 0x400a12 0x400b34 0x400c56
# Inline frames (-i)addr2line -e prog -f -i 0x400a12
# Common use: pipe from backtrace outputcat crash.log | grep '0x[0-9a-f]' | grep -o '0x[0-9a-f]*' | \  addr2line -e prog -f -i

Requires the binary to have debug info (compiled with -g). For stripped binaries, use the unstripped version or a .debug file.

5. c++filt — demangle C++ symbols

bash
# Demangle a single symbolc++filt _ZN3foo3barEv# Output: foo::bar()
# Demangle from nm outputnm prog | c++filt
# Demangle from crash logcat crash.log | c++filt

Alternative: nm -C prog (demangle directly in nm).

6. strings — extract printable strings

bash
strings prog                    # all strings >= 4 charsstrings -n 8 prog               # minimum length 8strings -t x prog               # with offset (hex)strings -t d prog               # with offset (decimal)
# Search for specific stringsstrings prog | grep "version"strings prog | grep "Copyright"

7. readelf and objdump quick reference

(Full coverage in skills/binaries/elf-inspection)

bash
# Symbol lookup for crash address (alternative to addr2line)objdump -d -M intel prog | grep -A5 "400a12:"
# Find which object file defines a symbolobjdump -t prog | grep my_function

8. Cross-binutils

For cross-compilation, use the target-prefixed versions:

bash
aarch64-linux-gnu-strip progaarch64-linux-gnu-objcopy --only-keep-debug prog prog.debugaarch64-linux-gnu-addr2line -e prog 0x400a12arm-none-eabi-nm libfirmware.a

For a complete command cheatsheet covering all tools (ar, strip, objcopy, addr2line, strings, c++filt), see references/cheatsheet.md [blocked].

Related skills

  • Use skills/binaries/elf-inspection for readelf, nm, ldd, objdump inspection
  • Use skills/binaries/linkers-lto for linker flags and LTO
  • Use skills/debuggers/core-dumps for debug file management with objcopy --add-gnu-debuglink

來源與署名

來源:mohitmishra786/low-level-dev-skills位於skills/binaries/binutils提交bdc5847

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架