Compare commits
381 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| e14d3cd063 | |||
| f4fc832ace | |||
| 6aab279244 | |||
| d3451be17b | |||
| 0300af3333 | |||
| 2c572e918f | |||
| f608dbc438 | |||
| 43c460741b | |||
| 5eed124b85 | |||
| e3ed8c298e | |||
| 5181e103dc | |||
| 433a9b22dd | |||
| 0701ac94e1 | |||
| 025122ec9a | |||
| b91e707a7e | |||
| c3d0e56f69 | |||
| e7893a0162 | |||
| a2b0c32a70 | |||
| e49c1f211c | |||
| 96f24e799a | |||
| f315f16e8e | |||
| ead0426ea0 | |||
| 74768693ec | |||
| 6bbc0eaf4f | |||
| 09bb2dc306 | |||
| 42229e5782 | |||
| d929efdffe | |||
| 98f30931a0 | |||
| a5e5628039 | |||
| 0e200758f0 | |||
| 2fc335c37d | |||
| 25b7089c54 | |||
| 8983998707 | |||
| 96610ccb16 | |||
| 704482be84 | |||
| 0997dd3b60 | |||
| 743b20b00b | |||
| e48d659bce | |||
| a86d21ec79 | |||
| f40e8587ac | |||
| 5bf2c7ddc1 | |||
| d146f9c3fc | |||
| d4a39ba75d | |||
| 9cc5188e5c | |||
| 6baa673252 | |||
| eefa98c961 | |||
| 88ae754b0f | |||
| e0f1e379b7 | |||
| 6d89d62e41 | |||
| 40e53ed02c | |||
| b55dd16a46 | |||
| 11b7991d81 | |||
| e18304d365 | |||
| 8614acff57 | |||
| 3ff09ae62c | |||
| 34be38260d | |||
| 1e0124c197 | |||
| 286a44461d | |||
| 8c353c6c66 | |||
| 3a038fe406 | |||
| 3bb6b4fc9d | |||
| a9bac8be8e | |||
| 3c28b0d1af | |||
| 4936654f84 | |||
| 4156dc5810 | |||
| fc1fdcc5ab | |||
| 1e8d46b258 | |||
| 8ae432223a | |||
| 9026220533 | |||
| f0c6dcf238 | |||
| 6c97bc4e2b | |||
| 3c67fea074 | |||
| 2a9507cb6a | |||
| 5b8bee286c | |||
| ba19954ffb | |||
| 88b4cad780 | |||
| a4c6aeed49 | |||
| 97498c560e | |||
| 8cb2a0f9c6 | |||
| 9f445904a5 | |||
| ce5d4204ac | |||
| 6ca735749e | |||
| 739228efdb | |||
| db5fb37980 | |||
| 0a7c4e129c | |||
| a96d06dbc0 | |||
| 06d94bb37d | |||
| f371349dd5 | |||
| fb38ee6087 | |||
| cd5983ecdd | |||
| f97654af86 | |||
| 755f237f17 | |||
| 49b18dd4ac | |||
| 274838cc2e | |||
| d76c184cf1 | |||
| d74aee33f7 | |||
| 52df78d24a | |||
| 22cfae830f | |||
| 404e859cb6 | |||
| 59c249e76a | |||
| bea3b49070 | |||
| e44c88dd68 | |||
| a842c5ffb0 | |||
| 7f17cfe439 | |||
| 622a6ab353 | |||
| 67d896615c | |||
| beb505b0fa | |||
| 43aa114bcd | |||
| 4b66906adc | |||
| 9823bdac78 | |||
| 7a4dab04d2 | |||
| 23f120f889 | |||
| 09db5413cd | |||
| 1a6355cad5 | |||
| 770029f207 | |||
| 802f0f580f | |||
| 6c7d0856b6 | |||
| dcd470cddc | |||
| 8f98e6adda | |||
| 106cb83988 | |||
| 33300f2ad1 | |||
| 12ad04c9d4 | |||
| 9c2edc4eee | |||
| de747b79e6 | |||
| dddcfb917c | |||
| ff915a306e | |||
| d6aa704b01 | |||
| 054a912357 | |||
| 3442eac6f0 | |||
| db743ffd1f | |||
| ab62440dbf | |||
| 92520de6c3 | |||
| be4c52ae89 | |||
| 967a808d73 | |||
| f60dd4da31 | |||
| c59c7d88f7 | |||
| b24e96b7e6 | |||
| a8078e1d8e | |||
| c6abc435cb | |||
| 9f1fc1b47c | |||
| d8d704d441 | |||
| 07d4a92309 | |||
| afa5f620bd | |||
| 56bd9ddc85 | |||
| 9ddd80993c | |||
| 25f4ad12bc | |||
| d37a9d5b5e | |||
| e5d356e8be | |||
| 0b189b36c5 | |||
| 11c17f3039 | |||
| 871d02406f | |||
| 6811caeab1 | |||
| d71234b03d | |||
| 8e1fb640b6 | |||
| 0019806a3b | |||
| c7c057a31a | |||
| 89dc1b1d85 | |||
| 13a22c4507 | |||
| 1db9acdf6d | |||
| 911c7a34fd | |||
| fcc314afb1 | |||
| b323244ac9 | |||
| 1d6a6fffcc | |||
| f56aa613da | |||
| 8c17f896b4 | |||
| c68c10cf04 | |||
| 7116046195 | |||
| dcac2c546b | |||
| 5c8e2dc0bd | |||
| bd03aec82a | |||
| e8d1c1ddac | |||
| f9740f640d | |||
| bf6db98f0d | |||
| fc55de19fa | |||
| 6ae3364bd0 | |||
| 5c40b4993f | |||
| fbc0da2a1b | |||
| 750d6c2e18 | |||
| 082246c085 | |||
| 16771b0b33 | |||
| 022634704a | |||
| 96ca7c0484 | |||
| 202366611e | |||
| ea92057e53 | |||
| c71593b286 | |||
| 413ad901fb | |||
| e0e46d8a57 | |||
| fbe29da05b | |||
| 9ffbd651b1 | |||
| aa5fb2cc40 | |||
| 468bc0fba9 | |||
| 571c5f9261 | |||
| cb32fe9b84 | |||
| fbe9804d3e | |||
| f6606accb3 | |||
| 0a007f4941 | |||
| 0c4aee6164 | |||
| a57f4930f0 | |||
| f9ca901a50 | |||
| 3ce69f8951 | |||
| acd1def00d | |||
| 5ec9c7f8bf | |||
| 11c028e6eb | |||
| afadb13de4 | |||
| b6398c44e6 | |||
| a2bd048ace | |||
| 2e97ff1461 | |||
| 7f37b37be3 | |||
| 4e31fb98a2 | |||
| 6cc22e5cc5 | |||
| b1d7ed2570 | |||
| dcbef721f2 | |||
| 772f8a615a | |||
| bf9ae20367 | |||
| 58d1f9426f | |||
| 3cd31c4322 | |||
| ae5feb05b7 | |||
| f2c4927ea6 | |||
| aa2abc2772 | |||
| 1aa84afa9a | |||
| 33e9118329 | |||
| e06fd57211 | |||
| 42fd3c7e90 | |||
| 0bc71dbd74 | |||
| 2ecd830d75 | |||
| 3a51b0ebd4 | |||
| ad406f21bd | |||
| 12fb9fc38b | |||
| 7b580a0070 | |||
| 22443a3810 | |||
| 0fce1e521c | |||
| 71fcf5e251 | |||
| 979e71fbea | |||
| 45e0b0bd95 | |||
| 70eb3fc13f | |||
| b30aa352f6 | |||
| 67cc33cfee | |||
| 6eec3b9ec7 | |||
| 57773b98ec | |||
| fe9b899a0e | |||
| abe9e663c1 | |||
| f5a33eb58c | |||
| a85090c3c6 | |||
| 97d48d8371 | |||
| 5020137050 | |||
| cf05ab2a9e | |||
| a6416a3f1d | |||
| 47ced228de | |||
| b8beeba98d | |||
| df6994c957 | |||
| d74e86c065 | |||
| 76512f6048 | |||
| 93a46d4de7 | |||
| 3ba24a0faf | |||
| 6926bb9528 | |||
| b1643309f6 | |||
| 43917a0051 | |||
| 1fac71e3ef | |||
| 747cc234c1 | |||
| fe72f0def2 | |||
| 884ecbba64 | |||
| 580d80a86e | |||
| 0e2ca5a7c3 | |||
| 4d2b8b9be3 | |||
| 0b31abe1d1 | |||
| 6b652cb0a2 | |||
| 3507c5714d | |||
| 4f78b9a875 | |||
| f3aebafcc7 | |||
| 1df0bc4f00 | |||
| 7d5d0cff06 | |||
| 8d752cb0e4 | |||
| 96e80ab293 | |||
| 49c5185ae3 | |||
| 181bd94341 | |||
| 09675a9f7f | |||
| 56c364e4c9 | |||
| 3021a4e761 | |||
| d240a61157 | |||
| d7c5307045 | |||
| 838d76f95e | |||
| 9791eee67b | |||
| 5d119f5555 | |||
| 46e5f612c8 | |||
| 41494bd18f | |||
| 40ebf7c1e7 | |||
| c7609252d2 | |||
| 4cf388dd3b | |||
| 00d85aa6e4 | |||
| d9e80a774a | |||
| a82407c686 | |||
| 805d754dc8 | |||
| d4c3811665 | |||
| b25761ea31 | |||
| 1c396dd562 | |||
| fc29c2eb9b | |||
| b0d5e04bb9 | |||
| 6746c75302 | |||
| b2697b13dc | |||
| e8ee6c34e7 | |||
| f42279f869 | |||
| 54ad9e8f79 | |||
| 6f16a231fc | |||
| 626c972232 | |||
| 44fcf24d92 | |||
| e187cd49a2 | |||
| 1631d3b1a2 | |||
| c71c2a8d33 | |||
| a51947562c | |||
| 63f02c4fb1 | |||
| 4fd5ee2608 | |||
| c7d4b9f753 | |||
| 37c2e5d7ee | |||
| 7dbd878398 | |||
| c2e2e0d8f2 | |||
| afc909fd3b | |||
| b607ff28cb | |||
| cf86d4e425 | |||
| 85761390a8 | |||
| 4d30d8b3e8 | |||
| 0e30980632 | |||
| 46a81e7a07 | |||
| e09344490f | |||
| 80a8bc4520 | |||
| b50e0359f7 | |||
| 58a300c7f4 | |||
| eb8311a5ee | |||
| 550a59d12c | |||
| 8c1d1ed958 | |||
| fc00b0c6f9 | |||
| 5276dd2066 | |||
| 88da16a11e | |||
| 3ef3bc32ec | |||
| 36fe1caa3f | |||
| f55c401b6c | |||
| b8037b9b22 | |||
| c0a3f68ded | |||
| 04c5043aba | |||
| 0b66662525 | |||
| cdea85e214 | |||
| 05f6147433 | |||
| 8f3b659c33 | |||
| c9ae914910 | |||
| 84e81f2037 | |||
| 696386a9c1 | |||
| aa2679162d | |||
| 096d1c882f | |||
| ca63095786 | |||
| c65e9c54ce | |||
| b1bc7a764e | |||
| d7c0a5521d | |||
| 2ae90b1ea9 | |||
| cfb0435d96 | |||
| fc411bb6f1 | |||
| 5bc39e902d | |||
| e2c4ca6d56 | |||
| 288d990821 | |||
| c03702707b | |||
| 89f77470f3 | |||
| 0d576a14b7 | |||
| c5807c07a9 | |||
| 8f5f54833f | |||
| f451406058 | |||
| 8aab2c0d41 | |||
| ed0ccb8c2b | |||
| b40adac3fc | |||
| bfb7876ed4 | |||
| 55b4e54d5f | |||
| fafa2f1858 | |||
| c84fd14cac | |||
| 23374312bc | |||
| a84a72e0c0 | |||
| 6c102f00c0 | |||
| 48aa955212 | |||
| cf3ddde3a6 | |||
| 468b006008 | |||
| e091921b18 | |||
| a9eb54ae9c | |||
| cf961603fe | |||
| cc3ecddc06 | |||
| a9a816e0ed |
@@ -0,0 +1,25 @@
|
||||
# OpenFUT Docker stack configuration. Copy to .env and adjust.
|
||||
# All values have sensible defaults in docker-compose.yml; override as needed.
|
||||
|
||||
# --- Container registry (Gitea) ---
|
||||
# Images resolve to ${REGISTRY}/${NAMESPACE}/<image>:${TAG}
|
||||
# e.g. git.aleshym.co/openfut/openfut-core:latest
|
||||
REGISTRY=git.aleshym.co
|
||||
NAMESPACE=openfut
|
||||
TAG=latest
|
||||
|
||||
# --- Networking ---
|
||||
# Where the bridge (FIFA client entry point) is published. 0.0.0.0 = all
|
||||
# interfaces so LAN clients can connect. Set to a specific IP to restrict.
|
||||
BRIDGE_PUBLISH=0.0.0.0
|
||||
# Where core's REST API is published. 127.0.0.1 keeps it host-local (the bridge
|
||||
# still reaches it over the internal docker network). Set 0.0.0.0 to expose it.
|
||||
CORE_PUBLISH=127.0.0.1
|
||||
|
||||
# --- Behaviour ---
|
||||
# Bridge returns placeholder JSON + captures unknown routes when true.
|
||||
PLACEHOLDER_MODE=true
|
||||
|
||||
# --- Logging (RUST_LOG filters) ---
|
||||
CORE_LOG=openfut_core=info,tower_http=info
|
||||
BRIDGE_LOG=openfut_bridge=info,tower_http=info
|
||||
+5
-5
@@ -30,9 +30,9 @@ Thumbs.db
|
||||
|
||||
# Frozen baseline archives / inspects / manifests
|
||||
/docker-backups/
|
||||
gate-evidence/
|
||||
|
||||
# local dev screenshots (not versioned)
|
||||
fifa17-recon/.screens/
|
||||
|
||||
# local hook backup
|
||||
*.pre-storeguard.bak
|
||||
# Raw Fire2 frame captures — forensic evidence, may contain session material.
|
||||
# Sanitize with `blaze-sanitize` before anything leaves this machine.
|
||||
*.ofcap
|
||||
captures/
|
||||
|
||||
@@ -0,0 +1,163 @@
|
||||
# AGENTS.md — OpenFUT
|
||||
|
||||
**Read this first.** It is the entry point for AI-assisted work on OpenFUT. It supersedes the
|
||||
root `README.md` and `CLAUDE.md`, which are **stale** (they describe an earlier FIFA 23 plan).
|
||||
|
||||
## Project
|
||||
|
||||
OpenFUT is a preservation / private-server project that restores **offline, single-player FIFA
|
||||
Ultimate Team (FUT)** after EA retired the online servers. You must own the game legitimately; the
|
||||
project does not bypass ownership checks — it only re-serves the dead online services locally.
|
||||
|
||||
**Current active target: FIFA 17 (PC).** A clean-room emulation of the full online + FUT stack
|
||||
was proven working end-to-end on **2026-08-01** (auth → Blaze login → device-trust → FUT hub).
|
||||
This lives in `fifa17-recon/`. The FIFA 17 work is explicitly the **Rosetta Stone for FIFA 23**
|
||||
(identical Blaze/LSX/UTAS wire format), so FIFA 23 remains the eventual second target.
|
||||
|
||||
Three moving parts, kept strictly separate:
|
||||
- **The FIFA client** — the retail game (FIFA 17 now). Unmodified except live cert-verify patches.
|
||||
- **The emulation layer** — Python responders in `fifa17-recon/tools/` (LSX, Blaze, UTAS, roster)
|
||||
that impersonate EA's online services on localhost. This is where all reverse engineering lives.
|
||||
- **OpenFUT Core** — a game-independent REST FUT economy backend (`openfut-core/`), feature-complete
|
||||
and tested. Knows nothing about FIFA. Intended to eventually back the emulation layer's FUT data.
|
||||
|
||||
> The emulation layer and Core are **not yet wired together.** The FIFA 17 UTAS server currently
|
||||
> serves its own hardcoded/JSON payloads, not Core's API. See `docs/PROJECT_STATE.md`.
|
||||
|
||||
## Repository map
|
||||
|
||||
Monorepo. `openfut-core`, `openfut-bridge`, `openfut-launcher`, `fifa-blaze` are **git submodules**
|
||||
(each with independent history — use `tea`/Gitea, not `gh`). `fifa17-recon/` is a plain directory.
|
||||
|
||||
| Path | What it is | Status |
|
||||
|---|---|---|
|
||||
| `fifa17-recon/` | **The live path.** FIFA 17 offline FUT emulation: Python responders, cert patcher, runbook, RE write-ups. | Working |
|
||||
| `openfut-core/` | Rust (Axum + SQLite) FUT economy backend. Game-independent REST API. | Working, tested |
|
||||
| `openfut-bridge/` | Rust FIFA 23 in-process hook / proxy RE effort. | Blocked (see below) |
|
||||
| `fifa-blaze/` | Rust Blaze protocol emulator scaffold for FIFA 23 (capture stub). | Milestone 1 stub |
|
||||
| `openfut-launcher/` | Rust egui/eframe desktop launcher (targets FIFA 23 hook flow). | Legacy plan |
|
||||
| `docs/` | **Mirrors** of the vault (`OpenFUT-Vault`), which is canonical. Direction pivots + context. | — |
|
||||
| `tools/` | Host-side RE helpers (file-watch-diff, exporters, squad-injector) from the FLE-bridge idea. | Legacy plan |
|
||||
| `setup.sh` | FIFA 23 full-stack orchestrator (core+bridge). | Legacy plan |
|
||||
|
||||
**Legacy vs live:** the project pivoted twice — (1) FIFA 23 Blaze backend → (2) FIFA 23 as a match
|
||||
renderer driven by an FLE Lua bridge (`docs/direction.md`) → (3) **FIFA 17 full online emulation,
|
||||
which succeeded and is now the primary path** (`fifa17-recon/`). Treat `openfut-bridge`,
|
||||
`openfut-launcher`, `fifa-blaze`, `tools/`, `setup.sh`, and `docs/direction.md` as historical unless
|
||||
a task explicitly targets the FIFA 23 port.
|
||||
|
||||
## Architecture (live path)
|
||||
|
||||
```
|
||||
FIFA 17 client (Wine/Proton, base 0x140000000)
|
||||
│ autopatch.py NOPs two ProtoSSL cert-verify gates in /proc/PID/mem
|
||||
├─ LSX 127.0.0.1:4216 → lsx_responder_v2.py (Origin login/profile/authcode)
|
||||
├─ TLS 127.0.0.1:42127 → blaze_responder_v3b.py (Blaze redirector, via DNAT of 159.153.51.20)
|
||||
├─ Blaze 42130 / Nucleus 42131 → blaze_responder_v3b.py (Fire2/Heat2 binary + login)
|
||||
├─ easw.easports.com (→127.0.0.1) :8099 → utas_server.py (UTAS/RS4 FUT API + device-trust)
|
||||
└─ roster :8081 → roster_server.py (FUT roster-update XML)
|
||||
|
||||
OpenFUT Core (openfut-core, :8080) ── clean REST FUT economy ── NOT YET CONNECTED to the above
|
||||
```
|
||||
|
||||
Host arming (`root_arm.sh` via `pkexec`, volatile across reboot): `ptrace_scope=0`,
|
||||
`route_localnet=1`, iptables DNAT `159.153.51.20→127.0.0.1:42127`, `/etc/hosts easw.easports.com`.
|
||||
|
||||
## Development commands (verified)
|
||||
|
||||
**FIFA 17 emulation** (from `fifa17-recon/tools/`):
|
||||
- Start everything (idempotent; re-run after reboot): `./openfut-fut.sh start`
|
||||
- Status / stop / restart: `./openfut-fut.sh status | stop | restart`
|
||||
- Then launch the game fresh (`~/Desktop/launch-fifa17.sh`) and pick Ultimate Team.
|
||||
- Logs: `/tmp/{lsx,blaze,roster,utas,autopatch}.log`
|
||||
- Full procedure + gate-ladder troubleshooting: `fifa17-recon/FUT-RUNBOOK.md`
|
||||
|
||||
**OpenFUT Core** (from `openfut-core/`): `cargo run` (creates `openfut.db`) · `cargo test`
|
||||
(full in-memory integration suite; requires `data/`) · `cargo test <name>` for one ·
|
||||
`cargo clippy -- -D warnings` · `cargo fmt`. Env: `LISTEN_ADDR` (127.0.0.1:8080), `DATABASE_URL`
|
||||
(sqlite://openfut.db), `DATA_DIR` (data).
|
||||
|
||||
**Other Rust crates** (`openfut-bridge`, `fifa-blaze`, `openfut-launcher`): standard
|
||||
`cargo run/build/test/clippy/fmt` from within each. `fifa-blaze` is a workspace (`--bin blaze-server`).
|
||||
|
||||
**CI:** only `openfut-core` has it (`.gitea/workflows/ci.yml`): `fmt --check`, `clippy -D warnings`,
|
||||
`build --locked`, `test --locked` on push/PR to main. No CI on the other crates or the recon dir.
|
||||
|
||||
There is **no install step, no Docker, no JS/TS frontend, no typecheck** in this repo. Do not invent them.
|
||||
|
||||
## Coding conventions
|
||||
|
||||
- **Rust (Core):** Axum 0.7 + SQLx 0.7 (SQLite, compile-time-checked queries). Strict layering —
|
||||
`routes/` (handlers, extract state, call services) → `services/` (own **all** DB access + logic)
|
||||
→ `models/` (pure `Serde`/`FromRow` data). Errors via `AppError` (`src/error.rs`) with
|
||||
`IntoResponse`. One file per domain across `routes/`, `services/`, `models/`. **Single-profile
|
||||
design:** every service reads "the active profile" as the first DB row — intentional, don't
|
||||
parameterize it. Content is data-driven: JSON under `data/` loaded at startup into Arc registries
|
||||
in `AppState`. Add content by dropping JSON files, not code. Migrations are numbered SQL in
|
||||
`migrations/`. Keep `clippy -D warnings` and `fmt` clean (CI enforces).
|
||||
- **Python (recon):** stdlib-only servers, no framework. Each responder is a standalone script with
|
||||
the reverse-engineered contract documented in its module docstring (byte offsets, VAs, symbol
|
||||
names). When changing a responder, preserve byte-exactness — the client is the oracle.
|
||||
- **Clean-room, always.** Every finding derives from binaries we own + live observation. **Never**
|
||||
use, reference, or reproduce leaked EA source. If a task seems to need it, stop and say so.
|
||||
|
||||
## AI-agent rules
|
||||
|
||||
1. Read this file before exploring the repo.
|
||||
2. Read the vault file relevant to the task (`../OpenFUT-Vault/`), not the whole tree. Repo
|
||||
`docs/` files are mirrors of the vault — consult them for the same content, but treat the
|
||||
vault as canonical.
|
||||
3. Don't scan the whole repository unless the knowledge base is clearly stale — if you find it
|
||||
stale, update the vault, then its repo `docs/` mirror.
|
||||
4. Search the specific directory (`fifa17-recon/`, `openfut-core/src/<layer>/`) before a repo-wide search.
|
||||
5. Update the vault when architecture materially changes (and sync the matching `docs/` mirror).
|
||||
6. Don't refactor or rewrite unrelated working code.
|
||||
7. Prefer small, testable changes; run the narrowest relevant test first (`cargo test <name>`).
|
||||
8. **Never invent EA/FIFA/Blaze protocol behavior.** Values you don't know are `TODO/CONFIRM`, not
|
||||
confident guesses. The live client is the only oracle for whether a gate is satisfied.
|
||||
9. Clearly separate discovered behavior from hypotheses; record findings in
|
||||
`../OpenFUT-Vault/02 Reverse Engineering/FIFA 17/Protocol Findings.md` under the right confidence
|
||||
tier — never silently promote a hypothesis to a fact.
|
||||
10. Root `README.md` / `CLAUDE.md` and `openfut-bridge/CLAUDE.md` describe superseded FIFA 23 plans;
|
||||
prefer vault + repository evidence over them when they conflict.
|
||||
|
||||
## AI Session Bootstrap
|
||||
|
||||
Future agents should start with:
|
||||
1. Read `AGENTS.md`.
|
||||
2. Read the vault README (`../OpenFUT-Vault/README.md`) to locate the canonical files.
|
||||
3. Identify the subsystem the task affects and read the corresponding vault file: Architecture,
|
||||
Project State, Roadmap/Current Priorities, or Protocol Findings.
|
||||
4. Inspect only the relevant source directories.
|
||||
5. Check `../OpenFUT-Vault/02 Reverse Engineering/FIFA 17/Protocol Findings.md` before assuming
|
||||
anything about FIFA/EA behavior.
|
||||
6. Check `../OpenFUT-Vault/06 Agent Memory/Project State.md` before assuming a feature exists.
|
||||
7. Implement the smallest coherent change.
|
||||
8. Run the narrowest relevant tests.
|
||||
9. Update the vault (and its repo `docs/` mirror) only if the change makes existing knowledge
|
||||
inaccurate.
|
||||
|
||||
Do not reread the entire repository during every session.
|
||||
|
||||
## OpenFUT Knowledge Base
|
||||
|
||||
**The OpenFUT Vault is the canonical project knowledge base.** Repo `docs/` files mirror it; the
|
||||
vault wins on any disagreement. Consult it before starting substantial work and update it after
|
||||
durable discoveries.
|
||||
|
||||
Vault location: `../OpenFUT-Vault/` — start at `../OpenFUT-Vault/README.md`.
|
||||
|
||||
Canonical files:
|
||||
- Dashboard: `00 Dashboard/OpenFUT.md`
|
||||
- Architecture: `01 Architecture/Architecture.md` (repo mirror `docs/ARCHITECTURE.md`)
|
||||
- RE findings: `02 Reverse Engineering/FIFA 17/Protocol Findings.md`
|
||||
(repo mirror `docs/research/KNOWN_FINDINGS.md`)
|
||||
- Direction history: `04 Decisions/Direction History.md`
|
||||
- Project State: `06 Agent Memory/Project State.md` (repo mirror `docs/PROJECT_STATE.md`)
|
||||
- Current Priorities: `06 Agent Memory/Current Priorities.md`
|
||||
- Known Issues: `06 Agent Memory/Known Issues.md`
|
||||
- Important Discoveries: `06 Agent Memory/Important Discoveries.md`
|
||||
- Roadmap: `08 Roadmap/Roadmap.md` (repo mirror `docs/ROADMAP.md`)
|
||||
|
||||
When editing knowledge that exists in both places, edit the vault first, then update the matching
|
||||
`docs/` mirror so they stay in sync.
|
||||
@@ -2,6 +2,8 @@
|
||||
|
||||
This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.
|
||||
|
||||
> ⚠️ **Stale (FIFA 23).** This file's status and targets predate the FIFA 17 pivot. Prefer [`docs/PROJECT_STATE.md`](./docs/PROJECT_STATE.md) (canonical). The working target is **FIFA 17**; the canonical server is `fifa17-recon/docker/fifa17-python` (`docker compose up -d`). `openfut-bridge` (FIFA 23) is superseded; `openfut-core` remains the shared backend.
|
||||
|
||||
## Repository Layout
|
||||
|
||||
This is a monorepo containing three independent Rust crates as git submodules:
|
||||
|
||||
Generated
+251
-96
@@ -457,6 +457,29 @@ version = "1.5.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "f2032f911046de80f0a198e0901378627c33f59ea0ac00e363d481118bd70a53"
|
||||
|
||||
[[package]]
|
||||
name = "aws-lc-rs"
|
||||
version = "1.18.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "ce2b2dcc879c3bae0d371e77c99f2238400ef24ec001394befa67b6e543add9e"
|
||||
dependencies = [
|
||||
"aws-lc-sys",
|
||||
"zeroize",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "aws-lc-sys"
|
||||
version = "0.44.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "f09fae7be8bb3174e05c6afdb34199e6dc0c7c04ba9fa237b1967adfbde27483"
|
||||
dependencies = [
|
||||
"cc",
|
||||
"cmake",
|
||||
"dunce",
|
||||
"fs_extra",
|
||||
"pkg-config",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "axum"
|
||||
version = "0.7.9"
|
||||
@@ -613,19 +636,6 @@ dependencies = [
|
||||
"tokio-util",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "blaze-ssl-async"
|
||||
version = "0.4.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "6fec08f35919613bda0b3eb3bc772c2f793b3634133923b931874b18e1ac55de"
|
||||
dependencies = [
|
||||
"bytes",
|
||||
"num_enum",
|
||||
"rsa",
|
||||
"tokio",
|
||||
"x509-cert",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "block"
|
||||
version = "0.1.6"
|
||||
@@ -830,6 +840,15 @@ dependencies = [
|
||||
"error-code",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "cmake"
|
||||
version = "0.1.58"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "c0f78a02292a74a88ac736019ab962ece0bc380e3f977bf72e376c5d78ff0678"
|
||||
dependencies = [
|
||||
"cc",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "codespan-reporting"
|
||||
version = "0.11.1"
|
||||
@@ -1062,23 +1081,10 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "e7c1832837b905bbfb5101e07cc24c8deddf52f93225eee6ead5f4d63d53ddcb"
|
||||
dependencies = [
|
||||
"const-oid",
|
||||
"der_derive",
|
||||
"flagset",
|
||||
"pem-rfc7468",
|
||||
"zeroize",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "der_derive"
|
||||
version = "0.7.3"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "8034092389675178f570469e6c3b0465d3d30b4505c294a6550db47f3c17ad18"
|
||||
dependencies = [
|
||||
"proc-macro2",
|
||||
"quote",
|
||||
"syn 2.0.119",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "deranged"
|
||||
version = "0.5.8"
|
||||
@@ -1187,6 +1193,12 @@ version = "0.1.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "d8b14ccef22fc6f5a8f4d7d768562a182c04ce9a3b3157b91390b52ddfdf1a76"
|
||||
|
||||
[[package]]
|
||||
name = "dunce"
|
||||
version = "1.0.5"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "92773504d58c093f6de2459af4af33faa518c13451eb8f2b5698ed3d36e7c813"
|
||||
|
||||
[[package]]
|
||||
name = "ecolor"
|
||||
version = "0.29.1"
|
||||
@@ -1457,12 +1469,6 @@ version = "0.1.9"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "5baebc0774151f905a1a2cc41989300b1e6fbb29aff0ceffa1064fdd3088d582"
|
||||
|
||||
[[package]]
|
||||
name = "flagset"
|
||||
version = "0.4.7"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "b7ac824320a75a52197e8f2d787f6a38b6718bb6897a35142d749af3c0e8f4fe"
|
||||
|
||||
[[package]]
|
||||
name = "flate2"
|
||||
version = "1.1.9"
|
||||
@@ -1547,6 +1553,12 @@ dependencies = [
|
||||
"percent-encoding",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "fs_extra"
|
||||
version = "1.3.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "42703706b716c37f96a77aea830392ad231f44c9e9a67872fa5548707e11b11c"
|
||||
|
||||
[[package]]
|
||||
name = "futures-channel"
|
||||
version = "0.3.33"
|
||||
@@ -2113,9 +2125,9 @@ dependencies = [
|
||||
"futures-util",
|
||||
"http 0.2.12",
|
||||
"hyper 0.14.32",
|
||||
"rustls",
|
||||
"rustls 0.21.12",
|
||||
"tokio",
|
||||
"tokio-rustls",
|
||||
"tokio-rustls 0.24.1",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
@@ -3126,11 +3138,34 @@ version = "1.21.4"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "9f7c3e4beb33f85d45ae3e3a1792185706c8e16d043238c593331cc7cd313b50"
|
||||
|
||||
[[package]]
|
||||
name = "openfut-adapter-fifa17"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"openfut-protocol-blaze",
|
||||
"rand",
|
||||
"serde",
|
||||
"serde_json",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-autopatch"
|
||||
version = "0.1.0"
|
||||
|
||||
[[package]]
|
||||
name = "openfut-blaze-host"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"openfut-adapter-fifa17",
|
||||
"openfut-protocol-blaze",
|
||||
"rand",
|
||||
"serde_json",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-bridge"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"aes",
|
||||
"anyhow",
|
||||
"axum",
|
||||
"bytes",
|
||||
@@ -3141,13 +3176,13 @@ dependencies = [
|
||||
"hyper-util",
|
||||
"rcgen",
|
||||
"reqwest",
|
||||
"rustls",
|
||||
"rustls-pemfile",
|
||||
"rustls 0.21.12",
|
||||
"rustls-pemfile 1.0.4",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"thiserror 1.0.69",
|
||||
"tokio",
|
||||
"tokio-rustls",
|
||||
"tokio-rustls 0.24.1",
|
||||
"tokio-stream",
|
||||
"tower 0.4.13",
|
||||
"tower-http",
|
||||
@@ -3175,6 +3210,7 @@ dependencies = [
|
||||
"serde",
|
||||
"serde_json",
|
||||
"sqlx",
|
||||
"tempfile",
|
||||
"thiserror 1.0.69",
|
||||
"tokio",
|
||||
"tower 0.5.3",
|
||||
@@ -3185,11 +3221,40 @@ dependencies = [
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-hook"
|
||||
name = "openfut-host-config"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"openfut-common",
|
||||
"windows-sys 0.59.0",
|
||||
"openfut-adapter-fifa17",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-http"
|
||||
version = "0.1.0"
|
||||
|
||||
[[package]]
|
||||
name = "openfut-identity"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"parking_lot",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"tempfile",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-import-fifa17"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"anyhow",
|
||||
"openfut-adapter-fifa17",
|
||||
"openfut-core",
|
||||
"openfut-identity",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"sqlx",
|
||||
"tempfile",
|
||||
"tokio",
|
||||
"uuid",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
@@ -3201,11 +3266,73 @@ dependencies = [
|
||||
"dirs",
|
||||
"eframe",
|
||||
"egui",
|
||||
"openfut-common",
|
||||
"parking_lot",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"tokio",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-lsx"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"aes",
|
||||
"parking_lot",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-protocol-blaze"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"serde_json",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-redirector-host"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"openfut-adapter-fifa17",
|
||||
"openfut-host-config",
|
||||
"openfut-http",
|
||||
"openfut-tls",
|
||||
"openssl",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-roster-host"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"openfut-adapter-fifa17",
|
||||
"openfut-host-config",
|
||||
"openfut-http",
|
||||
"openfut-tls",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-tls"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"openssl",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-utas-host"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"axum",
|
||||
"openfut-adapter-fifa17",
|
||||
"openfut-core",
|
||||
"openfut-http",
|
||||
"openfut-identity",
|
||||
"parking_lot",
|
||||
"rand",
|
||||
"reqwest",
|
||||
"serde_json",
|
||||
"sqlx",
|
||||
"tokio",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openssl"
|
||||
version = "0.10.81"
|
||||
@@ -3237,6 +3364,15 @@ version = "0.2.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "7c87def4c32ab89d880effc9e097653c8da5d6ef28e6b539d313baaacfbafcbe"
|
||||
|
||||
[[package]]
|
||||
name = "openssl-src"
|
||||
version = "300.6.1+3.6.3"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "46eb8fb9fb3b61ce1c0f8a026c4c1a0714d3a9e138e7fbde78753ce2babc3846"
|
||||
dependencies = [
|
||||
"cc",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openssl-sys"
|
||||
version = "0.9.117"
|
||||
@@ -3245,6 +3381,7 @@ checksum = "b47e7e6bb2c38cd930d25a23b40fa52e068c10e85f3e03a7f5ba5aaca5713695"
|
||||
dependencies = [
|
||||
"cc",
|
||||
"libc",
|
||||
"openssl-src",
|
||||
"pkg-config",
|
||||
"vcpkg",
|
||||
]
|
||||
@@ -3685,8 +3822,8 @@ dependencies = [
|
||||
"once_cell",
|
||||
"percent-encoding",
|
||||
"pin-project-lite",
|
||||
"rustls",
|
||||
"rustls-pemfile",
|
||||
"rustls 0.21.12",
|
||||
"rustls-pemfile 1.0.4",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"serde_urlencoded",
|
||||
@@ -3694,7 +3831,7 @@ dependencies = [
|
||||
"system-configuration",
|
||||
"tokio",
|
||||
"tokio-native-tls",
|
||||
"tokio-rustls",
|
||||
"tokio-rustls 0.24.1",
|
||||
"tower-service",
|
||||
"url",
|
||||
"wasm-bindgen",
|
||||
@@ -3833,10 +3970,26 @@ checksum = "3f56a14d1f48b391359b22f731fd4bd7e43c97f3c50eee276f3aa09c94784d3e"
|
||||
dependencies = [
|
||||
"log",
|
||||
"ring 0.17.14",
|
||||
"rustls-webpki",
|
||||
"rustls-webpki 0.101.7",
|
||||
"sct",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "rustls"
|
||||
version = "0.23.43"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "0283386ce02abc0151e1761d08802dfe86c173b0b494af5cbc086574e453da06"
|
||||
dependencies = [
|
||||
"aws-lc-rs",
|
||||
"log",
|
||||
"once_cell",
|
||||
"ring 0.17.14",
|
||||
"rustls-pki-types",
|
||||
"rustls-webpki 0.103.13",
|
||||
"subtle",
|
||||
"zeroize",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "rustls-pemfile"
|
||||
version = "1.0.4"
|
||||
@@ -3846,6 +3999,24 @@ dependencies = [
|
||||
"base64 0.21.7",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "rustls-pemfile"
|
||||
version = "2.2.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "dce314e5fee3f39953d46bb63bb8a46d40c2f8fb7cc5a3b6cab2bde9721d6e50"
|
||||
dependencies = [
|
||||
"rustls-pki-types",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "rustls-pki-types"
|
||||
version = "1.15.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "2f4925028c7eb5d1fcdaf196971378ed9d2c1c4efc7dc5d011256f76c99c0a96"
|
||||
dependencies = [
|
||||
"zeroize",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "rustls-webpki"
|
||||
version = "0.101.7"
|
||||
@@ -3856,6 +4027,18 @@ dependencies = [
|
||||
"untrusted 0.9.0",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "rustls-webpki"
|
||||
version = "0.103.13"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "61c429a8649f110dddef65e2a5ad240f747e85f7758a6bccc7e5777bd33f756e"
|
||||
dependencies = [
|
||||
"aws-lc-rs",
|
||||
"ring 0.17.14",
|
||||
"rustls-pki-types",
|
||||
"untrusted 0.9.0",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "rustversion"
|
||||
version = "1.0.23"
|
||||
@@ -4042,15 +4225,17 @@ version = "0.1.0"
|
||||
dependencies = [
|
||||
"anyhow",
|
||||
"blaze-proto",
|
||||
"blaze-ssl-async",
|
||||
"bytes",
|
||||
"chrono",
|
||||
"futures-util",
|
||||
"hex",
|
||||
"rustls 0.23.43",
|
||||
"rustls-pemfile 2.2.0",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"tdf",
|
||||
"tokio",
|
||||
"tokio-rustls 0.26.4",
|
||||
"tokio-util",
|
||||
"toml",
|
||||
"tracing",
|
||||
@@ -4068,6 +4253,12 @@ dependencies = [
|
||||
"digest",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "sha1_smol"
|
||||
version = "1.0.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "bbfa15b3dddfee50a0fff136974b3e1bde555604ba463834a7eb7deb6417705d"
|
||||
|
||||
[[package]]
|
||||
name = "sha2"
|
||||
version = "0.10.9"
|
||||
@@ -4334,8 +4525,8 @@ dependencies = [
|
||||
"once_cell",
|
||||
"paste",
|
||||
"percent-encoding",
|
||||
"rustls",
|
||||
"rustls-pemfile",
|
||||
"rustls 0.21.12",
|
||||
"rustls-pemfile 1.0.4",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"sha2",
|
||||
@@ -4789,27 +4980,6 @@ version = "0.1.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "1f3ccbac311fea05f86f61904b462b55fb3df8837a366dfc601a0161d0532f20"
|
||||
|
||||
[[package]]
|
||||
name = "tls_codec"
|
||||
version = "0.4.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "0de2e01245e2bb89d6f05801c564fa27624dbd7b1846859876c7dad82e90bf6b"
|
||||
dependencies = [
|
||||
"tls_codec_derive",
|
||||
"zeroize",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "tls_codec_derive"
|
||||
version = "0.4.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "2d2e76690929402faae40aebdda620a2c0e25dd6d3b9afe48867dfd95991f4bd"
|
||||
dependencies = [
|
||||
"proc-macro2",
|
||||
"quote",
|
||||
"syn 2.0.119",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "tokio"
|
||||
version = "1.53.1"
|
||||
@@ -4854,7 +5024,17 @@ version = "0.24.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "c28327cf380ac148141087fbfb9de9d7bd4e84ab5d2c28fbc911d753de8a7081"
|
||||
dependencies = [
|
||||
"rustls",
|
||||
"rustls 0.21.12",
|
||||
"tokio",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "tokio-rustls"
|
||||
version = "0.26.4"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "1729aa945f29d91ba541258c8df89027d5792d85a8841fb65e8bf0f4ede4ef61"
|
||||
dependencies = [
|
||||
"rustls 0.23.43",
|
||||
"tokio",
|
||||
]
|
||||
|
||||
@@ -5219,6 +5399,7 @@ dependencies = [
|
||||
"getrandom 0.4.3",
|
||||
"js-sys",
|
||||
"serde_core",
|
||||
"sha1_smol",
|
||||
"wasm-bindgen",
|
||||
]
|
||||
|
||||
@@ -6157,18 +6338,6 @@ version = "0.13.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "ea6fc2961e4ef194dcbfe56bb845534d0dc8098940c7e5c012a258bfec6701bd"
|
||||
|
||||
[[package]]
|
||||
name = "x509-cert"
|
||||
version = "0.2.5"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "1301e935010a701ae5f8655edc0ad17c44bad3ac5ce8c39185f75453b720ae94"
|
||||
dependencies = [
|
||||
"const-oid",
|
||||
"der",
|
||||
"spki",
|
||||
"tls_codec",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "xcursor"
|
||||
version = "0.3.11"
|
||||
@@ -6393,20 +6562,6 @@ name = "zeroize"
|
||||
version = "1.9.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "e13c156562582aa81c60cb29407084cdb54c4164760106ab78e6c5b0858cf64e"
|
||||
dependencies = [
|
||||
"zeroize_derive",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "zeroize_derive"
|
||||
version = "1.5.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "3c50655cbb0fe3fc43170059e702f1ce5e19b84cec58dc87b037a09935c2f328"
|
||||
dependencies = [
|
||||
"proc-macro2",
|
||||
"quote",
|
||||
"syn 2.0.119",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "zerotrie"
|
||||
|
||||
+22
-1
@@ -2,9 +2,30 @@
|
||||
resolver = "2"
|
||||
members = [
|
||||
"openfut-core",
|
||||
"openfut-protocol-blaze",
|
||||
"openfut-adapter-fifa17",
|
||||
"openfut-blaze-host",
|
||||
"openfut-host-config",
|
||||
"openfut-http",
|
||||
"openfut-tls",
|
||||
"openfut-redirector-host",
|
||||
"openfut-roster-host",
|
||||
"openfut-utas-host",
|
||||
"openfut-identity",
|
||||
"openfut-import-fifa17",
|
||||
"openfut-bridge",
|
||||
"openfut-launcher",
|
||||
"openfut-launcher/openfut-hook",
|
||||
# The two companion services the launcher used to shell out to Python for.
|
||||
"openfut-lsx",
|
||||
"openfut-autopatch",
|
||||
"fifa-blaze/crates/blaze-proto",
|
||||
"fifa-blaze/crates/server",
|
||||
]
|
||||
# openfut-hook is a Windows-only version.dll proxy injected into the FIFA client.
|
||||
# It MUST build with its own [profile.release] (panic="abort" — unwinding across
|
||||
# the DllMain/FFI boundary into the game process is UB — plus strip + opt-level="s").
|
||||
# Cargo ignores a non-root member's profile and forbids per-package `panic` overrides,
|
||||
# so the hook is deliberately EXCLUDED from this workspace to build as its own root
|
||||
# (this also lands its artifact in openfut-hook/target/, matching the launcher's
|
||||
# config.rs default hook_dll_path). Build: cargo build --release --target x86_64-pc-windows-gnu.
|
||||
exclude = ["openfut-launcher/openfut-hook"]
|
||||
|
||||
@@ -263,48 +263,3 @@ Both matter beyond themselves, because they are the only two routes into a match
|
||||
Useful framing: this project's failures have almost always come from proposing a fix
|
||||
before testing the assumption under it. Hypotheses that come with a cheap way to
|
||||
disconfirm them are worth far more than plausible ones.
|
||||
|
||||
## FIFA 17 network-redirect milestone (2026-08-09)
|
||||
|
||||
Hook now installs a GENERIC network redirect on the fifa17 feature path (fifa17.rs
|
||||
install_network_redirect): getaddrinfo IAT patch + inline connect detour + WSAConnect
|
||||
IAT, with a configurable destination (connect_hook::set_target_ipv4) read from
|
||||
openfut.cfg (single-line IP). Deployed DLL md5 bc9e0bc6, cfg=10.10.0.120.
|
||||
|
||||
RESULT of live launch (client 105 -> server 120):
|
||||
- Error changed: "servers shut down" -> "Unable to connect to EA servers / check
|
||||
network". Redirect IS firing (progress).
|
||||
- BLOCKER A: getaddrinfo IAT patched 0+0 -> FIFA 17 does NOT resolve via IAT
|
||||
getaddrinfo in the main exe or EAWebKit.dll. Names resolved via another path
|
||||
(gethostbyname or internal DirtySDK resolver). So no hostname reached 120.
|
||||
- BLOCKER B (architectural): FIFA 17 online = Blaze binary TCP on high ports. Log
|
||||
shows connect 20.51.153.159:42230 sock_type=1 -> wsa_err=10035 (WOULDBLOCK->dead).
|
||||
Port 42230 is NOT in the remap set (443,10041,42127,3216) so it was not redirected.
|
||||
Even if redirected, the Docker bridge only speaks HTTPS on 8443 -- no Blaze
|
||||
listener exists for FIFA 17. This is a server-side build, not a hook tweak.
|
||||
|
||||
NEXT (evidence-first): add gethostbyname (and possibly a DirtySDK resolver) capture
|
||||
to learn the hostname behind 20.51.153.159; widen Blaze port remap; then scope a
|
||||
Blaze-speaking bridge listener before expecting the error to clear.
|
||||
|
||||
## DNS/getaddrinfo fix — RESOLVED (2026-08-09, hook md5 67e3639b)
|
||||
|
||||
Added src/resolver_hook.rs: INLINE detours at ws2_32 export addresses for
|
||||
getaddrinfo + GetAddrInfoW + gethostbyname (same unhook/rehook pattern as
|
||||
connect_hook). Replaces the IAT approach that patched 0 slots on FIFA 17.
|
||||
Wired into fifa17.rs install_network_redirect; hooks.rs gained redirect_ip_cstr()
|
||||
and redirect_ip_str() helpers.
|
||||
|
||||
LIVE RESULT (client 105 -> server 120):
|
||||
- resolver detours 3/3 installed.
|
||||
- getaddrinfo(winter15.gosredirector.ea.com) -> redirect. Game now dials
|
||||
10.10.0.120 (was 20.51.153.159 before). DNS BLOCKER A = SOLVED.
|
||||
|
||||
REMAINING BLOCKER B (architectural, NOT DNS): FIFA 17 online = EA Blaze binary
|
||||
TCP. Game connects 10.10.0.120:42230 (gosredirector/Blaze redirector) ->
|
||||
wsa_err=10035 (nothing listening). Two gaps: (1) connect_hook remap set lacks
|
||||
42230; (2) even remapped, the Docker bridge only serves HTTPS on 8443 — no Blaze
|
||||
listener exists. Clearing Unable to connect requires a Blaze redirector+main
|
||||
server on the bridge side (real server build), not a hook change.
|
||||
NOTE: the 3s TLS-handshake-EOF spam in bridge logs on :8443 is the LAUNCHER health
|
||||
poller, not the game.
|
||||
|
||||
@@ -1,5 +1,9 @@
|
||||
# OpenFUT
|
||||
|
||||
> ⚠️ **Status — see [`docs/PROJECT_STATE.md`](./docs/PROJECT_STATE.md) (canonical).** The working, actively-developed target is **FIFA 17**, not FIFA 23. Everything below this banner describes the **superseded FIFA 23 `bridge` lineage** and is kept for historical context.
|
||||
>
|
||||
> **Run the server (canonical):** `cd fifa17-recon/docker/fifa17-python && docker compose up -d` — see [`fifa17-recon/FUT-RUNBOOK.md`](./fifa17-recon/FUT-RUNBOOK.md). `openfut-core` is the shared offline backend (still used by the FIFA 17 path); `openfut-bridge` is the retired FIFA 23 integration.
|
||||
|
||||
**Offline Ultimate Team — like SPT, but for FIFA 23.**
|
||||
|
||||
OpenFUT replaces EA's retired FUT servers with a fully offline, single-player backend. You own FIFA 23 legitimately. You just want to keep playing after EA shut down the servers.
|
||||
|
||||
@@ -0,0 +1,93 @@
|
||||
# ============================================================================
|
||||
# ⚠️ LEGACY (FIFA 23 lineage). This compose runs core + bridge for the
|
||||
# superseded FIFA 23 direction. It is NOT the canonical server bring-up.
|
||||
#
|
||||
# Canonical server (FIFA 17):
|
||||
# cd fifa17-recon/docker/fifa17-python && docker compose up -d
|
||||
# (runbook: fifa17-recon/FUT-RUNBOOK.md)
|
||||
#
|
||||
# `core` (openfut-core) IS still the shared, game-independent backend and is
|
||||
# used by the FIFA 17 UTAS host (OPENFUT_CORE_URL). `bridge` (openfut-bridge)
|
||||
# is the retired FIFA 23 integration, kept for reference.
|
||||
# Status source of truth: docs/PROJECT_STATE.md
|
||||
# ============================================================================
|
||||
# OpenFUT server stack — offline FUT backend (Core) + FIFA proxy (Bridge).
|
||||
#
|
||||
# Bring up: docker compose up -d
|
||||
# Tear down: docker compose down (keeps data/captures volumes)
|
||||
# Wipe state: docker compose down -v (also drops volumes)
|
||||
# Rebuild: docker compose build (or ./scripts/registry.sh build)
|
||||
# Logs: docker compose logs -f
|
||||
#
|
||||
# Images are pulled from / pushed to the Gitea container registry. Override the
|
||||
# registry, namespace, or tag in .env (see .env.example). When REGISTRY is set,
|
||||
# `up` pulls prebuilt images; the build: blocks let you rebuild locally too.
|
||||
|
||||
name: openfut
|
||||
|
||||
services:
|
||||
core:
|
||||
image: ${REGISTRY:-git.aleshym.co}/${NAMESPACE:-openfut}/openfut-core:${TAG:-latest}
|
||||
build:
|
||||
context: ./openfut-core
|
||||
dockerfile: Dockerfile
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
LISTEN_ADDR: 0.0.0.0:8080
|
||||
DATABASE_URL: sqlite:///app/db/openfut.db
|
||||
DATA_DIR: /app/data
|
||||
RUST_LOG: ${CORE_LOG:-openfut_core=info,tower_http=info}
|
||||
volumes:
|
||||
- core-db:/app/db
|
||||
# Bound to localhost by default — the bridge reaches core over the internal
|
||||
# network, so core need not be world-exposed. Set CORE_PUBLISH=0.0.0.0 in
|
||||
# .env if you want to hit the REST API directly from other hosts.
|
||||
ports:
|
||||
- "${CORE_PUBLISH:-127.0.0.1}:8080:8080"
|
||||
networks:
|
||||
- openfut
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-fsS", "http://127.0.0.1:8080/health"]
|
||||
interval: 15s
|
||||
timeout: 4s
|
||||
retries: 5
|
||||
start_period: 10s
|
||||
|
||||
bridge:
|
||||
image: ${REGISTRY:-git.aleshym.co}/${NAMESPACE:-openfut}/openfut-bridge:${TAG:-latest}
|
||||
build:
|
||||
context: ./openfut-bridge
|
||||
dockerfile: Dockerfile
|
||||
restart: unless-stopped
|
||||
depends_on:
|
||||
core:
|
||||
condition: service_healthy
|
||||
environment:
|
||||
BRIDGE_LISTEN_ADDR: 0.0.0.0:8443
|
||||
CORE_URL: http://core:8080
|
||||
CAPTURES_DIR: /app/captures
|
||||
PLACEHOLDER_MODE: ${PLACEHOLDER_MODE:-true}
|
||||
TLS_ENABLED: "true"
|
||||
RUST_LOG: ${BRIDGE_LOG:-openfut_bridge=info,tower_http=info}
|
||||
volumes:
|
||||
- bridge-captures:/app/captures
|
||||
# The FIFA client connects here — publish on all interfaces by default so
|
||||
# LAN clients (e.g. 10.10.0.0/24) can reach it.
|
||||
ports:
|
||||
- "${BRIDGE_PUBLISH:-0.0.0.0}:8443:8443"
|
||||
networks:
|
||||
- openfut
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-fsSk", "https://127.0.0.1:8443/_bridge/health"]
|
||||
interval: 15s
|
||||
timeout: 4s
|
||||
retries: 5
|
||||
start_period: 8s
|
||||
|
||||
networks:
|
||||
openfut:
|
||||
driver: bridge
|
||||
|
||||
volumes:
|
||||
core-db:
|
||||
bridge-captures:
|
||||
@@ -1,250 +0,0 @@
|
||||
# OpenFUT — Direction Document
|
||||
*The pivot: FUT lives in the app; FIFA 23 is the match renderer.*
|
||||
*Supersedes the Blaze-backend approach as the primary plan. Last updated 2026-06-30.*
|
||||
|
||||
---
|
||||
|
||||
## 1. Goal (revised)
|
||||
|
||||
Deliver an **intuitive way to play a FUT-style experience with FIFA 23**, where:
|
||||
|
||||
- The entire **FUT experience** — cards, squads, packs, SBCs, coins, chemistry,
|
||||
progression — lives in a **custom app** (web UI or desktop) built on the
|
||||
already-complete OpenFUT Core economy backend.
|
||||
- **FIFA 23 is demoted to a match renderer.** Its only job is to play a
|
||||
single-player match using the squad the app built. No FUT mode, no online, no
|
||||
Blaze, no EA servers.
|
||||
|
||||
This deliberately drops in-game FUT cards/UI (they live in the app) in exchange
|
||||
for a project that **converges** instead of being gated behind months of
|
||||
backend reverse-engineering.
|
||||
|
||||
### Why this replaces the backend plan
|
||||
|
||||
The status review confirmed the backend route (faking EA's online stack) is
|
||||
blocked at an upstream in-process EbisuSDK gate, with Blaze/Fire2 unconfirmed
|
||||
beyond it — realistically 3–6 months of expert RE that may not converge. The
|
||||
app-centric route sidesteps **every** wall in that review by never making FIFA's
|
||||
own FUT mode run.
|
||||
|
||||
---
|
||||
|
||||
## 2. Base mode: Career, not Kick-Off
|
||||
|
||||
**Career mode is the base.** Reasons:
|
||||
|
||||
- FLE's live-editing API (`EditDBTableField`, Freeze Lineup) is **confirmed to
|
||||
work in career mode** and explicitly does NOT work in FUT/online modes.
|
||||
- Career already provides the FUT-shaped scaffolding we'd otherwise fake:
|
||||
persistent club, a fixture schedule, recorded results, progression across a
|
||||
season.
|
||||
- **Match results are written into the career DB**, making result capture a DB
|
||||
read rather than a fragile live-memory grab.
|
||||
|
||||
**Kick-Off is the prototype sandbox.** Use it first to prove squad injection
|
||||
works with nothing to corrupt (no save to break), then move the real loop onto
|
||||
career. Run the foundational injection test in BOTH.
|
||||
|
||||
---
|
||||
|
||||
## 3. Core architecture: the bidirectional FLE bridge
|
||||
|
||||
The backbone is a **bidirectional channel between the app and a resident FLE Lua
|
||||
script running inside the game.** Everything else is messages over this channel.
|
||||
|
||||
```
|
||||
Custom App (FUT experience)
|
||||
│ squad push ──────────────► ┌─────────────────────────────┐
|
||||
│ │ Resident FLE Lua script │
|
||||
│ ◄────────── game state │ (inside FIFA 23, career) │
|
||||
│ ◄────────── match result │ - reads game state │
|
||||
└────────────────────────────► │ - applies squad live │
|
||||
(file-watch or local socket) │ - reads results from DB │
|
||||
└─────────────────────────────┘
|
||||
│
|
||||
FIFA 23 plays the match
|
||||
```
|
||||
|
||||
Three message types over the bridge:
|
||||
|
||||
1. **App → Game: squad push.** The app's chosen XI + stats applied LIVE via
|
||||
`EditDBTableField`, replicating whatever DB write FLE's "Freeze Lineup"
|
||||
feature performs (see `docs/foundational-xi-injection-test.md` — the exact
|
||||
field(s) are found by diffing, not assumed). No restart, no
|
||||
file-copy-reload. (File-load remains a fallback.)
|
||||
|
||||
2. **Game → App: game state.** The resident script polls the game's current
|
||||
screen/menu state and reports "safe to apply" vs "not safe", driving a smart
|
||||
Apply button in the app (see §5).
|
||||
|
||||
3. **Game → App: match result.** After full-time, the script reads the result
|
||||
from the career DB and pushes score/scorers to the app, which awards
|
||||
coins/progression. (Manual entry is the baseline fallback.)
|
||||
|
||||
The bridge transport can be a watched file the in-game Lua polls, or a local
|
||||
socket — decided in build (see §7). Either way the *game keeps running*; a file,
|
||||
if used, is just the message channel, not a reload.
|
||||
|
||||
---
|
||||
|
||||
## 4. Tiered mod scope
|
||||
|
||||
Build in tiers matched to risk. The core tier is all the SAME kind of DB write,
|
||||
so it lands together once squad injection works.
|
||||
|
||||
### Tier 1 — Core writes (ride the same live DB-edit mechanism)
|
||||
- **Squad / custom XI** — the load-bearing primitive (Freeze Lineup's
|
||||
underlying write, replicated via script — see §6).
|
||||
- **Player stats as "cards"** — card tiers, in-form versions, SBC upgrades all
|
||||
expressed as written attribute values.
|
||||
- **Chemistry as stat adjustment** — app computes FUT chemistry, applies it as
|
||||
small stat bumps when writing players in (no in-game chem UI; that's in the app).
|
||||
- **Appearance / identity** — kits, names, team assignment, so the club looks
|
||||
like your club on the pitch.
|
||||
- **Formation / tactics** — squad structure carries the app's build onto the pitch.
|
||||
|
||||
### Tier 2 — Confirm-then-add
|
||||
- **Match difficulty per game** — to drive a Squad-Battles-style "this opponent is
|
||||
World Class". Settable in-game trivially; programmatic drive needs confirming.
|
||||
- **Match rules / modifiers** (half length, etc.) — for app-defined challenges.
|
||||
|
||||
### Tier 3 — Result capture (manual baseline + automated stretch)
|
||||
- **Manual:** user enters the score in the app after the match. Zero RE, ships
|
||||
first.
|
||||
- **Automated:** resident script reads the career-DB result (or, for Kick-Off,
|
||||
reads the in-match score from memory at full-time — precedent exists: the
|
||||
CM cheat table's `export_season_stats.lua` already reads goals/cards from
|
||||
memory via known offsets). Push to app → auto-award progression.
|
||||
|
||||
### Out of scope (stays in the app, by design)
|
||||
- In-game FUT cards, FUT menus, pack-opening animation, chemistry board, FUT
|
||||
presentation. The app is where it looks/feels like FUT.
|
||||
|
||||
---
|
||||
|
||||
## 5. The smart Apply button (state-aware)
|
||||
|
||||
Live DB edits only "stick" in safe menu states (the in-game "Edit Player" screen,
|
||||
for example, overwrites edits). So the bridge reads game state and gates applying:
|
||||
|
||||
- Resident Lua script polls the game's current-screen value (a few Hz),
|
||||
classifies **safe / not safe**, reports to the app.
|
||||
- App's **Apply button is enabled only when the script confirms a safe state**
|
||||
(squad hub, main menu); greyed otherwise.
|
||||
- **Safe-by-default-OFF:** unknown state → button greyed → never a risky write.
|
||||
Expand the known-safe list incrementally as states are confirmed.
|
||||
- **v2 (more seamless):** instead of greying, the app always lets you click and
|
||||
the script **queues** the apply, executing the moment a safe state is entered,
|
||||
then confirms back. Greying is v1; queue-and-apply is v2.
|
||||
|
||||
`IsInCM()` is a confirmed state-read; the specific screen-state address + the
|
||||
value→screen mapping is one-time reconnaissance (same technique as result reading).
|
||||
|
||||
---
|
||||
|
||||
## 6. What's confirmed vs what needs validating
|
||||
|
||||
**Confirmed (from FLE's own Lua API docs/wiki, checked 2026-06-30):**
|
||||
- FLE live-edits the running career DB without restart, via `EditDBTableField`
|
||||
(real signature: `EditDBTableField(cell)` where `cell = row["fieldname"]`
|
||||
with `.value` mutated first — not the table/index/field/value form an
|
||||
earlier draft of this doc assumed).
|
||||
- FLE reads game state via `IsInCM()`.
|
||||
- A `MEMORY` Lua class exists (`ReadInt`/`WriteInt`/`ReadMultilevelPointer`/
|
||||
etc.) for arbitrary process memory — confirms the result-reading fallback
|
||||
in §4 Tier 3 is a real, documented capability, not just cheat-table analogy.
|
||||
- `GetPlayersStats()` is a documented function returning per-player
|
||||
goals/assists/cards/etc. — a better confirmed path for match-result capture
|
||||
than raw memory offsets.
|
||||
- **Freeze Lineup** (Formation Editor → arrange XI → tick "Freeze Lineup" →
|
||||
`Data → Save`) is FLE's actual documented mechanism for forcing a starting
|
||||
XI in career mode. This **replaces** "selection bias" below.
|
||||
- OpenFUT Core (economy) is complete and tested.
|
||||
|
||||
**Walked back — not actually confirmed:**
|
||||
- "Selection bias forces specific players into the starting XI" — no such
|
||||
field appears anywhere in FLE's documented Lua API or its own example
|
||||
scripts. This was an unverified assumption carried over from general FIFA
|
||||
modding precedent (other titles), not anything checked against FLE/FIFA 23.
|
||||
See `docs/foundational-xi-injection-test.md` for the corrected plan, which
|
||||
uses Freeze Lineup instead.
|
||||
|
||||
**Needs validating (the foundational tests — see §7):**
|
||||
- Whether Freeze Lineup actually holds into a played match (FLE's wiki
|
||||
documents the feature but not a live-match test of it).
|
||||
- What DB table/field Freeze Lineup's `Data → Save` actually writes — it's
|
||||
GUI-only and undocumented at that level; finding it is part of the
|
||||
foundational test.
|
||||
- Whether that write can be replicated by a script (`EditDBTableField`) well
|
||||
enough to drive it from an EXTERNAL trigger, not just the Formation Editor
|
||||
UI — required for the app↔game bridge.
|
||||
- The app↔game bridge transport (file-watch vs socket) works cleanly under the
|
||||
run setup.
|
||||
- The screen-state address + safe/not-safe classification (FLE's `Events`
|
||||
API page exists in the wiki index but its content is currently empty/
|
||||
undocumented — this is more open than previously assumed).
|
||||
- Result read-back from the career DB after a match.
|
||||
|
||||
**Standing caveat:** the whole stack rides on **EAAC staying neutralized**
|
||||
(FLE's fake-launcher bypass). If a game update re-enables it, hooks fail. Keep
|
||||
game updates off; confirm neutralized state each session.
|
||||
|
||||
---
|
||||
|
||||
## 7. Build order / next steps
|
||||
|
||||
Each is a bounded, verifiable step. Do them in order; later ones depend on
|
||||
earlier answers.
|
||||
|
||||
1. **FOUNDATIONAL TEST — live custom XI in career.** Confirm Freeze Lineup
|
||||
holds into a played match, reverse-engineer the DB write it makes, then
|
||||
replicate that write from a script so it can be triggered externally
|
||||
instead of through the Formation Editor UI. See
|
||||
`docs/foundational-xi-injection-test.md` for the full procedure. *Done =
|
||||
a script-driven write produces a match that fields the squad you
|
||||
specified.* Everything rests on this.
|
||||
|
||||
2. **Pick the bridge transport.** Decide file-watch vs local socket for app↔game
|
||||
messaging; implement the minimal app→game squad push. *Done = app sends a
|
||||
squad, the resident script receives and applies it.*
|
||||
|
||||
3. **Game-state reader + smart Apply.** Find the screen-state address, classify
|
||||
safe/not-safe, expose to the app, gate the Apply button. *Done = button greys
|
||||
when you enter a match/edit screen, enables in the squad hub.*
|
||||
|
||||
4. **Result read-back.** Read the career-DB match result post-game, push to app,
|
||||
award progression. Manual entry ships alongside as the fallback. *Done = app
|
||||
updates coins from a played match.*
|
||||
|
||||
5. **Tier 1 breadth.** Extend the squad push to carry stats, appearance,
|
||||
formation (same write mechanism). *Done = the club looks and plays like the
|
||||
app's build.*
|
||||
|
||||
6. **Tier 2 + economy loop polish.** Difficulty drive, challenges, and the full
|
||||
pack → SBC → squad → match → reward loop closed end-to-end.
|
||||
|
||||
### Decision still open
|
||||
- **App form factor:** web UI vs desktop app. This affects the bridge transport
|
||||
(a desktop app can hold a local socket more naturally; a web UI leans toward a
|
||||
small local helper/file-watch). Decide before step 2.
|
||||
|
||||
---
|
||||
|
||||
## 8. Provenance
|
||||
|
||||
Clean-room throughout. This route relies on FLE's documented public API and the
|
||||
game's own supported career mode — no EA backend, no Blaze, and nothing derived
|
||||
from leaked EA source. The earlier backend RE remains clean-room and is preserved
|
||||
as a spec artifact; it is simply no longer the primary path.
|
||||
|
||||
---
|
||||
|
||||
## 9. One-paragraph summary
|
||||
|
||||
OpenFUT becomes a **FUT companion app that uses FIFA 23 as a match engine.** The
|
||||
app owns the entire FUT experience; a resident FLE Lua script in career mode
|
||||
applies the app's squad live (no restart), reports game state to drive a safe
|
||||
Apply button, and reads match results back to feed progression. This sidesteps
|
||||
every backend wall, runs on confirmed FLE capabilities, builds on the finished
|
||||
economy core, and delivers the intuitive, offline, FUT-flavored loop that is the
|
||||
actual goal.
|
||||
@@ -1,108 +0,0 @@
|
||||
# FIFA 23 PC Startup Flow (Offline / Proton)
|
||||
|
||||
Observed via FLE log, hook log, and file inspection on 2026-06-26.
|
||||
|
||||
## Launch chain
|
||||
|
||||
```
|
||||
umu-run / Steam → FIFA23.exe (via Proton/Wine)
|
||||
│
|
||||
├─ DLL load order (before entry point)
|
||||
│ ntdll.dll, kernel32.dll, ws2_32.dll …
|
||||
│ version.dll ← our hook DLL slot (loads here)
|
||||
│ FIFALiveEditor.DLL ← injected by FLE launcher after ~100 ms
|
||||
│
|
||||
├─ anadius / LSX emulator (anadius64.dll)
|
||||
│ Fakes EA App / Origin session
|
||||
│ Reads HKLM\SOFTWARE\Wow6432Node\Origin\ClientPath
|
||||
│ Writes AppData\Local\anadius\LSX emu\achievement-*.xml
|
||||
│ Provides fake PersonaId=1144668899 / UserId=1000200030000
|
||||
│
|
||||
├─ EA Anti-Cheat (EAAntiCheat.GameServiceLauncher.exe)
|
||||
│ Spawns as child; checks EAAntiCheat.cfg
|
||||
│ Not active in offline/cracked builds (FakeEAACLauncher present)
|
||||
│
|
||||
└─ FIFA23.exe entry point
|
||||
Frostbite engine init (BuildDate 2023-07-05, changelist 5417699)
|
||||
Reads Data\initfs_Win32 ← Frostbite package manifest
|
||||
Reads Data\layout.toc ← file-system layout
|
||||
Reads Patch\initfs_Win32 ← patches on top of base
|
||||
Reads Documents\FIFA 23\fifasetup.ini ← display settings
|
||||
Reads Data\locale.ini ← language table
|
||||
Reads Data\db_meta.xml (via FLE) ← DB schema for all tables
|
||||
```
|
||||
|
||||
## Phase timing (observed, single machine)
|
||||
|
||||
| Phase | Time after launch | Trigger |
|
||||
|------------------------------|-------------------|----------------------------------|
|
||||
| DLL load + FLE injection | 0 – 0.3 s | OS loader |
|
||||
| Engine + DirectX init | 0.3 – 5 s | FIFA23 entry point |
|
||||
| "Press any key" splash | ~5 s | First rendered frame |
|
||||
| Main menu | ~25 s | After key press |
|
||||
| FUT mode entry (attempted) | user-driven | User selects FUT tile |
|
||||
| Network calls to EA services | at FUT entry | DirtySDK / EAWebKit |
|
||||
|
||||
## Files read at startup (observed)
|
||||
|
||||
| File | Format | Purpose |
|
||||
|------|--------|---------|
|
||||
| `Data/initfs_Win32` | Frostbite pkg | Base asset manifest |
|
||||
| `Data/layout.toc` | Frostbite TOC | File layout index |
|
||||
| `Patch/initfs_Win32` | Frostbite pkg | Patch layer |
|
||||
| `Data/locale.ini` | INI | String localisation |
|
||||
| `Data/db_meta.xml` | XML | DB schema (loaded by FLE) |
|
||||
| `Data/id_map.json` | JSON | Player/team ID→name map |
|
||||
| `Data/char_conv.json` | JSON | Character conversion table |
|
||||
| `Documents/FIFA 23/fifasetup.ini` | INI | Display/audio settings |
|
||||
| `AppData/Local/Temp/FIFA 23/_replay0.bin` | binary | Replay buffer |
|
||||
| `anadius.cfg` | VDF | Fake EA persona config |
|
||||
| `AppData/Local/anadius/LSX emu/achievement-*.xml` | XML | Achievement state |
|
||||
|
||||
## Files written during a session (observed)
|
||||
|
||||
| File | When written | Content |
|
||||
|------|-------------|---------|
|
||||
| `Documents/FIFA 23/settings/Settings*` | Main menu reached | FBCHUNKS — controller/display prefs |
|
||||
| `Documents/FIFA 23/settings/ProfileOptions` | Profile load | FBCHUNKS — 1.5 MB profile blob |
|
||||
| `Documents/FIFA 23/filesystemcache/survey.state` | Startup | Empty state file |
|
||||
| `Documents/FIFA 23/filesystemcache/atlPlayTimeJson/playtime_*.json` | Ongoing | Playtime tracking |
|
||||
| `FIFA 23 Live Editor/config.json` | FLE ready | FLE settings (rewritten each session) |
|
||||
| `Logs/log_DD-MM-YYYY.txt` | Throughout | FLE debug log |
|
||||
|
||||
## Save file formats
|
||||
|
||||
### FBCHUNKS (Frostbite chunk container)
|
||||
- Magic: `46 42 43 48 55 4E 4B 53` (`FBCHUNKS`)
|
||||
- Byte 8: version (01 seen)
|
||||
- Offset 0x12: null-terminated label string (e.g. "Personal Settings 1", "Career - Player Progress 1")
|
||||
- Remainder: compressed/binary chunk data — no public spec; requires Frostbite tooling to fully parse
|
||||
- Tools: [Frosty Tool Suite](https://github.com/CadeEvs/FrostyToolSuite) can read/write these
|
||||
|
||||
### fifasetup.ini
|
||||
- Plain `KEY = VALUE` ini, fully human-readable
|
||||
- Safe to edit (display resolution, locale, vsync)
|
||||
|
||||
## Network calls at FUT entry (observed with iptables redirect)
|
||||
|
||||
Traffic pattern captured before changing strategy:
|
||||
- Multiple TLS connections to port 443 (destination: EA servers, resolved as various EA IPs)
|
||||
- TLS 1.3, AES-256-GCM (DirtySDK's copy of ProtoSSL, inline in FIFA23.exe)
|
||||
- No SNI sent (DirtySDK does not set `server_name` extension)
|
||||
- Connections originate from Wine/Proton network stack via Linux kernel TCP
|
||||
|
||||
Specific EA hostnames used (from openfut-bridge captures, not decoded from TLS):
|
||||
- `fut.ea.com` (FUT API)
|
||||
- `accounts.ea.com` (auth)
|
||||
- `gateway.ea.com` (entitlements)
|
||||
- `pin-river.data.ea.com` (telemetry)
|
||||
|
||||
## Key FLE Lua API hooks
|
||||
|
||||
FLE injects `FIFALiveEditor.DLL` and exposes a Lua engine that can:
|
||||
- Read any in-memory DB table via `GetDBTableRows(tableName)`
|
||||
- Write any cell via `EditDBTableField`
|
||||
- Query career mode state via `IsInCM()`
|
||||
- Get player/team names via `GetPlayerName`, `GetTeamName`
|
||||
|
||||
This is the primary safe integration path (see `fut-integration-options.md`).
|
||||
@@ -1,191 +0,0 @@
|
||||
# Foundational test — live custom XI via Freeze Lineup
|
||||
|
||||
**Status: PENDING — test has not yet been run.**
|
||||
|
||||
This is build-order step 1 from `docs/direction.md`: the test everything else
|
||||
in the direction pivot depends on.
|
||||
|
||||
## What changed since the first draft of this doc
|
||||
|
||||
The first version of this test guessed at a "selection bias" DB field and a
|
||||
candidate squad/lineup table name, based on general FIFA-modding precedent
|
||||
that turned out not to hold for FLE's documented API — no such field appears
|
||||
anywhere in FLE's actual Lua API docs or its own example scripts. While
|
||||
researching an unrelated hotkey issue, a **confirmed, FLE-documented**
|
||||
mechanism for forcing a starting XI turned up instead: the **Formation
|
||||
Editor's "Freeze Lineup" feature** (FLE wiki, `Formation-Editor.md`):
|
||||
|
||||
> This feature can be used in player career mode if you want to manage the
|
||||
> starting lineup of your team. Can be also used in manager career mode to
|
||||
> manually manage your next opponent's starting lineup.
|
||||
|
||||
Steps (GUI, no scripting): open Formation Editor for a team → arrange players
|
||||
on the pitch → tick **Freeze Lineup** → `Data → Save`.
|
||||
|
||||
This is real and documented, but it's GUI-only — there is no Lua function for
|
||||
it, and what DB write it actually performs under the hood is undocumented.
|
||||
This test is now two phases: confirm the GUI feature works at all, then
|
||||
reverse the DB write it makes so it can be replicated programmatically
|
||||
(required for the app→game bridge in build-order step 2, which needs this
|
||||
driven from outside the game, not from a person clicking checkboxes).
|
||||
|
||||
Also fixed in this pass: `EditDBTableField`'s real signature, confirmed from
|
||||
FLE's own docs and `lua/scripts/99ovr_99pot.lua`, is
|
||||
`EditDBTableField(cell)` where `cell` is `row["fieldname"]` with `.value`
|
||||
mutated in place — **not** `EditDBTableField(table, row_index, field, value)`
|
||||
as originally (incorrectly) written into the first draft of the injector
|
||||
script.
|
||||
|
||||
## What this test settles
|
||||
|
||||
Whether a *specific, externally-chosen* 11 players can be forced into a
|
||||
career (or Kick-Off) match's starting lineup, live, with no restart — and
|
||||
whether the mechanism that does it (Freeze Lineup's underlying DB write) can
|
||||
be driven by a script instead of a person clicking through the Formation
|
||||
Editor UI.
|
||||
|
||||
If Freeze Lineup itself doesn't actually hold under match start (the wiki
|
||||
doesn't show it being tested against a live match, only "you should be able
|
||||
to see... when you play against them"), the whole bridge architecture in
|
||||
`docs/direction.md` §3 needs rethinking — there is no other documented
|
||||
mechanism for forcing a lineup.
|
||||
|
||||
## Prerequisites
|
||||
|
||||
- FIFA 23 launched normally (FLE injected, EAAC neutralized — same baseline
|
||||
as `track-c-fut-table-test.md`)
|
||||
- A career save loaded (Freeze Lineup is documented for career mode
|
||||
specifically — confirm separately whether it does anything in Kick-Off,
|
||||
don't assume it does)
|
||||
- Note 11 player IDs from your club (`tools/squad-exporter/export_squad.lua`
|
||||
output, `playerid` field) that are NOT currently your starting XI
|
||||
|
||||
## Phase 1 — confirm Freeze Lineup actually holds into a match
|
||||
|
||||
This has zero scripting and should be done first since everything else is
|
||||
wasted effort if it fails.
|
||||
|
||||
1. Open the Live Editor overlay (F9, or `Windows → Settings` from the
|
||||
overlay's own menu bar if the hotkey isn't registering — see the umu/Wine
|
||||
hotkey note below).
|
||||
2. `Features → Teams` → find your team → `Edit`.
|
||||
3. `Team → Formation` to open the Formation Editor.
|
||||
4. Swap players around on the pitch so the XI differs from your current
|
||||
actual starting XI in some checkable way (e.g. swap two outfield players'
|
||||
positions, or bench/start a specific player).
|
||||
5. Tick **Freeze Lineup**.
|
||||
6. `Data → Save`.
|
||||
7. Hide Live Editor (F9), save your career **on a new slot** (don't overwrite
|
||||
your main save in case this corrupts something), exit to main menu, reload
|
||||
that save, and check the team's lineup screen / play a match and watch who
|
||||
starts.
|
||||
|
||||
**Record in the Results table below whether the frozen lineup actually took
|
||||
the pitch.** If not, stop here — Phase 2 is moot.
|
||||
|
||||
## Phase 2 — find the underlying DB write
|
||||
|
||||
Only proceed if Phase 1 confirmed Freeze Lineup works.
|
||||
|
||||
1. In FLE's Lua Engine, run `tools/squad-injector/snapshot_lineup_tables.lua`.
|
||||
This dumps every DB table whose name contains `squad`, `lineup`,
|
||||
`formation`, `tactic`, `teamsheet`, `selection`, `players`, or `teams` to
|
||||
`C:\FIFA 23 Live Editor\openfut_snapshot_<timestamp>.json`. Note this
|
||||
filename — this is your **before** snapshot.
|
||||
2. Without restarting or reloading, repeat the Formation Editor steps from
|
||||
Phase 1 (steps 2–6 only — open Formation Editor, change the lineup, tick
|
||||
Freeze Lineup, `Data → Save`). Don't save/reload the career between
|
||||
snapshot and this step — keep it to a single live session so the diff
|
||||
isn't polluted by other state changes.
|
||||
3. Run `snapshot_lineup_tables.lua` again. This is your **after** snapshot.
|
||||
4. Copy both JSON files out of the Wine prefix (same path pattern as
|
||||
`track-c-fut-table-test.md`: `~/Games/umu/.../drive_c/FIFA 23 Live
|
||||
Editor/`) and run:
|
||||
|
||||
```bash
|
||||
python3 tools/squad-injector/diff_snapshots.py before.json after.json
|
||||
```
|
||||
|
||||
5. The output shows exactly which table(s) and field(s) changed. This is the
|
||||
real, confirmed write Freeze Lineup performs — record it in the Results
|
||||
table below.
|
||||
|
||||
## Phase 3 — replicate the write via script
|
||||
|
||||
1. Open `tools/squad-injector/apply_lineup_write.lua` and fill in
|
||||
`TARGET_TABLE` and `TARGET_FIELDS` using Phase 2's diff output.
|
||||
2. Edit `C:\FIFA 23 Live Editor\openfut_test_xi.json`:
|
||||
|
||||
```json
|
||||
{
|
||||
"team_id": 12345,
|
||||
"xi": [
|
||||
{ "player_id": 111111, "position": 0 },
|
||||
{ "player_id": 222222, "position": 5 }
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
Use 11 entries. Position codes are **confirmed numeric 0–27**
|
||||
(`GK=0, SW=1, RWB=2, RB=3, RCB=4, CB=5, LCB=6, LB=7, LWB=8, RDM=9, CDM=10,
|
||||
LDM=11, RM=12, RCM=13, CM=14, LCM=15, LM=16, RAM=17, CAM=18, LAM=19,
|
||||
RF=20, CF=21, LF=22, RW=23, RS=24, ST=25, LS=26, LW=27`) — from
|
||||
`lua/scripts/export_season_stats.lua`'s `get_pos_name` table in FLE's own
|
||||
repo, not a guess.
|
||||
3. Run `apply_lineup_write.lua` from FLE's Lua Engine.
|
||||
4. Repeat the save-to-new-slot / reload / check-lineup verification from
|
||||
Phase 1, but this time without ever opening the Formation Editor — the
|
||||
write was made entirely from the script.
|
||||
|
||||
## Classification criteria
|
||||
|
||||
### "Confirmed — full mechanism works"
|
||||
|
||||
Phase 1 holds, Phase 2 finds a clean diff, Phase 3's scripted write produces
|
||||
the same in-match result as the manual GUI path.
|
||||
|
||||
**Verdict:** Build-order step 1 done. Proceed to step 2 (bridge transport) in
|
||||
`docs/direction.md`.
|
||||
|
||||
### "GUI works, script doesn't"
|
||||
|
||||
Phase 1 holds but Phase 3's replicated write doesn't stick, even though the
|
||||
diffed fields matched what changed in Phase 2.
|
||||
|
||||
**Verdict:** Freeze Lineup likely does more than a single DB field write
|
||||
(e.g. an internal engine call beyond `EditDBTableField`'s reach, or a second
|
||||
write the diff missed because it happened in a table outside the `KEYWORDS`
|
||||
filter in `snapshot_lineup_tables.lua` — widen the filter and redo Phase 2).
|
||||
|
||||
### "Freeze Lineup doesn't hold at all"
|
||||
|
||||
Phase 1 fails — the lineup reverts to the game's own AI-picked XI regardless.
|
||||
|
||||
**Verdict:** No confirmed mechanism exists for forcing a lineup. This kills
|
||||
the bridge architecture as designed in `direction.md` §3 and needs a return
|
||||
to first principles — there is no fallback documented anywhere in FLE's wiki
|
||||
for this specific case.
|
||||
|
||||
## A note on the umu/Wine F9/F11 hotkey issue
|
||||
|
||||
If FLE's F9 (hide/show) hotkey isn't registering under umu, this is plausibly
|
||||
a Wine keyboard-hook limitation (FLE's global hotkey detection likely uses a
|
||||
low-level hook that doesn't translate cleanly through Wine's input layer) —
|
||||
not something documented anywhere in FLE's own troubleshooting docs, which
|
||||
don't mention Linux/Wine at all. F11 specifically has **no documented FLE
|
||||
function** — F9 is the only documented toggle. Workaround: click directly
|
||||
into the FLE overlay window (it should still be visible/clickable even if the
|
||||
hotkey doesn't fire) and use its own menu bar instead of relying on the
|
||||
hotkey.
|
||||
|
||||
## Results
|
||||
|
||||
*(To be filled in after the test is run.)*
|
||||
|
||||
| Field | Value |
|
||||
|---|---|
|
||||
| Date run | — |
|
||||
| Phase 1: Freeze Lineup holds into a match? | — |
|
||||
| Phase 2: table(s)/field(s) changed | — |
|
||||
| Phase 3: scripted write reproduces Phase 1 result? | — |
|
||||
| **Classification** | **PENDING** |
|
||||
@@ -1,136 +0,0 @@
|
||||
# FUT Integration Options
|
||||
|
||||
How to connect FIFA 23 to the OpenFUT local simulator, ranked by safety and feasibility.
|
||||
|
||||
## Option A — FLE Lua scripting (RECOMMENDED)
|
||||
|
||||
**What it does:** Use FIFA Live Editor's in-memory Lua API to read and write the game's
|
||||
database tables at runtime. FLE is already injected; no additional hooking needed.
|
||||
|
||||
**Why it's the right path:**
|
||||
- Fully offline, no EA servers touched
|
||||
- FLE is already trusted by the user (it's the launch mechanism)
|
||||
- `GetDBTableRows` / `EditDBTableField` expose the full Frostbite DB in memory
|
||||
- Scripts run inside the game process; no IPC complexity
|
||||
- Same mechanism used by modders for career mode edits today
|
||||
|
||||
**Integration design:**
|
||||
|
||||
```
|
||||
openfut-core (SQLite)
|
||||
│
|
||||
│ HTTP REST (localhost)
|
||||
▼
|
||||
openfut-bridge (port 8080, plain HTTP, no TLS)
|
||||
│ pulls club/squad/player data as JSON
|
||||
▼
|
||||
FLE Lua bridge script
|
||||
│ calls GetDBTableRows, EditDBTableField
|
||||
▼
|
||||
FIFA 23 in-memory DB (Frostbite)
|
||||
```
|
||||
|
||||
The Lua script polls openfut-core's REST API at intervals (or on FUT menu entry)
|
||||
and writes simulator data (coins, items, squad) into the appropriate DB tables.
|
||||
|
||||
**Tables likely involved (to verify with export_squad.lua):**
|
||||
|
||||
| Table | Expected FUT content |
|
||||
|-------|---------------------|
|
||||
| `players` | Player attributes (OVR, potential, stats) |
|
||||
| `teams` | Club identity, stadium, colors |
|
||||
| `fut_clubs` | FUT club record (if in memory when FUT loads) |
|
||||
| `fut_items` | Card inventory (if in memory) |
|
||||
| `fut_squads` | Active squad (if in memory) |
|
||||
|
||||
**Steps to implement:**
|
||||
1. Run `tools/squad-exporter/export_squad.lua` from FLE Lua Engine while in FUT to discover which tables are live
|
||||
2. Map openfut-core's data model to the discovered table fields
|
||||
3. Write a Lua polling script that fetches `/api/v1/club`, `/api/v1/squad`, etc. from openfut-core and calls `EditDBTableField` to populate them
|
||||
4. Optionally add a small HTTP client to the Lua script using LuaSocket (FLE ships with Lua 5.4)
|
||||
|
||||
**Limitations:**
|
||||
- Changes are in-memory only; they reset on game restart (acceptable for a simulator)
|
||||
- Only works while FLE is running (always true in our setup)
|
||||
- FUT tables may only be populated when the FUT hub is loaded; test with the exporter
|
||||
|
||||
---
|
||||
|
||||
## Option B — Local save file injection (career mode proxy)
|
||||
|
||||
**What it does:** Generate or modify offline career mode save files that contain FUT-like
|
||||
squad/player data, using Frostbite's FBCHUNKS format.
|
||||
|
||||
**Feasibility:** Medium
|
||||
- FBCHUNKS format is not publicly documented but has been partially reverse-engineered by the Frosty Tool Suite project
|
||||
- Career saves are 16 MB — large and complex
|
||||
- Changes take effect only after a game restart
|
||||
|
||||
**Best use:** Pre-populating a career club with the same players as the FUT simulator squad, so offline Squad Battles use "your" players.
|
||||
|
||||
**Steps:**
|
||||
1. Use Frosty Tool Suite to open a career save and map the schema
|
||||
2. Build a Python exporter that writes a valid FBCHUNKS save with simulator squad data
|
||||
3. Test: replace the career save, launch FIFA, verify squad is correct
|
||||
|
||||
---
|
||||
|
||||
## Option C — Local companion web UI
|
||||
|
||||
**What it does:** The user manages their FUT simulator entirely in a web browser (openfut-core already has this). A button exports the current squad/club state to a format that a Lua script or file injector can consume.
|
||||
|
||||
**This is already implemented** — openfut-core serves the FUT simulator REST API. The missing piece is the Lua bridge script (Option A) that reads from it.
|
||||
|
||||
---
|
||||
|
||||
## Option D — Local proxy for non-secured local calls only
|
||||
|
||||
**What it does:** Intercept FIFA 23's calls to `localhost:*` or a known local endpoint (not EA servers) and respond with simulator data.
|
||||
|
||||
**Feasibility:** Low value in isolation
|
||||
- FIFA 23 does not make calls to localhost in normal operation (except EA App on port 10853)
|
||||
- All FUT API calls go to EA's servers over TLS
|
||||
- Intercepting those would require the approach we explicitly ruled out
|
||||
|
||||
**Not recommended as a primary path.** Could be combined with Option A if the Lua script exposes a local socket that a coordinator process writes to.
|
||||
|
||||
---
|
||||
|
||||
## Option E — Memory bridge (Cheat Engine / FLE offsets)
|
||||
|
||||
**What it does:** Use known memory offsets (FLE's `offset_cache.json`) to read/write FUT state directly in FIFA23.exe's heap.
|
||||
|
||||
**Feasibility:** Medium — FLE already does this for career mode
|
||||
- FLE's `offset_cache.json` contains addresses for many game structures
|
||||
- FUT in-memory structs are separate from career structs and may not be mapped yet
|
||||
- This is fragile (offsets change with game updates)
|
||||
|
||||
**Not recommended** unless Options A and B both fail — too brittle.
|
||||
|
||||
---
|
||||
|
||||
## Recommendation
|
||||
|
||||
**Start with Option A (FLE Lua scripting).**
|
||||
|
||||
1. Run `tools/squad-exporter/export_squad.lua` in-game to discover which DB tables exist in FUT mode
|
||||
2. Use `tools/file-watch-diff/watch.sh` to snapshot file state entering FUT and identify any new local files
|
||||
3. Use `tools/network-metadata-logger/netlog.sh` to log which EA hosts FIFA contacts at FUT entry (metadata only, no decryption)
|
||||
4. Map findings back to openfut-core's data model
|
||||
5. Implement the Lua bridge script that calls openfut-core's REST API and writes to discovered tables
|
||||
|
||||
If FUT tables are not exposed by FLE's DB API (they may not be — FUT data lives server-side in online mode), fall back to **Option B** (career save injection) to provide a squad that mirrors the simulator's club.
|
||||
|
||||
---
|
||||
|
||||
## Safety boundary
|
||||
|
||||
The following are out of scope and must not be implemented:
|
||||
|
||||
- Decrypting or inspecting EA's TLS traffic
|
||||
- Spoofing EA domain names or impersonating EA servers
|
||||
- Sending modified clients to EA's production services
|
||||
- Bypassing EA App login or account verification
|
||||
- Anything that could constitute online cheating or violate EA's ToS for online play
|
||||
|
||||
All integration must remain local/offline/single-player.
|
||||
@@ -1,208 +0,0 @@
|
||||
# OpenFUT Status Review
|
||||
*Generated 2026-06-30 — read-only stocktake, no code changed.*
|
||||
|
||||
---
|
||||
|
||||
## Executive Summary
|
||||
|
||||
OpenFUT has a mature offline FUT economy backend (Core, 25 phases, fully functional in
|
||||
isolation) and a sophisticated hook DLL that loads into FIFA 23, redirects EA hostnames
|
||||
to loopback, and bypasses TLS certificate verification. The Blaze/ProtoSSL layer is
|
||||
structurally ready: framing code exists, a TLS listener runs, cert-verify is patched.
|
||||
However the project is currently blocked before any Blaze traffic is ever seen.
|
||||
The fundamental problem is that FIFA 23 submits `GoOnline` to EbisuSDK and then
|
||||
**waits for an asynchronous ONLINE_STATUS_EVENT push** from the EA-app LSX server —
|
||||
a push that current code never sends. Every approach tried so far (flipping poll
|
||||
return values, forcing the state flags, read-only probes) confirms the gate is
|
||||
event-driven, not poll-driven. The Blaze captures directory contains six empty files.
|
||||
No Fire2 frame from FIFA 23 has ever been decoded. Until the ONLINE_STATUS_EVENT push
|
||||
is synthesized and delivered correctly, Milestones 2–7 are all waiting on the same
|
||||
single wall.
|
||||
|
||||
---
|
||||
|
||||
## 1. Proven vs Assumed
|
||||
|
||||
| Claim | Status | Evidence |
|
||||
|---|---|---|
|
||||
| FIFA 23 uses DirtySDK / ProtoSSL | **Proven** | String scan hit `ProtoSSLSend`, `ProtoSSLRecv`, `gosredirector` in FIFA23.exe memory (Task 1) |
|
||||
| `version.dll` loads and runs hook code | **Proven** | `hook.log` written at DLL_PROCESS_ATTACH |
|
||||
| `getaddrinfo` IAT hook redirects EA domains to loopback | **Proven** | Hook log records every EA `getaddrinfo` call; connect_hook log confirms port redirects |
|
||||
| ProtoSSL cert-verify prologue found and patched (FIFA23.exe) | **Proven** | ssl_patch.rs prologue confirmed at file offset 0xf0c850; hook log "ssl: main exe cert-verify patched" |
|
||||
| ProtoSSL cert-verify patched in EAWebKit.dll | **Proven** (if loaded) | Lazy patch fires on first EA getaddrinfo call; hook log message confirms |
|
||||
| Gate is upstream of DirtySDK — no DNS/connect fires on FUT entry | **Proven** | getaddrinfo, connect, WSASend/Recv hooks all show zero external traffic during "connecting to EA Servers" |
|
||||
| `GoOnline` is called by the game | **Proven** | Read-only detour on `anadius64.dll+0x2BB90` confirmed hit |
|
||||
| anadius returns GoOnline success | **Proven** | Handler observed returning successfully; game still retries every ~7 s |
|
||||
| Gate is downstream of GoOnline | **Proven** | GoOnline called + returns success; no Blaze connect follows |
|
||||
| Connection-state function: `GetInternetConnectedState @ anadius64.dll+0x27790` | **Proven** | Located via anadius LSX command-registration table; two-flag branch decoded (`+0xCAB1A`, `+0xCAB1B`) |
|
||||
| Gate is event-driven (game waits for async push, not a poll return) | **Proven** | Forced both state flags AND GoOnline return to "1"; game kept retrying; worker-thread stack scan confirms handler runs on anadius IOCP thread, not FIFA's thread |
|
||||
| GoOnline runs on anadius worker thread, not FIFA's call thread | **Proven** | Stack scan from inside detour found zero FIFA23.exe frames, sp ~2.4 KB from thread stack top |
|
||||
| `protossl-scan` live toolkit is exhausted for finding GoOnline in FIFA23.exe | **Proven** | No `"GoOnline"` string in image; worker-thread call stack has no FIFA frames; jmpscan yields ~3875 hits (overwhelmingly data false positives) |
|
||||
| FIFA 23 redirector config references `Authorization:` header (Nucleus token) | **Proven** | Found in FIFA23.exe .rdata pointer table @ `+0x83FC858` |
|
||||
| openfut-core REST API complete and tested | **Proven** | 25 phases, 15 migrations, passing integration tests |
|
||||
| Bridge LSX server starts and handles request-response | **Proven** (code) | `openfut-bridge/src/lsx.rs` + `main.rs` — server starts on 127.0.0.1:3216 |
|
||||
| Bridge LSX server ACTUALLY receives FIFA's LSX connections | **UNCONFIRMED** | anadius may intercept the same calls in-process before the TCP connection reaches the bridge |
|
||||
| Bridge LSX server `GetInternetConnectedState → connected="1"` unblocks the gate | **UNCONFIRMED (known to fail in-process)** | Flipping the value via anadius in-process failed; bridge path not yet confirmed working |
|
||||
| ONLINE_STATUS_EVENT push XML format | **UNKNOWN** | No capture; format not derived |
|
||||
| Fire2 framing is correct for FIFA 23 | **UNCONFIRMED** | Implemented based on post-2012 EA convention; all blaze captures are empty (0 bytes) |
|
||||
| Blaze component / command IDs for FIFA 23 | **UNKNOWN** | Zero captures; dispatch table entirely empty placeholders |
|
||||
| ProtoSSL recv-injection convention (non-blocking return values etc.) | **UNCONFIRMED** | Never reached M4; recv_hook module removed from active install path |
|
||||
| FUT REST endpoint paths in mapper.rs | **SPECULATIVE** | Based on community knowledge of older FIFA titles; the one actual capture in `captures/` is an early GET from before the Blaze strategy |
|
||||
| FLE Lua API exposes FUT DB tables in memory | **UNKNOWN** | `export_squad.lua` has never been run; FUT data may only exist server-side in online mode |
|
||||
|
||||
---
|
||||
|
||||
## 2. Milestone Status
|
||||
|
||||
| Milestone | Status | Blocker | Depends on unconfirmed assumption? |
|
||||
|---|---|---|---|
|
||||
| **M1** — Locate connection-state decision point | ✅ Done | — | No |
|
||||
| **M2** — Flip gate, force "connected" | ⛔ Blocked | Game waits for async ONLINE_STATUS_EVENT push; no current code sends it | Yes — unknown event XML format |
|
||||
| **M3** — First ProtoSSL plaintext on Blaze connection | 🔲 Not started | Depends on M2 | Yes — Fire2 framing unconfirmed |
|
||||
| **M4** — Answer redirector + decode first Fire2 frame | 🔲 Not started | Hard wall: Fire2 framing, recv-injection convention, component/command IDs all unconfirmed | Yes — all three unknown |
|
||||
| **M5** — Blaze preauth / login / postauth | 🔲 Not started | Depends on M4 | Yes — Blaze auth TDF body layout unknown |
|
||||
| **M6** — FUT entry + hub load | 🔲 Not started | Depends on M5; also requires FUT REST response shapes confirmed | Yes — endpoint paths speculative |
|
||||
| **M7** — Squad Battles (AI FUT) | 🔲 Not started | Depends on M6 | Yes |
|
||||
|
||||
**Note on roadmap.md wording:** Under M2–M4, roadmap.md uses `**Done (observable):**` bullets. These describe the *success criterion* for each milestone, not an achieved state. The authoritative status is in `connection-gate-findings.md` (M2 attempts failed; M3/M4 never started). The roadmap has not been updated to reflect M2 failure.
|
||||
|
||||
### M4 is the first hard wall in detail
|
||||
|
||||
Even assuming M2 is solved, M4 requires three unconfirmed things simultaneously:
|
||||
1. **Fire2 framing** — the 12-byte header layout is assumed; if FIFA 23 uses an older Fire variant or a custom delta, the codec will misparse every packet.
|
||||
2. **ProtoSSL recv-injection** — delivering responses to the game via recv hook requires knowing what return values and buffer conventions ProtoSSL expects; recv_hook.rs exists but is not installed.
|
||||
3. **Blaze component/command IDs** — the dispatch table is entirely empty; we cannot answer any request until IDs are known from captures.
|
||||
|
||||
All three are resolved by getting one real captured frame. M4 is primarily a capture problem, not a decoding problem — once bytes exist, the framing and IDs are immediately readable.
|
||||
|
||||
---
|
||||
|
||||
## 3. Blockers, Risks, Unknowns
|
||||
|
||||
### Blockers (stop progress now)
|
||||
|
||||
1. **ONLINE_STATUS_EVENT push not synthesized** *(M2 wall)*
|
||||
The game calls GoOnline, gets success, then waits indefinitely for a push event on the LSX socket that never arrives. This is the single gate blocking all Blaze work. Options: (a) trace the event format via Ghidra on FIFA23.exe (xref `ONLINE_STATUS_EVENT` string + the game's EbisuSDK listener), (b) RE anadius's LSX event-send path (find what it would push in an "online" scenario), (c) brute-force push candidate event XMLs and observe whether the game advances.
|
||||
|
||||
2. **Bridge LSX server delivery unconfirmed** *(architectural risk converted to blocker)*
|
||||
The hook passes port 3216 connections through, assuming the bridge LSX server on the Linux host receives them. If anadius's in-process hooks intercept the winsock calls before they reach the TCP stack, the bridge server is never reached. This must be confirmed by checking `openfut_hook.log` for a getaddrinfo on the LSX host, or by observing the bridge server's accept logs.
|
||||
|
||||
### Risks (could derail later)
|
||||
|
||||
3. **Fire2 framing wrong** *(M4 risk)*
|
||||
If FIFA 23 uses Fire (pre-2012) or a modified frame layout, the codec misparses. Mitigation: the server has a `Raw` fallback mode for capturing raw bytes when framing fails.
|
||||
|
||||
4. **Secondary auth-token gate** *(M5 risk)*
|
||||
`connection-gate-findings.md` noted the redirector request carries an `Authorization:` header. M1's final conclusion said `GetAuthCode` returns a fake token that appears accepted — but this was inferred, not confirmed by seeing the redirector request actually constructed with that token.
|
||||
|
||||
5. **EAAC not fully neutralized** *(persistent risk)*
|
||||
`FakeEAACLauncher` bypasses the anticheat launcher. The hook DLL is unsigned. If EAAC is ever active (e.g., after a game update re-enables it), all hooks fail silently. Marked as "not active in offline/cracked builds" — assumed, not confirmed on every launch.
|
||||
|
||||
6. **FUT REST response shapes wrong** *(M6 risk)*
|
||||
The 61 endpoint mappings in mapper.rs and the shaper stubs in shaper.rs are based on community guesses about older FIFA FUT APIs, not FIFA 23 captures. Response JSON shapes may differ enough to cause the client to fail silently or crash.
|
||||
|
||||
### Unknowns (open questions)
|
||||
|
||||
7. **ONLINE_STATUS_EVENT XML format** — exact tag names, field order, sender attribute, and any nonces/tokens required.
|
||||
8. **GoOnline event sequence** — whether ONLINE_STATUS_EVENT alone is sufficient or a sequence of events (e.g., PROFILE_EVENT, LOGIN_EVENT, COMMERCE_EVENT) is expected.
|
||||
9. **Whether FLE exposes FUT DB tables** — FUT card inventory and squad data likely live server-side in online mode; FLE may not surface them for in-process editing.
|
||||
10. **Blaze component/command IDs for FIFA 23** — entirely unknown; no captures.
|
||||
11. **openfut_hook.log current content** — we have the code but no log output in any document. Whether the current hook (with connect, ssl_patch, tls_bypass, WSAIoctl, origin_spy all installed) fires correctly and what it observes is unverified in this review.
|
||||
|
||||
---
|
||||
|
||||
## 4. Track Comparison
|
||||
|
||||
### Track A — Full EA-backend fake (M1–M7, playable FUT vs AI)
|
||||
|
||||
**What it delivers:** The FIFA 23 FUT hub loads from OpenFUT Core; Squad Battles matches play and reward economy items.
|
||||
|
||||
**Effort:** Research-grade. Minimum path: synthesize ONLINE_STATUS_EVENT (unknown format, 1–2 weeks of RE), then capture Fire2 frames (days once M2 is solved), then implement Blaze auth handlers (weeks), then implement FUT entry (weeks), then Squad Battles (weeks). Realistic minimum: 3–6 months of expert RE work.
|
||||
|
||||
**Proven support:** Hook loads and redirects correctly. TLS bypass patched. Core economy backend complete. Blaze framing code and TLS listener exist.
|
||||
|
||||
**Assumed:** Fire2 framing correct; component/command IDs discoverable from captures; FUT REST shapes close enough to community guesses; no additional undiscovered gates.
|
||||
|
||||
**Evidence for:** Architecture is coherent. The M1 finding (gate precisely named and decoded) was achieved cleanly. The in-process hook approach is validated.
|
||||
|
||||
**Evidence against:** M2 was attempted and failed with the in-process approach. The event-driven architecture adds a full EbisuSDK emulation layer before even one Blaze byte is seen. The live toolkit is exhausted (Path A verdict); Ghidra-level work on a 505 MB binary is required. Six capture files with zero bytes.
|
||||
|
||||
---
|
||||
|
||||
### Track B — Clean-room spec deliverable (M1–M5 documented)
|
||||
|
||||
**What it delivers:** A documented map of the connection gate, LSX event sequence, Blaze auth surface (transport, framing, gate conditions, component IDs, TDF schemas). Valuable as an archival/community artifact even if Track A stalls.
|
||||
|
||||
**Effort:** Medium. M1 is done. M2–M5 documentation emerges as a by-product of engineering work. The spec itself (writing) is lightweight; the engineering to produce the captures is the cost.
|
||||
|
||||
**Proven support:** M1 complete and documented. connection-gate-findings.md is already a high-quality spec artifact.
|
||||
|
||||
**Assumed:** Same as Track A for the unconfirmed values, but the spec can mark them `TODO/CONFIRM` rather than needing to implement them.
|
||||
|
||||
**Evidence for:** The clean-room constraint means a spec is the only artifact that can be safely published. connection-gate-findings.md shows this approach produces real value. B finishes even if A is never fully playable.
|
||||
|
||||
**Evidence against:** Track B alone doesn't produce a playable FUT; it is a foundation, not an end-user product.
|
||||
|
||||
---
|
||||
|
||||
### Track C — FLE Lua bridge (local-match path, skip the backend gate)
|
||||
|
||||
**What it delivers:** FIFA 23 career mode or Kick-Off with an OpenFUT club's players and squad loaded via FLE's in-memory DB API. No online gate, no Blaze, no TLS. Fully offline from day one.
|
||||
|
||||
**Effort:** Low-to-medium. FLE is already loaded in the normal launch path. Tools exist (`tools/squad-exporter/`, `tools/profile-exporter/`). Primary unknown is whether FUT-relevant DB tables are accessible.
|
||||
|
||||
**Proven support:** FLE Lua API exposes `GetDBTableRows` / `EditDBTableField` for career mode. `fifa23-startup-flow.md` confirms FLE injects at load. `fut-integration-options.md` documents the integration path in detail and rates this as the recommended option.
|
||||
|
||||
**Assumed:** FUT card/club/squad data has in-memory DB table representations that FLE can write. If FUT data is purely server-side (loaded from EA servers, not from the Frostbite DB layer), Track C produces no FUT simulation at all — only career mode player stats.
|
||||
|
||||
**Evidence for:** Career mode already works with FLE edits (community precedent). Tools are present and designed for this path. No infrastructure work needed.
|
||||
|
||||
**Evidence against:** FUT in FIFA 23 uses server-side data. The cards in a player's FUT club, the coins, the squad — these are fetched from `fut.ea.com` REST APIs, not from the Frostbite embedded DB. FLE's `GetDBTableRows` likely exposes base player stats tables but not FUT item tables. The crucial test (run `export_squad.lua` while in FUT mode) has never been done.
|
||||
|
||||
---
|
||||
|
||||
### Recommendation
|
||||
|
||||
**Start Track C immediately as a parallel, low-cost validation.**
|
||||
|
||||
Run `export_squad.lua` in FLE while inside the FUT hub (or attempting to enter it). If FUT tables appear in the export, Track C is viable and is the fastest path to something a user can interact with. This test takes one session and costs nothing.
|
||||
|
||||
Simultaneously, **continue Track A/B with the next concrete RE step:** synthesize the ONLINE_STATUS_EVENT push. The most actionable option is to run `origin_spy` logs from the current hook to see what LSX events fire during a session, then attempt to push candidate event XMLs via the bridge LSX server and watch whether the game advances. This is bounded, testable work that either unblocks M2 or produces the spec value for Track B.
|
||||
|
||||
**Do not abandon Track A/B for Track C** — they are complementary. Core is already built; the bridge is mostly built. The gap is purely the RE wall at M2.
|
||||
|
||||
---
|
||||
|
||||
## 5. Architecture and Provenance Sanity-Check
|
||||
|
||||
### Hook + Brain coherence
|
||||
|
||||
The CLAUDE.md bridge architecture diagram (hook intercepts ProtoSSL → plain localhost TCP → blaze_brain → Core) remains coherent. The M1/M2 findings revealed one additional layer (EbisuSDK LSX event) that must precede the Blaze connection. The bridge has been updated to handle LSX directly. The overall design is sound; the M2 blocker is an implementation gap (event synthesis), not an architectural flaw.
|
||||
|
||||
**One inconsistency to flag:** The hook's `lsx.rs` contains a complete in-process LSX emulator (AES-128-ECB, CRandom, all response builders), but the recv/send hooks that activate it are explicitly removed (`lib.rs`: "recv/send hooks removed — LSX is now handled by the native openfut-bridge LSX server"). This is dead code. The bridge's LSX server is the current path. The in-process lsx.rs should either be deleted or documented as a fallback; its presence is confusing.
|
||||
|
||||
### Clean-room status
|
||||
|
||||
No evidence of EA leaked source anywhere in the tree. All RE work is derived from:
|
||||
- Running the shipping binary and observing behavior (function return values, network traffic patterns)
|
||||
- Memory scanning of the live process (string search, xref, disasm of observed addresses)
|
||||
- Reading anadius's own compiled output (its exported symbols, its LSX XML format — which is anadius's own implementation, not EA's)
|
||||
- Community FUT API knowledge (mapper.rs endpoint paths — plausible but speculative)
|
||||
|
||||
The Blaze framing in `fifa-blaze/crates/blaze-proto/src/frame.rs` cites "Fire2 used by ME3, BF3, and most post-2012 titles" — this is sourced from public community documentation of those older titles, not from any leaked EA source. **Clean-room intact.**
|
||||
|
||||
The `AES_KEY` in the hook's lsx.rs (`[0,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15]`) is a placeholder key used for the LSX session encryption. The real session key is derived from the challenge seed via CRandom — this algorithm was RE'd from anadius's own binary. No EA source required.
|
||||
|
||||
---
|
||||
|
||||
## 6. If You Read Only This
|
||||
|
||||
- **The project is blocked at M2.** FIFA 23 submits `GoOnline`, gets success, then waits for an async `ONLINE_STATUS_EVENT` push on the LSX socket that no current code ever sends. All six Blaze capture files are empty (0 bytes). No Fire2 frame has ever been decoded.
|
||||
|
||||
- **M1 is the only completed milestone.** The gate function (`GetInternetConnectedState @ anadius64.dll+0x27790`) is precisely named and its two-flag branch decoded. Everything after M1 is either blocked or not started.
|
||||
|
||||
- **The next concrete action** is synthesizing the ONLINE_STATUS_EVENT push XML and testing whether the bridge's LSX server can deliver it to the game. This is the single thing that unblocks all Blaze work.
|
||||
|
||||
- **Track C (FLE Lua) is untested but cheap to validate.** Run `export_squad.lua` while in FUT to find out if FUT DB tables are accessible. If yes, it is the fastest path to user-visible results. If no, it is ruled out with one session.
|
||||
|
||||
- **openfut-core is complete and ready** — 25 phases, 15 migrations, full economy REST API, passing tests. It is not blocking anything; it is waiting for the bridge to connect to it.
|
||||
@@ -1,93 +0,0 @@
|
||||
# Track C — FUT DB table viability test
|
||||
|
||||
**Status: PENDING — test has not yet been run.**
|
||||
|
||||
## What this test settles
|
||||
|
||||
Track C ("FLE Lua bridge") would inject OpenFUT club data directly into FIFA 23's
|
||||
in-memory Frostbite DB tables at runtime, bypassing the entire backend/Blaze stack.
|
||||
It is only viable for FUT (not just career mode) if FUT-specific tables — card
|
||||
inventory, squad composition with FUT fields, coins — are accessible in memory when
|
||||
the game is in the FUT area.
|
||||
|
||||
FUT data in online mode is fetched server-side from `fut.ea.com`. It is not known
|
||||
whether FIFA 23 mirrors any of this into the Frostbite in-memory DB that FLE
|
||||
can read/write. This test settles that question directly.
|
||||
|
||||
## Test procedure
|
||||
|
||||
**Prerequisites:**
|
||||
- FIFA 23 launched normally via umu-run/Steam
|
||||
- FLE (FIFA Live Editor) injected and active (normal launch path)
|
||||
- EAAC in offline/neutralized state
|
||||
- Game navigated as deep into FUT as possible (FUT hub if reachable; otherwise the
|
||||
furthest FUT screen before the gate blocks it)
|
||||
|
||||
**Run the exporter:**
|
||||
1. In FLE's Lua Engine, open and run `tools/squad-exporter/export_squad.lua`
|
||||
(full path on the Windows side: `C:\<game>\openfut_squad_export.json`)
|
||||
2. Wait for the MessageBox "Done! N players, M teams." or "ERROR writing..."
|
||||
3. Retrieve the output file from the Wine prefix:
|
||||
`~/Games/umu/fifa23-tools/drive_c/FIFA 23 Live Editor/openfut_squad_export.json`
|
||||
(or wherever `C:\FIFA 23 Live Editor\` maps in the active prefix)
|
||||
|
||||
**What to inspect in the output:**
|
||||
- `all_db_tables` array — the complete list of table names visible to FLE right now
|
||||
- `fut_tables` object — any table whose name contains `fut`, `club`, `pack`, `item`, or
|
||||
`market` (the script auto-extracts these)
|
||||
- `is_career_mode` — confirms whether FUT or career mode was active
|
||||
|
||||
## Classification criteria
|
||||
|
||||
### "FUT tables present"
|
||||
|
||||
`fut_tables` is non-empty AND contains FUT-specific fields beyond base player stats:
|
||||
- e.g., `fut_items` with card-type / rating / chemistry fields
|
||||
- e.g., a squad table with FUT formation / chemistry / loan-flag fields
|
||||
- e.g., a coins or points balance field
|
||||
|
||||
**Verdict:** Track C is viable for FUT. Fastest path to user-visible results.
|
||||
|
||||
### "only base player tables"
|
||||
|
||||
`fut_tables` is empty (no `fut_*` / `club_*` / `item_*` / `market_*` table names found
|
||||
in `all_db_tables`), OR those tables exist but contain only base player attributes
|
||||
(OVR, potential, position, pace, …) — the same fields visible in career mode.
|
||||
|
||||
**Verdict:** Track C cannot produce FUT. It could at most provide a custom Kick-Off or
|
||||
career-mode match with players sourced from OpenFUT Core. FUT items and coins exist
|
||||
only on EA's servers (not in the in-memory DB in offline mode).
|
||||
|
||||
### "FUT area unreachable to test"
|
||||
|
||||
The connection gate blocked entering FUT deeply enough for FUT tables to be populated.
|
||||
Record which tables were visible and at what screen the test was run.
|
||||
|
||||
**Verdict:** Retest after M2 is unblocked, OR test with `TLS_ENABLED=false` bridge
|
||||
handling the entry check stub.
|
||||
|
||||
## Results
|
||||
|
||||
*(To be filled in after the test is run.)*
|
||||
|
||||
| Field | Value |
|
||||
|---|---|
|
||||
| Date run | — |
|
||||
| FIFA screen at test time | — |
|
||||
| `is_career_mode` | — |
|
||||
| Total tables in `all_db_tables` | — |
|
||||
| FUT-specific table names found | — |
|
||||
| Key FUT fields present | — |
|
||||
| **Classification** | **PENDING** |
|
||||
|
||||
## Honest prior
|
||||
|
||||
`fut-integration-options.md` rates this as the recommended path and lists `fut_clubs`,
|
||||
`fut_items`, `fut_squads` as "expected" tables. However those expectations are based on
|
||||
analogy with career mode (which does store club/squad in the DB). FUT's data model is
|
||||
architecturally different — it is account-bound server-side. The expectation may be
|
||||
wrong. This test is the oracle.
|
||||
|
||||
The `export_squad.lua` script checks `GetDBTablesNames()` exhaustively (not just
|
||||
assumed names), so it will surface any FUT tables that actually exist, regardless of
|
||||
what name they use.
|
||||
+1
-1
Submodule fifa-blaze updated: d2a9a01ec9...f4f33969f2
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,934 @@
|
||||
k|J|
|
||||
tz^WU
|
||||
Gb\X[
|
||||
,j|L
|
||||
cXXXX
|
||||
gzW[rp
|
||||
)l``b`
|
||||
c^^^^
|
||||
zrbnz
|
||||
r--)
|
||||
&jzzx
|
||||
Jl```
|
||||
c^^^\
|
||||
----
|
||||
k|X\^_
|
||||
c\Xxx
|
||||
K|bjk
|
||||
cxxxx
|
||||
---%
|
||||
{xx|
|
||||
cxxxz
|
||||
Frxz
|
||||
{VVVW
|
||||
cpxz~
|
||||
gr*:
|
||||
sTVUU
|
||||
cxz^W
|
||||
[5555
|
||||
px~M
|
||||
cUUU5
|
||||
cUU-
|
||||
gz((+
|
||||
&rX`
|
||||
&kVX
|
||||
cUUUx
|
||||
&r^\
|
||||
%%%%
|
||||
&kUW
|
||||
f[UUW
|
||||
gcE[
|
||||
$gcE[
|
||||
cUU%
|
||||
UUWT
|
||||
xxxx
|
||||
FsUU^
|
||||
$ecF[
|
||||
icD[
|
||||
T\Rb
|
||||
sUW|
|
||||
UUU\
|
||||
VUUU
|
||||
BIGF
|
||||
L286
|
||||
Apt Data:1:7:8
|
||||
game/globalComponents/globalComponents
|
||||
game.globalComponents.ImageLoader
|
||||
game/components/SelectTeam
|
||||
game.components.SelectTeam
|
||||
Coins
|
||||
TournamentData
|
||||
BackingFUT
|
||||
VersusFUT
|
||||
external.ion_fut.screens.futSelectTeam
|
||||
__Packages.external.ion_fut.screens.futSelectTeam
|
||||
__Packages.ion.manager.HelpProperties
|
||||
EACondBold
|
||||
10.000
|
||||
Screen
|
||||
RtIL
|
||||
RYgO
|
||||
7uOO
|
||||
XsOY
|
||||
2sOY
|
||||
<@OY
|
||||
BG&Y
|
||||
3NuIL
|
||||
7NuI
|
||||
3NuI
|
||||
3NstY
|
||||
7uOY
|
||||
&v>Y
|
||||
&v>t
|
||||
3NYN
|
||||
7NYN
|
||||
tOYZ
|
||||
BG&v
|
||||
NZGO
|
||||
NZGOZu
|
||||
uOZu
|
||||
mcCup
|
||||
txtPrizeHeading
|
||||
txtCoins
|
||||
mcCoin
|
||||
mcBacking
|
||||
txtVs
|
||||
mcTournamentInfo
|
||||
mcSelectTeam
|
||||
mcVersusFUT
|
||||
publishObject
|
||||
dpID
|
||||
nHomeKitID
|
||||
nAwayKitID
|
||||
keyCode
|
||||
controllerId
|
||||
nSide
|
||||
arrKitIDs
|
||||
teamId
|
||||
kitToResolve
|
||||
side
|
||||
isUser
|
||||
arrKits
|
||||
objProperties
|
||||
Void
|
||||
nXPos
|
||||
DDS |
|
||||
NVTT
|
||||
DXT5
|
||||
8VTTT
|
||||
UUVT
|
||||
TTTU
|
||||
0TUVT
|
||||
TTUW
|
||||
$$r
|
||||
%UUU
|
||||
WUUU
|
||||
UUUSP
|
||||
UUUM
|
||||
UUUNK
|
||||
72Ib
|
||||
*72Ib
|
||||
U;8I
|
||||
WWWW?>I
|
||||
UIFI
|
||||
WWWWLKI
|
||||
WWWVQNI
|
||||
VVYVI
|
||||
`]IB
|
||||
daIB
|
||||
heIB
|
||||
VlhI
|
||||
vtI"I
|
||||
UU%!I
|
||||
*;8I
|
||||
U?>I
|
||||
ULKI
|
||||
Apt1
|
||||
_global
|
||||
external
|
||||
Object
|
||||
ion_fut
|
||||
screens
|
||||
futSelectTeam
|
||||
futSelectTeam::futSelectTeam()
|
||||
OnExitScreen
|
||||
cafe
|
||||
utility
|
||||
Delegate
|
||||
Create
|
||||
game
|
||||
globalClasses
|
||||
ScreenManager
|
||||
SetOnExitScreenCallback
|
||||
m_nFlowState
|
||||
EA_ZONE
|
||||
gScreenFlowManager
|
||||
getFlowState
|
||||
ION_Platform
|
||||
IsFinal
|
||||
CardNotification
|
||||
eState
|
||||
FUT_OFFLINE_DRAFT
|
||||
FUT_OFFLINE_TOURNAMENT
|
||||
FUT_OFFLINE_SEASON
|
||||
m_bAllowSelectAnyTeam
|
||||
FUT/ALLOW_ANY_CPU_TEAM
|
||||
ION_Customization
|
||||
GetAardvarkIntValue
|
||||
mcPanelHome
|
||||
mcPanelAway
|
||||
mcReadyHome
|
||||
mcReadyAway
|
||||
mcKitHome
|
||||
mcKitAway
|
||||
mcLockHome
|
||||
mcLockAway
|
||||
InitComponents
|
||||
InitializeScreen
|
||||
Initialize
|
||||
screen
|
||||
BaseScreen
|
||||
prototype
|
||||
futSelectTeam::InitializeScreen()
|
||||
_visible
|
||||
HOME_SIDE
|
||||
GameServices
|
||||
eTeamSide
|
||||
SIDE_HOME
|
||||
AWAY_SIDE
|
||||
SIDE_AWAY
|
||||
NEUTRAL_SIDE
|
||||
SIDE_NEUTRAL
|
||||
m_arrPanelData
|
||||
Array
|
||||
m_arrKitPanelData
|
||||
futSelectTeam::InitComponents()
|
||||
InitializeKitConfig
|
||||
InitializeTeamConfig
|
||||
SetTeamAndKitConfigs
|
||||
UIFDataProviderList
|
||||
FUT_USER_CLUB_DATA_DP
|
||||
UIFUtility
|
||||
RegisterDataProvider
|
||||
FUT_OPPONENT_CLUBS_LIST_DP
|
||||
FUT_OPPONENTS_SQUADS_LIST_DP
|
||||
FUT_OPPONENT_SQUAD_LINEUP_DP
|
||||
FUT_USER_SQUAD_LINEUP_DP
|
||||
FUT_CREATE_MATCH_DP
|
||||
FUT_GET_MATCH_KITS_DP
|
||||
SetupReadyTexts
|
||||
initSideInfo
|
||||
SetPanels
|
||||
m_arrPanels
|
||||
m_arrKitPanels
|
||||
KitSelectDP
|
||||
TeamSetupDP
|
||||
AnimateIn
|
||||
AnimateInComplete
|
||||
BeginAnimateIn
|
||||
futSelectTeam::AnimateInComplete()
|
||||
m_bHasAnimatedIn
|
||||
checkForDisconnect
|
||||
gScreenNotAborted
|
||||
LocalEventHandler
|
||||
InputManager
|
||||
AddLocalEventHandler
|
||||
SetHandlerId
|
||||
refreshCurrentConnectionStatus
|
||||
HelpManager
|
||||
Update
|
||||
futSelectTeam::OnExitScreen()
|
||||
AnimationManager
|
||||
ClearAnimations
|
||||
UnregisterDataProvider
|
||||
INJURY_POPUP_ID
|
||||
PopupManager
|
||||
DeletePopup
|
||||
TOTW_BELOW_MIN_POPUP_ID
|
||||
USER_BELOW_MIN_POPUP_ID
|
||||
OPP_BELOW_MIN_POPUP_ID
|
||||
OPP_HAS_NO_VALID_SQUADS_ID
|
||||
Shutdown
|
||||
ClearSavedOpponentData
|
||||
SQUAD_ID
|
||||
UUID_UPPER
|
||||
UUID_LOWER
|
||||
UIFActionList
|
||||
ACTION_SAVE_OPPONENT_DATA
|
||||
SendActionObj
|
||||
Publish
|
||||
futSelectTeam::Publish()
|
||||
header
|
||||
USER_CLUB_DATA
|
||||
SetUserClubData
|
||||
initVersusFUTComponents
|
||||
OPPONENT_CLUBS
|
||||
m_arrOpponentClubs
|
||||
data
|
||||
MATCH_CREATED
|
||||
FUT_PAFC_GAME
|
||||
GetCurrentCountryIndex
|
||||
SQUADS
|
||||
GetCurrentLeagueIndex
|
||||
ACTION_ADVANCE
|
||||
SendAction
|
||||
eSoundEvent
|
||||
PRIMARY_SELECT
|
||||
playSound
|
||||
m_bShouldWaitForPublish
|
||||
OPP_SQUADS_LIST
|
||||
SetOpponentSquadListData
|
||||
SQUAD_LINEUP_LOADED
|
||||
IS_USER
|
||||
SetSquadLineup
|
||||
KITS_AVAILABLE
|
||||
LENGTH
|
||||
KIT_
|
||||
push
|
||||
futSelectTeam::InitializeKitConfig()
|
||||
SetupTeamsInfo
|
||||
GetHomeTeamId
|
||||
ACTION_MATCHDAY_HOME_TEAM_CHANGE
|
||||
GetAwayTeamId
|
||||
ACTION_MATCHDAY_AWAY_TEAM_CHANGE
|
||||
ACTION_MATCHDAY_ADVANCE_KIT_SETUP
|
||||
SetReadyStatus
|
||||
FadeOut
|
||||
GetKitArrayForFUT
|
||||
HOME_KIT_ID
|
||||
AWAY_KIT_ID
|
||||
ION_Uniform
|
||||
IsKitSelectCreated
|
||||
EnterKitSelect
|
||||
IsAlternatingMode
|
||||
GetUnhighlightedSide
|
||||
SetKitUnReady
|
||||
InitializeKitsFromArray
|
||||
Unhighlight
|
||||
SetDisabled
|
||||
SetHighlightedSide
|
||||
GetHighlightedSide
|
||||
Highlight
|
||||
futSelectTeam::InitializeTeamConfig()
|
||||
LEAGUE_ID
|
||||
components
|
||||
TeamSetupControl
|
||||
TEAM_TOGGLE
|
||||
GetUserSideForFUT
|
||||
m_isInFUT
|
||||
InitData
|
||||
GetToggleValue
|
||||
UpdateTeamInfo
|
||||
m_bOpponentTeamInvalid
|
||||
m_OppHasSquads
|
||||
SetChemistryValue
|
||||
ResetTeamInfo
|
||||
FadeIn
|
||||
SetupMouseSupport
|
||||
SetWomenTeamsOnlyFilter
|
||||
SetMenTeamsOnlyFilter
|
||||
DeactivateReady
|
||||
futSelectTeam::SetupTeamsInfo()
|
||||
USER_TEAM_ID
|
||||
ION_GameSetup
|
||||
GetTeam
|
||||
SetHomeTeamId
|
||||
SetAwayTeamId
|
||||
setCustomSelectionArray
|
||||
Team
|
||||
eAttribute
|
||||
ION_Team
|
||||
GetAttributes
|
||||
futSelectTeam::LocalEventHandler()
|
||||
WARNING: Preventing the user to move until a Publish occurs.
|
||||
IsInTransition
|
||||
Stop spamming buttons, the team select screen is in a transition.
|
||||
GetUserControllerSide
|
||||
GetScreenState
|
||||
DataProviders
|
||||
STATE_TEAM
|
||||
InputCodes
|
||||
LEFT
|
||||
RIGHT
|
||||
GetReadyStatus
|
||||
DOWN
|
||||
BACK
|
||||
ADVANCE
|
||||
OPTION_TOP
|
||||
OPTION_LEFT
|
||||
IsSwitchSidesActive
|
||||
STATE_KIT
|
||||
SetUniform
|
||||
ExitKitSelect
|
||||
RemoveKitLocks
|
||||
ACTION_BACKOUT
|
||||
CANCEL
|
||||
SetKit
|
||||
SaveKitsForMatch
|
||||
FUT_TOTW_GAME
|
||||
SetGoingToKickoffHub
|
||||
SetHomeKitId
|
||||
SetAwayKitId
|
||||
GetHomeKitId
|
||||
GetAwayKitId
|
||||
ACTION_CREATE_MATCH
|
||||
SetReady
|
||||
SetKitReady
|
||||
FUT_OPP_HAS_NO_VALID_SQUADS
|
||||
PopupData
|
||||
Okay_abbr2
|
||||
AddButton
|
||||
ShowPopup
|
||||
ValidateFullLineUp
|
||||
m_sInjuryOrSuspendedWarning
|
||||
m_bConceptPlayersInSquad
|
||||
FUT_DB_Players_Not_Playable
|
||||
FUT_TOTW_BELOW_MIN_PLAYERS
|
||||
FUT_BELOW_MIN_PLAYERS
|
||||
FUT_OPP_BELOW_MIN_PLAYERS
|
||||
COUNTRY_TOGGLE
|
||||
LEAGUE_TOGGLE
|
||||
ACTION_GET_USER_SQUAD_LINEUP
|
||||
ACTION_GET_OPPONENT_SQUAD_LINEUP
|
||||
GoToViewSquad
|
||||
PlatformManager
|
||||
IsMicrosoft
|
||||
USER_NAME
|
||||
length
|
||||
gEaso
|
||||
showGamercard
|
||||
getHelpContext
|
||||
futSelectTeam::getHelpContext()
|
||||
STATE_INVALID
|
||||
FUT_VIEW_SQUAD_HOME
|
||||
ltxt
|
||||
manager
|
||||
HelpItem
|
||||
CreateHelpItem
|
||||
FUT_VIEW_SQUAD_AWAY
|
||||
ViewGamerCard
|
||||
CreateHelpTickerItem
|
||||
futSelectTeam::InitializeKitsFromArray()
|
||||
GetAllAttributes
|
||||
TYPE_UPPER
|
||||
ITEM_NAME
|
||||
ITEM_ID
|
||||
ASSET_ID
|
||||
StyleManager
|
||||
FONT_TILE_HS
|
||||
SetTitleTextFormat
|
||||
SetToggleOffset
|
||||
globalComponents
|
||||
BasePanel
|
||||
STYLE_FIFTEEN
|
||||
SetBasePanelStyle
|
||||
KIT_SCALE
|
||||
kits
|
||||
ToggleWithImage
|
||||
STYLE_TOGGLE
|
||||
SetStrokeVisibility
|
||||
CheckIsKitLocked
|
||||
futSelectTeam::GetKitArrayForFUT()
|
||||
GetNonConflictingUniformID
|
||||
eSortType
|
||||
SORT_ASCENDING
|
||||
Uniform
|
||||
eSortColumn
|
||||
SORT_NONE
|
||||
eFilter
|
||||
FILTER_UNFILTERED
|
||||
GetIDs
|
||||
LOCKED
|
||||
NAME
|
||||
shift
|
||||
futSelectTeam::initVersusFUTComponents()
|
||||
text
|
||||
Versus_abbr
|
||||
_height
|
||||
FUT_Tournament
|
||||
GetOfflineActiveTournamentId
|
||||
GetOfflineTournamentInfo
|
||||
TROPHY_ID
|
||||
trophy
|
||||
getArtAssetPath
|
||||
SCALE_ASPECT_CENTER
|
||||
setScaling
|
||||
setSize
|
||||
setImage
|
||||
FUT_UC_TOURNAMENT_BONUS
|
||||
PRIZE_FINAL
|
||||
ION_Localization
|
||||
LocalizeInteger
|
||||
_width
|
||||
textWidth
|
||||
FUT_COINS_OFFSET
|
||||
futSelectTeam::GoToViewSquad()
|
||||
isUserTeam
|
||||
CLUB_NAME
|
||||
BADGE_TEAM_ID
|
||||
SQUAD_NAME
|
||||
RATING
|
||||
SQUAD_RATING
|
||||
CHEMISTRY
|
||||
SQUAD_CHEMISTRY
|
||||
SHOW_CHEM_LINE
|
||||
SCREEN
|
||||
VIEW_SQUADS
|
||||
setContextDataObject
|
||||
loadOverlayScreen
|
||||
futSelectTeam::SetUserClubData()
|
||||
m_arrUserClubs
|
||||
PUBLIC
|
||||
CLUB_ABBR
|
||||
EST_DATE
|
||||
ACTIVE_SQUAD_ID
|
||||
SIDE_NAME
|
||||
Away_Side
|
||||
Home_Side
|
||||
futSelectTeam::SetOpponentSquadListData()
|
||||
split
|
||||
FUT_NO_VALID_SQUADS
|
||||
futSelectTeam::SetSquadLineup()
|
||||
SetTeam
|
||||
futSelectTeam::GetCurrentCountryIndex()
|
||||
futSelectTeam::GetCurrentLeagueIndex()
|
||||
futSelectTeam::GetUserSideForFUT()
|
||||
bIsDemo
|
||||
GetLockRules
|
||||
SIDE_LOCK
|
||||
futSelectTeam::ValidateFullLineUp()
|
||||
FUT_SquadManagement
|
||||
GetOpponentSquadLineup
|
||||
GetSquadLineup
|
||||
FUT_NUM_PLAYERS_IN_SQUAD
|
||||
CARD_ID
|
||||
ION_Card
|
||||
GetPlayerCardInfo
|
||||
IS_DREAM_PLAYER
|
||||
FUT_NUM_PLAYERS_IN_SQUAD_EXTENDED
|
||||
gFutHelpers
|
||||
GetInjuryOrSuspendedSquadWarning
|
||||
futSelectTeam::SaveKitsForMatch()
|
||||
SIDE
|
||||
NUM_KITS
|
||||
ACTION_SAVE_MATCH_KIT
|
||||
FUT_TOURNAMENT_CUP_SCALE
|
||||
INJURY_OR_SUSPENDED_POPUP
|
||||
TOTW_NUM_PLAYERS_BELOW_MIN_POPUP
|
||||
USER_NUM_PLAYERS_BELOW_MIN_POPUP
|
||||
OPP_NUM_PLAYERS_BELOW_MIN_POPUP
|
||||
OPP_HAS_NO_VALID_SQUADS
|
||||
SCALE_NONE
|
||||
SCALE_ASPECT
|
||||
SCALE_ABSOLUTE
|
||||
ASSetPropFlags
|
||||
HelpProperties
|
||||
mXPos
|
||||
GetXPos
|
||||
SetXPos
|
||||
registerClass
|
||||
hj\W
|
||||
hj/U
|
||||
UUUV
|
||||
'Z`XV
|
||||
j`XVW
|
||||
b$9^
|
||||
UW^}
|
||||
hb>x
|
||||
DA__\X
|
||||
UWW^
|
||||
HbCA
|
||||
hjCA/
|
||||
+{dA
|
||||
b#9X7*
|
||||
I^^|x
|
||||
(Z``pP
|
||||
Zxp`
|
||||
\j~X
|
||||
&j\xp
|
||||
jXXXX
|
||||
Fn%Vb=
|
||||
xxxp
|
||||
xh``
|
||||
WWWW
|
||||
r\XXX
|
||||
xxz_
|
||||
{XPpr
|
||||
Hb__^\
|
||||
`x|x
|
||||
``xX
|
||||
]{jp
|
||||
xxhh
|
||||
X\\\
|
||||
U\T_
|
||||
`pz~
|
||||
_^^^
|
||||
cq,6
|
||||
-/+*+
|
||||
jjjj
|
||||
jJJj
|
||||
_^Xp
|
||||
WV\p
|
||||
TTWU
|
||||
```h
|
||||
pWUU
|
||||
\UUU
|
||||
$I">
|
||||
x^UU
|
||||
/UUU
|
||||
$IR`m
|
||||
$IL#
|
||||
cAxW
|
||||
dI/U
|
||||
&b%W
|
||||
|UWV\
|
||||
j_uyQ
|
||||
|UUVT
|
||||
|WT\\
|
||||
j`ppp
|
||||
|\\\\
|
||||
bpppp
|
||||
)---
|
||||
||x||
|
||||
bzzzz
|
||||
s"#)5
|
||||
K{&R
|
||||
D(tFR```
|
||||
j5555
|
||||
){zxh`
|
||||
hlUU_`
|
||||
$Ithd
|
||||
Ithd
|
||||
hlUWVT
|
||||
s(ljj
|
||||
HR{O
|
||||
IBww
|
||||
@Bbb
|
||||
Hl\\Xx
|
||||
zzhh
|
||||
@`pP
|
||||
Htxxxx
|
||||
hlHd
|
||||
Ht%%%5
|
||||
ZZ\\
|
||||
H|xxxx
|
||||
Hthd
|
||||
xxxX
|
||||
TV_]
|
||||
H|hd
|
||||
Xxx`
|
||||
_\|p
|
||||
pppP
|
||||
H|xxxz
|
||||
i|%%%5
|
||||
pX\T
|
||||
H|xzzz
|
||||
(dHt
|
||||
H|`xz_
|
||||
UU^p
|
||||
$G|(t
|
||||
G|(t
|
||||
(tG\
|
||||
VTTT
|
||||
kUUU5
|
||||
(pXxx
|
||||
XXXX
|
||||
KOKK
|
||||
'cUU^
|
||||
hs'c
|
||||
$Gk(c
|
||||
Gk(c
|
||||
~ZZX
|
||||
GkUWx
|
||||
GkUUU\
|
||||
'Gk(c
|
||||
p``H
|
||||
zUU~
|
||||
X`pxZ
|
||||
sUWx
|
||||
c```
|
||||
@@@@
|
||||
WVT\
|
||||
Vw~U
|
||||
_^_j
|
||||
\XPp
|
||||
^|~^
|
||||
c``pX\
|
||||
````
|
||||
UUUU
|
||||
\\\\
|
||||
????
|
||||
p~UU
|
||||
Ib'b
|
||||
X\WU
|
||||
A*++
|
||||
UUUX
|
||||
VWUU
|
||||
z^VW
|
||||
W^x
|
||||
\\\\j
|
||||
TWVV
|
||||
\^xx
|
||||
W^~
|
||||
VWVt
|
||||
cI^xxp
|
||||
k$)WWVT
|
||||
)W_VT
|
||||
$1VTVT
|
||||
(\\\\
|
||||
\\\\"
|
||||
$1\\XX
|
||||
pr`z
|
||||
AXPp`
|
||||
yU^r^
|
||||
$I2,r
|
||||
PZrC
|
||||
U{Bz
|
||||
{||Z
|
||||
kkki
|
||||
c`p^
|
||||
cx6l
|
||||
\\\\]
|
||||
dIb`@@
|
||||
pvv]
|
||||
'z@@
|
||||
XVUU
|
||||
e9`p
|
||||
UVVV
|
||||
(.-5
|
||||
JJJJ
|
||||
cQxxx
|
||||
(%-)+
|
||||
VVVV
|
||||
#9ZZxx
|
||||
i-)-
|
||||
1U_|
|
||||
#9=*
|
||||
VVTT
|
||||
T\\X
|
||||
X^__
|
||||
5-)+
|
||||
$I"'r
|
||||
rrbJ
|
||||
8)-%5
|
||||
ZZZZ
|
||||
jjjk
|
||||
1^UUU
|
||||
g1G)^
|
||||
!XX\V
|
||||
BIGF0
|
||||
Apt Data:1:5:8
|
||||
U555
|
||||
Urpp
|
||||
~B'j
|
||||
5555
|
||||
m*((
|
||||
;RRRR
|
||||
m***
|
||||
:RRRR
|
||||
`15555
|
||||
sZPPP
|
||||
`95555
|
||||
Apppp
|
||||
95555
|
||||
{PPPR
|
||||
RRRR
|
||||
rrp_
|
||||
&j2'
|
||||
pppp
|
||||
Ns%!U
|
||||
%)%%%%
|
||||
f)%!
|
||||
` 6dC.kE!
|
||||
Z%)70
|
||||
1E!W
|
||||
1E!U
|
||||
f1E!
|
||||
F1Xp*
|
||||
9f)U
|
||||
xUU\
|
||||
JV~No
|
||||
(n{$!
|
||||
iJPPpp
|
||||
<W\^
|
||||
AqUW
|
||||
{Cq_
|
||||
U]P\
|
||||
Pppp
|
||||
TTTT
|
||||
PPPp
|
||||
,(;k
|
||||
z^\x
|
||||
\^VT
|
||||
???/
|
||||
btTVV
|
||||
M{-/75
|
||||
x~_^
|
||||
TUWW
|
||||
%555
|
||||
(^xp`
|
||||
UUWV
|
||||
jR\T\\
|
||||
1xp``
|
||||
b\\\X
|
||||
b557/
|
||||
jZ'5
|
||||
WWWh
|
||||
^XPZ
|
||||
zxxxx
|
||||
1UWVT
|
||||
h4Vb%
|
||||
\^U?
|
||||
\\\X
|
||||
I*.$
|
||||
Hb'A
|
||||
9UU\
|
||||
i--+
|
||||
Wka@
|
||||
P|WWW
|
||||
UW^x
|
||||
@PW^
|
||||
czXX
|
||||
++-5
|
||||
`x@p
|
||||
brp`
|
||||
U%%%
|
||||
\VUW
|
||||
XPXX
|
||||
WTTV
|
||||
PPXX
|
||||
zc9~^z
|
||||
I"1-+
|
||||
!*+*
|
||||
TTVT
|
||||
----Y
|
||||
73 &
|
||||
Av|z
|
||||
`^UJ
|
||||
xx~p
|
||||
&jB1_
|
||||
Y444$
|
||||
xWU0
|
||||
$_nO
|
||||
G1BBBB
|
||||
xxx^
|
||||
xxz~
|
||||
---=
|
||||
***J
|
||||
O"'@
|
||||
7 '>
|
||||
U`X\Y
|
||||
h035^
|
||||
Lw!f
|
||||
&T@a
|
||||
]8RR
|
||||
[OAq
|
||||
D/Oz%F
|
||||
+1.^-
|
||||
_,_Y
|
||||
..^O
|
||||
CG|!@
|
||||
;}>|
|
||||
nHT*
|
||||
a8Nj
|
||||
?'Un70
|
||||
^[zM2Bj @
|
||||
6nd[N
|
||||
Z)MBc
|
||||
wY=A
|
||||
8p(a
|
||||
:m"D
|
||||
[dbt
|
||||
E'0S
|
||||
nT+bJuZ
|
||||
V-:t
|
||||
v)(n
|
||||
(*s?p
|
||||
cc?r
|
||||
B%{r
|
||||
-4Yi
|
||||
sci,Iy
|
||||
|3;=
|
||||
<KB6
|
||||
cCFVJ
|
||||
J|jg
|
||||
4VvVV6
|
||||
p$$e&
|
||||
4%1{
|
||||
~%ew==_.
|
||||
EFGFFED
|
||||
[FFB}9
|
||||
$"dOz%^-
|
||||
mw77
|
||||
ct3r
|
||||
ecGB
|
||||
*\JV
|
||||
c&WV
|
||||
w6GMq
|
||||
13aB
|
||||
$X~_
|
||||
mMx%
|
||||
;11sZR
|
||||
'&'n
|
||||
q&##>o
|
||||
+:Z/Y
|
||||
]:AY
|
||||
$(+~
|
||||
,^:(,
|
||||
kp>C
|
||||
luqYql
|
||||
wf_q
|
||||
XYX\
|
||||
@p77
|
||||
--X&q
|
||||
{ cf
|
||||
waF,
|
||||
znrn;
|
||||
VRwCE
|
||||
5=#&
|
||||
/J"}
|
||||
_A4Z
|
||||
gnB7%
|
||||
q`Y
|
||||
Q|!+
|
||||
[MMA
|
||||
**rV
|
||||
)~U(w*,)m
|
||||
Z*SVd
|
||||
$#&qi
|
||||
qmUW=
|
||||
F"MN
|
||||
HaA%e%
|
||||
(T!]5(\
|
||||
IK#k
|
||||
v wQ
|
||||
C(\M
|
||||
];%P
|
||||
7f&=kJ
|
||||
%(oRtK
|
||||
gRr?
|
||||
+rq_
|
||||
/==7
|
||||
,IUk
|
||||
D?t(zC,
|
||||
\}oe
|
||||
'^YY
|
||||
nwzu
|
||||
jdf,
|
||||
i5hFc
|
||||
z@xOrFp
|
||||
aqgv
|
||||
y^oT+
|
||||
dZ13
|
||||
d{g~
|
||||
ttzi
|
||||
p,@B
|
||||
upqH
|
||||
1{pl0
|
||||
J4)~
|
||||
&W<;@
|
||||
p77Es
|
||||
:aPw
|
||||
`>(^&
|
||||
lnW|
|
||||
~+w8
|
||||
@@ -0,0 +1,278 @@
|
||||
# FIFA17.exe runtime command/event id -> name registry
|
||||
# Recovered 2026-08-24 from live pid 44405 (Denuvo-decrypted, /proc/PID/mem, read-only).
|
||||
# CardsDLL live base 0x6ffffc0f0000; registration loop at live 0x147dd0000-0x147df8000.
|
||||
# NOTE: this is a DIFFERENT namespace from CardsDLL's DataProvider id table.
|
||||
# the same numeric id has a different name in each, matching the APT's split
|
||||
# between game.uif.UIFDataProviderList and the action/command list.
|
||||
#
|
||||
0x0207 %d
|
||||
0x0bb9 back
|
||||
0x0bbb preScreenSucceeded
|
||||
0x0bbc preScreenFailed
|
||||
0x0bc0 clearTeamSheets
|
||||
0x0be7 selectTab
|
||||
0x0c15 optionSelected
|
||||
0x0c2a leaveGameGroup
|
||||
0x0c2c quitToHub
|
||||
0x0dac UpdateStadiumCrests
|
||||
0x0dac startStoryMode
|
||||
0x2713 matchdayFixtureChange
|
||||
0x271a evt_set_matchDay_offline_fixture
|
||||
0x271b evt_team_setup_state
|
||||
0x271c advanceDefault
|
||||
0x271d advanceDefaultWithTeam
|
||||
0x271e advancePran
|
||||
0x271f feInitialized
|
||||
0x2720 skipBootflow
|
||||
0x2721 startBootflow
|
||||
0x2722 bootflowStarted
|
||||
0x2723 bootflowFinished
|
||||
0x2724 bootflowSaveLoadFailed
|
||||
0x2725 returnToPressStart
|
||||
0x2726 showPressStart
|
||||
0x2727 evt_load_personal_settings
|
||||
0x2728 evt_settings_load_complete
|
||||
0x2729 assetUpdate
|
||||
0x272a pranUpload
|
||||
0x272b pranDownload
|
||||
0x272c controllerConfig
|
||||
0x272d activateGameModeIntro
|
||||
0x272e ActivateFullGame
|
||||
0x272f startIntroFlow
|
||||
0x2730 offlineEulaProfileSuccess
|
||||
0x2731 offlineEulaProfileFail
|
||||
0x2732 startIntroMatch
|
||||
0x2733 abortIntroMatch
|
||||
0x2735 setCareerType
|
||||
0x2736 exitTitle
|
||||
0x2737 evt_set_fullscreen
|
||||
0x273e enterSubPanel
|
||||
0x273f exitSubPanel
|
||||
0x2742 evt_invite_accepted
|
||||
0x2743 profileSignOut
|
||||
0x2744 profilePrepareForSave
|
||||
0x2745 logTelemetry
|
||||
0x2746 enterPracticeArena
|
||||
0x2748 navigationBackoutStart
|
||||
0x2749 navigationBackoutContinue
|
||||
0x274a navigationBackoutComplete
|
||||
0x274b checkSpeechData
|
||||
0x274c newsSharingSettings
|
||||
0x274d leaveBootFlow
|
||||
0x274e mainMenuProfileCreationDone
|
||||
0x274f nonLeadProfileCreation
|
||||
0x2750 nonLeadProfileLoad
|
||||
0x2755 teamSheetAction
|
||||
0x2758 evt_set_lead_profile
|
||||
0x2759 evt_sign_out
|
||||
0x275a notifySignOut
|
||||
0x275b notifySignOutReady
|
||||
0x275c notifySignOutTitleScreen
|
||||
0x275d evt_sign_out_flow_ready
|
||||
0x275e evt_sign_out_flow_not_ready
|
||||
0x275f showSignOutPopup
|
||||
0x2760 showSignOutTitleScreenPopup
|
||||
0x2761 evt_dismiss_sign_out_popup
|
||||
0x2762 evt_show_account_picker
|
||||
0x2763 evt_lead_profile_recovered
|
||||
0x2764 triggerSignOut
|
||||
0x2765 checkLeadProfilePairing
|
||||
0x2766 evt_lead_profile_paired
|
||||
0x2767 evt_lead_profile_unpaired
|
||||
0x2768 evt_lead_profile_controller_changed
|
||||
0x2769 beginProfileCheck
|
||||
0x276a endProfileCheck
|
||||
0x276b evt_controller_disconnect
|
||||
0x276c evt_notify_controller_disconnect
|
||||
0x276d evt_controller_disconnect_flow_ready
|
||||
0x276e evt_controller_disconnect_flow_not_ready
|
||||
0x276f showLoadPersonalSettingsPopup
|
||||
0x2770 showSavePersonalSettingsPopup
|
||||
0x2771 feRenderInGame
|
||||
0x2772 pvProfilerStart
|
||||
0x2773 pvProfilerStop
|
||||
0x2775 enterMatchDayTab
|
||||
0x2776 exitMatchDayTab
|
||||
0x2777 restartWithNewTeams
|
||||
0x2778 playSecondLegFixture
|
||||
0x2779 setupSecondLegFixture
|
||||
0x277a welcomeToMatchDayLive
|
||||
0x277b exitMatchDayLivePanel
|
||||
0x277c enableAardvark
|
||||
0x277d disableAardvark
|
||||
0x277e conditionAardvark
|
||||
0x2780 adaptiveDifficultyDetectedPopup
|
||||
0x2781 adaptiveDifficultyUpPopup
|
||||
0x2782 adaptiveDifficultyDownPopup
|
||||
0x2783 adaptiveDifficultyDetected
|
||||
0x2784 adaptiveDifficultyUp
|
||||
0x2785 adaptiveDifficultyDown
|
||||
0x2786 adaptiveDifficultyDisable
|
||||
0x2787 adaptiveDifficultyReset
|
||||
0x2788 adaptiveDifficultyKeep
|
||||
0x2789 adaptiveDifficultyOverride
|
||||
0x278c evt_countdown_done
|
||||
0x278d evt_countdown_restart
|
||||
0x278e evt_start_stadium_change
|
||||
0x278f evt_wait_for_stadium_change
|
||||
0x2790 evt_wait_for_stadium_change_bootflow
|
||||
0x2791 evt_advance_to_wait_popup
|
||||
0x2792 evt_advance_to_wait
|
||||
0x2793 evt_stadium_background_loaded
|
||||
0x2795 setupTournament
|
||||
0x2796 createTournament
|
||||
0x2797 createWomenTournament
|
||||
0x2799 setWomenTournament
|
||||
0x279a evt_sl_operation_started
|
||||
0x279b evt_sl_operation_complete
|
||||
0x279c evt_sl_operation_load
|
||||
0x279d evt_sl_operation_boot_load
|
||||
0x279e evt_sl_operation_save
|
||||
0x279f evt_sl_operation_delete
|
||||
0x27a0 FUTLoginComplete
|
||||
0x27a1 requestDownload
|
||||
0x27a2 backendEnter
|
||||
0x27a3 backendExit
|
||||
0x27a4 onlineLoginToEaPopup
|
||||
0x27a5 onlineBootLoginToEaPopup
|
||||
0x27a6 evt_onlineAlertPopup
|
||||
0x27a7 evt_onlineBootLoginFailurePopup
|
||||
0x27a8 evt_onlineLoginFailurePopup
|
||||
0x27a9 onlineLoginPopupHide
|
||||
0x27aa onlineLoginPopupShow
|
||||
0x27ab evt_invite_flow_ready
|
||||
0x27ac evt_invite_flow_not_ready
|
||||
0x27ad inviteFlowAbortSaveLoad
|
||||
0x27ae evt_verify_invite_nav_cleanup
|
||||
0x27af downloadComplete
|
||||
0x27b0 downloadFailed
|
||||
0x27b1 spevnetNotAvailable
|
||||
0x27b2 spevnetNotRegistered
|
||||
0x27b3 spevnetNotRegisteredBeta
|
||||
0x27b4 userBanned
|
||||
0x27b5 showExitConfirmPopup
|
||||
0x27b6 hideExitConfirmPopup
|
||||
0x27b7 confirmExit
|
||||
0x27b8 showRegisterConfirmPopup
|
||||
0x27b9 hideRegisterConfirmPopup
|
||||
0x27ba setStadiumPosition
|
||||
0x27bb liveCompCountryDecision
|
||||
0x27bc liveCompAllCountriesSelect
|
||||
0x27bd liveCompLimitedCountriesSelect
|
||||
0x27be liveCompAdvanceToTeamSelect
|
||||
0x27bf liveCompRegistrationConfirm
|
||||
0x27c0 liveCompEventListSuccess
|
||||
0x27c1 liveCompEventListFail
|
||||
0x27c2 postMatchHighlightExit
|
||||
0x27c3 postMatchHighlightComplete
|
||||
0x27c4 postMatchHighlightSelect
|
||||
0x27c5 postMatchHighlightReelSelect
|
||||
0x27c6 postMatchHighlightIRSelect
|
||||
0x27cf leaveUpsell
|
||||
0x27d0 purchase
|
||||
0x27d1 advanceFromPMA
|
||||
0x27d2 evt_transitionToPMADone
|
||||
0x27d3 cutSceneCommand
|
||||
0x27d4 cutScenePlay
|
||||
0x27d5 loadCutScenesSubLevel
|
||||
0x27d6 unloadCutScenesSubLevel
|
||||
0x27d7 evt_enable_skip_cutscene
|
||||
0x27d8 gmCutSceneStarted
|
||||
0x27d9 gmCutSceneEnded
|
||||
0x27da gmCutScenesSublevelLoaded
|
||||
0x27db gmCutScenesSublevelUnloaded
|
||||
0x27dc gmAirlockToGameplayEnded
|
||||
0x27dd gmAirlockLoadComplete
|
||||
0x27de evt_quit_to_training_hub
|
||||
0x27e0 evt_training_allow_advance_to_game
|
||||
0x27e1 checkOriginConnected
|
||||
0x27e2 OriginIsOnline
|
||||
0x27e3 OriginIsOffline
|
||||
0x27e4 OIGOpened
|
||||
0x27e5 OIGClosed
|
||||
0x27e6 overrideOnlineStadium
|
||||
0x27e7 smLoadFEStadium
|
||||
0x27e8 smActivateFreeRoam
|
||||
0x27e9 smGameOver
|
||||
0x27ea smScenePrime
|
||||
0x27eb smScenePrimeAndPrep
|
||||
0x27ec smScenePause
|
||||
0x27ed smSceneResume
|
||||
0x27ee smMoment
|
||||
0x27ef smMomentRepeat
|
||||
0x27f0 smMomentComplete
|
||||
0x27f1 smExitMomentState
|
||||
0x27f2 smOnPlayScene
|
||||
0x27f3 smConversation
|
||||
0x27f4 smConversationComplete
|
||||
0x27f5 smConversationNotification
|
||||
0x27f6 smConversationNotificationComplete
|
||||
0x27f7 smGameplayStartLoad
|
||||
0x27f8 smGameplayLoadOver
|
||||
0x27f9 smGameplayStart
|
||||
0x27fa smGameplayOver
|
||||
0x27fb smGameplayPause
|
||||
0x27fc smGameplayResume
|
||||
0x27ff smTweetConsume
|
||||
0x2800 smHeroLoanedOut
|
||||
0x2801 smSetupAcademyMatch
|
||||
0x2802 smSetupAcademyTeams
|
||||
0x2803 smStartIntroFlow
|
||||
0x2804 smStartSeason
|
||||
0x2805 smPlayMatch
|
||||
0x2806 smEndMatch
|
||||
0x2807 smGetTrainingSet
|
||||
0x2808 smEnterTrainingTeamHub
|
||||
0x2809 smEnterTraining
|
||||
0x280a smPlayTrainingSessionVO
|
||||
0x280b smPrepareTraining
|
||||
0x280c smPlayTraining
|
||||
0x280d smStopTraining
|
||||
0x280e smStartSkillGame
|
||||
0x280f smSimTraining
|
||||
0x2810 smEndTraining
|
||||
0x2811 smSave
|
||||
0x2812 smAutoSave
|
||||
0x2814 smLoad
|
||||
0x2815 smSetScreenFlowLocation
|
||||
0x2816 smGetScreenFlowLocation
|
||||
0x2817 smGetHomeHubLocation
|
||||
0x2818 smGetHeroLeague
|
||||
0x2819 smCompleteMatchday
|
||||
0x281a smEndInterviewPeriod
|
||||
0x281b smHeroRemovedFromMatch
|
||||
0x281c smEpisodicUploadCheck
|
||||
0x281d smRetryEpisodicUpload
|
||||
0x281e smNotifyMatchNotPlayed
|
||||
0x281f matchFlowStart
|
||||
0x2820 matchFlowHalftime
|
||||
0x2821 matchFlowPostgame
|
||||
0x2822 matchFlowEnd
|
||||
0x2823 enterGameplay
|
||||
0x2824 leaveGameplay
|
||||
0x2825 forfeitMatch
|
||||
0x2826 matchSetType
|
||||
0x2827 simMatch
|
||||
0x2828 simStarted
|
||||
0x2829 simStopped
|
||||
0x282a fbStartFlowEvent
|
||||
0x282b stopSavedInput
|
||||
0x282c changeSonyStoreBrowseMode
|
||||
0x282d trialCheck
|
||||
0x282e gotoTrialUpsell
|
||||
0x754d retrieveManagerQuestData
|
||||
0x7560 futWidgetShow
|
||||
0x7561 futWidgetHide
|
||||
0x7562 futWidgetLoad
|
||||
0x7563 futWidgetUnload
|
||||
0x7567 inviteAcceptedFUT
|
||||
0x7568 futAddCriticalSection
|
||||
0x7569 futRemoveCriticalSection
|
||||
0x7572 exitDraftMode
|
||||
0x7579 useSavedMatchData
|
||||
0x757a useSavedMatchKits
|
||||
0x7580 exitSbcMode
|
||||
0x7587 setFUTServerEnvironment
|
||||
0x9cc1 discardTeamSheet
|
||||
0x9cc1 resetReady
|
||||
0x9cd0 showKeyboard
|
||||
@@ -1,11 +1,37 @@
|
||||
# Copy to .env in this directory. Required for remote deployment.
|
||||
#
|
||||
# OPENFUT_ADVERTISE — the address of THIS host as seen from the game machine
|
||||
# (105). The responders advertise it to the client for every next hop (Blaze,
|
||||
# roster, UTAS, POW). Compose refuses to start without it.
|
||||
OPENFUT_ADVERTISE=10.10.0.120
|
||||
# OPENFUT_ADVERTISE — the IP address of THIS host as seen from the game machine
|
||||
# (105). Responders advertise it for Blaze, UTAS, telemetry, and QoS.
|
||||
OPENFUT_ADVERTISE=203.0.113.10 # <- REPLACE with this host's LAN IP
|
||||
|
||||
# OPENFUT_BIND — address the listeners bind inside the container.
|
||||
# Defaults to 0.0.0.0 (container-facing); the original all-on-localhost flow
|
||||
# uses the loopback default baked into the responders when unset.
|
||||
OPENFUT_BIND=0.0.0.0
|
||||
|
||||
# FIFA17's roster verifier accepts dNSName SANs but ignores iPAddress SANs.
|
||||
# Advertise the certificate's DNS identity, then resolve that one hostname to
|
||||
# OPENFUT_ADVERTISE on the client without changing the URL or certificate.
|
||||
OPENFUT_ROSTER_HOST=winter15.gosredirector.ea.com:8081
|
||||
|
||||
# OPENFUT_SERVERS — which Python responders Docker runs (space/comma separated).
|
||||
# Default (unset) = the server-side set: "blaze roster utas pow".
|
||||
#
|
||||
# This host is the SERVER (.120). Docker runs ONLY components that have NOT been
|
||||
# migrated to a Rust host. During migration the Rust hosts (redirector / roster
|
||||
# / utas) run OUTSIDE Docker; as each Python component is replaced, remove its
|
||||
# name here so the two never serve the same role at once.
|
||||
# blaze Blaze redirector + main + nucleus (bundled) :42127 :42130 :42131
|
||||
# roster FUT roster-update XML :8081
|
||||
# utas FUT/UTAS RS4 API :8099
|
||||
# (Rust utas-host still proxies its non-/club routes here for now)
|
||||
# pow POW / EASFC :8094 (+ content :8080)
|
||||
# lsx Origin LSX bootstrap :4216
|
||||
# CLIENT-SIDE: LSX runs on the game machine (.105) with autopatch, NOT
|
||||
# on this server. Leave it OUT unless client and server share one box.
|
||||
#
|
||||
# Example — Rust already owns roster, so Docker should not also serve it:
|
||||
# OPENFUT_SERVERS=blaze utas pow
|
||||
# When you drop a component, also stop advertising / DNAT'ing its port to this
|
||||
# container so the client is routed to the Rust host instead.
|
||||
#OPENFUT_SERVERS=blaze roster utas pow
|
||||
|
||||
@@ -37,17 +37,21 @@ RUN set -eu; \
|
||||
|
||||
COPY data/ /app/data/
|
||||
|
||||
# Redirector TLS cert (CN/SAN = winter15.gosredirector.ea.com). ProtoSSL
|
||||
# cert-verify is patched client-side, so a self-signed cert is fine. The pair is
|
||||
# git-ignored (*.pem/*.key); regenerate if absent so a fresh checkout builds
|
||||
# without extra steps.
|
||||
# Redirector/roster TLS certificate. FIFA17's roster verifier compares only
|
||||
# dNSName SAN entries, so deployment advertises winter15.gosredirector.ea.com
|
||||
# through OPENFUT_ROSTER_HOST and resolves that hostname on the client. The
|
||||
# entrypoint validates this stable certificate; it never reissues it for an IP
|
||||
# SAN that the verifier ignores.
|
||||
#
|
||||
# OpenSSL remains in the image both to create the git-ignored keypair on a fresh
|
||||
# checkout and to validate the configured DNS identity at startup.
|
||||
RUN apt-get update && apt-get install -y --no-install-recommends openssl && \
|
||||
rm -rf /var/lib/apt/lists/*
|
||||
RUN if [ ! -s tools/redir_cert.pem ] || [ ! -s tools/redir_key.pem ]; then \
|
||||
apt-get update && apt-get install -y --no-install-recommends openssl && \
|
||||
openssl req -x509 -newkey rsa:2048 -nodes \
|
||||
-keyout tools/redir_key.pem -out tools/redir_cert.pem \
|
||||
-days 3650 -subj "/CN=winter15.gosredirector.ea.com" \
|
||||
-addext "subjectAltName=DNS:winter15.gosredirector.ea.com,DNS:*.gosredirector.ea.com,DNS:*.ea.com" && \
|
||||
rm -rf /var/lib/apt/lists/*; \
|
||||
-addext "subjectAltName=DNS:winter15.gosredirector.ea.com,DNS:*.gosredirector.ea.com,DNS:*.ea.com,IP:127.0.0.1"; \
|
||||
fi
|
||||
|
||||
# Bake a dataset manifest so every image is self-identifying.
|
||||
|
||||
@@ -3,9 +3,9 @@
|
||||
# cp .env.example .env # set OPENFUT_ADVERTISE to THIS host's LAN IP
|
||||
# docker compose up -d --build
|
||||
#
|
||||
# Brings up the 5 responders the game dials. OPENFUT_ADVERTISE is the address
|
||||
# the servers hand the client (105) for every next hop (Blaze, roster, UTAS,
|
||||
# POW) and is required — there is no silent loopback fallback in remote mode.
|
||||
# Brings up the 5 responders the game dials. OPENFUT_ADVERTISE is the server IP
|
||||
# handed out for Blaze, UTAS, telemetry, and QoS; OPENFUT_ROSTER_HOST is the
|
||||
# certificate DNS identity handed out for roster HTTPS.
|
||||
#
|
||||
# The client (105) still needs its first-hop redirect (hook or DNAT) plus
|
||||
# autopatch.py running locally; see client_arm.sh and the FIFARUNBOOK.
|
||||
@@ -24,7 +24,10 @@ services:
|
||||
OPENFUT_BIND: "${OPENFUT_BIND:-0.0.0.0}"
|
||||
# Address advertised to the client for the next hop. MUST be this host's
|
||||
# LAN IP as seen from the game machine (105). Required (see .env.example).
|
||||
OPENFUT_ADVERTISE: "${OPENFUT_ADVERTISE:?set OPENFUT_ADVERTISE in .env to this host's LAN IP, e.g. 10.10.0.120}"
|
||||
OPENFUT_ADVERTISE: "${OPENFUT_ADVERTISE:?set OPENFUT_ADVERTISE in .env to this host's LAN IP, e.g. 203.0.113.10}"
|
||||
# FIFA17 roster TLS matches only certificate dNSName SANs. The client must
|
||||
# resolve this hostname to OPENFUT_ADVERTISE.
|
||||
OPENFUT_ROSTER_HOST: "${OPENFUT_ROSTER_HOST:-winter15.gosredirector.ea.com:8081}"
|
||||
# POW content advertises port 8080 by default, which collides with the
|
||||
# openfut-core publish on this host. Remap it to 8085 on the host and
|
||||
# advertise the remapped endpoint.
|
||||
@@ -36,10 +39,14 @@ services:
|
||||
FUT_PROFILE_ROOT: "/state/accounts"
|
||||
FUT_SETTINGS: "off"
|
||||
FUT_MODES: "1"
|
||||
# Which Python responders this SERVER runs. Default excludes lsx (that is
|
||||
# a client-side responder — see below). Drop a name once it is migrated to
|
||||
# a Rust host (run outside Docker) so the two never overlap. See .env.example.
|
||||
OPENFUT_SERVERS: "${OPENFUT_SERVERS:-blaze roster utas pow}"
|
||||
volumes:
|
||||
- "../state:/state"
|
||||
ports:
|
||||
- "4216:4216" # LSX (Origin bootstrap)
|
||||
- "4216:4216" # LSX — CLIENT-SIDE (.105); only used if lsx is enabled for all-on-one-box
|
||||
- "42127:42127" # Blaze redirector (TLS)
|
||||
- "42130:42130" # Blaze main
|
||||
- "42131:42131" # Nucleus OAuth stub
|
||||
|
||||
@@ -8,25 +8,39 @@
|
||||
# autopatch.py is NOT run here: it patches the FIFA17.exe process memory and must
|
||||
# run on the box the game runs on.
|
||||
#
|
||||
# Address behaviour is driven by two env vars (see each responder):
|
||||
# OPENFUT_BIND bind address for every listener (container: 0.0.0.0)
|
||||
# OPENFUT_ADVERTISE address handed to the client for the next hop
|
||||
# (the server's LAN IP, e.g. 10.10.0.120)
|
||||
# Address behaviour is driven by three env vars (see each responder):
|
||||
# OPENFUT_BIND bind address for every listener (container: 0.0.0.0)
|
||||
# OPENFUT_ADVERTISE IP address handed out for Blaze, UTAS, telemetry, and QoS
|
||||
# OPENFUT_ROSTER_HOST certificate DNS host:port handed out for roster HTTPS
|
||||
# ============================================================================
|
||||
set -uo pipefail
|
||||
cd "$(dirname "$(readlink -f "$0")")/tools"
|
||||
|
||||
BIND="${OPENFUT_BIND:-0.0.0.0}"
|
||||
ADV="${OPENFUT_ADVERTISE:?OPENFUT_ADVERTISE must be set to the server LAN IP (e.g. 10.10.0.120)}"
|
||||
ADV="${OPENFUT_ADVERTISE:?OPENFUT_ADVERTISE must be set to the server LAN IP (e.g. 203.0.113.10)}"
|
||||
ROSTER_HOST="${OPENFUT_ROSTER_HOST:-winter15.gosredirector.ea.com:8081}"
|
||||
export OPENFUT_BIND="$BIND"
|
||||
export OPENFUT_ADVERTISE="$ADV"
|
||||
export OPENFUT_ROSTER_HOST="$ROSTER_HOST"
|
||||
# POW keys advertised by blaze must also point at the server, not loopback.
|
||||
export POW_HOST="${POW_HOST:-$ADV:8094}"
|
||||
export POW_CONTENT_HOST="${POW_CONTENT_HOST:-$ADV:8080}"
|
||||
export POW_ADDR="${POW_ADDR:-$BIND:8094}"
|
||||
export POW_CONTENT_ADDR="${POW_CONTENT_ADDR:-$BIND:8080}"
|
||||
|
||||
echo "[openfut] bind=$BIND advertise=$ADV"
|
||||
echo "[openfut] bind=$BIND advertise=$ADV roster=$ROSTER_HOST"
|
||||
|
||||
# FIFA17's roster verifier compares only dNSName SAN entries. It ignores a valid
|
||||
# iPAddress SAN when the advertised URL contains an IP literal, so certificate
|
||||
# regeneration cannot fix that URL. Keep the certificate stable and fail startup
|
||||
# if the configured roster hostname is not already one of its DNS identities.
|
||||
CERT=redir_cert.pem
|
||||
ROSTER_NAME="${ROSTER_HOST%%:*}"
|
||||
if ! openssl x509 -in "$CERT" -noout -checkhost "$ROSTER_NAME" >/dev/null 2>&1; then
|
||||
echo "[openfut] FATAL: TLS cert does not cover roster hostname $ROSTER_NAME" >&2
|
||||
exit 1
|
||||
fi
|
||||
echo "[openfut] roster certificate matches $ROSTER_NAME; fingerprint: $(openssl x509 -in "$CERT" -noout -fingerprint -sha256)"
|
||||
|
||||
# name script extra-env
|
||||
declare -a SERVERS=(
|
||||
@@ -37,10 +51,40 @@ declare -a SERVERS=(
|
||||
"pow|pow_server.py|-"
|
||||
)
|
||||
|
||||
# ── Component selection ──────────────────────────────────────────────────────
|
||||
# OPENFUT_SERVERS picks which Python responders run (space- or comma-separated).
|
||||
# This container is the SERVER side (.120). It serves ONLY components that have
|
||||
# NOT been migrated to a Rust host — as each moves to Rust (which runs OUTSIDE
|
||||
# Docker during migration), drop its name so the two never serve the same role.
|
||||
# blaze Blaze redirector + main + nucleus (bundled) :42127 :42130 :42131
|
||||
# roster FUT roster-update XML :8081
|
||||
# utas FUT/UTAS RS4 API :8099
|
||||
# (the Rust utas-host currently reverse-proxies its non-/club routes
|
||||
# back here, so keep this enabled until UTAS is fully migrated)
|
||||
# pow POW / EASFC :8094 (+ content :8080)
|
||||
# lsx Origin LSX bootstrap :4216
|
||||
# CLIENT-SIDE — LSX runs on the game machine (.105) with autopatch,
|
||||
# NOT on the server. Excluded by default; enable ONLY for an
|
||||
# all-on-one-box dev setup where client and server share a host.
|
||||
OPENFUT_SERVERS="${OPENFUT_SERVERS:-blaze roster utas pow}"
|
||||
want=" ${OPENFUT_SERVERS//,/ } "
|
||||
known=" lsx blaze roster utas pow "
|
||||
for w in $want; do
|
||||
case "$known" in
|
||||
*" $w "*) ;;
|
||||
*) echo "[openfut] unknown component '$w' in OPENFUT_SERVERS (valid: lsx blaze roster utas pow)" >&2; exit 2 ;;
|
||||
esac
|
||||
done
|
||||
echo "[openfut] servers=$OPENFUT_SERVERS"
|
||||
|
||||
pids=()
|
||||
names=()
|
||||
for entry in "${SERVERS[@]}"; do
|
||||
IFS='|' read -r name script env <<<"$entry"
|
||||
case "$want" in
|
||||
*" $name "*) ;;
|
||||
*) echo "[openfut] skipping $name (not in OPENFUT_SERVERS)"; continue ;;
|
||||
esac
|
||||
envprefix=""; [ "$env" != "-" ] && envprefix="env $env"
|
||||
echo "[openfut] starting $name ($script)"
|
||||
# shellcheck disable=SC2086
|
||||
@@ -49,6 +93,11 @@ for entry in "${SERVERS[@]}"; do
|
||||
names+=("$name")
|
||||
done
|
||||
|
||||
if [ "${#pids[@]}" -eq 0 ]; then
|
||||
echo "[openfut] OPENFUT_SERVERS selected no components; nothing to run" >&2
|
||||
exit 2
|
||||
fi
|
||||
|
||||
# Propagate SIGTERM/SIGINT to children so `docker stop` is clean.
|
||||
term() {
|
||||
echo "[openfut] shutting down…"
|
||||
|
||||
@@ -347,10 +347,17 @@ The client's own dialog names the class: "Search Type: Consumables Search".
|
||||
times a session with the PLAYER stat set, so the panel read seven zeros and never
|
||||
proceeded. Two rounds of item-shape work sat unrequested for want of a counter.
|
||||
2. THE ROUTE IS GET club/consumables/<category>. Not club?type=, which a previous
|
||||
round shipped four arms for, and not the "/consumables/%s" template in .rdata,
|
||||
which the client has still never used. Worse, that path is a /club PREFIX, so it
|
||||
fell through to the generic route and the consumables screen was answered with the
|
||||
194-card player list.
|
||||
round shipped four arms for. That path is a /club PREFIX, so a naive router
|
||||
falls it through to the generic route and answers the consumables screen with
|
||||
the 194-card player list.
|
||||
|
||||
**CORRECTED 2026-08-21.** This item used to add "and not the
|
||||
`/consumables/%s` template in .rdata, which the client has still never used".
|
||||
That is false, and the same sentence is in commit `ccb736f`. It IS exactly
|
||||
that template: action row 9 `ConsumablesSearch` carries base index 3 =
|
||||
`ut/%s/club`, and `FUN_1801308c0` appends `/consumables/%s`. The base was
|
||||
`ut/%s/club` all along, which is why the observed URL and the template look
|
||||
like different things and are not.
|
||||
3. THE ELEMENT IS A STACK WRAPPER, NOT AN ITEM. FutConsumablesSearchServerResponse
|
||||
(RS4 literal 0x1802222f8, factory 0x180130a10, vtable 0x180222200, deser +0x08 =
|
||||
0x180130d10, 6873 chars) reads itemData(0x16b) at the root like the club list, but
|
||||
@@ -402,21 +409,40 @@ the same mapping: balls 37, kits 35, stadium 36, badges 39, league logos 40.
|
||||
|
||||
# Club items: what the research established, 2026-08-05
|
||||
|
||||
Researched after a guessed field crashed the client. Facts first, and the one thing
|
||||
still unknown is named as unknown.
|
||||
> **SUPERSEDED 2026-08-21 in part.** `docs/plan-2026-08-06-card-subsystem.md` is
|
||||
> the authority for club items and for the `itemState` vocabulary; where this
|
||||
> file and that one disagree, that one wins. The corrections are applied inline
|
||||
> below and marked. The subtype question this section calls UNKNOWN is ANSWERED.
|
||||
|
||||
Researched after a guessed field crashed the client. Facts first.
|
||||
|
||||
## VERIFIED IN BINARY
|
||||
|
||||
1. THE CARDTYPE MAP IS EXACT. FUN_1800d8330 (714 chars, read in full) returns cardtype
|
||||
9 for cardsubtypeid 0x1e, 0x1f, 0x91..0x96, 0xe7..0xe9 and 0xec, and nothing else.
|
||||
fcc_misccards carries cardsubtype 231 = 0xe7, which anchors the 0xe7..0xe9 block to
|
||||
misc cards. That leaves 0x1e, 0x1f and 0x91..0x96 for badges, kits, stadia, balls
|
||||
and league logos.
|
||||
2. ITEMSTATE CARRIES THE EQUIPPED STATE. The enum table at 0x180229d20 (stride 0x10)
|
||||
is: WAITING_FOR_GAME, inGame, forSale, offered, activeBadge, activeHomeKit,
|
||||
activeAwayKit, activeBall, activeStadium, active. So an EQUIPPED club item is not a
|
||||
misc cards.
|
||||
|
||||
**CORRECTED 2026-08-21.** The first half is right; the inference that followed
|
||||
it was wrong. It read "that leaves 0x1e, 0x1f and 0x91..0x96 for badges, kits,
|
||||
stadia, balls and league logos". In fact `0x91..0x96` are TROPHIES, and three
|
||||
of the five club families are **cardtype 7, not 9** — `FUN_1800d8330` contains
|
||||
`case 9: case 10: case 0xb: return 7;`. Only ball (0x1e) and league logo
|
||||
(0x1f) are cardtype 9.
|
||||
2. ITEMSTATE CARRIES THE EQUIPPED STATE. So an EQUIPPED club item is not a
|
||||
different subtype, it is the same item with itemState set to one of those five.
|
||||
"free" is correct for owned-but-not-equipped, which is what we send.
|
||||
|
||||
**CORRECTED 2026-08-21.** The table starts at **`0x180229cc0`**, not
|
||||
`0x180229d20` — the recorded address points into the MIDDLE of it, which is why
|
||||
only ten rows were seen. The full vocabulary is TWELVE rows; the six missing
|
||||
from the reading below are `invalid`, `free`, `WAITING_FOR_GAME`, `inGame`,
|
||||
`forSale` and `offered`. Two further consequences the ten-row reading hid:
|
||||
`WAITING_FOR_GAME` and `inGame` are genuine ALIASES (both decode to 2), and
|
||||
OMITTING the key yields `0` = `invalid`, which is NOT the same as `free` — an
|
||||
item left at 0 fails the squad builder's `state == 1 || state == 2` test. The
|
||||
match is also CASE-SENSITIVE (measured 2026-08-21: the comparator is
|
||||
`msvcr120.dll+0x3c330`, a plain `strncmp` with no case folding), so the casing
|
||||
in the table is a contract. See `openfut-adapter-fifa17/src/fut/item_state.rs`.
|
||||
3. CLUB ITEMS HAVE NO CATEGORY GROUP TABLE. Consumables have one at 0x180203260 (seven
|
||||
codes: training, contracts, fitness, healing, playStyle, managerLeagueModifier,
|
||||
position) and staff have one at 0x180203310 (five codes). There is no equivalent
|
||||
@@ -427,16 +453,30 @@ still unknown is named as unknown.
|
||||
type=ball, type=equippables (the combined customisation view). Not the plural stat
|
||||
names, and not a club/<family> path.
|
||||
|
||||
## STILL UNKNOWN, AND NOT GUESSED
|
||||
## ANSWERED 2026-08-06 (was "STILL UNKNOWN, AND NOT GUESSED")
|
||||
|
||||
Which of 0x1e, 0x1f, 0x91..0x96 means ball versus stadium versus badge versus kit.
|
||||
It is in none of the 149 dumped tables, there is no group table, and cardtype 9 has NO
|
||||
arm in the merge, so a wrong subtype cannot announce itself the way a coach's "DB
|
||||
Error" does. Two ways to settle it, in order of preference:
|
||||
a. more RE: find the consumer that switches on subtype for a club item, most likely
|
||||
in the equip path that writes itemState = activeBadge and friends;
|
||||
b. FUT_CLUBITEMS=probe:<family>, which serves ONE family as eight items, one per
|
||||
candidate subtype, so the screen names the right one.
|
||||
The question was "which of 0x1e, 0x1f, 0x91..0x96 means ball versus stadium versus
|
||||
badge versus kit". It was the wrong candidate set — three of the families are not
|
||||
in it at all. The settled map:
|
||||
|
||||
| family | cardsubtypeid | cardtype | how the caption resolves |
|
||||
|---|---|---|---|
|
||||
| kit | **9** | 7 | `TeamName_Abbr15_<teamid>` |
|
||||
| stadium | **10** | 7 | `StadiumName_<assetId>` |
|
||||
| badge | **11** | 7 | `TeamName_Abbr15_<teamid>` |
|
||||
| ball | **30** (0x1e) | 9 | no DB resolver; `FUT_UC_BALL` caption only |
|
||||
| league logo | **31** (0x1f) | 9 | by elimination |
|
||||
|
||||
`0x91..0x96` are TROPHIES, not club items. Route (a) of the two proposals above is
|
||||
what paid off — the consumer is the manager vtable slot `+0x498` =
|
||||
`FUN_180119bd0`, dispatched when `item+0x4c == 7`. Route (b),
|
||||
`FUT_CLUBITEMS=probe:<family>`, would have FAILED for three of the five families,
|
||||
because its candidate set never contained 9, 10 or 11.
|
||||
|
||||
Kit, badge and stadium are served by OpenFUT today. Ball and league logo are
|
||||
withheld: cardtype 9 has no database name resolver, so their name could only come
|
||||
from `localizedName` on the wire, and that is not established as safe to send.
|
||||
One residual probe remains, specified in `plan-2026-08-06-card-subsystem.md` §3.
|
||||
|
||||
## WHY THE CRASH HAPPENED, recorded so it is not repeated
|
||||
|
||||
@@ -447,3 +487,95 @@ taking its time and then dies. None of the three was needed to draw a card. Comp
|
||||
it, the response that crashed was type=equippables carrying 30 items across FIVE
|
||||
unverified subtypes at once, so even the crash taught us nothing about which subtype
|
||||
was wrong. Both are fixed: no extras, equippables withheld, one family per test.
|
||||
|
||||
---
|
||||
|
||||
# Field-map corrections (dated)
|
||||
|
||||
This file's earlier field notes predate the deserializer frame arithmetic. Where
|
||||
they disagree with the table in `plan-2026-08-06-card-subsystem.md` §2, that
|
||||
table wins — it is derived structurally (`FUN_18013fe00` builds the record as a
|
||||
stack struct and hands `&local_188` to the merge, so `record_offset = 0x188 - X`)
|
||||
rather than inferred backwards from an accessor.
|
||||
|
||||
```
|
||||
CORRECTED 2026-08-06 (live diff + deserializer frame arithmetic, record_off = 0x188 - X):
|
||||
+0x34 lastSalePrice (atom 0x185), published to Flash as BOUGHT_FOR
|
||||
+0x48 owners (atom 0x207, u8; constructor default 0)
|
||||
+0x49 TRADEABLE (atom 0x361 untradeable, u8, stored INVERTED; default 1)
|
||||
+0x54 discard LEVEL (3/2/1 by rating >= 0x4b / >= 0x41), NOT an itemType enum
|
||||
+0x5c itemState (atom 0x172 via FUN_180166660, u32)
|
||||
+0x88 playStyle (atom 0x23f via FUN_180136480; only 0xfb..0x111 map to 1..0x17)
|
||||
+0x90 loans (atom 0x19b) -- do not send; loans>0 with contract 0 greys MODIFY
|
||||
+0xbe amount (atom 0x1b, u8) for cardsubtypeid 250..273 (chemistry styles)
|
||||
+0xbf amount (atom 0x1b, u8) for the other consumable classes
|
||||
+0xd9 localizedName (atom 0x19c, 0x38 bytes) for cardtype 9; +0xbc (0x1f) for cardtype 7
|
||||
+0x111 description (atom 0xd1, 0x1f bytes) for cardtype 9; +0x10f for cardtype 7
|
||||
+0x30 is a CLIENT timestamp from FUN_1800d84e0(), not a wire field
|
||||
+0x60 pile is assigned by the owning list, not parsed; there is no 0x226 arm
|
||||
itemType (atom 0x173) is parsed into a heap string and never stored
|
||||
definitionId is NOT AN ATOM
|
||||
```
|
||||
|
||||
**`+0x60`, extended 2026-08-21.** "Assigned by the owning list, not parsed" is
|
||||
right. The pre-match kit selector gates on `+0x60 == 4` at `0x1801c34f2`, and no
|
||||
instruction in CardsDLL stores that constant immediately (29 stores, constants
|
||||
`{-2,0,1,908,0x3f800000}`), nor does FIFA17.exe across 79 MB.
|
||||
Tool: `fifa17-recon/tools/kit_gate_probe.py`.
|
||||
|
||||
**CORRECTED 2026-08-23 (live, pid 8793, read-only `/proc/PID/mem`).** The
|
||||
2026-08-21 entry went on to call the kit selector "a client dead end, not a
|
||||
missing wire field", on the grounds that "every OTHER input to that gate is
|
||||
already served". That conclusion is WITHDRAWN. It rested on two mistakes.
|
||||
|
||||
1. **`+0x60 == 4` does occur.** A live record reached the art-clone driver
|
||||
`FUN_1801c3480` holding `+0x4c == 2`, `+0x60 == 4`. So the value arrives by
|
||||
some path the immediate-store scan cannot see (register copy or computed),
|
||||
and "nothing can ever satisfy the gate" is false. What the static scan
|
||||
actually licenses is the narrower claim above.
|
||||
2. **cardtype 7 was never verified to be produced at all.** The probe annotates
|
||||
`cmp [rdi+0x4c], 7` with "<- we produce this". Nothing measured that. Its own
|
||||
live half showed `{1: players, 0: staff}` -- i.e. zero cardtype-7 records --
|
||||
and that was read as "the only thing missing is +0x60".
|
||||
|
||||
**What is actually measured now.** With the client parked on the kit selector,
|
||||
scanning all 3047 MiB of readable process memory for the exact u32 values the
|
||||
server sent:
|
||||
|
||||
```
|
||||
resident (record-shaped, sane fields):
|
||||
player resourceId 83906881 -> cardtype 1, itemState 1, teamid 243, +0x60 1
|
||||
staff resourceId 9000081 -> cardtype 2
|
||||
staff resourceId 3000083 -> cardtype 4, subtype 8
|
||||
staff resourceId 1000509 -> cardtype 2, subtype 4, teamid 241
|
||||
NOT resident, by resourceId AND by instance id, zero hits each:
|
||||
kit 6300006 / 100004874 (cardsubtypeid 9)
|
||||
kit 6400003 / 100004873 (cardsubtypeid 9)
|
||||
badge 6000005 / 100004875 (cardsubtypeid 11)
|
||||
stadium 6200000 / 100004876 (cardsubtypeid 10)
|
||||
```
|
||||
|
||||
The client fetched `?type=kit` at 17:50:09 this session and the host logged
|
||||
`total=2 emitted=2`. Both kits were delivered and NEITHER produced a record.
|
||||
Every cardtype-7 family is absent while cardtype 1/2/4 are resident.
|
||||
|
||||
So the blocker is upstream of the `+0x60` gate: no cardtype-7 record is ever
|
||||
created, therefore the club scan `FUN_1800d73d0` (`+0x4c==7 && +0x50==9 &&
|
||||
`+0x5c in {101,102}`) has nothing to match, `KIT_DESC` never fires, and
|
||||
`KITS_AVAILABLE` reads 0. Whether that is a bad wire shape (the cardtype-7 parse
|
||||
arm wants `name`/`localizedName`/`description`, which OpenFUT does not send) or
|
||||
cardtype-7 items being transient by design is NOT yet settled -- do not record
|
||||
either as fact.
|
||||
|
||||
**Method note.** `kit_gate_probe.py`'s live half is unreliable as written: on
|
||||
pid 8793 it printed "CardsDb is empty (no FUT session loaded)" while a byte scan
|
||||
found 1966 resident players. Its structural chain is stale, so its record counts
|
||||
(including the original "27 resident records") understate reality. Prefer the
|
||||
value scan until the chain is re-derived.
|
||||
|
||||
**`definitionId is NOT AN ATOM`, confirmed a fourth way 2026-08-21.** Every real
|
||||
atom name appears exactly once in CardsDLL's `.rdata` — `resourceId`,
|
||||
`cardsubtypeid`, `itemState`, `assetId`, `cardassetid`, `rareflag`, `owners`,
|
||||
`contract`, `discardValue`, `localizedName` — while `definitionId` is absent
|
||||
entirely. It is still sent on the live-proven player path; it is inert, not
|
||||
harmful, and has not been removed.
|
||||
|
||||
@@ -0,0 +1,406 @@
|
||||
# The client's complete UTAS route surface
|
||||
|
||||
Read out of the running client's own `.rdata` on 2026-08-21 (pid 6580) with
|
||||
`fifa17-recon/tools/url_template_probe.py`, then each route probed against
|
||||
staging. This bounds the server: FIFA 17 cannot ask for a route that is not in
|
||||
this list.
|
||||
|
||||
Staging's Python upstream is deliberately dead, so a `502` there means the Rust
|
||||
host does not own the route — which makes the coverage column a measurement
|
||||
rather than an audit of the source.
|
||||
|
||||
## Route templates in CardsDLL
|
||||
|
||||
`%s` is the sku segment, built from `game/%s` (`0x18021fac8`) → `game/fifa17`.
|
||||
|
||||
```
|
||||
ut/auth ut/delete/auth
|
||||
ut/%s/user ut/delete/%s/user ut/%s/user/list
|
||||
ut/%s/club ut/%s/clubUser
|
||||
ut/%s/item ut/%s/item/resource ut/delete/%s/item
|
||||
ut/%s/defid
|
||||
ut/%s/squad ut/delete/%s/squad ut/%s/squad/mode
|
||||
ut/%s/purchased ut/%s/store ut/v2/%s/store
|
||||
ut/%s/trade ut/delete/%s/trade
|
||||
ut/%s/tradePile ut/%s/watchList ut/delete/%s/watchList
|
||||
ut/%s/auctionhouse ut/%s/marketdata
|
||||
ut/%s/match ut/%s/sbs
|
||||
ut/%s/season ut/%s/season/user ut/%s/season/%%s/user
|
||||
ut/%s/season/%%s/reset ut/%s/season/friendly
|
||||
ut/%s/tournament ut/%s/tournament/user ut/delete/%s/tournament/user
|
||||
ut/%s/champion ut/%s/draft/mode
|
||||
ut/%s/leaderboards ut/%s/leaderboards/options
|
||||
ut/%s/activeMessage ut/%s/livemessage
|
||||
ut/%s/clientdata ut/%s/phishing ut/%s/captcha ut/%s/tfa
|
||||
```
|
||||
|
||||
Suffixes appended to the above, not standalone routes:
|
||||
`/consumables/%s`, `/items`, `/purchasegroup`, `/squadBuildingSets`,
|
||||
`/challenge/%d/squad`, `/choices/manager`, `/purchase/mode/%d/draft`,
|
||||
`/transfermarket?type=%s&start=%d&num=%d`.
|
||||
|
||||
## THE TRAP when reading this list
|
||||
|
||||
A literal in `.rdata` is a **fragment**, not necessarily a callable path. Probing
|
||||
fragments bare manufactures fake gaps. Every one of these looked unserved and was
|
||||
not:
|
||||
|
||||
| looked missing | actually |
|
||||
|---|---|
|
||||
| `clientdata` | real route is `clientdata/<key>`; served (`clientdata/userHubData` → 200) |
|
||||
| `purchasegroup` | a suffix of `store`; `store/purchasegroup/all` is served |
|
||||
| `sbs/challenges` | not a route; the real ones are `sbs/sets`, `sbs/setId/<n>/challenges`, `sbs/challenge/<n>` — all served |
|
||||
| `squadBuildingSets` | not a route in the oracle either |
|
||||
| `club/items` | `items/...` literals are ART ASSET paths, not UTAS |
|
||||
| `item` | only ever PUT (move/pile) and DELETE (quick-sell) |
|
||||
|
||||
Check a candidate gap against `tools/utas_server.py`'s regex table before
|
||||
believing it.
|
||||
|
||||
## Genuinely unserved, and why that is correct
|
||||
|
||||
* `squad/mode` — bare form is never used. The oracle only has Draft sub-paths
|
||||
(`squad/mode/draft/state`, `squad/mode/<n>/draft/choices/*`). Draft is out of
|
||||
scope, so this correctly stays on Python.
|
||||
|
||||
## Fixed by this measurement
|
||||
|
||||
Four handlers existed and were unreachable because `classify` never produced
|
||||
their route, so every request fell through to Python. This is a **recurring
|
||||
defect class** in `openfut-utas-host` — `season/list` and `watchList` were the
|
||||
first two, and their fix comments are still in the file:
|
||||
|
||||
| route | handler | was |
|
||||
|---|---|---|
|
||||
| `captcha` | `handle_static_ack`, returns the oracle's exact `{encodedImg,sequence,sizeBeforeEncode}` | fell to Python |
|
||||
| `tfa` / `livemessage` / `activeMessage` | `handle_static_ack`, `{}` | fell to Python |
|
||||
| `tournament/user` | `FeatureOffEmpty`, `{}` — the oracle's answer with `FUT_MODES` off | fell to Python |
|
||||
|
||||
`Route`'s own doc comment already claimed the first four as "Rust-owned
|
||||
UNCONDITIONAL", so the documentation had been wrong rather than the intent. All
|
||||
five are byte-identical to the oracle, so claiming them is parity, not new
|
||||
behaviour. Invisible in production (the upstream answers); a 502 on staging.
|
||||
|
||||
Two regression tests now pin the vocabularies —
|
||||
`every_static_ack_tail_is_actually_routed` and
|
||||
`the_disabled_mode_reads_are_all_claimed` — so a handler cannot go unreachable a
|
||||
fifth time.
|
||||
|
||||
## No consumable apply endpoint exists
|
||||
|
||||
Support level L5 for consumables was open, with an inherited note saying there is
|
||||
"no training/position/chemistry/manager-league endpoint at all". **The route
|
||||
table confirms it from the binary**: there is no apply/training/position/
|
||||
chemistry route anywhere in CardsDLL. The only owned-item mutations the client
|
||||
can express are:
|
||||
|
||||
```
|
||||
PUT ut/%s/item move / pile
|
||||
DELETE ut/%s/item/<id> quick sell
|
||||
POST ut/delete/%s/item bulk quick sell
|
||||
PUT ut/%s/squad squad write
|
||||
```
|
||||
|
||||
So applying a consumable is **not** a dedicated server route. If it reaches the
|
||||
server at all it must ride `PUT ut/%s/item`, and L5/L6 should be pursued by
|
||||
capturing that PUT's payload while applying a card — not by looking for an
|
||||
endpoint that does not exist.
|
||||
|
||||
## FUT task vocabulary (2026-08-21, live)
|
||||
|
||||
The client drives UTAS through named TASKS, not just URLs. The task-name table
|
||||
lives in CardsDLL `.rdata` as 0x20-byte inline slots holding MixedCase/UPPERCASE
|
||||
pairs (`tools/apply_route_search.py`, controls `tradePile`/`ut/%s/item`/`squad`
|
||||
all FOUND):
|
||||
|
||||
```
|
||||
ViewCards AssingCard(sic) ApplyCard ApplyCardByRes
|
||||
ActivateCard ConsumeCard DiscardCard DiscardCardByRes
|
||||
DiscardACard MoveCard MoveCardByRes SwapCard
|
||||
CreateMatch MatchReady DestroyMatch PlayGame ResetMatch KeepAlive
|
||||
LoadCategoryDetails LoadSetChallenges StartChallenge LoadSquadChallenge
|
||||
SaveSquadChallenge SubmitChallenge TagSets SetSbcData
|
||||
TournamentList TournamentTeams SetUserInfo GetHistorical SetTutData ...
|
||||
```
|
||||
|
||||
A descriptor table in `.data` pairs each name with a task id and a small setter
|
||||
thunk, e.g. `ApplyCard` id **0x0d** at `0x1802cb170`, `ApplyCardByRes` id **0x0e**
|
||||
at `0x1802cb1a0`. The thunks are `mov [rip+flag], cl; ret` (a per-task flag), NOT
|
||||
request builders, so the request is assembled elsewhere keyed by task id.
|
||||
|
||||
**So consumable application IS a first-class client action (`ApplyCard` /
|
||||
`ApplyCardByRes` / `ConsumeCard`), even though no `/apply` URL exists.** It
|
||||
therefore rides an existing route. Which one is a one-capture question, and the
|
||||
host now names every unclaimed request:
|
||||
|
||||
```
|
||||
utas-host owner=PYTHON route=passthrough method=GET path=/ut/... body_len=N
|
||||
```
|
||||
|
||||
## CONSUMABLE APPLY — LIVE_PROVEN (2026-08-21)
|
||||
|
||||
Captured end to end on staging, operator applying a bronze player contract:
|
||||
|
||||
```
|
||||
POST /ut/game/fifa17/item/resource/5001004
|
||||
{"apply":[{"id":100000003}]}
|
||||
```
|
||||
|
||||
| element | value | where |
|
||||
|---|---|---|
|
||||
| source consumable | resource id `5001004` (player contract, subtype 201) | **path** |
|
||||
| target item(s) | wire instance `100000003` (= squad slot 0 GK, resourceId 200389) | **body**, `apply[]` |
|
||||
| verb | `POST` | |
|
||||
|
||||
**There is no `/apply` endpoint** — the apply re-uses `ut/%s/item/resource`, which
|
||||
we already serve for **GET** (item-definition lookup). The **POST** verb on that
|
||||
path is the mutation, and nothing claimed it, so it fell through to Python. This
|
||||
is the wire form of the `ApplyCardByRes` task (id `0x0e`) -- "apply card **by
|
||||
res**ource" -- which is why the source is a definition id rather than an instance
|
||||
id.
|
||||
|
||||
`apply` is an ARRAY, so one consumable resource can name several targets in a
|
||||
single request. Whether the client ever batches is unobserved.
|
||||
|
||||
Corroborating UI evidence from the same session: applying to a PLAYER offered
|
||||
only the subtype-201 card and withheld both subtype-202 manager contracts,
|
||||
independently confirming the `201 = player_contract / 202 = manager_contract`
|
||||
split.
|
||||
|
||||
Fail-closed confirmed: with the upstream dead the request 502s and Core is left
|
||||
EXACTLY unchanged (coins, owned count, and the source card all identical).
|
||||
|
||||
### Not yet known
|
||||
* the **response shape** the client expects on success;
|
||||
* the **effect** -- how many matches a contract grants. Our own catalog carries
|
||||
`contract: 7` for `5001004`, documented as "the number of matches the card
|
||||
grants", but that is observed profile data, i.e. INFERRED, not reversed. No
|
||||
effect is implemented on that basis.
|
||||
|
||||
## Consumables category `development` is unmapped (client really asks)
|
||||
|
||||
The new passthrough/route logging caught the client requesting
|
||||
|
||||
```
|
||||
GET /ut/game/fifa17/club/consumables/development -> outcome=unknown_category emitted=0
|
||||
```
|
||||
|
||||
`consumable_families_for_category` has no `development` arm, so the screen is
|
||||
served empty. The client demonstrably asks for it, which is exactly the condition
|
||||
that function's own doc says should add an arm. Which families it should map to
|
||||
is NOT guessed here.
|
||||
|
||||
### Success contract — STATIC_REVERSED (2026-08-22)
|
||||
|
||||
The apply completion handler is `0x180035520`:
|
||||
|
||||
```asm
|
||||
0x180035529 mov ecx,DWORD PTR [rdx+0x1c] ; the ONLY field tested
|
||||
0x18003552c test ecx,ecx
|
||||
0x18003552e jne 0x18003555c ; nonzero -> FAILURE
|
||||
0x18003553c lea rdx,[EVENT_CARDS_APPLY_CARD_SUCCESS] ; 0x1801f37f0
|
||||
0x180035569 lea rdx,[EVENT_CARDS_APPLY_CARD_FAILURE] ; 0x1801f3810
|
||||
```
|
||||
|
||||
It tests exactly one 32-bit field — the transport code — and **never inspects
|
||||
the body**. `EVENT_CARDS_APPLY_CARD_SUCCESS` has precisely one reference in the
|
||||
module, so this is the whole verdict path.
|
||||
|
||||
This does NOT resemble the move ack (`0x180128600`), which builds per-item
|
||||
verdict records and reports FAILURE on an EMPTY vector. The "`{}` is
|
||||
known-broken" precedent is specific to that route and does not transfer here.
|
||||
|
||||
Supporting structure: the response object's constructor `0x1800a4ce0` installs
|
||||
vtable `0x1801fb5b0` and initialises its record vector at `+0x50`/`+0x58`/`+0x60`
|
||||
EMPTY (0x20-byte elements); `0x1800682b0` is the matching destructor, freeing
|
||||
that range with a 0x20 stride. An empty result is therefore a legal parsed state
|
||||
for this response, unlike the move.
|
||||
|
||||
Registration site: `0x1800357da` installs the completion handler and
|
||||
`0x1800357e5` the response factory, back to back.
|
||||
|
||||
**Probe response**: `{"itemData":[]}` — an object root (matching how the oracle's
|
||||
method-agnostic `item/resource` route answers this path) containing an empty
|
||||
vector (legal per the constructor). Labelled a PROBE. The client's SUCCESS only
|
||||
requires transport code 0.
|
||||
|
||||
## Consumables categories — nine, not seven (2026-08-22)
|
||||
|
||||
Correcting the earlier claim that the two formation-modifier families "have no
|
||||
group code, so no segment can reach them — the client's own gap". The client's
|
||||
own switch says otherwise. Literal table at `0x1801f5a38` (under
|
||||
`MyClubAdapterClass` / `CONSUMABLE_TYPE`); switch at `0x180048820` indexing by
|
||||
`enum + 1` through the byte table at `0x180048a90` into the case table at
|
||||
`0x180048a6c`:
|
||||
|
||||
| CONSUMABLE_TYPE | segment |
|
||||
|---|---|
|
||||
| **-1 (unset)** | `development` |
|
||||
| 1, 2 | `contracts` |
|
||||
| 3 | `healing` |
|
||||
| 4 | `fitness` |
|
||||
| **16** | `formation` |
|
||||
| 17 | `position` |
|
||||
| 23 | `playStyle` |
|
||||
| 24 | `managerLeagueModifier` |
|
||||
| 0, 5..15, 18..22 | `training` (switch default) |
|
||||
|
||||
`formation` was a SERVER gap, not a client one. `development` is the type-unset
|
||||
bucket — index 0 of an `enum + 1` table — i.e. the unfiltered view; the eight
|
||||
typed segments already reach all thirteen families exactly once, so it owns no
|
||||
family privately and maps to their union.
|
||||
|
||||
## Contract effect — the `contract: 7` inference is REFUTED at the source
|
||||
|
||||
Do not implement a contract effect from the catalog's `contract: 7`.
|
||||
|
||||
`fifa17-recon/tools/fut_store.py:232` — the generic `_item()` factory that builds
|
||||
EVERY item the oracle serves — hardcodes:
|
||||
|
||||
```python
|
||||
"playStyle": 250,
|
||||
"contract": 7,
|
||||
"fitness": 99,
|
||||
```
|
||||
|
||||
These are blanket placeholders on every item, players and consumables alike. The
|
||||
staging squad's GK reads back `contract 7 / fitness 99 / playStyle 250`: the same
|
||||
three constants. So the `contract: 7` carried in the production catalog for
|
||||
resource 5001004 is **our own oracle placeholder round-tripped through an
|
||||
observed profile**, not an EA value. Its evidence level is not INFERRED; it is
|
||||
KNOWN-BOGUS as a source of the effect.
|
||||
|
||||
### What the client's own table does say
|
||||
|
||||
`fcc_contractcards` (13 rows) is NOT amount-less, contrary to an earlier note
|
||||
here. Columns: `carddbid, cardsubtype, weightrare, cardassetid, gold, rating,
|
||||
bronze, silver`.
|
||||
|
||||
| rating | player (201) | manager (202) | gold | silver | bronze |
|
||||
|---|---|---|---|---|---|
|
||||
| 50 | 5001001 | 5001007 | 1 | 2 | 8 |
|
||||
| 65 | 5001002 | 5001008 | 8 | 10 | 10 / 8 |
|
||||
| 80 | 5001003 | 5001009 | 13 | 11 | 15 / 11 |
|
||||
| 60 | 5001004 | 5001010 | 3 | 6 | 15 |
|
||||
| 70 | 5001005 | 5001011 | 18 | 24 | 20 / 18 |
|
||||
| 90 | 5001006 | 5001012 | 28 | 24 | 28 / 24 |
|
||||
| 90 | 5001013 | — | 99 | 99 | 99 |
|
||||
|
||||
Compare the sibling `fcc_healingcards`, which shares `carddbid, cardsubtype,
|
||||
weightrare, cardassetid, rating` and differs only by carrying a single `amount`.
|
||||
So `weightrare` is the drop weight and the differing column(s) are the effect
|
||||
payload — which would make gold/silver/bronze a per-target-tier amount.
|
||||
|
||||
AGAINST that reading: the values are not monotonic across tiers (5001005 is gold
|
||||
18, silver 24, bronze 20; 5001003 is gold 13, silver 11, bronze 15), which is
|
||||
odd for an amount and unremarkable for a weight. Note also that **no column of
|
||||
5001004 equals 7**, so nothing here explains the placeholder either way.
|
||||
|
||||
Unresolved, and NOT to be guessed: the fcc tables are loaded by `FIFA17.exe`, not
|
||||
CardsDLL (the table-name and column literals are absent from the DLL), so the
|
||||
reader that would settle amount-vs-weight lives in the EXE. Status stays
|
||||
**EFFECT_UNKNOWN**.
|
||||
|
||||
## Post-ACK behaviour — OUTCOME B, LIVE_PROVEN (2026-08-22)
|
||||
|
||||
Captured with the staging probe answering `200 {"itemData":[]}` and mutating
|
||||
nothing:
|
||||
|
||||
```
|
||||
T0 POST /ut/game/fifa17/item/resource/5001004 {"apply":[{"id":100000003}]}
|
||||
T1 200 {"itemData":[]}
|
||||
T2 callback -> SUCCESS (no failure event; ZERO ut/delete/auth; session alive)
|
||||
T4 GET club/consumables/contracts <- refresh of the SOURCE list
|
||||
T5 GET club/consumables/development
|
||||
T6 GET squad/active <- refresh of the TARGET
|
||||
T7 no second mutation of any kind
|
||||
```
|
||||
|
||||
So of the candidate protocols:
|
||||
|
||||
```
|
||||
B) POST resource -> ACK -> client performs GET refresh
|
||||
-> the SERVER is expected to have mutated state
|
||||
```
|
||||
|
||||
Ruled out by observation: (A) the response carries the modified state — the body
|
||||
was empty and the client was satisfied; (C) a follow-up generic PUT/item — none
|
||||
was sent; (D) another route performs the mutation — nothing else was called.
|
||||
|
||||
Three consequences.
|
||||
|
||||
1. **The success verdict is transport-only, confirmed live.** The static read of
|
||||
`0x180035520` said the body is never inspected; an empty `itemData` produced a
|
||||
clean success and a surviving session, which is that prediction holding.
|
||||
2. **The server owns the effect entirely.** The client does not compute one; it
|
||||
re-reads. This is the good failure mode: a wrong server-side effect cannot be
|
||||
masked by client-side optimism, and the refresh will always show server truth.
|
||||
Here the refresh correctly showed `contracts copies=3` and an unchanged squad,
|
||||
because the probe consumed nothing.
|
||||
3. **There is no client-side amount to harvest.** Since the client never renders
|
||||
an optimistic "+N games" of its own, the live path cannot reveal the grant
|
||||
size. The number the client DISPLAYS on a contract card comes from the wire
|
||||
`contract` atom (0xb8 -> record+0x8c; see `fut_consumables.py`, which notes
|
||||
categories 2 and 3 ignore `amount` and read `contract`) — i.e. the server
|
||||
tells the client what the card is worth.
|
||||
|
||||
That last point matters for honesty: our oracle has been sending the placeholder
|
||||
`7` for that atom, so every contract card this project has ever shown a player
|
||||
said "7" because WE said 7. Recovering EA's real value is not reachable from the
|
||||
client's behaviour; it needs the `FIFA17.exe` reader of `fcc_contractcards`, or
|
||||
it becomes an explicit design decision. Status: **EFFECT_UNKNOWN**.
|
||||
|
||||
### Boundary status
|
||||
|
||||
| aspect | status |
|
||||
|---|---|
|
||||
| route, method, source encoding, target encoding | LIVE_PROVEN |
|
||||
| success condition (`[obj+0x1c] == 0`, body ignored) | STATIC_REVERSED + LIVE_CONFIRMED |
|
||||
| response shape accepted by the client | LIVE_PROVEN (`{"itemData":[]}`, session survived) |
|
||||
| post-ACK protocol | LIVE_PROVEN — outcome B |
|
||||
| batching | UNPROVEN — refused, never guessed |
|
||||
| contract effect / grant size | UNKNOWN (placeholder source refuted) |
|
||||
| source instance selection with multiple copies | UNDETERMINED (only 1 copy owned) |
|
||||
|
||||
## Consumable QUICK-SELL is PUT item/resource — LIVE_PROVEN (2026-08-22)
|
||||
|
||||
Captured on staging when the operator quick-sold a Position Modifier from the
|
||||
consumables screen:
|
||||
|
||||
```
|
||||
PUT /ut/game/fifa17/item/resource/5003068 body_len=0
|
||||
```
|
||||
|
||||
So `ut/<sku>/item/resource/<resourceId>` carries THREE verbs, and this is the
|
||||
third:
|
||||
|
||||
| verb | meaning |
|
||||
|---|---|
|
||||
| `GET` | item-definition lookup (`defs_route` parity) |
|
||||
| `POST` | apply the consumable (`ApplyCardByRes`, body `{"apply":[{"id":N}]}`) |
|
||||
| `PUT` | **quick-sell the consumable**, EMPTY body |
|
||||
|
||||
Note it is keyed by **resourceId**, i.e. the STACK, not by an owned instance
|
||||
id — unlike the player quick-sell, which is `DELETE ut/<sku>/item/<instanceId>`
|
||||
and is retail-proven in production. That asymmetry follows the consumables
|
||||
screen's own model: the UI entity there is a stack, not a card.
|
||||
|
||||
Neither stack has ever served this route. The Python oracle maps
|
||||
`item/resource` method-agnostically to `defs_route`, so a PUT would get a
|
||||
definition list and HTTP 200 while nothing was sold — the client would believe
|
||||
the sale succeeded. On staging the oracle is deliberately dead, so it 502'd and
|
||||
Core was left untouched (coins 29843976, owned 1993, consumables 17).
|
||||
|
||||
### Consequence for production
|
||||
|
||||
Production's oracle IS alive, so today a consumable quick-sell there would reach
|
||||
Python, return 200 from `defs_route`, and mutate nothing — the client would show
|
||||
a successful sale that never happened. That is a second, independent reason not
|
||||
to quick-sell consumables in production until this route is implemented in Rust.
|
||||
|
||||
### UNKNOWN, not to be guessed
|
||||
|
||||
* Does an empty-body PUT sell ONE copy or the WHOLE stack? The request carries no
|
||||
quantity, and both readings fit. A stack of 2 at 38 is either +38 or +76.
|
||||
* Which owned instance is consumed when several share the resourceId.
|
||||
* What response the client requires (the player path's ack shape may not apply).
|
||||
@@ -424,6 +424,25 @@ Chemistry/rating/nation/league-count constraints (`teamChemistry 0x307`, `starRa
|
||||
generically as `{eligibilityKey, eligibilityOperation, eligibilityValue}` triples, **not** as
|
||||
named scalar fields on the record. **FREEZE-RISK: elgReq must be a JSON array of objects.**
|
||||
|
||||
> **2026-08-19 — `eligibilityKey`/`eligibilityOperation` are LOCALIZATION ORDINALS, not the
|
||||
> atom hex ids above.** Reversed from the pinned CardsDLL (`4706a881…`). The client's sole
|
||||
> confirmed consumer of these fields is the requirement-display string builder at
|
||||
> `~0x1800ef900`: it loads the eligibility int fields (`0x148(rcx)`) and formats them through
|
||||
> *indexed localization keys* — `ELIGIBILITY_STRING%d` (`0x1802186b8`), `LOC_SBC_ELG_KEY_%d`
|
||||
> (`0x180226710`), `ELIGIBILITY_OPERATION` (`0x1802186e8`) — appending to a string builder via
|
||||
> vtable `*0x10`/`*0x20`. There is **no comparison/branch**: the client does not validate on
|
||||
> these ints, it renders `LOC_SBC_ELG_KEY_<eligibilityKey>` (and an operation string) as
|
||||
> display text. Therefore `eligibilityKey` is a small ordinal that indexes the **packed FIFA17
|
||||
> locale**, NOT `0x307`/`0x22f`/etc. (those hex values are the atom ids of the *named* fields
|
||||
> the encoding replaces, not the ordinal values). CONSEQUENCE: correct projection needs the
|
||||
> ordinal→locale-string map, which lives only in the packed locale (absent from CardsDLL and
|
||||
> every `fifa17-recon/data` file; a game-dir locale probe on the live client found none) or a
|
||||
> real EA `elgReq` capture (unavailable on a private server). Emitting a *guessed* ordinal
|
||||
> renders the WRONG requirement text to the player, so `elgReq` stays `[]` until the ordinal
|
||||
> map is recovered. This is a display-only gap: SBC submission is fully validated server-side
|
||||
> (Core), and an invalid squad's generic comms modal originates from the server 400, not from
|
||||
> the empty `elgReq`.
|
||||
|
||||
**awards / grantedAwards** — nested array of reward objects (atoms: `rewardType 0x28e`,
|
||||
`rewardValue 0x28f`, `rewardQuantity 0x28d`, `rewardMultiplier 0x28c`, `awardCount 0x40`,
|
||||
`awardSet 0x45`, `awardSetId 0x46`, `prizeSet 0x253`). **FREEZE-RISK: must be array.**
|
||||
@@ -920,16 +939,96 @@ freezes any of these — GAPs are "feature missing", not "crash".
|
||||
| 4 | FutViewCards | `0x1801293d0` | GET `ut/%s/item` | `itemData`(0x16b) → **array[card-item]** via `0x18013fe00` [FREEZE-RISK] | HANDLED (utas `/item` `defs_route` serves `itemData`) | HIGH |
|
||||
| 5 | FutActivateCard | `0x1801642c0` | PUT `ut/%s/item` (FUT_CLUB_ACTIVATE_ITEM_DP) | **none** (immediate `ret`) | ack — `{}` fine | HIGH |
|
||||
| 6 | FutApplyCard | `0x18012a710` | PUT `ut/%s/item` (apply by itemId) | `itemData`(0x16b) → **array[updated card-item]** via `0x18013fe00` [FREEZE-RISK] | GAP | HIGH |
|
||||
| 7 | FutApplyCardByRes | `0x18012ad10` | PUT `ut/%s/item` (apply by resourceId) | `itemData`(0x16b) → **array[updated card-item]** [FREEZE-RISK] | GAP | HIGH |
|
||||
| 7 | FutApplyCardByRes | `0x18012ad10` | **POST** `ut/%s/item/resource/<rid>` (apply by resourceId) | `itemData`(0x16b) → **array[updated card-item]** [FREEZE-RISK] | **SERVED** (Rust host, contracts + attribute training) | HIGH |
|
||||
|
||||
> **Rows 6 and 7 are NOT the same route.** `ApplyCardByRes` carries urlIndex
|
||||
> `0x0e`, which resolves to `ut/%s/item/resource` — not `ut/%s/item`
|
||||
> (`plan-2026-08-05-pack-opening.md:505-506`, shared with `DiscardCardByRes` and
|
||||
> `MoveCardByRes`). The verb is **POST**, live-proven by a real-client capture:
|
||||
> `POST /ut/game/fifa17/item/resource/5001004` `{"apply":[{"id":100000003}]}`.
|
||||
> This row previously read `PUT ut/%s/item` for both, and that conflation is what
|
||||
> kept the "apply must ride `PUT ut/%s/item`" hypothesis alive
|
||||
> (`CLIENT_ROUTE_SURFACE.md:104-106`) until the POST capture settled it — every
|
||||
> observed `PUT ut/%s/item` is a pile MOVE, never an apply.
|
||||
|
||||
| 8 | FutDiscardCard | `0x180127300` | DELETE `ut/delete/%s/item` (CardsDiscardCard) | `items`(0x171) → **array[int ids]** [FREEZE-RISK]; `totalCredits`(0x326) → int; `id`(0x15c) → int | GAP | HIGH |
|
||||
| 9 | FutDiscardCardByRes | `0x1801279c0` | DELETE `ut/delete/%s/item` (by res) | `totalCredits`(0x326) → int | GAP | HIGH |
|
||||
| 10 | FutMoveCard | `0x180128600` | PUT `ut/%s/item` (move) | `itemData`(0x16b) → **array** [FREEZE-RISK]; `chemistry`(0x81) → bool | GAP | HIGH |
|
||||
| 11 | FutMoveCardByRes | `0x180128e30` | PUT `ut/%s/item` (move by res) | `itemData`(0x16b) → **array** [FREEZE-RISK]; `chemistry`(0x81) → bool (+ 2 str/1 int minor) | GAP | HIGH / extra-fields MED |
|
||||
| 12 | FutConsumablesSearch | `0x180130d10` | GET `ut/%s/item?type=…` (GetFilteredConsumableSearchResults) | `itemData`(0x16b) → **array[consumable-item]** via `0x18013fe00` [FREEZE-RISK]; `displayGroupUseDefaultImage`(0xdb) → int + count scalars | GAP | deser HIGH / scalars MED |
|
||||
| 13 | FutStaffBonus | `0x18012b730` | GET `ut/%s/…` (CardsGetStaffBonuses) | `bonus`(0x5c) → **nested** (branch sets bool @rbp+0x51) [FREEZE-RISK]; `assetId`(0x23) → int | GAP | MED |
|
||||
| 12 | FutConsumablesSearch | `0x180130d10` | GET `ut/%s/club/consumables/<cat>` (ConsumablesSearch) **[CORRECTED 2026-08-21]** | `itemData`(0x16b) → **array[consumable-stack]** via `0x18013fe00` [FREEZE-RISK]; `displayGroupUseDefaultImage`(0xdb) → int + count scalars | SERVED (Rust host) | deser HIGH / scalars MED |
|
||||
| 13 | FutStaffBonus | `0x18012b730` | GET `ut/%s/club/stats/staff` (StaffStats, thunk `0x18012b080`) **[CORRECTED 2026-08-21]** | `bonus`(0x5c) → **nested** (branch sets bool @rbp+0x51) [FREEZE-RISK]; `assetId`(0x23) → int | SERVED (`{}`, the oracle body) | MED |
|
||||
| 14 | FutGetAvailableLoanPlayers | `0x18014e030` → sub `0x18013a1c0` | GET `ut/%s/item` (FUT_AVAILABLE_LOAN_PLAYERS_DP) | `loans`(0x19b) → **array** [FREEZE-RISK]; `itemData`(0x16b) → **array[card-item]** [FREEZE-RISK]; `default`(0xcd) → int | GAP | deser HIGH / fields MED |
|
||||
| 15 | FutSignLoanPlayer | `0x1801642c0` | PUT `ut/%s/item` (sign loan) | **none** (immediate `ret`) | ack — `{}` fine | HIGH |
|
||||
| 16 | FutStickerBookSearch | `0x18012eff0` | GET `ut/%s/…` (stickerbook search) | `itemData`(0x16b) → **array[card-item]** via `0x18013fe00` [FREEZE-RISK] | GAP | HIGH |
|
||||
| 16 | FutStickerBookSearch | `0x18012eff0` | GET `ut/%s/club?<query>` (ClubSearch, `FUN_18012ddf0`) **[CORRECTED 2026-08-21]** | `itemData`(0x16b) → **array[card-item]** via `0x18013fe00` [FREEZE-RISK] | SERVED (Rust host) | HIGH |
|
||||
|
||||
|
||||
### The four `ut/%s/club` routes are a TABLE, not an inference (2026-08-21)
|
||||
|
||||
The URLs for rows 12, 13 and 16 above were previously guessed as `ut/%s/item?…`
|
||||
or left as `ut/%s/…`. The binding is exact: the 125-row action table at
|
||||
`0x1802caa20` indexes the 48-entry URL-base table at `0x18021df80` through column
|
||||
1, and **base index 3 = `ut/%s/club` is carried by exactly four rows** — so the
|
||||
client can emit exactly four request families on that base and no others.
|
||||
|
||||
```
|
||||
| ClubSearch | FUN_18012ddf0 | GET ut/%s/club?<query> | FutStickerBookSearchServerResponse |
|
||||
| ClubStats | FUN_18012f4f0 | GET ut/%s/club/stats/<f>[/<id>] | FutStickerBookStats2ServerResponse |
|
||||
| StaffStats | thunk 0x18012b080 | GET ut/%s/club/stats/staff | FutStaffBonusServerResponse |
|
||||
| ConsumablesSearch | FUN_1801308c0 | GET ut/%s/club/consumables/<cat> | FutConsumablesSearchServerResponse |
|
||||
```
|
||||
|
||||
**Club query grammar**, complete and ordered: `?year=2017` (always, hardcoded),
|
||||
then `type`, `start` (omitted at 0), `count` (omitted at 100), `filter`, then
|
||||
EITHER the filter block (`position, formation, state, level, rare, nation,
|
||||
country, league, playStyle, team, sort`) OR a comma-joined `defId=` list, never
|
||||
both. Live control from the log:
|
||||
`GET /ut/game/fifa17/club?year=2017&type=equippables&count=11&level=any&sort=desc`
|
||||
matches the predicted order and every suppression rule.
|
||||
|
||||
Sub-vocabularies: `filter` = available/base/exact/any; `level` =
|
||||
bronze/silver/gold/any; `sort` = asc/desc; `rare` = the literal string `SP`, not
|
||||
a boolean; `state` = the itemState names plus `any` — and note the REQUEST spells
|
||||
it `onSale` where the RESPONSE value is `forSale`.
|
||||
|
||||
`?type=` has 30 values. Decoded 2026-08-21 from the jump table itself rather
|
||||
than from a case count: `FUN_18012ec50` is `cmp ecx,0x1d` + a 30-entry table at
|
||||
`0x18012ed9c`, and each case is `mov ecx,<atom>; jmp 0x180180cd0` (atom → string).
|
||||
Resolving those atoms against `fut_atoms.tsv` gives the vocabulary in table order:
|
||||
|
||||
```
|
||||
0 any 1 player 2 manager 3 headcoach
|
||||
4 fitnesscoach 5 physio 6 development 7 custom
|
||||
8 unlocks 9 gkcoach 10 staff 11 badge
|
||||
12 kit 13 stadium 14 ball 15 equippables
|
||||
16 leaguelogos 17 offlinetrophy 18 onlinetrophy 19 featuredofflinetrophy
|
||||
20 featuredonlinetrophy 21 allofflinetrophy
|
||||
22 allonlinetrophy 23 healing 24 contract
|
||||
25 training 26 misc 27 playerdefender
|
||||
28 playermidfielder 29 playerforward
|
||||
```
|
||||
|
||||
Notes worth having: there is **no `playergoalkeeper`** — the client has only
|
||||
DEF/MID/FWD tabs, so goalkeepers belong to `playerdefender`, and a GK appearing
|
||||
there is correct rather than a filter bug. `healing`, `contract` and `training`
|
||||
exist here as `?type=` arms even though consumables have their own
|
||||
`club/consumables/<cat>` route. Six of the thirty are trophy arms.
|
||||
|
||||
`openfut-utas-host`'s `club_type_filter` implements all 30 with no extras; a unit
|
||||
test pins the list so a missing arm (an empty real tab) or an invented one (dead
|
||||
code that looks like coverage) fails the build.
|
||||
|
||||
**`/club/stats` has exactly seven forms**: `club`, `year`, `country/<id>`,
|
||||
`league/<id>`, `newcards`, `consumables`, and the separately-dispatched `staff`.
|
||||
**There is no `/club/stats/team/<id>`** — verified twice (the switch has six cases
|
||||
with no such arm, and an exhaustive PE string scan finds no literal containing
|
||||
`stats/team`). Any handling of a `team` stats mode is dead code.
|
||||
|
||||
**Two holes in the base table**, recorded so nobody re-derives them as findings:
|
||||
base index 43 = `ut/v2/%s/store` is carried by no action row and has zero
|
||||
references in `.text`, yet `ut/v2/store` is live-proven; base index 9 =
|
||||
`ut/%s/activeMessage` is a second hole of the same kind. So at least one route is
|
||||
composed OUTSIDE CardsDLL, most likely in the packed exe — every "the table bounds
|
||||
it" statement here is bounded to CardsDLL only.
|
||||
|
||||
Notes:
|
||||
- **`0x1801642c0`** is a shared no-op deserializer (function body = `ret`). Three responses
|
||||
|
||||
@@ -607,6 +607,62 @@ cardtype 6, live-confirmed on the two resident consumables, so for exactly the
|
||||
items the warning was aimed at, the server's rating and rare flag are
|
||||
authoritative.
|
||||
|
||||
**APPLIED (2026-08-21), behind a default-off flag.** The table and the formula
|
||||
above are now in Rust as `openfut-adapter-fifa17::fut::discard`:
|
||||
`cardtype_for_subtype` is the decode, `discard_level` the 3/2/1 ladder,
|
||||
`table_price` the 141-row lookup (`0` for an absent key) and `discard_value` the
|
||||
`round_half_up(rating * price / 100)` formula. `DISCARD_COINS` is generated from
|
||||
`fifa17-recon/data/tables/fcc_discardcoins.json` and a test re-reads that file
|
||||
and asserts they still agree row for row, so the two cannot drift. The four
|
||||
worked examples above (`8 * rating`, `4 * rating`, the 50-rated bronze at 15,
|
||||
and an absent key paying 0) are tests.
|
||||
|
||||
Wire and wallet are now ONE method. `ItemIdentityResolver::discard_value` both
|
||||
stamps the card's `discardValue` and prices the sale, because a non-zero
|
||||
`discardValue` suppresses the client's local computation — so whatever is sent
|
||||
is what the player is promised. The host's separate `quick_sell_value` ladder is
|
||||
deleted (it was a second copy that could drift), and a test with a resolver
|
||||
double returning an impossible price proves the credit follows the wire.
|
||||
|
||||
`OPENFUT_FIFA17_DISCARD_TABLE=1` turns the table on; the default keeps the old
|
||||
placeholder ladder because switching revalues an existing club by **10.5x**
|
||||
(measured over the real 1991-item club: 1,820,400 -> 19,128,955 coins if wholly
|
||||
liquidated). Players drive it (an r93 special goes 1500 -> 74,400); consumables
|
||||
move the OTHER way (2,400 -> 437, i.e. the ladder was overpaying 5.5x).
|
||||
|
||||
STAFF: CLOSED, and the `value`-is-the-rating question is now SETTLED against the
|
||||
running client rather than inferred. A staff wire record carries no `rating`, no
|
||||
`rareflag` and no `discardValue`, so the displayed price had to be read back out
|
||||
of memory. `tools/coach_probe.py` grades the four resident staff records HIT,
|
||||
which requires record `+0xb4` == the table's `value` and `+0x58` == its `rare`;
|
||||
`tools/discard_probe.py` (new) then reads the two discard slots directly —
|
||||
`+0x38` is what we sent, `+0x3c` is what the client computed:
|
||||
|
||||
```
|
||||
resource sub ct rat lvl rar sent+38 calc+3c predicted
|
||||
1000509 4 2 88 3 1 0 282 282 AGREES (manager)
|
||||
9000081 6 10 66 2 0 0 36 36 AGREES (gk coach)
|
||||
3000083 8 4 66 2 0 0 36 36 AGREES (fitness)
|
||||
```
|
||||
|
||||
4 of 4 agree, 0 disagree, and 36 on the `value`-66 GK coach was the stated
|
||||
falsifier. `openfut-import-fifa17::Entities::enrich_staff` now carries `value` ->
|
||||
rating and `rare` -> rareflag for the five families, so the catalog holds what
|
||||
the client re-rates to; verified on staging, a GK coach quick-sells for 36 rather
|
||||
than the 150 floor. The catalog diff is exactly the two coach entries.
|
||||
|
||||
The same probe shows what production is doing to PLAYERS today: all 23 resident
|
||||
player records carry `sent+38 = 1500`, which suppresses the local computation, so
|
||||
the client displays 1500 for every one of them — against its own table's 688..752
|
||||
for a gold rare, 11,102..11,468 for the 21/23/24 specials, 22,080..23,280 for
|
||||
rareflag 11, and 72,800 / 74,400 for the two rareflag 5/6 legends. A 50x underpay
|
||||
at the top and a 2x overpay at the bottom.
|
||||
|
||||
STILL OPEN, and NOT a discard problem: the manager `fifa17_1000509` is owned in
|
||||
Core but has no catalog entry and no card definition (it reaches the client
|
||||
through the opaque squad extension), so pricing declines for it and falls back to
|
||||
the ladder — 150 against the client's 282. That is definition coverage.
|
||||
|
||||
### 3.7 `duplicateItemIdList`
|
||||
|
||||
CONFIRMED shape, INFERRED effect, never observed. Element deser `FUN_180138e10`,
|
||||
|
||||
@@ -304,8 +304,44 @@ elimination:**
|
||||
| kit | **9** | 7 | `FUN_180119bd0` → `FUT_UC_KITS` + `TeamName_Abbr15_<teamid>` | `teamid` |
|
||||
| stadium | **10** | 7 | `FUN_180119bd0` → `Stadium` + `StadiumName_<assetId>` | `assetId` |
|
||||
| badge | **11** | 7 | `FUN_180119bd0` → `Badge` + `TeamName_Abbr15_<teamid>` | `teamid` |
|
||||
| ball | **30** (0x1e) | 9 | none; `FUT_UC_BALL` caption only | `localizedName` |
|
||||
| league logo | **31** (0x1f) | 9 | `FUN_180098f20` keyed on leagueid | `localizedName`, probably |
|
||||
| ball | **30** (0x1e) | 9 | NONE — see the 2026-08-21 measurement below | unnameable |
|
||||
| league logo | **31** (0x1f) | 9 | NONE — see the 2026-08-21 measurement below | unnameable |
|
||||
|
||||
**MEASURED 2026-08-21 against the running client (`tools/cardtype_dispatch_probe.py`,
|
||||
pid 6580): no cardtype-9 family can be named, and no server change can alter that.**
|
||||
Four independent reads, each with a passing positive control:
|
||||
|
||||
1. The merge switch's jump table at rva `0x141eb4` is indexed by `cardtype - 1`
|
||||
and has exactly 10 entries. Cardtypes 1–5 and 10 each get their own DB-merge
|
||||
arm; **cardtypes 6, 7, 8 and 9 all land on the shared tail `0x180141e8a`**,
|
||||
which issues no query and writes no name — it only derives the discard level
|
||||
from the rating.
|
||||
2. Census of every `cmp [reg+0x4c], imm` (cardtype): 0 → 1 site, 1 → 13, 6 → 1,
|
||||
7 → 6, **9 → ZERO**.
|
||||
3. Census of every `cmp [reg+0x50], imm` (cardsubtypeid), which is what actually
|
||||
selects a club-item caption: kit 9, stadium 10 and badge 11 all present
|
||||
(control), **ball 30 → ZERO sites, league logo 31 → ZERO sites**. The only
|
||||
cardtype-9 subtypes that appear at all are `fcc_misccards` 231/232/233/236,
|
||||
and all four sites are one boolean predicate near `0x1801a72da` that returns
|
||||
FALSE for them — an exclusion, not a resolver. (That predicate's identity is
|
||||
NOT established; it reads `+0x49`, `+0x145` and a vtable slot `+0x270`.)
|
||||
4. The cardtype-7 resolver is reached only under `cmp DWORD PTR [rax+0x4c], 0x7`
|
||||
at `0x1800f6f04`, so a cardtype-9 item can never arrive there. Its `jne` path
|
||||
formats `AWARD_LABEL_%i` (`0x1801fd5a0`) — the TROPHY path, not a fallback
|
||||
that would name a ball.
|
||||
|
||||
So the earlier "`localizedName`, probably" for these two rows was optimistic:
|
||||
there is no code that would read it for a caption. Withholding ball and league
|
||||
logo from the projection is a measured limit of the client, not caution.
|
||||
|
||||
CORRECTION, same measurement: `FUN_180119bd0` was recorded elsewhere as having
|
||||
"zero refs in CardsDLL → almost certainly an export, its caller is in
|
||||
FIFA17.exe". It is **not** an export. Its address occurs exactly ONCE in the
|
||||
whole process, at `0x18021c738` in CardsDLL's own `.rdata`, and nothing in
|
||||
FIFA17.exe references it. It is a virtual function: vtable base `0x18021c2a0`,
|
||||
slot **+0x498**, index 147 (ctor LEAs at `0x18010ce10` / `0x18011111b`) — which
|
||||
independently reproduces the "manager vtable slot +0x498" recorded below, by a
|
||||
different method. It has 7 distinct `call [reg+0x498]` sites.
|
||||
|
||||
The premise that all five live in cardtype 9 is wrong, and the root fact is not an
|
||||
inference from a call site. `FUN_1800d8330`, read in full at 714 chars by two
|
||||
@@ -406,6 +442,91 @@ from an accessor. So: send `localizedName` and expect it to show; send
|
||||
`description` and do not be surprised if nothing changes. The same `+0xba` also
|
||||
holds the unresolved kit-variant selector, so these two gaps may be one gap.
|
||||
|
||||
### The cardtype-9 name gap is ONE gap, not three (2026-08-21)
|
||||
|
||||
Worth stating plainly, because it was being tracked as three separate holes.
|
||||
Everything OpenFUT still refuses to project is cardtype 9, and for exactly the
|
||||
same reason:
|
||||
|
||||
| family | subtype(s) | definition table | why withheld |
|
||||
|---|---|---|---|
|
||||
| ball | 30 | `fcc_balls` (42) | no DB name resolver |
|
||||
| league logo | 31 | `fcc_leaguelogos` (44) | no DB name resolver |
|
||||
| misc | 231, 232, 233, 236 | `fcc_misccards` (42) | no DB name resolver |
|
||||
|
||||
The cardtype-7 families (kit 9, badge 11, stadium 10) all resolve their caption
|
||||
from the client's own tables through `FUN_180119bd0`, so the server sends only
|
||||
identity and the name takes care of itself — which is why all three now project.
|
||||
Cardtype 9 has no such resolver, so the displayed name can ONLY come from
|
||||
`localizedName` on the wire, and that single unproven step gates all three
|
||||
families at once.
|
||||
|
||||
Closing it closes the last of the ownable taxonomy. It needs the launch-driven
|
||||
probe in "The one probe still outstanding" above — one item, one family — and
|
||||
nothing else. Ownership, `content_kind`, club/stats counting and restart
|
||||
durability are already in place for all three, so the probe is the only
|
||||
remaining work: the projection arm is a two-line change once the name is proven.
|
||||
|
||||
#### A lead on league logos: a `LeagueName_Abbr_15_%d` path DOES exist
|
||||
|
||||
`FUN_180098f20` (named above as the league-logo function, hedged "localizedName,
|
||||
probably") was read in full on 2026-08-21. It builds a real database query, and
|
||||
the literals settle what it does:
|
||||
|
||||
```
|
||||
table 'fcc_leaguelogos'
|
||||
where 'leagueid' '==' %d ; the id arrives in r9d
|
||||
columns 'carddbid' 'value' 'cardassetid'
|
||||
caption 'LeagueName_Abbr_15_%d' ; a localisation key built from the league id
|
||||
domain 'FUT String'
|
||||
```
|
||||
|
||||
So a database-backed league NAME demonstrably exists in the client, keyed on
|
||||
`leagueid`, in exactly the shape kits use (`TeamName_Abbr15_<teamid>`). That
|
||||
makes the blanket claim "cardtype 9 has no DB name resolver" too strong for
|
||||
league logos specifically.
|
||||
|
||||
WHAT THIS DOES NOT YET SHOW, stated plainly because the obvious next step is a
|
||||
trap. Its ONLY caller is `0x180098da3`, and the `[rbx+0x20]` it passes as the
|
||||
league id is NOT the item record: `rbx` is reloaded from `[rsp+0x48]` and
|
||||
compared against an end pointer, i.e. it is a cursor over a list of small
|
||||
elements (int at `+0x20`, double at `+0x24`, int at `+0x2c`), not the 0x158-byte
|
||||
card record. So this is a CATALOG/BROWSE builder, and it is not established that
|
||||
the owned-item render path reaches it at all. Reading `+0x20` as the record's
|
||||
`assetId` and concluding "send the leagueid as assetId" would be exactly the
|
||||
kind of inference this document exists to prevent.
|
||||
|
||||
The lead worth following: find whether the owned cardtype-9 render path reaches
|
||||
this resolver, and if so which field feeds the league id. If it does, league
|
||||
logos need no `localizedName` at all and separate from the ball/misc gap.
|
||||
|
||||
#### Where to look next, and where NOT to (2026-08-21)
|
||||
|
||||
The lead above was chased and stopped at a useful boundary. `FUN_180119bd0` —
|
||||
the cardtype-7 caption resolver this whole section rests on — has **zero
|
||||
references anywhere in CardsDLL**: no `call`, no `jmp`, and its address is never
|
||||
taken in `.text`, `.rdata` or `.data`. It is nonetheless a genuine function
|
||||
(clean `mov rax,rsp` entry after `int3` padding).
|
||||
|
||||
A real, unreferenced function in a DLL is almost certainly an **export**, which
|
||||
puts its caller in FIFA17.exe. That matches the shape of everything else here:
|
||||
CardsDLL owns the card model and the database, and the EXE owns the UI that asks
|
||||
for captions. `FUN_180098f20`'s only caller likewise iterates a small list
|
||||
element, not a card record — a browse/catalog builder, not the owned-item path.
|
||||
|
||||
So the practical guidance is: **stop looking for the owned cardtype-9 caption
|
||||
path inside CardsDLL.** It is not there. Closing this by static reading means
|
||||
parsing CardsDLL's export table and following the callers in FIFA17.exe's 79 MB,
|
||||
which is a much larger job than the launch probe in "The one probe still
|
||||
outstanding" — one item, one family, and the answer is visible on screen.
|
||||
|
||||
Method note for whoever does dump memory here: CardsDLL's sections are
|
||||
`.text` at image `0x180001000`, `.rdata` at `0x1801e5000`, `.data` at
|
||||
`0x18028a000`. Confusing a LIVE mapping offset with an IMAGE offset silently
|
||||
reads the wrong section and produces false negatives — every atom-name lookup
|
||||
came back ABSENT until the region was corrected, including controls like
|
||||
`resourceId`. Always validate a memory scan against a key known to be present.
|
||||
|
||||
---
|
||||
|
||||
## 4. The card lifecycle
|
||||
@@ -503,13 +624,6 @@ effects move in the permissive direction. There is also a second escape hatch in
|
||||
that gate -- `svc->0x308()` on service `0xed80ed8` -- that nobody resolved, so if
|
||||
squad submission behaves oddly afterwards, that is where to look.
|
||||
|
||||
**"List on Transfer Market" as a separate menu entry was not found.** The eight
|
||||
flags contain `TO_TRADE_PILE` and no listing action. `FUN_18003e550` publishes
|
||||
`DURATION` / `START_PRICE` / `ASKING_PRICE`, which is the listing panel, but
|
||||
whether it has its own enable predicate was not chased. The likely explanation is
|
||||
that listing is only reachable from the trade pile, so both entries share one root
|
||||
cause, but that is an inference and it is not established.
|
||||
|
||||
### Equipping club items
|
||||
|
||||
`itemState` really is the equip mechanism for the `IS_ACTIVE` tick:
|
||||
@@ -528,22 +642,60 @@ will not change the kit.
|
||||
|
||||
### Needs decompiling only
|
||||
|
||||
**Who writes item `+0x60`.** It gates the kit swap at value 4 and we can produce 1
|
||||
and 6. Both attempts to scan for it drowned: `+0x60` returns 1688 and 4144
|
||||
instructions depending on method. The narrower anchor is the `/club` and
|
||||
`/purchased` response handlers -- find the list-insert that assigns it, read the
|
||||
constants. This is the single blocker between "we can mark a kit equipped" and "we
|
||||
can equip a kit".
|
||||
**Who writes item `+0x60`. ANSWERED 2026-08-21 — NOTHING DOES.** It gates the kit
|
||||
swap at value 4 and we can produce 1 and 6. Both earlier scans drowned (`+0x60`
|
||||
returns 1688 and 4144 instructions) because it is a common struct offset. Two
|
||||
filters cut it to a readable set: only an IMMEDIATE store can introduce a
|
||||
constant, and item-record code is recognisable by touching `+0x4c`/`+0x5c`
|
||||
nearby. Measured with `fifa17-recon/tools/kit_gate_probe.py` against pid 6580:
|
||||
|
||||
| evidence | result |
|
||||
|---|---|
|
||||
| live `+0x60`, all 27 resident records | `{1: 23 players, 0: 4 staff}` — never 4 |
|
||||
| `cmp dword [reg+0x60], imm8` in CardsDLL | 4 sites: `0`, `0`, `1`, `4`; the `4` is the gate and is UNIQUE in the process |
|
||||
| immediate stores to `[reg+0x60]`, CardsDLL | 29; constants `{-2, 0, 1, 908, 0x3f800000}` — no 4 |
|
||||
| immediate stores of 4, FIFA17.exe (79 MB) | 0; also 0 comparisons against 4 |
|
||||
| xrefs to the gate function | 1 (`jmp` from `0x1801a5329`); address never taken |
|
||||
| register stores to `+0x60`, CardsDLL | all struct copies or inits to 0/1/-2 |
|
||||
|
||||
So the blocker is not a wire field we have not learned to send: the value the
|
||||
gate demands is never produced by anything. Every OTHER input to the gate is
|
||||
already served — `+0x4c == 7` (subtype 9), `+0x5c` 101/102
|
||||
(`activeHomeKit`/`activeAwayKit`), `+0x94` teamid — leaving only the `+0xba`
|
||||
variant selector below it. A client-side patch is therefore the only remaining
|
||||
avenue, and a small one; it is not proposed here.
|
||||
|
||||
|
||||
**The kit variant selector.** `FUN_1801bfac0` distinguishes home, away and third
|
||||
kits from `FUN_1801a8800` (`+0xba`, u16) and `FUN_1801a8040` (`+0xbf`, signed
|
||||
byte). Which wire atom sets it is unknown, so we cannot serve a specific kit
|
||||
deliberately. Note `+0xba` is the same slot as the unresolved ball subtitle.
|
||||
|
||||
**`FUN_1801aa190`.** The one unopened link inside the eight-flag chain: it is
|
||||
claimed to resolve `statsList[4]` and `[5]` at `+0x104 + idx*4`. It changes no
|
||||
action today because we send no `statsList`, but it is two minutes of work and it
|
||||
would close the chain.
|
||||
**`FUN_1801aa190`. CLOSED 2026-08-21.** The one unopened link inside the
|
||||
eight-flag chain. It is eleven instructions, and it resolves TWO parallel arrays
|
||||
rather than the one the earlier claim described:
|
||||
|
||||
```
|
||||
mov rax, [rcx+0x10] ; the ITEM record (same +0x10 hop the kit gate uses)
|
||||
test r8b, r8b
|
||||
jz .low
|
||||
mov eax, [rax + rdx*4 + 0x124] ; array B
|
||||
ret
|
||||
.low:
|
||||
mov eax, [rax + rcx*4 + 0x104] ; array A <- the claimed statsList
|
||||
ret
|
||||
```
|
||||
|
||||
So the signature is `f(self, int idx, bool which)`: `+0x104 + idx*4` when the
|
||||
flag is clear, `+0x124 + idx*4` when it is set. The two arrays are 0x20 apart,
|
||||
i.e. eight ints each (`+0x104..+0x123`, `+0x124..+0x143`).
|
||||
|
||||
LIVE (pid 6580, production-served records): BOTH arrays read all zeros on every
|
||||
resident record, players included — e.g. resourceId 20801 rating 94 has
|
||||
`A = [0]*8`, `B = [0]*8`. That confirms "changes no action today because we send
|
||||
no statsList", and extends it: the sibling array at `+0x124` is equally empty.
|
||||
Any action flag derived from either is reading 0 in production, so neither can
|
||||
be the reason an action is greyed.
|
||||
|
||||
**The `BOUGHT_FOR` consumer.** `+0x34` = atom `0x185 lastSalePrice` is resolved.
|
||||
What remains is whether the field is visible anywhere worth populating.
|
||||
@@ -553,24 +705,73 @@ depend on it (`FUN_180108c00` carries the same mapping independently), but the
|
||||
dispatch table that reaches it was not identified, and trophies are a whole
|
||||
unimplemented family.
|
||||
|
||||
**Case sensitivity of the `itemState` string match.** Almost certainly
|
||||
unresolvable statically: `FUN_180008190` is a single indirect call through
|
||||
`DAT_1802ddfd8 + 0x248`, a runtime-populated service pointer. Send the exact
|
||||
casing from the table and do not experiment on the live save.
|
||||
**Case sensitivity of the `itemState` string match. RESOLVED 2026-08-21 —
|
||||
CASE-SENSITIVE.** It was expected to be unresolvable statically, because
|
||||
`FUN_180008190` is nothing but a forwarding stub through a runtime-populated
|
||||
slot:
|
||||
|
||||
```
|
||||
mov rax, [DAT_1802ddfd8] ; service object, handed to CardsDLL by the host
|
||||
mov r9, [rax + 0x248]
|
||||
jmp r9
|
||||
```
|
||||
|
||||
Resolved read-only against the running client (pid 6580) with
|
||||
`fifa17-recon/tools/service_ptr_probe.py`, which follows the chain and
|
||||
attributes each hop to a module (Wine maps PE sections anonymously, so the
|
||||
module comes from the nearest preceding named mapping):
|
||||
|
||||
```
|
||||
*(service + 0x248) = 0x146d1c020 FIFA17.exe+0x20f9020 e9 … jmp rel32
|
||||
→ 0x145e27fe0 FIFA17.exe+0x1204fe0 ff 25 jmp [rip+…]
|
||||
→ 0x6ffffd11c330 msvcr120.dll+0x3c330 function body
|
||||
```
|
||||
|
||||
The body is `strncmp`: `sub rdx,rcx` / `test r8,r8` (count) / `test al,al`
|
||||
(NUL stop) / `cmp al,[rcx+rdx]`, then MSVC's 8-byte fast path with the
|
||||
`0x8080808080808080` and `0xfefefefefefefeff` NUL-detect constants. There is no
|
||||
`or ..,0x20` and no folding table anywhere in the body, so the compare is raw
|
||||
bytes.
|
||||
|
||||
CONSEQUENCE: a mis-cased token does not degrade, it matches nothing —
|
||||
`FUN_180166660` returns `0xffffffff`, the record keeps `0` = `invalid`, and the
|
||||
item fails the squad builder's `state == 1 || state == 2` test. The casing in
|
||||
the table at `0x180229cc0` is a contract. Send it verbatim; do not experiment on
|
||||
the live save.
|
||||
|
||||
### Needs a live probe (read-only, no launch)
|
||||
|
||||
**Resolve `DAT_1802ddfd8 + 0x248`** in the running process and identify the string
|
||||
comparator. That answers the casing question without a launch.
|
||||
|
||||
**Re-read `+0x30` after a refetch** to decide between "monotonic clock" and
|
||||
"sequence counter". Low value; nothing we send reaches it.
|
||||
|
||||
**Confirm the FUT roster database is loaded.** The `fcc_discardcoins` result
|
||||
proves `g_db` is loaded and complete; it says nothing about the separate database
|
||||
behind `LoadFUTDatabase` / `.dbFUTVer` / `DL_FUT_LIVEDB`, whose strings live in
|
||||
FIFA17.exe and not in CardsDLL. These are different databases and they should stop
|
||||
being conflated.
|
||||
**Confirm the FUT roster database is loaded. PARTLY ANSWERED 2026-08-21 — the
|
||||
two databases are now definitively distinct; the load FLAG is still unlocated.**
|
||||
The `fcc_discardcoins` result proves `g_db` is loaded and complete; it says
|
||||
nothing about the separate database behind `LoadFUTDatabase` / `.dbFUTVer` /
|
||||
`DL_FUT_LIVEDB`. Scanning FIFA17.exe's 79 MB of code+data in the live process
|
||||
(pid 6580) recovers the whole API name set, and it settles the distinction:
|
||||
|
||||
```
|
||||
SetFUTDatabaseUnloaded UpdateFUTDBVersion StartFUTRosterDownload
|
||||
LoadFUTDatabase UnLoadFUTDatabase GetFUTDBCRC
|
||||
CancelRosterDownload DL_FUT_LIVEDB APPLY_FUT_LIVEDB
|
||||
RosterXMLDownloadedFail .dbFUTVer .dbMajor .dbMinor .dbMajorCRC .dbMinorCRC
|
||||
```
|
||||
|
||||
Every one of those lives in FIFA17.exe; none is in CardsDLL. So the FUT roster
|
||||
DB is a DOWNLOADED, versioned, CRC-checked live database with its own
|
||||
download -> apply -> load/unload lifecycle (and its own failure state,
|
||||
`RosterXMLDownloadedFail`), which is a different kind of thing from the shipped
|
||||
card tables CardsDLL reads. They should stop being conflated, and this is the
|
||||
evidence for saying so.
|
||||
|
||||
What is NOT answered: whether it is loaded right now. The process holds no
|
||||
separate database file open — only Frostbite bundles (`.sb` / `.cas`) — which is
|
||||
consistent with the roster DB living inside a bundle or in memory, so absence of
|
||||
a file handle proves nothing either way. The `SetFUTDatabaseUnloaded` state
|
||||
implies a boolean somewhere; that global was not located, so "is it loaded"
|
||||
remains open and needs the flag found before it can be answered honestly.
|
||||
|
||||
### Needs a launch the user must drive -- ranked, and short
|
||||
|
||||
@@ -870,10 +1071,29 @@ be misrouted onto another field. **Freeze risk: none** -- removing a key the par
|
||||
skips strictly reduces executed code. Low value, zero cost, and it removes a field
|
||||
that three documents describe as if it did something.
|
||||
|
||||
**Fourth verification, 2026-08-21 (independent method).** Searched CardsDLL's
|
||||
own `.rdata` in the running client for the literal key names. Every real atom is
|
||||
present exactly once — `resourceId` `0x18022a3a8`, `cardsubtypeid` `0x180230520`,
|
||||
`itemState` `0x180231490`, `assetId` `0x180230178`, `cardassetid` `0x180204200`,
|
||||
`rareflag`, `untradeable`, `owners`, `contract`, `discardValue`, and notably
|
||||
`localizedName` at `0x1802316d0` — while **`definitionId` is ABSENT entirely**.
|
||||
The client has no string for it, so no arm can exist. That is a different method
|
||||
from the three above (string table rather than key dictionary) and it agrees.
|
||||
|
||||
NOT applied all the same. The player path that carries `definitionId` is
|
||||
live-proven in production, the saving is payload only, and this project's house
|
||||
rule is that a flag defaults to the live-proven value. "Provably inert" is a good
|
||||
reason to stop documenting it as meaningful; it is not on its own a reason to
|
||||
change a working wire. Bundle it with the next change that needs a launch.
|
||||
|
||||
---
|
||||
|
||||
## 7. Proposed corrections to existing documents
|
||||
|
||||
> **APPLIED 2026-08-21.** Every correction below has been made in the named file
|
||||
> and marked there with a dated note. This section is kept as the rationale and
|
||||
> the audit trail, not as an outstanding to-do.
|
||||
|
||||
### `docs/CARD_SYSTEM.md`
|
||||
|
||||
**Replace the "STILL UNKNOWN, AND NOT GUESSED" section entirely.** It is answered.
|
||||
|
||||
Executable
+697
@@ -0,0 +1,697 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Decoder for EA APT (compiled ActionScript) as shipped in FIFA 17.
|
||||
|
||||
Clean-room implementation. The byte-level format facts (opcode numbers, operand
|
||||
widths, alignment rule, branch base, DefineFunction2 field order) were taken from
|
||||
a written specification derived from OpenSAGE, which is GPL-3.0 with EA
|
||||
additional terms. No OpenSAGE code was copied or transliterated; only the format
|
||||
description -- an interface specification -- was used. Reference read at
|
||||
OpenSAGE/OpenSAGE commit 588ac477367a0022adf29f20a084e8873014e6ce and
|
||||
OpenSAGE/AptEditor commit 09f73c655c45a781f883b623a93d2e8f5b065a6c.
|
||||
|
||||
FIFA 17 ships a 64-BIT variant of the format. Differences from the 32-bit SAGE
|
||||
layout described by the reference, all established by measurement against
|
||||
futSelectTeam and asserted by --selftest:
|
||||
|
||||
* Container pointers and counts are u64, not u32.
|
||||
* Parameterised instructions align their operand block to 8 bytes, not 4.
|
||||
Proven by the ConstantPool at 0xd38: aligning to 4 yields garbage, aligning
|
||||
to 8 yields count=401 with an index array that ends exactly on the
|
||||
parameter-list region.
|
||||
* The constant pool lives in a separate "Apt1" container member rather than a
|
||||
".const" sibling file. Entries are 16 bytes: {u64 type, u64 value}; type 1
|
||||
is a string whose value is an absolute offset inside that same member.
|
||||
* DefineFunction2's operand block is 48 bytes rather than 28, and the
|
||||
0x1234567898765432 trailer is stored as two u64 halves.
|
||||
* Branch displacements remain i32 and remain relative to the end of the
|
||||
branch record, exactly as in the 32-bit format.
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
import struct
|
||||
import sys
|
||||
from dataclasses import dataclass, field
|
||||
|
||||
APT1_MAGIC = b"Apt1"
|
||||
APTDATA_MAGIC = b"Apt Data:1:7:8\x1a\x00"
|
||||
|
||||
# Trailer sentinel on DefineFunction/DefineFunction2, stored as two u64 halves.
|
||||
FUNC_SENTINEL_LO = 0x98765432
|
||||
FUNC_SENTINEL_HI = 0x12345678
|
||||
|
||||
ALIGN = 8
|
||||
|
||||
# Operand kinds.
|
||||
NONE = "none" # no operand block
|
||||
U8REG = "u8reg" # 1 raw byte, register index
|
||||
U8CONST = "u8const" # 1 raw byte, constant-pool index
|
||||
U16CONST = "u16const" # 2 raw bytes, constant-pool index
|
||||
U8LIT = "u8lit" # 1 raw byte, literal integer
|
||||
U16LIT = "u16lit" # 2 raw bytes, literal integer
|
||||
BRANCH = "branch" # aligned i32, relative to end of record
|
||||
U32 = "u32" # aligned u32
|
||||
F32 = "f32" # aligned f32
|
||||
STR64 = "str64" # aligned u64 absolute offset to NUL-terminated string
|
||||
POOL = "pool" # aligned u64 count + u64 array offset (array of u64 ids)
|
||||
FUNC2 = "func2" # aligned DefineFunction2 record
|
||||
FUNC1 = "func1" # aligned DefineFunction record
|
||||
|
||||
# opcode -> (mnemonic, operand kind)
|
||||
OPCODES: dict[int, tuple[str, str]] = {
|
||||
0x00: ("End", NONE),
|
||||
0x04: ("NextFrame", NONE),
|
||||
0x06: ("Play", NONE),
|
||||
0x07: ("Stop", NONE),
|
||||
0x0A: ("Add", NONE),
|
||||
0x0B: ("Subtract", NONE),
|
||||
0x0C: ("Multiply", NONE),
|
||||
0x0D: ("Divide", NONE),
|
||||
0x12: ("Not", NONE),
|
||||
0x13: ("StringEquals", NONE),
|
||||
0x17: ("Pop", NONE),
|
||||
0x18: ("ToInteger", NONE),
|
||||
0x1C: ("GetVariable", NONE),
|
||||
0x1D: ("SetVariable", NONE),
|
||||
0x21: ("StringConcat", NONE),
|
||||
0x22: ("GetProperty", NONE),
|
||||
0x23: ("SetProperty", NONE),
|
||||
0x26: ("Trace", NONE),
|
||||
0x30: ("Random", NONE),
|
||||
0x3A: ("Delete", NONE),
|
||||
0x3B: ("Delete2", NONE),
|
||||
0x3C: ("DefineLocal", NONE),
|
||||
0x3D: ("CallFunction", NONE),
|
||||
0x3E: ("Return", NONE),
|
||||
0x3F: ("Modulo", NONE),
|
||||
0x40: ("NewObject", NONE),
|
||||
0x41: ("Var", NONE),
|
||||
0x42: ("InitArray", NONE),
|
||||
0x43: ("InitObject", NONE),
|
||||
0x44: ("TypeOf", NONE),
|
||||
0x47: ("Add2", NONE),
|
||||
0x48: ("LessThan2", NONE),
|
||||
0x49: ("Equals2", NONE),
|
||||
0x4A: ("ToNumber", NONE),
|
||||
0x4B: ("ToString", NONE),
|
||||
0x4C: ("PushDuplicate", NONE),
|
||||
0x4E: ("GetMember", NONE),
|
||||
0x4F: ("SetMember", NONE),
|
||||
0x50: ("Increment", NONE),
|
||||
0x51: ("Decrement", NONE),
|
||||
0x52: ("CallMethod", NONE),
|
||||
# 0x53 appears in the reference enum as NewMethod but the reference never
|
||||
# parses it. Standard AVM1 ActionNewMethod carries no operand block;
|
||||
# decoding it as zero-length keeps this artifact synchronised with every
|
||||
# branch still landing on an instruction boundary, which is the check that
|
||||
# would break first if the width were wrong.
|
||||
0x53: ("NewMethod", NONE),
|
||||
0x54: ("InstanceOf", NONE),
|
||||
0x55: ("Enumerate2", NONE),
|
||||
0x56: ("PushThis", NONE),
|
||||
0x59: ("PushZero", NONE),
|
||||
0x5A: ("PushOne", NONE),
|
||||
0x5B: ("CallFuncPop", NONE),
|
||||
0x5C: ("CallFunc", NONE),
|
||||
0x5D: ("CallMethodPop", NONE),
|
||||
0x62: ("BitwiseXOr", NONE),
|
||||
0x66: ("StrictEqual", NONE),
|
||||
0x67: ("Greater", NONE),
|
||||
0x69: ("Extends", NONE),
|
||||
0x70: ("PushThisVar", NONE),
|
||||
0x71: ("PushGlobalVar", NONE),
|
||||
0x72: ("ZeroVar", NONE),
|
||||
0x73: ("PushTrue", NONE),
|
||||
0x74: ("PushFalse", NONE),
|
||||
0x75: ("PushNull", NONE),
|
||||
0x76: ("PushUndefined", NONE),
|
||||
0x87: ("SetRegister", U32),
|
||||
0x88: ("ConstantPool", POOL),
|
||||
0x8C: ("GotoLabel", STR64),
|
||||
0x8E: ("DefineFunction2", FUNC2),
|
||||
0x96: ("PushData", POOL),
|
||||
0x99: ("BranchAlways", BRANCH),
|
||||
0x9B: ("DefineFunction", FUNC1),
|
||||
0x9D: ("BranchIfTrue", BRANCH),
|
||||
0x9F: ("GotoFrame2", U32),
|
||||
0xA1: ("PushString", STR64),
|
||||
0xA2: ("PushConstantByte", U8CONST),
|
||||
0xA3: ("PushConstantWord", U16CONST),
|
||||
0xA4: ("GetStringVar", STR64),
|
||||
0xA5: ("GetStringMember", STR64),
|
||||
0xA6: ("SetStringVar", STR64),
|
||||
0xA7: ("SetStringMember", STR64),
|
||||
0xAE: ("PushValueOfVar", U8CONST),
|
||||
0xAF: ("GetNamedMember", U8CONST),
|
||||
0xB0: ("CallNamedFuncPop", U8CONST),
|
||||
0xB1: ("CallNamedFunc", U8CONST),
|
||||
0xB2: ("CallNamedMethodPop", U8CONST),
|
||||
0xB3: ("CallNamedMethod", U8CONST),
|
||||
0xB4: ("PushFloat", F32),
|
||||
0xB5: ("PushByte", U8LIT),
|
||||
0xB6: ("PushShort", U16LIT),
|
||||
0xB8: ("BranchIfFalse", BRANCH),
|
||||
0xB9: ("PushRegister", U8REG),
|
||||
}
|
||||
|
||||
ALIGNED_KINDS = {BRANCH, U32, F32, STR64, POOL, FUNC2, FUNC1}
|
||||
|
||||
|
||||
class DecodeError(Exception):
|
||||
"""Raised when the stream cannot be decoded without guessing."""
|
||||
|
||||
|
||||
@dataclass
|
||||
class Instr:
|
||||
offset: int
|
||||
opcode: int
|
||||
mnemonic: str
|
||||
length: int # opcode byte through end of operand block, incl. padding
|
||||
operands: dict
|
||||
raw: bytes
|
||||
target: int | None = None # resolved branch destination
|
||||
comment: str = ""
|
||||
|
||||
def render(self, width: int = 22) -> str:
|
||||
ops = self.comment or ""
|
||||
return f" {self.offset:#07x} {self.mnemonic:<{width}} {ops}"
|
||||
|
||||
|
||||
@dataclass
|
||||
class Function:
|
||||
name: str
|
||||
record_offset: int # offset of the DefineFunction* opcode byte
|
||||
body_start: int
|
||||
body_end: int
|
||||
n_params: int
|
||||
n_registers: int
|
||||
flags: int
|
||||
params: list = field(default_factory=list)
|
||||
|
||||
@property
|
||||
def anonymous(self) -> bool:
|
||||
return not self.name
|
||||
|
||||
|
||||
PRELOAD_FLAGS = [
|
||||
(0x010000, "PreloadExtern"),
|
||||
(0x008000, "PreloadParent"),
|
||||
(0x004000, "PreloadRoot"),
|
||||
(0x002000, "SupressSuper"),
|
||||
(0x001000, "PreloadSuper"),
|
||||
(0x000800, "SupressArguments"),
|
||||
(0x000400, "PreloadArguments"),
|
||||
(0x000200, "SupressThis"),
|
||||
(0x000100, "PreloadThis"),
|
||||
(0x000001, "PreloadGlobal"),
|
||||
]
|
||||
|
||||
# Registers preloaded by the VM, in flag order, starting at index 1.
|
||||
PRELOAD_ORDER = [
|
||||
(0x000100, "this"),
|
||||
(0x000400, "arguments"),
|
||||
(0x001000, "super"),
|
||||
(0x004000, "_root"),
|
||||
(0x008000, "_parent"),
|
||||
(0x000001, "_global"),
|
||||
(0x010000, "extern"),
|
||||
]
|
||||
|
||||
|
||||
def flag_names(flags: int) -> str:
|
||||
got = [n for bit, n in PRELOAD_FLAGS if flags & bit]
|
||||
return "|".join(got) if got else "0"
|
||||
|
||||
|
||||
def register_map(fn: Function) -> dict[int, str]:
|
||||
"""Reproduce the VM's register preload order, then bound parameters."""
|
||||
regs: dict[int, str] = {}
|
||||
idx = 1
|
||||
for bit, name in PRELOAD_ORDER:
|
||||
if fn.flags & bit:
|
||||
regs[idx] = name
|
||||
idx += 1
|
||||
for reg, pname in fn.params:
|
||||
if reg:
|
||||
regs[reg] = pname
|
||||
return regs
|
||||
|
||||
|
||||
class ConstPool:
|
||||
"""The 'Apt1' container member: header, 16-byte entries, string table."""
|
||||
|
||||
def __init__(self, data: bytes):
|
||||
if data[:4] != APT1_MAGIC:
|
||||
raise DecodeError(f"not an Apt1 member: {data[:4]!r}")
|
||||
self.data = data
|
||||
self.count = struct.unpack_from("<Q", data, 0x20)[0]
|
||||
self.first = struct.unpack_from("<Q", data, 0x28)[0]
|
||||
self.entries: list[tuple[int, int, str | None]] = []
|
||||
for i in range(self.count):
|
||||
off = self.first + i * 16
|
||||
if off + 16 > len(data):
|
||||
raise DecodeError(f"const entry {i} at {off:#x} runs past end")
|
||||
etype, value = struct.unpack_from("<QQ", data, off)
|
||||
text = None
|
||||
if etype == 1:
|
||||
if not (0 < value < len(data)):
|
||||
raise DecodeError(
|
||||
f"const entry {i}: string offset {value:#x} outside member"
|
||||
)
|
||||
end = data.find(b"\0", value)
|
||||
if end < 0:
|
||||
raise DecodeError(f"const entry {i}: unterminated string")
|
||||
text = data[value:end].decode("latin1")
|
||||
self.entries.append((etype, value, text))
|
||||
|
||||
def string(self, index: int) -> str:
|
||||
if not (0 <= index < len(self.entries)):
|
||||
raise DecodeError(f"const index {index} out of range (0..{len(self.entries)-1})")
|
||||
etype, _, text = self.entries[index]
|
||||
if etype != 1 or text is None:
|
||||
raise DecodeError(f"const index {index} is type {etype}, not a string")
|
||||
return text
|
||||
|
||||
def find(self, needle: str) -> list[int]:
|
||||
return [i for i, (_, _, t) in enumerate(self.entries) if t == needle]
|
||||
|
||||
|
||||
class AptData:
|
||||
"""The 'Apt Data' container member: movie structures plus action streams."""
|
||||
|
||||
def __init__(self, data: bytes, pool: ConstPool):
|
||||
if not data.startswith(APTDATA_MAGIC[:8]):
|
||||
raise DecodeError(f"not an Apt Data member: {data[:16]!r}")
|
||||
self.data = data
|
||||
self.pool = pool
|
||||
self.scope: list[str] = [] # installed by ConstantPool
|
||||
self.functions: list[Function] = []
|
||||
|
||||
# -- helpers ---------------------------------------------------------
|
||||
def cstr(self, off: int) -> str:
|
||||
if not (0 <= off < len(self.data)):
|
||||
raise DecodeError(f"string offset {off:#x} outside Apt Data")
|
||||
end = self.data.find(b"\0", off)
|
||||
if end < 0:
|
||||
raise DecodeError(f"unterminated string at {off:#x}")
|
||||
return self.data[off:end].decode("latin1")
|
||||
|
||||
def const(self, index: int) -> str:
|
||||
"""Resolve through the scope pool installed by the most recent 0x88."""
|
||||
if self.scope:
|
||||
if not (0 <= index < len(self.scope)):
|
||||
raise DecodeError(
|
||||
f"scope-pool index {index} out of range (0..{len(self.scope)-1})"
|
||||
)
|
||||
return self.scope[index]
|
||||
return self.pool.string(index)
|
||||
|
||||
def install_pool(self, ids: list[int]) -> None:
|
||||
self.scope = [self.pool.string(i) for i in ids]
|
||||
|
||||
# -- instruction decoding --------------------------------------------
|
||||
def decode_one(self, pos: int) -> Instr:
|
||||
d = self.data
|
||||
if pos >= len(d):
|
||||
raise DecodeError(f"position {pos:#x} past end of stream")
|
||||
op = d[pos]
|
||||
entry = OPCODES.get(op)
|
||||
if entry is None:
|
||||
raise DecodeError(
|
||||
f"unknown opcode {op:#04x} at {pos:#07x} "
|
||||
f"(raw {d[pos:pos+8].hex(' ')}) - refusing to guess its length"
|
||||
)
|
||||
mnem, kind = entry
|
||||
p = pos + 1
|
||||
if kind in ALIGNED_KINDS:
|
||||
p = (p + ALIGN - 1) & ~(ALIGN - 1)
|
||||
|
||||
ops: dict = {}
|
||||
comment = ""
|
||||
target = None
|
||||
|
||||
def need(n: int) -> None:
|
||||
if p + n > len(d):
|
||||
raise DecodeError(f"{mnem} at {pos:#07x} truncated: needs {n} bytes")
|
||||
|
||||
if kind == NONE:
|
||||
pass
|
||||
elif kind in (U8REG, U8LIT):
|
||||
need(1)
|
||||
ops["value"] = d[p]
|
||||
p += 1
|
||||
comment = f"r{ops['value']}" if kind == U8REG else str(ops["value"])
|
||||
elif kind == U8CONST:
|
||||
need(1)
|
||||
ops["index"] = d[p]
|
||||
p += 1
|
||||
comment = f"{ops['index']:#04x} -> {self.const(ops['index'])!r}"
|
||||
elif kind == U16CONST:
|
||||
need(2)
|
||||
ops["index"] = struct.unpack_from("<H", d, p)[0]
|
||||
p += 2
|
||||
comment = f"{ops['index']:#06x} -> {self.const(ops['index'])!r}"
|
||||
elif kind == U16LIT:
|
||||
need(2)
|
||||
ops["value"] = struct.unpack_from("<H", d, p)[0]
|
||||
p += 2
|
||||
comment = str(ops["value"])
|
||||
elif kind == U32:
|
||||
need(4)
|
||||
ops["value"] = struct.unpack_from("<I", d, p)[0]
|
||||
p += 4
|
||||
comment = str(ops["value"])
|
||||
elif kind == F32:
|
||||
need(4)
|
||||
ops["value"] = struct.unpack_from("<f", d, p)[0]
|
||||
p += 4
|
||||
comment = repr(ops["value"])
|
||||
elif kind == BRANCH:
|
||||
need(4)
|
||||
disp = struct.unpack_from("<i", d, p)[0]
|
||||
p += 4
|
||||
ops["displacement"] = disp
|
||||
target = p + disp # base = end of record
|
||||
comment = f"{disp:+d} -> {target:#07x}"
|
||||
elif kind == STR64:
|
||||
need(8)
|
||||
off = struct.unpack_from("<Q", d, p)[0]
|
||||
p += 8
|
||||
ops["offset"] = off
|
||||
ops["text"] = self.cstr(off)
|
||||
comment = f"{ops['text']!r}"
|
||||
elif kind == POOL:
|
||||
need(16)
|
||||
count, arr = struct.unpack_from("<QQ", d, p)
|
||||
p += 16
|
||||
if arr + count * 8 > len(d):
|
||||
raise DecodeError(f"{mnem} at {pos:#07x}: array {arr:#x}[{count}] overruns")
|
||||
ids = list(struct.unpack_from(f"<{count}Q", d, arr))
|
||||
ops["count"], ops["array"], ops["ids"] = count, arr, ids
|
||||
comment = f"count={count} array={arr:#x}"
|
||||
elif kind in (FUNC2, FUNC1):
|
||||
if kind == FUNC2:
|
||||
need(48)
|
||||
name_off, n_params = struct.unpack_from("<QI", d, p)
|
||||
n_reg = d[p + 12]
|
||||
flags = int.from_bytes(d[p + 13:p + 16], "little")
|
||||
plist, body = struct.unpack_from("<QQ", d, p + 16)
|
||||
lo, hi = struct.unpack_from("<QQ", d, p + 32)
|
||||
p += 48
|
||||
else:
|
||||
need(40)
|
||||
name_off, n_params, plist, body = struct.unpack_from("<QQQQ", d, p)
|
||||
n_reg, flags = 4, 0
|
||||
lo, hi = struct.unpack_from("<QQ", d, p + 32)
|
||||
p += 40
|
||||
if (lo, hi) != (FUNC_SENTINEL_LO, FUNC_SENTINEL_HI):
|
||||
raise DecodeError(
|
||||
f"{mnem} at {pos:#07x}: bad trailer {lo:#x}/{hi:#x}, "
|
||||
"record layout is wrong"
|
||||
)
|
||||
name = self.cstr(name_off)
|
||||
params = []
|
||||
for i in range(n_params):
|
||||
e = plist + i * 16
|
||||
if e + 16 > len(d):
|
||||
raise DecodeError(f"{mnem} at {pos:#07x}: param {i} overruns")
|
||||
reg, pn = struct.unpack_from("<QQ", d, e)
|
||||
params.append((reg, self.cstr(pn)))
|
||||
ops.update(name=name, n_params=n_params, n_registers=n_reg,
|
||||
flags=flags, params=params, body_size=body)
|
||||
comment = (f"{name or '<anonymous>'}({', '.join(n for _, n in params)}) "
|
||||
f"nRegs={n_reg} flags={flag_names(flags)} bodySize={body}")
|
||||
ops["body_start"] = p
|
||||
ops["body_end"] = p + body
|
||||
else:
|
||||
raise DecodeError(f"internal: unhandled kind {kind}")
|
||||
|
||||
return Instr(pos, op, mnem, p - pos, ops, d[pos:p], target, comment)
|
||||
|
||||
def decode_stream(self, start: int, limit: int | None = None) -> list[Instr]:
|
||||
"""Linear decode using the reference termination rule.
|
||||
|
||||
Stops when the last instruction was End AND we are past every branch
|
||||
destination seen so far. A stream may legitimately continue past an End.
|
||||
"""
|
||||
out: list[Instr] = []
|
||||
pos = start
|
||||
furthest = start
|
||||
while True:
|
||||
if limit is not None and pos >= limit:
|
||||
break
|
||||
ins = self.decode_one(pos)
|
||||
out.append(ins)
|
||||
if ins.target is not None:
|
||||
furthest = max(furthest, ins.target)
|
||||
if ins.mnemonic == "ConstantPool":
|
||||
self.install_pool(ins.operands["ids"])
|
||||
if ins.mnemonic in ("DefineFunction2", "DefineFunction"):
|
||||
fn = Function(
|
||||
name=ins.operands["name"],
|
||||
record_offset=ins.offset,
|
||||
body_start=ins.operands["body_start"],
|
||||
body_end=ins.operands["body_end"],
|
||||
n_params=ins.operands["n_params"],
|
||||
n_registers=ins.operands["n_registers"],
|
||||
flags=ins.operands["flags"],
|
||||
params=ins.operands["params"],
|
||||
)
|
||||
self.functions.append(fn)
|
||||
furthest = max(furthest, fn.body_end)
|
||||
pos = ins.offset + ins.length
|
||||
if ins.mnemonic == "End" and pos > furthest:
|
||||
break
|
||||
return out
|
||||
|
||||
|
||||
def load(apt1_path: str, aptdata_path: str) -> tuple[ConstPool, AptData]:
|
||||
pool = ConstPool(open(apt1_path, "rb").read())
|
||||
movie = AptData(open(aptdata_path, "rb").read(), pool)
|
||||
return pool, movie
|
||||
|
||||
|
||||
def find_streams(movie: AptData) -> list[int]:
|
||||
"""Seed stream starts: every ConstantPool record that validates."""
|
||||
seeds = []
|
||||
d = movie.data
|
||||
for p in range(len(d)):
|
||||
if d[p] != 0x88:
|
||||
continue
|
||||
try:
|
||||
ins = movie.decode_one(p)
|
||||
except DecodeError:
|
||||
continue
|
||||
if ins.operands.get("count", 0) and ins.operands["ids"] == list(
|
||||
range(ins.operands["count"])
|
||||
):
|
||||
seeds.append(p)
|
||||
return seeds
|
||||
|
||||
|
||||
def main(argv: list[str] | None = None) -> int:
|
||||
ap = argparse.ArgumentParser(description=__doc__,
|
||||
formatter_class=argparse.RawDescriptionHelpFormatter)
|
||||
ap.add_argument("--apt1", default="fifa17-recon/data/apt/futSelectTeam_Apt1.bin")
|
||||
ap.add_argument("--aptdata", default="fifa17-recon/data/apt/futSelectTeam_AptData.bin")
|
||||
ap.add_argument("--stream", type=lambda s: int(s, 0), help="decode one stream at offset")
|
||||
ap.add_argument("--function", help="decode the named function's body")
|
||||
ap.add_argument("--list-functions", action="store_true")
|
||||
ap.add_argument("--report", action="store_true", help="structural validation report")
|
||||
ap.add_argument("--strings", action="store_true", help="dump the constant pool")
|
||||
ap.add_argument("--selftest", action="store_true")
|
||||
args = ap.parse_args(argv)
|
||||
|
||||
pool, movie = load(args.apt1, args.aptdata)
|
||||
|
||||
if args.selftest:
|
||||
return selftest(pool, movie)
|
||||
|
||||
if args.strings:
|
||||
for i, (t, v, s) in enumerate(pool.entries):
|
||||
print(f" #{i:3d} type={t} @{v:#07x} {s!r}")
|
||||
return 0
|
||||
|
||||
seeds = find_streams(movie)
|
||||
if args.stream is not None:
|
||||
seeds = [args.stream]
|
||||
|
||||
all_instrs: list[Instr] = []
|
||||
for s in seeds:
|
||||
all_instrs.extend(movie.decode_stream(s))
|
||||
|
||||
if args.list_functions:
|
||||
for fn in movie.functions:
|
||||
regs = register_map(fn)
|
||||
rs = " ".join(f"r{k}={v}" for k, v in sorted(regs.items()))
|
||||
print(f" {fn.body_start:#07x}-{fn.body_end:#07x} "
|
||||
f"{fn.name or '<anonymous>':<34} {rs}")
|
||||
return 0
|
||||
|
||||
if args.function:
|
||||
for fn in movie.functions:
|
||||
if fn.name == args.function:
|
||||
print(f"; {fn.name} body {fn.body_start:#x}..{fn.body_end:#x} "
|
||||
f"flags={flag_names(fn.flags)} nRegs={fn.n_registers}")
|
||||
regs = register_map(fn)
|
||||
for k, v in sorted(regs.items()):
|
||||
print(f"; r{k} = {v}")
|
||||
for ins in movie.decode_stream(fn.body_start, fn.body_end):
|
||||
print(ins.render())
|
||||
return 0
|
||||
print(f"function {args.function!r} not found", file=sys.stderr)
|
||||
return 1
|
||||
|
||||
if args.report:
|
||||
return report(movie, seeds, all_instrs)
|
||||
|
||||
for ins in all_instrs:
|
||||
print(ins.render())
|
||||
return 0
|
||||
|
||||
|
||||
def report(movie: AptData, seeds: list[int], instrs: list[Instr]) -> int:
|
||||
import collections
|
||||
hist = collections.Counter(i.mnemonic for i in instrs)
|
||||
covered = set()
|
||||
for i in instrs:
|
||||
covered.update(range(i.offset, i.offset + i.length))
|
||||
branches = [i for i in instrs if i.target is not None]
|
||||
boundaries = {i.offset for i in instrs}
|
||||
bad = [i for i in branches if i.target not in boundaries]
|
||||
print(f" streams decoded : {len(seeds)} {[hex(s) for s in seeds]}")
|
||||
print(f" instructions : {len(instrs)}")
|
||||
print(f" bytes covered : {len(covered)} of {len(movie.data)}")
|
||||
print(f" functions : {len(movie.functions)}")
|
||||
print(f" branches : {len(branches)}")
|
||||
print(f" invalid branch targets: {len(bad)}")
|
||||
for i in bad[:10]:
|
||||
print(f" {i.offset:#07x} {i.mnemonic} -> {i.target:#07x}")
|
||||
print(f" distinct opcodes : {len(hist)}")
|
||||
for m, n in hist.most_common():
|
||||
print(f" {m:<22} {n}")
|
||||
return 1 if bad else 0
|
||||
|
||||
|
||||
def selftest(pool: ConstPool, movie: AptData) -> int:
|
||||
"""Assertions that pin the measured format facts."""
|
||||
ok = True
|
||||
|
||||
def check(label: str, cond: bool, detail: str = "") -> None:
|
||||
nonlocal ok
|
||||
print(f" [{'PASS' if cond else 'FAIL'}] {label}{(' - ' + detail) if detail else ''}")
|
||||
ok = ok and cond
|
||||
|
||||
check("Apt1 entry count", pool.count == 414, f"{pool.count}")
|
||||
check("Apt1 all entries are strings",
|
||||
all(t == 1 for t, _, _ in pool.entries))
|
||||
check("Apt1 entry array abuts string table",
|
||||
pool.first + pool.count * 16 == min(v for t, v, _ in pool.entries if t == 1))
|
||||
|
||||
# Phase 3: exact pointer -> string resolution for known symbols.
|
||||
for name in ("CheckIsKitLocked", "KITS_AVAILABLE", "FUT_GET_MATCH_KITS_DP",
|
||||
"mcLockHome"):
|
||||
idx = pool.find(name)
|
||||
check(f"string resolves: {name}", len(idx) == 1 and pool.string(idx[0]) == name,
|
||||
f"index {idx}")
|
||||
|
||||
# Bad pointers must raise, not fuzzy-match.
|
||||
for bad in (-1, 10 ** 6):
|
||||
try:
|
||||
pool.string(bad)
|
||||
check(f"bad const index {bad} rejected", False)
|
||||
except DecodeError:
|
||||
check(f"bad const index {bad} rejected", True)
|
||||
|
||||
# Phase 4 fixtures for the two EA opcodes.
|
||||
movie.scope = ["alpha", "beta"] + [f"c{i}" for i in range(2, 300)]
|
||||
fixtures = [
|
||||
(bytes([0xB9, 0x00]), "PushRegister", 2, "r0"),
|
||||
(bytes([0xB9, 0x05]), "PushRegister", 2, "r5"),
|
||||
(bytes([0xB9, 0xFF]), "PushRegister", 2, "r255"),
|
||||
(bytes([0xAF, 0x00]), "GetNamedMember", 2, "'alpha'"),
|
||||
(bytes([0xAF, 0x01]), "GetNamedMember", 2, "'beta'"),
|
||||
(bytes([0xA2, 0x01]), "PushConstantByte", 2, "'beta'"),
|
||||
]
|
||||
for raw, mnem, length, needle in fixtures:
|
||||
probe = AptData(APTDATA_MAGIC + raw.ljust(16, b"\0"), pool)
|
||||
probe.scope = movie.scope
|
||||
ins = probe.decode_one(16)
|
||||
check(f"fixture {raw.hex()} -> {mnem}",
|
||||
ins.mnemonic == mnem and ins.length == length and needle in ins.comment,
|
||||
f"{ins.mnemonic} len={ins.length} {ins.comment}")
|
||||
|
||||
# Truncated records must fail closed.
|
||||
for raw in (bytes([0xB9]), bytes([0xAF]), bytes([0xA3, 0x01])):
|
||||
probe = AptData(APTDATA_MAGIC + raw, pool)
|
||||
probe.scope = movie.scope
|
||||
try:
|
||||
probe.decode_one(16)
|
||||
check(f"truncated {raw.hex()} fails closed", False)
|
||||
except DecodeError:
|
||||
check(f"truncated {raw.hex()} fails closed", True)
|
||||
|
||||
# Out-of-range pool index must fail closed, not silently clamp.
|
||||
probe = AptData(APTDATA_MAGIC + bytes([0xAF, 0x10]), pool)
|
||||
probe.scope = ["only-one"]
|
||||
try:
|
||||
probe.decode_one(16)
|
||||
check("out-of-range scope index rejected", False)
|
||||
except DecodeError:
|
||||
check("out-of-range scope index rejected", True)
|
||||
|
||||
# Unknown opcode must refuse rather than resynchronise.
|
||||
probe = AptData(APTDATA_MAGIC + bytes([0xEE, 0x00]), pool)
|
||||
try:
|
||||
probe.decode_one(16)
|
||||
check("unknown opcode refuses to guess length", False)
|
||||
except DecodeError as e:
|
||||
check("unknown opcode refuses to guess length", "refusing to guess" in str(e))
|
||||
|
||||
# Whole-artifact decode.
|
||||
movie.scope = []
|
||||
movie.functions = []
|
||||
seeds = find_streams(movie)
|
||||
instrs: list[Instr] = []
|
||||
try:
|
||||
for s in seeds:
|
||||
instrs.extend(movie.decode_stream(s))
|
||||
check("whole artifact decodes", True, f"{len(instrs)} instructions")
|
||||
except DecodeError as e:
|
||||
check("whole artifact decodes", False, str(e))
|
||||
return 1
|
||||
|
||||
boundaries = {i.offset for i in instrs}
|
||||
bad = [i for i in instrs if i.target is not None and i.target not in boundaries]
|
||||
check("every branch lands on an instruction boundary", not bad,
|
||||
f"{len(bad)} bad")
|
||||
|
||||
# CheckIsKitLocked is CALLED here, never defined here: it is a method on the
|
||||
# mcSelectTeam child clip, whose class lives in another asset. Assert the
|
||||
# call site is bound exactly, and that this asset defines no such function.
|
||||
called = [i for i in instrs if i.comment and "CheckIsKitLocked" in i.comment]
|
||||
check("CheckIsKitLocked referenced exactly once", len(called) == 1,
|
||||
f"{[hex(i.offset) for i in called]}")
|
||||
check("CheckIsKitLocked reference is PushConstantWord (pool index > u8)",
|
||||
bool(called) and called[0].mnemonic == "PushConstantWord")
|
||||
check("CheckIsKitLocked is not defined in this asset",
|
||||
"CheckIsKitLocked" not in {f.name for f in movie.functions})
|
||||
|
||||
# The gate contract the native DP builder must satisfy.
|
||||
gate = [i for i in instrs if i.comment and "KITS_AVAILABLE" in i.comment]
|
||||
check("KITS_AVAILABLE read exactly once", len(gate) == 1)
|
||||
check("KITS_AVAILABLE read via GetNamedMember on the DP header",
|
||||
bool(gate) and gate[0].mnemonic == "GetNamedMember")
|
||||
|
||||
# 8-byte alignment is load-bearing: prove 4 would break the pool record.
|
||||
p4 = (0xD38 + 1 + 3) & ~3
|
||||
c4 = struct.unpack_from("<Q", movie.data, p4)[0]
|
||||
check("alignment is 8 not 4", c4 != 401, f"align4 count would be {c4:#x}")
|
||||
|
||||
print(f"\n {'ALL PASS' if ok else 'FAILURES PRESENT'}")
|
||||
return 0 if ok else 1
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Executable
+587
@@ -0,0 +1,587 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Interpret FIFA 17's atom -> field-id dispatch functions instead of pattern-scanning them.
|
||||
|
||||
WHY THIS EXISTS
|
||||
---------------
|
||||
CardsDLL turns a JSON key into an "atom index" (a position in the string-pointer
|
||||
table at .data 0x1802d2760), then a per-response-family mapper converts that index
|
||||
into an internal field id with a chain of integer compares and jump tables.
|
||||
|
||||
A previous attempt to recover each mapper's accepted atoms by scanning for
|
||||
`sub ecx,K` / `cmp ecx,L` / `ja` patterns produced a confidently wrong answer: it
|
||||
reported that no mapper accepts atom 424 (`manager`), while a live client plainly
|
||||
holds a resident manager record. Pattern scanning cannot see control flow, so it
|
||||
cannot tell which compares are actually reachable.
|
||||
|
||||
This module executes the mappers instead. The modelled subset is exactly what these
|
||||
functions use: the resolver call, integer cmp/sub/add/dec, conditional and computed
|
||||
jumps, jump-table loads out of the image, lea, movsxd, and `mov eax,imm; ret`.
|
||||
Anything outside that subset raises Unsupported, so a wrong field id is never
|
||||
returned silently.
|
||||
|
||||
TWO DECODER TRAPS THIS MODULE IS REQUIRED TO HANDLE
|
||||
---------------------------------------------------
|
||||
1. ModRM rm==5 with mod!=0 is [rbp+disp], NOT RIP-relative. Only mod==0 with rm==5
|
||||
is RIP-relative. Treating all rm==5 as RIP-relative hides rbp-based DTO accesses.
|
||||
Covered by test_rbp_relative_is_not_rip_relative.
|
||||
2. A constant frequently arrives in a register (`mov r8d,0x4` ... later stored), so
|
||||
searching for an immediate-to-memory store misses it. The interpreter tracks
|
||||
register values, so propagated constants are followed.
|
||||
Covered by test_constant_propagated_through_register.
|
||||
|
||||
Run `--selftest` to execute the positive controls. Negative results from this tool
|
||||
are only admissible when the selftest passes.
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
import bisect
|
||||
import struct
|
||||
import sys
|
||||
from pathlib import Path
|
||||
|
||||
REGS = ("rax", "rcx", "rdx", "rbx", "rsp", "rbp", "rsi", "rdi",
|
||||
"r8", "r9", "r10", "r11", "r12", "r13", "r14", "r15")
|
||||
|
||||
ATOM_TABLE_BASE = 0x1802D2760 # validated against 6 known anchors, see anchors()
|
||||
ATOM_RESOLVER = 0x180180D00 # key string -> atom index, returns in eax
|
||||
ITEM_MAPPER = 0x18012FD40 # the DTO/item mapper: atom 568 'players' -> 1
|
||||
|
||||
|
||||
class Unsupported(Exception):
|
||||
"""The mapper used an instruction or address outside the modelled subset."""
|
||||
|
||||
|
||||
def s32(v: int) -> int:
|
||||
v &= 0xFFFFFFFF
|
||||
return v - 0x100000000 if v & 0x80000000 else v
|
||||
|
||||
|
||||
class Image:
|
||||
"""A parsed PE, with VA<->file mapping and .pdata function bounds."""
|
||||
|
||||
def __init__(self, path: Path):
|
||||
self.buf = path.read_bytes()
|
||||
b = self.buf
|
||||
pe = struct.unpack_from("<I", b, 0x3C)[0]
|
||||
if b[pe:pe + 4] != b"PE\0\0":
|
||||
raise ValueError(f"{path} is not a PE image")
|
||||
nsec = struct.unpack_from("<H", b, pe + 6)[0]
|
||||
optsz = struct.unpack_from("<H", b, pe + 20)[0]
|
||||
self.base = struct.unpack_from("<Q", b, pe + 24 + 24)[0]
|
||||
self.sections = []
|
||||
for i in range(nsec):
|
||||
o = pe + 24 + optsz + 40 * i
|
||||
name = b[o:o + 8].rstrip(b"\0").decode(errors="replace")
|
||||
vsz, va, rsz, raw = struct.unpack_from("<IIII", b, o + 8)
|
||||
self.sections.append((name, va, vsz, raw, rsz))
|
||||
self._funcs = None
|
||||
|
||||
def va2off(self, va: int):
|
||||
rva = va - self.base
|
||||
for _name, sva, vsz, raw, rsz in self.sections:
|
||||
if sva <= rva < sva + max(vsz, rsz):
|
||||
off = raw + (rva - sva)
|
||||
if off < len(self.buf):
|
||||
return off
|
||||
return None
|
||||
|
||||
def rd8(self, va: int) -> int:
|
||||
o = self.va2off(va)
|
||||
if o is None:
|
||||
raise Unsupported(f"unmapped byte read 0x{va:x}")
|
||||
return self.buf[o]
|
||||
|
||||
def rd32(self, va: int) -> int:
|
||||
o = self.va2off(va)
|
||||
if o is None:
|
||||
raise Unsupported(f"unmapped dword read 0x{va:x}")
|
||||
return struct.unpack_from("<I", self.buf, o)[0]
|
||||
|
||||
def cstr(self, va: int, maxlen: int = 96):
|
||||
o = self.va2off(va)
|
||||
if o is None:
|
||||
return None
|
||||
end = self.buf.find(b"\0", o, o + maxlen)
|
||||
if end < 0:
|
||||
return None
|
||||
try:
|
||||
return self.buf[o:end].decode("ascii")
|
||||
except UnicodeDecodeError:
|
||||
return None
|
||||
|
||||
# ---- .pdata gives exact function bounds; never guess a prologue ----
|
||||
def functions(self):
|
||||
if self._funcs is None:
|
||||
sec = next(s for s in self.sections if s[0] == ".pdata")
|
||||
_n, _va, vsz, raw, _rsz = sec
|
||||
out = []
|
||||
for i in range(vsz // 12):
|
||||
beg, end, _unw = struct.unpack_from("<III", self.buf, raw + 12 * i)
|
||||
if beg or end:
|
||||
out.append((self.base + beg, self.base + end))
|
||||
out.sort()
|
||||
self._funcs = out
|
||||
return self._funcs
|
||||
|
||||
def function_of(self, va: int):
|
||||
fs = self.functions()
|
||||
starts = [f[0] for f in fs]
|
||||
i = bisect.bisect_right(starts, va) - 1
|
||||
if i >= 0 and fs[i][0] <= va < fs[i][1]:
|
||||
return fs[i]
|
||||
return None
|
||||
|
||||
def atom(self, index: int):
|
||||
ptr = struct.unpack_from("<Q", self.buf, self.va2off(ATOM_TABLE_BASE) + 8 * index)[0]
|
||||
return self.cstr(ptr)
|
||||
|
||||
def atom_index(self, name: str):
|
||||
off = self.va2off(ATOM_TABLE_BASE)
|
||||
for i in range(4096):
|
||||
ptr = struct.unpack_from("<Q", self.buf, off + 8 * i)[0]
|
||||
if self.cstr(ptr) == name:
|
||||
return i
|
||||
return None
|
||||
|
||||
|
||||
class Mapper:
|
||||
"""Executes one dispatch function for a given atom index."""
|
||||
|
||||
def __init__(self, image: Image, resolver: int = ATOM_RESOLVER):
|
||||
self.img = image
|
||||
self.resolver = resolver
|
||||
|
||||
def _ea(self, k: int, rex: int, r: dict):
|
||||
"""Decode ModRM[+SIB][+disp].
|
||||
|
||||
Returns (nbytes, dst_reg, addr, src_reg). addr is an int, or the marker
|
||||
("rip", disp) which the caller resolves once it knows the instruction
|
||||
length, or None for a register-form operand.
|
||||
|
||||
TRAP 1: rm==5 is RIP-relative ONLY when mod==0. With mod 1 or 2 it is
|
||||
[rbp+disp] and must be resolved from rbp.
|
||||
"""
|
||||
b = self.img.buf
|
||||
modrm = b[k]
|
||||
mod, rm = modrm >> 6, modrm & 7
|
||||
dst = REGS[(((modrm >> 3) & 7) | ((rex & 4) << 1)) & 15]
|
||||
n = 1
|
||||
if mod == 3:
|
||||
return n, dst, None, REGS[(rm | ((rex & 1) << 3)) & 15]
|
||||
base_v = idx_v = disp = 0
|
||||
if rm == 4:
|
||||
sib = b[k + 1]
|
||||
n += 1
|
||||
scale = 1 << (sib >> 6)
|
||||
ir = ((sib >> 3) & 7) | ((rex & 2) << 2)
|
||||
br = (sib & 7) | ((rex & 1) << 3)
|
||||
if (ir & 15) != 4:
|
||||
idx_v = r[REGS[ir & 15]] * scale
|
||||
if (sib & 7) == 5 and mod == 0:
|
||||
disp = struct.unpack_from("<i", b, k + n)[0]
|
||||
n += 4
|
||||
else:
|
||||
base_v = r[REGS[br & 15]]
|
||||
elif rm == 5 and mod == 0:
|
||||
disp = struct.unpack_from("<i", b, k + 1)[0]
|
||||
return n + 4, dst, ("rip", disp), None
|
||||
else:
|
||||
base_v = r[REGS[(rm | ((rex & 1) << 3)) & 15]]
|
||||
if mod == 1:
|
||||
disp = struct.unpack_from("<b", b, k + n)[0]
|
||||
n += 1
|
||||
elif mod == 2:
|
||||
disp = struct.unpack_from("<i", b, k + n)[0]
|
||||
n += 4
|
||||
return n, dst, (base_v + idx_v + disp) & 0xFFFFFFFFFFFFFFFF, None
|
||||
|
||||
@staticmethod
|
||||
def _cond(cc: int, last) -> bool:
|
||||
a, b = last
|
||||
sa, sb = s32(a), s32(b)
|
||||
ua, ub = a & 0xFFFFFFFF, b & 0xFFFFFFFF
|
||||
if cc == 0x4: return sa == sb
|
||||
if cc == 0x5: return sa != sb
|
||||
if cc == 0xF: return sa > sb
|
||||
if cc == 0xD: return sa >= sb
|
||||
if cc == 0xC: return sa < sb
|
||||
if cc == 0xE: return sa <= sb
|
||||
if cc == 0x7: return ua > ub
|
||||
if cc == 0x3: return ua >= ub
|
||||
if cc == 0x2: return ua < ub
|
||||
if cc == 0x6: return ua <= ub
|
||||
if cc == 0x8: return sa < sb
|
||||
if cc == 0x9: return sa >= sb
|
||||
raise Unsupported(f"condition code 0x{cc:x}")
|
||||
|
||||
def run(self, start: int, atom: int, limit: int = 5000) -> int:
|
||||
b = self.img.buf
|
||||
r = {k: 0 for k in REGS}
|
||||
last = (0, 0)
|
||||
va = start
|
||||
for _ in range(limit):
|
||||
i0 = self.img.va2off(va)
|
||||
if i0 is None:
|
||||
raise Unsupported(f"pc unmapped 0x{va:x}")
|
||||
j = i0
|
||||
while b[j] in (0x66, 0x67, 0xF2, 0xF3):
|
||||
j += 1
|
||||
rex = 0
|
||||
if 0x40 <= b[j] <= 0x4F:
|
||||
rex = b[j]
|
||||
j += 1
|
||||
op = b[j]
|
||||
pre = j - i0
|
||||
|
||||
if op == 0xC3:
|
||||
return r["rax"] & 0xFFFFFFFF
|
||||
if op == 0xCC:
|
||||
raise Unsupported(f"int3 at 0x{va:x}: ran off the end of the function")
|
||||
if op == 0xE8:
|
||||
tgt = va + pre + 5 + struct.unpack_from("<i", b, j + 1)[0]
|
||||
if tgt != self.resolver:
|
||||
raise Unsupported(f"call to non-resolver 0x{tgt:x} at 0x{va:x}")
|
||||
r["rax"] = atom & 0xFFFFFFFF # resolver returns the atom index
|
||||
va += pre + 5
|
||||
continue
|
||||
if op == 0xE9:
|
||||
va += pre + 5 + struct.unpack_from("<i", b, j + 1)[0]
|
||||
continue
|
||||
if op == 0xEB:
|
||||
va += pre + 2 + struct.unpack_from("<b", b, j + 1)[0]
|
||||
continue
|
||||
if 0x70 <= op <= 0x7F:
|
||||
nxt = va + pre + 2
|
||||
rel = struct.unpack_from("<b", b, j + 1)[0]
|
||||
va = nxt + rel if self._cond(op & 0xF, last) else nxt
|
||||
continue
|
||||
if op == 0x0F and 0x80 <= b[j + 1] <= 0x8F:
|
||||
nxt = va + pre + 6
|
||||
rel = struct.unpack_from("<i", b, j + 2)[0]
|
||||
va = nxt + rel if self._cond(b[j + 1] & 0xF, last) else nxt
|
||||
continue
|
||||
if 0xB8 <= op <= 0xBF:
|
||||
r[REGS[((op - 0xB8) | ((rex & 1) << 3)) & 15]] = struct.unpack_from("<I", b, j + 1)[0]
|
||||
va += pre + 5
|
||||
continue
|
||||
if op in (0x05, 0x2D, 0x3D):
|
||||
# accumulator short forms: add/sub/cmp eax, imm32
|
||||
imm = struct.unpack_from("<i", b, j + 1)[0]
|
||||
cur = r["rax"] & 0xFFFFFFFF
|
||||
if op == 0x3D:
|
||||
last = (cur, imm & 0xFFFFFFFF)
|
||||
elif op == 0x2D:
|
||||
r["rax"] = (cur - imm) & 0xFFFFFFFF
|
||||
last = (r["rax"], 0)
|
||||
else:
|
||||
r["rax"] = (cur + imm) & 0xFFFFFFFF
|
||||
last = (r["rax"], 0)
|
||||
va += pre + 5
|
||||
continue
|
||||
if op in (0x81, 0x83):
|
||||
w = 4 if op == 0x81 else 1
|
||||
modrm = b[j + 1]
|
||||
if modrm >> 6 != 3:
|
||||
raise Unsupported(f"{op:02x} memory form at 0x{va:x}")
|
||||
reg = REGS[((modrm & 7) | ((rex & 1) << 3)) & 15]
|
||||
imm = struct.unpack_from("<i" if w == 4 else "<b", b, j + 2)[0]
|
||||
ext = (modrm >> 3) & 7
|
||||
cur = r[reg] & 0xFFFFFFFF
|
||||
if ext == 7:
|
||||
last = (cur, imm & 0xFFFFFFFF)
|
||||
elif ext == 5:
|
||||
r[reg] = (cur - imm) & 0xFFFFFFFF
|
||||
last = (r[reg], 0)
|
||||
elif ext == 0:
|
||||
r[reg] = (cur + imm) & 0xFFFFFFFF
|
||||
last = (r[reg], 0)
|
||||
else:
|
||||
raise Unsupported(f"{op:02x} /{ext} at 0x{va:x}")
|
||||
va += pre + 2 + w
|
||||
continue
|
||||
if op == 0xFF and b[j + 1] >> 6 == 3:
|
||||
ext = (b[j + 1] >> 3) & 7
|
||||
reg = REGS[((b[j + 1] & 7) | ((rex & 1) << 3)) & 15]
|
||||
if ext == 1:
|
||||
r[reg] = (r[reg] - 1) & 0xFFFFFFFF
|
||||
last = (r[reg], 0)
|
||||
va += pre + 2
|
||||
continue
|
||||
if ext == 4:
|
||||
va = r[reg]
|
||||
continue
|
||||
raise Unsupported(f"ff /{ext} at 0x{va:x}")
|
||||
if op == 0x0F and b[j + 1] == 0xB6:
|
||||
n, dst, addr, src = self._ea(j + 2, rex, r)
|
||||
end = va + pre + 2 + n
|
||||
if isinstance(addr, tuple):
|
||||
addr = end + addr[1]
|
||||
r[dst] = self.img.rd8(addr) if addr is not None else r[src] & 0xFF
|
||||
va = end
|
||||
continue
|
||||
if op in (0x8B, 0x8D):
|
||||
n, dst, addr, src = self._ea(j + 1, rex, r)
|
||||
end = va + pre + 1 + n
|
||||
if isinstance(addr, tuple):
|
||||
addr = end + addr[1]
|
||||
if op == 0x8D:
|
||||
if addr is None:
|
||||
raise Unsupported(f"lea with register operand at 0x{va:x}")
|
||||
r[dst] = addr
|
||||
else:
|
||||
if addr is None:
|
||||
# register form: mov r32, r32 (e.g. 8b c8 = mov ecx,eax)
|
||||
r[dst] = r[src] if rex & 8 else r[src] & 0xFFFFFFFF
|
||||
else:
|
||||
r[dst] = self.img.rd32(addr)
|
||||
va = end
|
||||
continue
|
||||
if op == 0x89:
|
||||
modrm = b[j + 1]
|
||||
if modrm >> 6 != 3:
|
||||
raise Unsupported(f"89 memory store at 0x{va:x}")
|
||||
src = REGS[((((modrm >> 3) & 7) | ((rex & 4) << 1))) & 15]
|
||||
dst = REGS[((modrm & 7) | ((rex & 1) << 3)) & 15]
|
||||
r[dst] = r[src] if rex & 8 else r[src] & 0xFFFFFFFF
|
||||
va += pre + 2
|
||||
continue
|
||||
if op == 0x63:
|
||||
modrm = b[j + 1]
|
||||
if modrm >> 6 != 3:
|
||||
raise Unsupported(f"63 memory form at 0x{va:x}")
|
||||
src = REGS[((modrm & 7) | ((rex & 1) << 3)) & 15]
|
||||
dst = REGS[((((modrm >> 3) & 7) | ((rex & 4) << 1))) & 15]
|
||||
r[dst] = s32(r[src]) & 0xFFFFFFFFFFFFFFFF
|
||||
va += pre + 2
|
||||
continue
|
||||
if op in (0x01, 0x03, 0x29, 0x2B, 0x39, 0x3B,
|
||||
0x09, 0x0B, 0x21, 0x23, 0x31, 0x33, 0x85):
|
||||
modrm = b[j + 1]
|
||||
if modrm >> 6 != 3:
|
||||
raise Unsupported(f"{op:02x} memory form at 0x{va:x}")
|
||||
a = REGS[((modrm & 7) | ((rex & 1) << 3)) & 15]
|
||||
c = REGS[((((modrm >> 3) & 7) | ((rex & 4) << 1))) & 15]
|
||||
m = 0xFFFFFFFFFFFFFFFF if rex & 8 else 0xFFFFFFFF
|
||||
if op == 0x01:
|
||||
r[a] = (r[a] + r[c]) & m
|
||||
elif op == 0x03:
|
||||
r[c] = (r[c] + r[a]) & m
|
||||
elif op == 0x29:
|
||||
r[a] = (r[a] - r[c]) & m
|
||||
last = (r[a] & 0xFFFFFFFF, 0)
|
||||
elif op == 0x2B:
|
||||
r[c] = (r[c] - r[a]) & m
|
||||
last = (r[c] & 0xFFFFFFFF, 0)
|
||||
elif op in (0x09, 0x0B, 0x21, 0x23, 0x31, 0x33):
|
||||
fn = {0x09: lambda x, y: x | y, 0x0B: lambda x, y: x | y,
|
||||
0x21: lambda x, y: x & y, 0x23: lambda x, y: x & y,
|
||||
0x31: lambda x, y: x ^ y, 0x33: lambda x, y: x ^ y}[op]
|
||||
if op in (0x09, 0x21, 0x31):
|
||||
r[a] = fn(r[a], r[c]) & m
|
||||
last = (r[a] & 0xFFFFFFFF, 0)
|
||||
else:
|
||||
r[c] = fn(r[c], r[a]) & m
|
||||
last = (r[c] & 0xFFFFFFFF, 0)
|
||||
elif op == 0x85:
|
||||
last = ((r[a] & r[c]) & 0xFFFFFFFF, 0)
|
||||
elif op == 0x39:
|
||||
last = (r[a] & 0xFFFFFFFF, r[c] & 0xFFFFFFFF)
|
||||
else:
|
||||
last = (r[c] & 0xFFFFFFFF, r[a] & 0xFFFFFFFF)
|
||||
va += pre + 2
|
||||
continue
|
||||
if op == 0x90:
|
||||
va += pre + 1
|
||||
continue
|
||||
if op == 0x0F and b[j + 1] == 0x1F:
|
||||
n, _d, _a, _s = self._ea(j + 2, rex, r)
|
||||
va += pre + 2 + n
|
||||
continue
|
||||
raise Unsupported(f"opcode {op:02x} at 0x{va:x}")
|
||||
raise Unsupported("instruction limit reached")
|
||||
|
||||
|
||||
def find_mappers(img: Image, resolver: int = ATOM_RESOLVER):
|
||||
"""Every function containing a direct call to the atom resolver."""
|
||||
sec = next(s for s in img.sections if s[0] == ".text")
|
||||
_n, tva, _vsz, traw, trsz = sec
|
||||
out = {}
|
||||
for i in range(traw, traw + trsz - 5):
|
||||
if img.buf[i] != 0xE8:
|
||||
continue
|
||||
va = img.base + tva + (i - traw)
|
||||
if va + 5 + struct.unpack_from("<i", img.buf, i + 1)[0] == resolver:
|
||||
f = img.function_of(va)
|
||||
if f:
|
||||
out.setdefault(f[0], []).append(va)
|
||||
return out
|
||||
|
||||
|
||||
# --------------------------------------------------------------------------
|
||||
# selftest: the two decoder traps plus the live-verified positive controls
|
||||
# --------------------------------------------------------------------------
|
||||
def test_atom_anchors(img: Image) -> list:
|
||||
"""The atom table base must reproduce known anchors, or every index is wrong."""
|
||||
anchors = {11: "actives", 363: "itemData", 376: "kicktakers",
|
||||
424: "manager", 568: "players", 718: "squadActives"}
|
||||
fails = []
|
||||
for idx, want in anchors.items():
|
||||
got = img.atom(idx)
|
||||
if got != want:
|
||||
fails.append(f"atom[{idx}] = {got!r}, expected {want!r}")
|
||||
return fails
|
||||
|
||||
|
||||
def test_rbp_relative_is_not_rip_relative(img: Image) -> list:
|
||||
"""TRAP 1. mod!=0 with rm==5 must resolve as [rbp+disp], not RIP-relative.
|
||||
|
||||
Encoding under test: 8b 4d 20 == mov ecx,[rbp+0x20] (mod=01, rm=101).
|
||||
A decoder that treats rm==5 as RIP-relative computes a wildly different
|
||||
address and silently reads the wrong memory.
|
||||
"""
|
||||
m = Mapper(img)
|
||||
r = {k: 0 for k in REGS}
|
||||
r["rbp"] = 0x140000000
|
||||
saved = img.buf
|
||||
try:
|
||||
img.buf = bytes.fromhex("8b4d20")
|
||||
n, dst, addr, _src = m._ea(1, 0, r)
|
||||
finally:
|
||||
img.buf = saved
|
||||
fails = []
|
||||
if isinstance(addr, tuple):
|
||||
fails.append("mod=01 rm=101 decoded as RIP-relative; must be [rbp+disp]")
|
||||
elif addr != 0x140000020:
|
||||
fails.append(f"[rbp+0x20] resolved to 0x{addr:x}, expected 0x140000020")
|
||||
if dst != "rcx":
|
||||
fails.append(f"destination decoded as {dst}, expected rcx")
|
||||
if n != 2:
|
||||
fails.append(f"modrm+disp8 consumed {n} bytes, expected 2")
|
||||
return fails
|
||||
|
||||
|
||||
def test_constant_propagated_through_register(img: Image) -> list:
|
||||
"""TRAP 2. A constant reaching a use through a register must be followed.
|
||||
|
||||
Program: mov eax,0; mov r8d,4; mov eax,r8d; ret -> must yield 4, which is
|
||||
only observable if register values propagate. Scanning for an immediate
|
||||
store would see nothing.
|
||||
"""
|
||||
m = Mapper(img)
|
||||
saved = img.buf
|
||||
prog = bytes.fromhex("b800000000" "41b804000000" "4489c0" "c3")
|
||||
try:
|
||||
img.buf = prog
|
||||
img_va2off = img.va2off
|
||||
img.va2off = lambda va: va if 0 <= va < len(prog) else None
|
||||
got = m.run(0, 0)
|
||||
finally:
|
||||
img.buf = saved
|
||||
img.va2off = img_va2off
|
||||
return [] if got == 4 else [f"register-propagated constant yielded {got}, expected 4"]
|
||||
|
||||
|
||||
def test_item_mapper_controls(img: Image) -> list:
|
||||
"""Live/disassembly-verified behaviour of the item mapper."""
|
||||
m = Mapper(img)
|
||||
fails = []
|
||||
got = m.run(ITEM_MAPPER, 568)
|
||||
if got != 1:
|
||||
fails.append(f"item mapper atom 568 'players' -> {got}, expected 1")
|
||||
got = m.run(ITEM_MAPPER, 11)
|
||||
if got != 0:
|
||||
fails.append(f"item mapper atom 11 'actives' -> {got}, expected 0")
|
||||
return fails
|
||||
|
||||
|
||||
def test_manager_424_is_accepted_somewhere(img: Image) -> list:
|
||||
"""MANDATORY control. A live client holds a resident manager record, so some
|
||||
mapper must map atom 424 to a non-zero field id. The previous pattern-scan
|
||||
method failed exactly here, and any replacement must not."""
|
||||
m = Mapper(img)
|
||||
accepting = []
|
||||
for start in find_mappers(img):
|
||||
try:
|
||||
if m.run(start, 424):
|
||||
accepting.append(start)
|
||||
except Unsupported:
|
||||
continue
|
||||
if not accepting:
|
||||
return ["no mapper maps atom 424 'manager' to a non-zero field id, "
|
||||
"which contradicts the live resident manager record"]
|
||||
return []
|
||||
|
||||
|
||||
def selftest(img: Image) -> int:
|
||||
checks = [
|
||||
("atom table anchors", test_atom_anchors),
|
||||
("trap 1: rbp-relative modrm", test_rbp_relative_is_not_rip_relative),
|
||||
("trap 2: constant via register", test_constant_propagated_through_register),
|
||||
("item mapper positive controls", test_item_mapper_controls),
|
||||
("mandatory: manager atom 424 accepted", test_manager_424_is_accepted_somewhere),
|
||||
]
|
||||
bad = 0
|
||||
for name, fn in checks:
|
||||
try:
|
||||
fails = fn(img)
|
||||
except Exception as exc: # noqa: BLE001 - report, don't mask
|
||||
fails = [f"raised {type(exc).__name__}: {exc}"]
|
||||
if fails:
|
||||
bad += 1
|
||||
print(f" FAIL {name}")
|
||||
for f in fails:
|
||||
print(f" {f}")
|
||||
else:
|
||||
print(f" ok {name}")
|
||||
print("\n ALL PASS" if not bad else f"\n {bad} CHECK(S) FAILED - negative results are NOT admissible")
|
||||
return 1 if bad else 0
|
||||
|
||||
|
||||
def main() -> int:
|
||||
ap = argparse.ArgumentParser(description=__doc__,
|
||||
formatter_class=argparse.RawDescriptionHelpFormatter)
|
||||
ap.add_argument("image", type=Path, help="CardsDLL_Win64_retail.dll")
|
||||
ap.add_argument("--selftest", action="store_true")
|
||||
ap.add_argument("--atom", type=int, action="append", default=[],
|
||||
help="atom index to resolve through every mapper")
|
||||
ap.add_argument("--name", action="append", default=[],
|
||||
help="atom name to resolve through every mapper")
|
||||
args = ap.parse_args()
|
||||
img = Image(args.image)
|
||||
|
||||
if args.selftest:
|
||||
return selftest(img)
|
||||
|
||||
atoms = list(args.atom)
|
||||
for nm in args.name:
|
||||
idx = img.atom_index(nm)
|
||||
if idx is None:
|
||||
print(f" atom {nm!r} not found in the table")
|
||||
return 2
|
||||
atoms.append(idx)
|
||||
if not atoms:
|
||||
ap.error("give --atom/--name, or --selftest")
|
||||
|
||||
m = Mapper(img)
|
||||
mappers = find_mappers(img)
|
||||
print(f" {len(mappers)} mapper function(s) found\n")
|
||||
for a in atoms:
|
||||
print(f" === atom {a} ({img.atom(a)!r}) ===")
|
||||
rows, unsup = [], 0
|
||||
for start in sorted(mappers):
|
||||
try:
|
||||
fid = m.run(start, a)
|
||||
except Unsupported:
|
||||
unsup += 1
|
||||
continue
|
||||
if fid:
|
||||
rows.append((start, fid))
|
||||
for start, fid in rows:
|
||||
print(f" mapper 0x{start:x} -> field id {fid} (0x{fid:x})")
|
||||
print(f" {len(rows)} mapper(s) accept it; {unsup} not modelled\n")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Executable
+190
@@ -0,0 +1,190 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Canonical FIFA 17 kit map, joined from the extracted client tables.
|
||||
|
||||
Authority for every kit question that a table can answer, so nobody has to
|
||||
reverse a binary for a fact that is sitting in a JSON row. Reads only:
|
||||
|
||||
fifa17-recon/data/tables/fcc_kitcards.json the FUT KIT CARD definitions
|
||||
fifa17-recon/data/tables/teamkits.json the ENGINE kit rows
|
||||
|
||||
Everything printed is TABLE_PROVEN unless the line says otherwise: it is a
|
||||
direct count over the full table, not a sample.
|
||||
|
||||
Usage:
|
||||
python3 audit_fifa17_kits.py human report
|
||||
python3 audit_fifa17_kits.py --json machine-readable, for tests/tools
|
||||
python3 audit_fifa17_kits.py --team 21 drill into one team
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
import json
|
||||
import os
|
||||
import sys
|
||||
from collections import Counter, defaultdict
|
||||
|
||||
TABLES = os.path.join(os.path.dirname(os.path.abspath(__file__)), "..", "data", "tables")
|
||||
|
||||
# TABLE_PROVEN, established by this script's own discriminating test (see
|
||||
# category_type_evidence): a kit CARD's `category` selects the engine kit ROW's
|
||||
# `teamkittypetechid` at the same (team, year).
|
||||
CATEGORY_TO_KIT_TYPE = {2: 0, 3: 1, 5: 2}
|
||||
KIT_TYPE_NAME = {0: "HOME", 1: "AWAY", 2: "THIRD", 3: "FOURTH", 5: "GK", 6: "SPECIAL6", 7: "SPECIAL7"}
|
||||
|
||||
|
||||
def load(name):
|
||||
with open(os.path.join(TABLES, name), "r", encoding="utf-8") as fh:
|
||||
data = json.load(fh)
|
||||
return data if isinstance(data, list) else data.get("rows", data)
|
||||
|
||||
|
||||
def band(carddbid: int) -> int:
|
||||
"""The 6_300_000 / 6_400_000 id band."""
|
||||
return (carddbid // 100_000) * 100_000
|
||||
|
||||
|
||||
def category_type_evidence(cards, kits):
|
||||
"""The DISCRIMINATING test behind CATEGORY_TO_KIT_TYPE.
|
||||
|
||||
Asserting "category 3 means away" because away kits usually exist is not
|
||||
evidence -- types 0/1/2 are present for most teams, so the claim is true by
|
||||
construction. What discriminates is the teams that LACK a type: if category 3
|
||||
really means type 1, then no category-3 card may exist for a (team, year)
|
||||
that has no type-1 row. Same for category 5 and type 2.
|
||||
"""
|
||||
kits_by = defaultdict(set)
|
||||
for r in kits:
|
||||
kits_by[(r["teamtechid"], r["year"])].add(r["teamkittypetechid"])
|
||||
cards_by = defaultdict(list)
|
||||
for r in cards:
|
||||
cards_by[(r["teamid"], r["year"])].append(r)
|
||||
|
||||
out = {}
|
||||
for cat, want in CATEGORY_TO_KIT_TYPE.items():
|
||||
# keys that HAVE teamkits rows but not the wanted type
|
||||
lacking = [k for k, t in kits_by.items() if t and want not in t]
|
||||
counterexamples = [
|
||||
r["carddbid"] for k in lacking for r in cards_by.get(k, []) if r["category"] == cat
|
||||
]
|
||||
out[cat] = {
|
||||
"kit_type": want,
|
||||
"name": KIT_TYPE_NAME[want],
|
||||
"keys_lacking_type": len(lacking),
|
||||
"counterexamples": counterexamples,
|
||||
}
|
||||
return out
|
||||
|
||||
|
||||
def audit():
|
||||
cards = load("fcc_kitcards.json")
|
||||
kits = load("teamkits.json")
|
||||
|
||||
kits_by = defaultdict(list)
|
||||
for r in kits:
|
||||
kits_by[(r["teamtechid"], r["year"])].append(r)
|
||||
|
||||
rows = []
|
||||
for c in cards:
|
||||
key = (c["teamid"], c["year"])
|
||||
want = CATEGORY_TO_KIT_TYPE.get(c["category"])
|
||||
match = next((k for k in kits_by.get(key, []) if k["teamkittypetechid"] == want), None)
|
||||
rows.append(
|
||||
{
|
||||
"carddbid": c["carddbid"],
|
||||
"band": band(c["carddbid"]),
|
||||
"teamid": c["teamid"],
|
||||
"year": c["year"],
|
||||
"category": c["category"],
|
||||
"kit_type": want,
|
||||
"kit_type_name": KIT_TYPE_NAME.get(want, "?"),
|
||||
"assetid": c["assetid"],
|
||||
"cardassetid": c["cardassetid"],
|
||||
"value": c["value"],
|
||||
"weightrare": c["weightrare"],
|
||||
# These are BYTE OFFSETS into the table's string blob, not ids.
|
||||
# The blob is not among the extracted tables, so a kit's own
|
||||
# name string is NOT recoverable from data/tables alone.
|
||||
"name_offset": c["name"],
|
||||
"header_offset": c["header"],
|
||||
"description_offset": c["description"],
|
||||
"teamkitid": match["teamkitid"] if match else None,
|
||||
"teamkit_islocked": match["islocked"] if match else None,
|
||||
"teamkit_embargoed": match["isembargoed"] if match else None,
|
||||
}
|
||||
)
|
||||
|
||||
dupes = [k for k, n in Counter((r["teamid"], r["year"], r["category"]) for r in rows).items() if n > 1]
|
||||
|
||||
return {
|
||||
"counts": {"fcc_kitcards": len(cards), "teamkits": len(kits)},
|
||||
"bands": dict(sorted(Counter(r["band"] for r in rows).items())),
|
||||
"band_x_assetid": {f"{b}/{a}": n for (b, a), n in
|
||||
sorted(Counter((r["band"], r["assetid"]) for r in rows).items())},
|
||||
"band_x_category": {f"{b}/{c}": n for (b, c), n in
|
||||
sorted(Counter((r["band"], r["category"]) for r in rows).items())},
|
||||
"category_counts": dict(sorted(Counter(r["category"] for r in rows).items())),
|
||||
"cardassetid": sorted({r["cardassetid"] for r in rows}),
|
||||
"category_type_evidence": category_type_evidence(cards, kits),
|
||||
"unmatched": [r["carddbid"] for r in rows if r["teamkitid"] is None],
|
||||
"duplicate_team_year_category": dupes,
|
||||
"teamkits_islocked": dict(Counter(r["islocked"] for r in kits)),
|
||||
"teamkits_embargoed": dict(Counter(r["isembargoed"] for r in kits)),
|
||||
"teamkits_types": dict(sorted(Counter(r["teamkittypetechid"] for r in kits).items())),
|
||||
"rows": rows,
|
||||
}
|
||||
|
||||
|
||||
def main():
|
||||
ap = argparse.ArgumentParser()
|
||||
ap.add_argument("--json", action="store_true")
|
||||
ap.add_argument("--team", type=int)
|
||||
args = ap.parse_args()
|
||||
|
||||
a = audit()
|
||||
if args.json:
|
||||
json.dump(a, sys.stdout, indent=2)
|
||||
return
|
||||
|
||||
print("FIFA 17 kit map — TABLE_PROVEN from the extracted client tables")
|
||||
print(f" fcc_kitcards rows : {a['counts']['fcc_kitcards']}")
|
||||
print(f" teamkits rows : {a['counts']['teamkits']}")
|
||||
|
||||
print("\nid bands")
|
||||
for b, n in a["bands"].items():
|
||||
print(f" {b}: {n}")
|
||||
print("\nband/assetid (assetid is fully determined by band)")
|
||||
for k, n in a["band_x_assetid"].items():
|
||||
print(f" {k}: {n}")
|
||||
print("\nband/category")
|
||||
for k, n in a["band_x_category"].items():
|
||||
print(f" {k}: {n}")
|
||||
print(f"\ncardassetid values: {a['cardassetid']} (the FUT card frame, not the kit art)")
|
||||
|
||||
print("\ncategory -> engine kit type, with the discriminating test")
|
||||
for cat, ev in a["category_type_evidence"].items():
|
||||
verdict = "HOLDS" if not ev["counterexamples"] else f"FAILS ({len(ev['counterexamples'])})"
|
||||
print(f" category {cat} -> type {ev['kit_type']} {ev['name']:6s} "
|
||||
f"| {ev['keys_lacking_type']:4d} (team,year) keys lack that type, "
|
||||
f"{len(ev['counterexamples'])} counterexample(s) -> {verdict}")
|
||||
|
||||
print("\nengine kit types present in teamkits")
|
||||
for t, n in a["teamkits_types"].items():
|
||||
print(f" type {t} {KIT_TYPE_NAME.get(t,'?'):8s}: {n}")
|
||||
|
||||
print(f"\nteamkits islocked : {a['teamkits_islocked']} <- every row, so NOT the selector lock")
|
||||
print(f"teamkits embargoed : {a['teamkits_embargoed']}")
|
||||
|
||||
print(f"\nanomalies")
|
||||
print(f" cards with no matching teamkits row : {len(a['unmatched'])}")
|
||||
print(f" duplicate (team,year,category) : {len(a['duplicate_team_year_category'])}")
|
||||
|
||||
if args.team is not None:
|
||||
print(f"\n=== team {args.team} ===")
|
||||
print(f" {'carddbid':10s} {'cat':4s} {'type':7s} {'year':6s} {'assetid':8s} {'teamkitid':10s} locked")
|
||||
for r in sorted((r for r in a["rows"] if r["teamid"] == args.team), key=lambda r: r["carddbid"]):
|
||||
print(f" {r['carddbid']:<10} {r['category']:<4} {r['kit_type_name']:<7} {r['year']:<6} "
|
||||
f"{r['assetid']:<8} {str(r['teamkitid']):<10} {r['teamkit_islocked']}")
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
main()
|
||||
@@ -147,14 +147,13 @@ def refresh_account_identity():
|
||||
|
||||
# ================================================================== config
|
||||
#
|
||||
# Client/server split support (OpenFUT dev-container): two env vars, both
|
||||
# defaulting to loopback so the original all-on-localhost flow is byte-identical.
|
||||
# OPENFUT_BIND — the address the listeners bind (0.0.0.0 in a container).
|
||||
# OPENFUT_ADVERTISE — the address this server hands back to the client for the
|
||||
# NEXT hop (Blaze host, roster/UTAS/telemetry/QoS URLs). On
|
||||
# 105-local this is 127.0.0.1; on the 120 server it is the
|
||||
# server's LAN IP so the game dials 120 directly after the
|
||||
# first (hook/DNAT-redirected) contact.
|
||||
# Client/server split support (OpenFUT dev-container): bind and advertise default
|
||||
# to loopback so the original all-on-localhost flow is byte-identical.
|
||||
# OPENFUT_BIND — address the listeners bind (0.0.0.0 in a container).
|
||||
# OPENFUT_ADVERTISE — address handed back for Blaze, UTAS, telemetry, QoS,
|
||||
# and (unless overridden) the roster service.
|
||||
# OPENFUT_ROSTER_HOST — optional roster host:port advertised in HTTPS URLs.
|
||||
# Use a certificate dNSName and resolve it on the client.
|
||||
import os as _os_cfg
|
||||
_ADVERTISE = _os_cfg.environ.get("OPENFUT_ADVERTISE", "127.0.0.1")
|
||||
_BIND = _os_cfg.environ.get("OPENFUT_BIND", "127.0.0.1")
|
||||
@@ -563,9 +562,11 @@ OSDK_TICKER = []
|
||||
# never gets advance/back -> the silent FUT loading-screen hang. The store is the
|
||||
# MERGED '_all' section (getSection @0x14719e050), so any fetched CFID works; this
|
||||
# branch does NOT wrap the value ("https://%s" is only the ini path) -> ABSOLUTE url.
|
||||
# Serve HTTPS (EA's production value is https; the DirtySDK download mgr may reject
|
||||
# http). Our ProtoSSL cert-verify is patched (autopatch), so a self-signed cert is OK.
|
||||
ROSTER_HOST = "%s:8081" % _ADVERTISE
|
||||
# Serve HTTPS (EA's production value is https; the DirtySDK download manager may
|
||||
# reject http). FIFA17's roster verifier accepts dNSName SANs but ignores
|
||||
# iPAddress SANs, so an IP-literal URL fails with certificate_unknown. A remote
|
||||
# deployment can advertise a certificate DNS name without changing other hosts.
|
||||
ROSTER_HOST = os.environ.get("OPENFUT_ROSTER_HOST") or "%s:8081" % _ADVERTISE
|
||||
POW_CONTENT_HOST = os.environ.get("POW_CONTENT_HOST", "127.0.0.1:8080")
|
||||
OSDK_ROSTER = [
|
||||
("ROSTERUPDATE_URL", "https://%s/fifa17/fut/rosterupdate.xml" % ROSTER_HOST),
|
||||
|
||||
Executable
+77
@@ -0,0 +1,77 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Recover the kit caption/localisation vocabulary from the UNPACKED CardsDLL.
|
||||
|
||||
Why CardsDLL and not FIFA17.exe: CardsDLL is not packed, so a MISS here is
|
||||
meaningful. FIFA17.exe is Denuvo-packed and only partially readable -- a hit
|
||||
there is useful, a miss proves nothing. Every run therefore prints a positive
|
||||
control first; if the control fails, the run is void and no negative may be
|
||||
quoted from it.
|
||||
|
||||
Usage: python3 cardsdll_kit_strings.py [path-to-CardsDLL]
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import os
|
||||
import re
|
||||
import sys
|
||||
|
||||
DEFAULT = os.path.expanduser(
|
||||
"~/.cache/openfut-investigation/bin/CardsDLL_Win64_retail.dll"
|
||||
)
|
||||
|
||||
# Strings that MUST be present. If any is missing the search is broken.
|
||||
CONTROLS = [b"activeHomeKit", b"cardsubtypeid", b"resourceId", b"activeAwayKit"]
|
||||
|
||||
# The kit caption vocabulary this project has referred to, plus neighbours worth
|
||||
# knowing about either way.
|
||||
PROBES = [
|
||||
b"FUT_UC_KITS", b"TeamName_Abbr15_", b"TeamName_Abbr15", b"TeamName_",
|
||||
b"FUT_UC_", b"StadiumName_", b"Badge", b"Stadium",
|
||||
b"activeBadge", b"activeBall", b"activeStadium",
|
||||
b"kit", b"Kit", b"KIT",
|
||||
b"home", b"Home", b"HOME", b"away", b"Away", b"AWAY",
|
||||
b"locked", b"Locked", b"LOCKED", b"unlock",
|
||||
b"category", b"year", b"teamid", b"teamId",
|
||||
b"DataProvider", b"itemData", b"itemType", b"itemState",
|
||||
]
|
||||
|
||||
|
||||
def ascii_strings(data, minlen=4):
|
||||
for m in re.finditer(rb"[ -~]{%d,}" % minlen, data):
|
||||
yield m.start(), m.group()
|
||||
|
||||
|
||||
def main():
|
||||
path = sys.argv[1] if len(sys.argv) > 1 else DEFAULT
|
||||
data = open(path, "rb").read()
|
||||
print(f"{os.path.basename(path)} {len(data)} bytes")
|
||||
|
||||
print("\n-- positive control (a miss voids every negative below) --")
|
||||
ok = True
|
||||
for c in CONTROLS:
|
||||
n = data.count(c)
|
||||
print(f" {c.decode():16s} {n}")
|
||||
if n == 0:
|
||||
ok = False
|
||||
if not ok:
|
||||
print(" CONTROL FAILED — do not quote negatives from this run.")
|
||||
return 1
|
||||
|
||||
print("\n-- probe counts --")
|
||||
for p in PROBES:
|
||||
print(f" {p.decode():18s} {data.count(p)}")
|
||||
|
||||
# Whole-string table: every standalone string containing kit-ish substrings.
|
||||
print("\n-- standalone strings matching kit/team/caption vocabulary --")
|
||||
pat = re.compile(rb"(?i)(kit|teamname|abbr|stadiumname|fut_uc|locked|unlock)")
|
||||
seen = set()
|
||||
for off, s in ascii_strings(data, 5):
|
||||
if pat.search(s) and s not in seen:
|
||||
seen.add(s)
|
||||
print(f" @{off:#08x} {s.decode('latin1')[:110]}")
|
||||
print(f" ({len(seen)} distinct)")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
+202
@@ -0,0 +1,202 @@
|
||||
#!/usr/bin/env python3
|
||||
# -*- coding: utf-8 -*-
|
||||
"""Prove, from the live client, which cardtypes CardsDLL can NAME -- and that
|
||||
cardtype 9 (ball / league logo / fcc_misccards) is not one of them.
|
||||
|
||||
READ-ONLY: /proc/PID/mem opened 'rb'. No write path in this file.
|
||||
|
||||
WHY
|
||||
---
|
||||
Serving an owned ball or league logo was blocked on one question: where does a
|
||||
cardtype-9 item's caption come from? Three independent reads here say: nowhere.
|
||||
|
||||
MEASURED 2026-08-21, pid 6580, CardsDLL live base 0x6ffffc0f0000
|
||||
(module-relative offsets below are stable; live addresses are not).
|
||||
|
||||
1. THE CLUB-ITEM CAPTION RESOLVER IS A VTABLE SLOT, NOT AN EXPORT.
|
||||
An earlier note recorded FUN_180119bd0 as "zero refs in CardsDLL -> almost
|
||||
certainly an export, its caller is in FIFA17.exe". That is WRONG and this
|
||||
tool corrects it. Its address occurs exactly ONCE in the entire process, at
|
||||
image 0x18021c738, inside CardsDLL's own .rdata -- a vtable entry. Nothing in
|
||||
FIFA17.exe references it.
|
||||
|
||||
Walking backwards over "qwords pointing into .text" overshoots the vtable
|
||||
boundary (it runs 826 slots through several adjacent vtables). The reliable
|
||||
discriminator is that a vtable's START is referenced by its constructor via a
|
||||
RIP-relative LEA while interior slots never are:
|
||||
|
||||
vtable base image 0x18021c2a0 (ctor LEAs at 0x18010ce10, 0x18011111b)
|
||||
FUN_180119bd0 slot +0x498, index 147
|
||||
|
||||
which independently reproduces the previously recorded "manager vtable slot
|
||||
+0x498". There are 7 distinct `call [reg+0x498]` sites.
|
||||
|
||||
2. THE CAPTION CALL IS GATED ON cardtype == 7, AND THE ELSE IS TROPHIES.
|
||||
At 0x1800f6f04:
|
||||
|
||||
cmp DWORD PTR [rax+0x4c], 0x7 ; cardtype
|
||||
jne 0x1800f6f82
|
||||
...
|
||||
mov r9d, [rdx+0x94]
|
||||
mov r8d, [rdx+0x50] ; cardsubtypeid
|
||||
mov ecx, [rdx+0x20] ; assetid
|
||||
call QWORD PTR [r10+0x498] ; FUN_180119bd0
|
||||
|
||||
The jne path formats [rdi+0x8] into 'AWARD_LABEL_%i' (0x1801fd5a0) and
|
||||
localises it -- that is the TROPHY path (subtypes 0x91..0x96), not a fallback
|
||||
that would name a ball.
|
||||
|
||||
3. NO CARDTYPE-9 HANDLING EXISTS, BY TWO INDEPENDENT MEASURES.
|
||||
a) Census of every `cmp [reg+0x4c], imm8` in .text:
|
||||
cardtype 0 : 2 sites
|
||||
cardtype 1 : 14 sites
|
||||
cardtype 6 : 1 site
|
||||
cardtype 7 : 6 sites
|
||||
cardtype 9 : 0 sites
|
||||
b) The merge switch's jump table at rva 0x141eb4, indexed by cardtype-1,
|
||||
10 entries:
|
||||
idx 0..4 -> cardtypes 1..5 distinct DB-merge arms
|
||||
idx 5..8 -> cardtypes 6..9 ALL to the shared tail 0x180141e8a
|
||||
idx 9 -> cardtype 10 distinct arm (gkcoach)
|
||||
The shared tail does no DB query and writes no name: it only derives the
|
||||
discard level from the rating.
|
||||
|
||||
A cmp census alone would miss a jump-table switch, and a jump table alone
|
||||
would miss an explicit compare. Both say the same thing.
|
||||
|
||||
CONSEQUENCE
|
||||
-----------
|
||||
A cardtype-9 item cannot receive a client-resolved caption: it has no merge arm
|
||||
to fill a name and it can never reach the cardtype-7 resolver. Withholding ball
|
||||
and league logo from the projection is therefore an evidence-backed limit of the
|
||||
client, not caution -- and no server-side change can lift it.
|
||||
|
||||
BONUS, and it validates the discard work: the shared tail at 0x180141e8a IS the
|
||||
discard level ladder, live --
|
||||
movzx eax,[rdi+0xb4] ; cmp al,0x4b ; -> 3
|
||||
cmp al,0x41 ; sbb eax,eax ; add eax,2 ; -> 2 or 1
|
||||
mov [rdi+0x54], eax
|
||||
which is `discard::discard_level` instruction for instruction.
|
||||
|
||||
Usage:
|
||||
python3 cardtype_dispatch_probe.py
|
||||
"""
|
||||
import collections
|
||||
import struct
|
||||
import sys
|
||||
|
||||
import watch_club_model as W
|
||||
|
||||
TEXT_LO, TEXT_HI = 0x180001000, 0x1801E5000
|
||||
RDATA_LO, RDATA_HI = 0x1801E5000, 0x18028A000
|
||||
CAPTION_FN = 0x180119BD0
|
||||
JUMP_TABLE = 0x180141EB4
|
||||
SHARED_TAIL = 0x180141E8A
|
||||
REGS = {0x78: "rax", 0x79: "rcx", 0x7A: "rdx", 0x7B: "rbx",
|
||||
0x7D: "rbp", 0x7E: "rsi", 0x7F: "rdi"}
|
||||
|
||||
|
||||
def main():
|
||||
pid = W.find_pid()
|
||||
if pid is None:
|
||||
print("FIFA17.exe is not running.")
|
||||
return 1
|
||||
dll = W.dll_base(pid)
|
||||
if dll is None:
|
||||
print("pid %d is up but %s is not mapped yet." % (pid, W.DLL))
|
||||
return 1
|
||||
mem = W.Mem(pid)
|
||||
live = lambda i: dll + (i - W.IMG_BASE)
|
||||
print("pid=%d CardsDLL live base %#x" % (pid, dll))
|
||||
|
||||
text, bad = mem.read_pages(live(TEXT_LO), TEXT_HI - TEXT_LO)
|
||||
text = bytes(text)
|
||||
print("read %#x bytes .text (%d bad pages)" % (len(text), len(bad)))
|
||||
|
||||
# --- 1. locate the caption fn's single reference, and its vtable base ----
|
||||
target = live(CAPTION_FN)
|
||||
rdata, _ = mem.read_pages(live(RDATA_LO), RDATA_HI - RDATA_LO)
|
||||
rdata = bytes(rdata)
|
||||
slots = []
|
||||
needle = struct.pack("<Q", target)
|
||||
i = rdata.find(needle)
|
||||
while i != -1:
|
||||
slots.append(RDATA_LO + i)
|
||||
i = rdata.find(needle, i + 1)
|
||||
print("\n[1] FUN_%x referenced from .rdata at: %s"
|
||||
% (CAPTION_FN, [hex(s) for s in slots]) or "nowhere")
|
||||
|
||||
lea_t = set()
|
||||
for i in range(len(text) - 7):
|
||||
if text[i] in (0x48, 0x4C) and text[i + 1] == 0x8D and text[i + 2] in (
|
||||
0x05, 0x0D, 0x15, 0x1D, 0x25, 0x2D, 0x35, 0x3D):
|
||||
tgt = TEXT_LO + i + 7 + struct.unpack_from("<i", text, i + 3)[0]
|
||||
if RDATA_LO <= tgt < RDATA_HI:
|
||||
lea_t.add(tgt)
|
||||
for slot in slots:
|
||||
base = max((t for t in lea_t if t <= slot), default=None)
|
||||
if base is not None:
|
||||
print(" vtable base %#x -> slot +%#x (index %d)"
|
||||
% (base, slot - base, (slot - base) // 8))
|
||||
|
||||
# --- 2. cardtype compare census -----------------------------------------
|
||||
hits = collections.defaultdict(list)
|
||||
for i in range(len(text) - 4):
|
||||
if text[i] == 0x83 and text[i + 1] in REGS and text[i + 2] == 0x4C:
|
||||
hits[text[i + 3]].append(TEXT_LO + i)
|
||||
print("\n[2] cardtype tests `cmp [reg+0x4c], imm`:")
|
||||
for ct in sorted(hits):
|
||||
print(" cardtype %2d : %3d site(s) e.g. %s"
|
||||
% (ct, len(hits[ct]), ", ".join("%#x" % v for v in hits[ct][:4])))
|
||||
ok_control = 7 in hits and 1 in hits
|
||||
print(" CONTROL (cardtypes 1 and 7 must both appear): %s"
|
||||
% ("OK" if ok_control else "WRONG REGION -- results are meaningless"))
|
||||
print(" cardtype 9 sites: %d" % len(hits.get(9, [])))
|
||||
|
||||
# --- 3. merge jump table -------------------------------------------------
|
||||
jt, _ = mem.read_pages(live(JUMP_TABLE), 0x40)
|
||||
jt = bytes(jt)
|
||||
print("\n[3] merge jump table at %#x (index = cardtype - 1):" % JUMP_TABLE)
|
||||
tail_types = []
|
||||
for n in range(16):
|
||||
rva = struct.unpack_from("<I", jt, n * 4)[0]
|
||||
if not (0x1000 <= rva < 0x1E5000):
|
||||
break
|
||||
va = W.IMG_BASE + rva
|
||||
ct = n + 1
|
||||
mark = " <- SHARED TAIL (no DB query, no name)" if va == SHARED_TAIL else ""
|
||||
print(" cardtype %2d -> %#x%s" % (ct, va, mark))
|
||||
if va == SHARED_TAIL:
|
||||
tail_types.append(ct)
|
||||
|
||||
# --- 4. cardsubtypeid census -------------------------------------------
|
||||
# The club-item CAPTION is chosen by subtype (+0x50), not cardtype, so the
|
||||
# cardtype census alone does not settle whether a ball or logo is nameable.
|
||||
sub = collections.defaultdict(list)
|
||||
for i in range(len(text) - 8):
|
||||
if text[i] == 0x83 and text[i + 1] in REGS and text[i + 2] == 0x50:
|
||||
sub[text[i + 3]].append(TEXT_LO + i)
|
||||
elif text[i] == 0x81 and text[i + 1] in REGS and text[i + 2] == 0x50:
|
||||
sub[struct.unpack_from("<I", text, i + 3)[0]].append(TEXT_LO + i)
|
||||
print("\n[4] cardsubtypeid tests `cmp [reg+0x50], imm`:")
|
||||
for st in sorted(k for k in sub if k <= 400):
|
||||
print(" subtype %3d : %2d site(s) e.g. %s"
|
||||
% (st, len(sub[st]), ", ".join("%#x" % v for v in sub[st][:4])))
|
||||
print(" CONTROL (kit 9 / stadium 10 / badge 11 must appear): %s"
|
||||
% ("OK" if all(s in sub for s in (9, 10, 11)) else "WRONG REGION"))
|
||||
print(" ball(30)=%d leaguelogo(31)=%d misc(231/232/233/236)=%d"
|
||||
% (len(sub.get(30, [])), len(sub.get(31, [])),
|
||||
sum(len(sub.get(s, [])) for s in (231, 232, 233, 236))))
|
||||
print(" NOTE: the misc sites are all one boolean predicate near"
|
||||
" 0x1801a72da that returns FALSE for them -- an exclusion, not a"
|
||||
" caption. Its identity is NOT established.")
|
||||
|
||||
print("\nVERDICT: cardtypes with no merge arm: %s" % tail_types)
|
||||
print(" cardtype 9 named by CardsDLL: %s"
|
||||
% ("NO -- no merge arm and no compare site" if 9 in tail_types
|
||||
and not hits.get(9) else "reconsider"))
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Executable
+55
@@ -0,0 +1,55 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Classify call sites of the 130000/130001 provider stubs.
|
||||
|
||||
A call whose result is COMPARED implements a predicate ("is this the FUT custom
|
||||
club?"). Only a call whose result is STORED can assign a team id. This turns an
|
||||
unreadable 81-site list into the handful that could actually introduce 130000
|
||||
into a struct.
|
||||
|
||||
classify_calls.py <asmfile> <target_va_hex> [more_targets...]
|
||||
"""
|
||||
import re
|
||||
import sys
|
||||
|
||||
asm = sys.argv[1]
|
||||
targets = [t.lower().lstrip("0x") for t in sys.argv[2:]]
|
||||
|
||||
lines = []
|
||||
for l in open(asm, errors="replace"):
|
||||
m = re.match(r"\s*([0-9a-f]+):\s+((?:[0-9a-f]{2} )+)\s*(.*)", l)
|
||||
if m:
|
||||
lines.append((int(m.group(1), 16), m.group(3).strip()))
|
||||
idx = {a: i for i, (a, _t) in enumerate(lines)}
|
||||
|
||||
STORE = re.compile(r"^mov\s+(?:DWORD PTR |QWORD PTR )?\[[^\]]+\],(eax|rax)\b")
|
||||
CMP = re.compile(r"^(cmp|sub|test)\b.*\b(eax|rax)\b")
|
||||
MOVREG = re.compile(r"^mov\s+(e[a-z]{2}|r\d+d|r[a-z]{2}),(eax|rax)\b")
|
||||
|
||||
for tgt in targets:
|
||||
print(f"\n ===== callers of 0x{tgt} =====")
|
||||
stores, cmps, other = [], [], []
|
||||
for i, (a, txt) in enumerate(lines):
|
||||
if not txt.startswith("call") or tgt not in txt:
|
||||
continue
|
||||
# look at the next few instructions for the fate of eax
|
||||
window = [lines[j][1] for j in range(i + 1, min(i + 7, len(lines)))]
|
||||
verdict, detail = "other", window[0] if window else ""
|
||||
for w in window:
|
||||
if STORE.match(w):
|
||||
verdict, detail = "STORE", w
|
||||
break
|
||||
if CMP.match(w):
|
||||
verdict, detail = "compare", w
|
||||
break
|
||||
if MOVREG.match(w):
|
||||
verdict, detail = "movreg", w
|
||||
break
|
||||
rec = (a, detail)
|
||||
(stores if verdict == "STORE" else cmps if verdict == "compare" else other).append(rec)
|
||||
print(f" STORE (can assign) : {len(stores)}")
|
||||
for a, d in stores:
|
||||
print(f" 0x{a:x} {d}")
|
||||
print(f" compare (predicate) : {len(cmps)}")
|
||||
print(f" other/moved to reg : {len(other)}")
|
||||
for a, d in other[:14]:
|
||||
print(f" 0x{a:x} {d}")
|
||||
+111
@@ -0,0 +1,111 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Read-only probe v3: discriminate "kits never ingested" from "ingested then freed".
|
||||
|
||||
Staff was refetched by the client at 18:40:38, four minutes before the scan, and
|
||||
players are resident. If staff/badge/stadium records are resident but the two
|
||||
kits are not, the kits are being dropped specifically.
|
||||
"""
|
||||
import re
|
||||
import struct
|
||||
import subprocess
|
||||
import sys
|
||||
|
||||
NEEDLES = {
|
||||
"PLAYER resourceId 83906881 (control, resident)": 83906881,
|
||||
"STAFF resourceId 9000081 (headcoach-ish)": 9000081,
|
||||
"STAFF resourceId 3000083 (x2)": 3000083,
|
||||
"STAFF resourceId 1000509": 1000509,
|
||||
"STAFF instance 100004870": 100004870,
|
||||
"BADGE resourceId 6000005": 6000005,
|
||||
"BADGE instance 100004875": 100004875,
|
||||
"STADIUM resourceId 6200000": 6200000,
|
||||
"STADIUM instance 100004876": 100004876,
|
||||
"KIT resourceId 6300006 (home)": 6300006,
|
||||
"KIT resourceId 6400003 (away)": 6400003,
|
||||
"KIT instance 100004874 (home)": 100004874,
|
||||
"KIT instance 100004873 (away)": 100004873,
|
||||
"KIT cardassetid 35": 35,
|
||||
}
|
||||
|
||||
|
||||
def find_pid():
|
||||
out = subprocess.run(["pgrep", "-f", "FIFA17.exe"], capture_output=True, text=True).stdout.split()
|
||||
for p in out:
|
||||
try:
|
||||
with open(f"/proc/{p}/maps") as fh:
|
||||
if "CardsDLL" in fh.read():
|
||||
return int(p)
|
||||
except OSError:
|
||||
continue
|
||||
return int(out[0]) if out else None
|
||||
|
||||
|
||||
def main():
|
||||
pid = find_pid()
|
||||
if not pid:
|
||||
sys.exit("FIFA17.exe not running")
|
||||
print(f"pid={pid}")
|
||||
|
||||
regs = []
|
||||
with open(f"/proc/{pid}/maps") as fh:
|
||||
for line in fh:
|
||||
m = re.match(r"([0-9a-f]+)-([0-9a-f]+) (\S{4}) \S+ \S+ \S+\s*(.*)", line)
|
||||
if not m:
|
||||
continue
|
||||
lo, hi, perms, path = int(m.group(1), 16), int(m.group(2), 16), m.group(3), m.group(4)
|
||||
if "r" in perms and not path.startswith("/dev/") and (hi - lo) <= (512 << 20):
|
||||
regs.append((lo, hi))
|
||||
|
||||
hits = {k: [] for k in NEEDLES}
|
||||
pats = {k: struct.pack("<I", v) for k, v in NEEDLES.items()}
|
||||
mib = 0
|
||||
|
||||
with open(f"/proc/{pid}/mem", "rb", buffering=0) as mem:
|
||||
for lo, hi in regs:
|
||||
try:
|
||||
mem.seek(lo)
|
||||
buf = mem.read(hi - lo)
|
||||
except (OSError, ValueError, OverflowError):
|
||||
continue
|
||||
if not buf:
|
||||
continue
|
||||
mib += len(buf)
|
||||
for k, needle in pats.items():
|
||||
start = 0
|
||||
while len(hits[k]) < 5000:
|
||||
i = buf.find(needle, start)
|
||||
if i < 0:
|
||||
break
|
||||
hits[k].append(lo + i)
|
||||
start = i + 4
|
||||
|
||||
print(f"read {mib/(1<<20):.0f} MiB\n" + "=" * 66)
|
||||
|
||||
def rd(base, off, size=4):
|
||||
try:
|
||||
mem.seek(base + off)
|
||||
raw = mem.read(size)
|
||||
return int.from_bytes(raw, "little") if len(raw) == size else None
|
||||
except (OSError, ValueError, OverflowError):
|
||||
return None
|
||||
|
||||
for k in NEEDLES:
|
||||
addrs = hits[k]
|
||||
# count how many look like real item records (plausible cardtype)
|
||||
recs = []
|
||||
for a in addrs[:3000]:
|
||||
base = a - 0x18
|
||||
ct = rd(base, 0x4C)
|
||||
if ct in (1, 2, 3, 4, 5, 6, 7, 9):
|
||||
recs.append((base, ct))
|
||||
flag = "" if addrs else " <-- ZERO"
|
||||
print(f" {len(addrs):6d} raw / {len(recs):4d} record-shaped {k}{flag}")
|
||||
for base, ct in recs[:3]:
|
||||
print(f" @{base:#x} cardtype={ct} subtype={rd(base,0x50)} "
|
||||
f"itemState={rd(base,0x5c)} +0x60={rd(base,0x60)} "
|
||||
f"teamid={rd(base,0x94)} cat={rd(base,0xb8)} year={rd(base,0xba,2)}")
|
||||
print("=" * 66)
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
main()
|
||||
Executable
+332
@@ -0,0 +1,332 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Trace FIFA17 Screen event 0x30 through command 0x128 and ScenarioModeStart.
|
||||
|
||||
The generated GDB program uses hardware breakpoints, only reads registers and
|
||||
client memory, logs, and continues. Seven breakpoints are rotated so no more
|
||||
than four are enabled. It never calls client functions, writes client memory,
|
||||
emits events, or drives input.
|
||||
|
||||
command_128_trace.py [pid] [--output PATH]
|
||||
command_128_trace.py --selftest
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
import os
|
||||
from pathlib import Path
|
||||
import shutil
|
||||
import sys
|
||||
|
||||
sys.path.insert(0, str(Path(__file__).resolve().parent))
|
||||
import match_advance_trace as advance
|
||||
import match_transition_trace as transition
|
||||
|
||||
MANAGER_SELECT_ACTION_SOURCE_RVA = 0x0705A620
|
||||
MANAGER_SELECT_ACTION_RESULT_RVA = 0x07CDC4A6
|
||||
SCREEN_EVENT_CHANNEL_ROUTER_RVA = 0x080CE230
|
||||
SCREEN_EVENT_DISPATCH_RVA = 0x080CF790
|
||||
SKILL_INSTRUCTIONS_SCREEN_RVA = 0x07DCA400
|
||||
GAMEPLAY_COMMAND_DISPATCH_RVA = 0x07A8F6C0
|
||||
FREE_ROAM_COMMAND_128_RVA = 0x07A92B0F
|
||||
SCENARIO_SCHEDULER_RVA = 0x07AC3A40
|
||||
SCENARIO_MANAGER_START_RVA = 0x07B1C2B0
|
||||
MODE_ZERO_SCENARIO_START_RVA = 0x07B1C190
|
||||
GAMEPLAY_GLOBAL_RVA = 0x04BFB910
|
||||
SCREEN_VTABLE_RVA = 0x03B3ECC0
|
||||
FREE_ROAM_VTABLE_RVA = 0x03AEDF58
|
||||
MODE_ZERO_CHILD_VTABLE_RVA = 0x03AE9C00
|
||||
|
||||
|
||||
def addresses(base: int) -> dict[str, int]:
|
||||
return {
|
||||
"manager_select_source": base + MANAGER_SELECT_ACTION_SOURCE_RVA,
|
||||
"manager_select_action": base + MANAGER_SELECT_ACTION_RESULT_RVA,
|
||||
"screen_event_router": base + SCREEN_EVENT_CHANNEL_ROUTER_RVA,
|
||||
"screen_event_dispatch": base + SCREEN_EVENT_DISPATCH_RVA,
|
||||
"instructions_screen": base + SKILL_INSTRUCTIONS_SCREEN_RVA,
|
||||
"command_dispatch": base + GAMEPLAY_COMMAND_DISPATCH_RVA,
|
||||
"free_roam_case": base + FREE_ROAM_COMMAND_128_RVA,
|
||||
"scheduler": base + SCENARIO_SCHEDULER_RVA,
|
||||
"manager_start": base + SCENARIO_MANAGER_START_RVA,
|
||||
"scenario_start": base + MODE_ZERO_SCENARIO_START_RVA,
|
||||
"gameplay_global": base + GAMEPLAY_GLOBAL_RVA,
|
||||
"screen_vtable": base + SCREEN_VTABLE_RVA,
|
||||
"free_roam_vtable": base + FREE_ROAM_VTABLE_RVA,
|
||||
"mode_zero_child_vtable": base + MODE_ZERO_CHILD_VTABLE_RVA,
|
||||
}
|
||||
|
||||
|
||||
def gdb_prelude(pid: int, output: str) -> str:
|
||||
if any(character in output for character in "\n\r"):
|
||||
raise ValueError("output path cannot contain a newline")
|
||||
return f"""set pagination off
|
||||
set confirm off
|
||||
set print thread-events off
|
||||
set breakpoint always-inserted off
|
||||
set logging file {output}
|
||||
set logging overwrite on
|
||||
set logging redirect off
|
||||
set logging enabled on
|
||||
handle SIGSEGV nostop noprint pass
|
||||
handle SIGILL nostop noprint pass
|
||||
handle SIGFPE nostop noprint pass
|
||||
handle SIGPIPE nostop noprint pass
|
||||
handle SIGALRM nostop noprint pass
|
||||
handle SIGUSR1 nostop noprint pass
|
||||
handle SIGUSR2 nostop noprint pass
|
||||
|
||||
attach {pid}
|
||||
"""
|
||||
|
||||
|
||||
def build_script(pid: int, fifa_base: int, output: str) -> str:
|
||||
address = addresses(fifa_base)
|
||||
return (
|
||||
gdb_prelude(pid, output)
|
||||
+ f"""define snapshot_gameplay
|
||||
set $snap_gameplay_global = *(void**)0x{address['gameplay_global']:x}
|
||||
set $snap_listener_manager = 0
|
||||
set $snap_listener_table = 0
|
||||
set $snap_listener_index = -1
|
||||
set $snap_free_roam = 0
|
||||
set $snap_free_state = -1
|
||||
set $snap_free_111 = -1
|
||||
set $snap_free_112 = -1
|
||||
set $snap_free_124 = -1
|
||||
set $snap_selected = 0
|
||||
set $snap_selected_vtable = 0
|
||||
set $snap_selected_mode = -1
|
||||
if $snap_gameplay_global != 0
|
||||
set $snap_listener_manager = *(void**)($snap_gameplay_global+0x58)
|
||||
end
|
||||
if $snap_listener_manager != 0
|
||||
set $snap_listener_table = *(void**)$snap_listener_manager
|
||||
end
|
||||
if $snap_listener_table != 0
|
||||
set $snap_free_roam = *(void**)$snap_listener_table
|
||||
set $snap_listener_index = *(int*)($snap_listener_table+0x20)
|
||||
if $snap_listener_index >= 0 && $snap_listener_index < 3
|
||||
set $snap_selected = *(void**)($snap_listener_table+$snap_listener_index*8)
|
||||
end
|
||||
end
|
||||
if $snap_free_roam != 0
|
||||
set $snap_free_state = *(int*)($snap_free_roam+0x30)
|
||||
set $snap_free_111 = *(unsigned char*)($snap_free_roam+0x111)
|
||||
set $snap_free_112 = *(unsigned char*)($snap_free_roam+0x112)
|
||||
set $snap_free_124 = *(int*)($snap_free_roam+0x124)
|
||||
end
|
||||
if $snap_selected != 0
|
||||
set $snap_selected_vtable = *(void**)$snap_selected
|
||||
set $snap_selected_mode = *(int*)($snap_selected+0x18)
|
||||
end
|
||||
end
|
||||
|
||||
set $action_count = 0
|
||||
hbreak *0x{address['manager_select_action']:x}
|
||||
commands
|
||||
silent
|
||||
set $action_count = $action_count+1
|
||||
set $provider = $rbx
|
||||
snapshot_gameplay
|
||||
if $action_count <= 128
|
||||
python import time; print("COMMAND128 epoch_ns=%d mono_ns=%d MANAGER_SELECT_ACTION" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d ordinal=%d instruction=%p caller_return=%p provider=%p provider_vtable=%p action_id=%#x free_roam=%p free_state=%d free111=%d free112=%d free124=%d selected_index=%d selected=%p selected_vtable=%p selected_mode=%d\\n", $_thread, $action_count, $pc, *(void**)($rsp+0x58), $provider, *(void**)$provider, $eax, $snap_free_roam, $snap_free_state, $snap_free_111, $snap_free_112, $snap_free_124, $snap_listener_index, $snap_selected, $snap_selected_vtable, $snap_selected_mode
|
||||
end
|
||||
if $eax == 0x30
|
||||
bt 16
|
||||
end
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['instructions_screen']:x}
|
||||
condition 2 $edx == 0x30 && *(void**)$rcx == 0x{address['screen_vtable']:x}
|
||||
commands
|
||||
silent
|
||||
set $screen = $rcx
|
||||
set $screen_owner = *(void**)($screen+0x140)
|
||||
set $screen_owner_vtable = 0
|
||||
if $screen_owner != 0
|
||||
set $screen_owner_vtable = *(void**)$screen_owner
|
||||
end
|
||||
snapshot_gameplay
|
||||
python import time; print("COMMAND128 epoch_ns=%d mono_ns=%d INSTRUCTIONS_SCREEN_EVENT_30" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d handler=%p caller_return=%p screen=%p screen_vtable=%p event=%#x payload=%p allow_advance138=%d owner140=%p owner_vtable=%p free_roam=%p free_state=%d free111=%d free112=%d free124=%d selected_index=%d selected=%p selected_vtable=%p selected_mode=%d\\n", $_thread, $pc, *(void**)$rsp, $screen, *(void**)$screen, $edx, $r8, *(int*)($screen+0x138), $screen_owner, $screen_owner_vtable, $snap_free_roam, $snap_free_state, $snap_free_111, $snap_free_112, $snap_free_124, $snap_listener_index, $snap_selected, $snap_selected_vtable, $snap_selected_mode
|
||||
bt 16
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['command_dispatch']:x}
|
||||
condition 3 $edx == 0x128
|
||||
commands
|
||||
silent
|
||||
set $command_dispatcher = $rcx
|
||||
set $command_table = *(void**)$command_dispatcher
|
||||
snapshot_gameplay
|
||||
python import time; print("COMMAND128 epoch_ns=%d mono_ns=%d GAMEPLAY_COMMAND_128" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d function=%p caller_return=%p dispatcher=%p command=%#x payload=%p arg_r9=%p table=%p free_roam=%p free_state=%d free111=%d free112=%d free124=%d selected_index=%d selected=%p selected_vtable=%p selected_mode=%d\\n", $_thread, $pc, *(void**)$rsp, $command_dispatcher, $edx, $r8, $r9, $command_table, $snap_free_roam, $snap_free_state, $snap_free_111, $snap_free_112, $snap_free_124, $snap_listener_index, $snap_selected, $snap_selected_vtable, $snap_selected_mode
|
||||
disable 1
|
||||
disable 2
|
||||
disable 3
|
||||
enable 5
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['free_roam_case']:x}
|
||||
commands
|
||||
silent
|
||||
set $owner = $rbx
|
||||
snapshot_gameplay
|
||||
python import time; print("COMMAND128 epoch_ns=%d mono_ns=%d FREE_ROAM_COMMAND_128" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d callsite=%p caller_return=%p owner=%p owner_vtable=%p command=%#x payload=%p state=%d previous=%d free111=%d free112=%d free124=%d manager=%p selected_index=%d selected=%p selected_vtable=%p selected_mode=%d\\n", $_thread, $pc, *(void**)$rsp, $owner, *(void**)$owner, $esi, $rdi, *(int*)($owner+0x30), *(int*)($owner+0x34), *(unsigned char*)($owner+0x111), *(unsigned char*)($owner+0x112), *(int*)($owner+0x124), *(void**)($owner+0x168), $snap_listener_index, $snap_selected, $snap_selected_vtable, $snap_selected_mode
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['scheduler']:x}
|
||||
disable 5
|
||||
commands
|
||||
silent
|
||||
set $owner = $rcx
|
||||
set $manager = *(void**)($owner+0x168)
|
||||
set $manager_vtable = 0
|
||||
set $manager_mode = -1
|
||||
set $child = 0
|
||||
set $child_vtable = 0
|
||||
if $manager != 0
|
||||
set $manager_vtable = *(void**)$manager
|
||||
set $manager_mode = *(int*)($manager+0x50)
|
||||
set $child = *(void**)($manager+0x8)
|
||||
end
|
||||
if $child != 0
|
||||
set $child_vtable = *(void**)$child
|
||||
end
|
||||
python import time; print("COMMAND128 epoch_ns=%d mono_ns=%d SCENARIO_SCHEDULER" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d function=%p caller_return=%p owner=%p owner_vtable=%p free124=%d command=%#x payload=%p manager=%p manager_vtable=%p manager_mode=%d child=%p child_vtable=%p\\n", $_thread, $pc, *(void**)$rsp, $owner, *(void**)$owner, *(int*)($owner+0x124), $edx, $r8, $manager, $manager_vtable, $manager_mode, $child, $child_vtable
|
||||
disable 4
|
||||
disable 5
|
||||
enable 6
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['manager_start']:x}
|
||||
disable 6
|
||||
commands
|
||||
silent
|
||||
set $manager = $rcx
|
||||
set $child = *(void**)($manager+0x8)
|
||||
python import time; print("COMMAND128 epoch_ns=%d mono_ns=%d SCENARIO_MANAGER_START" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d function=%p caller_return=%p manager=%p manager_vtable=%p requested_countdown=%d mode=%d child=%p child_vtable=%p\\n", $_thread, $pc, *(void**)$rsp, $manager, *(void**)$manager, $rdx & 0xff, *(int*)($manager+0x50), $child, $child ? *(void**)$child : 0
|
||||
disable 6
|
||||
enable 7
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['scenario_start']:x}
|
||||
disable 7
|
||||
commands
|
||||
silent
|
||||
set $ctx = $rcx
|
||||
snapshot_gameplay
|
||||
python import time; print("COMMAND128 epoch_ns=%d mono_ns=%d MODE_ZERO_SCENARIO_START" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d function=%p caller_return=%p ctx=%p ctx_vtable=%p descriptor=%p scenario_index=%d requested_countdown=%d flag40_before=%d callback_owner78=%p callback_vtable48=%p dispatcher_vtable80=%p free_roam=%p free_state=%d free111=%d free112=%d free124=%d selected_index=%d selected=%p selected_vtable=%p selected_mode=%d\\n", $_thread, $pc, *(void**)$rsp, $ctx, *(void**)$ctx, $rdx, $r8d, $r9 & 0xff, *(unsigned char*)($ctx+0x40), *(void**)($ctx+0x78), *(void**)($ctx+0x48), *(void**)($ctx+0x80), $snap_free_roam, $snap_free_state, $snap_free_111, $snap_free_112, $snap_free_124, $snap_listener_index, $snap_selected, $snap_selected_vtable, $snap_selected_mode
|
||||
disable 7
|
||||
continue
|
||||
end
|
||||
|
||||
printf "COMMAND128 ARMED pid={pid} action_id=0x{address['manager_select_action']:x} screen_handler=0x{address['instructions_screen']:x} command_dispatch=0x{address['command_dispatch']:x} free_roam=0x{address['free_roam_case']:x} scheduler=0x{address['scheduler']:x} manager=0x{address['manager_start']:x} scenario=0x{address['scenario_start']:x}\\n"
|
||||
continue
|
||||
"""
|
||||
)
|
||||
|
||||
|
||||
def effective_environment(pid: int) -> dict[str, str]:
|
||||
values: dict[str, str] = {}
|
||||
for item in Path(f"/proc/{pid}/environ").read_bytes().split(b"\0"):
|
||||
if not item.startswith(b"OPENFUT_FIFA17_"):
|
||||
continue
|
||||
key, _, value = item.decode("utf-8", errors="replace").partition("=")
|
||||
values[key] = value
|
||||
return values
|
||||
|
||||
|
||||
def selftest() -> None:
|
||||
address = addresses(0x140000000)
|
||||
script = build_script(1234, 0x140000000, "/tmp/command-128.log")
|
||||
assert address["manager_select_source"] == 0x14705A620
|
||||
assert address["manager_select_action"] == 0x147CDC4A6
|
||||
assert address["instructions_screen"] == 0x147DCA400
|
||||
assert address["command_dispatch"] == 0x147A8F6C0
|
||||
assert address["free_roam_case"] == 0x147A92B0F
|
||||
assert address["scheduler"] == 0x147AC3A40
|
||||
assert address["manager_start"] == 0x147B1C2B0
|
||||
assert address["scenario_start"] == 0x147B1C190
|
||||
assert script.count("hbreak *") == 7
|
||||
assert "set $action_count = 0" in script
|
||||
assert "MANAGER_SELECT_ACTION" in script
|
||||
assert "condition 2 $edx == 0x30" in script
|
||||
assert "condition 3 $edx == 0x128" in script
|
||||
assert "disable 4" in script
|
||||
assert "disable 5" in script and "enable 5" in script
|
||||
assert "disable 6" in script and "enable 6" in script
|
||||
assert "disable 7" in script and "enable 7" in script
|
||||
assert "set *(" not in script
|
||||
print("command_128_trace selftest: PASS")
|
||||
|
||||
|
||||
def main() -> int:
|
||||
parser = argparse.ArgumentParser(description=__doc__)
|
||||
parser.add_argument("pid", nargs="?", type=int)
|
||||
parser.add_argument("--output")
|
||||
parser.add_argument("--print-script", action="store_true")
|
||||
parser.add_argument("--selftest", action="store_true")
|
||||
args = parser.parse_args()
|
||||
if args.selftest:
|
||||
selftest()
|
||||
return 0
|
||||
|
||||
pid = args.pid or transition.find_pid()
|
||||
if not pid:
|
||||
print("FIFA17.exe not found", file=sys.stderr)
|
||||
return 2
|
||||
try:
|
||||
fifa_base, fifa_path = advance.module_mapping(pid, advance.FIFA_MODULE)
|
||||
advance.validate_file(
|
||||
fifa_path,
|
||||
advance.PINNED_FIFA_SHA256,
|
||||
advance.FIFA_MODULE,
|
||||
)
|
||||
cards_base = 0
|
||||
cards_path = "<not-loaded>"
|
||||
try:
|
||||
cards_base, cards_path = transition.cards_mapping(pid)
|
||||
except RuntimeError:
|
||||
pass
|
||||
else:
|
||||
transition.validate_cards(cards_path)
|
||||
output = args.output or f"/tmp/fifa17-command-128-{pid}.log"
|
||||
script = build_script(pid, fifa_base, output)
|
||||
environment = effective_environment(pid)
|
||||
print(
|
||||
"COMMAND128 PREPARED "
|
||||
f"pid={pid} fifa_base={fifa_base:#x} cards_base={cards_base:#x} "
|
||||
f"cards_path={cards_path} "
|
||||
f"team_compat={environment.get('OPENFUT_FIFA17_SEASON_TEAM_COMPAT', '<absent>')} "
|
||||
f"pma_fix={environment.get('OPENFUT_FIFA17_OFFLINE_SEASONS_PMA_FIX', '<absent>')}"
|
||||
)
|
||||
except (OSError, RuntimeError, ValueError) as error:
|
||||
print(error, file=sys.stderr)
|
||||
return 2
|
||||
|
||||
if args.print_script:
|
||||
print(script, end="")
|
||||
return 0
|
||||
if not shutil.which("gdb"):
|
||||
print("gdb not found", file=sys.stderr)
|
||||
return 2
|
||||
script_path = f"/tmp/fifa17-command-128-{pid}.gdb"
|
||||
Path(script_path).write_text(script, encoding="utf-8")
|
||||
os.execvp("gdb", ["gdb", "-q", "-nx", "-batch", "-x", script_path])
|
||||
return 127
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
raise SystemExit(main())
|
||||
Executable
+190
@@ -0,0 +1,190 @@
|
||||
#!/usr/bin/env python3
|
||||
# -*- coding: utf-8 -*-
|
||||
"""Read back the DISCARD (quick-sell) value the live client holds for every
|
||||
resident card, and check it against the client's own `fcc_discardcoins` table.
|
||||
|
||||
READ-ONLY. Walks the same CardsDb node tree as card_identity_probe / coach_probe
|
||||
via /proc/PID/mem; there is no write path in this file.
|
||||
|
||||
WHAT THE TWO SLOTS MEAN (FUN_18013fe00 / FUN_180141660)
|
||||
-------------------------------------------------------
|
||||
item+0x38 the `discardValue` WE sent (atom 0xd7), stored verbatim.
|
||||
item+0x3c the value the CLIENT computed for itself.
|
||||
|
||||
At 0x180141025 a `cmp dword [rbp+0x198],0` / `ja` SKIPS the whole local
|
||||
computation when +0x38 is non-zero. So:
|
||||
|
||||
* +0x38 non-zero -> the client displays OUR number and +0x3c is not filled.
|
||||
* +0x38 zero -> the client computes, and +0x3c is what the player sees.
|
||||
|
||||
The local computation is
|
||||
SELECT price FROM fcc_discardcoins WHERE cardtype==? AND level==? AND rare==?
|
||||
value = round_half_up(rating * price / 100)
|
||||
with `level` = 3 if rating >= 0x4b, 2 if >= 0x41, else 1 (item+0x54), and
|
||||
cardtype derived from cardsubtypeid by FUN_1800d8330.
|
||||
|
||||
WHY THIS TOOL EXISTS
|
||||
--------------------
|
||||
For cardtypes 2/3/4/5/10 (the five staff families) the client OVERWRITES the
|
||||
rating and rare flag we send with values from its own card database before
|
||||
computing. The server therefore cannot know the displayed price from what it
|
||||
sent -- it has to be read back. +0x3c is that read-back, and it is the ground
|
||||
truth for what the server must credit on a quick sell.
|
||||
|
||||
Usage:
|
||||
python3 discard_probe.py # table of every resident card
|
||||
python3 discard_probe.py --kind staff # only the staff families
|
||||
python3 discard_probe.py --json out.json
|
||||
"""
|
||||
import argparse
|
||||
import json
|
||||
import os
|
||||
import sys
|
||||
|
||||
import card_identity_probe as P
|
||||
import watch_club_model as W
|
||||
|
||||
TABLES = os.path.join(os.path.dirname(os.path.abspath(__file__)), "..", "data", "tables")
|
||||
|
||||
F_SERVER_DISCARD = 0x38
|
||||
F_CLIENT_DISCARD = 0x3C
|
||||
F_LEVEL = 0x54
|
||||
F_RARE = 0x58
|
||||
F_RATING = 0xB4
|
||||
|
||||
|
||||
def cardtype_for_subtype(sub):
|
||||
"""FUN_1800d8330, read out of its raw two-level jump table."""
|
||||
if 0 <= sub <= 3:
|
||||
return 1
|
||||
if sub == 4:
|
||||
return 2
|
||||
if sub == 5:
|
||||
return 3
|
||||
if sub == 6:
|
||||
return 10
|
||||
if sub == 7:
|
||||
return 5
|
||||
if sub == 8:
|
||||
return 4
|
||||
if 9 <= sub <= 11:
|
||||
return 7
|
||||
if sub in (30, 31, 236) or 145 <= sub <= 150 or 231 <= sub <= 233:
|
||||
return 9
|
||||
if 51 <= sub <= 136 or 201 <= sub <= 220 or 250 <= sub <= 273 or 300 <= sub <= 341:
|
||||
return 6
|
||||
return 0
|
||||
|
||||
|
||||
def load_prices():
|
||||
"""{(cardtype, level, rare): price} from the client's own dumped table."""
|
||||
path = os.path.join(TABLES, "fcc_discardcoins.json")
|
||||
if not os.path.isfile(path):
|
||||
return None
|
||||
doc = json.load(open(path))
|
||||
rows = doc["rows"] if isinstance(doc, dict) else doc
|
||||
return {(r["cardtype"], r["level"], r["rare"]): r["price"] for r in rows}
|
||||
|
||||
|
||||
def predict(prices, cardtype, rating, rare):
|
||||
"""The client's formula, reproduced. An absent key pays 0, never a floor."""
|
||||
if prices is None or cardtype == 0 or rating is None:
|
||||
return None
|
||||
level = 3 if rating >= 0x4B else (2 if rating >= 0x41 else 1)
|
||||
price = prices.get((cardtype, level, rare), 0)
|
||||
if price == 0:
|
||||
return 0
|
||||
return (rating * price + 50) // 100
|
||||
|
||||
|
||||
STAFF_SUBTYPES = (4, 5, 6, 7, 8)
|
||||
|
||||
|
||||
def main():
|
||||
ap = argparse.ArgumentParser()
|
||||
ap.add_argument("--kind", choices=("all", "staff", "player", "other"), default="all")
|
||||
ap.add_argument("--json", metavar="PATH")
|
||||
a = ap.parse_args()
|
||||
|
||||
prices = load_prices()
|
||||
if prices is None:
|
||||
print("WARNING: no fcc_discardcoins.json under %s -- predictions disabled\n" % TABLES)
|
||||
|
||||
pid = W.find_pid()
|
||||
if pid is None:
|
||||
print("FIFA17.exe is not running.")
|
||||
return 1
|
||||
base = W.dll_base(pid)
|
||||
if base is None:
|
||||
print("pid %d is up but %s is not mapped yet." % (pid, W.DLL))
|
||||
return 1
|
||||
mem = W.Mem(pid)
|
||||
obj = mem.q(base + (W.G_CARDSDB - W.IMG_BASE))
|
||||
if not obj:
|
||||
print("CardsDb singleton is NULL (no FUT session loaded).")
|
||||
return 1
|
||||
|
||||
ns = P.nodes(mem, obj)
|
||||
print("pid=%d CardsDb=%#x walked=%d\n" % (pid, obj, len(ns)))
|
||||
|
||||
out = []
|
||||
for n in ns:
|
||||
buf = mem.read(n + P.REC, P.REC_LEN)
|
||||
if buf is None or len(buf) < P.REC_LEN:
|
||||
continue
|
||||
sub = P.u32(buf, P.F_SUBTYPE)
|
||||
ct = P.u32(buf, P.F_CARDTYPE)
|
||||
rating = P.u8(buf, F_RATING)
|
||||
rare = P.u32(buf, F_RARE)
|
||||
rec = {
|
||||
"resourceId": P.u32(buf, P.F_RESOURCE),
|
||||
"subtype": sub,
|
||||
"cardtype": ct,
|
||||
"decoded_cardtype": cardtype_for_subtype(sub),
|
||||
"rating": rating,
|
||||
"level": P.u32(buf, F_LEVEL),
|
||||
"rare": rare,
|
||||
"server_discard": P.u32(buf, F_SERVER_DISCARD),
|
||||
"client_discard": P.u32(buf, F_CLIENT_DISCARD),
|
||||
"predicted": predict(prices, ct, rating, rare),
|
||||
}
|
||||
if a.kind == "staff" and sub not in STAFF_SUBTYPES:
|
||||
continue
|
||||
if a.kind == "player" and ct != 1:
|
||||
continue
|
||||
if a.kind == "other" and (ct == 1 or sub in STAFF_SUBTYPES):
|
||||
continue
|
||||
out.append(rec)
|
||||
|
||||
out.sort(key=lambda r: (r["cardtype"], r["subtype"], r["resourceId"]))
|
||||
print("%-10s %-4s %-4s %-4s %-4s %-4s %-9s %-9s %-9s %s"
|
||||
% ("resource", "sub", "ct", "rat", "lvl", "rar", "sent+38", "calc+3c",
|
||||
"predict", "verdict"))
|
||||
agree = disagree = notcomputed = 0
|
||||
for r in out:
|
||||
if r["server_discard"]:
|
||||
verdict = "SERVER-SHOWN (local calc skipped)"
|
||||
notcomputed += 1
|
||||
elif r["predicted"] is None:
|
||||
verdict = "?"
|
||||
elif r["client_discard"] == r["predicted"]:
|
||||
verdict = "AGREES"
|
||||
agree += 1
|
||||
else:
|
||||
verdict = "DISAGREES"
|
||||
disagree += 1
|
||||
print("%-10s %-4s %-4s %-4s %-4s %-4s %-9s %-9s %-9s %s"
|
||||
% (r["resourceId"], r["subtype"], r["cardtype"], r["rating"],
|
||||
r["level"], r["rare"], r["server_discard"], r["client_discard"],
|
||||
r["predicted"], verdict))
|
||||
|
||||
print("\nAGREES=%d DISAGREES=%d server-shown=%d total=%d"
|
||||
% (agree, disagree, notcomputed, len(out)))
|
||||
if a.json:
|
||||
json.dump(out, open(a.json, "w"), indent=2)
|
||||
print("wrote %s" % a.json)
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Executable
+86
@@ -0,0 +1,86 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Find an APT/ActionScript symbol inside the FIFA 17 Frostbite .cas archives.
|
||||
|
||||
Frosty is a GUI-only tool and its Legacy Explorer is the documented way to reach
|
||||
these assets, but the chunks holding APT ActionScript are stored plainly enough to
|
||||
grep — so a screen can be identified, and its whole symbol table recovered,
|
||||
without driving the GUI at all.
|
||||
|
||||
ALWAYS passes a control first: `KitAssignmentPopup` is a string from an
|
||||
already-exported BIG, so if it misses, the archives are packed differently than
|
||||
assumed and no negative from this tool may be quoted.
|
||||
|
||||
python3 find_apt_in_cas.py FUT_GET_MATCH_KITS_DP
|
||||
python3 find_apt_in_cas.py --dump 0x3707ecd7 fifa_installpackage_01/cas_01.cas
|
||||
"""
|
||||
import argparse
|
||||
import glob
|
||||
import os
|
||||
import re
|
||||
import sys
|
||||
|
||||
ROOT = "/mnt/games/FIFA 17"
|
||||
CONTROL = b"KitAssignmentPopup"
|
||||
|
||||
|
||||
def cas_files():
|
||||
return sorted(glob.glob(os.path.join(ROOT, "**", "*.cas"), recursive=True))
|
||||
|
||||
|
||||
def find(needle: bytes):
|
||||
control_total = 0
|
||||
hits = []
|
||||
for p in cas_files():
|
||||
d = open(p, "rb").read()
|
||||
control_total += d.count(CONTROL)
|
||||
start = 0
|
||||
while True:
|
||||
i = d.find(needle, start)
|
||||
if i < 0:
|
||||
break
|
||||
hits.append((p, i))
|
||||
start = i + 1
|
||||
return control_total, hits
|
||||
|
||||
|
||||
def dump(path, off, span=90000):
|
||||
with open(path, "rb") as f:
|
||||
f.seek(max(0, off - span // 2))
|
||||
d = f.read(span)
|
||||
seen = []
|
||||
for m in re.finditer(rb"[ -~]{4,}", d):
|
||||
t = m.group().decode("latin1")
|
||||
if t not in seen:
|
||||
seen.append(t)
|
||||
return seen
|
||||
|
||||
|
||||
def main():
|
||||
ap = argparse.ArgumentParser()
|
||||
ap.add_argument("needle", nargs="?")
|
||||
ap.add_argument("--dump", metavar="OFFSET")
|
||||
ap.add_argument("--file")
|
||||
args = ap.parse_args()
|
||||
|
||||
if args.dump:
|
||||
path = args.file if os.path.isabs(args.file or "") else os.path.join(
|
||||
ROOT, "Data/Win32/superbundlelayout", args.file or "")
|
||||
for s in dump(path, int(args.dump, 0)):
|
||||
print(s)
|
||||
return 0
|
||||
|
||||
if not args.needle:
|
||||
ap.error("needle required")
|
||||
ctl, hits = find(args.needle.encode())
|
||||
print(f"control {CONTROL.decode()}: {ctl} hit(s)")
|
||||
if ctl == 0:
|
||||
print("CONTROL FAILED — archives not greppable this way; no negative is valid.")
|
||||
return 1
|
||||
print(f"{args.needle}: {len(hits)} hit(s)")
|
||||
for p, i in hits[:20]:
|
||||
print(f" {os.path.relpath(p, ROOT)} @ {i:#x}")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
@@ -299,10 +299,16 @@ def player_item(item_id, player, special=False):
|
||||
# The cause is the guard the table work reversed. FUN_18013fe00 stores our
|
||||
# discardValue at item +0x38; at 0x180141025 a `cmp dword [rbp+0x198],0` / `ja` skips
|
||||
# the client's own local computation when that value is NON-ZERO. We seed 0, so the
|
||||
# client runs its own fcc_discardcoins lookup, that lookup returns no row for our
|
||||
# cards, the price register stays 0, and it renders 0. WHY its lookup misses is still
|
||||
# UNKNOWN and worth knowing, but it does not have to be answered to fix the display:
|
||||
# sending a non-zero value bypasses the lookup entirely and the client uses ours.
|
||||
# client runs its own fcc_discardcoins lookup and the price register stays 0.
|
||||
#
|
||||
# CORRECTED 2026-08-06: the two claims that used to sit here -- "that lookup
|
||||
# returns no row for our cards" and "WHY its lookup misses is still UNKNOWN" --
|
||||
# are both FALSE. The lookup does not miss; real rows exist for both rare values
|
||||
# on (cardtype 6, level, rare). The tile reads a DIFFERENT property, which is why
|
||||
# the wallet and the screen disagreed. Sending a non-zero value still fixes the
|
||||
# display, for the reason below -- it bypasses the local computation entirely --
|
||||
# but do not carry the "missing row" story forward: it sent one round of work
|
||||
# looking for a table defect that was never there.
|
||||
#
|
||||
# Freeze risk: low and in the safe direction. discardValue is a plain INT read by the
|
||||
# scalar getter 0x1801c79d0. The freezes on this project have all come from feeding an
|
||||
|
||||
@@ -0,0 +1,126 @@
|
||||
"""Hardware-only trace of the engine-local overwrite wrapper entry.
|
||||
|
||||
Breaks before the prologue of FUN_147ce47e0, where [rsp] is the exact direct
|
||||
caller return address and R8D is the team ID later written to the final match
|
||||
record. This closes the one frame Wine PE unwinding could not recover.
|
||||
|
||||
No INT3/software breakpoints. No client memory writes.
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
import os
|
||||
import struct
|
||||
import time
|
||||
import traceback
|
||||
|
||||
import gdb
|
||||
|
||||
WRAPPER_VA = 0x147CE47E0
|
||||
_STATE = None
|
||||
|
||||
|
||||
def _reg(name: str) -> int:
|
||||
return int(gdb.parse_and_eval(f"${name}"))
|
||||
|
||||
|
||||
def _read(address: int, size: int) -> bytes | None:
|
||||
if not address or address < 0:
|
||||
return None
|
||||
try:
|
||||
return bytes(gdb.selected_inferior().read_memory(address, size))
|
||||
except gdb.error:
|
||||
return None
|
||||
|
||||
|
||||
def _u64(address: int) -> int | None:
|
||||
data = _read(address, 8)
|
||||
return struct.unpack("<Q", data)[0] if data else None
|
||||
|
||||
|
||||
def _thread() -> dict:
|
||||
thread = gdb.selected_thread()
|
||||
if thread is None:
|
||||
return {}
|
||||
return {"name": thread.name, "ptid": list(thread.ptid), "global_num": thread.global_num}
|
||||
|
||||
|
||||
def _registers() -> dict:
|
||||
names = (
|
||||
"rax", "rbx", "rcx", "rdx", "rsi", "rdi", "rbp", "rsp",
|
||||
"r8", "r9", "r10", "r11", "r12", "r13", "r14", "r15", "rip",
|
||||
)
|
||||
return {name: _reg(name) for name in names}
|
||||
|
||||
|
||||
class State:
|
||||
def __init__(self, path: str):
|
||||
self.path = path
|
||||
self.index = 0
|
||||
|
||||
def log(self, kind: str, **payload):
|
||||
self.index += 1
|
||||
thread = _thread()
|
||||
event = {
|
||||
"event": kind,
|
||||
"event_index": self.index,
|
||||
"time_unix": time.time(),
|
||||
"thread": thread,
|
||||
**payload,
|
||||
}
|
||||
with open(self.path, "a", encoding="utf-8") as handle:
|
||||
handle.write(json.dumps(event, sort_keys=True) + "\n")
|
||||
handle.flush()
|
||||
os.fsync(handle.fileno())
|
||||
|
||||
|
||||
class WrapperBreakpoint(gdb.Breakpoint):
|
||||
def __init__(self, state: State):
|
||||
self.state = state
|
||||
super().__init__(
|
||||
f"*0x{WRAPPER_VA:x}", type=gdb.BP_HARDWARE_BREAKPOINT, internal=False
|
||||
)
|
||||
self.silent = True
|
||||
|
||||
def stop(self):
|
||||
try:
|
||||
stack = _reg("rsp")
|
||||
caller_return = _u64(stack)
|
||||
self.state.log(
|
||||
"engine_overwrite_wrapper_entry",
|
||||
wrapper_va=WRAPPER_VA,
|
||||
caller_return_address=caller_return,
|
||||
source_team_id=_reg("r8") & 0xFFFFFFFF,
|
||||
side_argument=_reg("rdx") & 0xFFFFFFFF,
|
||||
registers=_registers(),
|
||||
caller_disassembly=(
|
||||
gdb.execute(f"x/12i 0x{caller_return - 32:x}", to_string=True)
|
||||
if caller_return else None
|
||||
),
|
||||
backtrace=gdb.execute("bt 32", to_string=True),
|
||||
)
|
||||
except Exception as exc:
|
||||
self.state.log(
|
||||
"trace_error", where="engine_overwrite_wrapper", error=str(exc),
|
||||
traceback=traceback.format_exc()
|
||||
)
|
||||
return False
|
||||
|
||||
|
||||
def _on_exit(event):
|
||||
if _STATE is not None:
|
||||
_STATE.log("inferior_exited", detail=str(event))
|
||||
|
||||
|
||||
def start_trace(log_path: str, _cards_base: int):
|
||||
global _STATE
|
||||
open(log_path, "w", encoding="utf-8").close()
|
||||
_STATE = State(log_path)
|
||||
breakpoint = WrapperBreakpoint(_STATE)
|
||||
gdb.events.exited.connect(_on_exit)
|
||||
_STATE.log(
|
||||
"trace_armed",
|
||||
breakpoints={"engine_overwrite_wrapper": {"number": breakpoint.number, "va": WRAPPER_VA}},
|
||||
hardware_only=True,
|
||||
client_memory_writes=False,
|
||||
)
|
||||
@@ -0,0 +1,226 @@
|
||||
"""GDB payload for the LIVE-PROVEN engine match-team +0x14 writer.
|
||||
|
||||
READ-ONLY hardware debug only:
|
||||
|
||||
0x147c652ce mov dword [rdx + rcx + 0x44], r8d
|
||||
|
||||
At the first team-like source value, derives both fixed-stride record fields
|
||||
from live RCX and arms 4-byte WRITE watchpoints on:
|
||||
|
||||
teamId A = rcx + 0x44
|
||||
teamId B = rcx + 0x44 + 0x45c
|
||||
|
||||
The execute breakpoint records the intended source value before every call. The
|
||||
watchpoints then capture both the expected write and any later overwrite, even
|
||||
if the overwrite comes from a different function.
|
||||
|
||||
No INT3/software breakpoints. No client memory writes.
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
import os
|
||||
import struct
|
||||
import time
|
||||
import traceback
|
||||
|
||||
import gdb
|
||||
|
||||
WRITER_VA = 0x147C652CE
|
||||
POST_WRITER_VA = 0x147C652D3
|
||||
SIDE_STRIDE = 0x45C
|
||||
TEAM_FIELD_OFF = 0x44
|
||||
RECORD_FIELD_OFF = 0x14
|
||||
TEAM_LIKE = {73, 240, 241, 243, 130000, 130001}
|
||||
|
||||
_STATE = None
|
||||
|
||||
|
||||
def _reg(name: str) -> int:
|
||||
return int(gdb.parse_and_eval(f"${name}"))
|
||||
|
||||
|
||||
def _thread() -> dict:
|
||||
thread = gdb.selected_thread()
|
||||
if thread is None:
|
||||
return {}
|
||||
return {"name": thread.name, "ptid": list(thread.ptid), "global_num": thread.global_num}
|
||||
|
||||
|
||||
def _read(address: int, size: int) -> bytes | None:
|
||||
if not address or address < 0:
|
||||
return None
|
||||
try:
|
||||
return bytes(gdb.selected_inferior().read_memory(address, size))
|
||||
except gdb.error:
|
||||
return None
|
||||
|
||||
|
||||
def _i32(address: int) -> int | None:
|
||||
data = _read(address, 4)
|
||||
return struct.unpack("<i", data)[0] if data else None
|
||||
|
||||
|
||||
def _registers() -> dict:
|
||||
names = (
|
||||
"rax", "rbx", "rcx", "rdx", "rsi", "rdi", "rbp", "rsp",
|
||||
"r8", "r9", "r10", "r11", "r12", "r13", "r14", "r15", "rip",
|
||||
)
|
||||
return {name: _reg(name) for name in names}
|
||||
|
||||
|
||||
class State:
|
||||
def __init__(self, log_path: str):
|
||||
self.log_path = log_path
|
||||
self.event_index = 0
|
||||
self.engine_base = None
|
||||
self.watch_a = None
|
||||
self.watch_b = None
|
||||
|
||||
def log(self, kind: str, **payload):
|
||||
self.event_index += 1
|
||||
event = {
|
||||
"event": kind,
|
||||
"event_index": self.event_index,
|
||||
"time_unix": time.time(),
|
||||
"thread": _thread(),
|
||||
**payload,
|
||||
}
|
||||
with open(self.log_path, "a", encoding="utf-8") as handle:
|
||||
handle.write(json.dumps(event, sort_keys=True) + "\n")
|
||||
handle.flush()
|
||||
os.fsync(handle.fileno())
|
||||
|
||||
def arm_fields(self, engine_base: int):
|
||||
if self.engine_base == engine_base and self.watch_a and self.watch_b:
|
||||
return
|
||||
for watchpoint in (self.watch_a, self.watch_b):
|
||||
if watchpoint is not None:
|
||||
try:
|
||||
watchpoint.delete()
|
||||
except gdb.error:
|
||||
pass
|
||||
self.engine_base = engine_base
|
||||
self.watch_a = TeamFieldWatchpoint(self, 0, engine_base + TEAM_FIELD_OFF)
|
||||
self.watch_b = TeamFieldWatchpoint(
|
||||
self, 1, engine_base + TEAM_FIELD_OFF + SIDE_STRIDE
|
||||
)
|
||||
self.log(
|
||||
"team_field_watchpoints_armed",
|
||||
engine_base=engine_base,
|
||||
team_id_a_address=self.watch_a.address,
|
||||
team_id_b_address=self.watch_b.address,
|
||||
watchpoint_a=self.watch_a.number,
|
||||
watchpoint_b=self.watch_b.number,
|
||||
)
|
||||
|
||||
|
||||
class TeamFieldWatchpoint(gdb.Breakpoint):
|
||||
def __init__(self, state: State, side: int, address: int):
|
||||
self.state = state
|
||||
self.side = side
|
||||
self.address = address
|
||||
super().__init__(
|
||||
f"*(int*)0x{address:x}",
|
||||
type=gdb.BP_WATCHPOINT,
|
||||
wp_class=gdb.WP_WRITE,
|
||||
internal=False,
|
||||
)
|
||||
self.silent = True
|
||||
|
||||
def stop(self):
|
||||
try:
|
||||
pc = _reg("rip")
|
||||
writer = WRITER_VA if pc == POST_WRITER_VA else None
|
||||
record_start = self.address - RECORD_FIELD_OFF
|
||||
record = _read(record_start, 0x7C)
|
||||
self.state.log(
|
||||
"final_team_field_write_post",
|
||||
side=self.side,
|
||||
watch_address=self.address,
|
||||
value=_i32(self.address),
|
||||
stopped_pc=pc,
|
||||
writer_va=writer,
|
||||
record_start=record_start,
|
||||
record_hex=record.hex() if record else None,
|
||||
registers=_registers(),
|
||||
disassembly=gdb.execute("x/12i $pc-32", to_string=True),
|
||||
backtrace=gdb.execute("bt 32", to_string=True),
|
||||
)
|
||||
except Exception as exc:
|
||||
self.state.log(
|
||||
"trace_error",
|
||||
where="team_field_watchpoint",
|
||||
error=str(exc),
|
||||
traceback=traceback.format_exc(),
|
||||
)
|
||||
return False
|
||||
|
||||
|
||||
class FinalWriterBreakpoint(gdb.Breakpoint):
|
||||
def __init__(self, state: State):
|
||||
self.state = state
|
||||
super().__init__(
|
||||
f"*0x{WRITER_VA:x}", type=gdb.BP_HARDWARE_BREAKPOINT, internal=False
|
||||
)
|
||||
self.silent = True
|
||||
|
||||
def stop(self):
|
||||
try:
|
||||
engine_base = _reg("rcx")
|
||||
side_offset = _reg("rdx")
|
||||
source_value = _reg("r8") & 0xFFFFFFFF
|
||||
if source_value in TEAM_LIKE:
|
||||
self.state.arm_fields(engine_base)
|
||||
destination = engine_base + side_offset + TEAM_FIELD_OFF
|
||||
side = side_offset // SIDE_STRIDE if side_offset in (0, SIDE_STRIDE) else None
|
||||
self.state.log(
|
||||
"final_writer_pre",
|
||||
instruction_va=WRITER_VA,
|
||||
engine_base=engine_base,
|
||||
side_offset=side_offset,
|
||||
side=side,
|
||||
destination=destination,
|
||||
record_start=destination - RECORD_FIELD_OFF,
|
||||
source_register="r8d",
|
||||
source_value=source_value,
|
||||
prior_value=_i32(destination),
|
||||
team_id_a_address=engine_base + TEAM_FIELD_OFF,
|
||||
team_id_b_address=engine_base + TEAM_FIELD_OFF + SIDE_STRIDE,
|
||||
team_id_a_before=_i32(engine_base + TEAM_FIELD_OFF),
|
||||
team_id_b_before=_i32(engine_base + TEAM_FIELD_OFF + SIDE_STRIDE),
|
||||
registers=_registers(),
|
||||
disassembly=gdb.execute("x/6i $pc", to_string=True),
|
||||
backtrace=gdb.execute("bt 32", to_string=True),
|
||||
)
|
||||
except Exception as exc:
|
||||
self.state.log(
|
||||
"trace_error",
|
||||
where="final_writer",
|
||||
error=str(exc),
|
||||
traceback=traceback.format_exc(),
|
||||
)
|
||||
return False
|
||||
|
||||
|
||||
def _on_exit(event):
|
||||
if _STATE is not None:
|
||||
_STATE.log("inferior_exited", detail=str(event))
|
||||
|
||||
|
||||
def start_trace(log_path: str, _cards_base: int):
|
||||
global _STATE
|
||||
open(log_path, "w", encoding="utf-8").close()
|
||||
_STATE = State(log_path)
|
||||
writer = FinalWriterBreakpoint(_STATE)
|
||||
gdb.events.exited.connect(_on_exit)
|
||||
_STATE.log(
|
||||
"trace_armed",
|
||||
breakpoints={
|
||||
"final_writer": {"number": writer.number, "va": WRITER_VA},
|
||||
},
|
||||
side_stride=SIDE_STRIDE,
|
||||
team_field_offset=TEAM_FIELD_OFF,
|
||||
hardware_only=True,
|
||||
client_memory_writes=False,
|
||||
)
|
||||
@@ -0,0 +1,225 @@
|
||||
"""Hardware-only origin trace for the exact SetTeam team context.
|
||||
|
||||
Matches the typed integer context pointer selected by SetTeam to the constructor
|
||||
invocation that produced it. No client memory writes.
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
from collections import deque
|
||||
import json
|
||||
import os
|
||||
import struct
|
||||
import time
|
||||
import traceback
|
||||
|
||||
import gdb
|
||||
|
||||
CONTEXT_REUSE = 0x1477C17FC
|
||||
CONTEXT_ALLOCATED = 0x1477C18C1
|
||||
SET_TEAM_STUB = 0x147060A80
|
||||
LOCKED_SETTER_RETURN = 0x1477C2415
|
||||
CONTEXT_STACK_COUNT = 0x144BCEDA0
|
||||
CONTEXT_STACK_ARRAY = 0x144BCEDA8
|
||||
INTERESTING = {73, 130000, 130001}
|
||||
_STATE = None
|
||||
|
||||
|
||||
def _reg(name):
|
||||
return int(gdb.parse_and_eval(f"${name}"))
|
||||
|
||||
|
||||
def _read(address, size):
|
||||
if not address or address < 0:
|
||||
return None
|
||||
try:
|
||||
return bytes(gdb.selected_inferior().read_memory(address, size))
|
||||
except gdb.error:
|
||||
return None
|
||||
|
||||
|
||||
def _u64(address):
|
||||
data = _read(address, 8)
|
||||
return struct.unpack("<Q", data)[0] if data else None
|
||||
|
||||
|
||||
def _i32(address):
|
||||
data = _read(address, 4)
|
||||
return struct.unpack("<i", data)[0] if data else None
|
||||
|
||||
|
||||
def _thread():
|
||||
thread = gdb.selected_thread()
|
||||
if thread is None:
|
||||
return {}
|
||||
return {"name": thread.name, "ptid": list(thread.ptid), "global_num": thread.global_num}
|
||||
|
||||
|
||||
class State:
|
||||
def __init__(self, path):
|
||||
self.path = path
|
||||
self.index = 0
|
||||
self.total_constructor_hits = 0
|
||||
self.interesting_constructor_hits = 0
|
||||
self.pending_allocations = {}
|
||||
self.origins = deque(maxlen=4096)
|
||||
|
||||
def log(self, kind, **payload):
|
||||
self.index += 1
|
||||
event = {
|
||||
"event": kind,
|
||||
"event_index": self.index,
|
||||
"time_unix": time.time(),
|
||||
"thread": _thread(),
|
||||
**payload,
|
||||
}
|
||||
with open(self.path, "a", encoding="utf-8") as handle:
|
||||
handle.write(json.dumps(event, sort_keys=True) + "\n")
|
||||
handle.flush()
|
||||
os.fsync(handle.fileno())
|
||||
|
||||
def thread_key(self):
|
||||
return tuple(_thread().get("ptid", ()))
|
||||
|
||||
def remember_origin(self, context, origin):
|
||||
if context:
|
||||
self.origins.append({**origin, "context": context})
|
||||
|
||||
def find_origin(self, context):
|
||||
return next((origin for origin in reversed(self.origins)
|
||||
if origin["context"] == context), None)
|
||||
|
||||
|
||||
class HardwareBreakpoint(gdb.Breakpoint):
|
||||
def __init__(self, state, address):
|
||||
self.state = state
|
||||
self.address = address
|
||||
super().__init__(f"*0x{address:x}", type=gdb.BP_HARDWARE_BREAKPOINT, internal=False)
|
||||
self.silent = True
|
||||
|
||||
|
||||
class ContextReuseBreakpoint(HardwareBreakpoint):
|
||||
def stop(self):
|
||||
self.state.total_constructor_hits += 1
|
||||
try:
|
||||
value = _reg("rcx") & 0xFFFFFFFF
|
||||
if value not in INTERESTING:
|
||||
return False
|
||||
self.state.interesting_constructor_hits += 1
|
||||
rsp = _reg("rsp")
|
||||
direct_return = _u64(rsp + 0x28)
|
||||
origin = {
|
||||
"value": value,
|
||||
"direct_return_address": direct_return,
|
||||
"upstream_return_address": (
|
||||
_u64(rsp + 0x68)
|
||||
if direct_return == LOCKED_SETTER_RETURN
|
||||
else direct_return
|
||||
),
|
||||
"constructor_stack_hex": (_read(rsp, 0x100) or b"").hex(),
|
||||
"constructor_hit": self.state.total_constructor_hits,
|
||||
}
|
||||
context = _reg("rax")
|
||||
if context:
|
||||
self.state.remember_origin(context, origin)
|
||||
else:
|
||||
self.state.pending_allocations[self.state.thread_key()] = origin
|
||||
except Exception as exc:
|
||||
self.state.log(
|
||||
"trace_error",
|
||||
where="context_reuse",
|
||||
error=str(exc),
|
||||
traceback=traceback.format_exc(),
|
||||
)
|
||||
return False
|
||||
|
||||
|
||||
class ContextAllocatedBreakpoint(HardwareBreakpoint):
|
||||
def stop(self):
|
||||
try:
|
||||
origin = self.state.pending_allocations.pop(self.state.thread_key(), None)
|
||||
if origin is not None:
|
||||
self.state.remember_origin(_reg("rdx"), origin)
|
||||
except Exception as exc:
|
||||
self.state.log(
|
||||
"trace_error",
|
||||
where="context_allocated",
|
||||
error=str(exc),
|
||||
traceback=traceback.format_exc(),
|
||||
)
|
||||
return False
|
||||
|
||||
|
||||
class SetTeamStubBreakpoint(HardwareBreakpoint):
|
||||
def stop(self):
|
||||
try:
|
||||
count = _i32(CONTEXT_STACK_COUNT)
|
||||
array = _u64(CONTEXT_STACK_ARRAY)
|
||||
team_context = (
|
||||
_u64(array + (count - 2) * 8)
|
||||
if array and count is not None and count >= 2
|
||||
else None
|
||||
)
|
||||
side_context = (
|
||||
_u64(array + (count - 1) * 8)
|
||||
if array and count is not None and count >= 1
|
||||
else None
|
||||
)
|
||||
rsp = _reg("rsp")
|
||||
self.state.log(
|
||||
"set_team_stub_entry",
|
||||
context_stack_count=count,
|
||||
team_context=team_context,
|
||||
team_context_hex=(_read(team_context, 0x40) or b"").hex(),
|
||||
team_value=_i32(team_context + 0x10) if team_context else None,
|
||||
side_context=side_context,
|
||||
side_value=_i32(side_context + 0x10) if side_context else None,
|
||||
matched_origin=self.state.find_origin(team_context),
|
||||
caller_return_address=_u64(rsp),
|
||||
entry_registers={
|
||||
name: _reg(name)
|
||||
for name in ("rcx", "rdx", "r8", "r9")
|
||||
},
|
||||
backtrace=gdb.execute("bt 32", to_string=True),
|
||||
total_constructor_hits=self.state.total_constructor_hits,
|
||||
interesting_constructor_hits=self.state.interesting_constructor_hits,
|
||||
)
|
||||
except Exception as exc:
|
||||
self.state.log(
|
||||
"trace_error",
|
||||
where="set_team_stub",
|
||||
error=str(exc),
|
||||
traceback=traceback.format_exc(),
|
||||
)
|
||||
return False
|
||||
|
||||
|
||||
def _on_exit(event):
|
||||
if _STATE is not None:
|
||||
_STATE.log(
|
||||
"inferior_exited",
|
||||
detail=str(event),
|
||||
total_constructor_hits=_STATE.total_constructor_hits,
|
||||
interesting_constructor_hits=_STATE.interesting_constructor_hits,
|
||||
)
|
||||
|
||||
|
||||
def start_trace(log_path, _cards_base):
|
||||
global _STATE
|
||||
open(log_path, "w", encoding="utf-8").close()
|
||||
_STATE = State(log_path)
|
||||
points = {
|
||||
"context_reuse": ContextReuseBreakpoint(_STATE, CONTEXT_REUSE),
|
||||
"context_allocated": ContextAllocatedBreakpoint(_STATE, CONTEXT_ALLOCATED),
|
||||
"set_team_stub": SetTeamStubBreakpoint(_STATE, SET_TEAM_STUB),
|
||||
}
|
||||
gdb.events.exited.connect(_on_exit)
|
||||
_STATE.log(
|
||||
"trace_armed",
|
||||
breakpoints={
|
||||
name: {"number": point.number, "va": point.address}
|
||||
for name, point in points.items()
|
||||
},
|
||||
hardware_only=True,
|
||||
client_memory_writes=False,
|
||||
matching="exact_context_pointer",
|
||||
)
|
||||
@@ -0,0 +1,167 @@
|
||||
"""Hardware-only trace of engine game-setup context selection.
|
||||
|
||||
Captures the function that requests team/side, selector indices 1/0, selected
|
||||
transient context objects, and the typed value getter. No client writes.
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
import os
|
||||
import struct
|
||||
import time
|
||||
import traceback
|
||||
|
||||
import gdb
|
||||
|
||||
DISPATCH = 0x147060D00
|
||||
SELECT_VALUE = 0x147572C50
|
||||
CONTEXT_SELECTED = 0x1477C845D
|
||||
_STATE = None
|
||||
|
||||
|
||||
def _reg(name: str) -> int:
|
||||
return int(gdb.parse_and_eval(f"${name}"))
|
||||
|
||||
|
||||
def _read(address: int, size: int) -> bytes | None:
|
||||
if not address or address < 0:
|
||||
return None
|
||||
try:
|
||||
return bytes(gdb.selected_inferior().read_memory(address, size))
|
||||
except gdb.error:
|
||||
return None
|
||||
|
||||
|
||||
def _u64(address: int) -> int | None:
|
||||
data = _read(address, 8)
|
||||
return struct.unpack("<Q", data)[0] if data else None
|
||||
|
||||
|
||||
def _i32(address: int) -> int | None:
|
||||
data = _read(address, 4)
|
||||
return struct.unpack("<i", data)[0] if data else None
|
||||
|
||||
|
||||
def _thread() -> dict:
|
||||
thread = gdb.selected_thread()
|
||||
if thread is None:
|
||||
return {}
|
||||
return {"name": thread.name, "ptid": list(thread.ptid), "global_num": thread.global_num}
|
||||
|
||||
|
||||
def _printable_pointers(address: int, data: bytes) -> dict:
|
||||
found = {}
|
||||
for offset in range(0, len(data) - 7, 8):
|
||||
pointer = struct.unpack_from("<Q", data, offset)[0]
|
||||
raw = _read(pointer, 128)
|
||||
if not raw:
|
||||
continue
|
||||
value = raw.split(b"\0", 1)[0]
|
||||
try:
|
||||
text = value.decode("utf-8")
|
||||
except UnicodeDecodeError:
|
||||
continue
|
||||
if len(text) >= 3 and all(char.isprintable() for char in text):
|
||||
found[hex(offset)] = {"pointer": pointer, "text": text}
|
||||
return found
|
||||
|
||||
|
||||
class State:
|
||||
def __init__(self, path: str):
|
||||
self.path = path
|
||||
self.index = 0
|
||||
self.requested_indices = {}
|
||||
|
||||
def log(self, kind: str, **payload):
|
||||
self.index += 1
|
||||
event = {"event": kind, "event_index": self.index, "time_unix": time.time(),
|
||||
"thread": _thread(), **payload}
|
||||
with open(self.path, "a", encoding="utf-8") as handle:
|
||||
handle.write(json.dumps(event, sort_keys=True) + "\n")
|
||||
handle.flush(); os.fsync(handle.fileno())
|
||||
|
||||
def key(self):
|
||||
return tuple(_thread().get("ptid", ()))
|
||||
|
||||
|
||||
class HardwareBreakpoint(gdb.Breakpoint):
|
||||
def __init__(self, state: State, address: int):
|
||||
self.state = state
|
||||
self.address = address
|
||||
super().__init__(f"*0x{address:x}", type=gdb.BP_HARDWARE_BREAKPOINT, internal=False)
|
||||
self.silent = True
|
||||
|
||||
|
||||
class DispatchBreakpoint(HardwareBreakpoint):
|
||||
def stop(self):
|
||||
try:
|
||||
rsp = _reg("rsp")
|
||||
caller = _u64(rsp)
|
||||
self.state.log(
|
||||
"game_setup_dispatch_entry",
|
||||
caller_return_address=caller,
|
||||
caller_disassembly=(gdb.execute(f"x/12i 0x{caller-32:x}", to_string=True)
|
||||
if caller else None),
|
||||
backtrace=gdb.execute("bt 24", to_string=True),
|
||||
)
|
||||
except Exception as exc:
|
||||
self.state.log("trace_error", where="dispatch", error=str(exc), traceback=traceback.format_exc())
|
||||
return False
|
||||
|
||||
|
||||
class SelectValueBreakpoint(HardwareBreakpoint):
|
||||
def stop(self):
|
||||
try:
|
||||
index = _reg("rcx") & 0xFFFFFFFF
|
||||
self.state.requested_indices[self.state.key()] = index
|
||||
self.state.log("context_value_request", index=index)
|
||||
except Exception as exc:
|
||||
self.state.log("trace_error", where="select_value", error=str(exc), traceback=traceback.format_exc())
|
||||
return False
|
||||
|
||||
|
||||
class ContextSelectedBreakpoint(HardwareBreakpoint):
|
||||
def stop(self):
|
||||
try:
|
||||
index = _reg("rdi") & 0xFFFFFFFF
|
||||
context = _reg("rbx")
|
||||
data = _read(context, 0x80) or b""
|
||||
self.state.log(
|
||||
"context_selected",
|
||||
requested_index=self.state.requested_indices.get(self.state.key()),
|
||||
selector_index=index,
|
||||
context=context,
|
||||
type_flags=_i32(context + 8),
|
||||
value_i32=_i32(context + 0x10),
|
||||
value_qword=_u64(context + 0x10),
|
||||
context_hex=data.hex(),
|
||||
printable_pointers=_printable_pointers(context, data),
|
||||
)
|
||||
except Exception as exc:
|
||||
self.state.log("trace_error", where="context_selected", error=str(exc), traceback=traceback.format_exc())
|
||||
return False
|
||||
|
||||
|
||||
|
||||
|
||||
def _on_exit(event):
|
||||
if _STATE is not None:
|
||||
_STATE.log("inferior_exited", detail=str(event))
|
||||
|
||||
|
||||
def start_trace(log_path: str, _cards_base: int):
|
||||
global _STATE
|
||||
open(log_path, "w", encoding="utf-8").close()
|
||||
_STATE = State(log_path)
|
||||
points = {
|
||||
"dispatch": DispatchBreakpoint(_STATE, DISPATCH),
|
||||
"select_value": SelectValueBreakpoint(_STATE, SELECT_VALUE),
|
||||
"context_selected": ContextSelectedBreakpoint(_STATE, CONTEXT_SELECTED),
|
||||
}
|
||||
gdb.events.exited.connect(_on_exit)
|
||||
_STATE.log(
|
||||
"trace_armed",
|
||||
breakpoints={name: {"number": bp.number, "va": bp.address} for name, bp in points.items()},
|
||||
hardware_only=True,
|
||||
client_memory_writes=False,
|
||||
)
|
||||
@@ -0,0 +1,264 @@
|
||||
"""Hardware-only trace of CardsGameSetupAdapter query 13 and overwrite input.
|
||||
|
||||
Breakpoints:
|
||||
|
||||
FUN_180031340 entry incoming teamId/side/context
|
||||
0x18003148f pre-call query id, selector, output/count pointers
|
||||
0x180031495 post-call complete 48-byte records and count
|
||||
0x180031861 submit original incoming teamId sent to engine
|
||||
|
||||
This proves whether query 13 influences the overwrite. No INT3/software
|
||||
breakpoints, client writes, or game input.
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
import os
|
||||
import struct
|
||||
import time
|
||||
import traceback
|
||||
|
||||
import gdb
|
||||
|
||||
CARDS_IMAGE_BASE = 0x180000000
|
||||
ENTRY = 0x180031340
|
||||
QUERY_PRE = 0x18003148F
|
||||
QUERY_POST = 0x180031495
|
||||
SUBMIT = 0x180031861
|
||||
MAX_RECORDS = 100
|
||||
RECORD_SIZE = 48
|
||||
_STATE = None
|
||||
|
||||
|
||||
def _reg(name: str) -> int:
|
||||
return int(gdb.parse_and_eval(f"${name}"))
|
||||
|
||||
|
||||
def _read(address: int, size: int) -> bytes | None:
|
||||
if not address or address < 0 or size < 0:
|
||||
return None
|
||||
try:
|
||||
return bytes(gdb.selected_inferior().read_memory(address, size))
|
||||
except gdb.error:
|
||||
return None
|
||||
|
||||
|
||||
def _u64(address: int) -> int | None:
|
||||
data = _read(address, 8)
|
||||
return struct.unpack("<Q", data)[0] if data else None
|
||||
|
||||
|
||||
def _i32(address: int) -> int | None:
|
||||
data = _read(address, 4)
|
||||
return struct.unpack("<i", data)[0] if data else None
|
||||
|
||||
|
||||
def _thread() -> dict:
|
||||
thread = gdb.selected_thread()
|
||||
if thread is None:
|
||||
return {}
|
||||
return {"name": thread.name, "ptid": list(thread.ptid), "global_num": thread.global_num}
|
||||
|
||||
|
||||
def _registers() -> dict:
|
||||
names = (
|
||||
"rax", "rbx", "rcx", "rdx", "rsi", "rdi", "rbp", "rsp",
|
||||
"r8", "r9", "r10", "r11", "r12", "r13", "r14", "r15", "rip",
|
||||
)
|
||||
return {name: _reg(name) for name in names}
|
||||
|
||||
|
||||
def _printable_pointer(pointer: int) -> str | None:
|
||||
data = _read(pointer, 96)
|
||||
if not data:
|
||||
return None
|
||||
raw = data.split(b"\0", 1)[0]
|
||||
if len(raw) < 3:
|
||||
return None
|
||||
try:
|
||||
text = raw.decode("utf-8")
|
||||
except UnicodeDecodeError:
|
||||
return None
|
||||
return text if all(char.isprintable() for char in text) else None
|
||||
|
||||
|
||||
def _decode_record(data: bytes, address: int) -> dict:
|
||||
words = list(struct.unpack("<12i", data))
|
||||
qwords = list(struct.unpack("<6Q", data))
|
||||
strings = {}
|
||||
for index, pointer in enumerate(qwords):
|
||||
text = _printable_pointer(pointer)
|
||||
if text:
|
||||
strings[f"qword_{index}"] = {"pointer": pointer, "text": text}
|
||||
interesting = {
|
||||
str(value): [index * 4 for index, word in enumerate(words) if word == value]
|
||||
for value in (73, 240, 241, 243, 130000, 130001)
|
||||
if value in words
|
||||
}
|
||||
return {
|
||||
"address": address,
|
||||
"hex": data.hex(),
|
||||
"i32": words,
|
||||
"u32": [value & 0xFFFFFFFF for value in words],
|
||||
"f32": list(struct.unpack("<12f", data)),
|
||||
"qwords": qwords,
|
||||
"strings": strings,
|
||||
"interesting_values": interesting,
|
||||
}
|
||||
|
||||
|
||||
class State:
|
||||
def __init__(self, path: str, cards_base: int):
|
||||
self.path = path
|
||||
self.cards_base = cards_base
|
||||
self.index = 0
|
||||
self.calls = {}
|
||||
|
||||
def log(self, kind: str, **payload):
|
||||
self.index += 1
|
||||
event = {
|
||||
"event": kind,
|
||||
"event_index": self.index,
|
||||
"time_unix": time.time(),
|
||||
"thread": _thread(),
|
||||
**payload,
|
||||
}
|
||||
with open(self.path, "a", encoding="utf-8") as handle:
|
||||
handle.write(json.dumps(event, sort_keys=True) + "\n")
|
||||
handle.flush()
|
||||
os.fsync(handle.fileno())
|
||||
|
||||
def thread_key(self):
|
||||
return tuple(_thread().get("ptid", ()))
|
||||
|
||||
|
||||
class HardwareBreakpoint(gdb.Breakpoint):
|
||||
def __init__(self, state: State, image_va: int):
|
||||
self.state = state
|
||||
self.image_va = image_va
|
||||
address = state.cards_base + (image_va - CARDS_IMAGE_BASE)
|
||||
super().__init__(f"*0x{address:x}", type=gdb.BP_HARDWARE_BREAKPOINT, internal=False)
|
||||
self.silent = True
|
||||
|
||||
|
||||
class EntryBreakpoint(HardwareBreakpoint):
|
||||
def stop(self):
|
||||
try:
|
||||
self.state.log(
|
||||
"game_setup_entry",
|
||||
incoming_context=_reg("rcx"),
|
||||
incoming_side=_reg("rdx") & 0xFFFFFFFF,
|
||||
incoming_team_id=_reg("r8") & 0xFFFFFFFF,
|
||||
incoming_r9=_reg("r9"),
|
||||
registers=_registers(),
|
||||
backtrace=gdb.execute("bt 24", to_string=True),
|
||||
)
|
||||
except Exception as exc:
|
||||
self.state.log("trace_error", where="entry", error=str(exc), traceback=traceback.format_exc())
|
||||
return False
|
||||
|
||||
|
||||
class QueryPreBreakpoint(HardwareBreakpoint):
|
||||
def stop(self):
|
||||
try:
|
||||
rsp = _reg("rsp")
|
||||
adapter = _reg("rcx")
|
||||
vtable = _u64(adapter)
|
||||
count_pointer = _u64(rsp + 0x20)
|
||||
state = {
|
||||
"adapter": adapter,
|
||||
"adapter_vtable": vtable,
|
||||
"query_target": _u64(vtable + 0xE0) if vtable else None,
|
||||
"query_id": _reg("rdx") & 0xFFFFFFFF,
|
||||
"selector": _reg("r8") & 0xFFFFFFFF,
|
||||
"output_buffer": _reg("r9"),
|
||||
"count_pointer": count_pointer,
|
||||
"sixth_argument": _u64(rsp + 0x28),
|
||||
"count_before": _i32(count_pointer) if count_pointer else None,
|
||||
"saved_incoming_team_id": _i32(rsp + 0x34),
|
||||
"saved_side": _i32(rsp + 0x50),
|
||||
"saved_engine_context": _u64(rsp + 0x68),
|
||||
"adapter_prefix_hex": (_read(adapter, 0x100) or b"").hex(),
|
||||
}
|
||||
self.state.calls[self.state.thread_key()] = state
|
||||
self.state.log(
|
||||
"query13_pre",
|
||||
**state,
|
||||
registers=_registers(),
|
||||
backtrace=gdb.execute("bt 24", to_string=True),
|
||||
)
|
||||
except Exception as exc:
|
||||
self.state.log("trace_error", where="query_pre", error=str(exc), traceback=traceback.format_exc())
|
||||
return False
|
||||
|
||||
|
||||
class QueryPostBreakpoint(HardwareBreakpoint):
|
||||
def stop(self):
|
||||
try:
|
||||
state = self.state.calls.get(self.state.thread_key(), {})
|
||||
count_pointer = state.get("count_pointer")
|
||||
output = state.get("output_buffer")
|
||||
count = _i32(count_pointer) if count_pointer else None
|
||||
safe_count = min(max(count or 0, 0), MAX_RECORDS)
|
||||
records = []
|
||||
for index in range(safe_count):
|
||||
address = output + index * RECORD_SIZE
|
||||
data = _read(address, RECORD_SIZE)
|
||||
if data and len(data) == RECORD_SIZE:
|
||||
records.append(_decode_record(data, address))
|
||||
self.state.log(
|
||||
"query13_post",
|
||||
query_state=state,
|
||||
count_after=count,
|
||||
records=records,
|
||||
saved_incoming_team_id_after=_i32(_reg("rsp") + 0x34),
|
||||
saved_side_after=_i32(_reg("rsp") + 0x50),
|
||||
registers=_registers(),
|
||||
)
|
||||
except Exception as exc:
|
||||
self.state.log("trace_error", where="query_post", error=str(exc), traceback=traceback.format_exc())
|
||||
return False
|
||||
|
||||
|
||||
class SubmitBreakpoint(HardwareBreakpoint):
|
||||
def stop(self):
|
||||
try:
|
||||
rsp = _reg("rsp")
|
||||
self.state.log(
|
||||
"game_setup_submit",
|
||||
submitted_team_id=_reg("r8") & 0xFFFFFFFF,
|
||||
submitted_side=_reg("rdx") & 0xFFFFFFFF,
|
||||
engine_context=_reg("rcx"),
|
||||
saved_incoming_team_id=_i32(rsp + 0x34),
|
||||
saved_side=_i32(rsp + 0x50),
|
||||
registers=_registers(),
|
||||
backtrace=gdb.execute("bt 24", to_string=True),
|
||||
)
|
||||
except Exception as exc:
|
||||
self.state.log("trace_error", where="submit", error=str(exc), traceback=traceback.format_exc())
|
||||
return False
|
||||
|
||||
|
||||
def _on_exit(event):
|
||||
if _STATE is not None:
|
||||
_STATE.log("inferior_exited", detail=str(event))
|
||||
|
||||
|
||||
def start_trace(log_path: str, cards_base: int):
|
||||
global _STATE
|
||||
open(log_path, "w", encoding="utf-8").close()
|
||||
_STATE = State(log_path, cards_base)
|
||||
points = {
|
||||
"entry": EntryBreakpoint(_STATE, ENTRY),
|
||||
"query_pre": QueryPreBreakpoint(_STATE, QUERY_PRE),
|
||||
"query_post": QueryPostBreakpoint(_STATE, QUERY_POST),
|
||||
"submit": SubmitBreakpoint(_STATE, SUBMIT),
|
||||
}
|
||||
gdb.events.exited.connect(_on_exit)
|
||||
_STATE.log(
|
||||
"trace_armed",
|
||||
breakpoints={name: {"number": bp.number, "image_va": bp.image_va} for name, bp in points.items()},
|
||||
record_size=RECORD_SIZE,
|
||||
hardware_only=True,
|
||||
client_memory_writes=False,
|
||||
)
|
||||
@@ -0,0 +1,388 @@
|
||||
"""GDB Python payload for read-only FIFA17 match-team writer tracing.
|
||||
|
||||
Loaded by trace_match_team_writer.py. Uses hardware execute breakpoints and a
|
||||
4-byte hardware WRITE watchpoint only; never inserts INT3 and never writes game
|
||||
memory.
|
||||
|
||||
Breakpoints (CardsDLL image VAs):
|
||||
|
||||
* FUN_1800fc500 entry -- derives output pair from RDX and arms *(int*)(rdx+4).
|
||||
* 0x1800fc595 -- pre-write opponent lookup into pair[1].
|
||||
* 0x1800fc5b8 -- mirrored pre-write opponent lookup into pair[0].
|
||||
|
||||
The dynamic watchpoint catches the exact write establishing pair[1], whether it
|
||||
is the opponent lookup at 0x1800fc595 or the own-club store at 0x1800fc5a0.
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
import os
|
||||
import struct
|
||||
import time
|
||||
import traceback
|
||||
|
||||
import gdb
|
||||
|
||||
CARDS_IMAGE_BASE = 0x180000000
|
||||
ENTRY_RVA = 0x0FC500
|
||||
LOOKUP_TO_TEAM1_RVA = 0x0FC595
|
||||
LOOKUP_TO_TEAM0_RVA = 0x0FC5B8
|
||||
TEAM1_POST_PC_TO_WRITER = {
|
||||
0x1800FC599: 0x1800FC595, # mov [r14+4],ecx
|
||||
0x1800FC5A4: 0x1800FC5A0, # mov [r14+4],eax
|
||||
}
|
||||
|
||||
_STATE = None
|
||||
|
||||
|
||||
def _reg(name: str) -> int:
|
||||
return int(gdb.parse_and_eval(f"${name}"))
|
||||
|
||||
|
||||
def _thread() -> dict:
|
||||
thread = gdb.selected_thread()
|
||||
if thread is None:
|
||||
return {}
|
||||
return {"name": thread.name, "ptid": list(thread.ptid), "global_num": thread.global_num}
|
||||
|
||||
|
||||
def _read(address: int, size: int) -> bytes | None:
|
||||
if not address or address < 0 or size < 0:
|
||||
return None
|
||||
try:
|
||||
return bytes(gdb.selected_inferior().read_memory(address, size))
|
||||
except gdb.error:
|
||||
return None
|
||||
|
||||
|
||||
def _u8(address: int) -> int | None:
|
||||
data = _read(address, 1)
|
||||
return data[0] if data else None
|
||||
|
||||
|
||||
def _u32(address: int) -> int | None:
|
||||
data = _read(address, 4)
|
||||
return struct.unpack("<I", data)[0] if data else None
|
||||
|
||||
|
||||
def _i32(address: int) -> int | None:
|
||||
data = _read(address, 4)
|
||||
return struct.unpack("<i", data)[0] if data else None
|
||||
|
||||
|
||||
def _u64(address: int) -> int | None:
|
||||
data = _read(address, 8)
|
||||
return struct.unpack("<Q", data)[0] if data else None
|
||||
|
||||
|
||||
def _cstring(address: int, maximum: int = 256) -> str | None:
|
||||
data = _read(address, maximum)
|
||||
if not data:
|
||||
return None
|
||||
return data.split(b"\0", 1)[0].decode("utf-8", "replace")
|
||||
|
||||
|
||||
def _rtti_name(vtable: int, cards_base: int) -> str | None:
|
||||
"""MSVC x64 RTTI name from vtable[-1] CompleteObjectLocator.
|
||||
|
||||
PE RVAs in the locator are module-relative. Failure is evidence-free and is
|
||||
logged as null; no pointer is named from an offset coincidence.
|
||||
"""
|
||||
locator = _u64(vtable - 8) if vtable else None
|
||||
if not locator:
|
||||
return None
|
||||
raw = _read(locator, 24)
|
||||
if not raw:
|
||||
return None
|
||||
_signature, _offset, _cd_offset, type_rva, _hier_rva, self_rva = struct.unpack(
|
||||
"<IIIiii", raw
|
||||
)
|
||||
if not (0 <= type_rva < 0x10000000 and 0 <= self_rva < 0x10000000):
|
||||
return None
|
||||
image_base = locator - self_rva
|
||||
if abs(image_base - cards_base) > 0x100000:
|
||||
return None
|
||||
return _cstring(image_base + type_rva + 16)
|
||||
|
||||
|
||||
def _object(address: int, cards_base: int) -> dict:
|
||||
vtable = _u64(address) if address else None
|
||||
return {
|
||||
"address": address,
|
||||
"vtable": vtable,
|
||||
"vtable_image_va": (
|
||||
CARDS_IMAGE_BASE + (vtable - cards_base)
|
||||
if vtable and cards_base <= vtable < cards_base + 0x400000
|
||||
else None
|
||||
),
|
||||
"rtti": _rtti_name(vtable, cards_base) if vtable else None,
|
||||
}
|
||||
|
||||
|
||||
def _registers() -> dict:
|
||||
names = (
|
||||
"rax",
|
||||
"rbx",
|
||||
"rcx",
|
||||
"rdx",
|
||||
"rsi",
|
||||
"rdi",
|
||||
"rbp",
|
||||
"rsp",
|
||||
"r8",
|
||||
"r9",
|
||||
"r10",
|
||||
"r11",
|
||||
"r12",
|
||||
"r13",
|
||||
"r14",
|
||||
"r15",
|
||||
"rip",
|
||||
)
|
||||
return {name: _reg(name) for name in names}
|
||||
|
||||
|
||||
def _provenance(state, destination: int | None = None) -> dict:
|
||||
"""Recover the candidate's live input chain without naming the objects."""
|
||||
regs = _registers()
|
||||
context = regs["rbx"]
|
||||
output_pair = regs["r14"]
|
||||
obj = regs["rbp"]
|
||||
nested = _u64(obj + 0xB0) if obj else None
|
||||
field_2e8 = nested + 0x2E8 if nested else None
|
||||
source_base = _u64(field_2e8) if field_2e8 else None
|
||||
participant_holder = regs["r12"]
|
||||
participant = _u64(participant_holder) if participant_holder else None
|
||||
index_70 = _u8(participant + 0x70) if participant else None
|
||||
source_address = (
|
||||
source_base + index_70 * 16
|
||||
if source_base is not None and index_70 is not None
|
||||
else None
|
||||
)
|
||||
source_bytes = _read(source_address, 16) if source_address else None
|
||||
decoded = None
|
||||
if source_bytes and len(source_bytes) == 16:
|
||||
team_id, byte4, byte5, pad, word8, wordc = struct.unpack("<iBBHii", source_bytes)
|
||||
decoded = {
|
||||
"team_id": team_id,
|
||||
"byte_4": byte4,
|
||||
"byte_5": byte5,
|
||||
"pad_6": pad,
|
||||
"word_8": word8,
|
||||
"word_c": wordc,
|
||||
}
|
||||
pair_bytes = _read(output_pair, 8) if output_pair else None
|
||||
return {
|
||||
"destination": destination,
|
||||
"context": _object(context, state.cards_base),
|
||||
"entry_context": _object(state.current_entry.get("context", 0), state.cards_base),
|
||||
"output_pair": output_pair,
|
||||
"entry_output_pair": state.current_entry.get("output_pair"),
|
||||
"output_pair_bytes": pair_bytes.hex() if pair_bytes else None,
|
||||
"output_team_id_0": _i32(output_pair) if output_pair else None,
|
||||
"output_team_id_1": _i32(output_pair + 4) if output_pair else None,
|
||||
"obj": _object(obj, state.cards_base),
|
||||
"nested_at_obj_plus_b0": _object(nested or 0, state.cards_base),
|
||||
"field_plus_2e8_address": field_2e8,
|
||||
"source_array_base": source_base,
|
||||
"participant_holder": participant_holder,
|
||||
"participant": _object(participant or 0, state.cards_base),
|
||||
"participant_plus_70": index_70,
|
||||
"source_record_address": source_address,
|
||||
"source_record_hex": source_bytes.hex() if source_bytes else None,
|
||||
"source_record": decoded,
|
||||
"registers": regs,
|
||||
}
|
||||
|
||||
|
||||
class State:
|
||||
def __init__(self, log_path: str, cards_base: int):
|
||||
self.log_path = log_path
|
||||
self.cards_base = cards_base
|
||||
self.current_entry: dict = {}
|
||||
self.watchpoint = None
|
||||
self.event_index = 0
|
||||
|
||||
def log(self, kind: str, **payload):
|
||||
self.event_index += 1
|
||||
event = {
|
||||
"event": kind,
|
||||
"event_index": self.event_index,
|
||||
"time_unix": time.time(),
|
||||
"thread": _thread(),
|
||||
**payload,
|
||||
}
|
||||
with open(self.log_path, "a", encoding="utf-8") as handle:
|
||||
handle.write(json.dumps(event, sort_keys=True) + "\n")
|
||||
handle.flush()
|
||||
os.fsync(handle.fileno())
|
||||
|
||||
|
||||
class Team1Watchpoint(gdb.Breakpoint):
|
||||
def __init__(self, state: State, address: int):
|
||||
self.state = state
|
||||
self.address = address
|
||||
super().__init__(
|
||||
f"*(int*)0x{address:x}",
|
||||
type=gdb.BP_WATCHPOINT,
|
||||
wp_class=gdb.WP_WRITE,
|
||||
internal=False,
|
||||
)
|
||||
self.silent = True
|
||||
|
||||
def stop(self):
|
||||
try:
|
||||
pc = _reg("rip")
|
||||
image_pc = CARDS_IMAGE_BASE + (pc - self.state.cards_base)
|
||||
writer = TEAM1_POST_PC_TO_WRITER.get(image_pc)
|
||||
source_value = None
|
||||
if writer == 0x1800FC595:
|
||||
source_value = _reg("rcx") & 0xFFFFFFFF
|
||||
elif writer == 0x1800FC5A0:
|
||||
source_value = _reg("rax") & 0xFFFFFFFF
|
||||
self.state.log(
|
||||
"team1_write_post",
|
||||
watch_address=self.address,
|
||||
value=_i32(self.address),
|
||||
stopped_pc=pc,
|
||||
stopped_image_va=image_pc,
|
||||
writer_image_va=writer,
|
||||
source_value=source_value,
|
||||
disassembly=gdb.execute("x/10i $pc-32", to_string=True),
|
||||
backtrace=gdb.execute("bt 24", to_string=True),
|
||||
provenance=_provenance(self.state, self.address),
|
||||
)
|
||||
if writer is not None:
|
||||
# The output pair is a short-lived stack buffer. Leaving the
|
||||
# watchpoint active after the candidate's exact write produced
|
||||
# 114k unrelated events when that stack memory was reused.
|
||||
# The two hardware lookup breakpoints remain armed, so disabling
|
||||
# only this completed one-shot watch loses no provenance.
|
||||
self.enabled = False
|
||||
self.state.log(
|
||||
"team1_watchpoint_disabled",
|
||||
watch_address=self.address,
|
||||
reason="candidate exact write captured",
|
||||
)
|
||||
except Exception as exc: # GDB must continue even if evidence rendering fails.
|
||||
self.state.log("trace_error", where="team1_watchpoint", error=str(exc),
|
||||
traceback=traceback.format_exc())
|
||||
return False
|
||||
|
||||
|
||||
class EntryBreakpoint(gdb.Breakpoint):
|
||||
def __init__(self, state: State, address: int):
|
||||
self.state = state
|
||||
super().__init__(
|
||||
f"*0x{address:x}", type=gdb.BP_HARDWARE_BREAKPOINT, internal=False
|
||||
)
|
||||
self.silent = True
|
||||
|
||||
def stop(self):
|
||||
try:
|
||||
context, output_pair = _reg("rcx"), _reg("rdx")
|
||||
self.state.current_entry = {
|
||||
"context": context,
|
||||
"output_pair": output_pair,
|
||||
"entry_thread": _thread(),
|
||||
}
|
||||
if self.state.watchpoint is not None:
|
||||
try:
|
||||
self.state.watchpoint.delete()
|
||||
except gdb.error:
|
||||
pass
|
||||
initial = _i32(output_pair + 4)
|
||||
self.state.watchpoint = Team1Watchpoint(self.state, output_pair + 4)
|
||||
self.state.log(
|
||||
"candidate_entry",
|
||||
entry_image_va=0x1800FC500,
|
||||
context=_object(context, self.state.cards_base),
|
||||
output_pair=output_pair,
|
||||
team_id_1_address=output_pair + 4,
|
||||
team_id_1_initial=initial,
|
||||
watchpoint_number=self.state.watchpoint.number,
|
||||
backtrace=gdb.execute("bt 24", to_string=True),
|
||||
registers=_registers(),
|
||||
)
|
||||
self.state.log(
|
||||
"team1_watchpoint_armed",
|
||||
watch_address=output_pair + 4,
|
||||
watchpoint_number=self.state.watchpoint.number,
|
||||
)
|
||||
except Exception as exc:
|
||||
self.state.log("trace_error", where="candidate_entry", error=str(exc),
|
||||
traceback=traceback.format_exc())
|
||||
return False
|
||||
|
||||
|
||||
class LookupStoreBreakpoint(gdb.Breakpoint):
|
||||
def __init__(self, state: State, address: int, image_va: int, destination_offset: int):
|
||||
self.state = state
|
||||
self.image_va = image_va
|
||||
self.destination_offset = destination_offset
|
||||
super().__init__(
|
||||
f"*0x{address:x}", type=gdb.BP_HARDWARE_BREAKPOINT, internal=False
|
||||
)
|
||||
self.silent = True
|
||||
|
||||
def stop(self):
|
||||
try:
|
||||
destination = _reg("r14") + self.destination_offset
|
||||
self.state.log(
|
||||
"opponent_lookup_store_pre",
|
||||
writer_image_va=self.image_va,
|
||||
destination=destination,
|
||||
destination_offset=self.destination_offset,
|
||||
source_register="ecx",
|
||||
source_value=_reg("rcx") & 0xFFFFFFFF,
|
||||
disassembly=gdb.execute("x/5i $pc", to_string=True),
|
||||
backtrace=gdb.execute("bt 24", to_string=True),
|
||||
provenance=_provenance(self.state, destination),
|
||||
)
|
||||
except Exception as exc:
|
||||
self.state.log("trace_error", where="lookup_store", error=str(exc),
|
||||
traceback=traceback.format_exc())
|
||||
return False
|
||||
|
||||
|
||||
def _on_exit(event):
|
||||
if _STATE is not None:
|
||||
_STATE.log("inferior_exited", detail=str(event))
|
||||
|
||||
|
||||
def start_trace(log_path: str, cards_base: int):
|
||||
"""Called from the supervisor's gdb command file after attach."""
|
||||
global _STATE
|
||||
open(log_path, "w", encoding="utf-8").close()
|
||||
_STATE = State(log_path, cards_base)
|
||||
entry = EntryBreakpoint(_STATE, cards_base + ENTRY_RVA)
|
||||
lookup_team1 = LookupStoreBreakpoint(
|
||||
_STATE,
|
||||
cards_base + LOOKUP_TO_TEAM1_RVA,
|
||||
0x1800FC595,
|
||||
4,
|
||||
)
|
||||
lookup_team0 = LookupStoreBreakpoint(
|
||||
_STATE,
|
||||
cards_base + LOOKUP_TO_TEAM0_RVA,
|
||||
0x1800FC5B8,
|
||||
0,
|
||||
)
|
||||
gdb.events.exited.connect(_on_exit)
|
||||
_STATE.log(
|
||||
"trace_armed",
|
||||
cards_base=cards_base,
|
||||
breakpoints={
|
||||
"candidate_entry": {"number": entry.number, "image_va": 0x1800FC500},
|
||||
"lookup_to_team1": {
|
||||
"number": lookup_team1.number,
|
||||
"image_va": 0x1800FC595,
|
||||
},
|
||||
"lookup_to_team0": {
|
||||
"number": lookup_team0.number,
|
||||
"image_va": 0x1800FC5B8,
|
||||
},
|
||||
},
|
||||
hardware_only=True,
|
||||
client_memory_writes=False,
|
||||
)
|
||||
@@ -0,0 +1,170 @@
|
||||
"""Hardware-only origin trace for CardsDLL team-pair submissions.
|
||||
|
||||
Distinguishes the three callers of the engine team-id service that can submit a
|
||||
full two-team pair, plus the mode-76 builder that prepares its pair:
|
||||
|
||||
0x1800c7583 correct fixture pair control
|
||||
0x1800c6c23 generic pair submitter
|
||||
0x1800c8dc1 mode-76 pair submitter
|
||||
0x1800c8bf0 mode-76 pair builder entry
|
||||
|
||||
No INT3/software breakpoints. No client memory writes.
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
import os
|
||||
import struct
|
||||
import time
|
||||
import traceback
|
||||
|
||||
import gdb
|
||||
|
||||
CARDS_IMAGE_BASE = 0x180000000
|
||||
SITES = {
|
||||
0x1800C7583: ("fixture_pair_submit", "r14", "rsi"),
|
||||
0x1800C6C23: ("generic_pair_submit", "r14", "rsi"),
|
||||
0x1800C8DC1: ("mode76_pair_submit", "r15", "rbp"),
|
||||
}
|
||||
MODE76_BUILDER = 0x1800C8BF0
|
||||
_STATE = None
|
||||
|
||||
|
||||
def _reg(name: str) -> int:
|
||||
return int(gdb.parse_and_eval(f"${name}"))
|
||||
|
||||
|
||||
def _thread() -> dict:
|
||||
thread = gdb.selected_thread()
|
||||
if thread is None:
|
||||
return {}
|
||||
return {"name": thread.name, "ptid": list(thread.ptid), "global_num": thread.global_num}
|
||||
|
||||
|
||||
def _read(address: int, size: int) -> bytes | None:
|
||||
if not address or address < 0:
|
||||
return None
|
||||
try:
|
||||
return bytes(gdb.selected_inferior().read_memory(address, size))
|
||||
except gdb.error:
|
||||
return None
|
||||
|
||||
|
||||
def _pair(address: int) -> list[int] | None:
|
||||
data = _read(address, 8)
|
||||
return list(struct.unpack("<2i", data)) if data else None
|
||||
|
||||
|
||||
def _registers() -> dict:
|
||||
names = (
|
||||
"rax", "rbx", "rcx", "rdx", "rsi", "rdi", "rbp", "rsp",
|
||||
"r8", "r9", "r10", "r11", "r12", "r13", "r14", "r15", "rip",
|
||||
)
|
||||
return {name: _reg(name) for name in names}
|
||||
|
||||
|
||||
class State:
|
||||
def __init__(self, log_path: str, cards_base: int):
|
||||
self.log_path = log_path
|
||||
self.cards_base = cards_base
|
||||
self.event_index = 0
|
||||
|
||||
def log(self, kind: str, **payload):
|
||||
self.event_index += 1
|
||||
event = {
|
||||
"event": kind,
|
||||
"event_index": self.event_index,
|
||||
"time_unix": time.time(),
|
||||
"thread": _thread(),
|
||||
**payload,
|
||||
}
|
||||
with open(self.log_path, "a", encoding="utf-8") as handle:
|
||||
handle.write(json.dumps(event, sort_keys=True) + "\n")
|
||||
handle.flush()
|
||||
os.fsync(handle.fileno())
|
||||
|
||||
|
||||
class PairSubmitBreakpoint(gdb.Breakpoint):
|
||||
def __init__(self, state: State, image_va: int, name: str, pointer_reg: str, index_reg: str):
|
||||
self.state = state
|
||||
self.image_va = image_va
|
||||
self.name = name
|
||||
self.pointer_reg = pointer_reg
|
||||
self.index_reg = index_reg
|
||||
address = state.cards_base + (image_va - CARDS_IMAGE_BASE)
|
||||
super().__init__(f"*0x{address:x}", type=gdb.BP_HARDWARE_BREAKPOINT, internal=False)
|
||||
self.silent = True
|
||||
|
||||
def stop(self):
|
||||
try:
|
||||
pointer = _reg(self.pointer_reg)
|
||||
index = _reg(self.index_reg) & 0xFFFFFFFF
|
||||
pair_base = pointer - index * 4
|
||||
self.state.log(
|
||||
self.name,
|
||||
instruction_image_va=self.image_va,
|
||||
source_value=_reg("r8") & 0xFFFFFFFF,
|
||||
side=_reg("rdx") & 0xFF,
|
||||
engine_base=_reg("rcx"),
|
||||
pair_pointer=pointer,
|
||||
pair_index=index,
|
||||
pair_base=pair_base,
|
||||
pair=_pair(pair_base),
|
||||
registers=_registers(),
|
||||
disassembly=gdb.execute("x/5i $pc", to_string=True),
|
||||
backtrace=gdb.execute("bt 24", to_string=True),
|
||||
)
|
||||
except Exception as exc:
|
||||
self.state.log(
|
||||
"trace_error", where=self.name, error=str(exc),
|
||||
traceback=traceback.format_exc()
|
||||
)
|
||||
return False
|
||||
|
||||
|
||||
class Mode76BuilderBreakpoint(gdb.Breakpoint):
|
||||
def __init__(self, state: State):
|
||||
self.state = state
|
||||
address = state.cards_base + (MODE76_BUILDER - CARDS_IMAGE_BASE)
|
||||
super().__init__(f"*0x{address:x}", type=gdb.BP_HARDWARE_BREAKPOINT, internal=False)
|
||||
self.silent = True
|
||||
|
||||
def stop(self):
|
||||
try:
|
||||
self.state.log(
|
||||
"mode76_builder_entry",
|
||||
instruction_image_va=MODE76_BUILDER,
|
||||
object=_reg("rcx"),
|
||||
registers=_registers(),
|
||||
backtrace=gdb.execute("bt 24", to_string=True),
|
||||
)
|
||||
except Exception as exc:
|
||||
self.state.log(
|
||||
"trace_error", where="mode76_builder", error=str(exc),
|
||||
traceback=traceback.format_exc()
|
||||
)
|
||||
return False
|
||||
|
||||
|
||||
def _on_exit(event):
|
||||
if _STATE is not None:
|
||||
_STATE.log("inferior_exited", detail=str(event))
|
||||
|
||||
|
||||
def start_trace(log_path: str, cards_base: int):
|
||||
global _STATE
|
||||
open(log_path, "w", encoding="utf-8").close()
|
||||
_STATE = State(log_path, cards_base)
|
||||
breakpoints = {}
|
||||
for image_va, (name, pointer_reg, index_reg) in SITES.items():
|
||||
bp = PairSubmitBreakpoint(_STATE, image_va, name, pointer_reg, index_reg)
|
||||
breakpoints[name] = {"number": bp.number, "image_va": image_va}
|
||||
builder = Mode76BuilderBreakpoint(_STATE)
|
||||
breakpoints["mode76_builder"] = {"number": builder.number, "image_va": MODE76_BUILDER}
|
||||
gdb.events.exited.connect(_on_exit)
|
||||
_STATE.log(
|
||||
"trace_armed",
|
||||
breakpoints=breakpoints,
|
||||
hardware_only=True,
|
||||
client_memory_writes=False,
|
||||
)
|
||||
+29
-11
@@ -15,16 +15,27 @@ reimplementations (the `tdf` crate cloned in this scratchpad), which were used
|
||||
only as a cross-check of *structure*, never copied.
|
||||
NO EA/FIFA leaked source was consulted.
|
||||
|
||||
VALIDATED RULES (byte-exact round-trip against the 219-byte capture)
|
||||
--------------------------------------------------------------------
|
||||
Fire2 frame header, 16 bytes big-endian:
|
||||
[0:4] u32 payload length (bytes after the header)
|
||||
[4:6] u16 always 0 (observed)
|
||||
[6:8] u16 component
|
||||
[8:10] u16 command
|
||||
[10:12]u16 error / msgId
|
||||
[12] u8 msgType (0x01 ping, 0x02 request, 0x03 pong/response)
|
||||
[13:16]3 reserved bytes (observed 00 00 00)
|
||||
VALIDATED RULES (the TDF body; byte-exact round-trip against the 219-byte capture)
|
||||
---------------------------------------------------------------------------------
|
||||
Fire2 frame header, 16 bytes big-endian.
|
||||
|
||||
!!! SUPERSEDED — the [10:16] FIELD SEMANTICS below are WRONG for FIFA 17. !!!
|
||||
The "byte-exact round-trip" only proves the payload length and the TDF body
|
||||
encoding: decoding then re-encoding with the SAME (mis)labelled header layout
|
||||
trivially reproduces the capture, so it never tested the header's field
|
||||
boundaries. The authoritative, live-driven layout is
|
||||
`openfut-protocol-blaze::fire2` / `blaze_responder_v3b.py::fire2`:
|
||||
[0:4] u32 payload length (bytes after header + metadata)
|
||||
[4:6] u16 metadata length (0 when absent — what this file called "always 0")
|
||||
[6:8] u16 component
|
||||
[8:10] u16 command
|
||||
[10:13] u24 msgNum (this file WRONGLY split it as [10:12] msgId + [12] msgType)
|
||||
[13] u8 (msgType << 5) | (userIndex & 0x1F)
|
||||
[14] u8 options
|
||||
[15] u8 reserved
|
||||
There is NO error field in Fire2 (that is Fire v1) and NO jumbo escape — the
|
||||
length is already a full u32. `build_fire2_frame`/`decode_fire2` below keep the
|
||||
old wrong `>IHHHHB3s` layout; they are dead and retained only for history.
|
||||
|
||||
Heat2 field = 3-byte packed tag + 1 type byte + value.
|
||||
|
||||
@@ -359,7 +370,14 @@ MSG_ERROR = 0x05 # UNVERIFIED
|
||||
|
||||
def build_fire2_frame(component: int, command: int, msgType: int,
|
||||
msgId: int, tdf_bytes: bytes) -> bytes:
|
||||
"""16-byte big-endian Fire2 header + TDF payload."""
|
||||
"""16-byte big-endian Fire2 header + TDF payload.
|
||||
|
||||
WRONG HEADER (dead code): the ``>IHHHHB3s`` layout mislabels [10:16] — it
|
||||
puts a u16 msgId at [10:12] and msgType at [12]. FIFA 17's real Fire2 header
|
||||
is [10:13] u24 msgNum, [13] (msgType<<5)|userIndex, [14] options, [15]
|
||||
reserved, and has no error field. Use ``openfut-protocol-blaze::fire2`` or
|
||||
``blaze_responder_v3b.py::fire2``; this is retained only for history.
|
||||
"""
|
||||
tdf_bytes = bytes(tdf_bytes)
|
||||
hdr = struct.pack(">IHHHHB3s", len(tdf_bytes), 0, component & 0xFFFF,
|
||||
command & 0xFFFF, msgId & 0xFFFF, msgType & 0xFF,
|
||||
|
||||
Executable
+95
@@ -0,0 +1,95 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Find IMMEDIATE stores of a constant to a struct offset, in a live module.
|
||||
|
||||
immstore.py <imm_dec> [disp_hex|any] [--exe]
|
||||
|
||||
Only `C7 /0` (mov dword [reg+disp], imm32) can INTRODUCE a constant into a
|
||||
field; `89 /r` merely propagates one. Emits image VAs so they can be fed to
|
||||
ldis.py. Read-only.
|
||||
"""
|
||||
import glob
|
||||
import os
|
||||
import re
|
||||
import struct
|
||||
import sys
|
||||
|
||||
CARDS_IMG = 0x180000000
|
||||
EXE_IMG = 0x140000000
|
||||
|
||||
|
||||
def pid():
|
||||
for d in glob.glob("/proc/[0-9]*"):
|
||||
try:
|
||||
if open(os.path.join(d, "comm")).read().strip() == "FIFA17.exe":
|
||||
return int(os.path.basename(d))
|
||||
except OSError:
|
||||
pass
|
||||
raise SystemExit("FIFA17.exe not running")
|
||||
|
||||
|
||||
P = pid()
|
||||
|
||||
|
||||
def module_base(n):
|
||||
for l in open(f"/proc/{P}/maps"):
|
||||
if n.lower() in l.lower():
|
||||
return int(l.split("-")[0], 16)
|
||||
raise SystemExit(f"{n} not mapped")
|
||||
|
||||
|
||||
def text_spans(base):
|
||||
out = []
|
||||
started = False
|
||||
for l in open(f"/proc/{P}/maps"):
|
||||
m = re.match(r"([0-9a-f]+)-([0-9a-f]+)\s+(\S{4})\s+\S+\s+\S+\s+\S+\s*(.*)", l)
|
||||
if not m:
|
||||
continue
|
||||
lo, hi, perms, path = int(m.group(1), 16), int(m.group(2), 16), m.group(3), m.group(4)
|
||||
if lo == base:
|
||||
started = True
|
||||
continue
|
||||
if started:
|
||||
if not path.strip() and "x" in perms:
|
||||
out.append((lo, hi))
|
||||
elif out:
|
||||
break
|
||||
return out
|
||||
|
||||
|
||||
args = [a for a in sys.argv[1:] if a != "--exe"]
|
||||
exe = "--exe" in sys.argv
|
||||
imm = int(args[0], 0)
|
||||
want_disp = None if len(args) < 2 or args[1] == "any" else int(args[1], 16)
|
||||
img = EXE_IMG if exe else CARDS_IMG
|
||||
base = module_base("FIFA17.exe" if exe else "CardsDLL")
|
||||
|
||||
mem = open(f"/proc/{P}/mem", "rb", 0)
|
||||
immb = struct.pack("<i", imm)
|
||||
hits = 0
|
||||
for lo, hi in text_spans(base):
|
||||
mem.seek(lo)
|
||||
buf = mem.read(hi - lo)
|
||||
img_lo = img + (lo - base)
|
||||
i = buf.find(b"\xc7", 0)
|
||||
while i >= 0:
|
||||
modrm = buf[i + 1] if i + 1 < len(buf) else 0
|
||||
if (modrm & 0x38) == 0: # /0
|
||||
mod, rm = modrm >> 6, modrm & 7
|
||||
if mod == 1 and i + 7 <= len(buf): # disp8
|
||||
disp, ib = buf[i + 2], i + 3
|
||||
sz = 7
|
||||
elif mod == 2 and i + 10 <= len(buf): # disp32
|
||||
disp, ib = struct.unpack_from("<i", buf, i + 2)[0], i + 6
|
||||
sz = 10
|
||||
elif mod == 0 and rm not in (4, 5) and i + 6 <= len(buf):
|
||||
disp, ib = 0, i + 2
|
||||
sz = 6
|
||||
else:
|
||||
disp = None
|
||||
if disp is not None and buf[ib:ib + 4] == immb:
|
||||
if want_disp is None or disp == want_disp:
|
||||
print(f" image 0x{img_lo+i:x} mov dword [reg+0x{disp:x}], {imm} ({sz}B)")
|
||||
hits += 1
|
||||
i = buf.find(b"\xc7", i + 1)
|
||||
print(f" {hits} immediate store(s) of {imm}"
|
||||
+ (f" at +0x{want_disp:x}" if want_disp is not None else ""))
|
||||
Executable
+177
@@ -0,0 +1,177 @@
|
||||
#!/usr/bin/env python3
|
||||
# -*- coding: utf-8 -*-
|
||||
"""Settle the pre-match kit selector gate: who, if anyone, writes item `+0x60`.
|
||||
|
||||
READ-ONLY. /proc/PID/mem is opened 'rb'; there is no write path in this file.
|
||||
|
||||
WHY THIS EXISTS
|
||||
---------------
|
||||
`plan-2026-08-06-card-subsystem.md` section 5 calls `+0x60` "the single blocker
|
||||
between 'we can mark a kit equipped' and 'we can equip a kit'", and records that
|
||||
two attempts to find its writer drowned: scanning for the offset returned 1688
|
||||
and 4144 instructions depending on method.
|
||||
|
||||
The scan drowns because `+0x60` is a common struct offset. Two cheap filters cut
|
||||
it to something a person can read:
|
||||
|
||||
* only IMMEDIATE stores can introduce a constant (a register store propagates
|
||||
one from somewhere else), and
|
||||
* item-record code is recognisable by touching `+0x4c` (cardtype) or `+0x5c`
|
||||
(itemState) within a few instructions.
|
||||
|
||||
WHAT IT REPORTS
|
||||
---------------
|
||||
1. The live `+0x60` distribution over every resident CardsDb record.
|
||||
2. Every `cmp dword [reg+0x60], imm8` in CardsDLL .text -- the readers.
|
||||
3. Every immediate store to `[reg+0x60]` and the constants they use.
|
||||
4. Which of those stores sit next to item-record code.
|
||||
|
||||
MEASURED 2026-08-21 (pid 6580, 27 resident records):
|
||||
live +0x60 : {1: 23 (players), 0: 4 (staff)} -- never 4
|
||||
readers : 4 total; exactly ONE compares against 4, at 0x1801c34f2,
|
||||
which is the kit gate in FUN_1801c3480
|
||||
immediate stores: 27 total; constants {-2, 0, 1, 908, 0x3f800000} -- NO 4
|
||||
FIFA17.exe : 0 immediate stores of 4 to +0x60 across its 79MB of code,
|
||||
and 0 comparisons against 4
|
||||
gate xrefs : 1 (a jmp from 0x1801a5329); address never taken
|
||||
|
||||
The gate at 0x1801c34f2 decodes as:
|
||||
|
||||
cmp [rdi+0x4c], 7 cardtype 7 = kit/stadium/badge <- we produce this
|
||||
cmp [rdi+0x60], 4 <- THE BLOCKER
|
||||
mov eax, [rdi+0x5c] itemState
|
||||
cmp eax, 0x65 / 0x66 101 activeHomeKit / 102 activeAwayKit <- we produce
|
||||
mov r8d, [rdi+0x94] teamid <- we produce
|
||||
mov r9d, [rdi+0xba] kit variant selector (unresolved)
|
||||
|
||||
So every input EXCEPT `+0x60` is already satisfied by what OpenFUT serves, and
|
||||
no instruction in either module ever stores the constant 4 there.
|
||||
|
||||
Usage: python3 kit_gate_probe.py
|
||||
"""
|
||||
import collections
|
||||
import struct
|
||||
import sys
|
||||
|
||||
import watch_club_model as W
|
||||
|
||||
try:
|
||||
import card_identity_probe as P
|
||||
except Exception: # pragma: no cover - probe is optional for the static half
|
||||
P = None
|
||||
|
||||
TEXT_START = 0x180001000
|
||||
FIELD = 0x60
|
||||
REGS = ["rax", "rcx", "rdx", "rbx", "rsp", "rbp", "rsi", "rdi"]
|
||||
REC_SIZE = 0x158
|
||||
F_SUBTYPE = 0x50
|
||||
|
||||
|
||||
def live_distribution(mem, base):
|
||||
"""(+0x60 histogram, (subtype,+0x60) histogram) over resident records."""
|
||||
if P is None:
|
||||
return None, None
|
||||
obj = mem.q(base + (W.G_CARDSDB - W.IMG_BASE))
|
||||
if not obj:
|
||||
return None, None
|
||||
by_value = collections.Counter()
|
||||
by_pair = collections.Counter()
|
||||
for node in P.nodes(mem, obj):
|
||||
buf = mem.read(node + 0x28, REC_SIZE)
|
||||
if not buf or len(buf) < REC_SIZE:
|
||||
continue
|
||||
subtype = struct.unpack_from("<I", buf, F_SUBTYPE)[0]
|
||||
value = struct.unpack_from("<i", buf, FIELD)[0]
|
||||
by_value[value] += 1
|
||||
by_pair[(subtype, value)] += 1
|
||||
return by_value, by_pair
|
||||
|
||||
|
||||
def scan_text(text):
|
||||
"""(readers, immediate stores, item-record markers) over a .text image."""
|
||||
readers, stores, markers = [], [], set()
|
||||
for i in range(len(text) - 8):
|
||||
op, modrm = text[i], text[i + 1]
|
||||
mod, reg, rm = modrm >> 6, (modrm >> 3) & 7, modrm & 7
|
||||
if mod != 1 or rm == 4:
|
||||
continue
|
||||
disp = text[i + 2]
|
||||
if disp in (0x4C, 0x5C) and op in (0x8B, 0x89, 0x83, 0x39, 0x3B, 0xC7, 0x0F):
|
||||
markers.add(TEXT_START + i)
|
||||
if disp != FIELD:
|
||||
continue
|
||||
if op == 0x83 and reg == 7: # cmp dword [reg+0x60], imm8
|
||||
readers.append((TEXT_START + i, REGS[rm], text[i + 3]))
|
||||
elif op == 0xC7 and reg == 0: # mov dword [reg+0x60], imm32
|
||||
stores.append((TEXT_START + i, REGS[rm], struct.unpack_from("<i", text, i + 3)[0], "dword"))
|
||||
elif op == 0xC6 and reg == 0: # mov byte [reg+0x60], imm8
|
||||
stores.append((TEXT_START + i, REGS[rm], text[i + 3], "byte"))
|
||||
return readers, stores, markers
|
||||
|
||||
|
||||
def main():
|
||||
pid = W.find_pid()
|
||||
if pid is None:
|
||||
print("FIFA17.exe is not running.")
|
||||
return 1
|
||||
base = W.dll_base(pid)
|
||||
if base is None:
|
||||
print("pid %d is up but %s is not mapped." % (pid, W.DLL))
|
||||
return 1
|
||||
mem = W.Mem(pid)
|
||||
|
||||
print("pid=%d %s base=%#x" % (pid, W.DLL, base))
|
||||
print()
|
||||
|
||||
by_value, by_pair = live_distribution(mem, base)
|
||||
print("── live records ──")
|
||||
if by_value is None:
|
||||
print(" CardsDb is empty (no FUT session loaded); static half still runs.")
|
||||
else:
|
||||
print(" +0x60 distribution : %s" % dict(by_value))
|
||||
print(" (cardsubtypeid, +0x60) : %s" % dict(by_pair))
|
||||
print(" holds the gate value 4 : %s" % ("YES" if 4 in by_value else "NO"))
|
||||
print()
|
||||
|
||||
# .text is the second CardsDLL mapping; read it whole and scan.
|
||||
size = 0x1E4000
|
||||
buf, bad = mem.read_pages(base + 0x1000, size)
|
||||
if bad:
|
||||
print(" WARNING: %d unreadable page(s); the scan is incomplete." % len(bad))
|
||||
text = bytes(buf)
|
||||
|
||||
readers, stores, markers = scan_text(text)
|
||||
print("── readers: cmp dword [reg+0x60], imm8 ──")
|
||||
for va, reg, imm in readers:
|
||||
flag = " <-- THE KIT GATE" if imm == 4 else ""
|
||||
print(" %#x cmp [%s+0x60], %d%s" % (va, reg, imm, flag))
|
||||
print()
|
||||
|
||||
print("── immediate stores to [reg+0x60] ──")
|
||||
consts = collections.Counter(s[2] for s in stores)
|
||||
print(" %d store(s); constants %s" % (len(stores), dict(sorted(consts.items()))))
|
||||
near = [s for s in stores if any(abs(m - s[0]) <= 96 for m in markers)]
|
||||
print(" %d of them sit within 96B of item-record code (+0x4c/+0x5c):" % len(near))
|
||||
for va, reg, imm, width in near:
|
||||
print(" %#x mov %s [%s+0x60], %d" % (va, width, reg, imm))
|
||||
print()
|
||||
|
||||
print("=" * 70)
|
||||
if any(s[2] == 4 for s in stores):
|
||||
print("A store of 4 EXISTS -- the gate is reachable. Follow the sites above.")
|
||||
return 0
|
||||
print("NO instruction in CardsDLL stores the constant 4 into +0x60.")
|
||||
print("Combined with the live records (never 4) and the fact that every OTHER")
|
||||
print("gate input is already served, the pre-match kit selector cannot be")
|
||||
print("opened by anything the server sends. This is a CLIENT-side dead end,")
|
||||
print("not a missing wire field.")
|
||||
print()
|
||||
print("Scope of the claim: immediate stores, all widths, disp8 form. A value")
|
||||
print("could still arrive by register copy -- but in CardsDLL every register")
|
||||
print("store to +0x60 is a field-by-field struct copy or an init to 0/1/-2.")
|
||||
print("=" * 70)
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Executable
+94
@@ -0,0 +1,94 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Read-only live disassembler for the FIFA17 client (CardsDLL / FIFA17.exe).
|
||||
|
||||
ldis.py <image_va_hex> [nbytes] [--exe] disassemble
|
||||
ldis.py --bytes <image_va_hex> [nbytes] hexdump
|
||||
ldis.py --map show module bases
|
||||
|
||||
CardsDLL image base 0x180000000; FIFA17.exe image base 0x140000000.
|
||||
Live address = module_base + (image_va - img_base). Sections map 1:1 for both,
|
||||
but this is recomputed and printed so the offset trap stays visible.
|
||||
"""
|
||||
import re
|
||||
import subprocess
|
||||
import sys
|
||||
import tempfile
|
||||
|
||||
PID = None
|
||||
CARDS_IMG = 0x180000000
|
||||
EXE_IMG = 0x140000000
|
||||
|
||||
|
||||
def pid():
|
||||
global PID
|
||||
if PID is None:
|
||||
import glob, os
|
||||
for d in glob.glob("/proc/[0-9]*"):
|
||||
try:
|
||||
if open(os.path.join(d, "comm")).read().strip() == "FIFA17.exe":
|
||||
PID = int(os.path.basename(d))
|
||||
break
|
||||
except OSError:
|
||||
pass
|
||||
if PID is None:
|
||||
raise SystemExit("FIFA17.exe not running")
|
||||
return PID
|
||||
|
||||
|
||||
def module_base(needle):
|
||||
"""Base = the NAMED PE-header mapping for the module (Wine maps the rest
|
||||
anonymously, so never trust the mapping that merely CONTAINS an address)."""
|
||||
for l in open(f"/proc/{pid()}/maps"):
|
||||
if needle.lower() in l.lower():
|
||||
return int(l.split("-")[0], 16)
|
||||
raise SystemExit(f"module {needle} not mapped")
|
||||
|
||||
|
||||
def live(va, exe=False):
|
||||
if exe:
|
||||
return module_base("FIFA17.exe") + (va - EXE_IMG)
|
||||
return module_base("CardsDLL") + (va - CARDS_IMG)
|
||||
|
||||
|
||||
def read(va, n, exe=False):
|
||||
la = live(va, exe)
|
||||
with open(f"/proc/{pid()}/mem", "rb", 0) as m:
|
||||
m.seek(la)
|
||||
return la, m.read(n)
|
||||
|
||||
|
||||
def main():
|
||||
a = sys.argv[1:]
|
||||
if not a or a[0] == "--map":
|
||||
print(f" pid = {pid()}")
|
||||
print(f" CardsDLL = 0x{module_base('CardsDLL'):x} (image 0x{CARDS_IMG:x})")
|
||||
print(f" FIFA17.exe = 0x{module_base('FIFA17.exe'):x} (image 0x{EXE_IMG:x})")
|
||||
return
|
||||
hexdump = a[0] == "--bytes"
|
||||
if hexdump:
|
||||
a = a[1:]
|
||||
exe = "--exe" in a
|
||||
a = [x for x in a if x != "--exe"]
|
||||
va = int(a[0], 16)
|
||||
n = int(a[1]) if len(a) > 1 else 160
|
||||
la, buf = read(va, n, exe)
|
||||
print(f" image 0x{va:x} -> live 0x{la:x} ({len(buf)} bytes)")
|
||||
if hexdump:
|
||||
for i in range(0, len(buf), 16):
|
||||
c = buf[i:i + 16]
|
||||
print(f" 0x{va+i:x}: {' '.join(f'{b:02x}' for b in c):<47} "
|
||||
+ "".join(chr(b) if 32 <= b < 127 else "." for b in c))
|
||||
return
|
||||
with tempfile.NamedTemporaryFile(suffix=".bin") as f:
|
||||
f.write(buf)
|
||||
f.flush()
|
||||
out = subprocess.run(
|
||||
["objdump", "-D", "-b", "binary", "-m", "i386:x86-64", "-M", "intel",
|
||||
f"--adjust-vma=0x{va:x}", f.name],
|
||||
capture_output=True, text=True).stdout
|
||||
for line in out.splitlines():
|
||||
if re.match(r"\s+[0-9a-f]+:", line):
|
||||
print(" " + line.strip())
|
||||
|
||||
|
||||
main()
|
||||
Executable
+114
@@ -0,0 +1,114 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Read-only census of FIFA 17's RESIDENT club-item vector.
|
||||
|
||||
Chain, every link from CardsDLL static RE:
|
||||
[CardsDLL+0x2e6398] -> owner object (FUN_18011a830)
|
||||
owner->vtable[0x4e8] -> getter returning mgr (call *0x4e8(%rdx))
|
||||
mgr+0x108 .. mgr+0x110 -> club-item vector, stride 24
|
||||
element+0x10 -> the item record pointer (FUN_1800d73d0)
|
||||
record+0x4c cardtype (derived from cardsubtypeid by FUN_1800d8330: 9/10/11 -> 7)
|
||||
record+0x50 cardsubtypeid
|
||||
record+0x5c itemState (101 activeHomeKit, 102 activeAwayKit)
|
||||
record+0x60 category (clone driver FUN_1801c3480 requires 4)
|
||||
record+0x94 teamid
|
||||
record+0xba teamkittypetechid (u16)
|
||||
Offsets not in that list are labelled UNVERIFIED and only dumped raw.
|
||||
No writes. Ever.
|
||||
"""
|
||||
import re, struct, sys, collections
|
||||
|
||||
PID = int(sys.argv[1]) if len(sys.argv) > 1 else 44405
|
||||
mem = open(f"/proc/{PID}/mem", "rb", buffering=0)
|
||||
|
||||
def rd(a, n):
|
||||
mem.seek(a); return mem.read(n)
|
||||
def q(a):
|
||||
return struct.unpack("<Q", rd(a, 8))[0]
|
||||
def i32(b, o):
|
||||
return struct.unpack_from("<i", b, o)[0]
|
||||
|
||||
# locate CardsDLL by its NEAREST PRECEDING NAMED mapping (Wine maps PE sections anon)
|
||||
named = []
|
||||
for ln in open(f"/proc/{PID}/maps"):
|
||||
m = re.match(r"([0-9a-f]+)-([0-9a-f]+) \S{4} \S+ \S+ \S+\s+(.+)", ln)
|
||||
if m: named.append((int(m.group(1),16), m.group(3).strip()))
|
||||
named.sort()
|
||||
base = None
|
||||
for s, p in named:
|
||||
if p.endswith("CardsDLL_Win64_retail.dll"):
|
||||
base = s; break
|
||||
if base is None:
|
||||
print(" CardsDLL mapping not found"); sys.exit(1)
|
||||
print(f" CardsDLL base = {base:#x}")
|
||||
def live(static): return base + (static - 0x180000000)
|
||||
|
||||
# sanity: the 0x7575 sender immediate must be where static RE says
|
||||
probe = rd(live(0x180026fea), 6)
|
||||
print(f" sanity @0x180026fea: {probe.hex(' ')} (expect ba 75 75 00 00)")
|
||||
if probe[:5] != bytes.fromhex("ba75750000"):
|
||||
print(" SANITY FAILED - base wrong, aborting"); sys.exit(1)
|
||||
|
||||
owner = q(live(0x1802e6398))
|
||||
print(f" owner object = {owner:#x}")
|
||||
vt = q(owner)
|
||||
getter = q(vt + 0x4e8)
|
||||
print(f" vtable = {vt:#x}")
|
||||
print(f" vtable[0x4e8] = {getter:#x} bytes: {rd(getter,12).hex(' ')}")
|
||||
# expect: mov rax,[rcx+off] ; ret -> 48 8b 81 off32 c3 or 48 8b 41 off8 c3
|
||||
b = rd(getter, 12)
|
||||
mgr = None
|
||||
if b[0:3] == bytes.fromhex("488d81"):
|
||||
off = struct.unpack_from("<I", b, 3)[0]; mgr = owner + off
|
||||
print(f" getter returns owner+{off:#x} (EMBEDDED subobject) -> mgr = {mgr:#x}")
|
||||
elif b[0:3] == bytes.fromhex("488d41"):
|
||||
off = b[3]; mgr = owner + off
|
||||
print(f" getter returns owner+{off:#x} (EMBEDDED subobject) -> mgr = {mgr:#x}")
|
||||
elif b[0:3] == bytes.fromhex("488b81"):
|
||||
off = struct.unpack_from("<I", b, 3)[0]; mgr = q(owner + off)
|
||||
print(f" getter returns [owner+{off:#x}] -> mgr = {mgr:#x}")
|
||||
elif b[0:3] == bytes.fromhex("488b41"):
|
||||
off = b[3]; mgr = q(owner + off)
|
||||
print(f" getter returns [owner+{off:#x}] -> mgr = {mgr:#x}")
|
||||
elif b[0:2] == bytes.fromhex("488b") and b[2] == 0xc1:
|
||||
mgr = owner; print(" getter returns owner itself")
|
||||
else:
|
||||
print(" getter shape unrecognised; trying owner as mgr")
|
||||
mgr = owner
|
||||
|
||||
for label, mgr_try in (("resolved", mgr), ("owner", owner)):
|
||||
try:
|
||||
beg, end = q(mgr_try + 0x108), q(mgr_try + 0x110)
|
||||
except OSError:
|
||||
print(f" [{label}] +0x108/0x110 unreadable"); continue
|
||||
if not (0 < beg <= end) or (end - beg) % 24 or (end - beg) > 24*100000:
|
||||
print(f" [{label}] vector implausible: {beg:#x}..{end:#x}")
|
||||
continue
|
||||
n = (end - beg) // 24
|
||||
print(f"\n === club-item vector via {label}: {beg:#x}..{end:#x} {n} slot(s) ===")
|
||||
hist = collections.Counter(); rows = []
|
||||
for k in range(n):
|
||||
try:
|
||||
rec = q(beg + k*24 + 0x10)
|
||||
except OSError:
|
||||
continue
|
||||
if not rec:
|
||||
hist[("<null slot>", None)] += 1; continue
|
||||
try:
|
||||
r = rd(rec, 0xC0)
|
||||
except OSError:
|
||||
continue
|
||||
if len(r) < 0xC0: continue
|
||||
ct, sub, st, cat = i32(r,0x4c), i32(r,0x50), i32(r,0x5c), i32(r,0x60)
|
||||
team = i32(r,0x94); kt = struct.unpack_from("<H", r, 0xba)[0]
|
||||
hist[(ct, sub)] += 1
|
||||
rows.append((rec, ct, sub, st, cat, team, kt))
|
||||
print(f" (cardtype, cardsubtypeid) histogram:")
|
||||
for key, c in sorted(hist.items(), key=lambda x: -x[1]):
|
||||
tag = " <== KIT (selector needs this)" if key == (7, 9) else ""
|
||||
print(f" {str(key):<18} x{c}{tag}")
|
||||
print(f" cardtype 7 records: {sum(c for (ct,_),c in hist.items() if ct==7)}")
|
||||
print(f"\n first 12 records:")
|
||||
print(f" {'ptr':>14} {'ctype':>5} {'subtype':>7} {'state':>5} {'cat':>4} {'team':>5} {'kittype':>7}")
|
||||
for rec, ct, sub, st, cat, team, kt in rows[:12]:
|
||||
print(f" {rec:#14x} {ct:>5} {sub:>7} {st:>5} {cat:>4} {team:>5} {kt:>7}")
|
||||
break
|
||||
Executable
+137
@@ -0,0 +1,137 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Byte-level diff of the two resident kit records in a live FIFA17 client.
|
||||
|
||||
The pre-match selector draws each kit from a clone query keyed on the record's
|
||||
own fields, so if both tiles render identically the question is precisely: which
|
||||
bytes of the home record differ from the away record? This prints every differing
|
||||
offset with the known field names attached, and dumps the fields the decoded
|
||||
clone query consumes.
|
||||
|
||||
Read-only. Never writes to the process.
|
||||
|
||||
Decoded query (FUN_1801c3480 -> FUN_1801c44b0):
|
||||
teamtechid == record+0x94
|
||||
teamkittypetechid == derived from itemState (101 -> 0 home, 102 -> 1 away)
|
||||
year == record+0xba
|
||||
"""
|
||||
import re
|
||||
import struct
|
||||
import sys
|
||||
|
||||
PID = int(sys.argv[1])
|
||||
WANT = [int(a) for a in sys.argv[2:]] or [100004874, 100004873]
|
||||
|
||||
mem = open(f"/proc/{PID}/mem", "rb", buffering=0)
|
||||
|
||||
|
||||
def rd(a, n):
|
||||
mem.seek(a)
|
||||
return mem.read(n)
|
||||
|
||||
|
||||
def q(a):
|
||||
return struct.unpack("<Q", rd(a, 8))[0]
|
||||
|
||||
|
||||
named = []
|
||||
for ln in open(f"/proc/{PID}/maps"):
|
||||
m = re.match(r"([0-9a-f]+)-([0-9a-f]+) \S{4} \S+ \S+ \S+\s+(.+)", ln)
|
||||
if m:
|
||||
named.append((int(m.group(1), 16), m.group(3).strip()))
|
||||
named.sort()
|
||||
base = next((s for s, p in named if p.endswith("CardsDLL_Win64_retail.dll")), None)
|
||||
if base is None:
|
||||
sys.exit("CardsDLL mapping not found")
|
||||
|
||||
|
||||
def live(static):
|
||||
return base + (static - 0x180000000)
|
||||
|
||||
|
||||
if rd(live(0x180026FEA), 5) != bytes.fromhex("ba75750000"):
|
||||
sys.exit("SANITY FAILED - wrong base")
|
||||
print(f" CardsDLL base = {base:#x} (sanity ok)")
|
||||
|
||||
owner = q(live(0x1802E6398))
|
||||
sentinel = owner + 0x160C8
|
||||
root = q(owner + 0x160D8)
|
||||
|
||||
# Known record fields, offset -> (name, width)
|
||||
FIELDS = {
|
||||
0x08: ("id", 8),
|
||||
0x18: ("resourceId/definitionId", 4),
|
||||
# Offsets per club_items.json `_record_map`, which is authoritative:
|
||||
# cardassetid is +0x1c and assetId is +0x20 — NOT the other way round.
|
||||
0x1C: ("cardassetid", 4),
|
||||
0x20: ("assetId", 4),
|
||||
0x38: ("discardValue", 4),
|
||||
0x4C: ("cardtype", 4),
|
||||
0x50: ("cardsubtypeid", 4),
|
||||
0x5C: ("itemState", 4),
|
||||
0x60: ("category(club slot)", 4),
|
||||
0x8C: ("contract", 4),
|
||||
0x94: ("teamid", 4),
|
||||
0xB4: ("rating", 4),
|
||||
0xB8: ("wire category", 1),
|
||||
0xBA: ("year", 2),
|
||||
0x148: ("nation", 4),
|
||||
0x154: ("leagueId", 4),
|
||||
}
|
||||
|
||||
|
||||
def walk(node, out):
|
||||
if not node or node == sentinel:
|
||||
return
|
||||
walk(q(node + 0x00), out)
|
||||
# The record is EMBEDDED at node+0x28 — NOT a pointer stored there.
|
||||
out.append((struct.unpack("<q", rd(node + 0x20, 8))[0], node + 0x28))
|
||||
walk(q(node + 0x08), out)
|
||||
|
||||
|
||||
nodes = []
|
||||
walk(root, nodes)
|
||||
recs = {k: v for k, v in nodes}
|
||||
|
||||
found = [(w, recs[w]) for w in WANT if w in recs]
|
||||
if len(found) < 2:
|
||||
sys.exit(f" need two resident kit records, found {[w for w, _ in found]}")
|
||||
|
||||
(id_a, ptr_a), (id_b, ptr_b) = found[0], found[1]
|
||||
a = rd(ptr_a, 0x180)
|
||||
b = rd(ptr_b, 0x180)
|
||||
print(f" A = {id_a} @ {ptr_a:#x}")
|
||||
print(f" B = {id_b} @ {ptr_b:#x}")
|
||||
|
||||
print("\n --- fields the clone query consumes ---")
|
||||
for off in (0x94, 0x5C, 0xBA):
|
||||
name = FIELDS[off][0]
|
||||
w = FIELDS[off][1]
|
||||
va = int.from_bytes(a[off : off + w], "little")
|
||||
vb = int.from_bytes(b[off : off + w], "little")
|
||||
flag = "" if va != vb else " <== IDENTICAL"
|
||||
print(f" +{off:#05x} {name:24} A={va:<12} B={vb:<12}{flag}")
|
||||
|
||||
print("\n --- every differing byte range ---")
|
||||
diffs = [i for i in range(0x180) if a[i] != b[i]]
|
||||
runs = []
|
||||
for i in diffs:
|
||||
if runs and i == runs[-1][1] + 1:
|
||||
runs[-1][1] = i
|
||||
else:
|
||||
runs.append([i, i])
|
||||
for s, e in runs:
|
||||
named_field = next(
|
||||
(n for o, (n, w) in FIELDS.items() if o <= s < o + w), "(unmapped)"
|
||||
)
|
||||
va = int.from_bytes(a[s : e + 1], "little")
|
||||
vb = int.from_bytes(b[s : e + 1], "little")
|
||||
print(f" +{s:#05x}..{e:#05x} {named_field:24} A={va:<12} B={vb}")
|
||||
print(f"\n {len(diffs)} differing bytes in {len(runs)} runs")
|
||||
|
||||
print("\n --- known fields, side by side ---")
|
||||
for off in sorted(FIELDS):
|
||||
name, w = FIELDS[off]
|
||||
va = int.from_bytes(a[off : off + w], "little")
|
||||
vb = int.from_bytes(b[off : off + w], "little")
|
||||
mark = " DIFFERS" if va != vb else ""
|
||||
print(f" +{off:#05x} {name:24} A={va:<12} B={vb:<12}{mark}")
|
||||
Executable
+58
@@ -0,0 +1,58 @@
|
||||
#!/bin/sh
|
||||
# Remove the port-8081 DNAT rule that hijacks FIFA 17's roster/squad-update TLS.
|
||||
#
|
||||
# Why: the FUT squad update is https://winter15.gosredirector.ea.com:8081/fifa17/fut/rosterupdate.xml
|
||||
# (TLS on port 8081). A DNAT rule rewriting dport 8081 -> 8299 sends that TLS
|
||||
# handshake to the plain-HTTP staging UTAS host, which closes the connection.
|
||||
# Proven: a probe to 10.10.0.120:8081 from this box arrives at the server as
|
||||
# dport 8299. Result: "An error occurred downloading the FUT squad update."
|
||||
#
|
||||
# The rule also never redirected UTAS, which lives on :8443, not :8081.
|
||||
#
|
||||
# Read-only until it deletes; deletes only nat rules whose target port is 8299.
|
||||
set -u
|
||||
|
||||
echo "== nat OUTPUT rules mentioning 8081 or 8299 =="
|
||||
iptables -t nat -S OUTPUT 2>/dev/null | grep -E '8081|8299' || echo " (none)"
|
||||
|
||||
echo
|
||||
echo "== deleting DNAT rules that redirect to port 8299 =="
|
||||
removed=0
|
||||
# Delete by spec, repeatedly, until no matching rule remains.
|
||||
while :; do
|
||||
rule=$(iptables -t nat -S OUTPUT 2>/dev/null | grep -m1 -E '\-\-dport 8081 .*8299|to-destination [0-9.]+:8299')
|
||||
[ -z "$rule" ] && break
|
||||
spec=$(printf '%s' "$rule" | sed 's/^-A /-D /')
|
||||
# shellcheck disable=SC2086
|
||||
if iptables -t nat $spec 2>/dev/null; then
|
||||
echo " removed: $rule"
|
||||
removed=$((removed + 1))
|
||||
else
|
||||
echo " FAILED to remove: $rule" >&2
|
||||
break
|
||||
fi
|
||||
done
|
||||
[ "$removed" -eq 0 ] && echo " (no matching rule found)"
|
||||
|
||||
echo
|
||||
echo "== remaining nat OUTPUT rules mentioning 8081 or 8299 =="
|
||||
iptables -t nat -S OUTPUT 2>/dev/null | grep -E '8081|8299' || echo " (none)"
|
||||
|
||||
echo
|
||||
echo "== verifying the roster endpoint now presents the correct certificate =="
|
||||
python3 - <<'PY'
|
||||
import socket, ssl
|
||||
host, port, sni = "10.10.0.120", 8081, "winter15.gosredirector.ea.com"
|
||||
try:
|
||||
ctx = ssl.SSLContext(ssl.PROTOCOL_TLS_CLIENT)
|
||||
ctx.check_hostname = False
|
||||
ctx.verify_mode = ssl.CERT_NONE
|
||||
with socket.create_connection((host, port), 8) as s:
|
||||
with ctx.wrap_socket(s, server_hostname=sni) as t:
|
||||
der = t.getpeercert(True)
|
||||
cn = dict(x[0] for x in t.getpeercert().get("subject", ()))
|
||||
print(f" PASS {host}:{port} sni={sni} {t.version()} der={len(der)}B subject={cn}")
|
||||
except Exception as e:
|
||||
print(f" FAIL {host}:{port} sni={sni} -> {type(e).__name__}: {e}")
|
||||
print(" The roster path is still broken; do not relaunch yet.")
|
||||
PY
|
||||
Executable
+84
@@ -0,0 +1,84 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Hunt for specific wire instance ids anywhere in the client's writable memory.
|
||||
|
||||
Answers whether a served item was materialised into a record at all, versus
|
||||
materialised but not attached to a collection. A record is recognised by its
|
||||
established layout: id at +0x08, resourceId at +0x18, cardtype at +0x4c.
|
||||
|
||||
Read-only. Never writes.
|
||||
|
||||
usage: probe_hunt.py PID id [id ...]
|
||||
"""
|
||||
import re, struct, sys
|
||||
|
||||
PID = int(sys.argv[1])
|
||||
IDS = [int(a) for a in sys.argv[2:]]
|
||||
if not IDS:
|
||||
sys.exit("give at least one wire id")
|
||||
mem = open(f"/proc/{PID}/mem", "rb", buffering=0)
|
||||
|
||||
regions = []
|
||||
for ln in open(f"/proc/{PID}/maps"):
|
||||
m = re.match(r"([0-9a-f]+)-([0-9a-f]+) (\S{4}) \S+ \S+ \S+\s*(.*)", ln)
|
||||
if not m:
|
||||
continue
|
||||
lo, hi, perms, path = int(m.group(1), 16), int(m.group(2), 16), m.group(3), m.group(4).strip()
|
||||
if "w" not in perms:
|
||||
continue
|
||||
if path.startswith("/") and not path.endswith(".dll") and not path.endswith(".exe"):
|
||||
continue
|
||||
regions.append((lo, hi, perms, path))
|
||||
total = sum(hi - lo for lo, hi, _, _ in regions)
|
||||
print(f" {len(regions)} writable regions, {total/2**20:.0f} MiB to scan")
|
||||
|
||||
needles = {struct.pack("<I", i): i for i in IDS}
|
||||
hits = {i: [] for i in IDS}
|
||||
CHUNK = 8 << 20
|
||||
scanned = 0
|
||||
for lo, hi, perms, path in regions:
|
||||
a = lo
|
||||
while a < hi:
|
||||
n = min(CHUNK, hi - a)
|
||||
try:
|
||||
mem.seek(a)
|
||||
data = mem.read(n)
|
||||
except OSError:
|
||||
a += n
|
||||
continue
|
||||
if not data:
|
||||
a += n
|
||||
continue
|
||||
scanned += len(data)
|
||||
for nd, wid in needles.items():
|
||||
start = 0
|
||||
while True:
|
||||
j = data.find(nd, start)
|
||||
if j < 0:
|
||||
break
|
||||
start = j + 1
|
||||
va = a + j
|
||||
# a record would place this id at +0x08
|
||||
rec = va - 0x08
|
||||
try:
|
||||
mem.seek(rec)
|
||||
r = mem.read(0x100)
|
||||
except OSError:
|
||||
continue
|
||||
if len(r) < 0x100:
|
||||
continue
|
||||
ct = struct.unpack_from("<i", r, 0x4c)[0]
|
||||
res = struct.unpack_from("<I", r, 0x18)[0]
|
||||
sub = struct.unpack_from("<i", r, 0x50)[0]
|
||||
cat = struct.unpack_from("<i", r, 0x60)[0]
|
||||
looks = 0 <= ct <= 32 and res > 1000
|
||||
hits[wid].append((va, rec, ct, sub, cat, res, looks))
|
||||
a += n
|
||||
print(f" scanned {scanned/2**20:.0f} MiB\n")
|
||||
for wid in IDS:
|
||||
hs = hits[wid]
|
||||
recs = [h for h in hs if h[6]]
|
||||
print(f" id {wid}: {len(hs)} raw occurrence(s), {len(recs)} record-shaped")
|
||||
for va, rec, ct, sub, cat, res, _ in recs[:6]:
|
||||
print(f" record {rec:#x}: cardtype={ct} subtype={sub} category={cat} resourceId={res}")
|
||||
if not recs:
|
||||
print(" NOT MATERIALISED as a record anywhere in writable memory")
|
||||
Executable
+92
@@ -0,0 +1,92 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Identify every resident record by its wire instance id.
|
||||
|
||||
Record layout established from known wire values:
|
||||
+0x08 id (wire instance) +0x18 resourceId +0x1c/+0x20 assetId
|
||||
+0x38 discardValue +0x4c cardtype +0x50 cardsubtypeid
|
||||
+0x5c itemState +0x60 category +0x94 teamid
|
||||
+0xb4 rating +0xba teamkittypetechid (u16)
|
||||
|
||||
Walks the contiguous 0x180-stride pool around the manager slot record so records
|
||||
that are resident but not in any collection are still seen. Read-only.
|
||||
|
||||
usage: probe_ids.py PID [expected_id ...]
|
||||
"""
|
||||
import re, struct, sys
|
||||
|
||||
PID = int(sys.argv[1])
|
||||
WANT = {int(a) for a in sys.argv[2:]}
|
||||
mem = open(f"/proc/{PID}/mem", "rb", buffering=0)
|
||||
|
||||
def rd(a, n):
|
||||
mem.seek(a); return mem.read(n)
|
||||
def q(a):
|
||||
return struct.unpack("<Q", rd(a, 8))[0]
|
||||
|
||||
named = []
|
||||
for ln in open(f"/proc/{PID}/maps"):
|
||||
m = re.match(r"([0-9a-f]+)-([0-9a-f]+) \S{4} \S+ \S+ \S+\s+(.+)", ln)
|
||||
if m:
|
||||
named.append((int(m.group(1), 16), m.group(3).strip()))
|
||||
named.sort()
|
||||
base = next(s for s, p in named if p.endswith("CardsDLL_Win64_retail.dll"))
|
||||
live = lambda s: base + (s - 0x180000000)
|
||||
if rd(live(0x180026fea), 5) != bytes.fromhex("ba75750000"):
|
||||
sys.exit("SANITY FAILED")
|
||||
owner = q(live(0x1802e6398))
|
||||
mgr = owner + 0x1f9d8
|
||||
RECSZ = 0x180
|
||||
|
||||
def dec(rec):
|
||||
r = rd(rec, 0x180)
|
||||
g = lambda o: struct.unpack_from("<i", r, o)[0]
|
||||
return dict(id=struct.unpack_from("<I", r, 0x8)[0], res=struct.unpack_from("<I", r, 0x18)[0],
|
||||
ct=g(0x4c), sub=g(0x50), st=g(0x5c), cat=g(0x60), team=g(0x94),
|
||||
rating=struct.unpack_from("<I", r, 0xb4)[0],
|
||||
kt=struct.unpack_from("<H", r, 0xba)[0])
|
||||
|
||||
mgr_rec = q(mgr + 0xc0 + 0x10)
|
||||
print(f" manager-slot record = {mgr_rec:#x}")
|
||||
anchor = mgr_rec if mgr_rec else q(q(mgr + 0xd8) + 0x10)
|
||||
|
||||
# walk backwards to the start of the contiguous run, then forwards
|
||||
lo = anchor
|
||||
for _ in range(64):
|
||||
prev = lo - RECSZ
|
||||
try:
|
||||
d = dec(prev)
|
||||
except OSError:
|
||||
break
|
||||
if not (0 < d["ct"] < 64) or d["id"] == 0:
|
||||
break
|
||||
lo = prev
|
||||
|
||||
print(f" pool run starts at {lo:#x}\n")
|
||||
print(f" {'idx':>3} {'addr':>12} {'id':>10} {'resource':>9} {'ct':>3} {'sub':>4} "
|
||||
f"{'st':>3} {'cat':>4} {'team':>5} {'rate':>5} {'kt':>6}")
|
||||
found = {}
|
||||
k = 0
|
||||
addr = lo
|
||||
while k < 48:
|
||||
try:
|
||||
d = dec(addr)
|
||||
except OSError:
|
||||
break
|
||||
if d["id"] == 0 and d["ct"] == 0:
|
||||
break
|
||||
tag = ""
|
||||
if d["ct"] == 7:
|
||||
tag = " <== CARDTYPE 7"
|
||||
if d["id"] in WANT:
|
||||
tag += " <== WANTED"
|
||||
found[d["id"]] = addr
|
||||
slot = " [manager slot]" if addr == mgr_rec else ""
|
||||
print(f" {k:>3} {addr:#12x} {d['id']:>10} {d['res']:>9} {d['ct']:>3} {d['sub']:>4} "
|
||||
f"{d['st']:>3} {d['cat']:>4} {d['team']:>5} {d['rating']:>5} {d['kt']:>6}{tag}{slot}")
|
||||
addr += RECSZ
|
||||
k += 1
|
||||
|
||||
if WANT:
|
||||
print(f"\n wanted ids: {sorted(WANT)}")
|
||||
for w in sorted(WANT):
|
||||
print(f" {w}: {'FOUND at ' + hex(found[w]) if w in found else 'NOT RESIDENT'}")
|
||||
Executable
+95
@@ -0,0 +1,95 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Map FIFA 17 resident record offsets using UNIQUE wire values as ground truth.
|
||||
|
||||
v2: identifies each record by its wire instance id (large, unique) and only
|
||||
accepts a field mapping when the value is distinctive (>= 16) and the same
|
||||
offset holds the right value for EVERY identified record. This avoids the v1
|
||||
failure where cardsubtypeid == 0 matched every zeroed field in the struct.
|
||||
|
||||
Read-only. Never writes.
|
||||
|
||||
usage: probe_layout2.py PID squad_active.json
|
||||
"""
|
||||
import re, struct, sys, json, collections
|
||||
|
||||
PID = int(sys.argv[1])
|
||||
SQUAD = json.load(open(sys.argv[2]))
|
||||
mem = open(f"/proc/{PID}/mem", "rb", buffering=0)
|
||||
|
||||
def rd(a, n):
|
||||
mem.seek(a); return mem.read(n)
|
||||
def q(a):
|
||||
return struct.unpack("<Q", rd(a, 8))[0]
|
||||
|
||||
named = []
|
||||
for ln in open(f"/proc/{PID}/maps"):
|
||||
m = re.match(r"([0-9a-f]+)-([0-9a-f]+) \S{4} \S+ \S+ \S+\s+(.+)", ln)
|
||||
if m:
|
||||
named.append((int(m.group(1), 16), m.group(3).strip()))
|
||||
named.sort()
|
||||
base = next(s for s, p in named if p.endswith("CardsDLL_Win64_retail.dll"))
|
||||
live = lambda s: base + (s - 0x180000000)
|
||||
if rd(live(0x180026fea), 5) != bytes.fromhex("ba75750000"):
|
||||
sys.exit("SANITY FAILED")
|
||||
owner = q(live(0x1802e6398))
|
||||
mgr = owner + 0x1f9d8
|
||||
RECSZ = 0x180
|
||||
|
||||
beg, end = q(mgr + 0xd8), q(mgr + 0xe0)
|
||||
recs = [r for r in (q(beg + k*24 + 0x10) for k in range((end - beg)//24)) if r]
|
||||
|
||||
wire = {}
|
||||
for p in SQUAD["players"]:
|
||||
it = p.get("itemData") or {}
|
||||
if it.get("id"):
|
||||
wire[it["id"]] = it
|
||||
|
||||
# --- identify each record by its wire instance id ---
|
||||
ident = {}
|
||||
for rec in recs:
|
||||
r = rd(rec, RECSZ)
|
||||
for off in range(0, RECSZ - 4, 4):
|
||||
v = struct.unpack_from("<I", r, off)[0]
|
||||
if v in wire:
|
||||
ident.setdefault(rec, (v, off))
|
||||
break
|
||||
print(f" resident player records: {len(recs)}, identified: {len(ident)}")
|
||||
id_offs = collections.Counter(o for _, o in ident.values())
|
||||
print(f" wire-id offset candidates: {[(hex(o), c) for o, c in id_offs.most_common()]}")
|
||||
|
||||
FIELDS = ("id", "resourceId", "assetId", "definitionId", "cardassetid", "rating",
|
||||
"teamid", "nation", "leagueId", "contract", "fitness", "playStyle",
|
||||
"discardValue", "cardsubtypeid", "owners", "rareflag")
|
||||
# --- for every offset, does it hold field F for every identified record? ---
|
||||
consistent = {}
|
||||
for off in range(0, RECSZ - 4, 4):
|
||||
for f in FIELDS:
|
||||
ok = 0; total = 0; distinct = set()
|
||||
for rec, (wid, _) in ident.items():
|
||||
it = wire[wid]
|
||||
v = it.get(f)
|
||||
if not isinstance(v, int) or v < 16: # require distinctive values
|
||||
continue
|
||||
total += 1
|
||||
got = struct.unpack_from("<I", rd(rec, RECSZ), off)[0]
|
||||
if got == v:
|
||||
ok += 1; distinct.add(v)
|
||||
if total >= 5 and ok == total and len(distinct) >= 2:
|
||||
consistent.setdefault(off, []).append((f, total, len(distinct)))
|
||||
|
||||
print(f"\n === offsets consistently holding a distinctive wire field ===")
|
||||
for off in sorted(consistent):
|
||||
for f, total, nd in consistent[off]:
|
||||
print(f" +0x{off:<4x} {f:14s} (matched {total}/{total} records, {nd} distinct values)")
|
||||
|
||||
# --- dump the manager and the three club staff for comparison ---
|
||||
print(f"\n === cardtype-2 slot (manager) ===")
|
||||
h = q(mgr + 0xc0 + 0x10)
|
||||
if h:
|
||||
r = rd(h, RECSZ)
|
||||
for off in sorted(consistent):
|
||||
f = consistent[off][0][0]
|
||||
print(f" +0x{off:<4x} {f:14s} = {struct.unpack_from('<I', r, off)[0]}")
|
||||
for name, off, sz in (("cardtype", 0x4c, 4), ("cardsubtypeid", 0x50, 4),
|
||||
("itemState", 0x5c, 4), ("category", 0x60, 4)):
|
||||
print(f" +0x{off:<4x} {name:14s} = {struct.unpack_from('<i', r, off)[0]}")
|
||||
Executable
+72
@@ -0,0 +1,72 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Enumerate FIFA 17's resident item map authoritatively.
|
||||
|
||||
Layout recovered from the lower_bound at 0x180119640:
|
||||
owner+0x160c8 sentinel / end marker
|
||||
owner+0x160d8 root
|
||||
owner+0x160e8 count
|
||||
node+0x00, node+0x08 children
|
||||
node+0x20 key = wire instance id (qword)
|
||||
node+0x28 the item record
|
||||
On miss the client returns the static sentinel 0x1802c2a28 whose +0x10 is NULL.
|
||||
|
||||
Read-only. usage: probe_map2.py PID [id ...]
|
||||
"""
|
||||
import re, struct, sys, collections
|
||||
|
||||
PID = int(sys.argv[1]); WANT = {int(a) for a in sys.argv[2:]}
|
||||
mem = open(f"/proc/{PID}/mem", "rb", buffering=0)
|
||||
def rd(a, n):
|
||||
mem.seek(a); return mem.read(n)
|
||||
def q(a): return struct.unpack("<Q", rd(a, 8))[0]
|
||||
named = []
|
||||
for ln in open(f"/proc/{PID}/maps"):
|
||||
m = re.match(r"([0-9a-f]+)-([0-9a-f]+) \S{4} \S+ \S+ \S+\s+(.+)", ln)
|
||||
if m: named.append((int(m.group(1), 16), m.group(3).strip()))
|
||||
named.sort()
|
||||
base = next(s for s, p in named if p.endswith("CardsDLL_Win64_retail.dll"))
|
||||
if rd(base + (0x180026fea - 0x180000000), 5) != bytes.fromhex("ba75750000"):
|
||||
sys.exit("SANITY FAILED")
|
||||
owner = q(base + (0x1802e6398 - 0x180000000))
|
||||
SENT, ROOT, COUNT = owner + 0x160c8, q(owner + 0x160d8), q(owner + 0x160e8) & 0xffffffff
|
||||
print(f" owner={owner:#x} sentinel={SENT:#x} root={ROOT:#x} count={COUNT}")
|
||||
|
||||
nodes, seen, stack = [], set(), [ROOT]
|
||||
while stack:
|
||||
n = stack.pop()
|
||||
if not n or n == SENT or n in seen or len(seen) > 5000:
|
||||
continue
|
||||
seen.add(n)
|
||||
try:
|
||||
h = rd(n, 0x30)
|
||||
except OSError:
|
||||
continue
|
||||
if len(h) < 0x30:
|
||||
continue
|
||||
nodes.append(n)
|
||||
stack.append(struct.unpack_from("<Q", h, 0)[0])
|
||||
stack.append(struct.unpack_from("<Q", h, 8)[0])
|
||||
print(f" nodes reached: {len(nodes)} (count field says {COUNT})\n")
|
||||
|
||||
print(f" {'key':>11} {'record':>12} {'id':>10} {'resource':>10} {'ct':>3} {'sub':>4} {'st':>4} {'cat':>4}")
|
||||
hist = collections.Counter(); found = {}
|
||||
rows = []
|
||||
for n in nodes:
|
||||
key = q(n + 0x20)
|
||||
rec = n + 0x28
|
||||
try: r = rd(rec, 0x180)
|
||||
except OSError: continue
|
||||
if len(r) < 0x180: continue
|
||||
g = lambda o: struct.unpack_from("<i", r, o)[0]
|
||||
rid = struct.unpack_from("<I", r, 0x8)[0]
|
||||
res = struct.unpack_from("<I", r, 0x18)[0]
|
||||
ct, sub, st, cat = g(0x4c), g(0x50), g(0x5c), g(0x60)
|
||||
hist[ct] += 1
|
||||
if rid in WANT: found[rid] = rec
|
||||
rows.append((key, rec, rid, res, ct, sub, st, cat))
|
||||
for key, rec, rid, res, ct, sub, st, cat in sorted(rows):
|
||||
tag = " <== CARDTYPE 7" if ct == 7 else (" <== WANTED" if rid in WANT else "")
|
||||
print(f" {key:>11} {rec:#12x} {rid:>10} {res:>10} {ct:>3} {sub:>4} {st:>4} {cat:>4}{tag}")
|
||||
print(f"\n cardtype histogram: {dict(sorted(hist.items()))} total={sum(hist.values())}")
|
||||
for w in sorted(WANT):
|
||||
print(f" id {w}: {'RESIDENT' if w in found else 'ABSENT'}")
|
||||
Executable
+62
@@ -0,0 +1,62 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Read-only scan of the record pool embedded in the club-model owner object.
|
||||
|
||||
The 18 resident player records sit at a fixed stride of 0x180 inside the owner
|
||||
object, below the embedded manager subobject at owner+0x1f9d8. This walks that
|
||||
pool to see whether storage for the five club items exists and what it holds.
|
||||
Read-only. Never writes.
|
||||
"""
|
||||
import re, struct, sys
|
||||
|
||||
PID = int(sys.argv[1])
|
||||
mem = open(f"/proc/{PID}/mem", "rb", buffering=0)
|
||||
|
||||
def rd(a, n):
|
||||
mem.seek(a); return mem.read(n)
|
||||
def q(a):
|
||||
return struct.unpack("<Q", rd(a, 8))[0]
|
||||
|
||||
named = []
|
||||
for ln in open(f"/proc/{PID}/maps"):
|
||||
m = re.match(r"([0-9a-f]+)-([0-9a-f]+) \S{4} \S+ \S+ \S+\s+(.+)", ln)
|
||||
if m:
|
||||
named.append((int(m.group(1), 16), m.group(3).strip()))
|
||||
named.sort()
|
||||
base = next(s for s, p in named if p.endswith("CardsDLL_Win64_retail.dll"))
|
||||
def live(s):
|
||||
return base + (s - 0x180000000)
|
||||
|
||||
owner = q(live(0x1802e6398))
|
||||
mgr = owner + 0x1f9d8
|
||||
beg, end = q(mgr + 0xd8), q(mgr + 0xe0)
|
||||
first = None
|
||||
for k in range((end - beg) // 24):
|
||||
r = q(beg + k * 24 + 0x10)
|
||||
if r:
|
||||
first = r; break
|
||||
if first is None:
|
||||
sys.exit("no populated player record to anchor the pool")
|
||||
|
||||
print(f" owner = {owner:#x} mgr = {mgr:#x} first record = {first:#x}")
|
||||
print(f" record - owner = {first - owner:#x} pool room to mgr = {(mgr - first) // 0x180} slots of 0x180")
|
||||
print()
|
||||
hdr = f" {'idx':>3} {'addr':>12} {'ctype':>6} {'subtyp':>6} {'state':>6} {'cat':>4} {'team':>5} {'kittyp':>6} set"
|
||||
print(hdr)
|
||||
n = (mgr - first) // 0x180
|
||||
for k in range(min(n, 40)):
|
||||
a = first + k * 0x180
|
||||
try:
|
||||
r = rd(a, 0xC0)
|
||||
except OSError:
|
||||
print(f" {k:>3} {a:#12x} unreadable"); break
|
||||
if len(r) < 0xC0:
|
||||
break
|
||||
ct, sub, st, cat, team = (struct.unpack_from("<i", r, o)[0] for o in (0x4c, 0x50, 0x5c, 0x60, 0x94))
|
||||
kt = struct.unpack_from("<H", r, 0xba)[0]
|
||||
nz = sum(1 for b in r if b)
|
||||
flag = ""
|
||||
if ct == 7:
|
||||
flag = " <== CARDTYPE 7"
|
||||
elif nz == 0:
|
||||
flag = " (all zero)"
|
||||
print(f" {k:>3} {a:#12x} {ct:>6} {sub:>6} {st:>6} {cat:>4} {team:>5} {kt:>6} {nz:>3}/192{flag}")
|
||||
+113
@@ -0,0 +1,113 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Read-only dump of RESIDENT record fields, for both the player and club-item vectors.
|
||||
|
||||
Purpose: the kit clone driver FUN_1801c3480 gates on record+0x60 (category) == 4.
|
||||
No instruction in CardsDLL writes immediate 4 there, so this reads what value a
|
||||
genuinely resident record actually carries. Read-only. Never writes.
|
||||
|
||||
mgr+0x0c0 cardtype-2 single slot
|
||||
mgr+0x0d8..0x0e0 cardtype-1 (player) vector
|
||||
mgr+0x108..0x110 club-item vector
|
||||
record+0x4c cardtype +0x50 cardsubtypeid +0x5c itemState
|
||||
record+0x60 category +0x94 teamid +0xba teamkittypetechid (u16)
|
||||
"""
|
||||
import re, struct, sys, collections
|
||||
|
||||
PID = int(sys.argv[1])
|
||||
mem = open(f"/proc/{PID}/mem", "rb", buffering=0)
|
||||
|
||||
def rd(a, n):
|
||||
mem.seek(a); return mem.read(n)
|
||||
def q(a):
|
||||
return struct.unpack("<Q", rd(a, 8))[0]
|
||||
def i32(b, o):
|
||||
return struct.unpack_from("<i", b, o)[0]
|
||||
|
||||
named = []
|
||||
for ln in open(f"/proc/{PID}/maps"):
|
||||
m = re.match(r"([0-9a-f]+)-([0-9a-f]+) \S{4} \S+ \S+ \S+\s+(.+)", ln)
|
||||
if m:
|
||||
named.append((int(m.group(1), 16), m.group(3).strip()))
|
||||
named.sort()
|
||||
base = next((s for s, p in named if p.endswith("CardsDLL_Win64_retail.dll")), None)
|
||||
if base is None:
|
||||
sys.exit("CardsDLL mapping not found")
|
||||
def live(static):
|
||||
return base + (static - 0x180000000)
|
||||
|
||||
if rd(live(0x180026fea), 5) != bytes.fromhex("ba75750000"):
|
||||
sys.exit("SANITY FAILED - wrong base")
|
||||
print(f" CardsDLL base = {base:#x} (sanity ok)")
|
||||
|
||||
owner = q(live(0x1802e6398))
|
||||
b = rd(q(owner) + 0x4e8, 12)
|
||||
b = rd(struct.unpack("<Q", struct.pack("<Q", q(q(owner) + 0x4e8)))[0], 12)
|
||||
getter = q(q(owner) + 0x4e8)
|
||||
gb = rd(getter, 12)
|
||||
if gb[0:3] == bytes.fromhex("488d81"):
|
||||
mgr = owner + struct.unpack_from("<I", gb, 3)[0]
|
||||
elif gb[0:3] == bytes.fromhex("488d41"):
|
||||
mgr = owner + gb[3]
|
||||
else:
|
||||
sys.exit(f"unexpected getter shape {gb.hex(' ')}")
|
||||
print(f" owner = {owner:#x} mgr = {mgr:#x}")
|
||||
|
||||
FIELDS = ("ctype", "subtype", "state", "cat", "team", "kittype")
|
||||
def decode(rec):
|
||||
r = rd(rec, 0xC0)
|
||||
if len(r) < 0xC0:
|
||||
return None
|
||||
return (i32(r, 0x4c), i32(r, 0x50), i32(r, 0x5c), i32(r, 0x60),
|
||||
i32(r, 0x94), struct.unpack_from("<H", r, 0xba)[0])
|
||||
|
||||
for label, vbeg, vend in (("players (cardtype 1)", mgr + 0xd8, mgr + 0xe0),
|
||||
("club items", mgr + 0x108, mgr + 0x110)):
|
||||
try:
|
||||
beg, end = q(vbeg), q(vend)
|
||||
except OSError:
|
||||
print(f"\n {label}: vector unreadable")
|
||||
continue
|
||||
span = end - beg
|
||||
print(f"\n === {label}: {beg:#x}..{end:#x} span={span} ===")
|
||||
if not (0 < beg <= end) or span > 24 * 100000:
|
||||
print(" implausible vector, skipping")
|
||||
continue
|
||||
# resolve stride: the element must contain a plausible heap pointer
|
||||
for stride, ptr_off in ((24, 0x10), (16, 0x08), (8, 0x00)):
|
||||
if span % stride:
|
||||
continue
|
||||
n = span // stride
|
||||
recs, nulls = [], []
|
||||
ok = True
|
||||
for k in range(n):
|
||||
try:
|
||||
rec = q(beg + k * stride + ptr_off)
|
||||
except OSError:
|
||||
ok = False; break
|
||||
if not rec:
|
||||
nulls.append(k); continue
|
||||
d = decode(rec)
|
||||
if d is None:
|
||||
ok = False; break
|
||||
recs.append((k, rec, d))
|
||||
if not ok:
|
||||
continue
|
||||
print(f" stride {stride} (ptr at +{ptr_off:#x}): {n} slots, {len(recs)} populated, {len(nulls)} null")
|
||||
if not recs and len(nulls) != n:
|
||||
continue
|
||||
hist = collections.Counter(d[0:2] for _, _, d in recs)
|
||||
for key, c in sorted(hist.items(), key=lambda x: -x[1]):
|
||||
print(f" (cardtype,subtype)={key} x{c}")
|
||||
# The SLOT INDEX is load-bearing evidence: the squad parser's `actives`
|
||||
# arm writes element i to slot `r15d + i`, and r15d is shared scratch
|
||||
# that other atom handlers clobber. Which slots are filled therefore
|
||||
# reveals the index the parse actually started from.
|
||||
print(f" {'slot':>4} {'ptr':>14} " + " ".join(f"{f:>8}" for f in FIELDS))
|
||||
for k, rec, d in recs[:8]:
|
||||
print(f" {k:>4} {rec:#14x} " + " ".join(f"{v:>8}" for v in d))
|
||||
if nulls:
|
||||
print(f" empty slots: {nulls[:16]}")
|
||||
cats = collections.Counter(d[3] for _, _, d in recs)
|
||||
if cats:
|
||||
print(f" CATEGORY (+0x60) distribution: {dict(cats)}")
|
||||
break
|
||||
Executable
+37
@@ -0,0 +1,37 @@
|
||||
#!/bin/sh
|
||||
# Native proof for the FIFA 17 kit milestone: does the client now hold resident
|
||||
# cardtype-7 records, and are the served kit ids among them?
|
||||
#
|
||||
# Auto-detects the live FIFA17.exe pid and walks the resident item map at
|
||||
# owner+0x160c8 (root +0x160d8, key = wire instance id at node+0x20, record at
|
||||
# node+0x28, count at owner+0x160e8). Read-only; never writes to the process.
|
||||
#
|
||||
# BEFORE this fix the map held 22 records with cardtype histogram {1:18, 2:1,
|
||||
# 4:2, 10:1} and both kit ids ABSENT.
|
||||
set -u
|
||||
|
||||
PID=$(for p in /proc/[0-9]*; do
|
||||
[ "$(cat "$p/comm" 2>/dev/null)" = "FIFA17.exe" ] && echo "${p#/proc/}"
|
||||
done | head -1)
|
||||
|
||||
if [ -z "$PID" ]; then
|
||||
echo " FIFA17.exe is not running - launch the game and enter FUT first"
|
||||
exit 1
|
||||
fi
|
||||
echo " live FIFA17 pid = $PID"
|
||||
echo
|
||||
|
||||
cd "$(dirname "$0")" || exit 1
|
||||
python3 probe_map2.py "$PID" 100004873 100004874 100004870
|
||||
|
||||
echo
|
||||
echo " ================ squad survival + slot indices ================"
|
||||
# The kit milestone is only real if the REST of the squad survives with it.
|
||||
# A populated `squad.actives` was once seen to leave the map holding just the
|
||||
# 2 kits with a fully null 23-slot player vector and an empty starting 11, so
|
||||
# the player-vector fill below is a PASS/FAIL gate, not decoration.
|
||||
#
|
||||
# The club-item slot indices are the other half: the parser writes element i to
|
||||
# slot r15d+i, and r15d is scratch other atom handlers clobber. Kits landing
|
||||
# somewhere other than slots 0 and 1 means the index did not start at zero.
|
||||
python3 probe_resident_fields.py "$PID"
|
||||
Executable
+225
@@ -0,0 +1,225 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Watch FIFA 17's resident club-item store and log every change, with timestamps.
|
||||
|
||||
Read-only. Waits for FIFA17.exe to appear, re-resolves the store each tick (the
|
||||
manager is reallocated across logins), and appends one line per CHANGE so the
|
||||
output can be aligned against the staging host's route log by wall clock.
|
||||
|
||||
Purpose: answer "after which response does a resident club item first appear?"
|
||||
without reversing the constructor first. Pair with
|
||||
|
||||
journalctl -u openfut-staging-host --since <start> -o short-iso
|
||||
|
||||
and compare timestamps.
|
||||
|
||||
Usage: watch_residency.py [--interval 1.0] [--out /path/log] [--once]
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
import collections
|
||||
import os
|
||||
import re
|
||||
import struct
|
||||
import sys
|
||||
import time
|
||||
|
||||
CARDS_DLL = "CardsDLL_Win64_retail.dll"
|
||||
OWNER_GLOBAL = 0x1802E6398 # FUN_18011a830: mov rax,[this]; ret
|
||||
SANITY_VA = 0x180026FEA # mov edx,0x7575
|
||||
SANITY_BYTES = bytes.fromhex("ba75750000")
|
||||
IMAGE_BASE = 0x180000000
|
||||
|
||||
# item-record offsets, all previously proven (see Vault: Kit Selector APT Decode)
|
||||
OFF = {"cardtype": 0x4C, "cardsubtypeid": 0x50, "itemState": 0x5C,
|
||||
"category": 0x60, "teamid": 0x94}
|
||||
OFF_KITTYPE_U16 = 0xBA
|
||||
|
||||
|
||||
class Target:
|
||||
"""One live FIFA17.exe, with the store chain resolved."""
|
||||
|
||||
def __init__(self, pid: int):
|
||||
self.pid = pid
|
||||
self.mem = open(f"/proc/{pid}/mem", "rb", buffering=0)
|
||||
self.base = self._cards_base()
|
||||
if self.base is None:
|
||||
raise RuntimeError("CardsDLL mapping not found")
|
||||
probe = self.rd(self.live(SANITY_VA), 5)
|
||||
if probe != SANITY_BYTES:
|
||||
raise RuntimeError(f"base sanity failed: {probe.hex(' ')}")
|
||||
owner = self.q(self.live(OWNER_GLOBAL))
|
||||
if not owner:
|
||||
raise RuntimeError("owner object is null (not logged in yet)")
|
||||
vt = self.q(owner)
|
||||
getter = self.q(vt + 0x4E8)
|
||||
b = self.rd(getter, 8)
|
||||
# lea rax,[rcx+imm32] ; ret / lea rax,[rcx+imm8] ; ret
|
||||
if b[0:3] == bytes.fromhex("488d81"):
|
||||
self.mgr = owner + struct.unpack_from("<I", b, 3)[0]
|
||||
elif b[0:3] == bytes.fromhex("488d41"):
|
||||
self.mgr = owner + b[3]
|
||||
elif b[0:3] == bytes.fromhex("488b81"):
|
||||
self.mgr = self.q(owner + struct.unpack_from("<I", b, 3)[0])
|
||||
else:
|
||||
raise RuntimeError(f"unrecognised getter: {b.hex(' ')}")
|
||||
|
||||
# -- raw access ------------------------------------------------------
|
||||
def rd(self, a: int, n: int) -> bytes:
|
||||
self.mem.seek(a)
|
||||
return self.mem.read(n)
|
||||
|
||||
def q(self, a: int) -> int:
|
||||
return struct.unpack("<Q", self.rd(a, 8))[0]
|
||||
|
||||
def live(self, static: int) -> int:
|
||||
return self.base + (static - IMAGE_BASE)
|
||||
|
||||
def _cards_base(self):
|
||||
named = []
|
||||
for ln in open(f"/proc/{self.pid}/maps"):
|
||||
m = re.match(r"([0-9a-f]+)-([0-9a-f]+) \S{4} \S+ \S+ \S+\s+(.+)", ln)
|
||||
if m:
|
||||
named.append((int(m.group(1), 16), m.group(3).strip()))
|
||||
# NEAREST PRECEDING NAMED mapping: Wine maps PE sections anonymously and
|
||||
# the Wine heap is also rwx, so permissions cannot identify a module.
|
||||
for start, path in sorted(named):
|
||||
if path.endswith(CARDS_DLL):
|
||||
return start
|
||||
return None
|
||||
|
||||
# -- the store -------------------------------------------------------
|
||||
def vector(self, off_begin: int):
|
||||
beg, end = self.q(self.mgr + off_begin), self.q(self.mgr + off_begin + 8)
|
||||
if not (0 < beg <= end) or (end - beg) % 24 or (end - beg) > 24 * 200000:
|
||||
return None, 0
|
||||
return beg, (end - beg) // 24
|
||||
|
||||
def records(self, off_begin: int):
|
||||
beg, n = self.vector(off_begin)
|
||||
out = []
|
||||
if beg is None:
|
||||
return out
|
||||
for k in range(n):
|
||||
try:
|
||||
rec = self.q(beg + k * 24 + 0x10)
|
||||
except OSError:
|
||||
continue
|
||||
if not rec:
|
||||
out.append(None)
|
||||
continue
|
||||
try:
|
||||
r = self.rd(rec, 0xC0)
|
||||
except OSError:
|
||||
out.append(None)
|
||||
continue
|
||||
if len(r) < 0xC0:
|
||||
out.append(None)
|
||||
continue
|
||||
f = {k2: struct.unpack_from("<i", r, v)[0] for k2, v in OFF.items()}
|
||||
f["teamkittypetechid"] = struct.unpack_from("<H", r, OFF_KITTYPE_U16)[0]
|
||||
f["ptr"] = rec
|
||||
out.append(f)
|
||||
return out
|
||||
|
||||
def snapshot(self) -> dict:
|
||||
club = self.records(0x108)
|
||||
players = self.records(0xD8)
|
||||
hist = collections.Counter(
|
||||
(r["cardtype"], r["cardsubtypeid"]) for r in club if r
|
||||
)
|
||||
return {
|
||||
"club_slots": len(club),
|
||||
"club_filled": sum(1 for r in club if r),
|
||||
"club_hist": dict(hist),
|
||||
"club_records": [r for r in club if r],
|
||||
"player_slots": len(players),
|
||||
"player_filled": sum(1 for r in players if r),
|
||||
}
|
||||
|
||||
|
||||
def find_pid() -> int | None:
|
||||
for d in os.listdir("/proc"):
|
||||
if not d.isdigit():
|
||||
continue
|
||||
try:
|
||||
with open(f"/proc/{d}/comm") as f:
|
||||
if f.read().strip() == "FIFA17.exe":
|
||||
return int(d)
|
||||
except OSError:
|
||||
continue
|
||||
return None
|
||||
|
||||
|
||||
def fmt(snap: dict) -> str:
|
||||
parts = [
|
||||
f"club={snap['club_filled']}/{snap['club_slots']}",
|
||||
f"players={snap['player_filled']}/{snap['player_slots']}",
|
||||
]
|
||||
if snap["club_hist"]:
|
||||
parts.append("hist=" + ",".join(
|
||||
f"(ct{a},st{b})x{c}" for (a, b), c in sorted(snap["club_hist"].items())))
|
||||
for r in snap["club_records"]:
|
||||
parts.append(
|
||||
"KIT[" if (r["cardtype"], r["cardsubtypeid"]) == (7, 9) else "rec[")
|
||||
parts[-1] += (f"ptr={r['ptr']:#x} ct={r['cardtype']} st={r['cardsubtypeid']} "
|
||||
f"state={r['itemState']} cat={r['category']} "
|
||||
f"team={r['teamid']} kittype={r['teamkittypetechid']}]")
|
||||
return " ".join(parts)
|
||||
|
||||
|
||||
def main() -> int:
|
||||
ap = argparse.ArgumentParser()
|
||||
ap.add_argument("--interval", type=float, default=1.0)
|
||||
ap.add_argument("--out", default="/home/alex/openfut-live/residency.log")
|
||||
ap.add_argument("--once", action="store_true")
|
||||
a = ap.parse_args()
|
||||
|
||||
sink = sys.stdout if a.out == "-" else open(a.out, "a", buffering=1)
|
||||
|
||||
def emit(msg: str) -> None:
|
||||
line = f"{time.strftime('%Y-%m-%dT%H:%M:%S%z')} {msg}"
|
||||
print(line, file=sink)
|
||||
if sink is not sys.stdout:
|
||||
print(line, flush=True)
|
||||
|
||||
emit("watch: start")
|
||||
target = None
|
||||
last = None
|
||||
while True:
|
||||
if target is None:
|
||||
pid = find_pid()
|
||||
if pid is None:
|
||||
if a.once:
|
||||
emit("watch: no FIFA17.exe"); return 1
|
||||
time.sleep(a.interval); continue
|
||||
try:
|
||||
target = Target(pid)
|
||||
emit(f"watch: attached pid={pid} cardsdll={target.base:#x} "
|
||||
f"mgr={target.mgr:#x}")
|
||||
last = None
|
||||
except (OSError, RuntimeError) as e:
|
||||
# not logged in yet, or the process died mid-resolve
|
||||
if a.once:
|
||||
emit(f"watch: not ready: {e}"); return 1
|
||||
target = None
|
||||
time.sleep(a.interval); continue
|
||||
try:
|
||||
snap = target.snapshot()
|
||||
except (OSError, struct.error) as e:
|
||||
emit(f"watch: detached ({e})")
|
||||
target = None
|
||||
if a.once:
|
||||
return 1
|
||||
continue
|
||||
key = fmt(snap)
|
||||
if key != last:
|
||||
emit(key)
|
||||
last = key
|
||||
if a.once:
|
||||
return 0
|
||||
time.sleep(a.interval)
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
@@ -162,19 +162,6 @@ def log(*a):
|
||||
print("[lsx]", *a, flush=True)
|
||||
|
||||
|
||||
def spawn_parent_watchdog():
|
||||
parent = os.getppid()
|
||||
|
||||
def _watch():
|
||||
while True:
|
||||
time.sleep(1)
|
||||
if os.getppid() != parent:
|
||||
log(f"launcher pid {parent} exited; stopping lsx")
|
||||
os._exit(0)
|
||||
|
||||
threading.Thread(target=_watch, daemon=True).start()
|
||||
|
||||
|
||||
_SECRET_ATTR_RE = re.compile(
|
||||
r'(?i)\b(AuthCode|AuthToken|SessionKey|Token|Sid)="[^"]*"')
|
||||
_AUTH_CODE_ATTR_RE = re.compile(r'(?i)\b(value|Code|Return)="[^"]*"')
|
||||
@@ -585,7 +572,6 @@ def serve(sock, addr):
|
||||
|
||||
|
||||
def main():
|
||||
spawn_parent_watchdog()
|
||||
s = socket.socket()
|
||||
s.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
|
||||
s.bind((os.environ.get("OPENFUT_BIND", "127.0.0.1"), 4216))
|
||||
|
||||
Executable
+100
@@ -0,0 +1,100 @@
|
||||
#!/usr/bin/env python3
|
||||
# -*- coding: utf-8 -*-
|
||||
"""Read back the MANAGER-ONLY chemistry slots the client resolved, and prove
|
||||
whether the server's `nation`/`leagueId` actually land in the record.
|
||||
|
||||
READ-ONLY. /proc/PID/mem is opened 'rb'; there is no write path in this file.
|
||||
|
||||
WHY THIS EXISTS
|
||||
---------------
|
||||
`card_identity_probe` reads the PLAYER slots (F_NATION = 0x148, F_LEAGUE =
|
||||
0x154). A manager does not use those, so grading a manager with that tool
|
||||
reports nation=0 / leagueId=0 and looks like a server bug when it is only the
|
||||
wrong offsets.
|
||||
|
||||
`fifa17-recon/tools/fut_staff.py` records the manager layout from Ghidra:
|
||||
|
||||
rec+0x94 teamid (read by the card view-model)
|
||||
rec+0xde nation MANAGER-ONLY slot, u16
|
||||
rec+0xe0 leagueId MANAGER-ONLY slot, u16
|
||||
rec+0xe2 talkrating written by the managercards merge
|
||||
rec+0xe3 negotiation written by the managercards merge
|
||||
|
||||
The merge (FUN_1801356c0) NEVER writes +0xde or +0xe0, so whatever sits there
|
||||
came from OUR JSON and nowhere else. That makes those two u16s a direct,
|
||||
unambiguous test of the server's manager chemistry fields: if they read back as
|
||||
the values we served, the wire contract is PROVEN rather than inferred; if they
|
||||
read zero, the client discarded them and manager chemistry cannot be rendering.
|
||||
|
||||
Usage: python3 manager_chem_probe.py # grade every manager in the map
|
||||
"""
|
||||
import sys
|
||||
|
||||
import watch_club_model as W
|
||||
import card_identity_probe as P
|
||||
|
||||
MANAGER_CARDTYPE = 2 # FUN_1800d8330: cardsubtypeid 4 -> cardtype 2
|
||||
F_CARDTYPE = 0x4C
|
||||
F_RESOURCE = 0x18
|
||||
F_TEAMID = 0x94
|
||||
F_NATION_MGR = 0xDE
|
||||
F_LEAGUE_MGR = 0xE0
|
||||
F_TALKRATING = 0xE2
|
||||
F_NEGOTIATION = 0xE3
|
||||
REC_SIZE = 0x158
|
||||
|
||||
|
||||
def main():
|
||||
pid = W.find_pid()
|
||||
if pid is None:
|
||||
print("FIFA17.exe is not running.")
|
||||
return 1
|
||||
base = W.dll_base(pid)
|
||||
if base is None:
|
||||
print("pid %d is up but %s is not mapped yet." % (pid, W.DLL))
|
||||
return 1
|
||||
mem = W.Mem(pid)
|
||||
obj = mem.q(base + (W.G_CARDSDB - W.IMG_BASE))
|
||||
if not obj:
|
||||
print("CardsDb singleton is NULL (no FUT session loaded).")
|
||||
return 1
|
||||
|
||||
ns = W.nodes(mem, obj) if hasattr(W, "nodes") else P.nodes(mem, obj)
|
||||
print("pid=%d CardsDb=%#x walked=%d" % (pid, obj, len(ns)))
|
||||
print()
|
||||
print("%-10s %-8s %-8s %-8s %-10s %-10s %s"
|
||||
% ("resource", "teamid", "nation", "league", "talkrating", "negot", "verdict"))
|
||||
|
||||
found = 0
|
||||
for n in ns:
|
||||
rec = n + 0x28
|
||||
buf = mem.read(rec, REC_SIZE)
|
||||
if not buf or len(buf) < REC_SIZE:
|
||||
continue
|
||||
if P.u8(buf, F_CARDTYPE) != MANAGER_CARDTYPE:
|
||||
continue
|
||||
found += 1
|
||||
resource = P.u32(buf, F_RESOURCE)
|
||||
teamid = P.u32(buf, F_TEAMID)
|
||||
nation = P.u16(buf, F_NATION_MGR)
|
||||
league = P.u16(buf, F_LEAGUE_MGR)
|
||||
talk = P.u8(buf, F_TALKRATING)
|
||||
negot = P.u8(buf, F_NEGOTIATION)
|
||||
# +0xde and +0xe0 are never written by the merge, so a non-zero value
|
||||
# can only have come from the server's JSON.
|
||||
if nation and league:
|
||||
verdict = "SERVER FIELDS LANDED"
|
||||
elif nation or league:
|
||||
verdict = "PARTIAL -- one slot empty"
|
||||
else:
|
||||
verdict = "EMPTY -- client kept nothing we sent"
|
||||
print("%-10d %-8d %-8d %-8d %-10d %-10d %s"
|
||||
% (resource, teamid, nation, league, talk, negot, verdict))
|
||||
|
||||
if not found:
|
||||
print("(no manager record in the map -- the client has not been served one)")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Executable
+252
@@ -0,0 +1,252 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Is the squad manager REGISTERED (not merely parsed) in a live FIFA17 client?
|
||||
|
||||
READ-ONLY. Opens /proc/<pid>/mem for reading and scans. Writes nothing, sends
|
||||
no input to the game, and never opens 'r+b'.
|
||||
|
||||
manager_coldproof.py [pid] [--manager-wire N] [--manager-resource N]
|
||||
[--control WIRE:RESOURCE ...]
|
||||
|
||||
Defaults describe the staging profile used to close the manager milestone; pass
|
||||
the flags for any other profile.
|
||||
|
||||
WHAT THIS DECIDES
|
||||
-----------------
|
||||
FIFA17's squad parser (FUN_18013d1f0) reaches the item parser FUN_18013fe00 by
|
||||
two different routes:
|
||||
|
||||
players : atom 568 -> per-element atoms 355 index / 363 itemData /
|
||||
378 kitNumber; the 363 arm at 0x18013d8d9 calls the item parser
|
||||
on the NESTED itemData object.
|
||||
manager : atom 424 -> array loop at 0x18013da29 calls that same item parser
|
||||
DIRECTLY on the array ELEMENT, into squad+0xC0. No itemData step.
|
||||
|
||||
So `squad.manager[]` elements must be BARE ITEM OBJECTS. When they were served
|
||||
as {id, itemData:{...}, dream} the parser read only the two keys that happen to
|
||||
be item atoms -- id and dream -- and left resourceId at 0. resourceId is the
|
||||
merge key, compared RAW against carddbid (fut_staff.py::manager_item, +0x18),
|
||||
so 0 resolves no manager: no name, no rating, no art, empty slot. Fixed in
|
||||
OpenFUT b91e707; see Vault "FIFA 17/Squad Manager Wire Shape.md".
|
||||
|
||||
CONTROLS
|
||||
--------
|
||||
manager wire id the instance id. Present even when BROKEN, because `id` is
|
||||
an item atom the parser reads at element level. Its
|
||||
presence proves the element was parsed and therefore proves
|
||||
nothing about registration -- do not use it as the verdict.
|
||||
manager resourceId THE VERDICT. Resident => the merge key survived the load.
|
||||
player wire id and positive controls. Players demonstrably render, so if their
|
||||
player resourceId resourceIds are absent the squad simply is not loaded yet
|
||||
and the run is INCONCLUSIVE, not a failure.
|
||||
|
||||
RESIDENT-MANAGER HIT
|
||||
--------------------
|
||||
A 4-byte-aligned little-endian i32 equal to the manager resourceId, anywhere in
|
||||
a readable private mapping. Corroborate with the record context printed below:
|
||||
a real item record carries resourceId eight words ahead of its wire id, which
|
||||
is the layout the player controls exhibit. Hits without that shape are usually
|
||||
id lists or unrelated integers -- the layout, not the raw count, is the proof.
|
||||
|
||||
LAYOUT ASSUMPTION (the only one)
|
||||
--------------------------------
|
||||
Item records place resourceId 0x20 bytes before the wire id. Measured, both
|
||||
sides:
|
||||
|
||||
before b91e707 (pid 126936) -- manager parsed, merge key absent
|
||||
player @0xb85dbf48: 83906881 1 0 0 0 0 0 0 | 100002878 0 | 7
|
||||
player @0xb85dbd68: 84053575 1 0 0 0 0 0 0 | 100003237 0 | 7
|
||||
manager @0xb85dc1b8: 0 0 0 0 0 0 0 0 | 100004870 0 | 7
|
||||
|
||||
after b91e707 (pid 134118) -- same layout, key present
|
||||
player @0xb8740fd8: 84053575 1 0 0 0 0 0 0 | 100003237 0 | 7 0
|
||||
player @0xb87411b8: 83906881 1 0 0 0 0 0 0 | 100002878 0 | 7 0
|
||||
manager @0xb8741428: 1000509 2 0 0 0 0 0 0 | 100004870 0 | 7 0
|
||||
|
||||
Addresses shift every session and are recorded only as provenance; nothing here
|
||||
depends on them. The tool re-derives everything by scanning.
|
||||
|
||||
EXIT CODES (fail-closed)
|
||||
------------------------
|
||||
0 PASS manager resourceId resident, controls present
|
||||
1 FAIL controls present, manager resourceId absent
|
||||
2 NO PROCESS no FIFA17.exe, or /proc/<pid>/mem unreadable
|
||||
3 INCONCLUSIVE controls absent -- squad not loaded yet; re-run at the
|
||||
squad screen. Deliberately NOT 0: absent controls mean the
|
||||
probe proved nothing.
|
||||
"""
|
||||
import argparse
|
||||
import glob
|
||||
import os
|
||||
import re
|
||||
import struct
|
||||
import sys
|
||||
|
||||
# Staging profile defaults (override on the command line).
|
||||
DEF_MANAGER_WIRE = 100004870
|
||||
DEF_MANAGER_RESOURCE = 1000509
|
||||
DEF_CONTROLS = [(100002878, 83906881), (100003237, 84053575)]
|
||||
|
||||
# Item record layout: resourceId sits this far BEFORE the wire id.
|
||||
RESOURCE_BACK_OFF = 0x20
|
||||
|
||||
|
||||
def find_pid():
|
||||
"""The Wine process whose comm is FIFA17.exe (same rule as memtool.py)."""
|
||||
for d in glob.glob("/proc/[0-9]*"):
|
||||
try:
|
||||
with open(os.path.join(d, "comm")) as fh:
|
||||
if fh.read().strip() == "FIFA17.exe":
|
||||
return int(os.path.basename(d))
|
||||
except OSError:
|
||||
continue
|
||||
return None
|
||||
|
||||
|
||||
def regions(pid):
|
||||
"""Readable private mappings worth scanning.
|
||||
|
||||
Skips device/memfd mappings and anything over 512 MiB (the big reserved
|
||||
ranges are not where parsed records live and dominate the runtime).
|
||||
"""
|
||||
out = []
|
||||
with open(f"/proc/{pid}/maps") as fh:
|
||||
for line in fh:
|
||||
m = re.match(r"([0-9a-f]+)-([0-9a-f]+)\s+(\S{4})\s+\S+\s+\S+\s+\S+\s*(.*)", line)
|
||||
if not m:
|
||||
continue
|
||||
lo, hi = int(m.group(1), 16), int(m.group(2), 16)
|
||||
perms, path = m.group(3), m.group(4)
|
||||
if perms[0] != "r" or path.startswith(("/dev", "/memfd")):
|
||||
continue
|
||||
if hi - lo > 512 * 1024 * 1024:
|
||||
continue
|
||||
out.append((lo, hi))
|
||||
return out
|
||||
|
||||
|
||||
def scan(pid, needles, ctx_before=0x40, ctx_after=0x40):
|
||||
"""4-byte-aligned little-endian i32 search; keeps a window around each hit."""
|
||||
found = {n: [] for n in needles}
|
||||
pats = {n: struct.pack("<i", n) for n in needles}
|
||||
with open(f"/proc/{pid}/mem", "rb", 0) as mem:
|
||||
for lo, hi in regions(pid):
|
||||
try:
|
||||
mem.seek(lo)
|
||||
buf = mem.read(hi - lo)
|
||||
except (OSError, ValueError, OverflowError):
|
||||
continue # torn-down or unreadable mapping; not a failure
|
||||
for n, pat in pats.items():
|
||||
i = buf.find(pat)
|
||||
while i >= 0:
|
||||
if i % 4 == 0:
|
||||
found[n].append(
|
||||
(lo + i, buf[max(0, i - ctx_before): i + ctx_after], min(i, ctx_before))
|
||||
)
|
||||
i = buf.find(pat, i + 4)
|
||||
return found
|
||||
|
||||
|
||||
def words(blob, centre, before=8, after=4):
|
||||
cells = []
|
||||
for k in range(-before, after):
|
||||
o = centre + k * 4
|
||||
if 0 <= o <= len(blob) - 4:
|
||||
cells.append(str(struct.unpack_from("<i", blob, o)[0]))
|
||||
return " ".join(cells)
|
||||
|
||||
|
||||
def record_shaped(blob, centre, resource):
|
||||
"""True when resourceId sits RESOURCE_BACK_OFF before the id -- the real
|
||||
item-record layout, as opposed to an incidental integer match."""
|
||||
o = centre - RESOURCE_BACK_OFF
|
||||
if o < 0 or o > len(blob) - 4:
|
||||
return False
|
||||
return struct.unpack_from("<i", blob, o)[0] == resource
|
||||
|
||||
|
||||
def main():
|
||||
ap = argparse.ArgumentParser(description="read-only manager registration probe")
|
||||
ap.add_argument("pid", nargs="?", type=int, help="FIFA17 pid (default: auto)")
|
||||
ap.add_argument("--manager-wire", type=int, default=DEF_MANAGER_WIRE)
|
||||
ap.add_argument("--manager-resource", type=int, default=DEF_MANAGER_RESOURCE)
|
||||
ap.add_argument(
|
||||
"--control",
|
||||
action="append",
|
||||
metavar="WIRE:RESOURCE",
|
||||
help="player positive control; repeatable (default: the staging pair)",
|
||||
)
|
||||
args = ap.parse_args()
|
||||
|
||||
controls = DEF_CONTROLS
|
||||
if args.control:
|
||||
try:
|
||||
controls = [tuple(int(x) for x in c.split(":", 1)) for c in args.control]
|
||||
except ValueError:
|
||||
print(" --control must be WIRE:RESOURCE", file=sys.stderr)
|
||||
return 2
|
||||
|
||||
pid = args.pid or find_pid()
|
||||
if not pid:
|
||||
print(" NO FIFA17 PROCESS (comm == FIFA17.exe) -- is the client running?")
|
||||
return 2
|
||||
if not os.access(f"/proc/{pid}/mem", os.R_OK):
|
||||
print(f" /proc/{pid}/mem is not readable -- wrong user, or the process exited")
|
||||
return 2
|
||||
print(f" pid={pid}")
|
||||
|
||||
needles = [args.manager_wire, args.manager_resource]
|
||||
for w, r in controls:
|
||||
needles += [w, r]
|
||||
try:
|
||||
res = scan(pid, sorted(set(needles)))
|
||||
except OSError as e:
|
||||
print(f" cannot read /proc/{pid}/mem: {e}")
|
||||
return 2
|
||||
|
||||
print("\n ===== hit counts =====")
|
||||
print(f" {'manager wire (parsed?)':32} {args.manager_wire:<12} hits={len(res[args.manager_wire])}")
|
||||
print(f" {'manager resourceId (VERDICT)':32} {args.manager_resource:<12} "
|
||||
f"hits={len(res[args.manager_resource])}")
|
||||
for w, r in controls:
|
||||
print(f" {'player wire (control)':32} {w:<12} hits={len(res[w])}")
|
||||
print(f" {'player resourceId (control)':32} {r:<12} hits={len(res[r])}")
|
||||
|
||||
print("\n ===== record context (8 words before the id, then the id) =====")
|
||||
shaped = {"manager": 0}
|
||||
for tag, wire, resource in (
|
||||
[("manager", args.manager_wire, args.manager_resource)]
|
||||
+ [(f"player{i}", w, r) for i, (w, r) in enumerate(controls)]
|
||||
):
|
||||
marked = 0
|
||||
for addr, blob, centre in res[wire]:
|
||||
ok = record_shaped(blob, centre, resource)
|
||||
if ok:
|
||||
marked += 1
|
||||
if marked <= 2 or ok:
|
||||
print(f" {tag:8} @0x{addr:x}{' <- item-record layout' if ok else ''}: "
|
||||
f"{words(blob, centre)}")
|
||||
if marked >= 2:
|
||||
break
|
||||
shaped[tag] = marked
|
||||
|
||||
ctl_keys = sum(len(res[r]) for _w, r in controls)
|
||||
mgr_keys = len(res[args.manager_resource])
|
||||
|
||||
print("\n ===== verdict =====")
|
||||
if ctl_keys == 0:
|
||||
print(" INCONCLUSIVE: no player resourceId control is resident, so the squad")
|
||||
print(" is not loaded. Reach the squad screen and re-run. (Nothing proven.)")
|
||||
return 3
|
||||
if mgr_keys == 0:
|
||||
print(f" FAIL: manager resourceId {args.manager_resource} is absent while "
|
||||
f"{ctl_keys} player")
|
||||
print(" resourceId control hit(s) are resident -> PARSED_BUT_NOT_REGISTERED.")
|
||||
return 1
|
||||
print(f" PASS: manager resourceId {args.manager_resource} is resident "
|
||||
f"({mgr_keys} hits, {shaped['manager']} in item-record layout).")
|
||||
print(" The merge key survived the load; the broken projection had 0.")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Executable
+189
@@ -0,0 +1,189 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Trace FIFA17 provider dispatch and ACTION_ADVANCE delivery boundaries.
|
||||
|
||||
This probe correlates the global UI dispatch of FUT_CREATE_MATCH_DP and
|
||||
FUT_GET_MATCH_KITS_DP, the subscribed CardsDLL provider, the internal 0x7546
|
||||
create-response callback that can replay FUT_CREATE_MATCH_DP, and the final
|
||||
native-to-UI bridge. At global dispatch, r8d is the provider ID and rdx is the
|
||||
payload; neither register is a screen key.
|
||||
|
||||
The generated GDB program uses hardware-assisted execution breakpoints only.
|
||||
It never writes client memory and never drives game input.
|
||||
|
||||
match_advance_trace.py [pid] [--output PATH]
|
||||
match_advance_trace.py --print-script [pid]
|
||||
match_advance_trace.py --selftest
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
import hashlib
|
||||
import os
|
||||
from pathlib import Path
|
||||
import shutil
|
||||
import sys
|
||||
|
||||
sys.path.insert(0, str(Path(__file__).resolve().parent))
|
||||
import match_transition_trace as transition
|
||||
|
||||
FIFA_MODULE = "FIFA17.exe"
|
||||
PINNED_FIFA_SHA256 = "29c31cef12b0c3c2a7305220617c7b4fa139ab76b8c857851bdbe88987962899"
|
||||
GLOBAL_UI_DISPATCH_RVA = 0x80D1070
|
||||
CREATE_MATCH_CONTROLLER_RVA = 0xBF950
|
||||
PROVIDER_BRIDGE_CALL_RVA = 0x1A4D41
|
||||
|
||||
|
||||
def module_mapping(pid: int, module: str) -> tuple[int, str]:
|
||||
with open(f"/proc/{pid}/maps", encoding="utf-8") as handle:
|
||||
for line in handle:
|
||||
fields = line.split(maxsplit=5)
|
||||
path = fields[5].rstrip() if len(fields) == 6 else ""
|
||||
if not path.endswith(module):
|
||||
continue
|
||||
return int(fields[0].split("-", 1)[0], 16), path
|
||||
raise RuntimeError(f"{module} is not mapped in PID {pid}")
|
||||
|
||||
|
||||
def validate_file(path: str, expected: str, label: str) -> None:
|
||||
digest = hashlib.sha256()
|
||||
with open(path, "rb") as handle:
|
||||
for chunk in iter(lambda: handle.read(1024 * 1024), b""):
|
||||
digest.update(chunk)
|
||||
actual = digest.hexdigest()
|
||||
if actual != expected:
|
||||
raise RuntimeError(f"unsupported {label}: sha256={actual}; expected={expected}")
|
||||
|
||||
|
||||
def trace_addresses(cards_base: int, fifa_base: int) -> dict[str, int]:
|
||||
return {
|
||||
"provider": cards_base + transition.PROVIDER_DISPATCH_RVA,
|
||||
"global_dispatch": fifa_base + GLOBAL_UI_DISPATCH_RVA,
|
||||
"controller": cards_base + CREATE_MATCH_CONTROLLER_RVA,
|
||||
"bridge": cards_base + PROVIDER_BRIDGE_CALL_RVA,
|
||||
}
|
||||
|
||||
|
||||
def build_gdb_script(pid: int, cards_base: int, fifa_base: int, output: str) -> str:
|
||||
if any(character in output for character in "\n\r"):
|
||||
raise ValueError("output path cannot contain a newline")
|
||||
address = trace_addresses(cards_base, fifa_base)
|
||||
return f"""set pagination off
|
||||
set confirm off
|
||||
set print thread-events off
|
||||
set breakpoint always-inserted on
|
||||
set logging file {output}
|
||||
set logging overwrite on
|
||||
set logging redirect off
|
||||
set logging enabled on
|
||||
handle SIGSEGV nostop noprint pass
|
||||
handle SIGILL nostop noprint pass
|
||||
handle SIGFPE nostop noprint pass
|
||||
handle SIGPIPE nostop noprint pass
|
||||
handle SIGALRM nostop noprint pass
|
||||
handle SIGUSR1 nostop noprint pass
|
||||
handle SIGUSR2 nostop noprint pass
|
||||
|
||||
attach {pid}
|
||||
|
||||
hbreak *0x{address['provider']:x}
|
||||
condition 1 $edx == 0x{transition.FUT_CREATE_MATCH_DP:x} || $edx == 0x{transition.FUT_GET_MATCH_KITS_DP:x}
|
||||
commands
|
||||
silent
|
||||
python import time; print("ADVTRACE epoch_ns=%d mono_ns=%d PROVIDER" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d provider=%#x payload=%p controller=%p caller=%p\\n", $_thread, $edx, $r8, $rcx, *(void**)$rsp
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['global_dispatch']:x}
|
||||
condition 2 $r8d == 0x{transition.FUT_CREATE_MATCH_DP:x} || $r8d == 0x{transition.FUT_GET_MATCH_KITS_DP:x}
|
||||
commands
|
||||
silent
|
||||
python import time; print("ADVTRACE epoch_ns=%d mono_ns=%d GLOBAL_DISPATCH" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d provider=%#x payload=%p manager=%p caller=%p\\n", $_thread, $r8d, $rdx, $rcx, *(void**)$rsp
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['controller']:x}
|
||||
condition 3 $edx == 0x7546
|
||||
commands
|
||||
silent
|
||||
python import time; print("ADVTRACE epoch_ns=%d mono_ns=%d CREATE_MATCH_CONTROLLER" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d event=%#x controller=%p caller=%p\\n", $_thread, $edx, $rcx, *(void**)$rsp
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['bridge']:x}
|
||||
condition 4 $edi == 0x{transition.FUT_CREATE_MATCH_DP:x} || $edi == 0x{transition.FUT_GET_MATCH_KITS_DP:x}
|
||||
commands
|
||||
silent
|
||||
python import time; print("ADVTRACE epoch_ns=%d mono_ns=%d PROVIDER_BRIDGE" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d provider=%#x target=%p bridge=%p callback=%p\\n", $_thread, $edi, $rsi, $rbx, *(void**)(*(void**)$rbx+0x48)
|
||||
continue
|
||||
end
|
||||
|
||||
printf "ADVTRACE ARMED pid={pid} provider=0x{address['provider']:x} global=0x{address['global_dispatch']:x} controller=0x{address['controller']:x} bridge=0x{address['bridge']:x}\\n"
|
||||
continue
|
||||
"""
|
||||
|
||||
|
||||
def selftest() -> None:
|
||||
address = trace_addresses(0x180000000, 0x140000000)
|
||||
assert address == {
|
||||
"provider": 0x1801A4CD0,
|
||||
"global_dispatch": 0x1480D1070,
|
||||
"controller": 0x1800BF950,
|
||||
"bridge": 0x1801A4D41,
|
||||
}
|
||||
script = build_gdb_script(28804, 0x180000000, 0x140000000, "/tmp/advance.log")
|
||||
assert script.count("hbreak *") == 4
|
||||
assert f"$edx == 0x{transition.FUT_CREATE_MATCH_DP:x}" in script
|
||||
assert f"$edx == 0x{transition.FUT_GET_MATCH_KITS_DP:x}" in script
|
||||
assert f"$r8d == 0x{transition.FUT_CREATE_MATCH_DP:x}" in script
|
||||
assert f"$r8d == 0x{transition.FUT_GET_MATCH_KITS_DP:x}" in script
|
||||
assert "CREATE_MATCH_CONTROLLER" in script
|
||||
assert "PROVIDER_BRIDGE" in script
|
||||
assert "set *(" not in script
|
||||
print("match_advance_trace selftest: PASS")
|
||||
|
||||
|
||||
def main() -> int:
|
||||
parser = argparse.ArgumentParser(description=__doc__)
|
||||
parser.add_argument("pid", nargs="?", type=int)
|
||||
parser.add_argument("--output")
|
||||
parser.add_argument("--print-script", action="store_true")
|
||||
parser.add_argument("--selftest", action="store_true")
|
||||
args = parser.parse_args()
|
||||
if args.selftest:
|
||||
selftest()
|
||||
return 0
|
||||
|
||||
pid = args.pid or transition.find_pid()
|
||||
if not pid:
|
||||
print("FIFA17.exe not found", file=sys.stderr)
|
||||
return 2
|
||||
try:
|
||||
cards_base, cards_path = transition.cards_mapping(pid)
|
||||
transition.validate_cards(cards_path)
|
||||
fifa_base, fifa_path = module_mapping(pid, FIFA_MODULE)
|
||||
validate_file(fifa_path, PINNED_FIFA_SHA256, FIFA_MODULE)
|
||||
output = args.output or f"/tmp/fifa17-match-advance-{pid}.log"
|
||||
script = build_gdb_script(pid, cards_base, fifa_base, output)
|
||||
except (OSError, RuntimeError, ValueError) as error:
|
||||
print(error, file=sys.stderr)
|
||||
return 2
|
||||
|
||||
if args.print_script:
|
||||
print(script, end="")
|
||||
return 0
|
||||
if not shutil.which("gdb"):
|
||||
print("gdb not found", file=sys.stderr)
|
||||
return 2
|
||||
script_path = f"/tmp/fifa17-match-advance-{pid}.gdb"
|
||||
with open(script_path, "w", encoding="utf-8") as handle:
|
||||
handle.write(script)
|
||||
os.execvp("gdb", ["gdb", "-q", "-nx", "-x", script_path])
|
||||
return 127
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
raise SystemExit(main())
|
||||
+208
@@ -0,0 +1,208 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Trace the FIFA17 ACTION_CREATE_MATCH-to-provider lifecycle.
|
||||
|
||||
The probe correlates:
|
||||
|
||||
* the select-team action handler for UIF action IDs 0x7574..0x757b;
|
||||
* DataManager's request dispatch for FutCreateMatchServerResponse (0x7546);
|
||||
* the concrete FutCreateMatchServerResponse data-source request method;
|
||||
* FIFA's global UI dispatch of providers 0x7563 and 0x7565.
|
||||
|
||||
Static decoding identifies action 0x7577 as the branch that constructs the
|
||||
create-match request and calls DataManager for source 0x7546. The trace proves
|
||||
whether that authentic trigger executes in the failing flow. It uses four
|
||||
hardware-assisted execution breakpoints, never writes client memory, and never
|
||||
drives game input.
|
||||
|
||||
match_create_action_trace.py [pid] [--output PATH]
|
||||
match_create_action_trace.py --print-script [pid]
|
||||
match_create_action_trace.py --selftest
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
import os
|
||||
from pathlib import Path
|
||||
import shutil
|
||||
import sys
|
||||
|
||||
sys.path.insert(0, str(Path(__file__).resolve().parent))
|
||||
import match_advance_trace as advance
|
||||
import match_transition_trace as transition
|
||||
|
||||
SELECT_TEAM_ACTION_HANDLER_RVA = 0x0BFCC0
|
||||
DATA_MANAGER_REQUEST_RVA = 0x80D2340
|
||||
DATA_SOURCE_REQUEST_RVA = 0x120270
|
||||
GLOBAL_UI_DISPATCH_RVA = advance.GLOBAL_UI_DISPATCH_RVA
|
||||
FIRST_SELECT_TEAM_ACTION = 0x7574
|
||||
LAST_SELECT_TEAM_ACTION = 0x757B
|
||||
ACTION_CREATE_MATCH = 0x7577
|
||||
CREATE_DATA_SOURCE = 0x7546
|
||||
|
||||
|
||||
def trace_addresses(cards_base: int, fifa_base: int) -> dict[str, int]:
|
||||
return {
|
||||
"action_handler": cards_base + SELECT_TEAM_ACTION_HANDLER_RVA,
|
||||
"manager_request": fifa_base + DATA_MANAGER_REQUEST_RVA,
|
||||
"data_source_request": cards_base + DATA_SOURCE_REQUEST_RVA,
|
||||
"ui_dispatch": fifa_base + GLOBAL_UI_DISPATCH_RVA,
|
||||
}
|
||||
|
||||
|
||||
def build_gdb_script(
|
||||
pid: int, cards_base: int, fifa_base: int, output: str
|
||||
) -> str:
|
||||
if any(character in output for character in "\n\r"):
|
||||
raise ValueError("output path cannot contain a newline")
|
||||
address = trace_addresses(cards_base, fifa_base)
|
||||
return f"""set pagination off
|
||||
set confirm off
|
||||
set print thread-events off
|
||||
set breakpoint always-inserted on
|
||||
set logging file {output}
|
||||
set logging overwrite on
|
||||
set logging redirect off
|
||||
set logging enabled on
|
||||
handle SIGSEGV nostop noprint pass
|
||||
handle SIGILL nostop noprint pass
|
||||
handle SIGFPE nostop noprint pass
|
||||
handle SIGPIPE nostop noprint pass
|
||||
handle SIGALRM nostop noprint pass
|
||||
handle SIGUSR1 nostop noprint pass
|
||||
handle SIGUSR2 nostop noprint pass
|
||||
|
||||
attach {pid}
|
||||
set $create_action_seen = 0
|
||||
set $manager_request_seen = 0
|
||||
set $data_source_request_seen = 0
|
||||
|
||||
hbreak *0x{address['action_handler']:x}
|
||||
condition 1 $edx >= 0x{FIRST_SELECT_TEAM_ACTION:x} && $edx <= 0x{LAST_SELECT_TEAM_ACTION:x}
|
||||
commands
|
||||
silent
|
||||
if $edx == 0x{ACTION_CREATE_MATCH:x}
|
||||
set $create_action_seen = 1
|
||||
end
|
||||
python import time; print("ACTIONTRACE epoch_ns=%d mono_ns=%d SELECT_TEAM_ACTION" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d action=%#x is_create=%d controller=%p payload=%p create_seen=%d\\n", $_thread, $edx, $edx==0x{ACTION_CREATE_MATCH:x}, $rcx, $r8, $create_action_seen
|
||||
bt 10
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['manager_request']:x}
|
||||
condition 2 $edx == 0x{CREATE_DATA_SOURCE:x}
|
||||
commands
|
||||
silent
|
||||
set $manager_request_seen = 1
|
||||
set $tree_sentinel = $rcx + 0x10
|
||||
set $tree_cursor = *(void**)($rcx+0x20)
|
||||
set $data_node = $tree_sentinel
|
||||
while $tree_cursor != 0 && $tree_cursor != $tree_sentinel
|
||||
if *(unsigned int*)($tree_cursor+0x20) >= 0x{CREATE_DATA_SOURCE:x}
|
||||
set $data_node = $tree_cursor
|
||||
set $tree_cursor = *(void**)($tree_cursor+0x08)
|
||||
else
|
||||
set $tree_cursor = *(void**)$tree_cursor
|
||||
end
|
||||
end
|
||||
set $data_source = 0
|
||||
set $request_method = 0
|
||||
if $data_node != $tree_sentinel && *(unsigned int*)($data_node+0x20) == 0x{CREATE_DATA_SOURCE:x}
|
||||
set $data_source = *(void**)($data_node+0x28)
|
||||
if $data_source != 0
|
||||
set $request_method = *(void**)(*(void**)$data_source+0x18)
|
||||
end
|
||||
end
|
||||
python import time; print("ACTIONTRACE epoch_ns=%d mono_ns=%d MANAGER_REQUEST" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d source=%#x manager=%p request=%p node=%p data_source=%p request_method=%p create_seen=%d\\n", $_thread, $edx, $rcx, $r8, $data_node, $data_source, $request_method, $create_action_seen
|
||||
bt 10
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['data_source_request']:x}
|
||||
commands
|
||||
silent
|
||||
set $data_source_request_seen = 1
|
||||
python import time; print("ACTIONTRACE epoch_ns=%d mono_ns=%d DATA_SOURCE_REQUEST" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d response=%p data_source=%p request=%p ready_before=%#x create_seen=%d manager_seen=%d\\n", $_thread, $rcx-0x50, $rcx, $rdx, *(unsigned char*)($rcx+0x38), $create_action_seen, $manager_request_seen
|
||||
bt 10
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['ui_dispatch']:x}
|
||||
condition 4 $r8d == 0x{transition.FUT_CREATE_MATCH_DP:x} || $r8d == 0x{transition.FUT_GET_MATCH_KITS_DP:x}
|
||||
commands
|
||||
silent
|
||||
python import time; print("ACTIONTRACE epoch_ns=%d mono_ns=%d UI_DISPATCH" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d provider=%#x payload=%p ui_manager=%p create_seen=%d manager_seen=%d data_source_seen=%d\\n", $_thread, $r8d, $rdx, $rcx, $create_action_seen, $manager_request_seen, $data_source_request_seen
|
||||
bt 10
|
||||
continue
|
||||
end
|
||||
|
||||
printf "ACTIONTRACE ARMED pid={pid} action_handler=0x{address['action_handler']:x} manager_request=0x{address['manager_request']:x} data_source_request=0x{address['data_source_request']:x} ui_dispatch=0x{address['ui_dispatch']:x}\\n"
|
||||
continue
|
||||
"""
|
||||
|
||||
|
||||
def selftest() -> None:
|
||||
address = trace_addresses(0x180000000, 0x140000000)
|
||||
assert address == {
|
||||
"action_handler": 0x1800BFCC0,
|
||||
"manager_request": 0x1480D2340,
|
||||
"data_source_request": 0x180120270,
|
||||
"ui_dispatch": 0x1480D1070,
|
||||
}
|
||||
script = build_gdb_script(
|
||||
45949, 0x180000000, 0x140000000, "/tmp/create-action.log"
|
||||
)
|
||||
assert script.count("hbreak *") == 4
|
||||
assert f"$edx == 0x{ACTION_CREATE_MATCH:x}" in script
|
||||
assert f"$edx == 0x{CREATE_DATA_SOURCE:x}" in script
|
||||
assert f"$r8d == 0x{transition.FUT_CREATE_MATCH_DP:x}" in script
|
||||
assert f"$r8d == 0x{transition.FUT_GET_MATCH_KITS_DP:x}" in script
|
||||
assert "request_method" in script
|
||||
assert "set *(" not in script
|
||||
print("match_create_action_trace selftest: PASS")
|
||||
|
||||
|
||||
def main() -> int:
|
||||
parser = argparse.ArgumentParser(description=__doc__)
|
||||
parser.add_argument("pid", nargs="?", type=int)
|
||||
parser.add_argument("--output")
|
||||
parser.add_argument("--print-script", action="store_true")
|
||||
parser.add_argument("--selftest", action="store_true")
|
||||
args = parser.parse_args()
|
||||
if args.selftest:
|
||||
selftest()
|
||||
return 0
|
||||
|
||||
pid = args.pid or transition.find_pid()
|
||||
if not pid:
|
||||
print("FIFA17.exe not found", file=sys.stderr)
|
||||
return 2
|
||||
try:
|
||||
cards_base, cards_path = transition.cards_mapping(pid)
|
||||
transition.validate_cards(cards_path)
|
||||
fifa_base, fifa_path = advance.module_mapping(pid, advance.FIFA_MODULE)
|
||||
advance.validate_file(fifa_path, advance.PINNED_FIFA_SHA256, advance.FIFA_MODULE)
|
||||
output = args.output or f"/tmp/fifa17-match-create-action-{pid}.log"
|
||||
script = build_gdb_script(pid, cards_base, fifa_base, output)
|
||||
except (OSError, RuntimeError, ValueError) as error:
|
||||
print(error, file=sys.stderr)
|
||||
return 2
|
||||
|
||||
if args.print_script:
|
||||
print(script, end="")
|
||||
return 0
|
||||
if not shutil.which("gdb"):
|
||||
print("gdb not found", file=sys.stderr)
|
||||
return 2
|
||||
script_path = f"/tmp/fifa17-match-create-action-{pid}.gdb"
|
||||
with open(script_path, "w", encoding="utf-8") as handle:
|
||||
handle.write(script)
|
||||
os.execvp("gdb", ["gdb", "-q", "-nx", "-batch", "-x", script_path])
|
||||
return 127
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
raise SystemExit(main())
|
||||
+188
@@ -0,0 +1,188 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Trace FIFA17 provider delivery lookup without heap-address assumptions.
|
||||
|
||||
The probe anchors the real CardsDLL call sequence in FUN_1801a4cd0 and the
|
||||
provider-specific FUT_CREATE_MATCH_DP readiness check in FUN_1800be500:
|
||||
|
||||
vslot +0x38 call -> create gate return -> returned target -> UI bridge
|
||||
|
||||
For FUT_CREATE_MATCH_DP and FUT_GET_MATCH_KITS_DP it records the live controller
|
||||
vtable, concrete lookup function, event service, readiness-gate implementation,
|
||||
every register input, returned target, and whether the native-to-UI bridge
|
||||
executes. No post-event object identity is used.
|
||||
|
||||
The generated GDB program uses hardware-assisted execution breakpoints only.
|
||||
It never writes client memory and never drives game input.
|
||||
|
||||
match_delivery_lifecycle_trace.py [pid] [--output PATH]
|
||||
match_delivery_lifecycle_trace.py --print-script [pid]
|
||||
match_delivery_lifecycle_trace.py --selftest
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
import os
|
||||
from pathlib import Path
|
||||
import shutil
|
||||
import sys
|
||||
|
||||
sys.path.insert(0, str(Path(__file__).resolve().parent))
|
||||
import match_advance_trace as advance
|
||||
import match_transition_trace as transition
|
||||
|
||||
LOOKUP_CALL_RVA = transition.PROVIDER_DISPATCH_RVA + 0x2C
|
||||
LOOKUP_RETURN_RVA = transition.PROVIDER_DISPATCH_RVA + 0x2F
|
||||
BRIDGE_CALL_RVA = transition.PROVIDER_DISPATCH_RVA + 0x71
|
||||
CREATE_GATE_RETURN_RVA = 0x0BE647
|
||||
|
||||
|
||||
def trace_addresses(cards_base: int) -> dict[str, int]:
|
||||
return {
|
||||
"lookup_call": cards_base + LOOKUP_CALL_RVA,
|
||||
"gate_return": cards_base + CREATE_GATE_RETURN_RVA,
|
||||
"lookup_return": cards_base + LOOKUP_RETURN_RVA,
|
||||
"bridge": cards_base + BRIDGE_CALL_RVA,
|
||||
}
|
||||
|
||||
|
||||
def build_gdb_script(pid: int, cards_base: int, output: str) -> str:
|
||||
if any(character in output for character in "\n\r"):
|
||||
raise ValueError("output path cannot contain a newline")
|
||||
address = trace_addresses(cards_base)
|
||||
return f"""set pagination off
|
||||
set confirm off
|
||||
set print thread-events off
|
||||
set breakpoint always-inserted on
|
||||
set logging file {output}
|
||||
set logging overwrite on
|
||||
set logging redirect off
|
||||
set logging enabled on
|
||||
handle SIGSEGV nostop noprint pass
|
||||
handle SIGILL nostop noprint pass
|
||||
handle SIGFPE nostop noprint pass
|
||||
handle SIGPIPE nostop noprint pass
|
||||
handle SIGALRM nostop noprint pass
|
||||
handle SIGUSR1 nostop noprint pass
|
||||
handle SIGUSR2 nostop noprint pass
|
||||
|
||||
attach {pid}
|
||||
set $current_provider = 0
|
||||
set $current_payload = 0
|
||||
set $current_controller = 0
|
||||
set $current_vtable = 0
|
||||
set $current_lookup = 0
|
||||
set $current_service = 0
|
||||
set $current_service_vtable = 0
|
||||
set $current_gate = 0
|
||||
|
||||
hbreak *0x{address['lookup_call']:x}
|
||||
condition 1 $edi == 0x{transition.FUT_CREATE_MATCH_DP:x} || $edi == 0x{transition.FUT_GET_MATCH_KITS_DP:x}
|
||||
commands
|
||||
silent
|
||||
set $current_provider = $edi
|
||||
set $current_payload = $rbp
|
||||
set $current_controller = $rcx
|
||||
set $current_vtable = *(void**)$rcx
|
||||
set $current_lookup = *(void**)(*(void**)$rcx+0x38)
|
||||
set $current_service = *(void**)($rcx+0x18)
|
||||
set $current_service_vtable = *(void**)$current_service
|
||||
set $current_gate = *(void**)($current_service_vtable+0x58)
|
||||
python import time; print("LOOKUPTRACE epoch_ns=%d mono_ns=%d LOOKUP_CALL" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d provider=%#x this=%p outer_controller=%p payload=%p vtable=%p lookup_fn=%p service=%p service_vtable=%p gate_fn=%p controller_mode=%#x controller_flag=%#x rdx=%p r8=%p r9=%p state_rbx=%p state_rbp=%p\\n", $_thread, $edi, $rcx, $rbx, $rbp, $current_vtable, $current_lookup, $current_service, $current_service_vtable, $current_gate, *(unsigned int*)($rcx+0x140), *(unsigned char*)($rcx+0x152), $rdx, $r8, $r9, $rbx, $rbp
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['gate_return']:x}
|
||||
condition 2 $current_provider == 0x{transition.FUT_CREATE_MATCH_DP:x} && $rbx == $current_controller
|
||||
commands
|
||||
silent
|
||||
python import time; print("LOOKUPTRACE epoch_ns=%d mono_ns=%d CREATE_GATE_RETURN" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d provider=%#x controller=%p service=%p service_vtable=%p gate_fn=%p selector=0x7546 result_al=%#x\\n", $_thread, $current_provider, $current_controller, $current_service, $current_service_vtable, $current_gate, $al
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['lookup_return']:x}
|
||||
condition 3 $edi == 0x{transition.FUT_CREATE_MATCH_DP:x} || $edi == 0x{transition.FUT_GET_MATCH_KITS_DP:x}
|
||||
commands
|
||||
silent
|
||||
python import time; print("LOOKUPTRACE epoch_ns=%d mono_ns=%d LOOKUP_RETURN" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d provider=%#x controller=%p payload=%p vtable=%p lookup_fn=%p result=%p\\n", $_thread, $edi, $rbx, $rbp, $current_vtable, $current_lookup, $rax
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['bridge']:x}
|
||||
condition 4 $edi == 0x{transition.FUT_CREATE_MATCH_DP:x} || $edi == 0x{transition.FUT_GET_MATCH_KITS_DP:x}
|
||||
commands
|
||||
silent
|
||||
python import time; print("LOOKUPTRACE epoch_ns=%d mono_ns=%d BRIDGE" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d provider=%#x controller=%p payload=%p target=%p bridge=%p callback=%p\\n", $_thread, $edi, $current_controller, $current_payload, $rsi, $rbx, *(void**)(*(void**)$rbx+0x48)
|
||||
continue
|
||||
end
|
||||
|
||||
printf "LOOKUPTRACE ARMED pid={pid} lookup_call=0x{address['lookup_call']:x} gate_return=0x{address['gate_return']:x} lookup_return=0x{address['lookup_return']:x} bridge=0x{address['bridge']:x}\\n"
|
||||
continue
|
||||
"""
|
||||
|
||||
|
||||
def selftest() -> None:
|
||||
address = trace_addresses(0x180000000)
|
||||
assert address == {
|
||||
"lookup_call": 0x1801A4CFC,
|
||||
"gate_return": 0x1800BE647,
|
||||
"lookup_return": 0x1801A4CFF,
|
||||
"bridge": 0x1801A4D41,
|
||||
}
|
||||
script = build_gdb_script(35632, 0x180000000, "/tmp/lookup.log")
|
||||
assert script.count("hbreak *") == 4
|
||||
assert f"$edi == 0x{transition.FUT_CREATE_MATCH_DP:x}" in script
|
||||
assert f"$edi == 0x{transition.FUT_GET_MATCH_KITS_DP:x}" in script
|
||||
assert "LOOKUP_CALL" in script
|
||||
assert "CREATE_GATE_RETURN" in script
|
||||
assert "LOOKUP_RETURN" in script
|
||||
assert "gate_fn" in script
|
||||
assert "BRIDGE" in script
|
||||
assert "set *(" not in script
|
||||
print("match_delivery_lifecycle_trace selftest: PASS")
|
||||
|
||||
|
||||
def main() -> int:
|
||||
parser = argparse.ArgumentParser(description=__doc__)
|
||||
parser.add_argument("pid", nargs="?", type=int)
|
||||
parser.add_argument("--output")
|
||||
parser.add_argument("--print-script", action="store_true")
|
||||
parser.add_argument("--selftest", action="store_true")
|
||||
args = parser.parse_args()
|
||||
if args.selftest:
|
||||
selftest()
|
||||
return 0
|
||||
|
||||
pid = args.pid or transition.find_pid()
|
||||
if not pid:
|
||||
print("FIFA17.exe not found", file=sys.stderr)
|
||||
return 2
|
||||
try:
|
||||
cards_base, cards_path = transition.cards_mapping(pid)
|
||||
transition.validate_cards(cards_path)
|
||||
_fifa_base, fifa_path = advance.module_mapping(pid, advance.FIFA_MODULE)
|
||||
advance.validate_file(fifa_path, advance.PINNED_FIFA_SHA256, advance.FIFA_MODULE)
|
||||
output = args.output or f"/tmp/fifa17-match-provider-lookup-{pid}.log"
|
||||
script = build_gdb_script(pid, cards_base, output)
|
||||
except (OSError, RuntimeError, ValueError) as error:
|
||||
print(error, file=sys.stderr)
|
||||
return 2
|
||||
|
||||
if args.print_script:
|
||||
print(script, end="")
|
||||
return 0
|
||||
if not shutil.which("gdb"):
|
||||
print("gdb not found", file=sys.stderr)
|
||||
return 2
|
||||
script_path = f"/tmp/fifa17-match-provider-lookup-{pid}.gdb"
|
||||
with open(script_path, "w", encoding="utf-8") as handle:
|
||||
handle.write(script)
|
||||
os.execvp("gdb", ["gdb", "-q", "-nx", "-batch", "-x", script_path])
|
||||
return 127
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
raise SystemExit(main())
|
||||
+231
@@ -0,0 +1,231 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Trace FIFA17's post-kit handoff into the gameplay loading state.
|
||||
|
||||
The probe anchors the second ACTION_SAVE_MATCH_KIT (0x7576), captures the
|
||||
select-team deleting destructor with its real caller, records entry to the
|
||||
Gameplay::ScenarioModeStart consumer with the state it would advance, and
|
||||
identifies the first TestingGame update after the boundary.
|
||||
|
||||
The generated GDB program uses four hardware-assisted execution breakpoints.
|
||||
It never writes client memory, calls client functions, drives input, emits
|
||||
actions, or changes timing deliberately.
|
||||
|
||||
match_drill_transition_trace.py [pid] [--output PATH]
|
||||
match_drill_transition_trace.py --print-script [pid]
|
||||
match_drill_transition_trace.py --selftest
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
import os
|
||||
from pathlib import Path
|
||||
import shutil
|
||||
import sys
|
||||
|
||||
sys.path.insert(0, str(Path(__file__).resolve().parent))
|
||||
import match_advance_trace as advance
|
||||
import match_transition_trace as transition
|
||||
|
||||
SAVE_KIT_ACTION = 0x7576
|
||||
SAVE_ACTION_RVA = 0x0BFCC0
|
||||
SELECT_TEAM_DELETING_DESTRUCTOR_RVA = 0x0BE020
|
||||
TESTING_GAME_UPDATE_RVA = 0x05A410C8
|
||||
SCENARIO_MODE_START_HANDLER_RVA = 0x05A58EC0
|
||||
TESTING_GAME_VTABLE_RVA = 0x035C58A8
|
||||
TESTING_GAME_STATE_VTABLE_RVA = 0x035C2EE0
|
||||
|
||||
OWNER_STATE_OFFSET = 0x1958
|
||||
STATE_GAME_DATABASE_OFFSET = 0x17450
|
||||
STATE_PHASE_OFFSET = 0x27BEC
|
||||
STATE_SCENARIO_MODE_START_GATE_OFFSET = 0x359E8
|
||||
DATABASE_IS_SKILL_GAME_OFFSET = 0x7382
|
||||
DATABASE_TEAM_PAIR_OFFSET = 0x73C4
|
||||
|
||||
|
||||
def trace_addresses(cards_base: int, fifa_base: int) -> dict[str, int]:
|
||||
return {
|
||||
"save_action": cards_base + SAVE_ACTION_RVA,
|
||||
"deleting_destructor": cards_base + SELECT_TEAM_DELETING_DESTRUCTOR_RVA,
|
||||
"testing_game_update": fifa_base + TESTING_GAME_UPDATE_RVA,
|
||||
"scenario_mode_start_handler": fifa_base + SCENARIO_MODE_START_HANDLER_RVA,
|
||||
"testing_game_vtable": fifa_base + TESTING_GAME_VTABLE_RVA,
|
||||
"testing_game_state_vtable": fifa_base + TESTING_GAME_STATE_VTABLE_RVA,
|
||||
}
|
||||
|
||||
|
||||
def build_gdb_script(
|
||||
pid: int,
|
||||
cards_base: int,
|
||||
fifa_base: int,
|
||||
output: str,
|
||||
) -> str:
|
||||
if any(character in output for character in "\n\r"):
|
||||
raise ValueError("output path cannot contain a newline")
|
||||
address = trace_addresses(cards_base, fifa_base)
|
||||
return f"""set pagination off
|
||||
set confirm off
|
||||
set print thread-events off
|
||||
set breakpoint always-inserted on
|
||||
set logging file {output}
|
||||
set logging overwrite on
|
||||
set logging redirect off
|
||||
set logging enabled on
|
||||
handle SIGSEGV nostop noprint pass
|
||||
handle SIGILL nostop noprint pass
|
||||
handle SIGFPE nostop noprint pass
|
||||
handle SIGPIPE nostop noprint pass
|
||||
handle SIGALRM nostop noprint pass
|
||||
handle SIGUSR1 nostop noprint pass
|
||||
handle SIGUSR2 nostop noprint pass
|
||||
|
||||
attach {pid}
|
||||
set $save_count = 0
|
||||
set $current_controller = 0
|
||||
set $engine_seen = 0
|
||||
|
||||
hbreak *0x{address['save_action']:x}
|
||||
commands
|
||||
silent
|
||||
if $edx == 0x{SAVE_KIT_ACTION:x}
|
||||
set $save_count = $save_count + 1
|
||||
set $current_controller = $rcx
|
||||
python import time; print("DRILLTRACE epoch_ns=%d mono_ns=%d SAVE_ACTION" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d ordinal=%d action=%#x controller=%p payload=%p second_boundary=%d\\n", $_thread, $save_count, $edx, $rcx, $r8, $save_count==2
|
||||
if $save_count == 2
|
||||
disable 1
|
||||
end
|
||||
end
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['deleting_destructor']:x}
|
||||
condition 2 $save_count >= 2 && $rcx == $current_controller
|
||||
commands
|
||||
silent
|
||||
python import time; print("DRILLTRACE epoch_ns=%d mono_ns=%d SELECT_TEAM_DELETING_DESTRUCTOR" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d controller=%p delete_flags=%#x caller_return=%p vtable=%p\\n", $_thread, $rcx, $edx, *(void**)$rsp, *(void**)$rcx
|
||||
x/16gx $rsp
|
||||
bt 12
|
||||
disable 2
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['scenario_mode_start_handler']:x}
|
||||
commands
|
||||
silent
|
||||
set $scenario_wrapper = $rcx
|
||||
set $scenario_state = *(void**)($scenario_wrapper+0x30)
|
||||
set $scenario_payload = $r9
|
||||
python import time; print("DRILLTRACE epoch_ns=%d mono_ns=%d SCENARIO_MODE_START" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
if $scenario_state != 0
|
||||
set $scenario_database = *(void**)($scenario_state+0x{STATE_GAME_DATABASE_OFFSET:x})
|
||||
if $scenario_database != 0
|
||||
printf "thread=%d wrapper=%p state=%p payload=%p phase=%d alternate_gate=%d is_skill_game=%d caller_return=%p\\n", $_thread, $scenario_wrapper, $scenario_state, $scenario_payload, *(unsigned int*)($scenario_state+0x{STATE_PHASE_OFFSET:x}), *(unsigned char*)($scenario_state+0x{STATE_SCENARIO_MODE_START_GATE_OFFSET:x}), *(unsigned char*)($scenario_database+0x{DATABASE_IS_SKILL_GAME_OFFSET:x}), *(void**)$rsp
|
||||
else
|
||||
printf "thread=%d wrapper=%p state=%p payload=%p database=0 caller_return=%p\\n", $_thread, $scenario_wrapper, $scenario_state, $scenario_payload, *(void**)$rsp
|
||||
end
|
||||
else
|
||||
printf "thread=%d wrapper=%p state=0 payload=%p caller_return=%p\\n", $_thread, $scenario_wrapper, $scenario_payload, *(void**)$rsp
|
||||
end
|
||||
bt 12
|
||||
disable 3
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['testing_game_update']:x}
|
||||
condition 4 $save_count >= 2 && $engine_seen == 0
|
||||
commands
|
||||
silent
|
||||
set $owner = $rsi
|
||||
set $state = *(void**)($owner+0x{OWNER_STATE_OFFSET:x})
|
||||
if $state != 0 && *(void**)$owner == 0x{address['testing_game_vtable']:x} && *(void**)$state == 0x{address['testing_game_state_vtable']:x}
|
||||
set $database = *(void**)($state+0x{STATE_GAME_DATABASE_OFFSET:x})
|
||||
if $database != 0
|
||||
set $engine_seen = 1
|
||||
python import time; print("DRILLTRACE epoch_ns=%d mono_ns=%d ENGINE_HANDOFF" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d owner=%p owner_vtable=%p state=%p state_vtable=%p database=%p phase=%d is_skill_game=%d teams=%d,%d\\n", $_thread, $owner, *(void**)$owner, $state, *(void**)$state, $database, *(unsigned int*)($state+0x{STATE_PHASE_OFFSET:x}), *(unsigned char*)($database+0x{DATABASE_IS_SKILL_GAME_OFFSET:x}), *(unsigned int*)($database+0x{DATABASE_TEAM_PAIR_OFFSET:x}), *(unsigned int*)($database+0x{DATABASE_TEAM_PAIR_OFFSET + 4:x})
|
||||
bt 12
|
||||
disable 4
|
||||
end
|
||||
end
|
||||
continue
|
||||
end
|
||||
|
||||
printf "DRILLTRACE ARMED pid={pid} save_action=0x{address['save_action']:x} deleting_destructor=0x{address['deleting_destructor']:x} scenario_mode_start_handler=0x{address['scenario_mode_start_handler']:x} testing_game_update=0x{address['testing_game_update']:x}\\n"
|
||||
continue
|
||||
"""
|
||||
|
||||
|
||||
def selftest() -> None:
|
||||
address = trace_addresses(0x180000000, 0x140000000)
|
||||
assert address == {
|
||||
"save_action": 0x1800BFCC0,
|
||||
"deleting_destructor": 0x1800BE020,
|
||||
"testing_game_update": 0x145A410C8,
|
||||
"scenario_mode_start_handler": 0x145A58EC0,
|
||||
"testing_game_vtable": 0x1435C58A8,
|
||||
"testing_game_state_vtable": 0x1435C2EE0,
|
||||
}
|
||||
script = build_gdb_script(
|
||||
49938,
|
||||
0x180000000,
|
||||
0x140000000,
|
||||
"/tmp/drill-transition.log",
|
||||
)
|
||||
assert script.count("hbreak *") == 4
|
||||
assert "SELECT_TEAM_DELETING_DESTRUCTOR" in script
|
||||
assert "SCENARIO_MODE_START" in script
|
||||
assert "wrapper=%p state=%p payload=%p" in script
|
||||
assert "alternate_gate=%d" in script
|
||||
assert "skill_game_start_constructor" not in script
|
||||
assert "ENGINE_HANDOFF" in script
|
||||
assert "GameplayGameDatabase.IsSkillGame" not in script
|
||||
assert "set *(" not in script
|
||||
print("match_drill_transition_trace selftest: PASS")
|
||||
|
||||
|
||||
def main() -> int:
|
||||
parser = argparse.ArgumentParser(description=__doc__)
|
||||
parser.add_argument("pid", nargs="?", type=int)
|
||||
parser.add_argument("--output")
|
||||
parser.add_argument("--print-script", action="store_true")
|
||||
parser.add_argument("--selftest", action="store_true")
|
||||
args = parser.parse_args()
|
||||
if args.selftest:
|
||||
selftest()
|
||||
return 0
|
||||
|
||||
pid = args.pid or transition.find_pid()
|
||||
if not pid:
|
||||
print("FIFA17.exe not found", file=sys.stderr)
|
||||
return 2
|
||||
try:
|
||||
cards_base, cards_path = transition.cards_mapping(pid)
|
||||
transition.validate_cards(cards_path)
|
||||
fifa_base, fifa_path = advance.module_mapping(pid, advance.FIFA_MODULE)
|
||||
advance.validate_file(
|
||||
fifa_path,
|
||||
advance.PINNED_FIFA_SHA256,
|
||||
advance.FIFA_MODULE,
|
||||
)
|
||||
output = args.output or f"/tmp/fifa17-match-drill-transition-{pid}.log"
|
||||
script = build_gdb_script(pid, cards_base, fifa_base, output)
|
||||
except (OSError, RuntimeError, ValueError) as error:
|
||||
print(error, file=sys.stderr)
|
||||
return 2
|
||||
|
||||
if args.print_script:
|
||||
print(script, end="")
|
||||
return 0
|
||||
if not shutil.which("gdb"):
|
||||
print("gdb not found", file=sys.stderr)
|
||||
return 2
|
||||
script_path = f"/tmp/fifa17-match-drill-transition-{pid}.gdb"
|
||||
with open(script_path, "w", encoding="utf-8") as handle:
|
||||
handle.write(script)
|
||||
os.execvp("gdb", ["gdb", "-q", "-nx", "-batch", "-x", script_path])
|
||||
return 127
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
raise SystemExit(main())
|
||||
Executable
+185
@@ -0,0 +1,185 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Trace FIFA17's post-kit boundary without changing client behavior.
|
||||
|
||||
The probe anchors both ACTION_SAVE_MATCH_KIT (0x7576) actions, their concrete
|
||||
native save call, the action-handler return, and select-team provider teardown.
|
||||
The second 0x7576 action is the temporal boundary for later drill/game-loader
|
||||
instrumentation.
|
||||
|
||||
The generated GDB program uses four hardware-assisted execution breakpoints. It
|
||||
never writes client memory, calls client functions, drives input, emits actions,
|
||||
or alters timing deliberately.
|
||||
|
||||
match_post_kit_trace.py [pid] [--output PATH]
|
||||
match_post_kit_trace.py --print-script [pid]
|
||||
match_post_kit_trace.py --selftest
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
import os
|
||||
from pathlib import Path
|
||||
import shutil
|
||||
import sys
|
||||
|
||||
sys.path.insert(0, str(Path(__file__).resolve().parent))
|
||||
import match_advance_trace as advance
|
||||
import match_transition_trace as transition
|
||||
|
||||
SAVE_KIT_ACTION = 0x7576
|
||||
ACTION_HANDLER_RVA = 0x0BFCC0
|
||||
SAVE_CALL_RVA = 0x0BFF25
|
||||
ACTION_RETURN_RVA = 0x0C00AE
|
||||
SELECT_TEAM_DESTRUCTOR_RVA = 0x0BDEC0
|
||||
|
||||
|
||||
def trace_addresses(cards_base: int) -> dict[str, int]:
|
||||
return {
|
||||
"action": cards_base + ACTION_HANDLER_RVA,
|
||||
"save_call": cards_base + SAVE_CALL_RVA,
|
||||
"action_return": cards_base + ACTION_RETURN_RVA,
|
||||
"destructor": cards_base + SELECT_TEAM_DESTRUCTOR_RVA,
|
||||
}
|
||||
|
||||
|
||||
def build_gdb_script(pid: int, cards_base: int, output: str) -> str:
|
||||
if any(character in output for character in "\n\r"):
|
||||
raise ValueError("output path cannot contain a newline")
|
||||
address = trace_addresses(cards_base)
|
||||
return f"""set pagination off
|
||||
set confirm off
|
||||
set print thread-events off
|
||||
set breakpoint always-inserted on
|
||||
set logging file {output}
|
||||
set logging overwrite on
|
||||
set logging redirect off
|
||||
set logging enabled on
|
||||
handle SIGSEGV nostop noprint pass
|
||||
handle SIGILL nostop noprint pass
|
||||
handle SIGFPE nostop noprint pass
|
||||
handle SIGPIPE nostop noprint pass
|
||||
handle SIGALRM nostop noprint pass
|
||||
handle SIGUSR1 nostop noprint pass
|
||||
handle SIGUSR2 nostop noprint pass
|
||||
|
||||
attach {pid}
|
||||
set $save_count = 0
|
||||
set $current_action = 0
|
||||
set $current_controller = 0
|
||||
set $current_payload = 0
|
||||
set $second_save_epoch = 0
|
||||
|
||||
hbreak *0x{address['action']:x}
|
||||
condition 1 $edx == 0x{SAVE_KIT_ACTION:x}
|
||||
commands
|
||||
silent
|
||||
set $save_count = $save_count + 1
|
||||
set $current_action = $edx
|
||||
set $current_controller = $rcx
|
||||
set $current_payload = $r8
|
||||
python import time, gdb; now = time.time_ns(); gdb.set_convenience_variable("event_epoch", now); print("POSTKIT epoch_ns=%d mono_ns=%d SAVE_ACTION" % (now, time.monotonic_ns()), end=" ")
|
||||
if $save_count == 2
|
||||
set $second_save_epoch = $event_epoch
|
||||
end
|
||||
printf "thread=%d ordinal=%d action=%#x controller=%p payload=%p payload_vtable=%p mode=%#x flags_150=%#x flags_151=%#x flags_152=%#x flags_155=%#x second_boundary=%d\\n", $_thread, $save_count, $edx, $rcx, $r8, *(void**)$r8, *(unsigned int*)($rcx+0x140), *(unsigned char*)($rcx+0x150), *(unsigned char*)($rcx+0x151), *(unsigned char*)($rcx+0x152), *(unsigned char*)($rcx+0x155), $save_count==2
|
||||
bt 10
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['save_call']:x}
|
||||
condition 2 $current_action == 0x{SAVE_KIT_ACTION:x}
|
||||
commands
|
||||
silent
|
||||
set $save_target = *(void**)(*(void**)$rcx+0x1d0)
|
||||
python import time; print("POSTKIT epoch_ns=%d mono_ns=%d NATIVE_SAVE_CALL" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d ordinal=%d central=%p central_vtable=%p target=%p side=%#x request=%p payload=%p\\n", $_thread, $save_count, $rcx, *(void**)$rcx, $save_target, $r8d, $rdx, $current_payload
|
||||
x/12gx $rdx
|
||||
bt 10
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['action_return']:x}
|
||||
condition 3 $current_action == 0x{SAVE_KIT_ACTION:x} && $rsi == $current_controller
|
||||
commands
|
||||
silent
|
||||
python import time; print("POSTKIT epoch_ns=%d mono_ns=%d ACTION_RETURN" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d ordinal=%d controller=%p handled=%#x mode=%#x flags_150=%#x flags_151=%#x flags_152=%#x flags_155=%#x\\n", $_thread, $save_count, $rsi, $al, *(unsigned int*)($rsi+0x140), *(unsigned char*)($rsi+0x150), *(unsigned char*)($rsi+0x151), *(unsigned char*)($rsi+0x152), *(unsigned char*)($rsi+0x155)
|
||||
set $current_action = 0
|
||||
bt 10
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['destructor']:x}
|
||||
condition 4 $save_count >= 2 && $rcx == $current_controller
|
||||
commands
|
||||
silent
|
||||
python import time; print("POSTKIT epoch_ns=%d mono_ns=%d SELECT_TEAM_DESTRUCTOR" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d controller=%p save_count=%d second_save_epoch=%lld vtable=%p mode=%#x\\n", $_thread, $rcx, $save_count, $second_save_epoch, *(void**)$rcx, *(unsigned int*)($rcx+0x140)
|
||||
bt 12
|
||||
continue
|
||||
end
|
||||
|
||||
printf "POSTKIT ARMED pid={pid} action=0x{address['action']:x} save_call=0x{address['save_call']:x} action_return=0x{address['action_return']:x} destructor=0x{address['destructor']:x}\\n"
|
||||
continue
|
||||
"""
|
||||
|
||||
|
||||
def selftest() -> None:
|
||||
address = trace_addresses(0x180000000)
|
||||
assert address == {
|
||||
"action": 0x1800BFCC0,
|
||||
"save_call": 0x1800BFF25,
|
||||
"action_return": 0x1800C00AE,
|
||||
"destructor": 0x1800BDEC0,
|
||||
}
|
||||
script = build_gdb_script(47872, 0x180000000, "/tmp/post-kit.log")
|
||||
assert script.count("hbreak *") == 4
|
||||
assert f"$edx == 0x{SAVE_KIT_ACTION:x}" in script
|
||||
assert "second_boundary" in script
|
||||
assert "NATIVE_SAVE_CALL" in script
|
||||
assert "SELECT_TEAM_DESTRUCTOR" in script
|
||||
assert "set *(" not in script
|
||||
print("match_post_kit_trace selftest: PASS")
|
||||
|
||||
|
||||
def main() -> int:
|
||||
parser = argparse.ArgumentParser(description=__doc__)
|
||||
parser.add_argument("pid", nargs="?", type=int)
|
||||
parser.add_argument("--output")
|
||||
parser.add_argument("--print-script", action="store_true")
|
||||
parser.add_argument("--selftest", action="store_true")
|
||||
args = parser.parse_args()
|
||||
if args.selftest:
|
||||
selftest()
|
||||
return 0
|
||||
|
||||
pid = args.pid or transition.find_pid()
|
||||
if not pid:
|
||||
print("FIFA17.exe not found", file=sys.stderr)
|
||||
return 2
|
||||
try:
|
||||
cards_base, cards_path = transition.cards_mapping(pid)
|
||||
transition.validate_cards(cards_path)
|
||||
_fifa_base, fifa_path = advance.module_mapping(pid, advance.FIFA_MODULE)
|
||||
advance.validate_file(fifa_path, advance.PINNED_FIFA_SHA256, advance.FIFA_MODULE)
|
||||
output = args.output or f"/tmp/fifa17-match-post-kit-{pid}.log"
|
||||
script = build_gdb_script(pid, cards_base, output)
|
||||
except (OSError, RuntimeError, ValueError) as error:
|
||||
print(error, file=sys.stderr)
|
||||
return 2
|
||||
|
||||
if args.print_script:
|
||||
print(script, end="")
|
||||
return 0
|
||||
if not shutil.which("gdb"):
|
||||
print("gdb not found", file=sys.stderr)
|
||||
return 2
|
||||
script_path = f"/tmp/fifa17-match-post-kit-{pid}.gdb"
|
||||
with open(script_path, "w", encoding="utf-8") as handle:
|
||||
handle.write(script)
|
||||
os.execvp("gdb", ["gdb", "-q", "-nx", "-batch", "-x", script_path])
|
||||
return 127
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
raise SystemExit(main())
|
||||
+201
@@ -0,0 +1,201 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Trace FIFA17 create-response readiness versus UI provider dispatch.
|
||||
|
||||
The probe correlates four concrete lifecycle boundaries:
|
||||
|
||||
* FutCreateMatchServerResponse data-source request;
|
||||
* the POST /match network response callback;
|
||||
* the response readiness/completion callback;
|
||||
* FIFA's global UI dispatch of providers 0x7563 and 0x7565.
|
||||
|
||||
This distinguishes network completion from the separate DataManager readiness
|
||||
lifecycle without assuming any screen or heap-object identity. The generated GDB
|
||||
program uses hardware-assisted execution breakpoints only. It never writes
|
||||
client memory and never drives game input.
|
||||
|
||||
match_provider_producer_trace.py [pid] [--output PATH]
|
||||
match_provider_producer_trace.py --print-script [pid]
|
||||
match_provider_producer_trace.py --selftest
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
import os
|
||||
from pathlib import Path
|
||||
import shutil
|
||||
import sys
|
||||
|
||||
sys.path.insert(0, str(Path(__file__).resolve().parent))
|
||||
import match_advance_trace as advance
|
||||
import match_transition_trace as transition
|
||||
|
||||
DATA_SOURCE_REQUEST_RVA = 0x120270
|
||||
NETWORK_RESPONSE_RVA = transition.RESPONSE_CALLBACK_RVA
|
||||
CREATE_COMPLETE_RVA = 0x120000
|
||||
GLOBAL_UI_DISPATCH_RVA = advance.GLOBAL_UI_DISPATCH_RVA
|
||||
CREATE_RESPONSE_OFFSET = 0xA0
|
||||
CREATE_DATA_SOURCE_OFFSET = CREATE_RESPONSE_OFFSET + 0x50
|
||||
CREATE_READY_OFFSET = CREATE_RESPONSE_OFFSET + 0x88
|
||||
ACTIVE_CALLBACK_OFFSET = 0x47D0
|
||||
|
||||
|
||||
def trace_addresses(cards_base: int, fifa_base: int) -> dict[str, int]:
|
||||
return {
|
||||
"data_source_request": cards_base + DATA_SOURCE_REQUEST_RVA,
|
||||
"network_response": cards_base + NETWORK_RESPONSE_RVA,
|
||||
"create_complete": cards_base + CREATE_COMPLETE_RVA,
|
||||
"ui_dispatch": fifa_base + GLOBAL_UI_DISPATCH_RVA,
|
||||
}
|
||||
|
||||
|
||||
def build_gdb_script(
|
||||
pid: int, cards_base: int, fifa_base: int, output: str
|
||||
) -> str:
|
||||
if any(character in output for character in "\n\r"):
|
||||
raise ValueError("output path cannot contain a newline")
|
||||
address = trace_addresses(cards_base, fifa_base)
|
||||
return f"""set pagination off
|
||||
set confirm off
|
||||
set print thread-events off
|
||||
set breakpoint always-inserted on
|
||||
set logging file {output}
|
||||
set logging overwrite on
|
||||
set logging redirect off
|
||||
set logging enabled on
|
||||
handle SIGSEGV nostop noprint pass
|
||||
handle SIGILL nostop noprint pass
|
||||
handle SIGFPE nostop noprint pass
|
||||
handle SIGPIPE nostop noprint pass
|
||||
handle SIGALRM nostop noprint pass
|
||||
handle SIGUSR1 nostop noprint pass
|
||||
handle SIGUSR2 nostop noprint pass
|
||||
|
||||
attach {pid}
|
||||
set $last_central = 0
|
||||
set $last_response = 0
|
||||
set $last_data_source = 0
|
||||
set $last_descriptor = 0
|
||||
|
||||
hbreak *0x{address['data_source_request']:x}
|
||||
commands
|
||||
silent
|
||||
set $request_data_source = $rcx
|
||||
set $request_response = $rcx - 0x50
|
||||
python import time; print("RESPTRACE epoch_ns=%d mono_ns=%d DATA_SOURCE_REQUEST" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d response=%p data_source=%p request=%p ready_before=%#x callback_adapter=%p callback_context=%p callback_target=%p\\n", $_thread, $request_response, $request_data_source, $rdx, *(unsigned char*)($request_data_source+0x38), *(void**)($request_response+0x90), *(void**)($request_response+0x98), *(void**)($request_response+0xa0)
|
||||
bt 10
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['network_response']:x}
|
||||
commands
|
||||
silent
|
||||
set $last_central = $rcx
|
||||
set $last_response = $rcx + 0x{CREATE_RESPONSE_OFFSET:x}
|
||||
set $last_data_source = $rcx + 0x{CREATE_DATA_SOURCE_OFFSET:x}
|
||||
set $last_descriptor = $rdx
|
||||
python import time; print("RESPTRACE epoch_ns=%d mono_ns=%d NETWORK_RESPONSE" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
if $rdx == 0
|
||||
printf "thread=%d central=%p descriptor=(nil) status=UNKNOWN wire_payload=(nil) response=%p data_source=%p ready=%#x active_adapter=%p active_context=%p active_target=%p\\n", $_thread, $last_central, $last_response, $last_data_source, *(unsigned char*)($last_central+0x{CREATE_READY_OFFSET:x}), *(void**)($last_central+0x{ACTIVE_CALLBACK_OFFSET:x}), *(void**)($last_central+0x{ACTIVE_CALLBACK_OFFSET + 8:x}), *(void**)($last_central+0x{ACTIVE_CALLBACK_OFFSET + 16:x})
|
||||
else
|
||||
printf "thread=%d central=%p descriptor=%p status=%#x wire_payload=%p response=%p data_source=%p ready=%#x active_adapter=%p active_context=%p active_target=%p\\n", $_thread, $last_central, $rdx, *(unsigned int*)($rdx+0x1c), *(void**)($rdx+0x28), $last_response, $last_data_source, *(unsigned char*)($last_central+0x{CREATE_READY_OFFSET:x}), *(void**)($last_central+0x{ACTIVE_CALLBACK_OFFSET:x}), *(void**)($last_central+0x{ACTIVE_CALLBACK_OFFSET + 8:x}), *(void**)($last_central+0x{ACTIVE_CALLBACK_OFFSET + 16:x})
|
||||
end
|
||||
bt 10
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['create_complete']:x}
|
||||
commands
|
||||
silent
|
||||
python import time; print("RESPTRACE epoch_ns=%d mono_ns=%d CREATE_COMPLETE" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
if $rdx == 0
|
||||
printf "thread=%d response=%p data_source=%p ready_before=%#x descriptor=(nil) status=UNKNOWN last_response=%p same_response=%d\\n", $_thread, $rcx, $rcx+0x50, *(unsigned char*)($rcx+0x88), $last_response, $rcx==$last_response
|
||||
else
|
||||
printf "thread=%d response=%p data_source=%p ready_before=%#x descriptor=%p status=%#x last_response=%p same_response=%d\\n", $_thread, $rcx, $rcx+0x50, *(unsigned char*)($rcx+0x88), $rdx, *(unsigned int*)($rdx+0x1c), $last_response, $rcx==$last_response
|
||||
end
|
||||
bt 10
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['ui_dispatch']:x}
|
||||
condition 4 $r8d == 0x{transition.FUT_CREATE_MATCH_DP:x} || $r8d == 0x{transition.FUT_GET_MATCH_KITS_DP:x}
|
||||
commands
|
||||
silent
|
||||
python import time; print("RESPTRACE epoch_ns=%d mono_ns=%d UI_DISPATCH" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
if $last_response == 0
|
||||
printf "thread=%d provider=%#x payload=%p ui_manager=%p last_response=(nil) ready=UNKNOWN\\n", $_thread, $r8d, $rdx, $rcx
|
||||
else
|
||||
printf "thread=%d provider=%#x payload=%p ui_manager=%p last_response=%p data_source=%p ready=%#x descriptor=%p\\n", $_thread, $r8d, $rdx, $rcx, $last_response, $last_data_source, *(unsigned char*)($last_response+0x88), $last_descriptor
|
||||
end
|
||||
bt 10
|
||||
continue
|
||||
end
|
||||
|
||||
printf "RESPTRACE ARMED pid={pid} data_source_request=0x{address['data_source_request']:x} network_response=0x{address['network_response']:x} create_complete=0x{address['create_complete']:x} ui_dispatch=0x{address['ui_dispatch']:x}\\n"
|
||||
continue
|
||||
"""
|
||||
|
||||
|
||||
def selftest() -> None:
|
||||
address = trace_addresses(0x180000000, 0x140000000)
|
||||
assert address == {
|
||||
"data_source_request": 0x180120270,
|
||||
"network_response": 0x180114D90,
|
||||
"create_complete": 0x180120000,
|
||||
"ui_dispatch": 0x1480D1070,
|
||||
}
|
||||
script = build_gdb_script(
|
||||
38872, 0x180000000, 0x140000000, "/tmp/response-lifecycle.log"
|
||||
)
|
||||
assert script.count("hbreak *") == 4
|
||||
assert "DATA_SOURCE_REQUEST" in script
|
||||
assert "NETWORK_RESPONSE" in script
|
||||
assert "CREATE_COMPLETE" in script
|
||||
assert "UI_DISPATCH" in script
|
||||
assert f"$r8d == 0x{transition.FUT_CREATE_MATCH_DP:x}" in script
|
||||
assert f"$r8d == 0x{transition.FUT_GET_MATCH_KITS_DP:x}" in script
|
||||
assert "set *(" not in script
|
||||
print("match_provider_producer_trace selftest: PASS")
|
||||
|
||||
|
||||
def main() -> int:
|
||||
parser = argparse.ArgumentParser(description=__doc__)
|
||||
parser.add_argument("pid", nargs="?", type=int)
|
||||
parser.add_argument("--output")
|
||||
parser.add_argument("--print-script", action="store_true")
|
||||
parser.add_argument("--selftest", action="store_true")
|
||||
args = parser.parse_args()
|
||||
if args.selftest:
|
||||
selftest()
|
||||
return 0
|
||||
|
||||
pid = args.pid or transition.find_pid()
|
||||
if not pid:
|
||||
print("FIFA17.exe not found", file=sys.stderr)
|
||||
return 2
|
||||
try:
|
||||
cards_base, cards_path = transition.cards_mapping(pid)
|
||||
transition.validate_cards(cards_path)
|
||||
fifa_base, fifa_path = advance.module_mapping(pid, advance.FIFA_MODULE)
|
||||
advance.validate_file(fifa_path, advance.PINNED_FIFA_SHA256, advance.FIFA_MODULE)
|
||||
output = args.output or f"/tmp/fifa17-match-response-lifecycle-{pid}.log"
|
||||
script = build_gdb_script(pid, cards_base, fifa_base, output)
|
||||
except (OSError, RuntimeError, ValueError) as error:
|
||||
print(error, file=sys.stderr)
|
||||
return 2
|
||||
|
||||
if args.print_script:
|
||||
print(script, end="")
|
||||
return 0
|
||||
if not shutil.which("gdb"):
|
||||
print("gdb not found", file=sys.stderr)
|
||||
return 2
|
||||
script_path = f"/tmp/fifa17-match-response-lifecycle-{pid}.gdb"
|
||||
with open(script_path, "w", encoding="utf-8") as handle:
|
||||
handle.write(script)
|
||||
os.execvp("gdb", ["gdb", "-q", "-nx", "-batch", "-x", script_path])
|
||||
return 127
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
raise SystemExit(main())
|
||||
Executable
+233
@@ -0,0 +1,233 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Trace the FIFA17 create-match publish boundary with hardware breakpoints.
|
||||
|
||||
The tracer covers the client-local path after POST /match:
|
||||
|
||||
response callback -> deserializer -> controller event 0x7546
|
||||
-> FUT_CREATE_MATCH_DP 0x7563
|
||||
|
||||
FUT_GET_MATCH_KITS_DP 0x7565 is captured as the positive control through the
|
||||
same native dispatcher. The generated GDB program uses only hardware-assisted
|
||||
execution breakpoints. It never writes client memory and never drives game
|
||||
input.
|
||||
|
||||
match_transition_trace.py [pid] [--output PATH]
|
||||
match_transition_trace.py --print-script [pid]
|
||||
match_transition_trace.py --selftest
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
import glob
|
||||
import hashlib
|
||||
import os
|
||||
import shutil
|
||||
import sys
|
||||
|
||||
CARDS_MODULE = "CardsDLL_Win64_retail.dll"
|
||||
PINNED_CARDS_SHA256 = "4706a881ae1fc7b5769fd810b25a868d29d2b16a8e65a7513436327ef645573c"
|
||||
RESPONSE_CALLBACK_RVA = 0x114D90
|
||||
DESERIALIZE_SUCCESS_RVA = 0x118940
|
||||
CREATE_MATCH_CONTROLLER_RVA = 0xBF950
|
||||
PROVIDER_DISPATCH_RVA = 0x1A4CD0
|
||||
CREATE_MATCH_CONTROLLER_EVENT = 0x7546
|
||||
FUT_CREATE_MATCH_DP = 0x7563
|
||||
FUT_GET_MATCH_KITS_DP = 0x7565
|
||||
|
||||
|
||||
def find_pid() -> int | None:
|
||||
found = []
|
||||
for directory in glob.glob("/proc/[0-9]*"):
|
||||
try:
|
||||
with open(os.path.join(directory, "comm"), encoding="utf-8") as handle:
|
||||
if handle.read().strip() != "FIFA17.exe":
|
||||
continue
|
||||
pid = int(os.path.basename(directory))
|
||||
with open(os.path.join(directory, "statm"), encoding="utf-8") as handle:
|
||||
resident_pages = int(handle.read().split()[1])
|
||||
found.append((resident_pages, pid))
|
||||
except (OSError, ValueError, IndexError):
|
||||
continue
|
||||
return max(found)[1] if found else None
|
||||
|
||||
|
||||
def parse_cards_mapping(lines) -> tuple[int, str]:
|
||||
for line in lines:
|
||||
fields = line.split(maxsplit=5)
|
||||
path = fields[5].rstrip() if len(fields) == 6 else ""
|
||||
if not path.endswith(CARDS_MODULE):
|
||||
continue
|
||||
start = int(fields[0].split("-", 1)[0], 16)
|
||||
return start, path
|
||||
raise RuntimeError(f"{CARDS_MODULE} is not mapped")
|
||||
|
||||
|
||||
def cards_mapping(pid: int) -> tuple[int, str]:
|
||||
with open(f"/proc/{pid}/maps", encoding="utf-8") as handle:
|
||||
try:
|
||||
return parse_cards_mapping(handle)
|
||||
except RuntimeError as error:
|
||||
raise RuntimeError(f"{error} in PID {pid}") from error
|
||||
|
||||
|
||||
def sha256_file(path: str) -> str:
|
||||
digest = hashlib.sha256()
|
||||
with open(path, "rb") as handle:
|
||||
for chunk in iter(lambda: handle.read(1024 * 1024), b""):
|
||||
digest.update(chunk)
|
||||
return digest.hexdigest()
|
||||
|
||||
|
||||
def validate_cards(path: str) -> None:
|
||||
actual = sha256_file(path)
|
||||
if actual != PINNED_CARDS_SHA256:
|
||||
raise RuntimeError(
|
||||
f"unsupported {CARDS_MODULE}: sha256={actual}; expected={PINNED_CARDS_SHA256}"
|
||||
)
|
||||
|
||||
|
||||
def trace_addresses(base: int) -> dict[str, int]:
|
||||
return {
|
||||
"response": base + RESPONSE_CALLBACK_RVA,
|
||||
"deserialize": base + DESERIALIZE_SUCCESS_RVA,
|
||||
"controller": base + CREATE_MATCH_CONTROLLER_RVA,
|
||||
"provider": base + PROVIDER_DISPATCH_RVA,
|
||||
}
|
||||
|
||||
|
||||
def build_gdb_script(pid: int, base: int, output: str) -> str:
|
||||
if any(character in output for character in "\n\r"):
|
||||
raise ValueError("output path cannot contain a newline")
|
||||
address = trace_addresses(base)
|
||||
return f"""set pagination off
|
||||
set confirm off
|
||||
set print thread-events off
|
||||
set breakpoint always-inserted on
|
||||
set logging file {output}
|
||||
set logging overwrite on
|
||||
set logging redirect off
|
||||
set logging enabled on
|
||||
handle SIGSEGV nostop noprint pass
|
||||
handle SIGILL nostop noprint pass
|
||||
handle SIGFPE nostop noprint pass
|
||||
handle SIGPIPE nostop noprint pass
|
||||
handle SIGALRM nostop noprint pass
|
||||
handle SIGUSR1 nostop noprint pass
|
||||
handle SIGUSR2 nostop noprint pass
|
||||
|
||||
attach {pid}
|
||||
|
||||
hbreak *0x{address['response']:x}
|
||||
commands
|
||||
silent
|
||||
python import time; print("HWTRACE epoch_ns=%d mono_ns=%d T3_RESPONSE_CALLBACK" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
if $rdx != 0
|
||||
printf "thread=%d manager=%p status_obj=%p status=%u wire_payload=%p caller=%p\\n", $_thread, $rcx, $rdx, *(unsigned int*)($rdx+0x1c), *(void**)($rdx+0x28), *(void**)$rsp
|
||||
else
|
||||
printf "thread=%d manager=%p status_obj=0 caller=%p\\n", $_thread, $rcx, *(void**)$rsp
|
||||
end
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['deserialize']:x}
|
||||
commands
|
||||
silent
|
||||
python import time; print("HWTRACE epoch_ns=%d mono_ns=%d T4_DESERIALIZE_SUCCESS" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d manager=%p payload=%p caller=%p\\n", $_thread, $rcx, $rdx, *(void**)$rsp
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['controller']:x}
|
||||
condition 3 $edx == 0x{CREATE_MATCH_CONTROLLER_EVENT:x}
|
||||
commands
|
||||
silent
|
||||
python import time; print("HWTRACE epoch_ns=%d mono_ns=%d T5_CREATE_MATCH_CONTROLLER" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d controller_subobject=%p event=%#x caller=%p\\n", $_thread, $rcx, $edx, *(void**)$rsp
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['provider']:x}
|
||||
condition 4 $edx == 0x{FUT_CREATE_MATCH_DP:x} || $edx == 0x{FUT_GET_MATCH_KITS_DP:x}
|
||||
commands
|
||||
silent
|
||||
python import time; print("HWTRACE epoch_ns=%d mono_ns=%d T6_PROVIDER_DISPATCH" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d controller=%p provider=%#x payload=%p callback=%p\\n", $_thread, $rcx, $edx, $r8, *(void**)$rsp
|
||||
continue
|
||||
end
|
||||
|
||||
printf "HWTRACE ARMED pid={pid} response=0x{address['response']:x} deserialize=0x{address['deserialize']:x} controller=0x{address['controller']:x} provider=0x{address['provider']:x}\\n"
|
||||
continue
|
||||
"""
|
||||
|
||||
|
||||
def selftest() -> None:
|
||||
base = 0x180000000
|
||||
address = trace_addresses(base)
|
||||
assert address == {
|
||||
"response": 0x180114D90,
|
||||
"deserialize": 0x180118940,
|
||||
"controller": 0x1800BF950,
|
||||
"provider": 0x1801A4CD0,
|
||||
}
|
||||
mapping = parse_cards_mapping(
|
||||
[
|
||||
"6ffffc0f0000-6ffffc0f1000 r--p 00000000 00:37 2941670 "
|
||||
"/mnt/games/FIFA 17/CardsDLL_Win64_retail.dll\n"
|
||||
]
|
||||
)
|
||||
assert mapping == (
|
||||
0x6FFFFC0F0000,
|
||||
"/mnt/games/FIFA 17/CardsDLL_Win64_retail.dll",
|
||||
)
|
||||
script = build_gdb_script(25718, base, "/tmp/match-transition.log")
|
||||
assert script.count("hbreak *") == 4
|
||||
assert f"$edx == 0x{CREATE_MATCH_CONTROLLER_EVENT:x}" in script
|
||||
assert f"$edx == 0x{FUT_CREATE_MATCH_DP:x}" in script
|
||||
assert f"$edx == 0x{FUT_GET_MATCH_KITS_DP:x}" in script
|
||||
assert "T3_RESPONSE_CALLBACK" in script
|
||||
assert "T4_DESERIALIZE_SUCCESS" in script
|
||||
assert "T5_CREATE_MATCH_CONTROLLER" in script
|
||||
assert "T6_PROVIDER_DISPATCH" in script
|
||||
assert "set *(" not in script
|
||||
print("match_transition_trace selftest: PASS")
|
||||
|
||||
|
||||
def main() -> int:
|
||||
parser = argparse.ArgumentParser(description=__doc__)
|
||||
parser.add_argument("pid", nargs="?", type=int)
|
||||
parser.add_argument("--output")
|
||||
parser.add_argument("--print-script", action="store_true")
|
||||
parser.add_argument("--selftest", action="store_true")
|
||||
args = parser.parse_args()
|
||||
if args.selftest:
|
||||
selftest()
|
||||
return 0
|
||||
|
||||
pid = args.pid or find_pid()
|
||||
if not pid:
|
||||
print("FIFA17.exe not found", file=sys.stderr)
|
||||
return 2
|
||||
try:
|
||||
base, cards_path = cards_mapping(pid)
|
||||
validate_cards(cards_path)
|
||||
output = args.output or f"/tmp/fifa17-match-transition-{pid}.log"
|
||||
script = build_gdb_script(pid, base, output)
|
||||
except (OSError, RuntimeError, ValueError) as error:
|
||||
print(error, file=sys.stderr)
|
||||
return 2
|
||||
|
||||
if args.print_script:
|
||||
print(script, end="")
|
||||
return 0
|
||||
if not shutil.which("gdb"):
|
||||
print("gdb not found", file=sys.stderr)
|
||||
return 2
|
||||
script_path = f"/tmp/fifa17-match-transition-{pid}.gdb"
|
||||
with open(script_path, "w", encoding="utf-8") as handle:
|
||||
handle.write(script)
|
||||
os.execvp("gdb", ["gdb", "-q", "-nx", "-x", script_path])
|
||||
return 127
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
raise SystemExit(main())
|
||||
Executable
+306
@@ -0,0 +1,306 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Read-only dynamic locator for FIFA17 Offline Seasons match state.
|
||||
|
||||
Never relies on heap addresses or allocator handles. It identifies:
|
||||
|
||||
* the 10 x 16-byte parsed fixture array from its complete wire-derived record
|
||||
sequence (teamId/difficulty/roundId/rewardMult/coins),
|
||||
* match-team records from the corrected invariant prefix (11,7,0,0,76), never
|
||||
from the transient +0x18 handle,
|
||||
* the match-config team pair from structural fields around it, not its team ids.
|
||||
|
||||
offline_match_locator.py [pid] [--fixture-index 0] [--json]
|
||||
offline_match_locator.py --selftest
|
||||
|
||||
READ-ONLY: /proc/<pid>/mem is opened 'rb'. No debugger and no game input.
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
import glob
|
||||
import json
|
||||
import os
|
||||
import re
|
||||
import struct
|
||||
import sys
|
||||
from dataclasses import asdict, dataclass
|
||||
|
||||
DEFAULT_TEAMS = (73, 240, 241, 243, 73, 240, 241, 243, 73, 240)
|
||||
MATCH_HEADER = struct.pack("<5i", 11, 7, 0, 0, 76)
|
||||
PARTICIPANT_PREFIX = struct.pack("<8i", -1, -2, -1, -2, -1, -2, -1, -2)
|
||||
F01 = 0x3DCCCCCD
|
||||
|
||||
|
||||
@dataclass
|
||||
class Fixture:
|
||||
address: int
|
||||
selected_address: int
|
||||
selected_index: int
|
||||
selected_team_id: int
|
||||
records: list[dict[str, int]]
|
||||
|
||||
|
||||
@dataclass
|
||||
class MatchTeam:
|
||||
address: int
|
||||
team_id: int
|
||||
marker_18: int
|
||||
marker_1c: int
|
||||
xi: list[int]
|
||||
substitutes: list[int]
|
||||
|
||||
|
||||
@dataclass
|
||||
class MatchConfig:
|
||||
pair_address: int
|
||||
team_id_0: int
|
||||
team_id_1: int
|
||||
player_count_0: int
|
||||
player_count_1: int
|
||||
|
||||
|
||||
def find_pids() -> list[int]:
|
||||
"""All live FIFA17.exe processes, largest resident set first.
|
||||
|
||||
The UMU/Proton launch chain briefly creates a small process with the same
|
||||
comm before the real game. Returning the first /proc glob match attached
|
||||
the trace supervisor to that short-lived process and missed the match.
|
||||
"""
|
||||
found = []
|
||||
for directory in glob.glob("/proc/[0-9]*"):
|
||||
try:
|
||||
with open(os.path.join(directory, "comm")) as handle:
|
||||
if handle.read().strip() != "FIFA17.exe":
|
||||
continue
|
||||
pid = int(os.path.basename(directory))
|
||||
with open(os.path.join(directory, "statm")) as handle:
|
||||
resident_pages = int(handle.read().split()[1])
|
||||
found.append((resident_pages, pid))
|
||||
except (OSError, ValueError, IndexError):
|
||||
continue
|
||||
return [pid for _resident, pid in sorted(found, reverse=True)]
|
||||
|
||||
|
||||
def find_pid() -> int | None:
|
||||
pids = find_pids()
|
||||
return pids[0] if pids else None
|
||||
|
||||
|
||||
def fixture_bytes(teams: tuple[int, ...] = DEFAULT_TEAMS) -> bytes:
|
||||
return b"".join(
|
||||
struct.pack("<iBBHii", team_id, 1, round_id, 0, 1, 400)
|
||||
for round_id, team_id in enumerate(teams)
|
||||
)
|
||||
|
||||
|
||||
def readable_regions(pid: int, *, writable_anon_only: bool = False):
|
||||
with open(f"/proc/{pid}/maps") as maps:
|
||||
for line in maps:
|
||||
match = re.match(
|
||||
r"([0-9a-f]+)-([0-9a-f]+)\s+(\S{4})\s+\S+\s+\S+\s+\S+\s*(.*)",
|
||||
line,
|
||||
)
|
||||
if not match:
|
||||
continue
|
||||
lo, hi = int(match.group(1), 16), int(match.group(2), 16)
|
||||
perms, path = match.group(3), match.group(4).strip()
|
||||
if perms[0] != "r" or path.startswith(("/dev", "/memfd")):
|
||||
continue
|
||||
if hi - lo > 512 * 1024 * 1024:
|
||||
continue
|
||||
if writable_anon_only and (perms[1] != "w" or path):
|
||||
continue
|
||||
yield lo, hi, perms, path
|
||||
|
||||
|
||||
def _i32(buf: bytes, offset: int) -> int:
|
||||
return struct.unpack_from("<i", buf, offset)[0]
|
||||
|
||||
|
||||
def scan_fixture_buffer(buf: bytes, base: int, selected_index: int) -> list[Fixture]:
|
||||
pattern = fixture_bytes()
|
||||
found = []
|
||||
offset = buf.find(pattern)
|
||||
while offset >= 0:
|
||||
records = []
|
||||
for round_id in range(len(DEFAULT_TEAMS)):
|
||||
at = offset + round_id * 16
|
||||
team_id, difficulty, parsed_round, _pad, reward_mult, coins = struct.unpack_from(
|
||||
"<iBBHii", buf, at
|
||||
)
|
||||
records.append(
|
||||
{
|
||||
"team_id": team_id,
|
||||
"difficulty": difficulty,
|
||||
"round_id": parsed_round,
|
||||
"reward_mult": reward_mult,
|
||||
"coins": coins,
|
||||
}
|
||||
)
|
||||
found.append(
|
||||
Fixture(
|
||||
address=base + offset,
|
||||
selected_address=base + offset + selected_index * 16,
|
||||
selected_index=selected_index,
|
||||
selected_team_id=records[selected_index]["team_id"],
|
||||
records=records,
|
||||
)
|
||||
)
|
||||
offset = buf.find(pattern, offset + 4)
|
||||
return found
|
||||
|
||||
|
||||
def scan_match_team_buffer(buf: bytes, base: int) -> list[MatchTeam]:
|
||||
found = []
|
||||
offset = buf.find(MATCH_HEADER)
|
||||
while offset >= 0:
|
||||
if offset + 0x7C <= len(buf):
|
||||
found.append(
|
||||
MatchTeam(
|
||||
address=base + offset,
|
||||
team_id=_i32(buf, offset + 0x14),
|
||||
marker_18=_i32(buf, offset + 0x18),
|
||||
marker_1c=_i32(buf, offset + 0x1C),
|
||||
xi=list(struct.unpack_from("<11i", buf, offset + 0x20)),
|
||||
substitutes=list(struct.unpack_from("<12i", buf, offset + 0x4C)),
|
||||
)
|
||||
)
|
||||
offset = buf.find(MATCH_HEADER, offset + 4)
|
||||
return found
|
||||
|
||||
|
||||
def _valid_config(buf: bytes, pair: int) -> bool:
|
||||
required = pair + 0x50
|
||||
if pair < 0 or required > len(buf):
|
||||
return False
|
||||
return (
|
||||
tuple(struct.unpack_from("<4I", buf, pair + 0x1C)) == (F01, F01, F01, F01)
|
||||
and _i32(buf, pair + 0x38) == 11
|
||||
and _i32(buf, pair + 0x3C) == 11
|
||||
and _i32(buf, pair + 0x40) == 0
|
||||
and _i32(buf, pair + 0x44) == 5
|
||||
)
|
||||
|
||||
|
||||
def scan_match_config_buffer(buf: bytes, base: int) -> list[MatchConfig]:
|
||||
found = []
|
||||
offset = buf.find(PARTICIPANT_PREFIX)
|
||||
while offset >= 0:
|
||||
pair = offset + len(PARTICIPANT_PREFIX)
|
||||
if _valid_config(buf, pair):
|
||||
found.append(
|
||||
MatchConfig(
|
||||
pair_address=base + pair,
|
||||
team_id_0=_i32(buf, pair),
|
||||
team_id_1=_i32(buf, pair + 4),
|
||||
player_count_0=_i32(buf, pair + 0x38),
|
||||
player_count_1=_i32(buf, pair + 0x3C),
|
||||
)
|
||||
)
|
||||
offset = buf.find(PARTICIPANT_PREFIX, offset + 4)
|
||||
return found
|
||||
|
||||
|
||||
def scan_process(
|
||||
pid: int,
|
||||
selected_index: int,
|
||||
*,
|
||||
include_fixture: bool = True,
|
||||
writable_anon_only: bool = False,
|
||||
) -> dict[str, list]:
|
||||
result: dict[str, list] = {"fixtures": [], "match_teams": [], "match_configs": []}
|
||||
with open(f"/proc/{pid}/mem", "rb", 0) as memory:
|
||||
for lo, hi, _perms, _path in readable_regions(
|
||||
pid, writable_anon_only=writable_anon_only
|
||||
):
|
||||
try:
|
||||
memory.seek(lo)
|
||||
buf = memory.read(hi - lo)
|
||||
except (OSError, ValueError, OverflowError):
|
||||
continue
|
||||
if include_fixture:
|
||||
result["fixtures"].extend(scan_fixture_buffer(buf, lo, selected_index))
|
||||
result["match_teams"].extend(scan_match_team_buffer(buf, lo))
|
||||
result["match_configs"].extend(scan_match_config_buffer(buf, lo))
|
||||
return result
|
||||
|
||||
|
||||
def selftest() -> None:
|
||||
fixture = fixture_bytes()
|
||||
team = bytearray(0x7C)
|
||||
team[:20] = MATCH_HEADER
|
||||
struct.pack_into("<iii", team, 0x14, 130000, 0x54001, 0x54002)
|
||||
struct.pack_into("<11i", team, 0x20, *range(11))
|
||||
struct.pack_into("<12i", team, 0x4C, *range(20, 32))
|
||||
config = bytearray(0x20 + 0x50)
|
||||
config[:0x20] = PARTICIPANT_PREFIX
|
||||
pair = 0x20
|
||||
struct.pack_into("<ii", config, pair, 130000, 130000)
|
||||
struct.pack_into("<4I", config, pair + 0x1C, F01, F01, F01, F01)
|
||||
struct.pack_into("<iiii", config, pair + 0x38, 11, 11, 0, 5)
|
||||
buf = b"X" * 32 + fixture + b"Y" * 32 + team + b"Z" * 32 + config
|
||||
fixtures = scan_fixture_buffer(buf, 0x1000, 0)
|
||||
teams = scan_match_team_buffer(buf, 0x1000)
|
||||
configs = scan_match_config_buffer(buf, 0x1000)
|
||||
assert len(fixtures) == 1 and fixtures[0].selected_team_id == 73
|
||||
assert len(teams) == 1 and teams[0].team_id == 130000
|
||||
assert len(configs) == 1 and configs[0].team_id_1 == 130000
|
||||
# The transient handle is never part of the anchor.
|
||||
struct.pack_into("<i", team, 0x18, -1)
|
||||
assert len(scan_match_team_buffer(bytes(team), 0)) == 1
|
||||
print("offline_match_locator selftest: PASS")
|
||||
|
||||
|
||||
def main() -> int:
|
||||
parser = argparse.ArgumentParser(description=__doc__)
|
||||
parser.add_argument("pid", nargs="?", type=int)
|
||||
parser.add_argument("--fixture-index", type=int, default=0)
|
||||
parser.add_argument("--json", action="store_true")
|
||||
parser.add_argument("--selftest", action="store_true")
|
||||
parser.add_argument("--writable-anon-only", action="store_true")
|
||||
args = parser.parse_args()
|
||||
if args.selftest:
|
||||
selftest()
|
||||
return 0
|
||||
pid = args.pid or find_pid()
|
||||
if not pid:
|
||||
print("FIFA17.exe not found", file=sys.stderr)
|
||||
return 2
|
||||
if not 0 <= args.fixture_index < len(DEFAULT_TEAMS):
|
||||
print("--fixture-index must be 0..9", file=sys.stderr)
|
||||
return 2
|
||||
result = scan_process(
|
||||
pid,
|
||||
args.fixture_index,
|
||||
writable_anon_only=args.writable_anon_only,
|
||||
)
|
||||
serial = {key: [asdict(value) for value in values] for key, values in result.items()}
|
||||
serial["pid"] = pid
|
||||
if args.json:
|
||||
print(json.dumps(serial, sort_keys=True))
|
||||
return 0
|
||||
print(f"pid={pid}")
|
||||
for fixture in result["fixtures"]:
|
||||
print(
|
||||
f"fixture @0x{fixture.address:x}; selected index {fixture.selected_index} "
|
||||
f"@0x{fixture.selected_address:x} teamId={fixture.selected_team_id}"
|
||||
)
|
||||
for config in result["match_configs"]:
|
||||
print(
|
||||
f"match config pair @0x{config.pair_address:x}: "
|
||||
f"[{config.team_id_0}, {config.team_id_1}]"
|
||||
)
|
||||
for team in result["match_teams"]:
|
||||
print(
|
||||
f"match team @0x{team.address:x}: teamId={team.team_id} "
|
||||
f"handles=[{team.marker_18}, {team.marker_1c}]"
|
||||
)
|
||||
print(
|
||||
f"counts: fixtures={len(result['fixtures'])} "
|
||||
f"configs={len(result['match_configs'])} teams={len(result['match_teams'])}"
|
||||
)
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
raise SystemExit(main())
|
||||
@@ -32,11 +32,26 @@ c() { printf ' %s\n' "$*"; }
|
||||
up() { ss -tlnp 2>/dev/null | grep -q ":$1 "; }
|
||||
|
||||
ensure_cert() {
|
||||
[ -s "$CERT" ] && [ -s "$KEY" ] && return 0
|
||||
echo "[*] generating self-signed TLS cert (redirector MITM; ProtoSSL verify is patched)"
|
||||
# The cert MUST carry the address the client dials in its SAN, or the roster
|
||||
# HTTPS handshake is rejected with fatal certificate_unknown and the FUT hub
|
||||
# fails to load (docs/FIFA17_FUT_SQUAD_UPDATE_TLS.md): the client dials the
|
||||
# roster/redirector by IP and that path validates the SAN against it. Default to
|
||||
# this host's primary LAN IP so a client on another machine works;
|
||||
# OPENFUT_ADVERTISE overrides. Reissue when absent OR when the current cert lacks
|
||||
# that IP, so this self-heals rather than serving a stale DNS-only cert.
|
||||
local adv ip_sans regen=0
|
||||
adv="${OPENFUT_ADVERTISE:-$(ip route get 1.1.1.1 2>/dev/null | awk '{print $7; exit}')}"
|
||||
ip_sans="IP:127.0.0.1"; [ -n "$adv" ] && ip_sans="IP:$adv,IP:127.0.0.1"
|
||||
if [ ! -s "$CERT" ] || [ ! -s "$KEY" ]; then
|
||||
regen=1
|
||||
elif [ -n "$adv" ] && ! openssl x509 -in "$CERT" -noout -ext subjectAltName 2>/dev/null | grep -qF "IP Address:$adv"; then
|
||||
regen=1
|
||||
fi
|
||||
[ "$regen" = 0 ] && return 0
|
||||
echo "[*] issuing self-signed TLS cert (SAN includes $ip_sans; redirector MITM; ProtoSSL verify is patched)"
|
||||
openssl req -x509 -newkey rsa:2048 -nodes -keyout "$KEY" -out "$CERT" -days 3650 \
|
||||
-subj "/CN=winter15.gosredirector.ea.com" \
|
||||
-addext "subjectAltName=DNS:winter15.gosredirector.ea.com,DNS:*.gosredirector.ea.com,DNS:*.ea.com,IP:127.0.0.1" \
|
||||
-addext "subjectAltName=DNS:winter15.gosredirector.ea.com,DNS:*.gosredirector.ea.com,DNS:*.ea.com,$ip_sans" \
|
||||
>/dev/null 2>&1
|
||||
}
|
||||
|
||||
|
||||
Executable
+394
@@ -0,0 +1,394 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Trace FIFA17's PMA ScenarioModeStart-to-event-5 producer chain.
|
||||
|
||||
The generated GDB program uses hardware breakpoints, only reads registers and
|
||||
client memory, logs, and continues. Breakpoints are rotated so no more than four
|
||||
are enabled. It never calls client functions, writes client memory, emits an
|
||||
event, or drives input.
|
||||
|
||||
pma_producer_trace.py [pid] [--variant mode0|alternate] [--output PATH]
|
||||
pma_producer_trace.py --selftest
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
from pathlib import Path
|
||||
import shutil
|
||||
import sys
|
||||
|
||||
sys.path.insert(0, str(Path(__file__).resolve().parent))
|
||||
import match_advance_trace as advance
|
||||
import match_transition_trace as transition
|
||||
|
||||
VARIANTS = {
|
||||
"mode0": {
|
||||
"scenario_rva": 0x07B1C190,
|
||||
"writer_rva": 0x07B1C26B,
|
||||
"register_rva": 0x07B1C282,
|
||||
"writer_context": "$rsi",
|
||||
"writer_async_requested": "1",
|
||||
"arm_condition": "1",
|
||||
},
|
||||
"alternate": {
|
||||
"scenario_rva": 0x07B1C050,
|
||||
"writer_rva": 0x07B1C12F,
|
||||
"register_rva": 0x07B1C146,
|
||||
"writer_context": "$rbp",
|
||||
"writer_async_requested": "$sil",
|
||||
"arm_condition": "$tracked_ctx != 0 && $rcx == $tracked_ctx",
|
||||
},
|
||||
}
|
||||
PMA_COMPLETION_ARM_RVA = 0x07B1AE60
|
||||
PMA_COMPLETION_ARM_WRITER_RVA = 0x07B1AF33
|
||||
ASYNC_COMPLETION_RVA = 0x07B046C0
|
||||
CALLBACK_DISPATCHER_RVA = 0x07AC87B0
|
||||
PMA_INSTRUCTIONS_HANDLER_RVA = 0x07AC91E0
|
||||
GAMEPLAY_GLOBAL_RVA = 0x04BFB910
|
||||
PMA_INSTRUCTIONS_VTABLE_RVA = 0x03AF2750
|
||||
|
||||
|
||||
def addresses(base: int, variant: str) -> dict[str, int]:
|
||||
config = VARIANTS[variant]
|
||||
return {
|
||||
"scenario": base + config["scenario_rva"],
|
||||
"writer": base + config["writer_rva"],
|
||||
"register": base + config["register_rva"],
|
||||
"arm": base + PMA_COMPLETION_ARM_RVA,
|
||||
"arm_writer": base + PMA_COMPLETION_ARM_WRITER_RVA,
|
||||
"completion": base + ASYNC_COMPLETION_RVA,
|
||||
"dispatcher": base + CALLBACK_DISPATCHER_RVA,
|
||||
"instructions": base + PMA_INSTRUCTIONS_HANDLER_RVA,
|
||||
"gameplay_global": base + GAMEPLAY_GLOBAL_RVA,
|
||||
"instructions_vtable": base + PMA_INSTRUCTIONS_VTABLE_RVA,
|
||||
}
|
||||
|
||||
|
||||
def gdb_prelude(pid: int, output: str) -> str:
|
||||
if any(character in output for character in "\n\r"):
|
||||
raise ValueError("output path cannot contain a newline")
|
||||
return f"""set pagination off
|
||||
set confirm off
|
||||
set print thread-events off
|
||||
set breakpoint always-inserted off
|
||||
set logging file {output}
|
||||
set logging overwrite on
|
||||
set logging redirect off
|
||||
set logging enabled on
|
||||
handle SIGSEGV nostop noprint pass
|
||||
handle SIGILL nostop noprint pass
|
||||
handle SIGFPE nostop noprint pass
|
||||
handle SIGPIPE nostop noprint pass
|
||||
handle SIGALRM nostop noprint pass
|
||||
handle SIGUSR1 nostop noprint pass
|
||||
handle SIGUSR2 nostop noprint pass
|
||||
|
||||
attach {pid}
|
||||
"""
|
||||
|
||||
|
||||
def build_script(pid: int, fifa_base: int, output: str, variant: str) -> str:
|
||||
address = addresses(fifa_base, variant)
|
||||
config = VARIANTS[variant]
|
||||
return (
|
||||
gdb_prelude(pid, output)
|
||||
+ f"""define snapshot_pma_context
|
||||
set $snap_ctx = $arg0
|
||||
set $snap_flag40 = -1
|
||||
set $snap_callback_vtable = 0
|
||||
set $snap_callback_owner = 0
|
||||
set $snap_dispatcher = 0
|
||||
set $snap_dispatcher_vtable = 0
|
||||
set $snap_pma = 0
|
||||
set $snap_pma_flag18 = -1
|
||||
set $snap_pma_parent = 0
|
||||
set $snap_pma_machine = 0
|
||||
set $snap_pma_current = 0
|
||||
if $snap_ctx != 0
|
||||
set $snap_flag40 = *(unsigned char*)($snap_ctx+0x40)
|
||||
set $snap_callback_vtable = *(void**)($snap_ctx+0x48)
|
||||
set $snap_callback_owner = *(void**)($snap_ctx+0x78)
|
||||
set $snap_dispatcher = $snap_ctx+0x80
|
||||
set $snap_dispatcher_vtable = *(void**)$snap_dispatcher
|
||||
set $snap_sentinel = $snap_ctx+0x88
|
||||
set $snap_node = *(void**)$snap_sentinel
|
||||
set $snap_scan = 0
|
||||
while $snap_node != 0 && $snap_node != $snap_sentinel && $snap_scan < 8
|
||||
set $snap_candidate = *(void**)($snap_node+0x10)
|
||||
if $snap_candidate != 0
|
||||
if *(void**)$snap_candidate == 0x{address['instructions_vtable']:x}
|
||||
set $snap_pma = $snap_candidate
|
||||
end
|
||||
end
|
||||
set $snap_node = *(void**)$snap_node
|
||||
set $snap_scan = $snap_scan+1
|
||||
end
|
||||
if $snap_pma != 0
|
||||
set $snap_pma_flag18 = *(unsigned char*)($snap_pma+0x18)
|
||||
set $snap_pma_parent = *(void**)($snap_pma+0x8)
|
||||
if $snap_pma_parent != 0
|
||||
set $snap_pma_machine = *(void**)($snap_pma_parent+0x8)
|
||||
end
|
||||
if $snap_pma_machine != 0
|
||||
set $snap_pma_current = *(void**)($snap_pma_machine+0x10)
|
||||
end
|
||||
end
|
||||
end
|
||||
end
|
||||
|
||||
define snapshot_gameplay
|
||||
set $snap_gameplay_global = *(void**)0x{address['gameplay_global']:x}
|
||||
set $snap_listener_manager = 0
|
||||
set $snap_listener_table = 0
|
||||
set $snap_listener_index = -1
|
||||
set $snap_free_roam = 0
|
||||
set $snap_free_roam_state = -1
|
||||
set $snap_free_roam_111 = -1
|
||||
set $snap_free_roam_112 = -1
|
||||
set $snap_free_roam_124 = -1
|
||||
set $snap_selected = 0
|
||||
set $snap_selected_vtable = 0
|
||||
set $snap_selected_mode = -1
|
||||
if $snap_gameplay_global != 0
|
||||
set $snap_listener_manager = *(void**)($snap_gameplay_global+0x58)
|
||||
end
|
||||
if $snap_listener_manager != 0
|
||||
set $snap_listener_table = *(void**)$snap_listener_manager
|
||||
end
|
||||
if $snap_listener_table != 0
|
||||
set $snap_free_roam = *(void**)$snap_listener_table
|
||||
set $snap_listener_index = *(int*)($snap_listener_table+0x20)
|
||||
if $snap_listener_index >= 0 && $snap_listener_index < 3
|
||||
set $snap_selected = *(void**)($snap_listener_table+$snap_listener_index*8)
|
||||
end
|
||||
end
|
||||
if $snap_free_roam != 0
|
||||
set $snap_free_roam_state = *(int*)($snap_free_roam+0x30)
|
||||
set $snap_free_roam_111 = *(unsigned char*)($snap_free_roam+0x111)
|
||||
set $snap_free_roam_112 = *(unsigned char*)($snap_free_roam+0x112)
|
||||
set $snap_free_roam_124 = *(int*)($snap_free_roam+0x124)
|
||||
end
|
||||
if $snap_selected != 0
|
||||
set $snap_selected_vtable = *(void**)$snap_selected
|
||||
set $snap_selected_mode = *(int*)($snap_selected+0x18)
|
||||
end
|
||||
end
|
||||
set $tracked_ctx = 0
|
||||
|
||||
|
||||
hbreak *0x{address['scenario']:x}
|
||||
commands
|
||||
silent
|
||||
set $ctx = $rcx
|
||||
set $tracked_ctx = $ctx
|
||||
snapshot_pma_context $ctx
|
||||
snapshot_gameplay
|
||||
python import time; print("PMAPRODUCER epoch_ns=%d mono_ns=%d SCENARIO_MODE_START" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d function=%p caller_return=%p ctx=%p ctx_vtable=%p arg_descriptor=%p arg_scenario=%p async_requested=%d flag40=%d callback_vtable=%p callback_owner=%p dispatcher=%p dispatcher_vtable=%p pma=%p pma_flag18=%d pma_parent=%p pma_machine=%p pma_current=%p free_roam=%p free_state=%d free111=%d free112=%d free124=%d selected_index=%d selected=%p selected_vtable=%p selected_mode=%d\\n", $_thread, $pc, *(void**)$rsp, $ctx, *(void**)$ctx, $rdx, $r8, $r9b, $snap_flag40, $snap_callback_vtable, $snap_callback_owner, $snap_dispatcher, $snap_dispatcher_vtable, $snap_pma, $snap_pma_flag18, $snap_pma_parent, $snap_pma_machine, $snap_pma_current, $snap_free_roam, $snap_free_roam_state, $snap_free_roam_111, $snap_free_roam_112, $snap_free_roam_124, $snap_listener_index, $snap_selected, $snap_selected_vtable, $snap_selected_mode
|
||||
disable 1
|
||||
enable 2
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['writer']:x}
|
||||
condition 2 $tracked_ctx != 0 && {config['writer_context']} == $tracked_ctx
|
||||
disable 2
|
||||
commands
|
||||
silent
|
||||
set $ctx = {config['writer_context']}
|
||||
snapshot_pma_context $ctx
|
||||
snapshot_gameplay
|
||||
python import time; print("PMAPRODUCER epoch_ns=%d mono_ns=%d CONTEXT_ARM_WRITER" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d instruction=%p caller_return=%p ctx=%p original_async_requested=%d flag40_before=%d callback_vtable=%p callback_owner_before=%p dispatcher=%p dispatcher_vtable=%p pma=%p pma_flag18=%d pma_current=%p free_roam=%p free_state=%d free111=%d free112=%d free124=%d selected_index=%d selected=%p selected_vtable=%p selected_mode=%d\\n", $_thread, $pc, *(void**)$rsp, $ctx, {config['writer_async_requested']}, $snap_flag40, $snap_callback_vtable, $snap_callback_owner, $snap_dispatcher, $snap_dispatcher_vtable, $snap_pma, $snap_pma_flag18, $snap_pma_current, $snap_free_roam, $snap_free_roam_state, $snap_free_roam_111, $snap_free_roam_112, $snap_free_roam_124, $snap_listener_index, $snap_selected, $snap_selected_vtable, $snap_selected_mode
|
||||
disable 2
|
||||
enable 3
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['register']:x}
|
||||
condition 3 $tracked_ctx != 0 && $rdx == $tracked_ctx+0x48
|
||||
disable 3
|
||||
commands
|
||||
silent
|
||||
set $callback = $rdx
|
||||
set $ctx = $callback-0x48
|
||||
snapshot_pma_context $ctx
|
||||
python import time; print("PMAPRODUCER epoch_ns=%d mono_ns=%d ASYNC_REGISTER_CALL" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d callsite=%p caller_return=%p service=%p service_vtable=%p callback=%p callback_vtable=%p ctx=%p flag40=%d callback_owner=%p dispatcher=%p dispatcher_vtable=%p\\n", $_thread, $pc, *(void**)$rsp, $rcx, *(void**)$rcx, $callback, *(void**)$callback, $ctx, $snap_flag40, $snap_callback_owner, $snap_dispatcher, $snap_dispatcher_vtable
|
||||
disable 3
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['arm']:x}
|
||||
condition 4 {config['arm_condition']}
|
||||
commands
|
||||
silent
|
||||
set $ctx = $rcx
|
||||
if $tracked_ctx == 0
|
||||
set $tracked_ctx = $ctx
|
||||
end
|
||||
snapshot_pma_context $ctx
|
||||
snapshot_gameplay
|
||||
python import time; print("PMAPRODUCER epoch_ns=%d mono_ns=%d COMPLETION_ARM_ENTRY" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d function=%p caller_return=%p ctx=%p ctx_vtable=%p flag40_before=%d callback_vtable=%p callback_owner=%p dispatcher=%p dispatcher_vtable=%p result_source=%p free_roam=%p free_state=%d free111=%d free112=%d free124=%d selected_index=%d selected=%p selected_vtable=%p selected_mode=%d\\n", $_thread, $pc, *(void**)$rsp, $ctx, *(void**)$ctx, $snap_flag40, $snap_callback_vtable, $snap_callback_owner, $snap_dispatcher, $snap_dispatcher_vtable, *(void**)($ctx+0xa8), $snap_free_roam, $snap_free_roam_state, $snap_free_roam_111, $snap_free_roam_112, $snap_free_roam_124, $snap_listener_index, $snap_selected, $snap_selected_vtable, $snap_selected_mode
|
||||
disable 4
|
||||
enable 5
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['arm_writer']:x}
|
||||
condition 5 $tracked_ctx != 0 && $rsi == $tracked_ctx
|
||||
disable 5
|
||||
commands
|
||||
silent
|
||||
set $ctx = $rsi
|
||||
snapshot_pma_context $ctx
|
||||
snapshot_gameplay
|
||||
python import time; print("PMAPRODUCER epoch_ns=%d mono_ns=%d COMPLETION_ARM_WRITER" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d instruction=%p caller_return=%p ctx=%p flag40_before=%d result_object=%p result_state28=%d callback_owner=%p dispatcher=%p dispatcher_vtable=%p pma=%p pma_flag18=%d pma_current=%p free_roam=%p free_state=%d free111=%d free112=%d free124=%d selected_index=%d selected=%p selected_vtable=%p selected_mode=%d\\n", $_thread, $pc, *(void**)$rsp, $ctx, $snap_flag40, $rax, *(int*)($rax+0x28), $snap_callback_owner, $snap_dispatcher, $snap_dispatcher_vtable, $snap_pma, $snap_pma_flag18, $snap_pma_current, $snap_free_roam, $snap_free_roam_state, $snap_free_roam_111, $snap_free_roam_112, $snap_free_roam_124, $snap_listener_index, $snap_selected, $snap_selected_vtable, $snap_selected_mode
|
||||
disable 5
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['completion']:x}
|
||||
condition 6 $tracked_ctx != 0 && $rcx == $tracked_ctx+0x48
|
||||
commands
|
||||
silent
|
||||
set $callback = $rcx
|
||||
set $ctx = *(void**)($callback+0x30)
|
||||
snapshot_pma_context $ctx
|
||||
snapshot_gameplay
|
||||
python import time; print("PMAPRODUCER epoch_ns=%d mono_ns=%d ASYNC_COMPLETION" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d function=%p caller_return=%p callback=%p callback_vtable=%p ctx=%p callback_matches_ctx48=%d flag40_before=%d arg_rdx=%p arg_r8=%p arg_r9=%p dispatcher=%p dispatcher_vtable=%p pma=%p pma_flag18=%d pma_current=%p free_roam=%p free_state=%d free111=%d free112=%d free124=%d selected_index=%d selected=%p selected_vtable=%p selected_mode=%d\\n", $_thread, $pc, *(void**)$rsp, $callback, *(void**)$callback, $ctx, $callback == $ctx+0x48, $snap_flag40, $rdx, $r8, $r9, $snap_dispatcher, $snap_dispatcher_vtable, $snap_pma, $snap_pma_flag18, $snap_pma_current, $snap_free_roam, $snap_free_roam_state, $snap_free_roam_111, $snap_free_roam_112, $snap_free_roam_124, $snap_listener_index, $snap_selected, $snap_selected_vtable, $snap_selected_mode
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['dispatcher']:x}
|
||||
condition 7 $tracked_ctx != 0 && $rcx == $tracked_ctx+0x80 && $edx == 5
|
||||
commands
|
||||
silent
|
||||
set $ctx = $rcx-0x80
|
||||
snapshot_pma_context $ctx
|
||||
snapshot_gameplay
|
||||
python import time; print("PMAPRODUCER epoch_ns=%d mono_ns=%d DISPATCHER_EVENT_5" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d function=%p caller_return=%p dispatcher=%p event=%d arg_r8=%p arg_r9=%p ctx=%p flag40=%d callback_owner=%p pma=%p pma_flag18=%d pma_current=%p free_roam=%p free_state=%d free111=%d free112=%d free124=%d selected_index=%d selected=%p selected_vtable=%p selected_mode=%d\\n", $_thread, $pc, *(void**)$rsp, $rcx, $edx, $r8, $r9, $ctx, $snap_flag40, $snap_callback_owner, $snap_pma, $snap_pma_flag18, $snap_pma_current, $snap_free_roam, $snap_free_roam_state, $snap_free_roam_111, $snap_free_roam_112, $snap_free_roam_124, $snap_listener_index, $snap_selected, $snap_selected_vtable, $snap_selected_mode
|
||||
disable 7
|
||||
enable 8
|
||||
continue
|
||||
end
|
||||
|
||||
hbreak *0x{address['instructions']:x}
|
||||
disable 8
|
||||
commands
|
||||
silent
|
||||
set $listener = $rcx
|
||||
set $parent = *(void**)($listener+0x8)
|
||||
set $machine = 0
|
||||
set $current = 0
|
||||
if $parent != 0
|
||||
set $machine = *(void**)($parent+0x8)
|
||||
end
|
||||
if $machine != 0
|
||||
set $current = *(void**)($machine+0x10)
|
||||
end
|
||||
snapshot_gameplay
|
||||
python import time; print("PMAPRODUCER epoch_ns=%d mono_ns=%d INSTRUCTIONS_AFTER_EVENT_5" % (time.time_ns(), time.monotonic_ns()), end=" ")
|
||||
printf "thread=%d handler=%p caller_return=%p listener=%p listener_vtable=%p event=%d flag18=%d parent=%p machine=%p current=%p current_vtable=%p free_roam=%p free_state=%d free111=%d free112=%d free124=%d selected_index=%d selected=%p selected_vtable=%p selected_mode=%d\\n", $_thread, $pc, *(void**)$rsp, $listener, *(void**)$listener, $edx, *(unsigned char*)($listener+0x18), $parent, $machine, $current, $current ? *(void**)$current : 0, $snap_free_roam, $snap_free_roam_state, $snap_free_roam_111, $snap_free_roam_112, $snap_free_roam_124, $snap_listener_index, $snap_selected, $snap_selected_vtable, $snap_selected_mode
|
||||
disable 6
|
||||
continue
|
||||
end
|
||||
|
||||
printf "PMAPRODUCER ARMED pid={pid} variant={variant} scenario=0x{address['scenario']:x} writer=0x{address['writer']:x} register=0x{address['register']:x} arm=0x{address['arm']:x} arm_writer=0x{address['arm_writer']:x} completion=0x{address['completion']:x} dispatcher=0x{address['dispatcher']:x} instructions=0x{address['instructions']:x}\\n"
|
||||
continue
|
||||
"""
|
||||
)
|
||||
|
||||
|
||||
def effective_environment(pid: int) -> dict[str, str]:
|
||||
values: dict[str, str] = {}
|
||||
for item in Path(f"/proc/{pid}/environ").read_bytes().split(b"\0"):
|
||||
if not item.startswith(b"OPENFUT_FIFA17_"):
|
||||
continue
|
||||
key, _, value = item.decode("utf-8", errors="replace").partition("=")
|
||||
values[key] = value
|
||||
return values
|
||||
|
||||
|
||||
def selftest() -> None:
|
||||
mode0 = addresses(0x140000000, "mode0")
|
||||
alternate = addresses(0x140000000, "alternate")
|
||||
script = build_script(1234, 0x140000000, "/tmp/pma-producer.log", "mode0")
|
||||
assert mode0["scenario"] == 0x147B1C190
|
||||
assert mode0["writer"] == 0x147B1C26B
|
||||
assert mode0["register"] == 0x147B1C282
|
||||
assert alternate["scenario"] == 0x147B1C050
|
||||
assert alternate["writer"] == 0x147B1C12F
|
||||
assert alternate["register"] == 0x147B1C146
|
||||
assert mode0["completion"] == 0x147B046C0
|
||||
assert mode0["dispatcher"] == 0x147AC87B0
|
||||
assert mode0["instructions"] == 0x147AC91E0
|
||||
assert mode0["arm"] == 0x147B1AE60
|
||||
assert mode0["arm_writer"] == 0x147B1AF33
|
||||
assert script.count("hbreak *") == 8
|
||||
assert "condition 7 $tracked_ctx != 0" in script
|
||||
assert "disable 2" in script and "enable 2" in script
|
||||
assert "disable 3" in script and "enable 3" in script
|
||||
assert "disable 5" in script and "enable 5" in script
|
||||
assert "disable 8" in script and "enable 8" in script
|
||||
assert "set *(" not in script
|
||||
print("pma_producer_trace selftest: PASS")
|
||||
|
||||
|
||||
def main() -> int:
|
||||
parser = argparse.ArgumentParser(description=__doc__)
|
||||
parser.add_argument("pid", nargs="?", type=int)
|
||||
parser.add_argument("--output")
|
||||
parser.add_argument("--variant", choices=tuple(VARIANTS), default="mode0")
|
||||
parser.add_argument("--print-script", action="store_true")
|
||||
parser.add_argument("--selftest", action="store_true")
|
||||
args = parser.parse_args()
|
||||
if args.selftest:
|
||||
selftest()
|
||||
return 0
|
||||
|
||||
pid = args.pid or transition.find_pid()
|
||||
if not pid:
|
||||
print("FIFA17.exe not found", file=sys.stderr)
|
||||
return 2
|
||||
try:
|
||||
fifa_base, fifa_path = advance.module_mapping(pid, advance.FIFA_MODULE)
|
||||
advance.validate_file(
|
||||
fifa_path,
|
||||
advance.PINNED_FIFA_SHA256,
|
||||
advance.FIFA_MODULE,
|
||||
)
|
||||
cards_base, cards_path = transition.cards_mapping(pid)
|
||||
transition.validate_cards(cards_path)
|
||||
output = args.output or f"/tmp/fifa17-pma-producer-{args.variant}-{pid}.log"
|
||||
script = build_script(pid, fifa_base, output, args.variant)
|
||||
environment = effective_environment(pid)
|
||||
print(
|
||||
"PMAPRODUCER PREPARED "
|
||||
f"pid={pid} variant={args.variant} fifa_base={fifa_base:#x} cards_base={cards_base:#x} "
|
||||
f"team_compat={environment.get('OPENFUT_FIFA17_SEASON_TEAM_COMPAT', '<absent>')} "
|
||||
f"pma_fix={environment.get('OPENFUT_FIFA17_OFFLINE_SEASONS_PMA_FIX', '<absent>')}"
|
||||
)
|
||||
except (OSError, RuntimeError, ValueError) as error:
|
||||
print(error, file=sys.stderr)
|
||||
return 2
|
||||
|
||||
if args.print_script:
|
||||
print(script, end="")
|
||||
return 0
|
||||
if not shutil.which("gdb"):
|
||||
print("gdb not found", file=sys.stderr)
|
||||
return 2
|
||||
script_path = f"/tmp/fifa17-pma-producer-{args.variant}-{pid}.gdb"
|
||||
Path(script_path).write_text(script, encoding="utf-8")
|
||||
import os
|
||||
|
||||
os.execvp("gdb", ["gdb", "-q", "-nx", "-batch", "-x", script_path])
|
||||
return 127
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
raise SystemExit(main())
|
||||
Executable
+107
@@ -0,0 +1,107 @@
|
||||
#!/usr/bin/env python3
|
||||
# -*- coding: utf-8 -*-
|
||||
"""Dump the CLASSIFICATION fields the client stored for every card it holds, so
|
||||
the subtype->cardtype map and the itemState runtime values are read from the
|
||||
running game instead of inferred.
|
||||
|
||||
READ-ONLY. /proc/PID/mem is opened 'rb'; there is no write path in this file.
|
||||
|
||||
WHY THIS EXISTS
|
||||
---------------
|
||||
Two things this project has repeatedly had to treat as INFERRED:
|
||||
|
||||
1. `FUN_1800d8330`'s cardsubtypeid -> cardtype map. It is read out of Ghidra
|
||||
(0..3->1 players, 4->2 manager, 5->3 headcoach, 6->10 gkcoach, 7->5 physio,
|
||||
8->4 fitnesscoach, 9..b->7), and the kit selector gate `FUN_1801c3480`
|
||||
branches on cardtype == 7. Serving a subtype whose cardtype we guessed
|
||||
wrong fails SILENTLY, because cardtype 9 has no arm in the merge.
|
||||
2. The itemState enum. The table at 0x180229d20 gives the tokens; the RUNTIME
|
||||
values the strings deserialize to (notably activeHomeKit/activeAwayKit ->
|
||||
101/102) have been carried as inferred.
|
||||
|
||||
Both are directly observable: the parser writes cardsubtypeid to rec+0x50, the
|
||||
derived cardtype to rec+0x4c, and the decoded itemState to rec+0x5c. Reading
|
||||
those back for every record turns the pair into measurements.
|
||||
|
||||
rec+0x18 resourceId
|
||||
rec+0x4c cardtype (derived by FUN_1800d8330 from cardsubtypeid)
|
||||
rec+0x50 cardsubtypeid (as sent)
|
||||
rec+0x5c itemState (decoded enum value)
|
||||
|
||||
Usage: python3 record_vocab_probe.py
|
||||
"""
|
||||
import collections
|
||||
import sys
|
||||
|
||||
import watch_club_model as W
|
||||
import card_identity_probe as P
|
||||
|
||||
F_RESOURCE = 0x18
|
||||
F_CARDTYPE = 0x4C
|
||||
F_SUBTYPE = 0x50
|
||||
F_ITEMSTATE = 0x5C
|
||||
REC_SIZE = 0x158
|
||||
|
||||
# What the Ghidra read of FUN_1800d8330 predicts, so a disagreement is loud.
|
||||
EXPECTED_CARDTYPE = {0: 1, 1: 1, 2: 1, 3: 1, 4: 2, 5: 3, 6: 10, 7: 5, 8: 4,
|
||||
9: 7, 10: 7, 11: 7}
|
||||
|
||||
|
||||
def main():
|
||||
pid = W.find_pid()
|
||||
if pid is None:
|
||||
print("FIFA17.exe is not running.")
|
||||
return 1
|
||||
base = W.dll_base(pid)
|
||||
if base is None:
|
||||
print("pid %d is up but %s is not mapped yet." % (pid, W.DLL))
|
||||
return 1
|
||||
mem = W.Mem(pid)
|
||||
obj = mem.q(base + (W.G_CARDSDB - W.IMG_BASE))
|
||||
if not obj:
|
||||
print("CardsDb singleton is NULL (no FUT session loaded).")
|
||||
return 1
|
||||
|
||||
ns = W.nodes(mem, obj) if hasattr(W, "nodes") else P.nodes(mem, obj)
|
||||
print("pid=%d CardsDb=%#x walked=%d\n" % (pid, obj, len(ns)))
|
||||
|
||||
pairs = collections.Counter()
|
||||
states = collections.Counter()
|
||||
rows = []
|
||||
for n in ns:
|
||||
buf = mem.read(n + 0x28, REC_SIZE)
|
||||
if not buf or len(buf) < REC_SIZE:
|
||||
continue
|
||||
resource = P.u32(buf, F_RESOURCE)
|
||||
cardtype = P.u8(buf, F_CARDTYPE)
|
||||
subtype = P.u8(buf, F_SUBTYPE)
|
||||
state = P.u8(buf, F_ITEMSTATE)
|
||||
pairs[(subtype, cardtype)] += 1
|
||||
states[state] += 1
|
||||
rows.append((resource, subtype, cardtype, state))
|
||||
|
||||
print("%-12s %-9s %-9s %s" % ("resource", "subtype", "cardtype", "itemState"))
|
||||
for r in sorted(rows):
|
||||
print("%-12d %-9d %-9d %d" % r)
|
||||
|
||||
print("\n--- MEASURED cardsubtypeid -> cardtype ---")
|
||||
for (sub, ct), n in sorted(pairs.items()):
|
||||
want = EXPECTED_CARDTYPE.get(sub)
|
||||
if want is None:
|
||||
verdict = "no Ghidra prediction for this subtype"
|
||||
elif want == ct:
|
||||
verdict = "agrees with FUN_1800d8330"
|
||||
else:
|
||||
verdict = "DISAGREES -- Ghidra said %d" % want
|
||||
print(" subtype %-4d -> cardtype %-4d (%d record(s)) %s" % (sub, ct, n, verdict))
|
||||
|
||||
print("\n--- MEASURED itemState runtime values ---")
|
||||
for st, n in sorted(states.items()):
|
||||
print(" %-5d %d record(s)" % (st, n))
|
||||
print("\nNOTE: a runtime value only appears here if the client was actually")
|
||||
print("served an item in that state. Absence is not evidence of absence.")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
@@ -0,0 +1,76 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Dump CardsDLL's 45-row route table from the ON-DISK PE. READ-ONLY, static.
|
||||
|
||||
The transfer-market analysis locates the table at .rdata 0x18021df80 as
|
||||
{char*, char*} rows. This resolves VA->file offset properly through the PE section
|
||||
table rather than assuming a single .text mapping, then prints every row so we can
|
||||
see whether any route other than `tradePile` could own a trade-pile ITEM list.
|
||||
"""
|
||||
import struct, sys
|
||||
|
||||
DLL = "/mnt/games/FIFA 17/CardsDLL_Win64_retail.dll"
|
||||
TABLE_VA = 0x18021DF80
|
||||
MAX_ROWS = 64
|
||||
|
||||
pe = open(DLL, "rb").read()
|
||||
e_lfanew = struct.unpack_from("<I", pe, 0x3C)[0]
|
||||
assert pe[e_lfanew:e_lfanew + 4] == b"PE\0\0", "not a PE"
|
||||
coff = e_lfanew + 4
|
||||
nsec, opt_size = struct.unpack_from("<HH", pe, coff + 2), None
|
||||
num_sections = struct.unpack_from("<H", pe, coff + 2)[0]
|
||||
opt_size = struct.unpack_from("<H", pe, coff + 16)[0]
|
||||
opt = coff + 20
|
||||
magic = struct.unpack_from("<H", pe, opt)[0]
|
||||
assert magic == 0x20B, "expected PE32+"
|
||||
image_base = struct.unpack_from("<Q", pe, opt + 24)[0]
|
||||
sec_off = opt + opt_size
|
||||
|
||||
sections = []
|
||||
for i in range(num_sections):
|
||||
b = sec_off + i * 40
|
||||
name = pe[b:b + 8].rstrip(b"\0").decode("ascii", "replace")
|
||||
vsize, vaddr, rawsize, rawptr = struct.unpack_from("<IIII", pe, b + 8)
|
||||
sections.append((name, vaddr, vsize, rawptr, rawsize))
|
||||
|
||||
print("image_base=%#x sections=%d" % (image_base, num_sections))
|
||||
for s in sections:
|
||||
print(" %-8s rva=%#010x vsize=%#x rawptr=%#010x rawsize=%#x" % s)
|
||||
|
||||
|
||||
def va2off(va):
|
||||
rva = va - image_base
|
||||
for name, vaddr, vsize, rawptr, rawsize in sections:
|
||||
if vaddr <= rva < vaddr + max(vsize, rawsize):
|
||||
off = rva - vaddr + rawptr
|
||||
if off < len(pe):
|
||||
return off
|
||||
return None
|
||||
|
||||
|
||||
def cstr(va, limit=96):
|
||||
off = va2off(va)
|
||||
if off is None:
|
||||
return None
|
||||
end = pe.find(b"\0", off, off + limit)
|
||||
if end < 0:
|
||||
return None
|
||||
try:
|
||||
return pe[off:end].decode("ascii")
|
||||
except UnicodeDecodeError:
|
||||
return None
|
||||
|
||||
|
||||
base = va2off(TABLE_VA)
|
||||
print("\nroute table VA %#x -> file offset %s" % (TABLE_VA, hex(base) if base else None))
|
||||
assert base, "table VA did not resolve"
|
||||
|
||||
print("\n%-4s %-34s %s" % ("#", "field A", "field B"))
|
||||
rows = 0
|
||||
for i in range(MAX_ROWS):
|
||||
a_va, b_va = struct.unpack_from("<QQ", pe, base + i * 16)
|
||||
a, b = cstr(a_va), cstr(b_va)
|
||||
if a is None and b is None:
|
||||
print("-- table ends after %d rows --" % rows)
|
||||
break
|
||||
print("%-4d %-34s %s" % (i, repr(a), repr(b)))
|
||||
rows += 1
|
||||
Executable
+67
@@ -0,0 +1,67 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Scan for FIFA17 match-team records by the invariant header prefix.
|
||||
|
||||
Anchors ONLY on (11,7,0,0,76) at +0x00..+0x10. Never filter on +0x18: it is a
|
||||
per-record marker whose value varies between sessions (-1 on 2026-08-24,
|
||||
344065/344064 on 2026-08-25), and filtering on it produced a false negative.
|
||||
|
||||
scan_mt.py [pid]
|
||||
"""
|
||||
import glob
|
||||
import os
|
||||
import re
|
||||
import struct
|
||||
import sys
|
||||
|
||||
PAT = struct.pack("<5i", 11, 7, 0, 0, 76)
|
||||
|
||||
|
||||
def find_pid():
|
||||
for d in glob.glob("/proc/[0-9]*"):
|
||||
try:
|
||||
if open(os.path.join(d, "comm")).read().strip() == "FIFA17.exe":
|
||||
return int(os.path.basename(d))
|
||||
except OSError:
|
||||
pass
|
||||
return None
|
||||
|
||||
|
||||
pid = int(sys.argv[1]) if len(sys.argv) > 1 else find_pid()
|
||||
if not pid:
|
||||
print(" no FIFA17.exe")
|
||||
raise SystemExit(2)
|
||||
|
||||
mem = open(f"/proc/{pid}/mem", "rb", 0)
|
||||
found = []
|
||||
for line in open(f"/proc/{pid}/maps"):
|
||||
m = re.match(r"([0-9a-f]+)-([0-9a-f]+)\s+(\S{4})\s+\S+\s+\S+\s+\S+\s*(.*)", line)
|
||||
if not m or m.group(3)[0] != "r":
|
||||
continue
|
||||
lo, hi, path = int(m.group(1), 16), int(m.group(2), 16), m.group(4)
|
||||
if path.startswith(("/dev", "/memfd")) or hi - lo > 512 * 1024 * 1024:
|
||||
continue
|
||||
try:
|
||||
mem.seek(lo)
|
||||
buf = mem.read(hi - lo)
|
||||
except (OSError, ValueError, OverflowError):
|
||||
continue
|
||||
i = buf.find(PAT)
|
||||
while i >= 0:
|
||||
rec = buf[i:i + 0x80]
|
||||
if len(rec) >= 0x80:
|
||||
tid = struct.unpack_from("<i", rec, 0x14)[0]
|
||||
m18 = struct.unpack_from("<i", rec, 0x18)[0]
|
||||
m1c = struct.unpack_from("<i", rec, 0x1c)[0]
|
||||
xi = list(struct.unpack_from("<11i", rec, 0x20))
|
||||
subs = list(struct.unpack_from("<12i", rec, 0x4c))
|
||||
found.append((lo + i, tid, m18, m1c, xi, subs))
|
||||
i = buf.find(PAT, i + 4)
|
||||
|
||||
print(f" pid={pid} {len(found)} match-team record(s)")
|
||||
for addr, tid, m18, m1c, xi, subs in found:
|
||||
print(f"\n @0x{addr:x}")
|
||||
print(f" +0x14 teamId = {tid}")
|
||||
print(f" +0x18 marker = {m18} +0x1c marker = {m1c}")
|
||||
print(f" XI = {xi}")
|
||||
print(f" subs = {subs}")
|
||||
print(f"\n distinct teamIds: {sorted({t for _a, t, *_r in found})}")
|
||||
+1101
File diff suppressed because it is too large
Load Diff
Executable
+161
@@ -0,0 +1,161 @@
|
||||
#!/usr/bin/env python3
|
||||
# -*- coding: utf-8 -*-
|
||||
"""Resolve the runtime string comparator behind `DAT_1802ddfd8 + 0x248`, and
|
||||
settle whether the `itemState` match is case-sensitive.
|
||||
|
||||
READ-ONLY. /proc/PID/mem is opened 'rb'; there is no write path in this file.
|
||||
|
||||
WHY THIS EXISTS
|
||||
---------------
|
||||
`itemState` arrives on the wire as a STRING ("free", "activeHomeKit", ...) and
|
||||
the client turns it into its runtime enum by comparing that string against its
|
||||
own table. The compare goes through `FUN_180008190`, whose whole body is:
|
||||
|
||||
mov rax, [DAT_1802ddfd8] ; the service object, populated at runtime
|
||||
mov r9, [rax + 0x248] ; slot 0x248
|
||||
jmp r9 ; tail-jump
|
||||
|
||||
The slot is empty on disk, so `plan-2026-08-06-card-subsystem.md` section 5
|
||||
recorded the casing question as "almost certainly unresolvable statically" and
|
||||
listed this as a read-only live probe. It is worth answering: every shaper in
|
||||
openfut-adapter-fifa17 emits these tokens, and if the comparator folded case then
|
||||
our table's casing would be a convention rather than a contract.
|
||||
|
||||
WHAT IT DOES
|
||||
------------
|
||||
Reads the slot in the live process and follows the forwarding chain
|
||||
(`e9` rel32 thunk -> `ff 25` IAT jump -> body), attributing each hop to a module.
|
||||
Wine maps PE images as anonymous, so a mapping's own path is usually empty; the
|
||||
module is recovered from the nearest PRECEDING named mapping, which is the PE
|
||||
header page.
|
||||
|
||||
At the body it decides case sensitivity from the instruction stream rather than
|
||||
from a symbol name: a case-insensitive comparator MUST fold case, so it carries
|
||||
an `or ..,0x20` / lowercase-table lookup. A byte compare with no folding is
|
||||
case-SENSITIVE.
|
||||
|
||||
MEASURED 2026-08-21 (pid 6580):
|
||||
slot -> 0x146d1c020 (thunk) -> 0x145e27fe0 (IAT) -> msvcr120.dll + 0x3c330
|
||||
body is strncmp: `sub rdx,rcx` / `test r8,r8` (count) / `test al,al` (NUL) /
|
||||
`cmp al,[rcx+rdx]` with NO case folding, plus the MSVC NUL-detect constants
|
||||
0x8080808080808080 and 0xfefefefefefefeff.
|
||||
=> the itemState match is CASE-SENSITIVE. Emit the table's exact casing.
|
||||
|
||||
Usage: python3 service_ptr_probe.py
|
||||
"""
|
||||
import re
|
||||
import struct
|
||||
import sys
|
||||
|
||||
import watch_club_model as W
|
||||
|
||||
DAT_SERVICE = 0x1802DDFD8
|
||||
SLOT = 0x248
|
||||
MAX_HOPS = 8
|
||||
|
||||
# A case-insensitive comparator has to fold case somewhere. These are the two
|
||||
# ways MSVC does it; neither appears in a plain strcmp/strncmp/memcmp.
|
||||
FOLD_OR_IMM8 = b"\x0c\x20" # or al, 0x20
|
||||
FOLD_OR_EAX = b"\x83\xc8\x20" # or eax, 0x20
|
||||
|
||||
|
||||
def mappings(pid):
|
||||
out = []
|
||||
with open("/proc/%d/maps" % pid) as fh:
|
||||
for line in fh:
|
||||
m = re.match(r"([0-9a-f]+)-([0-9a-f]+) (\S{4}) \S+ \S+ \S+\s*(.*)", line)
|
||||
if m:
|
||||
out.append((int(m.group(1), 16), int(m.group(2), 16), m.group(3), m.group(4)))
|
||||
return out
|
||||
|
||||
|
||||
def attribute(maps, va):
|
||||
"""(module_path, perms, offset_from_module_base) for `va`.
|
||||
|
||||
Wine maps PE sections anonymously, so the owning mapping usually has no
|
||||
path; the module is the nearest preceding NAMED mapping (its header page).
|
||||
"""
|
||||
named = None
|
||||
for start, end, perms, path in maps:
|
||||
if path:
|
||||
named = (start, path)
|
||||
if start <= va < end:
|
||||
if named:
|
||||
return named[1], perms, va - named[0]
|
||||
return path or "[anonymous]", perms, None
|
||||
return None, None, None
|
||||
|
||||
|
||||
def main():
|
||||
pid = W.find_pid()
|
||||
if pid is None:
|
||||
print("FIFA17.exe is not running.")
|
||||
return 1
|
||||
base = W.dll_base(pid)
|
||||
if base is None:
|
||||
print("pid %d is up but %s is not mapped." % (pid, W.DLL))
|
||||
return 1
|
||||
|
||||
mem = W.Mem(pid)
|
||||
maps = mappings(pid)
|
||||
glob = base + (DAT_SERVICE - W.IMG_BASE)
|
||||
svc = mem.q(glob)
|
||||
print("pid=%d %s base=%#x" % (pid, W.DLL, base))
|
||||
print("DAT_1802ddfd8 @ %#x -> service %#x" % (glob, svc or 0))
|
||||
if not svc:
|
||||
print("service pointer is NULL; the host has not handed CardsDLL its table yet.")
|
||||
return 2
|
||||
|
||||
va = mem.q(svc + SLOT)
|
||||
print("*(service + %#x) = %#x" % (SLOT, va or 0))
|
||||
if not va:
|
||||
print("slot %#x is empty." % SLOT)
|
||||
return 2
|
||||
print()
|
||||
|
||||
body = None
|
||||
for hop in range(MAX_HOPS):
|
||||
buf = mem.read(va, 16)
|
||||
if not buf or len(buf) < 6:
|
||||
print("hop %d: %#x unreadable" % (hop, va))
|
||||
return 2
|
||||
path, perms, off = attribute(maps, va)
|
||||
where = "%s+%#x" % (path, off) if off is not None else str(path)
|
||||
print("hop %d: %#x [%s] %s %s" % (hop, va, perms, where, buf[:8].hex()))
|
||||
if buf[0] == 0xE9: # jmp rel32
|
||||
va = va + 5 + struct.unpack("<i", buf[1:5])[0]
|
||||
elif buf[0] == 0xFF and buf[1] == 0x25: # jmp [rip+rel32]
|
||||
nxt = mem.q(va + 6 + struct.unpack("<i", buf[2:6])[0])
|
||||
if not nxt:
|
||||
print(" IAT slot is empty.")
|
||||
return 2
|
||||
va = nxt
|
||||
else:
|
||||
body = (va, path, off)
|
||||
print(" -> function body")
|
||||
break
|
||||
if body is None:
|
||||
print("chain did not settle within %d hops." % MAX_HOPS)
|
||||
return 2
|
||||
|
||||
addr, path, off = body
|
||||
code = mem.read(addr, 256) or b""
|
||||
folds = FOLD_OR_IMM8 in code or FOLD_OR_EAX in code
|
||||
print()
|
||||
print("=" * 70)
|
||||
print("COMPARATOR: %s+%#x (%#x)" % (path, off if off is not None else 0, addr))
|
||||
print("case folding in first %d bytes: %s" % (len(code), "YES" if folds else "NO"))
|
||||
if folds:
|
||||
print("VERDICT: case-INSENSITIVE. itemState casing is a convention, not a contract.")
|
||||
else:
|
||||
print("VERDICT: case-SENSITIVE. A byte compare with no folding means the")
|
||||
print(" wire token must match the table's casing EXACTLY -- a")
|
||||
print(" mis-cased token silently resolves to itemState 0 (invalid).")
|
||||
print(" openfut-adapter-fifa17's fut::item_state table is therefore")
|
||||
print(" a contract: emit its casing verbatim.")
|
||||
print("=" * 70)
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Executable
+65
@@ -0,0 +1,65 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Pure unit test for the empty-My-Packs store resolver guard in autopatch.py.
|
||||
|
||||
Covers the fail-closed guard decision (original -> PATCH, already-patched -> NOOP,
|
||||
unknown -> SKIP) and pins the guarded patch table to the exact RVA/bytes proven on
|
||||
the tested FIFA 17 build (JNZ 0x14869 -> JG 0x14869 at CardsDLL RVA 0x14858).
|
||||
|
||||
Run: python3 test_autopatch_guard.py
|
||||
"""
|
||||
import os
|
||||
import sys
|
||||
|
||||
sys.path.insert(0, os.path.dirname(os.path.abspath(__file__)))
|
||||
import autopatch # importable: runtime loop is guarded by `if __name__ == "__main__"`
|
||||
|
||||
GUARD_VA = 0x180014858
|
||||
ORIG = bytes.fromhex("750f") # JNZ 0x14869
|
||||
PATCH = bytes.fromhex("7f0f") # JG 0x14869
|
||||
|
||||
|
||||
def test_table_exact():
|
||||
assert autopatch.STORE_PATCHES_GUARDED == {GUARD_VA: (ORIG, PATCH)}, \
|
||||
autopatch.STORE_PATCHES_GUARDED
|
||||
# Byte-level pin so a bad hex literal cannot slip through.
|
||||
assert ORIG == b"\x75\x0f" and PATCH == b"\x7f\x0f"
|
||||
|
||||
|
||||
def test_decision():
|
||||
assert autopatch.guarded_action(ORIG, ORIG, PATCH) == "patch" # apply
|
||||
assert autopatch.guarded_action(PATCH, ORIG, PATCH) == "noop" # already patched
|
||||
assert autopatch.guarded_action(b"\x00\x00", ORIG, PATCH) == "skip" # build mismatch
|
||||
assert autopatch.guarded_action(b"\x90", ORIG, PATCH) == "skip" # wrong length
|
||||
|
||||
|
||||
def test_guard_state_after():
|
||||
# already patched (7f0f) -> VERIFIED (guarded_action "noop"); write args irrelevant.
|
||||
assert autopatch.guard_state_after(PATCH, ORIG, PATCH, True, PATCH) == autopatch.GUARD_VERIFIED
|
||||
# original (750f) + write ok + reread 7f0f -> VERIFIED (guarded_action "patch").
|
||||
assert autopatch.guard_state_after(ORIG, ORIG, PATCH, True, PATCH) == autopatch.GUARD_VERIFIED
|
||||
# original + write FAILS -> WRITE_FAILED.
|
||||
assert autopatch.guard_state_after(ORIG, ORIG, PATCH, False, ORIG) == autopatch.GUARD_WRITE_FAILED
|
||||
# original + write ok but reread != 7f0f -> VERIFY_FAILED.
|
||||
assert autopatch.guard_state_after(ORIG, ORIG, PATCH, True, ORIG) == autopatch.GUARD_VERIFY_FAILED
|
||||
assert autopatch.guard_state_after(ORIG, ORIG, PATCH, True, b"") == autopatch.GUARD_VERIFY_FAILED
|
||||
# unknown bytes -> UNSUPPORTED_BUILD (guarded_action "skip"); write args irrelevant.
|
||||
assert autopatch.guard_state_after(b"\x00\x00", ORIG, PATCH, True, PATCH) == autopatch.GUARD_UNSUPPORTED_BUILD
|
||||
|
||||
|
||||
def test_capability_constants():
|
||||
assert autopatch.EMPTY_MYPACKS_RESOLVER_VERSION == 1
|
||||
assert autopatch.EMPTY_MYPACKS_RESOLVER_CAPABILITY == "fifa17.empty_mypacks_resolver"
|
||||
# State constant values are the exact tokens carried in the emitted status line.
|
||||
assert autopatch.GUARD_VERIFIED == "VERIFIED"
|
||||
assert autopatch.GUARD_UNSUPPORTED_BUILD == "UNSUPPORTED_BUILD"
|
||||
assert autopatch.GUARD_WRITE_FAILED == "WRITE_FAILED"
|
||||
assert autopatch.GUARD_VERIFY_FAILED == "VERIFY_FAILED"
|
||||
assert autopatch.GUARD_NOT_ATTEMPTED == "NOT_ATTEMPTED"
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
test_table_exact()
|
||||
test_decision()
|
||||
test_guard_state_after()
|
||||
test_capability_constants()
|
||||
print("OK: autopatch guard table + fail-closed decision + guard-state function + capability constants")
|
||||
+301
@@ -0,0 +1,301 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Tests for the FIFA 17 verified-patched-client capability negotiation.
|
||||
|
||||
The additive empty-My-Packs switch on top of the P2 65534 sentinel: the sentinel is
|
||||
suppressed for ONE FIFA session only when the launcher has registered a verified
|
||||
resolver capability (v1) that binds to THAT process's UTAS session (keyed by the
|
||||
per-login-unique X-UT-SID; source IP + persona are auxiliary). Every failure /
|
||||
unknown / late / cross-process / cross-session case is fail-closed to the sentinel.
|
||||
|
||||
The initial prototype keyed by source IP alone; this suite proves the hardened
|
||||
per-session binding, including two sessions that SHARE a source IP.
|
||||
|
||||
Matrix (docs/plans/FIFA17_PATCHED_CLIENT_CAPABILITY.md):
|
||||
A no-capability, zero packs -> sentinel
|
||||
B verified v1, zero packs -> clean (no 65534)
|
||||
C real unopened pack + no capability -> genuine pack, no sentinel
|
||||
D real unopened pack + capability -> genuine pack, no sentinel
|
||||
E unsupported version / capability -> endpoint 400 AND mode sentinel
|
||||
F late capability after sentinel freeze -> stays sentinel
|
||||
G capability disappears after clean freeze -> stays clean (immutable)
|
||||
H two IPs (A verified, B none) -> A clean, B sentinel (no global leak)
|
||||
I new session after reset -> fresh unpatched -> sentinel
|
||||
J autopatch mismatch => never registers -> sentinel
|
||||
K SAME IP, two sessions (A patched, B not) -> A clean, B sentinel
|
||||
L SAME IP+persona relaunch (old ok, new not) -> new session sentinel
|
||||
M SAME IP, failed-patch second session -> first clean, second sentinel
|
||||
N late registration when sessions are frozen -> does not modify active sessions
|
||||
O session cleanup / TTL expiry -> capability gone, sentinel
|
||||
P duplicate registration for a session -> idempotent; no post-freeze change
|
||||
Q register-before-login (pending consumed) -> clean
|
||||
R topology freeze immutable per SID -> no flip either way; new SID fresh
|
||||
|
||||
Standalone unit test in the project style: `python3 test_capability_negotiation.py`.
|
||||
"""
|
||||
import importlib
|
||||
import json
|
||||
import os
|
||||
import sys
|
||||
import tempfile
|
||||
|
||||
TOOLS = os.path.dirname(os.path.abspath(__file__))
|
||||
if TOOLS not in sys.path:
|
||||
sys.path.insert(0, TOOLS)
|
||||
|
||||
SENTINEL_ID = 65534
|
||||
REAL_PACK_ID = 1
|
||||
PERSONA = 111001
|
||||
|
||||
|
||||
class _H:
|
||||
"""Minimal request-handler stand-in: peer IP, optional X-UT-SID, optional body."""
|
||||
|
||||
def __init__(self, ip, body=None, sid=None):
|
||||
self.client_address = (ip, 54321)
|
||||
self.headers = {"X-UT-SID": sid} if sid is not None else {}
|
||||
self._body = json.dumps(body).encode("utf-8") if body is not None else b""
|
||||
|
||||
|
||||
def _ids(catalog):
|
||||
return [p["id"] for p in catalog["purchase"]]
|
||||
|
||||
|
||||
def main():
|
||||
with tempfile.TemporaryDirectory() as state:
|
||||
os.environ["FUT_ACCOUNT_PATH"] = os.path.join(state, "active_account.json")
|
||||
os.environ["FUT_PROFILE_ROOT"] = os.path.join(state, "accounts")
|
||||
os.environ.pop("FUT_PROFILE", None)
|
||||
|
||||
import fut_account
|
||||
import fut_store
|
||||
import fut_accounts
|
||||
import utas_server
|
||||
importlib.reload(fut_account)
|
||||
importlib.reload(fut_store)
|
||||
importlib.reload(fut_accounts)
|
||||
importlib.reload(utas_server)
|
||||
|
||||
us = utas_server
|
||||
CLEAN, SENT = us.FIFA17_MODE_CLEAN, us.FIFA17_MODE_SENTINEL
|
||||
|
||||
_orig_visible = us.visible_unopened_packs
|
||||
|
||||
def set_zero_packs():
|
||||
us.visible_unopened_packs = lambda: []
|
||||
|
||||
def set_real_pack():
|
||||
us.visible_unopened_packs = lambda: [REAL_PACK_ID]
|
||||
|
||||
def reset_state():
|
||||
us._FIFA17_SESSIONS.clear()
|
||||
us._FIFA17_PENDING.clear()
|
||||
|
||||
def auth(sid, ip, persona=PERSONA):
|
||||
"""Simulate /ut/auth opening a per-login session with a chosen sid."""
|
||||
us.fifa17_open_session(sid, ip, persona)
|
||||
|
||||
def register(ip, version, persona=PERSONA, pid=4242):
|
||||
return us.fifa17_capability_route(_H(ip, {
|
||||
"capability": "empty_mypacks_resolver", "version": version,
|
||||
"personaId": persona, "fifaPid": pid,
|
||||
}))
|
||||
|
||||
def store(sid, ip):
|
||||
status, cat = us.store_catalog(_H(ip, sid=sid))
|
||||
assert status == 200, status
|
||||
return _ids(cat)
|
||||
|
||||
def mode_of(sid):
|
||||
return us._FIFA17_SESSIONS[sid]["mode"]
|
||||
|
||||
try:
|
||||
# ---- A. no capability, zero packs -> sentinel ----------------------
|
||||
reset_state(); set_zero_packs()
|
||||
auth("sidA", "10.0.0.1")
|
||||
assert SENTINEL_ID in store("sidA", "10.0.0.1")
|
||||
assert mode_of("sidA") == SENT
|
||||
print("A no-capability zero-packs -> sentinel: OK")
|
||||
|
||||
# ---- B. verified v1, zero packs -> clean ---------------------------
|
||||
reset_state(); set_zero_packs()
|
||||
auth("sidB", "10.0.0.2")
|
||||
assert register("10.0.0.2", 1)[0] == 200
|
||||
ids = store("sidB", "10.0.0.2")
|
||||
assert SENTINEL_ID not in ids, ids
|
||||
assert mode_of("sidB") == CLEAN
|
||||
print("B verified-v1 zero-packs -> clean: OK")
|
||||
|
||||
# ---- C. real pack + no capability -> genuine, no sentinel ----------
|
||||
reset_state(); set_real_pack()
|
||||
auth("sidC", "10.0.0.3")
|
||||
ids = store("sidC", "10.0.0.3")
|
||||
assert REAL_PACK_ID in ids and SENTINEL_ID not in ids, ids
|
||||
print("C real-pack no-capability -> genuine, no sentinel: OK")
|
||||
|
||||
# ---- D. real pack + capability -> genuine, no sentinel -------------
|
||||
reset_state(); set_real_pack()
|
||||
auth("sidD", "10.0.0.4"); register("10.0.0.4", 1)
|
||||
ids = store("sidD", "10.0.0.4")
|
||||
assert REAL_PACK_ID in ids and SENTINEL_ID not in ids, ids
|
||||
print("D real-pack capability -> genuine, no sentinel: OK")
|
||||
|
||||
# ---- E. unsupported version / capability -> 400 + sentinel ---------
|
||||
reset_state(); set_zero_packs()
|
||||
auth("sidE", "10.0.0.5")
|
||||
assert register("10.0.0.5", 2)[0] == 400
|
||||
assert register("10.0.0.5", 99)[0] == 400
|
||||
assert us.fifa17_capability_route(
|
||||
_H("10.0.0.5", {"capability": "bogus", "version": 1}))[0] == 400
|
||||
assert SENTINEL_ID in store("sidE", "10.0.0.5")
|
||||
assert mode_of("sidE") == SENT
|
||||
print("E unsupported version/capability -> 400 + sentinel: OK")
|
||||
|
||||
# ---- F. late capability after sentinel freeze -> sentinel ----------
|
||||
reset_state(); set_zero_packs()
|
||||
auth("sidF", "10.0.0.6")
|
||||
assert SENTINEL_ID in store("sidF", "10.0.0.6") # freezes sentinel
|
||||
assert register("10.0.0.6", 1)[0] == 200 # session frozen -> ignored-late
|
||||
assert SENTINEL_ID in store("sidF", "10.0.0.6")
|
||||
assert mode_of("sidF") == SENT
|
||||
print("F late capability after sentinel freeze -> sentinel: OK")
|
||||
|
||||
# ---- G. capability disappears after clean freeze -> clean ----------
|
||||
reset_state(); set_zero_packs()
|
||||
auth("sidG", "10.0.0.7"); register("10.0.0.7", 1)
|
||||
assert SENTINEL_ID not in store("sidG", "10.0.0.7") # freezes clean
|
||||
us._FIFA17_SESSIONS["sidG"]["resolver"] = None # capability vanishes
|
||||
assert SENTINEL_ID not in store("sidG", "10.0.0.7")
|
||||
assert mode_of("sidG") == CLEAN
|
||||
print("G capability disappears after clean freeze -> clean: OK")
|
||||
|
||||
# ---- H. two IPs (A verified, B none) -> no global leak -------------
|
||||
reset_state(); set_zero_packs()
|
||||
auth("sidH1", "10.0.1.1"); register("10.0.1.1", 1)
|
||||
auth("sidH2", "10.0.1.2")
|
||||
assert SENTINEL_ID not in store("sidH1", "10.0.1.1")
|
||||
assert SENTINEL_ID in store("sidH2", "10.0.1.2")
|
||||
print("H two IPs (A clean, B sentinel) -> no global leak: OK")
|
||||
|
||||
# ---- I. new session after reset -> fresh unpatched -> sentinel -----
|
||||
reset_state(); set_zero_packs()
|
||||
auth("sidI1", "10.0.1.3"); register("10.0.1.3", 1)
|
||||
assert SENTINEL_ID not in store("sidI1", "10.0.1.3") # A clean
|
||||
us.fifa17_clear_pending("10.0.1.3") # relaunch boundary
|
||||
auth("sidI2", "10.0.1.3") # new SID, autopatch failed
|
||||
assert SENTINEL_ID in store("sidI2", "10.0.1.3")
|
||||
print("I new session after reset -> sentinel (no cross-process leak): OK")
|
||||
|
||||
# ---- J. autopatch mismatch => never registers -> sentinel ----------
|
||||
reset_state(); set_zero_packs()
|
||||
auth("sidJ", "10.0.1.4")
|
||||
assert SENTINEL_ID in store("sidJ", "10.0.1.4")
|
||||
print("J autopatch mismatch (never registers) -> sentinel: OK")
|
||||
|
||||
# ---- K. SAME IP, two sessions: patched A clean, unpatched B sent ---
|
||||
reset_state(); set_zero_packs()
|
||||
IP = "10.0.2.1"
|
||||
auth("sidK_A", IP)
|
||||
assert register(IP, 1)[0] == 200 # A sole candidate -> bound
|
||||
auth("sidK_B", IP) # B joins, never registers
|
||||
assert SENTINEL_ID not in store("sidK_A", IP)
|
||||
assert SENTINEL_ID in store("sidK_B", IP)
|
||||
print("K same-IP two sessions -> A clean, B sentinel: OK")
|
||||
|
||||
# ---- L. SAME IP+persona relaunch: old ok, new not -> new sentinel --
|
||||
reset_state(); set_zero_packs()
|
||||
IP = "10.0.2.2"
|
||||
auth("sidL_old", IP, PERSONA); register(IP, 1, PERSONA)
|
||||
assert SENTINEL_ID not in store("sidL_old", IP)
|
||||
us.fifa17_clear_pending(IP)
|
||||
auth("sidL_new", IP, PERSONA) # same persona, unverified
|
||||
assert SENTINEL_ID in store("sidL_new", IP)
|
||||
print("L same-IP+persona relaunch -> new session sentinel: OK")
|
||||
|
||||
# ---- M. SAME IP, failed-patch second session -----------------------
|
||||
reset_state(); set_zero_packs()
|
||||
IP = "10.0.2.3"
|
||||
auth("sidM1", IP); register(IP, 1)
|
||||
assert SENTINEL_ID not in store("sidM1", IP)
|
||||
auth("sidM2", IP) # autopatch failed
|
||||
assert SENTINEL_ID in store("sidM2", IP)
|
||||
print("M same-IP failed-patch second session -> sentinel: OK")
|
||||
|
||||
# ---- N. late reg when sessions frozen -> no active session change --
|
||||
reset_state(); set_zero_packs()
|
||||
IP = "10.0.2.4"
|
||||
auth("sidN1", IP); register(IP, 1)
|
||||
assert SENTINEL_ID not in store("sidN1", IP) # N1 frozen clean
|
||||
auth("sidN2", IP)
|
||||
assert SENTINEL_ID in store("sidN2", IP) # N2 frozen sentinel
|
||||
assert register(IP, 1)[0] == 200 # late: both frozen -> ignored
|
||||
assert SENTINEL_ID not in store("sidN1", IP) # unchanged
|
||||
assert SENTINEL_ID in store("sidN2", IP) # unchanged
|
||||
print("N late registration does not modify active sessions: OK")
|
||||
|
||||
# ---- O. session cleanup / TTL expiry -> capability gone ------------
|
||||
reset_state(); set_zero_packs()
|
||||
IP = "10.0.2.5"
|
||||
auth("sidO", IP); register(IP, 1)
|
||||
assert SENTINEL_ID not in store("sidO", IP) # clean while live
|
||||
us._FIFA17_SESSIONS["sidO"]["last_seen"] = (
|
||||
us._fifa17_now() - us.FIFA17_SESSION_TTL - 10.0)
|
||||
store("sidUNKNOWN", IP) # any op triggers reap
|
||||
assert "sidO" not in us._FIFA17_SESSIONS, "expired session not reaped"
|
||||
assert SENTINEL_ID in store("sidO", IP) # gone -> sentinel
|
||||
print("O session cleanup / TTL expiry -> sentinel: OK")
|
||||
|
||||
# ---- P. duplicate registration -> idempotent, no post-freeze change
|
||||
reset_state(); set_zero_packs()
|
||||
IP = "10.0.2.6"
|
||||
auth("sidP", IP)
|
||||
assert register(IP, 1)[0] == 200 # bound
|
||||
assert register(IP, 1)[0] == 200 # duplicate -> ignored-late
|
||||
assert SENTINEL_ID not in store("sidP", IP) # still clean
|
||||
assert register(IP, 1)[0] == 200 # after freeze
|
||||
assert SENTINEL_ID not in store("sidP", IP) # unchanged
|
||||
assert mode_of("sidP") == CLEAN
|
||||
print("P duplicate registration -> idempotent: OK")
|
||||
|
||||
# ---- Q. register-before-login: pending consumed at auth -> clean ---
|
||||
reset_state(); set_zero_packs()
|
||||
IP = "10.0.2.7"
|
||||
assert register(IP, 1)[0] == 200 # no session yet -> pending
|
||||
assert (IP, PERSONA) in us._FIFA17_PENDING
|
||||
auth("sidQ", IP, PERSONA) # consumes pending
|
||||
assert (IP, PERSONA) not in us._FIFA17_PENDING # single-use
|
||||
assert SENTINEL_ID not in store("sidQ", IP)
|
||||
assert mode_of("sidQ") == CLEAN
|
||||
print("Q register-before-login pending consumed -> clean: OK")
|
||||
|
||||
# ---- R. topology freeze immutable per SID; new SID decides fresh ----
|
||||
# F3 invariant: once a SID's store topology is decided it NEVER flips,
|
||||
# in either direction, and a different SID may decide differently.
|
||||
reset_state(); set_zero_packs()
|
||||
IP = "10.0.2.8"
|
||||
# frozen Sentinel never becomes Clean, even if a capability appears later
|
||||
auth("sidR_s", IP)
|
||||
assert SENTINEL_ID in store("sidR_s", IP) # freeze Sentinel
|
||||
register(IP, 1)
|
||||
us._FIFA17_SESSIONS["sidR_s"]["resolver"] = 1 # force-present capability
|
||||
assert SENTINEL_ID in store("sidR_s", IP) # STILL Sentinel
|
||||
assert mode_of("sidR_s") == SENT
|
||||
# frozen Clean never becomes Sentinel, even if the capability is wiped
|
||||
auth("sidR_c", IP); register(IP, 1)
|
||||
assert SENTINEL_ID not in store("sidR_c", IP) # freeze Clean
|
||||
us._FIFA17_SESSIONS["sidR_c"]["resolver"] = None # capability vanishes
|
||||
assert SENTINEL_ID not in store("sidR_c", IP) # STILL Clean
|
||||
assert mode_of("sidR_c") == CLEAN
|
||||
# a fresh SID (same IP) decides independently
|
||||
auth("sidR_new", IP)
|
||||
assert SENTINEL_ID in store("sidR_new", IP)
|
||||
print("R topology freeze immutable per SID; new SID fresh: OK")
|
||||
|
||||
finally:
|
||||
us.visible_unopened_packs = _orig_visible
|
||||
|
||||
print("capability negotiation matrix A-R: OK")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
raise SystemExit(main())
|
||||
Executable
+136
@@ -0,0 +1,136 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Regression tests for the empty-My-Packs FIFA 17 compatibility workaround (bug 6c).
|
||||
|
||||
Pins the behavior store_catalog() now depends on:
|
||||
- unopenedPackIds == [] -> exactly one synthetic active `mypacks` placeholder id 65534
|
||||
- unopenedPackIds == [70] -> no synthetic placeholder; the genuine owned pack is shown
|
||||
- synthetic id 65534 stays economy-safe (non-resolvable, non-openable, non-granting)
|
||||
- normal store packs (1/5/6/7) are untouched by the empty-state behavior
|
||||
|
||||
See docs/evidence/STORE_TILE_6C.md and FIFA17_EMPTY_MYPACKS_CLIENT_CONTRACT.md.
|
||||
Standalone unit test in the project style: `python3 test_empty_mypacks.py`.
|
||||
"""
|
||||
import importlib
|
||||
import os
|
||||
import sys
|
||||
import tempfile
|
||||
|
||||
TOOLS = os.path.dirname(os.path.abspath(__file__))
|
||||
if TOOLS not in sys.path:
|
||||
sys.path.insert(0, TOOLS)
|
||||
|
||||
SENTINEL_ID = 65534
|
||||
|
||||
|
||||
def _set_unopened(fut_store, ids):
|
||||
"""Deterministically set the active profile's owned unopened packs."""
|
||||
p = fut_store.STORE.load()
|
||||
p["unopenedPackIds"] = list(ids)
|
||||
fut_store.STORE._save()
|
||||
|
||||
|
||||
def _mypacks(catalog):
|
||||
return [p for p in catalog["purchase"]
|
||||
if (p.get("displayGroup") or {}).get("value") == "mypacks"]
|
||||
|
||||
|
||||
def _fake_request(command, body):
|
||||
class _H:
|
||||
pass
|
||||
h = _H()
|
||||
h.command = command
|
||||
h._body = body
|
||||
return h
|
||||
|
||||
|
||||
def main():
|
||||
with tempfile.TemporaryDirectory() as state:
|
||||
os.environ["FUT_ACCOUNT_PATH"] = os.path.join(state, "active_account.json")
|
||||
os.environ["FUT_PROFILE_ROOT"] = os.path.join(state, "accounts")
|
||||
os.environ.pop("FUT_PROFILE", None)
|
||||
|
||||
import fut_account
|
||||
import fut_store
|
||||
import fut_accounts
|
||||
import utas_server
|
||||
importlib.reload(fut_account)
|
||||
importlib.reload(fut_store)
|
||||
importlib.reload(fut_accounts)
|
||||
importlib.reload(utas_server)
|
||||
|
||||
fut_accounts.activate({"personaId": 111001, "personaName": "TEST_A"})
|
||||
catalog_ids = [p["id"] for p in fut_store.PACK_CATALOG]
|
||||
|
||||
# ---- A. Empty unopened packs -> one active synthetic 65534 placeholder ----
|
||||
_set_unopened(fut_store, [])
|
||||
utas_server._OPENED_PACK_GRACE.clear()
|
||||
status, cat = utas_server.store_catalog(None)
|
||||
assert status == 200
|
||||
myp = _mypacks(cat)
|
||||
assert len(myp) == 1, "expected exactly one mypacks entry, got %r" % myp
|
||||
s = myp[0]
|
||||
assert s["id"] == SENTINEL_ID, s
|
||||
assert s["state"] == "active", s # the P2 fix: active, not inactive
|
||||
assert (s.get("displayGroup") or {}).get("value") == "mypacks", s
|
||||
assert SENTINEL_ID not in catalog_ids, "65534 must not be in PACK_CATALOG"
|
||||
assert fut_store.pack_by_id(SENTINEL_ID) is None
|
||||
print("A empty-state active placeholder: PASS")
|
||||
|
||||
# ---- D (empty half). Normal packs untouched in empty state ----
|
||||
norm = {p["id"]: p for p in cat["purchase"] if p["id"] in (1, 5, 6, 7)}
|
||||
assert set(norm) == {1, 5, 6, 7}, sorted(norm)
|
||||
assert all(norm[i]["state"] == "active" for i in norm), norm
|
||||
assert norm[1]["packType"] == "BRONZE" and norm[1]["description"] == "Bronze Pack"
|
||||
|
||||
# ---- B. Non-empty unopened packs -> NO synthetic; genuine owned pack shown ----
|
||||
_set_unopened(fut_store, [70])
|
||||
utas_server._OPENED_PACK_GRACE.clear()
|
||||
status, cat = utas_server.store_catalog(None)
|
||||
assert status == 200
|
||||
ids = [p["id"] for p in cat["purchase"]]
|
||||
assert SENTINEL_ID not in ids, "synthetic placeholder must be suppressed when a pack exists"
|
||||
myp = _mypacks(cat)
|
||||
assert len(myp) == 1 and myp[0]["id"] == 70, myp
|
||||
assert myp[0]["state"] == "active" and myp[0]["unopened"] is True, myp[0]
|
||||
# normal packs still intact alongside the owned pack
|
||||
assert {1, 5, 6, 7}.issubset(set(ids)), sorted(ids)
|
||||
print("B non-empty-state genuine pack: PASS")
|
||||
|
||||
# ---- C. Economy safety of the synthetic placeholder ----
|
||||
_set_unopened(fut_store, [])
|
||||
utas_server._OPENED_PACK_GRACE.clear()
|
||||
coins0 = fut_store.STORE.coins()
|
||||
items0 = len(fut_store.STORE.items())
|
||||
next0 = fut_store.STORE.load()["nextItemId"]
|
||||
|
||||
assert fut_store.pack_by_id(SENTINEL_ID) is None
|
||||
|
||||
# store_buy: a confirmed-buy transaction for 65534 must be a no-op {}
|
||||
status, body = utas_server.store_buy(
|
||||
_fake_request("PUT", b'{"packId":65534,"state":"TRANSACTIONCREATED"}'))
|
||||
assert status == 200 and body == {}, (status, body)
|
||||
|
||||
# purchased_items: POST buy for 65534 must not open/grant anything
|
||||
status, body = utas_server.purchased_items(
|
||||
_fake_request("POST", b'{"packId":65534,"useCredits":1,"usePreOrder":0,"currency":"COINS"}'))
|
||||
assert status == 200, (status, body)
|
||||
assert "createPackResponse" not in body, body
|
||||
|
||||
# 65534 cannot enter the owned-pack pile (not a catalog pack)
|
||||
assert fut_store.STORE.grant_unopened_pack(SENTINEL_ID) is False
|
||||
assert SENTINEL_ID not in fut_store.STORE.unopened_packs()
|
||||
|
||||
# nothing mutated
|
||||
assert fut_store.STORE.coins() == coins0, (fut_store.STORE.coins(), coins0)
|
||||
assert len(fut_store.STORE.items()) == items0
|
||||
assert fut_store.STORE.load()["nextItemId"] == next0
|
||||
assert not any(i.get("id") == SENTINEL_ID or i.get("resourceId") == SENTINEL_ID
|
||||
for i in fut_store.STORE.items())
|
||||
print("C economy safety (65534 non-openable / non-granting): PASS")
|
||||
|
||||
print("empty My Packs compatibility: PASS")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
raise SystemExit(main())
|
||||
+61
@@ -0,0 +1,61 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Standalone contract test for Blaze roster-host advertisement."""
|
||||
|
||||
import importlib
|
||||
import os
|
||||
import sys
|
||||
|
||||
TOOLS = os.path.dirname(os.path.abspath(__file__))
|
||||
if TOOLS not in sys.path:
|
||||
sys.path.insert(0, TOOLS)
|
||||
|
||||
ADVERTISE = "192.0.2.10"
|
||||
DNS_HOST = "winter15.gosredirector.ea.com:8081"
|
||||
|
||||
|
||||
def assert_roster_config(blaze, host):
|
||||
config = dict(blaze.OSDK_ROSTER)
|
||||
assert blaze.ROSTER_HOST == host
|
||||
assert config["ROSTERUPDATE_URL"] == (
|
||||
f"https://{host}/fifa17/fut/rosterupdate.xml"
|
||||
)
|
||||
assert config["ROSTER_URL"] == f"https://{host}/fifa17/roster/"
|
||||
assert config["ROSTER_VER"] == "0"
|
||||
assert config["ROSTER_CSUM"] == ""
|
||||
|
||||
|
||||
def main():
|
||||
old_advertise = os.environ.get("OPENFUT_ADVERTISE")
|
||||
old_roster_host = os.environ.get("OPENFUT_ROSTER_HOST")
|
||||
try:
|
||||
os.environ["OPENFUT_ADVERTISE"] = ADVERTISE
|
||||
os.environ.pop("OPENFUT_ROSTER_HOST", None)
|
||||
|
||||
import blaze_responder_v3b as blaze
|
||||
|
||||
blaze = importlib.reload(blaze)
|
||||
assert_roster_config(blaze, f"{ADVERTISE}:8081")
|
||||
|
||||
os.environ["OPENFUT_ROSTER_HOST"] = DNS_HOST
|
||||
blaze = importlib.reload(blaze)
|
||||
assert_roster_config(blaze, DNS_HOST)
|
||||
|
||||
os.environ["OPENFUT_ROSTER_HOST"] = ""
|
||||
blaze = importlib.reload(blaze)
|
||||
assert_roster_config(blaze, f"{ADVERTISE}:8081")
|
||||
finally:
|
||||
if old_advertise is None:
|
||||
os.environ.pop("OPENFUT_ADVERTISE", None)
|
||||
else:
|
||||
os.environ["OPENFUT_ADVERTISE"] = old_advertise
|
||||
if old_roster_host is None:
|
||||
os.environ.pop("OPENFUT_ROSTER_HOST", None)
|
||||
else:
|
||||
os.environ["OPENFUT_ROSTER_HOST"] = old_roster_host
|
||||
|
||||
print("PASS: roster host defaults, override, and URLs")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
raise SystemExit(main())
|
||||
+512
@@ -0,0 +1,512 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Supervise one hardware-only FIFA17 match-team writer capture.
|
||||
|
||||
This is the robust fresh-client entry point. It waits for the largest-RSS
|
||||
FIFA17.exe process that has CardsDLL loaded, attaches gdb before FUT navigation
|
||||
can construct match teams, and loads a hardware-only GDB Python payload.
|
||||
|
||||
The concurrent read-only structural locator proves when the fixture and final
|
||||
match-team records exist. A zero-hit result is trusted only if gdb is still
|
||||
alive, TracerPid is the gdb process, the payload reported `trace_armed`, no
|
||||
records pre-existed the trace, and two final records then appeared.
|
||||
|
||||
The default payload traces FUN_1800fc500 and derives a 4-byte teamId[1]
|
||||
watchpoint from live RDX. Other payloads trace the final engine writer or its
|
||||
caller; all expose the same `start_trace(log, cards_base)` entry point.
|
||||
|
||||
No INT3/software breakpoints. No client memory writes. /proc/<pid>/mem is opened
|
||||
'rb'. The operator alone drives the game.
|
||||
|
||||
trace_match_team_writer.py --status /tmp/mt-status.json \
|
||||
--trace /tmp/mt-trace.jsonl --gdb-log /tmp/mt-gdb.log --fixture-index 0
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
import json
|
||||
import os
|
||||
import signal
|
||||
import subprocess
|
||||
import sys
|
||||
import tempfile
|
||||
import time
|
||||
from dataclasses import asdict
|
||||
from pathlib import Path
|
||||
|
||||
from offline_match_locator import find_pids, scan_process
|
||||
|
||||
CARDS_IMAGE_BASE = 0x180000000
|
||||
DEFAULT_TIMEOUT = 45 * 60
|
||||
|
||||
|
||||
def cards_base(pid: int) -> int | None:
|
||||
try:
|
||||
with open(f"/proc/{pid}/maps") as maps:
|
||||
for line in maps:
|
||||
if "CardsDLL_Win64_retail.dll" in line:
|
||||
return int(line.split("-", 1)[0], 16)
|
||||
except OSError:
|
||||
pass
|
||||
return None
|
||||
|
||||
|
||||
def tracer_pid(pid: int) -> int | None:
|
||||
try:
|
||||
with open(f"/proc/{pid}/status") as status:
|
||||
for line in status:
|
||||
if line.startswith("TracerPid:"):
|
||||
return int(line.split()[1])
|
||||
except OSError:
|
||||
pass
|
||||
return None
|
||||
|
||||
|
||||
def target_state(pid: int) -> str | None:
|
||||
try:
|
||||
with open(f"/proc/{pid}/status") as status:
|
||||
for line in status:
|
||||
if line.startswith("State:"):
|
||||
return line.split()[1]
|
||||
except OSError:
|
||||
pass
|
||||
return None
|
||||
|
||||
|
||||
def read_events(path: Path) -> list[dict]:
|
||||
if not path.exists():
|
||||
return []
|
||||
events = []
|
||||
try:
|
||||
with path.open(encoding="utf-8", errors="replace") as handle:
|
||||
for line in handle:
|
||||
try:
|
||||
events.append(json.loads(line))
|
||||
except json.JSONDecodeError:
|
||||
continue
|
||||
except OSError:
|
||||
return []
|
||||
return events
|
||||
|
||||
|
||||
def event_counts(events: list[dict]) -> dict[str, int]:
|
||||
counts: dict[str, int] = {}
|
||||
for event in events:
|
||||
kind = event.get("event", "unknown")
|
||||
counts[kind] = counts.get(kind, 0) + 1
|
||||
return counts
|
||||
|
||||
|
||||
class Status:
|
||||
def __init__(self, path: Path, monitor_log: Path):
|
||||
self.path = path
|
||||
self.monitor_log = monitor_log
|
||||
self.data: dict = {"started_unix": time.time(), "state": "starting"}
|
||||
self.write()
|
||||
|
||||
def write(self, **updates):
|
||||
self.data.update(updates)
|
||||
self.data["updated_unix"] = time.time()
|
||||
temporary = self.path.with_suffix(self.path.suffix + ".tmp")
|
||||
temporary.write_text(json.dumps(self.data, indent=2, sort_keys=True) + "\n")
|
||||
os.replace(temporary, self.path)
|
||||
|
||||
def log(self, message: str, **payload):
|
||||
record = {"time_unix": time.time(), "message": message, **payload}
|
||||
with self.monitor_log.open("a", encoding="utf-8") as handle:
|
||||
handle.write(json.dumps(record, sort_keys=True) + "\n")
|
||||
handle.flush()
|
||||
os.fsync(handle.fileno())
|
||||
print(message, flush=True)
|
||||
|
||||
|
||||
def gdb_commands(pid: int, cards: int, payload: Path, trace: Path) -> str:
|
||||
# Wine uses these signals for thread suspension/runtime plumbing. They must
|
||||
# pass through, or batch gdb stops and silently detaches.
|
||||
signals = ["SIGUSR1", "SIGUSR2", "SIGPIPE", "SIGCHLD"] + [
|
||||
f"SIG{number}" for number in range(32, 40)
|
||||
]
|
||||
lines = [
|
||||
"set confirm off",
|
||||
"set pagination off",
|
||||
"set height 0",
|
||||
"set width 0",
|
||||
f"attach {pid}",
|
||||
]
|
||||
lines.extend(f"handle {name} nostop noprint pass" for name in signals)
|
||||
lines.extend(
|
||||
[
|
||||
f"source {payload}",
|
||||
f'python start_trace({json.dumps(str(trace))}, {cards})',
|
||||
"continue",
|
||||
]
|
||||
)
|
||||
return "\n".join(lines) + "\n"
|
||||
|
||||
|
||||
def serialise_locations(locations: dict) -> dict:
|
||||
return {key: [asdict(value) for value in values] for key, values in locations.items()}
|
||||
|
||||
|
||||
def terminate_gdb(process: subprocess.Popen, status: Status, pid: int):
|
||||
if process.poll() is None:
|
||||
process.terminate()
|
||||
try:
|
||||
process.wait(timeout=12)
|
||||
except subprocess.TimeoutExpired:
|
||||
process.kill()
|
||||
process.wait(timeout=5)
|
||||
deadline = time.time() + 8
|
||||
while time.time() < deadline and tracer_pid(pid):
|
||||
time.sleep(0.25)
|
||||
status.log(
|
||||
"gdb detached",
|
||||
gdb_returncode=process.returncode,
|
||||
tracer_pid=tracer_pid(pid),
|
||||
target_state=target_state(pid),
|
||||
)
|
||||
|
||||
|
||||
def main() -> int:
|
||||
parser = argparse.ArgumentParser(description=__doc__)
|
||||
parser.add_argument("--status", type=Path, required=True)
|
||||
parser.add_argument("--trace", type=Path, required=True)
|
||||
parser.add_argument("--gdb-log", type=Path, required=True)
|
||||
parser.add_argument("--monitor-log", type=Path, default=Path("/tmp/mt-monitor.jsonl"))
|
||||
parser.add_argument("--fixture-index", type=int, default=0)
|
||||
parser.add_argument("--timeout", type=int, default=DEFAULT_TIMEOUT)
|
||||
parser.add_argument("--post-record-wait", type=int, default=12)
|
||||
parser.add_argument(
|
||||
"--arm-check-seconds",
|
||||
type=int,
|
||||
default=0,
|
||||
help="attach, prove hardware breakpoints arm, then detach without claiming a capture",
|
||||
)
|
||||
parser.add_argument(
|
||||
"--wait-for-record-clear",
|
||||
action="store_true",
|
||||
help="keep tracing through abandon; accept creation only after old records disappear",
|
||||
)
|
||||
parser.add_argument(
|
||||
"--exclude-pid",
|
||||
action="append",
|
||||
type=int,
|
||||
default=[],
|
||||
help="ignore an existing FIFA process and attach only after process replacement",
|
||||
)
|
||||
parser.add_argument(
|
||||
"--payload",
|
||||
default="gdb_match_team_writer_trace.py",
|
||||
help="GDB Python payload in this tool directory; must expose start_trace(log, cards_base)",
|
||||
)
|
||||
args = parser.parse_args()
|
||||
|
||||
for path in (args.status, args.trace, args.gdb_log, args.monitor_log):
|
||||
path.parent.mkdir(parents=True, exist_ok=True)
|
||||
for path in (args.trace, args.gdb_log, args.monitor_log):
|
||||
path.unlink(missing_ok=True)
|
||||
status = Status(args.status, args.monitor_log)
|
||||
payload = Path(__file__).with_name(args.payload).resolve()
|
||||
if not payload.exists():
|
||||
status.write(state="failed", error=f"missing gdb payload: {payload}")
|
||||
return 2
|
||||
|
||||
deadline = time.time() + args.timeout
|
||||
status.write(state="waiting_for_ready_process", excluded_pids=args.exclude_pid)
|
||||
status.log(
|
||||
"waiting for FIFA17.exe with CardsDLL",
|
||||
excluded_pids=args.exclude_pid,
|
||||
)
|
||||
pid = None
|
||||
cards = None
|
||||
while time.time() < deadline:
|
||||
# UMU/Proton creates a short-lived small FIFA17.exe before the real
|
||||
# client. Never bind to the first comm match. Require CardsDLL and prefer
|
||||
# the largest-RSS process (find_pids is ordered that way).
|
||||
for candidate in find_pids():
|
||||
if candidate in args.exclude_pid:
|
||||
continue
|
||||
candidate_cards = cards_base(candidate)
|
||||
if candidate_cards:
|
||||
pid, cards = candidate, candidate_cards
|
||||
break
|
||||
if pid:
|
||||
break
|
||||
time.sleep(0.25)
|
||||
if not pid or not cards:
|
||||
status.write(state="timed_out", phase="ready_process")
|
||||
return 3
|
||||
|
||||
status.write(state="ready_process_found", pid=pid, cards_base=cards)
|
||||
status.log("real FIFA17.exe with CardsDLL found", pid=pid, cards_base=cards)
|
||||
|
||||
command_path = Path(tempfile.gettempdir()) / f"mt-trace-{pid}.gdb"
|
||||
command_path.write_text(gdb_commands(pid, cards, payload, args.trace))
|
||||
gdb_handle = args.gdb_log.open("w", encoding="utf-8")
|
||||
process = subprocess.Popen(
|
||||
["gdb", "-q", "-nx", "-x", str(command_path)],
|
||||
stdout=gdb_handle,
|
||||
stderr=subprocess.STDOUT,
|
||||
text=True,
|
||||
)
|
||||
status.write(
|
||||
state="attaching",
|
||||
pid=pid,
|
||||
cards_base=cards,
|
||||
cards_image_base=CARDS_IMAGE_BASE,
|
||||
gdb_pid=process.pid,
|
||||
gdb_command_file=str(command_path),
|
||||
payload=args.payload,
|
||||
hardware_only=True,
|
||||
client_memory_writes=False,
|
||||
)
|
||||
status.log("gdb launched", pid=pid, gdb_pid=process.pid, cards_base=cards)
|
||||
|
||||
armed = False
|
||||
arm_deadline = min(deadline, time.time() + 60)
|
||||
while time.time() < arm_deadline:
|
||||
if process.poll() is not None:
|
||||
break
|
||||
events = read_events(args.trace)
|
||||
if any(event.get("event") == "trace_armed" for event in events):
|
||||
armed = True
|
||||
break
|
||||
time.sleep(0.25)
|
||||
if not armed:
|
||||
gdb_handle.close()
|
||||
status.write(
|
||||
state="failed",
|
||||
phase="arm",
|
||||
gdb_returncode=process.poll(),
|
||||
tracer_pid=tracer_pid(pid),
|
||||
trace_events=event_counts(read_events(args.trace)),
|
||||
)
|
||||
if process.poll() is None:
|
||||
terminate_gdb(process, status, pid)
|
||||
return 4
|
||||
|
||||
attached = tracer_pid(pid) == process.pid
|
||||
status.write(
|
||||
state="armed",
|
||||
tracer_pid=tracer_pid(pid),
|
||||
target_state=target_state(pid),
|
||||
trace_events=event_counts(read_events(args.trace)),
|
||||
execution_breakpoints_armed=True,
|
||||
team1_watchpoint_armed=False,
|
||||
)
|
||||
status.log("trace armed", attached=attached, tracer_pid=tracer_pid(pid))
|
||||
if not attached:
|
||||
terminate_gdb(process, status, pid)
|
||||
gdb_handle.close()
|
||||
status.write(state="failed", phase="attach_verification")
|
||||
return 4
|
||||
if args.arm_check_seconds > 0:
|
||||
time.sleep(args.arm_check_seconds)
|
||||
events = read_events(args.trace)
|
||||
counts = event_counts(events)
|
||||
still_attached = tracer_pid(pid) == process.pid and process.poll() is None
|
||||
terminate_gdb(process, status, pid)
|
||||
gdb_handle.close()
|
||||
passed = (
|
||||
still_attached
|
||||
and counts.get("trace_armed", 0) == 1
|
||||
and counts.get("trace_error", 0) == 0
|
||||
and tracer_pid(pid) == 0
|
||||
and target_state(pid) != "T"
|
||||
)
|
||||
status.write(
|
||||
state="arm_check_passed" if passed else "arm_check_failed",
|
||||
trace_events=counts,
|
||||
attached_before_detach=still_attached,
|
||||
tracer_pid_after_detach=tracer_pid(pid),
|
||||
target_state_after_detach=target_state(pid),
|
||||
)
|
||||
status.log("arm check complete", passed=passed, trace_events=counts)
|
||||
return 0 if passed else 5
|
||||
|
||||
# A final record that already exists before arming cannot prove execution
|
||||
# crossed creation under the debugger. Fail closed instead of converting an
|
||||
# already-built match into a trusted zero-hit result.
|
||||
initial_heap = scan_process(
|
||||
pid,
|
||||
args.fixture_index,
|
||||
include_fixture=False,
|
||||
writable_anon_only=True,
|
||||
)
|
||||
records_preexisting = len(initial_heap["match_teams"]) >= 2
|
||||
records_cleared = not records_preexisting
|
||||
if records_preexisting and args.wait_for_record_clear:
|
||||
status.write(
|
||||
state="waiting_for_record_clear",
|
||||
locations=serialise_locations(initial_heap),
|
||||
target_crossed_match_team_creation=False,
|
||||
)
|
||||
status.log(
|
||||
"trace armed; waiting for old match-team records to disappear",
|
||||
team_ids=[team.team_id for team in initial_heap["match_teams"]],
|
||||
)
|
||||
while time.time() < deadline:
|
||||
if process.poll() is not None or not Path(f"/proc/{pid}").exists():
|
||||
terminate_gdb(process, status, pid)
|
||||
gdb_handle.close()
|
||||
status.write(state="failed", phase="record_clear")
|
||||
return 5
|
||||
heap = scan_process(
|
||||
pid,
|
||||
args.fixture_index,
|
||||
include_fixture=False,
|
||||
writable_anon_only=True,
|
||||
)
|
||||
if not heap["match_teams"]:
|
||||
records_cleared = True
|
||||
status.write(
|
||||
state="records_cleared",
|
||||
cleared_unix=time.time(),
|
||||
tracer_pid=tracer_pid(pid),
|
||||
gdb_alive=process.poll() is None,
|
||||
target_state=target_state(pid),
|
||||
)
|
||||
status.log(
|
||||
"old match-team records disappeared; next records are a fresh creation",
|
||||
tracer_pid=tracer_pid(pid),
|
||||
)
|
||||
break
|
||||
time.sleep(2)
|
||||
if not records_cleared:
|
||||
terminate_gdb(process, status, pid)
|
||||
gdb_handle.close()
|
||||
status.write(state="timed_out", phase="record_clear")
|
||||
return 3
|
||||
elif records_preexisting:
|
||||
counts = event_counts(read_events(args.trace))
|
||||
terminate_gdb(process, status, pid)
|
||||
gdb_handle.close()
|
||||
status.write(
|
||||
state="armed_too_late",
|
||||
phase="preexisting_records",
|
||||
trace_events=counts,
|
||||
locations=serialise_locations(initial_heap),
|
||||
target_crossed_match_team_creation=False,
|
||||
tracer_pid_after_detach=tracer_pid(pid),
|
||||
target_state_after_detach=target_state(pid),
|
||||
)
|
||||
status.log(
|
||||
"match-team records pre-existed trace; no writer claim",
|
||||
team_ids=[team.team_id for team in initial_heap["match_teams"]],
|
||||
)
|
||||
return 6
|
||||
|
||||
|
||||
fixture = None
|
||||
latest_locations = {"fixtures": [], "match_teams": [], "match_configs": []}
|
||||
last_fixture_scan = 0.0
|
||||
records_seen_at = None
|
||||
record_control = None
|
||||
try:
|
||||
while time.time() < deadline:
|
||||
if process.poll() is not None or not Path(f"/proc/{pid}").exists():
|
||||
status.write(
|
||||
state="failed",
|
||||
phase="monitor",
|
||||
gdb_returncode=process.poll(),
|
||||
target_exists=Path(f"/proc/{pid}").exists(),
|
||||
)
|
||||
return 5
|
||||
|
||||
now = time.time()
|
||||
if fixture is None and now - last_fixture_scan >= 8:
|
||||
full = scan_process(pid, args.fixture_index, include_fixture=True)
|
||||
last_fixture_scan = now
|
||||
if full["fixtures"]:
|
||||
fixture = full["fixtures"][0]
|
||||
latest_locations["fixtures"] = full["fixtures"]
|
||||
status.log(
|
||||
"fixture located",
|
||||
address=fixture.address,
|
||||
selected_address=fixture.selected_address,
|
||||
selected_index=fixture.selected_index,
|
||||
selected_team_id=fixture.selected_team_id,
|
||||
)
|
||||
|
||||
heap = scan_process(
|
||||
pid,
|
||||
args.fixture_index,
|
||||
include_fixture=False,
|
||||
writable_anon_only=True,
|
||||
)
|
||||
latest_locations["match_teams"] = heap["match_teams"]
|
||||
latest_locations["match_configs"] = heap["match_configs"]
|
||||
events = read_events(args.trace)
|
||||
counts = event_counts(events)
|
||||
is_attached = tracer_pid(pid) == process.pid
|
||||
watch_armed = counts.get("team1_watchpoint_armed", 0) > 0
|
||||
status.write(
|
||||
state="capturing" if len(heap["match_teams"]) < 2 else "records_observed",
|
||||
tracer_pid=tracer_pid(pid),
|
||||
gdb_alive=process.poll() is None,
|
||||
target_state=target_state(pid),
|
||||
trace_events=counts,
|
||||
team1_watchpoint_armed=watch_armed,
|
||||
locations=serialise_locations(latest_locations),
|
||||
)
|
||||
|
||||
if len(heap["match_teams"]) >= 2:
|
||||
if records_seen_at is None:
|
||||
if not is_attached or process.poll() is not None:
|
||||
status.write(
|
||||
state="failed",
|
||||
phase="record_creation_control",
|
||||
tracer_pid=tracer_pid(pid),
|
||||
gdb_alive=process.poll() is None,
|
||||
trace_events=counts,
|
||||
)
|
||||
return 5
|
||||
records_seen_at = now
|
||||
record_control = {
|
||||
"gdb_alive": process.poll() is None,
|
||||
"tracer_pid": tracer_pid(pid),
|
||||
"attached": is_attached,
|
||||
"execution_breakpoints_armed": counts.get("trace_armed", 0) == 1,
|
||||
"team1_watchpoint_armed": watch_armed,
|
||||
}
|
||||
status.log(
|
||||
"two match-team records located",
|
||||
team_ids=[team.team_id for team in heap["match_teams"]],
|
||||
trace_events=counts,
|
||||
**record_control,
|
||||
)
|
||||
if now - records_seen_at >= args.post_record_wait:
|
||||
break
|
||||
time.sleep(3)
|
||||
finally:
|
||||
terminate_gdb(process, status, pid)
|
||||
gdb_handle.close()
|
||||
|
||||
events = read_events(args.trace)
|
||||
counts = event_counts(events)
|
||||
final = {
|
||||
"state": "captured",
|
||||
"pid": pid,
|
||||
"cards_base": cards,
|
||||
"fixture": asdict(fixture) if fixture else None,
|
||||
"locations": serialise_locations(latest_locations),
|
||||
"trace_events": counts,
|
||||
"record_creation_control": record_control,
|
||||
"gdb_alive_at_record_creation": bool(
|
||||
record_control and record_control["gdb_alive"] and record_control["attached"]
|
||||
),
|
||||
"target_crossed_match_team_creation": len(latest_locations["match_teams"]) >= 2,
|
||||
"candidate_entry_hit": counts.get("candidate_entry", 0) > 0,
|
||||
"team1_write_hit": counts.get("team1_write_post", 0) > 0,
|
||||
"opponent_lookup_store_hit": counts.get("opponent_lookup_store_pre", 0) > 0,
|
||||
"tracer_pid_after_detach": tracer_pid(pid),
|
||||
"target_state_after_detach": target_state(pid),
|
||||
"records_preexisting": records_preexisting,
|
||||
"records_cleared_before_capture": records_cleared,
|
||||
}
|
||||
status.write(**final)
|
||||
status.log("capture complete", **final)
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
raise SystemExit(main())
|
||||
@@ -0,0 +1,76 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Read the FIFA 17 TRADING gate byte out of the live client. READ-ONLY.
|
||||
|
||||
Extends tools/gate_byte_probe.py with vtable slot +0x270 (IS_TRADING_ENABLED,
|
||||
displacement 0x1fd2e) plus the two pile-size dwords, which the transfer-market
|
||||
analysis names as the market screen's CardsDLL-supplied inputs.
|
||||
|
||||
Opens /proc/<pid>/mem O_RDONLY and preads. Nothing here can write.
|
||||
"""
|
||||
import os, struct
|
||||
|
||||
pid = None
|
||||
for d in os.listdir('/proc'):
|
||||
if d.isdigit():
|
||||
try:
|
||||
if open('/proc/%s/comm' % d).read().strip() == 'FIFA17.exe':
|
||||
pid = int(d)
|
||||
break
|
||||
except Exception:
|
||||
pass
|
||||
assert pid, "FIFA17.exe not running"
|
||||
|
||||
base = None
|
||||
for ln in open('/proc/%d/maps' % pid):
|
||||
if 'CardsDLL' in ln:
|
||||
base = int(ln.split('-')[0], 16)
|
||||
assert base, "CardsDLL not mapped (client has not reached Ultimate Team)"
|
||||
slide = base - 0x180000000
|
||||
|
||||
fd = os.open('/proc/%d/mem' % pid, os.O_RDONLY)
|
||||
|
||||
|
||||
def rd(va, n):
|
||||
return os.pread(fd, n, va)
|
||||
|
||||
|
||||
# Control: the FNV atom-hash prologue must match the on-disk PE before any other
|
||||
# address is trusted.
|
||||
pe = open('/mnt/games/FIFA 17/CardsDLL_Win64_retail.dll', 'rb').read()
|
||||
|
||||
|
||||
def f(va):
|
||||
return va - 0x180000000 - 0x1000 + 0x400
|
||||
|
||||
|
||||
ok = pe[f(0x180180d00):f(0x180180d00) + 32] == rd(0x180180d00 + slide, 32)
|
||||
print("pid=%d slide=%#x FNV control=%s" % (pid, slide, "MATCH" if ok else "MISMATCH"))
|
||||
assert ok, "slide not proven; refusing to read further"
|
||||
|
||||
obj = struct.unpack('<Q', rd(0x1802e6398 + slide, 8))[0]
|
||||
vt = struct.unpack('<Q', rd(obj, 8))[0]
|
||||
print("model=%#x vtable(static)=%#x" % (obj, vt - slide))
|
||||
|
||||
SLOTS = [
|
||||
(0x270, 'IS_TRADING_ENABLED '),
|
||||
(0x2b0, 'IS_FRIENDLY_SEASON '),
|
||||
(0x2c8, 'IS_DRAFT_MODE '),
|
||||
(0x2e0, 'packOpeningAnimation '),
|
||||
]
|
||||
print("\n-- gate bytes decoded from their accessor stubs --")
|
||||
for off, name in SLOTS:
|
||||
slot = struct.unpack('<Q', rd(vt + off, 8))[0]
|
||||
stub = rd(slot, 8)
|
||||
if stub[:3] == b'\x0f\xb6\x81':
|
||||
disp = struct.unpack('<I', stub[3:7])[0]
|
||||
val = rd(obj + disp, 1)[0]
|
||||
print(" slot +%#05x %s disp=%#x VALUE=%d" % (off, name, disp, val))
|
||||
else:
|
||||
print(" slot +%#05x %s NOT a movzx stub: %s" % (off, name, stub.hex()))
|
||||
|
||||
print("\n-- market screen inputs --")
|
||||
for disp, name in [(0x1fd1c, 'TRADE_PILE_SIZE'), (0x1fd20, 'watchListSize '),
|
||||
(0x1fd2e, 'tradingEnabled '), (0x1fd2f, 'storeEnabled ')]:
|
||||
print(" model+%#x %s = %d" % (disp, name, rd(obj + disp, 1)[0]))
|
||||
|
||||
os.close(fd)
|
||||
Executable
+102
@@ -0,0 +1,102 @@
|
||||
#!/usr/bin/env python3
|
||||
# -*- coding: utf-8 -*-
|
||||
"""Enumerate every UTAS URL template CardsDLL can build, from live memory.
|
||||
|
||||
READ-ONLY: /proc/PID/mem opened 'rb'. No write path in this file.
|
||||
|
||||
WHY
|
||||
---
|
||||
Support level L5 ("apply endpoint") for consumables was recorded as unreversed,
|
||||
with an earlier note claiming there is "no training/position/chemistry/
|
||||
manager-league endpoint at all" and that the only owned-item mutations upstream
|
||||
are quick sell and move/pile. That claim is load-bearing -- if true, applying a
|
||||
consumable is not a server route at all and L5/L6 cannot be implemented as one --
|
||||
so it deserves to be checked against the binary rather than inherited.
|
||||
|
||||
This scans CardsDLL's .rdata for route-shaped strings and prints them, so the
|
||||
full reachable surface can be read at once.
|
||||
|
||||
Positive control: known-live routes MUST appear (e.g. a 'item' path and a
|
||||
'club' path). If the control is empty the region is wrong, not the game.
|
||||
|
||||
Usage:
|
||||
python3 url_template_probe.py # route-shaped strings
|
||||
python3 url_template_probe.py --all # every printable string >= 6 chars
|
||||
python3 url_template_probe.py --grep pat # substring filter (case-insensitive)
|
||||
"""
|
||||
import argparse
|
||||
import re
|
||||
import sys
|
||||
|
||||
import watch_club_model as W
|
||||
|
||||
RDATA_LO, RDATA_HI = 0x1801E5000, 0x18028A000
|
||||
DATA_LO, DATA_HI = 0x18028A000, 0x1802F0000
|
||||
|
||||
# Route-ish: contains a slash and no spaces, or looks like a UTAS path fragment.
|
||||
ROUTE_HINTS = ("ut/", "game/", "item", "club", "squad", "purchase", "consumable",
|
||||
"apply", "training", "position", "chemistry", "contract",
|
||||
"fitness", "healing", "playstyle", "manager", "pile", "delete",
|
||||
"transfer", "market", "auction", "sbs", "pack", "store")
|
||||
|
||||
PRINTABLE = re.compile(rb"[\x20-\x7e]{6,}")
|
||||
|
||||
|
||||
def strings(mem, lo, hi):
|
||||
buf, bad = mem.read_pages(W_live(lo), hi - lo)
|
||||
if not buf:
|
||||
return [], bad
|
||||
out = []
|
||||
for m in PRINTABLE.finditer(bytes(buf)):
|
||||
out.append((lo + m.start(), m.group().decode("ascii")))
|
||||
return out, bad
|
||||
|
||||
|
||||
def main():
|
||||
ap = argparse.ArgumentParser()
|
||||
ap.add_argument("--all", action="store_true")
|
||||
ap.add_argument("--grep")
|
||||
a = ap.parse_args()
|
||||
|
||||
pid = W.find_pid()
|
||||
if pid is None:
|
||||
print("FIFA17.exe is not running.")
|
||||
return 1
|
||||
base = W.dll_base(pid)
|
||||
if base is None:
|
||||
print("pid %d is up but %s is not mapped yet." % (pid, W.DLL))
|
||||
return 1
|
||||
mem = W.Mem(pid)
|
||||
|
||||
global W_live
|
||||
W_live = lambda i: base + (i - W.IMG_BASE)
|
||||
|
||||
print("pid=%d CardsDLL live base %#x" % (pid, base))
|
||||
found = []
|
||||
for lo, hi, name in ((RDATA_LO, RDATA_HI, ".rdata"), (DATA_LO, DATA_HI, ".data")):
|
||||
ss, bad = strings(mem, lo, hi)
|
||||
print(" %s: %d strings (%d bad pages)" % (name, len(ss), len(bad)))
|
||||
found.extend(ss)
|
||||
|
||||
if a.grep:
|
||||
pat = a.grep.lower()
|
||||
sel = [(va, s) for va, s in found if pat in s.lower()]
|
||||
elif a.all:
|
||||
sel = found
|
||||
else:
|
||||
sel = [(va, s) for va, s in found
|
||||
if "/" in s and " " not in s
|
||||
and any(h in s.lower() for h in ROUTE_HINTS)]
|
||||
|
||||
print("\n%d matching string(s):" % len(sel))
|
||||
for va, s in sel:
|
||||
print(" %#x %s" % (va, s))
|
||||
|
||||
ctrl = [s for _, s in found if "ut/game" in s.lower()]
|
||||
print("\nCONTROL ('ut/game' present): %s (%d)"
|
||||
% ("OK" if ctrl else "EMPTY -> wrong region", len(ctrl)))
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
@@ -11,7 +11,7 @@ Rules (from CardsDLL 0x18016D230 / 0x1801a33a0):
|
||||
* body must parse as JSON (else err 0x3E6); 204 + empty body is accepted.
|
||||
* [resp+0x1c] == 0 is the success test; 404 is OK only on the first user GET.
|
||||
"""
|
||||
import copy, datetime, json, os, random, re, sys, http.server
|
||||
import copy, datetime, json, os, random, re, sys, threading, time, http.server
|
||||
from urllib.parse import parse_qs, urlencode, urlsplit, urlunsplit
|
||||
|
||||
sys.path.insert(0, os.path.dirname(os.path.abspath(__file__)))
|
||||
@@ -52,6 +52,173 @@ def visible_unopened_packs():
|
||||
return STORE.unopened_packs() + list(_OPENED_PACK_GRACE)
|
||||
|
||||
|
||||
# ---- FIFA17 empty-My-Packs capability negotiation (PER-SESSION, hardened) ----
|
||||
# The synthetic 65534 sentinel (store_catalog) is the universal P2 fallback. It is
|
||||
# suppressed for ONE FIFA session only when the launcher has registered that THAT
|
||||
# process positively verified the CardsDLL resolver guard (RVA 0x14858 == JG).
|
||||
#
|
||||
# BINDING: the authoritative key is the per-login-unique UTAS session id (X-UT-SID),
|
||||
# minted fresh at every /ut/auth and echoed by the client on every later call incl.
|
||||
# /store/purchasegroup (live-confirmed present on real store requests). The initial
|
||||
# prototype keyed on source IP ALONE; that was rejected because two FIFA processes
|
||||
# (concurrent or relaunched) share an IP, so an unverified process could inherit a
|
||||
# verified one's clean topology and crash. IP + persona are retained only as
|
||||
# auxiliary data: a fail-closed sid/ip sanity check and the (ip,persona) key for the
|
||||
# short-lived launcher->session hand-off.
|
||||
#
|
||||
# The launcher verifies out-of-band (autopatch) and cannot know the SID, so its
|
||||
# registration is staged as a SINGLE-USE, short-TTL PENDING keyed by (ip,persona)
|
||||
# and bound to exactly one FIFA session (directly if that session already exists,
|
||||
# else consumed at the session's login or its first store request). Fail-closed
|
||||
# everywhere: unknown / expired / absent / ambiguous / late => sentinel.
|
||||
# See docs/plans/FIFA17_PATCHED_CLIENT_CAPABILITY.md (§Session binding).
|
||||
FIFA17_EMPTY_MYPACKS_RESOLVER_VERSION = 1
|
||||
FIFA17_MODE_SENTINEL = "sentinel"
|
||||
FIFA17_MODE_CLEAN = "clean-v1"
|
||||
FIFA17_SESSION_TTL = 3600.0 # reap a FIFA session after this many idle seconds
|
||||
FIFA17_PENDING_TTL = 120.0 # a launcher capability may await its session this long
|
||||
|
||||
# sid -> {"ip","persona","resolver": Optional[int],"mode": Optional[str],"created","last_seen"}
|
||||
_FIFA17_SESSIONS = {}
|
||||
# (ip, persona) -> {"resolver": int, "ts"}: single-use launcher->session hand-off.
|
||||
_FIFA17_PENDING = {}
|
||||
_FIFA17_LOCK = threading.Lock()
|
||||
|
||||
|
||||
def _fifa17_now():
|
||||
return time.monotonic()
|
||||
|
||||
|
||||
def _fifa17_client_ip(h):
|
||||
"""Peer IP for the handler, or None when unavailable (e.g. h is None)."""
|
||||
try:
|
||||
return h.client_address[0]
|
||||
except Exception:
|
||||
return None
|
||||
|
||||
|
||||
def _fifa17_sid(h):
|
||||
"""The client's UTAS session id (X-UT-SID) for this request, or None."""
|
||||
try:
|
||||
return h.headers.get("X-UT-SID")
|
||||
except Exception:
|
||||
return None
|
||||
|
||||
|
||||
def _fifa17_sidlog(sid):
|
||||
"""A short, non-secret tag for correlating a session in logs."""
|
||||
return ("\u2026" + sid[-6:]) if sid else "-"
|
||||
|
||||
|
||||
def _fifa17_mint_sid():
|
||||
"""A fresh, per-login-unique UTAS session id (same shape/length as the legacy
|
||||
constant). Uniqueness -- not unpredictability -- is what the binding needs."""
|
||||
return "OPENFUT-SID-%016X" % random.getrandbits(64)
|
||||
|
||||
|
||||
def _fifa17_reap_locked(now):
|
||||
for sid in [s for s, r in _FIFA17_SESSIONS.items()
|
||||
if now - r["last_seen"] > FIFA17_SESSION_TTL]:
|
||||
del _FIFA17_SESSIONS[sid]
|
||||
for key in [k for k, p in _FIFA17_PENDING.items()
|
||||
if now - p["ts"] > FIFA17_PENDING_TTL]:
|
||||
del _FIFA17_PENDING[key]
|
||||
|
||||
|
||||
def _fifa17_take_pending_locked(ip, persona, now):
|
||||
"""Single-use: remove and return a fresh pending resolver for (ip,persona)."""
|
||||
p = _FIFA17_PENDING.get((ip, persona))
|
||||
if p is not None and now - p["ts"] <= FIFA17_PENDING_TTL:
|
||||
del _FIFA17_PENDING[(ip, persona)]
|
||||
return p["resolver"]
|
||||
return None
|
||||
|
||||
|
||||
def fifa17_session_known(sid):
|
||||
"""True if sid is a live session (or the legacy constant, accepted by the
|
||||
retired security-question gate ONLY -- never used to grant clean store mode)."""
|
||||
if sid == SID:
|
||||
return True
|
||||
with _FIFA17_LOCK:
|
||||
return sid in _FIFA17_SESSIONS
|
||||
|
||||
|
||||
def fifa17_open_session(sid, ip, persona):
|
||||
"""/ut/auth: open a per-login session and bind any pending launcher capability
|
||||
for (ip,persona) that arrived before login."""
|
||||
if not sid:
|
||||
return
|
||||
now = _fifa17_now()
|
||||
with _FIFA17_LOCK:
|
||||
_fifa17_reap_locked(now)
|
||||
resolver = _fifa17_take_pending_locked(ip, persona, now)
|
||||
_FIFA17_SESSIONS[sid] = {"ip": ip, "persona": persona, "resolver": resolver,
|
||||
"mode": None, "created": now, "last_seen": now}
|
||||
log("[fifa17-store] session opened %s (ip=%s persona=%s resolver=%s)"
|
||||
% (_fifa17_sidlog(sid), ip, persona, resolver))
|
||||
|
||||
|
||||
def fifa17_clear_pending(ip):
|
||||
"""/openfut/account/sync hygiene: drop any stale pending for this machine so a
|
||||
new launch's unverified session cannot inherit a leftover capability."""
|
||||
now = _fifa17_now()
|
||||
with _FIFA17_LOCK:
|
||||
_fifa17_reap_locked(now)
|
||||
for key in [k for k in _FIFA17_PENDING if k[0] == ip]:
|
||||
del _FIFA17_PENDING[key]
|
||||
|
||||
|
||||
def fifa17_register_capability(ip, persona, version):
|
||||
"""Launcher registration. Returns one of:
|
||||
"bound" exactly one live, unfrozen, unbound session for (ip,persona)
|
||||
existed (registration after login -- the common case): bound now.
|
||||
"pending" no session for (ip,persona) yet (before login): staged single-use.
|
||||
"ignored-late" a session for (ip,persona) exists but is frozen or ambiguous
|
||||
(>1 unbound): NOT staged, so no later/unverified process can
|
||||
inherit it. Fail-closed.
|
||||
Never authorizes more than one session."""
|
||||
now = _fifa17_now()
|
||||
with _FIFA17_LOCK:
|
||||
_fifa17_reap_locked(now)
|
||||
sessions = [r for r in _FIFA17_SESSIONS.values()
|
||||
if r["ip"] == ip and r["persona"] == persona]
|
||||
candidates = [r for r in sessions if r["mode"] is None and r["resolver"] is None]
|
||||
if len(candidates) == 1:
|
||||
candidates[0]["resolver"] = version
|
||||
return "bound"
|
||||
if sessions:
|
||||
return "ignored-late"
|
||||
_FIFA17_PENDING[(ip, persona)] = {"resolver": version, "ts": now}
|
||||
return "pending"
|
||||
|
||||
|
||||
def fifa17_empty_mypacks_mode(sid, ip):
|
||||
"""Freeze (once) and return the empty-My-Packs mode for FIFA session `sid`.
|
||||
Freeze point = the first /store/purchasegroup of the session. Fail-closed: an
|
||||
unknown session, or a sid presented from a different IP than it was opened on,
|
||||
resolves to the sentinel."""
|
||||
now = _fifa17_now()
|
||||
with _FIFA17_LOCK:
|
||||
_fifa17_reap_locked(now)
|
||||
rec = _FIFA17_SESSIONS.get(sid)
|
||||
if rec is None:
|
||||
return FIFA17_MODE_SENTINEL
|
||||
rec["last_seen"] = now
|
||||
if rec["ip"] is not None and ip is not None and rec["ip"] != ip:
|
||||
log("[fifa17-store] sid %s ip mismatch (session %s != request %s) -> sentinel"
|
||||
% (_fifa17_sidlog(sid), rec["ip"], ip))
|
||||
return FIFA17_MODE_SENTINEL
|
||||
if rec["mode"] is None:
|
||||
if rec["resolver"] is None:
|
||||
rec["resolver"] = _fifa17_take_pending_locked(rec["ip"], rec["persona"], now)
|
||||
rec["mode"] = (FIFA17_MODE_CLEAN
|
||||
if rec["resolver"] == FIFA17_EMPTY_MYPACKS_RESOLVER_VERSION
|
||||
else FIFA17_MODE_SENTINEL)
|
||||
log("[fifa17-store] session %s empty-mypacks mode frozen: %s"
|
||||
% (_fifa17_sidlog(sid), rec["mode"]))
|
||||
return rec["mode"]
|
||||
|
||||
|
||||
def now():
|
||||
return datetime.datetime.now().strftime("%Y-%m-%d %H:%M:%S")
|
||||
|
||||
@@ -102,7 +269,7 @@ def security_question_route(h):
|
||||
well-formed value without retaining or comparing it. Account selection has
|
||||
already initialized the server-owned verified compatibility state.
|
||||
"""
|
||||
if h.headers.get("X-UT-SID") != SID:
|
||||
if not fifa17_session_known(h.headers.get("X-UT-SID")):
|
||||
log("[FUT] security-question request has no matching OpenFUT session")
|
||||
return 400, {"reason": "invalid_session"}
|
||||
|
||||
@@ -193,11 +360,19 @@ def auth_body(h=None):
|
||||
except Exception as e: # adoption must never break auth
|
||||
log(" AUTH: adopt failed (%s: %s) -- keeping %s/%r"
|
||||
% (type(e).__name__, e, before[0], before[1]))
|
||||
return {"protocol": 1, "sid": SID, "serverTime": now(), "lastOnlineTime": now()}
|
||||
sid = _fifa17_mint_sid()
|
||||
fifa17_open_session(sid, _fifa17_client_ip(h), ACCOUNT.persona_id)
|
||||
return {"protocol": 1, "sid": sid, "serverTime": now(), "lastOnlineTime": now()}
|
||||
|
||||
|
||||
def account_sync_route(h):
|
||||
"""Launcher-only active-profile selection, before LSX/Blaze login starts."""
|
||||
# Pre-launch hygiene: drop any stale launcher capability still pending for this
|
||||
# machine so a new launch's unverified FIFA session cannot inherit it. The real
|
||||
# per-process session is opened later, at /ut/auth (keyed by the minted X-UT-SID).
|
||||
ip = _fifa17_client_ip(h)
|
||||
fifa17_clear_pending(ip)
|
||||
log(" ACCOUNT: cleared stale FIFA17 pending capability for ip %s" % ip)
|
||||
try:
|
||||
body = json.loads(h._body.decode("utf-8")) if getattr(h, "_body", b"") else {}
|
||||
account = activate_account(body)
|
||||
@@ -209,6 +384,33 @@ def account_sync_route(h):
|
||||
return 200, {"account": account, "status": "OK"}
|
||||
|
||||
|
||||
def fifa17_capability_route(h):
|
||||
"""POST /openfut/fifa17/capability -- launcher registers a verified resolver
|
||||
capability for the current FIFA process (bound to the peer IP). Fail-closed:
|
||||
anything but capability==empty_mypacks_resolver && version==current is a 400
|
||||
that records NOTHING (the session stays on the sentinel fallback)."""
|
||||
try:
|
||||
body = json.loads(h._body.decode("utf-8")) if getattr(h, "_body", b"") else {}
|
||||
except Exception:
|
||||
return 400, {"error": "unsupported capability"}
|
||||
if not isinstance(body, dict):
|
||||
return 400, {"error": "unsupported capability"}
|
||||
try:
|
||||
version = int(body.get("version"))
|
||||
except (TypeError, ValueError):
|
||||
return 400, {"error": "unsupported capability"}
|
||||
if (body.get("capability") != "empty_mypacks_resolver"
|
||||
or version != FIFA17_EMPTY_MYPACKS_RESOLVER_VERSION):
|
||||
return 400, {"error": "unsupported capability"}
|
||||
ip = _fifa17_client_ip(h)
|
||||
persona = body.get("personaId")
|
||||
fifa_pid = body.get("fifaPid", "?")
|
||||
status = fifa17_register_capability(ip, persona, version)
|
||||
log("[fifa17-store] capability empty_mypacks_resolver=%s ip=%s persona=%s "
|
||||
"fifa_pid=%s -> %s" % (version, ip, persona, fifa_pid, status))
|
||||
return 200, {"status": "OK"}
|
||||
|
||||
|
||||
def current_squad():
|
||||
"""The squad the client should see: the persisted one (item refs re-embedded
|
||||
from the club) or the seed ladder squad on first run.
|
||||
@@ -1203,6 +1405,10 @@ ROUTES = [
|
||||
# Launcher control-plane endpoint. It is intentionally outside /ut so FIFA
|
||||
# never calls it; launch is blocked unless this succeeds first.
|
||||
(re.compile(r"^/openfut/account/sync$"), lambda m, h: account_sync_route(h)),
|
||||
# Launcher registers a verified per-FIFA-process resolver capability (bound to
|
||||
# peer IP). Adjacent to account/sync, above the generic /ut routes; FIFA never
|
||||
# calls it. Fail-closed: absent/late/wrong-version => sentinel (store_catalog).
|
||||
(re.compile(r"^/openfut/fifa17/capability$"), lambda m, h: fifa17_capability_route(h)),
|
||||
# ---- FUT item-definition endpoints (must precede generic /item, /user) ----
|
||||
(re.compile(G + r"/item/resource"), lambda m, h: defs_route(h)),
|
||||
(re.compile(G + r"/defid"), lambda m, h: defs_route(h)),
|
||||
@@ -3426,24 +3632,54 @@ def store_catalog(h):
|
||||
if owned:
|
||||
packs.append(_pack_body(owned, idx, owned=True))
|
||||
if not owned_ids:
|
||||
# GOTO_STORE_MYPACK resolves the hard-coded `mypacks` group before it
|
||||
# renders rows. If the group is absent FIFA falls back to Bronze and
|
||||
# shows the empty-category dialog over the wrong tab. Retain an inactive
|
||||
# zero-item sentinel so the destination resolves, while state != active
|
||||
# keeps it out of the visible row list. Its id is deliberately absent
|
||||
# from PACK_CATALOG, so both purchase/open handlers reject it as well.
|
||||
sentinel = {
|
||||
"id": 65534,
|
||||
"name": "",
|
||||
"price": 0,
|
||||
"count": 0,
|
||||
"gold": True,
|
||||
"specialChance": 0.0,
|
||||
}
|
||||
empty = _pack_body(sentinel, 1, owned=True)
|
||||
empty["state"] = "inactive"
|
||||
empty["unopened"] = False
|
||||
packs.append(empty)
|
||||
# ADDITIVE capability switch (see docs/plans/FIFA17_PATCHED_CLIENT_CAPABILITY.md
|
||||
# §7/§9). This is the session-freeze point: the empty-mypacks decision for
|
||||
# this FIFA session (keyed by its X-UT-SID) is committed here at the first
|
||||
# /store/purchasegroup and is immutable for the session thereafter.
|
||||
mode = fifa17_empty_mypacks_mode(_fifa17_sid(h), _fifa17_client_ip(h))
|
||||
if mode == FIFA17_MODE_CLEAN:
|
||||
# Verified patched client: emit NO mypacks group; the CardsDLL resolver
|
||||
# guard (RVA 0x14858 JG) routes the -1 ordinal to Browse instead of
|
||||
# dereferencing a null group. (append nothing)
|
||||
pass
|
||||
else:
|
||||
# EMPTY MY PACKS -- FIFA 17 client-compatibility workaround (bug 6c, P2).
|
||||
#
|
||||
# The Store/Scaleform path RESOLVES the `mypacks` category even when the
|
||||
# account owns zero unopened packs (the category is chosen client-side from
|
||||
# the movie's CATEGORY_ID -> screen+0x290; no server field gates it).
|
||||
# CardsDLL FUN_1800147f0 then dereferences the resolved group with NO null
|
||||
# guard, so if no `mypacks` group exists the client CRASHES
|
||||
# (CardsDLL_Win64_retail.dll+0x14882, read of [NULL+0x48] -- confirmed by
|
||||
# minidump). We therefore MUST emit a `mypacks` group when empty.
|
||||
#
|
||||
# state="inactive" avoids the crash but makes the client report the pack
|
||||
# unavailable immediately on Store entry and bounce to the Hub. state="active"
|
||||
# keeps the group structurally valid AND lets the Store open normally; the
|
||||
# empty tile renders as "0 items" and an explicit open is rejected
|
||||
# CLIENT-SIDE ("This pack is no longer available") -- it sends NO backend
|
||||
# request and mutates nothing.
|
||||
#
|
||||
# id 65534 is deliberately ABSENT from PACK_CATALOG, so pack_by_id() returns
|
||||
# None and store_buy()/purchased_items() cannot open it, grant items/coins,
|
||||
# or add it to unopenedPackIds. This is a compatibility shim for FIFA 17
|
||||
# client behavior, NOT an EA-authentic empty-My-Packs representation, and it
|
||||
# is FIFA17-specific (do not lift into game-independent Core). A fully clean
|
||||
# zero-pack UX requires a client-side fix -- see
|
||||
# docs/plans/FIFA17_EMPTY_MYPACKS_CLIENT_FIX.md and the evidence in
|
||||
# docs/evidence/STORE_TILE_6C.md / FIFA17_EMPTY_MYPACKS_CLIENT_CONTRACT.md.
|
||||
sentinel = {
|
||||
"id": 65534,
|
||||
"name": "",
|
||||
"price": 0,
|
||||
"count": 0,
|
||||
"gold": True,
|
||||
"specialChance": 0.0,
|
||||
}
|
||||
empty = _pack_body(sentinel, 1, owned=True)
|
||||
empty["state"] = "active"
|
||||
empty["unopened"] = False
|
||||
packs.append(empty)
|
||||
return 200, {"purchase": packs, "timestamp": 1596326400}
|
||||
|
||||
|
||||
|
||||
@@ -0,0 +1,78 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Dump CardsDLL's NULL-terminated {const char*, int} vocabulary tables from the
|
||||
ON-DISK PE. READ-ONLY, static.
|
||||
|
||||
The transfer-market analysis records tradeState as decoding through a table walk at
|
||||
0x180229e40 and lists sibling vocabularies (type/zone/lev/pos) as tables of the same
|
||||
shape. This prints the exact token spellings and their integer codes, so the accepted
|
||||
strings come from the client rather than from inference.
|
||||
"""
|
||||
import struct
|
||||
|
||||
DLL = "/mnt/games/FIFA 17/CardsDLL_Win64_retail.dll"
|
||||
TABLES = [
|
||||
(0x180229E40, "tradeState (table walk)"),
|
||||
(0x180229C30, "type"),
|
||||
(0x1802296E0, "zone"),
|
||||
(0x180229A60, "lev"),
|
||||
(0x1802295C0, "pos"),
|
||||
(0x180229AB0, "cat"),
|
||||
(0x180229880, "form"),
|
||||
]
|
||||
MAX_ROWS = 64
|
||||
|
||||
pe = open(DLL, "rb").read()
|
||||
e_lfanew = struct.unpack_from("<I", pe, 0x3C)[0]
|
||||
coff = e_lfanew + 4
|
||||
num_sections = struct.unpack_from("<H", pe, coff + 2)[0]
|
||||
opt_size = struct.unpack_from("<H", pe, coff + 16)[0]
|
||||
opt = coff + 20
|
||||
image_base = struct.unpack_from("<Q", pe, opt + 24)[0]
|
||||
sec_off = opt + opt_size
|
||||
sections = []
|
||||
for i in range(num_sections):
|
||||
b = sec_off + i * 40
|
||||
vsize, vaddr, rawsize, rawptr = struct.unpack_from("<IIII", pe, b + 8)
|
||||
sections.append((vaddr, vsize, rawptr, rawsize))
|
||||
|
||||
|
||||
def va2off(va):
|
||||
rva = va - image_base
|
||||
for vaddr, vsize, rawptr, rawsize in sections:
|
||||
if vaddr <= rva < vaddr + max(vsize, rawsize):
|
||||
off = rva - vaddr + rawptr
|
||||
if 0 <= off < len(pe):
|
||||
return off
|
||||
return None
|
||||
|
||||
|
||||
def cstr(va, limit=64):
|
||||
off = va2off(va)
|
||||
if off is None:
|
||||
return None
|
||||
end = pe.find(b"\0", off, off + limit)
|
||||
if end < 0:
|
||||
return None
|
||||
try:
|
||||
s = pe[off:end].decode("ascii")
|
||||
except UnicodeDecodeError:
|
||||
return None
|
||||
return s if s.isprintable() else None
|
||||
|
||||
|
||||
for table_va, name in TABLES:
|
||||
base = va2off(table_va)
|
||||
print("\n=== %s VA %#x -> off %s ===" % (name, table_va, hex(base) if base else None))
|
||||
if base is None:
|
||||
print(" (VA did not resolve)")
|
||||
continue
|
||||
for i in range(MAX_ROWS):
|
||||
ptr, code = struct.unpack_from("<Qi", pe, base + i * 16)
|
||||
if ptr == 0:
|
||||
print(" -- NULL terminator after %d rows --" % i)
|
||||
break
|
||||
s = cstr(ptr)
|
||||
if s is None:
|
||||
print(" row %d: ptr %#x does not resolve to a string; stopping" % (i, ptr))
|
||||
break
|
||||
print(" %-28s = %d" % (repr(s), code))
|
||||
Executable
+84
@@ -0,0 +1,84 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Dump a CardsDLL vtable as image VAs, and find sibling vtables that hold a
|
||||
different function in the same slot (a type/mode dispatch).
|
||||
|
||||
vtab.py <slot_image_va_hex> [before] [after]
|
||||
"""
|
||||
import glob
|
||||
import os
|
||||
import re
|
||||
import struct
|
||||
import sys
|
||||
|
||||
CARDS_IMG = 0x180000000
|
||||
|
||||
|
||||
def pid():
|
||||
for d in glob.glob("/proc/[0-9]*"):
|
||||
try:
|
||||
if open(os.path.join(d, "comm")).read().strip() == "FIFA17.exe":
|
||||
return int(os.path.basename(d))
|
||||
except OSError:
|
||||
pass
|
||||
raise SystemExit("no FIFA17.exe")
|
||||
|
||||
|
||||
P = pid()
|
||||
BASE = [int(l.split("-")[0], 16) for l in open(f"/proc/{P}/maps") if "CardsDLL" in l][0]
|
||||
|
||||
|
||||
def img2live(va):
|
||||
return BASE + (va - CARDS_IMG)
|
||||
|
||||
|
||||
def live2img(la):
|
||||
return CARDS_IMG + (la - BASE)
|
||||
|
||||
|
||||
slot = int(sys.argv[1], 16)
|
||||
before = int(sys.argv[2]) if len(sys.argv) > 2 else 10
|
||||
after = int(sys.argv[3]) if len(sys.argv) > 3 else 10
|
||||
|
||||
mem = open(f"/proc/{P}/mem", "rb", 0)
|
||||
start = slot - before * 8
|
||||
mem.seek(img2live(start))
|
||||
buf = mem.read((before + after) * 8)
|
||||
print(f" vtable neighbourhood of image 0x{slot:x}")
|
||||
target = None
|
||||
for k in range(0, len(buf) - 7, 8):
|
||||
a = start + k
|
||||
p = struct.unpack_from("<Q", buf, k)[0]
|
||||
ivа = live2img(p) if BASE <= p < BASE + 0x400000 else None
|
||||
mark = " <== the team-pair assigner" if a == slot else ""
|
||||
if a == slot:
|
||||
target = ivа
|
||||
print(f" 0x{a:x} [{a-slot:+#5x}] -> "
|
||||
+ (f"image 0x{ivа:x}" if ivа else f"raw 0x{p:x}") + mark)
|
||||
|
||||
# Find every other .rdata slot pointing at a DIFFERENT function but whose
|
||||
# neighbours overlap this vtable -> sibling implementations of the same slot.
|
||||
print("\n === sibling vtables: same neighbour, different slot function ===")
|
||||
mem.seek(img2live(0x1801e5000))
|
||||
rdata = mem.read(0x28a000 - 0x1e5000)
|
||||
# take the two neighbours around the slot as a signature
|
||||
sig_prev = struct.unpack_from("<Q", buf, (before - 1) * 8)[0]
|
||||
sig_next = struct.unpack_from("<Q", buf, (before + 1) * 8)[0]
|
||||
found = 0
|
||||
for name, sig in (("preceding", sig_prev), ("following", sig_next)):
|
||||
pat = struct.pack("<Q", sig)
|
||||
i = rdata.find(pat)
|
||||
while i >= 0:
|
||||
if i % 8 == 0:
|
||||
here = 0x1801e5000 + i
|
||||
# the slot in THIS vtable at the same relative position
|
||||
off = i + (8 if name == "preceding" else -8)
|
||||
if 0 <= off <= len(rdata) - 8:
|
||||
fn = struct.unpack_from("<Q", rdata, off)[0]
|
||||
if BASE <= fn < BASE + 0x400000:
|
||||
fimg = live2img(fn)
|
||||
if fimg != target:
|
||||
print(f" vtable @image 0x{here:x} ({name} matches) "
|
||||
f"slot -> image 0x{fimg:x} DIFFERENT")
|
||||
found += 1
|
||||
i = rdata.find(pat, i + 1)
|
||||
print(f" {found} sibling implementation(s)")
|
||||
Executable
+111
@@ -0,0 +1,111 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Find references to an image VA inside a live module's .text/.rdata/.data.
|
||||
|
||||
xref.py <target_image_va_hex> [--exe]
|
||||
|
||||
Reports:
|
||||
call rel32 (e8) / jmp rel32 (e9) -- direct callers
|
||||
lea rip-rel (48 8d 0x) -- address-taken
|
||||
absolute 8-byte pointer -- vtable / table slot
|
||||
|
||||
Read-only. Section ranges are recomputed from /proc/<pid>/maps every run.
|
||||
"""
|
||||
import glob
|
||||
import os
|
||||
import re
|
||||
import struct
|
||||
import sys
|
||||
|
||||
CARDS_IMG = 0x180000000
|
||||
EXE_IMG = 0x140000000
|
||||
|
||||
|
||||
def pid():
|
||||
for d in glob.glob("/proc/[0-9]*"):
|
||||
try:
|
||||
if open(os.path.join(d, "comm")).read().strip() == "FIFA17.exe":
|
||||
return int(os.path.basename(d))
|
||||
except OSError:
|
||||
pass
|
||||
raise SystemExit("FIFA17.exe not running")
|
||||
|
||||
|
||||
P = pid()
|
||||
|
||||
|
||||
def module_base(needle):
|
||||
for l in open(f"/proc/{P}/maps"):
|
||||
if needle.lower() in l.lower():
|
||||
return int(l.split("-")[0], 16)
|
||||
raise SystemExit(f"{needle} not mapped")
|
||||
|
||||
|
||||
def spans(base, limit=0x400000):
|
||||
"""Contiguous mappings belonging to this module, as (live_lo, live_hi, perms)."""
|
||||
out = []
|
||||
for l in open(f"/proc/{P}/maps"):
|
||||
m = re.match(r"([0-9a-f]+)-([0-9a-f]+)\s+(\S{4})\s+\S+\s+\S+\s+\S+\s*(.*)", l)
|
||||
if not m:
|
||||
continue
|
||||
lo, hi, perms, path = int(m.group(1), 16), int(m.group(2), 16), m.group(3), m.group(4)
|
||||
if lo == base:
|
||||
out.append((lo, hi, perms))
|
||||
continue
|
||||
if out and lo == out[-1][1] and not path.strip():
|
||||
out.append((lo, hi, perms))
|
||||
elif out and lo > out[-1][1]:
|
||||
break
|
||||
return out
|
||||
|
||||
|
||||
def main():
|
||||
a = [x for x in sys.argv[1:] if x != "--exe"]
|
||||
exe = "--exe" in sys.argv
|
||||
target = int(a[0], 16)
|
||||
img = EXE_IMG if exe else CARDS_IMG
|
||||
base = module_base("FIFA17.exe" if exe else "CardsDLL")
|
||||
tgt_live = base + (target - img)
|
||||
|
||||
mem = open(f"/proc/{P}/mem", "rb", 0)
|
||||
print(f" pid={P} module_base=0x{base:x} target image 0x{target:x} live 0x{tgt_live:x}")
|
||||
hits = 0
|
||||
for lo, hi, perms in spans(base):
|
||||
try:
|
||||
mem.seek(lo)
|
||||
buf = mem.read(hi - lo)
|
||||
except (OSError, ValueError):
|
||||
continue
|
||||
img_lo = img + (lo - base)
|
||||
# rel32 call/jmp
|
||||
for op, name in ((0xE8, "call"), (0xE9, "jmp ")):
|
||||
i = buf.find(bytes([op]))
|
||||
while i >= 0:
|
||||
if i + 5 <= len(buf):
|
||||
rel = struct.unpack_from("<i", buf, i + 1)[0]
|
||||
if img_lo + i + 5 + rel == target:
|
||||
print(f" {name} rel32 from image 0x{img_lo+i:x} [{perms}]")
|
||||
hits += 1
|
||||
i = buf.find(bytes([op]), i + 1)
|
||||
# lea reg,[rip+rel32] (48 8d /r with mod=00 rm=101)
|
||||
i = buf.find(b"\x48\x8d")
|
||||
while i >= 0:
|
||||
if i + 7 <= len(buf):
|
||||
modrm = buf[i + 2]
|
||||
if (modrm & 0xC7) == 0x05:
|
||||
rel = struct.unpack_from("<i", buf, i + 3)[0]
|
||||
if img_lo + i + 7 + rel == target:
|
||||
print(f" lea rip-rel from image 0x{img_lo+i:x} [{perms}]")
|
||||
hits += 1
|
||||
i = buf.find(b"\x48\x8d", i + 1)
|
||||
# absolute pointer (live address stored in a table)
|
||||
pat = struct.pack("<Q", tgt_live)
|
||||
i = buf.find(pat)
|
||||
while i >= 0:
|
||||
if i % 8 == 0:
|
||||
print(f" abs ptr slot at image 0x{img_lo+i:x} [{perms}]")
|
||||
hits += 1
|
||||
i = buf.find(pat, i + 1)
|
||||
print(f" {hits} reference(s)")
|
||||
|
||||
|
||||
main()
|
||||
@@ -0,0 +1,24 @@
|
||||
[package]
|
||||
name = "openfut-adapter-fifa17"
|
||||
version = "0.1.0"
|
||||
edition = "2021"
|
||||
license = "MIT"
|
||||
description = "FIFA 17 game adapter: Blaze command tables, response bodies and dispatch"
|
||||
publish = false
|
||||
|
||||
[dependencies]
|
||||
openfut-protocol-blaze = { path = "../openfut-protocol-blaze" }
|
||||
# Reads the bundled fetchClientConfig table (227-243 rows per CFID), which is
|
||||
# generated from the Python oracle rather than transcribed by hand. Unlike the
|
||||
# protocol crate below it, this crate is ordinary server-side code, so a real
|
||||
# JSON parser is the right call — hand-rolling one to preserve a zero-dependency
|
||||
# streak would be reinventing a solved problem in the riskiest possible place.
|
||||
serde = { version = "1", features = ["derive"] }
|
||||
serde_json = "1"
|
||||
# Seeded RNG for the Store pack-content generator (`fut::pack_content`). The
|
||||
# generator is pure over an injected `rand::Rng`, so packs are deterministic
|
||||
# under a seeded `StdRng` in tests and reproducible in production.
|
||||
rand = "0.8"
|
||||
|
||||
[dev-dependencies]
|
||||
# Differential fixtures are JSONL; the runtime dependency already covers it.
|
||||
@@ -0,0 +1,115 @@
|
||||
# openfut-adapter-fifa17
|
||||
|
||||
The FIFA 17 game adapter. Everything true of *FIFA 17 specifically* lives here,
|
||||
so that neither OpenFUT Core nor the generic protocol crates have to know about
|
||||
it.
|
||||
|
||||
```
|
||||
openfut-protocol-blaze generic Blaze: Fire2 framing, Heat2/TDF codec
|
||||
▲
|
||||
openfut-adapter-fifa17 THIS: command tables, response bodies, dispatch order
|
||||
▲
|
||||
OpenFUT Core game-independent FUT domain (not yet wired)
|
||||
```
|
||||
|
||||
## Status
|
||||
|
||||
| Surface | Port | State |
|
||||
|---|---|---|
|
||||
| **Blaze / Fire2 RPC** | 42130 | **Implemented**, byte-for-byte parity-tested |
|
||||
| Redirector (HTTPS + XML) | 42127 | Python only |
|
||||
| Nucleus OAuth stub | 42131 | Python only |
|
||||
| LSX / Origin | 4216 | Python only |
|
||||
| Roster XML | 8081 | Python only |
|
||||
| UTAS / RS4 | 8099 | Python only |
|
||||
| POW / EASFC | 8094 / 8080 | Python only |
|
||||
|
||||
**Nothing here is wired into the running backend.** The crate answers frames; it
|
||||
opens no socket, terminates no TLS and owns no runtime. The Python backend
|
||||
remains the live service and the behavioural oracle.
|
||||
|
||||
## What the adapter owns, and what it must not
|
||||
|
||||
Owns: component/command/notification IDs, response body shapes, dispatch
|
||||
ordering, session identity, the `fetchClientConfig` tables.
|
||||
|
||||
Must not own: FUT domain state. Blaze is an auth/session/config protocol — no
|
||||
coins, packs, clubs or squads appear on this wire — so `Session` holds a session
|
||||
key, a locale, a service name, an auth code and a flag, and that is all. When
|
||||
UTAS is migrated that boundary will need active defending; here it comes free.
|
||||
|
||||
## Parity
|
||||
|
||||
```bash
|
||||
./check-parity.sh # oracle freshness + byte-for-byte replay
|
||||
./check-parity.sh --regen # after an intentional oracle change
|
||||
```
|
||||
|
||||
`fixtures/blaze_transactions.jsonl` holds 49 request→response(s) transactions
|
||||
produced by calling the real `blaze_responder_v3b.dispatch()`. They replay in
|
||||
order against a shared session per connection, so ordering-dependent behaviour
|
||||
is exercised rather than assumed: preAuth captures the locale that later `ALOC`
|
||||
fields echo, and login sets the auth code `getAuthToken` returns afterwards.
|
||||
|
||||
Comparison is byte-for-byte including frame count and order — a missing
|
||||
post-login notification or a reply where the oracle stays silent fails here.
|
||||
|
||||
The suite was **mutation-tested**: swapping two post-login notifications,
|
||||
flipping one enum deep inside `AccountInfo`, and hardcoding an address in
|
||||
`utas_base()`/`nucleus_base()` were each verified to turn it red. The third
|
||||
initially did *not*, because the config templating had made those helpers dead
|
||||
code; the table now templates on URL-level tokens so they are the single place a
|
||||
URL shape is defined.
|
||||
|
||||
## Three behaviours that are easy to get wrong
|
||||
|
||||
* **Login answers with four frames, in order**: reply, then `UserAuthenticated`,
|
||||
`UserSessionExtendedDataUpdate`, `UserAdded`.
|
||||
* **An unimplemented RPC still gets an empty reply.** Silence makes the client
|
||||
wait for a timeout; an empty reply lets every field fall back to a client-side
|
||||
default and the boot continues.
|
||||
* **Non-request message types get nothing at all.**
|
||||
|
||||
No error replies are emitted. `msgType` 3 exists, but the error-code placement
|
||||
is UNRESOLVED — three clean-room sources disagree between `header[14:16]`, a
|
||||
metadata `ERRC`, and a payload `CNTX`/`ERRC` — so emitting one would be a guess
|
||||
on the wire.
|
||||
|
||||
## The client config table
|
||||
|
||||
`fixtures/client_config.json` carries 227–243 rows per CFID, generated from the
|
||||
Python oracle and templated on `{utas_base}`, `{nucleus_base}`,
|
||||
`{pow_content_url}`, `{advertise}`, `{bind}`, `{pow_host}`. It is
|
||||
reverse-engineered *data*, not logic, and deriving it mechanically removes a
|
||||
class of transcription typo no reviewer could catch. The generator does not take
|
||||
its own templating on trust: it substitutes real addresses back in and diffs
|
||||
against the oracle for every section before writing the file.
|
||||
|
||||
The table must be *complete*, not representative. The client resolves a per-call
|
||||
key (`FUT_RS4_URL_<CALL>`) before a per-module one, and any unresolved call falls
|
||||
back to a real, dead EA host — that is what produced "there has been an error
|
||||
connecting to FIFA 17 Ultimate Team" mid-session when only the boot subset was
|
||||
served.
|
||||
|
||||
## Known defect reproduced deliberately
|
||||
|
||||
`nucleusConnect` and `nucleusConnectTrusted` are built from the **bind** address,
|
||||
not the advertised one. On the live split deployment that means the backend
|
||||
tells a client on another machine to reach Nucleus at `http://0.0.0.0:42131`,
|
||||
which it cannot. Verified against the running container, not inferred.
|
||||
|
||||
This is reproduced exactly, because it is what the only proven-working
|
||||
configuration does and changing it would break parity. It also implies the
|
||||
Nucleus stub is not actually reached in the current remote flow. Fixing it is a
|
||||
separate change that needs live validation — see the vault.
|
||||
|
||||
## Configuration
|
||||
|
||||
Nothing is hardcoded. `AdapterConfig` carries `Identity` (persona, ids, email,
|
||||
namespace, entitlement group, …) and `Endpoints` (advertise, bind, POW hosts,
|
||||
telemetry/ticker/QoS ports). `Default` gives the project's synthetic offline
|
||||
identity on loopback; a remote deployment must override `advertise`.
|
||||
|
||||
Bind and advertise are deliberately distinct: an advertised URL must carry the
|
||||
address the *client* can reach, which on a two-machine deployment is not the
|
||||
address the server binds.
|
||||
Executable
+28
@@ -0,0 +1,28 @@
|
||||
#!/usr/bin/env bash
|
||||
# Differential check: the Rust FIFA 17 Blaze adapter vs the Python responder.
|
||||
#
|
||||
# 1. assert the committed fixtures still match what the Python oracle emits
|
||||
# 2. replay every recorded transaction through the Rust adapter, byte-for-byte
|
||||
#
|
||||
# Read-only with respect to the running backend: the oracle is imported as a
|
||||
# library, no responder is started, no port is bound, no live service is
|
||||
# touched. Safe to run while the Python backend is serving a live FIFA client.
|
||||
#
|
||||
# Use --regen to rewrite the fixtures after an intentional oracle change.
|
||||
set -euo pipefail
|
||||
|
||||
cd "$(dirname "$(readlink -f "$0")")"
|
||||
|
||||
if [[ "${1:-}" == "--regen" ]]; then
|
||||
echo "==> regenerating fixtures from the Python oracle"
|
||||
python3 fixtures/generate.py
|
||||
else
|
||||
echo "==> checking committed fixtures against the Python oracle"
|
||||
python3 fixtures/generate.py --check
|
||||
fi
|
||||
|
||||
echo "==> replaying transactions through the Rust adapter"
|
||||
cargo test -p openfut-adapter-fifa17
|
||||
|
||||
echo
|
||||
echo "PARITY OK — the adapter reproduces the Python dispatcher byte-for-byte."
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,167 @@
|
||||
//! Emit the discard-pricing matrix for an entire FIFA 17 corpus, and audit it.
|
||||
//!
|
||||
//! Uses the SHIPPED implementation (`fut::discard::value_for_definition`) rather
|
||||
//! than reimplementing the formula, so the matrix cannot drift from what the
|
||||
//! server actually pays.
|
||||
//!
|
||||
//! ```text
|
||||
//! cargo run -p openfut-adapter-fifa17 --example discard_matrix -- \
|
||||
//! <catalog.json> <cards.json> [--csv out.csv]
|
||||
//! ```
|
||||
//!
|
||||
//! Prints an audit summary and, with `--csv`, the full per-definition matrix.
|
||||
|
||||
use std::collections::{BTreeMap, HashMap};
|
||||
|
||||
use openfut_adapter_fifa17::fut::discard;
|
||||
use openfut_adapter_fifa17::fut::item::legacy_discard_value;
|
||||
|
||||
fn main() {
|
||||
let args: Vec<String> = std::env::args().collect();
|
||||
if args.len() < 3 {
|
||||
eprintln!("usage: discard_matrix <catalog.json> <cards.json> [--csv <path>]");
|
||||
std::process::exit(2);
|
||||
}
|
||||
let catalog: serde_json::Value =
|
||||
serde_json::from_str(&std::fs::read_to_string(&args[1]).expect("read catalog"))
|
||||
.expect("parse catalog");
|
||||
let cards: serde_json::Value =
|
||||
serde_json::from_str(&std::fs::read_to_string(&args[2]).expect("read cards"))
|
||||
.expect("parse cards");
|
||||
let csv_path = args
|
||||
.iter()
|
||||
.position(|a| a == "--csv")
|
||||
.map(|i| args[i + 1].clone());
|
||||
|
||||
// Core's rating per definition id (non-players are 0, which is exactly why
|
||||
// the catalog rating matters).
|
||||
let mut core_rating: HashMap<String, u8> = HashMap::new();
|
||||
if let Some(arr) = cards.as_array() {
|
||||
for c in arr {
|
||||
let id = c["id"].as_str().unwrap_or_default().to_string();
|
||||
let r = c["overall"].as_i64().unwrap_or(0).clamp(0, 255) as u8;
|
||||
core_rating.insert(id, r);
|
||||
}
|
||||
}
|
||||
|
||||
let entries = catalog
|
||||
.get("cards")
|
||||
.and_then(|c| c.as_object())
|
||||
.expect("catalog has cards{}");
|
||||
|
||||
let mut rows: Vec<String> = Vec::new();
|
||||
rows.push("definition,kind,subtype,cardtype,rareflag,rating_src,rating,level,legacy,recovered,verdict".into());
|
||||
|
||||
let mut by_kind: BTreeMap<String, (usize, usize, i64, i64)> = BTreeMap::new(); // n, declined, legacy, recovered
|
||||
let (mut negatives, mut zero_priced, mut declined_total, mut overflow) =
|
||||
(0usize, 0usize, 0usize, 0usize);
|
||||
let mut boundary_probe_failures = Vec::new();
|
||||
|
||||
for (id, e) in entries {
|
||||
let kind = e["kind"].as_str().unwrap_or("player").to_string();
|
||||
let subtype = e["subtype"].as_i64().unwrap_or(0);
|
||||
let rareflag = e["rareflag"].as_i64().unwrap_or(0);
|
||||
let cat_rating = e["rating"].as_i64().map(|r| r.clamp(0, 255) as u8);
|
||||
let core = *core_rating.get(id).unwrap_or(&0);
|
||||
let cardtype = discard::cardtype_for_subtype(subtype);
|
||||
|
||||
let recovered = discard::value_for_definition(subtype, rareflag, cat_rating, core);
|
||||
let effective_rating = cat_rating.unwrap_or(core);
|
||||
let level = discard::discard_level(effective_rating);
|
||||
let legacy = legacy_discard_value(core);
|
||||
|
||||
let verdict = match recovered {
|
||||
None => {
|
||||
declined_total += 1;
|
||||
"DECLINES->legacy"
|
||||
}
|
||||
Some(v) if v < 0 => {
|
||||
negatives += 1;
|
||||
"NEGATIVE"
|
||||
}
|
||||
Some(0) => {
|
||||
zero_priced += 1;
|
||||
"ZERO"
|
||||
}
|
||||
Some(v) if v > 1_000_000 => {
|
||||
overflow += 1;
|
||||
"IMPLAUSIBLE"
|
||||
}
|
||||
Some(_) => "ok",
|
||||
};
|
||||
|
||||
let ent = by_kind.entry(kind.clone()).or_insert((0, 0, 0, 0));
|
||||
ent.0 += 1;
|
||||
ent.2 += legacy;
|
||||
match recovered {
|
||||
Some(v) => ent.3 += v,
|
||||
None => {
|
||||
ent.1 += 1;
|
||||
ent.3 += legacy; // declining means the legacy ladder is what pays
|
||||
}
|
||||
}
|
||||
|
||||
rows.push(format!(
|
||||
"{id},{kind},{subtype},{cardtype},{rareflag},{},{effective_rating},{level},{legacy},{},{verdict}",
|
||||
if cat_rating.is_some() { "catalog" } else { "core" },
|
||||
recovered.map(|v| v.to_string()).unwrap_or_else(|| "-".into()),
|
||||
));
|
||||
}
|
||||
|
||||
// Rating-boundary audit against the client's own ladder (cmp 0x4b / 0x41).
|
||||
for (rating, want) in [(0u8, 1u8), (64, 1), (65, 2), (74, 2), (75, 3), (99, 3)] {
|
||||
let got = discard::discard_level(rating);
|
||||
if got != want {
|
||||
boundary_probe_failures.push(format!("rating {rating}: level {got}, expected {want}"));
|
||||
}
|
||||
}
|
||||
|
||||
println!("== DISCARD MATRIX AUDIT ==");
|
||||
println!("definitions : {}", entries.len());
|
||||
println!("declined -> legacy : {declined_total}");
|
||||
println!("priced zero : {zero_priced}");
|
||||
println!("negative : {negatives}");
|
||||
println!("implausible (>1e6) : {overflow}");
|
||||
println!(
|
||||
"rating boundaries : {}",
|
||||
if boundary_probe_failures.is_empty() {
|
||||
"OK (1/2/3 at <65 / 65..74 / >=75)".to_string()
|
||||
} else {
|
||||
boundary_probe_failures.join("; ")
|
||||
}
|
||||
);
|
||||
println!();
|
||||
println!(
|
||||
"{:<12} {:>6} {:>9} {:>14} {:>14}",
|
||||
"kind", "n", "declined", "legacy", "recovered"
|
||||
);
|
||||
let (mut tl, mut tr) = (0i64, 0i64);
|
||||
for (kind, (n, dec, legacy, rec)) in &by_kind {
|
||||
println!("{kind:<12} {n:>6} {dec:>9} {legacy:>14} {rec:>14}");
|
||||
tl += legacy;
|
||||
tr += rec;
|
||||
}
|
||||
println!(
|
||||
"{:<12} {:>6} {:>9} {:>14} {:>14}",
|
||||
"TOTAL",
|
||||
entries.len(),
|
||||
declined_total,
|
||||
tl,
|
||||
tr
|
||||
);
|
||||
if tl > 0 {
|
||||
println!("ratio recovered/legacy : {:.2}x", tr as f64 / tl as f64);
|
||||
}
|
||||
|
||||
if let Some(path) = csv_path {
|
||||
std::fs::write(&path, rows.join("\n") + "\n").expect("write csv");
|
||||
println!("\nwrote {} rows to {path}", rows.len() - 1);
|
||||
}
|
||||
|
||||
let fatal = negatives + overflow + boundary_probe_failures.len();
|
||||
if fatal > 0 {
|
||||
eprintln!("\nFAIL: {fatal} fatal finding(s)");
|
||||
std::process::exit(1);
|
||||
}
|
||||
println!("\nRESULT: OK");
|
||||
}
|
||||
File diff suppressed because one or more lines are too long
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,460 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Freeze the Python Blaze responder's DISPATCH contract as replayable fixtures.
|
||||
|
||||
The crate-level fixtures in `openfut-protocol-blaze` pin the *codec*: given a
|
||||
field tree, what bytes come out. This file pins the layer above: given an
|
||||
inbound Fire2 frame and a session, **which frames go back, in what order**.
|
||||
|
||||
That is the whole contract of a Blaze adapter, and it is the thing a rewrite can
|
||||
silently get wrong in ways a codec test cannot see — a missing post-login
|
||||
notification, a reply where the oracle stays silent, notifications in the wrong
|
||||
order, session state not carried between RPCs.
|
||||
|
||||
Every transaction is produced by calling the real
|
||||
`blaze_responder_v3b.dispatch()`. Session state is threaded across a scripted
|
||||
connection exactly as it would be on a live socket, so ordering-dependent
|
||||
behaviour (preAuth captures the locale; login sets the auth code that
|
||||
getAuthToken later returns) is captured rather than assumed.
|
||||
|
||||
Determinism: the oracle's clock is pinned and its PRNG seeded, and the
|
||||
deployment-dependent addresses are set before import (the responder reads them
|
||||
at import time). See the sibling generator in openfut-protocol-blaze.
|
||||
|
||||
NO SECRETS. The identity here (persona 33068179 / "CAGE") is the project's fixed
|
||||
synthetic offline identity. Session keys are minted from a seeded PRNG.
|
||||
|
||||
Usage: python3 fixtures/generate.py (write)
|
||||
python3 fixtures/generate.py --check (verify committed files are current)
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
import os
|
||||
import random
|
||||
import sys
|
||||
from collections import OrderedDict
|
||||
|
||||
HERE = os.path.dirname(os.path.abspath(__file__))
|
||||
TOOLS = os.path.normpath(os.path.join(HERE, "..", "..", "fifa17-recon", "tools"))
|
||||
if not os.path.isdir(TOOLS):
|
||||
sys.exit("cannot find the Python oracle at %s" % TOOLS)
|
||||
sys.path.insert(0, TOOLS)
|
||||
|
||||
CHECK_ONLY = "--check" in sys.argv[1:]
|
||||
# Internal mode: re-exec of this script with sentinel addresses, used to derive
|
||||
# the templated client-config table (see emit_config_table).
|
||||
CONFIG_TABLE_MODE = "--_config_table" in sys.argv[1:]
|
||||
sys.argv = [sys.argv[0]]
|
||||
|
||||
# Sentinels substituted back into template tokens. Deliberately not IP-shaped so
|
||||
# a stray literal cannot be mistaken for a real address.
|
||||
SENTINELS = [
|
||||
("ADVERTISE-SENTINEL", "{advertise}"),
|
||||
("BIND-SENTINEL", "{bind}"),
|
||||
("POWCONTENT-SENTINEL", "{pow_content_host}"),
|
||||
("POWHOST-SENTINEL", "{pow_host}"),
|
||||
]
|
||||
|
||||
if CONFIG_TABLE_MODE:
|
||||
os.environ["OPENFUT_ADVERTISE"] = "ADVERTISE-SENTINEL"
|
||||
os.environ["OPENFUT_BIND"] = "BIND-SENTINEL"
|
||||
os.environ["POW_CONTENT_HOST"] = "POWCONTENT-SENTINEL"
|
||||
os.environ["POW_HOST"] = "POWHOST-SENTINEL"
|
||||
import blaze_responder_v3b as _B # noqa: E402
|
||||
out = {cfid: _B.client_config_for(cfid) for cfid in sorted(_B.CLIENT_CONFIGS)}
|
||||
out["__default__"] = _B.client_config_for("__no_such_section__")
|
||||
print(json.dumps(out))
|
||||
raise SystemExit(0)
|
||||
|
||||
# Pin deployment config BEFORE import — the responder snapshots these at import
|
||||
# time into module globals used by the response builders.
|
||||
#
|
||||
# Distinct, obviously-fake values on purpose: if the Rust adapter hardcoded an
|
||||
# address instead of reading its config, these make the failure loud rather than
|
||||
# accidentally matching a loopback default.
|
||||
ADVERTISE = "198.51.100.7"
|
||||
BIND = "0.0.0.0"
|
||||
POW_CONTENT_HOST = "198.51.100.7:8085"
|
||||
POW_HOST = "198.51.100.7:8094"
|
||||
|
||||
os.environ["OPENFUT_ADVERTISE"] = ADVERTISE
|
||||
os.environ["OPENFUT_BIND"] = BIND
|
||||
os.environ["POW_CONTENT_HOST"] = POW_CONTENT_HOST
|
||||
os.environ["POW_HOST"] = POW_HOST
|
||||
|
||||
import heat2 # noqa: E402
|
||||
import blaze_responder_v3b as B # noqa: E402
|
||||
from fut_account import ACCOUNT # noqa: E402
|
||||
|
||||
FIXED_NOW = 1754870400
|
||||
INT, STRING, STRUCT, LIST, MAP, BLOB = (
|
||||
heat2.INT, heat2.STRING, heat2.STRUCT, heat2.LIST, heat2.MAP, heat2.BLOB)
|
||||
|
||||
RECORDS = []
|
||||
|
||||
|
||||
# ------------------------------------------------------------------ helpers
|
||||
|
||||
def req_frame(component, command, fields=None, msg_num=1, msg_type=None,
|
||||
user_index=0):
|
||||
"""Build an inbound request frame the way the client would."""
|
||||
msg_type = B.MESSAGE if msg_type is None else msg_type
|
||||
payload = heat2.encode_tdf(fields) if fields else b""
|
||||
return B.fire2(component, command, msg_num, msg_type, payload,
|
||||
user_index=user_index)
|
||||
|
||||
|
||||
def tx(session, name, frame, note=""):
|
||||
"""Run one frame through the real dispatcher and record what came back."""
|
||||
hdr = B.parse_fire2_header(frame)
|
||||
body = frame[16 + hdr["metadata_len"]:]
|
||||
fields = heat2.decode_tdf(body) if body else OrderedDict()
|
||||
out = B.dispatch(hdr, fields, body, session["sess"])
|
||||
|
||||
RECORDS.append(OrderedDict((
|
||||
("kind", "tx"),
|
||||
("session", session["id"]),
|
||||
("name", name),
|
||||
("note", note),
|
||||
("request_hex", frame.hex()),
|
||||
("responses", [f.hex() for f in out]),
|
||||
)))
|
||||
return out
|
||||
|
||||
|
||||
def new_session(sid):
|
||||
s = {"id": sid, "sess": B.Session()}
|
||||
RECORDS.append(OrderedDict((
|
||||
("kind", "session"),
|
||||
("id", sid),
|
||||
# Minted per connection by the oracle; the Rust side must be able to
|
||||
# inject it, because it appears in LoginResponse.SESS.KEY, the
|
||||
# UserAuthenticated push and PostAuthResponse.TELE.SESS and all three
|
||||
# must be the same string.
|
||||
("session_key", s["sess"].session_key),
|
||||
("account_locale", s["sess"].account_locale),
|
||||
("service_name", s["sess"].service_name),
|
||||
)))
|
||||
return s
|
||||
|
||||
|
||||
# ------------------------------------------------------------------ script
|
||||
|
||||
def build():
|
||||
RECORDS.append(OrderedDict((
|
||||
("kind", "config"),
|
||||
("advertise", ADVERTISE),
|
||||
("bind", BIND),
|
||||
("pow_content_host", POW_CONTENT_HOST),
|
||||
("pow_host", POW_HOST),
|
||||
("now", FIXED_NOW),
|
||||
("identity", OrderedDict((
|
||||
("persona_id", ACCOUNT.persona_id),
|
||||
("persona_name", ACCOUNT.persona_name),
|
||||
("user_id", ACCOUNT.user_id),
|
||||
("ext_id", ACCOUNT.ext_id),
|
||||
("email", ACCOUNT.email),
|
||||
("namespace", ACCOUNT.NAMESPACE),
|
||||
("client_platform", ACCOUNT.CLIENT_PLATFORM),
|
||||
("persona_status", ACCOUNT.PERSONA_STATUS),
|
||||
("user_session_type", ACCOUNT.USER_SESSION_TYPE),
|
||||
("account_locale_int", ACCOUNT.account_locale_int),
|
||||
("locale", ACCOUNT.locale),
|
||||
("content_id", ACCOUNT.CONTENT_ID),
|
||||
("entitlement_tag", ACCOUNT.ENTITLEMENT_TAG),
|
||||
("entitlement_group", ACCOUNT.ENTITLEMENT_GROUP),
|
||||
("title_id", ACCOUNT.TITLE_ID),
|
||||
("client_id", ACCOUNT.CLIENT_ID),
|
||||
("platform", ACCOUNT.PLATFORM),
|
||||
("server_version", B.SERVER_VERSION),
|
||||
))),
|
||||
)))
|
||||
|
||||
# ================= main connection: the real boot order =================
|
||||
#
|
||||
# Mirrors what FIFA 17 actually does, because ordering is load-bearing:
|
||||
# preAuth captures the locale that later ALOC fields echo, and login sets
|
||||
# the auth code that getAuthToken returns afterwards.
|
||||
m = new_session("main")
|
||||
|
||||
tx(m, "preauth", req_frame(B.COMP_UTIL, B.CMD_PREAUTH, OrderedDict([
|
||||
("CDAT", (STRUCT, OrderedDict([
|
||||
("IITO", (INT, 0)),
|
||||
("LANG", (INT, 0x656E5553)), # 'enUS'
|
||||
("SVCN", (STRING, "fifa-2017-pc")), # echoed back as INST
|
||||
("TYPE", (INT, 0)),
|
||||
]))),
|
||||
("CINF", (STRUCT, OrderedDict([
|
||||
("BSDK", (STRING, "15.1.1.3.0")),
|
||||
("CLNT", (STRING, "FIFA17")),
|
||||
("ENV", (STRING, "prod")),
|
||||
("LOC", (INT, 0x656E5553)),
|
||||
]))),
|
||||
("FCCR", (STRUCT, OrderedDict([("CFID", (STRING, "BlazeSDK"))]))),
|
||||
])), "first RPC; echoes SVCN as INST and captures LANG for ALOC")
|
||||
|
||||
tx(m, "ping", req_frame(B.COMP_UTIL, B.CMD_PING, msg_num=2),
|
||||
"Util::ping -> STIM only")
|
||||
|
||||
# Every section the responder knows, plus unknown ones. The known sections
|
||||
# each add their own rows on top of the shared FUT/RS4 base — OSDK_ROSTER in
|
||||
# particular carries the roster URL, itself a documented loading gate — so
|
||||
# covering only "BlazeSDK" would leave most of the table unverified.
|
||||
for cfid in ("BlazeSDK", "netres", "IdentityParams", "OSDK_CORE",
|
||||
"OSDK_CLIENT", "OSDK_NUCLEUS", "OSDK_ROSTER", "OSDK_TICKER",
|
||||
"OSDK_WEBOFFER", "OSDK_POW", "OSDK_ABUSE_REPORTING",
|
||||
"OSDK_XMS_ABUSE_REPORTING", "UTAS", "FUT", "",
|
||||
"TOTALLY_UNKNOWN"):
|
||||
tx(m, "fetch_config_%s" % (cfid or "empty"),
|
||||
req_frame(B.COMP_UTIL, B.CMD_FETCHCLIENTCONFIG,
|
||||
OrderedDict([("CFID", (STRING, cfid))]), msg_num=3),
|
||||
"unknown CFIDs still get the shared FUT/POW rows")
|
||||
|
||||
tx(m, "get_auth_token_before_login",
|
||||
req_frame(B.COMP_AUTH, B.CMD_GETAUTHTOKEN, msg_num=4),
|
||||
"no auth code yet -> synthesised OPENFUT-<key[:16]> token")
|
||||
|
||||
tx(m, "logout_before_login", req_frame(B.COMP_AUTH, B.CMD_LOGOUT, msg_num=5),
|
||||
"routine LoginStateLogout (state 500), NOT a failure; empty reply")
|
||||
|
||||
tx(m, "login", req_frame(B.COMP_AUTH, B.CMD_LOGIN, OrderedDict([
|
||||
("AUTH", (STRING, "OPENFUT-TEST-AUTHCODE")),
|
||||
("EXTB", (BLOB, b"")),
|
||||
("PNAM", (STRING, "")),
|
||||
]), msg_num=6),
|
||||
"reply THEN three UserSessions pushes, in that order")
|
||||
|
||||
tx(m, "get_auth_token_after_login",
|
||||
req_frame(B.COMP_AUTH, B.CMD_GETAUTHTOKEN, msg_num=7),
|
||||
"now echoes the login's AUTH verbatim")
|
||||
|
||||
tx(m, "get_account", req_frame(B.COMP_AUTH, B.CMD_GETACCOUNT, msg_num=8),
|
||||
"the RPC behind 'Unable to retrieve account information'")
|
||||
tx(m, "get_persona", req_frame(B.COMP_AUTH, B.CMD_GETPERSONA, msg_num=9))
|
||||
tx(m, "list_personas", req_frame(B.COMP_AUTH, B.CMD_LISTPERSONAS, msg_num=10))
|
||||
|
||||
for cmd, label in ((B.CMD_LISTUSERENTITLEMENTS2, "listUserEntitlements2"),
|
||||
(0x20, "listEntitlements"),
|
||||
(0x30, "listPersonaEntitlements2"),
|
||||
(0x27, "grantEntitlement2")):
|
||||
tx(m, "entitlements_%s" % label,
|
||||
req_frame(B.COMP_AUTH, cmd, msg_num=11),
|
||||
"all four aliases return the same two ONLINE_ACCESS records")
|
||||
|
||||
tx(m, "post_auth", req_frame(B.COMP_UTIL, B.CMD_POSTAUTH, msg_num=12),
|
||||
"TELE/TICK/UROP; TELE.SESS must equal the login session key")
|
||||
tx(m, "fetch_qos_config", req_frame(B.COMP_UTIL, 0x15, msg_num=13))
|
||||
tx(m, "user_settings_load",
|
||||
req_frame(B.COMP_UTIL, B.CMD_USERSETTINGSLOAD, msg_num=14))
|
||||
tx(m, "user_settings_save",
|
||||
req_frame(B.COMP_UTIL, B.CMD_USERSETTINGSSAVE, msg_num=15),
|
||||
"accepted and discarded; empty reply")
|
||||
tx(m, "set_client_state",
|
||||
req_frame(B.COMP_UTIL, B.CMD_SETCLIENTSTATE, msg_num=16))
|
||||
tx(m, "set_client_metrics",
|
||||
req_frame(B.COMP_UTIL, B.CMD_SETCLIENTMETRICS, msg_num=17))
|
||||
|
||||
tx(m, "update_network_info",
|
||||
req_frame(B.COMP_USERSESSIONS, B.CMD_UPDATENETWORKINFO, msg_num=18),
|
||||
"empty reply PLUS an unsolicited ExtendedDataUpdate push")
|
||||
|
||||
tx(m, "get_lists", req_frame(B.COMP_ASSOCLISTS, B.CMD_GETLISTS, msg_num=19))
|
||||
|
||||
tx(m, "census_subscribe",
|
||||
req_frame(B.COMP_CENSUSDATA, B.CMD_SUBSCRIBETOCENSUSDATAUPDATES,
|
||||
OrderedDict([("RSUB", (INT, 1))]), msg_num=20),
|
||||
"non-zero TimeValues or the client storms at ~30/s and hangs the FUT load")
|
||||
|
||||
tx(m, "logout_after_login",
|
||||
req_frame(B.COMP_AUTH, B.CMD_LOGOUT, msg_num=21),
|
||||
"session teardown after a login; still an empty reply")
|
||||
|
||||
# ============================ fallback behaviour ========================
|
||||
f = new_session("fallbacks")
|
||||
|
||||
tx(f, "transport_ping",
|
||||
req_frame(B.COMP_UTIL, B.CMD_PING, msg_num=30, msg_type=B.PING),
|
||||
"msgType PING -> PING_REPLY with an empty body, whatever the command")
|
||||
|
||||
for mt, label in ((B.REPLY, "reply"), (B.NOTIFICATION, "notification"),
|
||||
(B.ERROR_REPLY, "error_reply"),
|
||||
(B.PING_REPLY, "ping_reply")):
|
||||
tx(f, "ignores_%s" % label,
|
||||
req_frame(B.COMP_UTIL, B.CMD_PING, msg_num=31, msg_type=mt),
|
||||
"not a request -> NO frames at all")
|
||||
|
||||
tx(f, "unknown_command",
|
||||
req_frame(B.COMP_UTIL, 0x0FFF, msg_num=32),
|
||||
"unimplemented RPC still gets an EMPTY reply so the client cannot hang")
|
||||
tx(f, "unknown_component",
|
||||
req_frame(0x1234, 0x0001, msg_num=33),
|
||||
"same fallback for an entirely unknown component")
|
||||
|
||||
tx(f, "user_index_is_echoed",
|
||||
req_frame(B.COMP_UTIL, B.CMD_PING, msg_num=34, user_index=7),
|
||||
"a reply echoes component/command/msgNum/userIndex verbatim")
|
||||
|
||||
# ================= locale echo on a non-default client ==================
|
||||
loc = new_session("locale")
|
||||
tx(loc, "preauth_de_locale",
|
||||
req_frame(B.COMP_UTIL, B.CMD_PREAUTH, OrderedDict([
|
||||
("CDAT", (STRUCT, OrderedDict([
|
||||
("LANG", (INT, 0x64654445)), # 'deDE'
|
||||
("SVCN", (STRING, "fifa-2017-pc-de")),
|
||||
]))),
|
||||
])),
|
||||
"a non-enUS client: SVCN echo AND the captured locale must both change")
|
||||
tx(loc, "login_with_de_locale",
|
||||
req_frame(B.COMP_AUTH, B.CMD_LOGIN, msg_num=41),
|
||||
"UserAuthenticated.ALOC must carry the captured deDE locale")
|
||||
|
||||
|
||||
# ------------------------------------------------------------------- output
|
||||
|
||||
def emit_config_table():
|
||||
"""Derive the fetchClientConfig tables as address-TEMPLATED data.
|
||||
|
||||
These are 227-243 key/value rows per CFID, almost all of them the same URL.
|
||||
Hand-transcribing them into Rust would be 400 lines of string literals that
|
||||
nobody can review and one typo can break; deriving them mechanically from
|
||||
the oracle removes that whole class of error and keeps them regenerable.
|
||||
They are reverse-engineered *data*, not logic — the same reason
|
||||
`openfut-core` loads its content from `data/` rather than from source.
|
||||
|
||||
The values are templated on {advertise}/{bind}/{pow_content_host}/{pow_host}
|
||||
so the adapter stays configurable; baking an address in here would recreate
|
||||
exactly the hardcoding the client/server split removed.
|
||||
|
||||
Correctness is not assumed: the caller substitutes real addresses back in
|
||||
and diffs against the oracle. See verify_config_table.
|
||||
"""
|
||||
import subprocess
|
||||
|
||||
raw = subprocess.run(
|
||||
[sys.executable, os.path.abspath(__file__), "--_config_table"],
|
||||
capture_output=True, text=True, check=True,
|
||||
# Inherit nothing address-shaped; the child sets its own sentinels.
|
||||
env={k: v for k, v in os.environ.items()
|
||||
if not k.startswith(("OPENFUT_", "POW_", "FUT_"))},
|
||||
).stdout
|
||||
table = json.loads(raw)
|
||||
|
||||
def templatise(value):
|
||||
for sentinel, token in SENTINELS:
|
||||
value = value.replace(sentinel, token)
|
||||
# Collapse whole URLs to URL-level tokens where one exists, so the Rust
|
||||
# side builds them in exactly one place (AdapterConfig::utas_base and
|
||||
# friends) instead of re-deriving the shape here. Without this the
|
||||
# helpers become dead code and a hardcoded address in them goes
|
||||
# undetected — verified by mutation testing. Longest first.
|
||||
for whole, token in (
|
||||
("http://{advertise}:8099/", "{utas_base}"),
|
||||
("http://{bind}:42131", "{nucleus_base}"),
|
||||
("http://{pow_content_host}", "{pow_content_url}"),
|
||||
):
|
||||
if value == whole:
|
||||
return token
|
||||
return value
|
||||
|
||||
return {cfid: [[k, templatise(v)] for k, v in rows]
|
||||
for cfid, rows in table.items()}
|
||||
|
||||
|
||||
def verify_config_table(table):
|
||||
"""Substitute the real addresses back and require the oracle's exact rows.
|
||||
|
||||
This is what makes the templated table trustworthy rather than plausible.
|
||||
"""
|
||||
subst = {
|
||||
"{utas_base}": "http://%s:8099/" % ADVERTISE,
|
||||
"{nucleus_base}": "http://%s:42131" % BIND,
|
||||
"{pow_content_url}": "http://%s" % POW_CONTENT_HOST,
|
||||
"{advertise}": ADVERTISE,
|
||||
"{bind}": BIND,
|
||||
"{pow_content_host}": POW_CONTENT_HOST,
|
||||
"{pow_host}": POW_HOST,
|
||||
}
|
||||
|
||||
def render(v):
|
||||
for token, real in subst.items():
|
||||
v = v.replace(token, real)
|
||||
return v
|
||||
|
||||
for cfid, rows in table.items():
|
||||
expected = B.client_config_for(
|
||||
"__no_such_section__" if cfid == "__default__" else cfid)
|
||||
got = [(k, render(v)) for k, v in rows]
|
||||
if got != [(k, v) for k, v in expected]:
|
||||
for (gk, gv), (ek, ev) in zip(got, expected):
|
||||
if (gk, gv) != (ek, ev):
|
||||
sys.exit("config template mismatch in %s: %r -> %r, oracle "
|
||||
"has %r -> %r" % (cfid, gk, gv, ek, ev))
|
||||
sys.exit("config template row-count mismatch in %s: %d vs %d"
|
||||
% (cfid, len(got), len(expected)))
|
||||
print("config table verified against the oracle for %d sections"
|
||||
% len(table))
|
||||
|
||||
|
||||
def frozen_clock():
|
||||
import time as _time
|
||||
original = _time.time
|
||||
_time.time = lambda: float(FIXED_NOW)
|
||||
return original, _time
|
||||
|
||||
|
||||
def write(path, records):
|
||||
body = "".join(json.dumps(r, separators=(",", ":")) + "\n" for r in records)
|
||||
if CHECK_ONLY:
|
||||
if not os.path.exists(path):
|
||||
sys.exit("MISSING: %s has never been generated" % path)
|
||||
with open(path, "r", encoding="utf-8") as fh:
|
||||
if fh.read() != body:
|
||||
sys.exit("STALE: %s does not match the oracle; re-run without "
|
||||
"--check" % path)
|
||||
print("current: %s (%d records)" % (os.path.basename(path), len(records)))
|
||||
return
|
||||
with open(path, "w", encoding="utf-8") as fh:
|
||||
fh.write(body)
|
||||
print("wrote %s (%d records)" % (os.path.basename(path), len(records)))
|
||||
|
||||
|
||||
def write_json(path, obj):
|
||||
body = json.dumps(obj, indent=1, sort_keys=True) + "\n"
|
||||
if CHECK_ONLY:
|
||||
if not os.path.exists(path):
|
||||
sys.exit("MISSING: %s has never been generated" % path)
|
||||
with open(path, "r", encoding="utf-8") as fh:
|
||||
if fh.read() != body:
|
||||
sys.exit("STALE: %s does not match the oracle" % path)
|
||||
print("current: %s" % os.path.basename(path))
|
||||
return
|
||||
with open(path, "w", encoding="utf-8") as fh:
|
||||
fh.write(body)
|
||||
print("wrote %s (%d sections)" % (os.path.basename(path), len(obj)))
|
||||
|
||||
|
||||
def main():
|
||||
# The oracle logs every dispatch to stdout; useful live, pure noise here.
|
||||
B.log = lambda *_a, **_k: None
|
||||
|
||||
table = emit_config_table()
|
||||
verify_config_table(table)
|
||||
write_json(os.path.join(HERE, "client_config.json"), table)
|
||||
|
||||
random.seed(0xB1A2E)
|
||||
original_time, time_mod = frozen_clock()
|
||||
try:
|
||||
build()
|
||||
finally:
|
||||
time_mod.time = original_time
|
||||
|
||||
write(os.path.join(HERE, "blaze_transactions.jsonl"), RECORDS)
|
||||
txs = [r for r in RECORDS if r["kind"] == "tx"]
|
||||
frames = sum(len(r["responses"]) for r in txs)
|
||||
print("%d transactions, %d response frames, %d sessions"
|
||||
% (len(txs), frames,
|
||||
len([r for r in RECORDS if r["kind"] == "session"])))
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
main()
|
||||
@@ -0,0 +1,123 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Capture the roster oracle's responses byte-for-byte.
|
||||
|
||||
generate_roster.py [--check] [host:port]
|
||||
|
||||
Unlike `generate.py`, which imports the Blaze responder and calls its pure
|
||||
functions, this captures over the wire. The roster response is shaped as much by
|
||||
`http.server.BaseHTTPRequestHandler` as by the handler code -- HTTP/1.0 status
|
||||
line, `Server:`/`Date:` injected ahead of the handler's own headers, POST
|
||||
answered without a body -- and only the real socket shows all of that.
|
||||
|
||||
Two fields are volatile and are MASKED rather than recorded:
|
||||
|
||||
Date: changes every second
|
||||
Server: carries the container's Python version
|
||||
|
||||
They are masked, not dropped, so their presence and position are still asserted.
|
||||
The Server string is additionally recorded verbatim under `observed_server`, so
|
||||
a drift between the container's Python and the adapter's `ORACLE_SERVER`
|
||||
constant is visible rather than silent.
|
||||
|
||||
`--check` re-captures and compares. If the oracle is unreachable it FAILS rather
|
||||
than passing: a check that cannot check must not report success.
|
||||
"""
|
||||
import json
|
||||
import os
|
||||
import re
|
||||
import socket
|
||||
import ssl
|
||||
import sys
|
||||
|
||||
HERE = os.path.dirname(os.path.abspath(__file__))
|
||||
OUT = os.path.join(HERE, "roster.json")
|
||||
PATH = "/fifa17/fut/rosterupdate.xml"
|
||||
|
||||
DATE_RE = re.compile(rb"^Date: .+?\r\n", re.M)
|
||||
SERVER_RE = re.compile(rb"^Server: (.+?)\r\n", re.M)
|
||||
|
||||
|
||||
def fetch(host, port, method, body=None):
|
||||
ctx = ssl.SSLContext(ssl.PROTOCOL_TLS_CLIENT)
|
||||
ctx.check_hostname = False
|
||||
ctx.verify_mode = ssl.CERT_NONE
|
||||
ctx.set_ciphers("ALL:@SECLEVEL=0")
|
||||
s = ctx.wrap_socket(socket.create_connection((host, port), timeout=8),
|
||||
server_hostname="fixture")
|
||||
req = "%s %s HTTP/1.1\r\nHost: %s:%d\r\nAccept: */*\r\n" % (method, PATH, host, port)
|
||||
if body is not None:
|
||||
req += "Content-Length: %d\r\n" % len(body)
|
||||
req += "\r\n"
|
||||
s.sendall(req.encode() + (body or b""))
|
||||
out = b""
|
||||
while True:
|
||||
chunk = s.recv(4096)
|
||||
if not chunk:
|
||||
break
|
||||
out += chunk
|
||||
s.close()
|
||||
return out
|
||||
|
||||
|
||||
def capture(host, port):
|
||||
result = {"path": PATH, "responses": {}}
|
||||
servers = set()
|
||||
for method, body in (("GET", None), ("HEAD", None), ("POST", b"probe=1")):
|
||||
raw = fetch(host, port, method, body)
|
||||
m = SERVER_RE.search(raw)
|
||||
if m:
|
||||
servers.add(m.group(1).decode())
|
||||
masked = DATE_RE.sub(b"Date: <MASKED>\r\n", raw)
|
||||
masked = SERVER_RE.sub(b"Server: <MASKED>\r\n", masked)
|
||||
result["responses"][method] = masked.hex()
|
||||
if len(servers) != 1:
|
||||
raise SystemExit("oracle returned inconsistent Server headers: %r" % servers)
|
||||
result["observed_server"] = servers.pop()
|
||||
return result
|
||||
|
||||
|
||||
def main():
|
||||
check = "--check" in sys.argv
|
||||
args = [a for a in sys.argv[1:] if not a.startswith("--")]
|
||||
host, port = (args[0].split(":") if args else ("127.0.0.1", "8081"))[0], \
|
||||
int((args[0].split(":")[1] if args and ":" in args[0] else "8081"))
|
||||
|
||||
try:
|
||||
fresh = capture(host, port)
|
||||
except Exception as e:
|
||||
# Explicitly a failure. A --check that silently passes when it could not
|
||||
# reach the oracle is exactly the class of self-confirming tooling this
|
||||
# project has been bitten by repeatedly.
|
||||
raise SystemExit("cannot reach the roster oracle at %s:%d (%s). "
|
||||
"Refusing to report success." % (host, port, e))
|
||||
|
||||
if check:
|
||||
if not os.path.exists(OUT):
|
||||
raise SystemExit("no fixture at %s -- run without --check first" % OUT)
|
||||
with open(OUT) as f:
|
||||
stored = json.load(f)
|
||||
if stored.get("responses") != fresh["responses"]:
|
||||
for m in sorted(set(stored.get("responses", {})) | set(fresh["responses"])):
|
||||
a = stored.get("responses", {}).get(m)
|
||||
b = fresh["responses"].get(m)
|
||||
if a != b:
|
||||
print("MISMATCH %s\n stored: %s\n live : %s" % (m, a, b))
|
||||
raise SystemExit("roster fixtures differ from the live oracle")
|
||||
if stored.get("observed_server") != fresh["observed_server"]:
|
||||
raise SystemExit(
|
||||
"the oracle's Server header changed: %r -> %r.\n"
|
||||
"Update roster::ORACLE_SERVER and regenerate."
|
||||
% (stored.get("observed_server"), fresh["observed_server"]))
|
||||
print("roster fixtures match the live oracle (%d responses, server=%r)"
|
||||
% (len(fresh["responses"]), fresh["observed_server"]))
|
||||
return
|
||||
|
||||
with open(OUT, "w") as f:
|
||||
json.dump(fresh, f, indent=2, sort_keys=True)
|
||||
f.write("\n")
|
||||
print("wrote %s (%d responses, server=%r)"
|
||||
% (OUT, len(fresh["responses"]), fresh["observed_server"]))
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
main()
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user