Ignore client race-finished notifications on server - #5881
Conversation
|
I'm not particularly familiar with the networking code, but the two kartFinishedRace function within the very same code file indicate quite clearly that one should only be called for clients and the others for servers ; while the GE_STARTUP_BOOST handling of the server case indicates that servers may be on the receiving end of Game Event data. So the fix in isolation appears sensible, however it opens some additional questions:
For example, the reset ball directly calls sw->handleResetBallFromServer after only checking that there is an actual soccer world, so if the server reads GE message from a client, it seems a client could modify server state that way. The called function doesn't handle the case either, but arguably the nicer solution would be making it impossible to call it at all if NetworkConfig indicates a server... That's kind of the issue with classes, state gets everywhere, we can't simply get a soccer world without those functions and a compile-time guarantee that a server will never try to call those. Now, this practically asks to build a client that can tell the server a goal has been scored on demand and see what happens. |
Only startup boost requests are sent from clients. Reject other\ngame-event types before they can modify server-side game state, and\nvalidate the startup-boost payload length.
|
Thanks, that was a good catch. I checked the other
I also added a length check for the remaining startup-boost request. I tested this with a local soccer server and a modified client sending |
GameEventsProtocol::notifyEvent handles GE_KART_FINISHED_RACE by calling the decoder that updates World::getWorld()->getKart(kart_id) and marks that kart as finished. There was no check that the event came from the server, so a modified client could send this notification directly. That could let a client forge race results, finish another kart early, or provide an invalid kart ID to the decoder.
On server instances, this change rejects GE_KART_FINISHED_RACE events received from clients and logs the sender. Clients still process the event because it is a server-to-client notification.