Setting Registers: set_regs()
The set_regs() method sets one or more registers to specific values.
Method Signature
**registers: Keyword arguments mapping register names to values (integers or symbolic values)preserve_regs: Set of register names that should not be modified during chain generation
RopChain object that sets the specified registers
Basic Examples
1
Set a single register
2
Set multiple registers
Angrop automatically finds the best gadgets to set your registers, preferring gadgets with minimal stack changes and side effects.
Preserving Register Values
Usepreserve_regs to ensure certain registers aren’t modified during chain generation:
Real-World Example: Preserving Function Arguments
This example from angrop’s kernel test suite shows preserving registers across function calls:Moving Registers: move_regs()
The move_regs() method copies data from one register to another.
Method Signature
**moves: Keyword arguments mapping destination register to source register name (as string)preserve_regs: Set of register names that should not be modified
RopChain object that performs the register moves
Basic Examples
Moving Multiple Registers
Angrop searches for direct move gadgets like
mov rax, rdx; ret. If direct moves aren’t available, it may chain multiple gadgets or use push/pop sequences to accomplish the move.Advanced Register Operations
Using Return Values from Functions
When calling functions, the return value is typically inrax (on x64) or eax (on x86). Use move_regs() to preserve it:
Combining Set and Move Operations
Architecture-Specific Registers
Angrop supports register operations across different architectures:x86_64 Registers
x86 (32-bit) Registers
ARM Registers
Register Setting with Badbytes
When badbytes are configured, angrop automatically avoids values containing them:When values contain badbytes, angrop uses arithmetic operations to construct them. For example, it might set a register to
0x0a0a0a0b and then subtract 1, rather than directly loading 0x0a0a0a0a.How Register Setting Works Internally
Angrop uses several strategies to set registers:- Direct pop gadgets -
pop rax; ret- Most efficient - Register arithmetic - If value contains badbytes, construct it via add/sub/xor
- Register moves - Chain register moves when direct pops aren’t available
- Complex gadget chains - Combine multiple gadgets when needed
Example: Register Arithmetic for Badbytes
From the source code (reg_setter.py:699-725):
Symbolic Register Values
You can also set registers to symbolic values for advanced use cases:Troubleshooting
”Couldn’t set registers” Error
If you see this error, it means angrop couldn’t find gadgets to set the requested registers:Best Practices
- Minimize register operations - Set multiple registers in one call when possible
- Use preserve_regs strategically - Only preserve registers when necessary
- Chain efficiently - Combine operations with
+instead of making separate calls - Verify your chains - Use
chain.pp()to inspect the generated gadgets
Examples from Different Architectures
x86_64 Function Call Setup
ARM Function Call Setup
Next Steps
- Memory Operations - Writing and modifying memory
- Function Calls - Using registers for function arguments
- Syscalls - Setting up syscall arguments