Skip to content

Releases: cagrianilokumus/squadreader

v1.4.8

Choose a tag to compare

@github-actions github-actions released this 11 Sep 19:26

Fixed

  • The replay download sent Transfer-Encoding: chunked to every client,
    including ones answered with an HTTP/1.0 status line - and HTTP/1.0 has
    no chunked encoding. Browsers tolerate the contradiction; a strict
    reverse proxy does not, and reads the hex chunk lengths as part of the
    recording. The framing now follows the version the client actually
    spoke: HTTP/1.1 gets a 1.1 status line and chunked (its terminator is
    how a client knows the download finished rather than died), HTTP/1.0
    gets the body bare, delimited by the connection close. Reported by a
    deployment sitting behind such a proxy.

v1.4.7

Choose a tag to compare

@github-actions github-actions released this 08 Sep 22:31

Same agent code as 1.4.6, which was tagged but never produced a binary: the
build broke on the day Debian 11 went end-of-life. 1.4.6 has no release
assets; use this one.

Fixed

  • The build image could no longer be built. bullseye-security's Release
    file passed its Valid-Until when Debian 11 reached end of life, and apt
    refuses the entire update over it. Only the freshness check is relaxed -
    signatures are still verified - because the alternative, moving to
    bookworm, raises the glibc floor from 2.31 to 2.36 and would kill the
    binary on the older boxes this base exists to support.
  • packaging/build.sh built the image with -q and its output redirected to
    /dev/null, so the failure above reached CI as a bare "exit code: 100"
    with nothing else. It now stays quiet on success and prints the docker
    output on failure.

CI build (unsigned)

CI build (unsigned) Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 08 Sep 22:23

Latest agent binary from CI. Unsigned — for testing and for feeding into the signing step, not for direct distribution.

v1.4.5

Choose a tag to compare

@github-actions github-actions released this 01 Sep 20:27

Fixed

  • Squad v10.5.3 moved most of the struct fields the reader's hardcoded
    offsets point at, and the reader did not notice. It kept running, kept
    reporting itself healthy, and kept recording - writing matches in which
    every position was {x: junk, y: 0, z: 1}. Rally points, vehicle and
    seat health, turret magazines, and deployable placer attribution were
    wrong in the same way. Anyone on 1.4.3 or 1.4.4 with Squad v10.5.3 has
    recordings from that window that cannot be repaired; new ones are
    correct from the moment this version starts.
  • Offsets are now re-derived from the running binary instead of being
    read out of a table. Most of the fields involved are UPROPERTYs, so the
    binary was carrying their real offsets all along; resolve_paths reads
    them at startup and prints what it corrected. The few that reflection
    cannot see move with a reflected neighbour rather than being left
    behind.
  • ComponentToWorld - the one that ruined the positions - has neither
    reflection nor a neighbour to anchor to, so the snapshot now recognises
    it instead: on a component with no attach parent the world transform is
    the relative one, which reflection does resolve. The offset is checked
    against live actors before it is used, and searched for only if the
    check fails. A split vote keeps the old value; a wrong coordinate in an
    archive is permanent, a stale one is not.
  • doctor resolves paths before it judges them, so it reports on the
    offsets the reader will actually use rather than on the constants in
    the source. Cap-zone geometry matching recovers with the positions.

v1.4.4

Choose a tag to compare

@github-actions github-actions released this 25 Aug 10:48

Added

  • Plugin alerts can be sent to a Discord webhook. Detection already worked
    and every alert already landed in the database, but nothing ever read that
    table - so the only way to learn about a cheater was to open SQLite, which
    means nobody learned about anything. Set alert_webhook in the config.
    Alerts carry the evidence the detector based its call on and a link to the
    replay they came from.
  • Plugins can be switched on from the config file (plugins_config), not only
    from the command line. On a deployment whose start command belongs to an
    image or a unit file somebody else manages, the detectors could not be
    enabled at all - which is why they had never run anywhere.
  • scripts/plugin_replay.py runs the detectors over recorded matches offline.
    A detector is an accusation generator, and until now the only way to find
    out what its thresholds did on your server was to switch it on and watch a
    channel fill with names. Now it can be measured against the archive instead.

Fixed

  • Cheat detection measured "sustained for N ticks", which only meant what it
    says at one tick rate. The inherited value meant 16 seconds at 0.5 Hz and
    2.7 seconds at 3 Hz - and a parachute landing or a bail from a moving
    vehicle lasts about that long, which is a false accusation waiting for a
    config nobody thought to rescale. Durations are now measured in seconds from
    the game's own clock and mean the same thing at any rate.
  • The 4 Hz position sampler could write a non-finite coordinate. Its gate was
    a magnitude test, and abs(nan) > 5e6 is false by IEEE rules, so a torn
    read passed straight through into the recording; z was never checked at
    all.
  • A recording whose layer the recorder could not identify - a scrim layer a
    community named after itself - now draws its map instead of a bare grid.