Skip to content

Write packet 0x68's a6 as a dword at offset 0x0B - #254

Open
ResurrectedTrader wants to merge 1 commit into
ThePhrozenKeep:masterfrom
ResurrectedTrader:fix/packet-0x68-a6-offset
Open

ResurrectedTrader wants to merge 1 commit into
ThePhrozenKeep:masterfrom
ResurrectedTrader:fix/packet-0x68-a6-offset

Conversation

@ResurrectedTrader

Copy link
Copy Markdown
Contributor

D2GAME_PACKETS_SendPacket0x68_6FC3CA90 stored its int32_t a6 in the int8_t unk0x10, which truncates it and leaves unk0x0B (int32_t) zero. The other 0x68 sender in SCmd.cpp already writes a6 to unk0x0B.

1.10f

D2Game.0x6FC3CA90, Hex-Rays. The packet buffer is at ebp-18h, so v21 at ebp-0Dh is packet offset 0x0B:

_DWORD pPacket[2];   // [ebp-18h]
__int16 v19;         // [ebp-10h]  packet + 0x08
char    v20;         // [ebp-0Eh]  packet + 0x0A
int     v21;         // [ebp-0Dh]  packet + 0x0B
char    v22;         // [ebp-09h]  packet + 0x0F
int     v23;         // [ebp-08h]  packet + 0x10
...
LOBYTE(pPacket[0]) = nHeader;
v21 = a6;                                  // <== a6 -> packet + 0x0B, 4 bytes
*(_DWORD *)((char *)pPacket + 1) = nUnitGUID;
v20 = a5;
...
v22 = a7;
...
BYTE1(v23) = v15;                          // nPathType (0x11); LOBYTE(v23) (0x10) stays 0
...
return sub_6FC3C710(pClient, pPacket, 21);

The stores (packet at esp+0Ch, a6 at esp+34h):

6FC3CA90  sub     esp, 18h
6FC3CA93  xor     eax, eax
6FC3CA95  push    ebx
6FC3CA96  mov     [esp+4], eax
6FC3CA9A  push    esi
6FC3CA9B  mov     [esp+0Ch], eax
6FC3CA9F  push    edi
6FC3CAA0  mov     [esp+14h], eax
6FC3CAA4  mov     edi, ecx
6FC3CAA6  mov     cl, [esp+2Ch]                     ; a4
6FC3CAAA  mov     [esp+18h], eax
6FC3CAAE  mov     [esp+1Ch], eax
6FC3CAB2  mov     [esp+11h], cl                     ; packet + 0x05
6FC3CAB6  mov     ecx, [esp+34h]                    ; <== a6
6FC3CABA  mov     [esp+20h], al
6FC3CABE  mov     eax, [esp+28h]                    ; nUnitGUID
6FC3CAC2  mov     [esp+0Ch], dl                     ; packet + 0x00, nHeader
6FC3CAC6  mov     dl, [esp+30h]                     ; a5
6FC3CACA  mov     [esp+17h], ecx                    ; <== packet + 0x0B = a6 (dword)
6FC3CACE  push    eax
6FC3CACF  mov     ecx, edi
6FC3CAD1  mov     [esp+11h], eax                    ; packet + 0x01, nUnitGUID
6FC3CAD5  mov     [esp+1Ah], dl                     ; packet + 0x0A, a5

1.14d

Game.exe 0x0053B5F0, Hex-Rays, the same layout (Src at ebp-18h, v21 at ebp-0Dh):

LOBYTE(Src[0]) = a2;
v21 = a6;                                  // <== packet + 0x0B
*(_DWORD *)((char *)Src + 1) = a3;
v20 = a5;
0053B60C  mov     ecx, [ebp+arg_C]                  ; <== a6
...
0053B621  mov     [ebp+var_10+3], ecx               ; <== packet + 0x0B

Change

packet68.unk0x0B = a6;. Not version-gated, since 1.10f and 1.14d agree. Also adds the 1.14d address.

🤖 Generated with Claude Code

D2GAME_PACKETS_SendPacket0x68_6FC3CA90 stored its int32 a6 in the
int8 unk0x10, which truncates it and leaves unk0x0B (int32) zero. The
other 0x68 sender in the same file already writes a6 to unk0x0B.

1.10f (D2Game.0x6FC3CA90), Hex-Rays with the packet buffer at ebp-18h:

    _DWORD pPacket[2];   // [ebp-18h]
    int    v21;          // [ebp-0Dh]  packet + 0x0B
    ...
    LOBYTE(pPacket[0]) = nHeader;
    *(_DWORD *)((char *)pPacket + 1) = nUnitGUID;
    BYTE1(pPacket[1]) = a4;
    v20 = a5;            // packet + 0x0A
    v21 = a6;            // packet + 0x0B

Disassembly (packet at esp+0Ch, a6 at esp+34h):

    6FC3CAB6  mov ecx, [esp+34h]
    6FC3CACA  mov [esp+17h], ecx

Offset 0x10 is never written. 1.14d (Game.exe 0x0053B5F0) is the same:
v21 = a6 at ebp-0Dh, 0x0053B621 mov [ebp+var_10+3], ecx.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant