Skip to content

Validate client edict bounds/free state in SV_DropClient_PreHook - #1160

Merged
psychonic merged 2 commits into
alliedmodders:masterfrom
gss-crazydog:Sv_DropClient_PreHook_Fix
Sep 16, 2026
Merged

psychonic merged 2 commits into
alliedmodders:masterfrom
gss-crazydog:Sv_DropClient_PreHook_Fix

Conversation

@gss-crazydog

@gss-crazydog gss-crazydog commented Aug 16, 2026 •

Copy link
Copy Markdown
Contributor

GET_PLAYER_POINTER was being called on the raw edict without confirming it was valid.

This would occasionally cause an "Bad entity in IndexOfEdict()" crash after a client disconnected unexpectedly (e.g. a timeout or other network drop).

I extracted a stacktrace from one of these crashes which helped point to this being the cause

...
L 08/08/2026 - 04:22:00: #4 addons/metamod/dlls/metamod.so(+0xa690) [0xe60cc690] mm_Sys_Error(char const*)
L 08/08/2026 - 04:22:00: #5 engine_i486.so(+0x69c4e) [0xee1cdc4e]
L 08/08/2026 - 04:22:00: #6 engine_i486.so(+0x65636) [0xee1c9636]
L 08/08/2026 - 04:22:00: #7 addons/amxmodx/dlls/amxmodx_mm_i386.so(+0x2068e) [0xe546968e] SV_DropClient(client_s*, int, char const*, ...)

I wasn't able to reliably repro this, although it happened relatively frequently, but I have not seen another crash of this type since applying this patch.

GET_PLAYER_POINTER was being called on the raw edict without confirming it was valid.
Comment thread amxmodx/meta_api.cpp Outdated
@psychonic
psychonic merged commit e75eaa0 into alliedmodders:master Sep 16, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants