mirror of
https://github.com/DarkflameUniverse/DarkflameServer.git
synced 2026-10-02 19:03:43 +00:00
Client-sent AMF (CONTROL_BEHAVIORS) was decoded without limits on the associative part of arrays, on nesting depth, or on the total number of values. Associative entries went into an unordered_map with the standard unseeded string hash, so a client could pick colliding keys and make insertion quadratic, and deeply nested arrays recursed until the stack overflowed, crashing the world server. - The associative map is now an ordered std::map (O(log n) whatever the keys, deterministic serialization order). - Each array allows at most 10,000 associative entries, the same as the existing dense limit, which is now checked before anything is read. - Arrays may nest at most 32 deep and one deserializer reads at most 100,000 values. Every limit throws, which the only caller already catches and drops the message. - Inserting a duplicate key keeps the last value and no longer returns a reference to a value that was destroyed when the key already held null. Verified with new unit tests for each limit (including a 100,000 deep nesting that previously overflowed the stack) and the existing live packet test, which still decodes. Fixes #2035 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
88 lines
2.4 KiB
C++
88 lines
2.4 KiB
C++
#pragma once
|
|
|
|
#include "Amf3.h"
|
|
#include "BitStream.h"
|
|
|
|
#include <memory>
|
|
#include <vector>
|
|
#include <string>
|
|
|
|
class AMFDeserialize {
|
|
public:
|
|
// Most entries one array may hold, in each of its dense and associative parts.
|
|
static constexpr uint32_t MaxArraySize = 10'000;
|
|
|
|
// Deepest nesting of arrays allowed. Client UI messages nest a handful of levels.
|
|
static constexpr uint32_t MaxDepth = 32;
|
|
|
|
// Most values one deserializer will read over its lifetime.
|
|
static constexpr uint32_t MaxValues = 100'000;
|
|
|
|
/**
|
|
* Read an AMF3 value from a bitstream.
|
|
*
|
|
* @param inStream inStream to read value from.
|
|
* @return Returns an AMFValue with all the information from the bitStream in it.
|
|
*/
|
|
std::unique_ptr<AMFBaseValue> Read(RakNet::BitStream& inStream);
|
|
private:
|
|
/**
|
|
* @brief Private method to read a U29 integer from a bitstream
|
|
*
|
|
* @param inStream bitstream to read data from
|
|
* @return The number as an unsigned 29 bit integer
|
|
*/
|
|
static uint32_t ReadU29(RakNet::BitStream& inStream);
|
|
|
|
/**
|
|
* @brief Reads a string from a bitstream
|
|
*
|
|
* @param inStream bitStream to read data from
|
|
* @return The read string
|
|
*/
|
|
const std::string ReadString(RakNet::BitStream& inStream);
|
|
|
|
/**
|
|
* @brief Read an AMFDouble value from a bitStream
|
|
*
|
|
* @param inStream bitStream to read data from
|
|
* @return Double value represented as an AMFValue
|
|
*/
|
|
static std::unique_ptr<AMFDoubleValue> ReadAmfDouble(RakNet::BitStream& inStream);
|
|
|
|
/**
|
|
* @brief Read an AMFArray from a bitStream
|
|
*
|
|
* @param inStream bitStream to read data from
|
|
* @return Array value represented as an AMFValue
|
|
*/
|
|
std::unique_ptr<AMFArrayValue> ReadAmfArray(RakNet::BitStream& inStream);
|
|
|
|
/**
|
|
* @brief Read an AMFString from a bitStream
|
|
*
|
|
* @param inStream bitStream to read data from
|
|
* @return String value represented as an AMFValue
|
|
*/
|
|
std::unique_ptr<AMFStringValue> ReadAmfString(RakNet::BitStream& inStream);
|
|
|
|
/**
|
|
* @brief Read an AMFInteger from a bitStream
|
|
*
|
|
* @param inStream bitStream to read data from
|
|
* @return Integer value represented as an AMFValue
|
|
*/
|
|
static std::unique_ptr<AMFIntValue> ReadAmfInteger(RakNet::BitStream& inStream);
|
|
|
|
/**
|
|
* List of strings read so far saved to be read by reference.
|
|
*/
|
|
std::vector<std::string> accessedElements;
|
|
|
|
// How deeply nested the array being read is.
|
|
uint32_t m_Depth = 0;
|
|
|
|
// How many values have been read so far.
|
|
uint32_t m_ValuesRead = 0;
|
|
};
|