Skip to main content
The FuncCaller class builds ROP chains that call functions with arguments, automatically handling the target platform’s calling convention.

Overview

Accessed through the ROP instance as rop.func_call(), FuncCaller automatically:
  • Detects the calling convention (System V, Windows x64, ARM AAPCS, etc.)
  • Sets register arguments correctly
  • Handles stack arguments when needed
  • Manages return address to maintain control flow
  • Supports both returning and non-returning calls

Class Definition

Located in angrop/chain_builder/func_caller.py

Public Method

func_call

Builds a ROP chain that calls a function with arguments.
int | str
required
Address or symbol name of the function to call. Can be:
  • Integer address: 0x400123
  • Symbol name: "execve"
  • PLT entry: "printf"
list | tuple
required
List of arguments to pass to the function. Arguments are mapped to registers/stack based on calling convention.
set | None
default:"None"
Set of register names that should not be modified.
bool
default:"True"
Whether the ROP chain should continue after the function returns. If False, generates a shorter chain but loses control flow.
Returns: A RopChain that invokes the function. Raises: RopException if function cannot be called.

ROP Instance Method

Implementation Details

Calling Convention Detection

FuncCaller automatically detects the calling convention: From source code (func_caller.py:28-32):
Supported conventions:
  • x86_64 Linux/BSD: System V AMD64 ABI (rdi, rsi, rdx, rcx, r8, r9, stack)
  • x86_64 Windows: Microsoft x64 (rcx, rdx, r8, r9, stack)
  • x86 (32-bit): cdecl (all stack), fastcall, stdcall
  • ARM: AAPCS (r0-r3, stack)
  • ARM64: AAPCS64 (x0-x7, stack)
  • MIPS: O32, N32, N64

Argument Handling

Register Arguments

From source code (func_caller.py:115-131):

Stack Arguments

From source code (func_caller.py:156-166):

Return Address Handling

Different calling conventions handle returns differently:

Stack-based Return (x86, x86_64, ARM)

Register-based Return (ARM64, MIPS)

From source code (func_caller.py:168-178):

Symbol Resolution

From source code (func_caller.py:189-199):

Usage Examples

Basic Function Call

Multiple Arguments

Using Symbol Names

Calling with Return Value

Non-Returning Calls

Preserving Registers

File Operations Example

Stack Arguments (7+ args on x86_64)

Kernel Function Calls

From angrop’s kernel test suite:

Advanced Features

GOT/PLT Resolution

FuncCaller searches for function pointers: From source code (func_caller.py:48-72):

Indirect Calls (jmp_mem)

When direct calls aren’t possible, FuncCaller uses indirect jumps:
From source code (func_caller.py:223-258):

Calling Convention Details

x86_64 System V

x86 cdecl

ARM AAPCS

Error Handling

”fail to invoke function: ”

Raised when function cannot be called. Solutions:
  1. Ensure find_gadgets(optimize=True) was called
  2. Check if symbol exists: proj.loader.find_symbol(name)
  3. Try needs_return=False for simpler chain
  4. Verify function address is correct

”Symbol does not exist in the binary”

Raised when symbol name is invalid. Solution: Use correct symbol name or address.

”fail to invoke function and return”

Raised when return mechanism cannot be built. Solution: Use needs_return=False or ensure ROP has necessary gadgets.

Performance Considerations

  • Simple calls (self-contained) are faster
  • Complex calls may need multiple gadgets
  • Stack arguments add overhead
  • Return handling adds complexity

Architecture Support

  • x86/x86_64: Full support
  • ARM/ARM64: Full support
  • MIPS: Full support
  • PowerPC: Basic support

See Also