ELF Inspection
Purpose
Guide agents through inspecting Linux ELF binaries: symbol tables, section layout, dynamic linking, debug info, and diagnosing linker errors.
Triggers
- "What libraries does this binary depend on?"
- "Why is this binary so large?"
- "I have an
undefined referenceor symbol not found at runtime" - "How do I check if debug info is in this binary?"
- "How do I find what symbols a library exports?"
- "How do I check if a binary is PIE / has RELRO?"
Workflow
1. Quick overview: file and size
2. Dynamic dependencies: ldd
If ldd shows not found, the shared library is missing from LD_LIBRARY_PATH or /etc/ld.so.conf.
Fix:
3. Symbols: nm
Symbol type codes:
T/t— text (code): global / localD/d— data (initialised): global / localB/b— BSS (uninitialised): global / localR/r— read-only data: global / localU— undefined (needs to be provided at link time)W/w— weak symbol
4. Sections: readelf
5. Disassembly and source: objdump
6. Binary hardening check
7. Section size analysis (binary bloat)
8. Build ID
Build IDs uniquely identify a binary/library build, enabling debuginfod lookups.
9. Common diagnosis flows
"undefined symbol at runtime"
"binary is too large"
For a quick reference, see references/cheatsheet.md [blocked].
Related skills
- Use
skills/binaries/linkers-ltofor linker flags and LTO - Use
skills/binaries/binutilsforar,strip,objcopy,addr2line - Use
skills/debuggers/core-dumpsfor build ID and debuginfod usage


