Skip to main content
The SigreturnBuilder class builds SROP (Sigreturn-Oriented Programming) chains that use the sigreturn syscall to set all registers and control execution flow with a single syscall.

Overview

Sigreturn is a powerful technique that allows setting arbitrary register values including PC and SP in one operation. Accessed through rop.sigreturn(), SigreturnBuilder automatically:
  • Creates properly formatted sigreturn frames
  • Invokes the sigreturn syscall
  • Handles stack pointer calculations
  • Supports chaining after sigreturn
  • Provides execve convenience method

Class Definition

Located in angrop/chain_builder/sigreturn.py

Public Methods

sigreturn

Builds a sigreturn chain that sets arbitrary registers.
Keyword arguments mapping register names to values. All registers can be set including:
  • General purpose: rax, rbx, rcx, etc.
  • Stack pointer: rsp
  • Instruction pointer: rip
  • Flags: rflags (on x64)
Returns: A RopChain containing sigreturn syscall and frame. Raises: RopException if sigreturn is not supported or cannot be built.

sigreturn_syscall

Builds a sigreturn chain that sets up and invokes a specific syscall.
int
required
Syscall number to invoke after sigreturn.
list
required
Arguments for the syscall (mapped to registers per syscall convention).
int | None
default:"None"
New stack pointer value. If provided, allows chaining after the syscall.
Returns: A RopChain that performs sigreturn then invokes the syscall.

sigreturn_execve

Convenience method to invoke execve via sigreturn.
int | None
required
Address containing the path string (e.g., “/bin/sh”).
Returns: A RopChain that spawns a shell via SROP. Raises: RopException if path_addr is None.

ROP Instance Methods

Implementation Details

Sigreturn Frame Structure

Sigreturn uses a frame structure defined by the OS kernel: From the sigreturn module:
Frame layout (x86_64):

Stack Pointer Calculation

SigreturnBuilder calculates where the frame should be placed: From source code (sigreturn.py:18-31):

Frame Placement

From source code (sigreturn.py:132-154):

Usage Examples

Basic Sigreturn

Sigreturn Execve

Sigreturn to Syscall

Complete SROP Chain

Chaining After Sigreturn

Setting Flags

Architecture Support

x86_64 Linux

x86 (32-bit) Linux

ARM Linux

Sigreturn vs Regular ROP

Advantages of SROP

  1. Single operation: Set all registers at once
  2. Minimal gadgets: Only need syscall gadget
  3. Full control: Can set PC, SP, and flags
  4. Badbyte friendly: Frame data can be manipulated

Disadvantages

  1. Frame size: Requires significant stack space (~248 bytes on x64)
  2. Platform specific: Frame layout varies by OS/arch
  3. Limited scenarios: Need control of stack and syscall gadget

Error Handling

”sigreturn is not supported on this architecture”

Raised when architecture doesn’t support sigreturn. Solution: Only Linux on x86/x64/ARM supports sigreturn.

” is not supported!”

Raised when OS is not Linux. Solution: SROP only works on Linux.

”target does not contain syscall gadget!”

Raised when no syscall gadgets exist. Solution: Binary must have syscall; ret or similar.

”Fail to execute sigreturn chain until syscall”

Raised when chain execution fails. Solution: Check gadgets and frame setup.

”path_addr is required for sigreturn_execve”

Raised when path_addr is None. Solution: Provide address with command string.

Frame Pretty Printing

Sigreturn frames are pretty-printed in chain output: From source code (sigreturn.py:153-154):
When you call chain.pp(), the frame is displayed:

Best Practices

  1. Check support: Verify arch.sigreturn_num is not None
  2. Plan stack: Ensure sufficient stack space for frame
  3. Set PC correctly: Point to syscall gadget or next ROP
  4. Use for complex setups: When many registers need setting
  5. Verify frame size: Different architectures have different sizes

Performance Considerations

  • Frame creation is lightweight
  • Stack space requirement is significant
  • Single syscall is very efficient
  • No need for many gadgets

Advanced Techniques

Stack Pivoting with SROP

Kernel SROP

See Also