Repository navigation
Conversation
|
I get why this is something one would want, but personally I think this is something plugins should take care of. |
|
I agree that tool-specific compatibility is often better handled by plugins, especially if they can avoid generating the packet burst in the first place. |
|
I don't think there should be any permission to bypass the packet limiter, and also think this is the wrong approach to fix the problem you're were describing. Allowing the packet limiter to be bypassed by ops to be able to spam command packets to paste a schematic is too niche a use case and isn't worth doing 20 permission checks every tick for every player. The need to bypass it means you're already doing something weird, and that there are probably better solutions. Using a plugin like worldedit to paste the schematic in is what we mainly recommend to people that come in and ask about this in paper-help on the discord. This'll be much faster and more accurate than your current approach, there even seem to be a couple of projects aimed at converting a litematic into a schematic file that worldedit understands if you're working with one of those. If that fails, you can also paste the schematic in a singleplayer world, move the world files to a paper server & move it to your main server using world edit. Or finally, either temporarily raise/remove the packet limit if your server is a private one, or configure your mod to not exceed the packet limit. tl;dr: not necessary, better alternatives exist |
Add a permission-based packet limiter bypass defaulting to operators
Motivation
When an OP or trusted player performs an authorized paste with a schematic tool, the client may send many packets in a short time, triggering Paper's all-packets packet limiter and causing a disconnect. Raising the global threshold is not appropriate because it would weaken packet-rate protection for every connection. Limiting the exemption to explicitly trusted players keeps existing protections for ordinary connections and reduces the opportunity for unauthorized players to abuse the exemption.
Behavior
Implemented through the permission node
paper.packet-limiter.bypass.PermissionDefault.OP, so it is granted to operators by default.isOp()check.all-packetslimit and packet-specific overrides.Implementation
false(fail-closed).LOGIN,CONFIG,HANDSHAKE, andSTATUSdo not receive bypass.Security Boundaries
This bypass only targets Paper's packet limiter and does not remove other protections.
server.propertiesrate-limit, codec/schema validation, command/chat/recipe spam limiters, connection throttling, and other protections still run under their own rules where applicable. Skipped decoder exceptions still incrementreceivedPackets, so the independentserver.propertiesrate-limit can still observe that traffic.PLAYstate is not an additional authentication mechanism; being granted the permission does not mean unlimited traffic is guaranteed to be safe.Validation
Local source patch rebuild and application, NormalTestSuite, full Gradle build, and Paperclip build completed and passed. All 13 feature-specific tests passed:
ConnectionPacketLimiterTest: 4 testsConnectionPacketLimiterIntegrationTest: 6 testsPaperPermissionsTest: 3 testsAll with
failures=0,errors=0,skipped=0.Coverage includes real
channelRead0()for all-packets KICK, packet override DROP/KICK, and differences with and without bypass, as well as full listenertick()for permission grant, revocation, and fail-closed behavior after disconnect.gitleaksscanned the single feature commit inorigin/main..HEADand reported no findings. Codex and an Astra subagent read-only reviews found no confirmed runtime defects.Live testing
Paperclip started successfully on Java 25 with Minecraft 26.3. The test server bound to
127.0.0.1:25566withonline-mode=true.For a stable, repeatable comparison,
all-packets.max-packet-ratewas temporarily lowered from500to20, with the action left asKICK. To avoid interference from the separate command spam limiter, test-only spam exclusions were configured for/filland/setblock.Kicked for exceeding packet rate limitwhen pasting with a real client and the actual schematic tool./fill,/setblock, and/summoncommands were processed successfully and the player stayed online.listthat the player was still online.This experiment validated the default OP permission path and used a controlled threshold, not the default configuration. Explicit non-OP grant and explicit OP deny are currently covered by automated permission tests and have not yet been tested live with LuckPerms.
Not yet performed: LuckPerms integration, Folia compatibility testing, or production deployment testing.
AI Involvement Disclosure
Codex assisted with codebase investigation, implementation, test writing, and local verification. Codex and an Astra subagent performed read-only code and security reviews. The submitter is responsible for the final commit and maintainer communication.