Skip to content

当前已知范围 ​

格式层 ​

当前 exact EW7 3.5.0 与 WS 3.2.2 BTLX corpus 均可作为 protobuf wire-format stream 直接解析,不需要额外引入一个未证实的自定义 header、trailer 或 envelope。

当前 wire 层支持并验证:

  • varint / fixed32 / fixed64 / length-delimited;
  • groups 的严格匹配;
  • field number 合法性;
  • truncated 数据拒绝;
  • field 原始编码保留;
  • duplicate field 与原始顺序保留;
  • non-canonical varint 原样保留。

“length-delimited payload 恰好还能递归 parse”本身不等于“它就是 nested protobuf message”。nested typing 以 exact native descriptor 为主要依据。

Schema 层 ​

两款游戏的 arm64 native 都包含序列化的 Game.proto FileDescriptorProto:

  • EW7 Android 3.5.0:97 个 top-level messages;
  • WS Android 3.2.2:107 个 top-level messages。

当前 BTLX 根结构指向 Game.ProtoBuf.BattleArgs。EW7 根身份为 Confirmed;WS 为 StronglySupported,主要保留边界是根字段 51/52/53 不在 exact WS 3.2.2 descriptor 中。

递归验证 ​

对 descriptor 可达的 BattleArgs message graph 已做完整 corpus 递归验证:

  • EW7:4,529,472 个 validated message instances;
  • WS:5,473,164 个 validated message instances;
  • 合计:10,002,636;
  • wire mismatch:0;
  • descriptor-typed child parse failure:0。

这说明当前 descriptor 与实际 corpus 的结构兼容性非常强,但依然不能把 schema 名字自动提升成完整 gameplay 行为语义。

跨标题差异 ​

BTLX 不能使用一个不带 profile 的“EasyTech 通用字段表”。已确认的 BattleArgs 同号冲突包括:

  • field 19:EW7 Passages / WS Rivers;
  • field 40:EW7 WinningMovieId / WS Time;
  • field 41:EW7 FailingMovieId / WS Weather;
  • field 130:EW7 CoinToIronRate / WS CoinToFoodRate;
  • field 131:EW7 IronToCoinRate / WS FoodToCoinRate。

WS 将 Passages 放在 field 1901。

仍未闭合 ​

当前重点 Unknown 包括:

  • WS 根 field 51 / 52 / 53;
  • WS BattleGeneralArgs.field4;
  • WS 路径 12.201;
  • EW7 BattleGoalArgs.field15 / field16 的异常样本;
  • exact native BattleArgs consumer;
  • exact native BattleArgs serializer;
  • 更深的玩法/枚举语义。

详见 Unknown / 未闭合。