[Sonic Frontiers] Converse: fix OOB reads, use-after-free and memory leak - #264

Merged
hyperbx merged 12 commits into
hedge-dev:mainfrom
hyperbx:main
Jul 2, 2026
Merged

[Sonic Frontiers] Converse: fix OOB reads, use-after-free and memory leak#264
hyperbx merged 12 commits into
hedge-dev:mainfrom
hyperbx:main

Conversation

@hyperbx

@hyperbxhyperbx commented Jun 29, 2026

Copy link
Copy Markdown
Member

This PR addresses three critical issues in the hook initialised by the Converse library.

  1. The string redirector was storing the length of the string data as the character length, rather than the number of characters in the string. This could lead to out-of-bounds reads when the game copies the redirected string into the Converse buffer.
  2. The string redirector was freeing redirected strings before they were being used.
  3. The string redirector could possibly return null. If it did, a new blank string would be allocated, but also never freed.

This fix needs testing on Linux, as these issues were made more apparent there, but these flaws would also affect Windows too.

@hyperbxhyperbx changed the title [Sonic Frontiers] Converse: fix use-after-free and memory leak[Sonic Frontiers] Converse: fix OOB reads, use-after-free and memory leakJun 29, 2026
@RagdollClashRagdollClash mentioned this pull request Jun 29, 2026
@RagdollClash

Copy link
Copy Markdown
Contributor

Fixes blank strings under Linux

imageimage

@Mefiresu

Copy link
Copy Markdown

Unfortunately still seems to crash with the Tutorial Skip code for me...

@hyperbx

Copy link
Copy Markdown
MemberAuthor

Unfortunately still seems to crash with the Tutorial Skip code for me...

I've been able to replicate this on Windows and it does appear to be a fault with the Converse library. Looking into it.

…ring
The game copies the string using a fixed length, rather than using a terminator.
@hyperbx

Copy link
Copy Markdown
MemberAuthor

@Mefiresu Tutorial Skip should work now, please test again using the latest Converse.hmm in the PR.

@Mefiresu

Copy link
Copy Markdown

Looks to be behaving properly now, 5/5 runs with no crashes.
Thanks for the patch!

@hyperbx
hyperbx requested a review from Sajidur78June 30, 2026 06:06
@hyperbx
hyperbx marked this pull request as draft June 30, 2026 20:40
@hyperbx
hyperbx marked this pull request as ready for review June 30, 2026 20:49
@hyperbx
hyperbxforce-pushed the main branch 2 times, most recently from ee4d9b6 to 3f6baabCompareJuly 1, 2026 09:31
Co-authored-by: Sajid <sajidur78@gmail.com>

@Sajidur78Sajidur78 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@hyperbx
hyperbx merged commit f195a54 into hedge-dev:mainJul 2, 2026
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@hyperbx@RagdollClash@Mefiresu@Sajidur78
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

[Sonic Frontiers] Converse: fix OOB reads, use-after-free and memory leak - #264

Merged
hyperbx merged 12 commits into
hedge-dev:mainfrom
hyperbx:main
Jul 2, 2026
Merged

[Sonic Frontiers] Converse: fix OOB reads, use-after-free and memory leak#264
hyperbx merged 12 commits into
hedge-dev:mainfrom
hyperbx:main

Conversation

@hyperbx

@hyperbxhyperbx commented Jun 29, 2026

Copy link
Copy Markdown
Member

This PR addresses three critical issues in the hook initialised by the Converse library.

  1. The string redirector was storing the length of the string data as the character length, rather than the number of characters in the string. This could lead to out-of-bounds reads when the game copies the redirected string into the Converse buffer.
  2. The string redirector was freeing redirected strings before they were being used.
  3. The string redirector could possibly return null. If it did, a new blank string would be allocated, but also never freed.

This fix needs testing on Linux, as these issues were made more apparent there, but these flaws would also affect Windows too.

@hyperbxhyperbx changed the title [Sonic Frontiers] Converse: fix use-after-free and memory leak[Sonic Frontiers] Converse: fix OOB reads, use-after-free and memory leakJun 29, 2026
@RagdollClashRagdollClash mentioned this pull request Jun 29, 2026
@RagdollClash

Copy link
Copy Markdown
Contributor

Fixes blank strings under Linux

imageimage

@Mefiresu

Copy link
Copy Markdown

Unfortunately still seems to crash with the Tutorial Skip code for me...

@hyperbx

Copy link
Copy Markdown
MemberAuthor

Unfortunately still seems to crash with the Tutorial Skip code for me...

I've been able to replicate this on Windows and it does appear to be a fault with the Converse library. Looking into it.

…ring
The game copies the string using a fixed length, rather than using a terminator.
@hyperbx

Copy link
Copy Markdown
MemberAuthor

@Mefiresu Tutorial Skip should work now, please test again using the latest Converse.hmm in the PR.

@Mefiresu

Copy link
Copy Markdown

Looks to be behaving properly now, 5/5 runs with no crashes.
Thanks for the patch!

@hyperbx
hyperbx requested a review from Sajidur78June 30, 2026 06:06
@hyperbx
hyperbx marked this pull request as draft June 30, 2026 20:40
@hyperbx
hyperbx marked this pull request as ready for review June 30, 2026 20:49
@hyperbx
hyperbxforce-pushed the main branch 2 times, most recently from ee4d9b6 to 3f6baabCompareJuly 1, 2026 09:31
Co-authored-by: Sajid <sajidur78@gmail.com>

@Sajidur78Sajidur78 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@hyperbx
hyperbx merged commit f195a54 into hedge-dev:mainJul 2, 2026
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@hyperbx@RagdollClash@Mefiresu@Sajidur78
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[Sonic Frontiers] Converse: fix OOB reads, use-after-free and memory leak - #264

Merged
hyperbx merged 12 commits into
hedge-dev:mainfrom
hyperbx:main
Jul 2, 2026
Merged

[Sonic Frontiers] Converse: fix OOB reads, use-after-free and memory leak#264
hyperbx merged 12 commits into
hedge-dev:mainfrom
hyperbx:main

Conversation

@hyperbx

@hyperbxhyperbx commented Jun 29, 2026

Copy link
Copy Markdown
Member

This PR addresses three critical issues in the hook initialised by the Converse library.

  1. The string redirector was storing the length of the string data as the character length, rather than the number of characters in the string. This could lead to out-of-bounds reads when the game copies the redirected string into the Converse buffer.
  2. The string redirector was freeing redirected strings before they were being used.
  3. The string redirector could possibly return null. If it did, a new blank string would be allocated, but also never freed.

This fix needs testing on Linux, as these issues were made more apparent there, but these flaws would also affect Windows too.

@hyperbxhyperbx changed the title [Sonic Frontiers] Converse: fix use-after-free and memory leak[Sonic Frontiers] Converse: fix OOB reads, use-after-free and memory leakJun 29, 2026
@RagdollClashRagdollClash mentioned this pull request Jun 29, 2026
@RagdollClash

Copy link
Copy Markdown
Contributor

Fixes blank strings under Linux

imageimage

@Mefiresu

Copy link
Copy Markdown

Unfortunately still seems to crash with the Tutorial Skip code for me...

@hyperbx

Copy link
Copy Markdown
MemberAuthor

Unfortunately still seems to crash with the Tutorial Skip code for me...

I've been able to replicate this on Windows and it does appear to be a fault with the Converse library. Looking into it.

…ring
The game copies the string using a fixed length, rather than using a terminator.
@hyperbx

Copy link
Copy Markdown
MemberAuthor

@Mefiresu Tutorial Skip should work now, please test again using the latest Converse.hmm in the PR.

@Mefiresu

Copy link
Copy Markdown

Looks to be behaving properly now, 5/5 runs with no crashes.
Thanks for the patch!

@hyperbx
hyperbx requested a review from Sajidur78June 30, 2026 06:06
@hyperbx
hyperbx marked this pull request as draft June 30, 2026 20:40
@hyperbx
hyperbx marked this pull request as ready for review June 30, 2026 20:49
@hyperbx
hyperbxforce-pushed the main branch 2 times, most recently from ee4d9b6 to 3f6baabCompareJuly 1, 2026 09:31
Co-authored-by: Sajid <sajidur78@gmail.com>

@Sajidur78Sajidur78 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@hyperbx
hyperbx merged commit f195a54 into hedge-dev:mainJul 2, 2026
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@hyperbx@RagdollClash@Mefiresu@Sajidur78
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[Sonic Frontiers] Converse: fix OOB reads, use-after-free and memory leak - #264

Merged
hyperbx merged 12 commits into
hedge-dev:mainfrom
hyperbx:main
Jul 2, 2026
Merged

[Sonic Frontiers] Converse: fix OOB reads, use-after-free and memory leak#264
hyperbx merged 12 commits into
hedge-dev:mainfrom
hyperbx:main

Conversation

@hyperbx

@hyperbxhyperbx commented Jun 29, 2026

Copy link
Copy Markdown
Member

This PR addresses three critical issues in the hook initialised by the Converse library.

  1. The string redirector was storing the length of the string data as the character length, rather than the number of characters in the string. This could lead to out-of-bounds reads when the game copies the redirected string into the Converse buffer.
  2. The string redirector was freeing redirected strings before they were being used.
  3. The string redirector could possibly return null. If it did, a new blank string would be allocated, but also never freed.

This fix needs testing on Linux, as these issues were made more apparent there, but these flaws would also affect Windows too.

@hyperbxhyperbx changed the title [Sonic Frontiers] Converse: fix use-after-free and memory leak[Sonic Frontiers] Converse: fix OOB reads, use-after-free and memory leakJun 29, 2026
@RagdollClashRagdollClash mentioned this pull request Jun 29, 2026
@RagdollClash

Copy link
Copy Markdown
Contributor

Fixes blank strings under Linux

imageimage

@Mefiresu

Copy link
Copy Markdown

Unfortunately still seems to crash with the Tutorial Skip code for me...

@hyperbx

Copy link
Copy Markdown
MemberAuthor

Unfortunately still seems to crash with the Tutorial Skip code for me...

I've been able to replicate this on Windows and it does appear to be a fault with the Converse library. Looking into it.

…ring
The game copies the string using a fixed length, rather than using a terminator.
@hyperbx

Copy link
Copy Markdown
MemberAuthor

@Mefiresu Tutorial Skip should work now, please test again using the latest Converse.hmm in the PR.

@Mefiresu

Copy link
Copy Markdown

Looks to be behaving properly now, 5/5 runs with no crashes.
Thanks for the patch!

@hyperbx
hyperbx requested a review from Sajidur78June 30, 2026 06:06
@hyperbx
hyperbx marked this pull request as draft June 30, 2026 20:40
@hyperbx
hyperbx marked this pull request as ready for review June 30, 2026 20:49
@hyperbx
hyperbxforce-pushed the main branch 2 times, most recently from ee4d9b6 to 3f6baabCompareJuly 1, 2026 09:31
Co-authored-by: Sajid <sajidur78@gmail.com>

@Sajidur78Sajidur78 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@hyperbx
hyperbx merged commit f195a54 into hedge-dev:mainJul 2, 2026
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@hyperbx@RagdollClash@Mefiresu@Sajidur78
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

[Sonic Frontiers] Converse: fix OOB reads, use-after-free and memory leak - #264

Merged
hyperbx merged 12 commits into
hedge-dev:mainfrom
hyperbx:main
Jul 2, 2026
Merged

[Sonic Frontiers] Converse: fix OOB reads, use-after-free and memory leak#264
hyperbx merged 12 commits into
hedge-dev:mainfrom
hyperbx:main

Conversation

@hyperbx

@hyperbxhyperbx commented Jun 29, 2026

Copy link
Copy Markdown
Member

This PR addresses three critical issues in the hook initialised by the Converse library.

  1. The string redirector was storing the length of the string data as the character length, rather than the number of characters in the string. This could lead to out-of-bounds reads when the game copies the redirected string into the Converse buffer.
  2. The string redirector was freeing redirected strings before they were being used.
  3. The string redirector could possibly return null. If it did, a new blank string would be allocated, but also never freed.

This fix needs testing on Linux, as these issues were made more apparent there, but these flaws would also affect Windows too.

@hyperbxhyperbx changed the title [Sonic Frontiers] Converse: fix use-after-free and memory leak[Sonic Frontiers] Converse: fix OOB reads, use-after-free and memory leakJun 29, 2026
@RagdollClashRagdollClash mentioned this pull request Jun 29, 2026
@RagdollClash

Copy link
Copy Markdown
Contributor

Fixes blank strings under Linux

imageimage

@Mefiresu

Copy link
Copy Markdown

Unfortunately still seems to crash with the Tutorial Skip code for me...

@hyperbx

Copy link
Copy Markdown
MemberAuthor

Unfortunately still seems to crash with the Tutorial Skip code for me...

I've been able to replicate this on Windows and it does appear to be a fault with the Converse library. Looking into it.

…ring
The game copies the string using a fixed length, rather than using a terminator.
@hyperbx

Copy link
Copy Markdown
MemberAuthor

@Mefiresu Tutorial Skip should work now, please test again using the latest Converse.hmm in the PR.

@Mefiresu

Copy link
Copy Markdown

Looks to be behaving properly now, 5/5 runs with no crashes.
Thanks for the patch!

@hyperbx
hyperbx requested a review from Sajidur78June 30, 2026 06:06
@hyperbx
hyperbx marked this pull request as draft June 30, 2026 20:40
@hyperbx
hyperbx marked this pull request as ready for review June 30, 2026 20:49
@hyperbx
hyperbxforce-pushed the main branch 2 times, most recently from ee4d9b6 to 3f6baabCompareJuly 1, 2026 09:31
Co-authored-by: Sajid <sajidur78@gmail.com>

@Sajidur78Sajidur78 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@hyperbx
hyperbx merged commit f195a54 into hedge-dev:mainJul 2, 2026
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@hyperbx@RagdollClash@Mefiresu@Sajidur78
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[Sonic Frontiers] Converse: fix OOB reads, use-after-free and memory leak - #264

Merged
hyperbx merged 12 commits into
hedge-dev:mainfrom
hyperbx:main
Jul 2, 2026
Merged

[Sonic Frontiers] Converse: fix OOB reads, use-after-free and memory leak#264
hyperbx merged 12 commits into
hedge-dev:mainfrom
hyperbx:main

Conversation

@hyperbx

@hyperbxhyperbx commented Jun 29, 2026

Copy link
Copy Markdown
Member

This PR addresses three critical issues in the hook initialised by the Converse library.

  1. The string redirector was storing the length of the string data as the character length, rather than the number of characters in the string. This could lead to out-of-bounds reads when the game copies the redirected string into the Converse buffer.
  2. The string redirector was freeing redirected strings before they were being used.
  3. The string redirector could possibly return null. If it did, a new blank string would be allocated, but also never freed.

This fix needs testing on Linux, as these issues were made more apparent there, but these flaws would also affect Windows too.

@hyperbxhyperbx changed the title [Sonic Frontiers] Converse: fix use-after-free and memory leak[Sonic Frontiers] Converse: fix OOB reads, use-after-free and memory leakJun 29, 2026
@RagdollClashRagdollClash mentioned this pull request Jun 29, 2026
@RagdollClash

Copy link
Copy Markdown
Contributor

Fixes blank strings under Linux

imageimage

@Mefiresu

Copy link
Copy Markdown

Unfortunately still seems to crash with the Tutorial Skip code for me...

@hyperbx

Copy link
Copy Markdown
MemberAuthor

Unfortunately still seems to crash with the Tutorial Skip code for me...

I've been able to replicate this on Windows and it does appear to be a fault with the Converse library. Looking into it.

…ring
The game copies the string using a fixed length, rather than using a terminator.
@hyperbx

Copy link
Copy Markdown
MemberAuthor

@Mefiresu Tutorial Skip should work now, please test again using the latest Converse.hmm in the PR.

@Mefiresu

Copy link
Copy Markdown

Looks to be behaving properly now, 5/5 runs with no crashes.
Thanks for the patch!

@hyperbx
hyperbx requested a review from Sajidur78June 30, 2026 06:06
@hyperbx
hyperbx marked this pull request as draft June 30, 2026 20:40
@hyperbx
hyperbx marked this pull request as ready for review June 30, 2026 20:49
@hyperbx
hyperbxforce-pushed the main branch 2 times, most recently from ee4d9b6 to 3f6baabCompareJuly 1, 2026 09:31
Co-authored-by: Sajid <sajidur78@gmail.com>

@Sajidur78Sajidur78 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@hyperbx
hyperbx merged commit f195a54 into hedge-dev:mainJul 2, 2026
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@hyperbx@RagdollClash@Mefiresu@Sajidur78
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[Sonic Frontiers] Converse: fix OOB reads, use-after-free and memory leak - #264

Merged
hyperbx merged 12 commits into
hedge-dev:mainfrom
hyperbx:main
Jul 2, 2026
Merged

[Sonic Frontiers] Converse: fix OOB reads, use-after-free and memory leak#264
hyperbx merged 12 commits into
hedge-dev:mainfrom
hyperbx:main

Conversation

@hyperbx

@hyperbxhyperbx commented Jun 29, 2026

Copy link
Copy Markdown
Member

This PR addresses three critical issues in the hook initialised by the Converse library.

  1. The string redirector was storing the length of the string data as the character length, rather than the number of characters in the string. This could lead to out-of-bounds reads when the game copies the redirected string into the Converse buffer.
  2. The string redirector was freeing redirected strings before they were being used.
  3. The string redirector could possibly return null. If it did, a new blank string would be allocated, but also never freed.

This fix needs testing on Linux, as these issues were made more apparent there, but these flaws would also affect Windows too.

@hyperbxhyperbx changed the title [Sonic Frontiers] Converse: fix use-after-free and memory leak[Sonic Frontiers] Converse: fix OOB reads, use-after-free and memory leakJun 29, 2026
@RagdollClashRagdollClash mentioned this pull request Jun 29, 2026
@RagdollClash

Copy link
Copy Markdown
Contributor

Fixes blank strings under Linux

imageimage

@Mefiresu

Copy link
Copy Markdown

Unfortunately still seems to crash with the Tutorial Skip code for me...

@hyperbx

Copy link
Copy Markdown
MemberAuthor

Unfortunately still seems to crash with the Tutorial Skip code for me...

I've been able to replicate this on Windows and it does appear to be a fault with the Converse library. Looking into it.

…ring
The game copies the string using a fixed length, rather than using a terminator.
@hyperbx

Copy link
Copy Markdown
MemberAuthor

@Mefiresu Tutorial Skip should work now, please test again using the latest Converse.hmm in the PR.

@Mefiresu

Copy link
Copy Markdown

Looks to be behaving properly now, 5/5 runs with no crashes.
Thanks for the patch!

@hyperbx
hyperbx requested a review from Sajidur78June 30, 2026 06:06
@hyperbx
hyperbx marked this pull request as draft June 30, 2026 20:40
@hyperbx
hyperbx marked this pull request as ready for review June 30, 2026 20:49
@hyperbx
hyperbxforce-pushed the main branch 2 times, most recently from ee4d9b6 to 3f6baabCompareJuly 1, 2026 09:31
Co-authored-by: Sajid <sajidur78@gmail.com>

@Sajidur78Sajidur78 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@hyperbx
hyperbx merged commit f195a54 into hedge-dev:mainJul 2, 2026
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@hyperbx@RagdollClash@Mefiresu@Sajidur78
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

[Sonic Frontiers] Converse: fix OOB reads, use-after-free and memory leak - #264

Merged
hyperbx merged 12 commits into
hedge-dev:mainfrom
hyperbx:main
Jul 2, 2026
Merged

[Sonic Frontiers] Converse: fix OOB reads, use-after-free and memory leak#264
hyperbx merged 12 commits into
hedge-dev:mainfrom
hyperbx:main

Conversation

@hyperbx

@hyperbxhyperbx commented Jun 29, 2026

Copy link
Copy Markdown
Member

This PR addresses three critical issues in the hook initialised by the Converse library.

  1. The string redirector was storing the length of the string data as the character length, rather than the number of characters in the string. This could lead to out-of-bounds reads when the game copies the redirected string into the Converse buffer.
  2. The string redirector was freeing redirected strings before they were being used.
  3. The string redirector could possibly return null. If it did, a new blank string would be allocated, but also never freed.

This fix needs testing on Linux, as these issues were made more apparent there, but these flaws would also affect Windows too.

@hyperbxhyperbx changed the title [Sonic Frontiers] Converse: fix use-after-free and memory leak[Sonic Frontiers] Converse: fix OOB reads, use-after-free and memory leakJun 29, 2026
@RagdollClashRagdollClash mentioned this pull request Jun 29, 2026
@RagdollClash

Copy link
Copy Markdown
Contributor

Fixes blank strings under Linux

imageimage

@Mefiresu

Copy link
Copy Markdown

Unfortunately still seems to crash with the Tutorial Skip code for me...

@hyperbx

Copy link
Copy Markdown
MemberAuthor

Unfortunately still seems to crash with the Tutorial Skip code for me...

I've been able to replicate this on Windows and it does appear to be a fault with the Converse library. Looking into it.

…ring
The game copies the string using a fixed length, rather than using a terminator.
@hyperbx

Copy link
Copy Markdown
MemberAuthor

@Mefiresu Tutorial Skip should work now, please test again using the latest Converse.hmm in the PR.

@Mefiresu

Copy link
Copy Markdown

Looks to be behaving properly now, 5/5 runs with no crashes.
Thanks for the patch!

@hyperbx
hyperbx requested a review from Sajidur78June 30, 2026 06:06
@hyperbx
hyperbx marked this pull request as draft June 30, 2026 20:40
@hyperbx
hyperbx marked this pull request as ready for review June 30, 2026 20:49
@hyperbx
hyperbxforce-pushed the main branch 2 times, most recently from ee4d9b6 to 3f6baabCompareJuly 1, 2026 09:31
Co-authored-by: Sajid <sajidur78@gmail.com>

@Sajidur78Sajidur78 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@hyperbx
hyperbx merged commit f195a54 into hedge-dev:mainJul 2, 2026
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@hyperbx@RagdollClash@Mefiresu@Sajidur78