- Batchfile 100%
Multi-agent sweep of the 5 runtime repos (22 agents, 18 candidates, per-finding adversarial verify). No ACTIVE stale-replay load-blocker: candidates were either dead code (orphan REPLAY builders, no-caller force hooks) or live-but-coordinated foreign identity (cosmetic; ProtoTunnel key derived from the same blob). Real finding: three correctness-critical flags default to the OLD/refuted behavior and are correct ONLY via one-off persistent setx on this machine, absent from the launcher and code defaults - BLAZE_DYNAMIC_MISSION_BURST (default 0 -> captured SigmaHeroh blob), BLAZE_CID207_DUALPRECOND, BLAZE_EA_FULL_PARITY. A fresh checkout / cleared env / other machine silently reverts to shipping captured data + refuted paths. Recommend flipping the defaults or setting them in start_anthem_stack.bat. cid=170: mechanism confirmed real; line 1331 correctly gated; third emitter still unlocated (wire-guard c9b29ac catches it and will name it next run). |
||
|---|---|---|
| 01-overview | ||
| 02-blaze | ||
| 03-api | ||
| 04-reverse-engineering | ||
| 05-postgres | ||
| 07-packet-captures | ||
| 08-reviews | ||
| findings | ||
| ops | ||
| output | ||
| .gitignore | ||
| ANTHEM_STACK_ARCHITECTURE.md | ||
| CHEAT_SHEET.md | ||
| DLL_HOOK_INVENTORY_2026-06-15.md | ||
| DOCUMENTATION_STATUS.md | ||
| ENV_VARS_REFERENCE.md | ||
| OBJECTIVE.md | ||
| README.md | ||
| ROADMAP_REALM_SERVER_2026-08-18.md | ||
| SERVER_SDK_2026-08-12.md | ||
| SUBLEVEL_LINK_SPEC_FROM_FIFA_2026-06-15.md | ||
| TWO_INSTANCE_FIX_2026-06-16.md | ||
| XBOX_DECOMP_RECIPE_2026-06-16.md | ||
Anthem Private Server - Documentation
(!) STALE (partial) 2026-06-05 - The live tree is
code/blaze_realudp_fork/(Blaze) +code/AnthemPacketLogger_realudp/(DLL); thecode/blaze_test*path in the diagram below does NOT exist (verified 2026-06-05). Also the "blocked at WaitingForGhosts / ghost replication" one-line summary is FALSIFIED: the 20% wall was the cid=207 baseline (IsBaselineMessage=True, SOLVED 2026-06-04, wire-only); the current frontier is the post-Ingame menu-peer teardown. Navigation/ports/archives still useful. - see DOCUMENTATION_STATUS.md
This folder is the authoritative reference for the Anthem private-server project. Everything that would otherwise be lost as "stuff we figured out once" lives here.
How to navigate
Start with 01-overview/ if you're new. Everything else is a
deep-dive on a single subsystem or problem class.
01-overview/ project status, scaling notes, morning-pickup logs
02-blaze/ Blaze server (Python 2.7): components, fixes, specs
03-api/ BIGS REST API (Node): routes, persistence, quirks
04-reverse-engineering/ Ghidra work, DLL injection, decompile analysis
05-postgres/ schema design, per-character isolation
06-reference-archives/ what's in archive/code/{BetaR2, frostbiteEngine, other_projects}
07-packet-captures/ how to read and use the pcap/apkl references
Current state - one-line summary
Main menu, character create/switch, crafting/customization, and Fort
Tarsis work end-to-end. Tutorial mission loading screen is blocked at
ClientState_WaitingForGhosts because we can't yet synthesize the
Frostbite-level NetworkLoadLevelMessage + ghost replication the
client expects. Details in 04-reverse-engineering/.
Runtime architecture in one picture
+-----------------------------------------------------------------+
| Anthem.exe (game client) |
| +----------------+ +------------------+ +-----------------+ |
| | BIGS HTTP | | Blaze TCP | | DirtySDK UDP | |
| | localhost:47873| | localhost:10041 | | port 21123 | |
| +----------------+ +------------------+ +-----------------+ |
+------+-------------------+-------------------------+------------+
| | |
v v v
+--------------+ +--------------+ +--------------+
| Node.js API | | Python 2.7 | | Python bridge|
| port 47873 | | Blaze server | | port 21123 |
| (api-*) | |(blaze_realudp| | (Frostbite |
| | | _fork) | | |
| | | | | passthrough |
| | | | | + replay) |
+------+-------+ +------+-------+ +--------------+
| |
+--------+----------+
v
+-------------+
| PostgreSQL |
| port 5432 |
| schema: |
| anthem |
+-------------+
Injected DLL AnthemHook.dll (loaded via DXGI proxy) hooks
multi-instance APIs, disables HMAC on ProtoTunnel, and hosts the
StateScanHook memory-patching toolkit used during state-machine
reverse engineering.
Ports (localhost only)
| Port | Service | Listener |
|---|---|---|
| 47873 | BIGS REST API | Node.js (api-*) |
| 42230 | BIGS secondary | same Node process |
| 42231 | BIGS secondary | same Node process |
| 10041 | Blaze TCP | Python 2.7 Twisted |
| 21123 | Frostbite tunnel bridge | Python |
| 3659 | Engine / ghost replication | Python (same) |
| 5432 | PostgreSQL | pg 18 local |
Environment
Dev host runs:
- Python 2.7 (old, required by BetaR2-derived Blaze code)
- Node 20+
- PostgreSQL 18
- Windows with Anthem.exe + Ghidra 12.x for reverse engineering
Reading order by topic
If you came for Blaze issues -> 02-blaze/README.md
If you came for API quirks -> 03-api/README.md
If you came for "why does WaitingForGhosts block" -> 04-reverse-engineering/README.md
If you came to scale -> 01-overview/SCALING_NOTES.md
Reference archives (in archive/code/, not this folder)
Several upstream codebases are in archive/code/:
| Archive | What it is | Useful for |
|---|---|---|
BetaR2/ |
BF4 Blaze emulator (Python 2.7) | the origin of our Blaze server - not reference, it IS our code |
blazeserver/ |
EA's production Blaze source (C++) | authoritative component/command definitions |
frostbiteEngine/ |
Frostbite engine dump (partial) | Entity/EntityBus/SubLevel reference; Gameplay/ClientServer is empty |
other_projects/frostbiteserver_clone/ |
Kyber SWBF2 Frostbite server | the connection state machine we'd emulate for Ingame flow |
other_projects/Kyber-ver-beta10/ |
Kyber SWBF2 full project | larger context for Frostbite protocol |
other_projects/anthemtool-master/ |
Anthem asset extraction tool (Python) | CAS/TOC/Bundle parsing |
A full index is at 06-reference-archives/README.md.
Contributing to this folder
- One problem = one markdown file.
- Commit message style:
docs(area): short reason. - If you solve a production bug, write a
BUG_FIX_*.mdwith exactly the symptom -> root cause -> fix -> grep-signature-if-it-regresses pattern that02-blaze/CHARACTER_SWITCH_RELOAD_FIX.mduses. - Cross-link with relative paths (not absolute), keeps the tree portable.