Compare commits
209 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| bf6db98f0d | |||
| fc55de19fa | |||
| 6ae3364bd0 | |||
| 5c40b4993f | |||
| fbc0da2a1b | |||
| 750d6c2e18 | |||
| 082246c085 | |||
| 16771b0b33 | |||
| 022634704a | |||
| 96ca7c0484 | |||
| 202366611e | |||
| ea92057e53 | |||
| c71593b286 | |||
| 413ad901fb | |||
| e0e46d8a57 | |||
| fbe29da05b | |||
| 9ffbd651b1 | |||
| aa5fb2cc40 | |||
| 468bc0fba9 | |||
| 571c5f9261 | |||
| cb32fe9b84 | |||
| fbe9804d3e | |||
| f6606accb3 | |||
| 0a007f4941 | |||
| 0c4aee6164 | |||
| a57f4930f0 | |||
| f9ca901a50 | |||
| 3ce69f8951 | |||
| acd1def00d | |||
| 5ec9c7f8bf | |||
| 11c028e6eb | |||
| afadb13de4 | |||
| b6398c44e6 | |||
| a2bd048ace | |||
| 2e97ff1461 | |||
| 7f37b37be3 | |||
| 4e31fb98a2 | |||
| 6cc22e5cc5 | |||
| b1d7ed2570 | |||
| dcbef721f2 | |||
| 772f8a615a | |||
| bf9ae20367 | |||
| 58d1f9426f | |||
| 3cd31c4322 | |||
| ae5feb05b7 | |||
| f2c4927ea6 | |||
| aa2abc2772 | |||
| 1aa84afa9a | |||
| 33e9118329 | |||
| e06fd57211 | |||
| 42fd3c7e90 | |||
| 0bc71dbd74 | |||
| 2ecd830d75 | |||
| 3a51b0ebd4 | |||
| ad406f21bd | |||
| 12fb9fc38b | |||
| 7b580a0070 | |||
| 22443a3810 | |||
| 0fce1e521c | |||
| 71fcf5e251 | |||
| 979e71fbea | |||
| 45e0b0bd95 | |||
| 70eb3fc13f | |||
| b30aa352f6 | |||
| 67cc33cfee | |||
| 6eec3b9ec7 | |||
| 57773b98ec | |||
| fe9b899a0e | |||
| abe9e663c1 | |||
| f5a33eb58c | |||
| a85090c3c6 | |||
| 97d48d8371 | |||
| 5020137050 | |||
| cf05ab2a9e | |||
| a6416a3f1d | |||
| 47ced228de | |||
| b8beeba98d | |||
| df6994c957 | |||
| d74e86c065 | |||
| 76512f6048 | |||
| 93a46d4de7 | |||
| 3ba24a0faf | |||
| 6926bb9528 | |||
| b1643309f6 | |||
| 43917a0051 | |||
| 1fac71e3ef | |||
| 747cc234c1 | |||
| fe72f0def2 | |||
| 884ecbba64 | |||
| 580d80a86e | |||
| 0e2ca5a7c3 | |||
| 4d2b8b9be3 | |||
| 0b31abe1d1 | |||
| 6b652cb0a2 | |||
| 3507c5714d | |||
| 4f78b9a875 | |||
| f3aebafcc7 | |||
| 1df0bc4f00 | |||
| 7d5d0cff06 | |||
| 8d752cb0e4 | |||
| 96e80ab293 | |||
| 49c5185ae3 | |||
| 181bd94341 | |||
| 09675a9f7f | |||
| 56c364e4c9 | |||
| 3021a4e761 | |||
| d240a61157 | |||
| d7c5307045 | |||
| 838d76f95e | |||
| 9791eee67b | |||
| 5d119f5555 | |||
| 46e5f612c8 | |||
| 41494bd18f | |||
| 40ebf7c1e7 | |||
| c7609252d2 | |||
| 4cf388dd3b | |||
| 00d85aa6e4 | |||
| d9e80a774a | |||
| a82407c686 | |||
| 805d754dc8 | |||
| d4c3811665 | |||
| b25761ea31 | |||
| 1c396dd562 | |||
| fc29c2eb9b | |||
| b0d5e04bb9 | |||
| 6746c75302 | |||
| b2697b13dc | |||
| e8ee6c34e7 | |||
| f42279f869 | |||
| 54ad9e8f79 | |||
| 6f16a231fc | |||
| 626c972232 | |||
| 44fcf24d92 | |||
| e187cd49a2 | |||
| 1631d3b1a2 | |||
| c71c2a8d33 | |||
| a51947562c | |||
| 63f02c4fb1 | |||
| 4fd5ee2608 | |||
| c7d4b9f753 | |||
| 37c2e5d7ee | |||
| 7dbd878398 | |||
| c2e2e0d8f2 | |||
| afc909fd3b | |||
| b607ff28cb | |||
| cf86d4e425 | |||
| 85761390a8 | |||
| 4d30d8b3e8 | |||
| 0e30980632 | |||
| 46a81e7a07 | |||
| e09344490f | |||
| 80a8bc4520 | |||
| b50e0359f7 | |||
| 58a300c7f4 | |||
| eb8311a5ee | |||
| 550a59d12c | |||
| 8c1d1ed958 | |||
| fc00b0c6f9 | |||
| 5276dd2066 | |||
| 88da16a11e | |||
| 3ef3bc32ec | |||
| 36fe1caa3f | |||
| f55c401b6c | |||
| b8037b9b22 | |||
| c0a3f68ded | |||
| 04c5043aba | |||
| 0b66662525 | |||
| cdea85e214 | |||
| 05f6147433 | |||
| 8f3b659c33 | |||
| c9ae914910 | |||
| 84e81f2037 | |||
| 696386a9c1 | |||
| aa2679162d | |||
| 096d1c882f | |||
| ca63095786 | |||
| c65e9c54ce | |||
| b1bc7a764e | |||
| d7c0a5521d | |||
| 2ae90b1ea9 | |||
| cfb0435d96 | |||
| fc411bb6f1 | |||
| 5bc39e902d | |||
| e2c4ca6d56 | |||
| 288d990821 | |||
| c03702707b | |||
| 89f77470f3 | |||
| 0d576a14b7 | |||
| c5807c07a9 | |||
| 8f5f54833f | |||
| f451406058 | |||
| 8aab2c0d41 | |||
| ed0ccb8c2b | |||
| b40adac3fc | |||
| bfb7876ed4 | |||
| 55b4e54d5f | |||
| fafa2f1858 | |||
| c84fd14cac | |||
| 23374312bc | |||
| a84a72e0c0 | |||
| 6c102f00c0 | |||
| 48aa955212 | |||
| cf3ddde3a6 | |||
| 468b006008 | |||
| e091921b18 | |||
| a9eb54ae9c | |||
| cf961603fe | |||
| cc3ecddc06 | |||
| a9a816e0ed |
+5
-5
@@ -30,9 +30,9 @@ Thumbs.db
|
||||
|
||||
# Frozen baseline archives / inspects / manifests
|
||||
/docker-backups/
|
||||
gate-evidence/
|
||||
|
||||
# local dev screenshots (not versioned)
|
||||
fifa17-recon/.screens/
|
||||
|
||||
# local hook backup
|
||||
*.pre-storeguard.bak
|
||||
# Raw Fire2 frame captures — forensic evidence, may contain session material.
|
||||
# Sanitize with `blaze-sanitize` before anything leaves this machine.
|
||||
*.ofcap
|
||||
captures/
|
||||
|
||||
Generated
+250
-96
@@ -457,6 +457,29 @@ version = "1.5.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "f2032f911046de80f0a198e0901378627c33f59ea0ac00e363d481118bd70a53"
|
||||
|
||||
[[package]]
|
||||
name = "aws-lc-rs"
|
||||
version = "1.18.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "ce2b2dcc879c3bae0d371e77c99f2238400ef24ec001394befa67b6e543add9e"
|
||||
dependencies = [
|
||||
"aws-lc-sys",
|
||||
"zeroize",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "aws-lc-sys"
|
||||
version = "0.44.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "f09fae7be8bb3174e05c6afdb34199e6dc0c7c04ba9fa237b1967adfbde27483"
|
||||
dependencies = [
|
||||
"cc",
|
||||
"cmake",
|
||||
"dunce",
|
||||
"fs_extra",
|
||||
"pkg-config",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "axum"
|
||||
version = "0.7.9"
|
||||
@@ -613,19 +636,6 @@ dependencies = [
|
||||
"tokio-util",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "blaze-ssl-async"
|
||||
version = "0.4.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "6fec08f35919613bda0b3eb3bc772c2f793b3634133923b931874b18e1ac55de"
|
||||
dependencies = [
|
||||
"bytes",
|
||||
"num_enum",
|
||||
"rsa",
|
||||
"tokio",
|
||||
"x509-cert",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "block"
|
||||
version = "0.1.6"
|
||||
@@ -830,6 +840,15 @@ dependencies = [
|
||||
"error-code",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "cmake"
|
||||
version = "0.1.58"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "c0f78a02292a74a88ac736019ab962ece0bc380e3f977bf72e376c5d78ff0678"
|
||||
dependencies = [
|
||||
"cc",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "codespan-reporting"
|
||||
version = "0.11.1"
|
||||
@@ -1062,23 +1081,10 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "e7c1832837b905bbfb5101e07cc24c8deddf52f93225eee6ead5f4d63d53ddcb"
|
||||
dependencies = [
|
||||
"const-oid",
|
||||
"der_derive",
|
||||
"flagset",
|
||||
"pem-rfc7468",
|
||||
"zeroize",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "der_derive"
|
||||
version = "0.7.3"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "8034092389675178f570469e6c3b0465d3d30b4505c294a6550db47f3c17ad18"
|
||||
dependencies = [
|
||||
"proc-macro2",
|
||||
"quote",
|
||||
"syn 2.0.119",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "deranged"
|
||||
version = "0.5.8"
|
||||
@@ -1187,6 +1193,12 @@ version = "0.1.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "d8b14ccef22fc6f5a8f4d7d768562a182c04ce9a3b3157b91390b52ddfdf1a76"
|
||||
|
||||
[[package]]
|
||||
name = "dunce"
|
||||
version = "1.0.5"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "92773504d58c093f6de2459af4af33faa518c13451eb8f2b5698ed3d36e7c813"
|
||||
|
||||
[[package]]
|
||||
name = "ecolor"
|
||||
version = "0.29.1"
|
||||
@@ -1457,12 +1469,6 @@ version = "0.1.9"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "5baebc0774151f905a1a2cc41989300b1e6fbb29aff0ceffa1064fdd3088d582"
|
||||
|
||||
[[package]]
|
||||
name = "flagset"
|
||||
version = "0.4.7"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "b7ac824320a75a52197e8f2d787f6a38b6718bb6897a35142d749af3c0e8f4fe"
|
||||
|
||||
[[package]]
|
||||
name = "flate2"
|
||||
version = "1.1.9"
|
||||
@@ -1547,6 +1553,12 @@ dependencies = [
|
||||
"percent-encoding",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "fs_extra"
|
||||
version = "1.3.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "42703706b716c37f96a77aea830392ad231f44c9e9a67872fa5548707e11b11c"
|
||||
|
||||
[[package]]
|
||||
name = "futures-channel"
|
||||
version = "0.3.33"
|
||||
@@ -2113,9 +2125,9 @@ dependencies = [
|
||||
"futures-util",
|
||||
"http 0.2.12",
|
||||
"hyper 0.14.32",
|
||||
"rustls",
|
||||
"rustls 0.21.12",
|
||||
"tokio",
|
||||
"tokio-rustls",
|
||||
"tokio-rustls 0.24.1",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
@@ -3126,11 +3138,34 @@ version = "1.21.4"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "9f7c3e4beb33f85d45ae3e3a1792185706c8e16d043238c593331cc7cd313b50"
|
||||
|
||||
[[package]]
|
||||
name = "openfut-adapter-fifa17"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"openfut-protocol-blaze",
|
||||
"rand",
|
||||
"serde",
|
||||
"serde_json",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-autopatch"
|
||||
version = "0.1.0"
|
||||
|
||||
[[package]]
|
||||
name = "openfut-blaze-host"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"openfut-adapter-fifa17",
|
||||
"openfut-protocol-blaze",
|
||||
"rand",
|
||||
"serde_json",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-bridge"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"aes",
|
||||
"anyhow",
|
||||
"axum",
|
||||
"bytes",
|
||||
@@ -3141,13 +3176,13 @@ dependencies = [
|
||||
"hyper-util",
|
||||
"rcgen",
|
||||
"reqwest",
|
||||
"rustls",
|
||||
"rustls-pemfile",
|
||||
"rustls 0.21.12",
|
||||
"rustls-pemfile 1.0.4",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"thiserror 1.0.69",
|
||||
"tokio",
|
||||
"tokio-rustls",
|
||||
"tokio-rustls 0.24.1",
|
||||
"tokio-stream",
|
||||
"tower 0.4.13",
|
||||
"tower-http",
|
||||
@@ -3185,11 +3220,40 @@ dependencies = [
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-hook"
|
||||
name = "openfut-host-config"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"openfut-common",
|
||||
"windows-sys 0.59.0",
|
||||
"openfut-adapter-fifa17",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-http"
|
||||
version = "0.1.0"
|
||||
|
||||
[[package]]
|
||||
name = "openfut-identity"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"parking_lot",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"tempfile",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-import-fifa17"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"anyhow",
|
||||
"openfut-adapter-fifa17",
|
||||
"openfut-core",
|
||||
"openfut-identity",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"sqlx",
|
||||
"tempfile",
|
||||
"tokio",
|
||||
"uuid",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
@@ -3201,11 +3265,73 @@ dependencies = [
|
||||
"dirs",
|
||||
"eframe",
|
||||
"egui",
|
||||
"openfut-common",
|
||||
"parking_lot",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"tokio",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-lsx"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"aes",
|
||||
"parking_lot",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-protocol-blaze"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"serde_json",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-redirector-host"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"openfut-adapter-fifa17",
|
||||
"openfut-host-config",
|
||||
"openfut-http",
|
||||
"openfut-tls",
|
||||
"openssl",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-roster-host"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"openfut-adapter-fifa17",
|
||||
"openfut-host-config",
|
||||
"openfut-http",
|
||||
"openfut-tls",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-tls"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"openssl",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openfut-utas-host"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"axum",
|
||||
"openfut-adapter-fifa17",
|
||||
"openfut-core",
|
||||
"openfut-http",
|
||||
"openfut-identity",
|
||||
"parking_lot",
|
||||
"rand",
|
||||
"reqwest",
|
||||
"serde_json",
|
||||
"sqlx",
|
||||
"tokio",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openssl"
|
||||
version = "0.10.81"
|
||||
@@ -3237,6 +3363,15 @@ version = "0.2.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "7c87def4c32ab89d880effc9e097653c8da5d6ef28e6b539d313baaacfbafcbe"
|
||||
|
||||
[[package]]
|
||||
name = "openssl-src"
|
||||
version = "300.6.1+3.6.3"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "46eb8fb9fb3b61ce1c0f8a026c4c1a0714d3a9e138e7fbde78753ce2babc3846"
|
||||
dependencies = [
|
||||
"cc",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openssl-sys"
|
||||
version = "0.9.117"
|
||||
@@ -3245,6 +3380,7 @@ checksum = "b47e7e6bb2c38cd930d25a23b40fa52e068c10e85f3e03a7f5ba5aaca5713695"
|
||||
dependencies = [
|
||||
"cc",
|
||||
"libc",
|
||||
"openssl-src",
|
||||
"pkg-config",
|
||||
"vcpkg",
|
||||
]
|
||||
@@ -3685,8 +3821,8 @@ dependencies = [
|
||||
"once_cell",
|
||||
"percent-encoding",
|
||||
"pin-project-lite",
|
||||
"rustls",
|
||||
"rustls-pemfile",
|
||||
"rustls 0.21.12",
|
||||
"rustls-pemfile 1.0.4",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"serde_urlencoded",
|
||||
@@ -3694,7 +3830,7 @@ dependencies = [
|
||||
"system-configuration",
|
||||
"tokio",
|
||||
"tokio-native-tls",
|
||||
"tokio-rustls",
|
||||
"tokio-rustls 0.24.1",
|
||||
"tower-service",
|
||||
"url",
|
||||
"wasm-bindgen",
|
||||
@@ -3833,10 +3969,26 @@ checksum = "3f56a14d1f48b391359b22f731fd4bd7e43c97f3c50eee276f3aa09c94784d3e"
|
||||
dependencies = [
|
||||
"log",
|
||||
"ring 0.17.14",
|
||||
"rustls-webpki",
|
||||
"rustls-webpki 0.101.7",
|
||||
"sct",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "rustls"
|
||||
version = "0.23.43"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "0283386ce02abc0151e1761d08802dfe86c173b0b494af5cbc086574e453da06"
|
||||
dependencies = [
|
||||
"aws-lc-rs",
|
||||
"log",
|
||||
"once_cell",
|
||||
"ring 0.17.14",
|
||||
"rustls-pki-types",
|
||||
"rustls-webpki 0.103.13",
|
||||
"subtle",
|
||||
"zeroize",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "rustls-pemfile"
|
||||
version = "1.0.4"
|
||||
@@ -3846,6 +3998,24 @@ dependencies = [
|
||||
"base64 0.21.7",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "rustls-pemfile"
|
||||
version = "2.2.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "dce314e5fee3f39953d46bb63bb8a46d40c2f8fb7cc5a3b6cab2bde9721d6e50"
|
||||
dependencies = [
|
||||
"rustls-pki-types",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "rustls-pki-types"
|
||||
version = "1.15.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "2f4925028c7eb5d1fcdaf196971378ed9d2c1c4efc7dc5d011256f76c99c0a96"
|
||||
dependencies = [
|
||||
"zeroize",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "rustls-webpki"
|
||||
version = "0.101.7"
|
||||
@@ -3856,6 +4026,18 @@ dependencies = [
|
||||
"untrusted 0.9.0",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "rustls-webpki"
|
||||
version = "0.103.13"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "61c429a8649f110dddef65e2a5ad240f747e85f7758a6bccc7e5777bd33f756e"
|
||||
dependencies = [
|
||||
"aws-lc-rs",
|
||||
"ring 0.17.14",
|
||||
"rustls-pki-types",
|
||||
"untrusted 0.9.0",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "rustversion"
|
||||
version = "1.0.23"
|
||||
@@ -4042,15 +4224,17 @@ version = "0.1.0"
|
||||
dependencies = [
|
||||
"anyhow",
|
||||
"blaze-proto",
|
||||
"blaze-ssl-async",
|
||||
"bytes",
|
||||
"chrono",
|
||||
"futures-util",
|
||||
"hex",
|
||||
"rustls 0.23.43",
|
||||
"rustls-pemfile 2.2.0",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"tdf",
|
||||
"tokio",
|
||||
"tokio-rustls 0.26.4",
|
||||
"tokio-util",
|
||||
"toml",
|
||||
"tracing",
|
||||
@@ -4068,6 +4252,12 @@ dependencies = [
|
||||
"digest",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "sha1_smol"
|
||||
version = "1.0.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "bbfa15b3dddfee50a0fff136974b3e1bde555604ba463834a7eb7deb6417705d"
|
||||
|
||||
[[package]]
|
||||
name = "sha2"
|
||||
version = "0.10.9"
|
||||
@@ -4334,8 +4524,8 @@ dependencies = [
|
||||
"once_cell",
|
||||
"paste",
|
||||
"percent-encoding",
|
||||
"rustls",
|
||||
"rustls-pemfile",
|
||||
"rustls 0.21.12",
|
||||
"rustls-pemfile 1.0.4",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"sha2",
|
||||
@@ -4789,27 +4979,6 @@ version = "0.1.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "1f3ccbac311fea05f86f61904b462b55fb3df8837a366dfc601a0161d0532f20"
|
||||
|
||||
[[package]]
|
||||
name = "tls_codec"
|
||||
version = "0.4.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "0de2e01245e2bb89d6f05801c564fa27624dbd7b1846859876c7dad82e90bf6b"
|
||||
dependencies = [
|
||||
"tls_codec_derive",
|
||||
"zeroize",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "tls_codec_derive"
|
||||
version = "0.4.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "2d2e76690929402faae40aebdda620a2c0e25dd6d3b9afe48867dfd95991f4bd"
|
||||
dependencies = [
|
||||
"proc-macro2",
|
||||
"quote",
|
||||
"syn 2.0.119",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "tokio"
|
||||
version = "1.53.1"
|
||||
@@ -4854,7 +5023,17 @@ version = "0.24.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "c28327cf380ac148141087fbfb9de9d7bd4e84ab5d2c28fbc911d753de8a7081"
|
||||
dependencies = [
|
||||
"rustls",
|
||||
"rustls 0.21.12",
|
||||
"tokio",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "tokio-rustls"
|
||||
version = "0.26.4"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "1729aa945f29d91ba541258c8df89027d5792d85a8841fb65e8bf0f4ede4ef61"
|
||||
dependencies = [
|
||||
"rustls 0.23.43",
|
||||
"tokio",
|
||||
]
|
||||
|
||||
@@ -5219,6 +5398,7 @@ dependencies = [
|
||||
"getrandom 0.4.3",
|
||||
"js-sys",
|
||||
"serde_core",
|
||||
"sha1_smol",
|
||||
"wasm-bindgen",
|
||||
]
|
||||
|
||||
@@ -6157,18 +6337,6 @@ version = "0.13.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "ea6fc2961e4ef194dcbfe56bb845534d0dc8098940c7e5c012a258bfec6701bd"
|
||||
|
||||
[[package]]
|
||||
name = "x509-cert"
|
||||
version = "0.2.5"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "1301e935010a701ae5f8655edc0ad17c44bad3ac5ce8c39185f75453b720ae94"
|
||||
dependencies = [
|
||||
"const-oid",
|
||||
"der",
|
||||
"spki",
|
||||
"tls_codec",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "xcursor"
|
||||
version = "0.3.11"
|
||||
@@ -6393,20 +6561,6 @@ name = "zeroize"
|
||||
version = "1.9.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "e13c156562582aa81c60cb29407084cdb54c4164760106ab78e6c5b0858cf64e"
|
||||
dependencies = [
|
||||
"zeroize_derive",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "zeroize_derive"
|
||||
version = "1.5.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "3c50655cbb0fe3fc43170059e702f1ce5e19b84cec58dc87b037a09935c2f328"
|
||||
dependencies = [
|
||||
"proc-macro2",
|
||||
"quote",
|
||||
"syn 2.0.119",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "zerotrie"
|
||||
|
||||
+22
-1
@@ -2,9 +2,30 @@
|
||||
resolver = "2"
|
||||
members = [
|
||||
"openfut-core",
|
||||
"openfut-protocol-blaze",
|
||||
"openfut-adapter-fifa17",
|
||||
"openfut-blaze-host",
|
||||
"openfut-host-config",
|
||||
"openfut-http",
|
||||
"openfut-tls",
|
||||
"openfut-redirector-host",
|
||||
"openfut-roster-host",
|
||||
"openfut-utas-host",
|
||||
"openfut-identity",
|
||||
"openfut-import-fifa17",
|
||||
"openfut-bridge",
|
||||
"openfut-launcher",
|
||||
"openfut-launcher/openfut-hook",
|
||||
# The two companion services the launcher used to shell out to Python for.
|
||||
"openfut-lsx",
|
||||
"openfut-autopatch",
|
||||
"fifa-blaze/crates/blaze-proto",
|
||||
"fifa-blaze/crates/server",
|
||||
]
|
||||
# openfut-hook is a Windows-only version.dll proxy injected into the FIFA client.
|
||||
# It MUST build with its own [profile.release] (panic="abort" — unwinding across
|
||||
# the DllMain/FFI boundary into the game process is UB — plus strip + opt-level="s").
|
||||
# Cargo ignores a non-root member's profile and forbids per-package `panic` overrides,
|
||||
# so the hook is deliberately EXCLUDED from this workspace to build as its own root
|
||||
# (this also lands its artifact in openfut-hook/target/, matching the launcher's
|
||||
# config.rs default hook_dll_path). Build: cargo build --release --target x86_64-pc-windows-gnu.
|
||||
exclude = ["openfut-launcher/openfut-hook"]
|
||||
|
||||
@@ -263,48 +263,3 @@ Both matter beyond themselves, because they are the only two routes into a match
|
||||
Useful framing: this project's failures have almost always come from proposing a fix
|
||||
before testing the assumption under it. Hypotheses that come with a cheap way to
|
||||
disconfirm them are worth far more than plausible ones.
|
||||
|
||||
## FIFA 17 network-redirect milestone (2026-08-09)
|
||||
|
||||
Hook now installs a GENERIC network redirect on the fifa17 feature path (fifa17.rs
|
||||
install_network_redirect): getaddrinfo IAT patch + inline connect detour + WSAConnect
|
||||
IAT, with a configurable destination (connect_hook::set_target_ipv4) read from
|
||||
openfut.cfg (single-line IP). Deployed DLL md5 bc9e0bc6, cfg=10.10.0.120.
|
||||
|
||||
RESULT of live launch (client 105 -> server 120):
|
||||
- Error changed: "servers shut down" -> "Unable to connect to EA servers / check
|
||||
network". Redirect IS firing (progress).
|
||||
- BLOCKER A: getaddrinfo IAT patched 0+0 -> FIFA 17 does NOT resolve via IAT
|
||||
getaddrinfo in the main exe or EAWebKit.dll. Names resolved via another path
|
||||
(gethostbyname or internal DirtySDK resolver). So no hostname reached 120.
|
||||
- BLOCKER B (architectural): FIFA 17 online = Blaze binary TCP on high ports. Log
|
||||
shows connect 20.51.153.159:42230 sock_type=1 -> wsa_err=10035 (WOULDBLOCK->dead).
|
||||
Port 42230 is NOT in the remap set (443,10041,42127,3216) so it was not redirected.
|
||||
Even if redirected, the Docker bridge only speaks HTTPS on 8443 -- no Blaze
|
||||
listener exists for FIFA 17. This is a server-side build, not a hook tweak.
|
||||
|
||||
NEXT (evidence-first): add gethostbyname (and possibly a DirtySDK resolver) capture
|
||||
to learn the hostname behind 20.51.153.159; widen Blaze port remap; then scope a
|
||||
Blaze-speaking bridge listener before expecting the error to clear.
|
||||
|
||||
## DNS/getaddrinfo fix — RESOLVED (2026-08-09, hook md5 67e3639b)
|
||||
|
||||
Added src/resolver_hook.rs: INLINE detours at ws2_32 export addresses for
|
||||
getaddrinfo + GetAddrInfoW + gethostbyname (same unhook/rehook pattern as
|
||||
connect_hook). Replaces the IAT approach that patched 0 slots on FIFA 17.
|
||||
Wired into fifa17.rs install_network_redirect; hooks.rs gained redirect_ip_cstr()
|
||||
and redirect_ip_str() helpers.
|
||||
|
||||
LIVE RESULT (client 105 -> server 120):
|
||||
- resolver detours 3/3 installed.
|
||||
- getaddrinfo(winter15.gosredirector.ea.com) -> redirect. Game now dials
|
||||
10.10.0.120 (was 20.51.153.159 before). DNS BLOCKER A = SOLVED.
|
||||
|
||||
REMAINING BLOCKER B (architectural, NOT DNS): FIFA 17 online = EA Blaze binary
|
||||
TCP. Game connects 10.10.0.120:42230 (gosredirector/Blaze redirector) ->
|
||||
wsa_err=10035 (nothing listening). Two gaps: (1) connect_hook remap set lacks
|
||||
42230; (2) even remapped, the Docker bridge only serves HTTPS on 8443 — no Blaze
|
||||
listener exists. Clearing Unable to connect requires a Blaze redirector+main
|
||||
server on the bridge side (real server build), not a hook change.
|
||||
NOTE: the 3s TLS-handshake-EOF spam in bridge logs on :8443 is the LAUNCHER health
|
||||
poller, not the game.
|
||||
|
||||
@@ -1,250 +0,0 @@
|
||||
# OpenFUT — Direction Document
|
||||
*The pivot: FUT lives in the app; FIFA 23 is the match renderer.*
|
||||
*Supersedes the Blaze-backend approach as the primary plan. Last updated 2026-06-30.*
|
||||
|
||||
---
|
||||
|
||||
## 1. Goal (revised)
|
||||
|
||||
Deliver an **intuitive way to play a FUT-style experience with FIFA 23**, where:
|
||||
|
||||
- The entire **FUT experience** — cards, squads, packs, SBCs, coins, chemistry,
|
||||
progression — lives in a **custom app** (web UI or desktop) built on the
|
||||
already-complete OpenFUT Core economy backend.
|
||||
- **FIFA 23 is demoted to a match renderer.** Its only job is to play a
|
||||
single-player match using the squad the app built. No FUT mode, no online, no
|
||||
Blaze, no EA servers.
|
||||
|
||||
This deliberately drops in-game FUT cards/UI (they live in the app) in exchange
|
||||
for a project that **converges** instead of being gated behind months of
|
||||
backend reverse-engineering.
|
||||
|
||||
### Why this replaces the backend plan
|
||||
|
||||
The status review confirmed the backend route (faking EA's online stack) is
|
||||
blocked at an upstream in-process EbisuSDK gate, with Blaze/Fire2 unconfirmed
|
||||
beyond it — realistically 3–6 months of expert RE that may not converge. The
|
||||
app-centric route sidesteps **every** wall in that review by never making FIFA's
|
||||
own FUT mode run.
|
||||
|
||||
---
|
||||
|
||||
## 2. Base mode: Career, not Kick-Off
|
||||
|
||||
**Career mode is the base.** Reasons:
|
||||
|
||||
- FLE's live-editing API (`EditDBTableField`, Freeze Lineup) is **confirmed to
|
||||
work in career mode** and explicitly does NOT work in FUT/online modes.
|
||||
- Career already provides the FUT-shaped scaffolding we'd otherwise fake:
|
||||
persistent club, a fixture schedule, recorded results, progression across a
|
||||
season.
|
||||
- **Match results are written into the career DB**, making result capture a DB
|
||||
read rather than a fragile live-memory grab.
|
||||
|
||||
**Kick-Off is the prototype sandbox.** Use it first to prove squad injection
|
||||
works with nothing to corrupt (no save to break), then move the real loop onto
|
||||
career. Run the foundational injection test in BOTH.
|
||||
|
||||
---
|
||||
|
||||
## 3. Core architecture: the bidirectional FLE bridge
|
||||
|
||||
The backbone is a **bidirectional channel between the app and a resident FLE Lua
|
||||
script running inside the game.** Everything else is messages over this channel.
|
||||
|
||||
```
|
||||
Custom App (FUT experience)
|
||||
│ squad push ──────────────► ┌─────────────────────────────┐
|
||||
│ │ Resident FLE Lua script │
|
||||
│ ◄────────── game state │ (inside FIFA 23, career) │
|
||||
│ ◄────────── match result │ - reads game state │
|
||||
└────────────────────────────► │ - applies squad live │
|
||||
(file-watch or local socket) │ - reads results from DB │
|
||||
└─────────────────────────────┘
|
||||
│
|
||||
FIFA 23 plays the match
|
||||
```
|
||||
|
||||
Three message types over the bridge:
|
||||
|
||||
1. **App → Game: squad push.** The app's chosen XI + stats applied LIVE via
|
||||
`EditDBTableField`, replicating whatever DB write FLE's "Freeze Lineup"
|
||||
feature performs (see `docs/foundational-xi-injection-test.md` — the exact
|
||||
field(s) are found by diffing, not assumed). No restart, no
|
||||
file-copy-reload. (File-load remains a fallback.)
|
||||
|
||||
2. **Game → App: game state.** The resident script polls the game's current
|
||||
screen/menu state and reports "safe to apply" vs "not safe", driving a smart
|
||||
Apply button in the app (see §5).
|
||||
|
||||
3. **Game → App: match result.** After full-time, the script reads the result
|
||||
from the career DB and pushes score/scorers to the app, which awards
|
||||
coins/progression. (Manual entry is the baseline fallback.)
|
||||
|
||||
The bridge transport can be a watched file the in-game Lua polls, or a local
|
||||
socket — decided in build (see §7). Either way the *game keeps running*; a file,
|
||||
if used, is just the message channel, not a reload.
|
||||
|
||||
---
|
||||
|
||||
## 4. Tiered mod scope
|
||||
|
||||
Build in tiers matched to risk. The core tier is all the SAME kind of DB write,
|
||||
so it lands together once squad injection works.
|
||||
|
||||
### Tier 1 — Core writes (ride the same live DB-edit mechanism)
|
||||
- **Squad / custom XI** — the load-bearing primitive (Freeze Lineup's
|
||||
underlying write, replicated via script — see §6).
|
||||
- **Player stats as "cards"** — card tiers, in-form versions, SBC upgrades all
|
||||
expressed as written attribute values.
|
||||
- **Chemistry as stat adjustment** — app computes FUT chemistry, applies it as
|
||||
small stat bumps when writing players in (no in-game chem UI; that's in the app).
|
||||
- **Appearance / identity** — kits, names, team assignment, so the club looks
|
||||
like your club on the pitch.
|
||||
- **Formation / tactics** — squad structure carries the app's build onto the pitch.
|
||||
|
||||
### Tier 2 — Confirm-then-add
|
||||
- **Match difficulty per game** — to drive a Squad-Battles-style "this opponent is
|
||||
World Class". Settable in-game trivially; programmatic drive needs confirming.
|
||||
- **Match rules / modifiers** (half length, etc.) — for app-defined challenges.
|
||||
|
||||
### Tier 3 — Result capture (manual baseline + automated stretch)
|
||||
- **Manual:** user enters the score in the app after the match. Zero RE, ships
|
||||
first.
|
||||
- **Automated:** resident script reads the career-DB result (or, for Kick-Off,
|
||||
reads the in-match score from memory at full-time — precedent exists: the
|
||||
CM cheat table's `export_season_stats.lua` already reads goals/cards from
|
||||
memory via known offsets). Push to app → auto-award progression.
|
||||
|
||||
### Out of scope (stays in the app, by design)
|
||||
- In-game FUT cards, FUT menus, pack-opening animation, chemistry board, FUT
|
||||
presentation. The app is where it looks/feels like FUT.
|
||||
|
||||
---
|
||||
|
||||
## 5. The smart Apply button (state-aware)
|
||||
|
||||
Live DB edits only "stick" in safe menu states (the in-game "Edit Player" screen,
|
||||
for example, overwrites edits). So the bridge reads game state and gates applying:
|
||||
|
||||
- Resident Lua script polls the game's current-screen value (a few Hz),
|
||||
classifies **safe / not safe**, reports to the app.
|
||||
- App's **Apply button is enabled only when the script confirms a safe state**
|
||||
(squad hub, main menu); greyed otherwise.
|
||||
- **Safe-by-default-OFF:** unknown state → button greyed → never a risky write.
|
||||
Expand the known-safe list incrementally as states are confirmed.
|
||||
- **v2 (more seamless):** instead of greying, the app always lets you click and
|
||||
the script **queues** the apply, executing the moment a safe state is entered,
|
||||
then confirms back. Greying is v1; queue-and-apply is v2.
|
||||
|
||||
`IsInCM()` is a confirmed state-read; the specific screen-state address + the
|
||||
value→screen mapping is one-time reconnaissance (same technique as result reading).
|
||||
|
||||
---
|
||||
|
||||
## 6. What's confirmed vs what needs validating
|
||||
|
||||
**Confirmed (from FLE's own Lua API docs/wiki, checked 2026-06-30):**
|
||||
- FLE live-edits the running career DB without restart, via `EditDBTableField`
|
||||
(real signature: `EditDBTableField(cell)` where `cell = row["fieldname"]`
|
||||
with `.value` mutated first — not the table/index/field/value form an
|
||||
earlier draft of this doc assumed).
|
||||
- FLE reads game state via `IsInCM()`.
|
||||
- A `MEMORY` Lua class exists (`ReadInt`/`WriteInt`/`ReadMultilevelPointer`/
|
||||
etc.) for arbitrary process memory — confirms the result-reading fallback
|
||||
in §4 Tier 3 is a real, documented capability, not just cheat-table analogy.
|
||||
- `GetPlayersStats()` is a documented function returning per-player
|
||||
goals/assists/cards/etc. — a better confirmed path for match-result capture
|
||||
than raw memory offsets.
|
||||
- **Freeze Lineup** (Formation Editor → arrange XI → tick "Freeze Lineup" →
|
||||
`Data → Save`) is FLE's actual documented mechanism for forcing a starting
|
||||
XI in career mode. This **replaces** "selection bias" below.
|
||||
- OpenFUT Core (economy) is complete and tested.
|
||||
|
||||
**Walked back — not actually confirmed:**
|
||||
- "Selection bias forces specific players into the starting XI" — no such
|
||||
field appears anywhere in FLE's documented Lua API or its own example
|
||||
scripts. This was an unverified assumption carried over from general FIFA
|
||||
modding precedent (other titles), not anything checked against FLE/FIFA 23.
|
||||
See `docs/foundational-xi-injection-test.md` for the corrected plan, which
|
||||
uses Freeze Lineup instead.
|
||||
|
||||
**Needs validating (the foundational tests — see §7):**
|
||||
- Whether Freeze Lineup actually holds into a played match (FLE's wiki
|
||||
documents the feature but not a live-match test of it).
|
||||
- What DB table/field Freeze Lineup's `Data → Save` actually writes — it's
|
||||
GUI-only and undocumented at that level; finding it is part of the
|
||||
foundational test.
|
||||
- Whether that write can be replicated by a script (`EditDBTableField`) well
|
||||
enough to drive it from an EXTERNAL trigger, not just the Formation Editor
|
||||
UI — required for the app↔game bridge.
|
||||
- The app↔game bridge transport (file-watch vs socket) works cleanly under the
|
||||
run setup.
|
||||
- The screen-state address + safe/not-safe classification (FLE's `Events`
|
||||
API page exists in the wiki index but its content is currently empty/
|
||||
undocumented — this is more open than previously assumed).
|
||||
- Result read-back from the career DB after a match.
|
||||
|
||||
**Standing caveat:** the whole stack rides on **EAAC staying neutralized**
|
||||
(FLE's fake-launcher bypass). If a game update re-enables it, hooks fail. Keep
|
||||
game updates off; confirm neutralized state each session.
|
||||
|
||||
---
|
||||
|
||||
## 7. Build order / next steps
|
||||
|
||||
Each is a bounded, verifiable step. Do them in order; later ones depend on
|
||||
earlier answers.
|
||||
|
||||
1. **FOUNDATIONAL TEST — live custom XI in career.** Confirm Freeze Lineup
|
||||
holds into a played match, reverse-engineer the DB write it makes, then
|
||||
replicate that write from a script so it can be triggered externally
|
||||
instead of through the Formation Editor UI. See
|
||||
`docs/foundational-xi-injection-test.md` for the full procedure. *Done =
|
||||
a script-driven write produces a match that fields the squad you
|
||||
specified.* Everything rests on this.
|
||||
|
||||
2. **Pick the bridge transport.** Decide file-watch vs local socket for app↔game
|
||||
messaging; implement the minimal app→game squad push. *Done = app sends a
|
||||
squad, the resident script receives and applies it.*
|
||||
|
||||
3. **Game-state reader + smart Apply.** Find the screen-state address, classify
|
||||
safe/not-safe, expose to the app, gate the Apply button. *Done = button greys
|
||||
when you enter a match/edit screen, enables in the squad hub.*
|
||||
|
||||
4. **Result read-back.** Read the career-DB match result post-game, push to app,
|
||||
award progression. Manual entry ships alongside as the fallback. *Done = app
|
||||
updates coins from a played match.*
|
||||
|
||||
5. **Tier 1 breadth.** Extend the squad push to carry stats, appearance,
|
||||
formation (same write mechanism). *Done = the club looks and plays like the
|
||||
app's build.*
|
||||
|
||||
6. **Tier 2 + economy loop polish.** Difficulty drive, challenges, and the full
|
||||
pack → SBC → squad → match → reward loop closed end-to-end.
|
||||
|
||||
### Decision still open
|
||||
- **App form factor:** web UI vs desktop app. This affects the bridge transport
|
||||
(a desktop app can hold a local socket more naturally; a web UI leans toward a
|
||||
small local helper/file-watch). Decide before step 2.
|
||||
|
||||
---
|
||||
|
||||
## 8. Provenance
|
||||
|
||||
Clean-room throughout. This route relies on FLE's documented public API and the
|
||||
game's own supported career mode — no EA backend, no Blaze, and nothing derived
|
||||
from leaked EA source. The earlier backend RE remains clean-room and is preserved
|
||||
as a spec artifact; it is simply no longer the primary path.
|
||||
|
||||
---
|
||||
|
||||
## 9. One-paragraph summary
|
||||
|
||||
OpenFUT becomes a **FUT companion app that uses FIFA 23 as a match engine.** The
|
||||
app owns the entire FUT experience; a resident FLE Lua script in career mode
|
||||
applies the app's squad live (no restart), reports game state to drive a safe
|
||||
Apply button, and reads match results back to feed progression. This sidesteps
|
||||
every backend wall, runs on confirmed FLE capabilities, builds on the finished
|
||||
economy core, and delivers the intuitive, offline, FUT-flavored loop that is the
|
||||
actual goal.
|
||||
@@ -1,108 +0,0 @@
|
||||
# FIFA 23 PC Startup Flow (Offline / Proton)
|
||||
|
||||
Observed via FLE log, hook log, and file inspection on 2026-06-26.
|
||||
|
||||
## Launch chain
|
||||
|
||||
```
|
||||
umu-run / Steam → FIFA23.exe (via Proton/Wine)
|
||||
│
|
||||
├─ DLL load order (before entry point)
|
||||
│ ntdll.dll, kernel32.dll, ws2_32.dll …
|
||||
│ version.dll ← our hook DLL slot (loads here)
|
||||
│ FIFALiveEditor.DLL ← injected by FLE launcher after ~100 ms
|
||||
│
|
||||
├─ anadius / LSX emulator (anadius64.dll)
|
||||
│ Fakes EA App / Origin session
|
||||
│ Reads HKLM\SOFTWARE\Wow6432Node\Origin\ClientPath
|
||||
│ Writes AppData\Local\anadius\LSX emu\achievement-*.xml
|
||||
│ Provides fake PersonaId=1144668899 / UserId=1000200030000
|
||||
│
|
||||
├─ EA Anti-Cheat (EAAntiCheat.GameServiceLauncher.exe)
|
||||
│ Spawns as child; checks EAAntiCheat.cfg
|
||||
│ Not active in offline/cracked builds (FakeEAACLauncher present)
|
||||
│
|
||||
└─ FIFA23.exe entry point
|
||||
Frostbite engine init (BuildDate 2023-07-05, changelist 5417699)
|
||||
Reads Data\initfs_Win32 ← Frostbite package manifest
|
||||
Reads Data\layout.toc ← file-system layout
|
||||
Reads Patch\initfs_Win32 ← patches on top of base
|
||||
Reads Documents\FIFA 23\fifasetup.ini ← display settings
|
||||
Reads Data\locale.ini ← language table
|
||||
Reads Data\db_meta.xml (via FLE) ← DB schema for all tables
|
||||
```
|
||||
|
||||
## Phase timing (observed, single machine)
|
||||
|
||||
| Phase | Time after launch | Trigger |
|
||||
|------------------------------|-------------------|----------------------------------|
|
||||
| DLL load + FLE injection | 0 – 0.3 s | OS loader |
|
||||
| Engine + DirectX init | 0.3 – 5 s | FIFA23 entry point |
|
||||
| "Press any key" splash | ~5 s | First rendered frame |
|
||||
| Main menu | ~25 s | After key press |
|
||||
| FUT mode entry (attempted) | user-driven | User selects FUT tile |
|
||||
| Network calls to EA services | at FUT entry | DirtySDK / EAWebKit |
|
||||
|
||||
## Files read at startup (observed)
|
||||
|
||||
| File | Format | Purpose |
|
||||
|------|--------|---------|
|
||||
| `Data/initfs_Win32` | Frostbite pkg | Base asset manifest |
|
||||
| `Data/layout.toc` | Frostbite TOC | File layout index |
|
||||
| `Patch/initfs_Win32` | Frostbite pkg | Patch layer |
|
||||
| `Data/locale.ini` | INI | String localisation |
|
||||
| `Data/db_meta.xml` | XML | DB schema (loaded by FLE) |
|
||||
| `Data/id_map.json` | JSON | Player/team ID→name map |
|
||||
| `Data/char_conv.json` | JSON | Character conversion table |
|
||||
| `Documents/FIFA 23/fifasetup.ini` | INI | Display/audio settings |
|
||||
| `AppData/Local/Temp/FIFA 23/_replay0.bin` | binary | Replay buffer |
|
||||
| `anadius.cfg` | VDF | Fake EA persona config |
|
||||
| `AppData/Local/anadius/LSX emu/achievement-*.xml` | XML | Achievement state |
|
||||
|
||||
## Files written during a session (observed)
|
||||
|
||||
| File | When written | Content |
|
||||
|------|-------------|---------|
|
||||
| `Documents/FIFA 23/settings/Settings*` | Main menu reached | FBCHUNKS — controller/display prefs |
|
||||
| `Documents/FIFA 23/settings/ProfileOptions` | Profile load | FBCHUNKS — 1.5 MB profile blob |
|
||||
| `Documents/FIFA 23/filesystemcache/survey.state` | Startup | Empty state file |
|
||||
| `Documents/FIFA 23/filesystemcache/atlPlayTimeJson/playtime_*.json` | Ongoing | Playtime tracking |
|
||||
| `FIFA 23 Live Editor/config.json` | FLE ready | FLE settings (rewritten each session) |
|
||||
| `Logs/log_DD-MM-YYYY.txt` | Throughout | FLE debug log |
|
||||
|
||||
## Save file formats
|
||||
|
||||
### FBCHUNKS (Frostbite chunk container)
|
||||
- Magic: `46 42 43 48 55 4E 4B 53` (`FBCHUNKS`)
|
||||
- Byte 8: version (01 seen)
|
||||
- Offset 0x12: null-terminated label string (e.g. "Personal Settings 1", "Career - Player Progress 1")
|
||||
- Remainder: compressed/binary chunk data — no public spec; requires Frostbite tooling to fully parse
|
||||
- Tools: [Frosty Tool Suite](https://github.com/CadeEvs/FrostyToolSuite) can read/write these
|
||||
|
||||
### fifasetup.ini
|
||||
- Plain `KEY = VALUE` ini, fully human-readable
|
||||
- Safe to edit (display resolution, locale, vsync)
|
||||
|
||||
## Network calls at FUT entry (observed with iptables redirect)
|
||||
|
||||
Traffic pattern captured before changing strategy:
|
||||
- Multiple TLS connections to port 443 (destination: EA servers, resolved as various EA IPs)
|
||||
- TLS 1.3, AES-256-GCM (DirtySDK's copy of ProtoSSL, inline in FIFA23.exe)
|
||||
- No SNI sent (DirtySDK does not set `server_name` extension)
|
||||
- Connections originate from Wine/Proton network stack via Linux kernel TCP
|
||||
|
||||
Specific EA hostnames used (from openfut-bridge captures, not decoded from TLS):
|
||||
- `fut.ea.com` (FUT API)
|
||||
- `accounts.ea.com` (auth)
|
||||
- `gateway.ea.com` (entitlements)
|
||||
- `pin-river.data.ea.com` (telemetry)
|
||||
|
||||
## Key FLE Lua API hooks
|
||||
|
||||
FLE injects `FIFALiveEditor.DLL` and exposes a Lua engine that can:
|
||||
- Read any in-memory DB table via `GetDBTableRows(tableName)`
|
||||
- Write any cell via `EditDBTableField`
|
||||
- Query career mode state via `IsInCM()`
|
||||
- Get player/team names via `GetPlayerName`, `GetTeamName`
|
||||
|
||||
This is the primary safe integration path (see `fut-integration-options.md`).
|
||||
@@ -1,191 +0,0 @@
|
||||
# Foundational test — live custom XI via Freeze Lineup
|
||||
|
||||
**Status: PENDING — test has not yet been run.**
|
||||
|
||||
This is build-order step 1 from `docs/direction.md`: the test everything else
|
||||
in the direction pivot depends on.
|
||||
|
||||
## What changed since the first draft of this doc
|
||||
|
||||
The first version of this test guessed at a "selection bias" DB field and a
|
||||
candidate squad/lineup table name, based on general FIFA-modding precedent
|
||||
that turned out not to hold for FLE's documented API — no such field appears
|
||||
anywhere in FLE's actual Lua API docs or its own example scripts. While
|
||||
researching an unrelated hotkey issue, a **confirmed, FLE-documented**
|
||||
mechanism for forcing a starting XI turned up instead: the **Formation
|
||||
Editor's "Freeze Lineup" feature** (FLE wiki, `Formation-Editor.md`):
|
||||
|
||||
> This feature can be used in player career mode if you want to manage the
|
||||
> starting lineup of your team. Can be also used in manager career mode to
|
||||
> manually manage your next opponent's starting lineup.
|
||||
|
||||
Steps (GUI, no scripting): open Formation Editor for a team → arrange players
|
||||
on the pitch → tick **Freeze Lineup** → `Data → Save`.
|
||||
|
||||
This is real and documented, but it's GUI-only — there is no Lua function for
|
||||
it, and what DB write it actually performs under the hood is undocumented.
|
||||
This test is now two phases: confirm the GUI feature works at all, then
|
||||
reverse the DB write it makes so it can be replicated programmatically
|
||||
(required for the app→game bridge in build-order step 2, which needs this
|
||||
driven from outside the game, not from a person clicking checkboxes).
|
||||
|
||||
Also fixed in this pass: `EditDBTableField`'s real signature, confirmed from
|
||||
FLE's own docs and `lua/scripts/99ovr_99pot.lua`, is
|
||||
`EditDBTableField(cell)` where `cell` is `row["fieldname"]` with `.value`
|
||||
mutated in place — **not** `EditDBTableField(table, row_index, field, value)`
|
||||
as originally (incorrectly) written into the first draft of the injector
|
||||
script.
|
||||
|
||||
## What this test settles
|
||||
|
||||
Whether a *specific, externally-chosen* 11 players can be forced into a
|
||||
career (or Kick-Off) match's starting lineup, live, with no restart — and
|
||||
whether the mechanism that does it (Freeze Lineup's underlying DB write) can
|
||||
be driven by a script instead of a person clicking through the Formation
|
||||
Editor UI.
|
||||
|
||||
If Freeze Lineup itself doesn't actually hold under match start (the wiki
|
||||
doesn't show it being tested against a live match, only "you should be able
|
||||
to see... when you play against them"), the whole bridge architecture in
|
||||
`docs/direction.md` §3 needs rethinking — there is no other documented
|
||||
mechanism for forcing a lineup.
|
||||
|
||||
## Prerequisites
|
||||
|
||||
- FIFA 23 launched normally (FLE injected, EAAC neutralized — same baseline
|
||||
as `track-c-fut-table-test.md`)
|
||||
- A career save loaded (Freeze Lineup is documented for career mode
|
||||
specifically — confirm separately whether it does anything in Kick-Off,
|
||||
don't assume it does)
|
||||
- Note 11 player IDs from your club (`tools/squad-exporter/export_squad.lua`
|
||||
output, `playerid` field) that are NOT currently your starting XI
|
||||
|
||||
## Phase 1 — confirm Freeze Lineup actually holds into a match
|
||||
|
||||
This has zero scripting and should be done first since everything else is
|
||||
wasted effort if it fails.
|
||||
|
||||
1. Open the Live Editor overlay (F9, or `Windows → Settings` from the
|
||||
overlay's own menu bar if the hotkey isn't registering — see the umu/Wine
|
||||
hotkey note below).
|
||||
2. `Features → Teams` → find your team → `Edit`.
|
||||
3. `Team → Formation` to open the Formation Editor.
|
||||
4. Swap players around on the pitch so the XI differs from your current
|
||||
actual starting XI in some checkable way (e.g. swap two outfield players'
|
||||
positions, or bench/start a specific player).
|
||||
5. Tick **Freeze Lineup**.
|
||||
6. `Data → Save`.
|
||||
7. Hide Live Editor (F9), save your career **on a new slot** (don't overwrite
|
||||
your main save in case this corrupts something), exit to main menu, reload
|
||||
that save, and check the team's lineup screen / play a match and watch who
|
||||
starts.
|
||||
|
||||
**Record in the Results table below whether the frozen lineup actually took
|
||||
the pitch.** If not, stop here — Phase 2 is moot.
|
||||
|
||||
## Phase 2 — find the underlying DB write
|
||||
|
||||
Only proceed if Phase 1 confirmed Freeze Lineup works.
|
||||
|
||||
1. In FLE's Lua Engine, run `tools/squad-injector/snapshot_lineup_tables.lua`.
|
||||
This dumps every DB table whose name contains `squad`, `lineup`,
|
||||
`formation`, `tactic`, `teamsheet`, `selection`, `players`, or `teams` to
|
||||
`C:\FIFA 23 Live Editor\openfut_snapshot_<timestamp>.json`. Note this
|
||||
filename — this is your **before** snapshot.
|
||||
2. Without restarting or reloading, repeat the Formation Editor steps from
|
||||
Phase 1 (steps 2–6 only — open Formation Editor, change the lineup, tick
|
||||
Freeze Lineup, `Data → Save`). Don't save/reload the career between
|
||||
snapshot and this step — keep it to a single live session so the diff
|
||||
isn't polluted by other state changes.
|
||||
3. Run `snapshot_lineup_tables.lua` again. This is your **after** snapshot.
|
||||
4. Copy both JSON files out of the Wine prefix (same path pattern as
|
||||
`track-c-fut-table-test.md`: `~/Games/umu/.../drive_c/FIFA 23 Live
|
||||
Editor/`) and run:
|
||||
|
||||
```bash
|
||||
python3 tools/squad-injector/diff_snapshots.py before.json after.json
|
||||
```
|
||||
|
||||
5. The output shows exactly which table(s) and field(s) changed. This is the
|
||||
real, confirmed write Freeze Lineup performs — record it in the Results
|
||||
table below.
|
||||
|
||||
## Phase 3 — replicate the write via script
|
||||
|
||||
1. Open `tools/squad-injector/apply_lineup_write.lua` and fill in
|
||||
`TARGET_TABLE` and `TARGET_FIELDS` using Phase 2's diff output.
|
||||
2. Edit `C:\FIFA 23 Live Editor\openfut_test_xi.json`:
|
||||
|
||||
```json
|
||||
{
|
||||
"team_id": 12345,
|
||||
"xi": [
|
||||
{ "player_id": 111111, "position": 0 },
|
||||
{ "player_id": 222222, "position": 5 }
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
Use 11 entries. Position codes are **confirmed numeric 0–27**
|
||||
(`GK=0, SW=1, RWB=2, RB=3, RCB=4, CB=5, LCB=6, LB=7, LWB=8, RDM=9, CDM=10,
|
||||
LDM=11, RM=12, RCM=13, CM=14, LCM=15, LM=16, RAM=17, CAM=18, LAM=19,
|
||||
RF=20, CF=21, LF=22, RW=23, RS=24, ST=25, LS=26, LW=27`) — from
|
||||
`lua/scripts/export_season_stats.lua`'s `get_pos_name` table in FLE's own
|
||||
repo, not a guess.
|
||||
3. Run `apply_lineup_write.lua` from FLE's Lua Engine.
|
||||
4. Repeat the save-to-new-slot / reload / check-lineup verification from
|
||||
Phase 1, but this time without ever opening the Formation Editor — the
|
||||
write was made entirely from the script.
|
||||
|
||||
## Classification criteria
|
||||
|
||||
### "Confirmed — full mechanism works"
|
||||
|
||||
Phase 1 holds, Phase 2 finds a clean diff, Phase 3's scripted write produces
|
||||
the same in-match result as the manual GUI path.
|
||||
|
||||
**Verdict:** Build-order step 1 done. Proceed to step 2 (bridge transport) in
|
||||
`docs/direction.md`.
|
||||
|
||||
### "GUI works, script doesn't"
|
||||
|
||||
Phase 1 holds but Phase 3's replicated write doesn't stick, even though the
|
||||
diffed fields matched what changed in Phase 2.
|
||||
|
||||
**Verdict:** Freeze Lineup likely does more than a single DB field write
|
||||
(e.g. an internal engine call beyond `EditDBTableField`'s reach, or a second
|
||||
write the diff missed because it happened in a table outside the `KEYWORDS`
|
||||
filter in `snapshot_lineup_tables.lua` — widen the filter and redo Phase 2).
|
||||
|
||||
### "Freeze Lineup doesn't hold at all"
|
||||
|
||||
Phase 1 fails — the lineup reverts to the game's own AI-picked XI regardless.
|
||||
|
||||
**Verdict:** No confirmed mechanism exists for forcing a lineup. This kills
|
||||
the bridge architecture as designed in `direction.md` §3 and needs a return
|
||||
to first principles — there is no fallback documented anywhere in FLE's wiki
|
||||
for this specific case.
|
||||
|
||||
## A note on the umu/Wine F9/F11 hotkey issue
|
||||
|
||||
If FLE's F9 (hide/show) hotkey isn't registering under umu, this is plausibly
|
||||
a Wine keyboard-hook limitation (FLE's global hotkey detection likely uses a
|
||||
low-level hook that doesn't translate cleanly through Wine's input layer) —
|
||||
not something documented anywhere in FLE's own troubleshooting docs, which
|
||||
don't mention Linux/Wine at all. F11 specifically has **no documented FLE
|
||||
function** — F9 is the only documented toggle. Workaround: click directly
|
||||
into the FLE overlay window (it should still be visible/clickable even if the
|
||||
hotkey doesn't fire) and use its own menu bar instead of relying on the
|
||||
hotkey.
|
||||
|
||||
## Results
|
||||
|
||||
*(To be filled in after the test is run.)*
|
||||
|
||||
| Field | Value |
|
||||
|---|---|
|
||||
| Date run | — |
|
||||
| Phase 1: Freeze Lineup holds into a match? | — |
|
||||
| Phase 2: table(s)/field(s) changed | — |
|
||||
| Phase 3: scripted write reproduces Phase 1 result? | — |
|
||||
| **Classification** | **PENDING** |
|
||||
@@ -1,136 +0,0 @@
|
||||
# FUT Integration Options
|
||||
|
||||
How to connect FIFA 23 to the OpenFUT local simulator, ranked by safety and feasibility.
|
||||
|
||||
## Option A — FLE Lua scripting (RECOMMENDED)
|
||||
|
||||
**What it does:** Use FIFA Live Editor's in-memory Lua API to read and write the game's
|
||||
database tables at runtime. FLE is already injected; no additional hooking needed.
|
||||
|
||||
**Why it's the right path:**
|
||||
- Fully offline, no EA servers touched
|
||||
- FLE is already trusted by the user (it's the launch mechanism)
|
||||
- `GetDBTableRows` / `EditDBTableField` expose the full Frostbite DB in memory
|
||||
- Scripts run inside the game process; no IPC complexity
|
||||
- Same mechanism used by modders for career mode edits today
|
||||
|
||||
**Integration design:**
|
||||
|
||||
```
|
||||
openfut-core (SQLite)
|
||||
│
|
||||
│ HTTP REST (localhost)
|
||||
▼
|
||||
openfut-bridge (port 8080, plain HTTP, no TLS)
|
||||
│ pulls club/squad/player data as JSON
|
||||
▼
|
||||
FLE Lua bridge script
|
||||
│ calls GetDBTableRows, EditDBTableField
|
||||
▼
|
||||
FIFA 23 in-memory DB (Frostbite)
|
||||
```
|
||||
|
||||
The Lua script polls openfut-core's REST API at intervals (or on FUT menu entry)
|
||||
and writes simulator data (coins, items, squad) into the appropriate DB tables.
|
||||
|
||||
**Tables likely involved (to verify with export_squad.lua):**
|
||||
|
||||
| Table | Expected FUT content |
|
||||
|-------|---------------------|
|
||||
| `players` | Player attributes (OVR, potential, stats) |
|
||||
| `teams` | Club identity, stadium, colors |
|
||||
| `fut_clubs` | FUT club record (if in memory when FUT loads) |
|
||||
| `fut_items` | Card inventory (if in memory) |
|
||||
| `fut_squads` | Active squad (if in memory) |
|
||||
|
||||
**Steps to implement:**
|
||||
1. Run `tools/squad-exporter/export_squad.lua` from FLE Lua Engine while in FUT to discover which tables are live
|
||||
2. Map openfut-core's data model to the discovered table fields
|
||||
3. Write a Lua polling script that fetches `/api/v1/club`, `/api/v1/squad`, etc. from openfut-core and calls `EditDBTableField` to populate them
|
||||
4. Optionally add a small HTTP client to the Lua script using LuaSocket (FLE ships with Lua 5.4)
|
||||
|
||||
**Limitations:**
|
||||
- Changes are in-memory only; they reset on game restart (acceptable for a simulator)
|
||||
- Only works while FLE is running (always true in our setup)
|
||||
- FUT tables may only be populated when the FUT hub is loaded; test with the exporter
|
||||
|
||||
---
|
||||
|
||||
## Option B — Local save file injection (career mode proxy)
|
||||
|
||||
**What it does:** Generate or modify offline career mode save files that contain FUT-like
|
||||
squad/player data, using Frostbite's FBCHUNKS format.
|
||||
|
||||
**Feasibility:** Medium
|
||||
- FBCHUNKS format is not publicly documented but has been partially reverse-engineered by the Frosty Tool Suite project
|
||||
- Career saves are 16 MB — large and complex
|
||||
- Changes take effect only after a game restart
|
||||
|
||||
**Best use:** Pre-populating a career club with the same players as the FUT simulator squad, so offline Squad Battles use "your" players.
|
||||
|
||||
**Steps:**
|
||||
1. Use Frosty Tool Suite to open a career save and map the schema
|
||||
2. Build a Python exporter that writes a valid FBCHUNKS save with simulator squad data
|
||||
3. Test: replace the career save, launch FIFA, verify squad is correct
|
||||
|
||||
---
|
||||
|
||||
## Option C — Local companion web UI
|
||||
|
||||
**What it does:** The user manages their FUT simulator entirely in a web browser (openfut-core already has this). A button exports the current squad/club state to a format that a Lua script or file injector can consume.
|
||||
|
||||
**This is already implemented** — openfut-core serves the FUT simulator REST API. The missing piece is the Lua bridge script (Option A) that reads from it.
|
||||
|
||||
---
|
||||
|
||||
## Option D — Local proxy for non-secured local calls only
|
||||
|
||||
**What it does:** Intercept FIFA 23's calls to `localhost:*` or a known local endpoint (not EA servers) and respond with simulator data.
|
||||
|
||||
**Feasibility:** Low value in isolation
|
||||
- FIFA 23 does not make calls to localhost in normal operation (except EA App on port 10853)
|
||||
- All FUT API calls go to EA's servers over TLS
|
||||
- Intercepting those would require the approach we explicitly ruled out
|
||||
|
||||
**Not recommended as a primary path.** Could be combined with Option A if the Lua script exposes a local socket that a coordinator process writes to.
|
||||
|
||||
---
|
||||
|
||||
## Option E — Memory bridge (Cheat Engine / FLE offsets)
|
||||
|
||||
**What it does:** Use known memory offsets (FLE's `offset_cache.json`) to read/write FUT state directly in FIFA23.exe's heap.
|
||||
|
||||
**Feasibility:** Medium — FLE already does this for career mode
|
||||
- FLE's `offset_cache.json` contains addresses for many game structures
|
||||
- FUT in-memory structs are separate from career structs and may not be mapped yet
|
||||
- This is fragile (offsets change with game updates)
|
||||
|
||||
**Not recommended** unless Options A and B both fail — too brittle.
|
||||
|
||||
---
|
||||
|
||||
## Recommendation
|
||||
|
||||
**Start with Option A (FLE Lua scripting).**
|
||||
|
||||
1. Run `tools/squad-exporter/export_squad.lua` in-game to discover which DB tables exist in FUT mode
|
||||
2. Use `tools/file-watch-diff/watch.sh` to snapshot file state entering FUT and identify any new local files
|
||||
3. Use `tools/network-metadata-logger/netlog.sh` to log which EA hosts FIFA contacts at FUT entry (metadata only, no decryption)
|
||||
4. Map findings back to openfut-core's data model
|
||||
5. Implement the Lua bridge script that calls openfut-core's REST API and writes to discovered tables
|
||||
|
||||
If FUT tables are not exposed by FLE's DB API (they may not be — FUT data lives server-side in online mode), fall back to **Option B** (career save injection) to provide a squad that mirrors the simulator's club.
|
||||
|
||||
---
|
||||
|
||||
## Safety boundary
|
||||
|
||||
The following are out of scope and must not be implemented:
|
||||
|
||||
- Decrypting or inspecting EA's TLS traffic
|
||||
- Spoofing EA domain names or impersonating EA servers
|
||||
- Sending modified clients to EA's production services
|
||||
- Bypassing EA App login or account verification
|
||||
- Anything that could constitute online cheating or violate EA's ToS for online play
|
||||
|
||||
All integration must remain local/offline/single-player.
|
||||
@@ -1,208 +0,0 @@
|
||||
# OpenFUT Status Review
|
||||
*Generated 2026-06-30 — read-only stocktake, no code changed.*
|
||||
|
||||
---
|
||||
|
||||
## Executive Summary
|
||||
|
||||
OpenFUT has a mature offline FUT economy backend (Core, 25 phases, fully functional in
|
||||
isolation) and a sophisticated hook DLL that loads into FIFA 23, redirects EA hostnames
|
||||
to loopback, and bypasses TLS certificate verification. The Blaze/ProtoSSL layer is
|
||||
structurally ready: framing code exists, a TLS listener runs, cert-verify is patched.
|
||||
However the project is currently blocked before any Blaze traffic is ever seen.
|
||||
The fundamental problem is that FIFA 23 submits `GoOnline` to EbisuSDK and then
|
||||
**waits for an asynchronous ONLINE_STATUS_EVENT push** from the EA-app LSX server —
|
||||
a push that current code never sends. Every approach tried so far (flipping poll
|
||||
return values, forcing the state flags, read-only probes) confirms the gate is
|
||||
event-driven, not poll-driven. The Blaze captures directory contains six empty files.
|
||||
No Fire2 frame from FIFA 23 has ever been decoded. Until the ONLINE_STATUS_EVENT push
|
||||
is synthesized and delivered correctly, Milestones 2–7 are all waiting on the same
|
||||
single wall.
|
||||
|
||||
---
|
||||
|
||||
## 1. Proven vs Assumed
|
||||
|
||||
| Claim | Status | Evidence |
|
||||
|---|---|---|
|
||||
| FIFA 23 uses DirtySDK / ProtoSSL | **Proven** | String scan hit `ProtoSSLSend`, `ProtoSSLRecv`, `gosredirector` in FIFA23.exe memory (Task 1) |
|
||||
| `version.dll` loads and runs hook code | **Proven** | `hook.log` written at DLL_PROCESS_ATTACH |
|
||||
| `getaddrinfo` IAT hook redirects EA domains to loopback | **Proven** | Hook log records every EA `getaddrinfo` call; connect_hook log confirms port redirects |
|
||||
| ProtoSSL cert-verify prologue found and patched (FIFA23.exe) | **Proven** | ssl_patch.rs prologue confirmed at file offset 0xf0c850; hook log "ssl: main exe cert-verify patched" |
|
||||
| ProtoSSL cert-verify patched in EAWebKit.dll | **Proven** (if loaded) | Lazy patch fires on first EA getaddrinfo call; hook log message confirms |
|
||||
| Gate is upstream of DirtySDK — no DNS/connect fires on FUT entry | **Proven** | getaddrinfo, connect, WSASend/Recv hooks all show zero external traffic during "connecting to EA Servers" |
|
||||
| `GoOnline` is called by the game | **Proven** | Read-only detour on `anadius64.dll+0x2BB90` confirmed hit |
|
||||
| anadius returns GoOnline success | **Proven** | Handler observed returning successfully; game still retries every ~7 s |
|
||||
| Gate is downstream of GoOnline | **Proven** | GoOnline called + returns success; no Blaze connect follows |
|
||||
| Connection-state function: `GetInternetConnectedState @ anadius64.dll+0x27790` | **Proven** | Located via anadius LSX command-registration table; two-flag branch decoded (`+0xCAB1A`, `+0xCAB1B`) |
|
||||
| Gate is event-driven (game waits for async push, not a poll return) | **Proven** | Forced both state flags AND GoOnline return to "1"; game kept retrying; worker-thread stack scan confirms handler runs on anadius IOCP thread, not FIFA's thread |
|
||||
| GoOnline runs on anadius worker thread, not FIFA's call thread | **Proven** | Stack scan from inside detour found zero FIFA23.exe frames, sp ~2.4 KB from thread stack top |
|
||||
| `protossl-scan` live toolkit is exhausted for finding GoOnline in FIFA23.exe | **Proven** | No `"GoOnline"` string in image; worker-thread call stack has no FIFA frames; jmpscan yields ~3875 hits (overwhelmingly data false positives) |
|
||||
| FIFA 23 redirector config references `Authorization:` header (Nucleus token) | **Proven** | Found in FIFA23.exe .rdata pointer table @ `+0x83FC858` |
|
||||
| openfut-core REST API complete and tested | **Proven** | 25 phases, 15 migrations, passing integration tests |
|
||||
| Bridge LSX server starts and handles request-response | **Proven** (code) | `openfut-bridge/src/lsx.rs` + `main.rs` — server starts on 127.0.0.1:3216 |
|
||||
| Bridge LSX server ACTUALLY receives FIFA's LSX connections | **UNCONFIRMED** | anadius may intercept the same calls in-process before the TCP connection reaches the bridge |
|
||||
| Bridge LSX server `GetInternetConnectedState → connected="1"` unblocks the gate | **UNCONFIRMED (known to fail in-process)** | Flipping the value via anadius in-process failed; bridge path not yet confirmed working |
|
||||
| ONLINE_STATUS_EVENT push XML format | **UNKNOWN** | No capture; format not derived |
|
||||
| Fire2 framing is correct for FIFA 23 | **UNCONFIRMED** | Implemented based on post-2012 EA convention; all blaze captures are empty (0 bytes) |
|
||||
| Blaze component / command IDs for FIFA 23 | **UNKNOWN** | Zero captures; dispatch table entirely empty placeholders |
|
||||
| ProtoSSL recv-injection convention (non-blocking return values etc.) | **UNCONFIRMED** | Never reached M4; recv_hook module removed from active install path |
|
||||
| FUT REST endpoint paths in mapper.rs | **SPECULATIVE** | Based on community knowledge of older FIFA titles; the one actual capture in `captures/` is an early GET from before the Blaze strategy |
|
||||
| FLE Lua API exposes FUT DB tables in memory | **UNKNOWN** | `export_squad.lua` has never been run; FUT data may only exist server-side in online mode |
|
||||
|
||||
---
|
||||
|
||||
## 2. Milestone Status
|
||||
|
||||
| Milestone | Status | Blocker | Depends on unconfirmed assumption? |
|
||||
|---|---|---|---|
|
||||
| **M1** — Locate connection-state decision point | ✅ Done | — | No |
|
||||
| **M2** — Flip gate, force "connected" | ⛔ Blocked | Game waits for async ONLINE_STATUS_EVENT push; no current code sends it | Yes — unknown event XML format |
|
||||
| **M3** — First ProtoSSL plaintext on Blaze connection | 🔲 Not started | Depends on M2 | Yes — Fire2 framing unconfirmed |
|
||||
| **M4** — Answer redirector + decode first Fire2 frame | 🔲 Not started | Hard wall: Fire2 framing, recv-injection convention, component/command IDs all unconfirmed | Yes — all three unknown |
|
||||
| **M5** — Blaze preauth / login / postauth | 🔲 Not started | Depends on M4 | Yes — Blaze auth TDF body layout unknown |
|
||||
| **M6** — FUT entry + hub load | 🔲 Not started | Depends on M5; also requires FUT REST response shapes confirmed | Yes — endpoint paths speculative |
|
||||
| **M7** — Squad Battles (AI FUT) | 🔲 Not started | Depends on M6 | Yes |
|
||||
|
||||
**Note on roadmap.md wording:** Under M2–M4, roadmap.md uses `**Done (observable):**` bullets. These describe the *success criterion* for each milestone, not an achieved state. The authoritative status is in `connection-gate-findings.md` (M2 attempts failed; M3/M4 never started). The roadmap has not been updated to reflect M2 failure.
|
||||
|
||||
### M4 is the first hard wall in detail
|
||||
|
||||
Even assuming M2 is solved, M4 requires three unconfirmed things simultaneously:
|
||||
1. **Fire2 framing** — the 12-byte header layout is assumed; if FIFA 23 uses an older Fire variant or a custom delta, the codec will misparse every packet.
|
||||
2. **ProtoSSL recv-injection** — delivering responses to the game via recv hook requires knowing what return values and buffer conventions ProtoSSL expects; recv_hook.rs exists but is not installed.
|
||||
3. **Blaze component/command IDs** — the dispatch table is entirely empty; we cannot answer any request until IDs are known from captures.
|
||||
|
||||
All three are resolved by getting one real captured frame. M4 is primarily a capture problem, not a decoding problem — once bytes exist, the framing and IDs are immediately readable.
|
||||
|
||||
---
|
||||
|
||||
## 3. Blockers, Risks, Unknowns
|
||||
|
||||
### Blockers (stop progress now)
|
||||
|
||||
1. **ONLINE_STATUS_EVENT push not synthesized** *(M2 wall)*
|
||||
The game calls GoOnline, gets success, then waits indefinitely for a push event on the LSX socket that never arrives. This is the single gate blocking all Blaze work. Options: (a) trace the event format via Ghidra on FIFA23.exe (xref `ONLINE_STATUS_EVENT` string + the game's EbisuSDK listener), (b) RE anadius's LSX event-send path (find what it would push in an "online" scenario), (c) brute-force push candidate event XMLs and observe whether the game advances.
|
||||
|
||||
2. **Bridge LSX server delivery unconfirmed** *(architectural risk converted to blocker)*
|
||||
The hook passes port 3216 connections through, assuming the bridge LSX server on the Linux host receives them. If anadius's in-process hooks intercept the winsock calls before they reach the TCP stack, the bridge server is never reached. This must be confirmed by checking `openfut_hook.log` for a getaddrinfo on the LSX host, or by observing the bridge server's accept logs.
|
||||
|
||||
### Risks (could derail later)
|
||||
|
||||
3. **Fire2 framing wrong** *(M4 risk)*
|
||||
If FIFA 23 uses Fire (pre-2012) or a modified frame layout, the codec misparses. Mitigation: the server has a `Raw` fallback mode for capturing raw bytes when framing fails.
|
||||
|
||||
4. **Secondary auth-token gate** *(M5 risk)*
|
||||
`connection-gate-findings.md` noted the redirector request carries an `Authorization:` header. M1's final conclusion said `GetAuthCode` returns a fake token that appears accepted — but this was inferred, not confirmed by seeing the redirector request actually constructed with that token.
|
||||
|
||||
5. **EAAC not fully neutralized** *(persistent risk)*
|
||||
`FakeEAACLauncher` bypasses the anticheat launcher. The hook DLL is unsigned. If EAAC is ever active (e.g., after a game update re-enables it), all hooks fail silently. Marked as "not active in offline/cracked builds" — assumed, not confirmed on every launch.
|
||||
|
||||
6. **FUT REST response shapes wrong** *(M6 risk)*
|
||||
The 61 endpoint mappings in mapper.rs and the shaper stubs in shaper.rs are based on community guesses about older FIFA FUT APIs, not FIFA 23 captures. Response JSON shapes may differ enough to cause the client to fail silently or crash.
|
||||
|
||||
### Unknowns (open questions)
|
||||
|
||||
7. **ONLINE_STATUS_EVENT XML format** — exact tag names, field order, sender attribute, and any nonces/tokens required.
|
||||
8. **GoOnline event sequence** — whether ONLINE_STATUS_EVENT alone is sufficient or a sequence of events (e.g., PROFILE_EVENT, LOGIN_EVENT, COMMERCE_EVENT) is expected.
|
||||
9. **Whether FLE exposes FUT DB tables** — FUT card inventory and squad data likely live server-side in online mode; FLE may not surface them for in-process editing.
|
||||
10. **Blaze component/command IDs for FIFA 23** — entirely unknown; no captures.
|
||||
11. **openfut_hook.log current content** — we have the code but no log output in any document. Whether the current hook (with connect, ssl_patch, tls_bypass, WSAIoctl, origin_spy all installed) fires correctly and what it observes is unverified in this review.
|
||||
|
||||
---
|
||||
|
||||
## 4. Track Comparison
|
||||
|
||||
### Track A — Full EA-backend fake (M1–M7, playable FUT vs AI)
|
||||
|
||||
**What it delivers:** The FIFA 23 FUT hub loads from OpenFUT Core; Squad Battles matches play and reward economy items.
|
||||
|
||||
**Effort:** Research-grade. Minimum path: synthesize ONLINE_STATUS_EVENT (unknown format, 1–2 weeks of RE), then capture Fire2 frames (days once M2 is solved), then implement Blaze auth handlers (weeks), then implement FUT entry (weeks), then Squad Battles (weeks). Realistic minimum: 3–6 months of expert RE work.
|
||||
|
||||
**Proven support:** Hook loads and redirects correctly. TLS bypass patched. Core economy backend complete. Blaze framing code and TLS listener exist.
|
||||
|
||||
**Assumed:** Fire2 framing correct; component/command IDs discoverable from captures; FUT REST shapes close enough to community guesses; no additional undiscovered gates.
|
||||
|
||||
**Evidence for:** Architecture is coherent. The M1 finding (gate precisely named and decoded) was achieved cleanly. The in-process hook approach is validated.
|
||||
|
||||
**Evidence against:** M2 was attempted and failed with the in-process approach. The event-driven architecture adds a full EbisuSDK emulation layer before even one Blaze byte is seen. The live toolkit is exhausted (Path A verdict); Ghidra-level work on a 505 MB binary is required. Six capture files with zero bytes.
|
||||
|
||||
---
|
||||
|
||||
### Track B — Clean-room spec deliverable (M1–M5 documented)
|
||||
|
||||
**What it delivers:** A documented map of the connection gate, LSX event sequence, Blaze auth surface (transport, framing, gate conditions, component IDs, TDF schemas). Valuable as an archival/community artifact even if Track A stalls.
|
||||
|
||||
**Effort:** Medium. M1 is done. M2–M5 documentation emerges as a by-product of engineering work. The spec itself (writing) is lightweight; the engineering to produce the captures is the cost.
|
||||
|
||||
**Proven support:** M1 complete and documented. connection-gate-findings.md is already a high-quality spec artifact.
|
||||
|
||||
**Assumed:** Same as Track A for the unconfirmed values, but the spec can mark them `TODO/CONFIRM` rather than needing to implement them.
|
||||
|
||||
**Evidence for:** The clean-room constraint means a spec is the only artifact that can be safely published. connection-gate-findings.md shows this approach produces real value. B finishes even if A is never fully playable.
|
||||
|
||||
**Evidence against:** Track B alone doesn't produce a playable FUT; it is a foundation, not an end-user product.
|
||||
|
||||
---
|
||||
|
||||
### Track C — FLE Lua bridge (local-match path, skip the backend gate)
|
||||
|
||||
**What it delivers:** FIFA 23 career mode or Kick-Off with an OpenFUT club's players and squad loaded via FLE's in-memory DB API. No online gate, no Blaze, no TLS. Fully offline from day one.
|
||||
|
||||
**Effort:** Low-to-medium. FLE is already loaded in the normal launch path. Tools exist (`tools/squad-exporter/`, `tools/profile-exporter/`). Primary unknown is whether FUT-relevant DB tables are accessible.
|
||||
|
||||
**Proven support:** FLE Lua API exposes `GetDBTableRows` / `EditDBTableField` for career mode. `fifa23-startup-flow.md` confirms FLE injects at load. `fut-integration-options.md` documents the integration path in detail and rates this as the recommended option.
|
||||
|
||||
**Assumed:** FUT card/club/squad data has in-memory DB table representations that FLE can write. If FUT data is purely server-side (loaded from EA servers, not from the Frostbite DB layer), Track C produces no FUT simulation at all — only career mode player stats.
|
||||
|
||||
**Evidence for:** Career mode already works with FLE edits (community precedent). Tools are present and designed for this path. No infrastructure work needed.
|
||||
|
||||
**Evidence against:** FUT in FIFA 23 uses server-side data. The cards in a player's FUT club, the coins, the squad — these are fetched from `fut.ea.com` REST APIs, not from the Frostbite embedded DB. FLE's `GetDBTableRows` likely exposes base player stats tables but not FUT item tables. The crucial test (run `export_squad.lua` while in FUT mode) has never been done.
|
||||
|
||||
---
|
||||
|
||||
### Recommendation
|
||||
|
||||
**Start Track C immediately as a parallel, low-cost validation.**
|
||||
|
||||
Run `export_squad.lua` in FLE while inside the FUT hub (or attempting to enter it). If FUT tables appear in the export, Track C is viable and is the fastest path to something a user can interact with. This test takes one session and costs nothing.
|
||||
|
||||
Simultaneously, **continue Track A/B with the next concrete RE step:** synthesize the ONLINE_STATUS_EVENT push. The most actionable option is to run `origin_spy` logs from the current hook to see what LSX events fire during a session, then attempt to push candidate event XMLs via the bridge LSX server and watch whether the game advances. This is bounded, testable work that either unblocks M2 or produces the spec value for Track B.
|
||||
|
||||
**Do not abandon Track A/B for Track C** — they are complementary. Core is already built; the bridge is mostly built. The gap is purely the RE wall at M2.
|
||||
|
||||
---
|
||||
|
||||
## 5. Architecture and Provenance Sanity-Check
|
||||
|
||||
### Hook + Brain coherence
|
||||
|
||||
The CLAUDE.md bridge architecture diagram (hook intercepts ProtoSSL → plain localhost TCP → blaze_brain → Core) remains coherent. The M1/M2 findings revealed one additional layer (EbisuSDK LSX event) that must precede the Blaze connection. The bridge has been updated to handle LSX directly. The overall design is sound; the M2 blocker is an implementation gap (event synthesis), not an architectural flaw.
|
||||
|
||||
**One inconsistency to flag:** The hook's `lsx.rs` contains a complete in-process LSX emulator (AES-128-ECB, CRandom, all response builders), but the recv/send hooks that activate it are explicitly removed (`lib.rs`: "recv/send hooks removed — LSX is now handled by the native openfut-bridge LSX server"). This is dead code. The bridge's LSX server is the current path. The in-process lsx.rs should either be deleted or documented as a fallback; its presence is confusing.
|
||||
|
||||
### Clean-room status
|
||||
|
||||
No evidence of EA leaked source anywhere in the tree. All RE work is derived from:
|
||||
- Running the shipping binary and observing behavior (function return values, network traffic patterns)
|
||||
- Memory scanning of the live process (string search, xref, disasm of observed addresses)
|
||||
- Reading anadius's own compiled output (its exported symbols, its LSX XML format — which is anadius's own implementation, not EA's)
|
||||
- Community FUT API knowledge (mapper.rs endpoint paths — plausible but speculative)
|
||||
|
||||
The Blaze framing in `fifa-blaze/crates/blaze-proto/src/frame.rs` cites "Fire2 used by ME3, BF3, and most post-2012 titles" — this is sourced from public community documentation of those older titles, not from any leaked EA source. **Clean-room intact.**
|
||||
|
||||
The `AES_KEY` in the hook's lsx.rs (`[0,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15]`) is a placeholder key used for the LSX session encryption. The real session key is derived from the challenge seed via CRandom — this algorithm was RE'd from anadius's own binary. No EA source required.
|
||||
|
||||
---
|
||||
|
||||
## 6. If You Read Only This
|
||||
|
||||
- **The project is blocked at M2.** FIFA 23 submits `GoOnline`, gets success, then waits for an async `ONLINE_STATUS_EVENT` push on the LSX socket that no current code ever sends. All six Blaze capture files are empty (0 bytes). No Fire2 frame has ever been decoded.
|
||||
|
||||
- **M1 is the only completed milestone.** The gate function (`GetInternetConnectedState @ anadius64.dll+0x27790`) is precisely named and its two-flag branch decoded. Everything after M1 is either blocked or not started.
|
||||
|
||||
- **The next concrete action** is synthesizing the ONLINE_STATUS_EVENT push XML and testing whether the bridge's LSX server can deliver it to the game. This is the single thing that unblocks all Blaze work.
|
||||
|
||||
- **Track C (FLE Lua) is untested but cheap to validate.** Run `export_squad.lua` while in FUT to find out if FUT DB tables are accessible. If yes, it is the fastest path to user-visible results. If no, it is ruled out with one session.
|
||||
|
||||
- **openfut-core is complete and ready** — 25 phases, 15 migrations, full economy REST API, passing tests. It is not blocking anything; it is waiting for the bridge to connect to it.
|
||||
@@ -1,93 +0,0 @@
|
||||
# Track C — FUT DB table viability test
|
||||
|
||||
**Status: PENDING — test has not yet been run.**
|
||||
|
||||
## What this test settles
|
||||
|
||||
Track C ("FLE Lua bridge") would inject OpenFUT club data directly into FIFA 23's
|
||||
in-memory Frostbite DB tables at runtime, bypassing the entire backend/Blaze stack.
|
||||
It is only viable for FUT (not just career mode) if FUT-specific tables — card
|
||||
inventory, squad composition with FUT fields, coins — are accessible in memory when
|
||||
the game is in the FUT area.
|
||||
|
||||
FUT data in online mode is fetched server-side from `fut.ea.com`. It is not known
|
||||
whether FIFA 23 mirrors any of this into the Frostbite in-memory DB that FLE
|
||||
can read/write. This test settles that question directly.
|
||||
|
||||
## Test procedure
|
||||
|
||||
**Prerequisites:**
|
||||
- FIFA 23 launched normally via umu-run/Steam
|
||||
- FLE (FIFA Live Editor) injected and active (normal launch path)
|
||||
- EAAC in offline/neutralized state
|
||||
- Game navigated as deep into FUT as possible (FUT hub if reachable; otherwise the
|
||||
furthest FUT screen before the gate blocks it)
|
||||
|
||||
**Run the exporter:**
|
||||
1. In FLE's Lua Engine, open and run `tools/squad-exporter/export_squad.lua`
|
||||
(full path on the Windows side: `C:\<game>\openfut_squad_export.json`)
|
||||
2. Wait for the MessageBox "Done! N players, M teams." or "ERROR writing..."
|
||||
3. Retrieve the output file from the Wine prefix:
|
||||
`~/Games/umu/fifa23-tools/drive_c/FIFA 23 Live Editor/openfut_squad_export.json`
|
||||
(or wherever `C:\FIFA 23 Live Editor\` maps in the active prefix)
|
||||
|
||||
**What to inspect in the output:**
|
||||
- `all_db_tables` array — the complete list of table names visible to FLE right now
|
||||
- `fut_tables` object — any table whose name contains `fut`, `club`, `pack`, `item`, or
|
||||
`market` (the script auto-extracts these)
|
||||
- `is_career_mode` — confirms whether FUT or career mode was active
|
||||
|
||||
## Classification criteria
|
||||
|
||||
### "FUT tables present"
|
||||
|
||||
`fut_tables` is non-empty AND contains FUT-specific fields beyond base player stats:
|
||||
- e.g., `fut_items` with card-type / rating / chemistry fields
|
||||
- e.g., a squad table with FUT formation / chemistry / loan-flag fields
|
||||
- e.g., a coins or points balance field
|
||||
|
||||
**Verdict:** Track C is viable for FUT. Fastest path to user-visible results.
|
||||
|
||||
### "only base player tables"
|
||||
|
||||
`fut_tables` is empty (no `fut_*` / `club_*` / `item_*` / `market_*` table names found
|
||||
in `all_db_tables`), OR those tables exist but contain only base player attributes
|
||||
(OVR, potential, position, pace, …) — the same fields visible in career mode.
|
||||
|
||||
**Verdict:** Track C cannot produce FUT. It could at most provide a custom Kick-Off or
|
||||
career-mode match with players sourced from OpenFUT Core. FUT items and coins exist
|
||||
only on EA's servers (not in the in-memory DB in offline mode).
|
||||
|
||||
### "FUT area unreachable to test"
|
||||
|
||||
The connection gate blocked entering FUT deeply enough for FUT tables to be populated.
|
||||
Record which tables were visible and at what screen the test was run.
|
||||
|
||||
**Verdict:** Retest after M2 is unblocked, OR test with `TLS_ENABLED=false` bridge
|
||||
handling the entry check stub.
|
||||
|
||||
## Results
|
||||
|
||||
*(To be filled in after the test is run.)*
|
||||
|
||||
| Field | Value |
|
||||
|---|---|
|
||||
| Date run | — |
|
||||
| FIFA screen at test time | — |
|
||||
| `is_career_mode` | — |
|
||||
| Total tables in `all_db_tables` | — |
|
||||
| FUT-specific table names found | — |
|
||||
| Key FUT fields present | — |
|
||||
| **Classification** | **PENDING** |
|
||||
|
||||
## Honest prior
|
||||
|
||||
`fut-integration-options.md` rates this as the recommended path and lists `fut_clubs`,
|
||||
`fut_items`, `fut_squads` as "expected" tables. However those expectations are based on
|
||||
analogy with career mode (which does store club/squad in the DB). FUT's data model is
|
||||
architecturally different — it is account-bound server-side. The expectation may be
|
||||
wrong. This test is the oracle.
|
||||
|
||||
The `export_squad.lua` script checks `GetDBTablesNames()` exhaustively (not just
|
||||
assumed names), so it will surface any FUT tables that actually exist, regardless of
|
||||
what name they use.
|
||||
+1
-1
Submodule fifa-blaze updated: d2a9a01ec9...f4f33969f2
@@ -3,7 +3,7 @@
|
||||
# OPENFUT_ADVERTISE — the address of THIS host as seen from the game machine
|
||||
# (105). The responders advertise it to the client for every next hop (Blaze,
|
||||
# roster, UTAS, POW). Compose refuses to start without it.
|
||||
OPENFUT_ADVERTISE=10.10.0.120
|
||||
OPENFUT_ADVERTISE=203.0.113.10 # <- REPLACE with this host's LAN IP
|
||||
|
||||
# OPENFUT_BIND — address the listeners bind inside the container.
|
||||
# Defaults to 0.0.0.0 (container-facing); the original all-on-localhost flow
|
||||
|
||||
@@ -37,17 +37,25 @@ RUN set -eu; \
|
||||
|
||||
COPY data/ /app/data/
|
||||
|
||||
# Redirector TLS cert (CN/SAN = winter15.gosredirector.ea.com). ProtoSSL
|
||||
# cert-verify is patched client-side, so a self-signed cert is fine. The pair is
|
||||
# git-ignored (*.pem/*.key); regenerate if absent so a fresh checkout builds
|
||||
# without extra steps.
|
||||
# Redirector/roster TLS cert (CN/SAN = winter15.gosredirector.ea.com). ProtoSSL
|
||||
# cert-verify is patched client-side, so a self-signed cert is fine — but the
|
||||
# client dials the roster and redirector BY IP, and that path still checks the
|
||||
# SAN against the dialed address (it is NOT covered by the two patched gates), so
|
||||
# a cert without a matching IP SAN is rejected with fatal certificate_unknown
|
||||
# (docs/FIFA17_FUT_SQUAD_UPDATE_TLS.md). The advertised LAN IP is a RUNTIME value,
|
||||
# unknown here, so this bakes only a loopback-IP baseline and the entrypoint
|
||||
# reissues with IP:$OPENFUT_ADVERTISE at start.
|
||||
#
|
||||
# openssl therefore has to remain in the image for the entrypoint, not be dropped
|
||||
# with the apt lists. The pair is git-ignored (*.pem/*.key); regenerate if absent
|
||||
# so a fresh checkout builds without extra steps.
|
||||
RUN apt-get update && apt-get install -y --no-install-recommends openssl && \
|
||||
rm -rf /var/lib/apt/lists/*
|
||||
RUN if [ ! -s tools/redir_cert.pem ] || [ ! -s tools/redir_key.pem ]; then \
|
||||
apt-get update && apt-get install -y --no-install-recommends openssl && \
|
||||
openssl req -x509 -newkey rsa:2048 -nodes \
|
||||
-keyout tools/redir_key.pem -out tools/redir_cert.pem \
|
||||
-days 3650 -subj "/CN=winter15.gosredirector.ea.com" \
|
||||
-addext "subjectAltName=DNS:winter15.gosredirector.ea.com,DNS:*.gosredirector.ea.com,DNS:*.ea.com" && \
|
||||
rm -rf /var/lib/apt/lists/*; \
|
||||
-addext "subjectAltName=DNS:winter15.gosredirector.ea.com,DNS:*.gosredirector.ea.com,DNS:*.ea.com,IP:127.0.0.1"; \
|
||||
fi
|
||||
|
||||
# Bake a dataset manifest so every image is self-identifying.
|
||||
|
||||
@@ -24,7 +24,7 @@ services:
|
||||
OPENFUT_BIND: "${OPENFUT_BIND:-0.0.0.0}"
|
||||
# Address advertised to the client for the next hop. MUST be this host's
|
||||
# LAN IP as seen from the game machine (105). Required (see .env.example).
|
||||
OPENFUT_ADVERTISE: "${OPENFUT_ADVERTISE:?set OPENFUT_ADVERTISE in .env to this host's LAN IP, e.g. 10.10.0.120}"
|
||||
OPENFUT_ADVERTISE: "${OPENFUT_ADVERTISE:?set OPENFUT_ADVERTISE in .env to this host's LAN IP, e.g. 203.0.113.10}"
|
||||
# POW content advertises port 8080 by default, which collides with the
|
||||
# openfut-core publish on this host. Remap it to 8085 on the host and
|
||||
# advertise the remapped endpoint.
|
||||
|
||||
@@ -11,13 +11,13 @@
|
||||
# Address behaviour is driven by two env vars (see each responder):
|
||||
# OPENFUT_BIND bind address for every listener (container: 0.0.0.0)
|
||||
# OPENFUT_ADVERTISE address handed to the client for the next hop
|
||||
# (the server's LAN IP, e.g. 10.10.0.120)
|
||||
# (the server's LAN IP, e.g. 203.0.113.10)
|
||||
# ============================================================================
|
||||
set -uo pipefail
|
||||
cd "$(dirname "$(readlink -f "$0")")/tools"
|
||||
|
||||
BIND="${OPENFUT_BIND:-0.0.0.0}"
|
||||
ADV="${OPENFUT_ADVERTISE:?OPENFUT_ADVERTISE must be set to the server LAN IP (e.g. 10.10.0.120)}"
|
||||
ADV="${OPENFUT_ADVERTISE:?OPENFUT_ADVERTISE must be set to the server LAN IP (e.g. 203.0.113.10)}"
|
||||
export OPENFUT_BIND="$BIND"
|
||||
export OPENFUT_ADVERTISE="$ADV"
|
||||
# POW keys advertised by blaze must also point at the server, not loopback.
|
||||
@@ -28,6 +28,26 @@ export POW_CONTENT_ADDR="${POW_CONTENT_ADDR:-$BIND:8080}"
|
||||
|
||||
echo "[openfut] bind=$BIND advertise=$ADV"
|
||||
|
||||
# The TLS cert every responder serves must carry the ADVERTISED IP in its SAN.
|
||||
# The client dials the roster (:8081) and redirector by that IP, and that path
|
||||
# validates the cert's SAN against the dialed address — it is NOT covered by the
|
||||
# two client-side ProtoSSL gates autopatch patches, so a cert lacking IP:$ADV is
|
||||
# rejected with fatal certificate_unknown and the FUT hub fails with "An error
|
||||
# occurred downloading the FUT Squad Update" (docs/FIFA17_FUT_SQUAD_UPDATE_TLS.md).
|
||||
# The advertised IP is unknown at image-build time, so reconcile it here: reissue
|
||||
# only when the current cert does not already carry it, so a restart reuses the
|
||||
# same cert (no per-start fingerprint churn) and this self-heals if $ADV changes.
|
||||
CERT=redir_cert.pem KEY=redir_key.pem
|
||||
if ! openssl x509 -in "$CERT" -noout -ext subjectAltName 2>/dev/null | grep -qF "IP Address:$ADV"; then
|
||||
echo "[openfut] reissuing TLS cert with SAN IP:$ADV (was missing it)"
|
||||
openssl req -x509 -newkey rsa:2048 -nodes -keyout "$KEY" -out "$CERT" -days 3650 \
|
||||
-subj "/CN=winter15.gosredirector.ea.com" \
|
||||
-addext "subjectAltName=DNS:winter15.gosredirector.ea.com,DNS:*.gosredirector.ea.com,DNS:*.ea.com,IP:$ADV,IP:127.0.0.1" \
|
||||
>/dev/null 2>&1 \
|
||||
&& echo "[openfut] cert SAN now: $(openssl x509 -in "$CERT" -noout -ext subjectAltName 2>/dev/null | tail -1 | tr -s ' ')" \
|
||||
|| { echo "[openfut] FATAL: could not reissue TLS cert" >&2; exit 1; }
|
||||
fi
|
||||
|
||||
# name script extra-env
|
||||
declare -a SERVERS=(
|
||||
"lsx|lsx_responder_v2.py|OPENFUT_LSX_EVENT_COUNT=100000"
|
||||
|
||||
@@ -55,34 +55,6 @@ verify_exports() {
|
||||
done
|
||||
}
|
||||
|
||||
# Refuse any DLL that is not a FIFA-17-profile build.
|
||||
#
|
||||
# openfut-hook builds TWO mutually exclusive injection paths from one crate: the
|
||||
# default (FIFA 23) path installs getaddrinfo/connect/ProtoSSL/origin hooks, while
|
||||
# `--features fifa17` installs ONLY the FIFA-17-safe logic (module map, FIFA 17
|
||||
# cert-verify, SBC dispatch, store tab bind). Deploying a default-feature build
|
||||
# into FIFA 17 hijacks the login transport and the client reports "Unable to
|
||||
# connect to the EA servers", with none of the FIFA 17 repairs present.
|
||||
#
|
||||
# That exact mistake happened on 2026-08-19 (artifact 1c71a17a, hand-built without
|
||||
# the feature): two failed launches, diagnosed only by comparing embedded strings.
|
||||
# `build` below passes the feature, but a hand-built DLL can reach `stage`/`deploy`
|
||||
# via OPENFUT_FIFA17_HOOK_DLL, so assert the profile on the bytes themselves.
|
||||
verify_fifa17_profile() {
|
||||
local dll=$1 marker
|
||||
# Markers that MUST be present: the FIFA 17 target module and its repairs.
|
||||
for marker in 'CardsDLL_Win64_retail.dll' 'SBC_DISPATCH'; do
|
||||
grep -qaF -- "$marker" "$dll" ||
|
||||
die "$dll is not a --features fifa17 build (missing $marker); refusing to stage/deploy"
|
||||
done
|
||||
# Markers that MUST be absent: the FIFA-23-only transport hooking.
|
||||
for marker in 'getaddrinfo IAT patched' 'connect: inline-hooked' 'origin_spy'; do
|
||||
if grep -qaF -- "$marker" "$dll"; then
|
||||
die "$dll contains FIFA-23-only hook '$marker'; build with --features fifa17"
|
||||
fi
|
||||
done
|
||||
}
|
||||
|
||||
verify_inputs() {
|
||||
command -v sha256sum >/dev/null || die "sha256sum is required"
|
||||
command -v x86_64-w64-mingw32-objdump >/dev/null ||
|
||||
@@ -90,7 +62,6 @@ verify_inputs() {
|
||||
need_file "$hook_dll"
|
||||
need_file "$system_version"
|
||||
verify_pe64 "$hook_dll"
|
||||
verify_fifa17_profile "$hook_dll"
|
||||
}
|
||||
|
||||
inspect() {
|
||||
@@ -158,7 +129,6 @@ deploy() {
|
||||
need_file "$manifest"
|
||||
verify_pe64 "$staged"
|
||||
verify_exports "$staged"
|
||||
verify_fifa17_profile "$staged"
|
||||
local recorded actual
|
||||
recorded="$(awk -F= '$1=="artifact_sha256"{print $2}' "$manifest")"
|
||||
actual="$(sha256 "$staged")"
|
||||
@@ -188,7 +158,7 @@ launch() {
|
||||
local trace_enabled=0
|
||||
local request_trace_enabled=0
|
||||
local notifier_trace_enabled=0
|
||||
local dispatch_enabled=0
|
||||
local commit_enabled=0
|
||||
case "$mode" in
|
||||
baseline)
|
||||
[[ "${OPENFUT_FIFA17_LAUNCH:-}" == "I_ACCEPT_M1_BASELINE_LAUNCH" ]] ||
|
||||
@@ -207,11 +177,14 @@ launch() {
|
||||
request_trace_enabled=1
|
||||
notifier_trace_enabled=1
|
||||
;;
|
||||
dispatch)
|
||||
[[ "${OPENFUT_FIFA17_DISPATCH:-}" == "I_ACCEPT_GUARDED_NATIVE_DISPATCH" ]] ||
|
||||
die "launch-dispatch requires OPENFUT_FIFA17_DISPATCH=I_ACCEPT_GUARDED_NATIVE_DISPATCH"
|
||||
commit)
|
||||
[[ "${OPENFUT_FIFA17_COMMIT:-}" == "I_ACCEPT_POST_PARSE_READY_BYTE" ]] ||
|
||||
die "launch-commit requires OPENFUT_FIFA17_COMMIT=I_ACCEPT_POST_PARSE_READY_BYTE"
|
||||
hook_enabled=1
|
||||
trace_enabled=1
|
||||
request_trace_enabled=1
|
||||
dispatch_enabled=1
|
||||
notifier_trace_enabled=1
|
||||
commit_enabled=1
|
||||
;;
|
||||
*) die "unknown launch mode: $mode" ;;
|
||||
esac
|
||||
@@ -234,7 +207,7 @@ launch() {
|
||||
done
|
||||
mkdir -p "${wine_prefix}/dosdevices"
|
||||
ln -sfn /mnt "${wine_prefix}/dosdevices/w:"
|
||||
note "Launching $mode mode (SBC_HOOK=$hook_enabled; SBC_TRACE=$trace_enabled; SBC_REQUEST_TRACE=$request_trace_enabled; SBC_NOTIFIER_TRACE=$notifier_trace_enabled; SBC_DISPATCH=$dispatch_enabled); log=/tmp/fifa17-hook-m1-launch.log"
|
||||
note "Launching $mode mode (SBC_HOOK=$hook_enabled; SBC_TRACE=$trace_enabled; SBC_REQUEST_TRACE=$request_trace_enabled; SBC_NOTIFIER_TRACE=$notifier_trace_enabled; SBC_COMMIT=$commit_enabled); log=/tmp/fifa17-hook-m1-launch.log"
|
||||
cd "$game_dir"
|
||||
env \
|
||||
GAMEID=fifa17 \
|
||||
@@ -245,8 +218,8 @@ launch() {
|
||||
OPENFUT_SBC_TRACE="$trace_enabled" \
|
||||
OPENFUT_SBC_REQUEST_TRACE="$request_trace_enabled" \
|
||||
OPENFUT_SBC_NOTIFIER_TRACE="$notifier_trace_enabled" \
|
||||
OPENFUT_SBC_DISPATCH="$dispatch_enabled" \
|
||||
OPENFUT_SBC_DISPATCH_TRACE=0 \
|
||||
OPENFUT_SBC_DISPATCH=0 \
|
||||
OPENFUT_SBC_COMMIT="$commit_enabled" \
|
||||
OPENFUT_SBC_ARM_ONLY=0 \
|
||||
OPENFUT_SBC_POPULATE=0 \
|
||||
umu-run _fifa17.exe 2>&1 | tee /tmp/fifa17-hook-m1-launch.log
|
||||
@@ -254,7 +227,7 @@ launch() {
|
||||
|
||||
usage() {
|
||||
cat <<'EOF'
|
||||
Usage: fifa17-hook-m1.sh [inspect|build|stage|deploy|launch|launch-resolve|launch-trace|launch-dispatch]
|
||||
Usage: fifa17-hook-m1.sh [inspect|build|stage|deploy|launch|launch-resolve|launch-trace|launch-commit]
|
||||
|
||||
inspect Read-only PE/hash/export preflight (default).
|
||||
build Cross-build the inert FIFA17 hook, then run inspect.
|
||||
@@ -267,11 +240,11 @@ Usage: fifa17-hook-m1.sh [inspect|build|stage|deploy|launch|launch-resolve|launc
|
||||
Start M2 resolve-only mode (guarded reads/logging, no detours/writes); requires:
|
||||
OPENFUT_FIFA17_RESOLVE=I_ACCEPT_M2_RESOLVE_LAUNCH
|
||||
launch-trace
|
||||
Start the M3-M6 passive parser/request/notifier trace; requires:
|
||||
Start the single M3 passive factory/deserializer trace; requires:
|
||||
OPENFUT_FIFA17_TRACE=I_ACCEPT_M3_PASSIVE_TRACE
|
||||
launch-dispatch
|
||||
Trace and repair only a fully validated native status-999 completion; requires:
|
||||
OPENFUT_FIFA17_DISPATCH=I_ACCEPT_GUARDED_NATIVE_DISPATCH
|
||||
launch-commit
|
||||
Trace and arm the SBC cache only after a validated native parse; requires:
|
||||
OPENFUT_FIFA17_COMMIT=I_ACCEPT_POST_PARSE_READY_BYTE
|
||||
|
||||
Optional path overrides:
|
||||
OPENFUT_FIFA17_HOOK_DLL, OPENFUT_FIFA17_GAME_DIR,
|
||||
@@ -287,7 +260,7 @@ case "${1:-inspect}" in
|
||||
launch) launch baseline ;;
|
||||
launch-resolve) launch resolve ;;
|
||||
launch-trace) launch trace ;;
|
||||
launch-dispatch) launch dispatch ;;
|
||||
launch-commit) launch commit ;;
|
||||
-h|--help|help) usage ;;
|
||||
*) usage >&2; die "unknown command: $1" ;;
|
||||
esac
|
||||
|
||||
+29
-11
@@ -15,16 +15,27 @@ reimplementations (the `tdf` crate cloned in this scratchpad), which were used
|
||||
only as a cross-check of *structure*, never copied.
|
||||
NO EA/FIFA leaked source was consulted.
|
||||
|
||||
VALIDATED RULES (byte-exact round-trip against the 219-byte capture)
|
||||
--------------------------------------------------------------------
|
||||
Fire2 frame header, 16 bytes big-endian:
|
||||
[0:4] u32 payload length (bytes after the header)
|
||||
[4:6] u16 always 0 (observed)
|
||||
[6:8] u16 component
|
||||
[8:10] u16 command
|
||||
[10:12]u16 error / msgId
|
||||
[12] u8 msgType (0x01 ping, 0x02 request, 0x03 pong/response)
|
||||
[13:16]3 reserved bytes (observed 00 00 00)
|
||||
VALIDATED RULES (the TDF body; byte-exact round-trip against the 219-byte capture)
|
||||
---------------------------------------------------------------------------------
|
||||
Fire2 frame header, 16 bytes big-endian.
|
||||
|
||||
!!! SUPERSEDED — the [10:16] FIELD SEMANTICS below are WRONG for FIFA 17. !!!
|
||||
The "byte-exact round-trip" only proves the payload length and the TDF body
|
||||
encoding: decoding then re-encoding with the SAME (mis)labelled header layout
|
||||
trivially reproduces the capture, so it never tested the header's field
|
||||
boundaries. The authoritative, live-driven layout is
|
||||
`openfut-protocol-blaze::fire2` / `blaze_responder_v3b.py::fire2`:
|
||||
[0:4] u32 payload length (bytes after header + metadata)
|
||||
[4:6] u16 metadata length (0 when absent — what this file called "always 0")
|
||||
[6:8] u16 component
|
||||
[8:10] u16 command
|
||||
[10:13] u24 msgNum (this file WRONGLY split it as [10:12] msgId + [12] msgType)
|
||||
[13] u8 (msgType << 5) | (userIndex & 0x1F)
|
||||
[14] u8 options
|
||||
[15] u8 reserved
|
||||
There is NO error field in Fire2 (that is Fire v1) and NO jumbo escape — the
|
||||
length is already a full u32. `build_fire2_frame`/`decode_fire2` below keep the
|
||||
old wrong `>IHHHHB3s` layout; they are dead and retained only for history.
|
||||
|
||||
Heat2 field = 3-byte packed tag + 1 type byte + value.
|
||||
|
||||
@@ -359,7 +370,14 @@ MSG_ERROR = 0x05 # UNVERIFIED
|
||||
|
||||
def build_fire2_frame(component: int, command: int, msgType: int,
|
||||
msgId: int, tdf_bytes: bytes) -> bytes:
|
||||
"""16-byte big-endian Fire2 header + TDF payload."""
|
||||
"""16-byte big-endian Fire2 header + TDF payload.
|
||||
|
||||
WRONG HEADER (dead code): the ``>IHHHHB3s`` layout mislabels [10:16] — it
|
||||
puts a u16 msgId at [10:12] and msgType at [12]. FIFA 17's real Fire2 header
|
||||
is [10:13] u24 msgNum, [13] (msgType<<5)|userIndex, [14] options, [15]
|
||||
reserved, and has no error field. Use ``openfut-protocol-blaze::fire2`` or
|
||||
``blaze_responder_v3b.py::fire2``; this is retained only for history.
|
||||
"""
|
||||
tdf_bytes = bytes(tdf_bytes)
|
||||
hdr = struct.pack(">IHHHHB3s", len(tdf_bytes), 0, component & 0xFFFF,
|
||||
command & 0xFFFF, msgId & 0xFFFF, msgType & 0xFF,
|
||||
|
||||
@@ -162,19 +162,6 @@ def log(*a):
|
||||
print("[lsx]", *a, flush=True)
|
||||
|
||||
|
||||
def spawn_parent_watchdog():
|
||||
parent = os.getppid()
|
||||
|
||||
def _watch():
|
||||
while True:
|
||||
time.sleep(1)
|
||||
if os.getppid() != parent:
|
||||
log(f"launcher pid {parent} exited; stopping lsx")
|
||||
os._exit(0)
|
||||
|
||||
threading.Thread(target=_watch, daemon=True).start()
|
||||
|
||||
|
||||
_SECRET_ATTR_RE = re.compile(
|
||||
r'(?i)\b(AuthCode|AuthToken|SessionKey|Token|Sid)="[^"]*"')
|
||||
_AUTH_CODE_ATTR_RE = re.compile(r'(?i)\b(value|Code|Return)="[^"]*"')
|
||||
@@ -585,7 +572,6 @@ def serve(sock, addr):
|
||||
|
||||
|
||||
def main():
|
||||
spawn_parent_watchdog()
|
||||
s = socket.socket()
|
||||
s.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
|
||||
s.bind((os.environ.get("OPENFUT_BIND", "127.0.0.1"), 4216))
|
||||
|
||||
@@ -32,11 +32,26 @@ c() { printf ' %s\n' "$*"; }
|
||||
up() { ss -tlnp 2>/dev/null | grep -q ":$1 "; }
|
||||
|
||||
ensure_cert() {
|
||||
[ -s "$CERT" ] && [ -s "$KEY" ] && return 0
|
||||
echo "[*] generating self-signed TLS cert (redirector MITM; ProtoSSL verify is patched)"
|
||||
# The cert MUST carry the address the client dials in its SAN, or the roster
|
||||
# HTTPS handshake is rejected with fatal certificate_unknown and the FUT hub
|
||||
# fails to load (docs/FIFA17_FUT_SQUAD_UPDATE_TLS.md): the client dials the
|
||||
# roster/redirector by IP and that path validates the SAN against it. Default to
|
||||
# this host's primary LAN IP so a client on another machine works;
|
||||
# OPENFUT_ADVERTISE overrides. Reissue when absent OR when the current cert lacks
|
||||
# that IP, so this self-heals rather than serving a stale DNS-only cert.
|
||||
local adv ip_sans regen=0
|
||||
adv="${OPENFUT_ADVERTISE:-$(ip route get 1.1.1.1 2>/dev/null | awk '{print $7; exit}')}"
|
||||
ip_sans="IP:127.0.0.1"; [ -n "$adv" ] && ip_sans="IP:$adv,IP:127.0.0.1"
|
||||
if [ ! -s "$CERT" ] || [ ! -s "$KEY" ]; then
|
||||
regen=1
|
||||
elif [ -n "$adv" ] && ! openssl x509 -in "$CERT" -noout -ext subjectAltName 2>/dev/null | grep -qF "IP Address:$adv"; then
|
||||
regen=1
|
||||
fi
|
||||
[ "$regen" = 0 ] && return 0
|
||||
echo "[*] issuing self-signed TLS cert (SAN includes $ip_sans; redirector MITM; ProtoSSL verify is patched)"
|
||||
openssl req -x509 -newkey rsa:2048 -nodes -keyout "$KEY" -out "$CERT" -days 3650 \
|
||||
-subj "/CN=winter15.gosredirector.ea.com" \
|
||||
-addext "subjectAltName=DNS:winter15.gosredirector.ea.com,DNS:*.gosredirector.ea.com,DNS:*.ea.com,IP:127.0.0.1" \
|
||||
-addext "subjectAltName=DNS:winter15.gosredirector.ea.com,DNS:*.gosredirector.ea.com,DNS:*.ea.com,$ip_sans" \
|
||||
>/dev/null 2>&1
|
||||
}
|
||||
|
||||
|
||||
@@ -0,0 +1,76 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Dump CardsDLL's 45-row route table from the ON-DISK PE. READ-ONLY, static.
|
||||
|
||||
The transfer-market analysis locates the table at .rdata 0x18021df80 as
|
||||
{char*, char*} rows. This resolves VA->file offset properly through the PE section
|
||||
table rather than assuming a single .text mapping, then prints every row so we can
|
||||
see whether any route other than `tradePile` could own a trade-pile ITEM list.
|
||||
"""
|
||||
import struct, sys
|
||||
|
||||
DLL = "/mnt/games/FIFA 17/CardsDLL_Win64_retail.dll"
|
||||
TABLE_VA = 0x18021DF80
|
||||
MAX_ROWS = 64
|
||||
|
||||
pe = open(DLL, "rb").read()
|
||||
e_lfanew = struct.unpack_from("<I", pe, 0x3C)[0]
|
||||
assert pe[e_lfanew:e_lfanew + 4] == b"PE\0\0", "not a PE"
|
||||
coff = e_lfanew + 4
|
||||
nsec, opt_size = struct.unpack_from("<HH", pe, coff + 2), None
|
||||
num_sections = struct.unpack_from("<H", pe, coff + 2)[0]
|
||||
opt_size = struct.unpack_from("<H", pe, coff + 16)[0]
|
||||
opt = coff + 20
|
||||
magic = struct.unpack_from("<H", pe, opt)[0]
|
||||
assert magic == 0x20B, "expected PE32+"
|
||||
image_base = struct.unpack_from("<Q", pe, opt + 24)[0]
|
||||
sec_off = opt + opt_size
|
||||
|
||||
sections = []
|
||||
for i in range(num_sections):
|
||||
b = sec_off + i * 40
|
||||
name = pe[b:b + 8].rstrip(b"\0").decode("ascii", "replace")
|
||||
vsize, vaddr, rawsize, rawptr = struct.unpack_from("<IIII", pe, b + 8)
|
||||
sections.append((name, vaddr, vsize, rawptr, rawsize))
|
||||
|
||||
print("image_base=%#x sections=%d" % (image_base, num_sections))
|
||||
for s in sections:
|
||||
print(" %-8s rva=%#010x vsize=%#x rawptr=%#010x rawsize=%#x" % s)
|
||||
|
||||
|
||||
def va2off(va):
|
||||
rva = va - image_base
|
||||
for name, vaddr, vsize, rawptr, rawsize in sections:
|
||||
if vaddr <= rva < vaddr + max(vsize, rawsize):
|
||||
off = rva - vaddr + rawptr
|
||||
if off < len(pe):
|
||||
return off
|
||||
return None
|
||||
|
||||
|
||||
def cstr(va, limit=96):
|
||||
off = va2off(va)
|
||||
if off is None:
|
||||
return None
|
||||
end = pe.find(b"\0", off, off + limit)
|
||||
if end < 0:
|
||||
return None
|
||||
try:
|
||||
return pe[off:end].decode("ascii")
|
||||
except UnicodeDecodeError:
|
||||
return None
|
||||
|
||||
|
||||
base = va2off(TABLE_VA)
|
||||
print("\nroute table VA %#x -> file offset %s" % (TABLE_VA, hex(base) if base else None))
|
||||
assert base, "table VA did not resolve"
|
||||
|
||||
print("\n%-4s %-34s %s" % ("#", "field A", "field B"))
|
||||
rows = 0
|
||||
for i in range(MAX_ROWS):
|
||||
a_va, b_va = struct.unpack_from("<QQ", pe, base + i * 16)
|
||||
a, b = cstr(a_va), cstr(b_va)
|
||||
if a is None and b is None:
|
||||
print("-- table ends after %d rows --" % rows)
|
||||
break
|
||||
print("%-4d %-34s %s" % (i, repr(a), repr(b)))
|
||||
rows += 1
|
||||
Executable
+65
@@ -0,0 +1,65 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Pure unit test for the empty-My-Packs store resolver guard in autopatch.py.
|
||||
|
||||
Covers the fail-closed guard decision (original -> PATCH, already-patched -> NOOP,
|
||||
unknown -> SKIP) and pins the guarded patch table to the exact RVA/bytes proven on
|
||||
the tested FIFA 17 build (JNZ 0x14869 -> JG 0x14869 at CardsDLL RVA 0x14858).
|
||||
|
||||
Run: python3 test_autopatch_guard.py
|
||||
"""
|
||||
import os
|
||||
import sys
|
||||
|
||||
sys.path.insert(0, os.path.dirname(os.path.abspath(__file__)))
|
||||
import autopatch # importable: runtime loop is guarded by `if __name__ == "__main__"`
|
||||
|
||||
GUARD_VA = 0x180014858
|
||||
ORIG = bytes.fromhex("750f") # JNZ 0x14869
|
||||
PATCH = bytes.fromhex("7f0f") # JG 0x14869
|
||||
|
||||
|
||||
def test_table_exact():
|
||||
assert autopatch.STORE_PATCHES_GUARDED == {GUARD_VA: (ORIG, PATCH)}, \
|
||||
autopatch.STORE_PATCHES_GUARDED
|
||||
# Byte-level pin so a bad hex literal cannot slip through.
|
||||
assert ORIG == b"\x75\x0f" and PATCH == b"\x7f\x0f"
|
||||
|
||||
|
||||
def test_decision():
|
||||
assert autopatch.guarded_action(ORIG, ORIG, PATCH) == "patch" # apply
|
||||
assert autopatch.guarded_action(PATCH, ORIG, PATCH) == "noop" # already patched
|
||||
assert autopatch.guarded_action(b"\x00\x00", ORIG, PATCH) == "skip" # build mismatch
|
||||
assert autopatch.guarded_action(b"\x90", ORIG, PATCH) == "skip" # wrong length
|
||||
|
||||
|
||||
def test_guard_state_after():
|
||||
# already patched (7f0f) -> VERIFIED (guarded_action "noop"); write args irrelevant.
|
||||
assert autopatch.guard_state_after(PATCH, ORIG, PATCH, True, PATCH) == autopatch.GUARD_VERIFIED
|
||||
# original (750f) + write ok + reread 7f0f -> VERIFIED (guarded_action "patch").
|
||||
assert autopatch.guard_state_after(ORIG, ORIG, PATCH, True, PATCH) == autopatch.GUARD_VERIFIED
|
||||
# original + write FAILS -> WRITE_FAILED.
|
||||
assert autopatch.guard_state_after(ORIG, ORIG, PATCH, False, ORIG) == autopatch.GUARD_WRITE_FAILED
|
||||
# original + write ok but reread != 7f0f -> VERIFY_FAILED.
|
||||
assert autopatch.guard_state_after(ORIG, ORIG, PATCH, True, ORIG) == autopatch.GUARD_VERIFY_FAILED
|
||||
assert autopatch.guard_state_after(ORIG, ORIG, PATCH, True, b"") == autopatch.GUARD_VERIFY_FAILED
|
||||
# unknown bytes -> UNSUPPORTED_BUILD (guarded_action "skip"); write args irrelevant.
|
||||
assert autopatch.guard_state_after(b"\x00\x00", ORIG, PATCH, True, PATCH) == autopatch.GUARD_UNSUPPORTED_BUILD
|
||||
|
||||
|
||||
def test_capability_constants():
|
||||
assert autopatch.EMPTY_MYPACKS_RESOLVER_VERSION == 1
|
||||
assert autopatch.EMPTY_MYPACKS_RESOLVER_CAPABILITY == "fifa17.empty_mypacks_resolver"
|
||||
# State constant values are the exact tokens carried in the emitted status line.
|
||||
assert autopatch.GUARD_VERIFIED == "VERIFIED"
|
||||
assert autopatch.GUARD_UNSUPPORTED_BUILD == "UNSUPPORTED_BUILD"
|
||||
assert autopatch.GUARD_WRITE_FAILED == "WRITE_FAILED"
|
||||
assert autopatch.GUARD_VERIFY_FAILED == "VERIFY_FAILED"
|
||||
assert autopatch.GUARD_NOT_ATTEMPTED == "NOT_ATTEMPTED"
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
test_table_exact()
|
||||
test_decision()
|
||||
test_guard_state_after()
|
||||
test_capability_constants()
|
||||
print("OK: autopatch guard table + fail-closed decision + guard-state function + capability constants")
|
||||
+301
@@ -0,0 +1,301 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Tests for the FIFA 17 verified-patched-client capability negotiation.
|
||||
|
||||
The additive empty-My-Packs switch on top of the P2 65534 sentinel: the sentinel is
|
||||
suppressed for ONE FIFA session only when the launcher has registered a verified
|
||||
resolver capability (v1) that binds to THAT process's UTAS session (keyed by the
|
||||
per-login-unique X-UT-SID; source IP + persona are auxiliary). Every failure /
|
||||
unknown / late / cross-process / cross-session case is fail-closed to the sentinel.
|
||||
|
||||
The initial prototype keyed by source IP alone; this suite proves the hardened
|
||||
per-session binding, including two sessions that SHARE a source IP.
|
||||
|
||||
Matrix (docs/plans/FIFA17_PATCHED_CLIENT_CAPABILITY.md):
|
||||
A no-capability, zero packs -> sentinel
|
||||
B verified v1, zero packs -> clean (no 65534)
|
||||
C real unopened pack + no capability -> genuine pack, no sentinel
|
||||
D real unopened pack + capability -> genuine pack, no sentinel
|
||||
E unsupported version / capability -> endpoint 400 AND mode sentinel
|
||||
F late capability after sentinel freeze -> stays sentinel
|
||||
G capability disappears after clean freeze -> stays clean (immutable)
|
||||
H two IPs (A verified, B none) -> A clean, B sentinel (no global leak)
|
||||
I new session after reset -> fresh unpatched -> sentinel
|
||||
J autopatch mismatch => never registers -> sentinel
|
||||
K SAME IP, two sessions (A patched, B not) -> A clean, B sentinel
|
||||
L SAME IP+persona relaunch (old ok, new not) -> new session sentinel
|
||||
M SAME IP, failed-patch second session -> first clean, second sentinel
|
||||
N late registration when sessions are frozen -> does not modify active sessions
|
||||
O session cleanup / TTL expiry -> capability gone, sentinel
|
||||
P duplicate registration for a session -> idempotent; no post-freeze change
|
||||
Q register-before-login (pending consumed) -> clean
|
||||
R topology freeze immutable per SID -> no flip either way; new SID fresh
|
||||
|
||||
Standalone unit test in the project style: `python3 test_capability_negotiation.py`.
|
||||
"""
|
||||
import importlib
|
||||
import json
|
||||
import os
|
||||
import sys
|
||||
import tempfile
|
||||
|
||||
TOOLS = os.path.dirname(os.path.abspath(__file__))
|
||||
if TOOLS not in sys.path:
|
||||
sys.path.insert(0, TOOLS)
|
||||
|
||||
SENTINEL_ID = 65534
|
||||
REAL_PACK_ID = 1
|
||||
PERSONA = 111001
|
||||
|
||||
|
||||
class _H:
|
||||
"""Minimal request-handler stand-in: peer IP, optional X-UT-SID, optional body."""
|
||||
|
||||
def __init__(self, ip, body=None, sid=None):
|
||||
self.client_address = (ip, 54321)
|
||||
self.headers = {"X-UT-SID": sid} if sid is not None else {}
|
||||
self._body = json.dumps(body).encode("utf-8") if body is not None else b""
|
||||
|
||||
|
||||
def _ids(catalog):
|
||||
return [p["id"] for p in catalog["purchase"]]
|
||||
|
||||
|
||||
def main():
|
||||
with tempfile.TemporaryDirectory() as state:
|
||||
os.environ["FUT_ACCOUNT_PATH"] = os.path.join(state, "active_account.json")
|
||||
os.environ["FUT_PROFILE_ROOT"] = os.path.join(state, "accounts")
|
||||
os.environ.pop("FUT_PROFILE", None)
|
||||
|
||||
import fut_account
|
||||
import fut_store
|
||||
import fut_accounts
|
||||
import utas_server
|
||||
importlib.reload(fut_account)
|
||||
importlib.reload(fut_store)
|
||||
importlib.reload(fut_accounts)
|
||||
importlib.reload(utas_server)
|
||||
|
||||
us = utas_server
|
||||
CLEAN, SENT = us.FIFA17_MODE_CLEAN, us.FIFA17_MODE_SENTINEL
|
||||
|
||||
_orig_visible = us.visible_unopened_packs
|
||||
|
||||
def set_zero_packs():
|
||||
us.visible_unopened_packs = lambda: []
|
||||
|
||||
def set_real_pack():
|
||||
us.visible_unopened_packs = lambda: [REAL_PACK_ID]
|
||||
|
||||
def reset_state():
|
||||
us._FIFA17_SESSIONS.clear()
|
||||
us._FIFA17_PENDING.clear()
|
||||
|
||||
def auth(sid, ip, persona=PERSONA):
|
||||
"""Simulate /ut/auth opening a per-login session with a chosen sid."""
|
||||
us.fifa17_open_session(sid, ip, persona)
|
||||
|
||||
def register(ip, version, persona=PERSONA, pid=4242):
|
||||
return us.fifa17_capability_route(_H(ip, {
|
||||
"capability": "empty_mypacks_resolver", "version": version,
|
||||
"personaId": persona, "fifaPid": pid,
|
||||
}))
|
||||
|
||||
def store(sid, ip):
|
||||
status, cat = us.store_catalog(_H(ip, sid=sid))
|
||||
assert status == 200, status
|
||||
return _ids(cat)
|
||||
|
||||
def mode_of(sid):
|
||||
return us._FIFA17_SESSIONS[sid]["mode"]
|
||||
|
||||
try:
|
||||
# ---- A. no capability, zero packs -> sentinel ----------------------
|
||||
reset_state(); set_zero_packs()
|
||||
auth("sidA", "10.0.0.1")
|
||||
assert SENTINEL_ID in store("sidA", "10.0.0.1")
|
||||
assert mode_of("sidA") == SENT
|
||||
print("A no-capability zero-packs -> sentinel: OK")
|
||||
|
||||
# ---- B. verified v1, zero packs -> clean ---------------------------
|
||||
reset_state(); set_zero_packs()
|
||||
auth("sidB", "10.0.0.2")
|
||||
assert register("10.0.0.2", 1)[0] == 200
|
||||
ids = store("sidB", "10.0.0.2")
|
||||
assert SENTINEL_ID not in ids, ids
|
||||
assert mode_of("sidB") == CLEAN
|
||||
print("B verified-v1 zero-packs -> clean: OK")
|
||||
|
||||
# ---- C. real pack + no capability -> genuine, no sentinel ----------
|
||||
reset_state(); set_real_pack()
|
||||
auth("sidC", "10.0.0.3")
|
||||
ids = store("sidC", "10.0.0.3")
|
||||
assert REAL_PACK_ID in ids and SENTINEL_ID not in ids, ids
|
||||
print("C real-pack no-capability -> genuine, no sentinel: OK")
|
||||
|
||||
# ---- D. real pack + capability -> genuine, no sentinel -------------
|
||||
reset_state(); set_real_pack()
|
||||
auth("sidD", "10.0.0.4"); register("10.0.0.4", 1)
|
||||
ids = store("sidD", "10.0.0.4")
|
||||
assert REAL_PACK_ID in ids and SENTINEL_ID not in ids, ids
|
||||
print("D real-pack capability -> genuine, no sentinel: OK")
|
||||
|
||||
# ---- E. unsupported version / capability -> 400 + sentinel ---------
|
||||
reset_state(); set_zero_packs()
|
||||
auth("sidE", "10.0.0.5")
|
||||
assert register("10.0.0.5", 2)[0] == 400
|
||||
assert register("10.0.0.5", 99)[0] == 400
|
||||
assert us.fifa17_capability_route(
|
||||
_H("10.0.0.5", {"capability": "bogus", "version": 1}))[0] == 400
|
||||
assert SENTINEL_ID in store("sidE", "10.0.0.5")
|
||||
assert mode_of("sidE") == SENT
|
||||
print("E unsupported version/capability -> 400 + sentinel: OK")
|
||||
|
||||
# ---- F. late capability after sentinel freeze -> sentinel ----------
|
||||
reset_state(); set_zero_packs()
|
||||
auth("sidF", "10.0.0.6")
|
||||
assert SENTINEL_ID in store("sidF", "10.0.0.6") # freezes sentinel
|
||||
assert register("10.0.0.6", 1)[0] == 200 # session frozen -> ignored-late
|
||||
assert SENTINEL_ID in store("sidF", "10.0.0.6")
|
||||
assert mode_of("sidF") == SENT
|
||||
print("F late capability after sentinel freeze -> sentinel: OK")
|
||||
|
||||
# ---- G. capability disappears after clean freeze -> clean ----------
|
||||
reset_state(); set_zero_packs()
|
||||
auth("sidG", "10.0.0.7"); register("10.0.0.7", 1)
|
||||
assert SENTINEL_ID not in store("sidG", "10.0.0.7") # freezes clean
|
||||
us._FIFA17_SESSIONS["sidG"]["resolver"] = None # capability vanishes
|
||||
assert SENTINEL_ID not in store("sidG", "10.0.0.7")
|
||||
assert mode_of("sidG") == CLEAN
|
||||
print("G capability disappears after clean freeze -> clean: OK")
|
||||
|
||||
# ---- H. two IPs (A verified, B none) -> no global leak -------------
|
||||
reset_state(); set_zero_packs()
|
||||
auth("sidH1", "10.0.1.1"); register("10.0.1.1", 1)
|
||||
auth("sidH2", "10.0.1.2")
|
||||
assert SENTINEL_ID not in store("sidH1", "10.0.1.1")
|
||||
assert SENTINEL_ID in store("sidH2", "10.0.1.2")
|
||||
print("H two IPs (A clean, B sentinel) -> no global leak: OK")
|
||||
|
||||
# ---- I. new session after reset -> fresh unpatched -> sentinel -----
|
||||
reset_state(); set_zero_packs()
|
||||
auth("sidI1", "10.0.1.3"); register("10.0.1.3", 1)
|
||||
assert SENTINEL_ID not in store("sidI1", "10.0.1.3") # A clean
|
||||
us.fifa17_clear_pending("10.0.1.3") # relaunch boundary
|
||||
auth("sidI2", "10.0.1.3") # new SID, autopatch failed
|
||||
assert SENTINEL_ID in store("sidI2", "10.0.1.3")
|
||||
print("I new session after reset -> sentinel (no cross-process leak): OK")
|
||||
|
||||
# ---- J. autopatch mismatch => never registers -> sentinel ----------
|
||||
reset_state(); set_zero_packs()
|
||||
auth("sidJ", "10.0.1.4")
|
||||
assert SENTINEL_ID in store("sidJ", "10.0.1.4")
|
||||
print("J autopatch mismatch (never registers) -> sentinel: OK")
|
||||
|
||||
# ---- K. SAME IP, two sessions: patched A clean, unpatched B sent ---
|
||||
reset_state(); set_zero_packs()
|
||||
IP = "10.0.2.1"
|
||||
auth("sidK_A", IP)
|
||||
assert register(IP, 1)[0] == 200 # A sole candidate -> bound
|
||||
auth("sidK_B", IP) # B joins, never registers
|
||||
assert SENTINEL_ID not in store("sidK_A", IP)
|
||||
assert SENTINEL_ID in store("sidK_B", IP)
|
||||
print("K same-IP two sessions -> A clean, B sentinel: OK")
|
||||
|
||||
# ---- L. SAME IP+persona relaunch: old ok, new not -> new sentinel --
|
||||
reset_state(); set_zero_packs()
|
||||
IP = "10.0.2.2"
|
||||
auth("sidL_old", IP, PERSONA); register(IP, 1, PERSONA)
|
||||
assert SENTINEL_ID not in store("sidL_old", IP)
|
||||
us.fifa17_clear_pending(IP)
|
||||
auth("sidL_new", IP, PERSONA) # same persona, unverified
|
||||
assert SENTINEL_ID in store("sidL_new", IP)
|
||||
print("L same-IP+persona relaunch -> new session sentinel: OK")
|
||||
|
||||
# ---- M. SAME IP, failed-patch second session -----------------------
|
||||
reset_state(); set_zero_packs()
|
||||
IP = "10.0.2.3"
|
||||
auth("sidM1", IP); register(IP, 1)
|
||||
assert SENTINEL_ID not in store("sidM1", IP)
|
||||
auth("sidM2", IP) # autopatch failed
|
||||
assert SENTINEL_ID in store("sidM2", IP)
|
||||
print("M same-IP failed-patch second session -> sentinel: OK")
|
||||
|
||||
# ---- N. late reg when sessions frozen -> no active session change --
|
||||
reset_state(); set_zero_packs()
|
||||
IP = "10.0.2.4"
|
||||
auth("sidN1", IP); register(IP, 1)
|
||||
assert SENTINEL_ID not in store("sidN1", IP) # N1 frozen clean
|
||||
auth("sidN2", IP)
|
||||
assert SENTINEL_ID in store("sidN2", IP) # N2 frozen sentinel
|
||||
assert register(IP, 1)[0] == 200 # late: both frozen -> ignored
|
||||
assert SENTINEL_ID not in store("sidN1", IP) # unchanged
|
||||
assert SENTINEL_ID in store("sidN2", IP) # unchanged
|
||||
print("N late registration does not modify active sessions: OK")
|
||||
|
||||
# ---- O. session cleanup / TTL expiry -> capability gone ------------
|
||||
reset_state(); set_zero_packs()
|
||||
IP = "10.0.2.5"
|
||||
auth("sidO", IP); register(IP, 1)
|
||||
assert SENTINEL_ID not in store("sidO", IP) # clean while live
|
||||
us._FIFA17_SESSIONS["sidO"]["last_seen"] = (
|
||||
us._fifa17_now() - us.FIFA17_SESSION_TTL - 10.0)
|
||||
store("sidUNKNOWN", IP) # any op triggers reap
|
||||
assert "sidO" not in us._FIFA17_SESSIONS, "expired session not reaped"
|
||||
assert SENTINEL_ID in store("sidO", IP) # gone -> sentinel
|
||||
print("O session cleanup / TTL expiry -> sentinel: OK")
|
||||
|
||||
# ---- P. duplicate registration -> idempotent, no post-freeze change
|
||||
reset_state(); set_zero_packs()
|
||||
IP = "10.0.2.6"
|
||||
auth("sidP", IP)
|
||||
assert register(IP, 1)[0] == 200 # bound
|
||||
assert register(IP, 1)[0] == 200 # duplicate -> ignored-late
|
||||
assert SENTINEL_ID not in store("sidP", IP) # still clean
|
||||
assert register(IP, 1)[0] == 200 # after freeze
|
||||
assert SENTINEL_ID not in store("sidP", IP) # unchanged
|
||||
assert mode_of("sidP") == CLEAN
|
||||
print("P duplicate registration -> idempotent: OK")
|
||||
|
||||
# ---- Q. register-before-login: pending consumed at auth -> clean ---
|
||||
reset_state(); set_zero_packs()
|
||||
IP = "10.0.2.7"
|
||||
assert register(IP, 1)[0] == 200 # no session yet -> pending
|
||||
assert (IP, PERSONA) in us._FIFA17_PENDING
|
||||
auth("sidQ", IP, PERSONA) # consumes pending
|
||||
assert (IP, PERSONA) not in us._FIFA17_PENDING # single-use
|
||||
assert SENTINEL_ID not in store("sidQ", IP)
|
||||
assert mode_of("sidQ") == CLEAN
|
||||
print("Q register-before-login pending consumed -> clean: OK")
|
||||
|
||||
# ---- R. topology freeze immutable per SID; new SID decides fresh ----
|
||||
# F3 invariant: once a SID's store topology is decided it NEVER flips,
|
||||
# in either direction, and a different SID may decide differently.
|
||||
reset_state(); set_zero_packs()
|
||||
IP = "10.0.2.8"
|
||||
# frozen Sentinel never becomes Clean, even if a capability appears later
|
||||
auth("sidR_s", IP)
|
||||
assert SENTINEL_ID in store("sidR_s", IP) # freeze Sentinel
|
||||
register(IP, 1)
|
||||
us._FIFA17_SESSIONS["sidR_s"]["resolver"] = 1 # force-present capability
|
||||
assert SENTINEL_ID in store("sidR_s", IP) # STILL Sentinel
|
||||
assert mode_of("sidR_s") == SENT
|
||||
# frozen Clean never becomes Sentinel, even if the capability is wiped
|
||||
auth("sidR_c", IP); register(IP, 1)
|
||||
assert SENTINEL_ID not in store("sidR_c", IP) # freeze Clean
|
||||
us._FIFA17_SESSIONS["sidR_c"]["resolver"] = None # capability vanishes
|
||||
assert SENTINEL_ID not in store("sidR_c", IP) # STILL Clean
|
||||
assert mode_of("sidR_c") == CLEAN
|
||||
# a fresh SID (same IP) decides independently
|
||||
auth("sidR_new", IP)
|
||||
assert SENTINEL_ID in store("sidR_new", IP)
|
||||
print("R topology freeze immutable per SID; new SID fresh: OK")
|
||||
|
||||
finally:
|
||||
us.visible_unopened_packs = _orig_visible
|
||||
|
||||
print("capability negotiation matrix A-R: OK")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
raise SystemExit(main())
|
||||
Executable
+136
@@ -0,0 +1,136 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Regression tests for the empty-My-Packs FIFA 17 compatibility workaround (bug 6c).
|
||||
|
||||
Pins the behavior store_catalog() now depends on:
|
||||
- unopenedPackIds == [] -> exactly one synthetic active `mypacks` placeholder id 65534
|
||||
- unopenedPackIds == [70] -> no synthetic placeholder; the genuine owned pack is shown
|
||||
- synthetic id 65534 stays economy-safe (non-resolvable, non-openable, non-granting)
|
||||
- normal store packs (1/5/6/7) are untouched by the empty-state behavior
|
||||
|
||||
See docs/evidence/STORE_TILE_6C.md and FIFA17_EMPTY_MYPACKS_CLIENT_CONTRACT.md.
|
||||
Standalone unit test in the project style: `python3 test_empty_mypacks.py`.
|
||||
"""
|
||||
import importlib
|
||||
import os
|
||||
import sys
|
||||
import tempfile
|
||||
|
||||
TOOLS = os.path.dirname(os.path.abspath(__file__))
|
||||
if TOOLS not in sys.path:
|
||||
sys.path.insert(0, TOOLS)
|
||||
|
||||
SENTINEL_ID = 65534
|
||||
|
||||
|
||||
def _set_unopened(fut_store, ids):
|
||||
"""Deterministically set the active profile's owned unopened packs."""
|
||||
p = fut_store.STORE.load()
|
||||
p["unopenedPackIds"] = list(ids)
|
||||
fut_store.STORE._save()
|
||||
|
||||
|
||||
def _mypacks(catalog):
|
||||
return [p for p in catalog["purchase"]
|
||||
if (p.get("displayGroup") or {}).get("value") == "mypacks"]
|
||||
|
||||
|
||||
def _fake_request(command, body):
|
||||
class _H:
|
||||
pass
|
||||
h = _H()
|
||||
h.command = command
|
||||
h._body = body
|
||||
return h
|
||||
|
||||
|
||||
def main():
|
||||
with tempfile.TemporaryDirectory() as state:
|
||||
os.environ["FUT_ACCOUNT_PATH"] = os.path.join(state, "active_account.json")
|
||||
os.environ["FUT_PROFILE_ROOT"] = os.path.join(state, "accounts")
|
||||
os.environ.pop("FUT_PROFILE", None)
|
||||
|
||||
import fut_account
|
||||
import fut_store
|
||||
import fut_accounts
|
||||
import utas_server
|
||||
importlib.reload(fut_account)
|
||||
importlib.reload(fut_store)
|
||||
importlib.reload(fut_accounts)
|
||||
importlib.reload(utas_server)
|
||||
|
||||
fut_accounts.activate({"personaId": 111001, "personaName": "TEST_A"})
|
||||
catalog_ids = [p["id"] for p in fut_store.PACK_CATALOG]
|
||||
|
||||
# ---- A. Empty unopened packs -> one active synthetic 65534 placeholder ----
|
||||
_set_unopened(fut_store, [])
|
||||
utas_server._OPENED_PACK_GRACE.clear()
|
||||
status, cat = utas_server.store_catalog(None)
|
||||
assert status == 200
|
||||
myp = _mypacks(cat)
|
||||
assert len(myp) == 1, "expected exactly one mypacks entry, got %r" % myp
|
||||
s = myp[0]
|
||||
assert s["id"] == SENTINEL_ID, s
|
||||
assert s["state"] == "active", s # the P2 fix: active, not inactive
|
||||
assert (s.get("displayGroup") or {}).get("value") == "mypacks", s
|
||||
assert SENTINEL_ID not in catalog_ids, "65534 must not be in PACK_CATALOG"
|
||||
assert fut_store.pack_by_id(SENTINEL_ID) is None
|
||||
print("A empty-state active placeholder: PASS")
|
||||
|
||||
# ---- D (empty half). Normal packs untouched in empty state ----
|
||||
norm = {p["id"]: p for p in cat["purchase"] if p["id"] in (1, 5, 6, 7)}
|
||||
assert set(norm) == {1, 5, 6, 7}, sorted(norm)
|
||||
assert all(norm[i]["state"] == "active" for i in norm), norm
|
||||
assert norm[1]["packType"] == "BRONZE" and norm[1]["description"] == "Bronze Pack"
|
||||
|
||||
# ---- B. Non-empty unopened packs -> NO synthetic; genuine owned pack shown ----
|
||||
_set_unopened(fut_store, [70])
|
||||
utas_server._OPENED_PACK_GRACE.clear()
|
||||
status, cat = utas_server.store_catalog(None)
|
||||
assert status == 200
|
||||
ids = [p["id"] for p in cat["purchase"]]
|
||||
assert SENTINEL_ID not in ids, "synthetic placeholder must be suppressed when a pack exists"
|
||||
myp = _mypacks(cat)
|
||||
assert len(myp) == 1 and myp[0]["id"] == 70, myp
|
||||
assert myp[0]["state"] == "active" and myp[0]["unopened"] is True, myp[0]
|
||||
# normal packs still intact alongside the owned pack
|
||||
assert {1, 5, 6, 7}.issubset(set(ids)), sorted(ids)
|
||||
print("B non-empty-state genuine pack: PASS")
|
||||
|
||||
# ---- C. Economy safety of the synthetic placeholder ----
|
||||
_set_unopened(fut_store, [])
|
||||
utas_server._OPENED_PACK_GRACE.clear()
|
||||
coins0 = fut_store.STORE.coins()
|
||||
items0 = len(fut_store.STORE.items())
|
||||
next0 = fut_store.STORE.load()["nextItemId"]
|
||||
|
||||
assert fut_store.pack_by_id(SENTINEL_ID) is None
|
||||
|
||||
# store_buy: a confirmed-buy transaction for 65534 must be a no-op {}
|
||||
status, body = utas_server.store_buy(
|
||||
_fake_request("PUT", b'{"packId":65534,"state":"TRANSACTIONCREATED"}'))
|
||||
assert status == 200 and body == {}, (status, body)
|
||||
|
||||
# purchased_items: POST buy for 65534 must not open/grant anything
|
||||
status, body = utas_server.purchased_items(
|
||||
_fake_request("POST", b'{"packId":65534,"useCredits":1,"usePreOrder":0,"currency":"COINS"}'))
|
||||
assert status == 200, (status, body)
|
||||
assert "createPackResponse" not in body, body
|
||||
|
||||
# 65534 cannot enter the owned-pack pile (not a catalog pack)
|
||||
assert fut_store.STORE.grant_unopened_pack(SENTINEL_ID) is False
|
||||
assert SENTINEL_ID not in fut_store.STORE.unopened_packs()
|
||||
|
||||
# nothing mutated
|
||||
assert fut_store.STORE.coins() == coins0, (fut_store.STORE.coins(), coins0)
|
||||
assert len(fut_store.STORE.items()) == items0
|
||||
assert fut_store.STORE.load()["nextItemId"] == next0
|
||||
assert not any(i.get("id") == SENTINEL_ID or i.get("resourceId") == SENTINEL_ID
|
||||
for i in fut_store.STORE.items())
|
||||
print("C economy safety (65534 non-openable / non-granting): PASS")
|
||||
|
||||
print("empty My Packs compatibility: PASS")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
raise SystemExit(main())
|
||||
@@ -0,0 +1,76 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Read the FIFA 17 TRADING gate byte out of the live client. READ-ONLY.
|
||||
|
||||
Extends tools/gate_byte_probe.py with vtable slot +0x270 (IS_TRADING_ENABLED,
|
||||
displacement 0x1fd2e) plus the two pile-size dwords, which the transfer-market
|
||||
analysis names as the market screen's CardsDLL-supplied inputs.
|
||||
|
||||
Opens /proc/<pid>/mem O_RDONLY and preads. Nothing here can write.
|
||||
"""
|
||||
import os, struct
|
||||
|
||||
pid = None
|
||||
for d in os.listdir('/proc'):
|
||||
if d.isdigit():
|
||||
try:
|
||||
if open('/proc/%s/comm' % d).read().strip() == 'FIFA17.exe':
|
||||
pid = int(d)
|
||||
break
|
||||
except Exception:
|
||||
pass
|
||||
assert pid, "FIFA17.exe not running"
|
||||
|
||||
base = None
|
||||
for ln in open('/proc/%d/maps' % pid):
|
||||
if 'CardsDLL' in ln:
|
||||
base = int(ln.split('-')[0], 16)
|
||||
assert base, "CardsDLL not mapped (client has not reached Ultimate Team)"
|
||||
slide = base - 0x180000000
|
||||
|
||||
fd = os.open('/proc/%d/mem' % pid, os.O_RDONLY)
|
||||
|
||||
|
||||
def rd(va, n):
|
||||
return os.pread(fd, n, va)
|
||||
|
||||
|
||||
# Control: the FNV atom-hash prologue must match the on-disk PE before any other
|
||||
# address is trusted.
|
||||
pe = open('/mnt/games/FIFA 17/CardsDLL_Win64_retail.dll', 'rb').read()
|
||||
|
||||
|
||||
def f(va):
|
||||
return va - 0x180000000 - 0x1000 + 0x400
|
||||
|
||||
|
||||
ok = pe[f(0x180180d00):f(0x180180d00) + 32] == rd(0x180180d00 + slide, 32)
|
||||
print("pid=%d slide=%#x FNV control=%s" % (pid, slide, "MATCH" if ok else "MISMATCH"))
|
||||
assert ok, "slide not proven; refusing to read further"
|
||||
|
||||
obj = struct.unpack('<Q', rd(0x1802e6398 + slide, 8))[0]
|
||||
vt = struct.unpack('<Q', rd(obj, 8))[0]
|
||||
print("model=%#x vtable(static)=%#x" % (obj, vt - slide))
|
||||
|
||||
SLOTS = [
|
||||
(0x270, 'IS_TRADING_ENABLED '),
|
||||
(0x2b0, 'IS_FRIENDLY_SEASON '),
|
||||
(0x2c8, 'IS_DRAFT_MODE '),
|
||||
(0x2e0, 'packOpeningAnimation '),
|
||||
]
|
||||
print("\n-- gate bytes decoded from their accessor stubs --")
|
||||
for off, name in SLOTS:
|
||||
slot = struct.unpack('<Q', rd(vt + off, 8))[0]
|
||||
stub = rd(slot, 8)
|
||||
if stub[:3] == b'\x0f\xb6\x81':
|
||||
disp = struct.unpack('<I', stub[3:7])[0]
|
||||
val = rd(obj + disp, 1)[0]
|
||||
print(" slot +%#05x %s disp=%#x VALUE=%d" % (off, name, disp, val))
|
||||
else:
|
||||
print(" slot +%#05x %s NOT a movzx stub: %s" % (off, name, stub.hex()))
|
||||
|
||||
print("\n-- market screen inputs --")
|
||||
for disp, name in [(0x1fd1c, 'TRADE_PILE_SIZE'), (0x1fd20, 'watchListSize '),
|
||||
(0x1fd2e, 'tradingEnabled '), (0x1fd2f, 'storeEnabled ')]:
|
||||
print(" model+%#x %s = %d" % (disp, name, rd(obj + disp, 1)[0]))
|
||||
|
||||
os.close(fd)
|
||||
@@ -11,7 +11,7 @@ Rules (from CardsDLL 0x18016D230 / 0x1801a33a0):
|
||||
* body must parse as JSON (else err 0x3E6); 204 + empty body is accepted.
|
||||
* [resp+0x1c] == 0 is the success test; 404 is OK only on the first user GET.
|
||||
"""
|
||||
import copy, datetime, json, os, random, re, sys, http.server
|
||||
import copy, datetime, json, os, random, re, sys, threading, time, http.server
|
||||
from urllib.parse import parse_qs, urlencode, urlsplit, urlunsplit
|
||||
|
||||
sys.path.insert(0, os.path.dirname(os.path.abspath(__file__)))
|
||||
@@ -52,6 +52,173 @@ def visible_unopened_packs():
|
||||
return STORE.unopened_packs() + list(_OPENED_PACK_GRACE)
|
||||
|
||||
|
||||
# ---- FIFA17 empty-My-Packs capability negotiation (PER-SESSION, hardened) ----
|
||||
# The synthetic 65534 sentinel (store_catalog) is the universal P2 fallback. It is
|
||||
# suppressed for ONE FIFA session only when the launcher has registered that THAT
|
||||
# process positively verified the CardsDLL resolver guard (RVA 0x14858 == JG).
|
||||
#
|
||||
# BINDING: the authoritative key is the per-login-unique UTAS session id (X-UT-SID),
|
||||
# minted fresh at every /ut/auth and echoed by the client on every later call incl.
|
||||
# /store/purchasegroup (live-confirmed present on real store requests). The initial
|
||||
# prototype keyed on source IP ALONE; that was rejected because two FIFA processes
|
||||
# (concurrent or relaunched) share an IP, so an unverified process could inherit a
|
||||
# verified one's clean topology and crash. IP + persona are retained only as
|
||||
# auxiliary data: a fail-closed sid/ip sanity check and the (ip,persona) key for the
|
||||
# short-lived launcher->session hand-off.
|
||||
#
|
||||
# The launcher verifies out-of-band (autopatch) and cannot know the SID, so its
|
||||
# registration is staged as a SINGLE-USE, short-TTL PENDING keyed by (ip,persona)
|
||||
# and bound to exactly one FIFA session (directly if that session already exists,
|
||||
# else consumed at the session's login or its first store request). Fail-closed
|
||||
# everywhere: unknown / expired / absent / ambiguous / late => sentinel.
|
||||
# See docs/plans/FIFA17_PATCHED_CLIENT_CAPABILITY.md (§Session binding).
|
||||
FIFA17_EMPTY_MYPACKS_RESOLVER_VERSION = 1
|
||||
FIFA17_MODE_SENTINEL = "sentinel"
|
||||
FIFA17_MODE_CLEAN = "clean-v1"
|
||||
FIFA17_SESSION_TTL = 3600.0 # reap a FIFA session after this many idle seconds
|
||||
FIFA17_PENDING_TTL = 120.0 # a launcher capability may await its session this long
|
||||
|
||||
# sid -> {"ip","persona","resolver": Optional[int],"mode": Optional[str],"created","last_seen"}
|
||||
_FIFA17_SESSIONS = {}
|
||||
# (ip, persona) -> {"resolver": int, "ts"}: single-use launcher->session hand-off.
|
||||
_FIFA17_PENDING = {}
|
||||
_FIFA17_LOCK = threading.Lock()
|
||||
|
||||
|
||||
def _fifa17_now():
|
||||
return time.monotonic()
|
||||
|
||||
|
||||
def _fifa17_client_ip(h):
|
||||
"""Peer IP for the handler, or None when unavailable (e.g. h is None)."""
|
||||
try:
|
||||
return h.client_address[0]
|
||||
except Exception:
|
||||
return None
|
||||
|
||||
|
||||
def _fifa17_sid(h):
|
||||
"""The client's UTAS session id (X-UT-SID) for this request, or None."""
|
||||
try:
|
||||
return h.headers.get("X-UT-SID")
|
||||
except Exception:
|
||||
return None
|
||||
|
||||
|
||||
def _fifa17_sidlog(sid):
|
||||
"""A short, non-secret tag for correlating a session in logs."""
|
||||
return ("\u2026" + sid[-6:]) if sid else "-"
|
||||
|
||||
|
||||
def _fifa17_mint_sid():
|
||||
"""A fresh, per-login-unique UTAS session id (same shape/length as the legacy
|
||||
constant). Uniqueness -- not unpredictability -- is what the binding needs."""
|
||||
return "OPENFUT-SID-%016X" % random.getrandbits(64)
|
||||
|
||||
|
||||
def _fifa17_reap_locked(now):
|
||||
for sid in [s for s, r in _FIFA17_SESSIONS.items()
|
||||
if now - r["last_seen"] > FIFA17_SESSION_TTL]:
|
||||
del _FIFA17_SESSIONS[sid]
|
||||
for key in [k for k, p in _FIFA17_PENDING.items()
|
||||
if now - p["ts"] > FIFA17_PENDING_TTL]:
|
||||
del _FIFA17_PENDING[key]
|
||||
|
||||
|
||||
def _fifa17_take_pending_locked(ip, persona, now):
|
||||
"""Single-use: remove and return a fresh pending resolver for (ip,persona)."""
|
||||
p = _FIFA17_PENDING.get((ip, persona))
|
||||
if p is not None and now - p["ts"] <= FIFA17_PENDING_TTL:
|
||||
del _FIFA17_PENDING[(ip, persona)]
|
||||
return p["resolver"]
|
||||
return None
|
||||
|
||||
|
||||
def fifa17_session_known(sid):
|
||||
"""True if sid is a live session (or the legacy constant, accepted by the
|
||||
retired security-question gate ONLY -- never used to grant clean store mode)."""
|
||||
if sid == SID:
|
||||
return True
|
||||
with _FIFA17_LOCK:
|
||||
return sid in _FIFA17_SESSIONS
|
||||
|
||||
|
||||
def fifa17_open_session(sid, ip, persona):
|
||||
"""/ut/auth: open a per-login session and bind any pending launcher capability
|
||||
for (ip,persona) that arrived before login."""
|
||||
if not sid:
|
||||
return
|
||||
now = _fifa17_now()
|
||||
with _FIFA17_LOCK:
|
||||
_fifa17_reap_locked(now)
|
||||
resolver = _fifa17_take_pending_locked(ip, persona, now)
|
||||
_FIFA17_SESSIONS[sid] = {"ip": ip, "persona": persona, "resolver": resolver,
|
||||
"mode": None, "created": now, "last_seen": now}
|
||||
log("[fifa17-store] session opened %s (ip=%s persona=%s resolver=%s)"
|
||||
% (_fifa17_sidlog(sid), ip, persona, resolver))
|
||||
|
||||
|
||||
def fifa17_clear_pending(ip):
|
||||
"""/openfut/account/sync hygiene: drop any stale pending for this machine so a
|
||||
new launch's unverified session cannot inherit a leftover capability."""
|
||||
now = _fifa17_now()
|
||||
with _FIFA17_LOCK:
|
||||
_fifa17_reap_locked(now)
|
||||
for key in [k for k in _FIFA17_PENDING if k[0] == ip]:
|
||||
del _FIFA17_PENDING[key]
|
||||
|
||||
|
||||
def fifa17_register_capability(ip, persona, version):
|
||||
"""Launcher registration. Returns one of:
|
||||
"bound" exactly one live, unfrozen, unbound session for (ip,persona)
|
||||
existed (registration after login -- the common case): bound now.
|
||||
"pending" no session for (ip,persona) yet (before login): staged single-use.
|
||||
"ignored-late" a session for (ip,persona) exists but is frozen or ambiguous
|
||||
(>1 unbound): NOT staged, so no later/unverified process can
|
||||
inherit it. Fail-closed.
|
||||
Never authorizes more than one session."""
|
||||
now = _fifa17_now()
|
||||
with _FIFA17_LOCK:
|
||||
_fifa17_reap_locked(now)
|
||||
sessions = [r for r in _FIFA17_SESSIONS.values()
|
||||
if r["ip"] == ip and r["persona"] == persona]
|
||||
candidates = [r for r in sessions if r["mode"] is None and r["resolver"] is None]
|
||||
if len(candidates) == 1:
|
||||
candidates[0]["resolver"] = version
|
||||
return "bound"
|
||||
if sessions:
|
||||
return "ignored-late"
|
||||
_FIFA17_PENDING[(ip, persona)] = {"resolver": version, "ts": now}
|
||||
return "pending"
|
||||
|
||||
|
||||
def fifa17_empty_mypacks_mode(sid, ip):
|
||||
"""Freeze (once) and return the empty-My-Packs mode for FIFA session `sid`.
|
||||
Freeze point = the first /store/purchasegroup of the session. Fail-closed: an
|
||||
unknown session, or a sid presented from a different IP than it was opened on,
|
||||
resolves to the sentinel."""
|
||||
now = _fifa17_now()
|
||||
with _FIFA17_LOCK:
|
||||
_fifa17_reap_locked(now)
|
||||
rec = _FIFA17_SESSIONS.get(sid)
|
||||
if rec is None:
|
||||
return FIFA17_MODE_SENTINEL
|
||||
rec["last_seen"] = now
|
||||
if rec["ip"] is not None and ip is not None and rec["ip"] != ip:
|
||||
log("[fifa17-store] sid %s ip mismatch (session %s != request %s) -> sentinel"
|
||||
% (_fifa17_sidlog(sid), rec["ip"], ip))
|
||||
return FIFA17_MODE_SENTINEL
|
||||
if rec["mode"] is None:
|
||||
if rec["resolver"] is None:
|
||||
rec["resolver"] = _fifa17_take_pending_locked(rec["ip"], rec["persona"], now)
|
||||
rec["mode"] = (FIFA17_MODE_CLEAN
|
||||
if rec["resolver"] == FIFA17_EMPTY_MYPACKS_RESOLVER_VERSION
|
||||
else FIFA17_MODE_SENTINEL)
|
||||
log("[fifa17-store] session %s empty-mypacks mode frozen: %s"
|
||||
% (_fifa17_sidlog(sid), rec["mode"]))
|
||||
return rec["mode"]
|
||||
|
||||
|
||||
def now():
|
||||
return datetime.datetime.now().strftime("%Y-%m-%d %H:%M:%S")
|
||||
|
||||
@@ -102,7 +269,7 @@ def security_question_route(h):
|
||||
well-formed value without retaining or comparing it. Account selection has
|
||||
already initialized the server-owned verified compatibility state.
|
||||
"""
|
||||
if h.headers.get("X-UT-SID") != SID:
|
||||
if not fifa17_session_known(h.headers.get("X-UT-SID")):
|
||||
log("[FUT] security-question request has no matching OpenFUT session")
|
||||
return 400, {"reason": "invalid_session"}
|
||||
|
||||
@@ -193,11 +360,19 @@ def auth_body(h=None):
|
||||
except Exception as e: # adoption must never break auth
|
||||
log(" AUTH: adopt failed (%s: %s) -- keeping %s/%r"
|
||||
% (type(e).__name__, e, before[0], before[1]))
|
||||
return {"protocol": 1, "sid": SID, "serverTime": now(), "lastOnlineTime": now()}
|
||||
sid = _fifa17_mint_sid()
|
||||
fifa17_open_session(sid, _fifa17_client_ip(h), ACCOUNT.persona_id)
|
||||
return {"protocol": 1, "sid": sid, "serverTime": now(), "lastOnlineTime": now()}
|
||||
|
||||
|
||||
def account_sync_route(h):
|
||||
"""Launcher-only active-profile selection, before LSX/Blaze login starts."""
|
||||
# Pre-launch hygiene: drop any stale launcher capability still pending for this
|
||||
# machine so a new launch's unverified FIFA session cannot inherit it. The real
|
||||
# per-process session is opened later, at /ut/auth (keyed by the minted X-UT-SID).
|
||||
ip = _fifa17_client_ip(h)
|
||||
fifa17_clear_pending(ip)
|
||||
log(" ACCOUNT: cleared stale FIFA17 pending capability for ip %s" % ip)
|
||||
try:
|
||||
body = json.loads(h._body.decode("utf-8")) if getattr(h, "_body", b"") else {}
|
||||
account = activate_account(body)
|
||||
@@ -209,6 +384,33 @@ def account_sync_route(h):
|
||||
return 200, {"account": account, "status": "OK"}
|
||||
|
||||
|
||||
def fifa17_capability_route(h):
|
||||
"""POST /openfut/fifa17/capability -- launcher registers a verified resolver
|
||||
capability for the current FIFA process (bound to the peer IP). Fail-closed:
|
||||
anything but capability==empty_mypacks_resolver && version==current is a 400
|
||||
that records NOTHING (the session stays on the sentinel fallback)."""
|
||||
try:
|
||||
body = json.loads(h._body.decode("utf-8")) if getattr(h, "_body", b"") else {}
|
||||
except Exception:
|
||||
return 400, {"error": "unsupported capability"}
|
||||
if not isinstance(body, dict):
|
||||
return 400, {"error": "unsupported capability"}
|
||||
try:
|
||||
version = int(body.get("version"))
|
||||
except (TypeError, ValueError):
|
||||
return 400, {"error": "unsupported capability"}
|
||||
if (body.get("capability") != "empty_mypacks_resolver"
|
||||
or version != FIFA17_EMPTY_MYPACKS_RESOLVER_VERSION):
|
||||
return 400, {"error": "unsupported capability"}
|
||||
ip = _fifa17_client_ip(h)
|
||||
persona = body.get("personaId")
|
||||
fifa_pid = body.get("fifaPid", "?")
|
||||
status = fifa17_register_capability(ip, persona, version)
|
||||
log("[fifa17-store] capability empty_mypacks_resolver=%s ip=%s persona=%s "
|
||||
"fifa_pid=%s -> %s" % (version, ip, persona, fifa_pid, status))
|
||||
return 200, {"status": "OK"}
|
||||
|
||||
|
||||
def current_squad():
|
||||
"""The squad the client should see: the persisted one (item refs re-embedded
|
||||
from the club) or the seed ladder squad on first run.
|
||||
@@ -1203,6 +1405,10 @@ ROUTES = [
|
||||
# Launcher control-plane endpoint. It is intentionally outside /ut so FIFA
|
||||
# never calls it; launch is blocked unless this succeeds first.
|
||||
(re.compile(r"^/openfut/account/sync$"), lambda m, h: account_sync_route(h)),
|
||||
# Launcher registers a verified per-FIFA-process resolver capability (bound to
|
||||
# peer IP). Adjacent to account/sync, above the generic /ut routes; FIFA never
|
||||
# calls it. Fail-closed: absent/late/wrong-version => sentinel (store_catalog).
|
||||
(re.compile(r"^/openfut/fifa17/capability$"), lambda m, h: fifa17_capability_route(h)),
|
||||
# ---- FUT item-definition endpoints (must precede generic /item, /user) ----
|
||||
(re.compile(G + r"/item/resource"), lambda m, h: defs_route(h)),
|
||||
(re.compile(G + r"/defid"), lambda m, h: defs_route(h)),
|
||||
@@ -3426,24 +3632,54 @@ def store_catalog(h):
|
||||
if owned:
|
||||
packs.append(_pack_body(owned, idx, owned=True))
|
||||
if not owned_ids:
|
||||
# GOTO_STORE_MYPACK resolves the hard-coded `mypacks` group before it
|
||||
# renders rows. If the group is absent FIFA falls back to Bronze and
|
||||
# shows the empty-category dialog over the wrong tab. Retain an inactive
|
||||
# zero-item sentinel so the destination resolves, while state != active
|
||||
# keeps it out of the visible row list. Its id is deliberately absent
|
||||
# from PACK_CATALOG, so both purchase/open handlers reject it as well.
|
||||
sentinel = {
|
||||
"id": 65534,
|
||||
"name": "",
|
||||
"price": 0,
|
||||
"count": 0,
|
||||
"gold": True,
|
||||
"specialChance": 0.0,
|
||||
}
|
||||
empty = _pack_body(sentinel, 1, owned=True)
|
||||
empty["state"] = "inactive"
|
||||
empty["unopened"] = False
|
||||
packs.append(empty)
|
||||
# ADDITIVE capability switch (see docs/plans/FIFA17_PATCHED_CLIENT_CAPABILITY.md
|
||||
# §7/§9). This is the session-freeze point: the empty-mypacks decision for
|
||||
# this FIFA session (keyed by its X-UT-SID) is committed here at the first
|
||||
# /store/purchasegroup and is immutable for the session thereafter.
|
||||
mode = fifa17_empty_mypacks_mode(_fifa17_sid(h), _fifa17_client_ip(h))
|
||||
if mode == FIFA17_MODE_CLEAN:
|
||||
# Verified patched client: emit NO mypacks group; the CardsDLL resolver
|
||||
# guard (RVA 0x14858 JG) routes the -1 ordinal to Browse instead of
|
||||
# dereferencing a null group. (append nothing)
|
||||
pass
|
||||
else:
|
||||
# EMPTY MY PACKS -- FIFA 17 client-compatibility workaround (bug 6c, P2).
|
||||
#
|
||||
# The Store/Scaleform path RESOLVES the `mypacks` category even when the
|
||||
# account owns zero unopened packs (the category is chosen client-side from
|
||||
# the movie's CATEGORY_ID -> screen+0x290; no server field gates it).
|
||||
# CardsDLL FUN_1800147f0 then dereferences the resolved group with NO null
|
||||
# guard, so if no `mypacks` group exists the client CRASHES
|
||||
# (CardsDLL_Win64_retail.dll+0x14882, read of [NULL+0x48] -- confirmed by
|
||||
# minidump). We therefore MUST emit a `mypacks` group when empty.
|
||||
#
|
||||
# state="inactive" avoids the crash but makes the client report the pack
|
||||
# unavailable immediately on Store entry and bounce to the Hub. state="active"
|
||||
# keeps the group structurally valid AND lets the Store open normally; the
|
||||
# empty tile renders as "0 items" and an explicit open is rejected
|
||||
# CLIENT-SIDE ("This pack is no longer available") -- it sends NO backend
|
||||
# request and mutates nothing.
|
||||
#
|
||||
# id 65534 is deliberately ABSENT from PACK_CATALOG, so pack_by_id() returns
|
||||
# None and store_buy()/purchased_items() cannot open it, grant items/coins,
|
||||
# or add it to unopenedPackIds. This is a compatibility shim for FIFA 17
|
||||
# client behavior, NOT an EA-authentic empty-My-Packs representation, and it
|
||||
# is FIFA17-specific (do not lift into game-independent Core). A fully clean
|
||||
# zero-pack UX requires a client-side fix -- see
|
||||
# docs/plans/FIFA17_EMPTY_MYPACKS_CLIENT_FIX.md and the evidence in
|
||||
# docs/evidence/STORE_TILE_6C.md / FIFA17_EMPTY_MYPACKS_CLIENT_CONTRACT.md.
|
||||
sentinel = {
|
||||
"id": 65534,
|
||||
"name": "",
|
||||
"price": 0,
|
||||
"count": 0,
|
||||
"gold": True,
|
||||
"specialChance": 0.0,
|
||||
}
|
||||
empty = _pack_body(sentinel, 1, owned=True)
|
||||
empty["state"] = "active"
|
||||
empty["unopened"] = False
|
||||
packs.append(empty)
|
||||
return 200, {"purchase": packs, "timestamp": 1596326400}
|
||||
|
||||
|
||||
|
||||
@@ -0,0 +1,78 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Dump CardsDLL's NULL-terminated {const char*, int} vocabulary tables from the
|
||||
ON-DISK PE. READ-ONLY, static.
|
||||
|
||||
The transfer-market analysis records tradeState as decoding through a table walk at
|
||||
0x180229e40 and lists sibling vocabularies (type/zone/lev/pos) as tables of the same
|
||||
shape. This prints the exact token spellings and their integer codes, so the accepted
|
||||
strings come from the client rather than from inference.
|
||||
"""
|
||||
import struct
|
||||
|
||||
DLL = "/mnt/games/FIFA 17/CardsDLL_Win64_retail.dll"
|
||||
TABLES = [
|
||||
(0x180229E40, "tradeState (table walk)"),
|
||||
(0x180229C30, "type"),
|
||||
(0x1802296E0, "zone"),
|
||||
(0x180229A60, "lev"),
|
||||
(0x1802295C0, "pos"),
|
||||
(0x180229AB0, "cat"),
|
||||
(0x180229880, "form"),
|
||||
]
|
||||
MAX_ROWS = 64
|
||||
|
||||
pe = open(DLL, "rb").read()
|
||||
e_lfanew = struct.unpack_from("<I", pe, 0x3C)[0]
|
||||
coff = e_lfanew + 4
|
||||
num_sections = struct.unpack_from("<H", pe, coff + 2)[0]
|
||||
opt_size = struct.unpack_from("<H", pe, coff + 16)[0]
|
||||
opt = coff + 20
|
||||
image_base = struct.unpack_from("<Q", pe, opt + 24)[0]
|
||||
sec_off = opt + opt_size
|
||||
sections = []
|
||||
for i in range(num_sections):
|
||||
b = sec_off + i * 40
|
||||
vsize, vaddr, rawsize, rawptr = struct.unpack_from("<IIII", pe, b + 8)
|
||||
sections.append((vaddr, vsize, rawptr, rawsize))
|
||||
|
||||
|
||||
def va2off(va):
|
||||
rva = va - image_base
|
||||
for vaddr, vsize, rawptr, rawsize in sections:
|
||||
if vaddr <= rva < vaddr + max(vsize, rawsize):
|
||||
off = rva - vaddr + rawptr
|
||||
if 0 <= off < len(pe):
|
||||
return off
|
||||
return None
|
||||
|
||||
|
||||
def cstr(va, limit=64):
|
||||
off = va2off(va)
|
||||
if off is None:
|
||||
return None
|
||||
end = pe.find(b"\0", off, off + limit)
|
||||
if end < 0:
|
||||
return None
|
||||
try:
|
||||
s = pe[off:end].decode("ascii")
|
||||
except UnicodeDecodeError:
|
||||
return None
|
||||
return s if s.isprintable() else None
|
||||
|
||||
|
||||
for table_va, name in TABLES:
|
||||
base = va2off(table_va)
|
||||
print("\n=== %s VA %#x -> off %s ===" % (name, table_va, hex(base) if base else None))
|
||||
if base is None:
|
||||
print(" (VA did not resolve)")
|
||||
continue
|
||||
for i in range(MAX_ROWS):
|
||||
ptr, code = struct.unpack_from("<Qi", pe, base + i * 16)
|
||||
if ptr == 0:
|
||||
print(" -- NULL terminator after %d rows --" % i)
|
||||
break
|
||||
s = cstr(ptr)
|
||||
if s is None:
|
||||
print(" row %d: ptr %#x does not resolve to a string; stopping" % (i, ptr))
|
||||
break
|
||||
print(" %-28s = %d" % (repr(s), code))
|
||||
@@ -0,0 +1,24 @@
|
||||
[package]
|
||||
name = "openfut-adapter-fifa17"
|
||||
version = "0.1.0"
|
||||
edition = "2021"
|
||||
license = "MIT"
|
||||
description = "FIFA 17 game adapter: Blaze command tables, response bodies and dispatch"
|
||||
publish = false
|
||||
|
||||
[dependencies]
|
||||
openfut-protocol-blaze = { path = "../openfut-protocol-blaze" }
|
||||
# Reads the bundled fetchClientConfig table (227-243 rows per CFID), which is
|
||||
# generated from the Python oracle rather than transcribed by hand. Unlike the
|
||||
# protocol crate below it, this crate is ordinary server-side code, so a real
|
||||
# JSON parser is the right call — hand-rolling one to preserve a zero-dependency
|
||||
# streak would be reinventing a solved problem in the riskiest possible place.
|
||||
serde = { version = "1", features = ["derive"] }
|
||||
serde_json = "1"
|
||||
# Seeded RNG for the Store pack-content generator (`fut::pack_content`). The
|
||||
# generator is pure over an injected `rand::Rng`, so packs are deterministic
|
||||
# under a seeded `StdRng` in tests and reproducible in production.
|
||||
rand = "0.8"
|
||||
|
||||
[dev-dependencies]
|
||||
# Differential fixtures are JSONL; the runtime dependency already covers it.
|
||||
@@ -0,0 +1,115 @@
|
||||
# openfut-adapter-fifa17
|
||||
|
||||
The FIFA 17 game adapter. Everything true of *FIFA 17 specifically* lives here,
|
||||
so that neither OpenFUT Core nor the generic protocol crates have to know about
|
||||
it.
|
||||
|
||||
```
|
||||
openfut-protocol-blaze generic Blaze: Fire2 framing, Heat2/TDF codec
|
||||
▲
|
||||
openfut-adapter-fifa17 THIS: command tables, response bodies, dispatch order
|
||||
▲
|
||||
OpenFUT Core game-independent FUT domain (not yet wired)
|
||||
```
|
||||
|
||||
## Status
|
||||
|
||||
| Surface | Port | State |
|
||||
|---|---|---|
|
||||
| **Blaze / Fire2 RPC** | 42130 | **Implemented**, byte-for-byte parity-tested |
|
||||
| Redirector (HTTPS + XML) | 42127 | Python only |
|
||||
| Nucleus OAuth stub | 42131 | Python only |
|
||||
| LSX / Origin | 4216 | Python only |
|
||||
| Roster XML | 8081 | Python only |
|
||||
| UTAS / RS4 | 8099 | Python only |
|
||||
| POW / EASFC | 8094 / 8080 | Python only |
|
||||
|
||||
**Nothing here is wired into the running backend.** The crate answers frames; it
|
||||
opens no socket, terminates no TLS and owns no runtime. The Python backend
|
||||
remains the live service and the behavioural oracle.
|
||||
|
||||
## What the adapter owns, and what it must not
|
||||
|
||||
Owns: component/command/notification IDs, response body shapes, dispatch
|
||||
ordering, session identity, the `fetchClientConfig` tables.
|
||||
|
||||
Must not own: FUT domain state. Blaze is an auth/session/config protocol — no
|
||||
coins, packs, clubs or squads appear on this wire — so `Session` holds a session
|
||||
key, a locale, a service name, an auth code and a flag, and that is all. When
|
||||
UTAS is migrated that boundary will need active defending; here it comes free.
|
||||
|
||||
## Parity
|
||||
|
||||
```bash
|
||||
./check-parity.sh # oracle freshness + byte-for-byte replay
|
||||
./check-parity.sh --regen # after an intentional oracle change
|
||||
```
|
||||
|
||||
`fixtures/blaze_transactions.jsonl` holds 49 request→response(s) transactions
|
||||
produced by calling the real `blaze_responder_v3b.dispatch()`. They replay in
|
||||
order against a shared session per connection, so ordering-dependent behaviour
|
||||
is exercised rather than assumed: preAuth captures the locale that later `ALOC`
|
||||
fields echo, and login sets the auth code `getAuthToken` returns afterwards.
|
||||
|
||||
Comparison is byte-for-byte including frame count and order — a missing
|
||||
post-login notification or a reply where the oracle stays silent fails here.
|
||||
|
||||
The suite was **mutation-tested**: swapping two post-login notifications,
|
||||
flipping one enum deep inside `AccountInfo`, and hardcoding an address in
|
||||
`utas_base()`/`nucleus_base()` were each verified to turn it red. The third
|
||||
initially did *not*, because the config templating had made those helpers dead
|
||||
code; the table now templates on URL-level tokens so they are the single place a
|
||||
URL shape is defined.
|
||||
|
||||
## Three behaviours that are easy to get wrong
|
||||
|
||||
* **Login answers with four frames, in order**: reply, then `UserAuthenticated`,
|
||||
`UserSessionExtendedDataUpdate`, `UserAdded`.
|
||||
* **An unimplemented RPC still gets an empty reply.** Silence makes the client
|
||||
wait for a timeout; an empty reply lets every field fall back to a client-side
|
||||
default and the boot continues.
|
||||
* **Non-request message types get nothing at all.**
|
||||
|
||||
No error replies are emitted. `msgType` 3 exists, but the error-code placement
|
||||
is UNRESOLVED — three clean-room sources disagree between `header[14:16]`, a
|
||||
metadata `ERRC`, and a payload `CNTX`/`ERRC` — so emitting one would be a guess
|
||||
on the wire.
|
||||
|
||||
## The client config table
|
||||
|
||||
`fixtures/client_config.json` carries 227–243 rows per CFID, generated from the
|
||||
Python oracle and templated on `{utas_base}`, `{nucleus_base}`,
|
||||
`{pow_content_url}`, `{advertise}`, `{bind}`, `{pow_host}`. It is
|
||||
reverse-engineered *data*, not logic, and deriving it mechanically removes a
|
||||
class of transcription typo no reviewer could catch. The generator does not take
|
||||
its own templating on trust: it substitutes real addresses back in and diffs
|
||||
against the oracle for every section before writing the file.
|
||||
|
||||
The table must be *complete*, not representative. The client resolves a per-call
|
||||
key (`FUT_RS4_URL_<CALL>`) before a per-module one, and any unresolved call falls
|
||||
back to a real, dead EA host — that is what produced "there has been an error
|
||||
connecting to FIFA 17 Ultimate Team" mid-session when only the boot subset was
|
||||
served.
|
||||
|
||||
## Known defect reproduced deliberately
|
||||
|
||||
`nucleusConnect` and `nucleusConnectTrusted` are built from the **bind** address,
|
||||
not the advertised one. On the live split deployment that means the backend
|
||||
tells a client on another machine to reach Nucleus at `http://0.0.0.0:42131`,
|
||||
which it cannot. Verified against the running container, not inferred.
|
||||
|
||||
This is reproduced exactly, because it is what the only proven-working
|
||||
configuration does and changing it would break parity. It also implies the
|
||||
Nucleus stub is not actually reached in the current remote flow. Fixing it is a
|
||||
separate change that needs live validation — see the vault.
|
||||
|
||||
## Configuration
|
||||
|
||||
Nothing is hardcoded. `AdapterConfig` carries `Identity` (persona, ids, email,
|
||||
namespace, entitlement group, …) and `Endpoints` (advertise, bind, POW hosts,
|
||||
telemetry/ticker/QoS ports). `Default` gives the project's synthetic offline
|
||||
identity on loopback; a remote deployment must override `advertise`.
|
||||
|
||||
Bind and advertise are deliberately distinct: an advertised URL must carry the
|
||||
address the *client* can reach, which on a two-machine deployment is not the
|
||||
address the server binds.
|
||||
Executable
+28
@@ -0,0 +1,28 @@
|
||||
#!/usr/bin/env bash
|
||||
# Differential check: the Rust FIFA 17 Blaze adapter vs the Python responder.
|
||||
#
|
||||
# 1. assert the committed fixtures still match what the Python oracle emits
|
||||
# 2. replay every recorded transaction through the Rust adapter, byte-for-byte
|
||||
#
|
||||
# Read-only with respect to the running backend: the oracle is imported as a
|
||||
# library, no responder is started, no port is bound, no live service is
|
||||
# touched. Safe to run while the Python backend is serving a live FIFA client.
|
||||
#
|
||||
# Use --regen to rewrite the fixtures after an intentional oracle change.
|
||||
set -euo pipefail
|
||||
|
||||
cd "$(dirname "$(readlink -f "$0")")"
|
||||
|
||||
if [[ "${1:-}" == "--regen" ]]; then
|
||||
echo "==> regenerating fixtures from the Python oracle"
|
||||
python3 fixtures/generate.py
|
||||
else
|
||||
echo "==> checking committed fixtures against the Python oracle"
|
||||
python3 fixtures/generate.py --check
|
||||
fi
|
||||
|
||||
echo "==> replaying transactions through the Rust adapter"
|
||||
cargo test -p openfut-adapter-fifa17
|
||||
|
||||
echo
|
||||
echo "PARITY OK — the adapter reproduces the Python dispatcher byte-for-byte."
|
||||
File diff suppressed because it is too large
Load Diff
File diff suppressed because one or more lines are too long
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,460 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Freeze the Python Blaze responder's DISPATCH contract as replayable fixtures.
|
||||
|
||||
The crate-level fixtures in `openfut-protocol-blaze` pin the *codec*: given a
|
||||
field tree, what bytes come out. This file pins the layer above: given an
|
||||
inbound Fire2 frame and a session, **which frames go back, in what order**.
|
||||
|
||||
That is the whole contract of a Blaze adapter, and it is the thing a rewrite can
|
||||
silently get wrong in ways a codec test cannot see — a missing post-login
|
||||
notification, a reply where the oracle stays silent, notifications in the wrong
|
||||
order, session state not carried between RPCs.
|
||||
|
||||
Every transaction is produced by calling the real
|
||||
`blaze_responder_v3b.dispatch()`. Session state is threaded across a scripted
|
||||
connection exactly as it would be on a live socket, so ordering-dependent
|
||||
behaviour (preAuth captures the locale; login sets the auth code that
|
||||
getAuthToken later returns) is captured rather than assumed.
|
||||
|
||||
Determinism: the oracle's clock is pinned and its PRNG seeded, and the
|
||||
deployment-dependent addresses are set before import (the responder reads them
|
||||
at import time). See the sibling generator in openfut-protocol-blaze.
|
||||
|
||||
NO SECRETS. The identity here (persona 33068179 / "CAGE") is the project's fixed
|
||||
synthetic offline identity. Session keys are minted from a seeded PRNG.
|
||||
|
||||
Usage: python3 fixtures/generate.py (write)
|
||||
python3 fixtures/generate.py --check (verify committed files are current)
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
import os
|
||||
import random
|
||||
import sys
|
||||
from collections import OrderedDict
|
||||
|
||||
HERE = os.path.dirname(os.path.abspath(__file__))
|
||||
TOOLS = os.path.normpath(os.path.join(HERE, "..", "..", "fifa17-recon", "tools"))
|
||||
if not os.path.isdir(TOOLS):
|
||||
sys.exit("cannot find the Python oracle at %s" % TOOLS)
|
||||
sys.path.insert(0, TOOLS)
|
||||
|
||||
CHECK_ONLY = "--check" in sys.argv[1:]
|
||||
# Internal mode: re-exec of this script with sentinel addresses, used to derive
|
||||
# the templated client-config table (see emit_config_table).
|
||||
CONFIG_TABLE_MODE = "--_config_table" in sys.argv[1:]
|
||||
sys.argv = [sys.argv[0]]
|
||||
|
||||
# Sentinels substituted back into template tokens. Deliberately not IP-shaped so
|
||||
# a stray literal cannot be mistaken for a real address.
|
||||
SENTINELS = [
|
||||
("ADVERTISE-SENTINEL", "{advertise}"),
|
||||
("BIND-SENTINEL", "{bind}"),
|
||||
("POWCONTENT-SENTINEL", "{pow_content_host}"),
|
||||
("POWHOST-SENTINEL", "{pow_host}"),
|
||||
]
|
||||
|
||||
if CONFIG_TABLE_MODE:
|
||||
os.environ["OPENFUT_ADVERTISE"] = "ADVERTISE-SENTINEL"
|
||||
os.environ["OPENFUT_BIND"] = "BIND-SENTINEL"
|
||||
os.environ["POW_CONTENT_HOST"] = "POWCONTENT-SENTINEL"
|
||||
os.environ["POW_HOST"] = "POWHOST-SENTINEL"
|
||||
import blaze_responder_v3b as _B # noqa: E402
|
||||
out = {cfid: _B.client_config_for(cfid) for cfid in sorted(_B.CLIENT_CONFIGS)}
|
||||
out["__default__"] = _B.client_config_for("__no_such_section__")
|
||||
print(json.dumps(out))
|
||||
raise SystemExit(0)
|
||||
|
||||
# Pin deployment config BEFORE import — the responder snapshots these at import
|
||||
# time into module globals used by the response builders.
|
||||
#
|
||||
# Distinct, obviously-fake values on purpose: if the Rust adapter hardcoded an
|
||||
# address instead of reading its config, these make the failure loud rather than
|
||||
# accidentally matching a loopback default.
|
||||
ADVERTISE = "198.51.100.7"
|
||||
BIND = "0.0.0.0"
|
||||
POW_CONTENT_HOST = "198.51.100.7:8085"
|
||||
POW_HOST = "198.51.100.7:8094"
|
||||
|
||||
os.environ["OPENFUT_ADVERTISE"] = ADVERTISE
|
||||
os.environ["OPENFUT_BIND"] = BIND
|
||||
os.environ["POW_CONTENT_HOST"] = POW_CONTENT_HOST
|
||||
os.environ["POW_HOST"] = POW_HOST
|
||||
|
||||
import heat2 # noqa: E402
|
||||
import blaze_responder_v3b as B # noqa: E402
|
||||
from fut_account import ACCOUNT # noqa: E402
|
||||
|
||||
FIXED_NOW = 1754870400
|
||||
INT, STRING, STRUCT, LIST, MAP, BLOB = (
|
||||
heat2.INT, heat2.STRING, heat2.STRUCT, heat2.LIST, heat2.MAP, heat2.BLOB)
|
||||
|
||||
RECORDS = []
|
||||
|
||||
|
||||
# ------------------------------------------------------------------ helpers
|
||||
|
||||
def req_frame(component, command, fields=None, msg_num=1, msg_type=None,
|
||||
user_index=0):
|
||||
"""Build an inbound request frame the way the client would."""
|
||||
msg_type = B.MESSAGE if msg_type is None else msg_type
|
||||
payload = heat2.encode_tdf(fields) if fields else b""
|
||||
return B.fire2(component, command, msg_num, msg_type, payload,
|
||||
user_index=user_index)
|
||||
|
||||
|
||||
def tx(session, name, frame, note=""):
|
||||
"""Run one frame through the real dispatcher and record what came back."""
|
||||
hdr = B.parse_fire2_header(frame)
|
||||
body = frame[16 + hdr["metadata_len"]:]
|
||||
fields = heat2.decode_tdf(body) if body else OrderedDict()
|
||||
out = B.dispatch(hdr, fields, body, session["sess"])
|
||||
|
||||
RECORDS.append(OrderedDict((
|
||||
("kind", "tx"),
|
||||
("session", session["id"]),
|
||||
("name", name),
|
||||
("note", note),
|
||||
("request_hex", frame.hex()),
|
||||
("responses", [f.hex() for f in out]),
|
||||
)))
|
||||
return out
|
||||
|
||||
|
||||
def new_session(sid):
|
||||
s = {"id": sid, "sess": B.Session()}
|
||||
RECORDS.append(OrderedDict((
|
||||
("kind", "session"),
|
||||
("id", sid),
|
||||
# Minted per connection by the oracle; the Rust side must be able to
|
||||
# inject it, because it appears in LoginResponse.SESS.KEY, the
|
||||
# UserAuthenticated push and PostAuthResponse.TELE.SESS and all three
|
||||
# must be the same string.
|
||||
("session_key", s["sess"].session_key),
|
||||
("account_locale", s["sess"].account_locale),
|
||||
("service_name", s["sess"].service_name),
|
||||
)))
|
||||
return s
|
||||
|
||||
|
||||
# ------------------------------------------------------------------ script
|
||||
|
||||
def build():
|
||||
RECORDS.append(OrderedDict((
|
||||
("kind", "config"),
|
||||
("advertise", ADVERTISE),
|
||||
("bind", BIND),
|
||||
("pow_content_host", POW_CONTENT_HOST),
|
||||
("pow_host", POW_HOST),
|
||||
("now", FIXED_NOW),
|
||||
("identity", OrderedDict((
|
||||
("persona_id", ACCOUNT.persona_id),
|
||||
("persona_name", ACCOUNT.persona_name),
|
||||
("user_id", ACCOUNT.user_id),
|
||||
("ext_id", ACCOUNT.ext_id),
|
||||
("email", ACCOUNT.email),
|
||||
("namespace", ACCOUNT.NAMESPACE),
|
||||
("client_platform", ACCOUNT.CLIENT_PLATFORM),
|
||||
("persona_status", ACCOUNT.PERSONA_STATUS),
|
||||
("user_session_type", ACCOUNT.USER_SESSION_TYPE),
|
||||
("account_locale_int", ACCOUNT.account_locale_int),
|
||||
("locale", ACCOUNT.locale),
|
||||
("content_id", ACCOUNT.CONTENT_ID),
|
||||
("entitlement_tag", ACCOUNT.ENTITLEMENT_TAG),
|
||||
("entitlement_group", ACCOUNT.ENTITLEMENT_GROUP),
|
||||
("title_id", ACCOUNT.TITLE_ID),
|
||||
("client_id", ACCOUNT.CLIENT_ID),
|
||||
("platform", ACCOUNT.PLATFORM),
|
||||
("server_version", B.SERVER_VERSION),
|
||||
))),
|
||||
)))
|
||||
|
||||
# ================= main connection: the real boot order =================
|
||||
#
|
||||
# Mirrors what FIFA 17 actually does, because ordering is load-bearing:
|
||||
# preAuth captures the locale that later ALOC fields echo, and login sets
|
||||
# the auth code that getAuthToken returns afterwards.
|
||||
m = new_session("main")
|
||||
|
||||
tx(m, "preauth", req_frame(B.COMP_UTIL, B.CMD_PREAUTH, OrderedDict([
|
||||
("CDAT", (STRUCT, OrderedDict([
|
||||
("IITO", (INT, 0)),
|
||||
("LANG", (INT, 0x656E5553)), # 'enUS'
|
||||
("SVCN", (STRING, "fifa-2017-pc")), # echoed back as INST
|
||||
("TYPE", (INT, 0)),
|
||||
]))),
|
||||
("CINF", (STRUCT, OrderedDict([
|
||||
("BSDK", (STRING, "15.1.1.3.0")),
|
||||
("CLNT", (STRING, "FIFA17")),
|
||||
("ENV", (STRING, "prod")),
|
||||
("LOC", (INT, 0x656E5553)),
|
||||
]))),
|
||||
("FCCR", (STRUCT, OrderedDict([("CFID", (STRING, "BlazeSDK"))]))),
|
||||
])), "first RPC; echoes SVCN as INST and captures LANG for ALOC")
|
||||
|
||||
tx(m, "ping", req_frame(B.COMP_UTIL, B.CMD_PING, msg_num=2),
|
||||
"Util::ping -> STIM only")
|
||||
|
||||
# Every section the responder knows, plus unknown ones. The known sections
|
||||
# each add their own rows on top of the shared FUT/RS4 base — OSDK_ROSTER in
|
||||
# particular carries the roster URL, itself a documented loading gate — so
|
||||
# covering only "BlazeSDK" would leave most of the table unverified.
|
||||
for cfid in ("BlazeSDK", "netres", "IdentityParams", "OSDK_CORE",
|
||||
"OSDK_CLIENT", "OSDK_NUCLEUS", "OSDK_ROSTER", "OSDK_TICKER",
|
||||
"OSDK_WEBOFFER", "OSDK_POW", "OSDK_ABUSE_REPORTING",
|
||||
"OSDK_XMS_ABUSE_REPORTING", "UTAS", "FUT", "",
|
||||
"TOTALLY_UNKNOWN"):
|
||||
tx(m, "fetch_config_%s" % (cfid or "empty"),
|
||||
req_frame(B.COMP_UTIL, B.CMD_FETCHCLIENTCONFIG,
|
||||
OrderedDict([("CFID", (STRING, cfid))]), msg_num=3),
|
||||
"unknown CFIDs still get the shared FUT/POW rows")
|
||||
|
||||
tx(m, "get_auth_token_before_login",
|
||||
req_frame(B.COMP_AUTH, B.CMD_GETAUTHTOKEN, msg_num=4),
|
||||
"no auth code yet -> synthesised OPENFUT-<key[:16]> token")
|
||||
|
||||
tx(m, "logout_before_login", req_frame(B.COMP_AUTH, B.CMD_LOGOUT, msg_num=5),
|
||||
"routine LoginStateLogout (state 500), NOT a failure; empty reply")
|
||||
|
||||
tx(m, "login", req_frame(B.COMP_AUTH, B.CMD_LOGIN, OrderedDict([
|
||||
("AUTH", (STRING, "OPENFUT-TEST-AUTHCODE")),
|
||||
("EXTB", (BLOB, b"")),
|
||||
("PNAM", (STRING, "")),
|
||||
]), msg_num=6),
|
||||
"reply THEN three UserSessions pushes, in that order")
|
||||
|
||||
tx(m, "get_auth_token_after_login",
|
||||
req_frame(B.COMP_AUTH, B.CMD_GETAUTHTOKEN, msg_num=7),
|
||||
"now echoes the login's AUTH verbatim")
|
||||
|
||||
tx(m, "get_account", req_frame(B.COMP_AUTH, B.CMD_GETACCOUNT, msg_num=8),
|
||||
"the RPC behind 'Unable to retrieve account information'")
|
||||
tx(m, "get_persona", req_frame(B.COMP_AUTH, B.CMD_GETPERSONA, msg_num=9))
|
||||
tx(m, "list_personas", req_frame(B.COMP_AUTH, B.CMD_LISTPERSONAS, msg_num=10))
|
||||
|
||||
for cmd, label in ((B.CMD_LISTUSERENTITLEMENTS2, "listUserEntitlements2"),
|
||||
(0x20, "listEntitlements"),
|
||||
(0x30, "listPersonaEntitlements2"),
|
||||
(0x27, "grantEntitlement2")):
|
||||
tx(m, "entitlements_%s" % label,
|
||||
req_frame(B.COMP_AUTH, cmd, msg_num=11),
|
||||
"all four aliases return the same two ONLINE_ACCESS records")
|
||||
|
||||
tx(m, "post_auth", req_frame(B.COMP_UTIL, B.CMD_POSTAUTH, msg_num=12),
|
||||
"TELE/TICK/UROP; TELE.SESS must equal the login session key")
|
||||
tx(m, "fetch_qos_config", req_frame(B.COMP_UTIL, 0x15, msg_num=13))
|
||||
tx(m, "user_settings_load",
|
||||
req_frame(B.COMP_UTIL, B.CMD_USERSETTINGSLOAD, msg_num=14))
|
||||
tx(m, "user_settings_save",
|
||||
req_frame(B.COMP_UTIL, B.CMD_USERSETTINGSSAVE, msg_num=15),
|
||||
"accepted and discarded; empty reply")
|
||||
tx(m, "set_client_state",
|
||||
req_frame(B.COMP_UTIL, B.CMD_SETCLIENTSTATE, msg_num=16))
|
||||
tx(m, "set_client_metrics",
|
||||
req_frame(B.COMP_UTIL, B.CMD_SETCLIENTMETRICS, msg_num=17))
|
||||
|
||||
tx(m, "update_network_info",
|
||||
req_frame(B.COMP_USERSESSIONS, B.CMD_UPDATENETWORKINFO, msg_num=18),
|
||||
"empty reply PLUS an unsolicited ExtendedDataUpdate push")
|
||||
|
||||
tx(m, "get_lists", req_frame(B.COMP_ASSOCLISTS, B.CMD_GETLISTS, msg_num=19))
|
||||
|
||||
tx(m, "census_subscribe",
|
||||
req_frame(B.COMP_CENSUSDATA, B.CMD_SUBSCRIBETOCENSUSDATAUPDATES,
|
||||
OrderedDict([("RSUB", (INT, 1))]), msg_num=20),
|
||||
"non-zero TimeValues or the client storms at ~30/s and hangs the FUT load")
|
||||
|
||||
tx(m, "logout_after_login",
|
||||
req_frame(B.COMP_AUTH, B.CMD_LOGOUT, msg_num=21),
|
||||
"session teardown after a login; still an empty reply")
|
||||
|
||||
# ============================ fallback behaviour ========================
|
||||
f = new_session("fallbacks")
|
||||
|
||||
tx(f, "transport_ping",
|
||||
req_frame(B.COMP_UTIL, B.CMD_PING, msg_num=30, msg_type=B.PING),
|
||||
"msgType PING -> PING_REPLY with an empty body, whatever the command")
|
||||
|
||||
for mt, label in ((B.REPLY, "reply"), (B.NOTIFICATION, "notification"),
|
||||
(B.ERROR_REPLY, "error_reply"),
|
||||
(B.PING_REPLY, "ping_reply")):
|
||||
tx(f, "ignores_%s" % label,
|
||||
req_frame(B.COMP_UTIL, B.CMD_PING, msg_num=31, msg_type=mt),
|
||||
"not a request -> NO frames at all")
|
||||
|
||||
tx(f, "unknown_command",
|
||||
req_frame(B.COMP_UTIL, 0x0FFF, msg_num=32),
|
||||
"unimplemented RPC still gets an EMPTY reply so the client cannot hang")
|
||||
tx(f, "unknown_component",
|
||||
req_frame(0x1234, 0x0001, msg_num=33),
|
||||
"same fallback for an entirely unknown component")
|
||||
|
||||
tx(f, "user_index_is_echoed",
|
||||
req_frame(B.COMP_UTIL, B.CMD_PING, msg_num=34, user_index=7),
|
||||
"a reply echoes component/command/msgNum/userIndex verbatim")
|
||||
|
||||
# ================= locale echo on a non-default client ==================
|
||||
loc = new_session("locale")
|
||||
tx(loc, "preauth_de_locale",
|
||||
req_frame(B.COMP_UTIL, B.CMD_PREAUTH, OrderedDict([
|
||||
("CDAT", (STRUCT, OrderedDict([
|
||||
("LANG", (INT, 0x64654445)), # 'deDE'
|
||||
("SVCN", (STRING, "fifa-2017-pc-de")),
|
||||
]))),
|
||||
])),
|
||||
"a non-enUS client: SVCN echo AND the captured locale must both change")
|
||||
tx(loc, "login_with_de_locale",
|
||||
req_frame(B.COMP_AUTH, B.CMD_LOGIN, msg_num=41),
|
||||
"UserAuthenticated.ALOC must carry the captured deDE locale")
|
||||
|
||||
|
||||
# ------------------------------------------------------------------- output
|
||||
|
||||
def emit_config_table():
|
||||
"""Derive the fetchClientConfig tables as address-TEMPLATED data.
|
||||
|
||||
These are 227-243 key/value rows per CFID, almost all of them the same URL.
|
||||
Hand-transcribing them into Rust would be 400 lines of string literals that
|
||||
nobody can review and one typo can break; deriving them mechanically from
|
||||
the oracle removes that whole class of error and keeps them regenerable.
|
||||
They are reverse-engineered *data*, not logic — the same reason
|
||||
`openfut-core` loads its content from `data/` rather than from source.
|
||||
|
||||
The values are templated on {advertise}/{bind}/{pow_content_host}/{pow_host}
|
||||
so the adapter stays configurable; baking an address in here would recreate
|
||||
exactly the hardcoding the client/server split removed.
|
||||
|
||||
Correctness is not assumed: the caller substitutes real addresses back in
|
||||
and diffs against the oracle. See verify_config_table.
|
||||
"""
|
||||
import subprocess
|
||||
|
||||
raw = subprocess.run(
|
||||
[sys.executable, os.path.abspath(__file__), "--_config_table"],
|
||||
capture_output=True, text=True, check=True,
|
||||
# Inherit nothing address-shaped; the child sets its own sentinels.
|
||||
env={k: v for k, v in os.environ.items()
|
||||
if not k.startswith(("OPENFUT_", "POW_", "FUT_"))},
|
||||
).stdout
|
||||
table = json.loads(raw)
|
||||
|
||||
def templatise(value):
|
||||
for sentinel, token in SENTINELS:
|
||||
value = value.replace(sentinel, token)
|
||||
# Collapse whole URLs to URL-level tokens where one exists, so the Rust
|
||||
# side builds them in exactly one place (AdapterConfig::utas_base and
|
||||
# friends) instead of re-deriving the shape here. Without this the
|
||||
# helpers become dead code and a hardcoded address in them goes
|
||||
# undetected — verified by mutation testing. Longest first.
|
||||
for whole, token in (
|
||||
("http://{advertise}:8099/", "{utas_base}"),
|
||||
("http://{bind}:42131", "{nucleus_base}"),
|
||||
("http://{pow_content_host}", "{pow_content_url}"),
|
||||
):
|
||||
if value == whole:
|
||||
return token
|
||||
return value
|
||||
|
||||
return {cfid: [[k, templatise(v)] for k, v in rows]
|
||||
for cfid, rows in table.items()}
|
||||
|
||||
|
||||
def verify_config_table(table):
|
||||
"""Substitute the real addresses back and require the oracle's exact rows.
|
||||
|
||||
This is what makes the templated table trustworthy rather than plausible.
|
||||
"""
|
||||
subst = {
|
||||
"{utas_base}": "http://%s:8099/" % ADVERTISE,
|
||||
"{nucleus_base}": "http://%s:42131" % BIND,
|
||||
"{pow_content_url}": "http://%s" % POW_CONTENT_HOST,
|
||||
"{advertise}": ADVERTISE,
|
||||
"{bind}": BIND,
|
||||
"{pow_content_host}": POW_CONTENT_HOST,
|
||||
"{pow_host}": POW_HOST,
|
||||
}
|
||||
|
||||
def render(v):
|
||||
for token, real in subst.items():
|
||||
v = v.replace(token, real)
|
||||
return v
|
||||
|
||||
for cfid, rows in table.items():
|
||||
expected = B.client_config_for(
|
||||
"__no_such_section__" if cfid == "__default__" else cfid)
|
||||
got = [(k, render(v)) for k, v in rows]
|
||||
if got != [(k, v) for k, v in expected]:
|
||||
for (gk, gv), (ek, ev) in zip(got, expected):
|
||||
if (gk, gv) != (ek, ev):
|
||||
sys.exit("config template mismatch in %s: %r -> %r, oracle "
|
||||
"has %r -> %r" % (cfid, gk, gv, ek, ev))
|
||||
sys.exit("config template row-count mismatch in %s: %d vs %d"
|
||||
% (cfid, len(got), len(expected)))
|
||||
print("config table verified against the oracle for %d sections"
|
||||
% len(table))
|
||||
|
||||
|
||||
def frozen_clock():
|
||||
import time as _time
|
||||
original = _time.time
|
||||
_time.time = lambda: float(FIXED_NOW)
|
||||
return original, _time
|
||||
|
||||
|
||||
def write(path, records):
|
||||
body = "".join(json.dumps(r, separators=(",", ":")) + "\n" for r in records)
|
||||
if CHECK_ONLY:
|
||||
if not os.path.exists(path):
|
||||
sys.exit("MISSING: %s has never been generated" % path)
|
||||
with open(path, "r", encoding="utf-8") as fh:
|
||||
if fh.read() != body:
|
||||
sys.exit("STALE: %s does not match the oracle; re-run without "
|
||||
"--check" % path)
|
||||
print("current: %s (%d records)" % (os.path.basename(path), len(records)))
|
||||
return
|
||||
with open(path, "w", encoding="utf-8") as fh:
|
||||
fh.write(body)
|
||||
print("wrote %s (%d records)" % (os.path.basename(path), len(records)))
|
||||
|
||||
|
||||
def write_json(path, obj):
|
||||
body = json.dumps(obj, indent=1, sort_keys=True) + "\n"
|
||||
if CHECK_ONLY:
|
||||
if not os.path.exists(path):
|
||||
sys.exit("MISSING: %s has never been generated" % path)
|
||||
with open(path, "r", encoding="utf-8") as fh:
|
||||
if fh.read() != body:
|
||||
sys.exit("STALE: %s does not match the oracle" % path)
|
||||
print("current: %s" % os.path.basename(path))
|
||||
return
|
||||
with open(path, "w", encoding="utf-8") as fh:
|
||||
fh.write(body)
|
||||
print("wrote %s (%d sections)" % (os.path.basename(path), len(obj)))
|
||||
|
||||
|
||||
def main():
|
||||
# The oracle logs every dispatch to stdout; useful live, pure noise here.
|
||||
B.log = lambda *_a, **_k: None
|
||||
|
||||
table = emit_config_table()
|
||||
verify_config_table(table)
|
||||
write_json(os.path.join(HERE, "client_config.json"), table)
|
||||
|
||||
random.seed(0xB1A2E)
|
||||
original_time, time_mod = frozen_clock()
|
||||
try:
|
||||
build()
|
||||
finally:
|
||||
time_mod.time = original_time
|
||||
|
||||
write(os.path.join(HERE, "blaze_transactions.jsonl"), RECORDS)
|
||||
txs = [r for r in RECORDS if r["kind"] == "tx"]
|
||||
frames = sum(len(r["responses"]) for r in txs)
|
||||
print("%d transactions, %d response frames, %d sessions"
|
||||
% (len(txs), frames,
|
||||
len([r for r in RECORDS if r["kind"] == "session"])))
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
main()
|
||||
@@ -0,0 +1,123 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Capture the roster oracle's responses byte-for-byte.
|
||||
|
||||
generate_roster.py [--check] [host:port]
|
||||
|
||||
Unlike `generate.py`, which imports the Blaze responder and calls its pure
|
||||
functions, this captures over the wire. The roster response is shaped as much by
|
||||
`http.server.BaseHTTPRequestHandler` as by the handler code -- HTTP/1.0 status
|
||||
line, `Server:`/`Date:` injected ahead of the handler's own headers, POST
|
||||
answered without a body -- and only the real socket shows all of that.
|
||||
|
||||
Two fields are volatile and are MASKED rather than recorded:
|
||||
|
||||
Date: changes every second
|
||||
Server: carries the container's Python version
|
||||
|
||||
They are masked, not dropped, so their presence and position are still asserted.
|
||||
The Server string is additionally recorded verbatim under `observed_server`, so
|
||||
a drift between the container's Python and the adapter's `ORACLE_SERVER`
|
||||
constant is visible rather than silent.
|
||||
|
||||
`--check` re-captures and compares. If the oracle is unreachable it FAILS rather
|
||||
than passing: a check that cannot check must not report success.
|
||||
"""
|
||||
import json
|
||||
import os
|
||||
import re
|
||||
import socket
|
||||
import ssl
|
||||
import sys
|
||||
|
||||
HERE = os.path.dirname(os.path.abspath(__file__))
|
||||
OUT = os.path.join(HERE, "roster.json")
|
||||
PATH = "/fifa17/fut/rosterupdate.xml"
|
||||
|
||||
DATE_RE = re.compile(rb"^Date: .+?\r\n", re.M)
|
||||
SERVER_RE = re.compile(rb"^Server: (.+?)\r\n", re.M)
|
||||
|
||||
|
||||
def fetch(host, port, method, body=None):
|
||||
ctx = ssl.SSLContext(ssl.PROTOCOL_TLS_CLIENT)
|
||||
ctx.check_hostname = False
|
||||
ctx.verify_mode = ssl.CERT_NONE
|
||||
ctx.set_ciphers("ALL:@SECLEVEL=0")
|
||||
s = ctx.wrap_socket(socket.create_connection((host, port), timeout=8),
|
||||
server_hostname="fixture")
|
||||
req = "%s %s HTTP/1.1\r\nHost: %s:%d\r\nAccept: */*\r\n" % (method, PATH, host, port)
|
||||
if body is not None:
|
||||
req += "Content-Length: %d\r\n" % len(body)
|
||||
req += "\r\n"
|
||||
s.sendall(req.encode() + (body or b""))
|
||||
out = b""
|
||||
while True:
|
||||
chunk = s.recv(4096)
|
||||
if not chunk:
|
||||
break
|
||||
out += chunk
|
||||
s.close()
|
||||
return out
|
||||
|
||||
|
||||
def capture(host, port):
|
||||
result = {"path": PATH, "responses": {}}
|
||||
servers = set()
|
||||
for method, body in (("GET", None), ("HEAD", None), ("POST", b"probe=1")):
|
||||
raw = fetch(host, port, method, body)
|
||||
m = SERVER_RE.search(raw)
|
||||
if m:
|
||||
servers.add(m.group(1).decode())
|
||||
masked = DATE_RE.sub(b"Date: <MASKED>\r\n", raw)
|
||||
masked = SERVER_RE.sub(b"Server: <MASKED>\r\n", masked)
|
||||
result["responses"][method] = masked.hex()
|
||||
if len(servers) != 1:
|
||||
raise SystemExit("oracle returned inconsistent Server headers: %r" % servers)
|
||||
result["observed_server"] = servers.pop()
|
||||
return result
|
||||
|
||||
|
||||
def main():
|
||||
check = "--check" in sys.argv
|
||||
args = [a for a in sys.argv[1:] if not a.startswith("--")]
|
||||
host, port = (args[0].split(":") if args else ("127.0.0.1", "8081"))[0], \
|
||||
int((args[0].split(":")[1] if args and ":" in args[0] else "8081"))
|
||||
|
||||
try:
|
||||
fresh = capture(host, port)
|
||||
except Exception as e:
|
||||
# Explicitly a failure. A --check that silently passes when it could not
|
||||
# reach the oracle is exactly the class of self-confirming tooling this
|
||||
# project has been bitten by repeatedly.
|
||||
raise SystemExit("cannot reach the roster oracle at %s:%d (%s). "
|
||||
"Refusing to report success." % (host, port, e))
|
||||
|
||||
if check:
|
||||
if not os.path.exists(OUT):
|
||||
raise SystemExit("no fixture at %s -- run without --check first" % OUT)
|
||||
with open(OUT) as f:
|
||||
stored = json.load(f)
|
||||
if stored.get("responses") != fresh["responses"]:
|
||||
for m in sorted(set(stored.get("responses", {})) | set(fresh["responses"])):
|
||||
a = stored.get("responses", {}).get(m)
|
||||
b = fresh["responses"].get(m)
|
||||
if a != b:
|
||||
print("MISMATCH %s\n stored: %s\n live : %s" % (m, a, b))
|
||||
raise SystemExit("roster fixtures differ from the live oracle")
|
||||
if stored.get("observed_server") != fresh["observed_server"]:
|
||||
raise SystemExit(
|
||||
"the oracle's Server header changed: %r -> %r.\n"
|
||||
"Update roster::ORACLE_SERVER and regenerate."
|
||||
% (stored.get("observed_server"), fresh["observed_server"]))
|
||||
print("roster fixtures match the live oracle (%d responses, server=%r)"
|
||||
% (len(fresh["responses"]), fresh["observed_server"]))
|
||||
return
|
||||
|
||||
with open(OUT, "w") as f:
|
||||
json.dump(fresh, f, indent=2, sort_keys=True)
|
||||
f.write("\n")
|
||||
print("wrote %s (%d responses, server=%r)"
|
||||
% (OUT, len(fresh["responses"]), fresh["observed_server"]))
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
main()
|
||||
@@ -0,0 +1,6 @@
|
||||
{
|
||||
"127.0.0.1": "485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f786d6c0d0a436f6e74656e742d4c656e6774683a203331350d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a3c3f786d6c2076657273696f6e3d22312e302220656e636f64696e673d225554462d38223f3e0a3c736572766572696e7374616e6365696e666f3e0a093c61646472657373206d656d6265723d2230223e0a09093c76616c753e0a0909093c686f73746e616d653e3132372e302e302e313c2f686f73746e616d653e0a0909093c69703e323133303730363433333c2f69703e0a0909093c706f72743e34323133303c2f706f72743e0a09093c2f76616c753e0a093c2f616464726573733e0a093c7365637572653e303c2f7365637572653e0a093c747269616c736572766963656e616d653e3c2f747269616c736572766963656e616d653e0a093c64656661756c74646e73616464726573733e303c2f64656661756c74646e73616464726573733e0a3c2f736572766572696e7374616e6365696e666f3e0a",
|
||||
"192.0.2.1": "485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f786d6c0d0a436f6e74656e742d4c656e6774683a203331350d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a3c3f786d6c2076657273696f6e3d22312e302220656e636f64696e673d225554462d38223f3e0a3c736572766572696e7374616e6365696e666f3e0a093c61646472657373206d656d6265723d2230223e0a09093c76616c753e0a0909093c686f73746e616d653e3139322e302e322e313c2f686f73746e616d653e0a0909093c69703e333232313232353938353c2f69703e0a0909093c706f72743e34323133303c2f706f72743e0a09093c2f76616c753e0a093c2f616464726573733e0a093c7365637572653e303c2f7365637572653e0a093c747269616c736572766963656e616d653e3c2f747269616c736572766963656e616d653e0a093c64656661756c74646e73616464726573733e303c2f64656661756c74646e73616464726573733e0a3c2f736572766572696e7374616e6365696e666f3e0a",
|
||||
"198.51.100.7": "485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f786d6c0d0a436f6e74656e742d4c656e6774683a203331380d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a3c3f786d6c2076657273696f6e3d22312e302220656e636f64696e673d225554462d38223f3e0a3c736572766572696e7374616e6365696e666f3e0a093c61646472657373206d656d6265723d2230223e0a09093c76616c753e0a0909093c686f73746e616d653e3139382e35312e3130302e373c2f686f73746e616d653e0a0909093c69703e333332353235363731313c2f69703e0a0909093c706f72743e34323133303c2f706f72743e0a09093c2f76616c753e0a093c2f616464726573733e0a093c7365637572653e303c2f7365637572653e0a093c747269616c736572766963656e616d653e3c2f747269616c736572766963656e616d653e0a093c64656661756c74646e73616464726573733e303c2f64656661756c74646e73616464726573733e0a3c2f736572766572696e7374616e6365696e666f3e0a",
|
||||
"203.0.113.42": "485454502f312e3120323030204f4b0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f786d6c0d0a436f6e74656e742d4c656e6774683a203331380d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a3c3f786d6c2076657273696f6e3d22312e302220656e636f64696e673d225554462d38223f3e0a3c736572766572696e7374616e6365696e666f3e0a093c61646472657373206d656d6265723d2230223e0a09093c76616c753e0a0909093c686f73746e616d653e3230332e302e3131332e34323c2f686f73746e616d653e0a0909093c69703e333430353830333831383c2f69703e0a0909093c706f72743e34323133303c2f706f72743e0a09093c2f76616c753e0a093c2f616464726573733e0a093c7365637572653e303c2f7365637572653e0a093c747269616c736572766963656e616d653e3c2f747269616c736572766963656e616d653e0a093c64656661756c74646e73616464726573733e303c2f64656661756c74646e73616464726573733e0a3c2f736572766572696e7374616e6365696e666f3e0a"
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
{
|
||||
"observed_server": "BaseHTTP/0.6 Python/3.12.13",
|
||||
"path": "/fifa17/fut/rosterupdate.xml",
|
||||
"responses": {
|
||||
"GET": "485454502f312e3020323030204f4b0d0a5365727665723a203c4d41534b45443e0d0a446174653a203c4d41534b45443e0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f786d6c0d0a436f6e74656e742d4c656e6774683a2036370d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a3c3f786d6c2076657273696f6e3d22312e302220656e636f64696e673d227574662d38223f3e0a3c726f737465727570646174652076657273696f6e3d2230222f3e0a",
|
||||
"HEAD": "485454502f312e3020323030204f4b0d0a5365727665723a203c4d41534b45443e0d0a446174653a203c4d41534b45443e0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f786d6c0d0a436f6e74656e742d4c656e6774683a2036370d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a",
|
||||
"POST": "485454502f312e3020323030204f4b0d0a5365727665723a203c4d41534b45443e0d0a446174653a203c4d41534b45443e0d0a436f6e74656e742d547970653a206170706c69636174696f6e2f786d6c0d0a436f6e74656e742d4c656e6774683a2036370d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a"
|
||||
}
|
||||
}
|
||||
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
@@ -0,0 +1,14 @@
|
||||
MARKER at-player-search 19:03:01 UTC
|
||||
watermark=13
|
||||
MARKER NO_FILTER 19:04:35 UTC
|
||||
MARKER GOLD 19:16:44 UTC
|
||||
NOTE: the FIFA 17 My Squad UI labels this filter SPECIAL, not Rare. Captured under label SPECIAL.
|
||||
MARKER SPECIAL 19:21:05 UTC
|
||||
MARKER POSITION_ST 19:22:00 UTC
|
||||
MARKER NATION_ARGENTINA 19:22:53 UTC
|
||||
MARKER LEAGUE_PREMIER 19:23:34 UTC
|
||||
MARKER CLUB_CHELSEA 19:24:34 UTC
|
||||
MARKER GOLD_PLUS_ST 19:25:26 UTC
|
||||
MARKER LEAGUE_PLUS_ST 19:27:27 UTC
|
||||
MARKER PAGINATION 19:28:49 UTC
|
||||
NOTE: no sort control exists in the My Squad UI; sort=desc is a client constant.
|
||||
@@ -0,0 +1,84 @@
|
||||
{
|
||||
"routes": {
|
||||
"accountInfo": {
|
||||
"body_len": 2,
|
||||
"fields": {
|
||||
"keys": []
|
||||
},
|
||||
"sha256": "44136fa355b3678a1146ad16f7e8649e94fb4fc21fe77e8310c060f61caaff8a",
|
||||
"status": 200
|
||||
},
|
||||
"activeSquad": {
|
||||
"body_len": 8034,
|
||||
"fields": {
|
||||
"formation": "f442",
|
||||
"id": 0,
|
||||
"players.count": 23,
|
||||
"slots": {
|
||||
"0": 100000003,
|
||||
"1": 100000006,
|
||||
"10": 100000010,
|
||||
"11": 0,
|
||||
"12": 0,
|
||||
"13": 0,
|
||||
"14": 0,
|
||||
"15": 0,
|
||||
"16": 0,
|
||||
"17": 0,
|
||||
"18": 0,
|
||||
"19": 0,
|
||||
"2": 100000005,
|
||||
"20": 0,
|
||||
"21": 0,
|
||||
"22": 0,
|
||||
"3": 100000008,
|
||||
"4": 100000007,
|
||||
"5": 100000002,
|
||||
"6": 100000004,
|
||||
"7": 100000009,
|
||||
"8": 100000001,
|
||||
"9": 100000025
|
||||
}
|
||||
},
|
||||
"sha256": "07e330ed358fbefe31379cd2462aaac4bdc9c85ee28b7500dd2d963e5ea565bd",
|
||||
"status": 200
|
||||
},
|
||||
"credits": {
|
||||
"body_len": 148,
|
||||
"fields": {
|
||||
"credits": 28112944
|
||||
},
|
||||
"sha256": "0a5f3bac80c3a8ee6f088ccf180f5fdcbcbe8a2ef19c7026e4f21876016d7786",
|
||||
"status": 200
|
||||
},
|
||||
"tradePile": {
|
||||
"body_len": 862,
|
||||
"fields": {
|
||||
"auctionInfo.count": 1
|
||||
},
|
||||
"sha256": "b42bab98202209bd8309beb0eca73dba471688e69fef3e014b59901fbc21fe04",
|
||||
"status": 200
|
||||
},
|
||||
"unassigned": {
|
||||
"body_len": 16,
|
||||
"fields": {
|
||||
"itemData.count": 0
|
||||
},
|
||||
"sha256": "873f8bba8baf9c573fc51b54d100c357b3bf0caeb2ccd104245c295e073cf342",
|
||||
"status": 200
|
||||
},
|
||||
"userMassInfo": {
|
||||
"body_len": 8929,
|
||||
"fields": {
|
||||
"clubAbbr": "OFC",
|
||||
"clubName": "OpenFUT",
|
||||
"personaId": 33068179,
|
||||
"trophies": 0
|
||||
},
|
||||
"sha256": "a616aca1742263c47ade9409693e66ec13b50114e608d88bb94141ce80237b66",
|
||||
"status": 200
|
||||
}
|
||||
},
|
||||
"unix": 1786476617.899911,
|
||||
"upstream": "127.0.0.1:8099"
|
||||
}
|
||||
@@ -0,0 +1,84 @@
|
||||
{
|
||||
"routes": {
|
||||
"accountInfo": {
|
||||
"body_len": 2,
|
||||
"fields": {
|
||||
"keys": []
|
||||
},
|
||||
"sha256": "44136fa355b3678a1146ad16f7e8649e94fb4fc21fe77e8310c060f61caaff8a",
|
||||
"status": 200
|
||||
},
|
||||
"activeSquad": {
|
||||
"body_len": 8034,
|
||||
"fields": {
|
||||
"formation": "f442",
|
||||
"id": 0,
|
||||
"players.count": 23,
|
||||
"slots": {
|
||||
"0": 100000003,
|
||||
"1": 100000006,
|
||||
"10": 100000010,
|
||||
"11": 0,
|
||||
"12": 0,
|
||||
"13": 0,
|
||||
"14": 0,
|
||||
"15": 0,
|
||||
"16": 0,
|
||||
"17": 0,
|
||||
"18": 0,
|
||||
"19": 0,
|
||||
"2": 100000005,
|
||||
"20": 0,
|
||||
"21": 0,
|
||||
"22": 0,
|
||||
"3": 100000008,
|
||||
"4": 100000007,
|
||||
"5": 100000002,
|
||||
"6": 100000004,
|
||||
"7": 100000009,
|
||||
"8": 100000001,
|
||||
"9": 100000025
|
||||
}
|
||||
},
|
||||
"sha256": "07e330ed358fbefe31379cd2462aaac4bdc9c85ee28b7500dd2d963e5ea565bd",
|
||||
"status": 200
|
||||
},
|
||||
"credits": {
|
||||
"body_len": 148,
|
||||
"fields": {
|
||||
"credits": 28112944
|
||||
},
|
||||
"sha256": "0a5f3bac80c3a8ee6f088ccf180f5fdcbcbe8a2ef19c7026e4f21876016d7786",
|
||||
"status": 200
|
||||
},
|
||||
"tradePile": {
|
||||
"body_len": 862,
|
||||
"fields": {
|
||||
"auctionInfo.count": 1
|
||||
},
|
||||
"sha256": "b42bab98202209bd8309beb0eca73dba471688e69fef3e014b59901fbc21fe04",
|
||||
"status": 200
|
||||
},
|
||||
"unassigned": {
|
||||
"body_len": 16,
|
||||
"fields": {
|
||||
"itemData.count": 0
|
||||
},
|
||||
"sha256": "873f8bba8baf9c573fc51b54d100c357b3bf0caeb2ccd104245c295e073cf342",
|
||||
"status": 200
|
||||
},
|
||||
"userMassInfo": {
|
||||
"body_len": 8929,
|
||||
"fields": {
|
||||
"clubAbbr": "OFC",
|
||||
"clubName": "OpenFUT",
|
||||
"personaId": 33068179,
|
||||
"trophies": 0
|
||||
},
|
||||
"sha256": "a616aca1742263c47ade9409693e66ec13b50114e608d88bb94141ce80237b66",
|
||||
"status": 200
|
||||
}
|
||||
},
|
||||
"unix": 1786474768.2925124,
|
||||
"upstream": "127.0.0.1:8099"
|
||||
}
|
||||
File diff suppressed because one or more lines are too long
@@ -0,0 +1 @@
|
||||
{"squad": [{"rating": 89, "chemistry": 59, "formation": "f442", "id": 0, "squadName": "OpenFUT", "squadType": "REGULAR_SQUAD"}]}
|
||||
@@ -0,0 +1 @@
|
||||
{"id": 0, "custom": "[0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,50,50,0,50,40,65,0,65,50,50,1]", "squadName": "OpenFUT", "chemistry": 49, "starRating": 90, "rating": 90, "formation": "f433", "squadType": "REGULAR_SQUAD", "manager": [{"id": 100000427, "dream": false}], "players": [{"index": 0, "itemData": {"id": 100000003, "dream": false}, "kitNumber": 1}, {"index": 1, "itemData": {"id": 100000006, "dream": false}, "kitNumber": 4}, {"index": 2, "itemData": {"id": 100000005, "dream": false}, "kitNumber": 3}, {"index": 3, "itemData": {"id": 100000008, "dream": false}, "kitNumber": 6}, {"index": 4, "itemData": {"id": 100000007, "dream": false}, "kitNumber": 5}, {"index": 5, "itemData": {"id": 100000002, "dream": false}, "kitNumber": 9}, {"index": 6, "itemData": {"id": 100000004, "dream": false}, "kitNumber": 2}, {"index": 7, "itemData": {"id": 100000009, "dream": false}, "kitNumber": 7}, {"index": 8, "itemData": {"id": 100000010, "dream": false}, "kitNumber": 10}, {"index": 9, "itemData": {"id": 100000025, "dream": false}, "kitNumber": 11}, {"index": 10, "itemData": {"id": 100000001, "dream": false}, "kitNumber": 8}, {"index": 11, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 12, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 13, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 14, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 15, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 16, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 17, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 18, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 19, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 20, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 21, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 22, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}], "captain": 100000001, "kicktakers": [{"index": 0, "id": 100000001, "dream": false}, {"index": 1, "id": 100000001, "dream": false}, {"index": 2, "id": 100000001, "dream": false}, {"index": 3, "id": 100000001, "dream": false}, {"index": 4, "id": 100000001, "dream": false}]}
|
||||
@@ -0,0 +1 @@
|
||||
{"id":0,"custom":"[0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,50,50,0,50,40,65,0,65,50,50,1]","squadName":"OpenFUT","chemistry":52,"starRating":90,"rating":90,"formation":"f442","squadType":"REGULAR_SQUAD","manager":[{"id":100000427,"dream":false}],"players":[{"index":0,"itemData":{"id":100000003,"dream":false},"kitNumber":1},{"index":1,"itemData":{"id":100000010,"dream":false},"kitNumber":10},{"index":2,"itemData":{"id":100000005,"dream":false},"kitNumber":3},{"index":3,"itemData":{"id":100000008,"dream":false},"kitNumber":6},{"index":4,"itemData":{"id":100000007,"dream":false},"kitNumber":5},{"index":5,"itemData":{"id":100000006,"dream":false},"kitNumber":4},{"index":6,"itemData":{"id":100000004,"dream":false},"kitNumber":2},{"index":7,"itemData":{"id":100000009,"dream":false},"kitNumber":7},{"index":8,"itemData":{"id":100000001,"dream":false},"kitNumber":8},{"index":9,"itemData":{"id":100000002,"dream":false},"kitNumber":9},{"index":10,"itemData":{"id":100000025,"dream":false},"kitNumber":11},{"index":11,"itemData":{"id":0,"dream":false},"kitNumber":0},{"index":12,"itemData":{"id":0,"dream":false},"kitNumber":0},{"index":13,"itemData":{"id":0,"dream":false},"kitNumber":0},{"index":14,"itemData":{"id":0,"dream":false},"kitNumber":0},{"index":15,"itemData":{"id":0,"dream":false},"kitNumber":0},{"index":16,"itemData":{"id":0,"dream":false},"kitNumber":0},{"index":17,"itemData":{"id":0,"dream":false},"kitNumber":0},{"index":18,"itemData":{"id":0,"dream":false},"kitNumber":0},{"index":19,"itemData":{"id":0,"dream":false},"kitNumber":0},{"index":20,"itemData":{"id":0,"dream":false},"kitNumber":0},{"index":21,"itemData":{"id":0,"dream":false},"kitNumber":0},{"index":22,"itemData":{"id":0,"dream":false},"kitNumber":0}],"captain":100000001,"kicktakers":[{"index":0,"id":100000001,"dream":false},{"index":1,"id":100000001,"dream":false},{"index":2,"id":100000001,"dream":false},{"index":3,"id":100000001,"dream":false},{"index":4,"id":100000001,"dream":false}]}
|
||||
@@ -0,0 +1 @@
|
||||
{"id": 0, "custom": "[0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,50,50,0,50,40,65,0,65,50,50,1]", "squadName": "OpenFUT", "chemistry": 58, "starRating": 90, "rating": 90, "formation": "f442", "squadType": "REGULAR_SQUAD", "manager": [{"id": 100000427, "dream": false}], "players": [{"index": 0, "itemData": {"id": 100000003, "dream": false}, "kitNumber": 1}, {"index": 1, "itemData": {"id": 100000006, "dream": false}, "kitNumber": 4}, {"index": 2, "itemData": {"id": 100000005, "dream": false}, "kitNumber": 3}, {"index": 3, "itemData": {"id": 100000008, "dream": false}, "kitNumber": 6}, {"index": 4, "itemData": {"id": 100000007, "dream": false}, "kitNumber": 5}, {"index": 5, "itemData": {"id": 100000002, "dream": false}, "kitNumber": 9}, {"index": 6, "itemData": {"id": 100000004, "dream": false}, "kitNumber": 2}, {"index": 7, "itemData": {"id": 100000009, "dream": false}, "kitNumber": 7}, {"index": 8, "itemData": {"id": 100000001, "dream": false}, "kitNumber": 8}, {"index": 9, "itemData": {"id": 100000010, "dream": false}, "kitNumber": 10}, {"index": 10, "itemData": {"id": 100000025, "dream": false}, "kitNumber": 11}, {"index": 11, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 12, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 13, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 14, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 15, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 16, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 17, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 18, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 19, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 20, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 21, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}, {"index": 22, "itemData": {"id": 0, "dream": false}, "kitNumber": 0}], "captain": 100000001, "kicktakers": [{"index": 0, "id": 100000001, "dream": false}, {"index": 1, "id": 100000001, "dream": false}, {"index": 2, "id": 100000001, "dream": false}, {"index": 3, "id": 100000001, "dream": false}, {"index": 4, "id": 100000001, "dream": false}]}
|
||||
File diff suppressed because one or more lines are too long
@@ -0,0 +1,84 @@
|
||||
{
|
||||
"routes": {
|
||||
"accountInfo": {
|
||||
"body_len": 2,
|
||||
"fields": {
|
||||
"keys": []
|
||||
},
|
||||
"sha256": "44136fa355b3678a1146ad16f7e8649e94fb4fc21fe77e8310c060f61caaff8a",
|
||||
"status": 200
|
||||
},
|
||||
"activeSquad": {
|
||||
"body_len": 8034,
|
||||
"fields": {
|
||||
"formation": "f442",
|
||||
"id": 0,
|
||||
"players.count": 23,
|
||||
"slots": {
|
||||
"0": 100000003,
|
||||
"1": 100000006,
|
||||
"10": 100000010,
|
||||
"11": 0,
|
||||
"12": 0,
|
||||
"13": 0,
|
||||
"14": 0,
|
||||
"15": 0,
|
||||
"16": 0,
|
||||
"17": 0,
|
||||
"18": 0,
|
||||
"19": 0,
|
||||
"2": 100000005,
|
||||
"20": 0,
|
||||
"21": 0,
|
||||
"22": 0,
|
||||
"3": 100000008,
|
||||
"4": 100000007,
|
||||
"5": 100000002,
|
||||
"6": 100000004,
|
||||
"7": 100000009,
|
||||
"8": 100000001,
|
||||
"9": 100000025
|
||||
}
|
||||
},
|
||||
"sha256": "07e330ed358fbefe31379cd2462aaac4bdc9c85ee28b7500dd2d963e5ea565bd",
|
||||
"status": 200
|
||||
},
|
||||
"credits": {
|
||||
"body_len": 148,
|
||||
"fields": {
|
||||
"credits": 28112944
|
||||
},
|
||||
"sha256": "0a5f3bac80c3a8ee6f088ccf180f5fdcbcbe8a2ef19c7026e4f21876016d7786",
|
||||
"status": 200
|
||||
},
|
||||
"tradePile": {
|
||||
"body_len": 862,
|
||||
"fields": {
|
||||
"auctionInfo.count": 1
|
||||
},
|
||||
"sha256": "b42bab98202209bd8309beb0eca73dba471688e69fef3e014b59901fbc21fe04",
|
||||
"status": 200
|
||||
},
|
||||
"unassigned": {
|
||||
"body_len": 16,
|
||||
"fields": {
|
||||
"itemData.count": 0
|
||||
},
|
||||
"sha256": "873f8bba8baf9c573fc51b54d100c357b3bf0caeb2ccd104245c295e073cf342",
|
||||
"status": 200
|
||||
},
|
||||
"userMassInfo": {
|
||||
"body_len": 8929,
|
||||
"fields": {
|
||||
"clubAbbr": "OFC",
|
||||
"clubName": "OpenFUT",
|
||||
"personaId": 33068179,
|
||||
"trophies": 0
|
||||
},
|
||||
"sha256": "a616aca1742263c47ade9409693e66ec13b50114e608d88bb94141ce80237b66",
|
||||
"status": 200
|
||||
}
|
||||
},
|
||||
"unix": 1786472465.339646,
|
||||
"upstream": "127.0.0.1:8099"
|
||||
}
|
||||
@@ -0,0 +1,84 @@
|
||||
{
|
||||
"routes": {
|
||||
"accountInfo": {
|
||||
"body_len": 2,
|
||||
"fields": {
|
||||
"keys": []
|
||||
},
|
||||
"sha256": "44136fa355b3678a1146ad16f7e8649e94fb4fc21fe77e8310c060f61caaff8a",
|
||||
"status": 200
|
||||
},
|
||||
"activeSquad": {
|
||||
"body_len": 8034,
|
||||
"fields": {
|
||||
"formation": "f442",
|
||||
"id": 0,
|
||||
"players.count": 23,
|
||||
"slots": {
|
||||
"0": 100000003,
|
||||
"1": 100000010,
|
||||
"10": 100000001,
|
||||
"11": 100000002,
|
||||
"12": 0,
|
||||
"13": 0,
|
||||
"14": 0,
|
||||
"15": 0,
|
||||
"16": 0,
|
||||
"17": 0,
|
||||
"18": 0,
|
||||
"19": 0,
|
||||
"2": 100000009,
|
||||
"20": 0,
|
||||
"21": 0,
|
||||
"22": 0,
|
||||
"3": 100000008,
|
||||
"4": 100000007,
|
||||
"5": 100000006,
|
||||
"6": 100000005,
|
||||
"7": 100000004,
|
||||
"8": 100000025,
|
||||
"9": 0
|
||||
}
|
||||
},
|
||||
"sha256": "768bb0584ad953ac5f088ad029f161d302ee1be3a63826eb186405acaf1b6232",
|
||||
"status": 200
|
||||
},
|
||||
"credits": {
|
||||
"body_len": 148,
|
||||
"fields": {
|
||||
"credits": 28020656
|
||||
},
|
||||
"sha256": "8d39fee51c24ddee9f12d98d7833af6cd3d3399a0e7567ab7062945a1180e30f",
|
||||
"status": 200
|
||||
},
|
||||
"tradePile": {
|
||||
"body_len": 862,
|
||||
"fields": {
|
||||
"auctionInfo.count": 1
|
||||
},
|
||||
"sha256": "1575046afb8ca60c76de64427ee0c70e1d4ca2da032819a60db95d72d272d11d",
|
||||
"status": 200
|
||||
},
|
||||
"unassigned": {
|
||||
"body_len": 16,
|
||||
"fields": {
|
||||
"itemData.count": 0
|
||||
},
|
||||
"sha256": "873f8bba8baf9c573fc51b54d100c357b3bf0caeb2ccd104245c295e073cf342",
|
||||
"status": 200
|
||||
},
|
||||
"userMassInfo": {
|
||||
"body_len": 8929,
|
||||
"fields": {
|
||||
"clubAbbr": "OFC",
|
||||
"clubName": "OpenFUT",
|
||||
"personaId": 33068179,
|
||||
"trophies": 0
|
||||
},
|
||||
"sha256": "3d89d0497661fc62f107081208a14c4fa5753ee4e6482eeda825fe4b622f871f",
|
||||
"status": 200
|
||||
}
|
||||
},
|
||||
"unix": 1786472102.908128,
|
||||
"upstream": "127.0.0.1:8099"
|
||||
}
|
||||
Executable
+108
@@ -0,0 +1,108 @@
|
||||
#!/usr/bin/env bash
|
||||
# FIFA 17 squad-adapter mutation battery.
|
||||
#
|
||||
# Each mutation injects a specific WRONG behaviour into the committed source,
|
||||
# runs the one test that defends the invariant, and requires that test to FAIL
|
||||
# (non-zero exit) — i.e. the mutant is killed. The source is reverted via
|
||||
# `git checkout` after every mutation, so the tree is left untouched.
|
||||
#
|
||||
# A mutant that SURVIVES (its guard test still passes) means the invariant is
|
||||
# not actually defended; the battery then exits non-zero.
|
||||
#
|
||||
# Run from the adapter crate root: bash mutation-battery.sh
|
||||
set -u
|
||||
cd "$(dirname "$0")"
|
||||
|
||||
FUT=src/fut
|
||||
PASS=0
|
||||
FAIL=0
|
||||
declare -a SURVIVORS=()
|
||||
|
||||
# mutate <file> <literal-old> <literal-new> (literal, multiline-safe)
|
||||
mutate() {
|
||||
OLD="$2" NEW="$3" perl -0777 -pi -e \
|
||||
's/\Q$ENV{OLD}\E/$ENV{NEW}/g or die "MUTATION PATTERN NOT FOUND in '"$1"'\n"' "$1"
|
||||
}
|
||||
|
||||
# kill <n> <label> <test-filter> <file> <old> <new>
|
||||
kill_test() {
|
||||
local n="$1" label="$2" filter="$3" file="$4" old="$5" new="$6"
|
||||
git checkout -- "$file"
|
||||
mutate "$file" "$old" "$new" || { echo " [#$n] SETUP ERROR"; FAIL=$((FAIL+1)); SURVIVORS+=("#$n $label (setup)"); return; }
|
||||
if cargo test --quiet "$filter" >/dev/null 2>&1; then
|
||||
echo " [#$n] SURVIVED — $label (test '$filter' still passed)"
|
||||
FAIL=$((FAIL+1)); SURVIVORS+=("#$n $label")
|
||||
else
|
||||
echo " [#$n] killed — $label"
|
||||
PASS=$((PASS+1))
|
||||
fi
|
||||
git checkout -- "$file"
|
||||
}
|
||||
|
||||
echo "== FIFA17 squad adapter mutation battery =="
|
||||
|
||||
kill_test 1 "kitNumber keyed by slot index, not owned item" \
|
||||
kit_number_is_keyed_by_owned_item_not_slot "$FUT/squad_ext.rs" \
|
||||
'(s.owned_card_id.clone(), s.kit_number)' '(s.index.to_string(), s.kit_number)'
|
||||
|
||||
kill_test 2 "captain emitted using resourceId (asset), not wire id" \
|
||||
fresh_projects_full_23_slot_array_with_captain_wire_id "$FUT/squad_projection.rs" \
|
||||
'captain_wire = id.item_id as i64;' 'captain_wire = id.asset_id as i64;'
|
||||
|
||||
kill_test 3 "client chemistry silently reconciled (shadow lost)" \
|
||||
swap_moves_two_players_with_their_kits_and_round_trips "$FUT/squad_projection.rs" \
|
||||
'"chemistry": ext.client_reported.chemistry,' '"chemistry": 0,'
|
||||
|
||||
kill_test 4 "custom[] regenerated instead of round-tripped verbatim" \
|
||||
custom_is_preserved_byte_for_byte "$FUT/squad_ext.rs" \
|
||||
'custom: put.custom.clone(),' 'custom: Some("[]".to_string()),'
|
||||
|
||||
kill_test 5 "index derived (zeroed) instead of round-tripped" \
|
||||
baseline_projects_the_known_squad_round_trip "$FUT/squad.rs" \
|
||||
'index: p.index,' 'index: 0,'
|
||||
|
||||
kill_test 6 "stale extension accepted and projected" \
|
||||
stale_is_never_applied "$FUT/squad_projection.rs" \
|
||||
'SquadExtInput::Stale(_) => return Ok(SquadProjection::Stale),' 'SquadExtInput::Stale(ext) => ext,'
|
||||
|
||||
kill_test 7 "missing extension fabricates default fields" \
|
||||
missing_is_explicit_never_fabricated "$FUT/squad_projection.rs" \
|
||||
'SquadExtInput::Missing => return Ok(SquadProjection::Missing),' \
|
||||
'SquadExtInput::Missing => return Ok(SquadProjection::Projected(json!({"custom":"[]","manager":[]}))),'
|
||||
|
||||
kill_test 8 "shaper fabricates asset id, bypassing real FIFA identity" \
|
||||
shapes_real_identity_and_reverse_entity_ids "$FUT/item.rs" \
|
||||
'let asset = id.asset_id;' 'let asset = 0;'
|
||||
|
||||
kill_test 9 "duplicate definition collapses owned instances (id=asset)" \
|
||||
two_owned_copies_of_one_definition_stay_distinct_on_the_wire "$FUT/item.rs" \
|
||||
'"id": id.item_id,' '"id": id.asset_id,'
|
||||
|
||||
kill_test 10 "PUT treated as a partial slot diff (drops slots)" \
|
||||
full_replacement_carries_every_occupied_slot_no_diff "$FUT/squad.rs" \
|
||||
'if p.item_data.id == 0 {' 'if p.item_data.id == 0 || p.index > 1 {'
|
||||
|
||||
kill_test 11 "FIFA wire item id stored in canonical replacement" \
|
||||
full_replacement_carries_every_occupied_slot_no_diff "$FUT/squad.rs" \
|
||||
'ProposedSlot {
|
||||
owned_card_id,' 'ProposedSlot {
|
||||
owned_card_id: p.item_data.id.to_string(),'
|
||||
|
||||
kill_test 12 "projector rebuilds items independently of shared shaper" \
|
||||
persisted_read_round_trips_via_reconstructed_canonical_and_extension "$FUT/squad_projection.rs" \
|
||||
'"itemData": shape_item(item, id, ent),' '"itemData": json!({"id": id.item_id}),'
|
||||
|
||||
kill_test 13 "extension schema version ignored on read" \
|
||||
unknown_schema_version_is_rejected_not_coerced "$FUT/squad_ext.rs" \
|
||||
'if schema_version != EXT_SCHEMA_VERSION {' 'if false {'
|
||||
|
||||
kill_test 14 "player state keyed by CardDefinitionId not OwnedItemId" \
|
||||
two_owned_copies_of_one_definition_project_as_distinct_players "$FUT/squad_projection.rs" \
|
||||
'.get(&slot.owned_card_id)' '.get(&item.card_id)'
|
||||
|
||||
echo "== mutants killed: $PASS / $((PASS+FAIL)) =="
|
||||
if [ "$FAIL" -ne 0 ]; then
|
||||
printf 'SURVIVORS:\n'; printf ' - %s\n' "${SURVIVORS[@]}"
|
||||
exit 1
|
||||
fi
|
||||
echo "all mutants killed"
|
||||
@@ -0,0 +1,177 @@
|
||||
//! `Util::fetchClientConfig` tables.
|
||||
//!
|
||||
//! Between 227 and 243 key/value rows per CFID, overwhelmingly the same RS4
|
||||
//! base URL repeated across 212 endpoint keys. The client resolves a per-call
|
||||
//! key (`FUT_RS4_URL_<CALL>`) before a per-module one
|
||||
//! (`FUT_RS4_APIURL_<MODULE>`), and any call left unresolved falls back to a
|
||||
//! real (dead) EA host — which is what produced "there has been an error
|
||||
//! connecting to FIFA 17 Ultimate Team" mid-session when only the boot subset
|
||||
//! was served. The table has to be complete, not representative.
|
||||
//!
|
||||
//! # Why this is data and not code
|
||||
//!
|
||||
//! The rows are reverse-engineered *configuration*, not logic. They live in
|
||||
//! `fixtures/client_config.json`, derived mechanically from the Python oracle
|
||||
//! and templated on `{advertise}`, `{bind}`, `{pow_content_host}` and
|
||||
//! `{pow_host}` so the adapter stays deployable anywhere. Hand-transcribing 400
|
||||
//! string literals would add a class of silent typo no reviewer can catch, and
|
||||
//! `openfut-core` already loads its content from `data/` for the same reason.
|
||||
//!
|
||||
//! The generator does not take its own templating on trust: it substitutes real
|
||||
//! addresses back in and diffs against the oracle for every section before
|
||||
//! writing the file.
|
||||
|
||||
use std::collections::BTreeMap;
|
||||
use std::sync::OnceLock;
|
||||
|
||||
use super::config::AdapterConfig;
|
||||
|
||||
/// Rows for every known CFID, plus `__default__` for unknown ones.
|
||||
const TABLE_JSON: &str = include_str!("../../fixtures/client_config.json");
|
||||
|
||||
type Table = BTreeMap<String, Vec<(String, String)>>;
|
||||
|
||||
fn table() -> &'static Table {
|
||||
static TABLE: OnceLock<Table> = OnceLock::new();
|
||||
TABLE.get_or_init(|| {
|
||||
serde_json::from_str(TABLE_JSON).expect("bundled client_config.json is valid")
|
||||
})
|
||||
}
|
||||
|
||||
/// Resolve the rows for a CFID, with addresses substituted in.
|
||||
///
|
||||
/// Unknown CFIDs deliberately still receive the shared FUT/RS4/POW rows: those
|
||||
/// consumers read a merged `_all` store and which section contributes is
|
||||
/// unproven, so a present-but-shared table is safer than an empty one.
|
||||
pub fn rows_for(cfid: &str, cfg: &AdapterConfig) -> Vec<(String, String)> {
|
||||
let t = table();
|
||||
let rows = t
|
||||
.get(cfid)
|
||||
.or_else(|| t.get("__default__"))
|
||||
.expect("client_config.json always carries a __default__ section");
|
||||
|
||||
// URL-level tokens resolve through AdapterConfig so those helpers are the
|
||||
// single place a URL shape is defined. Host-level tokens cover the values
|
||||
// that are not one of the three standard URLs (roster, POW API).
|
||||
let utas_base = cfg.utas_base();
|
||||
let nucleus_base = cfg.nucleus_base();
|
||||
let pow_content_url = cfg.pow_content_url();
|
||||
|
||||
rows.iter()
|
||||
.map(|(k, v)| {
|
||||
let v = if v.contains('{') {
|
||||
v.replace("{utas_base}", &utas_base)
|
||||
.replace("{nucleus_base}", &nucleus_base)
|
||||
.replace("{pow_content_url}", &pow_content_url)
|
||||
.replace("{advertise}", &cfg.endpoints.advertise)
|
||||
.replace("{bind}", &cfg.endpoints.bind)
|
||||
.replace("{pow_content_host}", &cfg.endpoints.pow_content_host)
|
||||
.replace("{pow_host}", &cfg.endpoints.pow_host)
|
||||
} else {
|
||||
v.clone()
|
||||
};
|
||||
debug_assert!(!v.contains('{'), "unsubstituted token left in {k}: {v}");
|
||||
(k.clone(), v)
|
||||
})
|
||||
.collect()
|
||||
}
|
||||
|
||||
/// Fingerprint of the bundled config table.
|
||||
///
|
||||
/// The table is generated data, so "which binary is this?" is only half the
|
||||
/// question — "which data does it carry?" is the other half. A running host
|
||||
/// logs this at startup so a live FIFA trace can be tied to an exact table, and
|
||||
/// a rebuild that silently picked up regenerated fixtures is visible.
|
||||
///
|
||||
/// FNV-1a, not a security hash and never used as one.
|
||||
pub fn table_fingerprint() -> u64 {
|
||||
let mut hash: u64 = 0xcbf2_9ce4_8422_2325;
|
||||
for byte in TABLE_JSON.as_bytes() {
|
||||
hash ^= *byte as u64;
|
||||
hash = hash.wrapping_mul(0x1000_0000_01b3);
|
||||
}
|
||||
hash
|
||||
}
|
||||
|
||||
/// Every CFID with its own section. Unknown CFIDs are still valid requests.
|
||||
pub fn known_sections() -> Vec<&'static str> {
|
||||
table()
|
||||
.keys()
|
||||
.filter(|k| k.as_str() != "__default__")
|
||||
.map(String::as_str)
|
||||
.collect()
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
fn cfg() -> AdapterConfig {
|
||||
let mut c = AdapterConfig::loopback();
|
||||
c.endpoints.advertise = "198.51.100.7".into();
|
||||
c.endpoints.bind = "0.0.0.0".into();
|
||||
c.endpoints.pow_content_host = "198.51.100.7:8085".into();
|
||||
c.endpoints.pow_host = "198.51.100.7:8094".into();
|
||||
c
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn bundled_table_parses() {
|
||||
assert!(table().contains_key("__default__"));
|
||||
assert!(table().contains_key("BlazeSDK"));
|
||||
assert!(known_sections().len() >= 10);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn default_section_is_the_shared_fut_base() {
|
||||
let rows = rows_for("literally-anything", &cfg());
|
||||
assert_eq!(rows.len(), 227);
|
||||
assert!(rows.iter().any(|(k, _)| k == "FUT_RS4_BASE_URL"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn addresses_are_substituted_not_baked() {
|
||||
let rows = rows_for("BlazeSDK", &cfg());
|
||||
let base = rows
|
||||
.iter()
|
||||
.find(|(k, _)| k == "FUT_RS4_BASE_URL")
|
||||
.expect("base url present");
|
||||
assert_eq!(base.1, "http://198.51.100.7:8099/");
|
||||
assert!(
|
||||
!rows.iter().any(|(_, v)| v.contains('{')),
|
||||
"a template token survived substitution"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn nucleus_follows_bind_reproducing_the_oracle() {
|
||||
let rows = rows_for("BlazeSDK", &cfg());
|
||||
let n = rows.iter().find(|(k, _)| k == "nucleusConnect").unwrap();
|
||||
assert_eq!(n.1, "http://0.0.0.0:42131");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn roster_section_carries_the_roster_urls() {
|
||||
let rows = rows_for("OSDK_ROSTER", &cfg());
|
||||
let r = rows.iter().find(|(k, _)| k == "ROSTER_URL").unwrap();
|
||||
assert_eq!(r.1, "https://198.51.100.7:8081/fifa17/roster/");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn rows_are_sorted_as_the_wire_requires() {
|
||||
// The oracle sorts; the TDF map encoder does not, so order is ours to keep.
|
||||
let rows = rows_for("BlazeSDK", &cfg());
|
||||
let mut sorted = rows.clone();
|
||||
sorted.sort();
|
||||
assert_eq!(rows, sorted);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn every_known_section_substitutes_cleanly() {
|
||||
for cfid in known_sections() {
|
||||
for (k, v) in rows_for(cfid, &cfg()) {
|
||||
assert!(!v.contains('{'), "{cfid}/{k} kept a token: {v}");
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,230 @@
|
||||
//! Adapter configuration: identity and endpoints.
|
||||
//!
|
||||
//! Everything deployment-dependent lives here, injected by the caller. No
|
||||
//! address, port or persona is baked into the response builders — the
|
||||
//! client/server split exists precisely because the Python responders used to
|
||||
//! assume loopback, and rebuilding that assumption in Rust would undo it.
|
||||
//!
|
||||
//! Note the deliberate asymmetry between *bind* and *advertise*: an advertised
|
||||
//! URL must carry the address the CLIENT can reach, which on a two-machine
|
||||
//! deployment is not the address the server binds.
|
||||
|
||||
/// The forged account the whole stack agrees on.
|
||||
///
|
||||
/// Identity has to be byte-identical across LSX, Blaze, POW and UTAS or the
|
||||
/// client rejects the session, so this is one struct passed everywhere rather
|
||||
/// than constants per responder.
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub struct Identity {
|
||||
pub persona_id: i64,
|
||||
pub persona_name: String,
|
||||
/// blazeId / userId. Must be non-zero or login is refused.
|
||||
pub user_id: i64,
|
||||
/// XREF externalId.
|
||||
pub ext_id: i64,
|
||||
pub email: String,
|
||||
/// Must equal `PreAuthResponse.NASP`.
|
||||
pub namespace: String,
|
||||
/// `Blaze::ClientPlatformType`; 4 = pc.
|
||||
pub client_platform: i64,
|
||||
/// `PersonaStatus::Code`; 2 = ACTIVE.
|
||||
pub persona_status: i64,
|
||||
/// `Blaze::UserSessionType`; 0 = normal user.
|
||||
pub user_session_type: i64,
|
||||
/// Fallback locale as a packed four-char int (`'enUS'`). Overwritten per
|
||||
/// session by the client's own preAuth `LANG`/`LOC`.
|
||||
pub account_locale: i64,
|
||||
/// `AccountInfo.LN`, e.g. `"en_US"`.
|
||||
pub locale: String,
|
||||
/// EA offer id.
|
||||
pub content_id: String,
|
||||
pub entitlement_tag: String,
|
||||
/// Must contain `"FIFA17PCBoxContent"` or `"FIFA16PC"` or FUT drops the
|
||||
/// entitlement and the store comes up empty.
|
||||
pub entitlement_group: String,
|
||||
pub title_id: String,
|
||||
pub client_id: String,
|
||||
pub platform: String,
|
||||
}
|
||||
|
||||
impl Default for Identity {
|
||||
/// The project's fixed synthetic offline identity.
|
||||
///
|
||||
/// A default, not a constant: the launcher can select a different persona,
|
||||
/// and FUT saves are isolated per persona id.
|
||||
fn default() -> Identity {
|
||||
Identity {
|
||||
persona_id: 33_068_179,
|
||||
persona_name: "CAGE".into(),
|
||||
user_id: 33_068_179,
|
||||
ext_id: 33_068_179,
|
||||
email: "cage@openfut.local".into(),
|
||||
namespace: "cem_ea_id".into(),
|
||||
client_platform: 4,
|
||||
persona_status: 2,
|
||||
user_session_type: 0,
|
||||
account_locale: 0x656E_5553, // 'enUS'
|
||||
locale: "en_US".into(),
|
||||
content_id: "1027460".into(),
|
||||
entitlement_tag: "ONLINE_ACCESS".into(),
|
||||
entitlement_group: "FIFA17PCBoxContent".into(),
|
||||
title_id: "309111".into(),
|
||||
client_id: "FIFA17-PC-SERVER-BLAZE".into(),
|
||||
platform: "pc".into(),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Where the client should be told to go next.
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub struct Endpoints {
|
||||
/// Address handed to the CLIENT for every next hop. On a split deployment
|
||||
/// this is the backend's LAN address as the game machine sees it.
|
||||
pub advertise: String,
|
||||
/// Address the server binds. Not interchangeable with `advertise`.
|
||||
pub bind: String,
|
||||
/// `host:port` for POW content.
|
||||
pub pow_content_host: String,
|
||||
/// `host:port` for the POW/EASFC API.
|
||||
pub pow_host: String,
|
||||
/// Blaze port ADVERTISED to the client by the redirector.
|
||||
///
|
||||
/// Our choice, not a protocol constant — the client goes wherever
|
||||
/// `<serverinstanceinfo>` sends it. Configurable so a sidecar can be
|
||||
/// advertised on a different port without a rebuild.
|
||||
pub blaze_port: u16,
|
||||
/// UTAS/RS4 port in generated `FUT_RS4_*` URLs.
|
||||
///
|
||||
/// 8099 is the client's own built-in default (`http://easw.easports.com:8099/`
|
||||
/// in CardsDLL), so it is the sane value — but it is still deployment
|
||||
/// configuration, not a constant we are entitled to bake in.
|
||||
pub utas_port: u16,
|
||||
pub telemetry_port: i64,
|
||||
pub ticker_port: i64,
|
||||
pub qos_port: i64,
|
||||
}
|
||||
|
||||
// NOTE: there is deliberately NO `impl Default for Endpoints`.
|
||||
//
|
||||
// A default would silently supply loopback, and a remote deployment that forgot
|
||||
// to set an address would then advertise `127.0.0.1` to a client on another
|
||||
// machine — failing far from the cause. Choosing loopback has to be an explicit
|
||||
// act, so it is a named constructor.
|
||||
|
||||
impl Endpoints {
|
||||
/// Endpoints for a backend the client reaches at `advertise`.
|
||||
///
|
||||
/// POW hosts DERIVE from the advertised host, matching what the deployed
|
||||
/// Python entrypoint does (`POW_HOST="${POW_HOST:-$ADV:8094}"`). They must
|
||||
/// not fall back to loopback independently: that would leave a remote
|
||||
/// deployment emitting loopback POW URLs while every other URL was correct.
|
||||
pub fn advertising(advertise: impl Into<String>) -> Endpoints {
|
||||
let advertise = advertise.into();
|
||||
Endpoints {
|
||||
pow_content_host: format!("{advertise}:8080"),
|
||||
pow_host: format!("{advertise}:8094"),
|
||||
bind: advertise.clone(),
|
||||
advertise,
|
||||
blaze_port: 42130,
|
||||
utas_port: 8099,
|
||||
telemetry_port: 9988,
|
||||
ticker_port: 8999,
|
||||
qos_port: 17502,
|
||||
}
|
||||
}
|
||||
|
||||
/// Explicit local-only / oracle mode: game and backend on one host.
|
||||
///
|
||||
/// Named rather than defaulted so that "everything is loopback" is always a
|
||||
/// decision someone made, and greppable.
|
||||
pub fn loopback() -> Endpoints {
|
||||
Endpoints::advertising("127.0.0.1")
|
||||
}
|
||||
}
|
||||
|
||||
/// Full adapter configuration.
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub struct AdapterConfig {
|
||||
pub identity: Identity,
|
||||
pub endpoints: Endpoints,
|
||||
/// `PreAuthResponse.SVER`. Carries a trailing newline in the oracle; kept
|
||||
/// because it is on the wire, not because it is meaningful.
|
||||
pub server_version: String,
|
||||
}
|
||||
|
||||
/// `PreAuthResponse.SVER`. On the wire, so it is config rather than a literal.
|
||||
pub const DEFAULT_SERVER_VERSION: &str = "Blaze 15.1.1.3.0 (OpenFUT)\n";
|
||||
|
||||
// No `Default` here either, for the same reason as `Endpoints`.
|
||||
|
||||
impl AdapterConfig {
|
||||
/// Adapter serving a client that reaches this backend at `advertise`.
|
||||
pub fn advertising(advertise: impl Into<String>) -> AdapterConfig {
|
||||
AdapterConfig {
|
||||
identity: Identity::default(),
|
||||
endpoints: Endpoints::advertising(advertise),
|
||||
server_version: DEFAULT_SERVER_VERSION.into(),
|
||||
}
|
||||
}
|
||||
|
||||
/// Explicit local-only / oracle mode.
|
||||
pub fn loopback() -> AdapterConfig {
|
||||
AdapterConfig::advertising("127.0.0.1")
|
||||
}
|
||||
|
||||
/// `http://<advertise>:8099/` — the RS4/UTAS base.
|
||||
///
|
||||
/// The trailing slash and the scheme are both mandatory: CardsDLL's
|
||||
/// `ServerSettings::resolve` uses the value verbatim once it contains
|
||||
/// `"://"`, and the auth path breaks without the slash.
|
||||
pub fn utas_base(&self) -> String {
|
||||
format!(
|
||||
"http://{}:{}/",
|
||||
self.endpoints.advertise, self.endpoints.utas_port
|
||||
)
|
||||
}
|
||||
|
||||
/// `http://<bind>:42131` — the Nucleus OAuth stub.
|
||||
///
|
||||
/// This derives from **bind**, not advertise, faithfully reproducing the
|
||||
/// Python oracle. On the live split deployment that makes it
|
||||
/// `http://0.0.0.0:42131`, which the client cannot dial — see the crate
|
||||
/// README and the vault. Reproduced deliberately: changing it would break
|
||||
/// byte parity with the only configuration ever proven to work, and the
|
||||
/// fix belongs in a separate, live-validated change.
|
||||
pub fn nucleus_base(&self) -> String {
|
||||
format!("http://{}:42131", self.endpoints.bind)
|
||||
}
|
||||
|
||||
pub fn pow_content_url(&self) -> String {
|
||||
format!("http://{}", self.endpoints.pow_content_host)
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn utas_base_keeps_scheme_and_trailing_slash() {
|
||||
let mut cfg = AdapterConfig::loopback();
|
||||
cfg.endpoints.advertise = "10.0.0.5".into();
|
||||
assert_eq!(cfg.utas_base(), "http://10.0.0.5:8099/");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn nucleus_follows_bind_not_advertise() {
|
||||
// Documents the oracle's behaviour, including its consequence.
|
||||
let mut cfg = AdapterConfig::loopback();
|
||||
cfg.endpoints.advertise = "10.0.0.5".into();
|
||||
cfg.endpoints.bind = "0.0.0.0".into();
|
||||
assert_eq!(cfg.nucleus_base(), "http://0.0.0.0:42131");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn pow_content_url_has_no_trailing_slash() {
|
||||
let mut cfg = AdapterConfig::loopback();
|
||||
cfg.endpoints.pow_content_host = "10.0.0.5:8085".into();
|
||||
assert_eq!(cfg.pow_content_url(), "http://10.0.0.5:8085");
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,464 @@
|
||||
//! Blaze RPC dispatch: inbound frame → outbound frames.
|
||||
//!
|
||||
//! Three behaviours here are load-bearing and none of them are obvious from the
|
||||
//! individual response shapes:
|
||||
//!
|
||||
//! * **Login answers with four frames, in order**: the reply first, then
|
||||
//! `UserAuthenticated`, `UserSessionExtendedDataUpdate`, `UserAdded`.
|
||||
//! * **An unimplemented RPC still gets an empty reply.** Silence makes the
|
||||
//! client wait for a timeout; an empty reply lets every field fall back to a
|
||||
//! client-side default and the boot continues.
|
||||
//! * **Non-request message types get nothing at all** — answering a reply or a
|
||||
//! notification would desynchronise the client's own correlation.
|
||||
//!
|
||||
//! No error replies are emitted. `msgType` 3 exists, but the error-code
|
||||
//! placement is UNRESOLVED — three clean-room sources disagree between
|
||||
//! `header[14:16]`, a metadata `ERRC`, and a payload `CNTX`/`ERRC` — so
|
||||
//! emitting one would be a guess on the wire. Do not add one without a capture.
|
||||
|
||||
use openfut_protocol_blaze::fire2::{Frame, Header, MsgType};
|
||||
use openfut_protocol_blaze::heat2::{self, Struct, Value};
|
||||
|
||||
use super::config::AdapterConfig;
|
||||
use super::ids::{association_lists, auth, census_data, component, user_sessions, util};
|
||||
use super::responses as r;
|
||||
use super::session::Session;
|
||||
|
||||
/// Everything needed to answer one RPC.
|
||||
pub struct Adapter {
|
||||
pub config: AdapterConfig,
|
||||
}
|
||||
|
||||
impl Adapter {
|
||||
pub fn new(config: AdapterConfig) -> Adapter {
|
||||
Adapter { config }
|
||||
}
|
||||
|
||||
/// Answer one inbound frame.
|
||||
///
|
||||
/// `now` is passed in rather than read from the clock so responses are
|
||||
/// reproducible: several bodies stamp a timestamp, and a hidden clock read
|
||||
/// would make every fixture unrepeatable.
|
||||
pub fn dispatch(
|
||||
&self,
|
||||
header: &Header,
|
||||
body: &Struct,
|
||||
session: &mut Session,
|
||||
now: i64,
|
||||
) -> Vec<Frame> {
|
||||
// Transport-level ping, whatever the component/command.
|
||||
if header.msg_type == MsgType::Ping {
|
||||
return vec![reply(header, Vec::new(), MsgType::PingReply)];
|
||||
}
|
||||
// Only requests are answered.
|
||||
if header.msg_type != MsgType::Message {
|
||||
return Vec::new();
|
||||
}
|
||||
|
||||
let cfg = &self.config;
|
||||
match (header.component, header.command) {
|
||||
// ------------------------------------------------------- Util
|
||||
(component::UTIL, util::PRE_AUTH) => {
|
||||
// preAuth is where the session learns who it is talking to:
|
||||
// the service name is echoed back, and the locale is captured
|
||||
// for every later ALOC field.
|
||||
session.service_name = service_name_of(body);
|
||||
if let Some(loc) =
|
||||
find_nested_int(body, "LANG").or_else(|| find_nested_int(body, "LOC"))
|
||||
{
|
||||
session.account_locale = loc;
|
||||
}
|
||||
let svc = session.service_name.clone();
|
||||
reply_tdf(header, &r::preauth_response(&svc, cfg))
|
||||
}
|
||||
|
||||
(component::UTIL, util::PING) => reply_tdf(header, &r::ping_response(now)),
|
||||
|
||||
(component::UTIL, util::FETCH_CLIENT_CONFIG) => {
|
||||
let cfid = get_str(body, "CFID");
|
||||
reply_tdf(header, &r::fetch_config_response(&cfid, cfg))
|
||||
}
|
||||
|
||||
(component::UTIL, util::POST_AUTH) => {
|
||||
reply_tdf(header, &r::post_auth_response(session, cfg))
|
||||
}
|
||||
|
||||
(component::UTIL, util::FETCH_QOS_CONFIG) => reply_tdf(header, &r::qos_config(cfg)),
|
||||
|
||||
(component::UTIL, util::USER_SETTINGS_LOAD) => {
|
||||
reply_tdf(header, &r::user_settings_response())
|
||||
}
|
||||
|
||||
// Accepted and discarded; the client only needs the ack.
|
||||
(component::UTIL, util::USER_SETTINGS_SAVE)
|
||||
| (component::UTIL, util::SET_CLIENT_STATE)
|
||||
| (component::UTIL, util::SET_CLIENT_METRICS) => empty_reply(header),
|
||||
|
||||
// --------------------------------------------- Authentication
|
||||
(component::AUTHENTICATION, auth::LOGIN) => {
|
||||
session.auth_code = get_str(body, "AUTH");
|
||||
session.logged_in = true;
|
||||
session.login_time = now;
|
||||
self.login_burst(header, session, now)
|
||||
}
|
||||
|
||||
// Same forged session; the request fields differ and are ignored.
|
||||
(component::AUTHENTICATION, auth::TRUSTED_LOGIN)
|
||||
| (component::AUTHENTICATION, auth::EXPRESS_LOGIN) => {
|
||||
session.logged_in = true;
|
||||
session.login_time = now;
|
||||
self.login_burst(header, session, now)
|
||||
}
|
||||
|
||||
// Receiving logout is NORMAL, not a failure: the OSDK state table
|
||||
// orders Connect -> Logout -> VersionCheck -> PCLogin, so this is
|
||||
// the routine "drop any stale session" step before login. It is
|
||||
// only a symptom if login never follows.
|
||||
(component::AUTHENTICATION, auth::LOGOUT) => empty_reply(header),
|
||||
|
||||
(component::AUTHENTICATION, auth::LIST_USER_ENTITLEMENTS2)
|
||||
| (component::AUTHENTICATION, auth::LIST_ENTITLEMENTS)
|
||||
| (component::AUTHENTICATION, auth::LIST_PERSONA_ENTITLEMENTS2)
|
||||
| (component::AUTHENTICATION, auth::GRANT_ENTITLEMENT2) => {
|
||||
reply_tdf(header, &r::entitlements_response(cfg))
|
||||
}
|
||||
|
||||
(component::AUTHENTICATION, auth::GET_AUTH_TOKEN) => {
|
||||
reply_tdf(header, &r::get_auth_token_response(session))
|
||||
}
|
||||
(component::AUTHENTICATION, auth::GET_ACCOUNT) => {
|
||||
reply_tdf(header, &r::account_info(now, cfg))
|
||||
}
|
||||
(component::AUTHENTICATION, auth::GET_PERSONA) => {
|
||||
reply_tdf(header, &r::get_persona_response(now, cfg))
|
||||
}
|
||||
(component::AUTHENTICATION, auth::LIST_PERSONAS) => {
|
||||
reply_tdf(header, &r::list_personas_response(now, cfg))
|
||||
}
|
||||
|
||||
// ---------------------------------------------- UserSessions
|
||||
(component::USER_SESSIONS, user_sessions::UPDATE_NETWORK_INFO) => {
|
||||
// Ack, then re-push the extended data so the client's cached
|
||||
// copy reflects the network info it just reported.
|
||||
vec![
|
||||
reply(header, Vec::new(), MsgType::Reply),
|
||||
notify(
|
||||
component::USER_SESSIONS,
|
||||
user_sessions::notify::EXTENDED_DATA_UPDATE,
|
||||
&r::user_session_extended_data_update(cfg),
|
||||
),
|
||||
]
|
||||
}
|
||||
|
||||
// ------------------------------------------ AssociationLists
|
||||
(component::ASSOCIATION_LISTS, association_lists::GET_LISTS) => {
|
||||
reply_tdf(header, &r::get_lists_response())
|
||||
}
|
||||
|
||||
// ----------------------------------------------- CensusData
|
||||
(component::CENSUS_DATA, census_data::SUBSCRIBE_TO_CENSUS_DATA_UPDATES) => {
|
||||
reply_tdf(header, &r::census_subscribe_response())
|
||||
}
|
||||
|
||||
// An empty reply, never silence: see the module docs.
|
||||
_ => empty_reply(header),
|
||||
}
|
||||
}
|
||||
|
||||
/// Login reply followed by the three UserSessions pushes, in order.
|
||||
///
|
||||
/// The order is the oracle's ("pamplona" order: reply first). The
|
||||
/// alternative ("grid-blaze": notifications first) is also reported to
|
||||
/// work, but only this one is proven against our client, so it is the one
|
||||
/// reproduced.
|
||||
fn login_burst(&self, header: &Header, session: &Session, now: i64) -> Vec<Frame> {
|
||||
let cfg = &self.config;
|
||||
vec![
|
||||
reply(
|
||||
header,
|
||||
heat2::encode(&r::login_response(session, now, cfg)),
|
||||
MsgType::Reply,
|
||||
),
|
||||
notify(
|
||||
component::USER_SESSIONS,
|
||||
user_sessions::notify::USER_AUTHENTICATED,
|
||||
&r::user_session_login_info(session, now, cfg),
|
||||
),
|
||||
notify(
|
||||
component::USER_SESSIONS,
|
||||
user_sessions::notify::EXTENDED_DATA_UPDATE,
|
||||
&r::user_session_extended_data_update(cfg),
|
||||
),
|
||||
notify(
|
||||
component::USER_SESSIONS,
|
||||
user_sessions::notify::USER_ADDED,
|
||||
&r::user_data(session, cfg),
|
||||
),
|
||||
]
|
||||
}
|
||||
}
|
||||
|
||||
// ------------------------------------------------------------------ helpers
|
||||
|
||||
fn reply(request: &Header, payload: Vec<u8>, msg_type: MsgType) -> Frame {
|
||||
let mut frame = Frame::new(
|
||||
request.component,
|
||||
request.command,
|
||||
request.msg_num,
|
||||
msg_type,
|
||||
payload,
|
||||
);
|
||||
// A reply echoes routing verbatim and changes only the msgType bits.
|
||||
frame.header.user_index = request.user_index;
|
||||
frame
|
||||
}
|
||||
|
||||
fn reply_tdf(request: &Header, body: &Struct) -> Vec<Frame> {
|
||||
vec![reply(request, heat2::encode(body), MsgType::Reply)]
|
||||
}
|
||||
|
||||
fn empty_reply(request: &Header) -> Vec<Frame> {
|
||||
vec![reply(request, Vec::new(), MsgType::Reply)]
|
||||
}
|
||||
|
||||
fn notify(component: u16, notify_id: u16, body: &Struct) -> Frame {
|
||||
Frame::notification(component, notify_id, heat2::encode(body))
|
||||
}
|
||||
|
||||
/// `PreAuthRequest.CDAT.SVCN`, echoed back as `INST`.
|
||||
fn service_name_of(body: &Struct) -> String {
|
||||
body.get("CDAT")
|
||||
.and_then(Value::as_struct)
|
||||
.and_then(|c| c.get("SVCN"))
|
||||
.and_then(Value::as_str)
|
||||
.filter(|s| !s.is_empty())
|
||||
.unwrap_or(super::session::DEFAULT_SERVICE_NAME)
|
||||
.to_string()
|
||||
}
|
||||
|
||||
/// Depth-first search for an INT member anywhere in a decoded body.
|
||||
///
|
||||
/// The client has moved which struct carries `LANG`/`LOC` between builds, so
|
||||
/// the oracle searches rather than addressing a fixed path.
|
||||
fn find_nested_int(body: &Struct, tag: &str) -> Option<i64> {
|
||||
for (t, v) in body.iter() {
|
||||
if t.to_label() == tag {
|
||||
if let Value::Int(n) = v {
|
||||
return Some(*n);
|
||||
}
|
||||
}
|
||||
if let Value::Struct(inner) = v {
|
||||
if let Some(found) = find_nested_int(inner, tag) {
|
||||
return Some(found);
|
||||
}
|
||||
}
|
||||
}
|
||||
None
|
||||
}
|
||||
|
||||
fn get_str(body: &Struct, tag: &str) -> String {
|
||||
body.get(tag)
|
||||
.and_then(Value::as_str)
|
||||
.unwrap_or("")
|
||||
.to_string()
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
use openfut_protocol_blaze::heat2::Struct as S;
|
||||
|
||||
fn adapter() -> Adapter {
|
||||
Adapter::new(AdapterConfig::loopback())
|
||||
}
|
||||
|
||||
fn req(component: u16, command: u16) -> Header {
|
||||
Header::new(component, command, 7, MsgType::Message)
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn login_answers_with_reply_then_three_pushes_in_order() {
|
||||
let a = adapter();
|
||||
let mut sess = Session::new("k", 0);
|
||||
let out = a.dispatch(
|
||||
&req(component::AUTHENTICATION, auth::LOGIN),
|
||||
&S::new(),
|
||||
&mut sess,
|
||||
1,
|
||||
);
|
||||
|
||||
assert_eq!(out.len(), 4);
|
||||
assert_eq!(out[0].header.msg_type, MsgType::Reply);
|
||||
let ids: Vec<u16> = out[1..].iter().map(|f| f.header.command).collect();
|
||||
assert_eq!(
|
||||
ids,
|
||||
vec![
|
||||
user_sessions::notify::USER_AUTHENTICATED,
|
||||
user_sessions::notify::EXTENDED_DATA_UPDATE,
|
||||
user_sessions::notify::USER_ADDED,
|
||||
]
|
||||
);
|
||||
for f in &out[1..] {
|
||||
assert_eq!(f.header.msg_type, MsgType::Notification);
|
||||
assert_eq!(f.header.msg_num, 0, "notifications are uncorrelated");
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn unimplemented_rpcs_get_an_empty_reply_not_silence() {
|
||||
let a = adapter();
|
||||
let mut sess = Session::new("k", 0);
|
||||
let out = a.dispatch(&req(0x1234, 0x0001), &S::new(), &mut sess, 1);
|
||||
assert_eq!(out.len(), 1);
|
||||
assert_eq!(out[0].header.msg_type, MsgType::Reply);
|
||||
assert!(out[0].payload.is_empty());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn non_requests_are_ignored_entirely() {
|
||||
let a = adapter();
|
||||
let mut sess = Session::new("k", 0);
|
||||
for mt in [
|
||||
MsgType::Reply,
|
||||
MsgType::Notification,
|
||||
MsgType::ErrorReply,
|
||||
MsgType::PingReply,
|
||||
] {
|
||||
let h = Header::new(component::UTIL, util::PING, 1, mt);
|
||||
assert!(a.dispatch(&h, &S::new(), &mut sess, 1).is_empty(), "{mt:?}");
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn transport_ping_gets_an_empty_ping_reply() {
|
||||
let a = adapter();
|
||||
let mut sess = Session::new("k", 0);
|
||||
let h = Header::new(component::UTIL, util::PING, 1, MsgType::Ping);
|
||||
let out = a.dispatch(&h, &S::new(), &mut sess, 1);
|
||||
assert_eq!(out.len(), 1);
|
||||
assert_eq!(out[0].header.msg_type, MsgType::PingReply);
|
||||
assert!(out[0].payload.is_empty());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn replies_echo_routing_including_user_index() {
|
||||
let a = adapter();
|
||||
let mut sess = Session::new("k", 0);
|
||||
let mut h = req(component::UTIL, util::PING);
|
||||
h.user_index = 7;
|
||||
h.msg_num = 0x4242;
|
||||
let out = a.dispatch(&h, &S::new(), &mut sess, 1);
|
||||
assert_eq!(out[0].header.user_index, 7);
|
||||
assert_eq!(out[0].header.msg_num, 0x4242);
|
||||
assert_eq!(out[0].header.component, component::UTIL);
|
||||
assert_eq!(out[0].header.command, util::PING);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn preauth_captures_locale_and_service_name() {
|
||||
let a = adapter();
|
||||
let mut sess = Session::new("k", 0x656E5553);
|
||||
let body = S::new().with(
|
||||
"CDAT",
|
||||
Value::Struct(
|
||||
S::new()
|
||||
.with("LANG", Value::Int(0x64654445))
|
||||
.with("SVCN", Value::String("fifa-2017-pc-de".into())),
|
||||
),
|
||||
);
|
||||
a.dispatch(&req(component::UTIL, util::PRE_AUTH), &body, &mut sess, 1);
|
||||
assert_eq!(sess.account_locale, 0x64654445);
|
||||
assert_eq!(sess.service_name, "fifa-2017-pc-de");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn preauth_without_svcn_falls_back_to_the_default() {
|
||||
let a = adapter();
|
||||
let mut sess = Session::new("k", 0);
|
||||
a.dispatch(
|
||||
&req(component::UTIL, util::PRE_AUTH),
|
||||
&S::new(),
|
||||
&mut sess,
|
||||
1,
|
||||
);
|
||||
assert_eq!(
|
||||
sess.service_name,
|
||||
super::super::session::DEFAULT_SERVICE_NAME
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn login_records_the_auth_code_for_later_get_auth_token() {
|
||||
let a = adapter();
|
||||
let mut sess = Session::new("k", 0);
|
||||
let body = S::new().with("AUTH", Value::String("CODE-123".into()));
|
||||
a.dispatch(
|
||||
&req(component::AUTHENTICATION, auth::LOGIN),
|
||||
&body,
|
||||
&mut sess,
|
||||
1,
|
||||
);
|
||||
|
||||
let out = a.dispatch(
|
||||
&req(component::AUTHENTICATION, auth::GET_AUTH_TOKEN),
|
||||
&S::new(),
|
||||
&mut sess,
|
||||
1,
|
||||
);
|
||||
let decoded = heat2::decode(&out[0].payload).unwrap();
|
||||
assert_eq!(
|
||||
decoded.get("AUTH").and_then(Value::as_str),
|
||||
Some("CODE-123")
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn update_network_info_acks_then_pushes() {
|
||||
let a = adapter();
|
||||
let mut sess = Session::new("k", 0);
|
||||
let out = a.dispatch(
|
||||
&req(component::USER_SESSIONS, user_sessions::UPDATE_NETWORK_INFO),
|
||||
&S::new(),
|
||||
&mut sess,
|
||||
1,
|
||||
);
|
||||
assert_eq!(out.len(), 2);
|
||||
assert!(out[0].payload.is_empty());
|
||||
assert_eq!(out[1].header.msg_type, MsgType::Notification);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn all_four_entitlement_aliases_agree() {
|
||||
let a = adapter();
|
||||
let mut sess = Session::new("k", 0);
|
||||
let bodies: Vec<Vec<u8>> = [
|
||||
auth::LIST_USER_ENTITLEMENTS2,
|
||||
auth::LIST_ENTITLEMENTS,
|
||||
auth::LIST_PERSONA_ENTITLEMENTS2,
|
||||
auth::GRANT_ENTITLEMENT2,
|
||||
]
|
||||
.iter()
|
||||
.map(|&cmd| {
|
||||
a.dispatch(
|
||||
&req(component::AUTHENTICATION, cmd),
|
||||
&S::new(),
|
||||
&mut sess,
|
||||
1,
|
||||
)[0]
|
||||
.payload
|
||||
.clone()
|
||||
})
|
||||
.collect();
|
||||
assert!(bodies.windows(2).all(|w| w[0] == w[1]));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn finds_a_nested_int_at_any_depth() {
|
||||
let body = S::new().with(
|
||||
"A",
|
||||
Value::Struct(S::new().with("B", Value::Struct(S::new().with("LANG", Value::Int(42))))),
|
||||
);
|
||||
assert_eq!(find_nested_int(&body, "LANG"), Some(42));
|
||||
assert_eq!(find_nested_int(&body, "NOPE"), None);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,269 @@
|
||||
//! FIFA 17 Blaze component, command and notification IDs.
|
||||
//!
|
||||
//! This is exactly the knowledge that must NOT live in
|
||||
//! `openfut-protocol-blaze`: the generic layer routes on numbers, and what
|
||||
//! those numbers mean is per-title.
|
||||
//!
|
||||
//! # Provenance
|
||||
//!
|
||||
//! The Util table was recovered from FIFA17.exe's own `getCommandName` switch
|
||||
//! (jump table `0x141b17af4`). The Authentication table could not be recovered
|
||||
//! statically — the name pool is Denuvo-mutated — so it was obtained by CALLING
|
||||
//! the client's own `getCommandName` (`0x146e0d2a0`) in-process over ids 1..320,
|
||||
//! validated by reproducing the known Util names, and cross-checked against a
|
||||
//! static REST-binding struct (`0x143896a80` → `trustedLogin = 0x0B`).
|
||||
//! UserSessions notification ids come from the clean, unmutated
|
||||
//! `getNotificationName` jump table at `0x141b03f70`.
|
||||
//!
|
||||
//! Names are for diagnostics only. Dispatch matches on the numeric constants.
|
||||
|
||||
pub mod component {
|
||||
pub const AUTHENTICATION: u16 = 0x0001;
|
||||
pub const GAME_MANAGER: u16 = 0x0004;
|
||||
pub const REDIRECTOR: u16 = 0x0005;
|
||||
pub const STATS: u16 = 0x0007;
|
||||
pub const UTIL: u16 = 0x0009;
|
||||
pub const CENSUS_DATA: u16 = 0x000A;
|
||||
pub const CLUBS: u16 = 0x000B;
|
||||
pub const MESSAGING: u16 = 0x000F;
|
||||
pub const ASSOCIATION_LISTS: u16 = 0x0019;
|
||||
pub const GAME_REPORTING: u16 = 0x001C;
|
||||
pub const SPONSORED_EVENTS: u16 = 0x081C;
|
||||
pub const OSDK_SETTINGS: u16 = 0x08C9;
|
||||
pub const USER_SESSIONS: u16 = 0x7802;
|
||||
}
|
||||
|
||||
pub mod util {
|
||||
pub const FETCH_CLIENT_CONFIG: u16 = 0x0001;
|
||||
pub const PING: u16 = 0x0002;
|
||||
pub const PRE_AUTH: u16 = 0x0007;
|
||||
pub const POST_AUTH: u16 = 0x0008;
|
||||
pub const USER_SETTINGS_LOAD: u16 = 0x000A;
|
||||
pub const USER_SETTINGS_SAVE: u16 = 0x000B;
|
||||
pub const FETCH_QOS_CONFIG: u16 = 0x0015;
|
||||
pub const SET_CLIENT_METRICS: u16 = 0x0016;
|
||||
pub const SET_CLIENT_STATE: u16 = 0x001C;
|
||||
}
|
||||
|
||||
pub mod auth {
|
||||
pub const LOGIN: u16 = 0x000A;
|
||||
pub const TRUSTED_LOGIN: u16 = 0x000B;
|
||||
pub const LIST_USER_ENTITLEMENTS2: u16 = 0x001D;
|
||||
pub const GET_ACCOUNT: u16 = 0x001E;
|
||||
pub const LIST_ENTITLEMENTS: u16 = 0x0020;
|
||||
pub const GET_AUTH_TOKEN: u16 = 0x0024;
|
||||
pub const GRANT_ENTITLEMENT2: u16 = 0x0027;
|
||||
pub const LIST_PERSONA_ENTITLEMENTS2: u16 = 0x0030;
|
||||
pub const EXPRESS_LOGIN: u16 = 0x003C;
|
||||
/// Routine "drop any stale session" step before PCLogin, NOT a failure.
|
||||
pub const LOGOUT: u16 = 0x0046;
|
||||
pub const GET_PERSONA: u16 = 0x005A;
|
||||
pub const LIST_PERSONAS: u16 = 0x0064;
|
||||
}
|
||||
|
||||
pub mod user_sessions {
|
||||
pub const UPDATE_NETWORK_INFO: u16 = 0x0014;
|
||||
|
||||
/// Notification ids live in a separate number space from commands.
|
||||
pub mod notify {
|
||||
pub const EXTENDED_DATA_UPDATE: u16 = 0x0001;
|
||||
pub const USER_ADDED: u16 = 0x0002;
|
||||
pub const USER_REMOVED: u16 = 0x0003;
|
||||
pub const USER_UPDATED: u16 = 0x0005;
|
||||
pub const USER_AUTHENTICATED: u16 = 0x0008;
|
||||
pub const USER_UNAUTHENTICATED: u16 = 0x0009;
|
||||
pub const SERVER_DRAINING: u16 = 0x000C;
|
||||
}
|
||||
}
|
||||
|
||||
pub mod association_lists {
|
||||
pub const GET_LISTS: u16 = 0x0006;
|
||||
}
|
||||
|
||||
pub mod census_data {
|
||||
pub const SUBSCRIBE_TO_CENSUS_DATA_UPDATES: u16 = 0x0005;
|
||||
}
|
||||
|
||||
/// Components advertised in `PreAuthResponse.CIDS`.
|
||||
///
|
||||
/// Order is the oracle's and is preserved: `CIDS` is a TDF list, and list
|
||||
/// elements are NOT reordered by the encoder the way struct members are.
|
||||
pub const ADVERTISED_COMPONENT_IDS: [i64; 9] = [
|
||||
component::AUTHENTICATION as i64,
|
||||
component::GAME_MANAGER as i64,
|
||||
component::REDIRECTOR as i64,
|
||||
component::STATS as i64,
|
||||
component::UTIL as i64,
|
||||
component::MESSAGING as i64,
|
||||
component::ASSOCIATION_LISTS as i64,
|
||||
component::GAME_REPORTING as i64,
|
||||
component::USER_SESSIONS as i64,
|
||||
];
|
||||
|
||||
pub fn component_name(component: u16) -> Option<&'static str> {
|
||||
Some(match component {
|
||||
component::AUTHENTICATION => "Authentication",
|
||||
component::GAME_MANAGER => "GameManager",
|
||||
component::REDIRECTOR => "Redirector",
|
||||
component::STATS => "Stats",
|
||||
component::UTIL => "Util",
|
||||
component::CENSUS_DATA => "CensusData",
|
||||
component::CLUBS => "Clubs",
|
||||
component::MESSAGING => "Messaging",
|
||||
component::ASSOCIATION_LISTS => "AssociationLists",
|
||||
component::GAME_REPORTING => "GameReporting",
|
||||
component::SPONSORED_EVENTS => "SponsoredEvents",
|
||||
component::OSDK_SETTINGS => "OSDKSettings",
|
||||
component::USER_SESSIONS => "UserSessions",
|
||||
_ => return None,
|
||||
})
|
||||
}
|
||||
|
||||
pub fn command_name(component: u16, command: u16) -> Option<&'static str> {
|
||||
Some(match (component, command) {
|
||||
(component::UTIL, 0x01) => "fetchClientConfig",
|
||||
(component::UTIL, 0x02) => "ping",
|
||||
(component::UTIL, 0x03) => "setClientData",
|
||||
(component::UTIL, 0x04) => "localizeStrings",
|
||||
(component::UTIL, 0x05) => "getTelemetryServer",
|
||||
(component::UTIL, 0x06) => "getTickerServer",
|
||||
(component::UTIL, 0x07) => "preAuth",
|
||||
(component::UTIL, 0x08) => "postAuth",
|
||||
(component::UTIL, 0x0A) => "userSettingsLoad",
|
||||
(component::UTIL, 0x0B) => "userSettingsSave",
|
||||
(component::UTIL, 0x0C) => "userSettingsLoadAll",
|
||||
(component::UTIL, 0x0E) => "userSettingsDelete",
|
||||
(component::UTIL, 0x0F) => "userSettingsLoadAllForUser",
|
||||
(component::UTIL, 0x14) => "filterForProfanity",
|
||||
(component::UTIL, 0x15) => "fetchQosConfig",
|
||||
(component::UTIL, 0x16) => "setClientMetrics",
|
||||
(component::UTIL, 0x17) => "setConnectionState",
|
||||
(component::UTIL, 0x19) => "getUserOptions",
|
||||
(component::UTIL, 0x1A) => "setUserOptions",
|
||||
(component::UTIL, 0x1B) => "suspendUserPing",
|
||||
(component::UTIL, 0x1C) => "setClientState",
|
||||
|
||||
(component::AUTHENTICATION, 0x0A) => "login",
|
||||
(component::AUTHENTICATION, 0x0B) => "trustedLogin",
|
||||
(component::AUTHENTICATION, 0x14) => "updateAccount",
|
||||
(component::AUTHENTICATION, 0x15) => "upgradeAccount",
|
||||
(component::AUTHENTICATION, 0x1D) => "listUserEntitlements2",
|
||||
(component::AUTHENTICATION, 0x1E) => "getAccount",
|
||||
(component::AUTHENTICATION, 0x1F) => "grantEntitlement",
|
||||
(component::AUTHENTICATION, 0x20) => "listEntitlements",
|
||||
(component::AUTHENTICATION, 0x22) => "getUseCount",
|
||||
(component::AUTHENTICATION, 0x23) => "decrementUseCount",
|
||||
(component::AUTHENTICATION, 0x24) => "getAuthToken",
|
||||
(component::AUTHENTICATION, 0x26) => "getPasswordRules",
|
||||
(component::AUTHENTICATION, 0x27) => "grantEntitlement2",
|
||||
(component::AUTHENTICATION, 0x2B) => "modifyEntitlement2",
|
||||
(component::AUTHENTICATION, 0x2C) => "consumecode",
|
||||
(component::AUTHENTICATION, 0x2D) => "passwordForgot",
|
||||
(component::AUTHENTICATION, 0x2F) => "getPrivacyPolicyContent",
|
||||
(component::AUTHENTICATION, 0x30) => "listPersonaEntitlements2",
|
||||
(component::AUTHENTICATION, 0x33) => "checkAgeReq",
|
||||
(component::AUTHENTICATION, 0x34) => "getOptIn",
|
||||
(component::AUTHENTICATION, 0x35) => "enableOptIn",
|
||||
(component::AUTHENTICATION, 0x36) => "disableOptIn",
|
||||
(component::AUTHENTICATION, 0x3C) => "expressLogin",
|
||||
(component::AUTHENTICATION, 0x46) => "logout",
|
||||
(component::AUTHENTICATION, 0x5A) => "getPersona",
|
||||
(component::AUTHENTICATION, 0x64) => "listPersonas",
|
||||
(component::AUTHENTICATION, 0x65) => "expressCreateAccount",
|
||||
(component::AUTHENTICATION, 0xE6) => "createWalUserSession",
|
||||
(component::AUTHENTICATION, 0xF1) => "acceptLegalDocs",
|
||||
(component::AUTHENTICATION, 0xF2) => "getEmailOptInSettings",
|
||||
(component::AUTHENTICATION, 0xF6) => "getTermsOfServiceContent",
|
||||
(component::AUTHENTICATION, 0x104) => "getOriginPersona",
|
||||
(component::AUTHENTICATION, 0x10E) => "checkEmail",
|
||||
(component::AUTHENTICATION, 0x118) => "getPersonaNameSuggestions",
|
||||
(component::AUTHENTICATION, 0x122) => "guestLogin",
|
||||
|
||||
(component::CENSUS_DATA, 0x01) => "subscribeToCensusData",
|
||||
(component::CENSUS_DATA, 0x02) => "unsubscribeFromCensusData",
|
||||
(component::CENSUS_DATA, 0x03) => "getRegionCounts",
|
||||
(component::CENSUS_DATA, 0x04) => "getLatestCensusData",
|
||||
(component::CENSUS_DATA, 0x05) => "subscribeToCensusDataUpdates",
|
||||
|
||||
(component::USER_SESSIONS, 0x14) => "updateNetworkInfo",
|
||||
(component::ASSOCIATION_LISTS, 0x06) => "getLists",
|
||||
_ => return None,
|
||||
})
|
||||
}
|
||||
|
||||
pub fn notification_name(component: u16, notify_id: u16) -> Option<&'static str> {
|
||||
if component != component::USER_SESSIONS {
|
||||
return None;
|
||||
}
|
||||
Some(match notify_id {
|
||||
0x01 => "UserSessionExtendedDataUpdate",
|
||||
0x02 => "UserAdded",
|
||||
0x03 => "UserRemoved",
|
||||
0x05 => "UserUpdated",
|
||||
0x08 => "UserAuthenticated",
|
||||
0x09 => "UserUnauthenticated",
|
||||
0x0C => "ServerDraining",
|
||||
_ => return None,
|
||||
})
|
||||
}
|
||||
|
||||
/// Human-readable label for a route, for logs and captures.
|
||||
pub fn describe(component: u16, command: u16, is_notification: bool) -> String {
|
||||
let comp = component_name(component)
|
||||
.map(str::to_string)
|
||||
.unwrap_or_else(|| format!("Component:0x{component:04x}"));
|
||||
if is_notification {
|
||||
if let Some(n) = notification_name(component, command) {
|
||||
return format!("{comp}::<{n}>");
|
||||
}
|
||||
return format!("{comp}::<notify:0x{command:04x}>");
|
||||
}
|
||||
match command_name(component, command) {
|
||||
Some(name) => format!("{comp}::{name}"),
|
||||
None => format!("{comp}::cmd:0x{command:04x}"),
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn describes_the_first_rpc_fifa_sends() {
|
||||
assert_eq!(
|
||||
describe(component::UTIL, util::PRE_AUTH, false),
|
||||
"Util::preAuth"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn commands_and_notifications_are_separate_number_spaces() {
|
||||
// 0x0002 is UserSessions "UserAdded" as a notification, but is not a
|
||||
// known UserSessions *command*.
|
||||
assert_eq!(
|
||||
describe(component::USER_SESSIONS, 0x0002, true),
|
||||
"UserSessions::<UserAdded>"
|
||||
);
|
||||
assert_eq!(
|
||||
describe(component::USER_SESSIONS, 0x0002, false),
|
||||
"UserSessions::cmd:0x0002"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn unknown_routes_degrade_to_numbers() {
|
||||
assert_eq!(
|
||||
describe(0x1234, 0x0001, false),
|
||||
"Component:0x1234::cmd:0x0001"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn advertised_components_are_in_oracle_order() {
|
||||
// A list, not a struct: the encoder will NOT sort these, so the order
|
||||
// here is the order on the wire.
|
||||
assert_eq!(ADVERTISED_COMPONENT_IDS[0], 0x0001);
|
||||
assert_eq!(ADVERTISED_COMPONENT_IDS[8], 0x7802);
|
||||
assert_eq!(ADVERTISED_COMPONENT_IDS.len(), 9);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,31 @@
|
||||
//! FIFA 17 Blaze adapter.
|
||||
//!
|
||||
//! Sits on `openfut-protocol-blaze` (Fire2 framing + Heat2/TDF) and supplies
|
||||
//! everything the generic layer deliberately refuses to know: which component
|
||||
//! and command numbers mean what, what each response body must contain, and in
|
||||
//! what order frames leave the server.
|
||||
//!
|
||||
//! ```text
|
||||
//! FIFA 17 client
|
||||
//! │ Fire2 frames
|
||||
//! openfut-protocol-blaze generic: framing + codec
|
||||
//! │ Header + Struct
|
||||
//! blaze::Adapter THIS: FIFA 17 ids, bodies, ordering
|
||||
//! │ (future) semantic calls
|
||||
//! OpenFUT Core game-independent FUT domain
|
||||
//! ```
|
||||
//!
|
||||
//! Blaze is an auth/session/config protocol: no coins, packs, clubs or squads
|
||||
//! appear on this wire, so the adapter carries no FUT domain state and has no
|
||||
//! reason to grow into a second backend.
|
||||
|
||||
pub mod client_config;
|
||||
pub mod config;
|
||||
pub mod dispatch;
|
||||
pub mod ids;
|
||||
pub mod responses;
|
||||
pub mod session;
|
||||
|
||||
pub use config::{AdapterConfig, Endpoints, Identity};
|
||||
pub use dispatch::Adapter;
|
||||
pub use session::Session;
|
||||
@@ -0,0 +1,623 @@
|
||||
//! FIFA 17 Blaze response bodies.
|
||||
//!
|
||||
//! Every builder here mirrors a `Blaze::*` TDF class reversed from FIFA17.exe's
|
||||
//! own reflection metadata. Member counts and tags are not guesses, and the
|
||||
//! comments carry the class addresses so a future reader can re-derive them.
|
||||
//!
|
||||
//! Two recurring rules, both learned the hard way:
|
||||
//!
|
||||
//! * **An absent member is safe; a wrongly-typed one is fatal.** A member the
|
||||
//! client does not receive keeps its client-side default. A member encoded
|
||||
//! with the wrong wire type desynchronises the whole TDF parse. That is why
|
||||
//! `CGID`, `ADDR`, `CVAR` and `ULST` are omitted rather than guessed — their
|
||||
//! union/objid encodings are UNVERIFIED.
|
||||
//! * **Identity must be byte-identical across responses.** `MAIL`/`UID`/`ASRC`
|
||||
//! in `AccountInfo` must match `LoginResponse.SESS` and `PreAuthResponse.NASP`,
|
||||
//! and the session key must be the same string in three places.
|
||||
//!
|
||||
//! Member order in the source below is the oracle's for readability; the
|
||||
//! encoder sorts by packed tag, so source order never reaches the wire.
|
||||
|
||||
use openfut_protocol_blaze::heat2::{Struct, TypeId, Value};
|
||||
|
||||
use super::client_config;
|
||||
use super::config::AdapterConfig;
|
||||
use super::ids::ADVERTISED_COMPONENT_IDS;
|
||||
use super::session::Session;
|
||||
|
||||
fn s(v: impl Into<String>) -> Value {
|
||||
Value::String(v.into())
|
||||
}
|
||||
|
||||
fn i(v: i64) -> Value {
|
||||
Value::Int(v)
|
||||
}
|
||||
|
||||
/// `Blaze::Util::FetchConfigResponse` @0x1448752e0 — a single `CONF`
|
||||
/// map<string,string>.
|
||||
///
|
||||
/// NOT double-nested. The extra nesting exists only inside `PreAuthResponse`,
|
||||
/// where `CONF` is itself a `FetchConfigResponse` whose own single member is
|
||||
/// also called `CONF`. Easy to get wrong.
|
||||
pub fn fetch_config_response(cfid: &str, cfg: &AdapterConfig) -> Struct {
|
||||
let entries = client_config::rows_for(cfid, cfg)
|
||||
.into_iter()
|
||||
.map(|(k, v)| (Value::String(k), Value::String(v)))
|
||||
.collect();
|
||||
Struct::new().with(
|
||||
"CONF",
|
||||
Value::Map {
|
||||
key: TypeId::String,
|
||||
val: TypeId::String,
|
||||
entries,
|
||||
},
|
||||
)
|
||||
}
|
||||
|
||||
/// `Blaze::QosConfigInfo` — 4 members.
|
||||
///
|
||||
/// FIFA 17's descriptor has no `SVID`, unlike Mirror's Edge Catalyst; do not
|
||||
/// add one back from another title's emulator.
|
||||
pub fn qos_config(cfg: &AdapterConfig) -> Struct {
|
||||
Struct::new()
|
||||
.with(
|
||||
"BWPS",
|
||||
Value::Struct(
|
||||
Struct::new()
|
||||
.with("PSA", s(&cfg.endpoints.advertise))
|
||||
.with("PSP", i(cfg.endpoints.qos_port)),
|
||||
),
|
||||
)
|
||||
.with("LNP", i(10))
|
||||
.with(
|
||||
"LTPS",
|
||||
Value::Map {
|
||||
key: TypeId::String,
|
||||
val: TypeId::Struct,
|
||||
entries: vec![],
|
||||
},
|
||||
)
|
||||
.with("TIME", i(5_000_000))
|
||||
}
|
||||
|
||||
/// `Blaze::Util::PreAuthResponse`.
|
||||
pub fn preauth_response(service_name: &str, cfg: &AdapterConfig) -> Struct {
|
||||
let id = &cfg.identity;
|
||||
Struct::new()
|
||||
.with("ASRC", s(&id.title_id))
|
||||
.with(
|
||||
"CIDS",
|
||||
Value::List {
|
||||
elem: TypeId::Int,
|
||||
items: ADVERTISED_COMPONENT_IDS.iter().copied().map(i).collect(),
|
||||
},
|
||||
)
|
||||
.with("CLID", s(&id.client_id))
|
||||
.with(
|
||||
"CONF",
|
||||
Value::Struct(fetch_config_response("BlazeSDK", cfg)),
|
||||
)
|
||||
.with("ESRC", s(&id.title_id))
|
||||
.with("INST", s(service_name)) // echo of CDAT.SVCN
|
||||
.with("MAID", i(0))
|
||||
.with("MINR", i(0))
|
||||
.with("NASP", s(&id.namespace))
|
||||
.with("PILD", s(""))
|
||||
.with("PLAT", s(&id.platform))
|
||||
.with("QOSS", Value::Struct(qos_config(cfg)))
|
||||
.with("RSRC", s(&id.title_id))
|
||||
.with("SVER", s(&cfg.server_version))
|
||||
}
|
||||
|
||||
/// `Blaze::Util::PingResponse` @0x144875560 — exactly one member.
|
||||
///
|
||||
/// v2 also sent `TIME`; that is MEC's field, not FIFA 17's.
|
||||
pub fn ping_response(now: i64) -> Struct {
|
||||
Struct::new().with("STIM", i(now))
|
||||
}
|
||||
|
||||
/// `Blaze::CensusData::SubscribeToCensusDataUpdatesResponse` — 3 TimeValues,
|
||||
/// encoded as INT microseconds.
|
||||
///
|
||||
/// These must be non-zero. The client computes `delay_ms = (CNP + NTMT) / 1000`
|
||||
/// and re-arms a resend timer; an empty reply gives delay 0, which lands the job
|
||||
/// on the scheduler's ready list and produces a ~30/s re-subscribe storm that
|
||||
/// hangs the FUT loading screen.
|
||||
pub fn census_subscribe_response() -> Struct {
|
||||
Struct::new()
|
||||
.with("CNP", i(30 * 1_000_000))
|
||||
.with("NTMT", i(90 * 1_000_000))
|
||||
.with("RTMT", i(300 * 1_000_000))
|
||||
}
|
||||
|
||||
/// `Blaze::Authentication::PersonaDetails` @0x14487cab0 — 6 members.
|
||||
pub fn persona_details(now: i64, cfg: &AdapterConfig) -> Struct {
|
||||
let id = &cfg.identity;
|
||||
Struct::new()
|
||||
.with("DSNM", s(&id.persona_name))
|
||||
.with("LAST", i(now))
|
||||
.with("PID", i(id.persona_id))
|
||||
.with("PLAT", i(id.client_platform))
|
||||
.with("STAS", i(id.persona_status))
|
||||
.with("XREF", i(id.ext_id))
|
||||
}
|
||||
|
||||
/// `Blaze::Authentication::UserLoginInfo` @0x14487cb00 — 8 members.
|
||||
///
|
||||
/// `'1CON'` packs to 0x11, which sorts below `'A'` = 0x21, so it leads.
|
||||
pub fn user_login_info(sess: &Session, now: i64, cfg: &AdapterConfig) -> Struct {
|
||||
let id = &cfg.identity;
|
||||
Struct::new()
|
||||
.with("1CON", i(0))
|
||||
.with("BUID", i(id.user_id)) // must be non-zero
|
||||
.with("FRST", i(0))
|
||||
.with("KEY", s(&sess.session_key)) // must be non-empty
|
||||
.with("LLOG", i(now))
|
||||
.with("MAIL", s(&id.email))
|
||||
.with("PDTL", Value::Struct(persona_details(now, cfg)))
|
||||
.with("UID", i(id.user_id)) // must be non-zero
|
||||
}
|
||||
|
||||
/// `Blaze::Authentication::LoginResponse` @0x14487d170 — exactly 5 members.
|
||||
///
|
||||
/// Diverges from both public MEC emulators, which emit `CNTX`, `ERRC` and a
|
||||
/// top-level `SKEY`. FIFA 17 has none of those: `CNTX`/`ERRC` are the Blaze
|
||||
/// error-metadata block, and the session key lives at `SESS.KEY`.
|
||||
pub fn login_response(sess: &Session, now: i64, cfg: &AdapterConfig) -> Struct {
|
||||
Struct::new()
|
||||
.with("ANON", i(0))
|
||||
.with("NTOS", i(0)) // 1 would divert to the legal-doc flow
|
||||
.with("SESS", Value::Struct(user_login_info(sess, now, cfg)))
|
||||
.with("SPAM", i(1))
|
||||
.with("UNDR", i(0))
|
||||
}
|
||||
|
||||
/// ISO-8601 UTC, matching the oracle's `%Y-%m-%dT%H:%M:%SZ`.
|
||||
///
|
||||
/// Hand-rolled from a Unix timestamp to keep this crate free of a date
|
||||
/// dependency for one format string. Proleptic Gregorian, no leap seconds —
|
||||
/// the same calendar `time.gmtime` uses.
|
||||
fn iso8601_utc(unix: i64) -> String {
|
||||
let days = unix.div_euclid(86_400);
|
||||
let secs = unix.rem_euclid(86_400);
|
||||
let (h, mi, sec) = (secs / 3600, (secs % 3600) / 60, secs % 60);
|
||||
|
||||
// Civil-from-days (Howard Hinnant's algorithm), shifted to a March-based year.
|
||||
let z = days + 719_468;
|
||||
let era = z.div_euclid(146_097);
|
||||
let doe = z.rem_euclid(146_097);
|
||||
let yoe = (doe - doe / 1460 + doe / 36_524 - doe / 146_096) / 365;
|
||||
let y = yoe + era * 400;
|
||||
let doy = doe - (365 * yoe + yoe / 4 - yoe / 100);
|
||||
let mp = (5 * doy + 2) / 153;
|
||||
let d = doy - (153 * mp + 2) / 5 + 1;
|
||||
let m = if mp < 10 { mp + 3 } else { mp - 9 };
|
||||
let y = if m <= 2 { y + 1 } else { y };
|
||||
|
||||
format!("{y:04}-{m:02}-{d:02}T{h:02}:{mi:02}:{sec:02}Z")
|
||||
}
|
||||
|
||||
/// `Blaze::Authentication::AccountInfo` @0x14487c810 — exactly 16 members.
|
||||
///
|
||||
/// The RPC behind the "Unable to retrieve account information" popup: before it
|
||||
/// was implemented, the empty-reply fallback produced an AccountInfo with
|
||||
/// `UID=0`/`CO=""` and the popup appeared one layer later.
|
||||
///
|
||||
/// Member tags come from the reflection tag table @0x1448775a0; wire types from
|
||||
/// each member's subtype descriptor (string subtype 0x144867628 covers ASRC CO
|
||||
/// DOB DTCR LATH LN MAIL PML; the other eight are int/enum). Enum values:
|
||||
/// `STAS` = AccountStatus ACTIVE = 1, `STAT` = EmailStatus VERIFIED = 2,
|
||||
/// `RC` = StatusReason none = 0.
|
||||
pub fn account_info(now: i64, cfg: &AdapterConfig) -> Struct {
|
||||
let id = &cfg.identity;
|
||||
Struct::new()
|
||||
.with("AMU", i(0))
|
||||
.with("ASRC", s(&id.namespace)) // == PreAuthResponse.NASP
|
||||
.with("CO", s("US"))
|
||||
.with("DOB", s("1990-01-01T00:00:00Z"))
|
||||
.with("DTCR", s("2016-09-01T00:00:00Z"))
|
||||
.with("GOPT", i(0))
|
||||
.with("LATH", s(iso8601_utc(now)))
|
||||
.with("LN", s(&id.locale))
|
||||
.with("MAIL", s(&id.email)) // == LoginResponse.SESS.MAIL
|
||||
.with("PML", s(""))
|
||||
.with("RC", i(0))
|
||||
.with("STAS", i(1))
|
||||
.with("STAT", i(2))
|
||||
.with("TPOT", i(0))
|
||||
.with("UDU", i(0))
|
||||
.with("UID", i(id.user_id)) // == LoginResponse.SESS.UID
|
||||
}
|
||||
|
||||
/// `Blaze::Authentication::PersonaInfo` @0x14487c7c0 — 7 members.
|
||||
///
|
||||
/// `STAS` here is PersonaStatus ACTIVE = 2 (table 0x14487ad20) — a different
|
||||
/// enum from AccountInfo's `STAS`, which is AccountStatus ACTIVE = 1. `LADT`'s
|
||||
/// wire type is a best guess (INT timestamp); it is only reachable via
|
||||
/// getPersona/listPersonas, off the critical getAccount path.
|
||||
pub fn persona_info(now: i64, cfg: &AdapterConfig) -> Struct {
|
||||
let id = &cfg.identity;
|
||||
Struct::new()
|
||||
.with("DSNM", s(&id.persona_name))
|
||||
.with("DTCR", s("2016-09-01T00:00:00Z"))
|
||||
.with("LADT", i(now))
|
||||
.with("NSNM", s(&id.namespace))
|
||||
.with("PID", i(id.persona_id))
|
||||
.with("STAS", i(2))
|
||||
.with("STRC", i(0))
|
||||
}
|
||||
|
||||
/// `Blaze::Authentication::GetPersonaResponse` @0x14487d1c0 — PINF + UID.
|
||||
pub fn get_persona_response(now: i64, cfg: &AdapterConfig) -> Struct {
|
||||
Struct::new()
|
||||
.with("PINF", Value::Struct(persona_info(now, cfg)))
|
||||
.with("UID", i(cfg.identity.user_id))
|
||||
}
|
||||
|
||||
/// `Blaze::Authentication::ListPersonasResponse` @0x14487d210 — one member.
|
||||
pub fn list_personas_response(now: i64, cfg: &AdapterConfig) -> Struct {
|
||||
Struct::new().with(
|
||||
"PINF",
|
||||
Value::List {
|
||||
elem: TypeId::Struct,
|
||||
items: vec![Value::Struct(persona_info(now, cfg))],
|
||||
},
|
||||
)
|
||||
}
|
||||
|
||||
/// `Blaze::UserSessionLoginInfo` @0x14486f920 — 16 members.
|
||||
///
|
||||
/// A superset of `UserLoginInfo` with the persona fields flattened in rather
|
||||
/// than nested. `KEY` must be byte-identical to `LoginResponse.SESS.KEY`.
|
||||
///
|
||||
/// `CGID` (a connectionGroup ObjectId) is omitted: the OBJID encoding is
|
||||
/// UNVERIFIED and a wrong one desynchronises the parse, while an absent member
|
||||
/// simply keeps its default.
|
||||
pub fn user_session_login_info(sess: &Session, now: i64, cfg: &AdapterConfig) -> Struct {
|
||||
let id = &cfg.identity;
|
||||
Struct::new()
|
||||
.with("1CON", i(0))
|
||||
.with("ALOC", i(sess.account_locale)) // echo the client's own locale
|
||||
.with("BUID", i(id.user_id))
|
||||
.with("DSNM", s(&id.persona_name))
|
||||
.with("FRST", i(0))
|
||||
.with("KEY", s(&sess.session_key)) // same string as LoginResponse
|
||||
.with("LAST", i(now))
|
||||
.with("LLOG", i(now))
|
||||
.with("MAIL", s(&id.email))
|
||||
.with("NASP", s(&id.namespace))
|
||||
.with("PID", i(id.persona_id))
|
||||
.with("PLAT", i(id.client_platform))
|
||||
.with("UID", i(id.user_id))
|
||||
.with("USTP", i(id.user_session_type))
|
||||
.with("XREF", i(id.ext_id))
|
||||
}
|
||||
|
||||
/// `Blaze::Util::NetworkQosData` @0x14486e680 — 5 members. `NATT` 0 = OPEN.
|
||||
pub fn network_qos_data() -> Struct {
|
||||
Struct::new()
|
||||
.with("BWHR", i(0))
|
||||
.with("DBPS", i(100_000))
|
||||
.with("NAHR", i(0))
|
||||
.with("NATT", i(0))
|
||||
.with("UBPS", i(100_000))
|
||||
}
|
||||
|
||||
/// `Blaze::UserSessionExtendedData` @0x144870390.
|
||||
///
|
||||
/// Two FIFA-17-specific deltas from the MEC emulators: FIFA HAS `PSLM`
|
||||
/// (latencyList), which they lack, and FIFA carries `BPS` as a top-level string
|
||||
/// whereas they bury it inside the `ADDR` union. Follow FIFA's layout.
|
||||
///
|
||||
/// `ADDR`, `CVAR` and `ULST` are omitted — unverified union/objid encodings.
|
||||
pub fn user_session_extended_data() -> Struct {
|
||||
Struct::new()
|
||||
.with("BPS", s("openfut"))
|
||||
.with("CTY", s("US"))
|
||||
.with(
|
||||
"DMAP",
|
||||
Value::Map {
|
||||
key: TypeId::Int,
|
||||
val: TypeId::Int,
|
||||
entries: vec![],
|
||||
},
|
||||
)
|
||||
.with("HWFG", i(0))
|
||||
.with("ISP", s("OpenFUT"))
|
||||
.with(
|
||||
"PSLM",
|
||||
Value::List {
|
||||
elem: TypeId::Int,
|
||||
items: vec![i(0)],
|
||||
},
|
||||
)
|
||||
.with("QDAT", Value::Struct(network_qos_data()))
|
||||
.with("TZ", s(""))
|
||||
.with("UATT", i(0))
|
||||
}
|
||||
|
||||
/// `Blaze::UserSessionExtendedDataUpdate` @0x1448703e0 — 3 members.
|
||||
pub fn user_session_extended_data_update(cfg: &AdapterConfig) -> Struct {
|
||||
Struct::new()
|
||||
.with("DATA", Value::Struct(user_session_extended_data()))
|
||||
.with("SUBS", i(1))
|
||||
.with("USID", i(cfg.identity.user_id))
|
||||
}
|
||||
|
||||
/// `Blaze::UserIdentification` @0x14486ebc0 — 9 members.
|
||||
pub fn user_identification(sess: &Session, cfg: &AdapterConfig) -> Struct {
|
||||
let id = &cfg.identity;
|
||||
Struct::new()
|
||||
.with("AID", i(id.user_id))
|
||||
.with("ALOC", i(sess.account_locale))
|
||||
.with("EXBB", Value::Blob(vec![]))
|
||||
.with("EXID", i(id.ext_id))
|
||||
.with("ID", i(id.user_id))
|
||||
.with("NAME", s(&id.persona_name))
|
||||
.with("NASP", s(&id.namespace))
|
||||
.with("ORIG", i(id.persona_id))
|
||||
.with("PIDI", i(id.persona_id))
|
||||
}
|
||||
|
||||
/// `Blaze::UserData` @0x1448706b0 — payload of the `UserAdded` push.
|
||||
/// `FLGS` is a UserDataFlags bitfield; bit 0 = online/authenticated.
|
||||
pub fn user_data(sess: &Session, cfg: &AdapterConfig) -> Struct {
|
||||
Struct::new()
|
||||
.with("EDAT", Value::Struct(user_session_extended_data()))
|
||||
.with("FLGS", i(3))
|
||||
.with("USER", Value::Struct(user_identification(sess, cfg)))
|
||||
}
|
||||
|
||||
/// `Blaze::Util::PostAuthResponse` @0x144875810 — TELE, TICK, UROP.
|
||||
///
|
||||
/// Telemetry and ticker point at dead local ports on purpose: the client gets a
|
||||
/// well-formed config and then fails to connect quietly, rather than resolving
|
||||
/// a real EA hostname.
|
||||
pub fn post_auth_response(sess: &Session, cfg: &AdapterConfig) -> Struct {
|
||||
let tele = Struct::new()
|
||||
.with("ADRS", s(&cfg.endpoints.advertise))
|
||||
.with("ANON", i(0))
|
||||
.with("DISA", s(""))
|
||||
.with("EDCT", i(0))
|
||||
.with("FILT", s(""))
|
||||
.with("LOC", i(sess.account_locale))
|
||||
.with("MINR", i(0))
|
||||
.with("NOOK", s(""))
|
||||
.with("PORT", i(cfg.endpoints.telemetry_port))
|
||||
.with("SDLY", i(15_000))
|
||||
.with("SESS", s(&sess.session_key)) // same key as login
|
||||
.with("SKEY", s(""))
|
||||
.with("SPCT", i(75))
|
||||
.with("STIM", s(""))
|
||||
.with("SVNM", s("telemetry-openfut"));
|
||||
|
||||
let tick = Struct::new()
|
||||
.with("ADRS", s(&cfg.endpoints.advertise))
|
||||
.with("PORT", i(cfg.endpoints.ticker_port))
|
||||
.with("SKEY", s(""));
|
||||
|
||||
let urop = Struct::new()
|
||||
.with("TMOP", i(0))
|
||||
.with("UID", i(cfg.identity.user_id));
|
||||
|
||||
Struct::new()
|
||||
.with("TELE", Value::Struct(tele))
|
||||
.with("TICK", Value::Struct(tick))
|
||||
.with("UROP", Value::Struct(urop))
|
||||
}
|
||||
|
||||
/// `Blaze::Authentication::Entitlement` @0x14487d490 — 16 members.
|
||||
///
|
||||
/// FUT's client-side filter (`onListEntitlements` @0x146f27440) keeps a record
|
||||
/// only if `GNAM` contains `"FIFA17PCBoxContent"` or `"FIFA16PC"`, `TAG` is
|
||||
/// non-empty, and `STAT == 1`. A plain `"FIFA17PC"` group matched neither
|
||||
/// needle and produced an empty store.
|
||||
///
|
||||
/// `PRID`/`GNAM`/`TAG` must contain no `'|'` and no `'/'`: the client
|
||||
/// re-serialises them as `PRID|GNAM|TAG|UCNT/`.
|
||||
pub fn entitlement(group: &str, tag: &str, eid: i64, cfg: &AdapterConfig) -> Struct {
|
||||
let id = &cfg.identity;
|
||||
Struct::new()
|
||||
.with("DEVI", s(""))
|
||||
.with("GDAY", s("2016-09-01T00:00:00Z"))
|
||||
.with("GNAM", s(group))
|
||||
.with("ID", i(eid))
|
||||
.with("ISCO", i(0))
|
||||
.with("PID", i(id.persona_id))
|
||||
.with("PJID", s(&id.content_id))
|
||||
.with("PRCA", i(2))
|
||||
.with("PRID", s(&id.content_id))
|
||||
.with("STAT", i(1)) // must be 1 or FUT drops it
|
||||
.with("STRC", i(0))
|
||||
.with("TAG", s(tag)) // must be non-empty
|
||||
.with("TDAY", s(""))
|
||||
.with("TYPE", i(1))
|
||||
.with("UCNT", i(0))
|
||||
.with("VER", i(1))
|
||||
}
|
||||
|
||||
/// `Blaze::Authentication::Entitlements` @0x14487d4e0 — single member `NLST`.
|
||||
///
|
||||
/// Emits BOTH accepted groups so the entitlement manager's "loaded" flag
|
||||
/// (`byte[entMgr+0x88]`) flips however the client asks.
|
||||
pub fn entitlements_response(cfg: &AdapterConfig) -> Struct {
|
||||
let tag = &cfg.identity.entitlement_tag;
|
||||
Struct::new().with(
|
||||
"NLST",
|
||||
Value::List {
|
||||
elem: TypeId::Struct,
|
||||
items: vec![
|
||||
Value::Struct(entitlement("FIFA17PCBoxContent", tag, 1, cfg)),
|
||||
Value::Struct(entitlement("FIFA16PC", tag, 2, cfg)),
|
||||
],
|
||||
},
|
||||
)
|
||||
}
|
||||
|
||||
/// `Blaze::Authentication::GetAuthTokenResponse` @0x14487d080 — one member.
|
||||
pub fn get_auth_token_response(sess: &Session) -> Struct {
|
||||
Struct::new().with("AUTH", s(sess.auth_token()))
|
||||
}
|
||||
|
||||
/// `Util::userSettingsLoad` response.
|
||||
///
|
||||
/// TODO(verify): the response descriptor was never reflected. Both independent
|
||||
/// clean-room emulators use a single `DATA` string, and an unknown-tag payload
|
||||
/// is ignored rather than fatal, so an empty `DATA` is the safe minimum — the
|
||||
/// client falls back to its defaults.
|
||||
pub fn user_settings_response() -> Struct {
|
||||
Struct::new().with("DATA", s(""))
|
||||
}
|
||||
|
||||
/// `AssociationLists::getLists` response.
|
||||
///
|
||||
/// TODO(verify): FIFA's association-list names are NOT known — do not invent
|
||||
/// them. An empty list is well-formed and means "this user has no association
|
||||
/// lists", which is true offline.
|
||||
pub fn get_lists_response() -> Struct {
|
||||
Struct::new().with(
|
||||
"LMAP",
|
||||
Value::List {
|
||||
elem: TypeId::Struct,
|
||||
items: vec![],
|
||||
},
|
||||
)
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
fn cfg() -> AdapterConfig {
|
||||
AdapterConfig::loopback()
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn iso8601_matches_known_instants() {
|
||||
assert_eq!(iso8601_utc(0), "1970-01-01T00:00:00Z");
|
||||
assert_eq!(iso8601_utc(1_754_870_400), "2025-08-11T00:00:00Z");
|
||||
// A leap day, to exercise the civil-from-days branch.
|
||||
assert_eq!(iso8601_utc(1_709_164_800), "2024-02-29T00:00:00Z");
|
||||
assert_eq!(iso8601_utc(951_782_400), "2000-02-29T00:00:00Z");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn login_response_has_exactly_five_members() {
|
||||
let sess = Session::new("k", 0);
|
||||
assert_eq!(login_response(&sess, 0, &cfg()).len(), 5);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn account_info_has_exactly_sixteen_members() {
|
||||
assert_eq!(account_info(0, &cfg()).len(), 16);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn session_key_appears_identically_in_all_three_places() {
|
||||
let sess = Session::new("THE-KEY", 0);
|
||||
let c = cfg();
|
||||
|
||||
let login = login_response(&sess, 1, &c);
|
||||
let in_login = login
|
||||
.get("SESS")
|
||||
.and_then(Value::as_struct)
|
||||
.and_then(|s| s.get("KEY"))
|
||||
.and_then(Value::as_str)
|
||||
.unwrap();
|
||||
|
||||
let notify = user_session_login_info(&sess, 1, &c);
|
||||
let in_notify = notify.get("KEY").and_then(Value::as_str).unwrap();
|
||||
|
||||
let post = post_auth_response(&sess, &c);
|
||||
let in_post = post
|
||||
.get("TELE")
|
||||
.and_then(Value::as_struct)
|
||||
.and_then(|s| s.get("SESS"))
|
||||
.and_then(Value::as_str)
|
||||
.unwrap();
|
||||
|
||||
assert_eq!(in_login, "THE-KEY");
|
||||
assert_eq!(in_notify, "THE-KEY");
|
||||
assert_eq!(in_post, "THE-KEY");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn identity_is_consistent_between_login_and_account_info() {
|
||||
let sess = Session::new("k", 0);
|
||||
let c = cfg();
|
||||
let acct = account_info(0, &c);
|
||||
let sess_info = user_login_info(&sess, 0, &c);
|
||||
|
||||
assert_eq!(
|
||||
acct.get("MAIL").and_then(Value::as_str),
|
||||
sess_info.get("MAIL").and_then(Value::as_str)
|
||||
);
|
||||
assert_eq!(
|
||||
acct.get("UID").and_then(Value::as_int),
|
||||
sess_info.get("UID").and_then(Value::as_int)
|
||||
);
|
||||
assert_eq!(
|
||||
acct.get("ASRC").and_then(Value::as_str),
|
||||
Some(c.identity.namespace.as_str())
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn entitlement_groups_match_the_clients_needles() {
|
||||
let c = cfg();
|
||||
let list = entitlements_response(&c);
|
||||
let items = match list.get("NLST") {
|
||||
Some(Value::List { items, .. }) => items,
|
||||
_ => panic!("NLST is a list"),
|
||||
};
|
||||
assert_eq!(items.len(), 2);
|
||||
for item in items {
|
||||
let e = item.as_struct().unwrap();
|
||||
let gnam = e.get("GNAM").and_then(Value::as_str).unwrap();
|
||||
assert!(
|
||||
gnam.contains("FIFA17PCBoxContent") || gnam.contains("FIFA16PC"),
|
||||
"group {gnam} matches neither client needle"
|
||||
);
|
||||
assert_eq!(e.get("STAT").and_then(Value::as_int), Some(1));
|
||||
assert!(!e.get("TAG").and_then(Value::as_str).unwrap().is_empty());
|
||||
// The client re-serialises these delimited; a separator would corrupt it.
|
||||
for tag in ["PRID", "GNAM", "TAG"] {
|
||||
let v = e.get(tag).and_then(Value::as_str).unwrap();
|
||||
assert!(
|
||||
!v.contains('|') && !v.contains('/'),
|
||||
"{tag} has a separator"
|
||||
);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn census_periods_are_non_zero() {
|
||||
// Zero here is the ~30/s storm that hangs the FUT loading screen.
|
||||
let r = census_subscribe_response();
|
||||
assert!(r.get("CNP").and_then(Value::as_int).unwrap() > 0);
|
||||
assert!(r.get("NTMT").and_then(Value::as_int).unwrap() > 0);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn preauth_echoes_the_requested_service_name() {
|
||||
let p = preauth_response("fifa-2017-pc-de", &cfg());
|
||||
assert_eq!(
|
||||
p.get("INST").and_then(Value::as_str),
|
||||
Some("fifa-2017-pc-de")
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn extended_data_omits_the_unverified_members() {
|
||||
// Absent is safe; a wrong union/objid encoding breaks the whole parse.
|
||||
let d = user_session_extended_data();
|
||||
for absent in ["ADDR", "CVAR", "ULST"] {
|
||||
assert!(d.get(absent).is_none(), "{absent} must stay omitted");
|
||||
}
|
||||
assert!(
|
||||
d.get("PSLM").is_some(),
|
||||
"PSLM is FIFA-specific and required"
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,110 @@
|
||||
//! Per-connection Blaze session state.
|
||||
//!
|
||||
//! Note how little there is: a session key, the client's locale, the echoed
|
||||
//! service name, an auth code and a logged-in flag. That is the whole of it.
|
||||
//!
|
||||
//! This is the point of the adapter boundary. Blaze is an auth/session/config
|
||||
//! protocol — coins, packs, clubs, squads and the rest of the FUT domain never
|
||||
//! appear on this wire, so there is nothing here tempting the adapter into
|
||||
//! becoming a second backend. When UTAS is migrated that discipline will need
|
||||
//! actively defending; here it comes for free.
|
||||
|
||||
/// State carried across RPCs on one Blaze connection.
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub struct Session {
|
||||
/// Minted once per connection. Must appear byte-identically in
|
||||
/// `LoginResponse.SESS.KEY`, the `UserAuthenticated` push, and
|
||||
/// `PostAuthResponse.TELE.SESS`.
|
||||
pub session_key: String,
|
||||
/// Whatever `LoginRequest.AUTH` carried; echoed back by `getAuthToken`.
|
||||
pub auth_code: String,
|
||||
/// Packed four-char locale, seeded from config and overwritten by the
|
||||
/// client's own preAuth `LANG`/`LOC`.
|
||||
pub account_locale: i64,
|
||||
/// Echoed back as `PreAuthResponse.INST`.
|
||||
pub service_name: String,
|
||||
pub logged_in: bool,
|
||||
pub login_time: i64,
|
||||
}
|
||||
|
||||
/// The oracle's default service name when preAuth carries no `CDAT.SVCN`.
|
||||
pub const DEFAULT_SERVICE_NAME: &str = "fifa-2017-pc";
|
||||
|
||||
impl Session {
|
||||
/// Start a session with an explicit key.
|
||||
///
|
||||
/// The key is injected rather than generated internally so it can be made
|
||||
/// deterministic for differential tests — it appears verbatim in three
|
||||
/// different responses, so a self-generated one would make every login
|
||||
/// fixture unreproducible.
|
||||
pub fn new(session_key: impl Into<String>, account_locale: i64) -> Session {
|
||||
Session {
|
||||
session_key: session_key.into(),
|
||||
auth_code: String::new(),
|
||||
account_locale,
|
||||
service_name: DEFAULT_SERVICE_NAME.into(),
|
||||
logged_in: false,
|
||||
login_time: 0,
|
||||
}
|
||||
}
|
||||
|
||||
/// The token `getAuthToken` returns.
|
||||
///
|
||||
/// Before login there is no auth code, so the oracle synthesises one from
|
||||
/// the session key. Reproduced exactly, including the 16-character slice.
|
||||
pub fn auth_token(&self) -> String {
|
||||
if !self.auth_code.is_empty() {
|
||||
return self.auth_code.clone();
|
||||
}
|
||||
// Byte slicing is safe here in practice (session keys are ASCII), but
|
||||
// char_indices keeps it correct for any injected key.
|
||||
let cut = self
|
||||
.session_key
|
||||
.char_indices()
|
||||
.nth(16)
|
||||
.map(|(i, _)| i)
|
||||
.unwrap_or(self.session_key.len());
|
||||
format!("OPENFUT-{}", &self.session_key[..cut])
|
||||
}
|
||||
}
|
||||
|
||||
/// Mint a Blaze-shaped session key: 16 hex, an underscore, then 44 alphanumerics.
|
||||
///
|
||||
/// The client never validates the format — one public emulator ships the
|
||||
/// literal `"0"` — so this only has to be stable within a connection. Callers
|
||||
/// supply the randomness so this crate needs no RNG dependency and stays
|
||||
/// deterministic under test.
|
||||
pub fn format_session_key(high_bits: u64, tail: &str) -> String {
|
||||
format!("{high_bits:016x}_{tail}")
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn synthesises_a_token_before_login() {
|
||||
let s = Session::new("0123456789abcdef_TAIL", 0);
|
||||
assert_eq!(s.auth_token(), "OPENFUT-0123456789abcdef");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn echoes_the_login_auth_code_afterwards() {
|
||||
let mut s = Session::new("0123456789abcdef_TAIL", 0);
|
||||
s.auth_code = "REAL-CODE".into();
|
||||
assert_eq!(s.auth_token(), "REAL-CODE");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn short_session_keys_do_not_panic() {
|
||||
assert_eq!(Session::new("abc", 0).auth_token(), "OPENFUT-abc");
|
||||
assert_eq!(Session::new("", 0).auth_token(), "OPENFUT-");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn session_key_has_the_blaze_shape() {
|
||||
let k = format_session_key(0x0123456789abcdef, &"x".repeat(44));
|
||||
assert_eq!(k.len(), 16 + 1 + 44);
|
||||
assert!(k.starts_with("0123456789abcdef_"));
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,411 @@
|
||||
//! FIFA 17 **card-definition identity catalog** and owned-item **wire-id policy**.
|
||||
//!
|
||||
//! Two distinct identities (never conflate them):
|
||||
//!
|
||||
//! * **Card definition** — *what card is this?* A semantic OpenFUT
|
||||
//! `CardDefinitionId` maps to a FIFA 17 render identity here:
|
||||
//! `resource_id = (version << 24) | asset_id`. The client resolves
|
||||
//! `resource_id & 0xFFFFFF` (= `asset_id`) against its own local player DB;
|
||||
//! an invented id renders a blank card, so this catalog is authored from
|
||||
//! verified FIFA 17 data (`pool.json` player asset ids), never guessed.
|
||||
//! * **Owned-item instance** — *which exact copy?* A monotonic integer wire id,
|
||||
//! allocated per account by the generic external-identity store; this module
|
||||
//! only holds the FIFA 17 numeric **policy** ([`Fifa17WireItemIdPolicy`]).
|
||||
//!
|
||||
//! The catalog is game DATA (a versioned JSON file), not deployment config, and
|
||||
//! not a generic-Core concern. Unknown definitions resolve to `None` — callers
|
||||
//! drop them, never fabricate an asset id.
|
||||
|
||||
use std::collections::HashMap;
|
||||
|
||||
use serde::Deserialize;
|
||||
|
||||
use crate::fut::content_taxonomy::ContentKind;
|
||||
|
||||
/// The FIFA 17 render identity of a card definition. `version` is the high byte
|
||||
/// of `resource_id`; `asset_id` (the low 24 bits) is the real FIFA player id.
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub struct Fifa17CardIdentity {
|
||||
pub asset_id: u32,
|
||||
pub version: u8,
|
||||
pub resource_id: u32,
|
||||
/// FIFA wire `rareflag` (rare/special card TYPE). Carried so specials render
|
||||
/// as specials; observed metadata, not a guessed label.
|
||||
pub rareflag: i64,
|
||||
/// Content class of this definition. A catalog authored before this field
|
||||
/// existed defaults to [`ContentKind::Player`] (backward compatible).
|
||||
pub kind: ContentKind,
|
||||
/// FIFA `cardsubtypeid` for a non-player definition (consumable family /
|
||||
/// staff role), `0` for a player or when absent.
|
||||
pub subtype: i64,
|
||||
}
|
||||
|
||||
/// The FIFA 17 numeric namespace policy for owned-item wire ids.
|
||||
///
|
||||
/// Owned-item ids are monotonic from `OWNED_ITEM_BASE + 1` (= 100_000_001,
|
||||
/// matching the oracle's `ITEM_ID_BASE = 100_000_000` and its first minted id),
|
||||
/// staying below the synthetic-overlay ranges the responder uses (≥ 9e8). The
|
||||
/// generic store enforces monotonicity/uniqueness; this type supplies the game,
|
||||
/// entity-kind and base floor.
|
||||
pub struct Fifa17WireItemIdPolicy;
|
||||
|
||||
impl Fifa17WireItemIdPolicy {
|
||||
pub const GAME: &'static str = "fifa17";
|
||||
pub const OWNED_ITEM_KIND: &'static str = "owned-item";
|
||||
pub const OWNED_ITEM_BASE: i64 = 100_000_000;
|
||||
|
||||
/// First owned-item wire id (`100_000_001`).
|
||||
pub fn owned_item_base_floor() -> i64 {
|
||||
Self::OWNED_ITEM_BASE + 1
|
||||
}
|
||||
}
|
||||
|
||||
/// Highest representable asset id (24 bits); above this `version` would be
|
||||
/// clobbered in `resource_id`.
|
||||
const MAX_ASSET_ID: u32 = 0x00FF_FFFF;
|
||||
const SCHEMA_VERSION: u32 = 1;
|
||||
|
||||
/// Catalog load/validation errors — all explicit, no silent fallback.
|
||||
#[derive(Debug, PartialEq, Eq)]
|
||||
pub enum CatalogError {
|
||||
BadSchemaVersion(u32),
|
||||
WrongGame(String),
|
||||
AssetTooLarge {
|
||||
card_id: String,
|
||||
asset_id: u32,
|
||||
},
|
||||
DuplicateResource {
|
||||
resource_id: u32,
|
||||
first: String,
|
||||
second: String,
|
||||
},
|
||||
Parse(String),
|
||||
}
|
||||
|
||||
impl std::fmt::Display for CatalogError {
|
||||
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
|
||||
match self {
|
||||
CatalogError::BadSchemaVersion(v) => {
|
||||
write!(f, "unsupported catalog schema_version {v}")
|
||||
}
|
||||
CatalogError::WrongGame(g) => write!(f, "catalog game is '{g}', expected 'fifa17'"),
|
||||
CatalogError::AssetTooLarge { card_id, asset_id } => {
|
||||
write!(f, "card '{card_id}' asset_id {asset_id} exceeds 24 bits")
|
||||
}
|
||||
CatalogError::DuplicateResource {
|
||||
resource_id,
|
||||
first,
|
||||
second,
|
||||
} => write!(
|
||||
f,
|
||||
"resource_id {resource_id} claimed by both '{first}' and '{second}'"
|
||||
),
|
||||
CatalogError::Parse(e) => write!(f, "catalog parse error: {e}"),
|
||||
}
|
||||
}
|
||||
}
|
||||
impl std::error::Error for CatalogError {}
|
||||
|
||||
#[derive(Deserialize)]
|
||||
struct RawCatalog {
|
||||
schema_version: u32,
|
||||
game: String,
|
||||
#[serde(default)]
|
||||
cards: std::collections::BTreeMap<String, RawCard>,
|
||||
}
|
||||
|
||||
#[derive(Deserialize)]
|
||||
struct RawCard {
|
||||
asset_id: u32,
|
||||
#[serde(default)]
|
||||
version: u8,
|
||||
/// Absent in a base-only catalog → default 1 (rare), preserving prior wire
|
||||
/// behaviour; the production catalog carries the observed value.
|
||||
#[serde(default = "default_rareflag")]
|
||||
rareflag: i64,
|
||||
/// Content class token ("player"|"consumable"|"staff"). Absent → default
|
||||
/// (empty) → [`ContentKind::Player`], so existing player-only catalogs load
|
||||
/// unchanged.
|
||||
#[serde(default)]
|
||||
kind: String,
|
||||
/// FIFA `cardsubtypeid` for a non-player entry; absent → `0`.
|
||||
#[serde(default)]
|
||||
subtype: i64,
|
||||
}
|
||||
|
||||
fn default_rareflag() -> i64 {
|
||||
1
|
||||
}
|
||||
|
||||
/// A loaded, validated FIFA 17 card-definition identity catalog.
|
||||
#[derive(Debug, Default, Clone)]
|
||||
pub struct Fifa17CardCatalog {
|
||||
by_card: HashMap<String, Fifa17CardIdentity>,
|
||||
/// Reverse index: full versioned `resource_id` → the card definition id. The
|
||||
/// wire carries a `resourceId`; the synthetic market must mint the
|
||||
/// authoritative Core `card_id`, never the raw FIFA number.
|
||||
by_resource: HashMap<u32, String>,
|
||||
}
|
||||
|
||||
impl Fifa17CardCatalog {
|
||||
/// Parse + validate a catalog document. Rejects wrong schema/game, an
|
||||
/// asset id that would overflow into the version byte, and two card ids
|
||||
/// claiming the same `resource_id` (a semantic-vs-FIFA identity conflict).
|
||||
pub fn from_json_str(s: &str) -> Result<Self, CatalogError> {
|
||||
let raw: RawCatalog =
|
||||
serde_json::from_str(s).map_err(|e| CatalogError::Parse(e.to_string()))?;
|
||||
if raw.schema_version != SCHEMA_VERSION {
|
||||
return Err(CatalogError::BadSchemaVersion(raw.schema_version));
|
||||
}
|
||||
if raw.game != Fifa17WireItemIdPolicy::GAME {
|
||||
return Err(CatalogError::WrongGame(raw.game));
|
||||
}
|
||||
let mut by_card = HashMap::new();
|
||||
let mut by_resource: HashMap<u32, String> = HashMap::new();
|
||||
for (card_id, rc) in raw.cards {
|
||||
if rc.asset_id > MAX_ASSET_ID {
|
||||
return Err(CatalogError::AssetTooLarge {
|
||||
card_id,
|
||||
asset_id: rc.asset_id,
|
||||
});
|
||||
}
|
||||
let resource_id = ((rc.version as u32) << 24) | rc.asset_id;
|
||||
if let Some(first) = by_resource.get(&resource_id) {
|
||||
return Err(CatalogError::DuplicateResource {
|
||||
resource_id,
|
||||
first: first.clone(),
|
||||
second: card_id,
|
||||
});
|
||||
}
|
||||
by_resource.insert(resource_id, card_id.clone());
|
||||
by_card.insert(
|
||||
card_id,
|
||||
Fifa17CardIdentity {
|
||||
asset_id: rc.asset_id,
|
||||
version: rc.version,
|
||||
resource_id,
|
||||
rareflag: rc.rareflag,
|
||||
kind: ContentKind::from_str(&rc.kind),
|
||||
subtype: rc.subtype,
|
||||
},
|
||||
);
|
||||
}
|
||||
Ok(Fifa17CardCatalog {
|
||||
by_card,
|
||||
by_resource,
|
||||
})
|
||||
}
|
||||
|
||||
/// Load a catalog from a JSON file.
|
||||
pub fn from_file(path: &std::path::Path) -> Result<Self, CatalogError> {
|
||||
let raw = std::fs::read_to_string(path)
|
||||
.map_err(|e| CatalogError::Parse(format!("reading {}: {e}", path.display())))?;
|
||||
Self::from_json_str(&raw)
|
||||
}
|
||||
|
||||
/// The FIFA 17 identity for a definition, or `None` (never a fabricated id).
|
||||
pub fn lookup(&self, card_id: &str) -> Option<Fifa17CardIdentity> {
|
||||
self.by_card.get(card_id).copied()
|
||||
}
|
||||
|
||||
/// Reverse a FIFA wire `resource_id` (full versioned id) to its authoritative
|
||||
/// Core `card_id`, or `None` (never a fabricated/heuristic id). Used by the
|
||||
/// synthetic transfer market so a purchase mints real Core content.
|
||||
pub fn card_id_for_resource(&self, resource_id: u32) -> Option<&str> {
|
||||
self.by_resource.get(&resource_id).map(String::as_str)
|
||||
}
|
||||
|
||||
/// Classify a `card_id` as player/consumable/staff. An unknown definition is
|
||||
/// [`ContentKind::Player`] — the neutral, backward-compatible default (an
|
||||
/// un-catalogued id was always treated as a player-shaped card).
|
||||
pub fn kind_of(&self, card_id: &str) -> ContentKind {
|
||||
self.by_card
|
||||
.get(card_id)
|
||||
.map(|c| c.kind)
|
||||
.unwrap_or(ContentKind::Player)
|
||||
}
|
||||
|
||||
/// The FIFA `cardsubtypeid` for a definition, or `0` if unknown / a player.
|
||||
pub fn subtype_of(&self, card_id: &str) -> i64 {
|
||||
self.by_card.get(card_id).map(|c| c.subtype).unwrap_or(0)
|
||||
}
|
||||
|
||||
pub fn len(&self) -> usize {
|
||||
self.by_card.len()
|
||||
}
|
||||
pub fn is_empty(&self) -> bool {
|
||||
self.by_card.is_empty()
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn resource_id_composition_base_and_special() {
|
||||
let cat = Fifa17CardCatalog::from_json_str(
|
||||
r#"{"schema_version":1,"game":"fifa17","cards":{
|
||||
"card_base":{"asset_id":20801},
|
||||
"card_totw":{"asset_id":20801,"version":3}
|
||||
}}"#,
|
||||
)
|
||||
.unwrap();
|
||||
// version 0 -> resource_id == asset_id
|
||||
let base = cat.lookup("card_base").unwrap();
|
||||
assert_eq!(base.version, 0);
|
||||
assert_eq!(base.resource_id, 20801);
|
||||
assert_eq!(base.resource_id, base.asset_id);
|
||||
// version 3 -> high byte set; same base player, different FIFA card
|
||||
let totw = cat.lookup("card_totw").unwrap();
|
||||
assert_eq!(totw.asset_id, 20801, "asset_id (base player) unchanged");
|
||||
assert_eq!(totw.resource_id, (3u32 << 24) | 20801);
|
||||
assert_ne!(base.resource_id, totw.resource_id);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn unknown_card_is_none() {
|
||||
let cat = Fifa17CardCatalog::from_json_str(
|
||||
r#"{"schema_version":1,"game":"fifa17","cards":{"card_base":{"asset_id":1}}}"#,
|
||||
)
|
||||
.unwrap();
|
||||
assert_eq!(cat.lookup("card_missing"), None);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn two_cards_same_resource_is_a_conflict() {
|
||||
let err = Fifa17CardCatalog::from_json_str(
|
||||
r#"{"schema_version":1,"game":"fifa17","cards":{
|
||||
"card_a":{"asset_id":20801},
|
||||
"card_b":{"asset_id":20801}
|
||||
}}"#,
|
||||
)
|
||||
.unwrap_err();
|
||||
assert!(matches!(
|
||||
err,
|
||||
CatalogError::DuplicateResource {
|
||||
resource_id: 20801,
|
||||
..
|
||||
}
|
||||
));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn schema_and_game_are_validated() {
|
||||
assert_eq!(
|
||||
Fifa17CardCatalog::from_json_str(r#"{"schema_version":2,"game":"fifa17","cards":{}}"#)
|
||||
.unwrap_err(),
|
||||
CatalogError::BadSchemaVersion(2)
|
||||
);
|
||||
assert_eq!(
|
||||
Fifa17CardCatalog::from_json_str(r#"{"schema_version":1,"game":"fifa23","cards":{}}"#)
|
||||
.unwrap_err(),
|
||||
CatalogError::WrongGame("fifa23".into())
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn asset_exceeding_24_bits_is_rejected() {
|
||||
let err = Fifa17CardCatalog::from_json_str(
|
||||
r#"{"schema_version":1,"game":"fifa17","cards":{"c":{"asset_id":16777216}}}"#,
|
||||
)
|
||||
.unwrap_err();
|
||||
assert!(matches!(
|
||||
err,
|
||||
CatalogError::AssetTooLarge {
|
||||
asset_id: 16_777_216,
|
||||
..
|
||||
}
|
||||
));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn malformed_json_is_a_parse_error() {
|
||||
assert!(matches!(
|
||||
Fifa17CardCatalog::from_json_str("{not json").unwrap_err(),
|
||||
CatalogError::Parse(_)
|
||||
));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn deterministic_reload() {
|
||||
let doc = r#"{"schema_version":1,"game":"fifa17","cards":{"a":{"asset_id":10},"b":{"asset_id":20,"version":1}}}"#;
|
||||
let c1 = Fifa17CardCatalog::from_json_str(doc).unwrap();
|
||||
let c2 = Fifa17CardCatalog::from_json_str(doc).unwrap();
|
||||
assert_eq!(c1.lookup("a"), c2.lookup("a"));
|
||||
assert_eq!(c1.lookup("b"), c2.lookup("b"));
|
||||
assert_eq!(c1.len(), 2);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn wire_id_policy_constants() {
|
||||
assert_eq!(Fifa17WireItemIdPolicy::GAME, "fifa17");
|
||||
assert_eq!(Fifa17WireItemIdPolicy::OWNED_ITEM_KIND, "owned-item");
|
||||
assert_eq!(Fifa17WireItemIdPolicy::owned_item_base_floor(), 100_000_001);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn loads_the_committed_generated_catalog() {
|
||||
// The generated base-card catalog (scripts/seed_fifa17_cards.py) must be
|
||||
// loadable by this adapter and carry real asset identities.
|
||||
let path = std::path::Path::new(env!("CARGO_MANIFEST_DIR"))
|
||||
.join("data/fifa17-card-identities.json");
|
||||
if !path.exists() {
|
||||
eprintln!("skip: {} not generated", path.display());
|
||||
return;
|
||||
}
|
||||
let cat = Fifa17CardCatalog::from_file(&path).expect("load committed catalog");
|
||||
assert!(
|
||||
cat.len() > 17_000,
|
||||
"full FIFA17 base pool, got {}",
|
||||
cat.len()
|
||||
);
|
||||
// Ronaldo (asset 20801), version 0 => resource_id == asset_id.
|
||||
let ron = cat
|
||||
.lookup("fifa17_20801")
|
||||
.expect("known base asset present");
|
||||
assert_eq!(ron.asset_id, 20801);
|
||||
assert_eq!(ron.version, 0);
|
||||
assert_eq!(ron.resource_id, 20801);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn legacy_catalog_without_kind_loads_as_player() {
|
||||
// A pre-taxonomy catalog (no `kind`/`subtype`) must load unchanged and
|
||||
// classify every entry as a player, with subtype 0.
|
||||
let cat = Fifa17CardCatalog::from_json_str(
|
||||
r#"{"schema_version":1,"game":"fifa17","cards":{
|
||||
"fifa17_20801":{"asset_id":20801},
|
||||
"fifa17_176580":{"asset_id":176580,"version":5,"rareflag":3}
|
||||
}}"#,
|
||||
)
|
||||
.unwrap();
|
||||
let base = cat.lookup("fifa17_20801").unwrap();
|
||||
assert_eq!(base.kind, ContentKind::Player);
|
||||
assert_eq!(base.subtype, 0);
|
||||
assert_eq!(base.rareflag, 1, "absent rareflag still defaults to 1");
|
||||
assert_eq!(cat.kind_of("fifa17_20801"), ContentKind::Player);
|
||||
assert_eq!(cat.kind_of("fifa17_176580"), ContentKind::Player);
|
||||
// Unknown id -> neutral Player default.
|
||||
assert_eq!(cat.kind_of("fifa17_missing"), ContentKind::Player);
|
||||
assert_eq!(cat.subtype_of("fifa17_missing"), 0);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn kind_and_subtype_are_parsed_for_non_player_entries() {
|
||||
let cat = Fifa17CardCatalog::from_json_str(
|
||||
r#"{"schema_version":1,"game":"fifa17","cards":{
|
||||
"fifa17_20801":{"asset_id":20801,"kind":"player","subtype":0},
|
||||
"fifa17_5003012":{"asset_id":5003012,"kind":"consumable","subtype":54,"rareflag":0},
|
||||
"fifa17_3000083":{"asset_id":3000083,"kind":"staff","subtype":8,"rareflag":0}
|
||||
}}"#,
|
||||
)
|
||||
.unwrap();
|
||||
assert_eq!(cat.kind_of("fifa17_20801"), ContentKind::Player);
|
||||
assert_eq!(cat.kind_of("fifa17_5003012"), ContentKind::Consumable);
|
||||
assert_eq!(cat.subtype_of("fifa17_5003012"), 54);
|
||||
assert_eq!(cat.kind_of("fifa17_3000083"), ContentKind::Staff);
|
||||
assert_eq!(cat.subtype_of("fifa17_3000083"), 8);
|
||||
assert_eq!(cat.lookup("fifa17_5003012").unwrap().rareflag, 0);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,265 @@
|
||||
//! Shape OpenFUT Core's semantic owned inventory into the FIFA 17 `/club`
|
||||
//! response envelope `{"itemData":[ <player item>, … ]}`.
|
||||
//!
|
||||
//! This module owns only the **`/club` envelope**; the per-item shape lives in
|
||||
//! the shared [`crate::fut::item`] primitive so `/club` and squad projection
|
||||
//! emit byte-identical items. Items whose real FIFA asset id is unknown are
|
||||
//! **dropped and counted** here (a collection may omit an unrenderable card);
|
||||
//! squad projection, which cannot omit a starter, refuses instead.
|
||||
|
||||
use serde_json::{json, Value};
|
||||
|
||||
use crate::fut::content_taxonomy::ContentKind;
|
||||
use crate::fut::entities::ReverseEntityResolver;
|
||||
use crate::fut::item::shape_item;
|
||||
// Re-exported so existing `club_response::{…}` callers keep working; the types
|
||||
// are now defined once in `fut::item`.
|
||||
pub use crate::fut::item::{CoreOwnedItem, Fifa17Identity, ItemIdentityResolver, ShapeStats};
|
||||
|
||||
/// Shape the whole `/club` response. Items without a resolvable real asset id
|
||||
/// are dropped (counted in `ShapeStats`), never emitted with a fabricated id.
|
||||
pub fn shape_club_response<I: ItemIdentityResolver + ?Sized>(
|
||||
items: &[CoreOwnedItem],
|
||||
ent: &impl ReverseEntityResolver,
|
||||
ident: &I,
|
||||
) -> (Value, ShapeStats) {
|
||||
let mut out = Vec::with_capacity(items.len());
|
||||
let mut stats = ShapeStats::default();
|
||||
for item in items {
|
||||
// Exclude non-player content (consumables/staff): a `/club` player list
|
||||
// must never render them as 0-rated players. Counted, never emitted.
|
||||
if ident.kind_of(item) != ContentKind::Player {
|
||||
stats.excluded_non_player += 1;
|
||||
continue;
|
||||
}
|
||||
match ident.resolve(item) {
|
||||
Some(id) => {
|
||||
out.push(shape_item(item, id, ent));
|
||||
stats.emitted += 1;
|
||||
}
|
||||
None => stats.dropped_no_asset += 1,
|
||||
}
|
||||
}
|
||||
(json!({ "itemData": out }), stats)
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
use crate::fut::entities::Fifa17Entities;
|
||||
use std::collections::HashMap;
|
||||
|
||||
fn entities() -> Fifa17Entities {
|
||||
Fifa17Entities::from_maps(
|
||||
HashMap::from([(13, "Premier League".to_string())]),
|
||||
HashMap::from([(52, "Argentina".to_string())]),
|
||||
HashMap::from([(5, "Chelsea".to_string())]),
|
||||
)
|
||||
}
|
||||
|
||||
fn item(
|
||||
owned: &str,
|
||||
card: &str,
|
||||
rating: u8,
|
||||
pos: &str,
|
||||
nation: &str,
|
||||
league: &str,
|
||||
club: &str,
|
||||
) -> CoreOwnedItem {
|
||||
CoreOwnedItem {
|
||||
owned_card_id: owned.into(),
|
||||
card_id: card.into(),
|
||||
rating,
|
||||
position: pos.into(),
|
||||
nation: nation.into(),
|
||||
league: league.into(),
|
||||
club: club.into(),
|
||||
attributes: [90, 88, 70, 85, 40, 78],
|
||||
}
|
||||
}
|
||||
|
||||
/// Test resolver: card_id -> real asset id, item_id from a table. Stands in
|
||||
/// for the (unresolved-in-production) Core-card→asset mapping.
|
||||
struct MapIdentity(HashMap<String, Fifa17Identity>);
|
||||
impl ItemIdentityResolver for MapIdentity {
|
||||
fn resolve(&self, it: &CoreOwnedItem) -> Option<Fifa17Identity> {
|
||||
self.0.get(&it.card_id).copied()
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn shapes_item_with_full_field_set_and_reverse_ids() {
|
||||
let ent = entities();
|
||||
let ident = MapIdentity(HashMap::from([(
|
||||
"card_ch_1".to_string(),
|
||||
Fifa17Identity {
|
||||
item_id: 100000001,
|
||||
asset_id: 20801,
|
||||
resource_id: 20801,
|
||||
rareflag: 1,
|
||||
},
|
||||
)]));
|
||||
let items = vec![item(
|
||||
"oc1",
|
||||
"card_ch_1",
|
||||
86,
|
||||
"CDM",
|
||||
"Argentina",
|
||||
"Premier League",
|
||||
"Chelsea",
|
||||
)];
|
||||
let (body, stats) = shape_club_response(&items, &ent, &ident);
|
||||
assert_eq!(stats.emitted, 1);
|
||||
assert_eq!(stats.dropped_no_asset, 0);
|
||||
let it = &body["itemData"][0];
|
||||
assert_eq!(it["id"], 100000001);
|
||||
assert_eq!(it["resourceId"], 20801);
|
||||
assert_eq!(it["assetId"], 20801);
|
||||
assert_eq!(
|
||||
it["definitionId"], 20801,
|
||||
"version byte 0 => resourceId==assetId==definitionId"
|
||||
);
|
||||
assert_eq!(it["rating"], 86);
|
||||
assert_eq!(it["preferredPosition"], "CDM");
|
||||
assert_eq!(it["leagueId"], 13);
|
||||
assert_eq!(it["teamid"], 5);
|
||||
assert_eq!(it["nation"], 52);
|
||||
assert_eq!(it["itemType"], "player");
|
||||
assert_eq!(it["rareflag"], 1);
|
||||
assert_eq!(it["contract"], 7);
|
||||
assert_eq!(it["fitness"], 99);
|
||||
assert_eq!(it["attributeList"].as_array().unwrap().len(), 6);
|
||||
assert_eq!(it["attributeList"][0], json!({"index":0,"value":90}));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn drops_items_without_a_real_asset_id_never_faking() {
|
||||
let ent = entities();
|
||||
// Empty identity map == the current synthetic-catalogue reality.
|
||||
let ident = MapIdentity(HashMap::new());
|
||||
let items = vec![item(
|
||||
"oc1",
|
||||
"card_pl_001",
|
||||
84,
|
||||
"ST",
|
||||
"England",
|
||||
"Premier League",
|
||||
"Northgate United",
|
||||
)];
|
||||
let (body, stats) = shape_club_response(&items, &ent, &ident);
|
||||
assert_eq!(stats.emitted, 0);
|
||||
assert_eq!(stats.dropped_no_asset, 1);
|
||||
assert_eq!(
|
||||
body["itemData"].as_array().unwrap().len(),
|
||||
0,
|
||||
"no fabricated ids emitted"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn unresolved_entity_names_become_neutral_zero_not_dropped() {
|
||||
let ent = entities();
|
||||
let ident = MapIdentity(HashMap::from([(
|
||||
"card_x".to_string(),
|
||||
Fifa17Identity {
|
||||
item_id: 100000002,
|
||||
asset_id: 158023,
|
||||
resource_id: 158023,
|
||||
rareflag: 1,
|
||||
},
|
||||
)]));
|
||||
// Synthetic club "Northgate United" has no FIFA team id.
|
||||
let items = vec![item(
|
||||
"oc2",
|
||||
"card_x",
|
||||
84,
|
||||
"ST",
|
||||
"England",
|
||||
"Premier League",
|
||||
"Northgate United",
|
||||
)];
|
||||
let (body, _) = shape_club_response(&items, &ent, &ident);
|
||||
let it = &body["itemData"][0];
|
||||
assert_eq!(
|
||||
it["teamid"], 0,
|
||||
"unknown club -> neutral 0, item still emitted"
|
||||
);
|
||||
assert_eq!(it["leagueId"], 13);
|
||||
assert_eq!(it["nation"], 0, "England not in the test nation map -> 0");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn envelope_is_itemdata_object() {
|
||||
let ent = entities();
|
||||
let ident = MapIdentity(HashMap::new());
|
||||
let (body, _) = shape_club_response(&[], &ent, &ident);
|
||||
assert!(body.get("itemData").unwrap().is_array());
|
||||
assert_eq!(
|
||||
body.as_object().unwrap().len(),
|
||||
1,
|
||||
"only itemData at top level"
|
||||
);
|
||||
}
|
||||
|
||||
/// A resolver that resolves an asset id for EVERY item (so exclusion is not
|
||||
/// an artifact of a missing asset) but classifies some card_ids as non-player
|
||||
/// via an explicit kind table.
|
||||
struct KindMapIdentity {
|
||||
ids: HashMap<String, Fifa17Identity>,
|
||||
kinds: HashMap<String, ContentKind>,
|
||||
}
|
||||
impl ItemIdentityResolver for KindMapIdentity {
|
||||
fn resolve(&self, it: &CoreOwnedItem) -> Option<Fifa17Identity> {
|
||||
self.ids.get(&it.card_id).copied()
|
||||
}
|
||||
fn kind_of(&self, it: &CoreOwnedItem) -> ContentKind {
|
||||
self.kinds
|
||||
.get(&it.card_id)
|
||||
.copied()
|
||||
.unwrap_or(ContentKind::Player)
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn consumable_and_staff_are_excluded_from_club_players() {
|
||||
let ent = entities();
|
||||
let id = |item_id: u32, asset: u32| Fifa17Identity {
|
||||
item_id,
|
||||
asset_id: asset,
|
||||
resource_id: asset,
|
||||
rareflag: 1,
|
||||
};
|
||||
let ident = KindMapIdentity {
|
||||
ids: HashMap::from([
|
||||
("card_player".to_string(), id(100000001, 20801)),
|
||||
("card_consumable".to_string(), id(100000002, 5003012)),
|
||||
("card_staff".to_string(), id(100000003, 3000083)),
|
||||
]),
|
||||
kinds: HashMap::from([
|
||||
("card_consumable".to_string(), ContentKind::Consumable),
|
||||
("card_staff".to_string(), ContentKind::Staff),
|
||||
]),
|
||||
};
|
||||
let items = vec![
|
||||
item(
|
||||
"oc1",
|
||||
"card_player",
|
||||
86,
|
||||
"ST",
|
||||
"Argentina",
|
||||
"Premier League",
|
||||
"Chelsea",
|
||||
),
|
||||
item("oc2", "card_consumable", 0, "", "", "", ""),
|
||||
item("oc3", "card_staff", 0, "", "", "", ""),
|
||||
];
|
||||
let (body, stats) = shape_club_response(&items, &ent, &ident);
|
||||
assert_eq!(stats.emitted, 1, "only the player is emitted");
|
||||
assert_eq!(stats.excluded_non_player, 2, "consumable + staff excluded");
|
||||
assert_eq!(stats.dropped_no_asset, 0);
|
||||
let arr = body["itemData"].as_array().unwrap();
|
||||
assert_eq!(arr.len(), 1);
|
||||
assert_eq!(arr[0]["id"], 100000001, "the player survives");
|
||||
assert_eq!(arr[0]["itemType"], "player");
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,430 @@
|
||||
//! FIFA17 MY CLUB stat set (`GET …/club/stats/{year,consumables}`), computed
|
||||
//! from OpenFUT Core's authoritative owned inventory.
|
||||
//!
|
||||
//! Faithful port of the Python oracle's `fut_club_stats.py` (`global_counts` +
|
||||
//! `context_rows` + `stats_body`), which is itself censused from CardsDLL
|
||||
//! (`FUN_18012fd40` atom table). The body is `{"stat":[{contextId,contextValue,
|
||||
//! type,typeValue}, …]}`:
|
||||
//! * a GLOBAL bucket (contextId 1, contextValue 0) with player tier counts,
|
||||
//! staff-by-family, consumables-by-family, and honest zeros for club items;
|
||||
//! * per-NATION buckets (contextId 3, contextValue = nation id) with the tier
|
||||
//! counts the MY CLUB summary panel sums into PLAYERS_EMPLOYED.
|
||||
//!
|
||||
//! Unlike the oracle (which counts its own stale profile + a synthetic consumable
|
||||
//! shelf), this counts Core — so staff and consumable families reflect the real
|
||||
//! imported content. Unrecognized atoms are inert in the client, so this is a
|
||||
//! low-risk cosmetic surface; the tier/staff/consumable atoms are the ones the
|
||||
//! screen reads and they are Core-accurate here.
|
||||
|
||||
use std::collections::BTreeMap;
|
||||
|
||||
use serde_json::{json, Value};
|
||||
|
||||
use crate::fut::content_taxonomy::{consumable_family, ContentKind};
|
||||
|
||||
/// One owned item, already classified from the catalog + entity tables by the
|
||||
/// host. `subtype`/`rare` come from the FIFA catalog; `nation_id`/`league_id`/
|
||||
/// `team_id` from the reverse entity resolver (None = unresolved, bucket skipped).
|
||||
#[derive(Debug, Clone)]
|
||||
pub struct ClubStatInput {
|
||||
pub kind: ContentKind,
|
||||
pub subtype: i64,
|
||||
pub rating: i64,
|
||||
pub rare: bool,
|
||||
pub nation_id: Option<i64>,
|
||||
pub league_id: Option<i64>,
|
||||
pub team_id: Option<i64>,
|
||||
}
|
||||
|
||||
/// Which entity the per-context (`contextId 3`) buckets are keyed by — the FIFA
|
||||
/// `MY CLUB` sub-screen selector (`fut_club_stats.py::context_rows`):
|
||||
/// * `Nation` — the default screen (year/consumables/club/newcards): nation buckets.
|
||||
/// * `League` — URL `club/stats/country/<id>`: league (leagueId) buckets, tier stats.
|
||||
/// * `Team` — URL `club/stats/league/<id>`: team (teamid) buckets, players/kits/badge.
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub enum ContextField {
|
||||
Nation,
|
||||
League,
|
||||
Team,
|
||||
}
|
||||
|
||||
// Stat ids (CardsDLL atom table, fut_club_stats.py VOCAB).
|
||||
const S_PLAYERS: i64 = 0x01;
|
||||
const S_BRONZE: i64 = 0x02;
|
||||
const S_SILVER: i64 = 0x03;
|
||||
const S_GOLD: i64 = 0x04;
|
||||
const S_RARE: i64 = 0x05;
|
||||
const S_STAFF: i64 = 0x0A;
|
||||
const S_CONSUMABLES: i64 = 0x3C;
|
||||
const S_KITS: i64 = 0x28;
|
||||
const S_BADGES: i64 = 0x2D;
|
||||
|
||||
/// cardsubtypeid (staff family) -> stat id (STAFF_SUBTYPE_STAT).
|
||||
fn staff_stat(subtype: i64) -> Option<i64> {
|
||||
match subtype {
|
||||
4 => Some(0x0B), // manager
|
||||
5 => Some(0x0C), // head coach
|
||||
6 => Some(0x0D), // GK coach
|
||||
7 => Some(0x0E), // physio
|
||||
8 => Some(0x0F), // fitness coach
|
||||
_ => None,
|
||||
}
|
||||
}
|
||||
|
||||
/// consumable family `kind` -> stat id (CONSUMABLE_KIND_STAT).
|
||||
fn consumable_stat(kind: &str) -> Option<i64> {
|
||||
Some(match kind {
|
||||
"player_contract" => 0x42,
|
||||
"manager_contract" => 0x47,
|
||||
"healing" => 0x41,
|
||||
"player_fitness" => 0x44,
|
||||
"squad_fitness" => 0x4A,
|
||||
"gk_training" => 0x46,
|
||||
"player_training" => 0x43,
|
||||
"position_mod" => 0x45,
|
||||
"player_playstyle" => 0x4B,
|
||||
"gk_playstyle" => 0x4C,
|
||||
"manager_league" => 0x4D,
|
||||
"manager_formation_mod" | "formation_mod" => 0x48,
|
||||
_ => return None,
|
||||
})
|
||||
}
|
||||
|
||||
/// The JSON `type` atom name for a stat id (VOCAB). Only the ids this module
|
||||
/// emits are mapped; an unmapped id would panic (guards a transcription slip).
|
||||
fn vocab(stat_id: i64) -> &'static str {
|
||||
match stat_id {
|
||||
0x01 => "players",
|
||||
0x02 => "playersBronze",
|
||||
0x03 => "playersSilver",
|
||||
0x04 => "playersGold",
|
||||
0x05 => "rarePlayers",
|
||||
0x0A => "staff",
|
||||
0x0B => "staffManager",
|
||||
0x0C => "staffHeadCoach",
|
||||
0x0D => "staffGKCoach",
|
||||
0x0E => "staffPhysio",
|
||||
0x0F => "staffFitnessCoach",
|
||||
0x14 => "stadia",
|
||||
0x1E => "balls",
|
||||
0x28 => "kits",
|
||||
0x29 => "kitsHome",
|
||||
0x2A => "kitsAway",
|
||||
0x2D => "badges",
|
||||
0x2E => "badgeDBid",
|
||||
0x2F => "leagueLogos",
|
||||
0x32 => "trophies",
|
||||
0x33 => "trophiesOffline",
|
||||
0x34 => "trophiesOnline",
|
||||
0x35 => "trophiesFeaturedOffline",
|
||||
0x36 => "trophiesFeaturedOnline",
|
||||
0x37 => "trophiesSeasonOffline",
|
||||
0x38 => "trophiesSeasonOnline",
|
||||
0x3C => "consumables",
|
||||
0x41 => "consumablesHealing",
|
||||
0x42 => "consumablesContractPlayer",
|
||||
0x43 => "consumablesTrainingPlayer",
|
||||
0x44 => "consumablesFitnessPlayer",
|
||||
0x45 => "consumablesPosition",
|
||||
0x46 => "consumablesTrainingGk",
|
||||
0x47 => "consumablesContractManager",
|
||||
0x48 => "consumablesFormationManager",
|
||||
0x49 => "consumablesTrainingManager",
|
||||
0x4A => "consumablesFitnessTeam",
|
||||
0x4B => "consumablesTrainingPlayerPlayStyle",
|
||||
0x4C => "consumablesTrainingGkPlayStyle",
|
||||
0x4D => "consumablesTrainingManagerLeagueModifier",
|
||||
other => panic!("club_stats: unmapped stat id {other:#x}"),
|
||||
}
|
||||
}
|
||||
|
||||
fn row(context_id: i64, context_value: i64, stat_id: i64, value: i64) -> Value {
|
||||
json!({
|
||||
"contextId": context_id,
|
||||
"contextValue": context_value,
|
||||
"type": vocab(stat_id),
|
||||
"typeValue": value,
|
||||
})
|
||||
}
|
||||
|
||||
fn is_player(i: &ClubStatInput) -> bool {
|
||||
matches!(i.kind, ContentKind::Player)
|
||||
}
|
||||
|
||||
/// Build the full `{"stat":[…]}` body for a club/stats screen — the global bucket
|
||||
/// (identical for every mode) plus per-context buckets keyed by `ctx`
|
||||
/// (nation / league / team), mirroring `fut_club_stats.py::stats_body`.
|
||||
pub fn club_stats_body(items: &[ClubStatInput], ctx: ContextField) -> Value {
|
||||
// ---- global bucket (contextId 1, contextValue 0), sorted by stat id ----
|
||||
let mut g: BTreeMap<i64, i64> = BTreeMap::new();
|
||||
let players: Vec<&ClubStatInput> = items.iter().filter(|i| is_player(i)).collect();
|
||||
g.insert(S_PLAYERS, players.len() as i64);
|
||||
g.insert(
|
||||
S_GOLD,
|
||||
players.iter().filter(|i| i.rating >= 75).count() as i64,
|
||||
);
|
||||
g.insert(
|
||||
S_SILVER,
|
||||
players
|
||||
.iter()
|
||||
.filter(|i| (65..75).contains(&i.rating))
|
||||
.count() as i64,
|
||||
);
|
||||
g.insert(
|
||||
S_BRONZE,
|
||||
players
|
||||
.iter()
|
||||
.filter(|i| i.rating > 0 && i.rating < 65)
|
||||
.count() as i64,
|
||||
);
|
||||
g.insert(S_RARE, players.iter().filter(|i| i.rare).count() as i64);
|
||||
|
||||
// staff per family + total
|
||||
for sid in [0x0B, 0x0C, 0x0D, 0x0E, 0x0F] {
|
||||
g.insert(sid, 0);
|
||||
}
|
||||
let mut staff_total = 0i64;
|
||||
for it in items
|
||||
.iter()
|
||||
.filter(|i| matches!(i.kind, ContentKind::Staff))
|
||||
{
|
||||
if let Some(sid) = staff_stat(it.subtype) {
|
||||
*g.get_mut(&sid).unwrap() += 1;
|
||||
staff_total += 1;
|
||||
}
|
||||
}
|
||||
g.insert(S_STAFF, staff_total);
|
||||
|
||||
// consumables per family + total
|
||||
for sid in [
|
||||
0x41, 0x42, 0x43, 0x44, 0x45, 0x46, 0x47, 0x48, 0x49, 0x4A, 0x4B, 0x4C, 0x4D,
|
||||
] {
|
||||
g.insert(sid, 0);
|
||||
}
|
||||
let mut cons_total = 0i64;
|
||||
for it in items
|
||||
.iter()
|
||||
.filter(|i| matches!(i.kind, ContentKind::Consumable))
|
||||
{
|
||||
cons_total += 1;
|
||||
if let Some((kind, _label)) = consumable_family(it.subtype) {
|
||||
if let Some(sid) = consumable_stat(kind) {
|
||||
*g.entry(sid).or_insert(0) += 1;
|
||||
}
|
||||
}
|
||||
}
|
||||
g.insert(S_CONSUMABLES, cons_total);
|
||||
|
||||
// club items: honest zeros (Core holds none; each is read by some panel).
|
||||
for sid in [
|
||||
0x14, 0x1E, 0x28, 0x29, 0x2A, 0x2D, 0x2E, 0x2F, 0x32, 0x33, 0x34, 0x35, 0x36, 0x37, 0x38,
|
||||
] {
|
||||
g.entry(sid).or_insert(0);
|
||||
}
|
||||
|
||||
let mut stat: Vec<Value> = g.iter().map(|(sid, v)| row(1, 0, *sid, *v)).collect();
|
||||
|
||||
// ---- per-context buckets (contextId 3, contextValue = entity id) ----
|
||||
// Nation/League read the tier set (gold/silver/bronze/rare/kits/badges);
|
||||
// Team (the league screen) reads players/kits/badgeDBid. Mirrors context_rows.
|
||||
let mut by_ctx: BTreeMap<i64, Vec<&ClubStatInput>> = BTreeMap::new();
|
||||
for p in &players {
|
||||
let id = match ctx {
|
||||
ContextField::Nation => p.nation_id,
|
||||
ContextField::League => p.league_id,
|
||||
ContextField::Team => p.team_id,
|
||||
};
|
||||
if let Some(id) = id {
|
||||
by_ctx.entry(id).or_default().push(p);
|
||||
}
|
||||
}
|
||||
for (cid, sel) in &by_ctx {
|
||||
if ctx == ContextField::Team {
|
||||
stat.push(row(3, *cid, S_PLAYERS, sel.len() as i64));
|
||||
stat.push(row(3, *cid, S_KITS, 0));
|
||||
stat.push(row(3, *cid, 0x2E, 0)); // badgeDBid
|
||||
} else {
|
||||
let gold = sel.iter().filter(|i| i.rating >= 75).count() as i64;
|
||||
let silver = sel.iter().filter(|i| (65..75).contains(&i.rating)).count() as i64;
|
||||
let bronze = sel.iter().filter(|i| i.rating > 0 && i.rating < 65).count() as i64;
|
||||
let rare = sel.iter().filter(|i| i.rare).count() as i64;
|
||||
stat.push(row(3, *cid, S_GOLD, gold));
|
||||
stat.push(row(3, *cid, S_SILVER, silver));
|
||||
stat.push(row(3, *cid, S_BRONZE, bronze));
|
||||
stat.push(row(3, *cid, S_RARE, rare));
|
||||
stat.push(row(3, *cid, S_KITS, 0));
|
||||
stat.push(row(3, *cid, S_BADGES, 0));
|
||||
}
|
||||
}
|
||||
|
||||
json!({ "stat": stat })
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
fn player(rating: i64, rare: bool, nation: Option<i64>) -> ClubStatInput {
|
||||
ClubStatInput {
|
||||
kind: ContentKind::Player,
|
||||
subtype: 0,
|
||||
rating,
|
||||
rare,
|
||||
nation_id: nation,
|
||||
league_id: None,
|
||||
team_id: None,
|
||||
}
|
||||
}
|
||||
fn staff(subtype: i64) -> ClubStatInput {
|
||||
ClubStatInput {
|
||||
kind: ContentKind::Staff,
|
||||
subtype,
|
||||
rating: 0,
|
||||
rare: false,
|
||||
nation_id: None,
|
||||
league_id: None,
|
||||
team_id: None,
|
||||
}
|
||||
}
|
||||
fn consumable(subtype: i64) -> ClubStatInput {
|
||||
ClubStatInput {
|
||||
kind: ContentKind::Consumable,
|
||||
subtype,
|
||||
rating: 0,
|
||||
rare: false,
|
||||
nation_id: None,
|
||||
league_id: None,
|
||||
team_id: None,
|
||||
}
|
||||
}
|
||||
|
||||
fn global(body: &Value) -> std::collections::HashMap<String, i64> {
|
||||
body["stat"]
|
||||
.as_array()
|
||||
.unwrap()
|
||||
.iter()
|
||||
.filter(|r| r["contextId"] == 1)
|
||||
.map(|r| {
|
||||
(
|
||||
r["type"].as_str().unwrap().to_string(),
|
||||
r["typeValue"].as_i64().unwrap(),
|
||||
)
|
||||
})
|
||||
.collect()
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn tiers_and_rare_counted() {
|
||||
let items = vec![
|
||||
player(90, true, Some(52)),
|
||||
player(70, true, Some(52)),
|
||||
player(60, false, Some(21)),
|
||||
];
|
||||
let g = global(&club_stats_body(&items, ContextField::Nation));
|
||||
assert_eq!(g["players"], 3);
|
||||
assert_eq!(g["playersGold"], 1);
|
||||
assert_eq!(g["playersSilver"], 1);
|
||||
assert_eq!(g["playersBronze"], 1);
|
||||
assert_eq!(g["rarePlayers"], 2);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn staff_by_family() {
|
||||
let items = vec![staff(6), staff(8), staff(8)]; // 1 gk coach, 2 fitness
|
||||
let g = global(&club_stats_body(&items, ContextField::Nation));
|
||||
assert_eq!(g["staffGKCoach"], 1);
|
||||
assert_eq!(g["staffFitnessCoach"], 2);
|
||||
assert_eq!(g["staff"], 3);
|
||||
assert_eq!(g["staffManager"], 0);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn consumables_by_family() {
|
||||
// 54 gk_training, 201 player_contract, 217 healing, 258 player_playstyle
|
||||
let items = vec![
|
||||
consumable(54),
|
||||
consumable(201),
|
||||
consumable(217),
|
||||
consumable(258),
|
||||
];
|
||||
let g = global(&club_stats_body(&items, ContextField::Nation));
|
||||
assert_eq!(g["consumables"], 4);
|
||||
assert_eq!(g["consumablesTrainingGk"], 1);
|
||||
assert_eq!(g["consumablesContractPlayer"], 1);
|
||||
assert_eq!(g["consumablesHealing"], 1);
|
||||
assert_eq!(g["consumablesTrainingPlayerPlayStyle"], 1);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn nation_buckets_emitted_and_players_excludes_nonplayers() {
|
||||
let items = vec![
|
||||
player(90, true, Some(52)),
|
||||
player(80, false, Some(52)),
|
||||
staff(8),
|
||||
];
|
||||
let body = club_stats_body(&items, ContextField::Nation);
|
||||
let g = global(&body);
|
||||
assert_eq!(g["players"], 2, "staff not counted as player");
|
||||
let buckets: Vec<&Value> = body["stat"]
|
||||
.as_array()
|
||||
.unwrap()
|
||||
.iter()
|
||||
.filter(|r| r["contextId"] == 3 && r["contextValue"] == 52)
|
||||
.collect();
|
||||
// gold, silver, bronze, rare, kits, badges
|
||||
assert_eq!(buckets.len(), 6);
|
||||
let gold = buckets.iter().find(|r| r["type"] == "playersGold").unwrap();
|
||||
assert_eq!(gold["typeValue"], 2);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn honest_zero_club_items_present() {
|
||||
let g = global(&club_stats_body(&[player(90, false, None)], ContextField::Nation));
|
||||
for atom in [
|
||||
"stadia",
|
||||
"balls",
|
||||
"kits",
|
||||
"badges",
|
||||
"trophies",
|
||||
"leagueLogos",
|
||||
] {
|
||||
assert_eq!(g[atom], 0, "{atom} present as honest zero");
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn league_and_team_context_modes() {
|
||||
let mut a = player(90, true, Some(52));
|
||||
a.league_id = Some(13);
|
||||
a.team_id = Some(240);
|
||||
let mut b = player(60, false, Some(52));
|
||||
b.league_id = Some(13);
|
||||
b.team_id = Some(9);
|
||||
let items = vec![a, b];
|
||||
|
||||
// country screen -> league (leagueId) buckets, tier set (6 rows).
|
||||
let body = club_stats_body(&items, ContextField::League);
|
||||
let league_rows: Vec<&Value> = body["stat"]
|
||||
.as_array()
|
||||
.unwrap()
|
||||
.iter()
|
||||
.filter(|r| r["contextId"] == 3 && r["contextValue"] == 13)
|
||||
.collect();
|
||||
assert_eq!(league_rows.len(), 6);
|
||||
let gold = league_rows.iter().find(|r| r["type"] == "playersGold").unwrap();
|
||||
assert_eq!(gold["typeValue"], 1);
|
||||
|
||||
// league screen -> team (teamid) buckets: players/kits/badgeDBid (3 rows).
|
||||
let body = club_stats_body(&items, ContextField::Team);
|
||||
let team_rows: Vec<&Value> = body["stat"]
|
||||
.as_array()
|
||||
.unwrap()
|
||||
.iter()
|
||||
.filter(|r| r["contextId"] == 3 && r["contextValue"] == 240)
|
||||
.collect();
|
||||
assert_eq!(team_rows.len(), 3);
|
||||
let players = team_rows.iter().find(|r| r["type"] == "players").unwrap();
|
||||
assert_eq!(players["typeValue"], 1);
|
||||
assert!(team_rows.iter().any(|r| r["type"] == "badgeDBid"));
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,177 @@
|
||||
//! FIFA 17 **non-player content taxonomy** — the evidence-based map from a card
|
||||
//! `cardsubtypeid` to its functional family (consumables) or role (staff).
|
||||
//!
|
||||
//! This is the ONLY place the FIFA-specific `cardsubtypeid` vocabulary lives; it
|
||||
//! keeps that game concept out of generic Core, exactly as the player-side
|
||||
//! catalog keeps `resourceId`/`rareflag` out of Core. Nothing here is guessed:
|
||||
//!
|
||||
//! * Consumable families and their contiguous `cardsubtypeid` ranges are taken
|
||||
//! verbatim from `fifa17-recon/tools/fut_consumables.py`
|
||||
//! (`BY_SUBTYPE`/`CORE_KINDS`, Ghidra-derived from `FUN_18013f4d0` /
|
||||
//! `FUN_1801bfac0`) and `docs/CARD_TAXONOMY.md` (verified against the `.105`
|
||||
//! `fcc_*.json` tables).
|
||||
//! * Staff roles are the `FUN_1800d8330` family selector: 4=manager, 5=headcoach,
|
||||
//! 6=gkcoach, 7=physio, 8=fitnesscoach.
|
||||
//!
|
||||
//! Display **labels are functional, never marketing** (e.g. "Player Chemistry
|
||||
//! Style", not a promo name). A `cardsubtypeid` outside every documented range
|
||||
//! resolves to `None` — the caller DEFERS it (mirroring the player NoName gate),
|
||||
//! never fabricating a family.
|
||||
|
||||
/// The disjoint content classes a FIFA 17 owned card can belong to. Player is
|
||||
/// the default so a catalog authored before this taxonomy existed (no `kind`
|
||||
/// field) still classifies every entry as a player, unchanged.
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq, Default)]
|
||||
pub enum ContentKind {
|
||||
#[default]
|
||||
Player,
|
||||
Consumable,
|
||||
Staff,
|
||||
}
|
||||
|
||||
impl ContentKind {
|
||||
/// The stable wire/catalog token for this kind.
|
||||
pub fn as_str(&self) -> &'static str {
|
||||
match self {
|
||||
ContentKind::Player => "player",
|
||||
ContentKind::Consumable => "consumable",
|
||||
ContentKind::Staff => "staff",
|
||||
}
|
||||
}
|
||||
|
||||
/// Parse a catalog `kind` token. Unknown or "player" (or an absent field that
|
||||
/// deserializes to the default) is `Player` — backward compatible.
|
||||
// Intentionally infallible (every input maps to a kind, unknown → Player), so
|
||||
// it is NOT `std::str::FromStr` (which is fallible); the name mirrors the
|
||||
// catalog token vocabulary.
|
||||
#[allow(clippy::should_implement_trait)]
|
||||
pub fn from_str(s: &str) -> ContentKind {
|
||||
match s {
|
||||
"consumable" => ContentKind::Consumable,
|
||||
"staff" => ContentKind::Staff,
|
||||
_ => ContentKind::Player,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// The functional family + honest display label for a consumable `cardsubtypeid`,
|
||||
/// or `None` if the subtype is outside every documented range (→ DEFER).
|
||||
///
|
||||
/// Returns `(family, label)`, both `'static`. `family` is the neutral machine
|
||||
/// name stored as the CardDefinition family; `label` is the functional
|
||||
/// human-readable name.
|
||||
pub fn consumable_family(subtype: i64) -> Option<(&'static str, &'static str)> {
|
||||
let pair = match subtype {
|
||||
51..=57 => ("gk_training", "GK Training"),
|
||||
61..=67 => ("player_training", "Player Training"),
|
||||
71..=86 => ("manager_formation_mod", "Manager Formation"),
|
||||
91..=110 => ("position_mod", "Position Modifier"),
|
||||
121..=136 => ("formation_mod", "Formation Modifier"),
|
||||
201 => ("player_contract", "Player Contract"),
|
||||
202 => ("manager_contract", "Manager Contract"),
|
||||
211..=218 => ("healing", "Healing"),
|
||||
219 => ("player_fitness", "Player Fitness"),
|
||||
220 => ("squad_fitness", "Squad Fitness"),
|
||||
250..=268 => ("player_playstyle", "Player Chemistry Style"),
|
||||
269..=273 => ("gk_playstyle", "GK Chemistry Style"),
|
||||
300..=341 => ("manager_league", "Manager League Modifier"),
|
||||
_ => return None,
|
||||
};
|
||||
Some(pair)
|
||||
}
|
||||
|
||||
/// The staff role + honest display label for a staff `cardsubtypeid` (4..=8), or
|
||||
/// `None` for any other subtype (→ DEFER). Grounded in the `FUN_1800d8330`
|
||||
/// family selector.
|
||||
pub fn staff_role(subtype: i64) -> Option<(&'static str, &'static str)> {
|
||||
let pair = match subtype {
|
||||
4 => ("manager", "Manager"),
|
||||
5 => ("headcoach", "Head Coach"),
|
||||
6 => ("gkcoach", "GK Coach"),
|
||||
7 => ("physio", "Physio"),
|
||||
8 => ("fitnesscoach", "Fitness Coach"),
|
||||
_ => return None,
|
||||
};
|
||||
Some(pair)
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn content_kind_round_trips_and_defaults_to_player() {
|
||||
assert_eq!(ContentKind::default(), ContentKind::Player);
|
||||
for k in [
|
||||
ContentKind::Player,
|
||||
ContentKind::Consumable,
|
||||
ContentKind::Staff,
|
||||
] {
|
||||
assert_eq!(ContentKind::from_str(k.as_str()), k);
|
||||
}
|
||||
// Unknown / absent tokens fall back to Player (backward compatible).
|
||||
assert_eq!(ContentKind::from_str(""), ContentKind::Player);
|
||||
assert_eq!(ContentKind::from_str("nonsense"), ContentKind::Player);
|
||||
assert_eq!(ContentKind::from_str("player"), ContentKind::Player);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn consumable_family_range_boundaries() {
|
||||
// Each contiguous range: lower boundary, upper boundary, family + label.
|
||||
let cases: &[(i64, i64, &str, &str)] = &[
|
||||
(51, 57, "gk_training", "GK Training"),
|
||||
(61, 67, "player_training", "Player Training"),
|
||||
(71, 86, "manager_formation_mod", "Manager Formation"),
|
||||
(91, 110, "position_mod", "Position Modifier"),
|
||||
(121, 136, "formation_mod", "Formation Modifier"),
|
||||
(211, 218, "healing", "Healing"),
|
||||
(250, 268, "player_playstyle", "Player Chemistry Style"),
|
||||
(269, 273, "gk_playstyle", "GK Chemistry Style"),
|
||||
(300, 341, "manager_league", "Manager League Modifier"),
|
||||
];
|
||||
for &(lo, hi, family, label) in cases {
|
||||
assert_eq!(consumable_family(lo), Some((family, label)), "lo {lo}");
|
||||
assert_eq!(consumable_family(hi), Some((family, label)), "hi {hi}");
|
||||
}
|
||||
// Singleton subtypes.
|
||||
assert_eq!(
|
||||
consumable_family(201),
|
||||
Some(("player_contract", "Player Contract"))
|
||||
);
|
||||
assert_eq!(
|
||||
consumable_family(202),
|
||||
Some(("manager_contract", "Manager Contract"))
|
||||
);
|
||||
assert_eq!(
|
||||
consumable_family(219),
|
||||
Some(("player_fitness", "Player Fitness"))
|
||||
);
|
||||
assert_eq!(
|
||||
consumable_family(220),
|
||||
Some(("squad_fitness", "Squad Fitness"))
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn consumable_family_gaps_and_out_of_range_are_none() {
|
||||
// Just outside range edges, and in documented gaps between ranges.
|
||||
for s in [
|
||||
0, 50, 58, 60, 68, 70, 87, 90, 111, 120, 137, 200, 203, 210, 221, 249, 274, 299, 342,
|
||||
999,
|
||||
] {
|
||||
assert_eq!(consumable_family(s), None, "subtype {s} must be unknown");
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn staff_role_each_role_and_unknown_is_none() {
|
||||
assert_eq!(staff_role(4), Some(("manager", "Manager")));
|
||||
assert_eq!(staff_role(5), Some(("headcoach", "Head Coach")));
|
||||
assert_eq!(staff_role(6), Some(("gkcoach", "GK Coach")));
|
||||
assert_eq!(staff_role(7), Some(("physio", "Physio")));
|
||||
assert_eq!(staff_role(8), Some(("fitnesscoach", "Fitness Coach")));
|
||||
for s in [0, 1, 2, 3, 9, 10, 201, 300] {
|
||||
assert_eq!(staff_role(s), None, "staff subtype {s} must be unknown");
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,442 @@
|
||||
//! FIFA 17 authoritative economy engine — coins + unopened-pack entitlements +
|
||||
//! owned inventory + stable item ids — with all-or-nothing transactional mutations.
|
||||
//!
|
||||
//! A faithful port of the Python oracle's `fut_store.Store` mutation primitives
|
||||
//! (`spend`/`grant_coins`/`quick_sell`/`record_match`/`grant_unopened_pack`/
|
||||
//! `consume_unopened_pack`/`open_pack`/`add_items`) — the single-writer engine the
|
||||
//! eventual economy cutover needs.
|
||||
//!
|
||||
//! ## Status / why not wired (R3)
|
||||
//!
|
||||
//! This engine is deliberately **not wired** into the live host. The live FIFA 17
|
||||
//! coin balance is one indivisible writer set — Store BUY (`spend`), pack-open,
|
||||
//! quick-sell, match rewards (`record_match`) AND the transfer-market buy-now
|
||||
//! (`spend`) all mutate the same `coins` + inventory in Python's `fut_profile.json`.
|
||||
//! No single route can become Rust-authoritative without migrating the whole
|
||||
//! cluster at once. The intended generic home (OpenFUT Core) is a preserved-dirty,
|
||||
//! frozen submodule, so the generic currency/inventory/transaction primitives can't
|
||||
//! land there yet. This engine + importer is therefore the coherent prerequisite:
|
||||
//! wiring it (and migrating every coin/inventory writer in one cut) is the R1 task.
|
||||
//!
|
||||
//! Generic concepts (balance/inventory/transaction) belong in Core once unfrozen;
|
||||
//! they are kept in the adapter meanwhile without distorting Core.
|
||||
//!
|
||||
//! ## Economy-parameter provenance
|
||||
//!
|
||||
//! Prices/odds/quick-sell values are current OpenFUT **PLACEHOLDER** economy, not
|
||||
//! EA-authentic. The mutation *invariants* (atomic debit, consume-once, no partial
|
||||
//! state, sentinel non-grantable) are the load-bearing contract this engine enforces.
|
||||
|
||||
use serde_json::{json, Value};
|
||||
|
||||
use crate::fut::store_catalog::pack_by_id;
|
||||
use crate::fut::store_session::SENTINEL_PACK_ID;
|
||||
|
||||
/// A transactional failure. On any `Err`, the engine is left UNCHANGED (no partial
|
||||
/// mutation) — the caller may retry or surface a wire error.
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub enum EconomyError {
|
||||
/// Debit rejected: balance would go negative.
|
||||
InsufficientFunds { balance: i64, needed: i64 },
|
||||
/// Pack id is not in the catalogue (includes the 65534 sentinel).
|
||||
UnknownPack(u64),
|
||||
/// No owned instance of this pack to consume.
|
||||
NotOwned(u64),
|
||||
/// The 65534 sentinel can never be bought/granted/opened.
|
||||
SentinelRejected,
|
||||
}
|
||||
|
||||
/// The authoritative per-profile economy state. Mirrors the load-bearing
|
||||
/// `fut_profile.json` fields. Wrap in a profile-scoped `Mutex`/DB transaction at the
|
||||
/// host boundary (as the eventual Core repository will); the methods here are the
|
||||
/// atomic units.
|
||||
#[derive(Debug, Clone, PartialEq)]
|
||||
pub struct ProfileEconomy {
|
||||
coins: i64,
|
||||
unopened_pack_ids: Vec<u64>,
|
||||
items: Vec<Value>,
|
||||
next_item_id: i64,
|
||||
}
|
||||
|
||||
impl ProfileEconomy {
|
||||
/// A fresh, empty economy (coins 0, no packs/items, ids from 1).
|
||||
pub fn new() -> Self {
|
||||
ProfileEconomy {
|
||||
coins: 0,
|
||||
unopened_pack_ids: Vec::new(),
|
||||
items: Vec::new(),
|
||||
next_item_id: 1,
|
||||
}
|
||||
}
|
||||
|
||||
/// Import from a `fut_profile.json` object (the current authoritative store).
|
||||
/// Deterministic and idempotent on a fixture: reads coins, `unopenedPackIds`,
|
||||
/// `items`, `nextItemId`; missing fields take safe defaults. Never mutates the
|
||||
/// source. Production migration is NOT executed here.
|
||||
pub fn from_fut_profile(profile: &Value) -> Self {
|
||||
let coins = profile.get("coins").and_then(Value::as_i64).unwrap_or(0);
|
||||
let unopened_pack_ids = profile
|
||||
.get("unopenedPackIds")
|
||||
.and_then(Value::as_array)
|
||||
.map(|a| a.iter().filter_map(Value::as_u64).collect())
|
||||
.unwrap_or_default();
|
||||
let items = profile
|
||||
.get("items")
|
||||
.and_then(Value::as_array)
|
||||
.cloned()
|
||||
.unwrap_or_default();
|
||||
// Continue item-id allocation past the highest existing id so re-import can
|
||||
// never mint a duplicate (Python persists nextItemId; we also floor by it).
|
||||
let max_item_id = items
|
||||
.iter()
|
||||
.filter_map(|it| it.get("id").and_then(Value::as_i64))
|
||||
.max()
|
||||
.unwrap_or(0);
|
||||
let next_item_id = profile
|
||||
.get("nextItemId")
|
||||
.and_then(Value::as_i64)
|
||||
.unwrap_or(1)
|
||||
.max(max_item_id + 1);
|
||||
ProfileEconomy {
|
||||
coins,
|
||||
unopened_pack_ids,
|
||||
items,
|
||||
next_item_id,
|
||||
}
|
||||
}
|
||||
|
||||
/// Write this economy back onto a `fut_profile.json` object (round-trip / export).
|
||||
/// Only the economy fields are touched; every other key is preserved.
|
||||
pub fn apply_to_fut_profile(&self, profile: &mut Value) {
|
||||
let obj = profile
|
||||
.as_object_mut()
|
||||
.expect("fut_profile is a JSON object");
|
||||
obj.insert("coins".into(), json!(self.coins));
|
||||
obj.insert("unopenedPackIds".into(), json!(self.unopened_pack_ids));
|
||||
obj.insert("items".into(), Value::Array(self.items.clone()));
|
||||
obj.insert("nextItemId".into(), json!(self.next_item_id));
|
||||
}
|
||||
|
||||
// ── reads ────────────────────────────────────────────────────────────────
|
||||
pub fn coins(&self) -> i64 {
|
||||
self.coins
|
||||
}
|
||||
pub fn unopened_pack_ids(&self) -> &[u64] {
|
||||
&self.unopened_pack_ids
|
||||
}
|
||||
pub fn next_item_id(&self) -> i64 {
|
||||
self.next_item_id
|
||||
}
|
||||
pub fn item_ids(&self) -> Vec<i64> {
|
||||
self.items
|
||||
.iter()
|
||||
.filter_map(|it| it.get("id").and_then(Value::as_i64))
|
||||
.collect()
|
||||
}
|
||||
|
||||
// ── generic primitives (atomic building blocks) ───────────────────────────
|
||||
|
||||
/// Credit coins (reward/quick-sell proceeds). Non-negative by type.
|
||||
pub fn credit(&mut self, amount: u64) {
|
||||
self.coins += amount as i64;
|
||||
}
|
||||
|
||||
/// Debit coins. Fail-closed: insufficient balance leaves coins UNCHANGED.
|
||||
pub fn debit(&mut self, amount: u64) -> Result<(), EconomyError> {
|
||||
let needed = amount as i64;
|
||||
if self.coins < needed {
|
||||
return Err(EconomyError::InsufficientFunds {
|
||||
balance: self.coins,
|
||||
needed,
|
||||
});
|
||||
}
|
||||
self.coins -= needed;
|
||||
Ok(())
|
||||
}
|
||||
|
||||
/// Grant one owned instance of a catalogue pack (reward/purchase entitlement).
|
||||
/// Rejects the 65534 sentinel and any non-catalogue id (mirrors
|
||||
/// `grant_unopened_pack`, which returns False for `pack_by_id() is None`).
|
||||
pub fn grant_pack(&mut self, pack_id: u64) -> Result<(), EconomyError> {
|
||||
if pack_id == SENTINEL_PACK_ID {
|
||||
return Err(EconomyError::SentinelRejected);
|
||||
}
|
||||
if pack_by_id(pack_id).is_none() {
|
||||
return Err(EconomyError::UnknownPack(pack_id));
|
||||
}
|
||||
self.unopened_pack_ids.push(pack_id);
|
||||
Ok(())
|
||||
}
|
||||
|
||||
/// Consume exactly one owned instance of a pack. Fail-closed: not owned ⇒ Err,
|
||||
/// no mutation (consume-once; mirrors `consume_unopened_pack`).
|
||||
pub fn consume_pack(&mut self, pack_id: u64) -> Result<(), EconomyError> {
|
||||
match self.unopened_pack_ids.iter().position(|&p| p == pack_id) {
|
||||
Some(idx) => {
|
||||
self.unopened_pack_ids.remove(idx);
|
||||
Ok(())
|
||||
}
|
||||
None => Err(EconomyError::NotOwned(pack_id)),
|
||||
}
|
||||
}
|
||||
|
||||
/// Allocate the next stable, monotonic, unique item id.
|
||||
pub fn allocate_item_id(&mut self) -> i64 {
|
||||
let id = self.next_item_id;
|
||||
self.next_item_id += 1;
|
||||
id
|
||||
}
|
||||
|
||||
/// Add an owned item, stamping a fresh unique id (overwriting any incoming id),
|
||||
/// and return the assigned id.
|
||||
pub fn add_item(&mut self, mut item: Value) -> i64 {
|
||||
let id = self.allocate_item_id();
|
||||
if let Some(obj) = item.as_object_mut() {
|
||||
obj.insert("id".into(), json!(id));
|
||||
}
|
||||
self.items.push(item);
|
||||
id
|
||||
}
|
||||
|
||||
// ── composed atomic transactions (validate-then-mutate) ────────────────────
|
||||
|
||||
/// Store BUY as an entitlement: validate the pack + funds FIRST, then debit and
|
||||
/// grant the unopened pack — all-or-nothing. Rejects the sentinel. (The Python
|
||||
/// oracle opens on buy; the authoritative model separates buy→entitlement→open,
|
||||
/// which is why `open_pack` exists — a DIFFERENT-BY-DESIGN improvement over the
|
||||
/// reference, preserving the coin/entitlement invariants.)
|
||||
pub fn buy_pack(&mut self, pack_id: u64, price: u64) -> Result<(), EconomyError> {
|
||||
if pack_id == SENTINEL_PACK_ID {
|
||||
return Err(EconomyError::SentinelRejected);
|
||||
}
|
||||
if pack_by_id(pack_id).is_none() {
|
||||
return Err(EconomyError::UnknownPack(pack_id));
|
||||
}
|
||||
if self.coins < price as i64 {
|
||||
return Err(EconomyError::InsufficientFunds {
|
||||
balance: self.coins,
|
||||
needed: price as i64,
|
||||
});
|
||||
}
|
||||
// Both preconditions hold: commit.
|
||||
self.coins -= price as i64;
|
||||
self.unopened_pack_ids.push(pack_id);
|
||||
Ok(())
|
||||
}
|
||||
|
||||
/// Open an owned pack: consume exactly one entitlement FIRST (so a failed/absent
|
||||
/// entitlement grants nothing), then add the generated items with fresh ids.
|
||||
/// Returns the ids granted. Content generation/odds are the caller's concern and
|
||||
/// are current OpenFUT PLACEHOLDER.
|
||||
pub fn open_pack(&mut self, pack_id: u64, items: Vec<Value>) -> Result<Vec<i64>, EconomyError> {
|
||||
self.consume_pack(pack_id)?; // fail-closed: no items on a missing entitlement
|
||||
Ok(items.into_iter().map(|it| self.add_item(it)).collect())
|
||||
}
|
||||
|
||||
/// Quick-sell owned items by id: remove them and credit the caller-computed value
|
||||
/// total (values are FIFA17 policy, placeholder). Only ids actually owned are
|
||||
/// sold/credited (mirrors `quick_sell`). Returns `(sold_count, coins_credited)`.
|
||||
pub fn quick_sell(&mut self, ids: &[i64], value_of: impl Fn(&Value) -> u64) -> (u64, u64) {
|
||||
let want: std::collections::HashSet<i64> = ids.iter().copied().collect();
|
||||
let mut credited = 0u64;
|
||||
let mut sold = 0u64;
|
||||
let mut kept = Vec::with_capacity(self.items.len());
|
||||
for it in std::mem::take(&mut self.items) {
|
||||
let owned_id = it.get("id").and_then(Value::as_i64);
|
||||
if owned_id.is_some_and(|id| want.contains(&id)) {
|
||||
credited += value_of(&it);
|
||||
sold += 1;
|
||||
} else {
|
||||
kept.push(it);
|
||||
}
|
||||
}
|
||||
self.items = kept;
|
||||
if sold > 0 {
|
||||
self.credit(credited);
|
||||
}
|
||||
(sold, credited)
|
||||
}
|
||||
|
||||
/// Transfer-market buy-now: debit the price FIRST, then acquire the item — the
|
||||
/// market shares the SAME authoritative coin balance (that is why it is inside
|
||||
/// this engine's boundary). All-or-nothing.
|
||||
pub fn market_buy_now(&mut self, price: u64, item: Value) -> Result<i64, EconomyError> {
|
||||
self.debit(price)?;
|
||||
Ok(self.add_item(item))
|
||||
}
|
||||
|
||||
/// Match/reward coin credit (`record_match` coin part; SBC/objective grants).
|
||||
pub fn grant_reward(&mut self, coins: u64) {
|
||||
self.credit(coins);
|
||||
}
|
||||
}
|
||||
|
||||
impl Default for ProfileEconomy {
|
||||
fn default() -> Self {
|
||||
Self::new()
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
fn eco(coins: i64, unopened: &[u64]) -> ProfileEconomy {
|
||||
ProfileEconomy {
|
||||
coins,
|
||||
unopened_pack_ids: unopened.to_vec(),
|
||||
items: Vec::new(),
|
||||
next_item_id: 1,
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn debit_insufficient_is_fail_closed() {
|
||||
let mut e = eco(100, &[]);
|
||||
assert_eq!(
|
||||
e.debit(101),
|
||||
Err(EconomyError::InsufficientFunds {
|
||||
balance: 100,
|
||||
needed: 101
|
||||
})
|
||||
);
|
||||
assert_eq!(e.coins(), 100, "no mutation on failure");
|
||||
assert_eq!(e.debit(100), Ok(()));
|
||||
assert_eq!(e.coins(), 0);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn buy_pack_is_atomic() {
|
||||
// Insufficient funds: neither coins nor entitlements change.
|
||||
let mut poor = eco(399, &[]);
|
||||
assert!(matches!(
|
||||
poor.buy_pack(1, 400),
|
||||
Err(EconomyError::InsufficientFunds { .. })
|
||||
));
|
||||
assert_eq!(poor.coins(), 399);
|
||||
assert!(poor.unopened_pack_ids().is_empty());
|
||||
// Enough funds: debit + grant together.
|
||||
let mut ok = eco(1000, &[]);
|
||||
assert_eq!(ok.buy_pack(1, 400), Ok(()));
|
||||
assert_eq!(ok.coins(), 600);
|
||||
assert_eq!(ok.unopened_pack_ids(), &[1]);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn sentinel_can_never_be_bought_or_granted() {
|
||||
let mut e = eco(1_000_000, &[]);
|
||||
assert_eq!(
|
||||
e.buy_pack(SENTINEL_PACK_ID, 0),
|
||||
Err(EconomyError::SentinelRejected)
|
||||
);
|
||||
assert_eq!(
|
||||
e.grant_pack(SENTINEL_PACK_ID),
|
||||
Err(EconomyError::SentinelRejected)
|
||||
);
|
||||
// Never openable either (no entitlement can exist for it).
|
||||
assert_eq!(
|
||||
e.open_pack(SENTINEL_PACK_ID, vec![json!({})]),
|
||||
Err(EconomyError::NotOwned(SENTINEL_PACK_ID))
|
||||
);
|
||||
assert_eq!(e.coins(), 1_000_000, "sentinel ops never mutate economy");
|
||||
assert!(e.item_ids().is_empty());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn unknown_pack_rejected() {
|
||||
let mut e = eco(1_000_000, &[]);
|
||||
assert_eq!(e.buy_pack(999, 0), Err(EconomyError::UnknownPack(999)));
|
||||
assert_eq!(e.grant_pack(999), Err(EconomyError::UnknownPack(999)));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn open_pack_consumes_exactly_once() {
|
||||
let mut e = eco(0, &[70]);
|
||||
let granted = e.open_pack(70, vec![json!({"rating": 84}), json!({"rating": 90})]);
|
||||
assert_eq!(granted, Ok(vec![1, 2]));
|
||||
assert!(e.unopened_pack_ids().is_empty(), "entitlement consumed");
|
||||
assert_eq!(e.item_ids(), vec![1, 2], "unique ids assigned");
|
||||
// Second open of the same (now-absent) entitlement grants nothing.
|
||||
assert_eq!(
|
||||
e.open_pack(70, vec![json!({})]),
|
||||
Err(EconomyError::NotOwned(70))
|
||||
);
|
||||
assert_eq!(e.item_ids(), vec![1, 2], "no items added on failed open");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn quick_sell_removes_owned_and_credits() {
|
||||
let mut e = eco(100, &[]);
|
||||
let a = e.add_item(json!({"rating": 84}));
|
||||
let b = e.add_item(json!({"rating": 90}));
|
||||
// sell only `a`; an unknown id is ignored (not owned).
|
||||
let (sold, credited) = e.quick_sell(&[a, 99999], |_| 300);
|
||||
assert_eq!((sold, credited), (1, 300));
|
||||
assert_eq!(e.coins(), 400);
|
||||
assert_eq!(e.item_ids(), vec![b], "only the sold item removed");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn market_buy_now_is_atomic() {
|
||||
let mut poor = eco(50, &[]);
|
||||
assert!(matches!(
|
||||
poor.market_buy_now(100, json!({"rating": 84})),
|
||||
Err(EconomyError::InsufficientFunds { .. })
|
||||
));
|
||||
assert_eq!(poor.coins(), 50);
|
||||
assert!(poor.item_ids().is_empty(), "no item acquired on failed buy");
|
||||
let mut ok = eco(500, &[]);
|
||||
let id = ok.market_buy_now(100, json!({"rating": 84})).unwrap();
|
||||
assert_eq!(ok.coins(), 400);
|
||||
assert_eq!(ok.item_ids(), vec![id]);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn item_ids_are_unique_and_monotonic() {
|
||||
let mut e = ProfileEconomy::new();
|
||||
let ids: Vec<i64> = (0..5).map(|_| e.allocate_item_id()).collect();
|
||||
assert_eq!(ids, vec![1, 2, 3, 4, 5]);
|
||||
assert_eq!(e.next_item_id(), 6);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn fut_profile_import_export_round_trip() {
|
||||
let mut profile = json!({
|
||||
"personaId": 33068179,
|
||||
"coins": 29876776,
|
||||
"unopenedPackIds": [70],
|
||||
"items": [{"id": 41, "rating": 84}, {"id": 42, "rating": 90}],
|
||||
"nextItemId": 43,
|
||||
"clubName": "OpenFUT"
|
||||
});
|
||||
let e = ProfileEconomy::from_fut_profile(&profile);
|
||||
assert_eq!(e.coins(), 29876776);
|
||||
assert_eq!(e.unopened_pack_ids(), &[70]);
|
||||
assert_eq!(e.next_item_id(), 43, "past the highest existing id");
|
||||
// Export preserves unrelated keys and reflects the economy exactly.
|
||||
e.apply_to_fut_profile(&mut profile);
|
||||
assert_eq!(
|
||||
profile["clubName"],
|
||||
json!("OpenFUT"),
|
||||
"unrelated key preserved"
|
||||
);
|
||||
assert_eq!(profile["coins"], json!(29876776));
|
||||
assert_eq!(profile["nextItemId"], json!(43));
|
||||
// Re-import is stable.
|
||||
let e2 = ProfileEconomy::from_fut_profile(&profile);
|
||||
assert_eq!(e, e2);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn import_floors_next_item_id_past_existing_ids() {
|
||||
// A stale/low nextItemId must never mint a duplicate id.
|
||||
let profile = json!({
|
||||
"coins": 0,
|
||||
"items": [{"id": 500}],
|
||||
"nextItemId": 10
|
||||
});
|
||||
let mut e = ProfileEconomy::from_fut_profile(&profile);
|
||||
assert_eq!(e.next_item_id(), 501);
|
||||
assert_eq!(e.allocate_item_id(), 501);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,186 @@
|
||||
//! FIFA 17 economy POLICY mappers (pure, game-specific).
|
||||
//!
|
||||
//! These translate FIFA 17 wire semantics into the generic amounts the host
|
||||
//! feeds to Core economy authority. They own NO state — Core owns balances and
|
||||
//! inventory; these are the FIFA-specific numbers/derivations. Values are the
|
||||
//! current OpenFUT economy (match rewards are the Python oracle's
|
||||
//! `MATCH_COINS`/`MATCH_PARTICIPATION` at production defaults); pack prices come
|
||||
//! from the Store catalogue.
|
||||
|
||||
use crate::fut::store_catalog::pack_by_id;
|
||||
|
||||
/// Normalized match outcome for reward purposes.
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub enum MatchResult {
|
||||
Win,
|
||||
Draw,
|
||||
Loss,
|
||||
}
|
||||
|
||||
/// Participation award added to every match reward (oracle `MATCH_PARTICIPATION`
|
||||
/// default = 0).
|
||||
pub const MATCH_PARTICIPATION: i64 = 0;
|
||||
|
||||
/// Per-result match coins (oracle `MATCH_COINS`: won 400 / draw 200 / loss 100).
|
||||
pub fn match_result_coins(result: MatchResult) -> i64 {
|
||||
match result {
|
||||
MatchResult::Win => 400,
|
||||
MatchResult::Draw => 200,
|
||||
MatchResult::Loss => 100,
|
||||
}
|
||||
}
|
||||
|
||||
/// Total match reward = per-result coins + participation.
|
||||
pub fn match_reward_total(result: MatchResult) -> i64 {
|
||||
match_result_coins(result) + MATCH_PARTICIPATION
|
||||
}
|
||||
|
||||
/// Derive the outcome from the match `endReason` enum (the oracle's primary
|
||||
/// signal, `_END_REASON`). Unknown/absent reasons default to `Draw`, matching
|
||||
/// the oracle's conservative default. Score-based derivation is a fallback the
|
||||
/// oracle also supports; the enum is authoritative when present.
|
||||
pub fn result_from_end_reason(end_reason: Option<&str>) -> MatchResult {
|
||||
match end_reason.unwrap_or("").to_ascii_uppercase().as_str() {
|
||||
"WIN" | "DNF_WIN" => MatchResult::Win,
|
||||
"LOSS" | "QUIT" | "DNF" | "DNF_LOSS" => MatchResult::Loss,
|
||||
// "DRAW", "DNF_DRAW", "NO_CONTEST", unknown -> draw.
|
||||
_ => MatchResult::Draw,
|
||||
}
|
||||
}
|
||||
|
||||
/// The Store buy-now price for a pack id (`None` for unknown/owned-only packs,
|
||||
/// which are never purchasable).
|
||||
pub fn pack_price(pack_id: u64) -> Option<u64> {
|
||||
pack_by_id(pack_id)
|
||||
.filter(|p| !p.owned_only)
|
||||
.map(|p| p.price)
|
||||
}
|
||||
|
||||
/// FIFA 17 transfer-market fee, in PERCENT of the gross sale price.
|
||||
///
|
||||
/// FIFA17-HISTORICAL: 5% is the well-documented FUT transfer tax of the era. It
|
||||
/// was not recovered from our client binary — no `tax`/`netPrice`/`sellerProceeds`
|
||||
/// wire field exists (`docs/FIFA17_TRANSFER_MARKET_WIRE.md`), because the client
|
||||
/// is told only the GROSS price and the deduction is server-side.
|
||||
pub const TRANSFER_MARKET_FEE_PERCENT: i64 = 5;
|
||||
|
||||
/// Fee withheld from a completed sale of `gross` coins.
|
||||
///
|
||||
/// Integer arithmetic only — coin settlement never touches floating point, where
|
||||
/// `0.05` is not representable and a large price could round a coin into or out of
|
||||
/// existence. Widening to `i128` for the multiply makes overflow unreachable for
|
||||
/// any `i64` price, so no ceiling has to be assumed.
|
||||
///
|
||||
/// ROUNDING, and it is a CHOICE that needs live confirmation: the fee is FLOORED,
|
||||
/// so the seller keeps the fractional coin. That is deliberate — it makes
|
||||
/// `fee + proceeds == gross` hold exactly for every input, which is the property
|
||||
/// the accounting invariant depends on. The discriminating case against the
|
||||
/// alternative (flooring the seller's 95% instead) is a gross of 150: this rule
|
||||
/// pays 143, the alternative 142. Nothing in the corpus settles which the real
|
||||
/// server did, so this MUST NOT be treated as confirmed FIFA behaviour.
|
||||
///
|
||||
/// A negative gross is not a sale; it yields a zero fee rather than inventing a
|
||||
/// negative one, and `settle_sale` rejects the price itself.
|
||||
pub fn transfer_market_fee(gross: i64) -> i64 {
|
||||
if gross <= 0 {
|
||||
return 0;
|
||||
}
|
||||
((gross as i128 * TRANSFER_MARKET_FEE_PERCENT as i128) / 100) as i64
|
||||
}
|
||||
|
||||
/// What the seller is credited for a completed sale of `gross` coins.
|
||||
///
|
||||
/// Defined as `gross - fee` rather than as its own percentage, so the pair can
|
||||
/// never disagree about where a rounded coin went.
|
||||
pub fn seller_proceeds(gross: i64) -> i64 {
|
||||
gross.max(0) - transfer_market_fee(gross)
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn match_rewards_match_oracle() {
|
||||
assert_eq!(match_reward_total(MatchResult::Win), 400);
|
||||
assert_eq!(match_reward_total(MatchResult::Draw), 200);
|
||||
assert_eq!(match_reward_total(MatchResult::Loss), 100);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn end_reason_maps_to_outcome() {
|
||||
assert_eq!(result_from_end_reason(Some("WIN")), MatchResult::Win);
|
||||
assert_eq!(result_from_end_reason(Some("dnf_win")), MatchResult::Win);
|
||||
assert_eq!(result_from_end_reason(Some("LOSS")), MatchResult::Loss);
|
||||
assert_eq!(result_from_end_reason(Some("QUIT")), MatchResult::Loss);
|
||||
assert_eq!(result_from_end_reason(Some("DRAW")), MatchResult::Draw);
|
||||
assert_eq!(result_from_end_reason(None), MatchResult::Draw);
|
||||
assert_eq!(result_from_end_reason(Some("weird")), MatchResult::Draw);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn pack_price_rejects_unknown_and_owned_only() {
|
||||
assert!(pack_price(1).is_some());
|
||||
assert_eq!(pack_price(65534), None); // sentinel absent from catalogue
|
||||
assert_eq!(pack_price(70), None); // owned-only reward pack, not purchasable
|
||||
}
|
||||
|
||||
/// Pins the rounding rule at every boundary the fee can turn over. If one of
|
||||
/// these ever changes, monetary behaviour changed — that must be deliberate.
|
||||
#[test]
|
||||
fn transfer_market_fee_is_floored_five_percent() {
|
||||
// (gross, expected fee, expected proceeds)
|
||||
let cases = [
|
||||
(0i64, 0i64, 0i64),
|
||||
(1, 0, 1), // 0.05 -> 0
|
||||
(19, 0, 19), // 0.95 -> 0, the last fee-free price
|
||||
(20, 1, 19), // exactly 1.0, the first price that pays
|
||||
(21, 1, 20), // 1.05 -> 1
|
||||
(39, 1, 38), // 1.95 -> 1
|
||||
(40, 2, 38), // exactly 2.0
|
||||
(100, 5, 95),
|
||||
(101, 5, 96), // 5.05 -> 5
|
||||
(119, 5, 114), // 5.95 -> 5, last price paying 5
|
||||
(120, 6, 114), // exactly 6.0
|
||||
(149, 7, 142), // 7.45 -> 7
|
||||
(150, 7, 143), // 7.5 -> 7: THE discriminating case (alternative: 8/142)
|
||||
(151, 7, 144), // 7.55 -> 7 (a HALF-UP rule would pay 8 here too)
|
||||
(199, 9, 190), // 9.95 -> 9
|
||||
(200, 10, 190), // exactly 10.0
|
||||
(1_000, 50, 950),
|
||||
(15_000, 750, 14_250), // the canonical fixture
|
||||
(15_000_000, 750_000, 14_250_000), // FUT's practical price ceiling
|
||||
(i64::MAX, i64::MAX / 20, i64::MAX - i64::MAX / 20), // no overflow
|
||||
];
|
||||
for (gross, fee, proceeds) in cases {
|
||||
assert_eq!(transfer_market_fee(gross), fee, "fee for gross {gross}");
|
||||
assert_eq!(
|
||||
seller_proceeds(gross),
|
||||
proceeds,
|
||||
"proceeds for gross {gross}"
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
/// The property the whole settlement's accounting rests on: the fee and the
|
||||
/// seller's proceeds account for the gross EXACTLY, with no coin created or
|
||||
/// destroyed by rounding, at every price.
|
||||
#[test]
|
||||
fn fee_plus_proceeds_is_exactly_gross() {
|
||||
for gross in (0i64..2_000).chain([15_000, 999_999, 15_000_000, i64::MAX]) {
|
||||
assert_eq!(
|
||||
transfer_market_fee(gross) + seller_proceeds(gross),
|
||||
gross,
|
||||
"fee + proceeds != gross at {gross}"
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
/// A non-sale must not invent a negative fee.
|
||||
#[test]
|
||||
fn negative_gross_yields_no_fee() {
|
||||
assert_eq!(transfer_market_fee(-1), 0);
|
||||
assert_eq!(transfer_market_fee(i64::MIN), 0);
|
||||
assert_eq!(seller_proceeds(-100), 0);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,239 @@
|
||||
//! FIFA 17 entity id ⇄ name resolution, loaded from the committed game-DB
|
||||
//! tables (`leagues.json`, `nations.json`, `teams.json`, dumped from
|
||||
//! `FIFA17.exe`'s resident DB).
|
||||
//!
|
||||
//! Two directions, both FIFA-17-specific and therefore adapter-owned:
|
||||
//! * **forward** id → name — resolves a wire filter (`league=13`) to the
|
||||
//! semantic name Core filters on ("Premier League"). See [`EntityResolver`].
|
||||
//! * **reverse** name → id — shapes a Core item's names back into the numeric
|
||||
//! ids the FIFA `/club` response carries (`leagueId`/`teamid`/`nation`).
|
||||
//!
|
||||
//! Grounding (worker-verified against the tables): forward is 1:1 for all three
|
||||
//! (unique ids, no gaps). Reverse is clean for leagues (50 distinct names) and
|
||||
//! nations (221 distinct); **team names collide** (e.g. `Arsenal` ×3, plus the
|
||||
//! FUT "CHAMPIONS *" placeholder teams), so reverse team lookup is first-id-wins
|
||||
//! and a collision count is exposed for diagnostics. `teamid == assetid` on
|
||||
//! every row.
|
||||
|
||||
use std::collections::HashMap;
|
||||
|
||||
use crate::fut::owned_query::EntityResolver;
|
||||
|
||||
/// Reverse (name → FIFA id) resolution, used when shaping a Core item back onto
|
||||
/// the FIFA wire. Unknown names return `None`; the shaper substitutes a neutral
|
||||
/// `0` (a valid, non-desyncing int) rather than dropping the item.
|
||||
pub trait ReverseEntityResolver {
|
||||
fn league_id(&self, name: &str) -> Option<u32>;
|
||||
fn nation_id(&self, name: &str) -> Option<u32>;
|
||||
fn team_id(&self, name: &str) -> Option<u32>;
|
||||
}
|
||||
|
||||
/// Forward + reverse FIFA 17 entity maps.
|
||||
#[derive(Debug, Default, Clone)]
|
||||
pub struct Fifa17Entities {
|
||||
league_by_id: HashMap<u32, String>,
|
||||
league_by_name: HashMap<String, u32>,
|
||||
nation_by_id: HashMap<u32, String>,
|
||||
nation_by_name: HashMap<String, u32>,
|
||||
team_by_id: HashMap<u32, String>,
|
||||
team_by_name: HashMap<String, u32>,
|
||||
/// name-collisions dropped from the reverse maps (diagnostics only).
|
||||
pub reverse_collisions: usize,
|
||||
}
|
||||
|
||||
/// Errors loading the entity tables.
|
||||
#[derive(Debug)]
|
||||
pub enum LoadError {
|
||||
Io(std::io::Error),
|
||||
Parse { file: String, detail: String },
|
||||
}
|
||||
|
||||
impl std::fmt::Display for LoadError {
|
||||
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
|
||||
match self {
|
||||
LoadError::Io(e) => write!(f, "reading entity tables: {e}"),
|
||||
LoadError::Parse { file, detail } => write!(f, "parsing {file}: {detail}"),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl std::error::Error for LoadError {}
|
||||
|
||||
impl Fifa17Entities {
|
||||
/// Load from a directory holding `leagues.json`, `nations.json`,
|
||||
/// `teams.json` in the FIFA17 `{schema, rows:[...]}` dump format.
|
||||
pub fn from_tables_dir(dir: &std::path::Path) -> Result<Self, LoadError> {
|
||||
let mut e = Fifa17Entities::default();
|
||||
e.load_table(
|
||||
&dir.join("leagues.json"),
|
||||
"leagueid",
|
||||
"leaguename",
|
||||
Entity::League,
|
||||
)?;
|
||||
e.load_table(
|
||||
&dir.join("nations.json"),
|
||||
"nationid",
|
||||
"nationname",
|
||||
Entity::Nation,
|
||||
)?;
|
||||
e.load_table(&dir.join("teams.json"), "teamid", "teamname", Entity::Team)?;
|
||||
Ok(e)
|
||||
}
|
||||
|
||||
fn load_table(
|
||||
&mut self,
|
||||
path: &std::path::Path,
|
||||
id_key: &str,
|
||||
name_key: &str,
|
||||
which: Entity,
|
||||
) -> Result<(), LoadError> {
|
||||
let raw = std::fs::read_to_string(path).map_err(LoadError::Io)?;
|
||||
let file = path.display().to_string();
|
||||
let doc: serde_json::Value = serde_json::from_str(&raw).map_err(|e| LoadError::Parse {
|
||||
file: file.clone(),
|
||||
detail: e.to_string(),
|
||||
})?;
|
||||
let rows = doc
|
||||
.get("rows")
|
||||
.and_then(|r| r.as_array())
|
||||
.ok_or_else(|| LoadError::Parse {
|
||||
file: file.clone(),
|
||||
detail: "missing `rows` array".into(),
|
||||
})?;
|
||||
for row in rows {
|
||||
let (Some(id), Some(name)) = (
|
||||
row.get(id_key).and_then(|v| v.as_u64()),
|
||||
row.get(name_key).and_then(|v| v.as_str()),
|
||||
) else {
|
||||
continue;
|
||||
};
|
||||
let id = id as u32;
|
||||
let (by_id, by_name) = match which {
|
||||
Entity::League => (&mut self.league_by_id, &mut self.league_by_name),
|
||||
Entity::Nation => (&mut self.nation_by_id, &mut self.nation_by_name),
|
||||
Entity::Team => (&mut self.team_by_id, &mut self.team_by_name),
|
||||
};
|
||||
by_id.insert(id, name.to_string());
|
||||
// Reverse: first id wins on a name collision; count the rest.
|
||||
if by_name.contains_key(name) {
|
||||
self.reverse_collisions += 1;
|
||||
} else {
|
||||
by_name.insert(name.to_string(), id);
|
||||
}
|
||||
}
|
||||
Ok(())
|
||||
}
|
||||
|
||||
/// Build directly from maps (tests / small deployments).
|
||||
pub fn from_maps(
|
||||
leagues: HashMap<u32, String>,
|
||||
nations: HashMap<u32, String>,
|
||||
teams: HashMap<u32, String>,
|
||||
) -> Self {
|
||||
let invert = |m: &HashMap<u32, String>| {
|
||||
let mut out = HashMap::new();
|
||||
for (&id, name) in m {
|
||||
out.entry(name.clone()).or_insert(id);
|
||||
}
|
||||
out
|
||||
};
|
||||
Fifa17Entities {
|
||||
league_by_name: invert(&leagues),
|
||||
nation_by_name: invert(&nations),
|
||||
team_by_name: invert(&teams),
|
||||
league_by_id: leagues,
|
||||
nation_by_id: nations,
|
||||
team_by_id: teams,
|
||||
reverse_collisions: 0,
|
||||
}
|
||||
}
|
||||
|
||||
pub fn league_count(&self) -> usize {
|
||||
self.league_by_id.len()
|
||||
}
|
||||
pub fn nation_count(&self) -> usize {
|
||||
self.nation_by_id.len()
|
||||
}
|
||||
pub fn team_count(&self) -> usize {
|
||||
self.team_by_id.len()
|
||||
}
|
||||
}
|
||||
|
||||
#[derive(Clone, Copy)]
|
||||
enum Entity {
|
||||
League,
|
||||
Nation,
|
||||
Team,
|
||||
}
|
||||
|
||||
impl EntityResolver for Fifa17Entities {
|
||||
fn league_name(&self, id: u32) -> Option<String> {
|
||||
self.league_by_id.get(&id).cloned()
|
||||
}
|
||||
fn nation_name(&self, id: u32) -> Option<String> {
|
||||
self.nation_by_id.get(&id).cloned()
|
||||
}
|
||||
fn team_name(&self, id: u32) -> Option<String> {
|
||||
self.team_by_id.get(&id).cloned()
|
||||
}
|
||||
}
|
||||
|
||||
impl ReverseEntityResolver for Fifa17Entities {
|
||||
fn league_id(&self, name: &str) -> Option<u32> {
|
||||
self.league_by_name.get(name).copied()
|
||||
}
|
||||
fn nation_id(&self, name: &str) -> Option<u32> {
|
||||
self.nation_by_name.get(name).copied()
|
||||
}
|
||||
fn team_id(&self, name: &str) -> Option<u32> {
|
||||
self.team_by_name.get(name).copied()
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
/// Path to the committed game-DB tables, relative to this crate.
|
||||
fn tables_dir() -> std::path::PathBuf {
|
||||
std::path::Path::new(env!("CARGO_MANIFEST_DIR")).join("../fifa17-recon/data/tables")
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn loads_committed_tables_and_resolves_both_directions() {
|
||||
let dir = tables_dir();
|
||||
if !dir.join("leagues.json").exists() {
|
||||
eprintln!(
|
||||
"skipping: committed tables not present at {}",
|
||||
dir.display()
|
||||
);
|
||||
return;
|
||||
}
|
||||
let e = Fifa17Entities::from_tables_dir(&dir).expect("load tables");
|
||||
assert_eq!(e.league_count(), 50);
|
||||
assert_eq!(e.nation_count(), 221);
|
||||
assert_eq!(e.team_count(), 750);
|
||||
// forward id -> name (grounding pinned in owned_query too)
|
||||
assert_eq!(e.league_name(13).as_deref(), Some("Premier League"));
|
||||
assert_eq!(e.nation_name(52).as_deref(), Some("Argentina"));
|
||||
assert_eq!(e.team_name(5).as_deref(), Some("Chelsea"));
|
||||
// reverse name -> id (clean for leagues/nations)
|
||||
assert_eq!(e.league_id("Premier League"), Some(13));
|
||||
assert_eq!(e.nation_id("Argentina"), Some(52));
|
||||
assert_eq!(e.team_id("Chelsea"), Some(5));
|
||||
// unknown -> None (never a raw-id fallback)
|
||||
assert_eq!(e.league_name(999_999), None);
|
||||
assert_eq!(e.team_id("Northgate United"), None);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn from_maps_inverts() {
|
||||
let e = Fifa17Entities::from_maps(
|
||||
HashMap::from([(13, "Premier League".to_string())]),
|
||||
HashMap::from([(52, "Argentina".to_string())]),
|
||||
HashMap::from([(5, "Chelsea".to_string())]),
|
||||
);
|
||||
assert_eq!(e.league_id("Premier League"), Some(13));
|
||||
assert_eq!(e.team_name(5).as_deref(), Some("Chelsea"));
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,284 @@
|
||||
//! The shared FIFA 17 FUT **item-shaping primitive**.
|
||||
//!
|
||||
//! One function shapes one owned FUT item into the numeric card object the FIFA
|
||||
//! 17 client renders, and **every** route that emits a player item goes through
|
||||
//! it — `/club` (via [`crate::fut::club_response`]) and squad projection (via
|
||||
//! [`crate::fut::squad_projection`]) alike. There is deliberately no second copy
|
||||
//! of the field set: an item is shaped in exactly one place so the two routes
|
||||
//! can never drift.
|
||||
//!
|
||||
//! ## The asset-id boundary (load-bearing, evidence-grounded)
|
||||
//!
|
||||
//! FIFA renders a card by resolving `resourceId & 0xffffff` against the client's
|
||||
//! OWN local players table (proven live): a real id renders a real footballer,
|
||||
//! an **invented id renders a blank generic card**. OpenFUT Core's catalogue is
|
||||
//! synthetic string ids (`card_pl_001`) with no FIFA asset id. So an
|
||||
//! [`ItemIdentityResolver`] is injected; when it cannot supply a **real** FIFA
|
||||
//! asset id for an item, the item carries no fabricated identity — the caller
|
||||
//! decides what that means (`/club` drops and counts it; a squad refuses to
|
||||
//! project a starter it cannot render, never faking one).
|
||||
//!
|
||||
//! Entity ids (`leagueId`/`teamid`/`nation`) come from a reverse resolver; an
|
||||
//! unresolved name yields a neutral `0` (a valid int — non-fatal; it only means
|
||||
//! "no badge/flag"), because those are not the identity the renderer keys on.
|
||||
|
||||
use serde_json::{json, Value};
|
||||
|
||||
use crate::fut::content_taxonomy::ContentKind;
|
||||
use crate::fut::entities::ReverseEntityResolver;
|
||||
|
||||
/// One owned item in game-independent terms, as read from Core's inventory.
|
||||
#[derive(Debug, Clone)]
|
||||
pub struct CoreOwnedItem {
|
||||
/// Core owned-instance id (string). The stable per-copy identity — two
|
||||
/// copies of the same card definition have distinct `owned_card_id`s.
|
||||
pub owned_card_id: String,
|
||||
/// Core card-definition id (string), used for asset resolution.
|
||||
pub card_id: String,
|
||||
/// Effective overall rating.
|
||||
pub rating: u8,
|
||||
/// Effective position, e.g. "ST".
|
||||
pub position: String,
|
||||
pub nation: String,
|
||||
pub league: String,
|
||||
pub club: String,
|
||||
/// [pace, shooting, passing, dribbling, defending, physical].
|
||||
pub attributes: [u8; 6],
|
||||
}
|
||||
|
||||
/// The FIFA-side numeric identity of an owned item. `asset_id` MUST be a real
|
||||
/// FIFA player asset (low 24 bits the client resolves); `item_id` is the wire
|
||||
/// instance id used for later item operations. Two owned copies of the same
|
||||
/// definition share an `asset_id` but MUST have distinct `item_id`s.
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub struct Fifa17Identity {
|
||||
pub item_id: u32,
|
||||
/// Base FIFA player asset (low 24 bits the client resolves art/name from).
|
||||
pub asset_id: u32,
|
||||
/// Full versioned resource id = `(version << 24) | asset_id`. Equals
|
||||
/// `asset_id` for a version-0 base card. This is the wire
|
||||
/// `resourceId`/`definitionId`, kept DISTINCT from `asset_id` so a versioned
|
||||
/// (special) card never collapses onto its base on the wire.
|
||||
pub resource_id: u32,
|
||||
/// FIFA wire `rareflag` — the card's rare/special TYPE (e.g. 3=inform,
|
||||
/// 21..=24 = special programmes). Drives the client's special-card art;
|
||||
/// carried from the catalog, never hardcoded, so specials render as specials.
|
||||
pub rareflag: i64,
|
||||
}
|
||||
|
||||
/// Supplies the FIFA numeric identity for a Core item. Returning `None` means
|
||||
/// "no real FIFA asset id known" → the caller must not fabricate one.
|
||||
pub trait ItemIdentityResolver {
|
||||
fn resolve(&self, item: &CoreOwnedItem) -> Option<Fifa17Identity>;
|
||||
|
||||
/// Classify a Core item's definition as player/consumable/staff. Defaults to
|
||||
/// [`ContentKind::Player`] so existing resolvers keep their behaviour; a
|
||||
/// catalog-backed resolver overrides this to consult its `kind_of`, letting
|
||||
/// `/club` exclude non-player content (which must never render as a
|
||||
/// 0-rated player).
|
||||
fn kind_of(&self, _item: &CoreOwnedItem) -> ContentKind {
|
||||
ContentKind::Player
|
||||
}
|
||||
}
|
||||
|
||||
/// Diagnostics from shaping (safe to log — counts only).
|
||||
#[derive(Debug, Default, Clone, Copy, PartialEq, Eq)]
|
||||
pub struct ShapeStats {
|
||||
pub emitted: usize,
|
||||
pub dropped_no_asset: usize,
|
||||
/// Consumable/staff items excluded from a player projection (they must never
|
||||
/// render as a 0-rated player). Counted, never emitted.
|
||||
pub excluded_non_player: usize,
|
||||
}
|
||||
|
||||
/// Quick-sell / discard value by rating tier (mirrors Core's quick-sell table;
|
||||
/// non-fatal display field).
|
||||
fn discard_value(rating: u8) -> i64 {
|
||||
match rating {
|
||||
r if r >= 85 => 1500,
|
||||
r if r >= 80 => 900,
|
||||
r if r >= 75 => 600,
|
||||
r if r >= 65 => 300,
|
||||
_ => 150,
|
||||
}
|
||||
}
|
||||
|
||||
/// Build one FIFA `_item` object. `resourceId`/`definitionId` carry the full
|
||||
/// versioned resource id; `assetId`/`cardassetid` carry the base asset. For a
|
||||
/// version-0 base card these coincide; for a special they differ and MUST NOT
|
||||
/// be collapsed.
|
||||
///
|
||||
/// This is the single source of truth for a player item's on-wire shape; the
|
||||
/// `/club` envelope and squad projection both call it, so their items are
|
||||
/// identical by construction. `id` is the owned instance's resolved FIFA
|
||||
/// identity — pass the resolver's answer for *this* owned copy so two copies of
|
||||
/// one definition stay distinct on the wire.
|
||||
pub fn shape_item(
|
||||
item: &CoreOwnedItem,
|
||||
id: Fifa17Identity,
|
||||
ent: &impl ReverseEntityResolver,
|
||||
) -> Value {
|
||||
let asset = id.asset_id;
|
||||
let league_id = ent.league_id(&item.league).unwrap_or(0);
|
||||
let team_id = ent.team_id(&item.club).unwrap_or(0);
|
||||
let nation_id = ent.nation_id(&item.nation).unwrap_or(0);
|
||||
let attribute_list: Vec<Value> = item
|
||||
.attributes
|
||||
.iter()
|
||||
.enumerate()
|
||||
.map(|(i, v)| json!({ "index": i, "value": v }))
|
||||
.collect();
|
||||
json!({
|
||||
"id": id.item_id,
|
||||
"resourceId": id.resource_id,
|
||||
"assetId": asset,
|
||||
"cardassetid": asset,
|
||||
"definitionId": id.resource_id,
|
||||
"cardsubtypeid": 0,
|
||||
"itemType": "player",
|
||||
"rareflag": id.rareflag,
|
||||
"rating": item.rating,
|
||||
"preferredPosition": item.position,
|
||||
"nation": nation_id,
|
||||
"teamid": team_id,
|
||||
"leagueId": league_id,
|
||||
"playStyle": 250,
|
||||
"attributeList": attribute_list,
|
||||
"itemState": "free",
|
||||
"owners": 1,
|
||||
// Owned/pack-pulled cards are TRADEABLE in FIFA 17 (untradeable is the
|
||||
// exception for SBC/promo rewards, which Core does not model). Emitting
|
||||
// `true` greyed out "Place on Transfer Market" for every card — the same
|
||||
// "our own data showing through" bug the Python oracle fixed by forcing
|
||||
// this off for owned copies (item_def keeps `true`; instances do not).
|
||||
"untradeable": false,
|
||||
"contract": 7,
|
||||
"fitness": 99,
|
||||
"discardValue": discard_value(item.rating),
|
||||
})
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
use crate::fut::entities::Fifa17Entities;
|
||||
use std::collections::HashMap;
|
||||
|
||||
fn entities() -> Fifa17Entities {
|
||||
Fifa17Entities::from_maps(
|
||||
HashMap::from([(13, "Premier League".to_string())]),
|
||||
HashMap::from([(52, "Argentina".to_string())]),
|
||||
HashMap::from([(5, "Chelsea".to_string())]),
|
||||
)
|
||||
}
|
||||
|
||||
fn item(owned: &str, card: &str, rating: u8, pos: &str) -> CoreOwnedItem {
|
||||
CoreOwnedItem {
|
||||
owned_card_id: owned.into(),
|
||||
card_id: card.into(),
|
||||
rating,
|
||||
position: pos.into(),
|
||||
nation: "Argentina".into(),
|
||||
league: "Premier League".into(),
|
||||
club: "Chelsea".into(),
|
||||
attributes: [90, 88, 70, 85, 40, 78],
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn shapes_real_identity_and_reverse_entity_ids() {
|
||||
let ent = entities();
|
||||
let it = shape_item(
|
||||
&item("oc1", "card_ch_1", 86, "CDM"),
|
||||
Fifa17Identity {
|
||||
item_id: 100000001,
|
||||
asset_id: 20801,
|
||||
resource_id: 20801,
|
||||
rareflag: 1,
|
||||
},
|
||||
&ent,
|
||||
);
|
||||
assert_eq!(it["id"], 100000001, "wire instance id");
|
||||
assert_eq!(it["resourceId"], 20801);
|
||||
assert_eq!(it["assetId"], 20801);
|
||||
assert_eq!(
|
||||
it["definitionId"], 20801,
|
||||
"version byte 0 => resourceId==assetId==definitionId"
|
||||
);
|
||||
assert_eq!(it["rating"], 86);
|
||||
assert_eq!(it["preferredPosition"], "CDM");
|
||||
assert_eq!(it["leagueId"], 13);
|
||||
assert_eq!(it["teamid"], 5);
|
||||
assert_eq!(it["nation"], 52);
|
||||
assert_eq!(it["itemType"], "player");
|
||||
assert_eq!(it["attributeList"].as_array().unwrap().len(), 6);
|
||||
assert_eq!(it["attributeList"][0], json!({"index":0,"value":90}));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn two_owned_copies_of_one_definition_stay_distinct_on_the_wire() {
|
||||
// fifa17_101490 has two owned instances: same definition/asset, two
|
||||
// distinct owned ids and two distinct wire ids. Shaping each from its
|
||||
// own identity must NEVER collapse them.
|
||||
let ent = entities();
|
||||
let a = shape_item(
|
||||
&item("oc-a", "fifa17_101490", 84, "ST"),
|
||||
Fifa17Identity {
|
||||
item_id: 100000030,
|
||||
asset_id: 101490,
|
||||
resource_id: 101490,
|
||||
rareflag: 1,
|
||||
},
|
||||
&ent,
|
||||
);
|
||||
let b = shape_item(
|
||||
&item("oc-b", "fifa17_101490", 84, "ST"),
|
||||
Fifa17Identity {
|
||||
item_id: 100000031,
|
||||
asset_id: 101490,
|
||||
resource_id: 101490,
|
||||
rareflag: 1,
|
||||
},
|
||||
&ent,
|
||||
);
|
||||
assert_eq!(
|
||||
a["resourceId"], b["resourceId"],
|
||||
"same definition => same asset"
|
||||
);
|
||||
assert_ne!(
|
||||
a["id"], b["id"],
|
||||
"distinct owned copies keep distinct wire ids"
|
||||
);
|
||||
assert_eq!(a["id"], 100000030);
|
||||
assert_eq!(b["id"], 100000031);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn versioned_special_keeps_resourceid_distinct_from_assetid() {
|
||||
// A versioned (special) card: resourceId/definitionId carry the full
|
||||
// versioned id; assetId/cardassetid stay the base asset. They MUST NOT
|
||||
// collapse. (resource 117617092 = version 7 of asset 176580.)
|
||||
let ent = entities();
|
||||
let it = shape_item(
|
||||
&item("oc-v", "fifa17_117617092", 92, "ST"),
|
||||
Fifa17Identity {
|
||||
item_id: 100000384,
|
||||
asset_id: 176580,
|
||||
resource_id: 117617092,
|
||||
rareflag: 3,
|
||||
},
|
||||
&ent,
|
||||
);
|
||||
assert_eq!(
|
||||
it["resourceId"], 117617092,
|
||||
"versioned resource id on the wire"
|
||||
);
|
||||
assert_eq!(it["definitionId"], 117617092);
|
||||
assert_eq!(it["assetId"], 176580, "base asset id preserved");
|
||||
assert_eq!(it["cardassetid"], 176580);
|
||||
assert_eq!(
|
||||
it["rareflag"], 3,
|
||||
"special rareflag carried, not hardcoded 1"
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,22 @@
|
||||
//! FIFA 17 FUT (UTAS/RS4) wire → OpenFUT Core semantic mappings.
|
||||
//!
|
||||
//! Unlike [`crate::blaze`] (binary Blaze RPC), this is the JSON/HTTP FUT surface.
|
||||
//! It currently holds the owned-player ("My Squad") search mapping; more UTAS
|
||||
//! routes join it as the UTAS→Core migration proceeds. Nothing here opens a
|
||||
//! socket — a Rust UTAS host wires it to Core later.
|
||||
pub mod catalog;
|
||||
pub mod club_response;
|
||||
pub mod club_stats;
|
||||
pub mod content_taxonomy;
|
||||
pub mod economy;
|
||||
pub mod economy_policy;
|
||||
pub mod entities;
|
||||
pub mod item;
|
||||
pub mod non_economy;
|
||||
pub mod owned_query;
|
||||
pub mod pack_content;
|
||||
pub mod squad;
|
||||
pub mod squad_ext;
|
||||
pub mod squad_projection;
|
||||
pub mod store_catalog;
|
||||
pub mod store_session;
|
||||
@@ -0,0 +1,684 @@
|
||||
//! FIFA17 non-economy presentation routes, migrated from the Python oracle.
|
||||
//!
|
||||
//! Pure, IO-free shapers that reproduce the **observed production** oracle
|
||||
//! contract (`fifa17-recon/tools/utas_server.py`) for the non-economy UTAS
|
||||
//! routes a Rust host can own without any Core or account state:
|
||||
//!
|
||||
//! * `GET …/user/accountinfo` → `{}` (FUT_ACCOUNTINFO off)
|
||||
//! * `GET …/settings` → `{"configs":[]}` (FUT_SETTINGS off)
|
||||
//! * `GET …/leaderboards/options` → `{}` (FUT_MODES off)
|
||||
//! * `PUT …/match/reset` → `{}` (Tier-B no-op ack)
|
||||
//! * `GET/POST/PUT …/phishing/{trusteddevice,question,validate}` — the retired
|
||||
//! FUT security-question service, a stateless acknowledgement.
|
||||
//!
|
||||
//! These match the bodies the live prod oracle actually returns under the
|
||||
//! production environment (`FUT_TRADING=1 FUT_PILESIZES=1 FUT_TRADEABLE=1`, none
|
||||
//! of the feature flags set). They carry no persisted state: the security
|
||||
//! record the oracle seeds (`{version:1,verified:true}`) is log-only — the
|
||||
//! response is invariant — so a faithful Rust owner needs no persistence.
|
||||
|
||||
use serde_json::{json, Value};
|
||||
|
||||
/// `GET …/user/accountinfo` — production oracle returns an empty object.
|
||||
pub fn accountinfo_body() -> Value {
|
||||
json!({})
|
||||
}
|
||||
|
||||
/// `GET …/settings` — production oracle returns an empty config list.
|
||||
pub fn settings_body() -> Value {
|
||||
json!({ "configs": [] })
|
||||
}
|
||||
|
||||
/// `GET …/leaderboards/options` — production oracle (FUT_MODES off) returns an
|
||||
/// empty object; the retail client ignores the body.
|
||||
pub fn leaderboard_options_body() -> Value {
|
||||
json!({})
|
||||
}
|
||||
|
||||
/// `PUT …/match/reset` — Tier-B no-op acknowledgement.
|
||||
pub fn match_reset_body() -> Value {
|
||||
json!({})
|
||||
}
|
||||
|
||||
/// `GET …/club/stats/staff` — production oracle returns an empty object (FIFA's
|
||||
/// staff-bonus stat set is deliberately empty; the client tolerates `{}`).
|
||||
pub fn club_stats_staff_body() -> Value {
|
||||
json!({})
|
||||
}
|
||||
|
||||
/// The FUT modes (Seasons / Tournaments / FUT Champions) and the club-identity
|
||||
/// service are disabled in this emulator, so their read routes (`season`,
|
||||
/// `tournament`, `champion`, `clubUser`, `user/list`) return an empty object —
|
||||
/// byte-identical to the Python oracle with `FUT_MODES` / `FUT_CLUB_IDENTITY`
|
||||
/// off. Enabling a mode later requires a real Rust implementation here, never a
|
||||
/// Python fallback (which would reintroduce split authority).
|
||||
pub fn feature_off_body() -> Value {
|
||||
json!({})
|
||||
}
|
||||
|
||||
/// One FUT item-definition for a requested `resource_id`, replicating the Python
|
||||
/// oracle's `item_def`: `assetId = resource_id & 0xffffff`; a single hardcoded
|
||||
/// card (Ronaldo, asset 20801) and a generic placeholder (`"Player"`, 75, CM,
|
||||
/// attrs 70) for every other asset. The FIFA client renders the real card from
|
||||
/// its LOCAL DB from the `(rareflag, resourceId)` pair, so this route only needs
|
||||
/// a valid-shaped record — the placeholder is exactly what the oracle itself
|
||||
/// returns for all but the one hardcoded asset. Key order is irrelevant (the
|
||||
/// client's deserializer is key-addressed and skip-safe).
|
||||
pub fn item_def(resource_id: i64) -> Value {
|
||||
let asset = resource_id & 0xff_ffff;
|
||||
// (name, rating, position, nation, leagueId, teamid, [6 attrs])
|
||||
let (name, rating, pos, nation, league, team, attrs): (&str, i64, &str, i64, i64, i64, [i64; 6]) =
|
||||
if asset == 20801 {
|
||||
("Ronaldo", 94, "ST", 38, 53, 243, [90, 93, 82, 91, 33, 80])
|
||||
} else {
|
||||
("Player", 75, "CM", 0, 0, 0, [70, 70, 70, 70, 70, 70])
|
||||
};
|
||||
let attribute_list: Vec<Value> = attrs
|
||||
.iter()
|
||||
.enumerate()
|
||||
.map(|(i, v)| json!({ "index": i, "value": v }))
|
||||
.collect();
|
||||
json!({
|
||||
"id": resource_id,
|
||||
"resourceId": resource_id,
|
||||
"definitionId": resource_id,
|
||||
"assetId": asset,
|
||||
"cardassetid": asset,
|
||||
"commodityId": asset,
|
||||
"cardsubtypeid": 0,
|
||||
"cardType": 0,
|
||||
"itemType": "player",
|
||||
"rareflag": 1,
|
||||
"rating": rating,
|
||||
"preferredPosition": pos,
|
||||
"nation": nation,
|
||||
"leagueId": league,
|
||||
"teamid": team,
|
||||
"playStyle": 250,
|
||||
"attributeList": attribute_list,
|
||||
"name": name,
|
||||
"commonName": name,
|
||||
"lastName": name,
|
||||
"itemState": "free",
|
||||
"untradeable": true,
|
||||
})
|
||||
}
|
||||
|
||||
/// `GET …/item/resource`, `…/defid` — `{itemData:[…]}` with one [`item_def`] per
|
||||
/// requested id (mirrors the oracle's `defs_route`). No ids → an empty list.
|
||||
pub fn item_defs_body(ids: &[i64]) -> Value {
|
||||
json!({ "itemData": ids.iter().map(|&id| item_def(id)).collect::<Vec<_>>() })
|
||||
}
|
||||
|
||||
/// `GET …/marketdata/pricelimits?defId=a,b,c` — FutGetSuggestedPricing. The root
|
||||
/// MUST be a BARE ARRAY (one element per defId): returning an object here froze a
|
||||
/// live client (object-where-array busy loop at the listing screen). Constant
|
||||
/// band 150..15000 (placeholder pricing; not a freeze concern).
|
||||
pub fn marketdata_pricelimits_body(def_ids: &[i64]) -> Value {
|
||||
json!(def_ids
|
||||
.iter()
|
||||
.map(|&d| json!({ "defId": d, "minPrice": 150, "maxPrice": 15000 }))
|
||||
.collect::<Vec<_>>())
|
||||
}
|
||||
|
||||
/// `GET …/marketdata` (NOT `/pricelimits`) — the price-comparison endpoint, which
|
||||
/// takes an OBJECT `{minPrice,maxPrice}`. Array-where-object would be the same
|
||||
/// freeze in reverse, so the container type is load-bearing. Constant band.
|
||||
pub fn marketdata_object_body() -> Value {
|
||||
json!({ "minPrice": 150, "maxPrice": 15000 })
|
||||
}
|
||||
|
||||
/// The phishing/security-question action, parsed from the URL tail.
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub enum SecurityAction {
|
||||
TrustedDevice,
|
||||
Question,
|
||||
Validate,
|
||||
Unknown,
|
||||
}
|
||||
|
||||
/// The `phishing/<action>` selector from a `…/phishing/<action>` path tail.
|
||||
pub fn parse_security_action(tail: &str) -> SecurityAction {
|
||||
let last = tail.trim_end_matches('/').rsplit('/').next().unwrap_or("");
|
||||
match last {
|
||||
"trusteddevice" => SecurityAction::TrustedDevice,
|
||||
"question" => SecurityAction::Question,
|
||||
"validate" => SecurityAction::Validate,
|
||||
_ => SecurityAction::Unknown,
|
||||
}
|
||||
}
|
||||
|
||||
/// A well-formed FUT phishing token is an opaque 32-char lowercase/uppercase hex
|
||||
/// value (`_PHISHING_HEX32.fullmatch` in the oracle).
|
||||
fn is_hex32(s: &str) -> bool {
|
||||
s.len() == 32 && s.bytes().all(|b| b.is_ascii_hexdigit())
|
||||
}
|
||||
|
||||
/// Reproduce `utas_server.py::security_question_route` verbatim.
|
||||
///
|
||||
/// The retired FUT security-question service is a stateless acknowledgement: it
|
||||
/// validates request shape (session, 32-hex device id, 32-hex answer, numeric
|
||||
/// question) and returns fixed bodies. The answer is a client-transformed opaque
|
||||
/// value that is **never stored or compared**; the trusted-device response is an
|
||||
/// invariant `verified/trusted` constant.
|
||||
///
|
||||
/// * `session_known` — whether `X-UT-SID` maps to an open Rust session.
|
||||
/// * `device_id` / `question` / `answer` — decoded query parameters (`""`/`None`
|
||||
/// when absent).
|
||||
///
|
||||
/// Returns `(http_status, body)`.
|
||||
pub fn security_question_response(
|
||||
method: &str,
|
||||
action: SecurityAction,
|
||||
session_known: bool,
|
||||
device_id: &str,
|
||||
question: Option<&str>,
|
||||
answer: Option<&str>,
|
||||
) -> (u16, Value) {
|
||||
let is = |m: &str| method.eq_ignore_ascii_case(m);
|
||||
if !session_known {
|
||||
return (400, json!({ "reason": "invalid_session" }));
|
||||
}
|
||||
if !is_hex32(device_id) {
|
||||
return (400, json!({ "reason": "malformed_request" }));
|
||||
}
|
||||
match action {
|
||||
SecurityAction::TrustedDevice => {
|
||||
if !is("GET") {
|
||||
return (405, json!({ "reason": "method_not_allowed" }));
|
||||
}
|
||||
(
|
||||
200,
|
||||
json!({ "changed": false, "exists": true, "locked": false, "trusted": true }),
|
||||
)
|
||||
}
|
||||
SecurityAction::Question if is("GET") => (
|
||||
200,
|
||||
json!({ "question": 0, "attempts": 5, "recoverAttempts": 0 }),
|
||||
),
|
||||
SecurityAction::Question if is("POST") || is("PUT") => {
|
||||
let q = question.unwrap_or("");
|
||||
let a = answer.unwrap_or("");
|
||||
if q.is_empty() || !q.bytes().all(|b| b.is_ascii_digit()) || !is_hex32(a) {
|
||||
return (400, json!({ "reason": "malformed_request" }));
|
||||
}
|
||||
(200, json!({}))
|
||||
}
|
||||
SecurityAction::Validate if is("POST") => {
|
||||
let a = answer.unwrap_or("");
|
||||
if !is_hex32(a) {
|
||||
return (400, json!({ "reason": "malformed_request" }));
|
||||
}
|
||||
(200, json!({}))
|
||||
}
|
||||
_ => (405, json!({ "reason": "method_not_allowed" })),
|
||||
}
|
||||
}
|
||||
|
||||
// ─────────────────── POST /openfut/account/sync (Rust-owned) ─────────────────
|
||||
|
||||
/// The launcher `account/sync` request fields, with production defaults already
|
||||
/// applied. Everything is optional in the wire body; missing fields fall back to
|
||||
/// the fixed defaults the launcher expects. `personaId` defaults to the host's
|
||||
/// configured persona (passed in), never a baked-in constant.
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub struct AccountSyncRequest {
|
||||
pub persona_id: i64,
|
||||
pub persona_name: String,
|
||||
pub level: i64,
|
||||
pub experience: i64,
|
||||
pub experience_max: i64,
|
||||
pub account_funds: i64,
|
||||
pub account_funds_cap: i64,
|
||||
}
|
||||
|
||||
/// The FIFA persona display name for this emulator's single account.
|
||||
///
|
||||
/// The oracle sources this from the shared account (`fut_account.py`, default
|
||||
/// `"CAGE"`) and documents the property as "Blaze PDTL.DSNM / LSX
|
||||
/// GetProfileResponse Persona / **UTAS sellerName**". That last role is
|
||||
/// load-bearing: the client decides whether a transfer-market listing is the
|
||||
/// player's OWN — and therefore whether to offer Remove / Re-list at all — from
|
||||
/// the seller identity on the auction record. Stamping EA's house name there
|
||||
/// makes the player's own listing un-actionable (pressing it opens no dialog).
|
||||
pub const PERSONA_DISPLAY_NAME: &str = "CAGE";
|
||||
|
||||
/// Parse the `account/sync` request body, applying every default. `default_persona`
|
||||
/// is the host's configured persona id (used when `personaId` is absent).
|
||||
pub fn parse_account_sync(body: &[u8], default_persona: i64) -> AccountSyncRequest {
|
||||
let v: Value = serde_json::from_slice(body).unwrap_or(Value::Null);
|
||||
let int = |key: &str, dflt: i64| v.get(key).and_then(Value::as_i64).unwrap_or(dflt);
|
||||
let persona_name = v
|
||||
.get("personaName")
|
||||
.and_then(Value::as_str)
|
||||
.unwrap_or(PERSONA_DISPLAY_NAME)
|
||||
.to_string();
|
||||
AccountSyncRequest {
|
||||
persona_id: int("personaId", default_persona),
|
||||
persona_name,
|
||||
level: int("level", 1),
|
||||
experience: int("experience", 0),
|
||||
experience_max: int("experienceMax", 1000),
|
||||
account_funds: int("accountFunds", 0),
|
||||
account_funds_cap: int("accountFundsCap", 100000),
|
||||
}
|
||||
}
|
||||
|
||||
/// `POST /openfut/account/sync` — the launcher control-plane account summary.
|
||||
/// `coins`/`unopened_packs` are the AUTHORITATIVE Core values (balance +
|
||||
/// entitlement count), never Python's stale profile funds.
|
||||
pub fn account_sync_body(
|
||||
req: &AccountSyncRequest,
|
||||
coins: i64,
|
||||
unopened_packs: usize,
|
||||
club_name: &str,
|
||||
club_abbr: &str,
|
||||
) -> Value {
|
||||
json!({
|
||||
"account": {
|
||||
"personaId": req.persona_id,
|
||||
"personaName": req.persona_name,
|
||||
"clubName": club_name,
|
||||
"clubAbbr": club_abbr,
|
||||
"level": req.level,
|
||||
"experience": req.experience,
|
||||
"experienceMax": req.experience_max,
|
||||
"accountFunds": req.account_funds,
|
||||
"accountFundsCap": req.account_funds_cap,
|
||||
"profilePath": "accounts/33068179/fifa17_profile.json",
|
||||
"coins": coins,
|
||||
"unopenedPacks": unopened_packs,
|
||||
},
|
||||
"status": "OK",
|
||||
})
|
||||
}
|
||||
|
||||
// ─────────────────────── GET …/userMassInfo (Rust-owned) ─────────────────────
|
||||
|
||||
/// Build the full `GET …/userMassInfo` body entirely in Rust (no Python).
|
||||
///
|
||||
/// `squad` is the Core-projected active squad (`user_mass_info_squad` output), so
|
||||
/// it is byte-for-byte the object `GET …/squad/active` embeds. `coins` and
|
||||
/// `unopened_packs` are the authoritative Core economy values. `userInfo.actives`
|
||||
/// mirrors the squad's `actives` (capped at 5), and `userInfo.squadList` is the
|
||||
/// summary of the current squad.
|
||||
pub fn user_mass_info_body(
|
||||
squad: Value,
|
||||
coins: i64,
|
||||
unopened_packs: usize,
|
||||
persona_id: i64,
|
||||
club_name: &str,
|
||||
club_abbr: &str,
|
||||
established: &str,
|
||||
) -> Value {
|
||||
let actives: Vec<Value> = squad
|
||||
.get("actives")
|
||||
.and_then(Value::as_array)
|
||||
.map(|a| a.iter().take(5).cloned().collect())
|
||||
.unwrap_or_default();
|
||||
let squad_list = crate::fut::squad_projection::squad_list(&squad);
|
||||
let mut user_info = json!({
|
||||
"personaId": persona_id,
|
||||
"clubName": club_name,
|
||||
"clubAbbr": club_abbr,
|
||||
"established": established,
|
||||
"accountCreatedPlatformName": "pc",
|
||||
"currencies": [
|
||||
{"name": "coins", "funds": coins, "finalFunds": coins, "active": true},
|
||||
{"name": "points", "funds": 0, "finalFunds": 0, "active": true},
|
||||
],
|
||||
"won": 0,
|
||||
"draw": 0,
|
||||
"loss": 0,
|
||||
"clubNameChangeAllowed": false,
|
||||
"divisionOffline": 10,
|
||||
"divisionOnline": 10,
|
||||
"purchased": false,
|
||||
"feature": {},
|
||||
"reliability": {"reliability": 100, "matchUnfinishedTime": 0},
|
||||
"bidTokens": {"count": 0, "updateTime": 0},
|
||||
"trophies": 0,
|
||||
"sessionCoinsBankBalance": 0,
|
||||
"actives": actives,
|
||||
"squadList": squad_list,
|
||||
});
|
||||
if unopened_packs > 0 {
|
||||
user_info.as_object_mut().unwrap().insert(
|
||||
"unopenedPacks".into(),
|
||||
json!({"preOrderPacks": 0, "recoveredPacks": unopened_packs}),
|
||||
);
|
||||
}
|
||||
json!({
|
||||
"pileSizeClientData": {"entries": [{"key": 2, "value": 100}, {"key": 4, "value": 50}]},
|
||||
"settings": {"configs": []},
|
||||
"userData": {},
|
||||
"squad": squad,
|
||||
"userInfo": user_info,
|
||||
})
|
||||
}
|
||||
|
||||
// ───────────────────────────── POST /ut/auth (Rust) ──────────────────────────
|
||||
|
||||
/// Format `epoch_secs` (seconds since the Unix epoch) as UTC
|
||||
/// `YYYY-MM-DD HH:MM:SS`. Pure civil-date arithmetic (Howard Hinnant's
|
||||
/// `civil_from_days`), so no `time`/`chrono` dependency is needed.
|
||||
pub fn format_utc_datetime(epoch_secs: i64) -> String {
|
||||
let days = epoch_secs.div_euclid(86_400);
|
||||
let secs_of_day = epoch_secs.rem_euclid(86_400);
|
||||
let (hour, min, sec) = (secs_of_day / 3600, (secs_of_day % 3600) / 60, secs_of_day % 60);
|
||||
// civil_from_days: days is a count of days since 1970-01-01.
|
||||
let z = days + 719_468;
|
||||
let era = if z >= 0 { z } else { z - 146_096 } / 146_097;
|
||||
let doe = z - era * 146_097; // [0, 146096]
|
||||
let yoe = (doe - doe / 1460 + doe / 36_524 - doe / 146_096) / 365; // [0, 399]
|
||||
let year = yoe + era * 400;
|
||||
let doy = doe - (365 * yoe + yoe / 4 - yoe / 100); // [0, 365]
|
||||
let mp = (5 * doy + 2) / 153; // [0, 11]
|
||||
let day = doy - (153 * mp + 2) / 5 + 1; // [1, 31]
|
||||
let month = if mp < 10 { mp + 3 } else { mp - 9 }; // [1, 12]
|
||||
let year = if month <= 2 { year + 1 } else { year };
|
||||
format!("{year:04}-{month:02}-{day:02} {hour:02}:{min:02}:{sec:02}")
|
||||
}
|
||||
|
||||
/// The persona a `/ut/auth` request adopts: `nucleusPersonaId` or `nuc` from the
|
||||
/// body (numeric or numeric string), else `None` (the host substitutes its
|
||||
/// configured persona). The client is never refused.
|
||||
pub fn parse_auth_persona(body: &[u8]) -> Option<i64> {
|
||||
let v: Value = serde_json::from_slice(body).ok()?;
|
||||
let field = |key: &str| {
|
||||
v.get(key).and_then(|x| {
|
||||
x.as_i64()
|
||||
.or_else(|| x.as_str().and_then(|s| s.parse::<i64>().ok()))
|
||||
})
|
||||
};
|
||||
field("nucleusPersonaId").or_else(|| field("nuc"))
|
||||
}
|
||||
|
||||
/// `POST /ut/auth` response body. `sid` is the freshly minted Rust session id;
|
||||
/// `server_time` is UTC `YYYY-MM-DD HH:MM:SS` (also used for `lastOnlineTime`).
|
||||
pub fn auth_body(sid: &str, server_time: &str) -> Value {
|
||||
json!({
|
||||
"protocol": 1,
|
||||
"sid": sid,
|
||||
"serverTime": server_time,
|
||||
"lastOnlineTime": server_time,
|
||||
})
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
const DEV: &str = "6236375476659cd0f6c780e728774b71"; // 32-hex (live deviceId)
|
||||
const ANS: &str = "0123456789abcdef0123456789abcdef";
|
||||
|
||||
#[test]
|
||||
fn static_bodies_match_oracle() {
|
||||
assert_eq!(accountinfo_body(), json!({}));
|
||||
assert_eq!(settings_body(), json!({ "configs": [] }));
|
||||
assert_eq!(leaderboard_options_body(), json!({}));
|
||||
assert_eq!(match_reset_body(), json!({}));
|
||||
assert_eq!(club_stats_staff_body(), json!({}));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn action_parse() {
|
||||
assert_eq!(
|
||||
parse_security_action("phishing/trusteddevice"),
|
||||
SecurityAction::TrustedDevice
|
||||
);
|
||||
assert_eq!(
|
||||
parse_security_action("phishing/question/"),
|
||||
SecurityAction::Question
|
||||
);
|
||||
assert_eq!(
|
||||
parse_security_action("phishing/validate"),
|
||||
SecurityAction::Validate
|
||||
);
|
||||
assert_eq!(
|
||||
parse_security_action("phishing/other"),
|
||||
SecurityAction::Unknown
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn trusted_device_verified_constant() {
|
||||
let (s, b) =
|
||||
security_question_response("GET", SecurityAction::TrustedDevice, true, DEV, None, None);
|
||||
assert_eq!(s, 200);
|
||||
assert_eq!(
|
||||
b,
|
||||
json!({ "changed": false, "exists": true, "locked": false, "trusted": true })
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn no_session_is_400_invalid_session() {
|
||||
let (s, b) = security_question_response(
|
||||
"GET",
|
||||
SecurityAction::TrustedDevice,
|
||||
false,
|
||||
DEV,
|
||||
None,
|
||||
None,
|
||||
);
|
||||
assert_eq!(s, 400);
|
||||
assert_eq!(b, json!({ "reason": "invalid_session" }));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn bad_device_id_is_malformed() {
|
||||
for bad in [
|
||||
"",
|
||||
"xyz",
|
||||
"6236375476659cd0f6c780e728774b7",
|
||||
"not-hex-not-hex-not-hex-not-hexx",
|
||||
] {
|
||||
let (s, b) = security_question_response(
|
||||
"GET",
|
||||
SecurityAction::TrustedDevice,
|
||||
true,
|
||||
bad,
|
||||
None,
|
||||
None,
|
||||
);
|
||||
assert_eq!(s, 400, "device {bad:?}");
|
||||
assert_eq!(b, json!({ "reason": "malformed_request" }));
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn trusted_device_wrong_method_405() {
|
||||
let (s, _) = security_question_response(
|
||||
"POST",
|
||||
SecurityAction::TrustedDevice,
|
||||
true,
|
||||
DEV,
|
||||
None,
|
||||
None,
|
||||
);
|
||||
assert_eq!(s, 405);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn question_get_returns_prompt() {
|
||||
let (s, b) =
|
||||
security_question_response("GET", SecurityAction::Question, true, DEV, None, None);
|
||||
assert_eq!(s, 200);
|
||||
assert_eq!(
|
||||
b,
|
||||
json!({ "question": 0, "attempts": 5, "recoverAttempts": 0 })
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn question_setup_validates_shape() {
|
||||
// valid numeric question + 32-hex answer
|
||||
let (s, b) = security_question_response(
|
||||
"POST",
|
||||
SecurityAction::Question,
|
||||
true,
|
||||
DEV,
|
||||
Some("0"),
|
||||
Some(ANS),
|
||||
);
|
||||
assert_eq!(s, 200);
|
||||
assert_eq!(b, json!({}));
|
||||
// empty question -> malformed
|
||||
let (s, _) = security_question_response(
|
||||
"POST",
|
||||
SecurityAction::Question,
|
||||
true,
|
||||
DEV,
|
||||
Some(""),
|
||||
Some(ANS),
|
||||
);
|
||||
assert_eq!(s, 400);
|
||||
// non-digit question -> malformed
|
||||
let (s, _) = security_question_response(
|
||||
"PUT",
|
||||
SecurityAction::Question,
|
||||
true,
|
||||
DEV,
|
||||
Some("x"),
|
||||
Some(ANS),
|
||||
);
|
||||
assert_eq!(s, 400);
|
||||
// bad answer -> malformed
|
||||
let (s, _) = security_question_response(
|
||||
"POST",
|
||||
SecurityAction::Question,
|
||||
true,
|
||||
DEV,
|
||||
Some("0"),
|
||||
Some("short"),
|
||||
);
|
||||
assert_eq!(s, 400);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn validate_checks_answer() {
|
||||
let (s, b) = security_question_response(
|
||||
"POST",
|
||||
SecurityAction::Validate,
|
||||
true,
|
||||
DEV,
|
||||
None,
|
||||
Some(ANS),
|
||||
);
|
||||
assert_eq!(s, 200);
|
||||
assert_eq!(b, json!({}));
|
||||
let (s, _) = security_question_response(
|
||||
"POST",
|
||||
SecurityAction::Validate,
|
||||
true,
|
||||
DEV,
|
||||
None,
|
||||
Some("nope"),
|
||||
);
|
||||
assert_eq!(s, 400);
|
||||
// wrong method for validate
|
||||
let (s, _) =
|
||||
security_question_response("GET", SecurityAction::Validate, true, DEV, None, Some(ANS));
|
||||
assert_eq!(s, 405);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn account_sync_defaults_and_core_economy() {
|
||||
// Empty body -> every default applied; persona falls back to the host's.
|
||||
let req = parse_account_sync(b"", 33_068_179);
|
||||
assert_eq!(req.persona_id, 33_068_179);
|
||||
assert_eq!(req.persona_name, "CAGE");
|
||||
assert_eq!(req.level, 1);
|
||||
assert_eq!(req.experience_max, 1000);
|
||||
assert_eq!(req.account_funds_cap, 100_000);
|
||||
let body = account_sync_body(&req, 29_859_876, 2, "Real FUT", "RF");
|
||||
let acc = &body["account"];
|
||||
assert_eq!(acc["clubName"], "Real FUT");
|
||||
assert_eq!(acc["clubAbbr"], "RF");
|
||||
assert_eq!(acc["profilePath"], "accounts/33068179/fifa17_profile.json");
|
||||
assert_eq!(acc["coins"], 29_859_876);
|
||||
assert_eq!(acc["unopenedPacks"], 2);
|
||||
assert_eq!(body["status"], "OK");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn account_sync_honours_request_overrides() {
|
||||
let req = parse_account_sync(
|
||||
br#"{"personaId":42,"personaName":"X","level":9,"accountFunds":500}"#,
|
||||
33_068_179,
|
||||
);
|
||||
assert_eq!(req.persona_id, 42);
|
||||
assert_eq!(req.persona_name, "X");
|
||||
assert_eq!(req.level, 9);
|
||||
assert_eq!(req.account_funds, 500);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn user_mass_info_flat_shape() {
|
||||
let squad = json!({
|
||||
"id": 0,
|
||||
"squadName": "OpenFUT",
|
||||
"formation": "f433",
|
||||
"squadType": "REGULAR_SQUAD",
|
||||
"rating": 90,
|
||||
"chemistry": 49,
|
||||
"actives": [],
|
||||
"players": [],
|
||||
});
|
||||
let body = user_mass_info_body(squad, 29_859_876, 0, 33_068_179, "Real FUT", "RF", "2016");
|
||||
// Flat top-level envelope.
|
||||
assert_eq!(body["pileSizeClientData"]["entries"][0], json!({"key": 2, "value": 100}));
|
||||
assert_eq!(body["pileSizeClientData"]["entries"][1], json!({"key": 4, "value": 50}));
|
||||
assert_eq!(body["settings"], json!({"configs": []}));
|
||||
assert_eq!(body["userData"], json!({}));
|
||||
// userInfo economy + club identity.
|
||||
let ui = &body["userInfo"];
|
||||
assert_eq!(ui["personaId"], 33_068_179);
|
||||
assert_eq!(ui["clubName"], "Real FUT");
|
||||
assert_eq!(ui["clubAbbr"], "RF");
|
||||
assert_eq!(ui["established"], "2016"); // string, not number
|
||||
assert_eq!(ui["accountCreatedPlatformName"], "pc");
|
||||
assert_eq!(ui["currencies"][0]["name"], "coins");
|
||||
assert_eq!(ui["currencies"][0]["funds"], 29_859_876);
|
||||
assert_eq!(ui["currencies"][0]["finalFunds"], 29_859_876);
|
||||
assert_eq!(ui["currencies"][1]["name"], "points");
|
||||
assert_eq!(ui["reliability"]["reliability"], 100);
|
||||
assert_eq!(ui["divisionOnline"], 10);
|
||||
assert!(ui.get("unopenedPacks").is_none(), "no packs -> key omitted");
|
||||
assert_eq!(ui["squadList"]["squad"][0]["squadName"], "OpenFUT");
|
||||
// Squad object embedded flat under top-level `squad`.
|
||||
assert_eq!(body["squad"]["squadName"], "OpenFUT");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn user_mass_info_includes_unopened_packs_when_present() {
|
||||
let squad = json!({"id": 0, "actives": [], "players": []});
|
||||
let body = user_mass_info_body(squad, 100, 3, 33_068_179, "OpenFUT", "OFC", "2026");
|
||||
assert_eq!(body["userInfo"]["unopenedPacks"]["recoveredPacks"], 3);
|
||||
assert_eq!(body["userInfo"]["unopenedPacks"]["preOrderPacks"], 0);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn utc_datetime_formats_known_epochs() {
|
||||
// 2026-08-17 03:54:47 UTC == 1_786_938_887.
|
||||
assert_eq!(format_utc_datetime(1_786_938_887), "2026-08-17 03:54:47");
|
||||
// Unix epoch.
|
||||
assert_eq!(format_utc_datetime(0), "1970-01-01 00:00:00");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn auth_persona_and_body() {
|
||||
assert_eq!(
|
||||
parse_auth_persona(br#"{"nucleusPersonaId":33068179}"#),
|
||||
Some(33_068_179)
|
||||
);
|
||||
assert_eq!(parse_auth_persona(br#"{"nuc":"42"}"#), Some(42));
|
||||
assert_eq!(parse_auth_persona(b"{}"), None);
|
||||
let b = auth_body("OPENFUT-SID-DEADBEEF", "2026-08-17 03:54:47");
|
||||
assert_eq!(b["protocol"], 1);
|
||||
assert_eq!(b["sid"], "OPENFUT-SID-DEADBEEF");
|
||||
assert_eq!(b["serverTime"], "2026-08-17 03:54:47");
|
||||
assert_eq!(b["lastOnlineTime"], "2026-08-17 03:54:47");
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,525 @@
|
||||
//! FIFA 17 "My Squad" owned-player search: parse the RS4 `club` query and map
|
||||
//! FIFA 17 wire encodings to the **game-independent** semantic values OpenFUT
|
||||
//! Core understands.
|
||||
//!
|
||||
//! ## The boundary this enforces
|
||||
//!
|
||||
//! The FIFA 17 client sends its owned-player search as query params on
|
||||
//! `GET /ut/game/fifa17/club`, e.g.
|
||||
//! `?year=2017&type=player&count=11&level=gold&position=ST&nation=52&league=13&team=5&sort=desc&start=10`.
|
||||
//! Two encoding families appear: **string enums** (`level`, `rare`, `position`)
|
||||
//! and **numeric FIFA entity ids** (`nation`, `league`, `team`).
|
||||
//!
|
||||
//! **Numeric FIFA ids must never reach Core.** Core filters on semantic names
|
||||
//! ("Premier League", "Chelsea", "Argentina"), so this adapter resolves each id
|
||||
//! to a name via an injected [`EntityResolver`]. An id the resolver cannot map is
|
||||
//! a hard [`MapError`] — never a silent passthrough of the raw number, which is
|
||||
//! exactly how a game-specific id would leak into the generic layer.
|
||||
//!
|
||||
//! ## Evidence-grounded semantics (see vault Protocol Findings / Endpoint Map)
|
||||
//!
|
||||
//! * `level=gold` → semantic quality tier. Grounded in FIFA 17's own convention
|
||||
//! (`fut_cards.py::tier`, gold ≥ 75). `level=any` (the always-present default)
|
||||
//! → no quality constraint.
|
||||
//! * `position` / `nation` / `league` / `team` → applied. The Python oracle
|
||||
//! applied only `league`+`team`; applying the rest is a deliberate correction
|
||||
//! of a proven bug, not a guess (each maps to a card attribute Core already
|
||||
//! stores). FIFA `team` is Core `club`.
|
||||
//! * `start` / `count` → semantic `offset` / `limit`. The oracle ignored both and
|
||||
//! re-served page one forever; Core paginates for real. The client's 11-count /
|
||||
//! 10-step windowing is a UI convention and stays out of Core.
|
||||
//! * `sort=desc` → **dropped**. No sort key was ever proven (the oracle does not
|
||||
//! sort); Core imposes its own deterministic order. We do not invent a named
|
||||
//! FIFA sort mode.
|
||||
//! * `rare=SP` ("Special") → **UNKNOWN and unsupported.** The oracle never reads
|
||||
//! it and no committed metadata grounds "SP" to a card set. It is recorded in
|
||||
//! [`CoreOwnedQuery::unsupported`] and deliberately produces **no** Core filter.
|
||||
//!
|
||||
//! ## Decoupling
|
||||
//!
|
||||
//! This module does not depend on `openfut-core`. The contract between the two is
|
||||
//! the set of Core `/collection` query-parameter *names* emitted by
|
||||
//! [`CoreOwnedQuery::to_query_pairs`]; they mirror Core's `OwnedItemQuery` fields
|
||||
//! and are pinned by a test so drift is caught.
|
||||
|
||||
use std::collections::HashMap;
|
||||
|
||||
/// The FIFA 17 club-search query exactly as it arrives on the wire. Numeric
|
||||
/// fields are FIFA entity ids that MUST be resolved before reaching Core.
|
||||
#[derive(Debug, Default, Clone, PartialEq, Eq)]
|
||||
pub struct Fifa17ClubQuery {
|
||||
/// Quality filter: `any` (default, always present) or `gold`.
|
||||
pub level: Option<String>,
|
||||
/// "Special" filter (`SP`). Semantics UNKNOWN — never applied.
|
||||
pub rare: Option<String>,
|
||||
/// Playing position, e.g. `ST`.
|
||||
pub position: Option<String>,
|
||||
/// FIFA nation id (e.g. 52 = Argentina).
|
||||
pub nation: Option<u32>,
|
||||
/// FIFA league id (e.g. 13 = Premier League).
|
||||
pub league: Option<u32>,
|
||||
/// FIFA team id (e.g. 5 = Chelsea). Core calls this "club".
|
||||
pub team: Option<u32>,
|
||||
/// Client sort token (`desc`). No proven key; dropped.
|
||||
pub sort: Option<String>,
|
||||
/// Pagination offset.
|
||||
pub start: Option<u32>,
|
||||
/// Pagination page size.
|
||||
pub count: Option<u32>,
|
||||
}
|
||||
|
||||
/// Minimal percent/`+` decoding, dependency-free. FIFA sends bare tokens and
|
||||
/// numeric ids, but names in general may be percent-encoded.
|
||||
fn percent_decode(s: &str) -> String {
|
||||
let b = s.as_bytes();
|
||||
let mut out = Vec::with_capacity(b.len());
|
||||
let hex = |c: u8| (c as char).to_digit(16);
|
||||
let mut i = 0;
|
||||
while i < b.len() {
|
||||
match b[i] {
|
||||
b'+' => {
|
||||
out.push(b' ');
|
||||
i += 1;
|
||||
}
|
||||
b'%' if i + 2 < b.len() => match (hex(b[i + 1]), hex(b[i + 2])) {
|
||||
(Some(hi), Some(lo)) => {
|
||||
out.push((hi * 16 + lo) as u8);
|
||||
i += 3;
|
||||
}
|
||||
_ => {
|
||||
out.push(b'%');
|
||||
i += 1;
|
||||
}
|
||||
},
|
||||
c => {
|
||||
out.push(c);
|
||||
i += 1;
|
||||
}
|
||||
}
|
||||
}
|
||||
String::from_utf8_lossy(&out).into_owned()
|
||||
}
|
||||
|
||||
/// Parse the raw query string into a [`Fifa17ClubQuery`].
|
||||
///
|
||||
/// Order-independent by construction (each key sets its own field), so HTTP
|
||||
/// parameter order can never change the result. Unknown keys (`year`, `type`, …)
|
||||
/// are ignored. A present-but-unparseable numeric id is treated as absent (the
|
||||
/// retail client never sends one; absent is the safe, non-amplifying choice).
|
||||
pub fn parse_club_query(query: &str) -> Fifa17ClubQuery {
|
||||
let q = query.strip_prefix('?').unwrap_or(query);
|
||||
let mut out = Fifa17ClubQuery::default();
|
||||
for pair in q.split('&').filter(|p| !p.is_empty()) {
|
||||
let (k, v) = match pair.split_once('=') {
|
||||
Some((k, v)) => (k, percent_decode(v)),
|
||||
None => (pair, String::new()),
|
||||
};
|
||||
match k {
|
||||
"level" => out.level = Some(v),
|
||||
"rare" => out.rare = Some(v),
|
||||
"position" => out.position = Some(v),
|
||||
"nation" => out.nation = v.parse().ok(),
|
||||
"league" => out.league = v.parse().ok(),
|
||||
"team" => out.team = v.parse().ok(),
|
||||
"sort" => out.sort = Some(v),
|
||||
"start" => out.start = v.parse().ok(),
|
||||
"count" => out.count = v.parse().ok(),
|
||||
_ => {}
|
||||
}
|
||||
}
|
||||
out
|
||||
}
|
||||
|
||||
/// Resolves FIFA 17 numeric entity ids to their semantic names. A real
|
||||
/// implementation reads the game's `leagues`/`teams`/`nations` tables; tests use
|
||||
/// [`StaticResolver`]. Returning `None` means "unknown id" and is fatal, by
|
||||
/// design — the raw id must not flow onward.
|
||||
pub trait EntityResolver {
|
||||
fn league_name(&self, id: u32) -> Option<String>;
|
||||
fn nation_name(&self, id: u32) -> Option<String>;
|
||||
fn team_name(&self, id: u32) -> Option<String>;
|
||||
}
|
||||
|
||||
/// A map-backed [`EntityResolver`] for tests and small deployments.
|
||||
#[derive(Debug, Default, Clone)]
|
||||
pub struct StaticResolver {
|
||||
pub leagues: HashMap<u32, String>,
|
||||
pub nations: HashMap<u32, String>,
|
||||
pub teams: HashMap<u32, String>,
|
||||
}
|
||||
|
||||
impl EntityResolver for StaticResolver {
|
||||
fn league_name(&self, id: u32) -> Option<String> {
|
||||
self.leagues.get(&id).cloned()
|
||||
}
|
||||
fn nation_name(&self, id: u32) -> Option<String> {
|
||||
self.nations.get(&id).cloned()
|
||||
}
|
||||
fn team_name(&self, id: u32) -> Option<String> {
|
||||
self.teams.get(&id).cloned()
|
||||
}
|
||||
}
|
||||
|
||||
/// A FIFA id that no resolver could map. Fatal on purpose: never fall back to
|
||||
/// the raw id.
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub enum MapError {
|
||||
UnknownLeague(u32),
|
||||
UnknownNation(u32),
|
||||
UnknownTeam(u32),
|
||||
}
|
||||
|
||||
impl std::fmt::Display for MapError {
|
||||
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
|
||||
match self {
|
||||
MapError::UnknownLeague(id) => write!(f, "unknown FIFA league id {id}"),
|
||||
MapError::UnknownNation(id) => write!(f, "unknown FIFA nation id {id}"),
|
||||
MapError::UnknownTeam(id) => write!(f, "unknown FIFA team id {id}"),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl std::error::Error for MapError {}
|
||||
|
||||
/// The semantic query handed to OpenFUT Core. Contains only game-independent
|
||||
/// values: a quality tier string, entity **names**, and semantic offset/limit.
|
||||
/// No FIFA ids.
|
||||
#[derive(Debug, Default, Clone, PartialEq, Eq)]
|
||||
pub struct CoreOwnedQuery {
|
||||
pub quality: Option<String>,
|
||||
pub position: Option<String>,
|
||||
pub nation: Option<String>,
|
||||
pub league: Option<String>,
|
||||
pub club: Option<String>,
|
||||
pub offset: Option<i64>,
|
||||
pub limit: Option<i64>,
|
||||
/// "Special" filter (`rare=SP`): keep only special cards. Applied by the
|
||||
/// HOST via the FIFA `rareflag` (which lives in the catalog, not Core) — so
|
||||
/// it is NEVER a Core `/collection` param. See [`is_special_rareflag`].
|
||||
pub special: bool,
|
||||
/// Wire filters that were parsed but deliberately NOT applied because their
|
||||
/// semantics are unproven (currently: `rare`/Special). Recorded, never guessed.
|
||||
pub unsupported: Vec<&'static str>,
|
||||
}
|
||||
|
||||
impl CoreOwnedQuery {
|
||||
/// Core `/collection` query parameters. Param **names mirror**
|
||||
/// `openfut_core::services::inventory::OwnedItemQuery` and are the wire
|
||||
/// contract between this adapter and Core (pinned by test). `unsupported`
|
||||
/// filters are intentionally absent.
|
||||
pub fn to_query_pairs(&self) -> Vec<(&'static str, String)> {
|
||||
let mut p = Vec::new();
|
||||
if let Some(q) = &self.quality {
|
||||
p.push(("quality", q.clone()));
|
||||
}
|
||||
if let Some(x) = &self.position {
|
||||
p.push(("position", x.clone()));
|
||||
}
|
||||
if let Some(x) = &self.nation {
|
||||
p.push(("nation", x.clone()));
|
||||
}
|
||||
if let Some(x) = &self.league {
|
||||
p.push(("league", x.clone()));
|
||||
}
|
||||
if let Some(x) = &self.club {
|
||||
p.push(("club", x.clone()));
|
||||
}
|
||||
if let Some(x) = self.offset {
|
||||
p.push(("offset", x.to_string()));
|
||||
}
|
||||
if let Some(x) = self.limit {
|
||||
p.push(("limit", x.to_string()));
|
||||
}
|
||||
p
|
||||
}
|
||||
}
|
||||
|
||||
/// Map a parsed FIFA 17 query to the semantic Core query, resolving every
|
||||
/// numeric id to a name. Any unknown id is a hard error — the raw id never flows
|
||||
/// through.
|
||||
pub fn map_to_core(
|
||||
q: &Fifa17ClubQuery,
|
||||
resolver: &impl EntityResolver,
|
||||
) -> Result<CoreOwnedQuery, MapError> {
|
||||
// level: only the proven quality tiers map; "any"/absent → no constraint.
|
||||
let quality = match q.level.as_deref() {
|
||||
Some("gold") => Some("gold".to_string()),
|
||||
Some("silver") => Some("silver".to_string()),
|
||||
Some("bronze") => Some("bronze".to_string()),
|
||||
_ => None,
|
||||
};
|
||||
|
||||
// rare=SP → "Special" quality. Now GROUNDED via the observed FIFA rareflag
|
||||
// (carried in the catalog): a special is rareflag > 1 (base rare = 1). The
|
||||
// host applies it post-shape; Core never sees it. Any OTHER `rare` value
|
||||
// stays genuinely unsupported (recorded, never guessed).
|
||||
let special = matches!(q.rare.as_deref(), Some(s) if s.eq_ignore_ascii_case("SP"));
|
||||
let mut unsupported = Vec::new();
|
||||
if q.rare.is_some() && !special {
|
||||
unsupported.push("rare");
|
||||
}
|
||||
|
||||
let position = q.position.as_ref().map(|p| p.to_uppercase());
|
||||
|
||||
let nation = match q.nation {
|
||||
Some(id) => Some(
|
||||
resolver
|
||||
.nation_name(id)
|
||||
.ok_or(MapError::UnknownNation(id))?,
|
||||
),
|
||||
None => None,
|
||||
};
|
||||
let league = match q.league {
|
||||
Some(id) => Some(
|
||||
resolver
|
||||
.league_name(id)
|
||||
.ok_or(MapError::UnknownLeague(id))?,
|
||||
),
|
||||
None => None,
|
||||
};
|
||||
// FIFA "team" is Core "club".
|
||||
let club = match q.team {
|
||||
Some(id) => Some(resolver.team_name(id).ok_or(MapError::UnknownTeam(id))?),
|
||||
None => None,
|
||||
};
|
||||
|
||||
Ok(CoreOwnedQuery {
|
||||
quality,
|
||||
position,
|
||||
nation,
|
||||
league,
|
||||
club,
|
||||
offset: q.start.map(|s| s as i64),
|
||||
limit: q.count.map(|c| c as i64),
|
||||
special,
|
||||
unsupported,
|
||||
})
|
||||
}
|
||||
|
||||
/// Whether a FIFA `rareflag` denotes a SPECIAL card (in-form/programme), as
|
||||
/// opposed to a base card. Grounded in the observed profile + the FIFA 17
|
||||
/// taxonomy: 0 = common, 1 = rare (both BASE gold/silver/bronze); every value
|
||||
/// above 1 is a special programme (3 = TOTW, 21..=24 = programmes, etc.).
|
||||
pub fn is_special_rareflag(rareflag: i64) -> bool {
|
||||
rareflag > 1
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
fn resolver() -> StaticResolver {
|
||||
// Confirmed against fifa17-recon/data/tables/{leagues,teams,nations}.json.
|
||||
StaticResolver {
|
||||
leagues: HashMap::from([(13, "Premier League".to_string())]),
|
||||
nations: HashMap::from([(52, "Argentina".to_string())]),
|
||||
teams: HashMap::from([(5, "Chelsea".to_string())]),
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn parse_full_query() {
|
||||
let q = parse_club_query(
|
||||
"year=2017&type=player&count=11&level=gold&position=ST&nation=52&league=13&team=5&sort=desc&start=10",
|
||||
);
|
||||
assert_eq!(
|
||||
q,
|
||||
Fifa17ClubQuery {
|
||||
level: Some("gold".into()),
|
||||
rare: None,
|
||||
position: Some("ST".into()),
|
||||
nation: Some(52),
|
||||
league: Some(13),
|
||||
team: Some(5),
|
||||
sort: Some("desc".into()),
|
||||
start: Some(10),
|
||||
count: Some(11),
|
||||
}
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn parse_is_parameter_order_independent() {
|
||||
let a = parse_club_query("level=gold&league=13&position=ST&start=10&count=11");
|
||||
let b = parse_club_query("count=11&start=10&position=ST&league=13&level=gold");
|
||||
assert_eq!(a, b);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn parse_ignores_unknown_keys_and_omitted_optionals() {
|
||||
let q = parse_club_query("year=2017&type=player&level=any&sort=desc");
|
||||
assert_eq!(q.level.as_deref(), Some("any"));
|
||||
assert!(q.rare.is_none() && q.position.is_none() && q.nation.is_none());
|
||||
assert!(q.league.is_none() && q.team.is_none() && q.start.is_none());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn parse_percent_encoded_value() {
|
||||
let q = parse_club_query("position=ST&rare=SP");
|
||||
assert_eq!(q.position.as_deref(), Some("ST"));
|
||||
assert_eq!(q.rare.as_deref(), Some("SP"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn parse_malformed_numeric_is_absent() {
|
||||
let q = parse_club_query("league=notanumber");
|
||||
assert!(
|
||||
q.league.is_none(),
|
||||
"malformed id treated as absent, not applied"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn map_level_gold_to_quality() {
|
||||
let core = map_to_core(&parse_club_query("level=gold"), &resolver()).unwrap();
|
||||
assert_eq!(core.quality.as_deref(), Some("gold"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn map_level_any_has_no_quality_filter() {
|
||||
let core = map_to_core(&parse_club_query("level=any"), &resolver()).unwrap();
|
||||
assert_eq!(core.quality, None, "'any' must NOT become a quality filter");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn map_rare_sp_sets_special_and_never_a_core_param() {
|
||||
let core = map_to_core(&parse_club_query("level=any&rare=SP"), &resolver()).unwrap();
|
||||
// rare=SP is now GROUNDED: a host-applied special flag, not "unsupported".
|
||||
assert!(core.special, "rare=SP must set the special flag");
|
||||
assert!(!core.unsupported.contains(&"rare"));
|
||||
// still NEVER a Core predicate (Core has no rareflag) and no quality guess.
|
||||
assert_eq!(core.quality, None);
|
||||
let keys: Vec<&str> = core.to_query_pairs().into_iter().map(|(k, _)| k).collect();
|
||||
assert!(!keys.contains(&"rare") && !keys.contains(&"special"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn map_unknown_rare_value_stays_unsupported() {
|
||||
let core = map_to_core(&parse_club_query("rare=WAT"), &resolver()).unwrap();
|
||||
assert!(!core.special);
|
||||
assert!(core.unsupported.contains(&"rare"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn special_predicate_base_vs_special() {
|
||||
assert!(!is_special_rareflag(0)); // common
|
||||
assert!(!is_special_rareflag(1)); // rare gold (base)
|
||||
assert!(is_special_rareflag(3)); // TOTW
|
||||
assert!(is_special_rareflag(24)); // programme
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn map_resolves_ids_to_semantic_names() {
|
||||
let core =
|
||||
map_to_core(&parse_club_query("nation=52&league=13&team=5"), &resolver()).unwrap();
|
||||
assert_eq!(core.nation.as_deref(), Some("Argentina"));
|
||||
assert_eq!(core.league.as_deref(), Some("Premier League"));
|
||||
assert_eq!(
|
||||
core.club.as_deref(),
|
||||
Some("Chelsea"),
|
||||
"FIFA team -> Core club"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn map_unknown_id_is_a_hard_error_not_passthrough() {
|
||||
assert_eq!(
|
||||
map_to_core(&parse_club_query("league=9999"), &resolver()),
|
||||
Err(MapError::UnknownLeague(9999))
|
||||
);
|
||||
assert_eq!(
|
||||
map_to_core(&parse_club_query("nation=9999"), &resolver()),
|
||||
Err(MapError::UnknownNation(9999))
|
||||
);
|
||||
assert_eq!(
|
||||
map_to_core(&parse_club_query("team=9999"), &resolver()),
|
||||
Err(MapError::UnknownTeam(9999))
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn no_raw_fifa_id_ever_reaches_core() {
|
||||
// Every resolvable id becomes a name; a numeric string must never appear
|
||||
// as a nation/league/club value in the Core-bound pairs.
|
||||
let core =
|
||||
map_to_core(&parse_club_query("nation=52&league=13&team=5"), &resolver()).unwrap();
|
||||
for (k, v) in core.to_query_pairs() {
|
||||
if matches!(k, "nation" | "league" | "club") {
|
||||
assert!(
|
||||
v.parse::<u32>().is_err(),
|
||||
"{k}={v} looks like a raw FIFA id leaking into Core"
|
||||
);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn map_start_count_to_offset_limit() {
|
||||
let core = map_to_core(&parse_club_query("start=20&count=11"), &resolver()).unwrap();
|
||||
assert_eq!(core.offset, Some(20));
|
||||
assert_eq!(core.limit, Some(11));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn map_position_uppercased() {
|
||||
let core = map_to_core(&parse_club_query("position=st"), &resolver()).unwrap();
|
||||
assert_eq!(core.position.as_deref(), Some("ST"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn sort_is_dropped_no_core_param() {
|
||||
let core = map_to_core(&parse_club_query("sort=desc"), &resolver()).unwrap();
|
||||
let keys: Vec<&str> = core.to_query_pairs().into_iter().map(|(k, _)| k).collect();
|
||||
assert!(
|
||||
!keys.contains(&"sort"),
|
||||
"no proven FIFA sort key; must not emit one"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn core_query_param_names_mirror_core_contract() {
|
||||
// Pins the wire contract with openfut-core's OwnedItemQuery field names.
|
||||
let core = CoreOwnedQuery {
|
||||
quality: Some("gold".into()),
|
||||
position: Some("ST".into()),
|
||||
nation: Some("Argentina".into()),
|
||||
league: Some("Premier League".into()),
|
||||
club: Some("Chelsea".into()),
|
||||
offset: Some(10),
|
||||
limit: Some(11),
|
||||
special: false,
|
||||
unsupported: vec![],
|
||||
};
|
||||
let keys: Vec<&str> = core.to_query_pairs().into_iter().map(|(k, _)| k).collect();
|
||||
assert_eq!(
|
||||
keys,
|
||||
["quality", "position", "nation", "league", "club", "offset", "limit"]
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn end_to_end_capture_shaped_query() {
|
||||
// Mirrors the retail PAGINATION capture: PL + Chelsea, page 2.
|
||||
let core = map_to_core(
|
||||
&parse_club_query(
|
||||
"year=2017&type=player&count=11&level=gold&nation=52&league=13&team=5&sort=desc&start=10",
|
||||
),
|
||||
&resolver(),
|
||||
)
|
||||
.unwrap();
|
||||
assert_eq!(
|
||||
core,
|
||||
CoreOwnedQuery {
|
||||
quality: Some("gold".into()),
|
||||
position: None,
|
||||
nation: Some("Argentina".into()),
|
||||
league: Some("Premier League".into()),
|
||||
club: Some("Chelsea".into()),
|
||||
offset: Some(10),
|
||||
limit: Some(11),
|
||||
special: false,
|
||||
unsupported: vec![],
|
||||
}
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,254 @@
|
||||
//! FIFA 17 Store pack-content generator (pure, seeded).
|
||||
//!
|
||||
//! Draws the cards a Store pack awards. It is a **pure function** of
|
||||
//! `(pack definition, RNG, candidate pool)` — no IO, no Core, no catalogue
|
||||
//! lookup — so it is deterministic under a seeded [`rand::Rng`] and trivially
|
||||
//! unit-tested. The host owns the impure parts: it builds the candidate pool
|
||||
//! (only card ids that resolve in BOTH the FIFA catalogue and Core content),
|
||||
//! mints the drawn cards into Core, and shapes them onto the wire.
|
||||
//!
|
||||
//! ## Parity note — Python `open_pack` / `_pack_body`
|
||||
//! (`fifa17-recon/tools/fut_store.py:689`, `utas_server.py:3474`)
|
||||
//! 1. `open_pack(price, count, gold, tiers, special_chance)` deducts coins then
|
||||
//! draws `count` items (mostly players); the reveal body wraps them verbatim.
|
||||
//! 2. Non-tiered draws split the pool at rating 75 by `gold` (`p[1] >= 75 == gold`)
|
||||
//! and fall back to the whole pool when that tier is empty (`... or PACK_POOL`).
|
||||
//! 3. Each drawn player becomes a special with probability `special_chance`
|
||||
//! (`random.random() < special_chance`).
|
||||
//! 4. `FUT_PACK_MIX` swaps ~`count // 4` players for consumables/staff extras;
|
||||
//! we deliberately OMIT that mix (Core candidates are player defs — players-only).
|
||||
//! 5. Prices/counts/odds are the OpenFUT **PLACEHOLDER** economy (the audit found
|
||||
//! them invented); only the wire *shape* is EA-observed/oracle-verified.
|
||||
//! 6. This port reproduces the count + gold-tier split + `special_chance` gate as
|
||||
//! that same PLACEHOLDER policy, drawing with replacement from the pool.
|
||||
|
||||
use rand::Rng;
|
||||
|
||||
use crate::fut::store_catalog::PackDef;
|
||||
|
||||
/// A candidate the host has already verified resolves in BOTH the FIFA catalogue
|
||||
/// and Core content. Carries the full Core definition the shaper needs plus the
|
||||
/// two draw-policy annotations (`gold` tier, `special` version) the host derives
|
||||
/// from the catalogue (keeping this generator pure — it never reads a catalogue).
|
||||
#[derive(Debug, Clone)]
|
||||
pub struct GeneratedCandidate {
|
||||
/// Core card-definition id (resolves in the FIFA catalogue and Core content).
|
||||
pub card_id: String,
|
||||
pub rating: u8,
|
||||
pub position: String,
|
||||
pub nation: String,
|
||||
pub league: String,
|
||||
pub club: String,
|
||||
/// [pace, shooting, passing, dribbling, defending, physical].
|
||||
pub attributes: [u8; 6],
|
||||
/// Gold tier (host derives this as `rating >= 75`, the oracle's split point).
|
||||
pub gold: bool,
|
||||
/// Special version available (host derives this from the catalogue rareflag
|
||||
/// `> 1`); gated by [`PackDef::special_chance`].
|
||||
pub special: bool,
|
||||
}
|
||||
|
||||
impl GeneratedCandidate {
|
||||
fn to_card(&self) -> GeneratedCard {
|
||||
GeneratedCard {
|
||||
card_id: self.card_id.clone(),
|
||||
rating: self.rating,
|
||||
position: self.position.clone(),
|
||||
nation: self.nation.clone(),
|
||||
league: self.league.clone(),
|
||||
club: self.club.clone(),
|
||||
attributes: self.attributes,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// One card a pack awarded. Carries `card_id` (the Core definition the host mints
|
||||
/// and shapes) plus the definition fields the shared item shaper needs. It is
|
||||
/// NOT an owned instance yet — the host mints the Core instance id and allocates
|
||||
/// the numeric wire id.
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub struct GeneratedCard {
|
||||
pub card_id: String,
|
||||
pub rating: u8,
|
||||
pub position: String,
|
||||
pub nation: String,
|
||||
pub league: String,
|
||||
pub club: String,
|
||||
pub attributes: [u8; 6],
|
||||
}
|
||||
|
||||
/// Draw `pack.count` cards from `pool` with the injected RNG. Pure and
|
||||
/// deterministic under a seeded RNG. Returns an empty `Vec` (fail-closed) when
|
||||
/// the pool is empty or the pack awards no cards.
|
||||
///
|
||||
/// Policy (PLACEHOLDER — see the module parity note): draw with replacement from
|
||||
/// the pack's tier (`gold`), biasing each draw toward a special card with
|
||||
/// probability `special_chance`. An empty tier or partition falls back to the
|
||||
/// next-wider set so a draw is always possible when the pool is non-empty.
|
||||
pub fn generate_pack_contents(
|
||||
pack: &PackDef,
|
||||
rng: &mut impl Rng,
|
||||
pool: &[GeneratedCandidate],
|
||||
) -> Vec<GeneratedCard> {
|
||||
if pool.is_empty() || pack.count == 0 {
|
||||
return Vec::new();
|
||||
}
|
||||
// Tier split: a gold pack draws gold-tier candidates, a non-gold pack draws
|
||||
// non-gold; an empty tier falls back to the whole pool (oracle `... or POOL`).
|
||||
let tier: Vec<&GeneratedCandidate> = pool.iter().filter(|c| c.gold == pack.gold).collect();
|
||||
let tier: Vec<&GeneratedCandidate> = if tier.is_empty() {
|
||||
pool.iter().collect()
|
||||
} else {
|
||||
tier
|
||||
};
|
||||
// Partition the tier by special so `special_chance` can bias a draw; either
|
||||
// partition falls back to the whole tier when empty.
|
||||
let special: Vec<&GeneratedCandidate> = tier.iter().copied().filter(|c| c.special).collect();
|
||||
let normal: Vec<&GeneratedCandidate> = tier.iter().copied().filter(|c| !c.special).collect();
|
||||
let chance = pack.special_chance.clamp(0.0, 1.0);
|
||||
|
||||
let mut out = Vec::with_capacity(pack.count as usize);
|
||||
for _ in 0..pack.count {
|
||||
let want_special = chance > 0.0 && rng.gen_bool(chance);
|
||||
let sub: &[&GeneratedCandidate] = if want_special && !special.is_empty() {
|
||||
&special
|
||||
} else if !want_special && !normal.is_empty() {
|
||||
&normal
|
||||
} else {
|
||||
&tier
|
||||
};
|
||||
let pick = sub[rng.gen_range(0..sub.len())];
|
||||
out.push(pick.to_card());
|
||||
}
|
||||
out
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
use rand::rngs::StdRng;
|
||||
use rand::SeedableRng;
|
||||
|
||||
fn cand(card: &str, rating: u8, gold: bool, special: bool) -> GeneratedCandidate {
|
||||
GeneratedCandidate {
|
||||
card_id: card.into(),
|
||||
rating,
|
||||
position: "ST".into(),
|
||||
nation: "Brazil".into(),
|
||||
league: "Premier League".into(),
|
||||
club: "Arsenal".into(),
|
||||
attributes: [rating; 6],
|
||||
gold,
|
||||
special,
|
||||
}
|
||||
}
|
||||
|
||||
/// A mixed pool: gold specials, gold normals, and a bronze tier.
|
||||
fn pool() -> Vec<GeneratedCandidate> {
|
||||
vec![
|
||||
cand("g-sp-1", 90, true, true),
|
||||
cand("g-sp-2", 88, true, true),
|
||||
cand("g-1", 84, true, false),
|
||||
cand("g-2", 82, true, false),
|
||||
cand("g-3", 79, true, false),
|
||||
cand("b-1", 64, false, false),
|
||||
cand("b-2", 62, false, false),
|
||||
]
|
||||
}
|
||||
|
||||
fn pack(id: u64, count: u64, gold: bool, special_chance: f64) -> PackDef {
|
||||
PackDef {
|
||||
id,
|
||||
name: "Test Pack",
|
||||
price: 1000,
|
||||
count,
|
||||
gold,
|
||||
special_chance,
|
||||
owned_only: false,
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn same_seed_same_output() {
|
||||
let pool = pool();
|
||||
let p = pack(5, 7, true, 0.3);
|
||||
let mut a = StdRng::seed_from_u64(42);
|
||||
let mut b = StdRng::seed_from_u64(42);
|
||||
assert_eq!(
|
||||
generate_pack_contents(&p, &mut a, &pool),
|
||||
generate_pack_contents(&p, &mut b, &pool)
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn different_seeds_can_diverge() {
|
||||
let pool = pool();
|
||||
let p = pack(5, 7, true, 0.3);
|
||||
let a = generate_pack_contents(&p, &mut StdRng::seed_from_u64(1), &pool);
|
||||
let b = generate_pack_contents(&p, &mut StdRng::seed_from_u64(999), &pool);
|
||||
// Not a hard guarantee, but with this pool/count the two seeds differ.
|
||||
assert_ne!(a, b);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn count_is_exact_and_all_cards_from_pool() {
|
||||
let pool = pool();
|
||||
let ids: std::collections::HashSet<&str> =
|
||||
pool.iter().map(|c| c.card_id.as_str()).collect();
|
||||
for &n in &[1u64, 5, 7, 11] {
|
||||
let p = pack(6, n, true, 0.08);
|
||||
let cards = generate_pack_contents(&p, &mut StdRng::seed_from_u64(n), &pool);
|
||||
assert_eq!(cards.len() as u64, n);
|
||||
for c in &cards {
|
||||
assert!(
|
||||
ids.contains(c.card_id.as_str()),
|
||||
"drew unknown card {}",
|
||||
c.card_id
|
||||
);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn gold_pack_draws_only_gold_tier() {
|
||||
let pool = pool();
|
||||
let p = pack(5, 20, true, 0.03);
|
||||
let cards = generate_pack_contents(&p, &mut StdRng::seed_from_u64(7), &pool);
|
||||
assert!(
|
||||
cards.iter().all(|c| c.rating >= 75),
|
||||
"gold pack drew a bronze card"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn bronze_pack_draws_only_bronze_tier() {
|
||||
let pool = pool();
|
||||
let p = pack(1, 20, false, 0.005);
|
||||
let cards = generate_pack_contents(&p, &mut StdRng::seed_from_u64(7), &pool);
|
||||
assert!(
|
||||
cards.iter().all(|c| c.rating < 75),
|
||||
"bronze pack drew a gold card"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn special_chance_one_draws_only_specials() {
|
||||
let pool = pool();
|
||||
let special_ids: std::collections::HashSet<&str> = pool
|
||||
.iter()
|
||||
.filter(|c| c.special)
|
||||
.map(|c| c.card_id.as_str())
|
||||
.collect();
|
||||
let p = pack(7, 11, true, 1.0);
|
||||
let cards = generate_pack_contents(&p, &mut StdRng::seed_from_u64(3), &pool);
|
||||
assert!(cards
|
||||
.iter()
|
||||
.all(|c| special_ids.contains(c.card_id.as_str())));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn empty_pool_fails_closed() {
|
||||
let p = pack(5, 7, true, 0.03);
|
||||
assert!(generate_pack_contents(&p, &mut StdRng::seed_from_u64(1), &[]).is_empty());
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,346 @@
|
||||
//! FIFA 17 squad **full-replacement** wire (`PUT /ut/game/fifa17/squad/<id>`) →
|
||||
//! a game-independent proposed replacement OpenFUT Core can apply.
|
||||
//!
|
||||
//! ## Scope (deliberately preparatory — nothing is routed yet)
|
||||
//!
|
||||
//! This module parses the captured squad-save wire and reverse-maps each slot's
|
||||
//! FIFA wire item id to a Core owned-instance id, producing a [`ProposedSquad`].
|
||||
//! It does **not** open a socket, call Core, or mutate state — squad is a
|
||||
//! *stateful* slice and its GET (retrieval) and PUT (save) must migrate together
|
||||
//! as one authority, which needs more captured evidence first. Until then this is
|
||||
//! pure, unit-tested scaffolding.
|
||||
//!
|
||||
//! ## What the wire proves (2 captured retail saves, `fixtures/utas/`)
|
||||
//!
|
||||
//! * The client sends the **whole** squad on every save — a fixed 23-slot array
|
||||
//! plus `formation`, `captain`, `kicktakers`, a 33-int `custom` string, and
|
||||
//! client-reported `chemistry`/`rating`/`starRating`. A two-player edit changed
|
||||
//! nine slots, so slot deltas never describe intent: the only honest operation
|
||||
//! is *this is the squad now*.
|
||||
//! * Each occupied slot carries its FIFA **wire item id** (`itemData.id`, the same
|
||||
//! namespace as `/club` and the identity store); an **empty** slot is `id == 0`.
|
||||
//! * `captain` and `kicktakers` reference the same wire item id space.
|
||||
//!
|
||||
//! ## What it does NOT prove (kept UNKNOWN, never invented)
|
||||
//!
|
||||
//! * The `index → (slot, bench)` layout for formations other than **f442**, and
|
||||
//! the meaning/stability of the `custom` 33-int array. `custom` is preserved
|
||||
//! **opaquely** so it can round-trip unchanged; its integers are not decoded.
|
||||
//! * FIFA's chemistry/rating algorithm — client-reported values are carried in
|
||||
//! [`ClientReportedSquadEval`] and never reconciled with Core's own evaluation.
|
||||
|
||||
use serde::{Deserialize, Serialize};
|
||||
|
||||
/// A `{ "id": <wire item id>, "dream": bool }` reference (player, manager, …).
|
||||
#[derive(Debug, Clone, Deserialize)]
|
||||
#[serde(rename_all = "camelCase")]
|
||||
pub struct SquadEntityRef {
|
||||
pub id: i64,
|
||||
#[serde(default)]
|
||||
pub dream: bool,
|
||||
}
|
||||
|
||||
/// One entry of the fixed-length `players` array.
|
||||
#[derive(Debug, Clone, Deserialize)]
|
||||
#[serde(rename_all = "camelCase")]
|
||||
pub struct SquadSlotWire {
|
||||
pub index: i64,
|
||||
pub item_data: SquadEntityRef,
|
||||
#[serde(default)]
|
||||
pub kit_number: i64,
|
||||
}
|
||||
|
||||
/// A `kicktakers` entry (penalty/corner/free-kick roles). Carries a wire item id;
|
||||
/// role semantics are UNKNOWN and not modelled.
|
||||
#[derive(Debug, Clone, Deserialize)]
|
||||
#[serde(rename_all = "camelCase")]
|
||||
pub struct SquadKicktaker {
|
||||
pub index: i64,
|
||||
pub id: i64,
|
||||
#[serde(default)]
|
||||
pub dream: bool,
|
||||
}
|
||||
|
||||
/// The squad-save body exactly as FIFA 17 sends it. FIFA-only fields
|
||||
/// (`custom`, `kicktakers`, `kit_number`, `manager`, `squad_type`) are captured
|
||||
/// verbatim; their persistence/reconstruction rules await more evidence.
|
||||
#[derive(Debug, Clone, Deserialize)]
|
||||
#[serde(rename_all = "camelCase")]
|
||||
pub struct Fifa17SquadPut {
|
||||
/// Squad id (the path `…/squad/0` and the body agree; `0` = active).
|
||||
#[serde(default)]
|
||||
pub id: i64,
|
||||
#[serde(default)]
|
||||
pub squad_name: Option<String>,
|
||||
#[serde(default)]
|
||||
pub formation: Option<String>,
|
||||
#[serde(default)]
|
||||
pub squad_type: Option<String>,
|
||||
#[serde(default)]
|
||||
pub chemistry: Option<i64>,
|
||||
#[serde(default)]
|
||||
pub rating: Option<i64>,
|
||||
#[serde(default)]
|
||||
pub star_rating: Option<i64>,
|
||||
/// Wire item id of the captain (must be one of the occupied slots).
|
||||
#[serde(default)]
|
||||
pub captain: Option<i64>,
|
||||
/// Opaque 33-int array as a JSON-encoded string. Semantics UNKNOWN — carried
|
||||
/// verbatim, never parsed or interpreted.
|
||||
#[serde(default)]
|
||||
pub custom: Option<String>,
|
||||
#[serde(default)]
|
||||
pub manager: Vec<SquadEntityRef>,
|
||||
#[serde(default)]
|
||||
pub players: Vec<SquadSlotWire>,
|
||||
#[serde(default)]
|
||||
pub kicktakers: Vec<SquadKicktaker>,
|
||||
}
|
||||
|
||||
/// Reverse-maps a FIFA wire item id to a Core owned-instance id. Implemented by
|
||||
/// the host over `Fifa17IdentityResolver`; `None` = unknown id (never guessed).
|
||||
pub trait SquadWireResolver {
|
||||
fn owned_id_for_wire(&self, wire: i64) -> Option<String>;
|
||||
}
|
||||
|
||||
/// Client-reported squad evaluation. Kept DISTINCT from Core's authoritative
|
||||
/// evaluation and never reconciled — FIFA's chemistry/rating algorithm is UNKNOWN.
|
||||
#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
|
||||
pub struct ClientReportedSquadEval {
|
||||
pub chemistry: Option<i64>,
|
||||
pub rating: Option<i64>,
|
||||
pub star_rating: Option<i64>,
|
||||
}
|
||||
|
||||
/// One resolved slot of a proposed replacement (game-independent).
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub struct ProposedSlot {
|
||||
pub owned_card_id: String,
|
||||
/// FIFA player-array index (0-based). Core imposes its own slot numbering;
|
||||
/// the adapter carries the index plus a bench flag from the f442 convention.
|
||||
pub index: i64,
|
||||
pub kit_number: i64,
|
||||
pub is_captain: bool,
|
||||
pub is_on_bench: bool,
|
||||
}
|
||||
|
||||
/// A full-squad replacement in **canonical** (game-independent) terms, ready for
|
||||
/// the host to map onto Core's `SquadReplacement`/`SaveSquadRequest`. Carries no
|
||||
/// FIFA-only state (that is [`crate::fut::squad_ext::Fifa17SquadExtensionV1`])
|
||||
/// and no `openfut-core` dependency. No FIFA wire integer survives into a slot —
|
||||
/// every player is a Core `owned_card_id`.
|
||||
#[derive(Debug, Clone)]
|
||||
pub struct ProposedSquad {
|
||||
/// The FIFA wire squad id the PUT targeted (`0` = the active squad). Routing
|
||||
/// only — it selects which Core squad to replace; it is never a Core field.
|
||||
pub squad_id: i64,
|
||||
pub name: Option<String>,
|
||||
/// The FIFA formation token exactly as sent (e.g. `"f442"`, `"f433"`). Core
|
||||
/// stores it verbatim as its opaque formation token and never interprets it,
|
||||
/// so it round-trips exactly — never mapped to a second representation and
|
||||
/// never used to derive slot layout.
|
||||
pub formation: Option<String>,
|
||||
pub slots: Vec<ProposedSlot>,
|
||||
/// Occupied wire item ids the resolver could not map. A caller MUST refuse the
|
||||
/// replacement if this is non-empty — a save must never silently drop an
|
||||
/// owned player it failed to identify.
|
||||
pub unresolved_wire_ids: Vec<i64>,
|
||||
}
|
||||
|
||||
/// Parse errors — explicit, never a silent empty squad.
|
||||
#[derive(Debug, PartialEq, Eq)]
|
||||
pub enum SquadError {
|
||||
Parse(String),
|
||||
}
|
||||
|
||||
impl std::fmt::Display for SquadError {
|
||||
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
|
||||
match self {
|
||||
SquadError::Parse(e) => write!(f, "squad wire parse error: {e}"),
|
||||
}
|
||||
}
|
||||
}
|
||||
impl std::error::Error for SquadError {}
|
||||
|
||||
/// The FIFA 17 squad wire is a fixed 23-slot array: indices `0..=10` are the
|
||||
/// pitch (the 11 starters), `11..=22` are bench/reserves. This layout is a
|
||||
/// property of the array, not of the formation — the captured f442 and f433
|
||||
/// saves both place their 11 starters at `0..=10`. Bench membership is therefore
|
||||
/// derived from the index alone, NEVER from the formation token.
|
||||
pub const FIFA17_STARTER_SLOTS: i64 = 11;
|
||||
|
||||
/// Length of the fixed FIFA 17 squad slot array (evidence: every captured save
|
||||
/// and read carries exactly 23 slots).
|
||||
pub const FIFA17_SQUAD_SLOTS: i64 = 23;
|
||||
|
||||
/// Parse a squad-save body into the typed wire form. Structural only.
|
||||
pub fn parse_squad_put(body: &[u8]) -> Result<Fifa17SquadPut, SquadError> {
|
||||
serde_json::from_slice(body).map_err(|e| SquadError::Parse(e.to_string()))
|
||||
}
|
||||
|
||||
/// Resolve a parsed save into a **canonical** [`ProposedSquad`]: drop empty
|
||||
/// (`id == 0`) slots, reverse-map each occupied slot's wire id to a Core
|
||||
/// `owned_card_id`, flag the captain, and derive the bench split from the fixed
|
||||
/// 23-slot array. FIFA-only state (`custom`, manager, kicktakers, kit numbers,
|
||||
/// squadType) and client-reported evaluation are NOT canonical — they are built
|
||||
/// separately into [`crate::fut::squad_ext::Fifa17SquadExtensionV1`]. The
|
||||
/// formation token is carried verbatim (never mapped). Unresolvable occupied ids
|
||||
/// are reported, never guessed or dropped.
|
||||
pub fn to_proposed(put: &Fifa17SquadPut, resolver: &dyn SquadWireResolver) -> ProposedSquad {
|
||||
let captain = put.captain.unwrap_or(0);
|
||||
let mut slots = Vec::new();
|
||||
let mut unresolved = Vec::new();
|
||||
for p in &put.players {
|
||||
if p.item_data.id == 0 {
|
||||
continue; // empty slot — never a Core player
|
||||
}
|
||||
match resolver.owned_id_for_wire(p.item_data.id) {
|
||||
Some(owned_card_id) => slots.push(ProposedSlot {
|
||||
owned_card_id,
|
||||
index: p.index,
|
||||
kit_number: p.kit_number,
|
||||
is_captain: captain != 0 && p.item_data.id == captain,
|
||||
is_on_bench: p.index >= FIFA17_STARTER_SLOTS,
|
||||
}),
|
||||
None => unresolved.push(p.item_data.id),
|
||||
}
|
||||
}
|
||||
ProposedSquad {
|
||||
squad_id: put.id,
|
||||
name: put.squad_name.clone(),
|
||||
formation: put.formation.clone(),
|
||||
slots,
|
||||
unresolved_wire_ids: unresolved,
|
||||
}
|
||||
}
|
||||
|
||||
/// The save acknowledgement FIFA expects: just the squad id (matches the oracle's
|
||||
/// `{"id": <n>}`, 9 bytes — it does NOT echo the squad).
|
||||
pub fn save_ack(squad_id: i64) -> serde_json::Value {
|
||||
serde_json::json!({ "id": squad_id })
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
use std::collections::HashMap;
|
||||
|
||||
/// The real captured f442 save body (decoded from `session-001.jsonl:21`).
|
||||
const PUT_F442: &str = include_str!("../../fixtures/utas/squad_put_f442.json");
|
||||
|
||||
/// A resolver mapping every occupied wire id in the fixture to a Core id.
|
||||
struct MapResolver(HashMap<i64, String>);
|
||||
impl SquadWireResolver for MapResolver {
|
||||
fn owned_id_for_wire(&self, wire: i64) -> Option<String> {
|
||||
self.0.get(&wire).cloned()
|
||||
}
|
||||
}
|
||||
fn full_resolver() -> MapResolver {
|
||||
// indices 0..=10 (11 starters); the rest of the 23 slots are id==0 (empty).
|
||||
let ids = [
|
||||
100000003, 100000010, 100000005, 100000008, 100000007, 100000006, 100000004, 100000009,
|
||||
100000001, 100000002, 100000025,
|
||||
];
|
||||
MapResolver(ids.iter().map(|&w| (w, format!("oc-{w}"))).collect())
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn parses_the_captured_full_squad_wire() {
|
||||
let put = parse_squad_put(PUT_F442.as_bytes()).unwrap();
|
||||
assert_eq!(put.id, 0, "path/body squad id 0 = active");
|
||||
assert_eq!(put.formation.as_deref(), Some("f442"));
|
||||
assert_eq!(put.squad_type.as_deref(), Some("REGULAR_SQUAD"));
|
||||
assert_eq!(put.chemistry, Some(52));
|
||||
assert_eq!(put.rating, Some(90));
|
||||
assert_eq!(put.star_rating, Some(90));
|
||||
assert_eq!(put.captain, Some(100000001));
|
||||
assert_eq!(put.players.len(), 23, "fixed 23-slot array");
|
||||
assert_eq!(put.kicktakers.len(), 5);
|
||||
// custom is carried opaquely, never parsed.
|
||||
assert!(put.custom.as_deref().unwrap().starts_with("[0,0,0"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn resolves_occupied_slots_drops_empties_and_flags_captain() {
|
||||
let put = parse_squad_put(PUT_F442.as_bytes()).unwrap();
|
||||
let sq = to_proposed(&put, &full_resolver());
|
||||
|
||||
assert_eq!(sq.slots.len(), 11, "11 occupied; 12 empty (id==0) dropped");
|
||||
assert!(
|
||||
sq.unresolved_wire_ids.is_empty(),
|
||||
"all occupied ids resolved"
|
||||
);
|
||||
assert_eq!(
|
||||
sq.formation.as_deref(),
|
||||
Some("f442"),
|
||||
"formation token carried verbatim, never mapped"
|
||||
);
|
||||
// Every occupied f442 slot is a starter (indices 0..=10).
|
||||
assert!(sq.slots.iter().all(|s| !s.is_on_bench));
|
||||
// The captain flag lands on exactly the captain's slot (id 100000001 @ index 8).
|
||||
let caps: Vec<_> = sq.slots.iter().filter(|s| s.is_captain).collect();
|
||||
assert_eq!(caps.len(), 1);
|
||||
assert_eq!(caps[0].owned_card_id, "oc-100000001");
|
||||
assert_eq!(caps[0].index, 8);
|
||||
assert_eq!(caps[0].kit_number, 8);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn unresolved_occupied_id_is_reported_never_dropped_silently() {
|
||||
let put = parse_squad_put(PUT_F442.as_bytes()).unwrap();
|
||||
// Resolver missing one occupied id (100000025).
|
||||
let mut ids = full_resolver().0;
|
||||
ids.remove(&100000025);
|
||||
let sq = to_proposed(&put, &MapResolver(ids));
|
||||
assert_eq!(
|
||||
sq.slots.len(),
|
||||
10,
|
||||
"the unresolved slot is not emitted as a player"
|
||||
);
|
||||
assert_eq!(
|
||||
sq.unresolved_wire_ids,
|
||||
vec![100000025],
|
||||
"reported for the caller to refuse"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn empty_slot_is_dropped_not_resolved() {
|
||||
// A minimal body: one occupied + one empty slot.
|
||||
let body = br#"{"id":0,"formation":"f442","captain":0,"players":[
|
||||
{"index":0,"itemData":{"id":100000003},"kitNumber":1},
|
||||
{"index":11,"itemData":{"id":0},"kitNumber":0}]}"#;
|
||||
let put = parse_squad_put(body).unwrap();
|
||||
let sq = to_proposed(&put, &full_resolver());
|
||||
assert_eq!(sq.slots.len(), 1);
|
||||
assert_eq!(sq.slots[0].index, 0);
|
||||
assert!(sq.unresolved_wire_ids.is_empty());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn formation_token_round_trips_verbatim() {
|
||||
// Canonical formation is the FIFA token as-sent; f433 is preserved as
|
||||
// readily as f442 (the old lossy f442->"4-4-2" map is gone).
|
||||
for tok in ["f442", "f433"] {
|
||||
let body = format!(
|
||||
r#"{{"id":0,"formation":"{tok}","captain":0,"players":[{{"index":0,"itemData":{{"id":100000003}},"kitNumber":1}}]}}"#
|
||||
);
|
||||
let sq = to_proposed(&parse_squad_put(body.as_bytes()).unwrap(), &full_resolver());
|
||||
assert_eq!(sq.formation.as_deref(), Some(tok));
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn save_ack_is_the_bare_id() {
|
||||
assert_eq!(save_ack(0), serde_json::json!({ "id": 0 }));
|
||||
assert_eq!(save_ack(7), serde_json::json!({ "id": 7 }));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn malformed_body_errors_never_empty_squad() {
|
||||
assert!(matches!(
|
||||
parse_squad_put(b"not json"),
|
||||
Err(SquadError::Parse(_))
|
||||
));
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,386 @@
|
||||
//! FIFA 17 **Squad Extension v1** — the adapter-owned, versioned payload that
|
||||
//! carries the squad's FIFA-only wire state that OpenFUT Core does not model.
|
||||
//!
|
||||
//! Core stores this serialized payload **opaquely** (never interpreting it) next
|
||||
//! to the canonical squad, anchored by a server fingerprint. This module owns its
|
||||
//! schema and meaning; Core must never import this type.
|
||||
//!
|
||||
//! ## What lives here (and why it is not canonical)
|
||||
//!
|
||||
//! | field | ownership rationale |
|
||||
//! |-------|---------------------|
|
||||
//! | `custom` | opaque 33-int string; meaning UNKNOWN, round-tripped verbatim |
|
||||
//! | `squad_type` | an observed FIFA wire token; no matching generic Core concept |
|
||||
//! | `kit_numbers` | keyed by **`owned_card_id`** — evidence: kit follows the player |
|
||||
//! | `manager` | a FIFA manager item ref; not a squad player, semantics opaque |
|
||||
//! | `kicktakers` | role→item refs; relationship to captain UNKNOWN, kept opaque |
|
||||
//! | `client_reported` | chemistry/rating/starRating — client shadow, NOT authority |
|
||||
//!
|
||||
//! ## Versioning
|
||||
//!
|
||||
//! Two independent version numbers must not be confused:
|
||||
//! * [`EXT_SCHEMA_VERSION`] — the version of **this** payload schema. Stored in
|
||||
//! Core's `game_entity_ext.schema_version` and re-checked on read
|
||||
//! ([`Fifa17SquadExtensionV1::from_payload`] rejects any other version).
|
||||
//! * Core's own DB storage schema version — a Core concern, unrelated to this.
|
||||
//!
|
||||
//! [`EXT_NAMESPACE`] is the opaque scope key Core files the row under.
|
||||
|
||||
use std::collections::BTreeMap;
|
||||
|
||||
use serde::{Deserialize, Serialize};
|
||||
|
||||
use crate::fut::squad::{ClientReportedSquadEval, Fifa17SquadPut, ProposedSquad, SquadEntityRef};
|
||||
|
||||
/// Opaque scope key Core files this extension under (`game_entity_ext.namespace`).
|
||||
pub const EXT_NAMESPACE: &str = "fifa17.squad";
|
||||
|
||||
/// The version of THIS payload schema (goes into `OpaqueExtensionWrite.schema_version`).
|
||||
/// Distinct from Core's DB storage schema version.
|
||||
pub const EXT_SCHEMA_VERSION: i64 = 1;
|
||||
|
||||
/// A FIFA item reference `{ id, dream }` preserved verbatim from the wire. `id`
|
||||
/// is the FIFA wire item id (opaque to this extension — used for manager and
|
||||
/// kicktaker refs whose semantics are not modelled).
|
||||
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
|
||||
pub struct WireItemRef {
|
||||
pub id: i64,
|
||||
#[serde(default)]
|
||||
pub dream: bool,
|
||||
}
|
||||
|
||||
impl From<&SquadEntityRef> for WireItemRef {
|
||||
fn from(r: &SquadEntityRef) -> Self {
|
||||
WireItemRef {
|
||||
id: r.id,
|
||||
dream: r.dream,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// A kicktaker slot preserved verbatim. `index` is the role slot (0..=4 observed);
|
||||
/// `item` is the referenced FIFA wire item. The role→player meaning and any
|
||||
/// relationship to the captain are UNKNOWN, so this is stored opaquely and never
|
||||
/// normalized to the captain or to a Core `owned_card_id`.
|
||||
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
|
||||
pub struct KicktakerRef {
|
||||
pub index: i64,
|
||||
#[serde(flatten)]
|
||||
pub item: WireItemRef,
|
||||
}
|
||||
|
||||
/// FIFA 17 Squad Extension, version 1. Serialized to the opaque payload Core stores.
|
||||
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
|
||||
pub struct Fifa17SquadExtensionV1 {
|
||||
/// Opaque 33-int array as a JSON-encoded string, verbatim. Never decoded.
|
||||
#[serde(default)]
|
||||
pub custom: Option<String>,
|
||||
/// FIFA squad-type wire token (e.g. `"REGULAR_SQUAD"`).
|
||||
#[serde(default)]
|
||||
pub squad_type: Option<String>,
|
||||
/// kit number per player, keyed by Core `owned_card_id`. Keyed by the player
|
||||
/// instance — NEVER by slot/index or by card definition — because the wire
|
||||
/// proves the kit number follows the player across swaps and formation change.
|
||||
#[serde(default)]
|
||||
pub kit_numbers: BTreeMap<String, i64>,
|
||||
/// Manager item ref(s), opaque. Not a squad player; not shaped as an item.
|
||||
#[serde(default)]
|
||||
pub manager: Vec<WireItemRef>,
|
||||
/// Kicktaker role refs, opaque (see [`KicktakerRef`]).
|
||||
#[serde(default)]
|
||||
pub kicktakers: Vec<KicktakerRef>,
|
||||
/// Client-reported evaluation (shadow state). NEVER Core's authoritative
|
||||
/// evaluation and never reconciled with it.
|
||||
#[serde(default)]
|
||||
pub client_reported: ClientReportedSquadEval,
|
||||
}
|
||||
|
||||
/// Errors reading a stored extension payload.
|
||||
#[derive(Debug, PartialEq, Eq)]
|
||||
pub enum ExtError {
|
||||
/// The stored `schema_version` is not one this adapter understands. Never
|
||||
/// silently coerced — the caller decides (e.g. treat as unreadable).
|
||||
UnsupportedSchemaVersion(i64),
|
||||
/// The payload bytes did not deserialize as this schema.
|
||||
Parse(String),
|
||||
}
|
||||
|
||||
impl std::fmt::Display for ExtError {
|
||||
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
|
||||
match self {
|
||||
ExtError::UnsupportedSchemaVersion(v) => {
|
||||
write!(f, "unsupported fifa17 squad extension schema version {v} (want {EXT_SCHEMA_VERSION})")
|
||||
}
|
||||
ExtError::Parse(e) => write!(f, "fifa17 squad extension parse error: {e}"),
|
||||
}
|
||||
}
|
||||
}
|
||||
impl std::error::Error for ExtError {}
|
||||
|
||||
impl Fifa17SquadExtensionV1 {
|
||||
/// Build the extension from the parsed PUT plus the resolved canonical squad.
|
||||
/// `custom`/`squad_type`/manager/kicktakers/client eval come straight off the
|
||||
/// wire; kit numbers are re-keyed from slot index onto the resolved
|
||||
/// `owned_card_id` so they stay bound to the player, not the slot.
|
||||
pub fn from_put(put: &Fifa17SquadPut, canonical: &ProposedSquad) -> Self {
|
||||
let kit_numbers = canonical
|
||||
.slots
|
||||
.iter()
|
||||
.map(|s| (s.owned_card_id.clone(), s.kit_number))
|
||||
.collect();
|
||||
Fifa17SquadExtensionV1 {
|
||||
custom: put.custom.clone(),
|
||||
squad_type: put.squad_type.clone(),
|
||||
kit_numbers,
|
||||
manager: put.manager.iter().map(WireItemRef::from).collect(),
|
||||
kicktakers: put
|
||||
.kicktakers
|
||||
.iter()
|
||||
.map(|k| KicktakerRef {
|
||||
index: k.index,
|
||||
item: WireItemRef {
|
||||
id: k.id,
|
||||
dream: k.dream,
|
||||
},
|
||||
})
|
||||
.collect(),
|
||||
client_reported: ClientReportedSquadEval {
|
||||
chemistry: put.chemistry,
|
||||
rating: put.rating,
|
||||
star_rating: put.star_rating,
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
/// Serialize to the opaque payload string Core stores.
|
||||
pub fn to_payload(&self) -> String {
|
||||
// Infallible for this type (no maps with non-string keys, no floats).
|
||||
serde_json::to_string(self).expect("fifa17 squad extension serializes")
|
||||
}
|
||||
|
||||
/// Parse a stored payload, enforcing the schema version FIRST. A version this
|
||||
/// adapter does not understand is rejected — never coerced or ignored.
|
||||
pub fn from_payload(schema_version: i64, payload: &str) -> Result<Self, ExtError> {
|
||||
if schema_version != EXT_SCHEMA_VERSION {
|
||||
return Err(ExtError::UnsupportedSchemaVersion(schema_version));
|
||||
}
|
||||
serde_json::from_str(payload).map_err(|e| ExtError::Parse(e.to_string()))
|
||||
}
|
||||
}
|
||||
|
||||
/// Errors building a squad write from a PUT. A save is refused, never silently
|
||||
/// degraded, when it cannot be expressed faithfully as a canonical replacement.
|
||||
#[derive(Debug, PartialEq, Eq)]
|
||||
pub enum SquadBuildError {
|
||||
/// One or more occupied wire ids did not reverse-map to a Core owned item.
|
||||
/// Saving would silently drop an owned player — refused.
|
||||
UnresolvedWireIds(Vec<i64>),
|
||||
/// The same Core owned item appears in two slots. A full replacement cannot
|
||||
/// place one instance twice (two *copies* of a definition are distinct owned
|
||||
/// items and are fine — this is the same `owned_card_id` twice).
|
||||
DuplicateOwnedItem(String),
|
||||
}
|
||||
|
||||
impl std::fmt::Display for SquadBuildError {
|
||||
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
|
||||
match self {
|
||||
SquadBuildError::UnresolvedWireIds(ids) => {
|
||||
write!(f, "unresolved FIFA wire item ids (save refused): {ids:?}")
|
||||
}
|
||||
SquadBuildError::DuplicateOwnedItem(id) => {
|
||||
write!(f, "owned item {id} placed in two slots (save refused)")
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
impl std::error::Error for SquadBuildError {}
|
||||
|
||||
/// The adapter's PUT-build output: a canonical replacement plus the FIFA-only
|
||||
/// extension. The host maps `canonical` onto Core's `SquadReplacement` and
|
||||
/// serializes `extension` into an `OpaqueExtensionWrite`
|
||||
/// (`namespace = EXT_NAMESPACE`, `schema_version = EXT_SCHEMA_VERSION`,
|
||||
/// `payload = extension.to_payload()`) so both commit in one Core transaction.
|
||||
#[derive(Debug, Clone)]
|
||||
pub struct SquadWriteBuild {
|
||||
pub canonical: ProposedSquad,
|
||||
pub extension: Fifa17SquadExtensionV1,
|
||||
}
|
||||
|
||||
/// Build a full-replacement squad write from a parsed PUT and a host-supplied
|
||||
/// wire→owned resolver. Refuses (never degrades) on any unresolved occupied id
|
||||
/// or a duplicate owned item.
|
||||
///
|
||||
/// The resolver only maps identity; it is NOT authorization. The host still
|
||||
/// verifies every resolved `owned_card_id` belongs to the active FIFA 17
|
||||
/// profile/club before committing — a resolvable id is not proof of ownership.
|
||||
pub fn build_squad_write(
|
||||
put: &Fifa17SquadPut,
|
||||
resolver: &dyn crate::fut::squad::SquadWireResolver,
|
||||
) -> Result<SquadWriteBuild, SquadBuildError> {
|
||||
let canonical = crate::fut::squad::to_proposed(put, resolver);
|
||||
if !canonical.unresolved_wire_ids.is_empty() {
|
||||
return Err(SquadBuildError::UnresolvedWireIds(
|
||||
canonical.unresolved_wire_ids.clone(),
|
||||
));
|
||||
}
|
||||
let mut seen = std::collections::HashSet::new();
|
||||
for slot in &canonical.slots {
|
||||
if !seen.insert(slot.owned_card_id.as_str()) {
|
||||
return Err(SquadBuildError::DuplicateOwnedItem(
|
||||
slot.owned_card_id.clone(),
|
||||
));
|
||||
}
|
||||
}
|
||||
let extension = Fifa17SquadExtensionV1::from_put(put, &canonical);
|
||||
Ok(SquadWriteBuild {
|
||||
canonical,
|
||||
extension,
|
||||
})
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
use crate::fut::squad::{parse_squad_put, SquadWireResolver};
|
||||
use std::collections::HashMap;
|
||||
|
||||
const PUT_F442: &str = include_str!("../../fixtures/utas/squad_put_f442.json");
|
||||
|
||||
struct MapResolver(HashMap<i64, String>);
|
||||
impl SquadWireResolver for MapResolver {
|
||||
fn owned_id_for_wire(&self, wire: i64) -> Option<String> {
|
||||
self.0.get(&wire).cloned()
|
||||
}
|
||||
}
|
||||
fn full_resolver() -> MapResolver {
|
||||
let ids = [
|
||||
100000003, 100000010, 100000005, 100000008, 100000007, 100000006, 100000004, 100000009,
|
||||
100000001, 100000002, 100000025,
|
||||
];
|
||||
MapResolver(ids.iter().map(|&w| (w, format!("oc-{w}"))).collect())
|
||||
}
|
||||
|
||||
fn built() -> SquadWriteBuild {
|
||||
let put = parse_squad_put(PUT_F442.as_bytes()).unwrap();
|
||||
build_squad_write(&put, &full_resolver()).unwrap()
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn serde_round_trips_the_whole_extension() {
|
||||
let ext = built().extension;
|
||||
let payload = ext.to_payload();
|
||||
let back = Fifa17SquadExtensionV1::from_payload(EXT_SCHEMA_VERSION, &payload).unwrap();
|
||||
assert_eq!(ext, back);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn custom_is_preserved_byte_for_byte() {
|
||||
let put = parse_squad_put(PUT_F442.as_bytes()).unwrap();
|
||||
let ext = built().extension;
|
||||
assert_eq!(ext.custom, put.custom, "opaque custom carried verbatim");
|
||||
// survives a serialize/parse cycle unchanged.
|
||||
let back =
|
||||
Fifa17SquadExtensionV1::from_payload(EXT_SCHEMA_VERSION, &ext.to_payload()).unwrap();
|
||||
assert_eq!(back.custom, put.custom);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn kit_number_is_keyed_by_owned_item_not_slot() {
|
||||
let ext = built().extension;
|
||||
// In the f442 fixture, owned oc-100000001 (captain) wears kit 8 at index 8;
|
||||
// oc-100000025 wears kit 11 at index 10. Keyed by owned id, not index.
|
||||
assert_eq!(ext.kit_numbers.get("oc-100000001"), Some(&8));
|
||||
assert_eq!(ext.kit_numbers.get("oc-100000025"), Some(&11));
|
||||
assert_eq!(ext.kit_numbers.len(), 11, "one per occupied slot");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn client_reported_eval_is_carried_as_shadow() {
|
||||
let ext = built().extension;
|
||||
assert_eq!(
|
||||
ext.client_reported,
|
||||
ClientReportedSquadEval {
|
||||
chemistry: Some(52),
|
||||
rating: Some(90),
|
||||
star_rating: Some(90)
|
||||
}
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn manager_and_kicktakers_preserved_opaquely() {
|
||||
let ext = built().extension;
|
||||
assert_eq!(
|
||||
ext.manager,
|
||||
vec![WireItemRef {
|
||||
id: 100000427,
|
||||
dream: false
|
||||
}]
|
||||
);
|
||||
assert_eq!(ext.kicktakers.len(), 5);
|
||||
// All five reference the same wire id in this capture; carried verbatim,
|
||||
// NEVER normalized to the captain even though they coincide here.
|
||||
assert!(ext.kicktakers.iter().all(|k| k.item.id == 100000001));
|
||||
assert_eq!(ext.kicktakers[0].index, 0);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn unknown_schema_version_is_rejected_not_coerced() {
|
||||
let payload = built().extension.to_payload();
|
||||
assert_eq!(
|
||||
Fifa17SquadExtensionV1::from_payload(2, &payload),
|
||||
Err(ExtError::UnsupportedSchemaVersion(2))
|
||||
);
|
||||
assert_eq!(
|
||||
Fifa17SquadExtensionV1::from_payload(0, &payload),
|
||||
Err(ExtError::UnsupportedSchemaVersion(0))
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn malformed_payload_errors() {
|
||||
assert!(matches!(
|
||||
Fifa17SquadExtensionV1::from_payload(EXT_SCHEMA_VERSION, "not json"),
|
||||
Err(ExtError::Parse(_))
|
||||
));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn build_refuses_unresolved_wire_ids() {
|
||||
let put = parse_squad_put(PUT_F442.as_bytes()).unwrap();
|
||||
let mut ids = full_resolver().0;
|
||||
ids.remove(&100000025);
|
||||
let err = build_squad_write(&put, &MapResolver(ids)).unwrap_err();
|
||||
assert_eq!(err, SquadBuildError::UnresolvedWireIds(vec![100000025]));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn build_refuses_duplicate_owned_item() {
|
||||
// Two occupied slots resolving to the SAME owned id (one instance twice).
|
||||
let body = br#"{"id":0,"formation":"f442","captain":100000003,"players":[
|
||||
{"index":0,"itemData":{"id":100000003},"kitNumber":1},
|
||||
{"index":1,"itemData":{"id":100000004},"kitNumber":2}]}"#;
|
||||
let put = parse_squad_put(body).unwrap();
|
||||
let mut m = HashMap::new();
|
||||
m.insert(100000003, "oc-dup".to_string());
|
||||
m.insert(100000004, "oc-dup".to_string()); // collide onto same owned id
|
||||
let err = build_squad_write(&put, &MapResolver(m)).unwrap_err();
|
||||
assert_eq!(
|
||||
err,
|
||||
SquadBuildError::DuplicateOwnedItem("oc-dup".to_string())
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn full_replacement_carries_every_occupied_slot_no_diff() {
|
||||
let build = built();
|
||||
assert_eq!(build.canonical.slots.len(), 11, "whole squad, not a diff");
|
||||
assert_eq!(build.canonical.formation.as_deref(), Some("f442"));
|
||||
// No FIFA wire integer survives into the canonical slots.
|
||||
assert!(build
|
||||
.canonical
|
||||
.slots
|
||||
.iter()
|
||||
.all(|s| s.owned_card_id.starts_with("oc-")));
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,426 @@
|
||||
//! The **single** FIFA 17 squad projector: canonical Core squad + Fresh FIFA
|
||||
//! extension → the FIFA 17 squad wire object.
|
||||
//!
|
||||
//! One projector serves every squad read shape. `userMassInfo.squad` embeds the
|
||||
//! full object; `GET /squad/list` is a summary *subset* of it; a future
|
||||
//! `/squad/active` is the same object again. Endpoint wrappers ([`user_mass_info_squad`],
|
||||
//! [`squad_list`]) only shape the outer envelope — there is deliberately no
|
||||
//! second squad domain model per endpoint.
|
||||
//!
|
||||
//! ## Purity / no N+1
|
||||
//!
|
||||
//! The projector touches no database, socket, or Core API. It consumes a
|
||||
//! [`SquadProjectionInput`] the host assembles from ONE bounded batch — Core's
|
||||
//! `read_squad_with_ext` (canonical squad + players + extension freshness) plus a
|
||||
//! single "all owned cards for this club" fetch joined against the in-memory card
|
||||
//! definitions. There is no per-slot lookup here or above.
|
||||
//!
|
||||
//! ## Item identity is shared, never reconstructed
|
||||
//!
|
||||
//! Each occupied slot is shaped by the shared [`crate::fut::item::shape_item`],
|
||||
//! the same primitive `/club` uses — the projector never rebuilds the card shape
|
||||
//! itself, so squad items and `/club` items cannot drift, and two owned copies of
|
||||
//! one definition stay distinct (each carries its own resolved wire id).
|
||||
//!
|
||||
//! ## Fresh / Stale / Missing
|
||||
//!
|
||||
//! Freshness comes from Core and is surfaced, never buried in a default:
|
||||
//! * **Fresh** → project the full object.
|
||||
//! * **Stale** → NEVER overlay the stale extension on the newer canonical squad;
|
||||
//! return [`SquadProjection::Stale`] for the host to act on (e.g. fall back).
|
||||
//! * **Missing** → return [`SquadProjection::Missing`]; the projector does NOT
|
||||
//! fabricate a manager/custom/kicktakers/kit numbers just to emit a response.
|
||||
|
||||
use std::collections::HashMap;
|
||||
|
||||
use serde_json::{json, Value};
|
||||
|
||||
use crate::fut::entities::ReverseEntityResolver;
|
||||
use crate::fut::item::{shape_item, CoreOwnedItem, ItemIdentityResolver};
|
||||
use crate::fut::squad::FIFA17_SQUAD_SLOTS;
|
||||
use crate::fut::squad_ext::Fifa17SquadExtensionV1;
|
||||
|
||||
/// Freshness of the FIFA 17 extension relative to the current canonical squad,
|
||||
/// as reported by Core's `read_squad_with_ext`. This is a game-independent mirror
|
||||
/// the host populates from Core's `SquadExtState`; the adapter never computes the
|
||||
/// canonical fingerprint itself (that is Core's server-side job).
|
||||
#[derive(Debug, Clone)]
|
||||
pub enum SquadExtInput {
|
||||
Fresh(Fifa17SquadExtensionV1),
|
||||
/// The stored extension whose fingerprint no longer matches the canonical
|
||||
/// squad. Carried so the host can log/inspect it, but the projector NEVER
|
||||
/// applies it over the newer canonical squad (mirrors Core's
|
||||
/// `SquadExtState::Stale { stored, .. }`).
|
||||
Stale(Fifa17SquadExtensionV1),
|
||||
Missing,
|
||||
}
|
||||
|
||||
/// One canonical slot as read back from Core. `is_on_bench` is carried through
|
||||
/// from Core, never re-derived from the formation.
|
||||
#[derive(Debug, Clone)]
|
||||
pub struct ProjectionSlot {
|
||||
pub owned_card_id: String,
|
||||
pub index: i64,
|
||||
pub is_captain: bool,
|
||||
pub is_on_bench: bool,
|
||||
}
|
||||
|
||||
/// Everything the pure projector needs to render one full squad.
|
||||
pub struct SquadProjectionInput<'a> {
|
||||
/// FIFA wire squad id (`0` = active).
|
||||
pub fifa_squad_id: i64,
|
||||
pub name: String,
|
||||
/// FIFA formation token, verbatim from the canonical squad (never mapped).
|
||||
pub formation: String,
|
||||
pub slots: Vec<ProjectionSlot>,
|
||||
pub ext: SquadExtInput,
|
||||
/// Every owned item a slot references, keyed by `owned_card_id`. Assembled by
|
||||
/// the host in one batch — the projector only reads from it.
|
||||
pub owned: &'a HashMap<String, CoreOwnedItem>,
|
||||
}
|
||||
|
||||
/// Result of a projection, with the extension-freshness verdict surfaced.
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub enum SquadProjection {
|
||||
/// A fully projected FIFA 17 squad object (the `userMassInfo.squad` shape,
|
||||
/// minus session envelope fields the endpoint wrapper adds).
|
||||
Projected(Value),
|
||||
/// The stored extension is stale vs the canonical squad — not applied.
|
||||
Stale,
|
||||
/// No extension stored — nothing fabricated.
|
||||
Missing,
|
||||
}
|
||||
|
||||
/// Hard projection failures — a squad cannot be rendered faithfully. Never
|
||||
/// silently degraded (a squad cannot drop a starter the way `/club` drops a card).
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub enum SquadProjectError {
|
||||
/// A slot references an `owned_card_id` absent from the projection input.
|
||||
MissingOwnedItem(String),
|
||||
/// An occupied slot's owned item has no real FIFA asset identity — it cannot
|
||||
/// be rendered and MUST NOT be faked.
|
||||
NoFifaIdentity(String),
|
||||
}
|
||||
|
||||
impl std::fmt::Display for SquadProjectError {
|
||||
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
|
||||
match self {
|
||||
SquadProjectError::MissingOwnedItem(id) => {
|
||||
write!(f, "projection input missing owned item {id}")
|
||||
}
|
||||
SquadProjectError::NoFifaIdentity(id) => {
|
||||
write!(
|
||||
f,
|
||||
"owned item {id} has no real FIFA asset identity (cannot render)"
|
||||
)
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
impl std::error::Error for SquadProjectError {}
|
||||
|
||||
/// Project a squad. On `Fresh`, returns the full FIFA squad object; on
|
||||
/// `Stale`/`Missing`, returns that verdict without fabricating anything.
|
||||
pub fn project_squad<I: ItemIdentityResolver + ?Sized>(
|
||||
input: &SquadProjectionInput<'_>,
|
||||
ident: &I,
|
||||
ent: &impl ReverseEntityResolver,
|
||||
) -> Result<SquadProjection, SquadProjectError> {
|
||||
let ext = match &input.ext {
|
||||
SquadExtInput::Stale(_) => return Ok(SquadProjection::Stale),
|
||||
SquadExtInput::Missing => return Ok(SquadProjection::Missing),
|
||||
SquadExtInput::Fresh(ext) => ext,
|
||||
};
|
||||
|
||||
// Index occupied slots by their FIFA array index for O(1) fill.
|
||||
let by_index: HashMap<i64, &ProjectionSlot> =
|
||||
input.slots.iter().map(|s| (s.index, s)).collect();
|
||||
|
||||
let mut players = Vec::with_capacity(FIFA17_SQUAD_SLOTS as usize);
|
||||
let mut captain_wire: i64 = 0;
|
||||
|
||||
for index in 0..FIFA17_SQUAD_SLOTS {
|
||||
match by_index.get(&index) {
|
||||
Some(slot) => {
|
||||
let item = input.owned.get(&slot.owned_card_id).ok_or_else(|| {
|
||||
SquadProjectError::MissingOwnedItem(slot.owned_card_id.clone())
|
||||
})?;
|
||||
let id = ident
|
||||
.resolve(item)
|
||||
.ok_or_else(|| SquadProjectError::NoFifaIdentity(slot.owned_card_id.clone()))?;
|
||||
if slot.is_captain {
|
||||
captain_wire = id.item_id as i64;
|
||||
}
|
||||
// kit follows the player: look it up by owned id, never by index.
|
||||
let kit = ext
|
||||
.kit_numbers
|
||||
.get(&slot.owned_card_id)
|
||||
.copied()
|
||||
.unwrap_or(0);
|
||||
players.push(json!({
|
||||
"index": index,
|
||||
"itemData": shape_item(item, id, ent),
|
||||
"kitNumber": kit,
|
||||
}));
|
||||
}
|
||||
None => players.push(json!({
|
||||
"index": index,
|
||||
"itemData": { "id": 0, "dream": false },
|
||||
"kitNumber": 0,
|
||||
})),
|
||||
}
|
||||
}
|
||||
|
||||
let squad = json!({
|
||||
"id": input.fifa_squad_id,
|
||||
"squadName": input.name,
|
||||
"formation": input.formation,
|
||||
"squadType": ext.squad_type,
|
||||
"chemistry": ext.client_reported.chemistry,
|
||||
"starRating": ext.client_reported.star_rating,
|
||||
"rating": ext.client_reported.rating,
|
||||
"captain": captain_wire,
|
||||
"manager": ext.manager,
|
||||
"custom": ext.custom,
|
||||
"players": players,
|
||||
"kicktakers": ext.kicktakers,
|
||||
});
|
||||
Ok(SquadProjection::Projected(squad))
|
||||
}
|
||||
|
||||
/// Wrap a projected squad object into the `userMassInfo.squad` shape, injecting
|
||||
/// the session-envelope fields the projector does not own (`personaId`, plus the
|
||||
/// observed constants `changed: 0`, `actives: []`).
|
||||
pub fn user_mass_info_squad(projected: Value, persona_id: i64) -> Value {
|
||||
let mut obj = projected;
|
||||
if let Value::Object(map) = &mut obj {
|
||||
map.insert("personaId".into(), json!(persona_id));
|
||||
map.insert("changed".into(), json!(0));
|
||||
map.insert("actives".into(), json!([]));
|
||||
}
|
||||
obj
|
||||
}
|
||||
|
||||
/// The `GET /squad/list` summary response — a subset of the SAME projected
|
||||
/// object, wrapped in `{"squad":[ … ]}`. Not a separate domain projection.
|
||||
pub fn squad_list(projected: &Value) -> Value {
|
||||
let summary = json!({
|
||||
"id": projected.get("id").cloned().unwrap_or(Value::Null),
|
||||
"squadName": projected.get("squadName").cloned().unwrap_or(Value::Null),
|
||||
"formation": projected.get("formation").cloned().unwrap_or(Value::Null),
|
||||
"squadType": projected.get("squadType").cloned().unwrap_or(Value::Null),
|
||||
"rating": projected.get("rating").cloned().unwrap_or(Value::Null),
|
||||
"chemistry": projected.get("chemistry").cloned().unwrap_or(Value::Null),
|
||||
});
|
||||
json!({ "squad": [summary] })
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
use crate::fut::entities::Fifa17Entities;
|
||||
use crate::fut::item::Fifa17Identity;
|
||||
|
||||
// A resolver that mints a distinct wire id per owned item and a fixed asset.
|
||||
struct TableIdentity(HashMap<String, Fifa17Identity>);
|
||||
impl ItemIdentityResolver for TableIdentity {
|
||||
fn resolve(&self, it: &CoreOwnedItem) -> Option<Fifa17Identity> {
|
||||
self.0.get(&it.owned_card_id).copied()
|
||||
}
|
||||
}
|
||||
|
||||
fn ent() -> Fifa17Entities {
|
||||
Fifa17Entities::from_maps(HashMap::new(), HashMap::new(), HashMap::new())
|
||||
}
|
||||
|
||||
fn owned_item(id: &str, card: &str) -> CoreOwnedItem {
|
||||
CoreOwnedItem {
|
||||
owned_card_id: id.into(),
|
||||
card_id: card.into(),
|
||||
rating: 84,
|
||||
position: "ST".into(),
|
||||
nation: "n".into(),
|
||||
league: "l".into(),
|
||||
club: "c".into(),
|
||||
attributes: [80, 80, 80, 80, 40, 80],
|
||||
}
|
||||
}
|
||||
|
||||
fn one_slot_input<'a>(
|
||||
owned: &'a HashMap<String, CoreOwnedItem>,
|
||||
ext: SquadExtInput,
|
||||
) -> SquadProjectionInput<'a> {
|
||||
SquadProjectionInput {
|
||||
fifa_squad_id: 0,
|
||||
name: "OpenFUT".into(),
|
||||
formation: "f442".into(),
|
||||
slots: vec![ProjectionSlot {
|
||||
owned_card_id: "oc1".into(),
|
||||
index: 0,
|
||||
is_captain: true,
|
||||
is_on_bench: false,
|
||||
}],
|
||||
ext,
|
||||
owned,
|
||||
}
|
||||
}
|
||||
|
||||
fn fresh_ext() -> Fifa17SquadExtensionV1 {
|
||||
let mut kit = std::collections::BTreeMap::new();
|
||||
kit.insert("oc1".to_string(), 9);
|
||||
Fifa17SquadExtensionV1 {
|
||||
custom: Some("[1,2,3]".into()),
|
||||
squad_type: Some("REGULAR_SQUAD".into()),
|
||||
kit_numbers: kit,
|
||||
manager: vec![],
|
||||
kicktakers: vec![],
|
||||
client_reported: Default::default(),
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn fresh_projects_full_23_slot_array_with_captain_wire_id() {
|
||||
let mut owned = HashMap::new();
|
||||
owned.insert("oc1".to_string(), owned_item("oc1", "card_x"));
|
||||
let ident = TableIdentity(HashMap::from([(
|
||||
"oc1".to_string(),
|
||||
Fifa17Identity {
|
||||
item_id: 100000042,
|
||||
asset_id: 20801,
|
||||
resource_id: 20801,
|
||||
rareflag: 1,
|
||||
},
|
||||
)]));
|
||||
let input = one_slot_input(&owned, SquadExtInput::Fresh(fresh_ext()));
|
||||
let SquadProjection::Projected(v) = project_squad(&input, &ident, &ent()).unwrap() else {
|
||||
panic!("expected Projected");
|
||||
};
|
||||
assert_eq!(
|
||||
v["players"].as_array().unwrap().len(),
|
||||
23,
|
||||
"fixed 23-slot array"
|
||||
);
|
||||
assert_eq!(
|
||||
v["players"][0]["itemData"]["id"], 100000042,
|
||||
"wire id, not resourceId"
|
||||
);
|
||||
assert_eq!(v["players"][0]["itemData"]["resourceId"], 20801);
|
||||
assert_eq!(v["players"][0]["kitNumber"], 9, "kit from ext by owned id");
|
||||
assert_eq!(v["players"][1]["itemData"]["id"], 0, "empty slot");
|
||||
assert_eq!(v["captain"], 100000042, "captain is the resolved WIRE id");
|
||||
assert_ne!(v["captain"], 20801, "captain must NOT be the resourceId");
|
||||
assert_eq!(v["custom"], "[1,2,3]");
|
||||
assert_eq!(v["formation"], "f442");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn stale_is_never_applied() {
|
||||
let owned = HashMap::new();
|
||||
// A stale extension IS carried (host may log it) but must not be applied.
|
||||
let input = one_slot_input(&owned, SquadExtInput::Stale(fresh_ext()));
|
||||
let ident = TableIdentity(HashMap::new());
|
||||
assert_eq!(
|
||||
project_squad(&input, &ident, &ent()).unwrap(),
|
||||
SquadProjection::Stale
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn missing_is_explicit_never_fabricated() {
|
||||
let owned = HashMap::new();
|
||||
let input = one_slot_input(&owned, SquadExtInput::Missing);
|
||||
let ident = TableIdentity(HashMap::new());
|
||||
assert_eq!(
|
||||
project_squad(&input, &ident, &ent()).unwrap(),
|
||||
SquadProjection::Missing
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn occupied_starter_without_asset_identity_is_refused_not_faked() {
|
||||
let mut owned = HashMap::new();
|
||||
owned.insert("oc1".to_string(), owned_item("oc1", "card_x"));
|
||||
let ident = TableIdentity(HashMap::new()); // resolves nothing
|
||||
let input = one_slot_input(&owned, SquadExtInput::Fresh(fresh_ext()));
|
||||
assert_eq!(
|
||||
project_squad(&input, &ident, &ent()),
|
||||
Err(SquadProjectError::NoFifaIdentity("oc1".into()))
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn two_owned_copies_of_one_definition_project_as_distinct_players() {
|
||||
// Same card definition -> same resourceId; two distinct owned instances
|
||||
// in two slots with distinct kits must stay distinct on the wire.
|
||||
let mut owned = HashMap::new();
|
||||
owned.insert("oc-a".to_string(), owned_item("oc-a", "fifa17_101490"));
|
||||
owned.insert("oc-b".to_string(), owned_item("oc-b", "fifa17_101490"));
|
||||
let ident = TableIdentity(HashMap::from([
|
||||
(
|
||||
"oc-a".to_string(),
|
||||
Fifa17Identity {
|
||||
item_id: 100000030,
|
||||
asset_id: 101490,
|
||||
resource_id: 101490,
|
||||
rareflag: 1,
|
||||
},
|
||||
),
|
||||
(
|
||||
"oc-b".to_string(),
|
||||
Fifa17Identity {
|
||||
item_id: 100000031,
|
||||
asset_id: 101490,
|
||||
resource_id: 101490,
|
||||
rareflag: 1,
|
||||
},
|
||||
),
|
||||
]));
|
||||
let mut kit = std::collections::BTreeMap::new();
|
||||
kit.insert("oc-a".to_string(), 7);
|
||||
kit.insert("oc-b".to_string(), 19);
|
||||
let ext = Fifa17SquadExtensionV1 {
|
||||
kit_numbers: kit,
|
||||
..fresh_ext()
|
||||
};
|
||||
let owned_ref = &owned;
|
||||
let input = SquadProjectionInput {
|
||||
fifa_squad_id: 0,
|
||||
name: "OpenFUT".into(),
|
||||
formation: "f442".into(),
|
||||
slots: vec![
|
||||
ProjectionSlot {
|
||||
owned_card_id: "oc-a".into(),
|
||||
index: 0,
|
||||
is_captain: false,
|
||||
is_on_bench: false,
|
||||
},
|
||||
ProjectionSlot {
|
||||
owned_card_id: "oc-b".into(),
|
||||
index: 1,
|
||||
is_captain: false,
|
||||
is_on_bench: false,
|
||||
},
|
||||
],
|
||||
ext: SquadExtInput::Fresh(ext),
|
||||
owned: owned_ref,
|
||||
};
|
||||
let SquadProjection::Projected(v) = project_squad(&input, &ident, &ent()).unwrap() else {
|
||||
panic!();
|
||||
};
|
||||
let a = &v["players"][0]["itemData"];
|
||||
let b = &v["players"][1]["itemData"];
|
||||
assert_eq!(
|
||||
a["resourceId"], b["resourceId"],
|
||||
"same definition => same asset"
|
||||
);
|
||||
assert_ne!(
|
||||
a["id"], b["id"],
|
||||
"distinct owned copies keep distinct wire ids"
|
||||
);
|
||||
assert_eq!(v["players"][0]["kitNumber"], 7);
|
||||
assert_eq!(
|
||||
v["players"][1]["kitNumber"], 19,
|
||||
"kit stays with the instance"
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,268 @@
|
||||
//! FIFA 17 Store pack catalogue + `/store/purchasegroup` wire shaping.
|
||||
//!
|
||||
//! A faithful Rust port of the Python oracle's `PACK_CATALOG` + `_pack_body` +
|
||||
//! `store_catalog` assembly (`fifa17-recon/tools/{fut_store,utas_server}.py`) at the
|
||||
//! **production flag defaults** (`FUT_STORE_DISPLAYGROUP=1` on, `FUT_STORE_GROUPID=0`
|
||||
//! off, `FUT_PRICE_PROBE=0` off). Parity is pinned by differential fixtures generated
|
||||
//! from the Python oracle (`tests/fixtures/purchasegroup_*.json`).
|
||||
//!
|
||||
//! ## Scope / split-brain safety
|
||||
//!
|
||||
//! This is **pure wire shaping** — no economy state, no IO. [`build_purchasegroup`]
|
||||
//! is a function of `(owned unopened pack ids, empty-My-Packs StoreMode)`. It is
|
||||
//! deliberately **not yet wired** into the live host: serving purchasegroup from Rust
|
||||
//! requires an authoritative Rust owner of `unopenedPackIds`, and today Python is the
|
||||
//! single writer of coins + unopened packs (BUY, quick-sell, rewards). Wiring this
|
||||
//! before that economy authority exists would create a dual-write/split-brain. See
|
||||
//! the R3 economy-authority prerequisite in the vault (`Rust UTAS Migration`).
|
||||
//!
|
||||
//! ## Economy-parameter provenance
|
||||
//!
|
||||
//! Prices, counts and odds are the current OpenFUT **PLACEHOLDER** economy, NOT
|
||||
//! EA-authentic (the overnight audit established the store economy is invented). The
|
||||
//! wire *shape* is EA-observed/oracle-verified; the *numbers* are placeholders.
|
||||
|
||||
use serde_json::{json, Value};
|
||||
|
||||
use crate::fut::store_session::{StoreMode, SENTINEL_PACK_ID};
|
||||
|
||||
/// A FIFA 17 Store pack definition. Wire shape is oracle-verified; the economy
|
||||
/// numbers (`price`/`count`/`special_chance`) are OpenFUT PLACEHOLDER, not EA-authentic.
|
||||
#[derive(Debug, Clone, Copy, PartialEq)]
|
||||
pub struct PackDef {
|
||||
pub id: u64,
|
||||
pub name: &'static str,
|
||||
pub price: u64,
|
||||
pub count: u64,
|
||||
pub gold: bool,
|
||||
pub special_chance: f64,
|
||||
/// Reward-only pack (no purchase path): excluded from the normal catalogue,
|
||||
/// rendered only when owned (in `unopenedPackIds`).
|
||||
pub owned_only: bool,
|
||||
}
|
||||
|
||||
/// The current supported FIFA 17 pack catalogue (`fut_store.py:820`). Only observed/
|
||||
/// currently-supported ids. The 65534 sentinel is deliberately ABSENT — it is a
|
||||
/// compatibility shim, never a catalogue pack (never purchasable/openable).
|
||||
pub const PACK_CATALOG: &[PackDef] = &[
|
||||
PackDef {
|
||||
id: 1,
|
||||
name: "Bronze Pack",
|
||||
price: 400,
|
||||
count: 5,
|
||||
gold: false,
|
||||
special_chance: 0.005,
|
||||
owned_only: false,
|
||||
},
|
||||
PackDef {
|
||||
id: 5,
|
||||
name: "Gold Pack",
|
||||
price: 5000,
|
||||
count: 7,
|
||||
gold: true,
|
||||
special_chance: 0.03,
|
||||
owned_only: false,
|
||||
},
|
||||
PackDef {
|
||||
id: 6,
|
||||
name: "Premium Gold",
|
||||
price: 15000,
|
||||
count: 11,
|
||||
gold: true,
|
||||
special_chance: 0.08,
|
||||
owned_only: false,
|
||||
},
|
||||
PackDef {
|
||||
id: 7,
|
||||
name: "Special Players Pack",
|
||||
price: 25000,
|
||||
count: 11,
|
||||
gold: true,
|
||||
special_chance: 1.0,
|
||||
owned_only: false,
|
||||
},
|
||||
PackDef {
|
||||
id: 70,
|
||||
name: "Reward Special Players Pack",
|
||||
price: 0,
|
||||
count: 11,
|
||||
gold: true,
|
||||
special_chance: 1.0,
|
||||
owned_only: true,
|
||||
},
|
||||
];
|
||||
|
||||
/// Look up a catalogue pack by id (the 65534 sentinel is never present).
|
||||
pub fn pack_by_id(id: u64) -> Option<&'static PackDef> {
|
||||
PACK_CATALOG.iter().find(|p| p.id == id)
|
||||
}
|
||||
|
||||
/// The FIFA17 StoreFront category token for a NORMAL pack tile (`utas_server.py:3579`):
|
||||
/// one of the six hard-coded tokens the client resolves.
|
||||
fn category(p: &PackDef) -> &'static str {
|
||||
if p.special_chance >= 1.0 {
|
||||
"special"
|
||||
} else if p.gold {
|
||||
"gold"
|
||||
} else {
|
||||
"bronze"
|
||||
}
|
||||
}
|
||||
|
||||
/// One `purchase[]` entry — the faithful `_pack_body` port (`utas_server.py:3474`) at
|
||||
/// production flag defaults. `owned` packs (My Packs / reward / sentinel) drop the
|
||||
/// purchase fields and take the `mypacks` display group.
|
||||
pub fn pack_body(p: &PackDef, idx: u64, owned: bool) -> Value {
|
||||
let mtx = std::cmp::max(1, p.price / 100);
|
||||
let mut body = json!({
|
||||
"assetId": p.id,
|
||||
"id": p.id,
|
||||
"packType": if p.gold { "GOLD" } else { "BRONZE" },
|
||||
"description": p.name,
|
||||
"state": "active",
|
||||
"saleType": "promo",
|
||||
"limitType": "NONE",
|
||||
"quantity": 0,
|
||||
"purchaseLimit": 0,
|
||||
"purchaseCount": 0,
|
||||
"isPremium": false,
|
||||
"sortPriority": idx,
|
||||
"currencies": [{ "name": "coins", "funds": p.price, "finalFunds": p.price }],
|
||||
"extPrice": {
|
||||
"finalPrice": { "amount": mtx, "currency": "mtx" },
|
||||
"originalPrice": { "amount": mtx, "currency": "mtx" },
|
||||
},
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": if p.gold { 0 } else { p.count },
|
||||
"silverQuantity": 0,
|
||||
"goldQuantity": if p.gold { p.count } else { 0 },
|
||||
"rareQuantity": if p.gold { p.count } else { 0 },
|
||||
"itemQuantity": p.count,
|
||||
},
|
||||
"unopened": owned,
|
||||
});
|
||||
let obj = body.as_object_mut().expect("pack body is a JSON object");
|
||||
if owned {
|
||||
// Reward/My-Packs tiles have no purchase path; leaving zero-value coin/mtx
|
||||
// objects makes the client render the price label as literal "undefined".
|
||||
obj.remove("currencies");
|
||||
obj.remove("extPrice");
|
||||
obj.insert(
|
||||
"displayGroup".into(),
|
||||
json!({ "value": "mypacks", "priority": idx }),
|
||||
);
|
||||
} else {
|
||||
obj.insert("displayGroup".into(), json!({ "value": category(p) }));
|
||||
}
|
||||
body
|
||||
}
|
||||
|
||||
/// The synthetic empty-My-Packs sentinel `purchase[]` entry (id 65534): an owned-style
|
||||
/// body forced to `state:"active"`, `unopened:false`. Compatibility shim ONLY — 65534
|
||||
/// is absent from [`PACK_CATALOG`], so it can never be bought/opened/granted.
|
||||
pub fn sentinel_body(idx: u64) -> Value {
|
||||
let sentinel = PackDef {
|
||||
id: SENTINEL_PACK_ID,
|
||||
name: "",
|
||||
price: 0,
|
||||
count: 0,
|
||||
gold: true,
|
||||
special_chance: 0.0,
|
||||
owned_only: true,
|
||||
};
|
||||
let mut body = pack_body(&sentinel, idx, true);
|
||||
let obj = body
|
||||
.as_object_mut()
|
||||
.expect("sentinel body is a JSON object");
|
||||
obj.insert("state".into(), json!("active"));
|
||||
obj.insert("unopened".into(), json!(false));
|
||||
body
|
||||
}
|
||||
|
||||
/// Build the full `/store/purchasegroup` body from the authoritative unopened-pack ids
|
||||
/// and the frozen empty-My-Packs mode. Pure — mirrors `store_catalog` (`3627`):
|
||||
/// normal packs (1,5,6,7) first, then any owned packs, then the empty-My-Packs shim
|
||||
/// (sentinel for [`StoreMode::Sentinel`], nothing for [`StoreMode::CleanV1`]).
|
||||
pub fn build_purchasegroup(unopened_ids: &[u64], mode: StoreMode) -> Value {
|
||||
let mut packs: Vec<Value> = PACK_CATALOG
|
||||
.iter()
|
||||
.filter(|p| !p.owned_only)
|
||||
.enumerate()
|
||||
.map(|(i, p)| pack_body(p, i as u64 + 1, false))
|
||||
.collect();
|
||||
for (i, &pid) in unopened_ids.iter().enumerate() {
|
||||
if let Some(owned) = pack_by_id(pid) {
|
||||
packs.push(pack_body(owned, i as u64 + 1, true));
|
||||
}
|
||||
}
|
||||
if unopened_ids.is_empty() && mode == StoreMode::Sentinel {
|
||||
packs.push(sentinel_body(1));
|
||||
}
|
||||
json!({ "purchase": packs, "timestamp": 1596326400i64 })
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
//! Differential parity against the Python oracle. The fixtures under
|
||||
//! `tests/fixtures/purchasegroup_*.json` are generated by calling the oracle's
|
||||
//! `_pack_body`/`store_catalog` at production flag defaults; Rust must match
|
||||
//! them semantically (object key order is irrelevant to `serde_json::Value` eq).
|
||||
use super::*;
|
||||
|
||||
fn parse(s: &str) -> Value {
|
||||
serde_json::from_str(s).expect("fixture parses")
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn purchasegroup_zero_sentinel_matches_oracle() {
|
||||
let got = build_purchasegroup(&[], StoreMode::Sentinel);
|
||||
let want = parse(include_str!(
|
||||
"../../tests/fixtures/purchasegroup_zero_sentinel.json"
|
||||
));
|
||||
assert_eq!(got, want);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn purchasegroup_zero_clean_matches_oracle() {
|
||||
let got = build_purchasegroup(&[], StoreMode::CleanV1);
|
||||
let want = parse(include_str!(
|
||||
"../../tests/fixtures/purchasegroup_zero_clean.json"
|
||||
));
|
||||
assert_eq!(got, want);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn purchasegroup_pack70_matches_oracle() {
|
||||
// Owned pack present -> no sentinel regardless of mode.
|
||||
let got = build_purchasegroup(&[70], StoreMode::Sentinel);
|
||||
let want = parse(include_str!(
|
||||
"../../tests/fixtures/purchasegroup_pack70.json"
|
||||
));
|
||||
assert_eq!(got, want);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn sentinel_absent_from_catalog() {
|
||||
assert!(pack_by_id(SENTINEL_PACK_ID).is_none());
|
||||
assert!(PACK_CATALOG.iter().all(|p| p.id != SENTINEL_PACK_ID));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn clean_v1_empty_emits_no_mypacks_group() {
|
||||
let got = build_purchasegroup(&[], StoreMode::CleanV1);
|
||||
let ids: Vec<u64> = got["purchase"]
|
||||
.as_array()
|
||||
.unwrap()
|
||||
.iter()
|
||||
.map(|e| e["id"].as_u64().unwrap())
|
||||
.collect();
|
||||
assert_eq!(ids, vec![1, 5, 6, 7]);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn category_tokens_are_canonical() {
|
||||
assert_eq!(category(pack_by_id(1).unwrap()), "bronze");
|
||||
assert_eq!(category(pack_by_id(5).unwrap()), "gold");
|
||||
assert_eq!(category(pack_by_id(7).unwrap()), "special");
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,726 @@
|
||||
//! FIFA 17 empty-My-Packs capability negotiation — per-session state machine.
|
||||
//!
|
||||
//! This is the Rust production port of the *novel* session/capability logic that
|
||||
//! was proven live on staging and currently lives in the Python oracle
|
||||
//! (`fifa17-recon/tools/utas_server.py`, "FIFA17 empty-My-Packs capability
|
||||
//! negotiation"). Python remains the behavioural **reference/oracle**; this module
|
||||
//! is the intended production **authority** for the machinery so new FUT session
|
||||
//! behaviour stops accumulating in Python.
|
||||
//!
|
||||
//! ## Scope (deliberately bounded)
|
||||
//!
|
||||
//! This module owns the pure state machine only:
|
||||
//! * per-login session table keyed by the unique UTAS session id (`X-UT-SID`),
|
||||
//! * the single-use `(ip, persona)` launcher→session capability hand-off (pending),
|
||||
//! * capability binding (`bound` / `pending` / `ignored-late`),
|
||||
//! * the once-per-session empty-My-Packs freeze (`clean-v1` vs `sentinel`),
|
||||
//! * TTL reaping and fail-closed rules (unknown / expired / ambiguous / late /
|
||||
//! cross-session / sid-ip-mismatch ⇒ sentinel).
|
||||
//!
|
||||
//! It has **no** HTTP, Core, or IO dependencies, and it does **not** reproduce the
|
||||
//! delicate `_pack_body` UTAS wire shaping (utas_server.py:3474 — a type-sensitive,
|
||||
//! reverse-engineered body where a wrong scalar type silently breaks pack buying).
|
||||
//! That shaping, the `/ut/auth` persona-adoption, `/store/purchasegroup` catalogue
|
||||
//! assembly, and the store BUY path remain Python-owned until a separate, carefully
|
||||
//! differential-tested slice ports them. Wiring these three routes
|
||||
//! (`/ut/auth` SID, `/openfut/fifa17/capability`, `/store/purchasegroup`) into
|
||||
//! `openfut-utas-host` against this state machine — without dividing store authority
|
||||
//! (i.e. porting BUY too, so purchasegroup display and buy validation don't split) —
|
||||
//! is the remaining bounded gap toward full Rust authority.
|
||||
//!
|
||||
//! ## Purity / testability
|
||||
//!
|
||||
//! The monotonic clock is injected (`now: f64` seconds) rather than read from a
|
||||
//! global, so every A–R matrix scenario is a deterministic unit test. SID entropy
|
||||
//! is likewise injected ([`format_sid`]) — the host supplies a unique 64-bit value;
|
||||
//! the Python oracle notes uniqueness (not unpredictability) is the requirement.
|
||||
|
||||
use std::collections::HashMap;
|
||||
|
||||
/// The single capability this negotiation understands.
|
||||
pub const CAPABILITY_NAME: &str = "empty_mypacks_resolver";
|
||||
/// The only accepted resolver version (FIFA17 CardsDLL guard at RVA `0x14858`).
|
||||
pub const EMPTY_MYPACKS_RESOLVER_VERSION: u32 = 1;
|
||||
/// Synthetic non-openable pack id — the universal P2 sentinel. Deliberately ABSENT
|
||||
/// from the store `PACK_CATALOG`, so it can never be bought/opened/granted.
|
||||
pub const SENTINEL_PACK_ID: u64 = 65534;
|
||||
/// A FIFA session is reaped after this many idle seconds.
|
||||
pub const SESSION_TTL_SECS: f64 = 3600.0;
|
||||
/// A launcher capability may await its session for this long before expiring.
|
||||
pub const PENDING_TTL_SECS: f64 = 120.0;
|
||||
|
||||
/// The empty-My-Packs store topology, frozen once per session at its first store
|
||||
/// request and immutable thereafter.
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub enum StoreMode {
|
||||
/// Universal fallback: emit the synthetic non-openable [`SENTINEL_PACK_ID`] pack
|
||||
/// so the client's `mypacks` category resolves and does not crash.
|
||||
Sentinel,
|
||||
/// Verified patched client: emit NO `mypacks` group; the CardsDLL resolver guard
|
||||
/// routes the absent category to Browse.
|
||||
CleanV1,
|
||||
}
|
||||
|
||||
impl StoreMode {
|
||||
/// The wire token the Python oracle logs/uses (`"sentinel"` / `"clean-v1"`).
|
||||
pub fn as_str(self) -> &'static str {
|
||||
match self {
|
||||
StoreMode::Sentinel => "sentinel",
|
||||
StoreMode::CleanV1 => "clean-v1",
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Outcome of a launcher capability registration.
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub enum RegisterOutcome {
|
||||
/// Exactly one live, unfrozen, unbound session for `(ip, persona)` existed and
|
||||
/// was bound now (the common post-login case).
|
||||
Bound,
|
||||
/// No session for `(ip, persona)` yet (registration before login): staged as a
|
||||
/// single-use pending hand-off.
|
||||
Pending,
|
||||
/// A session for `(ip, persona)` exists but is frozen or ambiguous (>1 unbound):
|
||||
/// NOT staged, so no later/unverified process can inherit it. Fail-closed.
|
||||
IgnoredLate,
|
||||
}
|
||||
|
||||
/// Rejection reason for a capability POST body (maps to HTTP 400 at the route).
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub enum CapabilityError {
|
||||
/// Capability name or version is not the supported `empty_mypacks_resolver` v1.
|
||||
Unsupported,
|
||||
}
|
||||
|
||||
/// Validate a capability registration request body. Anything but the supported
|
||||
/// `empty_mypacks_resolver` at the current version is rejected — the session then
|
||||
/// simply stays on the sentinel fallback (the route records nothing).
|
||||
pub fn validate_capability(name: &str, version: u32) -> Result<(), CapabilityError> {
|
||||
if name == CAPABILITY_NAME && version == EMPTY_MYPACKS_RESOLVER_VERSION {
|
||||
Ok(())
|
||||
} else {
|
||||
Err(CapabilityError::Unsupported)
|
||||
}
|
||||
}
|
||||
|
||||
/// Format a unique per-login UTAS session id from a caller-supplied 64-bit value.
|
||||
/// Same shape/length as the legacy constant; uniqueness — not unpredictability — is
|
||||
/// what the binding needs, so the host may use any unique source (random or counter).
|
||||
pub fn format_sid(bits: u64) -> String {
|
||||
format!("OPENFUT-SID-{bits:016X}")
|
||||
}
|
||||
|
||||
/// The identity of the synthetic empty-My-Packs sentinel pack (utas_server.py:3671).
|
||||
/// This is the *identity* only; the full UTAS `purchase[]` entry is produced by the
|
||||
/// Python `_pack_body` shaping, which is intentionally not ported here.
|
||||
#[derive(Debug, Clone, Copy, PartialEq)]
|
||||
pub struct SentinelPack {
|
||||
pub id: u64,
|
||||
pub price: u64,
|
||||
pub count: u64,
|
||||
pub gold: bool,
|
||||
pub special_chance: f64,
|
||||
}
|
||||
|
||||
impl SentinelPack {
|
||||
/// The v1 sentinel: empty, free, non-openable. `_pack_body` additionally forces
|
||||
/// `state="active"` and `unopened=false` (owned) — documented here, applied by
|
||||
/// the shaping layer, not this module.
|
||||
pub fn v1() -> Self {
|
||||
SentinelPack {
|
||||
id: SENTINEL_PACK_ID,
|
||||
price: 0,
|
||||
count: 0,
|
||||
gold: true,
|
||||
special_chance: 0.0,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone)]
|
||||
struct Session {
|
||||
ip: Option<String>,
|
||||
persona: i64,
|
||||
resolver: Option<u32>,
|
||||
mode: Option<StoreMode>,
|
||||
last_seen: f64,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone)]
|
||||
struct Pending {
|
||||
resolver: u32,
|
||||
ts: f64,
|
||||
}
|
||||
|
||||
/// The per-session capability/store-mode authority. Not `Sync` itself; the host
|
||||
/// wraps it in a `Mutex` exactly as the Python oracle guards its tables with a lock.
|
||||
#[derive(Debug, Default)]
|
||||
pub struct SessionStore {
|
||||
sessions: HashMap<String, Session>,
|
||||
pending: HashMap<(Option<String>, i64), Pending>,
|
||||
}
|
||||
|
||||
impl SessionStore {
|
||||
/// A fresh, empty store.
|
||||
pub fn new() -> Self {
|
||||
Self::default()
|
||||
}
|
||||
|
||||
/// Reap idle sessions (> [`SESSION_TTL_SECS`]) and expired pendings
|
||||
/// (> [`PENDING_TTL_SECS`]). Called at the start of every mutating operation,
|
||||
/// mirroring the oracle's lazy reap.
|
||||
fn reap(&mut self, now: f64) {
|
||||
self.sessions
|
||||
.retain(|_, r| now - r.last_seen <= SESSION_TTL_SECS);
|
||||
self.pending.retain(|_, p| now - p.ts <= PENDING_TTL_SECS);
|
||||
}
|
||||
|
||||
/// Single-use: remove and return a fresh pending resolver for `(ip, persona)`.
|
||||
fn take_pending(&mut self, ip: &Option<String>, persona: i64, now: f64) -> Option<u32> {
|
||||
let key = (ip.clone(), persona);
|
||||
if let Some(p) = self.pending.get(&key) {
|
||||
if now - p.ts <= PENDING_TTL_SECS {
|
||||
let resolver = p.resolver;
|
||||
self.pending.remove(&key);
|
||||
return Some(resolver);
|
||||
}
|
||||
}
|
||||
None
|
||||
}
|
||||
|
||||
/// `/ut/auth`: open a per-login session and bind any pending launcher capability
|
||||
/// for `(ip, persona)` that arrived before login. An empty `sid` is a no-op.
|
||||
pub fn open_session(&mut self, sid: &str, ip: Option<String>, persona: i64, now: f64) {
|
||||
if sid.is_empty() {
|
||||
return;
|
||||
}
|
||||
self.reap(now);
|
||||
let resolver = self.take_pending(&ip, persona, now);
|
||||
self.sessions.insert(
|
||||
sid.to_string(),
|
||||
Session {
|
||||
ip,
|
||||
persona,
|
||||
resolver,
|
||||
mode: None,
|
||||
last_seen: now,
|
||||
},
|
||||
);
|
||||
}
|
||||
|
||||
/// `/openfut/account/sync` hygiene: drop any stale pending for this machine so a
|
||||
/// new launch's unverified session cannot inherit a leftover capability.
|
||||
pub fn clear_pending(&mut self, ip: &str, now: f64) {
|
||||
self.reap(now);
|
||||
let ip_key = Some(ip.to_string());
|
||||
self.pending.retain(|(k_ip, _), _| *k_ip != ip_key);
|
||||
}
|
||||
|
||||
/// Launcher capability registration. Never authorizes more than one session:
|
||||
/// binds iff exactly one live, unfrozen, unbound session for `(ip, persona)`
|
||||
/// exists; otherwise stages a single-use pending (no session yet) or fails
|
||||
/// closed as ignored-late (a session exists but is frozen/ambiguous).
|
||||
pub fn register_capability(
|
||||
&mut self,
|
||||
ip: Option<String>,
|
||||
persona: i64,
|
||||
version: u32,
|
||||
now: f64,
|
||||
) -> RegisterOutcome {
|
||||
self.reap(now);
|
||||
let mut any_for_key = false;
|
||||
let mut candidate: Option<String> = None;
|
||||
let mut candidate_count = 0usize;
|
||||
for (sid, r) in &self.sessions {
|
||||
if r.ip == ip && r.persona == persona {
|
||||
any_for_key = true;
|
||||
if r.mode.is_none() && r.resolver.is_none() {
|
||||
candidate = Some(sid.clone());
|
||||
candidate_count += 1;
|
||||
}
|
||||
}
|
||||
}
|
||||
if candidate_count == 1 {
|
||||
let sid = candidate.expect("exactly one candidate");
|
||||
self.sessions
|
||||
.get_mut(&sid)
|
||||
.expect("candidate session present")
|
||||
.resolver = Some(version);
|
||||
return RegisterOutcome::Bound;
|
||||
}
|
||||
if any_for_key {
|
||||
return RegisterOutcome::IgnoredLate;
|
||||
}
|
||||
self.pending.insert(
|
||||
(ip, persona),
|
||||
Pending {
|
||||
resolver: version,
|
||||
ts: now,
|
||||
},
|
||||
);
|
||||
RegisterOutcome::Pending
|
||||
}
|
||||
|
||||
/// True if `sid` is a live session. (The legacy constant SID is accepted only by
|
||||
/// the retired security-question gate in Python — never used to grant clean
|
||||
/// mode — and is intentionally not modelled here.)
|
||||
pub fn session_known(&self, sid: &str) -> bool {
|
||||
self.sessions.contains_key(sid)
|
||||
}
|
||||
|
||||
/// Freeze (once) and return the empty-My-Packs mode for FIFA session `sid`.
|
||||
/// Freeze point = the first `/store/purchasegroup` of the session. Fail-closed:
|
||||
/// an unknown session, or a `sid` presented from a different IP than it was
|
||||
/// opened on, resolves to [`StoreMode::Sentinel`] (and a mismatch does NOT freeze
|
||||
/// the real session, so a later correct-IP request can still freeze it).
|
||||
pub fn empty_mypacks_mode(&mut self, sid: &str, ip: Option<&str>, now: f64) -> StoreMode {
|
||||
self.reap(now);
|
||||
|
||||
// Resolve/take pending without holding a mutable borrow across the call.
|
||||
let (session_ip, persona, already_frozen, resolver) = match self.sessions.get(sid) {
|
||||
None => return StoreMode::Sentinel,
|
||||
Some(r) => (r.ip.clone(), r.persona, r.mode, r.resolver),
|
||||
};
|
||||
|
||||
if let Some(r) = self.sessions.get_mut(sid) {
|
||||
r.last_seen = now;
|
||||
}
|
||||
|
||||
// Fail-closed sid/ip sanity check (does not freeze).
|
||||
if let (Some(sess_ip), Some(req_ip)) = (session_ip.as_deref(), ip) {
|
||||
if sess_ip != req_ip {
|
||||
return StoreMode::Sentinel;
|
||||
}
|
||||
}
|
||||
|
||||
if let Some(mode) = already_frozen {
|
||||
return mode; // immutable per SID
|
||||
}
|
||||
|
||||
// First store request for this session: consume a still-pending capability
|
||||
// if the session was opened before the launcher registered, then freeze.
|
||||
let resolver = match resolver {
|
||||
Some(v) => Some(v),
|
||||
None => self.take_pending(&session_ip, persona, now),
|
||||
};
|
||||
let mode = if resolver == Some(EMPTY_MYPACKS_RESOLVER_VERSION) {
|
||||
StoreMode::CleanV1
|
||||
} else {
|
||||
StoreMode::Sentinel
|
||||
};
|
||||
if let Some(r) = self.sessions.get_mut(sid) {
|
||||
r.resolver = resolver;
|
||||
r.mode = Some(mode);
|
||||
}
|
||||
mode
|
||||
}
|
||||
|
||||
/// Store-catalogue decision for a `/store/purchasegroup` request. Mirrors the
|
||||
/// oracle's `if not owned_ids:` gate: with owned unopened packs the real
|
||||
/// `mypacks` group is served and no freeze occurs (`None`); only an *empty*
|
||||
/// My Packs freezes and returns the topology mode.
|
||||
pub fn store_empty_mypacks(
|
||||
&mut self,
|
||||
sid: &str,
|
||||
ip: Option<&str>,
|
||||
has_unopened_packs: bool,
|
||||
now: f64,
|
||||
) -> Option<StoreMode> {
|
||||
if has_unopened_packs {
|
||||
return None;
|
||||
}
|
||||
Some(self.empty_mypacks_mode(sid, ip, now))
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
//! Ports the Python capability-negotiation matrix A–R
|
||||
//! (`fifa17-recon/tools/test_capability_negotiation.py`). Python is the oracle;
|
||||
//! these assertions must stay in lockstep with it.
|
||||
use super::*;
|
||||
|
||||
const IP1: &str = "10.10.0.105";
|
||||
const IP2: &str = "10.10.0.106";
|
||||
const PERSONA: i64 = 111001;
|
||||
|
||||
fn ip(s: &str) -> Option<String> {
|
||||
Some(s.to_string())
|
||||
}
|
||||
|
||||
// A: no-capability, zero packs -> sentinel
|
||||
#[test]
|
||||
fn a_no_capability_zero_packs_sentinel() {
|
||||
let mut s = SessionStore::new();
|
||||
s.open_session("sidA", ip(IP1), PERSONA, 0.0);
|
||||
assert_eq!(
|
||||
s.store_empty_mypacks("sidA", Some(IP1), false, 1.0),
|
||||
Some(StoreMode::Sentinel)
|
||||
);
|
||||
}
|
||||
|
||||
// B: verified v1, zero packs -> clean
|
||||
#[test]
|
||||
fn b_verified_v1_zero_packs_clean() {
|
||||
let mut s = SessionStore::new();
|
||||
s.open_session("sidB", ip(IP1), PERSONA, 0.0);
|
||||
assert_eq!(
|
||||
s.register_capability(ip(IP1), PERSONA, 1, 1.0),
|
||||
RegisterOutcome::Bound
|
||||
);
|
||||
assert_eq!(
|
||||
s.store_empty_mypacks("sidB", Some(IP1), false, 2.0),
|
||||
Some(StoreMode::CleanV1)
|
||||
);
|
||||
}
|
||||
|
||||
// C: real unopened pack + no capability -> genuine packs (no freeze/sentinel)
|
||||
#[test]
|
||||
fn c_real_pack_no_capability_genuine() {
|
||||
let mut s = SessionStore::new();
|
||||
s.open_session("sidC", ip(IP1), PERSONA, 0.0);
|
||||
assert_eq!(s.store_empty_mypacks("sidC", Some(IP1), true, 1.0), None);
|
||||
}
|
||||
|
||||
// D: real unopened pack + capability -> genuine packs (no freeze)
|
||||
#[test]
|
||||
fn d_real_pack_with_capability_genuine() {
|
||||
let mut s = SessionStore::new();
|
||||
s.open_session("sidD", ip(IP1), PERSONA, 0.0);
|
||||
assert_eq!(
|
||||
s.register_capability(ip(IP1), PERSONA, 1, 1.0),
|
||||
RegisterOutcome::Bound
|
||||
);
|
||||
assert_eq!(s.store_empty_mypacks("sidD", Some(IP1), true, 2.0), None);
|
||||
}
|
||||
|
||||
// E: unsupported version / capability -> endpoint rejects AND mode sentinel
|
||||
#[test]
|
||||
fn e_unsupported_capability_rejected_and_sentinel() {
|
||||
assert_eq!(validate_capability(CAPABILITY_NAME, 1), Ok(()));
|
||||
assert_eq!(
|
||||
validate_capability(CAPABILITY_NAME, 2),
|
||||
Err(CapabilityError::Unsupported)
|
||||
);
|
||||
assert_eq!(
|
||||
validate_capability("something_else", 1),
|
||||
Err(CapabilityError::Unsupported)
|
||||
);
|
||||
let mut s = SessionStore::new();
|
||||
s.open_session("sidE", ip(IP1), PERSONA, 0.0);
|
||||
// A rejected registration records nothing, so the session stays sentinel.
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidE", Some(IP1), 1.0),
|
||||
StoreMode::Sentinel
|
||||
);
|
||||
}
|
||||
|
||||
// F: late capability after sentinel freeze -> stays sentinel
|
||||
#[test]
|
||||
fn f_late_capability_after_sentinel_freeze_stays() {
|
||||
let mut s = SessionStore::new();
|
||||
s.open_session("sidF", ip(IP1), PERSONA, 0.0);
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidF", Some(IP1), 1.0),
|
||||
StoreMode::Sentinel
|
||||
);
|
||||
assert_eq!(
|
||||
s.register_capability(ip(IP1), PERSONA, 1, 2.0),
|
||||
RegisterOutcome::IgnoredLate
|
||||
);
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidF", Some(IP1), 3.0),
|
||||
StoreMode::Sentinel
|
||||
);
|
||||
}
|
||||
|
||||
// G: capability "disappears" after clean freeze -> stays clean (immutable)
|
||||
#[test]
|
||||
fn g_clean_freeze_immutable() {
|
||||
let mut s = SessionStore::new();
|
||||
s.open_session("sidG", ip(IP1), PERSONA, 0.0);
|
||||
assert_eq!(
|
||||
s.register_capability(ip(IP1), PERSONA, 1, 1.0),
|
||||
RegisterOutcome::Bound
|
||||
);
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidG", Some(IP1), 2.0),
|
||||
StoreMode::CleanV1
|
||||
);
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidG", Some(IP1), 3.0),
|
||||
StoreMode::CleanV1
|
||||
);
|
||||
}
|
||||
|
||||
// H: two IPs (A verified, B none) -> A clean, B sentinel (no global leak)
|
||||
#[test]
|
||||
fn h_two_ips_isolated() {
|
||||
let mut s = SessionStore::new();
|
||||
s.open_session("sidHa", ip(IP1), PERSONA, 0.0);
|
||||
s.open_session("sidHb", ip(IP2), PERSONA, 0.0);
|
||||
assert_eq!(
|
||||
s.register_capability(ip(IP1), PERSONA, 1, 1.0),
|
||||
RegisterOutcome::Bound
|
||||
);
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidHa", Some(IP1), 2.0),
|
||||
StoreMode::CleanV1
|
||||
);
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidHb", Some(IP2), 2.0),
|
||||
StoreMode::Sentinel
|
||||
);
|
||||
}
|
||||
|
||||
// I: new session after reset -> fresh unpatched -> sentinel
|
||||
#[test]
|
||||
fn i_fresh_session_sentinel() {
|
||||
let mut s = SessionStore::new();
|
||||
s.open_session("sidI", ip(IP1), PERSONA, 10.0);
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidI", Some(IP1), 11.0),
|
||||
StoreMode::Sentinel
|
||||
);
|
||||
}
|
||||
|
||||
// J: autopatch mismatch => never registers -> sentinel
|
||||
#[test]
|
||||
fn j_no_registration_sentinel() {
|
||||
let mut s = SessionStore::new();
|
||||
s.open_session("sidJ", ip(IP1), PERSONA, 0.0);
|
||||
// (no register_capability call at all)
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidJ", Some(IP1), 1.0),
|
||||
StoreMode::Sentinel
|
||||
);
|
||||
}
|
||||
|
||||
// K: SAME IP, two sessions (A patched, B not) -> A clean, B sentinel
|
||||
#[test]
|
||||
fn k_same_ip_two_sessions_isolated() {
|
||||
let mut s = SessionStore::new();
|
||||
s.open_session("sidKa", ip(IP1), PERSONA, 0.0);
|
||||
assert_eq!(
|
||||
s.register_capability(ip(IP1), PERSONA, 1, 1.0),
|
||||
RegisterOutcome::Bound
|
||||
);
|
||||
s.open_session("sidKb", ip(IP1), PERSONA, 2.0);
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidKa", Some(IP1), 3.0),
|
||||
StoreMode::CleanV1
|
||||
);
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidKb", Some(IP1), 3.0),
|
||||
StoreMode::Sentinel
|
||||
);
|
||||
}
|
||||
|
||||
// L: SAME IP+persona relaunch (old ok, new not) -> new session sentinel
|
||||
#[test]
|
||||
fn l_same_ip_persona_relaunch() {
|
||||
let mut s = SessionStore::new();
|
||||
s.open_session("sidLold", ip(IP1), PERSONA, 0.0);
|
||||
assert_eq!(
|
||||
s.register_capability(ip(IP1), PERSONA, 1, 1.0),
|
||||
RegisterOutcome::Bound
|
||||
);
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidLold", Some(IP1), 2.0),
|
||||
StoreMode::CleanV1
|
||||
);
|
||||
s.open_session("sidLnew", ip(IP1), PERSONA, 3.0);
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidLnew", Some(IP1), 4.0),
|
||||
StoreMode::Sentinel
|
||||
);
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidLold", Some(IP1), 5.0),
|
||||
StoreMode::CleanV1
|
||||
);
|
||||
}
|
||||
|
||||
// M: SAME IP, failed-patch second session -> first clean, second sentinel
|
||||
#[test]
|
||||
fn m_same_ip_failed_patch_second() {
|
||||
let mut s = SessionStore::new();
|
||||
s.open_session("sidMa", ip(IP1), PERSONA, 0.0);
|
||||
assert_eq!(
|
||||
s.register_capability(ip(IP1), PERSONA, 1, 1.0),
|
||||
RegisterOutcome::Bound
|
||||
);
|
||||
s.open_session("sidMb", ip(IP1), PERSONA, 2.0); // failed patch: never registers
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidMa", Some(IP1), 3.0),
|
||||
StoreMode::CleanV1
|
||||
);
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidMb", Some(IP1), 3.0),
|
||||
StoreMode::Sentinel
|
||||
);
|
||||
}
|
||||
|
||||
// N: late registration when sessions are frozen -> does not modify active,
|
||||
// and does not stage a pending that a later session could inherit.
|
||||
#[test]
|
||||
fn n_late_registration_no_effect() {
|
||||
let mut s = SessionStore::new();
|
||||
s.open_session("sidN", ip(IP1), PERSONA, 0.0);
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidN", Some(IP1), 1.0),
|
||||
StoreMode::Sentinel
|
||||
);
|
||||
assert_eq!(
|
||||
s.register_capability(ip(IP1), PERSONA, 1, 2.0),
|
||||
RegisterOutcome::IgnoredLate
|
||||
);
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidN", Some(IP1), 3.0),
|
||||
StoreMode::Sentinel
|
||||
);
|
||||
// No pending was staged, so a brand-new session cannot inherit it.
|
||||
s.open_session("sidN2", ip(IP1), PERSONA, 4.0);
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidN2", Some(IP1), 5.0),
|
||||
StoreMode::Sentinel
|
||||
);
|
||||
}
|
||||
|
||||
// O: session cleanup / TTL expiry -> capability gone, sentinel
|
||||
#[test]
|
||||
fn o_ttl_expiry() {
|
||||
// Pending expiry: registered before login, but login arrives too late.
|
||||
let mut s = SessionStore::new();
|
||||
assert_eq!(
|
||||
s.register_capability(ip(IP1), PERSONA, 1, 0.0),
|
||||
RegisterOutcome::Pending
|
||||
);
|
||||
s.open_session("sidO", ip(IP1), PERSONA, PENDING_TTL_SECS + 1.0);
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidO", Some(IP1), PENDING_TTL_SECS + 2.0),
|
||||
StoreMode::Sentinel
|
||||
);
|
||||
// Session expiry: a known session reaped after idle TTL becomes unknown.
|
||||
let mut s2 = SessionStore::new();
|
||||
s2.open_session("sidO2", ip(IP1), PERSONA, 0.0);
|
||||
assert_eq!(
|
||||
s2.empty_mypacks_mode("sidO2", Some(IP1), SESSION_TTL_SECS + 1.0),
|
||||
StoreMode::Sentinel
|
||||
);
|
||||
assert!(!s2.session_known("sidO2"));
|
||||
}
|
||||
|
||||
// P: duplicate registration for a session -> idempotent; no post-freeze change
|
||||
#[test]
|
||||
fn p_duplicate_registration_idempotent() {
|
||||
let mut s = SessionStore::new();
|
||||
s.open_session("sidP", ip(IP1), PERSONA, 0.0);
|
||||
assert_eq!(
|
||||
s.register_capability(ip(IP1), PERSONA, 1, 1.0),
|
||||
RegisterOutcome::Bound
|
||||
);
|
||||
// Second registration: the session is now bound (resolver set), so it is no
|
||||
// longer an unbound candidate -> ignored-late, and the outcome is unchanged.
|
||||
assert_eq!(
|
||||
s.register_capability(ip(IP1), PERSONA, 1, 2.0),
|
||||
RegisterOutcome::IgnoredLate
|
||||
);
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidP", Some(IP1), 3.0),
|
||||
StoreMode::CleanV1
|
||||
);
|
||||
}
|
||||
|
||||
// Q: register-before-login (pending consumed) -> clean; single-use
|
||||
#[test]
|
||||
fn q_register_before_login_pending_consumed() {
|
||||
let mut s = SessionStore::new();
|
||||
assert_eq!(
|
||||
s.register_capability(ip(IP1), PERSONA, 1, 0.0),
|
||||
RegisterOutcome::Pending
|
||||
);
|
||||
s.open_session("sidQ", ip(IP1), PERSONA, 1.0);
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidQ", Some(IP1), 2.0),
|
||||
StoreMode::CleanV1
|
||||
);
|
||||
// Single-use: a second login for the same (ip,persona) gets no capability.
|
||||
s.open_session("sidQ2", ip(IP1), PERSONA, 3.0);
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidQ2", Some(IP1), 4.0),
|
||||
StoreMode::Sentinel
|
||||
);
|
||||
}
|
||||
|
||||
// R: topology freeze immutable per SID -> no flip either way; new SID fresh
|
||||
#[test]
|
||||
fn r_topology_freeze_immutable_per_sid() {
|
||||
let mut s = SessionStore::new();
|
||||
s.open_session("sidR", ip(IP1), PERSONA, 0.0);
|
||||
assert_eq!(
|
||||
s.register_capability(ip(IP1), PERSONA, 1, 1.0),
|
||||
RegisterOutcome::Bound
|
||||
);
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidR", Some(IP1), 2.0),
|
||||
StoreMode::CleanV1
|
||||
);
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidR", Some(IP1), 3.0),
|
||||
StoreMode::CleanV1
|
||||
);
|
||||
// A brand-new SID from the same client is a fresh, unverified session.
|
||||
s.open_session("sidRnew", ip(IP1), PERSONA, 4.0);
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidRnew", Some(IP1), 5.0),
|
||||
StoreMode::Sentinel
|
||||
);
|
||||
}
|
||||
|
||||
// Extra: sid/ip mismatch is fail-closed and does NOT freeze the real session.
|
||||
#[test]
|
||||
fn sid_ip_mismatch_fails_closed_without_freezing() {
|
||||
let mut s = SessionStore::new();
|
||||
s.open_session("sidX", ip(IP1), PERSONA, 0.0);
|
||||
assert_eq!(
|
||||
s.register_capability(ip(IP1), PERSONA, 1, 1.0),
|
||||
RegisterOutcome::Bound
|
||||
);
|
||||
// Presented from the wrong IP: sentinel, but the session is not frozen.
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidX", Some(IP2), 2.0),
|
||||
StoreMode::Sentinel
|
||||
);
|
||||
// The genuine client (correct IP) still freezes clean.
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidX", Some(IP1), 3.0),
|
||||
StoreMode::CleanV1
|
||||
);
|
||||
}
|
||||
|
||||
// Extra: account_sync clears a stale pending for the machine.
|
||||
#[test]
|
||||
fn clear_pending_drops_stale_hand_off() {
|
||||
let mut s = SessionStore::new();
|
||||
assert_eq!(
|
||||
s.register_capability(ip(IP1), PERSONA, 1, 0.0),
|
||||
RegisterOutcome::Pending
|
||||
);
|
||||
s.clear_pending(IP1, 1.0);
|
||||
s.open_session("sidC1", ip(IP1), PERSONA, 2.0);
|
||||
assert_eq!(
|
||||
s.empty_mypacks_mode("sidC1", Some(IP1), 3.0),
|
||||
StoreMode::Sentinel
|
||||
);
|
||||
}
|
||||
|
||||
// Extra: format_sid shape matches the legacy constant length.
|
||||
#[test]
|
||||
fn format_sid_shape() {
|
||||
assert_eq!(
|
||||
format_sid(0x42C15A6F78DC6E74),
|
||||
"OPENFUT-SID-42C15A6F78DC6E74"
|
||||
);
|
||||
assert_eq!(format_sid(0).len(), "OPENFUT-SID-".len() + 16);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,79 @@
|
||||
//! # openfut-adapter-fifa17
|
||||
//!
|
||||
//! The FIFA 17 game adapter: everything that is true of *FIFA 17 specifically*
|
||||
//! and must therefore stay out of OpenFUT Core and out of the generic protocol
|
||||
//! crates.
|
||||
//!
|
||||
//! ## Layering
|
||||
//!
|
||||
//! ```text
|
||||
//! openfut-protocol-blaze generic Blaze: Fire2 framing, Heat2/TDF codec
|
||||
//! ▲
|
||||
//! openfut-adapter-fifa17 THIS: FIFA 17 command tables, response bodies,
|
||||
//! ▲ dispatch ordering, session identity
|
||||
//! OpenFUT Core game-independent FUT domain (not yet wired)
|
||||
//! ```
|
||||
//!
|
||||
//! A second title gets its own adapter crate and reuses the protocol layer
|
||||
//! underneath. Nothing here is written to be shared with one; if something in
|
||||
//! this crate turns out to be title-independent, it belongs one layer down.
|
||||
//!
|
||||
//! ## Modules
|
||||
//!
|
||||
//! * [`blaze`] — the Blaze/Fire2 RPC surface. Implemented, runtime validated.
|
||||
//! * [`redirector`] — the first hop's `<serverinstanceinfo>` response.
|
||||
//! Implemented; runtime validated against the retail client.
|
||||
//! * [`roster`] — the FUT roster-update response, the last gate before the hub.
|
||||
//! Implemented; not yet runtime validated.
|
||||
//! * [`fut`] — FUT/RS4 (UTAS) wire → Core semantic mappings; currently the
|
||||
//! owned-player ("My Squad") search: query parse + FIFA-id→name resolution +
|
||||
//! semantic filter/pagination. Pure mapping; no Rust UTAS host yet.
|
||||
//!
|
||||
//! Still served only by the Python backend: LSX/Origin (`:4216`), UTAS/RS4
|
||||
//! (`:8099`) and POW/EASFC (`:8094`). Roster XML (`:8081`) has an adapter here
|
||||
//! but no Rust host yet.
|
||||
//!
|
||||
//! **Nucleus (`:42131`) is deliberately not ported.** Instrumentation across
|
||||
//! every live session showed the client never dials it: the listener is bound,
|
||||
//! the handler logs unconditionally on connect, the client fetches the
|
||||
//! `OSDK_NUCLEUS` config that carries the URL — and makes zero requests. It is
|
||||
//! dead code on the observed path, so porting it would add an untested
|
||||
//! component for no parity gain. See the vault's Protocol Findings.
|
||||
//!
|
||||
//! ## Provenance
|
||||
//!
|
||||
//! Ported from `fifa17-recon/tools/blaze_responder_v3b.py`, the implementation
|
||||
//! that drove a retail FIFA 17 client from Origin login to an opened FUT pack.
|
||||
//! Parity is tested, not asserted: `fixtures/blaze_transactions.jsonl` records
|
||||
//! real request→response(s) transactions produced by the Python dispatcher, and
|
||||
//! `tests/oracle_parity.rs` replays them byte-for-byte.
|
||||
//!
|
||||
//! ## Not a server
|
||||
//!
|
||||
//! This crate answers frames. It opens no socket, terminates no TLS and owns no
|
||||
//! runtime. Hosting it is a separate, later decision — the Python backend
|
||||
//! remains the live runtime and nothing here is wired into it.
|
||||
//!
|
||||
//! ```
|
||||
//! use openfut_adapter_fifa17::blaze::{Adapter, AdapterConfig, Session};
|
||||
//! use openfut_protocol_blaze::fire2::{Header, MsgType};
|
||||
//! use openfut_protocol_blaze::heat2::Struct;
|
||||
//!
|
||||
//! let adapter = Adapter::new(AdapterConfig::loopback());
|
||||
//! let mut session = Session::new("session-key", 0x656E5553);
|
||||
//!
|
||||
//! // Util::ping
|
||||
//! let request = Header::new(0x0009, 0x0002, 1, MsgType::Message);
|
||||
//! let out = adapter.dispatch(&request, &Struct::new(), &mut session, 1_754_870_400);
|
||||
//!
|
||||
//! assert_eq!(out.len(), 1);
|
||||
//! assert_eq!(out[0].header.msg_type, MsgType::Reply);
|
||||
//! ```
|
||||
|
||||
pub mod blaze;
|
||||
pub mod fut;
|
||||
pub mod redirector;
|
||||
pub mod roster;
|
||||
pub mod tls;
|
||||
|
||||
pub use blaze::{Adapter, AdapterConfig, Session};
|
||||
@@ -0,0 +1,194 @@
|
||||
//! FIFA 17 Blaze redirector: the first hop.
|
||||
//!
|
||||
//! ```text
|
||||
//! FIFA 17 ──TLS──> redirector ──"connect to <ip>:<port>"──> plaintext Fire2 Blaze
|
||||
//! ```
|
||||
//!
|
||||
//! A different protocol from Blaze itself: HTTPS with an XML body (DirtySDK's
|
||||
//! ProtoHttp), not Fire2. Exactly one request is ever seen —
|
||||
//! `POST /redirector/getServerInstance` — observed 9 times across every live
|
||||
//! session with no other path.
|
||||
//!
|
||||
//! # Scope
|
||||
//!
|
||||
//! This module owns the **response**, which is game-specific. It does not own
|
||||
//! TLS or HTTP transport; that belongs to a host, exactly as the Blaze adapter
|
||||
//! owns dispatch while `openfut-blaze-host` owns the socket.
|
||||
//!
|
||||
//! # A TLS constraint that is not this module's problem, but is recorded here
|
||||
//!
|
||||
//! Every observed handshake negotiated `AES256-GCM-SHA384` — TLS 1.2 with
|
||||
//! **static RSA key exchange** (`TLS_RSA_WITH_AES_256_GCM_SHA384`), against a
|
||||
//! Python server offering `ALL:@SECLEVEL=0` and an RSA-2048 certificate
|
||||
//! (DirtySDK rejects ECDSA). `rustls` supports only forward-secret (EC)DHE
|
||||
//! suites, so it cannot serve that negotiation. Whether the client *offers*
|
||||
//! ECDHE at all is UNKNOWN — OpenSSL follows client preference by default, so
|
||||
//! preferring static RSA does not prove it is the only option. Instrument a
|
||||
//! real ClientHello before choosing a TLS stack.
|
||||
|
||||
use std::fmt::Write as _;
|
||||
|
||||
use crate::blaze::config::AdapterConfig;
|
||||
|
||||
/// The only request path the client ever uses.
|
||||
pub const REQUEST_PATH: &str = "/redirector/getServerInstance";
|
||||
|
||||
/// Where the client is told to find Blaze.
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub struct BlazeEndpoint {
|
||||
/// Advertised hostname or dotted-quad.
|
||||
pub host: String,
|
||||
pub port: u16,
|
||||
/// Whether the Blaze hop is TLS. **0 for FIFA 17** — the second hop is
|
||||
/// plaintext Fire2, which this field independently confirms.
|
||||
pub secure: bool,
|
||||
}
|
||||
|
||||
impl BlazeEndpoint {
|
||||
/// Both host and port come from configuration. Neither is a protocol
|
||||
/// constant: the client goes wherever this response sends it, so hardcoding
|
||||
/// either would make the deployment un-relocatable.
|
||||
pub fn from_config(cfg: &AdapterConfig) -> BlazeEndpoint {
|
||||
BlazeEndpoint {
|
||||
host: cfg.endpoints.advertise.clone(),
|
||||
port: cfg.endpoints.blaze_port,
|
||||
secure: false,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Dotted-quad to the decimal `u32` the client expects in `<ip>`.
|
||||
///
|
||||
/// Host byte order, so `127.0.0.1` is `2130706433` (`0x7F000001`). A non-IPv4
|
||||
/// advertise value (a hostname) has no numeric form; the oracle falls back to
|
||||
/// loopback rather than failing, and that behaviour is reproduced — the client
|
||||
/// reads `<hostname>` too, so the numeric field is not the only route.
|
||||
pub fn ip_to_u32(addr: &str) -> u32 {
|
||||
let octets: Vec<u32> = addr
|
||||
.split('.')
|
||||
.filter_map(|p| p.parse::<u32>().ok())
|
||||
.filter(|n| *n <= 255)
|
||||
.collect();
|
||||
if octets.len() == 4 {
|
||||
(octets[0] << 24) | (octets[1] << 16) | (octets[2] << 8) | octets[3]
|
||||
} else {
|
||||
(127 << 24) | 1
|
||||
}
|
||||
}
|
||||
|
||||
/// The `<serverinstanceinfo>` XML body.
|
||||
///
|
||||
/// `<address member="0">` is a `ServerAddress` union; member 0 selects the
|
||||
/// `ipAddress` variant `{hostname, ip, port}`. Tabs and newlines are part of
|
||||
/// the byte-exact output — the client does not care, but parity does.
|
||||
pub fn server_instance_info_xml(endpoint: &BlazeEndpoint) -> String {
|
||||
let mut s = String::with_capacity(320);
|
||||
s.push_str("<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n");
|
||||
s.push_str("<serverinstanceinfo>\n");
|
||||
s.push_str("\t<address member=\"0\">\n");
|
||||
s.push_str("\t\t<valu>\n");
|
||||
let _ = writeln!(s, "\t\t\t<hostname>{}</hostname>", endpoint.host);
|
||||
let _ = writeln!(s, "\t\t\t<ip>{}</ip>", ip_to_u32(&endpoint.host));
|
||||
let _ = writeln!(s, "\t\t\t<port>{}</port>", endpoint.port);
|
||||
s.push_str("\t\t</valu>\n");
|
||||
s.push_str("\t</address>\n");
|
||||
let _ = writeln!(s, "\t<secure>{}</secure>", u8::from(endpoint.secure));
|
||||
s.push_str("\t<trialservicename></trialservicename>\n");
|
||||
s.push_str("\t<defaultdnsaddress>0</defaultdnsaddress>\n");
|
||||
s.push_str("</serverinstanceinfo>\n");
|
||||
s
|
||||
}
|
||||
|
||||
/// The complete HTTP response, headers included.
|
||||
///
|
||||
/// `Connection: close` is the oracle's behaviour and the client accepts it —
|
||||
/// the redirector is a one-shot hop, unlike the long-lived Blaze connection.
|
||||
pub fn redirect_response(cfg: &AdapterConfig) -> Vec<u8> {
|
||||
let body = server_instance_info_xml(&BlazeEndpoint::from_config(cfg));
|
||||
let mut out = String::with_capacity(body.len() + 128);
|
||||
out.push_str("HTTP/1.1 200 OK\r\n");
|
||||
out.push_str("Content-Type: application/xml\r\n");
|
||||
let _ = write!(out, "Content-Length: {}\r\n", body.len());
|
||||
out.push_str("Connection: close\r\n\r\n");
|
||||
out.push_str(&body);
|
||||
out.into_bytes()
|
||||
}
|
||||
|
||||
/// Is this request line the one the client sends?
|
||||
///
|
||||
/// Diagnostics only: the oracle answers *any* request with the same body, so
|
||||
/// dispatch does not branch on this. Reproduced as-is — a redirector that
|
||||
/// started 404ing unexpected paths would be a behaviour change, not a fix.
|
||||
pub fn is_get_server_instance(request_line: &str) -> bool {
|
||||
request_line.starts_with("POST ") && request_line.contains(REQUEST_PATH)
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
fn cfg(advertise: &str) -> AdapterConfig {
|
||||
let mut c = AdapterConfig::loopback();
|
||||
c.endpoints.advertise = advertise.into();
|
||||
c
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn ip_encoding_is_host_order_decimal() {
|
||||
assert_eq!(ip_to_u32("127.0.0.1"), 2_130_706_433);
|
||||
assert_eq!(ip_to_u32("198.51.100.7"), 3_325_256_711);
|
||||
assert_eq!(ip_to_u32("203.0.113.42"), 3_405_803_818);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn a_non_ipv4_advertise_falls_back_to_loopback_like_the_oracle() {
|
||||
// The hostname element still carries the real value, so this is not a
|
||||
// dead end for the client.
|
||||
assert_eq!(ip_to_u32("blaze.example.com"), 2_130_706_433);
|
||||
assert_eq!(ip_to_u32("10.0.0"), 2_130_706_433);
|
||||
assert_eq!(ip_to_u32("999.1.1.1"), 2_130_706_433);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn secure_is_zero_confirming_the_plaintext_second_hop() {
|
||||
let body = server_instance_info_xml(&BlazeEndpoint::from_config(&cfg("203.0.113.42")));
|
||||
assert!(body.contains("<secure>0</secure>"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn response_advertises_the_configured_address_not_a_hardcoded_one() {
|
||||
let r = String::from_utf8(redirect_response(&cfg("198.51.100.7"))).unwrap();
|
||||
assert!(r.contains("<hostname>198.51.100.7</hostname>"));
|
||||
assert!(r.contains("<ip>3325256711</ip>"));
|
||||
assert!(r.contains("<port>42130</port>"));
|
||||
assert!(!r.contains("127.0.0.1"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn content_length_matches_the_body_exactly() {
|
||||
let bytes = redirect_response(&cfg("203.0.113.42"));
|
||||
let text = String::from_utf8(bytes).unwrap();
|
||||
let (head, body) = text.split_once("\r\n\r\n").expect("header/body split");
|
||||
let declared: usize = head
|
||||
.lines()
|
||||
.find_map(|l| l.strip_prefix("Content-Length: "))
|
||||
.and_then(|v| v.trim().parse().ok())
|
||||
.expect("content-length present");
|
||||
assert_eq!(
|
||||
declared,
|
||||
body.len(),
|
||||
"a wrong length would truncate the XML"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn recognises_the_only_observed_request_line() {
|
||||
assert!(is_get_server_instance(
|
||||
"POST /redirector/getServerInstance HTTP/1.1"
|
||||
));
|
||||
assert!(!is_get_server_instance(
|
||||
"GET /redirector/getServerInstance HTTP/1.1"
|
||||
));
|
||||
assert!(!is_get_server_instance("POST /something/else HTTP/1.1"));
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,219 @@
|
||||
//! The FUT roster-update response — "is there a squad update to download?".
|
||||
//!
|
||||
//! ```text
|
||||
//! FIFA 17 ──HTTPS GET /fifa17/fut/rosterupdate.xml──> <rosterupdate version="0"/>
|
||||
//! ```
|
||||
//!
|
||||
//! # Why this matters more than its size suggests
|
||||
//!
|
||||
//! `checkFUTRostersFlow` downloads this before entering FUT. On success it
|
||||
//! advances to the hub; on failure it aborts with *"An error occurred
|
||||
//! downloading the FUT Squad Update"*. It is the last gate before the hub, and
|
||||
//! because it is a separate TLS connection from the redirector it is also where
|
||||
//! a certificate mismatch elsewhere in the stack first becomes visible. Three
|
||||
//! redirector gates were lost to exactly that.
|
||||
//!
|
||||
//! # What the oracle actually puts on the wire
|
||||
//!
|
||||
//! `roster_server.py` uses `http.server.BaseHTTPRequestHandler`, which shapes
|
||||
//! the response in ways the handler code does not show:
|
||||
//!
|
||||
//! * the status line is **HTTP/1.0**, because `protocol_version` is left at its
|
||||
//! default — not HTTP/1.1, despite the client asking for 1.1
|
||||
//! * `send_response` emits `Server:` and `Date:` *before* any header the
|
||||
//! handler sets, so header order is Server, Date, Content-Type,
|
||||
//! Content-Length, Connection
|
||||
//! * **POST answers with headers only.** The handler writes the body `if method
|
||||
//! == "GET"`, so a POST advertises `Content-Length: 67` and then sends
|
||||
//! nothing. That is preserved here rather than corrected: it is the behaviour
|
||||
//! the retail client was proven against, and "obviously a bug" is exactly the
|
||||
//! kind of judgement that has been wrong before in this port.
|
||||
//!
|
||||
//! Any path gets the same answer — the oracle logs `self.path` and never routes
|
||||
//! on it. A reimplementation that started 404ing unknown paths would be a
|
||||
//! behaviour change, not a fix.
|
||||
|
||||
/// The path the client requests. Recorded for diagnostics; **not** used for
|
||||
/// routing, because the oracle does not route.
|
||||
pub const REQUEST_PATH: &str = "/fifa17/fut/rosterupdate.xml";
|
||||
|
||||
/// The "no update available" body, byte-for-byte from the oracle.
|
||||
pub const ROSTER_XML: &[u8] =
|
||||
b"<?xml version=\"1.0\" encoding=\"utf-8\"?>\n<rosterupdate version=\"0\"/>\n";
|
||||
|
||||
/// The `Server:` string the oracle emits.
|
||||
///
|
||||
/// Environment-derived, not protocol-derived: it is Python's version string,
|
||||
/// so it changes when the container's Python does. Kept as a default rather
|
||||
/// than hardcoded into the response builder so a host can match whatever the
|
||||
/// deployed oracle actually sends — the same reasoning that makes the
|
||||
/// advertised address configuration rather than a constant.
|
||||
pub const ORACLE_SERVER: &str = "BaseHTTP/0.6 Python/3.12.13";
|
||||
|
||||
/// Which of the oracle's three handlers a request lands in.
|
||||
///
|
||||
/// `Post` is distinct from `Head` in the oracle's *code* (it drains the request
|
||||
/// body first) but identical in its *response*, so the distinction is kept here
|
||||
/// for the host's benefit rather than the response builder's.
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub enum Method {
|
||||
Get,
|
||||
Head,
|
||||
Post,
|
||||
}
|
||||
|
||||
impl Method {
|
||||
/// Parse the request line's method. Unknown methods are `None` — the oracle
|
||||
/// only defines `do_GET`/`do_HEAD`/`do_POST`, and `BaseHTTPRequestHandler`
|
||||
/// answers anything else with its own 501, which is a different response
|
||||
/// this module deliberately does not claim to reproduce.
|
||||
pub fn parse(line0: &str) -> Option<Method> {
|
||||
match line0.split_whitespace().next()? {
|
||||
"GET" => Some(Method::Get),
|
||||
"HEAD" => Some(Method::Head),
|
||||
"POST" => Some(Method::Post),
|
||||
_ => None,
|
||||
}
|
||||
}
|
||||
|
||||
/// Only GET carries the body, per the oracle.
|
||||
pub fn carries_body(self) -> bool {
|
||||
matches!(self, Method::Get)
|
||||
}
|
||||
}
|
||||
|
||||
/// Build the response exactly as the oracle would.
|
||||
///
|
||||
/// `date` is supplied by the caller rather than read from the clock here, so
|
||||
/// this stays a pure function and the fixtures can pin it. Format is the one
|
||||
/// `BaseHTTPRequestHandler.date_time_string` produces: RFC 7231 IMF-fixdate,
|
||||
/// always GMT.
|
||||
pub fn roster_response(method: Method, server: &str, date: &str) -> Vec<u8> {
|
||||
let mut out = Vec::with_capacity(256);
|
||||
out.extend_from_slice(b"HTTP/1.0 200 OK\r\n");
|
||||
out.extend_from_slice(format!("Server: {server}\r\n").as_bytes());
|
||||
out.extend_from_slice(format!("Date: {date}\r\n").as_bytes());
|
||||
out.extend_from_slice(b"Content-Type: application/xml\r\n");
|
||||
// Always the body's length, even when no body follows. See the module note.
|
||||
out.extend_from_slice(format!("Content-Length: {}\r\n", ROSTER_XML.len()).as_bytes());
|
||||
out.extend_from_slice(b"Connection: close\r\n");
|
||||
out.extend_from_slice(b"\r\n");
|
||||
if method.carries_body() {
|
||||
out.extend_from_slice(ROSTER_XML);
|
||||
}
|
||||
out
|
||||
}
|
||||
|
||||
/// `Date:` in the oracle's format, from a Unix timestamp.
|
||||
///
|
||||
/// Implemented rather than pulled from a date crate to keep this crate
|
||||
/// dependency-free, matching the protocol layer's constraint. Civil-date
|
||||
/// conversion is the standard days-from-epoch algorithm.
|
||||
pub fn http_date(unix_secs: i64) -> String {
|
||||
const DAYS: [&str; 7] = ["Mon", "Tue", "Wed", "Thu", "Fri", "Sat", "Sun"];
|
||||
const MONTHS: [&str; 12] = [
|
||||
"Jan", "Feb", "Mar", "Apr", "May", "Jun", "Jul", "Aug", "Sep", "Oct", "Nov", "Dec",
|
||||
];
|
||||
let days = unix_secs.div_euclid(86_400);
|
||||
let secs = unix_secs.rem_euclid(86_400);
|
||||
// 1970-01-01 was a Thursday (index 3).
|
||||
let dow = DAYS[(days + 3).rem_euclid(7) as usize];
|
||||
|
||||
// days-from-civil, inverted (Howard Hinnant's algorithm).
|
||||
let z = days + 719_468;
|
||||
let era = z.div_euclid(146_097);
|
||||
let doe = z.rem_euclid(146_097);
|
||||
let yoe = (doe - doe / 1460 + doe / 36_524 - doe / 146_096) / 365;
|
||||
let y = yoe + era * 400;
|
||||
let doy = doe - (365 * yoe + yoe / 4 - yoe / 100);
|
||||
let mp = (5 * doy + 2) / 153;
|
||||
let d = doy - (153 * mp + 2) / 5 + 1;
|
||||
let m = if mp < 10 { mp + 3 } else { mp - 9 };
|
||||
let y = if m <= 2 { y + 1 } else { y };
|
||||
|
||||
format!(
|
||||
"{dow}, {d:02} {mon} {y} {h:02}:{mi:02}:{s:02} GMT",
|
||||
mon = MONTHS[(m - 1) as usize],
|
||||
h = secs / 3600,
|
||||
mi = (secs % 3600) / 60,
|
||||
s = secs % 60
|
||||
)
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn the_body_is_the_oracles_67_bytes() {
|
||||
assert_eq!(ROSTER_XML.len(), 67);
|
||||
assert!(ROSTER_XML.starts_with(b"<?xml version=\"1.0\" encoding=\"utf-8\"?>"));
|
||||
assert!(ROSTER_XML.ends_with(b"<rosterupdate version=\"0\"/>\n"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn only_get_carries_the_body() {
|
||||
let d = "Tue, 11 Aug 2026 05:15:13 GMT";
|
||||
let get = roster_response(Method::Get, ORACLE_SERVER, d);
|
||||
let head = roster_response(Method::Head, ORACLE_SERVER, d);
|
||||
let post = roster_response(Method::Post, ORACLE_SERVER, d);
|
||||
assert_eq!(get.len(), head.len() + ROSTER_XML.len());
|
||||
assert_eq!(head, post, "the oracle answers POST exactly as HEAD");
|
||||
}
|
||||
|
||||
/// The quirk, asserted so a future "cleanup" has to argue with a test.
|
||||
#[test]
|
||||
fn a_bodiless_response_still_advertises_the_body_length() {
|
||||
let r = roster_response(Method::Head, ORACLE_SERVER, "Tue, 11 Aug 2026 05:15:13 GMT");
|
||||
let text = String::from_utf8_lossy(&r);
|
||||
assert!(text.contains("Content-Length: 67"), "{text}");
|
||||
assert!(text.ends_with("\r\n\r\n"), "no body may follow");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn header_order_matches_basehttprequesthandler() {
|
||||
let r = roster_response(Method::Get, ORACLE_SERVER, "Tue, 11 Aug 2026 05:15:13 GMT");
|
||||
let text = String::from_utf8_lossy(&r);
|
||||
let order: Vec<&str> = [
|
||||
"Server:",
|
||||
"Date:",
|
||||
"Content-Type:",
|
||||
"Content-Length:",
|
||||
"Connection:",
|
||||
]
|
||||
.iter()
|
||||
.map(|h| text.find(h).map(|_| *h).unwrap_or("MISSING"))
|
||||
.collect();
|
||||
assert!(!order.contains(&"MISSING"), "{text}");
|
||||
let positions: Vec<usize> = order.iter().map(|h| text.find(h).unwrap()).collect();
|
||||
let mut sorted = positions.clone();
|
||||
sorted.sort_unstable();
|
||||
assert_eq!(
|
||||
positions, sorted,
|
||||
"headers out of the oracle's order:\n{text}"
|
||||
);
|
||||
assert!(
|
||||
text.starts_with("HTTP/1.0 200 OK\r\n"),
|
||||
"must be HTTP/1.0: {text}"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn methods_parse_and_unknown_ones_are_refused() {
|
||||
assert_eq!(Method::parse("GET /x HTTP/1.1"), Some(Method::Get));
|
||||
assert_eq!(Method::parse("HEAD /x HTTP/1.1"), Some(Method::Head));
|
||||
assert_eq!(Method::parse("POST /x HTTP/1.1"), Some(Method::Post));
|
||||
// Not reproduced on purpose: the oracle answers these with its own 501.
|
||||
assert_eq!(Method::parse("PUT /x HTTP/1.1"), None);
|
||||
assert_eq!(Method::parse(""), None);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn http_date_matches_the_oracles_format() {
|
||||
// 1786425313 == Tue, 11 Aug 2026 05:15:13 GMT, the captured fixture time.
|
||||
assert_eq!(http_date(1_786_425_313), "Tue, 11 Aug 2026 05:15:13 GMT");
|
||||
assert_eq!(http_date(0), "Thu, 01 Jan 1970 00:00:00 GMT");
|
||||
// A leap day, because the civil-date maths is the only real logic here.
|
||||
assert_eq!(http_date(1_709_164_800), "Thu, 29 Feb 2024 00:00:00 GMT");
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,141 @@
|
||||
//! FIFA 17's TLS profile — what the retail client was *observed* to offer.
|
||||
//!
|
||||
//! # Evidence, not assumption
|
||||
//!
|
||||
//! A retail FIFA 17 client was captured through a passive proxy while reaching
|
||||
//! the FUT hub. It offers **exactly eight suites, every one static-RSA**:
|
||||
//!
|
||||
//! ```text
|
||||
//! 0x009D TLS_RSA_WITH_AES_256_GCM_SHA384 0x0035 TLS_RSA_WITH_AES_256_CBC_SHA
|
||||
//! 0x009C TLS_RSA_WITH_AES_128_GCM_SHA256 0x002F TLS_RSA_WITH_AES_128_CBC_SHA
|
||||
//! 0x003D TLS_RSA_WITH_AES_256_CBC_SHA256 0x0005 TLS_RSA_WITH_RC4_128_SHA
|
||||
//! 0x003C TLS_RSA_WITH_AES_128_CBC_SHA256 0x0004 TLS_RSA_WITH_RC4_128_MD5
|
||||
//!
|
||||
//! client_version TLS 1.2 extensions: server_name, signature_algorithms only
|
||||
//! ```
|
||||
//!
|
||||
//! Zero forward-secret suites — which is why `rustls` cannot serve this client,
|
||||
//! and why the transport hosts link OpenSSL directly.
|
||||
//!
|
||||
//! # Deliberately not enabled
|
||||
//!
|
||||
//! * **RC4 and MD5.** The client offers them; it does not need them. It already
|
||||
//! negotiates `AES256-GCM-SHA384` against the Python oracle, so resurrecting
|
||||
//! RC4 for completeness would weaken the service for nothing.
|
||||
//! * **SSLv3.** Never.
|
||||
//! * **A lowered security level.** Not applied pre-emptively. The default
|
||||
//! policy is tried first; if a retail handshake fails because OpenSSL rejects
|
||||
//! something genuinely required, the narrowest possible change is made and
|
||||
//! documented — not a blanket `SECLEVEL=0`.
|
||||
//!
|
||||
//! # Why this is data and not code
|
||||
//!
|
||||
//! These are facts about FIFA 17, so they live in the FIFA 17 adapter rather
|
||||
//! than in `openfut-tls`, which must stay game-independent. They are plain
|
||||
//! strings so this crate keeps its lean dependency list: an adapter should not
|
||||
//! drag OpenSSL into the build of everything that reads a card table.
|
||||
//!
|
||||
//! Confirmed live on 2026-08-11: the retail client reached the FUT hub through
|
||||
//! a Rust host configured from exactly these values, negotiating
|
||||
//! `TLSv1.2 / AES256-GCM-SHA384` with `sni=winter15.gosredirector.ea.com`.
|
||||
|
||||
/// The suites enabled for FIFA 17: the six RSA+AES options the client offers,
|
||||
/// strongest first, in OpenSSL's pre-TLS-1.3 naming.
|
||||
///
|
||||
/// Order expresses preference; the client's own order put AES-256-GCM first
|
||||
/// anyway, which is what the live handshake selected.
|
||||
pub const CIPHER_LIST: &str =
|
||||
"AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-SHA256:AES128-SHA256:AES256-SHA:AES128-SHA";
|
||||
|
||||
/// Suites the observed client offers that are deliberately refused.
|
||||
pub const REFUSED_SUITES: [&str; 2] = ["RC4-SHA", "RC4-MD5"];
|
||||
|
||||
/// All eight suites the captured ClientHello offered, for handshake rehearsals.
|
||||
pub const OBSERVED_CLIENT_SUITES: &str =
|
||||
"AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-SHA256:AES128-SHA256:\
|
||||
AES256-SHA:AES128-SHA:RC4-SHA:RC4-MD5";
|
||||
|
||||
/// The SNI the retail client sends to the redirector.
|
||||
///
|
||||
/// Nothing routes on it — recorded so a rehearsal handshake matches the real
|
||||
/// one, and so a log line can show whether a connection came from the game or
|
||||
/// from a probe.
|
||||
pub const CLIENT_SNI: &str = "winter15.gosredirector.ea.com";
|
||||
|
||||
/// Protocol floor, as OpenSSL spells it.
|
||||
///
|
||||
/// The floor is NOT dropped to TLS 1.0 pre-emptively. The Python oracle permits
|
||||
/// it, but no evidence shows this client needs it, and "the oracle permits it"
|
||||
/// is not "the client requires it".
|
||||
pub const MIN_VERSION: &str = "TLSv1.2";
|
||||
|
||||
/// Protocol ceiling. The client offers no TLS 1.3, so the window is exact.
|
||||
pub const MAX_VERSION: &str = "TLSv1.2";
|
||||
|
||||
/// The suite the live retail handshake selected, and which a rehearsal is
|
||||
/// expected to reproduce.
|
||||
pub const EXPECTED_SUITE: &str = "AES256-GCM-SHA384";
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
/// The enabled list must be exactly the client's offer minus the refusals.
|
||||
/// Stated as a derivation so adding a suite to one constant without the
|
||||
/// other is a test failure rather than a silent divergence.
|
||||
#[test]
|
||||
fn the_enabled_list_is_the_offer_minus_the_refusals() {
|
||||
let offered: Vec<&str> = OBSERVED_CLIENT_SUITES.split(':').collect();
|
||||
let enabled: Vec<&str> = CIPHER_LIST.split(':').collect();
|
||||
let expected: Vec<&str> = offered
|
||||
.iter()
|
||||
.copied()
|
||||
.filter(|s| !REFUSED_SUITES.contains(s))
|
||||
.collect();
|
||||
assert_eq!(enabled, expected);
|
||||
assert_eq!(offered.len(), 8, "the capture showed eight suites");
|
||||
assert_eq!(enabled.len(), 6);
|
||||
}
|
||||
|
||||
/// Every enabled suite must be static RSA. An ECDHE suite slipping in would
|
||||
/// be silently useless to this client, which offers none.
|
||||
#[test]
|
||||
fn nothing_forward_secret_is_enabled() {
|
||||
for s in CIPHER_LIST.split(':') {
|
||||
assert!(
|
||||
!s.contains("ECDHE") && !s.contains("DHE"),
|
||||
"{s} is forward-secret; FIFA 17 offers no such suite"
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn rc4_and_md5_are_refused_not_merely_absent() {
|
||||
for s in REFUSED_SUITES {
|
||||
assert!(
|
||||
OBSERVED_CLIENT_SUITES.contains(s),
|
||||
"{s} must be one the client actually offers"
|
||||
);
|
||||
assert!(!CIPHER_LIST.contains(s), "{s} must not be enabled");
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn the_expected_suite_is_one_we_enable_and_the_client_offers() {
|
||||
assert!(CIPHER_LIST.split(':').any(|s| s == EXPECTED_SUITE));
|
||||
assert!(OBSERVED_CLIENT_SUITES
|
||||
.split(':')
|
||||
.any(|s| s == EXPECTED_SUITE));
|
||||
assert_eq!(
|
||||
CIPHER_LIST.split(':').next(),
|
||||
Some(EXPECTED_SUITE),
|
||||
"preference order should put the observed selection first"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn the_protocol_window_is_exactly_tls12() {
|
||||
assert_eq!(MIN_VERSION, "TLSv1.2");
|
||||
assert_eq!(MAX_VERSION, "TLSv1.2");
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,218 @@
|
||||
//! Deployment-address audit: the configured address must reach every
|
||||
//! client-visible endpoint, and nothing may quietly substitute its own.
|
||||
//!
|
||||
//! OpenFUT has to run on arbitrary addresses. The development topology is
|
||||
//! deployment configuration, not architecture, so no crate may contain a
|
||||
//! production destination, an advertised address, or a hidden localhost
|
||||
//! fallback.
|
||||
//!
|
||||
//! Two TEST-NET addresses are used throughout (RFC 5737), deliberately not the
|
||||
//! lab's real LAN addresses: a test that passes only because its constant
|
||||
//! happens to match the current lab proves nothing about relocatability.
|
||||
|
||||
use openfut_adapter_fifa17::blaze::{client_config, AdapterConfig, Endpoints};
|
||||
use openfut_adapter_fifa17::redirector;
|
||||
|
||||
/// TEST-NET-2 and TEST-NET-3. Never routable, never ours, and obviously not a
|
||||
/// lab address to anyone reading a failure.
|
||||
const ADDR_A: &str = "198.51.100.7";
|
||||
const ADDR_B: &str = "203.0.113.42";
|
||||
|
||||
fn cfg(advertise: &str) -> AdapterConfig {
|
||||
AdapterConfig::advertising(advertise)
|
||||
}
|
||||
|
||||
/// Every client-visible string a config produces, for wholesale comparison.
|
||||
fn client_visible_surface(cfg: &AdapterConfig) -> Vec<String> {
|
||||
let mut out = vec![
|
||||
cfg.utas_base(),
|
||||
cfg.nucleus_base(),
|
||||
cfg.pow_content_url(),
|
||||
String::from_utf8(redirector::redirect_response(cfg)).unwrap(),
|
||||
];
|
||||
for section in client_config::known_sections() {
|
||||
for (k, v) in client_config::rows_for(section, cfg) {
|
||||
out.push(format!("{section}/{k}={v}"));
|
||||
}
|
||||
}
|
||||
out
|
||||
}
|
||||
|
||||
/// (5) Changing the advertised host must update every applicable generated URL,
|
||||
/// with no recompilation and no leftovers.
|
||||
#[test]
|
||||
fn changing_the_advertised_host_updates_every_client_visible_url() {
|
||||
let a = client_visible_surface(&cfg(ADDR_A));
|
||||
let b = client_visible_surface(&cfg(ADDR_B));
|
||||
|
||||
assert_eq!(a.len(), b.len(), "the surface itself must not change shape");
|
||||
|
||||
let a_has = a.iter().filter(|s| s.contains(ADDR_A)).count();
|
||||
let b_has = b.iter().filter(|s| s.contains(ADDR_B)).count();
|
||||
assert!(a_has > 200, "expected the address throughout, saw {a_has}");
|
||||
assert_eq!(a_has, b_has, "the same entries must carry the new address");
|
||||
|
||||
// Nothing may retain the old address after reconfiguration.
|
||||
let stragglers: Vec<&String> = b.iter().filter(|s| s.contains(ADDR_A)).collect();
|
||||
assert!(
|
||||
stragglers.is_empty(),
|
||||
"these kept the previous address: {:?}",
|
||||
&stragglers[..stragglers.len().min(5)]
|
||||
);
|
||||
}
|
||||
|
||||
/// (1) A remote configuration must not silently become localhost anywhere.
|
||||
#[test]
|
||||
fn remote_configuration_never_silently_becomes_localhost() {
|
||||
let c = cfg(ADDR_A);
|
||||
// Allowlisted: two OAuth redirect targets that are literals in the oracle
|
||||
// and are never dialled (see the compatibility exceptions in the vault).
|
||||
const ALLOWED_LOOPBACK_KEYS: [&str; 2] = ["identityRedirectUri", "redirect_uri"];
|
||||
|
||||
for entry in client_visible_surface(&c) {
|
||||
if entry.contains("127.0.0.1") || entry.contains("localhost") {
|
||||
assert!(
|
||||
ALLOWED_LOOPBACK_KEYS.iter().any(|k| entry.contains(k)),
|
||||
"unexpected loopback in a remote configuration: {entry}"
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
// POW hosts in particular must derive from advertise, not fall back alone.
|
||||
assert!(c.endpoints.pow_content_host.starts_with(ADDR_A));
|
||||
assert!(c.endpoints.pow_host.starts_with(ADDR_A));
|
||||
assert!(c.pow_content_url().contains(ADDR_A));
|
||||
}
|
||||
|
||||
/// (3) Bind and advertise are different concepts and must never be conflated.
|
||||
#[test]
|
||||
fn bind_can_differ_from_advertise() {
|
||||
let mut c = cfg(ADDR_A);
|
||||
c.endpoints.bind = "0.0.0.0".into();
|
||||
|
||||
assert_eq!(c.endpoints.advertise, ADDR_A);
|
||||
assert_eq!(c.endpoints.bind, "0.0.0.0");
|
||||
// The advertised surface follows advertise, not bind.
|
||||
assert!(c.utas_base().contains(ADDR_A));
|
||||
assert!(!c.utas_base().contains("0.0.0.0"));
|
||||
|
||||
// COMPATIBILITY EXCEPTION, reproduced deliberately: nucleusConnect follows
|
||||
// BIND in the oracle. Instrumentation showed the client never dials it, so
|
||||
// this is cosmetic on the observed path. Asserted so the exception cannot
|
||||
// be "fixed" by accident without this test failing and forcing the decision
|
||||
// to be made explicitly.
|
||||
assert_eq!(c.nucleus_base(), "http://0.0.0.0:42131");
|
||||
}
|
||||
|
||||
/// (4) The advertised Blaze port must reach the redirect result.
|
||||
#[test]
|
||||
fn changing_the_blaze_port_changes_the_redirect() {
|
||||
let mut c = cfg(ADDR_A);
|
||||
let before = String::from_utf8(redirector::redirect_response(&c)).unwrap();
|
||||
assert!(before.contains("<port>42130</port>"));
|
||||
|
||||
c.endpoints.blaze_port = 42999;
|
||||
let after = String::from_utf8(redirector::redirect_response(&c)).unwrap();
|
||||
assert!(after.contains("<port>42999</port>"), "{after}");
|
||||
assert!(!after.contains("<port>42130</port>"));
|
||||
// And the advertised host still follows config.
|
||||
assert!(after.contains(&format!("<hostname>{ADDR_A}</hostname>")));
|
||||
}
|
||||
|
||||
/// The UTAS port is deployment configuration too, not a constant we own.
|
||||
#[test]
|
||||
fn changing_the_utas_port_changes_every_rs4_url() {
|
||||
let mut c = cfg(ADDR_A);
|
||||
assert!(c.utas_base().contains(":8099/"));
|
||||
|
||||
c.endpoints.utas_port = 9099;
|
||||
assert_eq!(c.utas_base(), format!("http://{ADDR_A}:9099/"));
|
||||
|
||||
let rows = client_config::rows_for("BlazeSDK", &c);
|
||||
let base = rows.iter().find(|(k, _)| k == "FUT_RS4_BASE_URL").unwrap();
|
||||
assert_eq!(base.1, format!("http://{ADDR_A}:9099/"));
|
||||
assert!(!rows.iter().any(|(_, v)| v.contains(":8099")));
|
||||
}
|
||||
|
||||
/// (6) No service-specific helper may construct an endpoint from a different
|
||||
/// source of truth than the central configuration.
|
||||
#[test]
|
||||
fn no_helper_bypasses_the_central_configuration() {
|
||||
// bind MUST differ from advertise here. With them equal, a helper that
|
||||
// wrongly reads `bind` is indistinguishable from one that reads
|
||||
// `advertise` — and reading `bind` is the single most likely bypass,
|
||||
// because the oracle really does it for nucleusConnect. Mutation-tested:
|
||||
// with bind == advertise this test could not detect that substitution.
|
||||
let mut c = cfg(ADDR_B);
|
||||
c.endpoints.bind = "0.0.0.0".into();
|
||||
|
||||
// Every URL-shaped helper resolves through the same Endpoints.
|
||||
assert!(c.utas_base().contains(ADDR_B));
|
||||
assert!(c.pow_content_url().contains(ADDR_B));
|
||||
let ep = redirector::BlazeEndpoint::from_config(&c);
|
||||
assert_eq!(
|
||||
ep.host, c.endpoints.advertise,
|
||||
"the redirector must advertise the ADVERTISED host, not the bind address"
|
||||
);
|
||||
assert_ne!(
|
||||
ep.host, c.endpoints.bind,
|
||||
"bind must not leak into the wire"
|
||||
);
|
||||
let xml = String::from_utf8(redirector::redirect_response(&c)).unwrap();
|
||||
assert!(xml.contains(ADDR_B));
|
||||
assert!(
|
||||
!xml.contains("0.0.0.0"),
|
||||
"the bind address must never reach the client"
|
||||
);
|
||||
assert_eq!(ep.port, c.endpoints.blaze_port);
|
||||
|
||||
// And the config table's URL tokens resolve through those same helpers,
|
||||
// rather than re-deriving a URL shape of their own.
|
||||
let rows = client_config::rows_for("BlazeSDK", &c);
|
||||
let base = rows.iter().find(|(k, _)| k == "FUT_RS4_BASE_URL").unwrap();
|
||||
assert_eq!(base.1, c.utas_base());
|
||||
let nucleus = rows.iter().find(|(k, _)| k == "nucleusConnect").unwrap();
|
||||
assert_eq!(nucleus.1, c.nucleus_base());
|
||||
}
|
||||
|
||||
/// (7) Mutating the configuration must make these tests fail — a suite that
|
||||
/// passes regardless of the configured address would prove nothing.
|
||||
#[test]
|
||||
fn configuration_mutations_are_detectable() {
|
||||
let a = cfg(ADDR_A);
|
||||
let b = cfg(ADDR_B);
|
||||
|
||||
// Each of these is what a mutation would have to defeat.
|
||||
assert_ne!(a.utas_base(), b.utas_base());
|
||||
assert_ne!(a.pow_content_url(), b.pow_content_url());
|
||||
assert_ne!(
|
||||
redirector::redirect_response(&a),
|
||||
redirector::redirect_response(&b)
|
||||
);
|
||||
assert_ne!(
|
||||
client_config::rows_for("BlazeSDK", &a),
|
||||
client_config::rows_for("BlazeSDK", &b)
|
||||
);
|
||||
|
||||
let mut port_changed = a.clone();
|
||||
port_changed.endpoints.blaze_port += 1;
|
||||
assert_ne!(
|
||||
redirector::redirect_response(&a),
|
||||
redirector::redirect_response(&port_changed)
|
||||
);
|
||||
}
|
||||
|
||||
/// Loopback must be a named, deliberate choice — not something a caller can
|
||||
/// reach by omission.
|
||||
#[test]
|
||||
fn loopback_is_explicit_not_a_default() {
|
||||
let l = Endpoints::loopback();
|
||||
assert_eq!(l.advertise, "127.0.0.1");
|
||||
assert!(l.pow_content_host.starts_with("127.0.0.1"));
|
||||
|
||||
// `Endpoints::default()` and `AdapterConfig::default()` deliberately do not
|
||||
// exist; this test documents that, and the crate would not compile if they
|
||||
// were reintroduced and used by accident elsewhere.
|
||||
let explicit = AdapterConfig::loopback();
|
||||
assert_eq!(explicit.endpoints.advertise, "127.0.0.1");
|
||||
}
|
||||
@@ -0,0 +1,199 @@
|
||||
{
|
||||
"purchase": [
|
||||
{
|
||||
"assetId": 1,
|
||||
"currencies": [
|
||||
{
|
||||
"finalFunds": 400,
|
||||
"funds": 400,
|
||||
"name": "coins"
|
||||
}
|
||||
],
|
||||
"description": "Bronze Pack",
|
||||
"displayGroup": {
|
||||
"value": "bronze"
|
||||
},
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 4,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 4,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"id": 1,
|
||||
"isPremium": false,
|
||||
"limitType": "NONE",
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 5,
|
||||
"goldQuantity": 0,
|
||||
"itemQuantity": 5,
|
||||
"rareQuantity": 0,
|
||||
"silverQuantity": 0
|
||||
},
|
||||
"packType": "BRONZE",
|
||||
"purchaseCount": 0,
|
||||
"purchaseLimit": 0,
|
||||
"quantity": 0,
|
||||
"saleType": "promo",
|
||||
"sortPriority": 1,
|
||||
"state": "active",
|
||||
"unopened": false
|
||||
},
|
||||
{
|
||||
"assetId": 5,
|
||||
"currencies": [
|
||||
{
|
||||
"finalFunds": 5000,
|
||||
"funds": 5000,
|
||||
"name": "coins"
|
||||
}
|
||||
],
|
||||
"description": "Gold Pack",
|
||||
"displayGroup": {
|
||||
"value": "gold"
|
||||
},
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 50,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 50,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"id": 5,
|
||||
"isPremium": false,
|
||||
"limitType": "NONE",
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"goldQuantity": 7,
|
||||
"itemQuantity": 7,
|
||||
"rareQuantity": 7,
|
||||
"silverQuantity": 0
|
||||
},
|
||||
"packType": "GOLD",
|
||||
"purchaseCount": 0,
|
||||
"purchaseLimit": 0,
|
||||
"quantity": 0,
|
||||
"saleType": "promo",
|
||||
"sortPriority": 2,
|
||||
"state": "active",
|
||||
"unopened": false
|
||||
},
|
||||
{
|
||||
"assetId": 6,
|
||||
"currencies": [
|
||||
{
|
||||
"finalFunds": 15000,
|
||||
"funds": 15000,
|
||||
"name": "coins"
|
||||
}
|
||||
],
|
||||
"description": "Premium Gold",
|
||||
"displayGroup": {
|
||||
"value": "gold"
|
||||
},
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 150,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 150,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"id": 6,
|
||||
"isPremium": false,
|
||||
"limitType": "NONE",
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"goldQuantity": 11,
|
||||
"itemQuantity": 11,
|
||||
"rareQuantity": 11,
|
||||
"silverQuantity": 0
|
||||
},
|
||||
"packType": "GOLD",
|
||||
"purchaseCount": 0,
|
||||
"purchaseLimit": 0,
|
||||
"quantity": 0,
|
||||
"saleType": "promo",
|
||||
"sortPriority": 3,
|
||||
"state": "active",
|
||||
"unopened": false
|
||||
},
|
||||
{
|
||||
"assetId": 7,
|
||||
"currencies": [
|
||||
{
|
||||
"finalFunds": 25000,
|
||||
"funds": 25000,
|
||||
"name": "coins"
|
||||
}
|
||||
],
|
||||
"description": "Special Players Pack",
|
||||
"displayGroup": {
|
||||
"value": "special"
|
||||
},
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 250,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 250,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"id": 7,
|
||||
"isPremium": false,
|
||||
"limitType": "NONE",
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"goldQuantity": 11,
|
||||
"itemQuantity": 11,
|
||||
"rareQuantity": 11,
|
||||
"silverQuantity": 0
|
||||
},
|
||||
"packType": "GOLD",
|
||||
"purchaseCount": 0,
|
||||
"purchaseLimit": 0,
|
||||
"quantity": 0,
|
||||
"saleType": "promo",
|
||||
"sortPriority": 4,
|
||||
"state": "active",
|
||||
"unopened": false
|
||||
},
|
||||
{
|
||||
"assetId": 70,
|
||||
"description": "Reward Special Players Pack",
|
||||
"displayGroup": {
|
||||
"priority": 1,
|
||||
"value": "mypacks"
|
||||
},
|
||||
"id": 70,
|
||||
"isPremium": false,
|
||||
"limitType": "NONE",
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"goldQuantity": 11,
|
||||
"itemQuantity": 11,
|
||||
"rareQuantity": 11,
|
||||
"silverQuantity": 0
|
||||
},
|
||||
"packType": "GOLD",
|
||||
"purchaseCount": 0,
|
||||
"purchaseLimit": 0,
|
||||
"quantity": 0,
|
||||
"saleType": "promo",
|
||||
"sortPriority": 1,
|
||||
"state": "active",
|
||||
"unopened": true
|
||||
}
|
||||
],
|
||||
"timestamp": 1596326400
|
||||
}
|
||||
@@ -0,0 +1,173 @@
|
||||
{
|
||||
"purchase": [
|
||||
{
|
||||
"assetId": 1,
|
||||
"currencies": [
|
||||
{
|
||||
"finalFunds": 400,
|
||||
"funds": 400,
|
||||
"name": "coins"
|
||||
}
|
||||
],
|
||||
"description": "Bronze Pack",
|
||||
"displayGroup": {
|
||||
"value": "bronze"
|
||||
},
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 4,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 4,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"id": 1,
|
||||
"isPremium": false,
|
||||
"limitType": "NONE",
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 5,
|
||||
"goldQuantity": 0,
|
||||
"itemQuantity": 5,
|
||||
"rareQuantity": 0,
|
||||
"silverQuantity": 0
|
||||
},
|
||||
"packType": "BRONZE",
|
||||
"purchaseCount": 0,
|
||||
"purchaseLimit": 0,
|
||||
"quantity": 0,
|
||||
"saleType": "promo",
|
||||
"sortPriority": 1,
|
||||
"state": "active",
|
||||
"unopened": false
|
||||
},
|
||||
{
|
||||
"assetId": 5,
|
||||
"currencies": [
|
||||
{
|
||||
"finalFunds": 5000,
|
||||
"funds": 5000,
|
||||
"name": "coins"
|
||||
}
|
||||
],
|
||||
"description": "Gold Pack",
|
||||
"displayGroup": {
|
||||
"value": "gold"
|
||||
},
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 50,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 50,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"id": 5,
|
||||
"isPremium": false,
|
||||
"limitType": "NONE",
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"goldQuantity": 7,
|
||||
"itemQuantity": 7,
|
||||
"rareQuantity": 7,
|
||||
"silverQuantity": 0
|
||||
},
|
||||
"packType": "GOLD",
|
||||
"purchaseCount": 0,
|
||||
"purchaseLimit": 0,
|
||||
"quantity": 0,
|
||||
"saleType": "promo",
|
||||
"sortPriority": 2,
|
||||
"state": "active",
|
||||
"unopened": false
|
||||
},
|
||||
{
|
||||
"assetId": 6,
|
||||
"currencies": [
|
||||
{
|
||||
"finalFunds": 15000,
|
||||
"funds": 15000,
|
||||
"name": "coins"
|
||||
}
|
||||
],
|
||||
"description": "Premium Gold",
|
||||
"displayGroup": {
|
||||
"value": "gold"
|
||||
},
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 150,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 150,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"id": 6,
|
||||
"isPremium": false,
|
||||
"limitType": "NONE",
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"goldQuantity": 11,
|
||||
"itemQuantity": 11,
|
||||
"rareQuantity": 11,
|
||||
"silverQuantity": 0
|
||||
},
|
||||
"packType": "GOLD",
|
||||
"purchaseCount": 0,
|
||||
"purchaseLimit": 0,
|
||||
"quantity": 0,
|
||||
"saleType": "promo",
|
||||
"sortPriority": 3,
|
||||
"state": "active",
|
||||
"unopened": false
|
||||
},
|
||||
{
|
||||
"assetId": 7,
|
||||
"currencies": [
|
||||
{
|
||||
"finalFunds": 25000,
|
||||
"funds": 25000,
|
||||
"name": "coins"
|
||||
}
|
||||
],
|
||||
"description": "Special Players Pack",
|
||||
"displayGroup": {
|
||||
"value": "special"
|
||||
},
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 250,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 250,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"id": 7,
|
||||
"isPremium": false,
|
||||
"limitType": "NONE",
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"goldQuantity": 11,
|
||||
"itemQuantity": 11,
|
||||
"rareQuantity": 11,
|
||||
"silverQuantity": 0
|
||||
},
|
||||
"packType": "GOLD",
|
||||
"purchaseCount": 0,
|
||||
"purchaseLimit": 0,
|
||||
"quantity": 0,
|
||||
"saleType": "promo",
|
||||
"sortPriority": 4,
|
||||
"state": "active",
|
||||
"unopened": false
|
||||
}
|
||||
],
|
||||
"timestamp": 1596326400
|
||||
}
|
||||
@@ -0,0 +1,199 @@
|
||||
{
|
||||
"purchase": [
|
||||
{
|
||||
"assetId": 1,
|
||||
"currencies": [
|
||||
{
|
||||
"finalFunds": 400,
|
||||
"funds": 400,
|
||||
"name": "coins"
|
||||
}
|
||||
],
|
||||
"description": "Bronze Pack",
|
||||
"displayGroup": {
|
||||
"value": "bronze"
|
||||
},
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 4,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 4,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"id": 1,
|
||||
"isPremium": false,
|
||||
"limitType": "NONE",
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 5,
|
||||
"goldQuantity": 0,
|
||||
"itemQuantity": 5,
|
||||
"rareQuantity": 0,
|
||||
"silverQuantity": 0
|
||||
},
|
||||
"packType": "BRONZE",
|
||||
"purchaseCount": 0,
|
||||
"purchaseLimit": 0,
|
||||
"quantity": 0,
|
||||
"saleType": "promo",
|
||||
"sortPriority": 1,
|
||||
"state": "active",
|
||||
"unopened": false
|
||||
},
|
||||
{
|
||||
"assetId": 5,
|
||||
"currencies": [
|
||||
{
|
||||
"finalFunds": 5000,
|
||||
"funds": 5000,
|
||||
"name": "coins"
|
||||
}
|
||||
],
|
||||
"description": "Gold Pack",
|
||||
"displayGroup": {
|
||||
"value": "gold"
|
||||
},
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 50,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 50,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"id": 5,
|
||||
"isPremium": false,
|
||||
"limitType": "NONE",
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"goldQuantity": 7,
|
||||
"itemQuantity": 7,
|
||||
"rareQuantity": 7,
|
||||
"silverQuantity": 0
|
||||
},
|
||||
"packType": "GOLD",
|
||||
"purchaseCount": 0,
|
||||
"purchaseLimit": 0,
|
||||
"quantity": 0,
|
||||
"saleType": "promo",
|
||||
"sortPriority": 2,
|
||||
"state": "active",
|
||||
"unopened": false
|
||||
},
|
||||
{
|
||||
"assetId": 6,
|
||||
"currencies": [
|
||||
{
|
||||
"finalFunds": 15000,
|
||||
"funds": 15000,
|
||||
"name": "coins"
|
||||
}
|
||||
],
|
||||
"description": "Premium Gold",
|
||||
"displayGroup": {
|
||||
"value": "gold"
|
||||
},
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 150,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 150,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"id": 6,
|
||||
"isPremium": false,
|
||||
"limitType": "NONE",
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"goldQuantity": 11,
|
||||
"itemQuantity": 11,
|
||||
"rareQuantity": 11,
|
||||
"silverQuantity": 0
|
||||
},
|
||||
"packType": "GOLD",
|
||||
"purchaseCount": 0,
|
||||
"purchaseLimit": 0,
|
||||
"quantity": 0,
|
||||
"saleType": "promo",
|
||||
"sortPriority": 3,
|
||||
"state": "active",
|
||||
"unopened": false
|
||||
},
|
||||
{
|
||||
"assetId": 7,
|
||||
"currencies": [
|
||||
{
|
||||
"finalFunds": 25000,
|
||||
"funds": 25000,
|
||||
"name": "coins"
|
||||
}
|
||||
],
|
||||
"description": "Special Players Pack",
|
||||
"displayGroup": {
|
||||
"value": "special"
|
||||
},
|
||||
"extPrice": {
|
||||
"finalPrice": {
|
||||
"amount": 250,
|
||||
"currency": "mtx"
|
||||
},
|
||||
"originalPrice": {
|
||||
"amount": 250,
|
||||
"currency": "mtx"
|
||||
}
|
||||
},
|
||||
"id": 7,
|
||||
"isPremium": false,
|
||||
"limitType": "NONE",
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"goldQuantity": 11,
|
||||
"itemQuantity": 11,
|
||||
"rareQuantity": 11,
|
||||
"silverQuantity": 0
|
||||
},
|
||||
"packType": "GOLD",
|
||||
"purchaseCount": 0,
|
||||
"purchaseLimit": 0,
|
||||
"quantity": 0,
|
||||
"saleType": "promo",
|
||||
"sortPriority": 4,
|
||||
"state": "active",
|
||||
"unopened": false
|
||||
},
|
||||
{
|
||||
"assetId": 65534,
|
||||
"description": "",
|
||||
"displayGroup": {
|
||||
"priority": 1,
|
||||
"value": "mypacks"
|
||||
},
|
||||
"id": 65534,
|
||||
"isPremium": false,
|
||||
"limitType": "NONE",
|
||||
"packContentInfo": {
|
||||
"bronzeQuantity": 0,
|
||||
"goldQuantity": 0,
|
||||
"itemQuantity": 0,
|
||||
"rareQuantity": 0,
|
||||
"silverQuantity": 0
|
||||
},
|
||||
"packType": "GOLD",
|
||||
"purchaseCount": 0,
|
||||
"purchaseLimit": 0,
|
||||
"quantity": 0,
|
||||
"saleType": "promo",
|
||||
"sortPriority": 1,
|
||||
"state": "active",
|
||||
"unopened": false
|
||||
}
|
||||
],
|
||||
"timestamp": 1596326400
|
||||
}
|
||||
@@ -0,0 +1,402 @@
|
||||
//! Differential tests: the Rust adapter against the Python Blaze responder.
|
||||
//!
|
||||
//! `openfut-protocol-blaze` proves the *codec* matches. This proves the layer
|
||||
//! that decides **what to say**: for each inbound frame, the exact frames that
|
||||
//! go back and their order.
|
||||
//!
|
||||
//! Every vector in `fixtures/blaze_transactions.jsonl` was produced by calling
|
||||
//! the real `blaze_responder_v3b.dispatch()`. Transactions replay in file order
|
||||
//! against a shared session per connection, so ordering-dependent behaviour is
|
||||
//! exercised rather than assumed — preAuth captures the locale that later ALOC
|
||||
//! fields echo, and login sets the auth code getAuthToken returns afterwards.
|
||||
//!
|
||||
//! Comparison is byte-for-byte, including frame count and order. A missing
|
||||
//! post-login notification or a reply where the oracle stays silent is a
|
||||
//! failure here, which is the whole point.
|
||||
//!
|
||||
//! Regenerate after any oracle change: python3 fixtures/generate.py
|
||||
|
||||
use std::collections::HashMap;
|
||||
|
||||
use openfut_adapter_fifa17::blaze::{Adapter, AdapterConfig, Endpoints, Identity, Session};
|
||||
use openfut_protocol_blaze::fire2::Frame;
|
||||
use openfut_protocol_blaze::heat2;
|
||||
use serde_json::Value as J;
|
||||
|
||||
fn records() -> Vec<J> {
|
||||
let path = format!(
|
||||
"{}/fixtures/blaze_transactions.jsonl",
|
||||
env!("CARGO_MANIFEST_DIR")
|
||||
);
|
||||
let text = std::fs::read_to_string(&path)
|
||||
.unwrap_or_else(|e| panic!("cannot read {path}: {e}\nrun: python3 fixtures/generate.py"));
|
||||
text.lines()
|
||||
.filter(|l| !l.trim().is_empty())
|
||||
.map(|l| serde_json::from_str(l).expect("fixture line is valid JSON"))
|
||||
.collect()
|
||||
}
|
||||
|
||||
fn unhex(s: &str) -> Vec<u8> {
|
||||
(0..s.len())
|
||||
.step_by(2)
|
||||
.map(|i| u8::from_str_radix(&s[i..i + 2], 16).expect("valid hex"))
|
||||
.collect()
|
||||
}
|
||||
|
||||
fn hex(b: &[u8]) -> String {
|
||||
b.iter().map(|x| format!("{x:02x}")).collect()
|
||||
}
|
||||
|
||||
fn st(j: &J, k: &str) -> String {
|
||||
j[k].as_str()
|
||||
.unwrap_or_else(|| panic!("{k} is a string"))
|
||||
.to_string()
|
||||
}
|
||||
|
||||
fn n(j: &J, k: &str) -> i64 {
|
||||
j[k].as_i64().unwrap_or_else(|| panic!("{k} is a number"))
|
||||
}
|
||||
|
||||
/// Rebuild the exact configuration the fixtures were generated under.
|
||||
///
|
||||
/// The generator uses deliberately non-loopback addresses, so an adapter that
|
||||
/// hardcoded one instead of reading its config fails loudly here rather than
|
||||
/// coincidentally matching a default.
|
||||
fn config_from(record: &J) -> (AdapterConfig, i64) {
|
||||
let id = &record["identity"];
|
||||
let identity = Identity {
|
||||
persona_id: n(id, "persona_id"),
|
||||
persona_name: st(id, "persona_name"),
|
||||
user_id: n(id, "user_id"),
|
||||
ext_id: n(id, "ext_id"),
|
||||
email: st(id, "email"),
|
||||
namespace: st(id, "namespace"),
|
||||
client_platform: n(id, "client_platform"),
|
||||
persona_status: n(id, "persona_status"),
|
||||
user_session_type: n(id, "user_session_type"),
|
||||
account_locale: n(id, "account_locale_int"),
|
||||
locale: st(id, "locale"),
|
||||
content_id: st(id, "content_id"),
|
||||
entitlement_tag: st(id, "entitlement_tag"),
|
||||
entitlement_group: st(id, "entitlement_group"),
|
||||
title_id: st(id, "title_id"),
|
||||
client_id: st(id, "client_id"),
|
||||
platform: st(id, "platform"),
|
||||
};
|
||||
let endpoints = Endpoints {
|
||||
advertise: st(record, "advertise"),
|
||||
bind: st(record, "bind"),
|
||||
pow_content_host: st(record, "pow_content_host"),
|
||||
pow_host: st(record, "pow_host"),
|
||||
..Endpoints::loopback()
|
||||
};
|
||||
let cfg = AdapterConfig {
|
||||
identity,
|
||||
endpoints,
|
||||
server_version: st(&record["identity"], "server_version"),
|
||||
};
|
||||
(cfg, n(record, "now"))
|
||||
}
|
||||
|
||||
struct Replay {
|
||||
adapter: Adapter,
|
||||
now: i64,
|
||||
sessions: HashMap<String, Session>,
|
||||
records: Vec<J>,
|
||||
}
|
||||
|
||||
fn setup() -> Replay {
|
||||
let records = records();
|
||||
let cfg_rec = records
|
||||
.iter()
|
||||
.find(|r| r["kind"] == "config")
|
||||
.expect("fixture carries a config record")
|
||||
.clone();
|
||||
let (cfg, now) = config_from(&cfg_rec);
|
||||
|
||||
let mut sessions = HashMap::new();
|
||||
for r in &records {
|
||||
if r["kind"] == "session" {
|
||||
// The session key is injected, not generated: it appears verbatim
|
||||
// in three responses, so a self-minted one could never match.
|
||||
sessions.insert(
|
||||
st(r, "id"),
|
||||
Session::new(st(r, "session_key"), n(r, "account_locale")),
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
Replay {
|
||||
adapter: Adapter::new(cfg),
|
||||
now,
|
||||
sessions,
|
||||
records,
|
||||
}
|
||||
}
|
||||
|
||||
/// The headline test: replay every transaction and require identical frames.
|
||||
#[test]
|
||||
fn dispatch_matches_python_oracle_byte_for_byte() {
|
||||
let mut rp = setup();
|
||||
let records = rp.records.clone();
|
||||
let mut checked = 0usize;
|
||||
|
||||
for rec in records.iter().filter(|r| r["kind"] == "tx") {
|
||||
let name = st(rec, "name");
|
||||
let sid = st(rec, "session");
|
||||
let request = unhex(&st(rec, "request_hex"));
|
||||
let expected: Vec<String> = rec["responses"]
|
||||
.as_array()
|
||||
.expect("responses array")
|
||||
.iter()
|
||||
.map(|f| f.as_str().unwrap().to_string())
|
||||
.collect();
|
||||
|
||||
let (frame, used) = Frame::parse(&request)
|
||||
.unwrap_or_else(|e| panic!("{name}: fixture request does not parse: {e}"));
|
||||
assert_eq!(used, request.len(), "{name}: trailing bytes in request");
|
||||
|
||||
let body = if frame.payload.is_empty() {
|
||||
heat2::Struct::new()
|
||||
} else {
|
||||
heat2::decode(&frame.payload)
|
||||
.unwrap_or_else(|e| panic!("{name}: request body is not valid TDF: {e}"))
|
||||
};
|
||||
|
||||
let session = rp.sessions.get_mut(&sid).expect("session declared");
|
||||
let out = rp.adapter.dispatch(&frame.header, &body, session, rp.now);
|
||||
|
||||
assert_eq!(
|
||||
out.len(),
|
||||
expected.len(),
|
||||
"\n{name}: produced {} frame(s), oracle produced {}",
|
||||
out.len(),
|
||||
expected.len()
|
||||
);
|
||||
for (idx, (got, want)) in out.iter().zip(expected.iter()).enumerate() {
|
||||
let got_hex = hex(&got.encode());
|
||||
if &got_hex != want {
|
||||
// Narrow the failure to header vs body before dumping bytes.
|
||||
let want_bytes = unhex(want);
|
||||
let got_bytes = got.encode();
|
||||
assert_eq!(
|
||||
hex(&got_bytes[..16.min(got_bytes.len())]),
|
||||
hex(&want_bytes[..16.min(want_bytes.len())]),
|
||||
"\n{name} frame {idx}: HEADER differs"
|
||||
);
|
||||
panic!(
|
||||
"\n{name} frame {idx}: BODY differs\n got {} bytes\n want {} bytes",
|
||||
got_bytes.len().saturating_sub(16),
|
||||
want_bytes.len().saturating_sub(16)
|
||||
);
|
||||
}
|
||||
}
|
||||
checked += 1;
|
||||
}
|
||||
|
||||
assert!(
|
||||
checked >= 40,
|
||||
"expected the full script, replayed {checked}"
|
||||
);
|
||||
}
|
||||
|
||||
/// Frame counts and ordering are part of the contract, so assert them
|
||||
/// separately from bytes — a rewrite that answered correctly but dropped a
|
||||
/// notification would otherwise fail with an unhelpful byte diff.
|
||||
#[test]
|
||||
fn frame_counts_and_ordering_match() {
|
||||
let mut rp = setup();
|
||||
let records = rp.records.clone();
|
||||
|
||||
for rec in records.iter().filter(|r| r["kind"] == "tx") {
|
||||
let name = st(rec, "name");
|
||||
let request = unhex(&st(rec, "request_hex"));
|
||||
let expected = rec["responses"].as_array().unwrap();
|
||||
|
||||
let (frame, _) = Frame::parse(&request).unwrap();
|
||||
let body = if frame.payload.is_empty() {
|
||||
heat2::Struct::new()
|
||||
} else {
|
||||
heat2::decode(&frame.payload).unwrap()
|
||||
};
|
||||
let session = rp.sessions.get_mut(&st(rec, "session")).unwrap();
|
||||
let out = rp.adapter.dispatch(&frame.header, &body, session, rp.now);
|
||||
|
||||
assert_eq!(out.len(), expected.len(), "{name}: frame count");
|
||||
|
||||
for (got, want_hex) in out.iter().zip(expected.iter()) {
|
||||
let want = Frame::parse(&unhex(want_hex.as_str().unwrap())).unwrap().0;
|
||||
assert_eq!(
|
||||
got.header.component, want.header.component,
|
||||
"{name}: component"
|
||||
);
|
||||
assert_eq!(got.header.command, want.header.command, "{name}: command");
|
||||
assert_eq!(got.header.msg_type, want.header.msg_type, "{name}: msgType");
|
||||
assert_eq!(got.header.msg_num, want.header.msg_num, "{name}: msgNum");
|
||||
assert_eq!(
|
||||
got.header.user_index, want.header.user_index,
|
||||
"{name}: userIndex"
|
||||
);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// The login burst is the sequence most likely to be silently wrong, so pin it
|
||||
/// explicitly rather than relying on it being buried in the byte comparison.
|
||||
#[test]
|
||||
fn login_emits_reply_then_exactly_three_pushes() {
|
||||
let rp = setup();
|
||||
let login = rp
|
||||
.records
|
||||
.iter()
|
||||
.find(|r| r["kind"] == "tx" && r["name"] == "login")
|
||||
.expect("login transaction present");
|
||||
|
||||
let frames: Vec<Frame> = login["responses"]
|
||||
.as_array()
|
||||
.unwrap()
|
||||
.iter()
|
||||
.map(|h| Frame::parse(&unhex(h.as_str().unwrap())).unwrap().0)
|
||||
.collect();
|
||||
|
||||
assert_eq!(frames.len(), 4, "reply + three UserSessions pushes");
|
||||
assert_eq!(
|
||||
frames[0].header.msg_type,
|
||||
openfut_protocol_blaze::fire2::MsgType::Reply
|
||||
);
|
||||
let notify_ids: Vec<u16> = frames[1..].iter().map(|f| f.header.command).collect();
|
||||
assert_eq!(notify_ids, vec![0x0008, 0x0001, 0x0002]);
|
||||
}
|
||||
|
||||
/// The generator uses non-loopback addresses, so any loopback literal left in a
|
||||
/// response means the adapter hardcoded something it should have read from
|
||||
/// config — the exact regression the client/server split was meant to prevent.
|
||||
///
|
||||
/// Two keys are genuine literals in the oracle, not substitution failures.
|
||||
/// Both are OAuth redirect targets the client never actually dials (the flow is
|
||||
/// forged), so the loopback is inert; they are allowlisted by key rather than
|
||||
/// by pattern so a third one cannot slip in unnoticed.
|
||||
const ALLOWED_LOOPBACK_KEYS: [&str; 2] = ["identityRedirectUri", "redirect_uri"];
|
||||
|
||||
#[test]
|
||||
fn no_response_hardcodes_a_loopback_address() {
|
||||
let mut rp = setup();
|
||||
let records = rp.records.clone();
|
||||
let advertise = "198.51.100.7";
|
||||
|
||||
for rec in records.iter().filter(|r| r["kind"] == "tx") {
|
||||
let name = st(rec, "name");
|
||||
let request = unhex(&st(rec, "request_hex"));
|
||||
let (frame, _) = Frame::parse(&request).unwrap();
|
||||
let body = if frame.payload.is_empty() {
|
||||
heat2::Struct::new()
|
||||
} else {
|
||||
heat2::decode(&frame.payload).unwrap()
|
||||
};
|
||||
let session = rp.sessions.get_mut(&st(rec, "session")).unwrap();
|
||||
let out = rp.adapter.dispatch(&frame.header, &body, session, rp.now);
|
||||
|
||||
for f in &out {
|
||||
let text = String::from_utf8_lossy(&f.payload);
|
||||
for (at, _) in text.match_indices("127.0.0.1") {
|
||||
// TDF strings are length-prefixed and NUL-terminated, so the
|
||||
// owning key sits shortly before the value. Look back far
|
||||
// enough to name it, and require it to be allowlisted.
|
||||
let start = at.saturating_sub(80);
|
||||
let context = &text[start..text.len().min(at + 64)];
|
||||
assert!(
|
||||
ALLOWED_LOOPBACK_KEYS.iter().any(|k| context.contains(k)),
|
||||
"\n{name}: unexpected loopback literal, context {context:?}"
|
||||
);
|
||||
}
|
||||
}
|
||||
// The advertised address must actually appear somewhere in the config
|
||||
// responses, or substitution silently did nothing.
|
||||
if name.starts_with("fetch_config") || name == "preauth" {
|
||||
let text = String::from_utf8_lossy(&out[0].payload);
|
||||
assert!(
|
||||
text.contains(advertise),
|
||||
"{name}: advertised address missing from the config payload"
|
||||
);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Session state must survive across RPCs on one connection, and must NOT leak
|
||||
/// between connections.
|
||||
#[test]
|
||||
fn session_state_is_per_connection() {
|
||||
let mut rp = setup();
|
||||
let records = rp.records.clone();
|
||||
for rec in records.iter().filter(|r| r["kind"] == "tx") {
|
||||
let request = unhex(&st(rec, "request_hex"));
|
||||
let (frame, _) = Frame::parse(&request).unwrap();
|
||||
let body = if frame.payload.is_empty() {
|
||||
heat2::Struct::new()
|
||||
} else {
|
||||
heat2::decode(&frame.payload).unwrap()
|
||||
};
|
||||
let session = rp.sessions.get_mut(&st(rec, "session")).unwrap();
|
||||
rp.adapter.dispatch(&frame.header, &body, session, rp.now);
|
||||
}
|
||||
|
||||
// "main" logged in with an auth code and an enUS preAuth.
|
||||
let main = &rp.sessions["main"];
|
||||
assert!(main.logged_in);
|
||||
assert_eq!(main.auth_code, "OPENFUT-TEST-AUTHCODE");
|
||||
assert_eq!(main.account_locale, 0x656E_5553);
|
||||
|
||||
// "locale" ran a deDE preAuth and a login carrying no AUTH member.
|
||||
let loc = &rp.sessions["locale"];
|
||||
assert_eq!(loc.account_locale, 0x6465_4445, "deDE locale captured");
|
||||
assert_eq!(loc.service_name, "fifa-2017-pc-de");
|
||||
assert!(loc.auth_code.is_empty());
|
||||
|
||||
// "fallbacks" never logged in.
|
||||
assert!(!rp.sessions["fallbacks"].logged_in);
|
||||
}
|
||||
|
||||
// ────────────────────────────── redirector ──────────────────────────────
|
||||
//
|
||||
// The first hop. A different protocol from Blaze — HTTPS with an XML body —
|
||||
// but the same rule: byte-for-byte against the oracle.
|
||||
|
||||
#[test]
|
||||
fn redirect_response_matches_python_oracle_byte_for_byte() {
|
||||
use openfut_adapter_fifa17::redirector;
|
||||
|
||||
let path = format!("{}/fixtures/redirector.json", env!("CARGO_MANIFEST_DIR"));
|
||||
let text = std::fs::read_to_string(&path).unwrap_or_else(|e| panic!("cannot read {path}: {e}"));
|
||||
let table: serde_json::Map<String, J> = serde_json::from_str(&text).expect("valid JSON");
|
||||
assert!(table.len() >= 3, "expected several advertised addresses");
|
||||
|
||||
for (advertise, want_hex) in &table {
|
||||
let mut cfg = AdapterConfig::loopback();
|
||||
cfg.endpoints.advertise = advertise.clone();
|
||||
|
||||
let got = redirector::redirect_response(&cfg);
|
||||
assert_eq!(
|
||||
hex(&got),
|
||||
want_hex.as_str().unwrap(),
|
||||
"\nredirector response differs for advertise={advertise}"
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
/// The advertised Blaze endpoint must follow config, and the fixtures use
|
||||
/// deliberately different addresses so a hardcoded one cannot pass.
|
||||
#[test]
|
||||
fn redirect_response_is_configurable_not_baked() {
|
||||
use openfut_adapter_fifa17::redirector;
|
||||
|
||||
let mut a = AdapterConfig::loopback();
|
||||
a.endpoints.advertise = "10.0.0.5".into();
|
||||
let mut b = AdapterConfig::loopback();
|
||||
b.endpoints.advertise = "10.0.0.6".into();
|
||||
|
||||
assert_ne!(
|
||||
redirector::redirect_response(&a),
|
||||
redirector::redirect_response(&b),
|
||||
"the advertised address must reach the wire"
|
||||
);
|
||||
}
|
||||
@@ -0,0 +1,122 @@
|
||||
//! The roster response, held against bytes captured from the live oracle.
|
||||
//!
|
||||
//! The fixture masks the two volatile fields (`Date:`, `Server:`) and records
|
||||
//! the observed `Server` string separately, so this can assert the full byte
|
||||
//! layout while still failing loudly if the oracle's Python version drifts away
|
||||
//! from the adapter's `ORACLE_SERVER` constant.
|
||||
|
||||
use openfut_adapter_fifa17::roster::{self, Method};
|
||||
|
||||
const MASK: &str = "<MASKED>";
|
||||
|
||||
fn fixture() -> String {
|
||||
let path = format!("{}/fixtures/roster.json", env!("CARGO_MANIFEST_DIR"));
|
||||
std::fs::read_to_string(&path)
|
||||
.unwrap_or_else(|e| panic!("roster fixtures missing at {path}: {e}"))
|
||||
}
|
||||
|
||||
/// Minimal extraction: the fixture is written by our own generator and is a
|
||||
/// flat object, so a JSON dependency would be overkill in a crate that has none.
|
||||
fn field(text: &str, key: &str) -> String {
|
||||
let needle = format!("\"{key}\"");
|
||||
let at = text
|
||||
.find(&needle)
|
||||
.unwrap_or_else(|| panic!("fixture has no {key}"));
|
||||
let rest = &text[at + needle.len()..];
|
||||
let colon = rest.find(':').expect("key: value");
|
||||
let open = rest[colon..].find('"').expect("value opens") + colon;
|
||||
let close = rest[open + 1..].find('"').expect("value closes");
|
||||
rest[open + 1..open + 1 + close].to_string()
|
||||
}
|
||||
|
||||
fn expected(method: &str) -> Vec<u8> {
|
||||
// Scope the search to the responses object so a key never matches elsewhere.
|
||||
let text = fixture();
|
||||
let at = text.find("\"responses\"").expect("responses");
|
||||
let hex = field(&text[at..], method);
|
||||
(0..hex.len())
|
||||
.step_by(2)
|
||||
.map(|i| u8::from_str_radix(&hex[i..i + 2], 16).expect("hex"))
|
||||
.collect()
|
||||
}
|
||||
|
||||
/// Re-apply the generator's masking so the comparison is like-for-like.
|
||||
fn mask(raw: &[u8]) -> Vec<u8> {
|
||||
let text = String::from_utf8_lossy(raw);
|
||||
let masked: String = text
|
||||
.split("\r\n")
|
||||
.map(|line| {
|
||||
if line.starts_with("Date: ") {
|
||||
format!("Date: {MASK}")
|
||||
} else if line.starts_with("Server: ") {
|
||||
format!("Server: {MASK}")
|
||||
} else {
|
||||
line.to_string()
|
||||
}
|
||||
})
|
||||
.collect::<Vec<_>>()
|
||||
.join("\r\n");
|
||||
masked.into_bytes()
|
||||
}
|
||||
|
||||
fn check(method: Method, name: &str) {
|
||||
let got = roster::roster_response(
|
||||
method,
|
||||
roster::ORACLE_SERVER,
|
||||
"Tue, 11 Aug 2026 05:15:13 GMT",
|
||||
);
|
||||
assert_eq!(
|
||||
String::from_utf8_lossy(&mask(&got)),
|
||||
String::from_utf8_lossy(&expected(name)),
|
||||
"{name} differs from the oracle"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn get_matches_the_oracle() {
|
||||
check(Method::Get, "GET");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn head_matches_the_oracle() {
|
||||
check(Method::Head, "HEAD");
|
||||
}
|
||||
|
||||
/// Including the quirk: headers advertising a body that never arrives.
|
||||
#[test]
|
||||
fn post_matches_the_oracle() {
|
||||
check(Method::Post, "POST");
|
||||
}
|
||||
|
||||
/// If the container's Python changes, `ORACLE_SERVER` is stale and every
|
||||
/// response this adapter builds is wrong in a byte the oracle would have got
|
||||
/// right. The fixture records what was actually observed so that drift is a
|
||||
/// test failure rather than a silent divergence.
|
||||
#[test]
|
||||
fn the_server_constant_still_matches_the_observed_oracle() {
|
||||
let observed = field(&fixture(), "observed_server");
|
||||
assert_eq!(
|
||||
roster::ORACLE_SERVER,
|
||||
observed,
|
||||
"roster::ORACLE_SERVER is stale — the oracle now sends {observed:?}. \
|
||||
Regenerate fixtures and update the constant."
|
||||
);
|
||||
}
|
||||
|
||||
/// The masking must not be able to hide a real difference. If `Date:` were
|
||||
/// dropped rather than masked, a response missing it entirely would still pass.
|
||||
#[test]
|
||||
fn masking_does_not_hide_a_missing_header() {
|
||||
let good = roster::roster_response(Method::Get, roster::ORACLE_SERVER, "X");
|
||||
let without_date: Vec<u8> = String::from_utf8_lossy(&good)
|
||||
.split("\r\n")
|
||||
.filter(|l| !l.starts_with("Date: "))
|
||||
.collect::<Vec<_>>()
|
||||
.join("\r\n")
|
||||
.into_bytes();
|
||||
assert_ne!(
|
||||
mask(&good),
|
||||
mask(&without_date),
|
||||
"masking collapsed a missing Date into a match"
|
||||
);
|
||||
}
|
||||
@@ -0,0 +1,457 @@
|
||||
//! Adapter-level squad read-after-write / round-trip fidelity, driven entirely by
|
||||
//! committed sanitized capture evidence.
|
||||
//!
|
||||
//! Pipeline exercised end to end, with NO database, socket, or Core:
|
||||
//!
|
||||
//! ```text
|
||||
//! captured PUT ─parse─▶ Fifa17SquadPut
|
||||
//! ─build─▶ ProposedSquad (canonical) + Fifa17SquadExtensionV1
|
||||
//! (simulate committed canonical state: the ProposedSquad IS what Core stored)
|
||||
//! ─project─▶ FIFA 17 squad wire object
|
||||
//! ```
|
||||
//!
|
||||
//! Fidelity is asserted by ownership class:
|
||||
//! CANONICAL player instance per index, formation, captain, bench split
|
||||
//! EXTENSION custom, kicktakers, manager, kit numbers (by player), squadType
|
||||
//! SHADOW chemistry/rating/starRating (client-reported, round-tripped as-is)
|
||||
//! DERIVED correct FIFA 17 item identity (wire id + resourceId)
|
||||
//!
|
||||
//! We assert *semantic wire fidelity*, not byte equality: the read oracle was
|
||||
//! produced by the pre-migration Python backend, whose display-only shadow fields
|
||||
//! (`untradeable`, `discardValue`) and server-*recomputed* chemistry are not the
|
||||
//! adapter's to reproduce.
|
||||
|
||||
use std::collections::HashMap;
|
||||
|
||||
use openfut_adapter_fifa17::fut::item::{CoreOwnedItem, Fifa17Identity, ItemIdentityResolver};
|
||||
use openfut_adapter_fifa17::fut::squad::{parse_squad_put, Fifa17SquadPut, SquadWireResolver};
|
||||
use openfut_adapter_fifa17::fut::squad_ext::{build_squad_write, SquadWriteBuild};
|
||||
use openfut_adapter_fifa17::fut::squad_projection::{
|
||||
project_squad, squad_list, user_mass_info_squad, ProjectionSlot, SquadExtInput,
|
||||
SquadProjection, SquadProjectionInput,
|
||||
};
|
||||
use serde_json::Value;
|
||||
|
||||
const PUT_BASELINE: &str = include_str!("../fixtures/utas/squad_put_f442.json");
|
||||
const PUT_SWAP: &str = include_str!("../fixtures/utas/squad_put_swap_f442.json");
|
||||
const PUT_F433: &str = include_str!("../fixtures/utas/squad_put_f433.json");
|
||||
const READ_ORACLE: &str = include_str!("../fixtures/utas/squad_read_usermassinfo.json");
|
||||
|
||||
// ---- host-role stand-ins (identity resolution, entity resolver) -------------
|
||||
|
||||
/// Wire→owned reverse map. In production the host builds this from the identity
|
||||
/// store; here every occupied wire id maps to a stable `oc-<wire>`.
|
||||
struct OcResolver;
|
||||
impl SquadWireResolver for OcResolver {
|
||||
fn owned_id_for_wire(&self, wire: i64) -> Option<String> {
|
||||
Some(format!("oc-{wire}"))
|
||||
}
|
||||
}
|
||||
|
||||
/// owned_card_id → FIFA identity, so two copies of one definition stay distinct.
|
||||
struct TableIdentity(HashMap<String, Fifa17Identity>);
|
||||
impl ItemIdentityResolver for TableIdentity {
|
||||
fn resolve(&self, it: &CoreOwnedItem) -> Option<Fifa17Identity> {
|
||||
self.0.get(&it.owned_card_id).copied()
|
||||
}
|
||||
}
|
||||
|
||||
/// Neutral entity resolver — badge/flag ids are covered by `fut::item` tests; the
|
||||
/// projector round-trip asserts item *identity* (wire id + asset), not entity ids.
|
||||
struct NoEntities;
|
||||
impl openfut_adapter_fifa17::fut::entities::ReverseEntityResolver for NoEntities {
|
||||
fn league_id(&self, _: &str) -> Option<u32> {
|
||||
None
|
||||
}
|
||||
fn team_id(&self, _: &str) -> Option<u32> {
|
||||
None
|
||||
}
|
||||
fn nation_id(&self, _: &str) -> Option<u32> {
|
||||
None
|
||||
}
|
||||
}
|
||||
|
||||
/// Build the owned-item map + identity table from the persisted read oracle, so
|
||||
/// every wire id used by the captures resolves to its real FIFA asset id/rating.
|
||||
/// Keyed by `oc-<wire>` to match `OcResolver`.
|
||||
fn oracle_tables() -> (HashMap<String, CoreOwnedItem>, TableIdentity) {
|
||||
let oracle: Value = serde_json::from_str(READ_ORACLE).unwrap();
|
||||
let mut owned = HashMap::new();
|
||||
let mut ident = HashMap::new();
|
||||
for p in oracle["players"].as_array().unwrap() {
|
||||
let it = &p["itemData"];
|
||||
let wire = it["id"].as_i64().unwrap();
|
||||
if wire == 0 {
|
||||
continue; // empty slot
|
||||
}
|
||||
let oc = format!("oc-{wire}");
|
||||
let asset = it["resourceId"].as_u64().unwrap() as u32;
|
||||
let attrs: Vec<u8> = it["attributeList"]
|
||||
.as_array()
|
||||
.unwrap()
|
||||
.iter()
|
||||
.map(|a| a["value"].as_u64().unwrap() as u8)
|
||||
.collect();
|
||||
owned.insert(
|
||||
oc.clone(),
|
||||
CoreOwnedItem {
|
||||
owned_card_id: oc.clone(),
|
||||
card_id: format!("def-{asset}"),
|
||||
rating: it["rating"].as_u64().unwrap() as u8,
|
||||
position: it["preferredPosition"].as_str().unwrap().to_string(),
|
||||
nation: String::new(),
|
||||
league: String::new(),
|
||||
club: String::new(),
|
||||
attributes: [attrs[0], attrs[1], attrs[2], attrs[3], attrs[4], attrs[5]],
|
||||
},
|
||||
);
|
||||
ident.insert(
|
||||
oc,
|
||||
Fifa17Identity {
|
||||
item_id: wire as u32,
|
||||
asset_id: asset,
|
||||
resource_id: asset,
|
||||
rareflag: 1,
|
||||
},
|
||||
);
|
||||
}
|
||||
(owned, TableIdentity(ident))
|
||||
}
|
||||
|
||||
/// The full pipeline: parse a captured PUT, build the canonical + extension, then
|
||||
/// project — treating the just-built canonical squad as Core's committed state.
|
||||
fn project_put(
|
||||
put: &Fifa17SquadPut,
|
||||
owned: &HashMap<String, CoreOwnedItem>,
|
||||
ident: &TableIdentity,
|
||||
) -> Value {
|
||||
let SquadWriteBuild {
|
||||
canonical,
|
||||
extension,
|
||||
} = build_squad_write(put, &OcResolver).expect("build must succeed for a full valid squad");
|
||||
let slots: Vec<ProjectionSlot> = canonical
|
||||
.slots
|
||||
.iter()
|
||||
.map(|s| ProjectionSlot {
|
||||
owned_card_id: s.owned_card_id.clone(),
|
||||
index: s.index,
|
||||
is_captain: s.is_captain,
|
||||
is_on_bench: s.is_on_bench,
|
||||
})
|
||||
.collect();
|
||||
let input = SquadProjectionInput {
|
||||
fifa_squad_id: canonical.squad_id,
|
||||
name: canonical.name.clone().unwrap_or_default(),
|
||||
formation: canonical.formation.clone().unwrap(),
|
||||
slots,
|
||||
ext: SquadExtInput::Fresh(extension),
|
||||
owned,
|
||||
};
|
||||
match project_squad(&input, ident, &NoEntities).unwrap() {
|
||||
SquadProjection::Projected(v) => v,
|
||||
other => panic!("expected Projected, got {other:?}"),
|
||||
}
|
||||
}
|
||||
|
||||
/// Map FIFA-array index → (wire item id, kit number) for the occupied slots of a
|
||||
/// projected or captured squad object.
|
||||
fn occupied(v: &Value) -> HashMap<i64, (i64, i64)> {
|
||||
v["players"]
|
||||
.as_array()
|
||||
.unwrap()
|
||||
.iter()
|
||||
.filter(|p| p["itemData"]["id"].as_i64().unwrap() != 0)
|
||||
.map(|p| {
|
||||
(
|
||||
p["index"].as_i64().unwrap(),
|
||||
(
|
||||
p["itemData"]["id"].as_i64().unwrap(),
|
||||
p["kitNumber"].as_i64().unwrap(),
|
||||
),
|
||||
)
|
||||
})
|
||||
.collect()
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn baseline_projects_the_known_squad_round_trip() {
|
||||
let (owned, ident) = oracle_tables();
|
||||
let put = parse_squad_put(PUT_BASELINE.as_bytes()).unwrap();
|
||||
let projected = project_put(&put, &owned, &ident);
|
||||
|
||||
// Fixed 23-slot array; 11 occupied at 0..=10.
|
||||
assert_eq!(projected["players"].as_array().unwrap().len(), 23);
|
||||
let put_v: Value = serde_json::from_str(PUT_BASELINE).unwrap();
|
||||
assert_eq!(
|
||||
occupied(&projected),
|
||||
occupied(&put_v),
|
||||
"wire id + kit per index round-trip"
|
||||
);
|
||||
|
||||
// CANONICAL: formation verbatim, captain follows the semantic player.
|
||||
assert_eq!(projected["formation"], "f442");
|
||||
assert_eq!(
|
||||
projected["captain"], 100000001,
|
||||
"captain is the player's WIRE id"
|
||||
);
|
||||
// EXTENSION: custom byte-identical, manager + squadType preserved.
|
||||
assert_eq!(projected["custom"], put_v["custom"]);
|
||||
assert_eq!(projected["manager"], put_v["manager"]);
|
||||
assert_eq!(projected["squadType"], "REGULAR_SQUAD");
|
||||
// SHADOW: client-reported values carried as-is (baseline chemistry 52).
|
||||
assert_eq!(projected["chemistry"], 52);
|
||||
assert_eq!(projected["rating"], 90);
|
||||
assert_eq!(projected["starRating"], 90);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn swap_moves_two_players_with_their_kits_and_round_trips() {
|
||||
// The swap PUT is baseline with two players rotated between slots. Projecting
|
||||
// build(swap) must reproduce the swap wire exactly, and the affected players'
|
||||
// kit numbers must have travelled with them (kit follows the player).
|
||||
let (owned, ident) = oracle_tables();
|
||||
let projected = project_put(
|
||||
&parse_squad_put(PUT_SWAP.as_bytes()).unwrap(),
|
||||
&owned,
|
||||
&ident,
|
||||
);
|
||||
let swap_v: Value = serde_json::from_str(PUT_SWAP).unwrap();
|
||||
let base_v: Value = serde_json::from_str(PUT_BASELINE).unwrap();
|
||||
|
||||
// CANONICAL: the projected occupancy per index matches the swap PUT exactly.
|
||||
assert_eq!(
|
||||
occupied(&projected),
|
||||
occupied(&swap_v),
|
||||
"player+kit per index round-trip"
|
||||
);
|
||||
|
||||
// The swap is real: at least two indices carry a different player than baseline.
|
||||
let (proj_occ, base_occ) = (occupied(&projected), occupied(&base_v));
|
||||
let moved: Vec<i64> = proj_occ
|
||||
.iter()
|
||||
.filter(|(idx, pair)| base_occ.get(idx).map(|b| b.0) != Some(pair.0))
|
||||
.map(|(idx, _)| *idx)
|
||||
.collect();
|
||||
assert!(
|
||||
moved.len() >= 2,
|
||||
"a swap changes at least two slots, got {moved:?}"
|
||||
);
|
||||
|
||||
// kit follows the PLAYER: for every player, its kit in baseline == its kit
|
||||
// in the swap projection, regardless of which slot it now occupies.
|
||||
let kit_by_player = |occ: &HashMap<i64, (i64, i64)>| -> HashMap<i64, i64> {
|
||||
occ.values().map(|(id, kit)| (*id, *kit)).collect()
|
||||
};
|
||||
assert_eq!(
|
||||
kit_by_player(&proj_occ),
|
||||
kit_by_player(&base_occ),
|
||||
"each player kept its kit number through the swap"
|
||||
);
|
||||
|
||||
assert_eq!(
|
||||
projected["captain"], 100000001,
|
||||
"captain follows the semantic player"
|
||||
);
|
||||
assert_eq!(
|
||||
projected["custom"], swap_v["custom"],
|
||||
"opaque custom unchanged by the swap"
|
||||
);
|
||||
// SHADOW: the client-reported chemistry from THIS PUT (58) is round-tripped
|
||||
// as-is — never reconciled to a server recompute.
|
||||
assert_eq!(projected["chemistry"], 58);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn persisted_read_round_trips_via_reconstructed_canonical_and_extension() {
|
||||
// Simulate Core's committed state for the persisted (post-relaunch) squad by
|
||||
// reconstructing the canonical slots + FIFA extension straight from the read
|
||||
// evidence, then project and require the read back — the strongest fidelity
|
||||
// check across all four ownership classes.
|
||||
use openfut_adapter_fifa17::fut::squad::ClientReportedSquadEval;
|
||||
use openfut_adapter_fifa17::fut::squad_ext::{
|
||||
Fifa17SquadExtensionV1, KicktakerRef, WireItemRef,
|
||||
};
|
||||
use std::collections::BTreeMap;
|
||||
|
||||
let oracle: Value = serde_json::from_str(READ_ORACLE).unwrap();
|
||||
let (owned, ident) = oracle_tables();
|
||||
let captain = oracle["captain"].as_i64().unwrap();
|
||||
|
||||
let mut slots = Vec::new();
|
||||
let mut kit_numbers = BTreeMap::new();
|
||||
for p in oracle["players"].as_array().unwrap() {
|
||||
let wire = p["itemData"]["id"].as_i64().unwrap();
|
||||
if wire == 0 {
|
||||
continue;
|
||||
}
|
||||
let index = p["index"].as_i64().unwrap();
|
||||
let oc = format!("oc-{wire}");
|
||||
kit_numbers.insert(oc.clone(), p["kitNumber"].as_i64().unwrap());
|
||||
slots.push(ProjectionSlot {
|
||||
owned_card_id: oc,
|
||||
index,
|
||||
is_captain: wire == captain,
|
||||
is_on_bench: index >= 11,
|
||||
});
|
||||
}
|
||||
let manager: Vec<WireItemRef> = serde_json::from_value(oracle["manager"].clone()).unwrap();
|
||||
let kicktakers: Vec<KicktakerRef> =
|
||||
serde_json::from_value(oracle["kicktakers"].clone()).unwrap();
|
||||
let ext = Fifa17SquadExtensionV1 {
|
||||
custom: oracle["custom"].as_str().map(str::to_string),
|
||||
squad_type: oracle["squadType"].as_str().map(str::to_string),
|
||||
kit_numbers,
|
||||
manager,
|
||||
kicktakers,
|
||||
client_reported: ClientReportedSquadEval {
|
||||
chemistry: oracle["chemistry"].as_i64(),
|
||||
rating: oracle["rating"].as_i64(),
|
||||
star_rating: oracle["starRating"].as_i64(),
|
||||
},
|
||||
};
|
||||
let input = SquadProjectionInput {
|
||||
fifa_squad_id: oracle["id"].as_i64().unwrap(),
|
||||
name: oracle["squadName"].as_str().unwrap().to_string(),
|
||||
formation: oracle["formation"].as_str().unwrap().to_string(),
|
||||
slots,
|
||||
ext: SquadExtInput::Fresh(ext),
|
||||
owned: &owned,
|
||||
};
|
||||
let SquadProjection::Projected(projected) = project_squad(&input, &ident, &NoEntities).unwrap()
|
||||
else {
|
||||
panic!("expected Projected");
|
||||
};
|
||||
|
||||
// CANONICAL + DERIVED: identity and placement per slot match the read.
|
||||
assert_eq!(
|
||||
occupied(&projected),
|
||||
occupied(&oracle),
|
||||
"player+kit per index"
|
||||
);
|
||||
assert_eq!(projected["captain"], oracle["captain"]);
|
||||
assert_eq!(projected["formation"], oracle["formation"]);
|
||||
for (pp, op) in projected["players"]
|
||||
.as_array()
|
||||
.unwrap()
|
||||
.iter()
|
||||
.zip(oracle["players"].as_array().unwrap())
|
||||
{
|
||||
assert_eq!(
|
||||
pp["itemData"]["id"], op["itemData"]["id"],
|
||||
"wire id per slot"
|
||||
);
|
||||
assert_eq!(
|
||||
pp["itemData"]["resourceId"], op["itemData"]["resourceId"],
|
||||
"asset id per slot"
|
||||
);
|
||||
assert_eq!(pp["itemData"]["rating"], op["itemData"]["rating"]);
|
||||
assert_eq!(
|
||||
pp["itemData"]["preferredPosition"],
|
||||
op["itemData"]["preferredPosition"]
|
||||
);
|
||||
}
|
||||
// EXTENSION + SHADOW: sourced from the read, so they round-trip identically.
|
||||
assert_eq!(projected["custom"], oracle["custom"]);
|
||||
assert_eq!(projected["manager"], oracle["manager"]);
|
||||
assert_eq!(projected["kicktakers"], oracle["kicktakers"]);
|
||||
assert_eq!(projected["squadType"], oracle["squadType"]);
|
||||
assert_eq!(projected["chemistry"], oracle["chemistry"]);
|
||||
assert_eq!(projected["rating"], oracle["rating"]);
|
||||
assert_eq!(projected["starRating"], oracle["starRating"]);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn formation_change_reindexes_without_deriving_slots_and_kit_follows_player() {
|
||||
let (owned, ident) = oracle_tables();
|
||||
let swap = project_put(
|
||||
&parse_squad_put(PUT_SWAP.as_bytes()).unwrap(),
|
||||
&owned,
|
||||
&ident,
|
||||
);
|
||||
let f433 = project_put(
|
||||
&parse_squad_put(PUT_F433.as_bytes()).unwrap(),
|
||||
&owned,
|
||||
&ident,
|
||||
);
|
||||
|
||||
assert_eq!(f433["formation"], "f433");
|
||||
assert_eq!(swap["formation"], "f442");
|
||||
|
||||
// Same 11 starters (same set of wire ids), reindexed.
|
||||
let set = |v: &Value| {
|
||||
let mut ids: Vec<i64> = occupied(v).values().map(|(id, _)| *id).collect();
|
||||
ids.sort();
|
||||
ids
|
||||
};
|
||||
assert_eq!(
|
||||
set(&swap),
|
||||
set(&f433),
|
||||
"same 11 players survive the formation change"
|
||||
);
|
||||
|
||||
// The captain (wire 100000001) moved from index 8 (f442) to index 10 (f433) —
|
||||
// proof indices are round-tripped, not derived from the formation.
|
||||
let idx_of = |v: &Value, wire: i64| -> i64 {
|
||||
occupied(v)
|
||||
.into_iter()
|
||||
.find(|(_, (id, _))| *id == wire)
|
||||
.unwrap()
|
||||
.0
|
||||
};
|
||||
assert_eq!(idx_of(&swap, 100000001), 8);
|
||||
assert_eq!(idx_of(&f433, 100000001), 10);
|
||||
|
||||
// kit follows the PLAYER, not the slot: captain keeps kit 8 across the reindex.
|
||||
let kit_of = |v: &Value, wire: i64| -> i64 {
|
||||
occupied(v)
|
||||
.into_iter()
|
||||
.find(|(_, (id, _))| *id == wire)
|
||||
.unwrap()
|
||||
.1
|
||||
.1
|
||||
};
|
||||
assert_eq!(kit_of(&swap, 100000001), 8);
|
||||
assert_eq!(
|
||||
kit_of(&f433, 100000001),
|
||||
8,
|
||||
"kit stayed with the player despite the reindex"
|
||||
);
|
||||
assert_eq!(f433["captain"], 100000001, "captain still the same player");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn one_projector_serves_every_endpoint_no_divergence() {
|
||||
let (owned, ident) = oracle_tables();
|
||||
let projected = project_put(
|
||||
&parse_squad_put(PUT_SWAP.as_bytes()).unwrap(),
|
||||
&owned,
|
||||
&ident,
|
||||
);
|
||||
|
||||
// userMassInfo.squad = the projected object + session envelope.
|
||||
let ummi = user_mass_info_squad(projected.clone(), 33068179);
|
||||
assert_eq!(ummi["personaId"], 33068179);
|
||||
assert_eq!(ummi["changed"], 0);
|
||||
assert!(ummi["actives"].is_array());
|
||||
assert_eq!(ummi["players"], projected["players"], "same projected body");
|
||||
assert_eq!(ummi["formation"], projected["formation"]);
|
||||
|
||||
// squad/list = a summary SUBSET of the SAME object, not a second projection.
|
||||
let list = squad_list(&projected);
|
||||
let entry = &list["squad"][0];
|
||||
for k in [
|
||||
"id",
|
||||
"squadName",
|
||||
"formation",
|
||||
"squadType",
|
||||
"rating",
|
||||
"chemistry",
|
||||
] {
|
||||
assert_eq!(
|
||||
entry[k], projected[k],
|
||||
"summary field {k} derived from the one projection"
|
||||
);
|
||||
}
|
||||
// The summary carries only those six keys — no divergent squad shape.
|
||||
assert_eq!(entry.as_object().unwrap().len(), 6);
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
[package]
|
||||
name = "openfut-autopatch"
|
||||
version = "0.1.0"
|
||||
edition = "2021"
|
||||
license = "MIT"
|
||||
description = "Applies the FIFA 17 ProtoSSL cert and CardsDLL store patches to a running client"
|
||||
publish = false
|
||||
|
||||
# Deliberately dependency-free. Everything this needs is in std: /proc scanning for
|
||||
# the client pid, and positioned reads/writes against /proc/<pid>/mem via
|
||||
# std::os::unix::fs::FileExt. A patcher that edits another process's memory should be
|
||||
# auditable end to end without pulling in a dependency tree.
|
||||
[dependencies]
|
||||
@@ -0,0 +1,477 @@
|
||||
//! FIFA 17 client patcher — the ProtoSSL cert gates and the CardsDLL FUT store
|
||||
//! patches, applied to a running `FIFA17.exe` through `/proc/<pid>/mem`.
|
||||
//!
|
||||
//! Port of `fifa17-recon/tools/autopatch.py`; that file is the specification and
|
||||
//! every address, byte pattern and log line here is reproduced from it verbatim.
|
||||
//! The store patches are re-applied on every tick because the game rewrites
|
||||
//! those sites; the cert gates are applied once per pid.
|
||||
//!
|
||||
//! This module holds the constants, the two pure decision functions and the
|
||||
//! parsers. The enforcement passes live in [`patch`], process access in
|
||||
//! [`procmem`], timestamping in [`localtime`], and the watch loop in `main.rs`.
|
||||
|
||||
pub mod localtime;
|
||||
pub mod logging;
|
||||
pub mod patch;
|
||||
pub mod procmem;
|
||||
|
||||
use std::fmt;
|
||||
|
||||
pub use logging::Logger;
|
||||
|
||||
/// `/proc/<pid>/comm` of the client we patch (exact match after trimming).
|
||||
pub const CLIENT_COMM: &str = "FIFA17.exe";
|
||||
|
||||
/// Substring identifying the CardsDLL mapping in `/proc/<pid>/maps`.
|
||||
pub const CARDSDLL_MARKER: &str = "CardsDLL";
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// ProtoSSL certificate gates (absolute VAs in the unpacked FIFA17.exe image;
|
||||
// present only once the packer has mapped the real code, hence the watch loop).
|
||||
// ---------------------------------------------------------------------------
|
||||
|
||||
pub const GATE2: u64 = 0x1461361b0;
|
||||
pub const GATE2_ORIG: [u8; 3] = [0x48, 0x89, 0x5c];
|
||||
pub const GATE2_PATCH: [u8; 3] = [0x31, 0xc0, 0xc3];
|
||||
|
||||
pub const GATE1: u64 = 0x146132548;
|
||||
pub const GATE1_ORIG: [u8; 6] = [0x0f, 0x85, 0x76, 0x01, 0x00, 0x00];
|
||||
pub const GATE1_PATCH: [u8; 6] = [0x90; 6];
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// FUT store patches, expressed against the CardsDLL preferred image base and
|
||||
// relocated to the live mapping base at runtime.
|
||||
// ---------------------------------------------------------------------------
|
||||
|
||||
/// `mov eax, 1; ret` — force a predicate true.
|
||||
pub const RET_TRUE: [u8; 6] = [0xb8, 0x01, 0x00, 0x00, 0x00, 0xc3];
|
||||
/// Two `nop`s.
|
||||
pub const NOP2: [u8; 2] = [0x90, 0x90];
|
||||
/// `jmp +0x3f`, the one non-uniform store patch (site `0x180017543`).
|
||||
pub const SHORT_JMP_3F: [u8; 2] = [0xeb, 0x3f];
|
||||
/// CardsDLL's preferred image base; live address = `cbase + (va - IMG_BASE)`.
|
||||
pub const IMG_BASE: u64 = 0x180000000;
|
||||
|
||||
/// Unconditional store patches, in the Python's insertion order — the order
|
||||
/// decides the order of the `ENFORCED store patch` log lines.
|
||||
///
|
||||
/// The Python carries no per-site rationale for these eight sites, so none is
|
||||
/// invented here; the addresses and bytes are reproduced verbatim.
|
||||
pub const STORE_PATCHES: [(u64, &[u8]); 8] = [
|
||||
(0x1800f7fb0, &RET_TRUE),
|
||||
(0x1800fb850, &RET_TRUE),
|
||||
(0x180100500, &RET_TRUE),
|
||||
(0x180013cf0, &RET_TRUE),
|
||||
(0x180017543, &SHORT_JMP_3F),
|
||||
(0x180017487, &NOP2),
|
||||
(0x180017490, &NOP2),
|
||||
(0x1800175aa, &NOP2),
|
||||
];
|
||||
|
||||
/// Store resolver crash-guard for the empty "My Packs" case (bug 6c; PROVEN R1 on the
|
||||
/// tested FIFA 17 build -- see docs/plans/FIFA17_EMPTY_MYPACKS_CLIENT_FIX.md PART IV and
|
||||
/// docs/evidence/FIFA17_EMPTY_MYPACKS_CLIENT_CONTRACT.md).
|
||||
///
|
||||
/// When no `mypacks` group exists, FIFA's Store resolver receives category id -1. CardsDLL
|
||||
/// FUN_1800147f0 @ 0x180014858 is `JNZ 0x14869` (75 0f): the original treats every non-zero
|
||||
/// category (including -1) as resolvable, calls FUN_180014420, gets NULL, and crashes at the
|
||||
/// \[NULL+0x48\] deref in FUN_1800147f0 (0x180014882). Changing JNZ->JG (7f 0f) preserves
|
||||
/// positive-category resolution (EDI>0 branch) while routing zero/negative categories through
|
||||
/// the existing Browse/list-all path -> no NULL lookup, no crash, Store opens on Browse Packs.
|
||||
///
|
||||
/// CAVEAT: this guards the category SIGN only. It does NOT protect a stale *positive* invalid
|
||||
/// ordinal produced by changing the Store group topology (sentinel-present <-> sentinel-absent)
|
||||
/// DURING one running FIFA process -- that reproduced the same crash in the confounded run F3.
|
||||
/// The empty-My-Packs representation MUST stay stable for a FIFA session (see the SESSION-STABLE
|
||||
/// invariant in the client-fix plan).
|
||||
///
|
||||
/// Orig-verified / fail-closed: applied only when the live bytes are the known original (75 0f);
|
||||
/// already-patched (7f 0f) is a no-op; anything else is logged and SKIPPED (never blindly
|
||||
/// overwritten), so an unrecognised CardsDLL build is not patched.
|
||||
///
|
||||
/// Tuple layout: `(va, orig, patch)`. `JNZ 0x14869` -> `JG 0x14869`.
|
||||
pub const STORE_PATCHES_GUARDED: [(u64, &[u8], &[u8]); 1] =
|
||||
[(0x180014858, &[0x75, 0x0f], &[0x7f, 0x0f])];
|
||||
|
||||
/// Capability advertised to the launcher/backend once the resolver guard is VERIFIED
|
||||
/// live in a specific FIFA process (docs/plans/FIFA17_PATCHED_CLIENT_CAPABILITY.md #3/#4).
|
||||
pub const EMPTY_MYPACKS_RESOLVER_CAPABILITY: &str = "fifa17.empty_mypacks_resolver";
|
||||
pub const EMPTY_MYPACKS_RESOLVER_VERSION: u32 = 1;
|
||||
|
||||
/// The guarded site whose verified enforcement backs the capability above.
|
||||
pub const RESOLVER_GUARD_VA: u64 = 0x180014858;
|
||||
|
||||
/// Longest patch payload, so the watch loop can compare live bytes on the stack.
|
||||
pub const MAX_PATCH_LEN: usize = RET_TRUE.len();
|
||||
|
||||
// Compile-time proof that the watch loop's stack buffers are large enough, so no
|
||||
// slicing panic is reachable from the patch tables.
|
||||
const _: () = {
|
||||
let mut i = 0;
|
||||
while i < STORE_PATCHES.len() {
|
||||
assert!(STORE_PATCHES[i].1.len() <= MAX_PATCH_LEN);
|
||||
i += 1;
|
||||
}
|
||||
let mut i = 0;
|
||||
while i < STORE_PATCHES_GUARDED.len() {
|
||||
assert!(STORE_PATCHES_GUARDED[i].1.len() <= MAX_PATCH_LEN);
|
||||
assert!(STORE_PATCHES_GUARDED[i].2.len() <= MAX_PATCH_LEN);
|
||||
assert!(STORE_PATCHES_GUARDED[i].1.len() == STORE_PATCHES_GUARDED[i].2.len());
|
||||
i += 1;
|
||||
}
|
||||
};
|
||||
|
||||
/// Fail-closed decision for a guarded byte patch (see [`STORE_PATCHES_GUARDED`]).
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub enum GuardedAction {
|
||||
/// Live bytes are already the patch; nothing to write.
|
||||
Noop,
|
||||
/// Live bytes are the known original; safe to apply.
|
||||
Patch,
|
||||
/// Unrecognised CardsDLL build — never blindly overwritten.
|
||||
Skip,
|
||||
}
|
||||
|
||||
/// Per-FIFA-pid guard status (fail-closed; FIFA17_PATCHED_CLIENT_CAPABILITY.md #4).
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub enum GuardState {
|
||||
/// CardsDLL not mapped / guard not yet evaluated.
|
||||
NotAttempted,
|
||||
/// Live bytes == patch after enforcement (patch or noop).
|
||||
Verified,
|
||||
/// Neither original nor patched ([`GuardedAction::Skip`]).
|
||||
UnsupportedBuild,
|
||||
/// The `/proc/<pid>/mem` write failed.
|
||||
WriteFailed,
|
||||
/// Post-write re-read != patch.
|
||||
VerifyFailed,
|
||||
}
|
||||
|
||||
impl GuardState {
|
||||
/// Wire spelling used in the `[store-guard] guard status=…` line the launcher reads.
|
||||
pub fn as_str(self) -> &'static str {
|
||||
match self {
|
||||
GuardState::NotAttempted => "NOT_ATTEMPTED",
|
||||
GuardState::Verified => "VERIFIED",
|
||||
GuardState::UnsupportedBuild => "UNSUPPORTED_BUILD",
|
||||
GuardState::WriteFailed => "WRITE_FAILED",
|
||||
GuardState::VerifyFailed => "VERIFY_FAILED",
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl fmt::Display for GuardState {
|
||||
fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
|
||||
f.write_str(self.as_str())
|
||||
}
|
||||
}
|
||||
|
||||
/// Fail-closed decision for a guarded byte patch.
|
||||
///
|
||||
/// [`GuardedAction::Noop`] when the live bytes are already patched,
|
||||
/// [`GuardedAction::Patch`] when they are the known original (safe to apply), or
|
||||
/// [`GuardedAction::Skip`] for anything else — an unrecognised CardsDLL build
|
||||
/// that must never be blindly overwritten.
|
||||
pub fn guarded_action(cur: &[u8], orig: &[u8], patch: &[u8]) -> GuardedAction {
|
||||
if cur == patch {
|
||||
return GuardedAction::Noop;
|
||||
}
|
||||
if cur == orig {
|
||||
return GuardedAction::Patch;
|
||||
}
|
||||
GuardedAction::Skip
|
||||
}
|
||||
|
||||
/// Map a guarded-patch enforcement outcome to a per-pid guard STATE (pure).
|
||||
///
|
||||
/// Mirrors [`guarded_action`]'s decision, extended with post-write verification so the
|
||||
/// caller advertises the capability only on VERIFIED. No `/proc` access — unit-testable.
|
||||
///
|
||||
/// - `cur_before == patch` -> VERIFIED (already patched; [`GuardedAction::Noop`])
|
||||
/// - `cur_before == orig` -> WRITE_FAILED if the write raised, else VERIFIED when the
|
||||
/// re-read is patch, else VERIFY_FAILED ([`GuardedAction::Patch`])
|
||||
/// - otherwise -> UNSUPPORTED_BUILD ([`GuardedAction::Skip`])
|
||||
///
|
||||
/// [`GuardState::NotAttempted`] is never returned: it is the state a pid carries before
|
||||
/// the guard is evaluated at all (CardsDLL not mapped yet), and this function is only
|
||||
/// reached once live bytes have been read.
|
||||
pub fn guard_state_after(
|
||||
cur_before: &[u8],
|
||||
orig: &[u8],
|
||||
patch: &[u8],
|
||||
wrote_ok: bool,
|
||||
cur_after: &[u8],
|
||||
) -> GuardState {
|
||||
if cur_before == patch {
|
||||
return GuardState::Verified;
|
||||
}
|
||||
if cur_before == orig {
|
||||
if !wrote_ok {
|
||||
return GuardState::WriteFailed;
|
||||
}
|
||||
if cur_after == patch {
|
||||
return GuardState::Verified;
|
||||
}
|
||||
return GuardState::VerifyFailed;
|
||||
}
|
||||
GuardState::UnsupportedBuild
|
||||
}
|
||||
|
||||
/// Live address of an image-relative patch site inside the mapped CardsDLL.
|
||||
pub fn live_addr(cbase: u64, va: u64) -> u64 {
|
||||
cbase + (va - IMG_BASE)
|
||||
}
|
||||
|
||||
/// Lowercase, unseparated hex — the spelling of `bytes.hex()` in the SKIP log line.
|
||||
pub fn hex(bytes: &[u8]) -> String {
|
||||
let mut out = String::with_capacity(bytes.len() * 2);
|
||||
for b in bytes {
|
||||
// Two nibbles, no separator, no allocation per byte.
|
||||
const DIGITS: &[u8; 16] = b"0123456789abcdef";
|
||||
out.push(DIGITS[(b >> 4) as usize] as char);
|
||||
out.push(DIGITS[(b & 0x0f) as usize] as char);
|
||||
}
|
||||
out
|
||||
}
|
||||
|
||||
/// True when a `/proc/<pid>/comm` body names the FIFA 17 client.
|
||||
pub fn is_client_comm(comm: &str) -> bool {
|
||||
comm.trim() == CLIENT_COMM
|
||||
}
|
||||
|
||||
/// Pid from a `/proc` directory entry name.
|
||||
///
|
||||
/// The Python globs `/proc/[0-9]*` and then `int()`s the name inside a bare
|
||||
/// `except`, so a name has to start with a digit *and* be entirely numeric.
|
||||
pub fn pid_from_proc_entry(name: &str) -> Option<u32> {
|
||||
if !name.as_bytes().first().is_some_and(u8::is_ascii_digit) {
|
||||
return None;
|
||||
}
|
||||
name.parse::<u32>().ok()
|
||||
}
|
||||
|
||||
/// Base address of the first `CardsDLL` mapping in a `/proc/<pid>/maps` body.
|
||||
///
|
||||
/// Only the first matching line is considered, and a line whose base does not
|
||||
/// parse yields `None` rather than falling through to the next mapping — the
|
||||
/// Python's `int(...)` raises inside the `try` that returns `None`.
|
||||
pub fn parse_cardsdll_base(maps: &str) -> Option<u64> {
|
||||
let line = maps.lines().find(|line| line.contains(CARDSDLL_MARKER))?;
|
||||
u64::from_str_radix(line.split('-').next()?, 16).ok()
|
||||
}
|
||||
|
||||
/// `--launcher-pid <pid>` out of the argument list.
|
||||
///
|
||||
/// `Ok(None)` when the flag is absent, `Err(())` when it is present with a
|
||||
/// missing or non-numeric value (the Python raises `SystemExit`). The value is
|
||||
/// kept signed and un-clamped so the liveness check behaves exactly like the
|
||||
/// Python's `os.path.exists(f"/proc/{launcher_pid}")` for odd inputs.
|
||||
#[allow(clippy::result_unit_err)]
|
||||
pub fn parse_launcher_pid<I, S>(args: I) -> Result<Option<i64>, ()>
|
||||
where
|
||||
I: IntoIterator<Item = S>,
|
||||
S: AsRef<str>,
|
||||
{
|
||||
let args: Vec<S> = args.into_iter().collect();
|
||||
let Some(idx) = args.iter().position(|a| a.as_ref() == "--launcher-pid") else {
|
||||
return Ok(None);
|
||||
};
|
||||
let value = args.get(idx + 1).ok_or(())?;
|
||||
value.as_ref().trim().parse::<i64>().map(Some).map_err(|_| ())
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
const ORIG: &[u8] = &[0x75, 0x0f];
|
||||
const PATCH: &[u8] = &[0x7f, 0x0f];
|
||||
|
||||
#[test]
|
||||
fn constants_match_the_python_spec() {
|
||||
assert_eq!(GATE2, 0x1461361b0);
|
||||
assert_eq!(GATE2_ORIG, [0x48, 0x89, 0x5c]);
|
||||
assert_eq!(GATE2_PATCH, [0x31, 0xc0, 0xc3]);
|
||||
assert_eq!(GATE1, 0x146132548);
|
||||
assert_eq!(GATE1_ORIG, [0x0f, 0x85, 0x76, 0x01, 0x00, 0x00]);
|
||||
assert_eq!(GATE1_PATCH, [0x90, 0x90, 0x90, 0x90, 0x90, 0x90]);
|
||||
assert_eq!(IMG_BASE, 0x180000000);
|
||||
assert_eq!(hex(&RET_TRUE), "b801000000c3");
|
||||
assert_eq!(hex(&NOP2), "9090");
|
||||
|
||||
// Site order is part of the log contract, so assert the whole table.
|
||||
let sites: Vec<(u64, String)> = STORE_PATCHES
|
||||
.iter()
|
||||
.map(|(va, data)| (*va, hex(data)))
|
||||
.collect();
|
||||
assert_eq!(
|
||||
sites,
|
||||
vec![
|
||||
(0x1800f7fb0, "b801000000c3".to_string()),
|
||||
(0x1800fb850, "b801000000c3".to_string()),
|
||||
(0x180100500, "b801000000c3".to_string()),
|
||||
(0x180013cf0, "b801000000c3".to_string()),
|
||||
(0x180017543, "eb3f".to_string()),
|
||||
(0x180017487, "9090".to_string()),
|
||||
(0x180017490, "9090".to_string()),
|
||||
(0x1800175aa, "9090".to_string()),
|
||||
]
|
||||
);
|
||||
|
||||
assert_eq!(STORE_PATCHES_GUARDED.len(), 1);
|
||||
let (va, orig, patch) = STORE_PATCHES_GUARDED[0];
|
||||
assert_eq!(va, 0x180014858);
|
||||
assert_eq!(hex(orig), "750f");
|
||||
assert_eq!(hex(patch), "7f0f");
|
||||
assert_eq!(RESOLVER_GUARD_VA, va);
|
||||
assert_eq!(EMPTY_MYPACKS_RESOLVER_CAPABILITY, "fifa17.empty_mypacks_resolver");
|
||||
assert_eq!(EMPTY_MYPACKS_RESOLVER_VERSION, 1);
|
||||
assert_eq!(MAX_PATCH_LEN, 6);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn guarded_action_noops_when_already_patched() {
|
||||
assert_eq!(guarded_action(PATCH, ORIG, PATCH), GuardedAction::Noop);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn guarded_action_patches_the_known_original() {
|
||||
assert_eq!(guarded_action(ORIG, ORIG, PATCH), GuardedAction::Patch);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn guarded_action_skips_an_unrecognised_build() {
|
||||
// Fail-closed: an unknown CardsDLL build is never overwritten.
|
||||
assert_eq!(guarded_action(&[0x74, 0x0f], ORIG, PATCH), GuardedAction::Skip);
|
||||
assert_eq!(guarded_action(&[], ORIG, PATCH), GuardedAction::Skip);
|
||||
assert_eq!(guarded_action(&[0x75], ORIG, PATCH), GuardedAction::Skip);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn guard_state_verified_when_already_patched() {
|
||||
// wrote_ok / cur_after are irrelevant on this branch.
|
||||
assert_eq!(
|
||||
guard_state_after(PATCH, ORIG, PATCH, false, &[]),
|
||||
GuardState::Verified
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn guard_state_verified_after_a_successful_write() {
|
||||
assert_eq!(
|
||||
guard_state_after(ORIG, ORIG, PATCH, true, PATCH),
|
||||
GuardState::Verified
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn guard_state_write_failed() {
|
||||
assert_eq!(
|
||||
guard_state_after(ORIG, ORIG, PATCH, false, ORIG),
|
||||
GuardState::WriteFailed
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn guard_state_verify_failed() {
|
||||
// Write reported success but the re-read still shows the original …
|
||||
assert_eq!(
|
||||
guard_state_after(ORIG, ORIG, PATCH, true, ORIG),
|
||||
GuardState::VerifyFailed
|
||||
);
|
||||
// … or could not be re-read at all (the Python's `cur_after = b""`).
|
||||
assert_eq!(
|
||||
guard_state_after(ORIG, ORIG, PATCH, true, &[]),
|
||||
GuardState::VerifyFailed
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn guard_state_unsupported_build() {
|
||||
assert_eq!(
|
||||
guard_state_after(&[0x74, 0x0f], ORIG, PATCH, true, PATCH),
|
||||
GuardState::UnsupportedBuild
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn guard_state_spellings_are_the_launcher_contract() {
|
||||
assert_eq!(GuardState::NotAttempted.to_string(), "NOT_ATTEMPTED");
|
||||
assert_eq!(GuardState::Verified.to_string(), "VERIFIED");
|
||||
assert_eq!(GuardState::UnsupportedBuild.to_string(), "UNSUPPORTED_BUILD");
|
||||
assert_eq!(GuardState::WriteFailed.to_string(), "WRITE_FAILED");
|
||||
assert_eq!(GuardState::VerifyFailed.to_string(), "VERIFY_FAILED");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn live_addr_relocates_against_the_image_base() {
|
||||
assert_eq!(live_addr(0x7f0000000000, 0x180014858), 0x7f0000014858);
|
||||
assert_eq!(live_addr(IMG_BASE, RESOLVER_GUARD_VA), RESOLVER_GUARD_VA);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn hex_is_lowercase_and_unseparated() {
|
||||
assert_eq!(hex(&[0x00, 0x0f, 0xa5, 0xff]), "000fa5ff");
|
||||
assert_eq!(hex(&[]), "");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn comm_matches_only_the_client() {
|
||||
assert!(is_client_comm("FIFA17.exe\n"));
|
||||
assert!(is_client_comm("FIFA17.exe"));
|
||||
assert!(!is_client_comm("fifa17.exe\n"));
|
||||
assert!(!is_client_comm("FIFA17.exe.bak\n"));
|
||||
assert!(!is_client_comm("wineserver\n"));
|
||||
assert!(!is_client_comm(""));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn proc_entry_names_yield_only_numeric_pids() {
|
||||
assert_eq!(pid_from_proc_entry("1"), Some(1));
|
||||
assert_eq!(pid_from_proc_entry("41234"), Some(41234));
|
||||
assert_eq!(pid_from_proc_entry("self"), None);
|
||||
assert_eq!(pid_from_proc_entry("1abc"), None);
|
||||
assert_eq!(pid_from_proc_entry("+7"), None);
|
||||
assert_eq!(pid_from_proc_entry(""), None);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn cardsdll_base_is_the_first_matching_mapping() {
|
||||
let maps = concat!(
|
||||
"140000000-140001000 r--p 00000000 08:02 12 /home/u/FIFA17.exe\n",
|
||||
"7f2a11c00000-7f2a11c9c000 r-xp 00000000 08:02 44 /home/u/CardsDLL_Win64_retail.dll\n",
|
||||
"7f2a12000000-7f2a12001000 r--p 00000000 08:02 45 /home/u/CardsDLL_second.dll\n",
|
||||
);
|
||||
assert_eq!(parse_cardsdll_base(maps), Some(0x7f2a11c00000));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn cardsdll_base_absent_or_unparsable() {
|
||||
assert_eq!(parse_cardsdll_base(""), None);
|
||||
let no_dll = "140000000-140001000 r--p 00000000 08:02 12 /home/u/FIFA17.exe\n";
|
||||
assert_eq!(parse_cardsdll_base(no_dll), None);
|
||||
// A CardsDLL line whose base is not hex: fail, do not fall through.
|
||||
let broken = concat!(
|
||||
"zzzz-140001000 r--p 00000000 08:02 12 /home/u/CardsDLL.dll\n",
|
||||
"7f2a11c00000-7f2a11c9c000 r-xp 0 08:02 44 /home/u/CardsDLL.dll\n",
|
||||
);
|
||||
assert_eq!(parse_cardsdll_base(broken), None);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn launcher_pid_parsing() {
|
||||
assert_eq!(parse_launcher_pid(Vec::<String>::new()), Ok(None));
|
||||
assert_eq!(parse_launcher_pid(["--other", "3"]), Ok(None));
|
||||
assert_eq!(parse_launcher_pid(["--launcher-pid", "4242"]), Ok(Some(4242)));
|
||||
assert_eq!(
|
||||
parse_launcher_pid(["-x", "--launcher-pid", "7", "--launcher-pid", "9"]),
|
||||
Ok(Some(7))
|
||||
);
|
||||
// Falsy in the Python (`if launcher_pid and ...`): parsed, never watched.
|
||||
assert_eq!(parse_launcher_pid(["--launcher-pid", "0"]), Ok(Some(0)));
|
||||
assert_eq!(parse_launcher_pid(["--launcher-pid", "-5"]), Ok(Some(-5)));
|
||||
assert_eq!(parse_launcher_pid(["--launcher-pid"]), Err(()));
|
||||
assert_eq!(parse_launcher_pid(["--launcher-pid", "abc"]), Err(()));
|
||||
assert_eq!(parse_launcher_pid(["--launcher-pid", ""]), Err(()));
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,304 @@
|
||||
//! Wall-clock `HH:MM:SS` in local time, from std alone.
|
||||
//!
|
||||
//! The Python logs `time.strftime('%H:%M:%S')`, i.e. *local* time, and the
|
||||
//! launcher interleaves these lines with its own log, so UTC would misreport the
|
||||
//! timestamps by the machine's offset. std has no local-time support, so the
|
||||
//! UTC offset is taken from the system's TZif database (`TZ` or `/etc/localtime`),
|
||||
//! parsed here — a bounded, well-specified format (RFC 8536).
|
||||
//!
|
||||
//! LIMITATION, stated rather than hidden: only the TZif transition table is
|
||||
//! evaluated, not the trailing POSIX-TZ footer string. With the "fat" tzdata
|
||||
//! that Debian-family systems ship, transitions run to 2037, so the offset —
|
||||
//! including DST — is exact. Two cases fall back to the last known transition's
|
||||
//! offset (so a DST-observing zone could read one hour off) and one falls back
|
||||
//! to UTC:
|
||||
//! * "slim" tzdata, or dates past the last transition -> last transition;
|
||||
//! * `TZ` holding a bare POSIX rule (`EST5EDT`) with no such zone file, or an
|
||||
//! unreadable/corrupt zone file -> UTC.
|
||||
//! The timestamp is diagnostic; no line the launcher parses carries a time.
|
||||
|
||||
use std::fs;
|
||||
use std::sync::LazyLock;
|
||||
use std::time::{SystemTime, UNIX_EPOCH};
|
||||
|
||||
/// Resolved UTC offsets over time: an offset before the first transition, then
|
||||
/// `(transition instant, offset from that instant on)` in ascending order.
|
||||
#[derive(Debug, PartialEq, Eq)]
|
||||
pub struct TzData {
|
||||
initial: i32,
|
||||
transitions: Vec<(i64, i32)>,
|
||||
}
|
||||
|
||||
impl TzData {
|
||||
/// UTC offset in seconds applying at `unix_secs`.
|
||||
pub fn offset_at(&self, unix_secs: i64) -> i32 {
|
||||
let idx = self
|
||||
.transitions
|
||||
.partition_point(|(start, _)| *start <= unix_secs);
|
||||
if idx == 0 {
|
||||
self.initial
|
||||
} else {
|
||||
self.transitions[idx - 1].1
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// `[HH:MM:SS]`-worthy time-of-day for a Unix timestamp at a given UTC offset.
|
||||
pub fn hms(unix_secs: i64, utc_offset_secs: i32) -> (u32, u32, u32) {
|
||||
let local = unix_secs + i64::from(utc_offset_secs);
|
||||
// rem_euclid keeps pre-epoch and negative-offset instants on a sane clock.
|
||||
let day = local.rem_euclid(86_400);
|
||||
((day / 3600) as u32, (day % 3600 / 60) as u32, (day % 60) as u32)
|
||||
}
|
||||
|
||||
/// Current local time of day, `(hour, minute, second)`.
|
||||
pub fn now_hms() -> (u32, u32, u32) {
|
||||
let unix = SystemTime::now()
|
||||
.duration_since(UNIX_EPOCH)
|
||||
.map(|d| d.as_secs() as i64)
|
||||
// Before 1970 the clock is broken anyway; keep logging rather than panic.
|
||||
.unwrap_or(0);
|
||||
hms(unix, local_offset_at(unix))
|
||||
}
|
||||
|
||||
/// UTC offset in seconds for `unix_secs`, or 0 when no zone data is usable.
|
||||
///
|
||||
/// The zone file is read and parsed once; the offset is then recomputed per call
|
||||
/// so a DST transition during a long-running session is picked up.
|
||||
pub fn local_offset_at(unix_secs: i64) -> i32 {
|
||||
static TZ: LazyLock<Option<TzData>> = LazyLock::new(load_system_tz);
|
||||
TZ.as_ref().map_or(0, |tz| tz.offset_at(unix_secs))
|
||||
}
|
||||
|
||||
/// Read and parse the zone file named by `TZ`, else `/etc/localtime`.
|
||||
fn load_system_tz() -> Option<TzData> {
|
||||
let path = match std::env::var("TZ") {
|
||||
Ok(tz) if !tz.is_empty() => {
|
||||
// glibc accepts a leading ':' and either an absolute path or a name
|
||||
// relative to the zoneinfo directory.
|
||||
let name = tz.strip_prefix(':').unwrap_or(&tz);
|
||||
if name.starts_with('/') {
|
||||
name.to_string()
|
||||
} else {
|
||||
format!("/usr/share/zoneinfo/{name}")
|
||||
}
|
||||
}
|
||||
_ => "/etc/localtime".to_string(),
|
||||
};
|
||||
parse_tzif(&fs::read(path).ok()?)
|
||||
}
|
||||
|
||||
/// Parse a TZif (RFC 8536) file into resolved offsets.
|
||||
///
|
||||
/// For version 2+ files the 64-bit data block is used; the legacy 32-bit block
|
||||
/// is skipped, because modern tzdata leaves it minimal.
|
||||
pub fn parse_tzif(bytes: &[u8]) -> Option<TzData> {
|
||||
let (version, counts) = parse_header(bytes, 0)?;
|
||||
if version >= b'2' {
|
||||
// Skip the v1 header + v1 data block, then re-read the 64-bit header.
|
||||
let v1_end = 44 + data_block_len(&counts, 4)?;
|
||||
let (_, counts64) = parse_header(bytes, v1_end)?;
|
||||
parse_data(bytes, v1_end + 44, &counts64, 8)
|
||||
} else {
|
||||
parse_data(bytes, 44, &counts, 4)
|
||||
}
|
||||
}
|
||||
|
||||
/// `(isutcnt, isstdcnt, leapcnt, timecnt, typecnt, charcnt)`.
|
||||
type Counts = [u32; 6];
|
||||
|
||||
fn parse_header(bytes: &[u8], off: usize) -> Option<(u8, Counts)> {
|
||||
let head = bytes.get(off..off + 44)?;
|
||||
if &head[0..4] != b"TZif" {
|
||||
return None;
|
||||
}
|
||||
let version = head[4];
|
||||
let mut counts = [0u32; 6];
|
||||
for (i, slot) in counts.iter_mut().enumerate() {
|
||||
let at = 20 + i * 4;
|
||||
*slot = u32::from_be_bytes(head[at..at + 4].try_into().ok()?);
|
||||
}
|
||||
Some((version, counts))
|
||||
}
|
||||
|
||||
/// Byte length of a data block with `time_len`-wide transition times.
|
||||
fn data_block_len(counts: &Counts, time_len: usize) -> Option<usize> {
|
||||
let [isutcnt, isstdcnt, leapcnt, timecnt, typecnt, charcnt] = counts.map(|c| c as usize);
|
||||
Some(
|
||||
timecnt * time_len
|
||||
+ timecnt
|
||||
+ typecnt * 6
|
||||
+ charcnt
|
||||
+ leapcnt * (time_len + 4)
|
||||
+ isstdcnt
|
||||
+ isutcnt,
|
||||
)
|
||||
}
|
||||
|
||||
fn parse_data(bytes: &[u8], off: usize, counts: &Counts, time_len: usize) -> Option<TzData> {
|
||||
let [_, _, _, timecnt, typecnt, _] = counts.map(|c| c as usize);
|
||||
if typecnt == 0 {
|
||||
return None;
|
||||
}
|
||||
let block = bytes.get(off..off + data_block_len(counts, time_len)?)?;
|
||||
|
||||
let times = block.get(..timecnt * time_len)?;
|
||||
let type_idx = block.get(timecnt * time_len..timecnt * time_len + timecnt)?;
|
||||
let ttinfo_at = timecnt * time_len + timecnt;
|
||||
let ttinfo = block.get(ttinfo_at..ttinfo_at + typecnt * 6)?;
|
||||
|
||||
// utoff + isdst per local-time type.
|
||||
let mut offsets = Vec::with_capacity(typecnt);
|
||||
for i in 0..typecnt {
|
||||
let rec = &ttinfo[i * 6..i * 6 + 6];
|
||||
let utoff = i32::from_be_bytes(rec[0..4].try_into().ok()?);
|
||||
offsets.push((utoff, rec[4] != 0));
|
||||
}
|
||||
|
||||
// Before the first transition, RFC 8536 says to use the first non-DST type,
|
||||
// falling back to the first type. This is also the whole answer for a
|
||||
// fixed-offset zone (typecnt 1, timecnt 0), e.g. Etc/UTC.
|
||||
let initial = offsets
|
||||
.iter()
|
||||
.find(|(_, isdst)| !*isdst)
|
||||
.unwrap_or(&offsets[0])
|
||||
.0;
|
||||
|
||||
let mut transitions = Vec::with_capacity(timecnt);
|
||||
for i in 0..timecnt {
|
||||
let raw = ×[i * time_len..(i + 1) * time_len];
|
||||
let at = if time_len == 8 {
|
||||
i64::from_be_bytes(raw.try_into().ok()?)
|
||||
} else {
|
||||
i64::from(i32::from_be_bytes(raw.try_into().ok()?))
|
||||
};
|
||||
let (utoff, _) = *offsets.get(*type_idx.get(i)? as usize)?;
|
||||
transitions.push((at, utoff));
|
||||
}
|
||||
|
||||
Some(TzData {
|
||||
initial,
|
||||
transitions,
|
||||
})
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
/// Minimal TZif builder: `transitions` are `(instant, type index)`.
|
||||
fn tzif(version: u8, types: &[(i32, bool)], transitions: &[(i64, u8)]) -> Vec<u8> {
|
||||
fn block(types: &[(i32, bool)], transitions: &[(i64, u8)], time_len: usize) -> Vec<u8> {
|
||||
let mut out = Vec::new();
|
||||
for (at, _) in transitions {
|
||||
if time_len == 8 {
|
||||
out.extend_from_slice(&at.to_be_bytes());
|
||||
} else {
|
||||
out.extend_from_slice(&(*at as i32).to_be_bytes());
|
||||
}
|
||||
}
|
||||
for (_, idx) in transitions {
|
||||
out.push(*idx);
|
||||
}
|
||||
for (utoff, isdst) in types {
|
||||
out.extend_from_slice(&utoff.to_be_bytes());
|
||||
out.push(u8::from(*isdst));
|
||||
out.push(0); // abbreviation index
|
||||
}
|
||||
out.push(0); // one NUL abbreviation byte
|
||||
out
|
||||
}
|
||||
fn header(version: u8, types: usize, transitions: usize) -> Vec<u8> {
|
||||
let mut out = Vec::from(*b"TZif");
|
||||
out.push(version);
|
||||
out.extend_from_slice(&[0u8; 15]);
|
||||
for count in [0u32, 0, 0, transitions as u32, types as u32, 1] {
|
||||
out.extend_from_slice(&count.to_be_bytes());
|
||||
}
|
||||
out
|
||||
}
|
||||
let mut out = header(version, types.len(), transitions.len());
|
||||
if version >= b'2' {
|
||||
// Modern "slim-ish" shape: an empty v1 block, then the 64-bit block.
|
||||
out.truncate(0);
|
||||
out.extend(header(version, types.len(), 0));
|
||||
out.extend(block(types, &[], 4));
|
||||
out.extend(header(version, types.len(), transitions.len()));
|
||||
out.extend(block(types, transitions, 8));
|
||||
} else {
|
||||
out.extend(block(types, transitions, 4));
|
||||
}
|
||||
out
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn fixed_offset_zone_has_no_transitions() {
|
||||
let tz = parse_tzif(&tzif(b'2', &[(0, false)], &[])).unwrap();
|
||||
assert_eq!(tz.offset_at(0), 0);
|
||||
assert_eq!(tz.offset_at(1_800_000_000), 0);
|
||||
|
||||
let kolkata = parse_tzif(&tzif(b'2', &[(19_800, false)], &[])).unwrap();
|
||||
assert_eq!(kolkata.offset_at(1_800_000_000), 19_800);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn dst_transitions_select_the_right_offset() {
|
||||
// CET/CEST with two transitions.
|
||||
let tz = parse_tzif(&tzif(
|
||||
b'2',
|
||||
&[(3600, false), (7200, true)],
|
||||
&[(1_000_000_000, 1), (1_100_000_000, 0)],
|
||||
))
|
||||
.unwrap();
|
||||
assert_eq!(tz.offset_at(999_999_999), 3600); // before the first transition
|
||||
assert_eq!(tz.offset_at(1_000_000_000), 7200); // exactly at it
|
||||
assert_eq!(tz.offset_at(1_050_000_000), 7200);
|
||||
assert_eq!(tz.offset_at(1_100_000_000), 3600);
|
||||
assert_eq!(tz.offset_at(i64::MAX), 3600); // past the table: last known
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn version_1_files_parse_from_the_32_bit_block() {
|
||||
let tz = parse_tzif(&tzif(b'\0', &[(-18_000, false)], &[(100, 0)])).unwrap();
|
||||
assert_eq!(tz.offset_at(0), -18_000);
|
||||
assert_eq!(tz.offset_at(1_000), -18_000);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn initial_offset_skips_a_leading_dst_type() {
|
||||
let tz = parse_tzif(&tzif(b'2', &[(7200, true), (3600, false)], &[])).unwrap();
|
||||
assert_eq!(tz.offset_at(0), 3600);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn garbage_is_rejected_rather_than_guessed() {
|
||||
assert_eq!(parse_tzif(b""), None);
|
||||
assert_eq!(parse_tzif(b"not a tzif file at all, truncated"), None);
|
||||
let mut truncated = tzif(b'2', &[(3600, false)], &[(1, 0)]);
|
||||
truncated.truncate(truncated.len() - 5);
|
||||
assert_eq!(parse_tzif(&truncated), None);
|
||||
// Well-formed header claiming zero local-time types is unusable.
|
||||
assert_eq!(parse_tzif(&tzif(b'2', &[], &[])), None);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn hms_matches_known_instants() {
|
||||
assert_eq!(hms(0, 0), (0, 0, 0));
|
||||
// 2026-08-18T04:52:08Z
|
||||
assert_eq!(hms(1_787_028_728, 0), (4, 52, 8));
|
||||
// …the same instant at +02:00 and at -05:00 (the latter is the day before).
|
||||
assert_eq!(hms(1_787_028_728, 7200), (6, 52, 8));
|
||||
assert_eq!(hms(1_787_028_728, -18_000), (23, 52, 8));
|
||||
// Offsets that cross midnight in either direction stay on the clock.
|
||||
assert_eq!(hms(86_399, 1), (0, 0, 0));
|
||||
assert_eq!(hms(0, -1), (23, 59, 59));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn the_system_zone_resolves_to_a_plausible_offset() {
|
||||
// Whatever this machine's zone is, the offset must be a real one.
|
||||
let offset = local_offset_at(1_786_697_528);
|
||||
assert!((-50_400..=50_400).contains(&offset), "implausible {offset}");
|
||||
assert_eq!(offset % 60, 0);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,103 @@
|
||||
//! `[HH:MM:SS] <msg>` to stdout (flushed per line) and appended to the log file.
|
||||
//!
|
||||
//! The launcher pipes this process's stdout into its own log buffer and *parses*
|
||||
//! some of these lines, so the per-line flush and the line shapes are a contract,
|
||||
//! not cosmetics.
|
||||
|
||||
use std::fs::OpenOptions;
|
||||
use std::io::{self, Write};
|
||||
use std::path::PathBuf;
|
||||
|
||||
use crate::localtime;
|
||||
use crate::procmem;
|
||||
|
||||
/// Environment override for the log file path.
|
||||
pub const LOG_PATH_ENV: &str = "OPENFUT_AUTOPATCH_LOG";
|
||||
|
||||
pub struct Logger {
|
||||
path: PathBuf,
|
||||
}
|
||||
|
||||
impl Logger {
|
||||
/// `$OPENFUT_AUTOPATCH_LOG`, defaulting to `/tmp/openfut-autopatch-<uid>.log`.
|
||||
///
|
||||
/// Resolved once at startup, exactly like the Python's module-level `LOG`, so
|
||||
/// a later environment change cannot move the file mid-run.
|
||||
pub fn from_env() -> io::Result<Self> {
|
||||
let path = match std::env::var_os(LOG_PATH_ENV) {
|
||||
Some(path) if !path.is_empty() => PathBuf::from(path),
|
||||
_ => PathBuf::from(format!(
|
||||
"/tmp/openfut-autopatch-{}.log",
|
||||
procmem::current_uid()?
|
||||
)),
|
||||
};
|
||||
Ok(Self { path })
|
||||
}
|
||||
|
||||
pub fn path(&self) -> &std::path::Path {
|
||||
&self.path
|
||||
}
|
||||
|
||||
/// Emit one line. Timestamped in local time.
|
||||
pub fn log(&self, msg: &str) {
|
||||
let (h, m, s) = localtime::now_hms();
|
||||
let line = format!("[{h:02}:{m:02}:{s:02}] {msg}");
|
||||
|
||||
let mut stdout = io::stdout().lock();
|
||||
// Ignore a broken pipe: the launcher may have stopped reading, and dying
|
||||
// here would leave FIFA's store patches unenforced.
|
||||
let _ = writeln!(stdout, "{line}");
|
||||
let _ = stdout.flush();
|
||||
drop(stdout);
|
||||
|
||||
if let Err(e) = self.append(&line) {
|
||||
// The Python lets a failing log write kill the process. Patching the
|
||||
// running client matters more than the transcript, so report once to
|
||||
// stderr (the launcher captures it too) and carry on.
|
||||
let _ = writeln!(io::stderr(), "autopatch: cannot append to {}: {e}", self.path.display());
|
||||
}
|
||||
}
|
||||
|
||||
fn append(&self, line: &str) -> io::Result<()> {
|
||||
let mut file = OpenOptions::new().create(true).append(true).open(&self.path)?;
|
||||
file.write_all(line.as_bytes())?;
|
||||
file.write_all(b"\n")
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn appends_a_timestamped_line_to_the_configured_path() {
|
||||
let path = std::env::temp_dir().join(format!(
|
||||
"openfut-autopatch-test-{}.log",
|
||||
std::process::id()
|
||||
));
|
||||
let _ = std::fs::remove_file(&path);
|
||||
let logger = Logger {
|
||||
path: path.clone(),
|
||||
};
|
||||
logger.log("pid 4242: PATCHED cert gates");
|
||||
logger.log("second line");
|
||||
|
||||
let body = std::fs::read_to_string(&path).unwrap();
|
||||
let lines: Vec<&str> = body.lines().collect();
|
||||
assert_eq!(lines.len(), 2);
|
||||
assert_eq!(&lines[0][..1], "[");
|
||||
assert_eq!(&lines[0][3..4], ":");
|
||||
assert_eq!(&lines[0][6..7], ":");
|
||||
assert_eq!(&lines[0][9..], "] pid 4242: PATCHED cert gates");
|
||||
assert!(lines[1].ends_with("] second line"));
|
||||
let _ = std::fs::remove_file(&path);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn a_bad_log_path_does_not_kill_the_patcher() {
|
||||
let logger = Logger {
|
||||
path: PathBuf::from("/proc/definitely/not/writable.log"),
|
||||
};
|
||||
logger.log("still running");
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,97 @@
|
||||
//! Watch for a (re)launched FIFA17.exe and auto-apply the ProtoSSL cert patches
|
||||
//! the moment its unpacked code is mapped, plus the CardsDLL FUT store patches.
|
||||
//! Idempotent; keeps watching across relaunches.
|
||||
//!
|
||||
//! Port of `fifa17-recon/tools/autopatch.py`, tick for tick: cert gates once per
|
||||
//! pid, store patches re-enforced every second (the game rewrites those sites),
|
||||
//! then the resolver-guard capability reported once per pid. The passes
|
||||
//! themselves live in `openfut_autopatch::patch`; this is the loop and the CLI.
|
||||
|
||||
use std::collections::HashSet;
|
||||
use std::process::ExitCode;
|
||||
use std::thread::sleep;
|
||||
use std::time::Duration;
|
||||
|
||||
use openfut_autopatch::patch::{cert_pass, enforce_store_patches};
|
||||
use openfut_autopatch::procmem::{self, ProcMem};
|
||||
use openfut_autopatch::{parse_launcher_pid, Logger};
|
||||
|
||||
/// One tick per second, as in the Python.
|
||||
const TICK: Duration = Duration::from_secs(1);
|
||||
|
||||
/// Per-pid bookkeeping so each of these lines is logged exactly once per client
|
||||
/// process (the Python's three module-level sets).
|
||||
#[derive(Default)]
|
||||
struct Seen {
|
||||
patched: HashSet<u32>,
|
||||
store_patched: HashSet<u32>,
|
||||
guard_reported: HashSet<u32>,
|
||||
}
|
||||
|
||||
fn main() -> ExitCode {
|
||||
let launcher_pid = match parse_launcher_pid(std::env::args().skip(1)) {
|
||||
Ok(pid) => pid,
|
||||
Err(()) => {
|
||||
eprintln!("invalid --launcher-pid");
|
||||
return ExitCode::FAILURE;
|
||||
}
|
||||
};
|
||||
|
||||
let logger = match Logger::from_env() {
|
||||
Ok(logger) => logger,
|
||||
Err(e) => {
|
||||
eprintln!("cannot resolve the autopatch log path: {e}");
|
||||
return ExitCode::FAILURE;
|
||||
}
|
||||
};
|
||||
|
||||
logger.log("=== AUTOPATCH watching for FIFA17.exe ===");
|
||||
|
||||
let mut seen = Seen::default();
|
||||
loop {
|
||||
// `if launcher_pid and not os.path.exists(...)`: pid 0 is falsy in the
|
||||
// Python, so `--launcher-pid 0` parses but is never watched.
|
||||
if let Some(pid) = launcher_pid {
|
||||
if pid != 0 && !procmem::pid_alive(pid) {
|
||||
logger.log(&format!("launcher pid {pid} exited; stopping autopatch"));
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
for pid in procmem::find_pids() {
|
||||
let mem = ProcMem::new(pid);
|
||||
|
||||
if !seen.patched.contains(&pid)
|
||||
&& !cert_pass(&mem, &mut |line| logger.log(line), &mut seen.patched)
|
||||
{
|
||||
// Code not mapped yet: nothing else to do for this pid this tick.
|
||||
continue;
|
||||
}
|
||||
|
||||
// Store patches are enforced on EVERY tick, not once: the game
|
||||
// rewrites these sites, so a single pass at startup does not hold.
|
||||
let Some(cbase) = procmem::cardsdll_base(pid) else {
|
||||
continue;
|
||||
};
|
||||
match enforce_store_patches(
|
||||
&mem,
|
||||
cbase,
|
||||
&mut |line| logger.log(line),
|
||||
&mut seen.guard_reported,
|
||||
) {
|
||||
Ok(()) => {
|
||||
if seen.store_patched.insert(pid) {
|
||||
logger.log(&format!(
|
||||
"pid {pid}: PATCHED store gates in CardsDLL @ {cbase:#x}"
|
||||
));
|
||||
}
|
||||
}
|
||||
Err(e) => logger.log(&format!("pid {pid}: store patch write failed: {e}")),
|
||||
}
|
||||
}
|
||||
|
||||
sleep(TICK);
|
||||
}
|
||||
|
||||
ExitCode::SUCCESS
|
||||
}
|
||||
@@ -0,0 +1,478 @@
|
||||
//! The two enforcement passes: ProtoSSL cert gates (once per pid) and the
|
||||
//! CardsDLL store patches (every tick).
|
||||
//!
|
||||
//! Both are written against the [`Memory`] trait rather than `/proc` directly, so
|
||||
//! the log lines and their order — which the launcher reads — are unit-testable
|
||||
//! without a live FIFA client.
|
||||
|
||||
use std::collections::HashSet;
|
||||
use std::io;
|
||||
|
||||
use crate::{
|
||||
guard_state_after, guarded_action, hex, live_addr, GuardState, GuardedAction,
|
||||
EMPTY_MYPACKS_RESOLVER_CAPABILITY, EMPTY_MYPACKS_RESOLVER_VERSION, GATE1, GATE1_ORIG,
|
||||
GATE1_PATCH, GATE2, GATE2_ORIG, GATE2_PATCH, MAX_PATCH_LEN, RESOLVER_GUARD_VA, STORE_PATCHES,
|
||||
STORE_PATCHES_GUARDED,
|
||||
};
|
||||
|
||||
/// Byte-level access to one client process's address space.
|
||||
pub trait Memory {
|
||||
/// The pid being patched; it appears in every log line.
|
||||
fn pid(&self) -> u32;
|
||||
/// Fill `buf` from virtual address `va`. An error means "not mapped (yet)".
|
||||
fn read(&self, va: u64, buf: &mut [u8]) -> io::Result<()>;
|
||||
/// Write `data` at virtual address `va`.
|
||||
fn write(&self, va: u64, data: &[u8]) -> io::Result<()>;
|
||||
}
|
||||
|
||||
/// Apply the two ProtoSSL cert gates, once per pid.
|
||||
///
|
||||
/// Returns `false` when the gates could not be read — the packer has not mapped
|
||||
/// that code yet, which is the Python's `continue`, not an error to report.
|
||||
pub fn cert_pass<M: Memory>(
|
||||
mem: &M,
|
||||
log: &mut impl FnMut(&str),
|
||||
patched: &mut HashSet<u32>,
|
||||
) -> bool {
|
||||
let pid = mem.pid();
|
||||
// Sized from the patterns themselves; the initial contents are overwritten by
|
||||
// the reads and are never compared unless both reads succeed.
|
||||
let mut g2 = GATE2_ORIG;
|
||||
let mut g1 = GATE1_ORIG;
|
||||
if mem.read(GATE2, &mut g2).is_err() || mem.read(GATE1, &mut g1).is_err() {
|
||||
return false;
|
||||
}
|
||||
|
||||
if g2 == GATE2_PATCH && g1 == GATE1_PATCH {
|
||||
log(&format!("pid {pid}: cert gates already patched"));
|
||||
patched.insert(pid);
|
||||
} else if g2 == GATE2_ORIG && g1 == GATE1_ORIG {
|
||||
match mem
|
||||
.write(GATE2, &GATE2_PATCH)
|
||||
.and_then(|()| mem.write(GATE1, &GATE1_PATCH))
|
||||
{
|
||||
Ok(()) => {
|
||||
log(&format!("pid {pid}: PATCHED cert gates"));
|
||||
patched.insert(pid);
|
||||
}
|
||||
Err(e) => log(&format!("pid {pid}: cert patch write failed: {e}")),
|
||||
}
|
||||
}
|
||||
// Anything else is a build we do not recognise: left alone, as in the Python.
|
||||
true
|
||||
}
|
||||
|
||||
/// Re-apply every store patch whose live bytes have drifted, then the guarded
|
||||
/// patch, then report the resolver-guard capability once per pid.
|
||||
///
|
||||
/// An `Err` is a read or write that failed outside the guarded site's own
|
||||
/// handling; it aborts the rest of this pid's pass for this tick, exactly like
|
||||
/// the Python's enclosing `try`.
|
||||
pub fn enforce_store_patches<M: Memory>(
|
||||
mem: &M,
|
||||
cbase: u64,
|
||||
log: &mut impl FnMut(&str),
|
||||
guard_reported: &mut HashSet<u32>,
|
||||
) -> io::Result<()> {
|
||||
let pid = mem.pid();
|
||||
|
||||
for (va, data) in STORE_PATCHES {
|
||||
let live = live_addr(cbase, va);
|
||||
let mut buf = [0u8; MAX_PATCH_LEN];
|
||||
let cur = &mut buf[..data.len()];
|
||||
mem.read(live, cur)?;
|
||||
if cur != data {
|
||||
mem.write(live, data)?;
|
||||
log(&format!("pid {pid}: ENFORCED store patch @ {live:#x}"));
|
||||
}
|
||||
}
|
||||
|
||||
for (va, orig, patch) in STORE_PATCHES_GUARDED {
|
||||
let live = live_addr(cbase, va);
|
||||
let mut before = [0u8; MAX_PATCH_LEN];
|
||||
mem.read(live, &mut before[..patch.len()])?;
|
||||
let cur = &before[..patch.len()];
|
||||
|
||||
let mut wrote_ok = true;
|
||||
// The Python starts with `cur_after = cur`, which only matters on the
|
||||
// branches that never re-read.
|
||||
let mut after = [0u8; MAX_PATCH_LEN];
|
||||
after[..patch.len()].copy_from_slice(cur);
|
||||
let mut after_len = patch.len();
|
||||
|
||||
match guarded_action(cur, orig, patch) {
|
||||
GuardedAction::Patch => {
|
||||
match mem.write(live, patch) {
|
||||
Ok(()) => log(&format!(
|
||||
"pid {pid}: ENFORCED guarded store patch @ {live:#x} (JNZ->JG, empty My Packs)"
|
||||
)),
|
||||
Err(e) => {
|
||||
wrote_ok = false;
|
||||
log(&format!(
|
||||
"pid {pid}: guarded patch write failed @ {live:#x}: {e}"
|
||||
));
|
||||
}
|
||||
}
|
||||
if wrote_ok && mem.read(live, &mut after[..patch.len()]).is_err() {
|
||||
// The Python's `cur_after = b""`: unverifiable, so not verified.
|
||||
after_len = 0;
|
||||
}
|
||||
}
|
||||
GuardedAction::Skip => log(&format!(
|
||||
"pid {pid}: SKIP guarded patch @ {live:#x}: unexpected {} (build mismatch)",
|
||||
hex(cur)
|
||||
)),
|
||||
// Already patched; nothing to write.
|
||||
GuardedAction::Noop => {}
|
||||
}
|
||||
|
||||
if va == RESOLVER_GUARD_VA && !guard_reported.contains(&pid) {
|
||||
let state = guard_state_after(cur, orig, patch, wrote_ok, &after[..after_len]);
|
||||
if state == GuardState::Verified {
|
||||
// PARSED BY THE LAUNCHER (fifa17_capability::parse_capability_line):
|
||||
// this line must keep both `verified capability` and the
|
||||
// `fifa17.empty_mypacks_resolver=<version>` token verbatim.
|
||||
log(&format!(
|
||||
"[store-guard] verified capability {EMPTY_MYPACKS_RESOLVER_CAPABILITY}={EMPTY_MYPACKS_RESOLVER_VERSION} fifa_pid={pid}"
|
||||
));
|
||||
} else {
|
||||
log(&format!(
|
||||
"[store-guard] guard status={state} fifa_pid={pid} (no capability advertised)"
|
||||
));
|
||||
}
|
||||
guard_reported.insert(pid);
|
||||
}
|
||||
}
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
use std::cell::RefCell;
|
||||
use std::collections::BTreeMap;
|
||||
|
||||
const CBASE: u64 = 0x7f2a11c00000;
|
||||
const GUARD_LIVE: u64 = CBASE + 0x14858;
|
||||
|
||||
/// Sparse fake address space: an unmapped byte reads as `NotFound`, mirroring
|
||||
/// `/proc/<pid>/mem` refusing an address the packer has not produced yet.
|
||||
struct FakeMemory {
|
||||
bytes: RefCell<BTreeMap<u64, u8>>,
|
||||
/// Writes to these addresses fail.
|
||||
fail_writes: Vec<u64>,
|
||||
/// Writes to these addresses report success but change nothing (the
|
||||
/// VERIFY_FAILED shape).
|
||||
swallow_writes: Vec<u64>,
|
||||
/// Reads of these addresses fail even when mapped.
|
||||
fail_reads: Vec<u64>,
|
||||
}
|
||||
|
||||
impl FakeMemory {
|
||||
fn new() -> Self {
|
||||
Self {
|
||||
bytes: RefCell::new(BTreeMap::new()),
|
||||
fail_writes: Vec::new(),
|
||||
swallow_writes: Vec::new(),
|
||||
fail_reads: Vec::new(),
|
||||
}
|
||||
}
|
||||
|
||||
fn map(self, va: u64, bytes: &[u8]) -> Self {
|
||||
{
|
||||
let mut mem = self.bytes.borrow_mut();
|
||||
for (i, b) in bytes.iter().enumerate() {
|
||||
mem.insert(va + i as u64, *b);
|
||||
}
|
||||
}
|
||||
self
|
||||
}
|
||||
|
||||
/// Every store-patch site mapped with filler that is neither the patch
|
||||
/// nor (for the guarded site) the original.
|
||||
fn with_store_sites(mut self, filler: u8) -> Self {
|
||||
for (va, data) in STORE_PATCHES {
|
||||
self = self.map(live_addr(CBASE, va), &vec![filler; data.len()]);
|
||||
}
|
||||
for (va, _, patch) in STORE_PATCHES_GUARDED {
|
||||
self = self.map(live_addr(CBASE, va), &vec![filler; patch.len()]);
|
||||
}
|
||||
self
|
||||
}
|
||||
|
||||
fn at(&self, va: u64, len: usize) -> Vec<u8> {
|
||||
let mem = self.bytes.borrow();
|
||||
(0..len as u64).map(|i| mem[&(va + i)]).collect()
|
||||
}
|
||||
}
|
||||
|
||||
impl Memory for FakeMemory {
|
||||
fn pid(&self) -> u32 {
|
||||
4242
|
||||
}
|
||||
|
||||
fn read(&self, va: u64, buf: &mut [u8]) -> io::Result<()> {
|
||||
if self.fail_reads.contains(&va) {
|
||||
return Err(io::Error::from(io::ErrorKind::PermissionDenied));
|
||||
}
|
||||
let mem = self.bytes.borrow();
|
||||
for (i, slot) in buf.iter_mut().enumerate() {
|
||||
*slot = *mem
|
||||
.get(&(va + i as u64))
|
||||
.ok_or_else(|| io::Error::from(io::ErrorKind::NotFound))?;
|
||||
}
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn write(&self, va: u64, data: &[u8]) -> io::Result<()> {
|
||||
if self.fail_writes.contains(&va) {
|
||||
return Err(io::Error::from(io::ErrorKind::PermissionDenied));
|
||||
}
|
||||
if self.swallow_writes.contains(&va) {
|
||||
return Ok(());
|
||||
}
|
||||
let mut mem = self.bytes.borrow_mut();
|
||||
for (i, b) in data.iter().enumerate() {
|
||||
mem.insert(va + i as u64, *b);
|
||||
}
|
||||
Ok(())
|
||||
}
|
||||
}
|
||||
|
||||
/// Collects log lines so the contract strings can be asserted verbatim.
|
||||
#[derive(Default)]
|
||||
struct Lines(Vec<String>);
|
||||
|
||||
impl Lines {
|
||||
fn sink(&mut self) -> impl FnMut(&str) + '_ {
|
||||
|line: &str| self.0.push(line.to_string())
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn cert_pass_defers_while_the_code_is_not_mapped() {
|
||||
let mem = FakeMemory::new();
|
||||
let mut lines = Lines::default();
|
||||
let mut patched = HashSet::new();
|
||||
assert!(!cert_pass(&mem, &mut lines.sink(), &mut patched));
|
||||
assert!(lines.0.is_empty(), "{:?}", lines.0);
|
||||
assert!(patched.is_empty());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn cert_pass_defers_when_only_the_first_gate_is_mapped() {
|
||||
let mem = FakeMemory::new().map(GATE2, &GATE2_ORIG);
|
||||
let mut lines = Lines::default();
|
||||
let mut patched = HashSet::new();
|
||||
assert!(!cert_pass(&mem, &mut lines.sink(), &mut patched));
|
||||
assert!(lines.0.is_empty());
|
||||
assert!(patched.is_empty());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn cert_pass_writes_both_gates_once() {
|
||||
let mem = FakeMemory::new()
|
||||
.map(GATE2, &GATE2_ORIG)
|
||||
.map(GATE1, &GATE1_ORIG);
|
||||
let mut lines = Lines::default();
|
||||
let mut patched = HashSet::new();
|
||||
assert!(cert_pass(&mem, &mut lines.sink(), &mut patched));
|
||||
assert_eq!(lines.0, vec!["pid 4242: PATCHED cert gates"]);
|
||||
assert_eq!(mem.at(GATE2, 3), GATE2_PATCH);
|
||||
assert_eq!(mem.at(GATE1, 6), GATE1_PATCH);
|
||||
assert!(patched.contains(&4242));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn cert_pass_recognises_an_already_patched_client() {
|
||||
let mem = FakeMemory::new()
|
||||
.map(GATE2, &GATE2_PATCH)
|
||||
.map(GATE1, &GATE1_PATCH);
|
||||
let mut lines = Lines::default();
|
||||
let mut patched = HashSet::new();
|
||||
assert!(cert_pass(&mem, &mut lines.sink(), &mut patched));
|
||||
assert_eq!(lines.0, vec!["pid 4242: cert gates already patched"]);
|
||||
assert!(patched.contains(&4242));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn cert_pass_reports_a_write_failure_and_stays_unpatched() {
|
||||
let mut mem = FakeMemory::new()
|
||||
.map(GATE2, &GATE2_ORIG)
|
||||
.map(GATE1, &GATE1_ORIG);
|
||||
mem.fail_writes.push(GATE2);
|
||||
let mut lines = Lines::default();
|
||||
let mut patched = HashSet::new();
|
||||
assert!(cert_pass(&mem, &mut lines.sink(), &mut patched));
|
||||
assert_eq!(lines.0.len(), 1);
|
||||
assert!(
|
||||
lines.0[0].starts_with("pid 4242: cert patch write failed: "),
|
||||
"{}",
|
||||
lines.0[0]
|
||||
);
|
||||
// Not recorded as patched, so the next tick tries again.
|
||||
assert!(patched.is_empty());
|
||||
assert_eq!(mem.at(GATE2, 3), GATE2_ORIG);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn cert_pass_leaves_an_unrecognised_build_alone() {
|
||||
let mem = FakeMemory::new()
|
||||
.map(GATE2, &[0x55, 0x48, 0x89])
|
||||
.map(GATE1, &[0x0f, 0x84, 0x76, 0x01, 0x00, 0x00]);
|
||||
let mut lines = Lines::default();
|
||||
let mut patched = HashSet::new();
|
||||
assert!(cert_pass(&mem, &mut lines.sink(), &mut patched));
|
||||
assert!(lines.0.is_empty(), "{:?}", lines.0);
|
||||
assert!(patched.is_empty());
|
||||
assert_eq!(mem.at(GATE2, 3), [0x55, 0x48, 0x89]);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn store_pass_enforces_every_site_in_table_order_then_advertises() {
|
||||
let mem = FakeMemory::new().with_store_sites(0xcc);
|
||||
let mut lines = Lines::default();
|
||||
let mut reported = HashSet::new();
|
||||
enforce_store_patches(&mem, CBASE, &mut lines.sink(), &mut reported).unwrap();
|
||||
|
||||
let mut expected: Vec<String> = STORE_PATCHES
|
||||
.iter()
|
||||
.map(|(va, _)| {
|
||||
let live = live_addr(CBASE, *va);
|
||||
format!("pid 4242: ENFORCED store patch @ {live:#x}")
|
||||
})
|
||||
.collect();
|
||||
// 0xcc is neither the original nor the patch: fail-closed SKIP, and the
|
||||
// capability is withheld.
|
||||
expected.push(format!(
|
||||
"pid 4242: SKIP guarded patch @ {GUARD_LIVE:#x}: unexpected cccc (build mismatch)"
|
||||
));
|
||||
expected.push(
|
||||
"[store-guard] guard status=UNSUPPORTED_BUILD fifa_pid=4242 (no capability advertised)"
|
||||
.to_string(),
|
||||
);
|
||||
assert_eq!(lines.0, expected);
|
||||
assert!(reported.contains(&4242));
|
||||
|
||||
for (va, data) in STORE_PATCHES {
|
||||
assert_eq!(mem.at(live_addr(CBASE, va), data.len()), data);
|
||||
}
|
||||
// The guarded site was NOT overwritten.
|
||||
assert_eq!(mem.at(GUARD_LIVE, 2), [0xcc, 0xcc]);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn store_pass_patches_the_guard_and_advertises_the_capability() {
|
||||
let mem = FakeMemory::new()
|
||||
.with_store_sites(0xcc)
|
||||
.map(GUARD_LIVE, STORE_PATCHES_GUARDED[0].1);
|
||||
let mut lines = Lines::default();
|
||||
let mut reported = HashSet::new();
|
||||
enforce_store_patches(&mem, CBASE, &mut lines.sink(), &mut reported).unwrap();
|
||||
|
||||
assert_eq!(
|
||||
lines.0[lines.0.len() - 2],
|
||||
format!(
|
||||
"pid 4242: ENFORCED guarded store patch @ {GUARD_LIVE:#x} (JNZ->JG, empty My Packs)"
|
||||
)
|
||||
);
|
||||
assert_eq!(
|
||||
lines.0[lines.0.len() - 1],
|
||||
"[store-guard] verified capability fifa17.empty_mypacks_resolver=1 fifa_pid=4242"
|
||||
);
|
||||
assert_eq!(mem.at(GUARD_LIVE, 2), [0x7f, 0x0f]);
|
||||
|
||||
// Second tick: everything already enforced, and the capability is not
|
||||
// re-advertised.
|
||||
let mut lines = Lines::default();
|
||||
enforce_store_patches(&mem, CBASE, &mut lines.sink(), &mut reported).unwrap();
|
||||
assert!(lines.0.is_empty(), "{:?}", lines.0);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn store_pass_verifies_an_already_patched_guard() {
|
||||
let mem = FakeMemory::new()
|
||||
.with_store_sites(0xcc)
|
||||
.map(GUARD_LIVE, STORE_PATCHES_GUARDED[0].2);
|
||||
let mut lines = Lines::default();
|
||||
let mut reported = HashSet::new();
|
||||
enforce_store_patches(&mem, CBASE, &mut lines.sink(), &mut reported).unwrap();
|
||||
assert_eq!(
|
||||
lines.0.last().unwrap(),
|
||||
"[store-guard] verified capability fifa17.empty_mypacks_resolver=1 fifa_pid=4242"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn store_pass_reports_a_guarded_write_failure_without_aborting_the_tick() {
|
||||
let mut mem = FakeMemory::new()
|
||||
.with_store_sites(0xcc)
|
||||
.map(GUARD_LIVE, STORE_PATCHES_GUARDED[0].1);
|
||||
mem.fail_writes.push(GUARD_LIVE);
|
||||
let mut lines = Lines::default();
|
||||
let mut reported = HashSet::new();
|
||||
// The guarded write failure is handled inline, so the pass still succeeds.
|
||||
enforce_store_patches(&mem, CBASE, &mut lines.sink(), &mut reported).unwrap();
|
||||
assert!(
|
||||
lines.0[lines.0.len() - 2]
|
||||
.starts_with(&format!("pid 4242: guarded patch write failed @ {GUARD_LIVE:#x}: ")),
|
||||
"{}",
|
||||
lines.0[lines.0.len() - 2]
|
||||
);
|
||||
assert_eq!(
|
||||
lines.0[lines.0.len() - 1],
|
||||
"[store-guard] guard status=WRITE_FAILED fifa_pid=4242 (no capability advertised)"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn store_pass_withholds_the_capability_when_verification_fails() {
|
||||
let mut mem = FakeMemory::new()
|
||||
.with_store_sites(0xcc)
|
||||
.map(GUARD_LIVE, STORE_PATCHES_GUARDED[0].1);
|
||||
// Write reported OK, memory unchanged: the re-read still shows the original.
|
||||
mem.swallow_writes.push(GUARD_LIVE);
|
||||
let mut lines = Lines::default();
|
||||
let mut reported = HashSet::new();
|
||||
enforce_store_patches(&mem, CBASE, &mut lines.sink(), &mut reported).unwrap();
|
||||
assert_eq!(
|
||||
lines.0[lines.0.len() - 1],
|
||||
"[store-guard] guard status=VERIFY_FAILED fifa_pid=4242 (no capability advertised)"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn store_pass_aborts_the_tick_when_a_site_is_not_mapped() {
|
||||
// CardsDLL is mapped but this tick catches a site mid-unpack.
|
||||
let mem = FakeMemory::new();
|
||||
let mut lines = Lines::default();
|
||||
let mut reported = HashSet::new();
|
||||
let err = enforce_store_patches(&mem, CBASE, &mut lines.sink(), &mut reported).unwrap_err();
|
||||
assert_eq!(err.kind(), io::ErrorKind::NotFound);
|
||||
assert!(lines.0.is_empty());
|
||||
// Nothing advertised, so the next tick re-evaluates the guard.
|
||||
assert!(reported.is_empty());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn store_pass_skips_writing_sites_that_already_hold_the_patch() {
|
||||
let mut mem = FakeMemory::new().with_store_sites(0xcc);
|
||||
for (va, data) in STORE_PATCHES {
|
||||
mem = mem.map(live_addr(CBASE, va), data);
|
||||
}
|
||||
mem = mem.map(GUARD_LIVE, STORE_PATCHES_GUARDED[0].2);
|
||||
// Any write at all would fail these sites, proving none is attempted.
|
||||
mem.fail_writes
|
||||
.extend(STORE_PATCHES.iter().map(|(va, _)| live_addr(CBASE, *va)));
|
||||
mem.fail_writes.push(GUARD_LIVE);
|
||||
|
||||
let mut lines = Lines::default();
|
||||
let mut reported = HashSet::new();
|
||||
enforce_store_patches(&mem, CBASE, &mut lines.sink(), &mut reported).unwrap();
|
||||
assert_eq!(
|
||||
lines.0,
|
||||
vec!["[store-guard] verified capability fifa17.empty_mypacks_resolver=1 fifa_pid=4242"]
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,160 @@
|
||||
//! `/proc` access: finding the client, locating CardsDLL, and positioned reads
|
||||
//! and writes against `/proc/<pid>/mem`.
|
||||
//!
|
||||
//! Positioned I/O (`pread`/`pwrite`) is used rather than seek+read: a 64-bit
|
||||
//! virtual address is passed straight through as the file offset, so nothing
|
||||
//! depends on a shared file cursor.
|
||||
|
||||
use std::fs::{self, File, OpenOptions};
|
||||
use std::io;
|
||||
use std::os::unix::fs::FileExt;
|
||||
|
||||
use crate::patch::Memory;
|
||||
use crate::{is_client_comm, parse_cardsdll_base, pid_from_proc_entry};
|
||||
|
||||
/// Pids whose `comm` is exactly `FIFA17.exe`.
|
||||
///
|
||||
/// Sorted ascending so that, when more than one client is somehow running, the
|
||||
/// per-pid log lines come out in a stable order (the Python inherits readdir
|
||||
/// order, which is arbitrary).
|
||||
pub fn find_pids() -> Vec<u32> {
|
||||
let mut out = Vec::new();
|
||||
let Ok(entries) = fs::read_dir("/proc") else {
|
||||
return out;
|
||||
};
|
||||
for entry in entries.flatten() {
|
||||
let name = entry.file_name();
|
||||
let Some(pid) = name.to_str().and_then(pid_from_proc_entry) else {
|
||||
continue;
|
||||
};
|
||||
// A pid can exit between readdir and this read; that is not an error.
|
||||
if let Ok(comm) = fs::read_to_string(format!("/proc/{pid}/comm")) {
|
||||
if is_client_comm(&comm) {
|
||||
out.push(pid);
|
||||
}
|
||||
}
|
||||
}
|
||||
out.sort_unstable();
|
||||
out
|
||||
}
|
||||
|
||||
/// Base address of the mapped CardsDLL, or `None` while it is not mapped.
|
||||
pub fn cardsdll_base(pid: u32) -> Option<u64> {
|
||||
let maps = fs::read_to_string(format!("/proc/{pid}/maps")).ok()?;
|
||||
parse_cardsdll_base(&maps)
|
||||
}
|
||||
|
||||
/// [`Memory`] over one live client process.
|
||||
pub struct ProcMem {
|
||||
pid: u32,
|
||||
}
|
||||
|
||||
impl ProcMem {
|
||||
pub fn new(pid: u32) -> Self {
|
||||
Self { pid }
|
||||
}
|
||||
}
|
||||
|
||||
impl Memory for ProcMem {
|
||||
fn pid(&self) -> u32 {
|
||||
self.pid
|
||||
}
|
||||
|
||||
/// A failure here normally means the address is not mapped yet — the packer
|
||||
/// has not unpacked that code — which the watch loop treats as "come back
|
||||
/// next tick", not as a failure worth reporting. Read-only handle.
|
||||
fn read(&self, va: u64, buf: &mut [u8]) -> io::Result<()> {
|
||||
File::open(format!("/proc/{}/mem", self.pid))?.read_exact_at(buf, va)
|
||||
}
|
||||
|
||||
/// Opened read+write like the Python's `r+b`; write-only is not universally
|
||||
/// accepted for `/proc/<pid>/mem` across kernels.
|
||||
fn write(&self, va: u64, data: &[u8]) -> io::Result<()> {
|
||||
OpenOptions::new()
|
||||
.read(true)
|
||||
.write(true)
|
||||
.open(format!("/proc/{}/mem", self.pid))?
|
||||
.write_all_at(data, va)
|
||||
}
|
||||
}
|
||||
|
||||
/// Whether `/proc/<pid>` still exists — the launcher-liveness check.
|
||||
pub fn pid_alive(pid: i64) -> bool {
|
||||
// Formatted exactly like the Python so a negative or zero pid behaves the
|
||||
// same way (the path simply does not exist).
|
||||
fs::metadata(format!("/proc/{pid}")).is_ok()
|
||||
}
|
||||
|
||||
/// Real uid of this process, from the ownership of `/proc/self`.
|
||||
///
|
||||
/// std exposes no `getuid`, and this crate takes no dependencies; `/proc` is
|
||||
/// mandatory for the patcher anyway, so reading it back is not a new assumption.
|
||||
pub fn current_uid() -> io::Result<u32> {
|
||||
use std::os::unix::fs::MetadataExt;
|
||||
Ok(fs::metadata("/proc/self")?.uid())
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn our_own_pid_is_alive_and_pid_zero_is_not() {
|
||||
let me: i64 = fs::read_to_string("/proc/self/stat")
|
||||
.unwrap()
|
||||
.split(' ')
|
||||
.next()
|
||||
.unwrap()
|
||||
.parse()
|
||||
.unwrap();
|
||||
assert!(pid_alive(me));
|
||||
// /proc/0 and /proc/-1 never exist, matching the Python's path check.
|
||||
assert!(!pid_alive(0));
|
||||
assert!(!pid_alive(-1));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn uid_is_readable() {
|
||||
// Only that it resolves; the value is environment-dependent.
|
||||
assert!(current_uid().is_ok());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn find_pids_scan_is_safe_without_a_client() {
|
||||
// Deterministic without a client: the scan must not panic and must only
|
||||
// ever return numeric pids.
|
||||
for pid in find_pids() {
|
||||
assert!(pid > 0);
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn positioned_io_round_trips_against_our_own_address_space() {
|
||||
// Patching FIFA is not testable here, but the /proc/<pid>/mem mechanism
|
||||
// is: read and write this process's own heap through the same code path.
|
||||
let me: u32 = fs::read_to_string("/proc/self/stat")
|
||||
.unwrap()
|
||||
.split(' ')
|
||||
.next()
|
||||
.unwrap()
|
||||
.parse()
|
||||
.unwrap();
|
||||
let mem = ProcMem::new(me);
|
||||
// black_box throughout: this buffer is mutated by the kernel on our
|
||||
// behalf, never by Rust code, so the compiler must not assume it is
|
||||
// unchanged across the write.
|
||||
let target = std::hint::black_box(vec![0x75u8, 0x0f, 0x11, 0x22]);
|
||||
let va = target.as_ptr() as u64;
|
||||
|
||||
let mut seen = [0u8; 4];
|
||||
mem.read(va, &mut seen).unwrap();
|
||||
assert_eq!(seen, *target);
|
||||
|
||||
mem.write(va, &[0x7f, 0x0f]).unwrap();
|
||||
assert_eq!(*std::hint::black_box(&target), [0x7f, 0x0f, 0x11, 0x22]);
|
||||
|
||||
// An address that is certainly not mapped reads as an error, which the
|
||||
// watch loop treats as "not unpacked yet".
|
||||
assert!(mem.read(0x1000, &mut seen).is_err());
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,38 @@
|
||||
[package]
|
||||
name = "openfut-blaze-host"
|
||||
version = "0.1.0"
|
||||
edition = "2021"
|
||||
license = "MIT"
|
||||
description = "Thin TCP host for the FIFA 17 Blaze RPC surface; runs beside the Python backend"
|
||||
publish = false
|
||||
|
||||
[dependencies]
|
||||
openfut-protocol-blaze = { path = "../openfut-protocol-blaze" }
|
||||
openfut-adapter-fifa17 = { path = "../openfut-adapter-fifa17" }
|
||||
# Session keys. The client never validates them, but they must be distinct per
|
||||
# connection; seeding from the clock would not be.
|
||||
rand = "0.8"
|
||||
# The probe replays the adapter's recorded fixture conversation.
|
||||
serde_json = "1"
|
||||
|
||||
# No async runtime and no TLS, both deliberate:
|
||||
# * A FIFA client opens a handful of connections, so a thread each mirrors the
|
||||
# Python oracle and keeps the host readable.
|
||||
# * The Blaze main port is plaintext — verified against the running backend.
|
||||
# TLS belongs to the redirector phase.
|
||||
|
||||
[[bin]]
|
||||
name = "openfut-blaze-host"
|
||||
path = "src/main.rs"
|
||||
|
||||
[[bin]]
|
||||
name = "blaze-probe"
|
||||
path = "src/bin/blaze-probe.rs"
|
||||
|
||||
[[bin]]
|
||||
name = "tls-observe"
|
||||
path = "src/bin/tls-observe.rs"
|
||||
|
||||
[[bin]]
|
||||
name = "blaze-sanitize"
|
||||
path = "src/bin/blaze-sanitize.rs"
|
||||
@@ -0,0 +1,293 @@
|
||||
# openfut-blaze-host
|
||||
|
||||
A deliberately thin TCP host for the FIFA 17 Blaze RPC surface. Runs **beside**
|
||||
the working Python backend, never instead of it.
|
||||
|
||||
```
|
||||
listener → Fire2 stream framing → per-connection Session
|
||||
│
|
||||
openfut-adapter-fifa17::dispatch
|
||||
│
|
||||
write returned frames, in order
|
||||
```
|
||||
|
||||
## Scope
|
||||
|
||||
Owns: a socket, a read buffer, one `Session` per connection, diagnostics.
|
||||
That is the complete list.
|
||||
|
||||
Must never acquire: coins, club state, packs, profiles, market state, UTAS
|
||||
logic. Those belong to OpenFUT Core, reached later through the adapter. A
|
||||
transport host that starts holding game state becomes a second backend — the
|
||||
architecture this migration exists to avoid.
|
||||
|
||||
## No TLS
|
||||
|
||||
The Blaze main port is **plaintext**. Verified against the running Python
|
||||
backend by sending a raw Fire2 `Util::ping` and getting a plaintext
|
||||
`PingResponse` back; `blaze_responder_v3b.py::blaze_handle` uses the raw socket
|
||||
and only `redir_handle` wraps `ssl`. TLS belongs to the redirector phase.
|
||||
|
||||
## Running it
|
||||
|
||||
Both critical settings are required — there is no default port anywhere in this
|
||||
crate, so it cannot silently collide with the Python container.
|
||||
|
||||
```bash
|
||||
cargo build -p openfut-blaze-host
|
||||
|
||||
OPENFUT_ADVERTISE=<backend LAN ip> \
|
||||
OPENFUT_BIND=0.0.0.0 \
|
||||
POW_CONTENT_HOST=<backend LAN ip>:8085 \
|
||||
OPENFUT_BLAZE_HOST_BIND=0.0.0.0 \
|
||||
OPENFUT_BLAZE_HOST_PORT=<free port> \
|
||||
OPENFUT_BLAZE_TRACE=/tmp/rust-blaze.trace \
|
||||
./target/debug/openfut-blaze-host
|
||||
```
|
||||
|
||||
`OPENFUT_BIND` is the **advertised-config** bind, not the listener's. The
|
||||
adapter derives `nucleusConnect` from it (reproducing the oracle — see the
|
||||
adapter README and the vault's known-issue entry), so it must mirror whatever
|
||||
the Python container runs with, or the two will not compare. The listener has
|
||||
its own `OPENFUT_BLAZE_HOST_BIND`.
|
||||
|
||||
For a FIFA test from another machine, `OPENFUT_BLAZE_HOST_BIND` must be `0.0.0.0`
|
||||
(or the LAN address); the default follows `OPENFUT_BIND`.
|
||||
|
||||
## Live A/B against Python
|
||||
|
||||
```bash
|
||||
./check-live-parity.sh 127.0.0.1:42130 127.0.0.1:<rust port>
|
||||
```
|
||||
|
||||
Replays the recorded conversations against both endpoints over real sockets and
|
||||
diffs the normalized traces. Session keys and server timestamps are masked, so
|
||||
anything that differs is a real behavioural difference.
|
||||
|
||||
**The diff is the test, not the probe's exit code.** The probe only detects
|
||||
anomalies visible live — missing frames, an early close. A same-length content
|
||||
change deep inside a notification body shows up *only* as a digest difference in
|
||||
the trace. Both cases were verified by mutation.
|
||||
|
||||
For the comparison to mean anything both servers must run the same config —
|
||||
same `OPENFUT_ADVERTISE`, `OPENFUT_BIND`, `POW_CONTENT_HOST` and active persona
|
||||
— or legitimate config differences read as parity failures.
|
||||
|
||||
Current result against the live container:
|
||||
|
||||
```
|
||||
main: IDENTICAL (82 frames)
|
||||
fallbacks: IDENTICAL (12 frames)
|
||||
locale: IDENTICAL (7 frames)
|
||||
LIVE PARITY OK — 101 frames, identical normalized traces.
|
||||
```
|
||||
|
||||
## Tests
|
||||
|
||||
`cargo test -p openfut-blaze-host` — 18 tests. The integration suite runs the
|
||||
real host on an ephemeral port and replays the recorded conversations over TCP,
|
||||
covering what fixtures cannot:
|
||||
|
||||
* byte-for-byte replay over a socket
|
||||
* requests dribbled **one byte at a time** (fragmentation)
|
||||
* several requests in **one write** (coalescing)
|
||||
* the four-frame login burst arriving in order on the wire
|
||||
* session state persisting across frames, and *not* leaking between connections
|
||||
* an absurd payload length closing the connection instead of allocating
|
||||
* an undecodable body still getting a reply
|
||||
|
||||
Byte-exactness is possible only because `Hooks` injects the session key and
|
||||
clock — they appear inside response bodies, so with the real ones no live run
|
||||
could reproduce a recording. That is the crate's only test seam.
|
||||
|
||||
## Promotion gates
|
||||
|
||||
Automated, re-runnable now:
|
||||
|
||||
1. ✅ All migration tests pass (116 across the three crates).
|
||||
2. ✅ Python contract suite still 446/446.
|
||||
3. ✅ Scripted connection to the Rust host succeeds.
|
||||
4. ✅ Recorded conversations work through the real TCP host, and the live A/B
|
||||
against Python is identical over 101 frames.
|
||||
|
||||
Requiring a FIFA client on the game machine — **not yet done**:
|
||||
|
||||
5. ⬜ FIFA reaches FUT with Rust Blaze.
|
||||
6. ⬜ Open a pack — exercise a known-working FUT action, not just bootstrap.
|
||||
7. ⬜ Close FIFA completely.
|
||||
8. ⬜ Repeat 5–6 with Rust Blaze.
|
||||
9. ⬜ Switch back to Python Blaze and verify FUT still works.
|
||||
10. ⬜ Switch to Rust once more and verify again.
|
||||
|
||||
Gates 9 and 10 matter as much as 5: `Python → Rust → Rust → Python → Rust`
|
||||
proves the rollback path rather than asserting one exists.
|
||||
|
||||
## Process and switch safety
|
||||
|
||||
Both were built after real incidents, not speculatively.
|
||||
|
||||
* **Orphaned sidecars.** A previous session's mutation runs left four sidecars
|
||||
listening, two serving deliberately broken builds. `sidecar.sh` refuses to
|
||||
start when any sidecar is already running, and `stop` verifies both that the
|
||||
PID is gone and that the port is free — failing if either check does not hold.
|
||||
Orphan detection matches the resolved *executable*, not the command line:
|
||||
`pgrep -f` was tried first and matched any shell whose arguments merely
|
||||
mentioned the name.
|
||||
* **A rollback that lied.** `blaze-switch.sh off` once reported success while
|
||||
two rules remained active, because it matched `--comment "tag"` with quotes
|
||||
that this iptables does not emit — and the verification used the same broken
|
||||
matcher, so it confirmed its own failure. Rules are now matched on the bare
|
||||
tag string, and `off` verifies with `iptables-save` plus a tag-independent
|
||||
check that nothing still redirects the port.
|
||||
|
||||
The general lesson, now applied throughout: **a verification must not share the
|
||||
failure mode of the thing it verifies.**
|
||||
|
||||
### Running gates 5–10
|
||||
|
||||
The Python redirector advertises a hardcoded `BLAZE_PORT = 42130`
|
||||
(`blaze_responder_v3b.py:173`), so redirecting Blaze by reconfiguring it would
|
||||
mean editing the frozen oracle and rebuilding the container. `blaze-switch.sh`
|
||||
does it with a scoped NAT rule instead: no Python change, instant rollback.
|
||||
|
||||
Rules match only `<LAN_IP>:42130`. Traffic to `127.0.0.1:42130` is deliberately
|
||||
left alone, so Python stays directly reachable on loopback and the A/B keeps
|
||||
comparing real Python against real Rust.
|
||||
|
||||
```bash
|
||||
cargo build -p openfut-blaze-host
|
||||
|
||||
export OPENFUT_ADVERTISE=<LAN_IP> OPENFUT_BIND=0.0.0.0 \
|
||||
POW_CONTENT_HOST=<LAN_IP>:8085 \
|
||||
OPENFUT_BLAZE_HOST_BIND=0.0.0.0 OPENFUT_BLAZE_HOST_PORT=<FREE_PORT> \
|
||||
OPENFUT_BLAZE_TRACE=/tmp/rust-blaze.trace
|
||||
|
||||
./sidecar.sh start # refuses if an orphan or the port is busy
|
||||
./blaze-switch.sh on <LAN_IP> <FREE_PORT> # Blaze -> Rust
|
||||
./blaze-switch.sh status # confirm before launching FIFA
|
||||
|
||||
# … launch FIFA, reach FUT, OPEN A PACK, close FIFA, repeat …
|
||||
|
||||
./blaze-switch.sh off # Blaze -> Python (rollback)
|
||||
./sidecar.sh stop # refuses while the switch is on
|
||||
```
|
||||
|
||||
`sidecar.sh stop` **refuses** while the switch is on: stopping the sidecar then
|
||||
would leave Blaze pointed at a dead port. Use `stop --force` only deliberately.
|
||||
|
||||
Evidence to keep from each live run:
|
||||
|
||||
* `/tmp/rust-blaze.trace` — the normalized trace, which begins with the build
|
||||
banner, so a session is attributable to an exact binary and config table
|
||||
* the sidecar log — connection accepted, preAuth, login, the three
|
||||
notifications, subsequent commands, close reason
|
||||
* whether the pack opened, not just whether the hub loaded
|
||||
|
||||
Then compare the Rust trace against a Python session trace. Message numbers and
|
||||
timestamps are session-dependent and masked; the semantic sequence and payload
|
||||
shapes must match.
|
||||
|
||||
## Diagnostics
|
||||
|
||||
The log mirrors the Python responder's shape so the two can be read side by
|
||||
side: connection id, peer, frame number, route, msgType, msgNum, userIndex,
|
||||
options, payload and metadata sizes, every response emitted, and a close reason.
|
||||
|
||||
`OPENFUT_BLAZE_TRACE=<path>` additionally writes the normalized structural
|
||||
trace — the same format the probe emits, so a live FIFA session against Rust can
|
||||
be diffed against one against Python.
|
||||
|
||||
No credential or token is logged. Volatile values are replaced before they reach
|
||||
the line, not truncated after, and a test asserts a known secret never appears
|
||||
in trace output.
|
||||
|
||||
## Evidence capture per gate
|
||||
|
||||
```bash
|
||||
./gate-evidence.sh <gate-label> # after each gate; never modifies anything
|
||||
```
|
||||
|
||||
Writes a timestamped bundle (switch rules, sidecar status, log, trace, Python
|
||||
contract result) and reports **configured** and **observed** state separately.
|
||||
|
||||
That separation is the point. `blaze-switch.sh status = ON` is an assertion from
|
||||
the same tooling that performs the switch — and that tooling reported a
|
||||
successful rollback once when it had not happened. The observed half comes from
|
||||
a different source: the sidecar's own record of which peers connected to it. A
|
||||
non-loopback peer in the sidecar log is proof the client's Blaze traffic landed
|
||||
on Rust that does not depend on reading an iptables rule correctly.
|
||||
|
||||
The script says so explicitly, in one of two forms:
|
||||
|
||||
```
|
||||
REMOTE peer(s) reached the Rust sidecar: 10.10.0.x
|
||||
=> the client's Blaze traffic observably landed on Rust
|
||||
```
|
||||
```
|
||||
no remote peer connected — only loopback (or nothing) reached Rust
|
||||
=> a FIFA session did NOT land here
|
||||
```
|
||||
|
||||
## Raw frame capture (opt-in)
|
||||
|
||||
Evidence infrastructure, off unless `OPENFUT_BLAZE_CAPTURE` names a file.
|
||||
|
||||
```bash
|
||||
OPENFUT_BLAZE_CAPTURE=/home/alex/OpenFUT/captures/gate7.ofcap ./sidecar.sh start
|
||||
```
|
||||
|
||||
Two layers, deliberately:
|
||||
|
||||
```
|
||||
live FIFA traffic
|
||||
├── raw capture exact RX/TX bytes, mode 0600, gitignored — NEVER commit
|
||||
└── blaze-sanitize → repository-safe, replayable fixtures
|
||||
```
|
||||
|
||||
The raw file is forensic evidence and does contain session material; that is
|
||||
what makes it worth keeping and why it never leaves the machine unsanitized.
|
||||
|
||||
**Format.** Deterministic, big-endian: a 20-byte file header, then per-frame
|
||||
records with connection id, a global monotonic sequence, timestamp, direction
|
||||
and the exact frame bytes. RX is recorded as received; TX only *after* a
|
||||
successful write, so a record means the bytes were sent, not intended.
|
||||
|
||||
Component, command, msgNum, msgType and payload length are **not** stored beside
|
||||
the frame — they are already in its 16-byte header, and a redundant copy can
|
||||
disagree with the bytes, leaving a reader unable to tell which is true.
|
||||
`Record::header()` derives them.
|
||||
|
||||
### Sanitizing
|
||||
|
||||
```bash
|
||||
./target/debug/blaze-sanitize captures/gate7.ofcap -o gate7.jsonl --report gate7.txt
|
||||
```
|
||||
|
||||
Redacts only the named tags (`KEY`, `AUTH`, `SESS`, `MAIL`, `PML`) and reports
|
||||
every substitution with path, kind and byte length. Replacement is
|
||||
**length-preserving**, so the TDF varint, payload length and Fire2 header are
|
||||
unchanged and the sanitized frame is exactly the size of the captured one —
|
||||
asserted per frame, failing rather than emitting a subtly different
|
||||
conversation. Frames with nothing sensitive keep their exact wire bytes.
|
||||
Payloads that will not decode are passed through *and reported*, so a reader
|
||||
knows they were never inspected rather than assuming they were checked clean.
|
||||
|
||||
Real run: 101 frames in, 9 redacted, 13 redactions; two live session keys
|
||||
present in the raw capture, zero in the sanitized output.
|
||||
|
||||
### What the tests do and do not cover
|
||||
|
||||
Nine cases, all passing: capture off produces no artefact; RX and TX captured
|
||||
exactly; ordering preserved; fragmented input (one byte at a time) reconstructs
|
||||
the same frames as a single write; coalesced input is captured per frame rather
|
||||
than per read; capture does not alter wire output; sanitization removes a real
|
||||
session key from a real captured login; malformed/truncated/wrong-version
|
||||
captures fail clearly; every listed sensitive tag is provably reachable.
|
||||
|
||||
Mutation-tested: dropping TX capture, truncating captured frames to their
|
||||
header, and removing `KEY` from the sensitive list each turn the suite red.
|
||||
|
||||
**One mutation is not caught:** moving the TX capture above the write. It is
|
||||
indistinguishable while writes succeed and diverges only when one fails, where
|
||||
it would record a frame the client never received. That invariant is held by
|
||||
code placement and a comment, not by a test.
|
||||
Executable
+73
@@ -0,0 +1,73 @@
|
||||
#!/usr/bin/env bash
|
||||
# Blaze switch — COMPATIBILITY WRAPPER over openfut-switch.sh.
|
||||
#
|
||||
# blaze-switch.sh status
|
||||
# blaze-switch.sh on <LAN_IP> <RUST_PORT> Blaze -> Rust sidecar
|
||||
# blaze-switch.sh off Blaze -> Python (rollback)
|
||||
#
|
||||
# The CLI and output are unchanged from the version used for gates 5–10, so the
|
||||
# validated Blaze runbook and `sidecar.sh`'s cross-check keep working exactly as
|
||||
# before. All iptables logic now lives in `openfut-switch.sh`: one
|
||||
# implementation, because two scripts editing the same table diverge and then
|
||||
# disagree about what is installed.
|
||||
#
|
||||
# The only Blaze-specific knowledge left here is the intercepted port, 42130,
|
||||
# which the generic tool never assumes.
|
||||
set -uo pipefail
|
||||
|
||||
HERE="$(cd "$(dirname "$(readlink -f "$0")")" && pwd)"
|
||||
GENERIC="$HERE/openfut-switch.sh"
|
||||
BLAZE_PORT=42130
|
||||
NAME=blaze
|
||||
# Tag used before the switch was generalised. Rules installed by the gate 5-10
|
||||
# tooling still carry it, so they must remain removable — a rename that orphans
|
||||
# live NAT rules is worse than no rename at all.
|
||||
LEGACY_TAG=openfut-blaze-switch
|
||||
|
||||
[[ -x "$GENERIC" ]] || { echo "blaze-switch: missing $GENERIC" >&2; exit 2; }
|
||||
|
||||
case "${1:-}" in
|
||||
status)
|
||||
# Translate the generic report into the wording the Blaze runbook and
|
||||
# sidecar.sh already match on ("redirected to the RUST" / "served by
|
||||
# PYTHON"). Kept verbatim so the proven tooling does not change.
|
||||
out="$("$GENERIC" status --name "$NAME" --legacy-tag "$LEGACY_TAG" --intercept-port "$BLAZE_PORT" 2>&1)"
|
||||
rc=$?
|
||||
if grep -q '^INACTIVE' <<<"$out"; then
|
||||
echo "Blaze is served by PYTHON (no switch rules)"
|
||||
else
|
||||
echo "Blaze is redirected to the RUST sidecar:"
|
||||
grep -E '^\s+(blaze|openfut-switch)' <<<"$out" | sed 's/^/ /'
|
||||
grep -E '^\s+!!|\?\?' <<<"$out" >&2 || true
|
||||
fi
|
||||
exit $rc
|
||||
;;
|
||||
on)
|
||||
shift
|
||||
ip="${1:-}"; port="${2:-}"
|
||||
[[ -n "$ip" && -n "$port" ]] || {
|
||||
echo "usage: blaze-switch.sh on <LAN_IP> <RUST_PORT>" >&2; exit 2; }
|
||||
"$GENERIC" on --name "$NAME" --legacy-tag "$LEGACY_TAG" --server-ip "$ip" \
|
||||
--intercept-port "$BLAZE_PORT" --target-port "$port" >/dev/null || exit 1
|
||||
echo "Blaze -> RUST: $ip:$BLAZE_PORT now lands on local port $port"
|
||||
echo " 127.0.0.1:$BLAZE_PORT still reaches PYTHON (unmatched by design)"
|
||||
echo " roll back with: $0 off"
|
||||
echo
|
||||
echo " NOTE: while this is on, the sidecar MUST stay up. Stopping it without"
|
||||
echo " switching off leaves Blaze pointing at a dead port."
|
||||
;;
|
||||
off)
|
||||
out="$("$GENERIC" off --name "$NAME" --legacy-tag "$LEGACY_TAG" --intercept-port "$BLAZE_PORT" 2>&1)"
|
||||
rc=$?
|
||||
if [[ $rc -ne 0 ]]; then
|
||||
echo "$out" >&2
|
||||
exit $rc
|
||||
fi
|
||||
n="$(sed -nE 's/.*removed ([0-9]+) rule.*/\1/p' <<<"$out")"
|
||||
echo "Blaze -> PYTHON: removed ${n:-0} rule(s), verified none remain"
|
||||
;;
|
||||
*)
|
||||
sed -n '2,8p' "$0" | sed 's/^# \?//'
|
||||
exit 2
|
||||
;;
|
||||
esac
|
||||
@@ -0,0 +1,78 @@
|
||||
//! Stamp build identity into the binary.
|
||||
//!
|
||||
//! A live FIFA trace has to be attributable to an exact binary. During the
|
||||
//! mutation runs for the previous step, four sidecars were left listening —
|
||||
//! two of them serving deliberately broken builds — and nothing in their output
|
||||
//! said so. A later A/B against one of those would have read as a genuine
|
||||
//! parity failure.
|
||||
//!
|
||||
//! So the host prints its commit, working-tree cleanliness and profile at
|
||||
//! startup, and `dirty` is the important one: a mutation-tested build is a
|
||||
//! dirty build, and now it announces itself.
|
||||
|
||||
use std::process::Command;
|
||||
|
||||
fn git(args: &[&str]) -> Option<String> {
|
||||
let out = Command::new("git").args(args).output().ok()?;
|
||||
if !out.status.success() {
|
||||
return None;
|
||||
}
|
||||
Some(String::from_utf8_lossy(&out.stdout).trim().to_string())
|
||||
}
|
||||
|
||||
fn main() {
|
||||
let commit = git(&["rev-parse", "--short=7", "HEAD"]).unwrap_or_else(|| "unknown".into());
|
||||
|
||||
// Scoped to the crates this binary is actually built from.
|
||||
//
|
||||
// A whole-repo check reads DIRTY permanently here, because unrelated
|
||||
// submodules carry pre-existing modifications. A warning that is always on
|
||||
// is a warning nobody reads — which would defeat the point, since the whole
|
||||
// job of this flag is to make a mutated build announce itself.
|
||||
//
|
||||
// Untracked files are excluded: scratch output is not a build difference,
|
||||
// but an edited source file certainly is.
|
||||
let dirty = match git(&[
|
||||
"status",
|
||||
"--porcelain",
|
||||
"--untracked-files=no",
|
||||
"--",
|
||||
"openfut-blaze-host",
|
||||
"openfut-adapter-fifa17",
|
||||
"openfut-protocol-blaze",
|
||||
]) {
|
||||
Some(s) if !s.is_empty() => "DIRTY",
|
||||
Some(_) => "clean",
|
||||
None => "unknown",
|
||||
};
|
||||
|
||||
println!("cargo:rustc-env=OPENFUT_BUILD_COMMIT={commit}");
|
||||
println!("cargo:rustc-env=OPENFUT_BUILD_DIRTY={dirty}");
|
||||
|
||||
// Re-stamp when HEAD moves.
|
||||
//
|
||||
// IMPORTANT LIMITATION: this flag is best-effort and CAN BE STALE. Cargo
|
||||
// will not re-run a build script because some other crate's source changed,
|
||||
// so editing the adapter and rebuilding the host can leave `dirty` reading
|
||||
// "clean". Verified: appending a line to the adapter and rebuilding did not
|
||||
// flip it.
|
||||
//
|
||||
// So the compiled-in value is useful for naming the commit, and is NOT the
|
||||
// safeguard. `sidecar.sh` re-checks the working tree at launch and
|
||||
// `check-live-parity.sh` refuses to produce evidence from a dirty tree —
|
||||
// those run at the right moment and cannot go stale.
|
||||
for p in ["../.git/HEAD", "../.git/index"] {
|
||||
if std::path::Path::new(p).exists() {
|
||||
println!("cargo:rerun-if-changed={p}");
|
||||
}
|
||||
}
|
||||
// Committing updates refs/heads/<branch>, NOT the HEAD file, so watching
|
||||
// HEAD alone leaves the stamp one commit behind. Observed: the banner read
|
||||
// a84a72e immediately after committing 2337431.
|
||||
if let Some(rf) = git(&["symbolic-ref", "-q", "HEAD"]) {
|
||||
let path = format!("../.git/{rf}");
|
||||
if std::path::Path::new(&path).exists() {
|
||||
println!("cargo:rerun-if-changed={path}");
|
||||
}
|
||||
}
|
||||
}
|
||||
Executable
+84
@@ -0,0 +1,84 @@
|
||||
#!/usr/bin/env bash
|
||||
# Live A/B: the Python Blaze responder vs the Rust sidecar, over real sockets.
|
||||
#
|
||||
# ./check-live-parity.sh <python-host:port> <rust-host:port> [outdir]
|
||||
#
|
||||
# Replays the recorded conversations against BOTH endpoints and diffs the
|
||||
# normalized traces. Session keys and server timestamps are masked, so anything
|
||||
# that differs is a real behavioural difference.
|
||||
#
|
||||
# IMPORTANT: the diff is the test, not the probe's exit code. The probe only
|
||||
# detects structural anomalies it can see live (missing frames, early close); a
|
||||
# same-length content change deep inside a notification body shows up ONLY as a
|
||||
# digest difference in the trace. Verified by mutation.
|
||||
#
|
||||
# Read-only against both backends: it opens client connections and sends
|
||||
# recorded requests. Safe to run while the Python backend is serving.
|
||||
#
|
||||
# For the comparison to mean anything, BOTH servers must run the same config —
|
||||
# same OPENFUT_ADVERTISE, OPENFUT_BIND, POW_CONTENT_HOST and active persona.
|
||||
# Otherwise legitimate config differences read as parity failures.
|
||||
set -uo pipefail
|
||||
|
||||
PY="${1:-}"
|
||||
RS="${2:-}"
|
||||
OUT="${3:-$(mktemp -d)}"
|
||||
|
||||
if [[ -z "$PY" || -z "$RS" ]]; then
|
||||
echo "usage: $0 <python-host:port> <rust-host:port> [outdir]" >&2
|
||||
echo "example: $0 127.0.0.1:42130 127.0.0.1:42230" >&2
|
||||
exit 2
|
||||
fi
|
||||
|
||||
cd "$(dirname "$(readlink -f "$0")")/.."
|
||||
PROBE="./target/debug/blaze-probe"
|
||||
[[ -x "$PROBE" ]] || PROBE="./target/release/blaze-probe"
|
||||
if [[ ! -x "$PROBE" ]]; then
|
||||
echo "blaze-probe not built; run: cargo build -p openfut-blaze-host" >&2
|
||||
exit 2
|
||||
fi
|
||||
|
||||
# This script produces the artefact a migration decision is made from, so it
|
||||
# refuses to run against a tree that does not correspond to a commit. The
|
||||
# compiled-in build stamp cannot be trusted for this (cargo will not re-run
|
||||
# build.rs for another crate's edit), so the check happens here, now.
|
||||
if git rev-parse --git-dir >/dev/null 2>&1; then
|
||||
DIRT="$(git status --porcelain --untracked-files=no -- \
|
||||
openfut-blaze-host openfut-adapter-fifa17 openfut-protocol-blaze 2>/dev/null)"
|
||||
if [[ -n "$DIRT" && "${ALLOW_DIRTY:-}" != "1" ]]; then
|
||||
echo "REFUSING: migration crates have uncommitted changes:" >&2
|
||||
echo "$DIRT" | sed 's/^/ /' >&2
|
||||
echo >&2
|
||||
echo "A parity result from an unidentifiable build is not evidence." >&2
|
||||
echo "Commit first, or re-run with ALLOW_DIRTY=1 for a throwaway check." >&2
|
||||
exit 2
|
||||
fi
|
||||
fi
|
||||
|
||||
mkdir -p "$OUT"
|
||||
fail=0
|
||||
frames=0
|
||||
|
||||
for sess in main fallbacks locale; do
|
||||
"$PROBE" "$PY" --session "$sess" > "$OUT/python-$sess.trace" 2>"$OUT/python-$sess.err" || true
|
||||
"$PROBE" "$RS" --session "$sess" > "$OUT/rust-$sess.trace" 2>"$OUT/rust-$sess.err" || true
|
||||
|
||||
n=$(grep -c '^conn-' "$OUT/python-$sess.trace" || true)
|
||||
if diff -u "$OUT/python-$sess.trace" "$OUT/rust-$sess.trace" > "$OUT/diff-$sess.txt"; then
|
||||
echo " $sess: IDENTICAL ($n frames)"
|
||||
frames=$((frames + n))
|
||||
else
|
||||
echo " $sess: DIFFERS -> $OUT/diff-$sess.txt"
|
||||
head -30 "$OUT/diff-$sess.txt"
|
||||
fail=1
|
||||
fi
|
||||
done
|
||||
|
||||
echo
|
||||
if [[ $fail -eq 0 ]]; then
|
||||
echo "LIVE PARITY OK — $frames frames, identical normalized traces."
|
||||
echo "traces: $OUT"
|
||||
else
|
||||
echo "LIVE PARITY FAILED — see $OUT"
|
||||
fi
|
||||
exit $fail
|
||||
Executable
+87
@@ -0,0 +1,87 @@
|
||||
#!/usr/bin/env bash
|
||||
# Is the FIFA client currently connected to anything?
|
||||
#
|
||||
# client-state.sh [client-ip]
|
||||
#
|
||||
# WHY THIS EXISTS
|
||||
#
|
||||
# Host-side `ss` CANNOT see the Python backend's connections. The Python
|
||||
# responders run inside a container, so a client session terminates at
|
||||
# 172.20.0.2:42130 in the container's network namespace; the host only ever sees
|
||||
# the NAT'd flow, and a plain `ss | grep <client>` on the host reports nothing.
|
||||
#
|
||||
# That produced a wrong precondition check: "no .105 Blaze session — closed" was
|
||||
# reported while FIFA was mid-session on Python, and gate 9 was armed against a
|
||||
# client that had never exited. Python's own log gave it away — it logs closes
|
||||
# reliably (45 of them) and there was no close for that session.
|
||||
#
|
||||
# So this looks in BOTH namespaces, and reports the Rust sidecar and the Python
|
||||
# container separately.
|
||||
#
|
||||
# Exit 0 when the client has no live session anywhere (safe to start a gate),
|
||||
# 1 when it does.
|
||||
set -uo pipefail
|
||||
|
||||
CLIENT="${1:-${OPENFUT_CLIENT_IP:-}}"
|
||||
if [[ -z "$CLIENT" ]]; then
|
||||
echo "usage: client-state.sh <client-ip> (or set OPENFUT_CLIENT_IP)" >&2
|
||||
echo " no default: the lab's address is deployment config, not architecture," >&2
|
||||
echo " and a default that matches the current lab hides the coupling." >&2
|
||||
exit 2
|
||||
fi
|
||||
CONTAINER="${OPENFUT_PY_CONTAINER:-openfut-fut-backend}"
|
||||
live=0
|
||||
|
||||
decode_tcp() {
|
||||
# /proc/net/tcp rows -> "local remote state", little-endian hex addresses.
|
||||
python3 -c "
|
||||
import sys
|
||||
def d(x):
|
||||
ip, port = x.split(':')
|
||||
return '.'.join(str(int(ip[i:i+2], 16)) for i in (6, 4, 2, 0)) + ':' + str(int(port, 16))
|
||||
for line in sys.stdin:
|
||||
f = line.split()
|
||||
if len(f) < 4 or not f[0].endswith(':'):
|
||||
continue
|
||||
try:
|
||||
print(d(f[1]), d(f[2]), f[3])
|
||||
except Exception:
|
||||
pass
|
||||
"
|
||||
}
|
||||
|
||||
echo "client: $CLIENT"
|
||||
|
||||
# ---- Rust sidecar (host namespace)
|
||||
rust="$(ss -tn state established 2>/dev/null | grep -F "$CLIENT" | grep -E ':42230' || true)"
|
||||
if [[ -n "$rust" ]]; then
|
||||
echo " RUST sidecar : LIVE session(s)"
|
||||
sed 's/^/ /' <<<"$rust"
|
||||
live=1
|
||||
else
|
||||
echo " RUST sidecar : none"
|
||||
fi
|
||||
|
||||
# ---- Python backend (container namespace)
|
||||
if docker exec "$CONTAINER" true 2>/dev/null; then
|
||||
py="$(docker exec "$CONTAINER" cat /proc/net/tcp 2>/dev/null | decode_tcp \
|
||||
| awk '$3=="01"' | grep -F "$CLIENT" || true)"
|
||||
if [[ -n "$py" ]]; then
|
||||
echo " PYTHON backend: LIVE session(s)"
|
||||
awk '{printf " %-22s <- %-22s ESTABLISHED\n", $1, $2}' <<<"$py"
|
||||
live=1
|
||||
else
|
||||
echo " PYTHON backend: none"
|
||||
fi
|
||||
else
|
||||
echo " PYTHON backend: container '$CONTAINER' not reachable — CANNOT confirm"
|
||||
live=1 # unknown is not the same as clear
|
||||
fi
|
||||
|
||||
echo
|
||||
if [[ $live -eq 0 ]]; then
|
||||
echo "RESULT: no live client session — safe to begin a gate"
|
||||
else
|
||||
echo "RESULT: client still connected — close FIFA before starting a gate"
|
||||
fi
|
||||
exit $live
|
||||
Executable
+200
@@ -0,0 +1,200 @@
|
||||
#!/usr/bin/env bash
|
||||
# Capture evidence for one live-FIFA gate.
|
||||
#
|
||||
# gate-evidence.sh <gate-label> [outdir]
|
||||
#
|
||||
# Records what the system was configured to do AND what it observably did, and
|
||||
# reports them separately.
|
||||
#
|
||||
# WHY BOTH
|
||||
#
|
||||
# `blaze-switch.sh status = ON` is an assertion produced by the same tooling
|
||||
# that performs the switch. If that tooling is wrong — and it has been once
|
||||
# already, reporting a rollback that had not happened — the assertion is
|
||||
# worthless. The observed half comes from a different source entirely: the
|
||||
# sidecar's own record of which peers connected to it. A remote peer appearing
|
||||
# in the sidecar log is proof the client reached Rust that does not depend on
|
||||
# reading an iptables rule correctly.
|
||||
#
|
||||
# Run it after each gate. It never modifies anything.
|
||||
set -uo pipefail
|
||||
|
||||
HERE="$(cd "$(dirname "$(readlink -f "$0")")" && pwd)"
|
||||
ROOT="$(cd "$HERE/.." && pwd)"
|
||||
RUNDIR="${OPENFUT_SIDECAR_RUNDIR:-${TMPDIR:-/tmp}/openfut-sidecar}"
|
||||
LOGFILE="${OPENFUT_SIDECAR_LOG:-$RUNDIR/sidecar.log}"
|
||||
TRACE="${OPENFUT_BLAZE_TRACE:-}"
|
||||
|
||||
LABEL="${1:-}"
|
||||
OUT="${2:-$ROOT/gate-evidence}"
|
||||
[[ -n "$LABEL" ]] || { echo "usage: gate-evidence.sh <gate-label> [outdir]" >&2; exit 2; }
|
||||
|
||||
STAMP="$(date -u +%Y%m%dT%H%M%SZ)"
|
||||
DEST="$OUT/${STAMP}-${LABEL}"
|
||||
mkdir -p "$DEST"
|
||||
|
||||
say() { echo "$@"; }
|
||||
both() { echo "$@" | tee -a "$DEST/summary.txt" >/dev/null; echo "$@"; }
|
||||
|
||||
both "=== gate evidence: $LABEL ($STAMP) ==="
|
||||
both ""
|
||||
|
||||
# ---------------------------------------------------- configured (asserted)
|
||||
both "--- CONFIGURED (asserted by tooling) ---"
|
||||
{
|
||||
"$HERE/blaze-switch.sh" status 2>&1
|
||||
echo
|
||||
"$HERE/sidecar.sh" status 2>&1
|
||||
} > "$DEST/configured.txt"
|
||||
sed 's/^/ /' "$DEST/configured.txt" | tee -a "$DEST/summary.txt"
|
||||
|
||||
# Raw rules, straight from the kernel, not via our parser.
|
||||
{ sudo iptables -t nat -S 2>/dev/null || true; } > "$DEST/iptables-nat.txt"
|
||||
both ""
|
||||
|
||||
# ------------------------------------------------------ observed (measured)
|
||||
both "--- OBSERVED (measured from the sidecar's own record) ---"
|
||||
|
||||
if [[ ! -f "$LOGFILE" ]]; then
|
||||
both " no sidecar log at $LOGFILE — nothing observed"
|
||||
else
|
||||
cp "$LOGFILE" "$DEST/sidecar.log" 2>/dev/null
|
||||
|
||||
banner="$(grep -m1 'openfut-blaze-host v' "$LOGFILE" 2>/dev/null || true)"
|
||||
both " build: ${banner:-<none>}"
|
||||
if grep -q 'tree=DIRTY' <<<"$banner"; then
|
||||
both " !! DIRTY BUILD — this run is NOT parity evidence"
|
||||
fi
|
||||
|
||||
conns="$(grep -c 'CONNECT from' "$LOGFILE" 2>/dev/null || echo 0)"
|
||||
both " connections accepted: $conns"
|
||||
|
||||
# THE INDEPENDENT ASSERTION: which peers actually reached this process.
|
||||
peers="$(grep -o 'CONNECT from [0-9.]*' "$LOGFILE" 2>/dev/null | awk '{print $3}' | sort -u || true)"
|
||||
remote="$(grep -v '^127\.' <<<"$peers" | grep -v '^$' || true)"
|
||||
both " peers: $(tr '\n' ' ' <<<"$peers")"
|
||||
if [[ -n "$remote" ]]; then
|
||||
both " REMOTE peer(s) reached the Rust sidecar: $(tr '\n' ' ' <<<"$remote")"
|
||||
both " => the client's Blaze traffic observably landed on Rust"
|
||||
else
|
||||
both " no remote peer connected — only loopback (or nothing) reached Rust"
|
||||
both " => a FIFA session did NOT land here"
|
||||
fi
|
||||
|
||||
# Session shape, straight from the log.
|
||||
logins="$(grep -c 'Authentication::login .*REPLY' "$LOGFILE" 2>/dev/null || echo 0)"
|
||||
notifs="$(grep -c 'UserSessions::<' "$LOGFILE" 2>/dev/null || echo 0)"
|
||||
both " login replies: $logins UserSessions notifications: $notifs"
|
||||
both " close reasons:"
|
||||
grep -o 'CLOSE after [0-9]* frame(s): .*' "$LOGFILE" 2>/dev/null \
|
||||
| sort | uniq -c | sed 's/^/ /' | tee -a "$DEST/summary.txt" || true
|
||||
|
||||
# Anything that looks wrong.
|
||||
probs="$(grep -E 'DECODE FAILED|REJECT|FAILED|absurd' "$LOGFILE" 2>/dev/null | head -20 || true)"
|
||||
if [[ -n "$probs" ]]; then
|
||||
both " ANOMALIES:"
|
||||
sed 's/^/ /' <<<"$probs" | tee -a "$DEST/summary.txt"
|
||||
else
|
||||
both " no anomalies in the log"
|
||||
fi
|
||||
fi
|
||||
|
||||
# ------------------------------------------------------------------ trace
|
||||
both ""
|
||||
both "--- TRACE ---"
|
||||
if [[ -n "$TRACE" && -f "$TRACE" ]]; then
|
||||
cp "$TRACE" "$DEST/rust-blaze.trace"
|
||||
# Count FRAME lines only. `^conn-` also matches the OPEN/CLOSE markers, and
|
||||
# counting those inflated the figure by one or two — which then looked like a
|
||||
# capture/trace divergence when compared against the capture's record count.
|
||||
frames="$(grep -cE '^conn-[0-9]+ (RX|TX) ' "$TRACE" 2>/dev/null || echo 0)"
|
||||
markers="$(grep -cE '^conn-[0-9]+ (OPEN|CLOSE)' "$TRACE" 2>/dev/null || echo 0)"
|
||||
both " $TRACE -> $DEST/rust-blaze.trace ($frames traced frames, $markers lifecycle markers)"
|
||||
# Capture and trace are written continuously; on a LIVE session they are only
|
||||
# comparable if read at the same instant.
|
||||
if [[ -n "${OPENFUT_BLAZE_CAPTURE:-}" && -f "${OPENFUT_BLAZE_CAPTURE}" ]]; then
|
||||
cp "$OPENFUT_BLAZE_CAPTURE" "$DEST/raw.ofcap" 2>/dev/null && chmod 600 "$DEST/raw.ofcap"
|
||||
both " raw capture -> $DEST/raw.ofcap (0600, NEVER commit)"
|
||||
fi
|
||||
both " routes seen:"
|
||||
grep -o '^conn-[0-9]* \(RX\|TX\) [^ ]* [A-Za-z]*::[^ ]*' "$TRACE" 2>/dev/null \
|
||||
| awk '{print $2, $4}' | sort | uniq -c | sort -rn | head -20 \
|
||||
| sed 's/^/ /' | tee -a "$DEST/summary.txt" || true
|
||||
else
|
||||
both " no trace configured (set OPENFUT_BLAZE_TRACE before starting the sidecar)"
|
||||
fi
|
||||
|
||||
# --------------------------------------------- python side (the other half)
|
||||
#
|
||||
# "Rust did not receive it" is weaker than "Python did". The redirector always
|
||||
# runs on Python and is never switched, so it advertises the Blaze endpoint on
|
||||
# every run; whether Python then receives the Blaze CONNECT it just advertised
|
||||
# is the positive observation that says where the hop actually went.
|
||||
both ""
|
||||
both "--- PYTHON SIDE (positive/negative observation) ---"
|
||||
PYLOG=/tmp/blaze_responder.log
|
||||
if docker exec openfut-fut-backend test -f "$PYLOG" 2>/dev/null; then
|
||||
docker exec openfut-fut-backend sh -c "grep -E 'REDIR SENT|BLAZE CONNECT from|closed' $PYLOG" \
|
||||
> "$DEST/python-blaze.log" 2>/dev/null || true
|
||||
CLIENT="${OPENFUT_CLIENT_IP:-}"
|
||||
if [[ -z "$CLIENT" ]]; then
|
||||
both " OPENFUT_CLIENT_IP not set — skipping the client-specific correlation"
|
||||
both " (set it to the FIFA machine's address for positive/negative observation)"
|
||||
fi
|
||||
redirs="$(grep -c "REDIR SENT ('$CLIENT'" "$DEST/python-blaze.log" 2>/dev/null || echo 0)"
|
||||
blazes="$(grep -c "BLAZE CONNECT from ('$CLIENT'" "$DEST/python-blaze.log" 2>/dev/null || echo 0)"
|
||||
both " client $CLIENT — redirector hops served by Python: $redirs"
|
||||
both " client $CLIENT — Blaze connections received by Python: $blazes"
|
||||
both " most recent:"
|
||||
grep -E "\('$CLIENT'" "$DEST/python-blaze.log" 2>/dev/null | tail -4 | sed 's/^/ /' \
|
||||
| tee -a "$DEST/summary.txt" || true
|
||||
both ""
|
||||
both " interpretation: a redirector hop with NO following Python Blaze CONNECT"
|
||||
both " means the Blaze hop went elsewhere (the Rust sidecar). A Python Blaze"
|
||||
both " CONNECT means it went to Python."
|
||||
else
|
||||
both " python blaze log not readable (container not running?)"
|
||||
fi
|
||||
|
||||
# ------------------------------------------------- FUT actions (UTAS side)
|
||||
#
|
||||
# "Known FUT action succeeded" is a client-side fact, but it leaves an
|
||||
# independent trace: FUT actions go over UTAS (Python, never switched), so the
|
||||
# UTAS log confirms them without relying on anyone's recollection of what they
|
||||
# clicked.
|
||||
both ""
|
||||
both "--- FUT ACTIONS (observed on UTAS, which is always Python) ---"
|
||||
UTASLOG=/tmp/utas_server.log
|
||||
if docker exec openfut-fut-backend test -f "$UTASLOG" 2>/dev/null; then
|
||||
docker exec openfut-fut-backend sh -c "grep -E 'STORE:|SQUAD:|SBC:|TRADE:' $UTASLOG" \
|
||||
> "$DEST/utas-actions.log" 2>/dev/null || true
|
||||
# Window to THIS gate. The UTAS log is cumulative across the whole
|
||||
# deployment, so a raw count reads as if 45 packs were opened in this gate.
|
||||
# The sidecar is restarted per gate, so its first log line is the window
|
||||
# start. Both numbers are reported, labelled, because a bare count in a gate
|
||||
# report is read as belonging to that gate.
|
||||
since="$(head -1 "$LOGFILE" 2>/dev/null | sed -E 's/^\[([0-9]+)\..*/\1/')"
|
||||
since_hm="$(date -d "@${since:-0}" '+%H:%M' 2>/dev/null || echo '00:00')"
|
||||
all_packs="$(grep -c 'opened pack' "$DEST/utas-actions.log" 2>/dev/null || echo 0)"
|
||||
gate_packs="$(awk -F'[][]' -v t="$since_hm" '$2>=t' "$DEST/utas-actions.log" 2>/dev/null \
|
||||
| grep -c 'opened pack' || echo 0)"
|
||||
both " pack opens THIS GATE (since $since_hm): $gate_packs"
|
||||
both " pack opens in the whole log (cumulative, all deployments): $all_packs"
|
||||
both " actions this gate:"
|
||||
awk -F'[][]' -v t="$since_hm" '$2>=t' "$DEST/utas-actions.log" 2>/dev/null | tail -6 \
|
||||
| sed 's/^/ /' | tee -a "$DEST/summary.txt" || true
|
||||
else
|
||||
both " utas log not readable"
|
||||
fi
|
||||
|
||||
# ----------------------------------------------------------- python health
|
||||
both ""
|
||||
both "--- PYTHON BACKEND (must stay healthy throughout) ---"
|
||||
if contract="$(cd "$ROOT/fifa17-recon" && timeout 120 python3 tools/test_fut_contract.py 2>&1 | tail -1)"; then
|
||||
both " contract suite: $contract"
|
||||
else
|
||||
both " contract suite: FAILED TO RUN"
|
||||
fi
|
||||
|
||||
both ""
|
||||
both "evidence bundle: $DEST"
|
||||
Executable
+142
@@ -0,0 +1,142 @@
|
||||
#!/usr/bin/env bash
|
||||
# Passive connection-attempt observer for one client address.
|
||||
#
|
||||
# openfut-observe.sh on <CLIENT_IP>
|
||||
# openfut-observe.sh off
|
||||
# openfut-observe.sh status
|
||||
# openfut-observe.sh mark record the current counters as a baseline
|
||||
# openfut-observe.sh delta attempts since the last mark
|
||||
#
|
||||
# WHY THIS EXISTS
|
||||
#
|
||||
# A live gate can fail in two very different ways that look identical in every
|
||||
# server log: the client tried to connect and could not, or the client never
|
||||
# tried at all. No server log can separate those, because both produce silence.
|
||||
#
|
||||
# Worked example, and the reason this exists: two redirector gates failed with
|
||||
# "An error occurred downloading the FUT Squad Update" while the roster server
|
||||
# logged nothing at all. "Nothing" was consistent with a broken roster service,
|
||||
# a wrong roster URL, and a client that never asked — three very different bugs.
|
||||
#
|
||||
# HOW
|
||||
#
|
||||
# This box has no tcpdump, no conntrack, and no readable kernel log (iptables
|
||||
# LOG rules match but their output goes nowhere — verified, not assumed). What
|
||||
# does work is iptables PACKET COUNTERS, so the observation is built from those:
|
||||
# a dedicated raw-table chain, one counting rule per interesting port, each with
|
||||
# no target so it counts and falls through.
|
||||
#
|
||||
# Only SYNs are counted, so one line per connection attempt, and no payload is
|
||||
# recorded — this cannot see message contents even in principle.
|
||||
#
|
||||
# SAFETY
|
||||
#
|
||||
# A counting rule has no target: it cannot drop, rewrite or delay a packet. All
|
||||
# state lives in one custom chain, so `off` is "unhook, flush, delete" and its
|
||||
# verification re-reads the table rather than trusting the delete's exit code.
|
||||
# No rule value contains a space, which is what made an earlier LOG-based
|
||||
# version impossible to delete by reconstructed spec.
|
||||
set -uo pipefail
|
||||
|
||||
TAG=openfut-observe
|
||||
CHAIN=OPENFUT_OBS
|
||||
TABLE=raw
|
||||
STATE="${OPENFUT_OBSERVE_STATE:-${TMPDIR:-/tmp}/openfut-observe.mark}"
|
||||
|
||||
# Ports worth separating. The final catch-all counts EVERY attempt, so it is a
|
||||
# TOTAL and not a remainder: attempts to an untracked port show up as the gap
|
||||
# between TOTAL and the sum of the named ports, rather than vanishing.
|
||||
PORTS=(42127 42227 42130 8081 8099 8080 8094 9988 8999 4216 80 443 17502)
|
||||
|
||||
die() { echo "observe: $*" >&2; exit 1; }
|
||||
ipt() { sudo iptables -t "$TABLE" "$@"; }
|
||||
chain_exists() { ipt -S "$CHAIN" >/dev/null 2>&1; }
|
||||
hooks() { sudo iptables-save -t "$TABLE" 2>/dev/null | grep -cF -- "--comment $TAG"; }
|
||||
|
||||
cmd_on() {
|
||||
local ip="${1:-}"
|
||||
[[ -n "$ip" ]] || die "usage: openfut-observe.sh on <CLIENT_IP>"
|
||||
chain_exists && die "already on — run 'off' first"
|
||||
|
||||
ipt -N "$CHAIN" || die "could not create $CHAIN"
|
||||
local p
|
||||
for p in "${PORTS[@]}"; do
|
||||
ipt -A "$CHAIN" -p tcp --dport "$p" || { cmd_off >/dev/null; die "rule for $p failed"; }
|
||||
done
|
||||
ipt -A "$CHAIN" -p tcp || { cmd_off >/dev/null; die "catch-all rule failed"; }
|
||||
|
||||
# --syn is SYN without ACK: one match per connection ATTEMPT, retries included.
|
||||
ipt -I PREROUTING -s "$ip" -p tcp --syn -m comment --comment "$TAG" -j "$CHAIN" \
|
||||
|| { cmd_off >/dev/null; die "could not hook $CHAIN into PREROUTING"; }
|
||||
|
||||
[[ "$(hooks)" == "1" ]] || { cmd_off >/dev/null; die "hook not installed"; }
|
||||
rm -f "$STATE"
|
||||
echo "observing $ip: ${#PORTS[@]} ports + catch-all, hooked into $TABLE/PREROUTING"
|
||||
}
|
||||
|
||||
cmd_off() {
|
||||
local removed=0
|
||||
# Unhook by parsed fields as argv elements, then flush and delete. No value
|
||||
# here contains a space, so this round trip is safe.
|
||||
while read -r ip; do
|
||||
[[ -n "$ip" ]] || continue
|
||||
ipt -D PREROUTING -s "$ip" -p tcp --syn -m comment --comment "$TAG" -j "$CHAIN" \
|
||||
2>/dev/null && removed=$((removed + 1))
|
||||
done < <(sudo iptables-save -t "$TABLE" 2>/dev/null \
|
||||
| grep -F -- "--comment $TAG" \
|
||||
| sed -nE 's/.* -s ([0-9.]+)(\/32)? .*/\1/p')
|
||||
|
||||
chain_exists && { ipt -F "$CHAIN"; ipt -X "$CHAIN"; }
|
||||
|
||||
local left_hooks left_chain
|
||||
left_hooks="$(hooks)"; chain_exists && left_chain=yes || left_chain=no
|
||||
if [[ "$left_hooks" != "0" || "$left_chain" != "no" ]]; then
|
||||
echo "observe: REFUSING to report success — hooks=$left_hooks chain=$left_chain" >&2
|
||||
return 1
|
||||
fi
|
||||
rm -f "$STATE"
|
||||
echo "observing off: removed $removed hook(s) and the chain, verified none remain"
|
||||
}
|
||||
|
||||
# "port<TAB>packets". The final catch-all is reported as TOTAL, not "other":
|
||||
# every packet reaching the chain counts there, including ones already counted
|
||||
# by a named-port rule above it.
|
||||
counters() {
|
||||
ipt -L "$CHAIN" -v -n -x 2>/dev/null | awk '
|
||||
/dpt:/ { for(i=1;i<=NF;i++) if($i ~ /^dpt:/){ sub(/dpt:/,"",$i); print $i "\t" $1 } ; next }
|
||||
/^ *[0-9]+ +[0-9]+ +/ && !/dpt:/ && NR>2 { print "TOTAL\t" $1 }'
|
||||
}
|
||||
|
||||
cmd_status() {
|
||||
chain_exists || { echo "INACTIVE (no observe chain)"; return 0; }
|
||||
echo "ACTIVE, hooked for: $(sudo iptables-save -t "$TABLE" | grep -F -- "--comment $TAG" \
|
||||
| sed -nE 's/.* -s ([0-9.]+)(\/32)? .*/\1/p' | tr '\n' ' ')"
|
||||
counters | awk -F'\t' '$2>0 {printf " %-8s %s attempt(s)\n", $1, $2}'
|
||||
counters | awk -F'\t' '$2>0' | grep -q . || echo " (no connection attempts yet)"
|
||||
}
|
||||
|
||||
cmd_mark() {
|
||||
chain_exists || die "not observing"
|
||||
counters > "$STATE" || die "could not write $STATE"
|
||||
echo "baseline recorded ($(wc -l <"$STATE") counters)"
|
||||
}
|
||||
|
||||
cmd_delta() {
|
||||
chain_exists || die "not observing"
|
||||
[[ -f "$STATE" ]] || die "no baseline — run 'mark' first"
|
||||
join -t$'\t' -a2 -e 0 -o '0,1.2,2.2' <(sort "$STATE") <(counters | sort) \
|
||||
| awk -F'\t' '{ d=$3-$2; if (d>0) printf " %-8s %s attempt(s)\n", $1, d }' \
|
||||
| sort -k2 -rn
|
||||
echo " ---"
|
||||
join -t$'\t' -a2 -e 0 -o '0,1.2,2.2' <(sort "$STATE") <(counters | sort) \
|
||||
| awk -F'\t' '{ if ($3-$2 > 0) n++ } END { print " ports contacted since mark: " n+0 }'
|
||||
}
|
||||
|
||||
case "${1:-}" in
|
||||
on) shift; cmd_on "$@" ;;
|
||||
off) cmd_off ;;
|
||||
status) cmd_status ;;
|
||||
mark) cmd_mark ;;
|
||||
delta) cmd_delta ;;
|
||||
*) sed -n '2,9p' "$0" | sed 's/^# \?//'; exit 2 ;;
|
||||
esac
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user