fifa17-recon: fix the match tail -- real URLs, endReason, and coins in the right place
The whole match family is one RPC descriptor block (rows 49-54, every row using URL
template index 16 = `ut/%s/match`) with a fixed suffix appended per call:
CREATEMATCH ut/game/fifa17/match PLAYGAME ut/game/fifa17/match
MATCHREADY ut/game/fifa17/match/ready DESTROYMATCH ut/game/fifa17/match/end
RESETMATCH ut/game/fifa17/match/reset KEEPALIVE ut/game/fifa17/match/keepalive
THERE IS NO /match/{id} URL. The id travels in the body. Our reward path was gated on
`h.command == "DELETE" or "/ut/delete/" in h.path` and extracted the id with
re.search(r"/match/(\d+)"), so it was waiting for a request the client does not make.
The gate is now widened to include a /match/end path with ANY verb, because the verb
genuinely cannot be determined statically: the strings "PUT" and "DELETE" do not exist
anywhere in cardsdll.dll (0 hits each), so verb selection happens outside this DLL. A
reviewer flagged "the reward path can never fire" as overreach on exactly that point;
widening rather than replacing the gate is the response.
THE RESULT SIGNAL IS `endReason` (atom 260), a STRING enum with nine values: WIN DRAW
LOSS DNF QUIT NO_CONTEST DNF_WIN DNF_DRAW DNF_LOSS. Not a score comparison. The score
lives in `myMatchStats.goals` / `opponentMatchStats.goals`, two literal-keyed objects
of 15 int fields each, and the client OMITS both when endReason is DNF or QUIT, so
nothing may require them. _match_result() now reads endReason first and keeps the old
spelling probe only as a fallback, because request-side static findings are a floor:
PUT /item's swap/tradeId appeared in no static listing either.
THREE CORRECTIONS TO THE RESPONSE, all of which were shipping wrong:
1. `coins` (atom 149) is NOT a top-level key. It is read only inside `gameModeAward`.
The one field most obviously named "the reward" was being silently skipped.
2. `qualifiedChampionEventId` (0x269) has a SIDE EFFECT: its branch calls through a
manager vtable after storing. Sending a habitual zero poked champion-event
machinery for no benefit. Removed.
3. `bidTokens` (atom 89) inside gameModeAward is MATCHED and then handled by nothing,
so its value token is left unconsumed. That is the precondition for the desync
spin. A freeze trap dressed as an ordinary field; now guarded by a unit check.
test_match_rewards.py rewrote its expectations. The old version asserted a top-level
`coins` and passed happily while the server shipped a body whose reward field the
client never read. A test that encodes the wrong schema converts a bug into a
guarantee. New test_end_reason_is_authoritative covers all nine enum values, the
stats-less DNF case, and that endReason beats a contradictory score probe.
DEFAULT ON (FUT_MATCH_END=0 reverts), a reasoned exception to the flag convention:
nothing here is live-proven because no match has ever been played, and the old
behaviour is not a working screen but a path that provably could not fire.
61 unit checks (58 with the flag off), 392 contract checks green.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VUT92pz6RWKih9dSr8ZpxW
This commit is contained in:
@@ -1126,17 +1126,54 @@ MATCH_COINS = {
|
||||
}
|
||||
MATCH_PARTICIPATION = int(os.environ.get("FUT_MATCH_PARTICIPATION", "0"))
|
||||
|
||||
# FUT_MATCH_END -- the 2026-08-04 correction of the whole match tail: route /match/end
|
||||
# as DestroyMatch regardless of verb, and move `coins` inside gameModeAward where the
|
||||
# deserializer actually reads it. DEFAULT ON, and like FUT_DRAFT_STATE this is a
|
||||
# reasoned exception to "default to the live-proven value": nothing here is
|
||||
# live-proven, because no match has ever been played. The old behaviour is not a
|
||||
# working screen being protected, it is a path that provably could not fire (it
|
||||
# required a verb and a /match/{id} URL the client does not use). Set to 0 to revert.
|
||||
MATCH_END = os.environ.get("FUT_MATCH_END", "1") == "1"
|
||||
|
||||
|
||||
# The DestroyMatch REQUEST, reversed 2026-08-04 from the serializer rather than
|
||||
# guessed from the response side. This replaces the spelling-probe below as the
|
||||
# PRIMARY path; the probe stays as a fallback because request-side static findings
|
||||
# are a floor, not a ceiling (PUT /item's swap/tradeId were in no static listing).
|
||||
#
|
||||
# endReason (atom 260) -- STRING enum, and it is the AUTHORITATIVE result signal.
|
||||
# Nine values: WIN DRAW LOSS DNF QUIT NO_CONTEST DNF_WIN DNF_DRAW DNF_LOSS.
|
||||
# A score comparison is NOT how the client reports the outcome.
|
||||
# myMatchStats / opponentMatchStats -- literal-keyed objects, 15 int fields each,
|
||||
# first of which is `goals`. OMITTED BY THE CLIENT when endReason is DNF or QUIT,
|
||||
# so nothing may require them.
|
||||
_END_REASON = {
|
||||
"WIN": "won", "DNF_WIN": "won",
|
||||
"DRAW": "draw", "DNF_DRAW": "draw", "NO_CONTEST": "draw",
|
||||
"LOSS": "loss", "DNF_LOSS": "loss", "DNF": "loss", "QUIT": "loss",
|
||||
}
|
||||
|
||||
|
||||
def _match_result(body):
|
||||
"""Work out win/draw/loss from whatever the client posted.
|
||||
|
||||
The PlayGame/DestroyMatch request shape is NOT reversed -- the response side is
|
||||
(that is what we serve), but nobody has captured the request yet. So probe the
|
||||
plausible spellings and fall back to a draw, which is the neutral outcome: it
|
||||
still credits coins and advances the record without inventing a win. Every body
|
||||
is logged, so the first live match tells us the real shape."""
|
||||
Primary: endReason, the string enum the serializer actually writes. Fallback:
|
||||
the old spelling probe, then a draw, which is the neutral outcome -- it credits
|
||||
coins and advances the record without inventing a win. Every body is logged, so
|
||||
the first live match still tells us if the static read was incomplete."""
|
||||
if not isinstance(body, dict):
|
||||
return "draw", None
|
||||
|
||||
reason = body.get("endReason")
|
||||
if isinstance(reason, str) and reason.upper() in _END_REASON:
|
||||
mine = body.get("myMatchStats") or {}
|
||||
theirs = body.get("opponentMatchStats") or {}
|
||||
score = None
|
||||
if isinstance(mine, dict) and isinstance(theirs, dict):
|
||||
a, b = mine.get("goals"), theirs.get("goals")
|
||||
if isinstance(a, int) and isinstance(b, int):
|
||||
score = (a, b)
|
||||
return _END_REASON[reason.upper()], score
|
||||
# a nested match/stats object is as likely as a flat one
|
||||
for key in ("match", "matchStats", "stats", "result", "gameResult"):
|
||||
inner = body.get(key)
|
||||
@@ -1168,19 +1205,42 @@ def destroy_match_body(result, coins, total):
|
||||
Split out of match_route so it can be unit-tested: the match loop mutates
|
||||
(credits coins, bumps W/D/L), so it cannot live in the read-only HTTP contract
|
||||
suite. See tools/test_match_rewards.py. Every field is a top-level scalar; the
|
||||
nested members gameModeAward(310)/matchCoinMultipliers(437)/userData(877) are
|
||||
SKIP-safe and deliberately omitted (userData is a documented freeze-risk)."""
|
||||
return {
|
||||
"coins": int(coins),
|
||||
nested members matchCoinMultipliers(437)/userData(877) are SKIP-safe and
|
||||
deliberately omitted (userData is a documented freeze-risk).
|
||||
|
||||
THREE CORRECTIONS from the 2026-08-04 pass over deser 0x180121b60, all of which
|
||||
were shipping wrong before:
|
||||
|
||||
1. `coins` (atom 149) is NOT a top-level key of this response. It is read ONLY
|
||||
inside the `gameModeAward` object. The top-level "coins" we were sending was
|
||||
silently skipped and never reached the client, which means the one field most
|
||||
obviously named "the reward" was the one field going nowhere.
|
||||
2. `qualifiedChampionEventId` (atom 0x269) HAS A SIDE EFFECT. Its branch does not
|
||||
just store the int, it calls through a manager vtable afterwards. Sending it
|
||||
as a habitual zero pokes champion-event machinery for no benefit. Removed.
|
||||
3. NEVER emit `bidTokens` (atom 89) inside gameModeAward. That atom is explicitly
|
||||
matched there and then handled by NOTHING: not read, not routed to the skip
|
||||
handler. Its value token is left unconsumed in the stream, which is the exact
|
||||
precondition for the type-desync spin. It is a freeze trap wearing the costume
|
||||
of an ordinary field.
|
||||
|
||||
FUT_MATCH_END=0 restores the previous body if the new one misbehaves live."""
|
||||
body = {
|
||||
"allCoins": int(total),
|
||||
"matchCoins": int(MATCH_COINS.get(result, 0)),
|
||||
"seasonCoins": 0,
|
||||
"tournamentCoins": 0,
|
||||
"boostConis": 0, # EA's spelling, atom 96
|
||||
"participationAward": int(MATCH_PARTICIPATION),
|
||||
"qualifiedChampionEventId": 0,
|
||||
"teamOfTournamentWinner": False,
|
||||
}
|
||||
if MATCH_END:
|
||||
# `coins` lives here and nowhere else. No bidTokens, ever.
|
||||
body["gameModeAward"] = {"coins": int(coins)}
|
||||
else:
|
||||
body["coins"] = int(coins)
|
||||
body["qualifiedChampionEventId"] = 0
|
||||
return body
|
||||
|
||||
|
||||
def match_route(h):
|
||||
@@ -1191,7 +1251,24 @@ def match_route(h):
|
||||
body = {}
|
||||
m = re.search(r"/match/(\d+)", h.path)
|
||||
match_id = int(m.group(1)) if m else None
|
||||
is_delete = h.command == "DELETE" or "/ut/delete/" in h.path
|
||||
# THE REAL URLS, from the RPC descriptor block (rows 49-54, all using template
|
||||
# index 16 = `ut/%s/match`, each appending a fixed suffix via the params object
|
||||
# at slot +0x08): CREATEMATCH and PLAYGAME append nothing, MATCHREADY `/ready`,
|
||||
# DESTROYMATCH `/end`, RESETMATCH `/reset`, KEEPALIVE `/keepalive`.
|
||||
#
|
||||
# THERE IS NO /match/{id} URL ANYWHERE. The id travels in the body. So the old
|
||||
# `re.search(r"/match/(\d+)")` could never match a real request, and the reward
|
||||
# path was gated on DELETE-or-/ut/delete/ which the client also never sends --
|
||||
# it would have fired on nothing. match_id is retained only for hand probes.
|
||||
#
|
||||
# The HTTP VERB for each call cannot be determined statically: the strings "PUT"
|
||||
# and "DELETE" do not exist anywhere in cardsdll.dll (0 hits each), so verb
|
||||
# selection happens in the HTTP layer outside this DLL. Hence: match on the PATH
|
||||
# and accept any verb. A reviewer specifically flagged the claim "the reward path
|
||||
# can never fire" as overreach on exactly this point, since the verb is unknown
|
||||
# rather than known-wrong, so this widens the gate instead of replacing it.
|
||||
is_delete = (h.command == "DELETE" or "/ut/delete/" in h.path
|
||||
or (MATCH_END and h.path.split("?")[0].endswith("/match/end")))
|
||||
|
||||
if is_delete:
|
||||
# FutDestroyMatch -- the ONLY place a match awards anything.
|
||||
|
||||
Reference in New Issue
Block a user