feat(capture): record whole packets of an account, a character or everything on every server

Staff arm a packet capture on the dashboard; master passes MESSAGE_CAPTURE_CONTROL ARM to
every world, auth and chat and arms its own. Each server's PacketCapture tap (dServer receive,
and a send hook in RakPeer::Send so replica constructions are seen too) records into one
preallocated chunk per server and ships sealed chunks through master on the main loop when
capture_flush_bytes or capture_flush_interval_ms is reached; past capture_buffer_max_mb the
oldest chunks are dropped and the dashboard records a gap. Nothing is armed: one flag check.

- targets: an account (from its login; packets before the login are kept per connection
  and added once auth or the world knows whose they are), a character (from when it is
  picked), or everything; up to 8 at once (a bit each in the record mask)
- worlds and auth record their clients' packets and the master link messages of a captured
  player (session keys by name, zone transfers by request, player added/removed, migration);
  chat finds the player in each packet; master records server traffic for everything
- secrets are never recorded: structs that carry them (login request, login response user
  key, world validation session key, session key messages between servers) are read,
  blanked and written again before recording; auth keeps only the handshake and login
- PacketDecoder: a registry by service and message id names every packet and decodes the
  registered structs; CaptureBundle is the file format (DLUBNDL1, metadata, records);
  CaptureTools orders records on one timeline, pulls movement out, makes bundles portable
  or anonymous and diffs replays
- the dashboard keeps packet captures in message_capture_sessions (capture_kind 1) and
  their packets in a file under capture_dir, one write per batch; arming is audited
- MESSAGE_CAPTURE_CONTROL/DATA only gain appended enum values and trailing fields

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Aaron Kimbrell
2026-09-27 08:45:12 -05:00
parent fb6d73e4bd
commit 332bc04ce8
35 changed files with 3207 additions and 15 deletions

View File

@@ -1,5 +1,6 @@
#include "Profiler.h"
#include "master/PlayerAction.h"
#include "PacketCapture.h"
#include "master/DashboardMessages.h"
#include <chrono>
#include <cstdlib>
@@ -559,10 +560,18 @@ int main(int argc, char** argv) {
constexpr uint32_t spareCheckTime = 10 * masterFramerate;
uint32_t framesSinceSpareCheck = 0;
// Master's own packet captures go straight to the dashboard
PacketCapture::SetSink([](MessageCaptureData& data) {
if (dashboardServerMasterPeerSysAddr == UNASSIGNED_SYSTEM_ADDRESS) return false;
MasterPackets::SendTo(dashboardServerMasterPeerSysAddr, data);
return true;
});
Game::logger->Flush();
while (!Game::ShouldShutdown()) {
Profiler::BeginFrame();
//In world we'd update our other systems here.
PacketCapture::Update();
//Check for packets here:
packet = Game::server->Receive();
@@ -747,6 +756,8 @@ namespace {
case ServiceType::DASHBOARD:
dashboardServerMasterPeerSysAddr = sysAddr;
g_DashboardConnects++;
// Its traffic isn't a player's; packet captures leave it out
PacketCapture::IgnorePeer(sysAddr);
break;
case ServiceType::UGC:
ugcServerMasterPeerSysAddr = sysAddr;
@@ -1129,6 +1140,20 @@ namespace {
for (const auto& instance : Game::im->GetInstances()) {
if (instance && instance->GetIsReady() && !instance->GetIsShuttingDown()) MasterPackets::SendTo(instance->GetSysAddr(), control);
}
// Packet captures (ARM, DISARM) run on every server, master included
if (control.action == eMessageCaptureControl::ARM || control.action == eMessageCaptureControl::DISARM) {
for (const auto& peer : { authServerMasterPeerSysAddr, chatServerMasterPeerSysAddr }) {
if (peer != UNASSIGNED_SYSTEM_ADDRESS) MasterPackets::SendTo(peer, control);
}
PacketCapture::Control(control);
}
}
// Captured messages and packets: from worlds, and (packet captures) from auth and chat
void OnMessageCaptureData(const MessageCaptureData& data, const SystemAddress& sysAddr) {
if (dashboardServerMasterPeerSysAddr == UNASSIGNED_SYSTEM_ADDRESS) return;
const bool known = Game::im->GetInstanceBySysAddr(sysAddr) || sysAddr == authServerMasterPeerSysAddr || sysAddr == chatServerMasterPeerSysAddr;
if (known) MasterPackets::SendTo(dashboardServerMasterPeerSysAddr, data);
}
void OnRequestServerList(const RequestServerList& request, const SystemAddress& sysAddr) {
@@ -1168,7 +1193,7 @@ namespace {
// Only world servers report game writes; pass them on unchanged
handlers.On<DataChanged>(Master::DATA_CHANGED, ForwardWorldToDashboard<DataChanged>);
handlers.On<MessageCaptureControl>(Master::MESSAGE_CAPTURE_CONTROL, OnMessageCaptureControl);
handlers.On<MessageCaptureData>(Master::MESSAGE_CAPTURE_DATA, ForwardWorldToDashboard<MessageCaptureData>);
handlers.On<MessageCaptureData>(Master::MESSAGE_CAPTURE_DATA, OnMessageCaptureData);
handlers.On<RequestServerList>(Master::REQUEST_SERVER_LIST, OnRequestServerList);
handlers.On<ServerTraffic>(Master::SERVER_TRAFFIC, OnServerTraffic);
handlers.On<ProfileRequest>(Master::PROFILE_REQUEST, OnProfileRequest);