59934b4ef0
The client now issues PUT /squad and the hub renders coins, record and the
squad roster. Three separate root causes, all verified live.
Squad blocker (the long-standing "client never sends PUT /squad"):
AddPlayerToSquad, GetSquads and SelectSquadById issue ZERO network requests
(pure local model reads/mutations, FutSquadServiceImpl vtable 0x180233ff0);
only SaveCurrentSquad writes, and it is unguarded. The client simply needed a
populated ACTIVE squad model, which arrives via the massinfo `squad` member.
No response of ours was ever being rejected.
userMassInfo is NOT required to be {}:
0x180174630 is a FLAT {userInfo, squad, settings, userData} body -- the old
"wrapper key is user" note was wrong, and the historical freeze was the
malformed squad member, not the envelope.
clubNameChangeAllowed must be false:
sending true advertises a club-rename flow whose UI model is never populated;
the client shows a naming prompt and dies confirming it (ACCESS_VIOLATION
reading 0x0 at FIFA17.exe+0x71b8651, 4/4 runs, no CardsDLL frame and no request
in flight). Isolated by a single-variable run; guarded by a contract check.
Endpoint/schema corrections found in live traffic, invisible to static analysis:
* GET ut/%s/squad/list is a real endpoint and must return {"squad":[...]},
not the active-squad object (the /list suffix is appended by the caller, so
it never appeared in the request table)
* PUT lands on ut/%s/squad/<id>, not a bare ut/%s/squad
* userInfo currencies are read as name/funds/finalFunds/active -- there is no
"value" key, so coins always rendered 0
* squad-list elements take STRING formation/squadType, not ints
* the CardsDLL script-API thunk<->name table was off by one (AddPlayerToSquad
is 0x18004aa70; 0x18004aff0 is GetPotentialChemistry_Club)
FUT_MASSINFO / FUT_USERINFO ladders keep every step of the bisect reproducible.
Contract suite 311 -> 358 checks. Tooling added: PyGhidra harness (Ghidra's
Java/OSGi script path is broken on this box), minidump reader, live code grabber.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VUT92pz6RWKih9dSr8ZpxW
66 lines
2.1 KiB
Python
66 lines
2.1 KiB
Python
# Q16: FutComponentServicesImpl::FutSquadServiceImpl -- get its ctor + vtable and
|
|
# decompile SaveCurrentSquad(+0x50) / AddPlayerToSquad(+0x168) for real.
|
|
out = open("/tmp/ghidra_fut/squad_impl.txt", "w")
|
|
P = lambda *a: print(*a, file=out)
|
|
|
|
P("=== all FutComponentServicesImpl::* service classes ===")
|
|
for a in find_all(b"FutComponentServicesImpl::", blocks=(".rdata", ".data")):
|
|
P(" %#x %s" % (a, rd_str(a, 90)))
|
|
|
|
P("\n=== ctor/factory FUN_180189be0 ===")
|
|
P(dec(0x180189be0)[:3000])
|
|
|
|
NAME = None
|
|
for a in find_all(b"FutComponentServicesImpl::FutSquadServiceImpl", blocks=(".rdata", ".data")):
|
|
NAME = a
|
|
P("\nclass-name string @ %#x; xrefs:" % NAME)
|
|
for frm, typ, fn, ent in xrefs_to(NAME):
|
|
P(" %#x %s in %s @ %#x" % (frm, typ, fn, ent))
|
|
|
|
# The ctor writes the vtable into the object. Find vtables whose slot count is
|
|
# large and that live near other Fut service vtables; verify by checking that
|
|
# +0x50 / +0x168 / +0x198 / +0x1b8 / +0x1c8 are all real functions.
|
|
P("\n=== candidate FutSquadServiceImpl vtables (>=58 slots) ===")
|
|
TXT_LO, TXT_HI = 0x180001000, 0x1801e4fff
|
|
|
|
|
|
def is_fn(v):
|
|
return TXT_LO <= v <= TXT_HI and fm.getFunctionAt(addr(v)) is not None
|
|
|
|
|
|
p, cur, runs = 0x1801e5000, None, []
|
|
while p < 0x2891f0 + 0x180000000:
|
|
try:
|
|
v = qword(p)
|
|
except Exception:
|
|
v = 0
|
|
if is_fn(v):
|
|
if cur is None:
|
|
cur = [p, 0]
|
|
cur[1] += 1
|
|
else:
|
|
if cur and cur[1] >= 58:
|
|
runs.append(tuple(cur))
|
|
cur = None
|
|
p += 8
|
|
if cur and cur[1] >= 58:
|
|
runs.append(tuple(cur))
|
|
|
|
for s, n in runs:
|
|
nm = rd_str(s + n * 8, 60)
|
|
P(" vtable %#x %d slots trailing=%r" % (s, n, nm[:45]))
|
|
|
|
P("\n=== slot decompiles for every candidate ===")
|
|
for s, n in runs:
|
|
nm = rd_str(s + n * 8, 60)
|
|
P("\n##### vtable %#x (%d slots, %r) #####" % (s, n, nm[:40]))
|
|
for off, tag in ((0x50, "SaveCurrentSquad"), (0x168, "AddPlayerToSquad")):
|
|
if off // 8 >= n:
|
|
continue
|
|
t = qword(s + off)
|
|
f = fm.getFunctionAt(addr(t))
|
|
P("--- +%#05x %s -> %#x %s ---" % (off, tag, t, f.getName() if f else ""))
|
|
P(dec(t)[:3000])
|
|
out.close()
|
|
print("wrote squad_impl.txt")
|