From 0798f903b04599d2ee5ccc3ea6b33d7fda16e2ea Mon Sep 17 00:00:00 2001 From: Minseong Choi Date: Thu, 23 Jul 2026 03:31:08 +0900 Subject: [PATCH] feat(bootstrap): allow the Felis-Legacy Velocity fork to be installed as the proxy MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Stock Velocity will not offer the login-plugin-message exchange below 1.13, so a 1.8 client reaching a modern-forwarding backend today is a side effect of Via replacing the channel initialisers before that check runs. It works, and nobody designed it. FL-008's fork registers the two login packets from 1.7.2 and drops the handshake gate, which makes the same outcome deliberate — and its gateonly control shows the registry half is the load-bearing one. FELIS_VELOCITY_FORK_JAR points at such a build; unset, the default, nothing changes and the stock 3.5.1 download runs as before. It stays opt-in because the fork is unmeasured where it counts: FL-008's probe runs offline-mode against a stub backend, while this jar would carry every real Mojang session on the server. No digest is pinned for it. The gradle build is not byte-reproducible across machines, so a hash here would assert a provenance that does not exist; the jar is trusted because that probe certified a build, and the path is checked for readability before anything is replaced. --- deploy/bootstrap.sh | 37 +++++++++++++++++++++++++++++-------- 1 file changed, 29 insertions(+), 8 deletions(-) diff --git a/deploy/bootstrap.sh b/deploy/bootstrap.sh index 51f06cb..8fef83f 100644 --- a/deploy/bootstrap.sh +++ b/deploy/bootstrap.sh @@ -108,6 +108,20 @@ FELIS_LOBBY_IMAGE="${FELIS_LOBBY_IMAGE:-felis-lobby:demo}" # runtime. Crossing a major is a deliberate code change, so we track the newest BUILD of # a pinned minor and let a human move the pin. FELIS_VELOCITY_VERSION="${FELIS_VELOCITY_VERSION:-3.5.1}" +# Path to a Felis-Legacy Velocity fork build, installed as the proxy in place of the +# stock download. Unset — the default — changes nothing. +# +# Stock Velocity will not offer the login-plugin-message exchange below 1.13, so a 1.8 +# client reaching a modern-forwarding backend today is a side effect of Via replacing +# the channel initializers before that check runs. It works, and nobody designed it. +# The fork registers the login packets on 1.7.2 and drops the gate, which makes the +# same outcome deliberate. +# +# Opt-in because it is unmeasured where it counts: FL-008's probe runs offline-mode +# against a stub, and this jar would carry every real Mojang session on the server. +# The build lives in Felis-Legacy and is not byte-reproducible, so there is no digest +# to pin here — the jar is trusted because that probe certified the build. +FELIS_VELOCITY_FORK_JAR="${FELIS_VELOCITY_FORK_JAR:-}" # Temurin 25: Velocity 3.5 needs 21+, and 25 is also what a future Velocity 4 requires, # so the runtime does not have to move again when the pin does. Distro JDK packaging is # a lottery across four package managers — a tarball is one code path everywhere (same @@ -1403,14 +1417,21 @@ install_velocity() { install_jre local url tmp prepare_velocity_layout - log "resolving the newest Velocity ${FELIS_VELOCITY_VERSION} build" - url="$(papermc_latest_jar velocity "$FELIS_VELOCITY_VERSION")" \ - || die "no Velocity build for ${FELIS_VELOCITY_VERSION} (override with FELIS_VELOCITY_VERSION)" - log "downloading Velocity ${FELIS_VELOCITY_VERSION}" - tmp="$(mktemp "${VELOCITY_DIR}/.velocity.jar.XXXXXX")" - remember_temp "$tmp" - curl -fsSL "$url" -o "$tmp" || die "failed to download Velocity: ${url}" - atomic_install_file "$tmp" "${VELOCITY_DIR}/velocity.jar" 0644 root root + if [ -n "$FELIS_VELOCITY_FORK_JAR" ]; then + [ -f "$FELIS_VELOCITY_FORK_JAR" ] \ + || die "FELIS_VELOCITY_FORK_JAR is not a readable file: ${FELIS_VELOCITY_FORK_JAR}" + log "installing the Felis-Legacy Velocity fork from ${FELIS_VELOCITY_FORK_JAR}" + atomic_install_file "$FELIS_VELOCITY_FORK_JAR" "${VELOCITY_DIR}/velocity.jar" 0644 root root + else + log "resolving the newest Velocity ${FELIS_VELOCITY_VERSION} build" + url="$(papermc_latest_jar velocity "$FELIS_VELOCITY_VERSION")" \ + || die "no Velocity build for ${FELIS_VELOCITY_VERSION} (override with FELIS_VELOCITY_VERSION)" + log "downloading Velocity ${FELIS_VELOCITY_VERSION}" + tmp="$(mktemp "${VELOCITY_DIR}/.velocity.jar.XXXXXX")" + remember_temp "$tmp" + curl -fsSL "$url" -o "$tmp" || die "failed to download Velocity: ${url}" + atomic_install_file "$tmp" "${VELOCITY_DIR}/velocity.jar" 0644 root root + fi install_via_plugins write_velocity_config