LogicBattle::resetSimulatedManaTimers reads both leaders out of the battle at +96 and +104 and calls a virtual on each without a null check, so an opening state with no leaders segfaults inside LogicGameMode ::decode before anything else happens. so the opening state carries the two king towers and nothing else. they are the objects that cannot get a model - the battle screen, and with it the listener, does not exist yet - and they are also the pair the hud caches at [SpellButton+0x1d0], so they are exactly the objects that must not be replaced later either. everything else, princess towers included, now arrives after the screen is up. |
||
|---|---|---|
| assets | ||
| config | ||
| crates | ||
| .gitignore | ||
| Cargo.lock | ||
| Cargo.toml | ||
| LICENSE | ||
| README.md | ||
scroll-server
A server for the scroll client (Clash Royale 2.0.1306, iOS). Takes a real
client from TCP connect to the lobby: login, own home data, chests, card
upgrades, the shop.
Requirements
- Rust 1.75+
- PostgreSQL 16
Running
createdb scroll
cargo run --release -p scroll-server
Listens on 0.0.0.0:9339, the port the client hardcodes. The schema is created
on first boot. DATABASE_URL defaults to postgres:///scroll.
On macOS a Homebrew cluster may need LC_ALL=C to start at all.
That runs everything in one process. For real isolation, SCROLL_MODE=supervised
makes it spawn the three services as child processes and restart any that dies,
with backoff:
SCROLL_MODE=supervised ./target/release/scroll-server
They can also be started by hand, in any order:
cargo run --release -p auth-service
cargo run --release -p game-service
cargo run --release -p gateway
Checking it without a phone
scroll-probe speaks the same protocol and prints the decoded lobby:
cargo run --release -p gateway --bin scroll-probe -- 127.0.0.1:9339
Flags: --claim-free-chest, --buy-chest <name>, --desync. Pass an account
and pass token to reconnect as an existing player:
scroll-probe 127.0.0.1:9339 0 1 <passtoken>.
Pointing a client at it
The client hardcodes game.clashroyaleapp.com. Patch that string in the binary
inside the ipa to your machine's address, keeping the 23 byte slot NUL padded so
nothing around it moves.
Configuration
| variable | default |
|---|---|
DATABASE_URL |
postgres:///scroll |
SCROLL_MODE |
single, or supervised |
SCROLL_BIN_DIR |
next to the running binary |
SCROLL_AUTH_LISTEN |
127.0.0.1:9401 |
SCROLL_GAME_LISTEN |
127.0.0.1:9402 |
SCROLL_GATEWAY_LISTEN |
0.0.0.0:9339 |
SCROLL_CSV_ROOT |
assets |
SCROLL_SHOP |
config/shop.json |
SCROLL_STARTER_PROFILE |
built in |
RUST_LOG |
info |
Shop
config/shop.json lists what the server sells, as Name#count:
{
"offers": [
{ "id": 1, "give": "Gold#1000" },
{ "id": 5, "give": "chest:Gold#1" },
{ "id": 7, "give": "Diamonds#500", "cost": "Gold#20000" }
]
}
Names resolve against the csv tables. cost is optional; without it the server
charges the same price the client computes from the game data.