Hook 5 intercepts loadModelFromFileAsync (0x71d4e0) to synchronously load M2
model data for fake in-memory file contexts. processLoadedModelData returns 1
and entities are created, but file context cleanup is currently skipped (leaks
0x60 bytes per load) due to a crash in the cleanup path, and there's a later
EIP=0 crash during the game main loop that needs investigation.
Also adds: combatlog module stub, framecrash anchor vtable hooks (GetRelativeTo
and GetWidth/GetHeight crash guards), embedded Raid_UI_FX model assets with
skins and textures, WU_XYZ debug model.
The native high-level destructor counterpart to CreateEntityInstance_WithAttachment.
Properly detaches from render lists and scene graph before freeing memory,
fixing the delayed crash from dangling pointers in the per-frame render path.
Markers are now created via the game's high-level entity factory (0x6707c0)
which handles spatial registration, render setup, and lifecycle internally.
Removed ~300 lines of dead code: manual game object list insertion, A/B mode
switching, parity scanning, and model attachment wrappers.
Creation works (markers visible). Destruction still crashes — needs correct
destructor for entities created via CreateWorldUnit path (not DestroyWorldObjectAndRelease).
Markers: client-side world object system using CreateGameObject. Places
M2 models at arbitrary world positions via Lua commands (/mark test,
/mark pos). Includes embedded addon, xyz.m2/blp assets served from DLL
memory, position helpers from unit movement struct, and object lifecycle
management (create, cleanup, reposition, alpha, animation).
Framecrash: stub module with reference to crash at 0x007A2452.
Console: debug output via AllocConsole/WriteConsoleA, compiles out
entirely in non-Debug builds. Used by markers and file serve logging.
Build: markers added to feature flag matrix and all-variants step.
Main: conditional markers import, Lua function registration, embedded
addon + asset file serving, console init/deinit lifecycle.
Outline README: added misc planned features and debug mode notes.
- Each module (outline, interact, screenshot) now has its own addon/
subdir with .toc, .lua, and Bindings.xml
- Core WeirdUtils addon lives in src/core/addon/
- build.zig supports compile-time feature gating via -D options
- main.zig uses build_options for conditional imports and addon embedding
- Module addons only load when their module is compiled in
- 'zig build all-variants' produces full.dll + 3 single-module DLLs
Render order: 3-way M2 batch partition — game objects + local player
render first (write depth), then outline targets (stencil marks), then
other players/gear/NPCs. Outlines show through other players but are
occluded by world/WMO/game objects/local player.
Stencil protection: set STENCILWRITEMASK=0 after outline target DIPs
to prevent subsequent renders from overwriting stencil marks.
JFA sentinel: changed from (1,1) to (-1,-1) to move it outside UV
space. Did not fix banding but is correct regardless.
Debug: added DEBUG_SHOW_SILHOUETTE comptime flag to bypass JFA and
composite raw silhouette RT. Confirmed silhouette is clean — banding
is in the JFA pipeline, not stale vertex buffers.
Game object + local player tracking in tracker.zig for batch ordering.
Added project README and outline subsystem README documenting render
pipeline, architecture, known issues, and planned features.
Outline targets now render after all other M2 models instead of before,
so the depth buffer contains full scene geometry (game objects, other
characters, NPCs) when stencil marks are written. Previously only
terrain+WMO depth was available, causing outlines to show through
fences, mailboxes, lamp posts, and other game objects.
StretchRect for depth-stencil surfaces is unsupported on DXVK, returning
D3DERR_INVALIDCALL every frame. Replace the entire DS snapshot approach
with stencil marks written during the DIP hook: outline targets already
depth-test against terrain (batch reordering ensures they draw first),
so STENCILPASS=REPLACE writes stencil=1 where visible. EndScene replay
gates silhouette drawing on STENCILFUNC=EQUAL to achieve terrain/WMO
occlusion without any depth buffer copy.
Switch from double-DIP (which corrupted WoW's GxDevice state) to cached
replay in EndScene. Cache draw params + GPU state (VB, IB, vertex decl,
VS, 256 VS constant registers) during the DIP hook, replay to silhouette
RT in EndScene before the JFA pipeline.
Remove D3D9 state blocks entirely — use comprehensive manual save/restore
of all modified state (render states, sampler states, shader constants,
COM objects with proper AddRef/Release).
Disable depth testing for all silhouette replay categories. By EndScene
the depth buffer has the full scene, so LESSEQUAL testing creates holes
in the silhouette wherever other models overlap — breaking the JFA
outline for targets and raid marks. Corpses already used ZENABLE=FALSE.
Add per-frame diagnostic counters (scan/classify counts by category)
logged via OutputDebugStringA for the first 20 active frames.
Clean up unused code: comAddRef, deviceCreateStateBlock, stateBlockApply.
The dummy device technique (Direct3DCreate9 + CreateDevice) corrupted the
d3d9 proxy's internal state when run on the main rendering thread, causing
model rendering to update at ~10fps while camera remained smooth.
Replace dummy device with direct vtable read from the game's existing
device via GxDevice global (0xC0ED38 + 0x38A8), sourced from UnitXP_SP3.
Also defer D3D9 hook installation until first rendered frame (triggered
from renderDrawDetour) to guarantee the device exists, and add
forceD24S8IfNeeded() in EndScene to force a Reset with D24S8 stencil
format since the deferred install misses the initial device Reset.
Other changes carried from prior session:
- model_hook.zig: native thiscall/naked detours (thunks eliminated)
- tracker.zig: tracked_obj_count made pub
classifyModel no longer calls resolveModelOwner (which dereferenced
unknown memory at model+0x3C0/+0x28 and crashed on terrain/doodad
models). Instead, scanObjects stores validated object pointers from
the object manager, and classifyModel compares model back-pointer
values against that known set — no pointer dereferencing beyond the
model struct itself.
Port the model outline hook system (CM2SceneRenderDraw, ManageRenderListNode,
DrawBatchProjected) from the C++ idris DLL to pure Zig. Includes D3D9 vtable
hooks for stencil-based outline rendering with per-category colors and thickness.
Fix GetObjectByGUID calling convention: was using fastcall (ECX/EDX) but Ghidra
confirms it's __stdcall with stack params and RET 8. Fix lua_pushcclosure address
from 0x6F3B80 (mid-body of another function) to 0x6F3920.
Guard resolveModelOwner in DrawBatchProj with hasTargets() check and cache unit
model status during ManageRenderListNode to avoid raw pointer chasing at render
time. Add IsBadReadPtr validation in resolveModelOwner to match C++ IsValidReadPtr
pattern for page-level memory safety.
Add InteractNearest() and LootAllCorpses() as registered Lua C functions,
ported from the standalone interact DLL. Uses the existing Lua protection
bypass instead of NOP-padding trampolines.
- interact.zig: game API wrappers, object scanning, loot queue with
SceneEnd hook for per-frame processing
- Bindings.xml: keybinding definitions loaded via LoadUIBindingsFromFile
(called explicitly since our virtual addon bypasses LoadAddonRecursive)
- Lua addon: BINDING_HEADER_WEIRDUTILS, Interact() wrapper, /wu interact
PNG encoder: replace literals-only fixed Huffman with stb-style LZ77
matching. Hash-table chain depth scales with compression level (1-9),
giving a smooth tradeoff from fast/light to slow/best. Lazy matching
cancels a match if the next position finds a longer one. Falls back
to store blocks if compressed output is larger than raw.
Screenshot: move hook install from loadScriptFunctionsDetour to
engineInitDetour (GameEngine_MainInitialize at 0x46a400) so it fires
after all DLL_PROCESS_ATTACH hooks. Restore original CTgaFile::Write
prologue before hooking to avoid chaining through UnitXP. Capture
compression level at enqueue time so each queued shot reflects the
quality setting at the moment it was taken. Counter uses hex suffix
(0-F, max 16/sec) and resets each second.