[Parity][net-world][S2][R] 自造的客户端限流器:阈值没有出处,而且会静默丢掉非移动命令 #575

Closed
opened 2026-10-02 11:42:40 +00:00 by troytt · 1 comment
Owner

1.13c 客户端保真度审计立项(基准快照:7bd1090 / main @ 77a20c7)

证据标记说明:V-data = 1.13c MPQ 数据表 (.txt / animdata.d2 / .tbl / pal.pl2);V-src = D2MOO 逆向源码;V-bin = 1.13c DLL 反汇编;K = 1.13c 公认行为。

来源审计项:net-world#15 — [S2][R] F15 自造的客户端限流器:阈值没有出处,而且会静默丢掉非移动命令

  • 位置:src/client/session/rate-limiter.ts:36-43、97-102、166-175(120/100/500/80 ms、burst 12、20 条/秒、350 ms 重复移动);src/client/session/online-session.ts:1072-1078(dispatchCommand 不通过就返回 false,没有任何提示);HUD 命令全部走这里(online-session.ts:368-370)
  • 原版:1.13c 客户端没有这种通用命令限流(K 中)。服务器侧也没有这些常量(?)。
  • 影响:连点物品、买卖、交易、对话等 HUD 操作时,部分命令被吞掉而界面不报错,表现为点了没反应。
  • 建议:删除通用限流,或者只保留原版确实存在的节流(例如移动包的发送节奏)并注明出处;被拒的命令至少要有可见反馈。
  • 已有 issue:—
> **1.13c 客户端保真度审计立项**(基准快照:`7bd1090` / `main @ 77a20c7`) > 证据标记说明:`V-data` = 1.13c MPQ 数据表 (`.txt` / `animdata.d2` / `.tbl` / `pal.pl2`);`V-src` = D2MOO 逆向源码;`V-bin` = 1.13c DLL 反汇编;`K` = 1.13c 公认行为。 ### 来源审计项:`net-world#15` — [S2][R] F15 自造的客户端限流器:阈值没有出处,而且会静默丢掉非移动命令 - 位置:`src/client/session/rate-limiter.ts:36-43`、`97-102`、`166-175`(120/100/500/80 ms、burst 12、20 条/秒、350 ms 重复移动);`src/client/session/online-session.ts:1072-1078`(`dispatchCommand` 不通过就返回 false,没有任何提示);HUD 命令全部走这里(`online-session.ts:368-370`) - 原版:1.13c 客户端没有这种通用命令限流(K 中)。服务器侧也没有这些常量(?)。 - 影响:连点物品、买卖、交易、对话等 HUD 操作时,部分命令被吞掉而界面不报错,表现为点了没反应。 - 建议:删除通用限流,或者只保留原版确实存在的节流(例如移动包的发送节奏)并注明出处;被拒的命令至少要有可见反馈。 - 已有 issue:—
Author
Owner

Fixed and verified in commit cc0756de2e.

  • Full typecheck clean across all 7 projects.
  • Comprehensive parity test suite passing (timing-modes-parity.test.ts).
  • Merged and pushed to main.
Fixed and verified in commit cc0756de2ecbfbed474b7d92cb842bde1de9ac7c. - Full typecheck clean across all 7 projects. - Comprehensive parity test suite passing (timing-modes-parity.test.ts). - Merged and pushed to main.
Sign in to join this conversation.
No Label
No Milestone
No project
No Assignees
1 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: troytt/diablo2-web#575
No description provided.