Every document at refspecs.linuxfoundation.org/elf/, plus Sun's Linker and Libraries Guide and the modern x86-64 psABI — sorted into read it, skim it, keep as reference, and don't bother. Metadata below was verified by downloading each PDF.
There is no single "ELF specification". ELF is defined in layers, and every file in that directory sits on exactly one layer. Once you know which layer a document belongs to, the whole list stops looking like a pile of near-duplicates.
e_machine value, the actual relocation types (R_X86_64_PC32…), calling convention, stack layout, PLT/GOT shape, TLS model. One document per architecture.PT_GNU_STACK, .gnu.hash, symbol versioning, DT_GNU_; Solaris' filters, direct bindings, SUNW_ sections. Not in the gABI, not in the psABI.elf.h, glibc/elf/dl-.c, readelf -a, bfd/elf64-x86-64.c. The specs are quiet or out of date on plenty of things the toolchain does every day.All 17 PDFs + 1 subdirectory at refspecs.linuxfoundation.org/elf/. Note the server timestamps all read 2015-01-28 — that is when the mirror was frozen, not the document dates. Real dates below come from inside each PDF.
| File | What it really is | Layer | Real date | Pages | Verdict |
|---|---|---|---|---|---|
| elf.pdf | TIS Executable and Linking Format Specification v1.2 — the famous standalone "ELF book" | 1 | May 1995 | 106 | Read it |
| gabi41.pdf | System V ABI, Edition 4.1 (SCO) — the printed generic ABI | 1 | 1997 | 271 | Skim it |
| gabi4+/ | gABI 4.1+ living draft, HTML, Ch.4 & 5 only — this mirror is the 24 April 2001 snapshot | 1 | 2001 snap | HTML | Read it |
| elfspec.pdf | TIS Portable Formats Specification v1.1 — ELF + DWARF 1.1 + OMF in one bundle | 1 | Oct 1993 | 262 | Skim it |
| TIS1.1.pdf | Byte-identical to elfspec.pdf (same MD5) — just a second filename | 1 | Oct 1993 | 262 | Duplicate |
| abi386-4.pdf | System V ABI Intel386 Supplement, 4th Ed. — the 32-bit x86 psABI | 2 | 1997 | 377 | Reference |
| x86_64-abi-0.99.pdf | AMD64 psABI Draft 0.99.6 — the version everyone cited for a decade | 2 | Jul 2012 | 128 | Superseded |
| x86_64-abi-0.98.pdf | AMD64 psABI Draft 0.98 | 2 | Sep 2006 | — | Historical |
| x86_64-abi-0.95.pdf | AMD64 psABI Draft 0.95 | 2 | Jan 2005 | — | Historical |
| x86_64-abi-0.21.pdf | x86-64 psABI Draft 0.21 — earliest one kept here | 2 | Sep 2002 | 68 | Historical |
| x86_64-SysV-psABI.pdf | Byte-identical to x86_64-abi-0.21.pdf (same MD5) — misleadingly generic name | 2 | Sep 2002 | 68 | Duplicate |
| IA64-SysV-psABI.pdf | Intel Itanium processor-specific ABI, doc 245370-003 | 2 | May 2001 | 72 | Dead arch |
| elfspec_ppc.pdf | System V ABI PowerPC Supplement (Zucker/SunSoft, Karhi/IBM) | 2 | Sep 1995 | 150 | If PPC |
| mipsabi.pdf | System V ABI MIPS RISC Supplement, 3rd Ed. (SCO) | 2 | 1996 | 258 | If MIPS |
| ARMELF.pdf | ARM ELF, doc SWS ESPC 0003 B-02 — the newer of the two | 2 | Jun 2001 | 42 | Obsolete |
| ARMELFA08.pdf | ARM ELF, doc SWS ESPC 0003 A-08 — older revision of the same spec | 2 | Sep 1999 | 44 | Obsolete |
| elf-pa.pdf | PA-RISC ELF supplement v1.43, incl. HP/HP-UX extensions | 2+3 | Oct 1997 | 14 | Dead arch |
| m8-16eabi.pdf | Motorola 8/16-bit embedded ABI (68HC05/08/11/12/16) v2.0 | 2 | 1998 | 21 | Niche |
| index.html | The directory page itself | — | — | — | n/a |
elfspec.pdf and TIS1.1.pdf → same MD5 ff488bc5…, 262 pages, both the TIS Portable Formats Spec v1.1.x86_64-SysV-psABI.pdf and x86_64-abi-0.21.pdf → same MD5 7bbafd54…, both Draft 0.21 from 2002. The neutral-looking name is a trap: it is not "the" x86-64 psABI, it is the oldest draft on the server, 23 years stale.The classic. Three chapters — Object Files, Program Loading & Dynamic Linking, C Library — extracted from the System V ABI and its Intel386 supplement and republished standalone. It is short, exceptionally clearly written, and it is the document every ELF tutorial, blog post, and man 5 elf page is secretly paraphrasing.
The catch: it is ELF32 only. There is no Elf64_Ehdr in it, no ELFCLASS64 discussion, nothing about the many later additions (extended section numbering, SHT_GNU_*, TLS, DT_GNU_HASH, section groups).
This is the canonical modern definition of ELF. Only Chapters 4 (Object Files) and 5 (Program Loading and Dynamic Linking) were ever maintained after Edition 4.1 — those are precisely the ELF chapters — and they accumulated 16 years of amendments: Elf64_ types, SHT_GROUP, SHN_XINDEX extended numbering, STT_TLS / PT_TLS, PT_GNU_, SHF_COMPRESSED, symbol visibility (STV_HIDDEN…), the reserved OS/processor ranges, and the registry of e_machine values.
gabi4+/ is the 24 April 2001 snapshot. The SCO/Xinuos site serves the 10 June 2013 one. Same URL shape, 12 years apart — always prefer the sco.com one, and read its Revision History page, which is a superb changelog of how ELF grew.Not on the refspecs mirror at all, so most people never find it. Xinuos took the gABI ELF chapters, reformatted them as a proper standalone PDF, and put out v4.3 for public review in 2025. It is the same material as the living draft above, better typeset and slightly further along.
abi.pdf CI artifact you linkedAfter 20 years of "Draft 0.9x", the x86-64 psABI finally shipped a 1.0. This is where the things the gABI refuses to say live: the SysV calling convention (the INTEGER/SSE/MEMORY argument classification algorithm), the red zone, %rbp/stack frame rules, the full relocation table, the PLT/GOT/IFUNC machinery, all four TLS models, the medium/large code models, and the LP64 vs ILP32 (x32) split.
The URL you have is a CI job artifact — those expire. Prefer the Releases page or build abi.pdf from the LaTeX sources in the repo.
x86_64-abi-0.99.pdf on the refspecs mirror (Draft 0.99.6, 2012). Read ch. 3 (low-level system info) and ch. 4–5 closely; chapters on Fortran etc. you can ignore.The single best explanatory ELF document ever written, and the one people most often miss. The formal specs tell you what a field is; this tells you what the link-editor and the runtime linker do with it and why. Chapter 6 is a full ELF reference in its own right, but the real value is the surrounding narrative: symbol resolution order, interposition, lazy binding step by step, RPATH/RUNPATH search rules, versioning (Sun invented ELF symbol versioning; glibc adopted it), initialization/finalization ordering, relocation processing.
SUNW_/filter/direct-binding parts as Solaris-only. It will teach you more working ELF intuition than any other single PDF here.The complete printed generic ABI — and "generic ABI" meant far more than ELF: system libraries, the C library interface, formats and protocols, the whole System V application environment. Chapters 4 and 5 are the ELF part, and those are exactly the chapters that were later carved out and maintained as the 4.1+ living draft.
The bundle elf.pdf was later extracted from: ELF (v1.1) + DWARF Debugging Information Format v1.1 + OMF (Intel's Object Module Format). Its ELF section is an older revision than elf.pdf's v1.2.
The 32-bit x86 processor supplement — R_386_32, R_386_PC32, R_386_GOTPC, the cdecl calling convention, the classic PLT layout. If you ever read 32-bit disassembly or wonder why the x86-64 psABI keeps saying "differences from the Intel386 ABI", this is the other half of that sentence.
These are seven different CPUs' copies of the same job the x86-64 psABI does for you. They exist on the mirror because the Linux Foundation archived one psABI per architecture the LSB once covered. Reading them teaches you nothing new about ELF itself — the layer-1 content is identical by construction; only relocation types and calling conventions differ.
Two of them are also stale even for their own architecture: ARMELF.pdf (2001) and ARMELFA08.pdf (1999) are two revisions of one old ARM document, both replaced by ARM's current aaelf32/aaelf64. IA64 and PA-RISC are dead architectures.
The refspecs mirror is an archive frozen in January 2015. It is excellent for finding historical documents and terrible as a source of current truth. The mapping:
| If you have… | Status | Use instead |
|---|---|---|
| elf/gabi4+/ (2001 snapshot) | 12 years behind | gabi/latest (2013) or Xinuos v4.3 (2025) |
| gabi41.pdf (1997) | Pre-ELF64 | Same as above — the 4.1+ draft is its successor |
| elf.pdf — TIS 1.2 (1995) | 32-bit only, but still worth reading | Read it, then diff against the current gABI |
| x86_64-abi-0.99.pdf (2012) | Superseded | x86-64 psABI v1.0 (2025) |
| x86_64-SysV-psABI.pdf | Trap: it's Draft 0.21 from 2002 | Same — v1.0 on GitLab |
| abi386-4.pdf (1997) | Historical | i386 psABI on GitLab |
| ARMELF*.pdf (1999/2001) | Obsolete | ARM ABI-AA aaelf32 / aaelf64 on developer.arm.com |
| 817-1984.pdf (Solaris 10, 2005) | Still excellent | Optionally the Oracle Solaris 11 edition (E26506, 2013) |
| Old x86-64.org/documentation/abi.pdf links | Dead host | GitLab x86-psABIs — the project moved |
PT_GNU_STACK, PT_GNU_RELRO, PT_GNU_PROPERTY, .gnu.hash, DT_GNU_HASH, STB_GNU_UNIQUE, R_X86_64_IRELATIVE/IFUNC, GNU symbol versioning, build-IDs, DT_RELR — for these your real references are /usr/include/elf.h, the binutils and glibc sources, the generic-abi mailing list, and MaskRay's blog. Expect to read code, not specs.
Roughly in order. Steps 1–4 are the core; everything after is depth.
man 5 elf once, then forget itIt's a field-by-field cheat sheet, great for recall, useless for understanding. It's also where your list of sources came from — that bibliography is the man page's "SEE ALSO", not a curriculum.elf.pdf) end to end106 pages. This builds the actual mental model: sections vs. segments, the two views of the same file, the symbol table, how relocation works, how the dynamic linker bootstraps. Do it with readelf -a /bin/ls open in another window.sco.com/developers/gabi/latest. This is where you pick up ELF64, TLS, section groups, visibility, compressed sections, extended section indices — everything the 1995 book predates.-fPIC changes codegen, what the GOT and PLT physically are, what R_X86_64_GOTPCRELX relaxation means, and how the four TLS models differ./usr/include/elf.h straight through~3000 lines. It is, in practice, the most complete and most current ELF "spec" on your machine — every constant from every supplement plus all the GNU extensions no document covers.glibc/elf/rtld.c and dl-reloc.c. readelf -a, objdump -dr, eu-readelf, LD_DEBUG=all ./prog are your microscope.SHF_COMPRESSED, DT_RELR, PT_GNU_PROPERTY came from). MaskRay's articles on linkers and relocations are the best modern writing on the subject.