Repository navigation
Scan target list slot 8 in sub_6FCF2110 - #255
Open
ResurrectedTrader wants to merge 1 commit into
Open
ResurrectedTrader wants to merge 1 commit into
ResurrectedTrader wants to merge 1 commit into
Conversation
After the eight player slots, the evil-alignment branch of
sub_6FCF2110 walks a further target list. MOO walked whatever
pTargetNode was left over from the player loop (slot 7's head, or
nullptr), so the slot 8 list was never scanned.
The game loads the next slot's head at the end of every player-slot
iteration, so after slot 7 it holds pGame->pTargetNodes[8].
1.10f (D2Game.0x6FCF2110), Hex-Rays (a1 = pGame, 4344 = 0x10F8 =
pTargetNodes):
v12 = *(int ***)(a1 + 4344); // pTargetNodes[0]
v69 = (int *)(a1 + 4344);
...
for ( i = 0; i < 8; ++i )
{
...
v12 = (int **)*++v69; // next slot's head
}
for ( ; v12 != nullptr; v12 = (int **)v12[2] ) // slot 8
{
...
}
v44 = v69;
v46 = (int **)v44[1]; // slot 9
Disassembly:
6FCF21A2 mov ebp, [edi+10F8h] ; pTargetNodes[0]
6FCF21A8 lea eax, [edi+10F8h] ; &pTargetNodes[0]
6FCF21B0 mov [esp+2Ch], eax
...
6FCF246E mov eax, [esp+2Ch] ; every player-slot path ends here
6FCF2472 add eax, 4
6FCF2475 mov [esp+2Ch], eax
6FCF2479 mov ebp, [eax] ; next slot's head
6FCF247B mov eax, [esp+38h] ; slot counter
6FCF247F inc eax
6FCF2480 cmp eax, 8
6FCF2487 jl 6FCF22E7
6FCF248D test ebp, ebp ; walk slot 8
6FCF248F jz 6FCF2551
...
6FCF2551 mov eax, [esp+2Ch] ; &pTargetNodes[8]
6FCF2562 mov ebp, [eax+4] ; pTargetNodes[9], the list that follows
1.14d (Game.exe 0x005DD7F0) is the same: each iteration ends with
v10 = *(int **)(v37 + 4); v37 += 4; (0x005DDA20 mov ebx, [eax+4]),
then the bare for ( ; v10 != nullptr; ...) loop at 0x005DDA3B.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
In the evil-alignment branch of
sub_6FCF2110, after the eight player slots, the game walks one more target list,pGame->pTargetNodes[8]. MOO walked whateverpTargetNodewas left over from the player loop (slot 7's head, ornullptr), so the slot 8 list was never scanned.The game loads the next slot's head at the end of every player-slot iteration, so after slot 7 the pointer holds slot 8.
1.10f
D2Game.0x6FCF2110, Hex-Rays (a1=pGame,4344=0x10F8=pTargetNodes):The slot pointer setup, the loop tail and what follows:
1.14d
MONSTERAI_FindBestTarget(Game.exe0x005DD7F0), Hex-Rays, the same structure:Change
Load
pGame->pTargetNodes[8]before the slot 8 loop. Not version-gated, since 1.10f and 1.14d agree. Also adds the 1.14d address.🤖 Generated with Claude Code