Skip to main content

stkfmt

Generate clean terminal diagrams of hand-authored memory layouts for reverse-engineering notes, educational material, and write-ups.

pip install stkfmt
stkfmt memory.json --unicode
stkfmt ghidra function.txt --unicode
stkfmt ghidra function.txt --abi windows-x64 --unicode
{
  "title": "main()",
  "regions": [
    {
      "name": "Stack",
      "direction": "down",
      "blocks": [
        {
          "id": "name-ptr",
          "address": "0x7fffffffe1a8",
          "size": 8,
          "value": "0x404050",
          "label": "name",
          "type": "char *",
          "points_to": "heap-name"
        }
      ]
    },
    {
      "name": "Heap",
      "blocks": [
        {
          "id": "heap-name",
          "address": "0x404050",
          "size": 4,
          "value": "41 64 61 00",
          "label": "name",
          "type": "char[4]",
          "note": "\"Ada\""
        }
      ]
    }
  ]
}

Usage

stkfmt <input> [options]
stkfmt ghidra <listing.txt> [options]

  input                 JSON file path, or - to read JSON from stdin
  -s, --style STYLE     ascii or unicode (default: ascii)
  -u, --unicode         shortcut for --style unicode
  -o, --output FILE     write output to FILE instead of stdout
      --no-addresses    hide address gutters and pointer-target addresses
      --abi ABI         apply an ABI profile to a Ghidra listing (windows-x64)
  -v, --version         show version

Each block requires size (bytes) and label. value is optional: omitted values render as <unknown>, which is useful for static Ghidra layouts. A region uses one coordinate system: either absolute address values, or signed offset values with a region base such as rsp.

An addressed block displays its inclusive byte range. An offset block displays a base-relative range, e.g. RSP-0x148..RSP-0x39. stkfmt sorts coordinate-bearing blocks into physical memory order (high-to-low for direction: "down"), renders unknown gaps as unmapped, rejects overlapping blocks, and validates an optional power-of-two align requirement. A gap is not assumed to be ABI padding; label an explicit block padding only when you know that is what it is.

Ghidra listings

Copy or export a Ghidra function listing to a text file, then import its Stack[...] rows directly:

stkfmt ghidra examples/ghidra_function_listing.txt --unicode

The importer reads Ghidra stack offsets, storage sizes, type names, and variable names. It intentionally ignores register rows, xrefs, decompiler output, and instruction listings. Static layout imports render values as <unknown>.

For a Windows x64 function, add its return-address stack slot explicitly:

stkfmt ghidra examples/ghidra_function_listing.txt --abi windows-x64 --unicode

This labels the return address at Stack[+0x0..+0x7].

Metadata

Release files for stkfmt 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for stkfmt 0.1.0
File Size Uploaded
stkfmt-0.1.0.tar.gz 12.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for stkfmt 0.1.0
File Interpreter ABI Platform
stkfmt-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 22.4 kB

Release files / stkfmt-0.1.0.tar.gz

Download URL stkfmt-0.1.0.tar.gz
Size 12.1 kB
Tags Source
SHA-256 checksum
How to use checksums
70c5741d1322446cc12bd23cd8ee1563c7489918cef5f99b8fb95659f240dbac
BLAKE2b-256 checksum
How to use checksums
9c7d9a8f1af0fb975358e47e57c01c772415a492aea4126e11fdd744aa9e4cfe
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 16, 2026.

Transparency log

Release files / stkfmt-0.1.0-py3-none-any.whl

Download URL stkfmt-0.1.0-py3-none-any.whl
Size 10.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7dde90cc4348f111257c5c83b0687f55db82ebde8c6ff87fe4605485128eb38e
BLAKE2b-256 checksum
How to use checksums
ec53a574ea495d9aa8a620c63ddea9d235c4a04921add0b6cfec8851da3a8390
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 16, 2026.

Transparency log

Release history Release notifications | RSS feed

0.1.1

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page