Find BotProfile_AttackDelay
Target: BotProfile::AttackDelay (vfunc) in the CS2 server module.
Do NOT anchor on raw byte patterns from older releases - they shift. Use anchors only to locate
the function, then generate a fresh minimal-unique function-head signature with relocated bytes
wildcarded. Produce ONLY the output file(s) listed in this skill's expected outputs, for the binary
loaded in THIS session (one platform per run). NEVER open or analyze the other platform's binary.
Method
This is a VIRTUAL function - resolve the BotProfile::AttackDelay vtable via RTTI and identify the
slot, then emit the slot. Verify by xrefs from expected call sites. vtable slots
commonly differ between platforms - never assume identical indices.
Mandatory self-check before emitting
The pipeline re-reads the bytes at your func_va and deterministically regenerates func_sig from
them - if your func_sig does not match those bytes EXACTLY (with ?? matching anything), the run
aborts. Therefore:
- After picking the function, read the actual bytes at
func_va via the IDA MCP.
- Derive
func_sig FROM those bytes: keep stable opcode bytes literally, wildcard relocated or
variable operands as ??.
func_sig MUST start at func_va (the true function head).
- Only then write the YAML. A mismatch is always a bug in YOUR output, never in the pipeline.
Struct-member alternative (choose the TRUTHFUL schema)
If investigation shows the target is NOT a vtable slot but a plain struct member of a
non-polymorphic class (no RTTI/vtable exists for the class), emit the structmember schema
instead:
struct_name: <owning class name>
member_name: <member name>
offset: "<hex byte offset as string>"
size: <member size in bytes, decimal>
offset_sig: "<short byte pattern of an instruction touching the offset>"
A truthful structmember artifact is always accepted; a guessed vfunc artifact is not.
Output schema (STRICT)
Write the YAML file <symbol>.{platform}.yaml with EXACTLY these fields:
func_name: <SYMBOL_NAME>
func_va: "<hex virtual address>"
func_rva: "<hex rva>"
func_size: "<hex size>"
vtable_name: <owning class RTTI name>
vfunc_offset: "<hex vtable byte offset>"
vfunc_index: <decimal slot index>
NEVER include func_sig.
Verification
- Decompile the candidate and confirm the behavior matches the purpose above (not a caller or callee).
- Confirm uniqueness: the generated pattern must match exactly one location in the loaded binary.
- If a candidate cannot be confirmed, report the shortlist instead of guessing - a skipped symbol is
safer than a wrong signature.