View Issue Details

IDProjectCategoryView StatusLast Update
0013552Dwarf FortressReactionspublic2026-09-28 15:34
Reportervirus_found Assigned To 
PrioritynormalSeveritycrashReproducibilityalways
Status newResolutionopen 
PlatformLinux x86_64OSLinuxOS VersionVoid Linux
Product Version53.16 
Summary0013552: Crash (SIGSEGV) in item view sheet when clicking items/vermin if entity.resources.reaction_idx contains unmapped or null reactio
DescriptionDwarf Fortress crashes with a segmentation fault (SIGSEGV) at address 0x13ad2f1 when the player clicks on an item on the ground (e.g. a live vermin item like a caught toad dropped because it is NOT_BUTCHERABLE).

Disassembly analysis of dwarfort (v50/v53 Linux build):

0x13ad2e0: movslq (%r14), %rcx ; rcx = reaction index from entity.resources.reaction_idx
0x13ad2e3: mov 0x147bbfe(%rip), %rax ; rax = world.raws.reactions.reactions._M_start
0x13ad2ea: mov %rcx, %rdx
0x13ad2ed: mov (%rax,%rcx,8), %rcx ; rcx = reactions[rcx] (evaluates to NULL)
0x13ad2f1: mov 0x50(%rcx), %r12 ; SIGSEGV dereference of 0x00000050

Root cause:
When opening the item view sheet (0x13acb90 invoked via 0x13ae0b0), the engine checks available workshop reactions by iterating over the player entity's known reactions (historical_entity.resources.reaction_idx).
At 0x13ad2e0, there is neither an index bounds check nor a null check on reactions[rcx]. If an entity acquires an invalid or unmapped reaction index (e.g. from procedural instruments generated during worldgen or civilization reaction additions),
dereferencing offset 0x50 on NULL causes an instant SIGSEGV crash.

Call stack:
0> libc.so.6(+0x40110)
1> dwarfort() [0x13ad2f1] ; mov 0x50(%rcx), %r12
2> dwarfort() [0x13ae10b] ; view_sheets dispatcher (context 1: item)
3> dwarfort() [0x13b6c7b] ; tile item query
4> dwarfort() [0xdfcd6c] ; handle tile click (x, y, z)
5> dwarfort() [0x138c16d] ; interface loop mouse handler
Steps To Reproduce1. Load a world or fortress where the entity has an unmapped or invalid index in historical_entity.resources.reaction_idx.
2. Catch a live vermin toad from a pool via the Fish job (CREATURE:TOAD has AMPHIBIOUS, UNDERSWIM, and NOT_BUTCHERABLE).
3. The fisher drops the live item_verminst onto the grass because it cannot be cleaned at a fishery.
4. Left-click (LMB) on the tile containing the dropped live toad.
5. The game crashes immediately with SIGSEGV.
Additional InformationDefensive fix in C++:
In the item view sheet reaction scanner, add bounds and null checks before dereferencing:

if (rcx >= 0 && rcx < reactions.size()) {
    reactionst *r = reactions[rcx];
    if (r != nullptr) {
        // scan r->reagents
    }
}
TagsNo tags attached.

Activities

There are no notes attached to this issue.

Add Note

Note

Issue History

Date Modified Username Field Change
2026-09-28 15:34 virus_found New Issue