Files
OpenFUT/fifa17-recon/tools/ghidra_queries/q16_impl.py
T
funman300 59934b4ef0 fifa17-recon: FUT squad blocker solved + userInfo delivered
The client now issues PUT /squad and the hub renders coins, record and the
squad roster. Three separate root causes, all verified live.

Squad blocker (the long-standing "client never sends PUT /squad"):
  AddPlayerToSquad, GetSquads and SelectSquadById issue ZERO network requests
  (pure local model reads/mutations, FutSquadServiceImpl vtable 0x180233ff0);
  only SaveCurrentSquad writes, and it is unguarded. The client simply needed a
  populated ACTIVE squad model, which arrives via the massinfo `squad` member.
  No response of ours was ever being rejected.

userMassInfo is NOT required to be {}:
  0x180174630 is a FLAT {userInfo, squad, settings, userData} body -- the old
  "wrapper key is user" note was wrong, and the historical freeze was the
  malformed squad member, not the envelope.

clubNameChangeAllowed must be false:
  sending true advertises a club-rename flow whose UI model is never populated;
  the client shows a naming prompt and dies confirming it (ACCESS_VIOLATION
  reading 0x0 at FIFA17.exe+0x71b8651, 4/4 runs, no CardsDLL frame and no request
  in flight). Isolated by a single-variable run; guarded by a contract check.

Endpoint/schema corrections found in live traffic, invisible to static analysis:
  * GET ut/%s/squad/list is a real endpoint and must return {"squad":[...]},
    not the active-squad object (the /list suffix is appended by the caller, so
    it never appeared in the request table)
  * PUT lands on ut/%s/squad/<id>, not a bare ut/%s/squad
  * userInfo currencies are read as name/funds/finalFunds/active -- there is no
    "value" key, so coins always rendered 0
  * squad-list elements take STRING formation/squadType, not ints
  * the CardsDLL script-API thunk<->name table was off by one (AddPlayerToSquad
    is 0x18004aa70; 0x18004aff0 is GetPotentialChemistry_Club)

FUT_MASSINFO / FUT_USERINFO ladders keep every step of the bisect reproducible.
Contract suite 311 -> 358 checks. Tooling added: PyGhidra harness (Ghidra's
Java/OSGi script path is broken on this box), minidump reader, live code grabber.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VUT92pz6RWKih9dSr8ZpxW
2026-08-03 20:47:16 -07:00

66 lines
2.1 KiB
Python

# Q16: FutComponentServicesImpl::FutSquadServiceImpl -- get its ctor + vtable and
# decompile SaveCurrentSquad(+0x50) / AddPlayerToSquad(+0x168) for real.
out = open("/tmp/ghidra_fut/squad_impl.txt", "w")
P = lambda *a: print(*a, file=out)
P("=== all FutComponentServicesImpl::* service classes ===")
for a in find_all(b"FutComponentServicesImpl::", blocks=(".rdata", ".data")):
P(" %#x %s" % (a, rd_str(a, 90)))
P("\n=== ctor/factory FUN_180189be0 ===")
P(dec(0x180189be0)[:3000])
NAME = None
for a in find_all(b"FutComponentServicesImpl::FutSquadServiceImpl", blocks=(".rdata", ".data")):
NAME = a
P("\nclass-name string @ %#x; xrefs:" % NAME)
for frm, typ, fn, ent in xrefs_to(NAME):
P(" %#x %s in %s @ %#x" % (frm, typ, fn, ent))
# The ctor writes the vtable into the object. Find vtables whose slot count is
# large and that live near other Fut service vtables; verify by checking that
# +0x50 / +0x168 / +0x198 / +0x1b8 / +0x1c8 are all real functions.
P("\n=== candidate FutSquadServiceImpl vtables (>=58 slots) ===")
TXT_LO, TXT_HI = 0x180001000, 0x1801e4fff
def is_fn(v):
return TXT_LO <= v <= TXT_HI and fm.getFunctionAt(addr(v)) is not None
p, cur, runs = 0x1801e5000, None, []
while p < 0x2891f0 + 0x180000000:
try:
v = qword(p)
except Exception:
v = 0
if is_fn(v):
if cur is None:
cur = [p, 0]
cur[1] += 1
else:
if cur and cur[1] >= 58:
runs.append(tuple(cur))
cur = None
p += 8
if cur and cur[1] >= 58:
runs.append(tuple(cur))
for s, n in runs:
nm = rd_str(s + n * 8, 60)
P(" vtable %#x %d slots trailing=%r" % (s, n, nm[:45]))
P("\n=== slot decompiles for every candidate ===")
for s, n in runs:
nm = rd_str(s + n * 8, 60)
P("\n##### vtable %#x (%d slots, %r) #####" % (s, n, nm[:40]))
for off, tag in ((0x50, "SaveCurrentSquad"), (0x168, "AddPlayerToSquad")):
if off // 8 >= n:
continue
t = qword(s + off)
f = fm.getFunctionAt(addr(t))
P("--- +%#05x %s -> %#x %s ---" % (off, tag, t, f.getName() if f else ""))
P(dec(t)[:3000])
out.close()
print("wrote squad_impl.txt")