Skip to content
Advertisement

How to calculate the total basic block number in a Linux ELF binary

I’m trying to see how many code blocks are not necessary for common software under common usage scenarios. Is there a static binary analysis tool that can calculate the total basic block number of a Linux ELF that?

Advertisement

Answer

Okay, I wrote a script using Angr to obtain all the basic blocks:

#!/usr/bin/env python3
# A script to dump function and basic block locations, size, etc.
# Install angr (https://docs.angr.io/introductory-errata/install) before use it.
# @author: xiaogw (https://stackoverflow.com/users/1267984/xiaogw)
import angr
import sys

def dump_functions_bbs(p, cfg):
  for key in cfg.kb.functions:
    for bb in cfg.kb.functions[key].blocks:
      print("%s: %s" % (hex(bb.addr), hex(bb.size)))

def main(argv):
  if (len(argv) < 2):
    print("Usage %s <BIN>" % argv[0])
    return 1
  path_to_binary = argv[1]
  p = angr.Project(path_to_binary, load_options={'auto_load_libs': False})
  cfg = p.analyses.CFGFast()
  dump_functions_bbs(p, cfg)

  return 0

if __name__ == '__main__':
  main(sys.argv)
User contributions licensed under: CC BY-SA
4 People found this is helpful
Advertisement