stkfmt
Generate clean terminal diagrams of hand-authored memory layouts for reverse-engineering notes, educational material, and write-ups.
pip install stkfmt
stkfmt memory.json --unicode
stkfmt ghidra function.txt --unicode
stkfmt ghidra function.txt --abi windows-x64 --unicode
{
"title": "main()",
"regions": [
{
"name": "Stack",
"direction": "down",
"blocks": [
{
"id": "name-ptr",
"address": "0x7fffffffe1a8",
"size": 8,
"value": "0x404050",
"label": "name",
"type": "char *",
"points_to": "heap-name"
}
]
},
{
"name": "Heap",
"blocks": [
{
"id": "heap-name",
"address": "0x404050",
"size": 4,
"value": "41 64 61 00",
"label": "name",
"type": "char[4]",
"note": "\"Ada\""
}
]
}
]
}
Usage
stkfmt <input> [options]
stkfmt ghidra <listing.txt> [options]
input JSON file path, or - to read JSON from stdin
-s, --style STYLE ascii or unicode (default: ascii)
-u, --unicode shortcut for --style unicode
-o, --output FILE write output to FILE instead of stdout
--no-addresses hide address gutters and pointer-target addresses
--abi ABI apply an ABI profile to a Ghidra listing (windows-x64)
-v, --version show version
Each block requires size (bytes) and label. value is optional: omitted values render as <unknown>, which is useful for static Ghidra layouts. A region uses one coordinate system: either absolute address values, or signed offset values with a region base such as rsp.
An addressed block displays its inclusive byte range. An offset block displays a base-relative range, e.g. RSP-0x148..RSP-0x39. stkfmt sorts coordinate-bearing blocks into physical memory order (high-to-low for direction: "down"), renders unknown gaps as unmapped, rejects overlapping blocks, and validates an optional power-of-two align requirement. A gap is not assumed to be ABI padding; label an explicit block padding only when you know that is what it is.
Ghidra listings
Copy or export a Ghidra function listing to a text file, then import its Stack[...] rows directly:
stkfmt ghidra examples/ghidra_function_listing.txt --unicode
The importer reads Ghidra stack offsets, storage sizes, type names, and variable names. It intentionally ignores register rows, xrefs, decompiler output, and instruction listings. Static layout imports render values as <unknown>.
For a Windows x64 function, add its return-address stack slot explicitly:
stkfmt ghidra examples/ghidra_function_listing.txt --abi windows-x64 --unicode
This labels the return address at Stack[+0x0..+0x7].
Metadata
Release files for stkfmt 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| stkfmt-0.1.0.tar.gz | 12.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| stkfmt-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 22.4 kB
Release files / stkfmt-0.1.0.tar.gz
| Download URL | stkfmt-0.1.0.tar.gz |
|---|---|
| Size | 12.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
70c5741d1322446cc12bd23cd8ee1563c7489918cef5f99b8fb95659f240dbac
|
|
BLAKE2b-256 checksum How to use checksums |
9c7d9a8f1af0fb975358e47e57c01c772415a492aea4126e11fdd744aa9e4cfe
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 16, 2026.
Transparency logRelease files / stkfmt-0.1.0-py3-none-any.whl
| Download URL | stkfmt-0.1.0-py3-none-any.whl |
|---|---|
| Size | 10.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
7dde90cc4348f111257c5c83b0687f55db82ebde8c6ff87fe4605485128eb38e
|
|
BLAKE2b-256 checksum How to use checksums |
ec53a574ea495d9aa8a620c63ddea9d235c4a04921add0b6cfec8851da3a8390
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 16, 2026.
Transparency log