Skip to main content
The ChainBuilder class provides high-level methods to generate common ROP chains based on discovered gadgets. It handles register setting, memory operations, function calls, system calls, and more.

Class Definition

Provides functions to generate common ROP chains based on existing gadgets.

Constructor

angr.Project
required
The angr project instance.
list[RopGadget]
required
List of ROP gadgets to use for chain building.
list[PivotGadget]
required
List of stack pivot gadgets.
list[SyscallGadget]
required
List of syscall gadgets.
RopArch
required
Architecture object describing the target platform.
list[int]
required
List of bytes to avoid in the generated chains.
int | None
required
Integer used when popping superfluous registers, or None for symbolic values.
You typically don’t instantiate ChainBuilder directly. Instead, access it through the ROP class, which automatically exposes all ChainBuilder methods.

Register Operations

set_regs

Generates a ROP chain that sets registers to requested values.
set[str] | None
Set of register names to preserve (e.g., {'eax', 'ebx'}).
int | RopValue
Register names mapped to their desired values.
Returns: A RopChain that sets the registers. Example:

move_regs

Generates a ROP chain that moves values from one register to another.
set[str] | None
Set of register names to preserve.
str
Mapping where key is destination register and value is source register name.
Returns: A RopChain that performs the register moves. Example:

Memory Operations

write_to_mem

Generates a ROP chain that writes data to memory.
int | RopValue
required
Address where data should be written.
bytes
required
Data to write to memory.
bytes
default:"b'\\xff'"
Byte used to fill/pad the data if necessary.
Returns: A RopChain that writes the data. Example:

add_to_mem

Generates a ROP chain that adds a value to a memory location.
int | RopValue
required
Memory address to modify.
int | RopValue
required
Value to add to the memory location.
int | None
Size of the data in bits (defaults to architecture word size).
Returns: A RopChain that performs [addr] += value. Example:

mem_xor

Generates a ROP chain that XORs a memory location with a value.
int | RopValue
required
Memory address to modify.
int | RopValue
required
Value to XOR with.
int | None
Size of the operation in bytes.
Returns: A RopChain that performs [addr] ^= value.

mem_add

Generates a ROP chain that adds to a memory location.
int | RopValue
required
Memory address to modify.
int | RopValue
required
Value to add.
int | None
Size of the operation in bytes.
Returns: A RopChain that performs [addr] += value.

mem_or

Generates a ROP chain that performs bitwise OR on a memory location.
int | RopValue
required
Memory address to modify.
int | RopValue
required
Value to OR with.
int | None
Size of the operation in bytes.
Returns: A RopChain that performs [addr] |= value.

mem_and

Generates a ROP chain that performs bitwise AND on a memory location.
int | RopValue
required
Memory address to modify.
int | RopValue
required
Value to AND with.
int | None
Size of the operation in bytes.
Returns: A RopChain that performs [addr] &= value.

Function and System Calls

func_call

Generates a ROP chain that calls a function with specified arguments.
int | str
required
Address or name of the function to call.
list | tuple
required
List or tuple of arguments to pass to the function.
set[str] | None
Set of registers to preserve.
bool
default:"True"
Whether to continue the ROP chain after invoking the function.
Returns: A RopChain that invokes the function. Example:

do_syscall

Generates a ROP chain that performs a system call.
int
required
The syscall number to execute.
list
required
List of register values to set before making the syscall.
bool
default:"True"
Whether to continue the ROP chain after the syscall.
set[str] | None
Set of registers to preserve.
Returns: A RopChain that makes the system call. Example:

execve

Generates a ROP chain that executes the execve system call.
bytes | None
Path of binary to execute. Defaults to b"/bin/sh\x00".
int | None
Address where the path string should be stored.
Returns: A RopChain that executes execve. Example:

sigreturn

Generates a ROP chain that invokes sigreturn/rt_sigreturn and loads registers from a frame.
int | None
Override syscall number if needed.
int
Register values to set in the sigreturn frame.
Returns: A RopChain that performs sigreturn.

sigreturn_syscall

Generates a sigreturn syscall chain with syscall gadget and ROP syscall registers.
int
required
Syscall number for sigreturn.
list
required
Syscall arguments for sigreturn.
int | None
Address to jump to after sigreturn.
Returns: A RopChain object.

Stack Operations

pivot

Generates a ROP chain that performs a stack pivot.
int | RopValue
required
New stack pointer value or register containing it.
Returns: A RopChain that pivots the stack.

shift

Generates a ROP chain to shift the stack pointer by a specific amount.
int
required
Number of bytes to shift the stack pointer.
set[str] | None
Set of registers to preserve.
int
default:"-1"
Index of the next PC value.
Returns: A RopChain that shifts the stack.

retsled

Creates a ret-sled ROP chain where control flow is maintained regardless of entry point.
int
required
Size of the retsled chain in bytes.
set[str] | None
Set of registers to preserve.
Returns: A RopChain consisting of ret gadgets.

Configuration Methods

set_badbytes

Updates the list of bad bytes to avoid in chains.
list[int]
required
List of 8-bit integers.

set_roparg_filler

Updates the filler value for useless register pops.
int | None
required
Filler value or None.

optimize

Optimizes the chain builder by improving register setter and mover capabilities.
int
default:"1"
Number of processes to use for optimization.

Internal Methods

bootstrap

Initializes all internal chain building components. Called automatically after gadget discovery.

check_can_do_write

Checks whether the chain builder has the capability to write to memory. Sets internal _can_do_write flag.

Usage Through ROP Class

All ChainBuilder methods are automatically exposed through the ROP class: