hn.today

Infidel Goes Wild

blog.zarfhome.com60 points8 comments
Screenshot of Infidel Goes Wild

This describes a severe but subtle memory-corruption bug found in Infidel’s handling of the Endless Desert. The game models all unmapped desert squares as a single room and records items dropped there in a DESERT-TABLE array (100 words at address 11129). The routine that moves objects into that table takes an optional TBL argument which should default to the DESERT-TABLE address, but the compiler initialized it to the global-variable index number 30 instead. As a result DESERT-TO-TABLE wrote object entries starting at low memory addresses instead of 11129, and TABLE-TO-DESERT later read back from those same wrong addresses. The mistake is a ZIL/Z-machine implementation error: a default argument was compiled as a global index rather than a constant address.

Practical effects were mostly invisible in normal play, because objects dropped in the Endless Desert have a chance to be buried and few players would pile up many items there. When exercised, however, the overflow overwrote header/abbreviation data (around address 64), producing garbled output such as common words being replaced and even interpreter crashes. The bug appears in both the 1983 and later Macintosh releases examined. The write-up demonstrates how a compiler-level default-argument error produced a wild pointer that quietly corrupted game memory until specifically probed.

Read on blog.zarfhome.com8 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Programming

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.