Skip to content

OnPlayerCheatDetected

A sign of cheating - return false to tolerate a proven one.

Every detection of the audit and of the server’s other measures goes through here. proven is true for what the server holds against the player’s game beyond doubt - an order it ignored, a claim it can disprove, a game gone silent, a forged value written back again and again - and then the [audit] action (log, kick or ban) follows unless you return false. A proven cheat acts in observe too. Everything else is advisory: it can be wrong (a modded server’s speeds, an overlay, a lag burst, a client the cheater controls) and is only counted and logged; what it means is the mode’s to decide - kick, freeze or flag the player here through the API. The log says anti-cheat: <kind> (proven|advisory): <detail> and, for a proven one, what happened to the player (, kick, , ban, , log only or , tolerated by the game mode); a kick’s reason is cheating: and the kind with its underscores as spaces. For each kind the log holds the first five lines of a player’s visit and then every 25th, with the running count; the mode is still told of every detection (the kinds held back below excepted).

Proven

  • the item check: removal_ignored - an exact order to take an item out, sent three times, and the item still there after about a minute and a half; forged_claim - the game’s reports do not count up, or an item is stamped with an order the server never made, three times within a minute; ledger_silent - no report of the bag for two minutes, or none within twenty seconds of the spawn’s strip; memory_write_repeat - the same item’s count written up again after the server took it away, three times within half a minute;
  • the progression check: progress_write_repeat - the same forged XP, level or perk points written back after the server put them back, three times within ten minutes; each time the forged rise must be at least 25 XP, or 2 or more perk points or a perk (only under enforce, only for a rule that acts, never on a server with story quests on); vitals_write_repeat - the same for a frozen nourishment or energy (this version cannot raise it: the rules it needs are not measured yet).

Advisory

  • movement and combat: speed (a way of moving held over its cap, beyond the allowance), blink (a step of more than two metres at a pace over the cap - a teleport - four within two minutes), noclip (six steps through a wall or out of the terrain’s window within a minute), jump, fall (a landing from four metres or more with no damage from the player’s game), horse (a horse galloping on stamina it has not got, or a loose horse moving faster than a rider could make it), never_hit (a player whose server actors never seem to hit), void_ratio (a victim whose guard voids almost every blow). [validation] strict = false, the default, only reports jump, fall, horse and the per-gait part of speed (a way of moving held over its own cap); true also pulls the player back. blink, the steps the max_speed caps refuse, and noclip are reported whatever strict says: the server’s step checks act on their own (a wall check pulls the player back with [validation] no_clip);
  • what the player’s own game signals about itself - hints, since a cheat that controls the game can silence or fake them: code (the game’s code patched in memory), code_guarded (a patch inside a function the progression and nourishment checks rely on), integrity (one of the multiplayer client’s own patches overwritten), timescale (the game’s clock running faster or slower than the real one, or the game’s speed changed from outside the game), clock (the game’s calendar drifting from the server’s), state (health or stamina written behind the game’s back), save_reenabled (saving switched back on), inventory_overflow (a bag with more items than the game’s client can read), foreign_call (an item made by code outside the game);
  • the item check: ledger_desync (the player’s list of items and the server’s records disagree; the server asks for the whole list again, up to three times), ledger_flood (more than twenty reports about items a second, or an impossibly long one), ledger_unavailable (the game says its item reporting cannot run), removal_refused (the game refused an order three times for an item it does not mark undeletable), horse_desync (a horse’s saddlebags that do not match its record after two fills), level_amount (more taken from a level item than the level’s data holds), loot_flags (a bag with more items the game refuses to delete - quest items - than a character can hold, or money or a weapon marked that way, which a body search would otherwise spare);
  • the progression check (OnPlayerProgressViolation): progress (a rise of XP, a level, perk points or a perk that nothing explains), progress_ack (the player’s game does not confirm the orders the server sends it), progress_gate (the player’s game says its own XP counting is not running, so the awards it makes cannot be seen), vitals (a nourishment or energy held over the game’s maximum, or a maximum the player’s game reports that is not the game’s), vitals_rewrite (written back to its maximum and written up again). weight (sprinting or mounting a horse while carrying more than the game allows - GetPlayerWeight -, a capacity above what the strength, perks, potions and drinks allow, a horse’s saddlebags holding more than the game lets them; an overloaded player’s jump is never judged, the game allows it) and the hints about a nourishment or energy that falls too slowly or rises with no meal wait for their measurements: they are counted and logged and not told to the mode yet.

The advisory kinds of the progression and weight checks, and code_guarded, are evidence for a rule of the mode’s own, never a reason to kick by themselves: a lag burst, an overlay or a mod can raise any of them. The server counts every one, but tells the mode (and its log) of one at most every 10 seconds and 30 times an hour per player and kind. The older kinds are told once for each detection, and a proven kind is never held back.

function OnPlayerCheatDetected(pid, kind, proven, detail)
-- ...
end
Parameter Type
pid number the player
kind string what was found - speed, blink, noclip, jump, fall, horse, never_hit, void_ratio, code, integrity, timescale, state, removal_ignored, progress_write_repeat, …
proven boolean true = held against the client beyond doubt (the [audit] action follows); false = a signal that can be wrong
detail string a line for the log

false tolerates the [audit] action for this event; anything else lets it happen (an advisory one never acts)

local strikes = {}
function OnPlayerCheatDetected(pid, kind, proven, detail)
if proven then return true end
strikes[pid] = (strikes[pid] or 0) + 1
Log(string.format("%s: %s (%s) - %d", GetPlayerName(pid), kind, detail, strikes[pid]))
if kind == "code" or strikes[pid] >= 50 then Kick(pid, "cheating") end -- this server decided an advisory sign is enough
end

OnPlayerAuditViolation · OnPlayerNativeItem · OnPlayerProgressViolation · GetPlayerProgressAudit · Kick · Ban · the Accounts, admins, bans and the audit group of the index