如何查找Linux ELF目标文件x.o中调用.rodata段my-string的函数?
my-string Static String in x.o (No Source Code) Alright, let's break down how to track down which functions in your object file x.o reference the my-string string from the .rodata section. Since we don't have source code, we'll rely on Linux binary analysis tools like readelf, objdump, and gdb to get the job done.
Step 1: Locate the exact address/offset of my-string
First, we need to pinpoint where my-string lives in the .rodata section. You already used readelf -p .rodata x.o to see the string—now let's get its precise offset:
- Run
objdump -s -j .rodata x.oto dump the.rodatasection with byte offsets and string representations. Look formy-stringin the output; the leftmost column will show its starting offset within.rodata(e.g.,0x00000010). - Alternatively, use
readelf -S x.oto get the base offset of the.rodatasection (check theAddrcolumn). Add this base offset to the string's internal offset to get the full address ofmy-stringwithin the object file (e.g., if.rodatastarts at0x200and the string is at offset0x10, the full address is0x210).
Step 2: Find references to this address in code
Now that we have the string's address, we can look for which functions reference it using these methods:
Method 1: Disassemble all functions and search for the address
- Run
objdump -d x.oto disassemble all executable sections (.text) of the object file. This will show every function's assembly code, labeled with function names (e.g.,foo:at the start of a function). - Pipe the output to grep to find lines that reference your string's address, and show surrounding context to identify the parent function:
Theobjdump -d x.o | grep -B5 -A5 0x210-B5and-A5flags show 5 lines before and after the match, so you can easily see which function the reference belongs to.
Method 2: Check the relocation table
Object files use relocations to track references between sections. We can leverage this to find where .rodata (and thus my-string) is referenced:
- Run
readelf -r x.oto list all relocation entries. Look for entries where theSectioncolumn points to.rodata, and theOffsetcolumn shows an address in the.textsection (executable code). - For each matching relocation entry, use
objdump -d x.o --start-address=<offset>to disassemble the code at that offset. This will directly show you the function containing the reference tomy-string.
Method 3: Use GDB to inspect references interactively
If you prefer an interactive tool, GDB can help you zero in on the referencing functions:
- Launch GDB with the object file:
gdb x.o - Find the address of
my-stringby searching the.rodatasection:find &.rodata, &.rodata + sizeof(.rodata), "my-string" - Once you have the address (e.g.,
0x210), usex/10i *(&.text)to disassemble the.textsection, or usex/10i <address-from-relocation>to view the surrounding code and identify the parent function. You can also runinfo functionsto list all function symbols and cross-reference their addresses with the references you find.
内容的提问来源于stack exchange,提问作者hes_theman

