fifa17-recon: match rewards, POW online layer, account backend, quick sell

Second session. FUT core loop, the EASFC/POW online layer, a central account
backend, and a lot of corrections. Everything risky is behind an env flag with
the default set to whatever was live-proven.

WORKING END TO END (live-verified this session):
  * match loop -- POST/PUT/POST/DELETE ut/%s/match, rewards via FutDestroyMatch
    (0x180121b60). Play a match, get coins, W/D/L updates.
  * packs -- buy, cards land in the club, session survives (FUT_PACK_AUTOCLUB=1)
  * quick sell -- POST ut/delete/%s/item was UNMAPPED and paid NOTHING; six cards
    were destroyed for 0 coins. Now credits discardValue.
  * POW/EASFC online -- the "EA FC servers unreachable" banner is powdll's layer,
    a THIRD http api on :8094 nobody had served. Redirect needs no root: powdll
    FUN_18005a460 reads FIFA_POW_URL from the same client-config store as
    ROSTERUPDATE_URL. FUT_POW=1.
  * account backend -- fut_account.py replaces 7 hardcoded copies of the persona
    across 5 files; club/persona/online-profile editable via CLI.

CORRECTIONS TO ENDPOINT_MAP (all re-extracted from the deserializers):
  * FutStoreGetPackTypes: id/packType/isPremium/quantity/saleType/purchaseLimit/
    purchaseCount are NOT skipped no-ops -- all are parsed. extPrice inner objects
    take externalPriceId(0x11a), not amount/currency.
  * FutMoveCard 0x180128600 has NO skip handler (FUN_180135ff0 appears zero times,
    unique among FUT deserializers) and parses only itemData -> dreamSquads.
  * class -> deserializer resolution: the name literal is preceded by a 4-BYTE
    HEADER and the factory LEA points at the header, so look up name_addr - 4.
    Six attempts failed on this; now ghidra_env.class_deser(). Unlocked 11 SBC/
    Draft schemas.
  * live-only endpoints the request table never lists: ut/%s/squad/list,
    ut/%s/user/club, ut/%s/club/stats/*, ut/%s/clientdata/<key>. The template
    table is a floor, not a ceiling -- the log is the only ground truth.
  * 163 RS4 call names exist; we served 17. All now served.

FIXED: club/stats/* was answering with the entire 28-item club inventory on every
poll (it fell through to the generic /club route).

UNSOLVED: the pack reveal's "Send to Club" (PUT ut/%s/item) kills the FUT session
whatever we answer -- {} included -- while its sibling quick-sell endpoint accepts
a bare {}. Seven hypotheses eliminated by live test, documented in
REBUILD_RESEARCH.md S14c so none get re-walked. FUT_PACK_AUTOCLUB routes around it.
Also unfixed: store tiles render "unknown" (displayGroup is parsed RECURSIVELY by
the same element parser; sending it FROZE the store, so FUT_STORE_GROUPS=1 is
default off).

Tests: test_fut_contract.py 380 (live, read-only) + test_match_rewards.py 51 (pure).

Note: fut_store.py carries some pre-existing uncommitted changes from before this
session (pack catalogue ids, pending-pile behaviour) that could not be separated
from this session's additions in the same file.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VUT92pz6RWKih9dSr8ZpxW
This commit is contained in:
funman300
2026-08-04 09:42:59 -07:00
parent 59934b4ef0
commit 5d5198f5d1
20 changed files with 3217 additions and 144 deletions
+15 -6
View File
@@ -25,9 +25,13 @@
# resourceId decompose 0x180166ca0 CONFIRMED: assetId = resourceId & 0xffffff,
# high byte = version. Version byte value is the open question s2v0/s2v1 answer.
# ---------------------------------------------------------------------------
import os
import os, sys
PERSONA_ID = 33068179
sys.path.insert(0, os.path.dirname(os.path.abspath(__file__)))
from fut_account import ACCOUNT # single source of truth for identity
# Back-compat snapshot; prefer ACCOUNT.persona_id in new code.
PERSONA_ID = ACCOUNT.persona_id
ITEM_ID_BASE = 100000000
# Real FIFA17 assetIds read earlier from the live InGameDB. assetId 41 (Iniesta)
@@ -59,7 +63,12 @@ def player_item(asset, rating, pos, version=0x00, nation=38, team=243, league=53
"resourceId": rid,
"assetId": asset,
"cardassetid": asset,
"definitionId": rid, # some FUT APIs key on definitionId
# definitionId is INERT in FIFA 17: it is not in the atom table at all, so
# the client's key hash never matches and it routes straight to the value-SKIP
# handler 0x180135ff0 -- same class as the itemDbVersion/checkServerDbVersion
# keys proven phantom in blaze_responder. Kept (harmless, and other FIFA
# versions do use it) but it is NOT read here; the live key is resourceId.
"definitionId": rid,
"cardsubtypeid": 0, # 0..3 => PLAYER
"itemType": "player",
"rareflag": 1,
@@ -88,8 +97,8 @@ def _base_squad():
MUST be unique 0..22) and manager empty -> zero item-deser calls by default."""
return {
"id": 0,
"personaId": PERSONA_ID, # must equal logged-in persona (0x18014659c)
"squadName": "OpenFUT",
"personaId": ACCOUNT.persona_id, # must equal logged-in persona (0x18014659c)
"squadName": ACCOUNT.squad_name,
"formation": "f442",
"squadType": "REGULAR_SQUAD",
"chemistry": 100,
@@ -182,7 +191,7 @@ def squad_summary(squad):
"chemistry": int(squad.get("chemistry", 0)),
"formation": squad.get("formation", "f442"),
"id": int(squad.get("id", 0)),
"squadName": squad.get("squadName", "OpenFUT"),
"squadName": squad.get("squadName", ACCOUNT.squad_name),
"squadType": squad.get("squadType", "REGULAR_SQUAD"),
}