feat(capture): record whole packets of an account, a character or everything on every server

Staff arm a packet capture on the dashboard; master passes MESSAGE_CAPTURE_CONTROL ARM to
every world, auth and chat and arms its own. Each server's PacketCapture tap (dServer receive,
and a send hook in RakPeer::Send so replica constructions are seen too) records into one
preallocated chunk per server and ships sealed chunks through master on the main loop when
capture_flush_bytes or capture_flush_interval_ms is reached; past capture_buffer_max_mb the
oldest chunks are dropped and the dashboard records a gap. Nothing is armed: one flag check.

- targets: an account (from its login; packets before the login are kept per connection
  and added once auth or the world knows whose they are), a character (from when it is
  picked), or everything; up to 8 at once (a bit each in the record mask)
- worlds and auth record their clients' packets and the master link messages of a captured
  player (session keys by name, zone transfers by request, player added/removed, migration);
  chat finds the player in each packet; master records server traffic for everything
- secrets are never recorded: structs that carry them (login request, login response user
  key, world validation session key, session key messages between servers) are read,
  blanked and written again before recording; auth keeps only the handshake and login
- PacketDecoder: a registry by service and message id names every packet and decodes the
  registered structs; CaptureBundle is the file format (DLUBNDL1, metadata, records);
  CaptureTools orders records on one timeline, pulls movement out, makes bundles portable
  or anonymous and diffs replays
- the dashboard keeps packet captures in message_capture_sessions (capture_kind 1) and
  their packets in a file under capture_dir, one write per batch; arming is audited
- MESSAGE_CAPTURE_CONTROL/DATA only gain appended enum values and trailing fields

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Aaron Kimbrell
2026-09-27 08:45:12 -05:00
parent fb6d73e4bd
commit 332bc04ce8
35 changed files with 3207 additions and 15 deletions

View File

@@ -12,6 +12,8 @@
#include "DashboardRoutes.h"
#include "Game.h"
#include "InspectorFormat.h"
#include "CaptureReplay.h"
#include <filesystem>
#include "Logger.h"
#include "master/MessageCapture.h"
#include "MessageType/Master.h"
@@ -152,7 +154,9 @@ namespace {
{"toClient", session.toClient},
{"only", InspectorFormat::MessageNames(InspectorFormat::ParseIds(session.onlyMessages))},
{"skip", InspectorFormat::MessageNames(InspectorFormat::ParseIds(session.skipMessages))},
{"lastSeq", session.messageCount}
{"lastSeq", session.messageCount},
{"kind", session.kind},
{"target", session.target}
};
}
@@ -263,6 +267,7 @@ namespace {
}
const char* StateOf(const Session& session) {
if (session.kind == 1) return CaptureReplay::IsRunning(session.id) ? "capturing" : "ended";
const auto* capture = Live(session.id);
return capture ? StateName(capture->state) : "ended";
}
@@ -278,7 +283,8 @@ namespace {
const auto maxMb = Setting("inspector_max_mb", DEFAULT_MAX_MB);
run->Log("inspector_session_days = " + (days > 0 ? std::to_string(days) : "0 (no age limit)"));
run->Log("inspector_max_mb = " + (maxMb > 0 ? std::to_string(maxMb) : "0 (no size limit)"));
const bool queued = Background::Run("message_capture_pruning", [days, maxMb](GameDatabase& db) -> nlohmann::json {
const auto folder = CaptureReplay::Folder();
const bool queued = Background::Run("message_capture_pruning", [days, maxMb, folder](GameDatabase& db) -> nlohmann::json {
std::vector<InspectorFormat::StoredSession> stored;
uint64_t total = 0;
for (uint32_t offset = 0;; offset += 1000) {
@@ -295,6 +301,9 @@ namespace {
const auto it = std::ranges::find(stored, id, &InspectorFormat::StoredSession::id);
if (it != stored.end()) freed += it->bytes;
db.DeleteMessageCaptureSession(id);
// A packet capture's packets are in its file (nothing there for a game message capture)
std::error_code ec;
std::filesystem::remove(folder / (std::to_string(id) + ".bundle"), ec);
}
return { {"sessions", stored.size()}, {"deleted", expired.size()}, {"total", total}, {"freed", freed} };
}, [run](nlohmann::json result, const std::string& error) {
@@ -360,6 +369,7 @@ namespace Inspector {
LOG("Couldn't read unfinished message captures: %s", e.what());
}
for (auto& session : unfinished) {
if (session.kind != 0) continue; // packet captures: CaptureReplay
const bool taken = std::ranges::any_of(g_Captures, [&](const auto& entry) { return entry.second.session.characterId == session.characterId; });
if (session.endsAt > now && session.id <= UINT32_MAX && g_Captures.size() < MAX_RUNNING && !taken) {
Capture capture;
@@ -659,7 +669,12 @@ namespace Inspector {
if (const auto* capture = Live(session->id); capture && capture->state != eState::ENDED) {
return JsonError(reply, eHTTPStatusCode::CONFLICT, "Stop the capture before deleting it");
}
if (session->kind == 1 && CaptureReplay::IsRunning(session->id)) return JsonError(reply, eHTTPStatusCode::CONFLICT, "Stop the capture before deleting it");
Database::Get()->DeleteMessageCaptureSession(session->id);
if (session->kind == 1) {
std::error_code ec;
std::filesystem::remove(CaptureReplay::FileOf(session->id), ec);
}
g_Captures.erase(static_cast<uint32_t>(session->id));
const auto reason = body->value("reason", std::string{});
Audit(context, "delete_message_capture", "Deleted the saved game messages of " + Describe(*session) + (reason.empty() ? "" : ": " + reason),