Skip to content

Harden local services and make setup portable - #2

Open
btjones-me wants to merge 1 commit into
rmalde:mainfrom
btjones-me:harden-portable-setup
Open

btjones-me wants to merge 1 commit into
rmalde:mainfrom
btjones-me:harden-portable-setup

Conversation

@btjones-me

@btjones-me btjones-me commented Sep 21, 2026 •

Copy link
Copy Markdown

A fresh checkout currently depends on personal Java paths and a deployment-specific Google project, and its local relay/legacy recorder trust every loopback caller. This makes onboarding fragile and lets unrelated local callers consume model credit or interfere with recordings.

This change provides a documented local setup and shared security boundaries while retaining the existing 1.16.5 gameplay routes.

Changes

  • Resolve Java through MC_JAVA_HOME/JAVA_HOME/PATH and ffmpeg through configuration; add verified server setup, shared Java builds, a doctor command, and SETUP.md. Preserve existing server configuration/worlds and leave EULA acceptance explicit.
  • Centralize explicit key-file, project-specific environment, or configurable Google Secret Manager credentials. Remove the original Google project and inspector-injected relay/transport patches.
  • Authenticate the loopback relay, validate Host/Origin/content type/model/output limits, cap concurrency and total request attempts, reject redirects, and remove automatic retries/hedged paid calls. Provider-side monetary limits remain necessary.
  • Authenticate and bound legacy recording uploads, enforce capture lifecycle/quota checks, reject malformed URLs, and abort failed browser recordings without falsely marking them complete. Bind the legacy browser viewer to loopback.
  • Pin direct npm versions, make dependency patching explicit rather than a postinstall hook, and override uuid to 11.1.1 for GHSA-w5hq-g745-h8pq. Pin SHA-256 digests for executable Maven overrides and verify caches before reuse.
  • Replace legacy Log4j 2.8.1 with pinned 2.26.1 for the renderer and server launch classpath.
  • Add Linux tests/macOS Java-build CI. Restrict automatic test discovery to unit tests so historical world-mutating setup scripts are not accidentally executed. Repair a stale terrain mock in the existing navigation test.

Validation

  • Clean npm ci --ignore-scripts followed by npm run prepare:local.
  • npm test: 115 passed.
  • npm run test:setup: 12 Node security/lifecycle tests + 4 Python setup tests passed. Includes unauthorized/cross-origin/rebound-Host requests with zero upstream calls, oversized chunked bodies, concurrency/call limits, legitimate authenticated relay behavior, upload quotas/replay rejection, and recorder failure cleanup.
  • npm audit --omit=dev: 0 reported vulnerabilities at validation time.
  • Observer and native-view Java agents compile successfully with Java 21 targeting Java 17.
  • Verified native dependencies (--libraries-only), downloaded/verified server, and launched the server with updated Log4j and observer. It reached the expected unaccepted-EULA exit without creating a world.
  • GitHub Actions on the fork: Linux unit/setup tests and observer build, plus macOS native dependency installation and both Java builds, passed.
  • Python/JavaScript syntax checks and git diff --check passed.
  • Independent read-only bypass/regression review; both reported recorder failure cases were fixed and covered by tests.

Compatibility and limits

Existing users must explicitly configure credentials and run the new setup steps. Native rendering remains macOS-only; Intel library selection is implemented but has not been live-tested. The pre-EULA server bootstrap emits legacy Mojang Log4j plugin-registration warnings. No paid model requests, EULA acceptance, complete gameplay run, or native video-rendering run was performed. A live isolated gameplay/recording check remains necessary before treating the setup as fully validated. This is hardening, not an OS sandbox or a general-purpose arbitrary-world agent.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant