RopChain class represents a complete ROP exploit chain. It holds gadgets, stack values, constraints, and provides methods for chain composition, execution, and payload generation.
Class Definition
rop.set_regs().
Constructor
angr.Project
required
The angr project instance.
ChainBuilder
required
The ChainBuilder instance that created this chain.
angr.SimState | None
Optional symbolic state to use. If None, a blank symbolic state is created.
list[int] | None
List of bad bytes to avoid. Defaults to empty list.
You typically don’t instantiate RopChain directly. Chain building methods like
rop.set_regs() return RopChain instances.Attributes
int
Length of the ROP chain payload in bytes.
list[int]
List of bytes to avoid in the payload.
Chain Composition
Addition Operator
Value and Gadget Management
add_value
int | RopValue
required
Value to add to the chain.
add_gadget
RopGadget
required
The gadget to add.
set_gadgets
list[RopGadget]
required
List of gadgets.
add_constraint
claripy.ast.Bool
required
Constraint to add.
Payload Generation
payload_str
list | claripy.ast.Bool | None
Additional constraints to apply when concretizing symbolic values.
int | None
Base address of the binary. Defaults to the main object’s mapped base.
int | None
Timeout in seconds for solving constraints.
payload_code
list | claripy.ast.Bool | None
Additional constraints for concretization.
bool
default:"True"
Whether to include gadget instructions as comments.
int | None
Timeout in seconds.
p32()/p64() functions.
Example:
print_payload_code
list | claripy.ast.Bool | None
Additional constraints.
bool
default:"True"
Whether to include instruction comments.
payload_bv
Display Methods
dstr
pp
dstr(). Outputs to stdout.
Example:
__str__
payload_code().
Execution Methods
exec
int | None
Timeout for execution in seconds.
bool
default:"False"
Whether to stop execution at a stack pivot.
sim_exec_til_syscall
concrete_exec_til_addr
int
required
Address to execute until.
Utility Methods
copy
set_timeout
int
required
Timeout in seconds.
set_cls_timeout (class method)
int
required
Default timeout in seconds.
next_pc_idx
pop pc, r1) have the PC not as the last value.
Returns: Index of the next PC symbolic value, or None if the chain doesn’t return.
find_symbol
int
required
Address to look up.
@plt suffix if PLT stub) or None.
set_project
angr.Project
required
New project instance.
set_builder
ChainBuilder
required
New builder instance.