Files
OpenFUT-Bridge/docs/roadmap.md
T
funman300 49b3030e34 docs: connection-gate findings + roadmap (strategy pivot)
Stop fighting anadius's offline verdict. Document the clean-room findings
(the gate is an upstream in-process Ebisu connection-state check, not socket
traffic) and a milestone roadmap with two first-class outcomes: full playable
AI FUT (A) and a clean-room spec deliverable (B). Name M3 (first ProtoSSL
plaintext on the real Blaze connection) as the smallest end-to-end proof.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29 18:00:27 -07:00

4.5 KiB
Raw Blame History

OpenFUT Bridge roadmap — from here to "Squad Battles loads"

Two first-class outcomes (not one goal + a consolation prize):

  • A. Full playable AI FUT — the emulator build (M1M7). Realistically a multi-month, expert-level reverse-engineering effort.
  • B. Clean-room spec deliverable — a documented map of the auth / Blaze / ProtoSSL / Fire2 surface (transport, gates, framing, decision points). Produced incrementally as the findings from M1M5; finishable and valuable on its own, and the foundation any future emulator needs.

Every milestone's "done" is a client-observable result. Unconfirmed dependencies are flagged.

Done so far

  • In-process version.dll hook (injects, forwards all 17 real exports).
  • Transport confirmed: DirtySDK/ProtoSSL. _ProtoSSLSendPacket @ FIFA23.exe+0xEFA530 hooked (plaintext-capture ready).
  • connect / DNS / LSX (send/recv + WSASend/WSARecv) capture; mutexed log.
  • Gate identified: upstream Ebisu connection-state, in-process (see connection-gate-findings.md).
  • RE toolkit: protossl-scan (scan / xref / disasm / module+offset).

M1 — Locate the connection-state decision point · Outcome B core

  • Read-only hook ProtoSSLConnect; find the Ebisu connection-state getter the FUT-entry path polls.
  • Done: we can name the exact function/return that gates "attempt online."
  • Unknown: coupling to anadius's detour. Effort: ~days.

M2 — Flip the gate (force "connected") · pure gate-flip proof

  • Out-hook the getter / patch the polled state so the game attempts the real connection.
  • Done (observable): the game emits a DNS lookup / connect for the Blaze redirector (gosredirector.*).
  • Unknown: a secondary auth-token gate may also block. TODO/CONFIRM. Effort: ~days.

M3 — First real ProtoSSL plaintext on the Blaze connection · SMALLEST END-TO-END PROOF (see "Smallest milestone")

  • Our redirect catches the Blaze connect; the ProtoSSL hook logs the first plaintext it emits (the TLS ClientHello to the redirector).
  • Done: hook.log shows the ClientHello from the real Blaze connection.
  • Note: this is a TLS handshake frame, not yet a Blaze/Fire2 app-data frame. Effort: small once M2 lands.

M4 — Answer the redirector + decode first Fire2 frame · Outcome B: first decode

  • Inject a response via the ProtoSSL recv side so the client advances; decode the first Blaze/Fire2 request frame from real captured bytes.
  • Done: the client advances past the redirector (sends the next gate's frame).
  • Unknown (BIG): Fire2 framing UNCONFIRMED; ProtoSSL recv-injection / TLS-bypass convention UNCONFIRMED; Blaze component/command IDs UNCONFIRMED. Effort: high.

M5 — Blaze preauth / login / postauth (online session) · Outcome B: full auth surface

  • Answer UTIL preauth, AUTHENTICATION login (reusing anadius's persona surface), UTIL postauth.
  • Done: client reports online / reaches the FUT entry check.
  • Depends on M4 framing. Effort: high.

M6 — FUT entry + hub load (route to OpenFUT Core) · Outcome A

  • Answer the FUT eligibility check; serve the FUT hub (club/squad) from OpenFUT Core via the bridge.
  • Done: the FUT hub UI loads (club/squad screen).
  • Depends on Core's FUT REST surface. Effort: high.

M7 — Squad Battles (AI FUT) · Outcome A goal

  • Wire Squad Battles match setup / rewards against Core.
  • Done: a Squad Battles match starts and rewards apply.
  • Effort: medium-high after M6.

Outcome mapping

  • B (spec) completes as M1M5 are documented — valuable even if A stalls.
  • A (playable AI FUT) requires M1M7.

Smallest provable milestone (step 4)

Refined from the proposed candidate. The single smallest result that validates the whole architecture end-to-end:

M3 — the client emits its first ProtoSSL plaintext onto the real Blaze connection (the ClientHello to the redirector), captured by our hook.

It proves both halves at once: (1) we got the game past its connection-state check — it went online for real; and (2) our redirect + ProtoSSL hook capture real plaintext from that connection.

It deliberately stops short of the candidate's "first Blaze frame" (a Fire2 app-data message), which requires answering the TLS handshake (M4) and depends on the unconfirmed Fire2 / recv-injection work. ClientHello capture needs none of that — making it the smallest, safest proof. The first Fire2 frame is the immediate follow-on (M4).