SEARCH
NEW RPMS
DIRECTORIES
ABOUT
FAQ
VARIOUS
BLOG

BotDetect - Real-Time Bot Detection API
 
 

MAN page from Trustix modutils-2.4.3-2tr.i586.rpm

KALLSYMS

Section: Linux Module Support (8)
Updated: April 20 2000
Index 

NAME

kallsyms - Extract all kernel symbols for debugging 

SYNOPSIS

kallsyms[-Vh] kernel_filename 

DESCRIPTION

Kallsymsextracts all the non-stack symbols from a kernel and builds a data blobthat can be linked into that kernel for use by debuggers.

A normal kernel only exports symbols that are used by modules.For debugging you may want a list of all the non-stack symbols, notjust the exported ones.kallsymsextracts all sections and symbols from a kernel, constructs a list ofthe sections, symbols and their addresses and writes a relocatableobject containing just the __kallsyms section.After the __kallsyms section is linked into the kernel and the kernelhas been booted, any debugger can use the data in the __kallsymssection to get better symbol resolution.

For example, a debugger can use the __kallsyms data to resolve a kerneladdress to :-

*
The owning kernel or module.
*
The section within the owning code.
*
The nearest symbol.
 

OPTIONS

-V
Print the version of modutils.
-h
Print the help text.
 

LINKER PASSES

To create a kernel containing an accurate __kallsyms section, you haveto make four linker passes instead of the normal single link step.kallsyms and the linker are fast, the three extra steps take a fewseconds on a P200.

1
The initial build of the kernel, without any __kallsyms data.Run kallsyms against the output of this link, creating a relocatableobject which contains all the sections and symbols in the raw kernel.
2
Link the kernel again, this time including the kallsyms output fromstep (1).Adding the __kallsyms section changes the number of sections and manyof the kernel symbol offsets so run kallsyms again against the secondlink, again saving the relocatable output.
3
Link the kernel again, this time including the kallsyms output fromstep (2).Run kallsyms against the latest version of the kernel.The size and position of the __kallsyms section on this run is nowstable, none of the kernel sections or symbols will change after thisrun.The kallsyms output contains the final values of the kernel symbols.
4
Link the final kernel, including the kallsyms output from step (3).
 

DATA FORMAT

The __kallsyms section is a bit unusual.It deliberately has no relocatable data, all "pointers" are representedas byte offsets into the section or as absolute numbers.This means it can be stored anywhere without relocation problems.In particular it can be stored within a kernel image, it can be storedseparately from the kernel image, it can be appended to a module justbefore loading, it can be stored in a separate area etc.

/usr/include/sys/kallsyms.h contains the mappings for the __kallsymsdata. 

Header

*
Size of header.
*
Total size of the __kallsyms data, including strings.
*
Number of sections.This only included sections which are loaded into memory.
*
Offset to the first section entry from start of the __kallsyms header.
*
Size of each section entry, excluding the name string.
*
Number of symbols.
*
Offset to the first symbol entry from the start of the __kallsymsheader.
*
Size of each symbol entry, excluding the name string.
*
Offset to the first string from the start of the __kallsyms header.
*
Start address of the first section[1].
*
End address of the last section[1].
 

Section entry

One entry per loaded section.Since __kallsyms is a loaded section, if the input file contains a__kallsyms section then it is included in this list.

*
Start of the section within the kernel[1].
*
Size of section.
*
Offset to the name of section, from the start of the __kallsymsstrings.
*
Section flags, from the original Elf section.
 

Symbol entry

One per symbol in the input file.Only symbols that fall within loaded sections are stored.

*
Offset to the __kallsyms section entry that this symbol falls within.The offset is from the start of the __kallsyms section entries.
*
Address of the symbol within the kernel[1].The symbols are sorted in ascending order on this field.
*
Offset to the name of symbol, from the start of the __kallsyms strings.
 

Strings

A set of NUL terminated strings.Each name is referenced using an offset from the start of the__kallsyms string area. 

Note [1]

These fields are exceptions to the "everything is an offset" rule.They contain absolute addresses within the kernel. 

SEE ALSO

insmod(8). 

HISTORY

Initial version by Keith Owens <kaosAATTocs.com.au>, April 2000


 

Index

NAME
SYNOPSIS
DESCRIPTION
OPTIONS
LINKER PASSES
DATA FORMAT
Header
Section entry
Symbol entry
Strings
Note [1]
SEE ALSO
HISTORY

This document was created byman2html,using the manual pages.
 
ICM Bot detect detector