Add default case to all savegame tag switches to prevent parser desync - #1233
Open
acato wants to merge 1 commit into
Open
Add default case to all savegame tag switches to prevent parser desync#1233acato wants to merge 1 commit into
acato wants to merge 1 commit into
Conversation
When an unrecognized tag value is encountered during savegame deserialization, the missing default case meant the tag's data bytes were not consumed. The next loop iteration read those data bytes as the next tag identifier, permanently misaligning the parser. A crafted savegame exploits this to inject controlled values into arbitrary game state fields. Setting bContinue = false in the default case stops deserialization safely. Files that already had FAssert-only defaults (which are stripped in Release builds) now also set bContinue = false. Fixes We-the-People-civ4col-mod#1230 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
default: bContinue = false; break;to 19 savegame switch statements that had no default casebContinue = false;to 3 existing default cases that only had FAssert (stripped in Release builds)22 files touched — all
*Savegame.cppfiles with tag-reading switch statements.Fixes #1230
Test plan
🤖 Generated with Claude Code