Skip to content

fix(Scripts/Brewfest): Prevent door blocking - #27858

Closed
AlsoNotMehh wants to merge 1 commit into
azerothcore:masterfrom
AlsoNotMehh:fix-direbrew-remote-collision
Closed

AlsoNotMehh wants to merge 1 commit into
azerothcore:masterfrom
AlsoNotMehh:fix-direbrew-remote-collision

Conversation

@AlsoNotMehh

Copy link
Copy Markdown
Contributor

Changes Proposed:

This PR proposes changes to:

  • Core (units, players, creatures, game systems).
  • Scripts (bosses, spell scripts, creature scripts).
  • Database (SAI, creatures, etc).

This prevents the Personal Mole Machine from blocking entrances and narrow paths in capitals and sanctuary areas. The existing gameobject state initialization is preserved, and collision behavior outside those protected areas is unchanged.

AI-assisted Pull Requests

Important

Using AI tools to prepare pull requests is allowed, but it must be disclosed and it must follow our AC guidelines for AI Agentic Engineering (link below).

You are expected to fully understand the changes you submit and to be able to explain and justify them when maintainers ask.

  • AI tools (e.g. Claude, ChatGPT, or similar) were used entirely or partially to prepare this pull request. If checked, specify which tools and models below.
    • Tools/models used: OpenAI Codex (GPT-5)
  • I have read and understood the AC guidelines for AI Agentic Engineering

Issues Addressed:

SOURCE:

The linked issue includes video evidence of the obstruction. This is a scoped exploit mitigation for capital and sanctuary areas. No claim of verified retail behavior is made.

The changes have been validated through:

  • Live research (checked on live servers, e.g Classic WotLK, Retail, etc.)
  • Sniffs (remember to share them with the open source community!)
  • Video evidence, knowledge databases or other public sources (e.g forums, Wowhead, etc.)
  • The changes promoted by this pull request come partially or entirely from another project (cherry-pick). Cherry-picks must be committed using the proper --author tag in order to be accepted, thus crediting the original authors, unless otherwise unable to be found

Tests Performed:

This PR has been:

  • Tested in-game by the author.
  • Tested in-game by other community members/someone else other than the author/has been live on production servers.
  • This pull request requires further testing and may have edge cases to be tested.

The AzerothCore C++ and SQL codestyle checks pass.

How to Test the Changes:

  • This pull request can be tested by following the reproduction steps provided in the linked issue
  • This pull request requires further testing. Provide steps to test your changes. If it requires any specific setup e.g multiple players please specify it as well.
  1. Add item 37863 with .additem 37863.
  2. Use Direbrew's Remote inside a narrow doorway in Stormwind.
  3. Verify players can walk through the Personal Mole Machine and the doorway remains usable.
  4. Repeat in a non-capital, non-sanctuary area and verify the existing collision behavior remains unchanged.

Known Issues and TODO List:

  • In-game verification is still required.

How to Test AzerothCore PRs

When a PR is ready to be tested, it will be marked as [WAITING TO BE TESTED].

You can help by testing PRs and writing your feedback here on the PR's page on GitHub. Follow the instructions here:

http://www.azerothcore.org/wiki/How-to-test-a-PR

REMEMBER: when testing a PR that changes something generic (i.e. a part of code that handles more than one specific thing), the tester should not only check that the PR does its job (e.g. fixing spell XXX) but especially check that the PR does not cause any regression (i.e. introducing new bugs).

For example: if a PR fixes spell X by changing a part of code that handles spells X, Y, and Z, we should not only test X, but we should test Y and Z as well.

Disable Personal Mole Machine collision in capitals and sanctuaries so the temporary object cannot obstruct entrances and other narrow paths.
@github-actions github-actions Bot added DB related to the SQL database Script Refers to C++ Scripts for the Core file-cpp Used to trigger the matrix build labels Sep 28, 2026
@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: azerothcore/azerothcore-wotlk/.coderabbit.yml

Review profile: CHILL

Plan: Advanced

Run ID: 4cc9474d-05ac-4379-8803-fb38959294d4

📥 Commits

Reviewing files that changed from the base of the PR and between a13a617 and 4e6e64b.

📒 Files selected for processing (2)
  • data/sql/updates/pending_db_world/rev_1790609336000000000.sql
  • src/server/scripts/Events/brewfest.cpp

Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

The update binds gameobject 190022 to go_personal_mole_machine and removes its smart_scripts rows. The registered AI marks the object ready on its first update, checks zone and area flags, and disables collision when either record has sanctuary or capital flags.

Priority: ⬇️ Low

Severity of issue fixed: Low

Merge Risk: ⚪ Minimal · up to 4e6e6

No identified issue currently prevents merging. In-game verification of doorway traversal remains appropriate.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 4e6e6

The change is limited to one game object and is intended to remove an obstruction in capitals and sanctuaries. Its location check may not cover every place treated as a sanctuary, and collision is checked only once. Neither condition is confirmed to be exploitable in this change.

Retained concerns

  • Low · security · inferred: The new collision rule checks sanctuary and capital flag bits, while the existing sanctuary helper also recognizes Ebon Hold by map. If an affected Ebon Hold area and its zone lack those bits, the summoned object will retain blocking collision there. The effective area records and summon availability there are unverified.
  • Low · security · inferred: The script applies its location-based collision decision once. A later ready-state change, model replacement, or relocation could leave collision inconsistent with the object's location. The available evidence does not establish that those transitions occur for this particular summoned object.
Security review details

Security Blast Radius

  • inferred — The intended change affects movement around instances of entry 190022 in flagged capitals and sanctuaries, not collision for all game objects. The number of simultaneously placed objects and effective client-side collision are unverified.

Security Findings and Attack Paths

  • inferred — Direbrew's Remote references spell 49844 and is a plausible player-controlled source for the object. The supplied source does not establish the spell effect linking it to entry 190022 or a player-reachable instance of either conditional collision failure.

Trust Boundaries and Controls

  • observed — The item template references a spell and a cooldown; the changed AI itself performs no player-identity or placement authorization check. Its decision uses the spawned object's area and zone records.

Resilience and Maintainability Implications

  • observed — The initialization guard is set before the area lookups. Missing records do not trigger a retry, while the normal valid flagged-area path calls the collision-disabling API.

Hardening Proposals

  • proposed — Align the collision decision with established sanctuary semantics and, if this object's lifecycle permits state or model changes, reapply the location policy after those changes.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@heyitsbench

Copy link
Copy Markdown
Contributor

If there is no official server verification, why is one of the source boxes ticked?

IMO, unless a source is provided, this belongs in a module or similar, I don't feel it should be a baseline AC change.

@LoturCC

LoturCC commented Sep 28, 2026

Copy link
Copy Markdown

IMO,fixing a bug that causes a gameplay interruption doesn't require an official source no? otherwise it will lead to a lot of in game drama and other stuff

@Nyeriah

Nyeriah commented Sep 28, 2026

Copy link
Copy Markdown
Member

Private server problems don’t concern AC and should be kept in modules imo

@Kitzunu

Kitzunu commented Sep 28, 2026

Copy link
Copy Markdown
Member

I agree with Bench and Nyeriah

Copy link
Copy Markdown
Contributor Author

Moved this into an optional module: mod-direbrew-anti-block.

It addresses Personal Mole Machine doorway blocking in capitals and sanctuaries. The README includes the original issue, code sources, and installation steps. In-game testing is still needed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

DB related to the SQL database file-cpp Used to trigger the matrix build Script Refers to C++ Scripts for the Core

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[ITEM]direbrew remote

5 participants