Bots affected
CoF, frequently
Tunnels, sometimes
Description
In commit e4916af, a safeguard was introduced to prevent reads from stale references that span memory block boundaries.
The original issue occurred when an item was picked up or an NPC died. If the corresponding structure extended into a second memory block, and that block contained only the last remaining live reference, the block could be decommitted. Attempting to read fields located in the decommitted block would then result in an access violation.
However, the current implementation is overly conservative. It aborts reads whenever a structure crosses into a different memory block, regardless of whether that block is actually decommitted. As a result, reads from valid, live agents can be prematurely truncated when part of their structure resides in a different committed block.
This causes all fields located in the second block to be read as zero. In practice, this can corrupt agent parsing; for example, an agent's allegiance field may be interpreted as 0, causing the agent to be misclassified or ignored entirely.
Fix
Before aborting a read that crosses a memory block boundary, verify whether the target block is actually decommitted.
If the block is decommitted, the reference is considered stale and the agent can be completely ignored, instead of half-read.
If the block is still committed, the agent is valid and the structure should be read in its entirety.
This preserves the original protection against access violations while allowing legitimate cross-block reads to succeed.
Bots affected
CoF, frequently
Tunnels, sometimes
Description
In commit e4916af, a safeguard was introduced to prevent reads from stale references that span memory block boundaries.
The original issue occurred when an item was picked up or an NPC died. If the corresponding structure extended into a second memory block, and that block contained only the last remaining live reference, the block could be decommitted. Attempting to read fields located in the decommitted block would then result in an access violation.
However, the current implementation is overly conservative. It aborts reads whenever a structure crosses into a different memory block, regardless of whether that block is actually decommitted. As a result, reads from valid, live agents can be prematurely truncated when part of their structure resides in a different committed block.
This causes all fields located in the second block to be read as zero. In practice, this can corrupt agent parsing; for example, an agent's allegiance field may be interpreted as 0, causing the agent to be misclassified or ignored entirely.
Fix
Before aborting a read that crosses a memory block boundary, verify whether the target block is actually decommitted.
If the block is decommitted, the reference is considered stale and the agent can be completely ignored, instead of half-read.
If the block is still committed, the agent is valid and the structure should be read in its entirety.
This preserves the original protection against access violations while allowing legitimate cross-block reads to succeed.