OnPlayerCheatDetected
A sign of cheating - return false to tolerate a proven one.
Every detection of the audit and of the server’s other measures goes through here. proven is true for what the server
holds against the player’s game beyond doubt - an order it ignored, a claim it can disprove, a game gone silent, a forged
value written back again and again - and then the
[audit] action (log, kick or ban) follows unless you return false. A proven cheat acts in observe too.
Everything else is advisory: it can be wrong (a modded server’s speeds, an overlay, a lag burst, a client the cheater
controls) and is only counted and logged; what it means is the mode’s to decide - kick, freeze or flag the player here
through the API. The log says anti-cheat: <kind> (proven|advisory): <detail> and, for a proven one, what happened to the
player (, kick, , ban, , log only or , tolerated by the game mode); a kick’s reason is cheating: and the kind with
its underscores as spaces. For each kind the log holds the first five lines of a player’s visit and then every 25th, with the
running count; the mode is still told of every detection (the kinds held back below excepted).
Proven
- the item check:
removal_ignored- an exact order to take an item out, sent three times, and the item still there after about a minute and a half;forged_claim- the game’s reports do not count up, or an item is stamped with an order the server never made, three times within a minute;ledger_silent- no report of the bag for two minutes, or none within twenty seconds of the spawn’s strip;memory_write_repeat- the same item’s count written up again after the server took it away, three times within half a minute; - the progression check:
progress_write_repeat- the same forged XP, level or perk points written back after the server put them back, three times within ten minutes; each time the forged rise must be at least 25 XP, or 2 or more perk points or a perk (only underenforce, only for a rule that acts, never on a server with story quests on);vitals_write_repeat- the same for a frozen nourishment or energy (this version cannot raise it: the rules it needs are not measured yet).
Advisory
- movement and combat:
speed(a way of moving held over its cap, beyond the allowance),blink(a step of more than two metres at a pace over the cap - a teleport - four within two minutes),noclip(six steps through a wall or out of the terrain’s window within a minute),jump,fall(a landing from four metres or more with no damage from the player’s game),horse(a horse galloping on stamina it has not got, or a loose horse moving faster than a rider could make it),never_hit(a player whose server actors never seem to hit),void_ratio(a victim whose guard voids almost every blow).[validation] strict = false, the default, only reportsjump,fall,horseand the per-gait part ofspeed(a way of moving held over its own cap);truealso pulls the player back.blink, the steps themax_speedcaps refuse, andnoclipare reported whateverstrictsays: the server’s step checks act on their own (a wall check pulls the player back with[validation] no_clip); - what the player’s own game signals about itself - hints, since a cheat that controls the game can silence or fake them:
code(the game’s code patched in memory),code_guarded(a patch inside a function the progression and nourishment checks rely on),integrity(one of the multiplayer client’s own patches overwritten),timescale(the game’s clock running faster or slower than the real one, or the game’s speed changed from outside the game),clock(the game’s calendar drifting from the server’s),state(health or stamina written behind the game’s back),save_reenabled(saving switched back on),inventory_overflow(a bag with more items than the game’s client can read),foreign_call(an item made by code outside the game); - the item check:
ledger_desync(the player’s list of items and the server’s records disagree; the server asks for the whole list again, up to three times),ledger_flood(more than twenty reports about items a second, or an impossibly long one),ledger_unavailable(the game says its item reporting cannot run),removal_refused(the game refused an order three times for an item it does not mark undeletable),horse_desync(a horse’s saddlebags that do not match its record after two fills),level_amount(more taken from a level item than the level’s data holds),loot_flags(a bag with more items the game refuses to delete - quest items - than a character can hold, or money or a weapon marked that way, which a body search would otherwise spare); - the progression check (
OnPlayerProgressViolation):progress(a rise of XP, a level, perk points or a perk that nothing explains),progress_ack(the player’s game does not confirm the orders the server sends it),progress_gate(the player’s game says its own XP counting is not running, so the awards it makes cannot be seen),vitals(a nourishment or energy held over the game’s maximum, or a maximum the player’s game reports that is not the game’s),vitals_rewrite(written back to its maximum and written up again).weight(sprinting or mounting a horse while carrying more than the game allows -GetPlayerWeight-, a capacity above what the strength, perks, potions and drinks allow, a horse’s saddlebags holding more than the game lets them; an overloaded player’s jump is never judged, the game allows it) and the hints about a nourishment or energy that falls too slowly or rises with no meal wait for their measurements: they are counted and logged and not told to the mode yet.
The advisory kinds of the progression and weight checks, and code_guarded, are evidence for a rule of the mode’s own,
never a reason to kick by themselves: a lag burst, an overlay or a mod can raise any of them. The server counts every one,
but tells the mode (and its log) of one at most every 10 seconds and 30 times an hour per player and kind. The older kinds
are told once for each detection, and a proven kind is never held back.
Syntax
Section titled “Syntax”function OnPlayerCheatDetected(pid, kind, proven, detail) -- ...end| Parameter | Type | |
|---|---|---|
pid |
number | the player |
kind |
string | what was found - speed, blink, noclip, jump, fall, horse, never_hit, void_ratio, code, integrity, timescale, state, removal_ignored, progress_write_repeat, … |
proven |
boolean | true = held against the client beyond doubt (the [audit] action follows); false = a signal that can be wrong |
detail |
string | a line for the log |
Returns
Section titled “Returns”false tolerates the [audit] action for this event; anything else lets it happen (an advisory one never acts)
Example
Section titled “Example”local strikes = {}function OnPlayerCheatDetected(pid, kind, proven, detail) if proven then return true end strikes[pid] = (strikes[pid] or 0) + 1 Log(string.format("%s: %s (%s) - %d", GetPlayerName(pid), kind, detail, strikes[pid])) if kind == "code" or strikes[pid] >= 50 then Kick(pid, "cheating") end -- this server decided an advisory sign is enoughendSee also
Section titled “See also”OnPlayerAuditViolation · OnPlayerNativeItem · OnPlayerProgressViolation · GetPlayerProgressAudit · Kick · Ban · the Accounts, admins, bans and the audit group of the index
