MHG-1132: update protocol to current Hytale (0.5.5) — handshake + transfer#1
Open
alepaez wants to merge 19 commits into
Open
MHG-1132: update protocol to current Hytale (0.5.5) — handshake + transfer#1alepaez wants to merge 19 commits into
alepaez wants to merge 19 commits into
Conversation
…ces deployed engine
…ocol from server jar
…y from JWT; gated byte logging
…l-safe language) and clientType decode
…ction, Collection players)
…token; defer player registration
…forward undecodable packets raw
claramelo
approved these changes
Jun 17, 2026
SantioMC
requested changes
Jun 22, 2026
SantioMC
left a comment
There was a problem hiding this comment.
Some code requires changing due to changes from upstream
pop4959
approved these changes
Jun 26, 2026
Players intermittently disconnect when the Hytale proxy runs behind Cloudflare Spectrum. Spectrum does not fragment UDP and drops any datagram too large to forward. The client-facing QUIC codec advertised the quiche default max_udp_payload_size (65527) and ran DPLPMTUD (discoverPmtu=true), so datagrams grew past the Spectrum-forwardable size and were blackholed, stalling sessions until the 60s idle timeout dropped the player. Cap the datagram size in both directions and disable PMTU probing, both driven by new config keys so the value can be tuned per deployment without a rebuild: - max-udp-payload-size (default 1200, QUIC's universal floor) sets both maxRecvUdpPayloadSize (advertised to the client, caps client->proxy, the direction Spectrum blackholes) and maxSendUdpPayloadSize (caps proxy->client) - discover-pmtu (default false) drives discoverPmtu(...) Behind Spectrum start at 1200 and raise toward 1350 once stability is confirmed. For direct (non-Spectrum) UDP exposure set discover-pmtu=true.
Addresses the review on xyzeva#5. Security: - PacketDecoder: stop swallowing deserialization failures. Let them propagate so the netty pipeline closes the connection instead of letting a client spam malformed packets while staying connected. Protocol string limits (were 4096000): - FormattedMessage: rawText 4096, messageId 256, param keys 256, color 256, link 4096 - ServerInfo: serverName 256, motd 4096 Applied to all 8 sites, not only the 4 flagged, to stay consistent. Noise removal: - Drop javadoc from internal classes (PlayerSkin, InsecurePlayerOptions, RequestInsecurePlayerOptions) - Drop `final` on locals; it is not used elsewhere in the codebase - Drop verbose explainer comments in Connect and InboundInitialPacketHandler - Drop log.warn on rejected pre-auth connections (console spam vector) - Lowercase internal disconnect messages, matching the existing "invalid referral data" convention Intentionally unchanged: the username now comes from the verified access token rather than a Connect field, because the 0.5.5 Connect packet no longer carries a username. registerPlayer moving after auth, the unregisterPlayer early return and the username null guard all follow from that. Restoring the old equality check would compare against null and reject every login; the UUID cross-check against the token is retained.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates hyproxy's hand-rolled protocol layer to current Hytale 0.5.5 so a client can join through the proxy and be transferred to a backend. Verified end-to-end locally (client → proxy auth handshake → transfer to lobby → spawn).
See
RE-NOTES.mdfor the reverse-engineered packet/sequence findings (decompiled fromHytaleServer.jar).Connect(id 0) re-layout: no uuid/username, 4-slot offset table, var block @46protocolCrcgate (varies per client build; backend validates)InsecurePlayerOptions(363) /RequestInsecurePlayerOptions(364)PacketDecoderforwards undecodable frames raw instead of killing the connectionChannelConnection,Collectionplayers) + backend name fromSERVER_ID-Dhyproxy.debugBytes=trueBuilt with JDK 25 (
./gradlew build).