RF455-038 RF 4.55: item flows where the server's reply doesn't match the client, or has no handler
New
Server: v0.2.0, Windows, stock gameserver.exe (SHA-256 96452fbd…).
Client: the supported Taiwan build, RF_Online.bin SHA-256 46528aac…2bbc558.
These come from comparing each reply with the client handler that reads it.
1. Beepers open the wrong NPC (seen in game)
- 07/3C (
NPCLinkCheckItemResult) sends the beeper's bag serial at body+2. - The client reads that word as the npclink row index, and opens that row's NPC.
- Example:
lknpc20at serial 0x30 opened row 48 (lkcha23, NPC054A7). A serial with no row shows "Can't open the beeper". The disposable beeper is used up either way. - Fix: send the link item's
npclinkitemindex in both success replies ofhandleNPCLinkCheckItem. A local byte patch doing this is in place.
2. Storage from a beeper (22/1B) has no handler
- The storage beepers
lknpc22–24make the client send 22/1Btrunk_download_from_iteminstead of 22/03. - 22/1B isn't registered, so storage never opens.
3. Beepers the client can't use are still consumed
- The client's beeper menu only enables NPC classes 1, 10, 11, 18, 19, 20, 22 and 167.
- So
lknpc06–11(class 6) and everylkcha*/lkchb–f*cash link (classes 168–470) are greyed out, but the server still accepts 07/3B for them and consumes them.
4. Unit replies set the client's gold to 0
- 17/02, 17/06, 17/0A and 17/0C carry two
u64[7]money arrays. - The server fills only
[0](dalant). The client writes[1]to gold, so gold shows 0.
5. Unit sell and bullet replace are stubs
- 17/03 always answers ret 100, and the client shows "MAU : Data error ( 100 )".
- 17/17 always answers ret 100 too, so bullet replace does nothing.
6. No server side for these items
- Summon player: 11/22 has no handler, and 11/20, 11/21 and 11/23 are never sent. The
ipcal01–04potions are refused on 07/07 (ret 0x2F). - Move-potion stone: 11/2D is never sent. The temp effect 70/71 potions are refused on 07/07.
- Soccer ball (07/2E) and rename (07/42): no handlers. The client's bag probably stays in its wait state.
7. 11/17 tower_complete is 2 bytes short
- The server sends 8 bytes.
- The owner's client also reads a u16 bag serial at body+8 and marks that item in use. So the tower item isn't marked, or a stray item is.
8. 07/35 radar_delay_inform is never sent
- No cooldown shows on the radar.
- The ret 8 message prints "Delay period 1 sec".
9. Minor
- Fire cracker: 07/27 goes out through
broadcastExcept, so the user probably doesn't see their own firework. - Box open:
- the item at the serial isn't checked to be that box;
- a full bag gives ret 0xFF "Unidentified error" after the box was already removed, instead of ret 3 "No space".
- Lost-EXP level-limit (0xF7): shows the "while trading" text.
- Trap refusals: sent on 3C/00 instead of 11/1C.
- Never sent: 11/16 (tower HP), 16/0D, 21/04–06, 0E/3B, 0E/3C and 0E/42.
- No handler: 0E/3D.
History
-
cybercyber