Jump to content

Safeguarding Against Unchecked And Potentially Damaging Plugins


Recommended Posts

Posted

As Mojang continue to work towards the Minecraft Plugin API (cleaning up and rewriting the code), the code within Minecraft and CraftBukkit will undoubtedly shift. Fortunately, as the majority of the plugins available have been developed using only the Bukkit API (which was designed to be resilient and mostly update proof), this code shifting should not affect most of your servers.

If, however, you happen to be running a plugin that uses code outside of the Bukkit API (like Minecraft or CraftBukkit code), those plugins are highly likely to break and bring down your servers with them - often without any advanced warning - whenever a Minecraft update is released. In response to this very real problem, we've had to make the difficult decision of forcing plugin developers that use Minecraft and/or CraftBukkit code within their plugins to re-evaluate their work with the release of every Minecraft update to ensure they are still functioning as intended.

It is important to note that even if a plugin you have been using has been working fine across Minecraft updates until now, there is simply no way to guarantee that this will always be the case. Making the assumption that it will work with every update is like playing Russian roulette with your server.

The problem:
With the extensive work being done to Minecraft to accommodate the Minecraft Plugin API, the Minecraft code is now more unpredictable and volatile than ever before. These changes have made it clear that allowing plugins to run unchecked across Minecraft updates is a big mistake that puts your servers at significant risk of being silently damaged. Neither Bukkit nor plugin developers have any control over the Minecraft (and, as it is built upon Minecraft itself, CraftBukkit) code. Therefore, if a plugin uses code outside of the Bukkit API and it has not been verified to work on the Minecraft version your server is running, using it can only lead to unpredictable problems.

What makes matters worse and more confusing is that there is no easy way for you, as a server admin, to tell if the plugins you are using utilise only the Bukkit API or unsupported code within Minecraft and/or CraftBukkit itself. As plugin developers have no incentive to do so, they have not been putting up a notice informing server admins that their plugins use more than just the Bukkit API and thus server admins are left in the dark. Without this important knowledge, server admins have been blindly running plugins that are not ensured to function as intended across Minecraft versions, potentially and unknowingly putting their servers at risk.

Up until this safeguard was introduced, plugin developers were not required to verify that their plugins continued to function as they intended whenever a Minecraft update came out. As a result, potentially unstable plugins have been running unchecked on your server with no indication that they could damage your server at any time without any advanced warning. The fact of the matter is: plugins that depend on Minecraft or CraftBukkit code need to have their code verified whenever a Minecraft update is released before it can be said with absolute certainty that a plugin is safe to run on your server.

In summary:
- Mojang is cleaning up and rewriting the Minecraft code in anticipation for the Minecraft Plugin API.
- Plugins that use Minecraft or CraftBukkit code will break in unpredictable ways.
- You aren't told that a plugin is using unsupported and volatile code, so you likely aren't aware that plugins you are using could be silently breaking your servers.

The solution:
To address this problem, we've made the difficult decision of including a safeguard directly into CraftBukkit. This safeguard serves many purposes but the major ones are: it will help protect your server against unchecked plugins, it will make determining which plugins are breaking with every Minecraft updates and it will force plugin developers to take responsibility for what their plugins do to your server.

With this safeguard in place, a potentially damaging plugin will not be able to run until it has been updated with a version that has been checked by the plugin developer. Granted, plugin developers have the option of completely bypassing this safeguard and putting your server at risk. However, if they choose to do this it will be very clear who was responsible for any damage done to your server and you'll know to avoid that developer's work in the future.

Note: this safeguard is not intended to stop the use of code outside of the Bukkit API, but rather to promote more responsible use of it if a plugin developer decides to do so.

So what does this safeguard mean for you?
Server Admins:
If you are a server admin that only uses plugins developed against the Bukkit API, this safeguard doesn't affect you at all. If you are a server admin that uses plugins which use Minecraft or CraftBukkit code (which we do not support or recommend using) then this safeguard means that those plugins will need to be updated with every Minecraft update.

It is important to note that while this safeguard does force plugin developers to take some sort of action to get their plugins built against Minecraft or CraftBukkit working on a new Minecraft version, plugin developers have the option of bypassing it. They can blindly update a few lines in their code to mark it as working with a new Minecraft update or utilise a bypass to trick the safeguard into letting the plugin run. As such, we recommend that server admins be wary of plugin developers who decide to work around this, as they are willingly putting your server at risk.

Plugin Developers:
If you are a plugin developer that purely uses the Bukkit API this safeguard does not affect you in any way.

If, however, you depend on the extremely volatile and unsupported CraftBukkit OR Minecraft code, you will now have to re-evaluate your plugins with every Minecraft update release. As this is what you should have been doing anyway as a responsible developer, this should not affect your update process in any way.

We are not trying to make utilising Minecraft or CraftBukkit code within your plugins more difficult, we are simply trying to promote using it more responsibly if you have a need to do so within your plugins. If there is no way for you to avoid using the volatile and unsupported internals of Minecraft or CraftBukkit, we recommend trying to work with us to design an addition to the Bukkit API that removes this need.

What if I'd rather take the risk?
Server Admins:
If you'd rather put your server at risk by running unchecked code, you are free to bypass this safeguard, however you will no longer receive support from us as a result. If you'd still like to bypass or disable this safeguard, you have the option of running an unofficial build or a tool to update the plugins you use. Unfortunately, since providing support for code we did not write is next to impossible, we still do not allow the discussion and distribution of unofficial builds within our community.

Plugin Developers:
Plugin developers bypassing this safeguard are willingly putting servers at risk with their unpredictable and unchecked code. If you as a plugin developer choose to bypass this safeguard bear in mind that you are taking full responsibility for anything your plugin does to a server and that this decision can affect your reputation as a developer.

There are several ways to bypass this safeguard that I'm sure many of you will be discussing on these forums, however, we would like to make it clear that plugins using any bypass that includes dynamic code generation will be denied from BukkitDev without hesitation due to the inherent security risks it poses for servers.

Whether you are a server admin or a plugin developer, you are free to discuss ways to get around this safeguard provided it does not involve an unofficial build. The issue with unofficial builds is that regardless of where people get them from, we almost inevitably end up having to provide support for them.

We know that this safeguard might cause a few of you some headaches, however we feel that choosing to let servers burn in the coming weeks is not a viable option. Thank you for your continued support, cooperation and understanding in this matter. This was a difficult decision for us to make, but preventing unchecked plugins from silently destroying servers was a big incentive for us.

 

Credits: Bukkit forum.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


  • Posts

    • L2GOLD LEGACY x45 THE ORIGINAL GOLD-STYLE EXPERIENCE Official L2OFF PTS • Chronicle C4 / Interlude • Long-Term Server GRAND OPENING 28 AUGUST 2026 WEBSITE SERVER INFO DOWNLOAD DISCORD OLD GOLD ORIGINAL THE LEGEND RETURNS L2Gold Legacy brings back the authentic Gold-style x45 experience on official L2OFF PTS files with custom systems, balanced progression, competitive PvP and a carefully protected long-term economy. NO WIPES — KEEP YOUR PROGRESS FOREVER SERVER INFORMATION SERVER CHARACTERISTICS EXP / SP x45 ADENA x1 DROP x1 SPOIL x1 RAID BOSS DROP x1 PLATFORM L2OFF PTS Custom Drop & Spoil rates can be checked directly in-game with SHIFT + CLICK on NPCs. GAMEPLAY MAIN FEATURES GAMEPLAY • Auto-learn Skills • Automatic Monster Loot • Shift + Click Droplist • Unlimited Offline Shop • 80 Inventory Slots • Weight Limit Disabled • Maximum 3 Clients per PC • Manual Raid / Epic Loot • Official L2OFF PTS Files PLAYER FRIENDLY • NPC Buffer • 27 Buff Slots • 2 Hour Buff Duration • Mana Potion restores 500 MP • No Mana Potion Cooldown • FREE 1st Profession • FREE 2nd Profession • 3rd Profession: 500,000 Adena • Solo & Party Friendly CLANS • Maximum 45 Clan Members • Maximum 2 Clans per Alliance • Clan Penalty: 1 Hour • Clan Skills for All Members • Castle Sieges • 9 Available Clan Halls PROGRESSION • Rebirth System • Noblesse Progression • Custom Tattoos • Daily Missions • Mining System • Custom Gold Equipment • S-Grade Weapons • Long-Term Economy RAID CONTENT RAID BOSSES & EPIC BOSSES Progressive boss loot, PvP-oriented encounters and controlled progression designed to protect the economy. BAIUM ANTHARAS VALAKAS EPIC BOSS SCHEDULE SERVER TIME — GMT+3 DAY BOSS TIME Monday Core 20:00 Monday Orfen 22:30 Tuesday Zaken 22:30 Wednesday Queen Ant 22:30 Thursday Antharas 22:30 Friday Baium 22:30 Saturday Valakas 22:30 Sunday Frintezza 22:30 CUSTOM EQUIPMENT S-GRADE & L2GOLD GEAR Custom weapons, shields and jewelry are an important part of L2Gold's long-term progression. Draconic Bow Guidance / Focus Angel Slayer Critical Damage / Haste Arcana Mace Acumen / Mana Up Heaven's Divider Haste / Health / Focus S-GRADE WEAPON PRICE 300 Fire Mantras + 1,000,000 Adena Available from Wilbrand, Mantra Manager at Giran Harbor. COMPETITIVE PVP OLYMPIAD CYCLE 7 DAYS WEAPON ENCHANT MAX +21 ARMOR ENCHANT MAX +8 Wednesday 21:00–22:00   •   Friday 21:00–22:00   •   Sunday 21:00–22:00 S-GRADE EQUIPMENT IS FORBIDDEN DAILY & WEEKEND CONTENT EVENTS CAPTURE THE FLAG 50 vs 50 competitive CTF battles. HIGH RATE EVENT Weekend farming and progression event. MINING EVENT Collect Minerals and earn special rewards. Death Match • Bandit Stronghold • TvT • Gold Arena 1v1–9v9 Korean Event • CTF • High Rate • Mining • Piggy • Squash • Discord Events TRANSPARENCY REAL-TIME SERVER STATISTICS Players can verify clans, characters, bosses, items, Olympiad, castles, Gold Weapons and the server economy. NO HIDDEN DROPS • NO SHADOW EDITS • FULL TRANSPARENCY L2GOLD LEGACY x45 • L2OFF PTS • NO WIPES 28 AUGUST 2026 The Original Gold-Style Experience Returns.   PLAY L2GOLD JOIN DISCORD   Website: https://l2gold.co Server Info: https://l2gold.co/server-info.php Discord: discord.com/invite/CBSqxqkhy2
    • Hello my wanna be designer....I see that u are still the same dumb kid u were before some years,takeing some brushes adding soem letters and call it design..Sad that u body might have grown up but ur wanna be brain is still the same shit.... No hard feelings,happens.   Cheers
    • New Release Video demo:   Platforms & recording Fermata is now available as an experimental Android preview for ARM64 devices running Android 13 or newer with Vulkan support. Players can import their own Interlude client from a ZIP or folder, configure their server, and play without modifying the source files. Android now has a dedicated mobile control profile with: A floating movement joystick Direct camera orbit and pinch zoom Camera-focused smart targeting A rotating shortcut selector A mobile HUD and compact window controls An optional Classic control profile Built-in video recording has also arrived on Windows and macOS. Press Shift+Alt+R, or Shift+Option+R on macOS, to open the recorder. Recordings support H.264 and HEVC, Native to 720p resolution, 30 or 60 FPS, configurable quality, game audio, and music. Recording continues across login, character selection, teleports, and window resizing. The recorder controls are excluded from the finished video, while the Fermata watermark is added directly to the MP4. Friends, chat & private stores The complete Interlude friends system is now implemented, including: Online and offline status Friend invitations Adding and removing friends Direct conversations Incoming-message notifications /friendlist Alt/Option+Y access The original blocking commands now work, including /block, /unblock, /blocklist, /allblock, and /allunblock. Private stores are now fully supported. Players can create sell, package-sale, and buy stores, configure their listings and message, receive abnormal-price warnings, and trade through another player's store. Active stores display their original-style sign and message above the seated character. Find Private Store is available from the Actions tab or through /findprivatestore. Entering part of a store message highlights matching store signs in green without contacting the server. Inventory & paperdoll The inventory has been completely remastered into a wider framed-doll layout with a ten-by-eight item grid and separate All, Weapon, Armor, Jewelry, Etc, and Quest tabs. The paperdoll now displays your complete live 3D character with equipped armor, weapons, enchant shells, and weapon enchant effects. Drag to rotate, use the wheel to zoom, and double-click to reset the view. Inventory improvements Holding Alt or Option over an equipment slot opens a quick-swap list containing every compatible item in your inventory. Items are ordered by enchantment, grade, and name, and can be equipped with one click. Dropping inventory items onto the ground has been restored. Drag an item outside the window and confirm the drop, with quantity selection for stackable items. Ground items now use their correct fall, landing, and sparkle effects. World, atmosphere & materials Volumetric fog volumes have been added. Authored banks of mist can drift with the wind, react to weather and time of day, and receive illumination from nearby lamps, torches, and other lights. Half and Full quality modes are available. Water has received a major presentation remaster. Lakes, rivers, wet ground, and puddles now mirror the sky and display a long HDR sun reflection at low angles. Half and Full reflection modes also mirror nearby terrain, trees, buildings, and shorelines. Off mode retains the sky reflection. A new light-particle system supports fireflies, embers, and drifting motes. The brightest particles become small moving light sources that illuminate the ground and nearby fog. Fog volumes and light-particle swarms can be placed through the Shift+Alt+L light editor. Lighting & material improvements Normal-map support has been added for authored stone, wood, terrain, buildings, and other world materials. Supported surfaces gain light-reactive relief, with controls for enabling the effect and adjusting its strength. Enhanced lighting now has smoother transitions, more accurate flame illumination, and additional remastered emissive surfaces across Giran and manor structures. Movement, characters & polish Corrected Strider and Wyvern rider placement, mounted animations, camera height, and nameplate positioning. Fixed Strider transparency and depth rendering so body parts no longer appear hollow or visible through themselves. NPCs now turn smoothly towards the local player when opening a conversation. Improved snowfall with denser flakes, wind-driven descent, varied flake sizes, and flakes that briefly settle before melting. Sounds produced by your own character remain at a stable volume regardless of camera distance. The O key once again starts typing in chat like every other unbound letter. Additional bug fixes and stability improvements. Documentation Fermata now has complete documentation covering installation, controls, settings, rendering, weather, interfaces, supported gameplay, server configuration, and troubleshooting. Documentation is available in English, Greek, Brazilian Portuguese, Russian, and Ukrainian at https://fermata.gg/docs.   Download from the launcher you have installed, or at https://fermata.gg/ if you don't have the launcher.    
  • Topics

×
×
  • Create New...

Important Information

This community uses essential cookies to function properly. Non-essential cookies and third-party services are used only with your consent. Read our Privacy Policy and We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue..