No description
Find a file
Leilani A. 11f9a2aee2
fix(monsters): reject invalid damage conditions during spell loading (#4072)
Prevent server crashes when loading monster spells that reference unsupported or non-damage condition types.

Main changes:
- Update Monsters::getDamageCondition to create the base condition first.
- Replace the unsafe static_self_cast path with dynamic_pointer_cast<ConditionDamage>.
- Return nullptr when the created condition is not a valid damage condition.
- Update Monsters::deserializeSpell to validate the returned damage condition before adding it to combat.
- Log an error with the condition id and monster description when the condition is invalid.
- Reject the invalid spell instead of continuing with a null or invalid condition pointer.

Crash fixed:
- Avoid access violations caused by monster attacks using condition types that cannot be converted to ConditionDamage.
- Prevent invalid condition setup from reaching Protocol or game startup paths through malformed monster spell definitions.

Tests:
- Add monster_spell_test.cpp.
- Cover unsupported damage condition rejection with CONDITION_AGONY.
- Cover non-damage condition rejection with CONDITION_HASTE.
- Verify invalid spells are rejected and spellBlock.spell remains empty.

This makes monster spell loading safer by rejecting invalid condition types during deserialization instead of allowing unsafe casts to crash the server.
2026-08-12 16:20:06 -03:00
.github build: pin vcpkg registry and developer tools (#4052) 2026-08-05 09:07:02 -03:00
cmake build: pin vcpkg registry and developer tools (#4052) 2026-08-05 09:07:02 -03:00
data feat(pvp): add Expert PvP world type and combat rules (#4033) 2026-08-10 18:42:55 -03:00
data-canary feat: protocol 15.11 (weapon proficiency and new imbuement scroll) (#3845) 2026-05-21 14:34:39 -03:00
data-otservbr-global feat(pvp): add Expert PvP world type and combat rules (#4033) 2026-08-10 18:42:55 -03:00
docker fix(docker): fix MyAAC frontend build and optimize image (#4048) 2026-08-06 13:16:15 -03:00
docs fix(network): retry rejected protocol cleanup (#4073) 2026-08-12 16:03:36 -03:00
metrics feat: 13.32 protocol and features (#2110) 2024-01-21 23:11:37 +00:00
src fix(monsters): reject invalid damage conditions during spell loading (#4072) 2026-08-12 16:20:06 -03:00
tests fix(monsters): reject invalid damage conditions during spell loading (#4072) 2026-08-12 16:20:06 -03:00
tools fix(audit): repair invalid item ranges and reduce storage false positives (#4034) 2026-07-13 22:02:47 -03:00
vcpkg-registry build: pin vcpkg registry and developer tools (#4052) 2026-08-05 09:07:02 -03:00
vcproj feat(pvp): add Expert PvP world type and combat rules (#4033) 2026-08-10 18:42:55 -03:00
.clang-format fix: clang format (#2710) 2024-06-24 14:23:51 -03:00
.cmake-format chore: add cmake-format and cmake-lint (#3672) 2025-09-04 08:37:29 -03:00
.cmake-lint chore: add cmake-format and cmake-lint (#3672) 2025-09-04 08:37:29 -03:00
.dockerignore build(docker): add Canary quickstart with MyAAC and login-server (#3973) 2026-05-25 01:18:52 -03:00
.editorconfig feat: new beds behavior (#1291) 2023-07-28 02:55:07 -03:00
.gitattributes build(docker): add Canary quickstart with MyAAC and login-server (#3973) 2026-05-25 01:18:52 -03:00
.gitignore build: pin vcpkg registry and developer tools (#4052) 2026-08-05 09:07:02 -03:00
.luarc.json feat: add Lua API documentation and doc generator (#3771) 2026-05-25 14:39:39 -03:00
.mise.toml build: pin vcpkg registry and developer tools (#4052) 2026-08-05 09:07:02 -03:00
.reviewdog.yml ci/cd: filter reviewdog to added lines; update ignores (#3846) 2026-02-13 00:52:30 -03:00
.sonarcloud.properties feat: add Lua API documentation and doc generator (#3771) 2026-05-25 14:39:39 -03:00
.yamllint.yaml Improve GHA (#31) 2021-05-21 13:04:57 -03:00
AGENTS.md feat(protocol): add runtime multiprotocol client profiles (#4009) 2026-07-01 13:14:58 -03:00
apply.patch Add apply.patch with git apply instructions 2025-08-28 14:38:53 -03:00
canary.rc Fix GHA builds (#2) 2021-04-28 18:18:18 -03:00
CMakeLists.txt fix: build update CMake policies and Player method access (#3977) 2026-05-25 01:21:33 -03:00
CMakePresets.json improve: refine vcpkg cache handling in CI workflows (#3976) 2026-05-25 00:05:08 -03:00
CODE_OF_CONDUCT.md Initial commit 2021-04-26 21:04:01 -03:00
config.lua.dist feat(pvp): add Expert PvP world type and combat rules (#4033) 2026-08-10 18:42:55 -03:00
CONTRIBUTING.md docs: add CONTRIBUTING.md Guidelines for Canary Project (#3041) 2024-10-31 18:20:01 -03:00
gdb_debug [Enhancement] added scripts to run server with gdb (linux) (#458) 2022-12-08 02:25:02 -03:00
GitVersion.yml Add project automatic version (#29) 2021-06-11 09:50:38 -03:00
Jenkinsfile Initial commit 2021-04-26 21:04:01 -03:00
key.pem Initial commit 2021-04-26 21:04:01 -03:00
LICENSE Initial commit 2021-04-26 21:04:01 -03:00
package.json Updated to version v1.4.1 2022-07-20 22:55:59 +00:00
README.md build: pin vcpkg registry and developer tools (#4052) 2026-08-05 09:07:02 -03:00
recompile.sh fix(recompile): back up the active runtime executable (#4026) 2026-07-06 20:31:54 -03:00
schema.sql feat(pvp): add Expert PvP world type and combat rules (#4033) 2026-08-10 18:42:55 -03:00
start.sh fix: docker ubuntu package and start.sh permission (#2681) 2024-06-11 10:05:04 -03:00
start_gdb.sh [Enhancement] added scripts to run server with gdb (linux) (#458) 2022-12-08 02:25:02 -03:00
vcpkg-configuration.json build: pin vcpkg registry and developer tools (#4052) 2026-08-05 09:07:02 -03:00
vcpkg.json chore: Update vcpkg baseline to 2026.06.24 (#4012) 2026-06-29 22:00:14 -03:00

Canary

Discord CI Quality Gate Status Repository size License

Canary is a free and open-source MMORPG server emulator for the OpenTibia community, written in C++20 and Lua. It is a fork of the OTServBR-Global project. The repository includes the server core, datapacks, Lua scripts, database schema, build presets, automated tests and development tooling used by the project.


Getting Started


Docker Quickstart

Canary includes a lightweight Docker quickstart for running a local test server without compiling Canary locally. The stack starts MariaDB, the published Canary runtime image, MyAAC as the website/admin AAC, and opentibiabr/login-server as the client login webservice.

This quickstart is for local development, testing, and LAN demos. Do not expose it directly to the public Internet with the default test accounts and passwords.

Run from the docker directory:

cp .env.dist .env
docker compose up -d --build

The docker directory also provides guarded start scripts that start the stack and clean safe Docker leftovers without removing database volumes:

.\up.ps1
sh ./up.sh

Default local endpoints:

  • Website/admin: http://localhost:8080
  • Client login webservice: http://localhost:8088/login
  • Game port: 7172

MyAAC's login.php is intentionally removed from the quickstart image. Clients should use login-server only. See docs/docker/quickstart-for-beginners.md for a beginner guide and docker/DOCKER.md for the full setup, environment variables, test account, and troubleshooting guide.


Documentation



Nightly Packages

Development builds can be downloaded from GitHub Actions artifacts. They are useful for testing recent changes from the main branch, but may include behavior that is not present in stable releases yet.


Running Tests

Tests can be run from the repository root using the tool versions and tasks pinned in .mise.toml:

mise install
mise run configure linux-debug
mise run build linux-debug
mise run test linux-debug

# Replace linux-debug with macos-debug or windows-debug as needed.

For detailed testing information including adding tests and framework usage, see tests/README.md.


Support & Community

For real-time support, join the OpenTibiaBR Discord.

The GitHub issue tracker should be used for bugs, improvements and technical project tasks. It is not a support forum.


Contributing

Contributions are welcome. You can help in several ways:

  • Report bugs through the Issue Tracker.
  • Submit improvements through Pull Requests.
  • Improve tests, documentation, scripts, datapacks, or C++ code.
  • Validate releases, nightly builds and recent changes.

Before contributing, read the Code of Conduct and the project Contributing guide.


Sponsorship

Canary is maintained by community contributors. To support development, visit the OpenTibiaBR sponsors page.


Acknowledgements

Thanks to all contributors of Canary, OTServBR-Global and the OpenTibia community.


License

This project is distributed under the GPL-2.0 license.