Old School Ops

RF455-029 RF 4.55: 03/1F other\_shape\_all\_zocl is 8 bytes shorter than the client reads

Game server RF Online: Dragonborn v0.1.1 low · filed by cybercyber 15h ago
Fixed

Game: RF 4.55 (Dragonborn), server v0.1.1. Client: the supported Taiwan build, RF_Online.bin SHA-256 46528aac…2bbc558 (8,430,808 bytes, 2025-07-16). Area: Server (protocol).

The server sends 03/1F (protocol.OtherShapeAll, built by buildShapeAll) as 62 bytes:

0x00  u16 index, u32 serial, u16 ver, u8, u8 race_sex, u8 face, u8 hair
0x0C  8 x (u16 part, u8 upgrade)
0x24  u8 grade
0x25  u32 guild serial
0x29  char name[17]
0x3A  4 bytes (FF FF FF 00 when not riding)

The client's 03/1F handler (RF_Online.bin VA 0x567030) reads 70 bytes, with one more field after the parts:

| Client offset | Field | Server has it at |
|---|---|---|
| 0x24 | u16 extra part (applied with the 8 parts by `0x568AE0`, part id at `0xAB2B75`) | not sent |
| 0x26 | u8 grade | 0x24 |
| 0x27 | u32 guild serial | 0x25 |
| 0x2B | name\\\\\\\[17\\\\\\\] | 0x29 |
| 0x3C, 0x3D | u8, u8 | 0x3A, 0x3B |
| 0x3E | u8 mode: **0 = riding a unit**; 1–4 other states; anything else = on foot | 0x3C |
| 0x3F | u8 unit frame | 0x3D |
| 0x40–0x45 | 6 × u8 unit parts | not sent |

Because of the missing u16 at 0x24, the client reads the name 2 bytes late and the mode byte past the end of the message. That byte is 0, which means "riding unit frame 0".

The look-change message 03/22 (client handler 0x567390, mode byte at 0x24) may have the same gap.

screenshot : Image ## Suggested fix In 03/1F: 1. Write a u16 extra part after the 8 parts (0xFFFF when empty). 2. Extend the unit block to the client's layout: u8, u8, u8 mode (0xFF when not riding), u8 frame, then 6 unit parts. That makes the message 70 bytes.

## Workaround On the client side, moving the 15 field reads in 0x567030 that come after the parts back by 2 bytes fixes it. Those are the 0x26–0x40 displacements, plus the extra-part pointer aimed at the FF FF at 0x3A.

Reported on version 0.1.1
❤️ Ron

History

  • cybercyber filed it · 15h ago
  • cybercyber edited: the game from none to RF Online: Dragonborn, the version from none to v0.1.1, the id from OSO-001 to RF455-029 · 15h ago
  • cybercyber edited: the body · 14h ago
  • cybercyber edited: the body · 14h ago
  • cybercyber edited: the body · 14h ago
  • cybercyber edited: the body · 14h ago
  • OSO AI moved it from New to Fixed · 13h ago

Replies 1

OSO AI Staff
Posts
68
Joined
Sep 2026
13h ago

Reported: The server's full-appearance message for another player (03/1F) is shorter than the 4.55 client reads, so every field after the equipment parts lands in the wrong place.

Found: Confirmed against the supported Taiwan build. The 4.55 client reads one extra two-byte equipment part after the eight standard parts, and our server did not send it. Everything after that point was read two bytes late: other players' grade and guild came out wrong, their names lost the first two characters, and the riding state was read from past the end of the message. A player who really was riding sent the unit block two bytes early and was not drawn on its unit.

The second handler named in the report handles 03/20, not the look-change message 03/22. The server never sends 03/20. The client reads 03/22 as 12 bytes, which is what the server sends, so 03/22 has no gap.

Fix: The server now sends the extra equipment part (empty) and the rest of the message at the positions the 4.55 client reads, as a fixed 70-byte message with the unit block always present. Ships in the next RF 4.55 update.

Sign in to comment.

Loading…
Open the full search page