59934b4ef0
The client now issues PUT /squad and the hub renders coins, record and the
squad roster. Three separate root causes, all verified live.
Squad blocker (the long-standing "client never sends PUT /squad"):
AddPlayerToSquad, GetSquads and SelectSquadById issue ZERO network requests
(pure local model reads/mutations, FutSquadServiceImpl vtable 0x180233ff0);
only SaveCurrentSquad writes, and it is unguarded. The client simply needed a
populated ACTIVE squad model, which arrives via the massinfo `squad` member.
No response of ours was ever being rejected.
userMassInfo is NOT required to be {}:
0x180174630 is a FLAT {userInfo, squad, settings, userData} body -- the old
"wrapper key is user" note was wrong, and the historical freeze was the
malformed squad member, not the envelope.
clubNameChangeAllowed must be false:
sending true advertises a club-rename flow whose UI model is never populated;
the client shows a naming prompt and dies confirming it (ACCESS_VIOLATION
reading 0x0 at FIFA17.exe+0x71b8651, 4/4 runs, no CardsDLL frame and no request
in flight). Isolated by a single-variable run; guarded by a contract check.
Endpoint/schema corrections found in live traffic, invisible to static analysis:
* GET ut/%s/squad/list is a real endpoint and must return {"squad":[...]},
not the active-squad object (the /list suffix is appended by the caller, so
it never appeared in the request table)
* PUT lands on ut/%s/squad/<id>, not a bare ut/%s/squad
* userInfo currencies are read as name/funds/finalFunds/active -- there is no
"value" key, so coins always rendered 0
* squad-list elements take STRING formation/squadType, not ints
* the CardsDLL script-API thunk<->name table was off by one (AddPlayerToSquad
is 0x18004aa70; 0x18004aff0 is GetPotentialChemistry_Club)
FUT_MASSINFO / FUT_USERINFO ladders keep every step of the bisect reproducible.
Contract suite 311 -> 358 checks. Tooling added: PyGhidra harness (Ghidra's
Java/OSGi script path is broken on this box), minidump reader, live code grabber.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VUT92pz6RWKih9dSr8ZpxW
65 lines
2.2 KiB
Python
65 lines
2.2 KiB
Python
# Q9: FUN_18004c180 builds the squad-service object registered into DAT_1802dfd18.
|
|
# Recover its vtable, then decompile AddPlayerToSquad(+0xc8) and SaveCurrentSquad
|
|
# (+0x28) -- the two slots that decide whether PUT /squad is ever issued.
|
|
out = open("/tmp/ghidra_fut/squad_service.txt", "w")
|
|
P = lambda *a: print(*a, file=out)
|
|
|
|
P("=== factory FUN_18004c180 ===")
|
|
P(dec(0x18004c180))
|
|
|
|
# find vtable pointers written by the factory
|
|
f = func(0x18004c180)
|
|
cands = {}
|
|
for a in f.getBody().getAddresses(True):
|
|
ins = listing.getInstructionAt(a)
|
|
if ins is None:
|
|
continue
|
|
for r in ins.getReferencesFrom():
|
|
t = int(r.getToAddress().getOffset())
|
|
if 0x1801e5000 <= t <= 0x1802891ff:
|
|
cands[t] = cands.get(t, 0) + 1
|
|
|
|
P("\n=== vtable candidates referenced by the factory ===")
|
|
best = None
|
|
for t, n in sorted(cands.items()):
|
|
try:
|
|
fns = [fm.getFunctionAt(addr(qword(t + i * 8))) for i in range(6)]
|
|
except Exception:
|
|
continue
|
|
nf = sum(1 for x in fns if x)
|
|
if nf >= 5:
|
|
P(" %#x (%d/6 fnptrs, %d refs)" % (t, nf, n))
|
|
if best is None:
|
|
best = t
|
|
|
|
SLOTS = {0x20: "SaveSquad", 0x28: "SaveCurrentSquad", 0x30: "RemovePlayer",
|
|
0x40: "GetCurrentSquadID?", 0x48: "GetCurrentSquadChemistry",
|
|
0x58: "GetCurrentSquadData", 0x80: "GetSquadList", 0x88: "GetSquads",
|
|
0x90: "SelectSquadById", 0xa8: "IsCardInSquad", 0xb8: "GetSquadLineup",
|
|
0xc0: "LoadActiveSquad", 0xc8: "AddPlayerToSquad"}
|
|
|
|
for t in sorted(cands):
|
|
try:
|
|
fns = [fm.getFunctionAt(addr(qword(t + i * 8))) for i in range(6)]
|
|
except Exception:
|
|
continue
|
|
if sum(1 for x in fns if x) < 5:
|
|
continue
|
|
P("\n=== VTABLE %#x ===" % t)
|
|
for off, tgt, name in vtable(t, 40):
|
|
tag = SLOTS.get(off, "")
|
|
P(" +%#04x -> %#x %-16s %s" % (off, tgt, name, tag))
|
|
P("\n--- key slot decompiles ---")
|
|
for off in (0x28, 0xc8, 0x88, 0x80, 0x90, 0xc0):
|
|
try:
|
|
tgt = qword(t + off)
|
|
except Exception:
|
|
continue
|
|
if not fm.getFunctionAt(addr(tgt)):
|
|
continue
|
|
P("### +%#04x %s -> %#x" % (off, SLOTS.get(off, ""), tgt))
|
|
P(dec(tgt))
|
|
break
|
|
out.close()
|
|
print("wrote squad_service.txt")
|