fix: optimize turtle monster move wrapped parsing

This commit is contained in:
Kelsi 2026-03-14 22:01:26 -07:00
parent bce1f4d211
commit f44ef7b9ea
2 changed files with 44 additions and 24 deletions

View file

@ -16290,6 +16290,22 @@ void GameHandler::handleMonsterMove(network::Packet& packet) {
LOG_WARNING(msg, " (occurrence=", failCount, ")"); LOG_WARNING(msg, " (occurrence=", failCount, ")");
} }
}; };
auto logWrappedFallbackUsed = [&]() {
static uint32_t wrappedFallbackCount = 0;
++wrappedFallbackCount;
if (wrappedFallbackCount <= 10 || (wrappedFallbackCount % 100) == 0) {
LOG_WARNING("SMSG_MONSTER_MOVE parsed via wrapped-subpacket fallback",
" (occurrence=", wrappedFallbackCount, ")");
}
};
auto logWrappedUncompressedFallbackUsed = [&]() {
static uint32_t wrappedUncompressedFallbackCount = 0;
++wrappedUncompressedFallbackCount;
if (wrappedUncompressedFallbackCount <= 10 || (wrappedUncompressedFallbackCount % 100) == 0) {
LOG_WARNING("SMSG_MONSTER_MOVE parsed via uncompressed wrapped-subpacket fallback",
" (occurrence=", wrappedUncompressedFallbackCount, ")");
}
};
auto stripWrappedSubpacket = [&](const std::vector<uint8_t>& bytes, std::vector<uint8_t>& stripped) -> bool { auto stripWrappedSubpacket = [&](const std::vector<uint8_t>& bytes, std::vector<uint8_t>& stripped) -> bool {
if (bytes.size() < 3) return false; if (bytes.size() < 3) return false;
uint8_t subSize = bytes[0]; uint8_t subSize = bytes[0];
@ -16331,22 +16347,31 @@ void GameHandler::handleMonsterMove(network::Packet& packet) {
std::vector<uint8_t> stripped; std::vector<uint8_t> stripped;
bool hasWrappedForm = stripWrappedSubpacket(decompressed, stripped); bool hasWrappedForm = stripWrappedSubpacket(decompressed, stripped);
// Try unwrapped payload first (common form), then wrapped-subpacket fallback. bool parsed = false;
network::Packet decompPacket(packet.getOpcode(), decompressed); if (hasWrappedForm) {
if (!packetParsers_->parseMonsterMove(decompPacket, data)) {
if (!hasWrappedForm) {
logMonsterMoveParseFailure("Failed to parse SMSG_MONSTER_MOVE (decompressed " +
std::to_string(destLen) + " bytes)");
return;
}
network::Packet wrappedPacket(packet.getOpcode(), stripped); network::Packet wrappedPacket(packet.getOpcode(), stripped);
if (!packetParsers_->parseMonsterMove(wrappedPacket, data)) { if (packetParsers_->parseMonsterMove(wrappedPacket, data)) {
parsed = true;
logWrappedFallbackUsed();
}
}
if (!parsed) {
network::Packet decompPacket(packet.getOpcode(), decompressed);
if (packetParsers_->parseMonsterMove(decompPacket, data)) {
parsed = true;
}
}
if (!parsed) {
if (hasWrappedForm) {
logMonsterMoveParseFailure("Failed to parse SMSG_MONSTER_MOVE (decompressed " + logMonsterMoveParseFailure("Failed to parse SMSG_MONSTER_MOVE (decompressed " +
std::to_string(destLen) + " bytes, wrapped payload " + std::to_string(destLen) + " bytes, wrapped payload " +
std::to_string(stripped.size()) + " bytes)"); std::to_string(stripped.size()) + " bytes)");
return; } else {
logMonsterMoveParseFailure("Failed to parse SMSG_MONSTER_MOVE (decompressed " +
std::to_string(destLen) + " bytes)");
} }
LOG_WARNING("SMSG_MONSTER_MOVE parsed via wrapped-subpacket fallback"); return;
} }
} else if (!packetParsers_->parseMonsterMove(packet, data)) { } else if (!packetParsers_->parseMonsterMove(packet, data)) {
// Some realms occasionally embed an extra [size|opcode] wrapper even when the // Some realms occasionally embed an extra [size|opcode] wrapper even when the
@ -16355,7 +16380,7 @@ void GameHandler::handleMonsterMove(network::Packet& packet) {
if (stripWrappedSubpacket(rawData, stripped)) { if (stripWrappedSubpacket(rawData, stripped)) {
network::Packet wrappedPacket(packet.getOpcode(), stripped); network::Packet wrappedPacket(packet.getOpcode(), stripped);
if (packetParsers_->parseMonsterMove(wrappedPacket, data)) { if (packetParsers_->parseMonsterMove(wrappedPacket, data)) {
LOG_WARNING("SMSG_MONSTER_MOVE parsed via uncompressed wrapped-subpacket fallback"); logWrappedUncompressedFallbackUsed();
} else { } else {
logMonsterMoveParseFailure("Failed to parse SMSG_MONSTER_MOVE"); logMonsterMoveParseFailure("Failed to parse SMSG_MONSTER_MOVE");
return; return;

View file

@ -3172,10 +3172,12 @@ bool MonsterMoveParser::parse(network::Packet& packet, MonsterMoveData& data) {
if (pointCount == 0) return true; if (pointCount == 0) return true;
// Reject extreme point counts from malformed packets. // Cap pointCount to prevent excessive iteration from malformed packets.
constexpr uint32_t kMaxSplinePoints = 1000; constexpr uint32_t kMaxSplinePoints = 1000;
if (pointCount > kMaxSplinePoints) { if (pointCount > kMaxSplinePoints) {
return false; LOG_WARNING("SMSG_MONSTER_MOVE: pointCount=", pointCount, " exceeds max ", kMaxSplinePoints,
" (guid=0x", std::hex, data.guid, std::dec, "), capping");
pointCount = kMaxSplinePoints;
} }
// Catmullrom or Flying → all waypoints stored as absolute float3 (uncompressed). // Catmullrom or Flying → all waypoints stored as absolute float3 (uncompressed).
@ -3183,27 +3185,20 @@ bool MonsterMoveParser::parse(network::Packet& packet, MonsterMoveData& data) {
bool uncompressed = (data.splineFlags & (0x00080000 | 0x00002000)) != 0; bool uncompressed = (data.splineFlags & (0x00080000 | 0x00002000)) != 0;
if (uncompressed) { if (uncompressed) {
const size_t requiredBytes = static_cast<size_t>(pointCount) * 12ull;
if (packet.getReadPos() + requiredBytes > packet.getSize()) return false;
// Read last point as destination // Read last point as destination
// Skip to last point: each point is 12 bytes // Skip to last point: each point is 12 bytes
for (uint32_t i = 0; i < pointCount - 1; i++) { for (uint32_t i = 0; i < pointCount - 1; i++) {
if (packet.getReadPos() + 12 > packet.getSize()) return false; if (packet.getReadPos() + 12 > packet.getSize()) return true;
packet.readFloat(); packet.readFloat(); packet.readFloat(); packet.readFloat(); packet.readFloat(); packet.readFloat();
} }
if (packet.getReadPos() + 12 > packet.getSize()) return false; if (packet.getReadPos() + 12 > packet.getSize()) return true;
data.destX = packet.readFloat(); data.destX = packet.readFloat();
data.destY = packet.readFloat(); data.destY = packet.readFloat();
data.destZ = packet.readFloat(); data.destZ = packet.readFloat();
data.hasDest = true; data.hasDest = true;
} else { } else {
// Compressed: first 3 floats are the destination (final point) // Compressed: first 3 floats are the destination (final point)
size_t requiredBytes = 12; if (packet.getReadPos() + 12 > packet.getSize()) return true;
if (pointCount > 1) {
requiredBytes += static_cast<size_t>(pointCount - 1) * 4ull;
}
if (packet.getReadPos() + requiredBytes > packet.getSize()) return false;
data.destX = packet.readFloat(); data.destX = packet.readFloat();
data.destY = packet.readFloat(); data.destY = packet.readFloat();
data.destZ = packet.readFloat(); data.destZ = packet.readFloat();