Skip to content

Releases: GordonFreesay/ValheimAutoModSync

Valheim AutoModSync 2.6.1

Choose a tag to compare

@GordonFreesay GordonFreesay released this 29 Sep 04:50

Valheim AutoModSync 2.6.1

AutoModSync 2.6.1 is the security and connection-boundary hardening release for the 2.6 line. It keeps AMS4 / protocol 4 and the 2.6.0 transfer/cache/resume/apply/ownership model.

One installer/updater, no Apply.exe

2.6.1 removes the standalone ValheimAutoModSync.Apply.exe helper.

ValheimAutoModSyncInstaller.exe now also owns the existing crash-safe post-exit apply/recovery transaction:

  • the updater is visible rather than hidden;
  • it waits for Valheim to close normally and never force-terminates the game;
  • normal sync updates run as the current user without a UAC prompt;
  • explicit install/repair/uninstall still uses normal Windows elevation when required;
  • PREPARED/COMMITTED journaling, verified backups, rollback/recovery, path/reparse validation, hashes, and ownership rules are preserved;
  • no packer, obfuscator, self-decrypting payload, or custom loader was added.

Standalone servers also provide the release installer/updater in the 2.6.1 migration payload so an existing 2.6.0 client can receive it before the new client DLL depends on it. After that migration, the 2.6.1 client treats the updater as local AutoModSync core and does not let a game server replace the running updater. A missing updater requires an AutoModSync repair/reinstall instead of invoking a self-update workaround.

The intended 2.6.1 mod-site packages are Nexus Mods and CurseForge. Thunderstore publication is deferred unless its policy fit is confirmed separately.

Password-protected servers

Password-protected servers now withhold protected AutoModSync synchronization state until the exact live connection is granted normal Valheim server access.

Before server access is granted, AMS exposes only product presence/version/protocol, the fact that server access is required, and an opaque random one-time challenge. It does not expose the server signing identity/fingerprint, manifest metadata/content, synchronized paths, hashes, sizes, configuration, bundle/cache state, transfer capabilities, or synchronized bytes.

2.6.1 replaces the earlier reusable-verifier proof design with password-auth2:

  • Valheim's normal password dialog remains the input UI.
  • The client derives Valheim's salted password verifier locally.
  • AMS sends a one-time HMAC-SHA256 challenge response instead of transmitting that reusable verifier.
  • The server challenge is random, exact-connection scoped, one-use, and time-bounded.
  • Authorization/challenge state is discarded when the connection ends.

A restart/reconnect must complete the normal server-access check again before protected AMS synchronization can resume.

Stale-mod compatibility preflight

2.6.1 also fixes a class of failures where an older client mod can reject/disconnect before AMS gets a chance to update it.

Some compatibility libraries send their own version RPCs directly from ZNet.OnNewConnection, earlier than Valheim's normal ServerHandshake. Holding only ServerHandshake therefore was not sufficient.

Current 2.6.1 peers negotiate preflight-quarantine1:

  • client and server temporarily quarantine non-AMS compatibility RPCs during AMS preflight;
  • AMS protocol/auth traffic continues normally;
  • core server denial/password controls are not delayed;
  • if files need updating, stale queued compatibility traffic is discarded with the old connection;
  • after a verified no-change preflight, AMS4_Ready releases the queues in their original invocation order;
  • non-AMS/legacy flows retain bounded fail-open/handshake fallback behavior;
  • genuine client disconnects bypass the quarantine immediately; and
  • recognized preflights with no active/queued transfer cannot retain auth/quarantine state indefinitely (30-minute hard lifetime).

Filesystem and apply safety

2.6.1 retains the 2.6.0 hardening already present in the delivery path: signed manifests, fixed synchronization roots, canonical path validation, traversal/reserved-name defenses, reparse-point rejection, bounded archive/resource handling, SHA-256 verified staging, fingerprint-scoped ownership/deletion, and the installer-linked journaled transaction engine with backup/rollback and pre/post-write digest verification.

Server private-key hardening

The persistent server signing key is now explicitly ACL-hardened on Windows instead of relying only on inherited filesystem permissions.

  • the private key remains excluded from all client synchronization;
  • ACL inheritance is disabled on the private-key file;
  • only the actual key-owning/runtime Windows identity, LocalSystem, and local Administrators receive Full Control;
  • broad principals such as Users/Everyone are removed;
  • existing identities are re-hardened by the server process on startup;
  • AutoModSync will not use a key if the restrictive ACL cannot be established and verified;
  • a newly generated identity is removed if hardening fails, so AMS does not leave a fresh insecure credential behind.

The public key/fingerprint remains public and is not subject to this restriction.

First-contact trust

The first server-fingerprint trust dialog now makes the executable-code boundary explicit: BepInEx mods are executable code and can act with the permissions of the user's Valheim process/account. Users should accept files only from a server operator they trust.

Choosing Yes authorizes that server to provide synchronized executable mod files and configuration to the user's PC. The joining player is not asked to certify that the server has redistribution rights for its third-party mod set.

Third-party content is provided by the server operator. AutoModSync does not determine or verify third-party licensing or redistribution rights; the server operator is responsible for ensuring each synchronized third-party file may be redistributed.

Compatibility

Public/no-password servers continue using AMS4/protocol 4.

Released AutoModSync 2.6.0 clients use a dedicated migration bridge on password-protected 2.6.1 servers. The first connection discloses no protected synchronization state before Valheim grants normal server access. After successful server access, the server creates a short-lived, one-use migration grant bound to the same platform identity and intentionally disconnects. A reconnect within the grant lifetime may consume that grant to receive the signed 2.6.1 migration payload; gameplay remains blocked on that migration-only authorization. After the updater applies 2.6.1 and Valheim restarts, the normal 2.6.1 server-access boundary is used.

AutoModSync 2.5.x and earlier clients do not have this protected-server migration bridge and are not given protected synchronization data by a password-protected 2.6.1 server.

Security reporting

The repository now includes a SECURITY.md policy defining the AMS threat boundary, what should be reported as a vulnerability, and the preferred private-disclosure path.

Release qualification

Live release qualification completed on September 29, 2026. The tested path included the protected-server access boundary, wrong/correct server-key behavior, stale-mod preflight isolation, a real released-2.6.0 -> 2.6.1 migration, updater apply/restart/reconnect, a normal post-migration 2.6.1 protected join, and final package inspection confirming that the standalone/Nexus/CurseForge archives contain no ValheimAutoModSync.Apply.exe.

Valheim AutoModSync 2.6.0

Choose a tag to compare

@github-actions github-actions released this 25 Sep 04:57

Valheim AutoModSync 2.6.0

AutoModSync 2.6 is a large reliability, scale, safety, and UX release. It keeps the existing AMS4 / protocol 4 compatibility baseline while adding negotiated 2.6 capabilities.

Highlights

  • Large public-server payloads: content-addressed immutable ZIP caching, startup prewarming, and single-flight construction let identical fresh clients reuse the same prepared bundle instead of recompressing it per connection.
  • Bounded concurrent transfers: a server-wide FIFO scheduler limits active/queued work, shares an aggregate bandwidth budget round-robin, observes Steam reliable-queue pressure, and keeps per-client transfer state bounded.
  • True interrupted-download resume: the client retains one bounded verified partial package and resumes only when the server independently verifies the exact retained prefix against its current immutable artifact.
  • Client-only server payloads: server operators can distribute files from BepInEx/AutoModSync/ClientPayload/plugins/** without making the dedicated server load those files itself.
  • Ownership-safe cleanup: AutoModSync records only files it actually installed/replaced. Stale files are removed only when their current bytes still exactly match the same trusted server's last-owned digest; locally modified, unrelated, pre-existing, and cross-server files are preserved.
  • Transactional apply and recovery: PREPARED/COMMITTED journals, verified backups, rollback, and retry protect live files across crashes or interrupted restarts.
  • Branded synchronization UX: comparison counts, queue position, current/average throughput, ETA, resume-retained bytes, verification, apply, restart, reconnect, completion, and bounded failure states are visible in the AMS panel.
  • Safer trust presentation: first contact shows a short human-comparison security code instead of exposing the complete fingerprint in normal UI/logs. The full 256-bit fingerprint is still used internally for signature validation and pinning.
  • Server-browser AMS badge: Steam-backed servers can passively advertise AMS version/protocol rules; AMS clients can show a small local badge beside positively identified servers without rewriting server names.
  • Installer overhaul: AMS-branded installer, live complete/partial detection, Repair / Update, and conservative role-aware uninstall. Shared BepInEx and unrelated files are preserved; server signing identity/config are preserved unless explicitly selected for removal.
  • Release provenance: official GitHub-built packages receive SHA-256 manifests plus GitHub/Sigstore build-provenance attestations.

Security and failure behavior

  • Non-AMS servers still fail open to normal Valheim after the short discovery window.
  • Once a server positively responds as AutoModSync, signature/trust/path/resource/transfer/apply-preparation failures fail closed for that protected join.
  • Client/server/apply enforce fixed synchronization roots, Windows reserved-name/trailing-dot-space defenses, reparse-point rejection, bounded bundle/file counts and sizes, and bounded ZIP expansion.
  • Server signing identity files and loader-wide BepInEx.cfg remain excluded from synchronized config manifests.

Compatibility

  • Protocol remains AMS4 / 4.
  • 2.6 retains negotiated transfer fallbacks for older AMS4 peers.
  • Store/package-manager installs continue to protect package-manager-owned AutoModSync binaries from server self-overwrite.

Verification

Official GitHub-built release files can be checked with:

gh attestation verify .\ValheimAutoModSync-2.6.0.zip -R GordonFreesay/ValheimAutoModSync

The release also includes SHA256SUMS.txt. GitHub/Sigstore provenance proves build origin/integrity for the exact artifact digest; it is separate from Windows Authenticode and does not suppress SmartScreen/unknown-publisher warnings.

See VERIFYING-RELEASES.md for the standalone and store-package verification commands.

Installation

Standalone users: close Valheim and any dedicated server process, extract ValheimAutoModSync-2.6.0.zip, and run ValheimAutoModSyncInstaller.exe.

Nexus Mods / CurseForge / Thunderstore users should use the package for that store. All channels use the same AutoModSync version.

Server operator notice:

AutoModSync does not grant redistribution rights for third-party mods. Before configuring AutoModSync to send third-party files to connecting clients, server operators are responsible for confirming that the applicable licenses or author permissions allow redistribution and for complying with their conditions. Private/password-protected/noncommercial use does not by itself grant permission. See the current redistribution policy in the repository.

Valheim AutoModSync 2.5.0

Choose a tag to compare

@GordonFreesay GordonFreesay released this 21 Sep 09:30

Valheim AutoModSync 2.5.0

Highlights

  • Synchronization now occurs before Valheim's normal mod compatibility handshake.
  • Supports required BepInEx plugins, patchers, and explicitly allowlisted config files.
  • Adds server-only and optional client-required file classification.
  • Adds faster windowed, binary-batch, and pipelined AMS4 bundle transfers.
  • Preserves normal Jotunn, ServerSync, and other compatibility checks after synchronization.
  • Adds the Windows GUI standalone installer.
  • Preserves automatic restart and reconnect after synchronization.
  • Built from source by GitHub Actions on a GitHub-hosted Windows runner.

Signing

This 2.5.0 release is unsigned. The SignPath Foundation application was declined at this stage because the project has not yet established enough external public-adoption and trust signals; trusted Authenticode signing may be revisited after broader adoption.

SHA-256

106f7cad4b4f4e75ffc7227d28332101ea01fd70631ee15d94d153fce0ed67ad

Valheim AutoModSync 2.4.8

Choose a tag to compare

@GordonFreesay GordonFreesay released this 19 Sep 19:20

Valheim AutoModSync 2.4.8

Fixes

  • Fixes Thunderstore/r2modman profile state handling during synchronization.
  • Saves the active package-manager launch context before restart.
  • Relaunches Valheim through Steam with the original Doorstop/BepInEx profile arguments.
  • Restores automatic reconnect after synchronized mods are applied.
  • Automatically continues through the previously selected character.
  • Prevents duplicate reconnect dispatches and false reconnect timeout warnings.
  • Preserves standalone/manual installation behavior and protocol version 4.

Downloads

  • ValheimAutoModSync-2.4.8.zip — standalone/manual installer
  • GordonFreesay-ValheimAutoModSync-2.4.8.zip — Thunderstore/r2modman package

SHA-256

Standalone:
9154e0d1388beefde7193998f42028908c2da45903af9de73474d90af04e9fa1

Thunderstore:
6b4c020fb7ce9dbcc032ce9a288c2ef960da38c71738968071c23120f30af50f

ValheimAutoModSync-2.4.5

Choose a tag to compare

@GordonFreesay GordonFreesay released this 18 Sep 22:34

Valheim AutoModSync 2.4.5

This release changes the client installation layout to be more transparent and less likely to trigger antivirus heuristics, while preserving the normal AutoModSync workflow.

What's Changed

  • Removed the packed AutoModSync version.dll bootstrap used by 2.4.4.
  • BepInEx, AutoModSync, and the apply helper are now installed as normal visible files on disk.
  • ValheimAutoModSync.Client.dll is installed as a standard BepInEx plugin.
  • The apply helper is installed separately under BepInEx\AutoModSync.
  • Removed the encoded PowerShell client-detection path from the installer.
  • Added automatic migration from the known 2.4.4 AutoModSync bootstrap.
  • Unknown existing version.dll files are left untouched rather than overwritten or deleted.
  • Updated project layout, documentation, and third-party license organization.

Core Functionality Retained

AutoModSync still provides:

  • Automatic server-to-client BepInEx plugin synchronization.
  • Transfers only missing or changed synchronized files.
  • Signed server manifests.
  • SHA-256 file verification.
  • In-game synchronization/download progress.
  • Automatic Valheim restart after required updates.
  • Automatic reconnect to the originating server.
  • Client, Dedicated Server, and Host & Play installation modes.
  • No additional AutoModSync sync port or firewall rule required.

Updating From 2.4.4

Run the 2.4.5 install.bat and select the appropriate installation mode.

The installer recognizes the known 2.4.4 AutoModSync bootstrap and migrates the installation to the new transparent layout automatically.

Security Note

SHA-256 verification confirms that synchronized files match the authenticated server manifest. It does not determine whether a third-party BepInEx plugin itself is safe.

BepInEx plugins are executable .NET code. Only use AutoModSync with servers you trust.

Download

ValheimAutoModSync-2.4.5.zip

SHA-256:

3c94db89766ed6f437d7f1d4bb7e601669309735600127857001dcf382855c9b

Source code and documentation:

https://github.com/GordonFreesay/ValheimAutoModSync

ValheimAutoModSync-2.4.4

Choose a tag to compare

@GordonFreesay GordonFreesay released this 18 Sep 16:23
3063b67
  • Preserves the original join destination before restart for more reliable reconnect behavior.
  • Captures direct host/port state before Valheim replaces it with backend/socket state.
  • Retains current host/port and socket endpoint fallbacks.
  • Keeps compressed delta synchronization and package/file verification from the 2.4.x line.