View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0013552 | Dwarf Fortress | Reactions | public | 2026-09-28 15:34 | 2026-09-28 15:34 |
| Reporter | virus_found | Assigned To | |||
| Priority | normal | Severity | crash | Reproducibility | always |
| Status | new | Resolution | open | ||
| Platform | Linux x86_64 | OS | Linux | OS Version | Void Linux |
| Product Version | 53.16 | ||||
| Summary | 0013552: Crash (SIGSEGV) in item view sheet when clicking items/vermin if entity.resources.reaction_idx contains unmapped or null reactio | ||||
| Description | Dwarf Fortress crashes with a segmentation fault (SIGSEGV) at address 0x13ad2f1 when the player clicks on an item on the ground (e.g. a live vermin item like a caught toad dropped because it is NOT_BUTCHERABLE). Disassembly analysis of dwarfort (v50/v53 Linux build): 0x13ad2e0: movslq (%r14), %rcx ; rcx = reaction index from entity.resources.reaction_idx 0x13ad2e3: mov 0x147bbfe(%rip), %rax ; rax = world.raws.reactions.reactions._M_start 0x13ad2ea: mov %rcx, %rdx 0x13ad2ed: mov (%rax,%rcx,8), %rcx ; rcx = reactions[rcx] (evaluates to NULL) 0x13ad2f1: mov 0x50(%rcx), %r12 ; SIGSEGV dereference of 0x00000050 Root cause: When opening the item view sheet (0x13acb90 invoked via 0x13ae0b0), the engine checks available workshop reactions by iterating over the player entity's known reactions (historical_entity.resources.reaction_idx). At 0x13ad2e0, there is neither an index bounds check nor a null check on reactions[rcx]. If an entity acquires an invalid or unmapped reaction index (e.g. from procedural instruments generated during worldgen or civilization reaction additions), dereferencing offset 0x50 on NULL causes an instant SIGSEGV crash. Call stack: 0> libc.so.6(+0x40110) 1> dwarfort() [0x13ad2f1] ; mov 0x50(%rcx), %r12 2> dwarfort() [0x13ae10b] ; view_sheets dispatcher (context 1: item) 3> dwarfort() [0x13b6c7b] ; tile item query 4> dwarfort() [0xdfcd6c] ; handle tile click (x, y, z) 5> dwarfort() [0x138c16d] ; interface loop mouse handler | ||||
| Steps To Reproduce | 1. Load a world or fortress where the entity has an unmapped or invalid index in historical_entity.resources.reaction_idx. 2. Catch a live vermin toad from a pool via the Fish job (CREATURE:TOAD has AMPHIBIOUS, UNDERSWIM, and NOT_BUTCHERABLE). 3. The fisher drops the live item_verminst onto the grass because it cannot be cleaned at a fishery. 4. Left-click (LMB) on the tile containing the dropped live toad. 5. The game crashes immediately with SIGSEGV. | ||||
| Additional Information | Defensive fix in C++: In the item view sheet reaction scanner, add bounds and null checks before dereferencing: if (rcx >= 0 && rcx < reactions.size()) { reactionst *r = reactions[rcx]; if (r != nullptr) { // scan r->reagents } } | ||||
| Tags | No tags attached. | ||||
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2026-09-28 15:34 | virus_found | New Issue |