Page 3 of 3
Re: Complete list of fixes in v2.0.0 b8
Posted: Thu Oct 08, 2026 11:01 am
by Adminion
Effects
- A particle emitter attached to a side that does not exist, to a missing segment or to a side with fewer than 3 corners emits without a side instead of crashing
- Smoke is not created for an object without an existing segment, and an emitter only takes over a segment that exists
- Particle systems hand out an emitter only for a valid system and an emitter number inside it; player smoke wrote through a pointer behind the emitter array
- The lookup of an object's particle system returns none for an object number outside the table
- Reactor smoke no longer crashes when the robot table has no entry for the reactor's id
- A particle buffer whose particles all have distance 0 or an invalid position is drawn and emptied too (it was never flushed); a negative drift of a rain emitter counts as 0
- Object smoke uses the checked light trail test, so an object id outside the weapon table no longer reads beyond the table
- Animated particle images never select a frame beyond the frames the image has
- Particle collision with the level: a side cache whose fill was cut short is discarded, so a stale entry can no longer lead to a missing surface normal
- Player bullet and gatling smoke effects: the stored ids are reset at level start and tested as particle system ids; objects with a player number outside the player table are skipped
- Moving lightning: a hop without a current way point or without a successor is not made instead of crashing (e.g. a path ending in a way point with speed 0 or less)
- Moving lightning: an object whose current way point is unknown is taken off its path; in a level without way points no lightning object keeps a way point number
- Moving lightning: the way point movement ends after at most 1000 + 2 x way point count hops per tick; it could loop forever
- Way point setup skips an effect object that has no way point data (not a lightning object) instead of crashing
- Omega lightning: a bolt whose owner is gone or whose object number now belongs to another object is dropped, and only the owner's own record is destroyed
- Omega lightning: creating a bolt gives up when its handle no longer exists instead of reading in front of the handle table
- Leaving a game while an omega bolt exists no longer ends the game with an exception (the lightning pool was already destroyed)
- Level lightning: the bolt count is limited to 1000 (the editor's maximum) and the stride of the light samples to 2048
- Hull discharge lightning ignores a sub model animation angle number outside the angle table (it comes unchecked from the model file)
- The lightning colour of an object without a segment is not looked up instead of crashing
- Explosions: an animation number outside the animation table (e.g. -1 from a water hit) becomes the small explosion instead of ending the game
- A fireball with an id outside the animation table is not drawn
- Delayed explosions always compare the signature of the object they are to destroy; with signature -1 they destroyed whatever object sat in the slot
- A robot without an entry in the robot table still explodes, but gives no score and drops no contained objects, stolen items or guidebot marker, instead of crashing
- Exploding models: the model number and the dying / dead model numbers are checked against their tables before they are used
- Splash damage: an explosion exactly at the target's position no longer divides by zero; the target gets full damage without a push
- Shrapnel: the shrapnel setting from the profile is clamped to its table
- Energy sparks: a segment with 0 sparks keeps its real segment number (it was rendered with an undefined segment)
- Shockwave effect: it remembers the signature of its object and lets go of it when the object is gone or the number was reused; it stays at its last position
Re: Complete list of fixes in v2.0.0 b8
Posted: Thu Oct 08, 2026 11:01 am
by Adminion
Cockpit and HUD
- HUD and cockpit texts (player names, guide-bot name, weapon names, game texts) are drawn as plain text and copied with the buffer size; a '%' or a long text could crash
- The ammo text of the primary weapon list is terminated; for weapons without ammo count it showed random memory
- The HUD label of the primary weapon is terminated in every case (super laser)
- The ship damage display reads the console object instead of the local player object, which is stale during demo playback
- The bomb counter is limited to 99 in release builds too; its buffer could overflow
- The cockpit window size and the HUD colour scheme from the player profile are limited to their tables where they are used
- Afterburner gauge of the full cockpit: a charge outside 0 .. 1 no longer walks out of the gauge table
- Player and team names in the name list and the kill list are copied with the buffer size
- A marker view whose marker object no longer exists is ended like an empty marker slot
- A cockpit window whose viewer object is missing for a moment (e.g. team mate view) shows the weapon display instead of failing an assertion; the selected view is kept
- Gauge, cockpit and weapon picture numbers outside the bitmap table are not drawn; weapon icons fall back to bitmap 0; the lives display copes with a missing bitmap
- Static in a cockpit window: an invalid frame or bitmap number or a bitmap without size gives the window back instead of looping without end
- File names of HUD icons are built with the buffer size
Re: Complete list of fixes in v2.0.0 b8
Posted: Thu Oct 08, 2026 11:01 am
by Adminion
Menus
- File selector: the menu is registered and unregistered exactly once on every path (also after Ctrl+D); a stale menu pointer could be called in the next game frame
- A progress window with a running job can no longer be ended by keys, the mouse or a leave request of a multiplayer game; the loader behind it returned with its work half done
- Menu titles, subtitles and message box texts are drawn as plain text instead of being used as printf formats
- A menu style number outside 0 .. 2 becomes 0 before it selects wallpaper and colour style
- A title higher than the usable screen no longer gives a negative menu height or a scroll position behind the items; at least one item line is kept
- New game menu: the start level is at least 1 and at most the last level of the loaded mission; level 0 could be started after a mission failed to load
- Menus and message boxes only render the game behind them while a level is loaded; during the tear down of a game they drew a game frame on destroyed level data
- A wallpaper or background picture that cannot be read is logged, freed and left out instead of ending the program
- An exception raised by a menu callback is logged and closes the menu as cancelled; the menu is unregistered on every way out
- Multiplayer: a request to leave the menus (e.g. reactor countdown below 10 s) closes a menu as cancelled; option menus took it for a rebuild request, reopened and locked the player in
- Quit / save / load menu: when loading a savegame from inside the game fails and no level is left, the game is left instead of running on
- Where the game jumps out of an open menu (game over, end of a demo, aborted wait for players), the abandoned menus are unregistered and text input is switched off
Re: Complete list of fixes in v2.0.0 b8
Posted: Thu Oct 08, 2026 11:01 am
by Adminion
Options, player profile and input
- Mouse joystick simulation: a sensitivity of 0 or a range of 0 gives no deflection instead of a division by zero
- Control bindings with a mouse button above 10, a mouse axis above 2 or a joystick axis above 23 are ignored when the controls are read instead of indexing past the input tables
- Joystick: negative button, axis and device numbers are rejected
- Key configuration: Ctrl+R (reset to defaults) no longer reads past the default tables for keyboard and joystick; mouse defaults come from the row of the mouse type
- When a multiplayer game asks to leave the menus, the input device and loadout menus end instead of opening a sub menu or spinning, and the "press new key" prompt is cancelled
- "Set defaults" in the render or main options menu during a game keeps the lighting method and the lightmap switch the loaded level was built with
- Option menus limit values before they select an entry: entropy virus stability and texture override, mesh quality, dead zone size
- Loading a savegame with Ctrl+F9 or Alt+F3: when the load fails and the game mode is left, the rest of that frame's key handling is skipped
- Player profile: a display mode with a width or height of 0 or below is not looked up; a mode that is not found gives mode 0 instead of an invalid number
- Player profile: values that select table entries (cockpit type, sensitivities, dead zones, radar and HUD settings, menu style, slow motion, entropy and others) are limited to their ranges
- Player profile: lighting method and energy recharge speed are limited to their ranges and are also guarded where they select a table entry
- Player profile: bindings to a mouse button, mouse axis, joystick button or joystick axis the game does not have are cleared; invert flags above 1 become 1 ("unbound" 255 is kept)
- Player profile: a negative count of highest level entries is read as 0; the guide-bot name is terminated
Re: Complete list of fixes in v2.0.0 b8
Posted: Thu Oct 08, 2026 11:01 am
by Adminion
Briefings, movies, texts and start-up
- Briefings: screen, picture and animation names from the script that are longer than their buffers are cut (the rest of the name is still skipped) instead of overflowing
- Briefings: the end of the script text is recognised by every command and treated like a page end (wait for a key, then finish) instead of reading past it
- Briefings: animation frame numbers are clamped to the frames that exist
- Briefing texts, level messages and table texts (version info, high scores) are drawn as plain text; a '%' in them is no longer read as a printf conversion
- The level message being shown is cleared when the level's text data is freed (it pointed at freed memory after a level change)
- Level text files: a file without numbered lines no longer writes in front of its index, a file ending in a line number no longer copies past its end
- A missing credits file skips the credits instead of ending the program
- Movies (MVE): a segment longer than its chunk or a frame size outside 1 .. 256 blocks ends the movie; segments shorter than their fields are skipped
- Movies (MVE): video data without frame buffers or code map is skipped; the decoders check the code map and the bytes each block needs and skip copies from outside the frame
- Movies (MVE): palette start and count are limited to the palette and the segment; the frame delay is limited to 1 second, a timer value could put the game to sleep for half an hour
- Movies (MVE): audio frames with inconsistent lengths are skipped, and frames are dropped while the audio queue is full (a stall led to a copy with a negative length)
- Movie libraries (MVL) with a file count below 1 or larger than the file can hold are refused
- Subtitles: a fourth overlapping caption waits for a free line instead of ending the game; captions that end before they start are ignored; a short read no longer frees the buffer twice
- Game text files: the text buffer is terminated; a short file or a last line without line feed no longer ends the program - missing texts come from the built-in table and are reported once
- Game text files: comment lines in a .tex file no longer shift the extra texts to a negative table index; a backslash at the very end of a text is handled
- Texts from a text file or a mod's text file only replace a built-in text when their printf conversions fit it; a mod text that does not fit is ignored with a log line
- German texts with wrong printf conversions are corrected (team change, lifetime efficiency, joystick axes / buttons / hats, equipment generators, ship drag, flag carrier, D1 texture)
- Destroying the game data resets object and segment counts, the console, viewer and camera pointers and the guided missile table; the distance tables are freed by their own length
- Segment grid: cell and list counts of very large levels are computed in 64 bit; above 4 million cells or 16 million entries the cell size is doubled until it fits
- Level outline: the edge copies made where more than two faces meet are capped (they tripled per face); the outline vertex buffer is checked for room in release builds too
- Thread pool: a worker outside a run could execute the next run's task twice; the number of active workers is now passed together with the run counter (no lock per run)
- Error () and Warning () called from a worker thread or while an error box is already open only write to the log (no box, no recursion); Error () then ends the program
- An Error () raised while an error box is open clears the pending exit message, so no further box is opened during shutdown
Re: Complete list of fixes in v2.0.0 b8
Posted: Thu Oct 08, 2026 11:01 am
by Adminion
Demos
- The frame length in the demo file is 32 bit (demo version 21); rewinding over a frame larger than 32767 bytes ended the playback; old format recordings keep 16 bit
- A frame length that is negative or larger than the file position ends rewinding and "go to end" with a message instead of seeking to a random place
- Multiplayer recordings write the end of the demo in the layout of its start; "go to end" in such a demo overwrote the player table
- An empty text (e.g. the call sign of a player who left) no longer counts as a write error that ends the recording
- A full disk stops the recording once, after the input handling of the frame; it was stopped in the middle of a write and could recurse without end
- Old format recordings and demo conversions: objects the format cannot hold no longer leave a lone event tag that made the file unreadable
- Ending a demo conversion at the physical end of the file no longer crashes
- A recording started in a level without walls no longer writes a second wall table at the next level
- Cloaking wall events are not recorded when a wall number does not fit into the demo format, instead of changing a wrong wall in playback
- Recording a sound of an object that no longer exists, or a 3D powerup whose clip has no frames, no longer crashes
- A demo that cannot be started or breaks in its first frames returns to the main menu instead of crashing; a broken auto demo ends auto demo mode instead of restarting forever
- A truncated demo is noticed at every read; values behind the end of the file are no longer executed as events
- Rewinding across a level change no longer crashes: object, wall, door, texture and viewer data that name segments, sides or walls the loaded level does not have are skipped
- The wall table of a recorded level is applied only to walls the loaded level has; the level's wall count is no longer replaced by the file's
- Player count and player numbers from the demo file are checked: an impossible player count rejects the demo as corrupt, events with invalid player numbers are skipped
- Playback shows a recorded super laser selection as the laser; weapon numbers outside the tables become laser / concussion missile, the afterburner charge is limited
- Objects read from a demo are validated (type, ids, model, texture override, animation clip and frame, smoke side); invalid objects are dropped
- An "attached" explosion as first object of a frame no longer crashes playback; a repeated viewer event in one frame unlinks the viewer before reading it again
- After a level was loaded inside a frame the viewer object is unlinked before the next viewer record overwrites it; a crafted demo could close a segment's object list to a ring
- When no object slot is free in playback the object's record is still read; the playback lost its position in the file before
- Playback of a reactor destruction no longer assumes that every reactor target is a door with a neighbour and an animation
- Cockpit window selectors and sound numbers outside the known ranges are ignored in playback
- Level number 0 in a demo is rejected; "go to end" ends the playback when the level cannot be loaded
- A mission name from the demo file no longer overflows the message buffer when the mission is not installed
- Playback waits at most 1 second per recorded frame; a stall in the recording or a bad frame time froze the playback for as long