Skip to content

Pathfinder::moveAllies walks a path that a nested move-away of the same unit has already destroyed #3323

Description

@bobtista

Pathfinder::moveAllies can continue walking a path after a nested move-away order destroys it.

Unit A orders B out of the way. B's own path walk orders A to move away, and A calls destroyPath() on the path the outer walk is still using. The outer walk then continues over freed nodes.

This can crash or change which allies get ordered to move, depending on what happens to the freed memory. Earlier testing with freed-memory poisoning exposed both outcomes.

[VS22 replay: 3323-moveallies-reentry.zip](https://github.com/user-attachments/files/32566939/3323-moveallies-reentry.zip)

Recorded with the automated LAN harness: Twilight Flame, two human GLA players and five hard AI.

To Reproduce:

  1. Play the replay on a stock VS22 Release build from e4017100cd.
  2. At frame 27111, watch Demo Scorpion 15538 order Demo Quad Cannon 14444 out of the way.
  3. The Quad's walk orders the Scorpion to move away. The Scorpion's privateMoveAwayFromUnit destroys the path its outer moveAllies call is still walking.

This replay reproduces the freed-path access, not a Release crash. The base build finishes all 36540 frames without a CRC mismatch.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

BugSomething is not working right, typically is user facing

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions