Repository navigation
Conversation
…ring game session cleanup
| memset(this, 0, sizeof(CRunningScript)); // clear base script struct | ||
| strcpy_s(Name, "DELETED"); // upper case | ||
| m_ownedBuffer = nullptr; | ||
| m_parentScript = nullptr; | ||
| m_childScripts.clear(); |
There was a problem hiding this comment.
Zeroing this and setting Name in a destructor does not prevent use-after-free, as the memory block is reclaimed by the heap allocator immediately after the destructor returns (accessing it is still undefined behavior). Also, m_childScripts.clear() is redundant since std::list destructor runs automatically right after.
There was a problem hiding this comment.
It prevents access to data I just nulled. Previously anybody who keep pointer to the just deleted script could use it without problems until that memory block was actually allocated and overwritten by something else.
I would not trust m_childScripts destructor to clear fields internal fields like count in the object that is about to be deleted anyway.
Fix allocated memory blocks summary accessing deleted scripts data during game session cleanup
Since now script structs are deleted right away, instead of waiting for game session to end it needs some consideration what else will start crashing now, including third party scripts and plugins.