Expand description
Static inspection of a built x86_64 Linux executable or shared object against a target’s glibc and kernel floors: tier 1 of the testing tiers.
| Tier | How | Reliability |
|---|---|---|
| 1. Inspect (this crate) | Read the ELF file; nothing runs | Exact for symbols, versions, and ELF notes; heuristic for syscalls in code |
| 2. Simulate | Run tests under a seccomp filter or in a container (kernel-abi-tools) | Catches what actually executes; syscall availability and madvise only |
| 3. Qualify | Run on a real host at the target’s minimums (e.g. SLES 12 SP5) | The only qualification |
A scan reports what the file could do, not what it does: it cannot see
syscalls made inside the C library, numbers computed at run time,
libraries loaded with dlopen, new flags on old syscalls, or whether a
program falls back when a call fails. Findings carry a Confidence.
The kernel data is the same that the seccomp profiles are built from
(kernel_abi_tools::syscalls, madvise_advice, and a preset’s
backports), so tiers 1 and 2 cannot disagree about what a kernel has.
Modules§
- elf
- A small, bounds-checked reader for x86_64 ELF64 little-endian executables and shared objects: just what the scan needs. Malformed input returns an error; nothing panics on untrusted bytes.
Structs§
- Finding
- Report
- Scan
Target - What to check against.
Noneskips that side’s checks (host glibc or host kernel), and the report says so.
Enums§
- Confidence
- How a finding was established.
- Severity