Skip to content

fix: bugs in message and netadr natives - #390

Open
Nord1cWarr1or wants to merge 1 commit into
rehlds:masterfrom
Nord1cWarr1or:fix/natives-bugs
Open

Nord1cWarr1or wants to merge 1 commit into
rehlds:masterfrom
Nord1cWarr1or:fix/natives-bugs

Conversation

@Nord1cWarr1or

@Nord1cWarr1or Nord1cWarr1or commented Aug 30, 2026 •

Copy link
Copy Markdown
Member

🖤

Purpose

Three bugs in the message-hook and netaddr natives, one per issue:

  1. GetMessageOrigData with MsgMsgId returned the current message id (getId()) instead of the original one, breaking the native's contract. Every other *Orig* branch in the file already used the original getters, and getOriginalId() has been part of the IMessageContext interface (IMessageManager.h) all along. Resolves GetMessageOrigData(MsgMsgId) returns the current message ID instead of the original one #387.
  2. set_netadr / get_netadr cast netadr_s.ip (an unsigned char ip[4] field) to size_t * and wrote/read through it. On LP64 size_t is 8 bytes, so 8 bytes went into a 4-byte field, clobbering the adjacent port and the head of ipx[10] — out-of-bounds access on 64-bit builds. Resolves Out-of-bounds write/read of netadr_s.ip[4] via size_t cast in set_netadr/get_netadr (64-bit builds) #388.
  3. CHECK_PARAMBOUNDS logged an error but did not return, so the native kept executing with the out-of-bounds argument.

Approach

  • GetMessageOrigData Index case: getId() → getOriginalId().
  • The size_t * cast becomes unsigned int * — 4 bytes on both ILP32 and LP64, so the OOB is gone and 32-bit behavior/codegen is unchanged (sizeof(size_t) == sizeof(unsigned int) == 4 there).
  • CHECK_PARAMBOUNDS gains return FALSE;. All six use sites audited (SetMessageData, GetMessageData, GetMessageOrigData, GetMessageArgType, IsMessageDataModified, ResetModifiedMessageData): each is a cell-returning native with an existing FALSE error path, so the abort follows the file's own convention.

Open Questions and Pre-Merge TODOs

  • Full Linux 32-bit build with the same flags as CI — builds and links cleanly (reapi_amxx_i386.so); the two changed translation units compile with no warnings.
  • 64-bit (-m64) syntax-only compile of the changed files — clean.
  • Offsets re-checked against netadr_s layout (common/netadr.h): type (4 bytes) is followed by ip[4], so ip is 4-byte aligned and a 4-byte access covers exactly the field.

Learning

netadr_s layout from ReHLDS common/netadr.h; original-id getters from IMessageManager.h.

Resolves: #387, #388, #389

…am bounds abort

- GetMessageOrigData(MsgMsgId) returned the current message id
  (getId()); use getOriginalId() like the other Original-branches do
  (rehlds#387)
- set_netadr/get_netadr wrote/read 8 bytes into the 4-byte netadr_s.ip
  field through a size_t cast - OOB on 64-bit builds; use unsigned int,
  32-bit behavior unchanged (rehlds#388)
- CHECK_PARAMBOUNDS now aborts the native (return FALSE) after logging
  instead of continuing with the out-of-bounds argument; all six
  use-sites reviewed, every caller already has FALSE error paths
  (rehlds#389)
@Nord1cWarr1or Nord1cWarr1or changed the title fix: original msg id in GetMessageOrigData, netadr_ip 64-bit OOB, param bounds abort fix: bugs in message and netadr natives Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant