Files
funman300 49b3030e34 docs: connection-gate findings + roadmap (strategy pivot)
Stop fighting anadius's offline verdict. Document the clean-room findings
(the gate is an upstream in-process Ebisu connection-state check, not socket
traffic) and a milestone roadmap with two first-class outcomes: full playable
AI FUT (A) and a clean-room spec deliverable (B). Name M3 (first ProtoSSL
plaintext on the real Blaze connection) as the smallest end-to-end proof.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29 18:00:27 -07:00

92 lines
4.5 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# OpenFUT Bridge roadmap — from here to "Squad Battles loads"
Two **first-class** outcomes (not one goal + a consolation prize):
- **A. Full playable AI FUT** — the emulator build (M1M7). Realistically a
multi-month, expert-level reverse-engineering effort.
- **B. Clean-room spec deliverable** — a documented map of the auth / Blaze /
ProtoSSL / Fire2 surface (transport, gates, framing, decision points). Produced
incrementally as the findings from M1M5; **finishable and valuable on its
own**, and the foundation any future emulator needs.
Every milestone's "done" is a **client-observable** result. Unconfirmed
dependencies are flagged.
## Done so far
- In-process `version.dll` hook (injects, forwards all 17 real exports).
- Transport confirmed: DirtySDK/ProtoSSL. `_ProtoSSLSendPacket` @
`FIFA23.exe+0xEFA530` hooked (plaintext-capture ready).
- `connect` / DNS / LSX (`send`/`recv` + `WSASend`/`WSARecv`) capture; mutexed log.
- Gate identified: **upstream Ebisu connection-state, in-process** (see
`connection-gate-findings.md`).
- RE toolkit: `protossl-scan` (scan / xref / disasm / module+offset).
## M1 — Locate the connection-state decision point · Outcome B core
- Read-only hook `ProtoSSLConnect`; find the Ebisu connection-state getter the
FUT-entry path polls.
- **Done:** we can name the exact function/return that gates "attempt online."
- Unknown: coupling to anadius's detour. **Effort:** ~days.
## M2 — Flip the gate (force "connected") · pure gate-flip proof
- Out-hook the getter / patch the polled state so the game attempts the real
connection.
- **Done (observable):** the game emits a DNS lookup / `connect` for the Blaze
redirector (`gosredirector.*`).
- Unknown: a secondary auth-token gate may also block. `TODO/CONFIRM`.
**Effort:** ~days.
## M3 — First real ProtoSSL plaintext on the Blaze connection · SMALLEST END-TO-END PROOF (see "Smallest milestone")
- Our redirect catches the Blaze connect; the ProtoSSL hook logs the first
plaintext it emits (the TLS **ClientHello** to the redirector).
- **Done:** `hook.log` shows the ClientHello from the *real* Blaze connection.
- Note: this is a TLS handshake frame, **not yet** a Blaze/Fire2 app-data frame.
**Effort:** small once M2 lands.
## M4 — Answer the redirector + decode first Fire2 frame · Outcome B: first decode
- Inject a response via the ProtoSSL recv side so the client advances; decode
the first Blaze/Fire2 request frame from real captured bytes.
- **Done:** the client advances past the redirector (sends the next gate's frame).
- Unknown (**BIG**): **Fire2 framing UNCONFIRMED**; **ProtoSSL recv-injection /
TLS-bypass convention UNCONFIRMED**; **Blaze component/command IDs UNCONFIRMED**.
**Effort:** high.
## M5 — Blaze preauth / login / postauth (online session) · Outcome B: full auth surface
- Answer UTIL preauth, AUTHENTICATION login (reusing anadius's persona surface),
UTIL postauth.
- **Done:** client reports online / reaches the FUT entry check.
- Depends on M4 framing. **Effort:** high.
## M6 — FUT entry + hub load (route to OpenFUT Core) · Outcome A
- Answer the FUT eligibility check; serve the FUT hub (club/squad) from OpenFUT
Core via the bridge.
- **Done:** the FUT hub UI loads (club/squad screen).
- Depends on Core's FUT REST surface. **Effort:** high.
## M7 — Squad Battles (AI FUT) · Outcome A goal
- Wire Squad Battles match setup / rewards against Core.
- **Done:** a Squad Battles match starts and rewards apply.
- **Effort:** medium-high after M6.
## Outcome mapping
- **B (spec)** completes as M1M5 are documented — valuable even if A stalls.
- **A (playable AI FUT)** requires M1M7.
## Smallest provable milestone (step 4)
Refined from the proposed candidate. The single smallest result that validates
the whole architecture end-to-end:
> **M3 — the client emits its first ProtoSSL plaintext onto the _real_ Blaze
> connection (the ClientHello to the redirector), captured by our hook.**
It proves both halves at once: (1) we got the game past its connection-state
check — it went online **for real**; and (2) our redirect + ProtoSSL hook
capture real plaintext from that connection.
It deliberately stops short of the candidate's "first **Blaze** frame" (a Fire2
app-data message), which requires answering the TLS handshake (M4) and depends
on the unconfirmed Fire2 / recv-injection work. ClientHello capture needs none
of that — making it the smallest, safest proof. The first Fire2 frame is the
immediate follow-on (M4).