1dc1952a3c
ci / verify (push) Successful in 45s
(1) Bullets appeared to trail the ship. Two independent causes, measured with
the new tools/diag_prediction.gd rather than guessed at:
- ServerRuntime ticked before ClientRuntime, so input sampled on frame N was
not consumed until frame N+1, leaving the drawn ship a constant one tick
(4.00px at 240 u/s) ahead of the authoritative one that bullets spawn from.
ClientRuntime now sets process_physics_priority = -10. Gap on a listen
server: 4.00px -> 0.10px mean, 0.30px worst.
- PLAYER_MUZZLE_OFFSET was PLAYER_RADIUS + 6 = 12px against a 13px drawn
ship, so bullets were born inside the sprite. Regression from the previous
commit's hitbox shrink; it now derives from PLAYER_VISUAL_RADIUS.
(2) No more timed respawn. A downed player stays down until they ask for the
hub (E), which is an ordinary input -- the server has no "revive me" message.
(3) Escape channel 3s -> 1s, and damage no longer cancels it. An interruptible
channel makes killing the process strictly better than using the button, so a
dropped connection now runs the same channel: the player stays in the world as
linkdead, still killable, and is only released once it completes. Instances
refuse to close while a linkdead body is resolving, or a solo drop would delete
it on the next tick and hand the exploit straight back.
(4) Escape opens an in-game menu: return to hub (routed through the same held-
escape channel, not a new message), disconnect, quit.
(5) Server pushes a roster so the hub shows who is online and which dungeon
they are in. Entering a dungeon grants 2s arrival protection -- invulnerable
AND weapons-cold, since invulnerability alone would make the spawn a free
firing position -- flagged in the snapshot and drawn on every protected ship.
(6) Cleared dungeons hold the party 30s (was 5s) with a visible countdown.
(7) The hub's grey circle was a 100k-HP target dummy that read as scenery. Now
drawn as a bullseye so its purpose is legible.
Protocol version 1 -> 2. 91 tests (was 78); smoke.sh gains a bot that is
SIGKILLed mid-dungeon to prove the disconnect path end to end. check.sh,
test.sh and smoke.sh all pass.
192 lines
6.8 KiB
GDScript
192 lines
6.8 KiB
GDScript
extends GutTest
|
|
## The security tests. Each one describes something a modified client would try
|
|
## and asserts that the authoritative world does not let it happen.
|
|
##
|
|
## The design intent is that these are boring to write, because the client has
|
|
## no message that expresses the cheat in the first place -- it can only send
|
|
## intent. These tests pin that property down so a future "just let the client
|
|
## send its position, it is simpler" change fails loudly.
|
|
|
|
var world: SimWorld
|
|
const PEER := 7
|
|
|
|
|
|
func before_each() -> void:
|
|
world = SimWorld.new(1)
|
|
world.add_player(PEER, "tester")
|
|
|
|
|
|
func _send(frame_tick: int, move := Vector2.ZERO, buttons := 0, aim := 0.0) -> void:
|
|
var frames: Array[InputFrame] = [InputFrame.make(frame_tick, move, aim, buttons)]
|
|
world.queue_input(PEER, frames)
|
|
|
|
|
|
## Drive the player for [param ticks] ticks with one fresh input per tick.
|
|
func _drive(ticks: int, move := Vector2.ZERO, buttons := 0, aim := 0.0) -> void:
|
|
for _i in ticks:
|
|
_send(world.tick + 1, move, buttons, aim)
|
|
world.step()
|
|
|
|
|
|
func test_player_cannot_outrun_the_configured_speed() -> void:
|
|
var start: Vector2 = world.players[PEER].pos
|
|
_drive(60, Vector2(1.0, 0.0))
|
|
var travelled: float = world.players[PEER].pos.distance_to(start)
|
|
assert_almost_eq(travelled, SimConfig.PLAYER_SPEED, 1.0,
|
|
"one second of held input must cover exactly one second of movement")
|
|
|
|
|
|
func test_replayed_input_is_dropped() -> void:
|
|
_drive(5, Vector2.RIGHT)
|
|
var pos_after: Vector2 = world.players[PEER].pos
|
|
var acked: int = world.players[PEER].last_input_tick
|
|
# Re-send an already-consumed tick, the classic replay attack.
|
|
_send(acked, Vector2.RIGHT)
|
|
assert_eq(world.players[PEER].input_queue.size(), 0)
|
|
world.step()
|
|
# The held input coasts one more tick, which is expected; what matters is
|
|
# that the stale frame did not stack a second move on top of it.
|
|
assert_almost_eq(world.players[PEER].pos.distance_to(pos_after),
|
|
SimConfig.PLAYER_SPEED * SimConfig.TICK_DELTA, 0.001)
|
|
|
|
|
|
func test_input_from_the_far_future_is_dropped() -> void:
|
|
_send(world.tick + SimConfig.INPUT_MAX_LEAD + 50, Vector2.RIGHT)
|
|
assert_eq(world.players[PEER].input_queue.size(), 0,
|
|
"a client cannot buy a head start by claiming a future tick")
|
|
|
|
|
|
func test_ancient_input_is_dropped() -> void:
|
|
world.tick = 10000
|
|
_send(1, Vector2.RIGHT)
|
|
assert_eq(world.players[PEER].input_queue.size(), 0)
|
|
|
|
|
|
func test_input_flood_cannot_grow_the_queue_without_bound() -> void:
|
|
for i in 500:
|
|
_send(world.tick + 1 + i, Vector2.RIGHT)
|
|
assert_lte(world.players[PEER].input_queue.size(), SimConfig.INPUT_MAX_AGE,
|
|
"a flood of inputs must not become unbounded server memory")
|
|
|
|
|
|
func test_fire_rate_is_enforced_by_the_server() -> void:
|
|
# Hold fire every single tick; the server still applies its own cooldown.
|
|
_drive(60, Vector2.ZERO, InputFrame.BTN_FIRE)
|
|
var expected := 60 / SimConfig.PLAYER_FIRE_COOLDOWN
|
|
assert_almost_eq(float(world.pool.live_count), float(expected), 2.0,
|
|
"holding fire must not fire faster than the cooldown allows")
|
|
|
|
|
|
func test_a_starved_player_eventually_stops_moving() -> void:
|
|
_drive(3, Vector2.RIGHT)
|
|
var pos_at_starve: Vector2 = world.players[PEER].pos
|
|
# Send nothing at all for a long time, as a disconnecting client would.
|
|
for _i in SimConfig.INPUT_MAX_AGE + 120:
|
|
world.step()
|
|
var coasted: float = world.players[PEER].pos.distance_to(pos_at_starve)
|
|
assert_lt(coasted, SimConfig.PLAYER_SPEED * 1.0,
|
|
"a silent client must coast briefly, then stop, not drift forever")
|
|
|
|
|
|
func test_enemy_bullets_damage_the_player_and_are_consumed() -> void:
|
|
var p: SimPlayer = world.players[PEER]
|
|
p.pos = Vector2.ZERO
|
|
p.iframes = 0
|
|
world.pool.spawn(Vector2(-1.0, 0.0), Vector2.ZERO, 6.0, 60, 25,
|
|
SimConfig.TEAM_ENEMY, SimConfig.KIND_ORB)
|
|
world.step()
|
|
assert_eq(p.hp, SimConfig.PLAYER_MAX_HP - 25)
|
|
assert_eq(world.pool.live_count, 0, "a bullet that hits must be consumed")
|
|
|
|
|
|
func test_invulnerability_frames_stop_a_second_hit() -> void:
|
|
var p: SimPlayer = world.players[PEER]
|
|
p.pos = Vector2.ZERO
|
|
p.iframes = 0
|
|
for _i in 2:
|
|
world.pool.spawn(Vector2.ZERO, Vector2.ZERO, 6.0, 60, 25,
|
|
SimConfig.TEAM_ENEMY, SimConfig.KIND_ORB)
|
|
world.step()
|
|
assert_eq(p.hp, SimConfig.PLAYER_MAX_HP - 25, "two bullets in one tick is still one hit")
|
|
|
|
|
|
func test_a_replica_world_never_resolves_a_hit() -> void:
|
|
world.authoritative = false
|
|
var p: SimPlayer = world.players[PEER]
|
|
p.pos = Vector2.ZERO
|
|
p.iframes = 0
|
|
world.pool.spawn(Vector2.ZERO, Vector2.ZERO, 6.0, 60, 25,
|
|
SimConfig.TEAM_ENEMY, SimConfig.KIND_ORB)
|
|
world.step()
|
|
assert_eq(p.hp, SimConfig.PLAYER_MAX_HP,
|
|
"only the server decides damage; a client replica must never apply it")
|
|
|
|
|
|
func _kill_player() -> SimPlayer:
|
|
var p: SimPlayer = world.players[PEER]
|
|
p.pos = Vector2.ZERO
|
|
p.hp = 5
|
|
p.iframes = 0
|
|
p.spawn_grace = 0
|
|
world.pool.spawn(Vector2.ZERO, Vector2.ZERO, 6.0, 60, 25,
|
|
SimConfig.TEAM_ENEMY, SimConfig.KIND_ORB)
|
|
world.step()
|
|
assert_false(p.alive, "setup: the player should be down")
|
|
return p
|
|
|
|
|
|
func _events_of(type: int) -> Array:
|
|
return world.events.filter(func(e: Dictionary) -> bool: return int(e["t"]) == type)
|
|
|
|
|
|
func test_a_downed_player_stays_down_without_input() -> void:
|
|
var p := _kill_player()
|
|
world.drain_events()
|
|
for _i in 600:
|
|
world.step()
|
|
assert_false(p.alive, "there is no timed respawn -- death waits for the player")
|
|
assert_eq(_events_of(SimEvent.Type.RESPAWN_REQUESTED).size(), 0)
|
|
|
|
|
|
func test_a_downed_player_asking_to_respawn_is_reported_once_per_tick() -> void:
|
|
_kill_player()
|
|
world.drain_events()
|
|
_drive(1, Vector2.ZERO, InputFrame.BTN_INTERACT)
|
|
assert_eq(_events_of(SimEvent.Type.RESPAWN_REQUESTED).size(), 1,
|
|
"the request is an event for the instance layer, not a local revive")
|
|
# Crucially the world does NOT revive the player itself: only the server's
|
|
# instance layer can, by moving them to the hub.
|
|
assert_false(world.players[PEER].alive)
|
|
|
|
|
|
func test_respawn_request_never_reaches_the_client() -> void:
|
|
_kill_player()
|
|
_drive(1, Vector2.ZERO, InputFrame.BTN_INTERACT)
|
|
var packet := NetCodec.decode_events(NetCodec.encode_events(world.tick, world.events))
|
|
for ev: Dictionary in packet["events"]:
|
|
assert_ne(int(ev["t"]), SimEvent.Type.RESPAWN_REQUESTED,
|
|
"where a dead player goes is the server's decision")
|
|
|
|
|
|
func test_spawn_grace_blocks_damage_and_firing() -> void:
|
|
var p: SimPlayer = world.players[PEER]
|
|
p.pos = Vector2.ZERO
|
|
p.iframes = 0
|
|
p.spawn_grace = 60
|
|
world.pool.spawn(Vector2.ZERO, Vector2.ZERO, 6.0, 60, 25,
|
|
SimConfig.TEAM_ENEMY, SimConfig.KIND_ORB)
|
|
_drive(1, Vector2.ZERO, InputFrame.BTN_FIRE)
|
|
assert_eq(p.hp, SimConfig.PLAYER_MAX_HP, "arrival protection must absorb the hit")
|
|
assert_eq(world.pool.live_count, 1,
|
|
"only the enemy bullet: a protected player cannot shoot either")
|
|
|
|
|
|
func test_spawn_grace_expires() -> void:
|
|
var p: SimPlayer = world.players[PEER]
|
|
p.spawn_grace = 5
|
|
_drive(6)
|
|
assert_eq(p.spawn_grace, 0)
|
|
assert_false(p.invulnerable())
|
|
_drive(1, Vector2.ZERO, InputFrame.BTN_FIRE)
|
|
assert_eq(world.pool.live_count, 1, "the gun comes back once grace ends")
|