Skip to main content

stkfmt

Generate clean terminal diagrams of hand-authored memory layouts for reverse-engineering notes, educational material, and write-ups.

Installation

pip install stkfmt

Features

  • Hand-authored memory diagrams - describe stack, heap, and register layouts in JSON, render deterministic ASCII or Unicode text
  • Ghidra stack import - turn a copied Stack[...] listing into a diagram directly, no manual transcription
  • ABI profiles - fill in ABI-implied slots (e.g. the Windows x64 return address) that Ghidra doesn't list
  • Pointer annotations - link a block to the region it points into with points_to
  • Overlap and alignment checks - rejects overlapping blocks and validates power-of-two align requirements
  • Terminal, Markdown, and issue-comment friendly - ASCII output by default for predictable copying anywhere

Quick Start

stkfmt memory.json --unicode
stkfmt ghidra function.txt --unicode
stkfmt ghidra function.txt --abi windows-x64 --unicode
{
  "title": "main()",
  "regions": [
    {
      "name": "Stack",
      "direction": "down",
      "blocks": [
        {
          "id": "name-ptr",
          "address": "0x7fffffffe1a8",
          "size": 8,
          "value": "0x404050",
          "label": "name",
          "type": "char *",
          "points_to": "heap-name"
        }
      ]
    },
    {
      "name": "Heap",
      "blocks": [
        {
          "id": "heap-name",
          "address": "0x404050",
          "size": 4,
          "value": "41 64 61 00",
          "label": "name",
          "type": "char[4]",
          "note": "\"Ada\""
        }
      ]
    }
  ]
}

Usage

stkfmt <input> [options]
stkfmt ghidra <listing.txt> [options]

  input                 JSON file path, or - to read JSON from stdin
  -s, --style STYLE     ascii or unicode (default: ascii)
  -u, --unicode         shortcut for --style unicode
  -o, --output FILE     write output to FILE instead of stdout
      --no-addresses    hide address gutters and pointer-target addresses
      --abi ABI         apply an ABI profile to a Ghidra listing (windows-x64, sysv-x64)
  -v, --version         show version

Each block requires size (bytes) and label. value is optional: omitted values render as <unknown>, which is useful for static Ghidra layouts. A region uses one coordinate system: either absolute address values, or signed offset values with a region base such as rsp.

An addressed block displays its inclusive byte range. An offset block displays a base-relative range, e.g. RSP-0x148..RSP-0x39. stkfmt sorts coordinate-bearing blocks into physical memory order (high-to-low for direction: "down"), renders unknown gaps as unmapped, rejects overlapping blocks, and validates an optional power-of-two align requirement. A gap is not assumed to be ABI padding; label an explicit block padding only when you know that is what it is.

Ghidra listings

Copy or export a Ghidra function listing to a text file, then import its Stack[...] rows directly:

stkfmt ghidra examples/ghidra_function_listing.txt --unicode

The importer reads Ghidra stack offsets, storage sizes, type names, and variable names. It intentionally ignores register rows, xrefs, decompiler output, and instruction listings. Static layout imports render values as <unknown>.

For a Windows x64 function, add its return-address stack slot explicitly:

stkfmt ghidra examples/ghidra_function_listing.txt --abi windows-x64 --unicode

This labels the return address at Stack[+0x0..+0x7].

For a Linux or macOS x86-64 function, use the sysv-x64 profile instead:

stkfmt ghidra examples/ghidra_function_listing.txt --abi sysv-x64 --unicode

Both profiles label the same call-pushed return address at Stack[+0x0..+0x7]; only the note distinguishing which ABI added it differs. windows-x64 and sysv-x64 intentionally leave shadow space and the red zone, respectively, unannotated.

License

MIT

Metadata

Release files for stkfmt 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for stkfmt 0.1.1
File Size Uploaded
stkfmt-0.1.1.tar.gz 14.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for stkfmt 0.1.1
File Interpreter ABI Platform
stkfmt-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 26.8 kB

Release files / stkfmt-0.1.1.tar.gz

Download URL stkfmt-0.1.1.tar.gz
Size 14.6 kB
Tags Source
SHA-256 checksum
How to use checksums
fa960280cf5b5d699d09b47f241e3e9bee2d5973f8b06a1a52812272f6968dfe
BLAKE2b-256 checksum
How to use checksums
409800d504dfabd2a915d0519dc91374cd86755efce32855f288493a10649750
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 16, 2026.

Transparency log

Release files / stkfmt-0.1.1-py3-none-any.whl

Download URL stkfmt-0.1.1-py3-none-any.whl
Size 12.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
31abdfbbd5c649cc547bc8b062856ce512390c05cd229b19b460db33a2009ecb
BLAKE2b-256 checksum
How to use checksums
b248d1c62c27fc2ab1c3e70f0cc97d838852724070ec61e068b86b6edaf8ca9e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 16, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page