Skip to content

Validate compressed GGPO input before decoding - #2519

Open
acts-1631 wants to merge 1 commit into
flyinghead:masterfrom
acts-1631:fix/ggpo-input-validation
Open

acts-1631 wants to merge 1 commit into
flyinghead:masterfrom
acts-1631:fix/ggpo-input-validation

Conversation

@acts-1631

Copy link
Copy Markdown
Contributor

A connected GGPO peer can send a compressed input record whose button number is outside the advertised input size. UdpProtocol::OnInput currently passes that number directly to:

_last_received_input.set(button);

GameInput::set indexes bits[button / 8]. A button value of 255 therefore accesses bits[31], beyond the 18-byte array, and corrupts adjacent GGPO session state. This can crash or destabilize online play.

Validate the complete Input packet before dispatch. The new validation checks the received byte length, compressed bit framing, input size, and every decoded button index. Validation occurs before the decoder mutates its receive state.

A connected peer can encode a button index beyond the advertised
input size. The decoder used it to write past GameInput::bits and into
adjacent session state.

Validate packet length, compressed bit framing, input size, and every
button index before dispatching the message.
Press5elect pushed a commit to Press5elect/PSFlycast that referenced this pull request Oct 7, 2026
…ast's open pull requests, release candidates in the updater, no Screenshot control

- Netplay: the checksum of a save state or of a CDI, GDI or CUE image is the
  file's, not its pointer's (flyinghead#2513).
- sh4: the FPSCR cause field is cleared when the guest writes FPSCR (flyinghead#2531).
- CHD: the track metadata's text fields are held to their buffers (flyinghead#2384).
- Input: absolute mouse motion rebased after relative input (flyinghead#2528); axis
  detection for triggers that report as buttons (flyinghead#2213).
- Checks of an ISO9660 directory record, RZIP chunk sizes, DNS answers,
  GGPO input packets and card events, and a Naomi LST's ranges (flyinghead#2414,
  flyinghead#2415, flyinghead#2416, flyinghead#2519, flyinghead#2520, flyinghead#2521).
- The updater ranks v1.1.0-rc1 under v1.1.0, and a release's build is not
  offered candidates.
- The quick menu's Screenshot row and control are gone: the console's
  Create button takes screenshots.
- Built with PS5_Vulkan 5b5e4fc, the payload SDK fork at b5efad5 and
  libsmb2 7e4ff97.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant