Skip to main content
angrop provides several gadget classes to represent different types of ROP gadgets discovered during analysis. These classes extend RopEffect and encapsulate gadget properties, transitions, and behaviors.

RopGadget

The base class for all ROP gadgets.

Class Definition

Constructor

int
required
Address where the gadget starts.

Attributes

int
Address of the gadget.
angr.Project | None
Reference to the angr project.
str | None
Type of gadget transition:
  • "pop_pc" - Returns via ret, jmp [sp+X], pop pc, or retn (self-contained)
  • "jmp_reg" - Jumps to a register value (requires prior register setting)
  • "jmp_mem" - Jumps to a memory location (requires prior memory setup)
int | None
For pop_pc gadgets: offset from stack pointer to PC value. For ret instructions, this is stack_change - arch.bytes.
str | None
For jmp_reg gadgets: name of the register that contains the jump target.
any
For jmp_mem gadgets: memory location that contains the jump target.

Inherited Attributes from RopEffect

RopGadget inherits many attributes from RopEffect that describe the gadget’s behavior:
int
Change in stack pointer after gadget execution.
set[str]
Set of registers modified by the gadget.
dict
Dictionary mapping registers to their pop offsets from the stack.
list
List of register-to-register moves performed by the gadget.
dict
Dictionary showing which registers each output register depends on.
dict
Dictionary showing which registers directly control each output register.
list
List of memory write operations performed.
list
List of memory read operations performed.
list
List of memory modification operations (add, sub, xor, etc.).
bool
Whether the gadget contains conditional branches.
bool
Whether the gadget is an “out-of-place” gadget (non-standard behavior).
list[int]
List of basic block addresses that make up the gadget.

Properties

self_contained

Returns True if the gadget is self-contained and doesn’t rely on other gadgets. A gadget is self-contained if:
  • It has no conditional branches
  • Its transit type is "pop_pc"
  • It’s not an out-of-place (oop) gadget

Methods

dstr

Returns a disassembly string showing the gadget’s instructions separated by semicolons. Returns: String like "pop rax; pop rbx; ret".

pp

Pretty-prints the disassembly string to stdout.

copy

Creates a deep copy of the gadget. Returns: New RopGadget instance with copied attributes.

__str__

Detailed string representation including:
  • Address
  • Stack change
  • Changed/popped registers
  • Register moves
  • Register dependencies and controllers
  • Memory operations (reads, writes, changes)
Example Output:

__repr__

Returns: String like "<Gadget 0x400123>".

PivotGadget

Represents a stack pivot gadget that can arbitrarily control the stack pointer.

Class Definition

A PivotGadget can control the stack pointer register and performs the pivot exactly once.

Constructor

int
required
Address where the pivot gadget starts.

Additional Attributes

int
Stack pointer change before the pivot occurs.
int
Stack pointer change after the pivot occurs.
set[str]
Set of registers that control the new stack pointer value.
set
Set of stack values that control the new stack pointer.

Properties

sp_controllers

Returns the union of sp_reg_controllers and sp_stack_controllers. Returns: Complete set of stack pointer controllers.

Methods

__str__

Example Output:

__repr__

Returns: String like "<PivotGadget 0x400789>".

copy

Creates a deep copy of the pivot gadget. Returns: New PivotGadget instance.

SyscallGadget

Represents a system call gadget.

Class Definition

Collects two types of syscall gadgets:
  1. With return: syscall; ret
  2. Without return: syscall; xxxx

Constructor

int
required
Address where the syscall gadget starts.

Additional Attributes

RopGadget | None
Optional prologue gadget that executes before the syscall.

Properties

can_return

Returns True if the syscall gadget has a return mechanism (i.e., transit_type is not None). Returns: Whether the gadget returns after the syscall.

Methods

__str__

Example Output:

__repr__

Returns: String like "<SyscallGadget 0x400456>".

copy

Creates a deep copy of the syscall gadget. Returns: New SyscallGadget instance.

FunctionGadget

Represents a function call gadget.

Class Definition

Constructor

int
required
Address of the function.
str
required
Symbol name of the function.

Additional Attributes

str
Name/symbol of the function.

Methods

dstr

Returns a formatted function name. Returns: String like "<system>" or "<func_0x400123>" if no symbol.

Usage Examples

Examining Gadgets

Filtering Gadgets

Detailed Gadget Information