Repository navigation
Memory Integrity System
Audience: Programmers
Thread Context: Singleton initialized in
InitDebugSystems()and ticked viaSPARK_GUARDED_UPDATEinsideUpdateDebugSystems(dt)on the main thread. Code-region scanning re-verifies executable pages in periodic batches. Violations are dispatched to Log + EventBus + a user callback.Platform/Backend Scope: Active in all builds (Debug and Release). Code-region discovery uses
VirtualQueryon Windows and/proc/self/mapson Linux.
The Memory Integrity System provides runtime anti-tamper protection. It detects code tampering (NOP'd branches, modified function bodies) and proves that security-critical execution paths actually run. It lives in SparkEngine/Source/Engine/Security/MemoryIntegrity.h / .cpp.
Two layers:
-
Code region scanning — FNV-1a hashes of executable memory pages with periodic batch re-verification. Regions are auto-discovered via
VirtualQuery(Windows) or/proc/self/maps(Linux). -
Branch guards — macros (
SPARK_BRANCH_GUARD_BEGIN/END,SPARK_INTEGRITY_CHECKPOINT/SPARK_VERIFY_CHECKPOINT) that prove a security-critical branch actually executed.
Verified present (2026-06-08) in all of the following:
-
PacketValidator.cpp— payload size, auth, direction checks -
NetworkConnection.cpp— packet validation gateway -
DedicatedServer.cpp— RCON command gate -
SparkConsole.cpp— RBAC permission check -
ScriptSandbox.cpp— instruction / timeout / memory limits -
AbilitySystem.cpp— cooldowns, damage validation, death check, health cap -
InventorySystem.cpp— add/remove validation, capacity check -
Player.cpp(FPS module) — death check -
PlayerConsole.cpp(FPS module) — speed / jump validation -
MMOTradingSystem.cpp— trade state validation -
ARPGSkillSystem.cpp— cooldown check and application
| Location | Reason |
|---|---|
MemoryIntegrity.cpp |
Circular self-reference; its code pages are auto-scanned anyway |
ScriptHotReload.cpp |
Intentionally modifies code at runtime |
RHIValidationLayer.cpp |
Debug-only, not security-critical |
PhysicsSystem.cpp |
Per-frame hot path — overhead unacceptable |
GraphicsEngine.cpp |
Per-frame render loop hot path |
SparkEditor/ |
Development tool, not the shipping client |
- Singleton via
GetInstance(), initialized inInitDebugSystems(). - Ticked via
SPARK_GUARDED_UPDATEinsideUpdateDebugSystems(dt). - Violation response: Log + EventBus event + user callback (the game decides what to do).
- Console commands:
memory.integrity.status/scan/violations(Developer permission). - Test coverage:
Tests/TestMemoryIntegrity.cpp(16 tests, confirmed 2026-06-08). - Active in both Debug and Release builds.
// Conditional branch protection
SPARK_BRANCH_GUARD_BEGIN("name")
if (condition) { ... }
SPARK_BRANCH_GUARD_END("name")
// Linear-flow checkpoint
SPARK_INTEGRITY_CHECKPOINT("name")
// critical code
SPARK_VERIFY_CHECKPOINT("name")- Original entry:
.claude/knowledge/memory-integrity-system.md(created 2026-04-05). - Verified against codebase 2026-06-08.
Status changes / verifications found during freshening:
-
MemoryIntegrity.hand.cppboth present inEngine/Security/. - All 11 documented guard call sites confirmed via grep for
SPARK_BRANCH_GUARD_BEGIN/SPARK_INTEGRITY_CHECKPOINT(engine + FPS/MMO/ARPG modules). -
Tests/TestMemoryIntegrity.cppconfirmed at 16 tests — unchanged. - No status changes; entry is current.
Published from 2b03dc797148. Edit the canonical source in wiki/.
- Documentation
- Docs route
- Wiki index
- Guides
- Tutorials
- Samples
- Examples
- API Reference
- API route
- Reference
- Build Guide
- Dependencies
- FAQ
- Changelog
- Roadmap
- Contributing
- Code of Conduct
- Home
- FAQ
- Getting Started
- Quick-Start Tutorial
- Making Your First Game
- Making Your First Multiplayer Game
- Artist Workflow Guide
- Editor Walkthrough
- Migration Guide
- How SparkEngine Works
- Architecture Overview
- Engine Architecture Flowchart
- Creating a Game Module
- Game Modules (catalog)
- Entity Component System
- Rendering and Graphics
- Physics
- Cloth Simulation
- Audio
- Input System
- Camera System
- Scripting with AngelScript
- Visual Scripting
- AI and Navigation
- Animation
- 2D Systems
- Networking
- Dedicated Server
- Multiplayer Quick Start
- Area Server Architecture
- Scene Management
- Large World Support
- Collaborative Editing
- Coroutine System
- Event System
- Event Response System
- Job System
- UI System
- UI Layout Extensions
- Localization
- Dialogue System
- Destruction System
- Replay System
- Achievement System
- Loading System
- Mod System
- Content Delivery
- Tween System
- Memory Integrity
- Gameplay Systems
- Terrain and Procedural Generation
- Save System
- Persistence System
- Day Night Cycle and Weather
- Cinematic Sequencer
- Runtime Prefabs
- SparkEditor
- Editor Tutorials
- SparkConsole
- SparkDaemon
- Shader Pipeline
- Asset Pipeline
- Asset Validation
- Asset Migration
- Game Packaging
- Online Services
- DataTable System
- Loot and Crafting System
- CSG System
- Font System
- Timer Manager
- Movie Render Pipeline
- HLOD and World Partition
- Remote Debug System
- Selection Manager
- Asset Dependency Graph
- Editor Automation
- File Watcher
- Project Templates
- System Requirements
- VR Support
- Mobile Platform
- Accessibility
- Platform Input
- Platform Certification
- Cross-Compilation: Wine Testing
- RHI Abstraction Layer
- D3D11 Backend
- D3D12 Backend
- Vulkan Backend
- OpenGL Backend
- Metal Backend
- DXR Raytracing
- Hybrid Ray Tracing
- Upscaling (DLSS/FSR)
- Render Graph
- Shader Graph
- GPU Particles
- GPU-Driven Rendering
- Volumetric Fog
- Volumetric Clouds
- Global Illumination
- Virtual Texturing
- Water Rendering
- Clustered Lighting
- Material System
- Post-Processing
- Shadow System
- Particle System
- Decal System
- Sky and Atmosphere
- Foliage System
- Mesh Shaders
- Neural Rendering
- Configuration Reference
- Performance Tips
- Benchmark Framework
- Threading Model
- Fuzz Policy and Parser Security
- Memory Safety
- Memory Management Patterns
- Build System and CMake Modules
- Profiler and Debugging
- Performance Profiling Guide
- Telemetry System
- Crash Reporting
- Golden Image Testing
- Utilities
- Testing
- Fuzz Policy and Parser Security
- Codebase Statistics
- Codebase Health
- Error Handling Patterns
- Hot Reload Overview
- Troubleshooting
- Contributing
- Workflow Patterns
- Build Optimizations
- CI Reproducible Builds
- GitHub API and PR Checks
- Git Rebase Conflicts
- Clang-Format
- Code Quality Violations
- AI Bloat Pattern
- MinGW + Wine Cross-Compilation
- Live Editor Testing
- Engine & Renderer Landscape
- DuetOS Portability Catalog
- Five-Engine Analysis
- Eleven-Engine Analysis
- ThorVG / Unity Graphics Analysis
- Advanced Techniques Catalog
- Third-Party Library Evaluation
- Engine Viability Evaluation
- Engine Feature Recommendations
- Project Recommendations
- Mac Compatibility Analysis
- Codebase Observations
- Codebase Bloat Audit
- Test Suite Audit
- Documentation Coverage Audit
- ThirdParty Dependencies Audit
- Load Test Baseline
- Gameplay Systems Status
- SparkGame Module Status
- Stub and Abandoned Features
- Memory Integrity System
- Memory Safety Evaluation
- Hardware Acceleration Systems
- Jolt Physics Integration
- GPU/CPU Separation Plan
- Daemon Services Architecture
- Reflection & Polymorphism Refactoring Plan
- SparkBuild In-Tree
- Wine No-JobSystem Breakthrough
- Wine Role and Fallback Tiers