Compare commits
82 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| bf6db98f0d | |||
| fc55de19fa | |||
| 6ae3364bd0 | |||
| 5c40b4993f | |||
| fbc0da2a1b | |||
| 750d6c2e18 | |||
| 082246c085 | |||
| 16771b0b33 | |||
| 022634704a | |||
| 96ca7c0484 | |||
| 202366611e | |||
| ea92057e53 | |||
| c71593b286 | |||
| 413ad901fb | |||
| e0e46d8a57 | |||
| fbe29da05b | |||
| 9ffbd651b1 | |||
| aa5fb2cc40 | |||
| 468bc0fba9 | |||
| 571c5f9261 | |||
| cb32fe9b84 | |||
| fbe9804d3e | |||
| f6606accb3 | |||
| 0a007f4941 | |||
| 0c4aee6164 | |||
| a57f4930f0 | |||
| f9ca901a50 | |||
| 3ce69f8951 | |||
| acd1def00d | |||
| 5ec9c7f8bf | |||
| 11c028e6eb | |||
| afadb13de4 | |||
| b6398c44e6 | |||
| a2bd048ace | |||
| 2e97ff1461 | |||
| 7f37b37be3 | |||
| 4e31fb98a2 | |||
| 6cc22e5cc5 | |||
| b1d7ed2570 | |||
| dcbef721f2 | |||
| 772f8a615a | |||
| bf9ae20367 | |||
| 58d1f9426f | |||
| 3cd31c4322 | |||
| ae5feb05b7 | |||
| f2c4927ea6 | |||
| aa2abc2772 | |||
| 1aa84afa9a | |||
| 33e9118329 | |||
| e06fd57211 | |||
| 42fd3c7e90 | |||
| 0bc71dbd74 | |||
| 2ecd830d75 | |||
| 3a51b0ebd4 | |||
| ad406f21bd | |||
| 12fb9fc38b | |||
| 7b580a0070 | |||
| 22443a3810 | |||
| 0fce1e521c | |||
| 71fcf5e251 | |||
| 979e71fbea | |||
| 45e0b0bd95 | |||
| 70eb3fc13f | |||
| b30aa352f6 | |||
| 67cc33cfee | |||
| 6eec3b9ec7 | |||
| 57773b98ec | |||
| fe9b899a0e | |||
| abe9e663c1 | |||
| f5a33eb58c | |||
| a85090c3c6 | |||
| 97d48d8371 | |||
| 5020137050 | |||
| cf05ab2a9e | |||
| a6416a3f1d | |||
| 47ced228de | |||
| b8beeba98d | |||
| df6994c957 | |||
| d74e86c065 | |||
| 76512f6048 | |||
| 93a46d4de7 | |||
| 3ba24a0faf |
Generated
+46
-7
@@ -114,6 +114,17 @@ version = "2.0.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "320119579fcad9c21884f5c4861d16174d0e06250625266f50fe6898340abefa"
|
||||
|
||||
[[package]]
|
||||
name = "aes"
|
||||
version = "0.8.4"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "b169f7a6d4742236a0a00c541b845991d0ac43e546831af1249753ab4c3aa3a0"
|
||||
dependencies = [
|
||||
"cfg-if",
|
||||
"cipher",
|
||||
"cpufeatures",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "ahash"
|
||||
version = "0.8.12"
|
||||
@@ -810,6 +821,16 @@ dependencies = [
|
||||
"windows-link",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "cipher"
|
||||
version = "0.4.4"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "773f3b9af64447d2ce9850330c473515014aa235e6a783b02db81ff39e4a3dad"
|
||||
dependencies = [
|
||||
"crypto-common",
|
||||
"inout",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "clipboard-win"
|
||||
version = "5.4.1"
|
||||
@@ -2307,6 +2328,15 @@ dependencies = [
|
||||
"hashbrown 0.17.1",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "inout"
|
||||
version = "0.1.4"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "879f10e63c20629ecabbb64a8010319738c66a5cd0c29b02d63d272b03751d01"
|
||||
dependencies = [
|
||||
"generic-array",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "ipnet"
|
||||
version = "2.12.1"
|
||||
@@ -3118,6 +3148,10 @@ dependencies = [
|
||||
"serde_json",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-autopatch"
|
||||
version = "0.1.0"
|
||||
|
||||
[[package]]
|
||||
name = "openfut-blaze-host"
|
||||
version = "0.1.0"
|
||||
@@ -3185,13 +3219,6 @@ dependencies = [
|
||||
"uuid",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-hook"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"windows-sys 0.59.0",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-host-config"
|
||||
version = "0.1.0"
|
||||
@@ -3219,10 +3246,13 @@ version = "0.1.0"
|
||||
dependencies = [
|
||||
"anyhow",
|
||||
"openfut-adapter-fifa17",
|
||||
"openfut-core",
|
||||
"openfut-identity",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"sqlx",
|
||||
"tempfile",
|
||||
"tokio",
|
||||
"uuid",
|
||||
]
|
||||
|
||||
@@ -3236,11 +3266,20 @@ dependencies = [
|
||||
"eframe",
|
||||
"egui",
|
||||
"openfut-common",
|
||||
"parking_lot",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"tokio",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-lsx"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"aes",
|
||||
"parking_lot",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-protocol-blaze"
|
||||
version = "0.1.0"
|
||||
|
||||
+11
-1
@@ -15,7 +15,17 @@ members = [
|
||||
"openfut-import-fifa17",
|
||||
"openfut-bridge",
|
||||
"openfut-launcher",
|
||||
"openfut-launcher/openfut-hook",
|
||||
# The two companion services the launcher used to shell out to Python for.
|
||||
"openfut-lsx",
|
||||
"openfut-autopatch",
|
||||
"fifa-blaze/crates/blaze-proto",
|
||||
"fifa-blaze/crates/server",
|
||||
]
|
||||
# openfut-hook is a Windows-only version.dll proxy injected into the FIFA client.
|
||||
# It MUST build with its own [profile.release] (panic="abort" — unwinding across
|
||||
# the DllMain/FFI boundary into the game process is UB — plus strip + opt-level="s").
|
||||
# Cargo ignores a non-root member's profile and forbids per-package `panic` overrides,
|
||||
# so the hook is deliberately EXCLUDED from this workspace to build as its own root
|
||||
# (this also lands its artifact in openfut-hook/target/, matching the launcher's
|
||||
# config.rs default hook_dll_path). Build: cargo build --release --target x86_64-pc-windows-gnu.
|
||||
exclude = ["openfut-launcher/openfut-hook"]
|
||||
|
||||
@@ -1,142 +0,0 @@
|
||||
# FIFA 17 FUT — Card Taxonomy (single source of truth)
|
||||
|
||||
Status: verified 2026-08-12. This document supersedes every earlier scattered
|
||||
taxonomy claim in the repo (see "Superseded taxonomy" at the bottom).
|
||||
|
||||
Evidence labels: **OBSERVED** = read directly from a shipped table or decompiled
|
||||
function; **INFERRED** = derived from OBSERVED facts; **HYPOTHESIS** = plausible,
|
||||
not yet proven. `UNKNOWN` is a valid answer and is stated as such.
|
||||
|
||||
## Provenance
|
||||
|
||||
- Authoritative tables: `10.10.0.105:/home/alex/Documents/OpenFUT/fifa17-recon/data/tables/`,
|
||||
copied byte-identical into this repo at `fifa17-recon/data/tables/`.
|
||||
SHA-256 manifest + verification: `docs/evidence/fifa17-recon/table-hashes.sha256`
|
||||
(36 files: 31 `fcc_*.json` + 5 staff tables; combined hash-of-hashes
|
||||
`10f239add919089354d8dbff873fc9737b0a0f80f6ac41b1aa2a096c0ec8d331`).
|
||||
- Each table file is a DECODED dump `{table, source, rowcount, schema[], rows[]}`;
|
||||
card instances are in `rows[]`, one object per card. Row counts and id ranges
|
||||
below were re-extracted from the in-repo `.120` copies.
|
||||
- Semantic (subtype→kind) labels are decompiler-derived, carried in
|
||||
`fifa17-recon/tools/fut_consumables.py` (`BY_SUBTYPE`, `_DOC`), generated by
|
||||
`tools/build_consumables.py` from `FUN_1800d8330`, `FUN_18013f4d0`,
|
||||
`FUN_1801bfac0`, `FUN_1801aa230`, `FUN_180048780` + the fcc tables.
|
||||
- Staff family selection: `fifa17-recon/docs/CARD_SYSTEM.md` (2026-08-04/05 blocks)
|
||||
and `fifa17-recon/tools/fut_staff.py` / `fut_coaches.py`.
|
||||
|
||||
## Family selector (OBSERVED, binary)
|
||||
|
||||
Before registering an item, `FUN_180141660` merges the client's local DB. It
|
||||
switches on record `+0x4c` (`cardtype`), which `FUN_1800d8330` derives from JSON
|
||||
atom `0x6c cardsubtypeid` alone:
|
||||
|
||||
```
|
||||
cardsubtypeid 0..3 -> cardtype 1 players
|
||||
4 -> cardtype 2 managercards
|
||||
5 -> cardtype 3 headcoachcards
|
||||
6 -> cardtype 10 gkcoachcards
|
||||
7 -> cardtype 5 physiocards
|
||||
8 -> cardtype 4 fitnesscoachcards
|
||||
0x1e,0x1f,0x91..0x96,0xe7..0xe9,0xec -> cardtype 9 club items + misc
|
||||
absent (default 342) -> cardtype 0 no merge
|
||||
```
|
||||
|
||||
Key: `carddbid == resourceId` for non-player families (queried RAW, no mask);
|
||||
players are queried by `playerid = resourceId & 0xffffff` (atom `0x287`), and
|
||||
`assetId` (atom `0x23`) is never read by the merge.
|
||||
|
||||
## Consumable & staff families — evidence table (OBSERVED, `.120` tables)
|
||||
|
||||
| Family | Table | Rows | carddbid range | cardsubtype set | cardassetid (ART) |
|
||||
|---|---|---|---|---|---|
|
||||
| Contracts | `fcc_contractcards.json` | 13 | 5001001–5001013 | {201, 202} | {7, 8} |
|
||||
| Fitness + Healing | `fcc_healingcards.json` | 27 | 5002001–5002030 | {211,212,213,215,216,217,218,219,220} | {9, 10} |
|
||||
| Training (6 sub-families) | `fcc_trainingcards.json` | 143 | 5003001–5003159 | 51-57, 61-67, 91-110, 121-136, 250-273, 300-340 | {1,3,32,34,35,50,51} |
|
||||
| Misc | `fcc_misccards.json` | 42 | 5004001–5004042 | {231, 232, 233, 236} | {43, 44, 45, 46} |
|
||||
| Badges | `fcc_badgecards.json` | 656 | 6000000–6000656 | (none in row) | {39} |
|
||||
| Stadiums | `fcc_stadium.json` | 78 | 6200000–6200077 | (none in row) | {36} |
|
||||
| Kits | `fcc_kitcards.json` | 1482 | 6300000–6400654 | (none in row) | {35} |
|
||||
| League logos | `fcc_leaguelogos.json` | 44 | 8010000–8010044 | (none in row) | {40} |
|
||||
| League logo stickers | `fcc_leaguelogostickers.json` | 39 | 8010000–8010039 | (none in row) | {40} |
|
||||
| Balls | `fcc_balls.json` | 42 | 8120194–8120236 | (none in row) | {37} |
|
||||
| Managers | `managercards.json` | 417 | 1000001–1001552 | (staff; by cardsubtypeid 4) | (assetid col) |
|
||||
| Head coaches | `headcoachcards.json` | 124 | 2000004–2000328 | (staff; subtype 5) | — |
|
||||
| GK coaches | `gkcoachcards.json` | 121 | 9000001–9000324 | (staff; subtype 6) | — |
|
||||
| Physios | `physiocards.json` | 51 | 4000002–4000259 | (staff; subtype 7) | — |
|
||||
| Fitness coaches | `fitnesscoachcards.json` | 115 | 3000019–3000328 | (staff; subtype 8) | — |
|
||||
|
||||
Notes:
|
||||
- **Contracts (5001xxx)** — 201 = player_contract, 202 = manager_contract
|
||||
(OBSERVED, `BY_SUBTYPE`).
|
||||
- **Fitness + Healing (5002xxx)** — subtype **214 is a valid enum value but ships
|
||||
ZERO rows** (OBSERVED: 214 absent from `rows[]`). Enum split (OBSERVED,
|
||||
`BY_SUBTYPE`): healing = 211-218, player_fitness = 219, squad_fitness = 220.
|
||||
The `+0x58 rareflag == 1` trap flips subtype 219 to squad-fitness.
|
||||
- **Training (5003xxx)** — SIX sub-families, all OBSERVED in `rows[]` and labelled
|
||||
in `BY_SUBTYPE`:
|
||||
- `gk_training` 51-57 (7)
|
||||
- `player_training` 61-67 (7)
|
||||
- `position_mod` 91-110 (20)
|
||||
- `formation_mod` 121-136 (16)
|
||||
- chem/play styles 250-273 (24): `player_playstyle` 250-268 (19) +
|
||||
`gk_playstyle` 269-273 (5)
|
||||
- `manager_league` 300-**341** in the client enum (42), but the shipped table
|
||||
contains only 300-340 (41 rows) — 341 is defined, not shipped.
|
||||
- Client enum also defines vestigial/unshipped ranges NOT in the table:
|
||||
`manager_formation_mod` 71-86, and `DEAD_ZONE`
|
||||
58-60,68-70,87-90,111-120,203-210 (28). These have no rows.
|
||||
- **Misc (5004xxx)** — subtypes {231,232,233,236}; cardassetid ART 43-46.
|
||||
cardsubtype 231 = 0xe7 anchors the 0xe7..0xe9 block to misc via `FUN_1800d8330`.
|
||||
- **Club items (badges/stadiums/kits/logos/balls)** carry no `cardsubtype` in the
|
||||
row; they are keyed by `carddbid` range and distinguished on the wire by ART
|
||||
`cardassetid` (badges 39, stadium 36, kits 35, logos 40, balls 37). **Kits live
|
||||
at 6300000–6400654 and are NOT badges** (badges are 6000xxx). The client-side
|
||||
subtype→family map (which of 0x1e,0x1f,0x91..0x96 is ball vs stadium vs badge vs
|
||||
kit) is **UNKNOWN** — it is in none of the dumped tables and cardtype 9 has no
|
||||
miss-fill arm (see `CARD_SYSTEM.md`, "Club items", 2026-08-05).
|
||||
|
||||
## Staff — subtype/cardtype selectors (OBSERVED, binary)
|
||||
|
||||
| cardsubtypeid | cardtype | Family | Table | Rows | carddbid range |
|
||||
|---|---|---|---|---|---|
|
||||
| 4 | 2 | Manager | `managercards.json` | 417 | 1000001–1001552 |
|
||||
| 5 | 3 | Head coach | `headcoachcards.json` | 124 | 2000004–2000328 |
|
||||
| 6 | 10 | GK coach | `gkcoachcards.json` | 121 | 9000001–9000324 |
|
||||
| 7 | 5 | Physio | `physiocards.json` | 51 | 4000002–4000259 |
|
||||
| 8 | 4 | Fitness coach | `fitnesscoachcards.json` | 115 | 3000019–3000328 |
|
||||
|
||||
`cardsubtypeid -> rec+0x50` is the only family selector; `FUN_1800d8330` maps it to
|
||||
`rec+0x4c cardtype`. Manager merge = `FUN_1801356c0` (queries `managercards` by
|
||||
`carddbid` raw); coach merges live in the respective tables (`fut_coaches.py`).
|
||||
All five render live with real photos/bonuses, zero "DB Error" (CARD_SYSTEM.md,
|
||||
2026-08-05).
|
||||
|
||||
## Players (context, out of taxonomy scope here)
|
||||
|
||||
Players use cardsubtypeid 0..3 -> cardtype 1; merged by `playerid = resourceId &
|
||||
0xffffff` against the local `players` table. Identity/name/nation/team come from
|
||||
the client DB; rating/position/attributes come from our item JSON. See
|
||||
`CARD_SYSTEM.md` and the migration work in `openfut-adapter-fifa17`.
|
||||
|
||||
## Superseded taxonomy (report only — no other files edited)
|
||||
|
||||
The earlier working taxonomy (in prior agent-session notes / long-term memory, and
|
||||
partially in the original `TablesTaxonomy` scout output) got four things wrong.
|
||||
Corrected here:
|
||||
|
||||
1. **Chemistry / play styles are 250-273, NOT 91-136.** 91-110 = `position_mod`,
|
||||
121-136 = `formation_mod`. (OBSERVED in `fcc_trainingcards` + `BY_SUBTYPE`.)
|
||||
2. **6300xxx/6400xxx are KITS, not badges.** Badges are 6000xxx. (OBSERVED.)
|
||||
3. **5004xxx misc cards exist** (subtypes 231/232/233/236, ART 43-46). Previously
|
||||
omitted. (OBSERVED, `fcc_misccards`.)
|
||||
4. **8010xxx league logos exist** (+ stickers), ART 40. Previously omitted.
|
||||
(OBSERVED, `fcc_leaguelogos`.)
|
||||
|
||||
**Repo blast-radius of the superseded values: NONE.** A repo-wide grep
|
||||
(`docs/`, `openfut-adapter-fifa17/`, `openfut-core/`, `fifa17-recon/`) for the wrong
|
||||
claims (`91-136` chem styles; `6300/6400xxx` as badges) returns zero hits.
|
||||
`fifa17-recon/docs/CARD_SYSTEM.md` and `plan-2026-08-06-card-subsystem.md` already
|
||||
use the correct `250..273` for chem styles and the correct staff subtypes 4-8;
|
||||
`CARD_SYSTEM.md` is a mechanism log, not a taxonomy, and asserts none of the wrong
|
||||
ranges. The superseded values therefore live only in non-repo agent memory, which
|
||||
should be corrected to point at this document.
|
||||
@@ -1,192 +0,0 @@
|
||||
# OpenFUT — Project State
|
||||
|
||||
> **Canonical source:** `../OpenFUT-Vault/06 Agent Memory/Project State.md`
|
||||
> This file is a mirror. If the two disagree, the vault wins. Update the vault first.
|
||||
|
||||
Factual snapshot. Prefer this over the stale root `README.md`/`CLAUDE.md` status tables (FIFA 23).
|
||||
Last compiled from repository evidence during context initialization.
|
||||
|
||||
## Working
|
||||
|
||||
- **FIFA 17 offline FUT stack, end-to-end.** Proven 2026-08-01: auth → Blaze login → device-trust →
|
||||
the FUT hub. Brought up by `fifa17-recon/tools/openfut-fut.sh start`. Evidence: `FUT-RUNBOOK.md`,
|
||||
`fifa17-recon/README.md`, the five responder scripts, gate-ladder troubleshooting table.
|
||||
- **ProtoSSL cert-pin defeat** — two live `/proc/PID/mem` patches (`autopatch.py`), VAs stable
|
||||
across launches. gdb-verified which gate was the wall.
|
||||
- **LSX / Origin layer** — crypto handshake reversed byte-exact and confirmed against the repack's
|
||||
own emu disassembly (`docs/REPACK_INTEL.md`); Origin login gates cleared.
|
||||
- **Blaze redirector + Fire2/Heat2** — both hops defeated; preAuth/login/personas answered.
|
||||
- **UTAS/RS4 FUT API** — `ut/auth` + boot calls + device-trust reach the hub with hand-authored JSON.
|
||||
- **Persistent FIFA 17 account selection** — the launcher synchronizes one configured EA persona to
|
||||
the Python backend before starting LSX/FIFA. LSX, Blaze, POW/EASFC, and UTAS then share that
|
||||
identity, while FUT coins, inventory, squads, progression, and unopened packs persist in an
|
||||
isolated save beneath `fifa17-recon/docker/state/accounts/<persona-id>/`. The POW level/XP/funds
|
||||
shown in FIFA's general account bar are account-scoped but remain distinct from FUT club coins.
|
||||
A reversible server test on 2026-08-09 verified profile switching, POW values, a 400-coin pack
|
||||
debit, five awarded items, and restoration of the original profile.
|
||||
- **Account-scoped FUT security compatibility** — launcher account synchronization initializes a
|
||||
persisted `securityQuestion` verification record in that persona's FIFA 17 profile. The UTAS
|
||||
PHISHING handler returns the complete CardsDLL trusted-console response (`changed`, `exists`,
|
||||
`locked`, `trusted`), accepts only well-formed legacy setup/validate requests under `X-UT-SID`,
|
||||
and never stores or logs the client-transformed answer. This is server-side emulation; the hook
|
||||
and launcher do not contain an answer or add UI automation. Automated contract coverage is in
|
||||
`fifa17-recon/docker/ctx/tools/test_security_question.py`; live first/repeat-launch acceptance is
|
||||
partially complete: the first launch entered FUT without a security dialog on 2026-08-09; a
|
||||
second fresh-process FUT entry is still required to close persistence acceptance.
|
||||
- **Safe responder diagnostics** — ordinary LSX logs redact challenge/session/auth-code attributes;
|
||||
ordinary Blaze logs redact auth/session keys and no longer emit raw Fire2 hex, decoded TDF, or
|
||||
config values. Forensic Blaze capture remains available only with the explicit
|
||||
`OPENFUT_BLAZE_DUMP_FRAMES=1` opt-in. LSX and Blaze self-tests cover the new defaults.
|
||||
- **OpenFUT Core** — Rust FUT economy backend, feature-complete for its scope and tested: profiles,
|
||||
clubs, coins, packs, cards, squads, chemistry styles, SBCs, objectives, matches, market (NPC),
|
||||
draft, FUT Champs, seasons, statistics, achievements, events, daily check-in, division
|
||||
leaderboard, market trade history. 13 migrations. Integration suite (`tests/integration_test.rs`,
|
||||
96 test fns) runs against in-memory SQLite; CI (fmt/clippy/build/test) green on `openfut-core`.
|
||||
|
||||
## Partially implemented
|
||||
|
||||
- **FIFA 17 FUT hub depth** — reaching the hub is proven, but how much of FUT is fully navigable
|
||||
beyond it (playing matches, pack opening, SBC submission through the *game* UI vs. spinner/error
|
||||
states) is not documented as complete. The runbook's gate ladder lists failure modes still
|
||||
guarded against. Treat "past the hub" as unverified.
|
||||
- **Pack opening through the game UI** — proven live on 2026-08-09 with the recovered CAGE test
|
||||
profile: purchase, reveal, item assignment/quick-sell, wallet refresh, and return from the reveal
|
||||
all completed. The Python transaction path also passes its 446-check contract suite. FIFA's
|
||||
hardcoded post-reveal `mypacks` return is supported by a short-lived active grace record for every
|
||||
opened pack; it is excluded from unopened-pack counts and retired at the next hub request.
|
||||
- **FIFA 17 FUT match lifecycle** — CardsDLL static analysis and isolated responder tests now cover
|
||||
CREATE→READY→PLAY→END. Bare `/match` requests carrying body `matchId` are classified as PLAY
|
||||
instead of accidentally allocating another match; READY returns the verified scalar `matchId`
|
||||
and `opponentPersonaId` fields; END persists W/D/L, matches played, and coin rewards per account.
|
||||
The implementation is deployed and `test_match_lifecycle.py` passes, but no football match has
|
||||
started or completed in FIFA yet. The READY opponent `items` contract and client mode-entry gate
|
||||
remain unresolved; `FUT_MODES` therefore stays off by default.
|
||||
- **Core ↔ emulation integration** — the two halves exist and wiring has **started**. First
|
||||
slice (2026-08-11): the My Squad owned-player search. `openfut-core` gained a semantic,
|
||||
game-independent owned-inventory query (`services::inventory::{OwnedItemQuery, apply_query}`
|
||||
+ a `Quality` tier) that filters (AND) → orders deterministically → paginates, wired into
|
||||
`GET /collection`; `openfut-adapter-fifa17::fut::owned_query` parses the FIFA17 `/club` wire
|
||||
query and resolves numeric league/nation/team ids → semantic names (unknown id = hard error,
|
||||
no raw-id passthrough). Intentional fix, not parity: Python applies only `league`+`team` and
|
||||
ignores `level`/`rare`/`position`/`nation`/`start`/`count` (the request-amplification bug);
|
||||
Core applies all proven filters and paginates. `rare=SP` semantics UNKNOWN, unimplemented.
|
||||
Slice 2 (2026-08-11): `openfut-utas-host` — the first live UTAS host. Serves `GET …/club`
|
||||
from Core through the adapter and reverse-proxies every other UTAS route verbatim to the
|
||||
Python oracle (`utas_server.py`); plaintext HTTP/1.1 keep-alive, classify-before-execute,
|
||||
no python-fallback after a Core error. `CoreAccess` is a host-owned boundary (the adapter
|
||||
stays transport-agnostic). 11 host + 22 adapter tests; 10/10 mutations killed; fmt/clippy
|
||||
clean. Slice 3 (2026-08-11, `3ef3bc3`): the real `Fifa17IdentityResolver` — catalog
|
||||
(card id → real asset id) + persistent `openfut-identity` store (owned instance →
|
||||
stable/reversible wire int) + wire-id policy, replacing all placeholders (one
|
||||
production path). Wire-id namespace is globally monotonic within `(fifa17, owned-item)`,
|
||||
not per-account (Core owned ids are UUIDs → unambiguous reverse). Slice 4 (2026-08-11,
|
||||
core `36abd4b`): a curated 32-card real FIFA17 dev content pack
|
||||
(`data/games/fifa17/dev/cards.json`, ids `fifa17_<asset>`), loaded only via opt-in
|
||||
`Config.dev_content_games`; `seed-dev` grants a `game_id=fifa17` profile+club real
|
||||
`OwnedCard`s (no FIFA wire ids — the resolver mints those at request time), idempotent,
|
||||
default content untouched. Slice 5 (2026-08-11, `5276dd2`): the host sends
|
||||
`X-OpenFUT-Game: fifa17` so `/club` resolves the all-mapped fifa17 profile —
|
||||
**composition proven live** over HTTP (real Core+host, no FIFA client): FIFA wire query
|
||||
→ real `resourceId`s (catalog) + stable/reversible wire `id`s (store); 33 renderable,
|
||||
gold=22, Premier League=18, pagination page1=11/page2=7/overlap=0 (clean paging, no
|
||||
drops). **The only remaining gate is the live retail FIFA A/B** (no FIFA client in the
|
||||
build env; runbook `openfut-utas-host/README.md`). See the vault UTAS Endpoint Map +
|
||||
Known Issues (incl. "identity resolution is NOT authorization" for later mutations).
|
||||
**Slice 6 (2026-08-11): `/club` RUNTIME VALIDATED on retail FIFA 17** — operator-assisted
|
||||
live A/B (`.105` client → `.120` backend via a source-scoped NAT redirect into a staged
|
||||
`36abd4b` Core + `openfut-utas-host`). Every checkpoint passed on the real client:
|
||||
transport, per-route Python fallback, Python-negative `/club`, Core `X-OpenFUT-Game`
|
||||
scoping, real card + persistent owned-item identity (incl. the two-copy fixture),
|
||||
no-filter/Gold/position/nation/league/team/combined-AND filtering, retail pagination
|
||||
with no amplification, card selection, identity stability across relaunch, Python
|
||||
rollback, and Rust re-enable (identity store byte-identical across the cycle, 0
|
||||
reallocation). Live findings: the retail client steps `start += 10` with `count=11`
|
||||
(sometimes bulk `count=100`) — Core honours `offset` and terminates; the My Club UI
|
||||
nests team under league; the "~1900" club counter is Python `userMassInfo`, not `/club`.
|
||||
Remaining is operational only (promote the staged stack to a durable deployment).
|
||||
- **Slice 7 (2026-08-12): FUT squad authority (read + write) RUNTIME VALIDATED on retail FIFA 17.**
|
||||
Staged operator-assisted A/B (`.105` retail client → `.120`, source-scoped utas switch
|
||||
`:8099→:8199` into `openfut-utas-host` over a staged `615c5fd` Core seeded by `seed-dev` with the
|
||||
dev 33-card inventory). FIFA itself consumed the Rust squad path end-to-end: FUT boot served
|
||||
`RUST_OVERLAY userMassInfo` (squad overlay) and the squad screen rendered the dev XI; a controlled
|
||||
in-game squad edit issued `PUT …/squad/0` → host `squad-replace` → Core → `{"id":0}`; an in-game
|
||||
formation change f442→f433 persisted to Core (canonical fingerprint changed, `position_index`
|
||||
remapped 0–10); a FULL FIFA relaunch cold-fetched and rendered the persisted f433 squad (no client
|
||||
cache). Reversibility proven on the exact client path by log presence, not response data (both
|
||||
backends coincidentally hold the same dev squad — the Python oracle `fifa17_profile.json` was
|
||||
seeded from the same `squad_put_f442.json` capture): disarmed `.105:8099` reached Python (absent
|
||||
from host log), re-armed reached Rust (`route=club limit=Some(9)` present); the persistent identity
|
||||
store survived the cycle with 0 reallocation. Non-migrated routes (`/ut/auth`, `account/sync`,
|
||||
`accountinfo`, `settings`, `hub`, store txn) correctly Python-fallback. NEW startup requirement:
|
||||
the Core server loads dev card defs only for games in env `OPENFUT_DEV_CONTENT_GAMES` (comma-sep);
|
||||
omitting `fifa17` makes `get_collection` silently drop every owned card (empty `/collection`,
|
||||
"no squad") despite a successful seed — MUST become a deployment/preflight assertion. Preceded the
|
||||
same day by a staged two-process parity gate (real Core+host over HTTP, no FIFA) confirming byte-
|
||||
shape parity of `userMassInfo.squad` vs the captured oracle. Next milestone: real-data Core
|
||||
import / profile strategy → production Rust UTAS. Blaze deferred.
|
||||
- **Slice 8 (2026-08-12): REAL-DATA staged retail A/B PASS (import + club + squad).** The real FIFA 17
|
||||
profile was imported into a staged Core via the two-store protocol (`openfut-import-fifa17 --apply`:
|
||||
generic transactional Core import + `openfut-identity` seeding, idempotent), then FIFA itself
|
||||
consumed it end-to-end over the source-scoped utas switch (`.105`→`.120:8199`). Imported population
|
||||
1949 of 1962 player instances (13 Legend/special assets deferred as unnameable — 9 NoName + the 4
|
||||
copies of `169193`), every original Python wire id preserved (set-equal, 0 minted/dropped), each
|
||||
owned instance an opaque Core UUID. On the retail client: real club rendered (1949, not the 33-card
|
||||
dev XI); `/club` pagination clean (paged==full, no loop/overlap/drop); the `Special` quality filter
|
||||
returned only specials (1665, 0 base leaked) and paginated the filtered set; a squad edit persisted
|
||||
to Core (canonical + opaque extension atomically, fingerprint recomputed) and survived a full cold
|
||||
relaunch; rollback→Python→Rust re-enable proven on the exact client path (disarm reached Python,
|
||||
re-arm returned the imported club + edited squad; identity store 0 reallocation). Three real-data
|
||||
fidelity gaps the base-only dev fixture had hidden were found on the live client and fixed:
|
||||
(1) `e187cd4` versioned `resourceId` — `shape_item` emitted the base assetId as `resourceId`,
|
||||
collapsing every special onto its base card art; `Fifa17Identity` now carries the versioned
|
||||
`resource_id`. (2) `626c972` observed `rareflag` — `shape_item` hardcoded `rareflag=1`, so all
|
||||
specials rendered as basic rare; `rareflag` now flows through the FIFA catalog and onto the wire
|
||||
(wire distribution == source exactly). (3) `6f16a23` `rare=SP` Special filter — previously a no-op
|
||||
("semantics UNKNOWN"), now grounded as `rareflag > 1` and applied host-side (Core has no rareflag).
|
||||
Also `44fcf24`: nation/league/team proven to be INSTANCE metadata (not definition identity — the 4
|
||||
copies of `169193` are identical but for club), so the definition-consistency gate now compares
|
||||
identity only (no `--defer-conflict` needed; no majority-vote). PRODUCTION NOT READY: the 13 deferred
|
||||
Legends are unnameable from the `.120` client dump (absent/placeholder in `players.json`; DLC/Legends
|
||||
name tables empty) — honest names require the FIFA 17 Legends locale data from the `.105` client.
|
||||
Next: resolve the 13 names → re-import to 1962/0 → full-fidelity gate → gitlink reconcile →
|
||||
production Rust UTAS.
|
||||
|
||||
## Stubbed / planned
|
||||
|
||||
- **`fifa-blaze`** (Rust) — Milestone 1 capture stub only. Two TLS listeners that log packets; no
|
||||
FIFA 23 component/command handlers. Its own README says IDs are unknown. Superseded in practice by
|
||||
the Python FIFA 17 responders, kept as the intended FIFA 23 implementation surface.
|
||||
- **`openfut-launcher` legacy controls** — core/bridge and FIFA 23 setup controls belong to a
|
||||
superseded plan. The launcher now also owns the live FIFA 17 client flow: server/hook config,
|
||||
account synchronization, local LSX, privileged autopatch, and game launch.
|
||||
- **`tools/`** (file-watch-diff, squad-injector, exporters) — helpers for the FLE-Lua-bridge idea in
|
||||
`docs/direction.md`. Not part of the live FIFA 17 path.
|
||||
- **`docs/foundational-xi-injection-test.md`** — a planned (not executed) test procedure for the FLE
|
||||
bridge route.
|
||||
|
||||
## Stubbed / blocked (FIFA 23 lineage)
|
||||
|
||||
- **`openfut-bridge`** — in-process `version.dll` hook on ProtoSSL. Git history: injection works but
|
||||
the effort hit an "architectural wall" (async event-driven gate, not a poll). Superseded first by
|
||||
the FLE-bridge pivot, then by the FIFA 17 route. Its `CLAUDE.md` task list is historical.
|
||||
|
||||
## Unknown / requires investigation
|
||||
|
||||
- Whether the FIFA 17 hub supports actually **playing a FUT match** offline and getting results back.
|
||||
- Whether FUT actions beyond the now-verified pack reveal/assignment flow (submit SBC, transfer
|
||||
market buy/sell, matches) round-trip correctly through `utas_server.py`.
|
||||
- The exact division of FUT state ownership once Core is wired in (who is source of truth).
|
||||
- Degree of FIFA 23 wire-format identity — asserted ("identical wire format") but the FIFA 23 client
|
||||
has not been re-tested against these responders in this repo's evidence.
|
||||
|
||||
## Known technical debt / hazards
|
||||
|
||||
- **Root docs are stale.** `README.md`, `CLAUDE.md`, `openfut-bridge/CLAUDE.md` all describe FIFA 23
|
||||
as the target and mark FIFA 23 integration as the open item — they predate the FIFA 17 success.
|
||||
- **All host state is volatile** across reboot except the `/etc/hosts` line — re-run
|
||||
`openfut-fut.sh start`. Requires `ptrace_scope=0` + root arming (security-relevant).
|
||||
- **Whole stack rides on EAAC staying neutralized** and game updates being off; a client update can
|
||||
break the memory patches (VAs) and cert bypass.
|
||||
- **`fifa17-recon/tools/lsx_responder_v2.py` is currently modified in the working tree** (uncommitted).
|
||||
- `33068179` / `CAGE` remains the responder fallback, but the launcher now blocks one-button launch
|
||||
until an explicit persona is configured and synchronized across LSX, Blaze, POW, and UTAS.
|
||||
@@ -1,250 +0,0 @@
|
||||
# OpenFUT — Direction Document
|
||||
*The pivot: FUT lives in the app; FIFA 23 is the match renderer.*
|
||||
*Supersedes the Blaze-backend approach as the primary plan. Last updated 2026-06-30.*
|
||||
|
||||
---
|
||||
|
||||
## 1. Goal (revised)
|
||||
|
||||
Deliver an **intuitive way to play a FUT-style experience with FIFA 23**, where:
|
||||
|
||||
- The entire **FUT experience** — cards, squads, packs, SBCs, coins, chemistry,
|
||||
progression — lives in a **custom app** (web UI or desktop) built on the
|
||||
already-complete OpenFUT Core economy backend.
|
||||
- **FIFA 23 is demoted to a match renderer.** Its only job is to play a
|
||||
single-player match using the squad the app built. No FUT mode, no online, no
|
||||
Blaze, no EA servers.
|
||||
|
||||
This deliberately drops in-game FUT cards/UI (they live in the app) in exchange
|
||||
for a project that **converges** instead of being gated behind months of
|
||||
backend reverse-engineering.
|
||||
|
||||
### Why this replaces the backend plan
|
||||
|
||||
The status review confirmed the backend route (faking EA's online stack) is
|
||||
blocked at an upstream in-process EbisuSDK gate, with Blaze/Fire2 unconfirmed
|
||||
beyond it — realistically 3–6 months of expert RE that may not converge. The
|
||||
app-centric route sidesteps **every** wall in that review by never making FIFA's
|
||||
own FUT mode run.
|
||||
|
||||
---
|
||||
|
||||
## 2. Base mode: Career, not Kick-Off
|
||||
|
||||
**Career mode is the base.** Reasons:
|
||||
|
||||
- FLE's live-editing API (`EditDBTableField`, Freeze Lineup) is **confirmed to
|
||||
work in career mode** and explicitly does NOT work in FUT/online modes.
|
||||
- Career already provides the FUT-shaped scaffolding we'd otherwise fake:
|
||||
persistent club, a fixture schedule, recorded results, progression across a
|
||||
season.
|
||||
- **Match results are written into the career DB**, making result capture a DB
|
||||
read rather than a fragile live-memory grab.
|
||||
|
||||
**Kick-Off is the prototype sandbox.** Use it first to prove squad injection
|
||||
works with nothing to corrupt (no save to break), then move the real loop onto
|
||||
career. Run the foundational injection test in BOTH.
|
||||
|
||||
---
|
||||
|
||||
## 3. Core architecture: the bidirectional FLE bridge
|
||||
|
||||
The backbone is a **bidirectional channel between the app and a resident FLE Lua
|
||||
script running inside the game.** Everything else is messages over this channel.
|
||||
|
||||
```
|
||||
Custom App (FUT experience)
|
||||
│ squad push ──────────────► ┌─────────────────────────────┐
|
||||
│ │ Resident FLE Lua script │
|
||||
│ ◄────────── game state │ (inside FIFA 23, career) │
|
||||
│ ◄────────── match result │ - reads game state │
|
||||
└────────────────────────────► │ - applies squad live │
|
||||
(file-watch or local socket) │ - reads results from DB │
|
||||
└─────────────────────────────┘
|
||||
│
|
||||
FIFA 23 plays the match
|
||||
```
|
||||
|
||||
Three message types over the bridge:
|
||||
|
||||
1. **App → Game: squad push.** The app's chosen XI + stats applied LIVE via
|
||||
`EditDBTableField`, replicating whatever DB write FLE's "Freeze Lineup"
|
||||
feature performs (see `docs/foundational-xi-injection-test.md` — the exact
|
||||
field(s) are found by diffing, not assumed). No restart, no
|
||||
file-copy-reload. (File-load remains a fallback.)
|
||||
|
||||
2. **Game → App: game state.** The resident script polls the game's current
|
||||
screen/menu state and reports "safe to apply" vs "not safe", driving a smart
|
||||
Apply button in the app (see §5).
|
||||
|
||||
3. **Game → App: match result.** After full-time, the script reads the result
|
||||
from the career DB and pushes score/scorers to the app, which awards
|
||||
coins/progression. (Manual entry is the baseline fallback.)
|
||||
|
||||
The bridge transport can be a watched file the in-game Lua polls, or a local
|
||||
socket — decided in build (see §7). Either way the *game keeps running*; a file,
|
||||
if used, is just the message channel, not a reload.
|
||||
|
||||
---
|
||||
|
||||
## 4. Tiered mod scope
|
||||
|
||||
Build in tiers matched to risk. The core tier is all the SAME kind of DB write,
|
||||
so it lands together once squad injection works.
|
||||
|
||||
### Tier 1 — Core writes (ride the same live DB-edit mechanism)
|
||||
- **Squad / custom XI** — the load-bearing primitive (Freeze Lineup's
|
||||
underlying write, replicated via script — see §6).
|
||||
- **Player stats as "cards"** — card tiers, in-form versions, SBC upgrades all
|
||||
expressed as written attribute values.
|
||||
- **Chemistry as stat adjustment** — app computes FUT chemistry, applies it as
|
||||
small stat bumps when writing players in (no in-game chem UI; that's in the app).
|
||||
- **Appearance / identity** — kits, names, team assignment, so the club looks
|
||||
like your club on the pitch.
|
||||
- **Formation / tactics** — squad structure carries the app's build onto the pitch.
|
||||
|
||||
### Tier 2 — Confirm-then-add
|
||||
- **Match difficulty per game** — to drive a Squad-Battles-style "this opponent is
|
||||
World Class". Settable in-game trivially; programmatic drive needs confirming.
|
||||
- **Match rules / modifiers** (half length, etc.) — for app-defined challenges.
|
||||
|
||||
### Tier 3 — Result capture (manual baseline + automated stretch)
|
||||
- **Manual:** user enters the score in the app after the match. Zero RE, ships
|
||||
first.
|
||||
- **Automated:** resident script reads the career-DB result (or, for Kick-Off,
|
||||
reads the in-match score from memory at full-time — precedent exists: the
|
||||
CM cheat table's `export_season_stats.lua` already reads goals/cards from
|
||||
memory via known offsets). Push to app → auto-award progression.
|
||||
|
||||
### Out of scope (stays in the app, by design)
|
||||
- In-game FUT cards, FUT menus, pack-opening animation, chemistry board, FUT
|
||||
presentation. The app is where it looks/feels like FUT.
|
||||
|
||||
---
|
||||
|
||||
## 5. The smart Apply button (state-aware)
|
||||
|
||||
Live DB edits only "stick" in safe menu states (the in-game "Edit Player" screen,
|
||||
for example, overwrites edits). So the bridge reads game state and gates applying:
|
||||
|
||||
- Resident Lua script polls the game's current-screen value (a few Hz),
|
||||
classifies **safe / not safe**, reports to the app.
|
||||
- App's **Apply button is enabled only when the script confirms a safe state**
|
||||
(squad hub, main menu); greyed otherwise.
|
||||
- **Safe-by-default-OFF:** unknown state → button greyed → never a risky write.
|
||||
Expand the known-safe list incrementally as states are confirmed.
|
||||
- **v2 (more seamless):** instead of greying, the app always lets you click and
|
||||
the script **queues** the apply, executing the moment a safe state is entered,
|
||||
then confirms back. Greying is v1; queue-and-apply is v2.
|
||||
|
||||
`IsInCM()` is a confirmed state-read; the specific screen-state address + the
|
||||
value→screen mapping is one-time reconnaissance (same technique as result reading).
|
||||
|
||||
---
|
||||
|
||||
## 6. What's confirmed vs what needs validating
|
||||
|
||||
**Confirmed (from FLE's own Lua API docs/wiki, checked 2026-06-30):**
|
||||
- FLE live-edits the running career DB without restart, via `EditDBTableField`
|
||||
(real signature: `EditDBTableField(cell)` where `cell = row["fieldname"]`
|
||||
with `.value` mutated first — not the table/index/field/value form an
|
||||
earlier draft of this doc assumed).
|
||||
- FLE reads game state via `IsInCM()`.
|
||||
- A `MEMORY` Lua class exists (`ReadInt`/`WriteInt`/`ReadMultilevelPointer`/
|
||||
etc.) for arbitrary process memory — confirms the result-reading fallback
|
||||
in §4 Tier 3 is a real, documented capability, not just cheat-table analogy.
|
||||
- `GetPlayersStats()` is a documented function returning per-player
|
||||
goals/assists/cards/etc. — a better confirmed path for match-result capture
|
||||
than raw memory offsets.
|
||||
- **Freeze Lineup** (Formation Editor → arrange XI → tick "Freeze Lineup" →
|
||||
`Data → Save`) is FLE's actual documented mechanism for forcing a starting
|
||||
XI in career mode. This **replaces** "selection bias" below.
|
||||
- OpenFUT Core (economy) is complete and tested.
|
||||
|
||||
**Walked back — not actually confirmed:**
|
||||
- "Selection bias forces specific players into the starting XI" — no such
|
||||
field appears anywhere in FLE's documented Lua API or its own example
|
||||
scripts. This was an unverified assumption carried over from general FIFA
|
||||
modding precedent (other titles), not anything checked against FLE/FIFA 23.
|
||||
See `docs/foundational-xi-injection-test.md` for the corrected plan, which
|
||||
uses Freeze Lineup instead.
|
||||
|
||||
**Needs validating (the foundational tests — see §7):**
|
||||
- Whether Freeze Lineup actually holds into a played match (FLE's wiki
|
||||
documents the feature but not a live-match test of it).
|
||||
- What DB table/field Freeze Lineup's `Data → Save` actually writes — it's
|
||||
GUI-only and undocumented at that level; finding it is part of the
|
||||
foundational test.
|
||||
- Whether that write can be replicated by a script (`EditDBTableField`) well
|
||||
enough to drive it from an EXTERNAL trigger, not just the Formation Editor
|
||||
UI — required for the app↔game bridge.
|
||||
- The app↔game bridge transport (file-watch vs socket) works cleanly under the
|
||||
run setup.
|
||||
- The screen-state address + safe/not-safe classification (FLE's `Events`
|
||||
API page exists in the wiki index but its content is currently empty/
|
||||
undocumented — this is more open than previously assumed).
|
||||
- Result read-back from the career DB after a match.
|
||||
|
||||
**Standing caveat:** the whole stack rides on **EAAC staying neutralized**
|
||||
(FLE's fake-launcher bypass). If a game update re-enables it, hooks fail. Keep
|
||||
game updates off; confirm neutralized state each session.
|
||||
|
||||
---
|
||||
|
||||
## 7. Build order / next steps
|
||||
|
||||
Each is a bounded, verifiable step. Do them in order; later ones depend on
|
||||
earlier answers.
|
||||
|
||||
1. **FOUNDATIONAL TEST — live custom XI in career.** Confirm Freeze Lineup
|
||||
holds into a played match, reverse-engineer the DB write it makes, then
|
||||
replicate that write from a script so it can be triggered externally
|
||||
instead of through the Formation Editor UI. See
|
||||
`docs/foundational-xi-injection-test.md` for the full procedure. *Done =
|
||||
a script-driven write produces a match that fields the squad you
|
||||
specified.* Everything rests on this.
|
||||
|
||||
2. **Pick the bridge transport.** Decide file-watch vs local socket for app↔game
|
||||
messaging; implement the minimal app→game squad push. *Done = app sends a
|
||||
squad, the resident script receives and applies it.*
|
||||
|
||||
3. **Game-state reader + smart Apply.** Find the screen-state address, classify
|
||||
safe/not-safe, expose to the app, gate the Apply button. *Done = button greys
|
||||
when you enter a match/edit screen, enables in the squad hub.*
|
||||
|
||||
4. **Result read-back.** Read the career-DB match result post-game, push to app,
|
||||
award progression. Manual entry ships alongside as the fallback. *Done = app
|
||||
updates coins from a played match.*
|
||||
|
||||
5. **Tier 1 breadth.** Extend the squad push to carry stats, appearance,
|
||||
formation (same write mechanism). *Done = the club looks and plays like the
|
||||
app's build.*
|
||||
|
||||
6. **Tier 2 + economy loop polish.** Difficulty drive, challenges, and the full
|
||||
pack → SBC → squad → match → reward loop closed end-to-end.
|
||||
|
||||
### Decision still open
|
||||
- **App form factor:** web UI vs desktop app. This affects the bridge transport
|
||||
(a desktop app can hold a local socket more naturally; a web UI leans toward a
|
||||
small local helper/file-watch). Decide before step 2.
|
||||
|
||||
---
|
||||
|
||||
## 8. Provenance
|
||||
|
||||
Clean-room throughout. This route relies on FLE's documented public API and the
|
||||
game's own supported career mode — no EA backend, no Blaze, and nothing derived
|
||||
from leaked EA source. The earlier backend RE remains clean-room and is preserved
|
||||
as a spec artifact; it is simply no longer the primary path.
|
||||
|
||||
---
|
||||
|
||||
## 9. One-paragraph summary
|
||||
|
||||
OpenFUT becomes a **FUT companion app that uses FIFA 23 as a match engine.** The
|
||||
app owns the entire FUT experience; a resident FLE Lua script in career mode
|
||||
applies the app's squad live (no restart), reports game state to drive a safe
|
||||
Apply button, and reads match results back to feed progression. This sidesteps
|
||||
every backend wall, runs on confirmed FLE capabilities, builds on the finished
|
||||
economy core, and delivers the intuitive, offline, FUT-flavored loop that is the
|
||||
actual goal.
|
||||
@@ -1,443 +0,0 @@
|
||||
# FIFA 17 — Empty "My Packs" Client Contract (store/purchasegroup)
|
||||
|
||||
> **STATUS (2026-08-13): ROOT CAUSE ESTABLISHED; P2 backend compatibility workaround
|
||||
> IMPLEMENTED.** Root cause: FIFA 17's Store/Scaleform path resolves the `mypacks`
|
||||
> category even with zero unopened packs, and CardsDLL `FUN_1800147f0` assumes the
|
||||
> resolved group is non-null (crash if absent). Backend decision: **P2** — emit an
|
||||
> **active** non-openable synthetic `mypacks` placeholder (id 65534) when
|
||||
> `unopenedPackIds == []` (`fifa17-recon/tools/utas_server.py` `store_catalog`; tests
|
||||
> `fifa17-recon/tools/test_empty_mypacks.py`). Crash-safe + economy-safe; known UX
|
||||
> limitations (fake tile, click-dialog, Browse→My-Packs nav quirk) are Scaleform-driven
|
||||
> and require the client-side fix in `docs/plans/FIFA17_EMPTY_MYPACKS_CLIENT_FIX.md`.
|
||||
> This is a FIFA-17-specific compatibility shim, NOT an EA-authentic representation,
|
||||
> and is confined to the FIFA-17 adapter/backend (NOT OpenFUT Core).
|
||||
|
||||
Evidence labels: **OBSERVED** (runtime capture / crash dump / already-decompiled RE
|
||||
quoted in-repo), **INFERRED**, **HYPOTHESIS**, **UNKNOWN**. No server behavior is
|
||||
changed by this document; it is analysis only.
|
||||
|
||||
Binaries (hashes verified 2026-08-13 on `.105`):
|
||||
`CardsDLL_Win64_retail.dll` SHA-256 `4706a881ae1fc7b5769fd810b25a868d29d2b16a8e65a7513436327ef645573c`
|
||||
(load base in the crash dump `0x00006FFFFC120000`; RE-space base `0x180000000`).
|
||||
`FIFA17.exe` SHA-256 `29c31cef12b0c3c2a7305220617c7b4fa139ab76b8c857851bdbe88987962899` (packed).
|
||||
|
||||
## 1. Question
|
||||
|
||||
How must the server represent an account that owns **zero unopened packs** in
|
||||
`GET /ut/game/fifa17/store/purchasegroup/all?ppInfo=true` so that FIFA 17 neither
|
||||
(a) crashes nor (b) shows "The pack you've selected is currently not available",
|
||||
**without granting the user a real/openable pack** and without breaking the normal
|
||||
bronze/gold/special store? The current OpenFUT answer (a synthetic inactive `mypacks`
|
||||
sentinel) only downgrades a crash to a dialog; it is not the correct contract.
|
||||
|
||||
## 2. Established experimental behavior (OBSERVED)
|
||||
|
||||
Profile-state ladder, all with normal packs 1/5/6/7 unchanged:
|
||||
|
||||
| profile `unopenedPackIds` | `mypacks` group in response | client outcome |
|
||||
|---|---|---|
|
||||
| `[]` (baseline) | one **inactive** sentinel pack `65534`, empty description | "pack not available" dialog → FUT Hub |
|
||||
| `[70]` (Exp A) | one **active** real owned pack `70` | **store works**; My Packs visible |
|
||||
| `[]` + sentinel suppressed (Exp B) | **no `mypacks` group at all** | **client CRASH** |
|
||||
|
||||
Captures: `store_purchasegroup_capture_2026-08-12.json` (baseline),
|
||||
`…_mypacks70_2026-08-12.json` (A), `…_empty_no_sentinel_2026-08-12.json` (B).
|
||||
Details in `STORE_TILE_6C.md` §14-§15.
|
||||
|
||||
## 3. Existing RE evidence (from `docs/plan-2026-08-05-store-subsystem.md`, decompiled)
|
||||
|
||||
All addresses RE-space (CardsDLL base `0x180000000`):
|
||||
- **`FUN_18013af30`** — per-element pack deser; each `purchase[]` entry → a `0x158`
|
||||
wire record. `displayGroup.value`(atom 0x377) → record `+0x00` (ctor default the
|
||||
literal `"unknown"`). `displayGroup.priority`(0x250) → `+0x34`.
|
||||
(store-subsystem §"wire record", :996.)
|
||||
- **`FUN_1800150d0`** — group builder. Walks `purchase[]` in array order; for each
|
||||
pack, finds-or-creates a `0x108` display group by **exact strcmp of
|
||||
`displayGroup.value` against `group+0x70`** (`FUN_180014380`). New group
|
||||
(`FUN_180012950`): `+0x00` = 1-based ordinal (groups-so-far+1), `+0x100` =
|
||||
priority, **`+0x104` = (value == "mypacks")**, `+0x40` = vector of `0x1a8` tile
|
||||
models. Pack→tile via `FUN_18002c3c0`. (:152-161, :1042-1049.)
|
||||
- **`FUN_1800147f0`** — group **resolver/renderer**, called as
|
||||
`FUN_1800147f0(model, screen+0x290, dataProvider, 0, 0)` from `FUN_18007dab0`.
|
||||
`screen+0x290 == 0` → "list the group tiles" (`FUN_180014610`); **any other value
|
||||
→ `FUN_180014420`, which exact-matches `group+0x00` (the ordinal) and returns NULL
|
||||
on a miss, after which `FUN_1800147f0` dereferences `[RAX+0x40]` with NO guard**
|
||||
("checked in raw disassembly … a real absence"). **"The only legal category values
|
||||
are 0 and the ordinals 1..N."** (:163-169, :1051-1054.)
|
||||
- **`FUN_180014580`** — the six-tab bar: switch 0..5 over the hardcoded lowercase
|
||||
literals `mypacks, points, bronze, silver, gold, special`. `FUN_18007e5e0` gives
|
||||
each panel a `PANEL_ID` = the matching group's ordinal, **or HIDES the panel** if no
|
||||
matching group; `FUN_18007df60` publishes `MYPACK_/…/SPECIAL_CATEGORY_ID`.
|
||||
(:202-206, :1058-1062.)
|
||||
|
||||
## 4. Store parser code path (OBSERVED, decompiled)
|
||||
|
||||
```
|
||||
HTTP 200 {"purchase":[...]} (server: store_catalog / _pack_body)
|
||||
→ per-element deser FUN_18013af30 → 0x158 wire records
|
||||
→ FUN_1800150d0 → 0x108 display groups (by displayGroup.value),
|
||||
tiles (0x1a8, FUN_18002c3c0) into group+0x40
|
||||
→ render FUN_18007dab0 → FUN_1800147f0(model, screen+0x290, …)
|
||||
screen+0x290 == 0 → FUN_180014610 list this group's tiles
|
||||
screen+0x290 == N>0 → FUN_180014420 exact-match ordinal; NULL on miss
|
||||
→ [RAX+0x40] dereference (NO NULL GUARD) ← crash site
|
||||
```
|
||||
|
||||
## 5. My Packs group construction (OBSERVED)
|
||||
|
||||
A `mypacks` group exists **iff at least one `purchase[]` entry carries
|
||||
`displayGroup.value == "mypacks"`** (the group is derived from packs; there is no
|
||||
independent group object on the wire). Its ordinal is its 1-based creation position
|
||||
in array order; `group+0x104` is set because the value is `"mypacks"`; its tiles live
|
||||
in `group+0x40`. Consequently the server **cannot** emit an "empty `mypacks` group"
|
||||
via `purchase[]` — removing the pack removes the group entirely.
|
||||
|
||||
## 6. Default / selected group logic (partly UNKNOWN)
|
||||
|
||||
- `FUN_1800147f0` resolves whatever category ordinal it is handed via `screen+0x290`;
|
||||
legal values are `0` (list tiles) and `1..N` (existing ordinals). A value that is
|
||||
not an existing ordinal (e.g. `-1` for a hidden/absent panel) → `FUN_180014420`
|
||||
NULL → crash. (OBSERVED via §8 crash + RE.)
|
||||
- **Whether the store defaults to / auto-resolves the `mypacks` category on open, and
|
||||
why it does so even when the unopened count is 0, is UNKNOWN** — the store-screen
|
||||
controller and default-tab selection are Scaleform/packed-FIFA17.exe
|
||||
("Which tile the movie thinks you clicked | CLIENT | Scaleform, unread",
|
||||
store-subsystem :695). Experiment B proves that in this configuration the client
|
||||
DID resolve a `mypacks` ordinal that did not exist (it crashed), so the store is
|
||||
reaching the My Packs category with zero owned packs. Root of "why" = UNKNOWN.
|
||||
|
||||
## 7. Pack availability predicate (UNKNOWN)
|
||||
|
||||
The predicate that turns the baseline inactive sentinel into "pack not available"
|
||||
(while active pack 70 passes) is **in the packed FIFA17.exe and unread**
|
||||
(`plan-2026-08-05-pack-opening.md:553`: `state/saleType/quantity/purchaseLimit/
|
||||
purchaseCount/start/end` are parsed and copied to the tile, "the predicate that greys
|
||||
a tile is in the packed exe and unread"). Candidate deciding fields, from the
|
||||
baseline↔A diff (INFERRED, unproven): **`state` (`inactive`→`active`)** and/or
|
||||
**`unopened` (`false`→`true`)**. The exact field is **UNKNOWN**.
|
||||
|
||||
## 8. Experiment B crash analysis (OBSERVED)
|
||||
|
||||
Minidump `CrashDump_…18.21.08…dmp` (the only crash in the hour; minute `:21` matches
|
||||
the `00:21:07` store request; SHA-256 `fbddda18…`), parsed:
|
||||
- Exception: **`0xC0000005` ACCESS_VIOLATION**, access type **READ**, **faulting VA
|
||||
`0x0000000000000048`**.
|
||||
- Faulting instruction: **`CardsDLL_Win64_retail.dll + 0x14882`** → RE-space
|
||||
**`0x180014882`** = **`0x92` bytes into `FUN_1800147f0`** (entry `0x1800147f0`).
|
||||
- Interpretation (OBSERVED crash ⋂ decompiled RE): the group pointer returned by
|
||||
`FUN_180014420` was **NULL** (no `mypacks` group present with `unopenedPackIds==[]`
|
||||
and the sentinel suppressed), and `FUN_1800147f0` dereferenced `[NULL+0x48]` → read
|
||||
of address `0x48` → access violation. This is exactly the "no null guard" branch
|
||||
the RE flagged (RE said `[RAX+0x40]`; the actual faulting offset is `+0x48`, same
|
||||
member region — the group struct's `+0x40` vector accessed via a `+0x48` field).
|
||||
- Note: the pre-built Ghidra project and `/tmp/fut/cardsdll.dll` were absent on `.105`
|
||||
(tmp cleared); confirmation used the OBSERVED crash dump + the previously-decompiled
|
||||
RE rather than a fresh (expensive) re-analysis. CardsDLL is unpacked, so this code
|
||||
is statically readable if a fresh project is ever needed.
|
||||
|
||||
## 9. Empty My Packs client contract (the answer, as far as evidence allows)
|
||||
|
||||
- **The client has NO guard for a missing selected group.** If the store resolves the
|
||||
`mypacks` category and no `mypacks` group exists, it null-derefs and crashes.
|
||||
(OBSERVED.)
|
||||
- **A `mypacks` group can only exist if a `purchase[]` entry carries
|
||||
`displayGroup.value=="mypacks"`.** (OBSERVED.) There is no wire representation of an
|
||||
"empty group."
|
||||
- **If the `mypacks` group's selected pack is not a valid/active pack, the client
|
||||
shows "pack not available".** (OBSERVED baseline vs A; deciding field UNKNOWN, §7.)
|
||||
- Therefore, under the *current* client behavior, a zero-unopened-packs account is
|
||||
only cleanly handled when the `mypacks` group contains a **valid active pack**
|
||||
(Exp A). Whether an active-but-non-openable placeholder would also satisfy the
|
||||
availability predicate is **UNKNOWN** (depends on §7).
|
||||
- **The correct retail-EA representation of zero unopened packs is UNKNOWN.** It is
|
||||
NOT "omit the group" (crash) and NOT "inactive placeholder" (dialog). It is most
|
||||
likely one of: (i) the retail store does not auto-select My Packs when the unopened
|
||||
count is 0 (a client/Scaleform decision, possibly gated by a count the server sets),
|
||||
or (ii) retail sends a `mypacks` entry the client treats as an empty-but-valid state
|
||||
via a field we have not identified. Neither is established.
|
||||
|
||||
## 10. Candidate server representations
|
||||
|
||||
| # | Candidate | Client evidence | Expected behavior | Confidence | Safe to test? |
|
||||
|---|---|---|---|---|---|
|
||||
| A | No `mypacks` pack, no `mypacks` group | Exp B crash (`0x180014882`, `[NULL+0x48]`) | **CRASH** | OBSERVED | Already tested — reject |
|
||||
| B | `mypacks` group present but zero packs | Not representable via `purchase[]` (groups derive from packs, `FUN_1800150d0`) | UNKNOWN | INFERRED-not-representable | No server mechanism |
|
||||
| C | Inactive placeholder pack (current sentinel) | Baseline dialog | "pack not available" → Hub | OBSERVED | Already tested — reject |
|
||||
| C′ | **Active** placeholder pack, id absent from `PACK_CATALOG` (so open/buy handlers reject it) | Exp A shows an *active* mypacks pack works; sentinel id 65534 is already rejected by open/buy (not in `PACK_CATALOG`) | Group resolves (no crash); MIGHT pass availability (no dialog) while remaining non-openable → no free pack | HYPOTHESIS | Yes — code change, restart; economy-safe (non-openable) |
|
||||
| D | Hide My Packs when unopened count == 0 | `FUN_18007e5e0` hides a panel with no group, but the store still resolved `mypacks` at count 0 (Exp B crash) | Hiding via absence CRASHES; a client count-gate is Scaleform/unknown | UNKNOWN | Not server-controllable as far as known |
|
||||
| E | Different default category when count == 0 | Default-tab selection is Scaleform/packed | UNKNOWN | UNKNOWN | Not server-controllable as far as known |
|
||||
| F | A count/quantities field (e.g. `ut/v2/store` `FutStorePackQuantities`, or `userInfo.unopenedPacks`) that suppresses the My Packs auto-select | eligibility gate exists (`ENDPOINT_MAP.md:60`); relationship to My Packs default UNKNOWN | UNKNOWN | HYPOTHESIS | Read-only RE first |
|
||||
|
||||
## 11. Recommended next controlled experiment
|
||||
|
||||
**Experiment C′ (economy-safe placeholder).** Keep `unopenedPackIds == []`; change the
|
||||
synthetic sentinel `65534` ONLY in `state` (and, if needed, `unopened`) so the
|
||||
`mypacks` group's single tile is **active** — but leave its id `65534` **absent from
|
||||
`PACK_CATALOG`** so `store_buy`/`open_pack`/`consume_unopened_pack` still reject it
|
||||
(no pack can be opened → **no free pack, no economy change**). Observe whether the
|
||||
store then opens without the "pack not available" dialog (would identify `state` as
|
||||
the availability field and give an economy-safe fix), or still shows the dialog
|
||||
(implicating another field / packed predicate).
|
||||
- Requires a temporary code change to `store_catalog` (sentinel construction) →
|
||||
restart. Same experiment discipline as Experiment B (patch container copy, capture,
|
||||
revert, restart). Economy-safe because the placeholder remains non-openable.
|
||||
- If C′ still fails, escalate to read-only RE of the availability predicate / the
|
||||
count-gated default-tab hypothesis (candidate F) before any further change.
|
||||
|
||||
## 12. Open questions
|
||||
|
||||
1. Exact field that flips the sentinel from "pack not available" to acceptable
|
||||
(`state`? `unopened`? another). UNKNOWN — packed predicate. (Exp C′ targets this.)
|
||||
2. Why does the store resolve/select `mypacks` with zero owned packs? Is there a
|
||||
server-settable count that would stop it? UNKNOWN — Scaleform/packed.
|
||||
3. Does retail FIFA 17 ever present an empty My Packs, and how? No capture on record.
|
||||
4. Is an active-but-non-openable placeholder (C′) accepted by the availability
|
||||
predicate? HYPOTHESIS — untested.
|
||||
|
||||
---
|
||||
|
||||
## Permanent-fix requirements (Phase 11 — REPORT ONLY, not implemented)
|
||||
|
||||
A correct permanent fix MUST satisfy ALL of:
|
||||
- Zero unopened packs must **NOT** grant the user a free pack.
|
||||
- No synthetic **openable** reward may be created (any placeholder must be rejected by
|
||||
`store_buy`/`open_pack`/`consume_unopened_pack`).
|
||||
- Client must **not crash** (a resolvable `mypacks` group must exist, OR the client
|
||||
must be kept from resolving `mypacks` when empty).
|
||||
- Client must **not** show "The pack you've selected is currently not available".
|
||||
- Normal Bronze/Gold/Special store categories must still work unchanged.
|
||||
- When a genuine unopened pack exists, My Packs must continue to work (Exp A).
|
||||
- Profile/economy semantics must remain correct (no coins/nextItemId/inventory drift).
|
||||
|
||||
Nothing implemented. The evidence favours investigating an **economy-safe active
|
||||
placeholder (C′)** and/or the **count-gated My-Packs default (F)**; it explicitly does
|
||||
NOT support "grant pack 70 whenever My Packs is empty".
|
||||
|
||||
---
|
||||
|
||||
## UPDATE after Experiment C′ (2026-08-13) — active non-openable placeholder tested
|
||||
|
||||
Executed C′: sentinel 65534 `state "inactive"→"active"` only; `unopenedPackIds==[]`;
|
||||
65534 kept out of `PACK_CATALOG`. Full record in `STORE_TILE_6C.md` §16. Capture:
|
||||
`store_purchasegroup_capture_active_placeholder_2026-08-12.json` (C′-vs-baseline JSON
|
||||
diff = only `65534.state`).
|
||||
|
||||
**Resolves §7 (availability predicate), partially:** `state` **DOES participate**
|
||||
(OBSERVED). `state:"active"` removed the "pack not available" dialog while the group's
|
||||
existence still prevented the crash. So the earlier §7 "deciding field UNKNOWN" is
|
||||
updated: **`state` (inactive vs active) is (at least) a deciding field** for the
|
||||
dialog. `unopened` was NOT varied and remains untested. The full predicate may still
|
||||
involve other fields, but `state` alone flips dialog→no-dialog.
|
||||
|
||||
**Updated candidate table verdict:**
|
||||
- **C′ (active placeholder, non-openable): SUPPORTED with UX caveats — best option so
|
||||
far, but NOT adopted.** No crash, no dialog, store usable, and **no automatic
|
||||
transaction/open for 65534** (only a routine boot `TRANSACTIONCANCEL` no-op).
|
||||
Caveats (OBSERVED): (1) the placeholder renders as a **visible empty pack tile**
|
||||
("0 items, 0 bronze, 0 rares", no cover) that a user could try to open (server-safe:
|
||||
opening 65534 → no-op `{}`/stale `last_pack`, no value — §16.1); (2) **navigation
|
||||
gate**: from the Store "Browse Packs" entry the Bronze/Gold/Special categories are
|
||||
not reachable until "My Packs" is opened first (not present with a genuine owned
|
||||
pack, Exp A).
|
||||
- A (real active pack 70): works cleanly but grants a real openable pack → economy
|
||||
risk; rejected as the permanent fix.
|
||||
- Candidate **F (count-gated My-Packs default)** gains weight: C′'s visible-empty-tile
|
||||
and Browse-Packs navigation gate suggest the client is being pushed to resolve/enter
|
||||
My Packs when it should not with zero packs. If a server-settable count (e.g.
|
||||
`userInfo.unopenedPacks` / `ut/v2/store` quantities) suppresses the My-Packs
|
||||
default/tile, that could remove both the crash risk and the empty-tile artifact
|
||||
without any placeholder. UNTESTED.
|
||||
|
||||
**Permanent fix: still NOT established.** Even though C′ is the first
|
||||
crash-free/dialog-free representation, the empty-tile UX + navigation gate + the
|
||||
untested "explicit placeholder selection" behavior bar adoption. Required next steps
|
||||
(design/authorize separately): (a) controlled test of explicitly focusing/opening the
|
||||
active placeholder; (b) investigate candidate F (count-gated My-Packs) to avoid a fake
|
||||
tile entirely. Do NOT adopt `state:"active"` or "grant pack 70" as the fix on current
|
||||
evidence.
|
||||
|
||||
---
|
||||
|
||||
# Candidate F — Count-Gated My Packs Navigation (READ-ONLY investigation, 2026-08-13)
|
||||
|
||||
Question: can the server make FIFA decide **not** to resolve/default into My Packs
|
||||
when the account owns zero unopened packs (avoiding any placeholder)?
|
||||
|
||||
## 1. Server-sent unopened-pack signals (inventory, OBSERVED code)
|
||||
| field / endpoint | source | value source | when sent | client consumer | conf |
|
||||
|---|---|---|---|---|---|
|
||||
| `userInfo.unopenedPacks.recoveredPacks` (via `userMassInfo`) | `utas_server.py:409-414` | `len(unopenedPackIds)` | boot massinfo; only if count>0 **or** `_UI∈{packs,full}` (default `_UI=roster` → omitted at 0) | hub unopened-pack model / My Packs badge (`FUN…vtbl[0x4e0]`, pack-opening RE) | OBSERVED (code) |
|
||||
| `/user/credits` `.unopenedPacks.recoveredPacks` | `utas_server.py:3542-3545` | `len(unopenedPackIds)` | on credits fetch; **only if count>0** | My Packs badge / CentralUnclaimedPack hub tile | OBSERVED (code+capture) |
|
||||
| `/hub` body | `utas_server.py:1449-1453` | — | hub load | — (**no pack count present**) | OBSERVED |
|
||||
| profile `unopenedPackIds` | `fut_store.py` | account state | internal | not wire-visible directly | OBSERVED |
|
||||
`pileSize`/`store quantities` (`ut/v2/store` `FutStorePackQuantities`) exist as an
|
||||
eligibility gate (`ENDPOINT_MAP.md:60`) but were **never requested** in any capture
|
||||
(8h logs); they carry a store-open `result`, not a My-Packs count.
|
||||
|
||||
## 2. Pre-store request sequence (OBSERVED, captures)
|
||||
Boot → `accountinfo → /ut/auth → settings → phishing → match/reset → userMassInfo →
|
||||
PUT store/transaction/0 (TRANSACTIONCANCEL→{}) → /hub → clientdata → /user/credits →
|
||||
GET /store/purchasegroup/all`. The only pack-count-bearing responses **before**
|
||||
`purchasegroup` are `userMassInfo`(userInfo) and `/user/credits`.
|
||||
|
||||
## 3. Baseline([]) vs Experiment A([70]) pre-store diff (OBSERVED, captures)
|
||||
The single profile change `[] → [70]` altered exactly one pre-store wire signal:
|
||||
- `/user/credits`: **`[]` → no `unopenedPacks` member** (C′ capture, all 3 fetches:
|
||||
`{"credits":…,"currencies":[…]}`); **`[70]` → `"unopenedPacks":{"preOrderPacks":0,
|
||||
"recoveredPacks":1}`** (A capture line 25). OBSERVED.
|
||||
- `userInfo.unopenedPacks`: same pattern (present at `[70]`, omitted at `[]` with
|
||||
`_UI=roster`). INFERRED from code; A-capture credits corroborates.
|
||||
- **No other pre-store field changed.**
|
||||
|
||||
Candidate signal:
|
||||
```
|
||||
Candidate: unopenedPacks.recoveredPacks (count)
|
||||
Endpoint: /user/credits and userMassInfo(userInfo)
|
||||
Baseline([]) value: ABSENT (i.e. zero)
|
||||
Experiment A([70]) value: {preOrderPacks:0, recoveredPacks:1}
|
||||
Source: utas_server.py:3542-3545 / :409-414 (= len(unopenedPackIds))
|
||||
Client-visible before purchasegroup?: YES
|
||||
Confidence: OBSERVED that it differs; its CONTROL over My-Packs nav = see §9
|
||||
```
|
||||
**Key point: this count is already CORRECT** — it reports zero (absent) when the
|
||||
account is empty. OpenFUT is **not** misreporting a nonzero pack count.
|
||||
|
||||
## 4. Navigation / client call path (OBSERVED, decompiled RE)
|
||||
`FUN_18007dab0 → FUN_1800147f0(model, screen+0x290, …)`. `screen+0x290==0` lists
|
||||
group tiles; else `FUN_180014420` exact-matches the group ordinal (NULL on miss →
|
||||
`[NULL+0x48]` crash). `screen+0x290` is written in exactly two CardsDLL sites: the
|
||||
screen ctor `FUN_18007d1a0` writes `0`, and **`FUN_18007e7f0` case `0x7551` copies
|
||||
the Flash movie message field `CATEGORY_ID` verbatim** into it
|
||||
(store-subsystem :172-175, :1055-1056). So the resolved category is chosen by the
|
||||
**Scaleform movie**, not by any server response field.
|
||||
|
||||
## 5. `GOTO_STORE_MYPACK` analysis (OBSERVED, RE)
|
||||
`GOTO_STORE_MYPACK` is the **destination of the hub `CentralUnclaimedPack` tile**
|
||||
(tile type 0x1c); "Nothing in the chain issues a request, and no request could
|
||||
exist" (pack-opening :888-890). Whether that HUB tile appears is gated by the
|
||||
unopened-pack count in the hub model (`model+0x20950`) — i.e. the count DOES control
|
||||
the *hub unclaimed-pack tile*, but the operator reached the store via **Browse Packs**
|
||||
/ the store screen, whose category resolution is the movie-driven `CATEGORY_ID` path
|
||||
(§4), not `GOTO_STORE_MYPACK`. `GOTO_STORE_MYPACK` is a UI navigation command,
|
||||
**not** a server-state-gated store-category selector.
|
||||
|
||||
## 6. Candidate count/flag fields — verdict per field
|
||||
- `unopenedPacks.recoveredPacks`: correct at 0 when empty; controls the hub badge /
|
||||
CentralUnclaimedPack tile, **not** the store's category resolver. Not a viable gate
|
||||
for the store My-Packs entry.
|
||||
- No other server field feeds `screen+0x290` (RE §4: only ctor-0 and movie
|
||||
`CATEGORY_ID`).
|
||||
|
||||
## 7. EA-capture evidence
|
||||
No EA-origin `purchasegroup`/`credits` capture for a zero-unopened-packs account
|
||||
exists in the repo (all captures are OpenFUT-generated). EA count semantics for empty
|
||||
My Packs remain **UNKNOWN**.
|
||||
|
||||
## 8. Where My Packs selection occurs (OBSERVED)
|
||||
**Before** `purchasegroup` parsing decides content, the **Scaleform movie** decides
|
||||
which category to resolve and writes it to `screen+0x290` (§4). The server's role is
|
||||
limited to which groups EXIST in `purchase[]`. Therefore the sentinel is compensating
|
||||
for a **movie-side** decision to resolve My Packs; it is not fixing an incorrect
|
||||
server count (the count is already correct).
|
||||
|
||||
## 9. Candidate F verdict — **F3 (CONTRADICTED)** (with an F4 residue)
|
||||
My Packs selection is **not** controlled by server-sent unopened-pack state:
|
||||
- OBSERVED: the server count is correctly zero/absent when empty, yet the store still
|
||||
resolved My Packs (baseline dialog, Exp-B crash). A correct zero signal did not stop
|
||||
it.
|
||||
- OBSERVED (RE): `screen+0x290` (the resolved category) comes from the movie's
|
||||
`CATEGORY_ID`, with no server-field input; default is 0.
|
||||
Residue (F4): the movie's internal logic for *why* it asks for My Packs on store open
|
||||
is in packed Scaleform and is not statically readable — but no server lever into it
|
||||
has been found. **Conclusion: there is no server-controlled count/flag that makes FIFA
|
||||
skip resolving My Packs; the server can only ensure the `mypacks` group exists.** The
|
||||
"clean count-gated fix" is therefore **not achievable server-side**.
|
||||
|
||||
## 10. Proposed next experiment
|
||||
Because F is contradicted, a count experiment is NOT recommended (the count is already
|
||||
correct and does not gate the store). No single-variable server signal will make FIFA
|
||||
enter Browse Packs instead of My Packs. The realistic next step is the previously
|
||||
deferred **explicit active-placeholder selection test**: with the C′ active
|
||||
non-openable placeholder in place (sentinel 65534 at baseline otherwise), have the
|
||||
operator explicitly focus/open the empty My-Packs tile and observe (server-safe per
|
||||
§16.1 — opening 65534 is a no-op — but UX/navigation behavior unknown). That
|
||||
characterizes the best available server-side option (C′) before any adoption.
|
||||
- Would it change profile state? No (`unopenedPackIds=[]`).
|
||||
- Would it change purchasegroup/sentinel behavior? Only `state:"active"` (as C′),
|
||||
reverted after.
|
||||
- Code change? Yes (same one-line C′ patch). Restart? Yes. (Not authorized here.)
|
||||
If explicit selection proves unsafe/ugly, the remaining options are all **client-side
|
||||
/ out-of-scope** (the decision is in the Scaleform movie), or accepting C′ with its
|
||||
documented UX artifacts.
|
||||
|
||||
**Candidate F does NOT provide the hoped-for clean fix. The active non-openable
|
||||
placeholder (C′) remains the best server-side representation; its empty-tile and
|
||||
Browse-Packs navigation artifacts are movie-driven and not server-fixable.**
|
||||
|
||||
---
|
||||
|
||||
# Explicit Active-Placeholder Selection Test — FINAL backend-side result (2026-08-13)
|
||||
|
||||
With the C′ active placeholder in place (`unopenedPackIds=[]`, 65534 active/mypacks/
|
||||
∉PACK_CATALOG), the operator explicitly opened the empty My-Packs tile once. Full
|
||||
record in `STORE_TILE_6C.md` §17.
|
||||
- **Outcome: S1 — pure client-side rejection.** Dialog **"This pack is no longer
|
||||
available"** → back to My Packs → Hub; **no crash**, navigation stays usable.
|
||||
- **No server request** on selection (no `/store/transaction`, no `/purchased/items`,
|
||||
no 65534 reference); the verdict is client-side. (OBSERVED)
|
||||
- **Zero economy/profile mutation:** coins/items/nextItemId/`unopenedPackIds`/
|
||||
`last_pack` all unchanged; profile byte-identical (`39bb3e83…`); 65534 not
|
||||
persisted. (OBSERVED)
|
||||
|
||||
**Active-placeholder verdict: MARGINALLY ACCEPTABLE** — crash-safe + economy-safe +
|
||||
navigable, but with user-visible defects (empty fake tile; "no longer available" on
|
||||
explicit click; Browse-Packs nav gate). It is a *strict improvement* over the current
|
||||
inactive-sentinel baseline (which errors on store OPEN and bounces to Hub).
|
||||
|
||||
**Backend-side question is now fully answered.** The complete zero-unopened-packs
|
||||
ladder:
|
||||
```
|
||||
no mypacks group -> CardsDLL null-deref CRASH (unsafe)
|
||||
inactive placeholder -> "pack not available" on store open -> Hub (baseline)
|
||||
active placeholder -> store loads; empty tile; "no longer available" only on
|
||||
explicit click; recoverable; economy-safe (best backend option)
|
||||
real active owned pack -> fully correct UI (but grants a real openable pack — economy risk)
|
||||
```
|
||||
|
||||
**Permanent-fix recommendation: P2.** The active non-openable placeholder is the best
|
||||
*safe* backend-only option, but a fully *clean* zero-pack experience is **not**
|
||||
achievable server-side (Candidate F CONTRADICTED — the My-Packs resolution is
|
||||
Scaleform/movie-driven). Recommend: adopt the active placeholder as an optional
|
||||
backend compatibility mode (safe, strictly better than baseline) AND pursue a
|
||||
client-side fix (hide the fake tile / stop the forced My-Packs resolution) for the
|
||||
fully clean result. **Not implemented.** Do NOT grant a real pack.
|
||||
|
||||
---
|
||||
|
||||
## Client resolver-guard experiment (2026-08-13) — RESULT F3 (crash, confounded)
|
||||
|
||||
A client-side `autopatch.py` memory guard (CardsDLL `0x180014858` `JNZ`→`JG`, routing
|
||||
category `<0` to list-all/Browse) was tested against the exact no-sentinel server condition
|
||||
(sentinel 65534 suppressed; `GET /store/purchasegroup` ids `[1,5,6,7]`, no mypacks group).
|
||||
The client **crashed at the identical resolver site `0x180014882`** (`[NULL+0x48]`), because
|
||||
it presented a **positive** My-Packs ordinal (crash is in the `>0` resolve branch), not the
|
||||
`-1` the guard diverts. **Confound:** FIFA was not relaunched after the backend flip, so it
|
||||
reused stale (sentinel-present) tab state. So the negative-only guard is **insufficient for a
|
||||
positive stale/invalid ordinal**, and the fresh-client case is **not yet decided** (needs a
|
||||
clean re-test: fresh launch with backend already no-sentinel). Backend P2 sentinel was
|
||||
restored immediately (mandatory rollback). Full record + candidate stronger guard:
|
||||
`docs/plans/FIFA17_EMPTY_MYPACKS_CLIENT_FIX.md` PART III.
|
||||
|
||||
## Fresh-process no-sentinel retest (2026-08-13) — RESULT R1 (SUCCESS)
|
||||
|
||||
Re-ran the above cleanly: backend entered no-sentinel mode **while FIFA was closed**, then a
|
||||
**fresh** FIFA (pid 553220, new autopatch 552999, guard `85 ff 7f 0f` enforced) launched and
|
||||
opened the Store. The genuine no-sentinel `/store/purchasegroup` (ids `[1,5,6,7]`, no 65534/
|
||||
mypacks) is **byte-identical** to the F3 capture, so the only changed variable is client
|
||||
process lifetime. Outcome: **no crash, no dialog, Store opens on Browse Packs, packs
|
||||
navigable** (cosmetics only: no tabs / no cover art / "0 items" — pre-existing). A fresh
|
||||
client publishes category `-1` for the absent group, which `JNZ→JG` routes to Browse/list-all
|
||||
with no NULL deref. **This confirms F3 was stale-positive-ordinal contamination, and proves
|
||||
Strategy A (resolver guard) on the tested build.** Backend P2 sentinel restored immediately
|
||||
(`f416e71e…`, `state=active`) and remains production default. Full record:
|
||||
`docs/plans/FIFA17_EMPTY_MYPACKS_CLIENT_FIX.md` PART IV.
|
||||
@@ -1,924 +0,0 @@
|
||||
# Store Tile Investigation (bug 6c)
|
||||
|
||||
Status: **ROOT CAUSE ESTABLISHED — P2 compatibility workaround IMPLEMENTED**
|
||||
(2026-08-13). Full investigation complete (§1-§17); backend fix landed in
|
||||
`fifa17-recon/tools/utas_server.py` `store_catalog` with regression tests in
|
||||
`fifa17-recon/tools/test_empty_mypacks.py`. The store-tiles flags are unchanged
|
||||
(`FUT_STORE_DISPLAYGROUP=ON`, `FUT_STORE_GROUPID=OFF`) and the profile is unchanged.
|
||||
|
||||
## RESOLUTION (2026-08-13)
|
||||
|
||||
**ROOT CAUSE (bug 6c):** FIFA 17's Store/Scaleform path RESOLVES the `mypacks`
|
||||
category even when the account owns zero unopened packs (the category is chosen
|
||||
client-side from the movie's `CATEGORY_ID` → `screen+0x290`; no server field gates
|
||||
it — Candidate F CONTRADICTED). CardsDLL `FUN_1800147f0` then dereferences the
|
||||
resolved group with NO null guard, so an absent `mypacks` group crashes the client
|
||||
(`CardsDLL_Win64_retail.dll+0x14882`, `[NULL+0x48]` — minidump-confirmed, §8).
|
||||
|
||||
**BACKEND RESULT / DECISION — P2 (compatibility workaround):** emit a synthetic,
|
||||
**active**, non-openable `mypacks` placeholder (id 65534, absent from `PACK_CATALOG`)
|
||||
only when `unopenedPackIds == []`. This is crash-safe AND economy-safe (explicit
|
||||
selection is rejected client-side with "This pack is no longer available", sends no
|
||||
backend request, and mutates nothing — §17). It is a FIFA-17 client-compatibility
|
||||
shim, **NOT** an EA-authentic empty-My-Packs representation, and is confined to the
|
||||
FIFA-17 adapter/backend layer (NOT OpenFUT Core).
|
||||
|
||||
**KNOWN UX LIMITATIONS (unfixable server-side):** a fake empty "0 items" tile; an
|
||||
explicit-selection dialog "This pack is no longer available"; and a Browse-Packs →
|
||||
My-Packs navigation quirk. These are Scaleform/movie-driven.
|
||||
|
||||
**CLEAN CLIENT FIX:** still unresolved; belongs to client-side work —
|
||||
`docs/plans/FIFA17_EMPTY_MYPACKS_CLIENT_FIX.md`.
|
||||
|
||||
Evidence labels: **OBSERVED** (running code / `docker inspect` / live log / minidump /
|
||||
table), **INFERRED**, **HYPOTHESIS**, **UNKNOWN**.
|
||||
|
||||
### Hypotheses
|
||||
|
||||
- **H1 (original — subtype/definition):** *Store tiles render "unknown" because the
|
||||
server emits definitions whose type/subtype the client cannot map (prime suspects
|
||||
5004xxx misc {231,232,233,236}, 8010xxx league logos, FCC↔wire subtype gaps).*
|
||||
**Verdict: CONTRADICTED by static store-handler evidence.** The `/store/purchasegroup`
|
||||
handler emits PACK definitions only — no `cardsubtypeid`/`carddbid`/`cardassetid`
|
||||
anywhere in the response (§2). Those subtype families belong to the separate
|
||||
**club-item / consumable / equippable** paths (`fut_clubitems.py`, `fut_consumables`,
|
||||
`/club?type=`), which are OUT OF SCOPE for this store-tile task. History preserved
|
||||
in §3.3 and §8; not investigated further here.
|
||||
- **H2 (revised — displayGroup token):** **HYPOTHESIS (under runtime test).** *The
|
||||
"unknown" FUT Store tile is caused by one or more pack entries whose
|
||||
`displayGroup.value` token is not one of the six categories FIFA 17 can render:*
|
||||
`mypacks, points, bronze, silver, gold, special`. Tested against a real capture in
|
||||
§4-§8.
|
||||
|
||||
---
|
||||
## Runtime capture plan (Phase 2) — OBSERVED
|
||||
|
||||
- **Backend container:** `openfut-fut-backend` (logs on stdout via `log()`,
|
||||
`utas_server.py:59-62`; each request logs `"<VERB> <path>"` at `:3732`, and the
|
||||
response line `" -> <code> <body[:200]>"` at `:3754` — **response body truncated
|
||||
to 200 bytes**, so the full JSON body is NOT in the log).
|
||||
- **Endpoint / path matcher:** `GET /ut/game/fifa17/store/purchasegroup/all?ppInfo=true`
|
||||
(OBSERVED historically in the log; route regex `/store/purchasegroup`,
|
||||
`utas_server.py:1215`).
|
||||
- **Capture marker (UTC, set immediately before the manual test):**
|
||||
`2026-08-12T23:54:01Z` (saved to `/tmp/store_capture_marker.txt`; 0 log lines
|
||||
after it at set-time → clean boundary).
|
||||
- **Log command to isolate the manual action:**
|
||||
`docker logs --since 2026-08-12T23:54:01Z --timestamps openfut-fut-backend`
|
||||
then locate the first `GET .../store/purchasegroup` line after the marker plus its
|
||||
following headers and `-> 200 {"purchase"...` line.
|
||||
- **Full-body recovery (because the log truncates at 200 bytes):** the response is a
|
||||
deterministic pure function — `store_catalog()` (`:3408`) over static `PACK_CATALOG`
|
||||
(`fut_store.py:820`) + live `STORE.unopened_packs()` (from `/state` profile) under
|
||||
fixed flags (`STORE_DISPLAYGROUP=ON`, `STORE_GROUPID=OFF`, `FUT_PRICE_PROBE=OFF`).
|
||||
Plan: reconstruct the exact body from the running `/app` code + live `/state`
|
||||
profile, then **verify** its `json.dumps(...)[:200]` byte-for-byte equals the genuine
|
||||
logged 200-byte prefix. Match ⇒ the reconstruction IS the sent body. No request is
|
||||
synthesized, replayed, or curl'd; the genuine log line is the ground-truth anchor.
|
||||
|
||||
|
||||
## 1. Method
|
||||
|
||||
### Environment (OBSERVED)
|
||||
- Running on `10.10.0.120` (dev-lxc). Client is `10.10.0.105`.
|
||||
- Backend under test: Docker container `openfut-fut-backend`
|
||||
(image `openfut-fut-backend:dev`), `Up 7 hours`, entrypoint `/app/entrypoint.sh`.
|
||||
- `docker inspect openfut-fut-backend`: only mount is
|
||||
`/home/alex/OpenFUT/fifa17-recon/docker/state -> /state (rw)`; container ENV
|
||||
contains **no `FUT_STORE_*`** vars.
|
||||
- `entrypoint.sh` launches `python3 -u utas_server.py` from `/app/tools` with extra
|
||||
env `FUT_TRADING=1 FUT_PILESIZES=1 FUT_TRADEABLE=1 FUT_DISCARD_TABLE=1
|
||||
FUT_DISCARD_SEND=1` — again **no `FUT_STORE_*`**.
|
||||
- The running store code is `/app/tools/utas_server.py`. Extracted read-only via
|
||||
`docker cp openfut-fut-backend:/app/tools /tmp/app-tools` and confirmed
|
||||
**byte-identical** (`sha256`) to the repo copy
|
||||
`fifa17-recon/tools/utas_server.py` (both 3765 lines) and
|
||||
`fifa17-recon/tools/fut_clubitems.py`. All line references below are to the repo
|
||||
paths and equal the running code.
|
||||
|
||||
### Commands (exact)
|
||||
```
|
||||
docker ps --format '{{.Names}}\t{{.Image}}\t{{.Command}}\t{{.Status}}'
|
||||
docker inspect openfut-fut-backend --format '...CMD/ENTRYPOINT/MOUNTS/ENV...'
|
||||
docker exec openfut-fut-backend cat /app/entrypoint.sh
|
||||
docker cp openfut-fut-backend:/app/tools /tmp/app-tools
|
||||
docker cp openfut-fut-backend:/app/data /tmp/app-data
|
||||
diff /tmp/app-tools/utas_server.py fifa17-recon/tools/utas_server.py # identical
|
||||
diff /tmp/app-tools/fut_clubitems.py fifa17-recon/tools/fut_clubitems.py # identical
|
||||
```
|
||||
|
||||
### Manual test sequence
|
||||
NOT executed. The manual FIFA-client store capture (2D/2E) was never reached
|
||||
because the investigation blocked at 2C before any flag could be enabled. No
|
||||
request was synthesized, replayed, or simulated.
|
||||
|
||||
---
|
||||
|
||||
## 2. Store handler code path (2A) — OBSERVED
|
||||
|
||||
Request → response for the store tile screen:
|
||||
|
||||
1. **Endpoint.** `GET ut/<sku>/store/purchasegroup/...` — `FutStoreGetPackTypes`
|
||||
(client deser root `0x1801234e0`). (`utas_server.py:3408-3409` docstring.)
|
||||
- Route table entry: `(re.compile(r"/store/purchasegroup"), lambda m,h:
|
||||
store_catalog(h))` at `utas_server.py:1215`.
|
||||
- Sibling store routes: `/store/transaction -> store_buy(h)` (`:1216`, the BUY);
|
||||
bare `/store(\?|$) -> (200,{"result":"SUCCESS"})` eligibility gate (`:1221`).
|
||||
2. **Handler.** `store_catalog(h)` (`utas_server.py:3408-3447`).
|
||||
- Iterates `PACK_CATALOG` (non-`ownedOnly` packs) → `_pack_body(p, idx)`.
|
||||
- Appends owned unopened packs from `visible_unopened_packs()` →
|
||||
`STORE.unopened_packs()` + `_OPENED_PACK_GRACE` (`:51-52`, `:3423-3427`).
|
||||
- If no owned packs, appends one inactive `mypacks` sentinel (id 65534) so
|
||||
`GOTO_STORE_MYPACK` resolves (`:3428-3446`).
|
||||
- Returns `200, {"purchase": [<pack bodies>], "timestamp": 1596326400}`
|
||||
(`:3447`).
|
||||
3. **Definition construction.** `_pack_body(p, idx, owned=False)`
|
||||
(`utas_server.py:3268-3405`). Emitted keys (OBSERVED, `:3293-3328`):
|
||||
`assetId`(=`p["id"]`), `id`(=`p["id"]`), `packType`, `description`(=`p["name"]`),
|
||||
`state`, `saleType`, `limitType`, `quantity`, `purchaseLimit`, `purchaseCount`,
|
||||
`isPremium`, `sortPriority`, `currencies`, `extPrice`, `packContentInfo`
|
||||
(`bronze/silver/gold/rare/itemQuantity`), `unopened`, and one of:
|
||||
- owned pack → `displayGroup = {"value":"mypacks","priority":idx}` (`:3336`);
|
||||
- else if `STORE_DISPLAYGROUP` → `displayGroup = {"value": category}` where
|
||||
`category ∈ {special, gold, silver, bronze}` chosen from
|
||||
`p["specialChance"]`/`p["gold"]` (`:3337`,`:3373-3379`), and if `STORE_GROUPID`
|
||||
also `displayGroupAssetId = p["id"]` (`:3403-3404`).
|
||||
4. **Data source(s).**
|
||||
- `PACK_CATALOG` — a hardcoded list of 3 pack dicts
|
||||
(`{id,name,price,count,gold,tiers,specialChance}`) at `fut_store.py:820-841`.
|
||||
There is NO card table read in this path.
|
||||
- `STORE = Store()` (`fut_store.py:843`), backed by the profile JSON
|
||||
(`unopened_packs()` reads `unopenedPackIds`, `fut_store.py:619-621`).
|
||||
5. **Serialization → HTTP.** The dict is JSON-encoded by the server's response
|
||||
writer and returned as the HTTP body.
|
||||
|
||||
### Fields 5 (`cardsubtypeid`/`carddbid`/`cardassetid`) — OBSERVED
|
||||
**None of `cardsubtypeid`, `carddbid`, or `cardassetid` appear anywhere in the
|
||||
store-tile (`purchasegroup`) response.** `_pack_body` (`:3293-3405`) emits only the
|
||||
pack keys listed above; `assetId`/`id` are the PACK id `p["id"]` (e.g. 1, 5), not a
|
||||
card asset id. The store catalog emits PACKS, never card definitions. (Grep of
|
||||
`_pack_body` and `store_catalog` for those three field names returns zero hits.)
|
||||
|
||||
### Families the store handler can emit
|
||||
Only **packs** (`PACK_CATALOG`: "Bronze Pack" id 1, "Gold Pack" id 5, and the third
|
||||
catalog entry) plus owned reward packs and the `mypacks` sentinel. It cannot emit
|
||||
any card family (players, staff, consumables, club items).
|
||||
|
||||
### Filtering / transformation
|
||||
- `normal = [p for p in PACK_CATALOG if not p.get("ownedOnly")]` (`:3421`).
|
||||
- `_pack_body` maps a pack to a category token via `specialChance>=1.0 -> special`,
|
||||
else `gold -> gold`, `p.get("silver") -> silver`, else `bronze` (`:3373-3379`).
|
||||
- The tile caption/category is `displayGroup.value`; `description` carries the
|
||||
per-pack title.
|
||||
|
||||
---
|
||||
|
||||
## 3. Wire subtype coverage (2B)
|
||||
|
||||
### 3.1 Store path
|
||||
The store-tile path emits **no `cardsubtypeid`** at all (see §2). So for the store
|
||||
tile, "is `cardsubtypeid` the raw FCC subtype, the wire category, transformed, or
|
||||
something else?" → **not present** (N/A). The store tile is selected by
|
||||
`displayGroup.value` (a category-token STRING), not by any card subtype.
|
||||
|
||||
Per `_pack_body:3367-3372` (citing `FUN_180014580`/`FUN_180014df0`): FIFA 17's
|
||||
StoreFront resolves exactly **six hard-coded category tokens** —
|
||||
`mypacks, points, bronze, silver, gold, special`. Any other `displayGroup.value`
|
||||
(e.g. a raw pack title) creates an "unsupported pseudo-category". The documented
|
||||
cause of "unknown" store tiles is therefore a **`displayGroup` category-token**
|
||||
issue on packs (absent group, or a non-canonical token), NOT a card type/subtype.
|
||||
|
||||
### 3.2 Club-item path (the only place wire subtypes live) — `fut_clubitems.py`
|
||||
Club items are served on the **`/club?type=` route** (`utas_server.py:2250`,
|
||||
`handle_club`), gated by `FUT_CLUBITEMS`, NOT by the store route. Current `FAMILIES`
|
||||
(`fut_clubitems.py:61-67`), format `(family, table, art id, stat id, stat name,
|
||||
UNVERIFIED cardsubtypeid)`:
|
||||
|
||||
| wire subtype | mapped family | table | art id | source | confidence |
|
||||
|---|---|---|---|---|---|
|
||||
| 9 | kits | fcc_kitcards.json | 35 | `fut_clubitems.py:65` | HYPOTHESIS (marked "UNVERIFIED", `:49`,`:30-32`) |
|
||||
| 10 | stadia | fcc_stadium.json | 36 | `fut_clubitems.py:63` | HYPOTHESIS ("UNVERIFIED") |
|
||||
| 11 | badges | fcc_badgecards.json| 39 | `fut_clubitems.py:64` | HYPOTHESIS ("UNVERIFIED") |
|
||||
| 30 | balls | fcc_balls.json | 37 | `fut_clubitems.py:62` | HYPOTHESIS ("UNVERIFIED") |
|
||||
| 31 | leaguelogos | fcc_leaguelogos.json| 40| `fut_clubitems.py:66` | HYPOTHESIS ("UNVERIFIED") |
|
||||
|
||||
- The prior recorded mapping (9=kits,10=stadia,11=badges,30=balls,31=logos) is
|
||||
**confirmed present in current code** — but the code itself marks every one
|
||||
"UNVERIFIED cardsubtypeid" and states the binary assigns family↔subtype **nowhere**
|
||||
in the 149 dumped tables; cardtype-9 admits the set `{30,31,145,146,147,148,149,150}`
|
||||
(`fut_clubitems.py:26-28`, `:73`). So these are server-chosen HYPOTHESIS values.
|
||||
- In the club-item wire item (`_item:88-119`), `cardsubtypeid` (`:97`) is a
|
||||
**server-assigned wire-category constant** (9/10/11/30/31), NOT the raw FCC
|
||||
subtype: the club-item fcc tables carry **no `cardsubtype` column at all** (Task 1:
|
||||
badges/stadium/kit/logos/balls have empty subtype sets). `resourceId`/`assetId`
|
||||
= `carddbid`, and `cardassetid` = the family ART id (`:94-96`). So for club items:
|
||||
**`cardsubtypeid` = wire category (server constant), `carddbid`/`cardassetid` =
|
||||
real fcc columns.**
|
||||
- By contrast, consumables (`fut_store._item` / `fut_consumables`) DO carry the raw
|
||||
FCC subtype (51..341) as `cardsubtypeid`.
|
||||
|
||||
### 3.3 Task-1 families vs wire-subtype coverage
|
||||
Families that the **store handler** can map to a wire subtype: **none** — the store
|
||||
handler emits packs, which have no card subtype (by design).
|
||||
|
||||
Families for which a **club-item** wire subtype exists (HYPOTHESIS-grade):
|
||||
kits(9), stadia(10), badges(11), balls(30), leaguelogos(31).
|
||||
|
||||
Task-1 card families with **no wire subtype mapping anywhere in the server**:
|
||||
- **5001xxx contracts, 5002xxx fitness/healing, 5003xxx training** — served as
|
||||
consumables carrying their raw FCC subtype; these are consumable overlays, not
|
||||
store tiles, and not part of any store/club-item wire-category map.
|
||||
- **5004xxx misc {231,232,233,236}** — **no wire subtype mapping found** in
|
||||
`fut_clubitems.py` or the store path. (Grep: no `misc` family, no {231,232,233,236}
|
||||
wire assignment.) They exist only as raw FCC subtypes in consumable data.
|
||||
- **8010xxx league logos/stickers** — mapped in the **club-item** path as wire
|
||||
subtype **31** (`fut_clubitems.py:66`), HYPOTHESIS-grade. `fcc_leaguelogostickers`
|
||||
(39 rows) is NOT wired in `FAMILIES` (only `fcc_leaguelogos`, 44 rows).
|
||||
- **6000xxx badges, 6200xxx stadiums, 6300/6400xxx kits, 8120xxx balls** — mapped in
|
||||
the club-item path (11/10/9/30), HYPOTHESIS-grade.
|
||||
- **staff (managers/coaches, subtypes 4-8)** — served by `fut_staff` on `/club?type=
|
||||
manager`, not a store tile.
|
||||
|
||||
Note none of these belong to the **store-tile** (`purchasegroup`) response.
|
||||
|
||||
---
|
||||
|
||||
## 2C flag investigation — BLOCKED
|
||||
|
||||
### Store-tiles flags located (OBSERVED)
|
||||
Two, both in `utas_server.py`, both module-level constants read **once at import**:
|
||||
|
||||
| flag | env var | line (read) | consumed | default | current running value |
|
||||
|---|---|---|---|---|---|
|
||||
| `STORE_DISPLAYGROUP` | `FUT_STORE_DISPLAYGROUP` | `:975` | `_pack_body:3337` | `"1"` → **ON** | **ON** (no env override) |
|
||||
| `STORE_GROUPID` | `FUT_STORE_GROUPID` | `:980` | `_pack_body:3403` | `"0"` → **OFF** | **OFF** (no env override) |
|
||||
|
||||
- `:975` `STORE_DISPLAYGROUP = os.environ.get("FUT_STORE_DISPLAYGROUP", "1") == "1"`
|
||||
- `:980` `STORE_GROUPID = os.environ.get("FUT_STORE_GROUPID", "0") == "1"`
|
||||
|
||||
**Current values (recorded before any change; nothing was changed):**
|
||||
- `FUT_STORE_DISPLAYGROUP`: unset in container env → default `"1"` →
|
||||
`STORE_DISPLAYGROUP = True` (**ON**). (INFERRED from OBSERVED env dump + OBSERVED
|
||||
code default.)
|
||||
- `FUT_STORE_GROUPID`: unset in container env → default `"0"` →
|
||||
`STORE_GROUPID = False` (**OFF**). This is the flag "expected to be OFF".
|
||||
|
||||
The related club-item flag `FUT_CLUBITEMS` (`:1647-1648`) is likewise unset →
|
||||
`CLUBITEMS = False` (club items not currently served), also a module-level import
|
||||
constant.
|
||||
|
||||
### Dynamic evaluation? NO (OBSERVED)
|
||||
- All three flags are top-level `os.environ.get(...)` assignments evaluated at
|
||||
module import (`:975`, `:980`, `:1647`); `_pack_body` reads the resulting module
|
||||
**constants** (`:3337`, `:3403`), never `os.environ` at request time.
|
||||
- Repo-wide there is **no** `importlib.reload`, no `signal`/`SIGHUP` handler, and no
|
||||
per-request environ re-read for these flags. (The only runtime-refreshable feature
|
||||
is `FUT_ID_SWEEP`, which re-reads a *file* `SWEEP_FILE`, `:1965-1966` — unrelated.)
|
||||
- `:3250` documents the intended workflow explicitly:
|
||||
`# Enable for the test with: FUT_PRICE_PROBE=1 ./openfut-fut.sh restart`.
|
||||
|
||||
### Restart conflict → STOP
|
||||
Changing either store flag requires either setting a container env var (→
|
||||
`docker` recreate = restart) or editing the module (→ re-import = restart). Both
|
||||
violate the no-restart / no-redeploy / no-recreate constraint. Therefore:
|
||||
|
||||
```
|
||||
TASK 2 BLOCKED AT 2C:
|
||||
Flag requires restart, conflicting with no-restart constraint.
|
||||
```
|
||||
|
||||
No flag was enabled. 2D/2E (manual client capture + definition analysis) NOT
|
||||
started. No client request generated, replayed, or simulated.
|
||||
|
||||
---
|
||||
|
||||
## 4. Captured request and response (Phase 3) — OBSERVED
|
||||
|
||||
Real client action (operator opened the FUT Store on `.105`, 2026-08-12). Only one
|
||||
`/store/purchasegroup` request occurred after the capture marker
|
||||
`2026-08-12T23:54:01Z`, so attribution is unambiguous (only the operator drives the
|
||||
client). Log via `docker logs --since 2026-08-12T23:54:01Z --timestamps openfut-fut-backend`.
|
||||
|
||||
- **Request:** `23:54:43 GET /ut/game/fifa17/store/purchasegroup/all?ppInfo=true`
|
||||
(Host `10.10.0.120:8099`, `User-Agent: ProtoHttp 1.3/DS 15.1.2.1.0 (Windows)`,
|
||||
`X-UT-SID` present). Preceded at 23:54:43 by `GET /ut/game/fifa17/user/credits`
|
||||
→ `200 {"credits": 29876776, ...}`.
|
||||
- **Response:** `200`. The server log truncates the body to 200 bytes
|
||||
(`utas_server.py:3754`, `raw[:200]`), genuine prefix:
|
||||
`{"purchase": [{"assetId": 1, "id": 1, "packType": "BRONZE", "description": "Bronze Pack", "state": "active", "saleType": "promo", "limitType": "NONE", "quantity": 0, "purchaseLimit": 0, "purchaseCount`
|
||||
- **Full body recovered** by running the exact running-container code
|
||||
(`docker exec openfut-fut-backend python3 -c "import utas_server as u; u.store_catalog(None)"`)
|
||||
over the live `/state` profile, under the live flags (confirmed in-process:
|
||||
`STORE_DISPLAYGROUP=True`, `STORE_GROUPID=False`). Its `json.dumps(...)[:200]`
|
||||
equals the genuine logged 200-byte prefix **byte-for-byte** (verified MATCH), so the
|
||||
reconstruction IS the sent body (deterministic pure function + verified prefix). No
|
||||
request was synthesized, replayed, or curl'd. Full body (2841 bytes) preserved
|
||||
verbatim at `docs/evidence/store_purchasegroup_capture_2026-08-12.json`.
|
||||
- **Operator-reported client behavior:** on opening the store, an error dialog
|
||||
appeared — *"The pack you've selected is currently not available. Please select a
|
||||
different pack or try again later."* — and clicking OK returned to the FUT hub. No
|
||||
tiles were browsable; **no "unknown" tiles were reported**. There was **no**
|
||||
`PUT /store/transaction` (no buy) and **no server error** (server answered `200`).
|
||||
|
||||
## 5. Definition analysis (Phase 4/5) — OBSERVED
|
||||
|
||||
`purchase[]` = 5 entries (`timestamp` 1596326400). No `cardsubtypeid`/`carddbid`/
|
||||
`cardassetid` in any entry (packs, not cards).
|
||||
|
||||
| idx | id | assetId | packType | description | displayGroup.value | priority | state | dgAssetId | classification |
|
||||
|---|---|---|---|---|---|---|---|---|---|
|
||||
| 0 | 1 | 1 | BRONZE | Bronze Pack | `bronze` | — | active | absent | KNOWN TOKEN |
|
||||
| 1 | 5 | 5 | GOLD | Gold Pack | `gold` | — | active | absent | KNOWN TOKEN |
|
||||
| 2 | 6 | 6 | GOLD | Premium Gold | `gold` | — | active | absent | KNOWN TOKEN |
|
||||
| 3 | 7 | 7 | GOLD | Special Players Pack | `special` | — | active | absent | KNOWN TOKEN |
|
||||
| 4 | 65534 | 65534 | GOLD | "" (empty) | `mypacks` | 1 | **inactive** | absent | KNOWN TOKEN |
|
||||
|
||||
Per-pack fields (idx 0-3 identical shape): `saleType:"promo"`, `limitType:"NONE"`,
|
||||
`quantity:0`, `purchaseLimit:0`, `purchaseCount:0`, `isPremium:false`,
|
||||
`currencies:[{"name":"coins","funds":<price>,"finalFunds":<price>}]`,
|
||||
`extPrice:{finalPrice/originalPrice:{amount:<price/100>,currency:"mtx"}}`,
|
||||
`packContentInfo:{...tier quantities...}`, `unopened:false`. Prices: Bronze 400,
|
||||
Gold 5000, Premium Gold 15000, Special Players 25000. The sentinel (idx 4) drops
|
||||
`currencies`/`extPrice`, has empty description, `state:"inactive"`.
|
||||
|
||||
**Unique `displayGroup.value` set emitted: `{bronze, gold, special, mypacks}`.**
|
||||
Compared to the six client renderer tokens `{mypacks, points, bronze, silver, gold,
|
||||
special}` (`FUN_180014580`/`FUN_180014df0`, `plan-2026-08-05-store-subsystem.md:202-206`):
|
||||
**every emitted token is a KNOWN token; the set outside the renderer categories is
|
||||
EMPTY.**
|
||||
|
||||
## 6. Unmapped definitions / suspect tokens found — OBSERVED
|
||||
|
||||
None. Zero SUSPECT/UNKNOWN `displayGroup.value` tokens; zero card definitions;
|
||||
zero `cardsubtypeid`/`carddbid`/`cardassetid`. The only anomalous element is the
|
||||
**inactive, empty-description `mypacks` sentinel** (idx 4), emitted by
|
||||
`store_catalog:3428-3446` **only when the profile owns zero unopened packs**
|
||||
(OBSERVED: profile `unopenedPackIds == []`).
|
||||
|
||||
## 7. Client-side evidence (Phase 7) — existing RE only
|
||||
|
||||
No new Ghidra run. Existing decompiler evidence already bounds the answer and shows
|
||||
new static analysis would be unproductive:
|
||||
- **The parser is not the gate** (`OPENCODE_ENDPOINT_PROMPT.md:118-120`): per-pack
|
||||
epilogue `0x18013badc` pushes every parsed pack unconditionally — no drop predicate
|
||||
in the parse path. So a `200` with clean JSON cannot be rejected by the deserializer.
|
||||
- **Store-level "not available"** (`FUT_CatalogNotAvailable`, msg `0x7550`) comes from
|
||||
downstream client gates (`OPENCODE_ENDPOINT_PROMPT.md:120-131`): (1) resolution
|
||||
`GetSystemMetrics` ≤1024×768, (2) store-data-model load status `0x180013cf0`,
|
||||
(3) Blaze purchase-config flags `IS_STORE_ENABLED/IS_COIN_PURCHASABLE/...` (these
|
||||
are already served, `blaze_responder_v3b.py:708-719`).
|
||||
- **Per-pack tile-availability predicate is in the PACKED FIFA17.exe and UNREAD**
|
||||
(`plan-2026-08-05-pack-opening.md:553`): fields `state/saleType/quantity/
|
||||
purchaseLimit/purchaseCount/start/end` are parsed and copied to the tile, but the
|
||||
predicate that greys/blocks a tile "is in the packed exe and unread." Whether
|
||||
`purchaseLimit`+`purchaseCount` greys a tile is explicitly an OPEN question
|
||||
(`:644-645`). Static Ghidra on the packed exe cannot read it (decrypts only in live
|
||||
memory); resolving it requires a live-memory experiment on the running FIFA process,
|
||||
which is out of scope (must not touch FIFA).
|
||||
- The exact operator string *"The pack you've selected is currently not available"*
|
||||
is **not present** anywhere in the recon corpus (docs/tools); the documented
|
||||
store/pack error strings are `FUT_CatalogNotAvailable` and
|
||||
`CARDS_CB_ERR_PACK_NOT_IN_DIME` (a server-returnable code). UNKNOWN loc key.
|
||||
|
||||
## 8. Assessment (Phase 8) — runtime verdict
|
||||
|
||||
- **H1 (subtype/definition): CONTRADICTED.** The captured response contains no card
|
||||
definitions and no `cardsubtypeid`/`carddbid`/`cardassetid` (OBSERVED §4-§5).
|
||||
- **H2 (unknown `displayGroup.value` token): CONTRADICTED.** Every emitted token is a
|
||||
KNOWN renderer category (`bronze/gold/special/mypacks`); the unsupported-token set
|
||||
is EMPTY (OBSERVED §5). The store-tile "unknown" mechanism is NOT reproduced under
|
||||
the current config (`STORE_DISPLAYGROUP=ON`).
|
||||
|
||||
Answering the Phase-8 questions:
|
||||
1. **Unsupported `displayGroup.value` in the response?** No — all four tokens
|
||||
(`bronze/gold/special/mypacks`) are recognized. (OBSERVED)
|
||||
2. **Which pack got it?** None. (OBSERVED)
|
||||
3. **Correspond to an unknown tile in FIFA?** No unknown tile was reported; the
|
||||
observed symptom was a *"pack not available"* dialog, not an unknown tile. (OBSERVED)
|
||||
4. **Where does the backend assign the token?** `_pack_body:3373-3379` maps each pack
|
||||
to `special/gold/silver/bronze` from `specialChance`/`gold`; owned/sentinel →
|
||||
`mypacks` (`:3336`). All canonical. (OBSERVED)
|
||||
5. **Is `displayGroup.value` sufficient to explain the bug?** No. The response is
|
||||
clean; the failure is a downstream client/packed-exe gate, not a token. (INFERRED)
|
||||
6. **Is the server emitting a value FIFA demonstrably cannot understand?** No.
|
||||
(OBSERVED)
|
||||
7. **Narrowest likely fix (REPORT ONLY — not implemented):** The single anomalous,
|
||||
server-controllable element is the **inactive empty `mypacks` sentinel** emitted
|
||||
when `unopenedPackIds == []` (`store_catalog:3428-3446`). Leading HYPOTHESIS: with
|
||||
no owned packs, the store's My-Packs group contains only this inactive pack, and
|
||||
the client's (packed-exe) selection/availability path lands on it →
|
||||
*"the pack you've selected is currently not available"* → back to hub. Narrowest
|
||||
candidate fixes to TEST (each needs a controlled change, hence a future
|
||||
restart-gated experiment — do NOT implement now):
|
||||
(a) suppress the sentinel when there are no owned packs and instead let the store
|
||||
land on a real active category (bronze/gold/special); or
|
||||
(b) if My-Packs must resolve, make the sentinel non-selectable rather than an
|
||||
`inactive` pack in the group.
|
||||
Cheaper-to-eliminate CLIENT-side cause to check first (existing RE, no server
|
||||
change): FIFA display resolution must be **>1024×768** on `.105`
|
||||
(`OPENCODE_ENDPOINT_PROMPT.md:122-124`).
|
||||
|
||||
**Overall runtime verdict: CONTRADICTED** — neither H1 nor H2 reproduces; the
|
||||
"unknown store tile" hypothesis is not the live failure. The live failure is a
|
||||
distinct *pack-availability* error whose trigger is in the packed FIFA17.exe and
|
||||
cannot be pinned from the (clean) server response alone.
|
||||
|
||||
## 9. Open questions
|
||||
1. What exactly raises *"The pack you've selected is currently not available"*? The
|
||||
loc key is unknown and the predicate is in the packed exe (unread). Resolving it
|
||||
needs a controlled field/flag experiment or live-memory RE (both currently gated).
|
||||
2. Does the store, with `unopenedPackIds == []`, land on / auto-select the inactive
|
||||
`mypacks` sentinel? (HYPOTHESIS §8.7; unproven without client-side observation.)
|
||||
3. Did the store render tiles successfully in earlier sessions when the profile
|
||||
owned unopened packs (e.g. the 21:54-21:57 pack-opening burst)? If so, the
|
||||
presence/absence of owned packs (sentinel) is implicated. (UNKNOWN — earlier logs
|
||||
truncate the body; not proven.)
|
||||
4. Does `purchaseLimit:0`/`purchaseCount:0` grey a tile? Existing RE lists this as an
|
||||
OPEN question; would need a controlled experiment. (UNKNOWN)
|
||||
5. Is bug 6c ("unknown tile") a stale symptom from before `STORE_DISPLAYGROUP` became
|
||||
the default `ON`? Under the current config no unknown tile reproduces.
|
||||
|
||||
---
|
||||
|
||||
## H3 — EMPTY MY-PACKS SENTINEL (HYPOTHESIS)
|
||||
|
||||
When the profile owns zero unopened packs (`unopenedPackIds == []`), OpenFUT emits
|
||||
synthetic **inactive** pack id **65534** in the `mypacks` display group
|
||||
(`store_catalog:3428-3446`). The FIFA 17 store may treat this object as a selectable
|
||||
pack whose availability predicate fails, producing *"The pack you've selected is
|
||||
currently not available"* and returning the user to the FUT Hub before any
|
||||
`/store/transaction`. **Status: HYPOTHESIS (untested).**
|
||||
|
||||
## 10. Resolution check (Phase 1) — OBSERVED
|
||||
|
||||
Read-only inspection of `.105` (FIFA pid 529227, not touched):
|
||||
- Desktop/monitor: **2560x1440** — DRM connectors `card1-DP-2` and `card1-HDMI-A-1`
|
||||
both `connected`, native mode 2560x1440; compositor KDE `kwin_wayland` (no gamescope).
|
||||
- FIFA render config: `…/Games/umu/fifa17/pfx/drive_c/users/steamuser/Documents/FIFA 17/settings/overrideAutodetect.lua`
|
||||
→ `ResolutionWidth = 1280`, `ResolutionHeight = 720`, `FullscreenEnabled = 0` (windowed).
|
||||
- Session: Wayland (`WAYLAND_DISPLAY=wayland-0`), FIFA via XWayland (`DISPLAY=:0`,
|
||||
`XAUTHORITY=/run/pressure-vessel/Xauthority` inside the game namespace).
|
||||
|
||||
**Is FIFA rendering above 1024x768? YES (1280x720).**
|
||||
**Resolution hypothesis eliminated for this reproduction.**
|
||||
|
||||
## 11. Sentinel 65534 provenance (Phase 3)
|
||||
|
||||
1. **Basis:** **OpenFUT INVENTION** (OBSERVED). `65534` (0xFFFE) appears nowhere in
|
||||
any EA capture or recon note — repo-wide it exists only in `utas_server.py`
|
||||
(`store_catalog:3435-3446`) and this evidence set. The author's comment
|
||||
(`:3428-3434`) states it is a workaround: "Retain an inactive zero-item sentinel so
|
||||
the [`mypacks`] destination resolves… Its id is deliberately absent from
|
||||
PACK_CATALOG." It is a compatibility guess, not captured behavior.
|
||||
2. **Known-good EA capture of EMPTY My Packs:** **UNKNOWN** — none found. All recon
|
||||
My-Packs analysis is client-side RE (`FUN_1800150d0` filters
|
||||
`displayGroup.value=="mypacks"`, `plan-2026-08-05-pack-opening.md:34-36,893-895`);
|
||||
no EA server response for an empty My Packs state is on record.
|
||||
3. **Known-good response with ≥1 unopened pack:** **UNKNOWN** for EA. OpenFUT's own
|
||||
seed grants reward pack id 70 (`_new_profile` `unopenedPackIds:[70]`,
|
||||
`fut_store.py:360`), but that is an OpenFUT synthetic grant, not an EA capture.
|
||||
4. **Evidence FIFA EXPECTS a sentinel/placeholder:** **NO / UNKNOWN.** Recon shows My
|
||||
Packs is a client-side filter over the ordinary catalogue; the "empty-category
|
||||
dialog over the wrong tab" concern behind the sentinel is the author's HYPOTHESIS,
|
||||
not decompiler-confirmed. No evidence FIFA requires a placeholder object.
|
||||
5. **Evidence for the `inactive` representation:** **UNKNOWN / HYPOTHESIS.** The claim
|
||||
"state != active keeps it out of the visible row list" (`:3432`) is an unverified
|
||||
author assumption; no RE shows `state:"inactive"` hides a pack from selection. If
|
||||
FIFA does NOT hide it, the sole `mypacks` entry is a selectable inactive pack —
|
||||
exactly the H3 failure mode.
|
||||
|
||||
## 12. Empty vs non-empty My Packs behavior (Phase 2) — OBSERVED (code) / captured
|
||||
|
||||
`store_catalog(h)` (`utas_server.py:3421-3447`):
|
||||
- Always emits the 4 non-`ownedOnly` catalogue packs (ids 1,5,6,7) via `_pack_body`.
|
||||
- For each id in `visible_unopened_packs()` (= `STORE.unopened_packs()` +
|
||||
`_OPENED_PACK_GRACE`) that resolves in `PACK_CATALOG`, appends `_pack_body(owned,
|
||||
idx, owned=True)`.
|
||||
- **Only when `unopened_packs()` is empty (`if not owned_ids`)** appends the inactive
|
||||
sentinel (`:3428-3446`).
|
||||
|
||||
Sentinel 65534 vs a normal active pack (Bronze, idx 0), field-by-field (from the
|
||||
captured body):
|
||||
|
||||
| field | sentinel 65534 | Bronze Pack (active) |
|
||||
|---|---|---|
|
||||
| id | 65534 | 1 |
|
||||
| assetId | 65534 | 1 |
|
||||
| packType | GOLD | BRONZE |
|
||||
| description | "" (empty) | "Bronze Pack" |
|
||||
| state | **inactive** | active |
|
||||
| saleType | promo | promo |
|
||||
| limitType | NONE | NONE |
|
||||
| quantity | 0 | 0 |
|
||||
| purchaseLimit | 0 | 0 |
|
||||
| purchaseCount | 0 | 0 |
|
||||
| isPremium | false | false |
|
||||
| sortPriority | 1 | 1 |
|
||||
| currencies | **ABSENT** (popped) | `[{coins,400,400}]` |
|
||||
| extPrice | **ABSENT** (popped) | `{mtx 4/4}` |
|
||||
| packContentInfo | all-zero quantities | bronze 5 / item 5 |
|
||||
| unopened | false | false |
|
||||
| displayGroup.value | **mypacks** | bronze |
|
||||
| displayGroup.priority | 1 | ABSENT |
|
||||
| displayGroupAssetId | ABSENT | ABSENT |
|
||||
|
||||
**What changes when `unopenedPackIds` is non-empty (e.g. `[70]`):** the sentinel is
|
||||
NOT emitted; instead pack 70 (Reward Special Players Pack, `ownedOnly`) appears via
|
||||
the owned branch of `_pack_body` (`:3335-3336`): `displayGroup={"value":"mypacks",
|
||||
"priority":idx}`, `state:"active"` (default), `unopened:true`, `currencies`/`extPrice`
|
||||
popped. i.e. the `mypacks` group would hold a genuine **active** owned pack instead of
|
||||
the inactive sentinel.
|
||||
|
||||
## 13. Proposed controlled experiments (Phase 5) — DESIGN ONLY, NOT EXECUTED
|
||||
|
||||
### Existing grant mechanism (Phase 4)
|
||||
- **Supported profile-only method: YES** — `Store.grant_unopened_pack(pack_id)`
|
||||
(`fut_store.py:635-643`): validates the id is in `PACK_CATALOG`, appends to
|
||||
`unopenedPackIds`, persists; reverts via `consume_unopened_pack` (`:623-633`).
|
||||
Modifies **only** profile state; cleanly reversible.
|
||||
- **BUT restart IS required to take effect.** `Store.load()` caches `self._p`
|
||||
(`:370-372`); **no route calls `grant_unopened_pack` or `select_account`**, and
|
||||
`select_account` only re-reads on a persona *change*. So an out-of-process grant or
|
||||
a raw profile-file edit writes disk but the **running server keeps serving its
|
||||
cached `unopenedPackIds`** until the process reloads. There is no SIGHUP/reload
|
||||
endpoint. Therefore any profile change needs a container restart to be observed.
|
||||
|
||||
### Experiment A — Non-empty My Packs (PREFERRED; least invasive)
|
||||
- **State change:** set the profile's `unopenedPackIds` to `[70]` (edit
|
||||
`…/state/accounts/33068179/fifa17_profile.json`, or call
|
||||
`STORE.grant_unopened_pack(70)`), **store code/config unchanged**.
|
||||
- **Restart required?** **YES** — profile cache (above). Profile-only; no code edit.
|
||||
- **Rollback:** set `unopenedPackIds` back to `[]` (or `consume_unopened_pack(70)`),
|
||||
restart. (Also restore `nextItemId`/coins only if a pack is actually opened — the
|
||||
grant alone touches only `unopenedPackIds`.)
|
||||
- **Expected `purchasegroup` difference:** sentinel 65534 GONE; instead one active
|
||||
pack id 70 in the `mypacks` group (`state:active`, `unopened:true`); hub/credits
|
||||
report `recoveredPacks:1`.
|
||||
- **Expected client observation:** if H3 is correct, the immediate *"pack not
|
||||
available"* dialog should NOT fire (or behavior changes) and My Packs should show a
|
||||
real pack. If the dialog still fires identically, H3 is weakened and the cause is
|
||||
elsewhere (packed-exe predicate / another field).
|
||||
|
||||
### Experiment B — Suppress the empty sentinel (only if A is inconclusive)
|
||||
- **Change:** in `store_catalog` (`:3428-3446`), when `unopened_packs()` is empty, do
|
||||
NOT append pack 65534 (emit no `mypacks` entry). **Code change ⇒ restart. NOT
|
||||
authorized.** Narrowest patch: guard/remove the `if not owned_ids:` sentinel block.
|
||||
- **Purpose:** distinguishes "the inactive sentinel is selected and fails" (A already
|
||||
tests the inverse) from "an absent `mypacks` group causes a different failure"
|
||||
(the original author's stated fear at `:3429-3431`).
|
||||
|
||||
### Experiment C — Alternate sentinel representation (design only)
|
||||
- If evidence later shows FIFA expects an empty `mypacks` group represented
|
||||
differently (e.g. present-but-not-a-pack, or `state` other than `inactive`), adjust
|
||||
the sentinel shape. **DESIGN ONLY; DO NOT IMPLEMENT.** No current evidence specifies
|
||||
the correct empty-group representation (see §11.4-11.5).
|
||||
|
||||
Note: both A and B require a restart (A for the profile cache, B for the code). A is
|
||||
strictly less invasive (profile-only, clean rollback, no code change) and is the
|
||||
preferred next experiment. Neither is authorized yet.
|
||||
|
||||
---
|
||||
|
||||
## 14. Experiment A — Non-empty My Packs (EXECUTED 2026-08-13) — OBSERVED
|
||||
|
||||
Authorized controlled test of H3: change ONLY the profile's `unopenedPackIds`
|
||||
(`[] → [70]`), restart the FUT backend once, capture a genuine FIFA store request,
|
||||
then roll back. No store code/config/flags/PACK_CATALOG/pack-70/sentinel-code
|
||||
changed; FIFA not modified/restarted; operator drove the client.
|
||||
|
||||
### 14.1 Baseline profile state
|
||||
- Path: `fifa17-recon/docker/state/accounts/33068179/fifa17_profile.json` (persona
|
||||
33068179/CAGE; proven live: `STORE.path` in-process = `/state/accounts/33068179/
|
||||
fifa17_profile.json`, coins 29876776 matching the live `/user/credits`).
|
||||
- `unopenedPackIds == []`. Original SHA-256
|
||||
`39bb3e833fa55287d8516815ba3a717b41c0f0c7a7c41d20503f3a55c65cc6e7`. Backup:
|
||||
`/tmp/fifa17_profile.33068179.ORIG.20260813T001228Z.json` (same hash).
|
||||
|
||||
### 14.2 State change
|
||||
- Narrow anchored edit of line 97070 only: ` "unopenedPackIds": [],` →
|
||||
` "unopenedPackIds": [70],`. Diff vs backup = exactly one line; semantic diff =
|
||||
only key `unopenedPackIds` (`[] → [70]`), all other 24 keys identical. Modified
|
||||
SHA-256 `2b5760baa265f320904de2d23fd6ab374733efe74cb0756c3be39c083bce4ac8`.
|
||||
(Used the direct edit rather than `grant_unopened_pack(70)` to avoid whole-file
|
||||
reserialization; net semantic effect is identical.)
|
||||
|
||||
### 14.3 Restart
|
||||
- `docker restart openfut-fut-backend` (Pid 1398009→1548312, StartedAt
|
||||
2026-08-12T16:40:52Z → 2026-08-13T00:13:54Z). Bridge/Core and Rust hosts untouched.
|
||||
This container bundles blaze/roster/utas/pow (per `entrypoint.sh`); all rebound.
|
||||
- Post-restart in-process check: `STORE.load()['unopenedPackIds'] == [70]`;
|
||||
`store_catalog(None)` → pack 70 present, sentinel 65534 absent.
|
||||
|
||||
### 14.4 Genuine FIFA capture
|
||||
- Marker `2026-08-13T00:14:24Z`. Single request after it (unambiguous):
|
||||
`00:14:58 GET /ut/game/fifa17/store/purchasegroup/all?ppInfo=true → 200`.
|
||||
**No `/store/transaction`, no `/purchased/items`** in the window (pack 70 not opened).
|
||||
- Full body recovered from the running code over the live [70] profile; its
|
||||
`[:200]` matches the genuine logged 200-byte prefix byte-for-byte (verified MATCH).
|
||||
Preserved at `docs/evidence/store_purchasegroup_capture_mypacks70_2026-08-12.json`.
|
||||
|
||||
### 14.5 Client-observed behavior (operator report)
|
||||
1. Store remains open: **YES**.
|
||||
2. "The pack you've selected is currently not available": **NO (gone)**.
|
||||
3. My Packs category / unopened reward pack visible: **YES**.
|
||||
4. Returned to FUT Hub: yes (normal navigation; not forced by an error dialog).
|
||||
|
||||
### 14.6 Response diff (baseline 2026-08-12 vs experiment)
|
||||
Only difference across all 5 entries:
|
||||
- **Removed:** id `65534` (`state:inactive`, `displayGroup:mypacks`, `description:""`).
|
||||
- **Added:** id `70` (`state:active`, `displayGroup:mypacks`,
|
||||
`description:"Reward Special Players Pack"`, `unopened:true`).
|
||||
- Packs 1/5/6/7 byte-identical. Classification: **all EXPECTED FROM UNOPENED PACK
|
||||
STATE; nothing UNEXPECTED.**
|
||||
|
||||
### 14.7 H3 assessment — **SUPPORTED**
|
||||
65534 disappeared AND pack 70 replaced it as a real My Packs entry AND the
|
||||
"pack not available" / store-exit behavior disappeared → per the pre-registered
|
||||
criterion, **H3 is strongly SUPPORTED**. The failure is tied to the My Packs group
|
||||
content when the profile owns zero unopened packs.
|
||||
|
||||
Sub-hypothesis resolution:
|
||||
- **H3c (failure unrelated to My Packs): RULED OUT.** A My-Packs-only profile change
|
||||
(no store code/config change) eliminated the failure.
|
||||
- **H3a (the inactive sentinel object itself is the trigger) vs H3b (empty My Packs
|
||||
state generally is the trigger): NOT DISTINGUISHED by Experiment A.** The change
|
||||
simultaneously (i) removed the inactive sentinel and (ii) supplied a real active
|
||||
owned pack. Either "presence of the inactive/empty sentinel" or "absence of any
|
||||
real owned pack" could be the cause. Distinguishing them requires Experiment B
|
||||
(empty `unopenedPackIds` AND suppress the sentinel so `mypacks` has no entry): if
|
||||
that also fixes it → H3a (sentinel object was the problem); if it re-breaks or
|
||||
changes → H3b (empty My Packs itself is the problem). Experiment B is a code change
|
||||
(restart-gated) and remains unauthorized.
|
||||
|
||||
### 14.8 Rollback verification
|
||||
- Profile restored from backup → SHA-256 `39bb3e83…` == original (byte-identical);
|
||||
`unopenedPackIds == []`. Disk was unmutated during the test (still `2b5760ba…`
|
||||
before rollback → store reads don't persist; pack 70 never opened).
|
||||
- `docker restart openfut-fut-backend` (Pid 1549503, StartedAt 2026-08-13T00:16:56Z).
|
||||
Post-restart in-process: `unopenedPackIds == []`, sentinel 65534 present again,
|
||||
pack 70 absent → runtime baseline restored. Bridge/Core untouched.
|
||||
|
||||
**H3 status: SUPPORTED (H3c ruled out; H3a vs H3b open).** No permanent fix
|
||||
implemented.
|
||||
|
||||
---
|
||||
|
||||
## 15. Experiment B — Empty My Packs Without Sentinel (EXECUTED 2026-08-13) — OBSERVED
|
||||
|
||||
### 15.1 Purpose
|
||||
Distinguish **H3a** (the synthetic inactive sentinel 65534 itself is the trigger)
|
||||
from **H3b** (FIFA cannot tolerate an empty My Packs state even without a sentinel).
|
||||
Hold `unopenedPackIds == []` constant; change ONLY: sentinel 65534 emitted →
|
||||
suppressed. Authorized TEMPORARY code change, reverted after test.
|
||||
|
||||
### 15.2 Baseline
|
||||
Profile `unopenedPackIds == []` (SHA-256 `39bb3e83…`, unchanged throughout). Running
|
||||
code before patch = `c89d43ea…` (host repo == container copy). Sentinel 65534 emitted.
|
||||
|
||||
### 15.3 Temporary patch — **TEMPORARY EXPERIMENT B PATCH, NOT A PERMANENT FIX**
|
||||
Applied to the **container** copy `/app/tools/utas_server.py` only (the container
|
||||
mounts `/state`, not `/app`; host repo `fifa17-recon/tools/utas_server.py` was NOT
|
||||
edited — its git diff stayed empty). Single line, `store_catalog` (line 3428):
|
||||
```
|
||||
- if not owned_ids:
|
||||
+ if False: # TEMP EXPERIMENT B PATCH -- suppress synthetic sentinel 65534 (NOT A PERMANENT FIX)
|
||||
```
|
||||
Semantic effect: when `unopened_packs()` is empty, append nothing (no sentinel, no
|
||||
replacement object). Normal packs 1/5/6/7 (appended earlier) unchanged. Diff vs the
|
||||
backed-up original = exactly this one line. Patched code SHA-256 `5bb8fca9…`.
|
||||
|
||||
### 15.4 Restart verification
|
||||
`docker restart openfut-fut-backend` (Pid 1549503→1551026, StartedAt
|
||||
2026-08-13T00:20:45Z). The writable-layer edit survived the restart; running
|
||||
`/app/tools/utas_server.py` = `5bb8fca9…` (patched). In-process: `unopenedPackIds ==
|
||||
[]`; `store_catalog` → 4 packs {1,5,6,7}, **no 65534, no 70, no `mypacks` entry**.
|
||||
Flags unchanged (`DISPLAYGROUP=ON`, `GROUPID=OFF`). Bridge/Core/Rust untouched.
|
||||
|
||||
### 15.5 Genuine FIFA capture
|
||||
Marker `2026-08-13T00:20:55Z`. Request sequence (operator opened the store):
|
||||
`00:21:05 GET /hub` → `00:21:07 GET /user/credits` → `00:21:07 GET
|
||||
/store/purchasegroup/all?ppInfo=true → 200`. **No `/store/transaction`; no further
|
||||
requests** (client crashed after receiving the store body). Full body recovered from
|
||||
the running patched code; `[:200]` matches the genuine logged prefix byte-for-byte
|
||||
(verified MATCH). Preserved at
|
||||
`docs/evidence/store_purchasegroup_capture_empty_no_sentinel_2026-08-12.json`
|
||||
(4 packs {1,5,6,7}, no `mypacks` group).
|
||||
|
||||
### 15.6 Client behavior (operator report)
|
||||
**The game CRASHED** on opening the store. Not the baseline dialog; a hard crash. No
|
||||
`/store/transaction` was issued.
|
||||
|
||||
### 15.7 Three-way response comparison
|
||||
| capture | ids present | `mypacks` group entry | client outcome |
|
||||
|---|---|---|---|
|
||||
| Baseline (`…_2026-08-12.json`) | 1,5,6,7,**65534** | 65534 `inactive`, desc "" | "pack not available" dialog → Hub |
|
||||
| Exp A (`…_mypacks70_…json`) | 1,5,6,7,**70** | 70 `active`, "Reward Special Players Pack" | **works** — store open, My Packs visible |
|
||||
| Exp B (`…_empty_no_sentinel_…json`) | 1,5,6,7 | **none** | **CRASH** |
|
||||
Normal packs {1,5,6,7} identical across all three.
|
||||
|
||||
### 15.8 H3a / H3b verdict
|
||||
- **H3a (sentinel object itself is the trigger): CONTRADICTED.** Removing the
|
||||
sentinel did NOT restore the store; it produced a *worse* outcome (crash). If the
|
||||
sentinel object were the sole cause, its removal would yield a working store (it
|
||||
did not).
|
||||
- **H3b (FIFA cannot tolerate an empty My Packs state): SUPPORTED.** Only Exp A — a
|
||||
real **active** owned pack in `mypacks` — worked. Both the inactive sentinel
|
||||
(graceful "pack not available" dialog) and the total absence of any `mypacks` entry
|
||||
(crash) fail. The sentinel is a **load-bearing workaround** that *downgrades* the
|
||||
failure from a crash to a dialog but does not fix it.
|
||||
- **Pre-registered-rule nuance:** Exp B produced a *distinct* failure (crash), which
|
||||
the pre-registered rules classify as **B3 (different failure)** rather than the
|
||||
exact B2 dialog. Documented as such: the crash is a THIRD failure mode. It still
|
||||
resolves the question — it rules out H3a and supports H3b — but the specific
|
||||
outcome (crash, not the same dialog) is stronger than B2 anticipated. Not forced
|
||||
into a clean binary beyond what the evidence shows.
|
||||
|
||||
**Does FIFA tolerate an empty My Packs without the sentinel? NO — it crashes.**
|
||||
|
||||
### 15.9 Rollback verification
|
||||
- Container `/app/tools/utas_server.py` restored from backup → SHA-256 `c89d43ea…`
|
||||
== pre-experiment (byte-identical); the `if False:` patch fully removed.
|
||||
- `docker restart openfut-fut-backend` (final Pid 1551901,
|
||||
StartedAt 2026-08-13T00:22:04Z). In-process: `unopenedPackIds == []`, sentinel
|
||||
65534 emitted again, pack 70 absent; `DISPLAYGROUP=ON`, `GROUPID=OFF`.
|
||||
- Host repo `fifa17-recon/tools/utas_server.py` never edited (git diff empty, SHA-256
|
||||
`c89d43ea…`). Profile unchanged (`39bb3e83…`). Bridge/Core/Rust untouched.
|
||||
|
||||
### 15.10 Likely permanent fix (REPORT ONLY — not implemented)
|
||||
Evidence: the store's `mypacks` group must contain a **valid, active, openable owned
|
||||
pack**; both an inactive sentinel and an absent group fail (dialog / crash). The only
|
||||
working configuration observed is a genuine active owned pack (Exp A). Candidate
|
||||
directions (report only, each needs design + authorization):
|
||||
1. Ensure the profile always owns ≥1 legitimate active unopened pack while the store
|
||||
is shown (e.g. keep a real reward pack such as id 70 granted), so `mypacks` is
|
||||
never empty — this matches the only known-working state but changes economy state
|
||||
and needs a lifecycle policy (what happens after the user opens it).
|
||||
2. Change what `store_catalog` advertises so FIFA never lands on / requires a
|
||||
`mypacks` group when there are zero owned packs (client-compatible empty-store
|
||||
representation) — the correct representation is UNKNOWN; neither current option
|
||||
(inactive sentinel / no group) is it, so this needs new client-side RE before
|
||||
implementation.
|
||||
Recommendation: do NOT simply delete the sentinel (Exp B proves that crashes). No fix
|
||||
implemented.
|
||||
|
||||
**H3 status: SUPPORTED. H3a CONTRADICTED, H3b SUPPORTED (Exp B crash = third failure
|
||||
mode; empty My Packs is the root problem). Sentinel is a load-bearing workaround.**
|
||||
|
||||
---
|
||||
|
||||
## 16. Experiment C′ — Active Non-Openable Placeholder (EXECUTED 2026-08-13) — OBSERVED
|
||||
|
||||
Question: can the required `mypacks` group be kept structurally valid with an
|
||||
**active** placeholder that stays impossible to open/purchase? Change exactly one
|
||||
field of sentinel 65534: `state "inactive" → "active"`. Profile untouched
|
||||
(`unopenedPackIds==[]`); 65534 kept absent from `PACK_CATALOG`.
|
||||
|
||||
### 16.1 Server-side safety proof (OBSERVED, code)
|
||||
65534 cannot grant value regardless of `state` — pack resolution is by
|
||||
`pack_by_id(id)` over `PACK_CATALOG` (ids 1,5,6,7,70), independent of the display
|
||||
`state`:
|
||||
- `store_buy` (PUT `/store/transaction`, `:3460-3465`): `pack_by_id(65534)=None` →
|
||||
`if not pack: return 200, {}` (no `open_pack`, no coin change).
|
||||
- `purchased_items` (POST, `:3494-3496`): `pack_by_id(65534)=None` →
|
||||
`return 200, {"itemData": STORE.last_pack()}` (stale prior items only; no new
|
||||
grant, no `open_pack`, no `consume_unopened_pack`).
|
||||
- `open_pack`/`consume_unopened_pack` are unreachable for 65534 (pack resolves to
|
||||
None first). Precondition PASSED.
|
||||
|
||||
### 16.2 Baseline / patch
|
||||
Baseline: profile `39bb3e83…`, code `c89d43ea…` (host==container), sentinel
|
||||
`inactive`/`mypacks`, 65534∉catalog, flags `DISPLAYGROUP=ON`/`GROUPID=OFF`.
|
||||
Temporary container-only patch (host repo untouched), line 3444:
|
||||
`empty["state"] = "inactive"` → `empty["state"] = "active"`. Diff vs original = this
|
||||
one line; patched code `e1a4e1dc…`. **TEMPORARY EXPERIMENT C′ PATCH — NOT A PERMANENT
|
||||
FIX.**
|
||||
|
||||
### 16.3 Restart / runtime
|
||||
`docker restart openfut-fut-backend` (Pid 1556305, StartedAt 00:38:51Z). Running code
|
||||
`e1a4e1dc…`; `unopenedPackIds==[]`; sentinel `65534 state=active unopened=False
|
||||
dg=mypacks desc=""`; 65534∉catalog; normal packs 1/5/6/7 active; 70 absent; flags
|
||||
unchanged.
|
||||
|
||||
### 16.4 Genuine FIFA capture
|
||||
Marker `2026-08-13T00:38:53Z`. FIFA relaunched (Exp-B crash had closed it) → booted to
|
||||
hub. Three genuine store fetches: `00:39:44`, `00:40:26`, `00:41:23`
|
||||
(`GET /store/purchasegroup/all?ppInfo=true → 200`), reconstructed body prefix-matches
|
||||
the logged 200-byte prefix (verified). Saved
|
||||
`docs/evidence/store_purchasegroup_capture_active_placeholder_2026-08-12.json`.
|
||||
C′-vs-baseline full JSON diff = **only** `65534.state: "inactive" → "active"`.
|
||||
|
||||
### 16.5 UI observation (operator report)
|
||||
1. **No crash** (game launched to hub).
|
||||
2. **No "pack not available" dialog.**
|
||||
3. Store remains open.
|
||||
4. My Packs tab **not shown while inside the Store (Browse Packs)**.
|
||||
5. Via the FUT-hub **My Packs** menu: **one pack tile with no cover, "0 items, 0
|
||||
bronze, 0 rares"** (the placeholder renders as a visible empty pack).
|
||||
6. Navigation: from the hub **My Packs** menu → Bronze/Gold/Special reachable; but
|
||||
from the **Browse Packs** (Store) entry, Bronze/Gold/Special are **not reachable
|
||||
until My Packs is opened first**.
|
||||
|
||||
### 16.6 Passive request sequence (OBSERVED)
|
||||
Boot: `.../accountinfo → /ut/auth → settings → phishing → match/reset → userMassInfo
|
||||
→ PUT store/transaction/0 → hub …`. The single `/store/transaction` is the routine
|
||||
**boot** call with body `{"state":"TRANSACTIONCANCEL"}` → `200 {}` (no packId), fired
|
||||
at 00:39:39 **before** any store fetch. Across all three store opens: **no
|
||||
`/store/transaction`, no `/purchased`, and no request referencing 65534.** The active
|
||||
placeholder did NOT cause FIFA to auto-submit any transaction/open.
|
||||
|
||||
### 16.7 Availability result / verdict
|
||||
**Result C1 (strong positive) — ACTIVE PLACEHOLDER HYPOTHESIS SUPPORTED, with UX
|
||||
caveats.** `state` participates materially: with `state:"active"` the group exists
|
||||
(no crash, as in baseline) AND the availability path is satisfied (no
|
||||
"pack not available" dialog, unlike baseline). So **C2 is refuted** — `state` is a
|
||||
deciding field for the dialog. But it is **not a clean permanent fix**:
|
||||
- the placeholder renders as a **visible empty pack tile** ("0 items"), i.e. a fake
|
||||
pack a user could try to open (server-safe: opening → no-op `{}` / stale
|
||||
`last_pack`, but confusing UX);
|
||||
- **navigation caveat #6**: from Browse Packs the other categories are gated behind
|
||||
opening My Packs first — an UNEXPECTED behavior not present with a genuine owned
|
||||
pack (Exp A).
|
||||
|
||||
### 16.8 Rollback verification
|
||||
Container code restored from backup → `c89d43ea…` (== host, == pre-experiment); the
|
||||
`state` change removed. `docker restart` (Pid 1557831, StartedAt 00:43:04Z).
|
||||
In-process: `unopenedPackIds==[]`, sentinel `state=inactive`, 65534∉catalog, 70
|
||||
absent, flags `DISPLAYGROUP=ON`/`GROUPID=OFF`. Host repo `utas_server.py` never edited
|
||||
(`c89d43ea…`, git diff empty). Profile `39bb3e83…` unchanged. Bridge/Core untouched.
|
||||
|
||||
### 16.9 Implications for the client contract
|
||||
`state:"active"` satisfies the pack-availability predicate (no dialog) while the
|
||||
group's existence prevents the crash — so an active non-openable placeholder is the
|
||||
first representation that neither crashes nor shows the dialog. However it exposes a
|
||||
**visible empty "pack"** and a **Browse-Packs navigation gate** (#5/#6), so it is NOT
|
||||
adopted. **Permanent fix NOT established.** Open follow-ups: (a) what happens if the
|
||||
user explicitly selects/opens the active placeholder (a later controlled test —
|
||||
server-safe per §16.1 but UX-unknown); (b) whether a count-gated My-Packs default or a
|
||||
representation that avoids rendering a fake tile can remove the empty-tile/navigation
|
||||
artifacts. Do NOT adopt `state:"active"` as the fix on this evidence alone.
|
||||
|
||||
---
|
||||
|
||||
## 17. Explicit Active-Placeholder Selection Test (EXECUTED 2026-08-13) — OBSERVED
|
||||
|
||||
**Purpose:** with the C′ active placeholder in place, characterize what happens when
|
||||
the user *explicitly opens* the empty 65534 My-Packs tile (the last open backend-side
|
||||
question).
|
||||
|
||||
**Server safety proof (re-confirmed, code `c89d43ea`):** `pack_by_id(65534)=None`;
|
||||
65534∉PACK_CATALOG∉unopenedPackIds. `store_buy`→`200 {}`; `purchased_items`→
|
||||
`200 {"itemData": last_pack}` (stale). No inventory/coin/profile mutation possible.
|
||||
|
||||
**Temporary C′ state:** container-only one-line patch `65534.state "inactive"→"active"`
|
||||
(patched `e1a4e1dc…`), restart (Pid 1560774). `unopenedPackIds=[]`, 65534
|
||||
active/mypacks/∉catalog, normal packs unchanged, flags ON/OFF, host code + profile
|
||||
unchanged. Marker `2026-08-13T00:53:09Z`.
|
||||
|
||||
**Manual selection behavior (operator report):** opened FUT → My Packs → the empty
|
||||
placeholder tile visible → selected/opened it ONCE:
|
||||
1. Dialog: **YES**. 2. Exact text: **"This pack is no longer available"**.
|
||||
3. Stays in My Packs: yes. 4. After closing the dialog → returns to My Packs.
|
||||
5. Then navigates back to the FUT Hub successfully. 6. **No crash.** 7. No spinner.
|
||||
8. **Navigation remains fully usable afterward.**
|
||||
|
||||
**Genuine request sequence (OBSERVED, marker `00:53:09Z`):** boot (`…/auth →
|
||||
userMassInfo → PUT store/transaction/0 {"state":"TRANSACTIONCANCEL"}→200 {} → hub →
|
||||
credits → purchasegroup`) then navigation (`hub→credits→purchasegroup` ×2 for the
|
||||
store/My-Packs views). **The explicit tile selection generated NO server request** —
|
||||
no `/store/transaction`, no `/purchased/items`, and NO reference to 65534 anywhere.
|
||||
The "no longer available" verdict is rendered **client-side**.
|
||||
|
||||
**Result class: S1 — pure client-side rejection.**
|
||||
|
||||
**Post-test profile/economy integrity (OBSERVED):** coins 29876776, nextItemId
|
||||
100004837, items 1995, purchased 0, `unopenedPackIds` `[]`, `last_pack` empty — ALL
|
||||
unchanged vs pre-test; 65534 not persisted in items or unopenedPackIds; profile
|
||||
SHA-256 `39bb3e83…` byte-identical. **Zero mutation.**
|
||||
|
||||
**UX assessment:** crash-safe ✓, economy-safe ✓ (no request even sent), navigation
|
||||
recoverable ✓. Blemishes: a **visible empty "0 items" tile**, a **"This pack is no
|
||||
longer available" dialog on explicit click**, and (from §16.5) the **Browse-Packs
|
||||
navigation gate** (must open My Packs first). Notably this is a *strict improvement*
|
||||
over the inactive-sentinel baseline, which throws "pack not available" immediately on
|
||||
STORE OPEN and bounces to the Hub; the active placeholder only errors if the user
|
||||
deliberately clicks the empty tile, and recovers cleanly.
|
||||
|
||||
**Active-placeholder verdict: MARGINALLY ACCEPTABLE.** Safe (crash + economy) and
|
||||
usable, but visibly imperfect (fake tile + click-dialog + browse nav gate). Not
|
||||
UNACCEPTABLE (no crash/economy risk, recoverable); not fully ACCEPTABLE (user-visible
|
||||
defects).
|
||||
|
||||
**Permanent-fix decision: P2.** The active sentinel technically works and is safe, but
|
||||
its UX is poor and — per Candidate F (CONTRADICTED) — **no backend-only *clean*
|
||||
solution exists** (the store's My-Packs resolution is Scaleform/movie-driven, not
|
||||
server-gated). Recommendation: keep the active placeholder as an optional/temporary
|
||||
backend compatibility mode (strictly better than the current inactive-sentinel
|
||||
baseline) and pursue a **client-side** fix for a fully clean zero-pack experience
|
||||
(hiding the fake tile / suppressing the forced My-Packs resolution). NOT implemented.
|
||||
|
||||
**Rollback verification:** container code restored to `c89d43ea…` (== host, ==
|
||||
pre-experiment), sentinel back to `inactive`; `docker restart` (Pid 1562665, StartedAt
|
||||
00:59:04Z); `unopenedPackIds=[]`, 65534 inactive/∉catalog, 70 absent, flags ON/OFF;
|
||||
host `utas_server.py` never edited; profile `39bb3e83…` unchanged. Bridge/Core
|
||||
untouched.
|
||||
|
||||
@@ -1,44 +0,0 @@
|
||||
# FIFA 17 card-table provenance manifest
|
||||
# Source (authoritative): 10.10.0.105:/home/alex/Documents/OpenFUT/fifa17-recon/data/tables/
|
||||
# Dest (this repo): fifa17-recon/data/tables/
|
||||
# Verified 2026-08-12: source and dest byte-identical (sha256), order-independent.
|
||||
# Combined hash-of-hashes: 10f239add919089354d8dbff873fc9737b0a0f80f6ac41b1aa2a096c0ec8d331
|
||||
# 31 fcc_*.json + 5 staff tables = 36 files. Files are DECODED tables:
|
||||
# each carries {table, source, rowcount, schema[], rows[]}; card instances live in rows[].
|
||||
#
|
||||
0d1c9af7ae654c3e4363f18bb89bad03a0631056d36425c84b9a680fa989618c fcc_managerbonusvalues.json
|
||||
0e5d5309cd1d9322476f8047fc6eaf4a88f4f19211b8ea01fe4d28ddd3733134 fcc_healingcards.json
|
||||
1da80e390169ebb8ee8a6543e14b1191d9151f675797f01e23628f6c24d434c5 fcc_misccards.json
|
||||
2212b0ee8d962f0fb6bd346bee35fff6566e22539e397cc2e42bb6efd4dc3ad3 fcc_textposvalues_hd.json
|
||||
2a8e22ddb000b2c08f1a3e5eb47bc56ecf43f733ce6e7519498d332e4f439746 headcoachcards.json
|
||||
3a323e1c0688a4068ccd21be0c9d8e88a875ab10ce2158d3aed79fc14e65f0fb fcc_chemlinkcalc.json
|
||||
4a60bc4c0d8cb8d2b903e152a3dd5302348753568630818fde059b2de41f82ab fcc_leaguelogos.json
|
||||
5304114078200da4564d33612c955598f12a44bdf52f18274184b98922229b8b fcc_GrandStandPlayers.json
|
||||
5503291e381fee5008120615cd6d30a732b97636d4694a88f943eb14cb992741 fcc_leaguelogostickers.json
|
||||
550739c124ca915fb294954afe3d9d04fb7d1faf2b0c96930b2dcdb1bfe7ac8f fcc_formationcardspositions_kc.json
|
||||
5a5aabec1d40ffa21b8effb84f79e4b788cb42352aa592d71d95eba1db0d209e fcc_trainingcards.json
|
||||
6476e396f166905857d2ada4f12cc37645ca42efdca121e8e74270fbf7422336 managercards.json
|
||||
6546f602024973e20d04522a857c6c243473a177cab5b3be8400390651a42fab fcc_navcoords_hd.json
|
||||
6b0209647383e4e940d2af2c3bbb2185a4aac7ac0e799fe6b50ae52e7625710d fcc_contractcards.json
|
||||
6c52c83aafd9d9d3406e21c656762ac5cc0ba4522002f424e5593430bc5190f5 physiocards.json
|
||||
765687d7f1e5c6c989adf45b174a0fdab0f65597c83132304b53b9f859c02586 fcc_stadium.json
|
||||
79e50b07eecc47a0edf4d2a87782e904785e653937698cc712258a82fdf8b079 fcc_formationcardspositions_hd.json
|
||||
7d36e0fbb9349eabd4267215bacbe29d78ff621deeb8cab3380dcac72c535eb9 fcc_preferredformationcalcmid.json
|
||||
8122a4070901662fac97f675a3e4194dd5fd7e02194fdab204989af42676e268 fitnesscoachcards.json
|
||||
828f8b90241672b9f62a9bbd3cb219a1d3bd8856bd160cc46284f2958e08f7d4 fcc_discardcoins.json
|
||||
852bb82ed373881373d8610e6f4f2ca4406bac13da4bda9d6abba693d7cafc56 fcc_myclubscategories.json
|
||||
974dcbbe6a46c02dc97c77df6c270c9a7f09ba23bee23005ecf95fd114ee66a7 gkcoachcards.json
|
||||
9aa4b3b3f226202b21d2e9f96a1508ecce56abba64372099e090df101fce5eeb fcc_nationcalc.json
|
||||
9b6797991520c05f7448b28e66d160f96afc73eefd661ed8272b0a093b6ba89f fcc_kitcards.json
|
||||
9e8e6595fa8d3bcf963eb25bd9f9ea5d131aa92ed0e7e4ae3089adf5e1d55927 fcc_preferredformationcalcst.json
|
||||
a4e8ac2ba0a6db45f1f59fe384fbd39a8cee8fb72a72f846e52daca44f1c7ff9 fcc_myclubs.json
|
||||
bbf405e3a63b6fd03da1237b8b118764c57a40c797faf85d1e4691a1c95a840e fcc_balls.json
|
||||
ca1184bd85cff3308af0104077feda4357ef483fae6335fa964922eea4e94330 fcc_navcoords_kc.json
|
||||
ca3e4ab0f7892aac7473b774de4699c067c54647ca4a82cdd5fd1108c56ed894 fcc_badgecards.json
|
||||
ccdda8ad0a15f73a056fa336abde8739b346d12b78cb8adbea0f0677487bb598 fcc_preferredpositioncalc.json
|
||||
dbf95bddd456137e4b90a44bdd1f637458f4846ecd5c3ba6747d3f069c3f590f fcc_textposvalues_kc.json
|
||||
dd8c2c860b18d999877c37e0f63dac64ef7bb57bff5a2173960cde71242f9a34 fcc_bonusvalues.json
|
||||
df5b997b153941a5bb760ad5bb0fb23dc16cf8612b300559be23ac929b55eec6 fcc_leagues.json
|
||||
e4619db324a7848639a8ba53f513cf3ea153eeaf698de05d71e56c319b3cc424 fcc_coinrewards.json
|
||||
e6b1ca3ecb7c3923d77e73bda2e6c3f9794b9158354d566112f7979b33b4422c fcc_preferredformationcalcgk.json
|
||||
f54814d61b72dd2b6186e9e414df4fbfbdbea1732da6a4622f001a1ff03bc12a fcc_preferredformationcalcback.json
|
||||
@@ -1,199 +0,0 @@
|
||||
{
|
||||
"purchase": [
|
||||
{
|
||||
"assetId": 1,
|
||||
"id": 1,
|
||||
"packType": "BRONZE",
|
||||
"description": "Bronze Pack",
|
||||
"state": "active",
|
||||
"saleType": "promo",
|
||||
"limitType": "NONE",
|
||||
"quantity": 0,
|
||||
"purchaseLimit": 0,
|
||||
"purchaseCount": 0,
|
||||
"isPremium": false,
|
||||
"sortPriority": 1,
|
||||
"currencies": [
|
||||
{
|
||||
"name": "coins",
|
||||
"funds": 400,
|
||||
"finalFunds": 400
|
||||
}
|
||||
],
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 4,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 4,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 5,
|
||||
"silverQuantity": 0,
|
||||
"goldQuantity": 0,
|
||||
"rareQuantity": 0,
|
||||
"itemQuantity": 5
|
||||
},
|
||||
"unopened": false,
|
||||
"displayGroup": {
|
||||
"value": "bronze"
|
||||
}
|
||||
},
|
||||
{
|
||||
"assetId": 5,
|
||||
"id": 5,
|
||||
"packType": "GOLD",
|
||||
"description": "Gold Pack",
|
||||
"state": "active",
|
||||
"saleType": "promo",
|
||||
"limitType": "NONE",
|
||||
"quantity": 0,
|
||||
"purchaseLimit": 0,
|
||||
"purchaseCount": 0,
|
||||
"isPremium": false,
|
||||
"sortPriority": 2,
|
||||
"currencies": [
|
||||
{
|
||||
"name": "coins",
|
||||
"funds": 5000,
|
||||
"finalFunds": 5000
|
||||
}
|
||||
],
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 50,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 50,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"silverQuantity": 0,
|
||||
"goldQuantity": 7,
|
||||
"rareQuantity": 7,
|
||||
"itemQuantity": 7
|
||||
},
|
||||
"unopened": false,
|
||||
"displayGroup": {
|
||||
"value": "gold"
|
||||
}
|
||||
},
|
||||
{
|
||||
"assetId": 6,
|
||||
"id": 6,
|
||||
"packType": "GOLD",
|
||||
"description": "Premium Gold",
|
||||
"state": "active",
|
||||
"saleType": "promo",
|
||||
"limitType": "NONE",
|
||||
"quantity": 0,
|
||||
"purchaseLimit": 0,
|
||||
"purchaseCount": 0,
|
||||
"isPremium": false,
|
||||
"sortPriority": 3,
|
||||
"currencies": [
|
||||
{
|
||||
"name": "coins",
|
||||
"funds": 15000,
|
||||
"finalFunds": 15000
|
||||
}
|
||||
],
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 150,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 150,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"silverQuantity": 0,
|
||||
"goldQuantity": 11,
|
||||
"rareQuantity": 11,
|
||||
"itemQuantity": 11
|
||||
},
|
||||
"unopened": false,
|
||||
"displayGroup": {
|
||||
"value": "gold"
|
||||
}
|
||||
},
|
||||
{
|
||||
"assetId": 7,
|
||||
"id": 7,
|
||||
"packType": "GOLD",
|
||||
"description": "Special Players Pack",
|
||||
"state": "active",
|
||||
"saleType": "promo",
|
||||
"limitType": "NONE",
|
||||
"quantity": 0,
|
||||
"purchaseLimit": 0,
|
||||
"purchaseCount": 0,
|
||||
"isPremium": false,
|
||||
"sortPriority": 4,
|
||||
"currencies": [
|
||||
{
|
||||
"name": "coins",
|
||||
"funds": 25000,
|
||||
"finalFunds": 25000
|
||||
}
|
||||
],
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 250,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 250,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"silverQuantity": 0,
|
||||
"goldQuantity": 11,
|
||||
"rareQuantity": 11,
|
||||
"itemQuantity": 11
|
||||
},
|
||||
"unopened": false,
|
||||
"displayGroup": {
|
||||
"value": "special"
|
||||
}
|
||||
},
|
||||
{
|
||||
"assetId": 65534,
|
||||
"id": 65534,
|
||||
"packType": "GOLD",
|
||||
"description": "",
|
||||
"state": "inactive",
|
||||
"saleType": "promo",
|
||||
"limitType": "NONE",
|
||||
"quantity": 0,
|
||||
"purchaseLimit": 0,
|
||||
"purchaseCount": 0,
|
||||
"isPremium": false,
|
||||
"sortPriority": 1,
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"silverQuantity": 0,
|
||||
"goldQuantity": 0,
|
||||
"rareQuantity": 0,
|
||||
"itemQuantity": 0
|
||||
},
|
||||
"unopened": false,
|
||||
"displayGroup": {
|
||||
"value": "mypacks",
|
||||
"priority": 1
|
||||
}
|
||||
}
|
||||
],
|
||||
"timestamp": 1596326400
|
||||
}
|
||||
@@ -1,199 +0,0 @@
|
||||
{
|
||||
"purchase": [
|
||||
{
|
||||
"assetId": 1,
|
||||
"id": 1,
|
||||
"packType": "BRONZE",
|
||||
"description": "Bronze Pack",
|
||||
"state": "active",
|
||||
"saleType": "promo",
|
||||
"limitType": "NONE",
|
||||
"quantity": 0,
|
||||
"purchaseLimit": 0,
|
||||
"purchaseCount": 0,
|
||||
"isPremium": false,
|
||||
"sortPriority": 1,
|
||||
"currencies": [
|
||||
{
|
||||
"name": "coins",
|
||||
"funds": 400,
|
||||
"finalFunds": 400
|
||||
}
|
||||
],
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 4,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 4,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 5,
|
||||
"silverQuantity": 0,
|
||||
"goldQuantity": 0,
|
||||
"rareQuantity": 0,
|
||||
"itemQuantity": 5
|
||||
},
|
||||
"unopened": false,
|
||||
"displayGroup": {
|
||||
"value": "bronze"
|
||||
}
|
||||
},
|
||||
{
|
||||
"assetId": 5,
|
||||
"id": 5,
|
||||
"packType": "GOLD",
|
||||
"description": "Gold Pack",
|
||||
"state": "active",
|
||||
"saleType": "promo",
|
||||
"limitType": "NONE",
|
||||
"quantity": 0,
|
||||
"purchaseLimit": 0,
|
||||
"purchaseCount": 0,
|
||||
"isPremium": false,
|
||||
"sortPriority": 2,
|
||||
"currencies": [
|
||||
{
|
||||
"name": "coins",
|
||||
"funds": 5000,
|
||||
"finalFunds": 5000
|
||||
}
|
||||
],
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 50,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 50,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"silverQuantity": 0,
|
||||
"goldQuantity": 7,
|
||||
"rareQuantity": 7,
|
||||
"itemQuantity": 7
|
||||
},
|
||||
"unopened": false,
|
||||
"displayGroup": {
|
||||
"value": "gold"
|
||||
}
|
||||
},
|
||||
{
|
||||
"assetId": 6,
|
||||
"id": 6,
|
||||
"packType": "GOLD",
|
||||
"description": "Premium Gold",
|
||||
"state": "active",
|
||||
"saleType": "promo",
|
||||
"limitType": "NONE",
|
||||
"quantity": 0,
|
||||
"purchaseLimit": 0,
|
||||
"purchaseCount": 0,
|
||||
"isPremium": false,
|
||||
"sortPriority": 3,
|
||||
"currencies": [
|
||||
{
|
||||
"name": "coins",
|
||||
"funds": 15000,
|
||||
"finalFunds": 15000
|
||||
}
|
||||
],
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 150,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 150,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"silverQuantity": 0,
|
||||
"goldQuantity": 11,
|
||||
"rareQuantity": 11,
|
||||
"itemQuantity": 11
|
||||
},
|
||||
"unopened": false,
|
||||
"displayGroup": {
|
||||
"value": "gold"
|
||||
}
|
||||
},
|
||||
{
|
||||
"assetId": 7,
|
||||
"id": 7,
|
||||
"packType": "GOLD",
|
||||
"description": "Special Players Pack",
|
||||
"state": "active",
|
||||
"saleType": "promo",
|
||||
"limitType": "NONE",
|
||||
"quantity": 0,
|
||||
"purchaseLimit": 0,
|
||||
"purchaseCount": 0,
|
||||
"isPremium": false,
|
||||
"sortPriority": 4,
|
||||
"currencies": [
|
||||
{
|
||||
"name": "coins",
|
||||
"funds": 25000,
|
||||
"finalFunds": 25000
|
||||
}
|
||||
],
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 250,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 250,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"silverQuantity": 0,
|
||||
"goldQuantity": 11,
|
||||
"rareQuantity": 11,
|
||||
"itemQuantity": 11
|
||||
},
|
||||
"unopened": false,
|
||||
"displayGroup": {
|
||||
"value": "special"
|
||||
}
|
||||
},
|
||||
{
|
||||
"assetId": 65534,
|
||||
"id": 65534,
|
||||
"packType": "GOLD",
|
||||
"description": "",
|
||||
"state": "active",
|
||||
"saleType": "promo",
|
||||
"limitType": "NONE",
|
||||
"quantity": 0,
|
||||
"purchaseLimit": 0,
|
||||
"purchaseCount": 0,
|
||||
"isPremium": false,
|
||||
"sortPriority": 1,
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"silverQuantity": 0,
|
||||
"goldQuantity": 0,
|
||||
"rareQuantity": 0,
|
||||
"itemQuantity": 0
|
||||
},
|
||||
"unopened": false,
|
||||
"displayGroup": {
|
||||
"value": "mypacks",
|
||||
"priority": 1
|
||||
}
|
||||
}
|
||||
],
|
||||
"timestamp": 1596326400
|
||||
}
|
||||
@@ -1 +0,0 @@
|
||||
{"purchase": [{"assetId": 1, "id": 1, "packType": "BRONZE", "description": "Bronze Pack", "state": "active", "saleType": "promo", "limitType": "NONE", "quantity": 0, "purchaseLimit": 0, "purchaseCount": 0, "isPremium": false, "sortPriority": 1, "currencies": [{"name": "coins", "funds": 400, "finalFunds": 400}], "extPrice": {"finalPrice": {"amount": 4, "currency": "mtx"}, "originalPrice": {"amount": 4, "currency": "mtx"}}, "packContentInfo": {"bronzeQuantity": 5, "silverQuantity": 0, "goldQuantity": 0, "rareQuantity": 0, "itemQuantity": 5}, "unopened": false, "displayGroup": {"value": "bronze"}}, {"assetId": 5, "id": 5, "packType": "GOLD", "description": "Gold Pack", "state": "active", "saleType": "promo", "limitType": "NONE", "quantity": 0, "purchaseLimit": 0, "purchaseCount": 0, "isPremium": false, "sortPriority": 2, "currencies": [{"name": "coins", "funds": 5000, "finalFunds": 5000}], "extPrice": {"finalPrice": {"amount": 50, "currency": "mtx"}, "originalPrice": {"amount": 50, "currency": "mtx"}}, "packContentInfo": {"bronzeQuantity": 0, "silverQuantity": 0, "goldQuantity": 7, "rareQuantity": 7, "itemQuantity": 7}, "unopened": false, "displayGroup": {"value": "gold"}}, {"assetId": 6, "id": 6, "packType": "GOLD", "description": "Premium Gold", "state": "active", "saleType": "promo", "limitType": "NONE", "quantity": 0, "purchaseLimit": 0, "purchaseCount": 0, "isPremium": false, "sortPriority": 3, "currencies": [{"name": "coins", "funds": 15000, "finalFunds": 15000}], "extPrice": {"finalPrice": {"amount": 150, "currency": "mtx"}, "originalPrice": {"amount": 150, "currency": "mtx"}}, "packContentInfo": {"bronzeQuantity": 0, "silverQuantity": 0, "goldQuantity": 11, "rareQuantity": 11, "itemQuantity": 11}, "unopened": false, "displayGroup": {"value": "gold"}}, {"assetId": 7, "id": 7, "packType": "GOLD", "description": "Special Players Pack", "state": "active", "saleType": "promo", "limitType": "NONE", "quantity": 0, "purchaseLimit": 0, "purchaseCount": 0, "isPremium": false, "sortPriority": 4, "currencies": [{"name": "coins", "funds": 25000, "finalFunds": 25000}], "extPrice": {"finalPrice": {"amount": 250, "currency": "mtx"}, "originalPrice": {"amount": 250, "currency": "mtx"}}, "packContentInfo": {"bronzeQuantity": 0, "silverQuantity": 0, "goldQuantity": 11, "rareQuantity": 11, "itemQuantity": 11}, "unopened": false, "displayGroup": {"value": "special"}}], "timestamp": 1596326400}
|
||||
@@ -1,173 +0,0 @@
|
||||
{
|
||||
"purchase": [
|
||||
{
|
||||
"assetId": 1,
|
||||
"id": 1,
|
||||
"packType": "BRONZE",
|
||||
"description": "Bronze Pack",
|
||||
"state": "active",
|
||||
"saleType": "promo",
|
||||
"limitType": "NONE",
|
||||
"quantity": 0,
|
||||
"purchaseLimit": 0,
|
||||
"purchaseCount": 0,
|
||||
"isPremium": false,
|
||||
"sortPriority": 1,
|
||||
"currencies": [
|
||||
{
|
||||
"name": "coins",
|
||||
"funds": 400,
|
||||
"finalFunds": 400
|
||||
}
|
||||
],
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 4,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 4,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 5,
|
||||
"silverQuantity": 0,
|
||||
"goldQuantity": 0,
|
||||
"rareQuantity": 0,
|
||||
"itemQuantity": 5
|
||||
},
|
||||
"unopened": false,
|
||||
"displayGroup": {
|
||||
"value": "bronze"
|
||||
}
|
||||
},
|
||||
{
|
||||
"assetId": 5,
|
||||
"id": 5,
|
||||
"packType": "GOLD",
|
||||
"description": "Gold Pack",
|
||||
"state": "active",
|
||||
"saleType": "promo",
|
||||
"limitType": "NONE",
|
||||
"quantity": 0,
|
||||
"purchaseLimit": 0,
|
||||
"purchaseCount": 0,
|
||||
"isPremium": false,
|
||||
"sortPriority": 2,
|
||||
"currencies": [
|
||||
{
|
||||
"name": "coins",
|
||||
"funds": 5000,
|
||||
"finalFunds": 5000
|
||||
}
|
||||
],
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 50,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 50,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"silverQuantity": 0,
|
||||
"goldQuantity": 7,
|
||||
"rareQuantity": 7,
|
||||
"itemQuantity": 7
|
||||
},
|
||||
"unopened": false,
|
||||
"displayGroup": {
|
||||
"value": "gold"
|
||||
}
|
||||
},
|
||||
{
|
||||
"assetId": 6,
|
||||
"id": 6,
|
||||
"packType": "GOLD",
|
||||
"description": "Premium Gold",
|
||||
"state": "active",
|
||||
"saleType": "promo",
|
||||
"limitType": "NONE",
|
||||
"quantity": 0,
|
||||
"purchaseLimit": 0,
|
||||
"purchaseCount": 0,
|
||||
"isPremium": false,
|
||||
"sortPriority": 3,
|
||||
"currencies": [
|
||||
{
|
||||
"name": "coins",
|
||||
"funds": 15000,
|
||||
"finalFunds": 15000
|
||||
}
|
||||
],
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 150,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 150,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"silverQuantity": 0,
|
||||
"goldQuantity": 11,
|
||||
"rareQuantity": 11,
|
||||
"itemQuantity": 11
|
||||
},
|
||||
"unopened": false,
|
||||
"displayGroup": {
|
||||
"value": "gold"
|
||||
}
|
||||
},
|
||||
{
|
||||
"assetId": 7,
|
||||
"id": 7,
|
||||
"packType": "GOLD",
|
||||
"description": "Special Players Pack",
|
||||
"state": "active",
|
||||
"saleType": "promo",
|
||||
"limitType": "NONE",
|
||||
"quantity": 0,
|
||||
"purchaseLimit": 0,
|
||||
"purchaseCount": 0,
|
||||
"isPremium": false,
|
||||
"sortPriority": 4,
|
||||
"currencies": [
|
||||
{
|
||||
"name": "coins",
|
||||
"funds": 25000,
|
||||
"finalFunds": 25000
|
||||
}
|
||||
],
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 250,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 250,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"silverQuantity": 0,
|
||||
"goldQuantity": 11,
|
||||
"rareQuantity": 11,
|
||||
"itemQuantity": 11
|
||||
},
|
||||
"unopened": false,
|
||||
"displayGroup": {
|
||||
"value": "special"
|
||||
}
|
||||
}
|
||||
],
|
||||
"timestamp": 1596326400
|
||||
}
|
||||
@@ -1 +0,0 @@
|
||||
{"purchase": [{"assetId": 1, "id": 1, "packType": "BRONZE", "description": "Bronze Pack", "state": "active", "saleType": "promo", "limitType": "NONE", "quantity": 0, "purchaseLimit": 0, "purchaseCount": 0, "isPremium": false, "sortPriority": 1, "currencies": [{"name": "coins", "funds": 400, "finalFunds": 400}], "extPrice": {"finalPrice": {"amount": 4, "currency": "mtx"}, "originalPrice": {"amount": 4, "currency": "mtx"}}, "packContentInfo": {"bronzeQuantity": 5, "silverQuantity": 0, "goldQuantity": 0, "rareQuantity": 0, "itemQuantity": 5}, "unopened": false, "displayGroup": {"value": "bronze"}}, {"assetId": 5, "id": 5, "packType": "GOLD", "description": "Gold Pack", "state": "active", "saleType": "promo", "limitType": "NONE", "quantity": 0, "purchaseLimit": 0, "purchaseCount": 0, "isPremium": false, "sortPriority": 2, "currencies": [{"name": "coins", "funds": 5000, "finalFunds": 5000}], "extPrice": {"finalPrice": {"amount": 50, "currency": "mtx"}, "originalPrice": {"amount": 50, "currency": "mtx"}}, "packContentInfo": {"bronzeQuantity": 0, "silverQuantity": 0, "goldQuantity": 7, "rareQuantity": 7, "itemQuantity": 7}, "unopened": false, "displayGroup": {"value": "gold"}}, {"assetId": 6, "id": 6, "packType": "GOLD", "description": "Premium Gold", "state": "active", "saleType": "promo", "limitType": "NONE", "quantity": 0, "purchaseLimit": 0, "purchaseCount": 0, "isPremium": false, "sortPriority": 3, "currencies": [{"name": "coins", "funds": 15000, "finalFunds": 15000}], "extPrice": {"finalPrice": {"amount": 150, "currency": "mtx"}, "originalPrice": {"amount": 150, "currency": "mtx"}}, "packContentInfo": {"bronzeQuantity": 0, "silverQuantity": 0, "goldQuantity": 11, "rareQuantity": 11, "itemQuantity": 11}, "unopened": false, "displayGroup": {"value": "gold"}}, {"assetId": 7, "id": 7, "packType": "GOLD", "description": "Special Players Pack", "state": "active", "saleType": "promo", "limitType": "NONE", "quantity": 0, "purchaseLimit": 0, "purchaseCount": 0, "isPremium": false, "sortPriority": 4, "currencies": [{"name": "coins", "funds": 25000, "finalFunds": 25000}], "extPrice": {"finalPrice": {"amount": 250, "currency": "mtx"}, "originalPrice": {"amount": 250, "currency": "mtx"}}, "packContentInfo": {"bronzeQuantity": 0, "silverQuantity": 0, "goldQuantity": 11, "rareQuantity": 11, "itemQuantity": 11}, "unopened": false, "displayGroup": {"value": "special"}}], "timestamp": 1596326400}
|
||||
@@ -1,199 +0,0 @@
|
||||
{
|
||||
"purchase": [
|
||||
{
|
||||
"assetId": 1,
|
||||
"id": 1,
|
||||
"packType": "BRONZE",
|
||||
"description": "Bronze Pack",
|
||||
"state": "active",
|
||||
"saleType": "promo",
|
||||
"limitType": "NONE",
|
||||
"quantity": 0,
|
||||
"purchaseLimit": 0,
|
||||
"purchaseCount": 0,
|
||||
"isPremium": false,
|
||||
"sortPriority": 1,
|
||||
"currencies": [
|
||||
{
|
||||
"name": "coins",
|
||||
"funds": 400,
|
||||
"finalFunds": 400
|
||||
}
|
||||
],
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 4,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 4,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 5,
|
||||
"silverQuantity": 0,
|
||||
"goldQuantity": 0,
|
||||
"rareQuantity": 0,
|
||||
"itemQuantity": 5
|
||||
},
|
||||
"unopened": false,
|
||||
"displayGroup": {
|
||||
"value": "bronze"
|
||||
}
|
||||
},
|
||||
{
|
||||
"assetId": 5,
|
||||
"id": 5,
|
||||
"packType": "GOLD",
|
||||
"description": "Gold Pack",
|
||||
"state": "active",
|
||||
"saleType": "promo",
|
||||
"limitType": "NONE",
|
||||
"quantity": 0,
|
||||
"purchaseLimit": 0,
|
||||
"purchaseCount": 0,
|
||||
"isPremium": false,
|
||||
"sortPriority": 2,
|
||||
"currencies": [
|
||||
{
|
||||
"name": "coins",
|
||||
"funds": 5000,
|
||||
"finalFunds": 5000
|
||||
}
|
||||
],
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 50,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 50,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"silverQuantity": 0,
|
||||
"goldQuantity": 7,
|
||||
"rareQuantity": 7,
|
||||
"itemQuantity": 7
|
||||
},
|
||||
"unopened": false,
|
||||
"displayGroup": {
|
||||
"value": "gold"
|
||||
}
|
||||
},
|
||||
{
|
||||
"assetId": 6,
|
||||
"id": 6,
|
||||
"packType": "GOLD",
|
||||
"description": "Premium Gold",
|
||||
"state": "active",
|
||||
"saleType": "promo",
|
||||
"limitType": "NONE",
|
||||
"quantity": 0,
|
||||
"purchaseLimit": 0,
|
||||
"purchaseCount": 0,
|
||||
"isPremium": false,
|
||||
"sortPriority": 3,
|
||||
"currencies": [
|
||||
{
|
||||
"name": "coins",
|
||||
"funds": 15000,
|
||||
"finalFunds": 15000
|
||||
}
|
||||
],
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 150,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 150,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"silverQuantity": 0,
|
||||
"goldQuantity": 11,
|
||||
"rareQuantity": 11,
|
||||
"itemQuantity": 11
|
||||
},
|
||||
"unopened": false,
|
||||
"displayGroup": {
|
||||
"value": "gold"
|
||||
}
|
||||
},
|
||||
{
|
||||
"assetId": 7,
|
||||
"id": 7,
|
||||
"packType": "GOLD",
|
||||
"description": "Special Players Pack",
|
||||
"state": "active",
|
||||
"saleType": "promo",
|
||||
"limitType": "NONE",
|
||||
"quantity": 0,
|
||||
"purchaseLimit": 0,
|
||||
"purchaseCount": 0,
|
||||
"isPremium": false,
|
||||
"sortPriority": 4,
|
||||
"currencies": [
|
||||
{
|
||||
"name": "coins",
|
||||
"funds": 25000,
|
||||
"finalFunds": 25000
|
||||
}
|
||||
],
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 250,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 250,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"silverQuantity": 0,
|
||||
"goldQuantity": 11,
|
||||
"rareQuantity": 11,
|
||||
"itemQuantity": 11
|
||||
},
|
||||
"unopened": false,
|
||||
"displayGroup": {
|
||||
"value": "special"
|
||||
}
|
||||
},
|
||||
{
|
||||
"assetId": 70,
|
||||
"id": 70,
|
||||
"packType": "GOLD",
|
||||
"description": "Reward Special Players Pack",
|
||||
"state": "active",
|
||||
"saleType": "promo",
|
||||
"limitType": "NONE",
|
||||
"quantity": 0,
|
||||
"purchaseLimit": 0,
|
||||
"purchaseCount": 0,
|
||||
"isPremium": false,
|
||||
"sortPriority": 1,
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"silverQuantity": 0,
|
||||
"goldQuantity": 11,
|
||||
"rareQuantity": 11,
|
||||
"itemQuantity": 11
|
||||
},
|
||||
"unopened": true,
|
||||
"displayGroup": {
|
||||
"value": "mypacks",
|
||||
"priority": 1
|
||||
}
|
||||
}
|
||||
],
|
||||
"timestamp": 1596326400
|
||||
}
|
||||
@@ -1,108 +0,0 @@
|
||||
# FIFA 23 PC Startup Flow (Offline / Proton)
|
||||
|
||||
Observed via FLE log, hook log, and file inspection on 2026-06-26.
|
||||
|
||||
## Launch chain
|
||||
|
||||
```
|
||||
umu-run / Steam → FIFA23.exe (via Proton/Wine)
|
||||
│
|
||||
├─ DLL load order (before entry point)
|
||||
│ ntdll.dll, kernel32.dll, ws2_32.dll …
|
||||
│ version.dll ← our hook DLL slot (loads here)
|
||||
│ FIFALiveEditor.DLL ← injected by FLE launcher after ~100 ms
|
||||
│
|
||||
├─ anadius / LSX emulator (anadius64.dll)
|
||||
│ Fakes EA App / Origin session
|
||||
│ Reads HKLM\SOFTWARE\Wow6432Node\Origin\ClientPath
|
||||
│ Writes AppData\Local\anadius\LSX emu\achievement-*.xml
|
||||
│ Provides fake PersonaId=1144668899 / UserId=1000200030000
|
||||
│
|
||||
├─ EA Anti-Cheat (EAAntiCheat.GameServiceLauncher.exe)
|
||||
│ Spawns as child; checks EAAntiCheat.cfg
|
||||
│ Not active in offline/cracked builds (FakeEAACLauncher present)
|
||||
│
|
||||
└─ FIFA23.exe entry point
|
||||
Frostbite engine init (BuildDate 2023-07-05, changelist 5417699)
|
||||
Reads Data\initfs_Win32 ← Frostbite package manifest
|
||||
Reads Data\layout.toc ← file-system layout
|
||||
Reads Patch\initfs_Win32 ← patches on top of base
|
||||
Reads Documents\FIFA 23\fifasetup.ini ← display settings
|
||||
Reads Data\locale.ini ← language table
|
||||
Reads Data\db_meta.xml (via FLE) ← DB schema for all tables
|
||||
```
|
||||
|
||||
## Phase timing (observed, single machine)
|
||||
|
||||
| Phase | Time after launch | Trigger |
|
||||
|------------------------------|-------------------|----------------------------------|
|
||||
| DLL load + FLE injection | 0 – 0.3 s | OS loader |
|
||||
| Engine + DirectX init | 0.3 – 5 s | FIFA23 entry point |
|
||||
| "Press any key" splash | ~5 s | First rendered frame |
|
||||
| Main menu | ~25 s | After key press |
|
||||
| FUT mode entry (attempted) | user-driven | User selects FUT tile |
|
||||
| Network calls to EA services | at FUT entry | DirtySDK / EAWebKit |
|
||||
|
||||
## Files read at startup (observed)
|
||||
|
||||
| File | Format | Purpose |
|
||||
|------|--------|---------|
|
||||
| `Data/initfs_Win32` | Frostbite pkg | Base asset manifest |
|
||||
| `Data/layout.toc` | Frostbite TOC | File layout index |
|
||||
| `Patch/initfs_Win32` | Frostbite pkg | Patch layer |
|
||||
| `Data/locale.ini` | INI | String localisation |
|
||||
| `Data/db_meta.xml` | XML | DB schema (loaded by FLE) |
|
||||
| `Data/id_map.json` | JSON | Player/team ID→name map |
|
||||
| `Data/char_conv.json` | JSON | Character conversion table |
|
||||
| `Documents/FIFA 23/fifasetup.ini` | INI | Display/audio settings |
|
||||
| `AppData/Local/Temp/FIFA 23/_replay0.bin` | binary | Replay buffer |
|
||||
| `anadius.cfg` | VDF | Fake EA persona config |
|
||||
| `AppData/Local/anadius/LSX emu/achievement-*.xml` | XML | Achievement state |
|
||||
|
||||
## Files written during a session (observed)
|
||||
|
||||
| File | When written | Content |
|
||||
|------|-------------|---------|
|
||||
| `Documents/FIFA 23/settings/Settings*` | Main menu reached | FBCHUNKS — controller/display prefs |
|
||||
| `Documents/FIFA 23/settings/ProfileOptions` | Profile load | FBCHUNKS — 1.5 MB profile blob |
|
||||
| `Documents/FIFA 23/filesystemcache/survey.state` | Startup | Empty state file |
|
||||
| `Documents/FIFA 23/filesystemcache/atlPlayTimeJson/playtime_*.json` | Ongoing | Playtime tracking |
|
||||
| `FIFA 23 Live Editor/config.json` | FLE ready | FLE settings (rewritten each session) |
|
||||
| `Logs/log_DD-MM-YYYY.txt` | Throughout | FLE debug log |
|
||||
|
||||
## Save file formats
|
||||
|
||||
### FBCHUNKS (Frostbite chunk container)
|
||||
- Magic: `46 42 43 48 55 4E 4B 53` (`FBCHUNKS`)
|
||||
- Byte 8: version (01 seen)
|
||||
- Offset 0x12: null-terminated label string (e.g. "Personal Settings 1", "Career - Player Progress 1")
|
||||
- Remainder: compressed/binary chunk data — no public spec; requires Frostbite tooling to fully parse
|
||||
- Tools: [Frosty Tool Suite](https://github.com/CadeEvs/FrostyToolSuite) can read/write these
|
||||
|
||||
### fifasetup.ini
|
||||
- Plain `KEY = VALUE` ini, fully human-readable
|
||||
- Safe to edit (display resolution, locale, vsync)
|
||||
|
||||
## Network calls at FUT entry (observed with iptables redirect)
|
||||
|
||||
Traffic pattern captured before changing strategy:
|
||||
- Multiple TLS connections to port 443 (destination: EA servers, resolved as various EA IPs)
|
||||
- TLS 1.3, AES-256-GCM (DirtySDK's copy of ProtoSSL, inline in FIFA23.exe)
|
||||
- No SNI sent (DirtySDK does not set `server_name` extension)
|
||||
- Connections originate from Wine/Proton network stack via Linux kernel TCP
|
||||
|
||||
Specific EA hostnames used (from openfut-bridge captures, not decoded from TLS):
|
||||
- `fut.ea.com` (FUT API)
|
||||
- `accounts.ea.com` (auth)
|
||||
- `gateway.ea.com` (entitlements)
|
||||
- `pin-river.data.ea.com` (telemetry)
|
||||
|
||||
## Key FLE Lua API hooks
|
||||
|
||||
FLE injects `FIFALiveEditor.DLL` and exposes a Lua engine that can:
|
||||
- Read any in-memory DB table via `GetDBTableRows(tableName)`
|
||||
- Write any cell via `EditDBTableField`
|
||||
- Query career mode state via `IsInCM()`
|
||||
- Get player/team names via `GetPlayerName`, `GetTeamName`
|
||||
|
||||
This is the primary safe integration path (see `fut-integration-options.md`).
|
||||
@@ -1,191 +0,0 @@
|
||||
# Foundational test — live custom XI via Freeze Lineup
|
||||
|
||||
**Status: PENDING — test has not yet been run.**
|
||||
|
||||
This is build-order step 1 from `docs/direction.md`: the test everything else
|
||||
in the direction pivot depends on.
|
||||
|
||||
## What changed since the first draft of this doc
|
||||
|
||||
The first version of this test guessed at a "selection bias" DB field and a
|
||||
candidate squad/lineup table name, based on general FIFA-modding precedent
|
||||
that turned out not to hold for FLE's documented API — no such field appears
|
||||
anywhere in FLE's actual Lua API docs or its own example scripts. While
|
||||
researching an unrelated hotkey issue, a **confirmed, FLE-documented**
|
||||
mechanism for forcing a starting XI turned up instead: the **Formation
|
||||
Editor's "Freeze Lineup" feature** (FLE wiki, `Formation-Editor.md`):
|
||||
|
||||
> This feature can be used in player career mode if you want to manage the
|
||||
> starting lineup of your team. Can be also used in manager career mode to
|
||||
> manually manage your next opponent's starting lineup.
|
||||
|
||||
Steps (GUI, no scripting): open Formation Editor for a team → arrange players
|
||||
on the pitch → tick **Freeze Lineup** → `Data → Save`.
|
||||
|
||||
This is real and documented, but it's GUI-only — there is no Lua function for
|
||||
it, and what DB write it actually performs under the hood is undocumented.
|
||||
This test is now two phases: confirm the GUI feature works at all, then
|
||||
reverse the DB write it makes so it can be replicated programmatically
|
||||
(required for the app→game bridge in build-order step 2, which needs this
|
||||
driven from outside the game, not from a person clicking checkboxes).
|
||||
|
||||
Also fixed in this pass: `EditDBTableField`'s real signature, confirmed from
|
||||
FLE's own docs and `lua/scripts/99ovr_99pot.lua`, is
|
||||
`EditDBTableField(cell)` where `cell` is `row["fieldname"]` with `.value`
|
||||
mutated in place — **not** `EditDBTableField(table, row_index, field, value)`
|
||||
as originally (incorrectly) written into the first draft of the injector
|
||||
script.
|
||||
|
||||
## What this test settles
|
||||
|
||||
Whether a *specific, externally-chosen* 11 players can be forced into a
|
||||
career (or Kick-Off) match's starting lineup, live, with no restart — and
|
||||
whether the mechanism that does it (Freeze Lineup's underlying DB write) can
|
||||
be driven by a script instead of a person clicking through the Formation
|
||||
Editor UI.
|
||||
|
||||
If Freeze Lineup itself doesn't actually hold under match start (the wiki
|
||||
doesn't show it being tested against a live match, only "you should be able
|
||||
to see... when you play against them"), the whole bridge architecture in
|
||||
`docs/direction.md` §3 needs rethinking — there is no other documented
|
||||
mechanism for forcing a lineup.
|
||||
|
||||
## Prerequisites
|
||||
|
||||
- FIFA 23 launched normally (FLE injected, EAAC neutralized — same baseline
|
||||
as `track-c-fut-table-test.md`)
|
||||
- A career save loaded (Freeze Lineup is documented for career mode
|
||||
specifically — confirm separately whether it does anything in Kick-Off,
|
||||
don't assume it does)
|
||||
- Note 11 player IDs from your club (`tools/squad-exporter/export_squad.lua`
|
||||
output, `playerid` field) that are NOT currently your starting XI
|
||||
|
||||
## Phase 1 — confirm Freeze Lineup actually holds into a match
|
||||
|
||||
This has zero scripting and should be done first since everything else is
|
||||
wasted effort if it fails.
|
||||
|
||||
1. Open the Live Editor overlay (F9, or `Windows → Settings` from the
|
||||
overlay's own menu bar if the hotkey isn't registering — see the umu/Wine
|
||||
hotkey note below).
|
||||
2. `Features → Teams` → find your team → `Edit`.
|
||||
3. `Team → Formation` to open the Formation Editor.
|
||||
4. Swap players around on the pitch so the XI differs from your current
|
||||
actual starting XI in some checkable way (e.g. swap two outfield players'
|
||||
positions, or bench/start a specific player).
|
||||
5. Tick **Freeze Lineup**.
|
||||
6. `Data → Save`.
|
||||
7. Hide Live Editor (F9), save your career **on a new slot** (don't overwrite
|
||||
your main save in case this corrupts something), exit to main menu, reload
|
||||
that save, and check the team's lineup screen / play a match and watch who
|
||||
starts.
|
||||
|
||||
**Record in the Results table below whether the frozen lineup actually took
|
||||
the pitch.** If not, stop here — Phase 2 is moot.
|
||||
|
||||
## Phase 2 — find the underlying DB write
|
||||
|
||||
Only proceed if Phase 1 confirmed Freeze Lineup works.
|
||||
|
||||
1. In FLE's Lua Engine, run `tools/squad-injector/snapshot_lineup_tables.lua`.
|
||||
This dumps every DB table whose name contains `squad`, `lineup`,
|
||||
`formation`, `tactic`, `teamsheet`, `selection`, `players`, or `teams` to
|
||||
`C:\FIFA 23 Live Editor\openfut_snapshot_<timestamp>.json`. Note this
|
||||
filename — this is your **before** snapshot.
|
||||
2. Without restarting or reloading, repeat the Formation Editor steps from
|
||||
Phase 1 (steps 2–6 only — open Formation Editor, change the lineup, tick
|
||||
Freeze Lineup, `Data → Save`). Don't save/reload the career between
|
||||
snapshot and this step — keep it to a single live session so the diff
|
||||
isn't polluted by other state changes.
|
||||
3. Run `snapshot_lineup_tables.lua` again. This is your **after** snapshot.
|
||||
4. Copy both JSON files out of the Wine prefix (same path pattern as
|
||||
`track-c-fut-table-test.md`: `~/Games/umu/.../drive_c/FIFA 23 Live
|
||||
Editor/`) and run:
|
||||
|
||||
```bash
|
||||
python3 tools/squad-injector/diff_snapshots.py before.json after.json
|
||||
```
|
||||
|
||||
5. The output shows exactly which table(s) and field(s) changed. This is the
|
||||
real, confirmed write Freeze Lineup performs — record it in the Results
|
||||
table below.
|
||||
|
||||
## Phase 3 — replicate the write via script
|
||||
|
||||
1. Open `tools/squad-injector/apply_lineup_write.lua` and fill in
|
||||
`TARGET_TABLE` and `TARGET_FIELDS` using Phase 2's diff output.
|
||||
2. Edit `C:\FIFA 23 Live Editor\openfut_test_xi.json`:
|
||||
|
||||
```json
|
||||
{
|
||||
"team_id": 12345,
|
||||
"xi": [
|
||||
{ "player_id": 111111, "position": 0 },
|
||||
{ "player_id": 222222, "position": 5 }
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
Use 11 entries. Position codes are **confirmed numeric 0–27**
|
||||
(`GK=0, SW=1, RWB=2, RB=3, RCB=4, CB=5, LCB=6, LB=7, LWB=8, RDM=9, CDM=10,
|
||||
LDM=11, RM=12, RCM=13, CM=14, LCM=15, LM=16, RAM=17, CAM=18, LAM=19,
|
||||
RF=20, CF=21, LF=22, RW=23, RS=24, ST=25, LS=26, LW=27`) — from
|
||||
`lua/scripts/export_season_stats.lua`'s `get_pos_name` table in FLE's own
|
||||
repo, not a guess.
|
||||
3. Run `apply_lineup_write.lua` from FLE's Lua Engine.
|
||||
4. Repeat the save-to-new-slot / reload / check-lineup verification from
|
||||
Phase 1, but this time without ever opening the Formation Editor — the
|
||||
write was made entirely from the script.
|
||||
|
||||
## Classification criteria
|
||||
|
||||
### "Confirmed — full mechanism works"
|
||||
|
||||
Phase 1 holds, Phase 2 finds a clean diff, Phase 3's scripted write produces
|
||||
the same in-match result as the manual GUI path.
|
||||
|
||||
**Verdict:** Build-order step 1 done. Proceed to step 2 (bridge transport) in
|
||||
`docs/direction.md`.
|
||||
|
||||
### "GUI works, script doesn't"
|
||||
|
||||
Phase 1 holds but Phase 3's replicated write doesn't stick, even though the
|
||||
diffed fields matched what changed in Phase 2.
|
||||
|
||||
**Verdict:** Freeze Lineup likely does more than a single DB field write
|
||||
(e.g. an internal engine call beyond `EditDBTableField`'s reach, or a second
|
||||
write the diff missed because it happened in a table outside the `KEYWORDS`
|
||||
filter in `snapshot_lineup_tables.lua` — widen the filter and redo Phase 2).
|
||||
|
||||
### "Freeze Lineup doesn't hold at all"
|
||||
|
||||
Phase 1 fails — the lineup reverts to the game's own AI-picked XI regardless.
|
||||
|
||||
**Verdict:** No confirmed mechanism exists for forcing a lineup. This kills
|
||||
the bridge architecture as designed in `direction.md` §3 and needs a return
|
||||
to first principles — there is no fallback documented anywhere in FLE's wiki
|
||||
for this specific case.
|
||||
|
||||
## A note on the umu/Wine F9/F11 hotkey issue
|
||||
|
||||
If FLE's F9 (hide/show) hotkey isn't registering under umu, this is plausibly
|
||||
a Wine keyboard-hook limitation (FLE's global hotkey detection likely uses a
|
||||
low-level hook that doesn't translate cleanly through Wine's input layer) —
|
||||
not something documented anywhere in FLE's own troubleshooting docs, which
|
||||
don't mention Linux/Wine at all. F11 specifically has **no documented FLE
|
||||
function** — F9 is the only documented toggle. Workaround: click directly
|
||||
into the FLE overlay window (it should still be visible/clickable even if the
|
||||
hotkey doesn't fire) and use its own menu bar instead of relying on the
|
||||
hotkey.
|
||||
|
||||
## Results
|
||||
|
||||
*(To be filled in after the test is run.)*
|
||||
|
||||
| Field | Value |
|
||||
|---|---|
|
||||
| Date run | — |
|
||||
| Phase 1: Freeze Lineup holds into a match? | — |
|
||||
| Phase 2: table(s)/field(s) changed | — |
|
||||
| Phase 3: scripted write reproduces Phase 1 result? | — |
|
||||
| **Classification** | **PENDING** |
|
||||
@@ -1,136 +0,0 @@
|
||||
# FUT Integration Options
|
||||
|
||||
How to connect FIFA 23 to the OpenFUT local simulator, ranked by safety and feasibility.
|
||||
|
||||
## Option A — FLE Lua scripting (RECOMMENDED)
|
||||
|
||||
**What it does:** Use FIFA Live Editor's in-memory Lua API to read and write the game's
|
||||
database tables at runtime. FLE is already injected; no additional hooking needed.
|
||||
|
||||
**Why it's the right path:**
|
||||
- Fully offline, no EA servers touched
|
||||
- FLE is already trusted by the user (it's the launch mechanism)
|
||||
- `GetDBTableRows` / `EditDBTableField` expose the full Frostbite DB in memory
|
||||
- Scripts run inside the game process; no IPC complexity
|
||||
- Same mechanism used by modders for career mode edits today
|
||||
|
||||
**Integration design:**
|
||||
|
||||
```
|
||||
openfut-core (SQLite)
|
||||
│
|
||||
│ HTTP REST (localhost)
|
||||
▼
|
||||
openfut-bridge (port 8080, plain HTTP, no TLS)
|
||||
│ pulls club/squad/player data as JSON
|
||||
▼
|
||||
FLE Lua bridge script
|
||||
│ calls GetDBTableRows, EditDBTableField
|
||||
▼
|
||||
FIFA 23 in-memory DB (Frostbite)
|
||||
```
|
||||
|
||||
The Lua script polls openfut-core's REST API at intervals (or on FUT menu entry)
|
||||
and writes simulator data (coins, items, squad) into the appropriate DB tables.
|
||||
|
||||
**Tables likely involved (to verify with export_squad.lua):**
|
||||
|
||||
| Table | Expected FUT content |
|
||||
|-------|---------------------|
|
||||
| `players` | Player attributes (OVR, potential, stats) |
|
||||
| `teams` | Club identity, stadium, colors |
|
||||
| `fut_clubs` | FUT club record (if in memory when FUT loads) |
|
||||
| `fut_items` | Card inventory (if in memory) |
|
||||
| `fut_squads` | Active squad (if in memory) |
|
||||
|
||||
**Steps to implement:**
|
||||
1. Run `tools/squad-exporter/export_squad.lua` from FLE Lua Engine while in FUT to discover which tables are live
|
||||
2. Map openfut-core's data model to the discovered table fields
|
||||
3. Write a Lua polling script that fetches `/api/v1/club`, `/api/v1/squad`, etc. from openfut-core and calls `EditDBTableField` to populate them
|
||||
4. Optionally add a small HTTP client to the Lua script using LuaSocket (FLE ships with Lua 5.4)
|
||||
|
||||
**Limitations:**
|
||||
- Changes are in-memory only; they reset on game restart (acceptable for a simulator)
|
||||
- Only works while FLE is running (always true in our setup)
|
||||
- FUT tables may only be populated when the FUT hub is loaded; test with the exporter
|
||||
|
||||
---
|
||||
|
||||
## Option B — Local save file injection (career mode proxy)
|
||||
|
||||
**What it does:** Generate or modify offline career mode save files that contain FUT-like
|
||||
squad/player data, using Frostbite's FBCHUNKS format.
|
||||
|
||||
**Feasibility:** Medium
|
||||
- FBCHUNKS format is not publicly documented but has been partially reverse-engineered by the Frosty Tool Suite project
|
||||
- Career saves are 16 MB — large and complex
|
||||
- Changes take effect only after a game restart
|
||||
|
||||
**Best use:** Pre-populating a career club with the same players as the FUT simulator squad, so offline Squad Battles use "your" players.
|
||||
|
||||
**Steps:**
|
||||
1. Use Frosty Tool Suite to open a career save and map the schema
|
||||
2. Build a Python exporter that writes a valid FBCHUNKS save with simulator squad data
|
||||
3. Test: replace the career save, launch FIFA, verify squad is correct
|
||||
|
||||
---
|
||||
|
||||
## Option C — Local companion web UI
|
||||
|
||||
**What it does:** The user manages their FUT simulator entirely in a web browser (openfut-core already has this). A button exports the current squad/club state to a format that a Lua script or file injector can consume.
|
||||
|
||||
**This is already implemented** — openfut-core serves the FUT simulator REST API. The missing piece is the Lua bridge script (Option A) that reads from it.
|
||||
|
||||
---
|
||||
|
||||
## Option D — Local proxy for non-secured local calls only
|
||||
|
||||
**What it does:** Intercept FIFA 23's calls to `localhost:*` or a known local endpoint (not EA servers) and respond with simulator data.
|
||||
|
||||
**Feasibility:** Low value in isolation
|
||||
- FIFA 23 does not make calls to localhost in normal operation (except EA App on port 10853)
|
||||
- All FUT API calls go to EA's servers over TLS
|
||||
- Intercepting those would require the approach we explicitly ruled out
|
||||
|
||||
**Not recommended as a primary path.** Could be combined with Option A if the Lua script exposes a local socket that a coordinator process writes to.
|
||||
|
||||
---
|
||||
|
||||
## Option E — Memory bridge (Cheat Engine / FLE offsets)
|
||||
|
||||
**What it does:** Use known memory offsets (FLE's `offset_cache.json`) to read/write FUT state directly in FIFA23.exe's heap.
|
||||
|
||||
**Feasibility:** Medium — FLE already does this for career mode
|
||||
- FLE's `offset_cache.json` contains addresses for many game structures
|
||||
- FUT in-memory structs are separate from career structs and may not be mapped yet
|
||||
- This is fragile (offsets change with game updates)
|
||||
|
||||
**Not recommended** unless Options A and B both fail — too brittle.
|
||||
|
||||
---
|
||||
|
||||
## Recommendation
|
||||
|
||||
**Start with Option A (FLE Lua scripting).**
|
||||
|
||||
1. Run `tools/squad-exporter/export_squad.lua` in-game to discover which DB tables exist in FUT mode
|
||||
2. Use `tools/file-watch-diff/watch.sh` to snapshot file state entering FUT and identify any new local files
|
||||
3. Use `tools/network-metadata-logger/netlog.sh` to log which EA hosts FIFA contacts at FUT entry (metadata only, no decryption)
|
||||
4. Map findings back to openfut-core's data model
|
||||
5. Implement the Lua bridge script that calls openfut-core's REST API and writes to discovered tables
|
||||
|
||||
If FUT tables are not exposed by FLE's DB API (they may not be — FUT data lives server-side in online mode), fall back to **Option B** (career save injection) to provide a squad that mirrors the simulator's club.
|
||||
|
||||
---
|
||||
|
||||
## Safety boundary
|
||||
|
||||
The following are out of scope and must not be implemented:
|
||||
|
||||
- Decrypting or inspecting EA's TLS traffic
|
||||
- Spoofing EA domain names or impersonating EA servers
|
||||
- Sending modified clients to EA's production services
|
||||
- Bypassing EA App login or account verification
|
||||
- Anything that could constitute online cheating or violate EA's ToS for online play
|
||||
|
||||
All integration must remain local/offline/single-player.
|
||||
@@ -1,523 +0,0 @@
|
||||
# FIFA 17 — Clean Empty-My-Packs client fix (DESIGN / RESEARCH ONLY)
|
||||
|
||||
Status: **design only — no client binary/movie changes made.** This is the client-side
|
||||
follow-up to bug 6c. The backend already ships a compatibility workaround (P2, active
|
||||
non-openable sentinel 65534; see `docs/evidence/STORE_TILE_6C.md` §17 and
|
||||
`FIFA17_EMPTY_MYPACKS_CLIENT_CONTRACT.md`). This plan describes what a *client-side*
|
||||
fix would need to change so the backend shim can eventually become unnecessary for
|
||||
patched clients.
|
||||
|
||||
Do NOT patch the executable, DLLs, or Scaleform movies in this task.
|
||||
|
||||
## 1. Established client-side evidence
|
||||
|
||||
Binary: `CardsDLL_Win64_retail.dll`
|
||||
SHA-256 `4706a881ae1fc7b5769fd810b25a868d29d2b16a8e65a7513436327ef645573c`
|
||||
(dump load base `0x00006FFFFC120000`; RE-space base `0x180000000`). `FIFA17.exe`
|
||||
(`29c31cef…`) is Denuvo-packed (decrypts only in live memory).
|
||||
|
||||
Store category pipeline (all decompiled; see `docs/plan-2026-08-05-store-subsystem.md`):
|
||||
- `FUN_1800150d0` — builds display groups from `purchase[]`; a `mypacks` group exists
|
||||
iff some pack has `displayGroup.value=="mypacks"`. `group+0x104=(value=="mypacks")`,
|
||||
tiles in `group+0x40`, ordinal in `group+0x00` (1-based creation order).
|
||||
- `FUN_18007dab0` → `FUN_1800147f0(model, screen+0x290, …)` — renders/resolves a
|
||||
category. `screen+0x290==0` lists group tiles (`FUN_180014610`); otherwise
|
||||
`FUN_180014420` exact-matches the ordinal and **returns NULL on a miss**, after
|
||||
which `FUN_1800147f0` dereferences `[RAX+0x48]` with **no null guard** →
|
||||
**crash at `0x180014882`** (`ACCESS_VIOLATION` read of `0x48`, minidump-confirmed).
|
||||
- `screen+0x290` is written in exactly two CardsDLL sites: ctor `FUN_18007d1a0`
|
||||
writes `0`; **`FUN_18007e7f0` case `0x7551` copies the Flash movie message field
|
||||
`CATEGORY_ID` verbatim** into it. So the category is chosen by the Scaleform movie.
|
||||
- `FUN_18007e5e0` binds the six store tabs (`FUN_180014580`: `mypacks, points, bronze,
|
||||
silver, gold, special`) to `PANEL_ID` = matching group ordinal, or hides the panel.
|
||||
- Unopened-pack count signals (server, already correct at 0 when empty):
|
||||
`userInfo.unopenedPacks.recoveredPacks` and `/user/credits .unopenedPacks`. The hub
|
||||
`CentralUnclaimedPack` tile (destination `GOTO_STORE_MYPACK`) is gated by this count
|
||||
in the hub model (`model+0x20950`). **Candidate F (a server count gating the STORE's
|
||||
My-Packs resolution) was CONTRADICTED**: the count is correct at 0 yet the store
|
||||
still resolves My Packs, because the decision is movie-side.
|
||||
|
||||
## 2. Desired clean client behavior
|
||||
|
||||
```
|
||||
unopened-pack count == 0:
|
||||
Store defaults to Browse Packs (e.g. a real category such as bronze/gold)
|
||||
My Packs is NOT selected/resolved
|
||||
no synthetic placeholder tile is required from the server
|
||||
unopened-pack count > 0:
|
||||
existing My Packs behavior unchanged
|
||||
```
|
||||
|
||||
## 3. Candidate insertion points (ranked)
|
||||
|
||||
Ranking favors fixing the UX (not merely preventing the crash) and the smallest,
|
||||
lowest-risk change that achieves it.
|
||||
|
||||
### Rank 1 (preferred, best UX) — Scaleform / category-selection layer
|
||||
Prevent the movie from emitting `CATEGORY_ID == mypacks` (and from defaulting the
|
||||
store into My Packs) when the unopened-pack count is 0; default to Browse Packs
|
||||
instead.
|
||||
- **Where:** the FUT Store Scaleform movie / ActionScript (`StoreFront`,
|
||||
`CATEGORY_ID`/`ACTION_GET_PACKLIST`, `GOTO_STORE_MYPACK`), which the packed exe hosts
|
||||
and which reads the hub model (it already knows the count for the
|
||||
`CentralUnclaimedPack` tile).
|
||||
- **Behavior changed:** the store's initial/selected category when empty.
|
||||
- **Scope:** movie asset edit (client-side), no native-code patch.
|
||||
- **Risk:** medium — Scaleform RE/editing is fiddly; must find where the default
|
||||
`CATEGORY_ID` is chosen and gate it on the count without breaking the count>0 path.
|
||||
- **Compatibility:** per-client asset change; does not touch protocol or other clients.
|
||||
- **Fixes UX or just crash?** **UX** — no fake tile, correct default; the crash also
|
||||
disappears because `mypacks` is never resolved when absent.
|
||||
- **Evidence:** `screen+0x290 ← CATEGORY_ID` (`FUN_18007e7f0` case `0x7551`); count
|
||||
already available client-side (hub model / `unopenedPacks`).
|
||||
|
||||
### Rank 2 — Native Store resolver fallback (CardsDLL)
|
||||
Make `FUN_1800147f0`/`FUN_180014420` fall back to a safe category (e.g. list-tiles
|
||||
`N==0`, or the first existing group) when the requested ordinal misses, instead of
|
||||
dereferencing NULL.
|
||||
- **Behavior changed:** category-miss handling for ALL categories, not just mypacks.
|
||||
- **Scope:** small, localized CardsDLL binary patch near `0x180014420`/`0x180014882`.
|
||||
- **Risk:** medium — alters native store behavior globally; could mask other
|
||||
legitimate misses; the movie may still believe it is in My Packs (empty/odd view).
|
||||
- **Compatibility:** binary patch to the shipped DLL (client-side).
|
||||
- **Fixes UX or just crash?** Crash + partial UX (no crash, but the empty-My-Packs
|
||||
view may still be awkward).
|
||||
- **Evidence:** the no-guard deref at `0x180014882`; `FUN_180014420` returns NULL on
|
||||
miss.
|
||||
|
||||
### Rank 3 (cheapest, crash-only) — CardsDLL null guard
|
||||
Insert a null check before the `[RAX+0x48]` dereference in `FUN_1800147f0` (a single
|
||||
`TEST/JZ` around the deref) so a NULL group is skipped/returned safely.
|
||||
- **Behavior changed:** only the crash path.
|
||||
- **Scope:** minimal (a few bytes) binary patch at `~0x180014882`.
|
||||
- **Risk:** low — smallest change; but purely crash-prevention. With no `mypacks`
|
||||
group the resulting empty view is unverified (could be a blank/empty-category state).
|
||||
- **Compatibility:** binary patch (client-side).
|
||||
- **Fixes UX or just crash?** Crash only.
|
||||
- **Evidence:** minidump faulting instruction `CardsDLL+0x14882`, `[NULL+0x48]`.
|
||||
|
||||
## 4. Recommended long-term outcome
|
||||
|
||||
Rank 1 (Scaleform default-category gating) is the clean fix: with count 0 the store
|
||||
opens on Browse Packs, no `mypacks` resolution, no fake tile — and the **backend
|
||||
sentinel 65534 can be dropped for patched clients** (the server would simply omit the
|
||||
`mypacks` group when empty, which is safe once the client no longer resolves it).
|
||||
Rank 3 (null guard) is a cheap universal crash-safety net that could ship alongside.
|
||||
Until a client-side fix exists, the backend P2 sentinel remains the required
|
||||
compatibility behavior for unpatched retail clients.
|
||||
|
||||
## 5. Open questions / next research (no execution here)
|
||||
- Locate the Store movie's default/initial `CATEGORY_ID` selection and confirm it can
|
||||
read the unopened count (Rank 1 feasibility).
|
||||
- Confirm, via a guarded-resolver experiment, what the empty-My-Packs view degrades to
|
||||
if the `mypacks` group is simply absent + a null guard is present (Rank 2/3).
|
||||
- Determine whether the Browse-Packs→My-Packs navigation gate (observed with the
|
||||
active sentinel) also resolves under Rank 1.
|
||||
|
||||
---
|
||||
|
||||
# PART II — Native client-fix design (RE-backed, 2026-08-13)
|
||||
|
||||
Investigation-and-design phase (no client binary/movie changed, no backend changed,
|
||||
no new live Store experiment). CardsDLL was re-analysed in Ghidra on `.105`; the
|
||||
in-repo decompiled addresses were reconfirmed against a freshly-built project. Every
|
||||
claim below is labelled **ESTABLISHED** (read from this build's binary / crash dump),
|
||||
**PROPOSED** (design, not yet implemented), or **UNKNOWN**.
|
||||
|
||||
## 6. Binary + environment verification (ESTABLISHED)
|
||||
|
||||
Hashes re-verified on `.105` (`/mnt/games/FIFA 17/`) — identical to the recorded RE:
|
||||
- `CardsDLL_Win64_retail.dll` SHA-256 `4706a881ae1fc7b5769fd810b25a868d29d2b16a8e65a7513436327ef645573c`,
|
||||
size 3179952, PE `TimeDateStamp` 1497050156 (2017-06-09T23:15:56Z), `SizeOfImage`
|
||||
`0x31d000`, image base `0x180000000` (RE-space). **Unpacked → statically analysable.**
|
||||
- `FIFA17.exe` SHA-256 `29c31cef12b0c3c2a7305220617c7b4fa139ab76b8c857851bdbe88987962899`,
|
||||
size 224639408, **Denuvo-packed** → the Scaleform/StoreFront ActionScript that
|
||||
*decides* to emit `CATEGORY_ID` is NOT statically readable. This is why a
|
||||
pure-Scaleform edit (old "Rank 1") is not the practical vehicle; the fix is taken
|
||||
at the readable native boundary in CardsDLL instead.
|
||||
- Ghidra project rebuilt at `.105:/tmp/ghidra_fut/cardsdll` (headless import+analysis
|
||||
succeeded). Tooling: `fifa17-recon/tools/ghidra_env.py` run under `~/.venv`
|
||||
(`PYTHONPATH=/opt/ghidra/Ghidra/Features/PyGhidra/pypkg/src:/usr/lib/python3.14/site-packages`;
|
||||
`jpype1` reinstalled offline from pip cache). RVAs below = static VA − `0x180000000`.
|
||||
|
||||
## 7. Category-selection path (ESTABLISHED — decompiled this build)
|
||||
|
||||
Store message dispatch `FUN_18007d880` (RVA `0x7d880`) routes Flash message ids:
|
||||
`0x753f → FUN_18007dab0` (render), `0x278a → FUN_18007df60` (publish category ids),
|
||||
and the input handler `FUN_18007e7f0` (RVA `0x7e7f0`) case **`0x7551`** copies the
|
||||
movie field `CATEGORY_ID` verbatim into `screen+0x290` (the only non-ctor writer;
|
||||
ctor `FUN_18007d1a0` writes 0).
|
||||
|
||||
**Store render `FUN_18007dab0` (RVA `0x7dab0`), decompiled verbatim, is the decision
|
||||
point:**
|
||||
```c
|
||||
iVar1 = *(int *)(param_1 + 0x290); // requested CATEGORY_ID (screen+0x290)
|
||||
iVar6 = FUN_180014580(store, 1); // the *points* category id (see tab map)
|
||||
if (iVar1 == iVar6) { // requested category is POINTS (real-money)
|
||||
if (region_check() == 0) { post "REGION_MISMATCH"; return; }
|
||||
if (FUN_180014de0(store) != 0) return; // points group present → handled
|
||||
FUN_180014b60(store, dp); // else points render
|
||||
} else {
|
||||
FUN_1800147f0(store, iVar1, dp, 0, 0); // EVERY other category, incl. My Packs
|
||||
}
|
||||
```
|
||||
- `param_1` (RCX) = the store-screen object; `+0x290` is the requested category.
|
||||
- **Tab→id map `FUN_180014580(store, n)` (RVA `0x14580`): `0=mypacks, 1=points,
|
||||
2=bronze, 3=silver, 4=gold, 5=special`.** Each returns the group's **1-based
|
||||
ordinal** (via caption compare `FUN_180014380`) or **`-1`** if that group is absent.
|
||||
So category ids are DYNAMIC ordinals, not fixed constants. The tab publisher
|
||||
`FUN_18007df60` pushes `MYPACK_/BRONZE_/…_CATEGORY_ID` to the movie from these
|
||||
lookups; the movie echoes one back as `CATEGORY_ID`.
|
||||
- The **points** tab is the only one special-cased (commerce/region gate). **My Packs
|
||||
is NOT special-cased — it falls into the `else` and is resolved by
|
||||
`FUN_1800147f0`.**
|
||||
|
||||
**Resolver `FUN_1800147f0` (RVA `0x147f0`) — the crash (ESTABLISHED, instruction
|
||||
level):**
|
||||
```
|
||||
0x14856: 85 ff TEST EDI,EDI ; EDI = category ordinal (param_2)
|
||||
0x14858: 75 0f JNZ 0x14869 ; ==0 → list-all (Browse), else resolve
|
||||
0x1485a: … CALL 0x14610 ; FUN_180014610 list ALL group tiles
|
||||
0x14867: eb 29 JMP 0x14892
|
||||
0x14869: 8b d7 MOV EDX,EDI
|
||||
0x1486b: e8 … CALL 0x14420 ; FUN_180014420(store, ordinal) → RAX (group|NULL)
|
||||
0x14870: 48 8d 50 40 LEA RDX,[RAX + 0x40] ; RDX = group+0x40 (=0x40 when RAX=NULL)
|
||||
0x14878: 48 3b c2 CMP RAX,RDX
|
||||
0x1487b: 74 15 JZ 0x14892
|
||||
0x14882: 4c 8b 42 08 MOV R8,[RDX + 0x8] ; <-- FAULT: read [0x40+0x8]=0x48 when NULL
|
||||
0x14886: 48 8b 12 MOV RDX,[RDX] ; [0x40]
|
||||
```
|
||||
`FUN_180014420` (RVA `0x14420`) exact-matches `group+0x00` (ordinal), stride `0x108`,
|
||||
**returns NULL on a miss, with no guard in the caller** → faulting read of VA `0x48`
|
||||
at `0x180014882`. This is byte-for-byte the Experiment-B minidump
|
||||
(`0xC0000005` READ `0x48` at `CardsDLL+0x14882`).
|
||||
- `param_2 == 0` → `FUN_180014610` lists **all** group tiles = the safe "Browse Packs"
|
||||
view. `param_2 == existing ordinal` → resolves. `param_2 == a non-existent ordinal`
|
||||
(e.g. `-1`, which `MYPACK_CATEGORY_ID` becomes when the group is absent) → NULL → crash.
|
||||
|
||||
**Why it crashes with zero packs (ESTABLISHED):** with `unopenedPackIds==[]` and no
|
||||
sentinel, no `mypacks` group exists, so `FUN_180014580(store,0) = -1`,
|
||||
`MYPACK_CATEGORY_ID = -1`, the movie still selects My Packs and echoes `CATEGORY_ID =
|
||||
-1`, and `FUN_1800147f0(store, -1, …)` → `FUN_180014420(-1)=NULL` → crash. The active
|
||||
sentinel (65534) works only because it makes a real `mypacks` ordinal exist to resolve.
|
||||
|
||||
## 8. Zero-pack state client-side (ESTABLISHED)
|
||||
|
||||
The client already holds the correct unopened-pack count in a **data-manager
|
||||
singleton** (the same one the store resolver uses):
|
||||
- Obtain: `seed = FUN_1800d7170()` then `FUN_180009c80(&p, seed)` → `p` (release with
|
||||
`p->vtbl[0x08](p)`). This exact accessor already runs inside `FUN_180014420` and
|
||||
`FUN_1800147f0`, so any store-category hook can reach it.
|
||||
- **Read count: `p->vtbl[0x4d8](p)` → int. Write: `p->vtbl[0x4e0](p, n)`.** Confirmed
|
||||
in `FUN_180019780`, which reads slot `0x4d8`, adds the number of set booleans in a
|
||||
pack response, and writes slot `0x4e0` (it also fetches `FutGetPurchasedItems`).
|
||||
- Representation: plain `int`; **0 = no unopened packs**, `>0` = count. Lifetime: the
|
||||
singleton persists for the session; updated on pack acquire/open.
|
||||
- No dedicated "hasUnopenedPacks" boolean helper was found; `count != 0` is the
|
||||
predicate. (The hub `CentralUnclaimedPack` tile is gated by this same count via
|
||||
`model+0x20950`, written by `FUN_18010cdc0`/`FUN_18011e120` — the hub mirror, not the
|
||||
store gate.)
|
||||
|
||||
## 9. Implementation vehicle (ESTABLISHED — reuse, do not build a new loader)
|
||||
|
||||
OpenFUT **already ships a client hook framework**: `openfut-launcher/openfut-hook`
|
||||
(`crate-type=["cdylib"]`) builds **`version.dll`**, a proxy DLL placed in the game dir
|
||||
(`/mnt/games/FIFA 17/version.dll`, present & active; log `~/.wine/drive_c/openfut_hook.log`).
|
||||
- Load path: Wine/Windows loads `version.dll` from the app dir at process start →
|
||||
`DllMain(DLL_PROCESS_ATTACH)` → `install_hooks()`.
|
||||
- Existing hooks (`lib.rs`): `getaddrinfo` (IAT via `iat::resolve`), `connect`
|
||||
(inline detour), `WSAConnect`, `WSAIoctl`/ConnectEx, origin_spy registry/mutex,
|
||||
crypt32 `CertVerifyCertificateChainPolicy`, **and in-memory byte-patching of the
|
||||
loaded (packed) main exe + EAWebKit** (`ssl_patch`: `GetModuleHandleA` → scan for a
|
||||
unique prologue → `VirtualProtect`+`copy_nonoverlapping`).
|
||||
- Inline-hook primitive (`connect_hook`): `write_hook(target, dest)` lays a 14-byte
|
||||
`FF 25 00000000 <abs64>` JMP; `restore_original` restores saved bytes
|
||||
(unhook → call real → rehook, avoiding trampoline relocation).
|
||||
- Config: `openfut.cfg` beside the DLL (`host`/ports today; a `store_mypacks_fix`
|
||||
flag would be added there).
|
||||
- **Suitability for the Store fix: direct.** The DLL is in-process with full access
|
||||
to the loaded `CardsDLL_Win64_retail.dll`; the store fix is a NEW module
|
||||
(`store_hook.rs`) installed from `install_hooks`, reusing the `ssl_patch`
|
||||
signature-scan and the `connect_hook` inline-detour patterns. No new loader, no ASI,
|
||||
no separate injector.
|
||||
|
||||
## 10. Three strategies re-evaluated against the RE (Task 4)
|
||||
|
||||
### A. Category-selection redirect — **PREFERRED** (best UX, native, targeted)
|
||||
Hook `FUN_18007dab0` (RVA `0x7dab0`) at entry; before the original runs, redirect a
|
||||
zero-pack My-Packs request to Browse Packs:
|
||||
```
|
||||
cat = *(int*)(store + 0x290)
|
||||
mypacks_id = FUN_180014580(store, 0) // -1 when the group is absent
|
||||
if (cat == mypacks_id) { // movie asked for My Packs (incl. cat==-1==id)
|
||||
if (unopened_count() == 0) // singleton vtbl[0x4d8]
|
||||
*(int*)(store + 0x290) = 0; // 0 = FUN_180014610 list-all = Browse Packs
|
||||
}
|
||||
// then call the original FUN_18007dab0(store)
|
||||
```
|
||||
- Uses the real count? **Yes** (singleton `vtbl[0x4d8]`). Removes the fake 65534 tile?
|
||||
**Yes** (server can omit the group). Removes the click-dialog? **Yes** (no placeholder
|
||||
to click). Removes the Browse→My-Packs nav gate? **Yes** (store lands on Browse, not
|
||||
an empty My-Packs). Preserves count>0? **Yes** (`cat==mypacks_id` with count>0 is left
|
||||
untouched → normal My Packs). Affects other categories? **No** (`cat!=mypacks_id`
|
||||
path is unmodified; points/bronze/… unchanged).
|
||||
- Prevents the crash as a side effect (My Packs is never resolved when its group is
|
||||
absent). This is the old "Rank 1" INTENT, implemented at the readable native boundary
|
||||
instead of in packed Scaleform.
|
||||
|
||||
### B. Resolver fallback — acceptable safety net, less targeted
|
||||
In `FUN_1800147f0` (or right after the `CALL 0x14420` at RVA `0x1486b`): if the
|
||||
resolved group is NULL, fall back to list-all (`param_2=0`) instead of dereferencing.
|
||||
- Prevents crash? **Yes.** Fixes default nav / removes fake tile? **Partially** — the
|
||||
movie still believes it is in My Packs, so the view may be an empty/odd My-Packs
|
||||
rather than a clean Browse. Leaves other lookups unchanged? **It changes miss-handling
|
||||
for ALL categories** — a generic NULL fallback that could mask a genuine
|
||||
missing-category protocol bug. Higher risk than A for that reason; keep as a
|
||||
belt-and-braces guard, not the primary UX fix. The resolver does NOT know *why*
|
||||
`mypacks` is missing, which is exactly the concern the task flags.
|
||||
|
||||
### C. Null-guard only — weakest (crash-only)
|
||||
Insert `TEST RAX,RAX; JZ 0x14892` immediately after `CALL 0x14420` (RVA `0x1486b`),
|
||||
before `LEA RDX,[RAX+0x40]`. Needs a trampoline (no inline slack).
|
||||
- Converts the crash into whatever an empty tile-vector renders (unverified; likely a
|
||||
blank/empty category). Does **not** remove the fake tile or fix the default category;
|
||||
the sentinel would still be needed for acceptable UX. Verified as expected-weakest.
|
||||
|
||||
## 11. Concrete hook target for strategy A (Task 6, PROPOSED)
|
||||
```
|
||||
module: CardsDLL_Win64_retail.dll (GetModuleHandleA)
|
||||
function: FUN_18007dab0 (store render / message 0x753f)
|
||||
RVA: 0x7dab0 (static VA 0x18007dab0)
|
||||
calling conv: Microsoft x64 fastcall; single arg store-screen ptr in RCX
|
||||
screen offset: store+0x290 = requested CATEGORY_ID (int)
|
||||
helpers to call: FUN_180014580 (RVA 0x14580) tab→ordinal, arg0=RCX store, arg1=EDX index(0=mypacks)
|
||||
count singleton: FUN_1800d7170 (0xd7370-seed) + FUN_180009c80 (0x9c80), read vtbl[0x4d8]
|
||||
redirect target: set store+0x290 = 0 (FUN_180014610 list-all → Browse Packs)
|
||||
original behavior: zero packs → resolves absent mypacks ordinal → FUN_180014420 NULL → crash at 0x14882
|
||||
desired behavior: zero packs + mypacks requested → store+0x290 forced to 0 → Browse Packs; no crash/dialog/tile
|
||||
```
|
||||
Hook mechanics (reuse `connect_hook`): lay a 14-byte `FF 25` JMP at `base+0x7dab0` to a
|
||||
Rust `hooked_store_render(store)`; inside: apply the redirect, unhook, call real
|
||||
`FUN_18007dab0(store)`, rehook, return its value. Intercepting only the entry means the
|
||||
minimum interception is the 14 JMP bytes; the first instructions of `FUN_18007dab0`
|
||||
(`MOV RAX,RSP; MOV [RAX+8],RCX; PUSH …`) are a standard prologue safe to save/restore.
|
||||
Alt insertion point (earlier): `FUN_18007e7f0` case `0x7551`, where `CATEGORY_ID` is
|
||||
written to `screen+0x290` — redirect there instead of at render. Entry-hook of
|
||||
`FUN_18007dab0` is preferred (single, well-typed arg; runs once per store render).
|
||||
|
||||
Thread/context: the store screen runs on the client's UI/update thread; the hook reads
|
||||
one int and (rarely) writes one int on the same object the callee immediately reads —
|
||||
no new synchronization needed. Called for categories other than My Packs? The FUNCTION
|
||||
is, but the redirect body only fires when `cat==mypacks_id`, so other tabs are
|
||||
untouched.
|
||||
|
||||
## 12. Version / build safety (Task 7, PROPOSED)
|
||||
FIFA17-specific compat code MUST validate the client before hooking, and MUST no-op on
|
||||
any other build (the same `version.dll` is also used for FIFA23):
|
||||
1. **Module gate:** only proceed if `GetModuleHandleA("CardsDLL_Win64_retail.dll")`
|
||||
resolves (FIFA23 has no such module → auto-skip).
|
||||
2. **Build gate (both, belt-and-braces):**
|
||||
- Exact hash/PE gate: on-disk SHA-256 == `4706a881…`, or PE `SizeOfImage==0x31d000`
|
||||
&& `TimeDateStamp==1497050156` (cheap in-memory check).
|
||||
- Signature scan + validation: locate `FUN_18007dab0` by a unique prologue/byte
|
||||
window rather than trusting the RVA, and assert the known bytes at the branch
|
||||
(`85 ff 75 0f` region) and at the resolver `CALL 0x14420` site match before
|
||||
installing. Recommend **both**: hash to reject the wrong game fast, signature to
|
||||
confirm the exact patch site.
|
||||
3. **Failure behavior:** any check fails (unknown/updated build) → **do NOT patch**,
|
||||
log, and leave the **backend P2 active-sentinel (65534) as the fallback**. Never
|
||||
patch or crash an unrecognised build.
|
||||
|
||||
## 13. First controlled client experiment (Task 8, PROPOSED — not executed here)
|
||||
Goal: prove a patched client sends zero-pack Store entry to Browse Packs with **no**
|
||||
active placeholder.
|
||||
- Build `openfut-hook` with strategy-A `store_hook`, gated behind `openfut.cfg`
|
||||
`store_mypacks_fix=1` (opt-in; default off preserves today's behavior).
|
||||
- Test profile: `unopenedPackIds == []`.
|
||||
- Sequence (each variable changed alone; operator drives FIFA; read-only capture):
|
||||
1. Deploy patched `version.dll`; confirm `openfut_hook.log` shows the store hook
|
||||
installed + build gate PASSED.
|
||||
2. **Backend test mode (LATER, separately authorized — NOT in this task):** switch the
|
||||
backend to *empty-no-sentinel* (the Exp-B config that crashed the UNPATCHED client)
|
||||
so the patched client must handle a genuinely-absent `mypacks` group.
|
||||
3. Operator opens Store. **Predicted (patched + zero packs + no sentinel):** Store
|
||||
opens, defaults to Browse Packs, no `mypacks` resolve, **no crash, no dialog, no
|
||||
fake tile**.
|
||||
4. Set `unopenedPackIds=[70]`; reopen. **Predicted:** My Packs works normally
|
||||
(hook body skipped because count>0).
|
||||
5. Revert backend to the active sentinel.
|
||||
- **Backend change eventually required for this experiment: YES** — a controlled
|
||||
empty-no-sentinel test mode to force the absent group. It is NOT performed in this
|
||||
phase and MUST be separately authorized (same experiment discipline: patch the
|
||||
container copy, capture, revert, restart; never synthesize a client request).
|
||||
- **Client rollback:** flip `store_mypacks_fix=0` (hook not installed) or restore the
|
||||
original `version.dll`; the game reverts to depending on the backend sentinel. No FIFA
|
||||
binaries/movies/config are modified on disk — the hook is in-memory only, so rollback
|
||||
is a file/flag swap.
|
||||
|
||||
## 14. Interaction with the backend 65534 fallback (ESTABLISHED + PROPOSED)
|
||||
- **Keep the backend sentinel deployed** until strategy A is implemented AND verified.
|
||||
It remains the required behavior for unpatched retail clients and for any client whose
|
||||
build gate fails.
|
||||
- Once strategy A is verified, the server MAY, **for patched clients only**, omit the
|
||||
`mypacks` group when empty (the safe representation the client will then handle) —
|
||||
but only behind explicit detection/opt-in; do NOT drop the sentinel globally, since
|
||||
unpatched clients still crash without it.
|
||||
|
||||
## 15. ESTABLISHED / PROPOSED / UNKNOWN summary
|
||||
- **ESTABLISHED:** binary hashes/build; the full native category path and addresses
|
||||
(`FUN_18007d880/18007dab0/18007e7f0/1800147f0/180014420/180014580/180014610`); the
|
||||
instruction-level crash (`0x14882`, `[NULL+0x48]`); tab→ordinal map; that My Packs is
|
||||
not special-cased and funnels through `FUN_1800147f0`; the unopened-count singleton
|
||||
and its `vtbl[0x4d8]/[0x4e0]` accessors, reachable from store code; the
|
||||
`openfut-hook`/`version.dll` vehicle and its hook/patch primitives.
|
||||
- **PROPOSED (not implemented):** the strategy-A entry hook and its redirect logic; the
|
||||
build-guard scheme; the opt-in config flag; the first experiment and its backend
|
||||
test-mode requirement; the per-patched-client server relaxation.
|
||||
- **UNKNOWN:** exactly why the packed Scaleform movie selects My Packs on store open
|
||||
(Denuvo-packed, unread) — not needed for strategy A, which intercepts the native
|
||||
result; the precise rendered appearance of `category==0` list-all in this empty
|
||||
configuration (to be observed in the experiment); whether any non-store path also
|
||||
drives `screen+0x290` to a My-Packs ordinal (none found; `FUN_18007e7f0` case `0x7551`
|
||||
and the ctor are the only writers).
|
||||
|
||||
---
|
||||
|
||||
# PART III — Final no-sentinel resolver experiment (2026-08-13) — RESULT F3 (CRASH), CONFOUNDED
|
||||
|
||||
Vehicle change: the resolver guard was implemented as an **`autopatch.py` memory patch**
|
||||
(the live FIFA-17 client-patch mechanism), NOT the `version.dll` proxy — Proton loads its
|
||||
builtin `version.dll`, so the earlier `store_hook`/`version.dll` prototype was inert and
|
||||
has been rolled back. Guard: at CardsDLL `0x180014858`, `JNZ 0x14869` (`75 0f`) →
|
||||
`JG 0x14869` (`7f 0f`), orig-verified; routes category `< 0` (and `== 0`) to the safe
|
||||
list-all/Browse path (`FUN_180014610`), category `> 0` to the existing resolver.
|
||||
`TEST EDI,EDI` at `0x180014856` is the flag source (OF cleared ⇒ `JG` = signed `> 0`).
|
||||
|
||||
## Setup (verified)
|
||||
- CLIENT: guard active/enforced — live bytes `85 ff 7f 0f` at `0x180014856` (FIFA pid 547843,
|
||||
autopatch pid 547621; log `ENFORCED guarded store patch @ … (JNZ->JG)`, orig `75 0f` matched).
|
||||
- BACKEND: sentinel 65534 suppressed by a one-line `if not owned_ids:` → `if False:` in the
|
||||
container copy only (committed source `f42279f` untouched; backup `/tmp/utas_server.EXP_ORIG.py`).
|
||||
Genuine `GET /store/purchasegroup` (02:44:39Z) → ids `[1,5,6,7]`, **no 65534, no mypacks group**,
|
||||
normal packs unchanged (evidence: `docs/evidence/store_purchasegroup_capture_client_guard_no_sentinel_2026-08-13.json`).
|
||||
- PROFILE: `unopenedPackIds=[]`, coins 29,876,776, sha `39bb3e83…` — unchanged throughout.
|
||||
|
||||
## Result — F3 (CRASH)
|
||||
Minidump `CrashDump_2026.08.12_20.44.40.302.dmp` (preserved `/tmp/expF_crash.dmp`, sha `4dcb0cb7…`):
|
||||
`0xC0000005` READ of VA `0x48` at `ExceptionAddress 0x6ffffc224882` → **RE `0x180014882`** —
|
||||
the **identical** resolver crash instruction as Experiment B (`FUN_1800147f0`,
|
||||
`MOV R8,[RDX+0x8]` with the group ptr NULL).
|
||||
|
||||
**Mechanism (decisive):** `0x14882` lives in the *resolve* branch, which the guard's `JG`
|
||||
reaches **only when category `> 0`**. Since the guard was verified in place, the client
|
||||
presented a **positive** My-Packs ordinal that no longer resolves (no mypacks group) →
|
||||
`FUN_180014420` returned NULL → crash. The guard's design assumption — *absent mypacks ⇒
|
||||
category `-1`* — did NOT hold on this path.
|
||||
|
||||
## Confound (uncontrolled variable)
|
||||
FIFA was **not relaunched** after the backend flipped to no-sentinel; the client carried
|
||||
**stale store/tab state** from the sentinel-present safe stage, where the mypacks group
|
||||
existed at a *positive* ordinal `N` (`MYPACK_CATEGORY_ID = N`). Reopening the Store reused
|
||||
that stale positive ordinal rather than the `-1` a **fresh** launch publishes
|
||||
(`FUN_18007df60 → FUN_180014580(store,0) = -1` when absent). So the intended clean A/B (client
|
||||
only ever sees the no-sentinel response) was not achieved — the category that reached the
|
||||
resolver was a stale `>0`, exactly the case the negative-only guard does not divert.
|
||||
|
||||
## Conclusion / strategy status
|
||||
- **The guard as-written does NOT handle a positive, now-invalid My-Packs ordinal** — proven
|
||||
by this crash. Diverting only `category < 0` is insufficient when the client presents a
|
||||
stale/positive ordinal for an absent group.
|
||||
- **Not falsified for the fresh-client case.** Whether a fresh no-sentinel launch presents
|
||||
`-1` (guard diverts → Browse, no crash) or still a positive ordinal is **UNKNOWN** and needs
|
||||
a **clean re-test**: launch FIFA fresh with the backend already in no-sentinel mode so the
|
||||
client never sees a mypacks group. That is the proper equivalent of Experiment B.
|
||||
- **Candidate stronger guard** (design only, not implemented): divert to list-all when the
|
||||
resolved group is NULL for *any* category (guard `FUN_180014420`'s NULL return at the
|
||||
`0x14870`/`0x14882` site), not merely when `category < 0`. This covers the positive-invalid
|
||||
ordinal too, at the cost of being a generic miss-fallback (the higher-risk Rank-2 behavior).
|
||||
Do NOT implement without authorization and a clean re-test first.
|
||||
|
||||
**Strategy A / resolver guard status: NOT PROVEN.** Crash-guard installs and is build-validated
|
||||
and dormant-safe with the sentinel present, but the first no-sentinel test CRASHED at the
|
||||
resolver via a positive stale ordinal (confounded by no relaunch). Backend P2 active-sentinel
|
||||
was restored immediately (mandatory rollback; source `f416e71e…`, sentinel `state=active`),
|
||||
and remains the production safety net. Guard left in `autopatch.py` (dormant) pending the
|
||||
clean re-test decision; `autopatch.py.pre-storeguard.bak` available to remove it.
|
||||
|
||||
---
|
||||
|
||||
# PART IV — Fresh-process no-sentinel retest (2026-08-13) — RESULT R1 (SUCCESS)
|
||||
|
||||
Corrects PART III's confound. This time the mandatory ordering was enforced: the backend
|
||||
entered no-sentinel mode **while FIFA was closed**, then FIFA launched **fresh** (new pid,
|
||||
new autopatch) so the process never saw a sentinel-present Store response.
|
||||
|
||||
## Setup (verified, clean A/B)
|
||||
- BACKEND set no-sentinel at 02:55:09Z with FIFA down; genuine `GET /store/purchasegroup`
|
||||
(02:58:45Z) served to the fresh client = ids `[1,5,6,7]`, **no 65534, no mypacks group**,
|
||||
packs 1/5/6/7 present. This body is **byte-identical** to the PART III (F3) no-sentinel
|
||||
capture — the ONLY changed variable vs F3 is the client process lifetime.
|
||||
Evidence: `docs/evidence/store_purchasegroup_capture_freshretest_no_sentinel_2026-08-13.json`.
|
||||
- CLIENT: NEW FIFA pid 553220, NEW autopatch pid 552999; guard ENFORCED (orig `75 0f`
|
||||
matched → `85 ff 7f 0f` = `TEST EDI,EDI; JG`). Process never saw a sentinel response
|
||||
(0 purchasegroup responses containing 65534 after the no-sentinel restart).
|
||||
- PROFILE unchanged throughout (`39bb3e83…`, `[]`, coins 29,876,776).
|
||||
|
||||
## Result — R1 (operator-observed)
|
||||
- **No crash** (FIFA 553220 alive after the test; no new minidump), **no dialog**, **Store
|
||||
stays open**, opens on **Browse Packs**, Bronze/Gold/Special packs visible and navigable.
|
||||
- Cosmetic-only imperfections (pre-existing, NOT caused by the guard): the six-tab bar is
|
||||
unbound (no tabs), packs render without cover art, and tiles show "0 items". These match
|
||||
the known store tab-bind / list-all rendering quirks (`plan-2026-08-05-store-subsystem.md`
|
||||
§2.1) and are independent of the resolver guard.
|
||||
|
||||
## Causal conclusion (decisive A/B)
|
||||
```
|
||||
server response (no sentinel, no mypacks group) == byte-identical across F3 and R1
|
||||
client original JNZ + this response -> CRASH 0x180014882 (Experiment B)
|
||||
client JG (stale positive ordinal) -> CRASH 0x180014882 (PART III F3, contaminated)
|
||||
client JG (FRESH, category = -1) -> NO CRASH, Browse Packs (PART IV R1) ✅
|
||||
```
|
||||
A **fresh** client publishes `MYPACK_CATEGORY_ID = FUN_180014580(store,0) = -1` for the absent
|
||||
group; the movie echoes `-1`; `TEST EDI,EDI; JG` does **not** take the resolve branch, so the
|
||||
client runs the list-all/Browse path (`FUN_180014610`) — no `FUN_180014420(NULL)` deref, no
|
||||
crash. **PART III's F3 is confirmed as stale-positive-ordinal contamination** (FIFA not
|
||||
relaunched across the sentinel→no-sentinel flip), not a guard failure.
|
||||
|
||||
## Strategy status
|
||||
**Strategy A / resolver guard: PROVEN ON THE TESTED FIFA 17 BUILD** (CardsDLL
|
||||
`4706a881…`) for the clean process-lifetime case — it safely routes the absent My-Packs
|
||||
category to Browse Packs with no crash and no dialog, needing **no** backend sentinel. Scope
|
||||
caveats: (1) tested build only; (2) the negative-only guard does NOT cover a stale/positive
|
||||
invalid ordinal (PART III) — only arises if the client's Store state predates a sentinel→
|
||||
no-sentinel change within one process, which does not happen on a normal launch; a NULL-return
|
||||
guard at `FUN_180014420` would additionally cover that, deferred/not implemented; (3) UX still
|
||||
has the pre-existing no-tabs/no-art/"0 items" cosmetics.
|
||||
|
||||
Backend P2 active-sentinel was restored immediately after capture (mandatory rollback; source
|
||||
`f416e71e…`, sentinel `state=active`) and **remains production default**. The clean UX is only
|
||||
safe to serve when the server knows the client is patched — see PART II §12 rollout options
|
||||
(recommend B: suppress the sentinel only when client patch-capability is known; keep the
|
||||
sentinel universal by default). Guard retained in `autopatch.py` (dormant with the sentinel).
|
||||
|
||||
## INVARIANT — empty-My-Packs capability MUST be session-stable
|
||||
|
||||
F3 vs R1 establish a hard operational invariant for any deployment (sentinel or client
|
||||
guard): **the server MUST NOT switch a running FIFA client between sentinel-present and
|
||||
sentinel-absent for the My Packs group within a single FIFA process lifetime.**
|
||||
|
||||
Rationale: the client resolves and caches the My-Packs group **ordinal** (positive when a
|
||||
group — real or sentinel — is present; `-1` when absent) from the `purchasegroup` response
|
||||
seen at Store-subsystem init. The resolver guard only reclassifies the ordinal *sign*
|
||||
(`≤0` → Browse). If a client that already cached a **positive** ordinal later receives a
|
||||
no-sentinel topology, the stale positive ordinal still takes the resolve branch and
|
||||
`FUN_180014420` returns NULL → crash at `0x180014882` (exactly F3). A **fresh** process that
|
||||
only ever sees the no-sentinel topology caches `-1` and is routed to Browse safely (R1).
|
||||
|
||||
Practical rules:
|
||||
- Choose the My-Packs representation (sentinel-present vs sentinel-absent) **before** a client
|
||||
starts its session, and hold it for that session.
|
||||
- The future patch-capability handshake (PART II §12) MUST therefore be decided at
|
||||
login/session start, not toggled mid-session.
|
||||
- A NULL-return guard at `FUN_180014420` (deferred) is the only thing that would make a
|
||||
mid-session flip crash-safe; until then, session stability is mandatory.
|
||||
@@ -1,358 +0,0 @@
|
||||
# FIFA 17 — verified patched-client capability negotiation
|
||||
|
||||
Goal: let the FIFA 17 backend suppress the synthetic My-Packs sentinel (id 65534)
|
||||
**only when the current FIFA process has positively verified that the CardsDLL
|
||||
resolver guard is active** (JNZ→JG at RVA `0x14858`). Unpatched / unsupported /
|
||||
unknown / failed-patch clients keep receiving the existing P2 active sentinel.
|
||||
|
||||
Core principle: **the capability is not "this launcher supports the patch"; it is
|
||||
"the resolver guard was verified in *this particular FIFA process*."**
|
||||
|
||||
This document is the design + the cross-component contract. It is deliberately
|
||||
additive: the P2 active-sentinel path (`docs/evidence/FIFA17_EMPTY_MYPACKS_CLIENT_CONTRACT.md`)
|
||||
remains the default and the universal fallback.
|
||||
|
||||
---
|
||||
|
||||
## 1. Architecture inventory (as-built, verified by reading the code)
|
||||
|
||||
Data flow today (launch of one FIFA process):
|
||||
|
||||
```
|
||||
LauncherApp::launch_game (openfut-launcher/src/app.rs:450)
|
||||
-> account_sync::sync POST /openfut/account/sync (:8099) [REQUIRED; launch is gated on it]
|
||||
-> ensure_local_services() spawn LSX, then autopatch.py --launcher-pid <launcher_pid>
|
||||
-> game_launch::launch umu-run FIFA17.exe (grandchild; launcher never learns FIFA PID)
|
||||
FIFA process
|
||||
-> autopatch.py self-discovers FIFA by comm=='FIFA17.exe'; patches /proc/<pid>/mem each tick
|
||||
-> FIFA -> backend POST /ut/auth (login) ; GET /store/purchasegroup ; ... (:8099)
|
||||
```
|
||||
|
||||
Facts that shape the design:
|
||||
|
||||
- **Launcher ↔ autopatch IPC = one-way stdout only.** `local_services::spawn`
|
||||
(openfut-launcher/src/local_services.rs:279-296) pipes autopatch stdout/stderr
|
||||
into the launcher `LogBuffer` line-by-line as `[autopatch] <line>`. There is no
|
||||
socket / named pipe / status-file readback. `--launcher-pid` is the *launcher's*
|
||||
own pid (local_services.rs:66), used for liveness, not to identify FIFA.
|
||||
- **Launcher ↔ backend = exactly one control call:** `account_sync::sync`
|
||||
(openfut-launcher/src/account_sync.rs:43) — a tiny stdlib-HTTP `POST
|
||||
/openfut/account/sync` on `openfut_account_sync_port` (default 8099), sent once
|
||||
per launch, *before* FIFA starts, and **launch is blocked unless it succeeds**
|
||||
(utas_server.py:1204). This is the reliable per-FIFA-process session boundary.
|
||||
- **Backend is single-account, stateless-per-request, threaded.** `SID` is a fixed
|
||||
module constant shared by all clients (utas_server.py:32); account identity is one
|
||||
global `ACCOUNT` singleton. There is **no per-session identity** in requests. The
|
||||
only per-connection discriminator available at every handler is
|
||||
`self.client_address[0]` (peer IP), currently unused. Server is
|
||||
`ThreadingHTTPServer` (utas_server.py:3784); module is import-safe (server under
|
||||
`if __name__ == "__main__"`).
|
||||
- **No bridge/proxy in the FIFA-17 path.** FIFA reaches the Python backend's
|
||||
published `:8099` directly (client-side DNAT/hosts redirect); the openfut-bridge is
|
||||
legacy FIFA-23. Docker's iptables DNAT preserves the source IP for external LAN
|
||||
clients. The launcher and FIFA run on the **same** client machine, so the backend
|
||||
observes them under the **same** peer IP regardless of NAT.
|
||||
|
||||
## 2. Capability transport — options and choice
|
||||
|
||||
Ranked against the as-built architecture:
|
||||
|
||||
**autopatch → launcher (chosen: structured stdout line).**
|
||||
1. **Structured stdout line (CHOSEN).** Reuses the existing one-way pipe the
|
||||
launcher already reads. It is *live* (only the current autopatch child's stdout),
|
||||
inherently child-bound, and carries **zero stale-file risk** — a previous
|
||||
launch's capability cannot leak because nothing is persisted. Smallest possible
|
||||
change. Format is a machine-readable token (§4).
|
||||
2. Status file in `$XDG_RUNTIME_DIR` keyed by launcher-pid+FIFA-pid+version+timestamp
|
||||
— works but needs explicit staleness handling and cleanup; more moving parts.
|
||||
3. Unix-domain socket — most capable but overkill; there is no bidirectional need.
|
||||
|
||||
**launcher → backend (chosen: sibling HTTP endpoint on the account-sync port).**
|
||||
- A. **Existing session-init channel (CHOSEN).** Add `POST /openfut/fifa17/capability`
|
||||
next to the existing `/openfut/account/sync` (same port 8099, same tiny stdlib-HTTP
|
||||
client). It cannot ride *inside* account_sync because the capability is only known
|
||||
*after* autopatch verifies (which happens after account_sync + FIFA start), so it is
|
||||
a separate, later call — but on the same proven transport.
|
||||
- B. Blaze/login metadata — rejected: no OpenFUT-owned field is available without
|
||||
risking a field FIFA depends on, and Blaze runs in a separate responder.
|
||||
- C. New local IPC + backend side-channel — unnecessary; A already exists.
|
||||
- D. Server-wide "assume patched" config — dev/testing fallback only; cannot
|
||||
distinguish patched vs unpatched clients, so never the production mechanism.
|
||||
|
||||
## 3. The capability (name + version + VERIFIED semantics)
|
||||
|
||||
- Name: **`fifa17.empty_mypacks_resolver`**, integer version, current **`1`**.
|
||||
- **VERIFIED (v1) means, for THIS FIFA process:** the CardsDLL tested build was
|
||||
recognised AND the live bytes at RVA `0x14858` are `7f 0f` (`JG`) **after
|
||||
autopatch enforcement** — i.e. `guarded_action` returned `"patch"` (was `75 0f`,
|
||||
written, re-read as `7f 0f`) **or** `"noop"` (already `7f 0f`).
|
||||
- It explicitly does **NOT** mean any of: "autopatch.py contains the guard code",
|
||||
"the launcher build is new enough", or "a config flag is set". The signal
|
||||
represents **observed runtime enforcement on the specific process**, nothing less.
|
||||
|
||||
## 4. autopatch verification state + emitted line
|
||||
|
||||
Per-FIFA-pid guard status (fail-closed; never loosens the existing byte guard):
|
||||
|
||||
| state | meaning |
|
||||
|---|---|
|
||||
| `NOT_ATTEMPTED` | CardsDLL not yet mapped / guard not evaluated for this pid |
|
||||
| `VERIFIED` | live bytes == `7f 0f` after enforcement (from `patch` or `noop`) |
|
||||
| `UNSUPPORTED_BUILD` | live bytes are neither the known original nor patched (`guarded_action` → `skip`) |
|
||||
| `WRITE_FAILED` | `/proc/<pid>/mem` write raised |
|
||||
| `VERIFY_FAILED` | post-write re-read != `7f 0f` |
|
||||
|
||||
Only `VERIFIED` advertises capability. On transition to `VERIFIED`, autopatch emits
|
||||
**once per FIFA pid** on stdout:
|
||||
|
||||
```
|
||||
[store-guard] verified capability fifa17.empty_mypacks_resolver=1 fifa_pid=<pid>
|
||||
```
|
||||
|
||||
Any non-verified terminal state emits an explicit, non-advertising status line, e.g.:
|
||||
|
||||
```
|
||||
[store-guard] guard status=UNSUPPORTED_BUILD fifa_pid=<pid> (no capability advertised)
|
||||
```
|
||||
|
||||
## 5. Launcher per-process capability state
|
||||
|
||||
```rust
|
||||
pub struct Fifa17ClientCapabilities { pub empty_mypacks_resolver: Option<u32> }
|
||||
```
|
||||
|
||||
- Starts **UNKNOWN** (`None`) at each launch.
|
||||
- Becomes `Some(1)` when the launcher parses a valid capability line from the
|
||||
**current** autopatch child's stdout (`parse_capability_line`).
|
||||
- **Discarded** when autopatch stops / FIFA exits / launcher exits / next launch. It
|
||||
is never persisted and never reused for a later FIFA process — staleness is
|
||||
structurally impossible.
|
||||
|
||||
On first `Some(v)`, the launcher registers the capability with the backend (§6) once.
|
||||
|
||||
## 6. Launcher → backend registration + binding
|
||||
|
||||
`POST /openfut/fifa17/capability` (port = `openfut_account_sync_port`, 8099), body:
|
||||
|
||||
```json
|
||||
{"capability":"empty_mypacks_resolver","version":1,"personaId":<id>,"fifaPid":<pid>}
|
||||
```
|
||||
|
||||
- **Binding key = source IP** (`self.client_address[0]`). The registration arrives
|
||||
from the client machine's IP; FIFA's `/store/purchasegroup` requests arrive from
|
||||
the **same** IP (same machine). `personaId`/`fifaPid` are for logging only (the
|
||||
backend is single-account, so persona cannot discriminate clients).
|
||||
- Concurrency: distinct client machines → distinct peer IPs → independent decisions
|
||||
(no global state). Two FIFA processes on **one** machine share an IP — an accepted
|
||||
limitation (the backend is single-account anyway); documented in §Trust.
|
||||
|
||||
## 7. Backend session-stable decision
|
||||
|
||||
Per-IP record (guarded by a lock; threaded server):
|
||||
|
||||
```
|
||||
_FIFA17_STORE[ip] = {"resolver": Option[int], "mode": Option[str]} # mode: None|"sentinel"|"clean-v1"
|
||||
```
|
||||
|
||||
- **Reset (session boundary):** `/openfut/account/sync` from `ip` sets
|
||||
`{resolver: None, mode: None}`. This is the launcher's required per-launch call, so
|
||||
every new FIFA process starts from a clean, unfrozen record — no cross-process leak.
|
||||
- **Register:** `/openfut/fifa17/capability` from `ip` sets `resolver = version`. If
|
||||
`mode` is already frozen, it is logged as late and **ignored for this session**.
|
||||
- **Freeze point = first `/store/purchasegroup`** from `ip` (§9): if `mode is None`,
|
||||
set `mode = "clean-v1"` iff `resolver == 1` else `"sentinel"`, and log once.
|
||||
Thereafter `mode` is immutable for the session.
|
||||
- **Default / fail-closed:** an IP with no record (no account-sync, no capability),
|
||||
an unknown resolver version, a late capability, or a disappeared capability all
|
||||
resolve to (or remain) `"sentinel"`.
|
||||
|
||||
## 8. Freeze point rationale
|
||||
|
||||
Freeze at **first `/store/purchasegroup`**, not at login/account-sync. account-sync
|
||||
fires *before* FIFA starts and *before* autopatch can verify, so freezing there would
|
||||
always be `sentinel`. First Store request is the earliest moment at which a genuine
|
||||
capability can already be registered (autopatch verifies at process start; the user
|
||||
opens the Store later), while still being a single, well-defined topology commit for
|
||||
the session. Once Store topology is served, it must not change (the F3 experiment
|
||||
proved a mid-session flip can leave a stale positive ordinal that crashes even the
|
||||
sign-only guard — see `FIFA17_EMPTY_MYPACKS_CLIENT_FIX.md` PART III/IV and the
|
||||
SESSION-STABLE invariant).
|
||||
|
||||
## 9. Store behaviour (additive switch)
|
||||
|
||||
At `store_catalog`, only the zero-owned-packs branch changes:
|
||||
|
||||
```
|
||||
if not owned_ids:
|
||||
if fifa17_empty_mypacks_mode(client_ip) == "clean-v1":
|
||||
pass # patched client: emit NO mypacks group; guard routes -1 to Browse
|
||||
else:
|
||||
<append active 65534 sentinel exactly as today> # P2 fallback (unchanged)
|
||||
```
|
||||
|
||||
Untouched: real owned-pack rendering, `PACK_CATALOG`, pack 70, normal packs 1/5/6/7,
|
||||
profile state, all store env flags. Default remains sentinel. This lives in the FIFA-17
|
||||
Python backend only — **never** in game-independent OpenFUT Core.
|
||||
|
||||
| client | zero packs | real unopened pack |
|
||||
|---|---|---|
|
||||
| verified v1 | **no sentinel** (clean) | genuine My Packs, no sentinel |
|
||||
| no / unknown capability | **active 65534 sentinel** | genuine My Packs, no sentinel |
|
||||
|
||||
## 10. Trust model (Task 14)
|
||||
|
||||
This is **not** anti-cheat / attestation. OpenFUT assumes the user controls the
|
||||
launcher/client machine and the server is a private preservation environment. The
|
||||
verification exists to prevent *accidents*: a stale capability, an unsupported
|
||||
CardsDLL build, a failed autopatch, the wrong process, or an unpatched client
|
||||
receiving no sentinel and crashing. No signatures / PKI / remote attestation.
|
||||
|
||||
Isolation across *distinct client machines* relies on the backend observing distinct
|
||||
peer IPs (source-IP-preserving publish; Docker's default for external LAN via iptables
|
||||
DNAT). Two FIFA processes on one machine cannot be distinguished by IP — accepted,
|
||||
since the backend is single-account. The single-client production case is unaffected
|
||||
by NAT because launcher and FIFA share one IP.
|
||||
|
||||
## 11. Fail-closed matrix (Task 15) — every failure ⇒ sentinel
|
||||
|
||||
autopatch missing / not run · guard `UNSUPPORTED_BUILD` / `WRITE_FAILED` /
|
||||
`VERIFY_FAILED` · launcher cannot parse the line · registration POST fails ·
|
||||
account-sync never called · unknown capability version · capability arrives after
|
||||
freeze · capability disappears after a sentinel freeze — **all resolve to the active
|
||||
65534 sentinel.** Asserted by tests (matrix A–J) and this document.
|
||||
|
||||
## 12. P2 retained (Task 16)
|
||||
|
||||
The active-sentinel implementation is **not** removed. It is the else-branch of the
|
||||
switch and the universal default for unpatched clients, unsupported builds, failed
|
||||
patches, unknown launchers, and late capabilities. The clean path is purely additive.
|
||||
|
||||
---
|
||||
|
||||
## 13. Session binding (hardening — supersedes the per-IP prototype)
|
||||
|
||||
**History.** The first implementation keyed the backend capability/store-mode by
|
||||
**source IP alone** (§7 as originally written). That was rejected before deployment:
|
||||
two FIFA processes that share a source IP — concurrent, or a relaunch — would share
|
||||
the key, so an *unverified* process could inherit a *verified* one's `clean-v1`
|
||||
topology and crash on the empty-My-Packs resolver. Source IP is now **auxiliary only**
|
||||
(logging, a fail-closed sid/ip sanity check, and the pending hand-off key). This
|
||||
history is retained deliberately; do not treat per-IP as the design.
|
||||
|
||||
**Authoritative key = the per-login UTAS session id (`X-UT-SID`).** `/ut/auth` now
|
||||
mints a fresh unique SID per login (was a shared constant `OPENFUT-SID-…0001`); the
|
||||
client echoes it on every later call, and it is **live-confirmed present on real
|
||||
`/store/purchasegroup` requests**. The SID uniquely identifies one FIFA process/login:
|
||||
a relaunch re-auths → new SID; two concurrent logins → two SIDs. The legacy constant
|
||||
is still accepted by the retired security-question gate only, and is **never** used to
|
||||
grant `clean-v1`. A store request whose SID was opened on a different source IP is
|
||||
fail-closed to sentinel (sid/ip sanity check).
|
||||
|
||||
**Why not persona alone:** the backend is single-account, so `personaId` cannot
|
||||
distinguish two sessions, and a relaunch keeps the same persona — persona alone would
|
||||
leak a prior session's mode. Persona is used only (with IP) to key the pending hand-off.
|
||||
|
||||
### State machine (per session, keyed by SID)
|
||||
```
|
||||
Capability : Unknown | ResolverV1
|
||||
StoreMode : Unfrozen | Sentinel | CleanV1
|
||||
|
||||
/ut/auth (new SID) : Capability=Unknown, StoreMode=Unfrozen, record {ip,persona}
|
||||
+ consume any pending (ip,persona) -> Capability=ResolverV1
|
||||
capability registered : bind to the one live Unfrozen/Unbound session for (ip,persona)
|
||||
-> Capability=ResolverV1 ; else stage single-use pending ;
|
||||
else (a session exists but is frozen/ambiguous) -> ignored-late
|
||||
first /store/purchasegroup : Unfrozen + ResolverV1 -> freeze CleanV1
|
||||
Unfrozen + otherwise -> freeze Sentinel (consume pending first)
|
||||
late capability : StoreMode already frozen -> unchanged (ignored-late, not staged)
|
||||
capability lost/cleared : after a CleanV1 freeze -> stays CleanV1 (mode is cached)
|
||||
session idle > TTL / reaped: session discarded (a later store with that SID -> Sentinel)
|
||||
```
|
||||
|
||||
### Registration order + pending hand-off
|
||||
The verified capability is known only after the FIFA process exists, CardsDLL is
|
||||
loaded, and autopatch confirms the JG bytes — which may land before or after
|
||||
`/ut/auth`, but reliably before the user opens the Store. The launcher cannot know
|
||||
the SID, so its registration is matched to a session by (source_ip, persona) as a
|
||||
**single-use, short-TTL pending** (`FIFA17_PENDING_TTL = 120s`) that is consumed by
|
||||
exactly one session, at whichever of these happens first for that session: its
|
||||
`/ut/auth` (pending predates login), the registration itself (session already live —
|
||||
bound directly), or its first store request (lazy). If the Store is reached before a
|
||||
capability binds, the session freezes **Sentinel** (fail-closed); a later capability
|
||||
does not change it.
|
||||
|
||||
### Session cleanup (Task 10)
|
||||
- **creation:** at `/ut/auth`.
|
||||
- **last activity:** bumped on every `/store/purchasegroup` for the session.
|
||||
- **freeze:** first `/store/purchasegroup`.
|
||||
- **expiry:** lazy sweep on every session op removes sessions idle for
|
||||
`FIFA17_SESSION_TTL = 3600s` and pendings older than `FIFA17_PENDING_TTL`. Explicit
|
||||
Blaze/UTAS teardown is not reliably observable at this handler, so a conservative
|
||||
activity-based TTL is used instead. Reaping only removes *expired* entries and never
|
||||
affects another live session from the same IP/persona (keyed by distinct SIDs).
|
||||
|
||||
### Residual limitation (documented, fail-closed)
|
||||
FIFA carries no launcher-controllable per-process token, so two **simultaneous** logins
|
||||
from the **same (ip, persona)** cannot be disambiguated at the instant a capability is
|
||||
registered while *both* are Unfrozen/Unbound. That ambiguous case resolves to
|
||||
`ignored-late` → **both freeze Sentinel** (safe: an unverified process is never granted
|
||||
clean). The normal one-launcher-per-FIFA and sequential-relaunch flows bind correctly
|
||||
(proven by matrix K/L/M). This is a UX conservativeness, never a safety hole.
|
||||
|
||||
---
|
||||
|
||||
## 14. Deployment candidate & controlled A/B (overnight reconciliation 2026-08-13)
|
||||
|
||||
**Launcher lineage reconciliation.** The two divergent launcher histories (merge
|
||||
base `87241ac`) were reconciled by a real merge — **not** a rebase/squash/rewrite —
|
||||
in a clean worktree:
|
||||
- `feat/launcher-arming` `13339c1` (client arming + FIFA-17 capability reporting)
|
||||
- `feat/sbc-hook-tracing` `958ff24` (openfut-hook SBC request tracing / RE probes)
|
||||
|
||||
Merged commit **`ca7ce26`** on branch `integration/fifa17-launcher-capability-sbc`
|
||||
retains **both** ancestors (`git merge-base --is-ancestor` true for both `958ff24`
|
||||
and `13339c1`). The only conflict was `src/process.rs` (launcher-arming deleted it +
|
||||
dropped `mod process`; SBC only incidentally tidied it) — resolved **keep-deleted**
|
||||
(orphan module; the SBC feature lives entirely in `openfut-hook/*`). The two features
|
||||
are in disjoint crates/processes (launcher-crate Rust host vs `openfut-hook` Windows
|
||||
DLL) and share no stdout readers, child handles, or lifecycle — no integration code
|
||||
was needed.
|
||||
|
||||
**Gitlink status — DEFERRED (morning blocker).** The superproject gitlink still
|
||||
records the pre-reconciliation `958ff24`. It was **not** bumped to `ca7ce26` because
|
||||
the live submodule checkout carries uncommitted `openfut-hook/*` WIP that overlaps the
|
||||
merged hook content; a non-destructive `git checkout ca7ce26` is refused ("local
|
||||
changes would be overwritten"), and no `-f`/`reset`/`clean` is permitted. The user
|
||||
must first reconcile that WIP against the merged `openfut-hook`, then the gitlink can
|
||||
bump. Preservation artifact: `/tmp/openfut-launcher-overnight-tracked.patch`
|
||||
(sha256 `8e65de2c…`).
|
||||
|
||||
**Validated deployment-candidate tuple** (reproducible from git except the deferred
|
||||
gitlink):
|
||||
```
|
||||
superproject HEAD a82407c (backend per-session + docs)
|
||||
backend guard b0d5e04 fix(fifa17): guard missing store category resolution
|
||||
client proof fc29c2e docs(fifa17): record no-sentinel client resolver proof
|
||||
autopatch report 1c396dd feat(fifa17): report verified client patch capability
|
||||
backend negotiate b25761e feat(fifa17): negotiate clean empty My Packs mode
|
||||
session binding 805d754 fix(fifa17): isolate patched-client capability per session
|
||||
launcher merged HEAD ca7ce26 merge: reconcile launcher capability and SBC tracing
|
||||
(ancestors 13339c1 capability + 958ff24 SBC)
|
||||
launcher gitlink (super) 958ff24 <-- to become ca7ce26 once WIP reconciled
|
||||
```
|
||||
Local build artifacts (NOT deployed): launcher `target/release/openfut-launcher`
|
||||
(sha256 `a390c61d…`); backend image `openfut-fut-backend:candidate-overnight`
|
||||
(`84d280be…`, ships `utas_server.py` `33e0ef3…`). Live `:dev` image and the running
|
||||
container were left untouched.
|
||||
|
||||
### Controlled A/B sequence (execute only in a later authorized deploy task)
|
||||
**A — patched client:** fresh FIFA process → autopatch verifies the JG guard →
|
||||
launcher parses the verified line and registers → `/ut/auth` mints a fresh `X-UT-SID`
|
||||
→ capability binds to that SID → first `/store/purchasegroup` freezes `clean-v1` →
|
||||
backend omits 65534 → Store opens on Browse Packs, no crash.
|
||||
**B — unpatched client, same machine/IP, NEW session:** new `X-UT-SID`, no verified
|
||||
capability → first store freezes `sentinel` → backend emits active 65534 → no crash.
|
||||
Proves same-IP isolation + fail-closed fallback.
|
||||
**C — failed patch (optional):** autopatch reports `UNSUPPORTED_BUILD`/`VERIFY_FAILED`
|
||||
→ launcher never registers → `sentinel`.
|
||||
Production remains the P2 active-sentinel universal default until this A/B passes.
|
||||
@@ -1,208 +0,0 @@
|
||||
# OpenFUT Status Review
|
||||
*Generated 2026-06-30 — read-only stocktake, no code changed.*
|
||||
|
||||
---
|
||||
|
||||
## Executive Summary
|
||||
|
||||
OpenFUT has a mature offline FUT economy backend (Core, 25 phases, fully functional in
|
||||
isolation) and a sophisticated hook DLL that loads into FIFA 23, redirects EA hostnames
|
||||
to loopback, and bypasses TLS certificate verification. The Blaze/ProtoSSL layer is
|
||||
structurally ready: framing code exists, a TLS listener runs, cert-verify is patched.
|
||||
However the project is currently blocked before any Blaze traffic is ever seen.
|
||||
The fundamental problem is that FIFA 23 submits `GoOnline` to EbisuSDK and then
|
||||
**waits for an asynchronous ONLINE_STATUS_EVENT push** from the EA-app LSX server —
|
||||
a push that current code never sends. Every approach tried so far (flipping poll
|
||||
return values, forcing the state flags, read-only probes) confirms the gate is
|
||||
event-driven, not poll-driven. The Blaze captures directory contains six empty files.
|
||||
No Fire2 frame from FIFA 23 has ever been decoded. Until the ONLINE_STATUS_EVENT push
|
||||
is synthesized and delivered correctly, Milestones 2–7 are all waiting on the same
|
||||
single wall.
|
||||
|
||||
---
|
||||
|
||||
## 1. Proven vs Assumed
|
||||
|
||||
| Claim | Status | Evidence |
|
||||
|---|---|---|
|
||||
| FIFA 23 uses DirtySDK / ProtoSSL | **Proven** | String scan hit `ProtoSSLSend`, `ProtoSSLRecv`, `gosredirector` in FIFA23.exe memory (Task 1) |
|
||||
| `version.dll` loads and runs hook code | **Proven** | `hook.log` written at DLL_PROCESS_ATTACH |
|
||||
| `getaddrinfo` IAT hook redirects EA domains to loopback | **Proven** | Hook log records every EA `getaddrinfo` call; connect_hook log confirms port redirects |
|
||||
| ProtoSSL cert-verify prologue found and patched (FIFA23.exe) | **Proven** | ssl_patch.rs prologue confirmed at file offset 0xf0c850; hook log "ssl: main exe cert-verify patched" |
|
||||
| ProtoSSL cert-verify patched in EAWebKit.dll | **Proven** (if loaded) | Lazy patch fires on first EA getaddrinfo call; hook log message confirms |
|
||||
| Gate is upstream of DirtySDK — no DNS/connect fires on FUT entry | **Proven** | getaddrinfo, connect, WSASend/Recv hooks all show zero external traffic during "connecting to EA Servers" |
|
||||
| `GoOnline` is called by the game | **Proven** | Read-only detour on `anadius64.dll+0x2BB90` confirmed hit |
|
||||
| anadius returns GoOnline success | **Proven** | Handler observed returning successfully; game still retries every ~7 s |
|
||||
| Gate is downstream of GoOnline | **Proven** | GoOnline called + returns success; no Blaze connect follows |
|
||||
| Connection-state function: `GetInternetConnectedState @ anadius64.dll+0x27790` | **Proven** | Located via anadius LSX command-registration table; two-flag branch decoded (`+0xCAB1A`, `+0xCAB1B`) |
|
||||
| Gate is event-driven (game waits for async push, not a poll return) | **Proven** | Forced both state flags AND GoOnline return to "1"; game kept retrying; worker-thread stack scan confirms handler runs on anadius IOCP thread, not FIFA's thread |
|
||||
| GoOnline runs on anadius worker thread, not FIFA's call thread | **Proven** | Stack scan from inside detour found zero FIFA23.exe frames, sp ~2.4 KB from thread stack top |
|
||||
| `protossl-scan` live toolkit is exhausted for finding GoOnline in FIFA23.exe | **Proven** | No `"GoOnline"` string in image; worker-thread call stack has no FIFA frames; jmpscan yields ~3875 hits (overwhelmingly data false positives) |
|
||||
| FIFA 23 redirector config references `Authorization:` header (Nucleus token) | **Proven** | Found in FIFA23.exe .rdata pointer table @ `+0x83FC858` |
|
||||
| openfut-core REST API complete and tested | **Proven** | 25 phases, 15 migrations, passing integration tests |
|
||||
| Bridge LSX server starts and handles request-response | **Proven** (code) | `openfut-bridge/src/lsx.rs` + `main.rs` — server starts on 127.0.0.1:3216 |
|
||||
| Bridge LSX server ACTUALLY receives FIFA's LSX connections | **UNCONFIRMED** | anadius may intercept the same calls in-process before the TCP connection reaches the bridge |
|
||||
| Bridge LSX server `GetInternetConnectedState → connected="1"` unblocks the gate | **UNCONFIRMED (known to fail in-process)** | Flipping the value via anadius in-process failed; bridge path not yet confirmed working |
|
||||
| ONLINE_STATUS_EVENT push XML format | **UNKNOWN** | No capture; format not derived |
|
||||
| Fire2 framing is correct for FIFA 23 | **UNCONFIRMED** | Implemented based on post-2012 EA convention; all blaze captures are empty (0 bytes) |
|
||||
| Blaze component / command IDs for FIFA 23 | **UNKNOWN** | Zero captures; dispatch table entirely empty placeholders |
|
||||
| ProtoSSL recv-injection convention (non-blocking return values etc.) | **UNCONFIRMED** | Never reached M4; recv_hook module removed from active install path |
|
||||
| FUT REST endpoint paths in mapper.rs | **SPECULATIVE** | Based on community knowledge of older FIFA titles; the one actual capture in `captures/` is an early GET from before the Blaze strategy |
|
||||
| FLE Lua API exposes FUT DB tables in memory | **UNKNOWN** | `export_squad.lua` has never been run; FUT data may only exist server-side in online mode |
|
||||
|
||||
---
|
||||
|
||||
## 2. Milestone Status
|
||||
|
||||
| Milestone | Status | Blocker | Depends on unconfirmed assumption? |
|
||||
|---|---|---|---|
|
||||
| **M1** — Locate connection-state decision point | ✅ Done | — | No |
|
||||
| **M2** — Flip gate, force "connected" | ⛔ Blocked | Game waits for async ONLINE_STATUS_EVENT push; no current code sends it | Yes — unknown event XML format |
|
||||
| **M3** — First ProtoSSL plaintext on Blaze connection | 🔲 Not started | Depends on M2 | Yes — Fire2 framing unconfirmed |
|
||||
| **M4** — Answer redirector + decode first Fire2 frame | 🔲 Not started | Hard wall: Fire2 framing, recv-injection convention, component/command IDs all unconfirmed | Yes — all three unknown |
|
||||
| **M5** — Blaze preauth / login / postauth | 🔲 Not started | Depends on M4 | Yes — Blaze auth TDF body layout unknown |
|
||||
| **M6** — FUT entry + hub load | 🔲 Not started | Depends on M5; also requires FUT REST response shapes confirmed | Yes — endpoint paths speculative |
|
||||
| **M7** — Squad Battles (AI FUT) | 🔲 Not started | Depends on M6 | Yes |
|
||||
|
||||
**Note on roadmap.md wording:** Under M2–M4, roadmap.md uses `**Done (observable):**` bullets. These describe the *success criterion* for each milestone, not an achieved state. The authoritative status is in `connection-gate-findings.md` (M2 attempts failed; M3/M4 never started). The roadmap has not been updated to reflect M2 failure.
|
||||
|
||||
### M4 is the first hard wall in detail
|
||||
|
||||
Even assuming M2 is solved, M4 requires three unconfirmed things simultaneously:
|
||||
1. **Fire2 framing** — the 12-byte header layout is assumed; if FIFA 23 uses an older Fire variant or a custom delta, the codec will misparse every packet.
|
||||
2. **ProtoSSL recv-injection** — delivering responses to the game via recv hook requires knowing what return values and buffer conventions ProtoSSL expects; recv_hook.rs exists but is not installed.
|
||||
3. **Blaze component/command IDs** — the dispatch table is entirely empty; we cannot answer any request until IDs are known from captures.
|
||||
|
||||
All three are resolved by getting one real captured frame. M4 is primarily a capture problem, not a decoding problem — once bytes exist, the framing and IDs are immediately readable.
|
||||
|
||||
---
|
||||
|
||||
## 3. Blockers, Risks, Unknowns
|
||||
|
||||
### Blockers (stop progress now)
|
||||
|
||||
1. **ONLINE_STATUS_EVENT push not synthesized** *(M2 wall)*
|
||||
The game calls GoOnline, gets success, then waits indefinitely for a push event on the LSX socket that never arrives. This is the single gate blocking all Blaze work. Options: (a) trace the event format via Ghidra on FIFA23.exe (xref `ONLINE_STATUS_EVENT` string + the game's EbisuSDK listener), (b) RE anadius's LSX event-send path (find what it would push in an "online" scenario), (c) brute-force push candidate event XMLs and observe whether the game advances.
|
||||
|
||||
2. **Bridge LSX server delivery unconfirmed** *(architectural risk converted to blocker)*
|
||||
The hook passes port 3216 connections through, assuming the bridge LSX server on the Linux host receives them. If anadius's in-process hooks intercept the winsock calls before they reach the TCP stack, the bridge server is never reached. This must be confirmed by checking `openfut_hook.log` for a getaddrinfo on the LSX host, or by observing the bridge server's accept logs.
|
||||
|
||||
### Risks (could derail later)
|
||||
|
||||
3. **Fire2 framing wrong** *(M4 risk)*
|
||||
If FIFA 23 uses Fire (pre-2012) or a modified frame layout, the codec misparses. Mitigation: the server has a `Raw` fallback mode for capturing raw bytes when framing fails.
|
||||
|
||||
4. **Secondary auth-token gate** *(M5 risk)*
|
||||
`connection-gate-findings.md` noted the redirector request carries an `Authorization:` header. M1's final conclusion said `GetAuthCode` returns a fake token that appears accepted — but this was inferred, not confirmed by seeing the redirector request actually constructed with that token.
|
||||
|
||||
5. **EAAC not fully neutralized** *(persistent risk)*
|
||||
`FakeEAACLauncher` bypasses the anticheat launcher. The hook DLL is unsigned. If EAAC is ever active (e.g., after a game update re-enables it), all hooks fail silently. Marked as "not active in offline/cracked builds" — assumed, not confirmed on every launch.
|
||||
|
||||
6. **FUT REST response shapes wrong** *(M6 risk)*
|
||||
The 61 endpoint mappings in mapper.rs and the shaper stubs in shaper.rs are based on community guesses about older FIFA FUT APIs, not FIFA 23 captures. Response JSON shapes may differ enough to cause the client to fail silently or crash.
|
||||
|
||||
### Unknowns (open questions)
|
||||
|
||||
7. **ONLINE_STATUS_EVENT XML format** — exact tag names, field order, sender attribute, and any nonces/tokens required.
|
||||
8. **GoOnline event sequence** — whether ONLINE_STATUS_EVENT alone is sufficient or a sequence of events (e.g., PROFILE_EVENT, LOGIN_EVENT, COMMERCE_EVENT) is expected.
|
||||
9. **Whether FLE exposes FUT DB tables** — FUT card inventory and squad data likely live server-side in online mode; FLE may not surface them for in-process editing.
|
||||
10. **Blaze component/command IDs for FIFA 23** — entirely unknown; no captures.
|
||||
11. **openfut_hook.log current content** — we have the code but no log output in any document. Whether the current hook (with connect, ssl_patch, tls_bypass, WSAIoctl, origin_spy all installed) fires correctly and what it observes is unverified in this review.
|
||||
|
||||
---
|
||||
|
||||
## 4. Track Comparison
|
||||
|
||||
### Track A — Full EA-backend fake (M1–M7, playable FUT vs AI)
|
||||
|
||||
**What it delivers:** The FIFA 23 FUT hub loads from OpenFUT Core; Squad Battles matches play and reward economy items.
|
||||
|
||||
**Effort:** Research-grade. Minimum path: synthesize ONLINE_STATUS_EVENT (unknown format, 1–2 weeks of RE), then capture Fire2 frames (days once M2 is solved), then implement Blaze auth handlers (weeks), then implement FUT entry (weeks), then Squad Battles (weeks). Realistic minimum: 3–6 months of expert RE work.
|
||||
|
||||
**Proven support:** Hook loads and redirects correctly. TLS bypass patched. Core economy backend complete. Blaze framing code and TLS listener exist.
|
||||
|
||||
**Assumed:** Fire2 framing correct; component/command IDs discoverable from captures; FUT REST shapes close enough to community guesses; no additional undiscovered gates.
|
||||
|
||||
**Evidence for:** Architecture is coherent. The M1 finding (gate precisely named and decoded) was achieved cleanly. The in-process hook approach is validated.
|
||||
|
||||
**Evidence against:** M2 was attempted and failed with the in-process approach. The event-driven architecture adds a full EbisuSDK emulation layer before even one Blaze byte is seen. The live toolkit is exhausted (Path A verdict); Ghidra-level work on a 505 MB binary is required. Six capture files with zero bytes.
|
||||
|
||||
---
|
||||
|
||||
### Track B — Clean-room spec deliverable (M1–M5 documented)
|
||||
|
||||
**What it delivers:** A documented map of the connection gate, LSX event sequence, Blaze auth surface (transport, framing, gate conditions, component IDs, TDF schemas). Valuable as an archival/community artifact even if Track A stalls.
|
||||
|
||||
**Effort:** Medium. M1 is done. M2–M5 documentation emerges as a by-product of engineering work. The spec itself (writing) is lightweight; the engineering to produce the captures is the cost.
|
||||
|
||||
**Proven support:** M1 complete and documented. connection-gate-findings.md is already a high-quality spec artifact.
|
||||
|
||||
**Assumed:** Same as Track A for the unconfirmed values, but the spec can mark them `TODO/CONFIRM` rather than needing to implement them.
|
||||
|
||||
**Evidence for:** The clean-room constraint means a spec is the only artifact that can be safely published. connection-gate-findings.md shows this approach produces real value. B finishes even if A is never fully playable.
|
||||
|
||||
**Evidence against:** Track B alone doesn't produce a playable FUT; it is a foundation, not an end-user product.
|
||||
|
||||
---
|
||||
|
||||
### Track C — FLE Lua bridge (local-match path, skip the backend gate)
|
||||
|
||||
**What it delivers:** FIFA 23 career mode or Kick-Off with an OpenFUT club's players and squad loaded via FLE's in-memory DB API. No online gate, no Blaze, no TLS. Fully offline from day one.
|
||||
|
||||
**Effort:** Low-to-medium. FLE is already loaded in the normal launch path. Tools exist (`tools/squad-exporter/`, `tools/profile-exporter/`). Primary unknown is whether FUT-relevant DB tables are accessible.
|
||||
|
||||
**Proven support:** FLE Lua API exposes `GetDBTableRows` / `EditDBTableField` for career mode. `fifa23-startup-flow.md` confirms FLE injects at load. `fut-integration-options.md` documents the integration path in detail and rates this as the recommended option.
|
||||
|
||||
**Assumed:** FUT card/club/squad data has in-memory DB table representations that FLE can write. If FUT data is purely server-side (loaded from EA servers, not from the Frostbite DB layer), Track C produces no FUT simulation at all — only career mode player stats.
|
||||
|
||||
**Evidence for:** Career mode already works with FLE edits (community precedent). Tools are present and designed for this path. No infrastructure work needed.
|
||||
|
||||
**Evidence against:** FUT in FIFA 23 uses server-side data. The cards in a player's FUT club, the coins, the squad — these are fetched from `fut.ea.com` REST APIs, not from the Frostbite embedded DB. FLE's `GetDBTableRows` likely exposes base player stats tables but not FUT item tables. The crucial test (run `export_squad.lua` while in FUT mode) has never been done.
|
||||
|
||||
---
|
||||
|
||||
### Recommendation
|
||||
|
||||
**Start Track C immediately as a parallel, low-cost validation.**
|
||||
|
||||
Run `export_squad.lua` in FLE while inside the FUT hub (or attempting to enter it). If FUT tables appear in the export, Track C is viable and is the fastest path to something a user can interact with. This test takes one session and costs nothing.
|
||||
|
||||
Simultaneously, **continue Track A/B with the next concrete RE step:** synthesize the ONLINE_STATUS_EVENT push. The most actionable option is to run `origin_spy` logs from the current hook to see what LSX events fire during a session, then attempt to push candidate event XMLs via the bridge LSX server and watch whether the game advances. This is bounded, testable work that either unblocks M2 or produces the spec value for Track B.
|
||||
|
||||
**Do not abandon Track A/B for Track C** — they are complementary. Core is already built; the bridge is mostly built. The gap is purely the RE wall at M2.
|
||||
|
||||
---
|
||||
|
||||
## 5. Architecture and Provenance Sanity-Check
|
||||
|
||||
### Hook + Brain coherence
|
||||
|
||||
The CLAUDE.md bridge architecture diagram (hook intercepts ProtoSSL → plain localhost TCP → blaze_brain → Core) remains coherent. The M1/M2 findings revealed one additional layer (EbisuSDK LSX event) that must precede the Blaze connection. The bridge has been updated to handle LSX directly. The overall design is sound; the M2 blocker is an implementation gap (event synthesis), not an architectural flaw.
|
||||
|
||||
**One inconsistency to flag:** The hook's `lsx.rs` contains a complete in-process LSX emulator (AES-128-ECB, CRandom, all response builders), but the recv/send hooks that activate it are explicitly removed (`lib.rs`: "recv/send hooks removed — LSX is now handled by the native openfut-bridge LSX server"). This is dead code. The bridge's LSX server is the current path. The in-process lsx.rs should either be deleted or documented as a fallback; its presence is confusing.
|
||||
|
||||
### Clean-room status
|
||||
|
||||
No evidence of EA leaked source anywhere in the tree. All RE work is derived from:
|
||||
- Running the shipping binary and observing behavior (function return values, network traffic patterns)
|
||||
- Memory scanning of the live process (string search, xref, disasm of observed addresses)
|
||||
- Reading anadius's own compiled output (its exported symbols, its LSX XML format — which is anadius's own implementation, not EA's)
|
||||
- Community FUT API knowledge (mapper.rs endpoint paths — plausible but speculative)
|
||||
|
||||
The Blaze framing in `fifa-blaze/crates/blaze-proto/src/frame.rs` cites "Fire2 used by ME3, BF3, and most post-2012 titles" — this is sourced from public community documentation of those older titles, not from any leaked EA source. **Clean-room intact.**
|
||||
|
||||
The `AES_KEY` in the hook's lsx.rs (`[0,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15]`) is a placeholder key used for the LSX session encryption. The real session key is derived from the challenge seed via CRandom — this algorithm was RE'd from anadius's own binary. No EA source required.
|
||||
|
||||
---
|
||||
|
||||
## 6. If You Read Only This
|
||||
|
||||
- **The project is blocked at M2.** FIFA 23 submits `GoOnline`, gets success, then waits for an async `ONLINE_STATUS_EVENT` push on the LSX socket that no current code ever sends. All six Blaze capture files are empty (0 bytes). No Fire2 frame has ever been decoded.
|
||||
|
||||
- **M1 is the only completed milestone.** The gate function (`GetInternetConnectedState @ anadius64.dll+0x27790`) is precisely named and its two-flag branch decoded. Everything after M1 is either blocked or not started.
|
||||
|
||||
- **The next concrete action** is synthesizing the ONLINE_STATUS_EVENT push XML and testing whether the bridge's LSX server can deliver it to the game. This is the single thing that unblocks all Blaze work.
|
||||
|
||||
- **Track C (FLE Lua) is untested but cheap to validate.** Run `export_squad.lua` while in FUT to find out if FUT DB tables are accessible. If yes, it is the fastest path to user-visible results. If no, it is ruled out with one session.
|
||||
|
||||
- **openfut-core is complete and ready** — 25 phases, 15 migrations, full economy REST API, passing tests. It is not blocking anything; it is waiting for the bridge to connect to it.
|
||||
@@ -1,93 +0,0 @@
|
||||
# Track C — FUT DB table viability test
|
||||
|
||||
**Status: PENDING — test has not yet been run.**
|
||||
|
||||
## What this test settles
|
||||
|
||||
Track C ("FLE Lua bridge") would inject OpenFUT club data directly into FIFA 23's
|
||||
in-memory Frostbite DB tables at runtime, bypassing the entire backend/Blaze stack.
|
||||
It is only viable for FUT (not just career mode) if FUT-specific tables — card
|
||||
inventory, squad composition with FUT fields, coins — are accessible in memory when
|
||||
the game is in the FUT area.
|
||||
|
||||
FUT data in online mode is fetched server-side from `fut.ea.com`. It is not known
|
||||
whether FIFA 23 mirrors any of this into the Frostbite in-memory DB that FLE
|
||||
can read/write. This test settles that question directly.
|
||||
|
||||
## Test procedure
|
||||
|
||||
**Prerequisites:**
|
||||
- FIFA 23 launched normally via umu-run/Steam
|
||||
- FLE (FIFA Live Editor) injected and active (normal launch path)
|
||||
- EAAC in offline/neutralized state
|
||||
- Game navigated as deep into FUT as possible (FUT hub if reachable; otherwise the
|
||||
furthest FUT screen before the gate blocks it)
|
||||
|
||||
**Run the exporter:**
|
||||
1. In FLE's Lua Engine, open and run `tools/squad-exporter/export_squad.lua`
|
||||
(full path on the Windows side: `C:\<game>\openfut_squad_export.json`)
|
||||
2. Wait for the MessageBox "Done! N players, M teams." or "ERROR writing..."
|
||||
3. Retrieve the output file from the Wine prefix:
|
||||
`~/Games/umu/fifa23-tools/drive_c/FIFA 23 Live Editor/openfut_squad_export.json`
|
||||
(or wherever `C:\FIFA 23 Live Editor\` maps in the active prefix)
|
||||
|
||||
**What to inspect in the output:**
|
||||
- `all_db_tables` array — the complete list of table names visible to FLE right now
|
||||
- `fut_tables` object — any table whose name contains `fut`, `club`, `pack`, `item`, or
|
||||
`market` (the script auto-extracts these)
|
||||
- `is_career_mode` — confirms whether FUT or career mode was active
|
||||
|
||||
## Classification criteria
|
||||
|
||||
### "FUT tables present"
|
||||
|
||||
`fut_tables` is non-empty AND contains FUT-specific fields beyond base player stats:
|
||||
- e.g., `fut_items` with card-type / rating / chemistry fields
|
||||
- e.g., a squad table with FUT formation / chemistry / loan-flag fields
|
||||
- e.g., a coins or points balance field
|
||||
|
||||
**Verdict:** Track C is viable for FUT. Fastest path to user-visible results.
|
||||
|
||||
### "only base player tables"
|
||||
|
||||
`fut_tables` is empty (no `fut_*` / `club_*` / `item_*` / `market_*` table names found
|
||||
in `all_db_tables`), OR those tables exist but contain only base player attributes
|
||||
(OVR, potential, position, pace, …) — the same fields visible in career mode.
|
||||
|
||||
**Verdict:** Track C cannot produce FUT. It could at most provide a custom Kick-Off or
|
||||
career-mode match with players sourced from OpenFUT Core. FUT items and coins exist
|
||||
only on EA's servers (not in the in-memory DB in offline mode).
|
||||
|
||||
### "FUT area unreachable to test"
|
||||
|
||||
The connection gate blocked entering FUT deeply enough for FUT tables to be populated.
|
||||
Record which tables were visible and at what screen the test was run.
|
||||
|
||||
**Verdict:** Retest after M2 is unblocked, OR test with `TLS_ENABLED=false` bridge
|
||||
handling the entry check stub.
|
||||
|
||||
## Results
|
||||
|
||||
*(To be filled in after the test is run.)*
|
||||
|
||||
| Field | Value |
|
||||
|---|---|
|
||||
| Date run | — |
|
||||
| FIFA screen at test time | — |
|
||||
| `is_career_mode` | — |
|
||||
| Total tables in `all_db_tables` | — |
|
||||
| FUT-specific table names found | — |
|
||||
| Key FUT fields present | — |
|
||||
| **Classification** | **PENDING** |
|
||||
|
||||
## Honest prior
|
||||
|
||||
`fut-integration-options.md` rates this as the recommended path and lists `fut_clubs`,
|
||||
`fut_items`, `fut_squads` as "expected" tables. However those expectations are based on
|
||||
analogy with career mode (which does store club/squad in the DB). FUT's data model is
|
||||
architecturally different — it is account-bound server-side. The expectation may be
|
||||
wrong. This test is the oracle.
|
||||
|
||||
The `export_squad.lua` script checks `GetDBTablesNames()` exhaustively (not just
|
||||
assumed names), so it will surface any FUT tables that actually exist, regardless of
|
||||
what name they use.
|
||||
+1
-1
Submodule fifa-blaze updated: d2a9a01ec9...f4f33969f2
@@ -37,17 +37,25 @@ RUN set -eu; \
|
||||
|
||||
COPY data/ /app/data/
|
||||
|
||||
# Redirector TLS cert (CN/SAN = winter15.gosredirector.ea.com). ProtoSSL
|
||||
# cert-verify is patched client-side, so a self-signed cert is fine. The pair is
|
||||
# git-ignored (*.pem/*.key); regenerate if absent so a fresh checkout builds
|
||||
# without extra steps.
|
||||
# Redirector/roster TLS cert (CN/SAN = winter15.gosredirector.ea.com). ProtoSSL
|
||||
# cert-verify is patched client-side, so a self-signed cert is fine — but the
|
||||
# client dials the roster and redirector BY IP, and that path still checks the
|
||||
# SAN against the dialed address (it is NOT covered by the two patched gates), so
|
||||
# a cert without a matching IP SAN is rejected with fatal certificate_unknown
|
||||
# (docs/FIFA17_FUT_SQUAD_UPDATE_TLS.md). The advertised LAN IP is a RUNTIME value,
|
||||
# unknown here, so this bakes only a loopback-IP baseline and the entrypoint
|
||||
# reissues with IP:$OPENFUT_ADVERTISE at start.
|
||||
#
|
||||
# openssl therefore has to remain in the image for the entrypoint, not be dropped
|
||||
# with the apt lists. The pair is git-ignored (*.pem/*.key); regenerate if absent
|
||||
# so a fresh checkout builds without extra steps.
|
||||
RUN apt-get update && apt-get install -y --no-install-recommends openssl && \
|
||||
rm -rf /var/lib/apt/lists/*
|
||||
RUN if [ ! -s tools/redir_cert.pem ] || [ ! -s tools/redir_key.pem ]; then \
|
||||
apt-get update && apt-get install -y --no-install-recommends openssl && \
|
||||
openssl req -x509 -newkey rsa:2048 -nodes \
|
||||
-keyout tools/redir_key.pem -out tools/redir_cert.pem \
|
||||
-days 3650 -subj "/CN=winter15.gosredirector.ea.com" \
|
||||
-addext "subjectAltName=DNS:winter15.gosredirector.ea.com,DNS:*.gosredirector.ea.com,DNS:*.ea.com" && \
|
||||
rm -rf /var/lib/apt/lists/*; \
|
||||
-addext "subjectAltName=DNS:winter15.gosredirector.ea.com,DNS:*.gosredirector.ea.com,DNS:*.ea.com,IP:127.0.0.1"; \
|
||||
fi
|
||||
|
||||
# Bake a dataset manifest so every image is self-identifying.
|
||||
|
||||
@@ -28,6 +28,26 @@ export POW_CONTENT_ADDR="${POW_CONTENT_ADDR:-$BIND:8080}"
|
||||
|
||||
echo "[openfut] bind=$BIND advertise=$ADV"
|
||||
|
||||
# The TLS cert every responder serves must carry the ADVERTISED IP in its SAN.
|
||||
# The client dials the roster (:8081) and redirector by that IP, and that path
|
||||
# validates the cert's SAN against the dialed address — it is NOT covered by the
|
||||
# two client-side ProtoSSL gates autopatch patches, so a cert lacking IP:$ADV is
|
||||
# rejected with fatal certificate_unknown and the FUT hub fails with "An error
|
||||
# occurred downloading the FUT Squad Update" (docs/FIFA17_FUT_SQUAD_UPDATE_TLS.md).
|
||||
# The advertised IP is unknown at image-build time, so reconcile it here: reissue
|
||||
# only when the current cert does not already carry it, so a restart reuses the
|
||||
# same cert (no per-start fingerprint churn) and this self-heals if $ADV changes.
|
||||
CERT=redir_cert.pem KEY=redir_key.pem
|
||||
if ! openssl x509 -in "$CERT" -noout -ext subjectAltName 2>/dev/null | grep -qF "IP Address:$ADV"; then
|
||||
echo "[openfut] reissuing TLS cert with SAN IP:$ADV (was missing it)"
|
||||
openssl req -x509 -newkey rsa:2048 -nodes -keyout "$KEY" -out "$CERT" -days 3650 \
|
||||
-subj "/CN=winter15.gosredirector.ea.com" \
|
||||
-addext "subjectAltName=DNS:winter15.gosredirector.ea.com,DNS:*.gosredirector.ea.com,DNS:*.ea.com,IP:$ADV,IP:127.0.0.1" \
|
||||
>/dev/null 2>&1 \
|
||||
&& echo "[openfut] cert SAN now: $(openssl x509 -in "$CERT" -noout -ext subjectAltName 2>/dev/null | tail -1 | tr -s ' ')" \
|
||||
|| { echo "[openfut] FATAL: could not reissue TLS cert" >&2; exit 1; }
|
||||
fi
|
||||
|
||||
# name script extra-env
|
||||
declare -a SERVERS=(
|
||||
"lsx|lsx_responder_v2.py|OPENFUT_LSX_EVENT_COUNT=100000"
|
||||
|
||||
@@ -15,16 +15,27 @@ reimplementations (the `tdf` crate cloned in this scratchpad), which were used
|
||||
only as a cross-check of *structure*, never copied.
|
||||
NO EA/FIFA leaked source was consulted.
|
||||
|
||||
VALIDATED RULES (byte-exact round-trip against the 219-byte capture)
|
||||
--------------------------------------------------------------------
|
||||
Fire2 frame header, 16 bytes big-endian:
|
||||
[0:4] u32 payload length (bytes after the header)
|
||||
[4:6] u16 always 0 (observed)
|
||||
VALIDATED RULES (the TDF body; byte-exact round-trip against the 219-byte capture)
|
||||
---------------------------------------------------------------------------------
|
||||
Fire2 frame header, 16 bytes big-endian.
|
||||
|
||||
!!! SUPERSEDED — the [10:16] FIELD SEMANTICS below are WRONG for FIFA 17. !!!
|
||||
The "byte-exact round-trip" only proves the payload length and the TDF body
|
||||
encoding: decoding then re-encoding with the SAME (mis)labelled header layout
|
||||
trivially reproduces the capture, so it never tested the header's field
|
||||
boundaries. The authoritative, live-driven layout is
|
||||
`openfut-protocol-blaze::fire2` / `blaze_responder_v3b.py::fire2`:
|
||||
[0:4] u32 payload length (bytes after header + metadata)
|
||||
[4:6] u16 metadata length (0 when absent — what this file called "always 0")
|
||||
[6:8] u16 component
|
||||
[8:10] u16 command
|
||||
[10:12]u16 error / msgId
|
||||
[12] u8 msgType (0x01 ping, 0x02 request, 0x03 pong/response)
|
||||
[13:16]3 reserved bytes (observed 00 00 00)
|
||||
[10:13] u24 msgNum (this file WRONGLY split it as [10:12] msgId + [12] msgType)
|
||||
[13] u8 (msgType << 5) | (userIndex & 0x1F)
|
||||
[14] u8 options
|
||||
[15] u8 reserved
|
||||
There is NO error field in Fire2 (that is Fire v1) and NO jumbo escape — the
|
||||
length is already a full u32. `build_fire2_frame`/`decode_fire2` below keep the
|
||||
old wrong `>IHHHHB3s` layout; they are dead and retained only for history.
|
||||
|
||||
Heat2 field = 3-byte packed tag + 1 type byte + value.
|
||||
|
||||
@@ -359,7 +370,14 @@ MSG_ERROR = 0x05 # UNVERIFIED
|
||||
|
||||
def build_fire2_frame(component: int, command: int, msgType: int,
|
||||
msgId: int, tdf_bytes: bytes) -> bytes:
|
||||
"""16-byte big-endian Fire2 header + TDF payload."""
|
||||
"""16-byte big-endian Fire2 header + TDF payload.
|
||||
|
||||
WRONG HEADER (dead code): the ``>IHHHHB3s`` layout mislabels [10:16] — it
|
||||
puts a u16 msgId at [10:12] and msgType at [12]. FIFA 17's real Fire2 header
|
||||
is [10:13] u24 msgNum, [13] (msgType<<5)|userIndex, [14] options, [15]
|
||||
reserved, and has no error field. Use ``openfut-protocol-blaze::fire2`` or
|
||||
``blaze_responder_v3b.py::fire2``; this is retained only for history.
|
||||
"""
|
||||
tdf_bytes = bytes(tdf_bytes)
|
||||
hdr = struct.pack(">IHHHHB3s", len(tdf_bytes), 0, component & 0xFFFF,
|
||||
command & 0xFFFF, msgId & 0xFFFF, msgType & 0xFF,
|
||||
|
||||
@@ -32,11 +32,26 @@ c() { printf ' %s\n' "$*"; }
|
||||
up() { ss -tlnp 2>/dev/null | grep -q ":$1 "; }
|
||||
|
||||
ensure_cert() {
|
||||
[ -s "$CERT" ] && [ -s "$KEY" ] && return 0
|
||||
echo "[*] generating self-signed TLS cert (redirector MITM; ProtoSSL verify is patched)"
|
||||
# The cert MUST carry the address the client dials in its SAN, or the roster
|
||||
# HTTPS handshake is rejected with fatal certificate_unknown and the FUT hub
|
||||
# fails to load (docs/FIFA17_FUT_SQUAD_UPDATE_TLS.md): the client dials the
|
||||
# roster/redirector by IP and that path validates the SAN against it. Default to
|
||||
# this host's primary LAN IP so a client on another machine works;
|
||||
# OPENFUT_ADVERTISE overrides. Reissue when absent OR when the current cert lacks
|
||||
# that IP, so this self-heals rather than serving a stale DNS-only cert.
|
||||
local adv ip_sans regen=0
|
||||
adv="${OPENFUT_ADVERTISE:-$(ip route get 1.1.1.1 2>/dev/null | awk '{print $7; exit}')}"
|
||||
ip_sans="IP:127.0.0.1"; [ -n "$adv" ] && ip_sans="IP:$adv,IP:127.0.0.1"
|
||||
if [ ! -s "$CERT" ] || [ ! -s "$KEY" ]; then
|
||||
regen=1
|
||||
elif [ -n "$adv" ] && ! openssl x509 -in "$CERT" -noout -ext subjectAltName 2>/dev/null | grep -qF "IP Address:$adv"; then
|
||||
regen=1
|
||||
fi
|
||||
[ "$regen" = 0 ] && return 0
|
||||
echo "[*] issuing self-signed TLS cert (SAN includes $ip_sans; redirector MITM; ProtoSSL verify is patched)"
|
||||
openssl req -x509 -newkey rsa:2048 -nodes -keyout "$KEY" -out "$CERT" -days 3650 \
|
||||
-subj "/CN=winter15.gosredirector.ea.com" \
|
||||
-addext "subjectAltName=DNS:winter15.gosredirector.ea.com,DNS:*.gosredirector.ea.com,DNS:*.ea.com,IP:127.0.0.1" \
|
||||
-addext "subjectAltName=DNS:winter15.gosredirector.ea.com,DNS:*.gosredirector.ea.com,DNS:*.ea.com,$ip_sans" \
|
||||
>/dev/null 2>&1
|
||||
}
|
||||
|
||||
|
||||
@@ -0,0 +1,76 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Dump CardsDLL's 45-row route table from the ON-DISK PE. READ-ONLY, static.
|
||||
|
||||
The transfer-market analysis locates the table at .rdata 0x18021df80 as
|
||||
{char*, char*} rows. This resolves VA->file offset properly through the PE section
|
||||
table rather than assuming a single .text mapping, then prints every row so we can
|
||||
see whether any route other than `tradePile` could own a trade-pile ITEM list.
|
||||
"""
|
||||
import struct, sys
|
||||
|
||||
DLL = "/mnt/games/FIFA 17/CardsDLL_Win64_retail.dll"
|
||||
TABLE_VA = 0x18021DF80
|
||||
MAX_ROWS = 64
|
||||
|
||||
pe = open(DLL, "rb").read()
|
||||
e_lfanew = struct.unpack_from("<I", pe, 0x3C)[0]
|
||||
assert pe[e_lfanew:e_lfanew + 4] == b"PE\0\0", "not a PE"
|
||||
coff = e_lfanew + 4
|
||||
nsec, opt_size = struct.unpack_from("<HH", pe, coff + 2), None
|
||||
num_sections = struct.unpack_from("<H", pe, coff + 2)[0]
|
||||
opt_size = struct.unpack_from("<H", pe, coff + 16)[0]
|
||||
opt = coff + 20
|
||||
magic = struct.unpack_from("<H", pe, opt)[0]
|
||||
assert magic == 0x20B, "expected PE32+"
|
||||
image_base = struct.unpack_from("<Q", pe, opt + 24)[0]
|
||||
sec_off = opt + opt_size
|
||||
|
||||
sections = []
|
||||
for i in range(num_sections):
|
||||
b = sec_off + i * 40
|
||||
name = pe[b:b + 8].rstrip(b"\0").decode("ascii", "replace")
|
||||
vsize, vaddr, rawsize, rawptr = struct.unpack_from("<IIII", pe, b + 8)
|
||||
sections.append((name, vaddr, vsize, rawptr, rawsize))
|
||||
|
||||
print("image_base=%#x sections=%d" % (image_base, num_sections))
|
||||
for s in sections:
|
||||
print(" %-8s rva=%#010x vsize=%#x rawptr=%#010x rawsize=%#x" % s)
|
||||
|
||||
|
||||
def va2off(va):
|
||||
rva = va - image_base
|
||||
for name, vaddr, vsize, rawptr, rawsize in sections:
|
||||
if vaddr <= rva < vaddr + max(vsize, rawsize):
|
||||
off = rva - vaddr + rawptr
|
||||
if off < len(pe):
|
||||
return off
|
||||
return None
|
||||
|
||||
|
||||
def cstr(va, limit=96):
|
||||
off = va2off(va)
|
||||
if off is None:
|
||||
return None
|
||||
end = pe.find(b"\0", off, off + limit)
|
||||
if end < 0:
|
||||
return None
|
||||
try:
|
||||
return pe[off:end].decode("ascii")
|
||||
except UnicodeDecodeError:
|
||||
return None
|
||||
|
||||
|
||||
base = va2off(TABLE_VA)
|
||||
print("\nroute table VA %#x -> file offset %s" % (TABLE_VA, hex(base) if base else None))
|
||||
assert base, "table VA did not resolve"
|
||||
|
||||
print("\n%-4s %-34s %s" % ("#", "field A", "field B"))
|
||||
rows = 0
|
||||
for i in range(MAX_ROWS):
|
||||
a_va, b_va = struct.unpack_from("<QQ", pe, base + i * 16)
|
||||
a, b = cstr(a_va), cstr(b_va)
|
||||
if a is None and b is None:
|
||||
print("-- table ends after %d rows --" % rows)
|
||||
break
|
||||
print("%-4d %-34s %s" % (i, repr(a), repr(b)))
|
||||
rows += 1
|
||||
@@ -0,0 +1,76 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Read the FIFA 17 TRADING gate byte out of the live client. READ-ONLY.
|
||||
|
||||
Extends tools/gate_byte_probe.py with vtable slot +0x270 (IS_TRADING_ENABLED,
|
||||
displacement 0x1fd2e) plus the two pile-size dwords, which the transfer-market
|
||||
analysis names as the market screen's CardsDLL-supplied inputs.
|
||||
|
||||
Opens /proc/<pid>/mem O_RDONLY and preads. Nothing here can write.
|
||||
"""
|
||||
import os, struct
|
||||
|
||||
pid = None
|
||||
for d in os.listdir('/proc'):
|
||||
if d.isdigit():
|
||||
try:
|
||||
if open('/proc/%s/comm' % d).read().strip() == 'FIFA17.exe':
|
||||
pid = int(d)
|
||||
break
|
||||
except Exception:
|
||||
pass
|
||||
assert pid, "FIFA17.exe not running"
|
||||
|
||||
base = None
|
||||
for ln in open('/proc/%d/maps' % pid):
|
||||
if 'CardsDLL' in ln:
|
||||
base = int(ln.split('-')[0], 16)
|
||||
assert base, "CardsDLL not mapped (client has not reached Ultimate Team)"
|
||||
slide = base - 0x180000000
|
||||
|
||||
fd = os.open('/proc/%d/mem' % pid, os.O_RDONLY)
|
||||
|
||||
|
||||
def rd(va, n):
|
||||
return os.pread(fd, n, va)
|
||||
|
||||
|
||||
# Control: the FNV atom-hash prologue must match the on-disk PE before any other
|
||||
# address is trusted.
|
||||
pe = open('/mnt/games/FIFA 17/CardsDLL_Win64_retail.dll', 'rb').read()
|
||||
|
||||
|
||||
def f(va):
|
||||
return va - 0x180000000 - 0x1000 + 0x400
|
||||
|
||||
|
||||
ok = pe[f(0x180180d00):f(0x180180d00) + 32] == rd(0x180180d00 + slide, 32)
|
||||
print("pid=%d slide=%#x FNV control=%s" % (pid, slide, "MATCH" if ok else "MISMATCH"))
|
||||
assert ok, "slide not proven; refusing to read further"
|
||||
|
||||
obj = struct.unpack('<Q', rd(0x1802e6398 + slide, 8))[0]
|
||||
vt = struct.unpack('<Q', rd(obj, 8))[0]
|
||||
print("model=%#x vtable(static)=%#x" % (obj, vt - slide))
|
||||
|
||||
SLOTS = [
|
||||
(0x270, 'IS_TRADING_ENABLED '),
|
||||
(0x2b0, 'IS_FRIENDLY_SEASON '),
|
||||
(0x2c8, 'IS_DRAFT_MODE '),
|
||||
(0x2e0, 'packOpeningAnimation '),
|
||||
]
|
||||
print("\n-- gate bytes decoded from their accessor stubs --")
|
||||
for off, name in SLOTS:
|
||||
slot = struct.unpack('<Q', rd(vt + off, 8))[0]
|
||||
stub = rd(slot, 8)
|
||||
if stub[:3] == b'\x0f\xb6\x81':
|
||||
disp = struct.unpack('<I', stub[3:7])[0]
|
||||
val = rd(obj + disp, 1)[0]
|
||||
print(" slot +%#05x %s disp=%#x VALUE=%d" % (off, name, disp, val))
|
||||
else:
|
||||
print(" slot +%#05x %s NOT a movzx stub: %s" % (off, name, stub.hex()))
|
||||
|
||||
print("\n-- market screen inputs --")
|
||||
for disp, name in [(0x1fd1c, 'TRADE_PILE_SIZE'), (0x1fd20, 'watchListSize '),
|
||||
(0x1fd2e, 'tradingEnabled '), (0x1fd2f, 'storeEnabled ')]:
|
||||
print(" model+%#x %s = %d" % (disp, name, rd(obj + disp, 1)[0]))
|
||||
|
||||
os.close(fd)
|
||||
@@ -0,0 +1,78 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Dump CardsDLL's NULL-terminated {const char*, int} vocabulary tables from the
|
||||
ON-DISK PE. READ-ONLY, static.
|
||||
|
||||
The transfer-market analysis records tradeState as decoding through a table walk at
|
||||
0x180229e40 and lists sibling vocabularies (type/zone/lev/pos) as tables of the same
|
||||
shape. This prints the exact token spellings and their integer codes, so the accepted
|
||||
strings come from the client rather than from inference.
|
||||
"""
|
||||
import struct
|
||||
|
||||
DLL = "/mnt/games/FIFA 17/CardsDLL_Win64_retail.dll"
|
||||
TABLES = [
|
||||
(0x180229E40, "tradeState (table walk)"),
|
||||
(0x180229C30, "type"),
|
||||
(0x1802296E0, "zone"),
|
||||
(0x180229A60, "lev"),
|
||||
(0x1802295C0, "pos"),
|
||||
(0x180229AB0, "cat"),
|
||||
(0x180229880, "form"),
|
||||
]
|
||||
MAX_ROWS = 64
|
||||
|
||||
pe = open(DLL, "rb").read()
|
||||
e_lfanew = struct.unpack_from("<I", pe, 0x3C)[0]
|
||||
coff = e_lfanew + 4
|
||||
num_sections = struct.unpack_from("<H", pe, coff + 2)[0]
|
||||
opt_size = struct.unpack_from("<H", pe, coff + 16)[0]
|
||||
opt = coff + 20
|
||||
image_base = struct.unpack_from("<Q", pe, opt + 24)[0]
|
||||
sec_off = opt + opt_size
|
||||
sections = []
|
||||
for i in range(num_sections):
|
||||
b = sec_off + i * 40
|
||||
vsize, vaddr, rawsize, rawptr = struct.unpack_from("<IIII", pe, b + 8)
|
||||
sections.append((vaddr, vsize, rawptr, rawsize))
|
||||
|
||||
|
||||
def va2off(va):
|
||||
rva = va - image_base
|
||||
for vaddr, vsize, rawptr, rawsize in sections:
|
||||
if vaddr <= rva < vaddr + max(vsize, rawsize):
|
||||
off = rva - vaddr + rawptr
|
||||
if 0 <= off < len(pe):
|
||||
return off
|
||||
return None
|
||||
|
||||
|
||||
def cstr(va, limit=64):
|
||||
off = va2off(va)
|
||||
if off is None:
|
||||
return None
|
||||
end = pe.find(b"\0", off, off + limit)
|
||||
if end < 0:
|
||||
return None
|
||||
try:
|
||||
s = pe[off:end].decode("ascii")
|
||||
except UnicodeDecodeError:
|
||||
return None
|
||||
return s if s.isprintable() else None
|
||||
|
||||
|
||||
for table_va, name in TABLES:
|
||||
base = va2off(table_va)
|
||||
print("\n=== %s VA %#x -> off %s ===" % (name, table_va, hex(base) if base else None))
|
||||
if base is None:
|
||||
print(" (VA did not resolve)")
|
||||
continue
|
||||
for i in range(MAX_ROWS):
|
||||
ptr, code = struct.unpack_from("<Qi", pe, base + i * 16)
|
||||
if ptr == 0:
|
||||
print(" -- NULL terminator after %d rows --" % i)
|
||||
break
|
||||
s = cstr(ptr)
|
||||
if s is None:
|
||||
print(" row %d: ptr %#x does not resolve to a string; stopping" % (i, ptr))
|
||||
break
|
||||
print(" %-28s = %d" % (repr(s), code))
|
||||
@@ -20,6 +20,8 @@ use std::collections::HashMap;
|
||||
|
||||
use serde::Deserialize;
|
||||
|
||||
use crate::fut::content_taxonomy::ContentKind;
|
||||
|
||||
/// The FIFA 17 render identity of a card definition. `version` is the high byte
|
||||
/// of `resource_id`; `asset_id` (the low 24 bits) is the real FIFA player id.
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
@@ -30,6 +32,12 @@ pub struct Fifa17CardIdentity {
|
||||
/// FIFA wire `rareflag` (rare/special card TYPE). Carried so specials render
|
||||
/// as specials; observed metadata, not a guessed label.
|
||||
pub rareflag: i64,
|
||||
/// Content class of this definition. A catalog authored before this field
|
||||
/// existed defaults to [`ContentKind::Player`] (backward compatible).
|
||||
pub kind: ContentKind,
|
||||
/// FIFA `cardsubtypeid` for a non-player definition (consumable family /
|
||||
/// staff role), `0` for a player or when absent.
|
||||
pub subtype: i64,
|
||||
}
|
||||
|
||||
/// The FIFA 17 numeric namespace policy for owned-item wire ids.
|
||||
@@ -115,6 +123,14 @@ struct RawCard {
|
||||
/// behaviour; the production catalog carries the observed value.
|
||||
#[serde(default = "default_rareflag")]
|
||||
rareflag: i64,
|
||||
/// Content class token ("player"|"consumable"|"staff"). Absent → default
|
||||
/// (empty) → [`ContentKind::Player`], so existing player-only catalogs load
|
||||
/// unchanged.
|
||||
#[serde(default)]
|
||||
kind: String,
|
||||
/// FIFA `cardsubtypeid` for a non-player entry; absent → `0`.
|
||||
#[serde(default)]
|
||||
subtype: i64,
|
||||
}
|
||||
|
||||
fn default_rareflag() -> i64 {
|
||||
@@ -169,6 +185,8 @@ impl Fifa17CardCatalog {
|
||||
version: rc.version,
|
||||
resource_id,
|
||||
rareflag: rc.rareflag,
|
||||
kind: ContentKind::from_str(&rc.kind),
|
||||
subtype: rc.subtype,
|
||||
},
|
||||
);
|
||||
}
|
||||
@@ -197,6 +215,21 @@ impl Fifa17CardCatalog {
|
||||
self.by_resource.get(&resource_id).map(String::as_str)
|
||||
}
|
||||
|
||||
/// Classify a `card_id` as player/consumable/staff. An unknown definition is
|
||||
/// [`ContentKind::Player`] — the neutral, backward-compatible default (an
|
||||
/// un-catalogued id was always treated as a player-shaped card).
|
||||
pub fn kind_of(&self, card_id: &str) -> ContentKind {
|
||||
self.by_card
|
||||
.get(card_id)
|
||||
.map(|c| c.kind)
|
||||
.unwrap_or(ContentKind::Player)
|
||||
}
|
||||
|
||||
/// The FIFA `cardsubtypeid` for a definition, or `0` if unknown / a player.
|
||||
pub fn subtype_of(&self, card_id: &str) -> i64 {
|
||||
self.by_card.get(card_id).map(|c| c.subtype).unwrap_or(0)
|
||||
}
|
||||
|
||||
pub fn len(&self) -> usize {
|
||||
self.by_card.len()
|
||||
}
|
||||
@@ -335,4 +368,44 @@ mod tests {
|
||||
assert_eq!(ron.version, 0);
|
||||
assert_eq!(ron.resource_id, 20801);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn legacy_catalog_without_kind_loads_as_player() {
|
||||
// A pre-taxonomy catalog (no `kind`/`subtype`) must load unchanged and
|
||||
// classify every entry as a player, with subtype 0.
|
||||
let cat = Fifa17CardCatalog::from_json_str(
|
||||
r#"{"schema_version":1,"game":"fifa17","cards":{
|
||||
"fifa17_20801":{"asset_id":20801},
|
||||
"fifa17_176580":{"asset_id":176580,"version":5,"rareflag":3}
|
||||
}}"#,
|
||||
)
|
||||
.unwrap();
|
||||
let base = cat.lookup("fifa17_20801").unwrap();
|
||||
assert_eq!(base.kind, ContentKind::Player);
|
||||
assert_eq!(base.subtype, 0);
|
||||
assert_eq!(base.rareflag, 1, "absent rareflag still defaults to 1");
|
||||
assert_eq!(cat.kind_of("fifa17_20801"), ContentKind::Player);
|
||||
assert_eq!(cat.kind_of("fifa17_176580"), ContentKind::Player);
|
||||
// Unknown id -> neutral Player default.
|
||||
assert_eq!(cat.kind_of("fifa17_missing"), ContentKind::Player);
|
||||
assert_eq!(cat.subtype_of("fifa17_missing"), 0);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn kind_and_subtype_are_parsed_for_non_player_entries() {
|
||||
let cat = Fifa17CardCatalog::from_json_str(
|
||||
r#"{"schema_version":1,"game":"fifa17","cards":{
|
||||
"fifa17_20801":{"asset_id":20801,"kind":"player","subtype":0},
|
||||
"fifa17_5003012":{"asset_id":5003012,"kind":"consumable","subtype":54,"rareflag":0},
|
||||
"fifa17_3000083":{"asset_id":3000083,"kind":"staff","subtype":8,"rareflag":0}
|
||||
}}"#,
|
||||
)
|
||||
.unwrap();
|
||||
assert_eq!(cat.kind_of("fifa17_20801"), ContentKind::Player);
|
||||
assert_eq!(cat.kind_of("fifa17_5003012"), ContentKind::Consumable);
|
||||
assert_eq!(cat.subtype_of("fifa17_5003012"), 54);
|
||||
assert_eq!(cat.kind_of("fifa17_3000083"), ContentKind::Staff);
|
||||
assert_eq!(cat.subtype_of("fifa17_3000083"), 8);
|
||||
assert_eq!(cat.lookup("fifa17_5003012").unwrap().rareflag, 0);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -9,6 +9,7 @@
|
||||
|
||||
use serde_json::{json, Value};
|
||||
|
||||
use crate::fut::content_taxonomy::ContentKind;
|
||||
use crate::fut::entities::ReverseEntityResolver;
|
||||
use crate::fut::item::shape_item;
|
||||
// Re-exported so existing `club_response::{…}` callers keep working; the types
|
||||
@@ -25,6 +26,12 @@ pub fn shape_club_response<I: ItemIdentityResolver + ?Sized>(
|
||||
let mut out = Vec::with_capacity(items.len());
|
||||
let mut stats = ShapeStats::default();
|
||||
for item in items {
|
||||
// Exclude non-player content (consumables/staff): a `/club` player list
|
||||
// must never render them as 0-rated players. Counted, never emitted.
|
||||
if ident.kind_of(item) != ContentKind::Player {
|
||||
stats.excluded_non_player += 1;
|
||||
continue;
|
||||
}
|
||||
match ident.resolve(item) {
|
||||
Some(id) => {
|
||||
out.push(shape_item(item, id, ent));
|
||||
@@ -193,4 +200,66 @@ mod tests {
|
||||
"only itemData at top level"
|
||||
);
|
||||
}
|
||||
|
||||
/// A resolver that resolves an asset id for EVERY item (so exclusion is not
|
||||
/// an artifact of a missing asset) but classifies some card_ids as non-player
|
||||
/// via an explicit kind table.
|
||||
struct KindMapIdentity {
|
||||
ids: HashMap<String, Fifa17Identity>,
|
||||
kinds: HashMap<String, ContentKind>,
|
||||
}
|
||||
impl ItemIdentityResolver for KindMapIdentity {
|
||||
fn resolve(&self, it: &CoreOwnedItem) -> Option<Fifa17Identity> {
|
||||
self.ids.get(&it.card_id).copied()
|
||||
}
|
||||
fn kind_of(&self, it: &CoreOwnedItem) -> ContentKind {
|
||||
self.kinds
|
||||
.get(&it.card_id)
|
||||
.copied()
|
||||
.unwrap_or(ContentKind::Player)
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn consumable_and_staff_are_excluded_from_club_players() {
|
||||
let ent = entities();
|
||||
let id = |item_id: u32, asset: u32| Fifa17Identity {
|
||||
item_id,
|
||||
asset_id: asset,
|
||||
resource_id: asset,
|
||||
rareflag: 1,
|
||||
};
|
||||
let ident = KindMapIdentity {
|
||||
ids: HashMap::from([
|
||||
("card_player".to_string(), id(100000001, 20801)),
|
||||
("card_consumable".to_string(), id(100000002, 5003012)),
|
||||
("card_staff".to_string(), id(100000003, 3000083)),
|
||||
]),
|
||||
kinds: HashMap::from([
|
||||
("card_consumable".to_string(), ContentKind::Consumable),
|
||||
("card_staff".to_string(), ContentKind::Staff),
|
||||
]),
|
||||
};
|
||||
let items = vec![
|
||||
item(
|
||||
"oc1",
|
||||
"card_player",
|
||||
86,
|
||||
"ST",
|
||||
"Argentina",
|
||||
"Premier League",
|
||||
"Chelsea",
|
||||
),
|
||||
item("oc2", "card_consumable", 0, "", "", "", ""),
|
||||
item("oc3", "card_staff", 0, "", "", "", ""),
|
||||
];
|
||||
let (body, stats) = shape_club_response(&items, &ent, &ident);
|
||||
assert_eq!(stats.emitted, 1, "only the player is emitted");
|
||||
assert_eq!(stats.excluded_non_player, 2, "consumable + staff excluded");
|
||||
assert_eq!(stats.dropped_no_asset, 0);
|
||||
let arr = body["itemData"].as_array().unwrap();
|
||||
assert_eq!(arr.len(), 1);
|
||||
assert_eq!(arr[0]["id"], 100000001, "the player survives");
|
||||
assert_eq!(arr[0]["itemType"], "player");
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,430 @@
|
||||
//! FIFA17 MY CLUB stat set (`GET …/club/stats/{year,consumables}`), computed
|
||||
//! from OpenFUT Core's authoritative owned inventory.
|
||||
//!
|
||||
//! Faithful port of the Python oracle's `fut_club_stats.py` (`global_counts` +
|
||||
//! `context_rows` + `stats_body`), which is itself censused from CardsDLL
|
||||
//! (`FUN_18012fd40` atom table). The body is `{"stat":[{contextId,contextValue,
|
||||
//! type,typeValue}, …]}`:
|
||||
//! * a GLOBAL bucket (contextId 1, contextValue 0) with player tier counts,
|
||||
//! staff-by-family, consumables-by-family, and honest zeros for club items;
|
||||
//! * per-NATION buckets (contextId 3, contextValue = nation id) with the tier
|
||||
//! counts the MY CLUB summary panel sums into PLAYERS_EMPLOYED.
|
||||
//!
|
||||
//! Unlike the oracle (which counts its own stale profile + a synthetic consumable
|
||||
//! shelf), this counts Core — so staff and consumable families reflect the real
|
||||
//! imported content. Unrecognized atoms are inert in the client, so this is a
|
||||
//! low-risk cosmetic surface; the tier/staff/consumable atoms are the ones the
|
||||
//! screen reads and they are Core-accurate here.
|
||||
|
||||
use std::collections::BTreeMap;
|
||||
|
||||
use serde_json::{json, Value};
|
||||
|
||||
use crate::fut::content_taxonomy::{consumable_family, ContentKind};
|
||||
|
||||
/// One owned item, already classified from the catalog + entity tables by the
|
||||
/// host. `subtype`/`rare` come from the FIFA catalog; `nation_id`/`league_id`/
|
||||
/// `team_id` from the reverse entity resolver (None = unresolved, bucket skipped).
|
||||
#[derive(Debug, Clone)]
|
||||
pub struct ClubStatInput {
|
||||
pub kind: ContentKind,
|
||||
pub subtype: i64,
|
||||
pub rating: i64,
|
||||
pub rare: bool,
|
||||
pub nation_id: Option<i64>,
|
||||
pub league_id: Option<i64>,
|
||||
pub team_id: Option<i64>,
|
||||
}
|
||||
|
||||
/// Which entity the per-context (`contextId 3`) buckets are keyed by — the FIFA
|
||||
/// `MY CLUB` sub-screen selector (`fut_club_stats.py::context_rows`):
|
||||
/// * `Nation` — the default screen (year/consumables/club/newcards): nation buckets.
|
||||
/// * `League` — URL `club/stats/country/<id>`: league (leagueId) buckets, tier stats.
|
||||
/// * `Team` — URL `club/stats/league/<id>`: team (teamid) buckets, players/kits/badge.
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub enum ContextField {
|
||||
Nation,
|
||||
League,
|
||||
Team,
|
||||
}
|
||||
|
||||
// Stat ids (CardsDLL atom table, fut_club_stats.py VOCAB).
|
||||
const S_PLAYERS: i64 = 0x01;
|
||||
const S_BRONZE: i64 = 0x02;
|
||||
const S_SILVER: i64 = 0x03;
|
||||
const S_GOLD: i64 = 0x04;
|
||||
const S_RARE: i64 = 0x05;
|
||||
const S_STAFF: i64 = 0x0A;
|
||||
const S_CONSUMABLES: i64 = 0x3C;
|
||||
const S_KITS: i64 = 0x28;
|
||||
const S_BADGES: i64 = 0x2D;
|
||||
|
||||
/// cardsubtypeid (staff family) -> stat id (STAFF_SUBTYPE_STAT).
|
||||
fn staff_stat(subtype: i64) -> Option<i64> {
|
||||
match subtype {
|
||||
4 => Some(0x0B), // manager
|
||||
5 => Some(0x0C), // head coach
|
||||
6 => Some(0x0D), // GK coach
|
||||
7 => Some(0x0E), // physio
|
||||
8 => Some(0x0F), // fitness coach
|
||||
_ => None,
|
||||
}
|
||||
}
|
||||
|
||||
/// consumable family `kind` -> stat id (CONSUMABLE_KIND_STAT).
|
||||
fn consumable_stat(kind: &str) -> Option<i64> {
|
||||
Some(match kind {
|
||||
"player_contract" => 0x42,
|
||||
"manager_contract" => 0x47,
|
||||
"healing" => 0x41,
|
||||
"player_fitness" => 0x44,
|
||||
"squad_fitness" => 0x4A,
|
||||
"gk_training" => 0x46,
|
||||
"player_training" => 0x43,
|
||||
"position_mod" => 0x45,
|
||||
"player_playstyle" => 0x4B,
|
||||
"gk_playstyle" => 0x4C,
|
||||
"manager_league" => 0x4D,
|
||||
"manager_formation_mod" | "formation_mod" => 0x48,
|
||||
_ => return None,
|
||||
})
|
||||
}
|
||||
|
||||
/// The JSON `type` atom name for a stat id (VOCAB). Only the ids this module
|
||||
/// emits are mapped; an unmapped id would panic (guards a transcription slip).
|
||||
fn vocab(stat_id: i64) -> &'static str {
|
||||
match stat_id {
|
||||
0x01 => "players",
|
||||
0x02 => "playersBronze",
|
||||
0x03 => "playersSilver",
|
||||
0x04 => "playersGold",
|
||||
0x05 => "rarePlayers",
|
||||
0x0A => "staff",
|
||||
0x0B => "staffManager",
|
||||
0x0C => "staffHeadCoach",
|
||||
0x0D => "staffGKCoach",
|
||||
0x0E => "staffPhysio",
|
||||
0x0F => "staffFitnessCoach",
|
||||
0x14 => "stadia",
|
||||
0x1E => "balls",
|
||||
0x28 => "kits",
|
||||
0x29 => "kitsHome",
|
||||
0x2A => "kitsAway",
|
||||
0x2D => "badges",
|
||||
0x2E => "badgeDBid",
|
||||
0x2F => "leagueLogos",
|
||||
0x32 => "trophies",
|
||||
0x33 => "trophiesOffline",
|
||||
0x34 => "trophiesOnline",
|
||||
0x35 => "trophiesFeaturedOffline",
|
||||
0x36 => "trophiesFeaturedOnline",
|
||||
0x37 => "trophiesSeasonOffline",
|
||||
0x38 => "trophiesSeasonOnline",
|
||||
0x3C => "consumables",
|
||||
0x41 => "consumablesHealing",
|
||||
0x42 => "consumablesContractPlayer",
|
||||
0x43 => "consumablesTrainingPlayer",
|
||||
0x44 => "consumablesFitnessPlayer",
|
||||
0x45 => "consumablesPosition",
|
||||
0x46 => "consumablesTrainingGk",
|
||||
0x47 => "consumablesContractManager",
|
||||
0x48 => "consumablesFormationManager",
|
||||
0x49 => "consumablesTrainingManager",
|
||||
0x4A => "consumablesFitnessTeam",
|
||||
0x4B => "consumablesTrainingPlayerPlayStyle",
|
||||
0x4C => "consumablesTrainingGkPlayStyle",
|
||||
0x4D => "consumablesTrainingManagerLeagueModifier",
|
||||
other => panic!("club_stats: unmapped stat id {other:#x}"),
|
||||
}
|
||||
}
|
||||
|
||||
fn row(context_id: i64, context_value: i64, stat_id: i64, value: i64) -> Value {
|
||||
json!({
|
||||
"contextId": context_id,
|
||||
"contextValue": context_value,
|
||||
"type": vocab(stat_id),
|
||||
"typeValue": value,
|
||||
})
|
||||
}
|
||||
|
||||
fn is_player(i: &ClubStatInput) -> bool {
|
||||
matches!(i.kind, ContentKind::Player)
|
||||
}
|
||||
|
||||
/// Build the full `{"stat":[…]}` body for a club/stats screen — the global bucket
|
||||
/// (identical for every mode) plus per-context buckets keyed by `ctx`
|
||||
/// (nation / league / team), mirroring `fut_club_stats.py::stats_body`.
|
||||
pub fn club_stats_body(items: &[ClubStatInput], ctx: ContextField) -> Value {
|
||||
// ---- global bucket (contextId 1, contextValue 0), sorted by stat id ----
|
||||
let mut g: BTreeMap<i64, i64> = BTreeMap::new();
|
||||
let players: Vec<&ClubStatInput> = items.iter().filter(|i| is_player(i)).collect();
|
||||
g.insert(S_PLAYERS, players.len() as i64);
|
||||
g.insert(
|
||||
S_GOLD,
|
||||
players.iter().filter(|i| i.rating >= 75).count() as i64,
|
||||
);
|
||||
g.insert(
|
||||
S_SILVER,
|
||||
players
|
||||
.iter()
|
||||
.filter(|i| (65..75).contains(&i.rating))
|
||||
.count() as i64,
|
||||
);
|
||||
g.insert(
|
||||
S_BRONZE,
|
||||
players
|
||||
.iter()
|
||||
.filter(|i| i.rating > 0 && i.rating < 65)
|
||||
.count() as i64,
|
||||
);
|
||||
g.insert(S_RARE, players.iter().filter(|i| i.rare).count() as i64);
|
||||
|
||||
// staff per family + total
|
||||
for sid in [0x0B, 0x0C, 0x0D, 0x0E, 0x0F] {
|
||||
g.insert(sid, 0);
|
||||
}
|
||||
let mut staff_total = 0i64;
|
||||
for it in items
|
||||
.iter()
|
||||
.filter(|i| matches!(i.kind, ContentKind::Staff))
|
||||
{
|
||||
if let Some(sid) = staff_stat(it.subtype) {
|
||||
*g.get_mut(&sid).unwrap() += 1;
|
||||
staff_total += 1;
|
||||
}
|
||||
}
|
||||
g.insert(S_STAFF, staff_total);
|
||||
|
||||
// consumables per family + total
|
||||
for sid in [
|
||||
0x41, 0x42, 0x43, 0x44, 0x45, 0x46, 0x47, 0x48, 0x49, 0x4A, 0x4B, 0x4C, 0x4D,
|
||||
] {
|
||||
g.insert(sid, 0);
|
||||
}
|
||||
let mut cons_total = 0i64;
|
||||
for it in items
|
||||
.iter()
|
||||
.filter(|i| matches!(i.kind, ContentKind::Consumable))
|
||||
{
|
||||
cons_total += 1;
|
||||
if let Some((kind, _label)) = consumable_family(it.subtype) {
|
||||
if let Some(sid) = consumable_stat(kind) {
|
||||
*g.entry(sid).or_insert(0) += 1;
|
||||
}
|
||||
}
|
||||
}
|
||||
g.insert(S_CONSUMABLES, cons_total);
|
||||
|
||||
// club items: honest zeros (Core holds none; each is read by some panel).
|
||||
for sid in [
|
||||
0x14, 0x1E, 0x28, 0x29, 0x2A, 0x2D, 0x2E, 0x2F, 0x32, 0x33, 0x34, 0x35, 0x36, 0x37, 0x38,
|
||||
] {
|
||||
g.entry(sid).or_insert(0);
|
||||
}
|
||||
|
||||
let mut stat: Vec<Value> = g.iter().map(|(sid, v)| row(1, 0, *sid, *v)).collect();
|
||||
|
||||
// ---- per-context buckets (contextId 3, contextValue = entity id) ----
|
||||
// Nation/League read the tier set (gold/silver/bronze/rare/kits/badges);
|
||||
// Team (the league screen) reads players/kits/badgeDBid. Mirrors context_rows.
|
||||
let mut by_ctx: BTreeMap<i64, Vec<&ClubStatInput>> = BTreeMap::new();
|
||||
for p in &players {
|
||||
let id = match ctx {
|
||||
ContextField::Nation => p.nation_id,
|
||||
ContextField::League => p.league_id,
|
||||
ContextField::Team => p.team_id,
|
||||
};
|
||||
if let Some(id) = id {
|
||||
by_ctx.entry(id).or_default().push(p);
|
||||
}
|
||||
}
|
||||
for (cid, sel) in &by_ctx {
|
||||
if ctx == ContextField::Team {
|
||||
stat.push(row(3, *cid, S_PLAYERS, sel.len() as i64));
|
||||
stat.push(row(3, *cid, S_KITS, 0));
|
||||
stat.push(row(3, *cid, 0x2E, 0)); // badgeDBid
|
||||
} else {
|
||||
let gold = sel.iter().filter(|i| i.rating >= 75).count() as i64;
|
||||
let silver = sel.iter().filter(|i| (65..75).contains(&i.rating)).count() as i64;
|
||||
let bronze = sel.iter().filter(|i| i.rating > 0 && i.rating < 65).count() as i64;
|
||||
let rare = sel.iter().filter(|i| i.rare).count() as i64;
|
||||
stat.push(row(3, *cid, S_GOLD, gold));
|
||||
stat.push(row(3, *cid, S_SILVER, silver));
|
||||
stat.push(row(3, *cid, S_BRONZE, bronze));
|
||||
stat.push(row(3, *cid, S_RARE, rare));
|
||||
stat.push(row(3, *cid, S_KITS, 0));
|
||||
stat.push(row(3, *cid, S_BADGES, 0));
|
||||
}
|
||||
}
|
||||
|
||||
json!({ "stat": stat })
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
fn player(rating: i64, rare: bool, nation: Option<i64>) -> ClubStatInput {
|
||||
ClubStatInput {
|
||||
kind: ContentKind::Player,
|
||||
subtype: 0,
|
||||
rating,
|
||||
rare,
|
||||
nation_id: nation,
|
||||
league_id: None,
|
||||
team_id: None,
|
||||
}
|
||||
}
|
||||
fn staff(subtype: i64) -> ClubStatInput {
|
||||
ClubStatInput {
|
||||
kind: ContentKind::Staff,
|
||||
subtype,
|
||||
rating: 0,
|
||||
rare: false,
|
||||
nation_id: None,
|
||||
league_id: None,
|
||||
team_id: None,
|
||||
}
|
||||
}
|
||||
fn consumable(subtype: i64) -> ClubStatInput {
|
||||
ClubStatInput {
|
||||
kind: ContentKind::Consumable,
|
||||
subtype,
|
||||
rating: 0,
|
||||
rare: false,
|
||||
nation_id: None,
|
||||
league_id: None,
|
||||
team_id: None,
|
||||
}
|
||||
}
|
||||
|
||||
fn global(body: &Value) -> std::collections::HashMap<String, i64> {
|
||||
body["stat"]
|
||||
.as_array()
|
||||
.unwrap()
|
||||
.iter()
|
||||
.filter(|r| r["contextId"] == 1)
|
||||
.map(|r| {
|
||||
(
|
||||
r["type"].as_str().unwrap().to_string(),
|
||||
r["typeValue"].as_i64().unwrap(),
|
||||
)
|
||||
})
|
||||
.collect()
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn tiers_and_rare_counted() {
|
||||
let items = vec![
|
||||
player(90, true, Some(52)),
|
||||
player(70, true, Some(52)),
|
||||
player(60, false, Some(21)),
|
||||
];
|
||||
let g = global(&club_stats_body(&items, ContextField::Nation));
|
||||
assert_eq!(g["players"], 3);
|
||||
assert_eq!(g["playersGold"], 1);
|
||||
assert_eq!(g["playersSilver"], 1);
|
||||
assert_eq!(g["playersBronze"], 1);
|
||||
assert_eq!(g["rarePlayers"], 2);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn staff_by_family() {
|
||||
let items = vec![staff(6), staff(8), staff(8)]; // 1 gk coach, 2 fitness
|
||||
let g = global(&club_stats_body(&items, ContextField::Nation));
|
||||
assert_eq!(g["staffGKCoach"], 1);
|
||||
assert_eq!(g["staffFitnessCoach"], 2);
|
||||
assert_eq!(g["staff"], 3);
|
||||
assert_eq!(g["staffManager"], 0);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn consumables_by_family() {
|
||||
// 54 gk_training, 201 player_contract, 217 healing, 258 player_playstyle
|
||||
let items = vec![
|
||||
consumable(54),
|
||||
consumable(201),
|
||||
consumable(217),
|
||||
consumable(258),
|
||||
];
|
||||
let g = global(&club_stats_body(&items, ContextField::Nation));
|
||||
assert_eq!(g["consumables"], 4);
|
||||
assert_eq!(g["consumablesTrainingGk"], 1);
|
||||
assert_eq!(g["consumablesContractPlayer"], 1);
|
||||
assert_eq!(g["consumablesHealing"], 1);
|
||||
assert_eq!(g["consumablesTrainingPlayerPlayStyle"], 1);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn nation_buckets_emitted_and_players_excludes_nonplayers() {
|
||||
let items = vec![
|
||||
player(90, true, Some(52)),
|
||||
player(80, false, Some(52)),
|
||||
staff(8),
|
||||
];
|
||||
let body = club_stats_body(&items, ContextField::Nation);
|
||||
let g = global(&body);
|
||||
assert_eq!(g["players"], 2, "staff not counted as player");
|
||||
let buckets: Vec<&Value> = body["stat"]
|
||||
.as_array()
|
||||
.unwrap()
|
||||
.iter()
|
||||
.filter(|r| r["contextId"] == 3 && r["contextValue"] == 52)
|
||||
.collect();
|
||||
// gold, silver, bronze, rare, kits, badges
|
||||
assert_eq!(buckets.len(), 6);
|
||||
let gold = buckets.iter().find(|r| r["type"] == "playersGold").unwrap();
|
||||
assert_eq!(gold["typeValue"], 2);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn honest_zero_club_items_present() {
|
||||
let g = global(&club_stats_body(&[player(90, false, None)], ContextField::Nation));
|
||||
for atom in [
|
||||
"stadia",
|
||||
"balls",
|
||||
"kits",
|
||||
"badges",
|
||||
"trophies",
|
||||
"leagueLogos",
|
||||
] {
|
||||
assert_eq!(g[atom], 0, "{atom} present as honest zero");
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn league_and_team_context_modes() {
|
||||
let mut a = player(90, true, Some(52));
|
||||
a.league_id = Some(13);
|
||||
a.team_id = Some(240);
|
||||
let mut b = player(60, false, Some(52));
|
||||
b.league_id = Some(13);
|
||||
b.team_id = Some(9);
|
||||
let items = vec![a, b];
|
||||
|
||||
// country screen -> league (leagueId) buckets, tier set (6 rows).
|
||||
let body = club_stats_body(&items, ContextField::League);
|
||||
let league_rows: Vec<&Value> = body["stat"]
|
||||
.as_array()
|
||||
.unwrap()
|
||||
.iter()
|
||||
.filter(|r| r["contextId"] == 3 && r["contextValue"] == 13)
|
||||
.collect();
|
||||
assert_eq!(league_rows.len(), 6);
|
||||
let gold = league_rows.iter().find(|r| r["type"] == "playersGold").unwrap();
|
||||
assert_eq!(gold["typeValue"], 1);
|
||||
|
||||
// league screen -> team (teamid) buckets: players/kits/badgeDBid (3 rows).
|
||||
let body = club_stats_body(&items, ContextField::Team);
|
||||
let team_rows: Vec<&Value> = body["stat"]
|
||||
.as_array()
|
||||
.unwrap()
|
||||
.iter()
|
||||
.filter(|r| r["contextId"] == 3 && r["contextValue"] == 240)
|
||||
.collect();
|
||||
assert_eq!(team_rows.len(), 3);
|
||||
let players = team_rows.iter().find(|r| r["type"] == "players").unwrap();
|
||||
assert_eq!(players["typeValue"], 1);
|
||||
assert!(team_rows.iter().any(|r| r["type"] == "badgeDBid"));
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,177 @@
|
||||
//! FIFA 17 **non-player content taxonomy** — the evidence-based map from a card
|
||||
//! `cardsubtypeid` to its functional family (consumables) or role (staff).
|
||||
//!
|
||||
//! This is the ONLY place the FIFA-specific `cardsubtypeid` vocabulary lives; it
|
||||
//! keeps that game concept out of generic Core, exactly as the player-side
|
||||
//! catalog keeps `resourceId`/`rareflag` out of Core. Nothing here is guessed:
|
||||
//!
|
||||
//! * Consumable families and their contiguous `cardsubtypeid` ranges are taken
|
||||
//! verbatim from `fifa17-recon/tools/fut_consumables.py`
|
||||
//! (`BY_SUBTYPE`/`CORE_KINDS`, Ghidra-derived from `FUN_18013f4d0` /
|
||||
//! `FUN_1801bfac0`) and `docs/CARD_TAXONOMY.md` (verified against the `.105`
|
||||
//! `fcc_*.json` tables).
|
||||
//! * Staff roles are the `FUN_1800d8330` family selector: 4=manager, 5=headcoach,
|
||||
//! 6=gkcoach, 7=physio, 8=fitnesscoach.
|
||||
//!
|
||||
//! Display **labels are functional, never marketing** (e.g. "Player Chemistry
|
||||
//! Style", not a promo name). A `cardsubtypeid` outside every documented range
|
||||
//! resolves to `None` — the caller DEFERS it (mirroring the player NoName gate),
|
||||
//! never fabricating a family.
|
||||
|
||||
/// The disjoint content classes a FIFA 17 owned card can belong to. Player is
|
||||
/// the default so a catalog authored before this taxonomy existed (no `kind`
|
||||
/// field) still classifies every entry as a player, unchanged.
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq, Default)]
|
||||
pub enum ContentKind {
|
||||
#[default]
|
||||
Player,
|
||||
Consumable,
|
||||
Staff,
|
||||
}
|
||||
|
||||
impl ContentKind {
|
||||
/// The stable wire/catalog token for this kind.
|
||||
pub fn as_str(&self) -> &'static str {
|
||||
match self {
|
||||
ContentKind::Player => "player",
|
||||
ContentKind::Consumable => "consumable",
|
||||
ContentKind::Staff => "staff",
|
||||
}
|
||||
}
|
||||
|
||||
/// Parse a catalog `kind` token. Unknown or "player" (or an absent field that
|
||||
/// deserializes to the default) is `Player` — backward compatible.
|
||||
// Intentionally infallible (every input maps to a kind, unknown → Player), so
|
||||
// it is NOT `std::str::FromStr` (which is fallible); the name mirrors the
|
||||
// catalog token vocabulary.
|
||||
#[allow(clippy::should_implement_trait)]
|
||||
pub fn from_str(s: &str) -> ContentKind {
|
||||
match s {
|
||||
"consumable" => ContentKind::Consumable,
|
||||
"staff" => ContentKind::Staff,
|
||||
_ => ContentKind::Player,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// The functional family + honest display label for a consumable `cardsubtypeid`,
|
||||
/// or `None` if the subtype is outside every documented range (→ DEFER).
|
||||
///
|
||||
/// Returns `(family, label)`, both `'static`. `family` is the neutral machine
|
||||
/// name stored as the CardDefinition family; `label` is the functional
|
||||
/// human-readable name.
|
||||
pub fn consumable_family(subtype: i64) -> Option<(&'static str, &'static str)> {
|
||||
let pair = match subtype {
|
||||
51..=57 => ("gk_training", "GK Training"),
|
||||
61..=67 => ("player_training", "Player Training"),
|
||||
71..=86 => ("manager_formation_mod", "Manager Formation"),
|
||||
91..=110 => ("position_mod", "Position Modifier"),
|
||||
121..=136 => ("formation_mod", "Formation Modifier"),
|
||||
201 => ("player_contract", "Player Contract"),
|
||||
202 => ("manager_contract", "Manager Contract"),
|
||||
211..=218 => ("healing", "Healing"),
|
||||
219 => ("player_fitness", "Player Fitness"),
|
||||
220 => ("squad_fitness", "Squad Fitness"),
|
||||
250..=268 => ("player_playstyle", "Player Chemistry Style"),
|
||||
269..=273 => ("gk_playstyle", "GK Chemistry Style"),
|
||||
300..=341 => ("manager_league", "Manager League Modifier"),
|
||||
_ => return None,
|
||||
};
|
||||
Some(pair)
|
||||
}
|
||||
|
||||
/// The staff role + honest display label for a staff `cardsubtypeid` (4..=8), or
|
||||
/// `None` for any other subtype (→ DEFER). Grounded in the `FUN_1800d8330`
|
||||
/// family selector.
|
||||
pub fn staff_role(subtype: i64) -> Option<(&'static str, &'static str)> {
|
||||
let pair = match subtype {
|
||||
4 => ("manager", "Manager"),
|
||||
5 => ("headcoach", "Head Coach"),
|
||||
6 => ("gkcoach", "GK Coach"),
|
||||
7 => ("physio", "Physio"),
|
||||
8 => ("fitnesscoach", "Fitness Coach"),
|
||||
_ => return None,
|
||||
};
|
||||
Some(pair)
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn content_kind_round_trips_and_defaults_to_player() {
|
||||
assert_eq!(ContentKind::default(), ContentKind::Player);
|
||||
for k in [
|
||||
ContentKind::Player,
|
||||
ContentKind::Consumable,
|
||||
ContentKind::Staff,
|
||||
] {
|
||||
assert_eq!(ContentKind::from_str(k.as_str()), k);
|
||||
}
|
||||
// Unknown / absent tokens fall back to Player (backward compatible).
|
||||
assert_eq!(ContentKind::from_str(""), ContentKind::Player);
|
||||
assert_eq!(ContentKind::from_str("nonsense"), ContentKind::Player);
|
||||
assert_eq!(ContentKind::from_str("player"), ContentKind::Player);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn consumable_family_range_boundaries() {
|
||||
// Each contiguous range: lower boundary, upper boundary, family + label.
|
||||
let cases: &[(i64, i64, &str, &str)] = &[
|
||||
(51, 57, "gk_training", "GK Training"),
|
||||
(61, 67, "player_training", "Player Training"),
|
||||
(71, 86, "manager_formation_mod", "Manager Formation"),
|
||||
(91, 110, "position_mod", "Position Modifier"),
|
||||
(121, 136, "formation_mod", "Formation Modifier"),
|
||||
(211, 218, "healing", "Healing"),
|
||||
(250, 268, "player_playstyle", "Player Chemistry Style"),
|
||||
(269, 273, "gk_playstyle", "GK Chemistry Style"),
|
||||
(300, 341, "manager_league", "Manager League Modifier"),
|
||||
];
|
||||
for &(lo, hi, family, label) in cases {
|
||||
assert_eq!(consumable_family(lo), Some((family, label)), "lo {lo}");
|
||||
assert_eq!(consumable_family(hi), Some((family, label)), "hi {hi}");
|
||||
}
|
||||
// Singleton subtypes.
|
||||
assert_eq!(
|
||||
consumable_family(201),
|
||||
Some(("player_contract", "Player Contract"))
|
||||
);
|
||||
assert_eq!(
|
||||
consumable_family(202),
|
||||
Some(("manager_contract", "Manager Contract"))
|
||||
);
|
||||
assert_eq!(
|
||||
consumable_family(219),
|
||||
Some(("player_fitness", "Player Fitness"))
|
||||
);
|
||||
assert_eq!(
|
||||
consumable_family(220),
|
||||
Some(("squad_fitness", "Squad Fitness"))
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn consumable_family_gaps_and_out_of_range_are_none() {
|
||||
// Just outside range edges, and in documented gaps between ranges.
|
||||
for s in [
|
||||
0, 50, 58, 60, 68, 70, 87, 90, 111, 120, 137, 200, 203, 210, 221, 249, 274, 299, 342,
|
||||
999,
|
||||
] {
|
||||
assert_eq!(consumable_family(s), None, "subtype {s} must be unknown");
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn staff_role_each_role_and_unknown_is_none() {
|
||||
assert_eq!(staff_role(4), Some(("manager", "Manager")));
|
||||
assert_eq!(staff_role(5), Some(("headcoach", "Head Coach")));
|
||||
assert_eq!(staff_role(6), Some(("gkcoach", "GK Coach")));
|
||||
assert_eq!(staff_role(7), Some(("physio", "Physio")));
|
||||
assert_eq!(staff_role(8), Some(("fitnesscoach", "Fitness Coach")));
|
||||
for s in [0, 1, 2, 3, 9, 10, 201, 300] {
|
||||
assert_eq!(staff_role(s), None, "staff subtype {s} must be unknown");
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -56,6 +56,46 @@ pub fn pack_price(pack_id: u64) -> Option<u64> {
|
||||
.map(|p| p.price)
|
||||
}
|
||||
|
||||
/// FIFA 17 transfer-market fee, in PERCENT of the gross sale price.
|
||||
///
|
||||
/// FIFA17-HISTORICAL: 5% is the well-documented FUT transfer tax of the era. It
|
||||
/// was not recovered from our client binary — no `tax`/`netPrice`/`sellerProceeds`
|
||||
/// wire field exists (`docs/FIFA17_TRANSFER_MARKET_WIRE.md`), because the client
|
||||
/// is told only the GROSS price and the deduction is server-side.
|
||||
pub const TRANSFER_MARKET_FEE_PERCENT: i64 = 5;
|
||||
|
||||
/// Fee withheld from a completed sale of `gross` coins.
|
||||
///
|
||||
/// Integer arithmetic only — coin settlement never touches floating point, where
|
||||
/// `0.05` is not representable and a large price could round a coin into or out of
|
||||
/// existence. Widening to `i128` for the multiply makes overflow unreachable for
|
||||
/// any `i64` price, so no ceiling has to be assumed.
|
||||
///
|
||||
/// ROUNDING, and it is a CHOICE that needs live confirmation: the fee is FLOORED,
|
||||
/// so the seller keeps the fractional coin. That is deliberate — it makes
|
||||
/// `fee + proceeds == gross` hold exactly for every input, which is the property
|
||||
/// the accounting invariant depends on. The discriminating case against the
|
||||
/// alternative (flooring the seller's 95% instead) is a gross of 150: this rule
|
||||
/// pays 143, the alternative 142. Nothing in the corpus settles which the real
|
||||
/// server did, so this MUST NOT be treated as confirmed FIFA behaviour.
|
||||
///
|
||||
/// A negative gross is not a sale; it yields a zero fee rather than inventing a
|
||||
/// negative one, and `settle_sale` rejects the price itself.
|
||||
pub fn transfer_market_fee(gross: i64) -> i64 {
|
||||
if gross <= 0 {
|
||||
return 0;
|
||||
}
|
||||
((gross as i128 * TRANSFER_MARKET_FEE_PERCENT as i128) / 100) as i64
|
||||
}
|
||||
|
||||
/// What the seller is credited for a completed sale of `gross` coins.
|
||||
///
|
||||
/// Defined as `gross - fee` rather than as its own percentage, so the pair can
|
||||
/// never disagree about where a rounded coin went.
|
||||
pub fn seller_proceeds(gross: i64) -> i64 {
|
||||
gross.max(0) - transfer_market_fee(gross)
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
@@ -84,4 +124,63 @@ mod tests {
|
||||
assert_eq!(pack_price(65534), None); // sentinel absent from catalogue
|
||||
assert_eq!(pack_price(70), None); // owned-only reward pack, not purchasable
|
||||
}
|
||||
|
||||
/// Pins the rounding rule at every boundary the fee can turn over. If one of
|
||||
/// these ever changes, monetary behaviour changed — that must be deliberate.
|
||||
#[test]
|
||||
fn transfer_market_fee_is_floored_five_percent() {
|
||||
// (gross, expected fee, expected proceeds)
|
||||
let cases = [
|
||||
(0i64, 0i64, 0i64),
|
||||
(1, 0, 1), // 0.05 -> 0
|
||||
(19, 0, 19), // 0.95 -> 0, the last fee-free price
|
||||
(20, 1, 19), // exactly 1.0, the first price that pays
|
||||
(21, 1, 20), // 1.05 -> 1
|
||||
(39, 1, 38), // 1.95 -> 1
|
||||
(40, 2, 38), // exactly 2.0
|
||||
(100, 5, 95),
|
||||
(101, 5, 96), // 5.05 -> 5
|
||||
(119, 5, 114), // 5.95 -> 5, last price paying 5
|
||||
(120, 6, 114), // exactly 6.0
|
||||
(149, 7, 142), // 7.45 -> 7
|
||||
(150, 7, 143), // 7.5 -> 7: THE discriminating case (alternative: 8/142)
|
||||
(151, 7, 144), // 7.55 -> 7 (a HALF-UP rule would pay 8 here too)
|
||||
(199, 9, 190), // 9.95 -> 9
|
||||
(200, 10, 190), // exactly 10.0
|
||||
(1_000, 50, 950),
|
||||
(15_000, 750, 14_250), // the canonical fixture
|
||||
(15_000_000, 750_000, 14_250_000), // FUT's practical price ceiling
|
||||
(i64::MAX, i64::MAX / 20, i64::MAX - i64::MAX / 20), // no overflow
|
||||
];
|
||||
for (gross, fee, proceeds) in cases {
|
||||
assert_eq!(transfer_market_fee(gross), fee, "fee for gross {gross}");
|
||||
assert_eq!(
|
||||
seller_proceeds(gross),
|
||||
proceeds,
|
||||
"proceeds for gross {gross}"
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
/// The property the whole settlement's accounting rests on: the fee and the
|
||||
/// seller's proceeds account for the gross EXACTLY, with no coin created or
|
||||
/// destroyed by rounding, at every price.
|
||||
#[test]
|
||||
fn fee_plus_proceeds_is_exactly_gross() {
|
||||
for gross in (0i64..2_000).chain([15_000, 999_999, 15_000_000, i64::MAX]) {
|
||||
assert_eq!(
|
||||
transfer_market_fee(gross) + seller_proceeds(gross),
|
||||
gross,
|
||||
"fee + proceeds != gross at {gross}"
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
/// A non-sale must not invent a negative fee.
|
||||
#[test]
|
||||
fn negative_gross_yields_no_fee() {
|
||||
assert_eq!(transfer_market_fee(-1), 0);
|
||||
assert_eq!(transfer_market_fee(i64::MIN), 0);
|
||||
assert_eq!(seller_proceeds(-100), 0);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -24,6 +24,7 @@
|
||||
|
||||
use serde_json::{json, Value};
|
||||
|
||||
use crate::fut::content_taxonomy::ContentKind;
|
||||
use crate::fut::entities::ReverseEntityResolver;
|
||||
|
||||
/// One owned item in game-independent terms, as read from Core's inventory.
|
||||
@@ -69,6 +70,15 @@ pub struct Fifa17Identity {
|
||||
/// "no real FIFA asset id known" → the caller must not fabricate one.
|
||||
pub trait ItemIdentityResolver {
|
||||
fn resolve(&self, item: &CoreOwnedItem) -> Option<Fifa17Identity>;
|
||||
|
||||
/// Classify a Core item's definition as player/consumable/staff. Defaults to
|
||||
/// [`ContentKind::Player`] so existing resolvers keep their behaviour; a
|
||||
/// catalog-backed resolver overrides this to consult its `kind_of`, letting
|
||||
/// `/club` exclude non-player content (which must never render as a
|
||||
/// 0-rated player).
|
||||
fn kind_of(&self, _item: &CoreOwnedItem) -> ContentKind {
|
||||
ContentKind::Player
|
||||
}
|
||||
}
|
||||
|
||||
/// Diagnostics from shaping (safe to log — counts only).
|
||||
@@ -76,6 +86,9 @@ pub trait ItemIdentityResolver {
|
||||
pub struct ShapeStats {
|
||||
pub emitted: usize,
|
||||
pub dropped_no_asset: usize,
|
||||
/// Consumable/staff items excluded from a player projection (they must never
|
||||
/// render as a 0-rated player). Counted, never emitted.
|
||||
pub excluded_non_player: usize,
|
||||
}
|
||||
|
||||
/// Quick-sell / discard value by rating tier (mirrors Core's quick-sell table;
|
||||
@@ -133,7 +146,12 @@ pub fn shape_item(
|
||||
"attributeList": attribute_list,
|
||||
"itemState": "free",
|
||||
"owners": 1,
|
||||
"untradeable": true,
|
||||
// Owned/pack-pulled cards are TRADEABLE in FIFA 17 (untradeable is the
|
||||
// exception for SBC/promo rewards, which Core does not model). Emitting
|
||||
// `true` greyed out "Place on Transfer Market" for every card — the same
|
||||
// "our own data showing through" bug the Python oracle fixed by forcing
|
||||
// this off for owned copies (item_def keeps `true`; instances do not).
|
||||
"untradeable": false,
|
||||
"contract": 7,
|
||||
"fitness": 99,
|
||||
"discardValue": discard_value(item.rating),
|
||||
|
||||
@@ -6,10 +6,13 @@
|
||||
//! socket — a Rust UTAS host wires it to Core later.
|
||||
pub mod catalog;
|
||||
pub mod club_response;
|
||||
pub mod club_stats;
|
||||
pub mod content_taxonomy;
|
||||
pub mod economy;
|
||||
pub mod economy_policy;
|
||||
pub mod entities;
|
||||
pub mod item;
|
||||
pub mod non_economy;
|
||||
pub mod owned_query;
|
||||
pub mod pack_content;
|
||||
pub mod squad;
|
||||
|
||||
@@ -0,0 +1,684 @@
|
||||
//! FIFA17 non-economy presentation routes, migrated from the Python oracle.
|
||||
//!
|
||||
//! Pure, IO-free shapers that reproduce the **observed production** oracle
|
||||
//! contract (`fifa17-recon/tools/utas_server.py`) for the non-economy UTAS
|
||||
//! routes a Rust host can own without any Core or account state:
|
||||
//!
|
||||
//! * `GET …/user/accountinfo` → `{}` (FUT_ACCOUNTINFO off)
|
||||
//! * `GET …/settings` → `{"configs":[]}` (FUT_SETTINGS off)
|
||||
//! * `GET …/leaderboards/options` → `{}` (FUT_MODES off)
|
||||
//! * `PUT …/match/reset` → `{}` (Tier-B no-op ack)
|
||||
//! * `GET/POST/PUT …/phishing/{trusteddevice,question,validate}` — the retired
|
||||
//! FUT security-question service, a stateless acknowledgement.
|
||||
//!
|
||||
//! These match the bodies the live prod oracle actually returns under the
|
||||
//! production environment (`FUT_TRADING=1 FUT_PILESIZES=1 FUT_TRADEABLE=1`, none
|
||||
//! of the feature flags set). They carry no persisted state: the security
|
||||
//! record the oracle seeds (`{version:1,verified:true}`) is log-only — the
|
||||
//! response is invariant — so a faithful Rust owner needs no persistence.
|
||||
|
||||
use serde_json::{json, Value};
|
||||
|
||||
/// `GET …/user/accountinfo` — production oracle returns an empty object.
|
||||
pub fn accountinfo_body() -> Value {
|
||||
json!({})
|
||||
}
|
||||
|
||||
/// `GET …/settings` — production oracle returns an empty config list.
|
||||
pub fn settings_body() -> Value {
|
||||
json!({ "configs": [] })
|
||||
}
|
||||
|
||||
/// `GET …/leaderboards/options` — production oracle (FUT_MODES off) returns an
|
||||
/// empty object; the retail client ignores the body.
|
||||
pub fn leaderboard_options_body() -> Value {
|
||||
json!({})
|
||||
}
|
||||
|
||||
/// `PUT …/match/reset` — Tier-B no-op acknowledgement.
|
||||
pub fn match_reset_body() -> Value {
|
||||
json!({})
|
||||
}
|
||||
|
||||
/// `GET …/club/stats/staff` — production oracle returns an empty object (FIFA's
|
||||
/// staff-bonus stat set is deliberately empty; the client tolerates `{}`).
|
||||
pub fn club_stats_staff_body() -> Value {
|
||||
json!({})
|
||||
}
|
||||
|
||||
/// The FUT modes (Seasons / Tournaments / FUT Champions) and the club-identity
|
||||
/// service are disabled in this emulator, so their read routes (`season`,
|
||||
/// `tournament`, `champion`, `clubUser`, `user/list`) return an empty object —
|
||||
/// byte-identical to the Python oracle with `FUT_MODES` / `FUT_CLUB_IDENTITY`
|
||||
/// off. Enabling a mode later requires a real Rust implementation here, never a
|
||||
/// Python fallback (which would reintroduce split authority).
|
||||
pub fn feature_off_body() -> Value {
|
||||
json!({})
|
||||
}
|
||||
|
||||
/// One FUT item-definition for a requested `resource_id`, replicating the Python
|
||||
/// oracle's `item_def`: `assetId = resource_id & 0xffffff`; a single hardcoded
|
||||
/// card (Ronaldo, asset 20801) and a generic placeholder (`"Player"`, 75, CM,
|
||||
/// attrs 70) for every other asset. The FIFA client renders the real card from
|
||||
/// its LOCAL DB from the `(rareflag, resourceId)` pair, so this route only needs
|
||||
/// a valid-shaped record — the placeholder is exactly what the oracle itself
|
||||
/// returns for all but the one hardcoded asset. Key order is irrelevant (the
|
||||
/// client's deserializer is key-addressed and skip-safe).
|
||||
pub fn item_def(resource_id: i64) -> Value {
|
||||
let asset = resource_id & 0xff_ffff;
|
||||
// (name, rating, position, nation, leagueId, teamid, [6 attrs])
|
||||
let (name, rating, pos, nation, league, team, attrs): (&str, i64, &str, i64, i64, i64, [i64; 6]) =
|
||||
if asset == 20801 {
|
||||
("Ronaldo", 94, "ST", 38, 53, 243, [90, 93, 82, 91, 33, 80])
|
||||
} else {
|
||||
("Player", 75, "CM", 0, 0, 0, [70, 70, 70, 70, 70, 70])
|
||||
};
|
||||
let attribute_list: Vec<Value> = attrs
|
||||
.iter()
|
||||
.enumerate()
|
||||
.map(|(i, v)| json!({ "index": i, "value": v }))
|
||||
.collect();
|
||||
json!({
|
||||
"id": resource_id,
|
||||
"resourceId": resource_id,
|
||||
"definitionId": resource_id,
|
||||
"assetId": asset,
|
||||
"cardassetid": asset,
|
||||
"commodityId": asset,
|
||||
"cardsubtypeid": 0,
|
||||
"cardType": 0,
|
||||
"itemType": "player",
|
||||
"rareflag": 1,
|
||||
"rating": rating,
|
||||
"preferredPosition": pos,
|
||||
"nation": nation,
|
||||
"leagueId": league,
|
||||
"teamid": team,
|
||||
"playStyle": 250,
|
||||
"attributeList": attribute_list,
|
||||
"name": name,
|
||||
"commonName": name,
|
||||
"lastName": name,
|
||||
"itemState": "free",
|
||||
"untradeable": true,
|
||||
})
|
||||
}
|
||||
|
||||
/// `GET …/item/resource`, `…/defid` — `{itemData:[…]}` with one [`item_def`] per
|
||||
/// requested id (mirrors the oracle's `defs_route`). No ids → an empty list.
|
||||
pub fn item_defs_body(ids: &[i64]) -> Value {
|
||||
json!({ "itemData": ids.iter().map(|&id| item_def(id)).collect::<Vec<_>>() })
|
||||
}
|
||||
|
||||
/// `GET …/marketdata/pricelimits?defId=a,b,c` — FutGetSuggestedPricing. The root
|
||||
/// MUST be a BARE ARRAY (one element per defId): returning an object here froze a
|
||||
/// live client (object-where-array busy loop at the listing screen). Constant
|
||||
/// band 150..15000 (placeholder pricing; not a freeze concern).
|
||||
pub fn marketdata_pricelimits_body(def_ids: &[i64]) -> Value {
|
||||
json!(def_ids
|
||||
.iter()
|
||||
.map(|&d| json!({ "defId": d, "minPrice": 150, "maxPrice": 15000 }))
|
||||
.collect::<Vec<_>>())
|
||||
}
|
||||
|
||||
/// `GET …/marketdata` (NOT `/pricelimits`) — the price-comparison endpoint, which
|
||||
/// takes an OBJECT `{minPrice,maxPrice}`. Array-where-object would be the same
|
||||
/// freeze in reverse, so the container type is load-bearing. Constant band.
|
||||
pub fn marketdata_object_body() -> Value {
|
||||
json!({ "minPrice": 150, "maxPrice": 15000 })
|
||||
}
|
||||
|
||||
/// The phishing/security-question action, parsed from the URL tail.
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub enum SecurityAction {
|
||||
TrustedDevice,
|
||||
Question,
|
||||
Validate,
|
||||
Unknown,
|
||||
}
|
||||
|
||||
/// The `phishing/<action>` selector from a `…/phishing/<action>` path tail.
|
||||
pub fn parse_security_action(tail: &str) -> SecurityAction {
|
||||
let last = tail.trim_end_matches('/').rsplit('/').next().unwrap_or("");
|
||||
match last {
|
||||
"trusteddevice" => SecurityAction::TrustedDevice,
|
||||
"question" => SecurityAction::Question,
|
||||
"validate" => SecurityAction::Validate,
|
||||
_ => SecurityAction::Unknown,
|
||||
}
|
||||
}
|
||||
|
||||
/// A well-formed FUT phishing token is an opaque 32-char lowercase/uppercase hex
|
||||
/// value (`_PHISHING_HEX32.fullmatch` in the oracle).
|
||||
fn is_hex32(s: &str) -> bool {
|
||||
s.len() == 32 && s.bytes().all(|b| b.is_ascii_hexdigit())
|
||||
}
|
||||
|
||||
/// Reproduce `utas_server.py::security_question_route` verbatim.
|
||||
///
|
||||
/// The retired FUT security-question service is a stateless acknowledgement: it
|
||||
/// validates request shape (session, 32-hex device id, 32-hex answer, numeric
|
||||
/// question) and returns fixed bodies. The answer is a client-transformed opaque
|
||||
/// value that is **never stored or compared**; the trusted-device response is an
|
||||
/// invariant `verified/trusted` constant.
|
||||
///
|
||||
/// * `session_known` — whether `X-UT-SID` maps to an open Rust session.
|
||||
/// * `device_id` / `question` / `answer` — decoded query parameters (`""`/`None`
|
||||
/// when absent).
|
||||
///
|
||||
/// Returns `(http_status, body)`.
|
||||
pub fn security_question_response(
|
||||
method: &str,
|
||||
action: SecurityAction,
|
||||
session_known: bool,
|
||||
device_id: &str,
|
||||
question: Option<&str>,
|
||||
answer: Option<&str>,
|
||||
) -> (u16, Value) {
|
||||
let is = |m: &str| method.eq_ignore_ascii_case(m);
|
||||
if !session_known {
|
||||
return (400, json!({ "reason": "invalid_session" }));
|
||||
}
|
||||
if !is_hex32(device_id) {
|
||||
return (400, json!({ "reason": "malformed_request" }));
|
||||
}
|
||||
match action {
|
||||
SecurityAction::TrustedDevice => {
|
||||
if !is("GET") {
|
||||
return (405, json!({ "reason": "method_not_allowed" }));
|
||||
}
|
||||
(
|
||||
200,
|
||||
json!({ "changed": false, "exists": true, "locked": false, "trusted": true }),
|
||||
)
|
||||
}
|
||||
SecurityAction::Question if is("GET") => (
|
||||
200,
|
||||
json!({ "question": 0, "attempts": 5, "recoverAttempts": 0 }),
|
||||
),
|
||||
SecurityAction::Question if is("POST") || is("PUT") => {
|
||||
let q = question.unwrap_or("");
|
||||
let a = answer.unwrap_or("");
|
||||
if q.is_empty() || !q.bytes().all(|b| b.is_ascii_digit()) || !is_hex32(a) {
|
||||
return (400, json!({ "reason": "malformed_request" }));
|
||||
}
|
||||
(200, json!({}))
|
||||
}
|
||||
SecurityAction::Validate if is("POST") => {
|
||||
let a = answer.unwrap_or("");
|
||||
if !is_hex32(a) {
|
||||
return (400, json!({ "reason": "malformed_request" }));
|
||||
}
|
||||
(200, json!({}))
|
||||
}
|
||||
_ => (405, json!({ "reason": "method_not_allowed" })),
|
||||
}
|
||||
}
|
||||
|
||||
// ─────────────────── POST /openfut/account/sync (Rust-owned) ─────────────────
|
||||
|
||||
/// The launcher `account/sync` request fields, with production defaults already
|
||||
/// applied. Everything is optional in the wire body; missing fields fall back to
|
||||
/// the fixed defaults the launcher expects. `personaId` defaults to the host's
|
||||
/// configured persona (passed in), never a baked-in constant.
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub struct AccountSyncRequest {
|
||||
pub persona_id: i64,
|
||||
pub persona_name: String,
|
||||
pub level: i64,
|
||||
pub experience: i64,
|
||||
pub experience_max: i64,
|
||||
pub account_funds: i64,
|
||||
pub account_funds_cap: i64,
|
||||
}
|
||||
|
||||
/// The FIFA persona display name for this emulator's single account.
|
||||
///
|
||||
/// The oracle sources this from the shared account (`fut_account.py`, default
|
||||
/// `"CAGE"`) and documents the property as "Blaze PDTL.DSNM / LSX
|
||||
/// GetProfileResponse Persona / **UTAS sellerName**". That last role is
|
||||
/// load-bearing: the client decides whether a transfer-market listing is the
|
||||
/// player's OWN — and therefore whether to offer Remove / Re-list at all — from
|
||||
/// the seller identity on the auction record. Stamping EA's house name there
|
||||
/// makes the player's own listing un-actionable (pressing it opens no dialog).
|
||||
pub const PERSONA_DISPLAY_NAME: &str = "CAGE";
|
||||
|
||||
/// Parse the `account/sync` request body, applying every default. `default_persona`
|
||||
/// is the host's configured persona id (used when `personaId` is absent).
|
||||
pub fn parse_account_sync(body: &[u8], default_persona: i64) -> AccountSyncRequest {
|
||||
let v: Value = serde_json::from_slice(body).unwrap_or(Value::Null);
|
||||
let int = |key: &str, dflt: i64| v.get(key).and_then(Value::as_i64).unwrap_or(dflt);
|
||||
let persona_name = v
|
||||
.get("personaName")
|
||||
.and_then(Value::as_str)
|
||||
.unwrap_or(PERSONA_DISPLAY_NAME)
|
||||
.to_string();
|
||||
AccountSyncRequest {
|
||||
persona_id: int("personaId", default_persona),
|
||||
persona_name,
|
||||
level: int("level", 1),
|
||||
experience: int("experience", 0),
|
||||
experience_max: int("experienceMax", 1000),
|
||||
account_funds: int("accountFunds", 0),
|
||||
account_funds_cap: int("accountFundsCap", 100000),
|
||||
}
|
||||
}
|
||||
|
||||
/// `POST /openfut/account/sync` — the launcher control-plane account summary.
|
||||
/// `coins`/`unopened_packs` are the AUTHORITATIVE Core values (balance +
|
||||
/// entitlement count), never Python's stale profile funds.
|
||||
pub fn account_sync_body(
|
||||
req: &AccountSyncRequest,
|
||||
coins: i64,
|
||||
unopened_packs: usize,
|
||||
club_name: &str,
|
||||
club_abbr: &str,
|
||||
) -> Value {
|
||||
json!({
|
||||
"account": {
|
||||
"personaId": req.persona_id,
|
||||
"personaName": req.persona_name,
|
||||
"clubName": club_name,
|
||||
"clubAbbr": club_abbr,
|
||||
"level": req.level,
|
||||
"experience": req.experience,
|
||||
"experienceMax": req.experience_max,
|
||||
"accountFunds": req.account_funds,
|
||||
"accountFundsCap": req.account_funds_cap,
|
||||
"profilePath": "accounts/33068179/fifa17_profile.json",
|
||||
"coins": coins,
|
||||
"unopenedPacks": unopened_packs,
|
||||
},
|
||||
"status": "OK",
|
||||
})
|
||||
}
|
||||
|
||||
// ─────────────────────── GET …/userMassInfo (Rust-owned) ─────────────────────
|
||||
|
||||
/// Build the full `GET …/userMassInfo` body entirely in Rust (no Python).
|
||||
///
|
||||
/// `squad` is the Core-projected active squad (`user_mass_info_squad` output), so
|
||||
/// it is byte-for-byte the object `GET …/squad/active` embeds. `coins` and
|
||||
/// `unopened_packs` are the authoritative Core economy values. `userInfo.actives`
|
||||
/// mirrors the squad's `actives` (capped at 5), and `userInfo.squadList` is the
|
||||
/// summary of the current squad.
|
||||
pub fn user_mass_info_body(
|
||||
squad: Value,
|
||||
coins: i64,
|
||||
unopened_packs: usize,
|
||||
persona_id: i64,
|
||||
club_name: &str,
|
||||
club_abbr: &str,
|
||||
established: &str,
|
||||
) -> Value {
|
||||
let actives: Vec<Value> = squad
|
||||
.get("actives")
|
||||
.and_then(Value::as_array)
|
||||
.map(|a| a.iter().take(5).cloned().collect())
|
||||
.unwrap_or_default();
|
||||
let squad_list = crate::fut::squad_projection::squad_list(&squad);
|
||||
let mut user_info = json!({
|
||||
"personaId": persona_id,
|
||||
"clubName": club_name,
|
||||
"clubAbbr": club_abbr,
|
||||
"established": established,
|
||||
"accountCreatedPlatformName": "pc",
|
||||
"currencies": [
|
||||
{"name": "coins", "funds": coins, "finalFunds": coins, "active": true},
|
||||
{"name": "points", "funds": 0, "finalFunds": 0, "active": true},
|
||||
],
|
||||
"won": 0,
|
||||
"draw": 0,
|
||||
"loss": 0,
|
||||
"clubNameChangeAllowed": false,
|
||||
"divisionOffline": 10,
|
||||
"divisionOnline": 10,
|
||||
"purchased": false,
|
||||
"feature": {},
|
||||
"reliability": {"reliability": 100, "matchUnfinishedTime": 0},
|
||||
"bidTokens": {"count": 0, "updateTime": 0},
|
||||
"trophies": 0,
|
||||
"sessionCoinsBankBalance": 0,
|
||||
"actives": actives,
|
||||
"squadList": squad_list,
|
||||
});
|
||||
if unopened_packs > 0 {
|
||||
user_info.as_object_mut().unwrap().insert(
|
||||
"unopenedPacks".into(),
|
||||
json!({"preOrderPacks": 0, "recoveredPacks": unopened_packs}),
|
||||
);
|
||||
}
|
||||
json!({
|
||||
"pileSizeClientData": {"entries": [{"key": 2, "value": 100}, {"key": 4, "value": 50}]},
|
||||
"settings": {"configs": []},
|
||||
"userData": {},
|
||||
"squad": squad,
|
||||
"userInfo": user_info,
|
||||
})
|
||||
}
|
||||
|
||||
// ───────────────────────────── POST /ut/auth (Rust) ──────────────────────────
|
||||
|
||||
/// Format `epoch_secs` (seconds since the Unix epoch) as UTC
|
||||
/// `YYYY-MM-DD HH:MM:SS`. Pure civil-date arithmetic (Howard Hinnant's
|
||||
/// `civil_from_days`), so no `time`/`chrono` dependency is needed.
|
||||
pub fn format_utc_datetime(epoch_secs: i64) -> String {
|
||||
let days = epoch_secs.div_euclid(86_400);
|
||||
let secs_of_day = epoch_secs.rem_euclid(86_400);
|
||||
let (hour, min, sec) = (secs_of_day / 3600, (secs_of_day % 3600) / 60, secs_of_day % 60);
|
||||
// civil_from_days: days is a count of days since 1970-01-01.
|
||||
let z = days + 719_468;
|
||||
let era = if z >= 0 { z } else { z - 146_096 } / 146_097;
|
||||
let doe = z - era * 146_097; // [0, 146096]
|
||||
let yoe = (doe - doe / 1460 + doe / 36_524 - doe / 146_096) / 365; // [0, 399]
|
||||
let year = yoe + era * 400;
|
||||
let doy = doe - (365 * yoe + yoe / 4 - yoe / 100); // [0, 365]
|
||||
let mp = (5 * doy + 2) / 153; // [0, 11]
|
||||
let day = doy - (153 * mp + 2) / 5 + 1; // [1, 31]
|
||||
let month = if mp < 10 { mp + 3 } else { mp - 9 }; // [1, 12]
|
||||
let year = if month <= 2 { year + 1 } else { year };
|
||||
format!("{year:04}-{month:02}-{day:02} {hour:02}:{min:02}:{sec:02}")
|
||||
}
|
||||
|
||||
/// The persona a `/ut/auth` request adopts: `nucleusPersonaId` or `nuc` from the
|
||||
/// body (numeric or numeric string), else `None` (the host substitutes its
|
||||
/// configured persona). The client is never refused.
|
||||
pub fn parse_auth_persona(body: &[u8]) -> Option<i64> {
|
||||
let v: Value = serde_json::from_slice(body).ok()?;
|
||||
let field = |key: &str| {
|
||||
v.get(key).and_then(|x| {
|
||||
x.as_i64()
|
||||
.or_else(|| x.as_str().and_then(|s| s.parse::<i64>().ok()))
|
||||
})
|
||||
};
|
||||
field("nucleusPersonaId").or_else(|| field("nuc"))
|
||||
}
|
||||
|
||||
/// `POST /ut/auth` response body. `sid` is the freshly minted Rust session id;
|
||||
/// `server_time` is UTC `YYYY-MM-DD HH:MM:SS` (also used for `lastOnlineTime`).
|
||||
pub fn auth_body(sid: &str, server_time: &str) -> Value {
|
||||
json!({
|
||||
"protocol": 1,
|
||||
"sid": sid,
|
||||
"serverTime": server_time,
|
||||
"lastOnlineTime": server_time,
|
||||
})
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
const DEV: &str = "6236375476659cd0f6c780e728774b71"; // 32-hex (live deviceId)
|
||||
const ANS: &str = "0123456789abcdef0123456789abcdef";
|
||||
|
||||
#[test]
|
||||
fn static_bodies_match_oracle() {
|
||||
assert_eq!(accountinfo_body(), json!({}));
|
||||
assert_eq!(settings_body(), json!({ "configs": [] }));
|
||||
assert_eq!(leaderboard_options_body(), json!({}));
|
||||
assert_eq!(match_reset_body(), json!({}));
|
||||
assert_eq!(club_stats_staff_body(), json!({}));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn action_parse() {
|
||||
assert_eq!(
|
||||
parse_security_action("phishing/trusteddevice"),
|
||||
SecurityAction::TrustedDevice
|
||||
);
|
||||
assert_eq!(
|
||||
parse_security_action("phishing/question/"),
|
||||
SecurityAction::Question
|
||||
);
|
||||
assert_eq!(
|
||||
parse_security_action("phishing/validate"),
|
||||
SecurityAction::Validate
|
||||
);
|
||||
assert_eq!(
|
||||
parse_security_action("phishing/other"),
|
||||
SecurityAction::Unknown
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn trusted_device_verified_constant() {
|
||||
let (s, b) =
|
||||
security_question_response("GET", SecurityAction::TrustedDevice, true, DEV, None, None);
|
||||
assert_eq!(s, 200);
|
||||
assert_eq!(
|
||||
b,
|
||||
json!({ "changed": false, "exists": true, "locked": false, "trusted": true })
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn no_session_is_400_invalid_session() {
|
||||
let (s, b) = security_question_response(
|
||||
"GET",
|
||||
SecurityAction::TrustedDevice,
|
||||
false,
|
||||
DEV,
|
||||
None,
|
||||
None,
|
||||
);
|
||||
assert_eq!(s, 400);
|
||||
assert_eq!(b, json!({ "reason": "invalid_session" }));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn bad_device_id_is_malformed() {
|
||||
for bad in [
|
||||
"",
|
||||
"xyz",
|
||||
"6236375476659cd0f6c780e728774b7",
|
||||
"not-hex-not-hex-not-hex-not-hexx",
|
||||
] {
|
||||
let (s, b) = security_question_response(
|
||||
"GET",
|
||||
SecurityAction::TrustedDevice,
|
||||
true,
|
||||
bad,
|
||||
None,
|
||||
None,
|
||||
);
|
||||
assert_eq!(s, 400, "device {bad:?}");
|
||||
assert_eq!(b, json!({ "reason": "malformed_request" }));
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn trusted_device_wrong_method_405() {
|
||||
let (s, _) = security_question_response(
|
||||
"POST",
|
||||
SecurityAction::TrustedDevice,
|
||||
true,
|
||||
DEV,
|
||||
None,
|
||||
None,
|
||||
);
|
||||
assert_eq!(s, 405);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn question_get_returns_prompt() {
|
||||
let (s, b) =
|
||||
security_question_response("GET", SecurityAction::Question, true, DEV, None, None);
|
||||
assert_eq!(s, 200);
|
||||
assert_eq!(
|
||||
b,
|
||||
json!({ "question": 0, "attempts": 5, "recoverAttempts": 0 })
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn question_setup_validates_shape() {
|
||||
// valid numeric question + 32-hex answer
|
||||
let (s, b) = security_question_response(
|
||||
"POST",
|
||||
SecurityAction::Question,
|
||||
true,
|
||||
DEV,
|
||||
Some("0"),
|
||||
Some(ANS),
|
||||
);
|
||||
assert_eq!(s, 200);
|
||||
assert_eq!(b, json!({}));
|
||||
// empty question -> malformed
|
||||
let (s, _) = security_question_response(
|
||||
"POST",
|
||||
SecurityAction::Question,
|
||||
true,
|
||||
DEV,
|
||||
Some(""),
|
||||
Some(ANS),
|
||||
);
|
||||
assert_eq!(s, 400);
|
||||
// non-digit question -> malformed
|
||||
let (s, _) = security_question_response(
|
||||
"PUT",
|
||||
SecurityAction::Question,
|
||||
true,
|
||||
DEV,
|
||||
Some("x"),
|
||||
Some(ANS),
|
||||
);
|
||||
assert_eq!(s, 400);
|
||||
// bad answer -> malformed
|
||||
let (s, _) = security_question_response(
|
||||
"POST",
|
||||
SecurityAction::Question,
|
||||
true,
|
||||
DEV,
|
||||
Some("0"),
|
||||
Some("short"),
|
||||
);
|
||||
assert_eq!(s, 400);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn validate_checks_answer() {
|
||||
let (s, b) = security_question_response(
|
||||
"POST",
|
||||
SecurityAction::Validate,
|
||||
true,
|
||||
DEV,
|
||||
None,
|
||||
Some(ANS),
|
||||
);
|
||||
assert_eq!(s, 200);
|
||||
assert_eq!(b, json!({}));
|
||||
let (s, _) = security_question_response(
|
||||
"POST",
|
||||
SecurityAction::Validate,
|
||||
true,
|
||||
DEV,
|
||||
None,
|
||||
Some("nope"),
|
||||
);
|
||||
assert_eq!(s, 400);
|
||||
// wrong method for validate
|
||||
let (s, _) =
|
||||
security_question_response("GET", SecurityAction::Validate, true, DEV, None, Some(ANS));
|
||||
assert_eq!(s, 405);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn account_sync_defaults_and_core_economy() {
|
||||
// Empty body -> every default applied; persona falls back to the host's.
|
||||
let req = parse_account_sync(b"", 33_068_179);
|
||||
assert_eq!(req.persona_id, 33_068_179);
|
||||
assert_eq!(req.persona_name, "CAGE");
|
||||
assert_eq!(req.level, 1);
|
||||
assert_eq!(req.experience_max, 1000);
|
||||
assert_eq!(req.account_funds_cap, 100_000);
|
||||
let body = account_sync_body(&req, 29_859_876, 2, "Real FUT", "RF");
|
||||
let acc = &body["account"];
|
||||
assert_eq!(acc["clubName"], "Real FUT");
|
||||
assert_eq!(acc["clubAbbr"], "RF");
|
||||
assert_eq!(acc["profilePath"], "accounts/33068179/fifa17_profile.json");
|
||||
assert_eq!(acc["coins"], 29_859_876);
|
||||
assert_eq!(acc["unopenedPacks"], 2);
|
||||
assert_eq!(body["status"], "OK");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn account_sync_honours_request_overrides() {
|
||||
let req = parse_account_sync(
|
||||
br#"{"personaId":42,"personaName":"X","level":9,"accountFunds":500}"#,
|
||||
33_068_179,
|
||||
);
|
||||
assert_eq!(req.persona_id, 42);
|
||||
assert_eq!(req.persona_name, "X");
|
||||
assert_eq!(req.level, 9);
|
||||
assert_eq!(req.account_funds, 500);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn user_mass_info_flat_shape() {
|
||||
let squad = json!({
|
||||
"id": 0,
|
||||
"squadName": "OpenFUT",
|
||||
"formation": "f433",
|
||||
"squadType": "REGULAR_SQUAD",
|
||||
"rating": 90,
|
||||
"chemistry": 49,
|
||||
"actives": [],
|
||||
"players": [],
|
||||
});
|
||||
let body = user_mass_info_body(squad, 29_859_876, 0, 33_068_179, "Real FUT", "RF", "2016");
|
||||
// Flat top-level envelope.
|
||||
assert_eq!(body["pileSizeClientData"]["entries"][0], json!({"key": 2, "value": 100}));
|
||||
assert_eq!(body["pileSizeClientData"]["entries"][1], json!({"key": 4, "value": 50}));
|
||||
assert_eq!(body["settings"], json!({"configs": []}));
|
||||
assert_eq!(body["userData"], json!({}));
|
||||
// userInfo economy + club identity.
|
||||
let ui = &body["userInfo"];
|
||||
assert_eq!(ui["personaId"], 33_068_179);
|
||||
assert_eq!(ui["clubName"], "Real FUT");
|
||||
assert_eq!(ui["clubAbbr"], "RF");
|
||||
assert_eq!(ui["established"], "2016"); // string, not number
|
||||
assert_eq!(ui["accountCreatedPlatformName"], "pc");
|
||||
assert_eq!(ui["currencies"][0]["name"], "coins");
|
||||
assert_eq!(ui["currencies"][0]["funds"], 29_859_876);
|
||||
assert_eq!(ui["currencies"][0]["finalFunds"], 29_859_876);
|
||||
assert_eq!(ui["currencies"][1]["name"], "points");
|
||||
assert_eq!(ui["reliability"]["reliability"], 100);
|
||||
assert_eq!(ui["divisionOnline"], 10);
|
||||
assert!(ui.get("unopenedPacks").is_none(), "no packs -> key omitted");
|
||||
assert_eq!(ui["squadList"]["squad"][0]["squadName"], "OpenFUT");
|
||||
// Squad object embedded flat under top-level `squad`.
|
||||
assert_eq!(body["squad"]["squadName"], "OpenFUT");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn user_mass_info_includes_unopened_packs_when_present() {
|
||||
let squad = json!({"id": 0, "actives": [], "players": []});
|
||||
let body = user_mass_info_body(squad, 100, 3, 33_068_179, "OpenFUT", "OFC", "2026");
|
||||
assert_eq!(body["userInfo"]["unopenedPacks"]["recoveredPacks"], 3);
|
||||
assert_eq!(body["userInfo"]["unopenedPacks"]["preOrderPacks"], 0);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn utc_datetime_formats_known_epochs() {
|
||||
// 2026-08-17 03:54:47 UTC == 1_786_938_887.
|
||||
assert_eq!(format_utc_datetime(1_786_938_887), "2026-08-17 03:54:47");
|
||||
// Unix epoch.
|
||||
assert_eq!(format_utc_datetime(0), "1970-01-01 00:00:00");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn auth_persona_and_body() {
|
||||
assert_eq!(
|
||||
parse_auth_persona(br#"{"nucleusPersonaId":33068179}"#),
|
||||
Some(33_068_179)
|
||||
);
|
||||
assert_eq!(parse_auth_persona(br#"{"nuc":"42"}"#), Some(42));
|
||||
assert_eq!(parse_auth_persona(b"{}"), None);
|
||||
let b = auth_body("OPENFUT-SID-DEADBEEF", "2026-08-17 03:54:47");
|
||||
assert_eq!(b["protocol"], 1);
|
||||
assert_eq!(b["sid"], "OPENFUT-SID-DEADBEEF");
|
||||
assert_eq!(b["serverTime"], "2026-08-17 03:54:47");
|
||||
assert_eq!(b["lastOnlineTime"], "2026-08-17 03:54:47");
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
[package]
|
||||
name = "openfut-autopatch"
|
||||
version = "0.1.0"
|
||||
edition = "2021"
|
||||
license = "MIT"
|
||||
description = "Applies the FIFA 17 ProtoSSL cert and CardsDLL store patches to a running client"
|
||||
publish = false
|
||||
|
||||
# Deliberately dependency-free. Everything this needs is in std: /proc scanning for
|
||||
# the client pid, and positioned reads/writes against /proc/<pid>/mem via
|
||||
# std::os::unix::fs::FileExt. A patcher that edits another process's memory should be
|
||||
# auditable end to end without pulling in a dependency tree.
|
||||
[dependencies]
|
||||
@@ -0,0 +1,477 @@
|
||||
//! FIFA 17 client patcher — the ProtoSSL cert gates and the CardsDLL FUT store
|
||||
//! patches, applied to a running `FIFA17.exe` through `/proc/<pid>/mem`.
|
||||
//!
|
||||
//! Port of `fifa17-recon/tools/autopatch.py`; that file is the specification and
|
||||
//! every address, byte pattern and log line here is reproduced from it verbatim.
|
||||
//! The store patches are re-applied on every tick because the game rewrites
|
||||
//! those sites; the cert gates are applied once per pid.
|
||||
//!
|
||||
//! This module holds the constants, the two pure decision functions and the
|
||||
//! parsers. The enforcement passes live in [`patch`], process access in
|
||||
//! [`procmem`], timestamping in [`localtime`], and the watch loop in `main.rs`.
|
||||
|
||||
pub mod localtime;
|
||||
pub mod logging;
|
||||
pub mod patch;
|
||||
pub mod procmem;
|
||||
|
||||
use std::fmt;
|
||||
|
||||
pub use logging::Logger;
|
||||
|
||||
/// `/proc/<pid>/comm` of the client we patch (exact match after trimming).
|
||||
pub const CLIENT_COMM: &str = "FIFA17.exe";
|
||||
|
||||
/// Substring identifying the CardsDLL mapping in `/proc/<pid>/maps`.
|
||||
pub const CARDSDLL_MARKER: &str = "CardsDLL";
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// ProtoSSL certificate gates (absolute VAs in the unpacked FIFA17.exe image;
|
||||
// present only once the packer has mapped the real code, hence the watch loop).
|
||||
// ---------------------------------------------------------------------------
|
||||
|
||||
pub const GATE2: u64 = 0x1461361b0;
|
||||
pub const GATE2_ORIG: [u8; 3] = [0x48, 0x89, 0x5c];
|
||||
pub const GATE2_PATCH: [u8; 3] = [0x31, 0xc0, 0xc3];
|
||||
|
||||
pub const GATE1: u64 = 0x146132548;
|
||||
pub const GATE1_ORIG: [u8; 6] = [0x0f, 0x85, 0x76, 0x01, 0x00, 0x00];
|
||||
pub const GATE1_PATCH: [u8; 6] = [0x90; 6];
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// FUT store patches, expressed against the CardsDLL preferred image base and
|
||||
// relocated to the live mapping base at runtime.
|
||||
// ---------------------------------------------------------------------------
|
||||
|
||||
/// `mov eax, 1; ret` — force a predicate true.
|
||||
pub const RET_TRUE: [u8; 6] = [0xb8, 0x01, 0x00, 0x00, 0x00, 0xc3];
|
||||
/// Two `nop`s.
|
||||
pub const NOP2: [u8; 2] = [0x90, 0x90];
|
||||
/// `jmp +0x3f`, the one non-uniform store patch (site `0x180017543`).
|
||||
pub const SHORT_JMP_3F: [u8; 2] = [0xeb, 0x3f];
|
||||
/// CardsDLL's preferred image base; live address = `cbase + (va - IMG_BASE)`.
|
||||
pub const IMG_BASE: u64 = 0x180000000;
|
||||
|
||||
/// Unconditional store patches, in the Python's insertion order — the order
|
||||
/// decides the order of the `ENFORCED store patch` log lines.
|
||||
///
|
||||
/// The Python carries no per-site rationale for these eight sites, so none is
|
||||
/// invented here; the addresses and bytes are reproduced verbatim.
|
||||
pub const STORE_PATCHES: [(u64, &[u8]); 8] = [
|
||||
(0x1800f7fb0, &RET_TRUE),
|
||||
(0x1800fb850, &RET_TRUE),
|
||||
(0x180100500, &RET_TRUE),
|
||||
(0x180013cf0, &RET_TRUE),
|
||||
(0x180017543, &SHORT_JMP_3F),
|
||||
(0x180017487, &NOP2),
|
||||
(0x180017490, &NOP2),
|
||||
(0x1800175aa, &NOP2),
|
||||
];
|
||||
|
||||
/// Store resolver crash-guard for the empty "My Packs" case (bug 6c; PROVEN R1 on the
|
||||
/// tested FIFA 17 build -- see docs/plans/FIFA17_EMPTY_MYPACKS_CLIENT_FIX.md PART IV and
|
||||
/// docs/evidence/FIFA17_EMPTY_MYPACKS_CLIENT_CONTRACT.md).
|
||||
///
|
||||
/// When no `mypacks` group exists, FIFA's Store resolver receives category id -1. CardsDLL
|
||||
/// FUN_1800147f0 @ 0x180014858 is `JNZ 0x14869` (75 0f): the original treats every non-zero
|
||||
/// category (including -1) as resolvable, calls FUN_180014420, gets NULL, and crashes at the
|
||||
/// \[NULL+0x48\] deref in FUN_1800147f0 (0x180014882). Changing JNZ->JG (7f 0f) preserves
|
||||
/// positive-category resolution (EDI>0 branch) while routing zero/negative categories through
|
||||
/// the existing Browse/list-all path -> no NULL lookup, no crash, Store opens on Browse Packs.
|
||||
///
|
||||
/// CAVEAT: this guards the category SIGN only. It does NOT protect a stale *positive* invalid
|
||||
/// ordinal produced by changing the Store group topology (sentinel-present <-> sentinel-absent)
|
||||
/// DURING one running FIFA process -- that reproduced the same crash in the confounded run F3.
|
||||
/// The empty-My-Packs representation MUST stay stable for a FIFA session (see the SESSION-STABLE
|
||||
/// invariant in the client-fix plan).
|
||||
///
|
||||
/// Orig-verified / fail-closed: applied only when the live bytes are the known original (75 0f);
|
||||
/// already-patched (7f 0f) is a no-op; anything else is logged and SKIPPED (never blindly
|
||||
/// overwritten), so an unrecognised CardsDLL build is not patched.
|
||||
///
|
||||
/// Tuple layout: `(va, orig, patch)`. `JNZ 0x14869` -> `JG 0x14869`.
|
||||
pub const STORE_PATCHES_GUARDED: [(u64, &[u8], &[u8]); 1] =
|
||||
[(0x180014858, &[0x75, 0x0f], &[0x7f, 0x0f])];
|
||||
|
||||
/// Capability advertised to the launcher/backend once the resolver guard is VERIFIED
|
||||
/// live in a specific FIFA process (docs/plans/FIFA17_PATCHED_CLIENT_CAPABILITY.md #3/#4).
|
||||
pub const EMPTY_MYPACKS_RESOLVER_CAPABILITY: &str = "fifa17.empty_mypacks_resolver";
|
||||
pub const EMPTY_MYPACKS_RESOLVER_VERSION: u32 = 1;
|
||||
|
||||
/// The guarded site whose verified enforcement backs the capability above.
|
||||
pub const RESOLVER_GUARD_VA: u64 = 0x180014858;
|
||||
|
||||
/// Longest patch payload, so the watch loop can compare live bytes on the stack.
|
||||
pub const MAX_PATCH_LEN: usize = RET_TRUE.len();
|
||||
|
||||
// Compile-time proof that the watch loop's stack buffers are large enough, so no
|
||||
// slicing panic is reachable from the patch tables.
|
||||
const _: () = {
|
||||
let mut i = 0;
|
||||
while i < STORE_PATCHES.len() {
|
||||
assert!(STORE_PATCHES[i].1.len() <= MAX_PATCH_LEN);
|
||||
i += 1;
|
||||
}
|
||||
let mut i = 0;
|
||||
while i < STORE_PATCHES_GUARDED.len() {
|
||||
assert!(STORE_PATCHES_GUARDED[i].1.len() <= MAX_PATCH_LEN);
|
||||
assert!(STORE_PATCHES_GUARDED[i].2.len() <= MAX_PATCH_LEN);
|
||||
assert!(STORE_PATCHES_GUARDED[i].1.len() == STORE_PATCHES_GUARDED[i].2.len());
|
||||
i += 1;
|
||||
}
|
||||
};
|
||||
|
||||
/// Fail-closed decision for a guarded byte patch (see [`STORE_PATCHES_GUARDED`]).
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub enum GuardedAction {
|
||||
/// Live bytes are already the patch; nothing to write.
|
||||
Noop,
|
||||
/// Live bytes are the known original; safe to apply.
|
||||
Patch,
|
||||
/// Unrecognised CardsDLL build — never blindly overwritten.
|
||||
Skip,
|
||||
}
|
||||
|
||||
/// Per-FIFA-pid guard status (fail-closed; FIFA17_PATCHED_CLIENT_CAPABILITY.md #4).
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub enum GuardState {
|
||||
/// CardsDLL not mapped / guard not yet evaluated.
|
||||
NotAttempted,
|
||||
/// Live bytes == patch after enforcement (patch or noop).
|
||||
Verified,
|
||||
/// Neither original nor patched ([`GuardedAction::Skip`]).
|
||||
UnsupportedBuild,
|
||||
/// The `/proc/<pid>/mem` write failed.
|
||||
WriteFailed,
|
||||
/// Post-write re-read != patch.
|
||||
VerifyFailed,
|
||||
}
|
||||
|
||||
impl GuardState {
|
||||
/// Wire spelling used in the `[store-guard] guard status=…` line the launcher reads.
|
||||
pub fn as_str(self) -> &'static str {
|
||||
match self {
|
||||
GuardState::NotAttempted => "NOT_ATTEMPTED",
|
||||
GuardState::Verified => "VERIFIED",
|
||||
GuardState::UnsupportedBuild => "UNSUPPORTED_BUILD",
|
||||
GuardState::WriteFailed => "WRITE_FAILED",
|
||||
GuardState::VerifyFailed => "VERIFY_FAILED",
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl fmt::Display for GuardState {
|
||||
fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
|
||||
f.write_str(self.as_str())
|
||||
}
|
||||
}
|
||||
|
||||
/// Fail-closed decision for a guarded byte patch.
|
||||
///
|
||||
/// [`GuardedAction::Noop`] when the live bytes are already patched,
|
||||
/// [`GuardedAction::Patch`] when they are the known original (safe to apply), or
|
||||
/// [`GuardedAction::Skip`] for anything else — an unrecognised CardsDLL build
|
||||
/// that must never be blindly overwritten.
|
||||
pub fn guarded_action(cur: &[u8], orig: &[u8], patch: &[u8]) -> GuardedAction {
|
||||
if cur == patch {
|
||||
return GuardedAction::Noop;
|
||||
}
|
||||
if cur == orig {
|
||||
return GuardedAction::Patch;
|
||||
}
|
||||
GuardedAction::Skip
|
||||
}
|
||||
|
||||
/// Map a guarded-patch enforcement outcome to a per-pid guard STATE (pure).
|
||||
///
|
||||
/// Mirrors [`guarded_action`]'s decision, extended with post-write verification so the
|
||||
/// caller advertises the capability only on VERIFIED. No `/proc` access — unit-testable.
|
||||
///
|
||||
/// - `cur_before == patch` -> VERIFIED (already patched; [`GuardedAction::Noop`])
|
||||
/// - `cur_before == orig` -> WRITE_FAILED if the write raised, else VERIFIED when the
|
||||
/// re-read is patch, else VERIFY_FAILED ([`GuardedAction::Patch`])
|
||||
/// - otherwise -> UNSUPPORTED_BUILD ([`GuardedAction::Skip`])
|
||||
///
|
||||
/// [`GuardState::NotAttempted`] is never returned: it is the state a pid carries before
|
||||
/// the guard is evaluated at all (CardsDLL not mapped yet), and this function is only
|
||||
/// reached once live bytes have been read.
|
||||
pub fn guard_state_after(
|
||||
cur_before: &[u8],
|
||||
orig: &[u8],
|
||||
patch: &[u8],
|
||||
wrote_ok: bool,
|
||||
cur_after: &[u8],
|
||||
) -> GuardState {
|
||||
if cur_before == patch {
|
||||
return GuardState::Verified;
|
||||
}
|
||||
if cur_before == orig {
|
||||
if !wrote_ok {
|
||||
return GuardState::WriteFailed;
|
||||
}
|
||||
if cur_after == patch {
|
||||
return GuardState::Verified;
|
||||
}
|
||||
return GuardState::VerifyFailed;
|
||||
}
|
||||
GuardState::UnsupportedBuild
|
||||
}
|
||||
|
||||
/// Live address of an image-relative patch site inside the mapped CardsDLL.
|
||||
pub fn live_addr(cbase: u64, va: u64) -> u64 {
|
||||
cbase + (va - IMG_BASE)
|
||||
}
|
||||
|
||||
/// Lowercase, unseparated hex — the spelling of `bytes.hex()` in the SKIP log line.
|
||||
pub fn hex(bytes: &[u8]) -> String {
|
||||
let mut out = String::with_capacity(bytes.len() * 2);
|
||||
for b in bytes {
|
||||
// Two nibbles, no separator, no allocation per byte.
|
||||
const DIGITS: &[u8; 16] = b"0123456789abcdef";
|
||||
out.push(DIGITS[(b >> 4) as usize] as char);
|
||||
out.push(DIGITS[(b & 0x0f) as usize] as char);
|
||||
}
|
||||
out
|
||||
}
|
||||
|
||||
/// True when a `/proc/<pid>/comm` body names the FIFA 17 client.
|
||||
pub fn is_client_comm(comm: &str) -> bool {
|
||||
comm.trim() == CLIENT_COMM
|
||||
}
|
||||
|
||||
/// Pid from a `/proc` directory entry name.
|
||||
///
|
||||
/// The Python globs `/proc/[0-9]*` and then `int()`s the name inside a bare
|
||||
/// `except`, so a name has to start with a digit *and* be entirely numeric.
|
||||
pub fn pid_from_proc_entry(name: &str) -> Option<u32> {
|
||||
if !name.as_bytes().first().is_some_and(u8::is_ascii_digit) {
|
||||
return None;
|
||||
}
|
||||
name.parse::<u32>().ok()
|
||||
}
|
||||
|
||||
/// Base address of the first `CardsDLL` mapping in a `/proc/<pid>/maps` body.
|
||||
///
|
||||
/// Only the first matching line is considered, and a line whose base does not
|
||||
/// parse yields `None` rather than falling through to the next mapping — the
|
||||
/// Python's `int(...)` raises inside the `try` that returns `None`.
|
||||
pub fn parse_cardsdll_base(maps: &str) -> Option<u64> {
|
||||
let line = maps.lines().find(|line| line.contains(CARDSDLL_MARKER))?;
|
||||
u64::from_str_radix(line.split('-').next()?, 16).ok()
|
||||
}
|
||||
|
||||
/// `--launcher-pid <pid>` out of the argument list.
|
||||
///
|
||||
/// `Ok(None)` when the flag is absent, `Err(())` when it is present with a
|
||||
/// missing or non-numeric value (the Python raises `SystemExit`). The value is
|
||||
/// kept signed and un-clamped so the liveness check behaves exactly like the
|
||||
/// Python's `os.path.exists(f"/proc/{launcher_pid}")` for odd inputs.
|
||||
#[allow(clippy::result_unit_err)]
|
||||
pub fn parse_launcher_pid<I, S>(args: I) -> Result<Option<i64>, ()>
|
||||
where
|
||||
I: IntoIterator<Item = S>,
|
||||
S: AsRef<str>,
|
||||
{
|
||||
let args: Vec<S> = args.into_iter().collect();
|
||||
let Some(idx) = args.iter().position(|a| a.as_ref() == "--launcher-pid") else {
|
||||
return Ok(None);
|
||||
};
|
||||
let value = args.get(idx + 1).ok_or(())?;
|
||||
value.as_ref().trim().parse::<i64>().map(Some).map_err(|_| ())
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
const ORIG: &[u8] = &[0x75, 0x0f];
|
||||
const PATCH: &[u8] = &[0x7f, 0x0f];
|
||||
|
||||
#[test]
|
||||
fn constants_match_the_python_spec() {
|
||||
assert_eq!(GATE2, 0x1461361b0);
|
||||
assert_eq!(GATE2_ORIG, [0x48, 0x89, 0x5c]);
|
||||
assert_eq!(GATE2_PATCH, [0x31, 0xc0, 0xc3]);
|
||||
assert_eq!(GATE1, 0x146132548);
|
||||
assert_eq!(GATE1_ORIG, [0x0f, 0x85, 0x76, 0x01, 0x00, 0x00]);
|
||||
assert_eq!(GATE1_PATCH, [0x90, 0x90, 0x90, 0x90, 0x90, 0x90]);
|
||||
assert_eq!(IMG_BASE, 0x180000000);
|
||||
assert_eq!(hex(&RET_TRUE), "b801000000c3");
|
||||
assert_eq!(hex(&NOP2), "9090");
|
||||
|
||||
// Site order is part of the log contract, so assert the whole table.
|
||||
let sites: Vec<(u64, String)> = STORE_PATCHES
|
||||
.iter()
|
||||
.map(|(va, data)| (*va, hex(data)))
|
||||
.collect();
|
||||
assert_eq!(
|
||||
sites,
|
||||
vec![
|
||||
(0x1800f7fb0, "b801000000c3".to_string()),
|
||||
(0x1800fb850, "b801000000c3".to_string()),
|
||||
(0x180100500, "b801000000c3".to_string()),
|
||||
(0x180013cf0, "b801000000c3".to_string()),
|
||||
(0x180017543, "eb3f".to_string()),
|
||||
(0x180017487, "9090".to_string()),
|
||||
(0x180017490, "9090".to_string()),
|
||||
(0x1800175aa, "9090".to_string()),
|
||||
]
|
||||
);
|
||||
|
||||
assert_eq!(STORE_PATCHES_GUARDED.len(), 1);
|
||||
let (va, orig, patch) = STORE_PATCHES_GUARDED[0];
|
||||
assert_eq!(va, 0x180014858);
|
||||
assert_eq!(hex(orig), "750f");
|
||||
assert_eq!(hex(patch), "7f0f");
|
||||
assert_eq!(RESOLVER_GUARD_VA, va);
|
||||
assert_eq!(EMPTY_MYPACKS_RESOLVER_CAPABILITY, "fifa17.empty_mypacks_resolver");
|
||||
assert_eq!(EMPTY_MYPACKS_RESOLVER_VERSION, 1);
|
||||
assert_eq!(MAX_PATCH_LEN, 6);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn guarded_action_noops_when_already_patched() {
|
||||
assert_eq!(guarded_action(PATCH, ORIG, PATCH), GuardedAction::Noop);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn guarded_action_patches_the_known_original() {
|
||||
assert_eq!(guarded_action(ORIG, ORIG, PATCH), GuardedAction::Patch);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn guarded_action_skips_an_unrecognised_build() {
|
||||
// Fail-closed: an unknown CardsDLL build is never overwritten.
|
||||
assert_eq!(guarded_action(&[0x74, 0x0f], ORIG, PATCH), GuardedAction::Skip);
|
||||
assert_eq!(guarded_action(&[], ORIG, PATCH), GuardedAction::Skip);
|
||||
assert_eq!(guarded_action(&[0x75], ORIG, PATCH), GuardedAction::Skip);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn guard_state_verified_when_already_patched() {
|
||||
// wrote_ok / cur_after are irrelevant on this branch.
|
||||
assert_eq!(
|
||||
guard_state_after(PATCH, ORIG, PATCH, false, &[]),
|
||||
GuardState::Verified
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn guard_state_verified_after_a_successful_write() {
|
||||
assert_eq!(
|
||||
guard_state_after(ORIG, ORIG, PATCH, true, PATCH),
|
||||
GuardState::Verified
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn guard_state_write_failed() {
|
||||
assert_eq!(
|
||||
guard_state_after(ORIG, ORIG, PATCH, false, ORIG),
|
||||
GuardState::WriteFailed
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn guard_state_verify_failed() {
|
||||
// Write reported success but the re-read still shows the original …
|
||||
assert_eq!(
|
||||
guard_state_after(ORIG, ORIG, PATCH, true, ORIG),
|
||||
GuardState::VerifyFailed
|
||||
);
|
||||
// … or could not be re-read at all (the Python's `cur_after = b""`).
|
||||
assert_eq!(
|
||||
guard_state_after(ORIG, ORIG, PATCH, true, &[]),
|
||||
GuardState::VerifyFailed
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn guard_state_unsupported_build() {
|
||||
assert_eq!(
|
||||
guard_state_after(&[0x74, 0x0f], ORIG, PATCH, true, PATCH),
|
||||
GuardState::UnsupportedBuild
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn guard_state_spellings_are_the_launcher_contract() {
|
||||
assert_eq!(GuardState::NotAttempted.to_string(), "NOT_ATTEMPTED");
|
||||
assert_eq!(GuardState::Verified.to_string(), "VERIFIED");
|
||||
assert_eq!(GuardState::UnsupportedBuild.to_string(), "UNSUPPORTED_BUILD");
|
||||
assert_eq!(GuardState::WriteFailed.to_string(), "WRITE_FAILED");
|
||||
assert_eq!(GuardState::VerifyFailed.to_string(), "VERIFY_FAILED");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn live_addr_relocates_against_the_image_base() {
|
||||
assert_eq!(live_addr(0x7f0000000000, 0x180014858), 0x7f0000014858);
|
||||
assert_eq!(live_addr(IMG_BASE, RESOLVER_GUARD_VA), RESOLVER_GUARD_VA);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn hex_is_lowercase_and_unseparated() {
|
||||
assert_eq!(hex(&[0x00, 0x0f, 0xa5, 0xff]), "000fa5ff");
|
||||
assert_eq!(hex(&[]), "");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn comm_matches_only_the_client() {
|
||||
assert!(is_client_comm("FIFA17.exe\n"));
|
||||
assert!(is_client_comm("FIFA17.exe"));
|
||||
assert!(!is_client_comm("fifa17.exe\n"));
|
||||
assert!(!is_client_comm("FIFA17.exe.bak\n"));
|
||||
assert!(!is_client_comm("wineserver\n"));
|
||||
assert!(!is_client_comm(""));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn proc_entry_names_yield_only_numeric_pids() {
|
||||
assert_eq!(pid_from_proc_entry("1"), Some(1));
|
||||
assert_eq!(pid_from_proc_entry("41234"), Some(41234));
|
||||
assert_eq!(pid_from_proc_entry("self"), None);
|
||||
assert_eq!(pid_from_proc_entry("1abc"), None);
|
||||
assert_eq!(pid_from_proc_entry("+7"), None);
|
||||
assert_eq!(pid_from_proc_entry(""), None);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn cardsdll_base_is_the_first_matching_mapping() {
|
||||
let maps = concat!(
|
||||
"140000000-140001000 r--p 00000000 08:02 12 /home/u/FIFA17.exe\n",
|
||||
"7f2a11c00000-7f2a11c9c000 r-xp 00000000 08:02 44 /home/u/CardsDLL_Win64_retail.dll\n",
|
||||
"7f2a12000000-7f2a12001000 r--p 00000000 08:02 45 /home/u/CardsDLL_second.dll\n",
|
||||
);
|
||||
assert_eq!(parse_cardsdll_base(maps), Some(0x7f2a11c00000));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn cardsdll_base_absent_or_unparsable() {
|
||||
assert_eq!(parse_cardsdll_base(""), None);
|
||||
let no_dll = "140000000-140001000 r--p 00000000 08:02 12 /home/u/FIFA17.exe\n";
|
||||
assert_eq!(parse_cardsdll_base(no_dll), None);
|
||||
// A CardsDLL line whose base is not hex: fail, do not fall through.
|
||||
let broken = concat!(
|
||||
"zzzz-140001000 r--p 00000000 08:02 12 /home/u/CardsDLL.dll\n",
|
||||
"7f2a11c00000-7f2a11c9c000 r-xp 0 08:02 44 /home/u/CardsDLL.dll\n",
|
||||
);
|
||||
assert_eq!(parse_cardsdll_base(broken), None);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn launcher_pid_parsing() {
|
||||
assert_eq!(parse_launcher_pid(Vec::<String>::new()), Ok(None));
|
||||
assert_eq!(parse_launcher_pid(["--other", "3"]), Ok(None));
|
||||
assert_eq!(parse_launcher_pid(["--launcher-pid", "4242"]), Ok(Some(4242)));
|
||||
assert_eq!(
|
||||
parse_launcher_pid(["-x", "--launcher-pid", "7", "--launcher-pid", "9"]),
|
||||
Ok(Some(7))
|
||||
);
|
||||
// Falsy in the Python (`if launcher_pid and ...`): parsed, never watched.
|
||||
assert_eq!(parse_launcher_pid(["--launcher-pid", "0"]), Ok(Some(0)));
|
||||
assert_eq!(parse_launcher_pid(["--launcher-pid", "-5"]), Ok(Some(-5)));
|
||||
assert_eq!(parse_launcher_pid(["--launcher-pid"]), Err(()));
|
||||
assert_eq!(parse_launcher_pid(["--launcher-pid", "abc"]), Err(()));
|
||||
assert_eq!(parse_launcher_pid(["--launcher-pid", ""]), Err(()));
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,304 @@
|
||||
//! Wall-clock `HH:MM:SS` in local time, from std alone.
|
||||
//!
|
||||
//! The Python logs `time.strftime('%H:%M:%S')`, i.e. *local* time, and the
|
||||
//! launcher interleaves these lines with its own log, so UTC would misreport the
|
||||
//! timestamps by the machine's offset. std has no local-time support, so the
|
||||
//! UTC offset is taken from the system's TZif database (`TZ` or `/etc/localtime`),
|
||||
//! parsed here — a bounded, well-specified format (RFC 8536).
|
||||
//!
|
||||
//! LIMITATION, stated rather than hidden: only the TZif transition table is
|
||||
//! evaluated, not the trailing POSIX-TZ footer string. With the "fat" tzdata
|
||||
//! that Debian-family systems ship, transitions run to 2037, so the offset —
|
||||
//! including DST — is exact. Two cases fall back to the last known transition's
|
||||
//! offset (so a DST-observing zone could read one hour off) and one falls back
|
||||
//! to UTC:
|
||||
//! * "slim" tzdata, or dates past the last transition -> last transition;
|
||||
//! * `TZ` holding a bare POSIX rule (`EST5EDT`) with no such zone file, or an
|
||||
//! unreadable/corrupt zone file -> UTC.
|
||||
//! The timestamp is diagnostic; no line the launcher parses carries a time.
|
||||
|
||||
use std::fs;
|
||||
use std::sync::LazyLock;
|
||||
use std::time::{SystemTime, UNIX_EPOCH};
|
||||
|
||||
/// Resolved UTC offsets over time: an offset before the first transition, then
|
||||
/// `(transition instant, offset from that instant on)` in ascending order.
|
||||
#[derive(Debug, PartialEq, Eq)]
|
||||
pub struct TzData {
|
||||
initial: i32,
|
||||
transitions: Vec<(i64, i32)>,
|
||||
}
|
||||
|
||||
impl TzData {
|
||||
/// UTC offset in seconds applying at `unix_secs`.
|
||||
pub fn offset_at(&self, unix_secs: i64) -> i32 {
|
||||
let idx = self
|
||||
.transitions
|
||||
.partition_point(|(start, _)| *start <= unix_secs);
|
||||
if idx == 0 {
|
||||
self.initial
|
||||
} else {
|
||||
self.transitions[idx - 1].1
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// `[HH:MM:SS]`-worthy time-of-day for a Unix timestamp at a given UTC offset.
|
||||
pub fn hms(unix_secs: i64, utc_offset_secs: i32) -> (u32, u32, u32) {
|
||||
let local = unix_secs + i64::from(utc_offset_secs);
|
||||
// rem_euclid keeps pre-epoch and negative-offset instants on a sane clock.
|
||||
let day = local.rem_euclid(86_400);
|
||||
((day / 3600) as u32, (day % 3600 / 60) as u32, (day % 60) as u32)
|
||||
}
|
||||
|
||||
/// Current local time of day, `(hour, minute, second)`.
|
||||
pub fn now_hms() -> (u32, u32, u32) {
|
||||
let unix = SystemTime::now()
|
||||
.duration_since(UNIX_EPOCH)
|
||||
.map(|d| d.as_secs() as i64)
|
||||
// Before 1970 the clock is broken anyway; keep logging rather than panic.
|
||||
.unwrap_or(0);
|
||||
hms(unix, local_offset_at(unix))
|
||||
}
|
||||
|
||||
/// UTC offset in seconds for `unix_secs`, or 0 when no zone data is usable.
|
||||
///
|
||||
/// The zone file is read and parsed once; the offset is then recomputed per call
|
||||
/// so a DST transition during a long-running session is picked up.
|
||||
pub fn local_offset_at(unix_secs: i64) -> i32 {
|
||||
static TZ: LazyLock<Option<TzData>> = LazyLock::new(load_system_tz);
|
||||
TZ.as_ref().map_or(0, |tz| tz.offset_at(unix_secs))
|
||||
}
|
||||
|
||||
/// Read and parse the zone file named by `TZ`, else `/etc/localtime`.
|
||||
fn load_system_tz() -> Option<TzData> {
|
||||
let path = match std::env::var("TZ") {
|
||||
Ok(tz) if !tz.is_empty() => {
|
||||
// glibc accepts a leading ':' and either an absolute path or a name
|
||||
// relative to the zoneinfo directory.
|
||||
let name = tz.strip_prefix(':').unwrap_or(&tz);
|
||||
if name.starts_with('/') {
|
||||
name.to_string()
|
||||
} else {
|
||||
format!("/usr/share/zoneinfo/{name}")
|
||||
}
|
||||
}
|
||||
_ => "/etc/localtime".to_string(),
|
||||
};
|
||||
parse_tzif(&fs::read(path).ok()?)
|
||||
}
|
||||
|
||||
/// Parse a TZif (RFC 8536) file into resolved offsets.
|
||||
///
|
||||
/// For version 2+ files the 64-bit data block is used; the legacy 32-bit block
|
||||
/// is skipped, because modern tzdata leaves it minimal.
|
||||
pub fn parse_tzif(bytes: &[u8]) -> Option<TzData> {
|
||||
let (version, counts) = parse_header(bytes, 0)?;
|
||||
if version >= b'2' {
|
||||
// Skip the v1 header + v1 data block, then re-read the 64-bit header.
|
||||
let v1_end = 44 + data_block_len(&counts, 4)?;
|
||||
let (_, counts64) = parse_header(bytes, v1_end)?;
|
||||
parse_data(bytes, v1_end + 44, &counts64, 8)
|
||||
} else {
|
||||
parse_data(bytes, 44, &counts, 4)
|
||||
}
|
||||
}
|
||||
|
||||
/// `(isutcnt, isstdcnt, leapcnt, timecnt, typecnt, charcnt)`.
|
||||
type Counts = [u32; 6];
|
||||
|
||||
fn parse_header(bytes: &[u8], off: usize) -> Option<(u8, Counts)> {
|
||||
let head = bytes.get(off..off + 44)?;
|
||||
if &head[0..4] != b"TZif" {
|
||||
return None;
|
||||
}
|
||||
let version = head[4];
|
||||
let mut counts = [0u32; 6];
|
||||
for (i, slot) in counts.iter_mut().enumerate() {
|
||||
let at = 20 + i * 4;
|
||||
*slot = u32::from_be_bytes(head[at..at + 4].try_into().ok()?);
|
||||
}
|
||||
Some((version, counts))
|
||||
}
|
||||
|
||||
/// Byte length of a data block with `time_len`-wide transition times.
|
||||
fn data_block_len(counts: &Counts, time_len: usize) -> Option<usize> {
|
||||
let [isutcnt, isstdcnt, leapcnt, timecnt, typecnt, charcnt] = counts.map(|c| c as usize);
|
||||
Some(
|
||||
timecnt * time_len
|
||||
+ timecnt
|
||||
+ typecnt * 6
|
||||
+ charcnt
|
||||
+ leapcnt * (time_len + 4)
|
||||
+ isstdcnt
|
||||
+ isutcnt,
|
||||
)
|
||||
}
|
||||
|
||||
fn parse_data(bytes: &[u8], off: usize, counts: &Counts, time_len: usize) -> Option<TzData> {
|
||||
let [_, _, _, timecnt, typecnt, _] = counts.map(|c| c as usize);
|
||||
if typecnt == 0 {
|
||||
return None;
|
||||
}
|
||||
let block = bytes.get(off..off + data_block_len(counts, time_len)?)?;
|
||||
|
||||
let times = block.get(..timecnt * time_len)?;
|
||||
let type_idx = block.get(timecnt * time_len..timecnt * time_len + timecnt)?;
|
||||
let ttinfo_at = timecnt * time_len + timecnt;
|
||||
let ttinfo = block.get(ttinfo_at..ttinfo_at + typecnt * 6)?;
|
||||
|
||||
// utoff + isdst per local-time type.
|
||||
let mut offsets = Vec::with_capacity(typecnt);
|
||||
for i in 0..typecnt {
|
||||
let rec = &ttinfo[i * 6..i * 6 + 6];
|
||||
let utoff = i32::from_be_bytes(rec[0..4].try_into().ok()?);
|
||||
offsets.push((utoff, rec[4] != 0));
|
||||
}
|
||||
|
||||
// Before the first transition, RFC 8536 says to use the first non-DST type,
|
||||
// falling back to the first type. This is also the whole answer for a
|
||||
// fixed-offset zone (typecnt 1, timecnt 0), e.g. Etc/UTC.
|
||||
let initial = offsets
|
||||
.iter()
|
||||
.find(|(_, isdst)| !*isdst)
|
||||
.unwrap_or(&offsets[0])
|
||||
.0;
|
||||
|
||||
let mut transitions = Vec::with_capacity(timecnt);
|
||||
for i in 0..timecnt {
|
||||
let raw = ×[i * time_len..(i + 1) * time_len];
|
||||
let at = if time_len == 8 {
|
||||
i64::from_be_bytes(raw.try_into().ok()?)
|
||||
} else {
|
||||
i64::from(i32::from_be_bytes(raw.try_into().ok()?))
|
||||
};
|
||||
let (utoff, _) = *offsets.get(*type_idx.get(i)? as usize)?;
|
||||
transitions.push((at, utoff));
|
||||
}
|
||||
|
||||
Some(TzData {
|
||||
initial,
|
||||
transitions,
|
||||
})
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
/// Minimal TZif builder: `transitions` are `(instant, type index)`.
|
||||
fn tzif(version: u8, types: &[(i32, bool)], transitions: &[(i64, u8)]) -> Vec<u8> {
|
||||
fn block(types: &[(i32, bool)], transitions: &[(i64, u8)], time_len: usize) -> Vec<u8> {
|
||||
let mut out = Vec::new();
|
||||
for (at, _) in transitions {
|
||||
if time_len == 8 {
|
||||
out.extend_from_slice(&at.to_be_bytes());
|
||||
} else {
|
||||
out.extend_from_slice(&(*at as i32).to_be_bytes());
|
||||
}
|
||||
}
|
||||
for (_, idx) in transitions {
|
||||
out.push(*idx);
|
||||
}
|
||||
for (utoff, isdst) in types {
|
||||
out.extend_from_slice(&utoff.to_be_bytes());
|
||||
out.push(u8::from(*isdst));
|
||||
out.push(0); // abbreviation index
|
||||
}
|
||||
out.push(0); // one NUL abbreviation byte
|
||||
out
|
||||
}
|
||||
fn header(version: u8, types: usize, transitions: usize) -> Vec<u8> {
|
||||
let mut out = Vec::from(*b"TZif");
|
||||
out.push(version);
|
||||
out.extend_from_slice(&[0u8; 15]);
|
||||
for count in [0u32, 0, 0, transitions as u32, types as u32, 1] {
|
||||
out.extend_from_slice(&count.to_be_bytes());
|
||||
}
|
||||
out
|
||||
}
|
||||
let mut out = header(version, types.len(), transitions.len());
|
||||
if version >= b'2' {
|
||||
// Modern "slim-ish" shape: an empty v1 block, then the 64-bit block.
|
||||
out.truncate(0);
|
||||
out.extend(header(version, types.len(), 0));
|
||||
out.extend(block(types, &[], 4));
|
||||
out.extend(header(version, types.len(), transitions.len()));
|
||||
out.extend(block(types, transitions, 8));
|
||||
} else {
|
||||
out.extend(block(types, transitions, 4));
|
||||
}
|
||||
out
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn fixed_offset_zone_has_no_transitions() {
|
||||
let tz = parse_tzif(&tzif(b'2', &[(0, false)], &[])).unwrap();
|
||||
assert_eq!(tz.offset_at(0), 0);
|
||||
assert_eq!(tz.offset_at(1_800_000_000), 0);
|
||||
|
||||
let kolkata = parse_tzif(&tzif(b'2', &[(19_800, false)], &[])).unwrap();
|
||||
assert_eq!(kolkata.offset_at(1_800_000_000), 19_800);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn dst_transitions_select_the_right_offset() {
|
||||
// CET/CEST with two transitions.
|
||||
let tz = parse_tzif(&tzif(
|
||||
b'2',
|
||||
&[(3600, false), (7200, true)],
|
||||
&[(1_000_000_000, 1), (1_100_000_000, 0)],
|
||||
))
|
||||
.unwrap();
|
||||
assert_eq!(tz.offset_at(999_999_999), 3600); // before the first transition
|
||||
assert_eq!(tz.offset_at(1_000_000_000), 7200); // exactly at it
|
||||
assert_eq!(tz.offset_at(1_050_000_000), 7200);
|
||||
assert_eq!(tz.offset_at(1_100_000_000), 3600);
|
||||
assert_eq!(tz.offset_at(i64::MAX), 3600); // past the table: last known
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn version_1_files_parse_from_the_32_bit_block() {
|
||||
let tz = parse_tzif(&tzif(b'\0', &[(-18_000, false)], &[(100, 0)])).unwrap();
|
||||
assert_eq!(tz.offset_at(0), -18_000);
|
||||
assert_eq!(tz.offset_at(1_000), -18_000);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn initial_offset_skips_a_leading_dst_type() {
|
||||
let tz = parse_tzif(&tzif(b'2', &[(7200, true), (3600, false)], &[])).unwrap();
|
||||
assert_eq!(tz.offset_at(0), 3600);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn garbage_is_rejected_rather_than_guessed() {
|
||||
assert_eq!(parse_tzif(b""), None);
|
||||
assert_eq!(parse_tzif(b"not a tzif file at all, truncated"), None);
|
||||
let mut truncated = tzif(b'2', &[(3600, false)], &[(1, 0)]);
|
||||
truncated.truncate(truncated.len() - 5);
|
||||
assert_eq!(parse_tzif(&truncated), None);
|
||||
// Well-formed header claiming zero local-time types is unusable.
|
||||
assert_eq!(parse_tzif(&tzif(b'2', &[], &[])), None);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn hms_matches_known_instants() {
|
||||
assert_eq!(hms(0, 0), (0, 0, 0));
|
||||
// 2026-08-18T04:52:08Z
|
||||
assert_eq!(hms(1_787_028_728, 0), (4, 52, 8));
|
||||
// …the same instant at +02:00 and at -05:00 (the latter is the day before).
|
||||
assert_eq!(hms(1_787_028_728, 7200), (6, 52, 8));
|
||||
assert_eq!(hms(1_787_028_728, -18_000), (23, 52, 8));
|
||||
// Offsets that cross midnight in either direction stay on the clock.
|
||||
assert_eq!(hms(86_399, 1), (0, 0, 0));
|
||||
assert_eq!(hms(0, -1), (23, 59, 59));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn the_system_zone_resolves_to_a_plausible_offset() {
|
||||
// Whatever this machine's zone is, the offset must be a real one.
|
||||
let offset = local_offset_at(1_786_697_528);
|
||||
assert!((-50_400..=50_400).contains(&offset), "implausible {offset}");
|
||||
assert_eq!(offset % 60, 0);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,103 @@
|
||||
//! `[HH:MM:SS] <msg>` to stdout (flushed per line) and appended to the log file.
|
||||
//!
|
||||
//! The launcher pipes this process's stdout into its own log buffer and *parses*
|
||||
//! some of these lines, so the per-line flush and the line shapes are a contract,
|
||||
//! not cosmetics.
|
||||
|
||||
use std::fs::OpenOptions;
|
||||
use std::io::{self, Write};
|
||||
use std::path::PathBuf;
|
||||
|
||||
use crate::localtime;
|
||||
use crate::procmem;
|
||||
|
||||
/// Environment override for the log file path.
|
||||
pub const LOG_PATH_ENV: &str = "OPENFUT_AUTOPATCH_LOG";
|
||||
|
||||
pub struct Logger {
|
||||
path: PathBuf,
|
||||
}
|
||||
|
||||
impl Logger {
|
||||
/// `$OPENFUT_AUTOPATCH_LOG`, defaulting to `/tmp/openfut-autopatch-<uid>.log`.
|
||||
///
|
||||
/// Resolved once at startup, exactly like the Python's module-level `LOG`, so
|
||||
/// a later environment change cannot move the file mid-run.
|
||||
pub fn from_env() -> io::Result<Self> {
|
||||
let path = match std::env::var_os(LOG_PATH_ENV) {
|
||||
Some(path) if !path.is_empty() => PathBuf::from(path),
|
||||
_ => PathBuf::from(format!(
|
||||
"/tmp/openfut-autopatch-{}.log",
|
||||
procmem::current_uid()?
|
||||
)),
|
||||
};
|
||||
Ok(Self { path })
|
||||
}
|
||||
|
||||
pub fn path(&self) -> &std::path::Path {
|
||||
&self.path
|
||||
}
|
||||
|
||||
/// Emit one line. Timestamped in local time.
|
||||
pub fn log(&self, msg: &str) {
|
||||
let (h, m, s) = localtime::now_hms();
|
||||
let line = format!("[{h:02}:{m:02}:{s:02}] {msg}");
|
||||
|
||||
let mut stdout = io::stdout().lock();
|
||||
// Ignore a broken pipe: the launcher may have stopped reading, and dying
|
||||
// here would leave FIFA's store patches unenforced.
|
||||
let _ = writeln!(stdout, "{line}");
|
||||
let _ = stdout.flush();
|
||||
drop(stdout);
|
||||
|
||||
if let Err(e) = self.append(&line) {
|
||||
// The Python lets a failing log write kill the process. Patching the
|
||||
// running client matters more than the transcript, so report once to
|
||||
// stderr (the launcher captures it too) and carry on.
|
||||
let _ = writeln!(io::stderr(), "autopatch: cannot append to {}: {e}", self.path.display());
|
||||
}
|
||||
}
|
||||
|
||||
fn append(&self, line: &str) -> io::Result<()> {
|
||||
let mut file = OpenOptions::new().create(true).append(true).open(&self.path)?;
|
||||
file.write_all(line.as_bytes())?;
|
||||
file.write_all(b"\n")
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn appends_a_timestamped_line_to_the_configured_path() {
|
||||
let path = std::env::temp_dir().join(format!(
|
||||
"openfut-autopatch-test-{}.log",
|
||||
std::process::id()
|
||||
));
|
||||
let _ = std::fs::remove_file(&path);
|
||||
let logger = Logger {
|
||||
path: path.clone(),
|
||||
};
|
||||
logger.log("pid 4242: PATCHED cert gates");
|
||||
logger.log("second line");
|
||||
|
||||
let body = std::fs::read_to_string(&path).unwrap();
|
||||
let lines: Vec<&str> = body.lines().collect();
|
||||
assert_eq!(lines.len(), 2);
|
||||
assert_eq!(&lines[0][..1], "[");
|
||||
assert_eq!(&lines[0][3..4], ":");
|
||||
assert_eq!(&lines[0][6..7], ":");
|
||||
assert_eq!(&lines[0][9..], "] pid 4242: PATCHED cert gates");
|
||||
assert!(lines[1].ends_with("] second line"));
|
||||
let _ = std::fs::remove_file(&path);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn a_bad_log_path_does_not_kill_the_patcher() {
|
||||
let logger = Logger {
|
||||
path: PathBuf::from("/proc/definitely/not/writable.log"),
|
||||
};
|
||||
logger.log("still running");
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,97 @@
|
||||
//! Watch for a (re)launched FIFA17.exe and auto-apply the ProtoSSL cert patches
|
||||
//! the moment its unpacked code is mapped, plus the CardsDLL FUT store patches.
|
||||
//! Idempotent; keeps watching across relaunches.
|
||||
//!
|
||||
//! Port of `fifa17-recon/tools/autopatch.py`, tick for tick: cert gates once per
|
||||
//! pid, store patches re-enforced every second (the game rewrites those sites),
|
||||
//! then the resolver-guard capability reported once per pid. The passes
|
||||
//! themselves live in `openfut_autopatch::patch`; this is the loop and the CLI.
|
||||
|
||||
use std::collections::HashSet;
|
||||
use std::process::ExitCode;
|
||||
use std::thread::sleep;
|
||||
use std::time::Duration;
|
||||
|
||||
use openfut_autopatch::patch::{cert_pass, enforce_store_patches};
|
||||
use openfut_autopatch::procmem::{self, ProcMem};
|
||||
use openfut_autopatch::{parse_launcher_pid, Logger};
|
||||
|
||||
/// One tick per second, as in the Python.
|
||||
const TICK: Duration = Duration::from_secs(1);
|
||||
|
||||
/// Per-pid bookkeeping so each of these lines is logged exactly once per client
|
||||
/// process (the Python's three module-level sets).
|
||||
#[derive(Default)]
|
||||
struct Seen {
|
||||
patched: HashSet<u32>,
|
||||
store_patched: HashSet<u32>,
|
||||
guard_reported: HashSet<u32>,
|
||||
}
|
||||
|
||||
fn main() -> ExitCode {
|
||||
let launcher_pid = match parse_launcher_pid(std::env::args().skip(1)) {
|
||||
Ok(pid) => pid,
|
||||
Err(()) => {
|
||||
eprintln!("invalid --launcher-pid");
|
||||
return ExitCode::FAILURE;
|
||||
}
|
||||
};
|
||||
|
||||
let logger = match Logger::from_env() {
|
||||
Ok(logger) => logger,
|
||||
Err(e) => {
|
||||
eprintln!("cannot resolve the autopatch log path: {e}");
|
||||
return ExitCode::FAILURE;
|
||||
}
|
||||
};
|
||||
|
||||
logger.log("=== AUTOPATCH watching for FIFA17.exe ===");
|
||||
|
||||
let mut seen = Seen::default();
|
||||
loop {
|
||||
// `if launcher_pid and not os.path.exists(...)`: pid 0 is falsy in the
|
||||
// Python, so `--launcher-pid 0` parses but is never watched.
|
||||
if let Some(pid) = launcher_pid {
|
||||
if pid != 0 && !procmem::pid_alive(pid) {
|
||||
logger.log(&format!("launcher pid {pid} exited; stopping autopatch"));
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
for pid in procmem::find_pids() {
|
||||
let mem = ProcMem::new(pid);
|
||||
|
||||
if !seen.patched.contains(&pid)
|
||||
&& !cert_pass(&mem, &mut |line| logger.log(line), &mut seen.patched)
|
||||
{
|
||||
// Code not mapped yet: nothing else to do for this pid this tick.
|
||||
continue;
|
||||
}
|
||||
|
||||
// Store patches are enforced on EVERY tick, not once: the game
|
||||
// rewrites these sites, so a single pass at startup does not hold.
|
||||
let Some(cbase) = procmem::cardsdll_base(pid) else {
|
||||
continue;
|
||||
};
|
||||
match enforce_store_patches(
|
||||
&mem,
|
||||
cbase,
|
||||
&mut |line| logger.log(line),
|
||||
&mut seen.guard_reported,
|
||||
) {
|
||||
Ok(()) => {
|
||||
if seen.store_patched.insert(pid) {
|
||||
logger.log(&format!(
|
||||
"pid {pid}: PATCHED store gates in CardsDLL @ {cbase:#x}"
|
||||
));
|
||||
}
|
||||
}
|
||||
Err(e) => logger.log(&format!("pid {pid}: store patch write failed: {e}")),
|
||||
}
|
||||
}
|
||||
|
||||
sleep(TICK);
|
||||
}
|
||||
|
||||
ExitCode::SUCCESS
|
||||
}
|
||||
@@ -0,0 +1,478 @@
|
||||
//! The two enforcement passes: ProtoSSL cert gates (once per pid) and the
|
||||
//! CardsDLL store patches (every tick).
|
||||
//!
|
||||
//! Both are written against the [`Memory`] trait rather than `/proc` directly, so
|
||||
//! the log lines and their order — which the launcher reads — are unit-testable
|
||||
//! without a live FIFA client.
|
||||
|
||||
use std::collections::HashSet;
|
||||
use std::io;
|
||||
|
||||
use crate::{
|
||||
guard_state_after, guarded_action, hex, live_addr, GuardState, GuardedAction,
|
||||
EMPTY_MYPACKS_RESOLVER_CAPABILITY, EMPTY_MYPACKS_RESOLVER_VERSION, GATE1, GATE1_ORIG,
|
||||
GATE1_PATCH, GATE2, GATE2_ORIG, GATE2_PATCH, MAX_PATCH_LEN, RESOLVER_GUARD_VA, STORE_PATCHES,
|
||||
STORE_PATCHES_GUARDED,
|
||||
};
|
||||
|
||||
/// Byte-level access to one client process's address space.
|
||||
pub trait Memory {
|
||||
/// The pid being patched; it appears in every log line.
|
||||
fn pid(&self) -> u32;
|
||||
/// Fill `buf` from virtual address `va`. An error means "not mapped (yet)".
|
||||
fn read(&self, va: u64, buf: &mut [u8]) -> io::Result<()>;
|
||||
/// Write `data` at virtual address `va`.
|
||||
fn write(&self, va: u64, data: &[u8]) -> io::Result<()>;
|
||||
}
|
||||
|
||||
/// Apply the two ProtoSSL cert gates, once per pid.
|
||||
///
|
||||
/// Returns `false` when the gates could not be read — the packer has not mapped
|
||||
/// that code yet, which is the Python's `continue`, not an error to report.
|
||||
pub fn cert_pass<M: Memory>(
|
||||
mem: &M,
|
||||
log: &mut impl FnMut(&str),
|
||||
patched: &mut HashSet<u32>,
|
||||
) -> bool {
|
||||
let pid = mem.pid();
|
||||
// Sized from the patterns themselves; the initial contents are overwritten by
|
||||
// the reads and are never compared unless both reads succeed.
|
||||
let mut g2 = GATE2_ORIG;
|
||||
let mut g1 = GATE1_ORIG;
|
||||
if mem.read(GATE2, &mut g2).is_err() || mem.read(GATE1, &mut g1).is_err() {
|
||||
return false;
|
||||
}
|
||||
|
||||
if g2 == GATE2_PATCH && g1 == GATE1_PATCH {
|
||||
log(&format!("pid {pid}: cert gates already patched"));
|
||||
patched.insert(pid);
|
||||
} else if g2 == GATE2_ORIG && g1 == GATE1_ORIG {
|
||||
match mem
|
||||
.write(GATE2, &GATE2_PATCH)
|
||||
.and_then(|()| mem.write(GATE1, &GATE1_PATCH))
|
||||
{
|
||||
Ok(()) => {
|
||||
log(&format!("pid {pid}: PATCHED cert gates"));
|
||||
patched.insert(pid);
|
||||
}
|
||||
Err(e) => log(&format!("pid {pid}: cert patch write failed: {e}")),
|
||||
}
|
||||
}
|
||||
// Anything else is a build we do not recognise: left alone, as in the Python.
|
||||
true
|
||||
}
|
||||
|
||||
/// Re-apply every store patch whose live bytes have drifted, then the guarded
|
||||
/// patch, then report the resolver-guard capability once per pid.
|
||||
///
|
||||
/// An `Err` is a read or write that failed outside the guarded site's own
|
||||
/// handling; it aborts the rest of this pid's pass for this tick, exactly like
|
||||
/// the Python's enclosing `try`.
|
||||
pub fn enforce_store_patches<M: Memory>(
|
||||
mem: &M,
|
||||
cbase: u64,
|
||||
log: &mut impl FnMut(&str),
|
||||
guard_reported: &mut HashSet<u32>,
|
||||
) -> io::Result<()> {
|
||||
let pid = mem.pid();
|
||||
|
||||
for (va, data) in STORE_PATCHES {
|
||||
let live = live_addr(cbase, va);
|
||||
let mut buf = [0u8; MAX_PATCH_LEN];
|
||||
let cur = &mut buf[..data.len()];
|
||||
mem.read(live, cur)?;
|
||||
if cur != data {
|
||||
mem.write(live, data)?;
|
||||
log(&format!("pid {pid}: ENFORCED store patch @ {live:#x}"));
|
||||
}
|
||||
}
|
||||
|
||||
for (va, orig, patch) in STORE_PATCHES_GUARDED {
|
||||
let live = live_addr(cbase, va);
|
||||
let mut before = [0u8; MAX_PATCH_LEN];
|
||||
mem.read(live, &mut before[..patch.len()])?;
|
||||
let cur = &before[..patch.len()];
|
||||
|
||||
let mut wrote_ok = true;
|
||||
// The Python starts with `cur_after = cur`, which only matters on the
|
||||
// branches that never re-read.
|
||||
let mut after = [0u8; MAX_PATCH_LEN];
|
||||
after[..patch.len()].copy_from_slice(cur);
|
||||
let mut after_len = patch.len();
|
||||
|
||||
match guarded_action(cur, orig, patch) {
|
||||
GuardedAction::Patch => {
|
||||
match mem.write(live, patch) {
|
||||
Ok(()) => log(&format!(
|
||||
"pid {pid}: ENFORCED guarded store patch @ {live:#x} (JNZ->JG, empty My Packs)"
|
||||
)),
|
||||
Err(e) => {
|
||||
wrote_ok = false;
|
||||
log(&format!(
|
||||
"pid {pid}: guarded patch write failed @ {live:#x}: {e}"
|
||||
));
|
||||
}
|
||||
}
|
||||
if wrote_ok && mem.read(live, &mut after[..patch.len()]).is_err() {
|
||||
// The Python's `cur_after = b""`: unverifiable, so not verified.
|
||||
after_len = 0;
|
||||
}
|
||||
}
|
||||
GuardedAction::Skip => log(&format!(
|
||||
"pid {pid}: SKIP guarded patch @ {live:#x}: unexpected {} (build mismatch)",
|
||||
hex(cur)
|
||||
)),
|
||||
// Already patched; nothing to write.
|
||||
GuardedAction::Noop => {}
|
||||
}
|
||||
|
||||
if va == RESOLVER_GUARD_VA && !guard_reported.contains(&pid) {
|
||||
let state = guard_state_after(cur, orig, patch, wrote_ok, &after[..after_len]);
|
||||
if state == GuardState::Verified {
|
||||
// PARSED BY THE LAUNCHER (fifa17_capability::parse_capability_line):
|
||||
// this line must keep both `verified capability` and the
|
||||
// `fifa17.empty_mypacks_resolver=<version>` token verbatim.
|
||||
log(&format!(
|
||||
"[store-guard] verified capability {EMPTY_MYPACKS_RESOLVER_CAPABILITY}={EMPTY_MYPACKS_RESOLVER_VERSION} fifa_pid={pid}"
|
||||
));
|
||||
} else {
|
||||
log(&format!(
|
||||
"[store-guard] guard status={state} fifa_pid={pid} (no capability advertised)"
|
||||
));
|
||||
}
|
||||
guard_reported.insert(pid);
|
||||
}
|
||||
}
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
use std::cell::RefCell;
|
||||
use std::collections::BTreeMap;
|
||||
|
||||
const CBASE: u64 = 0x7f2a11c00000;
|
||||
const GUARD_LIVE: u64 = CBASE + 0x14858;
|
||||
|
||||
/// Sparse fake address space: an unmapped byte reads as `NotFound`, mirroring
|
||||
/// `/proc/<pid>/mem` refusing an address the packer has not produced yet.
|
||||
struct FakeMemory {
|
||||
bytes: RefCell<BTreeMap<u64, u8>>,
|
||||
/// Writes to these addresses fail.
|
||||
fail_writes: Vec<u64>,
|
||||
/// Writes to these addresses report success but change nothing (the
|
||||
/// VERIFY_FAILED shape).
|
||||
swallow_writes: Vec<u64>,
|
||||
/// Reads of these addresses fail even when mapped.
|
||||
fail_reads: Vec<u64>,
|
||||
}
|
||||
|
||||
impl FakeMemory {
|
||||
fn new() -> Self {
|
||||
Self {
|
||||
bytes: RefCell::new(BTreeMap::new()),
|
||||
fail_writes: Vec::new(),
|
||||
swallow_writes: Vec::new(),
|
||||
fail_reads: Vec::new(),
|
||||
}
|
||||
}
|
||||
|
||||
fn map(self, va: u64, bytes: &[u8]) -> Self {
|
||||
{
|
||||
let mut mem = self.bytes.borrow_mut();
|
||||
for (i, b) in bytes.iter().enumerate() {
|
||||
mem.insert(va + i as u64, *b);
|
||||
}
|
||||
}
|
||||
self
|
||||
}
|
||||
|
||||
/// Every store-patch site mapped with filler that is neither the patch
|
||||
/// nor (for the guarded site) the original.
|
||||
fn with_store_sites(mut self, filler: u8) -> Self {
|
||||
for (va, data) in STORE_PATCHES {
|
||||
self = self.map(live_addr(CBASE, va), &vec![filler; data.len()]);
|
||||
}
|
||||
for (va, _, patch) in STORE_PATCHES_GUARDED {
|
||||
self = self.map(live_addr(CBASE, va), &vec![filler; patch.len()]);
|
||||
}
|
||||
self
|
||||
}
|
||||
|
||||
fn at(&self, va: u64, len: usize) -> Vec<u8> {
|
||||
let mem = self.bytes.borrow();
|
||||
(0..len as u64).map(|i| mem[&(va + i)]).collect()
|
||||
}
|
||||
}
|
||||
|
||||
impl Memory for FakeMemory {
|
||||
fn pid(&self) -> u32 {
|
||||
4242
|
||||
}
|
||||
|
||||
fn read(&self, va: u64, buf: &mut [u8]) -> io::Result<()> {
|
||||
if self.fail_reads.contains(&va) {
|
||||
return Err(io::Error::from(io::ErrorKind::PermissionDenied));
|
||||
}
|
||||
let mem = self.bytes.borrow();
|
||||
for (i, slot) in buf.iter_mut().enumerate() {
|
||||
*slot = *mem
|
||||
.get(&(va + i as u64))
|
||||
.ok_or_else(|| io::Error::from(io::ErrorKind::NotFound))?;
|
||||
}
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn write(&self, va: u64, data: &[u8]) -> io::Result<()> {
|
||||
if self.fail_writes.contains(&va) {
|
||||
return Err(io::Error::from(io::ErrorKind::PermissionDenied));
|
||||
}
|
||||
if self.swallow_writes.contains(&va) {
|
||||
return Ok(());
|
||||
}
|
||||
let mut mem = self.bytes.borrow_mut();
|
||||
for (i, b) in data.iter().enumerate() {
|
||||
mem.insert(va + i as u64, *b);
|
||||
}
|
||||
Ok(())
|
||||
}
|
||||
}
|
||||
|
||||
/// Collects log lines so the contract strings can be asserted verbatim.
|
||||
#[derive(Default)]
|
||||
struct Lines(Vec<String>);
|
||||
|
||||
impl Lines {
|
||||
fn sink(&mut self) -> impl FnMut(&str) + '_ {
|
||||
|line: &str| self.0.push(line.to_string())
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn cert_pass_defers_while_the_code_is_not_mapped() {
|
||||
let mem = FakeMemory::new();
|
||||
let mut lines = Lines::default();
|
||||
let mut patched = HashSet::new();
|
||||
assert!(!cert_pass(&mem, &mut lines.sink(), &mut patched));
|
||||
assert!(lines.0.is_empty(), "{:?}", lines.0);
|
||||
assert!(patched.is_empty());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn cert_pass_defers_when_only_the_first_gate_is_mapped() {
|
||||
let mem = FakeMemory::new().map(GATE2, &GATE2_ORIG);
|
||||
let mut lines = Lines::default();
|
||||
let mut patched = HashSet::new();
|
||||
assert!(!cert_pass(&mem, &mut lines.sink(), &mut patched));
|
||||
assert!(lines.0.is_empty());
|
||||
assert!(patched.is_empty());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn cert_pass_writes_both_gates_once() {
|
||||
let mem = FakeMemory::new()
|
||||
.map(GATE2, &GATE2_ORIG)
|
||||
.map(GATE1, &GATE1_ORIG);
|
||||
let mut lines = Lines::default();
|
||||
let mut patched = HashSet::new();
|
||||
assert!(cert_pass(&mem, &mut lines.sink(), &mut patched));
|
||||
assert_eq!(lines.0, vec!["pid 4242: PATCHED cert gates"]);
|
||||
assert_eq!(mem.at(GATE2, 3), GATE2_PATCH);
|
||||
assert_eq!(mem.at(GATE1, 6), GATE1_PATCH);
|
||||
assert!(patched.contains(&4242));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn cert_pass_recognises_an_already_patched_client() {
|
||||
let mem = FakeMemory::new()
|
||||
.map(GATE2, &GATE2_PATCH)
|
||||
.map(GATE1, &GATE1_PATCH);
|
||||
let mut lines = Lines::default();
|
||||
let mut patched = HashSet::new();
|
||||
assert!(cert_pass(&mem, &mut lines.sink(), &mut patched));
|
||||
assert_eq!(lines.0, vec!["pid 4242: cert gates already patched"]);
|
||||
assert!(patched.contains(&4242));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn cert_pass_reports_a_write_failure_and_stays_unpatched() {
|
||||
let mut mem = FakeMemory::new()
|
||||
.map(GATE2, &GATE2_ORIG)
|
||||
.map(GATE1, &GATE1_ORIG);
|
||||
mem.fail_writes.push(GATE2);
|
||||
let mut lines = Lines::default();
|
||||
let mut patched = HashSet::new();
|
||||
assert!(cert_pass(&mem, &mut lines.sink(), &mut patched));
|
||||
assert_eq!(lines.0.len(), 1);
|
||||
assert!(
|
||||
lines.0[0].starts_with("pid 4242: cert patch write failed: "),
|
||||
"{}",
|
||||
lines.0[0]
|
||||
);
|
||||
// Not recorded as patched, so the next tick tries again.
|
||||
assert!(patched.is_empty());
|
||||
assert_eq!(mem.at(GATE2, 3), GATE2_ORIG);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn cert_pass_leaves_an_unrecognised_build_alone() {
|
||||
let mem = FakeMemory::new()
|
||||
.map(GATE2, &[0x55, 0x48, 0x89])
|
||||
.map(GATE1, &[0x0f, 0x84, 0x76, 0x01, 0x00, 0x00]);
|
||||
let mut lines = Lines::default();
|
||||
let mut patched = HashSet::new();
|
||||
assert!(cert_pass(&mem, &mut lines.sink(), &mut patched));
|
||||
assert!(lines.0.is_empty(), "{:?}", lines.0);
|
||||
assert!(patched.is_empty());
|
||||
assert_eq!(mem.at(GATE2, 3), [0x55, 0x48, 0x89]);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn store_pass_enforces_every_site_in_table_order_then_advertises() {
|
||||
let mem = FakeMemory::new().with_store_sites(0xcc);
|
||||
let mut lines = Lines::default();
|
||||
let mut reported = HashSet::new();
|
||||
enforce_store_patches(&mem, CBASE, &mut lines.sink(), &mut reported).unwrap();
|
||||
|
||||
let mut expected: Vec<String> = STORE_PATCHES
|
||||
.iter()
|
||||
.map(|(va, _)| {
|
||||
let live = live_addr(CBASE, *va);
|
||||
format!("pid 4242: ENFORCED store patch @ {live:#x}")
|
||||
})
|
||||
.collect();
|
||||
// 0xcc is neither the original nor the patch: fail-closed SKIP, and the
|
||||
// capability is withheld.
|
||||
expected.push(format!(
|
||||
"pid 4242: SKIP guarded patch @ {GUARD_LIVE:#x}: unexpected cccc (build mismatch)"
|
||||
));
|
||||
expected.push(
|
||||
"[store-guard] guard status=UNSUPPORTED_BUILD fifa_pid=4242 (no capability advertised)"
|
||||
.to_string(),
|
||||
);
|
||||
assert_eq!(lines.0, expected);
|
||||
assert!(reported.contains(&4242));
|
||||
|
||||
for (va, data) in STORE_PATCHES {
|
||||
assert_eq!(mem.at(live_addr(CBASE, va), data.len()), data);
|
||||
}
|
||||
// The guarded site was NOT overwritten.
|
||||
assert_eq!(mem.at(GUARD_LIVE, 2), [0xcc, 0xcc]);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn store_pass_patches_the_guard_and_advertises_the_capability() {
|
||||
let mem = FakeMemory::new()
|
||||
.with_store_sites(0xcc)
|
||||
.map(GUARD_LIVE, STORE_PATCHES_GUARDED[0].1);
|
||||
let mut lines = Lines::default();
|
||||
let mut reported = HashSet::new();
|
||||
enforce_store_patches(&mem, CBASE, &mut lines.sink(), &mut reported).unwrap();
|
||||
|
||||
assert_eq!(
|
||||
lines.0[lines.0.len() - 2],
|
||||
format!(
|
||||
"pid 4242: ENFORCED guarded store patch @ {GUARD_LIVE:#x} (JNZ->JG, empty My Packs)"
|
||||
)
|
||||
);
|
||||
assert_eq!(
|
||||
lines.0[lines.0.len() - 1],
|
||||
"[store-guard] verified capability fifa17.empty_mypacks_resolver=1 fifa_pid=4242"
|
||||
);
|
||||
assert_eq!(mem.at(GUARD_LIVE, 2), [0x7f, 0x0f]);
|
||||
|
||||
// Second tick: everything already enforced, and the capability is not
|
||||
// re-advertised.
|
||||
let mut lines = Lines::default();
|
||||
enforce_store_patches(&mem, CBASE, &mut lines.sink(), &mut reported).unwrap();
|
||||
assert!(lines.0.is_empty(), "{:?}", lines.0);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn store_pass_verifies_an_already_patched_guard() {
|
||||
let mem = FakeMemory::new()
|
||||
.with_store_sites(0xcc)
|
||||
.map(GUARD_LIVE, STORE_PATCHES_GUARDED[0].2);
|
||||
let mut lines = Lines::default();
|
||||
let mut reported = HashSet::new();
|
||||
enforce_store_patches(&mem, CBASE, &mut lines.sink(), &mut reported).unwrap();
|
||||
assert_eq!(
|
||||
lines.0.last().unwrap(),
|
||||
"[store-guard] verified capability fifa17.empty_mypacks_resolver=1 fifa_pid=4242"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn store_pass_reports_a_guarded_write_failure_without_aborting_the_tick() {
|
||||
let mut mem = FakeMemory::new()
|
||||
.with_store_sites(0xcc)
|
||||
.map(GUARD_LIVE, STORE_PATCHES_GUARDED[0].1);
|
||||
mem.fail_writes.push(GUARD_LIVE);
|
||||
let mut lines = Lines::default();
|
||||
let mut reported = HashSet::new();
|
||||
// The guarded write failure is handled inline, so the pass still succeeds.
|
||||
enforce_store_patches(&mem, CBASE, &mut lines.sink(), &mut reported).unwrap();
|
||||
assert!(
|
||||
lines.0[lines.0.len() - 2]
|
||||
.starts_with(&format!("pid 4242: guarded patch write failed @ {GUARD_LIVE:#x}: ")),
|
||||
"{}",
|
||||
lines.0[lines.0.len() - 2]
|
||||
);
|
||||
assert_eq!(
|
||||
lines.0[lines.0.len() - 1],
|
||||
"[store-guard] guard status=WRITE_FAILED fifa_pid=4242 (no capability advertised)"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn store_pass_withholds_the_capability_when_verification_fails() {
|
||||
let mut mem = FakeMemory::new()
|
||||
.with_store_sites(0xcc)
|
||||
.map(GUARD_LIVE, STORE_PATCHES_GUARDED[0].1);
|
||||
// Write reported OK, memory unchanged: the re-read still shows the original.
|
||||
mem.swallow_writes.push(GUARD_LIVE);
|
||||
let mut lines = Lines::default();
|
||||
let mut reported = HashSet::new();
|
||||
enforce_store_patches(&mem, CBASE, &mut lines.sink(), &mut reported).unwrap();
|
||||
assert_eq!(
|
||||
lines.0[lines.0.len() - 1],
|
||||
"[store-guard] guard status=VERIFY_FAILED fifa_pid=4242 (no capability advertised)"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn store_pass_aborts_the_tick_when_a_site_is_not_mapped() {
|
||||
// CardsDLL is mapped but this tick catches a site mid-unpack.
|
||||
let mem = FakeMemory::new();
|
||||
let mut lines = Lines::default();
|
||||
let mut reported = HashSet::new();
|
||||
let err = enforce_store_patches(&mem, CBASE, &mut lines.sink(), &mut reported).unwrap_err();
|
||||
assert_eq!(err.kind(), io::ErrorKind::NotFound);
|
||||
assert!(lines.0.is_empty());
|
||||
// Nothing advertised, so the next tick re-evaluates the guard.
|
||||
assert!(reported.is_empty());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn store_pass_skips_writing_sites_that_already_hold_the_patch() {
|
||||
let mut mem = FakeMemory::new().with_store_sites(0xcc);
|
||||
for (va, data) in STORE_PATCHES {
|
||||
mem = mem.map(live_addr(CBASE, va), data);
|
||||
}
|
||||
mem = mem.map(GUARD_LIVE, STORE_PATCHES_GUARDED[0].2);
|
||||
// Any write at all would fail these sites, proving none is attempted.
|
||||
mem.fail_writes
|
||||
.extend(STORE_PATCHES.iter().map(|(va, _)| live_addr(CBASE, *va)));
|
||||
mem.fail_writes.push(GUARD_LIVE);
|
||||
|
||||
let mut lines = Lines::default();
|
||||
let mut reported = HashSet::new();
|
||||
enforce_store_patches(&mem, CBASE, &mut lines.sink(), &mut reported).unwrap();
|
||||
assert_eq!(
|
||||
lines.0,
|
||||
vec!["[store-guard] verified capability fifa17.empty_mypacks_resolver=1 fifa_pid=4242"]
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,160 @@
|
||||
//! `/proc` access: finding the client, locating CardsDLL, and positioned reads
|
||||
//! and writes against `/proc/<pid>/mem`.
|
||||
//!
|
||||
//! Positioned I/O (`pread`/`pwrite`) is used rather than seek+read: a 64-bit
|
||||
//! virtual address is passed straight through as the file offset, so nothing
|
||||
//! depends on a shared file cursor.
|
||||
|
||||
use std::fs::{self, File, OpenOptions};
|
||||
use std::io;
|
||||
use std::os::unix::fs::FileExt;
|
||||
|
||||
use crate::patch::Memory;
|
||||
use crate::{is_client_comm, parse_cardsdll_base, pid_from_proc_entry};
|
||||
|
||||
/// Pids whose `comm` is exactly `FIFA17.exe`.
|
||||
///
|
||||
/// Sorted ascending so that, when more than one client is somehow running, the
|
||||
/// per-pid log lines come out in a stable order (the Python inherits readdir
|
||||
/// order, which is arbitrary).
|
||||
pub fn find_pids() -> Vec<u32> {
|
||||
let mut out = Vec::new();
|
||||
let Ok(entries) = fs::read_dir("/proc") else {
|
||||
return out;
|
||||
};
|
||||
for entry in entries.flatten() {
|
||||
let name = entry.file_name();
|
||||
let Some(pid) = name.to_str().and_then(pid_from_proc_entry) else {
|
||||
continue;
|
||||
};
|
||||
// A pid can exit between readdir and this read; that is not an error.
|
||||
if let Ok(comm) = fs::read_to_string(format!("/proc/{pid}/comm")) {
|
||||
if is_client_comm(&comm) {
|
||||
out.push(pid);
|
||||
}
|
||||
}
|
||||
}
|
||||
out.sort_unstable();
|
||||
out
|
||||
}
|
||||
|
||||
/// Base address of the mapped CardsDLL, or `None` while it is not mapped.
|
||||
pub fn cardsdll_base(pid: u32) -> Option<u64> {
|
||||
let maps = fs::read_to_string(format!("/proc/{pid}/maps")).ok()?;
|
||||
parse_cardsdll_base(&maps)
|
||||
}
|
||||
|
||||
/// [`Memory`] over one live client process.
|
||||
pub struct ProcMem {
|
||||
pid: u32,
|
||||
}
|
||||
|
||||
impl ProcMem {
|
||||
pub fn new(pid: u32) -> Self {
|
||||
Self { pid }
|
||||
}
|
||||
}
|
||||
|
||||
impl Memory for ProcMem {
|
||||
fn pid(&self) -> u32 {
|
||||
self.pid
|
||||
}
|
||||
|
||||
/// A failure here normally means the address is not mapped yet — the packer
|
||||
/// has not unpacked that code — which the watch loop treats as "come back
|
||||
/// next tick", not as a failure worth reporting. Read-only handle.
|
||||
fn read(&self, va: u64, buf: &mut [u8]) -> io::Result<()> {
|
||||
File::open(format!("/proc/{}/mem", self.pid))?.read_exact_at(buf, va)
|
||||
}
|
||||
|
||||
/// Opened read+write like the Python's `r+b`; write-only is not universally
|
||||
/// accepted for `/proc/<pid>/mem` across kernels.
|
||||
fn write(&self, va: u64, data: &[u8]) -> io::Result<()> {
|
||||
OpenOptions::new()
|
||||
.read(true)
|
||||
.write(true)
|
||||
.open(format!("/proc/{}/mem", self.pid))?
|
||||
.write_all_at(data, va)
|
||||
}
|
||||
}
|
||||
|
||||
/// Whether `/proc/<pid>` still exists — the launcher-liveness check.
|
||||
pub fn pid_alive(pid: i64) -> bool {
|
||||
// Formatted exactly like the Python so a negative or zero pid behaves the
|
||||
// same way (the path simply does not exist).
|
||||
fs::metadata(format!("/proc/{pid}")).is_ok()
|
||||
}
|
||||
|
||||
/// Real uid of this process, from the ownership of `/proc/self`.
|
||||
///
|
||||
/// std exposes no `getuid`, and this crate takes no dependencies; `/proc` is
|
||||
/// mandatory for the patcher anyway, so reading it back is not a new assumption.
|
||||
pub fn current_uid() -> io::Result<u32> {
|
||||
use std::os::unix::fs::MetadataExt;
|
||||
Ok(fs::metadata("/proc/self")?.uid())
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn our_own_pid_is_alive_and_pid_zero_is_not() {
|
||||
let me: i64 = fs::read_to_string("/proc/self/stat")
|
||||
.unwrap()
|
||||
.split(' ')
|
||||
.next()
|
||||
.unwrap()
|
||||
.parse()
|
||||
.unwrap();
|
||||
assert!(pid_alive(me));
|
||||
// /proc/0 and /proc/-1 never exist, matching the Python's path check.
|
||||
assert!(!pid_alive(0));
|
||||
assert!(!pid_alive(-1));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn uid_is_readable() {
|
||||
// Only that it resolves; the value is environment-dependent.
|
||||
assert!(current_uid().is_ok());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn find_pids_scan_is_safe_without_a_client() {
|
||||
// Deterministic without a client: the scan must not panic and must only
|
||||
// ever return numeric pids.
|
||||
for pid in find_pids() {
|
||||
assert!(pid > 0);
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn positioned_io_round_trips_against_our_own_address_space() {
|
||||
// Patching FIFA is not testable here, but the /proc/<pid>/mem mechanism
|
||||
// is: read and write this process's own heap through the same code path.
|
||||
let me: u32 = fs::read_to_string("/proc/self/stat")
|
||||
.unwrap()
|
||||
.split(' ')
|
||||
.next()
|
||||
.unwrap()
|
||||
.parse()
|
||||
.unwrap();
|
||||
let mem = ProcMem::new(me);
|
||||
// black_box throughout: this buffer is mutated by the kernel on our
|
||||
// behalf, never by Rust code, so the compiler must not assume it is
|
||||
// unchanged across the write.
|
||||
let target = std::hint::black_box(vec![0x75u8, 0x0f, 0x11, 0x22]);
|
||||
let va = target.as_ptr() as u64;
|
||||
|
||||
let mut seen = [0u8; 4];
|
||||
mem.read(va, &mut seen).unwrap();
|
||||
assert_eq!(seen, *target);
|
||||
|
||||
mem.write(va, &[0x7f, 0x0f]).unwrap();
|
||||
assert_eq!(*std::hint::black_box(&target), [0x7f, 0x0f, 0x11, 0x22]);
|
||||
|
||||
// An address that is certainly not mapped reads as an error, which the
|
||||
// watch loop treats as "not unpacked yet".
|
||||
assert!(mem.read(0x1000, &mut seen).is_err());
|
||||
}
|
||||
}
|
||||
+1
-1
Submodule openfut-core updated: fbb54eac95...637a21eac1
@@ -22,3 +22,6 @@ openfut-identity = { path = "../openfut-identity" }
|
||||
|
||||
[dev-dependencies]
|
||||
tempfile = "3"
|
||||
openfut-core = { path = "../openfut-core" }
|
||||
tokio = { version = "1", features = ["macros", "rt-multi-thread"] }
|
||||
sqlx = { version = "0.7", features = ["sqlite", "runtime-tokio-rustls"] }
|
||||
|
||||
@@ -181,6 +181,23 @@ pub fn plan_apply(
|
||||
});
|
||||
}
|
||||
}
|
||||
// Non-player (consumable/staff) owned instances mint via the IDENTICAL
|
||||
// generic path: deterministic OwnedItemId per (persona, wire), an identity
|
||||
// mapping, and a GenericOwned with card_id = fifa17_<resourceId>.
|
||||
for def in &report.non_player.supported {
|
||||
for &wire in &def.wire_ids {
|
||||
let core_id = owned_item_id(persona, wire);
|
||||
wire_to_owned.insert(wire, core_id.clone());
|
||||
owned.push(GenericOwned {
|
||||
owned_item_id: core_id.clone(),
|
||||
card_id: def.card_id.clone(),
|
||||
});
|
||||
mappings.push(IdentityMapping {
|
||||
core_id,
|
||||
wire_id: wire,
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
// Canonical squad + opaque extension, built by the SAME adapter code the live
|
||||
// squad-write path uses, over the raw source squad. The resolver maps every
|
||||
@@ -253,8 +270,14 @@ pub fn plan_apply(
|
||||
request,
|
||||
mappings,
|
||||
watermark: report.identity.source_watermark,
|
||||
supported_instances: report.identity.import_wire_ids.len(),
|
||||
deferred_instances: report.deferred_instances(),
|
||||
supported_instances: report.identity.import_wire_ids.len()
|
||||
+ report
|
||||
.non_player
|
||||
.supported
|
||||
.iter()
|
||||
.map(|d| d.wire_ids.len())
|
||||
.sum::<usize>(),
|
||||
deferred_instances: report.deferred_instances() + report.non_player.deferred_instances(),
|
||||
source_fingerprint: snapshot_fingerprint.to_string(),
|
||||
})
|
||||
}
|
||||
|
||||
@@ -34,6 +34,7 @@ pub mod apply;
|
||||
pub mod model;
|
||||
|
||||
use model::{Item, Profile};
|
||||
use openfut_adapter_fifa17::fut::content_taxonomy::{consumable_family, staff_role, ContentKind};
|
||||
|
||||
// ----------------------------------------------------------------- roster
|
||||
|
||||
@@ -521,6 +522,157 @@ pub fn plan_definitions(
|
||||
plan
|
||||
}
|
||||
|
||||
// ------------------------------------------------------- non-player content
|
||||
|
||||
/// An honest, profile-derived NON-player CardDefinition proposal (consumable or
|
||||
/// staff), keyed by `fifa17_<resourceId>`. Neutral player fields are supplied at
|
||||
/// emit time; this carries only the identity + honest functional `name` (the
|
||||
/// taxonomy label, never a marketing name).
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub struct NonPlayerDefinition {
|
||||
pub card_id: String,
|
||||
pub resource_id: i64,
|
||||
/// Base asset id when the source carries one (consumables: `== resource_id`);
|
||||
/// staff carry no `assetId`, so this is `None`.
|
||||
pub asset_id: Option<i64>,
|
||||
pub kind: ContentKind,
|
||||
/// FIFA `cardsubtypeid` (consumable family / staff role selector).
|
||||
pub subtype: i64,
|
||||
/// Honest functional label (e.g. "Player Contract", "GK Coach").
|
||||
pub name: String,
|
||||
/// Wire ids of every owned copy of this resourceId (preserved).
|
||||
pub wire_ids: Vec<i64>,
|
||||
}
|
||||
|
||||
/// A non-player group that cannot be honestly classified (DEFERRED, never
|
||||
/// fabricated). Mirrors the player NoName gate.
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub struct DeferredNonPlayer {
|
||||
pub resource_id: i64,
|
||||
/// The agreed subtype when present; `None` when absent or in conflict.
|
||||
pub subtype: Option<i64>,
|
||||
pub wire_ids: Vec<i64>,
|
||||
pub reason: String,
|
||||
}
|
||||
|
||||
#[derive(Debug, Default)]
|
||||
pub struct NonPlayerPlan {
|
||||
pub supported: Vec<NonPlayerDefinition>,
|
||||
pub deferred: Vec<DeferredNonPlayer>,
|
||||
/// Count of SUPPORTED consumable definitions.
|
||||
pub consumables: usize,
|
||||
/// Count of SUPPORTED staff definitions.
|
||||
pub staff: usize,
|
||||
}
|
||||
|
||||
impl NonPlayerPlan {
|
||||
/// Deferred non-player INSTANCES (owned copies) across all deferred groups.
|
||||
pub fn deferred_instances(&self) -> usize {
|
||||
self.deferred.iter().map(|d| d.wire_ids.len()).sum()
|
||||
}
|
||||
}
|
||||
|
||||
/// Plan the non-player (consumable + staff) CardDefinitions. Groups Consumable
|
||||
/// and Staff items by `resourceId`; each group must agree on `cardsubtypeid`
|
||||
/// across copies (a disagreement DEFERS with `subtype_conflict`), then resolves
|
||||
/// the family (consumable) or role (staff) via the adapter's evidence-based
|
||||
/// taxonomy. A missing or unknown `cardsubtypeid` DEFERS — never a placeholder.
|
||||
pub fn plan_non_player_definitions(profile: &Profile) -> NonPlayerPlan {
|
||||
let mut groups: BTreeMap<i64, Vec<&Item>> = BTreeMap::new();
|
||||
for it in &profile.items {
|
||||
if matches!(classify(it), ItemClass::Consumable | ItemClass::Staff) {
|
||||
groups.entry(it.resource_id).or_default().push(it);
|
||||
}
|
||||
}
|
||||
|
||||
let mut plan = NonPlayerPlan::default();
|
||||
for (resource_id, items) in groups {
|
||||
let wire_ids: Vec<i64> = items.iter().map(|i| i.id).collect();
|
||||
|
||||
// Class agreement (a resourceId is either all-consumable or all-staff).
|
||||
let class = classify(items[0]);
|
||||
if items.iter().any(|i| classify(i) != class) {
|
||||
plan.deferred.push(DeferredNonPlayer {
|
||||
resource_id,
|
||||
subtype: None,
|
||||
wire_ids,
|
||||
reason: "class_conflict".to_string(),
|
||||
});
|
||||
continue;
|
||||
}
|
||||
|
||||
// Subtype must agree across every owned copy (identity invariant).
|
||||
let first_subtype = items[0].cardsubtypeid;
|
||||
if items.iter().any(|i| i.cardsubtypeid != first_subtype) {
|
||||
plan.deferred.push(DeferredNonPlayer {
|
||||
resource_id,
|
||||
subtype: None,
|
||||
wire_ids,
|
||||
reason: "subtype_conflict".to_string(),
|
||||
});
|
||||
continue;
|
||||
}
|
||||
let Some(subtype) = first_subtype else {
|
||||
plan.deferred.push(DeferredNonPlayer {
|
||||
resource_id,
|
||||
subtype: None,
|
||||
wire_ids,
|
||||
reason: "missing_cardsubtypeid".to_string(),
|
||||
});
|
||||
continue;
|
||||
};
|
||||
|
||||
let (kind, label) = match class {
|
||||
ItemClass::Consumable => match consumable_family(subtype) {
|
||||
Some((_family, label)) => (ContentKind::Consumable, label),
|
||||
None => {
|
||||
plan.deferred.push(DeferredNonPlayer {
|
||||
resource_id,
|
||||
subtype: Some(subtype),
|
||||
wire_ids,
|
||||
reason: "unknown_subtype".to_string(),
|
||||
});
|
||||
continue;
|
||||
}
|
||||
},
|
||||
ItemClass::Staff => match staff_role(subtype) {
|
||||
Some((_role, label)) => (ContentKind::Staff, label),
|
||||
None => {
|
||||
plan.deferred.push(DeferredNonPlayer {
|
||||
resource_id,
|
||||
subtype: Some(subtype),
|
||||
wire_ids,
|
||||
reason: "unknown_subtype".to_string(),
|
||||
});
|
||||
continue;
|
||||
}
|
||||
},
|
||||
_ => unreachable!("only Consumable/Staff were grouped"),
|
||||
};
|
||||
|
||||
plan.supported.push(NonPlayerDefinition {
|
||||
card_id: format!("fifa17_{resource_id}"),
|
||||
resource_id,
|
||||
asset_id: items[0].asset_id,
|
||||
kind,
|
||||
subtype,
|
||||
name: label.to_string(),
|
||||
wire_ids,
|
||||
});
|
||||
}
|
||||
plan.consumables = plan
|
||||
.supported
|
||||
.iter()
|
||||
.filter(|d| d.kind == ContentKind::Consumable)
|
||||
.count();
|
||||
plan.staff = plan
|
||||
.supported
|
||||
.iter()
|
||||
.filter(|d| d.kind == ContentKind::Staff)
|
||||
.count();
|
||||
plan
|
||||
}
|
||||
|
||||
// --------------------------------------------------------------- identity
|
||||
|
||||
#[derive(Debug, Default)]
|
||||
@@ -632,6 +784,8 @@ pub struct Report {
|
||||
pub definitions: DefinitionPlan,
|
||||
pub identity: IdentityPlan,
|
||||
pub squad: SquadCoverage,
|
||||
/// Consumable + staff content (supported definitions + deferred groups).
|
||||
pub non_player: NonPlayerPlan,
|
||||
/// Unconsumed pack entitlements to seed (from `unopenedPackIds`).
|
||||
pub unopened_pack_ids: Vec<i64>,
|
||||
}
|
||||
@@ -720,6 +874,7 @@ pub fn analyze(
|
||||
let identity = plan_identity(profile, &supported_rids);
|
||||
let supported_wire: BTreeSet<i64> = identity.import_wire_ids.iter().copied().collect();
|
||||
let squad = plan_squad(profile, &supported_wire);
|
||||
let non_player = plan_non_player_definitions(profile);
|
||||
Report {
|
||||
game: "fifa17".to_string(),
|
||||
persona_id: profile.persona_id,
|
||||
@@ -731,6 +886,7 @@ pub fn analyze(
|
||||
definitions,
|
||||
identity,
|
||||
squad,
|
||||
non_player,
|
||||
unopened_pack_ids: profile.unopened_pack_ids.clone(),
|
||||
}
|
||||
}
|
||||
@@ -740,6 +896,7 @@ impl std::fmt::Display for Report {
|
||||
let d = &self.definitions;
|
||||
let id = &self.identity;
|
||||
let sq = &self.squad;
|
||||
let np = &self.non_player;
|
||||
writeln!(f, "OpenFUT FIFA17 real-profile import — analysis")?;
|
||||
writeln!(f, "=============================================")?;
|
||||
writeln!(
|
||||
@@ -819,11 +976,30 @@ impl std::fmt::Display for Report {
|
||||
}
|
||||
writeln!(
|
||||
f,
|
||||
"\nRESULT would_import_players={} deferred_player_instances={} deferred_consumables={} deferred_staff={}",
|
||||
"\nNON-PLAYER CONTENT (consumable/staff) supported={} (consumables={} staff={}) deferred_groups={} deferred_instances={}",
|
||||
np.supported.len(),
|
||||
np.consumables,
|
||||
np.staff,
|
||||
np.deferred.len(),
|
||||
np.deferred_instances()
|
||||
)?;
|
||||
for nd in &np.deferred {
|
||||
writeln!(
|
||||
f,
|
||||
" DEFER resourceId={} subtype={:?} copies={} reason={}",
|
||||
nd.resource_id,
|
||||
nd.subtype,
|
||||
nd.wire_ids.len(),
|
||||
nd.reason
|
||||
)?;
|
||||
}
|
||||
writeln!(
|
||||
f,
|
||||
"\nRESULT would_import_players={} would_import_non_players={} deferred_player_instances={} deferred_non_player_instances={}",
|
||||
id.import_wire_ids.len(),
|
||||
np.supported.iter().map(|d| d.wire_ids.len()).sum::<usize>(),
|
||||
self.deferred_instances(),
|
||||
self.counts.consumables,
|
||||
self.counts.staff
|
||||
np.deferred_instances()
|
||||
)?;
|
||||
let blockers = self.blockers();
|
||||
if blockers.is_empty() {
|
||||
@@ -861,6 +1037,10 @@ pub struct EmitSummary {
|
||||
pub catalog_entries: usize,
|
||||
pub supported_instances: usize,
|
||||
pub deferred_instances: usize,
|
||||
/// Non-player (consumable/staff) supported definitions written.
|
||||
pub non_player_definitions: usize,
|
||||
/// Non-player supported owned INSTANCES (owned copies across those defs).
|
||||
pub non_player_instances: usize,
|
||||
}
|
||||
|
||||
/// Emit the PUBLIC content pack + host catalog for supported definitions, and a
|
||||
@@ -880,7 +1060,7 @@ pub fn emit_content(
|
||||
std::fs::create_dir_all(&manifest_dir)?;
|
||||
|
||||
// ---- PUBLIC: Core CardDefinition[] (matches openfut-core models::card) ----
|
||||
let defs: Vec<serde_json::Value> = report
|
||||
let mut defs: Vec<serde_json::Value> = report
|
||||
.definitions
|
||||
.supported
|
||||
.iter()
|
||||
@@ -904,15 +1084,58 @@ pub fn emit_content(
|
||||
})
|
||||
})
|
||||
.collect();
|
||||
// Non-player CardDefinitions use NEUTRAL player fields + the honest family/
|
||||
// role name; Core stores them like any other definition (no FIFA concept).
|
||||
for d in &report.non_player.supported {
|
||||
defs.push(serde_json::json!({
|
||||
"id": d.card_id,
|
||||
"name": d.name,
|
||||
"overall": 0,
|
||||
"position": "",
|
||||
"nation": "",
|
||||
"league": "",
|
||||
"club": "",
|
||||
"pace": 0,
|
||||
"shooting": 0,
|
||||
"passing": 0,
|
||||
"dribbling": 0,
|
||||
"defending": 0,
|
||||
"physical": 0,
|
||||
"rarity": "bronze",
|
||||
"image_path": serde_json::Value::Null,
|
||||
}));
|
||||
}
|
||||
let content_pack = content_dir.join("fifa17-production-cards.json");
|
||||
write_json_pretty(&content_pack, &defs)?;
|
||||
|
||||
// ---- PUBLIC: host identity catalog {card_id: {asset_id, version, rareflag}} ----
|
||||
let mut cards = serde_json::Map::new();
|
||||
for d in &report.definitions.supported {
|
||||
// Players carry an explicit kind:"player" + subtype:0 so the adapter can
|
||||
// classify EVERY catalogued card (not just non-players).
|
||||
cards.insert(
|
||||
d.card_id.clone(),
|
||||
serde_json::json!({ "asset_id": d.asset_id, "version": d.version, "rareflag": d.rareflag }),
|
||||
serde_json::json!({
|
||||
"asset_id": d.asset_id,
|
||||
"version": d.version,
|
||||
"rareflag": d.rareflag,
|
||||
"kind": "player",
|
||||
"subtype": 0,
|
||||
}),
|
||||
);
|
||||
}
|
||||
for d in &report.non_player.supported {
|
||||
// asset_id falls back to resource_id (staff carry no assetId); version 0,
|
||||
// rareflag 0 — a consumable/staff never renders as a special card.
|
||||
cards.insert(
|
||||
d.card_id.clone(),
|
||||
serde_json::json!({
|
||||
"asset_id": d.asset_id.unwrap_or(d.resource_id),
|
||||
"version": 0,
|
||||
"rareflag": 0,
|
||||
"kind": d.kind.as_str(),
|
||||
"subtype": d.subtype,
|
||||
}),
|
||||
);
|
||||
}
|
||||
let catalog = serde_json::json!({
|
||||
@@ -966,8 +1189,44 @@ pub fn emit_content(
|
||||
"distinct_variants": c.distinct.len(),
|
||||
}));
|
||||
}
|
||||
let non_player_supported: Vec<serde_json::Value> = report
|
||||
.non_player
|
||||
.supported
|
||||
.iter()
|
||||
.map(|d| {
|
||||
serde_json::json!({
|
||||
"card_id": d.card_id,
|
||||
"resource_id": d.resource_id,
|
||||
"asset_id": d.asset_id,
|
||||
"kind": d.kind.as_str(),
|
||||
"subtype": d.subtype,
|
||||
"name": d.name,
|
||||
"wire_ids": d.wire_ids,
|
||||
})
|
||||
})
|
||||
.collect();
|
||||
let non_player_deferred: Vec<serde_json::Value> = report
|
||||
.non_player
|
||||
.deferred
|
||||
.iter()
|
||||
.map(|dd| {
|
||||
serde_json::json!({
|
||||
"resource_id": dd.resource_id,
|
||||
"subtype": dd.subtype,
|
||||
"wire_ids": dd.wire_ids,
|
||||
"reason": dd.reason,
|
||||
})
|
||||
})
|
||||
.collect();
|
||||
let supported_instances = report.identity.import_wire_ids.len();
|
||||
let deferred_instances = report.deferred_instances();
|
||||
let non_player_definitions = report.non_player.supported.len();
|
||||
let non_player_instances: usize = report
|
||||
.non_player
|
||||
.supported
|
||||
.iter()
|
||||
.map(|d| d.wire_ids.len())
|
||||
.sum();
|
||||
let manifest = serde_json::json!({
|
||||
"generator": "openfut-import-fifa17",
|
||||
"source_kind": "python-profile-observation",
|
||||
@@ -987,6 +1246,12 @@ pub fn emit_content(
|
||||
},
|
||||
"supported_definitions": supported,
|
||||
"deferred": deferred,
|
||||
"non_player": {
|
||||
"supported_definitions": non_player_supported,
|
||||
"supported_instances": non_player_instances,
|
||||
"deferred": non_player_deferred,
|
||||
"deferred_instances": report.non_player.deferred_instances(),
|
||||
},
|
||||
});
|
||||
let manifest_path = manifest_dir.join("fifa17-import-manifest.json");
|
||||
write_json_pretty(&manifest_path, &manifest)?;
|
||||
@@ -996,9 +1261,11 @@ pub fn emit_content(
|
||||
host_catalog,
|
||||
manifest: manifest_path,
|
||||
definitions: report.definitions.supported.len(),
|
||||
catalog_entries: report.definitions.supported.len(),
|
||||
catalog_entries: report.definitions.supported.len() + non_player_definitions,
|
||||
supported_instances,
|
||||
deferred_instances,
|
||||
non_player_definitions,
|
||||
non_player_instances,
|
||||
})
|
||||
}
|
||||
|
||||
|
||||
@@ -123,6 +123,10 @@ fn run() -> Result<ExitCode> {
|
||||
sum.supported_instances,
|
||||
sum.deferred_instances
|
||||
);
|
||||
println!(
|
||||
" non-player : {} definition(s), {} instance(s) (consumable/staff)",
|
||||
sum.non_player_definitions, sum.non_player_instances
|
||||
);
|
||||
}
|
||||
|
||||
if do_apply {
|
||||
|
||||
@@ -63,6 +63,19 @@ pub struct Item {
|
||||
pub league_id: Option<i64>,
|
||||
#[serde(rename = "attributeList", default)]
|
||||
pub attribute_list: Option<Vec<Attr>>,
|
||||
/// FIFA `cardsubtypeid` — the consumable family / staff role selector. Absent
|
||||
/// for player cards; present for consumables and staff.
|
||||
#[serde(default)]
|
||||
pub cardsubtypeid: Option<i64>,
|
||||
/// Consumable ART id (small id), distinct from `resourceId`. Permissive.
|
||||
#[serde(default)]
|
||||
pub cardassetid: Option<i64>,
|
||||
/// Consumable stack size (`amount`). Permissive.
|
||||
#[serde(default)]
|
||||
pub amount: Option<i64>,
|
||||
/// Staff/contract `contract` count. Permissive.
|
||||
#[serde(default)]
|
||||
pub contract: Option<i64>,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, Deserialize)]
|
||||
|
||||
@@ -626,3 +626,259 @@ fn apply_fails_gracefully_when_core_binary_missing() {
|
||||
let err = apply_import(&plan, &paths, false).unwrap_err();
|
||||
assert!(format!("{err:#}").contains("spawn core import"), "{err:#}");
|
||||
}
|
||||
|
||||
// -------------------------------------------------- non-player content
|
||||
|
||||
use openfut_adapter_fifa17::fut::catalog::Fifa17CardCatalog;
|
||||
use openfut_adapter_fifa17::fut::content_taxonomy::ContentKind;
|
||||
|
||||
/// A consumable owned item: itemType="player" but NO attributeList; identity is
|
||||
/// carried entirely by resourceId (== assetId == carddbid) + cardsubtypeid.
|
||||
fn consumable(id: i64, resource: i64, subtype: i64) -> String {
|
||||
format!(
|
||||
r#"{{"id":{id},"resourceId":{resource},"assetId":{resource},"itemType":"player",
|
||||
"cardsubtypeid":{subtype},"cardassetid":3,"amount":1,"rating":0,"rareflag":0}}"#
|
||||
)
|
||||
}
|
||||
|
||||
/// A staff owned item: itemType="staff", resourceId only (NO assetId), keyed by
|
||||
/// cardsubtypeid.
|
||||
fn staff(id: i64, resource: i64, subtype: i64) -> String {
|
||||
format!(
|
||||
r#"{{"id":{id},"resourceId":{resource},"itemType":"staff","cardsubtypeid":{subtype},"contract":10}}"#
|
||||
)
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn plan_non_player_supports_seventeen_consumables_and_three_staff() {
|
||||
// The exact record set from the ticket: distinct resourceIds, so each is its
|
||||
// own definition even where two copies share a subtype (54,54 / 100,100 /
|
||||
// 202,202 / staff 8,8) — subtype duplication across DISTINCT definitions is
|
||||
// not a conflict.
|
||||
let consumable_subtypes = [
|
||||
54, 54, 52, 91, 92, 97, 98, 100, 100, 258, 267, 271, 201, 202, 202, 217, 213,
|
||||
];
|
||||
let staff_subtypes = [8i64, 8, 6];
|
||||
let mut items = Vec::new();
|
||||
for (i, &st) in consumable_subtypes.iter().enumerate() {
|
||||
let i = i as i64;
|
||||
items.push(consumable(100_000_200 + i, 5_003_001 + i, st));
|
||||
}
|
||||
for (i, &st) in staff_subtypes.iter().enumerate() {
|
||||
let i = i as i64;
|
||||
items.push(staff(100_000_300 + i, 3_000_001 + i, st));
|
||||
}
|
||||
let plan = plan_non_player_definitions(&profile(&items, "[]", 100000500));
|
||||
assert_eq!(
|
||||
plan.supported.len(),
|
||||
20,
|
||||
"17 consumable + 3 staff definitions"
|
||||
);
|
||||
assert_eq!(plan.consumables, 17);
|
||||
assert_eq!(plan.staff, 3);
|
||||
assert!(plan.deferred.is_empty(), "0 deferred: {:?}", plan.deferred);
|
||||
|
||||
// Honest labels + kinds resolve from the taxonomy (spot checks).
|
||||
let by_id = |cid: &str| plan.supported.iter().find(|d| d.card_id == cid).unwrap();
|
||||
// subtype 201 -> Player Contract (13th consumable, resource 5003013)
|
||||
let contract = by_id("fifa17_5003013");
|
||||
assert_eq!(contract.name, "Player Contract");
|
||||
assert_eq!(contract.kind, ContentKind::Consumable);
|
||||
assert_eq!(contract.subtype, 201);
|
||||
// subtype 258 -> Player Chemistry Style (10th consumable, resource 5003010)
|
||||
assert_eq!(by_id("fifa17_5003010").name, "Player Chemistry Style");
|
||||
// staff subtype 8 -> Fitness Coach; subtype 6 -> GK Coach
|
||||
let fitness = by_id("fifa17_3000001");
|
||||
assert_eq!(fitness.name, "Fitness Coach");
|
||||
assert_eq!(fitness.kind, ContentKind::Staff);
|
||||
assert_eq!(fitness.asset_id, None, "staff carry no assetId");
|
||||
assert_eq!(by_id("fifa17_3000003").name, "GK Coach");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn unknown_subtype_consumable_defers_never_fabricated() {
|
||||
let plan = plan_non_player_definitions(&profile(
|
||||
&[consumable(100000300, 5009999, 999)],
|
||||
"[]",
|
||||
100000500,
|
||||
));
|
||||
assert!(plan.supported.is_empty());
|
||||
assert_eq!(plan.deferred.len(), 1);
|
||||
assert_eq!(plan.deferred[0].reason, "unknown_subtype");
|
||||
assert_eq!(plan.deferred[0].subtype, Some(999));
|
||||
assert_eq!(plan.deferred[0].wire_ids, vec![100000300]);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn missing_cardsubtypeid_defers() {
|
||||
// itemType player, no attributeList, no cardsubtypeid -> consumable w/o a
|
||||
// resolvable family -> DEFER (never a placeholder).
|
||||
let item =
|
||||
r#"{"id":100000301,"resourceId":5003050,"assetId":5003050,"itemType":"player","rating":0}"#
|
||||
.to_string();
|
||||
let plan = plan_non_player_definitions(&profile(&[item], "[]", 100000500));
|
||||
assert!(plan.supported.is_empty());
|
||||
assert_eq!(plan.deferred.len(), 1);
|
||||
assert_eq!(plan.deferred[0].reason, "missing_cardsubtypeid");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn conflicting_subtype_across_copies_defers() {
|
||||
// Two copies of one resourceId that disagree on subtype -> defer, never a
|
||||
// silent winner.
|
||||
let plan = plan_non_player_definitions(&profile(
|
||||
&[
|
||||
consumable(100000302, 5003060, 201),
|
||||
consumable(100000303, 5003060, 202),
|
||||
],
|
||||
"[]",
|
||||
100000500,
|
||||
));
|
||||
assert!(plan.supported.is_empty());
|
||||
assert_eq!(plan.deferred.len(), 1);
|
||||
assert_eq!(plan.deferred[0].reason, "subtype_conflict");
|
||||
assert_eq!(plan.deferred[0].wire_ids, vec![100000302, 100000303]);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn non_player_deferral_is_not_a_blocker() {
|
||||
// A non-player deferral (like a player NoName deferral) must NOT block emit.
|
||||
let items = vec![
|
||||
player(100000001, 20801, 20801, 94),
|
||||
consumable(100000300, 5009999, 999), // unknown subtype -> deferred
|
||||
];
|
||||
let rep = analyze(
|
||||
&profile(&items, "[]", 100000500),
|
||||
&roster(),
|
||||
&entities(),
|
||||
&none(),
|
||||
);
|
||||
assert!(!rep.has_blockers(), "blockers: {:?}", rep.blockers());
|
||||
assert_eq!(rep.non_player.deferred.len(), 1);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn emit_content_writes_non_player_defs_catalog_kind_and_manifest() {
|
||||
let items = vec![
|
||||
player(100000001, 20801, 20801, 94),
|
||||
consumable(100000201, 5003012, 201), // Player Contract
|
||||
staff(100000427, 3000083, 8), // Fitness Coach
|
||||
];
|
||||
let rep = analyze(
|
||||
&profile(&items, "[]", 100000500),
|
||||
&roster(),
|
||||
&entities(),
|
||||
&none(),
|
||||
);
|
||||
assert!(!rep.has_blockers(), "blockers: {:?}", rep.blockers());
|
||||
assert_eq!(rep.non_player.supported.len(), 2);
|
||||
|
||||
let dir = tempfile::tempdir().unwrap();
|
||||
let sum = emit_content(&rep, dir.path(), "fp").unwrap();
|
||||
assert_eq!(sum.definitions, 1, "one player definition");
|
||||
assert_eq!(sum.non_player_definitions, 2);
|
||||
assert_eq!(sum.non_player_instances, 2);
|
||||
assert_eq!(
|
||||
sum.catalog_entries, 3,
|
||||
"player + 2 non-player catalog entries"
|
||||
);
|
||||
|
||||
// Content pack: neutral non-player CardDefinition with honest name.
|
||||
let pack: serde_json::Value =
|
||||
serde_json::from_str(&std::fs::read_to_string(&sum.content_pack).unwrap()).unwrap();
|
||||
let arr = pack.as_array().unwrap();
|
||||
let cons = arr.iter().find(|c| c["id"] == "fifa17_5003012").unwrap();
|
||||
assert_eq!(cons["name"], "Player Contract");
|
||||
assert_eq!(cons["overall"], 0);
|
||||
assert_eq!(cons["position"], "");
|
||||
assert_eq!(cons["nation"], "");
|
||||
assert_eq!(cons["rarity"], "bronze");
|
||||
assert!(cons["image_path"].is_null());
|
||||
|
||||
// Catalog: kind+subtype on player AND non-player; staff asset falls back to
|
||||
// resourceId; and the emitted catalog LOADS in the adapter with kind_of.
|
||||
let cat: serde_json::Value =
|
||||
serde_json::from_str(&std::fs::read_to_string(&sum.host_catalog).unwrap()).unwrap();
|
||||
assert_eq!(cat["cards"]["fifa17_20801"]["kind"], "player");
|
||||
assert_eq!(cat["cards"]["fifa17_20801"]["subtype"], 0);
|
||||
assert_eq!(cat["cards"]["fifa17_5003012"]["kind"], "consumable");
|
||||
assert_eq!(cat["cards"]["fifa17_5003012"]["subtype"], 201);
|
||||
assert_eq!(cat["cards"]["fifa17_5003012"]["rareflag"], 0);
|
||||
assert_eq!(cat["cards"]["fifa17_3000083"]["kind"], "staff");
|
||||
assert_eq!(cat["cards"]["fifa17_3000083"]["subtype"], 8);
|
||||
assert_eq!(cat["cards"]["fifa17_3000083"]["asset_id"], 3000083);
|
||||
|
||||
let loaded = Fifa17CardCatalog::from_file(&sum.host_catalog).unwrap();
|
||||
assert_eq!(loaded.kind_of("fifa17_20801"), ContentKind::Player);
|
||||
assert_eq!(loaded.kind_of("fifa17_5003012"), ContentKind::Consumable);
|
||||
assert_eq!(loaded.subtype_of("fifa17_5003012"), 201);
|
||||
assert_eq!(loaded.kind_of("fifa17_3000083"), ContentKind::Staff);
|
||||
|
||||
// Manifest: private non_player section with preserved wire ids.
|
||||
let man: serde_json::Value =
|
||||
serde_json::from_str(&std::fs::read_to_string(&sum.manifest).unwrap()).unwrap();
|
||||
assert_eq!(man["non_player"]["supported_instances"], 2);
|
||||
let np = man["non_player"]["supported_definitions"]
|
||||
.as_array()
|
||||
.unwrap();
|
||||
assert_eq!(np.len(), 2);
|
||||
let cons_man = np
|
||||
.iter()
|
||||
.find(|d| d["card_id"] == "fifa17_5003012")
|
||||
.unwrap();
|
||||
assert_eq!(cons_man["wire_ids"], serde_json::json!([100000201]));
|
||||
assert_eq!(cons_man["kind"], "consumable");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn plan_apply_mints_non_player_owned_instances() {
|
||||
let items = vec![
|
||||
player(100000001, 20801, 20801, 94),
|
||||
consumable(100000201, 5003012, 201),
|
||||
staff(100000427, 3000083, 8),
|
||||
];
|
||||
let (report, raw) = report_and_raw(&items, "[]", 100000500);
|
||||
let plan = plan_apply(&report, &raw, "fp").unwrap();
|
||||
// 1 player + 2 non-player owned instances, minted via the identical path.
|
||||
assert_eq!(plan.request.owned.len(), 3);
|
||||
assert_eq!(plan.mappings.len(), 3);
|
||||
assert_eq!(plan.supported_instances, 3);
|
||||
assert_eq!(plan.deferred_instances, 0);
|
||||
let cards: BTreeSet<&str> = plan
|
||||
.request
|
||||
.owned
|
||||
.iter()
|
||||
.map(|o| o.card_id.as_str())
|
||||
.collect();
|
||||
assert!(cards.contains("fifa17_5003012"), "consumable minted");
|
||||
assert!(cards.contains("fifa17_3000083"), "staff minted");
|
||||
// Deterministic OwnedItemId per (persona, wire) — same rule as players.
|
||||
let m = plan
|
||||
.mappings
|
||||
.iter()
|
||||
.find(|m| m.wire_id == 100000201)
|
||||
.unwrap();
|
||||
assert_eq!(m.core_id, owned_item_id(33068179, 100000201));
|
||||
|
||||
// Local preflight passes because the emitted content pack contains the
|
||||
// non-player card_ids too.
|
||||
let dir = tempfile::tempdir().unwrap();
|
||||
let sum = emit_content(&report, dir.path(), "fp").unwrap();
|
||||
let ids = content_card_ids(&sum.content_pack).unwrap();
|
||||
local_core_preflight(&plan, &ids).unwrap();
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn deferred_non_player_instances_gate_a_production_apply() {
|
||||
// A supported player + a deferred (unknown-subtype) consumable: the deferred
|
||||
// non-player instance blocks a production apply, allowed only for staging.
|
||||
let items = vec![
|
||||
player(100000001, 20801, 20801, 94),
|
||||
consumable(100000300, 5009999, 999),
|
||||
];
|
||||
let (report, raw) = report_and_raw(&items, "[]", 100000500);
|
||||
let plan = plan_apply(&report, &raw, "fp").unwrap();
|
||||
assert_eq!(plan.deferred_instances, 1, "the deferred consumable counts");
|
||||
assert!(gate_staging(&plan, false).is_err(), "production blocks");
|
||||
assert!(gate_staging(&plan, true).unwrap(), "staging opt-in allows");
|
||||
}
|
||||
|
||||
@@ -0,0 +1,387 @@
|
||||
//! Durable end-to-end proof of the FIFA17 real-profile import against a
|
||||
//! DISPOSABLE, temp-FILE Core SQLite DB (not `:memory:`, so a restart is real).
|
||||
//!
|
||||
//! This drives the REAL components exactly as the production dispatch does:
|
||||
//! * `openfut_import_fifa17::analyze` → the read-only [`Report`] (dry-run);
|
||||
//! * `openfut_import_fifa17::emit_content` → the production content pack;
|
||||
//! * `openfut_import_fifa17::apply::plan_apply` → the generic Core request +
|
||||
//! the deterministic identity mappings + the allocation watermark;
|
||||
//! * the real orchestration GATES (`gate_staging`, `local_core_preflight`,
|
||||
//! `identity_dry_preflight`, `seed_identity`, `post_validate_identity`) and a
|
||||
//! real `openfut_identity::JsonIdentityStore`;
|
||||
//! * `openfut_core::services::import::apply_profile_import` inside a single
|
||||
//! Core SQLite transaction on a temp-file pool.
|
||||
//!
|
||||
//! The ONLY place this test diverges from `apply::apply` is the Core boundary:
|
||||
//! `apply::apply` writes the request JSON and spawns the `openfut-core` binary
|
||||
//! (`import <req.json>`); here we serialize the SAME `GenericImportRequest` to
|
||||
//! JSON and deserialize it into Core's `ProfileImportRequest` (the two types
|
||||
//! share their field names by contract), then call `apply_profile_import`
|
||||
//! in-process against the temp-file pool. That collapses the process boundary
|
||||
//! without reimplementing any importer or Core logic, and lets the test drop &
|
||||
//! reopen the DB file to prove durability.
|
||||
//!
|
||||
//! Fingerprint mechanism under test: `openfut_import_fifa17::fingerprint` (a
|
||||
//! dependency-free FNV-1a-64 hex digest of the source snapshot bytes) is carried
|
||||
//! verbatim into `ProfileImportRequest::source_fingerprint`, which Core persists
|
||||
//! as `profiles.import_fingerprint` and uses as the per-game rerun-identity key:
|
||||
//! identical fingerprint on an already-imported game → idempotent no-op; a
|
||||
//! DIFFERENT fingerprint for the same game → hard failure (never a silent merge).
|
||||
|
||||
use std::collections::BTreeSet;
|
||||
|
||||
use openfut_adapter_fifa17::fut::catalog::Fifa17WireItemIdPolicy;
|
||||
use openfut_core::db::{init_pool, run_migrations, Pool};
|
||||
use openfut_core::services::card_db::CardDb;
|
||||
use openfut_core::services::import::{apply_profile_import, ImportOutcome, ProfileImportRequest};
|
||||
use openfut_identity::{ExternalIdentityStore, JsonIdentityStore};
|
||||
|
||||
use openfut_import_fifa17::apply::{
|
||||
content_card_ids, gate_staging, identity_dry_preflight, local_core_preflight, owned_item_id,
|
||||
plan_apply, post_validate_identity, seed_identity, ApplyPlan,
|
||||
};
|
||||
use openfut_import_fifa17::model::Profile;
|
||||
use openfut_import_fifa17::{analyze, emit_content, fingerprint, Entities, Report, Roster};
|
||||
|
||||
const PERSONA: i64 = 33068179;
|
||||
|
||||
// ---- sanitized in-test fixture (NOT production/live data) ----
|
||||
|
||||
fn roster() -> Roster {
|
||||
Roster::from_json_str(
|
||||
r#"[
|
||||
{"id":20801,"first":"Cristiano","last":"Ronaldo","common":""},
|
||||
{"id":176580,"first":"Luis","last":"Suárez","common":""},
|
||||
{"id":158023,"first":"Lionel","last":"Messi","common":""}
|
||||
]"#,
|
||||
)
|
||||
.unwrap()
|
||||
}
|
||||
|
||||
fn entities() -> Entities {
|
||||
use std::collections::BTreeMap;
|
||||
Entities::from_maps(
|
||||
BTreeMap::from([(53, "LaLiga".to_string())]),
|
||||
BTreeMap::from([(38, "Portugal".to_string())]),
|
||||
BTreeMap::from([(243, "Real Madrid".to_string())]),
|
||||
)
|
||||
}
|
||||
|
||||
/// A resolvable base player card (nation 38 / team 243 / league 53 all resolve).
|
||||
fn player(id: i64, resource: i64, asset: i64, rating: i64) -> String {
|
||||
format!(
|
||||
r#"{{"id":{id},"resourceId":{resource},"assetId":{asset},"itemType":"player",
|
||||
"rareflag":1,"rating":{rating},"preferredPosition":"ST","nation":38,
|
||||
"teamid":243,"leagueId":53,"attributeList":[
|
||||
{{"index":0,"value":90}},{{"index":1,"value":91}},{{"index":2,"value":82}},
|
||||
{{"index":3,"value":88}},{{"index":4,"value":30}},{{"index":5,"value":78}}]}}"#
|
||||
)
|
||||
}
|
||||
|
||||
const SQUAD_F433: &str = r#"[{"formation":"f433","squadName":"OpenFUT","captain":100000001,
|
||||
"squadType":"REGULAR_SQUAD","custom":"[0,0,0]",
|
||||
"players":[{"index":0,"itemData":{"id":100000001},"kitNumber":7},
|
||||
{"index":1,"itemData":{"id":100000002},"kitNumber":9}],
|
||||
"kicktakers":[{"index":0,"id":100000001}],"manager":[{"id":100000427}]}]"#;
|
||||
|
||||
/// The three owned player instances (wire ids 100000001..100000003).
|
||||
fn items() -> Vec<String> {
|
||||
vec![
|
||||
player(100000001, 20801, 20801, 94), // fifa17_20801 (Ronaldo)
|
||||
player(100000002, 176580, 176580, 86), // fifa17_176580 (Suárez)
|
||||
player(100000003, 158023, 158023, 93), // fifa17_158023 (Messi)
|
||||
]
|
||||
}
|
||||
|
||||
/// Build the source profile JSON with the given coins (varying coins is the
|
||||
/// "meaningful change" that flips the fingerprint for STEP E).
|
||||
fn profile_json(coins: i64) -> String {
|
||||
format!(
|
||||
r#"{{"personaId":{PERSONA},"personaName":"CAGE","clubName":"OpenFUT","clubAbbr":"OFC",
|
||||
"coins":{coins},"nextItemId":100000600,
|
||||
"items":[{}],"squads":{SQUAD_F433},"unopenedPackIds":[70,70,101]}}"#,
|
||||
items().join(",")
|
||||
)
|
||||
}
|
||||
|
||||
/// Analyze one snapshot into (report, raw Value, fingerprint), the read-only
|
||||
/// dry-run the production dispatch performs before any write.
|
||||
fn dry_run(coins: i64) -> (Report, serde_json::Value, String) {
|
||||
let json = profile_json(coins);
|
||||
let prof = Profile::from_json_str(&json).unwrap();
|
||||
let report = analyze(&prof, &roster(), &entities(), &BTreeSet::new());
|
||||
let raw: serde_json::Value = serde_json::from_str(&json).unwrap();
|
||||
let fp = fingerprint(json.as_bytes());
|
||||
(report, raw, fp)
|
||||
}
|
||||
|
||||
/// Serialize the importer's generic request and deserialize it into Core's
|
||||
/// request — the exact JSON contract `apply::apply` hands the Core binary.
|
||||
fn to_core_request(plan: &ApplyPlan) -> ProfileImportRequest {
|
||||
let bytes = serde_json::to_vec(&plan.request).expect("serialize generic request");
|
||||
serde_json::from_slice(&bytes).expect("deserialize into Core ProfileImportRequest")
|
||||
}
|
||||
|
||||
async fn count(pool: &Pool, table: &str) -> i64 {
|
||||
sqlx::query_scalar(&format!("SELECT COUNT(*) FROM {table}"))
|
||||
.fetch_one(pool)
|
||||
.await
|
||||
.unwrap()
|
||||
}
|
||||
|
||||
async fn coins(pool: &Pool) -> i64 {
|
||||
sqlx::query_scalar("SELECT coins FROM clubs")
|
||||
.fetch_one(pool)
|
||||
.await
|
||||
.unwrap()
|
||||
}
|
||||
|
||||
async fn owned_card_ids(pool: &Pool) -> BTreeSet<String> {
|
||||
sqlx::query_scalar::<_, String>("SELECT card_id FROM owned_cards")
|
||||
.fetch_all(pool)
|
||||
.await
|
||||
.unwrap()
|
||||
.into_iter()
|
||||
.collect()
|
||||
}
|
||||
|
||||
async fn owned_item_ids(pool: &Pool) -> BTreeSet<String> {
|
||||
sqlx::query_scalar::<_, String>("SELECT id FROM owned_cards")
|
||||
.fetch_all(pool)
|
||||
.await
|
||||
.unwrap()
|
||||
.into_iter()
|
||||
.collect()
|
||||
}
|
||||
|
||||
const CORE_TABLES: &[&str] = &[
|
||||
"profiles",
|
||||
"clubs",
|
||||
"owned_cards",
|
||||
"packs",
|
||||
"squads",
|
||||
"squad_players",
|
||||
"game_entity_ext",
|
||||
];
|
||||
|
||||
#[tokio::test]
|
||||
async fn durable_import_dryrun_apply_restart_idempotent_conflict() {
|
||||
let dir = tempfile::tempdir().unwrap();
|
||||
let db_path = dir.path().join("core.sqlite");
|
||||
let db_url = format!("sqlite://{}", db_path.display());
|
||||
let identity_store_path = dir.path().join("identity.json");
|
||||
|
||||
// Empty base catalog dir → CardDb has ONLY the emitted production pack.
|
||||
let data_dir = dir.path().join("data");
|
||||
std::fs::create_dir_all(&data_dir).unwrap();
|
||||
|
||||
// The expected import shape, derived from the fixture.
|
||||
let expected_coins = 750_000_i64;
|
||||
let expected_owned = 3_usize;
|
||||
let expected_packs = 3_usize; // unopenedPackIds [70,70,101]
|
||||
let expected_squad_slots = 2_usize;
|
||||
let expected_card_ids: BTreeSet<String> = ["fifa17_20801", "fifa17_176580", "fifa17_158023"]
|
||||
.iter()
|
||||
.map(|s| s.to_string())
|
||||
.collect();
|
||||
let expected_wires = [100000001_i64, 100000002, 100000003];
|
||||
let expected_owned_ids: BTreeSet<String> = expected_wires
|
||||
.iter()
|
||||
.map(|&w| owned_item_id(PERSONA, w))
|
||||
.collect();
|
||||
|
||||
let (g, k) = (
|
||||
Fifa17WireItemIdPolicy::GAME,
|
||||
Fifa17WireItemIdPolicy::OWNED_ITEM_KIND,
|
||||
);
|
||||
|
||||
// ============================ STEP A — DRY-RUN ============================
|
||||
let (report, raw, fp1) = dry_run(expected_coins);
|
||||
|
||||
// The report exposes the migration target + inventory + entitlements + the
|
||||
// provenance fingerprint, WITHOUT touching any store.
|
||||
assert_eq!(report.game, "fifa17");
|
||||
assert_eq!(report.persona_id, PERSONA);
|
||||
assert_eq!(report.persona_name, "CAGE");
|
||||
assert_eq!(report.coins, expected_coins);
|
||||
assert_eq!(report.counts.player_cards, expected_owned);
|
||||
assert!(report.counts.balances(), "item accounting must balance");
|
||||
assert_eq!(report.unopened_pack_ids, [70, 70, 101]);
|
||||
assert!(!report.has_blockers(), "clean fixture has no blockers");
|
||||
assert_eq!(fp1.len(), 16, "FNV-1a-64 fingerprint is 16 hex chars");
|
||||
assert!(fp1.chars().all(|c| c.is_ascii_hexdigit()));
|
||||
|
||||
// Plan the apply (still no writes) and emit the production content pack.
|
||||
let plan = plan_apply(&report, &raw, &fp1).expect("plan apply");
|
||||
assert_eq!(plan.source_fingerprint, fp1);
|
||||
assert_eq!(plan.request.owned.len(), expected_owned);
|
||||
assert_eq!(plan.mappings.len(), expected_owned);
|
||||
assert_eq!(plan.watermark, 100000600);
|
||||
assert_eq!(plan.request.entitlements.len(), expected_packs);
|
||||
|
||||
let emit = emit_content(&report, dir.path(), &fp1).expect("emit content");
|
||||
let pack_ids = content_card_ids(&emit.content_pack).expect("read emitted pack");
|
||||
assert_eq!(pack_ids, expected_card_ids, "emitted pack card ids");
|
||||
|
||||
// The real orchestration gates run against the plan (read-only).
|
||||
assert!(
|
||||
!gate_staging(&plan, false).expect("staging gate"),
|
||||
"zero deferred instances → production-complete, no staging flag"
|
||||
);
|
||||
local_core_preflight(&plan, &pack_ids).expect("local core preflight");
|
||||
|
||||
// Open the disposable temp-FILE Core pool + migrations, and PROVE the
|
||||
// dry-run above mutated nothing: every Core table is empty.
|
||||
let pool = init_pool(&db_url, 1).await.expect("init core pool");
|
||||
run_migrations(&pool).await.expect("migrations");
|
||||
let store = JsonIdentityStore::open(&identity_store_path).expect("open identity store");
|
||||
identity_dry_preflight(&store, &plan).expect("identity dry preflight");
|
||||
for t in CORE_TABLES {
|
||||
assert_eq!(count(&pool, t).await, 0, "dry-run left `{t}` unmutated");
|
||||
}
|
||||
// The dry identity preflight also seeded nothing.
|
||||
assert_eq!(
|
||||
store
|
||||
.external_for(g, k, &owned_item_id(PERSONA, 100000001))
|
||||
.unwrap(),
|
||||
None
|
||||
);
|
||||
|
||||
// ============================ STEP B — APPLY =============================
|
||||
// Idempotently seed the identity mappings + watermark, then run the ONE
|
||||
// generic Core import transaction (via the real JSON contract).
|
||||
seed_identity(&store, &plan).expect("seed identity");
|
||||
let req = to_core_request(&plan);
|
||||
let card_db = {
|
||||
let mut db = CardDb::load(data_dir.to_str().unwrap()).expect("load empty base catalog");
|
||||
db.load_pack(&emit.content_pack)
|
||||
.expect("load production pack");
|
||||
db
|
||||
};
|
||||
let outcome = apply_profile_import(&pool, &card_db, &req)
|
||||
.await
|
||||
.expect("core import");
|
||||
assert_eq!(
|
||||
outcome,
|
||||
ImportOutcome::Imported {
|
||||
owned: expected_owned,
|
||||
squad_slots: expected_squad_slots
|
||||
}
|
||||
);
|
||||
post_validate_identity(&store, &plan).expect("post-validate identity");
|
||||
|
||||
// Exact durable Core state.
|
||||
assert_eq!(count(&pool, "profiles").await, 1);
|
||||
assert_eq!(count(&pool, "clubs").await, 1);
|
||||
assert_eq!(coins(&pool).await, expected_coins, "exact coins");
|
||||
assert_eq!(count(&pool, "owned_cards").await, expected_owned as i64);
|
||||
assert_eq!(count(&pool, "packs").await, expected_packs as i64);
|
||||
let unopened: i64 = sqlx::query_scalar("SELECT COUNT(*) FROM packs WHERE opened = 0")
|
||||
.fetch_one(&pool)
|
||||
.await
|
||||
.unwrap();
|
||||
assert_eq!(unopened, expected_packs as i64, "unopened entitlements");
|
||||
assert_eq!(
|
||||
count(&pool, "squad_players").await,
|
||||
expected_squad_slots as i64
|
||||
);
|
||||
|
||||
// Core content identities + the deterministic opaque OwnedItemIds.
|
||||
assert_eq!(owned_card_ids(&pool).await, expected_card_ids);
|
||||
assert_eq!(
|
||||
owned_item_ids(&pool).await,
|
||||
expected_owned_ids,
|
||||
"Core owned_cards.id == deterministic owned_item_id(persona, wire)"
|
||||
);
|
||||
// The stored provenance/rerun key IS the source fingerprint.
|
||||
let stored_fp: String = sqlx::query_scalar("SELECT import_fingerprint FROM profiles")
|
||||
.fetch_one(&pool)
|
||||
.await
|
||||
.unwrap();
|
||||
assert_eq!(stored_fp, fp1);
|
||||
|
||||
// Identity store: every preserved wire id resolves both directions, and the
|
||||
// watermark is the source allocation floor.
|
||||
for &w in &expected_wires {
|
||||
let core_id = owned_item_id(PERSONA, w);
|
||||
assert_eq!(store.external_for(g, k, &core_id).unwrap(), Some(w));
|
||||
assert_eq!(store.core_for(g, k, w).unwrap(), Some(core_id));
|
||||
}
|
||||
assert_eq!(store.watermark_for(g, k), Some(100000600));
|
||||
|
||||
// ============================ STEP C — RESTART ===========================
|
||||
// Drop the pool, reopen the SAME db file, and re-read identical state.
|
||||
pool.close().await;
|
||||
drop(pool);
|
||||
let pool = init_pool(&db_url, 1).await.expect("reopen core pool");
|
||||
run_migrations(&pool).await.expect("migrations idempotent");
|
||||
assert_eq!(count(&pool, "profiles").await, 1);
|
||||
assert_eq!(coins(&pool).await, expected_coins, "coins survive restart");
|
||||
assert_eq!(count(&pool, "owned_cards").await, expected_owned as i64);
|
||||
assert_eq!(count(&pool, "packs").await, expected_packs as i64);
|
||||
assert_eq!(owned_card_ids(&pool).await, expected_card_ids);
|
||||
assert_eq!(owned_item_ids(&pool).await, expected_owned_ids);
|
||||
|
||||
// Identity store also durable across a reopen.
|
||||
let store = JsonIdentityStore::open(&identity_store_path).expect("reopen identity store");
|
||||
assert_eq!(
|
||||
store
|
||||
.external_for(g, k, &owned_item_id(PERSONA, 100000001))
|
||||
.unwrap(),
|
||||
Some(100000001)
|
||||
);
|
||||
|
||||
// ======================= STEP D — IDEMPOTENT RE-APPLY ====================
|
||||
// Same source (same fingerprint) → recognized as already imported, no dupes.
|
||||
identity_dry_preflight(&store, &plan).expect("re-run identity dry preflight");
|
||||
seed_identity(&store, &plan).expect("re-run identity seed is idempotent");
|
||||
let req_again = to_core_request(&plan);
|
||||
let outcome = apply_profile_import(&pool, &card_db, &req_again)
|
||||
.await
|
||||
.expect("re-apply");
|
||||
assert_eq!(outcome, ImportOutcome::AlreadyImported);
|
||||
assert_eq!(count(&pool, "profiles").await, 1, "no duplicate profile");
|
||||
assert_eq!(coins(&pool).await, expected_coins, "coins NOT doubled");
|
||||
assert_eq!(
|
||||
count(&pool, "owned_cards").await,
|
||||
expected_owned as i64,
|
||||
"no duplicate owned cards"
|
||||
);
|
||||
assert_eq!(
|
||||
count(&pool, "packs").await,
|
||||
expected_packs as i64,
|
||||
"no duplicate entitlements"
|
||||
);
|
||||
|
||||
// ============================ STEP E — CONFLICT ==========================
|
||||
// A MEANINGFUL change (different coins → different snapshot fingerprint) for
|
||||
// the SAME target (game fifa17) must FAIL CLOSED — never a silent merge.
|
||||
let (report2, raw2, fp2) = dry_run(expected_coins + 1);
|
||||
assert_ne!(fp2, fp1, "meaningful change flips the fingerprint");
|
||||
let plan2 = plan_apply(&report2, &raw2, &fp2).expect("plan conflicting apply");
|
||||
let req_conflict = to_core_request(&plan2);
|
||||
let err = apply_profile_import(&pool, &card_db, &req_conflict)
|
||||
.await
|
||||
.expect_err("different fingerprint on imported game must fail closed");
|
||||
let msg = format!("{err:#}");
|
||||
assert!(
|
||||
msg.contains("different source"),
|
||||
"expected explicit conflict, got: {msg}"
|
||||
);
|
||||
|
||||
// The failed conflicting import changed nothing.
|
||||
assert_eq!(count(&pool, "profiles").await, 1);
|
||||
assert_eq!(
|
||||
coins(&pool).await,
|
||||
expected_coins,
|
||||
"conflict left coins intact"
|
||||
);
|
||||
assert_eq!(count(&pool, "owned_cards").await, expected_owned as i64);
|
||||
let stored_fp: String = sqlx::query_scalar("SELECT import_fingerprint FROM profiles")
|
||||
.fetch_one(&pool)
|
||||
.await
|
||||
.unwrap();
|
||||
assert_eq!(stored_fp, fp1, "original fingerprint unchanged");
|
||||
|
||||
pool.close().await;
|
||||
}
|
||||
+1
-1
Submodule openfut-launcher updated: ca7ce267a0...1cd4f18e92
@@ -0,0 +1,18 @@
|
||||
[package]
|
||||
name = "openfut-lsx"
|
||||
version = "0.1.0"
|
||||
edition = "2021"
|
||||
license = "MIT"
|
||||
description = "EA Origin LSX emulator for the FIFA 17 client (loopback 4216)"
|
||||
publish = false
|
||||
|
||||
[dependencies]
|
||||
# AES-128-ECB only. The LSX session cipher is a single fixed-key ECB block operation,
|
||||
# so the block cipher alone is the whole requirement -- no AEAD, no TLS stack. Using
|
||||
# the `aes` crate rather than hand-rolling it keeps the one security-shaped primitive
|
||||
# in reviewed code, while the surrounding framing (PKCS7 pad, lowercase hex,
|
||||
# NUL-terminated) stays explicit here because it is protocol, not cryptography.
|
||||
aes = "0.8"
|
||||
|
||||
# Project rule rs-parking-lot: locks that are immediately unwrapped use parking_lot.
|
||||
parking_lot = "0.12"
|
||||
@@ -0,0 +1,429 @@
|
||||
//! LSX session crypto.
|
||||
//!
|
||||
//! Transcription of the crypto block of `fifa17-recon/tools/lsx_responder_v2.py`,
|
||||
//! which carries the note:
|
||||
//!
|
||||
//! > (verbatim from v1 -- verified end-to-end by decrypting captured
|
||||
//! > captures/lsx/lsx_raw/C1_ENC-IN_*.bin. DO NOT TOUCH.)
|
||||
//!
|
||||
//! So the Python is the specification and this file is a byte-for-byte port. The
|
||||
//! block cipher itself comes from the `aes` crate; the framing around it
|
||||
//! (PKCS7 pad to 16, lowercase hex, NUL terminator) is *protocol*, not
|
||||
//! cryptography, and is therefore spelled out here rather than delegated to a
|
||||
//! mode/padding helper.
|
||||
//!
|
||||
//! Wire recap (reversed from stp-origin_emu.dll @ 0x6ffffc930000):
|
||||
//! handshake: server sends `<Challenge key="...">` in PLAINTEXT; the client
|
||||
//! answers plaintext with `response=`/`key=`; the server answers
|
||||
//! `<ChallengeAccepted response="H">` where
|
||||
//! `H = hex(AES128_ECB(K_FIXED, clientKeyAscii))` + a fixed 3rd block.
|
||||
//! session: every later frame, both directions, Responses AND Events, is
|
||||
//! `hex_lower(AES128_ECB(SESSION_KEY, pkcs7pad16(xml))) + b"\0"`,
|
||||
//! with SESSION_KEY derived from `H` through the MSVCR srand/rand LCG.
|
||||
|
||||
use std::fmt;
|
||||
use std::sync::LazyLock;
|
||||
|
||||
use aes::cipher::generic_array::GenericArray;
|
||||
use aes::cipher::{BlockDecrypt, BlockEncrypt, KeyInit};
|
||||
use aes::Aes128;
|
||||
|
||||
/// A 128-bit LSX key (the fixed handshake key or a derived session key).
|
||||
pub type Key = [u8; 16];
|
||||
|
||||
/// Recovered from stp-origin_emu.dll .rdata @ VA 0x6ffffc935038.
|
||||
/// `bytes(range(16))` == `000102030405060708090a0b0c0d0e0f`.
|
||||
pub const K_FIXED: Key = [
|
||||
0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f,
|
||||
];
|
||||
|
||||
/// Failure modes of the LSX codec. The variants mirror the exceptions the Python
|
||||
/// raises at the same points, because they surface through the same log lines
|
||||
/// (`decrypt fail: ...`, `connection error: ...`).
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub enum CryptoError {
|
||||
/// ECB has no padding of its own: pycryptodome raises ValueError here.
|
||||
NotBlockAligned(usize),
|
||||
/// `bytes.fromhex` rejected the payload.
|
||||
BadHex,
|
||||
/// Nothing before the first NUL, so there is no block to decrypt (the Python
|
||||
/// dies on `raw[-1]` with IndexError).
|
||||
Empty,
|
||||
/// The client's own `response=` carried a 3rd block that is not the emu's
|
||||
/// constant. The Python asserts here on purpose: a future client that
|
||||
/// randomises block 3 must fail LOUDLY, not silently.
|
||||
UnexpectedTail(String),
|
||||
}
|
||||
|
||||
impl fmt::Display for CryptoError {
|
||||
fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
|
||||
match self {
|
||||
// Wording kept close to pycryptodome's so existing log greps still hit.
|
||||
CryptoError::NotBlockAligned(n) => write!(
|
||||
f,
|
||||
"Data must be padded to 16 byte boundary in ECB mode (got {n} bytes)"
|
||||
),
|
||||
CryptoError::BadHex => f.write_str("Non-hexadecimal digit found"),
|
||||
CryptoError::Empty => f.write_str("empty ciphertext"),
|
||||
CryptoError::UnexpectedTail(t) => {
|
||||
write!(f, "unexpected ChallengeResponse tail {t:?}")
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl std::error::Error for CryptoError {}
|
||||
|
||||
/// MSVCR120 `srand`/`rand` LCG (verified: `srand(7); rand() == 61`).
|
||||
pub struct MsvcrRand {
|
||||
state: u32,
|
||||
}
|
||||
|
||||
impl MsvcrRand {
|
||||
/// `srand(seed)`.
|
||||
pub fn new(seed: u32) -> Self {
|
||||
Self { state: seed }
|
||||
}
|
||||
|
||||
/// `rand()` -- 15 bits, exactly as MSVCR120 returns them.
|
||||
pub fn next_u15(&mut self) -> u16 {
|
||||
self.state = self.state.wrapping_mul(214013).wrapping_add(2531011);
|
||||
((self.state >> 16) & 0x7FFF) as u16
|
||||
}
|
||||
}
|
||||
|
||||
/// Reimplementation of emu `sub_0x6ffffc931f10` tail (0x9320bf-0x932101).
|
||||
///
|
||||
/// ```text
|
||||
/// srand(7); r0 = rand() -> r0 == 61
|
||||
/// bx = (u16)((resp[0] << 8) + resp[1]) (16-bit wrap)
|
||||
/// srand(bx + r0)
|
||||
/// key[i] = (uint8_t)rand() for i in 0..15
|
||||
/// ```
|
||||
///
|
||||
/// `resp[0]`/`resp[1]` are the first two ASCII *characters* of the hex response,
|
||||
/// not the first decoded byte.
|
||||
pub fn derive_session_key(resp_hex: &str) -> Key {
|
||||
let r0 = u32::from(MsvcrRand::new(7).next_u15()); // == 61
|
||||
let b = resp_hex.as_bytes();
|
||||
assert!(
|
||||
b.len() >= 2,
|
||||
"derive_session_key needs the first two response chars, got {:?}",
|
||||
resp_hex
|
||||
);
|
||||
let bx = ((u32::from(b[0]) << 8) + u32::from(b[1])) & 0xFFFF;
|
||||
let mut g = MsvcrRand::new(bx.wrapping_add(r0));
|
||||
let mut key = [0u8; 16];
|
||||
for byte in key.iter_mut() {
|
||||
*byte = (g.next_u15() & 0xFF) as u8;
|
||||
}
|
||||
key
|
||||
}
|
||||
|
||||
/// `AES128-ECB(K_FIXED, 0x10 * 16)` -- the constant the emu appends as the 3rd
|
||||
/// hex block (== the PKCS7 pad block of an aligned 32-byte key). See
|
||||
/// REPACK_INTEL.md sec.0-B.
|
||||
pub fn tail_const() -> &'static str {
|
||||
static TAIL: LazyLock<String> = LazyLock::new(|| {
|
||||
let mut block = [0x10u8; 16];
|
||||
ecb_encrypt_blocks(&K_FIXED, &mut block);
|
||||
hex_lower(&block)
|
||||
});
|
||||
TAIL.as_str()
|
||||
}
|
||||
|
||||
/// Emu-exact `ChallengeAccepted.response` (stp-origin_emu.dll 0x180001f10).
|
||||
///
|
||||
/// The emu computes only TWO AES blocks from the 32-ASCII client key, then
|
||||
/// `strcat_s`'s the client's OWN `response[64:]` verbatim (@0x1800020a9) -> 96
|
||||
/// hex. The older 3-block PKCS7 form is numerically identical *while the client
|
||||
/// PKCS7-pads its 3rd block* (REPACK_INTEL.md sec.0-A/0-B, workflow-confirmed
|
||||
/// byte-exact). We reproduce the emu exactly and, when the client's `response=`
|
||||
/// is available, echo its tail and assert the constant so a future client that
|
||||
/// randomises block 3 fails LOUDLY instead of silently.
|
||||
pub fn challenge_response(
|
||||
client_key_ascii: &str,
|
||||
client_response_attr: &str,
|
||||
) -> Result<String, CryptoError> {
|
||||
let mut buf = client_key_ascii.as_bytes().to_vec();
|
||||
if buf.is_empty() || buf.len() % 16 != 0 {
|
||||
// ECB cannot pad: the Python's AES.encrypt raises here too.
|
||||
return Err(CryptoError::NotBlockAligned(buf.len()));
|
||||
}
|
||||
ecb_encrypt_blocks(&K_FIXED, &mut buf);
|
||||
let two = hex_lower(&buf);
|
||||
|
||||
// Python slices `client_response_attr[64:]`, i.e. by characters.
|
||||
if let Some((idx, _)) = client_response_attr.char_indices().nth(64) {
|
||||
let tail = &client_response_attr[idx..];
|
||||
if tail != tail_const() {
|
||||
return Err(CryptoError::UnexpectedTail(tail.to_string()));
|
||||
}
|
||||
return Ok(two + tail);
|
||||
}
|
||||
if client_response_attr.chars().count() == 64 {
|
||||
// len(attr) >= 64 with an empty tail: the assert compares "" against the
|
||||
// constant and fails, exactly as it would here.
|
||||
return Err(CryptoError::UnexpectedTail(String::new()));
|
||||
}
|
||||
Ok(two + tail_const())
|
||||
}
|
||||
|
||||
/// pkcs7-pad to 16, AES-128-ECB, lowercase hex, NUL-terminated.
|
||||
pub fn lsx_encrypt(xml: &str, key: &Key) -> Vec<u8> {
|
||||
let body = xml.as_bytes();
|
||||
let pad = 16 - (body.len() % 16); // emu always pads (pad==16 when aligned)
|
||||
let mut buf = Vec::with_capacity(body.len() + pad);
|
||||
buf.extend_from_slice(body);
|
||||
buf.resize(body.len() + pad, pad as u8);
|
||||
ecb_encrypt_blocks(key, &mut buf);
|
||||
|
||||
// hex + NUL, sized up front: this runs on every frame we ever send.
|
||||
let mut out = Vec::with_capacity(buf.len() * 2 + 1);
|
||||
for b in &buf {
|
||||
out.push(HEX_DIGITS[usize::from(*b >> 4)]);
|
||||
out.push(HEX_DIGITS[usize::from(*b & 0x0f)]);
|
||||
}
|
||||
out.push(0);
|
||||
out
|
||||
}
|
||||
|
||||
/// Hex up to the first NUL, decrypt, then take up to the first NUL of the
|
||||
/// plaintext (the PKCS7 tail is stripped when it is well-formed, matching the
|
||||
/// Python's tolerant check).
|
||||
pub fn lsx_decrypt(data: &[u8], key: &Key) -> Result<String, CryptoError> {
|
||||
let head = match data.iter().position(|b| *b == 0) {
|
||||
Some(i) => &data[..i],
|
||||
None => data,
|
||||
};
|
||||
let mut raw = hex_decode(trim_ascii_ws(head))?;
|
||||
if raw.is_empty() {
|
||||
return Err(CryptoError::Empty);
|
||||
}
|
||||
if raw.len() % 16 != 0 {
|
||||
return Err(CryptoError::NotBlockAligned(raw.len()));
|
||||
}
|
||||
ecb_decrypt_blocks(key, &mut raw);
|
||||
|
||||
let pad = usize::from(raw[raw.len() - 1]);
|
||||
if pad > 0 && pad <= 16 && raw[raw.len() - pad..].iter().all(|c| usize::from(*c) == pad) {
|
||||
raw.truncate(raw.len() - pad);
|
||||
}
|
||||
if let Some(i) = raw.iter().position(|b| *b == 0) {
|
||||
raw.truncate(i);
|
||||
}
|
||||
// Python decodes with errors="replace".
|
||||
Ok(String::from_utf8_lossy(&raw).into_owned())
|
||||
}
|
||||
|
||||
const HEX_DIGITS: [u8; 16] = *b"0123456789abcdef";
|
||||
|
||||
/// Lowercase hex, like `bytes.hex()`.
|
||||
pub fn hex_lower(bytes: &[u8]) -> String {
|
||||
let mut s = String::with_capacity(bytes.len() * 2);
|
||||
for b in bytes {
|
||||
s.push(char::from(HEX_DIGITS[usize::from(*b >> 4)]));
|
||||
s.push(char::from(HEX_DIGITS[usize::from(*b & 0x0f)]));
|
||||
}
|
||||
s
|
||||
}
|
||||
|
||||
/// `bytes.fromhex`: ASCII whitespace between bytes is skipped, everything else
|
||||
/// must be a hex digit pair.
|
||||
fn hex_decode(s: &[u8]) -> Result<Vec<u8>, CryptoError> {
|
||||
let mut out = Vec::with_capacity(s.len() / 2);
|
||||
let mut hi: Option<u8> = None;
|
||||
for c in s {
|
||||
if c.is_ascii_whitespace() {
|
||||
continue;
|
||||
}
|
||||
let nib = match c {
|
||||
b'0'..=b'9' => c - b'0',
|
||||
b'a'..=b'f' => c - b'a' + 10,
|
||||
b'A'..=b'F' => c - b'A' + 10,
|
||||
_ => return Err(CryptoError::BadHex),
|
||||
};
|
||||
match hi.take() {
|
||||
None => hi = Some(nib),
|
||||
Some(h) => out.push((h << 4) | nib),
|
||||
}
|
||||
}
|
||||
if hi.is_some() {
|
||||
return Err(CryptoError::BadHex);
|
||||
}
|
||||
Ok(out)
|
||||
}
|
||||
|
||||
/// `bytes.strip()` -- ASCII whitespace at both ends.
|
||||
fn trim_ascii_ws(mut b: &[u8]) -> &[u8] {
|
||||
while let Some((first, rest)) = b.split_first() {
|
||||
if first.is_ascii_whitespace() {
|
||||
b = rest;
|
||||
} else {
|
||||
break;
|
||||
}
|
||||
}
|
||||
while let Some((last, rest)) = b.split_last() {
|
||||
if last.is_ascii_whitespace() {
|
||||
b = rest;
|
||||
} else {
|
||||
break;
|
||||
}
|
||||
}
|
||||
b
|
||||
}
|
||||
|
||||
fn ecb_encrypt_blocks(key: &Key, buf: &mut [u8]) {
|
||||
debug_assert_eq!(buf.len() % 16, 0);
|
||||
let cipher = Aes128::new(GenericArray::from_slice(key));
|
||||
for block in buf.chunks_exact_mut(16) {
|
||||
cipher.encrypt_block(GenericArray::from_mut_slice(block));
|
||||
}
|
||||
}
|
||||
|
||||
fn ecb_decrypt_blocks(key: &Key, buf: &mut [u8]) {
|
||||
debug_assert_eq!(buf.len() % 16, 0);
|
||||
let cipher = Aes128::new(GenericArray::from_slice(key));
|
||||
for block in buf.chunks_exact_mut(16) {
|
||||
cipher.decrypt_block(GenericArray::from_mut_slice(block));
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
/// The captured client key from the 2026-07-30 session the Python's own
|
||||
/// selftest pins.
|
||||
const CAPTURED_CLIENT_KEY: &str = "18a70055a3541fb27ab8e0f47afad18c";
|
||||
const CAPTURED_H: &str = concat!(
|
||||
"e4f5166209929e156a2ca47b81cdd6bf",
|
||||
"6f2a20371532ed4f968c5a9274899dbf",
|
||||
"954f64f2e4e86e9eee82d20216684899"
|
||||
);
|
||||
const CAPTURED_SESSION_KEY: &str = "6a9da3e78615153cc2f10eec25ae6382";
|
||||
|
||||
#[test]
|
||||
fn msvcr_srand7_first_rand_is_61() {
|
||||
// The one vector the Python names in its docstring.
|
||||
assert_eq!(MsvcrRand::new(7).next_u15(), 61);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn tail_const_is_the_emu_constant() {
|
||||
// AES128-ECB(K_FIXED, 0x10*16), pinned so a cipher/keying regression is
|
||||
// caught without a live client.
|
||||
assert_eq!(tail_const(), "954f64f2e4e86e9eee82d20216684899");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn k_fixed_is_000102_to_0f() {
|
||||
assert_eq!(hex_lower(&K_FIXED), "000102030405060708090a0b0c0d0e0f");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn challenge_response_matches_captured_session() {
|
||||
let h = challenge_response(CAPTURED_CLIENT_KEY, "").unwrap();
|
||||
assert!(h.starts_with("e4f5166209929e15"), "{h}");
|
||||
assert_eq!(h, CAPTURED_H);
|
||||
assert_eq!(h.len(), 96);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn challenge_response_echoes_the_clients_own_tail() {
|
||||
// The emu strcat_s's response[64:] verbatim; identical result while the
|
||||
// client pads block 3 with the constant.
|
||||
let h = challenge_response(CAPTURED_CLIENT_KEY, CAPTURED_H).unwrap();
|
||||
assert_eq!(h, CAPTURED_H);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn challenge_response_rejects_a_randomised_third_block() {
|
||||
let bogus = format!("{}{}", &CAPTURED_H[..64], "00".repeat(16));
|
||||
let err = challenge_response(CAPTURED_CLIENT_KEY, &bogus).unwrap_err();
|
||||
assert_eq!(err, CryptoError::UnexpectedTail("00".repeat(16)));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn challenge_response_rejects_unaligned_client_key() {
|
||||
let err = challenge_response("short", "").unwrap_err();
|
||||
assert_eq!(err, CryptoError::NotBlockAligned(5));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn session_key_derives_from_the_response() {
|
||||
let k = derive_session_key(CAPTURED_H);
|
||||
assert_eq!(hex_lower(&k), CAPTURED_SESSION_KEY);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn encrypt_pins_the_first_login_frame() {
|
||||
let k = derive_session_key(CAPTURED_H);
|
||||
let frame = r#"<LSX><Event sender=""><Login IsLoggedIn="true"/></Event></LSX>"#;
|
||||
let out = lsx_encrypt(frame, &k);
|
||||
assert_eq!(*out.last().unwrap(), 0, "frames are NUL-terminated");
|
||||
// Pinned against `openssl enc -aes-128-ecb -nopad` over the PKCS7-padded
|
||||
// frame under the captured session key: 62 bytes of XML -> pad 2 -> 4 blocks.
|
||||
assert_eq!(
|
||||
std::str::from_utf8(&out[..out.len() - 1]).unwrap(),
|
||||
concat!(
|
||||
"ded1180ab8a2ab85b7408cc009eb0191",
|
||||
"00b7b4c827fe0b9b4de2ca7834b3ed51",
|
||||
"31a0714a8eb66ba3e38d1855724b0a48",
|
||||
"09ad8616e71b3a78880c570c9af7ff80"
|
||||
)
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn round_trip() {
|
||||
let k = derive_session_key(CAPTURED_H);
|
||||
for xml in [
|
||||
r#"<LSX><Response id="1" sender=""><ErrorSuccess Code="0" Description=""/></Response></LSX>"#,
|
||||
r#"<LSX><Event sender="LOGIN_EVENT"><Login IsLoggedIn="true"/></Event></LSX>"#,
|
||||
"",
|
||||
] {
|
||||
assert_eq!(lsx_decrypt(&lsx_encrypt(xml, &k), &k).unwrap(), xml);
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn round_trip_of_block_aligned_plaintext_pads_a_whole_block() {
|
||||
let k = derive_session_key(CAPTURED_H);
|
||||
let xml = "0123456789abcdef"; // exactly 16 bytes
|
||||
let enc = lsx_encrypt(xml, &k);
|
||||
// 2 blocks (16 data + 16 pad) -> 64 hex chars + NUL.
|
||||
assert_eq!(enc.len(), 65);
|
||||
assert_eq!(lsx_decrypt(&enc, &k).unwrap(), xml);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn decrypt_ignores_everything_past_the_first_nul() {
|
||||
let k = derive_session_key(CAPTURED_H);
|
||||
let mut enc = lsx_encrypt("<LSX/>", &k);
|
||||
enc.extend_from_slice(b"deadbeef\0trailing");
|
||||
assert_eq!(lsx_decrypt(&enc, &k).unwrap(), "<LSX/>");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn decrypt_strips_surrounding_whitespace() {
|
||||
let k = derive_session_key(CAPTURED_H);
|
||||
let enc = lsx_encrypt("<LSX/>", &k);
|
||||
let mut padded = b" ".to_vec();
|
||||
padded.extend_from_slice(&enc[..enc.len() - 1]);
|
||||
padded.extend_from_slice(b"\r\n\0");
|
||||
assert_eq!(lsx_decrypt(&padded, &k).unwrap(), "<LSX/>");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn decrypt_rejects_garbage() {
|
||||
let k = derive_session_key(CAPTURED_H);
|
||||
assert_eq!(lsx_decrypt(b"zz\0", &k).unwrap_err(), CryptoError::BadHex);
|
||||
assert_eq!(lsx_decrypt(b"abc\0", &k).unwrap_err(), CryptoError::BadHex);
|
||||
assert_eq!(lsx_decrypt(b"\0", &k).unwrap_err(), CryptoError::Empty);
|
||||
assert_eq!(
|
||||
lsx_decrypt(b"00112233\0", &k).unwrap_err(),
|
||||
CryptoError::NotBlockAligned(4)
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,356 @@
|
||||
//! PUSHED EVENTS -- the whole reason v2 exists, plus the per-connection state
|
||||
//! they need.
|
||||
//!
|
||||
//! Frame shape is identical to the server-initiated `<Challenge>` that already
|
||||
//! works, i.e. `<LSX><Event sender="..."><Element .../></Event></LSX>`. No `id`
|
||||
//! attribute (the Challenge has none; the matcher never reads one).
|
||||
|
||||
use std::io::{self, Write};
|
||||
use std::net::{SocketAddr, TcpStream};
|
||||
use std::sync::atomic::{AtomicBool, Ordering};
|
||||
use std::sync::Arc;
|
||||
use std::time::Duration;
|
||||
|
||||
use parking_lot::{Mutex, RwLock};
|
||||
|
||||
use crate::crypto::{self, Key};
|
||||
use crate::{env_flag, log, ConfigError, Env};
|
||||
|
||||
/// `sender` is strcmp'd against the handler's registered service name. A mismatch
|
||||
/// is SILENTLY DROPPED -- it costs us nothing -- so we emit every candidate.
|
||||
///
|
||||
/// Event handlers are keyed on `serviceNames[facility]` (registrar 0x14710df80);
|
||||
/// with our empty GetConfigResponse those names are "", so the handlers expect
|
||||
/// `sender=""`. "" first; the named variants are harmless no-ops (dropped
|
||||
/// silently) and become correct once GetConfigResponse populates the table.
|
||||
/// "LOGIN_EVENT" is table index 14 (the one the event-handler factory uses) and
|
||||
/// "LOGIN" is index 8 (the plain service name); exactly one of the three will
|
||||
/// match.
|
||||
pub const LOGIN_EVENT_SENDERS: [&str; 3] = ["", "LOGIN_EVENT", "LOGIN"];
|
||||
pub const ONLINE_EVENT_SENDERS: [&str; 2] = ["", "ONLINE_STATUS_EVENT"];
|
||||
|
||||
pub fn event(sender: &str, element: &str) -> String {
|
||||
format!(r#"<LSX><Event sender="{sender}"><{element}/></Event></LSX>"#)
|
||||
}
|
||||
|
||||
/// The frames that flip `OriginMgr.m_isLoggedIn` ([OriginMgr+0x13]) to 1.
|
||||
///
|
||||
/// `IsLoggedIn` is parsed as `strcmp(v,"false") != 0`, so "true" -> TRUE. Keep the
|
||||
/// value literally "true" anyway: it is what a real Origin client sends and it
|
||||
/// keeps the log readable.
|
||||
pub fn login_event_frames() -> Vec<String> {
|
||||
let mut out = Vec::with_capacity(LOGIN_EVENT_SENDERS.len() + ONLINE_EVENT_SENDERS.len());
|
||||
out.extend(LOGIN_EVENT_SENDERS.iter().map(|s| event(s, r#"Login IsLoggedIn="true""#)));
|
||||
out.extend(
|
||||
ONLINE_EVENT_SENDERS
|
||||
.iter()
|
||||
.map(|s| event(s, r#"OnlineStatusEvent isOnline="true""#)),
|
||||
);
|
||||
out
|
||||
}
|
||||
|
||||
/// Event tuning.
|
||||
///
|
||||
/// Pushes are idempotent state notifications, so re-sending is harmless and is
|
||||
/// cheap insurance against FIFA registering its `<Login>` handler later than our
|
||||
/// first push. Set `OPENFUT_LSX_EVENTS=0` to fall back to v1 behaviour (useful as
|
||||
/// an A/B control if you want to prove the events are what moved the needle).
|
||||
#[derive(Debug, Clone, PartialEq)]
|
||||
pub struct EventConfig {
|
||||
/// `OPENFUT_LSX_EVENTS != "0"` (default on).
|
||||
pub enabled: bool,
|
||||
/// `OPENFUT_LSX_EVENT_PERIOD` seconds (default 5).
|
||||
pub period_secs: f64,
|
||||
/// `OPENFUT_LSX_EVENT_COUNT` heartbeat repeats (default 24).
|
||||
pub count: i64,
|
||||
/// EXPERIMENT (`OPENFUT_LSX_LOGIN_PLAINTEXT`, default off): push the Login
|
||||
/// Event in PLAINTEXT right after ChallengeAccepted (before the stream goes
|
||||
/// encrypted) instead of via the encrypted heartbeat. Tests the workflow's
|
||||
/// strongest remaining hypothesis -- that FIFA drops encrypted mid-session
|
||||
/// Events (the emu's only Event, the Challenge, is plaintext and pre-key).
|
||||
/// See REPACK_INTEL.md sec.4 step 2.
|
||||
pub login_plaintext: bool,
|
||||
}
|
||||
|
||||
impl Default for EventConfig {
|
||||
fn default() -> Self {
|
||||
Self {
|
||||
enabled: true,
|
||||
period_secs: 5.0,
|
||||
count: 24,
|
||||
login_plaintext: false,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl EventConfig {
|
||||
pub fn from_env() -> Result<Self, ConfigError> {
|
||||
Self::from_vars(&crate::os_env)
|
||||
}
|
||||
|
||||
pub fn from_vars(env: Env<'_>) -> Result<Self, ConfigError> {
|
||||
let period_secs = match env("OPENFUT_LSX_EVENT_PERIOD") {
|
||||
Some(v) => v.trim().parse::<f64>().map_err(|_| ConfigError {
|
||||
var: "OPENFUT_LSX_EVENT_PERIOD",
|
||||
value: v.clone(),
|
||||
expected: "a number of seconds",
|
||||
})?,
|
||||
None => 5.0,
|
||||
};
|
||||
let count = match env("OPENFUT_LSX_EVENT_COUNT") {
|
||||
Some(v) => v.trim().parse::<i64>().map_err(|_| ConfigError {
|
||||
var: "OPENFUT_LSX_EVENT_COUNT",
|
||||
value: v.clone(),
|
||||
expected: "an integer",
|
||||
})?,
|
||||
None => 24,
|
||||
};
|
||||
Ok(Self {
|
||||
enabled: env_flag(env, "OPENFUT_LSX_EVENTS", true),
|
||||
period_secs,
|
||||
count,
|
||||
login_plaintext: env_flag(env, "OPENFUT_LSX_LOGIN_PLAINTEXT", false),
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
/// Render a period the way Python's `float` repr does, so the startup line reads
|
||||
/// `period=5.0s` and not `period=5s`.
|
||||
pub fn fmt_secs(secs: f64) -> String {
|
||||
if secs.is_finite() && secs.fract() == 0.0 && secs.abs() < 1e16 {
|
||||
format!("{secs:.1}")
|
||||
} else {
|
||||
format!("{secs}")
|
||||
}
|
||||
}
|
||||
|
||||
/// Socket + session key + a send lock.
|
||||
///
|
||||
/// The lock matters: pushes come from a heartbeat thread while the request loop
|
||||
/// may be writing a Response. LSX frames are NUL-delimited, so two interleaved
|
||||
/// writes would corrupt the stream and the client would drop the connection
|
||||
/// (which would look exactly like a protocol bug).
|
||||
pub struct Conn {
|
||||
pub peer: SocketAddr,
|
||||
/// A `try_clone` of the accepted socket: the request loop reads from the
|
||||
/// original while this half is serialised behind the send lock.
|
||||
writer: Mutex<TcpStream>,
|
||||
key: RwLock<Option<Key>>,
|
||||
alive: AtomicBool,
|
||||
pushed_login: AtomicBool,
|
||||
/// Set once GetAuthCode has been issued, so the heartbeat stops re-pushing
|
||||
/// Login/OnlineStatus events. Re-pushing after the auth code is granted
|
||||
/// re-enters FIFA's state-mutating Origin event dispatcher (case 2
|
||||
/// @0x146f1e0ab sets m_isLoggedIn + clears loginError + rebroadcasts on the FE
|
||||
/// bus) ~24 more times DURING Blaze login, which we do not want.
|
||||
stop_events: AtomicBool,
|
||||
events: EventConfig,
|
||||
}
|
||||
|
||||
impl Conn {
|
||||
pub fn new(sock: &TcpStream, peer: SocketAddr, events: EventConfig) -> io::Result<Arc<Self>> {
|
||||
Ok(Arc::new(Self {
|
||||
peer,
|
||||
writer: Mutex::new(sock.try_clone()?),
|
||||
key: RwLock::new(None),
|
||||
alive: AtomicBool::new(true),
|
||||
pushed_login: AtomicBool::new(false),
|
||||
stop_events: AtomicBool::new(false),
|
||||
events,
|
||||
}))
|
||||
}
|
||||
|
||||
pub fn events(&self) -> &EventConfig {
|
||||
&self.events
|
||||
}
|
||||
|
||||
pub fn set_key(&self, key: Key) {
|
||||
*self.key.write() = Some(key);
|
||||
}
|
||||
|
||||
pub fn key(&self) -> Option<Key> {
|
||||
*self.key.read()
|
||||
}
|
||||
|
||||
// These flags are advisory hand-offs between the request loop and the
|
||||
// heartbeat thread; no data travels with them, so Relaxed is enough.
|
||||
pub fn is_alive(&self) -> bool {
|
||||
self.alive.load(Ordering::Relaxed)
|
||||
}
|
||||
|
||||
pub fn mark_dead(&self) {
|
||||
self.alive.store(false, Ordering::Relaxed);
|
||||
}
|
||||
|
||||
pub fn stop_events(&self) {
|
||||
self.stop_events.store(true, Ordering::Relaxed);
|
||||
}
|
||||
|
||||
pub fn events_stopped(&self) -> bool {
|
||||
self.stop_events.load(Ordering::Relaxed)
|
||||
}
|
||||
|
||||
pub fn send_plain(&self, xml: &str) -> io::Result<()> {
|
||||
let mut buf = Vec::with_capacity(xml.len() + 1);
|
||||
buf.extend_from_slice(xml.as_bytes());
|
||||
buf.push(0);
|
||||
self.writer.lock().write_all(&buf)
|
||||
}
|
||||
|
||||
pub fn send_enc(&self, xml: &str) -> io::Result<()> {
|
||||
let key = self
|
||||
.key()
|
||||
.ok_or_else(|| io::Error::other("session key not initialised"))?;
|
||||
let frame = crypto::lsx_encrypt(xml, &key);
|
||||
self.writer.lock().write_all(&frame)
|
||||
}
|
||||
|
||||
pub fn push_login_state(&self, why: &str) {
|
||||
if !self.events.enabled {
|
||||
return;
|
||||
}
|
||||
for frame in login_event_frames() {
|
||||
if let Err(e) = self.send_enc(&frame) {
|
||||
self.mark_dead();
|
||||
log!("push failed: {e}");
|
||||
return;
|
||||
}
|
||||
log!("PUSH ({why}) >> {frame}");
|
||||
}
|
||||
if !self.pushed_login.swap(true, Ordering::Relaxed) {
|
||||
log!(
|
||||
"*** first <Login IsLoggedIn=\"true\"> pushed. Watch for \
|
||||
GetAuthCode next. ***"
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
/// Re-push the login state a bounded number of times.
|
||||
///
|
||||
/// FIFA builds its Origin event handlers lazily; if our first push lands
|
||||
/// before the `<Login>` handler is registered the matcher simply finds no
|
||||
/// handler and drops it. Re-pushing removes that race without needing to
|
||||
/// guess the exact registration moment.
|
||||
pub fn heartbeat(&self) {
|
||||
let period = match Duration::try_from_secs_f64(self.events.period_secs) {
|
||||
Ok(d) => d,
|
||||
Err(e) => {
|
||||
// Python's time.sleep() would raise here and kill just this
|
||||
// thread; the connection keeps serving requests either way.
|
||||
log!(
|
||||
"heartbeat disabled: OPENFUT_LSX_EVENT_PERIOD={} is not a usable delay ({e})",
|
||||
self.events.period_secs
|
||||
);
|
||||
return;
|
||||
}
|
||||
};
|
||||
for _ in 0..self.events.count.max(0) {
|
||||
std::thread::sleep(period);
|
||||
if !self.is_alive() || self.events_stopped() {
|
||||
return;
|
||||
}
|
||||
self.push_login_state("heartbeat");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
use crate::crypto::{derive_session_key, lsx_decrypt, lsx_encrypt};
|
||||
use std::collections::HashMap;
|
||||
|
||||
fn env_of(pairs: &[(&str, &str)]) -> impl Fn(&str) -> Option<String> {
|
||||
let map: HashMap<String, String> = pairs
|
||||
.iter()
|
||||
.map(|(k, v)| ((*k).to_string(), (*v).to_string()))
|
||||
.collect();
|
||||
move |k: &str| map.get(k).cloned()
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn frames_are_the_five_candidate_pushes_with_the_empty_sender_first() {
|
||||
let frames = login_event_frames();
|
||||
assert_eq!(
|
||||
frames.len(),
|
||||
LOGIN_EVENT_SENDERS.len() + ONLINE_EVENT_SENDERS.len()
|
||||
);
|
||||
assert_eq!(
|
||||
frames,
|
||||
vec![
|
||||
r#"<LSX><Event sender=""><Login IsLoggedIn="true"/></Event></LSX>"#,
|
||||
r#"<LSX><Event sender="LOGIN_EVENT"><Login IsLoggedIn="true"/></Event></LSX>"#,
|
||||
r#"<LSX><Event sender="LOGIN"><Login IsLoggedIn="true"/></Event></LSX>"#,
|
||||
r#"<LSX><Event sender=""><OnlineStatusEvent isOnline="true"/></Event></LSX>"#,
|
||||
r#"<LSX><Event sender="ONLINE_STATUS_EVENT"><OnlineStatusEvent isOnline="true"/></Event></LSX>"#,
|
||||
]
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn frames_round_trip_through_the_session_codec() {
|
||||
let k = derive_session_key(&crate::crypto::challenge_response(
|
||||
"18a70055a3541fb27ab8e0f47afad18c",
|
||||
"",
|
||||
)
|
||||
.unwrap());
|
||||
for f in login_event_frames() {
|
||||
assert_eq!(lsx_decrypt(&lsx_encrypt(&f, &k), &k).unwrap(), f);
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn defaults_match_the_python() {
|
||||
let cfg = EventConfig::from_vars(&env_of(&[])).unwrap();
|
||||
assert_eq!(cfg, EventConfig::default());
|
||||
assert!(cfg.enabled);
|
||||
assert_eq!(cfg.period_secs, 5.0);
|
||||
assert_eq!(cfg.count, 24);
|
||||
assert!(!cfg.login_plaintext);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn events_are_disabled_only_by_the_literal_zero() {
|
||||
for (value, enabled) in [("0", false), ("1", true), ("", true), ("false", true)] {
|
||||
let cfg = EventConfig::from_vars(&env_of(&[("OPENFUT_LSX_EVENTS", value)])).unwrap();
|
||||
assert_eq!(cfg.enabled, enabled, "OPENFUT_LSX_EVENTS={value:?}");
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn login_plaintext_is_enabled_by_anything_but_zero() {
|
||||
for (value, on) in [("0", false), ("1", true), ("", true), ("no", true)] {
|
||||
let cfg =
|
||||
EventConfig::from_vars(&env_of(&[("OPENFUT_LSX_LOGIN_PLAINTEXT", value)])).unwrap();
|
||||
assert_eq!(cfg.login_plaintext, on, "OPENFUT_LSX_LOGIN_PLAINTEXT={value:?}");
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn period_and_count_are_overridable() {
|
||||
let cfg = EventConfig::from_vars(&env_of(&[
|
||||
("OPENFUT_LSX_EVENT_PERIOD", "0.25"),
|
||||
("OPENFUT_LSX_EVENT_COUNT", "3"),
|
||||
]))
|
||||
.unwrap();
|
||||
assert_eq!(cfg.period_secs, 0.25);
|
||||
assert_eq!(cfg.count, 3);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn bad_period_is_refused() {
|
||||
let err = EventConfig::from_vars(&env_of(&[("OPENFUT_LSX_EVENT_PERIOD", "soon")]))
|
||||
.unwrap_err();
|
||||
assert_eq!(err.var, "OPENFUT_LSX_EVENT_PERIOD");
|
||||
let err =
|
||||
EventConfig::from_vars(&env_of(&[("OPENFUT_LSX_EVENT_COUNT", "many")])).unwrap_err();
|
||||
assert_eq!(err.var, "OPENFUT_LSX_EVENT_COUNT");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn period_renders_like_a_python_float() {
|
||||
assert_eq!(fmt_secs(5.0), "5.0");
|
||||
assert_eq!(fmt_secs(0.25), "0.25");
|
||||
assert_eq!(fmt_secs(0.0), "0.0");
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,158 @@
|
||||
//! The identity LSX reports, ported from `fut_account.py`'s tier-1/tier-2 fields.
|
||||
//!
|
||||
//! SOURCED FROM `fut_account.ACCOUNT`, shared with blaze_responder_v3b.py,
|
||||
//! fut_store.py, fut_seed.py and utas_server.py.
|
||||
//!
|
||||
//! THE CONSTRAINT IS CROSS-LAYER CONSISTENCY, NOT ANY PARTICULAR VALUE: what LSX
|
||||
//! reports here must equal what Blaze returns in LoginResponse.SESS.PDTL and what
|
||||
//! UTAS serves as userInfo.personaId. (An older comment blamed a mismatch for
|
||||
//! AUTH_ERR_INVALID_PERSONA / AUTH_ERR_USER_DOES_NOT_MATCH_PERSONA /
|
||||
//! AUTH_ERR_PERSONA_NOT_FOUND -- those are Blaze *server* error codes and we are
|
||||
//! the server. Neither "CAGE" nor "33068179" appears in FIFA17.exe, CardsDLL or
|
||||
//! dbdata.dll; 33068179 lives only in stp-origin_emu.dll's own ini default. They
|
||||
//! stay the defaults because they are what the working stack asserts.)
|
||||
//!
|
||||
//! PRECEDENCE: env var > built-in default.
|
||||
//!
|
||||
//! `fut_account.py` sits one tier deeper -- env > `fut_account.json` > default --
|
||||
//! but the JSON is deliberately NOT read here: its persisted values for the three
|
||||
//! fields LSX uses (`persona_id`, `persona_name`; `locale` is not even stored) are
|
||||
//! identical to the built-in defaults, and the launcher always passes
|
||||
//! `FUT_PERSONA_ID`/`FUT_PERSONA_NAME` explicitly when it spawns us
|
||||
//! (openfut-launcher/src/local_services.rs), so env decides in every real run.
|
||||
//! Parsing a JSON file to reach the same answer would only add a failure mode --
|
||||
//! and the launcher, not a file next to the Python tools, is the identity owner
|
||||
//! for this binary.
|
||||
|
||||
use crate::{ConfigError, Env};
|
||||
|
||||
// ------------------------------------------------------------------ tier 1
|
||||
// LOCKED WIRE CONSTANTS. No env override on purpose: these are not preferences.
|
||||
|
||||
/// FIFA 17 EA offer id (retail).
|
||||
pub const CONTENT_ID: &str = "1027460";
|
||||
|
||||
/// `TRIAL_ONLINE_ACCESS` for FIFA17_Trial.exe; retail uses this.
|
||||
pub const ENTITLEMENT_TAG: &str = "ONLINE_ACCESS";
|
||||
|
||||
// ------------------------------------------------------------------ tier 2
|
||||
pub const DEFAULT_PERSONA_ID: i64 = 33068179;
|
||||
pub const DEFAULT_PERSONA_NAME: &str = "CAGE";
|
||||
pub const DEFAULT_LOCALE: &str = "en_US";
|
||||
|
||||
/// The identity fields LSX puts on the wire.
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub struct Identity {
|
||||
/// Blaze SESS.BUID / SESS.UID / PDTL.PID, LSX PersonaId/UserId, UTAS
|
||||
/// userInfo.personaId and squad.personaId.
|
||||
pub persona_id: i64,
|
||||
/// Blaze PDTL.DSNM / LSX GetProfileResponse Persona / UTAS sellerName.
|
||||
pub persona_name: String,
|
||||
/// LSX `GetSetting LANGUAGE`.
|
||||
pub locale: String,
|
||||
}
|
||||
|
||||
impl Default for Identity {
|
||||
fn default() -> Self {
|
||||
Self {
|
||||
persona_id: DEFAULT_PERSONA_ID,
|
||||
persona_name: DEFAULT_PERSONA_NAME.to_string(),
|
||||
locale: DEFAULT_LOCALE.to_string(),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl Identity {
|
||||
/// Read the process environment.
|
||||
pub fn from_env() -> Result<Self, ConfigError> {
|
||||
Self::from_vars(&crate::os_env)
|
||||
}
|
||||
|
||||
/// A `FUT_PERSONA_ID` that `int()` would reject kills `fut_account.py` at
|
||||
/// import; we refuse to start for the same reason, rather than serve one
|
||||
/// layer of the stack a silently different persona.
|
||||
pub fn from_vars(env: Env<'_>) -> Result<Self, ConfigError> {
|
||||
let persona_id = match env("FUT_PERSONA_ID") {
|
||||
// `int()` tolerates surrounding whitespace and a sign.
|
||||
Some(v) => v.trim().parse::<i64>().map_err(|_| ConfigError {
|
||||
var: "FUT_PERSONA_ID",
|
||||
value: v.clone(),
|
||||
expected: "an integer",
|
||||
})?,
|
||||
None => DEFAULT_PERSONA_ID,
|
||||
};
|
||||
Ok(Self {
|
||||
persona_id,
|
||||
persona_name: env("FUT_PERSONA_NAME").unwrap_or_else(|| DEFAULT_PERSONA_NAME.into()),
|
||||
locale: env("FUT_LOCALE").unwrap_or_else(|| DEFAULT_LOCALE.into()),
|
||||
})
|
||||
}
|
||||
|
||||
/// Blaze blazeId / userId (SESS.BUID, SESS.UID, AccountInfo.UID).
|
||||
///
|
||||
/// DERIVED, read-only, and deliberately NOT an independent knob: the client
|
||||
/// sends both `nuc` and `nucleusPersonaId` and both came out equal, so the
|
||||
/// getter->field mapping is undetermined. Do not split them until a live test
|
||||
/// proves Blaze USER_ID may legitimately differ from PERSONA_ID.
|
||||
pub fn user_id(&self) -> i64 {
|
||||
self.persona_id
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
use std::collections::HashMap;
|
||||
|
||||
fn env_of(pairs: &[(&str, &str)]) -> impl Fn(&str) -> Option<String> {
|
||||
let map: HashMap<String, String> = pairs
|
||||
.iter()
|
||||
.map(|(k, v)| ((*k).to_string(), (*v).to_string()))
|
||||
.collect();
|
||||
move |k: &str| map.get(k).cloned()
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn defaults_are_the_working_stacks_values() {
|
||||
let id = Identity::from_vars(&env_of(&[])).unwrap();
|
||||
assert_eq!(id.persona_id, 33068179);
|
||||
assert_eq!(id.persona_name, "CAGE");
|
||||
assert_eq!(id.locale, "en_US");
|
||||
assert_eq!(id.user_id(), id.persona_id);
|
||||
assert_eq!(id, Identity::default());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn env_wins_over_defaults() {
|
||||
let id = Identity::from_vars(&env_of(&[
|
||||
("FUT_PERSONA_ID", "1234567"),
|
||||
("FUT_PERSONA_NAME", "OTHER"),
|
||||
("FUT_LOCALE", "de_DE"),
|
||||
]))
|
||||
.unwrap();
|
||||
assert_eq!(id.persona_id, 1234567);
|
||||
assert_eq!(id.persona_name, "OTHER");
|
||||
assert_eq!(id.locale, "de_DE");
|
||||
assert_eq!(id.user_id(), 1234567);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn empty_env_value_still_wins() {
|
||||
// `os.environ.get` returns "" for `FUT_PERSONA_NAME=`, and "" is not None.
|
||||
let id = Identity::from_vars(&env_of(&[("FUT_PERSONA_NAME", "")])).unwrap();
|
||||
assert_eq!(id.persona_name, "");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn whitespace_around_the_persona_id_is_tolerated_like_int() {
|
||||
let id = Identity::from_vars(&env_of(&[("FUT_PERSONA_ID", " 42 ")])).unwrap();
|
||||
assert_eq!(id.persona_id, 42);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn a_non_numeric_persona_id_is_refused() {
|
||||
let err = Identity::from_vars(&env_of(&[("FUT_PERSONA_ID", "CAGE")])).unwrap_err();
|
||||
assert_eq!(err.var, "FUT_PERSONA_ID");
|
||||
assert_eq!(err.to_string(), r#"FUT_PERSONA_ID must be an integer (got "CAGE")"#);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,109 @@
|
||||
//! OpenFUT clean-room LSX responder for FIFA 17 -- Rust port of
|
||||
//! `fifa17-recon/tools/lsx_responder_v2.py` (v2, EVENT-PUSHING).
|
||||
//!
|
||||
//! v1 (`lsx_responder.py`) was REQUEST-DRIVEN ONLY. It answered every verb the
|
||||
//! client asked for and never sent an unsolicited frame. That is exactly why the
|
||||
//! client never issued GetAuthCode and never sent Blaze Authentication::login.
|
||||
//!
|
||||
//! THE ORIGIN SDK HAS TWO INDEPENDENT FLAGS, FED BY TWO DIFFERENT MECHANISMS:
|
||||
//!
|
||||
//! 1. "internet is reachable" -> OriginMgr online byte [0x1448a3ac0],
|
||||
//! fed by the REQUEST verb `GetInternetConnectedState -> connected="1"`
|
||||
//! (v1 already beat this; live-confirmed == 1).
|
||||
//! 2. "a user is LOGGED IN" -> `OriginMgr.m_isLoggedIn` [OriginMgr+0x13],
|
||||
//! fed ONLY by a server-PUSHED `<Event sender="LOGIN_EVENT"><Login/>`.
|
||||
//! There is NO request verb that can set it.
|
||||
//!
|
||||
//! v1 fed (1) and never fed (2), so `m_isLoggedIn` was 0 for the whole session,
|
||||
//! FIFA never enqueued an auth-code request into FirstPartyAuthTokenRetriever
|
||||
//! (both request slots live-read as 0x0), DoTick @0x146f199c0 exited immediately,
|
||||
//! OriginRequestAuthCodeSync @0x1470db3c0 was never called, LoginRequest.AUTH
|
||||
//! could never be filled -> no Blaze login -> "Unable to retrieve account
|
||||
//! information."
|
||||
//!
|
||||
//! The binary evidence for the push (dispatcher @0x146f1e060 case 2, the `<Login>`
|
||||
//! matcher @0x147102880 and its silent sender strcmp, the service-name tables at
|
||||
//! 0x144341420 / sdk+0x3b0, the `strcmp(v,"false")` truthiness of `IsLoggedIn`)
|
||||
//! lives in the Python's module docstring; the specific facts that constrain code
|
||||
//! are repeated at the site that depends on them. Nothing here is derived from
|
||||
//! the 2021 EA/FIFA leak: every constant came from our own static+dynamic
|
||||
//! analysis of binaries we own plus traffic we captured ourselves.
|
||||
//!
|
||||
//! Transport: TCP `127.0.0.1:4216`, every message NUL-terminated (send strlen+1).
|
||||
|
||||
pub mod crypto;
|
||||
pub mod events;
|
||||
pub mod identity;
|
||||
pub mod protocol;
|
||||
|
||||
/// Loopback port the Steampunks Origin emulator stub binds; we must own it
|
||||
/// BEFORE FIFA 17 starts so the stub's own `bind()` fails.
|
||||
pub const LSX_PORT: u16 = 4216;
|
||||
|
||||
/// Emu's own advertised challenge (any 32 hex chars work; the client echoes it
|
||||
/// back).
|
||||
pub const CHALLENGE_KEY: &str = "2b8ee7faea76e8a34f5f5d20e5328e32";
|
||||
pub const BUILD: &str = "release";
|
||||
pub const VERSION: &str = "10,4,13,6637";
|
||||
|
||||
/// Success-signal files the run's watch steps poll. Written only from a REAL
|
||||
/// GetAuthCode on a live connection.
|
||||
pub const AUTHCODE_FILE: &str = "/tmp/openfut_authcode.txt";
|
||||
pub const CLIENTID_FILE: &str = "/tmp/openfut_lsx_clientid.txt";
|
||||
|
||||
/// How the modules read environment knobs. Indirected through a closure so the
|
||||
/// tests can pin an environment without mutating the process (env vars are
|
||||
/// process-global and `cargo test` runs threads in parallel).
|
||||
pub type Env<'a> = &'a dyn Fn(&str) -> Option<String>;
|
||||
|
||||
/// The real environment. Present-but-empty is Some(""), which matters: the
|
||||
/// Python's `os.environ.get(...)` returns "" for `FOO=`, and "" is not None, so
|
||||
/// an empty setting WINS over the built-in default.
|
||||
pub fn os_env(name: &str) -> Option<String> {
|
||||
std::env::var_os(name).map(|v| v.to_string_lossy().into_owned())
|
||||
}
|
||||
|
||||
/// The Python's recurring `os.environ.get(NAME, "0") != "0"` rule: ANY value
|
||||
/// other than the literal "0" enables the knob (including the empty string).
|
||||
pub fn env_flag(env: Env<'_>, name: &str, default_on: bool) -> bool {
|
||||
match env(name) {
|
||||
Some(v) => v != "0",
|
||||
None => default_on,
|
||||
}
|
||||
}
|
||||
|
||||
/// An env knob was set to something the Python's own `int()`/`float()` would
|
||||
/// reject. The Python dies at import in that case; we refuse to start for the
|
||||
/// same reason -- a silently different persona, or a silently absent heartbeat,
|
||||
/// is worse than a loud failure.
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub struct ConfigError {
|
||||
pub var: &'static str,
|
||||
pub value: String,
|
||||
pub expected: &'static str,
|
||||
}
|
||||
|
||||
impl std::fmt::Display for ConfigError {
|
||||
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
|
||||
write!(
|
||||
f,
|
||||
"{} must be {} (got {:?})",
|
||||
self.var, self.expected, self.value
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
impl std::error::Error for ConfigError {}
|
||||
|
||||
/// Every diagnostic line carries the `[lsx] ` prefix and is flushed per line:
|
||||
/// the launcher pipes our stdout+stderr into its log buffer and parses some of
|
||||
/// these lines, so the formats are a contract.
|
||||
#[macro_export]
|
||||
macro_rules! log {
|
||||
($($arg:tt)*) => {{
|
||||
use std::io::Write;
|
||||
let mut out = std::io::stdout().lock();
|
||||
let _ = writeln!(out, "[lsx] {}", format_args!($($arg)*));
|
||||
let _ = out.flush();
|
||||
}};
|
||||
}
|
||||
@@ -0,0 +1,278 @@
|
||||
//! `openfut-lsx` -- the LSX responder process the launcher spawns.
|
||||
//!
|
||||
//! USAGE: bind BEFORE launching FIFA 17 so the Steampunks stub's `bind()` fails.
|
||||
//! This process does NOT auto-start anything; the launcher owns processes.
|
||||
|
||||
use std::io::{self, Read};
|
||||
use std::net::{SocketAddr, TcpListener, TcpStream};
|
||||
use std::process::ExitCode;
|
||||
use std::sync::Arc;
|
||||
|
||||
use openfut_lsx::crypto;
|
||||
use openfut_lsx::events::{fmt_secs, login_event_frames, Conn, EventConfig};
|
||||
use openfut_lsx::identity::Identity;
|
||||
use openfut_lsx::protocol::{
|
||||
parse_request, push_after, py_repr, resp, safe_xml_for_log, Attrs, ProtocolConfig, Responder,
|
||||
};
|
||||
use openfut_lsx::{log, os_env, BUILD, CHALLENGE_KEY, LSX_PORT, VERSION};
|
||||
|
||||
fn main() -> ExitCode {
|
||||
if std::env::args().skip(1).any(|a| a == "--selftest") {
|
||||
return match selftest() {
|
||||
Ok(()) => ExitCode::SUCCESS,
|
||||
Err(e) => {
|
||||
log!("SELFTEST FAILED: {e}");
|
||||
ExitCode::FAILURE
|
||||
}
|
||||
};
|
||||
}
|
||||
match serve_forever() {
|
||||
Ok(()) => ExitCode::SUCCESS,
|
||||
Err(e) => {
|
||||
log!("fatal: {e}");
|
||||
ExitCode::FAILURE
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn serve_forever() -> Result<(), Box<dyn std::error::Error>> {
|
||||
let identity = Identity::from_env()?;
|
||||
let events = EventConfig::from_env()?;
|
||||
let responder = Arc::new(Responder::new(identity, ProtocolConfig::from_env()));
|
||||
|
||||
// Readiness IS the bind: nothing is logged until 4216 is ours, so the launcher
|
||||
// never reads a ready line for a listener that does not exist. `TcpListener::bind`
|
||||
// already sets SO_REUSEADDR on every non-Windows target, which is the Python's
|
||||
// explicit `setsockopt(SO_REUSEADDR, 1)` -- do not reach for socket2 to re-add it.
|
||||
let bind_host = os_env("OPENFUT_BIND").unwrap_or_else(|| "127.0.0.1".to_string());
|
||||
let listener = TcpListener::bind((bind_host.as_str(), LSX_PORT))?;
|
||||
|
||||
// Literal "127.0.0.1:4216" even under OPENFUT_BIND, as the Python logs it: this
|
||||
// line is what the launcher watches for.
|
||||
log!("v2 listening on 127.0.0.1:{LSX_PORT} (start FIFA 17 now)");
|
||||
log!(
|
||||
"login-state event push: {} (period={}s count={})",
|
||||
if events.enabled { "ENABLED" } else { "DISABLED" },
|
||||
fmt_secs(events.period_secs),
|
||||
events.count
|
||||
);
|
||||
|
||||
for stream in listener.incoming() {
|
||||
let stream = match stream {
|
||||
Ok(s) => s,
|
||||
Err(e) => {
|
||||
log!("accept failed: {e}");
|
||||
continue;
|
||||
}
|
||||
};
|
||||
let peer = stream
|
||||
.peer_addr()
|
||||
.unwrap_or_else(|_| SocketAddr::from(([0, 0, 0, 0], 0)));
|
||||
log!("connection from {}", py_addr(peer));
|
||||
let responder = Arc::clone(&responder);
|
||||
let events = events.clone();
|
||||
std::thread::spawn(move || serve(stream, peer, &responder, events));
|
||||
}
|
||||
Ok(())
|
||||
}
|
||||
|
||||
/// Python prints the accept tuple, e.g. `('127.0.0.1', 54321)`.
|
||||
fn py_addr(peer: SocketAddr) -> String {
|
||||
format!("('{}', {})", peer.ip(), peer.port())
|
||||
}
|
||||
|
||||
fn serve(mut sock: TcpStream, peer: SocketAddr, responder: &Responder, events: EventConfig) {
|
||||
let conn = match Conn::new(&sock, peer, events) {
|
||||
Ok(c) => c,
|
||||
Err(e) => {
|
||||
log!("connection error: {e}");
|
||||
return;
|
||||
}
|
||||
};
|
||||
if let Err(e) = session(&mut sock, &conn, responder) {
|
||||
log!("connection error: {e}");
|
||||
}
|
||||
conn.mark_dead();
|
||||
// Dropping our halves closes the socket; the heartbeat thread notices on its
|
||||
// next tick (and its own send would fail regardless).
|
||||
drop(sock);
|
||||
log!("connection closed {}", py_addr(peer));
|
||||
}
|
||||
|
||||
fn session(
|
||||
sock: &mut TcpStream,
|
||||
conn: &Arc<Conn>,
|
||||
responder: &Responder,
|
||||
) -> Result<(), Box<dyn std::error::Error>> {
|
||||
// 1. plaintext Challenge
|
||||
conn.send_plain(&format!(
|
||||
r#"<LSX><Event sender="EALS"><Challenge key="{CHALLENGE_KEY}" build="{BUILD}" version="{VERSION}"/></Event></LSX>"#
|
||||
))?;
|
||||
|
||||
// 2. plaintext ChallengeResponse from the client. The emu parses `response="`
|
||||
// BEFORE `key="` (0x180001f10); extract both so challenge_response can echo
|
||||
// the client's own 3rd block (REPACK_INTEL.md C1/C2).
|
||||
let mut first = [0u8; 4096];
|
||||
let n = sock.read(&mut first)?;
|
||||
let txt = String::from_utf8_lossy(&first[..n]);
|
||||
let client_key = first_attr(&txt, "key").unwrap_or(CHALLENGE_KEY);
|
||||
let client_resp = first_attr(&txt, "response").unwrap_or("");
|
||||
let h = crypto::challenge_response(client_key, client_resp)?;
|
||||
conn.set_key(crypto::derive_session_key(&h));
|
||||
log!("handshake accepted; session crypto initialized");
|
||||
|
||||
// 3. plaintext ChallengeAccepted
|
||||
conn.send_plain(&resp(
|
||||
"1",
|
||||
&format!(r#"ChallengeAccepted response="{h}""#),
|
||||
"EALS",
|
||||
))?;
|
||||
|
||||
// 3b. EXPERIMENT (OPENFUT_LSX_LOGIN_PLAINTEXT=1): the shipped emu's ONLY
|
||||
// unsolicited Event is the plaintext, pre-session-key Challenge; there is
|
||||
// zero evidence an *encrypted mid-session* Event routes to the same parser
|
||||
// (REPACK_INTEL.md sec.4 step 2). So push the Login Event here, in
|
||||
// PLAINTEXT, right after ChallengeAccepted -- before the stream goes
|
||||
// encrypted -- and suppress the encrypted heartbeat to keep the A/B clean.
|
||||
if conn.events().login_plaintext && conn.events().enabled {
|
||||
conn.stop_events();
|
||||
for frame in login_event_frames() {
|
||||
conn.send_plain(&frame)?;
|
||||
log!("PUSH (plaintext post-accept) >> {frame}");
|
||||
}
|
||||
}
|
||||
|
||||
// 4. encrypted request/response loop
|
||||
let mut heartbeat_started = false;
|
||||
let mut buf = Vec::new();
|
||||
let mut chunk = [0u8; 65536];
|
||||
loop {
|
||||
let n = sock.read(&mut chunk)?;
|
||||
if n == 0 {
|
||||
break;
|
||||
}
|
||||
// Buffer partial frames: a 64 KiB read can straddle a NUL boundary, and
|
||||
// splitting without keeping the remainder would silently drop the trailing
|
||||
// partial (C3).
|
||||
buf.extend_from_slice(&chunk[..n]);
|
||||
let complete = match buf.iter().rposition(|b| *b == 0) {
|
||||
Some(i) => i + 1,
|
||||
None => continue,
|
||||
};
|
||||
let frames: Vec<Vec<u8>> = buf[..complete]
|
||||
.split(|b| *b == 0)
|
||||
.filter(|f| !f.is_empty())
|
||||
.map(<[u8]>::to_vec)
|
||||
.collect();
|
||||
buf.drain(..complete);
|
||||
|
||||
for frame in frames {
|
||||
let key = conn.key().expect("session key set during the handshake");
|
||||
let xml = match crypto::lsx_decrypt(&frame, &key) {
|
||||
Ok(x) => x,
|
||||
Err(e) => {
|
||||
log!("decrypt fail: {e}");
|
||||
continue;
|
||||
}
|
||||
};
|
||||
let Some(req) = parse_request(&xml) else {
|
||||
log!("<< {}", safe_xml_for_log(&xml));
|
||||
continue;
|
||||
};
|
||||
let reply = responder.build_reply(req.id, req.name, &req.attrs, Some(conn), req.recipient);
|
||||
log!(
|
||||
"<< id={} {} recipient={} {}",
|
||||
req.id,
|
||||
req.name,
|
||||
py_repr(req.recipient),
|
||||
req.attrs.py_repr()
|
||||
);
|
||||
log!(">> {}", safe_xml_for_log(&reply));
|
||||
conn.send_enc(&reply)?;
|
||||
|
||||
if let Some(why) = push_after(req.name) {
|
||||
if conn.events().enabled
|
||||
// For GetGameInfo only fire on UPTODATE, otherwise we would push
|
||||
// three times per boot for FREETRIAL/LANGUAGES too.
|
||||
&& (req.name != "GetGameInfo"
|
||||
|| req.attrs.get("GameInfoId") == Some("UPTODATE"))
|
||||
{
|
||||
conn.push_login_state(why);
|
||||
if !heartbeat_started {
|
||||
heartbeat_started = true;
|
||||
let conn = Arc::clone(conn);
|
||||
std::thread::spawn(move || conn.heartbeat());
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
Ok(())
|
||||
}
|
||||
|
||||
/// `re.search(r'name="([^"]*)"', txt)` -- the first occurrence anywhere in the
|
||||
/// plaintext handshake frame, with no word-boundary requirement (which is why the
|
||||
/// needle keeps its `="`).
|
||||
fn first_attr<'a>(txt: &'a str, name: &str) -> Option<&'a str> {
|
||||
let needle = format!("{name}=\"");
|
||||
let start = txt.find(&needle)? + needle.len();
|
||||
let len = txt[start..].find('"')?;
|
||||
Some(&txt[start..start + len])
|
||||
}
|
||||
|
||||
/// No live game needed. Proves the crypto is untouched and the event frames
|
||||
/// encrypt/decrypt cleanly through our own codec.
|
||||
fn selftest() -> Result<(), Box<dyn std::error::Error>> {
|
||||
let h = crypto::challenge_response("18a70055a3541fb27ab8e0f47afad18c", "")?;
|
||||
check(h.starts_with("e4f5166209929e15"), &h)?;
|
||||
let k = crypto::derive_session_key(&h);
|
||||
let k_hex = crypto::hex_lower(&k);
|
||||
check(k_hex == "6a9da3e78615153cc2f10eec25ae6382", &k_hex)?;
|
||||
println!("[ok] crypto matches the captured 2026-07-30 session verbatim");
|
||||
|
||||
let frames = login_event_frames();
|
||||
check(
|
||||
frames.len()
|
||||
== openfut_lsx::events::LOGIN_EVENT_SENDERS.len()
|
||||
+ openfut_lsx::events::ONLINE_EVENT_SENDERS.len(),
|
||||
&format!("{} frames", frames.len()),
|
||||
)?;
|
||||
for f in &frames {
|
||||
let round = crypto::lsx_decrypt(&crypto::lsx_encrypt(f, &k), &k)?;
|
||||
check(round == *f, &round)?;
|
||||
println!("[ok] round-trip: {f}");
|
||||
}
|
||||
// "" sender first (correct for the current empty service-name table)
|
||||
check(
|
||||
frames[0].contains(r#"<Event sender=""><Login IsLoggedIn="true"/></Event>"#),
|
||||
&frames[0],
|
||||
)?;
|
||||
|
||||
// conn=None: the selftest must not write the run's success-signal files.
|
||||
let responder = Responder::new(Identity::from_env()?, ProtocolConfig::from_env());
|
||||
let attrs: Attrs = [("ClientId", "X"), ("Scope", "Y")].into_iter().collect();
|
||||
let r = responder.build_reply("42", "GetAuthCode", &attrs, None, "");
|
||||
// `value` is the only attribute lsx::AuthCodeT's deserializer (0x1471312a0)
|
||||
// actually reads; Code=/Return= are legacy padding.
|
||||
check(r.contains("<AuthCode value="), &r)?;
|
||||
|
||||
let redacted = safe_xml_for_log(r#"<AuthCode value="secret" Code="secret" Return="secret"/>"#);
|
||||
check(
|
||||
!redacted.contains("secret") && redacted.matches("[REDACTED]").count() == 3,
|
||||
&redacted,
|
||||
)?;
|
||||
let status = safe_xml_for_log(r#"<ErrorSuccess Code="0" Description=""/>"#);
|
||||
check(status.contains(r#"Code="0""#), &status)?;
|
||||
println!("[ok] GetAuthCode response shape and log redaction");
|
||||
println!("[ok] selftest passed");
|
||||
Ok(())
|
||||
}
|
||||
|
||||
/// The Python's `assert cond, value`.
|
||||
fn check(cond: bool, value: &str) -> Result<(), io::Error> {
|
||||
if cond {
|
||||
Ok(())
|
||||
} else {
|
||||
Err(io::Error::other(format!("assertion failed: {value}")))
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,914 @@
|
||||
//! Request parsing, verb dispatch and log redaction.
|
||||
//!
|
||||
//! The dispatch is request-DRIVEN (the Steampunks stub was a blind fixed script),
|
||||
//! and the frame grammar is the Python's three regexes, transcribed by hand so the
|
||||
//! crate needs no regex engine. Where the regexes are tolerant, this is tolerant
|
||||
//! in the same way -- see [`parse_request`].
|
||||
|
||||
use std::fmt::Write as _;
|
||||
use std::fs;
|
||||
|
||||
use crate::events::Conn;
|
||||
use crate::identity::{Identity, CONTENT_ID, ENTITLEMENT_TAG};
|
||||
use crate::{env_flag, log, Env, AUTHCODE_FILE, CLIENTID_FILE};
|
||||
|
||||
/// Attributes of the request's child element, in the order they appeared.
|
||||
///
|
||||
/// Python builds `dict(ATTR_RE.findall(rest))`: a repeated attribute keeps its
|
||||
/// FIRST position but takes its LAST value, and that dict is echoed into the
|
||||
/// `<< id=...` log line, so the ordering is observable.
|
||||
#[derive(Debug, Default, Clone, PartialEq, Eq)]
|
||||
pub struct Attrs<'a>(Vec<(&'a str, &'a str)>);
|
||||
|
||||
impl<'a> Attrs<'a> {
|
||||
pub fn new() -> Self {
|
||||
Self(Vec::new())
|
||||
}
|
||||
|
||||
pub fn insert(&mut self, key: &'a str, value: &'a str) {
|
||||
match self.0.iter_mut().find(|(k, _)| *k == key) {
|
||||
Some(slot) => slot.1 = value,
|
||||
None => self.0.push((key, value)),
|
||||
}
|
||||
}
|
||||
|
||||
pub fn get(&self, key: &str) -> Option<&'a str> {
|
||||
self.0.iter().find(|(k, _)| *k == key).map(|(_, v)| *v)
|
||||
}
|
||||
|
||||
/// `attrs.get(key, "")`.
|
||||
pub fn get_or_empty(&self, key: &str) -> &'a str {
|
||||
self.get(key).unwrap_or("")
|
||||
}
|
||||
|
||||
pub fn is_empty(&self) -> bool {
|
||||
self.0.is_empty()
|
||||
}
|
||||
|
||||
pub fn len(&self) -> usize {
|
||||
self.0.len()
|
||||
}
|
||||
|
||||
pub fn iter(&self) -> impl Iterator<Item = (&'a str, &'a str)> + '_ {
|
||||
self.0.iter().copied()
|
||||
}
|
||||
|
||||
/// `repr(dict)`, because the request log line embeds it verbatim.
|
||||
pub fn py_repr(&self) -> String {
|
||||
let mut s = String::from("{");
|
||||
for (i, (k, v)) in self.0.iter().enumerate() {
|
||||
if i > 0 {
|
||||
s.push_str(", ");
|
||||
}
|
||||
let _ = write!(s, "{}: {}", py_repr(k), py_repr(v));
|
||||
}
|
||||
s.push('}');
|
||||
s
|
||||
}
|
||||
}
|
||||
|
||||
impl<'a> FromIterator<(&'a str, &'a str)> for Attrs<'a> {
|
||||
fn from_iter<T: IntoIterator<Item = (&'a str, &'a str)>>(iter: T) -> Self {
|
||||
let mut attrs = Attrs::new();
|
||||
for (k, v) in iter {
|
||||
attrs.insert(k, v);
|
||||
}
|
||||
attrs
|
||||
}
|
||||
}
|
||||
|
||||
/// One parsed `<Request>` frame.
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub struct Request<'a> {
|
||||
/// The digits of `id="N"`, kept as text: it is echoed, never arithmetic.
|
||||
pub id: &'a str,
|
||||
pub name: &'a str,
|
||||
pub attrs: Attrs<'a>,
|
||||
/// The response `sender` must byte-equal this (matcher 0x1471189b0). Captured
|
||||
/// separately from the rest of the frame, and defaulting to "", so a frame
|
||||
/// that ever lacks `recipient` still gets answered fast instead of a 15s
|
||||
/// stall.
|
||||
pub recipient: &'a str,
|
||||
}
|
||||
|
||||
/// `REQ_RE = r'<Request[^>]*\bid="(\d+)"[^>]*>\s*<([A-Za-z]+)([^>]*)/?>'` plus
|
||||
/// `RECIP_RE = r'<Request[^>]*\brecipient="([^"]*)"'`, both as `re.search`.
|
||||
///
|
||||
/// Transcription notes, all of them observable behaviour rather than style:
|
||||
/// * `[^>]*` cannot cross a `>`, so `id` must live inside the `<Request ...>`
|
||||
/// tag itself; the tag must be closed for the pattern to match at all.
|
||||
/// * that leading `[^>]*` is greedy, so with more than one `id="N"` in the tag
|
||||
/// the RIGHTMOST one wins.
|
||||
/// * the trailing `([^>]*)/?>` is greedy too, so the captured attribute region
|
||||
/// keeps a self-closing `/` -- harmless, `ATTR_RE` skips it.
|
||||
/// * `recipient` is searched over the whole frame independently of the element
|
||||
/// match, and its value may legally contain `>`.
|
||||
pub fn parse_request(xml: &str) -> Option<Request<'_>> {
|
||||
const TAG: &str = "<Request";
|
||||
let mut from = 0;
|
||||
while let Some(off) = xml[from..].find(TAG) {
|
||||
let start = from + off;
|
||||
from = start + TAG.len();
|
||||
let tag_end = match xml[from..].find('>') {
|
||||
Some(i) => from + i,
|
||||
None => continue, // `[^>]*>` needs the tag to close
|
||||
};
|
||||
let Some(id) = rightmost_id(xml, from, tag_end) else {
|
||||
continue;
|
||||
};
|
||||
// `>\s*<`
|
||||
let child = xml[tag_end + 1..].trim_start_matches(char::is_whitespace);
|
||||
let Some(child) = child.strip_prefix('<') else {
|
||||
continue;
|
||||
};
|
||||
let name_len = child
|
||||
.as_bytes()
|
||||
.iter()
|
||||
.take_while(|c| c.is_ascii_alphabetic())
|
||||
.count();
|
||||
if name_len == 0 {
|
||||
continue;
|
||||
}
|
||||
let (name, tail) = child.split_at(name_len);
|
||||
let Some(gt) = tail.find('>') else {
|
||||
continue;
|
||||
};
|
||||
return Some(Request {
|
||||
id,
|
||||
name,
|
||||
attrs: parse_attrs(&tail[..gt]),
|
||||
recipient: find_recipient(xml).unwrap_or(""),
|
||||
});
|
||||
}
|
||||
None
|
||||
}
|
||||
|
||||
/// The rightmost `\bid="(\d+)"` inside `xml[from..tag_end]`.
|
||||
fn rightmost_id(xml: &str, from: usize, tag_end: usize) -> Option<&str> {
|
||||
let tag = &xml[from..tag_end];
|
||||
let mut search_end = tag.len();
|
||||
while let Some(at) = tag[..search_end].rfind("id=\"") {
|
||||
search_end = at;
|
||||
// `\b`: the character before `id` must not be a word character. Look at
|
||||
// the whole frame, so `<Requestid="1">` correctly fails.
|
||||
if !word_boundary_before(xml, from + at) {
|
||||
continue;
|
||||
}
|
||||
let value = &tag[at + 4..];
|
||||
let digits = value.as_bytes().iter().take_while(|c| c.is_ascii_digit()).count();
|
||||
if digits > 0 && value.as_bytes().get(digits) == Some(&b'"') {
|
||||
return Some(&value[..digits]);
|
||||
}
|
||||
}
|
||||
None
|
||||
}
|
||||
|
||||
fn find_recipient(xml: &str) -> Option<&str> {
|
||||
const TAG: &str = "<Request";
|
||||
let mut from = 0;
|
||||
while let Some(off) = xml[from..].find(TAG) {
|
||||
from += off + TAG.len();
|
||||
// The literal must start before the tag closes; the VALUE may run past it.
|
||||
let limit = xml[from..].find('>').map_or(xml.len(), |i| from + i);
|
||||
let mut search_end = limit;
|
||||
while let Some(at) = xml[from..search_end].rfind("recipient=\"") {
|
||||
let at = from + at;
|
||||
search_end = at;
|
||||
if !word_boundary_before(xml, at) {
|
||||
continue;
|
||||
}
|
||||
let value_start = at + "recipient=\"".len();
|
||||
if let Some(len) = xml[value_start..].find('"') {
|
||||
return Some(&xml[value_start..value_start + len]);
|
||||
}
|
||||
}
|
||||
}
|
||||
None
|
||||
}
|
||||
|
||||
/// `ATTR_RE.findall` -- `(\w+)="([^"]*)"`, non-overlapping, left to right.
|
||||
fn parse_attrs(region: &str) -> Attrs<'_> {
|
||||
let mut attrs = Attrs::new();
|
||||
let mut pos = 0;
|
||||
while let Some(off) = region[pos..].find("=\"") {
|
||||
let eq = pos + off;
|
||||
// Greedy `\w+` immediately before `="`.
|
||||
let name_len: usize = region[..eq]
|
||||
.chars()
|
||||
.rev()
|
||||
.take_while(|c| is_word(*c))
|
||||
.map(char::len_utf8)
|
||||
.sum();
|
||||
let value_start = eq + 2;
|
||||
let Some(value_len) = region[value_start..].find('"') else {
|
||||
break; // an unterminated value ends the scan, as the regex does
|
||||
};
|
||||
if name_len > 0 {
|
||||
attrs.insert(
|
||||
®ion[eq - name_len..eq],
|
||||
®ion[value_start..value_start + value_len],
|
||||
);
|
||||
}
|
||||
pos = value_start + value_len + 1;
|
||||
}
|
||||
attrs
|
||||
}
|
||||
|
||||
fn is_word(c: char) -> bool {
|
||||
c.is_alphanumeric() || c == '_'
|
||||
}
|
||||
|
||||
fn word_boundary_before(s: &str, at: usize) -> bool {
|
||||
at == 0 || !s[..at].chars().next_back().is_some_and(is_word)
|
||||
}
|
||||
|
||||
// ------------------------------------------------------------------ redaction
|
||||
const SECRET_ATTRS: [&str; 5] = ["AuthCode", "AuthToken", "SessionKey", "Token", "Sid"];
|
||||
const AUTH_CODE_ATTRS: [&str; 3] = ["value", "Code", "Return"];
|
||||
const CHALLENGE_ATTRS: [&str; 1] = ["response"];
|
||||
|
||||
/// Redact credential-bearing LSX attributes from ordinary diagnostics.
|
||||
///
|
||||
/// The blanket pass only catches `Name="..."` pairs; the auth code and the
|
||||
/// challenge response hide behind generic attribute names (`value`, `Code`,
|
||||
/// `Return`, `response`), so those two elements get a second, element-scoped pass
|
||||
/// -- otherwise `<ErrorSuccess Code="0">` would be redacted too and the ordinary
|
||||
/// status lines would stop being readable.
|
||||
pub fn safe_xml_for_log(xml: &str) -> String {
|
||||
let safe = redact_attrs(xml, &SECRET_ATTRS);
|
||||
let safe = if safe.contains("<AuthCode ") {
|
||||
redact_attrs(&safe, &AUTH_CODE_ATTRS)
|
||||
} else {
|
||||
safe
|
||||
};
|
||||
if safe.contains("<ChallengeAccepted ") {
|
||||
redact_attrs(&safe, &CHALLENGE_ATTRS)
|
||||
} else {
|
||||
safe
|
||||
}
|
||||
}
|
||||
|
||||
/// `re.sub(r'(?i)\b(a|b|c)="[^"]*"', r'\1="[REDACTED]"', xml)`; the attribute name
|
||||
/// keeps the case it was written in.
|
||||
fn redact_attrs(input: &str, names: &[&str]) -> String {
|
||||
let mut out = String::with_capacity(input.len());
|
||||
let mut last = 0;
|
||||
let mut i = 0;
|
||||
while i < input.len() {
|
||||
if !input.is_char_boundary(i) || !word_boundary_before(input, i) {
|
||||
i += 1;
|
||||
continue;
|
||||
}
|
||||
let rest = &input[i..];
|
||||
let hit = names.iter().find_map(|name| {
|
||||
let after = rest.get(..name.len())?;
|
||||
if !after.eq_ignore_ascii_case(name) {
|
||||
return None;
|
||||
}
|
||||
let value = rest[name.len()..].strip_prefix("=\"")?;
|
||||
let len = value.find('"')?;
|
||||
Some((name.len(), name.len() + 2 + len + 1))
|
||||
});
|
||||
match hit {
|
||||
Some((name_len, match_len)) => {
|
||||
out.push_str(&input[last..i]);
|
||||
out.push_str(&rest[..name_len]);
|
||||
out.push_str("=\"[REDACTED]\"");
|
||||
i += match_len;
|
||||
last = i;
|
||||
}
|
||||
None => i += 1,
|
||||
}
|
||||
}
|
||||
out.push_str(&input[last..]);
|
||||
out
|
||||
}
|
||||
|
||||
/// `repr()` of a Python string, for the log lines that embed one.
|
||||
pub fn py_repr(s: &str) -> String {
|
||||
let quote = if s.contains('\'') && !s.contains('"') {
|
||||
'"'
|
||||
} else {
|
||||
'\''
|
||||
};
|
||||
let mut out = String::with_capacity(s.len() + 2);
|
||||
out.push(quote);
|
||||
for c in s.chars() {
|
||||
match c {
|
||||
'\\' => out.push_str("\\\\"),
|
||||
'\n' => out.push_str("\\n"),
|
||||
'\r' => out.push_str("\\r"),
|
||||
'\t' => out.push_str("\\t"),
|
||||
c if c == quote => {
|
||||
out.push('\\');
|
||||
out.push(c);
|
||||
}
|
||||
// Python renders the remaining ASCII controls as \xNN; anything
|
||||
// printable (including non-ASCII) goes through verbatim.
|
||||
c if (c as u32) < 0x20 || c as u32 == 0x7f => {
|
||||
let _ = write!(out, "\\x{:02x}", c as u32);
|
||||
}
|
||||
c => out.push(c),
|
||||
}
|
||||
}
|
||||
out.push(quote);
|
||||
out
|
||||
}
|
||||
|
||||
// ------------------------------------------------------------------ responses
|
||||
pub fn resp(mid: &str, body: &str, sender: &str) -> String {
|
||||
format!(r#"<LSX><Response id="{mid}" sender="{sender}"><{body}/></Response></LSX>"#)
|
||||
}
|
||||
|
||||
/// Knobs that shape individual replies.
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub struct ProtocolConfig {
|
||||
/// A/B-control integrity: v1 (`lsx_responder.py`) answered GetGameInfo
|
||||
/// FULLGAME_PURCHASED with "false" (it fell through to the default). v2 had
|
||||
/// silently changed it to "true", which meant `OPENFUT_LSX_EVENTS=0` was NOT a
|
||||
/// byte-identical control any more. Keep it OFF by default so events-off ==
|
||||
/// v1 exactly; flip `OPENFUT_LSX_FULLGAME=1` to run the FULLGAME="true"
|
||||
/// experiment on its own.
|
||||
pub fullgame_purchased: bool,
|
||||
/// `OPENFUT_AUTHCODE`.
|
||||
pub auth_code: String,
|
||||
}
|
||||
|
||||
impl Default for ProtocolConfig {
|
||||
fn default() -> Self {
|
||||
Self {
|
||||
fullgame_purchased: false,
|
||||
auth_code: format!("OPENFUT-{}", "0".repeat(24)),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl ProtocolConfig {
|
||||
pub fn from_env() -> Self {
|
||||
Self::from_vars(&crate::os_env)
|
||||
}
|
||||
|
||||
pub fn from_vars(env: Env<'_>) -> Self {
|
||||
Self {
|
||||
fullgame_purchased: env_flag(env, "OPENFUT_LSX_FULLGAME", false),
|
||||
auth_code: env("OPENFUT_AUTHCODE").unwrap_or_else(|| Self::default().auth_code),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// The verb dispatcher.
|
||||
pub struct Responder {
|
||||
pub identity: Identity,
|
||||
pub config: ProtocolConfig,
|
||||
}
|
||||
|
||||
impl Responder {
|
||||
pub fn new(identity: Identity, config: ProtocolConfig) -> Self {
|
||||
Self { identity, config }
|
||||
}
|
||||
|
||||
/// Request-DRIVEN dispatch.
|
||||
///
|
||||
/// CRITICAL (2026-07-31, connect-reverse workflow): FIFA's response matcher
|
||||
/// 0x1471189b0 rejects any `<Response>` whose `sender` attribute does not
|
||||
/// byte-equal the `recipient` the client put on the matching `<Request>` (it
|
||||
/// reads `serviceNames[facility]`; with our empty GetConfigResponse all 34
|
||||
/// names are "" so recipient="" for every verb after GetConfig, which itself
|
||||
/// uses the hard-coded literal "EbisuSDK"). We were answering GetProfile/
|
||||
/// GetAuthCode/QueryEntitlements with sender="EbisuSDK" -> silently discarded
|
||||
/// -> GetProfile (the SOLE writer of OriginSDK+0x3a0 default-user) never took
|
||||
/// -> the whole online-login chain stalled at OSDK_INVALID_USER. FIX = ECHO
|
||||
/// the request's recipient back as the response sender, which is what every
|
||||
/// `reply` below does.
|
||||
///
|
||||
/// `conn` is `None` in the selftest; a `None` connection must not touch the
|
||||
/// run's success-signal files.
|
||||
pub fn build_reply(
|
||||
&self,
|
||||
mid: &str,
|
||||
req_name: &str,
|
||||
attrs: &Attrs<'_>,
|
||||
conn: Option<&Conn>,
|
||||
recipient: &str,
|
||||
) -> String {
|
||||
let reply = |body: &str| resp(mid, body, recipient);
|
||||
|
||||
match req_name {
|
||||
// FLAG (1): "internet is reachable". The stub hardcoded
|
||||
// connected="0" -> "log in to Origin". This is NOT the logged-in
|
||||
// flag; see the crate docs.
|
||||
"GetInternetConnectedState" => reply(r#"InternetConnectedState connected="1""#),
|
||||
|
||||
// Request shape is built at 0x14713b8d0:
|
||||
// <GetAuthCode ClientId="..." Scope="..."/>
|
||||
// Response is matched at 0x1470e2b60: outer "LSX", element "AuthCode".
|
||||
//
|
||||
// THE ATTRIBUTE NAME IS "value" -- verified, not guessed: the
|
||||
// "AuthCode" element match at 0x1470e2b63 tail-jumps to 0x14712fac0
|
||||
// -> 0x1471312a0 = the lsx::AuthCodeT deserializer. It builds one
|
||||
// attribute name (ns-prefix for "lsx" @0x14394def0, then "value"
|
||||
// @0x1436c7768, concat at 0x14712d130) and does exactly ONE
|
||||
// get-attribute-as-string call 0x14713fe50(node, "value", &dest).
|
||||
// dest is ctx+0x00 == LSXRequest+0xb8, whose std::string size lands
|
||||
// at +0xc8 -- which is what OriginRequestAuthCodeSync's impl
|
||||
// 0x1470e67f0 reads back at 0x1470e6924 (`mov rbx,[rdi+0xc8]`) as
|
||||
// *out_len. Code=/Return= are NEVER read; with them alone the parsed
|
||||
// string is empty -> out_len 0 -> EbisuMgr+0x948 stays NULL -> the
|
||||
// OSDK classifier 0x14717d5d0 falls into its `test rbp,rbp / je` arm
|
||||
// and reports OSDK_UNDERAGE_ERROR (a mislabelled "no auth code"
|
||||
// fallback). Code=/Return= are kept only as harmless padding.
|
||||
"GetAuthCode" => {
|
||||
let client_id = attrs.get_or_empty("ClientId");
|
||||
let scope = attrs.get_or_empty("Scope");
|
||||
let code = &self.config.auth_code;
|
||||
// Only touch the run's success-signal files on a REAL request. The
|
||||
// selftest passes conn=None; if it wrote these files it would
|
||||
// pre-satisfy watch-step "authcode.txt becomes non-empty" and make
|
||||
// a non-event read as success on the next live run.
|
||||
if let Some(conn) = conn {
|
||||
for (path, val) in [(AUTHCODE_FILE, code.as_str()), (CLIENTID_FILE, client_id)]
|
||||
{
|
||||
if let Err(e) = fs::write(path, val) {
|
||||
log!("could not write {path}: {e}");
|
||||
}
|
||||
}
|
||||
// GetAuthCode has fired: stop the heartbeat so we do not keep
|
||||
// re-pushing Login/OnlineStatus events during Blaze login.
|
||||
conn.stop_events();
|
||||
}
|
||||
log!("*** GetAuthCode ISSUED ***");
|
||||
log!(
|
||||
" ClientId={} Scope={}",
|
||||
py_repr(client_id),
|
||||
py_repr(scope)
|
||||
);
|
||||
log!(" code=[REDACTED] -- issued for Blaze Authentication::login (1/0x0A)");
|
||||
reply(&format!(
|
||||
r#"AuthCode value="{code}" Code="{code}" Return="{code}""#
|
||||
))
|
||||
}
|
||||
|
||||
// The only reply with a child element, so it cannot use the
|
||||
// single-element `resp` helper.
|
||||
"QueryEntitlements" => format!(
|
||||
concat!(
|
||||
r#"<LSX><Response id="{mid}" sender="{recipient}">"#,
|
||||
r#"<QueryEntitlementsResponse>"#,
|
||||
r#"<OriginItem ItemId="{tag}" EntitlementId="1" "#,
|
||||
r#"ResourceId="{content}" OfferId="{content}" "#,
|
||||
r#"GrantDate="2016-09-01T00:00:00Z" bIsOwned="true" Uses="0"/>"#,
|
||||
r#"</QueryEntitlementsResponse>"#,
|
||||
r#"</Response></LSX>"#
|
||||
),
|
||||
mid = mid,
|
||||
recipient = recipient,
|
||||
tag = ENTITLEMENT_TAG,
|
||||
content = CONTENT_ID
|
||||
),
|
||||
|
||||
// This is the ONLY feed for OriginSDK[+0x3a0]/[+0x3a8]
|
||||
// (OriginGetDefaultUser @0x1470da6d0 / OriginGetDefaultPersona
|
||||
// @0x1470da680 are bare reads of those fields, written only by
|
||||
// OriginSDK::Initialize @0x1470e5ad5/0x1470e5ae1). Keep it complete.
|
||||
// ONLY PersonaId/UserId/Persona come from the identity; the rest of
|
||||
// this template (Country/CommerceCountry/GeoCountry/CommerceCurrency/
|
||||
// AvatarId/IsSubscriber/IsUnderAge) is byte-exact per REPACK_INTEL 1.4
|
||||
// and is latched into OriginSDK[+0x3a0]/[+0x3a8] -- leave it verbatim.
|
||||
"GetProfile" => reply(&format!(
|
||||
concat!(
|
||||
r#"GetProfileResponse IsSubscriber="true" PersonaId="{persona}" "#,
|
||||
r#"AvatarId="" Country="US" CommerceCountry="US" GeoCountry="US" "#,
|
||||
r#"UserId="{user}" Persona="{name}" IsUnderAge="false" "#,
|
||||
r#"CommerceCurrency="USD""#
|
||||
),
|
||||
persona = self.identity.persona_id,
|
||||
user = self.identity.user_id(),
|
||||
name = self.identity.persona_name
|
||||
)),
|
||||
|
||||
"GetGameInfo" => match attrs.get("GameInfoId") {
|
||||
Some("LANGUAGES") => reply(concat!(
|
||||
r#"GetGameInfoResponse GameInfo="ar_SA,cs_CZ,da_DK,de_DE,"#,
|
||||
r#"en_US,es_ES,es_MX,fr_FR,it_IT,nl_NL,no_NO,pl_PL,pt_BR,"#,
|
||||
r#"pt_PT,ru_RU,sv_SE,tr_TR,zh_TW""#
|
||||
)),
|
||||
// MUST be true or the client shows "Your title version is
|
||||
// outdated" and blocks all online features.
|
||||
Some("UPTODATE") => reply(r#"GetGameInfoResponse GameInfo="true""#),
|
||||
// OFF by default: v1 answered "false" here (fell through to the
|
||||
// default), and keeping this gated makes OPENFUT_LSX_EVENTS=0
|
||||
// byte-identical to v1.
|
||||
Some("FULLGAME_PURCHASED") if self.config.fullgame_purchased => {
|
||||
reply(r#"GetGameInfoResponse GameInfo="true""#)
|
||||
}
|
||||
// FREETRIAL / FULLGAME_PURCHASED etc. -> false (retail, not a
|
||||
// trial; matches v1 exactly)
|
||||
_ => reply(r#"GetGameInfoResponse GameInfo="false""#),
|
||||
},
|
||||
|
||||
"GetSetting" => {
|
||||
// The client asks in UPPERCASE.
|
||||
match attrs.get_or_empty("SettingId").to_uppercase().as_str() {
|
||||
"ENVIRONMENT" | "ENVIRONMENTNAME" => {
|
||||
reply(r#"GetSettingResponse Setting="production""#)
|
||||
}
|
||||
"LANGUAGE" => reply(&format!(
|
||||
r#"GetSettingResponse Setting="{}""#,
|
||||
self.identity.locale
|
||||
)),
|
||||
_ => reply(r#"GetSettingResponse Setting="false""#),
|
||||
}
|
||||
}
|
||||
|
||||
"GetConfig" => reply(r#"GetConfigResponse Config="false""#),
|
||||
|
||||
"IsProgressiveInstallationAvailable" => reply(concat!(
|
||||
r#"IsProgressiveInstallationAvailableResponse ItemId="" "#,
|
||||
r#"Available="false""#
|
||||
)),
|
||||
|
||||
_ => reply(r#"ErrorSuccess Code="0" Description="""#),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Trigger points: push right after answering these verbs. GetProfile is the
|
||||
/// earliest safe moment -- by then the SDK has built its handler set and has a
|
||||
/// default user, so a Login event has somewhere to land.
|
||||
///
|
||||
/// For GetGameInfo the caller only fires on UPTODATE, otherwise we would push
|
||||
/// three times per boot for FREETRIAL/LANGUAGES too.
|
||||
pub fn push_after(req_name: &str) -> Option<&'static str> {
|
||||
match req_name {
|
||||
"GetProfile" => Some("after GetProfile"),
|
||||
"GetInternetConnectedState" => Some("after GetInternetConnectedState"),
|
||||
"GetGameInfo" => Some("after GetGameInfo UPTODATE"),
|
||||
_ => None,
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
use std::collections::HashMap;
|
||||
|
||||
fn env_of(pairs: &[(&str, &str)]) -> impl Fn(&str) -> Option<String> {
|
||||
let map: HashMap<String, String> = pairs
|
||||
.iter()
|
||||
.map(|(k, v)| ((*k).to_string(), (*v).to_string()))
|
||||
.collect();
|
||||
move |k: &str| map.get(k).cloned()
|
||||
}
|
||||
|
||||
fn responder() -> Responder {
|
||||
Responder::new(Identity::default(), ProtocolConfig::default())
|
||||
}
|
||||
|
||||
fn reply(verb: &str, attrs: &[(&str, &str)]) -> String {
|
||||
responder().build_reply("7", verb, &attrs.iter().copied().collect(), None, "")
|
||||
}
|
||||
|
||||
// ---------------------------------------------------------------- parsing
|
||||
#[test]
|
||||
fn parses_a_request_with_a_recipient() {
|
||||
let xml = r#"<LSX><Request id="12" recipient="EbisuSDK"><GetConfig Locale="en_US" Env="prod"/></Request></LSX>"#;
|
||||
let req = parse_request(xml).unwrap();
|
||||
assert_eq!(req.id, "12");
|
||||
assert_eq!(req.name, "GetConfig");
|
||||
assert_eq!(req.recipient, "EbisuSDK");
|
||||
assert_eq!(req.attrs.get("Locale"), Some("en_US"));
|
||||
assert_eq!(req.attrs.get("Env"), Some("prod"));
|
||||
assert_eq!(req.attrs.len(), 2);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn parses_a_request_without_a_recipient() {
|
||||
// Must still be answered -- fast -- rather than stalling ~15s.
|
||||
let xml = r#"<LSX><Request id="3"><GetProfile/></Request></LSX>"#;
|
||||
let req = parse_request(xml).unwrap();
|
||||
assert_eq!((req.id, req.name, req.recipient), ("3", "GetProfile", ""));
|
||||
assert!(req.attrs.is_empty());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn parses_an_empty_recipient() {
|
||||
let xml = r#"<LSX><Request id="9" recipient=""><GetSetting SettingId="LANGUAGE"/></Request></LSX>"#;
|
||||
let req = parse_request(xml).unwrap();
|
||||
assert_eq!(req.recipient, "");
|
||||
assert_eq!(req.attrs.get("SettingId"), Some("LANGUAGE"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn tolerates_whitespace_between_the_request_and_its_element() {
|
||||
let xml = "<LSX><Request id=\"4\" recipient=\"X\">\n <GetAuthCode ClientId=\"c\" Scope=\"s\" />\n</Request></LSX>";
|
||||
let req = parse_request(xml).unwrap();
|
||||
assert_eq!((req.id, req.name, req.recipient), ("4", "GetAuthCode", "X"));
|
||||
assert_eq!(req.attrs.get("ClientId"), Some("c"));
|
||||
assert_eq!(req.attrs.get("Scope"), Some("s"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn rejects_frames_that_are_not_requests() {
|
||||
for xml in [
|
||||
"",
|
||||
r#"<LSX><Event sender=""><Login IsLoggedIn="true"/></Event></LSX>"#,
|
||||
r#"<LSX><Request recipient="X"><GetConfig/></Request></LSX>"#, // no id
|
||||
r#"<LSX><Request id="abc"><GetConfig/></Request></LSX>"#, // id not digits
|
||||
r#"<LSX><Requestid="1"><GetConfig/></Request></LSX>"#, // \b fails
|
||||
r#"<LSX><Request id="1">"#, // no element
|
||||
] {
|
||||
assert!(parse_request(xml).is_none(), "{xml}");
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn a_repeated_attribute_keeps_its_place_and_takes_the_last_value() {
|
||||
let xml = r#"<LSX><Request id="1"><V a="1" b="2" a="3"/></Request></LSX>"#;
|
||||
let req = parse_request(xml).unwrap();
|
||||
assert_eq!(req.attrs.py_repr(), "{'a': '3', 'b': '2'}");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn greedy_id_takes_the_rightmost_one() {
|
||||
let xml = r#"<LSX><Request id="1" other-id="2"><GetConfig/></Request></LSX>"#;
|
||||
assert_eq!(parse_request(xml).unwrap().id, "2");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn the_self_closing_slash_does_not_become_an_attribute() {
|
||||
let xml = r#"<LSX><Request id="1"><GetGameInfo GameInfoId="UPTODATE"/></Request></LSX>"#;
|
||||
let req = parse_request(xml).unwrap();
|
||||
assert_eq!(req.attrs.len(), 1);
|
||||
assert_eq!(req.attrs.get("GameInfoId"), Some("UPTODATE"));
|
||||
}
|
||||
|
||||
// ------------------------------------------------------------------ verbs
|
||||
#[test]
|
||||
fn internet_connected_state_is_one() {
|
||||
assert_eq!(
|
||||
reply("GetInternetConnectedState", &[]),
|
||||
r#"<LSX><Response id="7" sender=""><InternetConnectedState connected="1"/></Response></LSX>"#
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn auth_code_carries_the_value_attribute() {
|
||||
let r = reply("GetAuthCode", &[("ClientId", "X"), ("Scope", "Y")]);
|
||||
assert_eq!(
|
||||
r,
|
||||
concat!(
|
||||
r#"<LSX><Response id="7" sender=""><AuthCode "#,
|
||||
r#"value="OPENFUT-000000000000000000000000" "#,
|
||||
r#"Code="OPENFUT-000000000000000000000000" "#,
|
||||
r#"Return="OPENFUT-000000000000000000000000"/></Response></LSX>"#
|
||||
)
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn auth_code_honours_the_env_override() {
|
||||
let cfg = ProtocolConfig::from_vars(&env_of(&[("OPENFUT_AUTHCODE", "ABC")]));
|
||||
let r = Responder::new(Identity::default(), cfg).build_reply(
|
||||
"1",
|
||||
"GetAuthCode",
|
||||
&Attrs::new(),
|
||||
None,
|
||||
"",
|
||||
);
|
||||
assert!(r.contains(r#"<AuthCode value="ABC" Code="ABC" Return="ABC"/>"#), "{r}");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn query_entitlements_owns_the_retail_offer() {
|
||||
assert_eq!(
|
||||
reply("QueryEntitlements", &[]),
|
||||
concat!(
|
||||
r#"<LSX><Response id="7" sender=""><QueryEntitlementsResponse>"#,
|
||||
r#"<OriginItem ItemId="ONLINE_ACCESS" EntitlementId="1" "#,
|
||||
r#"ResourceId="1027460" OfferId="1027460" "#,
|
||||
r#"GrantDate="2016-09-01T00:00:00Z" bIsOwned="true" Uses="0"/>"#,
|
||||
r#"</QueryEntitlementsResponse></Response></LSX>"#
|
||||
)
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn profile_carries_the_identity_and_the_verbatim_template() {
|
||||
assert_eq!(
|
||||
reply("GetProfile", &[]),
|
||||
concat!(
|
||||
r#"<LSX><Response id="7" sender=""><GetProfileResponse IsSubscriber="true" "#,
|
||||
r#"PersonaId="33068179" AvatarId="" Country="US" CommerceCountry="US" "#,
|
||||
r#"GeoCountry="US" UserId="33068179" Persona="CAGE" IsUnderAge="false" "#,
|
||||
r#"CommerceCurrency="USD"/></Response></LSX>"#
|
||||
)
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn profile_echoes_an_overridden_persona() {
|
||||
let ident = Identity::from_vars(&env_of(&[
|
||||
("FUT_PERSONA_ID", "42"),
|
||||
("FUT_PERSONA_NAME", "ZED"),
|
||||
]))
|
||||
.unwrap();
|
||||
let r = Responder::new(ident, ProtocolConfig::default())
|
||||
.build_reply("1", "GetProfile", &Attrs::new(), None, "");
|
||||
assert!(r.contains(r#"PersonaId="42""#), "{r}");
|
||||
assert!(r.contains(r#"UserId="42""#), "{r}");
|
||||
assert!(r.contains(r#"Persona="ZED""#), "{r}");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn game_info_languages_and_uptodate() {
|
||||
let r = reply("GetGameInfo", &[("GameInfoId", "LANGUAGES")]);
|
||||
assert!(r.contains(r#"GameInfo="ar_SA,cs_CZ,"#), "{r}");
|
||||
assert!(r.ends_with(r#"tr_TR,zh_TW"/></Response></LSX>"#), "{r}");
|
||||
assert!(reply("GetGameInfo", &[("GameInfoId", "UPTODATE")])
|
||||
.contains(r#"GetGameInfoResponse GameInfo="true""#));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn fullgame_purchased_is_false_unless_the_knob_is_set() {
|
||||
// A/B-control integrity: events-off must stay byte-identical to v1.
|
||||
for id in ["FULLGAME_PURCHASED", "FREETRIAL", "ANYTHING_ELSE"] {
|
||||
assert!(
|
||||
reply("GetGameInfo", &[("GameInfoId", id)])
|
||||
.contains(r#"GetGameInfoResponse GameInfo="false""#),
|
||||
"{id}"
|
||||
);
|
||||
}
|
||||
// ... and a GetGameInfo with no GameInfoId at all.
|
||||
assert!(reply("GetGameInfo", &[]).contains(r#"GameInfo="false""#));
|
||||
|
||||
let cfg = ProtocolConfig::from_vars(&env_of(&[("OPENFUT_LSX_FULLGAME", "1")]));
|
||||
let on = Responder::new(Identity::default(), cfg);
|
||||
assert!(on
|
||||
.build_reply(
|
||||
"7",
|
||||
"GetGameInfo",
|
||||
&[("GameInfoId", "FULLGAME_PURCHASED")].into_iter().collect(),
|
||||
None,
|
||||
""
|
||||
)
|
||||
.contains(r#"GameInfo="true""#));
|
||||
// Still only that one id flips.
|
||||
assert!(on
|
||||
.build_reply(
|
||||
"7",
|
||||
"GetGameInfo",
|
||||
&[("GameInfoId", "FREETRIAL")].into_iter().collect(),
|
||||
None,
|
||||
""
|
||||
)
|
||||
.contains(r#"GameInfo="false""#));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn fullgame_knob_follows_the_not_zero_rule() {
|
||||
for (value, on) in [("0", false), ("1", true), ("", true), ("false", true)] {
|
||||
let cfg = ProtocolConfig::from_vars(&env_of(&[("OPENFUT_LSX_FULLGAME", value)]));
|
||||
assert_eq!(cfg.fullgame_purchased, on, "OPENFUT_LSX_FULLGAME={value:?}");
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn settings() {
|
||||
for id in ["ENVIRONMENT", "environment", "EnvironmentName"] {
|
||||
assert!(
|
||||
reply("GetSetting", &[("SettingId", id)])
|
||||
.contains(r#"GetSettingResponse Setting="production""#),
|
||||
"{id}"
|
||||
);
|
||||
}
|
||||
assert!(reply("GetSetting", &[("SettingId", "LANGUAGE")])
|
||||
.contains(r#"GetSettingResponse Setting="en_US""#));
|
||||
assert!(reply("GetSetting", &[("SettingId", "WHATEVER")])
|
||||
.contains(r#"GetSettingResponse Setting="false""#));
|
||||
assert!(reply("GetSetting", &[]).contains(r#"Setting="false""#));
|
||||
|
||||
let ident = Identity::from_vars(&env_of(&[("FUT_LOCALE", "fr_FR")])).unwrap();
|
||||
assert!(Responder::new(ident, ProtocolConfig::default())
|
||||
.build_reply(
|
||||
"7",
|
||||
"GetSetting",
|
||||
&[("SettingId", "LANGUAGE")].into_iter().collect(),
|
||||
None,
|
||||
""
|
||||
)
|
||||
.contains(r#"Setting="fr_FR""#));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn config_is_empty_which_is_why_every_recipient_is_the_empty_string() {
|
||||
assert!(reply("GetConfig", &[]).contains(r#"GetConfigResponse Config="false""#));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn progressive_installation_is_unavailable() {
|
||||
assert!(reply("IsProgressiveInstallationAvailable", &[]).contains(
|
||||
r#"IsProgressiveInstallationAvailableResponse ItemId="" Available="false""#
|
||||
));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn unknown_verbs_fall_through_to_error_success() {
|
||||
assert_eq!(
|
||||
reply("GetSomethingWeHaveNeverSeen", &[]),
|
||||
r#"<LSX><Response id="7" sender=""><ErrorSuccess Code="0" Description=""/></Response></LSX>"#
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn the_response_sender_byte_equals_the_request_recipient() {
|
||||
let r = responder().build_reply("5", "GetProfile", &Attrs::new(), None, "EbisuSDK");
|
||||
assert!(r.starts_with(r#"<LSX><Response id="5" sender="EbisuSDK">"#), "{r}");
|
||||
// Including for the one verb built without the `resp` helper.
|
||||
let q = responder().build_reply("5", "QueryEntitlements", &Attrs::new(), None, "EbisuSDK");
|
||||
assert!(q.starts_with(r#"<LSX><Response id="5" sender="EbisuSDK">"#), "{q}");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn push_triggers() {
|
||||
assert_eq!(push_after("GetProfile"), Some("after GetProfile"));
|
||||
assert_eq!(
|
||||
push_after("GetInternetConnectedState"),
|
||||
Some("after GetInternetConnectedState")
|
||||
);
|
||||
assert_eq!(push_after("GetGameInfo"), Some("after GetGameInfo UPTODATE"));
|
||||
assert_eq!(push_after("GetConfig"), None);
|
||||
assert_eq!(push_after("GetAuthCode"), None);
|
||||
}
|
||||
|
||||
// -------------------------------------------------------------- redaction
|
||||
#[test]
|
||||
fn redacts_credential_attributes() {
|
||||
let safe = safe_xml_for_log(
|
||||
r#"<Thing AuthCode="a" AuthToken="b" SessionKey="c" Token="d" Sid="e" Keep="f"/>"#,
|
||||
);
|
||||
assert_eq!(
|
||||
safe,
|
||||
concat!(
|
||||
r#"<Thing AuthCode="[REDACTED]" AuthToken="[REDACTED]" "#,
|
||||
r#"SessionKey="[REDACTED]" Token="[REDACTED]" Sid="[REDACTED]" Keep="f"/>"#
|
||||
)
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn redacts_the_auth_code_element_generically() {
|
||||
let safe =
|
||||
safe_xml_for_log(r#"<AuthCode value="secret" Code="secret" Return="secret"/>"#);
|
||||
assert!(!safe.contains("secret"), "{safe}");
|
||||
assert_eq!(safe.matches("[REDACTED]").count(), 3, "{safe}");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn redacts_the_challenge_response() {
|
||||
let safe = safe_xml_for_log(
|
||||
r#"<LSX><Response id="1" sender="EALS"><ChallengeAccepted response="e4f5"/></Response></LSX>"#,
|
||||
);
|
||||
assert!(!safe.contains("e4f5"), "{safe}");
|
||||
assert!(safe.contains(r#"response="[REDACTED]""#), "{safe}");
|
||||
assert!(safe.contains(r#"id="1""#), "{safe}");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn leaves_ordinary_status_lines_readable() {
|
||||
let status = safe_xml_for_log(r#"<ErrorSuccess Code="0" Description=""/>"#);
|
||||
assert_eq!(status, r#"<ErrorSuccess Code="0" Description=""/>"#);
|
||||
// The element name alone must not trip the blanket pass.
|
||||
assert_eq!(
|
||||
safe_xml_for_log(r#"<GetConfigResponse Config="false"/>"#),
|
||||
r#"<GetConfigResponse Config="false"/>"#
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn redaction_is_case_insensitive_and_keeps_the_written_case() {
|
||||
assert_eq!(
|
||||
safe_xml_for_log(r#"<X authtoken="q" SID="r"/>"#),
|
||||
r#"<X authtoken="[REDACTED]" SID="[REDACTED]"/>"#
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn redaction_respects_word_boundaries() {
|
||||
// `MySid="x"` has no boundary before `Sid`, so it is left alone.
|
||||
assert_eq!(
|
||||
safe_xml_for_log(r#"<X MySid="x"/>"#),
|
||||
r#"<X MySid="x"/>"#
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn python_repr_of_strings() {
|
||||
assert_eq!(py_repr(""), "''");
|
||||
assert_eq!(py_repr("X"), "'X'");
|
||||
assert_eq!(py_repr("it's"), "\"it's\"");
|
||||
assert_eq!(py_repr("a\"b"), "'a\"b'");
|
||||
assert_eq!(py_repr("a\nb"), r"'a\nb'");
|
||||
assert_eq!(py_repr("a\\b"), r"'a\\b'");
|
||||
assert_eq!(Attrs::new().py_repr(), "{}");
|
||||
}
|
||||
}
|
||||
@@ -233,32 +233,11 @@ pub fn serve(cfg: RedirectorConfig) -> std::io::Result<()> {
|
||||
bind(cfg)?.run()
|
||||
}
|
||||
|
||||
/// What a peer did with the connection before any TLS was attempted.
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub enum PeerOpening {
|
||||
/// Connected and closed without sending anything: a reachability probe.
|
||||
ClosedWithoutSpeaking,
|
||||
/// Sent at least one byte, so a real handshake is under way.
|
||||
Spoke,
|
||||
/// Timed out or errored. Deliberately NOT treated as a probe — a slow or
|
||||
/// broken client must still reach the acceptor and produce a real
|
||||
/// diagnostic, because misclassifying a fault as a probe would hide
|
||||
/// precisely what this distinction exists to protect.
|
||||
Undetermined,
|
||||
}
|
||||
|
||||
/// Classify the result of peeking at the first byte.
|
||||
///
|
||||
/// Split out as a pure function so the policy is testable without a socket —
|
||||
/// the interesting cases (EOF vs timeout) are awkward to provoke live and easy
|
||||
/// to get backwards.
|
||||
pub fn classify_opening(peek: &std::io::Result<usize>) -> PeerOpening {
|
||||
match peek {
|
||||
Ok(0) => PeerOpening::ClosedWithoutSpeaking,
|
||||
Ok(_) => PeerOpening::Spoke,
|
||||
Err(_) => PeerOpening::Undetermined,
|
||||
}
|
||||
}
|
||||
/// Re-exported from the shared TLS crate. The classification policy now lives in
|
||||
/// `openfut-tls` so every FIFA-facing TLS host shares one implementation; this
|
||||
/// host keeps naming them here so its public API and `probe_classification`
|
||||
/// integration test are unaffected.
|
||||
pub use openfut_tls::{classify_opening, PeerOpening};
|
||||
|
||||
fn handle(
|
||||
stream: TcpStream,
|
||||
@@ -285,8 +264,7 @@ fn handle(
|
||||
// exactly how the certificate mismatch that cost three live gates
|
||||
// presented, so a benign probe forging it poisons the one channel this
|
||||
// project gates on. Classified here, the two are never confused again.
|
||||
let mut first = [0u8; 1];
|
||||
if classify_opening(&stream.peek(&mut first)) == PeerOpening::ClosedWithoutSpeaking {
|
||||
if openfut_tls::peer_opening(&stream) == PeerOpening::ClosedWithoutSpeaking {
|
||||
probes.fetch_add(1, std::sync::atomic::Ordering::Relaxed);
|
||||
log(&format!(
|
||||
"conn-{id:04} {peer} PROBE: closed before sending a ClientHello (not a TLS fault)"
|
||||
|
||||
@@ -43,7 +43,7 @@
|
||||
|
||||
use std::io::{Read, Write};
|
||||
use std::net::{TcpListener, TcpStream};
|
||||
use std::sync::atomic::{AtomicU64, Ordering};
|
||||
use std::sync::atomic::{AtomicU64, AtomicUsize, Ordering};
|
||||
use std::sync::Arc;
|
||||
use std::time::{SystemTime, UNIX_EPOCH};
|
||||
|
||||
@@ -52,7 +52,7 @@ use openfut_adapter_fifa17::roster::{self, Method};
|
||||
use openfut_http::drain_body;
|
||||
pub use openfut_http::BodyRead;
|
||||
// The acceptor comes from the shared crate, so this host never names OpenSSL.
|
||||
use openfut_tls::SslAcceptor;
|
||||
use openfut_tls::{peer_opening, PeerOpening, SslAcceptor};
|
||||
|
||||
pub mod config;
|
||||
pub use config::RosterConfig;
|
||||
@@ -112,6 +112,15 @@ pub struct ConnOutcome {
|
||||
|
||||
pub type Outcomes = Arc<std::sync::Mutex<Vec<ConnOutcome>>>;
|
||||
|
||||
/// How many bare port probes have been classified before reaching the acceptor.
|
||||
///
|
||||
/// Counted, not only logged, for the same reason [`ConnOutcome`] exists: a test
|
||||
/// that asserts on client-visible symptoms cannot tell a probe that was
|
||||
/// classified from one that merely failed quietly, so removing the
|
||||
/// classification would leave the suite green. This makes it assertable — and
|
||||
/// mirrors the redirector, the host that first needed the distinction.
|
||||
pub type ProbeCount = Arc<AtomicUsize>;
|
||||
|
||||
/// Bounded: a host polled every few seconds must not accumulate forever.
|
||||
const OUTCOME_HISTORY: usize = 64;
|
||||
|
||||
@@ -130,6 +139,7 @@ pub struct Server {
|
||||
acceptor: Arc<SslAcceptor>,
|
||||
cfg: Arc<RosterConfig>,
|
||||
outcomes: Outcomes,
|
||||
probes: ProbeCount,
|
||||
}
|
||||
|
||||
impl Server {
|
||||
@@ -137,6 +147,11 @@ impl Server {
|
||||
self.outcomes.clone()
|
||||
}
|
||||
|
||||
/// A handle to the bare-probe counter, obtainable before [`Server::run`].
|
||||
pub fn probes(&self) -> ProbeCount {
|
||||
self.probes.clone()
|
||||
}
|
||||
|
||||
pub fn run(self) -> std::io::Result<()> {
|
||||
let counter = AtomicU64::new(0);
|
||||
for incoming in self.listener.incoming() {
|
||||
@@ -144,7 +159,8 @@ impl Server {
|
||||
let id = counter.fetch_add(1, Ordering::Relaxed) + 1;
|
||||
let (acceptor, cfg) = (self.acceptor.clone(), self.cfg.clone());
|
||||
let outcomes = self.outcomes.clone();
|
||||
std::thread::spawn(move || handle(stream, id, &acceptor, &cfg, &outcomes));
|
||||
let probes = self.probes.clone();
|
||||
std::thread::spawn(move || handle(stream, id, &acceptor, &cfg, &outcomes, &probes));
|
||||
}
|
||||
Ok(())
|
||||
}
|
||||
@@ -184,6 +200,7 @@ pub fn bind(cfg: RosterConfig) -> std::io::Result<Server> {
|
||||
acceptor: Arc::new(acceptor),
|
||||
cfg: Arc::new(cfg),
|
||||
outcomes: Arc::new(std::sync::Mutex::new(Vec::new())),
|
||||
probes: ProbeCount::default(),
|
||||
})
|
||||
}
|
||||
|
||||
@@ -207,12 +224,25 @@ fn handle(
|
||||
acceptor: &SslAcceptor,
|
||||
cfg: &RosterConfig,
|
||||
outcomes: &Outcomes,
|
||||
probes: &ProbeCount,
|
||||
) {
|
||||
let peer = stream
|
||||
.peer_addr()
|
||||
.map(|a| a.to_string())
|
||||
.unwrap_or_else(|_| "?".into());
|
||||
|
||||
// Classify a bare port probe BEFORE the acceptor sees it. A `connect` then
|
||||
// drop (the launcher's preflight makes one per run) otherwise reaches the
|
||||
// acceptor as `unexpected EOF` — byte-identical to the certificate mismatch
|
||||
// that cost three live gates. Shared with the redirector via openfut-tls so
|
||||
// the two hosts can never diverge on this.
|
||||
if peer_opening(&stream) == PeerOpening::ClosedWithoutSpeaking {
|
||||
probes.fetch_add(1, Ordering::Relaxed);
|
||||
log(&format!(
|
||||
"conn-{id:04} {peer} PROBE: closed before sending a ClientHello (not a TLS fault)"
|
||||
));
|
||||
return;
|
||||
}
|
||||
let mut tls = match acceptor.accept(stream) {
|
||||
Ok(s) => s,
|
||||
Err(e) => {
|
||||
|
||||
@@ -0,0 +1,132 @@
|
||||
//! A bare port probe must not be reported as a TLS fault on the roster host.
|
||||
//!
|
||||
//! `TLS HANDSHAKE FAILED: ... unexpected EOF` is the exact signature the
|
||||
//! certificate mismatch produced — the defect that cost three live gate attempts
|
||||
//! and was invisible everywhere else. A reachability probe forges it trivially:
|
||||
//! `TcpStream::connect` then drop opens the connection and closes it without
|
||||
//! sending a byte, which the acceptor reports as `unexpected EOF`. The launcher's
|
||||
//! preflight makes such probes, so the roster host — like the redirector — must
|
||||
//! classify the opening before the acceptor sees it. The policy is shared via
|
||||
//! `openfut-tls`; this proves the roster host actually applies it.
|
||||
|
||||
use std::io::{Read, Write};
|
||||
use std::net::TcpStream;
|
||||
use std::sync::atomic::Ordering;
|
||||
use std::time::Duration;
|
||||
|
||||
use openfut_roster_host::{bind, RosterConfig};
|
||||
|
||||
fn cert_pair() -> (String, String) {
|
||||
let base = concat!(env!("CARGO_MANIFEST_DIR"), "/../fifa17-recon/tools");
|
||||
(
|
||||
format!("{base}/redir_cert.pem"),
|
||||
format!("{base}/redir_key.pem"),
|
||||
)
|
||||
}
|
||||
|
||||
/// Start a host on an ephemeral port; hand back its address and its counters.
|
||||
fn start() -> (
|
||||
std::net::SocketAddr,
|
||||
openfut_roster_host::ProbeCount,
|
||||
openfut_roster_host::Outcomes,
|
||||
) {
|
||||
let (c, k) = cert_pair();
|
||||
let server = bind(RosterConfig::for_test(&c, &k)).expect("host binds");
|
||||
let addr = server.local_addr;
|
||||
let (probes, outcomes) = (server.probes(), server.outcomes());
|
||||
std::thread::spawn(move || {
|
||||
let _ = server.run();
|
||||
});
|
||||
(addr, probes, outcomes)
|
||||
}
|
||||
|
||||
/// A FIFA-like client: legacy suites, no certificate checking. Sends a GET and
|
||||
/// reads the response to EOF.
|
||||
fn tls_get(addr: std::net::SocketAddr) -> Vec<u8> {
|
||||
use openfut_tls::{SslConnector, SslMethod, SslVerifyMode};
|
||||
let mut b = SslConnector::builder(SslMethod::tls()).expect("connector");
|
||||
b.set_cipher_list(openfut_adapter_fifa17::tls::OBSERVED_CLIENT_SUITES)
|
||||
.expect("ciphers");
|
||||
b.set_verify(SslVerifyMode::NONE);
|
||||
let sock = TcpStream::connect(addr).expect("connect");
|
||||
let ssl = b
|
||||
.build()
|
||||
.configure()
|
||||
.and_then(|c| c.verify_hostname(false).into_ssl("roster-test"))
|
||||
.expect("ssl");
|
||||
let mut s = openfut_tls::SslStream::new(ssl, sock).expect("stream");
|
||||
s.connect().expect("handshake");
|
||||
s.write_all(
|
||||
b"GET /fifa17/fut/rosterupdate.xml HTTP/1.1\r\nHost: roster-test\r\nAccept: */*\r\n\r\n",
|
||||
)
|
||||
.expect("write");
|
||||
s.flush().ok();
|
||||
let mut out = Vec::new();
|
||||
let _ = s.read_to_end(&mut out);
|
||||
out
|
||||
}
|
||||
|
||||
/// The whole point: connect, send nothing, close — classified as a probe rather
|
||||
/// than reaching the acceptor. Asserting on the counter (not on client-visible
|
||||
/// behaviour) is deliberate: a probe produces no response either way, so a test
|
||||
/// on what the client sees would pass with the classification deleted.
|
||||
#[test]
|
||||
fn a_bare_connect_and_close_is_classified_as_a_probe() {
|
||||
let (addr, probes, outcomes) = start();
|
||||
|
||||
drop(TcpStream::connect(addr).expect("probe connects"));
|
||||
std::thread::sleep(Duration::from_millis(200));
|
||||
|
||||
assert_eq!(
|
||||
probes.load(Ordering::Relaxed),
|
||||
1,
|
||||
"a connect-and-close was not classified as a probe"
|
||||
);
|
||||
assert!(
|
||||
outcomes.lock().expect("lock").is_empty(),
|
||||
"a probe must not be recorded as a served connection"
|
||||
);
|
||||
}
|
||||
|
||||
/// A probe must not disturb the host: the next real client still gets served.
|
||||
#[test]
|
||||
fn a_probe_does_not_break_the_connection_that_follows_it() {
|
||||
let (addr, probes, _outcomes) = start();
|
||||
|
||||
drop(TcpStream::connect(addr).expect("probe connects"));
|
||||
std::thread::sleep(Duration::from_millis(100));
|
||||
|
||||
let response = tls_get(addr);
|
||||
assert!(
|
||||
response.starts_with(b"HTTP/1.0 200"),
|
||||
"real client after a probe got: {:?}",
|
||||
String::from_utf8_lossy(response.get(..64).unwrap_or(&response))
|
||||
);
|
||||
assert_eq!(
|
||||
probes.load(Ordering::Relaxed),
|
||||
1,
|
||||
"the real client was miscounted as a probe"
|
||||
);
|
||||
}
|
||||
|
||||
/// The dangerous direction: a client that DOES speak and then fails must still
|
||||
/// reach the acceptor and be reported as a fault, not silently reclassified as a
|
||||
/// benign probe.
|
||||
#[test]
|
||||
fn a_client_that_speaks_then_fails_is_not_a_probe() {
|
||||
let (addr, probes, _outcomes) = start();
|
||||
|
||||
let mut sock = TcpStream::connect(addr).expect("connect");
|
||||
// One byte of nonsense: the peer has spoken, but it is not a ClientHello, so
|
||||
// the handshake genuinely fails.
|
||||
sock.write_all(&[0x16]).expect("write");
|
||||
sock.flush().ok();
|
||||
drop(sock);
|
||||
std::thread::sleep(Duration::from_millis(200));
|
||||
|
||||
assert_eq!(
|
||||
probes.load(Ordering::Relaxed),
|
||||
0,
|
||||
"a failing handshake was silently reclassified as a benign probe"
|
||||
);
|
||||
}
|
||||
@@ -54,6 +54,52 @@ impl fmt::Display for TlsError {
|
||||
|
||||
impl std::error::Error for TlsError {}
|
||||
|
||||
/// What a peer did with the connection before any TLS was attempted.
|
||||
///
|
||||
/// A bare reachability probe — `TcpStream::connect` then drop, which the
|
||||
/// launcher's preflight makes twice per run — opens the connection and closes
|
||||
/// without sending a byte. If that reaches the acceptor it fails as
|
||||
/// `unexpected EOF`, which is **byte-identical** to the signature of the
|
||||
/// certificate mismatch that cost three live gates. Classifying the opening
|
||||
/// before the acceptor sees it keeps a benign probe from forging a TLS fault in
|
||||
/// the one channel this project gates on. Every FIFA-facing TLS host shares this
|
||||
/// policy so the distinction can never regress in just one of them.
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub enum PeerOpening {
|
||||
/// Connected and closed without sending anything: a reachability probe.
|
||||
ClosedWithoutSpeaking,
|
||||
/// Sent at least one byte, so a real handshake is under way.
|
||||
Spoke,
|
||||
/// Timed out or errored. Deliberately NOT treated as a probe — a slow or
|
||||
/// broken client must still reach the acceptor and produce a real
|
||||
/// diagnostic, because misclassifying a fault as a probe would hide
|
||||
/// precisely what this distinction exists to protect.
|
||||
Undetermined,
|
||||
}
|
||||
|
||||
/// Classify the result of peeking at the first byte.
|
||||
///
|
||||
/// Split out as a pure function so the policy is testable without a socket —
|
||||
/// the interesting cases (EOF vs timeout) are awkward to provoke live and easy
|
||||
/// to get backwards.
|
||||
pub fn classify_opening(peek: &std::io::Result<usize>) -> PeerOpening {
|
||||
match peek {
|
||||
Ok(0) => PeerOpening::ClosedWithoutSpeaking,
|
||||
Ok(_) => PeerOpening::Spoke,
|
||||
Err(_) => PeerOpening::Undetermined,
|
||||
}
|
||||
}
|
||||
|
||||
/// Peek one byte to classify a connection before the TLS acceptor sees it.
|
||||
///
|
||||
/// `MSG_PEEK` leaves the byte in the receive queue, so a subsequent
|
||||
/// `acceptor.accept(stream)` reads the ClientHello intact — this is
|
||||
/// non-destructive for a real handshake and only short-circuits a bare probe.
|
||||
pub fn peer_opening(stream: &std::net::TcpStream) -> PeerOpening {
|
||||
let mut first = [0u8; 1];
|
||||
classify_opening(&stream.peek(&mut first))
|
||||
}
|
||||
|
||||
/// A TLS protocol version, expressed without an OpenSSL type.
|
||||
///
|
||||
/// Adapters name the version window their client was observed to use; keeping
|
||||
@@ -299,6 +345,19 @@ pub fn self_test(cfg: &TlsConfig, client_ciphers: &str, sni: &str) -> Result<Neg
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn classify_opening_maps_each_case() {
|
||||
// EOF before any byte is the reachability probe this exists to catch.
|
||||
assert_eq!(classify_opening(&Ok(0)), PeerOpening::ClosedWithoutSpeaking);
|
||||
assert_eq!(classify_opening(&Ok(1)), PeerOpening::Spoke);
|
||||
// A timeout must NOT be a probe: a slow or broken client still deserves
|
||||
// a real diagnostic from the acceptor, not a silent probe reclassification.
|
||||
assert_eq!(
|
||||
classify_opening(&Err(std::io::Error::from(std::io::ErrorKind::WouldBlock))),
|
||||
PeerOpening::Undetermined
|
||||
);
|
||||
}
|
||||
|
||||
/// A self-signed pair, generated here rather than borrowed from the game
|
||||
/// stack: this crate is game-independent and its tests must not depend on
|
||||
/// FIFA material. Adapter crates test their own profiles.
|
||||
|
||||
+35
-60
@@ -1,47 +1,51 @@
|
||||
# openfut-utas-host
|
||||
|
||||
The first live FIFA 17 **UTAS migration host**. It fronts the client-visible UTAS
|
||||
port and migrates one route at a time to OpenFUT Core, proxying everything else to
|
||||
the Python UTAS oracle so the rest of FUT keeps working unchanged.
|
||||
The FIFA 17 UTAS migration boundary. It accepts the client-visible HTTP surface,
|
||||
serves migrated routes from Rust/Core plus host-owned durable stores, and proxies only
|
||||
the unclassified tail to the Python behavioral oracle.
|
||||
|
||||
```
|
||||
FIFA 17 ──HTTP──▶ openfut-utas-host
|
||||
├── GET …/club ──▶ FIFA17 adapter ──▶ OpenFUT Core (/collection)
|
||||
└── everything else ──▶ Python UTAS oracle (verbatim reverse proxy)
|
||||
├── migrated route ──▶ Rust adapter / Core / host stores
|
||||
└── unclassified tail ──▶ Python UTAS oracle
|
||||
```
|
||||
|
||||
## What it owns / does not own
|
||||
|
||||
Owns: socket + HTTP/1.1 keep-alive transport, route classification, the Core
|
||||
access client, the Python passthrough, and diagnostics. It owns **no** game
|
||||
domain state — filtering/pagination is Core's; wire parsing/shaping is the
|
||||
adapter's. The adapter never learns how Core is reached (the architecture rule):
|
||||
the host holds the [`CoreAccess`] boundary (`GET {core_url}/collection?…` today).
|
||||
`src/lib.rs::classify` is the route-level source of truth. The current Rust surface
|
||||
includes club/squad/user reads, club rename, auth/session/client data, Store/economy,
|
||||
packs, owned-item moves, market/trade-pile, and the observed hub support routes.
|
||||
|
||||
## Safety model
|
||||
|
||||
- **Classification happens once, before execution.** Exact `GET /ut/game/<title>/club`
|
||||
→ Rust; everything else → Python. No shared path, no "try Rust then Python".
|
||||
- A Core failure on `/club` degrades to a valid empty `{"itemData":[]}` and logs
|
||||
an error — it never falls back to Python (which could double-apply a mutation on
|
||||
other routes). `/club` is read-only, but the rule is absolute.
|
||||
- Mutating routes (PUT/POST, `/squad`, `/purchased`, quick-sell, market, auth, SBC,
|
||||
`/club/stats/*`, `/clubUser`) all classify to passthrough and are untouched.
|
||||
- Classification happens exactly once before execution. There is no "try Rust then
|
||||
Python"; a mutation cannot be double-applied.
|
||||
- A route classified to Rust never falls back to Python on a Core/store/projection
|
||||
failure. Each handler uses its captured fail-closed or honest-empty wire contract.
|
||||
- `PUT …/club` and `PUT|POST …/user/club` atomically update the shared account JSON.
|
||||
Every input returns the required zero-atom `200 {}` response; rejection and
|
||||
persistence failures remain visible in logs.
|
||||
- Numeric `GET …/squad/<n>` returns the one Core-backed current squad, matching the
|
||||
Python oracle's single-current-squad behavior.
|
||||
- Python remains the behavioral oracle and rollback backend for routes not yet
|
||||
classified to Rust. New economy behavior belongs in Rust/Core, never Python.
|
||||
|
||||
## Configuration (env)
|
||||
|
||||
| Var | Required | Default | Meaning |
|
||||
|---|---|---|---|
|
||||
| `OPENFUT_UTAS_HOST_ADDR` | yes | — | where this host listens (client-visible UTAS addr) |
|
||||
| `OPENFUT_UTAS_PYTHON_URL` | yes | — | Python UTAS oracle base URL for fallback (must differ from this host) |
|
||||
| `OPENFUT_FIFA17_CATALOG` | yes | — | FIFA 17 card-definition identity catalog (`Fifa17CardCatalog` JSON: card id → asset id) |
|
||||
| `OPENFUT_IDENTITY_STORE` | yes | — | persistent external-identity store file (owned instance → stable wire id) |
|
||||
| `OPENFUT_PERSONA_ID` | yes | — | FIFA persona id stamped on `GET /squad/active` (must match the persona LSX/Blaze/POW/UTAS agree on) |
|
||||
| `OPENFUT_UTAS_HOST_ADDR` | yes | — | client-visible host listen address |
|
||||
| `OPENFUT_UTAS_PYTHON_URL` | yes | — | Python oracle base for the unclassified tail; must differ from this host |
|
||||
| `OPENFUT_FIFA17_CATALOG` | yes | — | FIFA 17 definition identity catalog |
|
||||
| `OPENFUT_IDENTITY_STORE` | yes | — | persistent owned-instance ↔ wire-id store |
|
||||
| `OPENFUT_PERSONA_ID` | yes | — | non-zero FIFA persona id shared by LSX/Blaze/POW/UTAS |
|
||||
| `OPENFUT_MARKET_DB` | yes | — | durable host-owned transfer-market SQLite DB |
|
||||
| `OPENFUT_PILE_DB` | yes | — | durable host-owned item-pile SQLite DB |
|
||||
| `OPENFUT_CORE_URL` | no | `http://127.0.0.1:8080` | OpenFUT Core base |
|
||||
| `OPENFUT_FIFA17_TABLES_DIR` | no | `fifa17-recon/data/tables` | `leagues/nations/teams.json` for id⇄name |
|
||||
| `OPENFUT_FIFA17_TABLES_DIR` | no | `fifa17-recon/data/tables` | FIFA entity tables |
|
||||
| `OPENFUT_CLIENTDATA_DB` | no | identity-store sibling `clientdata.json` | durable opaque client-data JSON |
|
||||
| `OPENFUT_ACCOUNT_PATH` | no | `FUT_ACCOUNT_PATH`, then identity-store sibling `active_account.json` | shared FIFA account/club JSON |
|
||||
|
||||
Startup **fails clearly** if the catalog or identity store cannot be loaded —
|
||||
there is no placeholder fallback (exactly one production identity path).
|
||||
Startup fails if required identity or durable economy state cannot be opened. No
|
||||
placeholder production identity source is substituted.
|
||||
|
||||
## Identity model (resolved)
|
||||
|
||||
@@ -61,39 +65,10 @@ conflated, are resolved by [`Fifa17IdentityResolver`] (the single production pat
|
||||
within `(fifa17, owned-item)` — no per-account column is needed because Core
|
||||
owned-instance ids are globally-unique UUIDs.
|
||||
|
||||
**Remaining prerequisite for a *rendering* retail `/club`:** Core inventory must
|
||||
reference cards that exist in the catalog. The catalog + store + resolver are
|
||||
built and tested; wiring a controlled real FIFA 17 dev-content inventory (the
|
||||
curated per-game dev pack) is the next slice. `rare=SP` ("Special") stays
|
||||
UNSUPPORTED (semantics unproven; parsed, reported, never guessed).
|
||||
|
||||
## Retail A/B runbook (first `/club` gate)
|
||||
|
||||
Change **only** the UTAS routing layer; keep the validated Rust Redirector/Roster
|
||||
and the current Blaze path. Python remains the rollback oracle — do not modify it.
|
||||
|
||||
Preconditions (mirror the proven blaze/roster switch discipline):
|
||||
1. `cargo test -p openfut-utas-host -p openfut-adapter-fifa17` green; `clippy -D warnings` clean; `fmt --check` clean.
|
||||
2. Built binary identity == HEAD (`scripts/verify-build-identity.sh`); no dirty tree.
|
||||
3. Python UTAS directly reachable; the Rust host directly probeable; no stale NAT/switch rules; FIFA fully closed.
|
||||
|
||||
Bring-up:
|
||||
1. Move Python UTAS to an alternate port (`FUT_PORT=8199` in the container/`openfut-fut.sh`); it keeps serving there.
|
||||
2. Start this host on the client-visible UTAS addr:
|
||||
`OPENFUT_UTAS_HOST_ADDR=<lan>:8099 OPENFUT_UTAS_PYTHON_URL=http://127.0.0.1:8199 OPENFUT_CORE_URL=http://127.0.0.1:8080 OPENFUT_FIFA17_CATALOG=<catalog.json> OPENFUT_IDENTITY_STORE=<store.json> OPENFUT_PERSONA_ID=33068179 openfut-utas-host`
|
||||
3. Launch FIFA → FUT → **My Squad** player picker and exercise: no-filter, position, nation, league, league+team, Gold+position, then scroll beyond page one.
|
||||
|
||||
Evidence to capture (all six):
|
||||
- **Switch**: client traffic hits the Rust host.
|
||||
- **Rust positive**: host log `owner=RUST route=club …` for the client IP.
|
||||
- **Python negative for /club**: Python logs no `/club` request in the window.
|
||||
- **Python positive for other UTAS**: unimplemented routes still reach Python.
|
||||
- **Core positive**: Core logs the `/collection` query and returns the expected set.
|
||||
- **Application + pagination**: the UI shows filtered results; later pages differ
|
||||
from page one (no repeated-first-page amplification).
|
||||
|
||||
Rollback: point the UTAS addr back at Python directly; confirm FUT still usable;
|
||||
then re-enable the host and confirm `/club` again (proves reversibility).
|
||||
Production has a frozen post-P1 baseline and a hot Python rollback. A source change
|
||||
passing local tests is **not** deployment approval. Build verification, staging, host
|
||||
restart, and live-client promotion remain operator-gated; the current state and
|
||||
promotion evidence live in the OpenFUT Obsidian vault.
|
||||
|
||||
Logs are safe by construction: no auth/session/device/token material — only owner,
|
||||
route, filter summary, counts, status.
|
||||
|
||||
@@ -12,6 +12,91 @@ entitlements (`unopenedPackIds`). `points` has **no** writer (read-only). EASFC
|
||||
Legend: **R** = Rust/Core authoritative, **P** = Python proxied (oracle).
|
||||
Evidence lines refer to `fifa17-recon/tools/{utas_server.py,fut_store.py}`.
|
||||
|
||||
|
||||
## Accepted URL prefixes (v1 + v2) — S2 fix
|
||||
|
||||
The retail FIFA 17 client issues the **Store family** under a `/ut/v2/game/<sku>/`
|
||||
prefix (live-observed `PUT /ut/v2/game/fifa17/store/transaction/0`), while other
|
||||
routes use `/ut/game/<sku>/`. `classify_economy` normalizes BOTH prefixes to the
|
||||
same tail (`ut_tail`), so economy ownership is prefix-agnostic. This closes the
|
||||
S2 live-staging defect where the v2 Store BUY escaped to Python.
|
||||
|
||||
| Route | Accepted method + path shapes (both prefixes) | Economy route |
|
||||
|---|---|---|
|
||||
| Credits | `GET (/ut/game\|/ut/v2/game)/<sku>/user/credits` | `Credits` |
|
||||
| Store catalogue | `GET …/store/purchasegroup[/…]` | `PurchaseGroup` |
|
||||
| **Store BUY** | `PUT …/store/transaction` **and** `PUT …/store/transaction/<txn-id>` (numeric, e.g. `…/store/transaction/0`) | `StoreBuy` |
|
||||
| **Pack open** | `POST …/purchased` **and** `POST …/purchased/items` | `PackOpen` |
|
||||
| **Pack reveal** | `GET …/purchased` **and** `GET …/purchased/items` | `PackReveal` |
|
||||
| Quick-sell (path) | `DELETE …/item/<digits>` | `QuickSellPath` |
|
||||
| Quick-sell (body) | `POST (/ut/delete/game\|/ut/v2/delete/game)/<sku>/item` | `QuickSellBody` |
|
||||
| Move | `PUT …/item` | `MoveItems` |
|
||||
| Match end | `POST (/ut/delete/game\|/ut/v2/delete/game)/<sku>/match` | `MatchEnd` |
|
||||
| Market list | `POST …/auctionhouse` \| `…/transfermarket` | `MarketList` |
|
||||
| Market query | `GET …/tradePile` **and** `…/tradePile/counts` (CASE-INSENSITIVE: `tradepile` too) | `MarketQuery` |
|
||||
| Market buy | `…/trade/<id>` | `MarketBuy` |
|
||||
| Market cancel | `DELETE (/ut/delete/game\|/ut/v2/delete/game)/<sku>/trade/<id>` | `MarketCancel` |
|
||||
|
||||
`store/transaction` matching is BOUNDED to a single all-digit id segment — it
|
||||
never absorbs `store/transactions`, `store/transactionfoo`, or
|
||||
`store/transaction/<id>/extra` (those proxy to Python as non-economy). Audit
|
||||
basis: Python route table `utas_server.py:1420` matches the store family
|
||||
"regardless of /ut/game vs /ut/v2/game prefix"; all other economy routes are
|
||||
`G = /ut/game/[^/]+`-prefixed (v1-only) and the retail client uses v1 for them.
|
||||
|
||||
### Round-2 fix (retail `/purchased/items` + `tradePile` case) — candidate supersedes `47ced22`
|
||||
|
||||
Live re-stage of `47ced22` showed the CONFIRMED retail Store BUY uses
|
||||
`POST /ut/game/fifa17/purchased/items` (reveal `GET …/purchased/items`), which the
|
||||
exact-tail `purchased` match missed → Python (Core coins unchanged = no debit). Fix:
|
||||
`is_purchased_tail` accepts `purchased` AND `purchased/items` (bounded: rejects
|
||||
`purchasedfoo`, `purchased/items/extra`); `is_tradepile_tail` matches the `tradepile`
|
||||
family case-insensitively (`tradePile`, `tradepile`, `…/counts`) since the FUT hub tile
|
||||
polls lowercase while the screen uses camelCase (oracle routes both via `re.I`). Audit
|
||||
basis: oracle `utas_server.py:1428` bare `/purchased` regex matches `/purchased/items`;
|
||||
`:1539-1540` `tradePile`/`tradePile/counts` are `re.I`. The full contract is the
|
||||
machine-auditable `retail_route_matrix` unit test + the `pure_economy_routes` dispatch
|
||||
matrix (NEVER-BOTH / no-fallback) + `retail_purchased_items_buy_debits_core_through_dispatch`.
|
||||
|
||||
## E1 — CUTOVER READY (barrier `93a46d4`, superproject source-ready; NOT deployed)
|
||||
|
||||
The economy authority barrier is committed: `Server::handle_with_ip` dispatches
|
||||
every economy route to Rust/Core (`try_handle_economy`) BEFORE `classify()`, and
|
||||
`from_config` (`43917a0`) attaches the economy services in production. Final
|
||||
per-route authority (all economy routes owner = Rust, Python proxy = NO):
|
||||
|
||||
| Route (method) | Owner | coins R/W | inv R/W | ent R/W | pile R/W | listing R/W | reveal | Py proxy | Rust handler / Core primitive |
|
||||
|---|---|---|---|---|---|---|---|---|---|
|
||||
| `/user/credits` (GET) | R | R/- | - | R/- | - | - | - | NO | `handle_credits` (`balance`+ent count) |
|
||||
| `/userMassInfo` (GET) | R (hybrid) | R/- | R/- | R/- | - | - | - | envelope only | `overlay_massinfo_economy`+squad (Py non-economy envelope only) |
|
||||
| `/store/purchasegroup` (GET) | R | R/- | - | R/- | - | - | - | NO | `handle_purchasegroup` full-gen + `StoreMode` |
|
||||
| `/store/transaction` (PUT) | R | -/R | -/R | - | -/R | - | R | NO | `handle_store_buy` → `purchase_items` |
|
||||
| `/purchased` (POST) | R | -/R | -/R | -/R | -/R | - | R | NO | `handle_pack_open` → `redeem_entitlement`/mint |
|
||||
| `/purchased` (GET) | R | - | R/- | - | R/- | - | R | NO | `shape_purchased_reveal` (pile+inventory) |
|
||||
| `/item/<id>` (DELETE) | R | -/R | -/R | - | - | - | - | NO | `handle_quick_sell_path` → `sell_item` |
|
||||
| `/ut/delete/…/item` (POST) | R | -/R | -/R | - | - | - | - | NO | `handle_quick_sell_body` → `sell_item` |
|
||||
| `/item` (PUT) | R | - | R/- | - | -/R | - | - | NO | `handle_move_items` (PileStore) |
|
||||
| `/ut/delete/…/match` (POST) | R | -/R | - | - | - | - | - | NO | `handle_match_end` → `grant_reward` |
|
||||
| `/auctionhouse`,`/transfermarket` | R | R/- | - | - | - | -/R | - | NO | `handle_market_list` (MarketStore) |
|
||||
| `/tradePile` (GET) | R | R/- | - | - | - | R/- | - | NO | `handle_market_query` |
|
||||
| `/trade/<id>` (POST/PUT/GET) | R | R/R | -/R | - | - | R/R | - | NO | `handle_market_buy` → `purchase_item` |
|
||||
| `/ut/delete/…/trade/<id>` (DELETE) | R | - | - | - | - | -/R | - | NO | `handle_market_cancel` |
|
||||
|
||||
`/ut/auth`, `/openfut/fifa17/capability`, `/club`, `/squad/*` are NOT economy
|
||||
routes (classify_economy → None) and are unchanged. `userMassInfo` is the one
|
||||
intentional hybrid: Python supplies the non-economy envelope, Rust overlays the
|
||||
squad AND the economy fields — no Python economy value is authoritative/visible.
|
||||
|
||||
**Proofs (all green, source-ready):** differential 15 PARITY + 1
|
||||
DIFFERENT-BY-DESIGN (market second-buy: Rust single-debit ledger vs oracle
|
||||
stateless re-debit; compat NONE); host concurrency 8 races × 50 iters; failure
|
||||
injection 10 cases incl. complete-sale-after-commit = SAFE (listing left
|
||||
`reserved`, not buyable; one debit + one mint; no E3); importer
|
||||
dry-run/apply/restart/idempotency/conflict; `from_config` E2E + restart;
|
||||
NEVER-BOTH (economy routes → Rust, Python proxy count 0); no-fallback (dead Core
|
||||
→ 503, proxy count 0); stale-reader (Core values only, Python 111 never visible).
|
||||
Python source byte-unchanged; oracle suite 32/32 green.
|
||||
|
||||
## Writer routes (mutate cluster state)
|
||||
|
||||
| Route | Method | Python handler | Writes | Current | Target | Core primitive |
|
||||
|
||||
@@ -0,0 +1,372 @@
|
||||
//! Durable FIFA 17 club identity backed by the shared `fut_account.json` shape.
|
||||
//!
|
||||
//! The Python oracle and the launcher use snake-case keys in one account file.
|
||||
//! Rust owns the rename mutation now, but preserves every unrelated account key
|
||||
//! so Blaze/POW and rollback keep reading the same source of truth.
|
||||
|
||||
use std::fs::{self, OpenOptions};
|
||||
use std::io::Write;
|
||||
use std::os::unix::fs::MetadataExt;
|
||||
use std::path::{Path, PathBuf};
|
||||
use std::sync::atomic::{AtomicU64, Ordering};
|
||||
|
||||
use parking_lot::Mutex;
|
||||
use serde_json::{Map, Value};
|
||||
|
||||
pub const DEFAULT_CLUB_NAME: &str = "OpenFUT";
|
||||
pub const DEFAULT_CLUB_ABBR: &str = "OFC";
|
||||
pub const DEFAULT_ESTABLISHED: &str = "2026";
|
||||
|
||||
const CLUB_NAME_MIN: usize = 5;
|
||||
const CLUB_NAME_MAX: usize = 15;
|
||||
const CLUB_ABBR_MIN: usize = 1;
|
||||
const CLUB_ABBR_MAX: usize = 3;
|
||||
|
||||
/// The FIFA-facing club fields read by `user`, `userMassInfo`, and account sync.
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub struct ClubIdentity {
|
||||
pub name: String,
|
||||
pub abbr: String,
|
||||
pub established: String,
|
||||
}
|
||||
|
||||
type FileSignature = (u64, u64, i64, i64, u64);
|
||||
|
||||
#[derive(Debug)]
|
||||
struct AccountState {
|
||||
raw: Map<String, Value>,
|
||||
club: ClubIdentity,
|
||||
signature: Option<FileSignature>,
|
||||
}
|
||||
|
||||
/// Result of applying a rename body. Every result maps to the protocol's `200 {}`;
|
||||
/// the distinction exists for logging and tests, not for changing wire behavior.
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub enum RenameOutcome {
|
||||
Updated,
|
||||
Unchanged,
|
||||
Rejected(&'static str),
|
||||
PersistFailed(String),
|
||||
}
|
||||
|
||||
/// Thread-safe account state persisted by atomic replacement on a valid rename.
|
||||
pub struct AccountStore {
|
||||
path: PathBuf,
|
||||
state: Mutex<AccountState>,
|
||||
}
|
||||
|
||||
impl AccountStore {
|
||||
/// Load the shared account file. Missing or malformed files use the proven
|
||||
/// production defaults; the first valid rename creates/repairs the file.
|
||||
pub fn open(path: impl Into<PathBuf>) -> Self {
|
||||
let path = path.into();
|
||||
let raw = read_raw(&path);
|
||||
let club = club_from_raw(&raw);
|
||||
let signature = file_signature(&path);
|
||||
Self {
|
||||
path,
|
||||
state: Mutex::new(AccountState {
|
||||
raw,
|
||||
club,
|
||||
signature,
|
||||
}),
|
||||
}
|
||||
}
|
||||
|
||||
pub fn club(&self) -> ClubIdentity {
|
||||
let mut state = self.state.lock();
|
||||
self.refresh_if_changed(&mut state);
|
||||
state.club.clone()
|
||||
}
|
||||
|
||||
/// Apply `{clubName, clubAbbr}` with the exact Python-oracle semantics:
|
||||
/// either field may be omitted/null, invalid input is ignored, and the caller
|
||||
/// always acknowledges with `200 {}`. A valid change is durable before it
|
||||
/// becomes visible to Rust readers.
|
||||
pub fn rename_from_body(&self, body: &[u8]) -> RenameOutcome {
|
||||
let value: Value = match serde_json::from_slice(body) {
|
||||
Ok(value) => value,
|
||||
Err(_) => return RenameOutcome::Rejected("malformed_json"),
|
||||
};
|
||||
let Value::Object(request) = value else {
|
||||
return RenameOutcome::Rejected("body_not_object");
|
||||
};
|
||||
|
||||
let mut state = self.state.lock();
|
||||
self.refresh_if_changed(&mut state);
|
||||
let name = match optional_string(&request, "clubName") {
|
||||
Ok(Some(value)) => value.trim().to_owned(),
|
||||
Ok(None) => state.club.name.clone(),
|
||||
Err(()) => return RenameOutcome::Rejected("club_name_not_string"),
|
||||
};
|
||||
let abbr = match optional_string(&request, "clubAbbr") {
|
||||
Ok(Some(value)) => value.trim().to_owned(),
|
||||
Ok(None) => state.club.abbr.clone(),
|
||||
Err(()) => return RenameOutcome::Rejected("club_abbr_not_string"),
|
||||
};
|
||||
|
||||
if !valid_name(&name) {
|
||||
return RenameOutcome::Rejected("club_name_length");
|
||||
}
|
||||
if !valid_abbr(&abbr) {
|
||||
return RenameOutcome::Rejected("club_abbr_length");
|
||||
}
|
||||
if name == state.club.name && abbr == state.club.abbr {
|
||||
return RenameOutcome::Unchanged;
|
||||
}
|
||||
|
||||
let mut updated = state.raw.clone();
|
||||
updated.insert("club_name".into(), Value::String(name.clone()));
|
||||
updated.insert("club_abbr".into(), Value::String(abbr.clone()));
|
||||
let bytes = match serde_json::to_vec_pretty(&updated) {
|
||||
Ok(bytes) => bytes,
|
||||
Err(error) => return RenameOutcome::PersistFailed(error.to_string()),
|
||||
};
|
||||
if let Err(error) = persist_atomically(&self.path, &bytes) {
|
||||
return RenameOutcome::PersistFailed(error.to_string());
|
||||
}
|
||||
|
||||
state.raw = updated;
|
||||
state.club.name = name;
|
||||
state.club.abbr = abbr;
|
||||
state.signature = file_signature(&self.path);
|
||||
RenameOutcome::Updated
|
||||
}
|
||||
|
||||
fn refresh_if_changed(&self, state: &mut AccountState) {
|
||||
let signature = file_signature(&self.path);
|
||||
if signature == state.signature {
|
||||
return;
|
||||
}
|
||||
let raw = read_raw(&self.path);
|
||||
state.club = club_from_raw(&raw);
|
||||
state.raw = raw;
|
||||
state.signature = file_signature(&self.path);
|
||||
}
|
||||
}
|
||||
|
||||
fn read_raw(path: &Path) -> Map<String, Value> {
|
||||
fs::read(path)
|
||||
.ok()
|
||||
.and_then(|bytes| serde_json::from_slice(&bytes).ok())
|
||||
.unwrap_or_default()
|
||||
}
|
||||
|
||||
fn club_from_raw(raw: &Map<String, Value>) -> ClubIdentity {
|
||||
ClubIdentity {
|
||||
name: valid_stored(raw, "club_name", valid_name)
|
||||
.unwrap_or(DEFAULT_CLUB_NAME)
|
||||
.to_owned(),
|
||||
abbr: valid_stored(raw, "club_abbr", valid_abbr)
|
||||
.unwrap_or(DEFAULT_CLUB_ABBR)
|
||||
.to_owned(),
|
||||
established: stored_established(raw).unwrap_or_else(|| DEFAULT_ESTABLISHED.to_owned()),
|
||||
}
|
||||
}
|
||||
|
||||
fn file_signature(path: &Path) -> Option<FileSignature> {
|
||||
let metadata = fs::metadata(path).ok()?;
|
||||
Some((
|
||||
metadata.dev(),
|
||||
metadata.ino(),
|
||||
metadata.mtime(),
|
||||
metadata.mtime_nsec(),
|
||||
metadata.len(),
|
||||
))
|
||||
}
|
||||
|
||||
fn optional_string<'a>(object: &'a Map<String, Value>, key: &str) -> Result<Option<&'a str>, ()> {
|
||||
match object.get(key) {
|
||||
None | Some(Value::Null) => Ok(None),
|
||||
Some(Value::String(value)) => Ok(Some(value)),
|
||||
Some(_) => Err(()),
|
||||
}
|
||||
}
|
||||
|
||||
fn valid_stored<'a>(
|
||||
raw: &'a Map<String, Value>,
|
||||
key: &str,
|
||||
valid: fn(&str) -> bool,
|
||||
) -> Option<&'a str> {
|
||||
raw.get(key)
|
||||
.and_then(Value::as_str)
|
||||
.filter(|value| valid(value))
|
||||
}
|
||||
|
||||
fn stored_established(raw: &Map<String, Value>) -> Option<String> {
|
||||
match raw.get("established")? {
|
||||
Value::String(value) if valid_established(value) => Some(value.clone()),
|
||||
Value::Number(value) => value.as_u64().map(|year| year.to_string()),
|
||||
_ => None,
|
||||
}
|
||||
}
|
||||
|
||||
fn valid_name(value: &str) -> bool {
|
||||
let len = value.chars().count();
|
||||
(CLUB_NAME_MIN..=CLUB_NAME_MAX).contains(&len) && value == value.trim()
|
||||
}
|
||||
|
||||
fn valid_abbr(value: &str) -> bool {
|
||||
let len = value.chars().count();
|
||||
(CLUB_ABBR_MIN..=CLUB_ABBR_MAX).contains(&len) && value == value.trim()
|
||||
}
|
||||
|
||||
fn valid_established(value: &str) -> bool {
|
||||
!value.is_empty() && value.bytes().all(|byte| byte.is_ascii_digit())
|
||||
}
|
||||
|
||||
fn persist_atomically(path: &Path, bytes: &[u8]) -> std::io::Result<()> {
|
||||
if let Some(parent) = path
|
||||
.parent()
|
||||
.filter(|parent| !parent.as_os_str().is_empty())
|
||||
{
|
||||
fs::create_dir_all(parent)?;
|
||||
}
|
||||
static COUNTER: AtomicU64 = AtomicU64::new(0);
|
||||
let temp = path.with_extension(format!(
|
||||
"openfut-tmp-{}-{}",
|
||||
std::process::id(),
|
||||
COUNTER.fetch_add(1, Ordering::Relaxed)
|
||||
));
|
||||
let result = (|| {
|
||||
let mut file = OpenOptions::new()
|
||||
.write(true)
|
||||
.create_new(true)
|
||||
.open(&temp)?;
|
||||
file.write_all(bytes)?;
|
||||
file.sync_all()?;
|
||||
drop(file);
|
||||
fs::rename(&temp, path)
|
||||
})();
|
||||
if result.is_err() {
|
||||
let _ = fs::remove_file(&temp);
|
||||
}
|
||||
result
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
use serde_json::json;
|
||||
|
||||
fn temp_path(tag: &str) -> PathBuf {
|
||||
std::env::temp_dir().join(format!(
|
||||
"openfut-account-store-{}-{tag}.json",
|
||||
std::process::id()
|
||||
))
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn valid_rename_preserves_unrelated_account_fields_and_reopens() {
|
||||
let path = temp_path("persist");
|
||||
let _ = fs::remove_file(&path);
|
||||
fs::write(
|
||||
&path,
|
||||
serde_json::to_vec(&json!({
|
||||
"persona_id": 33068179,
|
||||
"persona_name": "CAGE",
|
||||
"club_name": "OpenFUT",
|
||||
"club_abbr": "OFC",
|
||||
"established": 2016,
|
||||
"pow_level": 7
|
||||
}))
|
||||
.unwrap(),
|
||||
)
|
||||
.unwrap();
|
||||
|
||||
let store = AccountStore::open(&path);
|
||||
assert_eq!(
|
||||
store.rename_from_body(br#"{"clubName":" Real FUT ","clubAbbr":"RF"}"#),
|
||||
RenameOutcome::Updated
|
||||
);
|
||||
assert_eq!(
|
||||
store.club(),
|
||||
ClubIdentity {
|
||||
name: "Real FUT".into(),
|
||||
abbr: "RF".into(),
|
||||
established: "2016".into()
|
||||
}
|
||||
);
|
||||
|
||||
let raw: Value = serde_json::from_slice(&fs::read(&path).unwrap()).unwrap();
|
||||
assert_eq!(raw["persona_id"], 33_068_179);
|
||||
assert_eq!(raw["persona_name"], "CAGE");
|
||||
assert_eq!(raw["pow_level"], 7);
|
||||
assert_eq!(raw["club_name"], "Real FUT");
|
||||
assert_eq!(raw["club_abbr"], "RF");
|
||||
assert_eq!(AccountStore::open(&path).club(), store.club());
|
||||
let _ = fs::remove_file(path);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn external_atomic_replacement_is_reloaded_before_read_and_rename() {
|
||||
let path = temp_path("external-replace");
|
||||
let _ = fs::remove_file(&path);
|
||||
fs::write(
|
||||
&path,
|
||||
serde_json::to_vec(&json!({
|
||||
"club_name": "OpenFUT",
|
||||
"club_abbr": "OFC",
|
||||
"pow_level": 7
|
||||
}))
|
||||
.unwrap(),
|
||||
)
|
||||
.unwrap();
|
||||
let store = AccountStore::open(&path);
|
||||
|
||||
let replacement = serde_json::to_vec(&json!({
|
||||
"club_name": "Other Club",
|
||||
"club_abbr": "OC",
|
||||
"established": "2015",
|
||||
"pow_level": 11
|
||||
}))
|
||||
.unwrap();
|
||||
persist_atomically(&path, &replacement).unwrap();
|
||||
assert_eq!(
|
||||
store.club(),
|
||||
ClubIdentity {
|
||||
name: "Other Club".into(),
|
||||
abbr: "OC".into(),
|
||||
established: "2015".into()
|
||||
}
|
||||
);
|
||||
|
||||
assert_eq!(
|
||||
store.rename_from_body(br#"{"clubName":"Third Club"}"#),
|
||||
RenameOutcome::Updated
|
||||
);
|
||||
let raw: Value = serde_json::from_slice(&fs::read(&path).unwrap()).unwrap();
|
||||
assert_eq!(raw["club_name"], "Third Club");
|
||||
assert_eq!(raw["club_abbr"], "OC");
|
||||
assert_eq!(raw["pow_level"], 11);
|
||||
let _ = fs::remove_file(path);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn partial_invalid_and_malformed_renames_match_oracle_no_change_semantics() {
|
||||
let path = temp_path("reject");
|
||||
let _ = fs::remove_file(&path);
|
||||
let store = AccountStore::open(&path);
|
||||
|
||||
assert_eq!(
|
||||
store.rename_from_body(br#"{"clubName":"Open FUT"}"#),
|
||||
RenameOutcome::Updated
|
||||
);
|
||||
assert_eq!(store.club().abbr, DEFAULT_CLUB_ABBR);
|
||||
let before = store.club();
|
||||
assert_eq!(
|
||||
store.rename_from_body(br#"{"clubName":"x","clubAbbr":"TOOLONG"}"#),
|
||||
RenameOutcome::Rejected("club_name_length")
|
||||
);
|
||||
assert_eq!(
|
||||
store.rename_from_body(br#"{"clubName":3}"#),
|
||||
RenameOutcome::Rejected("club_name_not_string")
|
||||
);
|
||||
assert_eq!(
|
||||
store.rename_from_body(b"not-json"),
|
||||
RenameOutcome::Rejected("malformed_json")
|
||||
);
|
||||
assert_eq!(store.club(), before);
|
||||
let _ = fs::remove_file(path);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,189 @@
|
||||
//! STAGING-ONLY: complete a market sale on behalf of a synthetic Buyer B.
|
||||
//!
|
||||
//! Production has no trigger that decides "your listing sold" — that needs the
|
||||
//! seller-facing sold wire contract, which is exactly what the staging experiment
|
||||
//! is trying to establish. This binary is the synthetic counterparty: it runs the
|
||||
//! REAL settlement path (`CoreEconomy::settle_sale` → Core's atomic
|
||||
//! `POST /economy/settle-sale`) and then flips the host's listing to `sold`, so the
|
||||
//! seller's client sees an authentic completed sale rather than a hand-written row.
|
||||
//!
|
||||
//! It is a separate binary precisely so no production HTTP surface grows an
|
||||
//! experiment hook. It is never deployed and never runs in production.
|
||||
//!
|
||||
//! Ordering is deliberate: **settle first, mark sold second.** If settlement fails
|
||||
//! the listing stays live and nothing has moved. If marking fails after a
|
||||
//! successful settlement, the coins and ownership are already correct and the
|
||||
//! listing is merely still shown as active — recoverable, and it never pays twice
|
||||
//! because `mark_sold` is a once-only transition and clearing is presentation-only.
|
||||
//!
|
||||
//! ```text
|
||||
//! staging-sell --market-db PATH --core-url URL --trade-id ID \
|
||||
//! --item CORE_ITEM_ID --seller CLUB --buyer CLUB [--gross N]
|
||||
//! ```
|
||||
//! `--gross` defaults to 150, the canonical staging sale.
|
||||
|
||||
use openfut_utas_host::market_store::MarketStore;
|
||||
use openfut_utas_host::{CoreEconomy, EconomySale, HttpCoreClient};
|
||||
|
||||
/// FIFA 17's transfer fee, taken from the adapter so this harness can never
|
||||
/// disagree with the shipped policy about what the seller is owed.
|
||||
fn fee_for(gross: i64) -> i64 {
|
||||
openfut_adapter_fifa17::fut::economy_policy::transfer_market_fee(gross)
|
||||
}
|
||||
|
||||
struct Args {
|
||||
market_db: String,
|
||||
core_url: String,
|
||||
trade_id: String,
|
||||
item: String,
|
||||
seller: String,
|
||||
buyer: String,
|
||||
gross: i64,
|
||||
}
|
||||
|
||||
fn parse_args() -> Result<Args, String> {
|
||||
let mut market_db = None;
|
||||
let mut core_url = None;
|
||||
let mut trade_id = None;
|
||||
let mut item = None;
|
||||
let mut seller = None;
|
||||
let mut buyer = None;
|
||||
let mut gross = 150i64;
|
||||
let argv: Vec<String> = std::env::args().skip(1).collect();
|
||||
let mut i = 0;
|
||||
while i < argv.len() {
|
||||
let need = |i: usize| -> Result<String, String> {
|
||||
argv.get(i + 1)
|
||||
.cloned()
|
||||
.ok_or_else(|| format!("{} needs a value", argv[i]))
|
||||
};
|
||||
match argv[i].as_str() {
|
||||
"--market-db" => market_db = Some(need(i)?),
|
||||
"--core-url" => core_url = Some(need(i)?),
|
||||
"--trade-id" => trade_id = Some(need(i)?),
|
||||
"--item" => item = Some(need(i)?),
|
||||
"--seller" => seller = Some(need(i)?),
|
||||
"--buyer" => buyer = Some(need(i)?),
|
||||
"--gross" => gross = need(i)?.parse().map_err(|e| format!("--gross: {e}"))?,
|
||||
other => return Err(format!("unknown argument {other}")),
|
||||
}
|
||||
i += 2;
|
||||
}
|
||||
Ok(Args {
|
||||
market_db: market_db.ok_or("--market-db is required")?,
|
||||
core_url: core_url.ok_or("--core-url is required")?,
|
||||
trade_id: trade_id.ok_or("--trade-id is required")?,
|
||||
item: item.ok_or("--item is required")?,
|
||||
seller: seller.ok_or("--seller is required")?,
|
||||
buyer: buyer.ok_or("--buyer is required")?,
|
||||
gross,
|
||||
})
|
||||
}
|
||||
|
||||
fn main() {
|
||||
let args = match parse_args() {
|
||||
Ok(a) => a,
|
||||
Err(e) => {
|
||||
eprintln!("staging-sell: {e}");
|
||||
eprintln!(
|
||||
"usage: staging-sell --market-db PATH --core-url URL --trade-id ID \
|
||||
--item CORE_ITEM_ID --seller CLUB --buyer CLUB [--gross N]"
|
||||
);
|
||||
std::process::exit(2);
|
||||
}
|
||||
};
|
||||
|
||||
// Refuse to run against anything that looks like production state. This binary
|
||||
// exists to keep an experiment isolated, so the guard belongs here rather than
|
||||
// only in the caller.
|
||||
for (label, value) in [
|
||||
("--market-db", &args.market_db),
|
||||
("--core-url", &args.core_url),
|
||||
] {
|
||||
if value.contains("openfut-promotion")
|
||||
|| value.contains(":18080")
|
||||
|| value.contains(":8099")
|
||||
{
|
||||
eprintln!("staging-sell: REFUSING to touch production via {label}={value}");
|
||||
std::process::exit(3);
|
||||
}
|
||||
}
|
||||
|
||||
let fee = fee_for(args.gross);
|
||||
let proceeds = args.gross - fee;
|
||||
println!(
|
||||
"staging-sell: gross={} fee={} proceeds={} (floor 5%, fee+proceeds==gross)",
|
||||
args.gross, fee, proceeds
|
||||
);
|
||||
|
||||
let core = HttpCoreClient::new(args.core_url.clone(), "fifa17");
|
||||
let sale = EconomySale {
|
||||
item_id: &args.item,
|
||||
seller_club_id: Some(&args.seller),
|
||||
buyer_club_id: Some(&args.buyer),
|
||||
gross: args.gross,
|
||||
fee,
|
||||
};
|
||||
|
||||
// 1. Settle atomically in Core: buyer debited, item transferred, seller paid net.
|
||||
let receipt = match core.settle_sale(&sale) {
|
||||
Ok(r) => r,
|
||||
Err(e) => {
|
||||
eprintln!("staging-sell: settlement FAILED, listing left live: {e:?}");
|
||||
std::process::exit(1);
|
||||
}
|
||||
};
|
||||
println!(
|
||||
"staging-sell: SETTLED item={} card={} seller={} -> buyer={:?} \
|
||||
seller_balance={} buyer_balance={:?} squad_slots_freed={}",
|
||||
receipt.item_id,
|
||||
receipt.card_id,
|
||||
receipt.seller_club_id,
|
||||
receipt.buyer_club_id,
|
||||
receipt.seller_balance,
|
||||
receipt.buyer_balance,
|
||||
receipt.squad_slots_freed
|
||||
);
|
||||
|
||||
// 2. Only now does the seller's listing become `sold`, so the client can be
|
||||
// shown a completed sale.
|
||||
let rt = match tokio::runtime::Builder::new_current_thread()
|
||||
.enable_all()
|
||||
.build()
|
||||
{
|
||||
Ok(rt) => rt,
|
||||
Err(e) => {
|
||||
eprintln!("staging-sell: runtime: {e} (settlement already committed)");
|
||||
std::process::exit(1);
|
||||
}
|
||||
};
|
||||
rt.block_on(async {
|
||||
let store = match MarketStore::open(&args.market_db).await {
|
||||
Ok(s) => s,
|
||||
Err(e) => {
|
||||
eprintln!(
|
||||
"staging-sell: market store {} failed to open: {e} \
|
||||
(settlement already committed — coins/ownership are correct)",
|
||||
args.market_db
|
||||
);
|
||||
std::process::exit(1);
|
||||
}
|
||||
};
|
||||
match store.mark_sold(&args.trade_id).await {
|
||||
Ok(true) => println!("staging-sell: listing {} -> sold", args.trade_id),
|
||||
Ok(false) => println!(
|
||||
"staging-sell: listing {} was NOT live (already sold/cancelled) — \
|
||||
no second sale, nothing changed",
|
||||
args.trade_id
|
||||
),
|
||||
Err(e) => {
|
||||
eprintln!("staging-sell: mark_sold failed: {e}");
|
||||
std::process::exit(1);
|
||||
}
|
||||
}
|
||||
match store.uncleared_sold().await {
|
||||
Ok(rows) => println!("staging-sell: uncleared sold rows now {}", rows.len()),
|
||||
Err(e) => eprintln!("staging-sell: uncleared_sold read failed: {e}"),
|
||||
}
|
||||
});
|
||||
}
|
||||
@@ -0,0 +1,105 @@
|
||||
//! Durable FIFA 17 **client-data blob** store (`clientdata` / `userHubData`).
|
||||
//!
|
||||
//! FIFA persists opaque per-user client blobs via `PUT/POST …/clientdata/<key>`
|
||||
//! and reads them back via `GET …/clientdata/<key>`. The blobs are entirely
|
||||
//! client-defined (UI/hub state) — the server only round-trips them and never
|
||||
//! interprets their contents. This store keeps them in memory keyed by
|
||||
//! `<persona>:<key>` and persists the whole map to a JSON file on every write, so
|
||||
//! the client's saved state survives a host restart.
|
||||
//!
|
||||
//! The blobs are non-authoritative client presentation state (NOT economy or
|
||||
//! ownership), so a missing/unreadable backing file starts empty rather than
|
||||
//! being a hard failure.
|
||||
|
||||
use std::collections::HashMap;
|
||||
use std::path::PathBuf;
|
||||
|
||||
use parking_lot::Mutex;
|
||||
use serde_json::Value;
|
||||
|
||||
/// In-memory client-data blobs, persisted to a JSON file on write.
|
||||
pub struct ClientDataStore {
|
||||
path: PathBuf,
|
||||
map: Mutex<HashMap<String, Value>>,
|
||||
}
|
||||
|
||||
impl ClientDataStore {
|
||||
/// Open the store, loading any previously-persisted blobs. A missing or
|
||||
/// unreadable file starts empty.
|
||||
pub fn open(path: impl Into<PathBuf>) -> Self {
|
||||
let path = path.into();
|
||||
let map = std::fs::read(&path)
|
||||
.ok()
|
||||
.and_then(|b| serde_json::from_slice::<HashMap<String, Value>>(&b).ok())
|
||||
.unwrap_or_default();
|
||||
ClientDataStore {
|
||||
path,
|
||||
map: Mutex::new(map),
|
||||
}
|
||||
}
|
||||
|
||||
fn compound_key(persona: i64, key: &str) -> String {
|
||||
format!("{persona}:{key}")
|
||||
}
|
||||
|
||||
/// The stored blob for `<persona>:<key>`, or `None` if never written.
|
||||
pub fn get(&self, persona: i64, key: &str) -> Option<Value> {
|
||||
self.map
|
||||
.lock()
|
||||
.get(&Self::compound_key(persona, key))
|
||||
.cloned()
|
||||
}
|
||||
|
||||
/// Store `value` under `<persona>:<key>` and persist the whole map to disk.
|
||||
/// The serialized snapshot is taken under the lock; the file write happens
|
||||
/// after the lock is released.
|
||||
pub fn put(&self, persona: i64, key: &str, value: Value) {
|
||||
let snapshot = {
|
||||
let mut map = self.map.lock();
|
||||
map.insert(Self::compound_key(persona, key), value);
|
||||
serde_json::to_vec(&*map).unwrap_or_default()
|
||||
};
|
||||
if let Some(parent) = self.path.parent() {
|
||||
if !parent.as_os_str().is_empty() {
|
||||
let _ = std::fs::create_dir_all(parent);
|
||||
}
|
||||
}
|
||||
let _ = std::fs::write(&self.path, snapshot);
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
use serde_json::json;
|
||||
|
||||
fn temp_path(tag: &str) -> PathBuf {
|
||||
std::env::temp_dir().join(format!(
|
||||
"openfut-clientdata-test-{}-{}.json",
|
||||
std::process::id(),
|
||||
tag
|
||||
))
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn round_trips_and_persists_across_reopen() {
|
||||
let path = temp_path("roundtrip");
|
||||
let _ = std::fs::remove_file(&path);
|
||||
let store = ClientDataStore::open(&path);
|
||||
assert_eq!(store.get(33_068_179, "userHubData"), None);
|
||||
store.put(33_068_179, "userHubData", json!({"tiles": [1, 2, 3]}));
|
||||
assert_eq!(
|
||||
store.get(33_068_179, "userHubData"),
|
||||
Some(json!({"tiles": [1, 2, 3]}))
|
||||
);
|
||||
// A different persona under the same key is isolated.
|
||||
assert_eq!(store.get(1, "userHubData"), None);
|
||||
// Reopening reads the persisted blob back.
|
||||
let reopened = ClientDataStore::open(&path);
|
||||
assert_eq!(
|
||||
reopened.get(33_068_179, "userHubData"),
|
||||
Some(json!({"tiles": [1, 2, 3]}))
|
||||
);
|
||||
let _ = std::fs::remove_file(&path);
|
||||
}
|
||||
}
|
||||
@@ -34,6 +34,16 @@ pub struct HostConfig {
|
||||
/// Durable FIFA17 item-pile metadata DB (host-owned SQLite). Required; must
|
||||
/// survive host restart. Env `OPENFUT_PILE_DB`.
|
||||
pub pile_db_path: String,
|
||||
/// Durable client-data blob store (`clientdata`/`userHubData`), host-owned
|
||||
/// JSON file. NOT required: defaults to env `OPENFUT_CLIENTDATA_DB`, else the
|
||||
/// identity store's parent directory + `clientdata.json`. The blobs are
|
||||
/// non-authoritative client UI state, so a default path is safe.
|
||||
pub clientdata_path: String,
|
||||
/// Shared FIFA17 account JSON (`fut_account.py` shape), used for club-name
|
||||
/// reads and the Rust-owned rename mutation. Defaults to
|
||||
/// `OPENFUT_ACCOUNT_PATH`, then existing `FUT_ACCOUNT_PATH`, then the
|
||||
/// identity store's parent directory + `active_account.json`.
|
||||
pub account_path: String,
|
||||
}
|
||||
|
||||
#[derive(Debug)]
|
||||
@@ -68,6 +78,16 @@ fn required_i64_nonzero(key: &str) -> Result<i64, ConfigError> {
|
||||
|
||||
impl HostConfig {
|
||||
pub fn from_env() -> Result<Self, ConfigError> {
|
||||
let identity_store_path = required("OPENFUT_IDENTITY_STORE")?;
|
||||
let clientdata_path = env::var("OPENFUT_CLIENTDATA_DB")
|
||||
.ok()
|
||||
.filter(|v| !v.is_empty())
|
||||
.unwrap_or_else(|| default_clientdata_path(&identity_store_path));
|
||||
let account_path = env::var("OPENFUT_ACCOUNT_PATH")
|
||||
.ok()
|
||||
.filter(|v| !v.is_empty())
|
||||
.or_else(|| env::var("FUT_ACCOUNT_PATH").ok().filter(|v| !v.is_empty()))
|
||||
.unwrap_or_else(|| default_account_path(&identity_store_path));
|
||||
Ok(HostConfig {
|
||||
listen_addr: required("OPENFUT_UTAS_HOST_ADDR")?,
|
||||
python_upstream: required("OPENFUT_UTAS_PYTHON_URL")?,
|
||||
@@ -76,10 +96,32 @@ impl HostConfig {
|
||||
tables_dir: env::var("OPENFUT_FIFA17_TABLES_DIR")
|
||||
.unwrap_or_else(|_| "fifa17-recon/data/tables".into()),
|
||||
catalog_path: required("OPENFUT_FIFA17_CATALOG")?,
|
||||
identity_store_path: required("OPENFUT_IDENTITY_STORE")?,
|
||||
persona_id: required_i64_nonzero("OPENFUT_PERSONA_ID")?,
|
||||
market_db_path: required("OPENFUT_MARKET_DB")?,
|
||||
pile_db_path: required("OPENFUT_PILE_DB")?,
|
||||
identity_store_path,
|
||||
clientdata_path,
|
||||
account_path,
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
/// Default client-data blob path: the identity store's parent directory +
|
||||
/// `clientdata.json` (co-located with the other host-owned durable state).
|
||||
fn default_clientdata_path(identity_store_path: &str) -> String {
|
||||
std::path::Path::new(identity_store_path)
|
||||
.parent()
|
||||
.map(|p| p.join("clientdata.json"))
|
||||
.unwrap_or_else(|| std::path::PathBuf::from("clientdata.json"))
|
||||
.to_string_lossy()
|
||||
.into_owned()
|
||||
}
|
||||
|
||||
fn default_account_path(identity_store_path: &str) -> String {
|
||||
std::path::Path::new(identity_store_path)
|
||||
.parent()
|
||||
.map(|p| p.join("active_account.json"))
|
||||
.unwrap_or_else(|| std::path::PathBuf::from("active_account.json"))
|
||||
.to_string_lossy()
|
||||
.into_owned()
|
||||
}
|
||||
|
||||
@@ -457,7 +457,7 @@ mod tests {
|
||||
use std::collections::HashMap;
|
||||
use std::sync::atomic::{AtomicI64, AtomicU32, Ordering};
|
||||
|
||||
use crate::{EconomyEntitlement, EconomyPurchase};
|
||||
use crate::{EconomyEntitlement, EconomyPurchase, EconomySale, EconomySaleReceipt};
|
||||
|
||||
// ── Recording economy double ────────────────────────────────────────────
|
||||
|
||||
@@ -588,6 +588,10 @@ mod tests {
|
||||
self.purchased.lock().push((cost, items.to_vec()));
|
||||
Ok(self.balance.fetch_sub(cost, Ordering::SeqCst) - cost)
|
||||
}
|
||||
fn settle_sale(&self, _sale: &EconomySale<'_>) -> Result<EconomySaleReceipt, CoreError> {
|
||||
// Sale settlement is not exercised by the Store/quick-sell paths.
|
||||
Err(CoreError::Status(501))
|
||||
}
|
||||
}
|
||||
|
||||
// ── Identity / entity / lookup doubles ──────────────────────────────────
|
||||
|
||||
+1513
-126
File diff suppressed because it is too large
Load Diff
@@ -1,8 +1,8 @@
|
||||
//! FIFA 17 UTAS migration host entrypoint.
|
||||
//!
|
||||
//! Serves `GET …/club` from OpenFUT Core and proxies every other UTAS route to
|
||||
//! the Python oracle. Config is env-only (see [`openfut_utas_host::config`]);
|
||||
//! bind and Python upstream are required with no default.
|
||||
//! Serves migrated FIFA 17 UTAS routes from Rust/Core and proxies only the
|
||||
//! remaining tail to the Python oracle. Config is env-only (see
|
||||
//! [`openfut_utas_host::config`]).
|
||||
|
||||
use openfut_utas_host::{config::HostConfig, Server};
|
||||
|
||||
@@ -15,8 +15,8 @@ fn main() {
|
||||
}
|
||||
};
|
||||
eprintln!(
|
||||
"utas-host starting: listen={} python_upstream={} core_url={} tables_dir={} catalog={} identity_store={} persona_id={}",
|
||||
cfg.listen_addr, cfg.python_upstream, cfg.core_url, cfg.tables_dir, cfg.catalog_path, cfg.identity_store_path, cfg.persona_id
|
||||
"utas-host starting: listen={} python_upstream={} core_url={} tables_dir={} catalog={} identity_store={} account={} persona_id={}",
|
||||
cfg.listen_addr, cfg.python_upstream, cfg.core_url, cfg.tables_dir, cfg.catalog_path, cfg.identity_store_path, cfg.account_path, cfg.persona_id
|
||||
);
|
||||
let server = match Server::from_config(&cfg) {
|
||||
Ok(s) => s,
|
||||
|
||||
+1276
-128
File diff suppressed because it is too large
Load Diff
@@ -146,6 +146,52 @@ pub struct Listing {
|
||||
pub state: String,
|
||||
/// Creation time, unix-epoch milliseconds as a string (sortable).
|
||||
pub created_at: String,
|
||||
/// The FIFA card object (`itemData`) as shaped at listing time, serialized.
|
||||
/// A listing is a SNAPSHOT: the auction record must carry the full card the
|
||||
/// client can render (rating/position/attributes/rareflag/assetId), not a
|
||||
/// stub — a stub leaves the Transfer List with an unrenderable row. `None`
|
||||
/// only for rows written before this column existed (renders as a stub).
|
||||
pub item_json: Option<String>,
|
||||
/// Listing duration in SECONDS, as sent by the client in the `ISStart` body
|
||||
/// (`duration`). With `created_at` this is the whole auction clock: FIFA 17
|
||||
/// renders a live countdown from `expires` and expects it to reach 0, so a
|
||||
/// listing has to know when it ends. `None` for rows written before this
|
||||
/// column existed, which fall back to the default duration.
|
||||
pub duration_secs: Option<i64>,
|
||||
}
|
||||
|
||||
/// FIFA 17 auction durations, in seconds: 3600, 10800, 21600, 43200, 86400,
|
||||
/// 259200. One hour is the shortest, and the fallback when a client body omits it
|
||||
/// or a pre-column row is read.
|
||||
pub const DEFAULT_DURATION_SECS: i64 = 3600;
|
||||
|
||||
/// Seconds since the unix epoch.
|
||||
pub fn now_secs() -> i64 {
|
||||
use std::time::{SystemTime, UNIX_EPOCH};
|
||||
SystemTime::now()
|
||||
.duration_since(UNIX_EPOCH)
|
||||
.map(|d| d.as_secs() as i64)
|
||||
.unwrap_or(0)
|
||||
}
|
||||
|
||||
impl Listing {
|
||||
/// SECONDS REMAINING on this auction at `now` (unix seconds), clamped at 0 —
|
||||
/// the wire semantics of `expires`, which is never an absolute epoch.
|
||||
///
|
||||
/// A closed/sold/cancelled listing reads 0: there is no time left on an
|
||||
/// auction that has already ended.
|
||||
pub fn expires_in_secs(&self, now: i64) -> i64 {
|
||||
if self.state != "active" {
|
||||
return 0;
|
||||
}
|
||||
let created_secs = self
|
||||
.created_at
|
||||
.parse::<i64>()
|
||||
.map(|ms| ms / 1000)
|
||||
.unwrap_or(now);
|
||||
let duration = self.duration_secs.unwrap_or(DEFAULT_DURATION_SECS);
|
||||
(created_secs + duration - now).max(0)
|
||||
}
|
||||
}
|
||||
|
||||
const CREATE_LISTINGS: &str = "CREATE TABLE IF NOT EXISTS listings (
|
||||
@@ -158,7 +204,13 @@ const CREATE_LISTINGS: &str = "CREATE TABLE IF NOT EXISTS listings (
|
||||
buy_now_price INTEGER NOT NULL,
|
||||
owner TEXT,
|
||||
state TEXT NOT NULL CHECK (state IN ('active','reserved','sold','cancelled')),
|
||||
created_at TEXT NOT NULL
|
||||
created_at TEXT NOT NULL,
|
||||
item_json TEXT,
|
||||
duration_secs INTEGER,
|
||||
-- Seller acknowledgement of a SOLD row, separate from the sale itself. Declared
|
||||
-- here so a fresh store never needs the ALTER path below; the additive
|
||||
-- migration exists only for stores created before this column.
|
||||
cleared_at TEXT
|
||||
)";
|
||||
|
||||
fn now_millis() -> String {
|
||||
@@ -182,6 +234,8 @@ fn row_to_listing(row: &sqlx::sqlite::SqliteRow) -> Listing {
|
||||
owner: row.get("owner"),
|
||||
state: row.get("state"),
|
||||
created_at: row.get("created_at"),
|
||||
item_json: row.get("item_json"),
|
||||
duration_secs: row.get("duration_secs"),
|
||||
}
|
||||
}
|
||||
|
||||
@@ -223,6 +277,35 @@ impl MarketStore {
|
||||
.execute(&pool)
|
||||
.await
|
||||
.map_err(db)?;
|
||||
// Additive migration: `item_json` was added after the first stores shipped,
|
||||
// and `CREATE TABLE IF NOT EXISTS` will not add a column to an existing
|
||||
// file. Add it when absent so an existing market DB keeps working (old
|
||||
// rows read back `None` and render the stub card).
|
||||
let existing: Vec<String> = sqlx::query("PRAGMA table_info(listings)")
|
||||
.fetch_all(&pool)
|
||||
.await
|
||||
.map_err(db)?
|
||||
.iter()
|
||||
.map(|r| r.get::<String, _>("name"))
|
||||
.collect();
|
||||
for (col, decl) in [
|
||||
("item_json", "TEXT"),
|
||||
("duration_secs", "INTEGER"),
|
||||
// A SOLD listing is not the end of the seller's involvement: FIFA 17 has
|
||||
// a bulk `DELETE …/trade/sold` verb (builder 0x1801647c0, request name
|
||||
// RemoveAllSoldFromTradePile), which only makes sense if sold rows
|
||||
// PERSIST in the seller's pile until cleared. `cleared_at` records that
|
||||
// acknowledgement separately from the sale itself, so clearing a row can
|
||||
// never be mistaken for re-settling it.
|
||||
("cleared_at", "TEXT"),
|
||||
] {
|
||||
if !existing.iter().any(|c| c == col) {
|
||||
sqlx::query(&format!("ALTER TABLE listings ADD COLUMN {col} {decl}"))
|
||||
.execute(&pool)
|
||||
.await
|
||||
.map_err(db)?;
|
||||
}
|
||||
}
|
||||
Ok(MarketStore {
|
||||
pool,
|
||||
fault: StoreFault::default(),
|
||||
@@ -249,6 +332,11 @@ impl MarketStore {
|
||||
start_price: i64,
|
||||
buy_now_price: i64,
|
||||
owner: Option<&str>,
|
||||
// The shaped FIFA card snapshot (`itemData`) for the auction record.
|
||||
item_json: Option<&str>,
|
||||
// Listing duration in seconds from the client's `ISStart` body; `None`
|
||||
// falls back to [`DEFAULT_DURATION_SECS`].
|
||||
duration_secs: Option<i64>,
|
||||
) -> Result<Listing, MarketError> {
|
||||
let created_at = now_millis();
|
||||
let mut conn = self.pool.acquire().await.map_err(db)?;
|
||||
@@ -258,8 +346,9 @@ impl MarketStore {
|
||||
.map_err(db)?;
|
||||
let res = sqlx::query(
|
||||
"INSERT INTO listings (listing_id, card_id, core_item_id, wire_item_id, \
|
||||
wire_resource_id, start_price, buy_now_price, owner, state, created_at) \
|
||||
VALUES (?, ?, ?, ?, ?, ?, ?, ?, 'active', ?)",
|
||||
wire_resource_id, start_price, buy_now_price, owner, state, created_at, item_json, \
|
||||
duration_secs) \
|
||||
VALUES (?, ?, ?, ?, ?, ?, ?, ?, 'active', ?, ?, ?)",
|
||||
)
|
||||
.bind(listing_id)
|
||||
.bind(card_id)
|
||||
@@ -270,6 +359,8 @@ impl MarketStore {
|
||||
.bind(buy_now_price)
|
||||
.bind(owner)
|
||||
.bind(&created_at)
|
||||
.bind(item_json)
|
||||
.bind(duration_secs)
|
||||
.execute(&mut *conn)
|
||||
.await;
|
||||
match res {
|
||||
@@ -289,6 +380,8 @@ impl MarketStore {
|
||||
owner: owner.map(str::to_string),
|
||||
state: "active".to_string(),
|
||||
created_at,
|
||||
item_json: item_json.map(str::to_string),
|
||||
duration_secs,
|
||||
})
|
||||
}
|
||||
Err(e) => {
|
||||
@@ -395,6 +488,73 @@ impl MarketStore {
|
||||
}
|
||||
}
|
||||
|
||||
/// Mark a live listing SOLD in one step (`active | reserved -> sold`), for a
|
||||
/// sale driven by a counterparty rather than by this client's own buy-now.
|
||||
/// Returns whether this call was the one that sold it, so a replay is visible
|
||||
/// to the caller instead of silently settling twice.
|
||||
pub async fn mark_sold(&self, listing_id: &str) -> Result<bool, MarketError> {
|
||||
let affected = sqlx::query(
|
||||
"UPDATE listings SET state = 'sold' \
|
||||
WHERE listing_id = ? AND state IN ('active', 'reserved')",
|
||||
)
|
||||
.bind(listing_id)
|
||||
.execute(&self.pool)
|
||||
.await
|
||||
.map_err(db)?
|
||||
.rows_affected();
|
||||
Ok(affected == 1)
|
||||
}
|
||||
|
||||
/// Sold listings the seller has NOT yet cleared, newest first.
|
||||
///
|
||||
/// Separate from [`Self::query_listings`] because "sold" and "still shown to
|
||||
/// the seller" are different facts: a sold row stays in the pile until the
|
||||
/// client acknowledges it via the bulk clear verb.
|
||||
pub async fn uncleared_sold(&self) -> Result<Vec<Listing>, MarketError> {
|
||||
let rows = sqlx::query(
|
||||
"SELECT * FROM listings WHERE state = 'sold' AND cleared_at IS NULL \
|
||||
ORDER BY created_at DESC",
|
||||
)
|
||||
.fetch_all(&self.pool)
|
||||
.await
|
||||
.map_err(db)?;
|
||||
Ok(rows.iter().map(row_to_listing).collect())
|
||||
}
|
||||
|
||||
/// Acknowledge every uncleared sold listing (the bulk `DELETE …/trade/sold`).
|
||||
/// Returns how many rows were cleared.
|
||||
///
|
||||
/// This is PRESENTATION ONLY. It records that the seller has seen the sale; it
|
||||
/// moves no coins and no ownership, because settlement already happened when
|
||||
/// the sale completed. Clearing must never be able to pay anyone twice.
|
||||
pub async fn clear_sold(&self) -> Result<u64, MarketError> {
|
||||
Ok(sqlx::query(
|
||||
"UPDATE listings SET cleared_at = ? \
|
||||
WHERE state = 'sold' AND cleared_at IS NULL",
|
||||
)
|
||||
.bind(now_millis())
|
||||
.execute(&self.pool)
|
||||
.await
|
||||
.map_err(db)?
|
||||
.rows_affected())
|
||||
}
|
||||
|
||||
/// Acknowledge ONE sold listing by id (the per-id `DELETE …/trade/{id}` form,
|
||||
/// if the client turns out to use it for sold rows). Same presentation-only
|
||||
/// contract as [`Self::clear_sold`].
|
||||
pub async fn clear_sold_one(&self, listing_id: &str) -> Result<u64, MarketError> {
|
||||
Ok(sqlx::query(
|
||||
"UPDATE listings SET cleared_at = ? \
|
||||
WHERE listing_id = ? AND state = 'sold' AND cleared_at IS NULL",
|
||||
)
|
||||
.bind(now_millis())
|
||||
.bind(listing_id)
|
||||
.execute(&self.pool)
|
||||
.await
|
||||
.map_err(db)?
|
||||
.rows_affected())
|
||||
}
|
||||
|
||||
/// Undo a reservation on a downstream failure (`reserved -> active`), so the
|
||||
/// listing becomes buyable again. Not in `reserved` -> [`MarketError::Conflict`].
|
||||
pub async fn rollback_reservation(&self, listing_id: &str) -> Result<(), MarketError> {
|
||||
@@ -463,6 +623,80 @@ impl MarketStore {
|
||||
}
|
||||
outcome
|
||||
}
|
||||
|
||||
/// RE-LIST an existing auction row for the same item: reset the clock to now
|
||||
/// and take the new prices/duration.
|
||||
///
|
||||
/// FIFA 17 relists by sending a fresh `ISStart` POST for an item that already
|
||||
/// has a listing row, so the primary-key conflict is EXPECTED and means
|
||||
/// "relist", not "error". Treating that conflict as success is how a relist
|
||||
/// silently did nothing: the client was acked while the stale, already-expired
|
||||
/// row kept its old `created_at` and stayed expired.
|
||||
///
|
||||
/// Only an `active` (including aged-out) or `cancelled` row may be relisted. A
|
||||
/// `sold` or `reserved` row is NEVER resurrected — the card is gone or in
|
||||
/// flight, and re-opening that auction would sell a card twice.
|
||||
pub async fn relist_listing(
|
||||
&self,
|
||||
listing_id: &str,
|
||||
start_price: i64,
|
||||
buy_now_price: i64,
|
||||
duration_secs: Option<i64>,
|
||||
item_json: Option<&str>,
|
||||
) -> Result<Listing, MarketError> {
|
||||
let created_at = now_millis();
|
||||
let affected = sqlx::query(
|
||||
"UPDATE listings SET state = 'active', created_at = ?, start_price = ?, \
|
||||
buy_now_price = ?, duration_secs = ?, item_json = COALESCE(?, item_json) \
|
||||
WHERE listing_id = ? AND state IN ('active', 'cancelled')",
|
||||
)
|
||||
.bind(&created_at)
|
||||
.bind(start_price)
|
||||
.bind(buy_now_price)
|
||||
.bind(duration_secs)
|
||||
.bind(item_json)
|
||||
.bind(listing_id)
|
||||
.execute(&self.pool)
|
||||
.await
|
||||
.map_err(db)?
|
||||
.rows_affected();
|
||||
if affected == 0 {
|
||||
// Either no such row, or it is sold/reserved and must not be revived.
|
||||
return Err(match self.get_listing(listing_id).await {
|
||||
Ok(l) if l.state == "sold" => MarketError::Sold,
|
||||
Ok(_) => MarketError::Conflict,
|
||||
Err(e) => e,
|
||||
});
|
||||
}
|
||||
self.get_listing(listing_id).await
|
||||
}
|
||||
|
||||
/// Cancel any `active` listing held by a Core owned item, returning how many
|
||||
/// rows were cancelled (0 when the item has no live auction).
|
||||
///
|
||||
/// This is the RETURN-TO-CLUB transition: the client sends a pile move for an
|
||||
/// expired transfer-list item, and the auction that put it there has to end with
|
||||
/// it. Without this the pile says `club` while the listing row stays `active`,
|
||||
/// so the card is still filtered out of `/club` AND still rendered in the
|
||||
/// Transfer List — the item appears not to move at all.
|
||||
///
|
||||
/// Deliberately scoped to `active`: a `reserved` row is mid-sale and a `sold`
|
||||
/// row is already gone, and cancelling either would let a card be both sold and
|
||||
/// returned.
|
||||
pub async fn cancel_active_for_core_item(
|
||||
&self,
|
||||
core_item_id: &str,
|
||||
) -> Result<u64, MarketError> {
|
||||
Ok(sqlx::query(
|
||||
"UPDATE listings SET state = 'cancelled' \
|
||||
WHERE core_item_id = ? AND state = 'active'",
|
||||
)
|
||||
.bind(core_item_id)
|
||||
.execute(&self.pool)
|
||||
.await
|
||||
.map_err(db)?
|
||||
.rows_affected())
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
@@ -494,6 +728,92 @@ mod tests {
|
||||
}
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn relist_resets_the_clock_and_takes_the_new_prices() {
|
||||
// FIFA 17 relists by re-sending ISStart for an item that already has a row,
|
||||
// so the PK conflict is the relist path. Before this existed the conflict was
|
||||
// acked as success and the stale expired row kept its old created_at, so the
|
||||
// card never came back to the market.
|
||||
let (store, _d) = temp_store().await;
|
||||
let first = seed(&store, "900000001").await;
|
||||
// Age it out by rewriting created_at to well past its default duration.
|
||||
let stale = (now_secs() - DEFAULT_DURATION_SECS - 600) * 1000;
|
||||
sqlx::query("UPDATE listings SET created_at = ? WHERE listing_id = ?")
|
||||
.bind(stale.to_string())
|
||||
.bind("900000001")
|
||||
.execute(&store.pool)
|
||||
.await
|
||||
.unwrap();
|
||||
let expired = store.get_listing("900000001").await.unwrap();
|
||||
assert_eq!(
|
||||
expired.expires_in_secs(now_secs()),
|
||||
0,
|
||||
"precondition: the listing has run out"
|
||||
);
|
||||
|
||||
let relisted = store
|
||||
.relist_listing("900000001", 250, 5000, Some(10_800), None)
|
||||
.await
|
||||
.unwrap();
|
||||
assert_eq!(relisted.state, "active");
|
||||
assert_eq!(relisted.start_price, 250, "new start price applied");
|
||||
assert_eq!(relisted.buy_now_price, 5000, "new buy-now applied");
|
||||
assert_eq!(relisted.duration_secs, Some(10_800));
|
||||
assert!(
|
||||
relisted.expires_in_secs(now_secs()) > 0,
|
||||
"the clock actually restarted"
|
||||
);
|
||||
assert_ne!(
|
||||
relisted.created_at, expired.created_at,
|
||||
"created_at moved forward"
|
||||
);
|
||||
// The snapshot is preserved when the relist does not supply a new one.
|
||||
assert_eq!(relisted.item_json, first.item_json);
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn relist_never_revives_a_sold_or_reserved_auction() {
|
||||
// Re-opening a sold auction would sell the same card twice.
|
||||
let (store, _d) = temp_store().await;
|
||||
seed(&store, "900000001").await;
|
||||
assert!(store.reserve_listing("900000001").await.unwrap());
|
||||
assert!(
|
||||
matches!(
|
||||
store.relist_listing("900000001", 1, 2, None, None).await,
|
||||
Err(MarketError::Conflict)
|
||||
),
|
||||
"a reserved (in-flight) auction is not relistable"
|
||||
);
|
||||
store.complete_sale("900000001").await.unwrap();
|
||||
assert!(
|
||||
matches!(
|
||||
store.relist_listing("900000001", 1, 2, None, None).await,
|
||||
Err(MarketError::Sold)
|
||||
),
|
||||
"a sold auction is never resurrected"
|
||||
);
|
||||
assert_eq!(store.get_listing("900000001").await.unwrap().state, "sold");
|
||||
|
||||
// A cancelled listing IS relistable (the card came back to the pile).
|
||||
seed(&store, "900000002").await;
|
||||
store.cancel_listing("900000002", None).await.unwrap();
|
||||
let back = store
|
||||
.relist_listing("900000002", 300, 900, None, None)
|
||||
.await
|
||||
.unwrap();
|
||||
assert_eq!(back.state, "active");
|
||||
assert_eq!(back.start_price, 300);
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn relist_of_a_missing_row_is_not_found() {
|
||||
let (store, _d) = temp_store().await;
|
||||
assert!(matches!(
|
||||
store.relist_listing("900000999", 1, 2, None, None).await,
|
||||
Err(MarketError::NotFound)
|
||||
));
|
||||
}
|
||||
|
||||
async fn temp_store() -> (MarketStore, TempDb) {
|
||||
let db = TempDb::new();
|
||||
let store = MarketStore::open(db.path()).await.unwrap();
|
||||
@@ -502,7 +822,18 @@ mod tests {
|
||||
|
||||
async fn seed(store: &MarketStore, id: &str) -> Listing {
|
||||
store
|
||||
.create_listing(id, "card_pl_001", None, None, None, 900, 2500, None)
|
||||
.create_listing(
|
||||
id,
|
||||
"card_pl_001",
|
||||
None,
|
||||
None,
|
||||
None,
|
||||
900,
|
||||
2500,
|
||||
None,
|
||||
None,
|
||||
None,
|
||||
)
|
||||
.await
|
||||
.unwrap()
|
||||
}
|
||||
@@ -533,7 +864,18 @@ mod tests {
|
||||
seed(&store, "900000001").await;
|
||||
assert!(matches!(
|
||||
store
|
||||
.create_listing("900000001", "card_pl_002", None, None, None, 1, 2, None)
|
||||
.create_listing(
|
||||
"900000001",
|
||||
"card_pl_002",
|
||||
None,
|
||||
None,
|
||||
None,
|
||||
1,
|
||||
2,
|
||||
None,
|
||||
None,
|
||||
None
|
||||
)
|
||||
.await,
|
||||
Err(MarketError::Conflict)
|
||||
));
|
||||
@@ -597,6 +939,8 @@ mod tests {
|
||||
900,
|
||||
2500,
|
||||
Some("alice"),
|
||||
None,
|
||||
None,
|
||||
)
|
||||
.await
|
||||
.unwrap();
|
||||
@@ -668,6 +1012,8 @@ mod tests {
|
||||
900,
|
||||
2500,
|
||||
Some("alice"),
|
||||
Some(r#"{"rating":84}"#),
|
||||
None,
|
||||
)
|
||||
.await
|
||||
.unwrap();
|
||||
@@ -683,5 +1029,10 @@ mod tests {
|
||||
assert_eq!(got.core_item_id.as_deref(), Some("core-7"));
|
||||
assert_eq!(got.wire_item_id, Some(100004617));
|
||||
assert_eq!(got.owner.as_deref(), Some("alice"));
|
||||
assert_eq!(
|
||||
got.item_json.as_deref(),
|
||||
Some(r#"{"rating":84}"#),
|
||||
"card snapshot survives reopen"
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,197 @@
|
||||
//! STAGING-ONLY seller-facing SOLD-row experiment.
|
||||
//!
|
||||
//! Static RE has exhausted CardsDLL on one question: for a `closed` row,
|
||||
//! `IS_GLOW = (bidState != none)` and `INBOX = (bidState in {highest, buyNow})`,
|
||||
//! so `closed/highest` and `closed/buyNow` are **bit-identical** to every native
|
||||
//! consumer. But `bidState` is also published to the movie verbatim as `YOURBID`,
|
||||
//! so the FUT ActionScript front end CAN separate them. This module exists to ask
|
||||
//! the client which one it treats as the seller's sale, by holding every other
|
||||
//! field constant and changing exactly that token.
|
||||
//!
|
||||
//! # Production safety
|
||||
//!
|
||||
//! Every knob is OFF unless its environment variable is set explicitly, and
|
||||
//! [`SoldExperiment::enabled`] gates every projection at the call site. With no
|
||||
//! env set this module changes nothing: `/tradePile` and `/trade/status` emit only
|
||||
//! real active auctions (the Fix A invariant) and `/tradePile/counts` reports
|
||||
//! `sold: 0` exactly as production does today. An unrecognised value is treated as
|
||||
//! OFF rather than as a default token, because silently picking a token would
|
||||
//! fabricate the very answer the experiment is meant to measure.
|
||||
//!
|
||||
//! # Why this cannot be "discovery"
|
||||
//!
|
||||
//! Our server IS the server, so nothing here recovers EA's original contract. It
|
||||
//! is a controlled discriminator: the client's *reaction* (which bucket it draws
|
||||
//! the row in, what it counts, and which request it issues to clear it) is the
|
||||
//! observation.
|
||||
|
||||
/// What `/tradePile/counts.count` should report while a sold row exists. FIFA 17's
|
||||
/// exact semantics for `count` are unknown — it is either the number of live
|
||||
/// auctions or the whole Transfer List membership — so it is a controlled variable
|
||||
/// rather than a guess.
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub enum CountMode {
|
||||
/// `count` = active auctions only (current production behaviour).
|
||||
Active,
|
||||
/// `count` = active + uncleared sold (Transfer List membership).
|
||||
ActivePlusSold,
|
||||
}
|
||||
|
||||
/// Resolved experiment configuration.
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub struct SoldExperiment {
|
||||
/// The `bidState` token to emit on a sold seller row. `None` disables every
|
||||
/// part of the experiment.
|
||||
pub bid_state: Option<&'static str>,
|
||||
/// The `coinsProcessed` value to emit (published to Flash as `COINS_AWARDED`).
|
||||
pub coins_processed: i64,
|
||||
pub count_mode: CountMode,
|
||||
}
|
||||
|
||||
impl SoldExperiment {
|
||||
/// All-off. This is what production runs.
|
||||
pub const OFF: Self = Self {
|
||||
bid_state: None,
|
||||
coins_processed: 0,
|
||||
count_mode: CountMode::Active,
|
||||
};
|
||||
|
||||
/// Read the configuration from the environment.
|
||||
///
|
||||
/// * `OPENFUT_FIFA17_SOLD_EXPERIMENT` — `highest` | `buyNow`; anything else
|
||||
/// (including absent) is OFF.
|
||||
/// * `OPENFUT_FIFA17_SOLD_COINS_PROCESSED` — `1` to emit 1, else 0.
|
||||
/// * `OPENFUT_FIFA17_SOLD_COUNT_MODE` — `active_plus_sold`, else `active`.
|
||||
pub fn from_env() -> Self {
|
||||
Self::from_values(
|
||||
std::env::var("OPENFUT_FIFA17_SOLD_EXPERIMENT")
|
||||
.ok()
|
||||
.as_deref(),
|
||||
std::env::var("OPENFUT_FIFA17_SOLD_COINS_PROCESSED")
|
||||
.ok()
|
||||
.as_deref(),
|
||||
std::env::var("OPENFUT_FIFA17_SOLD_COUNT_MODE")
|
||||
.ok()
|
||||
.as_deref(),
|
||||
)
|
||||
}
|
||||
|
||||
/// Pure resolver, so the parsing rules are testable without touching the
|
||||
/// process environment.
|
||||
pub fn from_values(
|
||||
experiment: Option<&str>,
|
||||
coins_processed: Option<&str>,
|
||||
count_mode: Option<&str>,
|
||||
) -> Self {
|
||||
// Matched case-insensitively for operator convenience, but ONLY the two
|
||||
// real FIFA 17 tokens are accepted. `none`/`outbid` are deliberately not
|
||||
// offered: neither can describe a completed sale, and `none` on a closed
|
||||
// row clears IS_GLOW, which would test nothing.
|
||||
let bid_state = match experiment.map(str::trim).unwrap_or("") {
|
||||
s if s.eq_ignore_ascii_case("highest") => Some("highest"),
|
||||
s if s.eq_ignore_ascii_case("buynow") => Some("buyNow"),
|
||||
_ => None,
|
||||
};
|
||||
Self {
|
||||
bid_state,
|
||||
coins_processed: i64::from(coins_processed == Some("1")),
|
||||
count_mode: match count_mode.map(str::trim).unwrap_or("") {
|
||||
s if s.eq_ignore_ascii_case("active_plus_sold") => CountMode::ActivePlusSold,
|
||||
_ => CountMode::Active,
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
/// Whether any sold projection is active. Production: always false.
|
||||
pub fn enabled(&self) -> bool {
|
||||
self.bid_state.is_some()
|
||||
}
|
||||
|
||||
/// A one-line banner for the host's startup log, so a staging run can never be
|
||||
/// mistaken for a production one in a capture.
|
||||
pub fn banner(&self) -> String {
|
||||
match self.bid_state {
|
||||
None => "sold-experiment=OFF (production behaviour)".to_string(),
|
||||
Some(b) => format!(
|
||||
"sold-experiment=ON bidState={b} coinsProcessed={} countMode={:?} \
|
||||
-- STAGING ONLY, never production",
|
||||
self.coins_processed, self.count_mode
|
||||
),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn absent_env_is_off_and_matches_production() {
|
||||
let e = SoldExperiment::from_values(None, None, None);
|
||||
assert!(!e.enabled());
|
||||
assert_eq!(e, SoldExperiment::OFF);
|
||||
assert_eq!(e.coins_processed, 0);
|
||||
assert_eq!(e.count_mode, CountMode::Active);
|
||||
}
|
||||
|
||||
/// The whole point of the harness: exactly two tokens, and nothing else may
|
||||
/// turn it on. A typo must not silently select a token and manufacture the
|
||||
/// answer we are trying to measure.
|
||||
#[test]
|
||||
fn only_the_two_real_tokens_enable_it() {
|
||||
for (input, expected) in [
|
||||
("highest", Some("highest")),
|
||||
("HIGHEST", Some("highest")),
|
||||
("buyNow", Some("buyNow")),
|
||||
("buynow", Some("buyNow")),
|
||||
(" highest ", Some("highest")),
|
||||
("off", None),
|
||||
("none", None),
|
||||
("outbid", None),
|
||||
("closed", None),
|
||||
("", None),
|
||||
("hihgest", None), // typo
|
||||
("1", None),
|
||||
] {
|
||||
let e = SoldExperiment::from_values(Some(input), None, None);
|
||||
assert_eq!(e.bid_state, expected, "input {input:?}");
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn coins_processed_is_strictly_one_or_zero() {
|
||||
for (input, expected) in [
|
||||
(Some("1"), 1),
|
||||
(Some("0"), 0),
|
||||
(Some("true"), 0), // only "1" means 1 — no fuzzy truthiness
|
||||
(Some(""), 0),
|
||||
(None, 0),
|
||||
] {
|
||||
assert_eq!(
|
||||
SoldExperiment::from_values(Some("highest"), input, None).coins_processed,
|
||||
expected,
|
||||
"input {input:?}"
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn count_mode_defaults_to_production_behaviour() {
|
||||
let mk = |m| SoldExperiment::from_values(Some("highest"), None, m).count_mode;
|
||||
assert_eq!(mk(None), CountMode::Active);
|
||||
assert_eq!(mk(Some("active")), CountMode::Active);
|
||||
assert_eq!(mk(Some("active_plus_sold")), CountMode::ActivePlusSold);
|
||||
assert_eq!(mk(Some("ACTIVE_PLUS_SOLD")), CountMode::ActivePlusSold);
|
||||
assert_eq!(mk(Some("everything")), CountMode::Active, "unknown -> safe");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn banner_names_the_variant_under_test() {
|
||||
assert!(SoldExperiment::OFF.banner().contains("OFF"));
|
||||
let on = SoldExperiment::from_values(Some("buyNow"), Some("1"), None);
|
||||
let b = on.banner();
|
||||
assert!(b.contains("bidState=buyNow"), "{b}");
|
||||
assert!(b.contains("coinsProcessed=1"), "{b}");
|
||||
assert!(b.contains("STAGING ONLY"), "{b}");
|
||||
}
|
||||
}
|
||||
@@ -164,6 +164,8 @@ fn build_harness(base: &str, dir: &std::path::Path) -> Harness {
|
||||
"content pool derived from real Core content"
|
||||
);
|
||||
let services = Arc::new(EconomyServices {
|
||||
// Production default: the sold experiment is OFF.
|
||||
sold_experiment: openfut_utas_host::sold_experiment::SoldExperiment::OFF,
|
||||
econ,
|
||||
market,
|
||||
piles,
|
||||
@@ -423,19 +425,18 @@ fn case_c_dup_quicksell(h: &Harness) -> String {
|
||||
/// exactly one debit; exactly one mint.
|
||||
fn case_d_two_market_buyers(h: &Harness) -> String {
|
||||
let mut wins = 0u32;
|
||||
for i in 0..ITERS {
|
||||
for _ in 0..ITERS {
|
||||
// List a genuinely-owned card: the server resolves the Core card_id +
|
||||
// resourceId from inventory via the wire id (you can only list what you own).
|
||||
let (item_id, _core) = mint_one(h);
|
||||
set_balance(&h.client, 50_000);
|
||||
let item_id = 500_000 + i as i64; // unique listing per iteration
|
||||
let list = h
|
||||
.server
|
||||
.try_handle_economy(
|
||||
"POST",
|
||||
"/ut/game/fifa17/auctionhouse",
|
||||
&[],
|
||||
format!(
|
||||
r#"{{"itemData":{{"id":{item_id},"resourceId":{}}},"buyNowPrice":1000,"startingBid":500}}"#,
|
||||
h.sample_resource
|
||||
)
|
||||
format!(r#"{{"itemData":{{"id":{item_id}}},"buyNowPrice":1000,"startingBid":500}}"#)
|
||||
.as_bytes(),
|
||||
None,
|
||||
)
|
||||
|
||||
@@ -51,7 +51,12 @@
|
||||
//! | market list POST /ah | PARITY | 200; `{"id":<tradeId>}` (a positive listing id). Id SPACES |
|
||||
//! | | | differ (Rust MarketStore vs oracle 900500000+seq) — a |
|
||||
//! | | | wire-insignificant server-private handle. |
|
||||
//! | market query tradePile | PARITY | after list -> `auctionInfo` len 1, `tradeState:"active"`. |
|
||||
//! | market query tradePile | DIFFERENT-BY-DESIGN| after list -> `auctionInfo` len 1, `tradeState:"active"`. |
|
||||
//! | | | ONE field diverges deliberately: `itemData.itemState`. The |
|
||||
//! | | | oracle emits `listFS`, which does not exist in FIFA 17 (0 in |
|
||||
//! | | | CardsDLL, 0 in 4.26 GiB of client memory) and decodes to -1; |
|
||||
//! | | | Rust emits `forSale` (5), the client's own token. Parity here |
|
||||
//! | | | passed while BOTH were wrong, which is why it survived. |
|
||||
//! | market buy POST /trade | DIFFERENT-BY-DESIGN| first buy debits exactly `buyNowPrice` & closes on BOTH, but |
|
||||
//! | | | Rust's MarketStore is STATEFUL single-debit (a second buy of |
|
||||
//! | | | a sold listing is a no-op: 0 delta, empty `auctionInfo`) |
|
||||
@@ -91,6 +96,7 @@
|
||||
|
||||
use openfut_adapter_fifa17::fut::catalog::Fifa17CardCatalog;
|
||||
use openfut_adapter_fifa17::fut::entities::Fifa17Entities;
|
||||
use openfut_adapter_fifa17::fut::non_economy::PERSONA_DISPLAY_NAME;
|
||||
use openfut_adapter_fifa17::fut::store_session::{SessionStore, StoreMode, SENTINEL_PACK_ID};
|
||||
use openfut_identity::JsonIdentityStore;
|
||||
use openfut_utas_host::async_bridge::AsyncBridge;
|
||||
@@ -352,6 +358,8 @@ fn build_econ_server(base: &str, dir: &std::path::Path) -> (Server, HttpCoreClie
|
||||
"content pool derived from real Core content"
|
||||
);
|
||||
let services = Arc::new(EconomyServices {
|
||||
// Production default: the sold experiment is OFF.
|
||||
sold_experiment: openfut_utas_host::sold_experiment::SoldExperiment::OFF,
|
||||
econ,
|
||||
market,
|
||||
piles,
|
||||
@@ -407,7 +415,7 @@ fn pack_ids(pg: &Value) -> Vec<u64> {
|
||||
fn run_differential(core_base: &str, oracle: &Oracle, dir: &std::path::Path) {
|
||||
wait_ready(core_base);
|
||||
let http = reqwest::blocking::Client::new();
|
||||
let (server, client, sample_resource) = build_econ_server(core_base, dir);
|
||||
let (server, client, _sample_resource) = build_econ_server(core_base, dir);
|
||||
|
||||
// ── Fixture alignment: both sides own exactly one pack-70 entitlement. ──
|
||||
// Oracle: fresh profile already owns pack 70. Core: grant the "70" entitlement
|
||||
@@ -847,7 +855,20 @@ fn run_differential(core_base: &str, oracle: &Oracle, dir: &std::path::Path) {
|
||||
None,
|
||||
);
|
||||
let o_trade_id = o_list["id"].as_i64().expect("oracle trade id");
|
||||
let (r_ls, r_list) = rust(&server, "POST", "/ut/game/fifa17/auctionhouse", format!(r#"{{"itemData":{{"id":777,"resourceId":{sample_resource}}},"buyNowPrice":1000,"startingBid":500}}"#).as_bytes(), None);
|
||||
// Same body shape as the oracle: the wire id ALONE (the server resolves the
|
||||
// owned card's card_id + resourceId from inventory). `r_wire[1]` is the card
|
||||
// moved to the trade pile in OP 9 — the Rust parallel of the oracle's o_wire[1].
|
||||
let (r_ls, r_list) = rust(
|
||||
&server,
|
||||
"POST",
|
||||
"/ut/game/fifa17/auctionhouse",
|
||||
format!(
|
||||
r#"{{"itemData":{{"id":{}}},"buyNowPrice":1000,"startingBid":500}}"#,
|
||||
r_wire[1]
|
||||
)
|
||||
.as_bytes(),
|
||||
None,
|
||||
);
|
||||
let r_trade_id = r_list["id"].as_i64().expect("rust trade id");
|
||||
assert_eq!(o_ls, 200);
|
||||
assert_eq!(r_ls, 200, "market list status parity");
|
||||
@@ -878,7 +899,82 @@ fn run_differential(core_base: &str, oracle: &Oracle, dir: &std::path::Path) {
|
||||
r_tp["auctionInfo"][0]["tradeState"], "active",
|
||||
"rust listing active"
|
||||
);
|
||||
matrix.push(("market query tradePile", "PARITY"));
|
||||
// Compare the record FIELD-FOR-FIELD, not merely its length and trade state.
|
||||
// The client reads the seller identity to decide whether a transfer-pile row is
|
||||
// the player's OWN — and therefore whether Remove / Re-list exist at all — and
|
||||
// a len+tradeState check is blind to that. A real client silently offered NO
|
||||
// action on the player's own listing (pressing it opened no dialog) because we
|
||||
// stamped EA's house name as the seller while the oracle stamps the persona.
|
||||
let o_rec = &o_tp["auctionInfo"][0];
|
||||
let r_rec = &r_tp["auctionInfo"][0];
|
||||
let keys = |v: &Value| {
|
||||
let mut k: Vec<String> = v
|
||||
.as_object()
|
||||
.expect("auction record is an object")
|
||||
.keys()
|
||||
.cloned()
|
||||
.collect();
|
||||
k.sort();
|
||||
k
|
||||
};
|
||||
// Both sides emit exactly FIFA 17's twelve auctionInfo atoms, so this is a
|
||||
// strict key-set equality. NOTE the limit of that: parity here proves we match
|
||||
// the oracle, NOT that either side is complete -- a field absent from BOTH is
|
||||
// invisible to this check. That is exactly how the Transfer List Actions-panel
|
||||
// bug hid, and the client binary's atom table is the authority that settled it
|
||||
// (see docs/FIFA17_TRANSFER_MARKET_WIRE.md).
|
||||
assert_eq!(
|
||||
keys(o_rec),
|
||||
keys(r_rec),
|
||||
"tradePile auction-record key set parity"
|
||||
);
|
||||
for f in [
|
||||
"sellerName",
|
||||
"bidState",
|
||||
"currentBid",
|
||||
"sellerEstablished",
|
||||
"watched",
|
||||
"coinsProcessed",
|
||||
] {
|
||||
assert_eq!(o_rec[f], r_rec[f], "tradePile record field `{f}` parity");
|
||||
}
|
||||
assert_eq!(
|
||||
r_rec["sellerName"], PERSONA_DISPLAY_NAME,
|
||||
"the player's own listing is sold BY the player, never by EA"
|
||||
);
|
||||
// `expires` is seconds remaining on a live clock, so it need not equal the
|
||||
// oracle's constant; it must be a positive 64-bit count for an active auction.
|
||||
assert!(
|
||||
r_rec["expires"].as_i64().is_some_and(|e| e > 0),
|
||||
"an active auction has positive seconds remaining"
|
||||
);
|
||||
// itemData must be the full shaped card on both sides; a stub cannot render.
|
||||
//
|
||||
// DELIBERATE DIVERGENCE — the one field on this route where the oracle is
|
||||
// WRONG. It stamps `listFS`, which is not a FIFA 17 token at all: zero
|
||||
// occurrences in `CardsDLL_Win64_retail.dll` (md5
|
||||
// 4de3493131d7d2ff7f8b360c5ac9b655), zero in 4.26 GiB of live client memory,
|
||||
// and it decodes to -1 through the itemState table walk, so the client is
|
||||
// handed an unrecognised `CARD_OFFERSTATE`. FIFA 17's value for an item
|
||||
// offered for sale is `forSale` (5), from the 12-row table at 0x180229cc0.
|
||||
//
|
||||
// This assertion used to demand parity, and passed while BOTH sides were
|
||||
// wrong — the reason the defect survived every differential run. Oracle parity
|
||||
// is necessary but not sufficient; where the binary contradicts the oracle,
|
||||
// the binary wins.
|
||||
assert_eq!(
|
||||
o_rec["itemData"]["itemState"], "listFS",
|
||||
"pins what the oracle actually emits, so this divergence stays visible"
|
||||
);
|
||||
assert_eq!(
|
||||
r_rec["itemData"]["itemState"], "forSale",
|
||||
"Rust emits FIFA 17's own token, not the oracle's non-existent one"
|
||||
);
|
||||
assert!(
|
||||
r_rec["itemData"]["rating"].is_i64() && r_rec["itemData"]["attributeList"].is_array(),
|
||||
"rust tradePile itemData is the full card, not a stub"
|
||||
);
|
||||
matrix.push(("market query tradePile", "DIFFERENT-BY-DESIGN"));
|
||||
|
||||
// ── OP 13: market buy (POST /trade/<id>) — DIFFERENT-BY-DESIGN ─────────
|
||||
// Shared invariant: the first buy debits exactly buyNowPrice and closes the
|
||||
@@ -992,7 +1088,19 @@ fn run_differential(core_base: &str, oracle: &Oracle, dir: &std::path::Path) {
|
||||
"oracle cancelled listing gone from tradePile"
|
||||
);
|
||||
// Rust: list a fresh item, cancel it, then a buy is a 0-delta empty auction.
|
||||
let clist = rust(&server, "POST", "/ut/game/fifa17/auctionhouse", format!(r#"{{"itemData":{{"id":888,"resourceId":{sample_resource}}},"buyNowPrice":1000,"startingBid":500}}"#).as_bytes(), None).1;
|
||||
// A still-owned card (r_wire[0]/[3] were quick-sold, [1] is listed above).
|
||||
let clist = rust(
|
||||
&server,
|
||||
"POST",
|
||||
"/ut/game/fifa17/auctionhouse",
|
||||
format!(
|
||||
r#"{{"itemData":{{"id":{}}},"buyNowPrice":1000,"startingBid":500}}"#,
|
||||
r_wire[2]
|
||||
)
|
||||
.as_bytes(),
|
||||
None,
|
||||
)
|
||||
.1;
|
||||
let r_cancel_id = clist["id"].as_i64().unwrap();
|
||||
let (r_cs, _) = rust(
|
||||
&server,
|
||||
|
||||
@@ -31,8 +31,8 @@ use openfut_utas_host::market_store::MarketStore;
|
||||
use openfut_utas_host::pile_store::PileStore;
|
||||
use openfut_utas_host::{
|
||||
build_content_pool, CoreAccess, CoreEconomy, CoreError, EconomyEntitlement, EconomyGrantItem,
|
||||
EconomyPurchase, EconomyServices, Fifa17IdentityResolver, HttpCoreClient, PassClient, Server,
|
||||
WireResponse,
|
||||
EconomyPurchase, EconomySale, EconomySaleReceipt, EconomyServices, Fifa17IdentityResolver,
|
||||
HttpCoreClient, PassClient, Server, WireResponse,
|
||||
};
|
||||
use parking_lot::Mutex;
|
||||
use serde_json::Value;
|
||||
@@ -134,6 +134,12 @@ impl CoreEconomy for FaultEconomy {
|
||||
}
|
||||
self.inner.purchase_items(cost, items)
|
||||
}
|
||||
fn settle_sale(&self, sale: &EconomySale<'_>) -> Result<EconomySaleReceipt, CoreError> {
|
||||
if self.trip("settle_sale") {
|
||||
return Err(Self::injected());
|
||||
}
|
||||
self.inner.settle_sale(sale)
|
||||
}
|
||||
}
|
||||
|
||||
/// An `ExternalIdentityStore` that forwards to a real `JsonIdentityStore` but can
|
||||
@@ -257,7 +263,6 @@ struct FailHarness {
|
||||
bridge: Arc<AsyncBridge>,
|
||||
core: Arc<dyn CoreAccess>,
|
||||
entities: Arc<Fifa17Entities>,
|
||||
sample_resource: i64,
|
||||
}
|
||||
|
||||
fn catalog_from_core(core: &dyn CoreAccess) -> Fifa17CardCatalog {
|
||||
@@ -315,6 +320,8 @@ fn build_fail_harness(base: &str, dir: &std::path::Path) -> FailHarness {
|
||||
"content pool derived from real Core content"
|
||||
);
|
||||
let services = Arc::new(EconomyServices {
|
||||
// Production default: the sold experiment is OFF.
|
||||
sold_experiment: openfut_utas_host::sold_experiment::SoldExperiment::OFF,
|
||||
econ: econ_dyn,
|
||||
market: market.clone(),
|
||||
piles: piles.clone(),
|
||||
@@ -341,7 +348,6 @@ fn build_fail_harness(base: &str, dir: &std::path::Path) -> FailHarness {
|
||||
bridge,
|
||||
core,
|
||||
entities,
|
||||
sample_resource: 20000,
|
||||
}
|
||||
}
|
||||
|
||||
@@ -351,6 +357,8 @@ impl FailHarness {
|
||||
/// generator path never consumes an entitlement.
|
||||
fn empty_pool_server(&self) -> Server {
|
||||
let services = Arc::new(EconomyServices {
|
||||
// Production default: the sold experiment is OFF.
|
||||
sold_experiment: openfut_utas_host::sold_experiment::SoldExperiment::OFF,
|
||||
econ: {
|
||||
let e: Arc<dyn CoreEconomy> = self.econ.clone();
|
||||
e
|
||||
@@ -676,15 +684,14 @@ fn case_move_pile_failure(h: &FailHarness) -> String {
|
||||
|
||||
/// MARKET RESERVE failure → no debit, no grant, listing stays legal (active).
|
||||
fn case_market_reserve_failure(h: &FailHarness) -> String {
|
||||
// List a genuinely-owned card: the server resolves card_id + resourceId from
|
||||
// Core inventory via the wire id (you can only list what you own).
|
||||
let (item_id, _core) = h.mint_one();
|
||||
set_balance(&h.client, 50_000);
|
||||
let item_id = 700_001i64;
|
||||
let list = h.dispatch(
|
||||
"POST",
|
||||
"/ut/game/fifa17/auctionhouse",
|
||||
format!(
|
||||
r#"{{"itemData":{{"id":{item_id},"resourceId":{}}},"buyNowPrice":1000,"startingBid":500}}"#,
|
||||
h.sample_resource
|
||||
)
|
||||
format!(r#"{{"itemData":{{"id":{item_id}}},"buyNowPrice":1000,"startingBid":500}}"#)
|
||||
.as_bytes(),
|
||||
);
|
||||
let trade_id = bj(&list)["id"].as_i64().expect("trade id");
|
||||
@@ -712,15 +719,12 @@ fn case_market_reserve_failure(h: &FailHarness) -> String {
|
||||
/// MARKET Core purchase_item failure AFTER reserve → reservation rolls back to
|
||||
/// active, no debit, no mint.
|
||||
fn case_market_purchase_failure(h: &FailHarness) -> String {
|
||||
let (item_id, _core) = h.mint_one();
|
||||
set_balance(&h.client, 50_000);
|
||||
let item_id = 700_002i64;
|
||||
let list = h.dispatch(
|
||||
"POST",
|
||||
"/ut/game/fifa17/auctionhouse",
|
||||
format!(
|
||||
r#"{{"itemData":{{"id":{item_id},"resourceId":{}}},"buyNowPrice":1000,"startingBid":500}}"#,
|
||||
h.sample_resource
|
||||
)
|
||||
format!(r#"{{"itemData":{{"id":{item_id}}},"buyNowPrice":1000,"startingBid":500}}"#)
|
||||
.as_bytes(),
|
||||
);
|
||||
let trade_id = bj(&list)["id"].as_i64().expect("trade id");
|
||||
@@ -754,15 +758,12 @@ fn case_market_purchase_failure(h: &FailHarness) -> String {
|
||||
/// active), so no further `active -> reserved` CAS can succeed → not buyable,
|
||||
/// with exactly one debit + one mint. Returns ("SAFE"|"E3", detail).
|
||||
fn case_market_complete_sale_failure(h: &FailHarness) -> (String, String) {
|
||||
let (item_id, _core) = h.mint_one();
|
||||
set_balance(&h.client, 50_000);
|
||||
let item_id = 700_003i64;
|
||||
let list = h.dispatch(
|
||||
"POST",
|
||||
"/ut/game/fifa17/auctionhouse",
|
||||
format!(
|
||||
r#"{{"itemData":{{"id":{item_id},"resourceId":{}}},"buyNowPrice":1000,"startingBid":500}}"#,
|
||||
h.sample_resource
|
||||
)
|
||||
format!(r#"{{"itemData":{{"id":{item_id}}},"buyNowPrice":1000,"startingBid":500}}"#)
|
||||
.as_bytes(),
|
||||
);
|
||||
let trade_id = bj(&list)["id"].as_i64().expect("trade id");
|
||||
|
||||
@@ -274,6 +274,7 @@ struct SeqResult {
|
||||
fn build_econ_server(
|
||||
base: &str,
|
||||
dir: &std::path::Path,
|
||||
pass_url: &str,
|
||||
) -> (Server, HttpCoreClient, Arc<Fifa17IdentityResolver>, i64) {
|
||||
let probe = HttpCoreClient::new(base, "fifa17");
|
||||
let owned = probe.all_owned().expect("core collection");
|
||||
@@ -324,6 +325,8 @@ fn build_econ_server(
|
||||
"content pool derived from real Core content"
|
||||
);
|
||||
let services = Arc::new(EconomyServices {
|
||||
// Production default: the sold experiment is OFF.
|
||||
sold_experiment: openfut_utas_host::sold_experiment::SoldExperiment::OFF,
|
||||
econ,
|
||||
market,
|
||||
piles,
|
||||
@@ -334,7 +337,7 @@ fn build_econ_server(
|
||||
core,
|
||||
entities,
|
||||
resolver.clone(),
|
||||
Arc::new(PassClient::new("http://127.0.0.1:9")),
|
||||
Arc::new(PassClient::new(pass_url)),
|
||||
33068179,
|
||||
)
|
||||
.with_economy(services);
|
||||
@@ -349,7 +352,8 @@ fn economy_sequence(base: &str, dir: &std::path::Path) -> SeqResult {
|
||||
wait_ready(base);
|
||||
// Core is seeded (start_core_seeded): a fifa17 profile with 100k coins + one
|
||||
// owned instance per definition. No /auth/local — the profile already exists.
|
||||
let (server, client, resolver, sample_resource) = build_econ_server(base, dir);
|
||||
let (server, client, resolver, _sample_resource) =
|
||||
build_econ_server(base, dir, "http://127.0.0.1:9");
|
||||
let start = client.balance().unwrap();
|
||||
assert!(start >= 5000, "seeded dev balance present ({start})");
|
||||
|
||||
@@ -438,14 +442,16 @@ fn economy_sequence(base: &str, dir: &std::path::Path) -> SeqResult {
|
||||
|
||||
// 5) MARKET buy-now (async handlers via the bridge): list -> query -> buy ->
|
||||
// query -> second buy fails, exactly one debit + one sale.
|
||||
// List a still-owned minted card (items[0] was quick-sold, items[1] is moved
|
||||
// below). The body carries the wire id ALONE — the server resolves the owned
|
||||
// card's Core card_id + FIFA resourceId from inventory.
|
||||
let list_wire = items[2]["id"].as_i64().unwrap();
|
||||
let list = server
|
||||
.try_handle_economy(
|
||||
"POST",
|
||||
"/ut/game/fifa17/auctionhouse",
|
||||
&[],
|
||||
format!(
|
||||
r#"{{"itemData":{{"id":777,"resourceId":{sample_resource}}},"buyNowPrice":1000,"startingBid":500}}"#
|
||||
)
|
||||
format!(r#"{{"itemData":{{"id":{list_wire}}},"buyNowPrice":1000,"startingBid":500}}"#)
|
||||
.as_bytes(),
|
||||
None,
|
||||
)
|
||||
@@ -502,13 +508,14 @@ fn economy_sequence(base: &str, dir: &std::path::Path) -> SeqResult {
|
||||
);
|
||||
|
||||
// 6) MARKET cancel: a cancelled listing cannot be bought.
|
||||
let cancel_wire = items[3]["id"].as_i64().unwrap();
|
||||
let clist = server
|
||||
.try_handle_economy(
|
||||
"POST",
|
||||
"/ut/game/fifa17/auctionhouse",
|
||||
&[],
|
||||
format!(
|
||||
r#"{{"itemData":{{"id":888,"resourceId":{sample_resource}}},"buyNowPrice":1000,"startingBid":500}}"#
|
||||
r#"{{"itemData":{{"id":{cancel_wire}}},"buyNowPrice":1000,"startingBid":500}}"#
|
||||
)
|
||||
.as_bytes(),
|
||||
None,
|
||||
@@ -757,6 +764,11 @@ fn from_config(base: &str, dir: &std::path::Path) -> openfut_utas_host::config::
|
||||
persona_id: 33_068_179,
|
||||
market_db_path: dir.join("market.db").to_string_lossy().into_owned(),
|
||||
pile_db_path: dir.join("pile.db").to_string_lossy().into_owned(),
|
||||
clientdata_path: dir.join("clientdata.json").to_string_lossy().into_owned(),
|
||||
account_path: dir
|
||||
.join("active_account.json")
|
||||
.to_string_lossy()
|
||||
.into_owned(),
|
||||
}
|
||||
}
|
||||
|
||||
@@ -793,6 +805,11 @@ fn exercise_from_config(base: &str, dir: &std::path::Path) -> i64 {
|
||||
)
|
||||
.expect("buy routed");
|
||||
assert_eq!(buy.status, 200);
|
||||
// A listing must name a card the club actually owns, so take one the BUY minted.
|
||||
let list_wire = serde_json::from_slice::<Value>(&buy.body).unwrap()["createPackResponse"]
|
||||
["itemList"][0]["id"]
|
||||
.as_i64()
|
||||
.expect("minted wire id");
|
||||
assert_eq!(
|
||||
client.balance().unwrap(),
|
||||
start - 400,
|
||||
@@ -805,7 +822,8 @@ fn exercise_from_config(base: &str, dir: &std::path::Path) -> i64 {
|
||||
"POST",
|
||||
"/ut/game/fifa17/auctionhouse",
|
||||
&[],
|
||||
br#"{"itemData":{"id":555,"resourceId":20000},"buyNowPrice":1000,"startingBid":500}"#,
|
||||
format!(r#"{{"itemData":{{"id":{list_wire}}},"buyNowPrice":1000,"startingBid":500}}"#)
|
||||
.as_bytes(),
|
||||
None,
|
||||
)
|
||||
.expect("list routed");
|
||||
@@ -889,3 +907,529 @@ async fn from_config_constructs_and_serves_economy() {
|
||||
|
||||
std::fs::remove_dir_all(&dir).ok();
|
||||
}
|
||||
|
||||
// ─────────────── Post-barrier authority proofs (NEVER BOTH / no fallback / ────
|
||||
// stale reader), through the REAL handle_with_ip dispatch ──────
|
||||
|
||||
/// A mock Python UTAS upstream that COUNTS every request it receives and always
|
||||
/// answers with a distinctive marker body carrying coins=111. If an economy
|
||||
/// route ever reaches Python, this counter moves and/or the marker leaks.
|
||||
struct MockPython {
|
||||
calls: Arc<std::sync::atomic::AtomicUsize>,
|
||||
url: String,
|
||||
}
|
||||
|
||||
fn start_mock_python() -> MockPython {
|
||||
use std::io::{Read, Write};
|
||||
let listener = std::net::TcpListener::bind("127.0.0.1:0").unwrap();
|
||||
let addr = listener.local_addr().unwrap();
|
||||
let calls = Arc::new(std::sync::atomic::AtomicUsize::new(0));
|
||||
let c2 = calls.clone();
|
||||
std::thread::spawn(move || {
|
||||
for stream in listener.incoming() {
|
||||
let Ok(mut s) = stream else { continue };
|
||||
c2.fetch_add(1, std::sync::atomic::Ordering::SeqCst);
|
||||
let mut buf = [0u8; 8192];
|
||||
let _ = s.read(&mut buf);
|
||||
let body = br#"{"__python__":true,"credits":111,"currencies":[{"name":"coins","funds":111,"finalFunds":111}],"userInfo":{"currencies":[{"name":"coins","funds":111,"finalFunds":111}]},"purchase":[]}"#;
|
||||
let head = format!(
|
||||
"HTTP/1.1 200 OK\r\nContent-Type: application/json\r\nContent-Length: {}\r\nConnection: close\r\n\r\n",
|
||||
body.len()
|
||||
);
|
||||
let _ = s.write_all(head.as_bytes());
|
||||
let _ = s.write_all(body);
|
||||
}
|
||||
});
|
||||
MockPython {
|
||||
calls,
|
||||
url: format!("http://{addr}"),
|
||||
}
|
||||
}
|
||||
|
||||
/// The pure economy routes (userMassInfo excluded — it is the documented hybrid
|
||||
/// that proxies the Python envelope but Rust-overlays the economy fields).
|
||||
fn pure_economy_routes() -> Vec<(&'static str, String, Vec<u8>)> {
|
||||
vec![
|
||||
("GET", "/ut/game/fifa17/user/credits".into(), b"".to_vec()),
|
||||
(
|
||||
"GET",
|
||||
"/ut/game/fifa17/store/purchasegroup".into(),
|
||||
b"".to_vec(),
|
||||
),
|
||||
(
|
||||
"PUT",
|
||||
"/ut/game/fifa17/store/transaction".into(),
|
||||
br#"{"packId":1}"#.to_vec(),
|
||||
),
|
||||
(
|
||||
"POST",
|
||||
"/ut/game/fifa17/purchased".into(),
|
||||
br#"{"packId":70}"#.to_vec(),
|
||||
),
|
||||
("GET", "/ut/game/fifa17/purchased".into(), b"".to_vec()),
|
||||
(
|
||||
"DELETE",
|
||||
"/ut/game/fifa17/item/100000001".into(),
|
||||
b"".to_vec(),
|
||||
),
|
||||
(
|
||||
"POST",
|
||||
"/ut/delete/game/fifa17/item".into(),
|
||||
br#"{"itemData":[{"id":100000001}]}"#.to_vec(),
|
||||
),
|
||||
(
|
||||
"PUT",
|
||||
"/ut/game/fifa17/item".into(),
|
||||
br#"{"itemData":[{"id":100000001,"pile":"trade"}]}"#.to_vec(),
|
||||
),
|
||||
(
|
||||
"POST",
|
||||
"/ut/delete/game/fifa17/match".into(),
|
||||
br#"{"endReason":"WIN"}"#.to_vec(),
|
||||
),
|
||||
(
|
||||
"POST",
|
||||
"/ut/game/fifa17/auctionhouse".into(),
|
||||
br#"{"itemData":{"id":555,"resourceId":20000},"buyNowPrice":1000,"startingBid":500}"#
|
||||
.to_vec(),
|
||||
),
|
||||
("GET", "/ut/game/fifa17/tradePile".into(), b"".to_vec()),
|
||||
(
|
||||
"POST",
|
||||
"/ut/game/fifa17/trade/900000001".into(),
|
||||
b"{}".to_vec(),
|
||||
),
|
||||
(
|
||||
"DELETE",
|
||||
"/ut/delete/game/fifa17/trade/900000001".into(),
|
||||
b"".to_vec(),
|
||||
),
|
||||
// ── Retail v2 Store family (the S2 live-failure shapes). These MUST be
|
||||
// Rust-owned exactly like their v1 forms. ──
|
||||
(
|
||||
"PUT",
|
||||
"/ut/v2/game/fifa17/store/transaction/0".into(),
|
||||
br#"{"packId":1}"#.to_vec(),
|
||||
),
|
||||
(
|
||||
"GET",
|
||||
"/ut/v2/game/fifa17/store/purchasegroup".into(),
|
||||
b"".to_vec(),
|
||||
),
|
||||
(
|
||||
"POST",
|
||||
"/ut/v2/game/fifa17/purchased".into(),
|
||||
br#"{"packId":70}"#.to_vec(),
|
||||
),
|
||||
("GET", "/ut/v2/game/fifa17/purchased".into(), b"".to_vec()),
|
||||
// ── Round-2 retail shapes: the confirmed BUY uses POST /purchased/items,
|
||||
// reveal GET /purchased/items; hub tile polls lowercase tradepile + /counts. ──
|
||||
(
|
||||
"POST",
|
||||
"/ut/game/fifa17/purchased/items".into(),
|
||||
br#"{"packId":1}"#.to_vec(),
|
||||
),
|
||||
(
|
||||
"GET",
|
||||
"/ut/game/fifa17/purchased/items".into(),
|
||||
b"".to_vec(),
|
||||
),
|
||||
("GET", "/ut/game/fifa17/tradepile".into(), b"".to_vec()),
|
||||
(
|
||||
"GET",
|
||||
"/ut/game/fifa17/tradePile/counts".into(),
|
||||
b"".to_vec(),
|
||||
),
|
||||
]
|
||||
}
|
||||
|
||||
fn barrier_checks(base: &str, dir: &std::path::Path, mock: &MockPython) {
|
||||
wait_ready(base);
|
||||
let (server, client, _r, _sample) = build_econ_server(base, dir, &mock.url);
|
||||
let core_coins = client.balance().unwrap();
|
||||
assert_ne!(
|
||||
core_coins, 111,
|
||||
"Core must diverge from the Python marker (111)"
|
||||
);
|
||||
|
||||
// ── STALE READER: readers show Core values, never the Python 111 ──
|
||||
let cr = server.handle_with_ip("GET", "/ut/game/fifa17/user/credits", &[], b"", None);
|
||||
let crv: Value = serde_json::from_slice(&cr.body).unwrap();
|
||||
assert!(
|
||||
crv.get("__python__").is_none(),
|
||||
"credits is Rust, not the Python body"
|
||||
);
|
||||
assert_eq!(
|
||||
crv["currencies"][0]["funds"], core_coins,
|
||||
"credits coins = Core, not 111"
|
||||
);
|
||||
// userMassInfo is the hybrid: Python envelope proxied, economy Rust-overlaid.
|
||||
let mi = server.handle_with_ip("GET", "/ut/game/fifa17/userMassInfo", &[], b"", None);
|
||||
let miv: Value = serde_json::from_slice(&mi.body).unwrap();
|
||||
assert_eq!(
|
||||
miv["userInfo"]["currencies"][0]["funds"], core_coins,
|
||||
"userMassInfo coins overlaid to Core (stale Python 111 not visible)"
|
||||
);
|
||||
|
||||
// ── PART 7 REPRO: the exact S2 live-failure shape (retail v2 Store BUY,
|
||||
// `PUT /ut/v2/game/fifa17/store/transaction/0`) is now Rust-owned — it
|
||||
// debits Core and returns a `createPackResponse`, NOT the Python
|
||||
// `{"state":"TRANSACTIONCANCEL"}` no-op the rejected candidate produced. ──
|
||||
let before_buy = client.balance().unwrap();
|
||||
let calls_before_buy = mock.calls.load(std::sync::atomic::Ordering::SeqCst);
|
||||
let buy = server.handle_with_ip(
|
||||
"PUT",
|
||||
"/ut/v2/game/fifa17/store/transaction/0",
|
||||
&[],
|
||||
br#"{"packId":1}"#,
|
||||
None,
|
||||
);
|
||||
assert_eq!(buy.status, 200, "v2 Store BUY handled by Rust (200)");
|
||||
let buyv: Value = serde_json::from_slice(&buy.body).unwrap();
|
||||
assert!(
|
||||
buyv.get("createPackResponse").is_some(),
|
||||
"v2 Store BUY returns a Rust createPackResponse, not the Python no-op: {buyv}"
|
||||
);
|
||||
assert_ne!(
|
||||
buyv.get("state").and_then(|s| s.as_str()),
|
||||
Some("TRANSACTIONCANCEL"),
|
||||
"v2 Store BUY must NOT be the Python TRANSACTIONCANCEL fallback"
|
||||
);
|
||||
assert_eq!(
|
||||
mock.calls.load(std::sync::atomic::Ordering::SeqCst),
|
||||
calls_before_buy,
|
||||
"v2 Store BUY never reached the Python proxy"
|
||||
);
|
||||
let after_buy = client.balance().unwrap();
|
||||
assert!(
|
||||
after_buy < before_buy,
|
||||
"v2 Store BUY debited Core coins ({before_buy} -> {after_buy})"
|
||||
);
|
||||
|
||||
// ── NEVER BOTH (Core up): pure economy routes reach Rust, never Python ──
|
||||
let before = mock.calls.load(std::sync::atomic::Ordering::SeqCst);
|
||||
for (m, p, b) in pure_economy_routes() {
|
||||
let r = server.handle_with_ip(m, &p, &[], &b, None);
|
||||
assert!(
|
||||
!r.body.windows(10).any(|w| w == b"__python__"),
|
||||
"{m} {p} must be Rust-owned (no Python marker in body)"
|
||||
);
|
||||
}
|
||||
assert_eq!(
|
||||
mock.calls.load(std::sync::atomic::Ordering::SeqCst),
|
||||
before,
|
||||
"NEVER BOTH: no pure economy route reached the Python proxy"
|
||||
);
|
||||
|
||||
// ── NO FALLBACK: a server pointed at a DEAD Core still fails closed and
|
||||
// never proxies to Python. Built without probing Core (empty catalog +
|
||||
// empty pool), so no live Core is needed to construct it. ──
|
||||
let dead_dir = dir.join("dead");
|
||||
std::fs::create_dir_all(&dead_dir).unwrap();
|
||||
let dead = build_dead_core_server(&dead_dir, &mock.url);
|
||||
let before_down = mock.calls.load(std::sync::atomic::Ordering::SeqCst);
|
||||
let credits_down = dead.handle_with_ip("GET", "/ut/game/fifa17/user/credits", &[], b"", None);
|
||||
assert_eq!(
|
||||
credits_down.status, 503,
|
||||
"credits fails closed against a dead Core"
|
||||
);
|
||||
let match_down = dead.handle_with_ip(
|
||||
"POST",
|
||||
"/ut/delete/game/fifa17/match",
|
||||
&[],
|
||||
br#"{"endReason":"WIN"}"#,
|
||||
None,
|
||||
);
|
||||
assert_eq!(
|
||||
match_down.status, 503,
|
||||
"match fails closed against a dead Core"
|
||||
);
|
||||
for (m, p, b) in pure_economy_routes() {
|
||||
let _ = dead.handle_with_ip(m, &p, &[], &b, None);
|
||||
}
|
||||
assert_eq!(
|
||||
mock.calls.load(std::sync::atomic::Ordering::SeqCst),
|
||||
before_down,
|
||||
"NO FALLBACK: economy routes never proxy to Python even against a dead Core"
|
||||
);
|
||||
}
|
||||
|
||||
/// A `Server` whose Core (read + economy) points at a definitely-dead loopback
|
||||
/// port, wired WITHOUT probing Core: an empty catalog + empty content pool. Used
|
||||
/// to prove economy routes fail closed (503) and never fall back to Python.
|
||||
fn build_dead_core_server(dir: &std::path::Path, pass_url: &str) -> Server {
|
||||
// A closed loopback port: bind then drop, so connects are refused.
|
||||
let dead_addr = {
|
||||
let l = std::net::TcpListener::bind("127.0.0.1:0").unwrap();
|
||||
l.local_addr().unwrap()
|
||||
};
|
||||
let dead_url = format!("http://{dead_addr}");
|
||||
let catalog =
|
||||
Fifa17CardCatalog::from_json_str(r#"{"schema_version":1,"game":"fifa17","cards":{}}"#)
|
||||
.unwrap();
|
||||
let store = JsonIdentityStore::open(dir.join("identity.json").to_str().unwrap()).unwrap();
|
||||
let resolver = Arc::new(Fifa17IdentityResolver::new(catalog, Arc::new(store)));
|
||||
let entities = Arc::new(Fifa17Entities::from_maps(
|
||||
HashMap::new(),
|
||||
HashMap::new(),
|
||||
HashMap::new(),
|
||||
));
|
||||
let core: Arc<dyn CoreAccess> = Arc::new(HttpCoreClient::new(dead_url.clone(), "fifa17"));
|
||||
let bridge = Arc::new(AsyncBridge::new().unwrap());
|
||||
let mp = dir.join("market.db").to_string_lossy().into_owned();
|
||||
let market = Arc::new(
|
||||
bridge
|
||||
.block_on(async move { MarketStore::open(&mp).await })
|
||||
.unwrap(),
|
||||
);
|
||||
let pp = dir.join("pile.db").to_string_lossy().into_owned();
|
||||
let piles = Arc::new(
|
||||
bridge
|
||||
.block_on(async move { PileStore::open(&pp).await })
|
||||
.unwrap(),
|
||||
);
|
||||
let econ: Arc<dyn CoreEconomy> = Arc::new(HttpCoreClient::new(dead_url, "fifa17"));
|
||||
let services = Arc::new(EconomyServices {
|
||||
// Production default: the sold experiment is OFF.
|
||||
sold_experiment: openfut_utas_host::sold_experiment::SoldExperiment::OFF,
|
||||
econ,
|
||||
market,
|
||||
piles,
|
||||
bridge,
|
||||
pool: Arc::new(Vec::new()),
|
||||
});
|
||||
Server::new(
|
||||
core,
|
||||
entities,
|
||||
resolver,
|
||||
Arc::new(PassClient::new(pass_url)),
|
||||
33_068_179,
|
||||
)
|
||||
.with_economy(services)
|
||||
}
|
||||
|
||||
#[tokio::test(flavor = "multi_thread", worker_threads = 4)]
|
||||
async fn barrier_never_both_no_fallback_and_stale_reader() {
|
||||
let dir = std::env::temp_dir().join(format!(
|
||||
"openfut-econ-barrier-{}-{}",
|
||||
std::process::id(),
|
||||
std::time::SystemTime::now()
|
||||
.duration_since(std::time::UNIX_EPOCH)
|
||||
.unwrap()
|
||||
.as_nanos()
|
||||
));
|
||||
std::fs::create_dir_all(&dir).unwrap();
|
||||
let db_url = format!("sqlite://{}/econ.db", dir.display());
|
||||
let (h, base) = start_core_seeded(&db_url, true).await;
|
||||
let mock = start_mock_python();
|
||||
let (b, d) = (base.clone(), dir.clone());
|
||||
tokio::task::spawn_blocking(move || {
|
||||
std::thread::spawn(move || barrier_checks(&b, &d, &mock))
|
||||
.join()
|
||||
.expect("barrier checks thread")
|
||||
})
|
||||
.await
|
||||
.expect("barrier phase");
|
||||
h.abort();
|
||||
std::fs::remove_dir_all(&dir).ok();
|
||||
}
|
||||
|
||||
// ─────────────── Retail v2 Store E2E + v1/v2 route equivalence ───────────────
|
||||
//
|
||||
// Proves the S2 fix end-to-end through the REAL dispatch: the Store flow driven
|
||||
// over the retail `/ut/v2/game/<sku>/…` paths is Rust-owned (Python proxy count
|
||||
// 0), mutates Core, and behaves IDENTICALLY to the v1 paths for the same op.
|
||||
|
||||
fn v2_store_flow(base: &str, dir: &std::path::Path) {
|
||||
let mock = start_mock_python();
|
||||
let (server, client, _r, _s) = build_econ_server(base, dir, &mock.url);
|
||||
let calls0 = mock.calls.load(std::sync::atomic::Ordering::SeqCst);
|
||||
|
||||
// GET purchasegroup via v2 → Rust catalogue (non-empty).
|
||||
let pg = server.handle_with_ip(
|
||||
"GET",
|
||||
"/ut/v2/game/fifa17/store/purchasegroup",
|
||||
&[],
|
||||
b"",
|
||||
None,
|
||||
);
|
||||
assert_eq!(pg.status, 200, "v2 purchasegroup handled by Rust");
|
||||
let pgv: Value = serde_json::from_slice(&pg.body).unwrap();
|
||||
assert!(
|
||||
pgv.get("purchase")
|
||||
.and_then(|p| p.as_array())
|
||||
.is_some_and(|a| !a.is_empty()),
|
||||
"v2 purchasegroup returns a Rust catalogue: {pgv}"
|
||||
);
|
||||
|
||||
// Same pack (id 1) via v1 then v2 → IDENTICAL debit + item count (Part 6).
|
||||
let bal0 = client.balance().unwrap();
|
||||
let v1 = server.handle_with_ip(
|
||||
"PUT",
|
||||
"/ut/game/fifa17/store/transaction",
|
||||
&[],
|
||||
br#"{"packId":1}"#,
|
||||
None,
|
||||
);
|
||||
assert_eq!(v1.status, 200);
|
||||
let bal1 = client.balance().unwrap();
|
||||
let v1v: Value = serde_json::from_slice(&v1.body).unwrap();
|
||||
let v1_items = v1v["createPackResponse"]["itemList"]
|
||||
.as_array()
|
||||
.map_or(0, |a| a.len());
|
||||
let v1_debit = bal0 - bal1;
|
||||
|
||||
let v2 = server.handle_with_ip(
|
||||
"PUT",
|
||||
"/ut/v2/game/fifa17/store/transaction/0",
|
||||
&[],
|
||||
br#"{"packId":1}"#,
|
||||
None,
|
||||
);
|
||||
assert_eq!(v2.status, 200);
|
||||
let bal2 = client.balance().unwrap();
|
||||
let v2v: Value = serde_json::from_slice(&v2.body).unwrap();
|
||||
let v2_items = v2v["createPackResponse"]["itemList"]
|
||||
.as_array()
|
||||
.map_or(0, |a| a.len());
|
||||
let v2_debit = bal1 - bal2;
|
||||
|
||||
assert!(v1_items > 0, "v1 BUY minted items");
|
||||
assert_eq!(v1_items, v2_items, "v1/v2 BUY yield identical item counts");
|
||||
assert_eq!(
|
||||
v1_debit, v2_debit,
|
||||
"v1/v2 BUY debit identically ({v1_debit} vs {v2_debit})"
|
||||
);
|
||||
|
||||
// GET purchased via v2 → Rust reveal shape; the just-bought items are in the pile.
|
||||
let reveal = server.handle_with_ip("GET", "/ut/v2/game/fifa17/purchased", &[], b"", None);
|
||||
assert_eq!(reveal.status, 200, "v2 GET /purchased handled by Rust");
|
||||
let rv: Value = serde_json::from_slice(&reveal.body).unwrap();
|
||||
assert!(
|
||||
rv.get("itemData").and_then(|d| d.as_array()).is_some(),
|
||||
"v2 reveal is a Rust itemData array: {rv}"
|
||||
);
|
||||
|
||||
// NEVER any Python proxy for the whole v2 Store flow.
|
||||
assert_eq!(
|
||||
mock.calls.load(std::sync::atomic::Ordering::SeqCst),
|
||||
calls0,
|
||||
"v2 Store flow never reached the Python proxy"
|
||||
);
|
||||
}
|
||||
|
||||
#[tokio::test(flavor = "multi_thread", worker_threads = 4)]
|
||||
async fn retail_v2_store_flow_matches_v1_through_dispatch() {
|
||||
let dir = std::env::temp_dir().join(format!(
|
||||
"openfut-econ-v2-{}-{}",
|
||||
std::process::id(),
|
||||
std::time::SystemTime::now()
|
||||
.duration_since(std::time::UNIX_EPOCH)
|
||||
.unwrap()
|
||||
.as_nanos()
|
||||
));
|
||||
std::fs::create_dir_all(&dir).unwrap();
|
||||
let db_url = format!("sqlite://{}/econ.db", dir.display());
|
||||
let (h, base) = start_core_seeded(&db_url, true).await;
|
||||
let (b, d) = (base.clone(), dir.clone());
|
||||
tokio::task::spawn_blocking(move || {
|
||||
std::thread::spawn(move || v2_store_flow(&b, &d))
|
||||
.join()
|
||||
.expect("v2 store flow thread")
|
||||
})
|
||||
.await
|
||||
.expect("v2 store phase");
|
||||
h.abort();
|
||||
std::fs::remove_dir_all(&dir).ok();
|
||||
}
|
||||
|
||||
// ─────────────── Retail /purchased/items BUY sequence (round-2 S2 regression) ─
|
||||
//
|
||||
// The rejected candidate 47ced22 sent the confirmed retail Store BUY
|
||||
// (POST /ut/game/fifa17/purchased/items) to Python and left Core coins unchanged.
|
||||
// This replays the exact live sequence through real dispatch and asserts the BUY
|
||||
// debits Core, the reveal shows the minted items, and Python proxy count is 0.
|
||||
|
||||
fn retail_purchased_items_flow(base: &str, dir: &std::path::Path) {
|
||||
let mock = start_mock_python();
|
||||
let (server, client, _r, _s) = build_econ_server(base, dir, &mock.url);
|
||||
let calls0 = mock.calls.load(std::sync::atomic::Ordering::SeqCst);
|
||||
|
||||
// Store screen catalogue (v1 /all) — Rust.
|
||||
let pg = server.handle_with_ip(
|
||||
"GET",
|
||||
"/ut/game/fifa17/store/purchasegroup/all",
|
||||
&[],
|
||||
b"",
|
||||
None,
|
||||
);
|
||||
assert_eq!(pg.status, 200, "purchasegroup/all Rust-owned");
|
||||
|
||||
// THE CONFIRMED RETAIL BUY: POST /ut/game/fifa17/purchased/items must debit Core.
|
||||
let bal0 = client.balance().unwrap();
|
||||
let buy = server.handle_with_ip(
|
||||
"POST",
|
||||
"/ut/game/fifa17/purchased/items",
|
||||
&[],
|
||||
br#"{"packId":1}"#,
|
||||
None,
|
||||
);
|
||||
assert_eq!(buy.status, 200, "purchased/items BUY handled by Rust (200)");
|
||||
assert!(
|
||||
!buy.body.windows(10).any(|w| w == b"__python__"),
|
||||
"purchased/items BUY is Rust-owned (no Python marker)"
|
||||
);
|
||||
let bal1 = client.balance().unwrap();
|
||||
assert!(
|
||||
bal1 < bal0,
|
||||
"purchased/items BUY debited Core ({bal0} -> {bal1}) — the round-2 S2 was NO debit"
|
||||
);
|
||||
|
||||
// Reveal poll: GET /ut/game/fifa17/purchased/items — Rust, shows the minted items.
|
||||
let reveal = server.handle_with_ip("GET", "/ut/game/fifa17/purchased/items", &[], b"", None);
|
||||
assert_eq!(reveal.status, 200, "purchased/items reveal Rust-owned");
|
||||
let rv: Value = serde_json::from_slice(&reveal.body).unwrap();
|
||||
let revealed = rv["itemData"].as_array().map_or(0, |a| a.len());
|
||||
assert!(revealed > 0, "reveal shows the freshly-minted items: {rv}");
|
||||
|
||||
// Repeat reveal is idempotent (no re-grant, no extra debit).
|
||||
let bal2 = client.balance().unwrap();
|
||||
let _ = server.handle_with_ip("GET", "/ut/game/fifa17/purchased/items", &[], b"", None);
|
||||
assert_eq!(
|
||||
client.balance().unwrap(),
|
||||
bal2,
|
||||
"repeat reveal does not mutate coins"
|
||||
);
|
||||
|
||||
// NEVER any Python proxy across the whole /purchased/items sequence.
|
||||
assert_eq!(
|
||||
mock.calls.load(std::sync::atomic::Ordering::SeqCst),
|
||||
calls0,
|
||||
"retail /purchased/items sequence never reached the Python proxy"
|
||||
);
|
||||
}
|
||||
|
||||
#[tokio::test(flavor = "multi_thread", worker_threads = 4)]
|
||||
async fn retail_purchased_items_buy_debits_core_through_dispatch() {
|
||||
let dir = std::env::temp_dir().join(format!(
|
||||
"openfut-econ-pi-{}-{}",
|
||||
std::process::id(),
|
||||
std::time::SystemTime::now()
|
||||
.duration_since(std::time::UNIX_EPOCH)
|
||||
.unwrap()
|
||||
.as_nanos()
|
||||
));
|
||||
std::fs::create_dir_all(&dir).unwrap();
|
||||
let db_url = format!("sqlite://{}/econ.db", dir.display());
|
||||
let (h, base) = start_core_seeded(&db_url, true).await;
|
||||
let (b, d) = (base.clone(), dir.clone());
|
||||
tokio::task::spawn_blocking(move || {
|
||||
std::thread::spawn(move || retail_purchased_items_flow(&b, &d))
|
||||
.join()
|
||||
.expect("purchased/items flow thread")
|
||||
})
|
||||
.await
|
||||
.expect("purchased/items phase");
|
||||
h.abort();
|
||||
std::fs::remove_dir_all(&dir).ok();
|
||||
}
|
||||
|
||||
@@ -12,11 +12,12 @@ use openfut_adapter_fifa17::fut::catalog::Fifa17CardCatalog;
|
||||
use openfut_adapter_fifa17::fut::club_response::{CoreOwnedItem, ItemIdentityResolver};
|
||||
use openfut_adapter_fifa17::fut::entities::Fifa17Entities;
|
||||
use openfut_identity::JsonIdentityStore;
|
||||
use openfut_utas_host::account_store::AccountStore;
|
||||
use openfut_utas_host::{
|
||||
classify, handle_put_squad, handle_squad_active, handle_squad_list, handle_user_mass_info,
|
||||
read_request, CoreAccess, CoreError, CoreExtState, CorePage, CoreReplaceRequest,
|
||||
CoreReplaceResult, CoreSquadRead, CoreSquadSlot, Fifa17IdentityResolver, HttpCoreClient,
|
||||
PassClient, Route, Server, SquadDeps,
|
||||
classify, handle_club, handle_put_squad, handle_squad_active, handle_squad_list,
|
||||
handle_user_mass_info, read_request, ClubDeps, CoreAccess, CoreError, CoreExtState, CorePage,
|
||||
CoreReplaceRequest, CoreReplaceResult, CoreSquadRead, CoreSquadSlot, Fifa17IdentityResolver,
|
||||
HttpCoreClient, PassClient, Route, Server, SquadDeps,
|
||||
};
|
||||
use parking_lot::Mutex;
|
||||
use serde_json::Value;
|
||||
@@ -279,6 +280,110 @@ fn build_server(
|
||||
)
|
||||
}
|
||||
|
||||
/// A real identity resolver over a `card_id -> asset_id` map (same construction
|
||||
/// `build_server` uses), for tests that call `handle_club` directly.
|
||||
fn resolver_for(cards: &[(&str, u32)]) -> Arc<Fifa17IdentityResolver> {
|
||||
let entries: Vec<String> = cards
|
||||
.iter()
|
||||
.map(|(id, asset)| format!("\"{id}\":{{\"asset_id\":{asset}}}"))
|
||||
.collect();
|
||||
let doc = format!(
|
||||
"{{\"schema_version\":1,\"game\":\"fifa17\",\"cards\":{{{}}}}}",
|
||||
entries.join(",")
|
||||
);
|
||||
let catalog = Fifa17CardCatalog::from_json_str(&doc).unwrap();
|
||||
let store = JsonIdentityStore::open(unique_store_path()).unwrap();
|
||||
Arc::new(Fifa17IdentityResolver::new(catalog, Arc::new(store)))
|
||||
}
|
||||
|
||||
/// A card with an ACTIVE listing has LEFT the club: `/club` must not show it, and
|
||||
/// pagination must run over the CLUB-VISIBLE set (never Core's unfiltered page,
|
||||
/// which would hand back short pages).
|
||||
#[test]
|
||||
fn club_excludes_listed_items_and_paginates_the_visible_set() {
|
||||
let core = Arc::new(FakeCore::new(
|
||||
vec![
|
||||
item(
|
||||
"oc1",
|
||||
"card_a",
|
||||
86,
|
||||
"CDM",
|
||||
"Argentina",
|
||||
"Premier League",
|
||||
"Chelsea",
|
||||
),
|
||||
item(
|
||||
"oc2",
|
||||
"card_b",
|
||||
85,
|
||||
"ST",
|
||||
"Argentina",
|
||||
"Premier League",
|
||||
"Chelsea",
|
||||
),
|
||||
item(
|
||||
"oc3",
|
||||
"card_c",
|
||||
84,
|
||||
"CB",
|
||||
"Argentina",
|
||||
"Premier League",
|
||||
"Chelsea",
|
||||
),
|
||||
],
|
||||
3,
|
||||
));
|
||||
let resolver = resolver_for(&[("card_a", 20801), ("card_b", 20802), ("card_c", 20803)]);
|
||||
let ents = entities();
|
||||
|
||||
// oc2 has an active transfer-market listing.
|
||||
let hidden: std::collections::HashSet<String> = ["oc2".to_string()].into_iter().collect();
|
||||
let deps = ClubDeps {
|
||||
core: core.as_ref(),
|
||||
entities: &ents,
|
||||
assets: resolver.as_ref(),
|
||||
hidden: &hidden,
|
||||
};
|
||||
let (resp, log) = handle_club("", &deps);
|
||||
let v: Value = serde_json::from_slice(&resp.body).unwrap();
|
||||
let assets: Vec<i64> = v["itemData"]
|
||||
.as_array()
|
||||
.unwrap()
|
||||
.iter()
|
||||
.map(|i| i["assetId"].as_i64().unwrap())
|
||||
.collect();
|
||||
assert_eq!(
|
||||
assets,
|
||||
vec![20801, 20803],
|
||||
"the transfer-pile card is not in the club"
|
||||
);
|
||||
assert_eq!(log.total, 2, "total is the club-visible count");
|
||||
|
||||
// A page of 2 over a 2-item visible set is FULL — not short because a hidden
|
||||
// item consumed a slot.
|
||||
let (resp2, log2) = handle_club("count=2", &deps);
|
||||
let v2: Value = serde_json::from_slice(&resp2.body).unwrap();
|
||||
assert_eq!(
|
||||
v2["itemData"].as_array().unwrap().len(),
|
||||
2,
|
||||
"full-width page from the visible set"
|
||||
);
|
||||
assert_eq!(log2.total, 2);
|
||||
|
||||
// Nothing hidden → the fast Core-paginated path, all three visible.
|
||||
let none: std::collections::HashSet<String> = std::collections::HashSet::new();
|
||||
let deps_all = ClubDeps {
|
||||
core: core.as_ref(),
|
||||
entities: &ents,
|
||||
assets: resolver.as_ref(),
|
||||
hidden: &none,
|
||||
};
|
||||
let (resp3, log3) = handle_club("", &deps_all);
|
||||
let v3: Value = serde_json::from_slice(&resp3.body).unwrap();
|
||||
assert_eq!(v3["itemData"].as_array().unwrap().len(), 3);
|
||||
assert_eq!(log3.total, 3);
|
||||
}
|
||||
|
||||
// ── /club served from Core ─────────────────────────────────────────────────
|
||||
|
||||
#[test]
|
||||
@@ -422,21 +527,43 @@ fn passthrough_forwards_verbatim_and_never_calls_core() {
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn mutating_route_classifies_to_passthrough_not_rust() {
|
||||
// A PUT to the club PATH is NOT the read route; it must go to Python, never
|
||||
// execute Rust/Core (guards against double-applying a mutation).
|
||||
assert_eq!(classify("PUT", "/ut/game/fifa17/club"), Route::Passthrough);
|
||||
fn club_rename_is_rust_owned_persistent_and_never_calls_python_or_core() {
|
||||
assert_eq!(classify("PUT", "/ut/game/fifa17/club"), Route::ClubRename);
|
||||
assert_eq!(
|
||||
classify("PUT", "/ut/game/fifa17/user/club"),
|
||||
Route::ClubRename
|
||||
);
|
||||
assert_eq!(
|
||||
classify("POST", "/ut/game/fifa17/user/club"),
|
||||
Route::ClubRename
|
||||
);
|
||||
assert_eq!(
|
||||
classify("POST", "/ut/game/fifa17/squad/0"),
|
||||
Route::Passthrough
|
||||
);
|
||||
|
||||
let (upstream, _rec) = spawn_mock_python();
|
||||
let (upstream, rec) = spawn_mock_python();
|
||||
let core = Arc::new(FakeCore::forbidden());
|
||||
let server = build_server(core.clone(), &upstream, None);
|
||||
let resp = server.handle("PUT", "/ut/game/fifa17/club", &[], br#"{"x":1}"#);
|
||||
let account_path = unique_store_path();
|
||||
let account = Arc::new(AccountStore::open(&account_path));
|
||||
let server = build_server(core.clone(), &upstream, None).with_account(account.clone());
|
||||
let resp = server.handle(
|
||||
"PUT",
|
||||
"/ut/game/fifa17/user/club",
|
||||
&[],
|
||||
br#"{"clubName":"Real FUT","clubAbbr":"RF"}"#,
|
||||
);
|
||||
assert_eq!(resp.status, 200);
|
||||
assert_eq!(
|
||||
serde_json::from_slice::<Value>(&resp.body).unwrap(),
|
||||
json!({})
|
||||
);
|
||||
assert_eq!(account.club().name, "Real FUT");
|
||||
assert_eq!(account.club().abbr, "RF");
|
||||
assert_eq!(AccountStore::open(&account_path).club(), account.club());
|
||||
assert_eq!(core.calls(), 0);
|
||||
assert_eq!(rec.lock().len(), 0, "rename never reached Python");
|
||||
let _ = std::fs::remove_file(account_path);
|
||||
}
|
||||
|
||||
// ── End-to-end over a socket (read_request + write_response + keep-alive) ─────
|
||||
@@ -794,8 +921,8 @@ fn classify_squad_and_usermassinfo_routes() {
|
||||
classify("GET", "/ut/game/fifa17/userMassInfo"),
|
||||
Route::UserMassInfo
|
||||
);
|
||||
// GET /squad/active is now Core-backed (SquadActive). A squad PUT is never a
|
||||
// GET; a numeric GET /squad/<n> for a non-active squad stays on Python.
|
||||
// GET /squad/active and every numeric GET are the one Core-backed current
|
||||
// squad, matching the oracle's single-squad response regardless of URL id.
|
||||
assert_eq!(
|
||||
classify("GET", "/ut/game/fifa17/squad/active"),
|
||||
Route::SquadActive
|
||||
@@ -806,7 +933,11 @@ fn classify_squad_and_usermassinfo_routes() {
|
||||
);
|
||||
assert_eq!(
|
||||
classify("GET", "/ut/game/fifa17/squad/0"),
|
||||
Route::Passthrough
|
||||
Route::SquadActive
|
||||
);
|
||||
assert_eq!(
|
||||
classify("GET", "/ut/game/fifa17/squad/5"),
|
||||
Route::SquadActive
|
||||
);
|
||||
assert_eq!(
|
||||
classify("PUT", "/ut/game/fifa17/squad/list"),
|
||||
@@ -815,6 +946,39 @@ fn classify_squad_and_usermassinfo_routes() {
|
||||
assert_eq!(classify("GET", "/ut/game/fifa17/club"), Route::Club);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn numbered_squad_get_returns_current_core_squad_without_python() {
|
||||
let items = vec![gk(), st()];
|
||||
let (resolver, wires) = resolver_with_wires(&items, ASSETS);
|
||||
let core = Arc::new(FakeCore::new(items, 2));
|
||||
let (python, recorded) = spawn_mock_python();
|
||||
let server = Server::new(
|
||||
core,
|
||||
Arc::new(entities()),
|
||||
Arc::new(resolver),
|
||||
Arc::new(PassClient::new(&python)),
|
||||
33_068_179,
|
||||
);
|
||||
let put = server.handle(
|
||||
"PUT",
|
||||
"/ut/game/fifa17/squad/0",
|
||||
&[],
|
||||
&put_body(
|
||||
"f442",
|
||||
wires["oc-a"],
|
||||
&[(0, wires["oc-a"], 1), (1, wires["oc-b"], 9)],
|
||||
"[1,2,3]",
|
||||
),
|
||||
);
|
||||
assert_eq!(put.status, 200);
|
||||
|
||||
let active = server.handle("GET", "/ut/game/fifa17/squad/active", &[], b"");
|
||||
let numbered = server.handle("GET", "/ut/game/fifa17/squad/5", &[], b"");
|
||||
assert_eq!(numbered.status, 200);
|
||||
assert_eq!(numbered.body, active.body);
|
||||
assert_eq!(recorded.lock().len(), 0, "numeric GET never reached Python");
|
||||
}
|
||||
|
||||
// ── PUT pipeline ────────────────────────────────────────────────────────────
|
||||
|
||||
#[test]
|
||||
@@ -1347,3 +1511,127 @@ fn duplicate_definition_instances_stay_distinct_through_host() {
|
||||
assert_eq!(p["itemData"]["resourceId"], 20801, "shared asset id");
|
||||
}
|
||||
}
|
||||
|
||||
// ── Non-economy routes owned by Rust (no Python fallback, no Core) ──────────────
|
||||
|
||||
/// The migrated non-economy static routes are served entirely by Rust: exact
|
||||
/// oracle-matching bodies, never proxied to Python, never touching Core. The
|
||||
/// security-question route fails closed (400) for an unknown session in Rust —
|
||||
/// again without any Python fallback. This is the per-domain no-fallback proof.
|
||||
#[test]
|
||||
fn non_economy_routes_rust_owned_no_python_no_core() {
|
||||
let core = Arc::new(FakeCore::forbidden()); // any Core call panics
|
||||
let (py_url, rec) = spawn_mock_python();
|
||||
let server = build_server(core, &py_url, None);
|
||||
|
||||
let cases: &[(&str, &str, serde_json::Value)] = &[
|
||||
(
|
||||
"GET",
|
||||
"/ut/game/fifa17/user/accountinfo",
|
||||
serde_json::json!({}),
|
||||
),
|
||||
(
|
||||
"GET",
|
||||
"/ut/game/fifa17/settings",
|
||||
serde_json::json!({ "configs": [] }),
|
||||
),
|
||||
(
|
||||
"GET",
|
||||
"/ut/game/fifa17/leaderboards/options",
|
||||
serde_json::json!({}),
|
||||
),
|
||||
("PUT", "/ut/game/fifa17/match/reset", serde_json::json!({})),
|
||||
(
|
||||
"GET",
|
||||
"/ut/game/fifa17/club/stats/staff",
|
||||
serde_json::json!({}),
|
||||
),
|
||||
];
|
||||
for (m, p, want) in cases {
|
||||
let resp = server.handle(m, p, &[], b"");
|
||||
assert_eq!(resp.status, 200, "{m} {p} status");
|
||||
let body: Value = serde_json::from_slice(&resp.body).unwrap();
|
||||
assert_eq!(&body, want, "{m} {p} body");
|
||||
}
|
||||
|
||||
// Security-question with an unknown session fails closed in Rust (never proxied).
|
||||
let resp = server.handle(
|
||||
"GET",
|
||||
"/ut/game/fifa17/phishing/trusteddevice?deviceId=6236375476659cd0f6c780e728774b71",
|
||||
&[("X-UT-SID".into(), "unknown-sid".into())],
|
||||
b"",
|
||||
);
|
||||
assert_eq!(resp.status, 400);
|
||||
let body: Value = serde_json::from_slice(&resp.body).unwrap();
|
||||
assert_eq!(body, serde_json::json!({ "reason": "invalid_session" }));
|
||||
|
||||
// None of the migrated routes reached the Python upstream.
|
||||
assert_eq!(
|
||||
rec.lock().len(),
|
||||
0,
|
||||
"no Python fallback for migrated non-economy routes"
|
||||
);
|
||||
}
|
||||
|
||||
/// `GET /hub` is served from Rust: `clubPlayers` counts owned PLAYER cards in
|
||||
/// Core, auction/tradePile counts come from the durable market store (0 with no
|
||||
/// economy wired), and Python is never consulted.
|
||||
#[test]
|
||||
fn hub_counts_players_from_core_no_python() {
|
||||
let items = vec![
|
||||
item("oc1", "card_a", 84, "ST", "Brazil", "La Liga", "Barcelona"),
|
||||
item("oc2", "card_b", 80, "CM", "Spain", "La Liga", "Real Madrid"),
|
||||
item("oc3", "card_c", 77, "CB", "France", "Ligue 1", "PSG"),
|
||||
];
|
||||
let core = Arc::new(FakeCore::new(items, 3));
|
||||
let (py_url, rec) = spawn_mock_python();
|
||||
let server = build_server(core, &py_url, None);
|
||||
|
||||
let resp = server.handle("GET", "/ut/game/fifa17/hub", &[], b"");
|
||||
assert_eq!(resp.status, 200);
|
||||
let body: Value = serde_json::from_slice(&resp.body).unwrap();
|
||||
assert_eq!(body["clubPlayers"], 3, "counts owned player cards");
|
||||
assert_eq!(body["auctionCount"], 0, "no economy wired => 0 listings");
|
||||
assert_eq!(
|
||||
body["tradePile"],
|
||||
serde_json::json!({ "count": 0, "selling": 0, "sold": 0 })
|
||||
);
|
||||
assert_eq!(rec.lock().len(), 0, "hub never reaches Python");
|
||||
}
|
||||
|
||||
/// `GET /club/stats/year` is served from Rust with Core-accurate player tier
|
||||
/// counts (contextId 1 global bucket), never reaching Python.
|
||||
#[test]
|
||||
fn club_stats_year_counts_tiers_from_core_no_python() {
|
||||
let items = vec![
|
||||
item("oc1", "card_a", 90, "ST", "Brazil", "La Liga", "Barcelona"), // gold
|
||||
item("oc2", "card_b", 70, "CM", "Spain", "La Liga", "Real Madrid"), // silver
|
||||
item("oc3", "card_c", 60, "CB", "France", "Ligue 1", "PSG"), // bronze
|
||||
];
|
||||
let core = Arc::new(FakeCore::new(items, 3));
|
||||
let (py_url, rec) = spawn_mock_python();
|
||||
let server = build_server(core, &py_url, None);
|
||||
|
||||
let resp = server.handle("GET", "/ut/game/fifa17/club/stats/year", &[], b"");
|
||||
assert_eq!(resp.status, 200);
|
||||
let body: Value = serde_json::from_slice(&resp.body).unwrap();
|
||||
let g: std::collections::HashMap<String, i64> = body["stat"]
|
||||
.as_array()
|
||||
.unwrap()
|
||||
.iter()
|
||||
.filter(|r| r["contextId"] == 1)
|
||||
.map(|r| {
|
||||
(
|
||||
r["type"].as_str().unwrap().to_string(),
|
||||
r["typeValue"].as_i64().unwrap(),
|
||||
)
|
||||
})
|
||||
.collect();
|
||||
assert_eq!(g["players"], 3);
|
||||
assert_eq!(g["playersGold"], 1);
|
||||
assert_eq!(g["playersSilver"], 1);
|
||||
assert_eq!(g["playersBronze"], 1);
|
||||
assert_eq!(g["consumables"], 0);
|
||||
assert_eq!(g["staff"], 0);
|
||||
assert_eq!(rec.lock().len(), 0, "club/stats never reaches Python");
|
||||
}
|
||||
|
||||
Executable
+113
@@ -0,0 +1,113 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Recover FIFA's on-screen error text from the live client, read-only.
|
||||
|
||||
Diagnosing this squad error from the server side has failed repeatedly: the host
|
||||
answers 200/ok for every request, the squad round-trips exactly, and its shape now
|
||||
matches production's known-good squad field for field. So the message the client is
|
||||
actually showing is the missing evidence.
|
||||
|
||||
Scans readable regions of /proc/<pid>/mem for candidate substrings in both ASCII and
|
||||
UTF-16LE (FIFA UI strings are typically wide), and prints the surrounding text so the
|
||||
full sentence and any error code come out. Opens the memory O_RDONLY and only ever
|
||||
pread()s -- it cannot perturb the process.
|
||||
"""
|
||||
import os
|
||||
import re
|
||||
import sys
|
||||
|
||||
NEEDLES = [b"quad Update", b"quad update", b"QUAD_UPDATE", b"quad_update",
|
||||
b"pdate your squad", b"pdating squad", b"quad Management",
|
||||
b"nable to update", b"FUT_ERR", b"SQUAD_ERR"]
|
||||
MAX_REGION = 96 * 1024 * 1024 # skip absurd regions; the UI heap is not that big
|
||||
CONTEXT = 140
|
||||
|
||||
|
||||
def pid_of(name="FIFA17.exe"):
|
||||
for d in os.listdir("/proc"):
|
||||
if not d.isdigit():
|
||||
continue
|
||||
try:
|
||||
if open(f"/proc/{d}/comm").read().strip() == name:
|
||||
return int(d)
|
||||
except OSError:
|
||||
continue
|
||||
return None
|
||||
|
||||
|
||||
def wide(b):
|
||||
"""UTF-16LE form of an ASCII needle."""
|
||||
return b"".join(bytes([c, 0]) for c in b)
|
||||
|
||||
|
||||
def regions(pid):
|
||||
out = []
|
||||
for line in open(f"/proc/{pid}/maps"):
|
||||
parts = line.split()
|
||||
if len(parts) < 2 or "r" not in parts[1]:
|
||||
continue
|
||||
lo, _, hi = parts[0].partition("-")
|
||||
lo, hi = int(lo, 16), int(hi, 16)
|
||||
size = hi - lo
|
||||
if 0 < size <= MAX_REGION:
|
||||
out.append((lo, size, parts[-1] if len(parts) > 5 else ""))
|
||||
return out
|
||||
|
||||
|
||||
def render(buf, pos, is_wide):
|
||||
lo = max(0, pos - CONTEXT)
|
||||
hi = min(len(buf), pos + CONTEXT)
|
||||
chunk = buf[lo:hi]
|
||||
if is_wide:
|
||||
try:
|
||||
txt = chunk.decode("utf-16le", errors="replace")
|
||||
except Exception:
|
||||
txt = repr(chunk)
|
||||
else:
|
||||
txt = chunk.decode("latin-1", errors="replace")
|
||||
txt = re.sub(r"[^\x20-\x7e]+", " ", txt)
|
||||
return re.sub(r"\s{2,}", " ", txt).strip()
|
||||
|
||||
|
||||
def main():
|
||||
pid = pid_of()
|
||||
if not pid:
|
||||
print("FIFA17.exe not running")
|
||||
return 1
|
||||
print(f"scanning pid {pid}")
|
||||
targets = [(n, False) for n in NEEDLES] + [(wide(n), True) for n in NEEDLES]
|
||||
hits, scanned = [], 0
|
||||
fd = os.open(f"/proc/{pid}/mem", os.O_RDONLY)
|
||||
try:
|
||||
for lo, size, path in regions(pid):
|
||||
try:
|
||||
buf = os.pread(fd, size, lo)
|
||||
except OSError:
|
||||
continue
|
||||
scanned += size
|
||||
for needle, is_wide in targets:
|
||||
start = 0
|
||||
while True:
|
||||
p = buf.find(needle, start)
|
||||
if p < 0:
|
||||
break
|
||||
hits.append((lo + p, is_wide, render(buf, p, is_wide), path))
|
||||
start = p + 1
|
||||
if len(hits) > 60:
|
||||
break
|
||||
finally:
|
||||
os.close(fd)
|
||||
print(f"scanned {scanned // (1024*1024)} MiB, {len(hits)} hit(s)\n")
|
||||
seen = set()
|
||||
for addr, is_wide, txt, path in hits:
|
||||
key = txt[:110]
|
||||
if key in seen:
|
||||
continue
|
||||
seen.add(key)
|
||||
kind = "utf16" if is_wide else "ascii"
|
||||
print(f"0x{addr:x} [{kind}] {path}")
|
||||
print(f" {txt}\n")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Executable
+138
@@ -0,0 +1,138 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Ensure the deployed launcher starts FIFA with the hook's WINEDLLOVERRIDES.
|
||||
|
||||
The hook ships as a `version.dll` proxy in the game directory, and Proton prefers a
|
||||
local DLL over its own builtin ONLY when WINEDLLOVERRIDES names it. Launcher builds
|
||||
before openfut-launcher c542415 apply `game_profile.env` but never that override, so
|
||||
the hook silently never loads -- and with no hook there is no port rewrite, the
|
||||
openfut.cfg the launcher just wrote is inert, and the client reaches EA's real Blaze
|
||||
ports (production, via /etc/hosts) while looking like a healthy configured launch.
|
||||
|
||||
This writes the override into `game_profile.env`, which the deployed launcher DOES
|
||||
apply, so it works without rebuilding. It is forward-compatible with the fixed
|
||||
launcher: hook_dll_overrides() defers to a profile that already pins `version=`, so
|
||||
the value set here simply wins and nothing conflicts.
|
||||
|
||||
python3 scripts/client-hook-override.py show
|
||||
python3 scripts/client-hook-override.py apply
|
||||
python3 scripts/client-hook-override.py revert
|
||||
|
||||
Safety: the prior value (including its absence) is recorded to a sidecar before the
|
||||
first mutation, so `revert` restores the real previous state rather than guessing;
|
||||
every operation re-reads and prints the result; and it refuses to edit while the
|
||||
launcher is running, because the launcher holds its config in memory and would write
|
||||
the stale value straight back over ours.
|
||||
"""
|
||||
import json
|
||||
import subprocess
|
||||
import sys
|
||||
|
||||
CLIENT = "alex@10.10.0.105"
|
||||
CFG = "/home/alex/.config/openfut-launcher/config.json"
|
||||
SIDECAR = "/home/alex/.config/openfut-launcher/config.json.openfut-prev-dlloverrides"
|
||||
KEY = "WINEDLLOVERRIDES"
|
||||
HOOK = "version=n,b"
|
||||
ABSENT = "<absent>"
|
||||
|
||||
|
||||
def ssh(script):
|
||||
r = subprocess.run(["ssh", "-o", "BatchMode=yes", CLIENT, script],
|
||||
capture_output=True, text=True, timeout=60)
|
||||
if r.returncode != 0:
|
||||
raise SystemExit(f"ssh failed ({r.returncode}): {r.stderr.strip()}")
|
||||
return r.stdout
|
||||
|
||||
|
||||
def launcher_running():
|
||||
"""comm is truncated by the kernel to 15 chars ("openfut-launche")."""
|
||||
out = ssh("for d in /proc/[0-9]*; do c=$(cat $d/comm 2>/dev/null); "
|
||||
"case \"$c\" in openfut-launche*) echo ${d#/proc/};; esac; done || true")
|
||||
return bool(out.strip())
|
||||
|
||||
|
||||
def fifa_running():
|
||||
out = ssh("for d in /proc/[0-9]*; do "
|
||||
"[ \"$(cat $d/comm 2>/dev/null)\" = FIFA17.exe ] && echo ${d#/proc/}; "
|
||||
"done || true")
|
||||
return bool(out.strip())
|
||||
|
||||
|
||||
def load():
|
||||
return json.loads(ssh(f'cat "{CFG}"'))
|
||||
|
||||
|
||||
def env_of(d):
|
||||
return d.setdefault("game_profile", {}).setdefault("env", {})
|
||||
|
||||
|
||||
def save(d):
|
||||
body = json.dumps(d, indent=2, sort_keys=True)
|
||||
ssh(f'cat > "{CFG}" <<\'EOF\'\n{body}\nEOF')
|
||||
|
||||
|
||||
def show():
|
||||
d = load()
|
||||
cur = env_of(d).get(KEY, ABSENT)
|
||||
print(f"--- {CFG}")
|
||||
print(f" game_profile.env[{KEY}] = {cur}")
|
||||
print(f" hook active on launch = {'YES' if 'version=' in cur else 'NO'}")
|
||||
side = ssh(f'cat "{SIDECAR}" 2>/dev/null || true').strip()
|
||||
print(f" recorded previous value = {side or '(none recorded yet)'}")
|
||||
print(f" launcher running = {'YES' if launcher_running() else 'no'}")
|
||||
return cur
|
||||
|
||||
|
||||
def guard():
|
||||
if fifa_running():
|
||||
raise SystemExit("REFUSING: a FIFA client is running; exit it first.")
|
||||
if launcher_running():
|
||||
raise SystemExit(
|
||||
"REFUSING: openfut-launcher is running. It holds its config in memory and\n"
|
||||
"would write the old value back over ours. Quit the launcher first.")
|
||||
|
||||
|
||||
def apply_override():
|
||||
guard()
|
||||
d = load()
|
||||
env = env_of(d)
|
||||
prior = env.get(KEY, ABSENT)
|
||||
if not ssh(f'cat "{SIDECAR}" 2>/dev/null || true').strip():
|
||||
ssh(f'cat > "{SIDECAR}" <<\'EOF\'\n{prior}\nEOF')
|
||||
print(f"recorded previous value to {SIDECAR}: {prior}")
|
||||
# Preserve an unrelated override rather than clobbering it, and never double up.
|
||||
if prior != ABSENT and "version=" in prior:
|
||||
print(f"already pins version= ({prior}); leaving it alone")
|
||||
return show()
|
||||
env[KEY] = HOOK if prior == ABSENT else f"{prior};{HOOK}"
|
||||
save(d)
|
||||
after = env_of(load()).get(KEY, ABSENT)
|
||||
if "version=" not in after:
|
||||
raise SystemExit(f"VERIFY FAILED: {KEY} is {after!r}")
|
||||
return show()
|
||||
|
||||
|
||||
def revert():
|
||||
guard()
|
||||
side = ssh(f'cat "{SIDECAR}" 2>/dev/null || true').strip()
|
||||
if not side:
|
||||
raise SystemExit(f"no recorded previous value at {SIDECAR}; refusing to guess")
|
||||
d = load()
|
||||
env = env_of(d)
|
||||
if side == ABSENT:
|
||||
env.pop(KEY, None)
|
||||
else:
|
||||
env[KEY] = side
|
||||
save(d)
|
||||
return show()
|
||||
|
||||
|
||||
def main():
|
||||
if len(sys.argv) != 2 or sys.argv[1] not in ("show", "apply", "revert"):
|
||||
print(__doc__)
|
||||
return 2
|
||||
{"show": show, "apply": apply_override, "revert": revert}[sys.argv[1]]()
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Executable
+62
@@ -0,0 +1,62 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Diff hub-route SHAPES between production (known-good) and staging.
|
||||
|
||||
Values legitimately differ (different clubs, different piles). What must not differ is
|
||||
structure: a key production sends that staging omits, or a type/null mismatch, is a
|
||||
candidate cause for the client rejecting FUT bootstrap.
|
||||
"""
|
||||
import json
|
||||
import os
|
||||
|
||||
PROD, STAG = "/tmp/hub_prod", "/tmp/hub_stag"
|
||||
|
||||
|
||||
def t(v):
|
||||
return "null" if v is None else type(v).__name__
|
||||
|
||||
|
||||
def shape(obj, prefix="", depth=0):
|
||||
"""path -> type, descending into the FIRST element of lists (representative)."""
|
||||
out = {}
|
||||
if depth > 6:
|
||||
return out
|
||||
if isinstance(obj, dict):
|
||||
for k, v in obj.items():
|
||||
p = f"{prefix}.{k}" if prefix else k
|
||||
out[p] = t(v)
|
||||
out.update(shape(v, p, depth + 1))
|
||||
elif isinstance(obj, list):
|
||||
out[(prefix or "<root>") + "[]"] = "list"
|
||||
if obj:
|
||||
out.update(shape(obj[0], f"{prefix}[0]", depth + 1))
|
||||
return out
|
||||
|
||||
|
||||
total = 0
|
||||
for name in sorted(os.listdir(PROD)):
|
||||
pf, sf = os.path.join(PROD, name), os.path.join(STAG, name)
|
||||
if not os.path.exists(sf):
|
||||
print(f"{name}: MISSING on staging")
|
||||
continue
|
||||
p = json.load(open(pf))
|
||||
s = json.load(open(sf))
|
||||
ps, ss = shape(p.get("body")), shape(s.get("body"))
|
||||
missing = [k for k in ps if k not in ss]
|
||||
types = [(k, ps[k], ss[k]) for k in ps if k in ss and ps[k] != ss[k]]
|
||||
nulls = [k for k in ps if k in ss and ss[k] == "null" and ps[k] != "null"]
|
||||
if p.get("status") != s.get("status"):
|
||||
print(f"\n### {name}: STATUS prod={p.get('status')} staging={s.get('status')}")
|
||||
total += 1
|
||||
if missing or types:
|
||||
print(f"\n### {name}")
|
||||
for k in missing:
|
||||
print(f" MISSING on staging: {k:<44} prod_type={ps[k]}")
|
||||
for k, a, b in types:
|
||||
mark = " <-- NULL" if b == "null" else ""
|
||||
print(f" TYPE {k:<48} prod={a:<7} staging={b}{mark}")
|
||||
total += len(missing) + len(types)
|
||||
|
||||
print(f"\n=== {total} structural difference(s) across {len(os.listdir(PROD))} routes ===")
|
||||
if total == 0:
|
||||
print("Every hub route matches production's shape. The bootstrap failure is not a")
|
||||
print("missing/mistyped field in these responses.")
|
||||
Executable
+56
@@ -0,0 +1,56 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Dump every FUT-hub route from one UTAS to a directory, for prod-vs-staging shape diffing.
|
||||
|
||||
Usage: dump_hub.py <port> <outdir>
|
||||
"""
|
||||
import json
|
||||
import os
|
||||
import socket
|
||||
import sys
|
||||
|
||||
ROUTES = {
|
||||
"user_accountinfo": "/ut/game/fifa17/user/accountinfo",
|
||||
"squad_active": "/ut/game/fifa17/squad/active",
|
||||
"squad_0": "/ut/game/fifa17/squad/0",
|
||||
"club": "/ut/game/fifa17/club?count=20",
|
||||
"club_stats_staff": "/ut/game/fifa17/club/stats/staff",
|
||||
"club_stats_club": "/ut/game/fifa17/club/stats/club",
|
||||
"clientdata_store": "/ut/game/fifa17/clientdata/store",
|
||||
"purchased_items": "/ut/game/fifa17/purchased/items",
|
||||
"tradepile": "/ut/game/fifa17/tradePile",
|
||||
"tradepile_counts": "/ut/game/fifa17/tradePile/counts",
|
||||
"watchlist": "/ut/game/fifa17/watchList",
|
||||
"trade_status": "/ut/game/fifa17/trade/status",
|
||||
"usermassinfo": "/ut/game/fifa17/userMassInfo",
|
||||
"settings": "/ut/game/fifa17/settings",
|
||||
}
|
||||
|
||||
port, outdir = int(sys.argv[1]), sys.argv[2]
|
||||
os.makedirs(outdir, exist_ok=True)
|
||||
|
||||
for name, path in ROUTES.items():
|
||||
try:
|
||||
s = socket.create_connection(("127.0.0.1", port), timeout=25)
|
||||
s.sendall((f"GET {path} HTTP/1.1\r\nHost: x\r\n"
|
||||
"X-OpenFUT-Game: fifa17\r\nConnection: close\r\n\r\n").encode())
|
||||
buf = b""
|
||||
while True:
|
||||
c = s.recv(65536)
|
||||
if not c:
|
||||
break
|
||||
buf += c
|
||||
s.close()
|
||||
head, _, body = buf.partition(b"\r\n\r\n")
|
||||
status = head.split(b" ")[1].decode()
|
||||
rec = {"status": status}
|
||||
try:
|
||||
rec["body"] = json.loads(body)
|
||||
except Exception:
|
||||
rec["body"] = None
|
||||
rec["raw"] = body[:200].decode(errors="replace")
|
||||
with open(os.path.join(outdir, f"{name}.json"), "w") as f:
|
||||
json.dump(rec, f)
|
||||
n = len(json.dumps(rec.get("body"))) if rec.get("body") is not None else 0
|
||||
print(f" {status} {name:<18} {n} bytes")
|
||||
except Exception as e:
|
||||
print(f" ERR {name:<18} {type(e).__name__}: {e}")
|
||||
Executable
+147
@@ -0,0 +1,147 @@
|
||||
#!/usr/bin/env python3
|
||||
"""OpenFUT UTAS route-reachability reporter.
|
||||
|
||||
Parses the openfut-utas-host `owner=` dispatch log (the line the host prints for
|
||||
EVERY request) into per-owner and per-Python-domain hit counts, so a staging
|
||||
preflight can assert the post-P1 invariants WITHOUT mutating anything:
|
||||
|
||||
* economy Python hits == 0 (any nonzero => P1 economy regression)
|
||||
* migrated non-economy Python hits == 0 (accountinfo/settings/leaderboards/
|
||||
match-reset/phishing are Rust-owned since post-P1)
|
||||
* remaining Python domains are exactly the documented residual set.
|
||||
|
||||
This is dev/staging tooling (Python is fine here — production authority is Rust).
|
||||
It only READS a log (file path arg, or stdin); it never touches production.
|
||||
|
||||
Log grammar (openfut-utas-host, src/lib.rs eprintln! lines), examples:
|
||||
utas-host owner=RUST route=economy method=GET path=/ut/game/fifa17/user/credits status=200
|
||||
utas-host owner=PYTHON_FALLBACK method=GET path=/ut/game/fifa17/hub status=200
|
||||
utas-host owner=RUST_OVERLAY route=userMassInfo status=200 ...
|
||||
utas-host owner=RUST_OBSERVE route=auth status=200 ...
|
||||
utas-host owner=RUST route=accountinfo status=200
|
||||
|
||||
Usage:
|
||||
openfut-reachability.py [LOGFILE] # report + gate (exit 1 on regression)
|
||||
hub logs ... | openfut-reachability.py # read from stdin
|
||||
"""
|
||||
import re
|
||||
import sys
|
||||
from collections import Counter
|
||||
|
||||
OWNER_RE = re.compile(r"utas-host owner=(\S+)")
|
||||
PATH_RE = re.compile(r"path=(\S+)")
|
||||
ROUTE_RE = re.compile(r"route=(\S+)")
|
||||
|
||||
# Non-economy routes migrated to Rust ownership post-P1. A PYTHON_FALLBACK hit on
|
||||
# any of these is a MIGRATION REGRESSION (the classifier lost the route).
|
||||
MIGRATED_NON_ECONOMY = {
|
||||
"user/accountinfo",
|
||||
"settings",
|
||||
"leaderboards/options",
|
||||
"match/reset",
|
||||
"phishing", # phishing/{trusteddevice,question,validate}
|
||||
"hub",
|
||||
"club/stats/global", # year/consumables/staff
|
||||
}
|
||||
|
||||
# Documented residual Python-owned non-economy domains (expected > 0 until
|
||||
# migrated). Keep in sync with docs/PRODUCTION_AUTHORITY_MATRIX.md.
|
||||
RESIDUAL_PYTHON = {
|
||||
"openfut/account/sync",
|
||||
"club/stats/context", # country/league/team nation-bucket sub-screens
|
||||
"clientdata/userHubData",
|
||||
}
|
||||
|
||||
|
||||
def python_domain(path: str) -> str:
|
||||
"""Normalize a proxied path to its domain key."""
|
||||
p = path.split("?", 1)[0]
|
||||
if p.startswith("/openfut/account/sync"):
|
||||
return "openfut/account/sync"
|
||||
# strip /ut/game/<sku>/ or /ut/v2/game/<sku>/ prefix
|
||||
m = re.match(r"/ut/(?:v2/)?game/[^/]+/(.*)", p)
|
||||
tail = m.group(1) if m else p.lstrip("/")
|
||||
if tail.startswith("phishing/"):
|
||||
return "phishing"
|
||||
if tail.startswith("club/stats/country") or tail.startswith(
|
||||
"club/stats/league"
|
||||
) or tail.startswith("club/stats/team"):
|
||||
return "club/stats/context"
|
||||
if tail.startswith("club/stats"):
|
||||
return "club/stats/global"
|
||||
if tail.startswith("clientdata/"):
|
||||
return "clientdata/userHubData"
|
||||
return tail
|
||||
|
||||
|
||||
def is_economy(line: str, route: str | None) -> bool:
|
||||
return route == "economy"
|
||||
|
||||
|
||||
def main() -> int:
|
||||
src = sys.stdin
|
||||
if len(sys.argv) > 1:
|
||||
src = open(sys.argv[1], encoding="utf-8", errors="replace")
|
||||
owners = Counter()
|
||||
economy_python = [] # economy routes that escaped to Python (BAD)
|
||||
migrated_regressions = [] # migrated non-economy routes that hit Python (BAD)
|
||||
python_domains = Counter()
|
||||
for line in src:
|
||||
mo = OWNER_RE.search(line)
|
||||
if not mo:
|
||||
continue
|
||||
owner = mo.group(1)
|
||||
owners[owner] += 1
|
||||
route = (ROUTE_RE.search(line) or [None, None])[1] if ROUTE_RE.search(line) else None
|
||||
if owner == "PYTHON_FALLBACK":
|
||||
pm = PATH_RE.search(line)
|
||||
path = pm.group(1) if pm else "?"
|
||||
dom = python_domain(path)
|
||||
python_domains[dom] += 1
|
||||
if dom in MIGRATED_NON_ECONOMY:
|
||||
migrated_regressions.append(path)
|
||||
# A properly classified economy route is owner=RUST route=economy. If an
|
||||
# economy tail ever shows up as PYTHON_FALLBACK that is the regression.
|
||||
if owner == "PYTHON_FALLBACK" and route is None:
|
||||
pm = PATH_RE.search(line)
|
||||
path = pm.group(1) if pm else ""
|
||||
if re.search(r"/(user/credits|store/(transaction|purchasegroup)|purchased|tradepile|"
|
||||
r"transfermarket|auctionhouse|trade/|item)", path, re.I):
|
||||
economy_python.append(path)
|
||||
|
||||
print("=== OWNER COUNTS ===")
|
||||
for owner, n in owners.most_common():
|
||||
print(f" {owner:18} {n}")
|
||||
print("=== PYTHON_FALLBACK DOMAINS ===")
|
||||
for dom, n in python_domains.most_common():
|
||||
tag = ""
|
||||
if dom in MIGRATED_NON_ECONOMY:
|
||||
tag = " <-- REGRESSION (should be Rust)"
|
||||
elif dom not in RESIDUAL_PYTHON:
|
||||
tag = " <-- UNEXPECTED (not in residual set)"
|
||||
print(f" {dom:28} {n}{tag}")
|
||||
|
||||
ok = True
|
||||
if economy_python:
|
||||
ok = False
|
||||
print("\nFAIL: economy routes reached Python (P1 REGRESSION):")
|
||||
for p in economy_python:
|
||||
print(f" {p}")
|
||||
if migrated_regressions:
|
||||
ok = False
|
||||
print("\nFAIL: migrated non-economy routes reached Python:")
|
||||
for p in migrated_regressions:
|
||||
print(f" {p}")
|
||||
unexpected = [d for d in python_domains
|
||||
if d not in RESIDUAL_PYTHON and d not in MIGRATED_NON_ECONOMY]
|
||||
if unexpected:
|
||||
print("\nWARN: undocumented Python domains (classify + add to matrix):")
|
||||
for d in unexpected:
|
||||
print(f" {d} ({python_domains[d]})")
|
||||
|
||||
print("\nGATE:", "PASS" if ok else "FAIL")
|
||||
return 0 if ok else 1
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Executable
+56
@@ -0,0 +1,56 @@
|
||||
#!/bin/bash
|
||||
# Isolated live confirmation of the roster-cert fix, using the REAL roster_server.py.
|
||||
# Runs under `sudo unshare -n` so port 8081 is free and production is never touched.
|
||||
#
|
||||
# Proves: with a cert from the FIXED generator (IP SAN), a client that verifies the cert
|
||||
# BY THE DIALED IP completes the handshake against the real server and gets the roster
|
||||
# XML; with the OLD DNS-only cert, the same client fails verification (certificate_unknown
|
||||
# class). That is the exact before/after the production fix targets.
|
||||
set -u
|
||||
D=/tmp/roster-iso
|
||||
rm -rf "$D"; mkdir -p "$D"
|
||||
cp /home/alex/OpenFUT/fifa17-recon/tools/roster_server.py "$D/" && sed -i "s@/tmp/roster_server.log@$D/roster_server.log@" "$D/roster_server.py"
|
||||
DIAL=127.0.0.1
|
||||
DNS="DNS:winter15.gosredirector.ea.com,DNS:*.gosredirector.ea.com,DNS:*.ea.com"
|
||||
|
||||
ip link set lo up 2>/dev/null || { echo " FATAL: cannot bring up lo in namespace"; exit 1; }
|
||||
|
||||
gen() { # $1 = san
|
||||
openssl req -x509 -newkey rsa:2048 -nodes -keyout "$D/redir_key.pem" -out "$D/redir_cert.pem" \
|
||||
-days 3650 -subj "/CN=winter15.gosredirector.ea.com" -addext "subjectAltName=$1" >/dev/null 2>&1
|
||||
}
|
||||
|
||||
run_server() {
|
||||
OPENFUT_BIND=127.0.0.1 python3 "$D/roster_server.py" >"$D/srv.log" 2>&1 &
|
||||
echo $! > "$D/srv.pid"
|
||||
for i in $(seq 1 25); do ss -tln 2>/dev/null | grep -q ":8081" && return 0; sleep 0.2; done
|
||||
echo " FATAL: roster_server never bound 8081"; echo " --- srv.log ---"; sed "s/^/ /" "$D/srv.log"; return 1
|
||||
}
|
||||
stop_server() { kill "$(cat "$D/srv.pid" 2>/dev/null)" 2>/dev/null; for i in $(seq 1 25); do ss -tln 2>/dev/null | grep -q ":8081" || return 0; sleep 0.2; done; echo " WARN: 8081 still bound after stop"; }
|
||||
|
||||
rc_new=9; rc_old=9
|
||||
|
||||
echo "=== NEW cert (fixed generator: DNS + IP:$DIAL,IP:10.10.0.120) ==="
|
||||
gen "$DNS,IP:$DIAL,IP:10.10.0.120"
|
||||
echo " SAN: $(openssl x509 -in "$D/redir_cert.pem" -noout -ext subjectAltName | tail -1 | tr -s ' ')"
|
||||
if run_server; then
|
||||
python3 "$(dirname "$0")/roster-cert-verify.py" "$D/redir_cert.pem" "$DIAL" 8081; rc_new=$?
|
||||
stop_server
|
||||
fi
|
||||
|
||||
echo "=== OLD cert (DNS-only, the failing production shape) ==="
|
||||
gen "$DNS"
|
||||
if run_server; then
|
||||
python3 "$(dirname "$0")/roster-cert-verify.py" "$D/redir_cert.pem" "$DIAL" 8081; rc_old=$?
|
||||
stop_server
|
||||
fi
|
||||
|
||||
echo "=== verdict ==="
|
||||
echo " new cert exit=$rc_new (want 0 = verified+200)"
|
||||
echo " old cert exit=$rc_old (want 1 = verify failed)"
|
||||
if [ "$rc_new" = 0 ] && [ "$rc_old" = 1 ]; then
|
||||
echo " PASS: the real roster server serves a by-IP-verifiable cert after the fix, not before"
|
||||
else
|
||||
echo " FAIL: unexpected outcome"
|
||||
fi
|
||||
rm -rf "$D"
|
||||
Executable
+63
@@ -0,0 +1,63 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Connect to the roster server and VERIFY its cert by the dialed IP, then GET the roster.
|
||||
|
||||
Mirrors the client's failing path: dial the roster by IP over TLS and validate the
|
||||
presented certificate against that IP. Exit 0 only if the cert verifies AND the roster
|
||||
XML comes back 200; exit 1 on cert-verify failure (the certificate_unknown class).
|
||||
|
||||
argv: <cafile> <dial_ip> <port>
|
||||
"""
|
||||
import socket
|
||||
import ssl
|
||||
import sys
|
||||
|
||||
cafile, dial_ip, port = sys.argv[1], sys.argv[2], int(sys.argv[3])
|
||||
|
||||
ctx = ssl.create_default_context(cafile=cafile) # trust the server's self-signed cert as CA
|
||||
ctx.check_hostname = True
|
||||
try:
|
||||
ctx.minimum_version = ssl.TLSVersion.TLSv1
|
||||
except Exception:
|
||||
pass
|
||||
try:
|
||||
ctx.set_ciphers("ALL:@SECLEVEL=0")
|
||||
except Exception:
|
||||
pass
|
||||
|
||||
try:
|
||||
raw = socket.create_connection((dial_ip, port), timeout=8)
|
||||
except Exception as e:
|
||||
print(f" CONNECT-FAIL {type(e).__name__}: {e}")
|
||||
sys.exit(2)
|
||||
|
||||
try:
|
||||
# server_hostname is the IP the roster is dialed by; ssl matches it against the
|
||||
# cert's iPAddress SANs — exactly the check the DNS-only cert failed.
|
||||
s = ctx.wrap_socket(raw, server_hostname=dial_ip)
|
||||
except ssl.SSLCertVerificationError as e:
|
||||
print(f" VERIFY-FAIL {e.verify_message or e}")
|
||||
sys.exit(1)
|
||||
except Exception as e:
|
||||
print(f" TLS-FAIL {type(e).__name__}: {e}")
|
||||
sys.exit(1)
|
||||
|
||||
try:
|
||||
ver, cipher = s.version(), s.cipher()[0]
|
||||
req = (f"GET /fifa17/fut/rosterupdate.xml HTTP/1.1\r\nHost: {dial_ip}:{port}\r\n"
|
||||
"Connection: close\r\n\r\n")
|
||||
s.sendall(req.encode())
|
||||
buf = b""
|
||||
while True:
|
||||
chunk = s.recv(4096)
|
||||
if not chunk:
|
||||
break
|
||||
buf += chunk
|
||||
s.close()
|
||||
status = buf.split(b"\r\n", 1)[0].decode(errors="replace")
|
||||
body = buf.split(b"\r\n\r\n", 1)[1] if b"\r\n\r\n" in buf else b""
|
||||
print(f" VERIFIED {ver} {cipher}")
|
||||
print(f" {status} body={len(body)}B head={body[:60]!r}")
|
||||
sys.exit(0 if status.endswith("200 OK") and body else 3)
|
||||
except Exception as e:
|
||||
print(f" GET-FAIL {type(e).__name__}: {e}")
|
||||
sys.exit(3)
|
||||
Executable
+566
@@ -0,0 +1,566 @@
|
||||
#!/usr/bin/env python3
|
||||
"""ISOLATED staging harness for the Core SOLD-settlement path.
|
||||
|
||||
Exercises the REAL `openfut-core` binary over REAL HTTP (`POST /economy/settle-sale`)
|
||||
against a THROWAWAY SQLite database in a fresh temp directory, so the transfer-market
|
||||
sold path can be validated with no FIFA client, no UTAS host, and no production state.
|
||||
|
||||
Isolation guarantees (all enforced below, not merely documented):
|
||||
* The database is created by `tempfile.mkdtemp()` and deleted on exit (`--keep` opts out).
|
||||
* The listen port is chosen by binding 127.0.0.1:0 and reading the port back; the
|
||||
PRODUCTION ports 8099 (utas-host), 8199 (oracle) and 18080 (prod Core) are in a
|
||||
hard deny-list and are never bound or contacted.
|
||||
* Nothing under /home/alex/openfut-promotion/state/ (the live DBs) is read or written.
|
||||
* Core runs with an explicit LISTEN_ADDR / DATABASE_URL / DATA_DIR and cwd set to the
|
||||
temp directory, so no relative path can escape into the repo or a live database.
|
||||
|
||||
Canonical two-party fixture reproduced here:
|
||||
seller 1,000 coins owning `item-x`; buyer 20,000; gross 15,000; fee 750.
|
||||
Expected: buyer 20,000 -> 5,000; seller 1,000 -> 15,250; owner seller -> buyer;
|
||||
exactly ONE row for `item-x`; modelled coins 21,000 -> 20,250 (delta == fee).
|
||||
|
||||
Usage:
|
||||
python3 scripts/settlement-staging.py [--keep] [--no-build]
|
||||
|
||||
Exit code 0 iff every assertion passes.
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
import http.client
|
||||
import json
|
||||
import os
|
||||
import shutil
|
||||
import socket
|
||||
import sqlite3
|
||||
import subprocess
|
||||
import sys
|
||||
import tempfile
|
||||
import time
|
||||
import urllib.error
|
||||
import urllib.request
|
||||
|
||||
# --- fixed facts about the repo (read from openfut-core/src/{main,config}.rs) -------
|
||||
# Config::from_env(): LISTEN_ADDR, DATABASE_URL, DATA_DIR, DB_MAX_CONNECTIONS.
|
||||
# Plain `openfut-core` (no subcommand) runs its own migrations, then serves axum.
|
||||
REPO_ROOT = os.path.dirname(os.path.dirname(os.path.abspath(__file__)))
|
||||
CORE_BIN = os.path.join(REPO_ROOT, "target", "release", "openfut-core")
|
||||
CORE_DATA_DIR = os.path.join(REPO_ROOT, "openfut-core", "data")
|
||||
|
||||
# Ports owned by the live production test. Never bind, never speak to.
|
||||
FORBIDDEN_PORTS = frozenset({8099, 8199, 18080})
|
||||
|
||||
GAME = "fifa17"
|
||||
TS = "2026-01-01T00:00:00Z"
|
||||
SELLER_PROFILE, SELLER_CLUB = "prof-seller", "club-seller"
|
||||
BUYER_PROFILE, BUYER_CLUB = "prof-buyer", "club-buyer"
|
||||
ITEM_ID, CARD_ID = "item-x", "def-x"
|
||||
SELLER_START, BUYER_START = 1_000, 20_000
|
||||
GROSS, FEE = 15_000, 750
|
||||
PROCEEDS = GROSS - FEE
|
||||
|
||||
# `app::build` runs a content preflight that rejects any owned card whose card_id is
|
||||
# not a loaded CardDefinition, so the fixture's definition ships as a one-entry
|
||||
# production content pack (shape: openfut-core/src/models/card.rs::CardDefinition).
|
||||
CARD_PACK = [
|
||||
{
|
||||
"id": CARD_ID,
|
||||
"name": "Staging Fixture",
|
||||
"overall": 82,
|
||||
"position": "ST",
|
||||
"nation": "Testland",
|
||||
"league": "Staging League",
|
||||
"club": "Fixture FC",
|
||||
"pace": 80,
|
||||
"shooting": 80,
|
||||
"passing": 80,
|
||||
"dribbling": 80,
|
||||
"defending": 40,
|
||||
"physical": 75,
|
||||
"rarity": "gold",
|
||||
"image_path": None,
|
||||
}
|
||||
]
|
||||
|
||||
READY_TIMEOUT_S = 30.0
|
||||
|
||||
|
||||
# --- output helpers -----------------------------------------------------------------
|
||||
|
||||
|
||||
def banner(title: str) -> None:
|
||||
print()
|
||||
print("=" * 72)
|
||||
print(f"== {title}")
|
||||
print("=" * 72)
|
||||
|
||||
|
||||
class Checks:
|
||||
"""Every expectation is printed where it happens AND tallied, so one failure never
|
||||
hides the rest and the RESULT block stays a summary."""
|
||||
|
||||
def __init__(self) -> None:
|
||||
self.results: list[tuple[str, bool, str]] = []
|
||||
|
||||
def _record(self, label: str, ok: bool, detail: str) -> bool:
|
||||
self.results.append((label, ok, detail))
|
||||
print(f" [{'PASS' if ok else 'FAIL'}] {label}: {detail}")
|
||||
return ok
|
||||
|
||||
def expect(self, label: str, actual, expected) -> bool:
|
||||
return self._record(
|
||||
label, actual == expected, f"expected {expected!r}, got {actual!r}"
|
||||
)
|
||||
|
||||
def expect_true(self, label: str, ok: bool, detail: str) -> bool:
|
||||
return self._record(label, bool(ok), detail)
|
||||
|
||||
def report(self) -> bool:
|
||||
failed = [label for label, ok, _ in self.results if not ok]
|
||||
print(f" {len(self.results) - len(failed)}/{len(self.results)} checks passed")
|
||||
for label, ok, detail in self.results:
|
||||
if not ok:
|
||||
print(f" [FAIL] {label}: {detail}")
|
||||
return not failed
|
||||
|
||||
|
||||
# --- port / process plumbing --------------------------------------------------------
|
||||
|
||||
|
||||
def pick_free_port() -> int:
|
||||
"""Bind 127.0.0.1:0, read the port back, release it. Production ports refused."""
|
||||
for _ in range(64):
|
||||
with socket.socket(socket.AF_INET, socket.SOCK_STREAM) as s:
|
||||
s.bind(("127.0.0.1", 0))
|
||||
port = s.getsockname()[1]
|
||||
if port not in FORBIDDEN_PORTS and port > 1024:
|
||||
return port
|
||||
raise RuntimeError("could not obtain a free non-production port")
|
||||
|
||||
|
||||
def build_core() -> None:
|
||||
print("building openfut-core (release)...")
|
||||
subprocess.run(
|
||||
["cargo", "build", "-p", "openfut-core", "--release"],
|
||||
cwd=REPO_ROOT,
|
||||
check=True,
|
||||
)
|
||||
|
||||
|
||||
def pack_path(workdir: str) -> str:
|
||||
return os.path.join(workdir, "content-pack.json")
|
||||
|
||||
|
||||
def write_content_pack(workdir: str) -> str:
|
||||
path = pack_path(workdir)
|
||||
with open(path, "w") as fh:
|
||||
json.dump(CARD_PACK, fh, indent=2)
|
||||
return path
|
||||
|
||||
|
||||
def launch_core(db_path: str, port: int, workdir: str, log_path: str, label: str):
|
||||
"""Start the real Core binary against the throwaway DB. Core runs its migrations."""
|
||||
if port in FORBIDDEN_PORTS:
|
||||
raise RuntimeError(f"refusing to bind production port {port}")
|
||||
env = dict(os.environ)
|
||||
env.update(
|
||||
{
|
||||
"LISTEN_ADDR": f"127.0.0.1:{port}",
|
||||
"DATABASE_URL": f"sqlite://{db_path}",
|
||||
"DATA_DIR": CORE_DATA_DIR,
|
||||
"OPENFUT_CONTENT_PACKS": pack_path(workdir),
|
||||
"RUST_LOG": "openfut_core=info",
|
||||
}
|
||||
)
|
||||
log = open(log_path, "ab", buffering=0)
|
||||
log.write(f"\n---- {label} on 127.0.0.1:{port} ----\n".encode())
|
||||
proc = subprocess.Popen(
|
||||
[CORE_BIN],
|
||||
cwd=workdir, # temp dir: no relative path can reach a real database
|
||||
env=env,
|
||||
stdout=log,
|
||||
stderr=log,
|
||||
)
|
||||
proc._log = log # type: ignore[attr-defined]
|
||||
return proc
|
||||
|
||||
|
||||
def wait_ready(proc, port: int, log_path: str) -> None:
|
||||
deadline = time.monotonic() + READY_TIMEOUT_S
|
||||
last = ""
|
||||
while time.monotonic() < deadline:
|
||||
if proc.poll() is not None:
|
||||
raise RuntimeError(
|
||||
f"Core exited early with code {proc.returncode}\n{tail(log_path)}"
|
||||
)
|
||||
try:
|
||||
conn = http.client.HTTPConnection("127.0.0.1", port, timeout=2)
|
||||
conn.request("GET", "/health")
|
||||
resp = conn.getresponse()
|
||||
resp.read()
|
||||
conn.close()
|
||||
if resp.status == 200:
|
||||
return
|
||||
last = f"/health -> HTTP {resp.status}"
|
||||
except OSError as exc:
|
||||
last = f"{type(exc).__name__}: {exc}"
|
||||
time.sleep(0.1)
|
||||
raise RuntimeError(
|
||||
f"Core on 127.0.0.1:{port} not ready after {READY_TIMEOUT_S:.0f}s "
|
||||
f"(last: {last})\n{tail(log_path)}"
|
||||
)
|
||||
|
||||
|
||||
def stop_core(proc) -> None:
|
||||
if proc is None or proc.poll() is not None:
|
||||
return
|
||||
proc.terminate()
|
||||
try:
|
||||
proc.wait(timeout=10)
|
||||
except subprocess.TimeoutExpired:
|
||||
proc.kill()
|
||||
proc.wait(timeout=10)
|
||||
finally:
|
||||
log = getattr(proc, "_log", None)
|
||||
if log is not None:
|
||||
log.close()
|
||||
|
||||
|
||||
def tail(log_path: str, lines: int = 25) -> str:
|
||||
try:
|
||||
with open(log_path, "r", errors="replace") as fh:
|
||||
body = fh.read().splitlines()
|
||||
except OSError:
|
||||
return "(no core log)"
|
||||
return "--- core log tail ---\n" + "\n".join(body[-lines:])
|
||||
|
||||
|
||||
# --- database -----------------------------------------------------------------------
|
||||
|
||||
|
||||
def connect(db_path: str) -> sqlite3.Connection:
|
||||
conn = sqlite3.connect(db_path, timeout=10)
|
||||
conn.execute("PRAGMA busy_timeout = 10000")
|
||||
return conn
|
||||
|
||||
|
||||
def seed(db_path: str) -> None:
|
||||
"""Direct-SQL fixture. Column sets match openfut-core/migrations/0001_initial.sql
|
||||
(+ 0016 game_dimension's profiles.game_id).
|
||||
|
||||
Two profiles share one game_id, which services::profile::create_profile would
|
||||
refuse -- that limit is a service rule, not a schema constraint, and the settle
|
||||
route never resolves the active profile when both club ids are named explicitly.
|
||||
"""
|
||||
conn = connect(db_path)
|
||||
try:
|
||||
with conn:
|
||||
conn.executemany(
|
||||
"INSERT INTO profiles (id, username, created_at, updated_at, game_id) "
|
||||
"VALUES (?, ?, ?, ?, ?)",
|
||||
[
|
||||
(SELLER_PROFILE, "seller", TS, TS, GAME),
|
||||
(BUYER_PROFILE, "buyer", TS, TS, GAME),
|
||||
],
|
||||
)
|
||||
conn.executemany(
|
||||
"INSERT INTO clubs (id, profile_id, name, coins, created_at, updated_at) "
|
||||
"VALUES (?, ?, ?, ?, ?, ?)",
|
||||
[
|
||||
(SELLER_CLUB, SELLER_PROFILE, "Seller FC", SELLER_START, TS, TS),
|
||||
(BUYER_CLUB, BUYER_PROFILE, "Buyer FC", BUYER_START, TS, TS),
|
||||
],
|
||||
)
|
||||
conn.execute(
|
||||
"INSERT INTO owned_cards (id, club_id, card_id, is_loan, acquired_at) "
|
||||
"VALUES (?, ?, ?, 0, ?)",
|
||||
(ITEM_ID, SELLER_CLUB, CARD_ID, TS),
|
||||
)
|
||||
finally:
|
||||
conn.close()
|
||||
|
||||
|
||||
def snapshot(db_path: str) -> dict:
|
||||
conn = connect(db_path)
|
||||
try:
|
||||
cur = conn.cursor()
|
||||
seller = cur.execute(
|
||||
"SELECT coins FROM clubs WHERE id = ?", (SELLER_CLUB,)
|
||||
).fetchone()[0]
|
||||
buyer = cur.execute(
|
||||
"SELECT coins FROM clubs WHERE id = ?", (BUYER_CLUB,)
|
||||
).fetchone()[0]
|
||||
owners = [
|
||||
row[0]
|
||||
for row in cur.execute(
|
||||
"SELECT club_id FROM owned_cards WHERE id = ?", (ITEM_ID,)
|
||||
)
|
||||
]
|
||||
total = cur.execute("SELECT COALESCE(SUM(coins), 0) FROM clubs").fetchone()[0]
|
||||
return {
|
||||
"seller_coins": seller,
|
||||
"buyer_coins": buyer,
|
||||
"owner": owners[0] if owners else None,
|
||||
"item_rows": len(owners),
|
||||
"total_coins": total,
|
||||
}
|
||||
finally:
|
||||
conn.close()
|
||||
|
||||
|
||||
def print_snapshot(title: str, snap: dict, extra: dict | None = None) -> None:
|
||||
banner(title)
|
||||
print(f" seller club {SELLER_CLUB!r:>14} coins : {snap['seller_coins']:>8,}")
|
||||
print(f" buyer club {BUYER_CLUB!r:>14} coins : {snap['buyer_coins']:>8,}")
|
||||
print(f" owner of {ITEM_ID!r:>17} : {snap['owner']}")
|
||||
print(f" rows in owned_cards for {ITEM_ID!r} : {snap['item_rows']}")
|
||||
print(f" total modelled coins (SUM clubs) : {snap['total_coins']:>8,}")
|
||||
for key, value in (extra or {}).items():
|
||||
print(f" {key:<32} : {value}")
|
||||
|
||||
|
||||
# --- HTTP ---------------------------------------------------------------------------
|
||||
|
||||
|
||||
def post_settle(port: int, body: dict) -> tuple[int, str]:
|
||||
if port in FORBIDDEN_PORTS:
|
||||
raise RuntimeError(f"refusing to POST to production port {port}")
|
||||
req = urllib.request.Request(
|
||||
f"http://127.0.0.1:{port}/economy/settle-sale",
|
||||
data=json.dumps(body).encode(),
|
||||
headers={"Content-Type": "application/json", "X-OpenFUT-Game": GAME},
|
||||
method="POST",
|
||||
)
|
||||
try:
|
||||
with urllib.request.urlopen(req, timeout=15) as resp:
|
||||
return resp.status, resp.read().decode(errors="replace")
|
||||
except urllib.error.HTTPError as exc: # 4xx/5xx carry the rejection body
|
||||
return exc.code, exc.read().decode(errors="replace")
|
||||
|
||||
|
||||
def show_response(status: int, body: str) -> dict | None:
|
||||
print(f" HTTP {status}")
|
||||
try:
|
||||
parsed = json.loads(body)
|
||||
except json.JSONDecodeError:
|
||||
print(f" body (not JSON): {body!r}")
|
||||
return None
|
||||
print(" body:")
|
||||
for line in json.dumps(parsed, indent=2, sort_keys=True).splitlines():
|
||||
print(f" {line}")
|
||||
return parsed
|
||||
|
||||
|
||||
# --- the run ------------------------------------------------------------------------
|
||||
|
||||
|
||||
def run(port: int, db_path: str, workdir: str, log_path: str, checks: Checks) -> None:
|
||||
settle_body = {
|
||||
"item_id": ITEM_ID,
|
||||
"gross": GROSS,
|
||||
"fee": FEE,
|
||||
"seller_club_id": SELLER_CLUB,
|
||||
"buyer_club_id": BUYER_CLUB,
|
||||
}
|
||||
|
||||
print(f" content pack : {write_content_pack(workdir)} (defines {CARD_ID})")
|
||||
|
||||
banner("MIGRATE (real Core creates the throwaway schema)")
|
||||
# Core owns its schema (sqlx migrations, embedded at compile time), so the
|
||||
# fixture cannot be seeded into an empty file. Start Core once purely to
|
||||
# migrate, stop it, THEN seed: the external writer and Core's WAL pool never
|
||||
# coexist, which is the safest ordering.
|
||||
migrator = launch_core(db_path, port, workdir, log_path, "migrate pass")
|
||||
try:
|
||||
wait_ready(migrator, port, log_path)
|
||||
print(f" migrations applied; Core answered /health on 127.0.0.1:{port}")
|
||||
finally:
|
||||
stop_core(migrator)
|
||||
print(" migrate pass stopped")
|
||||
|
||||
banner("SEED (canonical two-party fixture, direct SQL)")
|
||||
seed(db_path)
|
||||
print(f" {SELLER_CLUB}: {SELLER_START:,} coins, owns {ITEM_ID} ({CARD_ID})")
|
||||
print(f" {BUYER_CLUB}: {BUYER_START:,} coins")
|
||||
|
||||
banner(f"LAUNCH Core on 127.0.0.1:{port} (db {db_path})")
|
||||
server = launch_core(db_path, port, workdir, log_path, "serve pass")
|
||||
try:
|
||||
wait_ready(server, port, log_path)
|
||||
print(f" ready: GET /health -> 200 (pid {server.pid})")
|
||||
|
||||
before = snapshot(db_path)
|
||||
print_snapshot("BEFORE", before)
|
||||
|
||||
banner("PURCHASE POST /economy/settle-sale")
|
||||
print(f" request: {json.dumps(settle_body)}")
|
||||
status, body = post_settle(port, settle_body)
|
||||
receipt = show_response(status, body)
|
||||
|
||||
after = snapshot(db_path)
|
||||
print_snapshot(
|
||||
"AFTER",
|
||||
after,
|
||||
{
|
||||
"fee withheld and destroyed": f"{FEE:,}",
|
||||
f"DUPLICATE COUNT for {ITEM_ID!r}": after["item_rows"],
|
||||
"coins destroyed (before-after)": f"{before['total_coins'] - after['total_coins']:,}",
|
||||
},
|
||||
)
|
||||
|
||||
banner("EXPECTATIONS")
|
||||
checks.expect("purchase HTTP status", status, 200)
|
||||
checks.expect("buyer coins", after["buyer_coins"], BUYER_START - GROSS)
|
||||
checks.expect("seller coins", after["seller_coins"], SELLER_START + PROCEEDS)
|
||||
checks.expect("item owner is buyer club", after["owner"], BUYER_CLUB)
|
||||
checks.expect("duplicate count == 1", after["item_rows"], 1)
|
||||
checks.expect(
|
||||
"total coins before", before["total_coins"], SELLER_START + BUYER_START
|
||||
)
|
||||
checks.expect(
|
||||
"total coins after",
|
||||
after["total_coins"],
|
||||
SELLER_START + BUYER_START - FEE,
|
||||
)
|
||||
buyer_debit = before["buyer_coins"] - after["buyer_coins"]
|
||||
seller_credit = after["seller_coins"] - before["seller_coins"]
|
||||
checks.expect_true(
|
||||
"conservation buyer_debit == seller_credit + fee",
|
||||
buyer_debit == seller_credit + FEE,
|
||||
f"{buyer_debit:,} == {seller_credit:,} + {FEE:,}",
|
||||
)
|
||||
if receipt is None:
|
||||
checks.expect_true("receipt is JSON", False, "response body was not JSON")
|
||||
else:
|
||||
checks.expect("receipt.item_id", receipt.get("item_id"), ITEM_ID)
|
||||
checks.expect("receipt.card_id", receipt.get("card_id"), CARD_ID)
|
||||
checks.expect(
|
||||
"receipt.seller_club_id", receipt.get("seller_club_id"), SELLER_CLUB
|
||||
)
|
||||
checks.expect(
|
||||
"receipt.buyer_club_id", receipt.get("buyer_club_id"), BUYER_CLUB
|
||||
)
|
||||
checks.expect("receipt.gross", receipt.get("gross"), GROSS)
|
||||
checks.expect("receipt.fee", receipt.get("fee"), FEE)
|
||||
checks.expect("receipt.proceeds", receipt.get("proceeds"), PROCEEDS)
|
||||
checks.expect(
|
||||
"receipt.seller_balance",
|
||||
receipt.get("seller_balance"),
|
||||
after["seller_coins"],
|
||||
)
|
||||
checks.expect(
|
||||
"receipt.buyer_balance",
|
||||
receipt.get("buyer_balance"),
|
||||
after["buyer_coins"],
|
||||
)
|
||||
checks.expect(
|
||||
"receipt.squad_slots_freed", receipt.get("squad_slots_freed"), 0
|
||||
)
|
||||
|
||||
banner("RETRY (identical request must be rejected, nothing may move)")
|
||||
retry_status, retry_body = post_settle(port, settle_body)
|
||||
show_response(retry_status, retry_body)
|
||||
replay = snapshot(db_path)
|
||||
print_snapshot("AFTER RETRY", replay)
|
||||
checks.expect_true(
|
||||
"retry rejected (4xx)",
|
||||
400 <= retry_status < 500,
|
||||
f"HTTP {retry_status}",
|
||||
)
|
||||
checks.expect("retry left buyer coins", replay["buyer_coins"], after["buyer_coins"])
|
||||
checks.expect(
|
||||
"retry left seller coins", replay["seller_coins"], after["seller_coins"]
|
||||
)
|
||||
checks.expect("retry left owner", replay["owner"], after["owner"])
|
||||
checks.expect("retry left total coins", replay["total_coins"], after["total_coins"])
|
||||
checks.expect("retry left one row", replay["item_rows"], 1)
|
||||
|
||||
# The identical retry above is refused by the AFFORDABILITY guard, because
|
||||
# settle_sale debits before it touches ownership and the buyer no longer holds
|
||||
# 15,000. That alone never exercises the ownership CAS that is the actual
|
||||
# replay guard, so replay the same item at a price the buyer CAN afford: the
|
||||
# only thing left to stop it is "item not owned by the named seller".
|
||||
banner("REPLAY GUARD (affordable re-settle must still fail on ownership)")
|
||||
cheap = dict(settle_body, gross=100, fee=5)
|
||||
print(f" request: {json.dumps(cheap)}")
|
||||
guard_status, guard_body = post_settle(port, cheap)
|
||||
show_response(guard_status, guard_body)
|
||||
guarded = snapshot(db_path)
|
||||
print_snapshot("AFTER REPLAY GUARD", guarded)
|
||||
checks.expect("replay guard rejects with 404", guard_status, 404)
|
||||
checks.expect_true(
|
||||
"replay guard cites ownership",
|
||||
"not owned" in guard_body,
|
||||
f"body: {guard_body}",
|
||||
)
|
||||
checks.expect(
|
||||
"replay guard left buyer coins", guarded["buyer_coins"], after["buyer_coins"]
|
||||
)
|
||||
checks.expect(
|
||||
"replay guard left seller coins",
|
||||
guarded["seller_coins"],
|
||||
after["seller_coins"],
|
||||
)
|
||||
checks.expect("replay guard left owner", guarded["owner"], after["owner"])
|
||||
checks.expect(
|
||||
"replay guard left total coins",
|
||||
guarded["total_coins"],
|
||||
after["total_coins"],
|
||||
)
|
||||
checks.expect("replay guard left one row", guarded["item_rows"], 1)
|
||||
finally:
|
||||
stop_core(server)
|
||||
print("\n Core stopped")
|
||||
|
||||
|
||||
def main() -> int:
|
||||
parser = argparse.ArgumentParser(description=__doc__.splitlines()[0])
|
||||
parser.add_argument(
|
||||
"--keep", action="store_true", help="keep the temp dir (and its DB + core log)"
|
||||
)
|
||||
parser.add_argument(
|
||||
"--no-build", action="store_true", help="use target/release/openfut-core as-is"
|
||||
)
|
||||
args = parser.parse_args()
|
||||
|
||||
if not args.no_build:
|
||||
build_core()
|
||||
if not os.path.isfile(CORE_BIN):
|
||||
print(f"core binary not found: {CORE_BIN}", file=sys.stderr)
|
||||
return 2
|
||||
|
||||
port = pick_free_port()
|
||||
workdir = tempfile.mkdtemp(prefix="openfut-settlement-staging-")
|
||||
db_path = os.path.join(workdir, "staging.db")
|
||||
log_path = os.path.join(workdir, "core.log")
|
||||
|
||||
banner("SETTLEMENT STAGING HARNESS (isolated; production untouched)")
|
||||
print(f" temp dir : {workdir}")
|
||||
print(f" throwaway db : {db_path}")
|
||||
print(f" core binary : {CORE_BIN}")
|
||||
print(f" port : {port} (production {sorted(FORBIDDEN_PORTS)} never bound)")
|
||||
|
||||
checks = Checks()
|
||||
try:
|
||||
run(port, db_path, workdir, log_path, checks)
|
||||
except Exception as exc: # report, then still clean up
|
||||
banner("HARNESS ERROR")
|
||||
print(f" {type(exc).__name__}: {exc}")
|
||||
checks.expect_true("harness completed", False, f"{type(exc).__name__}: {exc}")
|
||||
finally:
|
||||
if args.keep:
|
||||
print(f"\n --keep: leaving {workdir} in place")
|
||||
else:
|
||||
shutil.rmtree(workdir, ignore_errors=True)
|
||||
print(f"\n removed {workdir}")
|
||||
|
||||
banner("RESULT")
|
||||
ok = checks.report()
|
||||
print()
|
||||
print(f" {'ALL CHECKS PASSED' if ok else 'FAILURES PRESENT'}")
|
||||
return 0 if ok else 1
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Executable
+375
@@ -0,0 +1,375 @@
|
||||
#!/usr/bin/env python3
|
||||
"""PRE-LIVE machine differential for the seller-facing sold-row A/B.
|
||||
|
||||
Purpose: prove, before any operator time is spent at a real FIFA client, that the
|
||||
two variants differ in EXACTLY the field under test. A contaminated A/B cannot
|
||||
attribute the client's reaction to anything, so this gate runs first.
|
||||
|
||||
It performs ONE synthetic settlement, then re-reads every seller-facing surface
|
||||
under each variant by restarting only the host (same Core, same DBs, same sale), and
|
||||
diffs the payloads with explicit classification:
|
||||
|
||||
MISSING key present in A, absent in B
|
||||
EXTRA key absent in A, present in B
|
||||
TYPE_MISMATCH same key, different JSON type
|
||||
VALUE_MISMATCH same key and type, different value
|
||||
|
||||
Two orthogonal pairs are checked:
|
||||
|
||||
PRIMARY bidState highest vs buyNow coinsProcessed held at 0
|
||||
ORTHOGONAL coinsProcessed 0 vs 1 bidState held at highest
|
||||
|
||||
Plus the two counts states the live experiment needs to interpret:
|
||||
|
||||
S1 0 active + 1 sold
|
||||
S2 1 active + 1 sold
|
||||
|
||||
Evidence is written per variant under docs/evidence/sold-ab-<date>/ with a sha256
|
||||
of each payload, so variant A evidence can never be confused with variant B.
|
||||
|
||||
ISOLATION: reuses the verified staging bring-up from sold-wire-check.py, which binds
|
||||
only ephemeral loopback ports, refuses every production port, and opens nothing under
|
||||
/home/alex/openfut-promotion/state/.
|
||||
|
||||
python3 scripts/sold-ab-differential.py [--out DIR] [--keep]
|
||||
"""
|
||||
import argparse
|
||||
import hashlib
|
||||
import importlib.util
|
||||
import json
|
||||
import os
|
||||
import shutil
|
||||
import sqlite3
|
||||
import subprocess
|
||||
import sys
|
||||
import tempfile
|
||||
import time
|
||||
|
||||
REPO = os.path.dirname(os.path.dirname(os.path.abspath(__file__)))
|
||||
|
||||
# Reuse the proven harness helpers rather than re-deriving them. The filename has
|
||||
# hyphens, so it cannot be imported normally.
|
||||
_spec = importlib.util.spec_from_file_location(
|
||||
"sold_wire_check", os.path.join(REPO, "scripts", "sold-wire-check.py"))
|
||||
H = importlib.util.module_from_spec(_spec)
|
||||
_spec.loader.exec_module(H)
|
||||
|
||||
SURFACES = {
|
||||
"tradePile": "/ut/game/fifa17/tradePile",
|
||||
"counts": "/ut/game/fifa17/tradePile/counts",
|
||||
"trade_status_filtered": f"/ut/game/fifa17/trade/status?tradeIds={H.TRADE_ID}",
|
||||
"trade_status_unfiltered": "/ut/game/fifa17/trade/status",
|
||||
}
|
||||
|
||||
results = []
|
||||
|
||||
|
||||
def check(label, ok, detail=""):
|
||||
results.append((label, bool(ok), detail))
|
||||
print(f" [{'PASS' if ok else 'FAIL'}] {label}{(': ' + detail) if detail else ''}")
|
||||
return ok
|
||||
|
||||
|
||||
def banner(t):
|
||||
print("\n" + "=" * 74)
|
||||
print(f"== {t}")
|
||||
print("=" * 74)
|
||||
|
||||
|
||||
def jtype(v):
|
||||
if isinstance(v, bool):
|
||||
return "bool"
|
||||
if isinstance(v, int):
|
||||
return "int"
|
||||
if isinstance(v, float):
|
||||
return "float"
|
||||
if isinstance(v, str):
|
||||
return "str"
|
||||
if isinstance(v, list):
|
||||
return "list"
|
||||
if isinstance(v, dict):
|
||||
return "dict"
|
||||
return "null"
|
||||
|
||||
|
||||
def classify(a, b, path=""):
|
||||
"""Recursive classified diff. Returns a list of (kind, path, a, b)."""
|
||||
out = []
|
||||
if jtype(a) != jtype(b):
|
||||
return [("TYPE_MISMATCH", path or "<root>", jtype(a), jtype(b))]
|
||||
if isinstance(a, dict):
|
||||
for k in a:
|
||||
if k not in b:
|
||||
out.append(("MISSING", f"{path}.{k}".lstrip("."), a[k], None))
|
||||
for k in b:
|
||||
if k not in a:
|
||||
out.append(("EXTRA", f"{path}.{k}".lstrip("."), None, b[k]))
|
||||
for k in a:
|
||||
if k in b:
|
||||
out += classify(a[k], b[k], f"{path}.{k}".lstrip("."))
|
||||
return out
|
||||
if isinstance(a, list):
|
||||
if len(a) != len(b):
|
||||
out.append(("VALUE_MISMATCH", f"{path}[len]", len(a), len(b)))
|
||||
for i, (x, y) in enumerate(zip(a, b)):
|
||||
out += classify(x, y, f"{path}[{i}]")
|
||||
return out
|
||||
if a != b:
|
||||
out.append(("VALUE_MISMATCH", path or "<root>", a, b))
|
||||
return out
|
||||
|
||||
|
||||
def capture(port):
|
||||
"""Every seller-facing surface, as parsed JSON plus a sha256 of the raw bytes."""
|
||||
snap = {}
|
||||
for name, path in SURFACES.items():
|
||||
st, body = H.req(port, "GET", path)
|
||||
raw = json.dumps(body, sort_keys=True, separators=(",", ":")).encode()
|
||||
snap[name] = {
|
||||
"status": st,
|
||||
"body": body,
|
||||
"sha256": hashlib.sha256(raw).hexdigest(),
|
||||
}
|
||||
return snap
|
||||
|
||||
|
||||
def sold_row(snap):
|
||||
rows = snap["tradePile"]["body"].get("auctionInfo", [])
|
||||
return rows[0] if rows else {}
|
||||
|
||||
|
||||
def report_diff(label, a, b, allowed):
|
||||
"""Print the classified diff and assert only `allowed` paths differ."""
|
||||
diffs = classify(a, b)
|
||||
print(f" classified diff ({len(diffs)} finding(s)):")
|
||||
for kind, path, av, bv in diffs:
|
||||
print(f" {kind:15s} {path:34s} A={av!r} B={bv!r}")
|
||||
kinds = {k for k, _, _, _ in diffs}
|
||||
for bad in ("MISSING", "EXTRA", "TYPE_MISMATCH"):
|
||||
check(f"{label}: no {bad}", bad not in kinds,
|
||||
", ".join(p for k, p, _, _ in diffs if k == bad) or "none")
|
||||
paths = sorted(p for _, p, _, _ in diffs)
|
||||
check(f"{label}: only {allowed} differ", paths == sorted(allowed), str(paths))
|
||||
return diffs
|
||||
|
||||
|
||||
def restart_host(state, variant, coins_processed):
|
||||
"""Same Core, same DBs, same settled sale — only the host's variant changes."""
|
||||
if state.get("host"):
|
||||
state["host"].terminate()
|
||||
state["host"].wait(timeout=20)
|
||||
state["host"] = H.start_host(state["tmp"], state["host_port"], state["core_port"],
|
||||
state["host_log"], variant,
|
||||
coins_processed=coins_processed)
|
||||
return state["host"]
|
||||
|
||||
|
||||
def main():
|
||||
ap = argparse.ArgumentParser()
|
||||
ap.add_argument("--out", default=os.path.join(
|
||||
REPO, "docs/evidence", f"sold-ab-{time.strftime('%Y-%m-%d')}"))
|
||||
ap.add_argument("--keep", action="store_true")
|
||||
args = ap.parse_args()
|
||||
os.makedirs(args.out, exist_ok=True)
|
||||
|
||||
tmp = tempfile.mkdtemp(prefix="openfut-sold-ab-")
|
||||
state = {"tmp": tmp, "host": None}
|
||||
evidence = {"generated": time.strftime("%Y-%m-%dT%H:%M:%SZ", time.gmtime()),
|
||||
"variants": {}, "diffs": {}, "counts_states": {}}
|
||||
try:
|
||||
state["core_port"] = H.free_port()
|
||||
state["host_port"] = H.free_port()
|
||||
state["core_log"] = os.path.join(tmp, "core.log")
|
||||
state["host_log"] = os.path.join(tmp, "host.log")
|
||||
banner("ISOLATED STAGING")
|
||||
print(f" tmp {tmp}\n core 127.0.0.1:{state['core_port']}"
|
||||
f"\n host 127.0.0.1:{state['host_port']}")
|
||||
core, core_db = H.start_core(tmp, state["core_port"], state["core_log"])
|
||||
state["core"] = core
|
||||
state["core_db"] = core_db
|
||||
mdb = os.path.join(tmp, "market.db")
|
||||
|
||||
# ---- one authentic listing + one real settlement -------------------
|
||||
restart_host(state, "highest", "0")
|
||||
con = sqlite3.connect(mdb)
|
||||
con.execute(
|
||||
"INSERT INTO listings (listing_id, card_id, core_item_id, wire_item_id, "
|
||||
"wire_resource_id, start_price, buy_now_price, owner, state, created_at, "
|
||||
"item_json, duration_secs) VALUES (?,?,?,?,?,?,?,?, 'active', ?, ?, ?)",
|
||||
(H.TRADE_ID, H.CARD, H.ITEM, 100000178, 212188, H.GROSS, H.GROSS, "CAGE",
|
||||
str(int(time.time() * 1000)), json.dumps({
|
||||
"id": 100000178, "resourceId": 212188, "rating": 75,
|
||||
"preferredPosition": "ST", "itemState": "forSale",
|
||||
"untradeable": False, "assetId": 212188}), 3600))
|
||||
con.commit(); con.close()
|
||||
banner(f"SETTLE — synthetic Buyer B buys at {H.GROSS}")
|
||||
out = subprocess.run(
|
||||
[os.path.join(REPO, "target/release/staging_sell"),
|
||||
"--market-db", mdb, "--core-url", f"http://127.0.0.1:{state['core_port']}",
|
||||
"--trade-id", H.TRADE_ID, "--item", H.ITEM,
|
||||
"--seller", H.SELLER_CLUB, "--buyer", H.BUYER_CLUB,
|
||||
"--gross", str(H.GROSS)],
|
||||
capture_output=True, text=True, timeout=120)
|
||||
print(" " + "\n ".join((out.stdout + out.stderr).strip().splitlines()))
|
||||
check("settlement succeeded", out.returncode == 0)
|
||||
own, n, coins = H.owner_of(core_db, H.ITEM)
|
||||
fee = H.GROSS * 5 // 100
|
||||
check("ownership -> buyer", own == H.BUYER_CLUB, str(own))
|
||||
check("exactly one authoritative instance", n == 1, str(n))
|
||||
check("seller credited net", coins[H.SELLER_CLUB] == 1000 + H.GROSS - fee,
|
||||
str(coins[H.SELLER_CLUB]))
|
||||
check("buyer debited gross", coins[H.BUYER_CLUB] == 20000 - H.GROSS,
|
||||
str(coins[H.BUYER_CLUB]))
|
||||
economy = {"seller": coins[H.SELLER_CLUB], "buyer": coins[H.BUYER_CLUB],
|
||||
"fee": fee, "owner": own, "instances": n}
|
||||
evidence["settlement"] = economy
|
||||
|
||||
# ---- PRIMARY A/B: bidState only ------------------------------------
|
||||
banner("PRIMARY A/B — bidState highest vs buyNow (coinsProcessed held at 0)")
|
||||
snaps = {}
|
||||
for name, variant in (("A_highest", "highest"), ("B_buyNow", "buyNow")):
|
||||
restart_host(state, variant, "0")
|
||||
snaps[name] = capture(state["host_port"])
|
||||
evidence["variants"][name] = {
|
||||
"env": {"OPENFUT_FIFA17_SOLD_EXPERIMENT": variant,
|
||||
"OPENFUT_FIFA17_SOLD_COINS_PROCESSED": "0"},
|
||||
"surfaces": snaps[name],
|
||||
}
|
||||
row = sold_row(snaps[name])
|
||||
print(f" {name}: tradeState={row.get('tradeState')} "
|
||||
f"bidState={row.get('bidState')} currentBid={row.get('currentBid')} "
|
||||
f"coinsProcessed={row.get('coinsProcessed')} atoms={len(row)}")
|
||||
# Every variant must independently be a well-formed sold row.
|
||||
check(f"{name}: tradeState closed", row.get("tradeState") == "closed")
|
||||
check(f"{name}: twelve atoms", len(row) == 12, str(len(row)))
|
||||
check(f"{name}: currentBid == gross", row.get("currentBid") == H.GROSS)
|
||||
check(f"{name}: expires 0", row.get("expires") == 0)
|
||||
check(f"{name}: counts.sold == 1",
|
||||
snaps[name]["counts"]["body"].get("sold") == 1)
|
||||
evidence["diffs"]["primary_bidstate"] = [
|
||||
{"kind": k, "path": p, "a": av, "b": bv}
|
||||
for k, p, av, bv in report_diff(
|
||||
"PRIMARY", snaps["A_highest"]["tradePile"]["body"],
|
||||
snaps["B_buyNow"]["tradePile"]["body"],
|
||||
["auctionInfo[0].bidState"])
|
||||
]
|
||||
# /trade/status must move in lockstep, or the screen would contradict itself.
|
||||
report_diff("PRIMARY /trade/status",
|
||||
snaps["A_highest"]["trade_status_filtered"]["body"],
|
||||
snaps["B_buyNow"]["trade_status_filtered"]["body"],
|
||||
["auctionInfo[0].bidState"])
|
||||
report_diff("PRIMARY counts",
|
||||
snaps["A_highest"]["counts"]["body"],
|
||||
snaps["B_buyNow"]["counts"]["body"], [])
|
||||
|
||||
# ---- ORTHOGONAL A/B: coinsProcessed only ---------------------------
|
||||
banner("ORTHOGONAL A/B — coinsProcessed 0 vs 1 (bidState held at highest)")
|
||||
for name, cp in (("C_cp0", "0"), ("D_cp1", "1")):
|
||||
restart_host(state, "highest", cp)
|
||||
snaps[name] = capture(state["host_port"])
|
||||
evidence["variants"][name] = {
|
||||
"env": {"OPENFUT_FIFA17_SOLD_EXPERIMENT": "highest",
|
||||
"OPENFUT_FIFA17_SOLD_COINS_PROCESSED": cp},
|
||||
"surfaces": snaps[name],
|
||||
}
|
||||
row = sold_row(snaps[name])
|
||||
print(f" {name}: bidState={row.get('bidState')} "
|
||||
f"coinsProcessed={row.get('coinsProcessed')}")
|
||||
evidence["diffs"]["orthogonal_coinsprocessed"] = [
|
||||
{"kind": k, "path": p, "a": av, "b": bv}
|
||||
for k, p, av, bv in report_diff(
|
||||
"ORTHOGONAL", snaps["C_cp0"]["tradePile"]["body"],
|
||||
snaps["D_cp1"]["tradePile"]["body"],
|
||||
["auctionInfo[0].coinsProcessed"])
|
||||
]
|
||||
check("C_cp0 is identical to A_highest (same env => same bytes)",
|
||||
snaps["C_cp0"]["tradePile"]["sha256"]
|
||||
== snaps["A_highest"]["tradePile"]["sha256"],
|
||||
"reproducible")
|
||||
|
||||
# ---- counts states the live run must interpret ----------------------
|
||||
banner("COUNTS STATES")
|
||||
restart_host(state, "highest", "0")
|
||||
s1 = H.req(state["host_port"], "GET", SURFACES["counts"])[1]
|
||||
print(f" S1 0 active + 1 sold -> {json.dumps(s1)}")
|
||||
con = sqlite3.connect(mdb)
|
||||
con.execute(
|
||||
"INSERT INTO listings (listing_id, card_id, core_item_id, wire_item_id, "
|
||||
"wire_resource_id, start_price, buy_now_price, owner, state, created_at, "
|
||||
"item_json, duration_secs) VALUES (?,?,?,?,?,?,?,?, 'active', ?, ?, ?)",
|
||||
("900500999", H.CARD, "core-second-x", 100000179, 212188, 300, 400, "CAGE",
|
||||
str(int(time.time() * 1000)), json.dumps({
|
||||
"id": 100000179, "resourceId": 212188, "rating": 75,
|
||||
"preferredPosition": "ST", "itemState": "forSale",
|
||||
"untradeable": False, "assetId": 212188}), 3600))
|
||||
con.commit(); con.close()
|
||||
s2_active = H.req(state["host_port"], "GET", SURFACES["counts"])[1]
|
||||
print(f" S2 1 active + 1 sold -> {json.dumps(s2_active)} (count mode: active)")
|
||||
restart_host(state, "highest", "0")
|
||||
os.environ["_"] = "_" # no-op; count mode is a host env, set below
|
||||
state["host"].terminate(); state["host"].wait(timeout=20)
|
||||
state["host"] = H.start_host(tmp, state["host_port"], state["core_port"],
|
||||
state["host_log"], "highest",
|
||||
coins_processed="0",
|
||||
count_mode="active_plus_sold")
|
||||
s2_member = H.req(state["host_port"], "GET", SURFACES["counts"])[1]
|
||||
print(f" S2 1 active + 1 sold -> {json.dumps(s2_member)} (count mode: membership)")
|
||||
evidence["counts_states"] = {
|
||||
"S1_zero_active_one_sold": s1,
|
||||
"S2_one_active_one_sold_count_active": s2_active,
|
||||
"S2_one_active_one_sold_count_membership": s2_member,
|
||||
}
|
||||
check("S1 reports sold 1 / selling 0", s1.get("sold") == 1 and s1.get("selling") == 0)
|
||||
check("S2 reports sold 1 / selling 1",
|
||||
s2_active.get("sold") == 1 and s2_active.get("selling") == 1)
|
||||
check("S2 count differs by mode (1 vs 2) — the open question for the client",
|
||||
s2_active.get("count") == 1 and s2_member.get("count") == 2,
|
||||
f"{s2_active.get('count')} vs {s2_member.get('count')}")
|
||||
|
||||
# ---- emit evidence --------------------------------------------------
|
||||
banner("EVIDENCE")
|
||||
for name, v in evidence["variants"].items():
|
||||
path = os.path.join(args.out, f"{name}.json")
|
||||
with open(path, "w") as f:
|
||||
json.dump(v, f, indent=2, sort_keys=True)
|
||||
print(f" {os.path.relpath(path, REPO)} "
|
||||
f"tradePile sha256={v['surfaces']['tradePile']['sha256'][:16]}…")
|
||||
idx = os.path.join(args.out, "differential.json")
|
||||
with open(idx, "w") as f:
|
||||
json.dump(evidence, f, indent=2, sort_keys=True)
|
||||
print(f" {os.path.relpath(idx, REPO)}")
|
||||
|
||||
banner("PRODUCTION UNTOUCHED")
|
||||
alive = subprocess.run(["ps", "-o", "pid=", "-p", "3631953"],
|
||||
capture_output=True, text=True).stdout.strip()
|
||||
check("prod-host pid 3631953 alive", alive == "3631953", alive or "gone")
|
||||
|
||||
banner("RESULT")
|
||||
passed = sum(1 for _, ok, _ in results if ok)
|
||||
failed = [l for l, ok, _ in results if not ok]
|
||||
print(f" {passed}/{len(results)} checks passed")
|
||||
if failed:
|
||||
print(" FAILED: " + "; ".join(failed))
|
||||
print("\n A/B IS CONTAMINATED — do NOT run the live experiment")
|
||||
return 1
|
||||
print("\n A/B IS CLEAN — one-field attribution proven; ready for the live client")
|
||||
return 0
|
||||
finally:
|
||||
for k in ("host", "core"):
|
||||
p = state.get(k)
|
||||
if p:
|
||||
try:
|
||||
p.terminate(); p.wait(timeout=15)
|
||||
except Exception:
|
||||
try:
|
||||
p.kill()
|
||||
except Exception:
|
||||
pass
|
||||
if args.keep:
|
||||
print(f"\n kept {tmp}")
|
||||
else:
|
||||
shutil.rmtree(tmp, ignore_errors=True)
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Executable
+218
@@ -0,0 +1,218 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Switch the FIFA client's Blaze ports between PRODUCTION and STAGING, reversibly.
|
||||
|
||||
The staging sold experiment needs the client to talk to the staging Blaze, which is
|
||||
what advertises the staging UTAS base. Two files are involved and the distinction
|
||||
matters, because getting it wrong silently runs the whole experiment against
|
||||
production:
|
||||
|
||||
* `openfut.cfg` in the game directory is what the injected hook reads at connect
|
||||
time -- but it is a DERIVED artifact.
|
||||
* `~/.config/openfut-launcher/config.json` is the AUTHORITATIVE source. The
|
||||
launcher reconciles openfut.cfg from it, fail-closed, immediately before every
|
||||
launch. An edit to openfut.cfg alone is therefore destroyed by the next launch:
|
||||
observed live, with openfut.cfg's mtime 2s before the FIFA process start and the
|
||||
hook logging `blaze_redir=42127 blaze_main=42130` after it had been set to
|
||||
staging. So this script owns BOTH, source first.
|
||||
|
||||
Safety properties, in order of importance:
|
||||
|
||||
* Production values are recorded to a sidecar next to each file BEFORE the first
|
||||
edit, and `restore` reads those sidecars rather than assuming what production
|
||||
was. Missing sidecar means restore refuses.
|
||||
* `restore` is idempotent and safe at any time, including after a crash.
|
||||
* Every operation re-reads both files afterwards and prints them, so the result is
|
||||
verified rather than assumed.
|
||||
* It refuses to edit while FIFA is running (the hook reads openfut.cfg at connect
|
||||
time) AND while the launcher is running (the launcher holds its config in
|
||||
memory and would write the stale values straight back over ours).
|
||||
* Only known keys are rewritten. Unknown lines and unrelated JSON keys are passed
|
||||
through untouched, and a missing key is an error rather than a silent append.
|
||||
|
||||
python3 scripts/sold-client-ports.py show
|
||||
python3 scripts/sold-client-ports.py staging # 42327 / 42330
|
||||
python3 scripts/sold-client-ports.py restore # back to the recorded values
|
||||
"""
|
||||
import json
|
||||
import subprocess
|
||||
import sys
|
||||
|
||||
CLIENT = "alex@10.10.0.105"
|
||||
CFG = "/mnt/games/FIFA 17/openfut.cfg"
|
||||
SIDECAR = "/mnt/games/FIFA 17/openfut.cfg.openfut-prod-ports"
|
||||
KEYS = ("blaze_redirector_port", "blaze_main_port")
|
||||
STAGING = {"blaze_redirector_port": "42327", "blaze_main_port": "42330"}
|
||||
# The launcher is the real owner; openfut.cfg is regenerated from these.
|
||||
LAUNCHER_CFG = "/home/alex/.config/openfut-launcher/config.json"
|
||||
LAUNCHER_SIDECAR = "/home/alex/.config/openfut-launcher/config.json.openfut-prod-ports"
|
||||
LAUNCHER_KEY = {"blaze_redirector_port": "openfut_blaze_redirector_port",
|
||||
"blaze_main_port": "openfut_blaze_main_port"}
|
||||
|
||||
|
||||
def ssh(script):
|
||||
r = subprocess.run(["ssh", "-o", "BatchMode=yes", CLIENT, script],
|
||||
capture_output=True, text=True, timeout=60)
|
||||
if r.returncode != 0:
|
||||
raise SystemExit(f"ssh failed ({r.returncode}): {r.stderr.strip()}")
|
||||
return r.stdout
|
||||
|
||||
|
||||
def read_cfg():
|
||||
return ssh(f'cat "{CFG}"')
|
||||
|
||||
|
||||
def parse(text):
|
||||
out = {}
|
||||
for line in text.splitlines():
|
||||
if "=" in line and not line.strip().startswith("#"):
|
||||
k, _, v = line.partition("=")
|
||||
out[k.strip()] = v.strip()
|
||||
return out
|
||||
|
||||
|
||||
def fifa_running():
|
||||
"""True if a real FIFA 17 process exists on the client.
|
||||
|
||||
Matches /proc/<pid>/comm exactly rather than `pgrep -f FIFA17.exe`: the pattern
|
||||
form self-matched the remote shell running it (the SSH command line contains the
|
||||
literal string), so the guard was permanently stuck ON and could never report
|
||||
"not running". comm is the executable name, so the shell reads as zsh/bash and
|
||||
only a genuine FIFA process matches. Still fail-closed: any read error or
|
||||
unexpected output is treated as "running".
|
||||
"""
|
||||
out = ssh(
|
||||
"for d in /proc/[0-9]*; do "
|
||||
"[ -r \"$d/comm\" ] && [ \"$(cat $d/comm 2>/dev/null)\" = FIFA17.exe ] "
|
||||
"&& echo ${d#/proc/}; done || true"
|
||||
).strip()
|
||||
return bool(out)
|
||||
|
||||
|
||||
def launcher_running():
|
||||
"""True if openfut-launcher is up. Its `comm` is truncated by the kernel to 15
|
||||
chars ("openfut-launche"), which has bitten this project before, so match the
|
||||
truncated form rather than the full name."""
|
||||
out = ssh(
|
||||
"for d in /proc/[0-9]*; do c=$(cat $d/comm 2>/dev/null); "
|
||||
"case \"$c\" in openfut-launche*) echo ${d#/proc/};; esac; done || true"
|
||||
).strip()
|
||||
return bool(out)
|
||||
|
||||
|
||||
def read_launcher():
|
||||
return ssh(f'cat "{LAUNCHER_CFG}"')
|
||||
|
||||
|
||||
def launcher_ports(text):
|
||||
d = json.loads(text)
|
||||
return {k: str(d.get(LAUNCHER_KEY[k])) for k in KEYS}
|
||||
|
||||
|
||||
def write_launcher(values):
|
||||
"""Rewrite only the two port keys, preserving every other setting and the file's
|
||||
formatting conventions, then verify by re-reading."""
|
||||
text = read_launcher()
|
||||
d = json.loads(text)
|
||||
for k in KEYS:
|
||||
if LAUNCHER_KEY[k] not in d:
|
||||
raise SystemExit(
|
||||
f"key {LAUNCHER_KEY[k]!r} absent from {LAUNCHER_CFG}; refusing to guess")
|
||||
existing = ssh(f'cat "{LAUNCHER_SIDECAR}" 2>/dev/null || true').strip()
|
||||
if not existing:
|
||||
rec = "\n".join(f"{k}={d[LAUNCHER_KEY[k]]}" for k in KEYS)
|
||||
ssh(f'cat > "{LAUNCHER_SIDECAR}" <<\'EOF\'\n{rec}\nEOF')
|
||||
print(f"recorded launcher production ports to {LAUNCHER_SIDECAR}:\n{rec}")
|
||||
for k, v in values.items():
|
||||
d[LAUNCHER_KEY[k]] = int(v)
|
||||
body = json.dumps(d, indent=2, sort_keys=True)
|
||||
ssh(f'cat > "{LAUNCHER_CFG}" <<\'EOF\'\n{body}\nEOF')
|
||||
after = launcher_ports(read_launcher())
|
||||
for k, v in values.items():
|
||||
if after.get(k) != str(v):
|
||||
raise SystemExit(
|
||||
f"VERIFY FAILED in launcher config: {k} is {after.get(k)!r}, want {v!r}")
|
||||
print(f"--- launcher config now: {after}")
|
||||
|
||||
|
||||
def show():
|
||||
text = read_cfg()
|
||||
print(f"--- {CFG}")
|
||||
print(text.rstrip())
|
||||
cur = parse(text)
|
||||
print("--- blaze ports:", {k: cur.get(k) for k in KEYS})
|
||||
side = ssh(f'cat "{SIDECAR}" 2>/dev/null || true').strip()
|
||||
print("--- recorded production ports:", side or "(none recorded yet)")
|
||||
print(f"--- {LAUNCHER_CFG} (authoritative)")
|
||||
print("--- launcher blaze ports:", launcher_ports(read_launcher()))
|
||||
lside = ssh(f'cat "{LAUNCHER_SIDECAR}" 2>/dev/null || true').strip()
|
||||
print("--- recorded launcher production ports:", lside or "(none recorded yet)")
|
||||
print("--- FIFA client running:", "YES" if fifa_running() else "no")
|
||||
print("--- launcher running:", "YES" if launcher_running() else "no")
|
||||
return cur
|
||||
|
||||
|
||||
def write_ports(values, label):
|
||||
if fifa_running():
|
||||
raise SystemExit(
|
||||
"REFUSING to edit while a FIFA client is running.\n"
|
||||
"The hook reads openfut.cfg at connect time; exit FIFA first."
|
||||
)
|
||||
if launcher_running():
|
||||
raise SystemExit(
|
||||
"REFUSING to edit while openfut-launcher is running.\n"
|
||||
"The launcher holds its config in memory and reconciles openfut.cfg from\n"
|
||||
"it fail-closed before every launch, so it would write the production\n"
|
||||
"ports straight back over ours. Quit the launcher first."
|
||||
)
|
||||
# Source of truth first, then the derived file.
|
||||
write_launcher(values)
|
||||
text = read_cfg()
|
||||
cur = parse(text)
|
||||
for k in KEYS:
|
||||
if k not in cur:
|
||||
raise SystemExit(f"key {k!r} is absent from {CFG}; refusing to guess it")
|
||||
# Record production values once, before the first mutation, so restore never
|
||||
# has to assume what they were.
|
||||
existing_sidecar = ssh(f'cat "{SIDECAR}" 2>/dev/null || true').strip()
|
||||
if not existing_sidecar and label == "staging":
|
||||
rec = "\n".join(f"{k}={cur[k]}" for k in KEYS)
|
||||
ssh(f'cat > "{SIDECAR}" <<\'EOF\'\n{rec}\nEOF')
|
||||
print(f"recorded production ports to {SIDECAR}:\n{rec}")
|
||||
|
||||
out = []
|
||||
for line in text.splitlines():
|
||||
k = line.partition("=")[0].strip()
|
||||
out.append(f"{k}={values[k]}" if k in values else line)
|
||||
body = "\n".join(out) + "\n"
|
||||
ssh(f'cat > "{CFG}" <<\'EOF\'\n{body.rstrip()}\nEOF')
|
||||
after = parse(read_cfg())
|
||||
for k, v in values.items():
|
||||
if after.get(k) != v:
|
||||
raise SystemExit(f"VERIFY FAILED: {k} is {after.get(k)!r}, expected {v!r}")
|
||||
print(f"--- now pointing at {label}")
|
||||
print(read_cfg().rstrip())
|
||||
|
||||
|
||||
def main():
|
||||
if len(sys.argv) != 2 or sys.argv[1] not in ("show", "staging", "restore"):
|
||||
print(__doc__)
|
||||
return 2
|
||||
cmd = sys.argv[1]
|
||||
if cmd == "show":
|
||||
show()
|
||||
return 0
|
||||
if cmd == "staging":
|
||||
write_ports(STAGING, "staging")
|
||||
return 0
|
||||
side = ssh(f'cat "{SIDECAR}" 2>/dev/null || true').strip()
|
||||
if not side:
|
||||
raise SystemExit(
|
||||
f"no recorded production ports at {SIDECAR}; refusing to guess.\n"
|
||||
"Set them by hand and verify with `show`."
|
||||
)
|
||||
write_ports(parse(side), "production (restored)")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Executable
+241
@@ -0,0 +1,241 @@
|
||||
#!/usr/bin/env python3
|
||||
"""ONE-COMMAND live capture for the seller-facing sold-row A/B.
|
||||
|
||||
Run while FIFA 17 sits on the Transfer List against the STAGING stack. Captures,
|
||||
labels and cross-checks everything at once, so a variant can never be half-recorded
|
||||
or mixed with the other:
|
||||
|
||||
1. staging wire surfaces (/tradePile, /tradePile/counts, /trade/status);
|
||||
2. the client's OWN auction record, decoded read-only out of /proc/<pid>/mem --
|
||||
STATE, YOURBID, COINS_AWARDED, MIN_CREDITS, IS_GLOW, INBOX, CARD_OFFERSTATE;
|
||||
3. the staging host's route-log DELTA since the previous capture, which is how a
|
||||
client-issued `DELETE .../trade/sold` is OBSERVED rather than assumed;
|
||||
4. a WIRE-vs-MEMORY cross-check of every shared field, plus the native IS_GLOW /
|
||||
INBOX formulas recomputed from the wire.
|
||||
|
||||
Point 4 is the discipline that matters. It validates the observation mechanism
|
||||
against a known-positive in the same run: if the wire says `bidState: "highest"` and
|
||||
the client's memory decodes `2(highest)`, the probe is demonstrably reading the right
|
||||
struct THIS time. Earlier sessions were misled twice by unvalidated negatives -- a
|
||||
sampler bug that printed "countdown NO", and empty auction containers read while the
|
||||
Transfer List was not bound. An empty read is not an empty pile.
|
||||
|
||||
python3 scripts/sold-live-capture.py --variant A_highest --label pre-clear
|
||||
"""
|
||||
import argparse
|
||||
import hashlib
|
||||
import http.client
|
||||
import json
|
||||
import os
|
||||
import re
|
||||
import subprocess
|
||||
import sys
|
||||
import time
|
||||
|
||||
REPO = os.path.dirname(os.path.dirname(os.path.abspath(__file__)))
|
||||
STAGING_DIR = "/home/alex/openfut-sold-staging"
|
||||
HOST_PORT = 8299
|
||||
CLIENT = "alex@10.10.0.105"
|
||||
PROBE = "/tmp/auction_record_probe.py"
|
||||
CURSOR = os.path.join(STAGING_DIR, ".capture-cursor")
|
||||
FORBIDDEN = {8099, 8199, 18080, 8443, 42127, 42130, 42131, 4216, 8080, 8081, 8094}
|
||||
|
||||
SURFACES = {
|
||||
"tradePile": "/ut/game/fifa17/tradePile",
|
||||
"counts": "/ut/game/fifa17/tradePile/counts",
|
||||
"trade_status_unfiltered": "/ut/game/fifa17/trade/status",
|
||||
}
|
||||
TRADE_STATE = {"active": 1, "inactive": 2, "expired": 3, "closed": 4}
|
||||
BID_STATE = {"none": 0, "outbid": 1, "highest": 2, "buyNow": 3}
|
||||
ITEM_STATE = {"invalid": 0, "free": 1, "forSale": 5, "offered": 6}
|
||||
|
||||
|
||||
def get(path):
|
||||
assert HOST_PORT not in FORBIDDEN, "refusing to contact a production port"
|
||||
c = http.client.HTTPConnection("127.0.0.1", HOST_PORT, timeout=20)
|
||||
c.request("GET", path, headers={"X-OpenFUT-Game": "fifa17"})
|
||||
r = c.getresponse()
|
||||
raw = r.read()
|
||||
c.close()
|
||||
body = json.loads(raw)
|
||||
sha = hashlib.sha256(
|
||||
json.dumps(body, sort_keys=True, separators=(",", ":")).encode()).hexdigest()
|
||||
return {"status": r.status, "body": body, "sha256": sha}
|
||||
|
||||
|
||||
def probe_client():
|
||||
"""Decode the client's live auction records. Never fabricates: no client, or an
|
||||
unbound container, is reported as-is."""
|
||||
r = subprocess.run(["ssh", "-o", "BatchMode=yes", CLIENT,
|
||||
f"cd /tmp && python3 {PROBE} 2>&1"],
|
||||
capture_output=True, text=True, timeout=120)
|
||||
text = r.stdout + r.stderr
|
||||
rows = []
|
||||
for m in re.finditer(
|
||||
r"\[\d+\]\s+rec=(\S+)\s+tradeId=(\d+)\s+state=(-?\d+)\((\w+)\)\s+"
|
||||
r"bid=(-?\d+)\((\w+)\)\s+buyNow=(\d+)\s+start=(\d+)\s+cur=(\d+)\s+"
|
||||
r"expires=(-?\d+)\s+coins=(\d+)\s+glow=(\d+)\s+inbox=(\d+)\s+watch=(\d+)"
|
||||
r"(?:.*?\n\s+item=\S+\s+CARD_ID=(\d+)\s+cardType=(\d+)\s+tradeable=(\d+)\s+"
|
||||
r"itemState=(-?\d+)\((\S+?)\)\s+rating=(\d+))?",
|
||||
text, re.S):
|
||||
g = m.groups()
|
||||
rows.append({
|
||||
"record": g[0], "tradeId": int(g[1]),
|
||||
"STATE_tradeState": f"{g[2]}({g[3]})",
|
||||
"YOURBID_bidState": f"{g[4]}({g[5]})",
|
||||
"MAX_CREDITS_buyNowPrice": int(g[6]),
|
||||
"RESERVEDPRICE_startingBid": int(g[7]),
|
||||
"MIN_CREDITS_currentBid": int(g[8]),
|
||||
"TIME_REMAINING_expires": int(g[9]),
|
||||
"COINS_AWARDED_coinsProcessed": int(g[10]),
|
||||
"IS_GLOW": int(g[11]),
|
||||
"INBOX": int(g[12]),
|
||||
"IS_WATCHED": int(g[13]),
|
||||
"CARD_ID": int(g[14]) if g[14] else None,
|
||||
"CARD_TYPE": int(g[15]) if g[15] else None,
|
||||
"tradeable": int(g[16]) if g[16] else None,
|
||||
"CARD_OFFERSTATE_itemState": f"{g[17]}({g[18]})" if g[17] else None,
|
||||
"rating": int(g[19]) if g[19] else None,
|
||||
})
|
||||
return {
|
||||
"client_running": "not running" not in text,
|
||||
"slide_control": "MATCH" if "FNV control=MATCH" in text else "UNVERIFIED",
|
||||
"rows": rows,
|
||||
"raw": text.strip(),
|
||||
}
|
||||
|
||||
|
||||
def route_delta():
|
||||
"""Staging host log lines since the previous capture: how a client-issued DELETE
|
||||
is observed rather than inferred."""
|
||||
log = os.path.join(STAGING_DIR, "logs", "utas-host.log")
|
||||
if not os.path.exists(log):
|
||||
return {"available": False, "lines": []}
|
||||
start = 0
|
||||
if os.path.exists(CURSOR):
|
||||
try:
|
||||
start = int(open(CURSOR).read().strip())
|
||||
except Exception:
|
||||
start = 0
|
||||
lines = open(log, errors="replace").read().splitlines()
|
||||
with open(CURSOR, "w") as f:
|
||||
f.write(str(len(lines)))
|
||||
new = lines[start:]
|
||||
return {
|
||||
"available": True, "from_line": start, "to_line": len(lines), "lines": new,
|
||||
"requests": [l for l in new if "route=" in l],
|
||||
"clear_or_delete": [l for l in new
|
||||
if "clear-sold" in l or "market-cancel" in l],
|
||||
}
|
||||
|
||||
|
||||
def cross_check(wire_row, mem_rows):
|
||||
out = []
|
||||
if not wire_row:
|
||||
return [{"field": "<no wire row>", "ok": False,
|
||||
"note": "nothing on the wire to compare against"}]
|
||||
mem = next((m for m in mem_rows if m["tradeId"] == wire_row.get("tradeId")), None)
|
||||
if mem is None:
|
||||
return [{"field": "<no memory row>", "ok": False,
|
||||
"note": "client holds no record for this tradeId -- it is probably not "
|
||||
"on the Transfer List screen. An empty container is NOT an "
|
||||
"empty pile; re-navigate and re-capture."}]
|
||||
|
||||
def cmp(field, wire_val, mem_val, expect=None):
|
||||
ok = (mem_val == expect) if expect is not None else (wire_val == mem_val)
|
||||
out.append({"field": field, "wire": wire_val, "memory": mem_val, "ok": ok})
|
||||
|
||||
ts, bs = wire_row.get("tradeState"), wire_row.get("bidState")
|
||||
cmp("tradeState/STATE", ts, mem["STATE_tradeState"],
|
||||
f"{TRADE_STATE.get(ts)}({ts})")
|
||||
cmp("bidState/YOURBID", bs, mem["YOURBID_bidState"], f"{BID_STATE.get(bs)}({bs})")
|
||||
cmp("currentBid/MIN_CREDITS", wire_row.get("currentBid"), mem["MIN_CREDITS_currentBid"])
|
||||
cmp("buyNowPrice/MAX_CREDITS", wire_row.get("buyNowPrice"), mem["MAX_CREDITS_buyNowPrice"])
|
||||
cmp("startingBid/RESERVEDPRICE", wire_row.get("startingBid"), mem["RESERVEDPRICE_startingBid"])
|
||||
cmp("expires/TIME_REMAINING", wire_row.get("expires"), mem["TIME_REMAINING_expires"])
|
||||
cmp("coinsProcessed/COINS_AWARDED", wire_row.get("coinsProcessed"),
|
||||
mem["COINS_AWARDED_coinsProcessed"])
|
||||
istate = wire_row.get("itemData", {}).get("itemState")
|
||||
cmp("itemState/CARD_OFFERSTATE", istate, mem["CARD_OFFERSTATE_itemState"],
|
||||
f"{ITEM_STATE.get(istate)}({istate})" if istate else None)
|
||||
exp_glow = int(bs != "none") if ts == "closed" else int(bs in ("outbid", "buyNow"))
|
||||
exp_inbox = int(bs in ("highest", "buyNow"))
|
||||
out.append({"field": "IS_GLOW (native formula)", "expected": exp_glow,
|
||||
"memory": mem["IS_GLOW"], "ok": mem["IS_GLOW"] == exp_glow})
|
||||
out.append({"field": "INBOX (native formula)", "expected": exp_inbox,
|
||||
"memory": mem["INBOX"], "ok": mem["INBOX"] == exp_inbox})
|
||||
return out
|
||||
|
||||
|
||||
def main():
|
||||
ap = argparse.ArgumentParser()
|
||||
ap.add_argument("--variant", required=True, help="A_highest | B_buyNow | C_cp0 | D_cp1")
|
||||
ap.add_argument("--label", default="capture", help="pre-clear | post-clear | reentry")
|
||||
ap.add_argument("--out", default=os.path.join(
|
||||
REPO, "docs/evidence", f"sold-ab-{time.strftime('%Y-%m-%d')}"))
|
||||
args = ap.parse_args()
|
||||
os.makedirs(args.out, exist_ok=True)
|
||||
|
||||
print("=" * 74)
|
||||
print(f"== LIVE CAPTURE variant={args.variant} label={args.label}")
|
||||
print("=" * 74)
|
||||
banner = ""
|
||||
hlog = os.path.join(STAGING_DIR, "logs", "utas-host.log")
|
||||
if os.path.exists(hlog):
|
||||
for l in open(hlog, errors="replace"):
|
||||
if "sold-experiment" in l:
|
||||
banner = l.strip()
|
||||
print(f" host banner : {banner or '(none)'}")
|
||||
|
||||
surfaces = {n: get(p) for n, p in SURFACES.items()}
|
||||
rows = surfaces["tradePile"]["body"].get("auctionInfo", [])
|
||||
wire_row = rows[0] if rows else {}
|
||||
print(f" wire : total={surfaces['tradePile']['body'].get('total')} "
|
||||
f"tradeState={wire_row.get('tradeState')} bidState={wire_row.get('bidState')} "
|
||||
f"coinsProcessed={wire_row.get('coinsProcessed')}")
|
||||
print(f" counts : {json.dumps(surfaces['counts']['body'])}")
|
||||
|
||||
mem = probe_client()
|
||||
print(f" client : running={mem['client_running']} slide={mem['slide_control']} "
|
||||
f"records={len(mem['rows'])}")
|
||||
for r in mem["rows"]:
|
||||
print(f" tradeId={r['tradeId']} STATE={r['STATE_tradeState']} "
|
||||
f"YOURBID={r['YOURBID_bidState']} "
|
||||
f"COINS_AWARDED={r['COINS_AWARDED_coinsProcessed']} "
|
||||
f"MIN_CREDITS={r['MIN_CREDITS_currentBid']} IS_GLOW={r['IS_GLOW']} "
|
||||
f"INBOX={r['INBOX']} CARD_OFFERSTATE={r['CARD_OFFERSTATE_itemState']}")
|
||||
|
||||
xc = cross_check(wire_row, mem["rows"])
|
||||
print(" cross-check (wire vs the client's own memory):")
|
||||
for c in xc:
|
||||
mark = "ok " if c.get("ok") else "FAIL"
|
||||
print(f" [{mark}] {c['field']:26s} "
|
||||
f"wire/exp={c.get('wire', c.get('expected'))!r} mem={c.get('memory')!r} "
|
||||
f"{c.get('note', '')}")
|
||||
validated = bool(mem["rows"]) and all(c.get("ok") for c in xc)
|
||||
print(f" INSTRUMENTATION {'VALIDATED' if validated else 'NOT VALIDATED'} this run")
|
||||
|
||||
routes = route_delta()
|
||||
print(f" route delta : lines {routes.get('from_line')}..{routes.get('to_line')}, "
|
||||
f"{len(routes.get('requests', []))} request line(s)")
|
||||
for l in routes.get("requests", [])[-30:]:
|
||||
print(f" {l}")
|
||||
if routes.get("clear_or_delete"):
|
||||
print(" *** CLEAR/DELETE observed:")
|
||||
for l in routes["clear_or_delete"]:
|
||||
print(f" *** {l}")
|
||||
|
||||
snap = {"variant": args.variant, "label": args.label,
|
||||
"captured": time.strftime("%Y-%m-%dT%H:%M:%SZ", time.gmtime()),
|
||||
"host_banner": banner, "surfaces": surfaces, "client_memory": mem,
|
||||
"cross_check": xc, "instrumentation_validated": validated,
|
||||
"route_delta": routes}
|
||||
path = os.path.join(args.out, f"live-{args.variant}-{args.label}.json")
|
||||
with open(path, "w") as f:
|
||||
json.dump(snap, f, indent=2, sort_keys=True)
|
||||
print(f"\n wrote {os.path.relpath(path, REPO)}")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Executable
+252
@@ -0,0 +1,252 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Tear down the isolated FIFA-17 SOLD staging stack brought up by
|
||||
`scripts/sold-staging-up.py` -- and NOTHING else.
|
||||
|
||||
Kill safety is the whole point of this file. `openfut-utas-host` and `openfut-core`
|
||||
each name TWO live processes on this machine: the staging ones and the PRODUCTION
|
||||
ones. So there is no pattern matching here at all:
|
||||
|
||||
* every pid comes from the manifest the up script wrote;
|
||||
* before any signal, /proc/<pid>/cmdline is read and MUST contain the staging
|
||||
directory -- production's cmdline never can, because staging runs binaries
|
||||
copied into that directory;
|
||||
* the known production pids are refused explicitly, as a second gate;
|
||||
* only the process GROUP the up script created (pgid == pid, via
|
||||
start_new_session) is signalled, so a responder thread/child cannot be orphaned;
|
||||
* afterwards every staging port is proven free and production is proven alive.
|
||||
|
||||
python3 scripts/sold-staging-down.py
|
||||
python3 scripts/sold-staging-down.py --purge # also delete the staging dir
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
import json
|
||||
import os
|
||||
import shutil
|
||||
import signal
|
||||
import sys
|
||||
import time
|
||||
|
||||
DEFAULT_STAGING_DIR = "/home/alex/openfut-sold-staging"
|
||||
|
||||
FORBIDDEN_PATHS = ("/home/alex/openfut-promotion/state",)
|
||||
# Production processes that MUST be alive before and after this script runs. These
|
||||
# two are the ones the batch contract names, and they live in the host pid view.
|
||||
PROD_PIDS = {3631953: "prod utas-host", 3374264: "prod Core"}
|
||||
# Reported but not gated: container pids change when the operator restarts the
|
||||
# container, and a stale entry here would turn a successful teardown into a FATAL.
|
||||
PROD_PIDS_INFO = {2090886: "prod blaze", 2091170: "prod python oracle",
|
||||
2090888: "prod pow"}
|
||||
PROD_PORTS = (8099, 8199, 18080, 8443, 42127, 42130, 42131, 4216, 8080, 8081, 8094)
|
||||
|
||||
|
||||
class Fatal(RuntimeError):
|
||||
pass
|
||||
|
||||
|
||||
def banner(title: str) -> None:
|
||||
print()
|
||||
print("=" * 78)
|
||||
print(f"== {title}")
|
||||
print("=" * 78)
|
||||
|
||||
|
||||
def ok(msg: str) -> None:
|
||||
print(f" [ OK ] {msg}")
|
||||
|
||||
|
||||
def step(msg: str) -> None:
|
||||
print(f" {msg}")
|
||||
|
||||
|
||||
def safe_path(path: str) -> str:
|
||||
real = os.path.realpath(path)
|
||||
for bad in FORBIDDEN_PATHS:
|
||||
if real == bad or real.startswith(bad + os.sep):
|
||||
raise Fatal(f"REFUSING to touch production state: {path} -> {real}")
|
||||
return path
|
||||
|
||||
|
||||
def pid_alive(pid: int) -> bool:
|
||||
try:
|
||||
os.kill(pid, 0)
|
||||
except ProcessLookupError:
|
||||
return False
|
||||
except PermissionError:
|
||||
return True
|
||||
return True
|
||||
|
||||
|
||||
def cmdline_of(pid: int) -> str:
|
||||
try:
|
||||
with open(f"/proc/{pid}/cmdline", "rb") as fh:
|
||||
return fh.read().replace(b"\0", b" ").decode(errors="replace").strip()
|
||||
except OSError:
|
||||
return ""
|
||||
|
||||
|
||||
def listening_ports() -> set[int]:
|
||||
"""Ports in state LISTEN, from the kernel socket table. A trial bind() would
|
||||
report EADDRINUSE for a stopped server's TIME_WAIT sockets and wrongly claim the
|
||||
teardown failed."""
|
||||
ports: set[int] = set()
|
||||
for path in ("/proc/net/tcp", "/proc/net/tcp6"):
|
||||
try:
|
||||
with open(path) as fh:
|
||||
next(fh, None) # header
|
||||
for line in fh:
|
||||
fields = line.split()
|
||||
if len(fields) < 4 or fields[3] != "0A": # TCP_LISTEN
|
||||
continue
|
||||
ports.add(int(fields[1].rsplit(":", 1)[1], 16))
|
||||
except OSError:
|
||||
continue
|
||||
return ports
|
||||
|
||||
|
||||
def port_free(port: int) -> bool:
|
||||
return port not in listening_ports()
|
||||
|
||||
|
||||
def stop_one(rec: dict, staging_dir: str) -> str:
|
||||
"""Stop exactly one recorded process. Returns a human-readable outcome."""
|
||||
name, pid = rec["name"], int(rec["pid"])
|
||||
|
||||
known_prod = {**PROD_PIDS, **PROD_PIDS_INFO}
|
||||
if pid in known_prod:
|
||||
raise Fatal(
|
||||
f"manifest entry {name} names PRODUCTION pid {pid} ({known_prod[pid]}). "
|
||||
"REFUSING to signal anything from this manifest."
|
||||
)
|
||||
if not pid_alive(pid):
|
||||
return f"{name} pid {pid}: already gone"
|
||||
|
||||
live = cmdline_of(pid)
|
||||
if staging_dir not in live:
|
||||
raise Fatal(
|
||||
f"{name} pid {pid} is alive but its cmdline does NOT contain "
|
||||
f"{staging_dir!r} -- pid reuse, or the wrong manifest. REFUSING to "
|
||||
f"signal it.\n cmdline: {live!r}"
|
||||
)
|
||||
|
||||
try:
|
||||
pgid = os.getpgid(pid)
|
||||
except OSError:
|
||||
pgid = pid
|
||||
recorded_pgid = int(rec.get("pgid", pid))
|
||||
if pgid != recorded_pgid:
|
||||
raise Fatal(
|
||||
f"{name} pid {pid} is in process group {pgid} but the manifest recorded "
|
||||
f"{recorded_pgid} -- REFUSING to signal a group we did not create."
|
||||
)
|
||||
if pgid != pid:
|
||||
raise Fatal(
|
||||
f"{name} pid {pid} is not its own group leader (pgid {pgid}) -- the up "
|
||||
"script always starts a new session, so this is not our process."
|
||||
)
|
||||
|
||||
os.killpg(pgid, signal.SIGTERM)
|
||||
deadline = time.monotonic() + 15.0
|
||||
while time.monotonic() < deadline and pid_alive(pid):
|
||||
time.sleep(0.1)
|
||||
if pid_alive(pid):
|
||||
os.killpg(pgid, signal.SIGKILL)
|
||||
deadline = time.monotonic() + 10.0
|
||||
while time.monotonic() < deadline and pid_alive(pid):
|
||||
time.sleep(0.1)
|
||||
if pid_alive(pid):
|
||||
raise Fatal(f"{name} pid {pid} survived SIGKILL")
|
||||
return f"{name} pid {pid} (pgid {pgid}): stopped and verified gone"
|
||||
|
||||
|
||||
def main() -> int:
|
||||
ap = argparse.ArgumentParser(description=__doc__.splitlines()[0])
|
||||
ap.add_argument("--dir", default=os.environ.get("OPENFUT_SOLD_STAGING_DIR",
|
||||
DEFAULT_STAGING_DIR),
|
||||
help=f"staging directory (default: {DEFAULT_STAGING_DIR})")
|
||||
ap.add_argument("--purge", action="store_true",
|
||||
help="delete the staging directory after stopping (default: keep "
|
||||
"the databases and logs as evidence)")
|
||||
args = ap.parse_args()
|
||||
|
||||
staging_dir = safe_path(os.path.abspath(args.dir))
|
||||
manifest_path = safe_path(os.path.join(staging_dir, "manifest.json"))
|
||||
|
||||
try:
|
||||
banner("STOPPING THE STAGING STACK (recorded pids only)")
|
||||
step(f"staging dir : {staging_dir}")
|
||||
if not os.path.exists(manifest_path):
|
||||
print(f" no manifest at {manifest_path} -- nothing was recorded, so "
|
||||
"nothing will be signalled.")
|
||||
print(" If a staging process is somehow still running, find it with "
|
||||
"its cmdline (it contains the staging dir) and stop it by pid.")
|
||||
return 0
|
||||
with open(manifest_path) as fh:
|
||||
manifest = json.load(fh)
|
||||
if manifest.get("staging_dir") != staging_dir:
|
||||
raise Fatal(
|
||||
f"manifest staging_dir {manifest.get('staging_dir')!r} != "
|
||||
f"{staging_dir!r} -- REFUSING to act on a foreign manifest."
|
||||
)
|
||||
step(f"variant : {manifest.get('variant')}")
|
||||
|
||||
for rec in manifest.get("processes", []):
|
||||
ok(stop_one(rec, staging_dir))
|
||||
|
||||
banner("PROVE STAGING IS GONE")
|
||||
ports = manifest.get("ports", {})
|
||||
for name, port in sorted(ports.items(), key=lambda kv: kv[1]):
|
||||
if port in PROD_PORTS:
|
||||
raise Fatal(f"manifest port {name}={port} is a PRODUCTION port")
|
||||
if not port_free(port):
|
||||
raise Fatal(f"staging port {name}={port} is STILL listening")
|
||||
ok(f"staging port {name} {port} free")
|
||||
|
||||
leftovers = []
|
||||
for rec in manifest.get("processes", []):
|
||||
pid = int(rec["pid"])
|
||||
if pid_alive(pid) and staging_dir in cmdline_of(pid):
|
||||
leftovers.append(f"{rec['name']} pid {pid}")
|
||||
if leftovers:
|
||||
raise Fatal("staging processes still alive: " + ", ".join(leftovers))
|
||||
ok("no recorded staging process is alive")
|
||||
|
||||
banner("PROVE PRODUCTION IS STILL UP")
|
||||
dead = [f"{what} pid {pid}" for pid, what in PROD_PIDS.items()
|
||||
if not pid_alive(pid)]
|
||||
for pid, what in PROD_PIDS.items():
|
||||
if pid_alive(pid):
|
||||
ok(f"{what} pid {pid} alive")
|
||||
if dead:
|
||||
raise Fatal("production process(es) NOT alive: " + ", ".join(dead))
|
||||
for pid, what in PROD_PIDS_INFO.items():
|
||||
state = "alive" if pid_alive(pid) else "not found (informational only)"
|
||||
step(f"{what} pid {pid} {state}")
|
||||
|
||||
if args.purge:
|
||||
shutil.rmtree(safe_path(staging_dir), ignore_errors=True)
|
||||
ok(f"purged {staging_dir}")
|
||||
else:
|
||||
os.replace(manifest_path, safe_path(manifest_path + ".stopped"))
|
||||
ok(f"kept {staging_dir} (manifest renamed to manifest.json.stopped so a "
|
||||
"fresh `up` is allowed)")
|
||||
|
||||
banner("REMINDER: REVERT THE CLIENT")
|
||||
print(' On 10.10.0.105, restore "/mnt/games/FIFA 17/openfut.cfg" to:')
|
||||
print()
|
||||
print(" host=10.10.0.120")
|
||||
print(" https_port=8443")
|
||||
print(" blaze_redirector_port=42127")
|
||||
print(" blaze_main_port=42130")
|
||||
print()
|
||||
print(" then RELAUNCH the FIFA 17 client. See docs/SOLD_STAGING_RUNBOOK.md.")
|
||||
return 0
|
||||
except Fatal as exc:
|
||||
print(f"\nFATAL: {exc}", file=sys.stderr)
|
||||
return 1
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Executable
+137
@@ -0,0 +1,137 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Probe every route the FIFA 17 FUT hub touches on the staging stack, and fail loudly
|
||||
on anything that would break it.
|
||||
|
||||
The sold-row A/B kept stalling on preconditions the headless checks never exercised:
|
||||
the identity had no squad (hub refuses to open), and any route not owned by Rust falls
|
||||
through to a deliberately dead Python upstream and answers 502. Each of those cost a
|
||||
full operator cycle -- launch, observe, report, diagnose -- so this front-loads the
|
||||
whole surface instead of discovering the next gap one restart at a time.
|
||||
|
||||
Flags three distinct failure classes, because they need different fixes:
|
||||
* 502 / PYTHON_FALLBACK -- route not implemented in Rust; the staging stack has no
|
||||
Python upstream, so it is fatal here even though production would proxy it.
|
||||
* missing_integrity -- Rust answered 200 but the underlying state is absent
|
||||
(this is exactly what "no extension stored" was before the squad was seeded).
|
||||
* empty-but-required -- 200 with a body the hub cannot work with, e.g. a squad
|
||||
with zero occupied slots. A 200 is not proof the client is satisfied.
|
||||
|
||||
python3 scripts/sold-staging-hub-sweep.py
|
||||
"""
|
||||
import http.client
|
||||
import json
|
||||
import os
|
||||
import sys
|
||||
|
||||
HOST, PORT = "127.0.0.1", 8299
|
||||
FORBIDDEN = {8099, 8199, 18080, 8443, 42127, 42130, 42131, 4216}
|
||||
HEADERS = {"X-OpenFUT-Game": "fifa17"}
|
||||
LOG = "/home/alex/openfut-sold-staging/logs/utas-host.log"
|
||||
|
||||
# Only paths the CLIENT is actually observed to request (host log route names), with
|
||||
# casing exactly as it sends them. An invented path that 502s is a bug in this list,
|
||||
# not in the stack: a first pass here flagged five "fatal" routes that turned out to
|
||||
# be guesses -- `/accountinfo` (the client uses `/user/accountinfo`), bare `/squad`
|
||||
# (it uses `/squad/active`), and `/watchlist` (it is camelCase `watchList`). Crying
|
||||
# wolf about the stack is worse than not checking, so every entry below is verified.
|
||||
ROUTES = [
|
||||
"/ut/game/fifa17/user/accountinfo",
|
||||
"/ut/game/fifa17/squad/0",
|
||||
"/ut/game/fifa17/squad/active",
|
||||
"/ut/game/fifa17/club?count=200",
|
||||
"/ut/game/fifa17/club/stats/staff",
|
||||
"/ut/game/fifa17/club/stats/club",
|
||||
"/ut/game/fifa17/clientdata/store",
|
||||
"/ut/game/fifa17/purchased/items",
|
||||
"/ut/game/fifa17/tradePile",
|
||||
"/ut/game/fifa17/tradePile/counts",
|
||||
"/ut/game/fifa17/watchList",
|
||||
"/ut/game/fifa17/trade/status",
|
||||
"/ut/game/fifa17/userMassInfo",
|
||||
"/ut/game/fifa17/settings",
|
||||
]
|
||||
|
||||
|
||||
def get(path):
|
||||
assert PORT not in FORBIDDEN, "refusing to touch a production port"
|
||||
c = http.client.HTTPConnection(HOST, PORT, timeout=20)
|
||||
c.request("GET", path, headers=HEADERS)
|
||||
r = c.getresponse()
|
||||
raw = r.read()
|
||||
c.close()
|
||||
try:
|
||||
return r.status, json.loads(raw), raw
|
||||
except Exception:
|
||||
return r.status, None, raw
|
||||
|
||||
|
||||
def squad_occupied(body):
|
||||
if not isinstance(body, dict):
|
||||
return None
|
||||
players = body.get("players")
|
||||
if not isinstance(players, list):
|
||||
return None
|
||||
return sum(1 for p in players if (p.get("itemData") or {}).get("id"))
|
||||
|
||||
|
||||
def main():
|
||||
start = 0
|
||||
if os.path.exists(LOG):
|
||||
start = len(open(LOG, errors="replace").read().splitlines())
|
||||
|
||||
fatal, warn, ok = [], [], []
|
||||
print(f"{'route':<44} {'code':>4} finding")
|
||||
print("-" * 90)
|
||||
for path in ROUTES:
|
||||
status, body, raw = get(path)
|
||||
note = ""
|
||||
if status == 502:
|
||||
note = "FATAL: no Rust owner -> dead Python upstream"
|
||||
fatal.append((path, note))
|
||||
elif status >= 400:
|
||||
note = f"FATAL: {raw[:60]!r}"
|
||||
fatal.append((path, note))
|
||||
else:
|
||||
occ = squad_occupied(body)
|
||||
if occ is not None and "squad" in path:
|
||||
note = f"squad occupied slots = {occ}"
|
||||
if occ == 0:
|
||||
note += " FATAL: hub cannot open on an empty squad"
|
||||
fatal.append((path, note))
|
||||
else:
|
||||
ok.append(path)
|
||||
else:
|
||||
ok.append(path)
|
||||
if isinstance(body, dict):
|
||||
n = body.get("total", body.get("totalResults"))
|
||||
note = f"ok{'' if n is None else f', total={n}'}"
|
||||
else:
|
||||
note = "ok"
|
||||
print(f"{path:<44} {status:>4} {note}")
|
||||
|
||||
# The host's own classification is the authority on ownership and integrity, so
|
||||
# read what it logged for the requests just made rather than inferring from bodies.
|
||||
if os.path.exists(LOG):
|
||||
new = open(LOG, errors="replace").read().splitlines()[start:]
|
||||
flagged = [l for l in new
|
||||
if "PYTHON_FALLBACK" in l or "missing_integrity" in l
|
||||
or "ERROR" in l]
|
||||
if flagged:
|
||||
print("\nhost-side findings for those requests:")
|
||||
for l in flagged:
|
||||
print(f" {l[:160]}")
|
||||
if "missing_integrity" in l:
|
||||
warn.append(l)
|
||||
|
||||
print(f"\n=== {len(ok)} ok, {len(warn)} integrity warning(s), {len(fatal)} fatal ===")
|
||||
for path, note in fatal:
|
||||
print(f" FATAL {path}: {note}")
|
||||
if fatal:
|
||||
print("\nThe hub will not work until the fatal rows are resolved.")
|
||||
return 1
|
||||
print("Every hub route the client needs is served. Safe to restart the client.")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Executable
+187
@@ -0,0 +1,187 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Seed the staging seller a valid starting XI so the FIFA hub will open.
|
||||
|
||||
The sold-row A/B only ever needed the tradePile wire, so the staging identity was
|
||||
created with owned items but NO squad. Every headless check passed because none of
|
||||
them asks for a squad -- but the real client refuses to enter the FUT hub with an
|
||||
empty one ("squad update error"), because a squad is a hub precondition, not a
|
||||
Transfer-List detail.
|
||||
|
||||
This seeds it through the REAL route -- `PUT /ut/game/fifa17/squad/0`, the same
|
||||
request the client itself sends -- so the squad is written by
|
||||
parse_squad_put/build_squad_write exactly as a genuine save would be. Writing
|
||||
Core/DB rows by hand would risk a shape the live path would never produce, which is
|
||||
the sort of divergence that invalidates an experiment.
|
||||
|
||||
Wire facts (openfut-adapter-fifa17/src/fut/squad.rs): the players array is a fixed 23
|
||||
slots; 0..=10 are the pitch, 11..=22 bench/reserves, derived from the INDEX alone and
|
||||
never from the formation token. Empty slots are `itemData.id == 0`. The formation
|
||||
token is carried verbatim and never interpreted server-side. A successful save
|
||||
answers `{"id": 0}` and does NOT echo the squad.
|
||||
|
||||
python3 scripts/sold-staging-seed-squad.py # seed, then verify
|
||||
python3 scripts/sold-staging-seed-squad.py --show # read-only
|
||||
"""
|
||||
import http.client
|
||||
import json
|
||||
import sys
|
||||
|
||||
HOST, PORT = "127.0.0.1", 8299
|
||||
FORBIDDEN = {8099, 8199, 18080, 8443, 42127, 42130, 42131, 4216}
|
||||
HEADERS = {"X-OpenFUT-Game": "fifa17", "Content-Type": "application/json"}
|
||||
SLOTS = 23
|
||||
STARTERS = 11
|
||||
# 4-3-3, laid out in the conventional FIFA slot order so the pitch reads correctly:
|
||||
# GK, RB, CB, CB, LB, CM, CM, CM, RW, ST, LW.
|
||||
LINEUP = ["GK", "RB", "CB", "CB", "LB", "CM", "CM", "CM", "RW", "ST", "LW"]
|
||||
FORMATION = "f433"
|
||||
SQUAD_TYPE = "REGULAR_SQUAD"
|
||||
CHEMISTRY = 50
|
||||
# Production's squad-manager reference, mirrored verbatim; it resolves to nothing in
|
||||
# production either (absent from its own /club/staff listing), which is exactly why
|
||||
# copying it is safe.
|
||||
PRODUCTION_MANAGER_REF = 100000427
|
||||
# Production's opaque 33-int tactics array. Never parsed server-side; reused because
|
||||
# only the shape (a JSON-encoded int array, not null) matters to the client.
|
||||
CUSTOM = ("[0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,"
|
||||
"50,50,0,50,40,65,0,65,50,50,1]")
|
||||
|
||||
|
||||
def call(method, path, body=None):
|
||||
assert PORT not in FORBIDDEN, "refusing to touch a production port"
|
||||
c = http.client.HTTPConnection(HOST, PORT, timeout=20)
|
||||
payload = json.dumps(body) if body is not None else None
|
||||
c.request(method, path, body=payload, headers=HEADERS)
|
||||
r = c.getresponse()
|
||||
raw = r.read()
|
||||
c.close()
|
||||
try:
|
||||
return r.status, json.loads(raw)
|
||||
except Exception:
|
||||
return r.status, raw.decode(errors="replace")
|
||||
|
||||
|
||||
def club_players():
|
||||
status, body = call("GET", "/ut/game/fifa17/club?count=200")
|
||||
assert status == 200, f"/club -> {status}"
|
||||
items = body.get("itemData", body.get("items", []))
|
||||
return [i for i in items if i.get("itemType") == "player"]
|
||||
|
||||
|
||||
def pick_xi(players):
|
||||
"""Choose one owned player per lineup position, best rating first, without
|
||||
reusing an instance. A position with no candidate is reported rather than
|
||||
quietly left empty -- an incomplete XI is why the hub errored in the first
|
||||
place, so silently reproducing it would defeat the point."""
|
||||
remaining = sorted(players, key=lambda p: -int(p.get("rating") or 0))
|
||||
chosen, missing = [], []
|
||||
for want in LINEUP:
|
||||
hit = next((p for p in remaining if p.get("preferredPosition") == want), None)
|
||||
if hit is None:
|
||||
hit = next((p for p in remaining), None) # any spare body, flagged below
|
||||
if hit is not None:
|
||||
missing.append(f"{want}->{hit.get('preferredPosition')}")
|
||||
if hit is None:
|
||||
missing.append(f"{want}->NONE")
|
||||
chosen.append(None)
|
||||
continue
|
||||
remaining.remove(hit)
|
||||
chosen.append(hit)
|
||||
return chosen, missing
|
||||
|
||||
|
||||
def build_put(chosen):
|
||||
players = []
|
||||
for idx in range(SLOTS):
|
||||
occupant = chosen[idx] if idx < STARTERS and chosen[idx] else None
|
||||
players.append({
|
||||
"index": idx,
|
||||
"itemData": {"id": int(occupant["id"]) if occupant else 0, "dream": False},
|
||||
"kitNumber": idx + 1 if occupant else 0,
|
||||
})
|
||||
captain = next((int(p["id"]) for p in chosen if p), 0)
|
||||
ratings = [int(p.get("rating") or 0) for p in chosen if p]
|
||||
mean_rating = sum(ratings) // len(ratings) if ratings else 0
|
||||
return {
|
||||
"id": 0,
|
||||
"squadName": "Staging XI",
|
||||
"formation": FORMATION,
|
||||
"captain": captain,
|
||||
"players": players,
|
||||
# A first attempt sent only name/formation/captain/players and the client
|
||||
# STILL refused the hub, while the host logged squad-active 200 ok -- the
|
||||
# route was fine and the body was not. Diffing against production's
|
||||
# known-good squad showed staging returning null for exactly these five,
|
||||
# because the PUT never carried them and the extension stored nothing.
|
||||
# Types matter here: the client wants scalars, not null.
|
||||
"squadType": SQUAD_TYPE,
|
||||
"chemistry": CHEMISTRY,
|
||||
"rating": mean_rating,
|
||||
"starRating": mean_rating,
|
||||
# Opaque 33-int tactics array, carried verbatim and never interpreted
|
||||
# server-side. Reused from production because only its SHAPE matters.
|
||||
"custom": CUSTOM,
|
||||
# Production carries five, all pointing at one player. Mirrored so the
|
||||
# array is populated rather than empty.
|
||||
"kicktakers": [{"index": i, "id": captain, "dream": False} for i in range(5)],
|
||||
# Mirrors production's manager reference verbatim, including the fact that
|
||||
# the id resolves to nothing.
|
||||
#
|
||||
# This looked unfixable at first: production points at instance 100000427
|
||||
# while the staging club holds 11 players and zero staff, so there was
|
||||
# apparently no manager to reference. Then checking production properly
|
||||
# showed 100000427 is absent from its OWN club listing too --
|
||||
# /club/staff returns 1975 items spanning ids 100000001..100004826 and
|
||||
# 100000427 is not one of them. Production's manager reference is dangling
|
||||
# and the client accepts that squad regardless, which proves the client does
|
||||
# not validate the manager id against the club. Only a populated array
|
||||
# matters, so replicating the known-good state exactly is both faithful and
|
||||
# sufficient -- and it beats pointing the manager slot at a player.
|
||||
"manager": [{"id": PRODUCTION_MANAGER_REF, "dream": False}],
|
||||
}
|
||||
|
||||
|
||||
def show():
|
||||
status, body = call("GET", "/ut/game/fifa17/squad/0")
|
||||
filled = [p for p in body.get("players", []) if p.get("itemData", {}).get("id")]
|
||||
print(f" /squad/0 -> {status} id={body.get('id')} "
|
||||
f"players={len(body.get('players', []))} occupied={len(filled)}")
|
||||
for p in filled:
|
||||
d = p.get("itemData", {})
|
||||
print(f" index={p.get('index')} id={d.get('id')} res={d.get('resourceId')} "
|
||||
f"pos={d.get('preferredPosition')} rating={d.get('rating')}")
|
||||
return len(filled)
|
||||
|
||||
|
||||
def main():
|
||||
print("=== staging squad, before ===")
|
||||
before = show()
|
||||
if "--show" in sys.argv:
|
||||
return 0
|
||||
players = club_players()
|
||||
print(f"=== owned players available: {len(players)} ===")
|
||||
chosen, missing = pick_xi(players)
|
||||
if missing:
|
||||
# Loud, because an out-of-position XI still opens the hub but is not what a
|
||||
# real save would look like.
|
||||
print(f" NOTE: substitutions made for {len(missing)} slot(s): {missing}")
|
||||
if any(c is None for c in chosen):
|
||||
raise SystemExit("not enough owned players for a starting XI; refusing to "
|
||||
"write a partial squad")
|
||||
put = build_put(chosen)
|
||||
print(f"=== PUT /squad/0 formation={put['formation']} captain={put['captain']} "
|
||||
f"occupied={sum(1 for p in put['players'] if p['itemData']['id'])} ===")
|
||||
status, body = call("PUT", "/ut/game/fifa17/squad/0", put)
|
||||
print(f" -> {status} {json.dumps(body)}")
|
||||
if status != 200 or body != {"id": 0}:
|
||||
raise SystemExit(f"squad save did not acknowledge as {{'id':0}}: {status} {body}")
|
||||
print("=== staging squad, after ===")
|
||||
after = show()
|
||||
if after != STARTERS:
|
||||
raise SystemExit(f"VERIFY FAILED: expected {STARTERS} occupied slots, got {after}")
|
||||
print(f" OK: {before} -> {after} occupied slots; the hub precondition is satisfied")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Executable
+1028
File diff suppressed because it is too large
Load Diff
Executable
+378
@@ -0,0 +1,378 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Wire-level verification of the seller-facing SOLD flow, in isolation.
|
||||
|
||||
Proves the harness produces a correct, authentic sold row BEFORE any operator time
|
||||
is spent driving a real FIFA client. Brings up its own Core + utas-host on ephemeral
|
||||
ports against throwaway databases, runs the real settlement through the
|
||||
`staging_sell` binary, then reads every seller-facing surface under BOTH A/B
|
||||
variants and exercises the bulk clear verb.
|
||||
|
||||
ISOLATION: production ports 8099, 8199, 18080, 8443, 42127, 42130, 42131, 4216,
|
||||
8080, 8081 and 8094 are in a hard deny-list checked before every bind and every
|
||||
request, and nothing under /home/alex/openfut-promotion/state/ is opened.
|
||||
|
||||
python3 scripts/sold-wire-check.py [--keep]
|
||||
"""
|
||||
import argparse
|
||||
import http.client
|
||||
import json
|
||||
import os
|
||||
import shutil
|
||||
import socket
|
||||
import sqlite3
|
||||
import subprocess
|
||||
import sys
|
||||
import tempfile
|
||||
import time
|
||||
|
||||
REPO = os.path.dirname(os.path.dirname(os.path.abspath(__file__)))
|
||||
FORBIDDEN = {8099, 8199, 18080, 8443, 42127, 42130, 42131, 4216, 8080, 8081, 8094}
|
||||
TS = "2026-01-01T00:00:00Z"
|
||||
PERSONA = "33068179"
|
||||
SELLER_CLUB = "club-seller-a"
|
||||
BUYER_CLUB = "club-buyer-b"
|
||||
ITEM = "core-disposable-x"
|
||||
CARD = "def-disposable"
|
||||
TRADE_ID = "900500150"
|
||||
GROSS = 150
|
||||
|
||||
checks = []
|
||||
|
||||
|
||||
def check(label, ok, detail=""):
|
||||
checks.append((label, bool(ok), detail))
|
||||
print(f" [{'PASS' if ok else 'FAIL'}] {label}{(': ' + detail) if detail else ''}")
|
||||
return ok
|
||||
|
||||
|
||||
def free_port():
|
||||
for _ in range(200):
|
||||
s = socket.socket()
|
||||
s.bind(("127.0.0.1", 0))
|
||||
p = s.getsockname()[1]
|
||||
s.close()
|
||||
if p not in FORBIDDEN and p > 1024:
|
||||
return p
|
||||
raise RuntimeError("no free port")
|
||||
|
||||
|
||||
def req(port, method, path, body=None):
|
||||
assert port not in FORBIDDEN, f"refusing to contact production port {port}"
|
||||
c = http.client.HTTPConnection("127.0.0.1", port, timeout=20)
|
||||
headers = {"X-OpenFUT-Game": "fifa17"}
|
||||
if body is not None:
|
||||
headers["Content-Type"] = "application/json"
|
||||
c.request(method, path, body=json.dumps(body) if body is not None else None,
|
||||
headers=headers)
|
||||
r = c.getresponse()
|
||||
raw = r.read()
|
||||
c.close()
|
||||
try:
|
||||
return r.status, json.loads(raw)
|
||||
except Exception:
|
||||
return r.status, raw.decode("utf-8", "replace")
|
||||
|
||||
|
||||
def wait_http(port, path, timeout=45, proc=None, log=None):
|
||||
deadline = time.time() + timeout
|
||||
while time.time() < deadline:
|
||||
if proc is not None and proc.poll() is not None:
|
||||
tail = ""
|
||||
if log and os.path.exists(log):
|
||||
tail = open(log).read()[-1500:]
|
||||
raise RuntimeError(f"process exited {proc.returncode}\n{tail}")
|
||||
try:
|
||||
st, _ = req(port, "GET", path)
|
||||
if st < 500:
|
||||
return
|
||||
except Exception:
|
||||
time.sleep(0.25)
|
||||
tail = open(log).read()[-1500:] if log and os.path.exists(log) else ""
|
||||
raise RuntimeError(f"{path} on {port} never became ready\n{tail}")
|
||||
|
||||
|
||||
def seed(db):
|
||||
"""Two identities by direct SQL: Seller A (the FIFA persona) and synthetic Buyer B."""
|
||||
con = sqlite3.connect(db)
|
||||
for prof, club, coins, game in (
|
||||
("prof-seller-a", SELLER_CLUB, 1_000, "fifa17"),
|
||||
("prof-buyer-b", BUYER_CLUB, 20_000, "buyer-game"),
|
||||
):
|
||||
con.execute(
|
||||
"INSERT INTO profiles (id, username, game_id, created_at, updated_at) "
|
||||
"VALUES (?, ?, ?, ?, ?)", (prof, prof, game, TS, TS))
|
||||
con.execute(
|
||||
"INSERT INTO clubs (id, profile_id, name, coins, created_at, updated_at) "
|
||||
"VALUES (?, ?, ?, ?, ?, ?)", (club, prof, club, coins, TS, TS))
|
||||
con.execute(
|
||||
"INSERT INTO owned_cards (id, club_id, card_id, is_loan, acquired_at) "
|
||||
"VALUES (?, ?, ?, 0, ?)", (ITEM, SELLER_CLUB, CARD, TS))
|
||||
con.commit()
|
||||
con.close()
|
||||
|
||||
|
||||
def owner_of(db, item):
|
||||
con = sqlite3.connect(db)
|
||||
row = con.execute("SELECT club_id FROM owned_cards WHERE id = ?", (item,)).fetchone()
|
||||
n = con.execute("SELECT COUNT(*) FROM owned_cards WHERE id = ?", (item,)).fetchone()[0]
|
||||
coins = dict(con.execute("SELECT id, coins FROM clubs").fetchall())
|
||||
con.close()
|
||||
return (row[0] if row else None), n, coins
|
||||
|
||||
|
||||
def start_core(tmp, port, log):
|
||||
db = os.path.join(tmp, "core.db")
|
||||
pack = os.path.join(tmp, "pack.json")
|
||||
with open(pack, "w") as f:
|
||||
# A top-level ARRAY: Core's content-pack loader expects a sequence, not a
|
||||
# map. Needed because the preflight refuses to start when an owned card
|
||||
# references a CardDefinitionId no pack defines.
|
||||
json.dump([{
|
||||
"id": CARD, "name": "Disposable", "overall": 75, "position": "ST",
|
||||
"nation": "Nation", "league": "League", "club": "Club",
|
||||
"pace": 75, "shooting": 75, "passing": 75, "dribbling": 75,
|
||||
"defending": 40, "physical": 70, "rarity": "gold",
|
||||
"image_path": None,
|
||||
}], f)
|
||||
env = dict(os.environ,
|
||||
LISTEN_ADDR=f"127.0.0.1:{port}",
|
||||
DATABASE_URL=f"sqlite://{db}",
|
||||
# Core's real data dir (read-only): it needs chemistry_styles.json
|
||||
# and friends. The throwaway DB and the content pack stay in tmp.
|
||||
DATA_DIR=os.path.join(REPO, "openfut-core", "data"),
|
||||
OPENFUT_CONTENT_PACKS=pack)
|
||||
# Migrate-only pass first: Core owns its schema, so the fixture cannot be
|
||||
# seeded into an empty file. Stop it before the external writer touches the db.
|
||||
with open(log, "w") as lf:
|
||||
p = subprocess.Popen([os.path.join(REPO, "target/release/openfut-core")],
|
||||
cwd=tmp, env=env, stdout=lf, stderr=subprocess.STDOUT)
|
||||
wait_http(port, "/health", proc=p, log=log)
|
||||
p.terminate()
|
||||
p.wait(timeout=20)
|
||||
seed(db)
|
||||
with open(log, "a") as lf:
|
||||
p = subprocess.Popen([os.path.join(REPO, "target/release/openfut-core")],
|
||||
cwd=tmp, env=env, stdout=lf, stderr=subprocess.STDOUT)
|
||||
wait_http(port, "/health", proc=p, log=log)
|
||||
return p, db
|
||||
|
||||
|
||||
def start_host(tmp, port, core_port, log, variant, coins_processed="0",
|
||||
count_mode="active"):
|
||||
with open(os.path.join(tmp, "catalog.json"), "w") as f:
|
||||
# Minimal STAGING catalog. Deliberately NOT the production catalog, which
|
||||
# lives under /home/alex/openfut-promotion/state/ and must never be opened.
|
||||
json.dump({"schema_version": 1, "game": "fifa17",
|
||||
"cards": {CARD: {"asset_id": 212188, "version": 0,
|
||||
"rareflag": 1, "kind": "player"}}}, f)
|
||||
env = dict(os.environ,
|
||||
OPENFUT_UTAS_HOST_ADDR=f"127.0.0.1:{port}",
|
||||
OPENFUT_CORE_URL=f"http://127.0.0.1:{core_port}",
|
||||
# Deliberately dead: any Python fallback must fail closed and be
|
||||
# visible, never silently serve production data.
|
||||
OPENFUT_UTAS_PYTHON_URL="http://127.0.0.1:9",
|
||||
OPENFUT_FIFA17_TABLES_DIR=os.path.join(REPO, "fifa17-recon/data/tables"),
|
||||
OPENFUT_IDENTITY_STORE=os.path.join(tmp, "identity.json"),
|
||||
OPENFUT_PERSONA_ID=PERSONA,
|
||||
OPENFUT_MARKET_DB=os.path.join(tmp, "market.db"),
|
||||
OPENFUT_PILE_DB=os.path.join(tmp, "pile.db"),
|
||||
OPENFUT_FIFA17_SOLD_EXPERIMENT=variant,
|
||||
OPENFUT_FIFA17_SOLD_COINS_PROCESSED=coins_processed,
|
||||
OPENFUT_FIFA17_SOLD_COUNT_MODE=count_mode,
|
||||
OPENFUT_FIFA17_CATALOG=os.path.join(tmp, "catalog.json"),
|
||||
RUST_LOG="info")
|
||||
with open(log, "w") as lf:
|
||||
p = subprocess.Popen([os.path.join(REPO, "target/release/openfut-utas-host")],
|
||||
cwd=tmp, env=env, stdout=lf, stderr=subprocess.STDOUT)
|
||||
wait_http(port, "/ut/game/fifa17/tradePile/counts", proc=p, log=log)
|
||||
return p
|
||||
|
||||
|
||||
def banner(t):
|
||||
print("\n" + "=" * 72)
|
||||
print(f"== {t}")
|
||||
print("=" * 72)
|
||||
|
||||
|
||||
def main():
|
||||
ap = argparse.ArgumentParser()
|
||||
ap.add_argument("--keep", action="store_true")
|
||||
args = ap.parse_args()
|
||||
|
||||
tmp = tempfile.mkdtemp(prefix="openfut-sold-wire-")
|
||||
procs = []
|
||||
try:
|
||||
core_port, host_port = free_port(), free_port()
|
||||
core_log = os.path.join(tmp, "core.log")
|
||||
host_log = os.path.join(tmp, "host.log")
|
||||
banner("ISOLATED STAGING (production untouched)")
|
||||
print(f" tmp : {tmp}")
|
||||
print(f" core : 127.0.0.1:{core_port}")
|
||||
print(f" utas-host : 127.0.0.1:{host_port}")
|
||||
print(f" forbidden : {sorted(FORBIDDEN)}")
|
||||
|
||||
core, core_db = start_core(tmp, core_port, core_log)
|
||||
procs.append(core)
|
||||
host = start_host(tmp, host_port, core_port, host_log, "highest")
|
||||
procs.append(host)
|
||||
print(" both ready")
|
||||
|
||||
bann = [l for l in open(host_log) if "sold-experiment" in l]
|
||||
check("host banner names the variant", any("bidState=highest" in l for l in bann),
|
||||
(bann[0].strip() if bann else "no banner"))
|
||||
|
||||
banner("BEFORE — seller A owns the item, nothing listed")
|
||||
own, n, coins = owner_of(core_db, ITEM)
|
||||
print(f" owner={own} instances={n} coins={coins}")
|
||||
st, pile = req(host_port, "GET", "/ut/game/fifa17/tradePile")
|
||||
st2, counts = req(host_port, "GET", "/ut/game/fifa17/tradePile/counts")
|
||||
print(f" /tradePile total={pile.get('total')} counts={json.dumps(counts)}")
|
||||
check("seller owns the item", own == SELLER_CLUB, str(own))
|
||||
check("no rows before listing", pile.get("total") == 0)
|
||||
check("sold counter starts at 0", counts.get("sold") == 0)
|
||||
|
||||
banner(f"LIST — authentic active listing at {GROSS} coins")
|
||||
# Seed the listing directly into the staging market db: the client normally
|
||||
# does this via POST /auctionhouse, which needs a wire-id mapping we do not
|
||||
# have in this headless check. The LISTING SHAPE is identical either way.
|
||||
mdb = os.path.join(tmp, "market.db")
|
||||
con = sqlite3.connect(mdb)
|
||||
con.execute(
|
||||
"INSERT INTO listings (listing_id, card_id, core_item_id, wire_item_id, "
|
||||
"wire_resource_id, start_price, buy_now_price, owner, state, created_at, "
|
||||
"item_json, duration_secs) VALUES (?,?,?,?,?,?,?,?, 'active', ?, ?, ?)",
|
||||
(TRADE_ID, CARD, ITEM, 100000178, 212188, GROSS, GROSS, "CAGE",
|
||||
str(int(time.time() * 1000)), json.dumps({
|
||||
"id": 100000178, "resourceId": 212188, "rating": 75,
|
||||
"preferredPosition": "ST", "itemState": "forSale",
|
||||
"untradeable": False, "assetId": 212188}), 3600))
|
||||
con.commit()
|
||||
con.close()
|
||||
st, pile = req(host_port, "GET", "/ut/game/fifa17/tradePile")
|
||||
st2, counts = req(host_port, "GET", "/ut/game/fifa17/tradePile/counts")
|
||||
row = pile["auctionInfo"][0]
|
||||
print(f" active row: tradeState={row['tradeState']} bidState={row['bidState']} "
|
||||
f"expires={row['expires']} counts={json.dumps(counts)}")
|
||||
check("active row is active/none", row["tradeState"] == "active" and row["bidState"] == "none")
|
||||
check("counts.selling == 1 while active", counts.get("selling") == 1)
|
||||
check("counts.sold still 0 while active", counts.get("sold") == 0)
|
||||
|
||||
banner("PURCHASE — synthetic Buyer B, through the REAL settlement path")
|
||||
out = subprocess.run(
|
||||
[os.path.join(REPO, "target/release/staging_sell"),
|
||||
"--market-db", mdb, "--core-url", f"http://127.0.0.1:{core_port}",
|
||||
"--trade-id", TRADE_ID, "--item", ITEM,
|
||||
"--seller", SELLER_CLUB, "--buyer", BUYER_CLUB, "--gross", str(GROSS)],
|
||||
capture_output=True, text=True, timeout=120)
|
||||
print(" " + "\n ".join((out.stdout + out.stderr).strip().splitlines()))
|
||||
check("staging_sell succeeded", out.returncode == 0, f"exit {out.returncode}")
|
||||
|
||||
own, n, coins = owner_of(core_db, ITEM)
|
||||
fee = GROSS * 5 // 100
|
||||
print(f" owner={own} instances={n} coins={coins} fee={fee}")
|
||||
check("ownership transferred to buyer", own == BUYER_CLUB, str(own))
|
||||
check("exactly ONE authoritative instance", n == 1, str(n))
|
||||
check("buyer debited gross", coins.get(BUYER_CLUB) == 20_000 - GROSS,
|
||||
str(coins.get(BUYER_CLUB)))
|
||||
check("seller credited net", coins.get(SELLER_CLUB) == 1_000 + GROSS - fee,
|
||||
str(coins.get(SELLER_CLUB)))
|
||||
check("economy shrank by exactly the fee",
|
||||
21_000 - sum(coins.values()) == fee, str(21_000 - sum(coins.values())))
|
||||
|
||||
banner("SOLD ROW — variant A: closed / highest")
|
||||
st, pile = req(host_port, "GET", "/ut/game/fifa17/tradePile")
|
||||
st2, counts = req(host_port, "GET", "/ut/game/fifa17/tradePile/counts")
|
||||
st3, status = req(host_port, "GET", f"/ut/game/fifa17/trade/status?tradeIds={TRADE_ID}")
|
||||
a_row = pile["auctionInfo"][0] if pile.get("auctionInfo") else {}
|
||||
print(" " + json.dumps(a_row, indent=2).replace("\n", "\n "))
|
||||
print(f" counts={json.dumps(counts)}")
|
||||
check("sold row is present in the pile", pile.get("total") == 1)
|
||||
check("tradeState closed", a_row.get("tradeState") == "closed")
|
||||
check("bidState highest (variant A)", a_row.get("bidState") == "highest")
|
||||
check("currentBid == sale price", a_row.get("currentBid") == GROSS)
|
||||
check("expires 0", a_row.get("expires") == 0)
|
||||
check("twelve atoms exactly", len(a_row) == 12, str(len(a_row)))
|
||||
check("counts.sold == 1", counts.get("sold") == 1)
|
||||
check("counts.selling == 0", counts.get("selling") == 0)
|
||||
check("/trade/status agrees", status["auctionInfo"][0]["tradeState"] == "closed"
|
||||
and status["auctionInfo"][0]["bidState"] == "highest")
|
||||
|
||||
banner("VARIANT B — same state, restart host with closed / buyNow")
|
||||
host.terminate(); host.wait(timeout=20); procs.remove(host)
|
||||
# coinsProcessed is held CONSTANT at 0 here: the primary A/B must be
|
||||
# attributable to bidState alone. The orthogonal coinsProcessed test is a
|
||||
# separate variant pair (see scripts/sold-ab-differential.py).
|
||||
host = start_host(tmp, host_port, core_port, host_log, "buyNow",
|
||||
coins_processed="0", count_mode="active_plus_sold")
|
||||
procs.append(host)
|
||||
st, pileb = req(host_port, "GET", "/ut/game/fifa17/tradePile")
|
||||
st2, countsb = req(host_port, "GET", "/ut/game/fifa17/tradePile/counts")
|
||||
b_row = pileb["auctionInfo"][0]
|
||||
print(f" bidState={b_row['bidState']} coinsProcessed={b_row['coinsProcessed']} "
|
||||
f"counts={json.dumps(countsb)}")
|
||||
check("bidState buyNow (variant B)", b_row.get("bidState") == "buyNow")
|
||||
check("coinsProcessed held constant at 0", b_row.get("coinsProcessed") == 0)
|
||||
check("count_mode active_plus_sold counts the sold row",
|
||||
countsb.get("count") == 1 and countsb.get("sold") == 1,
|
||||
json.dumps(countsb))
|
||||
differing = sorted(k for k in a_row if a_row.get(k) != b_row.get(k))
|
||||
check("A/B differ ONLY in bidState (one-field attribution)",
|
||||
differing == ["bidState"], str(differing))
|
||||
|
||||
banner("CLEAR — the PE-proven bulk verb DELETE .../trade/sold")
|
||||
pre_coins = owner_of(core_db, ITEM)[2]
|
||||
st, body = req(host_port, "DELETE", "/ut/delete/game/fifa17/trade/sold")
|
||||
print(f" HTTP {st} body={json.dumps(body)}")
|
||||
st2, pilec = req(host_port, "GET", "/ut/game/fifa17/tradePile")
|
||||
st3, countsc = req(host_port, "GET", "/ut/game/fifa17/tradePile/counts")
|
||||
own2, n2, post_coins = owner_of(core_db, ITEM)
|
||||
print(f" after clear: total={pilec.get('total')} counts={json.dumps(countsc)} "
|
||||
f"owner={own2} instances={n2}")
|
||||
check("clear acks 200 {}", st == 200 and body == {})
|
||||
check("sold row gone from the pile", pilec.get("total") == 0)
|
||||
check("counts.sold back to 0", countsc.get("sold") == 0)
|
||||
check("clear moved NO coins", pre_coins == post_coins, f"{pre_coins} -> {post_coins}")
|
||||
check("buyer still owns the item after clear", own2 == BUYER_CLUB, str(own2))
|
||||
check("still exactly one instance", n2 == 1, str(n2))
|
||||
st, again = req(host_port, "DELETE", "/ut/delete/game/fifa17/trade/sold")
|
||||
check("clearing again is a safe no-op", st == 200)
|
||||
cleared = [l for l in open(host_log) if "market-clear-sold" in l]
|
||||
check("clear is logged for capture", bool(cleared),
|
||||
cleared[-1].strip() if cleared else "no log line")
|
||||
|
||||
banner("PRODUCTION UNTOUCHED")
|
||||
alive = subprocess.run(["ps", "-o", "pid=", "-p", "3631953"],
|
||||
capture_output=True, text=True).stdout.strip()
|
||||
check("prod-host pid 3631953 still alive", alive == "3631953", alive or "gone")
|
||||
opened = subprocess.run(
|
||||
["bash", "-lc",
|
||||
"ls -l /proc/*/fd 2>/dev/null | grep -c openfut-promotion || true"],
|
||||
capture_output=True, text=True).stdout.strip()
|
||||
print(f" staging fds referencing production state: (informational) {opened}")
|
||||
|
||||
banner("RESULT")
|
||||
passed = sum(1 for _, ok, _ in checks if ok)
|
||||
print(f" {passed}/{len(checks)} checks passed")
|
||||
failed = [l for l, ok, _ in checks if not ok]
|
||||
if failed:
|
||||
print(" FAILED: " + "; ".join(failed))
|
||||
print("\n " + ("ALL CHECKS PASSED" if not failed else "FAILURES PRESENT"))
|
||||
return 0 if not failed else 1
|
||||
finally:
|
||||
for p in procs:
|
||||
try:
|
||||
p.terminate(); p.wait(timeout=15)
|
||||
except Exception:
|
||||
try:
|
||||
p.kill()
|
||||
except Exception:
|
||||
pass
|
||||
if args.keep:
|
||||
print(f"\n kept {tmp}")
|
||||
else:
|
||||
shutil.rmtree(tmp, ignore_errors=True)
|
||||
print(f"\n removed {tmp}")
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Reference in New Issue
Block a user