In-process, read-only probes and transport observation built while closing
the online/FUT route from both the memory and network sides.
- probe.rs / dial_notification.rs: menu-time ctx dump, connMgr enumerator,
synthetic dial-notification + direct-call dial trigger, and the
[element+0x40] container write-watchpoint. All env-gated, one-shot,
VirtualQuery-guarded; none alter game state by default.
- transport_watch.rs + connect/connectex/hooks/lib: M0 transport observation
(grep-friendly TRANSPORT_WATCH logging on the existing getaddrinfo/connect/
WSAConnect/ConnectEx detours) and an IPv6 (v4-mapped) EA-redirect so the
game's IPv6 :443 dials land on the bridge instead of the dead servers.
Findings: the game never initiates a Blaze connection offline; the dial
handler is registered by a self-registering, message-driven state machine
whose container stays empty with no Blaze exchange. See openfut-bridge
docs/closure-and-preservation.md.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
install_force_connect() is no longer auto-called from install_probes_deferred,
so normal probe builds don't poke the online flow. Kept for reference; re-enable
the call to reproduce the 2026-07-02 forcing experiment.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Expands to 8 entry probes across the connect-state lifecycle (ctor, controller
accessor, four vtable steps) to distinguish entered-but-stalled from never-entered.
Result: ctor fires x4, everything else 0 — subsystem created but dormant.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Replaces the anadius-connectivity probes with the game-side Nucleus-connect
functions (nucleusConnectREST/Trusted, connect-state tick) and adds a
VirtualQuery-guarded sampler thread that reads X=[0x14acd02c0] -> M=[X+0x360]
-> ctx=[M+0x778] once/sec to observe the session context directly. Per-slot
log cap prevents per-frame handlers flooding the log. Run 3 result: ctx is
non-null but the connect functions are never called (see bridge findings).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The OnlineStatusEventT::HandleMessage dispatch resolves its game-side
listener only at runtime (call [rax+0x28]). openfut_listener_stub patches
FIFA23.exe+0x274d4d7 to replicate the four dispatch instructions while
logging the resolved vtable/fn, then resumes. Alignment-safe (saves/rounds
rsp before the log call). Result: listener = FIFA23.exe+0x2751060 = ret 0,
a no-op default vtable slot -> the online->auth transition is state-polled,
not callback-driven.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Hook-side tooling for the LSX/Blaze reverse-engineering effort:
- probe.rs (new, `probe` feature): passive logging detours on FIFA's online-flow
functions via the unhook/rehook pattern (no trampoline/relocation, works on
RIP-relative prologues). Deferred install waits for anadius64.dll to load, then
logs enter/return for GoOnline + GetInternetConnectedState (anadius) and the
OnlineStatusEvent/Login deserializers (FIFA23.exe). Revealed that our pushed LSX
events reach FIFA and parse OK, while GoOnline never fires — localizing the online
gate to FIFA's game-side event consumer.
- connect_hook.rs: redirect FIFA's LSX connect :3216 → :3217 so it lands on the
native openfut-bridge LSX server (slips past anadius's in-process :3216 intercept);
gated off under the `capture_baseline` feature.
- recv_hook.rs: boundary-safe trampolines + LSX peer filtering for the
capture_baseline path (log anadius's real LSX frames when the redirect is off).
Build the instrumented DLL with `--features probe` (or `--features capture_baseline`
for the anadius-baseline capture). Both features are off by default.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>