Files
OpenFUT/fifa17-recon/tools/ghidra_queries/q_st_qs_9.py
T
funman300 21a81ad63c fifa17-recon: the real quick-sell table, and the grouping bug is not in our layer
Multi-agent pass over the store subsystem, 11 agents, findings run through three
adversarial verifiers. Full writeup in docs/plan-2026-08-05-store-subsystem.md.

THE REAL DISCARD TABLE IS RECOVERED. quick_sell() paid an invented rating tier
(600/300/150/50) that was wrong for every single card. The real table is
fcc_discardcoins in the client's own game DB, 141 rows keyed (cardtype, level, rare),
read out of the running client and verified 22/22 against live items:

    value = round_half_up(rating * price / 100)
    level    = 3 if rating >= 75, 2 if 65..74, else 1   (0x180141e8a..0x180141ea3,
               derived from rating, NOT a wire field)
    cardtype = FUN_1800d8330(cardsubtypeid), decoded from its jump table and checked
               across every subtype 0..599 with zero disagreements

A 94-rated gold rare is 752, not 600. A 76 rare is 608, not 150. A 55 bronze is 17,
not 50.

This also closes a disagreement nobody had noticed: the CLIENT already computes and
displays the correct value locally whenever our discardValue (atom 0xd7) is 0 or
absent. FUN_18013fe00 stores our value at item +0x38 and the guard at 0x180141025
skips the local computation when it is non-zero. So the screen has been showing the
real number while the server paid a made-up one, on every quick sell ever made.

Verified beyond what the report claimed, because a missing table row pays ZERO and
that would be a regression the old flat tier could not produce: across all 236 items
in the live profile, 230 map to cardtype 1 and 6 to cardtype 6, and NOT ONE would pay
0 coins. Table reproduces at 141 rows and the worked example lands exactly.

ZERO WIRE CHANGE, FUT_DISCARD_TABLE default off. Nothing new is sent; only the coin
figure the server credits moves. This is the patch worth defaulting on after one
in-game check, which is simply quick-selling a card and seeing the coins paid match
the value the card was already displaying.

THE GROUPING BUG IS NOT IN CARDSDLL, and the fix ranked first would have wasted a
launch. Live in the running client all three display groups own exactly the right
pack, there is exactly one copy of each pack record in 4 GiB, and nothing we send is
mis-parsed. The parsed model is correct and the Scaleform layer picks the wrong pack
when turning a tile click into a category id. displayGroupAssetId is served as 1/5/6
while the screen's category field reads 3, and group tiles carry a hardcoded
CATEGORY_ID of 0. Confirmed by direct read: ordinal 3, assetId 6, i.e. Premium, while
the last click was Gold.

The heap map that made this possible, all scoped to one pid: display-group vector
control block, 3 elements of 0x108; group record fields at +0x00 sortPriority,
+0x04 displayGroupAssetId, +0x40 a one-element pack vector; inner pack record 0x1a8
with packType at +0x38, ids at +0x70/+0xac, price at +0xa0, quantities at +0xc0..+0xd0.

extPrice SHOULD BE DELETED, not corrected. Both sub-parsers read only
externalPriceId; amount and currency are discarded. Sending the key at all creates an
"mtx" currency row that switches on a real-money price line the client can never fill
offline, which is the literal "or %1s" on every tile.

A WORRY NOBODY HAD RAISED, and I confirmed it from our own logs: the client has sent
packId 6 on every purchase it has ever made, four for four tonight and six for six
across history. We have never observed a successful buy of anything but Premium Gold.

Also settled: FUT_STORE_DISPLAYGROUP=0 is the right resting state, argued from
mechanism rather than from history; FUT_USERINFO=packs stays off because the
unopened-pack counter is client-mutable and the flag ladder silently drops squadList;
POST /user is a latent hard freeze that has never fired because the client never
issues that POST.

Honest coverage: the ActionScript layer is unread by everyone and every remaining
store mystery lives there.

Live: 439 contract checks pass, market suite passes, both flags off.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-06 07:43:51 -07:00

90 lines
3.6 KiB
Python

"""D2 QUICK SELL, batch 9: the wallet. Q2 assign-vs-add, final attempt.
PLAN. Find the credit-carrying response classes and their deserialisers:
RS4:FutUserCreditsServerResponse @ 0x18021dc18
RS4:FutUpdateCreditsServerResponse @ 0x18022cc10
RS4:FutDiscardCardServerResponse @ 0x180220540 (vtable 0x180220488, deser 0x180127300)
Resolve each by find_all(b"RS4:"+name) then xrefs_to(hit-4) -> factory -> the
.rdata vtable it installs -> slot +0x08. Decompile all three deserialisers and
every virtual they invoke on the FUT manager singleton, so the wallet field and
its writers are visible. Then enumerate every writer of that field.
CONTROL: the discard chain must resolve to 0x180127300, which is already known
independently (qword 0x180127300 sits at 0x180220490 = vtable+0x08). If the same
mechanism yields a plausible deser for the two credits classes, it is working.
"""
import traceback, os, struct
OUT = "/tmp/claude-1000/-home-alex-Documents-OpenFUT/8e521ca1-ca3e-4138-bb96-df1744dd1d30/scratchpad/store/qs/"
def dump(tag, va, path=None):
try:
src = dec(va)
except Exception as e:
src = "// threw %r" % (e,)
print("=" * 78)
print("%s %#x fname=%s len(src)=%d (FULL)" % (tag, va, fname(va), len(src)))
print("=" * 78)
print(src)
if path:
open(OUT + path, "w").write(src)
return src
def resolve(name):
out = []
for h in find_all(b"RS4:" + name.encode() + b"\x00"):
for frm, typ, fn, ent in xrefs_to(h - 4):
if ent:
out.append((h, frm, ent, fn))
return out
try:
for nm in ("FutDiscardCardServerResponse", "FutUserCreditsServerResponse",
"FutUpdateCreditsServerResponse"):
print("##### %s #####" % nm)
for h, frm, ent, fn in resolve(nm):
print(" literal %#x factory %#x %s (ref at %#x)" % (h, ent, fn, frm))
src = dump("factory", ent, "qs_r_fac_%x.txt" % ent)
# find the PTR_FUN_ vtable it installs
import re
for m in re.finditer(r"PTR_FUN_([0-9a-f]+)", src):
vt = int(m.group(1), 16)
print(" vtable %#x, slot+0x08 = %#x %s"
% (vt, qword(vt + 8), fname(qword(vt + 8))))
dump("deser", qword(vt + 8), "qs_r_deser_%x.txt" % qword(vt + 8))
for off, tgt, fnm in vtable(vt, 24):
print(" +%#05x %#x %s" % (off, tgt, fnm))
print()
print("##### the FUT manager slots used by the discard deser #####")
# the deser calls (**(code**)(*plVar4 + 0xa30))(plVar4, id) after parsing an id
# find every function that calls a virtual at +0xa30 / +0xa08 / +0xa48 and the
# ones that call slots near them, so a credit setter can be spotted by name.
it = fm.getFunctions(True)
want = ("0xa08", "0xa30", "0xa48", "0x9f8", "0xa00", "0xa10", "0xa18", "0xa20",
"0xa28", "0xa38", "0xa40", "0xa50", "0xa58", "0xa60")
tally = {}
while it.hasNext():
f = it.next()
ii = listing.getInstructions(f.getBody(), True)
got = []
while ii.hasNext():
i = ii.next()
t = str(i)
if t.startswith("CALL qword ptr [") and any(w in t for w in want):
got.append((int(i.getAddress().getOffset()), t))
if got:
tally[int(f.getEntryPoint().getOffset())] = (f.getName(), got)
print(" %d functions call one of those slots" % len(tally))
for e in sorted(tally):
nm, got = tally[e]
print(" %#x %s" % (e, nm))
for a, t in got:
print(" %#x %s" % (a, t))
except Exception:
traceback.print_exc()