stkfmt
Generate clean terminal diagrams of hand-authored memory layouts for reverse-engineering notes, educational material, and write-ups.
Installation
pip install stkfmt
Features
- Hand-authored memory diagrams - describe stack, heap, and register layouts in JSON, render deterministic ASCII or Unicode text
- Ghidra stack import - turn a copied
Stack[...]listing into a diagram directly, no manual transcription - ABI profiles - fill in ABI-implied slots (e.g. the Windows x64 return address) that Ghidra doesn't list
- Pointer annotations - link a block to the region it points into with
points_to - Overlap and alignment checks - rejects overlapping blocks and validates power-of-two
alignrequirements - Terminal, Markdown, and issue-comment friendly - ASCII output by default for predictable copying anywhere
Quick Start
stkfmt memory.json --unicode
stkfmt ghidra function.txt --unicode
stkfmt ghidra function.txt --abi windows-x64 --unicode
{
"title": "main()",
"regions": [
{
"name": "Stack",
"direction": "down",
"blocks": [
{
"id": "name-ptr",
"address": "0x7fffffffe1a8",
"size": 8,
"value": "0x404050",
"label": "name",
"type": "char *",
"points_to": "heap-name"
}
]
},
{
"name": "Heap",
"blocks": [
{
"id": "heap-name",
"address": "0x404050",
"size": 4,
"value": "41 64 61 00",
"label": "name",
"type": "char[4]",
"note": "\"Ada\""
}
]
}
]
}
Usage
stkfmt <input> [options]
stkfmt ghidra <listing.txt> [options]
input JSON file path, or - to read JSON from stdin
-s, --style STYLE ascii or unicode (default: ascii)
-u, --unicode shortcut for --style unicode
-o, --output FILE write output to FILE instead of stdout
--no-addresses hide address gutters and pointer-target addresses
--abi ABI apply an ABI profile to a Ghidra listing (windows-x64, sysv-x64)
-v, --version show version
Each block requires size (bytes) and label. value is optional: omitted values render as <unknown>, which is useful for static Ghidra layouts. A region uses one coordinate system: either absolute address values, or signed offset values with a region base such as rsp.
An addressed block displays its inclusive byte range. An offset block displays a base-relative range, e.g. RSP-0x148..RSP-0x39. stkfmt sorts coordinate-bearing blocks into physical memory order (high-to-low for direction: "down"), renders unknown gaps as unmapped, rejects overlapping blocks, and validates an optional power-of-two align requirement. A gap is not assumed to be ABI padding; label an explicit block padding only when you know that is what it is.
Ghidra listings
Copy or export a Ghidra function listing to a text file, then import its Stack[...] rows directly:
stkfmt ghidra examples/ghidra_function_listing.txt --unicode
The importer reads Ghidra stack offsets, storage sizes, type names, and variable names. It intentionally ignores register rows, xrefs, decompiler output, and instruction listings. Static layout imports render values as <unknown>.
For a Windows x64 function, add its return-address stack slot explicitly:
stkfmt ghidra examples/ghidra_function_listing.txt --abi windows-x64 --unicode
This labels the return address at Stack[+0x0..+0x7].
For a Linux or macOS x86-64 function, use the sysv-x64 profile instead:
stkfmt ghidra examples/ghidra_function_listing.txt --abi sysv-x64 --unicode
Both profiles label the same call-pushed return address at Stack[+0x0..+0x7]; only the note distinguishing which ABI added it differs. windows-x64 and sysv-x64 intentionally leave shadow space and the red zone, respectively, unannotated.
License
MIT
Metadata
Release files for stkfmt 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| stkfmt-0.1.1.tar.gz | 14.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| stkfmt-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 26.8 kB
Release files / stkfmt-0.1.1.tar.gz
| Download URL | stkfmt-0.1.1.tar.gz |
|---|---|
| Size | 14.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
fa960280cf5b5d699d09b47f241e3e9bee2d5973f8b06a1a52812272f6968dfe
|
|
BLAKE2b-256 checksum How to use checksums |
409800d504dfabd2a915d0519dc91374cd86755efce32855f288493a10649750
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 16, 2026.
Transparency logRelease files / stkfmt-0.1.1-py3-none-any.whl
| Download URL | stkfmt-0.1.1-py3-none-any.whl |
|---|---|
| Size | 12.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
31abdfbbd5c649cc547bc8b062856ce512390c05cd229b19b460db33a2009ecb
|
|
BLAKE2b-256 checksum How to use checksums |
b248d1c62c27fc2ab1c3e70f0cc97d838852724070ec61e068b86b6edaf8ca9e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 16, 2026.
Transparency log