Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

tweak(gamestate/server): sanitize network synchronized scene #3174

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

tens0rfl0w
Copy link
Contributor

Goal of this PR

The original GTA network code includes sanitization for local player peds, but it still allows malicious actors to permanently desync a player’s ped on all remote clients. Additionally, other remotely owned entities lack any sanitization, making them vulnerable to similar abuse.

How is this PR achieving the goal

  • Introduces a template-based Sanitize method for all game events, streamlining future sanitization implementations.
  • Blocks all networked synchronized scenes containing entities that are not owned by the requesting client.
  • Provides a bypass mechanism for specific entities via SET_ENTITY_REMOTE_SYNCED_SCENES_ALLOWED.
  • Allows retrieval of the current bypass state with GET_ENTITY_REMOTE_SYNCED_SCENES_ALLOWED.

Note: Once this change reaches general availability, client-side sanitization can be removed entirely.

This PR applies to the following area(s)

FiveM, Server

Successfully tested on

Game builds: 3407

Platforms: Windows

Checklist

  • Code compiles and has been tested successfully.
  • Code explains itself well and/or is documented.
  • My commit message explains what the changes do and what they are for.
  • No extra compilation warnings are added by these changes.

Fixes issues

/

@github-actions github-actions bot added the invalid Requires changes before it's considered valid and can be (re)triaged label Feb 19, 2025
@tens0rfl0w tens0rfl0w force-pushed the tweak/server-gamestate/sanitize-synced-scenes branch from 596f6d6 to 7be0199 Compare February 19, 2025 23:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
invalid Requires changes before it's considered valid and can be (re)triaged
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants