RopEffect and encapsulate gadget properties, transitions, and behaviors.
RopGadget
The base class for all ROP gadgets.Class Definition
Constructor
int
required
Address where the gadget starts.
Attributes
int
Address of the gadget.
angr.Project | None
Reference to the angr project.
str | None
Type of gadget transition:
"pop_pc"- Returns via ret,jmp [sp+X],pop pc, orretn(self-contained)"jmp_reg"- Jumps to a register value (requires prior register setting)"jmp_mem"- Jumps to a memory location (requires prior memory setup)
int | None
For
pop_pc gadgets: offset from stack pointer to PC value. For ret instructions, this is stack_change - arch.bytes.str | None
For
jmp_reg gadgets: name of the register that contains the jump target.any
For
jmp_mem gadgets: memory location that contains the jump target.Inherited Attributes from RopEffect
RopGadget inherits many attributes fromRopEffect that describe the gadget’s behavior:
int
Change in stack pointer after gadget execution.
set[str]
Set of registers modified by the gadget.
dict
Dictionary mapping registers to their pop offsets from the stack.
list
List of register-to-register moves performed by the gadget.
dict
Dictionary showing which registers each output register depends on.
dict
Dictionary showing which registers directly control each output register.
list
List of memory write operations performed.
list
List of memory read operations performed.
list
List of memory modification operations (add, sub, xor, etc.).
bool
Whether the gadget contains conditional branches.
bool
Whether the gadget is an “out-of-place” gadget (non-standard behavior).
list[int]
List of basic block addresses that make up the gadget.
Properties
self_contained
- It has no conditional branches
- Its transit type is
"pop_pc" - It’s not an out-of-place (oop) gadget
Methods
dstr
"pop rax; pop rbx; ret".
pp
copy
__str__
- Address
- Stack change
- Changed/popped registers
- Register moves
- Register dependencies and controllers
- Memory operations (reads, writes, changes)
__repr__
"<Gadget 0x400123>".
PivotGadget
Represents a stack pivot gadget that can arbitrarily control the stack pointer.Class Definition
Constructor
int
required
Address where the pivot gadget starts.
Additional Attributes
int
Stack pointer change before the pivot occurs.
int
Stack pointer change after the pivot occurs.
set[str]
Set of registers that control the new stack pointer value.
set
Set of stack values that control the new stack pointer.
Properties
sp_controllers
sp_reg_controllers and sp_stack_controllers.
Returns: Complete set of stack pointer controllers.
Methods
__str__
__repr__
"<PivotGadget 0x400789>".
copy
SyscallGadget
Represents a system call gadget.Class Definition
- With return:
syscall; ret - Without return:
syscall; xxxx
Constructor
int
required
Address where the syscall gadget starts.
Additional Attributes
RopGadget | None
Optional prologue gadget that executes before the syscall.
Properties
can_return
transit_type is not None).
Returns: Whether the gadget returns after the syscall.
Methods
__str__
__repr__
"<SyscallGadget 0x400456>".
copy
FunctionGadget
Represents a function call gadget.Class Definition
Constructor
int
required
Address of the function.
str
required
Symbol name of the function.
Additional Attributes
str
Name/symbol of the function.
Methods
dstr
"<system>" or "<func_0x400123>" if no symbol.