Fix two Jul-16 regressions: BT_DEV_GAUGES crash + -net dead controls mapper

Both surfaced today (dormant ~1 day) the moment the pod launch flags
(BT_DEV_GAUGES=1 BT_START_INSIDE=1, tools/mp_launch.sh) were used to drive in
multiplayer -- which made the same-day paint change look guilty.  Confirmed on
the pre-paint build too; the trigger was the Jul-16 audio attribute work.

1) BT_DEV_GAUGES crash (cdb: CoolingLoopConnection::Update, ~15s in as the gauge
   builds lazily).  The dev-gauge cooling-loop lamp reached the cooling master by
   RAW attribute index -- GetAttributePointer(3) + *(master+0x1d4).  The audio
   commits (cc2b109 ReportLeak etc.) inserted rows into the chained attribute
   tables, so index 3 shifted onto a scalar, the resolve walked garbage, and the
   background pass AV'd.  Fix: route through a complete-type bridge reading NAMED
   members (heat.cpp BTCoolingLoopFrame: linkedSinks.Resolve() +
   Condenser::condenserNumber) -- the databinding rule; never a raw numeric
   attribute index.  Removed the now-orphaned GetAttributePointer-by-index
   helper.  Name-keyed samplers (InputVoltage) were unaffected.

2) -net dead controls mapper (mech wouldn't walk; turning/weapons still worked).
   The RIO mapper is built from a stack SubsystemResource in btl4app.cpp that set
   only name/classID/modelSize -- leaving subsystemFlags as stack GARBAGE, which
   Subsystem::Subsystem copies into simulationFlags.  A stray DontExecuteFlag
   (0x2) froze the mapper (speedDemand stuck at 0).  Config-dependent: clean in
   SP, dirty in -net; the audio commits shifted the stack and flipped the bit.
   Fix: memset each hand-built control-mapper resource to 0 (flags 0 =
   AlwaysExecute, the faithful value -- a mapper must tick every frame).

Verified with the pod launch flags: SP alive 32s no crash; MP mech walks
(speedDemand 61.5 at full throttle, ~430u traveled), both nodes alive, no crash.

KB: reconstruction-gotchas.md gains gotcha 18 (uninitialized stack-resource
flags + the raw-attribute-index-into-a-growing-table variant) and a
verify-under-the-user's-launch-flags note.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
arcattack
2026-07-17 13:58:32 -05:00
co-authored by Claude Opus 4.8
parent e0474ff92a
commit 63250aee41
4 changed files with 104 additions and 27 deletions
+15 -27
View File
@@ -154,22 +154,11 @@ static void *ResolveLink(void *plug)
//
extern bool BTGetSubsystemAuxScreen(Subsystem *sub, int *screen, int *placement, char *label64);
//
// FUN_0041bf44 -- GetAttributePointer(index): a pointer to the subsystem's Nth
// attribute member (the cooling-loop lamp reaches its cooling-master link at
// attribute slot 3), or 0 if the index is out of range. The engine exposes this
// via Simulation::GetAttributePointer(AttributeID); a miss returns &NullAttribute,
// normalised to 0.
//
static void *FindLinkedSubsystem(void *subsystem, int slot)
{
if (subsystem == 0)
return 0;
void *p = ((Simulation *)subsystem)->GetAttributePointer((Simulation::AttributeID)slot);
if (p == (void *)&Simulation::NullAttribute)
return 0;
return p;
}
// (FUN_0041bf44 GetAttributePointer-by-index helper removed with the task #7
// fix: its only caller was CoolingLoopConnection, which now resolves the
// cooling master through the named-member bridge BTCoolingLoopFrame -- reaching
// an attribute by RAW numeric index is exactly what broke when the audio
// attribute rows grew the chained tables.)
//
// FUN_0041a1a4 IsDerivedFrom(0x50f4bc == PoweredSubsystem's ClassDerivations).
@@ -191,10 +180,16 @@ static Logical IsGeneratorDerived(Subsystem *sub) { return BTIsPoweredSubsystem(
//
// CoolingLoopConnection -- @004c3134 ctor / @004c31a0 sampler (vt 0x518ea8).
// When the source subsystem's coolant loop is active (source+0x134 == 1) it
// follows the linked cooling master (FindLinkedSubsystem(source,3) then Resolve)
// and copies its loop-lamp state (+0x1d4); otherwise 0.
// When the source subsystem's coolant loop is available (coolantAvailable == 1,
// the binary's source+0x134 gate) it follows the linked cooling master (binary
// attr id 3 == "HeatSink" == linkedSinks) and shows its Condenser loop number
// (+0x1d4 == condenserNumber, the image-strip frame); otherwise 0.
// task #7 REGRESSION FIX (2026-07-17): the old raw GetAttributePointer(3) +
// *(+0x1d4) walk AV'd after the audio attribute-table rows shifted the chained
// ids (BT_DEV_GAUGES crash). The sampler now routes through a complete-type
// bridge (heat.cpp) reading NAMED members -- the databinding rule (gotcha 8).
//
extern int BTCoolingLoopFrame(void *subsystem);
class CoolingLoopConnection : public GaugeConnection
{
public:
@@ -203,14 +198,7 @@ public:
source(source), destination(destination) {}
void Update() // @004c31a0
{
void *resolved = 0;
if (source != 0 && *(int *)((char *)source + 0x134) == 1)
{
void *linked = FindLinkedSubsystem(source, 3);
if (linked != 0)
resolved = ResolveLink(linked);
}
*destination = (resolved == 0) ? 0 : *(int *)((char *)resolved + 0x1d4);
*destination = BTCoolingLoopFrame(source);
}
protected:
void *source; // @0x10 this[4]