A field guide to the ELF paper trail

Which ELF spec should I actually read?

Every document at refspecs.linuxfoundation.org/elf/, plus Sun's Linker and Libraries Guide and the modern x86-64 psABI — sorted into read it, skim it, keep as reference, and don't bother. Metadata below was verified by downloading each PDF.

Read it Skim it Reference only Skip unless targeting it Duplicate file

01The one idea that removes the confusion

There is no single "ELF specification". ELF is defined in layers, and every file in that directory sits on exactly one layer. Once you know which layer a document belongs to, the whole list stops looking like a pile of near-duplicates.

Layer 1 — gABI (generic ABI) The processor-independent core: ELF header, sections, segments, symbol table, relocation mechanics, dynamic linking, program loading. This is "ELF" proper — Chapters 4 and 5 of the System V ABI. ~90% of what you need to master is here.
Layer 2 — psABI (processor supplement) Fills in the blanks the gABI deliberately leaves open for each CPU: the e_machine value, the actual relocation types (R_X86_64_PC32…), calling convention, stack layout, PLT/GOT shape, TLS model. One document per architecture.
Layer 3 — OS / vendor supplement What a specific OS adds on top: Linux's PT_GNU_STACK, .gnu.hash, symbol versioning, DT_GNU_; Solaris' filters, direct bindings, SUNW_ sections. Not in the gABI, not in the psABI.
Layer 4 — the reality layer What linkers and loaders actually implement. elf.h, glibc/elf/dl-.c, readelf -a, bfd/elf64-x86-64.c. The specs are quiet or out of date on plenty of things the toolchain does every day.
💡 The short answer To master ELF you need three documents, not nineteen: the gABI Chapters 4 & 5 (layer 1), the x86-64 psABI v1.0 (layer 2), and Sun's Linker and Libraries Guide (layer 3 + the best prose explanation of dynamic linking ever written). Everything else in that directory is a different CPU, an older draft, or a literal duplicate file.

02The whole directory at a glance

All 17 PDFs + 1 subdirectory at refspecs.linuxfoundation.org/elf/. Note the server timestamps all read 2015-01-28 — that is when the mirror was frozen, not the document dates. Real dates below come from inside each PDF.

FileWhat it really isLayerReal datePagesVerdict
elf.pdfTIS Executable and Linking Format Specification v1.2 — the famous standalone "ELF book"1May 1995106Read it
gabi41.pdfSystem V ABI, Edition 4.1 (SCO) — the printed generic ABI11997271Skim it
gabi4+/gABI 4.1+ living draft, HTML, Ch.4 & 5 only — this mirror is the 24 April 2001 snapshot12001 snapHTMLRead it
elfspec.pdfTIS Portable Formats Specification v1.1 — ELF + DWARF 1.1 + OMF in one bundle1Oct 1993262Skim it
TIS1.1.pdfByte-identical to elfspec.pdf (same MD5) — just a second filename1Oct 1993262Duplicate
abi386-4.pdfSystem V ABI Intel386 Supplement, 4th Ed. — the 32-bit x86 psABI21997377Reference
x86_64-abi-0.99.pdfAMD64 psABI Draft 0.99.6 — the version everyone cited for a decade2Jul 2012128Superseded
x86_64-abi-0.98.pdfAMD64 psABI Draft 0.982Sep 2006—Historical
x86_64-abi-0.95.pdfAMD64 psABI Draft 0.952Jan 2005—Historical
x86_64-abi-0.21.pdfx86-64 psABI Draft 0.21 — earliest one kept here2Sep 200268Historical
x86_64-SysV-psABI.pdfByte-identical to x86_64-abi-0.21.pdf (same MD5) — misleadingly generic name2Sep 200268Duplicate
IA64-SysV-psABI.pdfIntel Itanium processor-specific ABI, doc 245370-0032May 200172Dead arch
elfspec_ppc.pdfSystem V ABI PowerPC Supplement (Zucker/SunSoft, Karhi/IBM)2Sep 1995150If PPC
mipsabi.pdfSystem V ABI MIPS RISC Supplement, 3rd Ed. (SCO)21996258If MIPS
ARMELF.pdfARM ELF, doc SWS ESPC 0003 B-02 — the newer of the two2Jun 200142Obsolete
ARMELFA08.pdfARM ELF, doc SWS ESPC 0003 A-08 — older revision of the same spec2Sep 199944Obsolete
elf-pa.pdfPA-RISC ELF supplement v1.43, incl. HP/HP-UX extensions2+3Oct 199714Dead arch
m8-16eabi.pdfMotorola 8/16-bit embedded ABI (68HC05/08/11/12/16) v2.02199821Niche
index.htmlThe directory page itself———n/a

* Both ARM files are superseded by ARM's current ELF for the Arm Architecture (ABI-AA / aaelf32, aaelf64) on developer.arm.com.

⚠️ Two files in that directory are literal duplicates — verified by checksum Half of the "so many files!" feeling is this: duplicate names and four archived drafts of one document.

03The documents that matter, in detail

TIS ELF Specification v1.2

Read it — start here
refspecs.linuxfoundation.org/elf/elf.pdf
TIS Committee · May 1995 · 106 pages · Layer 1 · Frozen 1995

The classic. Three chapters — Object Files, Program Loading & Dynamic Linking, C Library — extracted from the System V ABI and its Intel386 supplement and republished standalone. It is short, exceptionally clearly written, and it is the document every ELF tutorial, blog post, and man 5 elf page is secretly paraphrasing.

The catch: it is ELF32 only. There is no Elf64_Ehdr in it, no ELFCLASS64 discussion, nothing about the many later additions (extended section numbering, SHT_GNU_*, TLS, DT_GNU_HASH, section groups).

Verdict: read it cover to cover — it's a weekend, not a month — but read it knowing it is the 1995 picture. Then patch your mental model with the living gABI below. Nothing in it is wrong; it's just the 32-bit subset.

gABI 4.1+ — System V ABI, living DRAFT (Ch. 4 & 5)

Read it — the real reference
sco.com/developers/gabi/latest/contents.html · mirror: refspecs.linuxfoundation.org/elf/gabi4+/contents.html
SCO → Caldera → Xinuos · latest draft: 10 June 2013 · HTML · Layer 1 · Most current gABI

This is the canonical modern definition of ELF. Only Chapters 4 (Object Files) and 5 (Program Loading and Dynamic Linking) were ever maintained after Edition 4.1 — those are precisely the ELF chapters — and they accumulated 16 years of amendments: Elf64_ types, SHT_GROUP, SHN_XINDEX extended numbering, STT_TLS / PT_TLS, PT_GNU_, SHF_COMPRESSED, symbol visibility (STV_HIDDEN…), the reserved OS/processor ranges, and the registry of e_machine values.

Version trap The LF mirror gabi4+/ is the 24 April 2001 snapshot. The SCO/Xinuos site serves the 10 June 2013 one. Same URL shape, 12 years apart — always prefer the sco.com one, and read its Revision History page, which is a superb changelog of how ELF grew.
Verdict: read after the TIS book, then keep it open permanently. It's the diff between "ELF in 1995" and "ELF as your linker implements it."

ELF Object File Format v4.3 DRAFT — Xinuos

Read it — the newest gABI
gabi.xinuos.com/elf.pdf
Xinuos, Inc. · 4 September 2025 · 83 pages · Layer 1 · Newest of all

Not on the refspecs mirror at all, so most people never find it. Xinuos took the gABI ELF chapters, reformatted them as a proper standalone PDF, and put out v4.3 for public review in 2025. It is the same material as the living draft above, better typeset and slightly further along.

Verdict: if you want one modern PDF of the core spec, this is it. Use the HTML gABI when you want to link to a specific paragraph, this when you want to read.

AMD64 psABI v1.0 (x86-64)

Read it — your CPU's half
gitlab.com/x86-psABIs/x86-64-ABI · the abi.pdf CI artifact you linked
Lu, Matz, Girkar, Hubička, Jaeger, Mitchell · 12 March 2025, Version 1.0 · 154 pages · Layer 2 · Current & maintained

After 20 years of "Draft 0.9x", the x86-64 psABI finally shipped a 1.0. This is where the things the gABI refuses to say live: the SysV calling convention (the INTEGER/SSE/MEMORY argument classification algorithm), the red zone, %rbp/stack frame rules, the full relocation table, the PLT/GOT/IFUNC machinery, all four TLS models, the medium/large code models, and the LP64 vs ILP32 (x32) split.

The URL you have is a CI job artifact — those expire. Prefer the Releases page or build abi.pdf from the LaTeX sources in the repo.

Verdict: essential, and it replaces x86_64-abi-0.99.pdf on the refspecs mirror (Draft 0.99.6, 2012). Read ch. 3 (low-level system info) and ch. 4–5 closely; chapters on Fortran etc. you can ignore.

Sun/Oracle — Linker and Libraries Guide

Read it — the missing manual
filibeto.org/sun/lib/solaris10-docs/817-1984.pdf
Sun Microsystems · Part No. 817‑1984‑10, January 2005 · 352 pages · Layers 1+3+4 · Solaris 10 era

The single best explanatory ELF document ever written, and the one people most often miss. The formal specs tell you what a field is; this tells you what the link-editor and the runtime linker do with it and why. Chapter 6 is a full ELF reference in its own right, but the real value is the surrounding narrative: symbol resolution order, interposition, lazy binding step by step, RPATH/RUNPATH search rules, versioning (Sun invented ELF symbol versioning; glibc adopted it), initialization/finalization ordering, relocation processing.

Verdict: read chapters 1–6 even though you're on Linux. Mentally tag the SUNW_/filter/direct-binding parts as Solaris-only. It will teach you more working ELF intuition than any other single PDF here.

System V ABI Edition 4.1 (gabi41.pdf)

Skim — historical base
refspecs.linuxfoundation.org/elf/gabi41.pdf · also sco.com/developers/devspecs/gabi41.pdf
The Santa Cruz Operation · 1997 · 271 pages · Layer 1 · Superseded by the 4.1+ draft

The complete printed generic ABI — and "generic ABI" meant far more than ELF: system libraries, the C library interface, formats and protocols, the whole System V application environment. Chapters 4 and 5 are the ELF part, and those are exactly the chapters that were later carved out and maintained as the 4.1+ living draft.

Verdict: don't read it as your ELF spec — it's 1997 and pre-ELF64. Skim Ch. 4–5 once if you like seeing the original wording, then use the 4.1+ draft instead. Genuinely useful only for archaeology: "was this field always here, or added later?"

TIS Portable Formats Spec v1.1 (elfspec.pdf = TIS1.1.pdf)

Skim — for the DWARF half
refspecs.linuxfoundation.org/elf/elfspec.pdf
TIS Committee · October 1993 · 262 pages · Layer 1 · Oldest here

The bundle elf.pdf was later extracted from: ELF (v1.1) + DWARF Debugging Information Format v1.1 + OMF (Intel's Object Module Format). Its ELF section is an older revision than elf.pdf's v1.2.

Verdict: skip its ELF part (use v1.2), and don't use its DWARF part either — DWARF 1 is long dead; go to dwarfstd.org for DWARF 5. Worth 10 minutes only for the historical context of how ELF, DWARF and OMF were standardized together.

Intel386 psABI, 4th Edition (abi386-4.pdf)

Reference
refspecs.linuxfoundation.org/elf/abi386-4.pdf
SCO · 1997 · 377 pages · Layer 2 · Superseded

The 32-bit x86 processor supplement — R_386_32, R_386_PC32, R_386_GOTPC, the cdecl calling convention, the classic PLT layout. If you ever read 32-bit disassembly or wonder why the x86-64 psABI keeps saying "differences from the Intel386 ABI", this is the other half of that sentence.

Verdict: look things up in it; don't read it. For live 32-bit work use the maintained i386 psABI on GitLab (or psABI-i386 v1.1) instead — this 1997 edition predates TLS and modern PIC conventions.

04What's outdated, and what replaced it

The refspecs mirror is an archive frozen in January 2015. It is excellent for finding historical documents and terrible as a source of current truth. The mapping:

If you have…StatusUse instead
elf/gabi4+/ (2001 snapshot)12 years behindgabi/latest (2013) or Xinuos v4.3 (2025)
gabi41.pdf (1997)Pre-ELF64Same as above — the 4.1+ draft is its successor
elf.pdf — TIS 1.2 (1995)32-bit only, but still worth readingRead it, then diff against the current gABI
x86_64-abi-0.99.pdf (2012)Supersededx86-64 psABI v1.0 (2025)
x86_64-SysV-psABI.pdfTrap: it's Draft 0.21 from 2002Same — v1.0 on GitLab
abi386-4.pdf (1997)Historicali386 psABI on GitLab
ARMELF*.pdf (1999/2001)ObsoleteARM ABI-AA aaelf32 / aaelf64 on developer.arm.com
817-1984.pdf (Solaris 10, 2005)Still excellentOptionally the Oracle Solaris 11 edition (E26506, 2013)
Old x86-64.org/documentation/abi.pdf linksDead hostGitLab x86-psABIs — the project moved
⚠️ The biggest gap: none of these describe Linux The gABI reserves ranges for OS extensions; Linux fills them in and documents them essentially nowhere authoritative. PT_GNU_STACK, PT_GNU_RELRO, PT_GNU_PROPERTY, .gnu.hash, DT_GNU_HASH, STB_GNU_UNIQUE, R_X86_64_IRELATIVE/IFUNC, GNU symbol versioning, build-IDs, DT_RELR — for these your real references are /usr/include/elf.h, the binutils and glibc sources, the generic-abi mailing list, and MaskRay's blog. Expect to read code, not specs.

05A concrete path to mastering ELF

Roughly in order. Steps 1–4 are the core; everything after is depth.

Read man 5 elf once, then forget itIt's a field-by-field cheat sheet, great for recall, useless for understanding. It's also where your list of sources came from — that bibliography is the man page's "SEE ALSO", not a curriculum.
Read TIS ELF v1.2 (elf.pdf) end to end106 pages. This builds the actual mental model: sections vs. segments, the two views of the same file, the symbol table, how relocation works, how the dynamic linker bootstraps. Do it with readelf -a /bin/ls open in another window.
Read the current gABI Ch. 4 & 5, plus its Revision HistoryXinuos v4.3 PDF or sco.com/developers/gabi/latest. This is where you pick up ELF64, TLS, section groups, visibility, compressed sections, extended section indices — everything the 1995 book predates.
Read the x86-64 psABI v1.0, chapters 3–5Now relocation stops being abstract. You'll understand why -fPIC changes codegen, what the GOT and PLT physically are, what R_X86_64_GOTPCRELX relaxation means, and how the four TLS models differ.
Read Sun's Linker and Libraries Guide, ch. 1–6The "why" layer. Symbol resolution and interposition, lazy binding, versioning, init/fini ordering, runpath semantics. This is what turns spec knowledge into linker intuition.
Read /usr/include/elf.h straight through~3000 lines. It is, in practice, the most complete and most current ELF "spec" on your machine — every constant from every supplement plus all the GNU extensions no document covers.
Build things and read the toolsParse an ELF yourself in C or Python; write a tiny static linker; hand-craft a minimal ELF executable; then read glibc/elf/rtld.c and dl-reloc.c. readelf -a, objdump -dr, eu-readelf, LD_DEBUG=all ./prog are your microscope.
Follow the living edgeThe generic-abi group is where new ELF features are actually proposed and argued (this is where SHF_COMPRESSED, DT_RELR, PT_GNU_PROPERTY came from). MaskRay's articles on linkers and relocations are the best modern writing on the subject.
✅ If you only keep four bookmarks