2024-01-04 13:52:38 +01:00
|
|
|
From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
|
|
|
|
From: Nassim Jahnke <nassim@njahnke.dev>
|
|
|
|
Date: Thu, 4 Jan 2024 13:49:14 +0100
|
|
|
|
Subject: [PATCH] Validate ResourceLocation in NBT reading
|
|
|
|
|
|
|
|
|
|
|
|
diff --git a/src/main/java/net/minecraft/nbt/NbtUtils.java b/src/main/java/net/minecraft/nbt/NbtUtils.java
|
2024-01-13 16:35:59 +01:00
|
|
|
index 18fad4f083862ace2bc56579883f548f6d697091..8e68a094a22243f3e84110ddf81136219ac1de7c 100644
|
2024-01-04 13:52:38 +01:00
|
|
|
--- a/src/main/java/net/minecraft/nbt/NbtUtils.java
|
|
|
|
+++ b/src/main/java/net/minecraft/nbt/NbtUtils.java
|
|
|
|
@@ -230,8 +230,10 @@ public final class NbtUtils {
|
|
|
|
if (!nbt.contains("Name", 8)) {
|
|
|
|
return Blocks.AIR.defaultBlockState();
|
|
|
|
} else {
|
|
|
|
- ResourceLocation resourceLocation = new ResourceLocation(nbt.getString("Name"));
|
|
|
|
- Optional<? extends Holder<Block>> optional = blockLookup.get(ResourceKey.create(Registries.BLOCK, resourceLocation));
|
|
|
|
+ // Paper start - Validate resource location
|
|
|
|
+ ResourceLocation resourceLocation = ResourceLocation.tryParse(nbt.getString("Name"));
|
|
|
|
+ Optional<? extends Holder<Block>> optional = resourceLocation != null ? blockLookup.get(ResourceKey.create(Registries.BLOCK, resourceLocation)) : Optional.empty();
|
2024-01-13 16:35:59 +01:00
|
|
|
+ // Paper end - Validate resource location
|
2024-01-04 13:52:38 +01:00
|
|
|
if (optional.isEmpty()) {
|
|
|
|
return Blocks.AIR.defaultBlockState();
|
|
|
|
} else {
|
2024-01-12 19:33:17 +01:00
|
|
|
diff --git a/src/main/java/net/minecraft/resources/ResourceLocation.java b/src/main/java/net/minecraft/resources/ResourceLocation.java
|
2024-01-12 23:08:19 +01:00
|
|
|
index 38e2a8cec48bc779b8154d6d719031f457a2403e..4379090b74d156b62b88163a234c22e78454f5e4 100644
|
2024-01-12 19:33:17 +01:00
|
|
|
--- a/src/main/java/net/minecraft/resources/ResourceLocation.java
|
|
|
|
+++ b/src/main/java/net/minecraft/resources/ResourceLocation.java
|
2024-01-12 23:08:19 +01:00
|
|
|
@@ -31,6 +31,13 @@ public class ResourceLocation implements Comparable<ResourceLocation> {
|
2024-01-12 19:33:17 +01:00
|
|
|
private final String path;
|
|
|
|
|
|
|
|
protected ResourceLocation(String namespace, String path, @Nullable ResourceLocation.Dummy extraData) {
|
2024-01-12 23:08:19 +01:00
|
|
|
+ // Paper start - Validate ResourceLocation
|
|
|
|
+ // Check for the max network string length (capped at Short.MAX_VALUE) as well as the max bytes of a StringTag (length written as an unsigned short)
|
|
|
|
+ final String resourceLocation = namespace + ":" + path;
|
|
|
|
+ if (resourceLocation.length() > Short.MAX_VALUE || io.netty.buffer.ByteBufUtil.utf8MaxBytes(resourceLocation) > 2 * Short.MAX_VALUE + 1) {
|
|
|
|
+ throw new ResourceLocationException("Resource location too long: " + resourceLocation);
|
|
|
|
+ }
|
|
|
|
+ // Paper end - Validate ResourceLocation
|
2024-01-12 19:33:17 +01:00
|
|
|
this.namespace = namespace;
|
|
|
|
this.path = path;
|
|
|
|
}
|
2024-01-06 09:51:49 +01:00
|
|
|
diff --git a/src/main/java/net/minecraft/world/entity/EntityType.java b/src/main/java/net/minecraft/world/entity/EntityType.java
|
2024-01-14 10:46:04 +01:00
|
|
|
index abb2a02e0fc1deedb0ad76aec64f74ce355129cc..4bede2ca556a3bbcfbde9709c8415c9ea94383de 100644
|
2024-01-06 09:51:49 +01:00
|
|
|
--- a/src/main/java/net/minecraft/world/entity/EntityType.java
|
|
|
|
+++ b/src/main/java/net/minecraft/world/entity/EntityType.java
|
|
|
|
@@ -618,7 +618,7 @@ public class EntityType<T extends Entity> implements FeatureElement, EntityTypeT
|
|
|
|
}
|
|
|
|
|
|
|
|
public static Optional<EntityType<?>> by(CompoundTag nbt) {
|
|
|
|
- return BuiltInRegistries.ENTITY_TYPE.getOptional(new ResourceLocation(nbt.getString("id")));
|
|
|
|
+ return BuiltInRegistries.ENTITY_TYPE.getOptional(ResourceLocation.tryParse(nbt.getString("id"))); // Paper - Validate ResourceLocation
|
|
|
|
}
|
|
|
|
|
|
|
|
@Nullable
|
2024-01-04 13:52:38 +01:00
|
|
|
diff --git a/src/main/java/net/minecraft/world/entity/Mob.java b/src/main/java/net/minecraft/world/entity/Mob.java
|
2024-01-14 10:46:04 +01:00
|
|
|
index 42e2be9286b75a1d34845f303ffc65e96fdd5416..0b5334004b9d0489e8465824870662b467ce321b 100644
|
2024-01-04 13:52:38 +01:00
|
|
|
--- a/src/main/java/net/minecraft/world/entity/Mob.java
|
|
|
|
+++ b/src/main/java/net/minecraft/world/entity/Mob.java
|
|
|
|
@@ -620,7 +620,7 @@ public abstract class Mob extends LivingEntity implements Targeting {
|
|
|
|
|
|
|
|
this.setLeftHanded(nbt.getBoolean("LeftHanded"));
|
|
|
|
if (nbt.contains("DeathLootTable", 8)) {
|
|
|
|
- this.lootTable = new ResourceLocation(nbt.getString("DeathLootTable"));
|
|
|
|
+ this.lootTable = ResourceLocation.tryParse(nbt.getString("DeathLootTable")); // Paper - Validate ResourceLocation
|
|
|
|
this.lootTableSeed = nbt.getLong("DeathLootTableSeed");
|
|
|
|
}
|
|
|
|
|
|
|
|
diff --git a/src/main/java/net/minecraft/world/entity/projectile/AbstractArrow.java b/src/main/java/net/minecraft/world/entity/projectile/AbstractArrow.java
|
2024-01-14 16:31:39 +01:00
|
|
|
index 6272b0e1e332789b983a486ee25226e2a1c9fdda..505fe5496044f090ce6f7d541b8c3e13c567b16d 100644
|
2024-01-04 13:52:38 +01:00
|
|
|
--- a/src/main/java/net/minecraft/world/entity/projectile/AbstractArrow.java
|
|
|
|
+++ b/src/main/java/net/minecraft/world/entity/projectile/AbstractArrow.java
|
|
|
|
@@ -560,7 +560,7 @@ public abstract class AbstractArrow extends Projectile {
|
|
|
|
this.setCritArrow(nbt.getBoolean("crit"));
|
|
|
|
this.setPierceLevel(nbt.getByte("PierceLevel"));
|
|
|
|
if (nbt.contains("SoundEvent", 8)) {
|
|
|
|
- this.soundEvent = (SoundEvent) BuiltInRegistries.SOUND_EVENT.getOptional(new ResourceLocation(nbt.getString("SoundEvent"))).orElse(this.getDefaultHitGroundSoundEvent());
|
|
|
|
+ this.soundEvent = (SoundEvent) BuiltInRegistries.SOUND_EVENT.getOptional(ResourceLocation.tryParse(nbt.getString("SoundEvent"))).orElse(this.getDefaultHitGroundSoundEvent()); // Paper - Validate resource location
|
|
|
|
}
|
|
|
|
|
|
|
|
this.setShotFromCrossbow(nbt.getBoolean("ShotFromCrossbow"));
|
|
|
|
diff --git a/src/main/java/net/minecraft/world/entity/vehicle/ContainerEntity.java b/src/main/java/net/minecraft/world/entity/vehicle/ContainerEntity.java
|
|
|
|
index 7529751afa2932fd16bc4591189b0358268a7b14..e2e1c7a017e82dc7299e5cd1783818e4f0319c0b 100644
|
|
|
|
--- a/src/main/java/net/minecraft/world/entity/vehicle/ContainerEntity.java
|
|
|
|
+++ b/src/main/java/net/minecraft/world/entity/vehicle/ContainerEntity.java
|
|
|
|
@@ -67,7 +67,7 @@ public interface ContainerEntity extends Container, MenuProvider {
|
|
|
|
default void readChestVehicleSaveData(CompoundTag nbt) {
|
|
|
|
this.clearItemStacks();
|
|
|
|
if (nbt.contains("LootTable", 8)) {
|
|
|
|
- this.setLootTable(new ResourceLocation(nbt.getString("LootTable")));
|
|
|
|
+ this.setLootTable(ResourceLocation.tryParse(nbt.getString("LootTable"))); // Paper - Validate ResourceLocation
|
|
|
|
this.setLootTableSeed(nbt.getLong("LootTableSeed"));
|
|
|
|
}
|
|
|
|
|