Elf Inspection

mohitmishra786/low-level-dev-skills/skills/binaries/elf-inspection

作者 mohitmishra786bdc58472fa9f無授權條款253 個星標收錄於 2026年10月9日更新於 2026年10月9日儲存庫3 個月前更新

ELF binary inspection skill for Linux. Use when examining ELF executables or shared libraries with readelf, objdump, nm, or ldd to understand symbol visibility, section layout, dynamic dependencies, build IDs, or relocation entries. Activates on queries about ELF format, shared library dependencies, symbol tables, section sizes, DWARF debug info in binaries, binary bloat analysis, or undefined symbol errors.

AI 產生的概覽

指導使用 readelf、objdump、nm 和 ldd 檢查 Linux ELF 二進位檔,查看符號、區段與相依性。

功能
此技能提供檢查 Linux ELF 執行檔與共享函式庫的參考工作流程。內容涵蓋使用 file 和 size 快速概覽、使用 ldd 查看動態相依性、使用 nm 查看符號表、使用 readelf 查看區段、標頭與重定位,以及使用 objdump 反組譯。也包含二進位加固檢查、區段大小膨脹分析、建置 ID 查詢,以及未定義符號與二進位檔過大的診斷流程,並附有速查表參考。
適用情境
適用於檢查 ELF 執行檔或共享函式庫,以了解符號可見性、區段配置、動態相依性、建置 ID 或重定位項目。也用於診斷連結錯誤,例如未定義參考或執行時找不到符號,檢查除錯資訊是否存在,以及分析二進位檔大小。
執行需求
需要 Linux 二進位分析工具:file、size、ldd、nm、readelf 和 objdump。選用工具為 checksec 和 bloaty,需另行安裝。此技能不附帶指令碼,僅為說明文件,並包含一份速查表參考。

ELF Inspection

Purpose

Guide agents through inspecting Linux ELF binaries: symbol tables, section layout, dynamic linking, debug info, and diagnosing linker errors.

Triggers

  • "What libraries does this binary depend on?"
  • "Why is this binary so large?"
  • "I have an undefined reference or symbol not found at runtime"
  • "How do I check if debug info is in this binary?"
  • "How do I find what symbols a library exports?"
  • "How do I check if a binary is PIE / has RELRO?"

Workflow

1. Quick overview: file and size

bash
file prog                    # type, arch, linkage, stripped or notsize prog                    # section sizes: text, data, bsssize --format=sysv prog      # detailed per-section breakdown

2. Dynamic dependencies: ldd

bash
ldd ./prog                   # show all shared lib dependenciesldd -v ./prog                # verbose: include symbol versions
# Check why a library is loadedldd ./prog | grep libssl
# For a library (not an executable)ldd ./libfoo.so

If ldd shows not found, the shared library is missing from LD_LIBRARY_PATH or /etc/ld.so.conf.

Fix:

bash
export LD_LIBRARY_PATH=/path/to/libs:$LD_LIBRARY_PATH# Or install the library and run ldconfigsudo ldconfig

3. Symbols: nm

bash
nm prog                       # all symbols (T=text, D=data, U=undefined, etc.)nm -D ./libfoo.so             # dynamic symbols onlynm -C prog                    # demangle C++ symbolsnm --defined-only prog        # only defined symbolsnm -u prog                    # only undefined (needed) symbolsnm -S prog                    # include symbol size
# Search for a symbolnm -D /usr/lib/libssl.so | grep SSL_read

Symbol type codes:

  • T / t — text (code): global / local
  • D / d — data (initialised): global / local
  • B / b — BSS (uninitialised): global / local
  • R / r — read-only data: global / local
  • U — undefined (needs to be provided at link time)
  • W / w — weak symbol

4. Sections: readelf

bash
readelf -h prog               # ELF header (arch, type, entry point)readelf -S prog               # all sectionsreadelf -l prog               # program headers (segments)readelf -d prog               # dynamic section (like ldd but raw)readelf -s prog               # symbol tablereadelf -r prog               # relocationsreadelf -n prog               # notes (build ID, ABI tag)readelf --debug-dump=info prog | head -100  # DWARF inforeadelf -a prog               # all of the above

5. Disassembly and source: objdump

bash
# Disassemble all code sectionsobjdump -d progobjdump -d -M intel prog      # Intel syntax
# Disassemble + intermix source (needs -g at compile time)objdump -d -S prog
# Disassemble specific symbolobjdump -d prog | awk '/^[0-9a-f]+ <main>:/,/^$/'
# All sections (including data)objdump -D prog
# Header infoobjdump -f progobjdump -p prog               # private headers (including needed libs)

6. Binary hardening check

bash
# Check for PIE, RELRO, stack canary, NX# Use checksec (install separately)checksec --file=prog
# Manual checks:readelf -h prog | grep Type           # ET_DYN = PIE, ET_EXEC = non-PIEreadelf -d prog | grep GNU_RELRO      # RELRO presentreadelf -d prog | grep BIND_NOW       # full RELROreadelf -s prog | grep __stack_chk    # stack protectorreadelf -l prog | grep GNU_STACK      # NX bit (RW = no exec, RWE = exec stack)

7. Section size analysis (binary bloat)

bash
# Detailed section sizessize --format=sysv prog | sort -k2 -nr | head -20
# Per-object contribution (with -Wl,--print-map or bloaty)# Bloaty (install separately): https://github.com/google/bloatybloaty prog
# Check stripped vs notfile progstrip --strip-all -o prog.stripped progls -lh prog prog.stripped

8. Build ID

Build IDs uniquely identify a binary/library build, enabling debuginfod lookups.

bash
readelf -n prog | grep 'Build ID'# orfile prog | grep BuildID

9. Common diagnosis flows

"undefined symbol at runtime"

bash
# Which library was expected to provide it?nm -D libfoo.so | grep mysymbol# Is the library in the runtime path?ldd ./prog | grep libfoo# Check LD_PRELOAD / LD_LIBRARY_PATH

"binary is too large"

bash
size --format=sysv prog | sort -k2 -nr | headnm -S --defined-only prog | sort -k2 -nr | head -20objdump -d prog | awk '/^[0-9a-f]+ </{fn=$2} /^[0-9a-f]/{count[fn]++} END{for(f in count) print count[f], f}' | sort -nr | head -20

For a quick reference, see references/cheatsheet.md [blocked].

Related skills

  • Use skills/binaries/linkers-lto for linker flags and LTO
  • Use skills/binaries/binutils for ar, strip, objcopy, addr2line
  • Use skills/debuggers/core-dumps for build ID and debuginfod usage

來源與署名

來源:mohitmishra786/low-level-dev-skills位於skills/binaries/elf-inspection提交bdc5847

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架