fix github issue #731 - accessing freed memory \
after charging causes a ring to explode Reported by gebulmer: if charging exploded a ring, the ring's memory got freed but the stale pointer was passed to cap_spe() which accessed it again. Fix by setting the object pointer to Null after using up the ring. This was a post-3.6 bug. Fixes #731
This commit is contained in:
@@ -1146,6 +1146,7 @@ add '#tip' for containers to context-sensitive invent handling
|
|||||||
sequencing confusion: picking an item when viewing inventory and picking an
|
sequencing confusion: picking an item when viewing inventory and picking an
|
||||||
action to do with it caused the inventory command to use time, then
|
action to do with it caused the inventory command to use time, then
|
||||||
on next turn the action was performed without taking any time
|
on next turn the action was performed without taking any time
|
||||||
|
program would access freed memory if charging caused a ring to explode
|
||||||
|
|
||||||
curses: 'msg_window' option wasn't functional for curses unless the binary
|
curses: 'msg_window' option wasn't functional for curses unless the binary
|
||||||
also included tty support
|
also included tty support
|
||||||
|
|||||||
@@ -786,7 +786,7 @@ recharge(struct obj* obj, int curse_bless)
|
|||||||
if (is_on)
|
if (is_on)
|
||||||
Ring_gone(obj);
|
Ring_gone(obj);
|
||||||
s = rnd(3 * abs(obj->spe)); /* amount of damage */
|
s = rnd(3 * abs(obj->spe)); /* amount of damage */
|
||||||
useup(obj);
|
useup(obj), obj = 0;
|
||||||
losehp(Maybe_Half_Phys(s), "exploding ring", KILLED_BY_AN);
|
losehp(Maybe_Half_Phys(s), "exploding ring", KILLED_BY_AN);
|
||||||
} else {
|
} else {
|
||||||
long mask = is_on ? (obj == uleft ? LEFT_RING : RIGHT_RING) : 0L;
|
long mask = is_on ? (obj == uleft ? LEFT_RING : RIGHT_RING) : 0L;
|
||||||
|
|||||||
Reference in New Issue
Block a user