Utility Functions
angrop provides a comprehensive set of utility functions inrop_utils.py for working with symbolic execution, gadget analysis, and ROP chain construction.
Address and Assembly
addr_to_asmstring
angr.Project
required
The project containing the binary
int
required
The address to disassemble
"pop rax; pop rbx; ret")
Example:
AST Dependency Analysis
get_ast_dependency
claripy.ast.BV
required
The AST to analyze. Must be created from a symbolic state where registers are named
"sreg_REG-"- Extracts all variables starting with
"sreg_" - Returns the register name portion (e.g.,
"sreg_rax-123"→"rax") - Returns empty set if any non-register variables are found
get_ast_controllers
angr.SimState
required
The symbolic state
claripy.ast.BV
required
The AST to analyze
set
required
Set of register dependencies (from
get_ast_dependency)- For each dependent register, set all other registers to a test value
- Check if the resulting AST is unconstrained using
fast_unconstrained_check - Return registers that allow arbitrary values
get_ast_const_offset
angr.SimState
required
The symbolic state
claripy.ast.BV
required
The memory address AST
set
required
Register dependencies
Constraint Checking
unconstrained_check
True if the AST has no constraints in the solver
fast_unconstrained_check
- Allowed operations: Extract, BVS, add, sub, xor, Reverse, BVV, ZeroExt, SignExt
- Disallowed patterns:
- Bitwise AND with non-all-ones constant
- Bitwise OR with non-zero constant
- Shifts by non-zero amount
- Operations like
x + x(constrained)
- Byte-level check: Each byte must be unconstrained
- Fallback: Uses
loose_constrained_checkif heuristics pass
loose_constrained_check
0x00xFFFFFFFF...(all ones)0xAAAAAAAA...(alternating)0x55555555...(alternating)0x9ABC...(mixed pattern)
True if at most 2 test values are unsatisfiable
Register Utilities
get_reg_name
angrop.arch.Arch
required
Architecture instance
int
required
Byte offset in the register file
RegNotFoundException if no register found at offset
Example:
State Creation
make_initial_state
- Custom memory plugin (
SpecialMem) for faster uninitialized memory - Symbolic stack of size
stack_gsize * arch.bytes - Optimized angr options for gadget analysis
- 1-second solver timeout
CONSERVATIVE_READ_STRATEGYAVOID_MULTIVALUED_WRITESNO_SYMBOLIC_JUMP_RESOLUTIONTRACK_ACTION_HISTORYTRACK_REGISTER_ACTIONSTRACK_MEMORY_ACTIONS
AVOID_MULTIVALUED_READSSUPPORT_FLOATING_POINT- All resilience and simplification options
make_symbolic_state
angr.Project
required
The angr project
set
required
Registers to symbolize (named
"sreg_REG-")int
required
Symbolic stack size in pointer-sized elements
set | None
default:"None"
Additional registers to symbolize (named
"esreg_REG-")bool
default:"False"
Symbolize the GOT table (for non-FULL RELRO binaries)
Execution Control
step_one_inst
- Kernel execution (steps through if not
stop_at_syscall) - Hooked addresses (steps through)
step_to_unconstrained_successor
int
default:"2"
Maximum steps to take
RopException if cannot reach unconstrained state
step_to_syscall
RuntimeError if unable to reach syscall
Address Checking
is_kernel_addr
True if the address belongs to the kernel object (cle##kernel)
is_in_kernel
Timeout Decorator
timeout
RopTimeoutException if function exceeds time limit.
Features:
- Uses SIGALRM signal
- Handles nested timeouts (respects shortest timeout)
- Delays timeout during
__del__methods to avoid exceptions during cleanup
Value Conversion
cast_rop_value
RopValue instance and performs rebase analysis.
bits_extended
Error Classes
angrop defines custom exceptions inerrors.py for fine-grained error handling.
RegNotFoundException
RopException
- Gadget does not reach unconstrained state
- Cannot get to single successor
- SP change is symbolic or uncontrolled
- Memory access with no dependencies