Repository navigation
Conversation
_tail points at the last node's next field, so *_tail is always null in a consistent list and the old test (*_tail == iter) never held. Removing the last node left _tail at &removed->next, and the next AddExtra of a non-high-use type wrote through it; re-adding the removed node made it point at itself, and BaseExtraList::RemoveAllDefault then looped or called through a freed object. The test is now _tail == &iter->next, and the removed node's next is cleared so it can be handed back to AddExtra. Co-Authored-By: Claude Opus 5.5 <[email protected]>
ejams1
marked this pull request as ready for review
October 3, 2026 00:20
Co-Authored-By: Claude Opus 5.5 <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
BaseExtraList::_tailpoints at the last node'snextfield (AddExtradoes*_tail = a_extra; _tail = &a_extra->next). In a consistent list*_tailis therefore alwaysnullptr, so the check inRemoveExtranever holds:if (!_tail || *_tail == iter) {When the removed node is the last one, which is the usual position for a non-high-use type such as
ExtraInstanceData,_tailis left at&removed->next. The nextAddExtraof a non-high-use type writes through it, into a node that is no longer in the list. If that node is the one just removed (remove, try to rebuild, put the old one back), it ends up pointing at itself.BaseExtraList::RemoveAllDefaultthen walks a cycle on the next revert. With one allocator it frees the same block forever; with the stock heap it calls through the freed object's cleared vtable (Fallout4.exe+0272571 call [rax]).The change:
_tail == std::addressof(iter->next), so_tailmoves back toprev->next(or_head) exactly when the last node is removed.nextis cleared. A node removed from the middle still pointed into the list, so handing it back toAddExtra(which assertsnext == nullptr) would link the rest of the list behind it.We found this through a plugin that refreshes reference instance data with
RemoveExtra(kInstanceData)and re-adds the old node when the rebuild fails. Every save load then hung or crashed inRemoveAllDefault.