FuncCaller class builds ROP chains that call functions with arguments, automatically handling the target platform’s calling convention.
Overview
Accessed through the ROP instance asrop.func_call(), FuncCaller automatically:
- Detects the calling convention (System V, Windows x64, ARM AAPCS, etc.)
- Sets register arguments correctly
- Handles stack arguments when needed
- Manages return address to maintain control flow
- Supports both returning and non-returning calls
Class Definition
angrop/chain_builder/func_caller.py
Public Method
func_call
int | str
required
Address or symbol name of the function to call. Can be:
- Integer address:
0x400123 - Symbol name:
"execve" - PLT entry:
"printf"
list | tuple
required
List of arguments to pass to the function. Arguments are mapped to registers/stack based on calling convention.
set | None
default:"None"
Set of register names that should not be modified.
bool
default:"True"
Whether the ROP chain should continue after the function returns. If False, generates a shorter chain but loses control flow.
RopChain that invokes the function.
Raises: RopException if function cannot be called.
ROP Instance Method
Implementation Details
Calling Convention Detection
FuncCaller automatically detects the calling convention: From source code (func_caller.py:28-32):- x86_64 Linux/BSD: System V AMD64 ABI (rdi, rsi, rdx, rcx, r8, r9, stack)
- x86_64 Windows: Microsoft x64 (rcx, rdx, r8, r9, stack)
- x86 (32-bit): cdecl (all stack), fastcall, stdcall
- ARM: AAPCS (r0-r3, stack)
- ARM64: AAPCS64 (x0-x7, stack)
- MIPS: O32, N32, N64
Argument Handling
Register Arguments
From source code (func_caller.py:115-131):Stack Arguments
From source code (func_caller.py:156-166):Return Address Handling
Different calling conventions handle returns differently:Stack-based Return (x86, x86_64, ARM)
Register-based Return (ARM64, MIPS)
Symbol Resolution
From source code (func_caller.py:189-199):Usage Examples
Basic Function Call
Multiple Arguments
Using Symbol Names
Calling with Return Value
Non-Returning Calls
Preserving Registers
File Operations Example
Stack Arguments (7+ args on x86_64)
Kernel Function Calls
From angrop’s kernel test suite:Advanced Features
GOT/PLT Resolution
FuncCaller searches for function pointers: From source code (func_caller.py:48-72):Indirect Calls (jmp_mem)
When direct calls aren’t possible, FuncCaller uses indirect jumps:Calling Convention Details
x86_64 System V
x86 cdecl
ARM AAPCS
Error Handling
”fail to invoke function: ”
Raised when function cannot be called. Solutions:- Ensure
find_gadgets(optimize=True)was called - Check if symbol exists:
proj.loader.find_symbol(name) - Try
needs_return=Falsefor simpler chain - Verify function address is correct
”Symbol does not exist in the binary”
Raised when symbol name is invalid. Solution: Use correct symbol name or address.”fail to invoke function and return”
Raised when return mechanism cannot be built. Solution: Useneeds_return=False or ensure ROP has necessary gadgets.
Performance Considerations
- Simple calls (self-contained) are faster
- Complex calls may need multiple gadgets
- Stack arguments add overhead
- Return handling adds complexity
Architecture Support
- x86/x86_64: Full support
- ARM/ARM64: Full support
- MIPS: Full support
- PowerPC: Basic support
See Also
- SysCaller - System call invocation
- Function Calls Guide - Usage examples and patterns
- RegSetter - Setting function arguments