Skip to main content

ElfBinary

Struct ElfBinary 

Source
pub struct ElfBinary {
    pub load_address: u64,
    pub segments: Vec<LoadSegment>,
    pub analysis: ElfAnalysis,
    pub architecture: Arch,
    pub needed_libraries: Vec<String>,
}
Expand description

A parsed and loaded ELF binary.

Every PT_LOAD segment is recorded as a mapped region. File-backed bytes are preserved per segment, and any p_memsz > p_filesz tail is modeled as implicit zero-fill rather than materialized up front.

ElfBinary::analysis is populated by two analysis passes run at parse time:

  • Entrypoint: e_entry from the ELF header.
  • Known functions: all STT_FUNC symbols found in .symtab or .dynsym.

Fields§

§load_address: u64§segments: Vec<LoadSegment>§analysis: ElfAnalysis§architecture: Arch§needed_libraries: Vec<String>

Shared-library sonames from the .dynamic section’s DT_NEEDED entries, in link order (e.g. libc.so.6).

Implementations§

Source§

impl ElfBinary

Source

pub fn parse(file_bytes: &[u8]) -> Result<Self, ElfError>

Parse an ELF binary from raw file bytes.

Records every PT_LOAD segment as a mapped region, reads the entrypoint from the ELF header, and collects all STT_FUNC symbols from .symtab and .dynsym.

Trait Implementations§

Source§

impl BinaryFormat for ElfBinary

Source§

fn is_known_read_only(&self, addr: u64) -> bool

ELF program headers carry PF_W, so a mapped segment without it is proven read-only for the lifetime of the process.

Source§

fn entry_points(&self) -> Vec<u64>

Entry points are the ELF entrypoint plus all known function starts.

Source§

fn entrypoint(&self) -> Option<u64>

The ELF entry point (e_entry from the header).

Source§

fn load_address(&self) -> u64

The lowest virtual address mapped by this binary image.
Source§

fn architecture(&self) -> Arch

Name of the architecture, should use embedded information from known binary format, or raw values from the blob.
Source§

fn os(&self) -> TargetOs

The operating system this binary targets, inferred from the container format. Defaults to TargetOs::Unknown; PE returns Windows, ELF Linux.
Source§

fn byte_at(&self, addr: u64) -> Option<u8>

Return the byte mapped at addr, or None if the address is unmapped.
Source§

fn bytes_at(&self, addr: u64) -> Option<&[u8]>

Return the contiguous bytes available at addr. Read more
Source§

fn is_executable(&self, addr: u64) -> bool

Return true if addr lies in an executable region of this binary image. Defaults to “mapped” for formats that don’t track per-region permissions; formats with permission information (e.g. ELF segment flags) should override this.
Source§

fn segment_bounds(&self, addr: u64) -> Option<(u64, u64)>

The [start, end) bounds of the mapped region containing addr, if any. Used to key per-segment facts (e.g. executability propositions) so repeated queries in one region collapse to a single entry. Defaults to None for formats that do not expose their segments.
Source§

fn is_known_writable(&self, addr: u64) -> bool

Return true only if addr lies in a region known to be writable (from the container’s segment flags). Passes that fold a value out of initialized memory use this to refuse mutable memory — e.g. a GOT slot the dynamic linker overwrites at load time. Defaults to false (“not proven writable”); Blob keeps the default.
Source§

fn linked_libraries(&self) -> Vec<String>

Library names this binary links against: ELF DT_NEEDED sonames, PE import-directory DLL names (original case; matching is case-insensitive). Empty when the format has no such notion (Blob).
Source§

fn mapped_regions(&self) -> Vec<(u64, Vec<u8>, bool, bool)>

Enumerate the binary’s mapped regions as (start, bytes, executable, writable). Read more
Source§

fn symbol_name(&self, addr: u64) -> Option<&str>

Return the symbol name for the function starting at addr, if the binary format has one (e.g. from an ELF symbol table). Returns None for formats with no symbol information.
Source§

fn is_external_symbol(&self, addr: u64) -> bool

Returns true if addr is an external (imported) function stub, e.g. a PLT thunk. The recursive disassembler will not lift the body of external functions. Defaults to false.
Source§

fn import_symbol_name(&self, addr: u64) -> Option<&str>

Return the imported symbol whose resolver slot lives at addr, if any. Read more
Source§

fn import_library(&self, addr: u64) -> Option<&str>

Return the name of the library providing the external function stub at addr: the PE import-directory DLL, or the ELF .gnu.version_r soname the symbol’s version requirement points at. None when the format does not record a per-symbol source library (e.g. an unversioned ELF import).
Source§

fn hex_rows( &self, addr: u64, len: usize, width: usize, ) -> Vec<(u64, Vec<Option<u8>>)>

Return rows of bytes suitable for a hex viewer. Read more
Source§

fn contains(&self, addr: u64) -> bool

Return true if addr is mapped by this binary image.
Source§

fn read_bytes(&self, addr: u64, n: usize) -> Option<Vec<u8>>

Read n bytes at virtual address addr. Read more
Source§

fn read_uint(&self, addr: u64, size: usize) -> Option<u64>

Read a little-endian unsigned integer of size bytes (1..=8) at addr. Read more
Source§

fn read_cstring(&self, addr: u64, max_len: Option<usize>) -> Option<Vec<u8>>

Read a null-terminated C string at virtual address addr, returning the bytes up to (but not including) the null terminator. Read more
Source§

fn read_printable_cstring( &self, addr: u64, max_len: Option<usize>, ) -> Option<Vec<u8>>

Read a null-terminated C string at virtual address addr, requiring every byte before the null terminator to be printable ASCII. Read more
Source§

impl Clone for ElfBinary

Source§

fn clone(&self) -> ElfBinary

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for ElfBinary

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.