This release is a pre-release and may not be stable for production use.
objectfile
Parse ELF, Mach-O, PE, and WebAssembly binaries (plus COFF and XCOFF) from Python:
read their format metadata, imported and exported symbols, shared-library dependencies,
and symbol tables. objectfile is a fast, typed extension built with
PyO3 on top of the read API of the Rust
object crate.
Files are memory-mapped, not read into memory, so even very large binaries only page in what you actually touch.
Install
$ pip install objectfile
Wheels are built with the stable ABI (abi3), so a single wheel per platform supports
CPython 3.12 and newer.
Quickstart
import objectfile
obj = objectfile.parse_file("/bin/ls")
# Metadata
obj.format # Format.Elf
obj.architecture # Architecture.X86_64
obj.is_64 # True
obj.endianness # Endianness.Little
obj.kind # ObjectKind.Dynamic
# Shared-library dependencies (DT_NEEDED / dylibs / imported DLLs)
list(obj.libraries()) # ['libc.so.6', ...]
# Imported and exported symbols (dynamic-linking view)
for imp in obj.imports():
print(imp.name, imp.library, imp.is_weak)
for exp in obj.exports():
print(exp.name, hex(exp.address) if exp.address is not None else None)
# Symbol tables (symbol-table view)
undefined = [s for s in obj.symbols() if s.is_undefined]
for sym in obj.dynamic_symbols():
print(sym.name, sym.kind, sym.scope)
All collections (imports(), exports(), libraries(), symbols(),
dynamic_symbols()) are methods returning lazy iterators - pass them to list(),
sorted(), or a comprehension.
You can also parse an in-memory buffer:
obj = objectfile.parse(open("/bin/ls", "rb").read())
Demangling symbols
Symbol names are returned raw (mangled), e.g. _ZN3std2io5Write9write_fmt. To turn
them into readable signatures, pair objectfile with
pycxxfilt, which demangles C++ and Rust symbols
(including the IA-64/Itanium and MSVC schemes):
import objectfile
import pycxxfilt
obj = objectfile.parse_file("/bin/ls")
for sym in obj.dynamic_symbols():
if sym.name:
print(pycxxfilt.demangle(sym.name))
Command line (unstable)
A small objectfile command prints a summary of a file:
$ objectfile /bin/ls
format: Elf
architecture: X86_64
bits: 64
endianness: Little
kind: Dynamic
libraries (1):
libc.so.6
imports: 128
exports: 0
Add --imports, --exports, or --symbols to list those entries, or run it as
python -m objectfile <path>. With the cli extra installed
(pip install objectfile[cli], which pulls in
pycxxfilt), --demangle renders C++/Rust symbol
names in a readable form.
The CLI and its output format are unstable and may change at any time. Do not parse this output in scripts - use the Python API instead.
API
parse(data: bytes) -> ObjectFile- parse a buffer.parse_file(path) -> ObjectFile- memory-map a file (stroros.PathLike) and parse it.parseaccepts any buffer-protocol object (bytes,bytearray,memoryview,mmap, ...).ObjectFile- propertiesformat,architecture,is_64,endianness,kind; methodsimports(),exports(),libraries(),symbols(),dynamic_symbols(), each returning a lazy iterator.Import-name,ordinal,library,is_weak.Export-name,ordinal,address,is_weak,version,version_hidden.Symbol-name,address,size,kind,scope,is_undefined,is_global,is_weak,section_index,version,version_hidden.Import,Export, andSymbolare comparable, hashable, and ordered by name, sosorted(...)works; they are also directly constructible.- Enums:
Format,Architecture,Endianness,ObjectKind,SymbolKind,SymbolScope.
imports()/exports() are the dynamic-linking tables (what the loader resolves);
symbols()/dynamic_symbols() are the symbol tables (every symbol) - complementary
views. Invalid input raises ObjectFileError (a subclass of ValueError); a missing
file raises the usual OSError (e.g. FileNotFoundError).
Symbol versions (ELF)
Exports and dynamic symbols carry the GNU symbol version: .version (e.g.
GLIBCXX_3.4.22) and .version_hidden (False for a default version - nm's @@ -
and True for a non-default one - @). It is set on exports() and
dynamic_symbols(); the full symbols() table (.symtab) is unversioned. This is
ELF-specific; Mach-O, PE, and wasm have no equivalent per-symbol versioning, so
version is None there. ELF version-node marker symbols (the pseudo-symbols named
after a version node) are filtered out of exports(), but remain in
dynamic_symbols(), which is the raw symbol-table view.
Enum members stringify to their bare name for display/serialization: str(obj.format)
is "Elf" (while repr keeps Format.Elf).
License
Dual-licensed under either of Apache-2.0 or MIT at
your option - the same terms as the upstream object crate.
Metadata
Release files for objectfile 0.0.1a1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| objectfile-0.0.1a1.tar.gz | 45.9 kB | Details |
Built distributions (wheels)
Total release size: 3.4 MB
Release files / objectfile-0.0.1a1.tar.gz
| Download URL | objectfile-0.0.1a1.tar.gz |
|---|---|
| Size | 45.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
206804a0303ff21d3e72af756ab2c7d035276c5ccca87bd02bae98f8d39c0fd2
|
|
BLAKE2b-256 checksum How to use checksums |
77060b5171ef11a3c3acabf5136c5fb7c3ba4d98c608b3b3b578965840ecacb8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / objectfile-0.0.1a1-cp314-cp314t-win_amd64.whl
| Download URL | objectfile-0.0.1a1-cp314-cp314t-win_amd64.whl |
|---|---|
| Size | 265.9 kB |
| Tags | CPython 3.14 CPython 3.14 free-threading Windows x86-64 |
|
SHA-256 checksum How to use checksums |
6c2663339292a2a4e09325ce8ff6e085908a6f52ef5b76ff8e5bc405036453bd
|
|
BLAKE2b-256 checksum How to use checksums |
f7032f33c87e6a1c0041042a0373e5e5033e12fee46a9ab8d405abcda1a0b3a1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / objectfile-0.0.1a1-cp314-cp314t-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | objectfile-0.0.1a1-cp314-cp314t-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 365.8 kB |
| Tags | CPython 3.14 CPython 3.14 free-threading Linux glibc 2.17+ x86-64 |
|
SHA-256 checksum How to use checksums |
5689808bebed3a94c9aede7fabe98b1146ab8dbe616dd4d1ac5374900ce7a0e1
|
|
BLAKE2b-256 checksum How to use checksums |
db308fe6670e7d41a3de63ef2c9339f5d6dc10049eef0273372996833b156822
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / objectfile-0.0.1a1-cp314-cp314t-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
| Download URL | objectfile-0.0.1a1-cp314-cp314t-manylinux_2_17_aarch64.manylinux2014_aarch64.whl |
|---|---|
| Size | 350.1 kB |
| Tags | CPython 3.14 CPython 3.14 free-threading Linux glibc 2.17+ ARM64 |
|
SHA-256 checksum How to use checksums |
0a77eef94ed6d94f6e9409797682776fabfb89d7cd595d3a0d22dc49fb92edee
|
|
BLAKE2b-256 checksum How to use checksums |
ec9179825af5a67798d2403ff589cfa5cceeaa70aac7bf9fa121a01a0ae45a1a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / objectfile-0.0.1a1-cp314-cp314t-macosx_11_0_arm64.whl
| Download URL | objectfile-0.0.1a1-cp314-cp314t-macosx_11_0_arm64.whl |
|---|---|
| Size | 337.1 kB |
| Tags | CPython 3.14 CPython 3.14 free-threading macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
3b64b2d0493db70f076602530237068ee30d5496cf0737477079bc5462c81da4
|
|
BLAKE2b-256 checksum How to use checksums |
45ecf973090fcb7d3b7a6fbdf008cbe7dd92e9798baf288d2c8bdb0670e92d30
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / objectfile-0.0.1a1-cp314-cp314t-macosx_10_12_x86_64.whl
| Download URL | objectfile-0.0.1a1-cp314-cp314t-macosx_10_12_x86_64.whl |
|---|---|
| Size | 341.3 kB |
| Tags | CPython 3.14 CPython 3.14 free-threading macOS 10.12+ x86-64 |
|
SHA-256 checksum How to use checksums |
b46e12783a5c434bfb63ae1fa8285851444eb8ceba98adb7cd3dd60479e5de6f
|
|
BLAKE2b-256 checksum How to use checksums |
5de964081fea5809a7a16d0979ad2e2a264cdc2847f968e3faff5180b05588fe
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / objectfile-0.0.1a1-cp312-abi3-win_amd64.whl
| Download URL | objectfile-0.0.1a1-cp312-abi3-win_amd64.whl |
|---|---|
| Size | 265.1 kB |
| Tags | CPython 3.12 Windows x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
e6a278c2abc8809526221324b92b2650fde904909507f0f9560b00e92e80a606
|
|
BLAKE2b-256 checksum How to use checksums |
53112f3ea1b4d05742d192982eef5371c072f6dbe931f1cf4875a7f863e7c87e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / objectfile-0.0.1a1-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | objectfile-0.0.1a1-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 367.4 kB |
| Tags | CPython 3.12 Linux glibc 2.17+ x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
bcd350f8a63e21a48848a6efa8a8469ae7de3468898728c697d83bdeb671af70
|
|
BLAKE2b-256 checksum How to use checksums |
4242f0984f0986edafe6a233ef764d044ce9fd43e43d61403b0a615c33f44df3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / objectfile-0.0.1a1-cp312-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
| Download URL | objectfile-0.0.1a1-cp312-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl |
|---|---|
| Size | 351.2 kB |
| Tags | CPython 3.12 Linux glibc 2.17+ ARM64 abi3 |
|
SHA-256 checksum How to use checksums |
d0d8a85567921b103e0f227fe2b9a85ba19caa452a4ca0905a54288c3f4af161
|
|
BLAKE2b-256 checksum How to use checksums |
74b36f9e682e7f4ba0c034710c64526cbffd1c08a986be247d7f6668fb9e28ab
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / objectfile-0.0.1a1-cp312-abi3-macosx_11_0_arm64.whl
| Download URL | objectfile-0.0.1a1-cp312-abi3-macosx_11_0_arm64.whl |
|---|---|
| Size | 336.1 kB |
| Tags | CPython 3.12 abi3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
af53820a15ca5dc2d45e40025c331e8a716edf2192c892678416dad3e11d7539
|
|
BLAKE2b-256 checksum How to use checksums |
96ee24ef635babe4a7c430da3dba1f4c5c993aa6884efc41a13ca30a588bc196
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / objectfile-0.0.1a1-cp312-abi3-macosx_10_12_x86_64.whl
| Download URL | objectfile-0.0.1a1-cp312-abi3-macosx_10_12_x86_64.whl |
|---|---|
| Size | 342.1 kB |
| Tags | CPython 3.12 abi3 macOS 10.12+ x86-64 |
|
SHA-256 checksum How to use checksums |
03fd694b12671a0d13e370afaf0e347fc9e6e9ab0ba91a6b227698dd71f716ad
|
|
BLAKE2b-256 checksum How to use checksums |
5862164283693de7e4162b7c95969579bde5afcf65b83d8fa173d1a332ed3641
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency log