Compare commits
364 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| a2b0c32a70 | |||
| e49c1f211c | |||
| 96f24e799a | |||
| f315f16e8e | |||
| ead0426ea0 | |||
| 74768693ec | |||
| 6bbc0eaf4f | |||
| 09bb2dc306 | |||
| 42229e5782 | |||
| d929efdffe | |||
| 98f30931a0 | |||
| a5e5628039 | |||
| 0e200758f0 | |||
| 2fc335c37d | |||
| 25b7089c54 | |||
| 8983998707 | |||
| 96610ccb16 | |||
| 704482be84 | |||
| 0997dd3b60 | |||
| 743b20b00b | |||
| e48d659bce | |||
| a86d21ec79 | |||
| f40e8587ac | |||
| 5bf2c7ddc1 | |||
| d146f9c3fc | |||
| d4a39ba75d | |||
| 9cc5188e5c | |||
| 6baa673252 | |||
| eefa98c961 | |||
| 88ae754b0f | |||
| e0f1e379b7 | |||
| 6d89d62e41 | |||
| 40e53ed02c | |||
| b55dd16a46 | |||
| 11b7991d81 | |||
| e18304d365 | |||
| 8614acff57 | |||
| 3ff09ae62c | |||
| 34be38260d | |||
| 1e0124c197 | |||
| 286a44461d | |||
| 8c353c6c66 | |||
| 3a038fe406 | |||
| 3bb6b4fc9d | |||
| a9bac8be8e | |||
| 3c28b0d1af | |||
| 4936654f84 | |||
| 4156dc5810 | |||
| fc1fdcc5ab | |||
| 1e8d46b258 | |||
| 8ae432223a | |||
| 9026220533 | |||
| f0c6dcf238 | |||
| 6c97bc4e2b | |||
| 3c67fea074 | |||
| 2a9507cb6a | |||
| 5b8bee286c | |||
| ba19954ffb | |||
| 88b4cad780 | |||
| a4c6aeed49 | |||
| 97498c560e | |||
| 8cb2a0f9c6 | |||
| 9f445904a5 | |||
| ce5d4204ac | |||
| 6ca735749e | |||
| 739228efdb | |||
| db5fb37980 | |||
| 0a7c4e129c | |||
| a96d06dbc0 | |||
| 06d94bb37d | |||
| f371349dd5 | |||
| fb38ee6087 | |||
| cd5983ecdd | |||
| f97654af86 | |||
| 755f237f17 | |||
| 49b18dd4ac | |||
| 274838cc2e | |||
| d76c184cf1 | |||
| d74aee33f7 | |||
| 52df78d24a | |||
| 22cfae830f | |||
| 404e859cb6 | |||
| 59c249e76a | |||
| bea3b49070 | |||
| e44c88dd68 | |||
| a842c5ffb0 | |||
| 7f17cfe439 | |||
| 622a6ab353 | |||
| 67d896615c | |||
| beb505b0fa | |||
| 43aa114bcd | |||
| 4b66906adc | |||
| 9823bdac78 | |||
| 7a4dab04d2 | |||
| 23f120f889 | |||
| 09db5413cd | |||
| 1a6355cad5 | |||
| 770029f207 | |||
| 802f0f580f | |||
| 6c7d0856b6 | |||
| dcd470cddc | |||
| 8f98e6adda | |||
| 106cb83988 | |||
| 33300f2ad1 | |||
| 12ad04c9d4 | |||
| 9c2edc4eee | |||
| de747b79e6 | |||
| dddcfb917c | |||
| ff915a306e | |||
| d6aa704b01 | |||
| 054a912357 | |||
| 3442eac6f0 | |||
| db743ffd1f | |||
| ab62440dbf | |||
| 92520de6c3 | |||
| be4c52ae89 | |||
| 967a808d73 | |||
| f60dd4da31 | |||
| c59c7d88f7 | |||
| b24e96b7e6 | |||
| a8078e1d8e | |||
| c6abc435cb | |||
| 9f1fc1b47c | |||
| d8d704d441 | |||
| 07d4a92309 | |||
| afa5f620bd | |||
| 56bd9ddc85 | |||
| 9ddd80993c | |||
| 25f4ad12bc | |||
| d37a9d5b5e | |||
| e5d356e8be | |||
| 0b189b36c5 | |||
| 11c17f3039 | |||
| 871d02406f | |||
| 6811caeab1 | |||
| d71234b03d | |||
| 8e1fb640b6 | |||
| 0019806a3b | |||
| c7c057a31a | |||
| 89dc1b1d85 | |||
| 13a22c4507 | |||
| 1db9acdf6d | |||
| 911c7a34fd | |||
| fcc314afb1 | |||
| b323244ac9 | |||
| 1d6a6fffcc | |||
| f56aa613da | |||
| 8c17f896b4 | |||
| c68c10cf04 | |||
| 7116046195 | |||
| dcac2c546b | |||
| 5c8e2dc0bd | |||
| bd03aec82a | |||
| e8d1c1ddac | |||
| f9740f640d | |||
| bf6db98f0d | |||
| fc55de19fa | |||
| 6ae3364bd0 | |||
| 5c40b4993f | |||
| fbc0da2a1b | |||
| 750d6c2e18 | |||
| 082246c085 | |||
| 16771b0b33 | |||
| 022634704a | |||
| 96ca7c0484 | |||
| 202366611e | |||
| ea92057e53 | |||
| c71593b286 | |||
| 413ad901fb | |||
| e0e46d8a57 | |||
| fbe29da05b | |||
| 9ffbd651b1 | |||
| aa5fb2cc40 | |||
| 468bc0fba9 | |||
| 571c5f9261 | |||
| cb32fe9b84 | |||
| fbe9804d3e | |||
| f6606accb3 | |||
| 0a007f4941 | |||
| 0c4aee6164 | |||
| a57f4930f0 | |||
| f9ca901a50 | |||
| 3ce69f8951 | |||
| acd1def00d | |||
| 5ec9c7f8bf | |||
| 11c028e6eb | |||
| afadb13de4 | |||
| b6398c44e6 | |||
| a2bd048ace | |||
| 2e97ff1461 | |||
| 7f37b37be3 | |||
| 4e31fb98a2 | |||
| 6cc22e5cc5 | |||
| b1d7ed2570 | |||
| dcbef721f2 | |||
| 772f8a615a | |||
| bf9ae20367 | |||
| 58d1f9426f | |||
| 3cd31c4322 | |||
| ae5feb05b7 | |||
| f2c4927ea6 | |||
| aa2abc2772 | |||
| 1aa84afa9a | |||
| 33e9118329 | |||
| e06fd57211 | |||
| 42fd3c7e90 | |||
| 0bc71dbd74 | |||
| 2ecd830d75 | |||
| 3a51b0ebd4 | |||
| ad406f21bd | |||
| 12fb9fc38b | |||
| 7b580a0070 | |||
| 22443a3810 | |||
| 0fce1e521c | |||
| 71fcf5e251 | |||
| 979e71fbea | |||
| 45e0b0bd95 | |||
| 70eb3fc13f | |||
| b30aa352f6 | |||
| 67cc33cfee | |||
| 6eec3b9ec7 | |||
| 57773b98ec | |||
| fe9b899a0e | |||
| abe9e663c1 | |||
| f5a33eb58c | |||
| a85090c3c6 | |||
| 97d48d8371 | |||
| 5020137050 | |||
| cf05ab2a9e | |||
| a6416a3f1d | |||
| 47ced228de | |||
| b8beeba98d | |||
| df6994c957 | |||
| d74e86c065 | |||
| 76512f6048 | |||
| 93a46d4de7 | |||
| 3ba24a0faf | |||
| 6926bb9528 | |||
| b1643309f6 | |||
| 43917a0051 | |||
| 1fac71e3ef | |||
| 747cc234c1 | |||
| fe72f0def2 | |||
| 884ecbba64 | |||
| 580d80a86e | |||
| 0e2ca5a7c3 | |||
| 4d2b8b9be3 | |||
| 0b31abe1d1 | |||
| 6b652cb0a2 | |||
| 3507c5714d | |||
| 4f78b9a875 | |||
| f3aebafcc7 | |||
| 1df0bc4f00 | |||
| 7d5d0cff06 | |||
| 8d752cb0e4 | |||
| 96e80ab293 | |||
| 49c5185ae3 | |||
| 181bd94341 | |||
| 09675a9f7f | |||
| 56c364e4c9 | |||
| 3021a4e761 | |||
| d240a61157 | |||
| d7c5307045 | |||
| 838d76f95e | |||
| 9791eee67b | |||
| 5d119f5555 | |||
| 46e5f612c8 | |||
| 41494bd18f | |||
| 40ebf7c1e7 | |||
| c7609252d2 | |||
| 4cf388dd3b | |||
| 00d85aa6e4 | |||
| d9e80a774a | |||
| a82407c686 | |||
| 805d754dc8 | |||
| d4c3811665 | |||
| b25761ea31 | |||
| 1c396dd562 | |||
| fc29c2eb9b | |||
| b0d5e04bb9 | |||
| 6746c75302 | |||
| b2697b13dc | |||
| e8ee6c34e7 | |||
| f42279f869 | |||
| 54ad9e8f79 | |||
| 6f16a231fc | |||
| 626c972232 | |||
| 44fcf24d92 | |||
| e187cd49a2 | |||
| 1631d3b1a2 | |||
| c71c2a8d33 | |||
| a51947562c | |||
| 63f02c4fb1 | |||
| 4fd5ee2608 | |||
| c7d4b9f753 | |||
| 37c2e5d7ee | |||
| 7dbd878398 | |||
| c2e2e0d8f2 | |||
| afc909fd3b | |||
| b607ff28cb | |||
| cf86d4e425 | |||
| 85761390a8 | |||
| 4d30d8b3e8 | |||
| 0e30980632 | |||
| 46a81e7a07 | |||
| e09344490f | |||
| 80a8bc4520 | |||
| b50e0359f7 | |||
| 58a300c7f4 | |||
| eb8311a5ee | |||
| 550a59d12c | |||
| 8c1d1ed958 | |||
| fc00b0c6f9 | |||
| 5276dd2066 | |||
| 88da16a11e | |||
| 3ef3bc32ec | |||
| 36fe1caa3f | |||
| f55c401b6c | |||
| b8037b9b22 | |||
| c0a3f68ded | |||
| 04c5043aba | |||
| 0b66662525 | |||
| cdea85e214 | |||
| 05f6147433 | |||
| 8f3b659c33 | |||
| c9ae914910 | |||
| 84e81f2037 | |||
| 696386a9c1 | |||
| aa2679162d | |||
| 096d1c882f | |||
| ca63095786 | |||
| c65e9c54ce | |||
| b1bc7a764e | |||
| d7c0a5521d | |||
| 2ae90b1ea9 | |||
| cfb0435d96 | |||
| fc411bb6f1 | |||
| 5bc39e902d | |||
| e2c4ca6d56 | |||
| 288d990821 | |||
| c03702707b | |||
| 89f77470f3 | |||
| 0d576a14b7 | |||
| c5807c07a9 | |||
| 8f5f54833f | |||
| f451406058 | |||
| 8aab2c0d41 | |||
| ed0ccb8c2b | |||
| b40adac3fc | |||
| bfb7876ed4 | |||
| 55b4e54d5f | |||
| fafa2f1858 | |||
| c84fd14cac | |||
| 23374312bc | |||
| a84a72e0c0 | |||
| 6c102f00c0 | |||
| 48aa955212 | |||
| cf3ddde3a6 | |||
| 468b006008 | |||
| e091921b18 | |||
| a9eb54ae9c | |||
| cf961603fe | |||
| cc3ecddc06 | |||
| a9a816e0ed |
@@ -0,0 +1,25 @@
|
|||||||
|
# OpenFUT Docker stack configuration. Copy to .env and adjust.
|
||||||
|
# All values have sensible defaults in docker-compose.yml; override as needed.
|
||||||
|
|
||||||
|
# --- Container registry (Gitea) ---
|
||||||
|
# Images resolve to ${REGISTRY}/${NAMESPACE}/<image>:${TAG}
|
||||||
|
# e.g. git.aleshym.co/openfut/openfut-core:latest
|
||||||
|
REGISTRY=git.aleshym.co
|
||||||
|
NAMESPACE=openfut
|
||||||
|
TAG=latest
|
||||||
|
|
||||||
|
# --- Networking ---
|
||||||
|
# Where the bridge (FIFA client entry point) is published. 0.0.0.0 = all
|
||||||
|
# interfaces so LAN clients can connect. Set to a specific IP to restrict.
|
||||||
|
BRIDGE_PUBLISH=0.0.0.0
|
||||||
|
# Where core's REST API is published. 127.0.0.1 keeps it host-local (the bridge
|
||||||
|
# still reaches it over the internal docker network). Set 0.0.0.0 to expose it.
|
||||||
|
CORE_PUBLISH=127.0.0.1
|
||||||
|
|
||||||
|
# --- Behaviour ---
|
||||||
|
# Bridge returns placeholder JSON + captures unknown routes when true.
|
||||||
|
PLACEHOLDER_MODE=true
|
||||||
|
|
||||||
|
# --- Logging (RUST_LOG filters) ---
|
||||||
|
CORE_LOG=openfut_core=info,tower_http=info
|
||||||
|
BRIDGE_LOG=openfut_bridge=info,tower_http=info
|
||||||
@@ -30,3 +30,9 @@ Thumbs.db
|
|||||||
|
|
||||||
# Frozen baseline archives / inspects / manifests
|
# Frozen baseline archives / inspects / manifests
|
||||||
/docker-backups/
|
/docker-backups/
|
||||||
|
gate-evidence/
|
||||||
|
|
||||||
|
# Raw Fire2 frame captures — forensic evidence, may contain session material.
|
||||||
|
# Sanitize with `blaze-sanitize` before anything leaves this machine.
|
||||||
|
*.ofcap
|
||||||
|
captures/
|
||||||
|
|||||||
@@ -0,0 +1,163 @@
|
|||||||
|
# AGENTS.md — OpenFUT
|
||||||
|
|
||||||
|
**Read this first.** It is the entry point for AI-assisted work on OpenFUT. It supersedes the
|
||||||
|
root `README.md` and `CLAUDE.md`, which are **stale** (they describe an earlier FIFA 23 plan).
|
||||||
|
|
||||||
|
## Project
|
||||||
|
|
||||||
|
OpenFUT is a preservation / private-server project that restores **offline, single-player FIFA
|
||||||
|
Ultimate Team (FUT)** after EA retired the online servers. You must own the game legitimately; the
|
||||||
|
project does not bypass ownership checks — it only re-serves the dead online services locally.
|
||||||
|
|
||||||
|
**Current active target: FIFA 17 (PC).** A clean-room emulation of the full online + FUT stack
|
||||||
|
was proven working end-to-end on **2026-08-01** (auth → Blaze login → device-trust → FUT hub).
|
||||||
|
This lives in `fifa17-recon/`. The FIFA 17 work is explicitly the **Rosetta Stone for FIFA 23**
|
||||||
|
(identical Blaze/LSX/UTAS wire format), so FIFA 23 remains the eventual second target.
|
||||||
|
|
||||||
|
Three moving parts, kept strictly separate:
|
||||||
|
- **The FIFA client** — the retail game (FIFA 17 now). Unmodified except live cert-verify patches.
|
||||||
|
- **The emulation layer** — Python responders in `fifa17-recon/tools/` (LSX, Blaze, UTAS, roster)
|
||||||
|
that impersonate EA's online services on localhost. This is where all reverse engineering lives.
|
||||||
|
- **OpenFUT Core** — a game-independent REST FUT economy backend (`openfut-core/`), feature-complete
|
||||||
|
and tested. Knows nothing about FIFA. Intended to eventually back the emulation layer's FUT data.
|
||||||
|
|
||||||
|
> The emulation layer and Core are **not yet wired together.** The FIFA 17 UTAS server currently
|
||||||
|
> serves its own hardcoded/JSON payloads, not Core's API. See `docs/PROJECT_STATE.md`.
|
||||||
|
|
||||||
|
## Repository map
|
||||||
|
|
||||||
|
Monorepo. `openfut-core`, `openfut-bridge`, `openfut-launcher`, `fifa-blaze` are **git submodules**
|
||||||
|
(each with independent history — use `tea`/Gitea, not `gh`). `fifa17-recon/` is a plain directory.
|
||||||
|
|
||||||
|
| Path | What it is | Status |
|
||||||
|
|---|---|---|
|
||||||
|
| `fifa17-recon/` | **The live path.** FIFA 17 offline FUT emulation: Python responders, cert patcher, runbook, RE write-ups. | Working |
|
||||||
|
| `openfut-core/` | Rust (Axum + SQLite) FUT economy backend. Game-independent REST API. | Working, tested |
|
||||||
|
| `openfut-bridge/` | Rust FIFA 23 in-process hook / proxy RE effort. | Blocked (see below) |
|
||||||
|
| `fifa-blaze/` | Rust Blaze protocol emulator scaffold for FIFA 23 (capture stub). | Milestone 1 stub |
|
||||||
|
| `openfut-launcher/` | Rust egui/eframe desktop launcher (targets FIFA 23 hook flow). | Legacy plan |
|
||||||
|
| `docs/` | **Mirrors** of the vault (`OpenFUT-Vault`), which is canonical. Direction pivots + context. | — |
|
||||||
|
| `tools/` | Host-side RE helpers (file-watch-diff, exporters, squad-injector) from the FLE-bridge idea. | Legacy plan |
|
||||||
|
| `setup.sh` | FIFA 23 full-stack orchestrator (core+bridge). | Legacy plan |
|
||||||
|
|
||||||
|
**Legacy vs live:** the project pivoted twice — (1) FIFA 23 Blaze backend → (2) FIFA 23 as a match
|
||||||
|
renderer driven by an FLE Lua bridge (`docs/direction.md`) → (3) **FIFA 17 full online emulation,
|
||||||
|
which succeeded and is now the primary path** (`fifa17-recon/`). Treat `openfut-bridge`,
|
||||||
|
`openfut-launcher`, `fifa-blaze`, `tools/`, `setup.sh`, and `docs/direction.md` as historical unless
|
||||||
|
a task explicitly targets the FIFA 23 port.
|
||||||
|
|
||||||
|
## Architecture (live path)
|
||||||
|
|
||||||
|
```
|
||||||
|
FIFA 17 client (Wine/Proton, base 0x140000000)
|
||||||
|
│ autopatch.py NOPs two ProtoSSL cert-verify gates in /proc/PID/mem
|
||||||
|
├─ LSX 127.0.0.1:4216 → lsx_responder_v2.py (Origin login/profile/authcode)
|
||||||
|
├─ TLS 127.0.0.1:42127 → blaze_responder_v3b.py (Blaze redirector, via DNAT of 159.153.51.20)
|
||||||
|
├─ Blaze 42130 / Nucleus 42131 → blaze_responder_v3b.py (Fire2/Heat2 binary + login)
|
||||||
|
├─ easw.easports.com (→127.0.0.1) :8099 → utas_server.py (UTAS/RS4 FUT API + device-trust)
|
||||||
|
└─ roster :8081 → roster_server.py (FUT roster-update XML)
|
||||||
|
|
||||||
|
OpenFUT Core (openfut-core, :8080) ── clean REST FUT economy ── NOT YET CONNECTED to the above
|
||||||
|
```
|
||||||
|
|
||||||
|
Host arming (`root_arm.sh` via `pkexec`, volatile across reboot): `ptrace_scope=0`,
|
||||||
|
`route_localnet=1`, iptables DNAT `159.153.51.20→127.0.0.1:42127`, `/etc/hosts easw.easports.com`.
|
||||||
|
|
||||||
|
## Development commands (verified)
|
||||||
|
|
||||||
|
**FIFA 17 emulation** (from `fifa17-recon/tools/`):
|
||||||
|
- Start everything (idempotent; re-run after reboot): `./openfut-fut.sh start`
|
||||||
|
- Status / stop / restart: `./openfut-fut.sh status | stop | restart`
|
||||||
|
- Then launch the game fresh (`~/Desktop/launch-fifa17.sh`) and pick Ultimate Team.
|
||||||
|
- Logs: `/tmp/{lsx,blaze,roster,utas,autopatch}.log`
|
||||||
|
- Full procedure + gate-ladder troubleshooting: `fifa17-recon/FUT-RUNBOOK.md`
|
||||||
|
|
||||||
|
**OpenFUT Core** (from `openfut-core/`): `cargo run` (creates `openfut.db`) · `cargo test`
|
||||||
|
(full in-memory integration suite; requires `data/`) · `cargo test <name>` for one ·
|
||||||
|
`cargo clippy -- -D warnings` · `cargo fmt`. Env: `LISTEN_ADDR` (127.0.0.1:8080), `DATABASE_URL`
|
||||||
|
(sqlite://openfut.db), `DATA_DIR` (data).
|
||||||
|
|
||||||
|
**Other Rust crates** (`openfut-bridge`, `fifa-blaze`, `openfut-launcher`): standard
|
||||||
|
`cargo run/build/test/clippy/fmt` from within each. `fifa-blaze` is a workspace (`--bin blaze-server`).
|
||||||
|
|
||||||
|
**CI:** only `openfut-core` has it (`.gitea/workflows/ci.yml`): `fmt --check`, `clippy -D warnings`,
|
||||||
|
`build --locked`, `test --locked` on push/PR to main. No CI on the other crates or the recon dir.
|
||||||
|
|
||||||
|
There is **no install step, no Docker, no JS/TS frontend, no typecheck** in this repo. Do not invent them.
|
||||||
|
|
||||||
|
## Coding conventions
|
||||||
|
|
||||||
|
- **Rust (Core):** Axum 0.7 + SQLx 0.7 (SQLite, compile-time-checked queries). Strict layering —
|
||||||
|
`routes/` (handlers, extract state, call services) → `services/` (own **all** DB access + logic)
|
||||||
|
→ `models/` (pure `Serde`/`FromRow` data). Errors via `AppError` (`src/error.rs`) with
|
||||||
|
`IntoResponse`. One file per domain across `routes/`, `services/`, `models/`. **Single-profile
|
||||||
|
design:** every service reads "the active profile" as the first DB row — intentional, don't
|
||||||
|
parameterize it. Content is data-driven: JSON under `data/` loaded at startup into Arc registries
|
||||||
|
in `AppState`. Add content by dropping JSON files, not code. Migrations are numbered SQL in
|
||||||
|
`migrations/`. Keep `clippy -D warnings` and `fmt` clean (CI enforces).
|
||||||
|
- **Python (recon):** stdlib-only servers, no framework. Each responder is a standalone script with
|
||||||
|
the reverse-engineered contract documented in its module docstring (byte offsets, VAs, symbol
|
||||||
|
names). When changing a responder, preserve byte-exactness — the client is the oracle.
|
||||||
|
- **Clean-room, always.** Every finding derives from binaries we own + live observation. **Never**
|
||||||
|
use, reference, or reproduce leaked EA source. If a task seems to need it, stop and say so.
|
||||||
|
|
||||||
|
## AI-agent rules
|
||||||
|
|
||||||
|
1. Read this file before exploring the repo.
|
||||||
|
2. Read the vault file relevant to the task (`../OpenFUT-Vault/`), not the whole tree. Repo
|
||||||
|
`docs/` files are mirrors of the vault — consult them for the same content, but treat the
|
||||||
|
vault as canonical.
|
||||||
|
3. Don't scan the whole repository unless the knowledge base is clearly stale — if you find it
|
||||||
|
stale, update the vault, then its repo `docs/` mirror.
|
||||||
|
4. Search the specific directory (`fifa17-recon/`, `openfut-core/src/<layer>/`) before a repo-wide search.
|
||||||
|
5. Update the vault when architecture materially changes (and sync the matching `docs/` mirror).
|
||||||
|
6. Don't refactor or rewrite unrelated working code.
|
||||||
|
7. Prefer small, testable changes; run the narrowest relevant test first (`cargo test <name>`).
|
||||||
|
8. **Never invent EA/FIFA/Blaze protocol behavior.** Values you don't know are `TODO/CONFIRM`, not
|
||||||
|
confident guesses. The live client is the only oracle for whether a gate is satisfied.
|
||||||
|
9. Clearly separate discovered behavior from hypotheses; record findings in
|
||||||
|
`../OpenFUT-Vault/02 Reverse Engineering/FIFA 17/Protocol Findings.md` under the right confidence
|
||||||
|
tier — never silently promote a hypothesis to a fact.
|
||||||
|
10. Root `README.md` / `CLAUDE.md` and `openfut-bridge/CLAUDE.md` describe superseded FIFA 23 plans;
|
||||||
|
prefer vault + repository evidence over them when they conflict.
|
||||||
|
|
||||||
|
## AI Session Bootstrap
|
||||||
|
|
||||||
|
Future agents should start with:
|
||||||
|
1. Read `AGENTS.md`.
|
||||||
|
2. Read the vault README (`../OpenFUT-Vault/README.md`) to locate the canonical files.
|
||||||
|
3. Identify the subsystem the task affects and read the corresponding vault file: Architecture,
|
||||||
|
Project State, Roadmap/Current Priorities, or Protocol Findings.
|
||||||
|
4. Inspect only the relevant source directories.
|
||||||
|
5. Check `../OpenFUT-Vault/02 Reverse Engineering/FIFA 17/Protocol Findings.md` before assuming
|
||||||
|
anything about FIFA/EA behavior.
|
||||||
|
6. Check `../OpenFUT-Vault/06 Agent Memory/Project State.md` before assuming a feature exists.
|
||||||
|
7. Implement the smallest coherent change.
|
||||||
|
8. Run the narrowest relevant tests.
|
||||||
|
9. Update the vault (and its repo `docs/` mirror) only if the change makes existing knowledge
|
||||||
|
inaccurate.
|
||||||
|
|
||||||
|
Do not reread the entire repository during every session.
|
||||||
|
|
||||||
|
## OpenFUT Knowledge Base
|
||||||
|
|
||||||
|
**The OpenFUT Vault is the canonical project knowledge base.** Repo `docs/` files mirror it; the
|
||||||
|
vault wins on any disagreement. Consult it before starting substantial work and update it after
|
||||||
|
durable discoveries.
|
||||||
|
|
||||||
|
Vault location: `../OpenFUT-Vault/` — start at `../OpenFUT-Vault/README.md`.
|
||||||
|
|
||||||
|
Canonical files:
|
||||||
|
- Dashboard: `00 Dashboard/OpenFUT.md`
|
||||||
|
- Architecture: `01 Architecture/Architecture.md` (repo mirror `docs/ARCHITECTURE.md`)
|
||||||
|
- RE findings: `02 Reverse Engineering/FIFA 17/Protocol Findings.md`
|
||||||
|
(repo mirror `docs/research/KNOWN_FINDINGS.md`)
|
||||||
|
- Direction history: `04 Decisions/Direction History.md`
|
||||||
|
- Project State: `06 Agent Memory/Project State.md` (repo mirror `docs/PROJECT_STATE.md`)
|
||||||
|
- Current Priorities: `06 Agent Memory/Current Priorities.md`
|
||||||
|
- Known Issues: `06 Agent Memory/Known Issues.md`
|
||||||
|
- Important Discoveries: `06 Agent Memory/Important Discoveries.md`
|
||||||
|
- Roadmap: `08 Roadmap/Roadmap.md` (repo mirror `docs/ROADMAP.md`)
|
||||||
|
|
||||||
|
When editing knowledge that exists in both places, edit the vault first, then update the matching
|
||||||
|
`docs/` mirror so they stay in sync.
|
||||||
@@ -2,6 +2,8 @@
|
|||||||
|
|
||||||
This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.
|
This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.
|
||||||
|
|
||||||
|
> ⚠️ **Stale (FIFA 23).** This file's status and targets predate the FIFA 17 pivot. Prefer [`docs/PROJECT_STATE.md`](./docs/PROJECT_STATE.md) (canonical). The working target is **FIFA 17**; the canonical server is `fifa17-recon/docker/fifa17-python` (`docker compose up -d`). `openfut-bridge` (FIFA 23) is superseded; `openfut-core` remains the shared backend.
|
||||||
|
|
||||||
## Repository Layout
|
## Repository Layout
|
||||||
|
|
||||||
This is a monorepo containing three independent Rust crates as git submodules:
|
This is a monorepo containing three independent Rust crates as git submodules:
|
||||||
|
|||||||
Generated
+255
-95
@@ -457,6 +457,29 @@ version = "1.5.1"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "f2032f911046de80f0a198e0901378627c33f59ea0ac00e363d481118bd70a53"
|
checksum = "f2032f911046de80f0a198e0901378627c33f59ea0ac00e363d481118bd70a53"
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "aws-lc-rs"
|
||||||
|
version = "1.18.0"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "ce2b2dcc879c3bae0d371e77c99f2238400ef24ec001394befa67b6e543add9e"
|
||||||
|
dependencies = [
|
||||||
|
"aws-lc-sys",
|
||||||
|
"zeroize",
|
||||||
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "aws-lc-sys"
|
||||||
|
version = "0.44.0"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "f09fae7be8bb3174e05c6afdb34199e6dc0c7c04ba9fa237b1967adfbde27483"
|
||||||
|
dependencies = [
|
||||||
|
"cc",
|
||||||
|
"cmake",
|
||||||
|
"dunce",
|
||||||
|
"fs_extra",
|
||||||
|
"pkg-config",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "axum"
|
name = "axum"
|
||||||
version = "0.7.9"
|
version = "0.7.9"
|
||||||
@@ -613,19 +636,6 @@ dependencies = [
|
|||||||
"tokio-util",
|
"tokio-util",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
|
||||||
name = "blaze-ssl-async"
|
|
||||||
version = "0.4.0"
|
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
|
||||||
checksum = "6fec08f35919613bda0b3eb3bc772c2f793b3634133923b931874b18e1ac55de"
|
|
||||||
dependencies = [
|
|
||||||
"bytes",
|
|
||||||
"num_enum",
|
|
||||||
"rsa",
|
|
||||||
"tokio",
|
|
||||||
"x509-cert",
|
|
||||||
]
|
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "block"
|
name = "block"
|
||||||
version = "0.1.6"
|
version = "0.1.6"
|
||||||
@@ -830,6 +840,15 @@ dependencies = [
|
|||||||
"error-code",
|
"error-code",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "cmake"
|
||||||
|
version = "0.1.58"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "c0f78a02292a74a88ac736019ab962ece0bc380e3f977bf72e376c5d78ff0678"
|
||||||
|
dependencies = [
|
||||||
|
"cc",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "codespan-reporting"
|
name = "codespan-reporting"
|
||||||
version = "0.11.1"
|
version = "0.11.1"
|
||||||
@@ -1062,23 +1081,10 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
|
|||||||
checksum = "e7c1832837b905bbfb5101e07cc24c8deddf52f93225eee6ead5f4d63d53ddcb"
|
checksum = "e7c1832837b905bbfb5101e07cc24c8deddf52f93225eee6ead5f4d63d53ddcb"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"const-oid",
|
"const-oid",
|
||||||
"der_derive",
|
|
||||||
"flagset",
|
|
||||||
"pem-rfc7468",
|
"pem-rfc7468",
|
||||||
"zeroize",
|
"zeroize",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
|
||||||
name = "der_derive"
|
|
||||||
version = "0.7.3"
|
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
|
||||||
checksum = "8034092389675178f570469e6c3b0465d3d30b4505c294a6550db47f3c17ad18"
|
|
||||||
dependencies = [
|
|
||||||
"proc-macro2",
|
|
||||||
"quote",
|
|
||||||
"syn 2.0.119",
|
|
||||||
]
|
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "deranged"
|
name = "deranged"
|
||||||
version = "0.5.8"
|
version = "0.5.8"
|
||||||
@@ -1187,6 +1193,12 @@ version = "0.1.2"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "d8b14ccef22fc6f5a8f4d7d768562a182c04ce9a3b3157b91390b52ddfdf1a76"
|
checksum = "d8b14ccef22fc6f5a8f4d7d768562a182c04ce9a3b3157b91390b52ddfdf1a76"
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "dunce"
|
||||||
|
version = "1.0.5"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "92773504d58c093f6de2459af4af33faa518c13451eb8f2b5698ed3d36e7c813"
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "ecolor"
|
name = "ecolor"
|
||||||
version = "0.29.1"
|
version = "0.29.1"
|
||||||
@@ -1457,12 +1469,6 @@ version = "0.1.9"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "5baebc0774151f905a1a2cc41989300b1e6fbb29aff0ceffa1064fdd3088d582"
|
checksum = "5baebc0774151f905a1a2cc41989300b1e6fbb29aff0ceffa1064fdd3088d582"
|
||||||
|
|
||||||
[[package]]
|
|
||||||
name = "flagset"
|
|
||||||
version = "0.4.7"
|
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
|
||||||
checksum = "b7ac824320a75a52197e8f2d787f6a38b6718bb6897a35142d749af3c0e8f4fe"
|
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "flate2"
|
name = "flate2"
|
||||||
version = "1.1.9"
|
version = "1.1.9"
|
||||||
@@ -1547,6 +1553,12 @@ dependencies = [
|
|||||||
"percent-encoding",
|
"percent-encoding",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "fs_extra"
|
||||||
|
version = "1.3.0"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "42703706b716c37f96a77aea830392ad231f44c9e9a67872fa5548707e11b11c"
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "futures-channel"
|
name = "futures-channel"
|
||||||
version = "0.3.33"
|
version = "0.3.33"
|
||||||
@@ -2113,9 +2125,9 @@ dependencies = [
|
|||||||
"futures-util",
|
"futures-util",
|
||||||
"http 0.2.12",
|
"http 0.2.12",
|
||||||
"hyper 0.14.32",
|
"hyper 0.14.32",
|
||||||
"rustls",
|
"rustls 0.21.12",
|
||||||
"tokio",
|
"tokio",
|
||||||
"tokio-rustls",
|
"tokio-rustls 0.24.1",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
@@ -3126,11 +3138,34 @@ version = "1.21.4"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "9f7c3e4beb33f85d45ae3e3a1792185706c8e16d043238c593331cc7cd313b50"
|
checksum = "9f7c3e4beb33f85d45ae3e3a1792185706c8e16d043238c593331cc7cd313b50"
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "openfut-adapter-fifa17"
|
||||||
|
version = "0.1.0"
|
||||||
|
dependencies = [
|
||||||
|
"openfut-protocol-blaze",
|
||||||
|
"rand",
|
||||||
|
"serde",
|
||||||
|
"serde_json",
|
||||||
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "openfut-autopatch"
|
||||||
|
version = "0.1.0"
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "openfut-blaze-host"
|
||||||
|
version = "0.1.0"
|
||||||
|
dependencies = [
|
||||||
|
"openfut-adapter-fifa17",
|
||||||
|
"openfut-protocol-blaze",
|
||||||
|
"rand",
|
||||||
|
"serde_json",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "openfut-bridge"
|
name = "openfut-bridge"
|
||||||
version = "0.1.0"
|
version = "0.1.0"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"aes",
|
|
||||||
"anyhow",
|
"anyhow",
|
||||||
"axum",
|
"axum",
|
||||||
"bytes",
|
"bytes",
|
||||||
@@ -3141,13 +3176,13 @@ dependencies = [
|
|||||||
"hyper-util",
|
"hyper-util",
|
||||||
"rcgen",
|
"rcgen",
|
||||||
"reqwest",
|
"reqwest",
|
||||||
"rustls",
|
"rustls 0.21.12",
|
||||||
"rustls-pemfile",
|
"rustls-pemfile 1.0.4",
|
||||||
"serde",
|
"serde",
|
||||||
"serde_json",
|
"serde_json",
|
||||||
"thiserror 1.0.69",
|
"thiserror 1.0.69",
|
||||||
"tokio",
|
"tokio",
|
||||||
"tokio-rustls",
|
"tokio-rustls 0.24.1",
|
||||||
"tokio-stream",
|
"tokio-stream",
|
||||||
"tower 0.4.13",
|
"tower 0.4.13",
|
||||||
"tower-http",
|
"tower-http",
|
||||||
@@ -3156,6 +3191,10 @@ dependencies = [
|
|||||||
"uuid",
|
"uuid",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "openfut-common"
|
||||||
|
version = "0.1.0"
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "openfut-core"
|
name = "openfut-core"
|
||||||
version = "0.1.0"
|
version = "0.1.0"
|
||||||
@@ -3171,6 +3210,7 @@ dependencies = [
|
|||||||
"serde",
|
"serde",
|
||||||
"serde_json",
|
"serde_json",
|
||||||
"sqlx",
|
"sqlx",
|
||||||
|
"tempfile",
|
||||||
"thiserror 1.0.69",
|
"thiserror 1.0.69",
|
||||||
"tokio",
|
"tokio",
|
||||||
"tower 0.5.3",
|
"tower 0.5.3",
|
||||||
@@ -3181,10 +3221,40 @@ dependencies = [
|
|||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "openfut-hook"
|
name = "openfut-host-config"
|
||||||
version = "0.1.0"
|
version = "0.1.0"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"windows-sys 0.59.0",
|
"openfut-adapter-fifa17",
|
||||||
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "openfut-http"
|
||||||
|
version = "0.1.0"
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "openfut-identity"
|
||||||
|
version = "0.1.0"
|
||||||
|
dependencies = [
|
||||||
|
"parking_lot",
|
||||||
|
"serde",
|
||||||
|
"serde_json",
|
||||||
|
"tempfile",
|
||||||
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "openfut-import-fifa17"
|
||||||
|
version = "0.1.0"
|
||||||
|
dependencies = [
|
||||||
|
"anyhow",
|
||||||
|
"openfut-adapter-fifa17",
|
||||||
|
"openfut-core",
|
||||||
|
"openfut-identity",
|
||||||
|
"serde",
|
||||||
|
"serde_json",
|
||||||
|
"sqlx",
|
||||||
|
"tempfile",
|
||||||
|
"tokio",
|
||||||
|
"uuid",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
@@ -3196,11 +3266,73 @@ dependencies = [
|
|||||||
"dirs",
|
"dirs",
|
||||||
"eframe",
|
"eframe",
|
||||||
"egui",
|
"egui",
|
||||||
|
"openfut-common",
|
||||||
|
"parking_lot",
|
||||||
"serde",
|
"serde",
|
||||||
"serde_json",
|
"serde_json",
|
||||||
"tokio",
|
"tokio",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "openfut-lsx"
|
||||||
|
version = "0.1.0"
|
||||||
|
dependencies = [
|
||||||
|
"aes",
|
||||||
|
"parking_lot",
|
||||||
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "openfut-protocol-blaze"
|
||||||
|
version = "0.1.0"
|
||||||
|
dependencies = [
|
||||||
|
"serde_json",
|
||||||
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "openfut-redirector-host"
|
||||||
|
version = "0.1.0"
|
||||||
|
dependencies = [
|
||||||
|
"openfut-adapter-fifa17",
|
||||||
|
"openfut-host-config",
|
||||||
|
"openfut-http",
|
||||||
|
"openfut-tls",
|
||||||
|
"openssl",
|
||||||
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "openfut-roster-host"
|
||||||
|
version = "0.1.0"
|
||||||
|
dependencies = [
|
||||||
|
"openfut-adapter-fifa17",
|
||||||
|
"openfut-host-config",
|
||||||
|
"openfut-http",
|
||||||
|
"openfut-tls",
|
||||||
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "openfut-tls"
|
||||||
|
version = "0.1.0"
|
||||||
|
dependencies = [
|
||||||
|
"openssl",
|
||||||
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "openfut-utas-host"
|
||||||
|
version = "0.1.0"
|
||||||
|
dependencies = [
|
||||||
|
"axum",
|
||||||
|
"openfut-adapter-fifa17",
|
||||||
|
"openfut-core",
|
||||||
|
"openfut-http",
|
||||||
|
"openfut-identity",
|
||||||
|
"parking_lot",
|
||||||
|
"rand",
|
||||||
|
"reqwest",
|
||||||
|
"serde_json",
|
||||||
|
"sqlx",
|
||||||
|
"tokio",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "openssl"
|
name = "openssl"
|
||||||
version = "0.10.81"
|
version = "0.10.81"
|
||||||
@@ -3232,6 +3364,15 @@ version = "0.2.1"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "7c87def4c32ab89d880effc9e097653c8da5d6ef28e6b539d313baaacfbafcbe"
|
checksum = "7c87def4c32ab89d880effc9e097653c8da5d6ef28e6b539d313baaacfbafcbe"
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "openssl-src"
|
||||||
|
version = "300.6.1+3.6.3"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "46eb8fb9fb3b61ce1c0f8a026c4c1a0714d3a9e138e7fbde78753ce2babc3846"
|
||||||
|
dependencies = [
|
||||||
|
"cc",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "openssl-sys"
|
name = "openssl-sys"
|
||||||
version = "0.9.117"
|
version = "0.9.117"
|
||||||
@@ -3240,6 +3381,7 @@ checksum = "b47e7e6bb2c38cd930d25a23b40fa52e068c10e85f3e03a7f5ba5aaca5713695"
|
|||||||
dependencies = [
|
dependencies = [
|
||||||
"cc",
|
"cc",
|
||||||
"libc",
|
"libc",
|
||||||
|
"openssl-src",
|
||||||
"pkg-config",
|
"pkg-config",
|
||||||
"vcpkg",
|
"vcpkg",
|
||||||
]
|
]
|
||||||
@@ -3680,8 +3822,8 @@ dependencies = [
|
|||||||
"once_cell",
|
"once_cell",
|
||||||
"percent-encoding",
|
"percent-encoding",
|
||||||
"pin-project-lite",
|
"pin-project-lite",
|
||||||
"rustls",
|
"rustls 0.21.12",
|
||||||
"rustls-pemfile",
|
"rustls-pemfile 1.0.4",
|
||||||
"serde",
|
"serde",
|
||||||
"serde_json",
|
"serde_json",
|
||||||
"serde_urlencoded",
|
"serde_urlencoded",
|
||||||
@@ -3689,7 +3831,7 @@ dependencies = [
|
|||||||
"system-configuration",
|
"system-configuration",
|
||||||
"tokio",
|
"tokio",
|
||||||
"tokio-native-tls",
|
"tokio-native-tls",
|
||||||
"tokio-rustls",
|
"tokio-rustls 0.24.1",
|
||||||
"tower-service",
|
"tower-service",
|
||||||
"url",
|
"url",
|
||||||
"wasm-bindgen",
|
"wasm-bindgen",
|
||||||
@@ -3828,10 +3970,26 @@ checksum = "3f56a14d1f48b391359b22f731fd4bd7e43c97f3c50eee276f3aa09c94784d3e"
|
|||||||
dependencies = [
|
dependencies = [
|
||||||
"log",
|
"log",
|
||||||
"ring 0.17.14",
|
"ring 0.17.14",
|
||||||
"rustls-webpki",
|
"rustls-webpki 0.101.7",
|
||||||
"sct",
|
"sct",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "rustls"
|
||||||
|
version = "0.23.43"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "0283386ce02abc0151e1761d08802dfe86c173b0b494af5cbc086574e453da06"
|
||||||
|
dependencies = [
|
||||||
|
"aws-lc-rs",
|
||||||
|
"log",
|
||||||
|
"once_cell",
|
||||||
|
"ring 0.17.14",
|
||||||
|
"rustls-pki-types",
|
||||||
|
"rustls-webpki 0.103.13",
|
||||||
|
"subtle",
|
||||||
|
"zeroize",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "rustls-pemfile"
|
name = "rustls-pemfile"
|
||||||
version = "1.0.4"
|
version = "1.0.4"
|
||||||
@@ -3841,6 +3999,24 @@ dependencies = [
|
|||||||
"base64 0.21.7",
|
"base64 0.21.7",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "rustls-pemfile"
|
||||||
|
version = "2.2.0"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "dce314e5fee3f39953d46bb63bb8a46d40c2f8fb7cc5a3b6cab2bde9721d6e50"
|
||||||
|
dependencies = [
|
||||||
|
"rustls-pki-types",
|
||||||
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "rustls-pki-types"
|
||||||
|
version = "1.15.1"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "2f4925028c7eb5d1fcdaf196971378ed9d2c1c4efc7dc5d011256f76c99c0a96"
|
||||||
|
dependencies = [
|
||||||
|
"zeroize",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "rustls-webpki"
|
name = "rustls-webpki"
|
||||||
version = "0.101.7"
|
version = "0.101.7"
|
||||||
@@ -3851,6 +4027,18 @@ dependencies = [
|
|||||||
"untrusted 0.9.0",
|
"untrusted 0.9.0",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "rustls-webpki"
|
||||||
|
version = "0.103.13"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "61c429a8649f110dddef65e2a5ad240f747e85f7758a6bccc7e5777bd33f756e"
|
||||||
|
dependencies = [
|
||||||
|
"aws-lc-rs",
|
||||||
|
"ring 0.17.14",
|
||||||
|
"rustls-pki-types",
|
||||||
|
"untrusted 0.9.0",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "rustversion"
|
name = "rustversion"
|
||||||
version = "1.0.23"
|
version = "1.0.23"
|
||||||
@@ -4037,15 +4225,17 @@ version = "0.1.0"
|
|||||||
dependencies = [
|
dependencies = [
|
||||||
"anyhow",
|
"anyhow",
|
||||||
"blaze-proto",
|
"blaze-proto",
|
||||||
"blaze-ssl-async",
|
|
||||||
"bytes",
|
"bytes",
|
||||||
"chrono",
|
"chrono",
|
||||||
"futures-util",
|
"futures-util",
|
||||||
"hex",
|
"hex",
|
||||||
|
"rustls 0.23.43",
|
||||||
|
"rustls-pemfile 2.2.0",
|
||||||
"serde",
|
"serde",
|
||||||
"serde_json",
|
"serde_json",
|
||||||
"tdf",
|
"tdf",
|
||||||
"tokio",
|
"tokio",
|
||||||
|
"tokio-rustls 0.26.4",
|
||||||
"tokio-util",
|
"tokio-util",
|
||||||
"toml",
|
"toml",
|
||||||
"tracing",
|
"tracing",
|
||||||
@@ -4063,6 +4253,12 @@ dependencies = [
|
|||||||
"digest",
|
"digest",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "sha1_smol"
|
||||||
|
version = "1.0.1"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "bbfa15b3dddfee50a0fff136974b3e1bde555604ba463834a7eb7deb6417705d"
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "sha2"
|
name = "sha2"
|
||||||
version = "0.10.9"
|
version = "0.10.9"
|
||||||
@@ -4329,8 +4525,8 @@ dependencies = [
|
|||||||
"once_cell",
|
"once_cell",
|
||||||
"paste",
|
"paste",
|
||||||
"percent-encoding",
|
"percent-encoding",
|
||||||
"rustls",
|
"rustls 0.21.12",
|
||||||
"rustls-pemfile",
|
"rustls-pemfile 1.0.4",
|
||||||
"serde",
|
"serde",
|
||||||
"serde_json",
|
"serde_json",
|
||||||
"sha2",
|
"sha2",
|
||||||
@@ -4784,27 +4980,6 @@ version = "0.1.1"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "1f3ccbac311fea05f86f61904b462b55fb3df8837a366dfc601a0161d0532f20"
|
checksum = "1f3ccbac311fea05f86f61904b462b55fb3df8837a366dfc601a0161d0532f20"
|
||||||
|
|
||||||
[[package]]
|
|
||||||
name = "tls_codec"
|
|
||||||
version = "0.4.2"
|
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
|
||||||
checksum = "0de2e01245e2bb89d6f05801c564fa27624dbd7b1846859876c7dad82e90bf6b"
|
|
||||||
dependencies = [
|
|
||||||
"tls_codec_derive",
|
|
||||||
"zeroize",
|
|
||||||
]
|
|
||||||
|
|
||||||
[[package]]
|
|
||||||
name = "tls_codec_derive"
|
|
||||||
version = "0.4.2"
|
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
|
||||||
checksum = "2d2e76690929402faae40aebdda620a2c0e25dd6d3b9afe48867dfd95991f4bd"
|
|
||||||
dependencies = [
|
|
||||||
"proc-macro2",
|
|
||||||
"quote",
|
|
||||||
"syn 2.0.119",
|
|
||||||
]
|
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "tokio"
|
name = "tokio"
|
||||||
version = "1.53.1"
|
version = "1.53.1"
|
||||||
@@ -4849,7 +5024,17 @@ version = "0.24.1"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "c28327cf380ac148141087fbfb9de9d7bd4e84ab5d2c28fbc911d753de8a7081"
|
checksum = "c28327cf380ac148141087fbfb9de9d7bd4e84ab5d2c28fbc911d753de8a7081"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"rustls",
|
"rustls 0.21.12",
|
||||||
|
"tokio",
|
||||||
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "tokio-rustls"
|
||||||
|
version = "0.26.4"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "1729aa945f29d91ba541258c8df89027d5792d85a8841fb65e8bf0f4ede4ef61"
|
||||||
|
dependencies = [
|
||||||
|
"rustls 0.23.43",
|
||||||
"tokio",
|
"tokio",
|
||||||
]
|
]
|
||||||
|
|
||||||
@@ -5214,6 +5399,7 @@ dependencies = [
|
|||||||
"getrandom 0.4.3",
|
"getrandom 0.4.3",
|
||||||
"js-sys",
|
"js-sys",
|
||||||
"serde_core",
|
"serde_core",
|
||||||
|
"sha1_smol",
|
||||||
"wasm-bindgen",
|
"wasm-bindgen",
|
||||||
]
|
]
|
||||||
|
|
||||||
@@ -6152,18 +6338,6 @@ version = "0.13.2"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "ea6fc2961e4ef194dcbfe56bb845534d0dc8098940c7e5c012a258bfec6701bd"
|
checksum = "ea6fc2961e4ef194dcbfe56bb845534d0dc8098940c7e5c012a258bfec6701bd"
|
||||||
|
|
||||||
[[package]]
|
|
||||||
name = "x509-cert"
|
|
||||||
version = "0.2.5"
|
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
|
||||||
checksum = "1301e935010a701ae5f8655edc0ad17c44bad3ac5ce8c39185f75453b720ae94"
|
|
||||||
dependencies = [
|
|
||||||
"const-oid",
|
|
||||||
"der",
|
|
||||||
"spki",
|
|
||||||
"tls_codec",
|
|
||||||
]
|
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "xcursor"
|
name = "xcursor"
|
||||||
version = "0.3.11"
|
version = "0.3.11"
|
||||||
@@ -6388,20 +6562,6 @@ name = "zeroize"
|
|||||||
version = "1.9.0"
|
version = "1.9.0"
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "e13c156562582aa81c60cb29407084cdb54c4164760106ab78e6c5b0858cf64e"
|
checksum = "e13c156562582aa81c60cb29407084cdb54c4164760106ab78e6c5b0858cf64e"
|
||||||
dependencies = [
|
|
||||||
"zeroize_derive",
|
|
||||||
]
|
|
||||||
|
|
||||||
[[package]]
|
|
||||||
name = "zeroize_derive"
|
|
||||||
version = "1.5.0"
|
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
|
||||||
checksum = "3c50655cbb0fe3fc43170059e702f1ce5e19b84cec58dc87b037a09935c2f328"
|
|
||||||
dependencies = [
|
|
||||||
"proc-macro2",
|
|
||||||
"quote",
|
|
||||||
"syn 2.0.119",
|
|
||||||
]
|
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "zerotrie"
|
name = "zerotrie"
|
||||||
|
|||||||
+22
-1
@@ -2,9 +2,30 @@
|
|||||||
resolver = "2"
|
resolver = "2"
|
||||||
members = [
|
members = [
|
||||||
"openfut-core",
|
"openfut-core",
|
||||||
|
"openfut-protocol-blaze",
|
||||||
|
"openfut-adapter-fifa17",
|
||||||
|
"openfut-blaze-host",
|
||||||
|
"openfut-host-config",
|
||||||
|
"openfut-http",
|
||||||
|
"openfut-tls",
|
||||||
|
"openfut-redirector-host",
|
||||||
|
"openfut-roster-host",
|
||||||
|
"openfut-utas-host",
|
||||||
|
"openfut-identity",
|
||||||
|
"openfut-import-fifa17",
|
||||||
"openfut-bridge",
|
"openfut-bridge",
|
||||||
"openfut-launcher",
|
"openfut-launcher",
|
||||||
"openfut-launcher/openfut-hook",
|
# The two companion services the launcher used to shell out to Python for.
|
||||||
|
"openfut-lsx",
|
||||||
|
"openfut-autopatch",
|
||||||
"fifa-blaze/crates/blaze-proto",
|
"fifa-blaze/crates/blaze-proto",
|
||||||
"fifa-blaze/crates/server",
|
"fifa-blaze/crates/server",
|
||||||
]
|
]
|
||||||
|
# openfut-hook is a Windows-only version.dll proxy injected into the FIFA client.
|
||||||
|
# It MUST build with its own [profile.release] (panic="abort" — unwinding across
|
||||||
|
# the DllMain/FFI boundary into the game process is UB — plus strip + opt-level="s").
|
||||||
|
# Cargo ignores a non-root member's profile and forbids per-package `panic` overrides,
|
||||||
|
# so the hook is deliberately EXCLUDED from this workspace to build as its own root
|
||||||
|
# (this also lands its artifact in openfut-hook/target/, matching the launcher's
|
||||||
|
# config.rs default hook_dll_path). Build: cargo build --release --target x86_64-pc-windows-gnu.
|
||||||
|
exclude = ["openfut-launcher/openfut-hook"]
|
||||||
|
|||||||
@@ -1,5 +1,9 @@
|
|||||||
# OpenFUT
|
# OpenFUT
|
||||||
|
|
||||||
|
> ⚠️ **Status — see [`docs/PROJECT_STATE.md`](./docs/PROJECT_STATE.md) (canonical).** The working, actively-developed target is **FIFA 17**, not FIFA 23. Everything below this banner describes the **superseded FIFA 23 `bridge` lineage** and is kept for historical context.
|
||||||
|
>
|
||||||
|
> **Run the server (canonical):** `cd fifa17-recon/docker/fifa17-python && docker compose up -d` — see [`fifa17-recon/FUT-RUNBOOK.md`](./fifa17-recon/FUT-RUNBOOK.md). `openfut-core` is the shared offline backend (still used by the FIFA 17 path); `openfut-bridge` is the retired FIFA 23 integration.
|
||||||
|
|
||||||
**Offline Ultimate Team — like SPT, but for FIFA 23.**
|
**Offline Ultimate Team — like SPT, but for FIFA 23.**
|
||||||
|
|
||||||
OpenFUT replaces EA's retired FUT servers with a fully offline, single-player backend. You own FIFA 23 legitimately. You just want to keep playing after EA shut down the servers.
|
OpenFUT replaces EA's retired FUT servers with a fully offline, single-player backend. You own FIFA 23 legitimately. You just want to keep playing after EA shut down the servers.
|
||||||
|
|||||||
@@ -0,0 +1,93 @@
|
|||||||
|
# ============================================================================
|
||||||
|
# ⚠️ LEGACY (FIFA 23 lineage). This compose runs core + bridge for the
|
||||||
|
# superseded FIFA 23 direction. It is NOT the canonical server bring-up.
|
||||||
|
#
|
||||||
|
# Canonical server (FIFA 17):
|
||||||
|
# cd fifa17-recon/docker/fifa17-python && docker compose up -d
|
||||||
|
# (runbook: fifa17-recon/FUT-RUNBOOK.md)
|
||||||
|
#
|
||||||
|
# `core` (openfut-core) IS still the shared, game-independent backend and is
|
||||||
|
# used by the FIFA 17 UTAS host (OPENFUT_CORE_URL). `bridge` (openfut-bridge)
|
||||||
|
# is the retired FIFA 23 integration, kept for reference.
|
||||||
|
# Status source of truth: docs/PROJECT_STATE.md
|
||||||
|
# ============================================================================
|
||||||
|
# OpenFUT server stack — offline FUT backend (Core) + FIFA proxy (Bridge).
|
||||||
|
#
|
||||||
|
# Bring up: docker compose up -d
|
||||||
|
# Tear down: docker compose down (keeps data/captures volumes)
|
||||||
|
# Wipe state: docker compose down -v (also drops volumes)
|
||||||
|
# Rebuild: docker compose build (or ./scripts/registry.sh build)
|
||||||
|
# Logs: docker compose logs -f
|
||||||
|
#
|
||||||
|
# Images are pulled from / pushed to the Gitea container registry. Override the
|
||||||
|
# registry, namespace, or tag in .env (see .env.example). When REGISTRY is set,
|
||||||
|
# `up` pulls prebuilt images; the build: blocks let you rebuild locally too.
|
||||||
|
|
||||||
|
name: openfut
|
||||||
|
|
||||||
|
services:
|
||||||
|
core:
|
||||||
|
image: ${REGISTRY:-git.aleshym.co}/${NAMESPACE:-openfut}/openfut-core:${TAG:-latest}
|
||||||
|
build:
|
||||||
|
context: ./openfut-core
|
||||||
|
dockerfile: Dockerfile
|
||||||
|
restart: unless-stopped
|
||||||
|
environment:
|
||||||
|
LISTEN_ADDR: 0.0.0.0:8080
|
||||||
|
DATABASE_URL: sqlite:///app/db/openfut.db
|
||||||
|
DATA_DIR: /app/data
|
||||||
|
RUST_LOG: ${CORE_LOG:-openfut_core=info,tower_http=info}
|
||||||
|
volumes:
|
||||||
|
- core-db:/app/db
|
||||||
|
# Bound to localhost by default — the bridge reaches core over the internal
|
||||||
|
# network, so core need not be world-exposed. Set CORE_PUBLISH=0.0.0.0 in
|
||||||
|
# .env if you want to hit the REST API directly from other hosts.
|
||||||
|
ports:
|
||||||
|
- "${CORE_PUBLISH:-127.0.0.1}:8080:8080"
|
||||||
|
networks:
|
||||||
|
- openfut
|
||||||
|
healthcheck:
|
||||||
|
test: ["CMD", "curl", "-fsS", "http://127.0.0.1:8080/health"]
|
||||||
|
interval: 15s
|
||||||
|
timeout: 4s
|
||||||
|
retries: 5
|
||||||
|
start_period: 10s
|
||||||
|
|
||||||
|
bridge:
|
||||||
|
image: ${REGISTRY:-git.aleshym.co}/${NAMESPACE:-openfut}/openfut-bridge:${TAG:-latest}
|
||||||
|
build:
|
||||||
|
context: ./openfut-bridge
|
||||||
|
dockerfile: Dockerfile
|
||||||
|
restart: unless-stopped
|
||||||
|
depends_on:
|
||||||
|
core:
|
||||||
|
condition: service_healthy
|
||||||
|
environment:
|
||||||
|
BRIDGE_LISTEN_ADDR: 0.0.0.0:8443
|
||||||
|
CORE_URL: http://core:8080
|
||||||
|
CAPTURES_DIR: /app/captures
|
||||||
|
PLACEHOLDER_MODE: ${PLACEHOLDER_MODE:-true}
|
||||||
|
TLS_ENABLED: "true"
|
||||||
|
RUST_LOG: ${BRIDGE_LOG:-openfut_bridge=info,tower_http=info}
|
||||||
|
volumes:
|
||||||
|
- bridge-captures:/app/captures
|
||||||
|
# The FIFA client connects here — publish on all interfaces by default so
|
||||||
|
# LAN clients (e.g. 10.10.0.0/24) can reach it.
|
||||||
|
ports:
|
||||||
|
- "${BRIDGE_PUBLISH:-0.0.0.0}:8443:8443"
|
||||||
|
networks:
|
||||||
|
- openfut
|
||||||
|
healthcheck:
|
||||||
|
test: ["CMD", "curl", "-fsSk", "https://127.0.0.1:8443/_bridge/health"]
|
||||||
|
interval: 15s
|
||||||
|
timeout: 4s
|
||||||
|
retries: 5
|
||||||
|
start_period: 8s
|
||||||
|
|
||||||
|
networks:
|
||||||
|
openfut:
|
||||||
|
driver: bridge
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
core-db:
|
||||||
|
bridge-captures:
|
||||||
@@ -1,250 +0,0 @@
|
|||||||
# OpenFUT — Direction Document
|
|
||||||
*The pivot: FUT lives in the app; FIFA 23 is the match renderer.*
|
|
||||||
*Supersedes the Blaze-backend approach as the primary plan. Last updated 2026-06-30.*
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 1. Goal (revised)
|
|
||||||
|
|
||||||
Deliver an **intuitive way to play a FUT-style experience with FIFA 23**, where:
|
|
||||||
|
|
||||||
- The entire **FUT experience** — cards, squads, packs, SBCs, coins, chemistry,
|
|
||||||
progression — lives in a **custom app** (web UI or desktop) built on the
|
|
||||||
already-complete OpenFUT Core economy backend.
|
|
||||||
- **FIFA 23 is demoted to a match renderer.** Its only job is to play a
|
|
||||||
single-player match using the squad the app built. No FUT mode, no online, no
|
|
||||||
Blaze, no EA servers.
|
|
||||||
|
|
||||||
This deliberately drops in-game FUT cards/UI (they live in the app) in exchange
|
|
||||||
for a project that **converges** instead of being gated behind months of
|
|
||||||
backend reverse-engineering.
|
|
||||||
|
|
||||||
### Why this replaces the backend plan
|
|
||||||
|
|
||||||
The status review confirmed the backend route (faking EA's online stack) is
|
|
||||||
blocked at an upstream in-process EbisuSDK gate, with Blaze/Fire2 unconfirmed
|
|
||||||
beyond it — realistically 3–6 months of expert RE that may not converge. The
|
|
||||||
app-centric route sidesteps **every** wall in that review by never making FIFA's
|
|
||||||
own FUT mode run.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 2. Base mode: Career, not Kick-Off
|
|
||||||
|
|
||||||
**Career mode is the base.** Reasons:
|
|
||||||
|
|
||||||
- FLE's live-editing API (`EditDBTableField`, Freeze Lineup) is **confirmed to
|
|
||||||
work in career mode** and explicitly does NOT work in FUT/online modes.
|
|
||||||
- Career already provides the FUT-shaped scaffolding we'd otherwise fake:
|
|
||||||
persistent club, a fixture schedule, recorded results, progression across a
|
|
||||||
season.
|
|
||||||
- **Match results are written into the career DB**, making result capture a DB
|
|
||||||
read rather than a fragile live-memory grab.
|
|
||||||
|
|
||||||
**Kick-Off is the prototype sandbox.** Use it first to prove squad injection
|
|
||||||
works with nothing to corrupt (no save to break), then move the real loop onto
|
|
||||||
career. Run the foundational injection test in BOTH.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 3. Core architecture: the bidirectional FLE bridge
|
|
||||||
|
|
||||||
The backbone is a **bidirectional channel between the app and a resident FLE Lua
|
|
||||||
script running inside the game.** Everything else is messages over this channel.
|
|
||||||
|
|
||||||
```
|
|
||||||
Custom App (FUT experience)
|
|
||||||
│ squad push ──────────────► ┌─────────────────────────────┐
|
|
||||||
│ │ Resident FLE Lua script │
|
|
||||||
│ ◄────────── game state │ (inside FIFA 23, career) │
|
|
||||||
│ ◄────────── match result │ - reads game state │
|
|
||||||
└────────────────────────────► │ - applies squad live │
|
|
||||||
(file-watch or local socket) │ - reads results from DB │
|
|
||||||
└─────────────────────────────┘
|
|
||||||
│
|
|
||||||
FIFA 23 plays the match
|
|
||||||
```
|
|
||||||
|
|
||||||
Three message types over the bridge:
|
|
||||||
|
|
||||||
1. **App → Game: squad push.** The app's chosen XI + stats applied LIVE via
|
|
||||||
`EditDBTableField`, replicating whatever DB write FLE's "Freeze Lineup"
|
|
||||||
feature performs (see `docs/foundational-xi-injection-test.md` — the exact
|
|
||||||
field(s) are found by diffing, not assumed). No restart, no
|
|
||||||
file-copy-reload. (File-load remains a fallback.)
|
|
||||||
|
|
||||||
2. **Game → App: game state.** The resident script polls the game's current
|
|
||||||
screen/menu state and reports "safe to apply" vs "not safe", driving a smart
|
|
||||||
Apply button in the app (see §5).
|
|
||||||
|
|
||||||
3. **Game → App: match result.** After full-time, the script reads the result
|
|
||||||
from the career DB and pushes score/scorers to the app, which awards
|
|
||||||
coins/progression. (Manual entry is the baseline fallback.)
|
|
||||||
|
|
||||||
The bridge transport can be a watched file the in-game Lua polls, or a local
|
|
||||||
socket — decided in build (see §7). Either way the *game keeps running*; a file,
|
|
||||||
if used, is just the message channel, not a reload.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 4. Tiered mod scope
|
|
||||||
|
|
||||||
Build in tiers matched to risk. The core tier is all the SAME kind of DB write,
|
|
||||||
so it lands together once squad injection works.
|
|
||||||
|
|
||||||
### Tier 1 — Core writes (ride the same live DB-edit mechanism)
|
|
||||||
- **Squad / custom XI** — the load-bearing primitive (Freeze Lineup's
|
|
||||||
underlying write, replicated via script — see §6).
|
|
||||||
- **Player stats as "cards"** — card tiers, in-form versions, SBC upgrades all
|
|
||||||
expressed as written attribute values.
|
|
||||||
- **Chemistry as stat adjustment** — app computes FUT chemistry, applies it as
|
|
||||||
small stat bumps when writing players in (no in-game chem UI; that's in the app).
|
|
||||||
- **Appearance / identity** — kits, names, team assignment, so the club looks
|
|
||||||
like your club on the pitch.
|
|
||||||
- **Formation / tactics** — squad structure carries the app's build onto the pitch.
|
|
||||||
|
|
||||||
### Tier 2 — Confirm-then-add
|
|
||||||
- **Match difficulty per game** — to drive a Squad-Battles-style "this opponent is
|
|
||||||
World Class". Settable in-game trivially; programmatic drive needs confirming.
|
|
||||||
- **Match rules / modifiers** (half length, etc.) — for app-defined challenges.
|
|
||||||
|
|
||||||
### Tier 3 — Result capture (manual baseline + automated stretch)
|
|
||||||
- **Manual:** user enters the score in the app after the match. Zero RE, ships
|
|
||||||
first.
|
|
||||||
- **Automated:** resident script reads the career-DB result (or, for Kick-Off,
|
|
||||||
reads the in-match score from memory at full-time — precedent exists: the
|
|
||||||
CM cheat table's `export_season_stats.lua` already reads goals/cards from
|
|
||||||
memory via known offsets). Push to app → auto-award progression.
|
|
||||||
|
|
||||||
### Out of scope (stays in the app, by design)
|
|
||||||
- In-game FUT cards, FUT menus, pack-opening animation, chemistry board, FUT
|
|
||||||
presentation. The app is where it looks/feels like FUT.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 5. The smart Apply button (state-aware)
|
|
||||||
|
|
||||||
Live DB edits only "stick" in safe menu states (the in-game "Edit Player" screen,
|
|
||||||
for example, overwrites edits). So the bridge reads game state and gates applying:
|
|
||||||
|
|
||||||
- Resident Lua script polls the game's current-screen value (a few Hz),
|
|
||||||
classifies **safe / not safe**, reports to the app.
|
|
||||||
- App's **Apply button is enabled only when the script confirms a safe state**
|
|
||||||
(squad hub, main menu); greyed otherwise.
|
|
||||||
- **Safe-by-default-OFF:** unknown state → button greyed → never a risky write.
|
|
||||||
Expand the known-safe list incrementally as states are confirmed.
|
|
||||||
- **v2 (more seamless):** instead of greying, the app always lets you click and
|
|
||||||
the script **queues** the apply, executing the moment a safe state is entered,
|
|
||||||
then confirms back. Greying is v1; queue-and-apply is v2.
|
|
||||||
|
|
||||||
`IsInCM()` is a confirmed state-read; the specific screen-state address + the
|
|
||||||
value→screen mapping is one-time reconnaissance (same technique as result reading).
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 6. What's confirmed vs what needs validating
|
|
||||||
|
|
||||||
**Confirmed (from FLE's own Lua API docs/wiki, checked 2026-06-30):**
|
|
||||||
- FLE live-edits the running career DB without restart, via `EditDBTableField`
|
|
||||||
(real signature: `EditDBTableField(cell)` where `cell = row["fieldname"]`
|
|
||||||
with `.value` mutated first — not the table/index/field/value form an
|
|
||||||
earlier draft of this doc assumed).
|
|
||||||
- FLE reads game state via `IsInCM()`.
|
|
||||||
- A `MEMORY` Lua class exists (`ReadInt`/`WriteInt`/`ReadMultilevelPointer`/
|
|
||||||
etc.) for arbitrary process memory — confirms the result-reading fallback
|
|
||||||
in §4 Tier 3 is a real, documented capability, not just cheat-table analogy.
|
|
||||||
- `GetPlayersStats()` is a documented function returning per-player
|
|
||||||
goals/assists/cards/etc. — a better confirmed path for match-result capture
|
|
||||||
than raw memory offsets.
|
|
||||||
- **Freeze Lineup** (Formation Editor → arrange XI → tick "Freeze Lineup" →
|
|
||||||
`Data → Save`) is FLE's actual documented mechanism for forcing a starting
|
|
||||||
XI in career mode. This **replaces** "selection bias" below.
|
|
||||||
- OpenFUT Core (economy) is complete and tested.
|
|
||||||
|
|
||||||
**Walked back — not actually confirmed:**
|
|
||||||
- "Selection bias forces specific players into the starting XI" — no such
|
|
||||||
field appears anywhere in FLE's documented Lua API or its own example
|
|
||||||
scripts. This was an unverified assumption carried over from general FIFA
|
|
||||||
modding precedent (other titles), not anything checked against FLE/FIFA 23.
|
|
||||||
See `docs/foundational-xi-injection-test.md` for the corrected plan, which
|
|
||||||
uses Freeze Lineup instead.
|
|
||||||
|
|
||||||
**Needs validating (the foundational tests — see §7):**
|
|
||||||
- Whether Freeze Lineup actually holds into a played match (FLE's wiki
|
|
||||||
documents the feature but not a live-match test of it).
|
|
||||||
- What DB table/field Freeze Lineup's `Data → Save` actually writes — it's
|
|
||||||
GUI-only and undocumented at that level; finding it is part of the
|
|
||||||
foundational test.
|
|
||||||
- Whether that write can be replicated by a script (`EditDBTableField`) well
|
|
||||||
enough to drive it from an EXTERNAL trigger, not just the Formation Editor
|
|
||||||
UI — required for the app↔game bridge.
|
|
||||||
- The app↔game bridge transport (file-watch vs socket) works cleanly under the
|
|
||||||
run setup.
|
|
||||||
- The screen-state address + safe/not-safe classification (FLE's `Events`
|
|
||||||
API page exists in the wiki index but its content is currently empty/
|
|
||||||
undocumented — this is more open than previously assumed).
|
|
||||||
- Result read-back from the career DB after a match.
|
|
||||||
|
|
||||||
**Standing caveat:** the whole stack rides on **EAAC staying neutralized**
|
|
||||||
(FLE's fake-launcher bypass). If a game update re-enables it, hooks fail. Keep
|
|
||||||
game updates off; confirm neutralized state each session.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 7. Build order / next steps
|
|
||||||
|
|
||||||
Each is a bounded, verifiable step. Do them in order; later ones depend on
|
|
||||||
earlier answers.
|
|
||||||
|
|
||||||
1. **FOUNDATIONAL TEST — live custom XI in career.** Confirm Freeze Lineup
|
|
||||||
holds into a played match, reverse-engineer the DB write it makes, then
|
|
||||||
replicate that write from a script so it can be triggered externally
|
|
||||||
instead of through the Formation Editor UI. See
|
|
||||||
`docs/foundational-xi-injection-test.md` for the full procedure. *Done =
|
|
||||||
a script-driven write produces a match that fields the squad you
|
|
||||||
specified.* Everything rests on this.
|
|
||||||
|
|
||||||
2. **Pick the bridge transport.** Decide file-watch vs local socket for app↔game
|
|
||||||
messaging; implement the minimal app→game squad push. *Done = app sends a
|
|
||||||
squad, the resident script receives and applies it.*
|
|
||||||
|
|
||||||
3. **Game-state reader + smart Apply.** Find the screen-state address, classify
|
|
||||||
safe/not-safe, expose to the app, gate the Apply button. *Done = button greys
|
|
||||||
when you enter a match/edit screen, enables in the squad hub.*
|
|
||||||
|
|
||||||
4. **Result read-back.** Read the career-DB match result post-game, push to app,
|
|
||||||
award progression. Manual entry ships alongside as the fallback. *Done = app
|
|
||||||
updates coins from a played match.*
|
|
||||||
|
|
||||||
5. **Tier 1 breadth.** Extend the squad push to carry stats, appearance,
|
|
||||||
formation (same write mechanism). *Done = the club looks and plays like the
|
|
||||||
app's build.*
|
|
||||||
|
|
||||||
6. **Tier 2 + economy loop polish.** Difficulty drive, challenges, and the full
|
|
||||||
pack → SBC → squad → match → reward loop closed end-to-end.
|
|
||||||
|
|
||||||
### Decision still open
|
|
||||||
- **App form factor:** web UI vs desktop app. This affects the bridge transport
|
|
||||||
(a desktop app can hold a local socket more naturally; a web UI leans toward a
|
|
||||||
small local helper/file-watch). Decide before step 2.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 8. Provenance
|
|
||||||
|
|
||||||
Clean-room throughout. This route relies on FLE's documented public API and the
|
|
||||||
game's own supported career mode — no EA backend, no Blaze, and nothing derived
|
|
||||||
from leaked EA source. The earlier backend RE remains clean-room and is preserved
|
|
||||||
as a spec artifact; it is simply no longer the primary path.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 9. One-paragraph summary
|
|
||||||
|
|
||||||
OpenFUT becomes a **FUT companion app that uses FIFA 23 as a match engine.** The
|
|
||||||
app owns the entire FUT experience; a resident FLE Lua script in career mode
|
|
||||||
applies the app's squad live (no restart), reports game state to drive a safe
|
|
||||||
Apply button, and reads match results back to feed progression. This sidesteps
|
|
||||||
every backend wall, runs on confirmed FLE capabilities, builds on the finished
|
|
||||||
economy core, and delivers the intuitive, offline, FUT-flavored loop that is the
|
|
||||||
actual goal.
|
|
||||||
@@ -1,108 +0,0 @@
|
|||||||
# FIFA 23 PC Startup Flow (Offline / Proton)
|
|
||||||
|
|
||||||
Observed via FLE log, hook log, and file inspection on 2026-06-26.
|
|
||||||
|
|
||||||
## Launch chain
|
|
||||||
|
|
||||||
```
|
|
||||||
umu-run / Steam → FIFA23.exe (via Proton/Wine)
|
|
||||||
│
|
|
||||||
├─ DLL load order (before entry point)
|
|
||||||
│ ntdll.dll, kernel32.dll, ws2_32.dll …
|
|
||||||
│ version.dll ← our hook DLL slot (loads here)
|
|
||||||
│ FIFALiveEditor.DLL ← injected by FLE launcher after ~100 ms
|
|
||||||
│
|
|
||||||
├─ anadius / LSX emulator (anadius64.dll)
|
|
||||||
│ Fakes EA App / Origin session
|
|
||||||
│ Reads HKLM\SOFTWARE\Wow6432Node\Origin\ClientPath
|
|
||||||
│ Writes AppData\Local\anadius\LSX emu\achievement-*.xml
|
|
||||||
│ Provides fake PersonaId=1144668899 / UserId=1000200030000
|
|
||||||
│
|
|
||||||
├─ EA Anti-Cheat (EAAntiCheat.GameServiceLauncher.exe)
|
|
||||||
│ Spawns as child; checks EAAntiCheat.cfg
|
|
||||||
│ Not active in offline/cracked builds (FakeEAACLauncher present)
|
|
||||||
│
|
|
||||||
└─ FIFA23.exe entry point
|
|
||||||
Frostbite engine init (BuildDate 2023-07-05, changelist 5417699)
|
|
||||||
Reads Data\initfs_Win32 ← Frostbite package manifest
|
|
||||||
Reads Data\layout.toc ← file-system layout
|
|
||||||
Reads Patch\initfs_Win32 ← patches on top of base
|
|
||||||
Reads Documents\FIFA 23\fifasetup.ini ← display settings
|
|
||||||
Reads Data\locale.ini ← language table
|
|
||||||
Reads Data\db_meta.xml (via FLE) ← DB schema for all tables
|
|
||||||
```
|
|
||||||
|
|
||||||
## Phase timing (observed, single machine)
|
|
||||||
|
|
||||||
| Phase | Time after launch | Trigger |
|
|
||||||
|------------------------------|-------------------|----------------------------------|
|
|
||||||
| DLL load + FLE injection | 0 – 0.3 s | OS loader |
|
|
||||||
| Engine + DirectX init | 0.3 – 5 s | FIFA23 entry point |
|
|
||||||
| "Press any key" splash | ~5 s | First rendered frame |
|
|
||||||
| Main menu | ~25 s | After key press |
|
|
||||||
| FUT mode entry (attempted) | user-driven | User selects FUT tile |
|
|
||||||
| Network calls to EA services | at FUT entry | DirtySDK / EAWebKit |
|
|
||||||
|
|
||||||
## Files read at startup (observed)
|
|
||||||
|
|
||||||
| File | Format | Purpose |
|
|
||||||
|------|--------|---------|
|
|
||||||
| `Data/initfs_Win32` | Frostbite pkg | Base asset manifest |
|
|
||||||
| `Data/layout.toc` | Frostbite TOC | File layout index |
|
|
||||||
| `Patch/initfs_Win32` | Frostbite pkg | Patch layer |
|
|
||||||
| `Data/locale.ini` | INI | String localisation |
|
|
||||||
| `Data/db_meta.xml` | XML | DB schema (loaded by FLE) |
|
|
||||||
| `Data/id_map.json` | JSON | Player/team ID→name map |
|
|
||||||
| `Data/char_conv.json` | JSON | Character conversion table |
|
|
||||||
| `Documents/FIFA 23/fifasetup.ini` | INI | Display/audio settings |
|
|
||||||
| `AppData/Local/Temp/FIFA 23/_replay0.bin` | binary | Replay buffer |
|
|
||||||
| `anadius.cfg` | VDF | Fake EA persona config |
|
|
||||||
| `AppData/Local/anadius/LSX emu/achievement-*.xml` | XML | Achievement state |
|
|
||||||
|
|
||||||
## Files written during a session (observed)
|
|
||||||
|
|
||||||
| File | When written | Content |
|
|
||||||
|------|-------------|---------|
|
|
||||||
| `Documents/FIFA 23/settings/Settings*` | Main menu reached | FBCHUNKS — controller/display prefs |
|
|
||||||
| `Documents/FIFA 23/settings/ProfileOptions` | Profile load | FBCHUNKS — 1.5 MB profile blob |
|
|
||||||
| `Documents/FIFA 23/filesystemcache/survey.state` | Startup | Empty state file |
|
|
||||||
| `Documents/FIFA 23/filesystemcache/atlPlayTimeJson/playtime_*.json` | Ongoing | Playtime tracking |
|
|
||||||
| `FIFA 23 Live Editor/config.json` | FLE ready | FLE settings (rewritten each session) |
|
|
||||||
| `Logs/log_DD-MM-YYYY.txt` | Throughout | FLE debug log |
|
|
||||||
|
|
||||||
## Save file formats
|
|
||||||
|
|
||||||
### FBCHUNKS (Frostbite chunk container)
|
|
||||||
- Magic: `46 42 43 48 55 4E 4B 53` (`FBCHUNKS`)
|
|
||||||
- Byte 8: version (01 seen)
|
|
||||||
- Offset 0x12: null-terminated label string (e.g. "Personal Settings 1", "Career - Player Progress 1")
|
|
||||||
- Remainder: compressed/binary chunk data — no public spec; requires Frostbite tooling to fully parse
|
|
||||||
- Tools: [Frosty Tool Suite](https://github.com/CadeEvs/FrostyToolSuite) can read/write these
|
|
||||||
|
|
||||||
### fifasetup.ini
|
|
||||||
- Plain `KEY = VALUE` ini, fully human-readable
|
|
||||||
- Safe to edit (display resolution, locale, vsync)
|
|
||||||
|
|
||||||
## Network calls at FUT entry (observed with iptables redirect)
|
|
||||||
|
|
||||||
Traffic pattern captured before changing strategy:
|
|
||||||
- Multiple TLS connections to port 443 (destination: EA servers, resolved as various EA IPs)
|
|
||||||
- TLS 1.3, AES-256-GCM (DirtySDK's copy of ProtoSSL, inline in FIFA23.exe)
|
|
||||||
- No SNI sent (DirtySDK does not set `server_name` extension)
|
|
||||||
- Connections originate from Wine/Proton network stack via Linux kernel TCP
|
|
||||||
|
|
||||||
Specific EA hostnames used (from openfut-bridge captures, not decoded from TLS):
|
|
||||||
- `fut.ea.com` (FUT API)
|
|
||||||
- `accounts.ea.com` (auth)
|
|
||||||
- `gateway.ea.com` (entitlements)
|
|
||||||
- `pin-river.data.ea.com` (telemetry)
|
|
||||||
|
|
||||||
## Key FLE Lua API hooks
|
|
||||||
|
|
||||||
FLE injects `FIFALiveEditor.DLL` and exposes a Lua engine that can:
|
|
||||||
- Read any in-memory DB table via `GetDBTableRows(tableName)`
|
|
||||||
- Write any cell via `EditDBTableField`
|
|
||||||
- Query career mode state via `IsInCM()`
|
|
||||||
- Get player/team names via `GetPlayerName`, `GetTeamName`
|
|
||||||
|
|
||||||
This is the primary safe integration path (see `fut-integration-options.md`).
|
|
||||||
@@ -1,191 +0,0 @@
|
|||||||
# Foundational test — live custom XI via Freeze Lineup
|
|
||||||
|
|
||||||
**Status: PENDING — test has not yet been run.**
|
|
||||||
|
|
||||||
This is build-order step 1 from `docs/direction.md`: the test everything else
|
|
||||||
in the direction pivot depends on.
|
|
||||||
|
|
||||||
## What changed since the first draft of this doc
|
|
||||||
|
|
||||||
The first version of this test guessed at a "selection bias" DB field and a
|
|
||||||
candidate squad/lineup table name, based on general FIFA-modding precedent
|
|
||||||
that turned out not to hold for FLE's documented API — no such field appears
|
|
||||||
anywhere in FLE's actual Lua API docs or its own example scripts. While
|
|
||||||
researching an unrelated hotkey issue, a **confirmed, FLE-documented**
|
|
||||||
mechanism for forcing a starting XI turned up instead: the **Formation
|
|
||||||
Editor's "Freeze Lineup" feature** (FLE wiki, `Formation-Editor.md`):
|
|
||||||
|
|
||||||
> This feature can be used in player career mode if you want to manage the
|
|
||||||
> starting lineup of your team. Can be also used in manager career mode to
|
|
||||||
> manually manage your next opponent's starting lineup.
|
|
||||||
|
|
||||||
Steps (GUI, no scripting): open Formation Editor for a team → arrange players
|
|
||||||
on the pitch → tick **Freeze Lineup** → `Data → Save`.
|
|
||||||
|
|
||||||
This is real and documented, but it's GUI-only — there is no Lua function for
|
|
||||||
it, and what DB write it actually performs under the hood is undocumented.
|
|
||||||
This test is now two phases: confirm the GUI feature works at all, then
|
|
||||||
reverse the DB write it makes so it can be replicated programmatically
|
|
||||||
(required for the app→game bridge in build-order step 2, which needs this
|
|
||||||
driven from outside the game, not from a person clicking checkboxes).
|
|
||||||
|
|
||||||
Also fixed in this pass: `EditDBTableField`'s real signature, confirmed from
|
|
||||||
FLE's own docs and `lua/scripts/99ovr_99pot.lua`, is
|
|
||||||
`EditDBTableField(cell)` where `cell` is `row["fieldname"]` with `.value`
|
|
||||||
mutated in place — **not** `EditDBTableField(table, row_index, field, value)`
|
|
||||||
as originally (incorrectly) written into the first draft of the injector
|
|
||||||
script.
|
|
||||||
|
|
||||||
## What this test settles
|
|
||||||
|
|
||||||
Whether a *specific, externally-chosen* 11 players can be forced into a
|
|
||||||
career (or Kick-Off) match's starting lineup, live, with no restart — and
|
|
||||||
whether the mechanism that does it (Freeze Lineup's underlying DB write) can
|
|
||||||
be driven by a script instead of a person clicking through the Formation
|
|
||||||
Editor UI.
|
|
||||||
|
|
||||||
If Freeze Lineup itself doesn't actually hold under match start (the wiki
|
|
||||||
doesn't show it being tested against a live match, only "you should be able
|
|
||||||
to see... when you play against them"), the whole bridge architecture in
|
|
||||||
`docs/direction.md` §3 needs rethinking — there is no other documented
|
|
||||||
mechanism for forcing a lineup.
|
|
||||||
|
|
||||||
## Prerequisites
|
|
||||||
|
|
||||||
- FIFA 23 launched normally (FLE injected, EAAC neutralized — same baseline
|
|
||||||
as `track-c-fut-table-test.md`)
|
|
||||||
- A career save loaded (Freeze Lineup is documented for career mode
|
|
||||||
specifically — confirm separately whether it does anything in Kick-Off,
|
|
||||||
don't assume it does)
|
|
||||||
- Note 11 player IDs from your club (`tools/squad-exporter/export_squad.lua`
|
|
||||||
output, `playerid` field) that are NOT currently your starting XI
|
|
||||||
|
|
||||||
## Phase 1 — confirm Freeze Lineup actually holds into a match
|
|
||||||
|
|
||||||
This has zero scripting and should be done first since everything else is
|
|
||||||
wasted effort if it fails.
|
|
||||||
|
|
||||||
1. Open the Live Editor overlay (F9, or `Windows → Settings` from the
|
|
||||||
overlay's own menu bar if the hotkey isn't registering — see the umu/Wine
|
|
||||||
hotkey note below).
|
|
||||||
2. `Features → Teams` → find your team → `Edit`.
|
|
||||||
3. `Team → Formation` to open the Formation Editor.
|
|
||||||
4. Swap players around on the pitch so the XI differs from your current
|
|
||||||
actual starting XI in some checkable way (e.g. swap two outfield players'
|
|
||||||
positions, or bench/start a specific player).
|
|
||||||
5. Tick **Freeze Lineup**.
|
|
||||||
6. `Data → Save`.
|
|
||||||
7. Hide Live Editor (F9), save your career **on a new slot** (don't overwrite
|
|
||||||
your main save in case this corrupts something), exit to main menu, reload
|
|
||||||
that save, and check the team's lineup screen / play a match and watch who
|
|
||||||
starts.
|
|
||||||
|
|
||||||
**Record in the Results table below whether the frozen lineup actually took
|
|
||||||
the pitch.** If not, stop here — Phase 2 is moot.
|
|
||||||
|
|
||||||
## Phase 2 — find the underlying DB write
|
|
||||||
|
|
||||||
Only proceed if Phase 1 confirmed Freeze Lineup works.
|
|
||||||
|
|
||||||
1. In FLE's Lua Engine, run `tools/squad-injector/snapshot_lineup_tables.lua`.
|
|
||||||
This dumps every DB table whose name contains `squad`, `lineup`,
|
|
||||||
`formation`, `tactic`, `teamsheet`, `selection`, `players`, or `teams` to
|
|
||||||
`C:\FIFA 23 Live Editor\openfut_snapshot_<timestamp>.json`. Note this
|
|
||||||
filename — this is your **before** snapshot.
|
|
||||||
2. Without restarting or reloading, repeat the Formation Editor steps from
|
|
||||||
Phase 1 (steps 2–6 only — open Formation Editor, change the lineup, tick
|
|
||||||
Freeze Lineup, `Data → Save`). Don't save/reload the career between
|
|
||||||
snapshot and this step — keep it to a single live session so the diff
|
|
||||||
isn't polluted by other state changes.
|
|
||||||
3. Run `snapshot_lineup_tables.lua` again. This is your **after** snapshot.
|
|
||||||
4. Copy both JSON files out of the Wine prefix (same path pattern as
|
|
||||||
`track-c-fut-table-test.md`: `~/Games/umu/.../drive_c/FIFA 23 Live
|
|
||||||
Editor/`) and run:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
python3 tools/squad-injector/diff_snapshots.py before.json after.json
|
|
||||||
```
|
|
||||||
|
|
||||||
5. The output shows exactly which table(s) and field(s) changed. This is the
|
|
||||||
real, confirmed write Freeze Lineup performs — record it in the Results
|
|
||||||
table below.
|
|
||||||
|
|
||||||
## Phase 3 — replicate the write via script
|
|
||||||
|
|
||||||
1. Open `tools/squad-injector/apply_lineup_write.lua` and fill in
|
|
||||||
`TARGET_TABLE` and `TARGET_FIELDS` using Phase 2's diff output.
|
|
||||||
2. Edit `C:\FIFA 23 Live Editor\openfut_test_xi.json`:
|
|
||||||
|
|
||||||
```json
|
|
||||||
{
|
|
||||||
"team_id": 12345,
|
|
||||||
"xi": [
|
|
||||||
{ "player_id": 111111, "position": 0 },
|
|
||||||
{ "player_id": 222222, "position": 5 }
|
|
||||||
]
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
Use 11 entries. Position codes are **confirmed numeric 0–27**
|
|
||||||
(`GK=0, SW=1, RWB=2, RB=3, RCB=4, CB=5, LCB=6, LB=7, LWB=8, RDM=9, CDM=10,
|
|
||||||
LDM=11, RM=12, RCM=13, CM=14, LCM=15, LM=16, RAM=17, CAM=18, LAM=19,
|
|
||||||
RF=20, CF=21, LF=22, RW=23, RS=24, ST=25, LS=26, LW=27`) — from
|
|
||||||
`lua/scripts/export_season_stats.lua`'s `get_pos_name` table in FLE's own
|
|
||||||
repo, not a guess.
|
|
||||||
3. Run `apply_lineup_write.lua` from FLE's Lua Engine.
|
|
||||||
4. Repeat the save-to-new-slot / reload / check-lineup verification from
|
|
||||||
Phase 1, but this time without ever opening the Formation Editor — the
|
|
||||||
write was made entirely from the script.
|
|
||||||
|
|
||||||
## Classification criteria
|
|
||||||
|
|
||||||
### "Confirmed — full mechanism works"
|
|
||||||
|
|
||||||
Phase 1 holds, Phase 2 finds a clean diff, Phase 3's scripted write produces
|
|
||||||
the same in-match result as the manual GUI path.
|
|
||||||
|
|
||||||
**Verdict:** Build-order step 1 done. Proceed to step 2 (bridge transport) in
|
|
||||||
`docs/direction.md`.
|
|
||||||
|
|
||||||
### "GUI works, script doesn't"
|
|
||||||
|
|
||||||
Phase 1 holds but Phase 3's replicated write doesn't stick, even though the
|
|
||||||
diffed fields matched what changed in Phase 2.
|
|
||||||
|
|
||||||
**Verdict:** Freeze Lineup likely does more than a single DB field write
|
|
||||||
(e.g. an internal engine call beyond `EditDBTableField`'s reach, or a second
|
|
||||||
write the diff missed because it happened in a table outside the `KEYWORDS`
|
|
||||||
filter in `snapshot_lineup_tables.lua` — widen the filter and redo Phase 2).
|
|
||||||
|
|
||||||
### "Freeze Lineup doesn't hold at all"
|
|
||||||
|
|
||||||
Phase 1 fails — the lineup reverts to the game's own AI-picked XI regardless.
|
|
||||||
|
|
||||||
**Verdict:** No confirmed mechanism exists for forcing a lineup. This kills
|
|
||||||
the bridge architecture as designed in `direction.md` §3 and needs a return
|
|
||||||
to first principles — there is no fallback documented anywhere in FLE's wiki
|
|
||||||
for this specific case.
|
|
||||||
|
|
||||||
## A note on the umu/Wine F9/F11 hotkey issue
|
|
||||||
|
|
||||||
If FLE's F9 (hide/show) hotkey isn't registering under umu, this is plausibly
|
|
||||||
a Wine keyboard-hook limitation (FLE's global hotkey detection likely uses a
|
|
||||||
low-level hook that doesn't translate cleanly through Wine's input layer) —
|
|
||||||
not something documented anywhere in FLE's own troubleshooting docs, which
|
|
||||||
don't mention Linux/Wine at all. F11 specifically has **no documented FLE
|
|
||||||
function** — F9 is the only documented toggle. Workaround: click directly
|
|
||||||
into the FLE overlay window (it should still be visible/clickable even if the
|
|
||||||
hotkey doesn't fire) and use its own menu bar instead of relying on the
|
|
||||||
hotkey.
|
|
||||||
|
|
||||||
## Results
|
|
||||||
|
|
||||||
*(To be filled in after the test is run.)*
|
|
||||||
|
|
||||||
| Field | Value |
|
|
||||||
|---|---|
|
|
||||||
| Date run | — |
|
|
||||||
| Phase 1: Freeze Lineup holds into a match? | — |
|
|
||||||
| Phase 2: table(s)/field(s) changed | — |
|
|
||||||
| Phase 3: scripted write reproduces Phase 1 result? | — |
|
|
||||||
| **Classification** | **PENDING** |
|
|
||||||
@@ -1,136 +0,0 @@
|
|||||||
# FUT Integration Options
|
|
||||||
|
|
||||||
How to connect FIFA 23 to the OpenFUT local simulator, ranked by safety and feasibility.
|
|
||||||
|
|
||||||
## Option A — FLE Lua scripting (RECOMMENDED)
|
|
||||||
|
|
||||||
**What it does:** Use FIFA Live Editor's in-memory Lua API to read and write the game's
|
|
||||||
database tables at runtime. FLE is already injected; no additional hooking needed.
|
|
||||||
|
|
||||||
**Why it's the right path:**
|
|
||||||
- Fully offline, no EA servers touched
|
|
||||||
- FLE is already trusted by the user (it's the launch mechanism)
|
|
||||||
- `GetDBTableRows` / `EditDBTableField` expose the full Frostbite DB in memory
|
|
||||||
- Scripts run inside the game process; no IPC complexity
|
|
||||||
- Same mechanism used by modders for career mode edits today
|
|
||||||
|
|
||||||
**Integration design:**
|
|
||||||
|
|
||||||
```
|
|
||||||
openfut-core (SQLite)
|
|
||||||
│
|
|
||||||
│ HTTP REST (localhost)
|
|
||||||
▼
|
|
||||||
openfut-bridge (port 8080, plain HTTP, no TLS)
|
|
||||||
│ pulls club/squad/player data as JSON
|
|
||||||
▼
|
|
||||||
FLE Lua bridge script
|
|
||||||
│ calls GetDBTableRows, EditDBTableField
|
|
||||||
▼
|
|
||||||
FIFA 23 in-memory DB (Frostbite)
|
|
||||||
```
|
|
||||||
|
|
||||||
The Lua script polls openfut-core's REST API at intervals (or on FUT menu entry)
|
|
||||||
and writes simulator data (coins, items, squad) into the appropriate DB tables.
|
|
||||||
|
|
||||||
**Tables likely involved (to verify with export_squad.lua):**
|
|
||||||
|
|
||||||
| Table | Expected FUT content |
|
|
||||||
|-------|---------------------|
|
|
||||||
| `players` | Player attributes (OVR, potential, stats) |
|
|
||||||
| `teams` | Club identity, stadium, colors |
|
|
||||||
| `fut_clubs` | FUT club record (if in memory when FUT loads) |
|
|
||||||
| `fut_items` | Card inventory (if in memory) |
|
|
||||||
| `fut_squads` | Active squad (if in memory) |
|
|
||||||
|
|
||||||
**Steps to implement:**
|
|
||||||
1. Run `tools/squad-exporter/export_squad.lua` from FLE Lua Engine while in FUT to discover which tables are live
|
|
||||||
2. Map openfut-core's data model to the discovered table fields
|
|
||||||
3. Write a Lua polling script that fetches `/api/v1/club`, `/api/v1/squad`, etc. from openfut-core and calls `EditDBTableField` to populate them
|
|
||||||
4. Optionally add a small HTTP client to the Lua script using LuaSocket (FLE ships with Lua 5.4)
|
|
||||||
|
|
||||||
**Limitations:**
|
|
||||||
- Changes are in-memory only; they reset on game restart (acceptable for a simulator)
|
|
||||||
- Only works while FLE is running (always true in our setup)
|
|
||||||
- FUT tables may only be populated when the FUT hub is loaded; test with the exporter
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Option B — Local save file injection (career mode proxy)
|
|
||||||
|
|
||||||
**What it does:** Generate or modify offline career mode save files that contain FUT-like
|
|
||||||
squad/player data, using Frostbite's FBCHUNKS format.
|
|
||||||
|
|
||||||
**Feasibility:** Medium
|
|
||||||
- FBCHUNKS format is not publicly documented but has been partially reverse-engineered by the Frosty Tool Suite project
|
|
||||||
- Career saves are 16 MB — large and complex
|
|
||||||
- Changes take effect only after a game restart
|
|
||||||
|
|
||||||
**Best use:** Pre-populating a career club with the same players as the FUT simulator squad, so offline Squad Battles use "your" players.
|
|
||||||
|
|
||||||
**Steps:**
|
|
||||||
1. Use Frosty Tool Suite to open a career save and map the schema
|
|
||||||
2. Build a Python exporter that writes a valid FBCHUNKS save with simulator squad data
|
|
||||||
3. Test: replace the career save, launch FIFA, verify squad is correct
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Option C — Local companion web UI
|
|
||||||
|
|
||||||
**What it does:** The user manages their FUT simulator entirely in a web browser (openfut-core already has this). A button exports the current squad/club state to a format that a Lua script or file injector can consume.
|
|
||||||
|
|
||||||
**This is already implemented** — openfut-core serves the FUT simulator REST API. The missing piece is the Lua bridge script (Option A) that reads from it.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Option D — Local proxy for non-secured local calls only
|
|
||||||
|
|
||||||
**What it does:** Intercept FIFA 23's calls to `localhost:*` or a known local endpoint (not EA servers) and respond with simulator data.
|
|
||||||
|
|
||||||
**Feasibility:** Low value in isolation
|
|
||||||
- FIFA 23 does not make calls to localhost in normal operation (except EA App on port 10853)
|
|
||||||
- All FUT API calls go to EA's servers over TLS
|
|
||||||
- Intercepting those would require the approach we explicitly ruled out
|
|
||||||
|
|
||||||
**Not recommended as a primary path.** Could be combined with Option A if the Lua script exposes a local socket that a coordinator process writes to.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Option E — Memory bridge (Cheat Engine / FLE offsets)
|
|
||||||
|
|
||||||
**What it does:** Use known memory offsets (FLE's `offset_cache.json`) to read/write FUT state directly in FIFA23.exe's heap.
|
|
||||||
|
|
||||||
**Feasibility:** Medium — FLE already does this for career mode
|
|
||||||
- FLE's `offset_cache.json` contains addresses for many game structures
|
|
||||||
- FUT in-memory structs are separate from career structs and may not be mapped yet
|
|
||||||
- This is fragile (offsets change with game updates)
|
|
||||||
|
|
||||||
**Not recommended** unless Options A and B both fail — too brittle.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Recommendation
|
|
||||||
|
|
||||||
**Start with Option A (FLE Lua scripting).**
|
|
||||||
|
|
||||||
1. Run `tools/squad-exporter/export_squad.lua` in-game to discover which DB tables exist in FUT mode
|
|
||||||
2. Use `tools/file-watch-diff/watch.sh` to snapshot file state entering FUT and identify any new local files
|
|
||||||
3. Use `tools/network-metadata-logger/netlog.sh` to log which EA hosts FIFA contacts at FUT entry (metadata only, no decryption)
|
|
||||||
4. Map findings back to openfut-core's data model
|
|
||||||
5. Implement the Lua bridge script that calls openfut-core's REST API and writes to discovered tables
|
|
||||||
|
|
||||||
If FUT tables are not exposed by FLE's DB API (they may not be — FUT data lives server-side in online mode), fall back to **Option B** (career save injection) to provide a squad that mirrors the simulator's club.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Safety boundary
|
|
||||||
|
|
||||||
The following are out of scope and must not be implemented:
|
|
||||||
|
|
||||||
- Decrypting or inspecting EA's TLS traffic
|
|
||||||
- Spoofing EA domain names or impersonating EA servers
|
|
||||||
- Sending modified clients to EA's production services
|
|
||||||
- Bypassing EA App login or account verification
|
|
||||||
- Anything that could constitute online cheating or violate EA's ToS for online play
|
|
||||||
|
|
||||||
All integration must remain local/offline/single-player.
|
|
||||||
@@ -1,208 +0,0 @@
|
|||||||
# OpenFUT Status Review
|
|
||||||
*Generated 2026-06-30 — read-only stocktake, no code changed.*
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Executive Summary
|
|
||||||
|
|
||||||
OpenFUT has a mature offline FUT economy backend (Core, 25 phases, fully functional in
|
|
||||||
isolation) and a sophisticated hook DLL that loads into FIFA 23, redirects EA hostnames
|
|
||||||
to loopback, and bypasses TLS certificate verification. The Blaze/ProtoSSL layer is
|
|
||||||
structurally ready: framing code exists, a TLS listener runs, cert-verify is patched.
|
|
||||||
However the project is currently blocked before any Blaze traffic is ever seen.
|
|
||||||
The fundamental problem is that FIFA 23 submits `GoOnline` to EbisuSDK and then
|
|
||||||
**waits for an asynchronous ONLINE_STATUS_EVENT push** from the EA-app LSX server —
|
|
||||||
a push that current code never sends. Every approach tried so far (flipping poll
|
|
||||||
return values, forcing the state flags, read-only probes) confirms the gate is
|
|
||||||
event-driven, not poll-driven. The Blaze captures directory contains six empty files.
|
|
||||||
No Fire2 frame from FIFA 23 has ever been decoded. Until the ONLINE_STATUS_EVENT push
|
|
||||||
is synthesized and delivered correctly, Milestones 2–7 are all waiting on the same
|
|
||||||
single wall.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 1. Proven vs Assumed
|
|
||||||
|
|
||||||
| Claim | Status | Evidence |
|
|
||||||
|---|---|---|
|
|
||||||
| FIFA 23 uses DirtySDK / ProtoSSL | **Proven** | String scan hit `ProtoSSLSend`, `ProtoSSLRecv`, `gosredirector` in FIFA23.exe memory (Task 1) |
|
|
||||||
| `version.dll` loads and runs hook code | **Proven** | `hook.log` written at DLL_PROCESS_ATTACH |
|
|
||||||
| `getaddrinfo` IAT hook redirects EA domains to loopback | **Proven** | Hook log records every EA `getaddrinfo` call; connect_hook log confirms port redirects |
|
|
||||||
| ProtoSSL cert-verify prologue found and patched (FIFA23.exe) | **Proven** | ssl_patch.rs prologue confirmed at file offset 0xf0c850; hook log "ssl: main exe cert-verify patched" |
|
|
||||||
| ProtoSSL cert-verify patched in EAWebKit.dll | **Proven** (if loaded) | Lazy patch fires on first EA getaddrinfo call; hook log message confirms |
|
|
||||||
| Gate is upstream of DirtySDK — no DNS/connect fires on FUT entry | **Proven** | getaddrinfo, connect, WSASend/Recv hooks all show zero external traffic during "connecting to EA Servers" |
|
|
||||||
| `GoOnline` is called by the game | **Proven** | Read-only detour on `anadius64.dll+0x2BB90` confirmed hit |
|
|
||||||
| anadius returns GoOnline success | **Proven** | Handler observed returning successfully; game still retries every ~7 s |
|
|
||||||
| Gate is downstream of GoOnline | **Proven** | GoOnline called + returns success; no Blaze connect follows |
|
|
||||||
| Connection-state function: `GetInternetConnectedState @ anadius64.dll+0x27790` | **Proven** | Located via anadius LSX command-registration table; two-flag branch decoded (`+0xCAB1A`, `+0xCAB1B`) |
|
|
||||||
| Gate is event-driven (game waits for async push, not a poll return) | **Proven** | Forced both state flags AND GoOnline return to "1"; game kept retrying; worker-thread stack scan confirms handler runs on anadius IOCP thread, not FIFA's thread |
|
|
||||||
| GoOnline runs on anadius worker thread, not FIFA's call thread | **Proven** | Stack scan from inside detour found zero FIFA23.exe frames, sp ~2.4 KB from thread stack top |
|
|
||||||
| `protossl-scan` live toolkit is exhausted for finding GoOnline in FIFA23.exe | **Proven** | No `"GoOnline"` string in image; worker-thread call stack has no FIFA frames; jmpscan yields ~3875 hits (overwhelmingly data false positives) |
|
|
||||||
| FIFA 23 redirector config references `Authorization:` header (Nucleus token) | **Proven** | Found in FIFA23.exe .rdata pointer table @ `+0x83FC858` |
|
|
||||||
| openfut-core REST API complete and tested | **Proven** | 25 phases, 15 migrations, passing integration tests |
|
|
||||||
| Bridge LSX server starts and handles request-response | **Proven** (code) | `openfut-bridge/src/lsx.rs` + `main.rs` — server starts on 127.0.0.1:3216 |
|
|
||||||
| Bridge LSX server ACTUALLY receives FIFA's LSX connections | **UNCONFIRMED** | anadius may intercept the same calls in-process before the TCP connection reaches the bridge |
|
|
||||||
| Bridge LSX server `GetInternetConnectedState → connected="1"` unblocks the gate | **UNCONFIRMED (known to fail in-process)** | Flipping the value via anadius in-process failed; bridge path not yet confirmed working |
|
|
||||||
| ONLINE_STATUS_EVENT push XML format | **UNKNOWN** | No capture; format not derived |
|
|
||||||
| Fire2 framing is correct for FIFA 23 | **UNCONFIRMED** | Implemented based on post-2012 EA convention; all blaze captures are empty (0 bytes) |
|
|
||||||
| Blaze component / command IDs for FIFA 23 | **UNKNOWN** | Zero captures; dispatch table entirely empty placeholders |
|
|
||||||
| ProtoSSL recv-injection convention (non-blocking return values etc.) | **UNCONFIRMED** | Never reached M4; recv_hook module removed from active install path |
|
|
||||||
| FUT REST endpoint paths in mapper.rs | **SPECULATIVE** | Based on community knowledge of older FIFA titles; the one actual capture in `captures/` is an early GET from before the Blaze strategy |
|
|
||||||
| FLE Lua API exposes FUT DB tables in memory | **UNKNOWN** | `export_squad.lua` has never been run; FUT data may only exist server-side in online mode |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 2. Milestone Status
|
|
||||||
|
|
||||||
| Milestone | Status | Blocker | Depends on unconfirmed assumption? |
|
|
||||||
|---|---|---|---|
|
|
||||||
| **M1** — Locate connection-state decision point | ✅ Done | — | No |
|
|
||||||
| **M2** — Flip gate, force "connected" | ⛔ Blocked | Game waits for async ONLINE_STATUS_EVENT push; no current code sends it | Yes — unknown event XML format |
|
|
||||||
| **M3** — First ProtoSSL plaintext on Blaze connection | 🔲 Not started | Depends on M2 | Yes — Fire2 framing unconfirmed |
|
|
||||||
| **M4** — Answer redirector + decode first Fire2 frame | 🔲 Not started | Hard wall: Fire2 framing, recv-injection convention, component/command IDs all unconfirmed | Yes — all three unknown |
|
|
||||||
| **M5** — Blaze preauth / login / postauth | 🔲 Not started | Depends on M4 | Yes — Blaze auth TDF body layout unknown |
|
|
||||||
| **M6** — FUT entry + hub load | 🔲 Not started | Depends on M5; also requires FUT REST response shapes confirmed | Yes — endpoint paths speculative |
|
|
||||||
| **M7** — Squad Battles (AI FUT) | 🔲 Not started | Depends on M6 | Yes |
|
|
||||||
|
|
||||||
**Note on roadmap.md wording:** Under M2–M4, roadmap.md uses `**Done (observable):**` bullets. These describe the *success criterion* for each milestone, not an achieved state. The authoritative status is in `connection-gate-findings.md` (M2 attempts failed; M3/M4 never started). The roadmap has not been updated to reflect M2 failure.
|
|
||||||
|
|
||||||
### M4 is the first hard wall in detail
|
|
||||||
|
|
||||||
Even assuming M2 is solved, M4 requires three unconfirmed things simultaneously:
|
|
||||||
1. **Fire2 framing** — the 12-byte header layout is assumed; if FIFA 23 uses an older Fire variant or a custom delta, the codec will misparse every packet.
|
|
||||||
2. **ProtoSSL recv-injection** — delivering responses to the game via recv hook requires knowing what return values and buffer conventions ProtoSSL expects; recv_hook.rs exists but is not installed.
|
|
||||||
3. **Blaze component/command IDs** — the dispatch table is entirely empty; we cannot answer any request until IDs are known from captures.
|
|
||||||
|
|
||||||
All three are resolved by getting one real captured frame. M4 is primarily a capture problem, not a decoding problem — once bytes exist, the framing and IDs are immediately readable.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 3. Blockers, Risks, Unknowns
|
|
||||||
|
|
||||||
### Blockers (stop progress now)
|
|
||||||
|
|
||||||
1. **ONLINE_STATUS_EVENT push not synthesized** *(M2 wall)*
|
|
||||||
The game calls GoOnline, gets success, then waits indefinitely for a push event on the LSX socket that never arrives. This is the single gate blocking all Blaze work. Options: (a) trace the event format via Ghidra on FIFA23.exe (xref `ONLINE_STATUS_EVENT` string + the game's EbisuSDK listener), (b) RE anadius's LSX event-send path (find what it would push in an "online" scenario), (c) brute-force push candidate event XMLs and observe whether the game advances.
|
|
||||||
|
|
||||||
2. **Bridge LSX server delivery unconfirmed** *(architectural risk converted to blocker)*
|
|
||||||
The hook passes port 3216 connections through, assuming the bridge LSX server on the Linux host receives them. If anadius's in-process hooks intercept the winsock calls before they reach the TCP stack, the bridge server is never reached. This must be confirmed by checking `openfut_hook.log` for a getaddrinfo on the LSX host, or by observing the bridge server's accept logs.
|
|
||||||
|
|
||||||
### Risks (could derail later)
|
|
||||||
|
|
||||||
3. **Fire2 framing wrong** *(M4 risk)*
|
|
||||||
If FIFA 23 uses Fire (pre-2012) or a modified frame layout, the codec misparses. Mitigation: the server has a `Raw` fallback mode for capturing raw bytes when framing fails.
|
|
||||||
|
|
||||||
4. **Secondary auth-token gate** *(M5 risk)*
|
|
||||||
`connection-gate-findings.md` noted the redirector request carries an `Authorization:` header. M1's final conclusion said `GetAuthCode` returns a fake token that appears accepted — but this was inferred, not confirmed by seeing the redirector request actually constructed with that token.
|
|
||||||
|
|
||||||
5. **EAAC not fully neutralized** *(persistent risk)*
|
|
||||||
`FakeEAACLauncher` bypasses the anticheat launcher. The hook DLL is unsigned. If EAAC is ever active (e.g., after a game update re-enables it), all hooks fail silently. Marked as "not active in offline/cracked builds" — assumed, not confirmed on every launch.
|
|
||||||
|
|
||||||
6. **FUT REST response shapes wrong** *(M6 risk)*
|
|
||||||
The 61 endpoint mappings in mapper.rs and the shaper stubs in shaper.rs are based on community guesses about older FIFA FUT APIs, not FIFA 23 captures. Response JSON shapes may differ enough to cause the client to fail silently or crash.
|
|
||||||
|
|
||||||
### Unknowns (open questions)
|
|
||||||
|
|
||||||
7. **ONLINE_STATUS_EVENT XML format** — exact tag names, field order, sender attribute, and any nonces/tokens required.
|
|
||||||
8. **GoOnline event sequence** — whether ONLINE_STATUS_EVENT alone is sufficient or a sequence of events (e.g., PROFILE_EVENT, LOGIN_EVENT, COMMERCE_EVENT) is expected.
|
|
||||||
9. **Whether FLE exposes FUT DB tables** — FUT card inventory and squad data likely live server-side in online mode; FLE may not surface them for in-process editing.
|
|
||||||
10. **Blaze component/command IDs for FIFA 23** — entirely unknown; no captures.
|
|
||||||
11. **openfut_hook.log current content** — we have the code but no log output in any document. Whether the current hook (with connect, ssl_patch, tls_bypass, WSAIoctl, origin_spy all installed) fires correctly and what it observes is unverified in this review.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 4. Track Comparison
|
|
||||||
|
|
||||||
### Track A — Full EA-backend fake (M1–M7, playable FUT vs AI)
|
|
||||||
|
|
||||||
**What it delivers:** The FIFA 23 FUT hub loads from OpenFUT Core; Squad Battles matches play and reward economy items.
|
|
||||||
|
|
||||||
**Effort:** Research-grade. Minimum path: synthesize ONLINE_STATUS_EVENT (unknown format, 1–2 weeks of RE), then capture Fire2 frames (days once M2 is solved), then implement Blaze auth handlers (weeks), then implement FUT entry (weeks), then Squad Battles (weeks). Realistic minimum: 3–6 months of expert RE work.
|
|
||||||
|
|
||||||
**Proven support:** Hook loads and redirects correctly. TLS bypass patched. Core economy backend complete. Blaze framing code and TLS listener exist.
|
|
||||||
|
|
||||||
**Assumed:** Fire2 framing correct; component/command IDs discoverable from captures; FUT REST shapes close enough to community guesses; no additional undiscovered gates.
|
|
||||||
|
|
||||||
**Evidence for:** Architecture is coherent. The M1 finding (gate precisely named and decoded) was achieved cleanly. The in-process hook approach is validated.
|
|
||||||
|
|
||||||
**Evidence against:** M2 was attempted and failed with the in-process approach. The event-driven architecture adds a full EbisuSDK emulation layer before even one Blaze byte is seen. The live toolkit is exhausted (Path A verdict); Ghidra-level work on a 505 MB binary is required. Six capture files with zero bytes.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
### Track B — Clean-room spec deliverable (M1–M5 documented)
|
|
||||||
|
|
||||||
**What it delivers:** A documented map of the connection gate, LSX event sequence, Blaze auth surface (transport, framing, gate conditions, component IDs, TDF schemas). Valuable as an archival/community artifact even if Track A stalls.
|
|
||||||
|
|
||||||
**Effort:** Medium. M1 is done. M2–M5 documentation emerges as a by-product of engineering work. The spec itself (writing) is lightweight; the engineering to produce the captures is the cost.
|
|
||||||
|
|
||||||
**Proven support:** M1 complete and documented. connection-gate-findings.md is already a high-quality spec artifact.
|
|
||||||
|
|
||||||
**Assumed:** Same as Track A for the unconfirmed values, but the spec can mark them `TODO/CONFIRM` rather than needing to implement them.
|
|
||||||
|
|
||||||
**Evidence for:** The clean-room constraint means a spec is the only artifact that can be safely published. connection-gate-findings.md shows this approach produces real value. B finishes even if A is never fully playable.
|
|
||||||
|
|
||||||
**Evidence against:** Track B alone doesn't produce a playable FUT; it is a foundation, not an end-user product.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
### Track C — FLE Lua bridge (local-match path, skip the backend gate)
|
|
||||||
|
|
||||||
**What it delivers:** FIFA 23 career mode or Kick-Off with an OpenFUT club's players and squad loaded via FLE's in-memory DB API. No online gate, no Blaze, no TLS. Fully offline from day one.
|
|
||||||
|
|
||||||
**Effort:** Low-to-medium. FLE is already loaded in the normal launch path. Tools exist (`tools/squad-exporter/`, `tools/profile-exporter/`). Primary unknown is whether FUT-relevant DB tables are accessible.
|
|
||||||
|
|
||||||
**Proven support:** FLE Lua API exposes `GetDBTableRows` / `EditDBTableField` for career mode. `fifa23-startup-flow.md` confirms FLE injects at load. `fut-integration-options.md` documents the integration path in detail and rates this as the recommended option.
|
|
||||||
|
|
||||||
**Assumed:** FUT card/club/squad data has in-memory DB table representations that FLE can write. If FUT data is purely server-side (loaded from EA servers, not from the Frostbite DB layer), Track C produces no FUT simulation at all — only career mode player stats.
|
|
||||||
|
|
||||||
**Evidence for:** Career mode already works with FLE edits (community precedent). Tools are present and designed for this path. No infrastructure work needed.
|
|
||||||
|
|
||||||
**Evidence against:** FUT in FIFA 23 uses server-side data. The cards in a player's FUT club, the coins, the squad — these are fetched from `fut.ea.com` REST APIs, not from the Frostbite embedded DB. FLE's `GetDBTableRows` likely exposes base player stats tables but not FUT item tables. The crucial test (run `export_squad.lua` while in FUT mode) has never been done.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
### Recommendation
|
|
||||||
|
|
||||||
**Start Track C immediately as a parallel, low-cost validation.**
|
|
||||||
|
|
||||||
Run `export_squad.lua` in FLE while inside the FUT hub (or attempting to enter it). If FUT tables appear in the export, Track C is viable and is the fastest path to something a user can interact with. This test takes one session and costs nothing.
|
|
||||||
|
|
||||||
Simultaneously, **continue Track A/B with the next concrete RE step:** synthesize the ONLINE_STATUS_EVENT push. The most actionable option is to run `origin_spy` logs from the current hook to see what LSX events fire during a session, then attempt to push candidate event XMLs via the bridge LSX server and watch whether the game advances. This is bounded, testable work that either unblocks M2 or produces the spec value for Track B.
|
|
||||||
|
|
||||||
**Do not abandon Track A/B for Track C** — they are complementary. Core is already built; the bridge is mostly built. The gap is purely the RE wall at M2.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 5. Architecture and Provenance Sanity-Check
|
|
||||||
|
|
||||||
### Hook + Brain coherence
|
|
||||||
|
|
||||||
The CLAUDE.md bridge architecture diagram (hook intercepts ProtoSSL → plain localhost TCP → blaze_brain → Core) remains coherent. The M1/M2 findings revealed one additional layer (EbisuSDK LSX event) that must precede the Blaze connection. The bridge has been updated to handle LSX directly. The overall design is sound; the M2 blocker is an implementation gap (event synthesis), not an architectural flaw.
|
|
||||||
|
|
||||||
**One inconsistency to flag:** The hook's `lsx.rs` contains a complete in-process LSX emulator (AES-128-ECB, CRandom, all response builders), but the recv/send hooks that activate it are explicitly removed (`lib.rs`: "recv/send hooks removed — LSX is now handled by the native openfut-bridge LSX server"). This is dead code. The bridge's LSX server is the current path. The in-process lsx.rs should either be deleted or documented as a fallback; its presence is confusing.
|
|
||||||
|
|
||||||
### Clean-room status
|
|
||||||
|
|
||||||
No evidence of EA leaked source anywhere in the tree. All RE work is derived from:
|
|
||||||
- Running the shipping binary and observing behavior (function return values, network traffic patterns)
|
|
||||||
- Memory scanning of the live process (string search, xref, disasm of observed addresses)
|
|
||||||
- Reading anadius's own compiled output (its exported symbols, its LSX XML format — which is anadius's own implementation, not EA's)
|
|
||||||
- Community FUT API knowledge (mapper.rs endpoint paths — plausible but speculative)
|
|
||||||
|
|
||||||
The Blaze framing in `fifa-blaze/crates/blaze-proto/src/frame.rs` cites "Fire2 used by ME3, BF3, and most post-2012 titles" — this is sourced from public community documentation of those older titles, not from any leaked EA source. **Clean-room intact.**
|
|
||||||
|
|
||||||
The `AES_KEY` in the hook's lsx.rs (`[0,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15]`) is a placeholder key used for the LSX session encryption. The real session key is derived from the challenge seed via CRandom — this algorithm was RE'd from anadius's own binary. No EA source required.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## 6. If You Read Only This
|
|
||||||
|
|
||||||
- **The project is blocked at M2.** FIFA 23 submits `GoOnline`, gets success, then waits for an async `ONLINE_STATUS_EVENT` push on the LSX socket that no current code ever sends. All six Blaze capture files are empty (0 bytes). No Fire2 frame has ever been decoded.
|
|
||||||
|
|
||||||
- **M1 is the only completed milestone.** The gate function (`GetInternetConnectedState @ anadius64.dll+0x27790`) is precisely named and its two-flag branch decoded. Everything after M1 is either blocked or not started.
|
|
||||||
|
|
||||||
- **The next concrete action** is synthesizing the ONLINE_STATUS_EVENT push XML and testing whether the bridge's LSX server can deliver it to the game. This is the single thing that unblocks all Blaze work.
|
|
||||||
|
|
||||||
- **Track C (FLE Lua) is untested but cheap to validate.** Run `export_squad.lua` while in FUT to find out if FUT DB tables are accessible. If yes, it is the fastest path to user-visible results. If no, it is ruled out with one session.
|
|
||||||
|
|
||||||
- **openfut-core is complete and ready** — 25 phases, 15 migrations, full economy REST API, passing tests. It is not blocking anything; it is waiting for the bridge to connect to it.
|
|
||||||
@@ -1,93 +0,0 @@
|
|||||||
# Track C — FUT DB table viability test
|
|
||||||
|
|
||||||
**Status: PENDING — test has not yet been run.**
|
|
||||||
|
|
||||||
## What this test settles
|
|
||||||
|
|
||||||
Track C ("FLE Lua bridge") would inject OpenFUT club data directly into FIFA 23's
|
|
||||||
in-memory Frostbite DB tables at runtime, bypassing the entire backend/Blaze stack.
|
|
||||||
It is only viable for FUT (not just career mode) if FUT-specific tables — card
|
|
||||||
inventory, squad composition with FUT fields, coins — are accessible in memory when
|
|
||||||
the game is in the FUT area.
|
|
||||||
|
|
||||||
FUT data in online mode is fetched server-side from `fut.ea.com`. It is not known
|
|
||||||
whether FIFA 23 mirrors any of this into the Frostbite in-memory DB that FLE
|
|
||||||
can read/write. This test settles that question directly.
|
|
||||||
|
|
||||||
## Test procedure
|
|
||||||
|
|
||||||
**Prerequisites:**
|
|
||||||
- FIFA 23 launched normally via umu-run/Steam
|
|
||||||
- FLE (FIFA Live Editor) injected and active (normal launch path)
|
|
||||||
- EAAC in offline/neutralized state
|
|
||||||
- Game navigated as deep into FUT as possible (FUT hub if reachable; otherwise the
|
|
||||||
furthest FUT screen before the gate blocks it)
|
|
||||||
|
|
||||||
**Run the exporter:**
|
|
||||||
1. In FLE's Lua Engine, open and run `tools/squad-exporter/export_squad.lua`
|
|
||||||
(full path on the Windows side: `C:\<game>\openfut_squad_export.json`)
|
|
||||||
2. Wait for the MessageBox "Done! N players, M teams." or "ERROR writing..."
|
|
||||||
3. Retrieve the output file from the Wine prefix:
|
|
||||||
`~/Games/umu/fifa23-tools/drive_c/FIFA 23 Live Editor/openfut_squad_export.json`
|
|
||||||
(or wherever `C:\FIFA 23 Live Editor\` maps in the active prefix)
|
|
||||||
|
|
||||||
**What to inspect in the output:**
|
|
||||||
- `all_db_tables` array — the complete list of table names visible to FLE right now
|
|
||||||
- `fut_tables` object — any table whose name contains `fut`, `club`, `pack`, `item`, or
|
|
||||||
`market` (the script auto-extracts these)
|
|
||||||
- `is_career_mode` — confirms whether FUT or career mode was active
|
|
||||||
|
|
||||||
## Classification criteria
|
|
||||||
|
|
||||||
### "FUT tables present"
|
|
||||||
|
|
||||||
`fut_tables` is non-empty AND contains FUT-specific fields beyond base player stats:
|
|
||||||
- e.g., `fut_items` with card-type / rating / chemistry fields
|
|
||||||
- e.g., a squad table with FUT formation / chemistry / loan-flag fields
|
|
||||||
- e.g., a coins or points balance field
|
|
||||||
|
|
||||||
**Verdict:** Track C is viable for FUT. Fastest path to user-visible results.
|
|
||||||
|
|
||||||
### "only base player tables"
|
|
||||||
|
|
||||||
`fut_tables` is empty (no `fut_*` / `club_*` / `item_*` / `market_*` table names found
|
|
||||||
in `all_db_tables`), OR those tables exist but contain only base player attributes
|
|
||||||
(OVR, potential, position, pace, …) — the same fields visible in career mode.
|
|
||||||
|
|
||||||
**Verdict:** Track C cannot produce FUT. It could at most provide a custom Kick-Off or
|
|
||||||
career-mode match with players sourced from OpenFUT Core. FUT items and coins exist
|
|
||||||
only on EA's servers (not in the in-memory DB in offline mode).
|
|
||||||
|
|
||||||
### "FUT area unreachable to test"
|
|
||||||
|
|
||||||
The connection gate blocked entering FUT deeply enough for FUT tables to be populated.
|
|
||||||
Record which tables were visible and at what screen the test was run.
|
|
||||||
|
|
||||||
**Verdict:** Retest after M2 is unblocked, OR test with `TLS_ENABLED=false` bridge
|
|
||||||
handling the entry check stub.
|
|
||||||
|
|
||||||
## Results
|
|
||||||
|
|
||||||
*(To be filled in after the test is run.)*
|
|
||||||
|
|
||||||
| Field | Value |
|
|
||||||
|---|---|
|
|
||||||
| Date run | — |
|
|
||||||
| FIFA screen at test time | — |
|
|
||||||
| `is_career_mode` | — |
|
|
||||||
| Total tables in `all_db_tables` | — |
|
|
||||||
| FUT-specific table names found | — |
|
|
||||||
| Key FUT fields present | — |
|
|
||||||
| **Classification** | **PENDING** |
|
|
||||||
|
|
||||||
## Honest prior
|
|
||||||
|
|
||||||
`fut-integration-options.md` rates this as the recommended path and lists `fut_clubs`,
|
|
||||||
`fut_items`, `fut_squads` as "expected" tables. However those expectations are based on
|
|
||||||
analogy with career mode (which does store club/squad in the DB). FUT's data model is
|
|
||||||
architecturally different — it is account-bound server-side. The expectation may be
|
|
||||||
wrong. This test is the oracle.
|
|
||||||
|
|
||||||
The `export_squad.lua` script checks `GetDBTablesNames()` exhaustively (not just
|
|
||||||
assumed names), so it will surface any FUT tables that actually exist, regardless of
|
|
||||||
what name they use.
|
|
||||||
+1
-1
Submodule fifa-blaze updated: d2a9a01ec9...f4f33969f2
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,934 @@
|
|||||||
|
k|J|
|
||||||
|
tz^WU
|
||||||
|
Gb\X[
|
||||||
|
,j|L
|
||||||
|
cXXXX
|
||||||
|
gzW[rp
|
||||||
|
)l``b`
|
||||||
|
c^^^^
|
||||||
|
zrbnz
|
||||||
|
r--)
|
||||||
|
&jzzx
|
||||||
|
Jl```
|
||||||
|
c^^^\
|
||||||
|
----
|
||||||
|
k|X\^_
|
||||||
|
c\Xxx
|
||||||
|
K|bjk
|
||||||
|
cxxxx
|
||||||
|
---%
|
||||||
|
{xx|
|
||||||
|
cxxxz
|
||||||
|
Frxz
|
||||||
|
{VVVW
|
||||||
|
cpxz~
|
||||||
|
gr*:
|
||||||
|
sTVUU
|
||||||
|
cxz^W
|
||||||
|
[5555
|
||||||
|
px~M
|
||||||
|
cUUU5
|
||||||
|
cUU-
|
||||||
|
gz((+
|
||||||
|
&rX`
|
||||||
|
&kVX
|
||||||
|
cUUUx
|
||||||
|
&r^\
|
||||||
|
%%%%
|
||||||
|
&kUW
|
||||||
|
f[UUW
|
||||||
|
gcE[
|
||||||
|
$gcE[
|
||||||
|
cUU%
|
||||||
|
UUWT
|
||||||
|
xxxx
|
||||||
|
FsUU^
|
||||||
|
$ecF[
|
||||||
|
icD[
|
||||||
|
T\Rb
|
||||||
|
sUW|
|
||||||
|
UUU\
|
||||||
|
VUUU
|
||||||
|
BIGF
|
||||||
|
L286
|
||||||
|
Apt Data:1:7:8
|
||||||
|
game/globalComponents/globalComponents
|
||||||
|
game.globalComponents.ImageLoader
|
||||||
|
game/components/SelectTeam
|
||||||
|
game.components.SelectTeam
|
||||||
|
Coins
|
||||||
|
TournamentData
|
||||||
|
BackingFUT
|
||||||
|
VersusFUT
|
||||||
|
external.ion_fut.screens.futSelectTeam
|
||||||
|
__Packages.external.ion_fut.screens.futSelectTeam
|
||||||
|
__Packages.ion.manager.HelpProperties
|
||||||
|
EACondBold
|
||||||
|
10.000
|
||||||
|
Screen
|
||||||
|
RtIL
|
||||||
|
RYgO
|
||||||
|
7uOO
|
||||||
|
XsOY
|
||||||
|
2sOY
|
||||||
|
<@OY
|
||||||
|
BG&Y
|
||||||
|
3NuIL
|
||||||
|
7NuI
|
||||||
|
3NuI
|
||||||
|
3NstY
|
||||||
|
7uOY
|
||||||
|
&v>Y
|
||||||
|
&v>t
|
||||||
|
3NYN
|
||||||
|
7NYN
|
||||||
|
tOYZ
|
||||||
|
BG&v
|
||||||
|
NZGO
|
||||||
|
NZGOZu
|
||||||
|
uOZu
|
||||||
|
mcCup
|
||||||
|
txtPrizeHeading
|
||||||
|
txtCoins
|
||||||
|
mcCoin
|
||||||
|
mcBacking
|
||||||
|
txtVs
|
||||||
|
mcTournamentInfo
|
||||||
|
mcSelectTeam
|
||||||
|
mcVersusFUT
|
||||||
|
publishObject
|
||||||
|
dpID
|
||||||
|
nHomeKitID
|
||||||
|
nAwayKitID
|
||||||
|
keyCode
|
||||||
|
controllerId
|
||||||
|
nSide
|
||||||
|
arrKitIDs
|
||||||
|
teamId
|
||||||
|
kitToResolve
|
||||||
|
side
|
||||||
|
isUser
|
||||||
|
arrKits
|
||||||
|
objProperties
|
||||||
|
Void
|
||||||
|
nXPos
|
||||||
|
DDS |
|
||||||
|
NVTT
|
||||||
|
DXT5
|
||||||
|
8VTTT
|
||||||
|
UUVT
|
||||||
|
TTTU
|
||||||
|
0TUVT
|
||||||
|
TTUW
|
||||||
|
$$r
|
||||||
|
%UUU
|
||||||
|
WUUU
|
||||||
|
UUUSP
|
||||||
|
UUUM
|
||||||
|
UUUNK
|
||||||
|
72Ib
|
||||||
|
*72Ib
|
||||||
|
U;8I
|
||||||
|
WWWW?>I
|
||||||
|
UIFI
|
||||||
|
WWWWLKI
|
||||||
|
WWWVQNI
|
||||||
|
VVYVI
|
||||||
|
`]IB
|
||||||
|
daIB
|
||||||
|
heIB
|
||||||
|
VlhI
|
||||||
|
vtI"I
|
||||||
|
UU%!I
|
||||||
|
*;8I
|
||||||
|
U?>I
|
||||||
|
ULKI
|
||||||
|
Apt1
|
||||||
|
_global
|
||||||
|
external
|
||||||
|
Object
|
||||||
|
ion_fut
|
||||||
|
screens
|
||||||
|
futSelectTeam
|
||||||
|
futSelectTeam::futSelectTeam()
|
||||||
|
OnExitScreen
|
||||||
|
cafe
|
||||||
|
utility
|
||||||
|
Delegate
|
||||||
|
Create
|
||||||
|
game
|
||||||
|
globalClasses
|
||||||
|
ScreenManager
|
||||||
|
SetOnExitScreenCallback
|
||||||
|
m_nFlowState
|
||||||
|
EA_ZONE
|
||||||
|
gScreenFlowManager
|
||||||
|
getFlowState
|
||||||
|
ION_Platform
|
||||||
|
IsFinal
|
||||||
|
CardNotification
|
||||||
|
eState
|
||||||
|
FUT_OFFLINE_DRAFT
|
||||||
|
FUT_OFFLINE_TOURNAMENT
|
||||||
|
FUT_OFFLINE_SEASON
|
||||||
|
m_bAllowSelectAnyTeam
|
||||||
|
FUT/ALLOW_ANY_CPU_TEAM
|
||||||
|
ION_Customization
|
||||||
|
GetAardvarkIntValue
|
||||||
|
mcPanelHome
|
||||||
|
mcPanelAway
|
||||||
|
mcReadyHome
|
||||||
|
mcReadyAway
|
||||||
|
mcKitHome
|
||||||
|
mcKitAway
|
||||||
|
mcLockHome
|
||||||
|
mcLockAway
|
||||||
|
InitComponents
|
||||||
|
InitializeScreen
|
||||||
|
Initialize
|
||||||
|
screen
|
||||||
|
BaseScreen
|
||||||
|
prototype
|
||||||
|
futSelectTeam::InitializeScreen()
|
||||||
|
_visible
|
||||||
|
HOME_SIDE
|
||||||
|
GameServices
|
||||||
|
eTeamSide
|
||||||
|
SIDE_HOME
|
||||||
|
AWAY_SIDE
|
||||||
|
SIDE_AWAY
|
||||||
|
NEUTRAL_SIDE
|
||||||
|
SIDE_NEUTRAL
|
||||||
|
m_arrPanelData
|
||||||
|
Array
|
||||||
|
m_arrKitPanelData
|
||||||
|
futSelectTeam::InitComponents()
|
||||||
|
InitializeKitConfig
|
||||||
|
InitializeTeamConfig
|
||||||
|
SetTeamAndKitConfigs
|
||||||
|
UIFDataProviderList
|
||||||
|
FUT_USER_CLUB_DATA_DP
|
||||||
|
UIFUtility
|
||||||
|
RegisterDataProvider
|
||||||
|
FUT_OPPONENT_CLUBS_LIST_DP
|
||||||
|
FUT_OPPONENTS_SQUADS_LIST_DP
|
||||||
|
FUT_OPPONENT_SQUAD_LINEUP_DP
|
||||||
|
FUT_USER_SQUAD_LINEUP_DP
|
||||||
|
FUT_CREATE_MATCH_DP
|
||||||
|
FUT_GET_MATCH_KITS_DP
|
||||||
|
SetupReadyTexts
|
||||||
|
initSideInfo
|
||||||
|
SetPanels
|
||||||
|
m_arrPanels
|
||||||
|
m_arrKitPanels
|
||||||
|
KitSelectDP
|
||||||
|
TeamSetupDP
|
||||||
|
AnimateIn
|
||||||
|
AnimateInComplete
|
||||||
|
BeginAnimateIn
|
||||||
|
futSelectTeam::AnimateInComplete()
|
||||||
|
m_bHasAnimatedIn
|
||||||
|
checkForDisconnect
|
||||||
|
gScreenNotAborted
|
||||||
|
LocalEventHandler
|
||||||
|
InputManager
|
||||||
|
AddLocalEventHandler
|
||||||
|
SetHandlerId
|
||||||
|
refreshCurrentConnectionStatus
|
||||||
|
HelpManager
|
||||||
|
Update
|
||||||
|
futSelectTeam::OnExitScreen()
|
||||||
|
AnimationManager
|
||||||
|
ClearAnimations
|
||||||
|
UnregisterDataProvider
|
||||||
|
INJURY_POPUP_ID
|
||||||
|
PopupManager
|
||||||
|
DeletePopup
|
||||||
|
TOTW_BELOW_MIN_POPUP_ID
|
||||||
|
USER_BELOW_MIN_POPUP_ID
|
||||||
|
OPP_BELOW_MIN_POPUP_ID
|
||||||
|
OPP_HAS_NO_VALID_SQUADS_ID
|
||||||
|
Shutdown
|
||||||
|
ClearSavedOpponentData
|
||||||
|
SQUAD_ID
|
||||||
|
UUID_UPPER
|
||||||
|
UUID_LOWER
|
||||||
|
UIFActionList
|
||||||
|
ACTION_SAVE_OPPONENT_DATA
|
||||||
|
SendActionObj
|
||||||
|
Publish
|
||||||
|
futSelectTeam::Publish()
|
||||||
|
header
|
||||||
|
USER_CLUB_DATA
|
||||||
|
SetUserClubData
|
||||||
|
initVersusFUTComponents
|
||||||
|
OPPONENT_CLUBS
|
||||||
|
m_arrOpponentClubs
|
||||||
|
data
|
||||||
|
MATCH_CREATED
|
||||||
|
FUT_PAFC_GAME
|
||||||
|
GetCurrentCountryIndex
|
||||||
|
SQUADS
|
||||||
|
GetCurrentLeagueIndex
|
||||||
|
ACTION_ADVANCE
|
||||||
|
SendAction
|
||||||
|
eSoundEvent
|
||||||
|
PRIMARY_SELECT
|
||||||
|
playSound
|
||||||
|
m_bShouldWaitForPublish
|
||||||
|
OPP_SQUADS_LIST
|
||||||
|
SetOpponentSquadListData
|
||||||
|
SQUAD_LINEUP_LOADED
|
||||||
|
IS_USER
|
||||||
|
SetSquadLineup
|
||||||
|
KITS_AVAILABLE
|
||||||
|
LENGTH
|
||||||
|
KIT_
|
||||||
|
push
|
||||||
|
futSelectTeam::InitializeKitConfig()
|
||||||
|
SetupTeamsInfo
|
||||||
|
GetHomeTeamId
|
||||||
|
ACTION_MATCHDAY_HOME_TEAM_CHANGE
|
||||||
|
GetAwayTeamId
|
||||||
|
ACTION_MATCHDAY_AWAY_TEAM_CHANGE
|
||||||
|
ACTION_MATCHDAY_ADVANCE_KIT_SETUP
|
||||||
|
SetReadyStatus
|
||||||
|
FadeOut
|
||||||
|
GetKitArrayForFUT
|
||||||
|
HOME_KIT_ID
|
||||||
|
AWAY_KIT_ID
|
||||||
|
ION_Uniform
|
||||||
|
IsKitSelectCreated
|
||||||
|
EnterKitSelect
|
||||||
|
IsAlternatingMode
|
||||||
|
GetUnhighlightedSide
|
||||||
|
SetKitUnReady
|
||||||
|
InitializeKitsFromArray
|
||||||
|
Unhighlight
|
||||||
|
SetDisabled
|
||||||
|
SetHighlightedSide
|
||||||
|
GetHighlightedSide
|
||||||
|
Highlight
|
||||||
|
futSelectTeam::InitializeTeamConfig()
|
||||||
|
LEAGUE_ID
|
||||||
|
components
|
||||||
|
TeamSetupControl
|
||||||
|
TEAM_TOGGLE
|
||||||
|
GetUserSideForFUT
|
||||||
|
m_isInFUT
|
||||||
|
InitData
|
||||||
|
GetToggleValue
|
||||||
|
UpdateTeamInfo
|
||||||
|
m_bOpponentTeamInvalid
|
||||||
|
m_OppHasSquads
|
||||||
|
SetChemistryValue
|
||||||
|
ResetTeamInfo
|
||||||
|
FadeIn
|
||||||
|
SetupMouseSupport
|
||||||
|
SetWomenTeamsOnlyFilter
|
||||||
|
SetMenTeamsOnlyFilter
|
||||||
|
DeactivateReady
|
||||||
|
futSelectTeam::SetupTeamsInfo()
|
||||||
|
USER_TEAM_ID
|
||||||
|
ION_GameSetup
|
||||||
|
GetTeam
|
||||||
|
SetHomeTeamId
|
||||||
|
SetAwayTeamId
|
||||||
|
setCustomSelectionArray
|
||||||
|
Team
|
||||||
|
eAttribute
|
||||||
|
ION_Team
|
||||||
|
GetAttributes
|
||||||
|
futSelectTeam::LocalEventHandler()
|
||||||
|
WARNING: Preventing the user to move until a Publish occurs.
|
||||||
|
IsInTransition
|
||||||
|
Stop spamming buttons, the team select screen is in a transition.
|
||||||
|
GetUserControllerSide
|
||||||
|
GetScreenState
|
||||||
|
DataProviders
|
||||||
|
STATE_TEAM
|
||||||
|
InputCodes
|
||||||
|
LEFT
|
||||||
|
RIGHT
|
||||||
|
GetReadyStatus
|
||||||
|
DOWN
|
||||||
|
BACK
|
||||||
|
ADVANCE
|
||||||
|
OPTION_TOP
|
||||||
|
OPTION_LEFT
|
||||||
|
IsSwitchSidesActive
|
||||||
|
STATE_KIT
|
||||||
|
SetUniform
|
||||||
|
ExitKitSelect
|
||||||
|
RemoveKitLocks
|
||||||
|
ACTION_BACKOUT
|
||||||
|
CANCEL
|
||||||
|
SetKit
|
||||||
|
SaveKitsForMatch
|
||||||
|
FUT_TOTW_GAME
|
||||||
|
SetGoingToKickoffHub
|
||||||
|
SetHomeKitId
|
||||||
|
SetAwayKitId
|
||||||
|
GetHomeKitId
|
||||||
|
GetAwayKitId
|
||||||
|
ACTION_CREATE_MATCH
|
||||||
|
SetReady
|
||||||
|
SetKitReady
|
||||||
|
FUT_OPP_HAS_NO_VALID_SQUADS
|
||||||
|
PopupData
|
||||||
|
Okay_abbr2
|
||||||
|
AddButton
|
||||||
|
ShowPopup
|
||||||
|
ValidateFullLineUp
|
||||||
|
m_sInjuryOrSuspendedWarning
|
||||||
|
m_bConceptPlayersInSquad
|
||||||
|
FUT_DB_Players_Not_Playable
|
||||||
|
FUT_TOTW_BELOW_MIN_PLAYERS
|
||||||
|
FUT_BELOW_MIN_PLAYERS
|
||||||
|
FUT_OPP_BELOW_MIN_PLAYERS
|
||||||
|
COUNTRY_TOGGLE
|
||||||
|
LEAGUE_TOGGLE
|
||||||
|
ACTION_GET_USER_SQUAD_LINEUP
|
||||||
|
ACTION_GET_OPPONENT_SQUAD_LINEUP
|
||||||
|
GoToViewSquad
|
||||||
|
PlatformManager
|
||||||
|
IsMicrosoft
|
||||||
|
USER_NAME
|
||||||
|
length
|
||||||
|
gEaso
|
||||||
|
showGamercard
|
||||||
|
getHelpContext
|
||||||
|
futSelectTeam::getHelpContext()
|
||||||
|
STATE_INVALID
|
||||||
|
FUT_VIEW_SQUAD_HOME
|
||||||
|
ltxt
|
||||||
|
manager
|
||||||
|
HelpItem
|
||||||
|
CreateHelpItem
|
||||||
|
FUT_VIEW_SQUAD_AWAY
|
||||||
|
ViewGamerCard
|
||||||
|
CreateHelpTickerItem
|
||||||
|
futSelectTeam::InitializeKitsFromArray()
|
||||||
|
GetAllAttributes
|
||||||
|
TYPE_UPPER
|
||||||
|
ITEM_NAME
|
||||||
|
ITEM_ID
|
||||||
|
ASSET_ID
|
||||||
|
StyleManager
|
||||||
|
FONT_TILE_HS
|
||||||
|
SetTitleTextFormat
|
||||||
|
SetToggleOffset
|
||||||
|
globalComponents
|
||||||
|
BasePanel
|
||||||
|
STYLE_FIFTEEN
|
||||||
|
SetBasePanelStyle
|
||||||
|
KIT_SCALE
|
||||||
|
kits
|
||||||
|
ToggleWithImage
|
||||||
|
STYLE_TOGGLE
|
||||||
|
SetStrokeVisibility
|
||||||
|
CheckIsKitLocked
|
||||||
|
futSelectTeam::GetKitArrayForFUT()
|
||||||
|
GetNonConflictingUniformID
|
||||||
|
eSortType
|
||||||
|
SORT_ASCENDING
|
||||||
|
Uniform
|
||||||
|
eSortColumn
|
||||||
|
SORT_NONE
|
||||||
|
eFilter
|
||||||
|
FILTER_UNFILTERED
|
||||||
|
GetIDs
|
||||||
|
LOCKED
|
||||||
|
NAME
|
||||||
|
shift
|
||||||
|
futSelectTeam::initVersusFUTComponents()
|
||||||
|
text
|
||||||
|
Versus_abbr
|
||||||
|
_height
|
||||||
|
FUT_Tournament
|
||||||
|
GetOfflineActiveTournamentId
|
||||||
|
GetOfflineTournamentInfo
|
||||||
|
TROPHY_ID
|
||||||
|
trophy
|
||||||
|
getArtAssetPath
|
||||||
|
SCALE_ASPECT_CENTER
|
||||||
|
setScaling
|
||||||
|
setSize
|
||||||
|
setImage
|
||||||
|
FUT_UC_TOURNAMENT_BONUS
|
||||||
|
PRIZE_FINAL
|
||||||
|
ION_Localization
|
||||||
|
LocalizeInteger
|
||||||
|
_width
|
||||||
|
textWidth
|
||||||
|
FUT_COINS_OFFSET
|
||||||
|
futSelectTeam::GoToViewSquad()
|
||||||
|
isUserTeam
|
||||||
|
CLUB_NAME
|
||||||
|
BADGE_TEAM_ID
|
||||||
|
SQUAD_NAME
|
||||||
|
RATING
|
||||||
|
SQUAD_RATING
|
||||||
|
CHEMISTRY
|
||||||
|
SQUAD_CHEMISTRY
|
||||||
|
SHOW_CHEM_LINE
|
||||||
|
SCREEN
|
||||||
|
VIEW_SQUADS
|
||||||
|
setContextDataObject
|
||||||
|
loadOverlayScreen
|
||||||
|
futSelectTeam::SetUserClubData()
|
||||||
|
m_arrUserClubs
|
||||||
|
PUBLIC
|
||||||
|
CLUB_ABBR
|
||||||
|
EST_DATE
|
||||||
|
ACTIVE_SQUAD_ID
|
||||||
|
SIDE_NAME
|
||||||
|
Away_Side
|
||||||
|
Home_Side
|
||||||
|
futSelectTeam::SetOpponentSquadListData()
|
||||||
|
split
|
||||||
|
FUT_NO_VALID_SQUADS
|
||||||
|
futSelectTeam::SetSquadLineup()
|
||||||
|
SetTeam
|
||||||
|
futSelectTeam::GetCurrentCountryIndex()
|
||||||
|
futSelectTeam::GetCurrentLeagueIndex()
|
||||||
|
futSelectTeam::GetUserSideForFUT()
|
||||||
|
bIsDemo
|
||||||
|
GetLockRules
|
||||||
|
SIDE_LOCK
|
||||||
|
futSelectTeam::ValidateFullLineUp()
|
||||||
|
FUT_SquadManagement
|
||||||
|
GetOpponentSquadLineup
|
||||||
|
GetSquadLineup
|
||||||
|
FUT_NUM_PLAYERS_IN_SQUAD
|
||||||
|
CARD_ID
|
||||||
|
ION_Card
|
||||||
|
GetPlayerCardInfo
|
||||||
|
IS_DREAM_PLAYER
|
||||||
|
FUT_NUM_PLAYERS_IN_SQUAD_EXTENDED
|
||||||
|
gFutHelpers
|
||||||
|
GetInjuryOrSuspendedSquadWarning
|
||||||
|
futSelectTeam::SaveKitsForMatch()
|
||||||
|
SIDE
|
||||||
|
NUM_KITS
|
||||||
|
ACTION_SAVE_MATCH_KIT
|
||||||
|
FUT_TOURNAMENT_CUP_SCALE
|
||||||
|
INJURY_OR_SUSPENDED_POPUP
|
||||||
|
TOTW_NUM_PLAYERS_BELOW_MIN_POPUP
|
||||||
|
USER_NUM_PLAYERS_BELOW_MIN_POPUP
|
||||||
|
OPP_NUM_PLAYERS_BELOW_MIN_POPUP
|
||||||
|
OPP_HAS_NO_VALID_SQUADS
|
||||||
|
SCALE_NONE
|
||||||
|
SCALE_ASPECT
|
||||||
|
SCALE_ABSOLUTE
|
||||||
|
ASSetPropFlags
|
||||||
|
HelpProperties
|
||||||
|
mXPos
|
||||||
|
GetXPos
|
||||||
|
SetXPos
|
||||||
|
registerClass
|
||||||
|
hj\W
|
||||||
|
hj/U
|
||||||
|
UUUV
|
||||||
|
'Z`XV
|
||||||
|
j`XVW
|
||||||
|
b$9^
|
||||||
|
UW^}
|
||||||
|
hb>x
|
||||||
|
DA__\X
|
||||||
|
UWW^
|
||||||
|
HbCA
|
||||||
|
hjCA/
|
||||||
|
+{dA
|
||||||
|
b#9X7*
|
||||||
|
I^^|x
|
||||||
|
(Z``pP
|
||||||
|
Zxp`
|
||||||
|
\j~X
|
||||||
|
&j\xp
|
||||||
|
jXXXX
|
||||||
|
Fn%Vb=
|
||||||
|
xxxp
|
||||||
|
xh``
|
||||||
|
WWWW
|
||||||
|
r\XXX
|
||||||
|
xxz_
|
||||||
|
{XPpr
|
||||||
|
Hb__^\
|
||||||
|
`x|x
|
||||||
|
``xX
|
||||||
|
]{jp
|
||||||
|
xxhh
|
||||||
|
X\\\
|
||||||
|
U\T_
|
||||||
|
`pz~
|
||||||
|
_^^^
|
||||||
|
cq,6
|
||||||
|
-/+*+
|
||||||
|
jjjj
|
||||||
|
jJJj
|
||||||
|
_^Xp
|
||||||
|
WV\p
|
||||||
|
TTWU
|
||||||
|
```h
|
||||||
|
pWUU
|
||||||
|
\UUU
|
||||||
|
$I">
|
||||||
|
x^UU
|
||||||
|
/UUU
|
||||||
|
$IR`m
|
||||||
|
$IL#
|
||||||
|
cAxW
|
||||||
|
dI/U
|
||||||
|
&b%W
|
||||||
|
|UWV\
|
||||||
|
j_uyQ
|
||||||
|
|UUVT
|
||||||
|
|WT\\
|
||||||
|
j`ppp
|
||||||
|
|\\\\
|
||||||
|
bpppp
|
||||||
|
)---
|
||||||
|
||x||
|
||||||
|
bzzzz
|
||||||
|
s"#)5
|
||||||
|
K{&R
|
||||||
|
D(tFR```
|
||||||
|
j5555
|
||||||
|
){zxh`
|
||||||
|
hlUU_`
|
||||||
|
$Ithd
|
||||||
|
Ithd
|
||||||
|
hlUWVT
|
||||||
|
s(ljj
|
||||||
|
HR{O
|
||||||
|
IBww
|
||||||
|
@Bbb
|
||||||
|
Hl\\Xx
|
||||||
|
zzhh
|
||||||
|
@`pP
|
||||||
|
Htxxxx
|
||||||
|
hlHd
|
||||||
|
Ht%%%5
|
||||||
|
ZZ\\
|
||||||
|
H|xxxx
|
||||||
|
Hthd
|
||||||
|
xxxX
|
||||||
|
TV_]
|
||||||
|
H|hd
|
||||||
|
Xxx`
|
||||||
|
_\|p
|
||||||
|
pppP
|
||||||
|
H|xxxz
|
||||||
|
i|%%%5
|
||||||
|
pX\T
|
||||||
|
H|xzzz
|
||||||
|
(dHt
|
||||||
|
H|`xz_
|
||||||
|
UU^p
|
||||||
|
$G|(t
|
||||||
|
G|(t
|
||||||
|
(tG\
|
||||||
|
VTTT
|
||||||
|
kUUU5
|
||||||
|
(pXxx
|
||||||
|
XXXX
|
||||||
|
KOKK
|
||||||
|
'cUU^
|
||||||
|
hs'c
|
||||||
|
$Gk(c
|
||||||
|
Gk(c
|
||||||
|
~ZZX
|
||||||
|
GkUWx
|
||||||
|
GkUUU\
|
||||||
|
'Gk(c
|
||||||
|
p``H
|
||||||
|
zUU~
|
||||||
|
X`pxZ
|
||||||
|
sUWx
|
||||||
|
c```
|
||||||
|
@@@@
|
||||||
|
WVT\
|
||||||
|
Vw~U
|
||||||
|
_^_j
|
||||||
|
\XPp
|
||||||
|
^|~^
|
||||||
|
c``pX\
|
||||||
|
````
|
||||||
|
UUUU
|
||||||
|
\\\\
|
||||||
|
????
|
||||||
|
p~UU
|
||||||
|
Ib'b
|
||||||
|
X\WU
|
||||||
|
A*++
|
||||||
|
UUUX
|
||||||
|
VWUU
|
||||||
|
z^VW
|
||||||
|
W^x
|
||||||
|
\\\\j
|
||||||
|
TWVV
|
||||||
|
\^xx
|
||||||
|
W^~
|
||||||
|
VWVt
|
||||||
|
cI^xxp
|
||||||
|
k$)WWVT
|
||||||
|
)W_VT
|
||||||
|
$1VTVT
|
||||||
|
(\\\\
|
||||||
|
\\\\"
|
||||||
|
$1\\XX
|
||||||
|
pr`z
|
||||||
|
AXPp`
|
||||||
|
yU^r^
|
||||||
|
$I2,r
|
||||||
|
PZrC
|
||||||
|
U{Bz
|
||||||
|
{||Z
|
||||||
|
kkki
|
||||||
|
c`p^
|
||||||
|
cx6l
|
||||||
|
\\\\]
|
||||||
|
dIb`@@
|
||||||
|
pvv]
|
||||||
|
'z@@
|
||||||
|
XVUU
|
||||||
|
e9`p
|
||||||
|
UVVV
|
||||||
|
(.-5
|
||||||
|
JJJJ
|
||||||
|
cQxxx
|
||||||
|
(%-)+
|
||||||
|
VVVV
|
||||||
|
#9ZZxx
|
||||||
|
i-)-
|
||||||
|
1U_|
|
||||||
|
#9=*
|
||||||
|
VVTT
|
||||||
|
T\\X
|
||||||
|
X^__
|
||||||
|
5-)+
|
||||||
|
$I"'r
|
||||||
|
rrbJ
|
||||||
|
8)-%5
|
||||||
|
ZZZZ
|
||||||
|
jjjk
|
||||||
|
1^UUU
|
||||||
|
g1G)^
|
||||||
|
!XX\V
|
||||||
|
BIGF0
|
||||||
|
Apt Data:1:5:8
|
||||||
|
U555
|
||||||
|
Urpp
|
||||||
|
~B'j
|
||||||
|
5555
|
||||||
|
m*((
|
||||||
|
;RRRR
|
||||||
|
m***
|
||||||
|
:RRRR
|
||||||
|
`15555
|
||||||
|
sZPPP
|
||||||
|
`95555
|
||||||
|
Apppp
|
||||||
|
95555
|
||||||
|
{PPPR
|
||||||
|
RRRR
|
||||||
|
rrp_
|
||||||
|
&j2'
|
||||||
|
pppp
|
||||||
|
Ns%!U
|
||||||
|
%)%%%%
|
||||||
|
f)%!
|
||||||
|
` 6dC.kE!
|
||||||
|
Z%)70
|
||||||
|
1E!W
|
||||||
|
1E!U
|
||||||
|
f1E!
|
||||||
|
F1Xp*
|
||||||
|
9f)U
|
||||||
|
xUU\
|
||||||
|
JV~No
|
||||||
|
(n{$!
|
||||||
|
iJPPpp
|
||||||
|
<W\^
|
||||||
|
AqUW
|
||||||
|
{Cq_
|
||||||
|
U]P\
|
||||||
|
Pppp
|
||||||
|
TTTT
|
||||||
|
PPPp
|
||||||
|
,(;k
|
||||||
|
z^\x
|
||||||
|
\^VT
|
||||||
|
???/
|
||||||
|
btTVV
|
||||||
|
M{-/75
|
||||||
|
x~_^
|
||||||
|
TUWW
|
||||||
|
%555
|
||||||
|
(^xp`
|
||||||
|
UUWV
|
||||||
|
jR\T\\
|
||||||
|
1xp``
|
||||||
|
b\\\X
|
||||||
|
b557/
|
||||||
|
jZ'5
|
||||||
|
WWWh
|
||||||
|
^XPZ
|
||||||
|
zxxxx
|
||||||
|
1UWVT
|
||||||
|
h4Vb%
|
||||||
|
\^U?
|
||||||
|
\\\X
|
||||||
|
I*.$
|
||||||
|
Hb'A
|
||||||
|
9UU\
|
||||||
|
i--+
|
||||||
|
Wka@
|
||||||
|
P|WWW
|
||||||
|
UW^x
|
||||||
|
@PW^
|
||||||
|
czXX
|
||||||
|
++-5
|
||||||
|
`x@p
|
||||||
|
brp`
|
||||||
|
U%%%
|
||||||
|
\VUW
|
||||||
|
XPXX
|
||||||
|
WTTV
|
||||||
|
PPXX
|
||||||
|
zc9~^z
|
||||||
|
I"1-+
|
||||||
|
!*+*
|
||||||
|
TTVT
|
||||||
|
----Y
|
||||||
|
73 &
|
||||||
|
Av|z
|
||||||
|
`^UJ
|
||||||
|
xx~p
|
||||||
|
&jB1_
|
||||||
|
Y444$
|
||||||
|
xWU0
|
||||||
|
$_nO
|
||||||
|
G1BBBB
|
||||||
|
xxx^
|
||||||
|
xxz~
|
||||||
|
---=
|
||||||
|
***J
|
||||||
|
O"'@
|
||||||
|
7 '>
|
||||||
|
U`X\Y
|
||||||
|
h035^
|
||||||
|
Lw!f
|
||||||
|
&T@a
|
||||||
|
]8RR
|
||||||
|
[OAq
|
||||||
|
D/Oz%F
|
||||||
|
+1.^-
|
||||||
|
_,_Y
|
||||||
|
..^O
|
||||||
|
CG|!@
|
||||||
|
;}>|
|
||||||
|
nHT*
|
||||||
|
a8Nj
|
||||||
|
?'Un70
|
||||||
|
^[zM2Bj @
|
||||||
|
6nd[N
|
||||||
|
Z)MBc
|
||||||
|
wY=A
|
||||||
|
8p(a
|
||||||
|
:m"D
|
||||||
|
[dbt
|
||||||
|
E'0S
|
||||||
|
nT+bJuZ
|
||||||
|
V-:t
|
||||||
|
v)(n
|
||||||
|
(*s?p
|
||||||
|
cc?r
|
||||||
|
B%{r
|
||||||
|
-4Yi
|
||||||
|
sci,Iy
|
||||||
|
|3;=
|
||||||
|
<KB6
|
||||||
|
cCFVJ
|
||||||
|
J|jg
|
||||||
|
4VvVV6
|
||||||
|
p$$e&
|
||||||
|
4%1{
|
||||||
|
~%ew==_.
|
||||||
|
EFGFFED
|
||||||
|
[FFB}9
|
||||||
|
$"dOz%^-
|
||||||
|
mw77
|
||||||
|
ct3r
|
||||||
|
ecGB
|
||||||
|
*\JV
|
||||||
|
c&WV
|
||||||
|
w6GMq
|
||||||
|
13aB
|
||||||
|
$X~_
|
||||||
|
mMx%
|
||||||
|
;11sZR
|
||||||
|
'&'n
|
||||||
|
q&##>o
|
||||||
|
+:Z/Y
|
||||||
|
]:AY
|
||||||
|
$(+~
|
||||||
|
,^:(,
|
||||||
|
kp>C
|
||||||
|
luqYql
|
||||||
|
wf_q
|
||||||
|
XYX\
|
||||||
|
@p77
|
||||||
|
--X&q
|
||||||
|
{ cf
|
||||||
|
waF,
|
||||||
|
znrn;
|
||||||
|
VRwCE
|
||||||
|
5=#&
|
||||||
|
/J"}
|
||||||
|
_A4Z
|
||||||
|
gnB7%
|
||||||
|
q`Y
|
||||||
|
Q|!+
|
||||||
|
[MMA
|
||||||
|
**rV
|
||||||
|
)~U(w*,)m
|
||||||
|
Z*SVd
|
||||||
|
$#&qi
|
||||||
|
qmUW=
|
||||||
|
F"MN
|
||||||
|
HaA%e%
|
||||||
|
(T!]5(\
|
||||||
|
IK#k
|
||||||
|
v wQ
|
||||||
|
C(\M
|
||||||
|
];%P
|
||||||
|
7f&=kJ
|
||||||
|
%(oRtK
|
||||||
|
gRr?
|
||||||
|
+rq_
|
||||||
|
/==7
|
||||||
|
,IUk
|
||||||
|
D?t(zC,
|
||||||
|
\}oe
|
||||||
|
'^YY
|
||||||
|
nwzu
|
||||||
|
jdf,
|
||||||
|
i5hFc
|
||||||
|
z@xOrFp
|
||||||
|
aqgv
|
||||||
|
y^oT+
|
||||||
|
dZ13
|
||||||
|
d{g~
|
||||||
|
ttzi
|
||||||
|
p,@B
|
||||||
|
upqH
|
||||||
|
1{pl0
|
||||||
|
J4)~
|
||||||
|
&W<;@
|
||||||
|
p77Es
|
||||||
|
:aPw
|
||||||
|
`>(^&
|
||||||
|
lnW|
|
||||||
|
~+w8
|
||||||
@@ -0,0 +1,278 @@
|
|||||||
|
# FIFA17.exe runtime command/event id -> name registry
|
||||||
|
# Recovered 2026-08-24 from live pid 44405 (Denuvo-decrypted, /proc/PID/mem, read-only).
|
||||||
|
# CardsDLL live base 0x6ffffc0f0000; registration loop at live 0x147dd0000-0x147df8000.
|
||||||
|
# NOTE: this is a DIFFERENT namespace from CardsDLL's DataProvider id table.
|
||||||
|
# the same numeric id has a different name in each, matching the APT's split
|
||||||
|
# between game.uif.UIFDataProviderList and the action/command list.
|
||||||
|
#
|
||||||
|
0x0207 %d
|
||||||
|
0x0bb9 back
|
||||||
|
0x0bbb preScreenSucceeded
|
||||||
|
0x0bbc preScreenFailed
|
||||||
|
0x0bc0 clearTeamSheets
|
||||||
|
0x0be7 selectTab
|
||||||
|
0x0c15 optionSelected
|
||||||
|
0x0c2a leaveGameGroup
|
||||||
|
0x0c2c quitToHub
|
||||||
|
0x0dac UpdateStadiumCrests
|
||||||
|
0x0dac startStoryMode
|
||||||
|
0x2713 matchdayFixtureChange
|
||||||
|
0x271a evt_set_matchDay_offline_fixture
|
||||||
|
0x271b evt_team_setup_state
|
||||||
|
0x271c advanceDefault
|
||||||
|
0x271d advanceDefaultWithTeam
|
||||||
|
0x271e advancePran
|
||||||
|
0x271f feInitialized
|
||||||
|
0x2720 skipBootflow
|
||||||
|
0x2721 startBootflow
|
||||||
|
0x2722 bootflowStarted
|
||||||
|
0x2723 bootflowFinished
|
||||||
|
0x2724 bootflowSaveLoadFailed
|
||||||
|
0x2725 returnToPressStart
|
||||||
|
0x2726 showPressStart
|
||||||
|
0x2727 evt_load_personal_settings
|
||||||
|
0x2728 evt_settings_load_complete
|
||||||
|
0x2729 assetUpdate
|
||||||
|
0x272a pranUpload
|
||||||
|
0x272b pranDownload
|
||||||
|
0x272c controllerConfig
|
||||||
|
0x272d activateGameModeIntro
|
||||||
|
0x272e ActivateFullGame
|
||||||
|
0x272f startIntroFlow
|
||||||
|
0x2730 offlineEulaProfileSuccess
|
||||||
|
0x2731 offlineEulaProfileFail
|
||||||
|
0x2732 startIntroMatch
|
||||||
|
0x2733 abortIntroMatch
|
||||||
|
0x2735 setCareerType
|
||||||
|
0x2736 exitTitle
|
||||||
|
0x2737 evt_set_fullscreen
|
||||||
|
0x273e enterSubPanel
|
||||||
|
0x273f exitSubPanel
|
||||||
|
0x2742 evt_invite_accepted
|
||||||
|
0x2743 profileSignOut
|
||||||
|
0x2744 profilePrepareForSave
|
||||||
|
0x2745 logTelemetry
|
||||||
|
0x2746 enterPracticeArena
|
||||||
|
0x2748 navigationBackoutStart
|
||||||
|
0x2749 navigationBackoutContinue
|
||||||
|
0x274a navigationBackoutComplete
|
||||||
|
0x274b checkSpeechData
|
||||||
|
0x274c newsSharingSettings
|
||||||
|
0x274d leaveBootFlow
|
||||||
|
0x274e mainMenuProfileCreationDone
|
||||||
|
0x274f nonLeadProfileCreation
|
||||||
|
0x2750 nonLeadProfileLoad
|
||||||
|
0x2755 teamSheetAction
|
||||||
|
0x2758 evt_set_lead_profile
|
||||||
|
0x2759 evt_sign_out
|
||||||
|
0x275a notifySignOut
|
||||||
|
0x275b notifySignOutReady
|
||||||
|
0x275c notifySignOutTitleScreen
|
||||||
|
0x275d evt_sign_out_flow_ready
|
||||||
|
0x275e evt_sign_out_flow_not_ready
|
||||||
|
0x275f showSignOutPopup
|
||||||
|
0x2760 showSignOutTitleScreenPopup
|
||||||
|
0x2761 evt_dismiss_sign_out_popup
|
||||||
|
0x2762 evt_show_account_picker
|
||||||
|
0x2763 evt_lead_profile_recovered
|
||||||
|
0x2764 triggerSignOut
|
||||||
|
0x2765 checkLeadProfilePairing
|
||||||
|
0x2766 evt_lead_profile_paired
|
||||||
|
0x2767 evt_lead_profile_unpaired
|
||||||
|
0x2768 evt_lead_profile_controller_changed
|
||||||
|
0x2769 beginProfileCheck
|
||||||
|
0x276a endProfileCheck
|
||||||
|
0x276b evt_controller_disconnect
|
||||||
|
0x276c evt_notify_controller_disconnect
|
||||||
|
0x276d evt_controller_disconnect_flow_ready
|
||||||
|
0x276e evt_controller_disconnect_flow_not_ready
|
||||||
|
0x276f showLoadPersonalSettingsPopup
|
||||||
|
0x2770 showSavePersonalSettingsPopup
|
||||||
|
0x2771 feRenderInGame
|
||||||
|
0x2772 pvProfilerStart
|
||||||
|
0x2773 pvProfilerStop
|
||||||
|
0x2775 enterMatchDayTab
|
||||||
|
0x2776 exitMatchDayTab
|
||||||
|
0x2777 restartWithNewTeams
|
||||||
|
0x2778 playSecondLegFixture
|
||||||
|
0x2779 setupSecondLegFixture
|
||||||
|
0x277a welcomeToMatchDayLive
|
||||||
|
0x277b exitMatchDayLivePanel
|
||||||
|
0x277c enableAardvark
|
||||||
|
0x277d disableAardvark
|
||||||
|
0x277e conditionAardvark
|
||||||
|
0x2780 adaptiveDifficultyDetectedPopup
|
||||||
|
0x2781 adaptiveDifficultyUpPopup
|
||||||
|
0x2782 adaptiveDifficultyDownPopup
|
||||||
|
0x2783 adaptiveDifficultyDetected
|
||||||
|
0x2784 adaptiveDifficultyUp
|
||||||
|
0x2785 adaptiveDifficultyDown
|
||||||
|
0x2786 adaptiveDifficultyDisable
|
||||||
|
0x2787 adaptiveDifficultyReset
|
||||||
|
0x2788 adaptiveDifficultyKeep
|
||||||
|
0x2789 adaptiveDifficultyOverride
|
||||||
|
0x278c evt_countdown_done
|
||||||
|
0x278d evt_countdown_restart
|
||||||
|
0x278e evt_start_stadium_change
|
||||||
|
0x278f evt_wait_for_stadium_change
|
||||||
|
0x2790 evt_wait_for_stadium_change_bootflow
|
||||||
|
0x2791 evt_advance_to_wait_popup
|
||||||
|
0x2792 evt_advance_to_wait
|
||||||
|
0x2793 evt_stadium_background_loaded
|
||||||
|
0x2795 setupTournament
|
||||||
|
0x2796 createTournament
|
||||||
|
0x2797 createWomenTournament
|
||||||
|
0x2799 setWomenTournament
|
||||||
|
0x279a evt_sl_operation_started
|
||||||
|
0x279b evt_sl_operation_complete
|
||||||
|
0x279c evt_sl_operation_load
|
||||||
|
0x279d evt_sl_operation_boot_load
|
||||||
|
0x279e evt_sl_operation_save
|
||||||
|
0x279f evt_sl_operation_delete
|
||||||
|
0x27a0 FUTLoginComplete
|
||||||
|
0x27a1 requestDownload
|
||||||
|
0x27a2 backendEnter
|
||||||
|
0x27a3 backendExit
|
||||||
|
0x27a4 onlineLoginToEaPopup
|
||||||
|
0x27a5 onlineBootLoginToEaPopup
|
||||||
|
0x27a6 evt_onlineAlertPopup
|
||||||
|
0x27a7 evt_onlineBootLoginFailurePopup
|
||||||
|
0x27a8 evt_onlineLoginFailurePopup
|
||||||
|
0x27a9 onlineLoginPopupHide
|
||||||
|
0x27aa onlineLoginPopupShow
|
||||||
|
0x27ab evt_invite_flow_ready
|
||||||
|
0x27ac evt_invite_flow_not_ready
|
||||||
|
0x27ad inviteFlowAbortSaveLoad
|
||||||
|
0x27ae evt_verify_invite_nav_cleanup
|
||||||
|
0x27af downloadComplete
|
||||||
|
0x27b0 downloadFailed
|
||||||
|
0x27b1 spevnetNotAvailable
|
||||||
|
0x27b2 spevnetNotRegistered
|
||||||
|
0x27b3 spevnetNotRegisteredBeta
|
||||||
|
0x27b4 userBanned
|
||||||
|
0x27b5 showExitConfirmPopup
|
||||||
|
0x27b6 hideExitConfirmPopup
|
||||||
|
0x27b7 confirmExit
|
||||||
|
0x27b8 showRegisterConfirmPopup
|
||||||
|
0x27b9 hideRegisterConfirmPopup
|
||||||
|
0x27ba setStadiumPosition
|
||||||
|
0x27bb liveCompCountryDecision
|
||||||
|
0x27bc liveCompAllCountriesSelect
|
||||||
|
0x27bd liveCompLimitedCountriesSelect
|
||||||
|
0x27be liveCompAdvanceToTeamSelect
|
||||||
|
0x27bf liveCompRegistrationConfirm
|
||||||
|
0x27c0 liveCompEventListSuccess
|
||||||
|
0x27c1 liveCompEventListFail
|
||||||
|
0x27c2 postMatchHighlightExit
|
||||||
|
0x27c3 postMatchHighlightComplete
|
||||||
|
0x27c4 postMatchHighlightSelect
|
||||||
|
0x27c5 postMatchHighlightReelSelect
|
||||||
|
0x27c6 postMatchHighlightIRSelect
|
||||||
|
0x27cf leaveUpsell
|
||||||
|
0x27d0 purchase
|
||||||
|
0x27d1 advanceFromPMA
|
||||||
|
0x27d2 evt_transitionToPMADone
|
||||||
|
0x27d3 cutSceneCommand
|
||||||
|
0x27d4 cutScenePlay
|
||||||
|
0x27d5 loadCutScenesSubLevel
|
||||||
|
0x27d6 unloadCutScenesSubLevel
|
||||||
|
0x27d7 evt_enable_skip_cutscene
|
||||||
|
0x27d8 gmCutSceneStarted
|
||||||
|
0x27d9 gmCutSceneEnded
|
||||||
|
0x27da gmCutScenesSublevelLoaded
|
||||||
|
0x27db gmCutScenesSublevelUnloaded
|
||||||
|
0x27dc gmAirlockToGameplayEnded
|
||||||
|
0x27dd gmAirlockLoadComplete
|
||||||
|
0x27de evt_quit_to_training_hub
|
||||||
|
0x27e0 evt_training_allow_advance_to_game
|
||||||
|
0x27e1 checkOriginConnected
|
||||||
|
0x27e2 OriginIsOnline
|
||||||
|
0x27e3 OriginIsOffline
|
||||||
|
0x27e4 OIGOpened
|
||||||
|
0x27e5 OIGClosed
|
||||||
|
0x27e6 overrideOnlineStadium
|
||||||
|
0x27e7 smLoadFEStadium
|
||||||
|
0x27e8 smActivateFreeRoam
|
||||||
|
0x27e9 smGameOver
|
||||||
|
0x27ea smScenePrime
|
||||||
|
0x27eb smScenePrimeAndPrep
|
||||||
|
0x27ec smScenePause
|
||||||
|
0x27ed smSceneResume
|
||||||
|
0x27ee smMoment
|
||||||
|
0x27ef smMomentRepeat
|
||||||
|
0x27f0 smMomentComplete
|
||||||
|
0x27f1 smExitMomentState
|
||||||
|
0x27f2 smOnPlayScene
|
||||||
|
0x27f3 smConversation
|
||||||
|
0x27f4 smConversationComplete
|
||||||
|
0x27f5 smConversationNotification
|
||||||
|
0x27f6 smConversationNotificationComplete
|
||||||
|
0x27f7 smGameplayStartLoad
|
||||||
|
0x27f8 smGameplayLoadOver
|
||||||
|
0x27f9 smGameplayStart
|
||||||
|
0x27fa smGameplayOver
|
||||||
|
0x27fb smGameplayPause
|
||||||
|
0x27fc smGameplayResume
|
||||||
|
0x27ff smTweetConsume
|
||||||
|
0x2800 smHeroLoanedOut
|
||||||
|
0x2801 smSetupAcademyMatch
|
||||||
|
0x2802 smSetupAcademyTeams
|
||||||
|
0x2803 smStartIntroFlow
|
||||||
|
0x2804 smStartSeason
|
||||||
|
0x2805 smPlayMatch
|
||||||
|
0x2806 smEndMatch
|
||||||
|
0x2807 smGetTrainingSet
|
||||||
|
0x2808 smEnterTrainingTeamHub
|
||||||
|
0x2809 smEnterTraining
|
||||||
|
0x280a smPlayTrainingSessionVO
|
||||||
|
0x280b smPrepareTraining
|
||||||
|
0x280c smPlayTraining
|
||||||
|
0x280d smStopTraining
|
||||||
|
0x280e smStartSkillGame
|
||||||
|
0x280f smSimTraining
|
||||||
|
0x2810 smEndTraining
|
||||||
|
0x2811 smSave
|
||||||
|
0x2812 smAutoSave
|
||||||
|
0x2814 smLoad
|
||||||
|
0x2815 smSetScreenFlowLocation
|
||||||
|
0x2816 smGetScreenFlowLocation
|
||||||
|
0x2817 smGetHomeHubLocation
|
||||||
|
0x2818 smGetHeroLeague
|
||||||
|
0x2819 smCompleteMatchday
|
||||||
|
0x281a smEndInterviewPeriod
|
||||||
|
0x281b smHeroRemovedFromMatch
|
||||||
|
0x281c smEpisodicUploadCheck
|
||||||
|
0x281d smRetryEpisodicUpload
|
||||||
|
0x281e smNotifyMatchNotPlayed
|
||||||
|
0x281f matchFlowStart
|
||||||
|
0x2820 matchFlowHalftime
|
||||||
|
0x2821 matchFlowPostgame
|
||||||
|
0x2822 matchFlowEnd
|
||||||
|
0x2823 enterGameplay
|
||||||
|
0x2824 leaveGameplay
|
||||||
|
0x2825 forfeitMatch
|
||||||
|
0x2826 matchSetType
|
||||||
|
0x2827 simMatch
|
||||||
|
0x2828 simStarted
|
||||||
|
0x2829 simStopped
|
||||||
|
0x282a fbStartFlowEvent
|
||||||
|
0x282b stopSavedInput
|
||||||
|
0x282c changeSonyStoreBrowseMode
|
||||||
|
0x282d trialCheck
|
||||||
|
0x282e gotoTrialUpsell
|
||||||
|
0x754d retrieveManagerQuestData
|
||||||
|
0x7560 futWidgetShow
|
||||||
|
0x7561 futWidgetHide
|
||||||
|
0x7562 futWidgetLoad
|
||||||
|
0x7563 futWidgetUnload
|
||||||
|
0x7567 inviteAcceptedFUT
|
||||||
|
0x7568 futAddCriticalSection
|
||||||
|
0x7569 futRemoveCriticalSection
|
||||||
|
0x7572 exitDraftMode
|
||||||
|
0x7579 useSavedMatchData
|
||||||
|
0x757a useSavedMatchKits
|
||||||
|
0x7580 exitSbcMode
|
||||||
|
0x7587 setFUTServerEnvironment
|
||||||
|
0x9cc1 discardTeamSheet
|
||||||
|
0x9cc1 resetReady
|
||||||
|
0x9cd0 showKeyboard
|
||||||
@@ -1,11 +1,37 @@
|
|||||||
# Copy to .env in this directory. Required for remote deployment.
|
# Copy to .env in this directory. Required for remote deployment.
|
||||||
#
|
#
|
||||||
# OPENFUT_ADVERTISE — the address of THIS host as seen from the game machine
|
# OPENFUT_ADVERTISE — the IP address of THIS host as seen from the game machine
|
||||||
# (105). The responders advertise it to the client for every next hop (Blaze,
|
# (105). Responders advertise it for Blaze, UTAS, telemetry, and QoS.
|
||||||
# roster, UTAS, POW). Compose refuses to start without it.
|
OPENFUT_ADVERTISE=203.0.113.10 # <- REPLACE with this host's LAN IP
|
||||||
OPENFUT_ADVERTISE=10.10.0.120
|
|
||||||
|
|
||||||
# OPENFUT_BIND — address the listeners bind inside the container.
|
# OPENFUT_BIND — address the listeners bind inside the container.
|
||||||
# Defaults to 0.0.0.0 (container-facing); the original all-on-localhost flow
|
# Defaults to 0.0.0.0 (container-facing); the original all-on-localhost flow
|
||||||
# uses the loopback default baked into the responders when unset.
|
# uses the loopback default baked into the responders when unset.
|
||||||
OPENFUT_BIND=0.0.0.0
|
OPENFUT_BIND=0.0.0.0
|
||||||
|
|
||||||
|
# FIFA17's roster verifier accepts dNSName SANs but ignores iPAddress SANs.
|
||||||
|
# Advertise the certificate's DNS identity, then resolve that one hostname to
|
||||||
|
# OPENFUT_ADVERTISE on the client without changing the URL or certificate.
|
||||||
|
OPENFUT_ROSTER_HOST=winter15.gosredirector.ea.com:8081
|
||||||
|
|
||||||
|
# OPENFUT_SERVERS — which Python responders Docker runs (space/comma separated).
|
||||||
|
# Default (unset) = the server-side set: "blaze roster utas pow".
|
||||||
|
#
|
||||||
|
# This host is the SERVER (.120). Docker runs ONLY components that have NOT been
|
||||||
|
# migrated to a Rust host. During migration the Rust hosts (redirector / roster
|
||||||
|
# / utas) run OUTSIDE Docker; as each Python component is replaced, remove its
|
||||||
|
# name here so the two never serve the same role at once.
|
||||||
|
# blaze Blaze redirector + main + nucleus (bundled) :42127 :42130 :42131
|
||||||
|
# roster FUT roster-update XML :8081
|
||||||
|
# utas FUT/UTAS RS4 API :8099
|
||||||
|
# (Rust utas-host still proxies its non-/club routes here for now)
|
||||||
|
# pow POW / EASFC :8094 (+ content :8080)
|
||||||
|
# lsx Origin LSX bootstrap :4216
|
||||||
|
# CLIENT-SIDE: LSX runs on the game machine (.105) with autopatch, NOT
|
||||||
|
# on this server. Leave it OUT unless client and server share one box.
|
||||||
|
#
|
||||||
|
# Example — Rust already owns roster, so Docker should not also serve it:
|
||||||
|
# OPENFUT_SERVERS=blaze utas pow
|
||||||
|
# When you drop a component, also stop advertising / DNAT'ing its port to this
|
||||||
|
# container so the client is routed to the Rust host instead.
|
||||||
|
#OPENFUT_SERVERS=blaze roster utas pow
|
||||||
|
|||||||
@@ -37,17 +37,21 @@ RUN set -eu; \
|
|||||||
|
|
||||||
COPY data/ /app/data/
|
COPY data/ /app/data/
|
||||||
|
|
||||||
# Redirector TLS cert (CN/SAN = winter15.gosredirector.ea.com). ProtoSSL
|
# Redirector/roster TLS certificate. FIFA17's roster verifier compares only
|
||||||
# cert-verify is patched client-side, so a self-signed cert is fine. The pair is
|
# dNSName SAN entries, so deployment advertises winter15.gosredirector.ea.com
|
||||||
# git-ignored (*.pem/*.key); regenerate if absent so a fresh checkout builds
|
# through OPENFUT_ROSTER_HOST and resolves that hostname on the client. The
|
||||||
# without extra steps.
|
# entrypoint validates this stable certificate; it never reissues it for an IP
|
||||||
|
# SAN that the verifier ignores.
|
||||||
|
#
|
||||||
|
# OpenSSL remains in the image both to create the git-ignored keypair on a fresh
|
||||||
|
# checkout and to validate the configured DNS identity at startup.
|
||||||
|
RUN apt-get update && apt-get install -y --no-install-recommends openssl && \
|
||||||
|
rm -rf /var/lib/apt/lists/*
|
||||||
RUN if [ ! -s tools/redir_cert.pem ] || [ ! -s tools/redir_key.pem ]; then \
|
RUN if [ ! -s tools/redir_cert.pem ] || [ ! -s tools/redir_key.pem ]; then \
|
||||||
apt-get update && apt-get install -y --no-install-recommends openssl && \
|
|
||||||
openssl req -x509 -newkey rsa:2048 -nodes \
|
openssl req -x509 -newkey rsa:2048 -nodes \
|
||||||
-keyout tools/redir_key.pem -out tools/redir_cert.pem \
|
-keyout tools/redir_key.pem -out tools/redir_cert.pem \
|
||||||
-days 3650 -subj "/CN=winter15.gosredirector.ea.com" \
|
-days 3650 -subj "/CN=winter15.gosredirector.ea.com" \
|
||||||
-addext "subjectAltName=DNS:winter15.gosredirector.ea.com,DNS:*.gosredirector.ea.com,DNS:*.ea.com" && \
|
-addext "subjectAltName=DNS:winter15.gosredirector.ea.com,DNS:*.gosredirector.ea.com,DNS:*.ea.com,IP:127.0.0.1"; \
|
||||||
rm -rf /var/lib/apt/lists/*; \
|
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Bake a dataset manifest so every image is self-identifying.
|
# Bake a dataset manifest so every image is self-identifying.
|
||||||
|
|||||||
@@ -20,13 +20,15 @@
|
|||||||
# after these first redirected contacts the game is handed <SERVER_IP> for every
|
# after these first redirected contacts the game is handed <SERVER_IP> for every
|
||||||
# later hop (Blaze main, roster, UTAS, telemetry) and dials the server directly.
|
# later hop (Blaze main, roster, UTAS, telemetry) and dials the server directly.
|
||||||
#
|
#
|
||||||
# Usage: sudo OPENFUT_SERVER=10.10.0.120 ./client_arm.sh
|
# Usage: sudo OPENFUT_SERVER=203.0.113.10 ./client_arm.sh
|
||||||
# (re-run after every reboot; the sysctl/iptables state is volatile)
|
# (re-run after every reboot; the sysctl/iptables state is volatile)
|
||||||
# ============================================================================
|
# ============================================================================
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
SERVER="${OPENFUT_SERVER:?set OPENFUT_SERVER to the backend host IP, e.g. 10.10.0.120}"
|
SERVER="${OPENFUT_SERVER:?set OPENFUT_SERVER to the backend host IP, e.g. 203.0.113.10}"
|
||||||
GOS_EA_IP="159.153.51.20" # winter15.gosredirector.ea.com (hardcoded in FIFA17)
|
GOS_EA_IP="159.153.51.20" # winter15.gosredirector.ea.com (hardcoded in FIFA17)
|
||||||
|
UTAS_HOST="easw.easports.com" # dead UTAS host baked into CardsDLL
|
||||||
|
UTAS_RE="${UTAS_HOST//./\\.}" # same, safe to embed in a regex
|
||||||
|
|
||||||
if [ "$(id -u)" -ne 0 ]; then
|
if [ "$(id -u)" -ne 0 ]; then
|
||||||
echo "!! must run as root (sudo). Re-run: sudo OPENFUT_SERVER=$SERVER $0" >&2
|
echo "!! must run as root (sudo). Re-run: sudo OPENFUT_SERVER=$SERVER $0" >&2
|
||||||
@@ -55,13 +57,46 @@ iptables -t nat -A POSTROUTING -p tcp -d "$SERVER" --dport 42127 -j MASQUERADE
|
|||||||
# 3) Point the dead hardcoded UTAS host at the server. The port (8099) is carried
|
# 3) Point the dead hardcoded UTAS host at the server. The port (8099) is carried
|
||||||
# in the game's own URL, so only the name needs redirecting. Remove any prior
|
# in the game's own URL, so only the name needs redirecting. Remove any prior
|
||||||
# OpenFUT-managed line (loopback or other server) and write the current one.
|
# OpenFUT-managed line (loopback or other server) and write the current one.
|
||||||
sed -i '/[[:space:]]easw\.easports\.com\b.*# openfut$/d' /etc/hosts
|
sed -i "/[[:space:]]${UTAS_RE}\b.*# openfut\$/d" /etc/hosts
|
||||||
printf '%s\teasw.easports.com\t# openfut\n' "$SERVER" >> /etc/hosts
|
printf '%s\t%s\t# openfut\n' "$SERVER" "$UTAS_HOST" >> /etc/hosts
|
||||||
|
|
||||||
echo "[client_arm] --- armed ---"
|
echo "[client_arm] --- armed ---"
|
||||||
sysctl kernel.yama.ptrace_scope
|
sysctl kernel.yama.ptrace_scope
|
||||||
iptables -t nat -L OUTPUT -n | grep -i "$GOS_EA_IP" || echo " (DNAT missing!)"
|
iptables -t nat -L OUTPUT -n | grep -i "$GOS_EA_IP" || echo " (DNAT missing!)"
|
||||||
grep 'easw.easports.com' /etc/hosts && echo " /etc/hosts ok" || echo " (/etc/hosts easw missing!)"
|
|
||||||
|
# Verify the hosts entry by EFFECT, not by presence.
|
||||||
|
#
|
||||||
|
# glibc returns the FIRST match in /etc/hosts, so our line can be written
|
||||||
|
# correctly and still lose to an earlier one -- and the sed above only removes
|
||||||
|
# lines this script wrote (`# openfut`), so re-running never clears a foreign
|
||||||
|
# one. The old check here was `grep easw /etc/hosts && echo ok`, which passed on
|
||||||
|
# the shadowing line itself and reported success while resolution was wrong.
|
||||||
|
#
|
||||||
|
# Observed on 2026-08-11: a leftover `127.0.0.1 easw.easports.com` from the
|
||||||
|
# single-machine era shadowed the OpenFUT line, and every re-run said "ok".
|
||||||
|
resolved="$(getent ahosts "$UTAS_HOST" 2>/dev/null | awk '{print $1}' | sort -u | tr '\n' ' ')"
|
||||||
|
# SERVER may be a hostname, so compare address-to-address rather than comparing
|
||||||
|
# the literal string against resolved IPs (which would warn spuriously).
|
||||||
|
server_ips="$(getent ahosts "$SERVER" 2>/dev/null | awk '{print $1}' | sort -u)"
|
||||||
|
[ -n "$server_ips" ] || server_ips="$SERVER"
|
||||||
|
match=0
|
||||||
|
for ip in $server_ips; do
|
||||||
|
printf '%s' "$resolved" | grep -qw -- "$ip" && match=1
|
||||||
|
done
|
||||||
|
if [ "$match" -eq 1 ]; then
|
||||||
|
echo " /etc/hosts ok ($UTAS_HOST -> $resolved)"
|
||||||
|
else
|
||||||
|
echo
|
||||||
|
echo " !! WARNING: $UTAS_HOST resolves to [$resolved], not $SERVER."
|
||||||
|
echo " An earlier /etc/hosts line is shadowing the OpenFUT one:"
|
||||||
|
grep -nE "^[[:space:]]*[^#].*[[:space:]]${UTAS_RE}([[:space:]]|\$)" /etc/hosts \
|
||||||
|
| grep -v '# openfut$' | sed 's/^/ /' || true
|
||||||
|
echo
|
||||||
|
echo " Not fatal: the responders advertise $SERVER, so the game stops using"
|
||||||
|
echo " this name after the first hop. Worth removing the line above anyway."
|
||||||
|
echo " Lines are listed rather than deleted -- this script will not remove"
|
||||||
|
echo " /etc/hosts entries it did not write."
|
||||||
|
fi
|
||||||
echo
|
echo
|
||||||
echo "[client_arm] Next: start the LOCAL pieces (LSX + autopatch) with client_local.sh,"
|
echo "[client_arm] Next: start the LOCAL pieces (LSX + autopatch) with client_local.sh,"
|
||||||
echo " ensure the container is up on $SERVER, then launch FIFA 17."
|
echo " ensure the container is up on $SERVER, then launch FIFA 17."
|
||||||
|
|||||||
@@ -3,9 +3,9 @@
|
|||||||
# cp .env.example .env # set OPENFUT_ADVERTISE to THIS host's LAN IP
|
# cp .env.example .env # set OPENFUT_ADVERTISE to THIS host's LAN IP
|
||||||
# docker compose up -d --build
|
# docker compose up -d --build
|
||||||
#
|
#
|
||||||
# Brings up the 5 responders the game dials. OPENFUT_ADVERTISE is the address
|
# Brings up the 5 responders the game dials. OPENFUT_ADVERTISE is the server IP
|
||||||
# the servers hand the client (105) for every next hop (Blaze, roster, UTAS,
|
# handed out for Blaze, UTAS, telemetry, and QoS; OPENFUT_ROSTER_HOST is the
|
||||||
# POW) and is required — there is no silent loopback fallback in remote mode.
|
# certificate DNS identity handed out for roster HTTPS.
|
||||||
#
|
#
|
||||||
# The client (105) still needs its first-hop redirect (hook or DNAT) plus
|
# The client (105) still needs its first-hop redirect (hook or DNAT) plus
|
||||||
# autopatch.py running locally; see client_arm.sh and the FIFARUNBOOK.
|
# autopatch.py running locally; see client_arm.sh and the FIFARUNBOOK.
|
||||||
@@ -24,7 +24,10 @@ services:
|
|||||||
OPENFUT_BIND: "${OPENFUT_BIND:-0.0.0.0}"
|
OPENFUT_BIND: "${OPENFUT_BIND:-0.0.0.0}"
|
||||||
# Address advertised to the client for the next hop. MUST be this host's
|
# Address advertised to the client for the next hop. MUST be this host's
|
||||||
# LAN IP as seen from the game machine (105). Required (see .env.example).
|
# LAN IP as seen from the game machine (105). Required (see .env.example).
|
||||||
OPENFUT_ADVERTISE: "${OPENFUT_ADVERTISE:?set OPENFUT_ADVERTISE in .env to this host's LAN IP, e.g. 10.10.0.120}"
|
OPENFUT_ADVERTISE: "${OPENFUT_ADVERTISE:?set OPENFUT_ADVERTISE in .env to this host's LAN IP, e.g. 203.0.113.10}"
|
||||||
|
# FIFA17 roster TLS matches only certificate dNSName SANs. The client must
|
||||||
|
# resolve this hostname to OPENFUT_ADVERTISE.
|
||||||
|
OPENFUT_ROSTER_HOST: "${OPENFUT_ROSTER_HOST:-winter15.gosredirector.ea.com:8081}"
|
||||||
# POW content advertises port 8080 by default, which collides with the
|
# POW content advertises port 8080 by default, which collides with the
|
||||||
# openfut-core publish on this host. Remap it to 8085 on the host and
|
# openfut-core publish on this host. Remap it to 8085 on the host and
|
||||||
# advertise the remapped endpoint.
|
# advertise the remapped endpoint.
|
||||||
@@ -36,10 +39,14 @@ services:
|
|||||||
FUT_PROFILE_ROOT: "/state/accounts"
|
FUT_PROFILE_ROOT: "/state/accounts"
|
||||||
FUT_SETTINGS: "off"
|
FUT_SETTINGS: "off"
|
||||||
FUT_MODES: "1"
|
FUT_MODES: "1"
|
||||||
|
# Which Python responders this SERVER runs. Default excludes lsx (that is
|
||||||
|
# a client-side responder — see below). Drop a name once it is migrated to
|
||||||
|
# a Rust host (run outside Docker) so the two never overlap. See .env.example.
|
||||||
|
OPENFUT_SERVERS: "${OPENFUT_SERVERS:-blaze roster utas pow}"
|
||||||
volumes:
|
volumes:
|
||||||
- "../state:/state"
|
- "../state:/state"
|
||||||
ports:
|
ports:
|
||||||
- "4216:4216" # LSX (Origin bootstrap)
|
- "4216:4216" # LSX — CLIENT-SIDE (.105); only used if lsx is enabled for all-on-one-box
|
||||||
- "42127:42127" # Blaze redirector (TLS)
|
- "42127:42127" # Blaze redirector (TLS)
|
||||||
- "42130:42130" # Blaze main
|
- "42130:42130" # Blaze main
|
||||||
- "42131:42131" # Nucleus OAuth stub
|
- "42131:42131" # Nucleus OAuth stub
|
||||||
|
|||||||
@@ -8,25 +8,39 @@
|
|||||||
# autopatch.py is NOT run here: it patches the FIFA17.exe process memory and must
|
# autopatch.py is NOT run here: it patches the FIFA17.exe process memory and must
|
||||||
# run on the box the game runs on.
|
# run on the box the game runs on.
|
||||||
#
|
#
|
||||||
# Address behaviour is driven by two env vars (see each responder):
|
# Address behaviour is driven by three env vars (see each responder):
|
||||||
# OPENFUT_BIND bind address for every listener (container: 0.0.0.0)
|
# OPENFUT_BIND bind address for every listener (container: 0.0.0.0)
|
||||||
# OPENFUT_ADVERTISE address handed to the client for the next hop
|
# OPENFUT_ADVERTISE IP address handed out for Blaze, UTAS, telemetry, and QoS
|
||||||
# (the server's LAN IP, e.g. 10.10.0.120)
|
# OPENFUT_ROSTER_HOST certificate DNS host:port handed out for roster HTTPS
|
||||||
# ============================================================================
|
# ============================================================================
|
||||||
set -uo pipefail
|
set -uo pipefail
|
||||||
cd "$(dirname "$(readlink -f "$0")")/tools"
|
cd "$(dirname "$(readlink -f "$0")")/tools"
|
||||||
|
|
||||||
BIND="${OPENFUT_BIND:-0.0.0.0}"
|
BIND="${OPENFUT_BIND:-0.0.0.0}"
|
||||||
ADV="${OPENFUT_ADVERTISE:?OPENFUT_ADVERTISE must be set to the server LAN IP (e.g. 10.10.0.120)}"
|
ADV="${OPENFUT_ADVERTISE:?OPENFUT_ADVERTISE must be set to the server LAN IP (e.g. 203.0.113.10)}"
|
||||||
|
ROSTER_HOST="${OPENFUT_ROSTER_HOST:-winter15.gosredirector.ea.com:8081}"
|
||||||
export OPENFUT_BIND="$BIND"
|
export OPENFUT_BIND="$BIND"
|
||||||
export OPENFUT_ADVERTISE="$ADV"
|
export OPENFUT_ADVERTISE="$ADV"
|
||||||
|
export OPENFUT_ROSTER_HOST="$ROSTER_HOST"
|
||||||
# POW keys advertised by blaze must also point at the server, not loopback.
|
# POW keys advertised by blaze must also point at the server, not loopback.
|
||||||
export POW_HOST="${POW_HOST:-$ADV:8094}"
|
export POW_HOST="${POW_HOST:-$ADV:8094}"
|
||||||
export POW_CONTENT_HOST="${POW_CONTENT_HOST:-$ADV:8080}"
|
export POW_CONTENT_HOST="${POW_CONTENT_HOST:-$ADV:8080}"
|
||||||
export POW_ADDR="${POW_ADDR:-$BIND:8094}"
|
export POW_ADDR="${POW_ADDR:-$BIND:8094}"
|
||||||
export POW_CONTENT_ADDR="${POW_CONTENT_ADDR:-$BIND:8080}"
|
export POW_CONTENT_ADDR="${POW_CONTENT_ADDR:-$BIND:8080}"
|
||||||
|
|
||||||
echo "[openfut] bind=$BIND advertise=$ADV"
|
echo "[openfut] bind=$BIND advertise=$ADV roster=$ROSTER_HOST"
|
||||||
|
|
||||||
|
# FIFA17's roster verifier compares only dNSName SAN entries. It ignores a valid
|
||||||
|
# iPAddress SAN when the advertised URL contains an IP literal, so certificate
|
||||||
|
# regeneration cannot fix that URL. Keep the certificate stable and fail startup
|
||||||
|
# if the configured roster hostname is not already one of its DNS identities.
|
||||||
|
CERT=redir_cert.pem
|
||||||
|
ROSTER_NAME="${ROSTER_HOST%%:*}"
|
||||||
|
if ! openssl x509 -in "$CERT" -noout -checkhost "$ROSTER_NAME" >/dev/null 2>&1; then
|
||||||
|
echo "[openfut] FATAL: TLS cert does not cover roster hostname $ROSTER_NAME" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
echo "[openfut] roster certificate matches $ROSTER_NAME; fingerprint: $(openssl x509 -in "$CERT" -noout -fingerprint -sha256)"
|
||||||
|
|
||||||
# name script extra-env
|
# name script extra-env
|
||||||
declare -a SERVERS=(
|
declare -a SERVERS=(
|
||||||
@@ -37,10 +51,40 @@ declare -a SERVERS=(
|
|||||||
"pow|pow_server.py|-"
|
"pow|pow_server.py|-"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
# ── Component selection ──────────────────────────────────────────────────────
|
||||||
|
# OPENFUT_SERVERS picks which Python responders run (space- or comma-separated).
|
||||||
|
# This container is the SERVER side (.120). It serves ONLY components that have
|
||||||
|
# NOT been migrated to a Rust host — as each moves to Rust (which runs OUTSIDE
|
||||||
|
# Docker during migration), drop its name so the two never serve the same role.
|
||||||
|
# blaze Blaze redirector + main + nucleus (bundled) :42127 :42130 :42131
|
||||||
|
# roster FUT roster-update XML :8081
|
||||||
|
# utas FUT/UTAS RS4 API :8099
|
||||||
|
# (the Rust utas-host currently reverse-proxies its non-/club routes
|
||||||
|
# back here, so keep this enabled until UTAS is fully migrated)
|
||||||
|
# pow POW / EASFC :8094 (+ content :8080)
|
||||||
|
# lsx Origin LSX bootstrap :4216
|
||||||
|
# CLIENT-SIDE — LSX runs on the game machine (.105) with autopatch,
|
||||||
|
# NOT on the server. Excluded by default; enable ONLY for an
|
||||||
|
# all-on-one-box dev setup where client and server share a host.
|
||||||
|
OPENFUT_SERVERS="${OPENFUT_SERVERS:-blaze roster utas pow}"
|
||||||
|
want=" ${OPENFUT_SERVERS//,/ } "
|
||||||
|
known=" lsx blaze roster utas pow "
|
||||||
|
for w in $want; do
|
||||||
|
case "$known" in
|
||||||
|
*" $w "*) ;;
|
||||||
|
*) echo "[openfut] unknown component '$w' in OPENFUT_SERVERS (valid: lsx blaze roster utas pow)" >&2; exit 2 ;;
|
||||||
|
esac
|
||||||
|
done
|
||||||
|
echo "[openfut] servers=$OPENFUT_SERVERS"
|
||||||
|
|
||||||
pids=()
|
pids=()
|
||||||
names=()
|
names=()
|
||||||
for entry in "${SERVERS[@]}"; do
|
for entry in "${SERVERS[@]}"; do
|
||||||
IFS='|' read -r name script env <<<"$entry"
|
IFS='|' read -r name script env <<<"$entry"
|
||||||
|
case "$want" in
|
||||||
|
*" $name "*) ;;
|
||||||
|
*) echo "[openfut] skipping $name (not in OPENFUT_SERVERS)"; continue ;;
|
||||||
|
esac
|
||||||
envprefix=""; [ "$env" != "-" ] && envprefix="env $env"
|
envprefix=""; [ "$env" != "-" ] && envprefix="env $env"
|
||||||
echo "[openfut] starting $name ($script)"
|
echo "[openfut] starting $name ($script)"
|
||||||
# shellcheck disable=SC2086
|
# shellcheck disable=SC2086
|
||||||
@@ -49,6 +93,11 @@ for entry in "${SERVERS[@]}"; do
|
|||||||
names+=("$name")
|
names+=("$name")
|
||||||
done
|
done
|
||||||
|
|
||||||
|
if [ "${#pids[@]}" -eq 0 ]; then
|
||||||
|
echo "[openfut] OPENFUT_SERVERS selected no components; nothing to run" >&2
|
||||||
|
exit 2
|
||||||
|
fi
|
||||||
|
|
||||||
# Propagate SIGTERM/SIGINT to children so `docker stop` is clean.
|
# Propagate SIGTERM/SIGINT to children so `docker stop` is clean.
|
||||||
term() {
|
term() {
|
||||||
echo "[openfut] shutting down…"
|
echo "[openfut] shutting down…"
|
||||||
|
|||||||
@@ -347,10 +347,17 @@ The client's own dialog names the class: "Search Type: Consumables Search".
|
|||||||
times a session with the PLAYER stat set, so the panel read seven zeros and never
|
times a session with the PLAYER stat set, so the panel read seven zeros and never
|
||||||
proceeded. Two rounds of item-shape work sat unrequested for want of a counter.
|
proceeded. Two rounds of item-shape work sat unrequested for want of a counter.
|
||||||
2. THE ROUTE IS GET club/consumables/<category>. Not club?type=, which a previous
|
2. THE ROUTE IS GET club/consumables/<category>. Not club?type=, which a previous
|
||||||
round shipped four arms for, and not the "/consumables/%s" template in .rdata,
|
round shipped four arms for. That path is a /club PREFIX, so a naive router
|
||||||
which the client has still never used. Worse, that path is a /club PREFIX, so it
|
falls it through to the generic route and answers the consumables screen with
|
||||||
fell through to the generic route and the consumables screen was answered with the
|
the 194-card player list.
|
||||||
194-card player list.
|
|
||||||
|
**CORRECTED 2026-08-21.** This item used to add "and not the
|
||||||
|
`/consumables/%s` template in .rdata, which the client has still never used".
|
||||||
|
That is false, and the same sentence is in commit `ccb736f`. It IS exactly
|
||||||
|
that template: action row 9 `ConsumablesSearch` carries base index 3 =
|
||||||
|
`ut/%s/club`, and `FUN_1801308c0` appends `/consumables/%s`. The base was
|
||||||
|
`ut/%s/club` all along, which is why the observed URL and the template look
|
||||||
|
like different things and are not.
|
||||||
3. THE ELEMENT IS A STACK WRAPPER, NOT AN ITEM. FutConsumablesSearchServerResponse
|
3. THE ELEMENT IS A STACK WRAPPER, NOT AN ITEM. FutConsumablesSearchServerResponse
|
||||||
(RS4 literal 0x1802222f8, factory 0x180130a10, vtable 0x180222200, deser +0x08 =
|
(RS4 literal 0x1802222f8, factory 0x180130a10, vtable 0x180222200, deser +0x08 =
|
||||||
0x180130d10, 6873 chars) reads itemData(0x16b) at the root like the club list, but
|
0x180130d10, 6873 chars) reads itemData(0x16b) at the root like the club list, but
|
||||||
@@ -402,21 +409,40 @@ the same mapping: balls 37, kits 35, stadium 36, badges 39, league logos 40.
|
|||||||
|
|
||||||
# Club items: what the research established, 2026-08-05
|
# Club items: what the research established, 2026-08-05
|
||||||
|
|
||||||
Researched after a guessed field crashed the client. Facts first, and the one thing
|
> **SUPERSEDED 2026-08-21 in part.** `docs/plan-2026-08-06-card-subsystem.md` is
|
||||||
still unknown is named as unknown.
|
> the authority for club items and for the `itemState` vocabulary; where this
|
||||||
|
> file and that one disagree, that one wins. The corrections are applied inline
|
||||||
|
> below and marked. The subtype question this section calls UNKNOWN is ANSWERED.
|
||||||
|
|
||||||
|
Researched after a guessed field crashed the client. Facts first.
|
||||||
|
|
||||||
## VERIFIED IN BINARY
|
## VERIFIED IN BINARY
|
||||||
|
|
||||||
1. THE CARDTYPE MAP IS EXACT. FUN_1800d8330 (714 chars, read in full) returns cardtype
|
1. THE CARDTYPE MAP IS EXACT. FUN_1800d8330 (714 chars, read in full) returns cardtype
|
||||||
9 for cardsubtypeid 0x1e, 0x1f, 0x91..0x96, 0xe7..0xe9 and 0xec, and nothing else.
|
9 for cardsubtypeid 0x1e, 0x1f, 0x91..0x96, 0xe7..0xe9 and 0xec, and nothing else.
|
||||||
fcc_misccards carries cardsubtype 231 = 0xe7, which anchors the 0xe7..0xe9 block to
|
fcc_misccards carries cardsubtype 231 = 0xe7, which anchors the 0xe7..0xe9 block to
|
||||||
misc cards. That leaves 0x1e, 0x1f and 0x91..0x96 for badges, kits, stadia, balls
|
misc cards.
|
||||||
and league logos.
|
|
||||||
2. ITEMSTATE CARRIES THE EQUIPPED STATE. The enum table at 0x180229d20 (stride 0x10)
|
**CORRECTED 2026-08-21.** The first half is right; the inference that followed
|
||||||
is: WAITING_FOR_GAME, inGame, forSale, offered, activeBadge, activeHomeKit,
|
it was wrong. It read "that leaves 0x1e, 0x1f and 0x91..0x96 for badges, kits,
|
||||||
activeAwayKit, activeBall, activeStadium, active. So an EQUIPPED club item is not a
|
stadia, balls and league logos". In fact `0x91..0x96` are TROPHIES, and three
|
||||||
|
of the five club families are **cardtype 7, not 9** — `FUN_1800d8330` contains
|
||||||
|
`case 9: case 10: case 0xb: return 7;`. Only ball (0x1e) and league logo
|
||||||
|
(0x1f) are cardtype 9.
|
||||||
|
2. ITEMSTATE CARRIES THE EQUIPPED STATE. So an EQUIPPED club item is not a
|
||||||
different subtype, it is the same item with itemState set to one of those five.
|
different subtype, it is the same item with itemState set to one of those five.
|
||||||
"free" is correct for owned-but-not-equipped, which is what we send.
|
|
||||||
|
**CORRECTED 2026-08-21.** The table starts at **`0x180229cc0`**, not
|
||||||
|
`0x180229d20` — the recorded address points into the MIDDLE of it, which is why
|
||||||
|
only ten rows were seen. The full vocabulary is TWELVE rows; the six missing
|
||||||
|
from the reading below are `invalid`, `free`, `WAITING_FOR_GAME`, `inGame`,
|
||||||
|
`forSale` and `offered`. Two further consequences the ten-row reading hid:
|
||||||
|
`WAITING_FOR_GAME` and `inGame` are genuine ALIASES (both decode to 2), and
|
||||||
|
OMITTING the key yields `0` = `invalid`, which is NOT the same as `free` — an
|
||||||
|
item left at 0 fails the squad builder's `state == 1 || state == 2` test. The
|
||||||
|
match is also CASE-SENSITIVE (measured 2026-08-21: the comparator is
|
||||||
|
`msvcr120.dll+0x3c330`, a plain `strncmp` with no case folding), so the casing
|
||||||
|
in the table is a contract. See `openfut-adapter-fifa17/src/fut/item_state.rs`.
|
||||||
3. CLUB ITEMS HAVE NO CATEGORY GROUP TABLE. Consumables have one at 0x180203260 (seven
|
3. CLUB ITEMS HAVE NO CATEGORY GROUP TABLE. Consumables have one at 0x180203260 (seven
|
||||||
codes: training, contracts, fitness, healing, playStyle, managerLeagueModifier,
|
codes: training, contracts, fitness, healing, playStyle, managerLeagueModifier,
|
||||||
position) and staff have one at 0x180203310 (five codes). There is no equivalent
|
position) and staff have one at 0x180203310 (five codes). There is no equivalent
|
||||||
@@ -427,16 +453,30 @@ still unknown is named as unknown.
|
|||||||
type=ball, type=equippables (the combined customisation view). Not the plural stat
|
type=ball, type=equippables (the combined customisation view). Not the plural stat
|
||||||
names, and not a club/<family> path.
|
names, and not a club/<family> path.
|
||||||
|
|
||||||
## STILL UNKNOWN, AND NOT GUESSED
|
## ANSWERED 2026-08-06 (was "STILL UNKNOWN, AND NOT GUESSED")
|
||||||
|
|
||||||
Which of 0x1e, 0x1f, 0x91..0x96 means ball versus stadium versus badge versus kit.
|
The question was "which of 0x1e, 0x1f, 0x91..0x96 means ball versus stadium versus
|
||||||
It is in none of the 149 dumped tables, there is no group table, and cardtype 9 has NO
|
badge versus kit". It was the wrong candidate set — three of the families are not
|
||||||
arm in the merge, so a wrong subtype cannot announce itself the way a coach's "DB
|
in it at all. The settled map:
|
||||||
Error" does. Two ways to settle it, in order of preference:
|
|
||||||
a. more RE: find the consumer that switches on subtype for a club item, most likely
|
| family | cardsubtypeid | cardtype | how the caption resolves |
|
||||||
in the equip path that writes itemState = activeBadge and friends;
|
|---|---|---|---|
|
||||||
b. FUT_CLUBITEMS=probe:<family>, which serves ONE family as eight items, one per
|
| kit | **9** | 7 | `TeamName_Abbr15_<teamid>` |
|
||||||
candidate subtype, so the screen names the right one.
|
| stadium | **10** | 7 | `StadiumName_<assetId>` |
|
||||||
|
| badge | **11** | 7 | `TeamName_Abbr15_<teamid>` |
|
||||||
|
| ball | **30** (0x1e) | 9 | no DB resolver; `FUT_UC_BALL` caption only |
|
||||||
|
| league logo | **31** (0x1f) | 9 | by elimination |
|
||||||
|
|
||||||
|
`0x91..0x96` are TROPHIES, not club items. Route (a) of the two proposals above is
|
||||||
|
what paid off — the consumer is the manager vtable slot `+0x498` =
|
||||||
|
`FUN_180119bd0`, dispatched when `item+0x4c == 7`. Route (b),
|
||||||
|
`FUT_CLUBITEMS=probe:<family>`, would have FAILED for three of the five families,
|
||||||
|
because its candidate set never contained 9, 10 or 11.
|
||||||
|
|
||||||
|
Kit, badge and stadium are served by OpenFUT today. Ball and league logo are
|
||||||
|
withheld: cardtype 9 has no database name resolver, so their name could only come
|
||||||
|
from `localizedName` on the wire, and that is not established as safe to send.
|
||||||
|
One residual probe remains, specified in `plan-2026-08-06-card-subsystem.md` §3.
|
||||||
|
|
||||||
## WHY THE CRASH HAPPENED, recorded so it is not repeated
|
## WHY THE CRASH HAPPENED, recorded so it is not repeated
|
||||||
|
|
||||||
@@ -447,3 +487,95 @@ taking its time and then dies. None of the three was needed to draw a card. Comp
|
|||||||
it, the response that crashed was type=equippables carrying 30 items across FIVE
|
it, the response that crashed was type=equippables carrying 30 items across FIVE
|
||||||
unverified subtypes at once, so even the crash taught us nothing about which subtype
|
unverified subtypes at once, so even the crash taught us nothing about which subtype
|
||||||
was wrong. Both are fixed: no extras, equippables withheld, one family per test.
|
was wrong. Both are fixed: no extras, equippables withheld, one family per test.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Field-map corrections (dated)
|
||||||
|
|
||||||
|
This file's earlier field notes predate the deserializer frame arithmetic. Where
|
||||||
|
they disagree with the table in `plan-2026-08-06-card-subsystem.md` §2, that
|
||||||
|
table wins — it is derived structurally (`FUN_18013fe00` builds the record as a
|
||||||
|
stack struct and hands `&local_188` to the merge, so `record_offset = 0x188 - X`)
|
||||||
|
rather than inferred backwards from an accessor.
|
||||||
|
|
||||||
|
```
|
||||||
|
CORRECTED 2026-08-06 (live diff + deserializer frame arithmetic, record_off = 0x188 - X):
|
||||||
|
+0x34 lastSalePrice (atom 0x185), published to Flash as BOUGHT_FOR
|
||||||
|
+0x48 owners (atom 0x207, u8; constructor default 0)
|
||||||
|
+0x49 TRADEABLE (atom 0x361 untradeable, u8, stored INVERTED; default 1)
|
||||||
|
+0x54 discard LEVEL (3/2/1 by rating >= 0x4b / >= 0x41), NOT an itemType enum
|
||||||
|
+0x5c itemState (atom 0x172 via FUN_180166660, u32)
|
||||||
|
+0x88 playStyle (atom 0x23f via FUN_180136480; only 0xfb..0x111 map to 1..0x17)
|
||||||
|
+0x90 loans (atom 0x19b) -- do not send; loans>0 with contract 0 greys MODIFY
|
||||||
|
+0xbe amount (atom 0x1b, u8) for cardsubtypeid 250..273 (chemistry styles)
|
||||||
|
+0xbf amount (atom 0x1b, u8) for the other consumable classes
|
||||||
|
+0xd9 localizedName (atom 0x19c, 0x38 bytes) for cardtype 9; +0xbc (0x1f) for cardtype 7
|
||||||
|
+0x111 description (atom 0xd1, 0x1f bytes) for cardtype 9; +0x10f for cardtype 7
|
||||||
|
+0x30 is a CLIENT timestamp from FUN_1800d84e0(), not a wire field
|
||||||
|
+0x60 pile is assigned by the owning list, not parsed; there is no 0x226 arm
|
||||||
|
itemType (atom 0x173) is parsed into a heap string and never stored
|
||||||
|
definitionId is NOT AN ATOM
|
||||||
|
```
|
||||||
|
|
||||||
|
**`+0x60`, extended 2026-08-21.** "Assigned by the owning list, not parsed" is
|
||||||
|
right. The pre-match kit selector gates on `+0x60 == 4` at `0x1801c34f2`, and no
|
||||||
|
instruction in CardsDLL stores that constant immediately (29 stores, constants
|
||||||
|
`{-2,0,1,908,0x3f800000}`), nor does FIFA17.exe across 79 MB.
|
||||||
|
Tool: `fifa17-recon/tools/kit_gate_probe.py`.
|
||||||
|
|
||||||
|
**CORRECTED 2026-08-23 (live, pid 8793, read-only `/proc/PID/mem`).** The
|
||||||
|
2026-08-21 entry went on to call the kit selector "a client dead end, not a
|
||||||
|
missing wire field", on the grounds that "every OTHER input to that gate is
|
||||||
|
already served". That conclusion is WITHDRAWN. It rested on two mistakes.
|
||||||
|
|
||||||
|
1. **`+0x60 == 4` does occur.** A live record reached the art-clone driver
|
||||||
|
`FUN_1801c3480` holding `+0x4c == 2`, `+0x60 == 4`. So the value arrives by
|
||||||
|
some path the immediate-store scan cannot see (register copy or computed),
|
||||||
|
and "nothing can ever satisfy the gate" is false. What the static scan
|
||||||
|
actually licenses is the narrower claim above.
|
||||||
|
2. **cardtype 7 was never verified to be produced at all.** The probe annotates
|
||||||
|
`cmp [rdi+0x4c], 7` with "<- we produce this". Nothing measured that. Its own
|
||||||
|
live half showed `{1: players, 0: staff}` -- i.e. zero cardtype-7 records --
|
||||||
|
and that was read as "the only thing missing is +0x60".
|
||||||
|
|
||||||
|
**What is actually measured now.** With the client parked on the kit selector,
|
||||||
|
scanning all 3047 MiB of readable process memory for the exact u32 values the
|
||||||
|
server sent:
|
||||||
|
|
||||||
|
```
|
||||||
|
resident (record-shaped, sane fields):
|
||||||
|
player resourceId 83906881 -> cardtype 1, itemState 1, teamid 243, +0x60 1
|
||||||
|
staff resourceId 9000081 -> cardtype 2
|
||||||
|
staff resourceId 3000083 -> cardtype 4, subtype 8
|
||||||
|
staff resourceId 1000509 -> cardtype 2, subtype 4, teamid 241
|
||||||
|
NOT resident, by resourceId AND by instance id, zero hits each:
|
||||||
|
kit 6300006 / 100004874 (cardsubtypeid 9)
|
||||||
|
kit 6400003 / 100004873 (cardsubtypeid 9)
|
||||||
|
badge 6000005 / 100004875 (cardsubtypeid 11)
|
||||||
|
stadium 6200000 / 100004876 (cardsubtypeid 10)
|
||||||
|
```
|
||||||
|
|
||||||
|
The client fetched `?type=kit` at 17:50:09 this session and the host logged
|
||||||
|
`total=2 emitted=2`. Both kits were delivered and NEITHER produced a record.
|
||||||
|
Every cardtype-7 family is absent while cardtype 1/2/4 are resident.
|
||||||
|
|
||||||
|
So the blocker is upstream of the `+0x60` gate: no cardtype-7 record is ever
|
||||||
|
created, therefore the club scan `FUN_1800d73d0` (`+0x4c==7 && +0x50==9 &&
|
||||||
|
`+0x5c in {101,102}`) has nothing to match, `KIT_DESC` never fires, and
|
||||||
|
`KITS_AVAILABLE` reads 0. Whether that is a bad wire shape (the cardtype-7 parse
|
||||||
|
arm wants `name`/`localizedName`/`description`, which OpenFUT does not send) or
|
||||||
|
cardtype-7 items being transient by design is NOT yet settled -- do not record
|
||||||
|
either as fact.
|
||||||
|
|
||||||
|
**Method note.** `kit_gate_probe.py`'s live half is unreliable as written: on
|
||||||
|
pid 8793 it printed "CardsDb is empty (no FUT session loaded)" while a byte scan
|
||||||
|
found 1966 resident players. Its structural chain is stale, so its record counts
|
||||||
|
(including the original "27 resident records") understate reality. Prefer the
|
||||||
|
value scan until the chain is re-derived.
|
||||||
|
|
||||||
|
**`definitionId is NOT AN ATOM`, confirmed a fourth way 2026-08-21.** Every real
|
||||||
|
atom name appears exactly once in CardsDLL's `.rdata` — `resourceId`,
|
||||||
|
`cardsubtypeid`, `itemState`, `assetId`, `cardassetid`, `rareflag`, `owners`,
|
||||||
|
`contract`, `discardValue`, `localizedName` — while `definitionId` is absent
|
||||||
|
entirely. It is still sent on the live-proven player path; it is inert, not
|
||||||
|
harmful, and has not been removed.
|
||||||
|
|||||||
@@ -0,0 +1,406 @@
|
|||||||
|
# The client's complete UTAS route surface
|
||||||
|
|
||||||
|
Read out of the running client's own `.rdata` on 2026-08-21 (pid 6580) with
|
||||||
|
`fifa17-recon/tools/url_template_probe.py`, then each route probed against
|
||||||
|
staging. This bounds the server: FIFA 17 cannot ask for a route that is not in
|
||||||
|
this list.
|
||||||
|
|
||||||
|
Staging's Python upstream is deliberately dead, so a `502` there means the Rust
|
||||||
|
host does not own the route — which makes the coverage column a measurement
|
||||||
|
rather than an audit of the source.
|
||||||
|
|
||||||
|
## Route templates in CardsDLL
|
||||||
|
|
||||||
|
`%s` is the sku segment, built from `game/%s` (`0x18021fac8`) → `game/fifa17`.
|
||||||
|
|
||||||
|
```
|
||||||
|
ut/auth ut/delete/auth
|
||||||
|
ut/%s/user ut/delete/%s/user ut/%s/user/list
|
||||||
|
ut/%s/club ut/%s/clubUser
|
||||||
|
ut/%s/item ut/%s/item/resource ut/delete/%s/item
|
||||||
|
ut/%s/defid
|
||||||
|
ut/%s/squad ut/delete/%s/squad ut/%s/squad/mode
|
||||||
|
ut/%s/purchased ut/%s/store ut/v2/%s/store
|
||||||
|
ut/%s/trade ut/delete/%s/trade
|
||||||
|
ut/%s/tradePile ut/%s/watchList ut/delete/%s/watchList
|
||||||
|
ut/%s/auctionhouse ut/%s/marketdata
|
||||||
|
ut/%s/match ut/%s/sbs
|
||||||
|
ut/%s/season ut/%s/season/user ut/%s/season/%%s/user
|
||||||
|
ut/%s/season/%%s/reset ut/%s/season/friendly
|
||||||
|
ut/%s/tournament ut/%s/tournament/user ut/delete/%s/tournament/user
|
||||||
|
ut/%s/champion ut/%s/draft/mode
|
||||||
|
ut/%s/leaderboards ut/%s/leaderboards/options
|
||||||
|
ut/%s/activeMessage ut/%s/livemessage
|
||||||
|
ut/%s/clientdata ut/%s/phishing ut/%s/captcha ut/%s/tfa
|
||||||
|
```
|
||||||
|
|
||||||
|
Suffixes appended to the above, not standalone routes:
|
||||||
|
`/consumables/%s`, `/items`, `/purchasegroup`, `/squadBuildingSets`,
|
||||||
|
`/challenge/%d/squad`, `/choices/manager`, `/purchase/mode/%d/draft`,
|
||||||
|
`/transfermarket?type=%s&start=%d&num=%d`.
|
||||||
|
|
||||||
|
## THE TRAP when reading this list
|
||||||
|
|
||||||
|
A literal in `.rdata` is a **fragment**, not necessarily a callable path. Probing
|
||||||
|
fragments bare manufactures fake gaps. Every one of these looked unserved and was
|
||||||
|
not:
|
||||||
|
|
||||||
|
| looked missing | actually |
|
||||||
|
|---|---|
|
||||||
|
| `clientdata` | real route is `clientdata/<key>`; served (`clientdata/userHubData` → 200) |
|
||||||
|
| `purchasegroup` | a suffix of `store`; `store/purchasegroup/all` is served |
|
||||||
|
| `sbs/challenges` | not a route; the real ones are `sbs/sets`, `sbs/setId/<n>/challenges`, `sbs/challenge/<n>` — all served |
|
||||||
|
| `squadBuildingSets` | not a route in the oracle either |
|
||||||
|
| `club/items` | `items/...` literals are ART ASSET paths, not UTAS |
|
||||||
|
| `item` | only ever PUT (move/pile) and DELETE (quick-sell) |
|
||||||
|
|
||||||
|
Check a candidate gap against `tools/utas_server.py`'s regex table before
|
||||||
|
believing it.
|
||||||
|
|
||||||
|
## Genuinely unserved, and why that is correct
|
||||||
|
|
||||||
|
* `squad/mode` — bare form is never used. The oracle only has Draft sub-paths
|
||||||
|
(`squad/mode/draft/state`, `squad/mode/<n>/draft/choices/*`). Draft is out of
|
||||||
|
scope, so this correctly stays on Python.
|
||||||
|
|
||||||
|
## Fixed by this measurement
|
||||||
|
|
||||||
|
Four handlers existed and were unreachable because `classify` never produced
|
||||||
|
their route, so every request fell through to Python. This is a **recurring
|
||||||
|
defect class** in `openfut-utas-host` — `season/list` and `watchList` were the
|
||||||
|
first two, and their fix comments are still in the file:
|
||||||
|
|
||||||
|
| route | handler | was |
|
||||||
|
|---|---|---|
|
||||||
|
| `captcha` | `handle_static_ack`, returns the oracle's exact `{encodedImg,sequence,sizeBeforeEncode}` | fell to Python |
|
||||||
|
| `tfa` / `livemessage` / `activeMessage` | `handle_static_ack`, `{}` | fell to Python |
|
||||||
|
| `tournament/user` | `FeatureOffEmpty`, `{}` — the oracle's answer with `FUT_MODES` off | fell to Python |
|
||||||
|
|
||||||
|
`Route`'s own doc comment already claimed the first four as "Rust-owned
|
||||||
|
UNCONDITIONAL", so the documentation had been wrong rather than the intent. All
|
||||||
|
five are byte-identical to the oracle, so claiming them is parity, not new
|
||||||
|
behaviour. Invisible in production (the upstream answers); a 502 on staging.
|
||||||
|
|
||||||
|
Two regression tests now pin the vocabularies —
|
||||||
|
`every_static_ack_tail_is_actually_routed` and
|
||||||
|
`the_disabled_mode_reads_are_all_claimed` — so a handler cannot go unreachable a
|
||||||
|
fifth time.
|
||||||
|
|
||||||
|
## No consumable apply endpoint exists
|
||||||
|
|
||||||
|
Support level L5 for consumables was open, with an inherited note saying there is
|
||||||
|
"no training/position/chemistry/manager-league endpoint at all". **The route
|
||||||
|
table confirms it from the binary**: there is no apply/training/position/
|
||||||
|
chemistry route anywhere in CardsDLL. The only owned-item mutations the client
|
||||||
|
can express are:
|
||||||
|
|
||||||
|
```
|
||||||
|
PUT ut/%s/item move / pile
|
||||||
|
DELETE ut/%s/item/<id> quick sell
|
||||||
|
POST ut/delete/%s/item bulk quick sell
|
||||||
|
PUT ut/%s/squad squad write
|
||||||
|
```
|
||||||
|
|
||||||
|
So applying a consumable is **not** a dedicated server route. If it reaches the
|
||||||
|
server at all it must ride `PUT ut/%s/item`, and L5/L6 should be pursued by
|
||||||
|
capturing that PUT's payload while applying a card — not by looking for an
|
||||||
|
endpoint that does not exist.
|
||||||
|
|
||||||
|
## FUT task vocabulary (2026-08-21, live)
|
||||||
|
|
||||||
|
The client drives UTAS through named TASKS, not just URLs. The task-name table
|
||||||
|
lives in CardsDLL `.rdata` as 0x20-byte inline slots holding MixedCase/UPPERCASE
|
||||||
|
pairs (`tools/apply_route_search.py`, controls `tradePile`/`ut/%s/item`/`squad`
|
||||||
|
all FOUND):
|
||||||
|
|
||||||
|
```
|
||||||
|
ViewCards AssingCard(sic) ApplyCard ApplyCardByRes
|
||||||
|
ActivateCard ConsumeCard DiscardCard DiscardCardByRes
|
||||||
|
DiscardACard MoveCard MoveCardByRes SwapCard
|
||||||
|
CreateMatch MatchReady DestroyMatch PlayGame ResetMatch KeepAlive
|
||||||
|
LoadCategoryDetails LoadSetChallenges StartChallenge LoadSquadChallenge
|
||||||
|
SaveSquadChallenge SubmitChallenge TagSets SetSbcData
|
||||||
|
TournamentList TournamentTeams SetUserInfo GetHistorical SetTutData ...
|
||||||
|
```
|
||||||
|
|
||||||
|
A descriptor table in `.data` pairs each name with a task id and a small setter
|
||||||
|
thunk, e.g. `ApplyCard` id **0x0d** at `0x1802cb170`, `ApplyCardByRes` id **0x0e**
|
||||||
|
at `0x1802cb1a0`. The thunks are `mov [rip+flag], cl; ret` (a per-task flag), NOT
|
||||||
|
request builders, so the request is assembled elsewhere keyed by task id.
|
||||||
|
|
||||||
|
**So consumable application IS a first-class client action (`ApplyCard` /
|
||||||
|
`ApplyCardByRes` / `ConsumeCard`), even though no `/apply` URL exists.** It
|
||||||
|
therefore rides an existing route. Which one is a one-capture question, and the
|
||||||
|
host now names every unclaimed request:
|
||||||
|
|
||||||
|
```
|
||||||
|
utas-host owner=PYTHON route=passthrough method=GET path=/ut/... body_len=N
|
||||||
|
```
|
||||||
|
|
||||||
|
## CONSUMABLE APPLY — LIVE_PROVEN (2026-08-21)
|
||||||
|
|
||||||
|
Captured end to end on staging, operator applying a bronze player contract:
|
||||||
|
|
||||||
|
```
|
||||||
|
POST /ut/game/fifa17/item/resource/5001004
|
||||||
|
{"apply":[{"id":100000003}]}
|
||||||
|
```
|
||||||
|
|
||||||
|
| element | value | where |
|
||||||
|
|---|---|---|
|
||||||
|
| source consumable | resource id `5001004` (player contract, subtype 201) | **path** |
|
||||||
|
| target item(s) | wire instance `100000003` (= squad slot 0 GK, resourceId 200389) | **body**, `apply[]` |
|
||||||
|
| verb | `POST` | |
|
||||||
|
|
||||||
|
**There is no `/apply` endpoint** — the apply re-uses `ut/%s/item/resource`, which
|
||||||
|
we already serve for **GET** (item-definition lookup). The **POST** verb on that
|
||||||
|
path is the mutation, and nothing claimed it, so it fell through to Python. This
|
||||||
|
is the wire form of the `ApplyCardByRes` task (id `0x0e`) -- "apply card **by
|
||||||
|
res**ource" -- which is why the source is a definition id rather than an instance
|
||||||
|
id.
|
||||||
|
|
||||||
|
`apply` is an ARRAY, so one consumable resource can name several targets in a
|
||||||
|
single request. Whether the client ever batches is unobserved.
|
||||||
|
|
||||||
|
Corroborating UI evidence from the same session: applying to a PLAYER offered
|
||||||
|
only the subtype-201 card and withheld both subtype-202 manager contracts,
|
||||||
|
independently confirming the `201 = player_contract / 202 = manager_contract`
|
||||||
|
split.
|
||||||
|
|
||||||
|
Fail-closed confirmed: with the upstream dead the request 502s and Core is left
|
||||||
|
EXACTLY unchanged (coins, owned count, and the source card all identical).
|
||||||
|
|
||||||
|
### Not yet known
|
||||||
|
* the **response shape** the client expects on success;
|
||||||
|
* the **effect** -- how many matches a contract grants. Our own catalog carries
|
||||||
|
`contract: 7` for `5001004`, documented as "the number of matches the card
|
||||||
|
grants", but that is observed profile data, i.e. INFERRED, not reversed. No
|
||||||
|
effect is implemented on that basis.
|
||||||
|
|
||||||
|
## Consumables category `development` is unmapped (client really asks)
|
||||||
|
|
||||||
|
The new passthrough/route logging caught the client requesting
|
||||||
|
|
||||||
|
```
|
||||||
|
GET /ut/game/fifa17/club/consumables/development -> outcome=unknown_category emitted=0
|
||||||
|
```
|
||||||
|
|
||||||
|
`consumable_families_for_category` has no `development` arm, so the screen is
|
||||||
|
served empty. The client demonstrably asks for it, which is exactly the condition
|
||||||
|
that function's own doc says should add an arm. Which families it should map to
|
||||||
|
is NOT guessed here.
|
||||||
|
|
||||||
|
### Success contract — STATIC_REVERSED (2026-08-22)
|
||||||
|
|
||||||
|
The apply completion handler is `0x180035520`:
|
||||||
|
|
||||||
|
```asm
|
||||||
|
0x180035529 mov ecx,DWORD PTR [rdx+0x1c] ; the ONLY field tested
|
||||||
|
0x18003552c test ecx,ecx
|
||||||
|
0x18003552e jne 0x18003555c ; nonzero -> FAILURE
|
||||||
|
0x18003553c lea rdx,[EVENT_CARDS_APPLY_CARD_SUCCESS] ; 0x1801f37f0
|
||||||
|
0x180035569 lea rdx,[EVENT_CARDS_APPLY_CARD_FAILURE] ; 0x1801f3810
|
||||||
|
```
|
||||||
|
|
||||||
|
It tests exactly one 32-bit field — the transport code — and **never inspects
|
||||||
|
the body**. `EVENT_CARDS_APPLY_CARD_SUCCESS` has precisely one reference in the
|
||||||
|
module, so this is the whole verdict path.
|
||||||
|
|
||||||
|
This does NOT resemble the move ack (`0x180128600`), which builds per-item
|
||||||
|
verdict records and reports FAILURE on an EMPTY vector. The "`{}` is
|
||||||
|
known-broken" precedent is specific to that route and does not transfer here.
|
||||||
|
|
||||||
|
Supporting structure: the response object's constructor `0x1800a4ce0` installs
|
||||||
|
vtable `0x1801fb5b0` and initialises its record vector at `+0x50`/`+0x58`/`+0x60`
|
||||||
|
EMPTY (0x20-byte elements); `0x1800682b0` is the matching destructor, freeing
|
||||||
|
that range with a 0x20 stride. An empty result is therefore a legal parsed state
|
||||||
|
for this response, unlike the move.
|
||||||
|
|
||||||
|
Registration site: `0x1800357da` installs the completion handler and
|
||||||
|
`0x1800357e5` the response factory, back to back.
|
||||||
|
|
||||||
|
**Probe response**: `{"itemData":[]}` — an object root (matching how the oracle's
|
||||||
|
method-agnostic `item/resource` route answers this path) containing an empty
|
||||||
|
vector (legal per the constructor). Labelled a PROBE. The client's SUCCESS only
|
||||||
|
requires transport code 0.
|
||||||
|
|
||||||
|
## Consumables categories — nine, not seven (2026-08-22)
|
||||||
|
|
||||||
|
Correcting the earlier claim that the two formation-modifier families "have no
|
||||||
|
group code, so no segment can reach them — the client's own gap". The client's
|
||||||
|
own switch says otherwise. Literal table at `0x1801f5a38` (under
|
||||||
|
`MyClubAdapterClass` / `CONSUMABLE_TYPE`); switch at `0x180048820` indexing by
|
||||||
|
`enum + 1` through the byte table at `0x180048a90` into the case table at
|
||||||
|
`0x180048a6c`:
|
||||||
|
|
||||||
|
| CONSUMABLE_TYPE | segment |
|
||||||
|
|---|---|
|
||||||
|
| **-1 (unset)** | `development` |
|
||||||
|
| 1, 2 | `contracts` |
|
||||||
|
| 3 | `healing` |
|
||||||
|
| 4 | `fitness` |
|
||||||
|
| **16** | `formation` |
|
||||||
|
| 17 | `position` |
|
||||||
|
| 23 | `playStyle` |
|
||||||
|
| 24 | `managerLeagueModifier` |
|
||||||
|
| 0, 5..15, 18..22 | `training` (switch default) |
|
||||||
|
|
||||||
|
`formation` was a SERVER gap, not a client one. `development` is the type-unset
|
||||||
|
bucket — index 0 of an `enum + 1` table — i.e. the unfiltered view; the eight
|
||||||
|
typed segments already reach all thirteen families exactly once, so it owns no
|
||||||
|
family privately and maps to their union.
|
||||||
|
|
||||||
|
## Contract effect — the `contract: 7` inference is REFUTED at the source
|
||||||
|
|
||||||
|
Do not implement a contract effect from the catalog's `contract: 7`.
|
||||||
|
|
||||||
|
`fifa17-recon/tools/fut_store.py:232` — the generic `_item()` factory that builds
|
||||||
|
EVERY item the oracle serves — hardcodes:
|
||||||
|
|
||||||
|
```python
|
||||||
|
"playStyle": 250,
|
||||||
|
"contract": 7,
|
||||||
|
"fitness": 99,
|
||||||
|
```
|
||||||
|
|
||||||
|
These are blanket placeholders on every item, players and consumables alike. The
|
||||||
|
staging squad's GK reads back `contract 7 / fitness 99 / playStyle 250`: the same
|
||||||
|
three constants. So the `contract: 7` carried in the production catalog for
|
||||||
|
resource 5001004 is **our own oracle placeholder round-tripped through an
|
||||||
|
observed profile**, not an EA value. Its evidence level is not INFERRED; it is
|
||||||
|
KNOWN-BOGUS as a source of the effect.
|
||||||
|
|
||||||
|
### What the client's own table does say
|
||||||
|
|
||||||
|
`fcc_contractcards` (13 rows) is NOT amount-less, contrary to an earlier note
|
||||||
|
here. Columns: `carddbid, cardsubtype, weightrare, cardassetid, gold, rating,
|
||||||
|
bronze, silver`.
|
||||||
|
|
||||||
|
| rating | player (201) | manager (202) | gold | silver | bronze |
|
||||||
|
|---|---|---|---|---|---|
|
||||||
|
| 50 | 5001001 | 5001007 | 1 | 2 | 8 |
|
||||||
|
| 65 | 5001002 | 5001008 | 8 | 10 | 10 / 8 |
|
||||||
|
| 80 | 5001003 | 5001009 | 13 | 11 | 15 / 11 |
|
||||||
|
| 60 | 5001004 | 5001010 | 3 | 6 | 15 |
|
||||||
|
| 70 | 5001005 | 5001011 | 18 | 24 | 20 / 18 |
|
||||||
|
| 90 | 5001006 | 5001012 | 28 | 24 | 28 / 24 |
|
||||||
|
| 90 | 5001013 | — | 99 | 99 | 99 |
|
||||||
|
|
||||||
|
Compare the sibling `fcc_healingcards`, which shares `carddbid, cardsubtype,
|
||||||
|
weightrare, cardassetid, rating` and differs only by carrying a single `amount`.
|
||||||
|
So `weightrare` is the drop weight and the differing column(s) are the effect
|
||||||
|
payload — which would make gold/silver/bronze a per-target-tier amount.
|
||||||
|
|
||||||
|
AGAINST that reading: the values are not monotonic across tiers (5001005 is gold
|
||||||
|
18, silver 24, bronze 20; 5001003 is gold 13, silver 11, bronze 15), which is
|
||||||
|
odd for an amount and unremarkable for a weight. Note also that **no column of
|
||||||
|
5001004 equals 7**, so nothing here explains the placeholder either way.
|
||||||
|
|
||||||
|
Unresolved, and NOT to be guessed: the fcc tables are loaded by `FIFA17.exe`, not
|
||||||
|
CardsDLL (the table-name and column literals are absent from the DLL), so the
|
||||||
|
reader that would settle amount-vs-weight lives in the EXE. Status stays
|
||||||
|
**EFFECT_UNKNOWN**.
|
||||||
|
|
||||||
|
## Post-ACK behaviour — OUTCOME B, LIVE_PROVEN (2026-08-22)
|
||||||
|
|
||||||
|
Captured with the staging probe answering `200 {"itemData":[]}` and mutating
|
||||||
|
nothing:
|
||||||
|
|
||||||
|
```
|
||||||
|
T0 POST /ut/game/fifa17/item/resource/5001004 {"apply":[{"id":100000003}]}
|
||||||
|
T1 200 {"itemData":[]}
|
||||||
|
T2 callback -> SUCCESS (no failure event; ZERO ut/delete/auth; session alive)
|
||||||
|
T4 GET club/consumables/contracts <- refresh of the SOURCE list
|
||||||
|
T5 GET club/consumables/development
|
||||||
|
T6 GET squad/active <- refresh of the TARGET
|
||||||
|
T7 no second mutation of any kind
|
||||||
|
```
|
||||||
|
|
||||||
|
So of the candidate protocols:
|
||||||
|
|
||||||
|
```
|
||||||
|
B) POST resource -> ACK -> client performs GET refresh
|
||||||
|
-> the SERVER is expected to have mutated state
|
||||||
|
```
|
||||||
|
|
||||||
|
Ruled out by observation: (A) the response carries the modified state — the body
|
||||||
|
was empty and the client was satisfied; (C) a follow-up generic PUT/item — none
|
||||||
|
was sent; (D) another route performs the mutation — nothing else was called.
|
||||||
|
|
||||||
|
Three consequences.
|
||||||
|
|
||||||
|
1. **The success verdict is transport-only, confirmed live.** The static read of
|
||||||
|
`0x180035520` said the body is never inspected; an empty `itemData` produced a
|
||||||
|
clean success and a surviving session, which is that prediction holding.
|
||||||
|
2. **The server owns the effect entirely.** The client does not compute one; it
|
||||||
|
re-reads. This is the good failure mode: a wrong server-side effect cannot be
|
||||||
|
masked by client-side optimism, and the refresh will always show server truth.
|
||||||
|
Here the refresh correctly showed `contracts copies=3` and an unchanged squad,
|
||||||
|
because the probe consumed nothing.
|
||||||
|
3. **There is no client-side amount to harvest.** Since the client never renders
|
||||||
|
an optimistic "+N games" of its own, the live path cannot reveal the grant
|
||||||
|
size. The number the client DISPLAYS on a contract card comes from the wire
|
||||||
|
`contract` atom (0xb8 -> record+0x8c; see `fut_consumables.py`, which notes
|
||||||
|
categories 2 and 3 ignore `amount` and read `contract`) — i.e. the server
|
||||||
|
tells the client what the card is worth.
|
||||||
|
|
||||||
|
That last point matters for honesty: our oracle has been sending the placeholder
|
||||||
|
`7` for that atom, so every contract card this project has ever shown a player
|
||||||
|
said "7" because WE said 7. Recovering EA's real value is not reachable from the
|
||||||
|
client's behaviour; it needs the `FIFA17.exe` reader of `fcc_contractcards`, or
|
||||||
|
it becomes an explicit design decision. Status: **EFFECT_UNKNOWN**.
|
||||||
|
|
||||||
|
### Boundary status
|
||||||
|
|
||||||
|
| aspect | status |
|
||||||
|
|---|---|
|
||||||
|
| route, method, source encoding, target encoding | LIVE_PROVEN |
|
||||||
|
| success condition (`[obj+0x1c] == 0`, body ignored) | STATIC_REVERSED + LIVE_CONFIRMED |
|
||||||
|
| response shape accepted by the client | LIVE_PROVEN (`{"itemData":[]}`, session survived) |
|
||||||
|
| post-ACK protocol | LIVE_PROVEN — outcome B |
|
||||||
|
| batching | UNPROVEN — refused, never guessed |
|
||||||
|
| contract effect / grant size | UNKNOWN (placeholder source refuted) |
|
||||||
|
| source instance selection with multiple copies | UNDETERMINED (only 1 copy owned) |
|
||||||
|
|
||||||
|
## Consumable QUICK-SELL is PUT item/resource — LIVE_PROVEN (2026-08-22)
|
||||||
|
|
||||||
|
Captured on staging when the operator quick-sold a Position Modifier from the
|
||||||
|
consumables screen:
|
||||||
|
|
||||||
|
```
|
||||||
|
PUT /ut/game/fifa17/item/resource/5003068 body_len=0
|
||||||
|
```
|
||||||
|
|
||||||
|
So `ut/<sku>/item/resource/<resourceId>` carries THREE verbs, and this is the
|
||||||
|
third:
|
||||||
|
|
||||||
|
| verb | meaning |
|
||||||
|
|---|---|
|
||||||
|
| `GET` | item-definition lookup (`defs_route` parity) |
|
||||||
|
| `POST` | apply the consumable (`ApplyCardByRes`, body `{"apply":[{"id":N}]}`) |
|
||||||
|
| `PUT` | **quick-sell the consumable**, EMPTY body |
|
||||||
|
|
||||||
|
Note it is keyed by **resourceId**, i.e. the STACK, not by an owned instance
|
||||||
|
id — unlike the player quick-sell, which is `DELETE ut/<sku>/item/<instanceId>`
|
||||||
|
and is retail-proven in production. That asymmetry follows the consumables
|
||||||
|
screen's own model: the UI entity there is a stack, not a card.
|
||||||
|
|
||||||
|
Neither stack has ever served this route. The Python oracle maps
|
||||||
|
`item/resource` method-agnostically to `defs_route`, so a PUT would get a
|
||||||
|
definition list and HTTP 200 while nothing was sold — the client would believe
|
||||||
|
the sale succeeded. On staging the oracle is deliberately dead, so it 502'd and
|
||||||
|
Core was left untouched (coins 29843976, owned 1993, consumables 17).
|
||||||
|
|
||||||
|
### Consequence for production
|
||||||
|
|
||||||
|
Production's oracle IS alive, so today a consumable quick-sell there would reach
|
||||||
|
Python, return 200 from `defs_route`, and mutate nothing — the client would show
|
||||||
|
a successful sale that never happened. That is a second, independent reason not
|
||||||
|
to quick-sell consumables in production until this route is implemented in Rust.
|
||||||
|
|
||||||
|
### UNKNOWN, not to be guessed
|
||||||
|
|
||||||
|
* Does an empty-body PUT sell ONE copy or the WHOLE stack? The request carries no
|
||||||
|
quantity, and both readings fit. A stack of 2 at 38 is either +38 or +76.
|
||||||
|
* Which owned instance is consumed when several share the resourceId.
|
||||||
|
* What response the client requires (the player path's ack shape may not apply).
|
||||||
@@ -424,6 +424,25 @@ Chemistry/rating/nation/league-count constraints (`teamChemistry 0x307`, `starRa
|
|||||||
generically as `{eligibilityKey, eligibilityOperation, eligibilityValue}` triples, **not** as
|
generically as `{eligibilityKey, eligibilityOperation, eligibilityValue}` triples, **not** as
|
||||||
named scalar fields on the record. **FREEZE-RISK: elgReq must be a JSON array of objects.**
|
named scalar fields on the record. **FREEZE-RISK: elgReq must be a JSON array of objects.**
|
||||||
|
|
||||||
|
> **2026-08-19 — `eligibilityKey`/`eligibilityOperation` are LOCALIZATION ORDINALS, not the
|
||||||
|
> atom hex ids above.** Reversed from the pinned CardsDLL (`4706a881…`). The client's sole
|
||||||
|
> confirmed consumer of these fields is the requirement-display string builder at
|
||||||
|
> `~0x1800ef900`: it loads the eligibility int fields (`0x148(rcx)`) and formats them through
|
||||||
|
> *indexed localization keys* — `ELIGIBILITY_STRING%d` (`0x1802186b8`), `LOC_SBC_ELG_KEY_%d`
|
||||||
|
> (`0x180226710`), `ELIGIBILITY_OPERATION` (`0x1802186e8`) — appending to a string builder via
|
||||||
|
> vtable `*0x10`/`*0x20`. There is **no comparison/branch**: the client does not validate on
|
||||||
|
> these ints, it renders `LOC_SBC_ELG_KEY_<eligibilityKey>` (and an operation string) as
|
||||||
|
> display text. Therefore `eligibilityKey` is a small ordinal that indexes the **packed FIFA17
|
||||||
|
> locale**, NOT `0x307`/`0x22f`/etc. (those hex values are the atom ids of the *named* fields
|
||||||
|
> the encoding replaces, not the ordinal values). CONSEQUENCE: correct projection needs the
|
||||||
|
> ordinal→locale-string map, which lives only in the packed locale (absent from CardsDLL and
|
||||||
|
> every `fifa17-recon/data` file; a game-dir locale probe on the live client found none) or a
|
||||||
|
> real EA `elgReq` capture (unavailable on a private server). Emitting a *guessed* ordinal
|
||||||
|
> renders the WRONG requirement text to the player, so `elgReq` stays `[]` until the ordinal
|
||||||
|
> map is recovered. This is a display-only gap: SBC submission is fully validated server-side
|
||||||
|
> (Core), and an invalid squad's generic comms modal originates from the server 400, not from
|
||||||
|
> the empty `elgReq`.
|
||||||
|
|
||||||
**awards / grantedAwards** — nested array of reward objects (atoms: `rewardType 0x28e`,
|
**awards / grantedAwards** — nested array of reward objects (atoms: `rewardType 0x28e`,
|
||||||
`rewardValue 0x28f`, `rewardQuantity 0x28d`, `rewardMultiplier 0x28c`, `awardCount 0x40`,
|
`rewardValue 0x28f`, `rewardQuantity 0x28d`, `rewardMultiplier 0x28c`, `awardCount 0x40`,
|
||||||
`awardSet 0x45`, `awardSetId 0x46`, `prizeSet 0x253`). **FREEZE-RISK: must be array.**
|
`awardSet 0x45`, `awardSetId 0x46`, `prizeSet 0x253`). **FREEZE-RISK: must be array.**
|
||||||
@@ -920,16 +939,96 @@ freezes any of these — GAPs are "feature missing", not "crash".
|
|||||||
| 4 | FutViewCards | `0x1801293d0` | GET `ut/%s/item` | `itemData`(0x16b) → **array[card-item]** via `0x18013fe00` [FREEZE-RISK] | HANDLED (utas `/item` `defs_route` serves `itemData`) | HIGH |
|
| 4 | FutViewCards | `0x1801293d0` | GET `ut/%s/item` | `itemData`(0x16b) → **array[card-item]** via `0x18013fe00` [FREEZE-RISK] | HANDLED (utas `/item` `defs_route` serves `itemData`) | HIGH |
|
||||||
| 5 | FutActivateCard | `0x1801642c0` | PUT `ut/%s/item` (FUT_CLUB_ACTIVATE_ITEM_DP) | **none** (immediate `ret`) | ack — `{}` fine | HIGH |
|
| 5 | FutActivateCard | `0x1801642c0` | PUT `ut/%s/item` (FUT_CLUB_ACTIVATE_ITEM_DP) | **none** (immediate `ret`) | ack — `{}` fine | HIGH |
|
||||||
| 6 | FutApplyCard | `0x18012a710` | PUT `ut/%s/item` (apply by itemId) | `itemData`(0x16b) → **array[updated card-item]** via `0x18013fe00` [FREEZE-RISK] | GAP | HIGH |
|
| 6 | FutApplyCard | `0x18012a710` | PUT `ut/%s/item` (apply by itemId) | `itemData`(0x16b) → **array[updated card-item]** via `0x18013fe00` [FREEZE-RISK] | GAP | HIGH |
|
||||||
| 7 | FutApplyCardByRes | `0x18012ad10` | PUT `ut/%s/item` (apply by resourceId) | `itemData`(0x16b) → **array[updated card-item]** [FREEZE-RISK] | GAP | HIGH |
|
| 7 | FutApplyCardByRes | `0x18012ad10` | **POST** `ut/%s/item/resource/<rid>` (apply by resourceId) | `itemData`(0x16b) → **array[updated card-item]** [FREEZE-RISK] | **SERVED** (Rust host, contracts + attribute training) | HIGH |
|
||||||
|
|
||||||
|
> **Rows 6 and 7 are NOT the same route.** `ApplyCardByRes` carries urlIndex
|
||||||
|
> `0x0e`, which resolves to `ut/%s/item/resource` — not `ut/%s/item`
|
||||||
|
> (`plan-2026-08-05-pack-opening.md:505-506`, shared with `DiscardCardByRes` and
|
||||||
|
> `MoveCardByRes`). The verb is **POST**, live-proven by a real-client capture:
|
||||||
|
> `POST /ut/game/fifa17/item/resource/5001004` `{"apply":[{"id":100000003}]}`.
|
||||||
|
> This row previously read `PUT ut/%s/item` for both, and that conflation is what
|
||||||
|
> kept the "apply must ride `PUT ut/%s/item`" hypothesis alive
|
||||||
|
> (`CLIENT_ROUTE_SURFACE.md:104-106`) until the POST capture settled it — every
|
||||||
|
> observed `PUT ut/%s/item` is a pile MOVE, never an apply.
|
||||||
|
|
||||||
| 8 | FutDiscardCard | `0x180127300` | DELETE `ut/delete/%s/item` (CardsDiscardCard) | `items`(0x171) → **array[int ids]** [FREEZE-RISK]; `totalCredits`(0x326) → int; `id`(0x15c) → int | GAP | HIGH |
|
| 8 | FutDiscardCard | `0x180127300` | DELETE `ut/delete/%s/item` (CardsDiscardCard) | `items`(0x171) → **array[int ids]** [FREEZE-RISK]; `totalCredits`(0x326) → int; `id`(0x15c) → int | GAP | HIGH |
|
||||||
| 9 | FutDiscardCardByRes | `0x1801279c0` | DELETE `ut/delete/%s/item` (by res) | `totalCredits`(0x326) → int | GAP | HIGH |
|
| 9 | FutDiscardCardByRes | `0x1801279c0` | DELETE `ut/delete/%s/item` (by res) | `totalCredits`(0x326) → int | GAP | HIGH |
|
||||||
| 10 | FutMoveCard | `0x180128600` | PUT `ut/%s/item` (move) | `itemData`(0x16b) → **array** [FREEZE-RISK]; `chemistry`(0x81) → bool | GAP | HIGH |
|
| 10 | FutMoveCard | `0x180128600` | PUT `ut/%s/item` (move) | `itemData`(0x16b) → **array** [FREEZE-RISK]; `chemistry`(0x81) → bool | GAP | HIGH |
|
||||||
| 11 | FutMoveCardByRes | `0x180128e30` | PUT `ut/%s/item` (move by res) | `itemData`(0x16b) → **array** [FREEZE-RISK]; `chemistry`(0x81) → bool (+ 2 str/1 int minor) | GAP | HIGH / extra-fields MED |
|
| 11 | FutMoveCardByRes | `0x180128e30` | PUT `ut/%s/item` (move by res) | `itemData`(0x16b) → **array** [FREEZE-RISK]; `chemistry`(0x81) → bool (+ 2 str/1 int minor) | GAP | HIGH / extra-fields MED |
|
||||||
| 12 | FutConsumablesSearch | `0x180130d10` | GET `ut/%s/item?type=…` (GetFilteredConsumableSearchResults) | `itemData`(0x16b) → **array[consumable-item]** via `0x18013fe00` [FREEZE-RISK]; `displayGroupUseDefaultImage`(0xdb) → int + count scalars | GAP | deser HIGH / scalars MED |
|
| 12 | FutConsumablesSearch | `0x180130d10` | GET `ut/%s/club/consumables/<cat>` (ConsumablesSearch) **[CORRECTED 2026-08-21]** | `itemData`(0x16b) → **array[consumable-stack]** via `0x18013fe00` [FREEZE-RISK]; `displayGroupUseDefaultImage`(0xdb) → int + count scalars | SERVED (Rust host) | deser HIGH / scalars MED |
|
||||||
| 13 | FutStaffBonus | `0x18012b730` | GET `ut/%s/…` (CardsGetStaffBonuses) | `bonus`(0x5c) → **nested** (branch sets bool @rbp+0x51) [FREEZE-RISK]; `assetId`(0x23) → int | GAP | MED |
|
| 13 | FutStaffBonus | `0x18012b730` | GET `ut/%s/club/stats/staff` (StaffStats, thunk `0x18012b080`) **[CORRECTED 2026-08-21]** | `bonus`(0x5c) → **nested** (branch sets bool @rbp+0x51) [FREEZE-RISK]; `assetId`(0x23) → int | SERVED (`{}`, the oracle body) | MED |
|
||||||
| 14 | FutGetAvailableLoanPlayers | `0x18014e030` → sub `0x18013a1c0` | GET `ut/%s/item` (FUT_AVAILABLE_LOAN_PLAYERS_DP) | `loans`(0x19b) → **array** [FREEZE-RISK]; `itemData`(0x16b) → **array[card-item]** [FREEZE-RISK]; `default`(0xcd) → int | GAP | deser HIGH / fields MED |
|
| 14 | FutGetAvailableLoanPlayers | `0x18014e030` → sub `0x18013a1c0` | GET `ut/%s/item` (FUT_AVAILABLE_LOAN_PLAYERS_DP) | `loans`(0x19b) → **array** [FREEZE-RISK]; `itemData`(0x16b) → **array[card-item]** [FREEZE-RISK]; `default`(0xcd) → int | GAP | deser HIGH / fields MED |
|
||||||
| 15 | FutSignLoanPlayer | `0x1801642c0` | PUT `ut/%s/item` (sign loan) | **none** (immediate `ret`) | ack — `{}` fine | HIGH |
|
| 15 | FutSignLoanPlayer | `0x1801642c0` | PUT `ut/%s/item` (sign loan) | **none** (immediate `ret`) | ack — `{}` fine | HIGH |
|
||||||
| 16 | FutStickerBookSearch | `0x18012eff0` | GET `ut/%s/…` (stickerbook search) | `itemData`(0x16b) → **array[card-item]** via `0x18013fe00` [FREEZE-RISK] | GAP | HIGH |
|
| 16 | FutStickerBookSearch | `0x18012eff0` | GET `ut/%s/club?<query>` (ClubSearch, `FUN_18012ddf0`) **[CORRECTED 2026-08-21]** | `itemData`(0x16b) → **array[card-item]** via `0x18013fe00` [FREEZE-RISK] | SERVED (Rust host) | HIGH |
|
||||||
|
|
||||||
|
|
||||||
|
### The four `ut/%s/club` routes are a TABLE, not an inference (2026-08-21)
|
||||||
|
|
||||||
|
The URLs for rows 12, 13 and 16 above were previously guessed as `ut/%s/item?…`
|
||||||
|
or left as `ut/%s/…`. The binding is exact: the 125-row action table at
|
||||||
|
`0x1802caa20` indexes the 48-entry URL-base table at `0x18021df80` through column
|
||||||
|
1, and **base index 3 = `ut/%s/club` is carried by exactly four rows** — so the
|
||||||
|
client can emit exactly four request families on that base and no others.
|
||||||
|
|
||||||
|
```
|
||||||
|
| ClubSearch | FUN_18012ddf0 | GET ut/%s/club?<query> | FutStickerBookSearchServerResponse |
|
||||||
|
| ClubStats | FUN_18012f4f0 | GET ut/%s/club/stats/<f>[/<id>] | FutStickerBookStats2ServerResponse |
|
||||||
|
| StaffStats | thunk 0x18012b080 | GET ut/%s/club/stats/staff | FutStaffBonusServerResponse |
|
||||||
|
| ConsumablesSearch | FUN_1801308c0 | GET ut/%s/club/consumables/<cat> | FutConsumablesSearchServerResponse |
|
||||||
|
```
|
||||||
|
|
||||||
|
**Club query grammar**, complete and ordered: `?year=2017` (always, hardcoded),
|
||||||
|
then `type`, `start` (omitted at 0), `count` (omitted at 100), `filter`, then
|
||||||
|
EITHER the filter block (`position, formation, state, level, rare, nation,
|
||||||
|
country, league, playStyle, team, sort`) OR a comma-joined `defId=` list, never
|
||||||
|
both. Live control from the log:
|
||||||
|
`GET /ut/game/fifa17/club?year=2017&type=equippables&count=11&level=any&sort=desc`
|
||||||
|
matches the predicted order and every suppression rule.
|
||||||
|
|
||||||
|
Sub-vocabularies: `filter` = available/base/exact/any; `level` =
|
||||||
|
bronze/silver/gold/any; `sort` = asc/desc; `rare` = the literal string `SP`, not
|
||||||
|
a boolean; `state` = the itemState names plus `any` — and note the REQUEST spells
|
||||||
|
it `onSale` where the RESPONSE value is `forSale`.
|
||||||
|
|
||||||
|
`?type=` has 30 values. Decoded 2026-08-21 from the jump table itself rather
|
||||||
|
than from a case count: `FUN_18012ec50` is `cmp ecx,0x1d` + a 30-entry table at
|
||||||
|
`0x18012ed9c`, and each case is `mov ecx,<atom>; jmp 0x180180cd0` (atom → string).
|
||||||
|
Resolving those atoms against `fut_atoms.tsv` gives the vocabulary in table order:
|
||||||
|
|
||||||
|
```
|
||||||
|
0 any 1 player 2 manager 3 headcoach
|
||||||
|
4 fitnesscoach 5 physio 6 development 7 custom
|
||||||
|
8 unlocks 9 gkcoach 10 staff 11 badge
|
||||||
|
12 kit 13 stadium 14 ball 15 equippables
|
||||||
|
16 leaguelogos 17 offlinetrophy 18 onlinetrophy 19 featuredofflinetrophy
|
||||||
|
20 featuredonlinetrophy 21 allofflinetrophy
|
||||||
|
22 allonlinetrophy 23 healing 24 contract
|
||||||
|
25 training 26 misc 27 playerdefender
|
||||||
|
28 playermidfielder 29 playerforward
|
||||||
|
```
|
||||||
|
|
||||||
|
Notes worth having: there is **no `playergoalkeeper`** — the client has only
|
||||||
|
DEF/MID/FWD tabs, so goalkeepers belong to `playerdefender`, and a GK appearing
|
||||||
|
there is correct rather than a filter bug. `healing`, `contract` and `training`
|
||||||
|
exist here as `?type=` arms even though consumables have their own
|
||||||
|
`club/consumables/<cat>` route. Six of the thirty are trophy arms.
|
||||||
|
|
||||||
|
`openfut-utas-host`'s `club_type_filter` implements all 30 with no extras; a unit
|
||||||
|
test pins the list so a missing arm (an empty real tab) or an invented one (dead
|
||||||
|
code that looks like coverage) fails the build.
|
||||||
|
|
||||||
|
**`/club/stats` has exactly seven forms**: `club`, `year`, `country/<id>`,
|
||||||
|
`league/<id>`, `newcards`, `consumables`, and the separately-dispatched `staff`.
|
||||||
|
**There is no `/club/stats/team/<id>`** — verified twice (the switch has six cases
|
||||||
|
with no such arm, and an exhaustive PE string scan finds no literal containing
|
||||||
|
`stats/team`). Any handling of a `team` stats mode is dead code.
|
||||||
|
|
||||||
|
**Two holes in the base table**, recorded so nobody re-derives them as findings:
|
||||||
|
base index 43 = `ut/v2/%s/store` is carried by no action row and has zero
|
||||||
|
references in `.text`, yet `ut/v2/store` is live-proven; base index 9 =
|
||||||
|
`ut/%s/activeMessage` is a second hole of the same kind. So at least one route is
|
||||||
|
composed OUTSIDE CardsDLL, most likely in the packed exe — every "the table bounds
|
||||||
|
it" statement here is bounded to CardsDLL only.
|
||||||
|
|
||||||
Notes:
|
Notes:
|
||||||
- **`0x1801642c0`** is a shared no-op deserializer (function body = `ret`). Three responses
|
- **`0x1801642c0`** is a shared no-op deserializer (function body = `ret`). Three responses
|
||||||
|
|||||||
@@ -607,6 +607,62 @@ cardtype 6, live-confirmed on the two resident consumables, so for exactly the
|
|||||||
items the warning was aimed at, the server's rating and rare flag are
|
items the warning was aimed at, the server's rating and rare flag are
|
||||||
authoritative.
|
authoritative.
|
||||||
|
|
||||||
|
**APPLIED (2026-08-21), behind a default-off flag.** The table and the formula
|
||||||
|
above are now in Rust as `openfut-adapter-fifa17::fut::discard`:
|
||||||
|
`cardtype_for_subtype` is the decode, `discard_level` the 3/2/1 ladder,
|
||||||
|
`table_price` the 141-row lookup (`0` for an absent key) and `discard_value` the
|
||||||
|
`round_half_up(rating * price / 100)` formula. `DISCARD_COINS` is generated from
|
||||||
|
`fifa17-recon/data/tables/fcc_discardcoins.json` and a test re-reads that file
|
||||||
|
and asserts they still agree row for row, so the two cannot drift. The four
|
||||||
|
worked examples above (`8 * rating`, `4 * rating`, the 50-rated bronze at 15,
|
||||||
|
and an absent key paying 0) are tests.
|
||||||
|
|
||||||
|
Wire and wallet are now ONE method. `ItemIdentityResolver::discard_value` both
|
||||||
|
stamps the card's `discardValue` and prices the sale, because a non-zero
|
||||||
|
`discardValue` suppresses the client's local computation — so whatever is sent
|
||||||
|
is what the player is promised. The host's separate `quick_sell_value` ladder is
|
||||||
|
deleted (it was a second copy that could drift), and a test with a resolver
|
||||||
|
double returning an impossible price proves the credit follows the wire.
|
||||||
|
|
||||||
|
`OPENFUT_FIFA17_DISCARD_TABLE=1` turns the table on; the default keeps the old
|
||||||
|
placeholder ladder because switching revalues an existing club by **10.5x**
|
||||||
|
(measured over the real 1991-item club: 1,820,400 -> 19,128,955 coins if wholly
|
||||||
|
liquidated). Players drive it (an r93 special goes 1500 -> 74,400); consumables
|
||||||
|
move the OTHER way (2,400 -> 437, i.e. the ladder was overpaying 5.5x).
|
||||||
|
|
||||||
|
STAFF: CLOSED, and the `value`-is-the-rating question is now SETTLED against the
|
||||||
|
running client rather than inferred. A staff wire record carries no `rating`, no
|
||||||
|
`rareflag` and no `discardValue`, so the displayed price had to be read back out
|
||||||
|
of memory. `tools/coach_probe.py` grades the four resident staff records HIT,
|
||||||
|
which requires record `+0xb4` == the table's `value` and `+0x58` == its `rare`;
|
||||||
|
`tools/discard_probe.py` (new) then reads the two discard slots directly —
|
||||||
|
`+0x38` is what we sent, `+0x3c` is what the client computed:
|
||||||
|
|
||||||
|
```
|
||||||
|
resource sub ct rat lvl rar sent+38 calc+3c predicted
|
||||||
|
1000509 4 2 88 3 1 0 282 282 AGREES (manager)
|
||||||
|
9000081 6 10 66 2 0 0 36 36 AGREES (gk coach)
|
||||||
|
3000083 8 4 66 2 0 0 36 36 AGREES (fitness)
|
||||||
|
```
|
||||||
|
|
||||||
|
4 of 4 agree, 0 disagree, and 36 on the `value`-66 GK coach was the stated
|
||||||
|
falsifier. `openfut-import-fifa17::Entities::enrich_staff` now carries `value` ->
|
||||||
|
rating and `rare` -> rareflag for the five families, so the catalog holds what
|
||||||
|
the client re-rates to; verified on staging, a GK coach quick-sells for 36 rather
|
||||||
|
than the 150 floor. The catalog diff is exactly the two coach entries.
|
||||||
|
|
||||||
|
The same probe shows what production is doing to PLAYERS today: all 23 resident
|
||||||
|
player records carry `sent+38 = 1500`, which suppresses the local computation, so
|
||||||
|
the client displays 1500 for every one of them — against its own table's 688..752
|
||||||
|
for a gold rare, 11,102..11,468 for the 21/23/24 specials, 22,080..23,280 for
|
||||||
|
rareflag 11, and 72,800 / 74,400 for the two rareflag 5/6 legends. A 50x underpay
|
||||||
|
at the top and a 2x overpay at the bottom.
|
||||||
|
|
||||||
|
STILL OPEN, and NOT a discard problem: the manager `fifa17_1000509` is owned in
|
||||||
|
Core but has no catalog entry and no card definition (it reaches the client
|
||||||
|
through the opaque squad extension), so pricing declines for it and falls back to
|
||||||
|
the ladder — 150 against the client's 282. That is definition coverage.
|
||||||
|
|
||||||
### 3.7 `duplicateItemIdList`
|
### 3.7 `duplicateItemIdList`
|
||||||
|
|
||||||
CONFIRMED shape, INFERRED effect, never observed. Element deser `FUN_180138e10`,
|
CONFIRMED shape, INFERRED effect, never observed. Element deser `FUN_180138e10`,
|
||||||
|
|||||||
@@ -304,8 +304,44 @@ elimination:**
|
|||||||
| kit | **9** | 7 | `FUN_180119bd0` → `FUT_UC_KITS` + `TeamName_Abbr15_<teamid>` | `teamid` |
|
| kit | **9** | 7 | `FUN_180119bd0` → `FUT_UC_KITS` + `TeamName_Abbr15_<teamid>` | `teamid` |
|
||||||
| stadium | **10** | 7 | `FUN_180119bd0` → `Stadium` + `StadiumName_<assetId>` | `assetId` |
|
| stadium | **10** | 7 | `FUN_180119bd0` → `Stadium` + `StadiumName_<assetId>` | `assetId` |
|
||||||
| badge | **11** | 7 | `FUN_180119bd0` → `Badge` + `TeamName_Abbr15_<teamid>` | `teamid` |
|
| badge | **11** | 7 | `FUN_180119bd0` → `Badge` + `TeamName_Abbr15_<teamid>` | `teamid` |
|
||||||
| ball | **30** (0x1e) | 9 | none; `FUT_UC_BALL` caption only | `localizedName` |
|
| ball | **30** (0x1e) | 9 | NONE — see the 2026-08-21 measurement below | unnameable |
|
||||||
| league logo | **31** (0x1f) | 9 | `FUN_180098f20` keyed on leagueid | `localizedName`, probably |
|
| league logo | **31** (0x1f) | 9 | NONE — see the 2026-08-21 measurement below | unnameable |
|
||||||
|
|
||||||
|
**MEASURED 2026-08-21 against the running client (`tools/cardtype_dispatch_probe.py`,
|
||||||
|
pid 6580): no cardtype-9 family can be named, and no server change can alter that.**
|
||||||
|
Four independent reads, each with a passing positive control:
|
||||||
|
|
||||||
|
1. The merge switch's jump table at rva `0x141eb4` is indexed by `cardtype - 1`
|
||||||
|
and has exactly 10 entries. Cardtypes 1–5 and 10 each get their own DB-merge
|
||||||
|
arm; **cardtypes 6, 7, 8 and 9 all land on the shared tail `0x180141e8a`**,
|
||||||
|
which issues no query and writes no name — it only derives the discard level
|
||||||
|
from the rating.
|
||||||
|
2. Census of every `cmp [reg+0x4c], imm` (cardtype): 0 → 1 site, 1 → 13, 6 → 1,
|
||||||
|
7 → 6, **9 → ZERO**.
|
||||||
|
3. Census of every `cmp [reg+0x50], imm` (cardsubtypeid), which is what actually
|
||||||
|
selects a club-item caption: kit 9, stadium 10 and badge 11 all present
|
||||||
|
(control), **ball 30 → ZERO sites, league logo 31 → ZERO sites**. The only
|
||||||
|
cardtype-9 subtypes that appear at all are `fcc_misccards` 231/232/233/236,
|
||||||
|
and all four sites are one boolean predicate near `0x1801a72da` that returns
|
||||||
|
FALSE for them — an exclusion, not a resolver. (That predicate's identity is
|
||||||
|
NOT established; it reads `+0x49`, `+0x145` and a vtable slot `+0x270`.)
|
||||||
|
4. The cardtype-7 resolver is reached only under `cmp DWORD PTR [rax+0x4c], 0x7`
|
||||||
|
at `0x1800f6f04`, so a cardtype-9 item can never arrive there. Its `jne` path
|
||||||
|
formats `AWARD_LABEL_%i` (`0x1801fd5a0`) — the TROPHY path, not a fallback
|
||||||
|
that would name a ball.
|
||||||
|
|
||||||
|
So the earlier "`localizedName`, probably" for these two rows was optimistic:
|
||||||
|
there is no code that would read it for a caption. Withholding ball and league
|
||||||
|
logo from the projection is a measured limit of the client, not caution.
|
||||||
|
|
||||||
|
CORRECTION, same measurement: `FUN_180119bd0` was recorded elsewhere as having
|
||||||
|
"zero refs in CardsDLL → almost certainly an export, its caller is in
|
||||||
|
FIFA17.exe". It is **not** an export. Its address occurs exactly ONCE in the
|
||||||
|
whole process, at `0x18021c738` in CardsDLL's own `.rdata`, and nothing in
|
||||||
|
FIFA17.exe references it. It is a virtual function: vtable base `0x18021c2a0`,
|
||||||
|
slot **+0x498**, index 147 (ctor LEAs at `0x18010ce10` / `0x18011111b`) — which
|
||||||
|
independently reproduces the "manager vtable slot +0x498" recorded below, by a
|
||||||
|
different method. It has 7 distinct `call [reg+0x498]` sites.
|
||||||
|
|
||||||
The premise that all five live in cardtype 9 is wrong, and the root fact is not an
|
The premise that all five live in cardtype 9 is wrong, and the root fact is not an
|
||||||
inference from a call site. `FUN_1800d8330`, read in full at 714 chars by two
|
inference from a call site. `FUN_1800d8330`, read in full at 714 chars by two
|
||||||
@@ -406,6 +442,91 @@ from an accessor. So: send `localizedName` and expect it to show; send
|
|||||||
`description` and do not be surprised if nothing changes. The same `+0xba` also
|
`description` and do not be surprised if nothing changes. The same `+0xba` also
|
||||||
holds the unresolved kit-variant selector, so these two gaps may be one gap.
|
holds the unresolved kit-variant selector, so these two gaps may be one gap.
|
||||||
|
|
||||||
|
### The cardtype-9 name gap is ONE gap, not three (2026-08-21)
|
||||||
|
|
||||||
|
Worth stating plainly, because it was being tracked as three separate holes.
|
||||||
|
Everything OpenFUT still refuses to project is cardtype 9, and for exactly the
|
||||||
|
same reason:
|
||||||
|
|
||||||
|
| family | subtype(s) | definition table | why withheld |
|
||||||
|
|---|---|---|---|
|
||||||
|
| ball | 30 | `fcc_balls` (42) | no DB name resolver |
|
||||||
|
| league logo | 31 | `fcc_leaguelogos` (44) | no DB name resolver |
|
||||||
|
| misc | 231, 232, 233, 236 | `fcc_misccards` (42) | no DB name resolver |
|
||||||
|
|
||||||
|
The cardtype-7 families (kit 9, badge 11, stadium 10) all resolve their caption
|
||||||
|
from the client's own tables through `FUN_180119bd0`, so the server sends only
|
||||||
|
identity and the name takes care of itself — which is why all three now project.
|
||||||
|
Cardtype 9 has no such resolver, so the displayed name can ONLY come from
|
||||||
|
`localizedName` on the wire, and that single unproven step gates all three
|
||||||
|
families at once.
|
||||||
|
|
||||||
|
Closing it closes the last of the ownable taxonomy. It needs the launch-driven
|
||||||
|
probe in "The one probe still outstanding" above — one item, one family — and
|
||||||
|
nothing else. Ownership, `content_kind`, club/stats counting and restart
|
||||||
|
durability are already in place for all three, so the probe is the only
|
||||||
|
remaining work: the projection arm is a two-line change once the name is proven.
|
||||||
|
|
||||||
|
#### A lead on league logos: a `LeagueName_Abbr_15_%d` path DOES exist
|
||||||
|
|
||||||
|
`FUN_180098f20` (named above as the league-logo function, hedged "localizedName,
|
||||||
|
probably") was read in full on 2026-08-21. It builds a real database query, and
|
||||||
|
the literals settle what it does:
|
||||||
|
|
||||||
|
```
|
||||||
|
table 'fcc_leaguelogos'
|
||||||
|
where 'leagueid' '==' %d ; the id arrives in r9d
|
||||||
|
columns 'carddbid' 'value' 'cardassetid'
|
||||||
|
caption 'LeagueName_Abbr_15_%d' ; a localisation key built from the league id
|
||||||
|
domain 'FUT String'
|
||||||
|
```
|
||||||
|
|
||||||
|
So a database-backed league NAME demonstrably exists in the client, keyed on
|
||||||
|
`leagueid`, in exactly the shape kits use (`TeamName_Abbr15_<teamid>`). That
|
||||||
|
makes the blanket claim "cardtype 9 has no DB name resolver" too strong for
|
||||||
|
league logos specifically.
|
||||||
|
|
||||||
|
WHAT THIS DOES NOT YET SHOW, stated plainly because the obvious next step is a
|
||||||
|
trap. Its ONLY caller is `0x180098da3`, and the `[rbx+0x20]` it passes as the
|
||||||
|
league id is NOT the item record: `rbx` is reloaded from `[rsp+0x48]` and
|
||||||
|
compared against an end pointer, i.e. it is a cursor over a list of small
|
||||||
|
elements (int at `+0x20`, double at `+0x24`, int at `+0x2c`), not the 0x158-byte
|
||||||
|
card record. So this is a CATALOG/BROWSE builder, and it is not established that
|
||||||
|
the owned-item render path reaches it at all. Reading `+0x20` as the record's
|
||||||
|
`assetId` and concluding "send the leagueid as assetId" would be exactly the
|
||||||
|
kind of inference this document exists to prevent.
|
||||||
|
|
||||||
|
The lead worth following: find whether the owned cardtype-9 render path reaches
|
||||||
|
this resolver, and if so which field feeds the league id. If it does, league
|
||||||
|
logos need no `localizedName` at all and separate from the ball/misc gap.
|
||||||
|
|
||||||
|
#### Where to look next, and where NOT to (2026-08-21)
|
||||||
|
|
||||||
|
The lead above was chased and stopped at a useful boundary. `FUN_180119bd0` —
|
||||||
|
the cardtype-7 caption resolver this whole section rests on — has **zero
|
||||||
|
references anywhere in CardsDLL**: no `call`, no `jmp`, and its address is never
|
||||||
|
taken in `.text`, `.rdata` or `.data`. It is nonetheless a genuine function
|
||||||
|
(clean `mov rax,rsp` entry after `int3` padding).
|
||||||
|
|
||||||
|
A real, unreferenced function in a DLL is almost certainly an **export**, which
|
||||||
|
puts its caller in FIFA17.exe. That matches the shape of everything else here:
|
||||||
|
CardsDLL owns the card model and the database, and the EXE owns the UI that asks
|
||||||
|
for captions. `FUN_180098f20`'s only caller likewise iterates a small list
|
||||||
|
element, not a card record — a browse/catalog builder, not the owned-item path.
|
||||||
|
|
||||||
|
So the practical guidance is: **stop looking for the owned cardtype-9 caption
|
||||||
|
path inside CardsDLL.** It is not there. Closing this by static reading means
|
||||||
|
parsing CardsDLL's export table and following the callers in FIFA17.exe's 79 MB,
|
||||||
|
which is a much larger job than the launch probe in "The one probe still
|
||||||
|
outstanding" — one item, one family, and the answer is visible on screen.
|
||||||
|
|
||||||
|
Method note for whoever does dump memory here: CardsDLL's sections are
|
||||||
|
`.text` at image `0x180001000`, `.rdata` at `0x1801e5000`, `.data` at
|
||||||
|
`0x18028a000`. Confusing a LIVE mapping offset with an IMAGE offset silently
|
||||||
|
reads the wrong section and produces false negatives — every atom-name lookup
|
||||||
|
came back ABSENT until the region was corrected, including controls like
|
||||||
|
`resourceId`. Always validate a memory scan against a key known to be present.
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## 4. The card lifecycle
|
## 4. The card lifecycle
|
||||||
@@ -503,13 +624,6 @@ effects move in the permissive direction. There is also a second escape hatch in
|
|||||||
that gate -- `svc->0x308()` on service `0xed80ed8` -- that nobody resolved, so if
|
that gate -- `svc->0x308()` on service `0xed80ed8` -- that nobody resolved, so if
|
||||||
squad submission behaves oddly afterwards, that is where to look.
|
squad submission behaves oddly afterwards, that is where to look.
|
||||||
|
|
||||||
**"List on Transfer Market" as a separate menu entry was not found.** The eight
|
|
||||||
flags contain `TO_TRADE_PILE` and no listing action. `FUN_18003e550` publishes
|
|
||||||
`DURATION` / `START_PRICE` / `ASKING_PRICE`, which is the listing panel, but
|
|
||||||
whether it has its own enable predicate was not chased. The likely explanation is
|
|
||||||
that listing is only reachable from the trade pile, so both entries share one root
|
|
||||||
cause, but that is an inference and it is not established.
|
|
||||||
|
|
||||||
### Equipping club items
|
### Equipping club items
|
||||||
|
|
||||||
`itemState` really is the equip mechanism for the `IS_ACTIVE` tick:
|
`itemState` really is the equip mechanism for the `IS_ACTIVE` tick:
|
||||||
@@ -528,22 +642,60 @@ will not change the kit.
|
|||||||
|
|
||||||
### Needs decompiling only
|
### Needs decompiling only
|
||||||
|
|
||||||
**Who writes item `+0x60`.** It gates the kit swap at value 4 and we can produce 1
|
**Who writes item `+0x60`. ANSWERED 2026-08-21 — NOTHING DOES.** It gates the kit
|
||||||
and 6. Both attempts to scan for it drowned: `+0x60` returns 1688 and 4144
|
swap at value 4 and we can produce 1 and 6. Both earlier scans drowned (`+0x60`
|
||||||
instructions depending on method. The narrower anchor is the `/club` and
|
returns 1688 and 4144 instructions) because it is a common struct offset. Two
|
||||||
`/purchased` response handlers -- find the list-insert that assigns it, read the
|
filters cut it to a readable set: only an IMMEDIATE store can introduce a
|
||||||
constants. This is the single blocker between "we can mark a kit equipped" and "we
|
constant, and item-record code is recognisable by touching `+0x4c`/`+0x5c`
|
||||||
can equip a kit".
|
nearby. Measured with `fifa17-recon/tools/kit_gate_probe.py` against pid 6580:
|
||||||
|
|
||||||
|
| evidence | result |
|
||||||
|
|---|---|
|
||||||
|
| live `+0x60`, all 27 resident records | `{1: 23 players, 0: 4 staff}` — never 4 |
|
||||||
|
| `cmp dword [reg+0x60], imm8` in CardsDLL | 4 sites: `0`, `0`, `1`, `4`; the `4` is the gate and is UNIQUE in the process |
|
||||||
|
| immediate stores to `[reg+0x60]`, CardsDLL | 29; constants `{-2, 0, 1, 908, 0x3f800000}` — no 4 |
|
||||||
|
| immediate stores of 4, FIFA17.exe (79 MB) | 0; also 0 comparisons against 4 |
|
||||||
|
| xrefs to the gate function | 1 (`jmp` from `0x1801a5329`); address never taken |
|
||||||
|
| register stores to `+0x60`, CardsDLL | all struct copies or inits to 0/1/-2 |
|
||||||
|
|
||||||
|
So the blocker is not a wire field we have not learned to send: the value the
|
||||||
|
gate demands is never produced by anything. Every OTHER input to the gate is
|
||||||
|
already served — `+0x4c == 7` (subtype 9), `+0x5c` 101/102
|
||||||
|
(`activeHomeKit`/`activeAwayKit`), `+0x94` teamid — leaving only the `+0xba`
|
||||||
|
variant selector below it. A client-side patch is therefore the only remaining
|
||||||
|
avenue, and a small one; it is not proposed here.
|
||||||
|
|
||||||
|
|
||||||
**The kit variant selector.** `FUN_1801bfac0` distinguishes home, away and third
|
**The kit variant selector.** `FUN_1801bfac0` distinguishes home, away and third
|
||||||
kits from `FUN_1801a8800` (`+0xba`, u16) and `FUN_1801a8040` (`+0xbf`, signed
|
kits from `FUN_1801a8800` (`+0xba`, u16) and `FUN_1801a8040` (`+0xbf`, signed
|
||||||
byte). Which wire atom sets it is unknown, so we cannot serve a specific kit
|
byte). Which wire atom sets it is unknown, so we cannot serve a specific kit
|
||||||
deliberately. Note `+0xba` is the same slot as the unresolved ball subtitle.
|
deliberately. Note `+0xba` is the same slot as the unresolved ball subtitle.
|
||||||
|
|
||||||
**`FUN_1801aa190`.** The one unopened link inside the eight-flag chain: it is
|
**`FUN_1801aa190`. CLOSED 2026-08-21.** The one unopened link inside the
|
||||||
claimed to resolve `statsList[4]` and `[5]` at `+0x104 + idx*4`. It changes no
|
eight-flag chain. It is eleven instructions, and it resolves TWO parallel arrays
|
||||||
action today because we send no `statsList`, but it is two minutes of work and it
|
rather than the one the earlier claim described:
|
||||||
would close the chain.
|
|
||||||
|
```
|
||||||
|
mov rax, [rcx+0x10] ; the ITEM record (same +0x10 hop the kit gate uses)
|
||||||
|
test r8b, r8b
|
||||||
|
jz .low
|
||||||
|
mov eax, [rax + rdx*4 + 0x124] ; array B
|
||||||
|
ret
|
||||||
|
.low:
|
||||||
|
mov eax, [rax + rcx*4 + 0x104] ; array A <- the claimed statsList
|
||||||
|
ret
|
||||||
|
```
|
||||||
|
|
||||||
|
So the signature is `f(self, int idx, bool which)`: `+0x104 + idx*4` when the
|
||||||
|
flag is clear, `+0x124 + idx*4` when it is set. The two arrays are 0x20 apart,
|
||||||
|
i.e. eight ints each (`+0x104..+0x123`, `+0x124..+0x143`).
|
||||||
|
|
||||||
|
LIVE (pid 6580, production-served records): BOTH arrays read all zeros on every
|
||||||
|
resident record, players included — e.g. resourceId 20801 rating 94 has
|
||||||
|
`A = [0]*8`, `B = [0]*8`. That confirms "changes no action today because we send
|
||||||
|
no statsList", and extends it: the sibling array at `+0x124` is equally empty.
|
||||||
|
Any action flag derived from either is reading 0 in production, so neither can
|
||||||
|
be the reason an action is greyed.
|
||||||
|
|
||||||
**The `BOUGHT_FOR` consumer.** `+0x34` = atom `0x185 lastSalePrice` is resolved.
|
**The `BOUGHT_FOR` consumer.** `+0x34` = atom `0x185 lastSalePrice` is resolved.
|
||||||
What remains is whether the field is visible anywhere worth populating.
|
What remains is whether the field is visible anywhere worth populating.
|
||||||
@@ -553,24 +705,73 @@ depend on it (`FUN_180108c00` carries the same mapping independently), but the
|
|||||||
dispatch table that reaches it was not identified, and trophies are a whole
|
dispatch table that reaches it was not identified, and trophies are a whole
|
||||||
unimplemented family.
|
unimplemented family.
|
||||||
|
|
||||||
**Case sensitivity of the `itemState` string match.** Almost certainly
|
**Case sensitivity of the `itemState` string match. RESOLVED 2026-08-21 —
|
||||||
unresolvable statically: `FUN_180008190` is a single indirect call through
|
CASE-SENSITIVE.** It was expected to be unresolvable statically, because
|
||||||
`DAT_1802ddfd8 + 0x248`, a runtime-populated service pointer. Send the exact
|
`FUN_180008190` is nothing but a forwarding stub through a runtime-populated
|
||||||
casing from the table and do not experiment on the live save.
|
slot:
|
||||||
|
|
||||||
|
```
|
||||||
|
mov rax, [DAT_1802ddfd8] ; service object, handed to CardsDLL by the host
|
||||||
|
mov r9, [rax + 0x248]
|
||||||
|
jmp r9
|
||||||
|
```
|
||||||
|
|
||||||
|
Resolved read-only against the running client (pid 6580) with
|
||||||
|
`fifa17-recon/tools/service_ptr_probe.py`, which follows the chain and
|
||||||
|
attributes each hop to a module (Wine maps PE sections anonymously, so the
|
||||||
|
module comes from the nearest preceding named mapping):
|
||||||
|
|
||||||
|
```
|
||||||
|
*(service + 0x248) = 0x146d1c020 FIFA17.exe+0x20f9020 e9 … jmp rel32
|
||||||
|
→ 0x145e27fe0 FIFA17.exe+0x1204fe0 ff 25 jmp [rip+…]
|
||||||
|
→ 0x6ffffd11c330 msvcr120.dll+0x3c330 function body
|
||||||
|
```
|
||||||
|
|
||||||
|
The body is `strncmp`: `sub rdx,rcx` / `test r8,r8` (count) / `test al,al`
|
||||||
|
(NUL stop) / `cmp al,[rcx+rdx]`, then MSVC's 8-byte fast path with the
|
||||||
|
`0x8080808080808080` and `0xfefefefefefefeff` NUL-detect constants. There is no
|
||||||
|
`or ..,0x20` and no folding table anywhere in the body, so the compare is raw
|
||||||
|
bytes.
|
||||||
|
|
||||||
|
CONSEQUENCE: a mis-cased token does not degrade, it matches nothing —
|
||||||
|
`FUN_180166660` returns `0xffffffff`, the record keeps `0` = `invalid`, and the
|
||||||
|
item fails the squad builder's `state == 1 || state == 2` test. The casing in
|
||||||
|
the table at `0x180229cc0` is a contract. Send it verbatim; do not experiment on
|
||||||
|
the live save.
|
||||||
|
|
||||||
### Needs a live probe (read-only, no launch)
|
### Needs a live probe (read-only, no launch)
|
||||||
|
|
||||||
**Resolve `DAT_1802ddfd8 + 0x248`** in the running process and identify the string
|
|
||||||
comparator. That answers the casing question without a launch.
|
|
||||||
|
|
||||||
**Re-read `+0x30` after a refetch** to decide between "monotonic clock" and
|
**Re-read `+0x30` after a refetch** to decide between "monotonic clock" and
|
||||||
"sequence counter". Low value; nothing we send reaches it.
|
"sequence counter". Low value; nothing we send reaches it.
|
||||||
|
|
||||||
**Confirm the FUT roster database is loaded.** The `fcc_discardcoins` result
|
**Confirm the FUT roster database is loaded. PARTLY ANSWERED 2026-08-21 — the
|
||||||
proves `g_db` is loaded and complete; it says nothing about the separate database
|
two databases are now definitively distinct; the load FLAG is still unlocated.**
|
||||||
behind `LoadFUTDatabase` / `.dbFUTVer` / `DL_FUT_LIVEDB`, whose strings live in
|
The `fcc_discardcoins` result proves `g_db` is loaded and complete; it says
|
||||||
FIFA17.exe and not in CardsDLL. These are different databases and they should stop
|
nothing about the separate database behind `LoadFUTDatabase` / `.dbFUTVer` /
|
||||||
being conflated.
|
`DL_FUT_LIVEDB`. Scanning FIFA17.exe's 79 MB of code+data in the live process
|
||||||
|
(pid 6580) recovers the whole API name set, and it settles the distinction:
|
||||||
|
|
||||||
|
```
|
||||||
|
SetFUTDatabaseUnloaded UpdateFUTDBVersion StartFUTRosterDownload
|
||||||
|
LoadFUTDatabase UnLoadFUTDatabase GetFUTDBCRC
|
||||||
|
CancelRosterDownload DL_FUT_LIVEDB APPLY_FUT_LIVEDB
|
||||||
|
RosterXMLDownloadedFail .dbFUTVer .dbMajor .dbMinor .dbMajorCRC .dbMinorCRC
|
||||||
|
```
|
||||||
|
|
||||||
|
Every one of those lives in FIFA17.exe; none is in CardsDLL. So the FUT roster
|
||||||
|
DB is a DOWNLOADED, versioned, CRC-checked live database with its own
|
||||||
|
download -> apply -> load/unload lifecycle (and its own failure state,
|
||||||
|
`RosterXMLDownloadedFail`), which is a different kind of thing from the shipped
|
||||||
|
card tables CardsDLL reads. They should stop being conflated, and this is the
|
||||||
|
evidence for saying so.
|
||||||
|
|
||||||
|
What is NOT answered: whether it is loaded right now. The process holds no
|
||||||
|
separate database file open — only Frostbite bundles (`.sb` / `.cas`) — which is
|
||||||
|
consistent with the roster DB living inside a bundle or in memory, so absence of
|
||||||
|
a file handle proves nothing either way. The `SetFUTDatabaseUnloaded` state
|
||||||
|
implies a boolean somewhere; that global was not located, so "is it loaded"
|
||||||
|
remains open and needs the flag found before it can be answered honestly.
|
||||||
|
|
||||||
### Needs a launch the user must drive -- ranked, and short
|
### Needs a launch the user must drive -- ranked, and short
|
||||||
|
|
||||||
@@ -870,10 +1071,29 @@ be misrouted onto another field. **Freeze risk: none** -- removing a key the par
|
|||||||
skips strictly reduces executed code. Low value, zero cost, and it removes a field
|
skips strictly reduces executed code. Low value, zero cost, and it removes a field
|
||||||
that three documents describe as if it did something.
|
that three documents describe as if it did something.
|
||||||
|
|
||||||
|
**Fourth verification, 2026-08-21 (independent method).** Searched CardsDLL's
|
||||||
|
own `.rdata` in the running client for the literal key names. Every real atom is
|
||||||
|
present exactly once — `resourceId` `0x18022a3a8`, `cardsubtypeid` `0x180230520`,
|
||||||
|
`itemState` `0x180231490`, `assetId` `0x180230178`, `cardassetid` `0x180204200`,
|
||||||
|
`rareflag`, `untradeable`, `owners`, `contract`, `discardValue`, and notably
|
||||||
|
`localizedName` at `0x1802316d0` — while **`definitionId` is ABSENT entirely**.
|
||||||
|
The client has no string for it, so no arm can exist. That is a different method
|
||||||
|
from the three above (string table rather than key dictionary) and it agrees.
|
||||||
|
|
||||||
|
NOT applied all the same. The player path that carries `definitionId` is
|
||||||
|
live-proven in production, the saving is payload only, and this project's house
|
||||||
|
rule is that a flag defaults to the live-proven value. "Provably inert" is a good
|
||||||
|
reason to stop documenting it as meaningful; it is not on its own a reason to
|
||||||
|
change a working wire. Bundle it with the next change that needs a launch.
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## 7. Proposed corrections to existing documents
|
## 7. Proposed corrections to existing documents
|
||||||
|
|
||||||
|
> **APPLIED 2026-08-21.** Every correction below has been made in the named file
|
||||||
|
> and marked there with a dated note. This section is kept as the rationale and
|
||||||
|
> the audit trail, not as an outstanding to-do.
|
||||||
|
|
||||||
### `docs/CARD_SYSTEM.md`
|
### `docs/CARD_SYSTEM.md`
|
||||||
|
|
||||||
**Replace the "STILL UNKNOWN, AND NOT GUESSED" section entirely.** It is answered.
|
**Replace the "STILL UNKNOWN, AND NOT GUESSED" section entirely.** It is answered.
|
||||||
|
|||||||
Executable
+697
@@ -0,0 +1,697 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Decoder for EA APT (compiled ActionScript) as shipped in FIFA 17.
|
||||||
|
|
||||||
|
Clean-room implementation. The byte-level format facts (opcode numbers, operand
|
||||||
|
widths, alignment rule, branch base, DefineFunction2 field order) were taken from
|
||||||
|
a written specification derived from OpenSAGE, which is GPL-3.0 with EA
|
||||||
|
additional terms. No OpenSAGE code was copied or transliterated; only the format
|
||||||
|
description -- an interface specification -- was used. Reference read at
|
||||||
|
OpenSAGE/OpenSAGE commit 588ac477367a0022adf29f20a084e8873014e6ce and
|
||||||
|
OpenSAGE/AptEditor commit 09f73c655c45a781f883b623a93d2e8f5b065a6c.
|
||||||
|
|
||||||
|
FIFA 17 ships a 64-BIT variant of the format. Differences from the 32-bit SAGE
|
||||||
|
layout described by the reference, all established by measurement against
|
||||||
|
futSelectTeam and asserted by --selftest:
|
||||||
|
|
||||||
|
* Container pointers and counts are u64, not u32.
|
||||||
|
* Parameterised instructions align their operand block to 8 bytes, not 4.
|
||||||
|
Proven by the ConstantPool at 0xd38: aligning to 4 yields garbage, aligning
|
||||||
|
to 8 yields count=401 with an index array that ends exactly on the
|
||||||
|
parameter-list region.
|
||||||
|
* The constant pool lives in a separate "Apt1" container member rather than a
|
||||||
|
".const" sibling file. Entries are 16 bytes: {u64 type, u64 value}; type 1
|
||||||
|
is a string whose value is an absolute offset inside that same member.
|
||||||
|
* DefineFunction2's operand block is 48 bytes rather than 28, and the
|
||||||
|
0x1234567898765432 trailer is stored as two u64 halves.
|
||||||
|
* Branch displacements remain i32 and remain relative to the end of the
|
||||||
|
branch record, exactly as in the 32-bit format.
|
||||||
|
"""
|
||||||
|
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import argparse
|
||||||
|
import struct
|
||||||
|
import sys
|
||||||
|
from dataclasses import dataclass, field
|
||||||
|
|
||||||
|
APT1_MAGIC = b"Apt1"
|
||||||
|
APTDATA_MAGIC = b"Apt Data:1:7:8\x1a\x00"
|
||||||
|
|
||||||
|
# Trailer sentinel on DefineFunction/DefineFunction2, stored as two u64 halves.
|
||||||
|
FUNC_SENTINEL_LO = 0x98765432
|
||||||
|
FUNC_SENTINEL_HI = 0x12345678
|
||||||
|
|
||||||
|
ALIGN = 8
|
||||||
|
|
||||||
|
# Operand kinds.
|
||||||
|
NONE = "none" # no operand block
|
||||||
|
U8REG = "u8reg" # 1 raw byte, register index
|
||||||
|
U8CONST = "u8const" # 1 raw byte, constant-pool index
|
||||||
|
U16CONST = "u16const" # 2 raw bytes, constant-pool index
|
||||||
|
U8LIT = "u8lit" # 1 raw byte, literal integer
|
||||||
|
U16LIT = "u16lit" # 2 raw bytes, literal integer
|
||||||
|
BRANCH = "branch" # aligned i32, relative to end of record
|
||||||
|
U32 = "u32" # aligned u32
|
||||||
|
F32 = "f32" # aligned f32
|
||||||
|
STR64 = "str64" # aligned u64 absolute offset to NUL-terminated string
|
||||||
|
POOL = "pool" # aligned u64 count + u64 array offset (array of u64 ids)
|
||||||
|
FUNC2 = "func2" # aligned DefineFunction2 record
|
||||||
|
FUNC1 = "func1" # aligned DefineFunction record
|
||||||
|
|
||||||
|
# opcode -> (mnemonic, operand kind)
|
||||||
|
OPCODES: dict[int, tuple[str, str]] = {
|
||||||
|
0x00: ("End", NONE),
|
||||||
|
0x04: ("NextFrame", NONE),
|
||||||
|
0x06: ("Play", NONE),
|
||||||
|
0x07: ("Stop", NONE),
|
||||||
|
0x0A: ("Add", NONE),
|
||||||
|
0x0B: ("Subtract", NONE),
|
||||||
|
0x0C: ("Multiply", NONE),
|
||||||
|
0x0D: ("Divide", NONE),
|
||||||
|
0x12: ("Not", NONE),
|
||||||
|
0x13: ("StringEquals", NONE),
|
||||||
|
0x17: ("Pop", NONE),
|
||||||
|
0x18: ("ToInteger", NONE),
|
||||||
|
0x1C: ("GetVariable", NONE),
|
||||||
|
0x1D: ("SetVariable", NONE),
|
||||||
|
0x21: ("StringConcat", NONE),
|
||||||
|
0x22: ("GetProperty", NONE),
|
||||||
|
0x23: ("SetProperty", NONE),
|
||||||
|
0x26: ("Trace", NONE),
|
||||||
|
0x30: ("Random", NONE),
|
||||||
|
0x3A: ("Delete", NONE),
|
||||||
|
0x3B: ("Delete2", NONE),
|
||||||
|
0x3C: ("DefineLocal", NONE),
|
||||||
|
0x3D: ("CallFunction", NONE),
|
||||||
|
0x3E: ("Return", NONE),
|
||||||
|
0x3F: ("Modulo", NONE),
|
||||||
|
0x40: ("NewObject", NONE),
|
||||||
|
0x41: ("Var", NONE),
|
||||||
|
0x42: ("InitArray", NONE),
|
||||||
|
0x43: ("InitObject", NONE),
|
||||||
|
0x44: ("TypeOf", NONE),
|
||||||
|
0x47: ("Add2", NONE),
|
||||||
|
0x48: ("LessThan2", NONE),
|
||||||
|
0x49: ("Equals2", NONE),
|
||||||
|
0x4A: ("ToNumber", NONE),
|
||||||
|
0x4B: ("ToString", NONE),
|
||||||
|
0x4C: ("PushDuplicate", NONE),
|
||||||
|
0x4E: ("GetMember", NONE),
|
||||||
|
0x4F: ("SetMember", NONE),
|
||||||
|
0x50: ("Increment", NONE),
|
||||||
|
0x51: ("Decrement", NONE),
|
||||||
|
0x52: ("CallMethod", NONE),
|
||||||
|
# 0x53 appears in the reference enum as NewMethod but the reference never
|
||||||
|
# parses it. Standard AVM1 ActionNewMethod carries no operand block;
|
||||||
|
# decoding it as zero-length keeps this artifact synchronised with every
|
||||||
|
# branch still landing on an instruction boundary, which is the check that
|
||||||
|
# would break first if the width were wrong.
|
||||||
|
0x53: ("NewMethod", NONE),
|
||||||
|
0x54: ("InstanceOf", NONE),
|
||||||
|
0x55: ("Enumerate2", NONE),
|
||||||
|
0x56: ("PushThis", NONE),
|
||||||
|
0x59: ("PushZero", NONE),
|
||||||
|
0x5A: ("PushOne", NONE),
|
||||||
|
0x5B: ("CallFuncPop", NONE),
|
||||||
|
0x5C: ("CallFunc", NONE),
|
||||||
|
0x5D: ("CallMethodPop", NONE),
|
||||||
|
0x62: ("BitwiseXOr", NONE),
|
||||||
|
0x66: ("StrictEqual", NONE),
|
||||||
|
0x67: ("Greater", NONE),
|
||||||
|
0x69: ("Extends", NONE),
|
||||||
|
0x70: ("PushThisVar", NONE),
|
||||||
|
0x71: ("PushGlobalVar", NONE),
|
||||||
|
0x72: ("ZeroVar", NONE),
|
||||||
|
0x73: ("PushTrue", NONE),
|
||||||
|
0x74: ("PushFalse", NONE),
|
||||||
|
0x75: ("PushNull", NONE),
|
||||||
|
0x76: ("PushUndefined", NONE),
|
||||||
|
0x87: ("SetRegister", U32),
|
||||||
|
0x88: ("ConstantPool", POOL),
|
||||||
|
0x8C: ("GotoLabel", STR64),
|
||||||
|
0x8E: ("DefineFunction2", FUNC2),
|
||||||
|
0x96: ("PushData", POOL),
|
||||||
|
0x99: ("BranchAlways", BRANCH),
|
||||||
|
0x9B: ("DefineFunction", FUNC1),
|
||||||
|
0x9D: ("BranchIfTrue", BRANCH),
|
||||||
|
0x9F: ("GotoFrame2", U32),
|
||||||
|
0xA1: ("PushString", STR64),
|
||||||
|
0xA2: ("PushConstantByte", U8CONST),
|
||||||
|
0xA3: ("PushConstantWord", U16CONST),
|
||||||
|
0xA4: ("GetStringVar", STR64),
|
||||||
|
0xA5: ("GetStringMember", STR64),
|
||||||
|
0xA6: ("SetStringVar", STR64),
|
||||||
|
0xA7: ("SetStringMember", STR64),
|
||||||
|
0xAE: ("PushValueOfVar", U8CONST),
|
||||||
|
0xAF: ("GetNamedMember", U8CONST),
|
||||||
|
0xB0: ("CallNamedFuncPop", U8CONST),
|
||||||
|
0xB1: ("CallNamedFunc", U8CONST),
|
||||||
|
0xB2: ("CallNamedMethodPop", U8CONST),
|
||||||
|
0xB3: ("CallNamedMethod", U8CONST),
|
||||||
|
0xB4: ("PushFloat", F32),
|
||||||
|
0xB5: ("PushByte", U8LIT),
|
||||||
|
0xB6: ("PushShort", U16LIT),
|
||||||
|
0xB8: ("BranchIfFalse", BRANCH),
|
||||||
|
0xB9: ("PushRegister", U8REG),
|
||||||
|
}
|
||||||
|
|
||||||
|
ALIGNED_KINDS = {BRANCH, U32, F32, STR64, POOL, FUNC2, FUNC1}
|
||||||
|
|
||||||
|
|
||||||
|
class DecodeError(Exception):
|
||||||
|
"""Raised when the stream cannot be decoded without guessing."""
|
||||||
|
|
||||||
|
|
||||||
|
@dataclass
|
||||||
|
class Instr:
|
||||||
|
offset: int
|
||||||
|
opcode: int
|
||||||
|
mnemonic: str
|
||||||
|
length: int # opcode byte through end of operand block, incl. padding
|
||||||
|
operands: dict
|
||||||
|
raw: bytes
|
||||||
|
target: int | None = None # resolved branch destination
|
||||||
|
comment: str = ""
|
||||||
|
|
||||||
|
def render(self, width: int = 22) -> str:
|
||||||
|
ops = self.comment or ""
|
||||||
|
return f" {self.offset:#07x} {self.mnemonic:<{width}} {ops}"
|
||||||
|
|
||||||
|
|
||||||
|
@dataclass
|
||||||
|
class Function:
|
||||||
|
name: str
|
||||||
|
record_offset: int # offset of the DefineFunction* opcode byte
|
||||||
|
body_start: int
|
||||||
|
body_end: int
|
||||||
|
n_params: int
|
||||||
|
n_registers: int
|
||||||
|
flags: int
|
||||||
|
params: list = field(default_factory=list)
|
||||||
|
|
||||||
|
@property
|
||||||
|
def anonymous(self) -> bool:
|
||||||
|
return not self.name
|
||||||
|
|
||||||
|
|
||||||
|
PRELOAD_FLAGS = [
|
||||||
|
(0x010000, "PreloadExtern"),
|
||||||
|
(0x008000, "PreloadParent"),
|
||||||
|
(0x004000, "PreloadRoot"),
|
||||||
|
(0x002000, "SupressSuper"),
|
||||||
|
(0x001000, "PreloadSuper"),
|
||||||
|
(0x000800, "SupressArguments"),
|
||||||
|
(0x000400, "PreloadArguments"),
|
||||||
|
(0x000200, "SupressThis"),
|
||||||
|
(0x000100, "PreloadThis"),
|
||||||
|
(0x000001, "PreloadGlobal"),
|
||||||
|
]
|
||||||
|
|
||||||
|
# Registers preloaded by the VM, in flag order, starting at index 1.
|
||||||
|
PRELOAD_ORDER = [
|
||||||
|
(0x000100, "this"),
|
||||||
|
(0x000400, "arguments"),
|
||||||
|
(0x001000, "super"),
|
||||||
|
(0x004000, "_root"),
|
||||||
|
(0x008000, "_parent"),
|
||||||
|
(0x000001, "_global"),
|
||||||
|
(0x010000, "extern"),
|
||||||
|
]
|
||||||
|
|
||||||
|
|
||||||
|
def flag_names(flags: int) -> str:
|
||||||
|
got = [n for bit, n in PRELOAD_FLAGS if flags & bit]
|
||||||
|
return "|".join(got) if got else "0"
|
||||||
|
|
||||||
|
|
||||||
|
def register_map(fn: Function) -> dict[int, str]:
|
||||||
|
"""Reproduce the VM's register preload order, then bound parameters."""
|
||||||
|
regs: dict[int, str] = {}
|
||||||
|
idx = 1
|
||||||
|
for bit, name in PRELOAD_ORDER:
|
||||||
|
if fn.flags & bit:
|
||||||
|
regs[idx] = name
|
||||||
|
idx += 1
|
||||||
|
for reg, pname in fn.params:
|
||||||
|
if reg:
|
||||||
|
regs[reg] = pname
|
||||||
|
return regs
|
||||||
|
|
||||||
|
|
||||||
|
class ConstPool:
|
||||||
|
"""The 'Apt1' container member: header, 16-byte entries, string table."""
|
||||||
|
|
||||||
|
def __init__(self, data: bytes):
|
||||||
|
if data[:4] != APT1_MAGIC:
|
||||||
|
raise DecodeError(f"not an Apt1 member: {data[:4]!r}")
|
||||||
|
self.data = data
|
||||||
|
self.count = struct.unpack_from("<Q", data, 0x20)[0]
|
||||||
|
self.first = struct.unpack_from("<Q", data, 0x28)[0]
|
||||||
|
self.entries: list[tuple[int, int, str | None]] = []
|
||||||
|
for i in range(self.count):
|
||||||
|
off = self.first + i * 16
|
||||||
|
if off + 16 > len(data):
|
||||||
|
raise DecodeError(f"const entry {i} at {off:#x} runs past end")
|
||||||
|
etype, value = struct.unpack_from("<QQ", data, off)
|
||||||
|
text = None
|
||||||
|
if etype == 1:
|
||||||
|
if not (0 < value < len(data)):
|
||||||
|
raise DecodeError(
|
||||||
|
f"const entry {i}: string offset {value:#x} outside member"
|
||||||
|
)
|
||||||
|
end = data.find(b"\0", value)
|
||||||
|
if end < 0:
|
||||||
|
raise DecodeError(f"const entry {i}: unterminated string")
|
||||||
|
text = data[value:end].decode("latin1")
|
||||||
|
self.entries.append((etype, value, text))
|
||||||
|
|
||||||
|
def string(self, index: int) -> str:
|
||||||
|
if not (0 <= index < len(self.entries)):
|
||||||
|
raise DecodeError(f"const index {index} out of range (0..{len(self.entries)-1})")
|
||||||
|
etype, _, text = self.entries[index]
|
||||||
|
if etype != 1 or text is None:
|
||||||
|
raise DecodeError(f"const index {index} is type {etype}, not a string")
|
||||||
|
return text
|
||||||
|
|
||||||
|
def find(self, needle: str) -> list[int]:
|
||||||
|
return [i for i, (_, _, t) in enumerate(self.entries) if t == needle]
|
||||||
|
|
||||||
|
|
||||||
|
class AptData:
|
||||||
|
"""The 'Apt Data' container member: movie structures plus action streams."""
|
||||||
|
|
||||||
|
def __init__(self, data: bytes, pool: ConstPool):
|
||||||
|
if not data.startswith(APTDATA_MAGIC[:8]):
|
||||||
|
raise DecodeError(f"not an Apt Data member: {data[:16]!r}")
|
||||||
|
self.data = data
|
||||||
|
self.pool = pool
|
||||||
|
self.scope: list[str] = [] # installed by ConstantPool
|
||||||
|
self.functions: list[Function] = []
|
||||||
|
|
||||||
|
# -- helpers ---------------------------------------------------------
|
||||||
|
def cstr(self, off: int) -> str:
|
||||||
|
if not (0 <= off < len(self.data)):
|
||||||
|
raise DecodeError(f"string offset {off:#x} outside Apt Data")
|
||||||
|
end = self.data.find(b"\0", off)
|
||||||
|
if end < 0:
|
||||||
|
raise DecodeError(f"unterminated string at {off:#x}")
|
||||||
|
return self.data[off:end].decode("latin1")
|
||||||
|
|
||||||
|
def const(self, index: int) -> str:
|
||||||
|
"""Resolve through the scope pool installed by the most recent 0x88."""
|
||||||
|
if self.scope:
|
||||||
|
if not (0 <= index < len(self.scope)):
|
||||||
|
raise DecodeError(
|
||||||
|
f"scope-pool index {index} out of range (0..{len(self.scope)-1})"
|
||||||
|
)
|
||||||
|
return self.scope[index]
|
||||||
|
return self.pool.string(index)
|
||||||
|
|
||||||
|
def install_pool(self, ids: list[int]) -> None:
|
||||||
|
self.scope = [self.pool.string(i) for i in ids]
|
||||||
|
|
||||||
|
# -- instruction decoding --------------------------------------------
|
||||||
|
def decode_one(self, pos: int) -> Instr:
|
||||||
|
d = self.data
|
||||||
|
if pos >= len(d):
|
||||||
|
raise DecodeError(f"position {pos:#x} past end of stream")
|
||||||
|
op = d[pos]
|
||||||
|
entry = OPCODES.get(op)
|
||||||
|
if entry is None:
|
||||||
|
raise DecodeError(
|
||||||
|
f"unknown opcode {op:#04x} at {pos:#07x} "
|
||||||
|
f"(raw {d[pos:pos+8].hex(' ')}) - refusing to guess its length"
|
||||||
|
)
|
||||||
|
mnem, kind = entry
|
||||||
|
p = pos + 1
|
||||||
|
if kind in ALIGNED_KINDS:
|
||||||
|
p = (p + ALIGN - 1) & ~(ALIGN - 1)
|
||||||
|
|
||||||
|
ops: dict = {}
|
||||||
|
comment = ""
|
||||||
|
target = None
|
||||||
|
|
||||||
|
def need(n: int) -> None:
|
||||||
|
if p + n > len(d):
|
||||||
|
raise DecodeError(f"{mnem} at {pos:#07x} truncated: needs {n} bytes")
|
||||||
|
|
||||||
|
if kind == NONE:
|
||||||
|
pass
|
||||||
|
elif kind in (U8REG, U8LIT):
|
||||||
|
need(1)
|
||||||
|
ops["value"] = d[p]
|
||||||
|
p += 1
|
||||||
|
comment = f"r{ops['value']}" if kind == U8REG else str(ops["value"])
|
||||||
|
elif kind == U8CONST:
|
||||||
|
need(1)
|
||||||
|
ops["index"] = d[p]
|
||||||
|
p += 1
|
||||||
|
comment = f"{ops['index']:#04x} -> {self.const(ops['index'])!r}"
|
||||||
|
elif kind == U16CONST:
|
||||||
|
need(2)
|
||||||
|
ops["index"] = struct.unpack_from("<H", d, p)[0]
|
||||||
|
p += 2
|
||||||
|
comment = f"{ops['index']:#06x} -> {self.const(ops['index'])!r}"
|
||||||
|
elif kind == U16LIT:
|
||||||
|
need(2)
|
||||||
|
ops["value"] = struct.unpack_from("<H", d, p)[0]
|
||||||
|
p += 2
|
||||||
|
comment = str(ops["value"])
|
||||||
|
elif kind == U32:
|
||||||
|
need(4)
|
||||||
|
ops["value"] = struct.unpack_from("<I", d, p)[0]
|
||||||
|
p += 4
|
||||||
|
comment = str(ops["value"])
|
||||||
|
elif kind == F32:
|
||||||
|
need(4)
|
||||||
|
ops["value"] = struct.unpack_from("<f", d, p)[0]
|
||||||
|
p += 4
|
||||||
|
comment = repr(ops["value"])
|
||||||
|
elif kind == BRANCH:
|
||||||
|
need(4)
|
||||||
|
disp = struct.unpack_from("<i", d, p)[0]
|
||||||
|
p += 4
|
||||||
|
ops["displacement"] = disp
|
||||||
|
target = p + disp # base = end of record
|
||||||
|
comment = f"{disp:+d} -> {target:#07x}"
|
||||||
|
elif kind == STR64:
|
||||||
|
need(8)
|
||||||
|
off = struct.unpack_from("<Q", d, p)[0]
|
||||||
|
p += 8
|
||||||
|
ops["offset"] = off
|
||||||
|
ops["text"] = self.cstr(off)
|
||||||
|
comment = f"{ops['text']!r}"
|
||||||
|
elif kind == POOL:
|
||||||
|
need(16)
|
||||||
|
count, arr = struct.unpack_from("<QQ", d, p)
|
||||||
|
p += 16
|
||||||
|
if arr + count * 8 > len(d):
|
||||||
|
raise DecodeError(f"{mnem} at {pos:#07x}: array {arr:#x}[{count}] overruns")
|
||||||
|
ids = list(struct.unpack_from(f"<{count}Q", d, arr))
|
||||||
|
ops["count"], ops["array"], ops["ids"] = count, arr, ids
|
||||||
|
comment = f"count={count} array={arr:#x}"
|
||||||
|
elif kind in (FUNC2, FUNC1):
|
||||||
|
if kind == FUNC2:
|
||||||
|
need(48)
|
||||||
|
name_off, n_params = struct.unpack_from("<QI", d, p)
|
||||||
|
n_reg = d[p + 12]
|
||||||
|
flags = int.from_bytes(d[p + 13:p + 16], "little")
|
||||||
|
plist, body = struct.unpack_from("<QQ", d, p + 16)
|
||||||
|
lo, hi = struct.unpack_from("<QQ", d, p + 32)
|
||||||
|
p += 48
|
||||||
|
else:
|
||||||
|
need(40)
|
||||||
|
name_off, n_params, plist, body = struct.unpack_from("<QQQQ", d, p)
|
||||||
|
n_reg, flags = 4, 0
|
||||||
|
lo, hi = struct.unpack_from("<QQ", d, p + 32)
|
||||||
|
p += 40
|
||||||
|
if (lo, hi) != (FUNC_SENTINEL_LO, FUNC_SENTINEL_HI):
|
||||||
|
raise DecodeError(
|
||||||
|
f"{mnem} at {pos:#07x}: bad trailer {lo:#x}/{hi:#x}, "
|
||||||
|
"record layout is wrong"
|
||||||
|
)
|
||||||
|
name = self.cstr(name_off)
|
||||||
|
params = []
|
||||||
|
for i in range(n_params):
|
||||||
|
e = plist + i * 16
|
||||||
|
if e + 16 > len(d):
|
||||||
|
raise DecodeError(f"{mnem} at {pos:#07x}: param {i} overruns")
|
||||||
|
reg, pn = struct.unpack_from("<QQ", d, e)
|
||||||
|
params.append((reg, self.cstr(pn)))
|
||||||
|
ops.update(name=name, n_params=n_params, n_registers=n_reg,
|
||||||
|
flags=flags, params=params, body_size=body)
|
||||||
|
comment = (f"{name or '<anonymous>'}({', '.join(n for _, n in params)}) "
|
||||||
|
f"nRegs={n_reg} flags={flag_names(flags)} bodySize={body}")
|
||||||
|
ops["body_start"] = p
|
||||||
|
ops["body_end"] = p + body
|
||||||
|
else:
|
||||||
|
raise DecodeError(f"internal: unhandled kind {kind}")
|
||||||
|
|
||||||
|
return Instr(pos, op, mnem, p - pos, ops, d[pos:p], target, comment)
|
||||||
|
|
||||||
|
def decode_stream(self, start: int, limit: int | None = None) -> list[Instr]:
|
||||||
|
"""Linear decode using the reference termination rule.
|
||||||
|
|
||||||
|
Stops when the last instruction was End AND we are past every branch
|
||||||
|
destination seen so far. A stream may legitimately continue past an End.
|
||||||
|
"""
|
||||||
|
out: list[Instr] = []
|
||||||
|
pos = start
|
||||||
|
furthest = start
|
||||||
|
while True:
|
||||||
|
if limit is not None and pos >= limit:
|
||||||
|
break
|
||||||
|
ins = self.decode_one(pos)
|
||||||
|
out.append(ins)
|
||||||
|
if ins.target is not None:
|
||||||
|
furthest = max(furthest, ins.target)
|
||||||
|
if ins.mnemonic == "ConstantPool":
|
||||||
|
self.install_pool(ins.operands["ids"])
|
||||||
|
if ins.mnemonic in ("DefineFunction2", "DefineFunction"):
|
||||||
|
fn = Function(
|
||||||
|
name=ins.operands["name"],
|
||||||
|
record_offset=ins.offset,
|
||||||
|
body_start=ins.operands["body_start"],
|
||||||
|
body_end=ins.operands["body_end"],
|
||||||
|
n_params=ins.operands["n_params"],
|
||||||
|
n_registers=ins.operands["n_registers"],
|
||||||
|
flags=ins.operands["flags"],
|
||||||
|
params=ins.operands["params"],
|
||||||
|
)
|
||||||
|
self.functions.append(fn)
|
||||||
|
furthest = max(furthest, fn.body_end)
|
||||||
|
pos = ins.offset + ins.length
|
||||||
|
if ins.mnemonic == "End" and pos > furthest:
|
||||||
|
break
|
||||||
|
return out
|
||||||
|
|
||||||
|
|
||||||
|
def load(apt1_path: str, aptdata_path: str) -> tuple[ConstPool, AptData]:
|
||||||
|
pool = ConstPool(open(apt1_path, "rb").read())
|
||||||
|
movie = AptData(open(aptdata_path, "rb").read(), pool)
|
||||||
|
return pool, movie
|
||||||
|
|
||||||
|
|
||||||
|
def find_streams(movie: AptData) -> list[int]:
|
||||||
|
"""Seed stream starts: every ConstantPool record that validates."""
|
||||||
|
seeds = []
|
||||||
|
d = movie.data
|
||||||
|
for p in range(len(d)):
|
||||||
|
if d[p] != 0x88:
|
||||||
|
continue
|
||||||
|
try:
|
||||||
|
ins = movie.decode_one(p)
|
||||||
|
except DecodeError:
|
||||||
|
continue
|
||||||
|
if ins.operands.get("count", 0) and ins.operands["ids"] == list(
|
||||||
|
range(ins.operands["count"])
|
||||||
|
):
|
||||||
|
seeds.append(p)
|
||||||
|
return seeds
|
||||||
|
|
||||||
|
|
||||||
|
def main(argv: list[str] | None = None) -> int:
|
||||||
|
ap = argparse.ArgumentParser(description=__doc__,
|
||||||
|
formatter_class=argparse.RawDescriptionHelpFormatter)
|
||||||
|
ap.add_argument("--apt1", default="fifa17-recon/data/apt/futSelectTeam_Apt1.bin")
|
||||||
|
ap.add_argument("--aptdata", default="fifa17-recon/data/apt/futSelectTeam_AptData.bin")
|
||||||
|
ap.add_argument("--stream", type=lambda s: int(s, 0), help="decode one stream at offset")
|
||||||
|
ap.add_argument("--function", help="decode the named function's body")
|
||||||
|
ap.add_argument("--list-functions", action="store_true")
|
||||||
|
ap.add_argument("--report", action="store_true", help="structural validation report")
|
||||||
|
ap.add_argument("--strings", action="store_true", help="dump the constant pool")
|
||||||
|
ap.add_argument("--selftest", action="store_true")
|
||||||
|
args = ap.parse_args(argv)
|
||||||
|
|
||||||
|
pool, movie = load(args.apt1, args.aptdata)
|
||||||
|
|
||||||
|
if args.selftest:
|
||||||
|
return selftest(pool, movie)
|
||||||
|
|
||||||
|
if args.strings:
|
||||||
|
for i, (t, v, s) in enumerate(pool.entries):
|
||||||
|
print(f" #{i:3d} type={t} @{v:#07x} {s!r}")
|
||||||
|
return 0
|
||||||
|
|
||||||
|
seeds = find_streams(movie)
|
||||||
|
if args.stream is not None:
|
||||||
|
seeds = [args.stream]
|
||||||
|
|
||||||
|
all_instrs: list[Instr] = []
|
||||||
|
for s in seeds:
|
||||||
|
all_instrs.extend(movie.decode_stream(s))
|
||||||
|
|
||||||
|
if args.list_functions:
|
||||||
|
for fn in movie.functions:
|
||||||
|
regs = register_map(fn)
|
||||||
|
rs = " ".join(f"r{k}={v}" for k, v in sorted(regs.items()))
|
||||||
|
print(f" {fn.body_start:#07x}-{fn.body_end:#07x} "
|
||||||
|
f"{fn.name or '<anonymous>':<34} {rs}")
|
||||||
|
return 0
|
||||||
|
|
||||||
|
if args.function:
|
||||||
|
for fn in movie.functions:
|
||||||
|
if fn.name == args.function:
|
||||||
|
print(f"; {fn.name} body {fn.body_start:#x}..{fn.body_end:#x} "
|
||||||
|
f"flags={flag_names(fn.flags)} nRegs={fn.n_registers}")
|
||||||
|
regs = register_map(fn)
|
||||||
|
for k, v in sorted(regs.items()):
|
||||||
|
print(f"; r{k} = {v}")
|
||||||
|
for ins in movie.decode_stream(fn.body_start, fn.body_end):
|
||||||
|
print(ins.render())
|
||||||
|
return 0
|
||||||
|
print(f"function {args.function!r} not found", file=sys.stderr)
|
||||||
|
return 1
|
||||||
|
|
||||||
|
if args.report:
|
||||||
|
return report(movie, seeds, all_instrs)
|
||||||
|
|
||||||
|
for ins in all_instrs:
|
||||||
|
print(ins.render())
|
||||||
|
return 0
|
||||||
|
|
||||||
|
|
||||||
|
def report(movie: AptData, seeds: list[int], instrs: list[Instr]) -> int:
|
||||||
|
import collections
|
||||||
|
hist = collections.Counter(i.mnemonic for i in instrs)
|
||||||
|
covered = set()
|
||||||
|
for i in instrs:
|
||||||
|
covered.update(range(i.offset, i.offset + i.length))
|
||||||
|
branches = [i for i in instrs if i.target is not None]
|
||||||
|
boundaries = {i.offset for i in instrs}
|
||||||
|
bad = [i for i in branches if i.target not in boundaries]
|
||||||
|
print(f" streams decoded : {len(seeds)} {[hex(s) for s in seeds]}")
|
||||||
|
print(f" instructions : {len(instrs)}")
|
||||||
|
print(f" bytes covered : {len(covered)} of {len(movie.data)}")
|
||||||
|
print(f" functions : {len(movie.functions)}")
|
||||||
|
print(f" branches : {len(branches)}")
|
||||||
|
print(f" invalid branch targets: {len(bad)}")
|
||||||
|
for i in bad[:10]:
|
||||||
|
print(f" {i.offset:#07x} {i.mnemonic} -> {i.target:#07x}")
|
||||||
|
print(f" distinct opcodes : {len(hist)}")
|
||||||
|
for m, n in hist.most_common():
|
||||||
|
print(f" {m:<22} {n}")
|
||||||
|
return 1 if bad else 0
|
||||||
|
|
||||||
|
|
||||||
|
def selftest(pool: ConstPool, movie: AptData) -> int:
|
||||||
|
"""Assertions that pin the measured format facts."""
|
||||||
|
ok = True
|
||||||
|
|
||||||
|
def check(label: str, cond: bool, detail: str = "") -> None:
|
||||||
|
nonlocal ok
|
||||||
|
print(f" [{'PASS' if cond else 'FAIL'}] {label}{(' - ' + detail) if detail else ''}")
|
||||||
|
ok = ok and cond
|
||||||
|
|
||||||
|
check("Apt1 entry count", pool.count == 414, f"{pool.count}")
|
||||||
|
check("Apt1 all entries are strings",
|
||||||
|
all(t == 1 for t, _, _ in pool.entries))
|
||||||
|
check("Apt1 entry array abuts string table",
|
||||||
|
pool.first + pool.count * 16 == min(v for t, v, _ in pool.entries if t == 1))
|
||||||
|
|
||||||
|
# Phase 3: exact pointer -> string resolution for known symbols.
|
||||||
|
for name in ("CheckIsKitLocked", "KITS_AVAILABLE", "FUT_GET_MATCH_KITS_DP",
|
||||||
|
"mcLockHome"):
|
||||||
|
idx = pool.find(name)
|
||||||
|
check(f"string resolves: {name}", len(idx) == 1 and pool.string(idx[0]) == name,
|
||||||
|
f"index {idx}")
|
||||||
|
|
||||||
|
# Bad pointers must raise, not fuzzy-match.
|
||||||
|
for bad in (-1, 10 ** 6):
|
||||||
|
try:
|
||||||
|
pool.string(bad)
|
||||||
|
check(f"bad const index {bad} rejected", False)
|
||||||
|
except DecodeError:
|
||||||
|
check(f"bad const index {bad} rejected", True)
|
||||||
|
|
||||||
|
# Phase 4 fixtures for the two EA opcodes.
|
||||||
|
movie.scope = ["alpha", "beta"] + [f"c{i}" for i in range(2, 300)]
|
||||||
|
fixtures = [
|
||||||
|
(bytes([0xB9, 0x00]), "PushRegister", 2, "r0"),
|
||||||
|
(bytes([0xB9, 0x05]), "PushRegister", 2, "r5"),
|
||||||
|
(bytes([0xB9, 0xFF]), "PushRegister", 2, "r255"),
|
||||||
|
(bytes([0xAF, 0x00]), "GetNamedMember", 2, "'alpha'"),
|
||||||
|
(bytes([0xAF, 0x01]), "GetNamedMember", 2, "'beta'"),
|
||||||
|
(bytes([0xA2, 0x01]), "PushConstantByte", 2, "'beta'"),
|
||||||
|
]
|
||||||
|
for raw, mnem, length, needle in fixtures:
|
||||||
|
probe = AptData(APTDATA_MAGIC + raw.ljust(16, b"\0"), pool)
|
||||||
|
probe.scope = movie.scope
|
||||||
|
ins = probe.decode_one(16)
|
||||||
|
check(f"fixture {raw.hex()} -> {mnem}",
|
||||||
|
ins.mnemonic == mnem and ins.length == length and needle in ins.comment,
|
||||||
|
f"{ins.mnemonic} len={ins.length} {ins.comment}")
|
||||||
|
|
||||||
|
# Truncated records must fail closed.
|
||||||
|
for raw in (bytes([0xB9]), bytes([0xAF]), bytes([0xA3, 0x01])):
|
||||||
|
probe = AptData(APTDATA_MAGIC + raw, pool)
|
||||||
|
probe.scope = movie.scope
|
||||||
|
try:
|
||||||
|
probe.decode_one(16)
|
||||||
|
check(f"truncated {raw.hex()} fails closed", False)
|
||||||
|
except DecodeError:
|
||||||
|
check(f"truncated {raw.hex()} fails closed", True)
|
||||||
|
|
||||||
|
# Out-of-range pool index must fail closed, not silently clamp.
|
||||||
|
probe = AptData(APTDATA_MAGIC + bytes([0xAF, 0x10]), pool)
|
||||||
|
probe.scope = ["only-one"]
|
||||||
|
try:
|
||||||
|
probe.decode_one(16)
|
||||||
|
check("out-of-range scope index rejected", False)
|
||||||
|
except DecodeError:
|
||||||
|
check("out-of-range scope index rejected", True)
|
||||||
|
|
||||||
|
# Unknown opcode must refuse rather than resynchronise.
|
||||||
|
probe = AptData(APTDATA_MAGIC + bytes([0xEE, 0x00]), pool)
|
||||||
|
try:
|
||||||
|
probe.decode_one(16)
|
||||||
|
check("unknown opcode refuses to guess length", False)
|
||||||
|
except DecodeError as e:
|
||||||
|
check("unknown opcode refuses to guess length", "refusing to guess" in str(e))
|
||||||
|
|
||||||
|
# Whole-artifact decode.
|
||||||
|
movie.scope = []
|
||||||
|
movie.functions = []
|
||||||
|
seeds = find_streams(movie)
|
||||||
|
instrs: list[Instr] = []
|
||||||
|
try:
|
||||||
|
for s in seeds:
|
||||||
|
instrs.extend(movie.decode_stream(s))
|
||||||
|
check("whole artifact decodes", True, f"{len(instrs)} instructions")
|
||||||
|
except DecodeError as e:
|
||||||
|
check("whole artifact decodes", False, str(e))
|
||||||
|
return 1
|
||||||
|
|
||||||
|
boundaries = {i.offset for i in instrs}
|
||||||
|
bad = [i for i in instrs if i.target is not None and i.target not in boundaries]
|
||||||
|
check("every branch lands on an instruction boundary", not bad,
|
||||||
|
f"{len(bad)} bad")
|
||||||
|
|
||||||
|
# CheckIsKitLocked is CALLED here, never defined here: it is a method on the
|
||||||
|
# mcSelectTeam child clip, whose class lives in another asset. Assert the
|
||||||
|
# call site is bound exactly, and that this asset defines no such function.
|
||||||
|
called = [i for i in instrs if i.comment and "CheckIsKitLocked" in i.comment]
|
||||||
|
check("CheckIsKitLocked referenced exactly once", len(called) == 1,
|
||||||
|
f"{[hex(i.offset) for i in called]}")
|
||||||
|
check("CheckIsKitLocked reference is PushConstantWord (pool index > u8)",
|
||||||
|
bool(called) and called[0].mnemonic == "PushConstantWord")
|
||||||
|
check("CheckIsKitLocked is not defined in this asset",
|
||||||
|
"CheckIsKitLocked" not in {f.name for f in movie.functions})
|
||||||
|
|
||||||
|
# The gate contract the native DP builder must satisfy.
|
||||||
|
gate = [i for i in instrs if i.comment and "KITS_AVAILABLE" in i.comment]
|
||||||
|
check("KITS_AVAILABLE read exactly once", len(gate) == 1)
|
||||||
|
check("KITS_AVAILABLE read via GetNamedMember on the DP header",
|
||||||
|
bool(gate) and gate[0].mnemonic == "GetNamedMember")
|
||||||
|
|
||||||
|
# 8-byte alignment is load-bearing: prove 4 would break the pool record.
|
||||||
|
p4 = (0xD38 + 1 + 3) & ~3
|
||||||
|
c4 = struct.unpack_from("<Q", movie.data, p4)[0]
|
||||||
|
check("alignment is 8 not 4", c4 != 401, f"align4 count would be {c4:#x}")
|
||||||
|
|
||||||
|
print(f"\n {'ALL PASS' if ok else 'FAILURES PRESENT'}")
|
||||||
|
return 0 if ok else 1
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
sys.exit(main())
|
||||||
Executable
+587
@@ -0,0 +1,587 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Interpret FIFA 17's atom -> field-id dispatch functions instead of pattern-scanning them.
|
||||||
|
|
||||||
|
WHY THIS EXISTS
|
||||||
|
---------------
|
||||||
|
CardsDLL turns a JSON key into an "atom index" (a position in the string-pointer
|
||||||
|
table at .data 0x1802d2760), then a per-response-family mapper converts that index
|
||||||
|
into an internal field id with a chain of integer compares and jump tables.
|
||||||
|
|
||||||
|
A previous attempt to recover each mapper's accepted atoms by scanning for
|
||||||
|
`sub ecx,K` / `cmp ecx,L` / `ja` patterns produced a confidently wrong answer: it
|
||||||
|
reported that no mapper accepts atom 424 (`manager`), while a live client plainly
|
||||||
|
holds a resident manager record. Pattern scanning cannot see control flow, so it
|
||||||
|
cannot tell which compares are actually reachable.
|
||||||
|
|
||||||
|
This module executes the mappers instead. The modelled subset is exactly what these
|
||||||
|
functions use: the resolver call, integer cmp/sub/add/dec, conditional and computed
|
||||||
|
jumps, jump-table loads out of the image, lea, movsxd, and `mov eax,imm; ret`.
|
||||||
|
Anything outside that subset raises Unsupported, so a wrong field id is never
|
||||||
|
returned silently.
|
||||||
|
|
||||||
|
TWO DECODER TRAPS THIS MODULE IS REQUIRED TO HANDLE
|
||||||
|
---------------------------------------------------
|
||||||
|
1. ModRM rm==5 with mod!=0 is [rbp+disp], NOT RIP-relative. Only mod==0 with rm==5
|
||||||
|
is RIP-relative. Treating all rm==5 as RIP-relative hides rbp-based DTO accesses.
|
||||||
|
Covered by test_rbp_relative_is_not_rip_relative.
|
||||||
|
2. A constant frequently arrives in a register (`mov r8d,0x4` ... later stored), so
|
||||||
|
searching for an immediate-to-memory store misses it. The interpreter tracks
|
||||||
|
register values, so propagated constants are followed.
|
||||||
|
Covered by test_constant_propagated_through_register.
|
||||||
|
|
||||||
|
Run `--selftest` to execute the positive controls. Negative results from this tool
|
||||||
|
are only admissible when the selftest passes.
|
||||||
|
"""
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import argparse
|
||||||
|
import bisect
|
||||||
|
import struct
|
||||||
|
import sys
|
||||||
|
from pathlib import Path
|
||||||
|
|
||||||
|
REGS = ("rax", "rcx", "rdx", "rbx", "rsp", "rbp", "rsi", "rdi",
|
||||||
|
"r8", "r9", "r10", "r11", "r12", "r13", "r14", "r15")
|
||||||
|
|
||||||
|
ATOM_TABLE_BASE = 0x1802D2760 # validated against 6 known anchors, see anchors()
|
||||||
|
ATOM_RESOLVER = 0x180180D00 # key string -> atom index, returns in eax
|
||||||
|
ITEM_MAPPER = 0x18012FD40 # the DTO/item mapper: atom 568 'players' -> 1
|
||||||
|
|
||||||
|
|
||||||
|
class Unsupported(Exception):
|
||||||
|
"""The mapper used an instruction or address outside the modelled subset."""
|
||||||
|
|
||||||
|
|
||||||
|
def s32(v: int) -> int:
|
||||||
|
v &= 0xFFFFFFFF
|
||||||
|
return v - 0x100000000 if v & 0x80000000 else v
|
||||||
|
|
||||||
|
|
||||||
|
class Image:
|
||||||
|
"""A parsed PE, with VA<->file mapping and .pdata function bounds."""
|
||||||
|
|
||||||
|
def __init__(self, path: Path):
|
||||||
|
self.buf = path.read_bytes()
|
||||||
|
b = self.buf
|
||||||
|
pe = struct.unpack_from("<I", b, 0x3C)[0]
|
||||||
|
if b[pe:pe + 4] != b"PE\0\0":
|
||||||
|
raise ValueError(f"{path} is not a PE image")
|
||||||
|
nsec = struct.unpack_from("<H", b, pe + 6)[0]
|
||||||
|
optsz = struct.unpack_from("<H", b, pe + 20)[0]
|
||||||
|
self.base = struct.unpack_from("<Q", b, pe + 24 + 24)[0]
|
||||||
|
self.sections = []
|
||||||
|
for i in range(nsec):
|
||||||
|
o = pe + 24 + optsz + 40 * i
|
||||||
|
name = b[o:o + 8].rstrip(b"\0").decode(errors="replace")
|
||||||
|
vsz, va, rsz, raw = struct.unpack_from("<IIII", b, o + 8)
|
||||||
|
self.sections.append((name, va, vsz, raw, rsz))
|
||||||
|
self._funcs = None
|
||||||
|
|
||||||
|
def va2off(self, va: int):
|
||||||
|
rva = va - self.base
|
||||||
|
for _name, sva, vsz, raw, rsz in self.sections:
|
||||||
|
if sva <= rva < sva + max(vsz, rsz):
|
||||||
|
off = raw + (rva - sva)
|
||||||
|
if off < len(self.buf):
|
||||||
|
return off
|
||||||
|
return None
|
||||||
|
|
||||||
|
def rd8(self, va: int) -> int:
|
||||||
|
o = self.va2off(va)
|
||||||
|
if o is None:
|
||||||
|
raise Unsupported(f"unmapped byte read 0x{va:x}")
|
||||||
|
return self.buf[o]
|
||||||
|
|
||||||
|
def rd32(self, va: int) -> int:
|
||||||
|
o = self.va2off(va)
|
||||||
|
if o is None:
|
||||||
|
raise Unsupported(f"unmapped dword read 0x{va:x}")
|
||||||
|
return struct.unpack_from("<I", self.buf, o)[0]
|
||||||
|
|
||||||
|
def cstr(self, va: int, maxlen: int = 96):
|
||||||
|
o = self.va2off(va)
|
||||||
|
if o is None:
|
||||||
|
return None
|
||||||
|
end = self.buf.find(b"\0", o, o + maxlen)
|
||||||
|
if end < 0:
|
||||||
|
return None
|
||||||
|
try:
|
||||||
|
return self.buf[o:end].decode("ascii")
|
||||||
|
except UnicodeDecodeError:
|
||||||
|
return None
|
||||||
|
|
||||||
|
# ---- .pdata gives exact function bounds; never guess a prologue ----
|
||||||
|
def functions(self):
|
||||||
|
if self._funcs is None:
|
||||||
|
sec = next(s for s in self.sections if s[0] == ".pdata")
|
||||||
|
_n, _va, vsz, raw, _rsz = sec
|
||||||
|
out = []
|
||||||
|
for i in range(vsz // 12):
|
||||||
|
beg, end, _unw = struct.unpack_from("<III", self.buf, raw + 12 * i)
|
||||||
|
if beg or end:
|
||||||
|
out.append((self.base + beg, self.base + end))
|
||||||
|
out.sort()
|
||||||
|
self._funcs = out
|
||||||
|
return self._funcs
|
||||||
|
|
||||||
|
def function_of(self, va: int):
|
||||||
|
fs = self.functions()
|
||||||
|
starts = [f[0] for f in fs]
|
||||||
|
i = bisect.bisect_right(starts, va) - 1
|
||||||
|
if i >= 0 and fs[i][0] <= va < fs[i][1]:
|
||||||
|
return fs[i]
|
||||||
|
return None
|
||||||
|
|
||||||
|
def atom(self, index: int):
|
||||||
|
ptr = struct.unpack_from("<Q", self.buf, self.va2off(ATOM_TABLE_BASE) + 8 * index)[0]
|
||||||
|
return self.cstr(ptr)
|
||||||
|
|
||||||
|
def atom_index(self, name: str):
|
||||||
|
off = self.va2off(ATOM_TABLE_BASE)
|
||||||
|
for i in range(4096):
|
||||||
|
ptr = struct.unpack_from("<Q", self.buf, off + 8 * i)[0]
|
||||||
|
if self.cstr(ptr) == name:
|
||||||
|
return i
|
||||||
|
return None
|
||||||
|
|
||||||
|
|
||||||
|
class Mapper:
|
||||||
|
"""Executes one dispatch function for a given atom index."""
|
||||||
|
|
||||||
|
def __init__(self, image: Image, resolver: int = ATOM_RESOLVER):
|
||||||
|
self.img = image
|
||||||
|
self.resolver = resolver
|
||||||
|
|
||||||
|
def _ea(self, k: int, rex: int, r: dict):
|
||||||
|
"""Decode ModRM[+SIB][+disp].
|
||||||
|
|
||||||
|
Returns (nbytes, dst_reg, addr, src_reg). addr is an int, or the marker
|
||||||
|
("rip", disp) which the caller resolves once it knows the instruction
|
||||||
|
length, or None for a register-form operand.
|
||||||
|
|
||||||
|
TRAP 1: rm==5 is RIP-relative ONLY when mod==0. With mod 1 or 2 it is
|
||||||
|
[rbp+disp] and must be resolved from rbp.
|
||||||
|
"""
|
||||||
|
b = self.img.buf
|
||||||
|
modrm = b[k]
|
||||||
|
mod, rm = modrm >> 6, modrm & 7
|
||||||
|
dst = REGS[(((modrm >> 3) & 7) | ((rex & 4) << 1)) & 15]
|
||||||
|
n = 1
|
||||||
|
if mod == 3:
|
||||||
|
return n, dst, None, REGS[(rm | ((rex & 1) << 3)) & 15]
|
||||||
|
base_v = idx_v = disp = 0
|
||||||
|
if rm == 4:
|
||||||
|
sib = b[k + 1]
|
||||||
|
n += 1
|
||||||
|
scale = 1 << (sib >> 6)
|
||||||
|
ir = ((sib >> 3) & 7) | ((rex & 2) << 2)
|
||||||
|
br = (sib & 7) | ((rex & 1) << 3)
|
||||||
|
if (ir & 15) != 4:
|
||||||
|
idx_v = r[REGS[ir & 15]] * scale
|
||||||
|
if (sib & 7) == 5 and mod == 0:
|
||||||
|
disp = struct.unpack_from("<i", b, k + n)[0]
|
||||||
|
n += 4
|
||||||
|
else:
|
||||||
|
base_v = r[REGS[br & 15]]
|
||||||
|
elif rm == 5 and mod == 0:
|
||||||
|
disp = struct.unpack_from("<i", b, k + 1)[0]
|
||||||
|
return n + 4, dst, ("rip", disp), None
|
||||||
|
else:
|
||||||
|
base_v = r[REGS[(rm | ((rex & 1) << 3)) & 15]]
|
||||||
|
if mod == 1:
|
||||||
|
disp = struct.unpack_from("<b", b, k + n)[0]
|
||||||
|
n += 1
|
||||||
|
elif mod == 2:
|
||||||
|
disp = struct.unpack_from("<i", b, k + n)[0]
|
||||||
|
n += 4
|
||||||
|
return n, dst, (base_v + idx_v + disp) & 0xFFFFFFFFFFFFFFFF, None
|
||||||
|
|
||||||
|
@staticmethod
|
||||||
|
def _cond(cc: int, last) -> bool:
|
||||||
|
a, b = last
|
||||||
|
sa, sb = s32(a), s32(b)
|
||||||
|
ua, ub = a & 0xFFFFFFFF, b & 0xFFFFFFFF
|
||||||
|
if cc == 0x4: return sa == sb
|
||||||
|
if cc == 0x5: return sa != sb
|
||||||
|
if cc == 0xF: return sa > sb
|
||||||
|
if cc == 0xD: return sa >= sb
|
||||||
|
if cc == 0xC: return sa < sb
|
||||||
|
if cc == 0xE: return sa <= sb
|
||||||
|
if cc == 0x7: return ua > ub
|
||||||
|
if cc == 0x3: return ua >= ub
|
||||||
|
if cc == 0x2: return ua < ub
|
||||||
|
if cc == 0x6: return ua <= ub
|
||||||
|
if cc == 0x8: return sa < sb
|
||||||
|
if cc == 0x9: return sa >= sb
|
||||||
|
raise Unsupported(f"condition code 0x{cc:x}")
|
||||||
|
|
||||||
|
def run(self, start: int, atom: int, limit: int = 5000) -> int:
|
||||||
|
b = self.img.buf
|
||||||
|
r = {k: 0 for k in REGS}
|
||||||
|
last = (0, 0)
|
||||||
|
va = start
|
||||||
|
for _ in range(limit):
|
||||||
|
i0 = self.img.va2off(va)
|
||||||
|
if i0 is None:
|
||||||
|
raise Unsupported(f"pc unmapped 0x{va:x}")
|
||||||
|
j = i0
|
||||||
|
while b[j] in (0x66, 0x67, 0xF2, 0xF3):
|
||||||
|
j += 1
|
||||||
|
rex = 0
|
||||||
|
if 0x40 <= b[j] <= 0x4F:
|
||||||
|
rex = b[j]
|
||||||
|
j += 1
|
||||||
|
op = b[j]
|
||||||
|
pre = j - i0
|
||||||
|
|
||||||
|
if op == 0xC3:
|
||||||
|
return r["rax"] & 0xFFFFFFFF
|
||||||
|
if op == 0xCC:
|
||||||
|
raise Unsupported(f"int3 at 0x{va:x}: ran off the end of the function")
|
||||||
|
if op == 0xE8:
|
||||||
|
tgt = va + pre + 5 + struct.unpack_from("<i", b, j + 1)[0]
|
||||||
|
if tgt != self.resolver:
|
||||||
|
raise Unsupported(f"call to non-resolver 0x{tgt:x} at 0x{va:x}")
|
||||||
|
r["rax"] = atom & 0xFFFFFFFF # resolver returns the atom index
|
||||||
|
va += pre + 5
|
||||||
|
continue
|
||||||
|
if op == 0xE9:
|
||||||
|
va += pre + 5 + struct.unpack_from("<i", b, j + 1)[0]
|
||||||
|
continue
|
||||||
|
if op == 0xEB:
|
||||||
|
va += pre + 2 + struct.unpack_from("<b", b, j + 1)[0]
|
||||||
|
continue
|
||||||
|
if 0x70 <= op <= 0x7F:
|
||||||
|
nxt = va + pre + 2
|
||||||
|
rel = struct.unpack_from("<b", b, j + 1)[0]
|
||||||
|
va = nxt + rel if self._cond(op & 0xF, last) else nxt
|
||||||
|
continue
|
||||||
|
if op == 0x0F and 0x80 <= b[j + 1] <= 0x8F:
|
||||||
|
nxt = va + pre + 6
|
||||||
|
rel = struct.unpack_from("<i", b, j + 2)[0]
|
||||||
|
va = nxt + rel if self._cond(b[j + 1] & 0xF, last) else nxt
|
||||||
|
continue
|
||||||
|
if 0xB8 <= op <= 0xBF:
|
||||||
|
r[REGS[((op - 0xB8) | ((rex & 1) << 3)) & 15]] = struct.unpack_from("<I", b, j + 1)[0]
|
||||||
|
va += pre + 5
|
||||||
|
continue
|
||||||
|
if op in (0x05, 0x2D, 0x3D):
|
||||||
|
# accumulator short forms: add/sub/cmp eax, imm32
|
||||||
|
imm = struct.unpack_from("<i", b, j + 1)[0]
|
||||||
|
cur = r["rax"] & 0xFFFFFFFF
|
||||||
|
if op == 0x3D:
|
||||||
|
last = (cur, imm & 0xFFFFFFFF)
|
||||||
|
elif op == 0x2D:
|
||||||
|
r["rax"] = (cur - imm) & 0xFFFFFFFF
|
||||||
|
last = (r["rax"], 0)
|
||||||
|
else:
|
||||||
|
r["rax"] = (cur + imm) & 0xFFFFFFFF
|
||||||
|
last = (r["rax"], 0)
|
||||||
|
va += pre + 5
|
||||||
|
continue
|
||||||
|
if op in (0x81, 0x83):
|
||||||
|
w = 4 if op == 0x81 else 1
|
||||||
|
modrm = b[j + 1]
|
||||||
|
if modrm >> 6 != 3:
|
||||||
|
raise Unsupported(f"{op:02x} memory form at 0x{va:x}")
|
||||||
|
reg = REGS[((modrm & 7) | ((rex & 1) << 3)) & 15]
|
||||||
|
imm = struct.unpack_from("<i" if w == 4 else "<b", b, j + 2)[0]
|
||||||
|
ext = (modrm >> 3) & 7
|
||||||
|
cur = r[reg] & 0xFFFFFFFF
|
||||||
|
if ext == 7:
|
||||||
|
last = (cur, imm & 0xFFFFFFFF)
|
||||||
|
elif ext == 5:
|
||||||
|
r[reg] = (cur - imm) & 0xFFFFFFFF
|
||||||
|
last = (r[reg], 0)
|
||||||
|
elif ext == 0:
|
||||||
|
r[reg] = (cur + imm) & 0xFFFFFFFF
|
||||||
|
last = (r[reg], 0)
|
||||||
|
else:
|
||||||
|
raise Unsupported(f"{op:02x} /{ext} at 0x{va:x}")
|
||||||
|
va += pre + 2 + w
|
||||||
|
continue
|
||||||
|
if op == 0xFF and b[j + 1] >> 6 == 3:
|
||||||
|
ext = (b[j + 1] >> 3) & 7
|
||||||
|
reg = REGS[((b[j + 1] & 7) | ((rex & 1) << 3)) & 15]
|
||||||
|
if ext == 1:
|
||||||
|
r[reg] = (r[reg] - 1) & 0xFFFFFFFF
|
||||||
|
last = (r[reg], 0)
|
||||||
|
va += pre + 2
|
||||||
|
continue
|
||||||
|
if ext == 4:
|
||||||
|
va = r[reg]
|
||||||
|
continue
|
||||||
|
raise Unsupported(f"ff /{ext} at 0x{va:x}")
|
||||||
|
if op == 0x0F and b[j + 1] == 0xB6:
|
||||||
|
n, dst, addr, src = self._ea(j + 2, rex, r)
|
||||||
|
end = va + pre + 2 + n
|
||||||
|
if isinstance(addr, tuple):
|
||||||
|
addr = end + addr[1]
|
||||||
|
r[dst] = self.img.rd8(addr) if addr is not None else r[src] & 0xFF
|
||||||
|
va = end
|
||||||
|
continue
|
||||||
|
if op in (0x8B, 0x8D):
|
||||||
|
n, dst, addr, src = self._ea(j + 1, rex, r)
|
||||||
|
end = va + pre + 1 + n
|
||||||
|
if isinstance(addr, tuple):
|
||||||
|
addr = end + addr[1]
|
||||||
|
if op == 0x8D:
|
||||||
|
if addr is None:
|
||||||
|
raise Unsupported(f"lea with register operand at 0x{va:x}")
|
||||||
|
r[dst] = addr
|
||||||
|
else:
|
||||||
|
if addr is None:
|
||||||
|
# register form: mov r32, r32 (e.g. 8b c8 = mov ecx,eax)
|
||||||
|
r[dst] = r[src] if rex & 8 else r[src] & 0xFFFFFFFF
|
||||||
|
else:
|
||||||
|
r[dst] = self.img.rd32(addr)
|
||||||
|
va = end
|
||||||
|
continue
|
||||||
|
if op == 0x89:
|
||||||
|
modrm = b[j + 1]
|
||||||
|
if modrm >> 6 != 3:
|
||||||
|
raise Unsupported(f"89 memory store at 0x{va:x}")
|
||||||
|
src = REGS[((((modrm >> 3) & 7) | ((rex & 4) << 1))) & 15]
|
||||||
|
dst = REGS[((modrm & 7) | ((rex & 1) << 3)) & 15]
|
||||||
|
r[dst] = r[src] if rex & 8 else r[src] & 0xFFFFFFFF
|
||||||
|
va += pre + 2
|
||||||
|
continue
|
||||||
|
if op == 0x63:
|
||||||
|
modrm = b[j + 1]
|
||||||
|
if modrm >> 6 != 3:
|
||||||
|
raise Unsupported(f"63 memory form at 0x{va:x}")
|
||||||
|
src = REGS[((modrm & 7) | ((rex & 1) << 3)) & 15]
|
||||||
|
dst = REGS[((((modrm >> 3) & 7) | ((rex & 4) << 1))) & 15]
|
||||||
|
r[dst] = s32(r[src]) & 0xFFFFFFFFFFFFFFFF
|
||||||
|
va += pre + 2
|
||||||
|
continue
|
||||||
|
if op in (0x01, 0x03, 0x29, 0x2B, 0x39, 0x3B,
|
||||||
|
0x09, 0x0B, 0x21, 0x23, 0x31, 0x33, 0x85):
|
||||||
|
modrm = b[j + 1]
|
||||||
|
if modrm >> 6 != 3:
|
||||||
|
raise Unsupported(f"{op:02x} memory form at 0x{va:x}")
|
||||||
|
a = REGS[((modrm & 7) | ((rex & 1) << 3)) & 15]
|
||||||
|
c = REGS[((((modrm >> 3) & 7) | ((rex & 4) << 1))) & 15]
|
||||||
|
m = 0xFFFFFFFFFFFFFFFF if rex & 8 else 0xFFFFFFFF
|
||||||
|
if op == 0x01:
|
||||||
|
r[a] = (r[a] + r[c]) & m
|
||||||
|
elif op == 0x03:
|
||||||
|
r[c] = (r[c] + r[a]) & m
|
||||||
|
elif op == 0x29:
|
||||||
|
r[a] = (r[a] - r[c]) & m
|
||||||
|
last = (r[a] & 0xFFFFFFFF, 0)
|
||||||
|
elif op == 0x2B:
|
||||||
|
r[c] = (r[c] - r[a]) & m
|
||||||
|
last = (r[c] & 0xFFFFFFFF, 0)
|
||||||
|
elif op in (0x09, 0x0B, 0x21, 0x23, 0x31, 0x33):
|
||||||
|
fn = {0x09: lambda x, y: x | y, 0x0B: lambda x, y: x | y,
|
||||||
|
0x21: lambda x, y: x & y, 0x23: lambda x, y: x & y,
|
||||||
|
0x31: lambda x, y: x ^ y, 0x33: lambda x, y: x ^ y}[op]
|
||||||
|
if op in (0x09, 0x21, 0x31):
|
||||||
|
r[a] = fn(r[a], r[c]) & m
|
||||||
|
last = (r[a] & 0xFFFFFFFF, 0)
|
||||||
|
else:
|
||||||
|
r[c] = fn(r[c], r[a]) & m
|
||||||
|
last = (r[c] & 0xFFFFFFFF, 0)
|
||||||
|
elif op == 0x85:
|
||||||
|
last = ((r[a] & r[c]) & 0xFFFFFFFF, 0)
|
||||||
|
elif op == 0x39:
|
||||||
|
last = (r[a] & 0xFFFFFFFF, r[c] & 0xFFFFFFFF)
|
||||||
|
else:
|
||||||
|
last = (r[c] & 0xFFFFFFFF, r[a] & 0xFFFFFFFF)
|
||||||
|
va += pre + 2
|
||||||
|
continue
|
||||||
|
if op == 0x90:
|
||||||
|
va += pre + 1
|
||||||
|
continue
|
||||||
|
if op == 0x0F and b[j + 1] == 0x1F:
|
||||||
|
n, _d, _a, _s = self._ea(j + 2, rex, r)
|
||||||
|
va += pre + 2 + n
|
||||||
|
continue
|
||||||
|
raise Unsupported(f"opcode {op:02x} at 0x{va:x}")
|
||||||
|
raise Unsupported("instruction limit reached")
|
||||||
|
|
||||||
|
|
||||||
|
def find_mappers(img: Image, resolver: int = ATOM_RESOLVER):
|
||||||
|
"""Every function containing a direct call to the atom resolver."""
|
||||||
|
sec = next(s for s in img.sections if s[0] == ".text")
|
||||||
|
_n, tva, _vsz, traw, trsz = sec
|
||||||
|
out = {}
|
||||||
|
for i in range(traw, traw + trsz - 5):
|
||||||
|
if img.buf[i] != 0xE8:
|
||||||
|
continue
|
||||||
|
va = img.base + tva + (i - traw)
|
||||||
|
if va + 5 + struct.unpack_from("<i", img.buf, i + 1)[0] == resolver:
|
||||||
|
f = img.function_of(va)
|
||||||
|
if f:
|
||||||
|
out.setdefault(f[0], []).append(va)
|
||||||
|
return out
|
||||||
|
|
||||||
|
|
||||||
|
# --------------------------------------------------------------------------
|
||||||
|
# selftest: the two decoder traps plus the live-verified positive controls
|
||||||
|
# --------------------------------------------------------------------------
|
||||||
|
def test_atom_anchors(img: Image) -> list:
|
||||||
|
"""The atom table base must reproduce known anchors, or every index is wrong."""
|
||||||
|
anchors = {11: "actives", 363: "itemData", 376: "kicktakers",
|
||||||
|
424: "manager", 568: "players", 718: "squadActives"}
|
||||||
|
fails = []
|
||||||
|
for idx, want in anchors.items():
|
||||||
|
got = img.atom(idx)
|
||||||
|
if got != want:
|
||||||
|
fails.append(f"atom[{idx}] = {got!r}, expected {want!r}")
|
||||||
|
return fails
|
||||||
|
|
||||||
|
|
||||||
|
def test_rbp_relative_is_not_rip_relative(img: Image) -> list:
|
||||||
|
"""TRAP 1. mod!=0 with rm==5 must resolve as [rbp+disp], not RIP-relative.
|
||||||
|
|
||||||
|
Encoding under test: 8b 4d 20 == mov ecx,[rbp+0x20] (mod=01, rm=101).
|
||||||
|
A decoder that treats rm==5 as RIP-relative computes a wildly different
|
||||||
|
address and silently reads the wrong memory.
|
||||||
|
"""
|
||||||
|
m = Mapper(img)
|
||||||
|
r = {k: 0 for k in REGS}
|
||||||
|
r["rbp"] = 0x140000000
|
||||||
|
saved = img.buf
|
||||||
|
try:
|
||||||
|
img.buf = bytes.fromhex("8b4d20")
|
||||||
|
n, dst, addr, _src = m._ea(1, 0, r)
|
||||||
|
finally:
|
||||||
|
img.buf = saved
|
||||||
|
fails = []
|
||||||
|
if isinstance(addr, tuple):
|
||||||
|
fails.append("mod=01 rm=101 decoded as RIP-relative; must be [rbp+disp]")
|
||||||
|
elif addr != 0x140000020:
|
||||||
|
fails.append(f"[rbp+0x20] resolved to 0x{addr:x}, expected 0x140000020")
|
||||||
|
if dst != "rcx":
|
||||||
|
fails.append(f"destination decoded as {dst}, expected rcx")
|
||||||
|
if n != 2:
|
||||||
|
fails.append(f"modrm+disp8 consumed {n} bytes, expected 2")
|
||||||
|
return fails
|
||||||
|
|
||||||
|
|
||||||
|
def test_constant_propagated_through_register(img: Image) -> list:
|
||||||
|
"""TRAP 2. A constant reaching a use through a register must be followed.
|
||||||
|
|
||||||
|
Program: mov eax,0; mov r8d,4; mov eax,r8d; ret -> must yield 4, which is
|
||||||
|
only observable if register values propagate. Scanning for an immediate
|
||||||
|
store would see nothing.
|
||||||
|
"""
|
||||||
|
m = Mapper(img)
|
||||||
|
saved = img.buf
|
||||||
|
prog = bytes.fromhex("b800000000" "41b804000000" "4489c0" "c3")
|
||||||
|
try:
|
||||||
|
img.buf = prog
|
||||||
|
img_va2off = img.va2off
|
||||||
|
img.va2off = lambda va: va if 0 <= va < len(prog) else None
|
||||||
|
got = m.run(0, 0)
|
||||||
|
finally:
|
||||||
|
img.buf = saved
|
||||||
|
img.va2off = img_va2off
|
||||||
|
return [] if got == 4 else [f"register-propagated constant yielded {got}, expected 4"]
|
||||||
|
|
||||||
|
|
||||||
|
def test_item_mapper_controls(img: Image) -> list:
|
||||||
|
"""Live/disassembly-verified behaviour of the item mapper."""
|
||||||
|
m = Mapper(img)
|
||||||
|
fails = []
|
||||||
|
got = m.run(ITEM_MAPPER, 568)
|
||||||
|
if got != 1:
|
||||||
|
fails.append(f"item mapper atom 568 'players' -> {got}, expected 1")
|
||||||
|
got = m.run(ITEM_MAPPER, 11)
|
||||||
|
if got != 0:
|
||||||
|
fails.append(f"item mapper atom 11 'actives' -> {got}, expected 0")
|
||||||
|
return fails
|
||||||
|
|
||||||
|
|
||||||
|
def test_manager_424_is_accepted_somewhere(img: Image) -> list:
|
||||||
|
"""MANDATORY control. A live client holds a resident manager record, so some
|
||||||
|
mapper must map atom 424 to a non-zero field id. The previous pattern-scan
|
||||||
|
method failed exactly here, and any replacement must not."""
|
||||||
|
m = Mapper(img)
|
||||||
|
accepting = []
|
||||||
|
for start in find_mappers(img):
|
||||||
|
try:
|
||||||
|
if m.run(start, 424):
|
||||||
|
accepting.append(start)
|
||||||
|
except Unsupported:
|
||||||
|
continue
|
||||||
|
if not accepting:
|
||||||
|
return ["no mapper maps atom 424 'manager' to a non-zero field id, "
|
||||||
|
"which contradicts the live resident manager record"]
|
||||||
|
return []
|
||||||
|
|
||||||
|
|
||||||
|
def selftest(img: Image) -> int:
|
||||||
|
checks = [
|
||||||
|
("atom table anchors", test_atom_anchors),
|
||||||
|
("trap 1: rbp-relative modrm", test_rbp_relative_is_not_rip_relative),
|
||||||
|
("trap 2: constant via register", test_constant_propagated_through_register),
|
||||||
|
("item mapper positive controls", test_item_mapper_controls),
|
||||||
|
("mandatory: manager atom 424 accepted", test_manager_424_is_accepted_somewhere),
|
||||||
|
]
|
||||||
|
bad = 0
|
||||||
|
for name, fn in checks:
|
||||||
|
try:
|
||||||
|
fails = fn(img)
|
||||||
|
except Exception as exc: # noqa: BLE001 - report, don't mask
|
||||||
|
fails = [f"raised {type(exc).__name__}: {exc}"]
|
||||||
|
if fails:
|
||||||
|
bad += 1
|
||||||
|
print(f" FAIL {name}")
|
||||||
|
for f in fails:
|
||||||
|
print(f" {f}")
|
||||||
|
else:
|
||||||
|
print(f" ok {name}")
|
||||||
|
print("\n ALL PASS" if not bad else f"\n {bad} CHECK(S) FAILED - negative results are NOT admissible")
|
||||||
|
return 1 if bad else 0
|
||||||
|
|
||||||
|
|
||||||
|
def main() -> int:
|
||||||
|
ap = argparse.ArgumentParser(description=__doc__,
|
||||||
|
formatter_class=argparse.RawDescriptionHelpFormatter)
|
||||||
|
ap.add_argument("image", type=Path, help="CardsDLL_Win64_retail.dll")
|
||||||
|
ap.add_argument("--selftest", action="store_true")
|
||||||
|
ap.add_argument("--atom", type=int, action="append", default=[],
|
||||||
|
help="atom index to resolve through every mapper")
|
||||||
|
ap.add_argument("--name", action="append", default=[],
|
||||||
|
help="atom name to resolve through every mapper")
|
||||||
|
args = ap.parse_args()
|
||||||
|
img = Image(args.image)
|
||||||
|
|
||||||
|
if args.selftest:
|
||||||
|
return selftest(img)
|
||||||
|
|
||||||
|
atoms = list(args.atom)
|
||||||
|
for nm in args.name:
|
||||||
|
idx = img.atom_index(nm)
|
||||||
|
if idx is None:
|
||||||
|
print(f" atom {nm!r} not found in the table")
|
||||||
|
return 2
|
||||||
|
atoms.append(idx)
|
||||||
|
if not atoms:
|
||||||
|
ap.error("give --atom/--name, or --selftest")
|
||||||
|
|
||||||
|
m = Mapper(img)
|
||||||
|
mappers = find_mappers(img)
|
||||||
|
print(f" {len(mappers)} mapper function(s) found\n")
|
||||||
|
for a in atoms:
|
||||||
|
print(f" === atom {a} ({img.atom(a)!r}) ===")
|
||||||
|
rows, unsup = [], 0
|
||||||
|
for start in sorted(mappers):
|
||||||
|
try:
|
||||||
|
fid = m.run(start, a)
|
||||||
|
except Unsupported:
|
||||||
|
unsup += 1
|
||||||
|
continue
|
||||||
|
if fid:
|
||||||
|
rows.append((start, fid))
|
||||||
|
for start, fid in rows:
|
||||||
|
print(f" mapper 0x{start:x} -> field id {fid} (0x{fid:x})")
|
||||||
|
print(f" {len(rows)} mapper(s) accept it; {unsup} not modelled\n")
|
||||||
|
return 0
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
sys.exit(main())
|
||||||
Executable
+190
@@ -0,0 +1,190 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Canonical FIFA 17 kit map, joined from the extracted client tables.
|
||||||
|
|
||||||
|
Authority for every kit question that a table can answer, so nobody has to
|
||||||
|
reverse a binary for a fact that is sitting in a JSON row. Reads only:
|
||||||
|
|
||||||
|
fifa17-recon/data/tables/fcc_kitcards.json the FUT KIT CARD definitions
|
||||||
|
fifa17-recon/data/tables/teamkits.json the ENGINE kit rows
|
||||||
|
|
||||||
|
Everything printed is TABLE_PROVEN unless the line says otherwise: it is a
|
||||||
|
direct count over the full table, not a sample.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
python3 audit_fifa17_kits.py human report
|
||||||
|
python3 audit_fifa17_kits.py --json machine-readable, for tests/tools
|
||||||
|
python3 audit_fifa17_kits.py --team 21 drill into one team
|
||||||
|
"""
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import argparse
|
||||||
|
import json
|
||||||
|
import os
|
||||||
|
import sys
|
||||||
|
from collections import Counter, defaultdict
|
||||||
|
|
||||||
|
TABLES = os.path.join(os.path.dirname(os.path.abspath(__file__)), "..", "data", "tables")
|
||||||
|
|
||||||
|
# TABLE_PROVEN, established by this script's own discriminating test (see
|
||||||
|
# category_type_evidence): a kit CARD's `category` selects the engine kit ROW's
|
||||||
|
# `teamkittypetechid` at the same (team, year).
|
||||||
|
CATEGORY_TO_KIT_TYPE = {2: 0, 3: 1, 5: 2}
|
||||||
|
KIT_TYPE_NAME = {0: "HOME", 1: "AWAY", 2: "THIRD", 3: "FOURTH", 5: "GK", 6: "SPECIAL6", 7: "SPECIAL7"}
|
||||||
|
|
||||||
|
|
||||||
|
def load(name):
|
||||||
|
with open(os.path.join(TABLES, name), "r", encoding="utf-8") as fh:
|
||||||
|
data = json.load(fh)
|
||||||
|
return data if isinstance(data, list) else data.get("rows", data)
|
||||||
|
|
||||||
|
|
||||||
|
def band(carddbid: int) -> int:
|
||||||
|
"""The 6_300_000 / 6_400_000 id band."""
|
||||||
|
return (carddbid // 100_000) * 100_000
|
||||||
|
|
||||||
|
|
||||||
|
def category_type_evidence(cards, kits):
|
||||||
|
"""The DISCRIMINATING test behind CATEGORY_TO_KIT_TYPE.
|
||||||
|
|
||||||
|
Asserting "category 3 means away" because away kits usually exist is not
|
||||||
|
evidence -- types 0/1/2 are present for most teams, so the claim is true by
|
||||||
|
construction. What discriminates is the teams that LACK a type: if category 3
|
||||||
|
really means type 1, then no category-3 card may exist for a (team, year)
|
||||||
|
that has no type-1 row. Same for category 5 and type 2.
|
||||||
|
"""
|
||||||
|
kits_by = defaultdict(set)
|
||||||
|
for r in kits:
|
||||||
|
kits_by[(r["teamtechid"], r["year"])].add(r["teamkittypetechid"])
|
||||||
|
cards_by = defaultdict(list)
|
||||||
|
for r in cards:
|
||||||
|
cards_by[(r["teamid"], r["year"])].append(r)
|
||||||
|
|
||||||
|
out = {}
|
||||||
|
for cat, want in CATEGORY_TO_KIT_TYPE.items():
|
||||||
|
# keys that HAVE teamkits rows but not the wanted type
|
||||||
|
lacking = [k for k, t in kits_by.items() if t and want not in t]
|
||||||
|
counterexamples = [
|
||||||
|
r["carddbid"] for k in lacking for r in cards_by.get(k, []) if r["category"] == cat
|
||||||
|
]
|
||||||
|
out[cat] = {
|
||||||
|
"kit_type": want,
|
||||||
|
"name": KIT_TYPE_NAME[want],
|
||||||
|
"keys_lacking_type": len(lacking),
|
||||||
|
"counterexamples": counterexamples,
|
||||||
|
}
|
||||||
|
return out
|
||||||
|
|
||||||
|
|
||||||
|
def audit():
|
||||||
|
cards = load("fcc_kitcards.json")
|
||||||
|
kits = load("teamkits.json")
|
||||||
|
|
||||||
|
kits_by = defaultdict(list)
|
||||||
|
for r in kits:
|
||||||
|
kits_by[(r["teamtechid"], r["year"])].append(r)
|
||||||
|
|
||||||
|
rows = []
|
||||||
|
for c in cards:
|
||||||
|
key = (c["teamid"], c["year"])
|
||||||
|
want = CATEGORY_TO_KIT_TYPE.get(c["category"])
|
||||||
|
match = next((k for k in kits_by.get(key, []) if k["teamkittypetechid"] == want), None)
|
||||||
|
rows.append(
|
||||||
|
{
|
||||||
|
"carddbid": c["carddbid"],
|
||||||
|
"band": band(c["carddbid"]),
|
||||||
|
"teamid": c["teamid"],
|
||||||
|
"year": c["year"],
|
||||||
|
"category": c["category"],
|
||||||
|
"kit_type": want,
|
||||||
|
"kit_type_name": KIT_TYPE_NAME.get(want, "?"),
|
||||||
|
"assetid": c["assetid"],
|
||||||
|
"cardassetid": c["cardassetid"],
|
||||||
|
"value": c["value"],
|
||||||
|
"weightrare": c["weightrare"],
|
||||||
|
# These are BYTE OFFSETS into the table's string blob, not ids.
|
||||||
|
# The blob is not among the extracted tables, so a kit's own
|
||||||
|
# name string is NOT recoverable from data/tables alone.
|
||||||
|
"name_offset": c["name"],
|
||||||
|
"header_offset": c["header"],
|
||||||
|
"description_offset": c["description"],
|
||||||
|
"teamkitid": match["teamkitid"] if match else None,
|
||||||
|
"teamkit_islocked": match["islocked"] if match else None,
|
||||||
|
"teamkit_embargoed": match["isembargoed"] if match else None,
|
||||||
|
}
|
||||||
|
)
|
||||||
|
|
||||||
|
dupes = [k for k, n in Counter((r["teamid"], r["year"], r["category"]) for r in rows).items() if n > 1]
|
||||||
|
|
||||||
|
return {
|
||||||
|
"counts": {"fcc_kitcards": len(cards), "teamkits": len(kits)},
|
||||||
|
"bands": dict(sorted(Counter(r["band"] for r in rows).items())),
|
||||||
|
"band_x_assetid": {f"{b}/{a}": n for (b, a), n in
|
||||||
|
sorted(Counter((r["band"], r["assetid"]) for r in rows).items())},
|
||||||
|
"band_x_category": {f"{b}/{c}": n for (b, c), n in
|
||||||
|
sorted(Counter((r["band"], r["category"]) for r in rows).items())},
|
||||||
|
"category_counts": dict(sorted(Counter(r["category"] for r in rows).items())),
|
||||||
|
"cardassetid": sorted({r["cardassetid"] for r in rows}),
|
||||||
|
"category_type_evidence": category_type_evidence(cards, kits),
|
||||||
|
"unmatched": [r["carddbid"] for r in rows if r["teamkitid"] is None],
|
||||||
|
"duplicate_team_year_category": dupes,
|
||||||
|
"teamkits_islocked": dict(Counter(r["islocked"] for r in kits)),
|
||||||
|
"teamkits_embargoed": dict(Counter(r["isembargoed"] for r in kits)),
|
||||||
|
"teamkits_types": dict(sorted(Counter(r["teamkittypetechid"] for r in kits).items())),
|
||||||
|
"rows": rows,
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
ap = argparse.ArgumentParser()
|
||||||
|
ap.add_argument("--json", action="store_true")
|
||||||
|
ap.add_argument("--team", type=int)
|
||||||
|
args = ap.parse_args()
|
||||||
|
|
||||||
|
a = audit()
|
||||||
|
if args.json:
|
||||||
|
json.dump(a, sys.stdout, indent=2)
|
||||||
|
return
|
||||||
|
|
||||||
|
print("FIFA 17 kit map — TABLE_PROVEN from the extracted client tables")
|
||||||
|
print(f" fcc_kitcards rows : {a['counts']['fcc_kitcards']}")
|
||||||
|
print(f" teamkits rows : {a['counts']['teamkits']}")
|
||||||
|
|
||||||
|
print("\nid bands")
|
||||||
|
for b, n in a["bands"].items():
|
||||||
|
print(f" {b}: {n}")
|
||||||
|
print("\nband/assetid (assetid is fully determined by band)")
|
||||||
|
for k, n in a["band_x_assetid"].items():
|
||||||
|
print(f" {k}: {n}")
|
||||||
|
print("\nband/category")
|
||||||
|
for k, n in a["band_x_category"].items():
|
||||||
|
print(f" {k}: {n}")
|
||||||
|
print(f"\ncardassetid values: {a['cardassetid']} (the FUT card frame, not the kit art)")
|
||||||
|
|
||||||
|
print("\ncategory -> engine kit type, with the discriminating test")
|
||||||
|
for cat, ev in a["category_type_evidence"].items():
|
||||||
|
verdict = "HOLDS" if not ev["counterexamples"] else f"FAILS ({len(ev['counterexamples'])})"
|
||||||
|
print(f" category {cat} -> type {ev['kit_type']} {ev['name']:6s} "
|
||||||
|
f"| {ev['keys_lacking_type']:4d} (team,year) keys lack that type, "
|
||||||
|
f"{len(ev['counterexamples'])} counterexample(s) -> {verdict}")
|
||||||
|
|
||||||
|
print("\nengine kit types present in teamkits")
|
||||||
|
for t, n in a["teamkits_types"].items():
|
||||||
|
print(f" type {t} {KIT_TYPE_NAME.get(t,'?'):8s}: {n}")
|
||||||
|
|
||||||
|
print(f"\nteamkits islocked : {a['teamkits_islocked']} <- every row, so NOT the selector lock")
|
||||||
|
print(f"teamkits embargoed : {a['teamkits_embargoed']}")
|
||||||
|
|
||||||
|
print(f"\nanomalies")
|
||||||
|
print(f" cards with no matching teamkits row : {len(a['unmatched'])}")
|
||||||
|
print(f" duplicate (team,year,category) : {len(a['duplicate_team_year_category'])}")
|
||||||
|
|
||||||
|
if args.team is not None:
|
||||||
|
print(f"\n=== team {args.team} ===")
|
||||||
|
print(f" {'carddbid':10s} {'cat':4s} {'type':7s} {'year':6s} {'assetid':8s} {'teamkitid':10s} locked")
|
||||||
|
for r in sorted((r for r in a["rows"] if r["teamid"] == args.team), key=lambda r: r["carddbid"]):
|
||||||
|
print(f" {r['carddbid']:<10} {r['category']:<4} {r['kit_type_name']:<7} {r['year']:<6} "
|
||||||
|
f"{r['assetid']:<8} {str(r['teamkitid']):<10} {r['teamkit_islocked']}")
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
main()
|
||||||
@@ -24,6 +24,45 @@ STORE_PATCHES = {
|
|||||||
0x1800175aa: NOP2,
|
0x1800175aa: NOP2,
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# Store resolver crash-guard for the empty "My Packs" case (bug 6c; PROVEN R1 on the
|
||||||
|
# tested FIFA 17 build -- see docs/plans/FIFA17_EMPTY_MYPACKS_CLIENT_FIX.md PART IV and
|
||||||
|
# docs/evidence/FIFA17_EMPTY_MYPACKS_CLIENT_CONTRACT.md).
|
||||||
|
#
|
||||||
|
# When no `mypacks` group exists, FIFA's Store resolver receives category id -1. CardsDLL
|
||||||
|
# FUN_1800147f0 @ 0x180014858 is `JNZ 0x14869` (75 0f): the original treats every non-zero
|
||||||
|
# category (including -1) as resolvable, calls FUN_180014420, gets NULL, and crashes at the
|
||||||
|
# [NULL+0x48] deref in FUN_1800147f0 (0x180014882). Changing JNZ->JG (7f 0f) preserves
|
||||||
|
# positive-category resolution (EDI>0 branch) while routing zero/negative categories through
|
||||||
|
# the existing Browse/list-all path -> no NULL lookup, no crash, Store opens on Browse Packs.
|
||||||
|
#
|
||||||
|
# CAVEAT: this guards the category SIGN only. It does NOT protect a stale *positive* invalid
|
||||||
|
# ordinal produced by changing the Store group topology (sentinel-present <-> sentinel-absent)
|
||||||
|
# DURING one running FIFA process -- that reproduced the same crash in the confounded run F3.
|
||||||
|
# The empty-My-Packs representation MUST stay stable for a FIFA session (see the SESSION-STABLE
|
||||||
|
# invariant in the client-fix plan).
|
||||||
|
#
|
||||||
|
# Orig-verified / fail-closed: applied only when the live bytes are the known original (75 0f);
|
||||||
|
# already-patched (7f 0f) is a no-op; anything else is logged and SKIPPED (never blindly
|
||||||
|
# overwritten), so an unrecognised CardsDLL build is not patched.
|
||||||
|
STORE_PATCHES_GUARDED = {
|
||||||
|
0x180014858: (bytes.fromhex("750f"), bytes.fromhex("7f0f")), # JNZ 0x14869 -> JG 0x14869
|
||||||
|
}
|
||||||
|
|
||||||
|
# Capability advertised to the launcher/backend once the resolver guard is VERIFIED
|
||||||
|
# live in a specific FIFA process (docs/plans/FIFA17_PATCHED_CLIENT_CAPABILITY.md #3/#4).
|
||||||
|
EMPTY_MYPACKS_RESOLVER_CAPABILITY = "fifa17.empty_mypacks_resolver"
|
||||||
|
EMPTY_MYPACKS_RESOLVER_VERSION = 1
|
||||||
|
|
||||||
|
# The guarded site whose verified enforcement backs the capability above.
|
||||||
|
RESOLVER_GUARD_VA = 0x180014858
|
||||||
|
|
||||||
|
# Per-FIFA-pid guard status (fail-closed; FIFA17_PATCHED_CLIENT_CAPABILITY.md #4).
|
||||||
|
GUARD_NOT_ATTEMPTED = "NOT_ATTEMPTED" # CardsDLL not mapped / guard not yet evaluated
|
||||||
|
GUARD_VERIFIED = "VERIFIED" # live bytes == patch after enforcement (patch or noop)
|
||||||
|
GUARD_UNSUPPORTED_BUILD = "UNSUPPORTED_BUILD" # neither original nor patched (guarded_action -> skip)
|
||||||
|
GUARD_WRITE_FAILED = "WRITE_FAILED" # /proc/<pid>/mem write raised
|
||||||
|
GUARD_VERIFY_FAILED = "VERIFY_FAILED" # post-write re-read != patch
|
||||||
|
|
||||||
LOG=os.environ.get("OPENFUT_AUTOPATCH_LOG", f"/tmp/openfut-autopatch-{os.getuid()}.log")
|
LOG=os.environ.get("OPENFUT_AUTOPATCH_LOG", f"/tmp/openfut-autopatch-{os.getuid()}.log")
|
||||||
|
|
||||||
def log(m):
|
def log(m):
|
||||||
@@ -52,16 +91,52 @@ def wr(pid,va,b):
|
|||||||
with open(f'/proc/{pid}/mem','r+b') as f:
|
with open(f'/proc/{pid}/mem','r+b') as f:
|
||||||
f.seek(va); f.write(b)
|
f.seek(va); f.write(b)
|
||||||
|
|
||||||
|
def guarded_action(cur, orig, patch):
|
||||||
|
"""Fail-closed decision for a guarded byte patch (see STORE_PATCHES_GUARDED).
|
||||||
|
|
||||||
|
Returns "noop" when the live bytes are already patched, "patch" when they are the
|
||||||
|
known original (safe to apply), or "skip" for anything else -- an unrecognised
|
||||||
|
CardsDLL build that must never be blindly overwritten.
|
||||||
|
"""
|
||||||
|
if cur == patch:
|
||||||
|
return "noop"
|
||||||
|
if cur == orig:
|
||||||
|
return "patch"
|
||||||
|
return "skip"
|
||||||
|
|
||||||
|
def guard_state_after(cur_before, orig, patch, wrote_ok, cur_after):
|
||||||
|
"""Map a guarded-patch enforcement outcome to a per-pid guard STATE (pure).
|
||||||
|
|
||||||
|
Mirrors guarded_action's decision, extended with post-write verification so the
|
||||||
|
caller advertises the capability only on VERIFIED. No /proc access -- unit-testable.
|
||||||
|
|
||||||
|
- cur_before == patch -> VERIFIED (already patched; guarded_action "noop")
|
||||||
|
- cur_before == orig -> WRITE_FAILED if the write raised, else VERIFIED when the
|
||||||
|
re-read is patch, else VERIFY_FAILED (guarded_action "patch")
|
||||||
|
- otherwise -> UNSUPPORTED_BUILD (guarded_action "skip")
|
||||||
|
"""
|
||||||
|
if cur_before == patch:
|
||||||
|
return GUARD_VERIFIED
|
||||||
|
if cur_before == orig:
|
||||||
|
if not wrote_ok:
|
||||||
|
return GUARD_WRITE_FAILED
|
||||||
|
if cur_after == patch:
|
||||||
|
return GUARD_VERIFIED
|
||||||
|
return GUARD_VERIFY_FAILED
|
||||||
|
return GUARD_UNSUPPORTED_BUILD
|
||||||
|
|
||||||
patched=set()
|
patched=set()
|
||||||
store_patched=set()
|
store_patched=set()
|
||||||
|
guard_reported=set()
|
||||||
|
|
||||||
launcher_pid = None
|
if __name__ == "__main__":
|
||||||
if "--launcher-pid" in sys.argv:
|
launcher_pid = None
|
||||||
|
if "--launcher-pid" in sys.argv:
|
||||||
try: launcher_pid = int(sys.argv[sys.argv.index("--launcher-pid") + 1])
|
try: launcher_pid = int(sys.argv[sys.argv.index("--launcher-pid") + 1])
|
||||||
except (ValueError, IndexError): raise SystemExit("invalid --launcher-pid")
|
except (ValueError, IndexError): raise SystemExit("invalid --launcher-pid")
|
||||||
|
|
||||||
log("=== AUTOPATCH watching for FIFA17.exe ===")
|
log("=== AUTOPATCH watching for FIFA17.exe ===")
|
||||||
while True:
|
while True:
|
||||||
if launcher_pid and not os.path.exists(f"/proc/{launcher_pid}"):
|
if launcher_pid and not os.path.exists(f"/proc/{launcher_pid}"):
|
||||||
log(f"launcher pid {launcher_pid} exited; stopping autopatch")
|
log(f"launcher pid {launcher_pid} exited; stopping autopatch")
|
||||||
break
|
break
|
||||||
@@ -90,6 +165,34 @@ while True:
|
|||||||
if rd(pid, live, len(data)) != data:
|
if rd(pid, live, len(data)) != data:
|
||||||
wr(pid, live, data)
|
wr(pid, live, data)
|
||||||
log(f"pid {pid}: ENFORCED store patch @ {live:#x}")
|
log(f"pid {pid}: ENFORCED store patch @ {live:#x}")
|
||||||
|
for va, (orig, patch) in STORE_PATCHES_GUARDED.items():
|
||||||
|
live = cbase + (va - IMG_BASE)
|
||||||
|
cur = rd(pid, live, len(patch))
|
||||||
|
action = guarded_action(cur, orig, patch)
|
||||||
|
wrote_ok = True
|
||||||
|
cur_after = cur
|
||||||
|
if action == "patch":
|
||||||
|
try:
|
||||||
|
wr(pid, live, patch)
|
||||||
|
log(f"pid {pid}: ENFORCED guarded store patch @ {live:#x} (JNZ->JG, empty My Packs)")
|
||||||
|
except Exception as e:
|
||||||
|
wrote_ok = False
|
||||||
|
log(f"pid {pid}: guarded patch write failed @ {live:#x}: {e}")
|
||||||
|
if wrote_ok:
|
||||||
|
try:
|
||||||
|
cur_after = rd(pid, live, len(patch))
|
||||||
|
except Exception:
|
||||||
|
cur_after = b""
|
||||||
|
elif action == "skip":
|
||||||
|
log(f"pid {pid}: SKIP guarded patch @ {live:#x}: unexpected {cur.hex()} (build mismatch)")
|
||||||
|
# action == "noop": already patched; nothing to write.
|
||||||
|
if va == RESOLVER_GUARD_VA and pid not in guard_reported:
|
||||||
|
state = guard_state_after(cur, orig, patch, wrote_ok, cur_after)
|
||||||
|
if state == GUARD_VERIFIED:
|
||||||
|
log(f"[store-guard] verified capability {EMPTY_MYPACKS_RESOLVER_CAPABILITY}={EMPTY_MYPACKS_RESOLVER_VERSION} fifa_pid={pid}")
|
||||||
|
else:
|
||||||
|
log(f"[store-guard] guard status={state} fifa_pid={pid} (no capability advertised)")
|
||||||
|
guard_reported.add(pid)
|
||||||
if pid not in store_patched:
|
if pid not in store_patched:
|
||||||
log(f"pid {pid}: PATCHED store gates in CardsDLL @ {cbase:#x}")
|
log(f"pid {pid}: PATCHED store gates in CardsDLL @ {cbase:#x}")
|
||||||
store_patched.add(pid)
|
store_patched.add(pid)
|
||||||
|
|||||||
@@ -147,14 +147,13 @@ def refresh_account_identity():
|
|||||||
|
|
||||||
# ================================================================== config
|
# ================================================================== config
|
||||||
#
|
#
|
||||||
# Client/server split support (OpenFUT dev-container): two env vars, both
|
# Client/server split support (OpenFUT dev-container): bind and advertise default
|
||||||
# defaulting to loopback so the original all-on-localhost flow is byte-identical.
|
# to loopback so the original all-on-localhost flow is byte-identical.
|
||||||
# OPENFUT_BIND — the address the listeners bind (0.0.0.0 in a container).
|
# OPENFUT_BIND — address the listeners bind (0.0.0.0 in a container).
|
||||||
# OPENFUT_ADVERTISE — the address this server hands back to the client for the
|
# OPENFUT_ADVERTISE — address handed back for Blaze, UTAS, telemetry, QoS,
|
||||||
# NEXT hop (Blaze host, roster/UTAS/telemetry/QoS URLs). On
|
# and (unless overridden) the roster service.
|
||||||
# 105-local this is 127.0.0.1; on the 120 server it is the
|
# OPENFUT_ROSTER_HOST — optional roster host:port advertised in HTTPS URLs.
|
||||||
# server's LAN IP so the game dials 120 directly after the
|
# Use a certificate dNSName and resolve it on the client.
|
||||||
# first (hook/DNAT-redirected) contact.
|
|
||||||
import os as _os_cfg
|
import os as _os_cfg
|
||||||
_ADVERTISE = _os_cfg.environ.get("OPENFUT_ADVERTISE", "127.0.0.1")
|
_ADVERTISE = _os_cfg.environ.get("OPENFUT_ADVERTISE", "127.0.0.1")
|
||||||
_BIND = _os_cfg.environ.get("OPENFUT_BIND", "127.0.0.1")
|
_BIND = _os_cfg.environ.get("OPENFUT_BIND", "127.0.0.1")
|
||||||
@@ -563,9 +562,11 @@ OSDK_TICKER = []
|
|||||||
# never gets advance/back -> the silent FUT loading-screen hang. The store is the
|
# never gets advance/back -> the silent FUT loading-screen hang. The store is the
|
||||||
# MERGED '_all' section (getSection @0x14719e050), so any fetched CFID works; this
|
# MERGED '_all' section (getSection @0x14719e050), so any fetched CFID works; this
|
||||||
# branch does NOT wrap the value ("https://%s" is only the ini path) -> ABSOLUTE url.
|
# branch does NOT wrap the value ("https://%s" is only the ini path) -> ABSOLUTE url.
|
||||||
# Serve HTTPS (EA's production value is https; the DirtySDK download mgr may reject
|
# Serve HTTPS (EA's production value is https; the DirtySDK download manager may
|
||||||
# http). Our ProtoSSL cert-verify is patched (autopatch), so a self-signed cert is OK.
|
# reject http). FIFA17's roster verifier accepts dNSName SANs but ignores
|
||||||
ROSTER_HOST = "%s:8081" % _ADVERTISE
|
# iPAddress SANs, so an IP-literal URL fails with certificate_unknown. A remote
|
||||||
|
# deployment can advertise a certificate DNS name without changing other hosts.
|
||||||
|
ROSTER_HOST = os.environ.get("OPENFUT_ROSTER_HOST") or "%s:8081" % _ADVERTISE
|
||||||
POW_CONTENT_HOST = os.environ.get("POW_CONTENT_HOST", "127.0.0.1:8080")
|
POW_CONTENT_HOST = os.environ.get("POW_CONTENT_HOST", "127.0.0.1:8080")
|
||||||
OSDK_ROSTER = [
|
OSDK_ROSTER = [
|
||||||
("ROSTERUPDATE_URL", "https://%s/fifa17/fut/rosterupdate.xml" % ROSTER_HOST),
|
("ROSTERUPDATE_URL", "https://%s/fifa17/fut/rosterupdate.xml" % ROSTER_HOST),
|
||||||
|
|||||||
Executable
+77
@@ -0,0 +1,77 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Recover the kit caption/localisation vocabulary from the UNPACKED CardsDLL.
|
||||||
|
|
||||||
|
Why CardsDLL and not FIFA17.exe: CardsDLL is not packed, so a MISS here is
|
||||||
|
meaningful. FIFA17.exe is Denuvo-packed and only partially readable -- a hit
|
||||||
|
there is useful, a miss proves nothing. Every run therefore prints a positive
|
||||||
|
control first; if the control fails, the run is void and no negative may be
|
||||||
|
quoted from it.
|
||||||
|
|
||||||
|
Usage: python3 cardsdll_kit_strings.py [path-to-CardsDLL]
|
||||||
|
"""
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import os
|
||||||
|
import re
|
||||||
|
import sys
|
||||||
|
|
||||||
|
DEFAULT = os.path.expanduser(
|
||||||
|
"~/.cache/openfut-investigation/bin/CardsDLL_Win64_retail.dll"
|
||||||
|
)
|
||||||
|
|
||||||
|
# Strings that MUST be present. If any is missing the search is broken.
|
||||||
|
CONTROLS = [b"activeHomeKit", b"cardsubtypeid", b"resourceId", b"activeAwayKit"]
|
||||||
|
|
||||||
|
# The kit caption vocabulary this project has referred to, plus neighbours worth
|
||||||
|
# knowing about either way.
|
||||||
|
PROBES = [
|
||||||
|
b"FUT_UC_KITS", b"TeamName_Abbr15_", b"TeamName_Abbr15", b"TeamName_",
|
||||||
|
b"FUT_UC_", b"StadiumName_", b"Badge", b"Stadium",
|
||||||
|
b"activeBadge", b"activeBall", b"activeStadium",
|
||||||
|
b"kit", b"Kit", b"KIT",
|
||||||
|
b"home", b"Home", b"HOME", b"away", b"Away", b"AWAY",
|
||||||
|
b"locked", b"Locked", b"LOCKED", b"unlock",
|
||||||
|
b"category", b"year", b"teamid", b"teamId",
|
||||||
|
b"DataProvider", b"itemData", b"itemType", b"itemState",
|
||||||
|
]
|
||||||
|
|
||||||
|
|
||||||
|
def ascii_strings(data, minlen=4):
|
||||||
|
for m in re.finditer(rb"[ -~]{%d,}" % minlen, data):
|
||||||
|
yield m.start(), m.group()
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
path = sys.argv[1] if len(sys.argv) > 1 else DEFAULT
|
||||||
|
data = open(path, "rb").read()
|
||||||
|
print(f"{os.path.basename(path)} {len(data)} bytes")
|
||||||
|
|
||||||
|
print("\n-- positive control (a miss voids every negative below) --")
|
||||||
|
ok = True
|
||||||
|
for c in CONTROLS:
|
||||||
|
n = data.count(c)
|
||||||
|
print(f" {c.decode():16s} {n}")
|
||||||
|
if n == 0:
|
||||||
|
ok = False
|
||||||
|
if not ok:
|
||||||
|
print(" CONTROL FAILED — do not quote negatives from this run.")
|
||||||
|
return 1
|
||||||
|
|
||||||
|
print("\n-- probe counts --")
|
||||||
|
for p in PROBES:
|
||||||
|
print(f" {p.decode():18s} {data.count(p)}")
|
||||||
|
|
||||||
|
# Whole-string table: every standalone string containing kit-ish substrings.
|
||||||
|
print("\n-- standalone strings matching kit/team/caption vocabulary --")
|
||||||
|
pat = re.compile(rb"(?i)(kit|teamname|abbr|stadiumname|fut_uc|locked|unlock)")
|
||||||
|
seen = set()
|
||||||
|
for off, s in ascii_strings(data, 5):
|
||||||
|
if pat.search(s) and s not in seen:
|
||||||
|
seen.add(s)
|
||||||
|
print(f" @{off:#08x} {s.decode('latin1')[:110]}")
|
||||||
|
print(f" ({len(seen)} distinct)")
|
||||||
|
return 0
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
sys.exit(main())
|
||||||
+202
@@ -0,0 +1,202 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
# -*- coding: utf-8 -*-
|
||||||
|
"""Prove, from the live client, which cardtypes CardsDLL can NAME -- and that
|
||||||
|
cardtype 9 (ball / league logo / fcc_misccards) is not one of them.
|
||||||
|
|
||||||
|
READ-ONLY: /proc/PID/mem opened 'rb'. No write path in this file.
|
||||||
|
|
||||||
|
WHY
|
||||||
|
---
|
||||||
|
Serving an owned ball or league logo was blocked on one question: where does a
|
||||||
|
cardtype-9 item's caption come from? Three independent reads here say: nowhere.
|
||||||
|
|
||||||
|
MEASURED 2026-08-21, pid 6580, CardsDLL live base 0x6ffffc0f0000
|
||||||
|
(module-relative offsets below are stable; live addresses are not).
|
||||||
|
|
||||||
|
1. THE CLUB-ITEM CAPTION RESOLVER IS A VTABLE SLOT, NOT AN EXPORT.
|
||||||
|
An earlier note recorded FUN_180119bd0 as "zero refs in CardsDLL -> almost
|
||||||
|
certainly an export, its caller is in FIFA17.exe". That is WRONG and this
|
||||||
|
tool corrects it. Its address occurs exactly ONCE in the entire process, at
|
||||||
|
image 0x18021c738, inside CardsDLL's own .rdata -- a vtable entry. Nothing in
|
||||||
|
FIFA17.exe references it.
|
||||||
|
|
||||||
|
Walking backwards over "qwords pointing into .text" overshoots the vtable
|
||||||
|
boundary (it runs 826 slots through several adjacent vtables). The reliable
|
||||||
|
discriminator is that a vtable's START is referenced by its constructor via a
|
||||||
|
RIP-relative LEA while interior slots never are:
|
||||||
|
|
||||||
|
vtable base image 0x18021c2a0 (ctor LEAs at 0x18010ce10, 0x18011111b)
|
||||||
|
FUN_180119bd0 slot +0x498, index 147
|
||||||
|
|
||||||
|
which independently reproduces the previously recorded "manager vtable slot
|
||||||
|
+0x498". There are 7 distinct `call [reg+0x498]` sites.
|
||||||
|
|
||||||
|
2. THE CAPTION CALL IS GATED ON cardtype == 7, AND THE ELSE IS TROPHIES.
|
||||||
|
At 0x1800f6f04:
|
||||||
|
|
||||||
|
cmp DWORD PTR [rax+0x4c], 0x7 ; cardtype
|
||||||
|
jne 0x1800f6f82
|
||||||
|
...
|
||||||
|
mov r9d, [rdx+0x94]
|
||||||
|
mov r8d, [rdx+0x50] ; cardsubtypeid
|
||||||
|
mov ecx, [rdx+0x20] ; assetid
|
||||||
|
call QWORD PTR [r10+0x498] ; FUN_180119bd0
|
||||||
|
|
||||||
|
The jne path formats [rdi+0x8] into 'AWARD_LABEL_%i' (0x1801fd5a0) and
|
||||||
|
localises it -- that is the TROPHY path (subtypes 0x91..0x96), not a fallback
|
||||||
|
that would name a ball.
|
||||||
|
|
||||||
|
3. NO CARDTYPE-9 HANDLING EXISTS, BY TWO INDEPENDENT MEASURES.
|
||||||
|
a) Census of every `cmp [reg+0x4c], imm8` in .text:
|
||||||
|
cardtype 0 : 2 sites
|
||||||
|
cardtype 1 : 14 sites
|
||||||
|
cardtype 6 : 1 site
|
||||||
|
cardtype 7 : 6 sites
|
||||||
|
cardtype 9 : 0 sites
|
||||||
|
b) The merge switch's jump table at rva 0x141eb4, indexed by cardtype-1,
|
||||||
|
10 entries:
|
||||||
|
idx 0..4 -> cardtypes 1..5 distinct DB-merge arms
|
||||||
|
idx 5..8 -> cardtypes 6..9 ALL to the shared tail 0x180141e8a
|
||||||
|
idx 9 -> cardtype 10 distinct arm (gkcoach)
|
||||||
|
The shared tail does no DB query and writes no name: it only derives the
|
||||||
|
discard level from the rating.
|
||||||
|
|
||||||
|
A cmp census alone would miss a jump-table switch, and a jump table alone
|
||||||
|
would miss an explicit compare. Both say the same thing.
|
||||||
|
|
||||||
|
CONSEQUENCE
|
||||||
|
-----------
|
||||||
|
A cardtype-9 item cannot receive a client-resolved caption: it has no merge arm
|
||||||
|
to fill a name and it can never reach the cardtype-7 resolver. Withholding ball
|
||||||
|
and league logo from the projection is therefore an evidence-backed limit of the
|
||||||
|
client, not caution -- and no server-side change can lift it.
|
||||||
|
|
||||||
|
BONUS, and it validates the discard work: the shared tail at 0x180141e8a IS the
|
||||||
|
discard level ladder, live --
|
||||||
|
movzx eax,[rdi+0xb4] ; cmp al,0x4b ; -> 3
|
||||||
|
cmp al,0x41 ; sbb eax,eax ; add eax,2 ; -> 2 or 1
|
||||||
|
mov [rdi+0x54], eax
|
||||||
|
which is `discard::discard_level` instruction for instruction.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
python3 cardtype_dispatch_probe.py
|
||||||
|
"""
|
||||||
|
import collections
|
||||||
|
import struct
|
||||||
|
import sys
|
||||||
|
|
||||||
|
import watch_club_model as W
|
||||||
|
|
||||||
|
TEXT_LO, TEXT_HI = 0x180001000, 0x1801E5000
|
||||||
|
RDATA_LO, RDATA_HI = 0x1801E5000, 0x18028A000
|
||||||
|
CAPTION_FN = 0x180119BD0
|
||||||
|
JUMP_TABLE = 0x180141EB4
|
||||||
|
SHARED_TAIL = 0x180141E8A
|
||||||
|
REGS = {0x78: "rax", 0x79: "rcx", 0x7A: "rdx", 0x7B: "rbx",
|
||||||
|
0x7D: "rbp", 0x7E: "rsi", 0x7F: "rdi"}
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
pid = W.find_pid()
|
||||||
|
if pid is None:
|
||||||
|
print("FIFA17.exe is not running.")
|
||||||
|
return 1
|
||||||
|
dll = W.dll_base(pid)
|
||||||
|
if dll is None:
|
||||||
|
print("pid %d is up but %s is not mapped yet." % (pid, W.DLL))
|
||||||
|
return 1
|
||||||
|
mem = W.Mem(pid)
|
||||||
|
live = lambda i: dll + (i - W.IMG_BASE)
|
||||||
|
print("pid=%d CardsDLL live base %#x" % (pid, dll))
|
||||||
|
|
||||||
|
text, bad = mem.read_pages(live(TEXT_LO), TEXT_HI - TEXT_LO)
|
||||||
|
text = bytes(text)
|
||||||
|
print("read %#x bytes .text (%d bad pages)" % (len(text), len(bad)))
|
||||||
|
|
||||||
|
# --- 1. locate the caption fn's single reference, and its vtable base ----
|
||||||
|
target = live(CAPTION_FN)
|
||||||
|
rdata, _ = mem.read_pages(live(RDATA_LO), RDATA_HI - RDATA_LO)
|
||||||
|
rdata = bytes(rdata)
|
||||||
|
slots = []
|
||||||
|
needle = struct.pack("<Q", target)
|
||||||
|
i = rdata.find(needle)
|
||||||
|
while i != -1:
|
||||||
|
slots.append(RDATA_LO + i)
|
||||||
|
i = rdata.find(needle, i + 1)
|
||||||
|
print("\n[1] FUN_%x referenced from .rdata at: %s"
|
||||||
|
% (CAPTION_FN, [hex(s) for s in slots]) or "nowhere")
|
||||||
|
|
||||||
|
lea_t = set()
|
||||||
|
for i in range(len(text) - 7):
|
||||||
|
if text[i] in (0x48, 0x4C) and text[i + 1] == 0x8D and text[i + 2] in (
|
||||||
|
0x05, 0x0D, 0x15, 0x1D, 0x25, 0x2D, 0x35, 0x3D):
|
||||||
|
tgt = TEXT_LO + i + 7 + struct.unpack_from("<i", text, i + 3)[0]
|
||||||
|
if RDATA_LO <= tgt < RDATA_HI:
|
||||||
|
lea_t.add(tgt)
|
||||||
|
for slot in slots:
|
||||||
|
base = max((t for t in lea_t if t <= slot), default=None)
|
||||||
|
if base is not None:
|
||||||
|
print(" vtable base %#x -> slot +%#x (index %d)"
|
||||||
|
% (base, slot - base, (slot - base) // 8))
|
||||||
|
|
||||||
|
# --- 2. cardtype compare census -----------------------------------------
|
||||||
|
hits = collections.defaultdict(list)
|
||||||
|
for i in range(len(text) - 4):
|
||||||
|
if text[i] == 0x83 and text[i + 1] in REGS and text[i + 2] == 0x4C:
|
||||||
|
hits[text[i + 3]].append(TEXT_LO + i)
|
||||||
|
print("\n[2] cardtype tests `cmp [reg+0x4c], imm`:")
|
||||||
|
for ct in sorted(hits):
|
||||||
|
print(" cardtype %2d : %3d site(s) e.g. %s"
|
||||||
|
% (ct, len(hits[ct]), ", ".join("%#x" % v for v in hits[ct][:4])))
|
||||||
|
ok_control = 7 in hits and 1 in hits
|
||||||
|
print(" CONTROL (cardtypes 1 and 7 must both appear): %s"
|
||||||
|
% ("OK" if ok_control else "WRONG REGION -- results are meaningless"))
|
||||||
|
print(" cardtype 9 sites: %d" % len(hits.get(9, [])))
|
||||||
|
|
||||||
|
# --- 3. merge jump table -------------------------------------------------
|
||||||
|
jt, _ = mem.read_pages(live(JUMP_TABLE), 0x40)
|
||||||
|
jt = bytes(jt)
|
||||||
|
print("\n[3] merge jump table at %#x (index = cardtype - 1):" % JUMP_TABLE)
|
||||||
|
tail_types = []
|
||||||
|
for n in range(16):
|
||||||
|
rva = struct.unpack_from("<I", jt, n * 4)[0]
|
||||||
|
if not (0x1000 <= rva < 0x1E5000):
|
||||||
|
break
|
||||||
|
va = W.IMG_BASE + rva
|
||||||
|
ct = n + 1
|
||||||
|
mark = " <- SHARED TAIL (no DB query, no name)" if va == SHARED_TAIL else ""
|
||||||
|
print(" cardtype %2d -> %#x%s" % (ct, va, mark))
|
||||||
|
if va == SHARED_TAIL:
|
||||||
|
tail_types.append(ct)
|
||||||
|
|
||||||
|
# --- 4. cardsubtypeid census -------------------------------------------
|
||||||
|
# The club-item CAPTION is chosen by subtype (+0x50), not cardtype, so the
|
||||||
|
# cardtype census alone does not settle whether a ball or logo is nameable.
|
||||||
|
sub = collections.defaultdict(list)
|
||||||
|
for i in range(len(text) - 8):
|
||||||
|
if text[i] == 0x83 and text[i + 1] in REGS and text[i + 2] == 0x50:
|
||||||
|
sub[text[i + 3]].append(TEXT_LO + i)
|
||||||
|
elif text[i] == 0x81 and text[i + 1] in REGS and text[i + 2] == 0x50:
|
||||||
|
sub[struct.unpack_from("<I", text, i + 3)[0]].append(TEXT_LO + i)
|
||||||
|
print("\n[4] cardsubtypeid tests `cmp [reg+0x50], imm`:")
|
||||||
|
for st in sorted(k for k in sub if k <= 400):
|
||||||
|
print(" subtype %3d : %2d site(s) e.g. %s"
|
||||||
|
% (st, len(sub[st]), ", ".join("%#x" % v for v in sub[st][:4])))
|
||||||
|
print(" CONTROL (kit 9 / stadium 10 / badge 11 must appear): %s"
|
||||||
|
% ("OK" if all(s in sub for s in (9, 10, 11)) else "WRONG REGION"))
|
||||||
|
print(" ball(30)=%d leaguelogo(31)=%d misc(231/232/233/236)=%d"
|
||||||
|
% (len(sub.get(30, [])), len(sub.get(31, [])),
|
||||||
|
sum(len(sub.get(s, [])) for s in (231, 232, 233, 236))))
|
||||||
|
print(" NOTE: the misc sites are all one boolean predicate near"
|
||||||
|
" 0x1801a72da that returns FALSE for them -- an exclusion, not a"
|
||||||
|
" caption. Its identity is NOT established.")
|
||||||
|
|
||||||
|
print("\nVERDICT: cardtypes with no merge arm: %s" % tail_types)
|
||||||
|
print(" cardtype 9 named by CardsDLL: %s"
|
||||||
|
% ("NO -- no merge arm and no compare site" if 9 in tail_types
|
||||||
|
and not hits.get(9) else "reconsider"))
|
||||||
|
return 0
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
sys.exit(main())
|
||||||
+111
@@ -0,0 +1,111 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Read-only probe v3: discriminate "kits never ingested" from "ingested then freed".
|
||||||
|
|
||||||
|
Staff was refetched by the client at 18:40:38, four minutes before the scan, and
|
||||||
|
players are resident. If staff/badge/stadium records are resident but the two
|
||||||
|
kits are not, the kits are being dropped specifically.
|
||||||
|
"""
|
||||||
|
import re
|
||||||
|
import struct
|
||||||
|
import subprocess
|
||||||
|
import sys
|
||||||
|
|
||||||
|
NEEDLES = {
|
||||||
|
"PLAYER resourceId 83906881 (control, resident)": 83906881,
|
||||||
|
"STAFF resourceId 9000081 (headcoach-ish)": 9000081,
|
||||||
|
"STAFF resourceId 3000083 (x2)": 3000083,
|
||||||
|
"STAFF resourceId 1000509": 1000509,
|
||||||
|
"STAFF instance 100004870": 100004870,
|
||||||
|
"BADGE resourceId 6000005": 6000005,
|
||||||
|
"BADGE instance 100004875": 100004875,
|
||||||
|
"STADIUM resourceId 6200000": 6200000,
|
||||||
|
"STADIUM instance 100004876": 100004876,
|
||||||
|
"KIT resourceId 6300006 (home)": 6300006,
|
||||||
|
"KIT resourceId 6400003 (away)": 6400003,
|
||||||
|
"KIT instance 100004874 (home)": 100004874,
|
||||||
|
"KIT instance 100004873 (away)": 100004873,
|
||||||
|
"KIT cardassetid 35": 35,
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
def find_pid():
|
||||||
|
out = subprocess.run(["pgrep", "-f", "FIFA17.exe"], capture_output=True, text=True).stdout.split()
|
||||||
|
for p in out:
|
||||||
|
try:
|
||||||
|
with open(f"/proc/{p}/maps") as fh:
|
||||||
|
if "CardsDLL" in fh.read():
|
||||||
|
return int(p)
|
||||||
|
except OSError:
|
||||||
|
continue
|
||||||
|
return int(out[0]) if out else None
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
pid = find_pid()
|
||||||
|
if not pid:
|
||||||
|
sys.exit("FIFA17.exe not running")
|
||||||
|
print(f"pid={pid}")
|
||||||
|
|
||||||
|
regs = []
|
||||||
|
with open(f"/proc/{pid}/maps") as fh:
|
||||||
|
for line in fh:
|
||||||
|
m = re.match(r"([0-9a-f]+)-([0-9a-f]+) (\S{4}) \S+ \S+ \S+\s*(.*)", line)
|
||||||
|
if not m:
|
||||||
|
continue
|
||||||
|
lo, hi, perms, path = int(m.group(1), 16), int(m.group(2), 16), m.group(3), m.group(4)
|
||||||
|
if "r" in perms and not path.startswith("/dev/") and (hi - lo) <= (512 << 20):
|
||||||
|
regs.append((lo, hi))
|
||||||
|
|
||||||
|
hits = {k: [] for k in NEEDLES}
|
||||||
|
pats = {k: struct.pack("<I", v) for k, v in NEEDLES.items()}
|
||||||
|
mib = 0
|
||||||
|
|
||||||
|
with open(f"/proc/{pid}/mem", "rb", buffering=0) as mem:
|
||||||
|
for lo, hi in regs:
|
||||||
|
try:
|
||||||
|
mem.seek(lo)
|
||||||
|
buf = mem.read(hi - lo)
|
||||||
|
except (OSError, ValueError, OverflowError):
|
||||||
|
continue
|
||||||
|
if not buf:
|
||||||
|
continue
|
||||||
|
mib += len(buf)
|
||||||
|
for k, needle in pats.items():
|
||||||
|
start = 0
|
||||||
|
while len(hits[k]) < 5000:
|
||||||
|
i = buf.find(needle, start)
|
||||||
|
if i < 0:
|
||||||
|
break
|
||||||
|
hits[k].append(lo + i)
|
||||||
|
start = i + 4
|
||||||
|
|
||||||
|
print(f"read {mib/(1<<20):.0f} MiB\n" + "=" * 66)
|
||||||
|
|
||||||
|
def rd(base, off, size=4):
|
||||||
|
try:
|
||||||
|
mem.seek(base + off)
|
||||||
|
raw = mem.read(size)
|
||||||
|
return int.from_bytes(raw, "little") if len(raw) == size else None
|
||||||
|
except (OSError, ValueError, OverflowError):
|
||||||
|
return None
|
||||||
|
|
||||||
|
for k in NEEDLES:
|
||||||
|
addrs = hits[k]
|
||||||
|
# count how many look like real item records (plausible cardtype)
|
||||||
|
recs = []
|
||||||
|
for a in addrs[:3000]:
|
||||||
|
base = a - 0x18
|
||||||
|
ct = rd(base, 0x4C)
|
||||||
|
if ct in (1, 2, 3, 4, 5, 6, 7, 9):
|
||||||
|
recs.append((base, ct))
|
||||||
|
flag = "" if addrs else " <-- ZERO"
|
||||||
|
print(f" {len(addrs):6d} raw / {len(recs):4d} record-shaped {k}{flag}")
|
||||||
|
for base, ct in recs[:3]:
|
||||||
|
print(f" @{base:#x} cardtype={ct} subtype={rd(base,0x50)} "
|
||||||
|
f"itemState={rd(base,0x5c)} +0x60={rd(base,0x60)} "
|
||||||
|
f"teamid={rd(base,0x94)} cat={rd(base,0xb8)} year={rd(base,0xba,2)}")
|
||||||
|
print("=" * 66)
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
main()
|
||||||
Executable
+190
@@ -0,0 +1,190 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
# -*- coding: utf-8 -*-
|
||||||
|
"""Read back the DISCARD (quick-sell) value the live client holds for every
|
||||||
|
resident card, and check it against the client's own `fcc_discardcoins` table.
|
||||||
|
|
||||||
|
READ-ONLY. Walks the same CardsDb node tree as card_identity_probe / coach_probe
|
||||||
|
via /proc/PID/mem; there is no write path in this file.
|
||||||
|
|
||||||
|
WHAT THE TWO SLOTS MEAN (FUN_18013fe00 / FUN_180141660)
|
||||||
|
-------------------------------------------------------
|
||||||
|
item+0x38 the `discardValue` WE sent (atom 0xd7), stored verbatim.
|
||||||
|
item+0x3c the value the CLIENT computed for itself.
|
||||||
|
|
||||||
|
At 0x180141025 a `cmp dword [rbp+0x198],0` / `ja` SKIPS the whole local
|
||||||
|
computation when +0x38 is non-zero. So:
|
||||||
|
|
||||||
|
* +0x38 non-zero -> the client displays OUR number and +0x3c is not filled.
|
||||||
|
* +0x38 zero -> the client computes, and +0x3c is what the player sees.
|
||||||
|
|
||||||
|
The local computation is
|
||||||
|
SELECT price FROM fcc_discardcoins WHERE cardtype==? AND level==? AND rare==?
|
||||||
|
value = round_half_up(rating * price / 100)
|
||||||
|
with `level` = 3 if rating >= 0x4b, 2 if >= 0x41, else 1 (item+0x54), and
|
||||||
|
cardtype derived from cardsubtypeid by FUN_1800d8330.
|
||||||
|
|
||||||
|
WHY THIS TOOL EXISTS
|
||||||
|
--------------------
|
||||||
|
For cardtypes 2/3/4/5/10 (the five staff families) the client OVERWRITES the
|
||||||
|
rating and rare flag we send with values from its own card database before
|
||||||
|
computing. The server therefore cannot know the displayed price from what it
|
||||||
|
sent -- it has to be read back. +0x3c is that read-back, and it is the ground
|
||||||
|
truth for what the server must credit on a quick sell.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
python3 discard_probe.py # table of every resident card
|
||||||
|
python3 discard_probe.py --kind staff # only the staff families
|
||||||
|
python3 discard_probe.py --json out.json
|
||||||
|
"""
|
||||||
|
import argparse
|
||||||
|
import json
|
||||||
|
import os
|
||||||
|
import sys
|
||||||
|
|
||||||
|
import card_identity_probe as P
|
||||||
|
import watch_club_model as W
|
||||||
|
|
||||||
|
TABLES = os.path.join(os.path.dirname(os.path.abspath(__file__)), "..", "data", "tables")
|
||||||
|
|
||||||
|
F_SERVER_DISCARD = 0x38
|
||||||
|
F_CLIENT_DISCARD = 0x3C
|
||||||
|
F_LEVEL = 0x54
|
||||||
|
F_RARE = 0x58
|
||||||
|
F_RATING = 0xB4
|
||||||
|
|
||||||
|
|
||||||
|
def cardtype_for_subtype(sub):
|
||||||
|
"""FUN_1800d8330, read out of its raw two-level jump table."""
|
||||||
|
if 0 <= sub <= 3:
|
||||||
|
return 1
|
||||||
|
if sub == 4:
|
||||||
|
return 2
|
||||||
|
if sub == 5:
|
||||||
|
return 3
|
||||||
|
if sub == 6:
|
||||||
|
return 10
|
||||||
|
if sub == 7:
|
||||||
|
return 5
|
||||||
|
if sub == 8:
|
||||||
|
return 4
|
||||||
|
if 9 <= sub <= 11:
|
||||||
|
return 7
|
||||||
|
if sub in (30, 31, 236) or 145 <= sub <= 150 or 231 <= sub <= 233:
|
||||||
|
return 9
|
||||||
|
if 51 <= sub <= 136 or 201 <= sub <= 220 or 250 <= sub <= 273 or 300 <= sub <= 341:
|
||||||
|
return 6
|
||||||
|
return 0
|
||||||
|
|
||||||
|
|
||||||
|
def load_prices():
|
||||||
|
"""{(cardtype, level, rare): price} from the client's own dumped table."""
|
||||||
|
path = os.path.join(TABLES, "fcc_discardcoins.json")
|
||||||
|
if not os.path.isfile(path):
|
||||||
|
return None
|
||||||
|
doc = json.load(open(path))
|
||||||
|
rows = doc["rows"] if isinstance(doc, dict) else doc
|
||||||
|
return {(r["cardtype"], r["level"], r["rare"]): r["price"] for r in rows}
|
||||||
|
|
||||||
|
|
||||||
|
def predict(prices, cardtype, rating, rare):
|
||||||
|
"""The client's formula, reproduced. An absent key pays 0, never a floor."""
|
||||||
|
if prices is None or cardtype == 0 or rating is None:
|
||||||
|
return None
|
||||||
|
level = 3 if rating >= 0x4B else (2 if rating >= 0x41 else 1)
|
||||||
|
price = prices.get((cardtype, level, rare), 0)
|
||||||
|
if price == 0:
|
||||||
|
return 0
|
||||||
|
return (rating * price + 50) // 100
|
||||||
|
|
||||||
|
|
||||||
|
STAFF_SUBTYPES = (4, 5, 6, 7, 8)
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
ap = argparse.ArgumentParser()
|
||||||
|
ap.add_argument("--kind", choices=("all", "staff", "player", "other"), default="all")
|
||||||
|
ap.add_argument("--json", metavar="PATH")
|
||||||
|
a = ap.parse_args()
|
||||||
|
|
||||||
|
prices = load_prices()
|
||||||
|
if prices is None:
|
||||||
|
print("WARNING: no fcc_discardcoins.json under %s -- predictions disabled\n" % TABLES)
|
||||||
|
|
||||||
|
pid = W.find_pid()
|
||||||
|
if pid is None:
|
||||||
|
print("FIFA17.exe is not running.")
|
||||||
|
return 1
|
||||||
|
base = W.dll_base(pid)
|
||||||
|
if base is None:
|
||||||
|
print("pid %d is up but %s is not mapped yet." % (pid, W.DLL))
|
||||||
|
return 1
|
||||||
|
mem = W.Mem(pid)
|
||||||
|
obj = mem.q(base + (W.G_CARDSDB - W.IMG_BASE))
|
||||||
|
if not obj:
|
||||||
|
print("CardsDb singleton is NULL (no FUT session loaded).")
|
||||||
|
return 1
|
||||||
|
|
||||||
|
ns = P.nodes(mem, obj)
|
||||||
|
print("pid=%d CardsDb=%#x walked=%d\n" % (pid, obj, len(ns)))
|
||||||
|
|
||||||
|
out = []
|
||||||
|
for n in ns:
|
||||||
|
buf = mem.read(n + P.REC, P.REC_LEN)
|
||||||
|
if buf is None or len(buf) < P.REC_LEN:
|
||||||
|
continue
|
||||||
|
sub = P.u32(buf, P.F_SUBTYPE)
|
||||||
|
ct = P.u32(buf, P.F_CARDTYPE)
|
||||||
|
rating = P.u8(buf, F_RATING)
|
||||||
|
rare = P.u32(buf, F_RARE)
|
||||||
|
rec = {
|
||||||
|
"resourceId": P.u32(buf, P.F_RESOURCE),
|
||||||
|
"subtype": sub,
|
||||||
|
"cardtype": ct,
|
||||||
|
"decoded_cardtype": cardtype_for_subtype(sub),
|
||||||
|
"rating": rating,
|
||||||
|
"level": P.u32(buf, F_LEVEL),
|
||||||
|
"rare": rare,
|
||||||
|
"server_discard": P.u32(buf, F_SERVER_DISCARD),
|
||||||
|
"client_discard": P.u32(buf, F_CLIENT_DISCARD),
|
||||||
|
"predicted": predict(prices, ct, rating, rare),
|
||||||
|
}
|
||||||
|
if a.kind == "staff" and sub not in STAFF_SUBTYPES:
|
||||||
|
continue
|
||||||
|
if a.kind == "player" and ct != 1:
|
||||||
|
continue
|
||||||
|
if a.kind == "other" and (ct == 1 or sub in STAFF_SUBTYPES):
|
||||||
|
continue
|
||||||
|
out.append(rec)
|
||||||
|
|
||||||
|
out.sort(key=lambda r: (r["cardtype"], r["subtype"], r["resourceId"]))
|
||||||
|
print("%-10s %-4s %-4s %-4s %-4s %-4s %-9s %-9s %-9s %s"
|
||||||
|
% ("resource", "sub", "ct", "rat", "lvl", "rar", "sent+38", "calc+3c",
|
||||||
|
"predict", "verdict"))
|
||||||
|
agree = disagree = notcomputed = 0
|
||||||
|
for r in out:
|
||||||
|
if r["server_discard"]:
|
||||||
|
verdict = "SERVER-SHOWN (local calc skipped)"
|
||||||
|
notcomputed += 1
|
||||||
|
elif r["predicted"] is None:
|
||||||
|
verdict = "?"
|
||||||
|
elif r["client_discard"] == r["predicted"]:
|
||||||
|
verdict = "AGREES"
|
||||||
|
agree += 1
|
||||||
|
else:
|
||||||
|
verdict = "DISAGREES"
|
||||||
|
disagree += 1
|
||||||
|
print("%-10s %-4s %-4s %-4s %-4s %-4s %-9s %-9s %-9s %s"
|
||||||
|
% (r["resourceId"], r["subtype"], r["cardtype"], r["rating"],
|
||||||
|
r["level"], r["rare"], r["server_discard"], r["client_discard"],
|
||||||
|
r["predicted"], verdict))
|
||||||
|
|
||||||
|
print("\nAGREES=%d DISAGREES=%d server-shown=%d total=%d"
|
||||||
|
% (agree, disagree, notcomputed, len(out)))
|
||||||
|
if a.json:
|
||||||
|
json.dump(out, open(a.json, "w"), indent=2)
|
||||||
|
print("wrote %s" % a.json)
|
||||||
|
return 0
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
sys.exit(main())
|
||||||
@@ -55,6 +55,34 @@ verify_exports() {
|
|||||||
done
|
done
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# Refuse any DLL that is not a FIFA-17-profile build.
|
||||||
|
#
|
||||||
|
# openfut-hook builds TWO mutually exclusive injection paths from one crate: the
|
||||||
|
# default (FIFA 23) path installs getaddrinfo/connect/ProtoSSL/origin hooks, while
|
||||||
|
# `--features fifa17` installs ONLY the FIFA-17-safe logic (module map, FIFA 17
|
||||||
|
# cert-verify, SBC dispatch, store tab bind). Deploying a default-feature build
|
||||||
|
# into FIFA 17 hijacks the login transport and the client reports "Unable to
|
||||||
|
# connect to the EA servers", with none of the FIFA 17 repairs present.
|
||||||
|
#
|
||||||
|
# That exact mistake happened on 2026-08-19 (artifact 1c71a17a, hand-built without
|
||||||
|
# the feature): two failed launches, diagnosed only by comparing embedded strings.
|
||||||
|
# `build` below passes the feature, but a hand-built DLL can reach `stage`/`deploy`
|
||||||
|
# via OPENFUT_FIFA17_HOOK_DLL, so assert the profile on the bytes themselves.
|
||||||
|
verify_fifa17_profile() {
|
||||||
|
local dll=$1 marker
|
||||||
|
# Markers that MUST be present: the FIFA 17 target module and its repairs.
|
||||||
|
for marker in 'CardsDLL_Win64_retail.dll' 'SBC_DISPATCH'; do
|
||||||
|
grep -qaF -- "$marker" "$dll" ||
|
||||||
|
die "$dll is not a --features fifa17 build (missing $marker); refusing to stage/deploy"
|
||||||
|
done
|
||||||
|
# Markers that MUST be absent: the FIFA-23-only transport hooking.
|
||||||
|
for marker in 'getaddrinfo IAT patched' 'connect: inline-hooked' 'origin_spy'; do
|
||||||
|
if grep -qaF -- "$marker" "$dll"; then
|
||||||
|
die "$dll contains FIFA-23-only hook '$marker'; build with --features fifa17"
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
}
|
||||||
|
|
||||||
verify_inputs() {
|
verify_inputs() {
|
||||||
command -v sha256sum >/dev/null || die "sha256sum is required"
|
command -v sha256sum >/dev/null || die "sha256sum is required"
|
||||||
command -v x86_64-w64-mingw32-objdump >/dev/null ||
|
command -v x86_64-w64-mingw32-objdump >/dev/null ||
|
||||||
@@ -62,6 +90,7 @@ verify_inputs() {
|
|||||||
need_file "$hook_dll"
|
need_file "$hook_dll"
|
||||||
need_file "$system_version"
|
need_file "$system_version"
|
||||||
verify_pe64 "$hook_dll"
|
verify_pe64 "$hook_dll"
|
||||||
|
verify_fifa17_profile "$hook_dll"
|
||||||
}
|
}
|
||||||
|
|
||||||
inspect() {
|
inspect() {
|
||||||
@@ -129,6 +158,7 @@ deploy() {
|
|||||||
need_file "$manifest"
|
need_file "$manifest"
|
||||||
verify_pe64 "$staged"
|
verify_pe64 "$staged"
|
||||||
verify_exports "$staged"
|
verify_exports "$staged"
|
||||||
|
verify_fifa17_profile "$staged"
|
||||||
local recorded actual
|
local recorded actual
|
||||||
recorded="$(awk -F= '$1=="artifact_sha256"{print $2}' "$manifest")"
|
recorded="$(awk -F= '$1=="artifact_sha256"{print $2}' "$manifest")"
|
||||||
actual="$(sha256 "$staged")"
|
actual="$(sha256 "$staged")"
|
||||||
@@ -158,7 +188,7 @@ launch() {
|
|||||||
local trace_enabled=0
|
local trace_enabled=0
|
||||||
local request_trace_enabled=0
|
local request_trace_enabled=0
|
||||||
local notifier_trace_enabled=0
|
local notifier_trace_enabled=0
|
||||||
local commit_enabled=0
|
local dispatch_enabled=0
|
||||||
case "$mode" in
|
case "$mode" in
|
||||||
baseline)
|
baseline)
|
||||||
[[ "${OPENFUT_FIFA17_LAUNCH:-}" == "I_ACCEPT_M1_BASELINE_LAUNCH" ]] ||
|
[[ "${OPENFUT_FIFA17_LAUNCH:-}" == "I_ACCEPT_M1_BASELINE_LAUNCH" ]] ||
|
||||||
@@ -177,14 +207,11 @@ launch() {
|
|||||||
request_trace_enabled=1
|
request_trace_enabled=1
|
||||||
notifier_trace_enabled=1
|
notifier_trace_enabled=1
|
||||||
;;
|
;;
|
||||||
commit)
|
dispatch)
|
||||||
[[ "${OPENFUT_FIFA17_COMMIT:-}" == "I_ACCEPT_POST_PARSE_READY_BYTE" ]] ||
|
[[ "${OPENFUT_FIFA17_DISPATCH:-}" == "I_ACCEPT_GUARDED_NATIVE_DISPATCH" ]] ||
|
||||||
die "launch-commit requires OPENFUT_FIFA17_COMMIT=I_ACCEPT_POST_PARSE_READY_BYTE"
|
die "launch-dispatch requires OPENFUT_FIFA17_DISPATCH=I_ACCEPT_GUARDED_NATIVE_DISPATCH"
|
||||||
hook_enabled=1
|
|
||||||
trace_enabled=1
|
|
||||||
request_trace_enabled=1
|
request_trace_enabled=1
|
||||||
notifier_trace_enabled=1
|
dispatch_enabled=1
|
||||||
commit_enabled=1
|
|
||||||
;;
|
;;
|
||||||
*) die "unknown launch mode: $mode" ;;
|
*) die "unknown launch mode: $mode" ;;
|
||||||
esac
|
esac
|
||||||
@@ -207,7 +234,7 @@ launch() {
|
|||||||
done
|
done
|
||||||
mkdir -p "${wine_prefix}/dosdevices"
|
mkdir -p "${wine_prefix}/dosdevices"
|
||||||
ln -sfn /mnt "${wine_prefix}/dosdevices/w:"
|
ln -sfn /mnt "${wine_prefix}/dosdevices/w:"
|
||||||
note "Launching $mode mode (SBC_HOOK=$hook_enabled; SBC_TRACE=$trace_enabled; SBC_REQUEST_TRACE=$request_trace_enabled; SBC_NOTIFIER_TRACE=$notifier_trace_enabled; SBC_COMMIT=$commit_enabled); log=/tmp/fifa17-hook-m1-launch.log"
|
note "Launching $mode mode (SBC_HOOK=$hook_enabled; SBC_TRACE=$trace_enabled; SBC_REQUEST_TRACE=$request_trace_enabled; SBC_NOTIFIER_TRACE=$notifier_trace_enabled; SBC_DISPATCH=$dispatch_enabled); log=/tmp/fifa17-hook-m1-launch.log"
|
||||||
cd "$game_dir"
|
cd "$game_dir"
|
||||||
env \
|
env \
|
||||||
GAMEID=fifa17 \
|
GAMEID=fifa17 \
|
||||||
@@ -218,8 +245,8 @@ launch() {
|
|||||||
OPENFUT_SBC_TRACE="$trace_enabled" \
|
OPENFUT_SBC_TRACE="$trace_enabled" \
|
||||||
OPENFUT_SBC_REQUEST_TRACE="$request_trace_enabled" \
|
OPENFUT_SBC_REQUEST_TRACE="$request_trace_enabled" \
|
||||||
OPENFUT_SBC_NOTIFIER_TRACE="$notifier_trace_enabled" \
|
OPENFUT_SBC_NOTIFIER_TRACE="$notifier_trace_enabled" \
|
||||||
OPENFUT_SBC_DISPATCH=0 \
|
OPENFUT_SBC_DISPATCH="$dispatch_enabled" \
|
||||||
OPENFUT_SBC_COMMIT="$commit_enabled" \
|
OPENFUT_SBC_DISPATCH_TRACE=0 \
|
||||||
OPENFUT_SBC_ARM_ONLY=0 \
|
OPENFUT_SBC_ARM_ONLY=0 \
|
||||||
OPENFUT_SBC_POPULATE=0 \
|
OPENFUT_SBC_POPULATE=0 \
|
||||||
umu-run _fifa17.exe 2>&1 | tee /tmp/fifa17-hook-m1-launch.log
|
umu-run _fifa17.exe 2>&1 | tee /tmp/fifa17-hook-m1-launch.log
|
||||||
@@ -227,7 +254,7 @@ launch() {
|
|||||||
|
|
||||||
usage() {
|
usage() {
|
||||||
cat <<'EOF'
|
cat <<'EOF'
|
||||||
Usage: fifa17-hook-m1.sh [inspect|build|stage|deploy|launch|launch-resolve|launch-trace|launch-commit]
|
Usage: fifa17-hook-m1.sh [inspect|build|stage|deploy|launch|launch-resolve|launch-trace|launch-dispatch]
|
||||||
|
|
||||||
inspect Read-only PE/hash/export preflight (default).
|
inspect Read-only PE/hash/export preflight (default).
|
||||||
build Cross-build the inert FIFA17 hook, then run inspect.
|
build Cross-build the inert FIFA17 hook, then run inspect.
|
||||||
@@ -240,11 +267,11 @@ Usage: fifa17-hook-m1.sh [inspect|build|stage|deploy|launch|launch-resolve|launc
|
|||||||
Start M2 resolve-only mode (guarded reads/logging, no detours/writes); requires:
|
Start M2 resolve-only mode (guarded reads/logging, no detours/writes); requires:
|
||||||
OPENFUT_FIFA17_RESOLVE=I_ACCEPT_M2_RESOLVE_LAUNCH
|
OPENFUT_FIFA17_RESOLVE=I_ACCEPT_M2_RESOLVE_LAUNCH
|
||||||
launch-trace
|
launch-trace
|
||||||
Start the single M3 passive factory/deserializer trace; requires:
|
Start the M3-M6 passive parser/request/notifier trace; requires:
|
||||||
OPENFUT_FIFA17_TRACE=I_ACCEPT_M3_PASSIVE_TRACE
|
OPENFUT_FIFA17_TRACE=I_ACCEPT_M3_PASSIVE_TRACE
|
||||||
launch-commit
|
launch-dispatch
|
||||||
Trace and arm the SBC cache only after a validated native parse; requires:
|
Trace and repair only a fully validated native status-999 completion; requires:
|
||||||
OPENFUT_FIFA17_COMMIT=I_ACCEPT_POST_PARSE_READY_BYTE
|
OPENFUT_FIFA17_DISPATCH=I_ACCEPT_GUARDED_NATIVE_DISPATCH
|
||||||
|
|
||||||
Optional path overrides:
|
Optional path overrides:
|
||||||
OPENFUT_FIFA17_HOOK_DLL, OPENFUT_FIFA17_GAME_DIR,
|
OPENFUT_FIFA17_HOOK_DLL, OPENFUT_FIFA17_GAME_DIR,
|
||||||
@@ -260,7 +287,7 @@ case "${1:-inspect}" in
|
|||||||
launch) launch baseline ;;
|
launch) launch baseline ;;
|
||||||
launch-resolve) launch resolve ;;
|
launch-resolve) launch resolve ;;
|
||||||
launch-trace) launch trace ;;
|
launch-trace) launch trace ;;
|
||||||
launch-commit) launch commit ;;
|
launch-dispatch) launch dispatch ;;
|
||||||
-h|--help|help) usage ;;
|
-h|--help|help) usage ;;
|
||||||
*) usage >&2; die "unknown command: $1" ;;
|
*) usage >&2; die "unknown command: $1" ;;
|
||||||
esac
|
esac
|
||||||
|
|||||||
Executable
+86
@@ -0,0 +1,86 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Find an APT/ActionScript symbol inside the FIFA 17 Frostbite .cas archives.
|
||||||
|
|
||||||
|
Frosty is a GUI-only tool and its Legacy Explorer is the documented way to reach
|
||||||
|
these assets, but the chunks holding APT ActionScript are stored plainly enough to
|
||||||
|
grep — so a screen can be identified, and its whole symbol table recovered,
|
||||||
|
without driving the GUI at all.
|
||||||
|
|
||||||
|
ALWAYS passes a control first: `KitAssignmentPopup` is a string from an
|
||||||
|
already-exported BIG, so if it misses, the archives are packed differently than
|
||||||
|
assumed and no negative from this tool may be quoted.
|
||||||
|
|
||||||
|
python3 find_apt_in_cas.py FUT_GET_MATCH_KITS_DP
|
||||||
|
python3 find_apt_in_cas.py --dump 0x3707ecd7 fifa_installpackage_01/cas_01.cas
|
||||||
|
"""
|
||||||
|
import argparse
|
||||||
|
import glob
|
||||||
|
import os
|
||||||
|
import re
|
||||||
|
import sys
|
||||||
|
|
||||||
|
ROOT = "/mnt/games/FIFA 17"
|
||||||
|
CONTROL = b"KitAssignmentPopup"
|
||||||
|
|
||||||
|
|
||||||
|
def cas_files():
|
||||||
|
return sorted(glob.glob(os.path.join(ROOT, "**", "*.cas"), recursive=True))
|
||||||
|
|
||||||
|
|
||||||
|
def find(needle: bytes):
|
||||||
|
control_total = 0
|
||||||
|
hits = []
|
||||||
|
for p in cas_files():
|
||||||
|
d = open(p, "rb").read()
|
||||||
|
control_total += d.count(CONTROL)
|
||||||
|
start = 0
|
||||||
|
while True:
|
||||||
|
i = d.find(needle, start)
|
||||||
|
if i < 0:
|
||||||
|
break
|
||||||
|
hits.append((p, i))
|
||||||
|
start = i + 1
|
||||||
|
return control_total, hits
|
||||||
|
|
||||||
|
|
||||||
|
def dump(path, off, span=90000):
|
||||||
|
with open(path, "rb") as f:
|
||||||
|
f.seek(max(0, off - span // 2))
|
||||||
|
d = f.read(span)
|
||||||
|
seen = []
|
||||||
|
for m in re.finditer(rb"[ -~]{4,}", d):
|
||||||
|
t = m.group().decode("latin1")
|
||||||
|
if t not in seen:
|
||||||
|
seen.append(t)
|
||||||
|
return seen
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
ap = argparse.ArgumentParser()
|
||||||
|
ap.add_argument("needle", nargs="?")
|
||||||
|
ap.add_argument("--dump", metavar="OFFSET")
|
||||||
|
ap.add_argument("--file")
|
||||||
|
args = ap.parse_args()
|
||||||
|
|
||||||
|
if args.dump:
|
||||||
|
path = args.file if os.path.isabs(args.file or "") else os.path.join(
|
||||||
|
ROOT, "Data/Win32/superbundlelayout", args.file or "")
|
||||||
|
for s in dump(path, int(args.dump, 0)):
|
||||||
|
print(s)
|
||||||
|
return 0
|
||||||
|
|
||||||
|
if not args.needle:
|
||||||
|
ap.error("needle required")
|
||||||
|
ctl, hits = find(args.needle.encode())
|
||||||
|
print(f"control {CONTROL.decode()}: {ctl} hit(s)")
|
||||||
|
if ctl == 0:
|
||||||
|
print("CONTROL FAILED — archives not greppable this way; no negative is valid.")
|
||||||
|
return 1
|
||||||
|
print(f"{args.needle}: {len(hits)} hit(s)")
|
||||||
|
for p, i in hits[:20]:
|
||||||
|
print(f" {os.path.relpath(p, ROOT)} @ {i:#x}")
|
||||||
|
return 0
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
sys.exit(main())
|
||||||
@@ -299,10 +299,16 @@ def player_item(item_id, player, special=False):
|
|||||||
# The cause is the guard the table work reversed. FUN_18013fe00 stores our
|
# The cause is the guard the table work reversed. FUN_18013fe00 stores our
|
||||||
# discardValue at item +0x38; at 0x180141025 a `cmp dword [rbp+0x198],0` / `ja` skips
|
# discardValue at item +0x38; at 0x180141025 a `cmp dword [rbp+0x198],0` / `ja` skips
|
||||||
# the client's own local computation when that value is NON-ZERO. We seed 0, so the
|
# the client's own local computation when that value is NON-ZERO. We seed 0, so the
|
||||||
# client runs its own fcc_discardcoins lookup, that lookup returns no row for our
|
# client runs its own fcc_discardcoins lookup and the price register stays 0.
|
||||||
# cards, the price register stays 0, and it renders 0. WHY its lookup misses is still
|
#
|
||||||
# UNKNOWN and worth knowing, but it does not have to be answered to fix the display:
|
# CORRECTED 2026-08-06: the two claims that used to sit here -- "that lookup
|
||||||
# sending a non-zero value bypasses the lookup entirely and the client uses ours.
|
# returns no row for our cards" and "WHY its lookup misses is still UNKNOWN" --
|
||||||
|
# are both FALSE. The lookup does not miss; real rows exist for both rare values
|
||||||
|
# on (cardtype 6, level, rare). The tile reads a DIFFERENT property, which is why
|
||||||
|
# the wallet and the screen disagreed. Sending a non-zero value still fixes the
|
||||||
|
# display, for the reason below -- it bypasses the local computation entirely --
|
||||||
|
# but do not carry the "missing row" story forward: it sent one round of work
|
||||||
|
# looking for a table defect that was never there.
|
||||||
#
|
#
|
||||||
# Freeze risk: low and in the safe direction. discardValue is a plain INT read by the
|
# Freeze risk: low and in the safe direction. discardValue is a plain INT read by the
|
||||||
# scalar getter 0x1801c79d0. The freezes on this project have all come from feeding an
|
# scalar getter 0x1801c79d0. The freezes on this project have all come from feeding an
|
||||||
|
|||||||
@@ -15,16 +15,27 @@ reimplementations (the `tdf` crate cloned in this scratchpad), which were used
|
|||||||
only as a cross-check of *structure*, never copied.
|
only as a cross-check of *structure*, never copied.
|
||||||
NO EA/FIFA leaked source was consulted.
|
NO EA/FIFA leaked source was consulted.
|
||||||
|
|
||||||
VALIDATED RULES (byte-exact round-trip against the 219-byte capture)
|
VALIDATED RULES (the TDF body; byte-exact round-trip against the 219-byte capture)
|
||||||
--------------------------------------------------------------------
|
---------------------------------------------------------------------------------
|
||||||
Fire2 frame header, 16 bytes big-endian:
|
Fire2 frame header, 16 bytes big-endian.
|
||||||
[0:4] u32 payload length (bytes after the header)
|
|
||||||
[4:6] u16 always 0 (observed)
|
!!! SUPERSEDED — the [10:16] FIELD SEMANTICS below are WRONG for FIFA 17. !!!
|
||||||
|
The "byte-exact round-trip" only proves the payload length and the TDF body
|
||||||
|
encoding: decoding then re-encoding with the SAME (mis)labelled header layout
|
||||||
|
trivially reproduces the capture, so it never tested the header's field
|
||||||
|
boundaries. The authoritative, live-driven layout is
|
||||||
|
`openfut-protocol-blaze::fire2` / `blaze_responder_v3b.py::fire2`:
|
||||||
|
[0:4] u32 payload length (bytes after header + metadata)
|
||||||
|
[4:6] u16 metadata length (0 when absent — what this file called "always 0")
|
||||||
[6:8] u16 component
|
[6:8] u16 component
|
||||||
[8:10] u16 command
|
[8:10] u16 command
|
||||||
[10:12]u16 error / msgId
|
[10:13] u24 msgNum (this file WRONGLY split it as [10:12] msgId + [12] msgType)
|
||||||
[12] u8 msgType (0x01 ping, 0x02 request, 0x03 pong/response)
|
[13] u8 (msgType << 5) | (userIndex & 0x1F)
|
||||||
[13:16]3 reserved bytes (observed 00 00 00)
|
[14] u8 options
|
||||||
|
[15] u8 reserved
|
||||||
|
There is NO error field in Fire2 (that is Fire v1) and NO jumbo escape — the
|
||||||
|
length is already a full u32. `build_fire2_frame`/`decode_fire2` below keep the
|
||||||
|
old wrong `>IHHHHB3s` layout; they are dead and retained only for history.
|
||||||
|
|
||||||
Heat2 field = 3-byte packed tag + 1 type byte + value.
|
Heat2 field = 3-byte packed tag + 1 type byte + value.
|
||||||
|
|
||||||
@@ -359,7 +370,14 @@ MSG_ERROR = 0x05 # UNVERIFIED
|
|||||||
|
|
||||||
def build_fire2_frame(component: int, command: int, msgType: int,
|
def build_fire2_frame(component: int, command: int, msgType: int,
|
||||||
msgId: int, tdf_bytes: bytes) -> bytes:
|
msgId: int, tdf_bytes: bytes) -> bytes:
|
||||||
"""16-byte big-endian Fire2 header + TDF payload."""
|
"""16-byte big-endian Fire2 header + TDF payload.
|
||||||
|
|
||||||
|
WRONG HEADER (dead code): the ``>IHHHHB3s`` layout mislabels [10:16] — it
|
||||||
|
puts a u16 msgId at [10:12] and msgType at [12]. FIFA 17's real Fire2 header
|
||||||
|
is [10:13] u24 msgNum, [13] (msgType<<5)|userIndex, [14] options, [15]
|
||||||
|
reserved, and has no error field. Use ``openfut-protocol-blaze::fire2`` or
|
||||||
|
``blaze_responder_v3b.py::fire2``; this is retained only for history.
|
||||||
|
"""
|
||||||
tdf_bytes = bytes(tdf_bytes)
|
tdf_bytes = bytes(tdf_bytes)
|
||||||
hdr = struct.pack(">IHHHHB3s", len(tdf_bytes), 0, component & 0xFFFF,
|
hdr = struct.pack(">IHHHHB3s", len(tdf_bytes), 0, component & 0xFFFF,
|
||||||
command & 0xFFFF, msgId & 0xFFFF, msgType & 0xFF,
|
command & 0xFFFF, msgId & 0xFFFF, msgType & 0xFF,
|
||||||
|
|||||||
Executable
+177
@@ -0,0 +1,177 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
# -*- coding: utf-8 -*-
|
||||||
|
"""Settle the pre-match kit selector gate: who, if anyone, writes item `+0x60`.
|
||||||
|
|
||||||
|
READ-ONLY. /proc/PID/mem is opened 'rb'; there is no write path in this file.
|
||||||
|
|
||||||
|
WHY THIS EXISTS
|
||||||
|
---------------
|
||||||
|
`plan-2026-08-06-card-subsystem.md` section 5 calls `+0x60` "the single blocker
|
||||||
|
between 'we can mark a kit equipped' and 'we can equip a kit'", and records that
|
||||||
|
two attempts to find its writer drowned: scanning for the offset returned 1688
|
||||||
|
and 4144 instructions depending on method.
|
||||||
|
|
||||||
|
The scan drowns because `+0x60` is a common struct offset. Two cheap filters cut
|
||||||
|
it to something a person can read:
|
||||||
|
|
||||||
|
* only IMMEDIATE stores can introduce a constant (a register store propagates
|
||||||
|
one from somewhere else), and
|
||||||
|
* item-record code is recognisable by touching `+0x4c` (cardtype) or `+0x5c`
|
||||||
|
(itemState) within a few instructions.
|
||||||
|
|
||||||
|
WHAT IT REPORTS
|
||||||
|
---------------
|
||||||
|
1. The live `+0x60` distribution over every resident CardsDb record.
|
||||||
|
2. Every `cmp dword [reg+0x60], imm8` in CardsDLL .text -- the readers.
|
||||||
|
3. Every immediate store to `[reg+0x60]` and the constants they use.
|
||||||
|
4. Which of those stores sit next to item-record code.
|
||||||
|
|
||||||
|
MEASURED 2026-08-21 (pid 6580, 27 resident records):
|
||||||
|
live +0x60 : {1: 23 (players), 0: 4 (staff)} -- never 4
|
||||||
|
readers : 4 total; exactly ONE compares against 4, at 0x1801c34f2,
|
||||||
|
which is the kit gate in FUN_1801c3480
|
||||||
|
immediate stores: 27 total; constants {-2, 0, 1, 908, 0x3f800000} -- NO 4
|
||||||
|
FIFA17.exe : 0 immediate stores of 4 to +0x60 across its 79MB of code,
|
||||||
|
and 0 comparisons against 4
|
||||||
|
gate xrefs : 1 (a jmp from 0x1801a5329); address never taken
|
||||||
|
|
||||||
|
The gate at 0x1801c34f2 decodes as:
|
||||||
|
|
||||||
|
cmp [rdi+0x4c], 7 cardtype 7 = kit/stadium/badge <- we produce this
|
||||||
|
cmp [rdi+0x60], 4 <- THE BLOCKER
|
||||||
|
mov eax, [rdi+0x5c] itemState
|
||||||
|
cmp eax, 0x65 / 0x66 101 activeHomeKit / 102 activeAwayKit <- we produce
|
||||||
|
mov r8d, [rdi+0x94] teamid <- we produce
|
||||||
|
mov r9d, [rdi+0xba] kit variant selector (unresolved)
|
||||||
|
|
||||||
|
So every input EXCEPT `+0x60` is already satisfied by what OpenFUT serves, and
|
||||||
|
no instruction in either module ever stores the constant 4 there.
|
||||||
|
|
||||||
|
Usage: python3 kit_gate_probe.py
|
||||||
|
"""
|
||||||
|
import collections
|
||||||
|
import struct
|
||||||
|
import sys
|
||||||
|
|
||||||
|
import watch_club_model as W
|
||||||
|
|
||||||
|
try:
|
||||||
|
import card_identity_probe as P
|
||||||
|
except Exception: # pragma: no cover - probe is optional for the static half
|
||||||
|
P = None
|
||||||
|
|
||||||
|
TEXT_START = 0x180001000
|
||||||
|
FIELD = 0x60
|
||||||
|
REGS = ["rax", "rcx", "rdx", "rbx", "rsp", "rbp", "rsi", "rdi"]
|
||||||
|
REC_SIZE = 0x158
|
||||||
|
F_SUBTYPE = 0x50
|
||||||
|
|
||||||
|
|
||||||
|
def live_distribution(mem, base):
|
||||||
|
"""(+0x60 histogram, (subtype,+0x60) histogram) over resident records."""
|
||||||
|
if P is None:
|
||||||
|
return None, None
|
||||||
|
obj = mem.q(base + (W.G_CARDSDB - W.IMG_BASE))
|
||||||
|
if not obj:
|
||||||
|
return None, None
|
||||||
|
by_value = collections.Counter()
|
||||||
|
by_pair = collections.Counter()
|
||||||
|
for node in P.nodes(mem, obj):
|
||||||
|
buf = mem.read(node + 0x28, REC_SIZE)
|
||||||
|
if not buf or len(buf) < REC_SIZE:
|
||||||
|
continue
|
||||||
|
subtype = struct.unpack_from("<I", buf, F_SUBTYPE)[0]
|
||||||
|
value = struct.unpack_from("<i", buf, FIELD)[0]
|
||||||
|
by_value[value] += 1
|
||||||
|
by_pair[(subtype, value)] += 1
|
||||||
|
return by_value, by_pair
|
||||||
|
|
||||||
|
|
||||||
|
def scan_text(text):
|
||||||
|
"""(readers, immediate stores, item-record markers) over a .text image."""
|
||||||
|
readers, stores, markers = [], [], set()
|
||||||
|
for i in range(len(text) - 8):
|
||||||
|
op, modrm = text[i], text[i + 1]
|
||||||
|
mod, reg, rm = modrm >> 6, (modrm >> 3) & 7, modrm & 7
|
||||||
|
if mod != 1 or rm == 4:
|
||||||
|
continue
|
||||||
|
disp = text[i + 2]
|
||||||
|
if disp in (0x4C, 0x5C) and op in (0x8B, 0x89, 0x83, 0x39, 0x3B, 0xC7, 0x0F):
|
||||||
|
markers.add(TEXT_START + i)
|
||||||
|
if disp != FIELD:
|
||||||
|
continue
|
||||||
|
if op == 0x83 and reg == 7: # cmp dword [reg+0x60], imm8
|
||||||
|
readers.append((TEXT_START + i, REGS[rm], text[i + 3]))
|
||||||
|
elif op == 0xC7 and reg == 0: # mov dword [reg+0x60], imm32
|
||||||
|
stores.append((TEXT_START + i, REGS[rm], struct.unpack_from("<i", text, i + 3)[0], "dword"))
|
||||||
|
elif op == 0xC6 and reg == 0: # mov byte [reg+0x60], imm8
|
||||||
|
stores.append((TEXT_START + i, REGS[rm], text[i + 3], "byte"))
|
||||||
|
return readers, stores, markers
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
pid = W.find_pid()
|
||||||
|
if pid is None:
|
||||||
|
print("FIFA17.exe is not running.")
|
||||||
|
return 1
|
||||||
|
base = W.dll_base(pid)
|
||||||
|
if base is None:
|
||||||
|
print("pid %d is up but %s is not mapped." % (pid, W.DLL))
|
||||||
|
return 1
|
||||||
|
mem = W.Mem(pid)
|
||||||
|
|
||||||
|
print("pid=%d %s base=%#x" % (pid, W.DLL, base))
|
||||||
|
print()
|
||||||
|
|
||||||
|
by_value, by_pair = live_distribution(mem, base)
|
||||||
|
print("── live records ──")
|
||||||
|
if by_value is None:
|
||||||
|
print(" CardsDb is empty (no FUT session loaded); static half still runs.")
|
||||||
|
else:
|
||||||
|
print(" +0x60 distribution : %s" % dict(by_value))
|
||||||
|
print(" (cardsubtypeid, +0x60) : %s" % dict(by_pair))
|
||||||
|
print(" holds the gate value 4 : %s" % ("YES" if 4 in by_value else "NO"))
|
||||||
|
print()
|
||||||
|
|
||||||
|
# .text is the second CardsDLL mapping; read it whole and scan.
|
||||||
|
size = 0x1E4000
|
||||||
|
buf, bad = mem.read_pages(base + 0x1000, size)
|
||||||
|
if bad:
|
||||||
|
print(" WARNING: %d unreadable page(s); the scan is incomplete." % len(bad))
|
||||||
|
text = bytes(buf)
|
||||||
|
|
||||||
|
readers, stores, markers = scan_text(text)
|
||||||
|
print("── readers: cmp dword [reg+0x60], imm8 ──")
|
||||||
|
for va, reg, imm in readers:
|
||||||
|
flag = " <-- THE KIT GATE" if imm == 4 else ""
|
||||||
|
print(" %#x cmp [%s+0x60], %d%s" % (va, reg, imm, flag))
|
||||||
|
print()
|
||||||
|
|
||||||
|
print("── immediate stores to [reg+0x60] ──")
|
||||||
|
consts = collections.Counter(s[2] for s in stores)
|
||||||
|
print(" %d store(s); constants %s" % (len(stores), dict(sorted(consts.items()))))
|
||||||
|
near = [s for s in stores if any(abs(m - s[0]) <= 96 for m in markers)]
|
||||||
|
print(" %d of them sit within 96B of item-record code (+0x4c/+0x5c):" % len(near))
|
||||||
|
for va, reg, imm, width in near:
|
||||||
|
print(" %#x mov %s [%s+0x60], %d" % (va, width, reg, imm))
|
||||||
|
print()
|
||||||
|
|
||||||
|
print("=" * 70)
|
||||||
|
if any(s[2] == 4 for s in stores):
|
||||||
|
print("A store of 4 EXISTS -- the gate is reachable. Follow the sites above.")
|
||||||
|
return 0
|
||||||
|
print("NO instruction in CardsDLL stores the constant 4 into +0x60.")
|
||||||
|
print("Combined with the live records (never 4) and the fact that every OTHER")
|
||||||
|
print("gate input is already served, the pre-match kit selector cannot be")
|
||||||
|
print("opened by anything the server sends. This is a CLIENT-side dead end,")
|
||||||
|
print("not a missing wire field.")
|
||||||
|
print()
|
||||||
|
print("Scope of the claim: immediate stores, all widths, disp8 form. A value")
|
||||||
|
print("could still arrive by register copy -- but in CardsDLL every register")
|
||||||
|
print("store to +0x60 is a field-by-field struct copy or an init to 0/1/-2.")
|
||||||
|
print("=" * 70)
|
||||||
|
return 0
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
sys.exit(main())
|
||||||
Executable
+114
@@ -0,0 +1,114 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Read-only census of FIFA 17's RESIDENT club-item vector.
|
||||||
|
|
||||||
|
Chain, every link from CardsDLL static RE:
|
||||||
|
[CardsDLL+0x2e6398] -> owner object (FUN_18011a830)
|
||||||
|
owner->vtable[0x4e8] -> getter returning mgr (call *0x4e8(%rdx))
|
||||||
|
mgr+0x108 .. mgr+0x110 -> club-item vector, stride 24
|
||||||
|
element+0x10 -> the item record pointer (FUN_1800d73d0)
|
||||||
|
record+0x4c cardtype (derived from cardsubtypeid by FUN_1800d8330: 9/10/11 -> 7)
|
||||||
|
record+0x50 cardsubtypeid
|
||||||
|
record+0x5c itemState (101 activeHomeKit, 102 activeAwayKit)
|
||||||
|
record+0x60 category (clone driver FUN_1801c3480 requires 4)
|
||||||
|
record+0x94 teamid
|
||||||
|
record+0xba teamkittypetechid (u16)
|
||||||
|
Offsets not in that list are labelled UNVERIFIED and only dumped raw.
|
||||||
|
No writes. Ever.
|
||||||
|
"""
|
||||||
|
import re, struct, sys, collections
|
||||||
|
|
||||||
|
PID = int(sys.argv[1]) if len(sys.argv) > 1 else 44405
|
||||||
|
mem = open(f"/proc/{PID}/mem", "rb", buffering=0)
|
||||||
|
|
||||||
|
def rd(a, n):
|
||||||
|
mem.seek(a); return mem.read(n)
|
||||||
|
def q(a):
|
||||||
|
return struct.unpack("<Q", rd(a, 8))[0]
|
||||||
|
def i32(b, o):
|
||||||
|
return struct.unpack_from("<i", b, o)[0]
|
||||||
|
|
||||||
|
# locate CardsDLL by its NEAREST PRECEDING NAMED mapping (Wine maps PE sections anon)
|
||||||
|
named = []
|
||||||
|
for ln in open(f"/proc/{PID}/maps"):
|
||||||
|
m = re.match(r"([0-9a-f]+)-([0-9a-f]+) \S{4} \S+ \S+ \S+\s+(.+)", ln)
|
||||||
|
if m: named.append((int(m.group(1),16), m.group(3).strip()))
|
||||||
|
named.sort()
|
||||||
|
base = None
|
||||||
|
for s, p in named:
|
||||||
|
if p.endswith("CardsDLL_Win64_retail.dll"):
|
||||||
|
base = s; break
|
||||||
|
if base is None:
|
||||||
|
print(" CardsDLL mapping not found"); sys.exit(1)
|
||||||
|
print(f" CardsDLL base = {base:#x}")
|
||||||
|
def live(static): return base + (static - 0x180000000)
|
||||||
|
|
||||||
|
# sanity: the 0x7575 sender immediate must be where static RE says
|
||||||
|
probe = rd(live(0x180026fea), 6)
|
||||||
|
print(f" sanity @0x180026fea: {probe.hex(' ')} (expect ba 75 75 00 00)")
|
||||||
|
if probe[:5] != bytes.fromhex("ba75750000"):
|
||||||
|
print(" SANITY FAILED - base wrong, aborting"); sys.exit(1)
|
||||||
|
|
||||||
|
owner = q(live(0x1802e6398))
|
||||||
|
print(f" owner object = {owner:#x}")
|
||||||
|
vt = q(owner)
|
||||||
|
getter = q(vt + 0x4e8)
|
||||||
|
print(f" vtable = {vt:#x}")
|
||||||
|
print(f" vtable[0x4e8] = {getter:#x} bytes: {rd(getter,12).hex(' ')}")
|
||||||
|
# expect: mov rax,[rcx+off] ; ret -> 48 8b 81 off32 c3 or 48 8b 41 off8 c3
|
||||||
|
b = rd(getter, 12)
|
||||||
|
mgr = None
|
||||||
|
if b[0:3] == bytes.fromhex("488d81"):
|
||||||
|
off = struct.unpack_from("<I", b, 3)[0]; mgr = owner + off
|
||||||
|
print(f" getter returns owner+{off:#x} (EMBEDDED subobject) -> mgr = {mgr:#x}")
|
||||||
|
elif b[0:3] == bytes.fromhex("488d41"):
|
||||||
|
off = b[3]; mgr = owner + off
|
||||||
|
print(f" getter returns owner+{off:#x} (EMBEDDED subobject) -> mgr = {mgr:#x}")
|
||||||
|
elif b[0:3] == bytes.fromhex("488b81"):
|
||||||
|
off = struct.unpack_from("<I", b, 3)[0]; mgr = q(owner + off)
|
||||||
|
print(f" getter returns [owner+{off:#x}] -> mgr = {mgr:#x}")
|
||||||
|
elif b[0:3] == bytes.fromhex("488b41"):
|
||||||
|
off = b[3]; mgr = q(owner + off)
|
||||||
|
print(f" getter returns [owner+{off:#x}] -> mgr = {mgr:#x}")
|
||||||
|
elif b[0:2] == bytes.fromhex("488b") and b[2] == 0xc1:
|
||||||
|
mgr = owner; print(" getter returns owner itself")
|
||||||
|
else:
|
||||||
|
print(" getter shape unrecognised; trying owner as mgr")
|
||||||
|
mgr = owner
|
||||||
|
|
||||||
|
for label, mgr_try in (("resolved", mgr), ("owner", owner)):
|
||||||
|
try:
|
||||||
|
beg, end = q(mgr_try + 0x108), q(mgr_try + 0x110)
|
||||||
|
except OSError:
|
||||||
|
print(f" [{label}] +0x108/0x110 unreadable"); continue
|
||||||
|
if not (0 < beg <= end) or (end - beg) % 24 or (end - beg) > 24*100000:
|
||||||
|
print(f" [{label}] vector implausible: {beg:#x}..{end:#x}")
|
||||||
|
continue
|
||||||
|
n = (end - beg) // 24
|
||||||
|
print(f"\n === club-item vector via {label}: {beg:#x}..{end:#x} {n} slot(s) ===")
|
||||||
|
hist = collections.Counter(); rows = []
|
||||||
|
for k in range(n):
|
||||||
|
try:
|
||||||
|
rec = q(beg + k*24 + 0x10)
|
||||||
|
except OSError:
|
||||||
|
continue
|
||||||
|
if not rec:
|
||||||
|
hist[("<null slot>", None)] += 1; continue
|
||||||
|
try:
|
||||||
|
r = rd(rec, 0xC0)
|
||||||
|
except OSError:
|
||||||
|
continue
|
||||||
|
if len(r) < 0xC0: continue
|
||||||
|
ct, sub, st, cat = i32(r,0x4c), i32(r,0x50), i32(r,0x5c), i32(r,0x60)
|
||||||
|
team = i32(r,0x94); kt = struct.unpack_from("<H", r, 0xba)[0]
|
||||||
|
hist[(ct, sub)] += 1
|
||||||
|
rows.append((rec, ct, sub, st, cat, team, kt))
|
||||||
|
print(f" (cardtype, cardsubtypeid) histogram:")
|
||||||
|
for key, c in sorted(hist.items(), key=lambda x: -x[1]):
|
||||||
|
tag = " <== KIT (selector needs this)" if key == (7, 9) else ""
|
||||||
|
print(f" {str(key):<18} x{c}{tag}")
|
||||||
|
print(f" cardtype 7 records: {sum(c for (ct,_),c in hist.items() if ct==7)}")
|
||||||
|
print(f"\n first 12 records:")
|
||||||
|
print(f" {'ptr':>14} {'ctype':>5} {'subtype':>7} {'state':>5} {'cat':>4} {'team':>5} {'kittype':>7}")
|
||||||
|
for rec, ct, sub, st, cat, team, kt in rows[:12]:
|
||||||
|
print(f" {rec:#14x} {ct:>5} {sub:>7} {st:>5} {cat:>4} {team:>5} {kt:>7}")
|
||||||
|
break
|
||||||
Executable
+137
@@ -0,0 +1,137 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Byte-level diff of the two resident kit records in a live FIFA17 client.
|
||||||
|
|
||||||
|
The pre-match selector draws each kit from a clone query keyed on the record's
|
||||||
|
own fields, so if both tiles render identically the question is precisely: which
|
||||||
|
bytes of the home record differ from the away record? This prints every differing
|
||||||
|
offset with the known field names attached, and dumps the fields the decoded
|
||||||
|
clone query consumes.
|
||||||
|
|
||||||
|
Read-only. Never writes to the process.
|
||||||
|
|
||||||
|
Decoded query (FUN_1801c3480 -> FUN_1801c44b0):
|
||||||
|
teamtechid == record+0x94
|
||||||
|
teamkittypetechid == derived from itemState (101 -> 0 home, 102 -> 1 away)
|
||||||
|
year == record+0xba
|
||||||
|
"""
|
||||||
|
import re
|
||||||
|
import struct
|
||||||
|
import sys
|
||||||
|
|
||||||
|
PID = int(sys.argv[1])
|
||||||
|
WANT = [int(a) for a in sys.argv[2:]] or [100004874, 100004873]
|
||||||
|
|
||||||
|
mem = open(f"/proc/{PID}/mem", "rb", buffering=0)
|
||||||
|
|
||||||
|
|
||||||
|
def rd(a, n):
|
||||||
|
mem.seek(a)
|
||||||
|
return mem.read(n)
|
||||||
|
|
||||||
|
|
||||||
|
def q(a):
|
||||||
|
return struct.unpack("<Q", rd(a, 8))[0]
|
||||||
|
|
||||||
|
|
||||||
|
named = []
|
||||||
|
for ln in open(f"/proc/{PID}/maps"):
|
||||||
|
m = re.match(r"([0-9a-f]+)-([0-9a-f]+) \S{4} \S+ \S+ \S+\s+(.+)", ln)
|
||||||
|
if m:
|
||||||
|
named.append((int(m.group(1), 16), m.group(3).strip()))
|
||||||
|
named.sort()
|
||||||
|
base = next((s for s, p in named if p.endswith("CardsDLL_Win64_retail.dll")), None)
|
||||||
|
if base is None:
|
||||||
|
sys.exit("CardsDLL mapping not found")
|
||||||
|
|
||||||
|
|
||||||
|
def live(static):
|
||||||
|
return base + (static - 0x180000000)
|
||||||
|
|
||||||
|
|
||||||
|
if rd(live(0x180026FEA), 5) != bytes.fromhex("ba75750000"):
|
||||||
|
sys.exit("SANITY FAILED - wrong base")
|
||||||
|
print(f" CardsDLL base = {base:#x} (sanity ok)")
|
||||||
|
|
||||||
|
owner = q(live(0x1802E6398))
|
||||||
|
sentinel = owner + 0x160C8
|
||||||
|
root = q(owner + 0x160D8)
|
||||||
|
|
||||||
|
# Known record fields, offset -> (name, width)
|
||||||
|
FIELDS = {
|
||||||
|
0x08: ("id", 8),
|
||||||
|
0x18: ("resourceId/definitionId", 4),
|
||||||
|
# Offsets per club_items.json `_record_map`, which is authoritative:
|
||||||
|
# cardassetid is +0x1c and assetId is +0x20 — NOT the other way round.
|
||||||
|
0x1C: ("cardassetid", 4),
|
||||||
|
0x20: ("assetId", 4),
|
||||||
|
0x38: ("discardValue", 4),
|
||||||
|
0x4C: ("cardtype", 4),
|
||||||
|
0x50: ("cardsubtypeid", 4),
|
||||||
|
0x5C: ("itemState", 4),
|
||||||
|
0x60: ("category(club slot)", 4),
|
||||||
|
0x8C: ("contract", 4),
|
||||||
|
0x94: ("teamid", 4),
|
||||||
|
0xB4: ("rating", 4),
|
||||||
|
0xB8: ("wire category", 1),
|
||||||
|
0xBA: ("year", 2),
|
||||||
|
0x148: ("nation", 4),
|
||||||
|
0x154: ("leagueId", 4),
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
def walk(node, out):
|
||||||
|
if not node or node == sentinel:
|
||||||
|
return
|
||||||
|
walk(q(node + 0x00), out)
|
||||||
|
# The record is EMBEDDED at node+0x28 — NOT a pointer stored there.
|
||||||
|
out.append((struct.unpack("<q", rd(node + 0x20, 8))[0], node + 0x28))
|
||||||
|
walk(q(node + 0x08), out)
|
||||||
|
|
||||||
|
|
||||||
|
nodes = []
|
||||||
|
walk(root, nodes)
|
||||||
|
recs = {k: v for k, v in nodes}
|
||||||
|
|
||||||
|
found = [(w, recs[w]) for w in WANT if w in recs]
|
||||||
|
if len(found) < 2:
|
||||||
|
sys.exit(f" need two resident kit records, found {[w for w, _ in found]}")
|
||||||
|
|
||||||
|
(id_a, ptr_a), (id_b, ptr_b) = found[0], found[1]
|
||||||
|
a = rd(ptr_a, 0x180)
|
||||||
|
b = rd(ptr_b, 0x180)
|
||||||
|
print(f" A = {id_a} @ {ptr_a:#x}")
|
||||||
|
print(f" B = {id_b} @ {ptr_b:#x}")
|
||||||
|
|
||||||
|
print("\n --- fields the clone query consumes ---")
|
||||||
|
for off in (0x94, 0x5C, 0xBA):
|
||||||
|
name = FIELDS[off][0]
|
||||||
|
w = FIELDS[off][1]
|
||||||
|
va = int.from_bytes(a[off : off + w], "little")
|
||||||
|
vb = int.from_bytes(b[off : off + w], "little")
|
||||||
|
flag = "" if va != vb else " <== IDENTICAL"
|
||||||
|
print(f" +{off:#05x} {name:24} A={va:<12} B={vb:<12}{flag}")
|
||||||
|
|
||||||
|
print("\n --- every differing byte range ---")
|
||||||
|
diffs = [i for i in range(0x180) if a[i] != b[i]]
|
||||||
|
runs = []
|
||||||
|
for i in diffs:
|
||||||
|
if runs and i == runs[-1][1] + 1:
|
||||||
|
runs[-1][1] = i
|
||||||
|
else:
|
||||||
|
runs.append([i, i])
|
||||||
|
for s, e in runs:
|
||||||
|
named_field = next(
|
||||||
|
(n for o, (n, w) in FIELDS.items() if o <= s < o + w), "(unmapped)"
|
||||||
|
)
|
||||||
|
va = int.from_bytes(a[s : e + 1], "little")
|
||||||
|
vb = int.from_bytes(b[s : e + 1], "little")
|
||||||
|
print(f" +{s:#05x}..{e:#05x} {named_field:24} A={va:<12} B={vb}")
|
||||||
|
print(f"\n {len(diffs)} differing bytes in {len(runs)} runs")
|
||||||
|
|
||||||
|
print("\n --- known fields, side by side ---")
|
||||||
|
for off in sorted(FIELDS):
|
||||||
|
name, w = FIELDS[off]
|
||||||
|
va = int.from_bytes(a[off : off + w], "little")
|
||||||
|
vb = int.from_bytes(b[off : off + w], "little")
|
||||||
|
mark = " DIFFERS" if va != vb else ""
|
||||||
|
print(f" +{off:#05x} {name:24} A={va:<12} B={vb:<12}{mark}")
|
||||||
Executable
+58
@@ -0,0 +1,58 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# Remove the port-8081 DNAT rule that hijacks FIFA 17's roster/squad-update TLS.
|
||||||
|
#
|
||||||
|
# Why: the FUT squad update is https://winter15.gosredirector.ea.com:8081/fifa17/fut/rosterupdate.xml
|
||||||
|
# (TLS on port 8081). A DNAT rule rewriting dport 8081 -> 8299 sends that TLS
|
||||||
|
# handshake to the plain-HTTP staging UTAS host, which closes the connection.
|
||||||
|
# Proven: a probe to 10.10.0.120:8081 from this box arrives at the server as
|
||||||
|
# dport 8299. Result: "An error occurred downloading the FUT squad update."
|
||||||
|
#
|
||||||
|
# The rule also never redirected UTAS, which lives on :8443, not :8081.
|
||||||
|
#
|
||||||
|
# Read-only until it deletes; deletes only nat rules whose target port is 8299.
|
||||||
|
set -u
|
||||||
|
|
||||||
|
echo "== nat OUTPUT rules mentioning 8081 or 8299 =="
|
||||||
|
iptables -t nat -S OUTPUT 2>/dev/null | grep -E '8081|8299' || echo " (none)"
|
||||||
|
|
||||||
|
echo
|
||||||
|
echo "== deleting DNAT rules that redirect to port 8299 =="
|
||||||
|
removed=0
|
||||||
|
# Delete by spec, repeatedly, until no matching rule remains.
|
||||||
|
while :; do
|
||||||
|
rule=$(iptables -t nat -S OUTPUT 2>/dev/null | grep -m1 -E '\-\-dport 8081 .*8299|to-destination [0-9.]+:8299')
|
||||||
|
[ -z "$rule" ] && break
|
||||||
|
spec=$(printf '%s' "$rule" | sed 's/^-A /-D /')
|
||||||
|
# shellcheck disable=SC2086
|
||||||
|
if iptables -t nat $spec 2>/dev/null; then
|
||||||
|
echo " removed: $rule"
|
||||||
|
removed=$((removed + 1))
|
||||||
|
else
|
||||||
|
echo " FAILED to remove: $rule" >&2
|
||||||
|
break
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
[ "$removed" -eq 0 ] && echo " (no matching rule found)"
|
||||||
|
|
||||||
|
echo
|
||||||
|
echo "== remaining nat OUTPUT rules mentioning 8081 or 8299 =="
|
||||||
|
iptables -t nat -S OUTPUT 2>/dev/null | grep -E '8081|8299' || echo " (none)"
|
||||||
|
|
||||||
|
echo
|
||||||
|
echo "== verifying the roster endpoint now presents the correct certificate =="
|
||||||
|
python3 - <<'PY'
|
||||||
|
import socket, ssl
|
||||||
|
host, port, sni = "10.10.0.120", 8081, "winter15.gosredirector.ea.com"
|
||||||
|
try:
|
||||||
|
ctx = ssl.SSLContext(ssl.PROTOCOL_TLS_CLIENT)
|
||||||
|
ctx.check_hostname = False
|
||||||
|
ctx.verify_mode = ssl.CERT_NONE
|
||||||
|
with socket.create_connection((host, port), 8) as s:
|
||||||
|
with ctx.wrap_socket(s, server_hostname=sni) as t:
|
||||||
|
der = t.getpeercert(True)
|
||||||
|
cn = dict(x[0] for x in t.getpeercert().get("subject", ()))
|
||||||
|
print(f" PASS {host}:{port} sni={sni} {t.version()} der={len(der)}B subject={cn}")
|
||||||
|
except Exception as e:
|
||||||
|
print(f" FAIL {host}:{port} sni={sni} -> {type(e).__name__}: {e}")
|
||||||
|
print(" The roster path is still broken; do not relaunch yet.")
|
||||||
|
PY
|
||||||
Executable
+84
@@ -0,0 +1,84 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Hunt for specific wire instance ids anywhere in the client's writable memory.
|
||||||
|
|
||||||
|
Answers whether a served item was materialised into a record at all, versus
|
||||||
|
materialised but not attached to a collection. A record is recognised by its
|
||||||
|
established layout: id at +0x08, resourceId at +0x18, cardtype at +0x4c.
|
||||||
|
|
||||||
|
Read-only. Never writes.
|
||||||
|
|
||||||
|
usage: probe_hunt.py PID id [id ...]
|
||||||
|
"""
|
||||||
|
import re, struct, sys
|
||||||
|
|
||||||
|
PID = int(sys.argv[1])
|
||||||
|
IDS = [int(a) for a in sys.argv[2:]]
|
||||||
|
if not IDS:
|
||||||
|
sys.exit("give at least one wire id")
|
||||||
|
mem = open(f"/proc/{PID}/mem", "rb", buffering=0)
|
||||||
|
|
||||||
|
regions = []
|
||||||
|
for ln in open(f"/proc/{PID}/maps"):
|
||||||
|
m = re.match(r"([0-9a-f]+)-([0-9a-f]+) (\S{4}) \S+ \S+ \S+\s*(.*)", ln)
|
||||||
|
if not m:
|
||||||
|
continue
|
||||||
|
lo, hi, perms, path = int(m.group(1), 16), int(m.group(2), 16), m.group(3), m.group(4).strip()
|
||||||
|
if "w" not in perms:
|
||||||
|
continue
|
||||||
|
if path.startswith("/") and not path.endswith(".dll") and not path.endswith(".exe"):
|
||||||
|
continue
|
||||||
|
regions.append((lo, hi, perms, path))
|
||||||
|
total = sum(hi - lo for lo, hi, _, _ in regions)
|
||||||
|
print(f" {len(regions)} writable regions, {total/2**20:.0f} MiB to scan")
|
||||||
|
|
||||||
|
needles = {struct.pack("<I", i): i for i in IDS}
|
||||||
|
hits = {i: [] for i in IDS}
|
||||||
|
CHUNK = 8 << 20
|
||||||
|
scanned = 0
|
||||||
|
for lo, hi, perms, path in regions:
|
||||||
|
a = lo
|
||||||
|
while a < hi:
|
||||||
|
n = min(CHUNK, hi - a)
|
||||||
|
try:
|
||||||
|
mem.seek(a)
|
||||||
|
data = mem.read(n)
|
||||||
|
except OSError:
|
||||||
|
a += n
|
||||||
|
continue
|
||||||
|
if not data:
|
||||||
|
a += n
|
||||||
|
continue
|
||||||
|
scanned += len(data)
|
||||||
|
for nd, wid in needles.items():
|
||||||
|
start = 0
|
||||||
|
while True:
|
||||||
|
j = data.find(nd, start)
|
||||||
|
if j < 0:
|
||||||
|
break
|
||||||
|
start = j + 1
|
||||||
|
va = a + j
|
||||||
|
# a record would place this id at +0x08
|
||||||
|
rec = va - 0x08
|
||||||
|
try:
|
||||||
|
mem.seek(rec)
|
||||||
|
r = mem.read(0x100)
|
||||||
|
except OSError:
|
||||||
|
continue
|
||||||
|
if len(r) < 0x100:
|
||||||
|
continue
|
||||||
|
ct = struct.unpack_from("<i", r, 0x4c)[0]
|
||||||
|
res = struct.unpack_from("<I", r, 0x18)[0]
|
||||||
|
sub = struct.unpack_from("<i", r, 0x50)[0]
|
||||||
|
cat = struct.unpack_from("<i", r, 0x60)[0]
|
||||||
|
looks = 0 <= ct <= 32 and res > 1000
|
||||||
|
hits[wid].append((va, rec, ct, sub, cat, res, looks))
|
||||||
|
a += n
|
||||||
|
print(f" scanned {scanned/2**20:.0f} MiB\n")
|
||||||
|
for wid in IDS:
|
||||||
|
hs = hits[wid]
|
||||||
|
recs = [h for h in hs if h[6]]
|
||||||
|
print(f" id {wid}: {len(hs)} raw occurrence(s), {len(recs)} record-shaped")
|
||||||
|
for va, rec, ct, sub, cat, res, _ in recs[:6]:
|
||||||
|
print(f" record {rec:#x}: cardtype={ct} subtype={sub} category={cat} resourceId={res}")
|
||||||
|
if not recs:
|
||||||
|
print(" NOT MATERIALISED as a record anywhere in writable memory")
|
||||||
Executable
+92
@@ -0,0 +1,92 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Identify every resident record by its wire instance id.
|
||||||
|
|
||||||
|
Record layout established from known wire values:
|
||||||
|
+0x08 id (wire instance) +0x18 resourceId +0x1c/+0x20 assetId
|
||||||
|
+0x38 discardValue +0x4c cardtype +0x50 cardsubtypeid
|
||||||
|
+0x5c itemState +0x60 category +0x94 teamid
|
||||||
|
+0xb4 rating +0xba teamkittypetechid (u16)
|
||||||
|
|
||||||
|
Walks the contiguous 0x180-stride pool around the manager slot record so records
|
||||||
|
that are resident but not in any collection are still seen. Read-only.
|
||||||
|
|
||||||
|
usage: probe_ids.py PID [expected_id ...]
|
||||||
|
"""
|
||||||
|
import re, struct, sys
|
||||||
|
|
||||||
|
PID = int(sys.argv[1])
|
||||||
|
WANT = {int(a) for a in sys.argv[2:]}
|
||||||
|
mem = open(f"/proc/{PID}/mem", "rb", buffering=0)
|
||||||
|
|
||||||
|
def rd(a, n):
|
||||||
|
mem.seek(a); return mem.read(n)
|
||||||
|
def q(a):
|
||||||
|
return struct.unpack("<Q", rd(a, 8))[0]
|
||||||
|
|
||||||
|
named = []
|
||||||
|
for ln in open(f"/proc/{PID}/maps"):
|
||||||
|
m = re.match(r"([0-9a-f]+)-([0-9a-f]+) \S{4} \S+ \S+ \S+\s+(.+)", ln)
|
||||||
|
if m:
|
||||||
|
named.append((int(m.group(1), 16), m.group(3).strip()))
|
||||||
|
named.sort()
|
||||||
|
base = next(s for s, p in named if p.endswith("CardsDLL_Win64_retail.dll"))
|
||||||
|
live = lambda s: base + (s - 0x180000000)
|
||||||
|
if rd(live(0x180026fea), 5) != bytes.fromhex("ba75750000"):
|
||||||
|
sys.exit("SANITY FAILED")
|
||||||
|
owner = q(live(0x1802e6398))
|
||||||
|
mgr = owner + 0x1f9d8
|
||||||
|
RECSZ = 0x180
|
||||||
|
|
||||||
|
def dec(rec):
|
||||||
|
r = rd(rec, 0x180)
|
||||||
|
g = lambda o: struct.unpack_from("<i", r, o)[0]
|
||||||
|
return dict(id=struct.unpack_from("<I", r, 0x8)[0], res=struct.unpack_from("<I", r, 0x18)[0],
|
||||||
|
ct=g(0x4c), sub=g(0x50), st=g(0x5c), cat=g(0x60), team=g(0x94),
|
||||||
|
rating=struct.unpack_from("<I", r, 0xb4)[0],
|
||||||
|
kt=struct.unpack_from("<H", r, 0xba)[0])
|
||||||
|
|
||||||
|
mgr_rec = q(mgr + 0xc0 + 0x10)
|
||||||
|
print(f" manager-slot record = {mgr_rec:#x}")
|
||||||
|
anchor = mgr_rec if mgr_rec else q(q(mgr + 0xd8) + 0x10)
|
||||||
|
|
||||||
|
# walk backwards to the start of the contiguous run, then forwards
|
||||||
|
lo = anchor
|
||||||
|
for _ in range(64):
|
||||||
|
prev = lo - RECSZ
|
||||||
|
try:
|
||||||
|
d = dec(prev)
|
||||||
|
except OSError:
|
||||||
|
break
|
||||||
|
if not (0 < d["ct"] < 64) or d["id"] == 0:
|
||||||
|
break
|
||||||
|
lo = prev
|
||||||
|
|
||||||
|
print(f" pool run starts at {lo:#x}\n")
|
||||||
|
print(f" {'idx':>3} {'addr':>12} {'id':>10} {'resource':>9} {'ct':>3} {'sub':>4} "
|
||||||
|
f"{'st':>3} {'cat':>4} {'team':>5} {'rate':>5} {'kt':>6}")
|
||||||
|
found = {}
|
||||||
|
k = 0
|
||||||
|
addr = lo
|
||||||
|
while k < 48:
|
||||||
|
try:
|
||||||
|
d = dec(addr)
|
||||||
|
except OSError:
|
||||||
|
break
|
||||||
|
if d["id"] == 0 and d["ct"] == 0:
|
||||||
|
break
|
||||||
|
tag = ""
|
||||||
|
if d["ct"] == 7:
|
||||||
|
tag = " <== CARDTYPE 7"
|
||||||
|
if d["id"] in WANT:
|
||||||
|
tag += " <== WANTED"
|
||||||
|
found[d["id"]] = addr
|
||||||
|
slot = " [manager slot]" if addr == mgr_rec else ""
|
||||||
|
print(f" {k:>3} {addr:#12x} {d['id']:>10} {d['res']:>9} {d['ct']:>3} {d['sub']:>4} "
|
||||||
|
f"{d['st']:>3} {d['cat']:>4} {d['team']:>5} {d['rating']:>5} {d['kt']:>6}{tag}{slot}")
|
||||||
|
addr += RECSZ
|
||||||
|
k += 1
|
||||||
|
|
||||||
|
if WANT:
|
||||||
|
print(f"\n wanted ids: {sorted(WANT)}")
|
||||||
|
for w in sorted(WANT):
|
||||||
|
print(f" {w}: {'FOUND at ' + hex(found[w]) if w in found else 'NOT RESIDENT'}")
|
||||||
Executable
+95
@@ -0,0 +1,95 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Map FIFA 17 resident record offsets using UNIQUE wire values as ground truth.
|
||||||
|
|
||||||
|
v2: identifies each record by its wire instance id (large, unique) and only
|
||||||
|
accepts a field mapping when the value is distinctive (>= 16) and the same
|
||||||
|
offset holds the right value for EVERY identified record. This avoids the v1
|
||||||
|
failure where cardsubtypeid == 0 matched every zeroed field in the struct.
|
||||||
|
|
||||||
|
Read-only. Never writes.
|
||||||
|
|
||||||
|
usage: probe_layout2.py PID squad_active.json
|
||||||
|
"""
|
||||||
|
import re, struct, sys, json, collections
|
||||||
|
|
||||||
|
PID = int(sys.argv[1])
|
||||||
|
SQUAD = json.load(open(sys.argv[2]))
|
||||||
|
mem = open(f"/proc/{PID}/mem", "rb", buffering=0)
|
||||||
|
|
||||||
|
def rd(a, n):
|
||||||
|
mem.seek(a); return mem.read(n)
|
||||||
|
def q(a):
|
||||||
|
return struct.unpack("<Q", rd(a, 8))[0]
|
||||||
|
|
||||||
|
named = []
|
||||||
|
for ln in open(f"/proc/{PID}/maps"):
|
||||||
|
m = re.match(r"([0-9a-f]+)-([0-9a-f]+) \S{4} \S+ \S+ \S+\s+(.+)", ln)
|
||||||
|
if m:
|
||||||
|
named.append((int(m.group(1), 16), m.group(3).strip()))
|
||||||
|
named.sort()
|
||||||
|
base = next(s for s, p in named if p.endswith("CardsDLL_Win64_retail.dll"))
|
||||||
|
live = lambda s: base + (s - 0x180000000)
|
||||||
|
if rd(live(0x180026fea), 5) != bytes.fromhex("ba75750000"):
|
||||||
|
sys.exit("SANITY FAILED")
|
||||||
|
owner = q(live(0x1802e6398))
|
||||||
|
mgr = owner + 0x1f9d8
|
||||||
|
RECSZ = 0x180
|
||||||
|
|
||||||
|
beg, end = q(mgr + 0xd8), q(mgr + 0xe0)
|
||||||
|
recs = [r for r in (q(beg + k*24 + 0x10) for k in range((end - beg)//24)) if r]
|
||||||
|
|
||||||
|
wire = {}
|
||||||
|
for p in SQUAD["players"]:
|
||||||
|
it = p.get("itemData") or {}
|
||||||
|
if it.get("id"):
|
||||||
|
wire[it["id"]] = it
|
||||||
|
|
||||||
|
# --- identify each record by its wire instance id ---
|
||||||
|
ident = {}
|
||||||
|
for rec in recs:
|
||||||
|
r = rd(rec, RECSZ)
|
||||||
|
for off in range(0, RECSZ - 4, 4):
|
||||||
|
v = struct.unpack_from("<I", r, off)[0]
|
||||||
|
if v in wire:
|
||||||
|
ident.setdefault(rec, (v, off))
|
||||||
|
break
|
||||||
|
print(f" resident player records: {len(recs)}, identified: {len(ident)}")
|
||||||
|
id_offs = collections.Counter(o for _, o in ident.values())
|
||||||
|
print(f" wire-id offset candidates: {[(hex(o), c) for o, c in id_offs.most_common()]}")
|
||||||
|
|
||||||
|
FIELDS = ("id", "resourceId", "assetId", "definitionId", "cardassetid", "rating",
|
||||||
|
"teamid", "nation", "leagueId", "contract", "fitness", "playStyle",
|
||||||
|
"discardValue", "cardsubtypeid", "owners", "rareflag")
|
||||||
|
# --- for every offset, does it hold field F for every identified record? ---
|
||||||
|
consistent = {}
|
||||||
|
for off in range(0, RECSZ - 4, 4):
|
||||||
|
for f in FIELDS:
|
||||||
|
ok = 0; total = 0; distinct = set()
|
||||||
|
for rec, (wid, _) in ident.items():
|
||||||
|
it = wire[wid]
|
||||||
|
v = it.get(f)
|
||||||
|
if not isinstance(v, int) or v < 16: # require distinctive values
|
||||||
|
continue
|
||||||
|
total += 1
|
||||||
|
got = struct.unpack_from("<I", rd(rec, RECSZ), off)[0]
|
||||||
|
if got == v:
|
||||||
|
ok += 1; distinct.add(v)
|
||||||
|
if total >= 5 and ok == total and len(distinct) >= 2:
|
||||||
|
consistent.setdefault(off, []).append((f, total, len(distinct)))
|
||||||
|
|
||||||
|
print(f"\n === offsets consistently holding a distinctive wire field ===")
|
||||||
|
for off in sorted(consistent):
|
||||||
|
for f, total, nd in consistent[off]:
|
||||||
|
print(f" +0x{off:<4x} {f:14s} (matched {total}/{total} records, {nd} distinct values)")
|
||||||
|
|
||||||
|
# --- dump the manager and the three club staff for comparison ---
|
||||||
|
print(f"\n === cardtype-2 slot (manager) ===")
|
||||||
|
h = q(mgr + 0xc0 + 0x10)
|
||||||
|
if h:
|
||||||
|
r = rd(h, RECSZ)
|
||||||
|
for off in sorted(consistent):
|
||||||
|
f = consistent[off][0][0]
|
||||||
|
print(f" +0x{off:<4x} {f:14s} = {struct.unpack_from('<I', r, off)[0]}")
|
||||||
|
for name, off, sz in (("cardtype", 0x4c, 4), ("cardsubtypeid", 0x50, 4),
|
||||||
|
("itemState", 0x5c, 4), ("category", 0x60, 4)):
|
||||||
|
print(f" +0x{off:<4x} {name:14s} = {struct.unpack_from('<i', r, off)[0]}")
|
||||||
Executable
+72
@@ -0,0 +1,72 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Enumerate FIFA 17's resident item map authoritatively.
|
||||||
|
|
||||||
|
Layout recovered from the lower_bound at 0x180119640:
|
||||||
|
owner+0x160c8 sentinel / end marker
|
||||||
|
owner+0x160d8 root
|
||||||
|
owner+0x160e8 count
|
||||||
|
node+0x00, node+0x08 children
|
||||||
|
node+0x20 key = wire instance id (qword)
|
||||||
|
node+0x28 the item record
|
||||||
|
On miss the client returns the static sentinel 0x1802c2a28 whose +0x10 is NULL.
|
||||||
|
|
||||||
|
Read-only. usage: probe_map2.py PID [id ...]
|
||||||
|
"""
|
||||||
|
import re, struct, sys, collections
|
||||||
|
|
||||||
|
PID = int(sys.argv[1]); WANT = {int(a) for a in sys.argv[2:]}
|
||||||
|
mem = open(f"/proc/{PID}/mem", "rb", buffering=0)
|
||||||
|
def rd(a, n):
|
||||||
|
mem.seek(a); return mem.read(n)
|
||||||
|
def q(a): return struct.unpack("<Q", rd(a, 8))[0]
|
||||||
|
named = []
|
||||||
|
for ln in open(f"/proc/{PID}/maps"):
|
||||||
|
m = re.match(r"([0-9a-f]+)-([0-9a-f]+) \S{4} \S+ \S+ \S+\s+(.+)", ln)
|
||||||
|
if m: named.append((int(m.group(1), 16), m.group(3).strip()))
|
||||||
|
named.sort()
|
||||||
|
base = next(s for s, p in named if p.endswith("CardsDLL_Win64_retail.dll"))
|
||||||
|
if rd(base + (0x180026fea - 0x180000000), 5) != bytes.fromhex("ba75750000"):
|
||||||
|
sys.exit("SANITY FAILED")
|
||||||
|
owner = q(base + (0x1802e6398 - 0x180000000))
|
||||||
|
SENT, ROOT, COUNT = owner + 0x160c8, q(owner + 0x160d8), q(owner + 0x160e8) & 0xffffffff
|
||||||
|
print(f" owner={owner:#x} sentinel={SENT:#x} root={ROOT:#x} count={COUNT}")
|
||||||
|
|
||||||
|
nodes, seen, stack = [], set(), [ROOT]
|
||||||
|
while stack:
|
||||||
|
n = stack.pop()
|
||||||
|
if not n or n == SENT or n in seen or len(seen) > 5000:
|
||||||
|
continue
|
||||||
|
seen.add(n)
|
||||||
|
try:
|
||||||
|
h = rd(n, 0x30)
|
||||||
|
except OSError:
|
||||||
|
continue
|
||||||
|
if len(h) < 0x30:
|
||||||
|
continue
|
||||||
|
nodes.append(n)
|
||||||
|
stack.append(struct.unpack_from("<Q", h, 0)[0])
|
||||||
|
stack.append(struct.unpack_from("<Q", h, 8)[0])
|
||||||
|
print(f" nodes reached: {len(nodes)} (count field says {COUNT})\n")
|
||||||
|
|
||||||
|
print(f" {'key':>11} {'record':>12} {'id':>10} {'resource':>10} {'ct':>3} {'sub':>4} {'st':>4} {'cat':>4}")
|
||||||
|
hist = collections.Counter(); found = {}
|
||||||
|
rows = []
|
||||||
|
for n in nodes:
|
||||||
|
key = q(n + 0x20)
|
||||||
|
rec = n + 0x28
|
||||||
|
try: r = rd(rec, 0x180)
|
||||||
|
except OSError: continue
|
||||||
|
if len(r) < 0x180: continue
|
||||||
|
g = lambda o: struct.unpack_from("<i", r, o)[0]
|
||||||
|
rid = struct.unpack_from("<I", r, 0x8)[0]
|
||||||
|
res = struct.unpack_from("<I", r, 0x18)[0]
|
||||||
|
ct, sub, st, cat = g(0x4c), g(0x50), g(0x5c), g(0x60)
|
||||||
|
hist[ct] += 1
|
||||||
|
if rid in WANT: found[rid] = rec
|
||||||
|
rows.append((key, rec, rid, res, ct, sub, st, cat))
|
||||||
|
for key, rec, rid, res, ct, sub, st, cat in sorted(rows):
|
||||||
|
tag = " <== CARDTYPE 7" if ct == 7 else (" <== WANTED" if rid in WANT else "")
|
||||||
|
print(f" {key:>11} {rec:#12x} {rid:>10} {res:>10} {ct:>3} {sub:>4} {st:>4} {cat:>4}{tag}")
|
||||||
|
print(f"\n cardtype histogram: {dict(sorted(hist.items()))} total={sum(hist.values())}")
|
||||||
|
for w in sorted(WANT):
|
||||||
|
print(f" id {w}: {'RESIDENT' if w in found else 'ABSENT'}")
|
||||||
Executable
+62
@@ -0,0 +1,62 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Read-only scan of the record pool embedded in the club-model owner object.
|
||||||
|
|
||||||
|
The 18 resident player records sit at a fixed stride of 0x180 inside the owner
|
||||||
|
object, below the embedded manager subobject at owner+0x1f9d8. This walks that
|
||||||
|
pool to see whether storage for the five club items exists and what it holds.
|
||||||
|
Read-only. Never writes.
|
||||||
|
"""
|
||||||
|
import re, struct, sys
|
||||||
|
|
||||||
|
PID = int(sys.argv[1])
|
||||||
|
mem = open(f"/proc/{PID}/mem", "rb", buffering=0)
|
||||||
|
|
||||||
|
def rd(a, n):
|
||||||
|
mem.seek(a); return mem.read(n)
|
||||||
|
def q(a):
|
||||||
|
return struct.unpack("<Q", rd(a, 8))[0]
|
||||||
|
|
||||||
|
named = []
|
||||||
|
for ln in open(f"/proc/{PID}/maps"):
|
||||||
|
m = re.match(r"([0-9a-f]+)-([0-9a-f]+) \S{4} \S+ \S+ \S+\s+(.+)", ln)
|
||||||
|
if m:
|
||||||
|
named.append((int(m.group(1), 16), m.group(3).strip()))
|
||||||
|
named.sort()
|
||||||
|
base = next(s for s, p in named if p.endswith("CardsDLL_Win64_retail.dll"))
|
||||||
|
def live(s):
|
||||||
|
return base + (s - 0x180000000)
|
||||||
|
|
||||||
|
owner = q(live(0x1802e6398))
|
||||||
|
mgr = owner + 0x1f9d8
|
||||||
|
beg, end = q(mgr + 0xd8), q(mgr + 0xe0)
|
||||||
|
first = None
|
||||||
|
for k in range((end - beg) // 24):
|
||||||
|
r = q(beg + k * 24 + 0x10)
|
||||||
|
if r:
|
||||||
|
first = r; break
|
||||||
|
if first is None:
|
||||||
|
sys.exit("no populated player record to anchor the pool")
|
||||||
|
|
||||||
|
print(f" owner = {owner:#x} mgr = {mgr:#x} first record = {first:#x}")
|
||||||
|
print(f" record - owner = {first - owner:#x} pool room to mgr = {(mgr - first) // 0x180} slots of 0x180")
|
||||||
|
print()
|
||||||
|
hdr = f" {'idx':>3} {'addr':>12} {'ctype':>6} {'subtyp':>6} {'state':>6} {'cat':>4} {'team':>5} {'kittyp':>6} set"
|
||||||
|
print(hdr)
|
||||||
|
n = (mgr - first) // 0x180
|
||||||
|
for k in range(min(n, 40)):
|
||||||
|
a = first + k * 0x180
|
||||||
|
try:
|
||||||
|
r = rd(a, 0xC0)
|
||||||
|
except OSError:
|
||||||
|
print(f" {k:>3} {a:#12x} unreadable"); break
|
||||||
|
if len(r) < 0xC0:
|
||||||
|
break
|
||||||
|
ct, sub, st, cat, team = (struct.unpack_from("<i", r, o)[0] for o in (0x4c, 0x50, 0x5c, 0x60, 0x94))
|
||||||
|
kt = struct.unpack_from("<H", r, 0xba)[0]
|
||||||
|
nz = sum(1 for b in r if b)
|
||||||
|
flag = ""
|
||||||
|
if ct == 7:
|
||||||
|
flag = " <== CARDTYPE 7"
|
||||||
|
elif nz == 0:
|
||||||
|
flag = " (all zero)"
|
||||||
|
print(f" {k:>3} {a:#12x} {ct:>6} {sub:>6} {st:>6} {cat:>4} {team:>5} {kt:>6} {nz:>3}/192{flag}")
|
||||||
+113
@@ -0,0 +1,113 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Read-only dump of RESIDENT record fields, for both the player and club-item vectors.
|
||||||
|
|
||||||
|
Purpose: the kit clone driver FUN_1801c3480 gates on record+0x60 (category) == 4.
|
||||||
|
No instruction in CardsDLL writes immediate 4 there, so this reads what value a
|
||||||
|
genuinely resident record actually carries. Read-only. Never writes.
|
||||||
|
|
||||||
|
mgr+0x0c0 cardtype-2 single slot
|
||||||
|
mgr+0x0d8..0x0e0 cardtype-1 (player) vector
|
||||||
|
mgr+0x108..0x110 club-item vector
|
||||||
|
record+0x4c cardtype +0x50 cardsubtypeid +0x5c itemState
|
||||||
|
record+0x60 category +0x94 teamid +0xba teamkittypetechid (u16)
|
||||||
|
"""
|
||||||
|
import re, struct, sys, collections
|
||||||
|
|
||||||
|
PID = int(sys.argv[1])
|
||||||
|
mem = open(f"/proc/{PID}/mem", "rb", buffering=0)
|
||||||
|
|
||||||
|
def rd(a, n):
|
||||||
|
mem.seek(a); return mem.read(n)
|
||||||
|
def q(a):
|
||||||
|
return struct.unpack("<Q", rd(a, 8))[0]
|
||||||
|
def i32(b, o):
|
||||||
|
return struct.unpack_from("<i", b, o)[0]
|
||||||
|
|
||||||
|
named = []
|
||||||
|
for ln in open(f"/proc/{PID}/maps"):
|
||||||
|
m = re.match(r"([0-9a-f]+)-([0-9a-f]+) \S{4} \S+ \S+ \S+\s+(.+)", ln)
|
||||||
|
if m:
|
||||||
|
named.append((int(m.group(1), 16), m.group(3).strip()))
|
||||||
|
named.sort()
|
||||||
|
base = next((s for s, p in named if p.endswith("CardsDLL_Win64_retail.dll")), None)
|
||||||
|
if base is None:
|
||||||
|
sys.exit("CardsDLL mapping not found")
|
||||||
|
def live(static):
|
||||||
|
return base + (static - 0x180000000)
|
||||||
|
|
||||||
|
if rd(live(0x180026fea), 5) != bytes.fromhex("ba75750000"):
|
||||||
|
sys.exit("SANITY FAILED - wrong base")
|
||||||
|
print(f" CardsDLL base = {base:#x} (sanity ok)")
|
||||||
|
|
||||||
|
owner = q(live(0x1802e6398))
|
||||||
|
b = rd(q(owner) + 0x4e8, 12)
|
||||||
|
b = rd(struct.unpack("<Q", struct.pack("<Q", q(q(owner) + 0x4e8)))[0], 12)
|
||||||
|
getter = q(q(owner) + 0x4e8)
|
||||||
|
gb = rd(getter, 12)
|
||||||
|
if gb[0:3] == bytes.fromhex("488d81"):
|
||||||
|
mgr = owner + struct.unpack_from("<I", gb, 3)[0]
|
||||||
|
elif gb[0:3] == bytes.fromhex("488d41"):
|
||||||
|
mgr = owner + gb[3]
|
||||||
|
else:
|
||||||
|
sys.exit(f"unexpected getter shape {gb.hex(' ')}")
|
||||||
|
print(f" owner = {owner:#x} mgr = {mgr:#x}")
|
||||||
|
|
||||||
|
FIELDS = ("ctype", "subtype", "state", "cat", "team", "kittype")
|
||||||
|
def decode(rec):
|
||||||
|
r = rd(rec, 0xC0)
|
||||||
|
if len(r) < 0xC0:
|
||||||
|
return None
|
||||||
|
return (i32(r, 0x4c), i32(r, 0x50), i32(r, 0x5c), i32(r, 0x60),
|
||||||
|
i32(r, 0x94), struct.unpack_from("<H", r, 0xba)[0])
|
||||||
|
|
||||||
|
for label, vbeg, vend in (("players (cardtype 1)", mgr + 0xd8, mgr + 0xe0),
|
||||||
|
("club items", mgr + 0x108, mgr + 0x110)):
|
||||||
|
try:
|
||||||
|
beg, end = q(vbeg), q(vend)
|
||||||
|
except OSError:
|
||||||
|
print(f"\n {label}: vector unreadable")
|
||||||
|
continue
|
||||||
|
span = end - beg
|
||||||
|
print(f"\n === {label}: {beg:#x}..{end:#x} span={span} ===")
|
||||||
|
if not (0 < beg <= end) or span > 24 * 100000:
|
||||||
|
print(" implausible vector, skipping")
|
||||||
|
continue
|
||||||
|
# resolve stride: the element must contain a plausible heap pointer
|
||||||
|
for stride, ptr_off in ((24, 0x10), (16, 0x08), (8, 0x00)):
|
||||||
|
if span % stride:
|
||||||
|
continue
|
||||||
|
n = span // stride
|
||||||
|
recs, nulls = [], []
|
||||||
|
ok = True
|
||||||
|
for k in range(n):
|
||||||
|
try:
|
||||||
|
rec = q(beg + k * stride + ptr_off)
|
||||||
|
except OSError:
|
||||||
|
ok = False; break
|
||||||
|
if not rec:
|
||||||
|
nulls.append(k); continue
|
||||||
|
d = decode(rec)
|
||||||
|
if d is None:
|
||||||
|
ok = False; break
|
||||||
|
recs.append((k, rec, d))
|
||||||
|
if not ok:
|
||||||
|
continue
|
||||||
|
print(f" stride {stride} (ptr at +{ptr_off:#x}): {n} slots, {len(recs)} populated, {len(nulls)} null")
|
||||||
|
if not recs and len(nulls) != n:
|
||||||
|
continue
|
||||||
|
hist = collections.Counter(d[0:2] for _, _, d in recs)
|
||||||
|
for key, c in sorted(hist.items(), key=lambda x: -x[1]):
|
||||||
|
print(f" (cardtype,subtype)={key} x{c}")
|
||||||
|
# The SLOT INDEX is load-bearing evidence: the squad parser's `actives`
|
||||||
|
# arm writes element i to slot `r15d + i`, and r15d is shared scratch
|
||||||
|
# that other atom handlers clobber. Which slots are filled therefore
|
||||||
|
# reveals the index the parse actually started from.
|
||||||
|
print(f" {'slot':>4} {'ptr':>14} " + " ".join(f"{f:>8}" for f in FIELDS))
|
||||||
|
for k, rec, d in recs[:8]:
|
||||||
|
print(f" {k:>4} {rec:#14x} " + " ".join(f"{v:>8}" for v in d))
|
||||||
|
if nulls:
|
||||||
|
print(f" empty slots: {nulls[:16]}")
|
||||||
|
cats = collections.Counter(d[3] for _, _, d in recs)
|
||||||
|
if cats:
|
||||||
|
print(f" CATEGORY (+0x60) distribution: {dict(cats)}")
|
||||||
|
break
|
||||||
Executable
+37
@@ -0,0 +1,37 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# Native proof for the FIFA 17 kit milestone: does the client now hold resident
|
||||||
|
# cardtype-7 records, and are the served kit ids among them?
|
||||||
|
#
|
||||||
|
# Auto-detects the live FIFA17.exe pid and walks the resident item map at
|
||||||
|
# owner+0x160c8 (root +0x160d8, key = wire instance id at node+0x20, record at
|
||||||
|
# node+0x28, count at owner+0x160e8). Read-only; never writes to the process.
|
||||||
|
#
|
||||||
|
# BEFORE this fix the map held 22 records with cardtype histogram {1:18, 2:1,
|
||||||
|
# 4:2, 10:1} and both kit ids ABSENT.
|
||||||
|
set -u
|
||||||
|
|
||||||
|
PID=$(for p in /proc/[0-9]*; do
|
||||||
|
[ "$(cat "$p/comm" 2>/dev/null)" = "FIFA17.exe" ] && echo "${p#/proc/}"
|
||||||
|
done | head -1)
|
||||||
|
|
||||||
|
if [ -z "$PID" ]; then
|
||||||
|
echo " FIFA17.exe is not running - launch the game and enter FUT first"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
echo " live FIFA17 pid = $PID"
|
||||||
|
echo
|
||||||
|
|
||||||
|
cd "$(dirname "$0")" || exit 1
|
||||||
|
python3 probe_map2.py "$PID" 100004873 100004874 100004870
|
||||||
|
|
||||||
|
echo
|
||||||
|
echo " ================ squad survival + slot indices ================"
|
||||||
|
# The kit milestone is only real if the REST of the squad survives with it.
|
||||||
|
# A populated `squad.actives` was once seen to leave the map holding just the
|
||||||
|
# 2 kits with a fully null 23-slot player vector and an empty starting 11, so
|
||||||
|
# the player-vector fill below is a PASS/FAIL gate, not decoration.
|
||||||
|
#
|
||||||
|
# The club-item slot indices are the other half: the parser writes element i to
|
||||||
|
# slot r15d+i, and r15d is scratch other atom handlers clobber. Kits landing
|
||||||
|
# somewhere other than slots 0 and 1 means the index did not start at zero.
|
||||||
|
python3 probe_resident_fields.py "$PID"
|
||||||
Executable
+225
@@ -0,0 +1,225 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Watch FIFA 17's resident club-item store and log every change, with timestamps.
|
||||||
|
|
||||||
|
Read-only. Waits for FIFA17.exe to appear, re-resolves the store each tick (the
|
||||||
|
manager is reallocated across logins), and appends one line per CHANGE so the
|
||||||
|
output can be aligned against the staging host's route log by wall clock.
|
||||||
|
|
||||||
|
Purpose: answer "after which response does a resident club item first appear?"
|
||||||
|
without reversing the constructor first. Pair with
|
||||||
|
|
||||||
|
journalctl -u openfut-staging-host --since <start> -o short-iso
|
||||||
|
|
||||||
|
and compare timestamps.
|
||||||
|
|
||||||
|
Usage: watch_residency.py [--interval 1.0] [--out /path/log] [--once]
|
||||||
|
"""
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import argparse
|
||||||
|
import collections
|
||||||
|
import os
|
||||||
|
import re
|
||||||
|
import struct
|
||||||
|
import sys
|
||||||
|
import time
|
||||||
|
|
||||||
|
CARDS_DLL = "CardsDLL_Win64_retail.dll"
|
||||||
|
OWNER_GLOBAL = 0x1802E6398 # FUN_18011a830: mov rax,[this]; ret
|
||||||
|
SANITY_VA = 0x180026FEA # mov edx,0x7575
|
||||||
|
SANITY_BYTES = bytes.fromhex("ba75750000")
|
||||||
|
IMAGE_BASE = 0x180000000
|
||||||
|
|
||||||
|
# item-record offsets, all previously proven (see Vault: Kit Selector APT Decode)
|
||||||
|
OFF = {"cardtype": 0x4C, "cardsubtypeid": 0x50, "itemState": 0x5C,
|
||||||
|
"category": 0x60, "teamid": 0x94}
|
||||||
|
OFF_KITTYPE_U16 = 0xBA
|
||||||
|
|
||||||
|
|
||||||
|
class Target:
|
||||||
|
"""One live FIFA17.exe, with the store chain resolved."""
|
||||||
|
|
||||||
|
def __init__(self, pid: int):
|
||||||
|
self.pid = pid
|
||||||
|
self.mem = open(f"/proc/{pid}/mem", "rb", buffering=0)
|
||||||
|
self.base = self._cards_base()
|
||||||
|
if self.base is None:
|
||||||
|
raise RuntimeError("CardsDLL mapping not found")
|
||||||
|
probe = self.rd(self.live(SANITY_VA), 5)
|
||||||
|
if probe != SANITY_BYTES:
|
||||||
|
raise RuntimeError(f"base sanity failed: {probe.hex(' ')}")
|
||||||
|
owner = self.q(self.live(OWNER_GLOBAL))
|
||||||
|
if not owner:
|
||||||
|
raise RuntimeError("owner object is null (not logged in yet)")
|
||||||
|
vt = self.q(owner)
|
||||||
|
getter = self.q(vt + 0x4E8)
|
||||||
|
b = self.rd(getter, 8)
|
||||||
|
# lea rax,[rcx+imm32] ; ret / lea rax,[rcx+imm8] ; ret
|
||||||
|
if b[0:3] == bytes.fromhex("488d81"):
|
||||||
|
self.mgr = owner + struct.unpack_from("<I", b, 3)[0]
|
||||||
|
elif b[0:3] == bytes.fromhex("488d41"):
|
||||||
|
self.mgr = owner + b[3]
|
||||||
|
elif b[0:3] == bytes.fromhex("488b81"):
|
||||||
|
self.mgr = self.q(owner + struct.unpack_from("<I", b, 3)[0])
|
||||||
|
else:
|
||||||
|
raise RuntimeError(f"unrecognised getter: {b.hex(' ')}")
|
||||||
|
|
||||||
|
# -- raw access ------------------------------------------------------
|
||||||
|
def rd(self, a: int, n: int) -> bytes:
|
||||||
|
self.mem.seek(a)
|
||||||
|
return self.mem.read(n)
|
||||||
|
|
||||||
|
def q(self, a: int) -> int:
|
||||||
|
return struct.unpack("<Q", self.rd(a, 8))[0]
|
||||||
|
|
||||||
|
def live(self, static: int) -> int:
|
||||||
|
return self.base + (static - IMAGE_BASE)
|
||||||
|
|
||||||
|
def _cards_base(self):
|
||||||
|
named = []
|
||||||
|
for ln in open(f"/proc/{self.pid}/maps"):
|
||||||
|
m = re.match(r"([0-9a-f]+)-([0-9a-f]+) \S{4} \S+ \S+ \S+\s+(.+)", ln)
|
||||||
|
if m:
|
||||||
|
named.append((int(m.group(1), 16), m.group(3).strip()))
|
||||||
|
# NEAREST PRECEDING NAMED mapping: Wine maps PE sections anonymously and
|
||||||
|
# the Wine heap is also rwx, so permissions cannot identify a module.
|
||||||
|
for start, path in sorted(named):
|
||||||
|
if path.endswith(CARDS_DLL):
|
||||||
|
return start
|
||||||
|
return None
|
||||||
|
|
||||||
|
# -- the store -------------------------------------------------------
|
||||||
|
def vector(self, off_begin: int):
|
||||||
|
beg, end = self.q(self.mgr + off_begin), self.q(self.mgr + off_begin + 8)
|
||||||
|
if not (0 < beg <= end) or (end - beg) % 24 or (end - beg) > 24 * 200000:
|
||||||
|
return None, 0
|
||||||
|
return beg, (end - beg) // 24
|
||||||
|
|
||||||
|
def records(self, off_begin: int):
|
||||||
|
beg, n = self.vector(off_begin)
|
||||||
|
out = []
|
||||||
|
if beg is None:
|
||||||
|
return out
|
||||||
|
for k in range(n):
|
||||||
|
try:
|
||||||
|
rec = self.q(beg + k * 24 + 0x10)
|
||||||
|
except OSError:
|
||||||
|
continue
|
||||||
|
if not rec:
|
||||||
|
out.append(None)
|
||||||
|
continue
|
||||||
|
try:
|
||||||
|
r = self.rd(rec, 0xC0)
|
||||||
|
except OSError:
|
||||||
|
out.append(None)
|
||||||
|
continue
|
||||||
|
if len(r) < 0xC0:
|
||||||
|
out.append(None)
|
||||||
|
continue
|
||||||
|
f = {k2: struct.unpack_from("<i", r, v)[0] for k2, v in OFF.items()}
|
||||||
|
f["teamkittypetechid"] = struct.unpack_from("<H", r, OFF_KITTYPE_U16)[0]
|
||||||
|
f["ptr"] = rec
|
||||||
|
out.append(f)
|
||||||
|
return out
|
||||||
|
|
||||||
|
def snapshot(self) -> dict:
|
||||||
|
club = self.records(0x108)
|
||||||
|
players = self.records(0xD8)
|
||||||
|
hist = collections.Counter(
|
||||||
|
(r["cardtype"], r["cardsubtypeid"]) for r in club if r
|
||||||
|
)
|
||||||
|
return {
|
||||||
|
"club_slots": len(club),
|
||||||
|
"club_filled": sum(1 for r in club if r),
|
||||||
|
"club_hist": dict(hist),
|
||||||
|
"club_records": [r for r in club if r],
|
||||||
|
"player_slots": len(players),
|
||||||
|
"player_filled": sum(1 for r in players if r),
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
def find_pid() -> int | None:
|
||||||
|
for d in os.listdir("/proc"):
|
||||||
|
if not d.isdigit():
|
||||||
|
continue
|
||||||
|
try:
|
||||||
|
with open(f"/proc/{d}/comm") as f:
|
||||||
|
if f.read().strip() == "FIFA17.exe":
|
||||||
|
return int(d)
|
||||||
|
except OSError:
|
||||||
|
continue
|
||||||
|
return None
|
||||||
|
|
||||||
|
|
||||||
|
def fmt(snap: dict) -> str:
|
||||||
|
parts = [
|
||||||
|
f"club={snap['club_filled']}/{snap['club_slots']}",
|
||||||
|
f"players={snap['player_filled']}/{snap['player_slots']}",
|
||||||
|
]
|
||||||
|
if snap["club_hist"]:
|
||||||
|
parts.append("hist=" + ",".join(
|
||||||
|
f"(ct{a},st{b})x{c}" for (a, b), c in sorted(snap["club_hist"].items())))
|
||||||
|
for r in snap["club_records"]:
|
||||||
|
parts.append(
|
||||||
|
"KIT[" if (r["cardtype"], r["cardsubtypeid"]) == (7, 9) else "rec[")
|
||||||
|
parts[-1] += (f"ptr={r['ptr']:#x} ct={r['cardtype']} st={r['cardsubtypeid']} "
|
||||||
|
f"state={r['itemState']} cat={r['category']} "
|
||||||
|
f"team={r['teamid']} kittype={r['teamkittypetechid']}]")
|
||||||
|
return " ".join(parts)
|
||||||
|
|
||||||
|
|
||||||
|
def main() -> int:
|
||||||
|
ap = argparse.ArgumentParser()
|
||||||
|
ap.add_argument("--interval", type=float, default=1.0)
|
||||||
|
ap.add_argument("--out", default="/home/alex/openfut-live/residency.log")
|
||||||
|
ap.add_argument("--once", action="store_true")
|
||||||
|
a = ap.parse_args()
|
||||||
|
|
||||||
|
sink = sys.stdout if a.out == "-" else open(a.out, "a", buffering=1)
|
||||||
|
|
||||||
|
def emit(msg: str) -> None:
|
||||||
|
line = f"{time.strftime('%Y-%m-%dT%H:%M:%S%z')} {msg}"
|
||||||
|
print(line, file=sink)
|
||||||
|
if sink is not sys.stdout:
|
||||||
|
print(line, flush=True)
|
||||||
|
|
||||||
|
emit("watch: start")
|
||||||
|
target = None
|
||||||
|
last = None
|
||||||
|
while True:
|
||||||
|
if target is None:
|
||||||
|
pid = find_pid()
|
||||||
|
if pid is None:
|
||||||
|
if a.once:
|
||||||
|
emit("watch: no FIFA17.exe"); return 1
|
||||||
|
time.sleep(a.interval); continue
|
||||||
|
try:
|
||||||
|
target = Target(pid)
|
||||||
|
emit(f"watch: attached pid={pid} cardsdll={target.base:#x} "
|
||||||
|
f"mgr={target.mgr:#x}")
|
||||||
|
last = None
|
||||||
|
except (OSError, RuntimeError) as e:
|
||||||
|
# not logged in yet, or the process died mid-resolve
|
||||||
|
if a.once:
|
||||||
|
emit(f"watch: not ready: {e}"); return 1
|
||||||
|
target = None
|
||||||
|
time.sleep(a.interval); continue
|
||||||
|
try:
|
||||||
|
snap = target.snapshot()
|
||||||
|
except (OSError, struct.error) as e:
|
||||||
|
emit(f"watch: detached ({e})")
|
||||||
|
target = None
|
||||||
|
if a.once:
|
||||||
|
return 1
|
||||||
|
continue
|
||||||
|
key = fmt(snap)
|
||||||
|
if key != last:
|
||||||
|
emit(key)
|
||||||
|
last = key
|
||||||
|
if a.once:
|
||||||
|
return 0
|
||||||
|
time.sleep(a.interval)
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
sys.exit(main())
|
||||||
Executable
+100
@@ -0,0 +1,100 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
# -*- coding: utf-8 -*-
|
||||||
|
"""Read back the MANAGER-ONLY chemistry slots the client resolved, and prove
|
||||||
|
whether the server's `nation`/`leagueId` actually land in the record.
|
||||||
|
|
||||||
|
READ-ONLY. /proc/PID/mem is opened 'rb'; there is no write path in this file.
|
||||||
|
|
||||||
|
WHY THIS EXISTS
|
||||||
|
---------------
|
||||||
|
`card_identity_probe` reads the PLAYER slots (F_NATION = 0x148, F_LEAGUE =
|
||||||
|
0x154). A manager does not use those, so grading a manager with that tool
|
||||||
|
reports nation=0 / leagueId=0 and looks like a server bug when it is only the
|
||||||
|
wrong offsets.
|
||||||
|
|
||||||
|
`fifa17-recon/tools/fut_staff.py` records the manager layout from Ghidra:
|
||||||
|
|
||||||
|
rec+0x94 teamid (read by the card view-model)
|
||||||
|
rec+0xde nation MANAGER-ONLY slot, u16
|
||||||
|
rec+0xe0 leagueId MANAGER-ONLY slot, u16
|
||||||
|
rec+0xe2 talkrating written by the managercards merge
|
||||||
|
rec+0xe3 negotiation written by the managercards merge
|
||||||
|
|
||||||
|
The merge (FUN_1801356c0) NEVER writes +0xde or +0xe0, so whatever sits there
|
||||||
|
came from OUR JSON and nowhere else. That makes those two u16s a direct,
|
||||||
|
unambiguous test of the server's manager chemistry fields: if they read back as
|
||||||
|
the values we served, the wire contract is PROVEN rather than inferred; if they
|
||||||
|
read zero, the client discarded them and manager chemistry cannot be rendering.
|
||||||
|
|
||||||
|
Usage: python3 manager_chem_probe.py # grade every manager in the map
|
||||||
|
"""
|
||||||
|
import sys
|
||||||
|
|
||||||
|
import watch_club_model as W
|
||||||
|
import card_identity_probe as P
|
||||||
|
|
||||||
|
MANAGER_CARDTYPE = 2 # FUN_1800d8330: cardsubtypeid 4 -> cardtype 2
|
||||||
|
F_CARDTYPE = 0x4C
|
||||||
|
F_RESOURCE = 0x18
|
||||||
|
F_TEAMID = 0x94
|
||||||
|
F_NATION_MGR = 0xDE
|
||||||
|
F_LEAGUE_MGR = 0xE0
|
||||||
|
F_TALKRATING = 0xE2
|
||||||
|
F_NEGOTIATION = 0xE3
|
||||||
|
REC_SIZE = 0x158
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
pid = W.find_pid()
|
||||||
|
if pid is None:
|
||||||
|
print("FIFA17.exe is not running.")
|
||||||
|
return 1
|
||||||
|
base = W.dll_base(pid)
|
||||||
|
if base is None:
|
||||||
|
print("pid %d is up but %s is not mapped yet." % (pid, W.DLL))
|
||||||
|
return 1
|
||||||
|
mem = W.Mem(pid)
|
||||||
|
obj = mem.q(base + (W.G_CARDSDB - W.IMG_BASE))
|
||||||
|
if not obj:
|
||||||
|
print("CardsDb singleton is NULL (no FUT session loaded).")
|
||||||
|
return 1
|
||||||
|
|
||||||
|
ns = W.nodes(mem, obj) if hasattr(W, "nodes") else P.nodes(mem, obj)
|
||||||
|
print("pid=%d CardsDb=%#x walked=%d" % (pid, obj, len(ns)))
|
||||||
|
print()
|
||||||
|
print("%-10s %-8s %-8s %-8s %-10s %-10s %s"
|
||||||
|
% ("resource", "teamid", "nation", "league", "talkrating", "negot", "verdict"))
|
||||||
|
|
||||||
|
found = 0
|
||||||
|
for n in ns:
|
||||||
|
rec = n + 0x28
|
||||||
|
buf = mem.read(rec, REC_SIZE)
|
||||||
|
if not buf or len(buf) < REC_SIZE:
|
||||||
|
continue
|
||||||
|
if P.u8(buf, F_CARDTYPE) != MANAGER_CARDTYPE:
|
||||||
|
continue
|
||||||
|
found += 1
|
||||||
|
resource = P.u32(buf, F_RESOURCE)
|
||||||
|
teamid = P.u32(buf, F_TEAMID)
|
||||||
|
nation = P.u16(buf, F_NATION_MGR)
|
||||||
|
league = P.u16(buf, F_LEAGUE_MGR)
|
||||||
|
talk = P.u8(buf, F_TALKRATING)
|
||||||
|
negot = P.u8(buf, F_NEGOTIATION)
|
||||||
|
# +0xde and +0xe0 are never written by the merge, so a non-zero value
|
||||||
|
# can only have come from the server's JSON.
|
||||||
|
if nation and league:
|
||||||
|
verdict = "SERVER FIELDS LANDED"
|
||||||
|
elif nation or league:
|
||||||
|
verdict = "PARTIAL -- one slot empty"
|
||||||
|
else:
|
||||||
|
verdict = "EMPTY -- client kept nothing we sent"
|
||||||
|
print("%-10d %-8d %-8d %-8d %-10d %-10d %s"
|
||||||
|
% (resource, teamid, nation, league, talk, negot, verdict))
|
||||||
|
|
||||||
|
if not found:
|
||||||
|
print("(no manager record in the map -- the client has not been served one)")
|
||||||
|
return 0
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
sys.exit(main())
|
||||||
@@ -32,11 +32,26 @@ c() { printf ' %s\n' "$*"; }
|
|||||||
up() { ss -tlnp 2>/dev/null | grep -q ":$1 "; }
|
up() { ss -tlnp 2>/dev/null | grep -q ":$1 "; }
|
||||||
|
|
||||||
ensure_cert() {
|
ensure_cert() {
|
||||||
[ -s "$CERT" ] && [ -s "$KEY" ] && return 0
|
# The cert MUST carry the address the client dials in its SAN, or the roster
|
||||||
echo "[*] generating self-signed TLS cert (redirector MITM; ProtoSSL verify is patched)"
|
# HTTPS handshake is rejected with fatal certificate_unknown and the FUT hub
|
||||||
|
# fails to load (docs/FIFA17_FUT_SQUAD_UPDATE_TLS.md): the client dials the
|
||||||
|
# roster/redirector by IP and that path validates the SAN against it. Default to
|
||||||
|
# this host's primary LAN IP so a client on another machine works;
|
||||||
|
# OPENFUT_ADVERTISE overrides. Reissue when absent OR when the current cert lacks
|
||||||
|
# that IP, so this self-heals rather than serving a stale DNS-only cert.
|
||||||
|
local adv ip_sans regen=0
|
||||||
|
adv="${OPENFUT_ADVERTISE:-$(ip route get 1.1.1.1 2>/dev/null | awk '{print $7; exit}')}"
|
||||||
|
ip_sans="IP:127.0.0.1"; [ -n "$adv" ] && ip_sans="IP:$adv,IP:127.0.0.1"
|
||||||
|
if [ ! -s "$CERT" ] || [ ! -s "$KEY" ]; then
|
||||||
|
regen=1
|
||||||
|
elif [ -n "$adv" ] && ! openssl x509 -in "$CERT" -noout -ext subjectAltName 2>/dev/null | grep -qF "IP Address:$adv"; then
|
||||||
|
regen=1
|
||||||
|
fi
|
||||||
|
[ "$regen" = 0 ] && return 0
|
||||||
|
echo "[*] issuing self-signed TLS cert (SAN includes $ip_sans; redirector MITM; ProtoSSL verify is patched)"
|
||||||
openssl req -x509 -newkey rsa:2048 -nodes -keyout "$KEY" -out "$CERT" -days 3650 \
|
openssl req -x509 -newkey rsa:2048 -nodes -keyout "$KEY" -out "$CERT" -days 3650 \
|
||||||
-subj "/CN=winter15.gosredirector.ea.com" \
|
-subj "/CN=winter15.gosredirector.ea.com" \
|
||||||
-addext "subjectAltName=DNS:winter15.gosredirector.ea.com,DNS:*.gosredirector.ea.com,DNS:*.ea.com,IP:127.0.0.1" \
|
-addext "subjectAltName=DNS:winter15.gosredirector.ea.com,DNS:*.gosredirector.ea.com,DNS:*.ea.com,$ip_sans" \
|
||||||
>/dev/null 2>&1
|
>/dev/null 2>&1
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Executable
+107
@@ -0,0 +1,107 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
# -*- coding: utf-8 -*-
|
||||||
|
"""Dump the CLASSIFICATION fields the client stored for every card it holds, so
|
||||||
|
the subtype->cardtype map and the itemState runtime values are read from the
|
||||||
|
running game instead of inferred.
|
||||||
|
|
||||||
|
READ-ONLY. /proc/PID/mem is opened 'rb'; there is no write path in this file.
|
||||||
|
|
||||||
|
WHY THIS EXISTS
|
||||||
|
---------------
|
||||||
|
Two things this project has repeatedly had to treat as INFERRED:
|
||||||
|
|
||||||
|
1. `FUN_1800d8330`'s cardsubtypeid -> cardtype map. It is read out of Ghidra
|
||||||
|
(0..3->1 players, 4->2 manager, 5->3 headcoach, 6->10 gkcoach, 7->5 physio,
|
||||||
|
8->4 fitnesscoach, 9..b->7), and the kit selector gate `FUN_1801c3480`
|
||||||
|
branches on cardtype == 7. Serving a subtype whose cardtype we guessed
|
||||||
|
wrong fails SILENTLY, because cardtype 9 has no arm in the merge.
|
||||||
|
2. The itemState enum. The table at 0x180229d20 gives the tokens; the RUNTIME
|
||||||
|
values the strings deserialize to (notably activeHomeKit/activeAwayKit ->
|
||||||
|
101/102) have been carried as inferred.
|
||||||
|
|
||||||
|
Both are directly observable: the parser writes cardsubtypeid to rec+0x50, the
|
||||||
|
derived cardtype to rec+0x4c, and the decoded itemState to rec+0x5c. Reading
|
||||||
|
those back for every record turns the pair into measurements.
|
||||||
|
|
||||||
|
rec+0x18 resourceId
|
||||||
|
rec+0x4c cardtype (derived by FUN_1800d8330 from cardsubtypeid)
|
||||||
|
rec+0x50 cardsubtypeid (as sent)
|
||||||
|
rec+0x5c itemState (decoded enum value)
|
||||||
|
|
||||||
|
Usage: python3 record_vocab_probe.py
|
||||||
|
"""
|
||||||
|
import collections
|
||||||
|
import sys
|
||||||
|
|
||||||
|
import watch_club_model as W
|
||||||
|
import card_identity_probe as P
|
||||||
|
|
||||||
|
F_RESOURCE = 0x18
|
||||||
|
F_CARDTYPE = 0x4C
|
||||||
|
F_SUBTYPE = 0x50
|
||||||
|
F_ITEMSTATE = 0x5C
|
||||||
|
REC_SIZE = 0x158
|
||||||
|
|
||||||
|
# What the Ghidra read of FUN_1800d8330 predicts, so a disagreement is loud.
|
||||||
|
EXPECTED_CARDTYPE = {0: 1, 1: 1, 2: 1, 3: 1, 4: 2, 5: 3, 6: 10, 7: 5, 8: 4,
|
||||||
|
9: 7, 10: 7, 11: 7}
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
pid = W.find_pid()
|
||||||
|
if pid is None:
|
||||||
|
print("FIFA17.exe is not running.")
|
||||||
|
return 1
|
||||||
|
base = W.dll_base(pid)
|
||||||
|
if base is None:
|
||||||
|
print("pid %d is up but %s is not mapped yet." % (pid, W.DLL))
|
||||||
|
return 1
|
||||||
|
mem = W.Mem(pid)
|
||||||
|
obj = mem.q(base + (W.G_CARDSDB - W.IMG_BASE))
|
||||||
|
if not obj:
|
||||||
|
print("CardsDb singleton is NULL (no FUT session loaded).")
|
||||||
|
return 1
|
||||||
|
|
||||||
|
ns = W.nodes(mem, obj) if hasattr(W, "nodes") else P.nodes(mem, obj)
|
||||||
|
print("pid=%d CardsDb=%#x walked=%d\n" % (pid, obj, len(ns)))
|
||||||
|
|
||||||
|
pairs = collections.Counter()
|
||||||
|
states = collections.Counter()
|
||||||
|
rows = []
|
||||||
|
for n in ns:
|
||||||
|
buf = mem.read(n + 0x28, REC_SIZE)
|
||||||
|
if not buf or len(buf) < REC_SIZE:
|
||||||
|
continue
|
||||||
|
resource = P.u32(buf, F_RESOURCE)
|
||||||
|
cardtype = P.u8(buf, F_CARDTYPE)
|
||||||
|
subtype = P.u8(buf, F_SUBTYPE)
|
||||||
|
state = P.u8(buf, F_ITEMSTATE)
|
||||||
|
pairs[(subtype, cardtype)] += 1
|
||||||
|
states[state] += 1
|
||||||
|
rows.append((resource, subtype, cardtype, state))
|
||||||
|
|
||||||
|
print("%-12s %-9s %-9s %s" % ("resource", "subtype", "cardtype", "itemState"))
|
||||||
|
for r in sorted(rows):
|
||||||
|
print("%-12d %-9d %-9d %d" % r)
|
||||||
|
|
||||||
|
print("\n--- MEASURED cardsubtypeid -> cardtype ---")
|
||||||
|
for (sub, ct), n in sorted(pairs.items()):
|
||||||
|
want = EXPECTED_CARDTYPE.get(sub)
|
||||||
|
if want is None:
|
||||||
|
verdict = "no Ghidra prediction for this subtype"
|
||||||
|
elif want == ct:
|
||||||
|
verdict = "agrees with FUN_1800d8330"
|
||||||
|
else:
|
||||||
|
verdict = "DISAGREES -- Ghidra said %d" % want
|
||||||
|
print(" subtype %-4d -> cardtype %-4d (%d record(s)) %s" % (sub, ct, n, verdict))
|
||||||
|
|
||||||
|
print("\n--- MEASURED itemState runtime values ---")
|
||||||
|
for st, n in sorted(states.items()):
|
||||||
|
print(" %-5d %d record(s)" % (st, n))
|
||||||
|
print("\nNOTE: a runtime value only appears here if the client was actually")
|
||||||
|
print("served an item in that state. Absence is not evidence of absence.")
|
||||||
|
return 0
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
sys.exit(main())
|
||||||
@@ -0,0 +1,76 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Dump CardsDLL's 45-row route table from the ON-DISK PE. READ-ONLY, static.
|
||||||
|
|
||||||
|
The transfer-market analysis locates the table at .rdata 0x18021df80 as
|
||||||
|
{char*, char*} rows. This resolves VA->file offset properly through the PE section
|
||||||
|
table rather than assuming a single .text mapping, then prints every row so we can
|
||||||
|
see whether any route other than `tradePile` could own a trade-pile ITEM list.
|
||||||
|
"""
|
||||||
|
import struct, sys
|
||||||
|
|
||||||
|
DLL = "/mnt/games/FIFA 17/CardsDLL_Win64_retail.dll"
|
||||||
|
TABLE_VA = 0x18021DF80
|
||||||
|
MAX_ROWS = 64
|
||||||
|
|
||||||
|
pe = open(DLL, "rb").read()
|
||||||
|
e_lfanew = struct.unpack_from("<I", pe, 0x3C)[0]
|
||||||
|
assert pe[e_lfanew:e_lfanew + 4] == b"PE\0\0", "not a PE"
|
||||||
|
coff = e_lfanew + 4
|
||||||
|
nsec, opt_size = struct.unpack_from("<HH", pe, coff + 2), None
|
||||||
|
num_sections = struct.unpack_from("<H", pe, coff + 2)[0]
|
||||||
|
opt_size = struct.unpack_from("<H", pe, coff + 16)[0]
|
||||||
|
opt = coff + 20
|
||||||
|
magic = struct.unpack_from("<H", pe, opt)[0]
|
||||||
|
assert magic == 0x20B, "expected PE32+"
|
||||||
|
image_base = struct.unpack_from("<Q", pe, opt + 24)[0]
|
||||||
|
sec_off = opt + opt_size
|
||||||
|
|
||||||
|
sections = []
|
||||||
|
for i in range(num_sections):
|
||||||
|
b = sec_off + i * 40
|
||||||
|
name = pe[b:b + 8].rstrip(b"\0").decode("ascii", "replace")
|
||||||
|
vsize, vaddr, rawsize, rawptr = struct.unpack_from("<IIII", pe, b + 8)
|
||||||
|
sections.append((name, vaddr, vsize, rawptr, rawsize))
|
||||||
|
|
||||||
|
print("image_base=%#x sections=%d" % (image_base, num_sections))
|
||||||
|
for s in sections:
|
||||||
|
print(" %-8s rva=%#010x vsize=%#x rawptr=%#010x rawsize=%#x" % s)
|
||||||
|
|
||||||
|
|
||||||
|
def va2off(va):
|
||||||
|
rva = va - image_base
|
||||||
|
for name, vaddr, vsize, rawptr, rawsize in sections:
|
||||||
|
if vaddr <= rva < vaddr + max(vsize, rawsize):
|
||||||
|
off = rva - vaddr + rawptr
|
||||||
|
if off < len(pe):
|
||||||
|
return off
|
||||||
|
return None
|
||||||
|
|
||||||
|
|
||||||
|
def cstr(va, limit=96):
|
||||||
|
off = va2off(va)
|
||||||
|
if off is None:
|
||||||
|
return None
|
||||||
|
end = pe.find(b"\0", off, off + limit)
|
||||||
|
if end < 0:
|
||||||
|
return None
|
||||||
|
try:
|
||||||
|
return pe[off:end].decode("ascii")
|
||||||
|
except UnicodeDecodeError:
|
||||||
|
return None
|
||||||
|
|
||||||
|
|
||||||
|
base = va2off(TABLE_VA)
|
||||||
|
print("\nroute table VA %#x -> file offset %s" % (TABLE_VA, hex(base) if base else None))
|
||||||
|
assert base, "table VA did not resolve"
|
||||||
|
|
||||||
|
print("\n%-4s %-34s %s" % ("#", "field A", "field B"))
|
||||||
|
rows = 0
|
||||||
|
for i in range(MAX_ROWS):
|
||||||
|
a_va, b_va = struct.unpack_from("<QQ", pe, base + i * 16)
|
||||||
|
a, b = cstr(a_va), cstr(b_va)
|
||||||
|
if a is None and b is None:
|
||||||
|
print("-- table ends after %d rows --" % rows)
|
||||||
|
break
|
||||||
|
print("%-4d %-34s %s" % (i, repr(a), repr(b)))
|
||||||
|
rows += 1
|
||||||
Executable
+161
@@ -0,0 +1,161 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
# -*- coding: utf-8 -*-
|
||||||
|
"""Resolve the runtime string comparator behind `DAT_1802ddfd8 + 0x248`, and
|
||||||
|
settle whether the `itemState` match is case-sensitive.
|
||||||
|
|
||||||
|
READ-ONLY. /proc/PID/mem is opened 'rb'; there is no write path in this file.
|
||||||
|
|
||||||
|
WHY THIS EXISTS
|
||||||
|
---------------
|
||||||
|
`itemState` arrives on the wire as a STRING ("free", "activeHomeKit", ...) and
|
||||||
|
the client turns it into its runtime enum by comparing that string against its
|
||||||
|
own table. The compare goes through `FUN_180008190`, whose whole body is:
|
||||||
|
|
||||||
|
mov rax, [DAT_1802ddfd8] ; the service object, populated at runtime
|
||||||
|
mov r9, [rax + 0x248] ; slot 0x248
|
||||||
|
jmp r9 ; tail-jump
|
||||||
|
|
||||||
|
The slot is empty on disk, so `plan-2026-08-06-card-subsystem.md` section 5
|
||||||
|
recorded the casing question as "almost certainly unresolvable statically" and
|
||||||
|
listed this as a read-only live probe. It is worth answering: every shaper in
|
||||||
|
openfut-adapter-fifa17 emits these tokens, and if the comparator folded case then
|
||||||
|
our table's casing would be a convention rather than a contract.
|
||||||
|
|
||||||
|
WHAT IT DOES
|
||||||
|
------------
|
||||||
|
Reads the slot in the live process and follows the forwarding chain
|
||||||
|
(`e9` rel32 thunk -> `ff 25` IAT jump -> body), attributing each hop to a module.
|
||||||
|
Wine maps PE images as anonymous, so a mapping's own path is usually empty; the
|
||||||
|
module is recovered from the nearest PRECEDING named mapping, which is the PE
|
||||||
|
header page.
|
||||||
|
|
||||||
|
At the body it decides case sensitivity from the instruction stream rather than
|
||||||
|
from a symbol name: a case-insensitive comparator MUST fold case, so it carries
|
||||||
|
an `or ..,0x20` / lowercase-table lookup. A byte compare with no folding is
|
||||||
|
case-SENSITIVE.
|
||||||
|
|
||||||
|
MEASURED 2026-08-21 (pid 6580):
|
||||||
|
slot -> 0x146d1c020 (thunk) -> 0x145e27fe0 (IAT) -> msvcr120.dll + 0x3c330
|
||||||
|
body is strncmp: `sub rdx,rcx` / `test r8,r8` (count) / `test al,al` (NUL) /
|
||||||
|
`cmp al,[rcx+rdx]` with NO case folding, plus the MSVC NUL-detect constants
|
||||||
|
0x8080808080808080 and 0xfefefefefefefeff.
|
||||||
|
=> the itemState match is CASE-SENSITIVE. Emit the table's exact casing.
|
||||||
|
|
||||||
|
Usage: python3 service_ptr_probe.py
|
||||||
|
"""
|
||||||
|
import re
|
||||||
|
import struct
|
||||||
|
import sys
|
||||||
|
|
||||||
|
import watch_club_model as W
|
||||||
|
|
||||||
|
DAT_SERVICE = 0x1802DDFD8
|
||||||
|
SLOT = 0x248
|
||||||
|
MAX_HOPS = 8
|
||||||
|
|
||||||
|
# A case-insensitive comparator has to fold case somewhere. These are the two
|
||||||
|
# ways MSVC does it; neither appears in a plain strcmp/strncmp/memcmp.
|
||||||
|
FOLD_OR_IMM8 = b"\x0c\x20" # or al, 0x20
|
||||||
|
FOLD_OR_EAX = b"\x83\xc8\x20" # or eax, 0x20
|
||||||
|
|
||||||
|
|
||||||
|
def mappings(pid):
|
||||||
|
out = []
|
||||||
|
with open("/proc/%d/maps" % pid) as fh:
|
||||||
|
for line in fh:
|
||||||
|
m = re.match(r"([0-9a-f]+)-([0-9a-f]+) (\S{4}) \S+ \S+ \S+\s*(.*)", line)
|
||||||
|
if m:
|
||||||
|
out.append((int(m.group(1), 16), int(m.group(2), 16), m.group(3), m.group(4)))
|
||||||
|
return out
|
||||||
|
|
||||||
|
|
||||||
|
def attribute(maps, va):
|
||||||
|
"""(module_path, perms, offset_from_module_base) for `va`.
|
||||||
|
|
||||||
|
Wine maps PE sections anonymously, so the owning mapping usually has no
|
||||||
|
path; the module is the nearest preceding NAMED mapping (its header page).
|
||||||
|
"""
|
||||||
|
named = None
|
||||||
|
for start, end, perms, path in maps:
|
||||||
|
if path:
|
||||||
|
named = (start, path)
|
||||||
|
if start <= va < end:
|
||||||
|
if named:
|
||||||
|
return named[1], perms, va - named[0]
|
||||||
|
return path or "[anonymous]", perms, None
|
||||||
|
return None, None, None
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
pid = W.find_pid()
|
||||||
|
if pid is None:
|
||||||
|
print("FIFA17.exe is not running.")
|
||||||
|
return 1
|
||||||
|
base = W.dll_base(pid)
|
||||||
|
if base is None:
|
||||||
|
print("pid %d is up but %s is not mapped." % (pid, W.DLL))
|
||||||
|
return 1
|
||||||
|
|
||||||
|
mem = W.Mem(pid)
|
||||||
|
maps = mappings(pid)
|
||||||
|
glob = base + (DAT_SERVICE - W.IMG_BASE)
|
||||||
|
svc = mem.q(glob)
|
||||||
|
print("pid=%d %s base=%#x" % (pid, W.DLL, base))
|
||||||
|
print("DAT_1802ddfd8 @ %#x -> service %#x" % (glob, svc or 0))
|
||||||
|
if not svc:
|
||||||
|
print("service pointer is NULL; the host has not handed CardsDLL its table yet.")
|
||||||
|
return 2
|
||||||
|
|
||||||
|
va = mem.q(svc + SLOT)
|
||||||
|
print("*(service + %#x) = %#x" % (SLOT, va or 0))
|
||||||
|
if not va:
|
||||||
|
print("slot %#x is empty." % SLOT)
|
||||||
|
return 2
|
||||||
|
print()
|
||||||
|
|
||||||
|
body = None
|
||||||
|
for hop in range(MAX_HOPS):
|
||||||
|
buf = mem.read(va, 16)
|
||||||
|
if not buf or len(buf) < 6:
|
||||||
|
print("hop %d: %#x unreadable" % (hop, va))
|
||||||
|
return 2
|
||||||
|
path, perms, off = attribute(maps, va)
|
||||||
|
where = "%s+%#x" % (path, off) if off is not None else str(path)
|
||||||
|
print("hop %d: %#x [%s] %s %s" % (hop, va, perms, where, buf[:8].hex()))
|
||||||
|
if buf[0] == 0xE9: # jmp rel32
|
||||||
|
va = va + 5 + struct.unpack("<i", buf[1:5])[0]
|
||||||
|
elif buf[0] == 0xFF and buf[1] == 0x25: # jmp [rip+rel32]
|
||||||
|
nxt = mem.q(va + 6 + struct.unpack("<i", buf[2:6])[0])
|
||||||
|
if not nxt:
|
||||||
|
print(" IAT slot is empty.")
|
||||||
|
return 2
|
||||||
|
va = nxt
|
||||||
|
else:
|
||||||
|
body = (va, path, off)
|
||||||
|
print(" -> function body")
|
||||||
|
break
|
||||||
|
if body is None:
|
||||||
|
print("chain did not settle within %d hops." % MAX_HOPS)
|
||||||
|
return 2
|
||||||
|
|
||||||
|
addr, path, off = body
|
||||||
|
code = mem.read(addr, 256) or b""
|
||||||
|
folds = FOLD_OR_IMM8 in code or FOLD_OR_EAX in code
|
||||||
|
print()
|
||||||
|
print("=" * 70)
|
||||||
|
print("COMPARATOR: %s+%#x (%#x)" % (path, off if off is not None else 0, addr))
|
||||||
|
print("case folding in first %d bytes: %s" % (len(code), "YES" if folds else "NO"))
|
||||||
|
if folds:
|
||||||
|
print("VERDICT: case-INSENSITIVE. itemState casing is a convention, not a contract.")
|
||||||
|
else:
|
||||||
|
print("VERDICT: case-SENSITIVE. A byte compare with no folding means the")
|
||||||
|
print(" wire token must match the table's casing EXACTLY -- a")
|
||||||
|
print(" mis-cased token silently resolves to itemState 0 (invalid).")
|
||||||
|
print(" openfut-adapter-fifa17's fut::item_state table is therefore")
|
||||||
|
print(" a contract: emit its casing verbatim.")
|
||||||
|
print("=" * 70)
|
||||||
|
return 0
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
sys.exit(main())
|
||||||
Executable
+65
@@ -0,0 +1,65 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Pure unit test for the empty-My-Packs store resolver guard in autopatch.py.
|
||||||
|
|
||||||
|
Covers the fail-closed guard decision (original -> PATCH, already-patched -> NOOP,
|
||||||
|
unknown -> SKIP) and pins the guarded patch table to the exact RVA/bytes proven on
|
||||||
|
the tested FIFA 17 build (JNZ 0x14869 -> JG 0x14869 at CardsDLL RVA 0x14858).
|
||||||
|
|
||||||
|
Run: python3 test_autopatch_guard.py
|
||||||
|
"""
|
||||||
|
import os
|
||||||
|
import sys
|
||||||
|
|
||||||
|
sys.path.insert(0, os.path.dirname(os.path.abspath(__file__)))
|
||||||
|
import autopatch # importable: runtime loop is guarded by `if __name__ == "__main__"`
|
||||||
|
|
||||||
|
GUARD_VA = 0x180014858
|
||||||
|
ORIG = bytes.fromhex("750f") # JNZ 0x14869
|
||||||
|
PATCH = bytes.fromhex("7f0f") # JG 0x14869
|
||||||
|
|
||||||
|
|
||||||
|
def test_table_exact():
|
||||||
|
assert autopatch.STORE_PATCHES_GUARDED == {GUARD_VA: (ORIG, PATCH)}, \
|
||||||
|
autopatch.STORE_PATCHES_GUARDED
|
||||||
|
# Byte-level pin so a bad hex literal cannot slip through.
|
||||||
|
assert ORIG == b"\x75\x0f" and PATCH == b"\x7f\x0f"
|
||||||
|
|
||||||
|
|
||||||
|
def test_decision():
|
||||||
|
assert autopatch.guarded_action(ORIG, ORIG, PATCH) == "patch" # apply
|
||||||
|
assert autopatch.guarded_action(PATCH, ORIG, PATCH) == "noop" # already patched
|
||||||
|
assert autopatch.guarded_action(b"\x00\x00", ORIG, PATCH) == "skip" # build mismatch
|
||||||
|
assert autopatch.guarded_action(b"\x90", ORIG, PATCH) == "skip" # wrong length
|
||||||
|
|
||||||
|
|
||||||
|
def test_guard_state_after():
|
||||||
|
# already patched (7f0f) -> VERIFIED (guarded_action "noop"); write args irrelevant.
|
||||||
|
assert autopatch.guard_state_after(PATCH, ORIG, PATCH, True, PATCH) == autopatch.GUARD_VERIFIED
|
||||||
|
# original (750f) + write ok + reread 7f0f -> VERIFIED (guarded_action "patch").
|
||||||
|
assert autopatch.guard_state_after(ORIG, ORIG, PATCH, True, PATCH) == autopatch.GUARD_VERIFIED
|
||||||
|
# original + write FAILS -> WRITE_FAILED.
|
||||||
|
assert autopatch.guard_state_after(ORIG, ORIG, PATCH, False, ORIG) == autopatch.GUARD_WRITE_FAILED
|
||||||
|
# original + write ok but reread != 7f0f -> VERIFY_FAILED.
|
||||||
|
assert autopatch.guard_state_after(ORIG, ORIG, PATCH, True, ORIG) == autopatch.GUARD_VERIFY_FAILED
|
||||||
|
assert autopatch.guard_state_after(ORIG, ORIG, PATCH, True, b"") == autopatch.GUARD_VERIFY_FAILED
|
||||||
|
# unknown bytes -> UNSUPPORTED_BUILD (guarded_action "skip"); write args irrelevant.
|
||||||
|
assert autopatch.guard_state_after(b"\x00\x00", ORIG, PATCH, True, PATCH) == autopatch.GUARD_UNSUPPORTED_BUILD
|
||||||
|
|
||||||
|
|
||||||
|
def test_capability_constants():
|
||||||
|
assert autopatch.EMPTY_MYPACKS_RESOLVER_VERSION == 1
|
||||||
|
assert autopatch.EMPTY_MYPACKS_RESOLVER_CAPABILITY == "fifa17.empty_mypacks_resolver"
|
||||||
|
# State constant values are the exact tokens carried in the emitted status line.
|
||||||
|
assert autopatch.GUARD_VERIFIED == "VERIFIED"
|
||||||
|
assert autopatch.GUARD_UNSUPPORTED_BUILD == "UNSUPPORTED_BUILD"
|
||||||
|
assert autopatch.GUARD_WRITE_FAILED == "WRITE_FAILED"
|
||||||
|
assert autopatch.GUARD_VERIFY_FAILED == "VERIFY_FAILED"
|
||||||
|
assert autopatch.GUARD_NOT_ATTEMPTED == "NOT_ATTEMPTED"
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
test_table_exact()
|
||||||
|
test_decision()
|
||||||
|
test_guard_state_after()
|
||||||
|
test_capability_constants()
|
||||||
|
print("OK: autopatch guard table + fail-closed decision + guard-state function + capability constants")
|
||||||
+301
@@ -0,0 +1,301 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Tests for the FIFA 17 verified-patched-client capability negotiation.
|
||||||
|
|
||||||
|
The additive empty-My-Packs switch on top of the P2 65534 sentinel: the sentinel is
|
||||||
|
suppressed for ONE FIFA session only when the launcher has registered a verified
|
||||||
|
resolver capability (v1) that binds to THAT process's UTAS session (keyed by the
|
||||||
|
per-login-unique X-UT-SID; source IP + persona are auxiliary). Every failure /
|
||||||
|
unknown / late / cross-process / cross-session case is fail-closed to the sentinel.
|
||||||
|
|
||||||
|
The initial prototype keyed by source IP alone; this suite proves the hardened
|
||||||
|
per-session binding, including two sessions that SHARE a source IP.
|
||||||
|
|
||||||
|
Matrix (docs/plans/FIFA17_PATCHED_CLIENT_CAPABILITY.md):
|
||||||
|
A no-capability, zero packs -> sentinel
|
||||||
|
B verified v1, zero packs -> clean (no 65534)
|
||||||
|
C real unopened pack + no capability -> genuine pack, no sentinel
|
||||||
|
D real unopened pack + capability -> genuine pack, no sentinel
|
||||||
|
E unsupported version / capability -> endpoint 400 AND mode sentinel
|
||||||
|
F late capability after sentinel freeze -> stays sentinel
|
||||||
|
G capability disappears after clean freeze -> stays clean (immutable)
|
||||||
|
H two IPs (A verified, B none) -> A clean, B sentinel (no global leak)
|
||||||
|
I new session after reset -> fresh unpatched -> sentinel
|
||||||
|
J autopatch mismatch => never registers -> sentinel
|
||||||
|
K SAME IP, two sessions (A patched, B not) -> A clean, B sentinel
|
||||||
|
L SAME IP+persona relaunch (old ok, new not) -> new session sentinel
|
||||||
|
M SAME IP, failed-patch second session -> first clean, second sentinel
|
||||||
|
N late registration when sessions are frozen -> does not modify active sessions
|
||||||
|
O session cleanup / TTL expiry -> capability gone, sentinel
|
||||||
|
P duplicate registration for a session -> idempotent; no post-freeze change
|
||||||
|
Q register-before-login (pending consumed) -> clean
|
||||||
|
R topology freeze immutable per SID -> no flip either way; new SID fresh
|
||||||
|
|
||||||
|
Standalone unit test in the project style: `python3 test_capability_negotiation.py`.
|
||||||
|
"""
|
||||||
|
import importlib
|
||||||
|
import json
|
||||||
|
import os
|
||||||
|
import sys
|
||||||
|
import tempfile
|
||||||
|
|
||||||
|
TOOLS = os.path.dirname(os.path.abspath(__file__))
|
||||||
|
if TOOLS not in sys.path:
|
||||||
|
sys.path.insert(0, TOOLS)
|
||||||
|
|
||||||
|
SENTINEL_ID = 65534
|
||||||
|
REAL_PACK_ID = 1
|
||||||
|
PERSONA = 111001
|
||||||
|
|
||||||
|
|
||||||
|
class _H:
|
||||||
|
"""Minimal request-handler stand-in: peer IP, optional X-UT-SID, optional body."""
|
||||||
|
|
||||||
|
def __init__(self, ip, body=None, sid=None):
|
||||||
|
self.client_address = (ip, 54321)
|
||||||
|
self.headers = {"X-UT-SID": sid} if sid is not None else {}
|
||||||
|
self._body = json.dumps(body).encode("utf-8") if body is not None else b""
|
||||||
|
|
||||||
|
|
||||||
|
def _ids(catalog):
|
||||||
|
return [p["id"] for p in catalog["purchase"]]
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
with tempfile.TemporaryDirectory() as state:
|
||||||
|
os.environ["FUT_ACCOUNT_PATH"] = os.path.join(state, "active_account.json")
|
||||||
|
os.environ["FUT_PROFILE_ROOT"] = os.path.join(state, "accounts")
|
||||||
|
os.environ.pop("FUT_PROFILE", None)
|
||||||
|
|
||||||
|
import fut_account
|
||||||
|
import fut_store
|
||||||
|
import fut_accounts
|
||||||
|
import utas_server
|
||||||
|
importlib.reload(fut_account)
|
||||||
|
importlib.reload(fut_store)
|
||||||
|
importlib.reload(fut_accounts)
|
||||||
|
importlib.reload(utas_server)
|
||||||
|
|
||||||
|
us = utas_server
|
||||||
|
CLEAN, SENT = us.FIFA17_MODE_CLEAN, us.FIFA17_MODE_SENTINEL
|
||||||
|
|
||||||
|
_orig_visible = us.visible_unopened_packs
|
||||||
|
|
||||||
|
def set_zero_packs():
|
||||||
|
us.visible_unopened_packs = lambda: []
|
||||||
|
|
||||||
|
def set_real_pack():
|
||||||
|
us.visible_unopened_packs = lambda: [REAL_PACK_ID]
|
||||||
|
|
||||||
|
def reset_state():
|
||||||
|
us._FIFA17_SESSIONS.clear()
|
||||||
|
us._FIFA17_PENDING.clear()
|
||||||
|
|
||||||
|
def auth(sid, ip, persona=PERSONA):
|
||||||
|
"""Simulate /ut/auth opening a per-login session with a chosen sid."""
|
||||||
|
us.fifa17_open_session(sid, ip, persona)
|
||||||
|
|
||||||
|
def register(ip, version, persona=PERSONA, pid=4242):
|
||||||
|
return us.fifa17_capability_route(_H(ip, {
|
||||||
|
"capability": "empty_mypacks_resolver", "version": version,
|
||||||
|
"personaId": persona, "fifaPid": pid,
|
||||||
|
}))
|
||||||
|
|
||||||
|
def store(sid, ip):
|
||||||
|
status, cat = us.store_catalog(_H(ip, sid=sid))
|
||||||
|
assert status == 200, status
|
||||||
|
return _ids(cat)
|
||||||
|
|
||||||
|
def mode_of(sid):
|
||||||
|
return us._FIFA17_SESSIONS[sid]["mode"]
|
||||||
|
|
||||||
|
try:
|
||||||
|
# ---- A. no capability, zero packs -> sentinel ----------------------
|
||||||
|
reset_state(); set_zero_packs()
|
||||||
|
auth("sidA", "10.0.0.1")
|
||||||
|
assert SENTINEL_ID in store("sidA", "10.0.0.1")
|
||||||
|
assert mode_of("sidA") == SENT
|
||||||
|
print("A no-capability zero-packs -> sentinel: OK")
|
||||||
|
|
||||||
|
# ---- B. verified v1, zero packs -> clean ---------------------------
|
||||||
|
reset_state(); set_zero_packs()
|
||||||
|
auth("sidB", "10.0.0.2")
|
||||||
|
assert register("10.0.0.2", 1)[0] == 200
|
||||||
|
ids = store("sidB", "10.0.0.2")
|
||||||
|
assert SENTINEL_ID not in ids, ids
|
||||||
|
assert mode_of("sidB") == CLEAN
|
||||||
|
print("B verified-v1 zero-packs -> clean: OK")
|
||||||
|
|
||||||
|
# ---- C. real pack + no capability -> genuine, no sentinel ----------
|
||||||
|
reset_state(); set_real_pack()
|
||||||
|
auth("sidC", "10.0.0.3")
|
||||||
|
ids = store("sidC", "10.0.0.3")
|
||||||
|
assert REAL_PACK_ID in ids and SENTINEL_ID not in ids, ids
|
||||||
|
print("C real-pack no-capability -> genuine, no sentinel: OK")
|
||||||
|
|
||||||
|
# ---- D. real pack + capability -> genuine, no sentinel -------------
|
||||||
|
reset_state(); set_real_pack()
|
||||||
|
auth("sidD", "10.0.0.4"); register("10.0.0.4", 1)
|
||||||
|
ids = store("sidD", "10.0.0.4")
|
||||||
|
assert REAL_PACK_ID in ids and SENTINEL_ID not in ids, ids
|
||||||
|
print("D real-pack capability -> genuine, no sentinel: OK")
|
||||||
|
|
||||||
|
# ---- E. unsupported version / capability -> 400 + sentinel ---------
|
||||||
|
reset_state(); set_zero_packs()
|
||||||
|
auth("sidE", "10.0.0.5")
|
||||||
|
assert register("10.0.0.5", 2)[0] == 400
|
||||||
|
assert register("10.0.0.5", 99)[0] == 400
|
||||||
|
assert us.fifa17_capability_route(
|
||||||
|
_H("10.0.0.5", {"capability": "bogus", "version": 1}))[0] == 400
|
||||||
|
assert SENTINEL_ID in store("sidE", "10.0.0.5")
|
||||||
|
assert mode_of("sidE") == SENT
|
||||||
|
print("E unsupported version/capability -> 400 + sentinel: OK")
|
||||||
|
|
||||||
|
# ---- F. late capability after sentinel freeze -> sentinel ----------
|
||||||
|
reset_state(); set_zero_packs()
|
||||||
|
auth("sidF", "10.0.0.6")
|
||||||
|
assert SENTINEL_ID in store("sidF", "10.0.0.6") # freezes sentinel
|
||||||
|
assert register("10.0.0.6", 1)[0] == 200 # session frozen -> ignored-late
|
||||||
|
assert SENTINEL_ID in store("sidF", "10.0.0.6")
|
||||||
|
assert mode_of("sidF") == SENT
|
||||||
|
print("F late capability after sentinel freeze -> sentinel: OK")
|
||||||
|
|
||||||
|
# ---- G. capability disappears after clean freeze -> clean ----------
|
||||||
|
reset_state(); set_zero_packs()
|
||||||
|
auth("sidG", "10.0.0.7"); register("10.0.0.7", 1)
|
||||||
|
assert SENTINEL_ID not in store("sidG", "10.0.0.7") # freezes clean
|
||||||
|
us._FIFA17_SESSIONS["sidG"]["resolver"] = None # capability vanishes
|
||||||
|
assert SENTINEL_ID not in store("sidG", "10.0.0.7")
|
||||||
|
assert mode_of("sidG") == CLEAN
|
||||||
|
print("G capability disappears after clean freeze -> clean: OK")
|
||||||
|
|
||||||
|
# ---- H. two IPs (A verified, B none) -> no global leak -------------
|
||||||
|
reset_state(); set_zero_packs()
|
||||||
|
auth("sidH1", "10.0.1.1"); register("10.0.1.1", 1)
|
||||||
|
auth("sidH2", "10.0.1.2")
|
||||||
|
assert SENTINEL_ID not in store("sidH1", "10.0.1.1")
|
||||||
|
assert SENTINEL_ID in store("sidH2", "10.0.1.2")
|
||||||
|
print("H two IPs (A clean, B sentinel) -> no global leak: OK")
|
||||||
|
|
||||||
|
# ---- I. new session after reset -> fresh unpatched -> sentinel -----
|
||||||
|
reset_state(); set_zero_packs()
|
||||||
|
auth("sidI1", "10.0.1.3"); register("10.0.1.3", 1)
|
||||||
|
assert SENTINEL_ID not in store("sidI1", "10.0.1.3") # A clean
|
||||||
|
us.fifa17_clear_pending("10.0.1.3") # relaunch boundary
|
||||||
|
auth("sidI2", "10.0.1.3") # new SID, autopatch failed
|
||||||
|
assert SENTINEL_ID in store("sidI2", "10.0.1.3")
|
||||||
|
print("I new session after reset -> sentinel (no cross-process leak): OK")
|
||||||
|
|
||||||
|
# ---- J. autopatch mismatch => never registers -> sentinel ----------
|
||||||
|
reset_state(); set_zero_packs()
|
||||||
|
auth("sidJ", "10.0.1.4")
|
||||||
|
assert SENTINEL_ID in store("sidJ", "10.0.1.4")
|
||||||
|
print("J autopatch mismatch (never registers) -> sentinel: OK")
|
||||||
|
|
||||||
|
# ---- K. SAME IP, two sessions: patched A clean, unpatched B sent ---
|
||||||
|
reset_state(); set_zero_packs()
|
||||||
|
IP = "10.0.2.1"
|
||||||
|
auth("sidK_A", IP)
|
||||||
|
assert register(IP, 1)[0] == 200 # A sole candidate -> bound
|
||||||
|
auth("sidK_B", IP) # B joins, never registers
|
||||||
|
assert SENTINEL_ID not in store("sidK_A", IP)
|
||||||
|
assert SENTINEL_ID in store("sidK_B", IP)
|
||||||
|
print("K same-IP two sessions -> A clean, B sentinel: OK")
|
||||||
|
|
||||||
|
# ---- L. SAME IP+persona relaunch: old ok, new not -> new sentinel --
|
||||||
|
reset_state(); set_zero_packs()
|
||||||
|
IP = "10.0.2.2"
|
||||||
|
auth("sidL_old", IP, PERSONA); register(IP, 1, PERSONA)
|
||||||
|
assert SENTINEL_ID not in store("sidL_old", IP)
|
||||||
|
us.fifa17_clear_pending(IP)
|
||||||
|
auth("sidL_new", IP, PERSONA) # same persona, unverified
|
||||||
|
assert SENTINEL_ID in store("sidL_new", IP)
|
||||||
|
print("L same-IP+persona relaunch -> new session sentinel: OK")
|
||||||
|
|
||||||
|
# ---- M. SAME IP, failed-patch second session -----------------------
|
||||||
|
reset_state(); set_zero_packs()
|
||||||
|
IP = "10.0.2.3"
|
||||||
|
auth("sidM1", IP); register(IP, 1)
|
||||||
|
assert SENTINEL_ID not in store("sidM1", IP)
|
||||||
|
auth("sidM2", IP) # autopatch failed
|
||||||
|
assert SENTINEL_ID in store("sidM2", IP)
|
||||||
|
print("M same-IP failed-patch second session -> sentinel: OK")
|
||||||
|
|
||||||
|
# ---- N. late reg when sessions frozen -> no active session change --
|
||||||
|
reset_state(); set_zero_packs()
|
||||||
|
IP = "10.0.2.4"
|
||||||
|
auth("sidN1", IP); register(IP, 1)
|
||||||
|
assert SENTINEL_ID not in store("sidN1", IP) # N1 frozen clean
|
||||||
|
auth("sidN2", IP)
|
||||||
|
assert SENTINEL_ID in store("sidN2", IP) # N2 frozen sentinel
|
||||||
|
assert register(IP, 1)[0] == 200 # late: both frozen -> ignored
|
||||||
|
assert SENTINEL_ID not in store("sidN1", IP) # unchanged
|
||||||
|
assert SENTINEL_ID in store("sidN2", IP) # unchanged
|
||||||
|
print("N late registration does not modify active sessions: OK")
|
||||||
|
|
||||||
|
# ---- O. session cleanup / TTL expiry -> capability gone ------------
|
||||||
|
reset_state(); set_zero_packs()
|
||||||
|
IP = "10.0.2.5"
|
||||||
|
auth("sidO", IP); register(IP, 1)
|
||||||
|
assert SENTINEL_ID not in store("sidO", IP) # clean while live
|
||||||
|
us._FIFA17_SESSIONS["sidO"]["last_seen"] = (
|
||||||
|
us._fifa17_now() - us.FIFA17_SESSION_TTL - 10.0)
|
||||||
|
store("sidUNKNOWN", IP) # any op triggers reap
|
||||||
|
assert "sidO" not in us._FIFA17_SESSIONS, "expired session not reaped"
|
||||||
|
assert SENTINEL_ID in store("sidO", IP) # gone -> sentinel
|
||||||
|
print("O session cleanup / TTL expiry -> sentinel: OK")
|
||||||
|
|
||||||
|
# ---- P. duplicate registration -> idempotent, no post-freeze change
|
||||||
|
reset_state(); set_zero_packs()
|
||||||
|
IP = "10.0.2.6"
|
||||||
|
auth("sidP", IP)
|
||||||
|
assert register(IP, 1)[0] == 200 # bound
|
||||||
|
assert register(IP, 1)[0] == 200 # duplicate -> ignored-late
|
||||||
|
assert SENTINEL_ID not in store("sidP", IP) # still clean
|
||||||
|
assert register(IP, 1)[0] == 200 # after freeze
|
||||||
|
assert SENTINEL_ID not in store("sidP", IP) # unchanged
|
||||||
|
assert mode_of("sidP") == CLEAN
|
||||||
|
print("P duplicate registration -> idempotent: OK")
|
||||||
|
|
||||||
|
# ---- Q. register-before-login: pending consumed at auth -> clean ---
|
||||||
|
reset_state(); set_zero_packs()
|
||||||
|
IP = "10.0.2.7"
|
||||||
|
assert register(IP, 1)[0] == 200 # no session yet -> pending
|
||||||
|
assert (IP, PERSONA) in us._FIFA17_PENDING
|
||||||
|
auth("sidQ", IP, PERSONA) # consumes pending
|
||||||
|
assert (IP, PERSONA) not in us._FIFA17_PENDING # single-use
|
||||||
|
assert SENTINEL_ID not in store("sidQ", IP)
|
||||||
|
assert mode_of("sidQ") == CLEAN
|
||||||
|
print("Q register-before-login pending consumed -> clean: OK")
|
||||||
|
|
||||||
|
# ---- R. topology freeze immutable per SID; new SID decides fresh ----
|
||||||
|
# F3 invariant: once a SID's store topology is decided it NEVER flips,
|
||||||
|
# in either direction, and a different SID may decide differently.
|
||||||
|
reset_state(); set_zero_packs()
|
||||||
|
IP = "10.0.2.8"
|
||||||
|
# frozen Sentinel never becomes Clean, even if a capability appears later
|
||||||
|
auth("sidR_s", IP)
|
||||||
|
assert SENTINEL_ID in store("sidR_s", IP) # freeze Sentinel
|
||||||
|
register(IP, 1)
|
||||||
|
us._FIFA17_SESSIONS["sidR_s"]["resolver"] = 1 # force-present capability
|
||||||
|
assert SENTINEL_ID in store("sidR_s", IP) # STILL Sentinel
|
||||||
|
assert mode_of("sidR_s") == SENT
|
||||||
|
# frozen Clean never becomes Sentinel, even if the capability is wiped
|
||||||
|
auth("sidR_c", IP); register(IP, 1)
|
||||||
|
assert SENTINEL_ID not in store("sidR_c", IP) # freeze Clean
|
||||||
|
us._FIFA17_SESSIONS["sidR_c"]["resolver"] = None # capability vanishes
|
||||||
|
assert SENTINEL_ID not in store("sidR_c", IP) # STILL Clean
|
||||||
|
assert mode_of("sidR_c") == CLEAN
|
||||||
|
# a fresh SID (same IP) decides independently
|
||||||
|
auth("sidR_new", IP)
|
||||||
|
assert SENTINEL_ID in store("sidR_new", IP)
|
||||||
|
print("R topology freeze immutable per SID; new SID fresh: OK")
|
||||||
|
|
||||||
|
finally:
|
||||||
|
us.visible_unopened_packs = _orig_visible
|
||||||
|
|
||||||
|
print("capability negotiation matrix A-R: OK")
|
||||||
|
return 0
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
raise SystemExit(main())
|
||||||
Executable
+136
@@ -0,0 +1,136 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Regression tests for the empty-My-Packs FIFA 17 compatibility workaround (bug 6c).
|
||||||
|
|
||||||
|
Pins the behavior store_catalog() now depends on:
|
||||||
|
- unopenedPackIds == [] -> exactly one synthetic active `mypacks` placeholder id 65534
|
||||||
|
- unopenedPackIds == [70] -> no synthetic placeholder; the genuine owned pack is shown
|
||||||
|
- synthetic id 65534 stays economy-safe (non-resolvable, non-openable, non-granting)
|
||||||
|
- normal store packs (1/5/6/7) are untouched by the empty-state behavior
|
||||||
|
|
||||||
|
See docs/evidence/STORE_TILE_6C.md and FIFA17_EMPTY_MYPACKS_CLIENT_CONTRACT.md.
|
||||||
|
Standalone unit test in the project style: `python3 test_empty_mypacks.py`.
|
||||||
|
"""
|
||||||
|
import importlib
|
||||||
|
import os
|
||||||
|
import sys
|
||||||
|
import tempfile
|
||||||
|
|
||||||
|
TOOLS = os.path.dirname(os.path.abspath(__file__))
|
||||||
|
if TOOLS not in sys.path:
|
||||||
|
sys.path.insert(0, TOOLS)
|
||||||
|
|
||||||
|
SENTINEL_ID = 65534
|
||||||
|
|
||||||
|
|
||||||
|
def _set_unopened(fut_store, ids):
|
||||||
|
"""Deterministically set the active profile's owned unopened packs."""
|
||||||
|
p = fut_store.STORE.load()
|
||||||
|
p["unopenedPackIds"] = list(ids)
|
||||||
|
fut_store.STORE._save()
|
||||||
|
|
||||||
|
|
||||||
|
def _mypacks(catalog):
|
||||||
|
return [p for p in catalog["purchase"]
|
||||||
|
if (p.get("displayGroup") or {}).get("value") == "mypacks"]
|
||||||
|
|
||||||
|
|
||||||
|
def _fake_request(command, body):
|
||||||
|
class _H:
|
||||||
|
pass
|
||||||
|
h = _H()
|
||||||
|
h.command = command
|
||||||
|
h._body = body
|
||||||
|
return h
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
with tempfile.TemporaryDirectory() as state:
|
||||||
|
os.environ["FUT_ACCOUNT_PATH"] = os.path.join(state, "active_account.json")
|
||||||
|
os.environ["FUT_PROFILE_ROOT"] = os.path.join(state, "accounts")
|
||||||
|
os.environ.pop("FUT_PROFILE", None)
|
||||||
|
|
||||||
|
import fut_account
|
||||||
|
import fut_store
|
||||||
|
import fut_accounts
|
||||||
|
import utas_server
|
||||||
|
importlib.reload(fut_account)
|
||||||
|
importlib.reload(fut_store)
|
||||||
|
importlib.reload(fut_accounts)
|
||||||
|
importlib.reload(utas_server)
|
||||||
|
|
||||||
|
fut_accounts.activate({"personaId": 111001, "personaName": "TEST_A"})
|
||||||
|
catalog_ids = [p["id"] for p in fut_store.PACK_CATALOG]
|
||||||
|
|
||||||
|
# ---- A. Empty unopened packs -> one active synthetic 65534 placeholder ----
|
||||||
|
_set_unopened(fut_store, [])
|
||||||
|
utas_server._OPENED_PACK_GRACE.clear()
|
||||||
|
status, cat = utas_server.store_catalog(None)
|
||||||
|
assert status == 200
|
||||||
|
myp = _mypacks(cat)
|
||||||
|
assert len(myp) == 1, "expected exactly one mypacks entry, got %r" % myp
|
||||||
|
s = myp[0]
|
||||||
|
assert s["id"] == SENTINEL_ID, s
|
||||||
|
assert s["state"] == "active", s # the P2 fix: active, not inactive
|
||||||
|
assert (s.get("displayGroup") or {}).get("value") == "mypacks", s
|
||||||
|
assert SENTINEL_ID not in catalog_ids, "65534 must not be in PACK_CATALOG"
|
||||||
|
assert fut_store.pack_by_id(SENTINEL_ID) is None
|
||||||
|
print("A empty-state active placeholder: PASS")
|
||||||
|
|
||||||
|
# ---- D (empty half). Normal packs untouched in empty state ----
|
||||||
|
norm = {p["id"]: p for p in cat["purchase"] if p["id"] in (1, 5, 6, 7)}
|
||||||
|
assert set(norm) == {1, 5, 6, 7}, sorted(norm)
|
||||||
|
assert all(norm[i]["state"] == "active" for i in norm), norm
|
||||||
|
assert norm[1]["packType"] == "BRONZE" and norm[1]["description"] == "Bronze Pack"
|
||||||
|
|
||||||
|
# ---- B. Non-empty unopened packs -> NO synthetic; genuine owned pack shown ----
|
||||||
|
_set_unopened(fut_store, [70])
|
||||||
|
utas_server._OPENED_PACK_GRACE.clear()
|
||||||
|
status, cat = utas_server.store_catalog(None)
|
||||||
|
assert status == 200
|
||||||
|
ids = [p["id"] for p in cat["purchase"]]
|
||||||
|
assert SENTINEL_ID not in ids, "synthetic placeholder must be suppressed when a pack exists"
|
||||||
|
myp = _mypacks(cat)
|
||||||
|
assert len(myp) == 1 and myp[0]["id"] == 70, myp
|
||||||
|
assert myp[0]["state"] == "active" and myp[0]["unopened"] is True, myp[0]
|
||||||
|
# normal packs still intact alongside the owned pack
|
||||||
|
assert {1, 5, 6, 7}.issubset(set(ids)), sorted(ids)
|
||||||
|
print("B non-empty-state genuine pack: PASS")
|
||||||
|
|
||||||
|
# ---- C. Economy safety of the synthetic placeholder ----
|
||||||
|
_set_unopened(fut_store, [])
|
||||||
|
utas_server._OPENED_PACK_GRACE.clear()
|
||||||
|
coins0 = fut_store.STORE.coins()
|
||||||
|
items0 = len(fut_store.STORE.items())
|
||||||
|
next0 = fut_store.STORE.load()["nextItemId"]
|
||||||
|
|
||||||
|
assert fut_store.pack_by_id(SENTINEL_ID) is None
|
||||||
|
|
||||||
|
# store_buy: a confirmed-buy transaction for 65534 must be a no-op {}
|
||||||
|
status, body = utas_server.store_buy(
|
||||||
|
_fake_request("PUT", b'{"packId":65534,"state":"TRANSACTIONCREATED"}'))
|
||||||
|
assert status == 200 and body == {}, (status, body)
|
||||||
|
|
||||||
|
# purchased_items: POST buy for 65534 must not open/grant anything
|
||||||
|
status, body = utas_server.purchased_items(
|
||||||
|
_fake_request("POST", b'{"packId":65534,"useCredits":1,"usePreOrder":0,"currency":"COINS"}'))
|
||||||
|
assert status == 200, (status, body)
|
||||||
|
assert "createPackResponse" not in body, body
|
||||||
|
|
||||||
|
# 65534 cannot enter the owned-pack pile (not a catalog pack)
|
||||||
|
assert fut_store.STORE.grant_unopened_pack(SENTINEL_ID) is False
|
||||||
|
assert SENTINEL_ID not in fut_store.STORE.unopened_packs()
|
||||||
|
|
||||||
|
# nothing mutated
|
||||||
|
assert fut_store.STORE.coins() == coins0, (fut_store.STORE.coins(), coins0)
|
||||||
|
assert len(fut_store.STORE.items()) == items0
|
||||||
|
assert fut_store.STORE.load()["nextItemId"] == next0
|
||||||
|
assert not any(i.get("id") == SENTINEL_ID or i.get("resourceId") == SENTINEL_ID
|
||||||
|
for i in fut_store.STORE.items())
|
||||||
|
print("C economy safety (65534 non-openable / non-granting): PASS")
|
||||||
|
|
||||||
|
print("empty My Packs compatibility: PASS")
|
||||||
|
return 0
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
raise SystemExit(main())
|
||||||
+61
@@ -0,0 +1,61 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Standalone contract test for Blaze roster-host advertisement."""
|
||||||
|
|
||||||
|
import importlib
|
||||||
|
import os
|
||||||
|
import sys
|
||||||
|
|
||||||
|
TOOLS = os.path.dirname(os.path.abspath(__file__))
|
||||||
|
if TOOLS not in sys.path:
|
||||||
|
sys.path.insert(0, TOOLS)
|
||||||
|
|
||||||
|
ADVERTISE = "192.0.2.10"
|
||||||
|
DNS_HOST = "winter15.gosredirector.ea.com:8081"
|
||||||
|
|
||||||
|
|
||||||
|
def assert_roster_config(blaze, host):
|
||||||
|
config = dict(blaze.OSDK_ROSTER)
|
||||||
|
assert blaze.ROSTER_HOST == host
|
||||||
|
assert config["ROSTERUPDATE_URL"] == (
|
||||||
|
f"https://{host}/fifa17/fut/rosterupdate.xml"
|
||||||
|
)
|
||||||
|
assert config["ROSTER_URL"] == f"https://{host}/fifa17/roster/"
|
||||||
|
assert config["ROSTER_VER"] == "0"
|
||||||
|
assert config["ROSTER_CSUM"] == ""
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
old_advertise = os.environ.get("OPENFUT_ADVERTISE")
|
||||||
|
old_roster_host = os.environ.get("OPENFUT_ROSTER_HOST")
|
||||||
|
try:
|
||||||
|
os.environ["OPENFUT_ADVERTISE"] = ADVERTISE
|
||||||
|
os.environ.pop("OPENFUT_ROSTER_HOST", None)
|
||||||
|
|
||||||
|
import blaze_responder_v3b as blaze
|
||||||
|
|
||||||
|
blaze = importlib.reload(blaze)
|
||||||
|
assert_roster_config(blaze, f"{ADVERTISE}:8081")
|
||||||
|
|
||||||
|
os.environ["OPENFUT_ROSTER_HOST"] = DNS_HOST
|
||||||
|
blaze = importlib.reload(blaze)
|
||||||
|
assert_roster_config(blaze, DNS_HOST)
|
||||||
|
|
||||||
|
os.environ["OPENFUT_ROSTER_HOST"] = ""
|
||||||
|
blaze = importlib.reload(blaze)
|
||||||
|
assert_roster_config(blaze, f"{ADVERTISE}:8081")
|
||||||
|
finally:
|
||||||
|
if old_advertise is None:
|
||||||
|
os.environ.pop("OPENFUT_ADVERTISE", None)
|
||||||
|
else:
|
||||||
|
os.environ["OPENFUT_ADVERTISE"] = old_advertise
|
||||||
|
if old_roster_host is None:
|
||||||
|
os.environ.pop("OPENFUT_ROSTER_HOST", None)
|
||||||
|
else:
|
||||||
|
os.environ["OPENFUT_ROSTER_HOST"] = old_roster_host
|
||||||
|
|
||||||
|
print("PASS: roster host defaults, override, and URLs")
|
||||||
|
return 0
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
raise SystemExit(main())
|
||||||
@@ -0,0 +1,76 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Read the FIFA 17 TRADING gate byte out of the live client. READ-ONLY.
|
||||||
|
|
||||||
|
Extends tools/gate_byte_probe.py with vtable slot +0x270 (IS_TRADING_ENABLED,
|
||||||
|
displacement 0x1fd2e) plus the two pile-size dwords, which the transfer-market
|
||||||
|
analysis names as the market screen's CardsDLL-supplied inputs.
|
||||||
|
|
||||||
|
Opens /proc/<pid>/mem O_RDONLY and preads. Nothing here can write.
|
||||||
|
"""
|
||||||
|
import os, struct
|
||||||
|
|
||||||
|
pid = None
|
||||||
|
for d in os.listdir('/proc'):
|
||||||
|
if d.isdigit():
|
||||||
|
try:
|
||||||
|
if open('/proc/%s/comm' % d).read().strip() == 'FIFA17.exe':
|
||||||
|
pid = int(d)
|
||||||
|
break
|
||||||
|
except Exception:
|
||||||
|
pass
|
||||||
|
assert pid, "FIFA17.exe not running"
|
||||||
|
|
||||||
|
base = None
|
||||||
|
for ln in open('/proc/%d/maps' % pid):
|
||||||
|
if 'CardsDLL' in ln:
|
||||||
|
base = int(ln.split('-')[0], 16)
|
||||||
|
assert base, "CardsDLL not mapped (client has not reached Ultimate Team)"
|
||||||
|
slide = base - 0x180000000
|
||||||
|
|
||||||
|
fd = os.open('/proc/%d/mem' % pid, os.O_RDONLY)
|
||||||
|
|
||||||
|
|
||||||
|
def rd(va, n):
|
||||||
|
return os.pread(fd, n, va)
|
||||||
|
|
||||||
|
|
||||||
|
# Control: the FNV atom-hash prologue must match the on-disk PE before any other
|
||||||
|
# address is trusted.
|
||||||
|
pe = open('/mnt/games/FIFA 17/CardsDLL_Win64_retail.dll', 'rb').read()
|
||||||
|
|
||||||
|
|
||||||
|
def f(va):
|
||||||
|
return va - 0x180000000 - 0x1000 + 0x400
|
||||||
|
|
||||||
|
|
||||||
|
ok = pe[f(0x180180d00):f(0x180180d00) + 32] == rd(0x180180d00 + slide, 32)
|
||||||
|
print("pid=%d slide=%#x FNV control=%s" % (pid, slide, "MATCH" if ok else "MISMATCH"))
|
||||||
|
assert ok, "slide not proven; refusing to read further"
|
||||||
|
|
||||||
|
obj = struct.unpack('<Q', rd(0x1802e6398 + slide, 8))[0]
|
||||||
|
vt = struct.unpack('<Q', rd(obj, 8))[0]
|
||||||
|
print("model=%#x vtable(static)=%#x" % (obj, vt - slide))
|
||||||
|
|
||||||
|
SLOTS = [
|
||||||
|
(0x270, 'IS_TRADING_ENABLED '),
|
||||||
|
(0x2b0, 'IS_FRIENDLY_SEASON '),
|
||||||
|
(0x2c8, 'IS_DRAFT_MODE '),
|
||||||
|
(0x2e0, 'packOpeningAnimation '),
|
||||||
|
]
|
||||||
|
print("\n-- gate bytes decoded from their accessor stubs --")
|
||||||
|
for off, name in SLOTS:
|
||||||
|
slot = struct.unpack('<Q', rd(vt + off, 8))[0]
|
||||||
|
stub = rd(slot, 8)
|
||||||
|
if stub[:3] == b'\x0f\xb6\x81':
|
||||||
|
disp = struct.unpack('<I', stub[3:7])[0]
|
||||||
|
val = rd(obj + disp, 1)[0]
|
||||||
|
print(" slot +%#05x %s disp=%#x VALUE=%d" % (off, name, disp, val))
|
||||||
|
else:
|
||||||
|
print(" slot +%#05x %s NOT a movzx stub: %s" % (off, name, stub.hex()))
|
||||||
|
|
||||||
|
print("\n-- market screen inputs --")
|
||||||
|
for disp, name in [(0x1fd1c, 'TRADE_PILE_SIZE'), (0x1fd20, 'watchListSize '),
|
||||||
|
(0x1fd2e, 'tradingEnabled '), (0x1fd2f, 'storeEnabled ')]:
|
||||||
|
print(" model+%#x %s = %d" % (disp, name, rd(obj + disp, 1)[0]))
|
||||||
|
|
||||||
|
os.close(fd)
|
||||||
Executable
+102
@@ -0,0 +1,102 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
# -*- coding: utf-8 -*-
|
||||||
|
"""Enumerate every UTAS URL template CardsDLL can build, from live memory.
|
||||||
|
|
||||||
|
READ-ONLY: /proc/PID/mem opened 'rb'. No write path in this file.
|
||||||
|
|
||||||
|
WHY
|
||||||
|
---
|
||||||
|
Support level L5 ("apply endpoint") for consumables was recorded as unreversed,
|
||||||
|
with an earlier note claiming there is "no training/position/chemistry/
|
||||||
|
manager-league endpoint at all" and that the only owned-item mutations upstream
|
||||||
|
are quick sell and move/pile. That claim is load-bearing -- if true, applying a
|
||||||
|
consumable is not a server route at all and L5/L6 cannot be implemented as one --
|
||||||
|
so it deserves to be checked against the binary rather than inherited.
|
||||||
|
|
||||||
|
This scans CardsDLL's .rdata for route-shaped strings and prints them, so the
|
||||||
|
full reachable surface can be read at once.
|
||||||
|
|
||||||
|
Positive control: known-live routes MUST appear (e.g. a 'item' path and a
|
||||||
|
'club' path). If the control is empty the region is wrong, not the game.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
python3 url_template_probe.py # route-shaped strings
|
||||||
|
python3 url_template_probe.py --all # every printable string >= 6 chars
|
||||||
|
python3 url_template_probe.py --grep pat # substring filter (case-insensitive)
|
||||||
|
"""
|
||||||
|
import argparse
|
||||||
|
import re
|
||||||
|
import sys
|
||||||
|
|
||||||
|
import watch_club_model as W
|
||||||
|
|
||||||
|
RDATA_LO, RDATA_HI = 0x1801E5000, 0x18028A000
|
||||||
|
DATA_LO, DATA_HI = 0x18028A000, 0x1802F0000
|
||||||
|
|
||||||
|
# Route-ish: contains a slash and no spaces, or looks like a UTAS path fragment.
|
||||||
|
ROUTE_HINTS = ("ut/", "game/", "item", "club", "squad", "purchase", "consumable",
|
||||||
|
"apply", "training", "position", "chemistry", "contract",
|
||||||
|
"fitness", "healing", "playstyle", "manager", "pile", "delete",
|
||||||
|
"transfer", "market", "auction", "sbs", "pack", "store")
|
||||||
|
|
||||||
|
PRINTABLE = re.compile(rb"[\x20-\x7e]{6,}")
|
||||||
|
|
||||||
|
|
||||||
|
def strings(mem, lo, hi):
|
||||||
|
buf, bad = mem.read_pages(W_live(lo), hi - lo)
|
||||||
|
if not buf:
|
||||||
|
return [], bad
|
||||||
|
out = []
|
||||||
|
for m in PRINTABLE.finditer(bytes(buf)):
|
||||||
|
out.append((lo + m.start(), m.group().decode("ascii")))
|
||||||
|
return out, bad
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
ap = argparse.ArgumentParser()
|
||||||
|
ap.add_argument("--all", action="store_true")
|
||||||
|
ap.add_argument("--grep")
|
||||||
|
a = ap.parse_args()
|
||||||
|
|
||||||
|
pid = W.find_pid()
|
||||||
|
if pid is None:
|
||||||
|
print("FIFA17.exe is not running.")
|
||||||
|
return 1
|
||||||
|
base = W.dll_base(pid)
|
||||||
|
if base is None:
|
||||||
|
print("pid %d is up but %s is not mapped yet." % (pid, W.DLL))
|
||||||
|
return 1
|
||||||
|
mem = W.Mem(pid)
|
||||||
|
|
||||||
|
global W_live
|
||||||
|
W_live = lambda i: base + (i - W.IMG_BASE)
|
||||||
|
|
||||||
|
print("pid=%d CardsDLL live base %#x" % (pid, base))
|
||||||
|
found = []
|
||||||
|
for lo, hi, name in ((RDATA_LO, RDATA_HI, ".rdata"), (DATA_LO, DATA_HI, ".data")):
|
||||||
|
ss, bad = strings(mem, lo, hi)
|
||||||
|
print(" %s: %d strings (%d bad pages)" % (name, len(ss), len(bad)))
|
||||||
|
found.extend(ss)
|
||||||
|
|
||||||
|
if a.grep:
|
||||||
|
pat = a.grep.lower()
|
||||||
|
sel = [(va, s) for va, s in found if pat in s.lower()]
|
||||||
|
elif a.all:
|
||||||
|
sel = found
|
||||||
|
else:
|
||||||
|
sel = [(va, s) for va, s in found
|
||||||
|
if "/" in s and " " not in s
|
||||||
|
and any(h in s.lower() for h in ROUTE_HINTS)]
|
||||||
|
|
||||||
|
print("\n%d matching string(s):" % len(sel))
|
||||||
|
for va, s in sel:
|
||||||
|
print(" %#x %s" % (va, s))
|
||||||
|
|
||||||
|
ctrl = [s for _, s in found if "ut/game" in s.lower()]
|
||||||
|
print("\nCONTROL ('ut/game' present): %s (%d)"
|
||||||
|
% ("OK" if ctrl else "EMPTY -> wrong region", len(ctrl)))
|
||||||
|
return 0
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
sys.exit(main())
|
||||||
@@ -11,7 +11,7 @@ Rules (from CardsDLL 0x18016D230 / 0x1801a33a0):
|
|||||||
* body must parse as JSON (else err 0x3E6); 204 + empty body is accepted.
|
* body must parse as JSON (else err 0x3E6); 204 + empty body is accepted.
|
||||||
* [resp+0x1c] == 0 is the success test; 404 is OK only on the first user GET.
|
* [resp+0x1c] == 0 is the success test; 404 is OK only on the first user GET.
|
||||||
"""
|
"""
|
||||||
import copy, datetime, json, os, random, re, sys, http.server
|
import copy, datetime, json, os, random, re, sys, threading, time, http.server
|
||||||
from urllib.parse import parse_qs, urlencode, urlsplit, urlunsplit
|
from urllib.parse import parse_qs, urlencode, urlsplit, urlunsplit
|
||||||
|
|
||||||
sys.path.insert(0, os.path.dirname(os.path.abspath(__file__)))
|
sys.path.insert(0, os.path.dirname(os.path.abspath(__file__)))
|
||||||
@@ -52,6 +52,173 @@ def visible_unopened_packs():
|
|||||||
return STORE.unopened_packs() + list(_OPENED_PACK_GRACE)
|
return STORE.unopened_packs() + list(_OPENED_PACK_GRACE)
|
||||||
|
|
||||||
|
|
||||||
|
# ---- FIFA17 empty-My-Packs capability negotiation (PER-SESSION, hardened) ----
|
||||||
|
# The synthetic 65534 sentinel (store_catalog) is the universal P2 fallback. It is
|
||||||
|
# suppressed for ONE FIFA session only when the launcher has registered that THAT
|
||||||
|
# process positively verified the CardsDLL resolver guard (RVA 0x14858 == JG).
|
||||||
|
#
|
||||||
|
# BINDING: the authoritative key is the per-login-unique UTAS session id (X-UT-SID),
|
||||||
|
# minted fresh at every /ut/auth and echoed by the client on every later call incl.
|
||||||
|
# /store/purchasegroup (live-confirmed present on real store requests). The initial
|
||||||
|
# prototype keyed on source IP ALONE; that was rejected because two FIFA processes
|
||||||
|
# (concurrent or relaunched) share an IP, so an unverified process could inherit a
|
||||||
|
# verified one's clean topology and crash. IP + persona are retained only as
|
||||||
|
# auxiliary data: a fail-closed sid/ip sanity check and the (ip,persona) key for the
|
||||||
|
# short-lived launcher->session hand-off.
|
||||||
|
#
|
||||||
|
# The launcher verifies out-of-band (autopatch) and cannot know the SID, so its
|
||||||
|
# registration is staged as a SINGLE-USE, short-TTL PENDING keyed by (ip,persona)
|
||||||
|
# and bound to exactly one FIFA session (directly if that session already exists,
|
||||||
|
# else consumed at the session's login or its first store request). Fail-closed
|
||||||
|
# everywhere: unknown / expired / absent / ambiguous / late => sentinel.
|
||||||
|
# See docs/plans/FIFA17_PATCHED_CLIENT_CAPABILITY.md (§Session binding).
|
||||||
|
FIFA17_EMPTY_MYPACKS_RESOLVER_VERSION = 1
|
||||||
|
FIFA17_MODE_SENTINEL = "sentinel"
|
||||||
|
FIFA17_MODE_CLEAN = "clean-v1"
|
||||||
|
FIFA17_SESSION_TTL = 3600.0 # reap a FIFA session after this many idle seconds
|
||||||
|
FIFA17_PENDING_TTL = 120.0 # a launcher capability may await its session this long
|
||||||
|
|
||||||
|
# sid -> {"ip","persona","resolver": Optional[int],"mode": Optional[str],"created","last_seen"}
|
||||||
|
_FIFA17_SESSIONS = {}
|
||||||
|
# (ip, persona) -> {"resolver": int, "ts"}: single-use launcher->session hand-off.
|
||||||
|
_FIFA17_PENDING = {}
|
||||||
|
_FIFA17_LOCK = threading.Lock()
|
||||||
|
|
||||||
|
|
||||||
|
def _fifa17_now():
|
||||||
|
return time.monotonic()
|
||||||
|
|
||||||
|
|
||||||
|
def _fifa17_client_ip(h):
|
||||||
|
"""Peer IP for the handler, or None when unavailable (e.g. h is None)."""
|
||||||
|
try:
|
||||||
|
return h.client_address[0]
|
||||||
|
except Exception:
|
||||||
|
return None
|
||||||
|
|
||||||
|
|
||||||
|
def _fifa17_sid(h):
|
||||||
|
"""The client's UTAS session id (X-UT-SID) for this request, or None."""
|
||||||
|
try:
|
||||||
|
return h.headers.get("X-UT-SID")
|
||||||
|
except Exception:
|
||||||
|
return None
|
||||||
|
|
||||||
|
|
||||||
|
def _fifa17_sidlog(sid):
|
||||||
|
"""A short, non-secret tag for correlating a session in logs."""
|
||||||
|
return ("\u2026" + sid[-6:]) if sid else "-"
|
||||||
|
|
||||||
|
|
||||||
|
def _fifa17_mint_sid():
|
||||||
|
"""A fresh, per-login-unique UTAS session id (same shape/length as the legacy
|
||||||
|
constant). Uniqueness -- not unpredictability -- is what the binding needs."""
|
||||||
|
return "OPENFUT-SID-%016X" % random.getrandbits(64)
|
||||||
|
|
||||||
|
|
||||||
|
def _fifa17_reap_locked(now):
|
||||||
|
for sid in [s for s, r in _FIFA17_SESSIONS.items()
|
||||||
|
if now - r["last_seen"] > FIFA17_SESSION_TTL]:
|
||||||
|
del _FIFA17_SESSIONS[sid]
|
||||||
|
for key in [k for k, p in _FIFA17_PENDING.items()
|
||||||
|
if now - p["ts"] > FIFA17_PENDING_TTL]:
|
||||||
|
del _FIFA17_PENDING[key]
|
||||||
|
|
||||||
|
|
||||||
|
def _fifa17_take_pending_locked(ip, persona, now):
|
||||||
|
"""Single-use: remove and return a fresh pending resolver for (ip,persona)."""
|
||||||
|
p = _FIFA17_PENDING.get((ip, persona))
|
||||||
|
if p is not None and now - p["ts"] <= FIFA17_PENDING_TTL:
|
||||||
|
del _FIFA17_PENDING[(ip, persona)]
|
||||||
|
return p["resolver"]
|
||||||
|
return None
|
||||||
|
|
||||||
|
|
||||||
|
def fifa17_session_known(sid):
|
||||||
|
"""True if sid is a live session (or the legacy constant, accepted by the
|
||||||
|
retired security-question gate ONLY -- never used to grant clean store mode)."""
|
||||||
|
if sid == SID:
|
||||||
|
return True
|
||||||
|
with _FIFA17_LOCK:
|
||||||
|
return sid in _FIFA17_SESSIONS
|
||||||
|
|
||||||
|
|
||||||
|
def fifa17_open_session(sid, ip, persona):
|
||||||
|
"""/ut/auth: open a per-login session and bind any pending launcher capability
|
||||||
|
for (ip,persona) that arrived before login."""
|
||||||
|
if not sid:
|
||||||
|
return
|
||||||
|
now = _fifa17_now()
|
||||||
|
with _FIFA17_LOCK:
|
||||||
|
_fifa17_reap_locked(now)
|
||||||
|
resolver = _fifa17_take_pending_locked(ip, persona, now)
|
||||||
|
_FIFA17_SESSIONS[sid] = {"ip": ip, "persona": persona, "resolver": resolver,
|
||||||
|
"mode": None, "created": now, "last_seen": now}
|
||||||
|
log("[fifa17-store] session opened %s (ip=%s persona=%s resolver=%s)"
|
||||||
|
% (_fifa17_sidlog(sid), ip, persona, resolver))
|
||||||
|
|
||||||
|
|
||||||
|
def fifa17_clear_pending(ip):
|
||||||
|
"""/openfut/account/sync hygiene: drop any stale pending for this machine so a
|
||||||
|
new launch's unverified session cannot inherit a leftover capability."""
|
||||||
|
now = _fifa17_now()
|
||||||
|
with _FIFA17_LOCK:
|
||||||
|
_fifa17_reap_locked(now)
|
||||||
|
for key in [k for k in _FIFA17_PENDING if k[0] == ip]:
|
||||||
|
del _FIFA17_PENDING[key]
|
||||||
|
|
||||||
|
|
||||||
|
def fifa17_register_capability(ip, persona, version):
|
||||||
|
"""Launcher registration. Returns one of:
|
||||||
|
"bound" exactly one live, unfrozen, unbound session for (ip,persona)
|
||||||
|
existed (registration after login -- the common case): bound now.
|
||||||
|
"pending" no session for (ip,persona) yet (before login): staged single-use.
|
||||||
|
"ignored-late" a session for (ip,persona) exists but is frozen or ambiguous
|
||||||
|
(>1 unbound): NOT staged, so no later/unverified process can
|
||||||
|
inherit it. Fail-closed.
|
||||||
|
Never authorizes more than one session."""
|
||||||
|
now = _fifa17_now()
|
||||||
|
with _FIFA17_LOCK:
|
||||||
|
_fifa17_reap_locked(now)
|
||||||
|
sessions = [r for r in _FIFA17_SESSIONS.values()
|
||||||
|
if r["ip"] == ip and r["persona"] == persona]
|
||||||
|
candidates = [r for r in sessions if r["mode"] is None and r["resolver"] is None]
|
||||||
|
if len(candidates) == 1:
|
||||||
|
candidates[0]["resolver"] = version
|
||||||
|
return "bound"
|
||||||
|
if sessions:
|
||||||
|
return "ignored-late"
|
||||||
|
_FIFA17_PENDING[(ip, persona)] = {"resolver": version, "ts": now}
|
||||||
|
return "pending"
|
||||||
|
|
||||||
|
|
||||||
|
def fifa17_empty_mypacks_mode(sid, ip):
|
||||||
|
"""Freeze (once) and return the empty-My-Packs mode for FIFA session `sid`.
|
||||||
|
Freeze point = the first /store/purchasegroup of the session. Fail-closed: an
|
||||||
|
unknown session, or a sid presented from a different IP than it was opened on,
|
||||||
|
resolves to the sentinel."""
|
||||||
|
now = _fifa17_now()
|
||||||
|
with _FIFA17_LOCK:
|
||||||
|
_fifa17_reap_locked(now)
|
||||||
|
rec = _FIFA17_SESSIONS.get(sid)
|
||||||
|
if rec is None:
|
||||||
|
return FIFA17_MODE_SENTINEL
|
||||||
|
rec["last_seen"] = now
|
||||||
|
if rec["ip"] is not None and ip is not None and rec["ip"] != ip:
|
||||||
|
log("[fifa17-store] sid %s ip mismatch (session %s != request %s) -> sentinel"
|
||||||
|
% (_fifa17_sidlog(sid), rec["ip"], ip))
|
||||||
|
return FIFA17_MODE_SENTINEL
|
||||||
|
if rec["mode"] is None:
|
||||||
|
if rec["resolver"] is None:
|
||||||
|
rec["resolver"] = _fifa17_take_pending_locked(rec["ip"], rec["persona"], now)
|
||||||
|
rec["mode"] = (FIFA17_MODE_CLEAN
|
||||||
|
if rec["resolver"] == FIFA17_EMPTY_MYPACKS_RESOLVER_VERSION
|
||||||
|
else FIFA17_MODE_SENTINEL)
|
||||||
|
log("[fifa17-store] session %s empty-mypacks mode frozen: %s"
|
||||||
|
% (_fifa17_sidlog(sid), rec["mode"]))
|
||||||
|
return rec["mode"]
|
||||||
|
|
||||||
|
|
||||||
def now():
|
def now():
|
||||||
return datetime.datetime.now().strftime("%Y-%m-%d %H:%M:%S")
|
return datetime.datetime.now().strftime("%Y-%m-%d %H:%M:%S")
|
||||||
|
|
||||||
@@ -102,7 +269,7 @@ def security_question_route(h):
|
|||||||
well-formed value without retaining or comparing it. Account selection has
|
well-formed value without retaining or comparing it. Account selection has
|
||||||
already initialized the server-owned verified compatibility state.
|
already initialized the server-owned verified compatibility state.
|
||||||
"""
|
"""
|
||||||
if h.headers.get("X-UT-SID") != SID:
|
if not fifa17_session_known(h.headers.get("X-UT-SID")):
|
||||||
log("[FUT] security-question request has no matching OpenFUT session")
|
log("[FUT] security-question request has no matching OpenFUT session")
|
||||||
return 400, {"reason": "invalid_session"}
|
return 400, {"reason": "invalid_session"}
|
||||||
|
|
||||||
@@ -193,11 +360,19 @@ def auth_body(h=None):
|
|||||||
except Exception as e: # adoption must never break auth
|
except Exception as e: # adoption must never break auth
|
||||||
log(" AUTH: adopt failed (%s: %s) -- keeping %s/%r"
|
log(" AUTH: adopt failed (%s: %s) -- keeping %s/%r"
|
||||||
% (type(e).__name__, e, before[0], before[1]))
|
% (type(e).__name__, e, before[0], before[1]))
|
||||||
return {"protocol": 1, "sid": SID, "serverTime": now(), "lastOnlineTime": now()}
|
sid = _fifa17_mint_sid()
|
||||||
|
fifa17_open_session(sid, _fifa17_client_ip(h), ACCOUNT.persona_id)
|
||||||
|
return {"protocol": 1, "sid": sid, "serverTime": now(), "lastOnlineTime": now()}
|
||||||
|
|
||||||
|
|
||||||
def account_sync_route(h):
|
def account_sync_route(h):
|
||||||
"""Launcher-only active-profile selection, before LSX/Blaze login starts."""
|
"""Launcher-only active-profile selection, before LSX/Blaze login starts."""
|
||||||
|
# Pre-launch hygiene: drop any stale launcher capability still pending for this
|
||||||
|
# machine so a new launch's unverified FIFA session cannot inherit it. The real
|
||||||
|
# per-process session is opened later, at /ut/auth (keyed by the minted X-UT-SID).
|
||||||
|
ip = _fifa17_client_ip(h)
|
||||||
|
fifa17_clear_pending(ip)
|
||||||
|
log(" ACCOUNT: cleared stale FIFA17 pending capability for ip %s" % ip)
|
||||||
try:
|
try:
|
||||||
body = json.loads(h._body.decode("utf-8")) if getattr(h, "_body", b"") else {}
|
body = json.loads(h._body.decode("utf-8")) if getattr(h, "_body", b"") else {}
|
||||||
account = activate_account(body)
|
account = activate_account(body)
|
||||||
@@ -209,6 +384,33 @@ def account_sync_route(h):
|
|||||||
return 200, {"account": account, "status": "OK"}
|
return 200, {"account": account, "status": "OK"}
|
||||||
|
|
||||||
|
|
||||||
|
def fifa17_capability_route(h):
|
||||||
|
"""POST /openfut/fifa17/capability -- launcher registers a verified resolver
|
||||||
|
capability for the current FIFA process (bound to the peer IP). Fail-closed:
|
||||||
|
anything but capability==empty_mypacks_resolver && version==current is a 400
|
||||||
|
that records NOTHING (the session stays on the sentinel fallback)."""
|
||||||
|
try:
|
||||||
|
body = json.loads(h._body.decode("utf-8")) if getattr(h, "_body", b"") else {}
|
||||||
|
except Exception:
|
||||||
|
return 400, {"error": "unsupported capability"}
|
||||||
|
if not isinstance(body, dict):
|
||||||
|
return 400, {"error": "unsupported capability"}
|
||||||
|
try:
|
||||||
|
version = int(body.get("version"))
|
||||||
|
except (TypeError, ValueError):
|
||||||
|
return 400, {"error": "unsupported capability"}
|
||||||
|
if (body.get("capability") != "empty_mypacks_resolver"
|
||||||
|
or version != FIFA17_EMPTY_MYPACKS_RESOLVER_VERSION):
|
||||||
|
return 400, {"error": "unsupported capability"}
|
||||||
|
ip = _fifa17_client_ip(h)
|
||||||
|
persona = body.get("personaId")
|
||||||
|
fifa_pid = body.get("fifaPid", "?")
|
||||||
|
status = fifa17_register_capability(ip, persona, version)
|
||||||
|
log("[fifa17-store] capability empty_mypacks_resolver=%s ip=%s persona=%s "
|
||||||
|
"fifa_pid=%s -> %s" % (version, ip, persona, fifa_pid, status))
|
||||||
|
return 200, {"status": "OK"}
|
||||||
|
|
||||||
|
|
||||||
def current_squad():
|
def current_squad():
|
||||||
"""The squad the client should see: the persisted one (item refs re-embedded
|
"""The squad the client should see: the persisted one (item refs re-embedded
|
||||||
from the club) or the seed ladder squad on first run.
|
from the club) or the seed ladder squad on first run.
|
||||||
@@ -1203,6 +1405,10 @@ ROUTES = [
|
|||||||
# Launcher control-plane endpoint. It is intentionally outside /ut so FIFA
|
# Launcher control-plane endpoint. It is intentionally outside /ut so FIFA
|
||||||
# never calls it; launch is blocked unless this succeeds first.
|
# never calls it; launch is blocked unless this succeeds first.
|
||||||
(re.compile(r"^/openfut/account/sync$"), lambda m, h: account_sync_route(h)),
|
(re.compile(r"^/openfut/account/sync$"), lambda m, h: account_sync_route(h)),
|
||||||
|
# Launcher registers a verified per-FIFA-process resolver capability (bound to
|
||||||
|
# peer IP). Adjacent to account/sync, above the generic /ut routes; FIFA never
|
||||||
|
# calls it. Fail-closed: absent/late/wrong-version => sentinel (store_catalog).
|
||||||
|
(re.compile(r"^/openfut/fifa17/capability$"), lambda m, h: fifa17_capability_route(h)),
|
||||||
# ---- FUT item-definition endpoints (must precede generic /item, /user) ----
|
# ---- FUT item-definition endpoints (must precede generic /item, /user) ----
|
||||||
(re.compile(G + r"/item/resource"), lambda m, h: defs_route(h)),
|
(re.compile(G + r"/item/resource"), lambda m, h: defs_route(h)),
|
||||||
(re.compile(G + r"/defid"), lambda m, h: defs_route(h)),
|
(re.compile(G + r"/defid"), lambda m, h: defs_route(h)),
|
||||||
@@ -3426,12 +3632,42 @@ def store_catalog(h):
|
|||||||
if owned:
|
if owned:
|
||||||
packs.append(_pack_body(owned, idx, owned=True))
|
packs.append(_pack_body(owned, idx, owned=True))
|
||||||
if not owned_ids:
|
if not owned_ids:
|
||||||
# GOTO_STORE_MYPACK resolves the hard-coded `mypacks` group before it
|
# ADDITIVE capability switch (see docs/plans/FIFA17_PATCHED_CLIENT_CAPABILITY.md
|
||||||
# renders rows. If the group is absent FIFA falls back to Bronze and
|
# §7/§9). This is the session-freeze point: the empty-mypacks decision for
|
||||||
# shows the empty-category dialog over the wrong tab. Retain an inactive
|
# this FIFA session (keyed by its X-UT-SID) is committed here at the first
|
||||||
# zero-item sentinel so the destination resolves, while state != active
|
# /store/purchasegroup and is immutable for the session thereafter.
|
||||||
# keeps it out of the visible row list. Its id is deliberately absent
|
mode = fifa17_empty_mypacks_mode(_fifa17_sid(h), _fifa17_client_ip(h))
|
||||||
# from PACK_CATALOG, so both purchase/open handlers reject it as well.
|
if mode == FIFA17_MODE_CLEAN:
|
||||||
|
# Verified patched client: emit NO mypacks group; the CardsDLL resolver
|
||||||
|
# guard (RVA 0x14858 JG) routes the -1 ordinal to Browse instead of
|
||||||
|
# dereferencing a null group. (append nothing)
|
||||||
|
pass
|
||||||
|
else:
|
||||||
|
# EMPTY MY PACKS -- FIFA 17 client-compatibility workaround (bug 6c, P2).
|
||||||
|
#
|
||||||
|
# The Store/Scaleform path RESOLVES the `mypacks` category even when the
|
||||||
|
# account owns zero unopened packs (the category is chosen client-side from
|
||||||
|
# the movie's CATEGORY_ID -> screen+0x290; no server field gates it).
|
||||||
|
# CardsDLL FUN_1800147f0 then dereferences the resolved group with NO null
|
||||||
|
# guard, so if no `mypacks` group exists the client CRASHES
|
||||||
|
# (CardsDLL_Win64_retail.dll+0x14882, read of [NULL+0x48] -- confirmed by
|
||||||
|
# minidump). We therefore MUST emit a `mypacks` group when empty.
|
||||||
|
#
|
||||||
|
# state="inactive" avoids the crash but makes the client report the pack
|
||||||
|
# unavailable immediately on Store entry and bounce to the Hub. state="active"
|
||||||
|
# keeps the group structurally valid AND lets the Store open normally; the
|
||||||
|
# empty tile renders as "0 items" and an explicit open is rejected
|
||||||
|
# CLIENT-SIDE ("This pack is no longer available") -- it sends NO backend
|
||||||
|
# request and mutates nothing.
|
||||||
|
#
|
||||||
|
# id 65534 is deliberately ABSENT from PACK_CATALOG, so pack_by_id() returns
|
||||||
|
# None and store_buy()/purchased_items() cannot open it, grant items/coins,
|
||||||
|
# or add it to unopenedPackIds. This is a compatibility shim for FIFA 17
|
||||||
|
# client behavior, NOT an EA-authentic empty-My-Packs representation, and it
|
||||||
|
# is FIFA17-specific (do not lift into game-independent Core). A fully clean
|
||||||
|
# zero-pack UX requires a client-side fix -- see
|
||||||
|
# docs/plans/FIFA17_EMPTY_MYPACKS_CLIENT_FIX.md and the evidence in
|
||||||
|
# docs/evidence/STORE_TILE_6C.md / FIFA17_EMPTY_MYPACKS_CLIENT_CONTRACT.md.
|
||||||
sentinel = {
|
sentinel = {
|
||||||
"id": 65534,
|
"id": 65534,
|
||||||
"name": "",
|
"name": "",
|
||||||
@@ -3441,7 +3677,7 @@ def store_catalog(h):
|
|||||||
"specialChance": 0.0,
|
"specialChance": 0.0,
|
||||||
}
|
}
|
||||||
empty = _pack_body(sentinel, 1, owned=True)
|
empty = _pack_body(sentinel, 1, owned=True)
|
||||||
empty["state"] = "inactive"
|
empty["state"] = "active"
|
||||||
empty["unopened"] = False
|
empty["unopened"] = False
|
||||||
packs.append(empty)
|
packs.append(empty)
|
||||||
return 200, {"purchase": packs, "timestamp": 1596326400}
|
return 200, {"purchase": packs, "timestamp": 1596326400}
|
||||||
|
|||||||
@@ -0,0 +1,78 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Dump CardsDLL's NULL-terminated {const char*, int} vocabulary tables from the
|
||||||
|
ON-DISK PE. READ-ONLY, static.
|
||||||
|
|
||||||
|
The transfer-market analysis records tradeState as decoding through a table walk at
|
||||||
|
0x180229e40 and lists sibling vocabularies (type/zone/lev/pos) as tables of the same
|
||||||
|
shape. This prints the exact token spellings and their integer codes, so the accepted
|
||||||
|
strings come from the client rather than from inference.
|
||||||
|
"""
|
||||||
|
import struct
|
||||||
|
|
||||||
|
DLL = "/mnt/games/FIFA 17/CardsDLL_Win64_retail.dll"
|
||||||
|
TABLES = [
|
||||||
|
(0x180229E40, "tradeState (table walk)"),
|
||||||
|
(0x180229C30, "type"),
|
||||||
|
(0x1802296E0, "zone"),
|
||||||
|
(0x180229A60, "lev"),
|
||||||
|
(0x1802295C0, "pos"),
|
||||||
|
(0x180229AB0, "cat"),
|
||||||
|
(0x180229880, "form"),
|
||||||
|
]
|
||||||
|
MAX_ROWS = 64
|
||||||
|
|
||||||
|
pe = open(DLL, "rb").read()
|
||||||
|
e_lfanew = struct.unpack_from("<I", pe, 0x3C)[0]
|
||||||
|
coff = e_lfanew + 4
|
||||||
|
num_sections = struct.unpack_from("<H", pe, coff + 2)[0]
|
||||||
|
opt_size = struct.unpack_from("<H", pe, coff + 16)[0]
|
||||||
|
opt = coff + 20
|
||||||
|
image_base = struct.unpack_from("<Q", pe, opt + 24)[0]
|
||||||
|
sec_off = opt + opt_size
|
||||||
|
sections = []
|
||||||
|
for i in range(num_sections):
|
||||||
|
b = sec_off + i * 40
|
||||||
|
vsize, vaddr, rawsize, rawptr = struct.unpack_from("<IIII", pe, b + 8)
|
||||||
|
sections.append((vaddr, vsize, rawptr, rawsize))
|
||||||
|
|
||||||
|
|
||||||
|
def va2off(va):
|
||||||
|
rva = va - image_base
|
||||||
|
for vaddr, vsize, rawptr, rawsize in sections:
|
||||||
|
if vaddr <= rva < vaddr + max(vsize, rawsize):
|
||||||
|
off = rva - vaddr + rawptr
|
||||||
|
if 0 <= off < len(pe):
|
||||||
|
return off
|
||||||
|
return None
|
||||||
|
|
||||||
|
|
||||||
|
def cstr(va, limit=64):
|
||||||
|
off = va2off(va)
|
||||||
|
if off is None:
|
||||||
|
return None
|
||||||
|
end = pe.find(b"\0", off, off + limit)
|
||||||
|
if end < 0:
|
||||||
|
return None
|
||||||
|
try:
|
||||||
|
s = pe[off:end].decode("ascii")
|
||||||
|
except UnicodeDecodeError:
|
||||||
|
return None
|
||||||
|
return s if s.isprintable() else None
|
||||||
|
|
||||||
|
|
||||||
|
for table_va, name in TABLES:
|
||||||
|
base = va2off(table_va)
|
||||||
|
print("\n=== %s VA %#x -> off %s ===" % (name, table_va, hex(base) if base else None))
|
||||||
|
if base is None:
|
||||||
|
print(" (VA did not resolve)")
|
||||||
|
continue
|
||||||
|
for i in range(MAX_ROWS):
|
||||||
|
ptr, code = struct.unpack_from("<Qi", pe, base + i * 16)
|
||||||
|
if ptr == 0:
|
||||||
|
print(" -- NULL terminator after %d rows --" % i)
|
||||||
|
break
|
||||||
|
s = cstr(ptr)
|
||||||
|
if s is None:
|
||||||
|
print(" row %d: ptr %#x does not resolve to a string; stopping" % (i, ptr))
|
||||||
|
break
|
||||||
|
print(" %-28s = %d" % (repr(s), code))
|
||||||
@@ -0,0 +1,24 @@
|
|||||||
|
[package]
|
||||||
|
name = "openfut-adapter-fifa17"
|
||||||
|
version = "0.1.0"
|
||||||
|
edition = "2021"
|
||||||
|
license = "MIT"
|
||||||
|
description = "FIFA 17 game adapter: Blaze command tables, response bodies and dispatch"
|
||||||
|
publish = false
|
||||||
|
|
||||||
|
[dependencies]
|
||||||
|
openfut-protocol-blaze = { path = "../openfut-protocol-blaze" }
|
||||||
|
# Reads the bundled fetchClientConfig table (227-243 rows per CFID), which is
|
||||||
|
# generated from the Python oracle rather than transcribed by hand. Unlike the
|
||||||
|
# protocol crate below it, this crate is ordinary server-side code, so a real
|
||||||
|
# JSON parser is the right call — hand-rolling one to preserve a zero-dependency
|
||||||
|
# streak would be reinventing a solved problem in the riskiest possible place.
|
||||||
|
serde = { version = "1", features = ["derive"] }
|
||||||
|
serde_json = "1"
|
||||||
|
# Seeded RNG for the Store pack-content generator (`fut::pack_content`). The
|
||||||
|
# generator is pure over an injected `rand::Rng`, so packs are deterministic
|
||||||
|
# under a seeded `StdRng` in tests and reproducible in production.
|
||||||
|
rand = "0.8"
|
||||||
|
|
||||||
|
[dev-dependencies]
|
||||||
|
# Differential fixtures are JSONL; the runtime dependency already covers it.
|
||||||
@@ -0,0 +1,115 @@
|
|||||||
|
# openfut-adapter-fifa17
|
||||||
|
|
||||||
|
The FIFA 17 game adapter. Everything true of *FIFA 17 specifically* lives here,
|
||||||
|
so that neither OpenFUT Core nor the generic protocol crates have to know about
|
||||||
|
it.
|
||||||
|
|
||||||
|
```
|
||||||
|
openfut-protocol-blaze generic Blaze: Fire2 framing, Heat2/TDF codec
|
||||||
|
▲
|
||||||
|
openfut-adapter-fifa17 THIS: command tables, response bodies, dispatch order
|
||||||
|
▲
|
||||||
|
OpenFUT Core game-independent FUT domain (not yet wired)
|
||||||
|
```
|
||||||
|
|
||||||
|
## Status
|
||||||
|
|
||||||
|
| Surface | Port | State |
|
||||||
|
|---|---|---|
|
||||||
|
| **Blaze / Fire2 RPC** | 42130 | **Implemented**, byte-for-byte parity-tested |
|
||||||
|
| Redirector (HTTPS + XML) | 42127 | Python only |
|
||||||
|
| Nucleus OAuth stub | 42131 | Python only |
|
||||||
|
| LSX / Origin | 4216 | Python only |
|
||||||
|
| Roster XML | 8081 | Python only |
|
||||||
|
| UTAS / RS4 | 8099 | Python only |
|
||||||
|
| POW / EASFC | 8094 / 8080 | Python only |
|
||||||
|
|
||||||
|
**Nothing here is wired into the running backend.** The crate answers frames; it
|
||||||
|
opens no socket, terminates no TLS and owns no runtime. The Python backend
|
||||||
|
remains the live service and the behavioural oracle.
|
||||||
|
|
||||||
|
## What the adapter owns, and what it must not
|
||||||
|
|
||||||
|
Owns: component/command/notification IDs, response body shapes, dispatch
|
||||||
|
ordering, session identity, the `fetchClientConfig` tables.
|
||||||
|
|
||||||
|
Must not own: FUT domain state. Blaze is an auth/session/config protocol — no
|
||||||
|
coins, packs, clubs or squads appear on this wire — so `Session` holds a session
|
||||||
|
key, a locale, a service name, an auth code and a flag, and that is all. When
|
||||||
|
UTAS is migrated that boundary will need active defending; here it comes free.
|
||||||
|
|
||||||
|
## Parity
|
||||||
|
|
||||||
|
```bash
|
||||||
|
./check-parity.sh # oracle freshness + byte-for-byte replay
|
||||||
|
./check-parity.sh --regen # after an intentional oracle change
|
||||||
|
```
|
||||||
|
|
||||||
|
`fixtures/blaze_transactions.jsonl` holds 49 request→response(s) transactions
|
||||||
|
produced by calling the real `blaze_responder_v3b.dispatch()`. They replay in
|
||||||
|
order against a shared session per connection, so ordering-dependent behaviour
|
||||||
|
is exercised rather than assumed: preAuth captures the locale that later `ALOC`
|
||||||
|
fields echo, and login sets the auth code `getAuthToken` returns afterwards.
|
||||||
|
|
||||||
|
Comparison is byte-for-byte including frame count and order — a missing
|
||||||
|
post-login notification or a reply where the oracle stays silent fails here.
|
||||||
|
|
||||||
|
The suite was **mutation-tested**: swapping two post-login notifications,
|
||||||
|
flipping one enum deep inside `AccountInfo`, and hardcoding an address in
|
||||||
|
`utas_base()`/`nucleus_base()` were each verified to turn it red. The third
|
||||||
|
initially did *not*, because the config templating had made those helpers dead
|
||||||
|
code; the table now templates on URL-level tokens so they are the single place a
|
||||||
|
URL shape is defined.
|
||||||
|
|
||||||
|
## Three behaviours that are easy to get wrong
|
||||||
|
|
||||||
|
* **Login answers with four frames, in order**: reply, then `UserAuthenticated`,
|
||||||
|
`UserSessionExtendedDataUpdate`, `UserAdded`.
|
||||||
|
* **An unimplemented RPC still gets an empty reply.** Silence makes the client
|
||||||
|
wait for a timeout; an empty reply lets every field fall back to a client-side
|
||||||
|
default and the boot continues.
|
||||||
|
* **Non-request message types get nothing at all.**
|
||||||
|
|
||||||
|
No error replies are emitted. `msgType` 3 exists, but the error-code placement
|
||||||
|
is UNRESOLVED — three clean-room sources disagree between `header[14:16]`, a
|
||||||
|
metadata `ERRC`, and a payload `CNTX`/`ERRC` — so emitting one would be a guess
|
||||||
|
on the wire.
|
||||||
|
|
||||||
|
## The client config table
|
||||||
|
|
||||||
|
`fixtures/client_config.json` carries 227–243 rows per CFID, generated from the
|
||||||
|
Python oracle and templated on `{utas_base}`, `{nucleus_base}`,
|
||||||
|
`{pow_content_url}`, `{advertise}`, `{bind}`, `{pow_host}`. It is
|
||||||
|
reverse-engineered *data*, not logic, and deriving it mechanically removes a
|
||||||
|
class of transcription typo no reviewer could catch. The generator does not take
|
||||||
|
its own templating on trust: it substitutes real addresses back in and diffs
|
||||||
|
against the oracle for every section before writing the file.
|
||||||
|
|
||||||
|
The table must be *complete*, not representative. The client resolves a per-call
|
||||||
|
key (`FUT_RS4_URL_<CALL>`) before a per-module one, and any unresolved call falls
|
||||||
|
back to a real, dead EA host — that is what produced "there has been an error
|
||||||
|
connecting to FIFA 17 Ultimate Team" mid-session when only the boot subset was
|
||||||
|
served.
|
||||||
|
|
||||||
|
## Known defect reproduced deliberately
|
||||||
|
|
||||||
|
`nucleusConnect` and `nucleusConnectTrusted` are built from the **bind** address,
|
||||||
|
not the advertised one. On the live split deployment that means the backend
|
||||||
|
tells a client on another machine to reach Nucleus at `http://0.0.0.0:42131`,
|
||||||
|
which it cannot. Verified against the running container, not inferred.
|
||||||
|
|
||||||
|
This is reproduced exactly, because it is what the only proven-working
|
||||||
|
configuration does and changing it would break parity. It also implies the
|
||||||
|
Nucleus stub is not actually reached in the current remote flow. Fixing it is a
|
||||||
|
separate change that needs live validation — see the vault.
|
||||||
|
|
||||||
|
## Configuration
|
||||||
|
|
||||||
|
Nothing is hardcoded. `AdapterConfig` carries `Identity` (persona, ids, email,
|
||||||
|
namespace, entitlement group, …) and `Endpoints` (advertise, bind, POW hosts,
|
||||||
|
telemetry/ticker/QoS ports). `Default` gives the project's synthetic offline
|
||||||
|
identity on loopback; a remote deployment must override `advertise`.
|
||||||
|
|
||||||
|
Bind and advertise are deliberately distinct: an advertised URL must carry the
|
||||||
|
address the *client* can reach, which on a two-machine deployment is not the
|
||||||
|
address the server binds.
|
||||||
Executable
+28
@@ -0,0 +1,28 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
# Differential check: the Rust FIFA 17 Blaze adapter vs the Python responder.
|
||||||
|
#
|
||||||
|
# 1. assert the committed fixtures still match what the Python oracle emits
|
||||||
|
# 2. replay every recorded transaction through the Rust adapter, byte-for-byte
|
||||||
|
#
|
||||||
|
# Read-only with respect to the running backend: the oracle is imported as a
|
||||||
|
# library, no responder is started, no port is bound, no live service is
|
||||||
|
# touched. Safe to run while the Python backend is serving a live FIFA client.
|
||||||
|
#
|
||||||
|
# Use --regen to rewrite the fixtures after an intentional oracle change.
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
cd "$(dirname "$(readlink -f "$0")")"
|
||||||
|
|
||||||
|
if [[ "${1:-}" == "--regen" ]]; then
|
||||||
|
echo "==> regenerating fixtures from the Python oracle"
|
||||||
|
python3 fixtures/generate.py
|
||||||
|
else
|
||||||
|
echo "==> checking committed fixtures against the Python oracle"
|
||||||
|
python3 fixtures/generate.py --check
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "==> replaying transactions through the Rust adapter"
|
||||||
|
cargo test -p openfut-adapter-fifa17
|
||||||
|
|
||||||
|
echo
|
||||||
|
echo "PARITY OK — the adapter reproduces the Python dispatcher byte-for-byte."
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,167 @@
|
|||||||
|
//! Emit the discard-pricing matrix for an entire FIFA 17 corpus, and audit it.
|
||||||
|
//!
|
||||||
|
//! Uses the SHIPPED implementation (`fut::discard::value_for_definition`) rather
|
||||||
|
//! than reimplementing the formula, so the matrix cannot drift from what the
|
||||||
|
//! server actually pays.
|
||||||
|
//!
|
||||||
|
//! ```text
|
||||||
|
//! cargo run -p openfut-adapter-fifa17 --example discard_matrix -- \
|
||||||
|
//! <catalog.json> <cards.json> [--csv out.csv]
|
||||||
|
//! ```
|
||||||
|
//!
|
||||||
|
//! Prints an audit summary and, with `--csv`, the full per-definition matrix.
|
||||||
|
|
||||||
|
use std::collections::{BTreeMap, HashMap};
|
||||||
|
|
||||||
|
use openfut_adapter_fifa17::fut::discard;
|
||||||
|
use openfut_adapter_fifa17::fut::item::legacy_discard_value;
|
||||||
|
|
||||||
|
fn main() {
|
||||||
|
let args: Vec<String> = std::env::args().collect();
|
||||||
|
if args.len() < 3 {
|
||||||
|
eprintln!("usage: discard_matrix <catalog.json> <cards.json> [--csv <path>]");
|
||||||
|
std::process::exit(2);
|
||||||
|
}
|
||||||
|
let catalog: serde_json::Value =
|
||||||
|
serde_json::from_str(&std::fs::read_to_string(&args[1]).expect("read catalog"))
|
||||||
|
.expect("parse catalog");
|
||||||
|
let cards: serde_json::Value =
|
||||||
|
serde_json::from_str(&std::fs::read_to_string(&args[2]).expect("read cards"))
|
||||||
|
.expect("parse cards");
|
||||||
|
let csv_path = args
|
||||||
|
.iter()
|
||||||
|
.position(|a| a == "--csv")
|
||||||
|
.map(|i| args[i + 1].clone());
|
||||||
|
|
||||||
|
// Core's rating per definition id (non-players are 0, which is exactly why
|
||||||
|
// the catalog rating matters).
|
||||||
|
let mut core_rating: HashMap<String, u8> = HashMap::new();
|
||||||
|
if let Some(arr) = cards.as_array() {
|
||||||
|
for c in arr {
|
||||||
|
let id = c["id"].as_str().unwrap_or_default().to_string();
|
||||||
|
let r = c["overall"].as_i64().unwrap_or(0).clamp(0, 255) as u8;
|
||||||
|
core_rating.insert(id, r);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
let entries = catalog
|
||||||
|
.get("cards")
|
||||||
|
.and_then(|c| c.as_object())
|
||||||
|
.expect("catalog has cards{}");
|
||||||
|
|
||||||
|
let mut rows: Vec<String> = Vec::new();
|
||||||
|
rows.push("definition,kind,subtype,cardtype,rareflag,rating_src,rating,level,legacy,recovered,verdict".into());
|
||||||
|
|
||||||
|
let mut by_kind: BTreeMap<String, (usize, usize, i64, i64)> = BTreeMap::new(); // n, declined, legacy, recovered
|
||||||
|
let (mut negatives, mut zero_priced, mut declined_total, mut overflow) =
|
||||||
|
(0usize, 0usize, 0usize, 0usize);
|
||||||
|
let mut boundary_probe_failures = Vec::new();
|
||||||
|
|
||||||
|
for (id, e) in entries {
|
||||||
|
let kind = e["kind"].as_str().unwrap_or("player").to_string();
|
||||||
|
let subtype = e["subtype"].as_i64().unwrap_or(0);
|
||||||
|
let rareflag = e["rareflag"].as_i64().unwrap_or(0);
|
||||||
|
let cat_rating = e["rating"].as_i64().map(|r| r.clamp(0, 255) as u8);
|
||||||
|
let core = *core_rating.get(id).unwrap_or(&0);
|
||||||
|
let cardtype = discard::cardtype_for_subtype(subtype);
|
||||||
|
|
||||||
|
let recovered = discard::value_for_definition(subtype, rareflag, cat_rating, core);
|
||||||
|
let effective_rating = cat_rating.unwrap_or(core);
|
||||||
|
let level = discard::discard_level(effective_rating);
|
||||||
|
let legacy = legacy_discard_value(core);
|
||||||
|
|
||||||
|
let verdict = match recovered {
|
||||||
|
None => {
|
||||||
|
declined_total += 1;
|
||||||
|
"DECLINES->legacy"
|
||||||
|
}
|
||||||
|
Some(v) if v < 0 => {
|
||||||
|
negatives += 1;
|
||||||
|
"NEGATIVE"
|
||||||
|
}
|
||||||
|
Some(0) => {
|
||||||
|
zero_priced += 1;
|
||||||
|
"ZERO"
|
||||||
|
}
|
||||||
|
Some(v) if v > 1_000_000 => {
|
||||||
|
overflow += 1;
|
||||||
|
"IMPLAUSIBLE"
|
||||||
|
}
|
||||||
|
Some(_) => "ok",
|
||||||
|
};
|
||||||
|
|
||||||
|
let ent = by_kind.entry(kind.clone()).or_insert((0, 0, 0, 0));
|
||||||
|
ent.0 += 1;
|
||||||
|
ent.2 += legacy;
|
||||||
|
match recovered {
|
||||||
|
Some(v) => ent.3 += v,
|
||||||
|
None => {
|
||||||
|
ent.1 += 1;
|
||||||
|
ent.3 += legacy; // declining means the legacy ladder is what pays
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
rows.push(format!(
|
||||||
|
"{id},{kind},{subtype},{cardtype},{rareflag},{},{effective_rating},{level},{legacy},{},{verdict}",
|
||||||
|
if cat_rating.is_some() { "catalog" } else { "core" },
|
||||||
|
recovered.map(|v| v.to_string()).unwrap_or_else(|| "-".into()),
|
||||||
|
));
|
||||||
|
}
|
||||||
|
|
||||||
|
// Rating-boundary audit against the client's own ladder (cmp 0x4b / 0x41).
|
||||||
|
for (rating, want) in [(0u8, 1u8), (64, 1), (65, 2), (74, 2), (75, 3), (99, 3)] {
|
||||||
|
let got = discard::discard_level(rating);
|
||||||
|
if got != want {
|
||||||
|
boundary_probe_failures.push(format!("rating {rating}: level {got}, expected {want}"));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
println!("== DISCARD MATRIX AUDIT ==");
|
||||||
|
println!("definitions : {}", entries.len());
|
||||||
|
println!("declined -> legacy : {declined_total}");
|
||||||
|
println!("priced zero : {zero_priced}");
|
||||||
|
println!("negative : {negatives}");
|
||||||
|
println!("implausible (>1e6) : {overflow}");
|
||||||
|
println!(
|
||||||
|
"rating boundaries : {}",
|
||||||
|
if boundary_probe_failures.is_empty() {
|
||||||
|
"OK (1/2/3 at <65 / 65..74 / >=75)".to_string()
|
||||||
|
} else {
|
||||||
|
boundary_probe_failures.join("; ")
|
||||||
|
}
|
||||||
|
);
|
||||||
|
println!();
|
||||||
|
println!(
|
||||||
|
"{:<12} {:>6} {:>9} {:>14} {:>14}",
|
||||||
|
"kind", "n", "declined", "legacy", "recovered"
|
||||||
|
);
|
||||||
|
let (mut tl, mut tr) = (0i64, 0i64);
|
||||||
|
for (kind, (n, dec, legacy, rec)) in &by_kind {
|
||||||
|
println!("{kind:<12} {n:>6} {dec:>9} {legacy:>14} {rec:>14}");
|
||||||
|
tl += legacy;
|
||||||
|
tr += rec;
|
||||||
|
}
|
||||||
|
println!(
|
||||||
|
"{:<12} {:>6} {:>9} {:>14} {:>14}",
|
||||||
|
"TOTAL",
|
||||||
|
entries.len(),
|
||||||
|
declined_total,
|
||||||
|
tl,
|
||||||
|
tr
|
||||||
|
);
|
||||||
|
if tl > 0 {
|
||||||
|
println!("ratio recovered/legacy : {:.2}x", tr as f64 / tl as f64);
|
||||||
|
}
|
||||||
|
|
||||||
|
if let Some(path) = csv_path {
|
||||||
|
std::fs::write(&path, rows.join("\n") + "\n").expect("write csv");
|
||||||
|
println!("\nwrote {} rows to {path}", rows.len() - 1);
|
||||||
|
}
|
||||||
|
|
||||||
|
let fatal = negatives + overflow + boundary_probe_failures.len();
|
||||||
|
if fatal > 0 {
|
||||||
|
eprintln!("\nFAIL: {fatal} fatal finding(s)");
|
||||||
|
std::process::exit(1);
|
||||||
|
}
|
||||||
|
println!("\nRESULT: OK");
|
||||||
|
}
|
||||||
File diff suppressed because one or more lines are too long
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,460 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Freeze the Python Blaze responder's DISPATCH contract as replayable fixtures.
|
||||||
|
|
||||||
|
The crate-level fixtures in `openfut-protocol-blaze` pin the *codec*: given a
|
||||||
|
field tree, what bytes come out. This file pins the layer above: given an
|
||||||
|
inbound Fire2 frame and a session, **which frames go back, in what order**.
|
||||||
|
|
||||||
|
That is the whole contract of a Blaze adapter, and it is the thing a rewrite can
|
||||||
|
silently get wrong in ways a codec test cannot see — a missing post-login
|
||||||
|
notification, a reply where the oracle stays silent, notifications in the wrong
|
||||||
|
order, session state not carried between RPCs.
|
||||||
|
|
||||||
|
Every transaction is produced by calling the real
|
||||||
|
`blaze_responder_v3b.dispatch()`. Session state is threaded across a scripted
|
||||||
|
connection exactly as it would be on a live socket, so ordering-dependent
|
||||||
|
behaviour (preAuth captures the locale; login sets the auth code that
|
||||||
|
getAuthToken later returns) is captured rather than assumed.
|
||||||
|
|
||||||
|
Determinism: the oracle's clock is pinned and its PRNG seeded, and the
|
||||||
|
deployment-dependent addresses are set before import (the responder reads them
|
||||||
|
at import time). See the sibling generator in openfut-protocol-blaze.
|
||||||
|
|
||||||
|
NO SECRETS. The identity here (persona 33068179 / "CAGE") is the project's fixed
|
||||||
|
synthetic offline identity. Session keys are minted from a seeded PRNG.
|
||||||
|
|
||||||
|
Usage: python3 fixtures/generate.py (write)
|
||||||
|
python3 fixtures/generate.py --check (verify committed files are current)
|
||||||
|
"""
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import json
|
||||||
|
import os
|
||||||
|
import random
|
||||||
|
import sys
|
||||||
|
from collections import OrderedDict
|
||||||
|
|
||||||
|
HERE = os.path.dirname(os.path.abspath(__file__))
|
||||||
|
TOOLS = os.path.normpath(os.path.join(HERE, "..", "..", "fifa17-recon", "tools"))
|
||||||
|
if not os.path.isdir(TOOLS):
|
||||||
|
sys.exit("cannot find the Python oracle at %s" % TOOLS)
|
||||||
|
sys.path.insert(0, TOOLS)
|
||||||
|
|
||||||
|
CHECK_ONLY = "--check" in sys.argv[1:]
|
||||||
|
# Internal mode: re-exec of this script with sentinel addresses, used to derive
|
||||||
|
# the templated client-config table (see emit_config_table).
|
||||||
|
CONFIG_TABLE_MODE = "--_config_table" in sys.argv[1:]
|
||||||
|
sys.argv = [sys.argv[0]]
|
||||||
|
|
||||||
|
# Sentinels substituted back into template tokens. Deliberately not IP-shaped so
|
||||||
|
# a stray literal cannot be mistaken for a real address.
|
||||||
|
SENTINELS = [
|
||||||
|
("ADVERTISE-SENTINEL", "{advertise}"),
|
||||||
|
("BIND-SENTINEL", "{bind}"),
|
||||||
|
("POWCONTENT-SENTINEL", "{pow_content_host}"),
|
||||||
|
("POWHOST-SENTINEL", "{pow_host}"),
|
||||||
|
]
|
||||||
|
|
||||||
|
if CONFIG_TABLE_MODE:
|
||||||
|
os.environ["OPENFUT_ADVERTISE"] = "ADVERTISE-SENTINEL"
|
||||||
|
os.environ["OPENFUT_BIND"] = "BIND-SENTINEL"
|
||||||
|
os.environ["POW_CONTENT_HOST"] = "POWCONTENT-SENTINEL"
|
||||||
|
os.environ["POW_HOST"] = "POWHOST-SENTINEL"
|
||||||
|
import blaze_responder_v3b as _B # noqa: E402
|
||||||
|
out = {cfid: _B.client_config_for(cfid) for cfid in sorted(_B.CLIENT_CONFIGS)}
|
||||||
|
out["__default__"] = _B.client_config_for("__no_such_section__")
|
||||||
|
print(json.dumps(out))
|
||||||
|
raise SystemExit(0)
|
||||||
|
|
||||||
|
# Pin deployment config BEFORE import — the responder snapshots these at import
|
||||||
|
# time into module globals used by the response builders.
|
||||||
|
#
|
||||||
|
# Distinct, obviously-fake values on purpose: if the Rust adapter hardcoded an
|
||||||
|
# address instead of reading its config, these make the failure loud rather than
|
||||||
|
# accidentally matching a loopback default.
|
||||||
|
ADVERTISE = "198.51.100.7"
|
||||||
|
BIND = "0.0.0.0"
|
||||||
|
POW_CONTENT_HOST = "198.51.100.7:8085"
|
||||||
|
POW_HOST = "198.51.100.7:8094"
|
||||||
|
|
||||||
|
os.environ["OPENFUT_ADVERTISE"] = ADVERTISE
|
||||||
|
os.environ["OPENFUT_BIND"] = BIND
|
||||||
|
os.environ["POW_CONTENT_HOST"] = POW_CONTENT_HOST
|
||||||
|
os.environ["POW_HOST"] = POW_HOST
|
||||||
|
|
||||||
|
import heat2 # noqa: E402
|
||||||
|
import blaze_responder_v3b as B # noqa: E402
|
||||||
|
from fut_account import ACCOUNT # noqa: E402
|
||||||
|
|
||||||
|
FIXED_NOW = 1754870400
|
||||||
|
INT, STRING, STRUCT, LIST, MAP, BLOB = (
|
||||||
|
heat2.INT, heat2.STRING, heat2.STRUCT, heat2.LIST, heat2.MAP, heat2.BLOB)
|
||||||
|
|
||||||
|
RECORDS = []
|
||||||
|
|
||||||
|
|
||||||
|
# ------------------------------------------------------------------ helpers
|
||||||
|
|
||||||
|
def req_frame(component, command, fields=None, msg_num=1, msg_type=None,
|
||||||
|
user_index=0):
|
||||||
|
"""Build an inbound request frame the way the client would."""
|
||||||
|
msg_type = B.MESSAGE if msg_type is None else msg_type
|
||||||
|
payload = heat2.encode_tdf(fields) if fields else b""
|
||||||
|
return B.fire2(component, command, msg_num, msg_type, payload,
|
||||||
|
user_index=user_index)
|
||||||
|
|
||||||
|
|
||||||
|
def tx(session, name, frame, note=""):
|
||||||
|
"""Run one frame through the real dispatcher and record what came back."""
|
||||||
|
hdr = B.parse_fire2_header(frame)
|
||||||
|
body = frame[16 + hdr["metadata_len"]:]
|
||||||
|
fields = heat2.decode_tdf(body) if body else OrderedDict()
|
||||||
|
out = B.dispatch(hdr, fields, body, session["sess"])
|
||||||
|
|
||||||
|
RECORDS.append(OrderedDict((
|
||||||
|
("kind", "tx"),
|
||||||
|
("session", session["id"]),
|
||||||
|
("name", name),
|
||||||
|
("note", note),
|
||||||
|
("request_hex", frame.hex()),
|
||||||
|
("responses", [f.hex() for f in out]),
|
||||||
|
)))
|
||||||
|
return out
|
||||||
|
|
||||||
|
|
||||||
|
def new_session(sid):
|
||||||
|
s = {"id": sid, "sess": B.Session()}
|
||||||
|
RECORDS.append(OrderedDict((
|
||||||
|
("kind", "session"),
|
||||||
|
("id", sid),
|
||||||
|
# Minted per connection by the oracle; the Rust side must be able to
|
||||||
|
# inject it, because it appears in LoginResponse.SESS.KEY, the
|
||||||
|
# UserAuthenticated push and PostAuthResponse.TELE.SESS and all three
|
||||||
|
# must be the same string.
|
||||||
|
("session_key", s["sess"].session_key),
|
||||||
|
("account_locale", s["sess"].account_locale),
|
||||||
|
("service_name", s["sess"].service_name),
|
||||||
|
)))
|
||||||
|
return s
|
||||||
|
|
||||||
|
|
||||||
|
# ------------------------------------------------------------------ script
|
||||||
|
|
||||||
|
def build():
|
||||||
|
RECORDS.append(OrderedDict((
|
||||||
|
("kind", "config"),
|
||||||
|
("advertise", ADVERTISE),
|
||||||
|
("bind", BIND),
|
||||||
|
("pow_content_host", POW_CONTENT_HOST),
|
||||||
|
("pow_host", POW_HOST),
|
||||||
|
("now", FIXED_NOW),
|
||||||
|
("identity", OrderedDict((
|
||||||
|
("persona_id", ACCOUNT.persona_id),
|
||||||
|
("persona_name", ACCOUNT.persona_name),
|
||||||
|
("user_id", ACCOUNT.user_id),
|
||||||
|
("ext_id", ACCOUNT.ext_id),
|
||||||
|
("email", ACCOUNT.email),
|
||||||
|
("namespace", ACCOUNT.NAMESPACE),
|
||||||
|
("client_platform", ACCOUNT.CLIENT_PLATFORM),
|
||||||
|
("persona_status", ACCOUNT.PERSONA_STATUS),
|
||||||
|
("user_session_type", ACCOUNT.USER_SESSION_TYPE),
|
||||||
|
("account_locale_int", ACCOUNT.account_locale_int),
|
||||||
|
("locale", ACCOUNT.locale),
|
||||||
|
("content_id", ACCOUNT.CONTENT_ID),
|
||||||
|
("entitlement_tag", ACCOUNT.ENTITLEMENT_TAG),
|
||||||
|
("entitlement_group", ACCOUNT.ENTITLEMENT_GROUP),
|
||||||
|
("title_id", ACCOUNT.TITLE_ID),
|
||||||
|
("client_id", ACCOUNT.CLIENT_ID),
|
||||||
|
("platform", ACCOUNT.PLATFORM),
|
||||||
|
("server_version", B.SERVER_VERSION),
|
||||||
|
))),
|
||||||
|
)))
|
||||||
|
|
||||||
|
# ================= main connection: the real boot order =================
|
||||||
|
#
|
||||||
|
# Mirrors what FIFA 17 actually does, because ordering is load-bearing:
|
||||||
|
# preAuth captures the locale that later ALOC fields echo, and login sets
|
||||||
|
# the auth code that getAuthToken returns afterwards.
|
||||||
|
m = new_session("main")
|
||||||
|
|
||||||
|
tx(m, "preauth", req_frame(B.COMP_UTIL, B.CMD_PREAUTH, OrderedDict([
|
||||||
|
("CDAT", (STRUCT, OrderedDict([
|
||||||
|
("IITO", (INT, 0)),
|
||||||
|
("LANG", (INT, 0x656E5553)), # 'enUS'
|
||||||
|
("SVCN", (STRING, "fifa-2017-pc")), # echoed back as INST
|
||||||
|
("TYPE", (INT, 0)),
|
||||||
|
]))),
|
||||||
|
("CINF", (STRUCT, OrderedDict([
|
||||||
|
("BSDK", (STRING, "15.1.1.3.0")),
|
||||||
|
("CLNT", (STRING, "FIFA17")),
|
||||||
|
("ENV", (STRING, "prod")),
|
||||||
|
("LOC", (INT, 0x656E5553)),
|
||||||
|
]))),
|
||||||
|
("FCCR", (STRUCT, OrderedDict([("CFID", (STRING, "BlazeSDK"))]))),
|
||||||
|
])), "first RPC; echoes SVCN as INST and captures LANG for ALOC")
|
||||||
|
|
||||||
|
tx(m, "ping", req_frame(B.COMP_UTIL, B.CMD_PING, msg_num=2),
|
||||||
|
"Util::ping -> STIM only")
|
||||||
|
|
||||||
|
# Every section the responder knows, plus unknown ones. The known sections
|
||||||
|
# each add their own rows on top of the shared FUT/RS4 base — OSDK_ROSTER in
|
||||||
|
# particular carries the roster URL, itself a documented loading gate — so
|
||||||
|
# covering only "BlazeSDK" would leave most of the table unverified.
|
||||||
|
for cfid in ("BlazeSDK", "netres", "IdentityParams", "OSDK_CORE",
|
||||||
|
"OSDK_CLIENT", "OSDK_NUCLEUS", "OSDK_ROSTER", "OSDK_TICKER",
|
||||||
|
"OSDK_WEBOFFER", "OSDK_POW", "OSDK_ABUSE_REPORTING",
|
||||||
|
"OSDK_XMS_ABUSE_REPORTING", "UTAS", "FUT", "",
|
||||||
|
"TOTALLY_UNKNOWN"):
|
||||||
|
tx(m, "fetch_config_%s" % (cfid or "empty"),
|
||||||
|
req_frame(B.COMP_UTIL, B.CMD_FETCHCLIENTCONFIG,
|
||||||
|
OrderedDict([("CFID", (STRING, cfid))]), msg_num=3),
|
||||||
|
"unknown CFIDs still get the shared FUT/POW rows")
|
||||||
|
|
||||||
|
tx(m, "get_auth_token_before_login",
|
||||||
|
req_frame(B.COMP_AUTH, B.CMD_GETAUTHTOKEN, msg_num=4),
|
||||||
|
"no auth code yet -> synthesised OPENFUT-<key[:16]> token")
|
||||||
|
|
||||||
|
tx(m, "logout_before_login", req_frame(B.COMP_AUTH, B.CMD_LOGOUT, msg_num=5),
|
||||||
|
"routine LoginStateLogout (state 500), NOT a failure; empty reply")
|
||||||
|
|
||||||
|
tx(m, "login", req_frame(B.COMP_AUTH, B.CMD_LOGIN, OrderedDict([
|
||||||
|
("AUTH", (STRING, "OPENFUT-TEST-AUTHCODE")),
|
||||||
|
("EXTB", (BLOB, b"")),
|
||||||
|
("PNAM", (STRING, "")),
|
||||||
|
]), msg_num=6),
|
||||||
|
"reply THEN three UserSessions pushes, in that order")
|
||||||
|
|
||||||
|
tx(m, "get_auth_token_after_login",
|
||||||
|
req_frame(B.COMP_AUTH, B.CMD_GETAUTHTOKEN, msg_num=7),
|
||||||
|
"now echoes the login's AUTH verbatim")
|
||||||
|
|
||||||
|
tx(m, "get_account", req_frame(B.COMP_AUTH, B.CMD_GETACCOUNT, msg_num=8),
|
||||||
|
"the RPC behind 'Unable to retrieve account information'")
|
||||||
|
tx(m, "get_persona", req_frame(B.COMP_AUTH, B.CMD_GETPERSONA, msg_num=9))
|
||||||
|
tx(m, "list_personas", req_frame(B.COMP_AUTH, B.CMD_LISTPERSONAS, msg_num=10))
|
||||||
|
|
||||||
|
for cmd, label in ((B.CMD_LISTUSERENTITLEMENTS2, "listUserEntitlements2"),
|
||||||
|
(0x20, "listEntitlements"),
|
||||||
|
(0x30, "listPersonaEntitlements2"),
|
||||||
|
(0x27, "grantEntitlement2")):
|
||||||
|
tx(m, "entitlements_%s" % label,
|
||||||
|
req_frame(B.COMP_AUTH, cmd, msg_num=11),
|
||||||
|
"all four aliases return the same two ONLINE_ACCESS records")
|
||||||
|
|
||||||
|
tx(m, "post_auth", req_frame(B.COMP_UTIL, B.CMD_POSTAUTH, msg_num=12),
|
||||||
|
"TELE/TICK/UROP; TELE.SESS must equal the login session key")
|
||||||
|
tx(m, "fetch_qos_config", req_frame(B.COMP_UTIL, 0x15, msg_num=13))
|
||||||
|
tx(m, "user_settings_load",
|
||||||
|
req_frame(B.COMP_UTIL, B.CMD_USERSETTINGSLOAD, msg_num=14))
|
||||||
|
tx(m, "user_settings_save",
|
||||||
|
req_frame(B.COMP_UTIL, B.CMD_USERSETTINGSSAVE, msg_num=15),
|
||||||
|
"accepted and discarded; empty reply")
|
||||||
|
tx(m, "set_client_state",
|
||||||
|
req_frame(B.COMP_UTIL, B.CMD_SETCLIENTSTATE, msg_num=16))
|
||||||
|
tx(m, "set_client_metrics",
|
||||||
|
req_frame(B.COMP_UTIL, B.CMD_SETCLIENTMETRICS, msg_num=17))
|
||||||
|
|
||||||
|
tx(m, "update_network_info",
|
||||||
|
req_frame(B.COMP_USERSESSIONS, B.CMD_UPDATENETWORKINFO, msg_num=18),
|
||||||
|
"empty reply PLUS an unsolicited ExtendedDataUpdate push")
|
||||||
|
|
||||||
|
tx(m, "get_lists", req_frame(B.COMP_ASSOCLISTS, B.CMD_GETLISTS, msg_num=19))
|
||||||
|
|
||||||
|
tx(m, "census_subscribe",
|
||||||
|
req_frame(B.COMP_CENSUSDATA, B.CMD_SUBSCRIBETOCENSUSDATAUPDATES,
|
||||||
|
OrderedDict([("RSUB", (INT, 1))]), msg_num=20),
|
||||||
|
"non-zero TimeValues or the client storms at ~30/s and hangs the FUT load")
|
||||||
|
|
||||||
|
tx(m, "logout_after_login",
|
||||||
|
req_frame(B.COMP_AUTH, B.CMD_LOGOUT, msg_num=21),
|
||||||
|
"session teardown after a login; still an empty reply")
|
||||||
|
|
||||||
|
# ============================ fallback behaviour ========================
|
||||||
|
f = new_session("fallbacks")
|
||||||
|
|
||||||
|
tx(f, "transport_ping",
|
||||||
|
req_frame(B.COMP_UTIL, B.CMD_PING, msg_num=30, msg_type=B.PING),
|
||||||
|
"msgType PING -> PING_REPLY with an empty body, whatever the command")
|
||||||
|
|
||||||
|
for mt, label in ((B.REPLY, "reply"), (B.NOTIFICATION, "notification"),
|
||||||
|
(B.ERROR_REPLY, "error_reply"),
|
||||||
|
(B.PING_REPLY, "ping_reply")):
|
||||||
|
tx(f, "ignores_%s" % label,
|
||||||
|
req_frame(B.COMP_UTIL, B.CMD_PING, msg_num=31, msg_type=mt),
|
||||||
|
"not a request -> NO frames at all")
|
||||||
|
|
||||||
|
tx(f, "unknown_command",
|
||||||
|
req_frame(B.COMP_UTIL, 0x0FFF, msg_num=32),
|
||||||
|
"unimplemented RPC still gets an EMPTY reply so the client cannot hang")
|
||||||
|
tx(f, "unknown_component",
|
||||||
|
req_frame(0x1234, 0x0001, msg_num=33),
|
||||||
|
"same fallback for an entirely unknown component")
|
||||||
|
|
||||||
|
tx(f, "user_index_is_echoed",
|
||||||
|
req_frame(B.COMP_UTIL, B.CMD_PING, msg_num=34, user_index=7),
|
||||||
|
"a reply echoes component/command/msgNum/userIndex verbatim")
|
||||||
|
|
||||||
|
# ================= locale echo on a non-default client ==================
|
||||||
|
loc = new_session("locale")
|
||||||
|
tx(loc, "preauth_de_locale",
|
||||||
|
req_frame(B.COMP_UTIL, B.CMD_PREAUTH, OrderedDict([
|
||||||
|
("CDAT", (STRUCT, OrderedDict([
|
||||||
|
("LANG", (INT, 0x64654445)), # 'deDE'
|
||||||
|
("SVCN", (STRING, "fifa-2017-pc-de")),
|
||||||
|
]))),
|
||||||
|
])),
|
||||||
|
"a non-enUS client: SVCN echo AND the captured locale must both change")
|
||||||
|
tx(loc, "login_with_de_locale",
|
||||||
|
req_frame(B.COMP_AUTH, B.CMD_LOGIN, msg_num=41),
|
||||||
|
"UserAuthenticated.ALOC must carry the captured deDE locale")
|
||||||
|
|
||||||
|
|
||||||
|
# ------------------------------------------------------------------- output
|
||||||
|
|
||||||
|
def emit_config_table():
|
||||||
|
"""Derive the fetchClientConfig tables as address-TEMPLATED data.
|
||||||
|
|
||||||
|
These are 227-243 key/value rows per CFID, almost all of them the same URL.
|
||||||
|
Hand-transcribing them into Rust would be 400 lines of string literals that
|
||||||
|
nobody can review and one typo can break; deriving them mechanically from
|
||||||
|
the oracle removes that whole class of error and keeps them regenerable.
|
||||||
|
They are reverse-engineered *data*, not logic — the same reason
|
||||||
|
`openfut-core` loads its content from `data/` rather than from source.
|
||||||
|
|
||||||
|
The values are templated on {advertise}/{bind}/{pow_content_host}/{pow_host}
|
||||||
|
so the adapter stays configurable; baking an address in here would recreate
|
||||||
|
exactly the hardcoding the client/server split removed.
|
||||||
|
|
||||||
|
Correctness is not assumed: the caller substitutes real addresses back in
|
||||||
|
and diffs against the oracle. See verify_config_table.
|
||||||
|
"""
|
||||||
|
import subprocess
|
||||||
|
|
||||||
|
raw = subprocess.run(
|
||||||
|
[sys.executable, os.path.abspath(__file__), "--_config_table"],
|
||||||
|
capture_output=True, text=True, check=True,
|
||||||
|
# Inherit nothing address-shaped; the child sets its own sentinels.
|
||||||
|
env={k: v for k, v in os.environ.items()
|
||||||
|
if not k.startswith(("OPENFUT_", "POW_", "FUT_"))},
|
||||||
|
).stdout
|
||||||
|
table = json.loads(raw)
|
||||||
|
|
||||||
|
def templatise(value):
|
||||||
|
for sentinel, token in SENTINELS:
|
||||||
|
value = value.replace(sentinel, token)
|
||||||
|
# Collapse whole URLs to URL-level tokens where one exists, so the Rust
|
||||||
|
# side builds them in exactly one place (AdapterConfig::utas_base and
|
||||||
|
# friends) instead of re-deriving the shape here. Without this the
|
||||||
|
# helpers become dead code and a hardcoded address in them goes
|
||||||
|
# undetected — verified by mutation testing. Longest first.
|
||||||
|
for whole, token in (
|
||||||
|
("http://{advertise}:8099/", "{utas_base}"),
|
||||||
|
("http://{bind}:42131", "{nucleus_base}"),
|
||||||
|
("http://{pow_content_host}", "{pow_content_url}"),
|
||||||
|
):
|
||||||
|
if value == whole:
|
||||||
|
return token
|
||||||
|
return value
|
||||||
|
|
||||||
|
return {cfid: [[k, templatise(v)] for k, v in rows]
|
||||||
|
for cfid, rows in table.items()}
|
||||||
|
|
||||||
|
|
||||||
|
def verify_config_table(table):
|
||||||
|
"""Substitute the real addresses back and require the oracle's exact rows.
|
||||||
|
|
||||||
|
This is what makes the templated table trustworthy rather than plausible.
|
||||||
|
"""
|
||||||
|
subst = {
|
||||||
|
"{utas_base}": "http://%s:8099/" % ADVERTISE,
|
||||||
|
"{nucleus_base}": "http://%s:42131" % BIND,
|
||||||
|
"{pow_content_url}": "http://%s" % POW_CONTENT_HOST,
|
||||||
|
"{advertise}": ADVERTISE,
|
||||||
|
"{bind}": BIND,
|
||||||
|
"{pow_content_host}": POW_CONTENT_HOST,
|
||||||
|
"{pow_host}": POW_HOST,
|
||||||
|
}
|
||||||
|
|
||||||
|
def render(v):
|
||||||
|
for token, real in subst.items():
|
||||||
|
v = v.replace(token, real)
|
||||||
|
return v
|
||||||
|
|
||||||
|
for cfid, rows in table.items():
|
||||||
|
expected = B.client_config_for(
|
||||||
|
"__no_such_section__" if cfid == "__default__" else cfid)
|
||||||
|
got = [(k, render(v)) for k, v in rows]
|
||||||
|
if got != [(k, v) for k, v in expected]:
|
||||||
|
for (gk, gv), (ek, ev) in zip(got, expected):
|
||||||
|
if (gk, gv) != (ek, ev):
|
||||||
|
sys.exit("config template mismatch in %s: %r -> %r, oracle "
|
||||||
|
"has %r -> %r" % (cfid, gk, gv, ek, ev))
|
||||||
|
sys.exit("config template row-count mismatch in %s: %d vs %d"
|
||||||
|
% (cfid, len(got), len(expected)))
|
||||||
|
print("config table verified against the oracle for %d sections"
|
||||||
|
% len(table))
|
||||||
|
|
||||||
|
|
||||||
|
def frozen_clock():
|
||||||
|
import time as _time
|
||||||
|
original = _time.time
|
||||||
|
_time.time = lambda: float(FIXED_NOW)
|
||||||
|
return original, _time
|
||||||
|
|
||||||
|
|
||||||
|
def write(path, records):
|
||||||
|
body = "".join(json.dumps(r, separators=(",", ":")) + "\n" for r in records)
|
||||||
|
if CHECK_ONLY:
|
||||||
|
if not os.path.exists(path):
|
||||||
|
sys.exit("MISSING: %s has never been generated" % path)
|
||||||
|
with open(path, "r", encoding="utf-8") as fh:
|
||||||
|
if fh.read() != body:
|
||||||
|
sys.exit("STALE: %s does not match the oracle; re-run without "
|
||||||
|
"--check" % path)
|
||||||
|
print("current: %s (%d records)" % (os.path.basename(path), len(records)))
|
||||||
|
return
|
||||||
|
with open(path, "w", encoding="utf-8") as fh:
|
||||||
|
fh.write(body)
|
||||||
|
print("wrote %s (%d records)" % (os.path.basename(path), len(records)))
|
||||||
|
|
||||||
|
|
||||||
|
def write_json(path, obj):
|
||||||
|
body = json.dumps(obj, indent=1, sort_keys=True) + "\n"
|
||||||
|
if CHECK_ONLY:
|
||||||
|
if not os.path.exists(path):
|
||||||
|
sys.exit("MISSING: %s has never been generated" % path)
|
||||||
|
with open(path, "r", encoding="utf-8") as fh:
|
||||||
|
if fh.read() != body:
|
||||||
|
sys.exit("STALE: %s does not match the oracle" % path)
|
||||||
|
print("current: %s" % os.path.basename(path))
|
||||||
|
return
|
||||||
|
with open(path, "w", encoding="utf-8") as fh:
|
||||||
|
fh.write(body)
|
||||||
|
print("wrote %s (%d sections)" % (os.path.basename(path), len(obj)))
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
# The oracle logs every dispatch to stdout; useful live, pure noise here.
|
||||||
|
B.log = lambda *_a, **_k: None
|
||||||
|
|
||||||
|
table = emit_config_table()
|
||||||
|
verify_config_table(table)
|
||||||
|
write_json(os.path.join(HERE, "client_config.json"), table)
|
||||||
|
|
||||||
|
random.seed(0xB1A2E)
|
||||||
|
original_time, time_mod = frozen_clock()
|
||||||
|
try:
|
||||||
|
build()
|
||||||
|
finally:
|
||||||
|
time_mod.time = original_time
|
||||||
|
|
||||||
|
write(os.path.join(HERE, "blaze_transactions.jsonl"), RECORDS)
|
||||||
|
txs = [r for r in RECORDS if r["kind"] == "tx"]
|
||||||
|
frames = sum(len(r["responses"]) for r in txs)
|
||||||
|
print("%d transactions, %d response frames, %d sessions"
|
||||||
|
% (len(txs), frames,
|
||||||
|
len([r for r in RECORDS if r["kind"] == "session"])))
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
main()
|
||||||
@@ -0,0 +1,123 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Capture the roster oracle's responses byte-for-byte.
|
||||||
|
|
||||||
|
generate_roster.py [--check] [host:port]
|
||||||
|
|
||||||
|
Unlike `generate.py`, which imports the Blaze responder and calls its pure
|
||||||
|
functions, this captures over the wire. The roster response is shaped as much by
|
||||||
|
`http.server.BaseHTTPRequestHandler` as by the handler code -- HTTP/1.0 status
|
||||||
|
line, `Server:`/`Date:` injected ahead of the handler's own headers, POST
|
||||||
|
answered without a body -- and only the real socket shows all of that.
|
||||||
|
|
||||||
|
Two fields are volatile and are MASKED rather than recorded:
|
||||||
|
|
||||||
|
Date: changes every second
|
||||||
|
Server: carries the container's Python version
|
||||||
|
|
||||||
|
They are masked, not dropped, so their presence and position are still asserted.
|
||||||
|
The Server string is additionally recorded verbatim under `observed_server`, so
|
||||||
|
a drift between the container's Python and the adapter's `ORACLE_SERVER`
|
||||||
|
constant is visible rather than silent.
|
||||||
|
|
||||||
|
`--check` re-captures and compares. If the oracle is unreachable it FAILS rather
|
||||||
|
than passing: a check that cannot check must not report success.
|
||||||
|
"""
|
||||||
|
import json
|
||||||
|
import os
|
||||||
|
import re
|
||||||
|
import socket
|
||||||
|
import ssl
|
||||||
|
import sys
|
||||||
|
|
||||||
|
HERE = os.path.dirname(os.path.abspath(__file__))
|
||||||
|
OUT = os.path.join(HERE, "roster.json")
|
||||||
|
PATH = "/fifa17/fut/rosterupdate.xml"
|
||||||
|
|
||||||
|
DATE_RE = re.compile(rb"^Date: .+?\r\n", re.M)
|
||||||
|
SERVER_RE = re.compile(rb"^Server: (.+?)\r\n", re.M)
|
||||||
|
|
||||||
|
|
||||||
|
def fetch(host, port, method, body=None):
|
||||||
|
ctx = ssl.SSLContext(ssl.PROTOCOL_TLS_CLIENT)
|
||||||
|
ctx.check_hostname = False
|
||||||
|
ctx.verify_mode = ssl.CERT_NONE
|
||||||
|
ctx.set_ciphers("ALL:@SECLEVEL=0")
|
||||||
|
s = ctx.wrap_socket(socket.create_connection((host, port), timeout=8),
|
||||||
|
server_hostname="fixture")
|
||||||
|
req = "%s %s HTTP/1.1\r\nHost: %s:%d\r\nAccept: */*\r\n" % (method, PATH, host, port)
|
||||||
|
if body is not None:
|
||||||
|
req += "Content-Length: %d\r\n" % len(body)
|
||||||
|
req += "\r\n"
|
||||||
|
s.sendall(req.encode() + (body or b""))
|
||||||
|
out = b""
|
||||||
|
while True:
|
||||||
|
chunk = s.recv(4096)
|
||||||
|
if not chunk:
|
||||||
|
break
|
||||||
|
out += chunk
|
||||||
|
s.close()
|
||||||
|
return out
|
||||||
|
|
||||||
|
|
||||||
|
def capture(host, port):
|
||||||
|
result = {"path": PATH, "responses": {}}
|
||||||
|
servers = set()
|
||||||
|
for method, body in (("GET", None), ("HEAD", None), ("POST", b"probe=1")):
|
||||||
|
raw = fetch(host, port, method, body)
|
||||||
|
m = SERVER_RE.search(raw)
|
||||||
|
if m:
|
||||||
|
servers.add(m.group(1).decode())
|
||||||
|
masked = DATE_RE.sub(b"Date: <MASKED>\r\n", raw)
|
||||||
|
masked = SERVER_RE.sub(b"Server: <MASKED>\r\n", masked)
|
||||||
|
result["responses"][method] = masked.hex()
|
||||||
|
if len(servers) != 1:
|
||||||
|
raise SystemExit("oracle returned inconsistent Server headers: %r" % servers)
|
||||||
|
result["observed_server"] = servers.pop()
|
||||||
|
return result
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
check = "--check" in sys.argv
|
||||||
|
args = [a for a in sys.argv[1:] if not a.startswith("--")]
|
||||||
|
host, port = (args[0].split(":") if args else ("127.0.0.1", "8081"))[0], \
|
||||||
|
int((args[0].split(":")[1] if args and ":" in args[0] else "8081"))
|
||||||
|
|
||||||
|
try:
|
||||||
|
fresh = capture(host, port)
|
||||||
|
except Exception as e:
|
||||||
|
# Explicitly a failure. A --check that silently passes when it could not
|
||||||
|
# reach the oracle is exactly the class of self-confirming tooling this
|
||||||
|
# project has been bitten by repeatedly.
|
||||||
|
raise SystemExit("cannot reach the roster oracle at %s:%d (%s). "
|
||||||
|
"Refusing to report success." % (host, port, e))
|
||||||
|
|
||||||
|
if check:
|
||||||
|
if not os.path.exists(OUT):
|
||||||
|
raise SystemExit("no fixture at %s -- run without --check first" % OUT)
|
||||||
|
with open(OUT) as f:
|
||||||
|
stored = json.load(f)
|
||||||
|
if stored.get("responses") != fresh["responses"]:
|
||||||
|
for m in sorted(set(stored.get("responses", {})) | set(fresh["responses"])):
|
||||||
|
a = stored.get("responses", {}).get(m)
|
||||||
|
b = fresh["responses"].get(m)
|
||||||
|
if a != b:
|
||||||
|
print("MISMATCH %s\n stored: %s\n live : %s" % (m, a, b))
|
||||||
|
raise SystemExit("roster fixtures differ from the live oracle")
|
||||||
|
if stored.get("observed_server") != fresh["observed_server"]:
|
||||||
|
raise SystemExit(
|
||||||
|
"the oracle's Server header changed: %r -> %r.\n"
|
||||||
|
"Update roster::ORACLE_SERVER and regenerate."
|
||||||
|
% (stored.get("observed_server"), fresh["observed_server"]))
|
||||||
|
print("roster fixtures match the live oracle (%d responses, server=%r)"
|
||||||
|
% (len(fresh["responses"]), fresh["observed_server"]))
|
||||||
|
return
|
||||||
|
|
||||||
|
with open(OUT, "w") as f:
|
||||||
|
json.dump(fresh, f, indent=2, sort_keys=True)
|
||||||
|
f.write("\n")
|
||||||
|
print("wrote %s (%d responses, server=%r)"
|
||||||
|
% (OUT, len(fresh["responses"]), fresh["observed_server"]))
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
main()
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
{
|
||||||
|
"127.0.0.1": "485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f786d6c0d0a436f6e74656e742d4c656e6774683a203331350d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a3c3f786d6c2076657273696f6e3d22312e302220656e636f64696e673d225554462d38223f3e0a3c736572766572696e7374616e6365696e666f3e0a093c61646472657373206d656d6265723d2230223e0a09093c76616c753e0a0909093c686f73746e616d653e3132372e302e302e313c2f686f73746e616d653e0a0909093c69703e323133303730363433333c2f69703e0a0909093c706f72743e34323133303c2f706f72743e0a09093c2f76616c753e0a093c2f616464726573733e0a093c7365637572653e303c2f7365637572653e0a093c747269616c736572766963656e616d653e3c2f747269616c736572766963656e616d653e0a093c64656661756c74646e73616464726573733e303c2f64656661756c74646e73616464726573733e0a3c2f736572766572696e7374616e6365696e666f3e0a",
|
||||||
|
"192.0.2.1": "485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f786d6c0d0a436f6e74656e742d4c656e6774683a203331350d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a3c3f786d6c2076657273696f6e3d22312e302220656e636f64696e673d225554462d38223f3e0a3c736572766572696e7374616e6365696e666f3e0a093c61646472657373206d656d6265723d2230223e0a09093c76616c753e0a0909093c686f73746e616d653e3139322e302e322e313c2f686f73746e616d653e0a0909093c69703e333232313232353938353c2f69703e0a0909093c706f72743e34323133303c2f706f72743e0a09093c2f76616c753e0a093c2f616464726573733e0a093c7365637572653e303c2f7365637572653e0a093c747269616c736572766963656e616d653e3c2f747269616c736572766963656e616d653e0a093c64656661756c74646e73616464726573733e303c2f64656661756c74646e73616464726573733e0a3c2f736572766572696e7374616e6365696e666f3e0a",
|
||||||
|
"198.51.100.7": "485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f786d6c0d0a436f6e74656e742d4c656e6774683a203331380d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a3c3f786d6c2076657273696f6e3d22312e302220656e636f64696e673d225554462d38223f3e0a3c736572766572696e7374616e6365696e666f3e0a093c61646472657373206d656d6265723d2230223e0a09093c76616c753e0a0909093c686f73746e616d653e3139382e35312e3130302e373c2f686f73746e616d653e0a0909093c69703e333332353235363731313c2f69703e0a0909093c706f72743e34323133303c2f706f72743e0a09093c2f76616c753e0a093c2f616464726573733e0a093c7365637572653e303c2f7365637572653e0a093c747269616c736572766963656e616d653e3c2f747269616c736572766963656e616d653e0a093c64656661756c74646e73616464726573733e303c2f64656661756c74646e73616464726573733e0a3c2f736572766572696e7374616e6365696e666f3e0a",
|
||||||
|
"203.0.113.42": "485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f786d6c0d0a436f6e74656e742d4c656e6774683a203331380d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a3c3f786d6c2076657273696f6e3d22312e302220656e636f64696e673d225554462d38223f3e0a3c736572766572696e7374616e6365696e666f3e0a093c61646472657373206d656d6265723d2230223e0a09093c76616c753e0a0909093c686f73746e616d653e3230332e302e3131332e34323c2f686f73746e616d653e0a0909093c69703e333430353830333831383c2f69703e0a0909093c706f72743e34323133303c2f706f72743e0a09093c2f76616c753e0a093c2f616464726573733e0a093c7365637572653e303c2f7365637572653e0a093c747269616c736572766963656e616d653e3c2f747269616c736572766963656e616d653e0a093c64656661756c74646e73616464726573733e303c2f64656661756c74646e73616464726573733e0a3c2f736572766572696e7374616e6365696e666f3e0a"
|
||||||
|
}
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
{
|
||||||
|
"observed_server": "BaseHTTP/0.6 Python/3.12.13",
|
||||||
|
"path": "/fifa17/fut/rosterupdate.xml",
|
||||||
|
"responses": {
|
||||||
|
"GET": "485454502f312e3020323030204f4b0d0a5365727665723a203c4d41534b45443e0d0a446174653a203c4d41534b45443e0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f786d6c0d0a436f6e74656e742d4c656e6774683a2036370d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a3c3f786d6c2076657273696f6e3d22312e302220656e636f64696e673d227574662d38223f3e0a3c726f737465727570646174652076657273696f6e3d2230222f3e0a",
|
||||||
|
"HEAD": "485454502f312e3020323030204f4b0d0a5365727665723a203c4d41534b45443e0d0a446174653a203c4d41534b45443e0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f786d6c0d0a436f6e74656e742d4c656e6774683a2036370d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a",
|
||||||
|
"POST": "485454502f312e3020323030204f4b0d0a5365727665723a203c4d41534b45443e0d0a446174653a203c4d41534b45443e0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f786d6c0d0a436f6e74656e742d4c656e6774683a2036370d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a"
|
||||||
|
}
|
||||||
|
}
|
||||||
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
@@ -0,0 +1,14 @@
|
|||||||
|
MARKER at-player-search 19:03:01 UTC
|
||||||
|
watermark=13
|
||||||
|
MARKER NO_FILTER 19:04:35 UTC
|
||||||
|
MARKER GOLD 19:16:44 UTC
|
||||||
|
NOTE: the FIFA 17 My Squad UI labels this filter SPECIAL, not Rare. Captured under label SPECIAL.
|
||||||
|
MARKER SPECIAL 19:21:05 UTC
|
||||||
|
MARKER POSITION_ST 19:22:00 UTC
|
||||||
|
MARKER NATION_ARGENTINA 19:22:53 UTC
|
||||||
|
MARKER LEAGUE_PREMIER 19:23:34 UTC
|
||||||
|
MARKER CLUB_CHELSEA 19:24:34 UTC
|
||||||
|
MARKER GOLD_PLUS_ST 19:25:26 UTC
|
||||||
|
MARKER LEAGUE_PLUS_ST 19:27:27 UTC
|
||||||
|
MARKER PAGINATION 19:28:49 UTC
|
||||||
|
NOTE: no sort control exists in the My Squad UI; sort=desc is a client constant.
|
||||||
@@ -0,0 +1,84 @@
|
|||||||
|
{
|
||||||
|
"routes": {
|
||||||
|
"accountInfo": {
|
||||||
|
"body_len": 2,
|
||||||
|
"fields": {
|
||||||
|
"keys": []
|
||||||
|
},
|
||||||
|
"sha256": "44136fa355b3678a1146ad16f7e8649e94fb4fc21fe77e8310c060f61caaff8a",
|
||||||
|
"status": 200
|
||||||
|
},
|
||||||
|
"activeSquad": {
|
||||||
|
"body_len": 8034,
|
||||||
|
"fields": {
|
||||||
|
"formation": "f442",
|
||||||
|
"id": 0,
|
||||||
|
"players.count": 23,
|
||||||
|
"slots": {
|
||||||
|
"0": 100000003,
|
||||||
|
"1": 100000006,
|
||||||
|
"10": 100000010,
|
||||||
|
"11": 0,
|
||||||
|
"12": 0,
|
||||||
|
"13": 0,
|
||||||
|
"14": 0,
|
||||||
|
"15": 0,
|
||||||
|
"16": 0,
|
||||||
|
"17": 0,
|
||||||
|
"18": 0,
|
||||||
|
"19": 0,
|
||||||
|
"2": 100000005,
|
||||||
|
"20": 0,
|
||||||
|
"21": 0,
|
||||||
|
"22": 0,
|
||||||
|
"3": 100000008,
|
||||||
|
"4": 100000007,
|
||||||
|
"5": 100000002,
|
||||||
|
"6": 100000004,
|
||||||
|
"7": 100000009,
|
||||||
|
"8": 100000001,
|
||||||
|
"9": 100000025
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"sha256": "07e330ed358fbefe31379cd2462aaac4bdc9c85ee28b7500dd2d963e5ea565bd",
|
||||||
|
"status": 200
|
||||||
|
},
|
||||||
|
"credits": {
|
||||||
|
"body_len": 148,
|
||||||
|
"fields": {
|
||||||
|
"credits": 28112944
|
||||||
|
},
|
||||||
|
"sha256": "0a5f3bac80c3a8ee6f088ccf180f5fdcbcbe8a2ef19c7026e4f21876016d7786",
|
||||||
|
"status": 200
|
||||||
|
},
|
||||||
|
"tradePile": {
|
||||||
|
"body_len": 862,
|
||||||
|
"fields": {
|
||||||
|
"auctionInfo.count": 1
|
||||||
|
},
|
||||||
|
"sha256": "b42bab98202209bd8309beb0eca73dba471688e69fef3e014b59901fbc21fe04",
|
||||||
|
"status": 200
|
||||||
|
},
|
||||||
|
"unassigned": {
|
||||||
|
"body_len": 16,
|
||||||
|
"fields": {
|
||||||
|
"itemData.count": 0
|
||||||
|
},
|
||||||
|
"sha256": "873f8bba8baf9c573fc51b54d100c357b3bf0caeb2ccd104245c295e073cf342",
|
||||||
|
"status": 200
|
||||||
|
},
|
||||||
|
"userMassInfo": {
|
||||||
|
"body_len": 8929,
|
||||||
|
"fields": {
|
||||||
|
"clubAbbr": "OFC",
|
||||||
|
"clubName": "OpenFUT",
|
||||||
|
"personaId": 33068179,
|
||||||
|
"trophies": 0
|
||||||
|
},
|
||||||
|
"sha256": "a616aca1742263c47ade9409693e66ec13b50114e608d88bb94141ce80237b66",
|
||||||
|
"status": 200
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"unix": 1786476617.899911,
|
||||||
|
"upstream": "127.0.0.1:8099"
|
||||||
|
}
|
||||||
@@ -0,0 +1,84 @@
|
|||||||
|
{
|
||||||
|
"routes": {
|
||||||
|
"accountInfo": {
|
||||||
|
"body_len": 2,
|
||||||
|
"fields": {
|
||||||
|
"keys": []
|
||||||
|
},
|
||||||
|
"sha256": "44136fa355b3678a1146ad16f7e8649e94fb4fc21fe77e8310c060f61caaff8a",
|
||||||
|
"status": 200
|
||||||
|
},
|
||||||
|
"activeSquad": {
|
||||||
|
"body_len": 8034,
|
||||||
|
"fields": {
|
||||||
|
"formation": "f442",
|
||||||
|
"id": 0,
|
||||||
|
"players.count": 23,
|
||||||
|
"slots": {
|
||||||
|
"0": 100000003,
|
||||||
|
"1": 100000006,
|
||||||
|
"10": 100000010,
|
||||||
|
"11": 0,
|
||||||
|
"12": 0,
|
||||||
|
"13": 0,
|
||||||
|
"14": 0,
|
||||||
|
"15": 0,
|
||||||
|
"16": 0,
|
||||||
|
"17": 0,
|
||||||
|
"18": 0,
|
||||||
|
"19": 0,
|
||||||
|
"2": 100000005,
|
||||||
|
"20": 0,
|
||||||
|
"21": 0,
|
||||||
|
"22": 0,
|
||||||
|
"3": 100000008,
|
||||||
|
"4": 100000007,
|
||||||
|
"5": 100000002,
|
||||||
|
"6": 100000004,
|
||||||
|
"7": 100000009,
|
||||||
|
"8": 100000001,
|
||||||
|
"9": 100000025
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"sha256": "07e330ed358fbefe31379cd2462aaac4bdc9c85ee28b7500dd2d963e5ea565bd",
|
||||||
|
"status": 200
|
||||||
|
},
|
||||||
|
"credits": {
|
||||||
|
"body_len": 148,
|
||||||
|
"fields": {
|
||||||
|
"credits": 28112944
|
||||||
|
},
|
||||||
|
"sha256": "0a5f3bac80c3a8ee6f088ccf180f5fdcbcbe8a2ef19c7026e4f21876016d7786",
|
||||||
|
"status": 200
|
||||||
|
},
|
||||||
|
"tradePile": {
|
||||||
|
"body_len": 862,
|
||||||
|
"fields": {
|
||||||
|
"auctionInfo.count": 1
|
||||||
|
},
|
||||||
|
"sha256": "b42bab98202209bd8309beb0eca73dba471688e69fef3e014b59901fbc21fe04",
|
||||||
|
"status": 200
|
||||||
|
},
|
||||||
|
"unassigned": {
|
||||||
|
"body_len": 16,
|
||||||
|
"fields": {
|
||||||
|
"itemData.count": 0
|
||||||
|
},
|
||||||
|
"sha256": "873f8bba8baf9c573fc51b54d100c357b3bf0caeb2ccd104245c295e073cf342",
|
||||||
|
"status": 200
|
||||||
|
},
|
||||||
|
"userMassInfo": {
|
||||||
|
"body_len": 8929,
|
||||||
|
"fields": {
|
||||||
|
"clubAbbr": "OFC",
|
||||||
|
"clubName": "OpenFUT",
|
||||||
|
"personaId": 33068179,
|
||||||
|
"trophies": 0
|
||||||
|
},
|
||||||
|
"sha256": "a616aca1742263c47ade9409693e66ec13b50114e608d88bb94141ce80237b66",
|
||||||
|
"status": 200
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"unix": 1786474768.2925124,
|
||||||
|
"upstream": "127.0.0.1:8099"
|
||||||
|
}
|
||||||
File diff suppressed because one or more lines are too long
@@ -0,0 +1 @@
|
|||||||
|
{"squad": [{"rating": 89, "chemistry": 59, "formation": "f442", "id": 0, "squadName": "OpenFUT", "squadType": "REGULAR_SQUAD"}]}
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
{"id": 0, "custom": "[0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,50,50,0,50,40,65,0,65,50,50,1]", "squadName": "OpenFUT", "chemistry": 49, "starRating": 90, "rating": 90, "formation": "f433", "squadType": "REGULAR_SQUAD", "manager": [{"id": 100000427, "dream": false}], "players": [{"index": 0, "itemData": {"id": 100000003, "dream": false}, "kitNumber": 1}, {"index": 1, "itemData": {"id": 100000006, "dream": false}, "kitNumber": 4}, {"index": 2, "itemData": {"id": 100000005, "dream": false}, "kitNumber": 3}, {"index": 3, "itemData": {"id": 100000008, "dream": false}, "kitNumber": 6}, {"index": 4, "itemData": {"id": 100000007, "dream": false}, "kitNumber": 5}, {"index": 5, "itemData": {"id": 100000002, "dream": false}, "kitNumber": 9}, {"index": 6, "itemData": {"id": 100000004, "dream": false}, "kitNumber": 2}, {"index": 7, "itemData": {"id": 100000009, "dream": false}, "kitNumber": 7}, {"index": 8, "itemData": {"id": 100000010, "dream": false}, "kitNumber": 10}, {"index": 9, "itemData": {"id": 100000025, "dream": false}, "kitNumber": 11}, {"index": 10, "itemData": {"id": 100000001, "dream": false}, "kitNumber": 8}, {"index": 11, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 12, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 13, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 14, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 15, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 16, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 17, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 18, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 19, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 20, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 21, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 22, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}], "captain": 100000001, "kicktakers": [{"index": 0, "id": 100000001, "dream": false}, {"index": 1, "id": 100000001, "dream": false}, {"index": 2, "id": 100000001, "dream": false}, {"index": 3, "id": 100000001, "dream": false}, {"index": 4, "id": 100000001, "dream": false}]}
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
{"id":0,"custom":"[0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,50,50,0,50,40,65,0,65,50,50,1]","squadName":"OpenFUT","chemistry":52,"starRating":90,"rating":90,"formation":"f442","squadType":"REGULAR_SQUAD","manager":[{"id":100000427,"dream":false}],"players":[{"index":0,"itemData":{"id":100000003,"dream":false},"kitNumber":1},{"index":1,"itemData":{"id":100000010,"dream":false},"kitNumber":10},{"index":2,"itemData":{"id":100000005,"dream":false},"kitNumber":3},{"index":3,"itemData":{"id":100000008,"dream":false},"kitNumber":6},{"index":4,"itemData":{"id":100000007,"dream":false},"kitNumber":5},{"index":5,"itemData":{"id":100000006,"dream":false},"kitNumber":4},{"index":6,"itemData":{"id":100000004,"dream":false},"kitNumber":2},{"index":7,"itemData":{"id":100000009,"dream":false},"kitNumber":7},{"index":8,"itemData":{"id":100000001,"dream":false},"kitNumber":8},{"index":9,"itemData":{"id":100000002,"dream":false},"kitNumber":9},{"index":10,"itemData":{"id":100000025,"dream":false},"kitNumber":11},{"index":11,"itemData":{"id":0,"dream":false},"kitNumber":0},{"index":12,"itemData":{"id":0,"dream":false},"kitNumber":0},{"index":13,"itemData":{"id":0,"dream":false},"kitNumber":0},{"index":14,"itemData":{"id":0,"dream":false},"kitNumber":0},{"index":15,"itemData":{"id":0,"dream":false},"kitNumber":0},{"index":16,"itemData":{"id":0,"dream":false},"kitNumber":0},{"index":17,"itemData":{"id":0,"dream":false},"kitNumber":0},{"index":18,"itemData":{"id":0,"dream":false},"kitNumber":0},{"index":19,"itemData":{"id":0,"dream":false},"kitNumber":0},{"index":20,"itemData":{"id":0,"dream":false},"kitNumber":0},{"index":21,"itemData":{"id":0,"dream":false},"kitNumber":0},{"index":22,"itemData":{"id":0,"dream":false},"kitNumber":0}],"captain":100000001,"kicktakers":[{"index":0,"id":100000001,"dream":false},{"index":1,"id":100000001,"dream":false},{"index":2,"id":100000001,"dream":false},{"index":3,"id":100000001,"dream":false},{"index":4,"id":100000001,"dream":false}]}
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
{"id": 0, "custom": "[0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,50,50,0,50,40,65,0,65,50,50,1]", "squadName": "OpenFUT", "chemistry": 58, "starRating": 90, "rating": 90, "formation": "f442", "squadType": "REGULAR_SQUAD", "manager": [{"id": 100000427, "dream": false}], "players": [{"index": 0, "itemData": {"id": 100000003, "dream": false}, "kitNumber": 1}, {"index": 1, "itemData": {"id": 100000006, "dream": false}, "kitNumber": 4}, {"index": 2, "itemData": {"id": 100000005, "dream": false}, "kitNumber": 3}, {"index": 3, "itemData": {"id": 100000008, "dream": false}, "kitNumber": 6}, {"index": 4, "itemData": {"id": 100000007, "dream": false}, "kitNumber": 5}, {"index": 5, "itemData": {"id": 100000002, "dream": false}, "kitNumber": 9}, {"index": 6, "itemData": {"id": 100000004, "dream": false}, "kitNumber": 2}, {"index": 7, "itemData": {"id": 100000009, "dream": false}, "kitNumber": 7}, {"index": 8, "itemData": {"id": 100000001, "dream": false}, "kitNumber": 8}, {"index": 9, "itemData": {"id": 100000010, "dream": false}, "kitNumber": 10}, {"index": 10, "itemData": {"id": 100000025, "dream": false}, "kitNumber": 11}, {"index": 11, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 12, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 13, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 14, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 15, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 16, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 17, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 18, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 19, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 20, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 21, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 22, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}], "captain": 100000001, "kicktakers": [{"index": 0, "id": 100000001, "dream": false}, {"index": 1, "id": 100000001, "dream": false}, {"index": 2, "id": 100000001, "dream": false}, {"index": 3, "id": 100000001, "dream": false}, {"index": 4, "id": 100000001, "dream": false}]}
|
||||||
File diff suppressed because one or more lines are too long
@@ -0,0 +1,84 @@
|
|||||||
|
{
|
||||||
|
"routes": {
|
||||||
|
"accountInfo": {
|
||||||
|
"body_len": 2,
|
||||||
|
"fields": {
|
||||||
|
"keys": []
|
||||||
|
},
|
||||||
|
"sha256": "44136fa355b3678a1146ad16f7e8649e94fb4fc21fe77e8310c060f61caaff8a",
|
||||||
|
"status": 200
|
||||||
|
},
|
||||||
|
"activeSquad": {
|
||||||
|
"body_len": 8034,
|
||||||
|
"fields": {
|
||||||
|
"formation": "f442",
|
||||||
|
"id": 0,
|
||||||
|
"players.count": 23,
|
||||||
|
"slots": {
|
||||||
|
"0": 100000003,
|
||||||
|
"1": 100000006,
|
||||||
|
"10": 100000010,
|
||||||
|
"11": 0,
|
||||||
|
"12": 0,
|
||||||
|
"13": 0,
|
||||||
|
"14": 0,
|
||||||
|
"15": 0,
|
||||||
|
"16": 0,
|
||||||
|
"17": 0,
|
||||||
|
"18": 0,
|
||||||
|
"19": 0,
|
||||||
|
"2": 100000005,
|
||||||
|
"20": 0,
|
||||||
|
"21": 0,
|
||||||
|
"22": 0,
|
||||||
|
"3": 100000008,
|
||||||
|
"4": 100000007,
|
||||||
|
"5": 100000002,
|
||||||
|
"6": 100000004,
|
||||||
|
"7": 100000009,
|
||||||
|
"8": 100000001,
|
||||||
|
"9": 100000025
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"sha256": "07e330ed358fbefe31379cd2462aaac4bdc9c85ee28b7500dd2d963e5ea565bd",
|
||||||
|
"status": 200
|
||||||
|
},
|
||||||
|
"credits": {
|
||||||
|
"body_len": 148,
|
||||||
|
"fields": {
|
||||||
|
"credits": 28112944
|
||||||
|
},
|
||||||
|
"sha256": "0a5f3bac80c3a8ee6f088ccf180f5fdcbcbe8a2ef19c7026e4f21876016d7786",
|
||||||
|
"status": 200
|
||||||
|
},
|
||||||
|
"tradePile": {
|
||||||
|
"body_len": 862,
|
||||||
|
"fields": {
|
||||||
|
"auctionInfo.count": 1
|
||||||
|
},
|
||||||
|
"sha256": "b42bab98202209bd8309beb0eca73dba471688e69fef3e014b59901fbc21fe04",
|
||||||
|
"status": 200
|
||||||
|
},
|
||||||
|
"unassigned": {
|
||||||
|
"body_len": 16,
|
||||||
|
"fields": {
|
||||||
|
"itemData.count": 0
|
||||||
|
},
|
||||||
|
"sha256": "873f8bba8baf9c573fc51b54d100c357b3bf0caeb2ccd104245c295e073cf342",
|
||||||
|
"status": 200
|
||||||
|
},
|
||||||
|
"userMassInfo": {
|
||||||
|
"body_len": 8929,
|
||||||
|
"fields": {
|
||||||
|
"clubAbbr": "OFC",
|
||||||
|
"clubName": "OpenFUT",
|
||||||
|
"personaId": 33068179,
|
||||||
|
"trophies": 0
|
||||||
|
},
|
||||||
|
"sha256": "a616aca1742263c47ade9409693e66ec13b50114e608d88bb94141ce80237b66",
|
||||||
|
"status": 200
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"unix": 1786472465.339646,
|
||||||
|
"upstream": "127.0.0.1:8099"
|
||||||
|
}
|
||||||
@@ -0,0 +1,84 @@
|
|||||||
|
{
|
||||||
|
"routes": {
|
||||||
|
"accountInfo": {
|
||||||
|
"body_len": 2,
|
||||||
|
"fields": {
|
||||||
|
"keys": []
|
||||||
|
},
|
||||||
|
"sha256": "44136fa355b3678a1146ad16f7e8649e94fb4fc21fe77e8310c060f61caaff8a",
|
||||||
|
"status": 200
|
||||||
|
},
|
||||||
|
"activeSquad": {
|
||||||
|
"body_len": 8034,
|
||||||
|
"fields": {
|
||||||
|
"formation": "f442",
|
||||||
|
"id": 0,
|
||||||
|
"players.count": 23,
|
||||||
|
"slots": {
|
||||||
|
"0": 100000003,
|
||||||
|
"1": 100000010,
|
||||||
|
"10": 100000001,
|
||||||
|
"11": 100000002,
|
||||||
|
"12": 0,
|
||||||
|
"13": 0,
|
||||||
|
"14": 0,
|
||||||
|
"15": 0,
|
||||||
|
"16": 0,
|
||||||
|
"17": 0,
|
||||||
|
"18": 0,
|
||||||
|
"19": 0,
|
||||||
|
"2": 100000009,
|
||||||
|
"20": 0,
|
||||||
|
"21": 0,
|
||||||
|
"22": 0,
|
||||||
|
"3": 100000008,
|
||||||
|
"4": 100000007,
|
||||||
|
"5": 100000006,
|
||||||
|
"6": 100000005,
|
||||||
|
"7": 100000004,
|
||||||
|
"8": 100000025,
|
||||||
|
"9": 0
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"sha256": "768bb0584ad953ac5f088ad029f161d302ee1be3a63826eb186405acaf1b6232",
|
||||||
|
"status": 200
|
||||||
|
},
|
||||||
|
"credits": {
|
||||||
|
"body_len": 148,
|
||||||
|
"fields": {
|
||||||
|
"credits": 28020656
|
||||||
|
},
|
||||||
|
"sha256": "8d39fee51c24ddee9f12d98d7833af6cd3d3399a0e7567ab7062945a1180e30f",
|
||||||
|
"status": 200
|
||||||
|
},
|
||||||
|
"tradePile": {
|
||||||
|
"body_len": 862,
|
||||||
|
"fields": {
|
||||||
|
"auctionInfo.count": 1
|
||||||
|
},
|
||||||
|
"sha256": "1575046afb8ca60c76de64427ee0c70e1d4ca2da032819a60db95d72d272d11d",
|
||||||
|
"status": 200
|
||||||
|
},
|
||||||
|
"unassigned": {
|
||||||
|
"body_len": 16,
|
||||||
|
"fields": {
|
||||||
|
"itemData.count": 0
|
||||||
|
},
|
||||||
|
"sha256": "873f8bba8baf9c573fc51b54d100c357b3bf0caeb2ccd104245c295e073cf342",
|
||||||
|
"status": 200
|
||||||
|
},
|
||||||
|
"userMassInfo": {
|
||||||
|
"body_len": 8929,
|
||||||
|
"fields": {
|
||||||
|
"clubAbbr": "OFC",
|
||||||
|
"clubName": "OpenFUT",
|
||||||
|
"personaId": 33068179,
|
||||||
|
"trophies": 0
|
||||||
|
},
|
||||||
|
"sha256": "3d89d0497661fc62f107081208a14c4fa5753ee4e6482eeda825fe4b622f871f",
|
||||||
|
"status": 200
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"unix": 1786472102.908128,
|
||||||
|
"upstream": "127.0.0.1:8099"
|
||||||
|
}
|
||||||
Executable
+114
@@ -0,0 +1,114 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
# FIFA 17 squad-adapter mutation battery.
|
||||||
|
#
|
||||||
|
# Each mutation injects a specific WRONG behaviour into the committed source,
|
||||||
|
# runs the one test that defends the invariant, and requires that test to FAIL
|
||||||
|
# (non-zero exit) — i.e. the mutant is killed. The source is reverted via
|
||||||
|
# `git checkout` after every mutation, so the tree is left untouched.
|
||||||
|
#
|
||||||
|
# A mutant that SURVIVES (its guard test still passes) means the invariant is
|
||||||
|
# not actually defended; the battery then exits non-zero.
|
||||||
|
#
|
||||||
|
# Run from the adapter crate root: bash mutation-battery.sh
|
||||||
|
set -u
|
||||||
|
cd "$(dirname "$0")"
|
||||||
|
|
||||||
|
FUT=src/fut
|
||||||
|
PASS=0
|
||||||
|
FAIL=0
|
||||||
|
declare -a SURVIVORS=()
|
||||||
|
|
||||||
|
# mutate <file> <literal-old> <literal-new> (literal, multiline-safe)
|
||||||
|
mutate() {
|
||||||
|
OLD="$2" NEW="$3" perl -0777 -pi -e \
|
||||||
|
's/\Q$ENV{OLD}\E/$ENV{NEW}/g or die "MUTATION PATTERN NOT FOUND in '"$1"'\n"' "$1"
|
||||||
|
}
|
||||||
|
|
||||||
|
# kill <n> <label> <test-filter> <file> <old> <new>
|
||||||
|
kill_test() {
|
||||||
|
local n="$1" label="$2" filter="$3" file="$4" old="$5" new="$6"
|
||||||
|
git checkout -- "$file"
|
||||||
|
mutate "$file" "$old" "$new" || { echo " [#$n] SETUP ERROR"; FAIL=$((FAIL+1)); SURVIVORS+=("#$n $label (setup)"); return; }
|
||||||
|
if cargo test --quiet "$filter" >/dev/null 2>&1; then
|
||||||
|
echo " [#$n] SURVIVED — $label (test '$filter' still passed)"
|
||||||
|
FAIL=$((FAIL+1)); SURVIVORS+=("#$n $label")
|
||||||
|
else
|
||||||
|
echo " [#$n] killed — $label"
|
||||||
|
PASS=$((PASS+1))
|
||||||
|
fi
|
||||||
|
git checkout -- "$file"
|
||||||
|
}
|
||||||
|
|
||||||
|
echo "== FIFA17 squad adapter mutation battery =="
|
||||||
|
|
||||||
|
kill_test 1 "kitNumber keyed by slot index, not owned item" \
|
||||||
|
kit_number_is_keyed_by_owned_item_not_slot "$FUT/squad_ext.rs" \
|
||||||
|
'(s.owned_card_id.clone(), s.kit_number)' '(s.index.to_string(), s.kit_number)'
|
||||||
|
|
||||||
|
kill_test 2 "captain emitted using resourceId (asset), not wire id" \
|
||||||
|
fresh_projects_full_23_slot_array_with_captain_wire_id "$FUT/squad_projection.rs" \
|
||||||
|
'captain_wire = id.item_id as i64;' 'captain_wire = id.asset_id as i64;'
|
||||||
|
|
||||||
|
kill_test 3 "client chemistry silently reconciled (shadow lost)" \
|
||||||
|
swap_moves_two_players_with_their_kits_and_round_trips "$FUT/squad_projection.rs" \
|
||||||
|
'"chemistry": ext.client_reported.chemistry,' '"chemistry": 0,'
|
||||||
|
|
||||||
|
kill_test 4 "custom[] regenerated instead of round-tripped verbatim" \
|
||||||
|
custom_is_preserved_byte_for_byte "$FUT/squad_ext.rs" \
|
||||||
|
'custom: put.custom.clone(),' 'custom: Some("[]".to_string()),'
|
||||||
|
|
||||||
|
kill_test 5 "index derived (zeroed) instead of round-tripped" \
|
||||||
|
baseline_projects_the_known_squad_round_trip "$FUT/squad.rs" \
|
||||||
|
'index: p.index,' 'index: 0,'
|
||||||
|
|
||||||
|
kill_test 6 "stale extension accepted and projected" \
|
||||||
|
stale_is_never_applied "$FUT/squad_projection.rs" \
|
||||||
|
'SquadExtInput::Stale(_) => return Ok(SquadProjection::Stale),' 'SquadExtInput::Stale(ext) => ext,'
|
||||||
|
|
||||||
|
kill_test 7 "missing extension fabricates default fields" \
|
||||||
|
missing_is_explicit_never_fabricated "$FUT/squad_projection.rs" \
|
||||||
|
'SquadExtInput::Missing => return Ok(SquadProjection::Missing),' \
|
||||||
|
'SquadExtInput::Missing => return Ok(SquadProjection::Projected(json!({"custom":"[]","manager":[]}))),'
|
||||||
|
|
||||||
|
kill_test 8 "shaper fabricates asset id, bypassing real FIFA identity" \
|
||||||
|
shapes_real_identity_and_reverse_entity_ids "$FUT/item.rs" \
|
||||||
|
'let asset = id.asset_id;' 'let asset = 0;'
|
||||||
|
|
||||||
|
kill_test 9 "duplicate definition collapses owned instances (id=asset)" \
|
||||||
|
two_owned_copies_of_one_definition_stay_distinct_on_the_wire "$FUT/item.rs" \
|
||||||
|
'"id": id.item_id,' '"id": id.asset_id,'
|
||||||
|
|
||||||
|
kill_test 10 "PUT treated as a partial slot diff (drops slots)" \
|
||||||
|
full_replacement_carries_every_occupied_slot_no_diff "$FUT/squad.rs" \
|
||||||
|
'if p.item_data.id == 0 {' 'if p.item_data.id == 0 || p.index > 1 {'
|
||||||
|
|
||||||
|
kill_test 11 "FIFA wire item id stored in canonical replacement" \
|
||||||
|
full_replacement_carries_every_occupied_slot_no_diff "$FUT/squad.rs" \
|
||||||
|
'ProposedSlot {
|
||||||
|
owned_card_id,' 'ProposedSlot {
|
||||||
|
owned_card_id: p.item_data.id.to_string(),'
|
||||||
|
|
||||||
|
kill_test 12 "projector rebuilds items independently of shared shaper" \
|
||||||
|
persisted_read_round_trips_via_reconstructed_canonical_and_extension "$FUT/squad_projection.rs" \
|
||||||
|
'"itemData": shape_item(
|
||||||
|
item,
|
||||||
|
id,
|
||||||
|
ent,
|
||||||
|
ident.discard_value(item),
|
||||||
|
item.contract_matches.unwrap_or(PACK_FRESH_CONTRACT_MATCHES),
|
||||||
|
),' '"itemData": json!({"id": id.item_id}),'
|
||||||
|
|
||||||
|
kill_test 13 "extension schema version ignored on read" \
|
||||||
|
unknown_schema_version_is_rejected_not_coerced "$FUT/squad_ext.rs" \
|
||||||
|
'if schema_version != EXT_SCHEMA_VERSION {' 'if false {'
|
||||||
|
|
||||||
|
kill_test 14 "player state keyed by CardDefinitionId not OwnedItemId" \
|
||||||
|
two_owned_copies_of_one_definition_project_as_distinct_players "$FUT/squad_projection.rs" \
|
||||||
|
'.get(&slot.owned_card_id)' '.get(&item.card_id)'
|
||||||
|
|
||||||
|
echo "== mutants killed: $PASS / $((PASS+FAIL)) =="
|
||||||
|
if [ "$FAIL" -ne 0 ]; then
|
||||||
|
printf 'SURVIVORS:\n'; printf ' - %s\n' "${SURVIVORS[@]}"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
echo "all mutants killed"
|
||||||
@@ -0,0 +1,177 @@
|
|||||||
|
//! `Util::fetchClientConfig` tables.
|
||||||
|
//!
|
||||||
|
//! Between 227 and 243 key/value rows per CFID, overwhelmingly the same RS4
|
||||||
|
//! base URL repeated across 212 endpoint keys. The client resolves a per-call
|
||||||
|
//! key (`FUT_RS4_URL_<CALL>`) before a per-module one
|
||||||
|
//! (`FUT_RS4_APIURL_<MODULE>`), and any call left unresolved falls back to a
|
||||||
|
//! real (dead) EA host — which is what produced "there has been an error
|
||||||
|
//! connecting to FIFA 17 Ultimate Team" mid-session when only the boot subset
|
||||||
|
//! was served. The table has to be complete, not representative.
|
||||||
|
//!
|
||||||
|
//! # Why this is data and not code
|
||||||
|
//!
|
||||||
|
//! The rows are reverse-engineered *configuration*, not logic. They live in
|
||||||
|
//! `fixtures/client_config.json`, derived mechanically from the Python oracle
|
||||||
|
//! and templated on `{advertise}`, `{bind}`, `{pow_content_host}` and
|
||||||
|
//! `{pow_host}` so the adapter stays deployable anywhere. Hand-transcribing 400
|
||||||
|
//! string literals would add a class of silent typo no reviewer can catch, and
|
||||||
|
//! `openfut-core` already loads its content from `data/` for the same reason.
|
||||||
|
//!
|
||||||
|
//! The generator does not take its own templating on trust: it substitutes real
|
||||||
|
//! addresses back in and diffs against the oracle for every section before
|
||||||
|
//! writing the file.
|
||||||
|
|
||||||
|
use std::collections::BTreeMap;
|
||||||
|
use std::sync::OnceLock;
|
||||||
|
|
||||||
|
use super::config::AdapterConfig;
|
||||||
|
|
||||||
|
/// Rows for every known CFID, plus `__default__` for unknown ones.
|
||||||
|
const TABLE_JSON: &str = include_str!("../../fixtures/client_config.json");
|
||||||
|
|
||||||
|
type Table = BTreeMap<String, Vec<(String, String)>>;
|
||||||
|
|
||||||
|
fn table() -> &'static Table {
|
||||||
|
static TABLE: OnceLock<Table> = OnceLock::new();
|
||||||
|
TABLE.get_or_init(|| {
|
||||||
|
serde_json::from_str(TABLE_JSON).expect("bundled client_config.json is valid")
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Resolve the rows for a CFID, with addresses substituted in.
|
||||||
|
///
|
||||||
|
/// Unknown CFIDs deliberately still receive the shared FUT/RS4/POW rows: those
|
||||||
|
/// consumers read a merged `_all` store and which section contributes is
|
||||||
|
/// unproven, so a present-but-shared table is safer than an empty one.
|
||||||
|
pub fn rows_for(cfid: &str, cfg: &AdapterConfig) -> Vec<(String, String)> {
|
||||||
|
let t = table();
|
||||||
|
let rows = t
|
||||||
|
.get(cfid)
|
||||||
|
.or_else(|| t.get("__default__"))
|
||||||
|
.expect("client_config.json always carries a __default__ section");
|
||||||
|
|
||||||
|
// URL-level tokens resolve through AdapterConfig so those helpers are the
|
||||||
|
// single place a URL shape is defined. Host-level tokens cover the values
|
||||||
|
// that are not one of the three standard URLs (roster, POW API).
|
||||||
|
let utas_base = cfg.utas_base();
|
||||||
|
let nucleus_base = cfg.nucleus_base();
|
||||||
|
let pow_content_url = cfg.pow_content_url();
|
||||||
|
|
||||||
|
rows.iter()
|
||||||
|
.map(|(k, v)| {
|
||||||
|
let v = if v.contains('{') {
|
||||||
|
v.replace("{utas_base}", &utas_base)
|
||||||
|
.replace("{nucleus_base}", &nucleus_base)
|
||||||
|
.replace("{pow_content_url}", &pow_content_url)
|
||||||
|
.replace("{advertise}", &cfg.endpoints.advertise)
|
||||||
|
.replace("{bind}", &cfg.endpoints.bind)
|
||||||
|
.replace("{pow_content_host}", &cfg.endpoints.pow_content_host)
|
||||||
|
.replace("{pow_host}", &cfg.endpoints.pow_host)
|
||||||
|
} else {
|
||||||
|
v.clone()
|
||||||
|
};
|
||||||
|
debug_assert!(!v.contains('{'), "unsubstituted token left in {k}: {v}");
|
||||||
|
(k.clone(), v)
|
||||||
|
})
|
||||||
|
.collect()
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Fingerprint of the bundled config table.
|
||||||
|
///
|
||||||
|
/// The table is generated data, so "which binary is this?" is only half the
|
||||||
|
/// question — "which data does it carry?" is the other half. A running host
|
||||||
|
/// logs this at startup so a live FIFA trace can be tied to an exact table, and
|
||||||
|
/// a rebuild that silently picked up regenerated fixtures is visible.
|
||||||
|
///
|
||||||
|
/// FNV-1a, not a security hash and never used as one.
|
||||||
|
pub fn table_fingerprint() -> u64 {
|
||||||
|
let mut hash: u64 = 0xcbf2_9ce4_8422_2325;
|
||||||
|
for byte in TABLE_JSON.as_bytes() {
|
||||||
|
hash ^= *byte as u64;
|
||||||
|
hash = hash.wrapping_mul(0x1000_0000_01b3);
|
||||||
|
}
|
||||||
|
hash
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Every CFID with its own section. Unknown CFIDs are still valid requests.
|
||||||
|
pub fn known_sections() -> Vec<&'static str> {
|
||||||
|
table()
|
||||||
|
.keys()
|
||||||
|
.filter(|k| k.as_str() != "__default__")
|
||||||
|
.map(String::as_str)
|
||||||
|
.collect()
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
|
||||||
|
fn cfg() -> AdapterConfig {
|
||||||
|
let mut c = AdapterConfig::loopback();
|
||||||
|
c.endpoints.advertise = "198.51.100.7".into();
|
||||||
|
c.endpoints.bind = "0.0.0.0".into();
|
||||||
|
c.endpoints.pow_content_host = "198.51.100.7:8085".into();
|
||||||
|
c.endpoints.pow_host = "198.51.100.7:8094".into();
|
||||||
|
c
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn bundled_table_parses() {
|
||||||
|
assert!(table().contains_key("__default__"));
|
||||||
|
assert!(table().contains_key("BlazeSDK"));
|
||||||
|
assert!(known_sections().len() >= 10);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn default_section_is_the_shared_fut_base() {
|
||||||
|
let rows = rows_for("literally-anything", &cfg());
|
||||||
|
assert_eq!(rows.len(), 227);
|
||||||
|
assert!(rows.iter().any(|(k, _)| k == "FUT_RS4_BASE_URL"));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn addresses_are_substituted_not_baked() {
|
||||||
|
let rows = rows_for("BlazeSDK", &cfg());
|
||||||
|
let base = rows
|
||||||
|
.iter()
|
||||||
|
.find(|(k, _)| k == "FUT_RS4_BASE_URL")
|
||||||
|
.expect("base url present");
|
||||||
|
assert_eq!(base.1, "http://198.51.100.7:8099/");
|
||||||
|
assert!(
|
||||||
|
!rows.iter().any(|(_, v)| v.contains('{')),
|
||||||
|
"a template token survived substitution"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn nucleus_follows_bind_reproducing_the_oracle() {
|
||||||
|
let rows = rows_for("BlazeSDK", &cfg());
|
||||||
|
let n = rows.iter().find(|(k, _)| k == "nucleusConnect").unwrap();
|
||||||
|
assert_eq!(n.1, "http://0.0.0.0:42131");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn roster_section_carries_the_roster_urls() {
|
||||||
|
let rows = rows_for("OSDK_ROSTER", &cfg());
|
||||||
|
let r = rows.iter().find(|(k, _)| k == "ROSTER_URL").unwrap();
|
||||||
|
assert_eq!(r.1, "https://198.51.100.7:8081/fifa17/roster/");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn rows_are_sorted_as_the_wire_requires() {
|
||||||
|
// The oracle sorts; the TDF map encoder does not, so order is ours to keep.
|
||||||
|
let rows = rows_for("BlazeSDK", &cfg());
|
||||||
|
let mut sorted = rows.clone();
|
||||||
|
sorted.sort();
|
||||||
|
assert_eq!(rows, sorted);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn every_known_section_substitutes_cleanly() {
|
||||||
|
for cfid in known_sections() {
|
||||||
|
for (k, v) in rows_for(cfid, &cfg()) {
|
||||||
|
assert!(!v.contains('{'), "{cfid}/{k} kept a token: {v}");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,230 @@
|
|||||||
|
//! Adapter configuration: identity and endpoints.
|
||||||
|
//!
|
||||||
|
//! Everything deployment-dependent lives here, injected by the caller. No
|
||||||
|
//! address, port or persona is baked into the response builders — the
|
||||||
|
//! client/server split exists precisely because the Python responders used to
|
||||||
|
//! assume loopback, and rebuilding that assumption in Rust would undo it.
|
||||||
|
//!
|
||||||
|
//! Note the deliberate asymmetry between *bind* and *advertise*: an advertised
|
||||||
|
//! URL must carry the address the CLIENT can reach, which on a two-machine
|
||||||
|
//! deployment is not the address the server binds.
|
||||||
|
|
||||||
|
/// The forged account the whole stack agrees on.
|
||||||
|
///
|
||||||
|
/// Identity has to be byte-identical across LSX, Blaze, POW and UTAS or the
|
||||||
|
/// client rejects the session, so this is one struct passed everywhere rather
|
||||||
|
/// than constants per responder.
|
||||||
|
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||||
|
pub struct Identity {
|
||||||
|
pub persona_id: i64,
|
||||||
|
pub persona_name: String,
|
||||||
|
/// blazeId / userId. Must be non-zero or login is refused.
|
||||||
|
pub user_id: i64,
|
||||||
|
/// XREF externalId.
|
||||||
|
pub ext_id: i64,
|
||||||
|
pub email: String,
|
||||||
|
/// Must equal `PreAuthResponse.NASP`.
|
||||||
|
pub namespace: String,
|
||||||
|
/// `Blaze::ClientPlatformType`; 4 = pc.
|
||||||
|
pub client_platform: i64,
|
||||||
|
/// `PersonaStatus::Code`; 2 = ACTIVE.
|
||||||
|
pub persona_status: i64,
|
||||||
|
/// `Blaze::UserSessionType`; 0 = normal user.
|
||||||
|
pub user_session_type: i64,
|
||||||
|
/// Fallback locale as a packed four-char int (`'enUS'`). Overwritten per
|
||||||
|
/// session by the client's own preAuth `LANG`/`LOC`.
|
||||||
|
pub account_locale: i64,
|
||||||
|
/// `AccountInfo.LN`, e.g. `"en_US"`.
|
||||||
|
pub locale: String,
|
||||||
|
/// EA offer id.
|
||||||
|
pub content_id: String,
|
||||||
|
pub entitlement_tag: String,
|
||||||
|
/// Must contain `"FIFA17PCBoxContent"` or `"FIFA16PC"` or FUT drops the
|
||||||
|
/// entitlement and the store comes up empty.
|
||||||
|
pub entitlement_group: String,
|
||||||
|
pub title_id: String,
|
||||||
|
pub client_id: String,
|
||||||
|
pub platform: String,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Default for Identity {
|
||||||
|
/// The project's fixed synthetic offline identity.
|
||||||
|
///
|
||||||
|
/// A default, not a constant: the launcher can select a different persona,
|
||||||
|
/// and FUT saves are isolated per persona id.
|
||||||
|
fn default() -> Identity {
|
||||||
|
Identity {
|
||||||
|
persona_id: 33_068_179,
|
||||||
|
persona_name: "CAGE".into(),
|
||||||
|
user_id: 33_068_179,
|
||||||
|
ext_id: 33_068_179,
|
||||||
|
email: "cage@openfut.local".into(),
|
||||||
|
namespace: "cem_ea_id".into(),
|
||||||
|
client_platform: 4,
|
||||||
|
persona_status: 2,
|
||||||
|
user_session_type: 0,
|
||||||
|
account_locale: 0x656E_5553, // 'enUS'
|
||||||
|
locale: "en_US".into(),
|
||||||
|
content_id: "1027460".into(),
|
||||||
|
entitlement_tag: "ONLINE_ACCESS".into(),
|
||||||
|
entitlement_group: "FIFA17PCBoxContent".into(),
|
||||||
|
title_id: "309111".into(),
|
||||||
|
client_id: "FIFA17-PC-SERVER-BLAZE".into(),
|
||||||
|
platform: "pc".into(),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Where the client should be told to go next.
|
||||||
|
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||||
|
pub struct Endpoints {
|
||||||
|
/// Address handed to the CLIENT for every next hop. On a split deployment
|
||||||
|
/// this is the backend's LAN address as the game machine sees it.
|
||||||
|
pub advertise: String,
|
||||||
|
/// Address the server binds. Not interchangeable with `advertise`.
|
||||||
|
pub bind: String,
|
||||||
|
/// `host:port` for POW content.
|
||||||
|
pub pow_content_host: String,
|
||||||
|
/// `host:port` for the POW/EASFC API.
|
||||||
|
pub pow_host: String,
|
||||||
|
/// Blaze port ADVERTISED to the client by the redirector.
|
||||||
|
///
|
||||||
|
/// Our choice, not a protocol constant — the client goes wherever
|
||||||
|
/// `<serverinstanceinfo>` sends it. Configurable so a sidecar can be
|
||||||
|
/// advertised on a different port without a rebuild.
|
||||||
|
pub blaze_port: u16,
|
||||||
|
/// UTAS/RS4 port in generated `FUT_RS4_*` URLs.
|
||||||
|
///
|
||||||
|
/// 8099 is the client's own built-in default (`http://easw.easports.com:8099/`
|
||||||
|
/// in CardsDLL), so it is the sane value — but it is still deployment
|
||||||
|
/// configuration, not a constant we are entitled to bake in.
|
||||||
|
pub utas_port: u16,
|
||||||
|
pub telemetry_port: i64,
|
||||||
|
pub ticker_port: i64,
|
||||||
|
pub qos_port: i64,
|
||||||
|
}
|
||||||
|
|
||||||
|
// NOTE: there is deliberately NO `impl Default for Endpoints`.
|
||||||
|
//
|
||||||
|
// A default would silently supply loopback, and a remote deployment that forgot
|
||||||
|
// to set an address would then advertise `127.0.0.1` to a client on another
|
||||||
|
// machine — failing far from the cause. Choosing loopback has to be an explicit
|
||||||
|
// act, so it is a named constructor.
|
||||||
|
|
||||||
|
impl Endpoints {
|
||||||
|
/// Endpoints for a backend the client reaches at `advertise`.
|
||||||
|
///
|
||||||
|
/// POW hosts DERIVE from the advertised host, matching what the deployed
|
||||||
|
/// Python entrypoint does (`POW_HOST="${POW_HOST:-$ADV:8094}"`). They must
|
||||||
|
/// not fall back to loopback independently: that would leave a remote
|
||||||
|
/// deployment emitting loopback POW URLs while every other URL was correct.
|
||||||
|
pub fn advertising(advertise: impl Into<String>) -> Endpoints {
|
||||||
|
let advertise = advertise.into();
|
||||||
|
Endpoints {
|
||||||
|
pow_content_host: format!("{advertise}:8080"),
|
||||||
|
pow_host: format!("{advertise}:8094"),
|
||||||
|
bind: advertise.clone(),
|
||||||
|
advertise,
|
||||||
|
blaze_port: 42130,
|
||||||
|
utas_port: 8099,
|
||||||
|
telemetry_port: 9988,
|
||||||
|
ticker_port: 8999,
|
||||||
|
qos_port: 17502,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Explicit local-only / oracle mode: game and backend on one host.
|
||||||
|
///
|
||||||
|
/// Named rather than defaulted so that "everything is loopback" is always a
|
||||||
|
/// decision someone made, and greppable.
|
||||||
|
pub fn loopback() -> Endpoints {
|
||||||
|
Endpoints::advertising("127.0.0.1")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Full adapter configuration.
|
||||||
|
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||||
|
pub struct AdapterConfig {
|
||||||
|
pub identity: Identity,
|
||||||
|
pub endpoints: Endpoints,
|
||||||
|
/// `PreAuthResponse.SVER`. Carries a trailing newline in the oracle; kept
|
||||||
|
/// because it is on the wire, not because it is meaningful.
|
||||||
|
pub server_version: String,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `PreAuthResponse.SVER`. On the wire, so it is config rather than a literal.
|
||||||
|
pub const DEFAULT_SERVER_VERSION: &str = "Blaze 15.1.1.3.0 (OpenFUT)\n";
|
||||||
|
|
||||||
|
// No `Default` here either, for the same reason as `Endpoints`.
|
||||||
|
|
||||||
|
impl AdapterConfig {
|
||||||
|
/// Adapter serving a client that reaches this backend at `advertise`.
|
||||||
|
pub fn advertising(advertise: impl Into<String>) -> AdapterConfig {
|
||||||
|
AdapterConfig {
|
||||||
|
identity: Identity::default(),
|
||||||
|
endpoints: Endpoints::advertising(advertise),
|
||||||
|
server_version: DEFAULT_SERVER_VERSION.into(),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Explicit local-only / oracle mode.
|
||||||
|
pub fn loopback() -> AdapterConfig {
|
||||||
|
AdapterConfig::advertising("127.0.0.1")
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `http://<advertise>:8099/` — the RS4/UTAS base.
|
||||||
|
///
|
||||||
|
/// The trailing slash and the scheme are both mandatory: CardsDLL's
|
||||||
|
/// `ServerSettings::resolve` uses the value verbatim once it contains
|
||||||
|
/// `"://"`, and the auth path breaks without the slash.
|
||||||
|
pub fn utas_base(&self) -> String {
|
||||||
|
format!(
|
||||||
|
"http://{}:{}/",
|
||||||
|
self.endpoints.advertise, self.endpoints.utas_port
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `http://<bind>:42131` — the Nucleus OAuth stub.
|
||||||
|
///
|
||||||
|
/// This derives from **bind**, not advertise, faithfully reproducing the
|
||||||
|
/// Python oracle. On the live split deployment that makes it
|
||||||
|
/// `http://0.0.0.0:42131`, which the client cannot dial — see the crate
|
||||||
|
/// README and the vault. Reproduced deliberately: changing it would break
|
||||||
|
/// byte parity with the only configuration ever proven to work, and the
|
||||||
|
/// fix belongs in a separate, live-validated change.
|
||||||
|
pub fn nucleus_base(&self) -> String {
|
||||||
|
format!("http://{}:42131", self.endpoints.bind)
|
||||||
|
}
|
||||||
|
|
||||||
|
pub fn pow_content_url(&self) -> String {
|
||||||
|
format!("http://{}", self.endpoints.pow_content_host)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn utas_base_keeps_scheme_and_trailing_slash() {
|
||||||
|
let mut cfg = AdapterConfig::loopback();
|
||||||
|
cfg.endpoints.advertise = "10.0.0.5".into();
|
||||||
|
assert_eq!(cfg.utas_base(), "http://10.0.0.5:8099/");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn nucleus_follows_bind_not_advertise() {
|
||||||
|
// Documents the oracle's behaviour, including its consequence.
|
||||||
|
let mut cfg = AdapterConfig::loopback();
|
||||||
|
cfg.endpoints.advertise = "10.0.0.5".into();
|
||||||
|
cfg.endpoints.bind = "0.0.0.0".into();
|
||||||
|
assert_eq!(cfg.nucleus_base(), "http://0.0.0.0:42131");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn pow_content_url_has_no_trailing_slash() {
|
||||||
|
let mut cfg = AdapterConfig::loopback();
|
||||||
|
cfg.endpoints.pow_content_host = "10.0.0.5:8085".into();
|
||||||
|
assert_eq!(cfg.pow_content_url(), "http://10.0.0.5:8085");
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,464 @@
|
|||||||
|
//! Blaze RPC dispatch: inbound frame → outbound frames.
|
||||||
|
//!
|
||||||
|
//! Three behaviours here are load-bearing and none of them are obvious from the
|
||||||
|
//! individual response shapes:
|
||||||
|
//!
|
||||||
|
//! * **Login answers with four frames, in order**: the reply first, then
|
||||||
|
//! `UserAuthenticated`, `UserSessionExtendedDataUpdate`, `UserAdded`.
|
||||||
|
//! * **An unimplemented RPC still gets an empty reply.** Silence makes the
|
||||||
|
//! client wait for a timeout; an empty reply lets every field fall back to a
|
||||||
|
//! client-side default and the boot continues.
|
||||||
|
//! * **Non-request message types get nothing at all** — answering a reply or a
|
||||||
|
//! notification would desynchronise the client's own correlation.
|
||||||
|
//!
|
||||||
|
//! No error replies are emitted. `msgType` 3 exists, but the error-code
|
||||||
|
//! placement is UNRESOLVED — three clean-room sources disagree between
|
||||||
|
//! `header[14:16]`, a metadata `ERRC`, and a payload `CNTX`/`ERRC` — so
|
||||||
|
//! emitting one would be a guess on the wire. Do not add one without a capture.
|
||||||
|
|
||||||
|
use openfut_protocol_blaze::fire2::{Frame, Header, MsgType};
|
||||||
|
use openfut_protocol_blaze::heat2::{self, Struct, Value};
|
||||||
|
|
||||||
|
use super::config::AdapterConfig;
|
||||||
|
use super::ids::{association_lists, auth, census_data, component, user_sessions, util};
|
||||||
|
use super::responses as r;
|
||||||
|
use super::session::Session;
|
||||||
|
|
||||||
|
/// Everything needed to answer one RPC.
|
||||||
|
pub struct Adapter {
|
||||||
|
pub config: AdapterConfig,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Adapter {
|
||||||
|
pub fn new(config: AdapterConfig) -> Adapter {
|
||||||
|
Adapter { config }
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Answer one inbound frame.
|
||||||
|
///
|
||||||
|
/// `now` is passed in rather than read from the clock so responses are
|
||||||
|
/// reproducible: several bodies stamp a timestamp, and a hidden clock read
|
||||||
|
/// would make every fixture unrepeatable.
|
||||||
|
pub fn dispatch(
|
||||||
|
&self,
|
||||||
|
header: &Header,
|
||||||
|
body: &Struct,
|
||||||
|
session: &mut Session,
|
||||||
|
now: i64,
|
||||||
|
) -> Vec<Frame> {
|
||||||
|
// Transport-level ping, whatever the component/command.
|
||||||
|
if header.msg_type == MsgType::Ping {
|
||||||
|
return vec![reply(header, Vec::new(), MsgType::PingReply)];
|
||||||
|
}
|
||||||
|
// Only requests are answered.
|
||||||
|
if header.msg_type != MsgType::Message {
|
||||||
|
return Vec::new();
|
||||||
|
}
|
||||||
|
|
||||||
|
let cfg = &self.config;
|
||||||
|
match (header.component, header.command) {
|
||||||
|
// ------------------------------------------------------- Util
|
||||||
|
(component::UTIL, util::PRE_AUTH) => {
|
||||||
|
// preAuth is where the session learns who it is talking to:
|
||||||
|
// the service name is echoed back, and the locale is captured
|
||||||
|
// for every later ALOC field.
|
||||||
|
session.service_name = service_name_of(body);
|
||||||
|
if let Some(loc) =
|
||||||
|
find_nested_int(body, "LANG").or_else(|| find_nested_int(body, "LOC"))
|
||||||
|
{
|
||||||
|
session.account_locale = loc;
|
||||||
|
}
|
||||||
|
let svc = session.service_name.clone();
|
||||||
|
reply_tdf(header, &r::preauth_response(&svc, cfg))
|
||||||
|
}
|
||||||
|
|
||||||
|
(component::UTIL, util::PING) => reply_tdf(header, &r::ping_response(now)),
|
||||||
|
|
||||||
|
(component::UTIL, util::FETCH_CLIENT_CONFIG) => {
|
||||||
|
let cfid = get_str(body, "CFID");
|
||||||
|
reply_tdf(header, &r::fetch_config_response(&cfid, cfg))
|
||||||
|
}
|
||||||
|
|
||||||
|
(component::UTIL, util::POST_AUTH) => {
|
||||||
|
reply_tdf(header, &r::post_auth_response(session, cfg))
|
||||||
|
}
|
||||||
|
|
||||||
|
(component::UTIL, util::FETCH_QOS_CONFIG) => reply_tdf(header, &r::qos_config(cfg)),
|
||||||
|
|
||||||
|
(component::UTIL, util::USER_SETTINGS_LOAD) => {
|
||||||
|
reply_tdf(header, &r::user_settings_response())
|
||||||
|
}
|
||||||
|
|
||||||
|
// Accepted and discarded; the client only needs the ack.
|
||||||
|
(component::UTIL, util::USER_SETTINGS_SAVE)
|
||||||
|
| (component::UTIL, util::SET_CLIENT_STATE)
|
||||||
|
| (component::UTIL, util::SET_CLIENT_METRICS) => empty_reply(header),
|
||||||
|
|
||||||
|
// --------------------------------------------- Authentication
|
||||||
|
(component::AUTHENTICATION, auth::LOGIN) => {
|
||||||
|
session.auth_code = get_str(body, "AUTH");
|
||||||
|
session.logged_in = true;
|
||||||
|
session.login_time = now;
|
||||||
|
self.login_burst(header, session, now)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Same forged session; the request fields differ and are ignored.
|
||||||
|
(component::AUTHENTICATION, auth::TRUSTED_LOGIN)
|
||||||
|
| (component::AUTHENTICATION, auth::EXPRESS_LOGIN) => {
|
||||||
|
session.logged_in = true;
|
||||||
|
session.login_time = now;
|
||||||
|
self.login_burst(header, session, now)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Receiving logout is NORMAL, not a failure: the OSDK state table
|
||||||
|
// orders Connect -> Logout -> VersionCheck -> PCLogin, so this is
|
||||||
|
// the routine "drop any stale session" step before login. It is
|
||||||
|
// only a symptom if login never follows.
|
||||||
|
(component::AUTHENTICATION, auth::LOGOUT) => empty_reply(header),
|
||||||
|
|
||||||
|
(component::AUTHENTICATION, auth::LIST_USER_ENTITLEMENTS2)
|
||||||
|
| (component::AUTHENTICATION, auth::LIST_ENTITLEMENTS)
|
||||||
|
| (component::AUTHENTICATION, auth::LIST_PERSONA_ENTITLEMENTS2)
|
||||||
|
| (component::AUTHENTICATION, auth::GRANT_ENTITLEMENT2) => {
|
||||||
|
reply_tdf(header, &r::entitlements_response(cfg))
|
||||||
|
}
|
||||||
|
|
||||||
|
(component::AUTHENTICATION, auth::GET_AUTH_TOKEN) => {
|
||||||
|
reply_tdf(header, &r::get_auth_token_response(session))
|
||||||
|
}
|
||||||
|
(component::AUTHENTICATION, auth::GET_ACCOUNT) => {
|
||||||
|
reply_tdf(header, &r::account_info(now, cfg))
|
||||||
|
}
|
||||||
|
(component::AUTHENTICATION, auth::GET_PERSONA) => {
|
||||||
|
reply_tdf(header, &r::get_persona_response(now, cfg))
|
||||||
|
}
|
||||||
|
(component::AUTHENTICATION, auth::LIST_PERSONAS) => {
|
||||||
|
reply_tdf(header, &r::list_personas_response(now, cfg))
|
||||||
|
}
|
||||||
|
|
||||||
|
// ---------------------------------------------- UserSessions
|
||||||
|
(component::USER_SESSIONS, user_sessions::UPDATE_NETWORK_INFO) => {
|
||||||
|
// Ack, then re-push the extended data so the client's cached
|
||||||
|
// copy reflects the network info it just reported.
|
||||||
|
vec![
|
||||||
|
reply(header, Vec::new(), MsgType::Reply),
|
||||||
|
notify(
|
||||||
|
component::USER_SESSIONS,
|
||||||
|
user_sessions::notify::EXTENDED_DATA_UPDATE,
|
||||||
|
&r::user_session_extended_data_update(cfg),
|
||||||
|
),
|
||||||
|
]
|
||||||
|
}
|
||||||
|
|
||||||
|
// ------------------------------------------ AssociationLists
|
||||||
|
(component::ASSOCIATION_LISTS, association_lists::GET_LISTS) => {
|
||||||
|
reply_tdf(header, &r::get_lists_response())
|
||||||
|
}
|
||||||
|
|
||||||
|
// ----------------------------------------------- CensusData
|
||||||
|
(component::CENSUS_DATA, census_data::SUBSCRIBE_TO_CENSUS_DATA_UPDATES) => {
|
||||||
|
reply_tdf(header, &r::census_subscribe_response())
|
||||||
|
}
|
||||||
|
|
||||||
|
// An empty reply, never silence: see the module docs.
|
||||||
|
_ => empty_reply(header),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Login reply followed by the three UserSessions pushes, in order.
|
||||||
|
///
|
||||||
|
/// The order is the oracle's ("pamplona" order: reply first). The
|
||||||
|
/// alternative ("grid-blaze": notifications first) is also reported to
|
||||||
|
/// work, but only this one is proven against our client, so it is the one
|
||||||
|
/// reproduced.
|
||||||
|
fn login_burst(&self, header: &Header, session: &Session, now: i64) -> Vec<Frame> {
|
||||||
|
let cfg = &self.config;
|
||||||
|
vec![
|
||||||
|
reply(
|
||||||
|
header,
|
||||||
|
heat2::encode(&r::login_response(session, now, cfg)),
|
||||||
|
MsgType::Reply,
|
||||||
|
),
|
||||||
|
notify(
|
||||||
|
component::USER_SESSIONS,
|
||||||
|
user_sessions::notify::USER_AUTHENTICATED,
|
||||||
|
&r::user_session_login_info(session, now, cfg),
|
||||||
|
),
|
||||||
|
notify(
|
||||||
|
component::USER_SESSIONS,
|
||||||
|
user_sessions::notify::EXTENDED_DATA_UPDATE,
|
||||||
|
&r::user_session_extended_data_update(cfg),
|
||||||
|
),
|
||||||
|
notify(
|
||||||
|
component::USER_SESSIONS,
|
||||||
|
user_sessions::notify::USER_ADDED,
|
||||||
|
&r::user_data(session, cfg),
|
||||||
|
),
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// ------------------------------------------------------------------ helpers
|
||||||
|
|
||||||
|
fn reply(request: &Header, payload: Vec<u8>, msg_type: MsgType) -> Frame {
|
||||||
|
let mut frame = Frame::new(
|
||||||
|
request.component,
|
||||||
|
request.command,
|
||||||
|
request.msg_num,
|
||||||
|
msg_type,
|
||||||
|
payload,
|
||||||
|
);
|
||||||
|
// A reply echoes routing verbatim and changes only the msgType bits.
|
||||||
|
frame.header.user_index = request.user_index;
|
||||||
|
frame
|
||||||
|
}
|
||||||
|
|
||||||
|
fn reply_tdf(request: &Header, body: &Struct) -> Vec<Frame> {
|
||||||
|
vec![reply(request, heat2::encode(body), MsgType::Reply)]
|
||||||
|
}
|
||||||
|
|
||||||
|
fn empty_reply(request: &Header) -> Vec<Frame> {
|
||||||
|
vec![reply(request, Vec::new(), MsgType::Reply)]
|
||||||
|
}
|
||||||
|
|
||||||
|
fn notify(component: u16, notify_id: u16, body: &Struct) -> Frame {
|
||||||
|
Frame::notification(component, notify_id, heat2::encode(body))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `PreAuthRequest.CDAT.SVCN`, echoed back as `INST`.
|
||||||
|
fn service_name_of(body: &Struct) -> String {
|
||||||
|
body.get("CDAT")
|
||||||
|
.and_then(Value::as_struct)
|
||||||
|
.and_then(|c| c.get("SVCN"))
|
||||||
|
.and_then(Value::as_str)
|
||||||
|
.filter(|s| !s.is_empty())
|
||||||
|
.unwrap_or(super::session::DEFAULT_SERVICE_NAME)
|
||||||
|
.to_string()
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Depth-first search for an INT member anywhere in a decoded body.
|
||||||
|
///
|
||||||
|
/// The client has moved which struct carries `LANG`/`LOC` between builds, so
|
||||||
|
/// the oracle searches rather than addressing a fixed path.
|
||||||
|
fn find_nested_int(body: &Struct, tag: &str) -> Option<i64> {
|
||||||
|
for (t, v) in body.iter() {
|
||||||
|
if t.to_label() == tag {
|
||||||
|
if let Value::Int(n) = v {
|
||||||
|
return Some(*n);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if let Value::Struct(inner) = v {
|
||||||
|
if let Some(found) = find_nested_int(inner, tag) {
|
||||||
|
return Some(found);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
None
|
||||||
|
}
|
||||||
|
|
||||||
|
fn get_str(body: &Struct, tag: &str) -> String {
|
||||||
|
body.get(tag)
|
||||||
|
.and_then(Value::as_str)
|
||||||
|
.unwrap_or("")
|
||||||
|
.to_string()
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
use openfut_protocol_blaze::heat2::Struct as S;
|
||||||
|
|
||||||
|
fn adapter() -> Adapter {
|
||||||
|
Adapter::new(AdapterConfig::loopback())
|
||||||
|
}
|
||||||
|
|
||||||
|
fn req(component: u16, command: u16) -> Header {
|
||||||
|
Header::new(component, command, 7, MsgType::Message)
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn login_answers_with_reply_then_three_pushes_in_order() {
|
||||||
|
let a = adapter();
|
||||||
|
let mut sess = Session::new("k", 0);
|
||||||
|
let out = a.dispatch(
|
||||||
|
&req(component::AUTHENTICATION, auth::LOGIN),
|
||||||
|
&S::new(),
|
||||||
|
&mut sess,
|
||||||
|
1,
|
||||||
|
);
|
||||||
|
|
||||||
|
assert_eq!(out.len(), 4);
|
||||||
|
assert_eq!(out[0].header.msg_type, MsgType::Reply);
|
||||||
|
let ids: Vec<u16> = out[1..].iter().map(|f| f.header.command).collect();
|
||||||
|
assert_eq!(
|
||||||
|
ids,
|
||||||
|
vec![
|
||||||
|
user_sessions::notify::USER_AUTHENTICATED,
|
||||||
|
user_sessions::notify::EXTENDED_DATA_UPDATE,
|
||||||
|
user_sessions::notify::USER_ADDED,
|
||||||
|
]
|
||||||
|
);
|
||||||
|
for f in &out[1..] {
|
||||||
|
assert_eq!(f.header.msg_type, MsgType::Notification);
|
||||||
|
assert_eq!(f.header.msg_num, 0, "notifications are uncorrelated");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn unimplemented_rpcs_get_an_empty_reply_not_silence() {
|
||||||
|
let a = adapter();
|
||||||
|
let mut sess = Session::new("k", 0);
|
||||||
|
let out = a.dispatch(&req(0x1234, 0x0001), &S::new(), &mut sess, 1);
|
||||||
|
assert_eq!(out.len(), 1);
|
||||||
|
assert_eq!(out[0].header.msg_type, MsgType::Reply);
|
||||||
|
assert!(out[0].payload.is_empty());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn non_requests_are_ignored_entirely() {
|
||||||
|
let a = adapter();
|
||||||
|
let mut sess = Session::new("k", 0);
|
||||||
|
for mt in [
|
||||||
|
MsgType::Reply,
|
||||||
|
MsgType::Notification,
|
||||||
|
MsgType::ErrorReply,
|
||||||
|
MsgType::PingReply,
|
||||||
|
] {
|
||||||
|
let h = Header::new(component::UTIL, util::PING, 1, mt);
|
||||||
|
assert!(a.dispatch(&h, &S::new(), &mut sess, 1).is_empty(), "{mt:?}");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn transport_ping_gets_an_empty_ping_reply() {
|
||||||
|
let a = adapter();
|
||||||
|
let mut sess = Session::new("k", 0);
|
||||||
|
let h = Header::new(component::UTIL, util::PING, 1, MsgType::Ping);
|
||||||
|
let out = a.dispatch(&h, &S::new(), &mut sess, 1);
|
||||||
|
assert_eq!(out.len(), 1);
|
||||||
|
assert_eq!(out[0].header.msg_type, MsgType::PingReply);
|
||||||
|
assert!(out[0].payload.is_empty());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn replies_echo_routing_including_user_index() {
|
||||||
|
let a = adapter();
|
||||||
|
let mut sess = Session::new("k", 0);
|
||||||
|
let mut h = req(component::UTIL, util::PING);
|
||||||
|
h.user_index = 7;
|
||||||
|
h.msg_num = 0x4242;
|
||||||
|
let out = a.dispatch(&h, &S::new(), &mut sess, 1);
|
||||||
|
assert_eq!(out[0].header.user_index, 7);
|
||||||
|
assert_eq!(out[0].header.msg_num, 0x4242);
|
||||||
|
assert_eq!(out[0].header.component, component::UTIL);
|
||||||
|
assert_eq!(out[0].header.command, util::PING);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn preauth_captures_locale_and_service_name() {
|
||||||
|
let a = adapter();
|
||||||
|
let mut sess = Session::new("k", 0x656E5553);
|
||||||
|
let body = S::new().with(
|
||||||
|
"CDAT",
|
||||||
|
Value::Struct(
|
||||||
|
S::new()
|
||||||
|
.with("LANG", Value::Int(0x64654445))
|
||||||
|
.with("SVCN", Value::String("fifa-2017-pc-de".into())),
|
||||||
|
),
|
||||||
|
);
|
||||||
|
a.dispatch(&req(component::UTIL, util::PRE_AUTH), &body, &mut sess, 1);
|
||||||
|
assert_eq!(sess.account_locale, 0x64654445);
|
||||||
|
assert_eq!(sess.service_name, "fifa-2017-pc-de");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn preauth_without_svcn_falls_back_to_the_default() {
|
||||||
|
let a = adapter();
|
||||||
|
let mut sess = Session::new("k", 0);
|
||||||
|
a.dispatch(
|
||||||
|
&req(component::UTIL, util::PRE_AUTH),
|
||||||
|
&S::new(),
|
||||||
|
&mut sess,
|
||||||
|
1,
|
||||||
|
);
|
||||||
|
assert_eq!(
|
||||||
|
sess.service_name,
|
||||||
|
super::super::session::DEFAULT_SERVICE_NAME
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn login_records_the_auth_code_for_later_get_auth_token() {
|
||||||
|
let a = adapter();
|
||||||
|
let mut sess = Session::new("k", 0);
|
||||||
|
let body = S::new().with("AUTH", Value::String("CODE-123".into()));
|
||||||
|
a.dispatch(
|
||||||
|
&req(component::AUTHENTICATION, auth::LOGIN),
|
||||||
|
&body,
|
||||||
|
&mut sess,
|
||||||
|
1,
|
||||||
|
);
|
||||||
|
|
||||||
|
let out = a.dispatch(
|
||||||
|
&req(component::AUTHENTICATION, auth::GET_AUTH_TOKEN),
|
||||||
|
&S::new(),
|
||||||
|
&mut sess,
|
||||||
|
1,
|
||||||
|
);
|
||||||
|
let decoded = heat2::decode(&out[0].payload).unwrap();
|
||||||
|
assert_eq!(
|
||||||
|
decoded.get("AUTH").and_then(Value::as_str),
|
||||||
|
Some("CODE-123")
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn update_network_info_acks_then_pushes() {
|
||||||
|
let a = adapter();
|
||||||
|
let mut sess = Session::new("k", 0);
|
||||||
|
let out = a.dispatch(
|
||||||
|
&req(component::USER_SESSIONS, user_sessions::UPDATE_NETWORK_INFO),
|
||||||
|
&S::new(),
|
||||||
|
&mut sess,
|
||||||
|
1,
|
||||||
|
);
|
||||||
|
assert_eq!(out.len(), 2);
|
||||||
|
assert!(out[0].payload.is_empty());
|
||||||
|
assert_eq!(out[1].header.msg_type, MsgType::Notification);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn all_four_entitlement_aliases_agree() {
|
||||||
|
let a = adapter();
|
||||||
|
let mut sess = Session::new("k", 0);
|
||||||
|
let bodies: Vec<Vec<u8>> = [
|
||||||
|
auth::LIST_USER_ENTITLEMENTS2,
|
||||||
|
auth::LIST_ENTITLEMENTS,
|
||||||
|
auth::LIST_PERSONA_ENTITLEMENTS2,
|
||||||
|
auth::GRANT_ENTITLEMENT2,
|
||||||
|
]
|
||||||
|
.iter()
|
||||||
|
.map(|&cmd| {
|
||||||
|
a.dispatch(
|
||||||
|
&req(component::AUTHENTICATION, cmd),
|
||||||
|
&S::new(),
|
||||||
|
&mut sess,
|
||||||
|
1,
|
||||||
|
)[0]
|
||||||
|
.payload
|
||||||
|
.clone()
|
||||||
|
})
|
||||||
|
.collect();
|
||||||
|
assert!(bodies.windows(2).all(|w| w[0] == w[1]));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn finds_a_nested_int_at_any_depth() {
|
||||||
|
let body = S::new().with(
|
||||||
|
"A",
|
||||||
|
Value::Struct(S::new().with("B", Value::Struct(S::new().with("LANG", Value::Int(42))))),
|
||||||
|
);
|
||||||
|
assert_eq!(find_nested_int(&body, "LANG"), Some(42));
|
||||||
|
assert_eq!(find_nested_int(&body, "NOPE"), None);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,269 @@
|
|||||||
|
//! FIFA 17 Blaze component, command and notification IDs.
|
||||||
|
//!
|
||||||
|
//! This is exactly the knowledge that must NOT live in
|
||||||
|
//! `openfut-protocol-blaze`: the generic layer routes on numbers, and what
|
||||||
|
//! those numbers mean is per-title.
|
||||||
|
//!
|
||||||
|
//! # Provenance
|
||||||
|
//!
|
||||||
|
//! The Util table was recovered from FIFA17.exe's own `getCommandName` switch
|
||||||
|
//! (jump table `0x141b17af4`). The Authentication table could not be recovered
|
||||||
|
//! statically — the name pool is Denuvo-mutated — so it was obtained by CALLING
|
||||||
|
//! the client's own `getCommandName` (`0x146e0d2a0`) in-process over ids 1..320,
|
||||||
|
//! validated by reproducing the known Util names, and cross-checked against a
|
||||||
|
//! static REST-binding struct (`0x143896a80` → `trustedLogin = 0x0B`).
|
||||||
|
//! UserSessions notification ids come from the clean, unmutated
|
||||||
|
//! `getNotificationName` jump table at `0x141b03f70`.
|
||||||
|
//!
|
||||||
|
//! Names are for diagnostics only. Dispatch matches on the numeric constants.
|
||||||
|
|
||||||
|
pub mod component {
|
||||||
|
pub const AUTHENTICATION: u16 = 0x0001;
|
||||||
|
pub const GAME_MANAGER: u16 = 0x0004;
|
||||||
|
pub const REDIRECTOR: u16 = 0x0005;
|
||||||
|
pub const STATS: u16 = 0x0007;
|
||||||
|
pub const UTIL: u16 = 0x0009;
|
||||||
|
pub const CENSUS_DATA: u16 = 0x000A;
|
||||||
|
pub const CLUBS: u16 = 0x000B;
|
||||||
|
pub const MESSAGING: u16 = 0x000F;
|
||||||
|
pub const ASSOCIATION_LISTS: u16 = 0x0019;
|
||||||
|
pub const GAME_REPORTING: u16 = 0x001C;
|
||||||
|
pub const SPONSORED_EVENTS: u16 = 0x081C;
|
||||||
|
pub const OSDK_SETTINGS: u16 = 0x08C9;
|
||||||
|
pub const USER_SESSIONS: u16 = 0x7802;
|
||||||
|
}
|
||||||
|
|
||||||
|
pub mod util {
|
||||||
|
pub const FETCH_CLIENT_CONFIG: u16 = 0x0001;
|
||||||
|
pub const PING: u16 = 0x0002;
|
||||||
|
pub const PRE_AUTH: u16 = 0x0007;
|
||||||
|
pub const POST_AUTH: u16 = 0x0008;
|
||||||
|
pub const USER_SETTINGS_LOAD: u16 = 0x000A;
|
||||||
|
pub const USER_SETTINGS_SAVE: u16 = 0x000B;
|
||||||
|
pub const FETCH_QOS_CONFIG: u16 = 0x0015;
|
||||||
|
pub const SET_CLIENT_METRICS: u16 = 0x0016;
|
||||||
|
pub const SET_CLIENT_STATE: u16 = 0x001C;
|
||||||
|
}
|
||||||
|
|
||||||
|
pub mod auth {
|
||||||
|
pub const LOGIN: u16 = 0x000A;
|
||||||
|
pub const TRUSTED_LOGIN: u16 = 0x000B;
|
||||||
|
pub const LIST_USER_ENTITLEMENTS2: u16 = 0x001D;
|
||||||
|
pub const GET_ACCOUNT: u16 = 0x001E;
|
||||||
|
pub const LIST_ENTITLEMENTS: u16 = 0x0020;
|
||||||
|
pub const GET_AUTH_TOKEN: u16 = 0x0024;
|
||||||
|
pub const GRANT_ENTITLEMENT2: u16 = 0x0027;
|
||||||
|
pub const LIST_PERSONA_ENTITLEMENTS2: u16 = 0x0030;
|
||||||
|
pub const EXPRESS_LOGIN: u16 = 0x003C;
|
||||||
|
/// Routine "drop any stale session" step before PCLogin, NOT a failure.
|
||||||
|
pub const LOGOUT: u16 = 0x0046;
|
||||||
|
pub const GET_PERSONA: u16 = 0x005A;
|
||||||
|
pub const LIST_PERSONAS: u16 = 0x0064;
|
||||||
|
}
|
||||||
|
|
||||||
|
pub mod user_sessions {
|
||||||
|
pub const UPDATE_NETWORK_INFO: u16 = 0x0014;
|
||||||
|
|
||||||
|
/// Notification ids live in a separate number space from commands.
|
||||||
|
pub mod notify {
|
||||||
|
pub const EXTENDED_DATA_UPDATE: u16 = 0x0001;
|
||||||
|
pub const USER_ADDED: u16 = 0x0002;
|
||||||
|
pub const USER_REMOVED: u16 = 0x0003;
|
||||||
|
pub const USER_UPDATED: u16 = 0x0005;
|
||||||
|
pub const USER_AUTHENTICATED: u16 = 0x0008;
|
||||||
|
pub const USER_UNAUTHENTICATED: u16 = 0x0009;
|
||||||
|
pub const SERVER_DRAINING: u16 = 0x000C;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pub mod association_lists {
|
||||||
|
pub const GET_LISTS: u16 = 0x0006;
|
||||||
|
}
|
||||||
|
|
||||||
|
pub mod census_data {
|
||||||
|
pub const SUBSCRIBE_TO_CENSUS_DATA_UPDATES: u16 = 0x0005;
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Components advertised in `PreAuthResponse.CIDS`.
|
||||||
|
///
|
||||||
|
/// Order is the oracle's and is preserved: `CIDS` is a TDF list, and list
|
||||||
|
/// elements are NOT reordered by the encoder the way struct members are.
|
||||||
|
pub const ADVERTISED_COMPONENT_IDS: [i64; 9] = [
|
||||||
|
component::AUTHENTICATION as i64,
|
||||||
|
component::GAME_MANAGER as i64,
|
||||||
|
component::REDIRECTOR as i64,
|
||||||
|
component::STATS as i64,
|
||||||
|
component::UTIL as i64,
|
||||||
|
component::MESSAGING as i64,
|
||||||
|
component::ASSOCIATION_LISTS as i64,
|
||||||
|
component::GAME_REPORTING as i64,
|
||||||
|
component::USER_SESSIONS as i64,
|
||||||
|
];
|
||||||
|
|
||||||
|
pub fn component_name(component: u16) -> Option<&'static str> {
|
||||||
|
Some(match component {
|
||||||
|
component::AUTHENTICATION => "Authentication",
|
||||||
|
component::GAME_MANAGER => "GameManager",
|
||||||
|
component::REDIRECTOR => "Redirector",
|
||||||
|
component::STATS => "Stats",
|
||||||
|
component::UTIL => "Util",
|
||||||
|
component::CENSUS_DATA => "CensusData",
|
||||||
|
component::CLUBS => "Clubs",
|
||||||
|
component::MESSAGING => "Messaging",
|
||||||
|
component::ASSOCIATION_LISTS => "AssociationLists",
|
||||||
|
component::GAME_REPORTING => "GameReporting",
|
||||||
|
component::SPONSORED_EVENTS => "SponsoredEvents",
|
||||||
|
component::OSDK_SETTINGS => "OSDKSettings",
|
||||||
|
component::USER_SESSIONS => "UserSessions",
|
||||||
|
_ => return None,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
pub fn command_name(component: u16, command: u16) -> Option<&'static str> {
|
||||||
|
Some(match (component, command) {
|
||||||
|
(component::UTIL, 0x01) => "fetchClientConfig",
|
||||||
|
(component::UTIL, 0x02) => "ping",
|
||||||
|
(component::UTIL, 0x03) => "setClientData",
|
||||||
|
(component::UTIL, 0x04) => "localizeStrings",
|
||||||
|
(component::UTIL, 0x05) => "getTelemetryServer",
|
||||||
|
(component::UTIL, 0x06) => "getTickerServer",
|
||||||
|
(component::UTIL, 0x07) => "preAuth",
|
||||||
|
(component::UTIL, 0x08) => "postAuth",
|
||||||
|
(component::UTIL, 0x0A) => "userSettingsLoad",
|
||||||
|
(component::UTIL, 0x0B) => "userSettingsSave",
|
||||||
|
(component::UTIL, 0x0C) => "userSettingsLoadAll",
|
||||||
|
(component::UTIL, 0x0E) => "userSettingsDelete",
|
||||||
|
(component::UTIL, 0x0F) => "userSettingsLoadAllForUser",
|
||||||
|
(component::UTIL, 0x14) => "filterForProfanity",
|
||||||
|
(component::UTIL, 0x15) => "fetchQosConfig",
|
||||||
|
(component::UTIL, 0x16) => "setClientMetrics",
|
||||||
|
(component::UTIL, 0x17) => "setConnectionState",
|
||||||
|
(component::UTIL, 0x19) => "getUserOptions",
|
||||||
|
(component::UTIL, 0x1A) => "setUserOptions",
|
||||||
|
(component::UTIL, 0x1B) => "suspendUserPing",
|
||||||
|
(component::UTIL, 0x1C) => "setClientState",
|
||||||
|
|
||||||
|
(component::AUTHENTICATION, 0x0A) => "login",
|
||||||
|
(component::AUTHENTICATION, 0x0B) => "trustedLogin",
|
||||||
|
(component::AUTHENTICATION, 0x14) => "updateAccount",
|
||||||
|
(component::AUTHENTICATION, 0x15) => "upgradeAccount",
|
||||||
|
(component::AUTHENTICATION, 0x1D) => "listUserEntitlements2",
|
||||||
|
(component::AUTHENTICATION, 0x1E) => "getAccount",
|
||||||
|
(component::AUTHENTICATION, 0x1F) => "grantEntitlement",
|
||||||
|
(component::AUTHENTICATION, 0x20) => "listEntitlements",
|
||||||
|
(component::AUTHENTICATION, 0x22) => "getUseCount",
|
||||||
|
(component::AUTHENTICATION, 0x23) => "decrementUseCount",
|
||||||
|
(component::AUTHENTICATION, 0x24) => "getAuthToken",
|
||||||
|
(component::AUTHENTICATION, 0x26) => "getPasswordRules",
|
||||||
|
(component::AUTHENTICATION, 0x27) => "grantEntitlement2",
|
||||||
|
(component::AUTHENTICATION, 0x2B) => "modifyEntitlement2",
|
||||||
|
(component::AUTHENTICATION, 0x2C) => "consumecode",
|
||||||
|
(component::AUTHENTICATION, 0x2D) => "passwordForgot",
|
||||||
|
(component::AUTHENTICATION, 0x2F) => "getPrivacyPolicyContent",
|
||||||
|
(component::AUTHENTICATION, 0x30) => "listPersonaEntitlements2",
|
||||||
|
(component::AUTHENTICATION, 0x33) => "checkAgeReq",
|
||||||
|
(component::AUTHENTICATION, 0x34) => "getOptIn",
|
||||||
|
(component::AUTHENTICATION, 0x35) => "enableOptIn",
|
||||||
|
(component::AUTHENTICATION, 0x36) => "disableOptIn",
|
||||||
|
(component::AUTHENTICATION, 0x3C) => "expressLogin",
|
||||||
|
(component::AUTHENTICATION, 0x46) => "logout",
|
||||||
|
(component::AUTHENTICATION, 0x5A) => "getPersona",
|
||||||
|
(component::AUTHENTICATION, 0x64) => "listPersonas",
|
||||||
|
(component::AUTHENTICATION, 0x65) => "expressCreateAccount",
|
||||||
|
(component::AUTHENTICATION, 0xE6) => "createWalUserSession",
|
||||||
|
(component::AUTHENTICATION, 0xF1) => "acceptLegalDocs",
|
||||||
|
(component::AUTHENTICATION, 0xF2) => "getEmailOptInSettings",
|
||||||
|
(component::AUTHENTICATION, 0xF6) => "getTermsOfServiceContent",
|
||||||
|
(component::AUTHENTICATION, 0x104) => "getOriginPersona",
|
||||||
|
(component::AUTHENTICATION, 0x10E) => "checkEmail",
|
||||||
|
(component::AUTHENTICATION, 0x118) => "getPersonaNameSuggestions",
|
||||||
|
(component::AUTHENTICATION, 0x122) => "guestLogin",
|
||||||
|
|
||||||
|
(component::CENSUS_DATA, 0x01) => "subscribeToCensusData",
|
||||||
|
(component::CENSUS_DATA, 0x02) => "unsubscribeFromCensusData",
|
||||||
|
(component::CENSUS_DATA, 0x03) => "getRegionCounts",
|
||||||
|
(component::CENSUS_DATA, 0x04) => "getLatestCensusData",
|
||||||
|
(component::CENSUS_DATA, 0x05) => "subscribeToCensusDataUpdates",
|
||||||
|
|
||||||
|
(component::USER_SESSIONS, 0x14) => "updateNetworkInfo",
|
||||||
|
(component::ASSOCIATION_LISTS, 0x06) => "getLists",
|
||||||
|
_ => return None,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
pub fn notification_name(component: u16, notify_id: u16) -> Option<&'static str> {
|
||||||
|
if component != component::USER_SESSIONS {
|
||||||
|
return None;
|
||||||
|
}
|
||||||
|
Some(match notify_id {
|
||||||
|
0x01 => "UserSessionExtendedDataUpdate",
|
||||||
|
0x02 => "UserAdded",
|
||||||
|
0x03 => "UserRemoved",
|
||||||
|
0x05 => "UserUpdated",
|
||||||
|
0x08 => "UserAuthenticated",
|
||||||
|
0x09 => "UserUnauthenticated",
|
||||||
|
0x0C => "ServerDraining",
|
||||||
|
_ => return None,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Human-readable label for a route, for logs and captures.
|
||||||
|
pub fn describe(component: u16, command: u16, is_notification: bool) -> String {
|
||||||
|
let comp = component_name(component)
|
||||||
|
.map(str::to_string)
|
||||||
|
.unwrap_or_else(|| format!("Component:0x{component:04x}"));
|
||||||
|
if is_notification {
|
||||||
|
if let Some(n) = notification_name(component, command) {
|
||||||
|
return format!("{comp}::<{n}>");
|
||||||
|
}
|
||||||
|
return format!("{comp}::<notify:0x{command:04x}>");
|
||||||
|
}
|
||||||
|
match command_name(component, command) {
|
||||||
|
Some(name) => format!("{comp}::{name}"),
|
||||||
|
None => format!("{comp}::cmd:0x{command:04x}"),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn describes_the_first_rpc_fifa_sends() {
|
||||||
|
assert_eq!(
|
||||||
|
describe(component::UTIL, util::PRE_AUTH, false),
|
||||||
|
"Util::preAuth"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn commands_and_notifications_are_separate_number_spaces() {
|
||||||
|
// 0x0002 is UserSessions "UserAdded" as a notification, but is not a
|
||||||
|
// known UserSessions *command*.
|
||||||
|
assert_eq!(
|
||||||
|
describe(component::USER_SESSIONS, 0x0002, true),
|
||||||
|
"UserSessions::<UserAdded>"
|
||||||
|
);
|
||||||
|
assert_eq!(
|
||||||
|
describe(component::USER_SESSIONS, 0x0002, false),
|
||||||
|
"UserSessions::cmd:0x0002"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn unknown_routes_degrade_to_numbers() {
|
||||||
|
assert_eq!(
|
||||||
|
describe(0x1234, 0x0001, false),
|
||||||
|
"Component:0x1234::cmd:0x0001"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn advertised_components_are_in_oracle_order() {
|
||||||
|
// A list, not a struct: the encoder will NOT sort these, so the order
|
||||||
|
// here is the order on the wire.
|
||||||
|
assert_eq!(ADVERTISED_COMPONENT_IDS[0], 0x0001);
|
||||||
|
assert_eq!(ADVERTISED_COMPONENT_IDS[8], 0x7802);
|
||||||
|
assert_eq!(ADVERTISED_COMPONENT_IDS.len(), 9);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,31 @@
|
|||||||
|
//! FIFA 17 Blaze adapter.
|
||||||
|
//!
|
||||||
|
//! Sits on `openfut-protocol-blaze` (Fire2 framing + Heat2/TDF) and supplies
|
||||||
|
//! everything the generic layer deliberately refuses to know: which component
|
||||||
|
//! and command numbers mean what, what each response body must contain, and in
|
||||||
|
//! what order frames leave the server.
|
||||||
|
//!
|
||||||
|
//! ```text
|
||||||
|
//! FIFA 17 client
|
||||||
|
//! │ Fire2 frames
|
||||||
|
//! openfut-protocol-blaze generic: framing + codec
|
||||||
|
//! │ Header + Struct
|
||||||
|
//! blaze::Adapter THIS: FIFA 17 ids, bodies, ordering
|
||||||
|
//! │ (future) semantic calls
|
||||||
|
//! OpenFUT Core game-independent FUT domain
|
||||||
|
//! ```
|
||||||
|
//!
|
||||||
|
//! Blaze is an auth/session/config protocol: no coins, packs, clubs or squads
|
||||||
|
//! appear on this wire, so the adapter carries no FUT domain state and has no
|
||||||
|
//! reason to grow into a second backend.
|
||||||
|
|
||||||
|
pub mod client_config;
|
||||||
|
pub mod config;
|
||||||
|
pub mod dispatch;
|
||||||
|
pub mod ids;
|
||||||
|
pub mod responses;
|
||||||
|
pub mod session;
|
||||||
|
|
||||||
|
pub use config::{AdapterConfig, Endpoints, Identity};
|
||||||
|
pub use dispatch::Adapter;
|
||||||
|
pub use session::Session;
|
||||||
@@ -0,0 +1,623 @@
|
|||||||
|
//! FIFA 17 Blaze response bodies.
|
||||||
|
//!
|
||||||
|
//! Every builder here mirrors a `Blaze::*` TDF class reversed from FIFA17.exe's
|
||||||
|
//! own reflection metadata. Member counts and tags are not guesses, and the
|
||||||
|
//! comments carry the class addresses so a future reader can re-derive them.
|
||||||
|
//!
|
||||||
|
//! Two recurring rules, both learned the hard way:
|
||||||
|
//!
|
||||||
|
//! * **An absent member is safe; a wrongly-typed one is fatal.** A member the
|
||||||
|
//! client does not receive keeps its client-side default. A member encoded
|
||||||
|
//! with the wrong wire type desynchronises the whole TDF parse. That is why
|
||||||
|
//! `CGID`, `ADDR`, `CVAR` and `ULST` are omitted rather than guessed — their
|
||||||
|
//! union/objid encodings are UNVERIFIED.
|
||||||
|
//! * **Identity must be byte-identical across responses.** `MAIL`/`UID`/`ASRC`
|
||||||
|
//! in `AccountInfo` must match `LoginResponse.SESS` and `PreAuthResponse.NASP`,
|
||||||
|
//! and the session key must be the same string in three places.
|
||||||
|
//!
|
||||||
|
//! Member order in the source below is the oracle's for readability; the
|
||||||
|
//! encoder sorts by packed tag, so source order never reaches the wire.
|
||||||
|
|
||||||
|
use openfut_protocol_blaze::heat2::{Struct, TypeId, Value};
|
||||||
|
|
||||||
|
use super::client_config;
|
||||||
|
use super::config::AdapterConfig;
|
||||||
|
use super::ids::ADVERTISED_COMPONENT_IDS;
|
||||||
|
use super::session::Session;
|
||||||
|
|
||||||
|
fn s(v: impl Into<String>) -> Value {
|
||||||
|
Value::String(v.into())
|
||||||
|
}
|
||||||
|
|
||||||
|
fn i(v: i64) -> Value {
|
||||||
|
Value::Int(v)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `Blaze::Util::FetchConfigResponse` @0x1448752e0 — a single `CONF`
|
||||||
|
/// map<string,string>.
|
||||||
|
///
|
||||||
|
/// NOT double-nested. The extra nesting exists only inside `PreAuthResponse`,
|
||||||
|
/// where `CONF` is itself a `FetchConfigResponse` whose own single member is
|
||||||
|
/// also called `CONF`. Easy to get wrong.
|
||||||
|
pub fn fetch_config_response(cfid: &str, cfg: &AdapterConfig) -> Struct {
|
||||||
|
let entries = client_config::rows_for(cfid, cfg)
|
||||||
|
.into_iter()
|
||||||
|
.map(|(k, v)| (Value::String(k), Value::String(v)))
|
||||||
|
.collect();
|
||||||
|
Struct::new().with(
|
||||||
|
"CONF",
|
||||||
|
Value::Map {
|
||||||
|
key: TypeId::String,
|
||||||
|
val: TypeId::String,
|
||||||
|
entries,
|
||||||
|
},
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `Blaze::QosConfigInfo` — 4 members.
|
||||||
|
///
|
||||||
|
/// FIFA 17's descriptor has no `SVID`, unlike Mirror's Edge Catalyst; do not
|
||||||
|
/// add one back from another title's emulator.
|
||||||
|
pub fn qos_config(cfg: &AdapterConfig) -> Struct {
|
||||||
|
Struct::new()
|
||||||
|
.with(
|
||||||
|
"BWPS",
|
||||||
|
Value::Struct(
|
||||||
|
Struct::new()
|
||||||
|
.with("PSA", s(&cfg.endpoints.advertise))
|
||||||
|
.with("PSP", i(cfg.endpoints.qos_port)),
|
||||||
|
),
|
||||||
|
)
|
||||||
|
.with("LNP", i(10))
|
||||||
|
.with(
|
||||||
|
"LTPS",
|
||||||
|
Value::Map {
|
||||||
|
key: TypeId::String,
|
||||||
|
val: TypeId::Struct,
|
||||||
|
entries: vec![],
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.with("TIME", i(5_000_000))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `Blaze::Util::PreAuthResponse`.
|
||||||
|
pub fn preauth_response(service_name: &str, cfg: &AdapterConfig) -> Struct {
|
||||||
|
let id = &cfg.identity;
|
||||||
|
Struct::new()
|
||||||
|
.with("ASRC", s(&id.title_id))
|
||||||
|
.with(
|
||||||
|
"CIDS",
|
||||||
|
Value::List {
|
||||||
|
elem: TypeId::Int,
|
||||||
|
items: ADVERTISED_COMPONENT_IDS.iter().copied().map(i).collect(),
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.with("CLID", s(&id.client_id))
|
||||||
|
.with(
|
||||||
|
"CONF",
|
||||||
|
Value::Struct(fetch_config_response("BlazeSDK", cfg)),
|
||||||
|
)
|
||||||
|
.with("ESRC", s(&id.title_id))
|
||||||
|
.with("INST", s(service_name)) // echo of CDAT.SVCN
|
||||||
|
.with("MAID", i(0))
|
||||||
|
.with("MINR", i(0))
|
||||||
|
.with("NASP", s(&id.namespace))
|
||||||
|
.with("PILD", s(""))
|
||||||
|
.with("PLAT", s(&id.platform))
|
||||||
|
.with("QOSS", Value::Struct(qos_config(cfg)))
|
||||||
|
.with("RSRC", s(&id.title_id))
|
||||||
|
.with("SVER", s(&cfg.server_version))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `Blaze::Util::PingResponse` @0x144875560 — exactly one member.
|
||||||
|
///
|
||||||
|
/// v2 also sent `TIME`; that is MEC's field, not FIFA 17's.
|
||||||
|
pub fn ping_response(now: i64) -> Struct {
|
||||||
|
Struct::new().with("STIM", i(now))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `Blaze::CensusData::SubscribeToCensusDataUpdatesResponse` — 3 TimeValues,
|
||||||
|
/// encoded as INT microseconds.
|
||||||
|
///
|
||||||
|
/// These must be non-zero. The client computes `delay_ms = (CNP + NTMT) / 1000`
|
||||||
|
/// and re-arms a resend timer; an empty reply gives delay 0, which lands the job
|
||||||
|
/// on the scheduler's ready list and produces a ~30/s re-subscribe storm that
|
||||||
|
/// hangs the FUT loading screen.
|
||||||
|
pub fn census_subscribe_response() -> Struct {
|
||||||
|
Struct::new()
|
||||||
|
.with("CNP", i(30 * 1_000_000))
|
||||||
|
.with("NTMT", i(90 * 1_000_000))
|
||||||
|
.with("RTMT", i(300 * 1_000_000))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `Blaze::Authentication::PersonaDetails` @0x14487cab0 — 6 members.
|
||||||
|
pub fn persona_details(now: i64, cfg: &AdapterConfig) -> Struct {
|
||||||
|
let id = &cfg.identity;
|
||||||
|
Struct::new()
|
||||||
|
.with("DSNM", s(&id.persona_name))
|
||||||
|
.with("LAST", i(now))
|
||||||
|
.with("PID", i(id.persona_id))
|
||||||
|
.with("PLAT", i(id.client_platform))
|
||||||
|
.with("STAS", i(id.persona_status))
|
||||||
|
.with("XREF", i(id.ext_id))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `Blaze::Authentication::UserLoginInfo` @0x14487cb00 — 8 members.
|
||||||
|
///
|
||||||
|
/// `'1CON'` packs to 0x11, which sorts below `'A'` = 0x21, so it leads.
|
||||||
|
pub fn user_login_info(sess: &Session, now: i64, cfg: &AdapterConfig) -> Struct {
|
||||||
|
let id = &cfg.identity;
|
||||||
|
Struct::new()
|
||||||
|
.with("1CON", i(0))
|
||||||
|
.with("BUID", i(id.user_id)) // must be non-zero
|
||||||
|
.with("FRST", i(0))
|
||||||
|
.with("KEY", s(&sess.session_key)) // must be non-empty
|
||||||
|
.with("LLOG", i(now))
|
||||||
|
.with("MAIL", s(&id.email))
|
||||||
|
.with("PDTL", Value::Struct(persona_details(now, cfg)))
|
||||||
|
.with("UID", i(id.user_id)) // must be non-zero
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `Blaze::Authentication::LoginResponse` @0x14487d170 — exactly 5 members.
|
||||||
|
///
|
||||||
|
/// Diverges from both public MEC emulators, which emit `CNTX`, `ERRC` and a
|
||||||
|
/// top-level `SKEY`. FIFA 17 has none of those: `CNTX`/`ERRC` are the Blaze
|
||||||
|
/// error-metadata block, and the session key lives at `SESS.KEY`.
|
||||||
|
pub fn login_response(sess: &Session, now: i64, cfg: &AdapterConfig) -> Struct {
|
||||||
|
Struct::new()
|
||||||
|
.with("ANON", i(0))
|
||||||
|
.with("NTOS", i(0)) // 1 would divert to the legal-doc flow
|
||||||
|
.with("SESS", Value::Struct(user_login_info(sess, now, cfg)))
|
||||||
|
.with("SPAM", i(1))
|
||||||
|
.with("UNDR", i(0))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// ISO-8601 UTC, matching the oracle's `%Y-%m-%dT%H:%M:%SZ`.
|
||||||
|
///
|
||||||
|
/// Hand-rolled from a Unix timestamp to keep this crate free of a date
|
||||||
|
/// dependency for one format string. Proleptic Gregorian, no leap seconds —
|
||||||
|
/// the same calendar `time.gmtime` uses.
|
||||||
|
fn iso8601_utc(unix: i64) -> String {
|
||||||
|
let days = unix.div_euclid(86_400);
|
||||||
|
let secs = unix.rem_euclid(86_400);
|
||||||
|
let (h, mi, sec) = (secs / 3600, (secs % 3600) / 60, secs % 60);
|
||||||
|
|
||||||
|
// Civil-from-days (Howard Hinnant's algorithm), shifted to a March-based year.
|
||||||
|
let z = days + 719_468;
|
||||||
|
let era = z.div_euclid(146_097);
|
||||||
|
let doe = z.rem_euclid(146_097);
|
||||||
|
let yoe = (doe - doe / 1460 + doe / 36_524 - doe / 146_096) / 365;
|
||||||
|
let y = yoe + era * 400;
|
||||||
|
let doy = doe - (365 * yoe + yoe / 4 - yoe / 100);
|
||||||
|
let mp = (5 * doy + 2) / 153;
|
||||||
|
let d = doy - (153 * mp + 2) / 5 + 1;
|
||||||
|
let m = if mp < 10 { mp + 3 } else { mp - 9 };
|
||||||
|
let y = if m <= 2 { y + 1 } else { y };
|
||||||
|
|
||||||
|
format!("{y:04}-{m:02}-{d:02}T{h:02}:{mi:02}:{sec:02}Z")
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `Blaze::Authentication::AccountInfo` @0x14487c810 — exactly 16 members.
|
||||||
|
///
|
||||||
|
/// The RPC behind the "Unable to retrieve account information" popup: before it
|
||||||
|
/// was implemented, the empty-reply fallback produced an AccountInfo with
|
||||||
|
/// `UID=0`/`CO=""` and the popup appeared one layer later.
|
||||||
|
///
|
||||||
|
/// Member tags come from the reflection tag table @0x1448775a0; wire types from
|
||||||
|
/// each member's subtype descriptor (string subtype 0x144867628 covers ASRC CO
|
||||||
|
/// DOB DTCR LATH LN MAIL PML; the other eight are int/enum). Enum values:
|
||||||
|
/// `STAS` = AccountStatus ACTIVE = 1, `STAT` = EmailStatus VERIFIED = 2,
|
||||||
|
/// `RC` = StatusReason none = 0.
|
||||||
|
pub fn account_info(now: i64, cfg: &AdapterConfig) -> Struct {
|
||||||
|
let id = &cfg.identity;
|
||||||
|
Struct::new()
|
||||||
|
.with("AMU", i(0))
|
||||||
|
.with("ASRC", s(&id.namespace)) // == PreAuthResponse.NASP
|
||||||
|
.with("CO", s("US"))
|
||||||
|
.with("DOB", s("1990-01-01T00:00:00Z"))
|
||||||
|
.with("DTCR", s("2016-09-01T00:00:00Z"))
|
||||||
|
.with("GOPT", i(0))
|
||||||
|
.with("LATH", s(iso8601_utc(now)))
|
||||||
|
.with("LN", s(&id.locale))
|
||||||
|
.with("MAIL", s(&id.email)) // == LoginResponse.SESS.MAIL
|
||||||
|
.with("PML", s(""))
|
||||||
|
.with("RC", i(0))
|
||||||
|
.with("STAS", i(1))
|
||||||
|
.with("STAT", i(2))
|
||||||
|
.with("TPOT", i(0))
|
||||||
|
.with("UDU", i(0))
|
||||||
|
.with("UID", i(id.user_id)) // == LoginResponse.SESS.UID
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `Blaze::Authentication::PersonaInfo` @0x14487c7c0 — 7 members.
|
||||||
|
///
|
||||||
|
/// `STAS` here is PersonaStatus ACTIVE = 2 (table 0x14487ad20) — a different
|
||||||
|
/// enum from AccountInfo's `STAS`, which is AccountStatus ACTIVE = 1. `LADT`'s
|
||||||
|
/// wire type is a best guess (INT timestamp); it is only reachable via
|
||||||
|
/// getPersona/listPersonas, off the critical getAccount path.
|
||||||
|
pub fn persona_info(now: i64, cfg: &AdapterConfig) -> Struct {
|
||||||
|
let id = &cfg.identity;
|
||||||
|
Struct::new()
|
||||||
|
.with("DSNM", s(&id.persona_name))
|
||||||
|
.with("DTCR", s("2016-09-01T00:00:00Z"))
|
||||||
|
.with("LADT", i(now))
|
||||||
|
.with("NSNM", s(&id.namespace))
|
||||||
|
.with("PID", i(id.persona_id))
|
||||||
|
.with("STAS", i(2))
|
||||||
|
.with("STRC", i(0))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `Blaze::Authentication::GetPersonaResponse` @0x14487d1c0 — PINF + UID.
|
||||||
|
pub fn get_persona_response(now: i64, cfg: &AdapterConfig) -> Struct {
|
||||||
|
Struct::new()
|
||||||
|
.with("PINF", Value::Struct(persona_info(now, cfg)))
|
||||||
|
.with("UID", i(cfg.identity.user_id))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `Blaze::Authentication::ListPersonasResponse` @0x14487d210 — one member.
|
||||||
|
pub fn list_personas_response(now: i64, cfg: &AdapterConfig) -> Struct {
|
||||||
|
Struct::new().with(
|
||||||
|
"PINF",
|
||||||
|
Value::List {
|
||||||
|
elem: TypeId::Struct,
|
||||||
|
items: vec![Value::Struct(persona_info(now, cfg))],
|
||||||
|
},
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `Blaze::UserSessionLoginInfo` @0x14486f920 — 16 members.
|
||||||
|
///
|
||||||
|
/// A superset of `UserLoginInfo` with the persona fields flattened in rather
|
||||||
|
/// than nested. `KEY` must be byte-identical to `LoginResponse.SESS.KEY`.
|
||||||
|
///
|
||||||
|
/// `CGID` (a connectionGroup ObjectId) is omitted: the OBJID encoding is
|
||||||
|
/// UNVERIFIED and a wrong one desynchronises the parse, while an absent member
|
||||||
|
/// simply keeps its default.
|
||||||
|
pub fn user_session_login_info(sess: &Session, now: i64, cfg: &AdapterConfig) -> Struct {
|
||||||
|
let id = &cfg.identity;
|
||||||
|
Struct::new()
|
||||||
|
.with("1CON", i(0))
|
||||||
|
.with("ALOC", i(sess.account_locale)) // echo the client's own locale
|
||||||
|
.with("BUID", i(id.user_id))
|
||||||
|
.with("DSNM", s(&id.persona_name))
|
||||||
|
.with("FRST", i(0))
|
||||||
|
.with("KEY", s(&sess.session_key)) // same string as LoginResponse
|
||||||
|
.with("LAST", i(now))
|
||||||
|
.with("LLOG", i(now))
|
||||||
|
.with("MAIL", s(&id.email))
|
||||||
|
.with("NASP", s(&id.namespace))
|
||||||
|
.with("PID", i(id.persona_id))
|
||||||
|
.with("PLAT", i(id.client_platform))
|
||||||
|
.with("UID", i(id.user_id))
|
||||||
|
.with("USTP", i(id.user_session_type))
|
||||||
|
.with("XREF", i(id.ext_id))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `Blaze::Util::NetworkQosData` @0x14486e680 — 5 members. `NATT` 0 = OPEN.
|
||||||
|
pub fn network_qos_data() -> Struct {
|
||||||
|
Struct::new()
|
||||||
|
.with("BWHR", i(0))
|
||||||
|
.with("DBPS", i(100_000))
|
||||||
|
.with("NAHR", i(0))
|
||||||
|
.with("NATT", i(0))
|
||||||
|
.with("UBPS", i(100_000))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `Blaze::UserSessionExtendedData` @0x144870390.
|
||||||
|
///
|
||||||
|
/// Two FIFA-17-specific deltas from the MEC emulators: FIFA HAS `PSLM`
|
||||||
|
/// (latencyList), which they lack, and FIFA carries `BPS` as a top-level string
|
||||||
|
/// whereas they bury it inside the `ADDR` union. Follow FIFA's layout.
|
||||||
|
///
|
||||||
|
/// `ADDR`, `CVAR` and `ULST` are omitted — unverified union/objid encodings.
|
||||||
|
pub fn user_session_extended_data() -> Struct {
|
||||||
|
Struct::new()
|
||||||
|
.with("BPS", s("openfut"))
|
||||||
|
.with("CTY", s("US"))
|
||||||
|
.with(
|
||||||
|
"DMAP",
|
||||||
|
Value::Map {
|
||||||
|
key: TypeId::Int,
|
||||||
|
val: TypeId::Int,
|
||||||
|
entries: vec![],
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.with("HWFG", i(0))
|
||||||
|
.with("ISP", s("OpenFUT"))
|
||||||
|
.with(
|
||||||
|
"PSLM",
|
||||||
|
Value::List {
|
||||||
|
elem: TypeId::Int,
|
||||||
|
items: vec![i(0)],
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.with("QDAT", Value::Struct(network_qos_data()))
|
||||||
|
.with("TZ", s(""))
|
||||||
|
.with("UATT", i(0))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `Blaze::UserSessionExtendedDataUpdate` @0x1448703e0 — 3 members.
|
||||||
|
pub fn user_session_extended_data_update(cfg: &AdapterConfig) -> Struct {
|
||||||
|
Struct::new()
|
||||||
|
.with("DATA", Value::Struct(user_session_extended_data()))
|
||||||
|
.with("SUBS", i(1))
|
||||||
|
.with("USID", i(cfg.identity.user_id))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `Blaze::UserIdentification` @0x14486ebc0 — 9 members.
|
||||||
|
pub fn user_identification(sess: &Session, cfg: &AdapterConfig) -> Struct {
|
||||||
|
let id = &cfg.identity;
|
||||||
|
Struct::new()
|
||||||
|
.with("AID", i(id.user_id))
|
||||||
|
.with("ALOC", i(sess.account_locale))
|
||||||
|
.with("EXBB", Value::Blob(vec![]))
|
||||||
|
.with("EXID", i(id.ext_id))
|
||||||
|
.with("ID", i(id.user_id))
|
||||||
|
.with("NAME", s(&id.persona_name))
|
||||||
|
.with("NASP", s(&id.namespace))
|
||||||
|
.with("ORIG", i(id.persona_id))
|
||||||
|
.with("PIDI", i(id.persona_id))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `Blaze::UserData` @0x1448706b0 — payload of the `UserAdded` push.
|
||||||
|
/// `FLGS` is a UserDataFlags bitfield; bit 0 = online/authenticated.
|
||||||
|
pub fn user_data(sess: &Session, cfg: &AdapterConfig) -> Struct {
|
||||||
|
Struct::new()
|
||||||
|
.with("EDAT", Value::Struct(user_session_extended_data()))
|
||||||
|
.with("FLGS", i(3))
|
||||||
|
.with("USER", Value::Struct(user_identification(sess, cfg)))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `Blaze::Util::PostAuthResponse` @0x144875810 — TELE, TICK, UROP.
|
||||||
|
///
|
||||||
|
/// Telemetry and ticker point at dead local ports on purpose: the client gets a
|
||||||
|
/// well-formed config and then fails to connect quietly, rather than resolving
|
||||||
|
/// a real EA hostname.
|
||||||
|
pub fn post_auth_response(sess: &Session, cfg: &AdapterConfig) -> Struct {
|
||||||
|
let tele = Struct::new()
|
||||||
|
.with("ADRS", s(&cfg.endpoints.advertise))
|
||||||
|
.with("ANON", i(0))
|
||||||
|
.with("DISA", s(""))
|
||||||
|
.with("EDCT", i(0))
|
||||||
|
.with("FILT", s(""))
|
||||||
|
.with("LOC", i(sess.account_locale))
|
||||||
|
.with("MINR", i(0))
|
||||||
|
.with("NOOK", s(""))
|
||||||
|
.with("PORT", i(cfg.endpoints.telemetry_port))
|
||||||
|
.with("SDLY", i(15_000))
|
||||||
|
.with("SESS", s(&sess.session_key)) // same key as login
|
||||||
|
.with("SKEY", s(""))
|
||||||
|
.with("SPCT", i(75))
|
||||||
|
.with("STIM", s(""))
|
||||||
|
.with("SVNM", s("telemetry-openfut"));
|
||||||
|
|
||||||
|
let tick = Struct::new()
|
||||||
|
.with("ADRS", s(&cfg.endpoints.advertise))
|
||||||
|
.with("PORT", i(cfg.endpoints.ticker_port))
|
||||||
|
.with("SKEY", s(""));
|
||||||
|
|
||||||
|
let urop = Struct::new()
|
||||||
|
.with("TMOP", i(0))
|
||||||
|
.with("UID", i(cfg.identity.user_id));
|
||||||
|
|
||||||
|
Struct::new()
|
||||||
|
.with("TELE", Value::Struct(tele))
|
||||||
|
.with("TICK", Value::Struct(tick))
|
||||||
|
.with("UROP", Value::Struct(urop))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `Blaze::Authentication::Entitlement` @0x14487d490 — 16 members.
|
||||||
|
///
|
||||||
|
/// FUT's client-side filter (`onListEntitlements` @0x146f27440) keeps a record
|
||||||
|
/// only if `GNAM` contains `"FIFA17PCBoxContent"` or `"FIFA16PC"`, `TAG` is
|
||||||
|
/// non-empty, and `STAT == 1`. A plain `"FIFA17PC"` group matched neither
|
||||||
|
/// needle and produced an empty store.
|
||||||
|
///
|
||||||
|
/// `PRID`/`GNAM`/`TAG` must contain no `'|'` and no `'/'`: the client
|
||||||
|
/// re-serialises them as `PRID|GNAM|TAG|UCNT/`.
|
||||||
|
pub fn entitlement(group: &str, tag: &str, eid: i64, cfg: &AdapterConfig) -> Struct {
|
||||||
|
let id = &cfg.identity;
|
||||||
|
Struct::new()
|
||||||
|
.with("DEVI", s(""))
|
||||||
|
.with("GDAY", s("2016-09-01T00:00:00Z"))
|
||||||
|
.with("GNAM", s(group))
|
||||||
|
.with("ID", i(eid))
|
||||||
|
.with("ISCO", i(0))
|
||||||
|
.with("PID", i(id.persona_id))
|
||||||
|
.with("PJID", s(&id.content_id))
|
||||||
|
.with("PRCA", i(2))
|
||||||
|
.with("PRID", s(&id.content_id))
|
||||||
|
.with("STAT", i(1)) // must be 1 or FUT drops it
|
||||||
|
.with("STRC", i(0))
|
||||||
|
.with("TAG", s(tag)) // must be non-empty
|
||||||
|
.with("TDAY", s(""))
|
||||||
|
.with("TYPE", i(1))
|
||||||
|
.with("UCNT", i(0))
|
||||||
|
.with("VER", i(1))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `Blaze::Authentication::Entitlements` @0x14487d4e0 — single member `NLST`.
|
||||||
|
///
|
||||||
|
/// Emits BOTH accepted groups so the entitlement manager's "loaded" flag
|
||||||
|
/// (`byte[entMgr+0x88]`) flips however the client asks.
|
||||||
|
pub fn entitlements_response(cfg: &AdapterConfig) -> Struct {
|
||||||
|
let tag = &cfg.identity.entitlement_tag;
|
||||||
|
Struct::new().with(
|
||||||
|
"NLST",
|
||||||
|
Value::List {
|
||||||
|
elem: TypeId::Struct,
|
||||||
|
items: vec![
|
||||||
|
Value::Struct(entitlement("FIFA17PCBoxContent", tag, 1, cfg)),
|
||||||
|
Value::Struct(entitlement("FIFA16PC", tag, 2, cfg)),
|
||||||
|
],
|
||||||
|
},
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `Blaze::Authentication::GetAuthTokenResponse` @0x14487d080 — one member.
|
||||||
|
pub fn get_auth_token_response(sess: &Session) -> Struct {
|
||||||
|
Struct::new().with("AUTH", s(sess.auth_token()))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `Util::userSettingsLoad` response.
|
||||||
|
///
|
||||||
|
/// TODO(verify): the response descriptor was never reflected. Both independent
|
||||||
|
/// clean-room emulators use a single `DATA` string, and an unknown-tag payload
|
||||||
|
/// is ignored rather than fatal, so an empty `DATA` is the safe minimum — the
|
||||||
|
/// client falls back to its defaults.
|
||||||
|
pub fn user_settings_response() -> Struct {
|
||||||
|
Struct::new().with("DATA", s(""))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `AssociationLists::getLists` response.
|
||||||
|
///
|
||||||
|
/// TODO(verify): FIFA's association-list names are NOT known — do not invent
|
||||||
|
/// them. An empty list is well-formed and means "this user has no association
|
||||||
|
/// lists", which is true offline.
|
||||||
|
pub fn get_lists_response() -> Struct {
|
||||||
|
Struct::new().with(
|
||||||
|
"LMAP",
|
||||||
|
Value::List {
|
||||||
|
elem: TypeId::Struct,
|
||||||
|
items: vec![],
|
||||||
|
},
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
|
||||||
|
fn cfg() -> AdapterConfig {
|
||||||
|
AdapterConfig::loopback()
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn iso8601_matches_known_instants() {
|
||||||
|
assert_eq!(iso8601_utc(0), "1970-01-01T00:00:00Z");
|
||||||
|
assert_eq!(iso8601_utc(1_754_870_400), "2025-08-11T00:00:00Z");
|
||||||
|
// A leap day, to exercise the civil-from-days branch.
|
||||||
|
assert_eq!(iso8601_utc(1_709_164_800), "2024-02-29T00:00:00Z");
|
||||||
|
assert_eq!(iso8601_utc(951_782_400), "2000-02-29T00:00:00Z");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn login_response_has_exactly_five_members() {
|
||||||
|
let sess = Session::new("k", 0);
|
||||||
|
assert_eq!(login_response(&sess, 0, &cfg()).len(), 5);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn account_info_has_exactly_sixteen_members() {
|
||||||
|
assert_eq!(account_info(0, &cfg()).len(), 16);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn session_key_appears_identically_in_all_three_places() {
|
||||||
|
let sess = Session::new("THE-KEY", 0);
|
||||||
|
let c = cfg();
|
||||||
|
|
||||||
|
let login = login_response(&sess, 1, &c);
|
||||||
|
let in_login = login
|
||||||
|
.get("SESS")
|
||||||
|
.and_then(Value::as_struct)
|
||||||
|
.and_then(|s| s.get("KEY"))
|
||||||
|
.and_then(Value::as_str)
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
let notify = user_session_login_info(&sess, 1, &c);
|
||||||
|
let in_notify = notify.get("KEY").and_then(Value::as_str).unwrap();
|
||||||
|
|
||||||
|
let post = post_auth_response(&sess, &c);
|
||||||
|
let in_post = post
|
||||||
|
.get("TELE")
|
||||||
|
.and_then(Value::as_struct)
|
||||||
|
.and_then(|s| s.get("SESS"))
|
||||||
|
.and_then(Value::as_str)
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
assert_eq!(in_login, "THE-KEY");
|
||||||
|
assert_eq!(in_notify, "THE-KEY");
|
||||||
|
assert_eq!(in_post, "THE-KEY");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn identity_is_consistent_between_login_and_account_info() {
|
||||||
|
let sess = Session::new("k", 0);
|
||||||
|
let c = cfg();
|
||||||
|
let acct = account_info(0, &c);
|
||||||
|
let sess_info = user_login_info(&sess, 0, &c);
|
||||||
|
|
||||||
|
assert_eq!(
|
||||||
|
acct.get("MAIL").and_then(Value::as_str),
|
||||||
|
sess_info.get("MAIL").and_then(Value::as_str)
|
||||||
|
);
|
||||||
|
assert_eq!(
|
||||||
|
acct.get("UID").and_then(Value::as_int),
|
||||||
|
sess_info.get("UID").and_then(Value::as_int)
|
||||||
|
);
|
||||||
|
assert_eq!(
|
||||||
|
acct.get("ASRC").and_then(Value::as_str),
|
||||||
|
Some(c.identity.namespace.as_str())
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn entitlement_groups_match_the_clients_needles() {
|
||||||
|
let c = cfg();
|
||||||
|
let list = entitlements_response(&c);
|
||||||
|
let items = match list.get("NLST") {
|
||||||
|
Some(Value::List { items, .. }) => items,
|
||||||
|
_ => panic!("NLST is a list"),
|
||||||
|
};
|
||||||
|
assert_eq!(items.len(), 2);
|
||||||
|
for item in items {
|
||||||
|
let e = item.as_struct().unwrap();
|
||||||
|
let gnam = e.get("GNAM").and_then(Value::as_str).unwrap();
|
||||||
|
assert!(
|
||||||
|
gnam.contains("FIFA17PCBoxContent") || gnam.contains("FIFA16PC"),
|
||||||
|
"group {gnam} matches neither client needle"
|
||||||
|
);
|
||||||
|
assert_eq!(e.get("STAT").and_then(Value::as_int), Some(1));
|
||||||
|
assert!(!e.get("TAG").and_then(Value::as_str).unwrap().is_empty());
|
||||||
|
// The client re-serialises these delimited; a separator would corrupt it.
|
||||||
|
for tag in ["PRID", "GNAM", "TAG"] {
|
||||||
|
let v = e.get(tag).and_then(Value::as_str).unwrap();
|
||||||
|
assert!(
|
||||||
|
!v.contains('|') && !v.contains('/'),
|
||||||
|
"{tag} has a separator"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn census_periods_are_non_zero() {
|
||||||
|
// Zero here is the ~30/s storm that hangs the FUT loading screen.
|
||||||
|
let r = census_subscribe_response();
|
||||||
|
assert!(r.get("CNP").and_then(Value::as_int).unwrap() > 0);
|
||||||
|
assert!(r.get("NTMT").and_then(Value::as_int).unwrap() > 0);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn preauth_echoes_the_requested_service_name() {
|
||||||
|
let p = preauth_response("fifa-2017-pc-de", &cfg());
|
||||||
|
assert_eq!(
|
||||||
|
p.get("INST").and_then(Value::as_str),
|
||||||
|
Some("fifa-2017-pc-de")
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn extended_data_omits_the_unverified_members() {
|
||||||
|
// Absent is safe; a wrong union/objid encoding breaks the whole parse.
|
||||||
|
let d = user_session_extended_data();
|
||||||
|
for absent in ["ADDR", "CVAR", "ULST"] {
|
||||||
|
assert!(d.get(absent).is_none(), "{absent} must stay omitted");
|
||||||
|
}
|
||||||
|
assert!(
|
||||||
|
d.get("PSLM").is_some(),
|
||||||
|
"PSLM is FIFA-specific and required"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,110 @@
|
|||||||
|
//! Per-connection Blaze session state.
|
||||||
|
//!
|
||||||
|
//! Note how little there is: a session key, the client's locale, the echoed
|
||||||
|
//! service name, an auth code and a logged-in flag. That is the whole of it.
|
||||||
|
//!
|
||||||
|
//! This is the point of the adapter boundary. Blaze is an auth/session/config
|
||||||
|
//! protocol — coins, packs, clubs, squads and the rest of the FUT domain never
|
||||||
|
//! appear on this wire, so there is nothing here tempting the adapter into
|
||||||
|
//! becoming a second backend. When UTAS is migrated that discipline will need
|
||||||
|
//! actively defending; here it comes for free.
|
||||||
|
|
||||||
|
/// State carried across RPCs on one Blaze connection.
|
||||||
|
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||||
|
pub struct Session {
|
||||||
|
/// Minted once per connection. Must appear byte-identically in
|
||||||
|
/// `LoginResponse.SESS.KEY`, the `UserAuthenticated` push, and
|
||||||
|
/// `PostAuthResponse.TELE.SESS`.
|
||||||
|
pub session_key: String,
|
||||||
|
/// Whatever `LoginRequest.AUTH` carried; echoed back by `getAuthToken`.
|
||||||
|
pub auth_code: String,
|
||||||
|
/// Packed four-char locale, seeded from config and overwritten by the
|
||||||
|
/// client's own preAuth `LANG`/`LOC`.
|
||||||
|
pub account_locale: i64,
|
||||||
|
/// Echoed back as `PreAuthResponse.INST`.
|
||||||
|
pub service_name: String,
|
||||||
|
pub logged_in: bool,
|
||||||
|
pub login_time: i64,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The oracle's default service name when preAuth carries no `CDAT.SVCN`.
|
||||||
|
pub const DEFAULT_SERVICE_NAME: &str = "fifa-2017-pc";
|
||||||
|
|
||||||
|
impl Session {
|
||||||
|
/// Start a session with an explicit key.
|
||||||
|
///
|
||||||
|
/// The key is injected rather than generated internally so it can be made
|
||||||
|
/// deterministic for differential tests — it appears verbatim in three
|
||||||
|
/// different responses, so a self-generated one would make every login
|
||||||
|
/// fixture unreproducible.
|
||||||
|
pub fn new(session_key: impl Into<String>, account_locale: i64) -> Session {
|
||||||
|
Session {
|
||||||
|
session_key: session_key.into(),
|
||||||
|
auth_code: String::new(),
|
||||||
|
account_locale,
|
||||||
|
service_name: DEFAULT_SERVICE_NAME.into(),
|
||||||
|
logged_in: false,
|
||||||
|
login_time: 0,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The token `getAuthToken` returns.
|
||||||
|
///
|
||||||
|
/// Before login there is no auth code, so the oracle synthesises one from
|
||||||
|
/// the session key. Reproduced exactly, including the 16-character slice.
|
||||||
|
pub fn auth_token(&self) -> String {
|
||||||
|
if !self.auth_code.is_empty() {
|
||||||
|
return self.auth_code.clone();
|
||||||
|
}
|
||||||
|
// Byte slicing is safe here in practice (session keys are ASCII), but
|
||||||
|
// char_indices keeps it correct for any injected key.
|
||||||
|
let cut = self
|
||||||
|
.session_key
|
||||||
|
.char_indices()
|
||||||
|
.nth(16)
|
||||||
|
.map(|(i, _)| i)
|
||||||
|
.unwrap_or(self.session_key.len());
|
||||||
|
format!("OPENFUT-{}", &self.session_key[..cut])
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Mint a Blaze-shaped session key: 16 hex, an underscore, then 44 alphanumerics.
|
||||||
|
///
|
||||||
|
/// The client never validates the format — one public emulator ships the
|
||||||
|
/// literal `"0"` — so this only has to be stable within a connection. Callers
|
||||||
|
/// supply the randomness so this crate needs no RNG dependency and stays
|
||||||
|
/// deterministic under test.
|
||||||
|
pub fn format_session_key(high_bits: u64, tail: &str) -> String {
|
||||||
|
format!("{high_bits:016x}_{tail}")
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn synthesises_a_token_before_login() {
|
||||||
|
let s = Session::new("0123456789abcdef_TAIL", 0);
|
||||||
|
assert_eq!(s.auth_token(), "OPENFUT-0123456789abcdef");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn echoes_the_login_auth_code_afterwards() {
|
||||||
|
let mut s = Session::new("0123456789abcdef_TAIL", 0);
|
||||||
|
s.auth_code = "REAL-CODE".into();
|
||||||
|
assert_eq!(s.auth_token(), "REAL-CODE");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn short_session_keys_do_not_panic() {
|
||||||
|
assert_eq!(Session::new("abc", 0).auth_token(), "OPENFUT-abc");
|
||||||
|
assert_eq!(Session::new("", 0).auth_token(), "OPENFUT-");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn session_key_has_the_blaze_shape() {
|
||||||
|
let k = format_session_key(0x0123456789abcdef, &"x".repeat(44));
|
||||||
|
assert_eq!(k.len(), 16 + 1 + 44);
|
||||||
|
assert!(k.starts_with("0123456789abcdef_"));
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,633 @@
|
|||||||
|
//! FIFA 17 **card-definition identity catalog** and owned-item **wire-id policy**.
|
||||||
|
//!
|
||||||
|
//! Two distinct identities (never conflate them):
|
||||||
|
//!
|
||||||
|
//! * **Card definition** — *what card is this?* A semantic OpenFUT
|
||||||
|
//! `CardDefinitionId` maps to a FIFA 17 render identity here:
|
||||||
|
//! `resource_id = (version << 24) | asset_id`. The client resolves
|
||||||
|
//! `resource_id & 0xFFFFFF` (= `asset_id`) against its own local player DB;
|
||||||
|
//! an invented id renders a blank card, so this catalog is authored from
|
||||||
|
//! verified FIFA 17 data (`pool.json` player asset ids), never guessed.
|
||||||
|
//! * **Owned-item instance** — *which exact copy?* A monotonic integer wire id,
|
||||||
|
//! allocated per account by the generic external-identity store; this module
|
||||||
|
//! only holds the FIFA 17 numeric **policy** ([`Fifa17WireItemIdPolicy`]).
|
||||||
|
//!
|
||||||
|
//! The catalog is game DATA (a versioned JSON file), not deployment config, and
|
||||||
|
//! not a generic-Core concern. Unknown definitions resolve to `None` — callers
|
||||||
|
//! drop them, never fabricate an asset id.
|
||||||
|
|
||||||
|
use std::collections::HashMap;
|
||||||
|
|
||||||
|
use serde::Deserialize;
|
||||||
|
|
||||||
|
use crate::fut::content_taxonomy::ContentKind;
|
||||||
|
|
||||||
|
/// The FIFA 17 render identity of a card definition. `version` is the high byte
|
||||||
|
/// of `resource_id`; `asset_id` (the low 24 bits) is the real FIFA player id.
|
||||||
|
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||||
|
pub struct Fifa17CardIdentity {
|
||||||
|
pub asset_id: u32,
|
||||||
|
pub version: u8,
|
||||||
|
pub resource_id: u32,
|
||||||
|
/// FIFA wire `rareflag` (rare/special card TYPE). Carried so specials render
|
||||||
|
/// as specials; observed metadata, not a guessed label.
|
||||||
|
pub rareflag: i64,
|
||||||
|
/// Content class of this definition. A catalog authored before this field
|
||||||
|
/// existed defaults to [`ContentKind::Player`] (backward compatible).
|
||||||
|
pub kind: ContentKind,
|
||||||
|
/// FIFA `cardsubtypeid` for a non-player definition (consumable family /
|
||||||
|
/// staff role), `0` for a player or when absent.
|
||||||
|
pub subtype: i64,
|
||||||
|
/// FIFA card-art class. Players default to `asset_id`; kit definitions carry
|
||||||
|
/// the verified `fcc_kitcards.cardassetid` value (`35`).
|
||||||
|
pub card_asset_id: u32,
|
||||||
|
/// The wire `assetId` for a CLUB item (record `+0x20`), which is family
|
||||||
|
/// specific and is NOT the carddbid: a kit carries the art class from
|
||||||
|
/// `fcc_kitcards.assetid` (`14` home/third band, `15` away band), a badge
|
||||||
|
/// carries its team id, a stadium and a ball their own asset number.
|
||||||
|
///
|
||||||
|
/// Distinct from [`Self::asset_id`], which for these definitions is the
|
||||||
|
/// carddbid and is what `resource_id` is derived from — so the two cannot be
|
||||||
|
/// the same field. Shipping the carddbid here is what left the client
|
||||||
|
/// holding `assetId 6300006` at record `+0x20` where its own table says
|
||||||
|
/// `14`, with both pre-match kit tiles rendering identically.
|
||||||
|
///
|
||||||
|
/// Defaults to `asset_id` when a catalog does not specify it, which is the
|
||||||
|
/// pre-existing behaviour and is correct for every non-club kind.
|
||||||
|
pub club_asset_id: u32,
|
||||||
|
/// Source team id for a club kit, or a manager's real club. Zero for content
|
||||||
|
/// kinds that do not use it.
|
||||||
|
pub team_id: i64,
|
||||||
|
/// Kit slot family (`club_items.json → kits[].category`): `2` home, `3`
|
||||||
|
/// away, `5` third. Zero for definitions that do not use it.
|
||||||
|
///
|
||||||
|
/// Load-bearing for the pre-match kit selector, not cosmetic. The client's
|
||||||
|
/// active-kit resolver (`FUN_1800d73d0`) reads it at record `+0xb8` and maps
|
||||||
|
/// it to the engine's kit SLOT — 2→0, 3→1, 5→3 — which then forms part of
|
||||||
|
/// the `(teamid, year, slot)` triple the kit descriptor
|
||||||
|
/// (`sub_180033430`) must match. Omit it and the triple cannot match, so the
|
||||||
|
/// engine falls through to its own catalogue kit and reports the kit as
|
||||||
|
/// locked.
|
||||||
|
pub category: i64,
|
||||||
|
/// Kit season (`club_items.json → kits[].year`), `0` for a current-season
|
||||||
|
/// kit and e.g. `2002` for a historical one.
|
||||||
|
///
|
||||||
|
/// Record `+0xba`, atom `0x389`. The third member of the identity triple
|
||||||
|
/// above, and the key the runtime `teamkits` clone queries on.
|
||||||
|
pub year: i64,
|
||||||
|
/// Manager chemistry nation (`managercards.nation`), zero when unused.
|
||||||
|
///
|
||||||
|
/// The client NEVER supplies this: the managercards merge (`FUN_1801356c0`)
|
||||||
|
/// leaves the manager-only record slot `rec+0xde` untouched, so the server is
|
||||||
|
/// its only source. See `fifa17-recon/tools/fut_staff.py`.
|
||||||
|
pub nation: i64,
|
||||||
|
/// Manager chemistry league, zero when unused. Derived upstream through
|
||||||
|
/// `manager.teamid` → `leagueteamlinks.leagueid`, because `managercards` has
|
||||||
|
/// no league column. Lands in the equally untouched slot `rec+0xe0`.
|
||||||
|
pub league_id: i64,
|
||||||
|
/// EA's authored `rating` for a NON-PLAYER definition (`fcc_*.rating`), which
|
||||||
|
/// Core does not model: an imported consumable's Core `overall` is 0, while
|
||||||
|
/// the client's own copies carry 55..95 and the value drives the card level
|
||||||
|
/// (`rec+0x54`) and therefore its quick-sell price. `None` → the caller falls
|
||||||
|
/// back to Core's rating, which stays authoritative for players.
|
||||||
|
pub rating: Option<u8>,
|
||||||
|
/// `amount` (atom 0x1b) for a consumable definition — the bonus magnitude EA
|
||||||
|
/// authored in the `fcc_*` row (+5 / +10 / +15 …). MANDATORY for the
|
||||||
|
/// training, healing, fitness, play-style and manager-league families:
|
||||||
|
/// omitting the key draws "-1" on the card, not "0".
|
||||||
|
pub amount: Option<i64>,
|
||||||
|
/// `contract` (atom 0xb8) for a contract-card definition (`cardsubtypeid`
|
||||||
|
/// 201/202) — the number of matches the card grants. `fcc_contractcards` has
|
||||||
|
/// no amount column, so this value comes from observed data; it is never
|
||||||
|
/// defaulted here.
|
||||||
|
pub contract: Option<i64>,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The FIFA 17 numeric namespace policy for owned-item wire ids.
|
||||||
|
///
|
||||||
|
/// Owned-item ids are monotonic from `OWNED_ITEM_BASE + 1` (= 100_000_001,
|
||||||
|
/// matching the oracle's `ITEM_ID_BASE = 100_000_000` and its first minted id),
|
||||||
|
/// staying below the synthetic-overlay ranges the responder uses (≥ 9e8). The
|
||||||
|
/// generic store enforces monotonicity/uniqueness; this type supplies the game,
|
||||||
|
/// entity-kind and base floor.
|
||||||
|
pub struct Fifa17WireItemIdPolicy;
|
||||||
|
|
||||||
|
impl Fifa17WireItemIdPolicy {
|
||||||
|
pub const GAME: &'static str = "fifa17";
|
||||||
|
pub const OWNED_ITEM_KIND: &'static str = "owned-item";
|
||||||
|
pub const OWNED_ITEM_BASE: i64 = 100_000_000;
|
||||||
|
|
||||||
|
/// First owned-item wire id (`100_000_001`).
|
||||||
|
pub fn owned_item_base_floor() -> i64 {
|
||||||
|
Self::OWNED_ITEM_BASE + 1
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Identity scope for MATCH session ids.
|
||||||
|
///
|
||||||
|
/// A match id is deliberately NOT drawn from the owned-item scope. The
|
||||||
|
/// oracle mints both from one counter, which is why an observed match id
|
||||||
|
/// looks like an item id — but that is an artifact of a single-counter save
|
||||||
|
/// file, not a client requirement. Here the identity store keeps a real
|
||||||
|
/// reverse map, so an item-scoped match id would make
|
||||||
|
/// `owned_id_for_wire` resolve a match to a bogus owned card and corrupt
|
||||||
|
/// quick-sell and move. The store is generic over `(game, kind)`, so a
|
||||||
|
/// separate scope costs one constant and cannot collide with, or advance,
|
||||||
|
/// the owned-item watermark.
|
||||||
|
pub const MATCH_KIND: &'static str = "match";
|
||||||
|
|
||||||
|
/// Base for match session ids. Clear of the owned-item range
|
||||||
|
/// (`100_000_000+`) and of every synthetic overlay range the responder
|
||||||
|
/// reserves (`≥ 9e8`). The client only requires a non-zero int.
|
||||||
|
pub const MATCH_BASE: i64 = 200_000_000;
|
||||||
|
|
||||||
|
/// First match wire id (`200_000_001`).
|
||||||
|
pub fn match_base_floor() -> i64 {
|
||||||
|
Self::MATCH_BASE + 1
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Highest representable asset id (24 bits); above this `version` would be
|
||||||
|
/// clobbered in `resource_id`.
|
||||||
|
const MAX_ASSET_ID: u32 = 0x00FF_FFFF;
|
||||||
|
const SCHEMA_VERSION: u32 = 1;
|
||||||
|
|
||||||
|
/// Catalog load/validation errors — all explicit, no silent fallback.
|
||||||
|
#[derive(Debug, PartialEq, Eq)]
|
||||||
|
pub enum CatalogError {
|
||||||
|
BadSchemaVersion(u32),
|
||||||
|
WrongGame(String),
|
||||||
|
AssetTooLarge {
|
||||||
|
card_id: String,
|
||||||
|
asset_id: u32,
|
||||||
|
},
|
||||||
|
DuplicateResource {
|
||||||
|
resource_id: u32,
|
||||||
|
first: String,
|
||||||
|
second: String,
|
||||||
|
},
|
||||||
|
Parse(String),
|
||||||
|
}
|
||||||
|
|
||||||
|
impl std::fmt::Display for CatalogError {
|
||||||
|
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
|
||||||
|
match self {
|
||||||
|
CatalogError::BadSchemaVersion(v) => {
|
||||||
|
write!(f, "unsupported catalog schema_version {v}")
|
||||||
|
}
|
||||||
|
CatalogError::WrongGame(g) => write!(f, "catalog game is '{g}', expected 'fifa17'"),
|
||||||
|
CatalogError::AssetTooLarge { card_id, asset_id } => {
|
||||||
|
write!(f, "card '{card_id}' asset_id {asset_id} exceeds 24 bits")
|
||||||
|
}
|
||||||
|
CatalogError::DuplicateResource {
|
||||||
|
resource_id,
|
||||||
|
first,
|
||||||
|
second,
|
||||||
|
} => write!(
|
||||||
|
f,
|
||||||
|
"resource_id {resource_id} claimed by both '{first}' and '{second}'"
|
||||||
|
),
|
||||||
|
CatalogError::Parse(e) => write!(f, "catalog parse error: {e}"),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
impl std::error::Error for CatalogError {}
|
||||||
|
|
||||||
|
#[derive(Deserialize)]
|
||||||
|
struct RawCatalog {
|
||||||
|
schema_version: u32,
|
||||||
|
game: String,
|
||||||
|
#[serde(default)]
|
||||||
|
cards: std::collections::BTreeMap<String, RawCard>,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Deserialize)]
|
||||||
|
struct RawCard {
|
||||||
|
asset_id: u32,
|
||||||
|
#[serde(default)]
|
||||||
|
version: u8,
|
||||||
|
/// Absent in a base-only catalog → default 1 (rare), preserving prior wire
|
||||||
|
/// behaviour; the production catalog carries the observed value.
|
||||||
|
#[serde(default = "default_rareflag")]
|
||||||
|
rareflag: i64,
|
||||||
|
/// Content class token ("player"|"consumable"|"staff"). Absent → default
|
||||||
|
/// (empty) → [`ContentKind::Player`], so existing player-only catalogs load
|
||||||
|
/// unchanged.
|
||||||
|
#[serde(default)]
|
||||||
|
kind: String,
|
||||||
|
/// FIFA `cardsubtypeid` for a non-player entry; absent → `0`.
|
||||||
|
#[serde(default)]
|
||||||
|
subtype: i64,
|
||||||
|
/// Separate card-art id for non-player definitions; absent → `asset_id`.
|
||||||
|
#[serde(default)]
|
||||||
|
card_asset_id: Option<u32>,
|
||||||
|
/// Wire `assetId` for a club item; defaults to `asset_id`. See
|
||||||
|
/// [`Fifa17CardIdentity::club_asset_id`].
|
||||||
|
club_asset_id: Option<u32>,
|
||||||
|
/// Source team id for a kit or manager definition; absent → `0`.
|
||||||
|
#[serde(default)]
|
||||||
|
team_id: Option<i64>,
|
||||||
|
/// Manager chemistry nation; absent → `0`.
|
||||||
|
#[serde(default)]
|
||||||
|
nation: Option<i64>,
|
||||||
|
/// Manager chemistry league; absent → `0`.
|
||||||
|
#[serde(default)]
|
||||||
|
league_id: Option<i64>,
|
||||||
|
/// EA-authored rating for a non-player definition; absent → Core's rating.
|
||||||
|
#[serde(default)]
|
||||||
|
rating: Option<u8>,
|
||||||
|
/// Consumable bonus magnitude (atom 0x1b); absent → key omitted.
|
||||||
|
#[serde(default)]
|
||||||
|
amount: Option<i64>,
|
||||||
|
/// Contract-card grant (atom 0xb8); absent → key omitted.
|
||||||
|
#[serde(default)]
|
||||||
|
contract: Option<i64>,
|
||||||
|
/// Kit slot family (2 home / 3 away / 5 third); absent → `0`.
|
||||||
|
#[serde(default)]
|
||||||
|
category: Option<i64>,
|
||||||
|
/// Kit season; absent → `0` (current season).
|
||||||
|
#[serde(default)]
|
||||||
|
year: Option<i64>,
|
||||||
|
}
|
||||||
|
|
||||||
|
fn default_rareflag() -> i64 {
|
||||||
|
1
|
||||||
|
}
|
||||||
|
|
||||||
|
/// A loaded, validated FIFA 17 card-definition identity catalog.
|
||||||
|
#[derive(Debug, Default, Clone)]
|
||||||
|
pub struct Fifa17CardCatalog {
|
||||||
|
by_card: HashMap<String, Fifa17CardIdentity>,
|
||||||
|
/// Reverse index: full versioned `resource_id` → the card definition id. The
|
||||||
|
/// wire carries a `resourceId`; the synthetic market must mint the
|
||||||
|
/// authoritative Core `card_id`, never the raw FIFA number.
|
||||||
|
by_resource: HashMap<u32, String>,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Fifa17CardCatalog {
|
||||||
|
/// Parse + validate a catalog document. Rejects wrong schema/game, an
|
||||||
|
/// asset id that would overflow into the version byte, and two card ids
|
||||||
|
/// claiming the same `resource_id` (a semantic-vs-FIFA identity conflict).
|
||||||
|
pub fn from_json_str(s: &str) -> Result<Self, CatalogError> {
|
||||||
|
let raw: RawCatalog =
|
||||||
|
serde_json::from_str(s).map_err(|e| CatalogError::Parse(e.to_string()))?;
|
||||||
|
if raw.schema_version != SCHEMA_VERSION {
|
||||||
|
return Err(CatalogError::BadSchemaVersion(raw.schema_version));
|
||||||
|
}
|
||||||
|
if raw.game != Fifa17WireItemIdPolicy::GAME {
|
||||||
|
return Err(CatalogError::WrongGame(raw.game));
|
||||||
|
}
|
||||||
|
let mut by_card = HashMap::new();
|
||||||
|
let mut by_resource: HashMap<u32, String> = HashMap::new();
|
||||||
|
for (card_id, rc) in raw.cards {
|
||||||
|
if rc.asset_id > MAX_ASSET_ID {
|
||||||
|
return Err(CatalogError::AssetTooLarge {
|
||||||
|
card_id,
|
||||||
|
asset_id: rc.asset_id,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
let resource_id = ((rc.version as u32) << 24) | rc.asset_id;
|
||||||
|
if let Some(first) = by_resource.get(&resource_id) {
|
||||||
|
return Err(CatalogError::DuplicateResource {
|
||||||
|
resource_id,
|
||||||
|
first: first.clone(),
|
||||||
|
second: card_id,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
by_resource.insert(resource_id, card_id.clone());
|
||||||
|
by_card.insert(
|
||||||
|
card_id,
|
||||||
|
Fifa17CardIdentity {
|
||||||
|
asset_id: rc.asset_id,
|
||||||
|
version: rc.version,
|
||||||
|
resource_id,
|
||||||
|
rareflag: rc.rareflag,
|
||||||
|
kind: ContentKind::from_str(&rc.kind),
|
||||||
|
subtype: rc.subtype,
|
||||||
|
card_asset_id: rc.card_asset_id.unwrap_or(rc.asset_id),
|
||||||
|
club_asset_id: rc.club_asset_id.unwrap_or(rc.asset_id),
|
||||||
|
team_id: rc.team_id.unwrap_or(0),
|
||||||
|
category: rc.category.unwrap_or(0),
|
||||||
|
year: rc.year.unwrap_or(0),
|
||||||
|
nation: rc.nation.unwrap_or(0),
|
||||||
|
league_id: rc.league_id.unwrap_or(0),
|
||||||
|
rating: rc.rating,
|
||||||
|
amount: rc.amount,
|
||||||
|
contract: rc.contract,
|
||||||
|
},
|
||||||
|
);
|
||||||
|
}
|
||||||
|
Ok(Fifa17CardCatalog {
|
||||||
|
by_card,
|
||||||
|
by_resource,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Load a catalog from a JSON file.
|
||||||
|
pub fn from_file(path: &std::path::Path) -> Result<Self, CatalogError> {
|
||||||
|
let raw = std::fs::read_to_string(path)
|
||||||
|
.map_err(|e| CatalogError::Parse(format!("reading {}: {e}", path.display())))?;
|
||||||
|
Self::from_json_str(&raw)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The FIFA 17 identity for a definition, or `None` (never a fabricated id).
|
||||||
|
pub fn lookup(&self, card_id: &str) -> Option<Fifa17CardIdentity> {
|
||||||
|
self.by_card.get(card_id).copied()
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Reverse a FIFA wire `resource_id` (full versioned id) to its authoritative
|
||||||
|
/// Core `card_id`, or `None` (never a fabricated/heuristic id). Used by the
|
||||||
|
/// synthetic transfer market so a purchase mints real Core content.
|
||||||
|
pub fn card_id_for_resource(&self, resource_id: u32) -> Option<&str> {
|
||||||
|
self.by_resource.get(&resource_id).map(String::as_str)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Classify a `card_id` as player/consumable/staff. An unknown definition is
|
||||||
|
/// [`ContentKind::Player`] — the neutral, backward-compatible default (an
|
||||||
|
/// un-catalogued id was always treated as a player-shaped card).
|
||||||
|
pub fn kind_of(&self, card_id: &str) -> ContentKind {
|
||||||
|
self.by_card
|
||||||
|
.get(card_id)
|
||||||
|
.map(|c| c.kind)
|
||||||
|
.unwrap_or(ContentKind::Player)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The FIFA `cardsubtypeid` for a definition, or `0` if unknown / a player.
|
||||||
|
pub fn subtype_of(&self, card_id: &str) -> i64 {
|
||||||
|
self.by_card.get(card_id).map(|c| c.subtype).unwrap_or(0)
|
||||||
|
}
|
||||||
|
|
||||||
|
pub fn len(&self) -> usize {
|
||||||
|
self.by_card.len()
|
||||||
|
}
|
||||||
|
pub fn is_empty(&self) -> bool {
|
||||||
|
self.by_card.is_empty()
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn resource_id_composition_base_and_special() {
|
||||||
|
let cat = Fifa17CardCatalog::from_json_str(
|
||||||
|
r#"{"schema_version":1,"game":"fifa17","cards":{
|
||||||
|
"card_base":{"asset_id":20801},
|
||||||
|
"card_totw":{"asset_id":20801,"version":3}
|
||||||
|
}}"#,
|
||||||
|
)
|
||||||
|
.unwrap();
|
||||||
|
// version 0 -> resource_id == asset_id
|
||||||
|
let base = cat.lookup("card_base").unwrap();
|
||||||
|
assert_eq!(base.version, 0);
|
||||||
|
assert_eq!(base.resource_id, 20801);
|
||||||
|
assert_eq!(base.resource_id, base.asset_id);
|
||||||
|
// version 3 -> high byte set; same base player, different FIFA card
|
||||||
|
let totw = cat.lookup("card_totw").unwrap();
|
||||||
|
assert_eq!(totw.asset_id, 20801, "asset_id (base player) unchanged");
|
||||||
|
assert_eq!(totw.resource_id, (3u32 << 24) | 20801);
|
||||||
|
assert_ne!(base.resource_id, totw.resource_id);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn unknown_card_is_none() {
|
||||||
|
let cat = Fifa17CardCatalog::from_json_str(
|
||||||
|
r#"{"schema_version":1,"game":"fifa17","cards":{"card_base":{"asset_id":1}}}"#,
|
||||||
|
)
|
||||||
|
.unwrap();
|
||||||
|
assert_eq!(cat.lookup("card_missing"), None);
|
||||||
|
}
|
||||||
|
|
||||||
|
/// A club item's wire `assetId` is family specific and is NOT the carddbid.
|
||||||
|
///
|
||||||
|
/// Regression: the catalog shipped `asset_id` (the carddbid) as the wire
|
||||||
|
/// `assetId`, so the client held `assetId 6300006` at record `+0x20` where
|
||||||
|
/// its own `fcc_kitcards` says `14`, and both pre-match kit tiles rendered
|
||||||
|
/// identically. `resource_id` is derived from `asset_id`, and every home kit
|
||||||
|
/// shares art class 14, so the two genuinely cannot be one field.
|
||||||
|
#[test]
|
||||||
|
fn club_items_carry_their_own_wire_asset_id_distinct_from_the_carddbid() {
|
||||||
|
let cat = Fifa17CardCatalog::from_json_str(
|
||||||
|
r#"{"schema_version":1,"game":"fifa17","cards":{
|
||||||
|
"fifa17_6300006":{"asset_id":6300006,"kind":"kit","subtype":9,
|
||||||
|
"card_asset_id":35,"club_asset_id":14,"team_id":21,"category":2,"year":0},
|
||||||
|
"fifa17_6400003":{"asset_id":6400003,"kind":"kit","subtype":9,
|
||||||
|
"card_asset_id":35,"club_asset_id":15,"team_id":21,"category":3,"year":0},
|
||||||
|
"fifa17_20801":{"asset_id":20801}
|
||||||
|
}}"#,
|
||||||
|
)
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
let home = cat.lookup("fifa17_6300006").unwrap();
|
||||||
|
let away = cat.lookup("fifa17_6400003").unwrap();
|
||||||
|
|
||||||
|
// resourceId stays the carddbid — it is what the staff/kit merge keys on.
|
||||||
|
assert_eq!(home.resource_id, 6300006);
|
||||||
|
assert_eq!(away.resource_id, 6400003);
|
||||||
|
// The card frame art is shared by the whole kit family.
|
||||||
|
assert_eq!(home.card_asset_id, 35);
|
||||||
|
assert_eq!(away.card_asset_id, 35);
|
||||||
|
// The art class is what distinguishes home from away on the wire.
|
||||||
|
assert_eq!(home.club_asset_id, 14);
|
||||||
|
assert_eq!(away.club_asset_id, 15);
|
||||||
|
assert_ne!(
|
||||||
|
home.club_asset_id, away.club_asset_id,
|
||||||
|
"home and away must not present the same assetId"
|
||||||
|
);
|
||||||
|
|
||||||
|
// Absent: defaults to asset_id, which is correct for every non-club kind
|
||||||
|
// and preserves the behaviour of a catalog that predates the field.
|
||||||
|
let player = cat.lookup("fifa17_20801").unwrap();
|
||||||
|
assert_eq!(player.club_asset_id, 20801);
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The non-player definition fields a consumable needs, and the ABSENCE that
|
||||||
|
/// must stay an absence: a defaulted `amount` would draw "-1" on the card and
|
||||||
|
/// a defaulted `contract` would invent the number of matches a card grants.
|
||||||
|
#[test]
|
||||||
|
fn consumable_definition_fields_are_carried_and_never_defaulted() {
|
||||||
|
let cat = Fifa17CardCatalog::from_json_str(
|
||||||
|
r#"{"schema_version":1,"game":"fifa17","cards":{
|
||||||
|
"fifa17_5003012":{"asset_id":5003012,"kind":"consumable","subtype":54,
|
||||||
|
"card_asset_id":3,"rareflag":0,"rating":85,"amount":15},
|
||||||
|
"fifa17_5001004":{"asset_id":5001004,"kind":"consumable","subtype":201,
|
||||||
|
"card_asset_id":7,"rareflag":0,"rating":60,"contract":7},
|
||||||
|
"fifa17_5003059":{"asset_id":5003059,"kind":"consumable","subtype":91,
|
||||||
|
"card_asset_id":34,"rareflag":0,"rating":95},
|
||||||
|
"fifa17_20801":{"asset_id":20801}
|
||||||
|
}}"#,
|
||||||
|
)
|
||||||
|
.unwrap();
|
||||||
|
// A training card: art id 3 (NOT the carddbid), EA's rating, amount 15.
|
||||||
|
let training = cat.lookup("fifa17_5003012").unwrap();
|
||||||
|
assert_eq!(training.kind, ContentKind::Consumable);
|
||||||
|
assert_eq!(training.subtype, 54);
|
||||||
|
assert_eq!(training.card_asset_id, 3);
|
||||||
|
assert_eq!(training.rating, Some(85));
|
||||||
|
assert_eq!(training.amount, Some(15));
|
||||||
|
assert_eq!(training.contract, None);
|
||||||
|
// A contract card takes its number from `contract`, not `amount`.
|
||||||
|
let contract = cat.lookup("fifa17_5001004").unwrap();
|
||||||
|
assert_eq!(contract.contract, Some(7));
|
||||||
|
assert_eq!(contract.amount, None);
|
||||||
|
// A position modifier needs neither.
|
||||||
|
let position = cat.lookup("fifa17_5003059").unwrap();
|
||||||
|
assert_eq!(position.amount, None);
|
||||||
|
assert_eq!(position.contract, None);
|
||||||
|
assert_eq!(position.card_asset_id, 34);
|
||||||
|
// A player carries none of them and keeps Core's authoritative rating.
|
||||||
|
let player = cat.lookup("fifa17_20801").unwrap();
|
||||||
|
assert_eq!(player.kind, ContentKind::Player);
|
||||||
|
assert_eq!(player.rating, None);
|
||||||
|
assert_eq!(player.amount, None);
|
||||||
|
assert_eq!(player.contract, None);
|
||||||
|
assert_eq!(
|
||||||
|
player.card_asset_id, player.asset_id,
|
||||||
|
"a player's card art IS its asset id"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn two_cards_same_resource_is_a_conflict() {
|
||||||
|
let err = Fifa17CardCatalog::from_json_str(
|
||||||
|
r#"{"schema_version":1,"game":"fifa17","cards":{
|
||||||
|
"card_a":{"asset_id":20801},
|
||||||
|
"card_b":{"asset_id":20801}
|
||||||
|
}}"#,
|
||||||
|
)
|
||||||
|
.unwrap_err();
|
||||||
|
assert!(matches!(
|
||||||
|
err,
|
||||||
|
CatalogError::DuplicateResource {
|
||||||
|
resource_id: 20801,
|
||||||
|
..
|
||||||
|
}
|
||||||
|
));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn schema_and_game_are_validated() {
|
||||||
|
assert_eq!(
|
||||||
|
Fifa17CardCatalog::from_json_str(r#"{"schema_version":2,"game":"fifa17","cards":{}}"#)
|
||||||
|
.unwrap_err(),
|
||||||
|
CatalogError::BadSchemaVersion(2)
|
||||||
|
);
|
||||||
|
assert_eq!(
|
||||||
|
Fifa17CardCatalog::from_json_str(r#"{"schema_version":1,"game":"fifa23","cards":{}}"#)
|
||||||
|
.unwrap_err(),
|
||||||
|
CatalogError::WrongGame("fifa23".into())
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn asset_exceeding_24_bits_is_rejected() {
|
||||||
|
let err = Fifa17CardCatalog::from_json_str(
|
||||||
|
r#"{"schema_version":1,"game":"fifa17","cards":{"c":{"asset_id":16777216}}}"#,
|
||||||
|
)
|
||||||
|
.unwrap_err();
|
||||||
|
assert!(matches!(
|
||||||
|
err,
|
||||||
|
CatalogError::AssetTooLarge {
|
||||||
|
asset_id: 16_777_216,
|
||||||
|
..
|
||||||
|
}
|
||||||
|
));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn malformed_json_is_a_parse_error() {
|
||||||
|
assert!(matches!(
|
||||||
|
Fifa17CardCatalog::from_json_str("{not json").unwrap_err(),
|
||||||
|
CatalogError::Parse(_)
|
||||||
|
));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn deterministic_reload() {
|
||||||
|
let doc = r#"{"schema_version":1,"game":"fifa17","cards":{"a":{"asset_id":10},"b":{"asset_id":20,"version":1}}}"#;
|
||||||
|
let c1 = Fifa17CardCatalog::from_json_str(doc).unwrap();
|
||||||
|
let c2 = Fifa17CardCatalog::from_json_str(doc).unwrap();
|
||||||
|
assert_eq!(c1.lookup("a"), c2.lookup("a"));
|
||||||
|
assert_eq!(c1.lookup("b"), c2.lookup("b"));
|
||||||
|
assert_eq!(c1.len(), 2);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn wire_id_policy_constants() {
|
||||||
|
assert_eq!(Fifa17WireItemIdPolicy::GAME, "fifa17");
|
||||||
|
assert_eq!(Fifa17WireItemIdPolicy::OWNED_ITEM_KIND, "owned-item");
|
||||||
|
assert_eq!(Fifa17WireItemIdPolicy::owned_item_base_floor(), 100_000_001);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn loads_the_committed_generated_catalog() {
|
||||||
|
// The generated base-card catalog (scripts/seed_fifa17_cards.py) must be
|
||||||
|
// loadable by this adapter and carry real asset identities.
|
||||||
|
let path = std::path::Path::new(env!("CARGO_MANIFEST_DIR"))
|
||||||
|
.join("data/fifa17-card-identities.json");
|
||||||
|
if !path.exists() {
|
||||||
|
eprintln!("skip: {} not generated", path.display());
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
let cat = Fifa17CardCatalog::from_file(&path).expect("load committed catalog");
|
||||||
|
assert!(
|
||||||
|
cat.len() > 17_000,
|
||||||
|
"full FIFA17 base pool, got {}",
|
||||||
|
cat.len()
|
||||||
|
);
|
||||||
|
// Ronaldo (asset 20801), version 0 => resource_id == asset_id.
|
||||||
|
let ron = cat
|
||||||
|
.lookup("fifa17_20801")
|
||||||
|
.expect("known base asset present");
|
||||||
|
assert_eq!(ron.asset_id, 20801);
|
||||||
|
assert_eq!(ron.version, 0);
|
||||||
|
assert_eq!(ron.resource_id, 20801);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn legacy_catalog_without_kind_loads_as_player() {
|
||||||
|
// A pre-taxonomy catalog (no `kind`/`subtype`) must load unchanged and
|
||||||
|
// classify every entry as a player, with subtype 0.
|
||||||
|
let cat = Fifa17CardCatalog::from_json_str(
|
||||||
|
r#"{"schema_version":1,"game":"fifa17","cards":{
|
||||||
|
"fifa17_20801":{"asset_id":20801},
|
||||||
|
"fifa17_176580":{"asset_id":176580,"version":5,"rareflag":3}
|
||||||
|
}}"#,
|
||||||
|
)
|
||||||
|
.unwrap();
|
||||||
|
let base = cat.lookup("fifa17_20801").unwrap();
|
||||||
|
assert_eq!(base.kind, ContentKind::Player);
|
||||||
|
assert_eq!(base.subtype, 0);
|
||||||
|
assert_eq!(base.rareflag, 1, "absent rareflag still defaults to 1");
|
||||||
|
assert_eq!(cat.kind_of("fifa17_20801"), ContentKind::Player);
|
||||||
|
assert_eq!(cat.kind_of("fifa17_176580"), ContentKind::Player);
|
||||||
|
// Unknown id -> neutral Player default.
|
||||||
|
assert_eq!(cat.kind_of("fifa17_missing"), ContentKind::Player);
|
||||||
|
assert_eq!(cat.subtype_of("fifa17_missing"), 0);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn kind_and_subtype_are_parsed_for_non_player_entries() {
|
||||||
|
let cat = Fifa17CardCatalog::from_json_str(
|
||||||
|
r#"{"schema_version":1,"game":"fifa17","cards":{
|
||||||
|
"fifa17_20801":{"asset_id":20801,"kind":"player","subtype":0},
|
||||||
|
"fifa17_5003012":{"asset_id":5003012,"kind":"consumable","subtype":54,"rareflag":0},
|
||||||
|
"fifa17_3000083":{"asset_id":3000083,"kind":"staff","subtype":8,"rareflag":0},
|
||||||
|
"fifa17_6300006":{"asset_id":6300006,"kind":"kit","subtype":9,
|
||||||
|
"card_asset_id":35,"team_id":21,"rareflag":0}
|
||||||
|
}}"#,
|
||||||
|
)
|
||||||
|
.unwrap();
|
||||||
|
assert_eq!(cat.kind_of("fifa17_20801"), ContentKind::Player);
|
||||||
|
assert_eq!(cat.kind_of("fifa17_5003012"), ContentKind::Consumable);
|
||||||
|
assert_eq!(cat.subtype_of("fifa17_5003012"), 54);
|
||||||
|
assert_eq!(cat.kind_of("fifa17_3000083"), ContentKind::Staff);
|
||||||
|
assert_eq!(cat.subtype_of("fifa17_3000083"), 8);
|
||||||
|
assert_eq!(cat.lookup("fifa17_5003012").unwrap().rareflag, 0);
|
||||||
|
let kit = cat.lookup("fifa17_6300006").unwrap();
|
||||||
|
assert_eq!(kit.kind, ContentKind::Kit);
|
||||||
|
assert_eq!(kit.subtype, 9);
|
||||||
|
assert_eq!(kit.card_asset_id, 35);
|
||||||
|
assert_eq!(kit.team_id, 21);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,645 @@
|
|||||||
|
//! Shape OpenFUT Core's semantic owned inventory into the FIFA 17 `/club`
|
||||||
|
//! response envelope `{"itemData":[ <player item>, … ]}`.
|
||||||
|
//!
|
||||||
|
//! This module owns only the **`/club` envelope**; the per-item shape lives in
|
||||||
|
//! the shared [`crate::fut::item`] primitive so `/club` and squad projection
|
||||||
|
//! emit byte-identical items. Items whose real FIFA asset id is unknown are
|
||||||
|
//! **dropped and counted** here (a collection may omit an unrenderable card);
|
||||||
|
//! squad projection, which cannot omit a starter, refuses instead.
|
||||||
|
|
||||||
|
use serde_json::{json, Value};
|
||||||
|
|
||||||
|
use crate::fut::content_taxonomy::ContentKind;
|
||||||
|
use crate::fut::contract_cards::PACK_FRESH_CONTRACT_MATCHES;
|
||||||
|
use crate::fut::entities::ReverseEntityResolver;
|
||||||
|
use crate::fut::item::{shape_club_item, shape_item, shape_staff_item, STAFF_CONTRACT};
|
||||||
|
use crate::fut::item_state;
|
||||||
|
// Re-exported so existing `club_response::{…}` callers keep working; the types
|
||||||
|
// are now defined once in `fut::item`.
|
||||||
|
pub use crate::fut::item::{
|
||||||
|
CoreOwnedItem, Fifa17ConsumableIdentity, Fifa17Identity, Fifa17KitIdentity,
|
||||||
|
Fifa17StaffIdentity, ItemIdentityResolver, ShapeStats,
|
||||||
|
};
|
||||||
|
|
||||||
|
/// Active club-level kit roles, keyed by Core owned-instance id.
|
||||||
|
#[derive(Debug, Clone, Copy, Default)]
|
||||||
|
pub struct ActiveKitAssignments<'a> {
|
||||||
|
pub home: Option<&'a str>,
|
||||||
|
pub away: Option<&'a str>,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Shape the player portion of `/club` (the historical/default query).
|
||||||
|
pub fn shape_club_response<I: ItemIdentityResolver + ?Sized>(
|
||||||
|
items: &[CoreOwnedItem],
|
||||||
|
ent: &impl ReverseEntityResolver,
|
||||||
|
ident: &I,
|
||||||
|
) -> (Value, ShapeStats) {
|
||||||
|
shape_club_response_with_kits(items, ent, ident, ActiveKitAssignments::default())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Shape `/club` items, including ownership-backed active kit designations.
|
||||||
|
///
|
||||||
|
/// This envelope carries the two families whose record shape it can carry:
|
||||||
|
/// players and kits, plus the staff family (manager + the four coach families).
|
||||||
|
/// Consumables have their own route and their own STACK envelope, and the
|
||||||
|
/// club-customisation families are counted and withheld — see each arm.
|
||||||
|
pub fn shape_club_response_with_kits<I: ItemIdentityResolver + ?Sized>(
|
||||||
|
items: &[CoreOwnedItem],
|
||||||
|
ent: &impl ReverseEntityResolver,
|
||||||
|
ident: &I,
|
||||||
|
active_kits: ActiveKitAssignments<'_>,
|
||||||
|
) -> (Value, ShapeStats) {
|
||||||
|
let mut out = Vec::with_capacity(items.len());
|
||||||
|
let mut stats = ShapeStats::default();
|
||||||
|
for item in items {
|
||||||
|
match ident.kind_of(item) {
|
||||||
|
ContentKind::Player => match ident.resolve(item) {
|
||||||
|
Some(id) => {
|
||||||
|
out.push(shape_item(
|
||||||
|
item,
|
||||||
|
id,
|
||||||
|
ent,
|
||||||
|
ident.discard_value(item),
|
||||||
|
item.contract_matches.unwrap_or(PACK_FRESH_CONTRACT_MATCHES),
|
||||||
|
));
|
||||||
|
stats.emitted += 1;
|
||||||
|
}
|
||||||
|
None => stats.dropped_no_asset += 1,
|
||||||
|
},
|
||||||
|
// Kit, badge and stadium are ONE cardtype-7 record with one
|
||||||
|
// client-side resolver; only the equipped designation differs.
|
||||||
|
ContentKind::Kit | ContentKind::Badge | ContentKind::Stadium => {
|
||||||
|
match ident.resolve_kit(item) {
|
||||||
|
Some(id) => {
|
||||||
|
let state = if active_kits.home == Some(item.owned_card_id.as_str()) {
|
||||||
|
item_state::ACTIVE_HOME_KIT
|
||||||
|
} else if active_kits.away == Some(item.owned_card_id.as_str()) {
|
||||||
|
item_state::ACTIVE_AWAY_KIT
|
||||||
|
} else {
|
||||||
|
item_state::FREE
|
||||||
|
};
|
||||||
|
out.push(shape_club_item(id, state));
|
||||||
|
stats.emitted += 1;
|
||||||
|
}
|
||||||
|
None => stats.dropped_no_asset += 1,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
// A manager is a staff card: both Core kinds resolve through the one
|
||||||
|
// staff record shape, discriminated on the wire by `cardsubtypeid`
|
||||||
|
// (the same set as `ContentKind::is_staff_family`, spelled out here
|
||||||
|
// because a guard arm would not prove exhaustiveness).
|
||||||
|
ContentKind::Manager | ContentKind::Staff => match ident.resolve_staff(item) {
|
||||||
|
Some(id) => {
|
||||||
|
out.push(shape_staff_item(
|
||||||
|
id,
|
||||||
|
item.contract_matches.unwrap_or(STAFF_CONTRACT),
|
||||||
|
));
|
||||||
|
stats.emitted += 1;
|
||||||
|
}
|
||||||
|
None => stats.dropped_no_asset += 1,
|
||||||
|
},
|
||||||
|
// Consumables have their OWN route and their own envelope:
|
||||||
|
// `GET club/consumables/<category>`, whose element is a stack
|
||||||
|
// wrapper, not an item (see [`crate::fut::consumables`]). A bare
|
||||||
|
// consumable item in THIS envelope is accepted by the client and
|
||||||
|
// silently discarded, so emitting one here would be a 200 that does
|
||||||
|
// nothing — the worst failure shape in this project. Counted.
|
||||||
|
ContentKind::Consumable => {
|
||||||
|
stats.excluded_non_player += 1;
|
||||||
|
}
|
||||||
|
// The cardtype-9 families. Unlike kits/badges/stadia these have NO
|
||||||
|
// database name resolver at all, so the displayed name can only come
|
||||||
|
// from `localizedName` on the wire. That offset is confirmed
|
||||||
|
// (`+0xd9`), but "the parser reads it" is NOT "sending it is safe",
|
||||||
|
// and this project pays for that distinction with a client freeze.
|
||||||
|
// Counted and withheld rather than guessed: ownership stays
|
||||||
|
// authoritative in Core either way, and club/stats still counts the
|
||||||
|
// families so the screen's own numbers are right.
|
||||||
|
ContentKind::Ball | ContentKind::Misc => {
|
||||||
|
stats.excluded_non_player += 1;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
(json!({ "itemData": out }), stats)
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
use crate::fut::contract_cards::CONTRACT_MATCH_CAP;
|
||||||
|
use crate::fut::entities::Fifa17Entities;
|
||||||
|
use std::collections::HashMap;
|
||||||
|
|
||||||
|
fn entities() -> Fifa17Entities {
|
||||||
|
Fifa17Entities::from_maps(
|
||||||
|
HashMap::from([(13, "Premier League".to_string())]),
|
||||||
|
HashMap::from([(52, "Argentina".to_string())]),
|
||||||
|
HashMap::from([(5, "Chelsea".to_string())]),
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
fn item(
|
||||||
|
owned: &str,
|
||||||
|
card: &str,
|
||||||
|
rating: u8,
|
||||||
|
pos: &str,
|
||||||
|
nation: &str,
|
||||||
|
league: &str,
|
||||||
|
club: &str,
|
||||||
|
) -> CoreOwnedItem {
|
||||||
|
CoreOwnedItem {
|
||||||
|
owned_card_id: owned.into(),
|
||||||
|
card_id: card.into(),
|
||||||
|
rating,
|
||||||
|
position: pos.into(),
|
||||||
|
nation: nation.into(),
|
||||||
|
league: league.into(),
|
||||||
|
club: club.into(),
|
||||||
|
attributes: [90, 88, 70, 85, 40, 78],
|
||||||
|
// Untracked by default, so these fixtures exercise the pack-fresh
|
||||||
|
// fallback; a test that cares sets it explicitly.
|
||||||
|
contract_matches: None,
|
||||||
|
source_rating: None,
|
||||||
|
core_content_kind: None,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Test resolver: card_id -> real asset id, item_id from a table. Stands in
|
||||||
|
/// for the (unresolved-in-production) Core-card→asset mapping.
|
||||||
|
struct MapIdentity(HashMap<String, Fifa17Identity>);
|
||||||
|
impl ItemIdentityResolver for MapIdentity {
|
||||||
|
fn resolve(&self, it: &CoreOwnedItem) -> Option<Fifa17Identity> {
|
||||||
|
self.0.get(&it.card_id).copied()
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn shapes_item_with_full_field_set_and_reverse_ids() {
|
||||||
|
let ent = entities();
|
||||||
|
let ident = MapIdentity(HashMap::from([(
|
||||||
|
"card_ch_1".to_string(),
|
||||||
|
Fifa17Identity {
|
||||||
|
item_id: 100000001,
|
||||||
|
asset_id: 20801,
|
||||||
|
resource_id: 20801,
|
||||||
|
rareflag: 1,
|
||||||
|
},
|
||||||
|
)]));
|
||||||
|
let items = vec![item(
|
||||||
|
"oc1",
|
||||||
|
"card_ch_1",
|
||||||
|
86,
|
||||||
|
"CDM",
|
||||||
|
"Argentina",
|
||||||
|
"Premier League",
|
||||||
|
"Chelsea",
|
||||||
|
)];
|
||||||
|
let (body, stats) = shape_club_response(&items, &ent, &ident);
|
||||||
|
assert_eq!(stats.emitted, 1);
|
||||||
|
assert_eq!(stats.dropped_no_asset, 0);
|
||||||
|
let it = &body["itemData"][0];
|
||||||
|
assert_eq!(it["id"], 100000001);
|
||||||
|
assert_eq!(it["resourceId"], 20801);
|
||||||
|
assert_eq!(it["assetId"], 20801);
|
||||||
|
assert_eq!(
|
||||||
|
it["definitionId"], 20801,
|
||||||
|
"version byte 0 => resourceId==assetId==definitionId"
|
||||||
|
);
|
||||||
|
assert_eq!(it["rating"], 86);
|
||||||
|
assert_eq!(it["preferredPosition"], "CDM");
|
||||||
|
assert_eq!(it["leagueId"], 13);
|
||||||
|
assert_eq!(it["teamid"], 5);
|
||||||
|
assert_eq!(it["nation"], 52);
|
||||||
|
assert_eq!(it["itemType"], "player");
|
||||||
|
assert_eq!(it["rareflag"], 1);
|
||||||
|
assert_eq!(it["contract"], 7);
|
||||||
|
assert_eq!(it["fitness"], 99);
|
||||||
|
assert_eq!(it["attributeList"].as_array().unwrap().len(), 6);
|
||||||
|
assert_eq!(it["attributeList"][0], json!({"index":0,"value":90}));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn drops_items_without_a_real_asset_id_never_faking() {
|
||||||
|
let ent = entities();
|
||||||
|
// Empty identity map == the current synthetic-catalogue reality.
|
||||||
|
let ident = MapIdentity(HashMap::new());
|
||||||
|
let items = vec![item(
|
||||||
|
"oc1",
|
||||||
|
"card_pl_001",
|
||||||
|
84,
|
||||||
|
"ST",
|
||||||
|
"England",
|
||||||
|
"Premier League",
|
||||||
|
"Northgate United",
|
||||||
|
)];
|
||||||
|
let (body, stats) = shape_club_response(&items, &ent, &ident);
|
||||||
|
assert_eq!(stats.emitted, 0);
|
||||||
|
assert_eq!(stats.dropped_no_asset, 1);
|
||||||
|
assert_eq!(
|
||||||
|
body["itemData"].as_array().unwrap().len(),
|
||||||
|
0,
|
||||||
|
"no fabricated ids emitted"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn unresolved_entity_names_become_neutral_zero_not_dropped() {
|
||||||
|
let ent = entities();
|
||||||
|
let ident = MapIdentity(HashMap::from([(
|
||||||
|
"card_x".to_string(),
|
||||||
|
Fifa17Identity {
|
||||||
|
item_id: 100000002,
|
||||||
|
asset_id: 158023,
|
||||||
|
resource_id: 158023,
|
||||||
|
rareflag: 1,
|
||||||
|
},
|
||||||
|
)]));
|
||||||
|
// Synthetic club "Northgate United" has no FIFA team id.
|
||||||
|
let items = vec![item(
|
||||||
|
"oc2",
|
||||||
|
"card_x",
|
||||||
|
84,
|
||||||
|
"ST",
|
||||||
|
"England",
|
||||||
|
"Premier League",
|
||||||
|
"Northgate United",
|
||||||
|
)];
|
||||||
|
let (body, _) = shape_club_response(&items, &ent, &ident);
|
||||||
|
let it = &body["itemData"][0];
|
||||||
|
assert_eq!(
|
||||||
|
it["teamid"], 0,
|
||||||
|
"unknown club -> neutral 0, item still emitted"
|
||||||
|
);
|
||||||
|
assert_eq!(it["leagueId"], 13);
|
||||||
|
assert_eq!(it["nation"], 0, "England not in the test nation map -> 0");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn envelope_is_itemdata_object() {
|
||||||
|
let ent = entities();
|
||||||
|
let ident = MapIdentity(HashMap::new());
|
||||||
|
let (body, _) = shape_club_response(&[], &ent, &ident);
|
||||||
|
assert!(body.get("itemData").unwrap().is_array());
|
||||||
|
assert_eq!(
|
||||||
|
body.as_object().unwrap().len(),
|
||||||
|
1,
|
||||||
|
"only itemData at top level"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/// A resolver that resolves an asset id for EVERY item (so exclusion is not
|
||||||
|
/// an artifact of a missing asset) but classifies some card_ids as non-player
|
||||||
|
/// via an explicit kind table.
|
||||||
|
struct KindMapIdentity {
|
||||||
|
ids: HashMap<String, Fifa17Identity>,
|
||||||
|
kinds: HashMap<String, ContentKind>,
|
||||||
|
kits: HashMap<String, Fifa17KitIdentity>,
|
||||||
|
staff: HashMap<String, Fifa17StaffIdentity>,
|
||||||
|
}
|
||||||
|
impl ItemIdentityResolver for KindMapIdentity {
|
||||||
|
fn resolve(&self, it: &CoreOwnedItem) -> Option<Fifa17Identity> {
|
||||||
|
self.ids.get(&it.card_id).copied()
|
||||||
|
}
|
||||||
|
fn resolve_kit(&self, it: &CoreOwnedItem) -> Option<Fifa17KitIdentity> {
|
||||||
|
self.kits.get(&it.card_id).copied()
|
||||||
|
}
|
||||||
|
fn resolve_staff(&self, it: &CoreOwnedItem) -> Option<Fifa17StaffIdentity> {
|
||||||
|
self.staff.get(&it.card_id).copied()
|
||||||
|
}
|
||||||
|
fn kind_of(&self, it: &CoreOwnedItem) -> ContentKind {
|
||||||
|
self.kinds
|
||||||
|
.get(&it.card_id)
|
||||||
|
.copied()
|
||||||
|
.unwrap_or(ContentKind::Player)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn consumables_are_excluded_but_staff_is_shaped() {
|
||||||
|
let ent = entities();
|
||||||
|
let id = |item_id: u32, asset: u32| Fifa17Identity {
|
||||||
|
item_id,
|
||||||
|
asset_id: asset,
|
||||||
|
resource_id: asset,
|
||||||
|
rareflag: 1,
|
||||||
|
};
|
||||||
|
let ident = KindMapIdentity {
|
||||||
|
ids: HashMap::from([
|
||||||
|
("card_player".to_string(), id(100000001, 20801)),
|
||||||
|
("card_consumable".to_string(), id(100000002, 5003012)),
|
||||||
|
]),
|
||||||
|
kits: HashMap::new(),
|
||||||
|
staff: HashMap::from([(
|
||||||
|
"card_staff".to_string(),
|
||||||
|
Fifa17StaffIdentity {
|
||||||
|
item_id: 100000003,
|
||||||
|
resource_id: 3000083,
|
||||||
|
subtype: 8,
|
||||||
|
nation: 0,
|
||||||
|
league_id: 0,
|
||||||
|
team_id: 0,
|
||||||
|
},
|
||||||
|
)]),
|
||||||
|
kinds: HashMap::from([
|
||||||
|
("card_consumable".to_string(), ContentKind::Consumable),
|
||||||
|
("card_staff".to_string(), ContentKind::Staff),
|
||||||
|
]),
|
||||||
|
};
|
||||||
|
let items = vec![
|
||||||
|
item(
|
||||||
|
"oc1",
|
||||||
|
"card_player",
|
||||||
|
86,
|
||||||
|
"ST",
|
||||||
|
"Argentina",
|
||||||
|
"Premier League",
|
||||||
|
"Chelsea",
|
||||||
|
),
|
||||||
|
item("oc2", "card_consumable", 0, "", "", "", ""),
|
||||||
|
item("oc3", "card_staff", 0, "", "", "", ""),
|
||||||
|
];
|
||||||
|
let (body, stats) = shape_club_response(&items, &ent, &ident);
|
||||||
|
assert_eq!(
|
||||||
|
stats.emitted, 2,
|
||||||
|
"the player and the staff card are emitted"
|
||||||
|
);
|
||||||
|
assert_eq!(
|
||||||
|
stats.excluded_non_player, 1,
|
||||||
|
"only the consumable is excluded; staff has a wire envelope of its own"
|
||||||
|
);
|
||||||
|
assert_eq!(stats.dropped_no_asset, 0);
|
||||||
|
let arr = body["itemData"].as_array().unwrap();
|
||||||
|
assert_eq!(arr.len(), 2);
|
||||||
|
assert_eq!(arr[0]["id"], 100000001, "the player survives");
|
||||||
|
assert_eq!(arr[0]["itemType"], "player");
|
||||||
|
let coach = &arr[1];
|
||||||
|
assert_eq!(coach["id"], 100000003);
|
||||||
|
assert_eq!(coach["resourceId"], 3000083);
|
||||||
|
assert_eq!(coach["cardsubtypeid"], 8);
|
||||||
|
assert_eq!(coach["itemType"], "staff");
|
||||||
|
assert_eq!(
|
||||||
|
coach["contract"], STAFF_CONTRACT,
|
||||||
|
"this fixture is UNTRACKED (contract_matches None), so the wire shows \
|
||||||
|
the pack-fresh fallback — not because the shaper hardcodes it"
|
||||||
|
);
|
||||||
|
assert!(
|
||||||
|
coach.get("nation").is_none()
|
||||||
|
&& coach.get("leagueId").is_none()
|
||||||
|
&& coach.get("teamid").is_none(),
|
||||||
|
"a COACH has no nation/league/team column in the client's tables, so \
|
||||||
|
those keys must be absent rather than invented as zeroes"
|
||||||
|
);
|
||||||
|
assert!(
|
||||||
|
coach.get("attributeList").is_none() && coach.get("preferredPosition").is_none(),
|
||||||
|
"both survive the client's merge and are read by the card view-model"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn manager_carries_the_chemistry_fields_only_the_server_can_supply() {
|
||||||
|
let ent = entities();
|
||||||
|
let ident = KindMapIdentity {
|
||||||
|
ids: HashMap::new(),
|
||||||
|
kits: HashMap::new(),
|
||||||
|
staff: HashMap::from([(
|
||||||
|
"card_manager".to_string(),
|
||||||
|
Fifa17StaffIdentity {
|
||||||
|
item_id: 100004871,
|
||||||
|
resource_id: 1000509,
|
||||||
|
subtype: 4,
|
||||||
|
nation: 45,
|
||||||
|
league_id: 53,
|
||||||
|
team_id: 241,
|
||||||
|
},
|
||||||
|
)]),
|
||||||
|
kinds: HashMap::from([("card_manager".to_string(), ContentKind::Staff)]),
|
||||||
|
};
|
||||||
|
let items = vec![item("oc-mgr", "card_manager", 0, "", "", "", "")];
|
||||||
|
let (body, stats) = shape_club_response(&items, &ent, &ident);
|
||||||
|
assert_eq!(stats.emitted, 1);
|
||||||
|
let mgr = &body["itemData"][0];
|
||||||
|
assert_eq!(
|
||||||
|
mgr["cardsubtypeid"], 4,
|
||||||
|
"subtype alone selects managercards"
|
||||||
|
);
|
||||||
|
assert_eq!(
|
||||||
|
mgr["resourceId"], 1000509,
|
||||||
|
"the merge key is read RAW: it must equal the carddbid with no version byte"
|
||||||
|
);
|
||||||
|
// rec+0xde / rec+0xe0 / rec+0x94 — the merge never writes these, so an
|
||||||
|
// omission here is an unrecoverable blank flag and zero chemistry.
|
||||||
|
assert_eq!(mgr["nation"], 45);
|
||||||
|
assert_eq!(mgr["leagueId"], 53);
|
||||||
|
assert_eq!(mgr["teamid"], 241);
|
||||||
|
assert_eq!(
|
||||||
|
mgr["contract"], STAFF_CONTRACT,
|
||||||
|
"untracked fixture => pack-fresh fallback"
|
||||||
|
);
|
||||||
|
assert_eq!(mgr["itemState"], "free");
|
||||||
|
assert_eq!(mgr["owners"], 1);
|
||||||
|
let keys: Vec<&String> = mgr.as_object().unwrap().keys().collect();
|
||||||
|
assert_eq!(
|
||||||
|
keys.len(),
|
||||||
|
11,
|
||||||
|
"exactly the 11 justified keys, no more: {keys:?}"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/// `/club` is the screen a contract apply is judged on: if the envelope keeps
|
||||||
|
/// reporting the pack-fresh count, a committed apply is invisible and the
|
||||||
|
/// operator sees a 200 that did nothing. Both families must carry the number
|
||||||
|
/// Core persisted.
|
||||||
|
#[test]
|
||||||
|
fn club_reports_the_contract_core_persisted_for_players_and_staff() {
|
||||||
|
let ent = entities();
|
||||||
|
let ident = KindMapIdentity {
|
||||||
|
ids: HashMap::from([(
|
||||||
|
"card_player".to_string(),
|
||||||
|
Fifa17Identity {
|
||||||
|
item_id: 100000001,
|
||||||
|
asset_id: 20801,
|
||||||
|
resource_id: 20801,
|
||||||
|
rareflag: 1,
|
||||||
|
},
|
||||||
|
)]),
|
||||||
|
kits: HashMap::new(),
|
||||||
|
staff: HashMap::from([(
|
||||||
|
"card_manager".to_string(),
|
||||||
|
Fifa17StaffIdentity {
|
||||||
|
item_id: 100004871,
|
||||||
|
resource_id: 1000509,
|
||||||
|
subtype: 4,
|
||||||
|
nation: 45,
|
||||||
|
league_id: 53,
|
||||||
|
team_id: 241,
|
||||||
|
},
|
||||||
|
)]),
|
||||||
|
kinds: HashMap::from([
|
||||||
|
("card_player".to_string(), ContentKind::Player),
|
||||||
|
("card_manager".to_string(), ContentKind::Staff),
|
||||||
|
]),
|
||||||
|
};
|
||||||
|
// A player mid-way through its contracts, a fully topped-up manager, and
|
||||||
|
// one untracked player that must fall back.
|
||||||
|
let mut played = item(
|
||||||
|
"oc-played",
|
||||||
|
"card_player",
|
||||||
|
86,
|
||||||
|
"ST",
|
||||||
|
"Argentina",
|
||||||
|
"Premier League",
|
||||||
|
"Chelsea",
|
||||||
|
);
|
||||||
|
played.contract_matches = Some(3);
|
||||||
|
let mut manager = item("oc-mgr", "card_manager", 0, "", "", "", "");
|
||||||
|
manager.contract_matches = Some(CONTRACT_MATCH_CAP);
|
||||||
|
let untracked = item(
|
||||||
|
"oc-fresh",
|
||||||
|
"card_player",
|
||||||
|
86,
|
||||||
|
"ST",
|
||||||
|
"Argentina",
|
||||||
|
"Premier League",
|
||||||
|
"Chelsea",
|
||||||
|
);
|
||||||
|
|
||||||
|
let (body, stats) = shape_club_response(&[played, manager, untracked], &ent, &ident);
|
||||||
|
assert_eq!(stats.emitted, 3);
|
||||||
|
let arr = body["itemData"].as_array().unwrap();
|
||||||
|
assert_eq!(arr[0]["contract"], 3, "the player's persisted count");
|
||||||
|
assert_eq!(
|
||||||
|
arr[1]["contract"], CONTRACT_MATCH_CAP,
|
||||||
|
"staff read the same persisted field, not STAFF_CONTRACT"
|
||||||
|
);
|
||||||
|
assert_eq!(
|
||||||
|
arr[2]["contract"], PACK_FRESH_CONTRACT_MATCHES,
|
||||||
|
"only an untracked instance falls back"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn kits_project_with_owned_active_home_and_away_states() {
|
||||||
|
let ent = entities();
|
||||||
|
let kit = |item_id, resource_id, team_id| Fifa17KitIdentity {
|
||||||
|
item_id,
|
||||||
|
asset_id: resource_id,
|
||||||
|
resource_id,
|
||||||
|
card_asset_id: 35,
|
||||||
|
subtype: 9,
|
||||||
|
team_id,
|
||||||
|
category: 2,
|
||||||
|
year: 0,
|
||||||
|
};
|
||||||
|
let ident = KindMapIdentity {
|
||||||
|
ids: HashMap::new(),
|
||||||
|
staff: HashMap::new(),
|
||||||
|
kits: HashMap::from([
|
||||||
|
("kit-home".into(), kit(100000010, 6300006, 21)),
|
||||||
|
("kit-away".into(), kit(100000011, 6400003, 21)),
|
||||||
|
]),
|
||||||
|
kinds: HashMap::from([
|
||||||
|
("kit-home".into(), ContentKind::Kit),
|
||||||
|
("kit-away".into(), ContentKind::Kit),
|
||||||
|
]),
|
||||||
|
};
|
||||||
|
let items = vec![
|
||||||
|
item("owned-home", "kit-home", 0, "", "", "", ""),
|
||||||
|
item("owned-away", "kit-away", 0, "", "", "", ""),
|
||||||
|
];
|
||||||
|
let (body, stats) = shape_club_response_with_kits(
|
||||||
|
&items,
|
||||||
|
&ent,
|
||||||
|
&ident,
|
||||||
|
ActiveKitAssignments {
|
||||||
|
home: Some("owned-home"),
|
||||||
|
away: Some("owned-away"),
|
||||||
|
},
|
||||||
|
);
|
||||||
|
assert_eq!(stats.emitted, 2);
|
||||||
|
assert_eq!(body["itemData"][0]["resourceId"], 6300006);
|
||||||
|
assert_eq!(body["itemData"][0]["cardassetid"], 35);
|
||||||
|
assert_eq!(body["itemData"][0]["cardsubtypeid"], 9);
|
||||||
|
assert_eq!(body["itemData"][0]["teamid"], 21);
|
||||||
|
assert_eq!(body["itemData"][0]["itemState"], "activeHomeKit");
|
||||||
|
assert_eq!(body["itemData"][1]["itemState"], "activeAwayKit");
|
||||||
|
assert!(body["itemData"][0].get("attributeList").is_none());
|
||||||
|
assert_eq!(body["itemData"][0]["itemType"], "kit");
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Kit, badge and stadium are one cardtype-7 record and MUST all project.
|
||||||
|
/// Ball and league logo are cardtype 9, have no database name resolver, and
|
||||||
|
/// stay withheld until `localizedName` is established as safe to send.
|
||||||
|
/// Counting a family in club/stats while never shaping it is the divergence
|
||||||
|
/// this test pins: the wire set and the withheld set are both asserted.
|
||||||
|
#[test]
|
||||||
|
fn cardtype7_club_items_project_and_cardtype9_stay_withheld() {
|
||||||
|
let ent = entities();
|
||||||
|
let kit_id = |item_id, resource, subtype, art| Fifa17KitIdentity {
|
||||||
|
item_id,
|
||||||
|
asset_id: resource,
|
||||||
|
resource_id: resource,
|
||||||
|
card_asset_id: art,
|
||||||
|
subtype,
|
||||||
|
team_id: 21,
|
||||||
|
category: 2,
|
||||||
|
year: 0,
|
||||||
|
};
|
||||||
|
let ident = KindMapIdentity {
|
||||||
|
ids: HashMap::new(),
|
||||||
|
kinds: HashMap::from([
|
||||||
|
("c_kit".to_string(), ContentKind::Kit),
|
||||||
|
("c_badge".to_string(), ContentKind::Badge),
|
||||||
|
("c_stadium".to_string(), ContentKind::Stadium),
|
||||||
|
("c_ball".to_string(), ContentKind::Ball),
|
||||||
|
("c_logo".to_string(), ContentKind::Misc),
|
||||||
|
]),
|
||||||
|
kits: HashMap::from([
|
||||||
|
("c_kit".to_string(), kit_id(1, 6_300_006, 9, 35)),
|
||||||
|
("c_badge".to_string(), kit_id(2, 6_000_005, 11, 39)),
|
||||||
|
("c_stadium".to_string(), kit_id(3, 6_200_000, 10, 36)),
|
||||||
|
// Resolvable on purpose: withholding must be a decision about the
|
||||||
|
// FAMILY, not an accident of a missing identity.
|
||||||
|
("c_ball".to_string(), kit_id(4, 8_120_194, 30, 37)),
|
||||||
|
("c_logo".to_string(), kit_id(5, 8_010_015, 31, 40)),
|
||||||
|
]),
|
||||||
|
staff: HashMap::new(),
|
||||||
|
};
|
||||||
|
let items: Vec<CoreOwnedItem> = ["c_kit", "c_badge", "c_stadium", "c_ball", "c_logo"]
|
||||||
|
.iter()
|
||||||
|
.map(|c| item(&format!("oc_{c}"), c, 0, "", "", "", ""))
|
||||||
|
.collect();
|
||||||
|
|
||||||
|
let (body, stats) = shape_club_response_with_kits(
|
||||||
|
&items,
|
||||||
|
&ent,
|
||||||
|
&ident,
|
||||||
|
ActiveKitAssignments {
|
||||||
|
home: None,
|
||||||
|
away: None,
|
||||||
|
},
|
||||||
|
);
|
||||||
|
let arr = body["itemData"].as_array().unwrap();
|
||||||
|
assert_eq!(stats.emitted, 3, "kit + badge + stadium");
|
||||||
|
assert_eq!(stats.excluded_non_player, 2, "ball + league logo withheld");
|
||||||
|
assert_eq!(stats.dropped_no_asset, 0, "withholding is not a drop");
|
||||||
|
|
||||||
|
let subtypes: Vec<i64> = arr
|
||||||
|
.iter()
|
||||||
|
.map(|i| i["cardsubtypeid"].as_i64().unwrap())
|
||||||
|
.collect();
|
||||||
|
assert_eq!(subtypes, vec![9, 11, 10]);
|
||||||
|
// teamid only where the caption resolves TeamName_Abbr15_<teamid>.
|
||||||
|
assert_eq!(arr[0]["teamid"], 21, "kit");
|
||||||
|
assert_eq!(arr[1]["teamid"], 21, "badge");
|
||||||
|
assert!(
|
||||||
|
arr[2].get("teamid").is_none(),
|
||||||
|
"stadium caption reads assetId"
|
||||||
|
);
|
||||||
|
for it in arr {
|
||||||
|
assert!(
|
||||||
|
item_state::is_recovered(it["itemState"].as_str().unwrap()),
|
||||||
|
"every emitted state must be a recovered token"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user