Skip to content

Releases: ZhangZuoqian/secure_shell

v2.1.0 — pluggable engine extension / 引擎拆分为可选扩展包

Choose a tag to compare

@ZhangZuoqian ZhangZuoqian released this 05 Oct 00:49

EN

  • The shell engine ships as a separate optional pack: not bundled, not downloaded, not loaded by the main plugin.
  • !!secure_shell management commands (install / check / enable / disable / uninstall) are console-only — in-game players are always rejected.
  • Download via Python stdlib only (urllib); integrity enforced by the SHA-256 pinned in the plugin source.
  • Optional second-factor password (PBKDF2 in config, never hardcoded). Engine stays disabled until enable_ext.
  • Docs: per-OS command examples, requirements section.

中文

  • shell 执行引擎拆分为独立可选扩展包:主插件默认不带、不下载、不加载。
  • !!secure_shell 管理命令(安装/查看/启用/停用/卸载)仅限控制台,游戏内玩家一律拒绝。
  • 下载仅用 Python 标准库(urllib),完整性由源码内置 SHA-256 锚定。
  • 可选二次密码(PBKDF2 存配置,零硬编码)。安装后保持停用,需 enable_ext 显式开启。
  • 文档:命令示例按系统分区,新增前置说明。

Assets

  • secure_shell-v2.1.0.mcdr:主插件
  • shell_ext-1.0.0.zip:执行引擎扩展包(install_ext 会自动拉取)

v2.0.3 — bilingual replies / 回复语双语化

Choose a tag to compare

@ZhangZuoqian ZhangZuoqian released this 05 Oct 00:49

回复语改为中英双语(中文在前 + 英文括注)。Replies are now bilingual — Chinese first with an English gloss.

v2.0.2 — console-only by default / 默认仅控制台

Choose a tag to compare

@ZhangZuoqian ZhangZuoqian released this 04 Oct 05:02

Changes / 变更

EN

  • In-game execution is now disabled by default. Only the MCDR console can run commands.
  • To enable in-game execution, set allow_player_execution: true in the config — players still need MCDR permission level required_permission (default 4). Both gates must pass.
  • !!shellstatus now shows the in-game execution switch state.
  • README reworked: English and 简体中文 split into README.md / README_CN.md; security notes updated.

中文

  • 游戏内执行默认禁用,仅 MCDR 控制台可执行。
  • 如需开放游戏内执行,把配置里的 allow_player_execution 改为 true——玩家仍需 MCDR 权限等级 required_permission(默认 4),两道门槛缺一不可。
  • !!shellstatus 新增游戏内执行开关状态显示。
  • README 拆分为英文版与中文版,安全说明已更新。

Install / 安装

Download secure_shell-v2.0.2.mcdr and drop it into plugins/, then !!MCDR reload plugin.
下载 secure_shell-v2.0.2.mcdr 放进 plugins/,然后 !!MCDR reload plugin。

v2.0.1

Choose a tag to compare

@ZhangZuoqian ZhangZuoqian released this 28 Sep 15:43

Security fix: shell command injection eliminated

  • Removed the /bin/sh -c / cmd.exe /c wrapper layer: user input is never handed to any shell interpreter
  • Commands are tokenized with shlex.split(); unclosed quotes return a format error and nothing is executed; empty commands are rejected
  • Blacklist / allowlist are matched against the real program name (cmd_list[0]), not the raw input string; config fields blacklist / allowlist / enforce_allowlist unchanged
  • Executed via subprocess.Popen(cmd_list, shell=False); streaming output, per-command timeout with automatic kill, stderr capture and audit log fully preserved; status markers [INFO] / [OK] / [FAIL]

Breaking change

In-game commands no longer support shell built-in syntax (pipes, redirections, wildcards, ;, &&, ||, $(), backticks). For complex logic, write a shell script, put it in the allowlist and run it by name. See README.


⚠️ 该版本已停止分发(含旧版执行策略,游戏内执行未默认禁用)。请使用 v2.1.0。

Secure Shell 2.0.0

Choose a tag to compare

@ZhangZuoqian ZhangZuoqian released this 28 Sep 14:05

Cross-platform secure shell executor for MCDReforged.


⚠️ 该版本已停止分发(含旧版执行策略,游戏内执行未默认禁用)。请使用 v2.1.0。