Fix the tester 'buttons crash the game' report: two keyboard killers

Reproduced by full-keyboard fuzz (every WM_CHAR + WM_KEYUP posted to the
game window, per-key liveness; delivery proven by the new BT_KEY_LOG
[keych] trace).  Two distinct issues:

1) '&' == Shift+7 is the engine's dev-console STOP-MISSION keystroke --
   one shifted-key slip while hunting unmapped panel keys (MAP zoom '+'
   is Shift+'=') instantly ended the session, indistinguishable from a
   crash.  Now env-gated (APP.cpp): default ignored with a log line;
   BT_KEY_STOP=1 restores the authentic stop (verified both ways live).
   Same hazard class as the arrow-release '&' alias already swallowed in
   L4CTRL.cpp:1516.

2) '\' (the developer fake-event key) was a REAL wild-jump crash:
   Entity::Dispatch STAMPS entityID/interestZoneID into the message at
   Entity::Message offsets (ENTITY.cpp:236), and the '\' case dispatched
   a bare Receiver-sized ReceiverDataMessageOf<ControlsButton> at the
   Mech -- the stamp wrote past the stack object and corrupted the frame
   (cdb: call to eip=1 out of Receiver::Receive).  The 1995 binary does
   the identical overwrite and survived on stack-layout luck.  Fixed with
   Entity::Message-sized placement-new backing (btl4mppr.cpp); the only
   such call site (grep-verified).

Verified: full fuzz (95 chars + F-keys + letter/digit keyups, 118 keys
delivered) survives end-to-end; '&' stops cleanly under BT_KEY_STOP=1.
KB: reconstruction-gotchas.md gains gotcha 19 (Entity::Dispatch message
stamping) + the '&' note.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
arcattack
2026-07-17 16:06:46 -05:00
co-authored by Claude Opus 4.8
parent 1ed8b05160
commit e2c21c4db2
3 changed files with 69 additions and 3 deletions
+23 -3
View File
@@ -92,6 +92,8 @@
#include <bt.hpp>
#pragma hdrstop
#include <new> // placement-new (the '\' fake-event padded message)
#if !defined(BTL4MPPR_HPP)
# include <btl4mppr.hpp>
#endif
@@ -205,9 +207,22 @@ static void
{
case 0x5c: // '\' -- momentary press straight onto the owner Mech
{
ReceiverDataMessageOf<ControlsButton>
press(0x19, sizeof(ReceiverDataMessageOf<ControlsButton>), 1);
mapper->GetMech()->Dispatch(&press); // (this+0xd0)->vtbl+0xc
// STACK-OVERWRITE FIX (tester "crash" hunt, 2026-07-17):
// Entity::Dispatch STAMPS entityID/interestZoneID into the message
// at Entity::Message offsets (ENTITY.cpp:236) -- dispatching a bare
// ReceiverDataMessageOf<ControlsButton> at an ENTITY writes past
// the stack object and corrupts the frame (the '\' key was an
// instant wild-jump crash; the 1995 build survived the identical
// overwrite on stack-layout luck). Give the message
// Entity::Message-sized backing so the stamp lands in owned
// memory; messageID/messageLength semantics are unchanged.
double storage[
(sizeof(Entity::Message) + sizeof(ReceiverDataMessageOf<ControlsButton>))
/ sizeof(double) + 1];
ReceiverDataMessageOf<ControlsButton> *press =
new ((void *)storage) ReceiverDataMessageOf<ControlsButton>(
0x19, sizeof(ReceiverDataMessageOf<ControlsButton>), 1);
mapper->GetMech()->Dispatch(press); // (this+0xd0)->vtbl+0xc
}
break;
case 0x15e: SendFakeButtonEvent("GeneratorA", 0); break;
@@ -655,6 +670,11 @@ L4MechControlsMapper::MessageHandlerSet&
ReceiverDataMessageOf<ControlsKey> *message
)
{
// DIAG (BT_KEY_LOG): trace every key that reaches the cockpit keyboard
// dispatcher -- proves delivery + names the key in a crash repro.
if (getenv("BT_KEY_LOG"))
DEBUG_STREAM << "[keych] 0x" << std::hex << (int)message->dataContents
<< std::dec << "\n" << std::flush;
switch (message->dataContents)
{
// ---- target range zoom ----