Skip to main content
The RopChain class represents a complete ROP exploit chain. It holds gadgets, stack values, constraints, and provides methods for chain composition, execution, and payload generation.

Class Definition

Holds ROP chains returned by chain building methods such as rop.set_regs().

Constructor

angr.Project
required
The angr project instance.
ChainBuilder
required
The ChainBuilder instance that created this chain.
angr.SimState | None
Optional symbolic state to use. If None, a blank symbolic state is created.
list[int] | None
List of bad bytes to avoid. Defaults to empty list.
You typically don’t instantiate RopChain directly. Chain building methods like rop.set_regs() return RopChain instances.

Attributes

int
Length of the ROP chain payload in bytes.
list[int]
List of bytes to avoid in the payload.

Chain Composition

Addition Operator

Combines two ROP chains into a single chain. The second chain is appended after the first. Example:
Returns: A new RopChain combining both chains.
Chains with conflicting symbolic constraints cannot be combined. An exception is raised if constraints are unsatisfiable.

Value and Gadget Management

add_value

Adds a value to the chain’s stack.
int | RopValue
required
Value to add to the chain.

add_gadget

Adds a gadget to the chain.
RopGadget
required
The gadget to add.

set_gadgets

Sets the complete list of gadgets for the chain.
list[RopGadget]
required
List of gadgets.

add_constraint

Adds a symbolic constraint to the chain. Useful when the chain contains symbolic values.
claripy.ast.Bool
required
Constraint to add.

Payload Generation

payload_str

Generates the concrete byte string payload for the ROP chain.
list | claripy.ast.Bool | None
Additional constraints to apply when concretizing symbolic values.
int | None
Base address of the binary. Defaults to the main object’s mapped base.
int | None
Timeout in seconds for solving constraints.
Returns: Raw bytes of the ROP payload. Example:

payload_code

Generates Python code that constructs the ROP payload.
list | claripy.ast.Bool | None
Additional constraints for concretization.
bool
default:"True"
Whether to include gadget instructions as comments.
int | None
Timeout in seconds.
Returns: Python code string using p32()/p64() functions. Example:
Output:
Prints the Python code for the payload to stdout.
list | claripy.ast.Bool | None
Additional constraints.
bool
default:"True"
Whether to include instruction comments.

payload_bv

Generates a symbolic bitvector representation of the payload. Returns: Claripy bitvector of the entire payload.

Display Methods

dstr

Generates a detailed string representation of the chain showing gadgets and values. Returns: Human-readable string representation. Example Output:

pp

Pretty-prints the chain using dstr(). Outputs to stdout. Example:

__str__

String representation returns the payload code. Returns: Same as payload_code().

Execution Methods

exec

Symbolically executes the ROP chain and returns the final state.
int | None
Timeout for execution in seconds.
bool
default:"False"
Whether to stop execution at a stack pivot.
Returns: The final angr SimState after executing the chain. Example:

sim_exec_til_syscall

Symbolically executes the chain until a syscall is encountered. Returns: The state at the syscall.

concrete_exec_til_addr

Concretely executes the chain until reaching a specific address.
int
required
Address to execute until.
Returns: The state at the target address.

Utility Methods

copy

Creates a deep copy of the chain. Returns: A new RopChain instance with copied gadgets and values.

set_timeout

Sets the timeout for this chain instance.
int
required
Timeout in seconds.

set_cls_timeout (class method)

Sets the default timeout for all new RopChain instances.
int
required
Default timeout in seconds.

next_pc_idx

Finds the index of the next PC value in the chain. Some gadgets (like pop pc, r1) have the PC not as the last value. Returns: Index of the next PC symbolic value, or None if the chain doesn’t return.

find_symbol

Finds the symbol name for an address.
int
required
Address to look up.
Returns: Symbol name (with @plt suffix if PLT stub) or None.

set_project

Updates the project reference for the chain and all its gadgets.
angr.Project
required
New project instance.

set_builder

Updates the chain builder reference.
ChainBuilder
required
New builder instance.

Complete Example