Files
OpenFUT/fifa17-recon/tools/ghidra_queries/q_st_unop_1.py
T
funman300 21a81ad63c fifa17-recon: the real quick-sell table, and the grouping bug is not in our layer
Multi-agent pass over the store subsystem, 11 agents, findings run through three
adversarial verifiers. Full writeup in docs/plan-2026-08-05-store-subsystem.md.

THE REAL DISCARD TABLE IS RECOVERED. quick_sell() paid an invented rating tier
(600/300/150/50) that was wrong for every single card. The real table is
fcc_discardcoins in the client's own game DB, 141 rows keyed (cardtype, level, rare),
read out of the running client and verified 22/22 against live items:

    value = round_half_up(rating * price / 100)
    level    = 3 if rating >= 75, 2 if 65..74, else 1   (0x180141e8a..0x180141ea3,
               derived from rating, NOT a wire field)
    cardtype = FUN_1800d8330(cardsubtypeid), decoded from its jump table and checked
               across every subtype 0..599 with zero disagreements

A 94-rated gold rare is 752, not 600. A 76 rare is 608, not 150. A 55 bronze is 17,
not 50.

This also closes a disagreement nobody had noticed: the CLIENT already computes and
displays the correct value locally whenever our discardValue (atom 0xd7) is 0 or
absent. FUN_18013fe00 stores our value at item +0x38 and the guard at 0x180141025
skips the local computation when it is non-zero. So the screen has been showing the
real number while the server paid a made-up one, on every quick sell ever made.

Verified beyond what the report claimed, because a missing table row pays ZERO and
that would be a regression the old flat tier could not produce: across all 236 items
in the live profile, 230 map to cardtype 1 and 6 to cardtype 6, and NOT ONE would pay
0 coins. Table reproduces at 141 rows and the worked example lands exactly.

ZERO WIRE CHANGE, FUT_DISCARD_TABLE default off. Nothing new is sent; only the coin
figure the server credits moves. This is the patch worth defaulting on after one
in-game check, which is simply quick-selling a card and seeing the coins paid match
the value the card was already displaying.

THE GROUPING BUG IS NOT IN CARDSDLL, and the fix ranked first would have wasted a
launch. Live in the running client all three display groups own exactly the right
pack, there is exactly one copy of each pack record in 4 GiB, and nothing we send is
mis-parsed. The parsed model is correct and the Scaleform layer picks the wrong pack
when turning a tile click into a category id. displayGroupAssetId is served as 1/5/6
while the screen's category field reads 3, and group tiles carry a hardcoded
CATEGORY_ID of 0. Confirmed by direct read: ordinal 3, assetId 6, i.e. Premium, while
the last click was Gold.

The heap map that made this possible, all scoped to one pid: display-group vector
control block, 3 elements of 0x108; group record fields at +0x00 sortPriority,
+0x04 displayGroupAssetId, +0x40 a one-element pack vector; inner pack record 0x1a8
with packType at +0x38, ids at +0x70/+0xac, price at +0xa0, quantities at +0xc0..+0xd0.

extPrice SHOULD BE DELETED, not corrected. Both sub-parsers read only
externalPriceId; amount and currency are discarded. Sending the key at all creates an
"mtx" currency row that switches on a real-money price line the client can never fill
offline, which is the literal "or %1s" on every tile.

A WORRY NOBODY HAD RAISED, and I confirmed it from our own logs: the client has sent
packId 6 on every purchase it has ever made, four for four tonight and six for six
across history. We have never observed a successful buy of anything but Premium Gold.

Also settled: FUT_STORE_DISPLAYGROUP=0 is the right resting state, argued from
mechanism rather than from history; FUT_USERINFO=packs stays off because the
unopened-pack counter is client-mutable and the flag ladder silently drops squadList;
POST /user is a latent hard freeze that has never fired because the client never
issues that POST.

Honest coverage: the ActionScript layer is unread by everyone and every remaining
store mystery lives there.

Live: 439 contract checks pass, market suite passes, both flags off.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-06 07:43:51 -07:00

60 lines
2.5 KiB
Python

"""DIMENSION 5 / unopenedPacks -- pass 1: dump the four deserializers end to end.
HYPOTHESIS: (a) FutCreateUser deser 0x18014cc60 has arms for starterPack(0x2e5) and
bonusPacks(0x5d) that call dedicated sub-deserializers; (b) userInfo 0x18013ec10 has an
arm for unopenedPacks(0x35e) that calls a sub-deser and then a singleton vtbl slot;
(c) pack element 0x18013af30 has an arm for packContentInfo(0x20c) calling a sub-deser
that holds unopened(0x35d).
CONTROL: 0x18013c6d0 (settings deser) is a deserializer of the SAME family with a
KNOWN answer -- exactly one key `configs`(0xa2). If the dump/parse pipeline is sound,
the settings dump must show 0xa2 and nothing else in its key ladder. Same syntactic
form family (ladder), so it controls the extraction, not just the decompile.
NO ABSENCE CLAIMS FROM THIS PASS: it only dumps. Full text goes to disk, lengths are
printed so truncation is visible.
"""
import traceback, os
OUT = "/tmp/claude-1000/-home-alex-Documents-OpenFUT/8e521ca1-ca3e-4138-bb96-df1744dd1d30/scratchpad/store"
try:
os.makedirs(OUT, exist_ok=True)
targets = {
"createuser_18014cc60": 0x18014cc60,
"userinfo_18013ec10": 0x18013ec10,
"packelem_18013af30": 0x18013af30,
"settings_18013c6d0": 0x18013c6d0, # CONTROL
}
for name, a in targets.items():
src = dec(a, 300)
p = os.path.join(OUT, "dec_%s.c" % name)
with open(p, "w") as f:
f.write(src)
f2 = func(a)
print("== %s @ %#x fn=%s body=%#x-%#x declen=%d" % (
name, a, f2.getName() if f2 else "?",
int(f2.getEntryPoint().getOffset()) if f2 else 0,
int(f2.getBody().getMaxAddress().getOffset()) if f2 else 0,
len(src)))
print(" written %s" % p)
# Raw instruction-level immediate enumeration for each target, so the ladder /
# switch / sub-dec forms are all visible regardless of how Ghidra renders them.
for name, a in targets.items():
f2 = func(a)
if f2 is None:
print("!! no function at %#x" % a)
continue
lines = []
it = listing.getInstructions(f2.getBody(), True)
while it.hasNext():
ins = it.next()
lines.append("%#x %s" % (int(ins.getAddress().getOffset()), str(ins)))
p = os.path.join(OUT, "asm_%s.txt" % name)
with open(p, "w") as fh:
fh.write("\n".join(lines))
print("== asm %s: %d instructions -> %s" % (name, len(lines), p))
except Exception:
traceback.print_exc()