ELF (Linux / BSD) binary reader in pure OCaml
README.md

ocaml-elf #

ELF (Linux / BSD) binary reader in pure OCaml.

Overview #

ocaml-elf reads 64-bit ELF images -- the executable and object format used by Linux and the BSDs. The on-disk structures (the ELF header, the section header table, and the .symtab symbol table with its string table) are described with the wire combinator library and decoded through bytesrw, so a binary's sections and symbols can be inspected without shelling out to nm, size or readelf.

Unlike Mach-O, ELF symbol records carry an explicit size, so each symbol's byte size is read directly rather than inferred.

It reads 64-bit little-endian images (ELFCLASS64 / ELFDATA2LSB).

Reading #

Elf.of_string parses an image and exposes its architecture, sections and defined symbols. Malformed input is rejected with a message rather than an exception:

# Elf.of_string
    "this text is plainly not an ELF binary; it is just an ordinary sentence."
- : (Elf.t, string) result = Error "ELF: not an ELF image"

On a real binary, Elf.sections and Elf.symbols return the section layout and the section-defined symbols, each tagged with the section-header index that Elf.section_by_index resolves.

Status #

The ELF header, section header table (including the extended numbering encoded in section 0), and the symbol and string tables are parsed and bounds-checked against the input. Undefined, absolute and common symbols are dropped. Only 64-bit little-endian images are read; the format is read, not written.

Licence #

ISC. See LICENSE.md.