如何正确解析ELF可执行文件的.note.gnu.property节?
ELF解析器中.note*节的解析困惑
我在开发一个ELF解析器作为副项目时,遇到了.note*节的解析问题。根据ELF32和ELF64的文档描述:
这些节包含任意数量的note条目,每个条目都是ELF文件头定义的字节序下的N字节字数组。
其中ELF32对应的N为4,ELF64对应的N为8。
但实际观察到的情况与文档描述存在矛盾:我用gcc 11.4.0编译了一个C语言的Hello World程序,查看其64位ELF文件的.note.gnu.property节,执行readelf -x .note.gnu.property hello.x得到的十六进制输出如下:
Hex dump of section '.note.gnu.property': 0x00000338 04000000 20000000 05000000 474e5500 .... .......GNU. 0x00000348 020000c0 04000000 03000000 00000000 ................ 0x00000358 028000c0 04000000 01000000 00000000 ................
通过readelf -h hello.x可以确认这是一个64位ELF文件:
ELF Header: Magic: 7f 45 4c 46 02 01 01 00 00 00 00 00 00 00 00 00 Class: ELF64 Data: 2's complement, little endian Version: 1 (current) OS/ABI: UNIX - System V ABI Version: 0 Type: DYN (Position-Independent Executable file) Machine: Advanced Micro Devices X86-64 Version: 0x1 Entry point address: 0x1060 Start of program headers: 64 (bytes into file) Start of section headers: 13976 (bytes into file) Flags: 0x0 Size of this header: 64 (bytes) Size of program headers: 56 (bytes) Number of program headers: 13 Size of section headers: 64 (bytes) Number of section headers: 31 Section header string table index: 30
同时,节头信息显示.note.gnu.property节的对齐要求为8字节:
There are 31 section headers, starting at offset 0x3698: Section Headers: [Nr] Name Type Address Offset Size EntSize Flags Link Info Align ... [ 2] .note.gnu.pr[...] NOTE 0000000000000338 00000338 0000000000000030 0000000000000000 A 0 0 8 ...
我尝试按照文档要求,将该节解析为8字节字数组并按8字节边界对齐,结果出现读取越界问题——解析出的namesz为0x2000000004而非预期的0x4,descsz为0x20。实际测试发现,正确的解析方式似乎是无论ELF文件是32位还是64位,都按ELF32的4字节字、4字节边界对齐来解析.note*节,但我无法理解这一行为的原因,怀疑是对文档内容存在误解。
内容的提问来源于stack exchange,提问作者Ledmington
相关产品推荐
相关产品推荐

