Stop fighting anadius's offline verdict. Document the clean-room findings (the gate is an upstream in-process Ebisu connection-state check, not socket traffic) and a milestone roadmap with two first-class outcomes: full playable AI FUT (A) and a clean-room spec deliverable (B). Name M3 (first ProtoSSL plaintext on the real Blaze connection) as the smallest end-to-end proof. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
4.5 KiB
OpenFUT Bridge roadmap — from here to "Squad Battles loads"
Two first-class outcomes (not one goal + a consolation prize):
- A. Full playable AI FUT — the emulator build (M1–M7). Realistically a multi-month, expert-level reverse-engineering effort.
- B. Clean-room spec deliverable — a documented map of the auth / Blaze / ProtoSSL / Fire2 surface (transport, gates, framing, decision points). Produced incrementally as the findings from M1–M5; finishable and valuable on its own, and the foundation any future emulator needs.
Every milestone's "done" is a client-observable result. Unconfirmed dependencies are flagged.
Done so far
- In-process
version.dllhook (injects, forwards all 17 real exports). - Transport confirmed: DirtySDK/ProtoSSL.
_ProtoSSLSendPacket@FIFA23.exe+0xEFA530hooked (plaintext-capture ready). connect/ DNS / LSX (send/recv+WSASend/WSARecv) capture; mutexed log.- Gate identified: upstream Ebisu connection-state, in-process (see
connection-gate-findings.md). - RE toolkit:
protossl-scan(scan / xref / disasm / module+offset).
M1 — Locate the connection-state decision point · Outcome B core
- Read-only hook
ProtoSSLConnect; find the Ebisu connection-state getter the FUT-entry path polls. - Done: we can name the exact function/return that gates "attempt online."
- Unknown: coupling to anadius's detour. Effort: ~days.
M2 — Flip the gate (force "connected") · pure gate-flip proof
- Out-hook the getter / patch the polled state so the game attempts the real connection.
- Done (observable): the game emits a DNS lookup /
connectfor the Blaze redirector (gosredirector.*). - Unknown: a secondary auth-token gate may also block.
TODO/CONFIRM. Effort: ~days.
M3 — First real ProtoSSL plaintext on the Blaze connection · SMALLEST END-TO-END PROOF (see "Smallest milestone")
- Our redirect catches the Blaze connect; the ProtoSSL hook logs the first plaintext it emits (the TLS ClientHello to the redirector).
- Done:
hook.logshows the ClientHello from the real Blaze connection. - Note: this is a TLS handshake frame, not yet a Blaze/Fire2 app-data frame. Effort: small once M2 lands.
M4 — Answer the redirector + decode first Fire2 frame · Outcome B: first decode
- Inject a response via the ProtoSSL recv side so the client advances; decode the first Blaze/Fire2 request frame from real captured bytes.
- Done: the client advances past the redirector (sends the next gate's frame).
- Unknown (BIG): Fire2 framing UNCONFIRMED; ProtoSSL recv-injection / TLS-bypass convention UNCONFIRMED; Blaze component/command IDs UNCONFIRMED. Effort: high.
M5 — Blaze preauth / login / postauth (online session) · Outcome B: full auth surface
- Answer UTIL preauth, AUTHENTICATION login (reusing anadius's persona surface), UTIL postauth.
- Done: client reports online / reaches the FUT entry check.
- Depends on M4 framing. Effort: high.
M6 — FUT entry + hub load (route to OpenFUT Core) · Outcome A
- Answer the FUT eligibility check; serve the FUT hub (club/squad) from OpenFUT Core via the bridge.
- Done: the FUT hub UI loads (club/squad screen).
- Depends on Core's FUT REST surface. Effort: high.
M7 — Squad Battles (AI FUT) · Outcome A goal
- Wire Squad Battles match setup / rewards against Core.
- Done: a Squad Battles match starts and rewards apply.
- Effort: medium-high after M6.
Outcome mapping
- B (spec) completes as M1–M5 are documented — valuable even if A stalls.
- A (playable AI FUT) requires M1–M7.
Smallest provable milestone (step 4)
Refined from the proposed candidate. The single smallest result that validates the whole architecture end-to-end:
M3 — the client emits its first ProtoSSL plaintext onto the real Blaze connection (the ClientHello to the redirector), captured by our hook.
It proves both halves at once: (1) we got the game past its connection-state check — it went online for real; and (2) our redirect + ProtoSSL hook capture real plaintext from that connection.
It deliberately stops short of the candidate's "first Blaze frame" (a Fire2 app-data message), which requires answering the TLS handshake (M4) and depends on the unconfirmed Fire2 / recv-injection work. ClientHello capture needs none of that — making it the smallest, safest proof. The first Fire2 frame is the immediate follow-on (M4).