Skip to main content

Supported Architectures

From the README, angrop supports multiple processor architectures:
  • x86 (32-bit Intel/AMD)
  • x64 (AMD64, 64-bit Intel/AMD)
  • MIPS (32-bit and 64-bit)
  • ARM (32-bit, including Thumb mode)
  • AArch64 (ARM 64-bit)
  • RISC-V (64-bit)

Architecture-Agnostic Design

From the README:
“Its design is architecture-agnostic so it supports multiple architectures.”
angrop achieves architecture independence through abstraction layers:

The ROPArch Class

From arch.py:5-39, the base architecture class:
This provides a uniform interface across architectures while allowing specialization.

Register Management

From arch.py:24-39:
This automatically adapts to different register naming conventions:
  • x86: eax, ebx, ecx, edx, esi, edi, ebp
  • x64: rax, rbx, rcx, rdx, rsi, rdi, r8-r15, rbp
  • ARM: r0-r12, lr
  • AArch64: x0-x30
  • MIPS: $v0-$v1, $a0-$a3, $t0-$t9, $s0-$s8

x86 (32-bit)

From arch.py:44-86:
Key characteristics:
  • Uses int 0x80 for system calls
  • Multiple return instruction variants (ret, ret imm16, retf, etc.)
  • Segment registers not used in ROP (filtered out)
  • Smaller maximum gadget size (20 instructions)
Filtered instructions (arch.py:69-77):

x64 (AMD64)

From arch.py:87-96:
Key differences from x86:
  • Uses syscall instruction instead of int 0x80
  • Different syscall numbers (Linux x64 ABI)
  • 64-bit registers (rax vs eax)
  • Different calling convention (registers vs stack)

ARM (32-bit)

From arch.py:100-128:
ARM-specific features:
  • Return via pop {pc} or bx lr
  • Conditional execution on every instruction
  • Thumb mode for 16-bit instruction encoding
Conditional instruction filtering (arch.py:122-128):

Thumb Mode

From rop.py:36-37:
Thumb mode characteristics:
  • 16-bit instruction encoding (vs 32-bit ARM)
  • 2-byte instruction alignment
  • Smaller code size
  • Most ARM instructions available in Thumb
  • Cannot mix ARM and Thumb in same ROP chain
Setting Thumb mode:
When is_thumb=True, gadgets are searched at 2-byte aligned addresses with Thumb decoding.

AArch64 (ARM 64-bit)

From arch.py:130-143:
AArch64 features:
  • 64-bit registers: x0-x30 (vs ARM’s r0-r12)
  • Fixed 4-byte instruction size (no Thumb)
  • Return via ret instruction
  • PAC (Pointer Authentication Codes) filtered - incompatible with ROP

MIPS

From arch.py:145-152:
MIPS characteristics:
  • Delay slots after branches (branch executes, then next instruction, then jump)
  • Different syscall number encoding
  • Both big-endian and little-endian variants supported

RISC-V (64-bit)

From arch.py:154-160:
RISC-V features:
  • Clean RISC architecture
  • Compressed instruction set (16-bit and 32-bit)
  • Return via ret (pseudo-instruction for jalr x0, x1, 0)

Architecture Detection

From arch.py:162-178:
This is called automatically when creating an ROP analysis:

Kernel Mode

All architectures support kernel mode for finding gadgets in kernel code:
Kernel mode differences:
  • Uses kernel syscall numbers
  • Allows segment register operations (x86/x64)
  • Searches in .text section of kernel images
  • Different constraints on memory accesses
From arch.py:

Adding New Architectures

From the README:
“It should be relatively easy to support other architectures that are supported by angr. If you’d like to use angrop on other architectures, please create an issue and we will look into it :)”
To add a new architecture:
  1. Create a new class inheriting from ROPArch:
  1. Implement block_make_sense() to filter invalid instruction sequences
  2. Add to get_arch() function:
The rest of angrop (gadget finding, chain building, symbolic execution) works without modification due to the architecture-agnostic design.

Cross-Architecture Exploitation

The same angrop API works across all architectures:
angrop handles:
  • Register name differences
  • Calling convention differences
  • Instruction encoding differences
  • Endianness differences
  • Alignment requirements
This makes it easy to develop exploits for different architectures without learning architecture-specific ROP techniques.